Spyware / Malware / Virus Removal
BACK DOOR BOT [Solved]
71 min read
karenoregon
Topic Starter
I have previously been infected with the Back Door Bot. The last couple of days my computer has been acting just like it did before I got the Back Door Bot infection. I am running Windows XP, service pack #3. I have CCleaner, Baseline Analyzer, Spy Bot Search and Destroy, Advanced System Cleaner, MBAM, Super Anti Spyware with Comodo Firewall and Comodo Anti Virus.
My internet has taken to shutting itself down. By that I mean that with three or four windows open I will all of a sudden have all
the windows close and need to restart Windows Internet Explorer and do my searches all over again.
My computer is also very, very slow. I have cleaned and defragged.
My computer is also freezing up at times. An example would be going to Start to get email going or a Word document and the computer just sits there.
Again, all of these items were present when I was infected before.
Thank you for helping me,
Karen
Posting DDS Results:
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 18:07:00.93 on Mon 02/11/2013
Internet Explorer: 8.0.6001.18702
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.dogpile.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: ChromeFrame BHO: {ecb3c477-1a0a-44bd-bb57-78f9efe34fa7} - c:\program files\google\chrome\application\24.0.1312.57\npchrome_frame.dll
TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
Trusted Zone: facebook.com\www
Trusted Zone: geekpolice.net\www
DPF: Microsoft XML Parser for Java
DPF: vzTCPConfig - hxxp://www2.verizon.net/help/dsl_settings/include/vzTCPConfig.CAB
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://support.microsoft.com/OAS/ActiveX/MSDcode.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photo.walgreens.com/WalgreensActivia.cab
DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-36.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1353121288140
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1342117178000
DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - hxxp://uguardu.com/ie/AMC.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab
DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} - hxxp://hgtv.view22.com/view22/app/view22rte.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - c:\program files\google\chrome\application\24.0.1312.57\npchrome_frame.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2013-02-09 00:23:23 ——– d—–w- c:\docume~1\owner\applic~1\Comodo
2013-02-08 23:12:39 ——– d—–w- c:\docume~1\alluse~1\applic~1\Comodo
2013-02-08 23:12:36 ——– d—–w- c:\docume~1\alluse~1\applic~1\Comodo Downloader
2013-02-08 23:12:30 ——– d—–w- c:\program files\COMODO
2013-02-08 23:04:05 130846192 —-a-w- c:\program files\cav_installer.exe
2013-02-08 14:23:02 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-02-08 14:23:01 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-02-08 02:21:23 ——– d—–w- c:\docume~1\owner\locals~1\applic~1\Avg2013
2013-02-07 01:40:33 ——– d—–w- c:\docume~1\owner\applic~1\TuneUp Software
2013-02-07 01:11:25 ——– d—–w- c:\docume~1\owner\locals~1\applic~1\MFAData
2013-02-06 12:02:09 36760 —-a-w- c:\windows\system32\drivers\fvstore.dat
2013-02-06 11:45:14 ——– dc-h–w- C:\VTRoot
2013-02-06 11:15:35 ——– d-s—w- c:\docume~1\alluse~1\applic~1\Shared Space
2013-02-06 07:36:06 ——– dc-h–w- C:\VritualRoot
2013-02-03 07:37:51 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2013-02-03 07:37:51 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2013-02-03 07:37:51 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2013-02-03 07:37:51 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2013-02-03 07:37:51 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2013-02-03 07:37:51 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2013-02-03 07:37:51 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2013-01-29 07:52:32 29528 —-a-w- c:\windows\system32\SmartDefragBootTime.exe
2013-01-29 07:52:15 14776 —-a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2013-01-29 07:24:58 ——– d—–w- c:\docume~1\alluse~1\applic~1\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
2013-01-27 20:54:18 4189792 —-a-w- c:\program files\ccsetup327.exe
2013-01-25 06:43:02 35488 —-a-w- c:\windows\system32\cmdcsr.dll
2013-01-25 06:43:02 354752 —-a-w- c:\windows\system32\guard32.dll
2013-01-25 06:42:50 40656 —-a-w- c:\windows\system32\cmdkbd32.dll
2013-01-25 06:42:50 263888 —-a-w- c:\windows\system32\cmdvrt32.dll
2013-01-17 03:51:56 586728 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2013-01-17 03:51:56 32824 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2013-01-17 03:51:54 18536 —-a-w- c:\windows\system32\drivers\cmderd.sys
.
==================== Find3M ====================
.
2013-02-03 22:03:35 40437664 —-a-w- c:\program files\QuickTimeInstaller.exe
2013-01-29 07:21:35 21494224 —-a-w- c:\program files\asc-setup.exe
2013-01-16 02:49:16 23360 —-a-w- c:\windows\system32\RegistryDefragBootTime.exe
2013-01-12 21:50:30 4178040 —-a-w- c:\program files\ccsetup326.exe
2013-01-12 20:32:04 697864 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-12 20:32:03 74248 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-10 00:40:28 24265736 —-a-w- c:\program files\dotnetfx.exe
2013-01-09 06:14:23 3327000 —-a-w- c:\program files\WindowsXP-KB942288-v3-x86.exe
2013-01-09 05:58:37 15900360 —-a-w- c:\program files\NDP1.1sp1-KB2742597-X86.exe
2012-12-18 19:00:52 4976384 —-a-w- c:\program files\defragsetup.exe
2012-12-16 12:23:59 290560 —-a-w- c:\windows\system32\atmfd.dll
2012-11-18 00:57:38 2959376 —-a-w- c:\program files\dotnetfx35setup.exe
2012-10-28 00:17:47 38984 —-a-w- c:\program files\DellPCDiagnostics.exe
2012-10-27 22:47:09 347424 —-a-w- c:\program files\MicrosoftFixit.AudioPlayback.Run.exe
2012-10-27 19:10:57 10669896 —-a-w- c:\program files\mbam-setup.exe
2012-02-24 00:50:33 8669472 —-a-w- c:\program files\Windows7UpgradeAdvisorSetup.exe
2012-02-16 02:52:12 14809712 —-a-w- c:\program files\SUPERAntiSpyware.exe
2011-07-25 03:12:45 16409960 —-a-w- c:\program files\spybotsd162.exe
2011-07-23 09:00:17 908064 —-a-w- c:\program files\jre-6u26-windows-i586-iftw.exe
2011-07-20 05:55:25 684297 —-a-w- c:\program files\unhide.exe
2010-12-26 06:19:56 12965392 —-a-w- c:\program files\RealPlayer10-5GOLD.exe
2010-12-26 05:03:20 12252656 —-a-w- c:\program files\RealPlayer11GOLD.exe
2010-12-25 07:47:18 602464 —-a-w- c:\program files\RealPlayer.exe
2010-12-25 03:18:23 25740256 —-a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2010-09-12 01:42:33 6776168 —-a-w- c:\program files\WindowsUpdateAgent30-x86.exe
2010-08-26 19:15:26 1625600 -c–a-w- c:\program files\MBSASetup-x86-EN.msi
2010-05-22 22:28:32 6108728 —-a-w- c:\program files\picasaweb-current-setup.exe
2010-04-19 18:37:56 2270216 —-a-w- c:\program files\advisor.exe
2010-02-05 19:35:28 1114576 —-a-w- c:\program files\revosetup.exe
2010-01-07 20:04:01 9476032 —-a-w- c:\program files\RevoUninProSetup.exe
2009-10-25 20:03:19 747520 -c–a-w- c:\program files\MicrosoftFixit50198.msi
2009-10-20 20:54:04 16883056 —-a-w- c:\program files\IE8-WindowsXP-x86-ENU.exe
2009-09-27 07:35:03 1146184 —-a-w- c:\program files\wlsetup-web.exe
2009-07-25 18:24:03 2052104 —-a-w- c:\program files\advisor belarc.exe
2009-06-04 21:16:13 14243328 -c–a-w- c:\program files\DM510.32.4071221.EN.msi
2009-04-01 03:21:35 224 -c–a-w- c:\program files\fix.bat
2009-01-02 22:57:39 1945096 -c–a-w- c:\program files\BELARC advisor.exe
2008-06-23 17:11:54 2400784 —-a-w- c:\program files\WLinstaller.exe
2008-01-14 20:32:30 6957056 -c–a-w- c:\program files\PhotoLibrary.msp
2006-12-29 23:58:46 15505200 -c–a-w- c:\program files\IE7-WindowsXP-x86-enu.exe
2006-12-18 05:44:05 20036629 -c–a-w- c:\program files\eppwin300aus.exe
2006-11-07 00:49:20 64512 -c–a-w- c:\program files\Compatibility_Check.exe
2006-10-27 16:50:51 317248 -c–a-w- c:\program files\WINDOWS OCT06.exe
2005-12-17 01:24:09 561 -c–a-w- c:\program files\os449133.bin
.
============= FINISH: 18:12:50.00 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
.
==== Disk Partitions =========================
.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
Acrobat.com
Adobe Flash Player 11 ActiveX
Adobe Reader X (10.1.4)
Adobe Shockwave Player 11.6
Adobe® Photoshop® Album Starter Edition 3.2
Advanced SystemCare 6
Apple Application Support
Apple Software Update
Auslogics Duplicate File Finder
BCM V.92 56K Modem
Broadcom 440x 10/100 Integrated Controller
Canon CanoScan LiDE 100 User Registration
Canon MP Navigator EX 2.0
Canon S450
Canon Utilities Solution Menu
CanoScan LiDE 100 Scanner Driver
CCleaner
CenturyLink Help
CenturyLink Remote Control
COMODO Internet Security
Dell ResourceCD
Dell Support Center
ESET Online Scanner v3
Form Fill (Windows Live Toolbar)
Google Chrome Frame
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB2570791)
Hotfix for Windows XP (KB2633952)
Hotfix for Windows XP (KB2756822)
Hotfix for Windows XP (KB2779562)
Hotfix for Windows XP (KB942288-v3)
Hotfix for Windows XP (KB954708)
Intel® Extreme Graphics Driver
Internet Explorer (Enable DEP)
Junk Mail filter update
Malwarebytes Anti-Malware version 1.70.0.1100
Map Button (Windows Live Toolbar)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2698023)
Microsoft .NET Framework 1.1 Security Update (KB2742597)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Baseline Security Analyzer 2.2
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2003
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser (KB933579)
OneCare Advisor (Windows Live Toolbar)
OneTouch Version 3.0
PaperPort 7.02
Picasa 2
PMB
QuickTime
RealPlayer
Revo Uninstaller 1.92
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)
Security Update for Microsoft Windows (KB2564958)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2530548)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2559049)
Security Update for Windows Internet Explorer 8 (KB2586448)
Security Update for Windows Internet Explorer 8 (KB2618444)
Security Update for Windows Internet Explorer 8 (KB2647516)
Security Update for Windows Internet Explorer 8 (KB2675157)
Security Update for Windows Internet Explorer 8 (KB2699988)
Security Update for Windows Internet Explorer 8 (KB2722913)
Security Update for Windows Internet Explorer 8 (KB2744842)
Security Update for Windows Internet Explorer 8 (KB2761465)
Security Update for Windows Internet Explorer 8 (KB2799329)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2503665)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2536276)
Security Update for Windows XP (KB2544893-v2)
Security Update for Windows XP (KB2544893)
Security Update for Windows XP (KB2555917)
Security Update for Windows XP (KB2562937)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2567053)
Security Update for Windows XP (KB2567680)
Security Update for Windows XP (KB2570222)
Security Update for Windows XP (KB2570947)
Security Update for Windows XP (KB2584146)
Security Update for Windows XP (KB2585542)
Security Update for Windows XP (KB2592799)
Security Update for Windows XP (KB2598479)
Security Update for Windows XP (KB2603381)
Security Update for Windows XP (KB2618451)
Security Update for Windows XP (KB2619339)
Security Update for Windows XP (KB2620712)
Security Update for Windows XP (KB2621440)
Security Update for Windows XP (KB2624667)
Security Update for Windows XP (KB2631813)
Security Update for Windows XP (KB2633171)
Security Update for Windows XP (KB2639417)
Security Update for Windows XP (KB2641653)
Security Update for Windows XP (KB2646524)
Security Update for Windows XP (KB2647518)
Security Update for Windows XP (KB2653956)
Security Update for Windows XP (KB2655992)
Security Update for Windows XP (KB2659262)
Security Update for Windows XP (KB2660465)
Security Update for Windows XP (KB2661637)
Security Update for Windows XP (KB2676562)
Security Update for Windows XP (KB2685939)
Security Update for Windows XP (KB2686509)
Security Update for Windows XP (KB2691442)
Security Update for Windows XP (KB2695962)
Security Update for Windows XP (KB2698365)
Security Update for Windows XP (KB2705219)
Security Update for Windows XP (KB2707511)
Security Update for Windows XP (KB2709162)
Security Update for Windows XP (KB2712808)
Security Update for Windows XP (KB2718523)
Security Update for Windows XP (KB2719985)
Security Update for Windows XP (KB2723135)
Security Update for Windows XP (KB2724197)
Security Update for Windows XP (KB2727528)
Security Update for Windows XP (KB2731847)
Security Update for Windows XP (KB2753842-v2)
Security Update for Windows XP (KB2753842)
Security Update for Windows XP (KB2757638)
Security Update for Windows XP (KB2758857)
Security Update for Windows XP (KB2761226)
Security Update for Windows XP (KB2770660)
Security Update for Windows XP (KB2779030)
Segoe UI
Smart Defrag 2
SoundMAX
Spelling Dictionaries For Adobe Reader Package
Spybot - Search & Destroy
SUPERAntiSpyware
swMSM
Unlocker 1.9.1
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB2447568)
Update for Windows Internet Explorer 8 (KB2598845)
Update for Windows Internet Explorer 8 (KB2632503)
Update for Windows XP (KB2492386)
Update for Windows XP (KB2541763)
Update for Windows XP (KB2607712)
Update for Windows XP (KB2616676)
Update for Windows XP (KB2641690)
Update for Windows XP (KB2661254-v2)
Update for Windows XP (KB2718704)
Update for Windows XP (KB2736233)
Update for Windows XP (KB2749655)
Update for Windows XP (KB961503)
Update for Windows XP (KB971029)
WD Diagnostics
WebFldrs XP
Windows Defender Signatures
Windows Imaging Component
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
Windows Management Framework Core
Windows Media Format 11 runtime
Windows Messenger 5.1
Windows Rights Management Client Backwards Compatibility SP2
Windows Rights Management Client with Service Pack 2
Windows XP Service Pack 3
WordPerfect Office 11
XML Paper Specification Shared Components Pack 1.0
XVID Codec Installation
ZoneAlarm Antivirus
ZoneAlarm LTD Toolbar
.
==== End Of File ===========================
MrCharlie
Welcome to the forum.
Please remove any usb or external drives from the computer before you run this scan!
Please download and run RogueKiller to your desktop.
http://tigzy.geekstogo.com/Tools/RogueKillerX64.exe <—use this one for 64 bit systems
Quit all running programs.
For Windows XP, double-click to start.
For Vista or Windows 7-8, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.
Click Scan to scan the system.
When the scan completes > Close out the program > Don't Fix anything!
Don't run any other options, they're not all bad!!!!!!!
Post back the report which should be located on your desktop.
MrC
Please remove any usb or external drives from the computer before you run this scan!
Please download and run RogueKiller to your desktop.
http://tigzy.geekstogo.com/Tools/RogueKillerX64.exe <—use this one for 64 bit systems
Quit all running programs.
For Windows XP, double-click to start.
For Vista or Windows 7-8, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.
Click Scan to scan the system.
When the scan completes > Close out the program > Don't Fix anything!
Don't run any other options, they're not all bad!!!!!!!
Post back the report which should be located on your desktop.
MrC
karenoregon
Mr. C:
Thanks for helping me. I ran the Rogue Killer twice and it does not produce a report. I will post the items that are showing after the scan.
Thanks,
Karen
Posting:
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: +++++
— User —
[MBR] 4e653a2a6234a6be6ae4b0dbeb097c9f
[BSP] f49789793de47e240f41ae14e0e5fc8e : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 38154 Mo
Error reading LL1 MBR!
Error reading LL2 MBR!
——–127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com——–
——————–
Six items were also found in the Processes area, but Rogue Killer will not let me copy them to past here.
HJPOL, HKLM
HJ, HKLM
HJ, HKCU
HJSMENU, HKCU
HJ DESK, HKLM
WALLP, HKCU
—————————–
MrCharlie
OK…please do this:
Please read the directions carefully so you don't end up deleting something that is good!!
If in doubt about an entry….please ask or choose Skip!!!!
If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
Skip and click on Continue
If a suspicious object is detected, the default action will be Skip, click on Continue
Please note that TDSSKiller can be run in safe mode if needed.
Here's a video that explains how to run it if needed:
How To Run TDSSKiller
Please download the latest version of TDSSKiller from here and save it to your Desktop.
If in doubt about an entry….please ask or choose Skip
If a suspicious object is detected, the default action will be Skip, click on Continue
If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
Skip and click on Continue
Any entries like this: \Device\Harddisk0\DR0 ( TDSS File System ) - please choose Skip.
If malicious objects are found, they will show in the Scan results and offer three (3) options.
Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
MrC
Please read the directions carefully so you don't end up deleting something that is good!!
If in doubt about an entry….please ask or choose Skip!!!!
If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
Skip and click on Continue
If a suspicious object is detected, the default action will be Skip, click on Continue
Please note that TDSSKiller can be run in safe mode if needed.
Here's a video that explains how to run it if needed:
How To Run TDSSKiller
Please download the latest version of TDSSKiller from here and save it to your Desktop.
- Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
[external image: Posted Image]
- Put a checkmark beside loaded modules.
[external image: Posted Image]
- A reboot will be needed to apply the changes. Do it.
- TDSSKiller will launch automatically after the reboot. Also your computer may seem very slow and unusable. This is normal. Give it enough time to load your background programs.
- Then click on Change parameters in TDSSKiller.
- Check all boxes then click OK.
[external image: Posted Image]
- Click the Start Scan button.
[external image: Posted Image]
- The scan should take no longer than 2 minutes.
- If a suspicious object is detected, the default action will be Skip, click on Continue.
[external image: Posted Image]
Any entries like this: \Device\Harddisk0\DR0 ( TDSS File System ) - please choose Skip.
If in doubt about an entry….please ask or choose Skip
- If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
[external image: Posted Image]
Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed. - A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here. There may be 3 logs > so post or attach all of them.
- Sometimes these logs can be very large, in that case please attach it or zip it up and attach it.
Here's a summary of what to do if you would like to print it out:
If in doubt about an entry….please ask or choose Skip
If a suspicious object is detected, the default action will be Skip, click on Continue
If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
Skip and click on Continue
Any entries like this: \Device\Harddisk0\DR0 ( TDSS File System ) - please choose Skip.
If malicious objects are found, they will show in the Scan results and offer three (3) options.
Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
MrC
karenoregon
Hi Mr. Charlie:
Here are the two reports generated after the TDS Killer scan.
Posting:
10:56:34.0546 3668 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
10:56:35.0671 3668 ============================================================
10:56:35.0671 3668 Current date / time: 2013/02/13 10:56:35.0671
10:56:35.0671 3668 SystemInfo:
10:56:35.0671 3668
10:56:35.0671 3668 OS Version: 5.1.2600 ServicePack: 3.0
10:56:35.0671 3668 Product type: Workstation
10:56:35.0671 3668 ComputerName: KURTCOMPUTER
10:56:35.0671 3668 UserName: Owner
10:56:35.0671 3668 Windows directory: C:\WINDOWS
10:56:35.0671 3668 System windows directory: C:\WINDOWS
10:56:35.0671 3668 Processor architecture: Intel x86
10:56:35.0671 3668 Number of processors: 1
10:56:35.0671 3668 Page size: 0x1000
10:56:35.0671 3668 Boot type: Normal boot
10:56:35.0671 3668 ============================================================
10:56:39.0265 3668 Drive \Device\Harddisk0\DR0 - Size: 0x9516AE000 (37.27 Gb), SectorSize: 0x200, Cylinders: 0x1301, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
10:56:39.0296 3668 ============================================================
10:56:39.0296 3668 \Device\Harddisk0\DR0:
10:56:39.0296 3668 MBR partitions:
10:56:39.0296 3668 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x4A852C1
10:56:39.0296 3668 ============================================================
10:56:39.0343 3668 C: <-> \Device\Harddisk0\DR0\Partition1
10:56:39.0343 3668 ============================================================
10:56:39.0343 3668 Initialize success
10:56:39.0343 3668 ============================================================
10:57:40.0218 3820 Deinitialize success
———————–
10:59:57.0250 2780 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
10:59:59.0296 2780 ============================================================
10:59:59.0296 2780 Current date / time: 2013/02/13 10:59:59.0296
10:59:59.0296 2780 SystemInfo:
10:59:59.0296 2780
10:59:59.0296 2780 OS Version: 5.1.2600 ServicePack: 3.0
10:59:59.0312 2780 Product type: Workstation
10:59:59.0312 2780 ComputerName: KURTCOMPUTER
10:59:59.0312 2780 UserName: Owner
10:59:59.0312 2780 Windows directory: C:\WINDOWS
10:59:59.0312 2780 System windows directory: C:\WINDOWS
10:59:59.0312 2780 Processor architecture: Intel x86
10:59:59.0312 2780 Number of processors: 1
10:59:59.0312 2780 Page size: 0x1000
10:59:59.0343 2780 Boot type: Normal boot
10:59:59.0343 2780 ============================================================
11:00:15.0375 2780 BG loaded
11:00:16.0484 2780 Drive \Device\Harddisk0\DR0 - Size: 0x9516AE000 (37.27 Gb), SectorSize: 0x200, Cylinders: 0x1301, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
11:00:16.0484 2780 ============================================================
11:00:16.0484 2780 \Device\Harddisk0\DR0:
11:00:16.0515 2780 MBR partitions:
11:00:16.0515 2780 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x4A852C1
11:00:16.0515 2780 ============================================================
11:00:16.0531 2780 C: <-> \Device\Harddisk0\DR0\Partition1
11:00:16.0531 2780 ============================================================
11:00:16.0531 2780 Initialize success
11:00:16.0531 2780 ============================================================
11:00:43.0750 3772 ============================================================
11:00:43.0750 3772 Scan started
11:00:43.0750 3772 Mode: Manual; SigCheck; TDLFS;
11:00:43.0750 3772 ============================================================
11:00:45.0281 3772 ================ Scan system memory ========================
11:00:45.0312 3772 System memory - ok
11:00:45.0328 3772 ================ Scan services =============================
11:00:46.0015 3772 [ 01E81C84AD1D0ACC61CF3CFD06632210 ] !SASCORE C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
11:00:46.0562 3772 !SASCORE - ok
11:00:47.0437 3772 Abiosdsk - ok
11:00:47.0468 3772 abp480n5 - ok
11:00:47.0640 3772 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
11:00:54.0703 3772 ACPI - ok
11:00:54.0796 3772 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
11:00:55.0390 3772 ACPIEC - ok
11:00:55.0406 3772 adpu160m - ok
11:00:55.0765 3772 [ CBFAA333EBA2E402A0439A3A0E5413F3 ] AdvancedSystemCareService6 C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe
11:00:55.0921 3772 AdvancedSystemCareService6 - ok
11:00:56.0031 3772 [ 11C04B17ED2ABBB4833694BCD644AC90 ] aeaudio C:\WINDOWS\system32\drivers\aeaudio.sys
11:00:56.0187 3772 aeaudio - ok
11:00:56.0265 3772 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
11:00:56.0562 3772 aec - ok
11:00:56.0625 3772 [ A7B8A3A79D35215D798A300DF49ED23F ] Afc C:\WINDOWS\system32\drivers\Afc.sys
11:00:56.0718 3772 Afc ( UnsignedFile.Multi.Generic ) - warning
11:00:56.0718 3772 Afc - detected UnsignedFile.Multi.Generic (1)
11:00:56.0796 3772 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
11:00:56.0984 3772 AFD - ok
11:00:57.0000 3772 Aha154x - ok
11:00:57.0031 3772 aic78u2 - ok
11:00:57.0046 3772 aic78xx - ok
11:00:57.0109 3772 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
11:00:57.0640 3772 Alerter - ok
11:00:57.0687 3772 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe
11:00:57.0828 3772 ALG - ok
11:00:57.0843 3772 AliIde - ok
11:00:57.0875 3772 amsint - ok
11:00:57.0890 3772 AppMgmt - ok
11:00:57.0921 3772 asc - ok
11:00:57.0953 3772 asc3350p - ok
11:00:57.0968 3772 asc3550 - ok
11:00:58.0187 3772 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
11:00:58.0546 3772 aspnet_state - ok
11:00:58.0593 3772 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
11:00:58.0875 3772 AsyncMac - ok
11:00:58.0906 3772 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
11:00:59.0250 3772 atapi - ok
11:00:59.0281 3772 Atdisk - ok
11:00:59.0343 3772 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
11:00:59.0656 3772 Atmarpc - ok
11:00:59.0718 3772 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
11:01:00.0093 3772 AudioSrv - ok
11:01:00.0171 3772 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
11:01:00.0500 3772 audstub - ok
11:01:00.0562 3772 [ 5D7BE7B19E827125E016325334E58FF1 ] BANTExt C:\WINDOWS\System32\Drivers\BANTExt.sys
11:01:00.0640 3772 BANTExt ( UnsignedFile.Multi.Generic ) - warning
11:01:00.0640 3772 BANTExt - detected UnsignedFile.Multi.Generic (1)
11:01:00.0734 3772 [ B60F57B4D9CDBC663CC03EB8AF7EC34E ] bcm4sbxp C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
11:01:00.0875 3772 bcm4sbxp - ok
11:01:01.0140 3772 [ 41347688046D49CDE0F6D138A534F73D ] BCMModem C:\WINDOWS\system32\DRIVERS\BCMSM.sys
11:01:01.0359 3772 BCMModem - ok
11:01:01.0453 3772 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
11:01:01.0750 3772 Beep - ok
11:01:02.0046 3772 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll
11:01:04.0234 3772 BITS - ok
11:01:04.0312 3772 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll
11:01:04.0484 3772 Browser - ok
11:01:04.0500 3772 catchme - ok
11:01:04.0562 3772 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
11:01:04.0937 3772 cbidf2k - ok
11:01:05.0000 3772 [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
11:01:05.0328 3772 CCDECODE - ok
11:01:05.0343 3772 cd20xrnt - ok
11:01:05.0406 3772 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
11:01:05.0718 3772 Cdaudio - ok
11:01:05.0796 3772 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
11:01:06.0156 3772 Cdfs - ok
11:01:06.0203 3772 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
11:01:06.0546 3772 Cdrom - ok
11:01:06.0625 3772 [ 8F9347656BEBDF8225D7B7A948CD043F ] ch7009 C:\WINDOWS\system32\DRIVERS\ch7009.sys
11:01:06.0796 3772 ch7009 ( UnsignedFile.Multi.Generic ) - warning
11:01:06.0796 3772 ch7009 - detected UnsignedFile.Multi.Generic (1)
11:01:06.0828 3772 [ 9B17BCD1F4FCD3798F0DAB8CA268EC93 ] ch7017 C:\WINDOWS\system32\DRIVERS\ch7017.sys
11:01:06.0906 3772 ch7017 ( UnsignedFile.Multi.Generic ) - warning
11:01:06.0906 3772 ch7017 - detected UnsignedFile.Multi.Generic (1)
11:01:06.0937 3772 Changer - ok
11:01:06.0984 3772 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe
11:01:07.0343 3772 CiSvc - ok
11:01:07.0453 3772 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
11:01:07.0796 3772 ClipSrv - ok
11:01:07.0875 3772 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:01:08.0796 3772 clr_optimization_v2.0.50727_32 - ok
11:01:10.0046 3772 [ DAA199690ED70FFE5765FBC3BCB48E7C ] cmdAgent C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
11:01:10.0781 3772 cmdAgent - ok
11:01:10.0859 3772 [ 60F9E45290DF5209DE2756812B3414C6 ] cmderd C:\WINDOWS\system32\DRIVERS\cmderd.sys
11:01:10.0906 3772 cmderd - ok
11:01:11.0000 3772 [ 7B470691BF8494AE294C0B4C546899ED ] cmdGuard C:\WINDOWS\system32\DRIVERS\cmdguard.sys
11:01:11.0140 3772 cmdGuard - ok
11:01:11.0203 3772 [ DD3EC4E63708D3519F6E4418AC5203A8 ] cmdHlp C:\WINDOWS\system32\DRIVERS\cmdhlp.sys
11:01:11.0265 3772 cmdHlp - ok
11:01:11.0281 3772 CmdIde - ok
11:01:11.0500 3772 [ 2BB9FB821D508758916CF4C78E68694A ] cmdvirth C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
11:01:11.0562 3772 cmdvirth - ok
11:01:11.0625 3772 [ 7A0B457EEFEF8CBAA0CC44C8819113BD ] CoachUsb C:\WINDOWS\system32\DRIVERS\CoachUsb.sys
11:01:11.0687 3772 CoachUsb ( UnsignedFile.Multi.Generic ) - warning
11:01:11.0687 3772 CoachUsb - detected UnsignedFile.Multi.Generic (1)
11:01:11.0703 3772 CoachVc - ok
11:01:11.0718 3772 COMSysApp - ok
11:01:11.0765 3772 Cpqarray - ok
11:01:11.0781 3772 Crypkey License - ok
11:01:11.0875 3772 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
11:01:12.0218 3772 CryptSvc - ok
11:01:12.0296 3772 [ EEA4EAB0CCB70A625055988976777CEB ] d3dUtil C:\WINDOWS\system32\DRIVERS\d3dutil.sys
11:01:12.0359 3772 d3dUtil ( UnsignedFile.Multi.Generic ) - warning
11:01:12.0359 3772 d3dUtil - detected UnsignedFile.Multi.Generic (1)
11:01:12.0390 3772 dac2w2k - ok
11:01:12.0421 3772 dac960nt - ok
11:01:12.0515 3772 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
11:01:12.0796 3772 DcomLaunch - ok
11:01:12.0906 3772 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
11:01:13.0265 3772 Dhcp - ok
11:01:13.0328 3772 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
11:01:13.0625 3772 Disk - ok
11:01:13.0656 3772 dmadmin - ok
11:01:13.0765 3772 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
11:01:14.0281 3772 dmboot - ok
11:01:14.0328 3772 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys
11:01:14.0656 3772 dmio - ok
11:01:14.0718 3772 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
11:01:15.0062 3772 dmload - ok
11:01:15.0125 3772 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll
11:01:15.0468 3772 dmserver - ok
11:01:15.0546 3772 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
11:01:15.0906 3772 DMusic - ok
11:01:15.0984 3772 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
11:01:16.0343 3772 Dnscache - ok
11:01:16.0406 3772 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
11:01:17.0578 3772 Dot3svc - ok
11:01:17.0593 3772 dpti2o - ok
11:01:17.0671 3772 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
11:01:17.0984 3772 drmkaud - ok
11:01:18.0000 3772 DwProt - ok
11:01:18.0062 3772 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll
11:01:18.0453 3772 EapHost - ok
11:01:18.0500 3772 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll
11:01:18.0828 3772 ERSvc - ok
11:01:18.0890 3772 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe
11:01:19.0031 3772 Eventlog - ok
11:01:19.0109 3772 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll
11:01:19.0218 3772 EventSystem - ok
11:01:19.0296 3772 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
11:01:19.0593 3772 Fastfat - ok
11:01:19.0671 3772 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
11:01:20.0000 3772 FastUserSwitchingCompatibility - ok
11:01:20.0062 3772 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
11:01:20.0406 3772 Fdc - ok
11:01:20.0468 3772 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
11:01:20.0812 3772 Fips - ok
11:01:20.0890 3772 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
11:01:21.0296 3772 Flpydisk - ok
11:01:21.0500 3772 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
11:01:21.0781 3772 FltMgr - ok
11:01:21.0906 3772 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
11:01:22.0031 3772 FontCache3.0.0.0 - ok
11:01:22.0093 3772 [ 32C98379A90968103D01B256A9BAEA28 ] fs454 C:\WINDOWS\system32\DRIVERS\fs454.sys
11:01:22.0171 3772 fs454 ( UnsignedFile.Multi.Generic ) - warning
11:01:22.0171 3772 fs454 - detected UnsignedFile.Multi.Generic (1)
11:01:22.0312 3772 [ E0087225B137E57239FF40F8AE82059B ] fssfltr C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys
11:01:22.0343 3772 fssfltr - ok
11:01:22.0687 3772 [ 45B52394F9624237F33A8A3D73C0B221 ] fsssvc C:\Program Files\Windows Live\Family Safety\fsssvc.exe
11:01:23.0203 3772 fsssvc - ok
11:01:23.0328 3772 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
11:01:23.0687 3772 Fs_Rec - ok
11:01:23.0765 3772 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
11:01:24.0093 3772 Ftdisk - ok
11:01:24.0171 3772 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
11:01:24.0531 3772 Gpc - ok
11:01:24.0656 3772 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
11:01:24.0703 3772 gupdate - ok
11:01:24.0718 3772 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
11:01:24.0765 3772 gupdatem - ok
11:01:24.0843 3772 helpsvc - ok
11:01:24.0859 3772 HidServ - ok
11:01:24.0921 3772 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
11:01:25.0218 3772 hkmsvc - ok
11:01:25.0250 3772 hpn - ok
11:01:25.0437 3772 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
11:01:25.0546 3772 HTTP - ok
11:01:25.0625 3772 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
11:01:26.0343 3772 HTTPFilter - ok
11:01:26.0375 3772 i2omgmt - ok
11:01:26.0390 3772 i2omp - ok
11:01:26.0484 3772 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
11:01:26.0812 3772 i8042prt - ok
11:01:27.0046 3772 [ 44B7D5A4F2BD9FE21AEA0BB0BACE38C4 ] ialm C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
11:01:27.0265 3772 ialm - ok
11:01:27.0515 3772 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
11:01:27.0687 3772 idsvc - ok
11:01:27.0796 3772 [ 31B9783E002B67A623EB04AE8638AD93 ] igdmini C:\WINDOWS\system32\DRIVERS\igdmini.sys
11:01:27.0828 3772 igdmini ( UnsignedFile.Multi.Generic ) - warning
11:01:27.0828 3772 igdmini - detected UnsignedFile.Multi.Generic (1)
11:01:27.0890 3772 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
11:01:28.0234 3772 Imapi - ok
11:01:28.0531 3772 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe
11:01:28.0875 3772 ImapiService - ok
11:01:28.0937 3772 ini910u - ok
11:01:29.0031 3772 [ 5FDF42923656BF77DD5D7A5D8D0E1268 ] Inspect C:\WINDOWS\system32\DRIVERS\inspect.sys
11:01:29.0093 3772 Inspect - ok
11:01:29.0156 3772 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys
11:01:29.0500 3772 IntelIde - ok
11:01:29.0546 3772 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
11:01:29.0843 3772 intelppm - ok
11:01:29.0890 3772 [ 3BB22519A194418D5FEC05D800A19AD0 ] ip6fw C:\WINDOWS\system32\drivers\ip6fw.sys
11:01:30.0187 3772 ip6fw - ok
11:01:30.0281 3772 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
11:01:30.0578 3772 IpFilterDriver - ok
11:01:30.0625 3772 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
11:01:30.0921 3772 IpInIp - ok
11:01:31.0093 3772 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
11:01:31.0437 3772 IpNat - ok
11:01:31.0500 3772 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
11:01:31.0812 3772 IPSec - ok
11:01:31.0875 3772 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
11:01:32.0046 3772 IRENUM - ok
11:01:32.0140 3772 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
11:01:32.0468 3772 isapnp - ok
11:01:32.0546 3772 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
11:01:32.0828 3772 Kbdclass - ok
11:01:32.0906 3772 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
11:01:33.0250 3772 kmixer - ok
11:01:33.0343 3772 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
11:01:33.0593 3772 KSecDD - ok
11:01:33.0671 3772 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
11:01:33.0843 3772 lanmanserver - ok
11:01:33.0937 3772 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
11:01:34.0140 3772 lanmanworkstation - ok
11:01:34.0171 3772 lbrtfdc - ok
11:01:34.0250 3772 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
11:01:34.0578 3772 LmHosts - ok
11:01:34.0625 3772 [ E6BA9E361BD6513EF800DD6E1AA389EF ] lvds C:\WINDOWS\system32\DRIVERS\lvds.sys
11:01:34.0703 3772 lvds ( UnsignedFile.Multi.Generic ) - warning
11:01:34.0703 3772 lvds - detected UnsignedFile.Multi.Generic (1)
11:01:35.0015 3772 [ F8B823414A22DBF3BEC10DCAA5F93CD8 ] McciCMService C:\Program Files\Common Files\Motive\McciCMService.exe
11:01:35.0078 3772 McciCMService ( UnsignedFile.Multi.Generic ) - warning
11:01:35.0078 3772 McciCMService - detected UnsignedFile.Multi.Generic (1)
11:01:35.0140 3772 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll
11:01:35.0453 3772 Messenger - ok
11:01:35.0500 3772 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
11:01:35.0984 3772 mnmdd - ok
11:01:36.0046 3772 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\System32\mnmsrvc.exe
11:01:36.0375 3772 mnmsrvc - ok
11:01:36.0453 3772 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
11:01:36.0765 3772 Modem - ok
11:01:36.0828 3772 [ 1992E0D143B09653AB0F9C5E04B0FD65 ] MODEMCSA C:\WINDOWS\system32\drivers\MODEMCSA.sys
11:01:37.0140 3772 MODEMCSA - ok
11:01:37.0203 3772 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
11:01:37.0546 3772 Mouclass - ok
11:01:37.0593 3772 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
11:01:37.0937 3772 MountMgr - ok
11:01:37.0953 3772 mraid35x - ok
11:01:38.0015 3772 [ 9BD4DCB5412921864A7AACDEDFBD1923 ] MREMP50 C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
11:01:38.0046 3772 MREMP50 ( UnsignedFile.Multi.Generic ) - warning
11:01:38.0046 3772 MREMP50 - detected UnsignedFile.Multi.Generic (1)
11:01:38.0109 3772 [ 2BC9E43F55DE8C30FC817ED56D0EE907 ] MREMPR5 C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS
11:01:38.0187 3772 MREMPR5 ( UnsignedFile.Multi.Generic ) - warning
11:01:38.0187 3772 MREMPR5 - detected UnsignedFile.Multi.Generic (1)
11:01:38.0281 3772 [ 594B9D8194E3F4ECBF0325BD10BBEB05 ] MRENDIS5 C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS
11:01:38.0359 3772 MRENDIS5 ( UnsignedFile.Multi.Generic ) - warning
11:01:38.0359 3772 MRENDIS5 - detected UnsignedFile.Multi.Generic (1)
11:01:38.0437 3772 [ 07C02C892E8E1A72D6BF35004F0E9C5E ] MRESP50 C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
11:01:38.0468 3772 MRESP50 ( UnsignedFile.Multi.Generic ) - warning
11:01:38.0468 3772 MRESP50 - detected UnsignedFile.Multi.Generic (1)
11:01:38.0531 3772 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
11:01:38.0812 3772 MRxDAV - ok
11:01:39.0015 3772 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
11:01:39.0203 3772 MRxSmb - ok
11:01:39.0281 3772 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\System32\msdtc.exe
11:01:39.0609 3772 MSDTC - ok
11:01:39.0687 3772 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
11:01:40.0015 3772 Msfs - ok
11:01:40.0031 3772 MSIServer - ok
11:01:40.0078 3772 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
11:01:40.0359 3772 MSKSSRV - ok
11:01:40.0406 3772 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
11:01:40.0687 3772 MSPCLOCK - ok
11:01:40.0718 3772 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
11:01:40.0984 3772 MSPQM - ok
11:01:41.0046 3772 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
11:01:41.0328 3772 mssmbios - ok
11:01:41.0390 3772 [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys
11:01:41.0687 3772 MSTEE - ok
11:01:41.0781 3772 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
11:01:41.0859 3772 Mup - ok
11:01:41.0937 3772 [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
11:01:42.0218 3772 NABTSFEC - ok
11:01:42.0359 3772 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll
11:01:42.0671 3772 napagent - ok
11:01:42.0765 3772 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
11:01:43.0031 3772 NDIS - ok
11:01:43.0093 3772 [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys
11:01:43.0437 3772 NdisIP - ok
11:01:43.0515 3772 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
11:01:43.0625 3772 NdisTapi - ok
11:01:43.0656 3772 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
11:01:43.0937 3772 Ndisuio - ok
11:01:44.0000 3772 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
11:01:44.0328 3772 NdisWan - ok
11:01:44.0421 3772 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
11:01:44.0593 3772 NDProxy - ok
11:01:44.0640 3772 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
11:01:44.0953 3772 NetBIOS - ok
11:01:45.0031 3772 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
11:01:45.0281 3772 NetBT - ok
11:01:45.0359 3772 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
11:01:45.0625 3772 NetDDE - ok
11:01:45.0656 3772 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
11:01:45.0937 3772 NetDDEdsdm - ok
11:01:46.0000 3772 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
11:01:46.0312 3772 Netlogon - ok
11:01:46.0390 3772 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
11:01:46.0703 3772 Netman - ok
11:01:46.0765 3772 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
11:01:46.0812 3772 NetTcpPortSharing - ok
11:01:46.0875 3772 [ 5EF7DD401771693245D46F4B0B69FE2B ] NetworkX C:\WINDOWS\system32\ckldrv.sys
11:01:46.0953 3772 NetworkX ( UnsignedFile.Multi.Generic ) - warning
11:01:46.0953 3772 NetworkX - detected UnsignedFile.Multi.Generic (1)
11:01:47.0062 3772 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
11:01:47.0187 3772 Nla - ok
11:01:47.0250 3772 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
11:01:47.0640 3772 Npfs - ok
11:01:47.0718 3772 [ DC23BF0190ACAA6FE49579B99474C931 ] ns2501 C:\WINDOWS\system32\DRIVERS\ns2501.sys
11:01:47.0750 3772 ns2501 ( UnsignedFile.Multi.Generic ) - warning
11:01:47.0750 3772 ns2501 - detected UnsignedFile.Multi.Generic (1)
11:01:47.0781 3772 [ 1D35A6DAD47330B8DA57130F9A924D98 ] ns387 C:\WINDOWS\system32\DRIVERS\ns387.sys
11:01:47.0812 3772 ns387 ( UnsignedFile.Multi.Generic ) - warning
11:01:47.0812 3772 ns387 - detected UnsignedFile.Multi.Generic (1)
11:01:48.0171 3772 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
11:01:48.0578 3772 Ntfs - ok
11:01:48.0640 3772 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\System32\lsass.exe
11:01:48.0921 3772 NtLmSsp - ok
11:01:49.0046 3772 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
11:01:49.0343 3772 NtmsSvc - ok
11:01:49.0437 3772 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
11:01:49.0734 3772 Null - ok
11:01:49.0781 3772 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
11:01:50.0062 3772 NwlnkFlt - ok
11:01:50.0109 3772 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
11:01:50.0406 3772 NwlnkFwd - ok
11:01:50.0453 3772 [ 8B8B1BE2DBA4025DA6786C645F77F123 ] NwlnkIpx C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys
11:01:50.0781 3772 NwlnkIpx - ok
11:01:50.0828 3772 [ 56D34A67C05E94E16377C60609741FF8 ] NwlnkNb C:\WINDOWS\system32\DRIVERS\nwlnknb.sys
11:01:51.0156 3772 NwlnkNb - ok
11:01:51.0234 3772 [ C0BB7D1615E1ACBDC99757F6CEAF8CF0 ] NwlnkSpx C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys
11:01:51.0546 3772 NwlnkSpx - ok
11:01:51.0640 3772 [ 4B83FCBBE72AF5F99D109798653E8B78 ] NwSapAgent C:\WINDOWS\System32\ipxsap.dll
11:01:51.0890 3772 NwSapAgent - ok
11:01:51.0937 3772 [ CEC7E2C6C1FA00C7AB2F5434F848AE51 ] OMCI C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS
11:01:52.0000 3772 OMCI ( UnsignedFile.Multi.Generic ) - warning
11:01:52.0000 3772 OMCI - detected UnsignedFile.Multi.Generic (1)
11:01:52.0109 3772 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
11:01:52.0390 3772 Parport - ok
11:01:52.0437 3772 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
11:01:52.0718 3772 PartMgr - ok
11:01:52.0765 3772 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
11:01:53.0015 3772 ParVdm - ok
11:01:53.0140 3772 [ 2DD9D5A9150C7015AC7F215EFA59E44F ] PCDSRVC{E9D79540-57D5953E-06020200}_0 c:\program files\dell support center\pcdsrvc.pkms
11:01:53.0265 3772 PCDSRVC{E9D79540-57D5953E-06020200}_0 - ok
11:01:53.0328 3772 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
11:01:53.0609 3772 PCI - ok
11:01:53.0640 3772 PCIDump - ok
11:01:53.0718 3772 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\drivers\PCIIde.sys
11:01:54.0000 3772 PCIIde - ok
11:01:54.0093 3772 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
11:01:54.0390 3772 Pcmcia - ok
11:01:54.0421 3772 PDCOMP - ok
11:01:54.0453 3772 PDFRAME - ok
11:01:54.0484 3772 PDRELI - ok
11:01:54.0500 3772 PDRFRAME - ok
11:01:54.0531 3772 perc2 - ok
11:01:54.0562 3772 perc2hib - ok
11:01:54.0656 3772 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
11:01:54.0781 3772 PlugPlay - ok
11:01:55.0015 3772 [ 627FA58ADC043704F9D14CA44340956F ] PMBDeviceInfoProvider C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
11:01:55.0359 3772 PMBDeviceInfoProvider - ok
11:01:55.0406 3772 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
11:01:55.0656 3772 PolicyAgent - ok
11:01:55.0718 3772 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
11:01:56.0031 3772 PptpMiniport - ok
11:01:56.0093 3772 [ A32BEBAF723557681BFC6BD93E98BD26 ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys
11:01:56.0421 3772 Processor - ok
11:01:56.0484 3772 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
11:01:56.0750 3772 ProtectedStorage - ok
11:01:56.0828 3772 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
11:01:57.0093 3772 PSched - ok
11:01:57.0203 3772 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
11:01:57.0546 3772 Ptilink - ok
11:01:57.0625 3772 [ 49452BFCEC22F36A7A9B9C2181BC3042 ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys
11:01:57.0671 3772 PxHelp20 - ok
11:01:57.0703 3772 ql1080 - ok
11:01:57.0718 3772 Ql10wnt - ok
11:01:57.0750 3772 ql12160 - ok
11:01:57.0781 3772 ql1240 - ok
11:01:57.0812 3772 ql1280 - ok
11:01:57.0859 3772 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
11:01:58.0093 3772 RasAcd - ok
11:01:58.0156 3772 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
11:01:58.0453 3772 RasAuto - ok
11:01:58.0515 3772 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
11:01:58.0843 3772 Rasl2tp - ok
11:01:58.0921 3772 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
11:01:59.0234 3772 RasMan - ok
11:01:59.0296 3772 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
11:01:59.0609 3772 RasPppoe - ok
11:01:59.0640 3772 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
11:01:59.0937 3772 Raspti - ok
11:02:00.0062 3772 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
11:02:00.0328 3772 Rdbss - ok
11:02:00.0390 3772 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
11:02:00.0703 3772 RDPCDD - ok
11:02:00.0812 3772 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
11:02:01.0000 3772 RDPWD - ok
11:02:01.0062 3772 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
11:02:01.0343 3772 RDSessMgr - ok
11:02:01.0421 3772 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
11:02:01.0750 3772 redbook - ok
11:02:01.0812 3772 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
11:02:02.0109 3772 RemoteAccess - ok
11:02:02.0171 3772 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\System32\locator.exe
11:02:02.0421 3772 RpcLocator - ok
11:02:02.0515 3772 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll
11:02:02.0656 3772 RpcSs - ok
11:02:02.0718 3772 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\System32\rsvp.exe
11:02:03.0031 3772 RSVP - ok
11:02:03.0078 3772 SABProcEnum - ok
11:02:03.0125 3772 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
11:02:03.0390 3772 SamSs - ok
11:02:03.0468 3772 [ 39763504067962108505BFF25F024345 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
11:02:03.0515 3772 SASDIFSV - ok
11:02:03.0562 3772 [ 77B9FC20084B48408AD3E87570EB4A85 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
11:02:03.0609 3772 SASKUTIL - ok
11:02:03.0640 3772 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
11:02:03.0953 3772 SCardSvr - ok
11:02:04.0031 3772 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
11:02:04.0328 3772 Schedule - ok
11:02:04.0406 3772 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
11:02:04.0546 3772 Secdrv - ok
11:02:04.0625 3772 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
11:02:04.0968 3772 seclogon - ok
11:02:05.0031 3772 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll
11:02:05.0328 3772 SENS - ok
11:02:05.0390 3772 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
11:02:05.0906 3772 serenum - ok
11:02:05.0921 3772 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
11:02:06.0562 3772 Serial - ok
11:02:06.0671 3772 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
11:02:07.0156 3772 Sfloppy - ok
11:02:07.0312 3772 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
11:02:07.0609 3772 SharedAccess - ok
11:02:07.0671 3772 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
11:02:07.0734 3772 ShellHWDetection - ok
11:02:07.0796 3772 [ 2327F5FFA223EC9B415F4A0CDBDF4EE1 ] sii164 C:\WINDOWS\system32\DRIVERS\sii164.sys
11:02:07.0843 3772 sii164 ( UnsignedFile.Multi.Generic ) - warning
11:02:07.0843 3772 sii164 - detected UnsignedFile.Multi.Generic (1)
11:02:07.0875 3772 Simbad - ok
11:02:07.0937 3772 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys
11:02:08.0234 3772 SLIP - ok
11:02:08.0328 3772 [ 14BB60A4F1C5291217A05D5728C403E6 ] SmartDefragDriver C:\WINDOWS\system32\Drivers\SmartDefragDriver.sys
11:02:08.0390 3772 SmartDefragDriver - ok
11:02:08.0515 3772 [ 31FD0707C7DBE715234F2823B27214FE ] smwdm C:\WINDOWS\system32\drivers\smwdm.sys
11:02:08.0625 3772 smwdm - ok
11:02:08.0656 3772 Sparrow - ok
11:02:08.0703 3772 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
11:02:08.0953 3772 splitter - ok
11:02:09.0031 3772 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
11:02:09.0234 3772 Spooler - ok
11:02:09.0296 3772 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
11:02:09.0453 3772 sr - ok
11:02:09.0515 3772 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
11:02:09.0656 3772 srservice - ok
11:02:09.0734 3772 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
11:02:09.0921 3772 Srv - ok
11:02:10.0046 3772 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
11:02:10.0203 3772 SSDPSRV - ok
11:02:10.0265 3772 [ EE74E3B1B521CEF8E8C9D008E4BDB45C ] STAC97 C:\WINDOWS\system32\drivers\STAC97.sys
11:02:10.0343 3772 STAC97 ( UnsignedFile.Multi.Generic ) - warning
11:02:10.0343 3772 STAC97 - detected UnsignedFile.Multi.Generic (1)
11:02:10.0468 3772 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
11:02:10.0812 3772 stisvc - ok
11:02:10.0859 3772 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys
11:02:11.0171 3772 streamip - ok
11:02:11.0203 3772 SVKP - ok
11:02:11.0265 3772 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
11:02:11.0562 3772 swenum - ok
11:02:11.0640 3772 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
11:02:11.0937 3772 swmidi - ok
11:02:11.0968 3772 SwPrv - ok
11:02:12.0015 3772 symc810 - ok
11:02:12.0031 3772 symc8xx - ok
11:02:12.0046 3772 sym_hi - ok
11:02:12.0078 3772 sym_u3 - ok
11:02:12.0125 3772 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
11:02:12.0390 3772 sysaudio - ok
11:02:12.0453 3772 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
11:02:12.0750 3772 SysmonLog - ok
11:02:12.0875 3772 SysProtDrv.sys - ok
11:02:12.0968 3772 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
11:02:13.0265 3772 TapiSrv - ok
11:02:13.0421 3772 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
11:02:13.0546 3772 Tcpip - ok
11:02:13.0609 3772 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
11:02:13.0937 3772 TDPIPE - ok
11:02:13.0968 3772 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
11:02:14.0250 3772 TDTCP - ok
11:02:14.0312 3772 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
11:02:14.0593 3772 TermDD - ok
11:02:14.0687 3772 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
11:02:14.0953 3772 TermService - ok
11:02:15.0031 3772 [ 201BE1C73FA333A8872AD738AC49B9B4 ] th164 C:\WINDOWS\system32\DRIVERS\th164.sys
11:02:15.0046 3772 th164 ( UnsignedFile.Multi.Generic ) - warning
11:02:15.0046 3772 th164 - detected UnsignedFile.Multi.Generic (1)
11:02:15.0125 3772 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
11:02:15.0187 3772 Themes - ok
11:02:15.0234 3772 [ AB9720ADBE304893516521D2E440BD45 ] ti410 C:\WINDOWS\system32\DRIVERS\ti410.sys
11:02:15.0296 3772 ti410 ( UnsignedFile.Multi.Generic ) - warning
11:02:15.0296 3772 ti410 - detected UnsignedFile.Multi.Generic (1)
11:02:15.0312 3772 TICalc - ok
11:02:15.0421 3772 [ DF8444A8FA8FD38D8848BDD40A8403B3 ] tmcomm C:\WINDOWS\system32\drivers\tmcomm.sys
11:02:15.0468 3772 tmcomm - ok
11:02:15.0484 3772 TosIde - ok
11:02:15.0546 3772 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
11:02:15.0828 3772 TrkWks - ok
11:02:15.0875 3772 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
11:02:16.0156 3772 Udfs - ok
11:02:16.0203 3772 ultra - ok
11:02:16.0343 3772 [ BB879DCFD22926EFBEB3298129898CBB ] UnlockerDriver5 C:\Program Files\Unlocker\UnlockerDriver5.sys
11:02:16.0359 3772 UnlockerDriver5 ( UnsignedFile.Multi.Generic ) - warning
11:02:16.0359 3772 UnlockerDriver5 - detected UnsignedFile.Multi.Generic (1)
11:02:16.0500 3772 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
11:02:16.0859 3772 Update - ok
11:02:16.0968 3772 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
11:02:17.0203 3772 upnphost - ok
11:02:17.0359 3772 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
11:02:17.0703 3772 UPS - ok
11:02:17.0765 3772 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
11:02:18.0031 3772 usbehci - ok
11:02:18.0093 3772 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
11:02:18.0390 3772 usbhub - ok
11:02:18.0437 3772 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
11:02:18.0734 3772 usbscan - ok
11:02:18.0781 3772 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
11:02:19.0046 3772 USBSTOR - ok
11:02:19.0078 3772 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
11:02:19.0343 3772 usbuhci - ok
11:02:19.0375 3772 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
11:02:19.0718 3772 VgaSave - ok
11:02:19.0734 3772 ViaIde - ok
11:02:19.0812 3772 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
11:02:20.0296 3772 VolSnap - ok
11:02:20.0578 3772 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
11:02:20.0843 3772 VSS - ok
11:02:20.0937 3772 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll
11:02:21.0234 3772 W32Time - ok
11:02:21.0296 3772 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
11:02:21.0593 3772 Wanarp - ok
11:02:21.0609 3772 WDICA - ok
11:02:21.0687 3772 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
11:02:21.0953 3772 wdmaud - ok
11:02:22.0046 3772 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
11:02:22.0421 3772 WebClient - ok
11:02:22.0609 3772 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
11:02:22.0859 3772 winmgmt - ok
11:02:23.0046 3772 [ 18F347402DA544A780949B8FDF83351B ] WinRM C:\WINDOWS\system32\WsmSvc.dll
11:02:23.0406 3772 WinRM - ok
11:02:23.0515 3772 [ 051B1BDECD6DEE18C771B5D5EC7F044D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
11:02:23.0687 3772 WmdmPmSN - ok
11:02:23.0765 3772 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\System32\wbem\wmiapsrv.exe
11:02:24.0031 3772 WmiApSrv - ok
11:02:24.0078 3772 [ C60DC16D4E406810FAD54B98DC92D5EC ] WpdUsb C:\WINDOWS\system32\Drivers\wpdusb.sys
11:02:24.0156 3772 WpdUsb - ok
11:02:24.0218 3772 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
11:02:24.0484 3772 WS2IFSL - ok
11:02:24.0546 3772 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
11:02:24.0812 3772 wscsvc - ok
11:02:24.0843 3772 WSearch - ok
11:02:24.0906 3772 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
11:02:25.0218 3772 WSTCODEC - ok
11:02:25.0296 3772 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll
11:02:25.0562 3772 wuauserv - ok
11:02:25.0625 3772 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
11:02:25.0718 3772 WudfPf - ok
11:02:25.0750 3772 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
11:02:25.0812 3772 WudfRd - ok
11:02:25.0859 3772 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
11:02:25.0937 3772 WudfSvc - ok
11:02:26.0734 3772 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
11:02:27.0046 3772 xmlprov - ok
11:02:27.0078 3772 zntport - ok
11:02:27.0156 3772 [ FD1F4E9CF06C71C8D73A24ACF18D8296 ] {6080A529-897E-4629-A488-ABA0C29B635E} C:\WINDOWS\system32\drivers\ialmsbw.sys
11:02:27.0671 3772 {6080A529-897E-4629-A488-ABA0C29B635E} - ok
11:02:27.0765 3772 [ D4D7331D33D1FA73E588E5CE0D90A4C1 ] {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} C:\WINDOWS\system32\drivers\ialmkchw.sys
11:02:27.0828 3772 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} - ok
11:02:27.0828 3772 ================ Scan global ===============================
11:02:27.0890 3772 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
11:02:28.0000 3772 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
11:02:28.0046 3772 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
11:02:28.0093 3772 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
11:02:28.0093 3772 [Global] - ok
11:02:28.0109 3772 ================ Scan MBR ==================================
11:02:28.0156 3772 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0
11:02:28.0468 3772 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
11:02:28.0468 3772 \Device\Harddisk0\DR0 - detected TDSS File System (1)
11:02:28.0468 3772 ================ Scan VBR ==================================
11:02:28.0484 3772 [ D1DAFF5B33FC746EBC58ADAEC37E6BBC ] \Device\Harddisk0\DR0\Partition1
11:02:28.0484 3772 \Device\Harddisk0\DR0\Partition1 - ok
11:02:28.0500 3772 ================ Scan active images ========================
11:02:28.0500 3772 [ 8C953733D8F36EB2133F5BB58808B66B ] C:\WINDOWS\system32\drivers\intelppm.sys
11:02:28.0500 3772 C:\WINDOWS\system32\drivers\intelppm.sys - ok
11:02:28.0515 3772 [ E28726B72C46821A28830E077D39A55B ] C:\WINDOWS\system32\drivers\videoprt.sys
11:02:28.0515 3772 C:\WINDOWS\system32\drivers\videoprt.sys - ok
11:02:28.0531 3772 [ 31B9783E002B67A623EB04AE8638AD93 ] C:\WINDOWS\system32\drivers\igdmini.sys
11:02:28.0531 3772 C:\WINDOWS\system32\drivers\igdmini.sys - ok
11:02:28.0562 3772 [ 791912E524CC2CC6F50B5F2B52D1EB71 ] C:\WINDOWS\system32\drivers\usbport.sys
11:02:28.0562 3772 C:\WINDOWS\system32\drivers\usbport.sys - ok
11:02:28.0578 3772 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] C:\WINDOWS\system32\drivers\usbuhci.sys
11:02:28.0578 3772 C:\WINDOWS\system32\drivers\usbuhci.sys - ok
11:02:28.0593 3772 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] C:\WINDOWS\system32\drivers\usbehci.sys
11:02:28.0593 3772 C:\WINDOWS\system32\drivers\usbehci.sys - ok
11:02:28.0609 3772 [ 0753515F78DF7F271A5E61C20BCD36A1 ] C:\WINDOWS\system32\drivers\ks.sys
11:02:28.0609 3772 C:\WINDOWS\system32\drivers\ks.sys - ok
11:02:28.0625 3772 [ 41347688046D49CDE0F6D138A534F73D ] C:\WINDOWS\system32\drivers\BCMSM.sys
11:02:28.0625 3772 C:\WINDOWS\system32\drivers\BCMSM.sys - ok
11:02:28.0640 3772 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] C:\WINDOWS\system32\drivers\modem.sys
11:02:28.0640 3772 C:\WINDOWS\system32\drivers\modem.sys - ok
11:02:28.0656 3772 [ B60F57B4D9CDBC663CC03EB8AF7EC34E ] C:\WINDOWS\system32\drivers\bcm4sbxp.sys
11:02:28.0656 3772 C:\WINDOWS\system32\drivers\bcm4sbxp.sys - ok
11:02:28.0671 3772 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] C:\WINDOWS\system32\drivers\fdc.sys
11:02:28.0671 3772 C:\WINDOWS\system32\drivers\fdc.sys - ok
11:02:28.0687 3772 [ 4A0B06AA8943C1E332520F7440C0AA30 ] C:\WINDOWS\system32\drivers\i8042prt.sys
11:02:28.0687 3772 C:\WINDOWS\system32\drivers\i8042prt.sys - ok
11:02:28.0703 3772 [ 463C1EC80CD17420A542B7F36A36F128 ] C:\WINDOWS\system32\drivers\kbdclass.sys
11:02:28.0703 3772 C:\WINDOWS\system32\drivers\kbdclass.sys - ok
11:02:28.0718 3772 [ 35C9E97194C8CFB8430125F8DBC34D04 ] C:\WINDOWS\system32\drivers\mouclass.sys
11:02:28.0718 3772 C:\WINDOWS\system32\drivers\mouclass.sys - ok
11:02:28.0734 3772 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] C:\WINDOWS\system32\drivers\serial.sys
11:02:28.0734 3772 C:\WINDOWS\system32\drivers\serial.sys - ok
11:02:28.0750 3772 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] C:\WINDOWS\system32\drivers\serenum.sys
11:02:28.0750 3772 C:\WINDOWS\system32\drivers\serenum.sys - ok
11:02:28.0765 3772 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] C:\WINDOWS\system32\drivers\parport.sys
11:02:28.0765 3772 C:\WINDOWS\system32\drivers\parport.sys - ok
11:02:28.0781 3772 [ 083A052659F5310DD8B6A6CB05EDCF8E ] C:\WINDOWS\system32\drivers\imapi.sys
11:02:28.0781 3772 C:\WINDOWS\system32\drivers\imapi.sys - ok
11:02:28.0796 3772 [ A7B8A3A79D35215D798A300DF49ED23F ] C:\WINDOWS\system32\drivers\afc.sys
11:02:28.0796 3772 C:\WINDOWS\system32\drivers\afc.sys - ok
11:02:28.0812 3772 [ 1F4260CC5B42272D71F79E570A27A4FE ] C:\WINDOWS\system32\drivers\cdrom.sys
11:02:28.0812 3772 C:\WINDOWS\system32\drivers\cdrom.sys - ok
11:02:28.0828 3772 [ F828DD7E1419B6653894A8F97A0094C5 ] C:\WINDOWS\system32\drivers\redbook.sys
11:02:28.0828 3772 C:\WINDOWS\system32\drivers\redbook.sys - ok
11:02:28.0843 3772 [ 6CB08593487F5701D2D2254E693EAFCE ] C:\WINDOWS\system32\drivers\drmk.sys
11:02:28.0843 3772 C:\WINDOWS\system32\drivers\drmk.sys - ok
11:02:28.0859 3772 [ E82A496C3961EFC6828B508C310CE98F ] C:\WINDOWS\system32\drivers\portcls.sys
11:02:28.0859 3772 C:\WINDOWS\system32\drivers\portcls.sys - ok
11:02:28.0890 3772 [ 31FD0707C7DBE715234F2823B27214FE ] C:\WINDOWS\system32\drivers\smwdm.sys
11:02:28.0890 3772 C:\WINDOWS\system32\drivers\smwdm.sys - ok
11:02:28.0906 3772 [ 11C04B17ED2ABBB4833694BCD644AC90 ] C:\WINDOWS\system32\drivers\aeaudio.sys
11:02:28.0906 3772 C:\WINDOWS\system32\drivers\aeaudio.sys - ok
11:02:28.0921 3772 [ D9F724AA26C010A217C97606B160ED68 ] C:\WINDOWS\system32\drivers\audstub.sys
11:02:28.0921 3772 C:\WINDOWS\system32\drivers\audstub.sys - ok
11:02:28.0937 3772 [ 0109C4F3850DFBAB279542515386AE22 ] C:\WINDOWS\system32\drivers\ndistapi.sys
11:02:28.0937 3772 C:\WINDOWS\system32\drivers\ndistapi.sys - ok
11:02:28.0953 3772 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] C:\WINDOWS\system32\drivers\rasl2tp.sys
11:02:28.0953 3772 C:\WINDOWS\system32\drivers\rasl2tp.sys - ok
11:02:28.0968 3772 [ EDC1531A49C80614B2CFDA43CA8659AB ] C:\WINDOWS\system32\drivers\ndiswan.sys
11:02:28.0968 3772 C:\WINDOWS\system32\drivers\ndiswan.sys - ok
11:02:28.0984 3772 [ 5BC962F2654137C9909C3D4603587DEE ] C:\WINDOWS\system32\drivers\raspppoe.sys
11:02:28.0984 3772 C:\WINDOWS\system32\drivers\raspppoe.sys - ok
11:02:29.0000 3772 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] C:\WINDOWS\system32\drivers\raspptp.sys
11:02:29.0000 3772 C:\WINDOWS\system32\drivers\raspptp.sys - ok
11:02:29.0015 3772 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] C:\WINDOWS\system32\drivers\msgpc.sys
11:02:29.0015 3772 C:\WINDOWS\system32\drivers\msgpc.sys - ok
11:02:29.0031 3772 [ 09298EC810B07E5D582CB3A3F9255424 ] C:\WINDOWS\system32\drivers\psched.sys
11:02:29.0031 3772 C:\WINDOWS\system32\drivers\psched.sys - ok
11:02:29.0046 3772 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] C:\WINDOWS\system32\drivers\ptilink.sys
11:02:29.0046 3772 C:\WINDOWS\system32\drivers\ptilink.sys - ok
11:02:29.0062 3772 [ FDBB1D60066FCFBB7452FD8F9829B242 ] C:\WINDOWS\system32\drivers\raspti.sys
11:02:29.0062 3772 C:\WINDOWS\system32\drivers\raspti.sys - ok
11:02:29.0093 3772 [ 88155247177638048422893737429D9E ] C:\WINDOWS\system32\drivers\termdd.sys
11:02:29.0093 3772 C:\WINDOWS\system32\drivers\termdd.sys - ok
11:02:29.0109 3772 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] C:\WINDOWS\system32\drivers\swenum.sys
11:02:29.0109 3772 C:\WINDOWS\system32\drivers\swenum.sys - ok
11:02:29.0125 3772 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] C:\WINDOWS\system32\drivers\update.sys
11:02:29.0125 3772 C:\WINDOWS\system32\drivers\update.sys - ok
11:02:29.0156 3772 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] C:\WINDOWS\system32\drivers\mssmbios.sys
11:02:29.0156 3772 C:\WINDOWS\system32\drivers\mssmbios.sys - ok
11:02:29.0171 3772 [ 9282BD12DFB069D3889EB3FCC1000A9B ] C:\WINDOWS\system32\drivers\ndproxy.sys
11:02:29.0171 3772 C:\WINDOWS\system32\drivers\ndproxy.sys - ok
11:02:29.0187 3772 [ 8F9347656BEBDF8225D7B7A948CD043F ] C:\WINDOWS\system32\drivers\ch7009.sys
11:02:29.0187 3772 C:\WINDOWS\system32\drivers\ch7009.sys - ok
11:02:29.0203 3772 [ 9B17BCD1F4FCD3798F0DAB8CA268EC93 ] C:\WINDOWS\system32\drivers\ch7017.sys
11:02:29.0203 3772 C:\WINDOWS\system32\drivers\ch7017.sys - ok
11:02:29.0218 3772 [ 32C98379A90968103D01B256A9BAEA28 ] C:\WINDOWS\system32\drivers\fs454.sys
11:02:29.0218 3772 C:\WINDOWS\system32\drivers\fs454.sys - ok
11:02:29.0234 3772 [ E6BA9E361BD6513EF800DD6E1AA389EF ] C:\WINDOWS\system32\drivers\lvds.sys
11:02:29.0234 3772 C:\WINDOWS\system32\drivers\lvds.sys - ok
11:02:29.0250 3772 [ DC23BF0190ACAA6FE49579B99474C931 ] C:\WINDOWS\system32\drivers\ns2501.sys
11:02:29.0250 3772 C:\WINDOWS\system32\drivers\ns2501.sys - ok
11:02:29.0265 3772 [ 1D35A6DAD47330B8DA57130F9A924D98 ] C:\WINDOWS\system32\drivers\ns387.sys
11:02:29.0265 3772 C:\WINDOWS\system32\drivers\ns387.sys - ok
11:02:29.0312 3772 [ EEA4EAB0CCB70A625055988976777CEB ] C:\WINDOWS\system32\drivers\d3dutil.sys
11:02:29.0312 3772 C:\WINDOWS\system32\drivers\d3dutil.sys - ok
11:02:29.0375 3772 [ 2327F5FFA223EC9B415F4A0CDBDF4EE1 ] C:\WINDOWS\system32\drivers\sii164.sys
11:02:29.0375 3772 C:\WINDOWS\system32\drivers\sii164.sys - ok
11:02:29.0437 3772 [ 201BE1C73FA333A8872AD738AC49B9B4 ] C:\WINDOWS\system32\drivers\th164.sys
11:02:29.0437 3772 C:\WINDOWS\system32\drivers\th164.sys - ok
11:02:29.0453 3772 [ AB9720ADBE304893516521D2E440BD45 ] C:\WINDOWS\system32\drivers\ti410.sys
11:02:29.0453 3772 C:\WINDOWS\system32\drivers\ti410.sys - ok
11:02:29.0468 3772 [ 596EB39B50D6EBD9B734DC4AE0544693 ] C:\WINDOWS\system32\drivers\usbd.sys
11:02:29.0468 3772 C:\WINDOWS\system32\drivers\usbd.sys - ok
11:02:29.0500 3772 [ 1AB3CDDE553B6E064D2E754EFE20285C ] C:\WINDOWS\system32\drivers\usbhub.sys
11:02:29.0500 3772 C:\WINDOWS\system32\drivers\usbhub.sys - ok
11:02:29.0515 3772 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] C:\WINDOWS\system32\drivers\flpydisk.sys
11:02:29.0515 3772 C:\WINDOWS\system32\drivers\flpydisk.sys - ok
11:02:29.0515 3772 [ 60F9E45290DF5209DE2756812B3414C6 ] C:\WINDOWS\system32\drivers\cmderd.sys
11:02:29.0515 3772 C:\WINDOWS\system32\drivers\cmderd.sys - ok
11:02:29.0531 3772 [ 7B470691BF8494AE294C0B4C546899ED ] C:\WINDOWS\system32\drivers\cmdGuard.sys
11:02:29.0531 3772 C:\WINDOWS\system32\drivers\cmdGuard.sys - ok
11:02:29.0546 3772 [ 8E6B8C671615D126FDC553D1E2DE5562 ] C:\WINDOWS\system32\drivers\sfloppy.sys
11:02:29.0562 3772 C:\WINDOWS\system32\drivers\sfloppy.sys - ok
11:02:29.0578 3772 [ C1B486A7658353D33A10CC15211A873B ] C:\WINDOWS\system32\drivers\cdaudio.sys
11:02:29.0578 3772 C:\WINDOWS\system32\drivers\cdaudio.sys - ok
11:02:29.0593 3772 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] C:\WINDOWS\system32\drivers\fs_rec.sys
11:02:29.0593 3772 C:\WINDOWS\system32\drivers\fs_rec.sys - ok
11:02:29.0625 3772 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] C:\WINDOWS\system32\drivers\null.sys
11:02:29.0625 3772 C:\WINDOWS\system32\drivers\null.sys - ok
11:02:29.0656 3772 [ DA1F27D85E0D1525F6621372E7B685E9 ] C:\WINDOWS\system32\drivers\beep.sys
11:02:29.0656 3772 C:\WINDOWS\system32\drivers\beep.sys - ok
11:02:29.0671 3772 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] C:\WINDOWS\system32\drivers\mnmdd.sys
11:02:29.0671 3772 C:\WINDOWS\system32\drivers\mnmdd.sys - ok
11:02:29.0687 3772 [ 4912D5B403614CE99C28420F75353332 ] C:\WINDOWS\system32\drivers\rdpcdd.sys
11:02:29.0687 3772 C:\WINDOWS\system32\drivers\rdpcdd.sys - ok
11:02:29.0703 3772 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] C:\WINDOWS\system32\drivers\vga.sys
11:02:29.0703 3772 C:\WINDOWS\system32\drivers\vga.sys - ok
11:02:29.0718 3772 [ C941EA2454BA8350021D774DAF0F1027 ] C:\WINDOWS\system32\drivers\msfs.sys
11:02:29.0718 3772 C:\WINDOWS\system32\drivers\msfs.sys - ok
11:02:29.0734 3772 [ 3182D64AE053D6FB034F44B6DEF8034A ] C:\WINDOWS\system32\drivers\npfs.sys
11:02:29.0734 3772 C:\WINDOWS\system32\drivers\npfs.sys - ok
11:02:29.0750 3772 [ 23C74D75E36E7158768DD63D92789A91 ] C:\WINDOWS\system32\drivers\ipsec.sys
11:02:29.0750 3772 C:\WINDOWS\system32\drivers\ipsec.sys - ok
11:02:29.0781 3772 [ FE0D99D6F31E4FAD8159F690D68DED9C ] C:\WINDOWS\system32\drivers\rasacd.sys
11:02:29.0781 3772 C:\WINDOWS\system32\drivers\rasacd.sys - ok
11:02:29.0796 3772 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] C:\WINDOWS\system32\drivers\tcpip.sys
11:02:29.0796 3772 C:\WINDOWS\system32\drivers\tcpip.sys - ok
11:02:29.0812 3772 [ DD3EC4E63708D3519F6E4418AC5203A8 ] C:\WINDOWS\system32\drivers\cmdhlp.sys
11:02:29.0812 3772 C:\WINDOWS\system32\drivers\cmdhlp.sys - ok
11:02:29.0843 3772 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] C:\WINDOWS\system32\drivers\netbt.sys
11:02:29.0843 3772 C:\WINDOWS\system32\drivers\netbt.sys - ok
11:02:29.0875 3772 [ CC748EA12C6EFFDE940EE98098BF96BB ] C:\WINDOWS\system32\drivers\ipnat.sys
11:02:29.0875 3772 C:\WINDOWS\system32\drivers\ipnat.sys - ok
11:02:29.0890 3772 [ E20B95BAEDB550F32DD489265C1DA1F6 ] C:\WINDOWS\system32\drivers\wanarp.sys
11:02:29.0890 3772 C:\WINDOWS\system32\drivers\wanarp.sys - ok
11:02:29.0906 3772 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] C:\WINDOWS\system32\drivers\afd.sys
11:02:29.0906 3772 C:\WINDOWS\system32\drivers\afd.sys - ok
11:02:29.0937 3772 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] C:\WINDOWS\system32\drivers\ws2ifsl.sys
11:02:29.0937 3772 C:\WINDOWS\system32\drivers\ws2ifsl.sys - ok
11:02:29.0968 3772 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] C:\WINDOWS\system32\drivers\netbios.sys
11:02:29.0968 3772 C:\WINDOWS\system32\drivers\netbios.sys - ok
11:02:30.0031 3772 [ A32BEBAF723557681BFC6BD93E98BD26 ] C:\WINDOWS\system32\drivers\processr.sys
11:02:30.0031 3772 C:\WINDOWS\system32\drivers\processr.sys - ok
11:02:30.0046 3772 [ 39763504067962108505BFF25F024345 ] C:\Program Files\SUPERAntiSpyware\sasdifsv.sys
11:02:30.0046 3772 C:\Program Files\SUPERAntiSpyware\sasdifsv.sys - ok
11:02:30.0062 3772 [ 77B9FC20084B48408AD3E87570EB4A85 ] C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
11:02:30.0062 3772 C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS - ok
11:02:30.0078 3772 [ 7AD224AD1A1437FE28D89CF22B17780A ] C:\WINDOWS\system32\drivers\rdbss.sys
11:02:30.0078 3772 C:\WINDOWS\system32\drivers\rdbss.sys - ok
11:02:30.0109 3772 [ CEC7E2C6C1FA00C7AB2F5434F848AE51 ] C:\WINDOWS\system32\drivers\omci.sys
11:02:30.0109 3772 C:\WINDOWS\system32\drivers\omci.sys - ok
11:02:30.0125 3772 [ 5EF7DD401771693245D46F4B0B69FE2B ] C:\WINDOWS\system32\Ckldrv.sys
11:02:30.0125 3772 C:\WINDOWS\system32\Ckldrv.sys - ok
11:02:30.0156 3772 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] C:\WINDOWS\system32\drivers\mrxsmb.sys
11:02:30.0156 3772 C:\WINDOWS\system32\drivers\mrxsmb.sys - ok
11:02:30.0171 3772 [ D45926117EB9FA946A6AF572FBE1CAA3 ] C:\WINDOWS\system32\drivers\fips.sys
11:02:30.0171 3772 C:\WINDOWS\system32\drivers\fips.sys - ok
11:02:30.0203 3772 [ 5D7BE7B19E827125E016325334E58FF1 ] C:\WINDOWS\system32\drivers\BANTExt.sys
11:02:30.0203 3772 C:\WINDOWS\system32\drivers\BANTExt.sys - ok
11:02:30.0218 3772 [ 5F816C1F539266D2D4C78694239DA0B5 ] C:\WINDOWS\system32\smss.exe
11:02:30.0218 3772 C:\WINDOWS\system32\smss.exe - ok
11:02:30.0234 3772 [ F8F0D25CA553E39DDE485D8FC7FCCE89 ] C:\WINDOWS\system32\ntdll.dll
11:02:30.0234 3772 C:\WINDOWS\system32\ntdll.dll - ok
11:02:30.0250 3772 [ 23043C91A0F9DFB4B9E9F87B680863B4 ] C:\WINDOWS\system32\autochk.exe
11:02:30.0250 3772 C:\WINDOWS\system32\autochk.exe - ok
11:02:30.0265 3772 [ 9DD07AF82244867CA36681EA2D29CE79 ] C:\WINDOWS\system32\sfcfiles.dll
11:02:30.0265 3772 C:\WINDOWS\system32\sfcfiles.dll - ok
11:02:30.0281 3772 [ C885B02847F5D2FD45A24E219ED93B32 ] C:\WINDOWS\system32\drivers\cdfs.sys
11:02:30.0296 3772 C:\WINDOWS\system32\drivers\cdfs.sys - ok
11:02:30.0312 3772 [ FE97D0343ACFDEBDD578FC67CC91FA87 ] C:\WINDOWS\system32\drivers\dxapi.sys
11:02:30.0312 3772 C:\WINDOWS\system32\drivers\dxapi.sys - ok
11:02:30.0328 3772 [ 9A10AACBFDC4922715375FB4065EC930 ] C:\WINDOWS\system32\watchdog.sys
11:02:30.0328 3772 C:\WINDOWS\system32\watchdog.sys - ok
11:02:30.0328 3772 [ BD39EC6064A1B5DFDABCF312A38A37EE ] C:\WINDOWS\system32\win32k.sys
11:02:30.0328 3772 C:\WINDOWS\system32\win32k.sys - ok
11:02:30.0343 3772 [ DD40363ABAD230A84C5E2178B11EFA88 ] C:\WINDOWS\system32\csrsrv.dll
11:02:30.0343 3772 C:\WINDOWS\system32\csrsrv.dll - ok
11:02:30.0359 3772 [ 44F275C64738EA2056E3D9580C23B60F ] C:\WINDOWS\system32\csrss.exe
11:02:30.0359 3772 C:\WINDOWS\system32\csrss.exe - ok
11:02:30.0375 3772 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
11:02:30.0390 3772 C:\WINDOWS\system32\basesrv.dll - ok
11:02:30.0406 3772 [ 3A291C3526126E9408C85EA46D5AA525 ] C:\WINDOWS\system32\cmdcsr.dll
11:02:30.0406 3772 C:\WINDOWS\system32\cmdcsr.dll - ok
11:02:30.0421 3772 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
11:02:30.0421 3772 C:\WINDOWS\system32\winsrv.dll - ok
11:02:30.0437 3772 [ 8B1F3320AEBB536E021A5014409862DE ] C:\WINDOWS\system32\gdi32.dll
11:02:30.0437 3772 C:\WINDOWS\system32\gdi32.dll - ok
11:02:30.0453 3772 [ 6FE42512AB1B89F32A7407F261B1D2D0 ] C:\WINDOWS\system32\kernel32.dll
11:02:30.0453 3772 C:\WINDOWS\system32\kernel32.dll - ok
11:02:30.0468 3772 [ B26B135FF1B9F60C9388B4A7D16F600B ] C:\WINDOWS\system32\user32.dll
11:02:30.0468 3772 C:\WINDOWS\system32\user32.dll - ok
11:02:30.0484 3772 [ AC7280566A7BB85CB3291F04DDC1198E ] C:\WINDOWS\system32\drivers\dxg.sys
11:02:30.0484 3772 C:\WINDOWS\system32\drivers\dxg.sys - ok
11:02:30.0500 3772 [ A73F5D6705B1D820C19B18782E176EFD ] C:\WINDOWS\system32\drivers\dxgthk.sys
11:02:30.0500 3772 C:\WINDOWS\system32\drivers\dxgthk.sys - ok
11:02:30.0515 3772 [ 11D9BCF27F357DCB1AE08BD97495979F ] C:\WINDOWS\system32\igddis.dll
11:02:30.0515 3772 C:\WINDOWS\system32\igddis.dll - ok
11:02:30.0531 3772 [ ECB7591870F8BFB1A4C17B718AD5A4AA ] C:\WINDOWS\system32\vga.dll
11:02:30.0531 3772 C:\WINDOWS\system32\vga.dll - ok
11:02:30.0531 3772 [ 6DAC20FF92D80CBCD80AA0C63722B084 ] C:\WINDOWS\system32\igd3dalm.dll
11:02:30.0531 3772 C:\WINDOWS\system32\igd3dalm.dll - ok
11:02:30.0546 3772 [ ED0EF0A136DEC83DF69F04118870003E ] C:\WINDOWS\system32\winlogon.exe
11:02:30.0546 3772 C:\WINDOWS\system32\winlogon.exe - ok
11:02:30.0562 3772 [ E76F8807070ED04E7408A86D6D3A6137 ] C:\WINDOWS\system32\advapi32.dll
11:02:30.0562 3772 C:\WINDOWS\system32\advapi32.dll - ok
11:02:30.0593 3772 [ D4502F124289A31976130CCCB014C9AA ] C:\WINDOWS\system32\rpcrt4.dll
11:02:30.0593 3772 C:\WINDOWS\system32\rpcrt4.dll - ok
11:02:30.0609 3772 [ 714705F29A917993536A6AB2DEDB0B7F ] C:\WINDOWS\system32\authz.dll
11:02:30.0609 3772 C:\WINDOWS\system32\authz.dll - ok
11:02:30.0625 3772 [ 5357826C8A8DD6A07F17C48BB45BE46E ] C:\WINDOWS\system32\secur32.dll
11:02:30.0625 3772 C:\WINDOWS\system32\secur32.dll - ok
11:02:30.0656 3772 [ 355EDBB4D412B01F1740C17E3F50FA00 ] C:\WINDOWS\system32\msvcrt.dll
11:02:30.0656 3772 C:\WINDOWS\system32\msvcrt.dll - ok
11:02:30.0671 3772 [ 6BEE5D4EFF0A0341BCC4A462D81CCFC1 ] C:\WINDOWS\system32\crypt32.dll
11:02:30.0671 3772 C:\WINDOWS\system32\crypt32.dll - ok
11:02:30.0687 3772 [ 04D898830DF96A17A20FD35D7590F87E ] C:\WINDOWS\system32\msasn1.dll
11:02:30.0687 3772 C:\WINDOWS\system32\msasn1.dll - ok
11:02:30.0718 3772 [ 013C1148C1EC025596896E093F60F608 ] C:\WINDOWS\system32\nddeapi.dll
11:02:30.0718 3772 C:\WINDOWS\system32\nddeapi.dll - ok
11:02:30.0734 3772 [ CAC752BF84DB4666ED3CE0948E6EA937 ] C:\WINDOWS\system32\netapi32.dll
11:02:30.0734 3772 C:\WINDOWS\system32\netapi32.dll - ok
11:02:30.0750 3772 [ FCFA1C55971CC229D353B3A15ACCD995 ] C:\WINDOWS\system32\profmap.dll
11:02:30.0750 3772 C:\WINDOWS\system32\profmap.dll - ok
11:02:30.0765 3772 [ 43D13C80EBEC0135A3611E0F616F179B ] C:\WINDOWS\system32\userenv.dll
11:02:30.0765 3772 C:\WINDOWS\system32\userenv.dll - ok
11:02:30.0781 3772 [ 9CFCB3CA3D83B4EAA133F0644A2C6F31 ] C:\WINDOWS\system32\psapi.dll
11:02:30.0781 3772 C:\WINDOWS\system32\psapi.dll - ok
11:02:30.0796 3772 [ AF11C591F2F4AFF4A6CF699D376F618B ] C:\WINDOWS\system32\regapi.dll
11:02:30.0796 3772 C:\WINDOWS\system32\regapi.dll - ok
11:02:30.0812 3772 [ 24192246760E0E64435522E246B1D6C2 ] C:\WINDOWS\system32\setupapi.dll
11:02:30.0812 3772 C:\WINDOWS\system32\setupapi.dll - ok
11:02:30.0828 3772 [ C7CE131408739B0B3A318BE2D0032719 ] C:\WINDOWS\system32\version.dll
11:02:30.0828 3772 C:\WINDOWS\system32\version.dll - ok
11:02:30.0843 3772 [ 430CEB794F6E6EF8AC86958C242366D6 ] C:\WINDOWS\system32\winsta.dll
11:02:30.0843 3772 C:\WINDOWS\system32\winsta.dll - ok
11:02:30.0859 3772 [ D458B738B4C2CE33174CFB2CE12412DB ] C:\WINDOWS\system32\wintrust.dll
11:02:30.0859 3772 C:\WINDOWS\system32\wintrust.dll - ok
11:02:30.0875 3772 [ FFC01A72D1C25CCB39F61B202CE60819 ] C:\WINDOWS\system32\imagehlp.dll
11:02:30.0875 3772 C:\WINDOWS\system32\imagehlp.dll - ok
11:02:30.0890 3772 [ 2CCC474EB85CEAA3E1FA1726580A3E5A ] C:\WINDOWS\system32\ws2_32.dll
11:02:30.0890 3772 C:\WINDOWS\system32\ws2_32.dll - ok
11:02:30.0921 3772 [ 0DA85218E92526972A821587E6A8BF8F ] C:\WINDOWS\system32\imm32.dll
11:02:30.0921 3772 C:\WINDOWS\system32\imm32.dll - ok
11:02:30.0937 3772 [ 9789E95E1D88EEB4B922BF3EA7779C28 ] C:\WINDOWS\system32\ws2help.dll
11:02:30.0937 3772 C:\WINDOWS\system32\ws2help.dll - ok
11:02:30.0953 3772 [ 56C5B179FE3308B655EB6208C3256FEC ] C:\WINDOWS\system32\kbdus.dll
11:02:30.0953 3772 C:\WINDOWS\system32\kbdus.dll - ok
11:02:30.0968 3772 [ D7B7A57C0E57C836F18CF12A4C62A1CA ] C:\WINDOWS\system32\msgina.dll
11:02:30.0968 3772 C:\WINDOWS\system32\msgina.dll - ok
11:02:30.0984 3772 [ 93AFB83FBC1F9443CAC722FCA63D73BF ] C:\WINDOWS\system32\comctl32.dll
11:02:30.0984 3772 C:\WINDOWS\system32\comctl32.dll - ok
11:02:31.0000 3772 [ 40B0F98BAD16AD5DEF894E88C3EF8014 ] C:\WINDOWS\system32\odbc32.dll
11:02:31.0000 3772 C:\WINDOWS\system32\odbc32.dll - ok
11:02:31.0015 3772 [ 86987A5000DFA3EBE2275C0456BCF2FE ] C:\WINDOWS\system32\comdlg32.dll
11:02:31.0015 3772 C:\WINDOWS\system32\comdlg32.dll - ok
11:02:31.0031 3772 [ 6843D54BC4A40CC8C5741AF750233D10 ] C:\WINDOWS\system32\shell32.dll
11:02:31.0031 3772 C:\WINDOWS\system32\shell32.dll - ok
11:02:31.0046 3772 [ C448A248B743F5FB935C787A5D97268B ] C:\WINDOWS\system32\shlwapi.dll
11:02:31.0046 3772 C:\WINDOWS\system32\shlwapi.dll - ok
11:02:31.0062 3772 [ 694503348B586E99D56C0E30AB5B3EF8 ] C:\WINDOWS\system32\sxs.dll
11:02:31.0062 3772 C:\WINDOWS\system32\sxs.dll - ok
11:02:31.0078 3772 [ 736B12B725AEB2B07F0241A9F680CB10 ] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
11:02:31.0078 3772 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll - ok
11:02:31.0093 3772 [ 6B7C6B32F8E84D56C6260D684019FEA2 ] C:\WINDOWS\system32\odbcint.dll
11:02:31.0093 3772 C:\WINDOWS\system32\odbcint.dll - ok
11:02:31.0109 3772 [ 99BC0B50F511924348BE19C7C7313BBF ] C:\WINDOWS\system32\shsvcs.dll
11:02:31.0109 3772 C:\WINDOWS\system32\shsvcs.dll - ok
11:02:31.0125 3772 [ 96E1C926F22EE1BFBAE82901A35F6BF3 ] C:\WINDOWS\system32\sfc.dll
11:02:31.0125 3772 C:\WINDOWS\system32\sfc.dll - ok
11:02:31.0140 3772 [ 6B5DB6789177A4FD0DEBC248041D0739 ] C:\WINDOWS\system32\sfc_os.dll
11:02:31.0156 3772 C:\WINDOWS\system32\sfc_os.dll - ok
11:02:31.0171 3772 [ 6BAD1BED9872E62049E487FB91AE2F3A ] C:\WINDOWS\system32\ole32.dll
11:02:31.0171 3772 C:\WINDOWS\system32\ole32.dll - ok
11:02:31.0187 3772 [ CF492D7E9AF1C628B3536D20EF6F5CC7 ] C:\WINDOWS\system32\apphelp.dll
11:02:31.0187 3772 C:\WINDOWS\system32\apphelp.dll - ok
11:02:31.0203 3772 [ BF2466B3E18E970D8A976FB95FC1CA85 ] C:\WINDOWS\system32\lsass.exe
11:02:31.0203 3772 C:\WINDOWS\system32\lsass.exe - ok
11:02:31.0218 3772 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
11:02:31.0218 3772 C:\WINDOWS\system32\services.exe - ok
11:02:31.0234 3772 [ BD31DC6DBE9333C4FBD4BDF0899F2160 ] C:\WINDOWS\system32\lsasrv.dll
11:02:31.0234 3772 C:\WINDOWS\system32\lsasrv.dll - ok
11:02:31.0250 3772 [ EC29A79F1E76DC509E24D401F29D0678 ] C:\WINDOWS\system32\ncobjapi.dll
11:02:31.0250 3772 C:\WINDOWS\system32\ncobjapi.dll - ok
11:02:31.0265 3772 [ F404830F3CD9BF8F2515E489C0CDA297 ] C:\WINDOWS\system32\msvcp60.dll
11:02:31.0265 3772 C:\WINDOWS\system32\msvcp60.dll - ok
11:02:31.0281 3772 [ B24A42A413E694AD73FDFB7FBD492C31 ] C:\WINDOWS\system32\scesrv.dll
11:02:31.0281 3772 C:\WINDOWS\system32\scesrv.dll - ok
11:02:31.0296 3772 [ DD7BD97FB8BD800963789158A5E4B41D ] C:\WINDOWS\system32\mpr.dll
11:02:31.0296 3772 C:\WINDOWS\system32\mpr.dll - ok
11:02:31.0312 3772 [ EC4C0D9BFD9F7E33F8B395AD54E13063 ] C:\WINDOWS\system32\ntdsapi.dll
11:02:31.0312 3772 C:\WINDOWS\system32\ntdsapi.dll - ok
11:02:31.0328 3772 [ 2EDFC2A8893435723AD80481803C6D5C ] C:\WINDOWS\system32\umpnpmgr.dll
11:02:31.0328 3772 C:\WINDOWS\system32\umpnpmgr.dll - ok
11:02:31.0343 3772 [ 389496118B3B03C2328024AF320132AC ] C:\WINDOWS\system32\dnsapi.dll
11:02:31.0343 3772 C:\WINDOWS\system32\dnsapi.dll - ok
11:02:31.0359 3772 [ 1F03103598BD817B1078DAB1326DDE11 ] C:\WINDOWS\system32\shimeng.dll
11:02:31.0359 3772 C:\WINDOWS\system32\shimeng.dll - ok
11:02:31.0375 3772 [ 0492CF5870F0E616B0C71695A433D162 ] C:\WINDOWS\system32\wldap32.dll
11:02:31.0375 3772 C:\WINDOWS\system32\wldap32.dll - ok
11:02:31.0390 3772 [ EA9EE60B408878E5F2012F9C783836DB ] C:\WINDOWS\AppPatch\acadproc.dll
11:02:31.0390 3772 C:\WINDOWS\AppPatch\acadproc.dll - ok
11:02:31.0406 3772 [ 8329A39D5A402A75A74301D6A62ECDA1 ] C:\WINDOWS\system32\samlib.dll
11:02:31.0406 3772 C:\WINDOWS\system32\samlib.dll - ok
11:02:31.0421 3772 [ F05B8CDB7FE0E55DCCFB1D946CE80064 ] C:\WINDOWS\system32\samsrv.dll
11:02:31.0421 3772 C:\WINDOWS\system32\samsrv.dll - ok
11:02:31.0437 3772 [ D72EEFF5DB99017A7F3664B33C657B8A ] C:\WINDOWS\system32\guard32.dll
11:02:31.0437 3772 C:\WINDOWS\system32\guard32.dll - ok
11:02:31.0453 3772 [ 17A1D675C12BBF80CAAC54A4855C41D0 ] C:\WINDOWS\system32\cryptdll.dll
11:02:31.0453 3772 C:\WINDOWS\system32\cryptdll.dll - ok
11:02:31.0468 3772 [ 310C15FD8358B2C4CD7A5B98A112883F ] C:\WINDOWS\AppPatch\acgenral.dll
11:02:31.0468 3772 C:\WINDOWS\AppPatch\acgenral.dll - ok
11:02:31.0484 3772 [ 5D43C9A33F18C707BA169AFDA88BDF30 ] C:\WINDOWS\system32\fltlib.dll
11:02:31.0484 3772 C:\WINDOWS\system32\fltlib.dll - ok
11:02:31.0515 3772 [ 4A953F13942867BA8FB41F141EC1B80C ] C:\WINDOWS\system32\winmm.dll
11:02:31.0515 3772 C:\WINDOWS\system32\winmm.dll - ok
11:02:31.0531 3772 [ EFF03460E542EEA6B0ABDEC6BF19C897 ] C:\WINDOWS\system32\oleaut32.dll
11:02:31.0531 3772 C:\WINDOWS\system32\oleaut32.dll - ok
11:02:31.0531 3772 [ 2098AB52BD5316E59AA36F3437B13BE6 ] C:\WINDOWS\system32\msacm32.dll
11:02:31.0531 3772 C:\WINDOWS\system32\msacm32.dll - ok
11:02:31.0546 3772 [ 7A2CC3719B255E6B5D74396183B7715B ] C:\WINDOWS\system32\uxtheme.dll
11:02:31.0546 3772 C:\WINDOWS\system32\uxtheme.dll - ok
11:02:31.0578 3772 [ F24B12786D60A17008319E3F2AEE7799 ] C:\WINDOWS\system32\msapsspc.dll
11:02:31.0578 3772 C:\WINDOWS\system32\msapsspc.dll - ok
11:02:31.0593 3772 [ 7A660EDC0757849DF5F8706FB6E9F740 ] C:\WINDOWS\system32\msvcrt40.dll
11:02:31.0593 3772 C:\WINDOWS\system32\msvcrt40.dll - ok
11:02:31.0609 3772 [ 0F64207B49390C8063C36AE7CBF9C2DB ] C:\WINDOWS\system32\schannel.dll
11:02:31.0609 3772 C:\WINDOWS\system32\schannel.dll - ok
11:02:31.0625 3772 [ 3D76DD0CBC536E0F8C45D23ED230BEB2 ] C:\WINDOWS\system32\digest.dll
11:02:31.0625 3772 C:\WINDOWS\system32\digest.dll - ok
11:02:31.0640 3772 [ A4388DF80E52695AE92EE5F3F61F1619 ] C:\WINDOWS\system32\msnsspc.dll
11:02:31.0640 3772 C:\WINDOWS\system32\msnsspc.dll - ok
11:02:31.0656 3772 [ 3F790874A85819E94574F3E7AF9C5806 ] C:\WINDOWS\system32\msctfime.ime
11:02:31.0656 3772 C:\WINDOWS\system32\msctfime.ime - ok
11:02:31.0671 3772 [ C6BB1D1500DB4A0E224CB65E6C7E8A80 ] C:\WINDOWS\system32\msprivs.dll
11:02:31.0671 3772 C:\WINDOWS\system32\msprivs.dll - ok
11:02:31.0687 3772 [ A525C96C51D55111FDF3BEA9FFFFC7AE ] C:\WINDOWS\system32\kerberos.dll
11:02:31.0687 3772 C:\WINDOWS\system32\kerberos.dll - ok
11:02:31.0703 3772 [ 517561A1113B04E51D936CD018DE1C1F ] C:\WINDOWS\system32\msv1_0.dll
11:02:31.0703 3772 C:\WINDOWS\system32\msv1_0.dll - ok
11:02:31.0718 3772 [ C11D10A3C164AC222BC9AAB3650A88B3 ] C:\WINDOWS\system32\atmfd.dll
11:02:31.0718 3772 C:\WINDOWS\system32\atmfd.dll - ok
11:02:31.0734 3772 [ AF07DC9B7CC455629E732340C7B15F3A ] C:\WINDOWS\system32\iphlpapi.dll
11:02:31.0734 3772 C:\WINDOWS\system32\iphlpapi.dll - ok
11:02:31.0765 3772 [ 1B7F071C51B77C272875C3A23E1E4550 ] C:\WINDOWS\system32\netlogon.dll
11:02:31.0765 3772 C:\WINDOWS\system32\netlogon.dll - ok
11:02:31.0781 3772 [ 54AF4B1D5459500EF0937F6D33B1914F ] C:\WINDOWS\system32\w32time.dll
11:02:31.0781 3772 C:\WINDOWS\system32\w32time.dll - ok
11:02:31.0796 3772 [ 3AAF9B35939FF9E58CCD18D41655C2FC ] C:\WINDOWS\system32\wdigest.dll
11:02:31.0796 3772 C:\WINDOWS\system32\wdigest.dll - ok
11:02:31.0812 3772 [ 54DAE3EA34802B4ED9AE1C6B1209FA56 ] C:\WINDOWS\system32\rsaenh.dll
11:02:31.0812 3772 C:\WINDOWS\system32\rsaenh.dll - ok
11:02:31.0828 3772 [ 02988B904C386B500CD08639C4C20EEA ] C:\WINDOWS\system32\winscard.dll
11:02:31.0828 3772 C:\WINDOWS\system32\winscard.dll - ok
11:02:31.0843 3772 [ 0E2735281FBB9A764D5584C2A5DCBA59 ] C:\WINDOWS\system32\wtsapi32.dll
11:02:31.0843 3772 C:\WINDOWS\system32\wtsapi32.dll - ok
11:02:31.0859 3772 [ A86BB5E61BF3E39B62AB4C7E7085A084 ] C:\WINDOWS\system32\scecli.dll
11:02:31.0859 3772 C:\WINDOWS\system32\scecli.dll - ok
11:02:31.0890 3772 [ CBFAA333EBA2E402A0439A3A0E5413F3 ] C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe
11:02:31.0890 3772 C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe - ok
11:02:31.0906 3772 [ DDB9BCFF8CBF73638A15579FEC223229 ] C:\Program Files\IObit\Advanced SystemCare 6\rtl120.bpl
11:02:31.0906 3772 C:\Program Files\IObit\Advanced SystemCare 6\rtl120.bpl - ok
11:02:31.0921 3772 [ 67156D5A9AC356DC99D7BCCB388E3316 ] C:\WINDOWS\system32\wsock32.dll
11:02:31.0921 3772 C:\WINDOWS\system32\wsock32.dll - ok
11:02:31.0937 3772 [ 20200EE3CFE10E9F0C028D8653BE11C6 ] C:\WINDOWS\system32\oleacc.dll
11:02:31.0937 3772 C:\WINDOWS\system32\oleacc.dll - ok
11:02:31.0953 3772 [ 8290E04F8A4D9594BFB53D520B677B8A ] C:\Program Files\IObit\Advanced SystemCare 6\vcl120.bpl
11:02:31.0953 3772 C:\Program Files\IObit\Advanced SystemCare 6\vcl120.bpl - ok
11:02:31.0968 3772 [ AFFC87E2501FCE8F09D4C10BA6421CCF ] C:\WINDOWS\system32\msimg32.dll
11:02:31.0968 3772 C:\WINDOWS\system32\msimg32.dll - ok
11:02:32.0000 3772 [ BD83ABA61E8ACCC8D9FFB869F29418CE ] C:\WINDOWS\system32\winspool.drv
11:02:32.0000 3772 C:\WINDOWS\system32\winspool.drv - ok
11:02:32.0015 3772 [ 0B467F470CC9918FDCEEDCFD7DC4D697 ] C:\WINDOWS\system32\oledlg.dll
11:02:32.0015 3772 C:\WINDOWS\system32\oledlg.dll - ok
11:02:32.0031 3772 [ 2081A5B5E4ABA206A0A8A1A97DF0FB23 ] C:\WINDOWS\system32\logonui.exe
11:02:32.0031 3772 C:\WINDOWS\system32\logonui.exe - ok
11:02:32.0046 3772 [ 3D41A9326F0376FC73AF961DD23B1FB1 ] C:\WINDOWS\system32\duser.dll
11:02:32.0046 3772 C:\WINDOWS\system32\duser.dll - ok
11:02:32.0062 3772 [ F137A0CA70003DB20448D540651FA003 ] C:\WINDOWS\system32\clbcatq.dll
11:02:32.0062 3772 C:\WINDOWS\system32\clbcatq.dll - ok
11:02:32.0093 3772 [ 1280A158C722FA95A80FB7AEBE78FA7D ] C:\WINDOWS\system32\comres.dll
11:02:32.0093 3772 C:\WINDOWS\system32\comres.dll - ok
11:02:32.0125 3772 [ E5EDBD51476DB5001ABF5C82AE5C3DD1 ] C:\WINDOWS\system32\shgina.dll
11:02:32.0125 3772 C:\WINDOWS\system32\shgina.dll - ok
11:02:32.0156 3772 [ 27C6D03BCDB8CFEB96B716F3D8BE3E18 ] C:\WINDOWS\system32\svchost.exe
11:02:32.0156 3772 C:\WINDOWS\system32\svchost.exe - ok
11:02:32.0171 3772 [ 549290DBC280C887681D7652978DBBE0 ] C:\WINDOWS\system32\ntmarta.dll
11:02:32.0171 3772 C:\WINDOWS\system32\ntmarta.dll - ok
11:02:32.0218 3772 [ 6B27A5C03DFB94B4245739065431322C ] C:\WINDOWS\system32\rpcss.dll
11:02:32.0218 3772 C:\WINDOWS\system32\rpcss.dll - ok
11:02:32.0234 3772 [ 16403217AB6FC5C30C14C6B12098AD4B ] C:\WINDOWS\system32\xpsp2res.dll
11:02:32.0234 3772 C:\WINDOWS\system32\xpsp2res.dll - ok
11:02:32.0250 3772 [ 6D4FEB43EE538FC5428CC7F0565AA656 ] C:\WINDOWS\system32\eventlog.dll
11:02:32.0250 3772 C:\WINDOWS\system32\eventlog.dll - ok
11:02:32.0265 3772 [ 943337D786A56729263071623BBB9DE5 ] C:\WINDOWS\system32\mswsock.dll
11:02:32.0265 3772 C:\WINDOWS\system32\mswsock.dll - ok
11:02:32.0281 3772 [ 3CB32D3B8CBE79899D63280BB7A83CD9 ] C:\WINDOWS\system32\hnetcfg.dll
11:02:32.0281 3772 C:\WINDOWS\system32\hnetcfg.dll - ok
11:02:32.0296 3772 [ 4E3D06D6E68EEDB52565080F55B460D3 ] C:\WINDOWS\system32\wshtcpip.dll
11:02:32.0296 3772 C:\WINDOWS\system32\wshtcpip.dll - ok
11:02:32.0312 3772 [ 811BB60991FC03A63F2F844A3F9C6488 ] C:\WINDOWS\system32\wshisn.dll
11:02:32.0312 3772 C:\WINDOWS\system32\wshisn.dll - ok
11:02:32.0343 3772 [ 6F9BEF24C578D5D6740E080BEDD6A448 ] C:\WINDOWS\system32\rasadhlp.dll
11:02:32.0343 3772 C:\WINDOWS\system32\rasadhlp.dll - ok
11:02:32.0359 3772 [ D72B9EC3337B247A666F098F3D6B43DE ] C:\WINDOWS\system32\winrnr.dll
11:02:32.0359 3772 C:\WINDOWS\system32\winrnr.dll - ok
11:02:32.0375 3772 [ DAA199690ED70FFE5765FBC3BCB48E7C ] C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
11:02:32.0375 3772 C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe - ok
11:02:32.0390 3772 [ E7582A17BFF084C03349011A82C06EEE ] C:\Program Files\COMODO\COMODO Internet Security\dbghelp.dll
11:02:32.0390 3772 C:\Program Files\COMODO\COMODO Internet Security\dbghelp.dll - ok
11:02:32.0421 3772 [ D175F91A4C98B8848818C9B5089F88A2 ] C:\WINDOWS\system32\wininet.dll
11:02:32.0421 3772 C:\WINDOWS\system32\wininet.dll - ok
11:02:32.0437 3772 [ 10753A3ADC3E39A3B10CC3F08E98E6B4 ] C:\WINDOWS\system32\normaliz.dll
11:02:32.0437 3772 C:\WINDOWS\system32\normaliz.dll - ok
11:02:32.0453 3772 [ 84A5C7B9B1B82F94A8245781FD44D8BA ] C:\WINDOWS\system32\urlmon.dll
11:02:32.0453 3772 C:\WINDOWS\system32\urlmon.dll - ok
11:02:32.0468 3772 [ D1B3D1E05BEDC8F9B0BBBC03D6033F82 ] C:\WINDOWS\system32\iertutil.dll
11:02:32.0468 3772 C:\WINDOWS\system32\iertutil.dll - ok
11:02:32.0500 3772 [ 8C22083ED515DC94D575438662F0BE6A ] C:\WINDOWS\system32\msi.dll
11:02:32.0500 3772 C:\WINDOWS\system32\msi.dll - ok
11:02:32.0515 3772 [ 205ADD80FF8099B1A8101EB490B933D1 ] C:\WINDOWS\system32\wbem\wbemprox.dll
11:02:32.0515 3772 C:\WINDOWS\system32\wbem\wbemprox.dll - ok
11:02:32.0531 3772 [ D95C71052E5EF63B55997FB31483D02F ] C:\WINDOWS\system32\wbem\wbemcomn.dll
11:02:32.0531 3772 C:\WINDOWS\system32\wbem\wbemcomn.dll - ok
11:02:32.0546 3772 [ 3D4E199942E29207970E04315D02AD3B ] C:\WINDOWS\system32\cryptsvc.dll
11:02:32.0546 3772 C:\WINDOWS\system32\cryptsvc.dll - ok
11:02:32.0562 3772 [ 00709952D444EAE14DBBD30D36FBAE0F ] C:\WINDOWS\system32\certcli.dll
11:02:32.0562 3772 C:\WINDOWS\system32\certcli.dll - ok
11:02:32.0578 3772 [ 224FB925C641DA16CEB6D60F40CA4C75 ] C:\WINDOWS\system32\atl.dll
11:02:32.0578 3772 C:\WINDOWS\system32\atl.dll - ok
11:02:32.0609 3772 [ 6E4BE11D50F8A8DE2BAD644C9C9DE8D3 ] C:\WINDOWS\system32\cryptui.dll
11:02:32.0609 3772 C:\WINDOWS\system32\cryptui.dll - ok
11:02:32.0609 3772 [ F5B754CDEA20BBB3A31E16A776EDE6D6 ] C:\WINDOWS\system32\esent.dll
11:02:32.0609 3772 C:\WINDOWS\system32\esent.dll - ok
11:02:32.0640 3772 [ C1FAEA15E41F62D7BFA7FBC395C24BA6 ] C:\WINDOWS\system32\riched20.dll
11:02:32.0640 3772 C:\WINDOWS\system32\riched20.dll - ok
11:02:32.0656 3772 [ 515A7FAE2070C2B0242B2353443E2F11 ] C:\WINDOWS\system32\cscdll.dll
11:02:32.0656 3772 C:\WINDOWS\system32\cscdll.dll - ok
11:02:32.0671 3772 [ E0087225B137E57239FF40F8AE82059B ] C:\WINDOWS\system32\drivers\fssfltr_tdi.sys
11:02:32.0671 3772 C:\WINDOWS\system32\drivers\fssfltr_tdi.sys - ok
11:02:32.0703 3772 [ E2092F0A1D7ABC243F9C2362483D150D ] C:\WINDOWS\system32\dimsntfy.dll
11:02:32.0703 3772 C:\WINDOWS\system32\dimsntfy.dll - ok
11:02:32.0718 3772 [ 8B8B1BE2DBA4025DA6786C645F77F123 ] C:\WINDOWS\system32\drivers\nwlnkipx.sys
11:02:32.0718 3772 C:\WINDOWS\system32\drivers\nwlnkipx.sys - ok
11:02:32.0734 3772 [ 2CC34E8BB667EEF78899546E12649196 ] C:\WINDOWS\system32\wlnotify.dll
11:02:32.0734 3772 C:\WINDOWS\system32\wlnotify.dll - ok
11:02:32.0765 3772 [ D7DCFB4D0C58FFB569DE93E1681FD37A ] C:\WINDOWS\system32\WgaLogon.dll
11:02:32.0765 3772 C:\WINDOWS\system32\WgaLogon.dll - ok
11:02:32.0781 3772 [ 56D34A67C05E94E16377C60609741FF8 ] C:\WINDOWS\system32\drivers\nwlnknb.sys
11:02:32.0781 3772 C:\WINDOWS\system32\drivers\nwlnknb.sys - ok
11:02:32.0796 3772 [ ACFEE2392503DD5E457363A0510B8BCB ] C:\WINDOWS\system32\msxml3.dll
11:02:32.0796 3772 C:\WINDOWS\system32\msxml3.dll - ok
11:02:32.0812 3772 [ 5E38D7684A49CACFB752B046357E0589 ] C:\WINDOWS\system32\dhcpcsvc.dll
11:02:32.0812 3772 C:\WINDOWS\system32\dhcpcsvc.dll - ok
11:02:32.0843 3772 [ 5F7E24FA9EAB896051FFB87F840730D2 ] C:\WINDOWS\system32\dnsrslvr.dll
11:02:32.0843 3772 C:\WINDOWS\system32\dnsrslvr.dll - ok
11:02:32.0875 3772 [ A7DB739AE99A796D91580147E919CC59 ] C:\WINDOWS\system32\lmhsvc.dll
11:02:32.0875 3772 C:\WINDOWS\system32\lmhsvc.dll - ok
11:02:32.0890 3772 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] C:\WINDOWS\system32\schedsvc.dll
11:02:32.0890 3772 C:\WINDOWS\system32\schedsvc.dll - ok
11:02:32.0906 3772 [ E47E364C96467FD54FA44D59F927C3AB ] C:\WINDOWS\system32\msidle.dll
11:02:32.0906 3772 C:\WINDOWS\system32\msidle.dll - ok
11:02:32.0937 3772 [ 60784F891563FB1B767F70117FC2428F ] C:\WINDOWS\system32\spoolsv.exe
11:02:32.0937 3772 C:\WINDOWS\system32\spoolsv.exe - ok
11:02:32.0953 3772 [ DEF7A7882BEC100FE0B2CE2549188F9D ] C:\WINDOWS\system32\audiosrv.dll
11:02:32.0953 3772 C:\WINDOWS\system32\audiosrv.dll - ok
11:02:32.0984 3772 [ A8888A5327621856C0CEC4E385F69309 ] C:\WINDOWS\system32\wkssvc.dll
11:02:32.0984 3772 C:\WINDOWS\system32\wkssvc.dll - ok
11:02:33.0000 3772 [ C0BB7D1615E1ACBDC99757F6CEAF8CF0 ] C:\WINDOWS\system32\drivers\nwlnkspx.sys
11:02:33.0000 3772 C:\WINDOWS\system32\drivers\nwlnkspx.sys - ok
11:02:33.0015 3772 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] C:\WINDOWS\system32\drivers\parvdm.sys
11:02:33.0015 3772 C:\WINDOWS\system32\drivers\parvdm.sys - ok
11:02:33.0046 3772 [ 085ED2E391A871C7BAE87E0228B546BA ] C:\WINDOWS\system32\cscui.dll
11:02:33.0046 3772 C:\WINDOWS\system32\cscui.dll - ok
11:02:33.0062 3772 [ 01E81C84AD1D0ACC61CF3CFD06632210 ] C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
11:02:33.0062 3772 C:\Program Files\SUPERAntiSpyware\SASCORE.EXE - ok
11:02:33.0078 3772 [ 50A166237A0FA771261275A405646CC0 ] C:\WINDOWS\system32\powrprof.dll
11:02:33.0078 3772 C:\WINDOWS\system32\powrprof.dll - ok
11:02:33.0093 3772 [ 3E2F3E2F4A82B7FAE23BAB864FB0F837 ] C:\WINDOWS\system32\dpcdll.dll
11:02:33.0093 3772 C:\WINDOWS\system32\dpcdll.dll - ok
11:02:33.0125 3772 [ 680B56A8B62D1BCF4A0B2AAAD03D88E4 ] C:\WINDOWS\system32\wdmaud.drv
11:02:33.0125 3772 C:\WINDOWS\system32\wdmaud.drv - ok
11:02:33.0140 3772 [ A93AEE1928A9D7CE3E16D24EC7380F89 ] C:\WINDOWS\system32\userinit.exe
11:02:33.0140 3772 C:\WINDOWS\system32\userinit.exe - ok
11:02:33.0156 3772 [ 6768ACF64B18196494413695F0C3A00F ] C:\WINDOWS\system32\drivers\wdmaud.sys
11:02:33.0156 3772 C:\WINDOWS\system32\drivers\wdmaud.sys - ok
11:02:33.0187 3772 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] C:\WINDOWS\system32\drivers\sysaudio.sys
11:02:33.0187 3772 C:\WINDOWS\system32\drivers\sysaudio.sys - ok
11:02:33.0203 3772 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] C:\WINDOWS\system32\drivers\splitter.sys
11:02:33.0203 3772 C:\WINDOWS\system32\drivers\splitter.sys - ok
11:02:33.0218 3772 [ 8BED39E3C35D6A489438B8141717A557 ] C:\WINDOWS\system32\drivers\aec.sys
11:02:33.0218 3772 C:\WINDOWS\system32\drivers\aec.sys - ok
11:02:33.0234 3772 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] C:\WINDOWS\system32\drivers\swmidi.sys
11:02:33.0234 3772 C:\WINDOWS\system32\drivers\swmidi.sys - ok
11:02:33.0265 3772 [ 8A208DFCF89792A484E76C40E5F50B45 ] C:\WINDOWS\system32\drivers\dmusic.sys
11:02:33.0265 3772 C:\WINDOWS\system32\drivers\dmusic.sys - ok
11:02:33.0281 3772 [ 692BCF44383D056AED41B045A323D378 ] C:\WINDOWS\system32\drivers\kmixer.sys
11:02:33.0281 3772 C:\WINDOWS\system32\drivers\kmixer.sys - ok
11:02:33.0312 3772 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] C:\WINDOWS\system32\drivers\drmkaud.sys
11:02:33.0312 3772 C:\WINDOWS\system32\drivers\drmkaud.sys - ok
11:02:33.0312 3772 [ 9A3BD5F55AADFF859539142F6328A66E ] C:\WINDOWS\system32\msacm32.drv
11:02:33.0312 3772 C:\WINDOWS\system32\msacm32.drv - ok
11:02:33.0328 3772 [ 5C12660A97822F6E61576943B49AAAD6 ] C:\WINDOWS\system32\midimap.dll
11:02:33.0328 3772 C:\WINDOWS\system32\midimap.dll - ok
11:02:33.0343 3772 [ 506708142BC63DABA64F2D3AD1DCD5BF ] C:\Program Files\Google\Update\GoogleUpdate.exe
11:02:33.0343 3772 C:\Program Files\Google\Update\GoogleUpdate.exe - ok
11:02:33.0375 3772 [ 9FF47CD8A3787C8FD3CDFE40441C722E ] C:\Program Files\Google\Update\1.3.21.123\goopdate.dll
11:02:33.0375 3772 C:\Program Files\Google\Update\1.3.21.123\goopdate.dll - ok
11:02:33.0406 3772 [ 574738F61FCA2935F5265DC4E5691314 ] C:\WINDOWS\system32\qmgr.dll
11:02:33.0406 3772 C:\WINDOWS\system32\qmgr.dll - ok
11:02:33.0421 3772 [ D87ACAED61E417BBA546CED5E7E36D9C ] C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:02:33.0421 3772 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe - ok
11:02:33.0437 3772 [ 128DD9AF8640DBCC711940903C8B554F ] C:\WINDOWS\system32\mscoree.dll
11:02:33.0437 3772 C:\WINDOWS\system32\mscoree.dll - ok
11:02:33.0468 3772 [ C14AA05881A35B6D6BB8D55B117EE22D ] C:\WINDOWS\system32\shfolder.dll
11:02:33.0468 3772 C:\WINDOWS\system32\shfolder.dll - ok
11:02:33.0484 3772 [ B6E6F3F5B63053D5DC1F4EE32992492F ] C:\WINDOWS\system32\dbghelp.dll
11:02:33.0484 3772 C:\WINDOWS\system32\dbghelp.dll - ok
11:02:33.0531 3772 [ 684559A03CBC1D05BA120A18B0D8BA5D ] C:\WINDOWS\system32\winhttp.dll
11:02:33.0531 3772 C:\WINDOWS\system32\winhttp.dll - ok
11:02:33.0546 3772 [ C9564CF4976E7E96B4052737AA2492B4 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll
11:02:33.0546 3772 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll - ok
11:02:33.0578 3772 [ 12896823FB95BFB3DC9B46BCAEDC9923 ] C:\WINDOWS\explorer.exe
11:02:33.0578 3772 C:\WINDOWS\explorer.exe - ok
11:02:33.0593 3772 [ E392E172687BE172F8600C5F41AB03D9 ] C:\WINDOWS\system32\browseui.dll
11:02:33.0593 3772 C:\WINDOWS\system32\browseui.dll - ok
11:02:33.0609 3772 [ 937C2A0C453625F42FAB39CD78EC0166 ] C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll
11:02:33.0609 3772 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll - ok
11:02:33.0625 3772 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] C:\WINDOWS\system32\netman.dll
11:02:33.0625 3772 C:\WINDOWS\system32\netman.dll - ok
11:02:33.0640 3772 [ 26CB10FA893F940AB09713FF46DCDADE ] C:\WINDOWS\system32\shdocvw.dll
11:02:33.0640 3772 C:\WINDOWS\system32\shdocvw.dll - ok
11:02:33.0656 3772 [ 133F82B6391F3390BECFA429C23FB2BE ] C:\WINDOWS\system32\Crypserv.exe
11:02:33.0656 3772 C:\WINDOWS\system32\Crypserv.exe - ok
11:02:33.0671 3772 [ EA5B8BECA3F279C757578CD7F1E95855 ] C:\WINDOWS\system32\mprapi.dll
11:02:33.0671 3772 C:\WINDOWS\system32\mprapi.dll - ok
11:02:33.0687 3772 [ AE5A69F44C1F97EDC83237FC0B29B6FB ] C:\Program Files\Google\Update\1.3.21.123\GoogleCrashHandler.exe
11:02:33.0687 3772 C:\Program Files\Google\Update\1.3.21.123\GoogleCrashHandler.exe - ok
11:02:33.0703 3772 [ 4044E880593FE1AC9942190FCE414BE7 ] C:\WINDOWS\system32\mstask.dll
11:02:33.0703 3772 C:\WINDOWS\system32\mstask.dll - ok
11:02:33.0718 3772 [ 2CDAE321B8E878A278BA2D2FA013060B ] C:\WINDOWS\system32\activeds.dll
11:02:33.0718 3772 C:\WINDOWS\system32\activeds.dll - ok
11:02:33.0734 3772 [ 0D84657DBF93DB98673DEFDF2B29E25A ] C:\WINDOWS\system32\adsldpc.dll
11:02:33.0734 3772 C:\WINDOWS\system32\adsldpc.dll - ok
11:02:33.0750 3772 [ 876CCF164E08D6B903CD14398E056DD2 ] C:\WINDOWS\system32\rtutils.dll
11:02:33.0750 3772 C:\WINDOWS\system32\rtutils.dll - ok
11:02:33.0765 3772 [ 062F837C1FBDB6A0A75F82EFC2EE8E74 ] C:\WINDOWS\system32\netshell.dll
11:02:33.0765 3772 C:\WINDOWS\system32\netshell.dll - ok
11:02:33.0781 3772 [ D4991D98F2DB73C60D042F1AEF79EFAE ] C:\WINDOWS\system32\es.dll
11:02:33.0781 3772 C:\WINDOWS\system32\es.dll - ok
11:02:33.0796 3772 [ B4ED498E3BFEE64E952BC44FC6057DB8 ] C:\WINDOWS\system32\desk.cpl
11:02:33.0796 3772 C:\WINDOWS\system32\desk.cpl - ok
11:02:33.0812 3772 [ 235892E493845D64D890163CFEF90E97 ] C:\WINDOWS\system32\credui.dll
11:02:33.0812 3772 C:\WINDOWS\system32\credui.dll - ok
11:02:33.0828 3772 [ A314EEA2A503A8E04085201E436384A5 ] C:\WINDOWS\system32\themeui.dll
11:02:33.0828 3772 C:\WINDOWS\system32\themeui.dll - ok
11:02:33.0828 3772 [ 8E2CC37BA87D8F681066E0E9C8A19F73 ] C:\WINDOWS\system32\dot3api.dll
11:02:33.0843 3772 C:\WINDOWS\system32\dot3api.dll - ok
11:02:33.0859 3772 [ 4E8F3230BAC8C1CAADF01A8C728E1C5C ] C:\WINDOWS\system32\dot3dlg.dll
11:02:33.0859 3772 C:\WINDOWS\system32\dot3dlg.dll - ok
11:02:33.0875 3772 [ CA04959077AFE36369D37B3504740C87 ] C:\WINDOWS\system32\onex.dll
11:02:33.0875 3772 C:\WINDOWS\system32\onex.dll - ok
11:02:33.0890 3772 [ 5DB625E7D095604010CF84DE2D8ACFA6 ] C:\WINDOWS\system32\eappcfg.dll
11:02:33.0890 3772 C:\WINDOWS\system32\eappcfg.dll - ok
11:02:33.0906 3772 [ 912B67BB8249925A5C972FC5839EAE09 ] C:\WINDOWS\system32\actxprxy.dll
11:02:33.0906 3772 C:\WINDOWS\system32\actxprxy.dll - ok
11:02:33.0906 3772 [ ABC4206543450C0666D152F4B65833B8 ] C:\WINDOWS\system32\eappprxy.dll
11:02:33.0921 3772 C:\WINDOWS\system32\eappprxy.dll - ok
11:02:33.0921 3772 [ 92C4F48B62B0B876194584C3FF09CCB6 ] C:\WINDOWS\system32\rasapi32.dll
11:02:33.0921 3772 C:\WINDOWS\system32\rasapi32.dll - ok
11:02:33.0953 3772 [ 4DEF926F6A0545AE486A03C84F2EE482 ] C:\WINDOWS\system32\rasman.dll
11:02:33.0953 3772 C:\WINDOWS\system32\rasman.dll - ok
11:02:33.0968 3772 [ 00AABF131B4823785818DB99A075A313 ] C:\WINDOWS\system32\tapi32.dll
11:02:33.0968 3772 C:\WINDOWS\system32\tapi32.dll - ok
11:02:33.0984 3772 [ F8B823414A22DBF3BEC10DCAA5F93CD8 ] C:\Program Files\Common Files\Motive\McciCMService.exe
11:02:33.0984 3772 C:\Program Files\Common Files\Motive\McciCMService.exe - ok
11:02:34.0000 3772 [ 767FF54A552732CE772C2302025FA82F ] C:\WINDOWS\system32\wzcsapi.dll
11:02:34.0000 3772 C:\WINDOWS\system32\wzcsapi.dll - ok
11:02:34.0015 3772 [ 994AD0D8550B8B26990A6E3AA0791502 ] C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll
11:02:34.0015 3772 C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll - ok
11:02:34.0031 3772 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] C:\WINDOWS\system32\srvsvc.dll
11:02:34.0031 3772 C:\WINDOWS\system32\srvsvc.dll - ok
11:02:34.0031 3772 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] C:\WINDOWS\system32\wzcsvc.dll
11:02:34.0046 3772 C:\WINDOWS\system32\wzcsvc.dll - ok
11:02:34.0046 3772 [ 2975C66459C426C20BC22D639DF6B611 ] C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
11:02:34.0062 3772 C:\Program Files\SUPERAntiSpyware\SASSEH.DLL - ok
11:02:34.0062 3772 [ 20FD44370267CCD0A64A1B31861C21D2 ] C:\WINDOWS\system32\netmsg.dll
11:02:34.0062 3772 C:\WINDOWS\system32\netmsg.dll - ok
11:02:34.0078 3772 [ 38D332A6D56AF32635675F132548343E ] C:\WINDOWS\system32\drivers\fastfat.sys
11:02:34.0078 3772 C:\WINDOWS\system32\drivers\fastfat.sys - ok
11:02:34.0093 3772 [ 7B0770526801F05D58C51A3DFB87B4BD ] C:\WINDOWS\system32\wmi.dll
11:02:34.0093 3772 C:\WINDOWS\system32\wmi.dll - ok
11:02:34.0109 3772 [ E6EF7BC927D9F8F9BA1584BFC39E0C6F ] C:\WINDOWS\system32\eapolqec.dll
11:02:34.0109 3772 C:\WINDOWS\system32\eapolqec.dll - ok
11:02:34.0125 3772 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] C:\WINDOWS\system32\drivers\srv.sys
11:02:34.0125 3772 C:\WINDOWS\system32\drivers\srv.sys - ok
11:02:34.0140 3772 [ 8AE93AACC648921BAACB8602991AC4B3 ] C:\WINDOWS\system32\qutil.dll
11:02:34.0140 3772 C:\WINDOWS\system32\qutil.dll - ok
11:02:34.0156 3772 [ 6D778E0F95447E6546553EEEA709D03C ] C:\WINDOWS\system32\cmd.exe
11:02:34.0156 3772 C:\WINDOWS\system32\cmd.exe - ok
11:02:34.0171 3772 [ 53249B2147DDC8212B290ACF80570290 ] C:\WINDOWS\system32\ieframe.dll
11:02:34.0171 3772 C:\WINDOWS\system32\ieframe.dll - ok
11:02:34.0187 3772 [ 627FA58ADC043704F9D14CA44340956F ] C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe
11:02:34.0187 3772 C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe - ok
11:02:34.0203 3772 [ 58A14C45A5CD2528F10A889E7B0C3FC2 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_92453bb7\atl90.dll
11:02:34.0203 3772 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_92453bb7\atl90.dll - ok
11:02:34.0218 3772 [ 4C39358EBDD2FFCD9132A30E1EC31E16 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll
11:02:34.0218 3772 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll - ok
11:02:34.0234 3772 [ CDBE9690CF2B8409FACAD94FAC9479C9 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll
11:02:34.0234 3772 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll - ok
11:02:34.0250 3772 [ 4B83FCBBE72AF5F99D109798653E8B78 ] C:\WINDOWS\system32\ipxsap.dll
11:02:34.0250 3772 C:\WINDOWS\system32\ipxsap.dll - ok
11:02:34.0265 3772 [ B92A85618A470F4406CEE8785CE89B4F ] C:\WINDOWS\system32\rtm.dll
11:02:34.0265 3772 C:\WINDOWS\system32\rtm.dll - ok
11:02:34.0281 3772 [ D05AB88927849DF74CF4F1C303DAEB4F ] C:\WINDOWS\system32\adptif.dll
11:02:34.0281 3772 C:\WINDOWS\system32\adptif.dll - ok
11:02:34.0296 3772 [ 332760FBA1655FCFD35BD6F4FD871300 ] C:\WINDOWS\system32\ipsecsvc.dll
11:02:34.0296 3772 C:\WINDOWS\system32\ipsecsvc.dll - ok
11:02:34.0312 3772 [ C5FF8682EADA5B3B27A865F1C3EF9270 ] C:\WINDOWS\system32\oakley.dll
11:02:34.0312 3772 C:\WINDOWS\system32\oakley.dll - ok
11:02:34.0328 3772 [ 853D0D0C6F02D7BFDF1CF99DD7553732 ] C:\WINDOWS\system32\pstorsvc.dll
11:02:34.0328 3772 C:\WINDOWS\system32\pstorsvc.dll - ok
11:02:34.0343 3772 [ 248712EA6BA17B9FF0C542A3828375DD ] C:\WINDOWS\system32\winipsec.dll
11:02:34.0343 3772 C:\WINDOWS\system32\winipsec.dll - ok
11:02:34.0359 3772 [ 22D89D84E8E081CDA529DBF8C0255A38 ] C:\WINDOWS\system32\psbase.dll
11:02:34.0359 3772 C:\WINDOWS\system32\psbase.dll - ok
11:02:34.0375 3772 [ CBE612E2BB6A10E3563336191EDA1250 ] C:\WINDOWS\system32\seclogon.dll
11:02:34.0375 3772 C:\WINDOWS\system32\seclogon.dll - ok
11:02:34.0390 3772 [ 3805DF0AC4296A34BA4BF93B346CC378 ] C:\WINDOWS\system32\srsvc.dll
11:02:34.0390 3772 C:\WINDOWS\system32\srsvc.dll - ok
11:02:34.0406 3772 [ FEDE68BF80052BAD393AFD5C2E60DCB0 ] C:\WINDOWS\system32\dssenh.dll
11:02:34.0406 3772 C:\WINDOWS\system32\dssenh.dll - ok
11:02:34.0421 3772 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] C:\WINDOWS\system32\sens.dll
11:02:34.0421 3772 C:\WINDOWS\system32\sens.dll - ok
11:02:34.0437 3772 [ 79E3A8C328E7E569C32B0998377D9742 ] C:\WINDOWS\system32\spoolss.dll
11:02:34.0437 3772 C:\WINDOWS\system32\spoolss.dll - ok
11:02:34.0453 3772 [ DF8444A8FA8FD38D8848BDD40A8403B3 ] C:\WINDOWS\system32\drivers\tmcomm.sys
11:02:34.0453 3772 C:\WINDOWS\system32\drivers\tmcomm.sys - ok
11:02:34.0453 3772 [ FF3477C03BE7201C294C35F684B3479F ] C:\WINDOWS\system32\termsrv.dll
11:02:34.0468 3772 C:\WINDOWS\system32\termsrv.dll - ok
11:02:34.0468 3772 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] C:\WINDOWS\system32\wiaservc.dll
11:02:34.0468 3772 C:\WINDOWS\system32\wiaservc.dll - ok
11:02:34.0484 3772 [ 2D0E4ED081963804CCC196A0929275B5 ] C:\WINDOWS\system32\wbem\wmisvc.dll
11:02:34.0484 3772 C:\WINDOWS\system32\wbem\wmisvc.dll - ok
11:02:34.0500 3772 [ 5677DFE438EC1F009273FC84FEED6B10 ] C:\WINDOWS\system32\localspl.dll
11:02:34.0500 3772 C:\WINDOWS\system32\localspl.dll - ok
11:02:34.0515 3772 [ ACACB8B14E66109B8ACD6644B5574B9A ] C:\WINDOWS\system32\vssapi.dll
11:02:34.0515 3772 C:\WINDOWS\system32\vssapi.dll - ok
11:02:34.0531 3772 [ 5F0CE62E0831CF972EC6949FD3E37DA7 ] C:\WINDOWS\system32\cfgmgr32.dll
11:02:34.0531 3772 C:\WINDOWS\system32\cfgmgr32.dll - ok
11:02:34.0546 3772 [ DF6551E4C4C46655A0C76194F1FCEA5D ] C:\WINDOWS\system32\icaapi.dll
11:02:34.0546 3772 C:\WINDOWS\system32\icaapi.dll - ok
11:02:34.0562 3772 [ CFD4E51402DA9838B5A04AE680AF54A0 ] C:\WINDOWS\system32\browser.dll
11:02:34.0562 3772 C:\WINDOWS\system32\browser.dll - ok
11:02:34.0578 3772 [ 4AC2FA4A6F0DF2511BAC13393C06EFF1 ] C:\WINDOWS\system32\mscms.dll
11:02:34.0578 3772 C:\WINDOWS\system32\mscms.dll - ok
11:02:34.0593 3772 [ 2D65D56C2F8B6CC5EBFF8E7200C30304 ] C:\WINDOWS\system32\mstlsapi.dll
11:02:34.0593 3772 C:\WINDOWS\system32\mstlsapi.dll - ok
11:02:34.0609 3772 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] C:\WINDOWS\system32\wuauserv.dll
11:02:34.0609 3772 C:\WINDOWS\system32\wuauserv.dll - ok
11:02:34.0625 3772 [ 83F41D0D89645D7235C051AB1D9523AC ] C:\WINDOWS\system32\ipnathlp.dll
11:02:34.0625 3772 C:\WINDOWS\system32\ipnathlp.dll - ok
11:02:34.0640 3772 [ 7778BDFA3F6F6FBA0E75B9594098F737 ] C:\WINDOWS\system32\searchindexer.exe
11:02:34.0640 3772 C:\WINDOWS\system32\searchindexer.exe - ok
11:02:34.0656 3772 [ 5D3D1AB0EF4EA55B731863050482C111 ] C:\WINDOWS\system32\cnbjmon.dll
11:02:34.0656 3772 C:\WINDOWS\system32\cnbjmon.dll - ok
11:02:34.0671 3772 [ FC3EC24FCE372C89423E015A2AC1A31E ] C:\WINDOWS\system32\wuaueng.dll
11:02:34.0671 3772 C:\WINDOWS\system32\wuaueng.dll - ok
11:02:34.0687 3772 [ C14350FC0D47D806699C4F907FC6785B ] C:\WINDOWS\system32\cryptnet.dll
11:02:34.0687 3772 C:\WINDOWS\system32\cryptnet.dll - ok
11:02:34.0703 3772 [ 3CBA2210FA39C6ED7895634842E930DD ] C:\WINDOWS\system32\sensapi.dll
11:02:34.0703 3772 C:\WINDOWS\system32\sensapi.dll - ok
11:02:34.0718 3772 [ A31D3787ECB0E43EF63CE410F4E96C18 ] C:\WINDOWS\system32\cnbjmon2.dll
11:02:34.0718 3772 C:\WINDOWS\system32\cnbjmon2.dll - ok
11:02:34.0734 3772 [ 0CBD1906F74BEB539FCEF6493095B933 ] C:\WINDOWS\system32\tquery.dll
11:02:34.0734 3772 C:\WINDOWS\system32\tquery.dll - ok
11:02:34.0750 3772 [ F9D3C78CFE15271D80790677C893CE45 ] C:\WINDOWS\system32\cabinet.dll
11:02:34.0750 3772 C:\WINDOWS\system32\cabinet.dll - ok
11:02:34.0765 3772 [ B995A68A741A2D6D372B4B2409EDC38B ] C:\WINDOWS\system32\CNMLM2R.DLL
11:02:34.0765 3772 C:\WINDOWS\system32\CNMLM2R.DLL - ok
11:02:34.0781 3772 [ B85E95679B5ADC12311BCD3F5385D623 ] C:\WINDOWS\system32\mspatcha.dll
11:02:34.0781 3772 C:\WINDOWS\system32\mspatcha.dll - ok
11:02:34.0796 3772 [ 7C278E6408D1DCE642230C0585A854D5 ] C:\WINDOWS\system32\wscsvc.dll
11:02:34.0796 3772 C:\WINDOWS\system32\wscsvc.dll - ok
11:02:34.0812 3772 [ ED0C0DF222209E43AD9AFBF3FE87DDE0 ] C:\WINDOWS\system32\comsvcs.dll
11:02:34.0812 3772 C:\WINDOWS\system32\comsvcs.dll - ok
11:02:34.0812 3772 [ 89D74683C859B7982056D15938BACA3E ] C:\WINDOWS\system32\propsys.dll
11:02:34.0812 3772 C:\WINDOWS\system32\propsys.dll - ok
11:02:34.0828 3772 [ 690D97864735E8ECD87F55777E266690 ] C:\WINDOWS\system32\colbact.dll
11:02:34.0828 3772 C:\WINDOWS\system32\colbact.dll - ok
11:02:34.0859 3772 [ 36795A645EAA47FE31D2A8F136A2C69B ] C:\WINDOWS\system32\mtxclu.dll
11:02:34.0859 3772 C:\WINDOWS\system32\mtxclu.dll - ok
11:02:34.0875 3772 [ 222DE7F5EDB9DDBE628384A1A8BE59CE ] C:\WINDOWS\system32\pjlmon.dll
11:02:34.0875 3772 C:\WINDOWS\system32\pjlmon.dll - ok
11:02:34.0875 3772 [ DF82E222578DBE59FCBBD69A02E4C806 ] C:\WINDOWS\system32\clusapi.dll
11:02:34.0890 3772 C:\WINDOWS\system32\clusapi.dll - ok
11:02:34.0890 3772 [ F51EBB6FC536A6B2D588FD668D3A8249 ] C:\WINDOWS\system32\resutils.dll
11:02:34.0890 3772 C:\WINDOWS\system32\resutils.dll - ok
11:02:34.0906 3772 [ E65C5F612400B39D7AA83E7057D798C2 ] C:\WINDOWS\system32\mssrch.dll
11:02:34.0906 3772 C:\WINDOWS\system32\mssrch.dll - ok
11:02:34.0921 3772 [ AE0382AD9C73D343D85E1A50C80B7C20 ] C:\WINDOWS\system32\tcpmon.dll
11:02:34.0921 3772 C:\WINDOWS\system32\tcpmon.dll - ok
11:02:34.0953 3772 [ F0BF811622F2DD6C8E26EE4600D83731 ] C:\WINDOWS\system32\wbem\wbemcore.dll
11:02:34.0953 3772 C:\WINDOWS\system32\wbem\wbemcore.dll - ok
11:02:34.0968 3772 [ F26385E8BA4549B5186B774EC0E45D86 ] C:\WINDOWS\system32\usbmon.dll
11:02:34.0968 3772 C:\WINDOWS\system32\usbmon.dll - ok
11:02:34.0968 3772 [ E4616430709F440CF1809D88DC2366EA ] C:\WINDOWS\system32\wbem\esscli.dll
11:02:34.0984 3772 C:\WINDOWS\system32\wbem\esscli.dll - ok
11:02:34.0984 3772 [ 378A0AEFB11D8B0DC8C27B9F7604B88D ] C:\WINDOWS\system32\wbem\fastprox.dll
11:02:34.0984 3772 C:\WINDOWS\system32\wbem\fastprox.dll - ok
11:02:35.0000 3772 [ 8EA4D2FB065D9A7CB63D36F80180D08C ] C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD2R.DLL
11:02:35.0000 3772 C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD2R.DLL - ok
11:02:35.0015 3772 [ 3458EDA96E30FBD0477A2800D3FB1909 ] C:\WINDOWS\system32\wups.dll
11:02:35.0015 3772 C:\WINDOWS\system32\wups.dll - ok
11:02:35.0031 3772 [ 010472D0AE758227C6F6E6933549C219 ] C:\WINDOWS\system32\wbem\wbemsvc.dll
11:02:35.0031 3772 C:\WINDOWS\system32\wbem\wbemsvc.dll - ok
11:02:35.0046 3772 [ EEE7F12D9FF46F68FBC0DA059A359E9E ] C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
11:02:35.0046 3772 C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll - ok
11:02:35.0062 3772 [ BDC0C99E472176C8C2C853A68ADC5073 ] C:\WINDOWS\system32\wups2.dll
11:02:35.0062 3772 C:\WINDOWS\system32\wups2.dll - ok
11:02:35.0078 3772 [ 3273D1565BF30225C115B480A3BB2C9D ] C:\WINDOWS\system32\wbem\wmiutils.dll
11:02:35.0078 3772 C:\WINDOWS\system32\wbem\wmiutils.dll - ok
11:02:35.0093 3772 [ 942A17D2901A31EA68627CBFFCD268CC ] C:\WINDOWS\system32\wbem\repdrvfs.dll
11:02:35.0093 3772 C:\WINDOWS\system32\wbem\repdrvfs.dll - ok
11:02:35.0109 3772 [ 2E0B0A051FFAA86E358465BB0880D453 ] C:\WINDOWS\system32\wuauclt.exe
11:02:35.0109 3772 C:\WINDOWS\system32\wuauclt.exe - ok
11:02:35.0125 3772 [ 071143F687B4F887E21461CA6CC7EB29 ] C:\WINDOWS\system32\wbem\wmiprvsd.dll
11:02:35.0125 3772 C:\WINDOWS\system32\wbem\wmiprvsd.dll - ok
11:02:35.0156 3772 [ 26D881D27CBE51D3614E68D7313EA026 ] C:\WINDOWS\system32\wbem\wbemess.dll
11:02:35.0156 3772 C:\WINDOWS\system32\wbem\wbemess.dll - ok
11:02:35.0171 3772 [ 22DD6D7D4BFE2B8CE705CC950C8AEA4C ] C:\WINDOWS\system32\win32spl.dll
11:02:35.0171 3772 C:\WINDOWS\system32\win32spl.dll - ok
11:02:35.0171 3772 [ 8BEAF2B4BCDE405AF7EC46A9E03B2D65 ] C:\WINDOWS\system32\mssprxy.dll
11:02:35.0187 3772 C:\WINDOWS\system32\mssprxy.dll - ok
11:02:35.0187 3772 [ 1A617835452EEE5060976C9B9F5FE635 ] C:\WINDOWS\system32\wuapi.dll
11:02:35.0187 3772 C:\WINDOWS\system32\wuapi.dll - ok
11:02:35.0203 3772 [ 43E4758953F454090CAD65C303796ED5 ] C:\WINDOWS\system32\query.dll
11:02:35.0203 3772 C:\WINDOWS\system32\query.dll - ok
11:02:35.0218 3772 [ B41D53899E37CC43DA85DA19998BEE81 ] C:\WINDOWS\system32\netrap.dll
11:02:35.0218 3772 C:\WINDOWS\system32\netrap.dll - ok
11:02:35.0234 3772 [ D26451B540720A7313A9BCBE794DAF62 ] C:\WINDOWS\system32\wbem\ncprov.dll
11:02:35.0234 3772 C:\WINDOWS\system32\wbem\ncprov.dll - ok
11:02:35.0250 3772 [ 6404807ABC7AF52FA3792697AE638B50 ] C:\WINDOWS\system32\wbem\wbemcons.dll
11:02:35.0250 3772 C:\WINDOWS\system32\wbem\wbemcons.dll - ok
11:02:35.0265 3772 [ EE4C651A217B01D636B5364AC77DA892 ] C:\WINDOWS\system32\inetpp.dll
11:02:35.0265 3772 C:\WINDOWS\system32\inetpp.dll - ok
11:02:35.0281 3772 [ D1E18F4AE94FFEC7270BE0A10C0B295E ] C:\WINDOWS\system32\xmllite.dll
11:02:35.0281 3772 C:\WINDOWS\system32\xmllite.dll - ok
11:02:35.0296 3772 [ FFB3115AA757ABEFBA7FBA90BAD5DD0A ] C:\WINDOWS\system32\en-US\tquery.dll.mui
11:02:35.0296 3772 C:\WINDOWS\system32\en-US\tquery.dll.mui - ok
11:02:35.0312 3772 [ 8F580BCC5296ECC9DC8A649D75BE6BA5 ] C:\WINDOWS\system32\msscb.dll
11:02:35.0312 3772 C:\WINDOWS\system32\msscb.dll - ok
11:02:35.0328 3772 [ 047CD344AC7B76BA3C224FAE1A4627C9 ] C:\WINDOWS\system32\WgaTray.exe
11:02:35.0328 3772 C:\WINDOWS\system32\WgaTray.exe - ok
11:02:35.0343 3772 [ 3307A07B81206F354F0D4BEFEE922437 ] C:\WINDOWS\system32\LegitCheckControl.DLL
11:02:35.0343 3772 C:\WINDOWS\system32\LegitCheckControl.DLL - ok
11:02:35.0359 3772 [ 798A9E6828997EEF4517ADA8A2259831 ] C:\WINDOWS\system32\wbem\wmiprvse.exe
11:02:35.0359 3772 C:\WINDOWS\system32\wbem\wmiprvse.exe - ok
11:02:35.0375 3772 [ 6895427873D6C37A6D6DA7C3DB37DA14 ] C:\WINDOWS\system32\licwmi.dll
11:02:35.0375 3772 C:\WINDOWS\system32\licwmi.dll - ok
11:02:35.0390 3772 [ 4306FA2F1099D7C606139255FDB62B19 ] C:\WINDOWS\system32\wbem\framedyn.dll
11:02:35.0390 3772 C:\WINDOWS\system32\wbem\framedyn.dll - ok
11:02:35.0406 3772 [ 1793CC660605F63B14FB96C7707F75BA ] C:\WINDOWS\system32\perfproc.dll
11:02:35.0406 3772 C:\WINDOWS\system32\perfproc.dll - ok
11:02:35.0421 3772 [ A693A49A67673F2C8D76797EA9A628D0 ] C:\WINDOWS\system32\licdll.dll
11:02:35.0421 3772 C:\WINDOWS\system32\licdll.dll - ok
11:02:35.0437 3772 [ 9EFBB3055B3EECE5B0FC7BAED07A6EE9 ] C:\WINDOWS\system32\msxml6.dll
11:02:35.0437 3772 C:\WINDOWS\system32\msxml6.dll - ok
11:02:35.0453 3772 [ E837FDBB92E9873E538395B623F45462 ] C:\WINDOWS\system32\wbem\cimwin32.dll
11:02:35.0453 3772 C:\WINDOWS\system32\wbem\cimwin32.dll - ok
11:02:35.0468 3772 [ 3420D325EE810E0D0495EA47A64603ED ] C:\Program Files\IObit\Advanced SystemCare 6\DelayLoad.exe
11:02:35.0468 3772 C:\Program Files\IObit\Advanced SystemCare 6\DelayLoad.exe - ok
11:02:35.0484 3772 [ 8C515081584A38AA007909CD02020B3D ] C:\WINDOWS\system32\alg.exe
11:02:35.0484 3772 C:\WINDOWS\system32\alg.exe - ok
11:02:35.0500 3772 [ 178A34E5554DCE485E1262DDF027960C ] C:\DOCUME~1\Owner\LOCALS~1\Temp\406DB210-1B28-43BE-8585-8B34360CA72D.exe
11:02:35.0500 3772 C:\DOCUME~1\Owner\LOCALS~1\Temp\406DB210-1B28-43BE-8585-8B34360CA72D.exe - ok
11:02:35.0515 3772 [ FB6EE278BC2046E0952F320AC62D3E07 ] C:\WINDOWS\system32\dskquota.dll
11:02:35.0515 3772 C:\WINDOWS\system32\dskquota.dll - ok
11:02:35.0531 3772 [ B714735C12A70171DE28657948FD91F1 ] C:\WINDOWS\system32\mlang.dll
11:02:35.0531 3772 C:\WINDOWS\system32\mlang.dll - ok
11:02:35.0546 3772 [ 039399B6F5BB622ECD4AF27FC037F270 ] C:\Program Files\COMODO\COMODO Internet Security\cmdavcen.dll
11:02:35.0546 3772 C:\Program Files\COMODO\COMODO Internet Security\cmdavcen.dll - ok
11:02:35.0562 3772 [ 5A961B491F9A037384247D0DC9B809C6 ] C:\Program Files\COMODO\COMODO Internet Security\cmdboost.dll
11:02:35.0562 3772 C:\Program Files\COMODO\COMODO Internet Security\cmdboost.dll - ok
11:02:35.0578 3772 [ 37A62C6092AADD2EFDE0468DD8818E99 ] C:\WINDOWS\system32\netcfgx.dll
11:02:35.0578 3772 C:\WINDOWS\system32\netcfgx.dll - ok
11:02:35.0578 3772 [ A70A2D85AD143D6BB823C246CEB699A5 ] C:\WINDOWS\system32\ntshrui.dll
11:02:35.0578 3772 C:\WINDOWS\system32\ntshrui.dll - ok
11:02:35.0593 3772 [ 2DC5A8019E2387987905F77C664E4BE2 ] C:\WINDOWS\system32\linkinfo.dll
11:02:35.0593 3772 C:\WINDOWS\system32\linkinfo.dll - ok
11:02:35.0609 3772 [ EE4F22740262299B2905E2F34D104CAF ] C:\Program Files\COMODO\COMODO Internet Security\cmdtrust.dll
11:02:35.0609 3772 C:\Program Files\COMODO\COMODO Internet Security\cmdtrust.dll - ok
11:02:35.0625 3772 [ 48F6477512C9CE8548A13A342986C752 ] C:\Program Files\COMODO\COMODO Internet Security\cmdcfg.dll
11:02:35.0625 3772 C:\Program Files\COMODO\COMODO Internet Security\cmdcfg.dll - ok
11:02:35.0640 3772 [ 50D2105BD1453B4009244EB91518131A ] C:\Program Files\COMODO\COMODO Internet Security\cmdcloud.dll
11:02:35.0640 3772 C:\Program Files\COMODO\COMODO Internet Security\cmdcloud.dll - ok
11:02:35.0656 3772 [ 2A8681AEA24003040CA7D677BE9F1702 ] C:\WINDOWS\system32\drivers\53343036.sys
11:02:35.0656 3772 C:\WINDOWS\system32\drivers\53343036.sys - ok
11:02:35.0671 3772 [ CC8915DB4E33E8FB29CA0D2DBF75306E ] C:\WINDOWS\system32\webcheck.dll
11:02:35.0671 3772 C:\WINDOWS\system32\webcheck.dll - ok
11:02:35.0687 3772 [ D7D69F304A604387B86BE991CBF07663 ] C:\WINDOWS\system32\WPDShServiceObj.dll
11:02:35.0687 3772 C:\WINDOWS\system32\WPDShServiceObj.dll - ok
11:02:35.0703 3772 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] C:\WINDOWS\system32\imapi.exe
11:02:35.0703 3772 C:\WINDOWS\system32\imapi.exe - ok
11:02:35.0718 3772 [ 50512FC9B7878E3C2C147BC17326A7DB ] C:\WINDOWS\system32\stobject.dll
11:02:35.0718 3772 C:\WINDOWS\system32\stobject.dll - ok
11:02:35.0734 3772 [ 231A0B0E3BA7ABFE469A8262FAA1FD71 ] C:\WINDOWS\system32\batmeter.dll
11:02:35.0734 3772 C:\WINDOWS\system32\batmeter.dll - ok
11:02:35.0750 3772 [ 5F1D5F88303D4A4DBC8E5F97BA967CC3 ] C:\WINDOWS\system32\ctfmon.exe
11:02:35.0750 3772 C:\WINDOWS\system32\ctfmon.exe - ok
11:02:35.0765 3772 [ 538A270F35A713C360B7ED4168BB7521 ] C:\WINDOWS\system32\mydocs.dll
11:02:35.0765 3772 C:\WINDOWS\system32\mydocs.dll - ok
11:02:35.0781 3772 [ 3436993699358419DFF0AB9DE669BE92 ] C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
11:02:35.0781 3772 C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe - ok
11:02:35.0796 3772 [ E40FCF943127DDC8FD60554B722D762B ] C:\WINDOWS\system32\msctf.dll
11:02:35.0796 3772 C:\WINDOWS\system32\msctf.dll - ok
11:02:35.0812 3772 [ A687C458B80C7D55CBE39649D952ED2A ] C:\WINDOWS\system32\PortableDeviceTypes.dll
11:02:35.0812 3772 C:\WINDOWS\system32\PortableDeviceTypes.dll - ok
11:02:35.0828 3772 [ 93C088C2AEB2F23E720BDA7E32BD5117 ] C:\WINDOWS\system32\upnp.dll
11:02:35.0828 3772 C:\WINDOWS\system32\upnp.dll - ok
11:02:35.0843 3772 [ 17AA58A54C00F1746B8654C050491F43 ] C:\WINDOWS\system32\msutb.dll
11:02:35.0843 3772 C:\WINDOWS\system32\msutb.dll - ok
11:02:35.0859 3772 [ 3D075865DCC26931972F6476AD0497BE ] C:\WINDOWS\system32\ssdpapi.dll
11:02:35.0859 3772 C:\WINDOWS\system32\ssdpapi.dll - ok
11:02:35.0875 3772 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] C:\WINDOWS\system32\rasmans.dll
11:02:35.0875 3772 C:\WINDOWS\system32\rasmans.dll - ok
11:02:35.0890 3772 [ E132AD94798E72ACB650E985984C7F58 ] C:\WINDOWS\system32\PortableDeviceApi.dll
11:02:35.0890 3772 C:\WINDOWS\system32\PortableDeviceApi.dll - ok
11:02:35.0906 3772 [ F80A415EF82CD06FFAF0D971528EAD38 ] C:\WINDOWS\system32\drivers\http.sys
11:02:35.0906 3772 C:\WINDOWS\system32\drivers\http.sys - ok
11:02:35.0921 3772 [ D9D53AFA94D247308DF77436F03A9D69 ] C:\Program Files\COMODO\COMODO Internet Security\framework.dll
11:02:35.0921 3772 C:\Program Files\COMODO\COMODO Internet Security\framework.dll - ok
11:02:35.0937 3772 [ 0A5679B3714EDAB99E357057EE88FCA6 ] C:\WINDOWS\system32\ssdpsrv.dll
11:02:35.0937 3772 C:\WINDOWS\system32\ssdpsrv.dll - ok
11:02:35.0953 3772 [ 745178DB48B2AB5F4930F5EF0FED903B ] C:\Program Files\COMODO\COMODO Internet Security\cavwpps.dll
11:02:35.0953 3772 C:\Program Files\COMODO\COMODO Internet Security\cavwpps.dll - ok
11:02:35.0968 3772 [ 3CB78C17BB664637787C9A1C98F79C38 ] C:\WINDOWS\system32\tapisrv.dll
11:02:35.0968 3772 C:\WINDOWS\system32\tapisrv.dll - ok
11:02:35.0984 3772 [ F6FAEC07446A78A9C5AF4558FF5BD118 ] C:\WINDOWS\ime\sptip.dll
11:02:35.0984 3772 C:\WINDOWS\ime\sptip.dll - ok
11:02:36.0000 3772 [ 850A6D8082F6F896DD3133453B145495 ] C:\Program Files\COMODO\COMODO Internet Security\platform.dll
11:02:36.0000 3772 C:\Program Files\COMODO\COMODO Internet Security\platform.dll - ok
11:02:36.0015 3772 [ 13D1A1276AAD8F0458137E380136B6C7 ] C:\Program Files\COMODO\COMODO Internet Security\scanners\common.cav
11:02:36.0015 3772 C:\Program Files\COMODO\COMODO Internet Security\scanners\common.cav - ok
11:02:36.0031 3772 [ C7873CE82DBB31A8EEF524A91B1C865D ] C:\Program Files\COMODO\COMODO Internet Security\signmgr.dll
11:02:36.0031 3772 C:\Program Files\COMODO\COMODO Internet Security\signmgr.dll - ok
11:02:36.0046 3772 [ 5F7692CEC90E2E9AA32CD58321E234B8 ] C:\WINDOWS\system32\rastapi.dll
11:02:36.0046 3772 C:\WINDOWS\system32\rastapi.dll - ok
11:02:36.0062 3772 [ AACE07FE34FADDDF973CE068A6424957 ] C:\WINDOWS\system32\unimdm.tsp
11:02:36.0062 3772 C:\WINDOWS\system32\unimdm.tsp - ok
11:02:36.0078 3772 [ F1DAC7969C1337AF790BD1D981AA780C ] C:\WINDOWS\system32\qmgrprxy.dll
11:02:36.0078 3772 C:\WINDOWS\system32\qmgrprxy.dll - ok
11:02:36.0078 3772 [ 995252FCC4692B5B97EE17D596C9386E ] C:\WINDOWS\system32\uniplat.dll
11:02:36.0078 3772 C:\WINDOWS\system32\uniplat.dll - ok
11:02:36.0093 3772 [ 19AE6CBA05B9005698A6DEDCC88F202E ] C:\WINDOWS\system32\unimdmat.dll
11:02:36.0093 3772 C:\WINDOWS\system32\unimdmat.dll - ok
11:02:36.0109 3772 [ FE4A73CDBC882A19D070F1C01586E81A ] C:\WINDOWS\system32\modemui.dll
11:02:36.0109 3772 C:\WINDOWS\system32\modemui.dll - ok
11:02:36.0125 3772 [ 76EC97C5068D3D9FAA7774B0F659D31A ] C:\WINDOWS\system32\kmddsp.tsp
11:02:36.0125 3772 C:\WINDOWS\system32\kmddsp.tsp - ok
11:02:36.0140 3772 [ 4589963D84F2984FA5949A72162BA4F4 ] C:\WINDOWS\system32\ndptsp.tsp
11:02:36.0140 3772 C:\WINDOWS\system32\ndptsp.tsp - ok
11:02:36.0156 3772 [ 8B8A45DF7CEF36D93C7BD3E4C84003B8 ] C:\WINDOWS\system32\ipconf.tsp
11:02:36.0156 3772 C:\WINDOWS\system32\ipconf.tsp - ok
11:02:36.0171 3772 [ 8BC2B02DC11C98D14CEE43B8E8393FF3 ] C:\WINDOWS\system32\h323.tsp
11:02:36.0171 3772 C:\WINDOWS\system32\h323.tsp - ok
11:02:36.0187 3772 [ 6B552ED3BEE5AA3C4560478FF779BA98 ] C:\WINDOWS\system32\hidphone.tsp
11:02:36.0187 3772 C:\WINDOWS\system32\hidphone.tsp - ok
11:02:36.0203 3772 [ 8973122796E3B5D6B5900FC186E55FEA ] C:\WINDOWS\system32\hid.dll
11:02:36.0203 3772 C:\WINDOWS\system32\hid.dll - ok
11:02:36.0218 3772 [ D0545A010ED2259A740C8414899A938F ] C:\WINDOWS\system32\rasppp.dll
11:02:36.0218 3772 C:\WINDOWS\system32\rasppp.dll - ok
11:02:36.0234 3772 [ B464BD425D5D09ABE4192234D1577B22 ] C:\WINDOWS\system32\ntlsapi.dll
11:02:36.0234 3772 C:\WINDOWS\system32\ntlsapi.dll - ok
11:02:36.0250 3772 [ A655C88AA555BB8EF8957BD29408827F ] C:\WINDOWS\system32\rasqec.dll
11:02:36.0250 3772 C:\WINDOWS\system32\rasqec.dll - ok
11:02:36.0265 3772 [ 8BCD11D38FCE43A519246A91CC40DE6A ] C:\WINDOWS\system32\security.dll
11:02:36.0265 3772 C:\WINDOWS\system32\security.dll - ok
11:02:36.0281 3772 [ 56CE97FF94B7662A300D359CD6F4D601 ] C:\WINDOWS\system32\raschap.dll
11:02:36.0281 3772 C:\WINDOWS\system32\raschap.dll - ok
11:02:36.0296 3772 [ A39BE37C9237DB5F1990D61B268EA555 ] C:\WINDOWS\system32\rastls.dll
11:02:36.0296 3772 C:\WINDOWS\system32\rastls.dll - ok
11:02:36.0312 3772 [ B1DED39112E0C85BAFA58DCBEC6718B6 ] C:\WINDOWS\system32\ipxwan.dll
11:02:36.0312 3772 C:\WINDOWS\system32\ipxwan.dll - ok
11:02:36.0328 3772 [ C730F70351D950DDA7388C9A9763CF54 ] C:\WINDOWS\system32\wbem\wmipcima.dll
11:02:36.0328 3772 C:\WINDOWS\system32\wbem\wmipcima.dll - ok
11:02:36.0343 3772 [ 401A8C0BE0BAA7D7A470F0942244152D ] C:\WINDOWS\system32\rasdlg.dll
11:02:36.0343 3772 C:\WINDOWS\system32\rasdlg.dll - ok
11:02:36.0343 3772 ============================================================
11:02:36.0343 3772 Scan finished
11:02:36.0343 3772 ============================================================
11:02:36.0500 3764 Detected object count: 24
11:02:36.0500 3764 Actual detected object count: 24
11:05:01.0406 3764 Afc ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0406 3764 Afc ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0421 3764 BANTExt ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0421 3764 BANTExt ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0421 3764 ch7009 ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0421 3764 ch7009 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0437 3764 ch7017 ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0437 3764 ch7017 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0453 3764 CoachUsb ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0453 3764 CoachUsb ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0453 3764 d3dUtil ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0453 3764 d3dUtil ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0468 3764 fs454 ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0468 3764 fs454 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0484 3764 igdmini ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0484 3764 igdmini ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0484 3764 lvds ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0484 3764 lvds ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0500 3764 McciCMService ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0500 3764 McciCMService ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0500 3764 MREMP50 ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0500 3764 MREMP50 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0515 3764 MREMPR5 ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0515 3764 MREMPR5 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0515 3764 MRENDIS5 ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0515 3764 MRENDIS5 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0531 3764 MRESP50 ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0531 3764 MRESP50 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0531 3764 NetworkX ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0531 3764 NetworkX ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0546 3764 ns2501 ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0546 3764 ns2501 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0546 3764 ns387 ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0546 3764 ns387 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0562 3764 OMCI ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0562 3764 OMCI ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0562 3764 sii164 ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0562 3764 sii164 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0578 3764 STAC97 ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0578 3764 STAC97 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0578 3764 th164 ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0578 3764 th164 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0593 3764 ti410 ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0593 3764 ti410 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0593 3764 UnlockerDriver5 ( UnsignedFile.Multi.Generic ) - skipped by user
11:05:01.0593 3764 UnlockerDriver5 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:05:01.0609 3764 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
11:05:01.0609 3764 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
-hank you,
Karen
MrCharlie
Run TDSSKiller again and choose Delete for this one only: (no need to post the log)
Then………………
Please download and run ComboFix.
The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.
Please visit this webpage for download links, and instructions for running ComboFix
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Information on disabling your malware programs can be found Here.
Make sure you run ComboFix from your desktop.
Give it at least 30-45 minutes to finish if needed.
Please include the C:\ComboFix.txt in your next reply for further review.
MrC
11:05:01.0609 3764 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
11:05:01.0609 3764 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
Then………………
Please download and run ComboFix.
The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.
Please visit this webpage for download links, and instructions for running ComboFix
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Information on disabling your malware programs can be found Here.
Make sure you run ComboFix from your desktop.
Give it at least 30-45 minutes to finish if needed.
Please include the C:\ComboFix.txt in your next reply for further review.
———->NOTE<———-
If you get the message Illegal operation attempted on registry key that has been marked for deletion after you run ComboFix….please reboot the computer, this should resolve the problem. You may have to do this several times if needed.MrC
karenoregon
Hello Mr. Charlie:
Here is the Comb Fix Log:
ComboFix 13-02-13.02 - Owner 02/13/2013 21:35:22.15.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1614 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: COMODO Antivirus *Disabled/Updated* {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
AV: ZoneAlarm Antivirus *Disabled/Updated* {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: COMODO Firewall *Disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\NDP1.1sp1-KB2742597-X86.exe
c:\program files\WindowsXP-KB942288-v3-x86.exe
c:\windows\system32\SET18C.tmp
.
.
((((((((((((((((((((((((( Files Created from 2013-01-14 to 2013-02-14 )))))))))))))))))))))))))))))))
.
.
2013-02-14 05:12 . 2013-02-14 05:12 ——– dc—-w- C:\TDSSKiller_Quarantine
2013-02-09 00:23 . 2013-02-09 00:35 ——– d—–w- c:\documents and settings\Owner\Application Data\Comodo
2013-02-08 23:12 . 2013-02-08 23:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Comodo
2013-02-08 23:12 . 2013-02-08 23:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Comodo Downloader
2013-02-08 23:12 . 2013-02-08 23:12 ——– d—–w- c:\program files\COMODO
2013-02-08 23:04 . 2013-02-08 23:04 130846192 —-a-w- c:\program files\cav_installer.exe
2013-02-08 14:23 . 2012-12-15 00:49 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-02-08 14:23 . 2013-02-08 14:56 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-02-08 02:21 . 2013-02-08 02:27 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Avg2013
2013-02-07 01:40 . 2013-02-07 01:40 ——– d—–w- c:\documents and settings\Owner\Application Data\TuneUp Software
2013-02-07 01:11 . 2013-02-07 01:11 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\MFAData
2013-02-06 12:02 . 2013-02-06 20:50 36760 —-a-w- c:\windows\system32\drivers\fvstore.dat
2013-02-06 11:45 . 2013-02-06 11:45 ——– dc—-w- C:\VTRoot
2013-02-06 11:15 . 2013-02-06 11:15 ——– d-s—w- c:\documents and settings\All Users\Application Data\Shared Space
2013-02-06 07:36 . 2013-02-06 07:36 ——– dc—-w- C:\VritualRoot
2013-02-03 22:08 . 2013-02-03 22:09 ——– d—–w- c:\program files\QuickTime
2013-02-03 22:08 . 2013-02-03 22:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2013-02-03 22:07 . 2013-02-03 22:07 ——– d—–w- c:\program files\Common Files\Apple
2013-02-03 22:06 . 2013-02-03 22:06 ——– d—–w- c:\program files\Apple Software Update
2013-02-03 07:37 . 2013-02-03 22:09 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2013-02-03 07:37 . 2013-02-03 22:09 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2013-02-03 07:37 . 2013-02-03 22:09 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2013-02-03 07:37 . 2013-02-03 22:09 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2013-02-03 07:37 . 2013-02-03 22:09 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2013-02-03 07:37 . 2013-02-03 22:09 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2013-02-03 07:37 . 2013-02-03 22:09 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2013-01-29 07:52 . 2012-05-09 02:35 29528 —-a-w- c:\windows\system32\SmartDefragBootTime.exe
2013-01-29 07:52 . 2010-11-27 02:02 14776 —-a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2013-01-29 07:24 . 2013-01-29 07:24 ——– d—–w- c:\documents and settings\All Users\Application Data\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
2013-01-27 20:54 . 2013-01-27 20:54 4189792 —-a-w- c:\program files\ccsetup327.exe
2013-01-25 06:43 . 2013-01-25 06:43 35488 —-a-w- c:\windows\system32\cmdcsr.dll
2013-01-25 06:43 . 2013-01-25 06:43 354752 —-a-w- c:\windows\system32\guard32.dll
2013-01-25 06:42 . 2013-01-25 06:42 40656 —-a-w- c:\windows\system32\cmdkbd32.dll
2013-01-25 06:42 . 2013-01-25 06:42 263888 —-a-w- c:\windows\system32\cmdvrt32.dll
2013-01-17 03:51 . 2013-01-17 03:51 98752 —-a-w- c:\windows\system32\drivers\inspect.sys
2013-01-17 03:51 . 2013-01-17 03:51 586728 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2013-01-17 03:51 . 2013-01-17 03:51 32824 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2013-01-17 03:51 . 2013-01-17 03:51 18536 —-a-w- c:\windows\system32\drivers\cmderd.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-03 22:03 . 2011-09-14 18:56 40437664 —-a-w- c:\program files\QuickTimeInstaller.exe
2013-01-29 07:21 . 2012-12-28 02:22 21494224 —-a-w- c:\program files\asc-setup.exe
2013-01-26 03:55 . 2003-07-16 20:40 552448 ——w- c:\windows\system32\oleaut32.dll
2013-01-16 02:49 . 2012-12-28 03:56 23360 —-a-w- c:\windows\system32\RegistryDefragBootTime.exe
2013-01-12 21:50 . 2013-01-12 21:50 4178040 —-a-w- c:\program files\ccsetup326.exe
2013-01-12 20:32 . 2012-11-24 22:41 697864 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-12 20:32 . 2011-07-22 08:54 74248 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-10 00:40 . 2012-11-18 00:43 24265736 —-a-w- c:\program files\dotnetfx.exe
2013-01-07 01:16 . 2003-07-16 20:39 2193024 ——w- c:\windows\system32\ntoskrnl.exe
2013-01-07 00:36 . 2002-08-29 01:04 2069760 ——w- c:\windows\system32\ntkrnlpa.exe
2013-01-04 01:20 . 2003-07-16 20:51 1867264 —-a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49 . 2003-07-16 20:34 148992 —-a-w- c:\windows\system32\mpg2splt.ax
2013-01-02 06:49 . 2003-05-13 17:28 1292288 —-a-w- c:\windows\system32\quartz.dll
2012-12-26 20:16 . 2004-02-07 01:05 916480 —-a-w- c:\windows\system32\wininet.dll
2012-12-26 20:16 . 2010-10-14 16:46 43520 ——w- c:\windows\system32\licmgr10.dll
2012-12-26 20:16 . 2010-10-14 16:46 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-12-24 06:40 . 2004-08-04 05:59 385024 ——w- c:\windows\system32\html.iec
2012-12-18 19:00 . 2012-11-03 00:40 4976384 —-a-w- c:\program files\defragsetup.exe
2012-12-16 12:23 . 2003-07-16 20:24 290560 —-a-w- c:\windows\system32\atmfd.dll
2012-11-18 00:57 . 2012-11-18 00:57 2959376 —-a-w- c:\program files\dotnetfx35setup.exe
2012-10-28 00:17 . 2012-10-28 00:17 38984 —-a-w- c:\program files\DellPCDiagnostics.exe
2012-10-27 22:47 . 2012-10-27 22:47 347424 —-a-w- c:\program files\MicrosoftFixit.AudioPlayback.Run.exe
2012-10-27 19:10 . 2012-10-27 19:10 10669896 —-a-w- c:\program files\mbam-setup.exe
2012-02-24 00:50 . 2012-02-24 00:50 8669472 —-a-w- c:\program files\Windows7UpgradeAdvisorSetup.exe
2012-02-16 02:52 . 2012-02-16 02:52 14809712 —-a-w- c:\program files\SUPERAntiSpyware.exe
2011-07-25 03:12 . 2010-07-24 19:14 16409960 —-a-w- c:\program files\spybotsd162.exe
2011-07-23 09:00 . 2011-07-23 09:00 908064 —-a-w- c:\program files\jre-6u26-windows-i586-iftw.exe
2011-07-20 05:55 . 2011-07-20 05:55 684297 —-a-w- c:\program files\unhide.exe
2010-12-26 06:19 . 2010-12-26 06:19 12965392 —-a-w- c:\program files\RealPlayer10-5GOLD.exe
2010-12-26 05:03 . 2010-12-26 05:03 12252656 —-a-w- c:\program files\RealPlayer11GOLD.exe
2010-12-25 07:47 . 2010-12-25 07:47 602464 —-a-w- c:\program files\RealPlayer.exe
2010-12-25 03:18 . 2010-12-24 06:45 25740256 —-a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2010-09-12 01:42 . 2010-09-12 01:42 6776168 —-a-w- c:\program files\WindowsUpdateAgent30-x86.exe
2010-08-26 19:15 . 2008-06-30 18:11 1625600 -c–a-w- c:\program files\MBSASetup-x86-EN.msi
2010-05-22 22:28 . 2010-05-22 22:28 6108728 —-a-w- c:\program files\picasaweb-current-setup.exe
2010-04-19 18:37 . 2010-04-19 18:37 2270216 —-a-w- c:\program files\advisor.exe
2010-02-05 19:35 . 2008-06-09 02:21 1114576 —-a-w- c:\program files\revosetup.exe
2010-01-07 20:04 . 2009-12-24 18:13 9476032 —-a-w- c:\program files\RevoUninProSetup.exe
2009-10-25 20:03 . 2009-10-20 01:14 747520 -c–a-w- c:\program files\MicrosoftFixit50198.msi
2009-10-20 20:54 . 2009-10-20 20:54 16883056 —-a-w- c:\program files\IE8-WindowsXP-x86-ENU.exe
2009-09-27 07:35 . 2008-09-19 06:15 1146184 —-a-w- c:\program files\wlsetup-web.exe
2009-07-25 18:24 . 2009-07-25 18:23 2052104 —-a-w- c:\program files\advisor belarc.exe
2009-06-04 21:16 . 2009-06-04 21:15 14243328 -c–a-w- c:\program files\DM510.32.4071221.EN.msi
2009-04-01 03:21 . 2009-03-10 16:45 224 -c–a-w- c:\program files\fix.bat
2009-01-02 22:57 . 2009-01-02 22:57 1945096 -c–a-w- c:\program files\BELARC advisor.exe
2008-06-23 17:11 . 2008-06-23 17:11 2400784 —-a-w- c:\program files\WLinstaller.exe
2008-01-14 20:32 . 2008-04-25 07:31 6957056 -c–a-w- c:\program files\PhotoLibrary.msp
2006-12-29 23:58 . 2006-12-29 23:58 15505200 -c–a-w- c:\program files\IE7-WindowsXP-x86-enu.exe
2006-12-18 05:44 . 2006-12-18 05:44 20036629 -c–a-w- c:\program files\eppwin300aus.exe
2006-11-07 00:49 . 2006-11-07 00:49 64512 -c–a-w- c:\program files\Compatibility_Check.exe
2006-10-27 16:50 . 2006-10-27 16:51 317248 -c–a-w- c:\program files\WINDOWS OCT06.exe
2005-12-17 01:24 . 2005-12-15 00:35 561 -c–a-w- c:\program files\os449133.bin
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
desktop(2).ini [2004-5-28 84]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
desktop(2).ini [2004-5-28 84]
.
c:\documents and settings\JEFF\Start Menu\Programs\Startup\
desktop(2).ini [2004-5-28 84]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPA
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Installer
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2012-10-25 11:12 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"PPWebCap"=c:\progra~1\ScanSoft\PAPERP~1\PPWebCap.exe
"SUPERAntiSpyware"=c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
"Advanced SystemCare 6"="c:\program files\IObit\Advanced SystemCare 6\ASCTray.exe" /AutoStart
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"OneTouch Monitor"=c:\program files\Visioneer OneTouch\OneTouchMon.exe
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe"
"BearShare"="c:\program files\BearShare\BearShare.exe" /pause
"CanonSolutionMenu"=c:\program files\Canon\SolutionMenu\CNSLMAIN.exe /logon
"TrojanScanner"=c:\program files\Trojan Remover\Trjscan.exe /boot
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"PMBVolumeWatcher"=c:\program files\Sony\PMB\PMBVolumeWatcher.exe
"Motive SmartBridge"=c:\progra~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
"ZoneAlarm Installer"="c:\program files\CheckPoint\Install\Launcher.exe" "c:\program files\CheckPoint\Install\Install.exe" /r install /c "c:\program files\CheckPoint\Install\Install.xml" /l /w
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
"COMODO Internet Security"=c:\program files\COMODO\COMODO Internet Security\cistray.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ScanSoft\\PaperPort\\NAVBrowser.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [1/28/2013 11:52 PM 14776]
R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [1/16/2013 7:51 PM 18536]
R1 cmdGuard;COMODO Internet Security Driver;c:\windows\system32\drivers\cmdGuard.sys [1/16/2013 7:51 PM 586728]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [1/16/2013 7:51 PM 32824]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 8:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 1:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [8/11/2011 3:38 PM 116608]
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files\IObit\Advanced SystemCare 6\ASCService.exe [12/27/2012 6:23 PM 465216]
R3 ch7009;ch7009;c:\windows\system32\drivers\ch7009.sys [10/27/2012 11:32 AM 20224]
R3 ch7017;ch7017;c:\windows\system32\drivers\ch7017.sys [10/27/2012 11:32 AM 26368]
R3 fs454;fs454;c:\windows\system32\drivers\fs454.sys [10/27/2012 11:32 AM 15616]
R3 igdmini;igdmini;c:\windows\system32\drivers\igdmini.sys [10/27/2012 11:32 AM 256896]
R3 lvds;lvds;c:\windows\system32\drivers\lvds.sys [10/27/2012 11:32 AM 5632]
R3 ns2501;ns2501;c:\windows\system32\drivers\ns2501.sys [10/27/2012 11:32 AM 7424]
R3 ns387;ns387;c:\windows\system32\drivers\ns387.sys [10/27/2012 11:32 AM 5376]
R3 sii164;sii164;c:\windows\system32\drivers\sii164.sys [10/27/2012 11:32 AM 4992]
R3 th164;th164;c:\windows\system32\drivers\th164.sys [10/27/2012 11:32 AM 4736]
R3 ti410;ti410;c:\windows\system32\drivers\ti410.sys [10/27/2012 11:32 AM 4864]
S0 DwProt;DrWeb Protection;c:\windows\system32\drivers\dwprot.sys –> c:\windows\system32\drivers\dwprot.sys [?]
S3 cmdvirth;COMODO Virtual Service Manager;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe [1/24/2013 10:42 PM 127184]
S3 d3dUtil;d3dutil;c:\windows\system32\drivers\d3dutil.sys [10/27/2012 11:32 AM 2560]
S3 PCDSRVC{E9D79540-57D5953E-06020200}_0;PCDSRVC{E9D79540-57D5953E-06020200}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\Dell Support Center\pcdsrvc.pkms [9/3/2012 9:54 PM 22640]
S3 SysProtDrv.sys;SysProtDrv.sys;\??\c:\documents and settings\Owner\Desktop\SysProt\SysProt\SysProtDrv.sys –> c:\documents and settings\Owner\Desktop\SysProt\SysProt\SysProtDrv.sys [?]
S4 SVKP;SVKP;\??\c:\windows\system32\SVKP.sys –> c:\windows\system32\SVKP.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - 11801583
*NewlyCreated* - 91089738
*Deregistered* - 11801583
*Deregistered* - 91089738
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2013-02-02 c:\windows\Tasks\ASC6_PerformanceMonitor.job
- c:\program files\IObit\Advanced SystemCare 6\Monitor.exe [2012-12-28 02:47]
.
2013-02-14 c:\windows\Tasks\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9}.job
- c:\program files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-01-25 06:42]
.
2013-02-14 c:\windows\Tasks\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22}.job
- c:\program files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-01-25 06:42]
.
2013-02-14 c:\windows\Tasks\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59}.job
- c:\program files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-01-25 06:42]
.
2013-02-14 c:\windows\Tasks\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}.job
- c:\program files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-01-25 06:42]
.
2013-02-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-23 21:52]
.
2013-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-23 21:52]
.
2013-02-05 c:\windows\Tasks\SmartDefragUpdate.job
- c:\program files\IObit\Smart Defrag 2\AutoUpdate.exe [2012-12-18 19:06]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uStart Page = hxxp://www.dogpile.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: facebook.com\www
Trusted Zone: geekpolice.net\www
TCP: DhcpNameServer = 10.0.0.1
DPF: Microsoft XML Parser for Java
DPF: vzTCPConfig - hxxp://www2.verizon.net/help/dsl_settings/include/vzTCPConfig.CAB
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-07076720.sys
SafeBoot-91089738.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-02-13 22:04
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCDSRVC{E9D79540-57D5953E-06020200}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,38,89,37,d4,0f,f6,56,43,88,58,fb,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\System\VritualRoot\MACHINE\Software\CLASSES\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(820)
c:\windows\system32\guard32.dll
c:\windows\system32\mswsock.dll
c:\windows\System32\wshtcpip.dll
.
- - - - - - - > 'csrss.exe'(736)
c:\windows\system32\cmdcsr.dll
.
Completion time: 2013-02-13 22:16:11
ComboFix-quarantined-files.txt 2013-02-14 06:15
.
Pre-Run: 15,940,780,032 bytes free
Post-Run: 16,051,249,152 bytes free
.
- - End Of File - - 9D6D277B7B6FB2FB94C8D11BEF196630
——-
Many thanks for all that you are doing to help me,
Karen
Here is the Comb Fix Log:
ComboFix 13-02-13.02 - Owner 02/13/2013 21:35:22.15.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1614 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: COMODO Antivirus *Disabled/Updated* {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
AV: ZoneAlarm Antivirus *Disabled/Updated* {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: COMODO Firewall *Disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\NDP1.1sp1-KB2742597-X86.exe
c:\program files\WindowsXP-KB942288-v3-x86.exe
c:\windows\system32\SET18C.tmp
.
.
((((((((((((((((((((((((( Files Created from 2013-01-14 to 2013-02-14 )))))))))))))))))))))))))))))))
.
.
2013-02-14 05:12 . 2013-02-14 05:12 ——– dc—-w- C:\TDSSKiller_Quarantine
2013-02-09 00:23 . 2013-02-09 00:35 ——– d—–w- c:\documents and settings\Owner\Application Data\Comodo
2013-02-08 23:12 . 2013-02-08 23:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Comodo
2013-02-08 23:12 . 2013-02-08 23:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Comodo Downloader
2013-02-08 23:12 . 2013-02-08 23:12 ——– d—–w- c:\program files\COMODO
2013-02-08 23:04 . 2013-02-08 23:04 130846192 —-a-w- c:\program files\cav_installer.exe
2013-02-08 14:23 . 2012-12-15 00:49 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-02-08 14:23 . 2013-02-08 14:56 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-02-08 02:21 . 2013-02-08 02:27 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Avg2013
2013-02-07 01:40 . 2013-02-07 01:40 ——– d—–w- c:\documents and settings\Owner\Application Data\TuneUp Software
2013-02-07 01:11 . 2013-02-07 01:11 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\MFAData
2013-02-06 12:02 . 2013-02-06 20:50 36760 —-a-w- c:\windows\system32\drivers\fvstore.dat
2013-02-06 11:45 . 2013-02-06 11:45 ——– dc—-w- C:\VTRoot
2013-02-06 11:15 . 2013-02-06 11:15 ——– d-s—w- c:\documents and settings\All Users\Application Data\Shared Space
2013-02-06 07:36 . 2013-02-06 07:36 ——– dc—-w- C:\VritualRoot
2013-02-03 22:08 . 2013-02-03 22:09 ——– d—–w- c:\program files\QuickTime
2013-02-03 22:08 . 2013-02-03 22:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2013-02-03 22:07 . 2013-02-03 22:07 ——– d—–w- c:\program files\Common Files\Apple
2013-02-03 22:06 . 2013-02-03 22:06 ——– d—–w- c:\program files\Apple Software Update
2013-02-03 07:37 . 2013-02-03 22:09 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2013-02-03 07:37 . 2013-02-03 22:09 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2013-02-03 07:37 . 2013-02-03 22:09 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2013-02-03 07:37 . 2013-02-03 22:09 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2013-02-03 07:37 . 2013-02-03 22:09 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2013-02-03 07:37 . 2013-02-03 22:09 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2013-02-03 07:37 . 2013-02-03 22:09 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2013-01-29 07:52 . 2012-05-09 02:35 29528 —-a-w- c:\windows\system32\SmartDefragBootTime.exe
2013-01-29 07:52 . 2010-11-27 02:02 14776 —-a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2013-01-29 07:24 . 2013-01-29 07:24 ——– d—–w- c:\documents and settings\All Users\Application Data\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
2013-01-27 20:54 . 2013-01-27 20:54 4189792 —-a-w- c:\program files\ccsetup327.exe
2013-01-25 06:43 . 2013-01-25 06:43 35488 —-a-w- c:\windows\system32\cmdcsr.dll
2013-01-25 06:43 . 2013-01-25 06:43 354752 —-a-w- c:\windows\system32\guard32.dll
2013-01-25 06:42 . 2013-01-25 06:42 40656 —-a-w- c:\windows\system32\cmdkbd32.dll
2013-01-25 06:42 . 2013-01-25 06:42 263888 —-a-w- c:\windows\system32\cmdvrt32.dll
2013-01-17 03:51 . 2013-01-17 03:51 98752 —-a-w- c:\windows\system32\drivers\inspect.sys
2013-01-17 03:51 . 2013-01-17 03:51 586728 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2013-01-17 03:51 . 2013-01-17 03:51 32824 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2013-01-17 03:51 . 2013-01-17 03:51 18536 —-a-w- c:\windows\system32\drivers\cmderd.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-03 22:03 . 2011-09-14 18:56 40437664 —-a-w- c:\program files\QuickTimeInstaller.exe
2013-01-29 07:21 . 2012-12-28 02:22 21494224 —-a-w- c:\program files\asc-setup.exe
2013-01-26 03:55 . 2003-07-16 20:40 552448 ——w- c:\windows\system32\oleaut32.dll
2013-01-16 02:49 . 2012-12-28 03:56 23360 —-a-w- c:\windows\system32\RegistryDefragBootTime.exe
2013-01-12 21:50 . 2013-01-12 21:50 4178040 —-a-w- c:\program files\ccsetup326.exe
2013-01-12 20:32 . 2012-11-24 22:41 697864 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-12 20:32 . 2011-07-22 08:54 74248 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-10 00:40 . 2012-11-18 00:43 24265736 —-a-w- c:\program files\dotnetfx.exe
2013-01-07 01:16 . 2003-07-16 20:39 2193024 ——w- c:\windows\system32\ntoskrnl.exe
2013-01-07 00:36 . 2002-08-29 01:04 2069760 ——w- c:\windows\system32\ntkrnlpa.exe
2013-01-04 01:20 . 2003-07-16 20:51 1867264 —-a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49 . 2003-07-16 20:34 148992 —-a-w- c:\windows\system32\mpg2splt.ax
2013-01-02 06:49 . 2003-05-13 17:28 1292288 —-a-w- c:\windows\system32\quartz.dll
2012-12-26 20:16 . 2004-02-07 01:05 916480 —-a-w- c:\windows\system32\wininet.dll
2012-12-26 20:16 . 2010-10-14 16:46 43520 ——w- c:\windows\system32\licmgr10.dll
2012-12-26 20:16 . 2010-10-14 16:46 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-12-24 06:40 . 2004-08-04 05:59 385024 ——w- c:\windows\system32\html.iec
2012-12-18 19:00 . 2012-11-03 00:40 4976384 —-a-w- c:\program files\defragsetup.exe
2012-12-16 12:23 . 2003-07-16 20:24 290560 —-a-w- c:\windows\system32\atmfd.dll
2012-11-18 00:57 . 2012-11-18 00:57 2959376 —-a-w- c:\program files\dotnetfx35setup.exe
2012-10-28 00:17 . 2012-10-28 00:17 38984 —-a-w- c:\program files\DellPCDiagnostics.exe
2012-10-27 22:47 . 2012-10-27 22:47 347424 —-a-w- c:\program files\MicrosoftFixit.AudioPlayback.Run.exe
2012-10-27 19:10 . 2012-10-27 19:10 10669896 —-a-w- c:\program files\mbam-setup.exe
2012-02-24 00:50 . 2012-02-24 00:50 8669472 —-a-w- c:\program files\Windows7UpgradeAdvisorSetup.exe
2012-02-16 02:52 . 2012-02-16 02:52 14809712 —-a-w- c:\program files\SUPERAntiSpyware.exe
2011-07-25 03:12 . 2010-07-24 19:14 16409960 —-a-w- c:\program files\spybotsd162.exe
2011-07-23 09:00 . 2011-07-23 09:00 908064 —-a-w- c:\program files\jre-6u26-windows-i586-iftw.exe
2011-07-20 05:55 . 2011-07-20 05:55 684297 —-a-w- c:\program files\unhide.exe
2010-12-26 06:19 . 2010-12-26 06:19 12965392 —-a-w- c:\program files\RealPlayer10-5GOLD.exe
2010-12-26 05:03 . 2010-12-26 05:03 12252656 —-a-w- c:\program files\RealPlayer11GOLD.exe
2010-12-25 07:47 . 2010-12-25 07:47 602464 —-a-w- c:\program files\RealPlayer.exe
2010-12-25 03:18 . 2010-12-24 06:45 25740256 —-a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2010-09-12 01:42 . 2010-09-12 01:42 6776168 —-a-w- c:\program files\WindowsUpdateAgent30-x86.exe
2010-08-26 19:15 . 2008-06-30 18:11 1625600 -c–a-w- c:\program files\MBSASetup-x86-EN.msi
2010-05-22 22:28 . 2010-05-22 22:28 6108728 —-a-w- c:\program files\picasaweb-current-setup.exe
2010-04-19 18:37 . 2010-04-19 18:37 2270216 —-a-w- c:\program files\advisor.exe
2010-02-05 19:35 . 2008-06-09 02:21 1114576 —-a-w- c:\program files\revosetup.exe
2010-01-07 20:04 . 2009-12-24 18:13 9476032 —-a-w- c:\program files\RevoUninProSetup.exe
2009-10-25 20:03 . 2009-10-20 01:14 747520 -c–a-w- c:\program files\MicrosoftFixit50198.msi
2009-10-20 20:54 . 2009-10-20 20:54 16883056 —-a-w- c:\program files\IE8-WindowsXP-x86-ENU.exe
2009-09-27 07:35 . 2008-09-19 06:15 1146184 —-a-w- c:\program files\wlsetup-web.exe
2009-07-25 18:24 . 2009-07-25 18:23 2052104 —-a-w- c:\program files\advisor belarc.exe
2009-06-04 21:16 . 2009-06-04 21:15 14243328 -c–a-w- c:\program files\DM510.32.4071221.EN.msi
2009-04-01 03:21 . 2009-03-10 16:45 224 -c–a-w- c:\program files\fix.bat
2009-01-02 22:57 . 2009-01-02 22:57 1945096 -c–a-w- c:\program files\BELARC advisor.exe
2008-06-23 17:11 . 2008-06-23 17:11 2400784 —-a-w- c:\program files\WLinstaller.exe
2008-01-14 20:32 . 2008-04-25 07:31 6957056 -c–a-w- c:\program files\PhotoLibrary.msp
2006-12-29 23:58 . 2006-12-29 23:58 15505200 -c–a-w- c:\program files\IE7-WindowsXP-x86-enu.exe
2006-12-18 05:44 . 2006-12-18 05:44 20036629 -c–a-w- c:\program files\eppwin300aus.exe
2006-11-07 00:49 . 2006-11-07 00:49 64512 -c–a-w- c:\program files\Compatibility_Check.exe
2006-10-27 16:50 . 2006-10-27 16:51 317248 -c–a-w- c:\program files\WINDOWS OCT06.exe
2005-12-17 01:24 . 2005-12-15 00:35 561 -c–a-w- c:\program files\os449133.bin
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
desktop(2).ini [2004-5-28 84]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
desktop(2).ini [2004-5-28 84]
.
c:\documents and settings\JEFF\Start Menu\Programs\Startup\
desktop(2).ini [2004-5-28 84]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPA
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Installer
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2012-10-25 11:12 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"PPWebCap"=c:\progra~1\ScanSoft\PAPERP~1\PPWebCap.exe
"SUPERAntiSpyware"=c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
"Advanced SystemCare 6"="c:\program files\IObit\Advanced SystemCare 6\ASCTray.exe" /AutoStart
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"OneTouch Monitor"=c:\program files\Visioneer OneTouch\OneTouchMon.exe
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe"
"BearShare"="c:\program files\BearShare\BearShare.exe" /pause
"CanonSolutionMenu"=c:\program files\Canon\SolutionMenu\CNSLMAIN.exe /logon
"TrojanScanner"=c:\program files\Trojan Remover\Trjscan.exe /boot
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"PMBVolumeWatcher"=c:\program files\Sony\PMB\PMBVolumeWatcher.exe
"Motive SmartBridge"=c:\progra~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
"ZoneAlarm Installer"="c:\program files\CheckPoint\Install\Launcher.exe" "c:\program files\CheckPoint\Install\Install.exe" /r install /c "c:\program files\CheckPoint\Install\Install.xml" /l /w
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
"COMODO Internet Security"=c:\program files\COMODO\COMODO Internet Security\cistray.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ScanSoft\\PaperPort\\NAVBrowser.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [1/28/2013 11:52 PM 14776]
R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [1/16/2013 7:51 PM 18536]
R1 cmdGuard;COMODO Internet Security Driver;c:\windows\system32\drivers\cmdGuard.sys [1/16/2013 7:51 PM 586728]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [1/16/2013 7:51 PM 32824]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 8:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 1:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [8/11/2011 3:38 PM 116608]
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\program files\IObit\Advanced SystemCare 6\ASCService.exe [12/27/2012 6:23 PM 465216]
R3 ch7009;ch7009;c:\windows\system32\drivers\ch7009.sys [10/27/2012 11:32 AM 20224]
R3 ch7017;ch7017;c:\windows\system32\drivers\ch7017.sys [10/27/2012 11:32 AM 26368]
R3 fs454;fs454;c:\windows\system32\drivers\fs454.sys [10/27/2012 11:32 AM 15616]
R3 igdmini;igdmini;c:\windows\system32\drivers\igdmini.sys [10/27/2012 11:32 AM 256896]
R3 lvds;lvds;c:\windows\system32\drivers\lvds.sys [10/27/2012 11:32 AM 5632]
R3 ns2501;ns2501;c:\windows\system32\drivers\ns2501.sys [10/27/2012 11:32 AM 7424]
R3 ns387;ns387;c:\windows\system32\drivers\ns387.sys [10/27/2012 11:32 AM 5376]
R3 sii164;sii164;c:\windows\system32\drivers\sii164.sys [10/27/2012 11:32 AM 4992]
R3 th164;th164;c:\windows\system32\drivers\th164.sys [10/27/2012 11:32 AM 4736]
R3 ti410;ti410;c:\windows\system32\drivers\ti410.sys [10/27/2012 11:32 AM 4864]
S0 DwProt;DrWeb Protection;c:\windows\system32\drivers\dwprot.sys –> c:\windows\system32\drivers\dwprot.sys [?]
S3 cmdvirth;COMODO Virtual Service Manager;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe [1/24/2013 10:42 PM 127184]
S3 d3dUtil;d3dutil;c:\windows\system32\drivers\d3dutil.sys [10/27/2012 11:32 AM 2560]
S3 PCDSRVC{E9D79540-57D5953E-06020200}_0;PCDSRVC{E9D79540-57D5953E-06020200}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\Dell Support Center\pcdsrvc.pkms [9/3/2012 9:54 PM 22640]
S3 SysProtDrv.sys;SysProtDrv.sys;\??\c:\documents and settings\Owner\Desktop\SysProt\SysProt\SysProtDrv.sys –> c:\documents and settings\Owner\Desktop\SysProt\SysProt\SysProtDrv.sys [?]
S4 SVKP;SVKP;\??\c:\windows\system32\SVKP.sys –> c:\windows\system32\SVKP.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - 11801583
*NewlyCreated* - 91089738
*Deregistered* - 11801583
*Deregistered* - 91089738
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2013-02-02 c:\windows\Tasks\ASC6_PerformanceMonitor.job
- c:\program files\IObit\Advanced SystemCare 6\Monitor.exe [2012-12-28 02:47]
.
2013-02-14 c:\windows\Tasks\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9}.job
- c:\program files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-01-25 06:42]
.
2013-02-14 c:\windows\Tasks\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22}.job
- c:\program files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-01-25 06:42]
.
2013-02-14 c:\windows\Tasks\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59}.job
- c:\program files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-01-25 06:42]
.
2013-02-14 c:\windows\Tasks\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}.job
- c:\program files\COMODO\COMODO Internet Security\cfpconfg.exe [2013-01-25 06:42]
.
2013-02-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-23 21:52]
.
2013-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-23 21:52]
.
2013-02-05 c:\windows\Tasks\SmartDefragUpdate.job
- c:\program files\IObit\Smart Defrag 2\AutoUpdate.exe [2012-12-18 19:06]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uStart Page = hxxp://www.dogpile.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: facebook.com\www
Trusted Zone: geekpolice.net\www
TCP: DhcpNameServer = 10.0.0.1
DPF: Microsoft XML Parser for Java
DPF: vzTCPConfig - hxxp://www2.verizon.net/help/dsl_settings/include/vzTCPConfig.CAB
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-07076720.sys
SafeBoot-91089738.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-02-13 22:04
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCDSRVC{E9D79540-57D5953E-06020200}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,38,89,37,d4,0f,f6,56,43,88,58,fb,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\System\VritualRoot\MACHINE\Software\CLASSES\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(820)
c:\windows\system32\guard32.dll
c:\windows\system32\mswsock.dll
c:\windows\System32\wshtcpip.dll
.
- - - - - - - > 'csrss.exe'(736)
c:\windows\system32\cmdcsr.dll
.
Completion time: 2013-02-13 22:16:11
ComboFix-quarantined-files.txt 2013-02-14 06:15
.
Pre-Run: 15,940,780,032 bytes free
Post-Run: 16,051,249,152 bytes free
.
- - End Of File - - 9D6D277B7B6FB2FB94C8D11BEF196630
——-
Many thanks for all that you are doing to help me,
Karen
MrCharlie
Did you delete this one using TDSSKiller??
Download aswMBR to your desktop.
http://public.avast.com/~gmerek/aswMBR.exe
Double click the aswMBR.exe to run it.
If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
Click the "Scan" button to start scan.
On completion of the scan click "Save log", save it to your desktop and post in your next reply.
NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.
Please zip it up and attach it to your next post.
MrC
11:05:01.0609 3764 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
11:05:01.0609 3764 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
Download aswMBR to your desktop.
http://public.avast.com/~gmerek/aswMBR.exe
Double click the aswMBR.exe to run it.
If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
Click the "Scan" button to start scan.
On completion of the scan click "Save log", save it to your desktop and post in your next reply.
NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.
Please zip it up and attach it to your next post.
MrC
karenoregon
Hi Mr. Charlie:
Yes, I did delete the items as you instructed. Why are we not deleteing all the other items that scan found? I am sorry, but I do not know how to make Zip Folders for you. I do apologize. Tell me how to do it and I will do it in the future.
Here is the AswMBR.exe results:
aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2013-02-14 11:49:44
—————————–
11:49:44.078 OS Version: Windows 5.1.2600 Service Pack 3
11:49:44.078 Number of processors: 1 586 0x209
11:49:44.078 ComputerName: KURTCOMPUTER UserName: Owner
11:49:44.703 Initialize success
12:00:26.218 AVAST engine defs: 13021400
12:04:11.140 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
12:04:11.140 Disk 0 Vendor: WDC_WD400EB-75CPF0 06.04G06 Size: 38166MB BusType: 3
12:04:11.171 Disk 0 MBR read successfully
12:04:11.171 Disk 0 MBR scan
12:04:11.250 Disk 0 Windows XP default MBR code
12:04:11.250 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 38154 MB offset 63
12:04:11.265 Disk 0 scanning sectors +78140160
12:04:11.359 Disk 0 scanning C:\WINDOWS\system32\drivers
12:04:59.531 Service scanning
12:05:35.953 Modules scanning
12:05:46.921 Disk 0 trace - called modules:
12:05:46.968 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll intelide.sys PCIIDEX.SYS
12:05:46.984 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a57eab8]
12:05:46.984 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a57ab00]
12:05:47.375 AVAST engine scan C:\WINDOWS
12:06:13.062 AVAST engine scan C:\WINDOWS\system32
12:15:56.671 AVAST engine scan C:\WINDOWS\system32\drivers
12:16:58.671 AVAST engine scan C:\Documents and Settings\Owner
12:29:25.812 AVAST engine scan C:\Documents and Settings\All Users
12:31:38.828 Scan finished successfully
12:36:42.203 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat"
12:36:42.203 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt"
——————–
Thank you very much,
Karen
MrCharlie
Because they're good files.Why are we not deleteing all the other items that scan found?
———————————-
For zip files:
Right click on a file, folder, or selection of files and click on the Send To menu option and then choose Compressed (zipped) Folder. The image below shows the location of these menu items:
[external image: Posted Image]
———————————
Please run this scan next:
Please create a new system restore point before running Malwarebytes Anti-Rootkit if you can.
MBAR tutorial
Download Malwarebytes Anti-Rootkit from HERE
- Unzip the contents to a folder in a convenient location.
- Open the folder where the contents were unzipped and run mbar.exe
- Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
- Click on the Cleanup button to remove any threats and reboot if prompted to do so.
- Wait while the system shuts down and the cleanup process is performed.
- Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
- When done, please post the two logs produced they will be in the MBAR folder….. mbar-log.txt and system-log.txt
~~~~~~~~~~~~~~~~~~~~~~~
Note:
If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:
Internet access
Windows Update
Windows Firewall
If there are additional problems with your system, such as any of those listed above or other system issues, then run the fixdamage tool included with Malwarebytes Anti-Rootkit and reboot.
Verify that your system is now functioning normally.
MrC
karenoregon
Hi Mr. Charlie:
Whew! What an experience. Mbar found two threats and I asked them to be cleaned. The system rebooted and I tried to access the internet to contact you and could not do so. I had to contact my Internet Provider, Century Link. A technician from CL got my internet access going again. He had me do a system restore to February 14th. I had called the Restore Point Mr. Charlie. I am up and running now, but hope that going to that restore point has not ruined the cleaning that mbar did. I will post the logs:
Malwarebytes Anti-Rootkit BETA 1.01.0.1020
www.malwarebytes.org
Database version: v2013.02.15.04
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Owner :: KURTCOMPUTER [administrator]
2/14/2013 11:15:14 PM
mbar-log-2013-02-14 (23-15-14).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 26418
Time elapsed: 27 minute(s), 53 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
c:\Program Files\revosetup.exe (Trojan.Backdoor.MRX) -> Delete on reboot.
c:\Documents and Settings\Owner\Local Settings\Temp\~nsu.tmp\Au_.exe (Trojan.Backdoor.MRX) -> Delete on reboot.
(end)
—————
—————————————
Malwarebytes Anti-Rootkit BETA 1.01.0.1020
© Malwarebytes Corporation 2011-2012
OS version: 5.1.2600 Windows XP Service Pack 3 x86
Account is Administrative
Internet Explorer version: 8.0.6001.18702
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.392000 GHz
Memory total: 2145386496, free: 1471619072
—————————————
Malwarebytes Anti-Rootkit BETA 1.01.0.1020
© Malwarebytes Corporation 2011-2012
OS version: 5.1.2600 Windows XP Service Pack 3 x86
Account is Administrative
Internet Explorer version: 8.0.6001.18702
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.392000 GHz
Memory total: 2145386496, free: 1473511424
———— Kernel report ————
02/14/2013 22:36:34
———— Loaded modules ———–
\WINDOWS\system32\ntoskrnl.exe
\WINDOWS\system32\hal.dll
\WINDOWS\system32\KDCOM.DLL
\WINDOWS\system32\BOOTVID.dll
ACPI.sys
\WINDOWS\System32\DRIVERS\WMILIB.SYS
pci.sys
isapnp.sys
PCIIde.sys
\WINDOWS\System32\Drivers\PCIIDEX.SYS
intelide.sys
MountMgr.sys
ftdisk.sys
PartMgr.sys
VolSnap.sys
atapi.sys
disk.sys
\WINDOWS\System32\DRIVERS\CLASSPNP.SYS
fltmgr.sys
sr.sys
PxHelp20.sys
KSecDD.sys
Ntfs.sys
inspect.sys
\WINDOWS\System32\DRIVERS\NDIS.SYS
\WINDOWS\System32\DRIVERS\TDI.SYS
SmartDefragDriver.sys
Mup.sys
\SystemRoot\System32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\igdmini.sys
\SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
\SystemRoot\System32\DRIVERS\usbuhci.sys
\SystemRoot\System32\DRIVERS\USBPORT.SYS
\SystemRoot\System32\DRIVERS\usbehci.sys
\SystemRoot\System32\DRIVERS\BCMSM.sys
\SystemRoot\System32\DRIVERS\ks.sys
\SystemRoot\System32\Drivers\Modem.SYS
\SystemRoot\System32\DRIVERS\bcm4sbxp.sys
\SystemRoot\System32\DRIVERS\fdc.sys
\SystemRoot\System32\DRIVERS\i8042prt.sys
\SystemRoot\System32\DRIVERS\kbdclass.sys
\SystemRoot\System32\DRIVERS\mouclass.sys
\SystemRoot\System32\DRIVERS\serial.sys
\SystemRoot\System32\DRIVERS\serenum.sys
\SystemRoot\System32\DRIVERS\parport.sys
\SystemRoot\System32\DRIVERS\imapi.sys
\SystemRoot\system32\drivers\Afc.sys
\SystemRoot\System32\DRIVERS\cdrom.sys
\SystemRoot\System32\DRIVERS\redbook.sys
\SystemRoot\system32\drivers\smwdm.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\aeaudio.sys
\SystemRoot\System32\DRIVERS\audstub.sys
\SystemRoot\System32\DRIVERS\rasl2tp.sys
\SystemRoot\System32\DRIVERS\ndistapi.sys
\SystemRoot\System32\DRIVERS\ndiswan.sys
\SystemRoot\System32\DRIVERS\raspppoe.sys
\SystemRoot\System32\DRIVERS\raspptp.sys
\SystemRoot\System32\DRIVERS\psched.sys
\SystemRoot\System32\DRIVERS\msgpc.sys
\SystemRoot\System32\DRIVERS\ptilink.sys
\SystemRoot\System32\DRIVERS\raspti.sys
\SystemRoot\System32\DRIVERS\termdd.sys
\SystemRoot\System32\DRIVERS\swenum.sys
\SystemRoot\System32\DRIVERS\update.sys
\SystemRoot\System32\DRIVERS\mssmbios.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\DRIVERS\ch7009.sys
\SystemRoot\system32\DRIVERS\ch7017.sys
\SystemRoot\system32\DRIVERS\fs454.sys
\SystemRoot\system32\DRIVERS\lvds.sys
\SystemRoot\system32\DRIVERS\ns2501.sys
\SystemRoot\system32\DRIVERS\ns387.sys
\SystemRoot\system32\DRIVERS\sii164.sys
\SystemRoot\system32\DRIVERS\ti410.sys
\SystemRoot\system32\DRIVERS\th164.sys
\SystemRoot\System32\DRIVERS\usbhub.sys
\SystemRoot\System32\DRIVERS\USBD.SYS
\SystemRoot\System32\DRIVERS\flpydisk.sys
\SystemRoot\System32\DRIVERS\cmderd.sys
\SystemRoot\System32\DRIVERS\cmdguard.sys
\SystemRoot\System32\Drivers\Fs_Rec.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\Drivers\mnmdd.SYS
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\System32\DRIVERS\rasacd.sys
\SystemRoot\system32\DRIVERS\ipsec.sys
\SystemRoot\System32\DRIVERS\tcpip.sys
\SystemRoot\System32\DRIVERS\cmdhlp.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\System32\drivers\ws2ifsl.sys
\SystemRoot\System32\drivers\afd.sys
\SystemRoot\System32\DRIVERS\netbios.sys
\??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
\??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
\SystemRoot\System32\DRIVERS\rdbss.sys
\SystemRoot\SYSTEM32\DRIVERS\OMCI.SYS
\SystemRoot\system32\ckldrv.sys
\SystemRoot\System32\DRIVERS\ipnat.sys
\SystemRoot\System32\DRIVERS\wanarp.sys
\SystemRoot\System32\DRIVERS\mrxsmb.sys
\SystemRoot\System32\Drivers\Fips.SYS
\SystemRoot\System32\Drivers\BANTExt.sys
\SystemRoot\System32\Drivers\Cdfs.SYS
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\watchdog.sys
\SystemRoot\System32\drivers\dxg.sys
\SystemRoot\System32\drivers\dxgthk.sys
\SystemRoot\System32\igddis.dll
\SystemRoot\System32\igd3dalm.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\DRIVERS\fssfltr_tdi.sys
\SystemRoot\system32\DRIVERS\nwlnkipx.sys
\SystemRoot\system32\DRIVERS\nwlnknb.sys
\SystemRoot\system32\DRIVERS\nwlnkspx.sys
\SystemRoot\System32\Drivers\ParVdm.SYS
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\System32\Drivers\Fastfat.SYS
\??\C:\WINDOWS\system32\drivers\tmcomm.sys
\SystemRoot\system32\drivers\wdmaud.sys
\SystemRoot\system32\drivers\sysaudio.sys
\SystemRoot\System32\Drivers\HTTP.sys
\SystemRoot\system32\drivers\kmixer.sys
\??\C:\WINDOWS\system32\drivers\mbamchameleon.sys
\??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys
\WINDOWS\system32\ntdll.dll
———– End ———–
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xffffffff8a57eab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP0T0L0-3\
Lower Device Object: 0xffffffff8a57ab00
Lower Device Driver Name: \Driver\atapi\
Driver name found: atapi
Initialization returned 0x0
Load Function returned 0x0
Downloaded database version: v2013.02.15.04
Initializing…
Done!
<<<2>>>
Device number: 0, partition: 1
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffffff8a57eab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff8a616900, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff8a57eab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff8a57ab00, DeviceName: \Device\Ide\IdeDeviceP0T0L0-3\, DriverName: \Driver\atapi\
———— End ———-
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0xffffffffe3d47430, 0xffffffff8a57eab8, 0xffffffff893e5040
Lower DeviceData: 0xffffffffe3ce0420, 0xffffffff8a57ab00, 0xffffffff88a03580
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning directory: C:\WINDOWS\system32\drivers…
<<<2>>>
Device number: 0, partition: 1
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Read File: File "C:\WINDOWS\system32\drivers\a302.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\a303.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\a304.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\a305.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\a306.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\a307.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\a308.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\a309.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\a310.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\a311.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\a313.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\a314.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\acpi(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\acpiec.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\aeaudio(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\aec(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\mnmdd(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\modem(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\MODEMCSA(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\mouclass(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\mrxdav(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\msfs(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\riodrv.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\rootmdm.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\s3gnbm.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\scsiport(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\secdrv(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\serial(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\sfloppy(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\SilvrLnk.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\slnt7554.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\slntamr.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\slnthal.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\fastfat(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\fdc(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\fips(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\flpydisk(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\fltmgr(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\omci(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\oprghdlr.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\parport(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\parvdm(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\pci(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\usbd(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\usbehci(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\usbhub(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ati2mtag.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\atmuni.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\cbidf2k.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\fsvga.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\hsfdpsp2.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\mdmxsdk.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\msgpc(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\mtxparhm.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\netwlan5.img" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\nwlnkspx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\rio8drv.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\slwdmsup.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\tsbvcap.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\VetFDDNT(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\wadv08nt.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\cdaudio(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\cdfs(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\cdrom(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\cinemst2.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\cpqdap01.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\cxthsfs2.cty" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\VetMonNT(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\vga(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\videoprt(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\wa301a.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\wa301b.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\wadv07nt.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\smclib.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\smwdm(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\splitter(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\sr(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\srv(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\swenum(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\i8042prt(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ialmkchw(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ialmnt5(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ialmsbw(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\imapi(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\intelide(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\intelppm(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ip6fw(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ipfltdrv(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ipinip(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\asyncmac(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\atapi(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ati1btxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ati1mdxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ati1pdxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ati1raxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ati1rvxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ati1snxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ati1ttxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ati1tuxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ati1xbxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ati1xsxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ati2mtaa.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\audstub(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\BCMDM.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\BCMSM(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\beep(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\bvrp_pci.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\raspptp(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\raspti(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\rawwan.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\rdpcdd(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\recagent.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\redbook(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ndistapi(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ndisuio(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ndiswan(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ndproxy(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\netbios(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\netbt(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ipsec(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\irenum(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\isapnp(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\kbdclass(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\kmixer(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ks(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\mcd.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\dmboot(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\dmio(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\dmload(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\dmusic(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\drmk(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\drmkaud(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\dxapi(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\dxg(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\dxg(3)(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\dxgthk(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\usbport(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\usbscan(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\USBSTOR(2).SYS" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\usbuhci(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\vch.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\vdmindvd.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\Vet-Filt(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\Vet-Rec(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\fs_rec(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ftdisk(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\gm.dls" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\hsfbs2s2.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\hsfcxts2.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\portcls(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\processr(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\psched(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ptilink(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\rasacd(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\rasl2tp(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\raspppoe(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\wadv09nt.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\wadv11nt.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\wanarp(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\watv06nt.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\watv10nt.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\wdmaud(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\wmilib(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\wpdusb(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ws2ifsl.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\atinbtxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\atinmdxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\atinpdxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\atinraxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\atinrvxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\atinsnxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\atinttxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\atintuxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\atinxbxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\atinxsxx.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ativmc20.cod" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\atmarpc(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\atmepvc.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\nikedrv.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\npfs(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\ntmtlfax.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\null(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\nv4_mini.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\nwlnkflt(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\nwlnkfwd(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\nwlnknb.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\mskssrv(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\mspclock(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\mspqm(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\mssmbios(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\mtlmnt5.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\mtlstrm.sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\swmidi(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\sysaudio(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\tdi(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\termdd(2).sys" is compressed (flags = 1)
Read File: File "C:\WINDOWS\system32\drivers\tosdvd.sys" is compressed (flags = 1)
Done!
Drive 0
Scanning MBR on drive 0…
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: B38BB38B
Partition information:
Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 63 Numsec = 78140097
Partition file system is NTFS
Partition is bootable
Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Disk Size: 40020664320 bytes
Sector size: 512 bytes
Scanning physical sectors of unpartitioned space on drive 0 (1-62-78145360-78165360)…
Done!
Performing system, memory and registry scan…
Read File: File "c:\Documents and Settings\All Users\Application Data\CanonIJEGV\egvinfo.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\All Users\Application Data\Lavasoft\License\adaware2007.dat" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\All Users\Application Data\Lavasoft\MiniMessage\1" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\All Users\Application Data\Lavasoft\MiniMessage\2" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\hhcolreg.dat" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\All Users\Application Data\MSN6\au.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Default User\Application Data\desktop(2).ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Default User\Application Data\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Guest\Application Data\desktop(2).ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Guest\Application Data\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\JEFF\Application Data\desktop(2).ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\JEFF\Application Data\Microsoft\Protect\CREDHIST" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\JEFF\Application Data\Windows Desktop Search\WindowsDesktopShortcuts.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Owner\Application Data\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Owner\Application Data\Canon\CNQ2413\SCGR.MRK" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Owner\Application Data\MSN6\au.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Owner\Application Data\MSN6\MSNCoreFiles.NEW.{9D6EAA4F-27B2-4407-AC72-4BBD2FCB6ED1}\market.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Owner\Application Data\MSN6\MSNCoreFiles.NEW.{9D6EAA4F-27B2-4407-AC72-4BBD2FCB6ED1}\dwprivacy.hta" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Owner\Application Data\Real\RealMediaSDK\4b6ac100.txt" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Owner\Application Data\Windows Desktop Search\WindowsDesktopShortcuts.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Owner\Application Data\IObit\InternetBooster\LastSetBandWidth.ib" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Owner\Application Data\Microsoft\Protect\CREDHIST" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\config\systemprofile\Application Data\desktop.ini" is compressed (flags = 1)
Infected: c:\Program Files\revosetup.exe –> [Trojan.Backdoor.MRX]
Read File: File "c:\Program Files\fix.bat" is compressed (flags = 1)
Read File: File "c:\Program Files\Outlook Express\msoe.txt" is compressed (flags = 1)
Read File: File "c:\boot.ini" is compressed (flags = 1)
Read File: File "c:\RECYCLER\S-1-5-21-776561741-448539723-725345543-1003\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Default User\Start Menu\Programs\Startup\desktop(2).ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Default User\Start Menu\Programs\Startup\desktop.ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\$winnt$(2).inf" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\.dat" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\.ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\BurnData.bin" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\d3d8caps.dat" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\dsound.vxd" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\perffilt.h" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\perfwci.h" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\View Channels.scf" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\prodspec.ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\pcl.sep" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\perfci.h" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\BDEMERGE.INI" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\pscript.sep" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\l_except.nls" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\desktop.ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\zonedoff.reg" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\zonedon.reg" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\cmos.ram" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\config\systemprofile\WGAErrLog.txt" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\config\systemprofile\Application Data\desktop.ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\drivers\etc\networks" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\oobe\migip.dun" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\oobe\migrate.isp" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\oobe\msobe.isp" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\oobe\obeip.dun" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\oobe\oobeinfo.ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\oobe\reg.isp" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\wbem\WindowsSearchEngine_Uninst.mof" is compressed (flags = 1)
Infected: c:\Documents and Settings\Owner\Local Settings\Temp\~nsu.tmp\Au_.exe –> [Trojan.Backdoor.MRX]
Read File: File "c:\Documents and Settings\Guest\ntuser(2).ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Guest\ntuser.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\JEFF\ntuser.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\LocalService\ntuser.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\NetworkService\ntuser.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Owner\maxdesk.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Owner\WGAErrLog.txt" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Owner\WGANotify.settings" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\config\systemprofile\WGAErrLog.txt" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Default User\Local Settings\desktop(2).ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Default User\Local Settings\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Guest\Local Settings\desktop(2).ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Guest\Local Settings\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\JEFF\Local Settings\desktop(2).ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\JEFF\Local Settings\desktop.ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\config\systemprofile\Local Settings\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Internet Explorer\brndlog.txt" is compressed (flags = 1)
Read File: File "c:\WINDOWS\explorer.scf" is compressed (flags = 1)
Read File: File "c:\WINDOWS\fls.002" is compressed (flags = 1)
Read File: File "c:\WINDOWS\vb(2).ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\vb.ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\vbaddin(2).ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\vbaddin.ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\savers(2).ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\savers.ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\cdplayer(2).ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\control(2).ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\control.ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\jngnign nkinhirimokmjilkjgol 2005.jgn" is compressed (flags = 1)
Read File: File "c:\WINDOWS\SYSTEM$$.VIZ" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system.ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\System.ipe" is compressed (flags = 1)
Read File: File "c:\WINDOWS\SYSTEM.UNV" is compressed (flags = 1)
Read File: File "c:\WINDOWS\top-windows-downloads.url" is compressed (flags = 1)
Read File: File "c:\WINDOWS\logfile.txt" is compressed (flags = 1)
Read File: File "c:\WINDOWS\IC32.INI" is compressed (flags = 1)
Read File: File "c:\WINDOWS\xm.url" is compressed (flags = 1)
Read File: File "c:\WINDOWS\Zone.Identifier" is compressed (flags = 1)
Read File: File "c:\WINDOWS\desktop.ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\Fonts\desktop.ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\Help\ciadmin.htm" is compressed (flags = 1)
Read File: File "c:\WINDOWS\Help\conf.cnt" is compressed (flags = 1)
Read File: File "c:\WINDOWS\Help\connect.cnt" is compressed (flags = 1)
Read File: File "c:\WINDOWS\Help\mshearts.cnt" is compressed (flags = 1)
Read File: File "c:\WINDOWS\Help\msnauth.cnt" is compressed (flags = 1)
Read File: File "c:\WINDOWS\Help\nocontnt.cnt" is compressed (flags = 1)
Read File: File "c:\WINDOWS\Help\ratings.cnt" is compressed (flags = 1)
Read File: File "c:\WINDOWS\Help\update.cnt" is compressed (flags = 1)
Read File: File "c:\WINDOWS\Help\windows.cnt" is compressed (flags = 1)
Read File: File "c:\WINDOWS\Help\winhlp32.cnt" is compressed (flags = 1)
Read File: File "c:\WINDOWS\Installer\{75D46594-4DE1-4A90-AE74-38637D301EF2}\_473B6F95_B37B_444E_BAE6_8F5B0AD9EA62" is compressed (flags = 1)
Read File: File "c:\WINDOWS\Tasks\desktop.ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\Web\bullet.gif" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Default User\Local Settings\desktop(2).ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Default User\Local Settings\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Default User\Local Settings\History\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Default User\Local Settings\History\History.IE5\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Guest\Local Settings\desktop(2).ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Guest\Local Settings\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Guest\Local Settings\History\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Guest\Local Settings\History\History.IE5\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\JEFF\Local Settings\desktop(2).ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\JEFF\Local Settings\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\JEFF\Local Settings\History\History.IE5\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\LocalService\Local Settings\History\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\LocalService\Local Settings\History\History.IE5\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\NetworkService\Local Settings\History\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\config\systemprofile\Local Settings\desktop.ini" is compressed (flags = 1)
Read File: File "c:\WINDOWS\system32\config\systemprofile\Local Settings\History\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Guest\Local Settings\Application Data\Microsoft\Feeds Cache\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\JEFF\Local Settings\Application Data\Microsoft\Feeds Cache\desktop.ini" is compressed (flags = 1)
Read File: File "c:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Internet Explorer\brndlog.txt" is compressed (flags = 1)
Read File: File "c:\RECYCLER\S-1-5-21-776561741-448539723-725345543-1003\desktop.ini" is compressed (flags = 1)
Done!
Scan finished
Creating System Restore point…
Scheduling clean up…
<<<2>>>
Device number: 0, partition: 1
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Removal scheduling successful. System shutdown needed.
System shutdown occurred
=======================================
—————————————
Malwarebytes Anti-Rootkit BETA 1.01.0.1020
© Malwarebytes Corporation 2011-2012
OS version: 5.1.2600 Windows XP Service Pack 3 x86
Account is Administrative
Internet Explorer version: 8.0.6001.18702
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.392000 GHz
Memory total: 2145386496, free: 1784754176
Removal queue found; removal started
Removing c:\Program Files\revosetup.exe…
Removing c:\Documents and Settings\Owner\Local Settings\Temp\~nsu.tmp\Au_.exe…
Removal finished
=======================================
Thank you,
Karen
MrCharlie
I'm not sure why you lost your connection.
I did ask you to create a system restore point before you ran it, was that the restore point you used?
Malwarebytes Anti-Rootkit also created one just before it rebooted the computer, did you use this one?
MrC
karenoregon
Dear Mr. Charlie:
Absolutely. I created the Mr. Charlie Restore Point! That is what Century Link used to get my internet back. After that happened I ran an ESET. ESET is something that I keep on my computer and run from time to time. Usually ESET scans are clean. The scan run after losing my internet was dirty. I have tried repeatedly to save the results to my desk top and can not do it. Perhaps it is because I ran the scan while sleeping and was not available to save the results immediately upon completion. All items indicate cleaned by deletion. There were five items. Four of the items say TDSS Killer, Quarantine, I am going to try to do a zip for you. No, can not do that. Can not right or left click on the results. I will paste what I could save in a text.
C:\System Volume Information\_restore{2C77E77B-A42C-4B63-B1C7-3D2020EEE0A3}\RP3453\A0564019.exe probably a variant of Win32/InstallIQ application cleaned by deleting - quarantined
C:\TDSSKiller_Quarantine\13.02.2013_21.06.18\tdlfs0000\tsk0004.dta Win32/Olmasco.O trojan cleaned by deleting - quarantined
C:\TDSSKiller_Quarantine\13.02.2013_21.06.18\tdlfs0000\tsk0008.dta a variant of Win32/Olmasco.O trojan cleaned by deleting - quarantined
C:\TDSSKiller_Quarantine\13.02.2013_21.06.18\tdlfs0000\tsk0016.dta a variant of Win32/Kryptik.QQF trojan cleaned by deleting - quarantined
C:\TDSSKiller_Quarantine\13.02.2013_21.06.18\tdlfs0000\tsk0017.dta a variant of Win32/Kryptik.QQF trojan cleaned by deleting - quarantined
Thanks,
Karen
MrCharlie
Those are all OK, already in quarantine.
How's the computer?? MrC
karenoregon
Hi Mr. Charlie:
The computer still seems a bit off. I am just feeling like I am stil infected because the computer is still hesitating before responding to things like it always does when I am infected.
If it was necessary to do the system restore after doing the mbar does that mean that the stuff mbar found is really gone? Should the items in ESET be deleted of just left in quarantine? Should I do another ESET?
Thanks,
Karen
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI