This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Random Shutdown and lots of Pop-ups [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have an older, slower desktop that I use for basic CAD drawings, and some online CCC classes. Lately, when I turn the computer on, it shuts off randomly and reboots with a message about a system32 file. Thank you for the assisstance. The DDS log is below: DDS (Ver_2012-10-14.05) - NTFS_x86 Internet Explorer: 8.0.6001.18702 Run by [removed] at 10:44:14 on 2012-10-16 . ============== Running Processes ================ . . ============== Pseudo HJT Report =============== . uStart Page = hxxp://cnn.com/ uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser uSearchURL,(Default) = hxxp://www.google.com/keyword/%s dURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - BHO: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - c:\program files\avg\avg2012\avgdtiex.dll BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - c:\program files\avg\avg2012\avgssie.dll BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\avg secure search\11.1.0.12\AVG Secure Search_toolbar.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll BHO: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\ask.com\GenericAskToolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: &Google: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\ask.com\GenericAskToolbar.dll TB: : {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - LocalServer32 - TB: &Google: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\ask.com\GenericAskToolbar.dll TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\avg secure search\11.1.0.12\AVG Secure Search_toolbar.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil32_11_4_402_278_ActiveX.exe -update activex mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [HPHUPD08] c:\program files\hp\digital imaging\{33d6cc28-9f75-4d1b-a11d-98895b3a3729}\hphupd08.exe mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe" mRun: [vProt] "c:\program files\avg secure search\vprot.exe" mRun: [ROC_roc_dec12] "c:\program files\avg secure search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 mRun: [HF_G_Jul] "c:\program files\avg secure search\HF_G_Jul.exe" /DoAction mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:323 uPolicies-Explorer: NoDriveAutoRun = dword:67108863 uPolicies-Explorer: NoDrives = dword:0 mPolicies-Explorer: NoDriveAutoRun = dword:67108863 mPolicies-Explorer: NoDriveTypeAutoRun = dword:323 mPolicies-Explorer: NoDrives = dword:0 mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1 mPolicies-Explorer: NoDriveTypeAutoRun = dword:323 mPolicies-Explorer: NoDriveAutoRun = dword:67108863 IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000 IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - c:\program files\avg\avg2012\avgdtiex.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe LSP: mswsock.dll . INFO: HKCU has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: NameServer = 192.168.2.1 TCP: Interfaces\{08411D52-6E1E-4DA4-8EE4-DE46E0C4EF34} : DHCPNameServer = 192.168.2.1 Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\11.2.0\ViProtocol.dll Notify: igfxcui - igfxdev.dll Notify: NecUsb3Sevices - USB3Sw32.dll Notify: USB3Sw32 - USB3Sw32.dll SEH: Microsoft AntiMalware ShellExecuteHook - {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - c:\program files\windows defender\MpShHook.dll . ============= SERVICES / DRIVERS =============== . . =============== Created Last 30 ================ . 2012-10-16 17:36:35 54016 —-a-w- c:\windows\system32\drivers\hrak.sys . ==================== Find3M ==================== . 2012-10-16 16:17:00 0 –sha-w- c:\windows\system32\dds_trash_log.cmd 2012-09-24 00:40:56 73136 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-09-24 00:40:56 696240 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-09-08 00:04:46 22856 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-08-16 21:08:37 9232584 —-a-w- c:\windows\system32\FlashPlayerInstaller.exe . ============= FINISH: 10:44:52.42 ===============
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!


One or more of the identified infections is a backdoor Trojan and rootkit which can allow an attacker to gain control of the system, log keystrokes, steal passwords, access personal data, send malevolent outgoing traffic, and close the security warning messages displayed by some anti-virus and security programs.

At the moment, the particular infection identified normally interacts with rogue security programs, but that does not mean it's interaction is limited to this. It is all that we know of at this time. It has the potential to interact in any number of ways.

While it may be overly cautious, I suggest you do the following immediately:
From a known clean computer, change ALL your on-line passwords for email, banks, financial accounts, PayPal, eBay, on-line companies, any on-line forums or groups you belong to.
Do NOT change passwords or do any transactions while using the infected computer because the attacker may get the new passwords and transaction information.

Though the Trojan/Rootkit has been identified and can most likely be killed, because of it's back door functionality, Your PC is possibly compromised and there is no way to be sure your computer can ever fully again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Making this decision is based on what the computer is used for, and what information can be accessed from it.

While the choice to reformat or procede with cleaning is yours, I do believe we can clean this particular infection successfully. However, I would not be doing my job if I did not give you full disclosure over the type of infection and the possible outcomes so that you could make an informed decision as to what you wanted to do.


Assuming you do wish to go ahead wtih the cleaning please do the following:




Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

Note: If you have any trouble running TDSSKiller just move ahead to the next steps and let me know.


Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing antying, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Patndoris:

Thank you for the assisstance with this. The computer is never used to access any sensitive data; strictly as a back-up for my CAD drawings.

Here are the logs you requested:

Combo Fix:
ComboFix 12-10-16.02 - HP_Administrator 10/16/2012 16:13:50.2.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\HP_Administrator\Application Data\HPSU_48BitScanUpdate.log
c:\documents and settings\HP_Administrator\WINDOWS
c:\windows\$NtUninstallKB28130$
c:\windows\$NtUninstallKB28130$\1753171909
c:\windows\$NtUninstallKB28130$\3403196218\@
c:\windows\$NtUninstallKB28130$\3403196218\cfg.ini
c:\windows\$NtUninstallKB28130$\3403196218\Desktop.ini
c:\windows\$NtUninstallKB28130$\3403196218\L\00000004.@
c:\windows\$NtUninstallKB28130$\3403196218\L\1afb2d56
c:\windows\$NtUninstallKB28130$\3403196218\L\201d3dde
c:\windows\$NtUninstallKB28130$\3403196218\L\55490ac4
c:\windows\$NtUninstallKB28130$\3403196218\L\dievdnxz
c:\windows\$NtUninstallKB28130$\3403196218\oemid
c:\windows\$NtUninstallKB28130$\3403196218\U\00000001.@
c:\windows\$NtUninstallKB28130$\3403196218\U\00000002.@
c:\windows\$NtUninstallKB28130$\3403196218\U\00000004.@
c:\windows\$NtUninstallKB28130$\3403196218\U\80000000.@
c:\windows\$NtUninstallKB28130$\3403196218\U\80000004.@
c:\windows\$NtUninstallKB28130$\3403196218\U\80000032.@
c:\windows\$NtUninstallKB28130$\3403196218\version
c:\windows\system32\avgfwdx.dll
c:\windows\system32\Cache
c:\windows\system32\Cache\0030eca2208749cd.fb
c:\windows\system32\Cache\1f3a9a9d7b1c4846.fb
c:\windows\system32\Cache\272512937d9e61a4.fb
c:\windows\system32\Cache\287204568329e189.fb
c:\windows\system32\Cache\28bc8f716fd76a47.fb
c:\windows\system32\Cache\2c53092c95605355.fb
c:\windows\system32\Cache\30846609500d664a.fb
c:\windows\system32\Cache\31a0997e9a5b5eb3.fb
c:\windows\system32\Cache\32c84fe32bb74d60.fb
c:\windows\system32\Cache\3917078cb68ec657.fb
c:\windows\system32\Cache\40e81568be539544.fb
c:\windows\system32\Cache\590ba23ce359fd0c.fb
c:\windows\system32\Cache\610289e025a3ee9a.fb
c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
c:\windows\system32\Cache\6955a478e2b1fada.fb
c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\system32\Cache\6d03dad1035885d3.fb
c:\windows\system32\Cache\a8556537add6dfc5.fb
c:\windows\system32\Cache\ad10a52aff5e038d.fb
c:\windows\system32\Cache\c1fa887b03019701.fb
c:\windows\system32\Cache\c4d28dca2e7648be.fb
c:\windows\system32\Cache\d201ef9910cd39de.fb
c:\windows\system32\Cache\d2e94710a5708128.fb
c:\windows\system32\Cache\d79b9dfe81484ec4.fb
c:\windows\system32\Cache\e0de16f883bea794.fb
c:\windows\system32\Cache\f36e630886327f03.fb
c:\windows\system32\Cache\f8462207e609949f.fb
c:\windows\system32\Cache\f998975c9cc711ee.fb
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\dds_trash_log.cmd
c:\windows\system32\FlashPlayerInstaller.exe
c:\windows\system32\msstdfmt.dll
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
.
Infected copy of c:\windows\system32\drivers\cdrom.sys was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\cdrom.sys
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_EPSONSTATUSAGENT2
——-\Legacy_TNIDRIVER
——-\Legacy_USNJSVC
——-\Service_epsonstatusagent2
——-\Service_usnjsvc
.
.
((((((((((((((((((((((((( Files Created from 2012-09-16 to 2012-10-16 )))))))))))))))))))))))))))))))
.
.
2012-09-24 19:34 . 2012-09-24 19:34 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-24 00:40 . 2012-04-03 20:13 696240 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-24 00:40 . 2011-05-17 21:32 73136 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-08 00:04 . 2011-01-05 00:39 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-08-02 20:42 2074208 —-a-w- c:\program files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-08-24 04:20 1515688 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-08-24 1515688]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll" [2012-08-02 2074208]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-08-24 1515688]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-11 59392]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-08 61952]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-08 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-06-08 114688]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-02-18 49208]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-09-17 180269]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-04-05 2587008]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-09-17 98304]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2011-08-24 887976]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-08-02 1107552]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [4/19/2012 4:50 AM 24896]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 3:48 AM 31952]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [12/8/2010 4:12 AM 235216]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [11/12/2010 1:19 PM 301248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2/14/2012 4:53 AM 193288]
R2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [7/9/2012 2:26 PM 935008]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [7/12/2010 4:33 AM 30944]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [12/23/2011 1:32 PM 139856]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilterx.sys [12/23/2011 1:32 PM 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [12/23/2011 1:32 PM 17232]
S2 avgfws;AVG Firewall;c:\program files\AVG\AVG2012\avgfws.exe [6/13/2012 3:48 AM 2321560]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\avgidsagent.exe [7/4/2012 5:25 PM 5160568]
S2 NecUsb3;USB3 Service;c:\windows\System32\svchost.exe -k NecUsb3Sevic [8/10/2004 12:00 PM 14336]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/3/2012 1:13 PM 250288]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe [6/8/2011 1:29 PM 947528]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [7/12/2010 4:33 AM 30944]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
NecUsb3Sevic REG_MULTI_SZ NecUsb3
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
fsks
hpqwmi
pccsmcfd
relational
HssTrayService
iAimTV5
acmservice
ndasscsi
lxrjd31d
tosrfnds
tosporte
Cam5607
aeaudio
ZSMC211
pptchpad
us30service
DELL_A02
processor
avsvcmonitor
KR3NPXP
nimcrpcsu
tifm
NETMDUSB
dlaopiom
mgactrl
digitizer
smtpd32
atinevxx
AtiHdmiService
streamloadservice
vpcnfltr
nvatabus
dvd-ram_service
nv
SRTSP
NPDriver
NETGEAR_MA111
rasirda
TMMEmu
Tablet2k
SE2Emdm
wmp54gv4svc
btwdndis
adihdaudaddservice
regdefend
winvnc4
rnadiagnosticsservice
sentinel
NWSAP
mpfp
AFGMp50
monfilt
id2scaps
z525mdm
datasvr
DeviceScanner
VMAUDIO
mcmispupdmgr
ahcix86s
EIO_XP
NVNET
s117nd5
gameenum
lvpopflt
Defrag32b
ms_mpu401
mediaviewer
navapel
bcserver
oracleorahome90agent
cq_mem
curtainssyssvc
sffdisk
PCTINDIS5
keymaestro
pavdrv
DN2AKNET
SE2Bmgmt
FireHook
cqcpu
a8djusb
QPCapSvc
atitool
DKbFltr
SE2Dbus
LVVI500A
viairda
ssfs0509
swmsflt
SISNICXP
backupexecjobengine
odserv
nvstor32
nimdbgk
SunkFilt
npptnt2
MA8032M
SNPSTD3
brmfrmps
rdnaoflsvc
lvupdtio
hpqddsvc
netmnt
fsma
tvtfilter
USB11LDR
ipassconnectengine
AsuhfivrO
oracledbconsoleorcl
DniVad
citrixxteserver
purgeieservice
SprintRcAppSvc
USBCamera
UsbDiag
WinVd32
pwd_2K
avidstartup
MRESP50
WMIService
se45mdm
wlankeeper
prevxdriver
cvintdrv
netw4x32
wap3gx
n3900
wampmysqld
slpmonx
W55U01
avfilter
DM9102
uhcd
PhilCam8116
tosrfbnp
ppa3
cis1284
nvidesm
CTAUDFX.DLL
ehstart
siswlsvc
rtport
SE2Emgmt
sddmi2
cmigameport
sbiesvc
amdk77
PSDNServ
amusbprt
JiaoCap
apache
prfldsvc
websensedcagent
s217unic
NWSLP
EU3_USB
GT891x
WacomVKHid
nmap
vmm
mcp
nuvaud2
firesvc
TestHandler
dnsexit
BlueSoleilCS
se59obex
SQLAgent$MICROSOFTSMLBIZ
raidmsvr
npkcsvc
SWNC8U20
anbmservice
3dkeybd
CE3
digirefresh
USBAAPL
DgiVecp
ZSMC303
MSSQL$AUTODESKVAULT
ZY202_XP
dlbx_device
zebrmdfl
pdlnshay
scdemu
sentinelprotectionserver
w550mdfl
s3savagenb
bcm43xx
statusagent4
emitray
tng-dts
MA8032C
VAIOMediaPlatform-MusicServer-UPnP
usbser
DSDrv4
hidbatt
symlcbrd
rtl8187Se
iviaspi
WaveEnrollmentService
opcenum
cpqvcagent
pdfcreatormessages
LMouFilt
GoToAssist
dcfssvc
zebrmdmc
pnkbstrk
CVPND
CoolerXPDriver
RalinkRegistryWriter
ca-messagequeuing
Xyz777s
eamon
acrsch2svc
idsvc
OracleOraHome92ClientCache
61883
wlancfg
pav_service
k750bus
spkrmon
slee_81_service
RAPIProtocol
FreeTdi
NIPALK
dktknsrv
thinkpadmodemservice
cnmpar21
svv
personalsecuredriveservice
portmapper
hpwirelessmgr
mwstick
nsausvc
epgspooler
tmxpflt
RR2IOMod
WSIMD
mohfilt
emproxy
LVRS
fsaa
USBCCID
pdlnsv25
PGPwded
Intel_MIPMNMP
SfCtlCom
PCASp50
RIOUNIV
ptserial
tifm21
tfsnboio
ha10kx2k
adfs
hcmon
ipsecmon
oracleservicelocalora
incdpass
lxcj_device
AYDrvNT_ALYAC
WaveFDE
clmtomcatstartersvc
hwdatacard
oracle_load_balancer_60_client-forms6ip9
Via4in1
retrolauncher
aliadwdm
lvhidsvc
symproxysvc
sagefserver
etoksrv
dvd43llh
kavsvc
s217mgmt
sermouse
lirsgt
mclogmanagerservice
Blfp
SE2Cmgmt
harmony
ati2mtaa
Ndismeetro
PAR1284
exfat
zd1211u(zydas)
vpnva
nipsvc
wintabservice
arhidfltr
mcproxy
NWUSBModem
vrfwsvc
pnrouter
se59mgmt
lxdm_device
tbhsd
sympxsvc
iaantmon
tsp
WIBUKEY
dsncservice
HFACSVC
mirrorv3
PSSdk23
SE2Cbus
ssrvc
elnkservice
iaimtv3
usb_rndisx
FINEPIX_PCC
xfactorae1
P17xfi
ltck000c
sfcure01
lvuvc
sprtsvc_dellsupportcenter
houdiniserver
tng-dtmg
dimension4
smrt
Wbutton
bdfsfltr
oracle_load_balancer_60_server-forms6ip14
nvenetfd
dvd_2K
merakpop3
SPCtl
bdpredir
mvwebserver
eSettingsService
SNMP
BLKWGU(Belkin)
datasvr2
adminserver
AmdLLD
LC7981
bcm4sbxp
arkbcfltr
WimFltr
asp.net_2.0.50727
vxsvc
cqmghost
MSSQL$MSSMLBIZ
p17xfilt
vmware
CXTUNE
oracleorahomehttpserver
wkscfgsrv
tapvpn
As6frin
https-admserv61
rapapp
mssqlserver
toscosrv
Appn
bridgemp
s616mgmt
sigfilt
sonicstagemonitoring
om518p
tpkd
p17
mvserver
Epiusb
iaimfp4
TPPWRIF
ibmasrex
s616bus
nod32krn
USR1806V
qfcoresvc
SE27mdfl
deckzpsx
tosrfusb
cwafadminmonitor
W700obex
fix
avgascln
atfsd
LKbdFlt2
FGDSCSI
atitunep
nalntservice
yukonwlh
pdlndtdl
k750mdm
nsysaudm
U81xobex
VAIOMediaPlatform-MusicServer-HTTP
QPSched
KMW_USB
mcrdsvc
mrvw245
vetefile
pavagente
tangoservice
nfmservice
elbydelay
omniusb
ipahelper.exe
marvinbus
CTEAPSFX.DLL
agp440
umpusbxp
SGIR
ooclevercacheagent
pav_security
snareiis
MKEMUSB
BCMTPM
usbvm321
snare
procexp90
ARSVC
idebusdr
lbtserv
ATKFUSService
ati2mtag
L6POD
s125mdm
SaiNtSub
mcods
fasttrackinstallerservice
JiaoIO
pml
websensecommunicationagent
FTSER2K
PolarUSB
SE26mdm
z525mdfl
IntelC51
_iomega_active_disk_service_
rtl8185
USB_NDIS_51
cm102u32
emu10k1
dcpflics
avcgbdr
remoterecord
se2Bunic
jukebox3
syntp
zebrbus
ultra66
szserver
clsched
wampapache
cicsclient
vmodem
vds
DMICall
w300mdfl
fcprintservice
CA561
ksthunk
elbycdio
cpqfws2e
HssSrv
aolservice
XFX_program
roxmediadb
DXEC02
modemcsa
iisadmin
MtxDma0
FiltUSBEMPIA
SNMPTRAP
avgems
akshhl
w200obex
sonypvs1
UxTuneUp
hsfhwazl
w800mdfl
serialkeys
asmagent
SSHDRV61
tunmp
ctljystk
Ktp
GTPTSER
nvgts
NdisFilt
lvcomser
com4qlb
ma763004
oracle_load_balancer_60_client-forms6i
dkeysync
iaimfp0
emu10k
aclient
pmounter
inorpc
ctaud2k
pdiddcci
pcscnsrv
NWDNS
ATIVXSTW
ZuneWlanCfgSvc
se44bus
paamsrv
fsssvc
DCamUSBDXGTech
HECI
LVBulk
U81xmdm
mqdmbus
GT680x
meraksmtp
tdcmdpst
sgectl
magictuneengine
qcdonner
cicssfs.scmmc223
artourservice
XilinxPC4Driver
toshidpt
oracleoradb10g_home1isql*plus
PhilCam8116_XP
trcboot
avipbb
SimpTcp
TPECioCtl
WISTechVIDCAP
vaiomediaplatform-videoserver-appserver
psadd
mgisvr
Cam5603C
Xyz777b
akshasp
cmpci
SaiNtBus
MSFWHLPR
ANC
bdselfpr
axinstsv
SWUMX51
NxSysMon
vci
DumaNT
srtspx
tgsrvc_smartagent
wfxsvc
cfsvcs
iaimtv4
omci
ichaud
hcf_msft
apphostsvc
mcupdmgr.exe
wwsecsvc
senfilt
U81xmgmt
npkcrypt
KMW_SYS
IASJet
papyjoy
ctac32k
wmp54gsvc
a016mdm
prodrv06
mi-raysat_3dsmax9_32
IntelC53
rt2500usb
icraplus
BRGSp50
bc_filter
sndsrvc
ghaio
A88xEnc
hidir
3comtftp
cwcwdm
fcdabus
s117bus
wm
SQTECH905C
ssm_bus
vvdsvc
se44mgmt
se2Dunic
pilogsrv
n558
Shockprf
ROB_A
SE2Dmdfl
webrootspysweeperservice
SQLAgent$MICROSOFTBCM
phnxvcdservice
DritekPortIO
w200mdm
usbaudio
pfmodnt
sisnic
TuneUp.Defrag
ghostsec
InterBaseGuardian
YahooAUService
zebrsce
DFUBTUSB
adiusbaw
sqlagent$soshome22
s716mdm
wltwo51b
CTHWIUT.DLL
rimsptsk
s116obex
IPSECSHM
USBMN1X1
symsnap
lvckap
XTrapD12
ClntMgmt.sys
acdpowerservice
O2SCBUS
dpc_srv_webcast
addfiltr
tsdhd
freebsd
z525bus
s117unic
amdagp
mldserv
WUSB54GPV4SRV
CYGF32X
ELkbd
UMAXPCLS
egathdrv
nwdls
bltrust
AVCamUSB20
allegro
ALABULK
{95808DC4-FA4A-4c74-92FE-5B863F82066B}
dot4ufd
superproserver
vusbbus
vmauthdservice
NetPipeActivator
STV680m
AsDsm
dntus26
OsaFsLoc
rtl8023
avgcoresvc
ESDCR
quickbooksdb
UPATC
flashpnt
AdobeActiveFileMonitor6.0
LVCap138
pvservice
adaptecstoragemanageragent
spsslm
sscdbhk5
sbp2port
PD0620VID
iksysflt
srvdpi
twdns
L8042Kbd
atchksrv
elbycdfl
mfeavfk
tiumfwl
nmraapache
dlabmfsm
NPPTNT
wmp54gssvc
se26unic
gtndis5
VIAPFD
smartlinkservice
mfesmfk
sandrathesrv
driverhardwarev2
pinnaclemarvinusb
sit_prt
DcCam
se45mgmt
oraclewebassistant
msftpsvc
tmlisten
hidusb
CnxTrLan
nwlnkspx
eaps2kbd
Cap7134
sit_flt
s116bus
WINIO
USB_RNDIS
PTDCVsp
k56
hap16v2k
mfebopk
filechecker
houdinilicenseserver
F700imd
ATSWPDRV
Ptserlp
TUWinStylerThemeSvc
vzupsvc
HpqRemHid
mysql
WmUsbHid
kraidsvc
mskservice
vzfw
ibmcicstransactiongateway
ativraxx
bhmonitorservice
usnsvc
Subsonic
ARCSOFTVIRTUALCAPTURE
openvpnservice
AMDPCI
pivot
NVXBAR
risdptsk
MA_CMIDI
TClass2k
wlancig
mstdfrgs
nnsvc
nvstor64
pctavsvc
EACSvrMngr
aniwzcsdservice
NCPro
psdvdisk
wanusb
atimpab
avgntflt
CX88AUD
SNTIE
aksusb
atikmdag
mwssched
ccevtmgr
ATWPKT2
acrotray
ZTEusbmdm6k
winmtsrv
s616unic
se27unic
ss_bus
ptbsync
defragfs
rsvchost
HpqKbFiltr
v124
avgtdi
vhidmini
axskbus
carboncopyscheduler
p2psvc
p1110vid
diskeeper
cdr4_2k
PDExchange
cwcpsvc20
elaunidr
nchssvad
netrcacm
utilman
lmab_device
roxliveshare
tnbrlds
CADlink
eskerlicensecontrol
btserial
NWDHCP
ds1
hSONYPVh
ovmsmaccessmanager
STV680
W700mdfl
yukonwxp
mcdetect.exe
Nsynas32
beatjamupnpmusicserver
epson_pm_rpcv4_01
osanbm
roxliveshare9
BrUsbSer
ilicensesvc
sdcoreservice
licensemanagersocket
nhcDriverDevice
sisidex
rtl8029
dsproct
bt
teefer2
se58obex
SE2Cmdfl
slabbus
iPassP
hf30service
DSXUSB
lpds
HabuFltr
vstor2
MTDVC2_ENUM
winpowerrmi
oracleorahome811cmadmin
IBM_LLC2
aegisp
lxda_device
nwlnknb
db2remotecmd
ccproxy
smserial
pclepci
TMHIDSRV
navex15
CrystalSysInfo
aswlsvc
CTEXFIFX.DLL
wmconnectcds
SE26mgmt
sp_clamsrv
mdc8021x
rimmptsk
acedrv05
DSI_SiUSBXp_3_1
UsbserFilt
nscservice
db2ntsecserver
icam4usb
bthmodem
VC6SecS
PBADRV
rksample
WUSB54Gv4SVC
Wpsnuio
streamip
abnetmon
niorbk
cusrvc
DC21x4
bcftdi
M2500
PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 00:40]
.
2012-10-16 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2011-08-24 04:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://cnn.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
TCP: DhcpNameServer = 192.168.2.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
HKLM-Run-ROC_roc_dec12 - c:\program files\AVG Secure Search\ROC_roc_dec12.exe
HKLM-Run-HF_G_Jul - c:\program files\AVG Secure Search\HF_G_Jul.exe
Notify-NecUsb3Sevices - USB3Sw32.dll
Notify-USB3Sw32 - USB3Sw32.dll
SafeBoot-WinDefend
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-16 16:29
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(760)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\windows\eHome\ehRecvr.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\windows\eHome\ehSched.exe
c:\windows\eHome\ehRec.exe
c:\windows\eHome\ehRec.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wscntfy.exe
c:\windows\eHome\ehmsas.exe
c:\windows\eHome\ehRec.exe
c:\windows\eHome\ehRec.exe
.
**************************************************************************
.
Completion time: 2012-10-16 16:32:02 - machine was rebooted
ComboFix-quarantined-files.txt 2012-10-16 23:31
.
Pre-Run: 171,413,438,464 bytes free
Post-Run: 172,959,272,960 bytes free
.
- - End Of File - - F2726F4CE04547CAA64FF668592E2031





TDSSSKiller Log:
15:57:58.0218 1848 TDSS rootkit removing tool [removed] Oct 12 2012 17:26:47
15:57:58.0859 1848 ============================================================
15:57:58.0859 1848 Current date / time: 2012/10/16 15:57:58.0859
15:57:58.0859 1848 SystemInfo:
15:57:58.0859 1848
15:57:58.0859 1848 OS Version: 5.1.2600 ServicePack: 3.0
15:57:58.0859 1848 Product type: Workstation
15:57:58.0859 1848 ComputerName: FERGUSONHOME
15:57:58.0859 1848 UserName: HP_Administrator
15:57:58.0859 1848 Windows directory: C:\WINDOWS
15:57:58.0859 1848 System windows directory: C:\WINDOWS
15:57:58.0859 1848 Processor architecture: Intel x86
15:57:58.0859 1848 Number of processors: 1
15:57:58.0859 1848 Page size: 0x1000
15:57:58.0859 1848 Boot type: Normal boot
15:57:58.0859 1848 ============================================================
15:58:03.0984 1848 Drive \Device\Harddisk0\DR0 - Size: 0x2E93E36000 (186.31 Gb), SectorSize: 0x200, Cylinders: 0x64F1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000054
15:58:04.0109 1848 ============================================================
15:58:04.0109 1848 \Device\Harddisk0\DR0:
15:58:04.0109 1848 MBR partitions:
15:58:04.0109 1848 \Device\Harddisk0\DR0\Partition1: MBR, Type 0xC, StartLBA 0x3F, BlocksNum 0x1005231
15:58:04.0109 1848 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1005270, BlocksNum 0x16494C90
15:58:04.0109 1848 ============================================================
15:58:04.0265 1848 C: <-> \Device\Harddisk0\DR0\Partition2
15:58:04.0265 1848 D: <-> \Device\Harddisk0\DR0\Partition1
15:58:04.0265 1848 ============================================================
15:58:04.0265 1848 Initialize success
15:58:04.0265 1848 ============================================================
15:58:56.0375 5656 ============================================================
15:58:56.0375 5656 Scan started
15:58:56.0375 5656 Mode: Manual;
15:58:56.0375 5656 ============================================================
15:58:59.0296 5656 ================ Scan system memory ========================
15:58:59.0296 5656 System memory - ok
15:58:59.0296 5656 ================ Scan services =============================
15:58:59.0437 5656 3comtftp - ok
15:58:59.0453 5656 3dkeybd - ok
15:58:59.0453 5656 61883 - ok
15:58:59.0468 5656 a016mdm - ok
15:58:59.0468 5656 A88xEnc - ok
15:58:59.0484 5656 a8djusb - ok
15:58:59.0515 5656 Abiosdsk - ok
15:58:59.0531 5656 abnetmon - ok
15:58:59.0546 5656 abp480n5 - ok
15:58:59.0546 5656 acdpowerservice - ok
15:58:59.0562 5656 acedrv05 - ok
15:58:59.0578 5656 aclient - ok
15:58:59.0578 5656 acmservice - ok
15:58:59.0625 5656 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
15:58:59.0640 5656 ACPI - ok
15:58:59.0671 5656 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
15:58:59.0671 5656 ACPIEC - ok
15:58:59.0687 5656 acrotray - ok
15:58:59.0687 5656 acrsch2svc - ok
15:58:59.0703 5656 adaptecstoragemanageragent - ok
15:58:59.0718 5656 addfiltr - ok
15:58:59.0718 5656 adfs - ok
15:58:59.0734 5656 adihdaudaddservice - ok
15:58:59.0750 5656 adiusbaw - ok
15:58:59.0765 5656 adminserver - ok
15:58:59.0765 5656 AdobeActiveFileMonitor6.0 - ok
15:58:59.0843 5656 [ E12CFCF1DDBFC50948A75E6E38793225 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
15:58:59.0859 5656 AdobeFlashPlayerUpdateSvc - ok
15:58:59.0859 5656 adpu160m - ok
15:58:59.0875 5656 aeaudio - ok
15:58:59.0921 5656 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
15:58:59.0921 5656 aec - ok
15:58:59.0937 5656 aegisp - ok
15:59:00.0000 5656 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
15:59:00.0015 5656 AFD - ok
15:59:00.0015 5656 AFGMp50 - ok
15:59:00.0031 5656 agp440 - ok
15:59:00.0046 5656 Aha154x - ok
15:59:00.0046 5656 ahcix86s - ok
15:59:00.0062 5656 aic78u2 - ok
15:59:00.0062 5656 aic78xx - ok
15:59:00.0078 5656 akshasp - ok
15:59:00.0093 5656 akshhl - ok
15:59:00.0093 5656 aksusb - ok
15:59:00.0109 5656 ALABULK - ok
15:59:00.0156 5656 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
15:59:00.0156 5656 Alerter - ok
15:59:00.0187 5656 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe
15:59:00.0187 5656 ALG - ok
15:59:00.0203 5656 aliadwdm - ok
15:59:00.0203 5656 AliIde - ok
15:59:00.0218 5656 allegro - ok
15:59:00.0234 5656 amdagp - ok
15:59:00.0234 5656 amdk77 - ok
15:59:00.0250 5656 AmdLLD - ok
15:59:00.0265 5656 AMDPCI - ok
15:59:00.0265 5656 amsint - ok
15:59:00.0281 5656 amusbprt - ok
15:59:00.0296 5656 anbmservice - ok
15:59:00.0296 5656 ANC - ok
15:59:00.0312 5656 aniwzcsdservice - ok
15:59:00.0312 5656 aolservice - ok
15:59:00.0328 5656 apache - ok
15:59:00.0343 5656 apphostsvc - ok
15:59:00.0390 5656 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
15:59:00.0406 5656 AppMgmt - ok
15:59:00.0406 5656 Appn - ok
15:59:00.0421 5656 ARCSOFTVIRTUALCAPTURE - ok
15:59:00.0437 5656 arhidfltr - ok
15:59:00.0453 5656 arkbcfltr - ok
15:59:00.0484 5656 [ B5B8A80875C1DEDEDA8B02765642C32F ] Arp1394 C:\WINDOWS\system32\DRIVERS\arp1394.sys
15:59:00.0484 5656 Arp1394 - ok
15:59:00.0500 5656 ARSVC - ok
15:59:00.0500 5656 artourservice - ok
15:59:00.0515 5656 As6frin - ok
15:59:00.0515 5656 asc - ok
15:59:00.0531 5656 asc3350p - ok
15:59:00.0546 5656 asc3550 - ok
15:59:00.0546 5656 AsDsm - ok
15:59:00.0562 5656 asmagent - ok
15:59:00.0578 5656 asp.net_2.0.50727 - ok
15:59:00.0687 5656 [ E1A1206A4FB19B675E947B29CCD25FBA ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
15:59:00.0687 5656 aspnet_state - ok
15:59:00.0703 5656 AsuhfivrO - ok
15:59:00.0703 5656 aswlsvc - ok
15:59:00.0765 5656 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
15:59:00.0765 5656 AsyncMac - ok
15:59:00.0796 5656 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
15:59:00.0796 5656 atapi - ok
15:59:00.0812 5656 atchksrv - ok
15:59:00.0812 5656 Atdisk - ok
15:59:00.0828 5656 atfsd - ok
15:59:00.0843 5656 ati2mtaa - ok
15:59:00.0843 5656 ati2mtag - ok
15:59:00.0859 5656 AtiHdmiService - ok
15:59:00.0859 5656 atikmdag - ok
15:59:00.0875 5656 atimpab - ok
15:59:00.0890 5656 atinevxx - ok
15:59:00.0890 5656 atitool - ok
15:59:00.0906 5656 atitunep - ok
15:59:00.0921 5656 ativraxx - ok
15:59:00.0921 5656 ATIVXSTW - ok
15:59:00.0937 5656 ATKFUSService - ok
15:59:00.0968 5656 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
15:59:00.0968 5656 Atmarpc - ok
15:59:00.0968 5656 ATSWPDRV - ok
15:59:00.0984 5656 ATWPKT2 - ok
15:59:01.0046 5656 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
15:59:01.0046 5656 AudioSrv - ok
15:59:01.0109 5656 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
15:59:01.0109 5656 audstub - ok
15:59:01.0125 5656 AVCamUSB20 - ok
15:59:01.0125 5656 avcgbdr - ok
15:59:01.0140 5656 avfilter - ok
15:59:01.0343 5656 [ EE651D98B03FE3C075CCC58AB61C9287 ] AVG Security Toolbar Service C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe
15:59:01.0437 5656 AVG Security Toolbar Service - ok
15:59:01.0437 5656 avgascln - ok
15:59:01.0500 5656 [ 9C454CD857B4C0CCF7A614B047616503 ] avgcoresvc C:\WINDOWS\system32\SimpTcp.dll
15:59:01.0531 5656 avgcoresvc - ok
15:59:01.0546 5656 avgems - ok
15:59:01.0578 5656 [ 8BE661C16FBF84A73BCEC84B6B4A9DB5 ] Avgfwdx C:\WINDOWS\system32\DRIVERS\avgfwdx.sys
15:59:01.0578 5656 Avgfwdx - ok
15:59:01.0593 5656 [ 8BE661C16FBF84A73BCEC84B6B4A9DB5 ] Avgfwfd C:\WINDOWS\system32\DRIVERS\avgfwdx.sys
15:59:01.0593 5656 Avgfwfd - ok
15:59:01.0734 5656 [ BD5D11CEDBCDE4FA97D2387E7069B1FF ] avgfws C:\Program Files\AVG\AVG2012\avgfws.exe
15:59:01.0796 5656 avgfws - ok
15:59:02.0265 5656 [ D67719BCFDE5798F5C30D14EFED3BCAF ] AVGIDSAgent C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
15:59:02.0562 5656 AVGIDSAgent - ok
15:59:02.0609 5656 [ 1074F787080068C71303B61FAE7E7CA4 ] AVGIDSDriver C:\WINDOWS\system32\DRIVERS\avgidsdriverx.sys
15:59:02.0609 5656 AVGIDSDriver - ok
15:59:02.0640 5656 [ 61A7E0B02F82CFF3DB2445BBE50B3589 ] AVGIDSFilter C:\WINDOWS\system32\DRIVERS\avgidsfilterx.sys
15:59:02.0640 5656 AVGIDSFilter - ok
15:59:02.0671 5656 [ D63D83659EEDF60B3A3E620281A888E5 ] AVGIDSHX C:\WINDOWS\system32\DRIVERS\avgidshx.sys
15:59:02.0671 5656 AVGIDSHX - ok
15:59:02.0687 5656 [ BAF975B72062F53D327788E99D64197E ] AVGIDSShim C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys
15:59:02.0687 5656 AVGIDSShim - ok
15:59:02.0734 5656 [ DDA6A2A18841E4C9172BB85958B8D948 ] Avgldx86 C:\WINDOWS\system32\DRIVERS\avgldx86.sys
15:59:02.0750 5656 Avgldx86 - ok
15:59:02.0796 5656 [ CCDD61545AAEA265977E4B1EFDC74E8C ] Avgmfx86 C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
15:59:02.0796 5656 Avgmfx86 - ok
15:59:02.0812 5656 avgntflt - ok
15:59:02.0828 5656 [ 1FD90B28D2C3100BF4500199C8AD6358 ] Avgrkx86 C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
15:59:02.0828 5656 Avgrkx86 - ok
15:59:02.0843 5656 avgtdi - ok
15:59:02.0875 5656 [ 1263F2554ACE925C237A40B4C568D815 ] Avgtdix C:\WINDOWS\system32\DRIVERS\avgtdix.sys
15:59:02.0906 5656 Avgtdix - ok
15:59:02.0937 5656 [ EA1145DEBCD508FD25BD1E95C4346929 ] avgwd C:\Program Files\AVG\AVG2012\avgwdsvc.exe
15:59:02.0937 5656 avgwd - ok
15:59:02.0953 5656 avidstartup - ok
15:59:02.0968 5656 avipbb - ok
15:59:02.0968 5656 avsvcmonitor - ok
15:59:02.0984 5656 axinstsv - ok
15:59:03.0000 5656 axskbus - ok
15:59:03.0000 5656 AYDrvNT_ALYAC - ok
15:59:03.0015 5656 backupexecjobengine - ok
15:59:03.0062 5656 [ 7270D070173B20AC9487EA16BB08B45F ] bb-run C:\WINDOWS\system32\DRIVERS\bb-run.sys
15:59:03.0062 5656 bb-run - ok
15:59:03.0078 5656 bcftdi - ok
15:59:03.0078 5656 bcm43xx - ok
15:59:03.0093 5656 bcm4sbxp - ok
15:59:03.0109 5656 BCMTPM - ok
15:59:03.0109 5656 bcserver - ok
15:59:03.0125 5656 bc_filter - ok
15:59:03.0140 5656 bdfsfltr - ok
15:59:03.0140 5656 bdpredir - ok
15:59:03.0156 5656 bdselfpr - ok
15:59:03.0156 5656 beatjamupnpmusicserver - ok
15:59:03.0171 5656 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
15:59:03.0171 5656 Beep - ok
15:59:03.0187 5656 bhmonitorservice - ok
15:59:03.0203 5656 Blfp - ok
15:59:03.0203 5656 BLKWGU(Belkin) - ok
15:59:03.0218 5656 bltrust - ok
15:59:03.0234 5656 BlueSoleilCS - ok
15:59:03.0234 5656 BRGSp50 - ok
15:59:03.0250 5656 bridgemp - ok
15:59:03.0250 5656 brmfrmps - ok
15:59:03.0296 5656 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll
15:59:03.0296 5656 Browser - ok
15:59:03.0312 5656 BrUsbSer - ok
15:59:03.0312 5656 bt - ok
15:59:03.0328 5656 bthmodem - ok
15:59:03.0343 5656 btserial - ok
15:59:03.0343 5656 btwdndis - ok
15:59:03.0359 5656 ca-messagequeuing - ok
15:59:03.0359 5656 CA561 - ok
15:59:03.0375 5656 CADlink - ok
15:59:03.0390 5656 Cam5603C - ok
15:59:03.0390 5656 Cam5607 - ok
15:59:03.0406 5656 Cap7134 - ok
15:59:03.0421 5656 carboncopyscheduler - ok
15:59:03.0437 5656 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
15:59:03.0437 5656 cbidf2k - ok
15:59:03.0453 5656 ccevtmgr - ok
15:59:03.0468 5656 ccproxy - ok
15:59:03.0468 5656 cd20xrnt - ok
15:59:03.0484 5656 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
15:59:03.0484 5656 Cdaudio - ok
15:59:03.0531 5656 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
15:59:03.0531 5656 Cdfs - ok
15:59:03.0546 5656 cdr4_2k - ok
15:59:03.0562 5656 [ DBD9C3653C24F5003DBCE78270745B94 ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
15:59:03.0562 5656 Cdrom ( Virus.Win32.ZAccess.k ) - infected
15:59:03.0562 5656 Cdrom - detected Virus.Win32.ZAccess.k (0)
15:59:03.0578 5656 CE3 - ok
15:59:03.0578 5656 cfsvcs - ok
15:59:03.0593 5656 Changer - ok
15:59:03.0609 5656 cicsclient - ok
15:59:03.0609 5656 cicssfs.scmmc223 - ok
15:59:03.0625 5656 cis1284 - ok
15:59:03.0687 5656 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe
15:59:03.0687 5656 CiSvc - ok
15:59:03.0687 5656 citrixxteserver - ok
15:59:03.0703 5656 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
15:59:03.0703 5656 ClipSrv - ok
15:59:03.0718 5656 clmtomcatstartersvc - ok
15:59:03.0734 5656 clsched - ok
15:59:03.0734 5656 cm102u32 - ok
15:59:03.0750 5656 CmdIde - ok
15:59:03.0765 5656 cmigameport - ok
15:59:03.0765 5656 cmpci - ok
15:59:03.0781 5656 cnmpar21 - ok
15:59:03.0796 5656 CnxTrLan - ok
15:59:03.0796 5656 com4qlb - ok
15:59:03.0812 5656 COMSysApp - ok
15:59:03.0828 5656 CoolerXPDriver - ok
15:59:03.0843 5656 Cpqarray - ok
15:59:03.0859 5656 cpqfws2e - ok
15:59:03.0875 5656 cpqvcagent - ok
15:59:03.0875 5656 cqcpu - ok
15:59:03.0890 5656 cqmghost - ok
15:59:03.0906 5656 cq_mem - ok
15:59:03.0937 5656 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
15:59:03.0937 5656 CryptSvc - ok
15:59:03.0937 5656 CrystalSysInfo - ok
15:59:03.0953 5656 ctac32k - ok
15:59:03.0968 5656 ctaud2k - ok
15:59:03.0968 5656 CTAUDFX.DLL - ok
15:59:03.0984 5656 CTEAPSFX.DLL - ok
15:59:04.0000 5656 CTEXFIFX.DLL - ok
15:59:04.0000 5656 CTHWIUT.DLL - ok
15:59:04.0015 5656 ctljystk - ok
15:59:04.0031 5656 curtainssyssvc - ok
15:59:04.0031 5656 cusrvc - ok
15:59:04.0046 5656 cvintdrv - ok
15:59:04.0062 5656 CVPND - ok
15:59:04.0062 5656 cwafadminmonitor - ok
15:59:04.0078 5656 cwcpsvc20 - ok
15:59:04.0093 5656 cwcwdm - ok
15:59:04.0093 5656 CX88AUD - ok
15:59:04.0109 5656 CXTUNE - ok
15:59:04.0125 5656 CYGF32X - ok
15:59:04.0125 5656 dac2w2k - ok
15:59:04.0140 5656 dac960nt - ok
15:59:04.0156 5656 datasvr - ok
15:59:04.0156 5656 datasvr2 - ok
15:59:04.0171 5656 db2ntsecserver - ok
15:59:04.0187 5656 db2remotecmd - ok
15:59:04.0187 5656 DC21x4 - ok
15:59:04.0203 5656 DCamUSBDXGTech - ok
15:59:04.0218 5656 DcCam - ok
15:59:04.0218 5656 dcfssvc - ok
15:59:04.0281 5656 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
15:59:04.0296 5656 DcomLaunch - ok
15:59:04.0312 5656 dcpflics - ok
15:59:04.0312 5656 deckzpsx - ok
15:59:04.0328 5656 Defrag32b - ok
15:59:04.0328 5656 defragfs - ok
15:59:04.0343 5656 DELL_A02 - ok
15:59:04.0359 5656 DeviceScanner - ok
15:59:04.0359 5656 DFUBTUSB - ok
15:59:04.0375 5656 DgiVecp - ok
15:59:04.0437 5656 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
15:59:04.0437 5656 Dhcp - ok
15:59:04.0453 5656 digirefresh - ok
15:59:04.0468 5656 digitizer - ok
15:59:04.0468 5656 dimension4 - ok
15:59:04.0500 5656 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
15:59:04.0500 5656 Disk - ok
15:59:04.0515 5656 diskeeper - ok
15:59:04.0515 5656 DKbFltr - ok
15:59:04.0531 5656 dkeysync - ok
15:59:04.0546 5656 dktknsrv - ok
15:59:04.0546 5656 dlabmfsm - ok
15:59:04.0562 5656 dlaopiom - ok
15:59:04.0578 5656 dlbx_device - ok
15:59:04.0578 5656 DM9102 - ok
15:59:04.0593 5656 dmadmin - ok
15:59:04.0625 5656 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
15:59:04.0656 5656 dmboot - ok
15:59:04.0671 5656 DMICall - ok
15:59:04.0703 5656 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys
15:59:04.0703 5656 dmio - ok
15:59:04.0718 5656 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
15:59:04.0718 5656 dmload - ok
15:59:04.0765 5656 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll
15:59:04.0765 5656 dmserver - ok
15:59:04.0781 5656 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
15:59:04.0781 5656 DMusic - ok
15:59:04.0796 5656 DN2AKNET - ok
15:59:04.0812 5656 DniVad - ok
15:59:04.0875 5656 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
15:59:04.0875 5656 Dnscache - ok
15:59:04.0890 5656 dnsexit - ok
15:59:04.0906 5656 dntus26 - ok
15:59:04.0968 5656 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
15:59:04.0968 5656 Dot3svc - ok
15:59:04.0984 5656 dot4ufd - ok
15:59:05.0000 5656 dpc_srv_webcast - ok
15:59:05.0000 5656 dpti2o - ok
15:59:05.0015 5656 DritekPortIO - ok
15:59:05.0031 5656 driverhardwarev2 - ok
15:59:05.0031 5656 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
15:59:05.0031 5656 drmkaud - ok
15:59:05.0046 5656 ds1 - ok
15:59:05.0062 5656 DSDrv4 - ok
15:59:05.0062 5656 DSI_SiUSBXp_3_1 - ok
15:59:05.0078 5656 dsncservice - ok
15:59:05.0093 5656 dsproct - ok
15:59:05.0093 5656 DSXUSB - ok
15:59:05.0109 5656 DumaNT - ok
15:59:05.0125 5656 dvd-ram_service - ok
15:59:05.0125 5656 dvd43llh - ok
15:59:05.0140 5656 dvd_2K - ok
15:59:05.0156 5656 DXEC02 - ok
15:59:05.0156 5656 EACSvrMngr - ok
15:59:05.0171 5656 eamon - ok
15:59:05.0203 5656 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll
15:59:05.0203 5656 EapHost - ok
15:59:05.0218 5656 eaps2kbd - ok
15:59:05.0234 5656 egathdrv - ok
15:59:05.0296 5656 [ 63F371F0248E3732A4821F86E6D0E370 ] ehRecvr C:\WINDOWS\eHome\ehRecvr.exe
15:59:05.0296 5656 ehRecvr - ok
15:59:05.0312 5656 [ 16910F8B482919BB6035ED053B691692 ] ehSched C:\WINDOWS\eHome\ehSched.exe
15:59:05.0312 5656 ehSched - ok
15:59:05.0328 5656 ehstart - ok
15:59:05.0343 5656 EIO_XP - ok
15:59:05.0343 5656 elaunidr - ok
15:59:05.0359 5656 elbycdfl - ok
15:59:05.0375 5656 elbycdio - ok
15:59:05.0375 5656 elbydelay - ok
15:59:05.0390 5656 ELkbd - ok
15:59:05.0406 5656 elnkservice - ok
15:59:05.0421 5656 emitray - ok
15:59:05.0421 5656 emproxy - ok
15:59:05.0437 5656 emu10k - ok
15:59:05.0453 5656 emu10k1 - ok
15:59:05.0453 5656 epgspooler - ok
15:59:05.0468 5656 Epiusb - ok
15:59:05.0484 5656 epsonstatusagent2 - ok
15:59:05.0484 5656 epson_pm_rpcv4_01 - ok
15:59:05.0562 5656 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll
15:59:05.0562 5656 ERSvc - ok
15:59:05.0562 5656 ESDCR - ok
15:59:05.0578 5656 eSettingsService - ok
15:59:05.0593 5656 eskerlicensecontrol - ok
15:59:05.0593 5656 etoksrv - ok
15:59:05.0609 5656 EU3_USB - ok
15:59:05.0671 5656 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe
15:59:05.0687 5656 Eventlog - ok
15:59:05.0750 5656 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll
15:59:05.0781 5656 EventSystem - ok
15:59:05.0781 5656 exfat - ok
15:59:05.0796 5656 F700imd - ok
15:59:05.0859 5656 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
15:59:05.0875 5656 Fastfat - ok
15:59:05.0875 5656 fasttrackinstallerservice - ok
15:59:05.0937 5656 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
15:59:05.0953 5656 FastUserSwitchingCompatibility - ok
15:59:06.0046 5656 [ E97D6A8684466DF94FF3BC24FB787A07 ] Fax C:\WINDOWS\system32\fxssvc.exe
15:59:06.0109 5656 Fax - ok
15:59:06.0125 5656 fcdabus - ok
15:59:06.0125 5656 fcprintservice - ok
15:59:06.0171 5656 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
15:59:06.0171 5656 Fdc - ok
15:59:06.0171 5656 FGDSCSI - ok
15:59:06.0187 5656 filechecker - ok
15:59:06.0203 5656 FiltUSBEMPIA - ok
15:59:06.0218 5656 FINEPIX_PCC - ok
15:59:06.0250 5656 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
15:59:06.0250 5656 Fips - ok
15:59:06.0250 5656 FireHook - ok
15:59:06.0265 5656 firesvc - ok
15:59:06.0281 5656 fix - ok
15:59:06.0296 5656 flashpnt - ok
15:59:06.0328 5656 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
15:59:06.0328 5656 Flpydisk - ok
15:59:06.0375 5656 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
15:59:06.0390 5656 FltMgr - ok
15:59:06.0390 5656 freebsd - ok
15:59:06.0406 5656 FreeTdi - ok
15:59:06.0421 5656 fsaa - ok
15:59:06.0421 5656 fsks - ok
15:59:06.0437 5656 fsma - ok
15:59:06.0453 5656 fsssvc - ok
15:59:06.0515 5656 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
15:59:06.0515 5656 Fs_Rec - ok
15:59:06.0531 5656 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
15:59:06.0531 5656 Ftdisk - ok
15:59:06.0531 5656 [ 92E8443C7BF5C0137671CDE080655DFC ] ftsata2 C:\WINDOWS\system32\DRIVERS\ftsata2.sys
15:59:06.0546 5656 ftsata2 - ok
15:59:06.0546 5656 FTSER2K - ok
15:59:06.0562 5656 gameenum - ok
15:59:06.0578 5656 [ 6F55305289A0765BD8AE8E8D32F17117 ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
15:59:06.0578 5656 GEARAspiWDM - ok
15:59:06.0593 5656 ghaio - ok
15:59:06.0593 5656 ghostsec - ok
15:59:06.0609 5656 GoToAssist - ok
15:59:06.0640 5656 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
15:59:06.0640 5656 Gpc - ok
15:59:06.0656 5656 GT891x - ok
15:59:06.0671 5656 gtndis5 - ok
15:59:06.0671 5656 GTPTSER - ok
15:59:06.0687 5656 ha10kx2k - ok
15:59:06.0703 5656 HabuFltr - ok
15:59:06.0703 5656 hap16v2k - ok
15:59:06.0718 5656 harmony - ok
15:59:06.0734 5656 hcf_msft - ok
15:59:06.0750 5656 hcmon - ok
15:59:06.0781 5656 [ 2A013E7530BEAB6E569FAA83F517E836 ] HdAudAddService C:\WINDOWS\system32\drivers\HdAudio.sys
15:59:06.0796 5656 HdAudAddService - ok
15:59:06.0812 5656 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
15:59:06.0828 5656 HDAudBus - ok
15:59:06.0843 5656 HECI - ok
15:59:06.0953 5656 helpsvc - ok
15:59:06.0968 5656 hf30service - ok
15:59:06.0984 5656 HFACSVC - ok
15:59:07.0000 5656 hidbatt - ok
15:59:07.0015 5656 hidir - ok
15:59:07.0015 5656 HidServ - ok
15:59:07.0031 5656 hidusb - ok
15:59:07.0093 5656 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
15:59:07.0093 5656 hkmsvc - ok
15:59:07.0109 5656 houdinilicenseserver - ok
15:59:07.0125 5656 houdiniserver - ok
15:59:07.0125 5656 hpn - ok
15:59:07.0140 5656 HpqKbFiltr - ok
15:59:07.0156 5656 HpqRemHid - ok
15:59:07.0171 5656 hpqwmi - ok
15:59:07.0171 5656 hpwirelessmgr - ok
15:59:07.0218 5656 [ 9F1D80908658EB7F1BF70809E0B51470 ] HPZid412 C:\WINDOWS\system32\DRIVERS\HPZid412.sys
15:59:07.0218 5656 HPZid412 - ok
15:59:07.0250 5656 [ F7E3E9D50F9CD3DE28085A8FDAA0A1C3 ] HPZipr12 C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
15:59:07.0250 5656 HPZipr12 - ok
15:59:07.0281 5656 [ CF1B7951B4EC8D13F3C93B74BB2B461B ] HPZius12 C:\WINDOWS\system32\DRIVERS\HPZius12.sys
15:59:07.0281 5656 HPZius12 - ok
15:59:07.0281 5656 hsfhwazl - ok
15:59:07.0343 5656 [ 5DF616ADDB75C1AD36C1F9E4DE0F7654 ] HSFHWBS2 C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys
15:59:07.0343 5656 HSFHWBS2 - ok
15:59:07.0375 5656 [ DFA8F86C0DBCA7DB948043AA3BE6793B ] HSF_DP C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
15:59:07.0406 5656 HSF_DP - ok
15:59:07.0421 5656 hSONYPVh - ok
15:59:07.0437 5656 HssSrv - ok
15:59:07.0437 5656 HssTrayService - ok
15:59:07.0515 5656 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
15:59:07.0515 5656 HTTP - ok
15:59:07.0562 5656 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
15:59:07.0578 5656 HTTPFilter - ok
15:59:07.0593 5656 https-admserv61 - ok
15:59:07.0609 5656 hwdatacard - ok
15:59:07.0625 5656 i2omgmt - ok
15:59:07.0625 5656 i2omp - ok
15:59:07.0640 5656 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
15:59:07.0640 5656 i8042prt - ok
15:59:07.0656 5656 iaantmon - ok
15:59:07.0671 5656 iaimfp0 - ok
15:59:07.0671 5656 iaimfp4 - ok
15:59:07.0687 5656 iaimtv3 - ok
15:59:07.0703 5656 iaimtv4 - ok
15:59:07.0718 5656 iAimTV5 - ok
15:59:07.0781 5656 [ 4007984827E19E6A5B6FAF8532EAEFBA ] ialm C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
15:59:07.0828 5656 ialm - ok
15:59:07.0828 5656 IASJet - ok
15:59:07.0875 5656 [ 79AE2A97C120F282845D854D0F070EA9 ] iaStor C:\WINDOWS\system32\DRIVERS\iaStor.sys
15:59:07.0890 5656 iaStor - ok
15:59:07.0906 5656 ibmasrex - ok
15:59:07.0921 5656 ibmcicstransactiongateway - ok
15:59:07.0937 5656 IBM_LLC2 - ok
15:59:07.0937 5656 icam4usb - ok
15:59:07.0953 5656 ichaud - ok
15:59:07.0968 5656 icraplus - ok
15:59:07.0984 5656 id2scaps - ok
15:59:08.0000 5656 idebusdr - ok
15:59:08.0125 5656 [ 6F95324909B502E2651442C1548AB12F ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
15:59:08.0140 5656 IDriverT - ok
15:59:08.0156 5656 idsvc - ok
15:59:08.0171 5656 iisadmin - ok
15:59:08.0171 5656 iksysflt - ok
15:59:08.0187 5656 ilicensesvc - ok
15:59:08.0250 5656 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
15:59:08.0250 5656 Imapi - ok
15:59:08.0312 5656 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe
15:59:08.0312 5656 ImapiService - ok
15:59:08.0328 5656 incdpass - ok
15:59:08.0343 5656 ini910u - ok
15:59:08.0359 5656 inorpc - ok
15:59:08.0515 5656 [ D87FFA95D630EC8D1482CA25C454846A ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys
15:59:08.0593 5656 IntcAzAudAddService - ok
15:59:08.0609 5656 IntelC51 - ok
15:59:08.0625 5656 IntelC53 - ok
15:59:08.0640 5656 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys
15:59:08.0640 5656 IntelIde - ok
15:59:08.0656 5656 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
15:59:08.0656 5656 intelppm - ok
15:59:08.0671 5656 Intel_MIPMNMP - ok
15:59:08.0687 5656 InterBaseGuardian - ok
15:59:08.0718 5656 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys
15:59:08.0718 5656 Ip6Fw - ok
15:59:08.0718 5656 ipahelper.exe - ok
15:59:08.0734 5656 ipassconnectengine - ok
15:59:08.0750 5656 iPassP - ok
15:59:08.0765 5656 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
15:59:08.0781 5656 IpFilterDriver - ok
15:59:08.0796 5656 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
15:59:08.0796 5656 IpInIp - ok
15:59:08.0843 5656 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
15:59:08.0843 5656 IpNat - ok
15:59:08.0906 5656 [ 50F2E042C33ED8D11264BE5C4D533C7F ] iPodService C:\Program Files\iPod\bin\iPodService.exe
15:59:08.0937 5656 iPodService - ok
15:59:09.0000 5656 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
15:59:09.0000 5656 IPSec - ok
15:59:09.0015 5656 ipsecmon - ok
15:59:09.0031 5656 IPSECSHM - ok
15:59:09.0062 5656 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
15:59:09.0062 5656 IRENUM - ok
15:59:09.0093 5656 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
15:59:09.0093 5656 isapnp - ok
15:59:09.0109 5656 iviaspi - ok
15:59:09.0171 5656 [ E731921DB2E17DCD3DB472FAD5549C57 ] JavaQuickStarterService C:\Program Files\Java\jre6\bin\jqs.exe
15:59:09.0187 5656 JavaQuickStarterService - ok
15:59:09.0187 5656 JiaoCap - ok
15:59:09.0203 5656 JiaoIO - ok
15:59:09.0218 5656 jukebox3 - ok
15:59:09.0234 5656 k56 - ok
15:59:09.0234 5656 k750bus - ok
15:59:09.0250 5656 k750mdm - ok
15:59:09.0265 5656 kavsvc - ok
15:59:09.0281 5656 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
15:59:09.0296 5656 Kbdclass - ok
15:59:09.0296 5656 keymaestro - ok
15:59:09.0375 5656 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
15:59:09.0375 5656 kmixer - ok
15:59:09.0390 5656 KMW_SYS - ok
15:59:09.0406 5656 KMW_USB - ok
15:59:09.0421 5656 kraidsvc - ok
15:59:09.0484 5656 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
15:59:09.0484 5656 KSecDD - ok
15:59:09.0500 5656 ksthunk - ok
15:59:09.0500 5656 Ktp - ok
15:59:09.0515 5656 L6POD - ok
15:59:09.0531 5656 L8042Kbd - ok
15:59:09.0593 5656 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
15:59:09.0593 5656 lanmanserver - ok
15:59:09.0656 5656 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
15:59:09.0671 5656 lanmanworkstation - ok
15:59:09.0687 5656 lbrtfdc - ok
15:59:09.0687 5656 lbtserv - ok
15:59:09.0703 5656 LC7981 - ok
15:59:09.0718 5656 licensemanagersocket - ok
15:59:09.0796 5656 [ 00944D59948596721D17510C94CD3E4F ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
15:59:09.0796 5656 LightScribeService - ok
15:59:09.0812 5656 lirsgt - ok
15:59:09.0812 5656 LKbdFlt2 - ok
15:59:09.0828 5656 lmab_device - ok
15:59:09.0906 5656 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
15:59:09.0906 5656 LmHosts - ok
15:59:09.0906 5656 LMouFilt - ok
15:59:09.0921 5656 lpds - ok
15:59:09.0937 5656 ltck000c - ok
15:59:10.0062 5656 [ 9EE18A5A45552673A67532EA37370377 ] ltmodem5 C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys
15:59:10.0187 5656 ltmodem5 - ok
15:59:10.0203 5656 LVBulk - ok
15:59:10.0203 5656 LVCap138 - ok
15:59:10.0218 5656 lvckap - ok
15:59:10.0234 5656 lvcomser - ok
15:59:10.0234 5656 lvhidsvc - ok
15:59:10.0250 5656 lvpopflt - ok
15:59:10.0265 5656 LVRS - ok
15:59:10.0265 5656 lvupdtio - ok
15:59:10.0281 5656 lvuvc - ok
15:59:10.0296 5656 LVVI500A - ok
15:59:10.0312 5656 lxcj_device - ok
15:59:10.0312 5656 lxda_device - ok
15:59:10.0328 5656 lxdm_device - ok
15:59:10.0328 5656 lxrjd31d - ok
15:59:10.0343 5656 M2500 - ok
15:59:10.0359 5656 ma763004 - ok
15:59:10.0359 5656 MA8032C - ok
15:59:10.0375 5656 MA8032M - ok
15:59:10.0390 5656 magictuneengine - ok
15:59:10.0406 5656 marvinbus - ok
15:59:10.0406 5656 MA_CMIDI - ok
15:59:10.0421 5656 mcdetect.exe - ok
15:59:10.0437 5656 mclogmanagerservice - ok
15:59:10.0437 5656 mcmispupdmgr - ok
15:59:10.0453 5656 mcods - ok
15:59:10.0468 5656 mcp - ok
15:59:10.0468 5656 mcproxy - ok
15:59:10.0484 5656 mcrdsvc - ok
15:59:10.0500 5656 mcupdmgr.exe - ok
15:59:10.0500 5656 mdc8021x - ok
15:59:10.0578 5656 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
15:59:10.0593 5656 MDM - ok
15:59:10.0593 5656 [ 3C318B9CD391371BED62126581EE9961 ] mdmxsdk C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
15:59:10.0609 5656 mdmxsdk - ok
15:59:10.0609 5656 mediaviewer - ok
15:59:10.0625 5656 merakpop3 - ok
15:59:10.0640 5656 meraksmtp - ok
15:59:10.0703 5656 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll
15:59:10.0703 5656 Messenger - ok
15:59:10.0718 5656 mfeavfk - ok
15:59:10.0718 5656 mfebopk - ok
15:59:10.0734 5656 mfesmfk - ok
15:59:10.0750 5656 mgactrl - ok
15:59:10.0765 5656 mgisvr - ok
15:59:10.0796 5656 [ B7521F69C0A9B29D356157229376FB21 ] MHN C:\WINDOWS\System32\mhn.dll
15:59:10.0796 5656 MHN - ok
15:59:10.0843 5656 [ 7F2F1D2815A6449D346FCCCBC569FBD6 ] MHNDRV C:\WINDOWS\system32\DRIVERS\mhndrv.sys
15:59:10.0843 5656 MHNDRV - ok
15:59:10.0843 5656 mi-raysat_3dsmax9_32 - ok
15:59:10.0859 5656 mirrorv3 - ok
15:59:10.0875 5656 MKEMUSB - ok
15:59:10.0875 5656 mldserv - ok
15:59:10.0921 5656 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
15:59:10.0921 5656 mnmdd - ok
15:59:10.0984 5656 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
15:59:10.0984 5656 mnmsrvc - ok
15:59:11.0046 5656 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
15:59:11.0046 5656 Modem - ok
15:59:11.0062 5656 modemcsa - ok
15:59:11.0078 5656 mohfilt - ok
15:59:11.0093 5656 monfilt - ok
15:59:11.0109 5656 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
15:59:11.0109 5656 Mouclass - ok
15:59:11.0140 5656 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
15:59:11.0140 5656 MountMgr - ok
15:59:11.0156 5656 mpfp - ok
15:59:11.0171 5656 mqdmbus - ok
15:59:11.0171 5656 mraid35x - ok
15:59:11.0187 5656 MRESP50 - ok
15:59:11.0203 5656 mrvw245 - ok
15:59:11.0218 5656 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
15:59:11.0218 5656 MRxDAV - ok
15:59:11.0265 5656 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
15:59:11.0296 5656 MRxSmb - ok
15:59:11.0312 5656 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe
15:59:11.0312 5656 MSDTC - ok
15:59:11.0328 5656 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
15:59:11.0328 5656 Msfs - ok
15:59:11.0343 5656 msftpsvc - ok
15:59:11.0359 5656 MSFWHLPR - ok
15:59:11.0375 5656 MSIServer - ok
15:59:11.0375 5656 mskservice - ok
15:59:11.0406 5656 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
15:59:11.0406 5656 MSKSSRV - ok
15:59:11.0453 5656 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
15:59:11.0453 5656 MSPCLOCK - ok
15:59:11.0468 5656 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
15:59:11.0468 5656 MSPQM - ok
15:59:11.0500 5656 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
15:59:11.0500 5656 mssmbios - ok
15:59:11.0515 5656 MSSQL$AUTODESKVAULT - ok
15:59:11.0515 5656 MSSQL$MSSMLBIZ - ok
15:59:11.0531 5656 mssqlserver - ok
15:59:11.0546 5656 mstdfrgs - ok
15:59:11.0546 5656 ms_mpu401 - ok
15:59:11.0562 5656 MTDVC2_ENUM - ok
15:59:11.0578 5656 MtxDma0 - ok
15:59:11.0609 5656 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
15:59:11.0609 5656 Mup - ok
15:59:11.0625 5656 mvserver - ok
15:59:11.0640 5656 mvwebserver - ok
15:59:11.0640 5656 mwssched - ok
15:59:11.0656 5656 mwstick - ok
15:59:11.0671 5656 mysql - ok
15:59:11.0687 5656 n3900 - ok
15:59:11.0687 5656 n558 - ok
15:59:11.0703 5656 nalntservice - ok
15:59:11.0750 5656 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll
15:59:11.0765 5656 napagent - ok
15:59:11.0781 5656 navapel - ok
15:59:11.0781 5656 navex15 - ok
15:59:11.0796 5656 nchssvad - ok
15:59:11.0812 5656 NCPro - ok
15:59:11.0828 5656 ndasscsi - ok
15:59:11.0859 5656 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
15:59:11.0875 5656 NDIS - ok
15:59:11.0875 5656 NdisFilt - ok
15:59:11.0890 5656 Ndismeetro - ok
15:59:11.0953 5656 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
15:59:11.0953 5656 NdisTapi - ok
15:59:12.0015 5656 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
15:59:12.0015 5656 Ndisuio - ok
15:59:12.0031 5656 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
15:59:12.0031 5656 NdisWan - ok
15:59:12.0109 5656 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
15:59:12.0109 5656 NDProxy - ok
15:59:12.0125 5656 NecUsb3 - ok
15:59:12.0140 5656 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
15:59:12.0140 5656 NetBIOS - ok
15:59:12.0156 5656 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
15:59:12.0171 5656 NetBT - ok
15:59:12.0234 5656 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
15:59:12.0234 5656 NetDDE - ok
15:59:12.0250 5656 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
15:59:12.0250 5656 NetDDEdsdm - ok
15:59:12.0250 5656 NETGEAR_MA111 - ok
15:59:12.0296 5656 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
15:59:12.0296 5656 Netlogon - ok
15:59:12.0312 5656 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
15:59:12.0328 5656 Netman - ok
15:59:12.0328 5656 NETMDUSB - ok
15:59:12.0343 5656 netmnt - ok
15:59:12.0359 5656 NetPipeActivator - ok
15:59:12.0359 5656 netrcacm - ok
15:59:12.0375 5656 netw4x32 - ok
15:59:12.0390 5656 nfmservice - ok
15:59:12.0390 5656 nhcDriverDevice - ok
15:59:12.0421 5656 [ E9E47CFB2D461FA0FC75B7A74C6383EA ] NIC1394 C:\WINDOWS\system32\DRIVERS\nic1394.sys
15:59:12.0421 5656 NIC1394 - ok
15:59:12.0421 5656 nimcrpcsu - ok
15:59:12.0437 5656 nimdbgk - ok
15:59:12.0453 5656 niorbk - ok
15:59:12.0468 5656 NIPALK - ok
15:59:12.0468 5656 nipsvc - ok
15:59:12.0500 5656 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
15:59:12.0515 5656 Nla - ok
15:59:12.0531 5656 nmap - ok
15:59:12.0531 5656 nmraapache - ok
15:59:12.0546 5656 nnsvc - ok
15:59:12.0562 5656 NPDriver - ok
15:59:12.0625 5656 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
15:59:12.0625 5656 Npfs - ok
15:59:12.0640 5656 npkcrypt - ok
15:59:12.0640 5656 npkcsvc - ok
15:59:12.0656 5656 NPPTNT - ok
15:59:12.0671 5656 npptnt2 - ok
15:59:12.0671 5656 nsausvc - ok
15:59:12.0687 5656 nscservice - ok
15:59:12.0703 5656 Nsynas32 - ok
15:59:12.0718 5656 nsysaudm - ok
15:59:12.0734 5656 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
15:59:12.0750 5656 Ntfs - ok
15:59:12.0765 5656 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
15:59:12.0781 5656 NtLmSsp - ok
15:59:12.0843 5656 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
15:59:12.0859 5656 NtmsSvc - ok
15:59:12.0906 5656 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
15:59:12.0906 5656 Null - ok
15:59:12.0921 5656 nuvaud2 - ok
15:59:12.0937 5656 nv - ok
15:59:12.0953 5656 nvatabus - ok
15:59:12.0953 5656 nvenetfd - ok
15:59:12.0968 5656 nvgts - ok
15:59:12.0984 5656 nvidesm - ok
15:59:13.0000 5656 NVNET - ok
15:59:13.0000 5656 nvstor32 - ok
15:59:13.0015 5656 nvstor64 - ok
15:59:13.0031 5656 NVXBAR - ok
15:59:13.0046 5656 nwcworkstation - ok
15:59:13.0046 5656 NWDHCP - ok
15:59:13.0062 5656 nwdls - ok
15:59:13.0078 5656 NWDNS - ok
15:59:13.0109 5656 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
15:59:13.0109 5656 NwlnkFlt - ok
15:59:13.0125 5656 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
15:59:13.0125 5656 NwlnkFwd - ok
15:59:13.0156 5656 nwlnknb - ok
15:59:13.0156 5656 nwlnkspx - ok
15:59:13.0171 5656 NWSAP - ok
15:59:13.0187 5656 NWSLP - ok
15:59:13.0203 5656 NWUSBModem - ok
15:59:13.0218 5656 NxSysMon - ok
15:59:13.0218 5656 O2SCBUS - ok
15:59:13.0234 5656 odserv - ok
15:59:13.0281 5656 [ CA33832DF41AFB202EE7AEB05145922F ] ohci1394 C:\WINDOWS\system32\DRIVERS\ohci1394.sys
15:59:13.0281 5656 ohci1394 - ok
15:59:13.0296 5656 om518p - ok
15:59:13.0312 5656 omci - ok
15:59:13.0328 5656 omniusb - ok
15:59:13.0343 5656 ooclevercacheagent - ok
15:59:13.0343 5656 opcenum - ok
15:59:13.0359 5656 openvpnservice - ok
15:59:13.0375 5656 oracledbconsoleorcl - ok
15:59:13.0390 5656 oracleoradb10g_home1isql*plus - ok
15:59:13.0406 5656 oracleorahome811cmadmin - ok
15:59:13.0406 5656 oracleorahome90agent - ok
15:59:13.0421 5656 OracleOraHome92ClientCache - ok
15:59:13.0437 5656 oracleorahomehttpserver - ok
15:59:13.0453 5656 oracleservicelocalora - ok
15:59:13.0468 5656 oraclewebassistant - ok
15:59:13.0468 5656 oracle_load_balancer_60_client-forms6i - ok
15:59:13.0484 5656 oracle_load_balancer_60_client-forms6ip9 - ok
15:59:13.0500 5656 oracle_load_balancer_60_server-forms6ip14 - ok
15:59:13.0515 5656 OsaFsLoc - ok
15:59:13.0515 5656 osanbm - ok
15:59:13.0593 5656 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
15:59:13.0593 5656 ose - ok
15:59:13.0609 5656 ovmsmaccessmanager - ok
15:59:13.0625 5656 p1110vid - ok
15:59:13.0640 5656 p17 - ok
15:59:13.0656 5656 P17xfi - ok
15:59:13.0656 5656 p17xfilt - ok
15:59:13.0671 5656 p2psvc - ok
15:59:13.0687 5656 paamsrv - ok
15:59:13.0703 5656 papyjoy - ok
15:59:13.0718 5656 PAR1284 - ok
15:59:13.0734 5656 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
15:59:13.0734 5656 Parport - ok
15:59:13.0750 5656 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
15:59:13.0750 5656 PartMgr - ok
15:59:13.0796 5656 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
15:59:13.0796 5656 ParVdm - ok
15:59:13.0812 5656 pavagente - ok
15:59:13.0828 5656 pavdrv - ok
15:59:13.0843 5656 pav_security - ok
15:59:13.0843 5656 pav_service - ok
15:59:13.0859 5656 PBADRV - ok
15:59:13.0875 5656 PCASp50 - ok
15:59:13.0890 5656 pccsmcfd - ok
15:59:13.0937 5656 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
15:59:13.0937 5656 PCI - ok
15:59:13.0953 5656 PCIDump - ok
15:59:13.0953 5656 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
15:59:13.0968 5656 PCIIde - ok
15:59:13.0968 5656 pclepci - ok
15:59:14.0093 5656 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
15:59:14.0093 5656 Pcmcia - ok
15:59:14.0109 5656 pcscnsrv - ok
15:59:14.0125 5656 pctavsvc - ok
15:59:14.0140 5656 PCTINDIS5 - ok
15:59:14.0156 5656 PD0620VID - ok
15:59:14.0171 5656 PDCOMP - ok
15:59:14.0187 5656 PDExchange - ok
15:59:14.0203 5656 pdfcreatormessages - ok
15:59:14.0218 5656 PDFRAME - ok
15:59:14.0218 5656 pdiddcci - ok
15:59:14.0234 5656 pdlndtdl - ok
15:59:14.0250 5656 pdlnshay - ok
15:59:14.0265 5656 pdlnsv25 - ok
15:59:14.0281 5656 PDRELI - ok
15:59:14.0281 5656 PDRFRAME - ok
15:59:14.0296 5656 perc2 - ok
15:59:14.0312 5656 perc2hib - ok
15:59:14.0343 5656 personalsecuredriveservice - ok
15:59:14.0359 5656 pfmodnt - ok
15:59:14.0375 5656 PGPwded - ok
15:59:14.0390 5656 PhilCam8116 - ok
15:59:14.0406 5656 PhilCam8116_XP - ok
15:59:14.0421 5656 phnxvcdservice - ok
15:59:14.0421 5656 pilogsrv - ok
15:59:14.0437 5656 pinnaclemarvinusb - ok
15:59:14.0453 5656 pivot - ok
15:59:14.0484 5656 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
15:59:14.0484 5656 PlugPlay - ok
15:59:14.0500 5656 pml - ok
15:59:14.0609 5656 [ 2D091A99624FB9E7EEF0A86D872EC0C3 ] Pml Driver HPZ12 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
15:59:14.0625 5656 Pml Driver HPZ12 - ok
15:59:14.0625 5656 pmounter - ok
15:59:14.0640 5656 pnkbstrk - ok
15:59:14.0656 5656 pnrouter - ok
15:59:14.0671 5656 PNRPSvc - ok
15:59:14.0687 5656 PolarUSB - ok
15:59:14.0703 5656 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
15:59:14.0703 5656 PolicyAgent - ok
15:59:14.0718 5656 portmapper - ok
15:59:14.0718 5656 ppa3 - ok
15:59:14.0734 5656 pptchpad - ok
15:59:14.0796 5656 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
15:59:14.0796 5656 PptpMiniport - ok
15:59:14.0812 5656 prevxdriver - ok
15:59:14.0828 5656 prfldsvc - ok
15:59:14.0843 5656 processor - ok
15:59:14.0859 5656 procexp90 - ok
15:59:14.0859 5656 prodrv06 - ok
15:59:14.0890 5656 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
15:59:14.0890 5656 ProtectedStorage - ok
15:59:14.0953 5656 [ BFFDB363485501A38F0BCA83AEC810DB ] Ps2 C:\WINDOWS\system32\DRIVERS\PS2.sys
15:59:14.0953 5656 Ps2 - ok
15:59:14.0968 5656 psadd - ok
15:59:14.0984 5656 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
15:59:14.0984 5656 PSched - ok
15:59:15.0000 5656 PSDNServ - ok
15:59:15.0000 5656 psdvdisk - ok
15:59:15.0015 5656 PSSdk23 - ok
15:59:15.0031 5656 ptbsync - ok
15:59:15.0046 5656 PTDCVsp - ok
15:59:15.0078 5656 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
15:59:15.0078 5656 Ptilink - ok
15:59:15.0078 5656 ptserial - ok
15:59:15.0093 5656 Ptserlp - ok
15:59:15.0109 5656 purgeieservice - ok
15:59:15.0125 5656 pvservice - ok
15:59:15.0125 5656 pwd_2K - ok
15:59:15.0171 5656 [ 86724469CD077901706854974CD13C3E ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys
15:59:15.0171 5656 PxHelp20 - ok
15:59:15.0187 5656 qcdonner - ok
15:59:15.0203 5656 qfcoresvc - ok
15:59:15.0218 5656 ql1080 - ok
15:59:15.0234 5656 Ql10wnt - ok
15:59:15.0250 5656 ql12160 - ok
15:59:15.0265 5656 ql1240 - ok
15:59:15.0265 5656 ql1280 - ok
15:59:15.0281 5656 QPCapSvc - ok
15:59:15.0296 5656 QPSched - ok
15:59:15.0312 5656 quickbooksdb - ok
15:59:15.0328 5656 raidmsvr - ok
15:59:15.0328 5656 RalinkRegistryWriter - ok
15:59:15.0343 5656 rapapp - ok
15:59:15.0359 5656 RAPIProtocol - ok
15:59:15.0375 5656 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
15:59:15.0375 5656 RasAcd - ok
15:59:15.0437 5656 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
15:59:15.0437 5656 RasAuto - ok
15:59:15.0453 5656 rasirda - ok
15:59:15.0484 5656 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
15:59:15.0484 5656 Rasl2tp - ok
15:59:15.0546 5656 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
15:59:15.0562 5656 RasMan - ok
15:59:15.0578 5656 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
15:59:15.0578 5656 RasPppoe - ok
15:59:15.0609 5656 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
15:59:15.0609 5656 Raspti - ok
15:59:15.0656 5656 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
15:59:15.0656 5656 Rdbss - ok
15:59:15.0671 5656 rdnaoflsvc - ok
15:59:15.0687 5656 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
15:59:15.0687 5656 RDPCDD - ok
15:59:15.0718 5656 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
15:59:15.0718 5656 rdpdr - ok
15:59:15.0781 5656 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
15:59:15.0796 5656 RDPWD - ok
15:59:15.0843 5656 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
15:59:15.0859 5656 RDSessMgr - ok
15:59:15.0921 5656 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
15:59:15.0921 5656 redbook - ok
15:59:15.0937 5656 regdefend - ok
15:59:15.0953 5656 relational - ok
15:59:16.0000 5656 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
15:59:16.0000 5656 RemoteAccess - ok
15:59:16.0015 5656 remoterecord - ok
15:59:16.0078 5656 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
15:59:16.0078 5656 RemoteRegistry - ok
15:59:16.0093 5656 retrolauncher - ok
15:59:16.0109 5656 rimmptsk - ok
15:59:16.0125 5656 rimsptsk - ok
15:59:16.0140 5656 RIOUNIV - ok
15:59:16.0140 5656 risdptsk - ok
15:59:16.0156 5656 rksample - ok
15:59:16.0171 5656 rnadiagnosticsservice - ok
15:59:16.0187 5656 ROB_A - ok
15:59:16.0203 5656 roxliveshare - ok
15:59:16.0218 5656 roxliveshare9 - ok
15:59:16.0218 5656 roxmediadb - ok
15:59:16.0265 5656 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe
15:59:16.0281 5656 RpcLocator - ok
15:59:16.0312 5656 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll
15:59:16.0312 5656 RpcSs - ok
15:59:16.0328 5656 RR2IOMod - ok
15:59:16.0343 5656 rsvchost - ok
15:59:16.0421 5656 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe
15:59:16.0421 5656 RSVP - ok
15:59:16.0437 5656 rt2500usb - ok
15:59:16.0453 5656 rtl8023 - ok
15:59:16.0468 5656 [ 7F0413BDD7D53EB4C7A371E7F6F84DF1 ] RTL8023xp C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys
15:59:16.0468 5656 RTL8023xp - ok
15:59:16.0484 5656 rtl8029 - ok
15:59:16.0531 5656 [ D507C1400284176573224903819FFDA3 ] rtl8139 C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
15:59:16.0531 5656 rtl8139 - ok
15:59:16.0546 5656 rtl8185 - ok
15:59:16.0562 5656 rtl8187Se - ok
15:59:16.0578 5656 rtport - ok
15:59:16.0593 5656 s116bus - ok
15:59:16.0593 5656 s116obex - ok
15:59:16.0609 5656 s117bus - ok
15:59:16.0625 5656 s117nd5 - ok
15:59:16.0640 5656 s117unic - ok
15:59:16.0656 5656 s125mdm - ok
15:59:16.0656 5656 s217mgmt - ok
15:59:16.0671 5656 s217unic - ok
15:59:16.0687 5656 s3savagenb - ok
15:59:16.0703 5656 s616bus - ok
15:59:16.0718 5656 s616mgmt - ok
15:59:16.0734 5656 s616unic - ok
15:59:16.0734 5656 s716mdm - ok
15:59:16.0750 5656 sagefserver - ok
15:59:16.0765 5656 SaiNtBus - ok
15:59:16.0781 5656 SaiNtSub - ok
15:59:16.0812 5656 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
15:59:16.0828 5656 SamSs - ok
15:59:16.0828 5656 sandrathesrv - ok
15:59:16.0843 5656 sbiesvc - ok
15:59:16.0859 5656 sbp2port - ok
15:59:16.0890 5656 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
15:59:16.0890 5656 SCardSvr - ok
15:59:16.0906 5656 scdemu - ok
15:59:16.0968 5656 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
15:59:16.0984 5656 Schedule - ok
15:59:17.0000 5656 sdcoreservice - ok
15:59:17.0015 5656 sddmi2 - ok
15:59:17.0031 5656 SE26mdm - ok
15:59:17.0031 5656 SE26mgmt - ok
15:59:17.0046 5656 se26unic - ok
15:59:17.0062 5656 SE27mdfl - ok
15:59:17.0078 5656 se27unic - ok
15:59:17.0078 5656 SE2Bmgmt - ok
15:59:17.0093 5656 se2Bunic - ok
15:59:17.0109 5656 SE2Cbus - ok
15:59:17.0125 5656 SE2Cmdfl - ok
15:59:17.0125 5656 SE2Cmgmt - ok
15:59:17.0140 5656 SE2Dbus - ok
15:59:17.0156 5656 SE2Dmdfl - ok
15:59:17.0171 5656 se2Dunic - ok
15:59:17.0171 5656 SE2Emdm - ok
15:59:17.0187 5656 SE2Emgmt - ok
15:59:17.0203 5656 se44bus - ok
15:59:17.0218 5656 se44mgmt - ok
15:59:17.0218 5656 se45mdm - ok
15:59:17.0234 5656 se45mgmt - ok
15:59:17.0250 5656 se58obex - ok
15:59:17.0250 5656 se59mgmt - ok
15:59:17.0281 5656 se59obex - ok
15:59:17.0328 5656 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
15:59:17.0328 5656 Secdrv - ok
15:59:17.0359 5656 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
15:59:17.0375 5656 seclogon - ok
15:59:17.0375 5656 senfilt - ok
15:59:17.0390 5656 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\System32\sens.dll
15:59:17.0390 5656 SENS - ok
15:59:17.0406 5656 sentinel - ok
15:59:17.0421 5656 sentinelprotectionserver - ok
15:59:17.0453 5656 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] Serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
15:59:17.0453 5656 Serenum - ok
15:59:17.0500 5656 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
15:59:17.0500 5656 Serial - ok
15:59:17.0515 5656 serialkeys - ok
15:59:17.0531 5656 sermouse - ok
15:59:17.0531 5656 SfCtlCom - ok
15:59:17.0546 5656 sfcure01 - ok
15:59:17.0562 5656 sffdisk - ok
15:59:17.0578 5656 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
15:59:17.0578 5656 Sfloppy - ok
15:59:17.0593 5656 sgectl - ok
15:59:17.0609 5656 SGIR - ok
15:59:17.0671 5656 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
15:59:17.0687 5656 SharedAccess - ok
15:59:17.0718 5656 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
15:59:17.0718 5656 ShellHWDetection - ok
15:59:17.0734 5656 Shockprf - ok
15:59:17.0750 5656 sigfilt - ok
15:59:17.0750 5656 Simbad - ok
15:59:17.0765 5656 SimpTcp - ok
15:59:17.0781 5656 sisidex - ok
15:59:17.0796 5656 sisnic - ok
15:59:17.0812 5656 SISNICXP - ok
15:59:17.0828 5656 siswlsvc - ok
15:59:17.0843 5656 sit_flt - ok
15:59:17.0843 5656 sit_prt - ok
15:59:17.0859 5656 slabbus - ok
15:59:17.0875 5656 slee_81_service - ok
15:59:17.0890 5656 slpmonx - ok
15:59:17.0906 5656 smartlinkservice - ok
15:59:17.0906 5656 smrt - ok
15:59:17.0921 5656 smserial - ok
15:59:17.0937 5656 smtpd32 - ok
15:59:17.0953 5656 snare - ok
15:59:17.0968 5656 snareiis - ok
15:59:17.0984 5656 sndsrvc - ok
15:59:18.0000 5656 SNMP - ok
15:59:18.0000 5656 SNMPTRAP - ok
15:59:18.0015 5656 SNPSTD3 - ok
15:59:18.0031 5656 SNTIE - ok
15:59:18.0046 5656 sonicstagemonitoring - ok
15:59:18.0062 5656 sonypvs1 - ok
15:59:18.0078 5656 Sparrow - ok
15:59:18.0093 5656 SPCtl - ok
15:59:18.0109 5656 spkrmon - ok
15:59:18.0187 5656 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
15:59:18.0187 5656 splitter - ok
15:59:18.0250 5656 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
15:59:18.0250 5656 Spooler - ok
15:59:18.0250 5656 SprintRcAppSvc - ok
15:59:18.0265 5656 sprtsvc_dellsupportcenter - ok
15:59:18.0281 5656 spsslm - ok
15:59:18.0296 5656 sp_clamsrv - ok
15:59:18.0312 5656 SQLAgent$MICROSOFTBCM - ok
15:59:18.0328 5656 SQLAgent$MICROSOFTSMLBIZ - ok
15:59:18.0343 5656 sqlagent$soshome22 - ok
15:59:18.0343 5656 SQTECH905C - ok
15:59:18.0375 5656 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
15:59:18.0375 5656 sr - ok
15:59:18.0437 5656 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
15:59:18.0453 5656 srservice - ok
15:59:18.0468 5656 SRTSP - ok
15:59:18.0484 5656 srtspx - ok
15:59:18.0515 5656 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
15:59:18.0546 5656 Srv - ok
15:59:18.0562 5656 srvdpi - ok
15:59:18.0578 5656 sscdbhk5 - ok
15:59:18.0609 5656 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
15:59:18.0609 5656 SSDPSRV - ok
15:59:18.0625 5656 ssfs0509 - ok
15:59:18.0625 5656 SSHDRV61 - ok
15:59:18.0640 5656 ssm_bus - ok
15:59:18.0656 5656 ssrvc - ok
15:59:18.0671 5656 ss_bus - ok
15:59:18.0687 5656 statusagent4 - ok
15:59:18.0765 5656 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
15:59:18.0781 5656 stisvc - ok
15:59:18.0796 5656 streamip - ok
15:59:18.0796 5656 streamloadservice - ok
15:59:18.0812 5656 STV680 - ok
15:59:18.0828 5656 STV680m - ok
15:59:18.0843 5656 Subsonic - ok
15:59:18.0859 5656 SunkFilt - ok
15:59:18.0875 5656 superproserver - ok
15:59:18.0890 5656 svv - ok
15:59:18.0953 5656 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
15:59:18.0953 5656 swenum - ok
15:59:18.0968 5656 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
15:59:18.0968 5656 swmidi - ok
15:59:18.0984 5656 swmsflt - ok
15:59:19.0000 5656 SWNC8U20 - ok
15:59:19.0015 5656 SwPrv - ok
15:59:19.0031 5656 SWUMX51 - ok
15:59:19.0046 5656 symc810 - ok
15:59:19.0062 5656 symc8xx - ok
15:59:19.0078 5656 symlcbrd - ok
15:59:19.0093 5656 symproxysvc - ok
15:59:19.0109 5656 sympxsvc - ok
15:59:19.0125 5656 symsnap - ok
15:59:19.0125 5656 sym_hi - ok
15:59:19.0140 5656 sym_u3 - ok
15:59:19.0156 5656 syntp - ok
15:59:19.0187 5656 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
15:59:19.0187 5656 sysaudio - ok
15:59:19.0218 5656 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
15:59:19.0234 5656 SysmonLog - ok
15:59:19.0234 5656 szserver - ok
15:59:19.0250 5656 Tablet2k - ok
15:59:19.0265 5656 tangoservice - ok
15:59:19.0312 5656 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
15:59:19.0328 5656 TapiSrv - ok
15:59:19.0343 5656 tapvpn - ok
15:59:19.0359 5656 tbhsd - ok
15:59:19.0375 5656 TClass2k - ok
15:59:19.0437 5656 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
15:59:19.0453 5656 Tcpip - ok
15:59:19.0468 5656 tdcmdpst - ok
15:59:19.0531 5656 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
15:59:19.0531 5656 TDPIPE - ok
15:59:19.0562 5656 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
15:59:19.0562 5656 TDTCP - ok
15:59:19.0578 5656 teefer2 - ok
15:59:19.0625 5656 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
15:59:19.0625 5656 TermDD - ok
15:59:19.0703 5656 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
15:59:19.0718 5656 TermService - ok
15:59:19.0718 5656 TestHandler - ok
15:59:19.0734 5656 tfsnboio - ok
15:59:19.0750 5656 tgsrvc_smartagent - ok
15:59:19.0781 5656 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
15:59:19.0781 5656 Themes - ok
15:59:19.0796 5656 thinkpadmodemservice - ok
15:59:19.0812 5656 tifm - ok
15:59:19.0828 5656 tifm21 - ok
15:59:19.0828 5656 tiumfwl - ok
15:59:19.0906 5656 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
15:59:19.0906 5656 TlntSvr - ok
15:59:19.0921 5656 TMHIDSRV - ok
15:59:19.0937 5656 tmlisten - ok
15:59:19.0953 5656 TMMEmu - ok
15:59:19.0968 5656 tmxpflt - ok
15:59:19.0984 5656 tnbrlds - ok
15:59:19.0984 5656 tng-dtmg - ok
15:59:20.0000 5656 tng-dts - ok
15:59:20.0015 5656 toscosrv - ok
15:59:20.0031 5656 toshidpt - ok
15:59:20.0046 5656 TosIde - ok
15:59:20.0062 5656 tosporte - ok
15:59:20.0078 5656 tosrfbnp - ok
15:59:20.0093 5656 tosrfnds - ok
15:59:20.0109 5656 tosrfusb - ok
15:59:20.0125 5656 TPECioCtl - ok
15:59:20.0125 5656 tpkd - ok
15:59:20.0140 5656 trcboot - ok
15:59:20.0203 5656 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
15:59:20.0218 5656 TrkWks - ok
15:59:20.0234 5656 tsdhd - ok
15:59:20.0234 5656 tsp - ok
15:59:20.0250 5656 TuneUp.Defrag - ok
15:59:20.0265 5656 tunmp - ok
15:59:20.0281 5656 TUWinStylerThemeSvc - ok
15:59:20.0296 5656 tvtfilter - ok
15:59:20.0312 5656 twdns - ok
15:59:20.0312 5656 U81xmdm - ok
15:59:20.0328 5656 U81xmgmt - ok
15:59:20.0343 5656 U81xobex - ok
15:59:20.0406 5656 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
15:59:20.0406 5656 Udfs - ok
15:59:20.0406 5656 uhcd - ok
15:59:20.0421 5656 ultra - ok
15:59:20.0437 5656 ultra66 - ok
15:59:20.0453 5656 UMAXPCLS - ok
15:59:20.0468 5656 umpusbxp - ok
15:59:20.0515 5656 [ AB0A7CA90D9E3D6A193905DC1715DED0 ] UMWdf C:\WINDOWS\system32\wdfmgr.exe
15:59:20.0515 5656 UMWdf - ok
15:59:20.0531 5656 UPATC - ok
15:59:20.0593 5656 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
15:59:20.0625 5656 Update - ok
15:59:20.0703 5656 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
15:59:20.0703 5656 upnphost - ok
15:59:20.0718 5656 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
15:59:20.0718 5656 UPS - ok
15:59:20.0734 5656 us30service - ok
15:59:20.0750 5656 USB11LDR - ok
15:59:20.0765 5656 USBAAPL - ok
15:59:20.0781 5656 usbaudio - ok
15:59:20.0796 5656 USBCamera - ok
15:59:20.0828 5656 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
15:59:20.0828 5656 usbccgp - ok
15:59:20.0843 5656 USBCCID - ok
15:59:20.0859 5656 UsbDiag - ok
15:59:20.0906 5656 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
15:59:20.0921 5656 usbehci - ok
15:59:20.0968 5656 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
15:59:20.0984 5656 usbhub - ok
15:59:20.0984 5656 USBMN1X1 - ok
15:59:21.0046 5656 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
15:59:21.0046 5656 usbprint - ok
15:59:21.0062 5656 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
15:59:21.0062 5656 usbscan - ok
15:59:21.0078 5656 usbser - ok
15:59:21.0093 5656 UsbserFilt - ok
15:59:21.0140 5656 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
15:59:21.0140 5656 USBSTOR - ok
15:59:21.0156 5656 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
15:59:21.0156 5656 usbuhci - ok
15:59:21.0171 5656 usbvm321 - ok
15:59:21.0187 5656 USB_NDIS_51 - ok
15:59:21.0203 5656 USB_RNDIS - ok
15:59:21.0218 5656 usb_rndisx - ok
15:59:21.0234 5656 usnjsvc - ok
15:59:21.0234 5656 usnsvc - ok
15:59:21.0250 5656 USR1806V - ok
15:59:21.0265 5656 utilman - ok
15:59:21.0281 5656 UxTuneUp - ok
15:59:21.0296 5656 v124 - ok
15:59:21.0312 5656 VAIOMediaPlatform-MusicServer-HTTP - ok
15:59:21.0328 5656 VAIOMediaPlatform-MusicServer-UPnP - ok
15:59:21.0343 5656 vaiomediaplatform-videoserver-appserver - ok
15:59:21.0359 5656 vci - ok
15:59:21.0375 5656 vds - ok
15:59:21.0390 5656 vetefile - ok
15:59:21.0421 5656 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
15:59:21.0421 5656 VgaSave - ok
15:59:21.0437 5656 vhidmini - ok
15:59:21.0453 5656 Via4in1 - ok
15:59:21.0500 5656 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys
15:59:21.0500 5656 ViaIde - ok
15:59:21.0515 5656 viairda - ok
15:59:21.0531 5656 VIAPFD - ok
15:59:21.0546 5656 VMAUDIO - ok
15:59:21.0562 5656 vmauthdservice - ok
15:59:21.0578 5656 vmm - ok
15:59:21.0593 5656 vmodem - ok
15:59:21.0609 5656 vmware - ok
15:59:21.0625 5656 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
15:59:21.0625 5656 VolSnap - ok
15:59:21.0640 5656 vpcnfltr - ok
15:59:21.0656 5656 vpnva - ok
15:59:21.0671 5656 vrfwsvc - ok
15:59:21.0734 5656 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
15:59:21.0750 5656 VSS - ok
15:59:21.0765 5656 vstor2 - ok
15:59:21.0875 5656 [ 8ED347BAD8D1FB7C40B593BFB01786D2 ] vToolbarUpdater11.2.0 C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe
15:59:21.0890 5656 vToolbarUpdater11.2.0 - ok
15:59:21.0906 5656 vusbbus - ok
15:59:21.0921 5656 vvdsvc - ok
15:59:21.0937 5656 vxsvc - ok
15:59:21.0953 5656 vzfw - ok
15:59:21.0968 5656 vzupsvc - ok
15:59:21.0984 5656 w200mdm - ok
15:59:22.0000 5656 w200obex - ok
15:59:22.0000 5656 w300mdfl - ok
15:59:22.0046 5656 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll
15:59:22.0062 5656 W32Time - ok
15:59:22.0078 5656 w550mdfl - ok
15:59:22.0093 5656 W55U01 - ok
15:59:22.0109 5656 W700mdfl - ok
15:59:22.0125 5656 W700obex - ok
15:59:22.0140 5656 w800mdfl - ok
15:59:22.0156 5656 WacomVKHid - ok
15:59:22.0171 5656 wampapache - ok
15:59:22.0187 5656 wampmysqld - ok
15:59:22.0203 5656 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
15:59:22.0203 5656 Wanarp - ok
15:59:22.0218 5656 wanusb - ok
15:59:22.0234 5656 wap3gx - ok
15:59:22.0250 5656 WaveEnrollmentService - ok
15:59:22.0265 5656 WaveFDE - ok
15:59:22.0265 5656 Wbutton - ok
15:59:22.0281 5656 WDICA - ok
15:59:22.0359 5656 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
15:59:22.0359 5656 wdmaud - ok
15:59:22.0421 5656 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
15:59:22.0421 5656 WebClient - ok
15:59:22.0437 5656 webrootspysweeperservice - ok
15:59:22.0453 5656 websensecommunicationagent - ok
15:59:22.0468 5656 websensedcagent - ok
15:59:22.0484 5656 wfxsvc - ok
15:59:22.0500 5656 WIBUKEY - ok
15:59:22.0515 5656 WimFltr - ok
15:59:22.0546 5656 [ 473EE64C368CE2EED110376C11960259 ] winachsf C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
15:59:22.0578 5656 winachsf - ok
15:59:22.0593 5656 WINIO - ok
15:59:22.0703 5656 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
15:59:22.0718 5656 winmgmt - ok
15:59:22.0734 5656 winmtsrv - ok
15:59:22.0750 5656 winpowerrmi - ok
15:59:22.0781 5656 wintabservice - ok
15:59:22.0796 5656 WinVd32 - ok
15:59:22.0812 5656 winvnc4 - ok
15:59:22.0828 5656 WISTechVIDCAP - ok
15:59:22.0843 5656 wkscfgsrv - ok
15:59:22.0859 5656 wlancfg - ok
15:59:22.0875 5656 wlancig - ok
15:59:22.0890 5656 wlankeeper - ok
15:59:22.0906 5656 wltwo51b - ok
15:59:22.0906 5656 wm - ok
15:59:22.0921 5656 wmconnectcds - ok
15:59:22.0984 5656 [ 140EF97B64F560FD78643CAE2CDAD838 ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
15:59:22.0984 5656 WmdmPmSN - ok
15:59:23.0046 5656 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll
15:59:23.0078 5656 Wmi - ok
15:59:23.0109 5656 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
15:59:23.0109 5656 WmiApSrv - ok
15:59:23.0125 5656 WMIService - ok
15:59:23.0140 5656 wmp54gssvc - ok
15:59:23.0156 5656 wmp54gsvc - ok
15:59:23.0171 5656 wmp54gv4svc - ok
15:59:23.0187 5656 WmUsbHid - ok
15:59:23.0203 5656 Wpsnuio - ok
15:59:23.0218 5656 WSIMD - ok
15:59:23.0234 5656 WUSB54GPV4SRV - ok
15:59:23.0250 5656 WUSB54Gv4SVC - ok
15:59:23.0265 5656 wwsecsvc - ok
15:59:23.0343 5656 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
15:59:23.0359 5656 WZCSVC - ok
15:59:23.0375 5656 xfactorae1 - ok
15:59:23.0390 5656 XFX_program - ok
15:59:23.0406 5656 XilinxPC4Driver - ok
15:59:23.0468 5656 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
15:59:23.0484 5656 xmlprov - ok
15:59:23.0500 5656 XTrapD12 - ok
15:59:23.0515 5656 Xyz777b - ok
15:59:23.0515 5656 Xyz777s - ok
15:59:23.0531 5656 YahooAUService - ok
15:59:23.0546 5656 yukonwlh - ok
15:59:23.0562 5656 yukonwxp - ok
15:59:23.0578 5656 z525bus - ok
15:59:23.0593 5656 z525mdfl - ok
15:59:23.0609 5656 z525mdm - ok
15:59:23.0625 5656 zd1211u(zydas) - ok
15:59:23.0640 5656 zebrbus - ok
15:59:23.0656 5656 zebrmdfl - ok
15:59:23.0671 5656 zebrmdmc - ok
15:59:23.0687 5656 zebrsce - ok
15:59:23.0703 5656 ZSMC211 - ok
15:59:23.0718 5656 ZSMC303 - ok
15:59:23.0734 5656 ZTEusbmdm6k - ok
15:59:23.0734 5656 ZuneWlanCfgSvc - ok
15:59:23.0750 5656 ZY202_XP - ok
15:59:23.0765 5656 _iomega_active_disk_service_ - ok
15:59:23.0812 5656 {95808DC4-FA4A-4c74-92FE-5B863F82066B} - ok
15:59:23.0828 5656 ================ Scan global ===============================
15:59:23.0875 5656 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
15:59:23.0921 5656 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
15:59:23.0968 5656 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
15:59:24.0015 5656 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
15:59:24.0015 5656 [Global] - ok
15:59:24.0015 5656 ================ Scan MBR ==================================
15:59:24.0062 5656 [ 0AC6D996BCE152AED9600E6D6B797E2E ] \Device\Harddisk0\DR0
15:59:24.0281 5656 \Device\Harddisk0\DR0 - ok
15:59:24.0281 5656 ================ Scan VBR ==================================
15:59:24.0281 5656 [ 3808371A5F7299B80EAF3AF005675D29 ] \Device\Harddisk0\DR0\Partition1
15:59:24.0296 5656 \Device\Harddisk0\DR0\Partition1 - ok
15:59:24.0296 5656 [ 35BAFD6565C7FBE130F6FCFD30DA96F1 ] \Device\Harddisk0\DR0\Partition2
15:59:24.0296 5656 \Device\Harddisk0\DR0\Partition2 - ok
15:59:24.0296 5656 ============================================================
15:59:24.0296 5656 Scan finished
15:59:24.0296 5656 ============================================================
15:59:24.0312 2832 Detected object count: 1
15:59:24.0312 2832 Actual detected object count: 1
15:59:39.0312 2832 Cdrom ( Virus.Win32.ZAccess.k ) - skipped by user
15:59:39.0312 2832 Cdrom ( Virus.Win32.ZAccess.k ) - User select action: Skip
I suspect your CDROM was not working before with this infection either based on the entries from TDSSKiller. I believe you should find that it is working now. Combofix should have fixed that problem.

How is the machine running now? Are you seeing an improvement? Have the pop-ups gone away? Can you please try using it for a bit and let me know if the random shutdowns continue?

Also, I can see that you have AVG Firewall on the machine but neither DDS nor Combofix are detecting a current Antivirus program. This could be a result of the infection but can you please confirm if you do or do not have one installed? If not, I can certainly suggest some free solutions for you, but you should definitely have an antivirus installed to help prevent further infections.

In the mean time, let's go ahead with some additional scans. Different tools look in different places for malware and I want to be sure we haven't missed anything.


I see you have Malwarebytes already on your machine. Please run it by double clicking the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.


Go here to run an online scannner from ESET.
  • Note: For browsers other than Internet Explorer, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
I would love to know the suggestions for the antivirus/spyware/firewall programs you have. I'm a bit of a Luddite when it comes to those topics. MBAM Log: Malwarebytes Anti-Malware 1.65.1.1000 www.malwarebytes.org Database version: v2012.10.17.12 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 HP_Administrator :: FERGUSONHOME [administrator] 10/17/2012 3:55:04 PM mbam-log-2012-10-17 (15-55-04).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 213848 Time elapsed: 4 minute(s), 57 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ESET Log: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=bfbed45f0543d64bb96db2cc9d02bb6b # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2012-10-18 12:16:41 # local_time=2012-10-17 05:16:41 (-0700, US Mountain Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1279 16777215 0 0 0 0 0 0 # compatibility_mode=5889 16768382 80 100 56250426 190328815 0 55494469 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=74533 # found=8 # cleaned=0 # scan_time=4134 C:\Documents and Settings\HP_Administrator\Application Data\Sun\Java\Deployment\cache\6.0\11\1a45980b-592654c7 multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\HP_Administrator\Application Data\Sun\Java\Deployment\cache\6.0\16\2ec5eb90-341161f3 multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\HP_Administrator\Application Data\Sun\Java\Deployment\cache\6.0\24\34f9c118-3cbc42f9 multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\AskToolbar\setup.exe Win32/Bundled.Toolbar.Ask application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\{bbc9ca29-23d1-71ae-3dd2-875eff9c385e}\U\80000032.@ probably a variant of Win32/Sirefef.FD trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\8\353109c8-65372fa9 multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\hugziqjlhncqkoa4.jar-440e6e60-6e3af672.zip multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\cdrom.sys.vir a variant of Win32/Rootkit.Kryptik.KI trojan (unable to clean) 00000000000000000000000000000000 I
1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\AskToolbar\setup.exe
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\{bbc9ca29-23d1-71ae-3dd2-875eff9c385e}\U\80000032.@

ClearJavaCache::


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe. ComboFix may request an update; please allow it.

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.




Also, it does not appear that you have an antivirus program running on your machine. I'd advise installing now to help prevent this kind of infection in the future.
Here are some of the better free AV products.
Microsoft Security Essentials <– I recommend it highly
Avira AntiVir
Avast!
AVG Anti-Virus (Free version available)



Please tell me how the machine is running now.
Per your instructions:

ComboFix 12-10-17.05 - HP_Administrator 10/17/2012 18:22:01.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2039.1566 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\HP_Administrator\Desktop\CFScript.txt
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
FILE ::
"c:\documents and settings\HP_Administrator\Local Settings\Application Data\{bbc9ca29-23d1-71ae-3dd2-875eff9c385e}\U\80000032.@"
"c:\documents and settings\HP_Administrator\Local Settings\Application Data\AskToolbar\setup.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\HP_Administrator\Local Settings\Application Data\{bbc9ca29-23d1-71ae-3dd2-875eff9c385e}\U\80000032.@
c:\documents and settings\HP_Administrator\Local Settings\Application Data\AskToolbar\setup.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-09-18 to 2012-10-18 )))))))))))))))))))))))))))))))
.
.
2012-10-17 23:04 . 2012-10-17 23:04 ——– d—–w- c:\program files\ESET
2012-09-24 19:34 . 2012-09-24 19:34 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-30 02:54 . 2011-01-05 00:39 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-09-24 00:40 . 2012-04-03 20:13 696240 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-24 00:40 . 2011-05-17 21:32 73136 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-08-02 20:42 2074208 —-a-w- c:\program files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-08-24 04:20 1515688 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-08-24 1515688]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll" [2012-08-02 2074208]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-08-24 1515688]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-11 59392]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-08 61952]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-08 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-06-08 114688]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-02-18 49208]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-09-17 180269]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-04-05 2587008]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-09-17 98304]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2011-08-24 887976]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-08-02 1107552]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [4/19/2012 4:50 AM 24896]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 3:48 AM 31952]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [12/8/2010 4:12 AM 235216]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [11/12/2010 1:19 PM 301248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2/14/2012 4:53 AM 193288]
R2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [7/9/2012 2:26 PM 935008]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [7/12/2010 4:33 AM 30944]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [12/23/2011 1:32 PM 139856]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilterx.sys [12/23/2011 1:32 PM 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [12/23/2011 1:32 PM 17232]
S2 avgfws;AVG Firewall;c:\program files\AVG\AVG2012\avgfws.exe [6/13/2012 3:48 AM 2321560]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\avgidsagent.exe [7/4/2012 5:25 PM 5160568]
S2 NecUsb3;USB3 Service;c:\windows\System32\svchost.exe -k NecUsb3Sevic [8/10/2004 12:00 PM 14336]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/3/2012 1:13 PM 250288]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe [6/8/2011 1:29 PM 947528]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [7/12/2010 4:33 AM 30944]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
NecUsb3Sevic REG_MULTI_SZ NecUsb3
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
fsks
hpqwmi
pccsmcfd
relational
HssTrayService
iAimTV5
acmservice
ndasscsi
lxrjd31d
tosrfnds
tosporte
Cam5607
aeaudio
ZSMC211
pptchpad
us30service
DELL_A02
processor
avsvcmonitor
KR3NPXP
nimcrpcsu
tifm
NETMDUSB
dlaopiom
mgactrl
digitizer
smtpd32
atinevxx
AtiHdmiService
streamloadservice
vpcnfltr
nvatabus
dvd-ram_service
nv
SRTSP
NPDriver
NETGEAR_MA111
rasirda
TMMEmu
Tablet2k
SE2Emdm
wmp54gv4svc
btwdndis
adihdaudaddservice
regdefend
winvnc4
rnadiagnosticsservice
sentinel
NWSAP
mpfp
AFGMp50
monfilt
id2scaps
z525mdm
datasvr
DeviceScanner
VMAUDIO
mcmispupdmgr
ahcix86s
EIO_XP
NVNET
s117nd5
gameenum
lvpopflt
Defrag32b
ms_mpu401
mediaviewer
navapel
bcserver
oracleorahome90agent
cq_mem
curtainssyssvc
sffdisk
PCTINDIS5
keymaestro
pavdrv
DN2AKNET
SE2Bmgmt
FireHook
cqcpu
a8djusb
QPCapSvc
atitool
DKbFltr
SE2Dbus
LVVI500A
viairda
ssfs0509
swmsflt
SISNICXP
backupexecjobengine
odserv
nvstor32
nimdbgk
SunkFilt
npptnt2
MA8032M
SNPSTD3
brmfrmps
rdnaoflsvc
lvupdtio
hpqddsvc
netmnt
fsma
tvtfilter
USB11LDR
ipassconnectengine
AsuhfivrO
oracledbconsoleorcl
DniVad
citrixxteserver
purgeieservice
SprintRcAppSvc
USBCamera
UsbDiag
WinVd32
pwd_2K
avidstartup
MRESP50
WMIService
se45mdm
wlankeeper
prevxdriver
cvintdrv
netw4x32
wap3gx
n3900
wampmysqld
slpmonx
W55U01
avfilter
DM9102
uhcd
PhilCam8116
tosrfbnp
ppa3
cis1284
nvidesm
CTAUDFX.DLL
ehstart
siswlsvc
rtport
SE2Emgmt
sddmi2
cmigameport
sbiesvc
amdk77
PSDNServ
amusbprt
JiaoCap
apache
prfldsvc
websensedcagent
s217unic
NWSLP
EU3_USB
GT891x
WacomVKHid
nmap
vmm
mcp
nuvaud2
firesvc
TestHandler
dnsexit
BlueSoleilCS
se59obex
SQLAgent$MICROSOFTSMLBIZ
raidmsvr
npkcsvc
SWNC8U20
anbmservice
3dkeybd
CE3
digirefresh
USBAAPL
DgiVecp
ZSMC303
MSSQL$AUTODESKVAULT
ZY202_XP
dlbx_device
zebrmdfl
pdlnshay
scdemu
sentinelprotectionserver
w550mdfl
s3savagenb
bcm43xx
statusagent4
emitray
tng-dts
MA8032C
VAIOMediaPlatform-MusicServer-UPnP
usbser
DSDrv4
hidbatt
symlcbrd
rtl8187Se
iviaspi
WaveEnrollmentService
opcenum
cpqvcagent
pdfcreatormessages
LMouFilt
GoToAssist
dcfssvc
zebrmdmc
pnkbstrk
CVPND
CoolerXPDriver
RalinkRegistryWriter
ca-messagequeuing
Xyz777s
eamon
acrsch2svc
idsvc
OracleOraHome92ClientCache
61883
wlancfg
pav_service
k750bus
spkrmon
slee_81_service
RAPIProtocol
FreeTdi
NIPALK
dktknsrv
thinkpadmodemservice
cnmpar21
svv
personalsecuredriveservice
portmapper
hpwirelessmgr
mwstick
nsausvc
epgspooler
tmxpflt
RR2IOMod
WSIMD
mohfilt
emproxy
LVRS
fsaa
USBCCID
pdlnsv25
PGPwded
Intel_MIPMNMP
SfCtlCom
PCASp50
RIOUNIV
ptserial
tifm21
tfsnboio
ha10kx2k
adfs
hcmon
ipsecmon
oracleservicelocalora
incdpass
lxcj_device
AYDrvNT_ALYAC
WaveFDE
clmtomcatstartersvc
hwdatacard
oracle_load_balancer_60_client-forms6ip9
Via4in1
retrolauncher
aliadwdm
lvhidsvc
symproxysvc
sagefserver
etoksrv
dvd43llh
kavsvc
s217mgmt
sermouse
lirsgt
mclogmanagerservice
Blfp
SE2Cmgmt
harmony
ati2mtaa
Ndismeetro
PAR1284
exfat
zd1211u(zydas)
vpnva
nipsvc
wintabservice
arhidfltr
mcproxy
NWUSBModem
vrfwsvc
pnrouter
se59mgmt
lxdm_device
tbhsd
sympxsvc
iaantmon
tsp
WIBUKEY
dsncservice
HFACSVC
mirrorv3
PSSdk23
SE2Cbus
ssrvc
elnkservice
iaimtv3
usb_rndisx
FINEPIX_PCC
xfactorae1
P17xfi
ltck000c
sfcure01
lvuvc
sprtsvc_dellsupportcenter
houdiniserver
tng-dtmg
dimension4
smrt
Wbutton
bdfsfltr
oracle_load_balancer_60_server-forms6ip14
nvenetfd
dvd_2K
merakpop3
SPCtl
bdpredir
mvwebserver
eSettingsService
SNMP
BLKWGU(Belkin)
datasvr2
adminserver
AmdLLD
LC7981
bcm4sbxp
arkbcfltr
WimFltr
asp.net_2.0.50727
vxsvc
cqmghost
MSSQL$MSSMLBIZ
p17xfilt
vmware
CXTUNE
oracleorahomehttpserver
wkscfgsrv
tapvpn
As6frin
https-admserv61
rapapp
mssqlserver
toscosrv
Appn
bridgemp
s616mgmt
sigfilt
sonicstagemonitoring
om518p
tpkd
p17
mvserver
Epiusb
iaimfp4
TPPWRIF
ibmasrex
s616bus
nod32krn
USR1806V
qfcoresvc
SE27mdfl
deckzpsx
tosrfusb
cwafadminmonitor
W700obex
fix
avgascln
atfsd
LKbdFlt2
FGDSCSI
atitunep
nalntservice
yukonwlh
pdlndtdl
k750mdm
nsysaudm
U81xobex
VAIOMediaPlatform-MusicServer-HTTP
QPSched
KMW_USB
mcrdsvc
mrvw245
vetefile
pavagente
tangoservice
nfmservice
elbydelay
omniusb
ipahelper.exe
marvinbus
CTEAPSFX.DLL
agp440
umpusbxp
SGIR
ooclevercacheagent
pav_security
snareiis
MKEMUSB
BCMTPM
usbvm321
snare
procexp90
ARSVC
idebusdr
lbtserv
ATKFUSService
ati2mtag
L6POD
s125mdm
SaiNtSub
mcods
fasttrackinstallerservice
JiaoIO
pml
websensecommunicationagent
FTSER2K
PolarUSB
SE26mdm
z525mdfl
IntelC51
_iomega_active_disk_service_
rtl8185
USB_NDIS_51
cm102u32
emu10k1
dcpflics
avcgbdr
remoterecord
se2Bunic
jukebox3
syntp
zebrbus
ultra66
szserver
clsched
wampapache
cicsclient
vmodem
vds
DMICall
w300mdfl
fcprintservice
CA561
ksthunk
elbycdio
cpqfws2e
HssSrv
aolservice
XFX_program
roxmediadb
DXEC02
modemcsa
iisadmin
MtxDma0
FiltUSBEMPIA
SNMPTRAP
avgems
akshhl
w200obex
sonypvs1
UxTuneUp
hsfhwazl
w800mdfl
serialkeys
asmagent
SSHDRV61
tunmp
ctljystk
Ktp
GTPTSER
nvgts
NdisFilt
lvcomser
com4qlb
ma763004
oracle_load_balancer_60_client-forms6i
dkeysync
iaimfp0
emu10k
aclient
pmounter
inorpc
ctaud2k
pdiddcci
pcscnsrv
NWDNS
ATIVXSTW
ZuneWlanCfgSvc
se44bus
paamsrv
fsssvc
DCamUSBDXGTech
HECI
LVBulk
U81xmdm
mqdmbus
GT680x
meraksmtp
tdcmdpst
sgectl
magictuneengine
qcdonner
cicssfs.scmmc223
artourservice
XilinxPC4Driver
toshidpt
oracleoradb10g_home1isql*plus
PhilCam8116_XP
trcboot
avipbb
SimpTcp
TPECioCtl
WISTechVIDCAP
vaiomediaplatform-videoserver-appserver
psadd
mgisvr
Cam5603C
Xyz777b
akshasp
cmpci
SaiNtBus
MSFWHLPR
ANC
bdselfpr
axinstsv
SWUMX51
NxSysMon
vci
DumaNT
srtspx
tgsrvc_smartagent
wfxsvc
cfsvcs
iaimtv4
omci
ichaud
hcf_msft
apphostsvc
mcupdmgr.exe
wwsecsvc
senfilt
U81xmgmt
npkcrypt
KMW_SYS
IASJet
papyjoy
ctac32k
wmp54gsvc
a016mdm
prodrv06
mi-raysat_3dsmax9_32
IntelC53
rt2500usb
icraplus
BRGSp50
bc_filter
sndsrvc
ghaio
A88xEnc
hidir
3comtftp
cwcwdm
fcdabus
s117bus
wm
SQTECH905C
ssm_bus
vvdsvc
se44mgmt
se2Dunic
pilogsrv
n558
Shockprf
ROB_A
SE2Dmdfl
webrootspysweeperservice
SQLAgent$MICROSOFTBCM
phnxvcdservice
DritekPortIO
w200mdm
usbaudio
pfmodnt
sisnic
TuneUp.Defrag
ghostsec
InterBaseGuardian
YahooAUService
zebrsce
DFUBTUSB
adiusbaw
sqlagent$soshome22
s716mdm
wltwo51b
CTHWIUT.DLL
rimsptsk
s116obex
IPSECSHM
USBMN1X1
symsnap
lvckap
XTrapD12
ClntMgmt.sys
acdpowerservice
O2SCBUS
dpc_srv_webcast
addfiltr
tsdhd
freebsd
z525bus
s117unic
amdagp
mldserv
WUSB54GPV4SRV
CYGF32X
ELkbd
UMAXPCLS
egathdrv
nwdls
bltrust
AVCamUSB20
allegro
ALABULK
{95808DC4-FA4A-4c74-92FE-5B863F82066B}
dot4ufd
superproserver
vusbbus
vmauthdservice
NetPipeActivator
STV680m
AsDsm
dntus26
OsaFsLoc
rtl8023
avgcoresvc
ESDCR
quickbooksdb
UPATC
flashpnt
AdobeActiveFileMonitor6.0
LVCap138
pvservice
adaptecstoragemanageragent
spsslm
sscdbhk5
sbp2port
PD0620VID
iksysflt
srvdpi
twdns
L8042Kbd
atchksrv
elbycdfl
mfeavfk
tiumfwl
nmraapache
dlabmfsm
NPPTNT
wmp54gssvc
se26unic
gtndis5
VIAPFD
smartlinkservice
mfesmfk
sandrathesrv
driverhardwarev2
pinnaclemarvinusb
sit_prt
DcCam
se45mgmt
oraclewebassistant
msftpsvc
tmlisten
hidusb
CnxTrLan
nwlnkspx
eaps2kbd
Cap7134
sit_flt
s116bus
WINIO
USB_RNDIS
PTDCVsp
k56
hap16v2k
mfebopk
filechecker
houdinilicenseserver
F700imd
ATSWPDRV
Ptserlp
TUWinStylerThemeSvc
vzupsvc
HpqRemHid
mysql
WmUsbHid
kraidsvc
mskservice
vzfw
ibmcicstransactiongateway
ativraxx
bhmonitorservice
usnsvc
Subsonic
ARCSOFTVIRTUALCAPTURE
openvpnservice
AMDPCI
pivot
NVXBAR
risdptsk
MA_CMIDI
TClass2k
wlancig
mstdfrgs
nnsvc
nvstor64
pctavsvc
EACSvrMngr
aniwzcsdservice
NCPro
psdvdisk
wanusb
atimpab
avgntflt
CX88AUD
SNTIE
aksusb
atikmdag
mwssched
ccevtmgr
ATWPKT2
acrotray
ZTEusbmdm6k
winmtsrv
s616unic
se27unic
ss_bus
ptbsync
defragfs
rsvchost
HpqKbFiltr
v124
avgtdi
vhidmini
axskbus
carboncopyscheduler
p2psvc
p1110vid
diskeeper
cdr4_2k
PDExchange
cwcpsvc20
elaunidr
nchssvad
netrcacm
utilman
lmab_device
roxliveshare
tnbrlds
CADlink
eskerlicensecontrol
btserial
NWDHCP
ds1
hSONYPVh
ovmsmaccessmanager
STV680
W700mdfl
yukonwxp
mcdetect.exe
Nsynas32
beatjamupnpmusicserver
epson_pm_rpcv4_01
osanbm
roxliveshare9
BrUsbSer
ilicensesvc
sdcoreservice
licensemanagersocket
nhcDriverDevice
sisidex
rtl8029
dsproct
bt
teefer2
se58obex
SE2Cmdfl
slabbus
iPassP
hf30service
DSXUSB
lpds
HabuFltr
vstor2
MTDVC2_ENUM
winpowerrmi
oracleorahome811cmadmin
IBM_LLC2
aegisp
lxda_device
nwlnknb
db2remotecmd
ccproxy
smserial
pclepci
TMHIDSRV
navex15
CrystalSysInfo
aswlsvc
CTEXFIFX.DLL
wmconnectcds
SE26mgmt
sp_clamsrv
mdc8021x
rimmptsk
acedrv05
DSI_SiUSBXp_3_1
UsbserFilt
nscservice
db2ntsecserver
icam4usb
bthmodem
VC6SecS
PBADRV
rksample
WUSB54Gv4SVC
Wpsnuio
streamip
abnetmon
niorbk
cusrvc
DC21x4
bcftdi
M2500
PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 00:40]
.
2012-10-18 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2011-08-24 04:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://cnn.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
TCP: DhcpNameServer = 192.168.2.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-17 18:30
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2012-10-17 18:31:54
ComboFix-quarantined-files.txt 2012-10-18 01:31
ComboFix2.txt 2012-10-16 23:32
.
Pre-Run: 172,634,849,280 bytes free
Post-Run: 172,643,409,920 bytes free
.
- - End Of File - - 8C8C852651F25E5E4854FF87399B52B7
It appears to be running just fine now…much faster too. I'm not getting the shutdowns or the pop-ups. I'm installing MSE right now, so the computer will be better protected after that. Is it a firewall too, or just AV?
MSE is just anti-virus. It will work quite nicely with Windows Firewall if you choose, but if you wish to keep your AVG Firewall in place, you could do that as well.

I'm glad to hear the system appears to be running well now. That's great news! We can do some clean up of tools now.


The following will implement some cleanup procedures as well as reset System Restore points:
  • Click Start > Run
  • Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]

If there are any remaining tools or logs on your desktop you can right-click and delete them.

===========================================


Great job! Your logs appear to be malware free and you do not appear to be experiencing any malware related problems.
Please follow these simple steps in order to keep your computer malware free and secure:

Visit Microsoft's Windows Update Site Frequently
It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Use and Update your AntiVirus Software
It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall
I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this. Simply using a Firewall in its default configuration can lower your risk greatly.

Use only one antivirus and one firewall on your machine
Having more than one anti-virus program and one firewall on your machine, even if only one is running, can cause conflicts and slowdowns in the performance of the machine.

If you need more information on free anti-virus or firewall options please let me know and I will give you some recommendations.

Make your Internet Explorer more secure
This can be done by following these simple instructions:
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click once on the Security tab
3. Click once on the Internet icon so it becomes highlighted.
4. Click once on the Custom Level button.
5. Change the Download signed ActiveX controls to Prompt
6. Change the Download unsigned ActiveX controls to Disable
7. Change the Initialize and script ActiveX controls not marked as safe to Disable
8. Change the Installation of desktop items to Prompt
9. Change the Launching programs and files in an IFRAME to Prompt
10. Change the Navigate sub-frames across different domains to Prompt
11. When all these settings have been made, click on the OK button.
12. If it prompts you as to whether or not you want to save the settings, press the Yes button.
13. Next press the Apply button and then the OK to exit the Internet Properties page.

Keep your Java, Adobe Reader and Adobe Flash Up to Date
Older versions of these programs can contain security vulnerabilities. It is very important to keep them updated.

Update and Run Malwarebytes Anti-Malware
Scan your computer with this program on a regular basis just as you would an antivirus software making sure you update definitions each time you scan.

To simplify making sure you have the latest version of many of your security programs and applications, you may want to consider:
Secunia's Personal Software Inspector (PSI). It is a free utility that scans your computer for installed applications and checks to see if they have the latest security patches and updates. If it finds any applications with possible security issues, links and/or instructions are provided for the necessariy updates.

Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.

I would suggest you read:
Tony Klein's excellent article: How I got Infected in the First Place
PC Safety and Security–What Do I Need?
How to Prevent Malware

Good luck & Happy surfing!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI