This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Adware popups [Solved]

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am getting unwanted popups and a short buzzing tone from my computer ( related to Firefox..happens each time I open a new page )… please help.

Here is my HT log

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:52:37 AM, on 3/29/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WTouch\WTouchService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WTouch\WTouchUser.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe
C:\xampp\mysql\bin\mysqld.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\GIGABYTE\GEST\GEST.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\GIGABYTE\GEST\GSvr.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\mark\Local Settings\Application Data\Smartbar\Application\QuickShare.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\Program Files\DAP\DAPBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1FD79A59-37B1-459B-9097-09F9FAB8A523} - (no file)
O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll
O2 - BHO: QuickShare WidgetEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - mscoree.dll (file missing)
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: Sing Along - {6492E171-2427-4932-B414-33574A089F5E} - C:\Program Files\SingAlong\singalng.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\Program Files\DAP\DAPIEBar.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll (file missing)
O3 - Toolbar: QuickShare Widget - {ae07101b-46d4-4a98-af68-0333ea26e113} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GEST] C:\Program Files\GIGABYTE\GEST\RUN.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Wondershare Helper Compact.exe] C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Browser Infrastructure Helper] C:\Documents and Settings\mark\Local Settings\Application Data\Smartbar\Application\QuickShare.exe startup
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll
O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {C53BDC3D-19A0-4062-BF34-0897A4E6A6A2} (Wild Pockets Loader Plugin Control Class) - https://plugin.wildpockets.com/common/WildP…oader-15079.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\GEST\GSvr.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit (mi-raysat_3dsMax2009_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: MySQL - MySQL AB - C:\xampp\mysql\bin\mysqld.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
O23 - Service: WTouch Service (WTouchService) - Wacom Technology, Corp. - C:\Program Files\WTouch\WTouchService.exe

–
End of file - 10739 bytes
Hello markoid. Posted Image

My name is fbfbfb. I will gladly assist you with your concerns.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your HJT log now, and I will post back shortly with instructions.

While working to resolve the issues with your machine, please follow these guidelines:
  • Please be patient. Logs are lengthy and can take time to analyze.
  • Read and follow my directions carefully, in the sequence they are posted.
  • If you are unsure about anything, please ask for clarification before continuing.
  • Use only those tools that you have been directed to use.
  • Do not install or uninstall any applications or run any other scans without being directed to do so.
  • Copy and Paste the log files inside your post. Do not send them as attachments unless otherwise instructed.
  • Stay with me until your machine has been deemed all clear.
  • Please reply within 3 days to avoid closing this topic.
Hi fbfbfb, thanks for your reply. My internet connection is a bit sporadic and I will hopefully be able to log on regularly to check for instructions.. cheers
Hello Markoid.

I would like to take a closer look at your system.

Please run the following scans

1. DDS

Please download DDS from HERE and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • When done, Attach.txt will open.
Please copy / paste the scan results of DDS.txt.

Please attach the second file: Attach.txt.

To attach a file, do the following:
  • Under the reply panel is the Attachments Panel.
  • Browse for the attachment file you want to upload, then click the green Upload button.
  • Once it has uploaded, click the Manage Current Attachments drop down box.
  • Click on [external image: Posted Image] to insert the attachment into your post.
2. aswMBR

Please download aswMBR from HERE.
  • Double click aswMBR.exe to run it.
  • When asked if you want to download Avast's virus definitions, please select Yes.
  • Click the Scan button to start the scan.
[external image: Posted Image]
  • On completion of the scan, click save log, save it to your desktop, and post in your next reply.
[external image: Posted Image]
Hi fbfbfb, 1- I don't know how to check for script blocking 2- The DDS file I downloading is names DDS.com, though it does still produce a DDS.txt and a Attach.txt when I run it. Should I go ahead with it? 3- The download freezes before it can finish d/l of the virus definitions with aswMBR
Hey fbfbfb, I have to be away from home 'til Wednesday night (it is 10am Monday here in Australia) and it is a desktop computer that we are dealing with, so won't be able to tend to this 'til then. My apologies, this was unexpected. I will come back to this thread when I return and hope that we can resume sorting out the problem… thanks
Hello, Markoid.

Thank you for advising me of your absence. When you return, please continue with this thread.

Yes, you are correct—you are downloading DDS.com and this will produce 2 logs: DDS.txt and attach.txt.

Script blocking programs refers to your anti-virus, anti-spyware, and other security applications. Because many security programs detect these specialized tools as malicious threats, they can interfere or block them, resulting in unreliable results. Therefore, we ask that you disable these programs. You can re-enable these programs after you have completed your scans.

Before beginning your scans, you should also exit any applications that you may be running (internet, email, media players, etc).

To disable your security protection, please go to this LINK and follow the instructions for your particular security programs.

Since you are experiencing problems with aswMBR, let’s run TDSSKiller instead. Please ensure your security programs are still disabled.

Please download TDSSKiller.zip
  • Extract it to your desktop.
  • Double click TDSSKiller.exe.
  • When the window opens, click on Change Parameters.
  • Under Additional options, put a check mark in the box next to Detect TDLFS File System.
  • Click OK.
  • Press Start Scan.
  • As we are only looking for a log of what is on the machine right now, choose to Skip whatever is found.
  • Then click Continue > Reboot now.
Copy and paste the log in your next reply.
  • A copy of the log will be saved automatically to the root of the drive (typically C:\).
Hi fbfbfb, Back again…here are the logs requested. DDS attach.txt 📎attach.txt DDS.txt DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 8.0.6001.18702 Run by [removed] at 15:35:05 on 2013-04-03 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1298 [GMT 11:00] . AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ============== Running Processes ================ . C:\Program Files\WTouch\WTouchService.exe C:\Program Files\WTouch\WTouchUser.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe C:\Program Files\AVG\AVG2012\avgwdsvc.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe C:\xampp\mysql\bin\mysqld.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\Pen_Tablet.exe C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe C:\WINDOWS\system32\Pen_Tablet.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\GIGABYTE\GEST\GEST.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files\AVG\AVG2012\avgtray.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe C:\WINDOWS\system32\ctfmon.exe C:\Documents and Settings\mark\Local Settings\Application Data\Smartbar\Application\QuickShare.exe C:\WINDOWS\System32\alg.exe C:\Program Files\GIGABYTE\GEST\GSvr.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k imgsvc . ============== Pseudo HJT Report =============== . uStart Page = hxxp://yahoo.com/ uSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ptec/defaults/sb/*http://www.yahoo.com/search/ie.html uSearch Page = hxxp://red.clientapps.yahoo.com/customize/ptec/defaults/sp/*http://www.yahoo.com uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ptec/defaults/su/*http://www.yahoo.com BHO: DAPHelper Class: {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - c:\program files\dap\DAPBHO.dll BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: {1FD79A59-37B1-459B-9097-09F9FAB8A523} - BHO: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - c:\program files\avg\avg2012\avgdtiex.dll BHO: QuickShare WidgetEngine: {31ad400d-1b06-4e33-a59a-90c2c140cba0} - BHO: DivX Plus Web Player HTML5 : {326E768D-4182-46FD-9C16-1449A49795F4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - c:\program files\avg\avg2012\avgssie.dll BHO: Sing Along: {6492E171-2427-4932-B414-33574A089F5E} - c:\program files\singalong\singalng.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - TB: DAP Bar: {62999427-33FC-4baf-9C9C-BCE6BD127F08} - c:\program files\dap\DAPIEBar.dll TB: Veoh Browser Plug-in: {D0943516-5076-4020-A3B5-AEFAF26AB263} - TB: QuickShare Widget: {ae07101b-46d4-4a98-af68-0333ea26e113} - uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Veoh] "c:\program files\veoh networks\veoh\VeohClient.exe" /VeohHide uRun: [Browser Infrastructure Helper] c:\documents and settings\mark\local settings\application data\smartbar\application\QuickShare.exe startup mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [GEST] c:\program files\gigabyte\gest\RUN.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [JMB36X IDE Setup] c:\windows\raidtool\xInsIDE.exe mRun: [36X Raid Configurer] c:\windows\system32\xRaidSetup.exe boot mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe" mRun: [WinampAgent] "c:\program files\winamp\winampa.exe" mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe" mRun: [Wondershare Helper Compact.exe] c:\program files\common files\wondershare\wondershare helper compact\WSHelper.exe mRun: [VirtualCloneDrive] "c:\program files\elaborate bytes\virtualclonedrive\VCDDaemon.exe" /s mRun: [DivXMediaServer] c:\program files\divx\divx media server\DivXMediaServer.exe mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoDriveTypeAutoRun = dword:145 IE: &Download with &DAP - c:\progra~1\dap\dapextie.htm IE: Download &all with DAP - c:\progra~1\dap\dapextie2.htm IE: Sothink SWF Catcher - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm IE: {669695BC-A811-4A9D-8CDF-BA8C795F261C} - c:\progra~1\dap\DAP.EXE IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - c:\program files\avg\avg2012\avgdtiex.dll IE: {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - LocalServer32 - IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {C53BDC3D-19A0-4062-BF34-0897A4E6A6A2} - hxxps://plugin.wildpockets.com/common/WildPocketsLoader-15079.cab TCP: NameServer = 192.168.0.1 TCP: Interfaces\{ADB71D2D-3D0A-4BD1-BBAE-C9210E41A10F} : DHCPNameServer = 192.168.0.1 Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\program files\dap\dapie.dll Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\program files\dap\dapie.dll Name-Space Handler: HTTPS\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\program files\dap\dapie.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe" . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\mark\application data\mozilla\firefox\profiles\0r02yzpl.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: keyword.URL - hxxp://au.search.yahoo.com/search?ei=UTF-8&fr=w3i&type=W3i_DS,157,0_0,Search,20130310,17023,0,53,0&p= FF - plugin: c:\documents and settings\mark\local settings\application data\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.3.21.135\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll FF - plugin: c:\program files\tabletplugins\npwacom.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_6_602_180.dll FF - ExtSQL: 2013-03-09 19:21; [removed]; c:\documents and settings\mark\application data\mozilla\firefox\profiles\0r02yzpl.default\extensions\[removed] FF - ExtSQL: 2013-03-09 21:41; {23fcfd51-4958-4f00-80a3-ae97e717ed8b}; c:\program files\divx\divx plus web player\firefox\DivXHTML5 FF - ExtSQL: 2013-03-28 22:15; [removed]; c:\program files\singalong\FF FF - ExtSQL: 2013-03-28 22:16; {1fcbcf80-4afa-4a9e-bcaf-892dee3334b8}; c:\documents and settings\mark\application data\mozilla\firefox\profiles\0r02yzpl.default\extensions\{1fcbcf80-4afa-4a9e-bcaf-892dee3334b8} FF - ExtSQL: !HIDDEN! 2010-01-16 11:34; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension . —- FIREFOX POLICIES —- FF - user.js: extensions.autoDisableScopes - 0 FF - user.js: extensions.shownSelectionUI - true . ============= SERVICES / DRIVERS =============== . R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2012-4-19 24896] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 31952] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 250080] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 41040] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-9-7 301920] R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2012-2-14 193288] R2 mi-raysat_3dsMax2009_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit;c:\program files\autodesk\3ds max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe [2008-3-10 65536] R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2010-5-26 4497704] R2 WTouchService;WTouch Service;c:\program files\wtouch\WTouchService.exe [2010-5-26 113448] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2011-12-23 142176] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilterx.sys [2011-12-23 24144] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2011-12-23 17232] R3 GEST Service;GEST Service for program management.;c:\program files\gigabyte\gest\GSvr.exe [2010-1-1 47624] R3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTWlanU.sys [2012-11-22 915432] S2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\avgidsagent.exe [2012-11-2 5174392] S3 Cdadmbupfvplend;Cdadmbupfvplend;c:\windows\system32\drivers\netbios.sys [2008-4-14 34688] S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys –> c:\windows\system32\drivers\wg111v2.sys [?] S4 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2010-8-25 29416] . =============== File Associations =============== . ShellExec: FRONTPG.EXE: edit=c:\progra~1\micros~2\office\FRONTPG.EXE . =============== Created Last 30 ================ . 2013-03-28 23:50:42 388096 —-a-r- c:\documents and settings\mark\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2013-03-28 23:17:12 73432 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-03-28 23:17:12 693976 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2013-03-28 11:40:04 ——– d—–w- c:\documents and settings\mark\.FBReader 2013-03-28 11:16:51 ——– d—–w- c:\program files\FBReader 2013-03-28 11:16:06 ——– d—–w- c:\documents and settings\mark\local settings\application data\Smartbar 2013-03-28 11:15:35 ——– d—–w- c:\program files\SingAlong 2013-03-09 21:46:30 ——– d—–w- c:\documents and settings\all users\Uniblue 2013-03-09 10:43:12 ——– d—–w- c:\documents and settings\mark\application data\DDMSettings 2013-03-09 08:46:30 ——– d—–w- c:\program files\common files\DivX Shared 2013-03-09 08:34:24 ——– d—–w- c:\program files\DivX 2013-03-09 08:33:11 ——– d—–w- c:\documents and settings\all users\application data\DivX 2013-03-09 08:23:11 ——– d—–w- c:\program files\VIO Player 2013-03-09 08:20:41 ——– d—–w- c:\documents and settings\mark\application data\DefaultTab 2013-03-09 08:17:42 ——– d—–w- c:\documents and settings\all users\application data\APN . ==================== Find3M ==================== . 2013-04-02 21:30:41 16608 —-a-w- c:\windows\gdrv.sys . ============= FINISH: 15:35:31.32 =============== TDSS log 15:32:52.0546 3052 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 15:32:54.0531 3052 ============================================================ 15:32:54.0531 3052 Current date / time: 2013/04/03 15:32:54.0531 15:32:54.0531 3052 SystemInfo: 15:32:54.0531 3052 15:32:54.0531 3052 OS Version: 5.1.2600 ServicePack: 3.0 15:32:54.0531 3052 Product type: Workstation 15:32:54.0531 3052 ComputerName: MARK-B08C776A0F 15:32:54.0531 3052 UserName: mark 15:32:54.0531 3052 Windows directory: C:\WINDOWS 15:32:54.0531 3052 System windows directory: C:\WINDOWS 15:32:54.0531 3052 Processor architecture: Intel x86 15:32:54.0531 3052 Number of processors: 4 15:32:54.0531 3052 Page size: 0x1000 15:32:54.0531 3052 Boot type: Normal boot 15:32:54.0531 3052 ============================================================ 15:32:55.0359 3052 Drive \Device\Harddisk0\DR0 - Size: 0x4A85C4DE00 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 15:32:55.0359 3052 Drive \Device\Harddisk1\DR3 - Size: 0x7470BFF800 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 15:32:55.0390 3052 ============================================================ 15:32:55.0390 3052 \Device\Harddisk0\DR0: 15:32:55.0390 3052 MBR partitions: 15:32:55.0390 3052 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x2711637 15:32:55.0390 3052 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x27116B5, BlocksNum 0xD8E958F 15:32:55.0390 3052 \Device\Harddisk1\DR3: 15:32:55.0390 3052 MBR partitions: 15:32:55.0390 3052 \Device\Harddisk1\DR3\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x3A384800 15:32:55.0390 3052 ============================================================ 15:32:55.0406 3052 C: <-> \Device\Harddisk0\DR0\Partition1 15:32:55.0515 3052 D: <-> \Device\Harddisk0\DR0\Partition2 15:32:55.0546 3052 G: <-> \Device\Harddisk1\DR3\Partition1 15:32:55.0546 3052 ============================================================ 15:32:55.0546 3052 Initialize success 15:32:55.0546 3052 ============================================================ 15:33:28.0593 2752 ============================================================ 15:33:28.0593 2752 Scan started 15:33:28.0593 2752 Mode: Manual; TDLFS; 15:33:28.0593 2752 ============================================================ 15:33:30.0125 2752 ================ Scan system memory ======================== 15:33:30.0140 2752 System memory - ok 15:33:30.0140 2752 ================ Scan services ============================= 15:33:30.0218 2752 Abiosdsk - ok 15:33:30.0218 2752 abp480n5 - ok 15:33:30.0250 2752 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 15:33:30.0250 2752 ACPI - ok 15:33:30.0265 2752 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 15:33:30.0265 2752 ACPIEC - ok 15:33:30.0312 2752 [ 5DDC0A8D2CD60BDA593DDAF45821CE08 ] Adobe LM Service C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe 15:33:30.0312 2752 Adobe LM Service - ok 15:33:30.0328 2752 adpu160m - ok 15:33:30.0359 2752 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 15:33:30.0359 2752 aec - ok 15:33:30.0375 2752 [ 30BB1BDE595CA65FD5549462080D94E5 ] AegisP C:\WINDOWS\system32\DRIVERS\AegisP.sys 15:33:30.0375 2752 AegisP - ok 15:33:30.0406 2752 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys 15:33:30.0406 2752 AFD - ok 15:33:30.0453 2752 [ 994A42D273C35B43EE9D1E8A5D8BC639 ] AgereSoftModem C:\WINDOWS\system32\DRIVERS\AGRSM.sys 15:33:30.0484 2752 AgereSoftModem - ok 15:33:30.0500 2752 Aha154x - ok 15:33:30.0500 2752 aic78u2 - ok 15:33:30.0500 2752 aic78xx - ok 15:33:30.0515 2752 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll 15:33:30.0515 2752 Alerter - ok 15:33:30.0531 2752 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe 15:33:30.0531 2752 ALG - ok 15:33:30.0531 2752 AliIde - ok 15:33:30.0546 2752 amsint - ok 15:33:30.0609 2752 [ FB32F046A2578755FA0DA5052C6A9CD3 ] Apache2.2 C:\xampp\apache\bin\httpd.exe 15:33:30.0609 2752 Apache2.2 - ok 15:33:30.0609 2752 AppMgmt - ok 15:33:30.0609 2752 asc - ok 15:33:30.0609 2752 asc3350p - ok 15:33:30.0625 2752 asc3550 - ok 15:33:30.0671 2752 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 15:33:30.0671 2752 aspnet_state - ok 15:33:30.0687 2752 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 15:33:30.0687 2752 AsyncMac - ok 15:33:30.0703 2752 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 15:33:30.0703 2752 atapi - ok 15:33:30.0703 2752 Atdisk - ok 15:33:30.0703 2752 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 15:33:30.0703 2752 Atmarpc - ok 15:33:30.0718 2752 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 15:33:30.0718 2752 AudioSrv - ok 15:33:30.0718 2752 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 15:33:30.0734 2752 audstub - ok 15:33:30.0765 2752 [ EAD65493EDBA0EBEA2192D46B938298E ] Autodesk Licensing Service C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe 15:33:30.0765 2752 Autodesk Licensing Service - ok 15:33:32.0171 2752 [ 231B6AD3DB2866BC3FDB9979E6B2B61E ] AVGIDSAgent C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe 15:33:33.0562 2752 AVGIDSAgent - ok 15:33:33.0593 2752 [ EF67527CC2AD77D22AB1405C6470407E ] AVGIDSDriver C:\WINDOWS\system32\DRIVERS\avgidsdriverx.sys 15:33:33.0593 2752 AVGIDSDriver - ok 15:33:33.0609 2752 [ 61A7E0B02F82CFF3DB2445BBE50B3589 ] AVGIDSFilter C:\WINDOWS\system32\DRIVERS\avgidsfilterx.sys 15:33:33.0609 2752 AVGIDSFilter - ok 15:33:33.0640 2752 [ D63D83659EEDF60B3A3E620281A888E5 ] AVGIDSHX C:\WINDOWS\system32\DRIVERS\avgidshx.sys 15:33:33.0640 2752 AVGIDSHX - ok 15:33:33.0656 2752 [ BAF975B72062F53D327788E99D64197E ] AVGIDSShim C:\WINDOWS\system32\DRIVERS\avgidsshimx.sys 15:33:33.0656 2752 AVGIDSShim - ok 15:33:33.0671 2752 [ 6671345A6E2669AF1966BAF68EC5620F ] Avgldx86 C:\WINDOWS\system32\DRIVERS\avgldx86.sys 15:33:33.0671 2752 Avgldx86 - ok 15:33:33.0687 2752 [ CCDD61545AAEA265977E4B1EFDC74E8C ] Avgmfx86 C:\WINDOWS\system32\DRIVERS\avgmfx86.sys 15:33:33.0687 2752 Avgmfx86 - ok 15:33:33.0703 2752 [ 1FD90B28D2C3100BF4500199C8AD6358 ] Avgrkx86 C:\WINDOWS\system32\DRIVERS\avgrkx86.sys 15:33:33.0703 2752 Avgrkx86 - ok 15:33:33.0718 2752 [ C0BC3B2E3FD625E7F55E1FF863E94592 ] Avgtdix C:\WINDOWS\system32\DRIVERS\avgtdix.sys 15:33:33.0718 2752 Avgtdix - ok 15:33:33.0750 2752 [ EA1145DEBCD508FD25BD1E95C4346929 ] avgwd C:\Program Files\AVG\AVG2012\avgwdsvc.exe 15:33:33.0765 2752 avgwd - ok 15:33:33.0765 2752 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 15:33:33.0765 2752 Beep - ok 15:33:33.0796 2752 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll 15:33:33.0828 2752 BITS - ok 15:33:33.0859 2752 [ A06CE3399D16DB864F55FAEB1F1927A9 ] Browser C:\WINDOWS\System32\browser.dll 15:33:33.0859 2752 Browser - ok 15:33:33.0875 2752 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 15:33:33.0875 2752 cbidf2k - ok 15:33:33.0875 2752 cd20xrnt - ok 15:33:33.0906 2752 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] Cdadmbupfvplend C:\WINDOWS\system32\drivers\netbios.sys 15:33:33.0906 2752 Cdadmbupfvplend - ok 15:33:33.0921 2752 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 15:33:33.0921 2752 Cdaudio - ok 15:33:33.0937 2752 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 15:33:33.0937 2752 Cdfs - ok 15:33:33.0953 2752 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 15:33:33.0953 2752 Cdrom - ok 15:33:33.0953 2752 Changer - ok 15:33:33.0953 2752 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe 15:33:33.0953 2752 CiSvc - ok 15:33:33.0968 2752 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 15:33:33.0984 2752 ClipSrv - ok 15:33:34.0000 2752 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 15:33:34.0000 2752 clr_optimization_v2.0.50727_32 - ok 15:33:34.0000 2752 CmdIde - ok 15:33:34.0015 2752 COMSysApp - ok 15:33:34.0015 2752 Cpqarray - ok 15:33:34.0031 2752 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 15:33:34.0031 2752 CryptSvc - ok 15:33:34.0031 2752 dac2w2k - ok 15:33:34.0031 2752 dac960nt - ok 15:33:34.0062 2752 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 15:33:34.0078 2752 DcomLaunch - ok 15:33:34.0078 2752 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 15:33:34.0078 2752 Dhcp - ok 15:33:34.0093 2752 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 15:33:34.0093 2752 Disk - ok 15:33:34.0093 2752 dmadmin - ok 15:33:34.0125 2752 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 15:33:34.0140 2752 dmboot - ok 15:33:34.0140 2752 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys 15:33:34.0156 2752 dmio - ok 15:33:34.0156 2752 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 15:33:34.0156 2752 dmload - ok 15:33:34.0171 2752 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll 15:33:34.0171 2752 dmserver - ok 15:33:34.0187 2752 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 15:33:34.0187 2752 DMusic - ok 15:33:34.0203 2752 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 15:33:34.0203 2752 Dnscache - ok 15:33:34.0234 2752 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 15:33:34.0234 2752 Dot3svc - ok 15:33:34.0234 2752 dpti2o - ok 15:33:34.0234 2752 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 15:33:34.0250 2752 drmkaud - ok 15:33:34.0265 2752 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll 15:33:34.0265 2752 EapHost - ok 15:33:34.0296 2752 [ D71233D7CCC2E64F8715A20428D5A33B ] ElbyCDIO C:\WINDOWS\system32\Drivers\ElbyCDIO.sys 15:33:34.0296 2752 ElbyCDIO - ok 15:33:34.0296 2752 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll 15:33:34.0312 2752 ERSvc - ok 15:33:34.0328 2752 [ E5030E34DE21A6818E8586BFB7DD4B60 ] ET5Drv C:\WINDOWS\system32\Drivers\ET5Drv.sys 15:33:34.0328 2752 ET5Drv - ok 15:33:34.0343 2752 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe 15:33:34.0343 2752 Eventlog - ok 15:33:34.0375 2752 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll 15:33:34.0375 2752 EventSystem - ok 15:33:34.0406 2752 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 15:33:34.0406 2752 Fastfat - ok 15:33:34.0421 2752 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 15:33:34.0437 2752 FastUserSwitchingCompatibility - ok 15:33:34.0437 2752 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys 15:33:34.0437 2752 Fdc - ok 15:33:34.0453 2752 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 15:33:34.0453 2752 Fips - ok 15:33:34.0468 2752 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys 15:33:34.0468 2752 Flpydisk - ok 15:33:34.0484 2752 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys 15:33:34.0484 2752 FltMgr - ok 15:33:34.0546 2752 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 15:33:34.0546 2752 FontCache3.0.0.0 - ok 15:33:34.0562 2752 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 15:33:34.0562 2752 Fs_Rec - ok 15:33:34.0562 2752 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 15:33:34.0578 2752 Ftdisk - ok 15:33:34.0578 2752 [ 5C230948DD6652228F88CA7AE6CB276C ] gdrv C:\WINDOWS\gdrv.sys 15:33:34.0578 2752 gdrv - ok 15:33:34.0609 2752 [ A73082BAB773171B34D656609C6D5854 ] GEST Service C:\Program Files\GIGABYTE\GEST\GSvr.exe 15:33:34.0625 2752 GEST Service - ok 15:33:34.0625 2752 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 15:33:34.0625 2752 Gpc - ok 15:33:34.0671 2752 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe 15:33:34.0671 2752 gupdate - ok 15:33:34.0687 2752 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe 15:33:34.0687 2752 gupdatem - ok 15:33:34.0703 2752 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 15:33:34.0703 2752 HDAudBus - ok 15:33:34.0750 2752 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 15:33:34.0750 2752 helpsvc - ok 15:33:34.0765 2752 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ C:\WINDOWS\System32\hidserv.dll 15:33:34.0765 2752 HidServ - ok 15:33:34.0765 2752 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] hidusb C:\WINDOWS\system32\DRIVERS\hidusb.sys 15:33:34.0765 2752 hidusb - ok 15:33:34.0796 2752 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 15:33:34.0796 2752 hkmsvc - ok 15:33:34.0796 2752 hpn - ok 15:33:34.0843 2752 [ 9EFA5FEC26CEC696A66A891AC90B412D ] HSF_DPV C:\WINDOWS\system32\DRIVERS\HSX_DPV.sys 15:33:34.0859 2752 HSF_DPV - ok 15:33:34.0875 2752 [ A3077D9ED7FF612A033536A6009DBEA5 ] HSXHWBS2 C:\WINDOWS\system32\DRIVERS\HSXHWBS2.sys 15:33:34.0890 2752 HSXHWBS2 - ok 15:33:34.0906 2752 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 15:33:34.0906 2752 HTTP - ok 15:33:34.0921 2752 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 15:33:34.0937 2752 HTTPFilter - ok 15:33:34.0937 2752 i2omgmt - ok 15:33:34.0937 2752 i2omp - ok 15:33:34.0968 2752 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\drivers\i8042prt.sys 15:33:34.0968 2752 i8042prt - ok 15:33:35.0015 2752 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 15:33:35.0031 2752 idsvc - ok 15:33:35.0046 2752 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 15:33:35.0046 2752 Imapi - ok 15:33:35.0062 2752 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe 15:33:35.0062 2752 ImapiService - ok 15:33:35.0062 2752 ini910u - ok 15:33:35.0187 2752 [ C282875880DF189C64C465FC54A0150A ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys 15:33:35.0296 2752 IntcAzAudAddService - ok 15:33:35.0296 2752 IntelIde - ok 15:33:35.0328 2752 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 15:33:35.0328 2752 intelppm - ok 15:33:35.0343 2752 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 15:33:35.0343 2752 Ip6Fw - ok 15:33:35.0359 2752 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 15:33:35.0359 2752 IpFilterDriver - ok 15:33:35.0359 2752 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 15:33:35.0359 2752 IpInIp - ok 15:33:35.0390 2752 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 15:33:35.0390 2752 IpNat - ok 15:33:35.0406 2752 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 15:33:35.0406 2752 IPSec - ok 15:33:35.0421 2752 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 15:33:35.0421 2752 IRENUM - ok 15:33:35.0453 2752 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 15:33:35.0453 2752 isapnp - ok 15:33:35.0453 2752 [ AB95B2DDB49F6B6CF52625E56C1F1F71 ] JRAID C:\WINDOWS\system32\DRIVERS\jraid.sys 15:33:35.0468 2752 JRAID - ok 15:33:35.0484 2752 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 15:33:35.0484 2752 Kbdclass - ok 15:33:35.0484 2752 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys 15:33:35.0484 2752 kbdhid - ok 15:33:35.0500 2752 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 15:33:35.0500 2752 kmixer - ok 15:33:35.0531 2752 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 15:33:35.0531 2752 KSecDD - ok 15:33:35.0546 2752 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] LanmanServer C:\WINDOWS\System32\srvsvc.dll 15:33:35.0562 2752 LanmanServer - ok 15:33:35.0578 2752 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 15:33:35.0578 2752 lanmanworkstation - ok 15:33:35.0578 2752 lbrtfdc - ok 15:33:35.0609 2752 [ 75AC54B996F7C8E17594EBC32B6614BD ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe 15:33:35.0625 2752 LightScribeService - ok 15:33:35.0640 2752 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 15:33:35.0640 2752 LmHosts - ok 15:33:35.0656 2752 [ 0CEA2D0D3FA284B85ED5B68365114F76 ] mdmxsdk C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 15:33:35.0656 2752 mdmxsdk - ok 15:33:35.0656 2752 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll 15:33:35.0671 2752 Messenger - ok 15:33:35.0703 2752 [ AA0C4A2C33CE075DF2C272D678734991 ] mi-raysat_3dsMax2009_32 C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe 15:33:35.0703 2752 mi-raysat_3dsMax2009_32 - ok 15:33:35.0734 2752 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 15:33:35.0734 2752 mnmdd - ok 15:33:35.0765 2752 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 15:33:35.0765 2752 mnmsrvc - ok 15:33:35.0781 2752 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 15:33:35.0781 2752 Modem - ok 15:33:35.0796 2752 [ 1992E0D143B09653AB0F9C5E04B0FD65 ] MODEMCSA C:\WINDOWS\system32\drivers\MODEMCSA.sys 15:33:35.0796 2752 MODEMCSA - ok 15:33:35.0828 2752 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 15:33:35.0828 2752 Mouclass - ok 15:33:35.0843 2752 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 15:33:35.0843 2752 mouhid - ok 15:33:35.0859 2752 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 15:33:35.0859 2752 MountMgr - ok 15:33:35.0906 2752 [ 46297FA8E30A6007F14118FC2B942FBC ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 15:33:35.0906 2752 MozillaMaintenance - ok 15:33:35.0906 2752 mraid35x - ok 15:33:35.0921 2752 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 15:33:35.0921 2752 MRxDAV - ok 15:33:35.0953 2752 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 15:33:35.0968 2752 MRxSmb - ok 15:33:35.0984 2752 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe 15:33:35.0984 2752 MSDTC - ok 15:33:36.0000 2752 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 15:33:36.0000 2752 Msfs - ok 15:33:36.0000 2752 MSIServer - ok 15:33:36.0015 2752 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 15:33:36.0015 2752 MSKSSRV - ok 15:33:36.0031 2752 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 15:33:36.0031 2752 MSPCLOCK - ok 15:33:36.0031 2752 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 15:33:36.0031 2752 MSPQM - ok 15:33:36.0062 2752 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 15:33:36.0062 2752 mssmbios - ok 15:33:36.0078 2752 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 15:33:36.0078 2752 Mup - ok 15:33:36.0250 2752 [ 21EEF976D53A0BCB603ABFF4AB6E4C88 ] MySQL C:\xampp\mysql\bin\mysqld.exe 15:33:36.0390 2752 MySQL - ok 15:33:36.0421 2752 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll 15:33:36.0421 2752 napagent - ok 15:33:36.0437 2752 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 15:33:36.0453 2752 NDIS - ok 15:33:36.0468 2752 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 15:33:36.0468 2752 NdisTapi - ok 15:33:36.0515 2752 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 15:33:36.0515 2752 Ndisuio - ok 15:33:36.0515 2752 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 15:33:36.0515 2752 NdisWan - ok 15:33:36.0546 2752 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 15:33:36.0546 2752 NDProxy - ok 15:33:36.0562 2752 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 15:33:36.0562 2752 NetBIOS - ok 15:33:36.0562 2752 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 15:33:36.0562 2752 NetBT - ok 15:33:36.0578 2752 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe 15:33:36.0578 2752 NetDDE - ok 15:33:36.0609 2752 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 15:33:36.0625 2752 NetDDEdsdm - ok 15:33:36.0640 2752 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe 15:33:36.0640 2752 Netlogon - ok 15:33:36.0671 2752 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll 15:33:36.0671 2752 Netman - ok 15:33:36.0703 2752 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 15:33:36.0703 2752 NetTcpPortSharing - ok 15:33:36.0734 2752 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll 15:33:36.0734 2752 Nla - ok 15:33:36.0734 2752 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 15:33:36.0734 2752 Npfs - ok 15:33:36.0750 2752 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 15:33:36.0765 2752 Ntfs - ok 15:33:36.0765 2752 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 15:33:36.0765 2752 NtLmSsp - ok 15:33:36.0796 2752 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 15:33:36.0812 2752 NtmsSvc - ok 15:33:36.0812 2752 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 15:33:36.0828 2752 Null - ok 15:33:36.0984 2752 [ CEAB17BA3E0F7DE96A4649F896B35131 ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 15:33:37.0140 2752 nv - ok 15:33:37.0156 2752 [ DF6FD57D6807AE459B3463FBFDA02D49 ] NVSvc C:\WINDOWS\system32\nvsvc32.exe 15:33:37.0156 2752 NVSvc - ok 15:33:37.0171 2752 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 15:33:37.0171 2752 NwlnkFlt - ok 15:33:37.0187 2752 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 15:33:37.0187 2752 NwlnkFwd - ok 15:33:37.0203 2752 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys 15:33:37.0203 2752 Parport - ok 15:33:37.0203 2752 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 15:33:37.0203 2752 PartMgr - ok 15:33:37.0234 2752 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 15:33:37.0234 2752 ParVdm - ok 15:33:37.0250 2752 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 15:33:37.0250 2752 PCI - ok 15:33:37.0250 2752 PCIDump - ok 15:33:37.0250 2752 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 15:33:37.0250 2752 PCIIde - ok 15:33:37.0281 2752 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys 15:33:37.0281 2752 Pcmcia - ok 15:33:37.0281 2752 PDCOMP - ok 15:33:37.0281 2752 PDFRAME - ok 15:33:37.0281 2752 PDRELI - ok 15:33:37.0281 2752 PDRFRAME - ok 15:33:37.0296 2752 perc2 - ok 15:33:37.0296 2752 perc2hib - ok 15:33:37.0312 2752 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe 15:33:37.0312 2752 PlugPlay - ok 15:33:37.0328 2752 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 15:33:37.0328 2752 PolicyAgent - ok 15:33:37.0343 2752 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 15:33:37.0343 2752 PptpMiniport - ok 15:33:37.0343 2752 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 15:33:37.0343 2752 ProtectedStorage - ok 15:33:37.0359 2752 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 15:33:37.0359 2752 PSched - ok 15:33:37.0359 2752 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 15:33:37.0359 2752 Ptilink - ok 15:33:37.0390 2752 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys 15:33:37.0390 2752 PxHelp20 - ok 15:33:37.0390 2752 ql1080 - ok 15:33:37.0390 2752 Ql10wnt - ok 15:33:37.0390 2752 ql12160 - ok 15:33:37.0390 2752 ql1240 - ok 15:33:37.0406 2752 ql1280 - ok 15:33:37.0406 2752 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 15:33:37.0406 2752 RasAcd - ok 15:33:37.0406 2752 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll 15:33:37.0421 2752 RasAuto - ok 15:33:37.0437 2752 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 15:33:37.0437 2752 Rasl2tp - ok 15:33:37.0437 2752 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll 15:33:37.0453 2752 RasMan - ok 15:33:37.0453 2752 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 15:33:37.0453 2752 RasPppoe - ok 15:33:37.0468 2752 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 15:33:37.0468 2752 Raspti - ok 15:33:37.0484 2752 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 15:33:37.0484 2752 Rdbss - ok 15:33:37.0484 2752 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 15:33:37.0484 2752 RDPCDD - ok 15:33:37.0515 2752 [ FC105DD312ED64EB66BFF111E8EC6EAC ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 15:33:37.0531 2752 RDPWD - ok 15:33:37.0546 2752 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 15:33:37.0562 2752 RDSessMgr - ok 15:33:37.0562 2752 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 15:33:37.0562 2752 redbook - ok 15:33:37.0578 2752 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 15:33:37.0578 2752 RemoteAccess - ok 15:33:37.0593 2752 [ D8B0B4ADE32574B2D9C5CC34DC0DBBE7 ] ROOTMODEM C:\WINDOWS\system32\Drivers\RootMdm.sys 15:33:37.0593 2752 ROOTMODEM - ok 15:33:37.0609 2752 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe 15:33:37.0609 2752 RpcLocator - ok 15:33:37.0640 2752 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\system32\rpcss.dll 15:33:37.0640 2752 RpcSs - ok 15:33:37.0656 2752 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe 15:33:37.0671 2752 RSVP - ok 15:33:37.0703 2752 [ 835161DD872B5D6BC815B98C0BA624D1 ] RTL8192cu C:\WINDOWS\system32\DRIVERS\rtwlanu.sys 15:33:37.0734 2752 RTL8192cu - ok 15:33:37.0765 2752 [ 36ADA62330C31AD314E4A26B815FC485 ] RTLE8023xp C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 15:33:37.0765 2752 RTLE8023xp - ok 15:33:37.0781 2752 RTLWUSB - ok 15:33:37.0781 2752 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe 15:33:37.0781 2752 SamSs - ok 15:33:37.0812 2752 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 15:33:37.0812 2752 SCardSvr - ok 15:33:37.0828 2752 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll 15:33:37.0843 2752 Schedule - ok 15:33:37.0843 2752 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 15:33:37.0843 2752 Secdrv - ok 15:33:37.0859 2752 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll 15:33:37.0859 2752 seclogon - ok 15:33:37.0875 2752 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll 15:33:37.0875 2752 SENS - ok 15:33:37.0890 2752 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 15:33:37.0890 2752 serenum - ok 15:33:37.0890 2752 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys 15:33:37.0890 2752 Serial - ok 15:33:37.0906 2752 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 15:33:37.0906 2752 Sfloppy - ok 15:33:37.0921 2752 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 15:33:37.0937 2752 SharedAccess - ok 15:33:37.0937 2752 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 15:33:37.0937 2752 ShellHWDetection - ok 15:33:37.0953 2752 Simbad - ok 15:33:37.0953 2752 Sparrow - ok 15:33:37.0968 2752 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 15:33:37.0968 2752 splitter - ok 15:33:37.0984 2752 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe 15:33:37.0984 2752 Spooler - ok 15:33:38.0015 2752 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 15:33:38.0015 2752 sr - ok 15:33:38.0015 2752 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll 15:33:38.0031 2752 srservice - ok 15:33:38.0046 2752 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 15:33:38.0046 2752 Srv - ok 15:33:38.0078 2752 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 15:33:38.0078 2752 SSDPSRV - ok 15:33:38.0078 2752 StarOpen - ok 15:33:38.0093 2752 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll 15:33:38.0109 2752 stisvc - ok 15:33:38.0125 2752 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 15:33:38.0125 2752 swenum - ok 15:33:38.0125 2752 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 15:33:38.0125 2752 swmidi - ok 15:33:38.0125 2752 SwPrv - ok 15:33:38.0140 2752 symc810 - ok 15:33:38.0140 2752 symc8xx - ok 15:33:38.0140 2752 sym_hi - ok 15:33:38.0140 2752 sym_u3 - ok 15:33:38.0156 2752 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 15:33:38.0156 2752 sysaudio - ok 15:33:38.0171 2752 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 15:33:38.0171 2752 SysmonLog - ok 15:33:38.0296 2752 [ 099AEE120CAC4A43CE307A828998392F ] TabletServicePen C:\WINDOWS\system32\Pen_Tablet.exe 15:33:38.0421 2752 TabletServicePen - ok 15:33:38.0468 2752 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 15:33:38.0484 2752 TapiSrv - ok 15:33:38.0500 2752 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 15:33:38.0515 2752 Tcpip - ok 15:33:38.0531 2752 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 15:33:38.0531 2752 TDPIPE - ok 15:33:38.0546 2752 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 15:33:38.0562 2752 TDTCP - ok 15:33:38.0562 2752 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 15:33:38.0562 2752 TermDD - ok 15:33:38.0578 2752 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll 15:33:38.0578 2752 TermService - ok 15:33:38.0609 2752 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll 15:33:38.0609 2752 Themes - ok 15:33:38.0609 2752 TosIde - ok 15:33:38.0640 2752 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll 15:33:38.0640 2752 TrkWks - ok 15:33:38.0640 2752 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 15:33:38.0640 2752 Udfs - ok 15:33:38.0656 2752 ultra - ok 15:33:38.0687 2752 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 15:33:38.0687 2752 Update - ok 15:33:38.0703 2752 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll 15:33:38.0703 2752 upnphost - ok 15:33:38.0718 2752 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe 15:33:38.0718 2752 UPS - ok 15:33:38.0734 2752 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 15:33:38.0734 2752 usbccgp - ok 15:33:38.0750 2752 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 15:33:38.0750 2752 usbehci - ok 15:33:38.0781 2752 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 15:33:38.0781 2752 usbhub - ok 15:33:38.0796 2752 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys 15:33:38.0796 2752 usbscan - ok 15:33:38.0812 2752 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 15:33:38.0812 2752 USBSTOR - ok 15:33:38.0812 2752 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 15:33:38.0812 2752 usbuhci - ok 15:33:38.0828 2752 [ FCE98C43B5C5DB8E0DA8EA0E2B45E044 ] VClone C:\WINDOWS\system32\DRIVERS\VClone.sys 15:33:38.0828 2752 VClone - ok 15:33:38.0843 2752 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 15:33:38.0843 2752 VgaSave - ok 15:33:38.0843 2752 ViaIde - ok 15:33:38.0859 2752 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 15:33:38.0859 2752 VolSnap - ok 15:33:38.0875 2752 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe 15:33:38.0875 2752 VSS - ok 15:33:38.0906 2752 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll 15:33:38.0906 2752 W32Time - ok 15:33:38.0937 2752 [ 427A8BC96F16C40DF81C2D2F4EDD32DD ] wacommousefilter C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys 15:33:38.0937 2752 wacommousefilter - ok 15:33:38.0937 2752 [ 51D580F30D1A1F2EA4965AF6ABC2BCB2 ] wacomvhid C:\WINDOWS\system32\DRIVERS\wacomvhid.sys 15:33:38.0937 2752 wacomvhid - ok 15:33:38.0937 2752 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 15:33:38.0953 2752 Wanarp - ok 15:33:38.0953 2752 WDICA - ok 15:33:38.0953 2752 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 15:33:38.0968 2752 wdmaud - ok 15:33:38.0968 2752 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll 15:33:38.0968 2752 WebClient - ok 15:33:39.0000 2752 [ CF27EDAC75C87F2B776D9218F02F8301 ] winachsf C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys 15:33:39.0015 2752 winachsf - ok 15:33:39.0046 2752 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 15:33:39.0046 2752 winmgmt - ok 15:33:39.0078 2752 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll 15:33:39.0078 2752 WmdmPmSN - ok 15:33:39.0093 2752 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 15:33:39.0093 2752 WmiApSrv - ok 15:33:39.0140 2752 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe 15:33:39.0171 2752 WMPNetworkSvc - ok 15:33:39.0187 2752 [ CF4DEF1BF66F06964DC0D91844239104 ] WpdUsb C:\WINDOWS\system32\DRIVERS\wpdusb.sys 15:33:39.0187 2752 WpdUsb - ok 15:33:39.0218 2752 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll 15:33:39.0234 2752 wscsvc - ok 15:33:39.0265 2752 [ 77A3988CF9B5848BCBC9FB6A79508A56 ] WTouchService C:\Program Files\WTouch\WTouchService.exe 15:33:39.0265 2752 WTouchService - ok 15:33:39.0281 2752 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll 15:33:39.0296 2752 wuauserv - ok 15:33:39.0296 2752 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys 15:33:39.0296 2752 WudfPf - ok 15:33:39.0312 2752 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys 15:33:39.0312 2752 WudfRd - ok 15:33:39.0328 2752 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll 15:33:39.0328 2752 WudfSvc - ok 15:33:39.0343 2752 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 15:33:39.0359 2752 WZCSVC - ok 15:33:39.0375 2752 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 15:33:39.0390 2752 xmlprov - ok 15:33:39.0390 2752 ================ Scan global =============================== 15:33:39.0406 2752 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll 15:33:39.0437 2752 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll 15:33:39.0437 2752 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll 15:33:39.0468 2752 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe 15:33:39.0468 2752 [Global] - ok 15:33:39.0468 2752 ================ Scan MBR ================================== 15:33:39.0484 2752 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0 15:33:39.0765 2752 \Device\Harddisk0\DR0 - ok 15:33:39.0796 2752 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR3 15:33:39.0968 2752 \Device\Harddisk1\DR3 - ok 15:33:39.0968 2752 ================ Scan VBR ================================== 15:33:39.0968 2752 [ 3BA0F385E06E0AC9F25CAF6B002A7F59 ] \Device\Harddisk0\DR0\Partition1 15:33:39.0968 2752 \Device\Harddisk0\DR0\Partition1 - ok 15:33:40.0000 2752 [ CE1F1569DDD07F740E4D2EF207F52E81 ] \Device\Harddisk0\DR0\Partition2 15:33:40.0000 2752 \Device\Harddisk0\DR0\Partition2 - ok 15:33:40.0031 2752 [ A21379C3F5E9EB194556BDF74106B740 ] \Device\Harddisk1\DR3\Partition1 15:33:40.0031 2752 \Device\Harddisk1\DR3\Partition1 - ok 15:33:40.0031 2752 ============================================================ 15:33:40.0031 2752 Scan finished 15:33:40.0031 2752 ============================================================ 15:33:40.0031 0968 Detected object count: 0 15:33:40.0031 0968 Actual detected object count: 0 15:34:27.0328 2092 Deinitialize success
Hello, markoid.

Thank you for the logs. Please run the following scan.

Note: Before you begin, please read through these instructions completely, noting all important messages and warnings.
  • Please download ComboFix from HERE or HERE.
Very Important! Save ComboFix.exe to to your Desktop.
  • Close all browsers.
  • Disable your AntiVirus and AntiSpyware applications as they can interfere with running ComboFix. To disable any security programs:

  • Right click on the System Tray icon, or
  • Refer to this link HERE for further assistance.

  • Double click on ComboFix.exe and follow the prompts. ComboFix will automatically check to see if the Microsoft Windows Recovery Console is installed.

Note:

  • If Combofix asks you to install the Microsoft Windows Recovery Console, please allow it.
  • If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • When prompted, agree to the End-User License Agreement to begin installation.
  • If ComboFix asks you to update the program, please do so.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, ComboFix will produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Warnings:
  • Do not mouse-click on ComboFix's window while it is running. This may cause it to stall.
  • Do not re-run ComboFix. If problems occur with the installation or running of ComboFix, please reply back for further instructions.
  • Do not attempt to surf the internet while ComboFix is scanning.

Note: If there is no internet connection after running ComboFix, reboot your computer to restore the connection.

Very Important! Make sure you re-enable your security programs when ComboFix is finished.
Hello fbfbfb,
Done. Here is combofix log

ComboFix 13-03-26.01 - mark 04/04/2013 8:43.1.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1590 [GMT 11:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\mark\Application Data\DefaultTab\DefaultTab
c:\documents and settings\mark\Application Data\DefaultTab\DefaultTab\uninstalldt.exe
c:\documents and settings\mark\Application Data\WTouch
c:\documents and settings\mark\Application Data\WTouch\WTouch.xml
D:\install.exe
.
.
((((((((((((((((((((((((( Files Created from 2013-03-03 to 2013-04-03 )))))))))))))))))))))))))))))))
.
.
2013-03-28 23:50 . 2013-03-28 23:50 388096 —-a-r- c:\documents and settings\mark\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-03-28 23:17 . 2013-03-28 23:17 73432 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-28 23:17 . 2013-03-28 23:17 693976 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-28 11:40 . 2013-03-29 22:21 ——– d—–w- c:\documents and settings\mark\.FBReader
2013-03-28 11:16 . 2013-03-28 11:16 ——– d—–w- c:\program files\FBReader
2013-03-28 11:16 . 2013-03-28 11:16 ——– d—–w- c:\documents and settings\mark\Local Settings\Application Data\Smartbar
2013-03-28 11:15 . 2013-03-28 11:15 ——– d—–w- c:\program files\SingAlong
2013-03-09 21:46 . 2013-03-09 21:46 ——– d—–w- c:\documents and settings\All Users\Uniblue
2013-03-09 10:43 . 2013-03-09 10:43 ——– d—–w- c:\documents and settings\mark\Application Data\DDMSettings
2013-03-09 10:41 . 2013-03-09 10:43 ——– d—–w- c:\documents and settings\mark\Application Data\DivX
2013-03-09 08:46 . 2013-03-09 10:41 ——– d—–w- c:\program files\Common Files\DivX Shared
2013-03-09 08:34 . 2013-03-09 10:42 ——– d—–w- c:\program files\DivX
2013-03-09 08:33 . 2013-03-09 10:42 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX
2013-03-09 08:23 . 2013-03-09 09:01 ——– d—–w- c:\program files\VIO Player
2013-03-09 08:20 . 2013-04-03 21:47 ——– d—–w- c:\documents and settings\mark\Application Data\DefaultTab
2013-03-09 08:17 . 2013-03-09 08:17 ——– d—–w- c:\documents and settings\All Users\Application Data\APN
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-03 21:48 . 2010-01-01 05:59 16608 —-a-w- c:\windows\gdrv.sys
2012-07-19 00:06 . 2012-04-16 23:00 136672 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{6492E171-2427-4932-B414-33574A089F5E}]
2013-02-28 16:24 109568 —-a-w- c:\program files\SingAlong\singalng.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-09-19 455968]
"Browser Infrastructure Helper"="c:\documents and settings\mark\Local Settings\Application Data\Smartbar\Application\QuickShare.exe" [2013-02-10 13824]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-10 8429568]
"nwiz"="nwiz.exe" [2007-05-10 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-10 81920]
"GEST"="c:\program files\GIGABYTE\GEST\RUN.exe" [2007-12-14 236040]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-19 16844800]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-08-29 1966080]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-01-22 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-02-15 417792]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-11-19 2598520]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-03-22 74752]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2013-01-30 450560]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2013-02-13 1263952]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-1-1 113664]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\WS_FTP\\WS_FTP95.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Program Files\\FinalMediaPlayer\\FMPCheckForUpdates.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2009\\3dsmax.exe"=
"d:\\9eagle9\\EQuake3D.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Outlook Express\\msimn.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3306:TCP"= 3306:TCP:mysql
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [4/19/2012 5:50 AM 24896]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 3:48 AM 31952]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [9/7/2010 3:48 AM 250080]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [9/7/2010 3:49 AM 301920]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2/14/2012 5:53 AM 193288]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [5/26/2010 1:38 PM 4497704]
R2 WTouchService;WTouch Service;c:\program files\WTouch\WTouchService.exe [5/26/2010 1:38 PM 113448]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [12/23/2011 2:32 PM 142176]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilterx.sys [12/23/2011 2:32 PM 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [12/23/2011 2:32 PM 17232]
R3 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\GEST\GSvr.exe [1/1/2010 5:00 PM 47624]
R3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTWlanU.sys [11/22/2012 1:08 PM 915432]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\avgidsagent.exe [11/2/2012 3:51 AM 5174392]
S2 mi-raysat_3dsMax2009_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit;c:\program files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe [3/10/2008 12:04 AM 65536]
S3 Cdadmbupfvplend;Cdadmbupfvplend;c:\windows\system32\drivers\netbios.sys [4/14/2008 11:00 PM 34688]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys –> c:\windows\system32\DRIVERS\wg111v2.sys [?]
S4 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [8/25/2010 8:59 PM 29416]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-09-19 10:46 451872 -c–a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-04-03 c:\windows\Tasks\Final Media Player Update Checker.job
- c:\program files\FinalMediaPlayer\FMPCheckForUpdates.exe [2011-05-18 06:50]
.
2013-04-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-04-24 06:18]
.
2013-04-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-04-24 06:18]
.
2013-04-03 c:\windows\Tasks\Sing Along Update.job
- c:\program files\SingAlong\SingalngUpdater.exe [2013-02-28 16:24]
.
2013-04-03 c:\windows\Tasks\User_Feed_Synchronization-{7CF1AE61-4DD4-4FCE-B165-7885BCCE74C1}.job
- c:\windows\system32\msfeedssync.exe [2009-03-07 17:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://yahoo.com/
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ptec/defaults/su/*http://www.yahoo.com
IE: &Download with &DAP - c:\progra~1\DAP\dapextie.htm
IE: Download &all with DAP - c:\progra~1\DAP\dapextie2.htm
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
TCP: DhcpNameServer = 192.168.0.1
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
Name-Space Handler: HTTPS\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
DPF: {C53BDC3D-19A0-4062-BF34-0897A4E6A6A2} - hxxps://plugin.wildpockets.com/common/WildPocketsLoader-15079.cab
FF - ProfilePath - c:\documents and settings\mark\Application Data\Mozilla\Firefox\Profiles\0r02yzpl.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://au.search.yahoo.com/search?ei=UTF-8&fr=w3i&type=W3i_DS,157,0_0,Search,20130310,17023,0,53,0&p=
FF - ExtSQL: 2013-03-09 19:21; [removed]; c:\documents and settings\mark\Application Data\Mozilla\Firefox\Profiles\0r02yzpl.default\extensions\[removed]
FF - ExtSQL: 2013-03-09 21:41; {23fcfd51-4958-4f00-80a3-ae97e717ed8b}; c:\program files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF - ExtSQL: 2013-03-28 22:15; [removed]; c:\program files\SingAlong\FF
FF - ExtSQL: 2013-03-28 22:16; {1fcbcf80-4afa-4a9e-bcaf-892dee3334b8}; c:\documents and settings\mark\Application Data\Mozilla\Firefox\Profiles\0r02yzpl.default\extensions\{1fcbcf80-4afa-4a9e-bcaf-892dee3334b8}
FF - ExtSQL: !HIDDEN! 2010-01-16 11:34; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - user.js: extensions.autoDisableScopes - 0
FF - user.js: extensions.shownSelectionUI - true
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Veoh - c:\program files\Veoh Networks\Veoh\VeohClient.exe
HKLM-Run-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
HKLM-Run-Wondershare Helper Compact.exe - c:\program files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
AddRemove-DefaultTab - c:\documents and settings\mark\Application Data\DefaultTab\DefaultTab\uninstalldt.exe
AddRemove-V-Ray for 3dsmax 2009 for x86 - c:\program files\Chaos Group\V-Ray\3dsmax 2009 for x86\uninstall\wininstaller.exe-uninstall=c:\program files\Chaos Group\V-Ray\3dsmax 2009 for x86\uninstall\install.log
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-04 08:48
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2013-04-04 08:49:40
ComboFix-quarantined-files.txt 2013-04-03 21:49
.
Pre-Run: 2,546,118,656 bytes free
Post-Run: 4,185,477,120 bytes free
.
- - End Of File - - B38B576274151B951D8757526E22287E
I forgot to mention that downloading the files for recovery console failed, so the scan was done without it. I hope this doesn't matter but let me know if I need to let combofix try again to d/l those files again and repeat the procedure.. thanks The beeping sound has stopped now but I still have various words on webpages showing as links with a small popups when I mouseover.
Hello, markoid.

Before proceeding any further, let's take care of installing the Windows Recovery Console on your machine.

Please download and Install the Windows Recovery Console
  • With malware infections being as they are today, it's strongly recommended to have the Windows Recovery Console pre-installed on your machine before removing any malware.
  • The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.
  • Download the tools needed to a flash drive or other removable media, and transfer them to the infected computer.
  • Go to Microsoft's website HERE.
  • Scroll down to Step 1: Download the Setup disk program.
  • Click on Click here to show/hide solution.
  • Under Windows XP Service Pack 2 (SP2), select the download that's appropriate for your Operating System.

Note: You have SP3 but SP2 will work for you.

  • Download the file and save it as it's originally named to your flash drive or other removable media.
  • Transfer all of the downloaded files to the desktop of the infected computer.
  • Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.
  • Referring to the image below, drag the setup package onto the (renamed) ComboFix.exe icon and drop it.

[external image: Posted Image]

  • Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.

[external image: Posted Image]

  • At the next prompt, click Yes to run the full ComboFix scan.
  • When the tool is finished, it will produce a report for you.
Please post the C:\ComboFix.txt in your next reply.
Hi fbfbfb,
Thank you for your ongoing help with this.
Here is the new combofix log.

ComboFix 13-03-26.01 - mark 04/05/2013 9:27.2.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1531 [GMT 11:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\mark\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\mark\Application Data\WTouch
c:\documents and settings\mark\Application Data\WTouch\WTouch.xml
.
.
((((((((((((((((((((((((( Files Created from 2013-03-04 to 2013-04-04 )))))))))))))))))))))))))))))))
.
.
2013-03-28 23:50 . 2013-03-28 23:50 388096 —-a-r- c:\documents and settings\mark\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-03-28 23:17 . 2013-03-28 23:17 73432 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-28 23:17 . 2013-03-28 23:17 693976 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-28 11:40 . 2013-03-29 22:21 ——– d—–w- c:\documents and settings\mark\.FBReader
2013-03-28 11:16 . 2013-03-28 11:16 ——– d—–w- c:\program files\FBReader
2013-03-28 11:16 . 2013-03-28 11:16 ——– d—–w- c:\documents and settings\mark\Local Settings\Application Data\Smartbar
2013-03-28 11:15 . 2013-03-28 11:15 ——– d—–w- c:\program files\SingAlong
2013-03-09 21:46 . 2013-03-09 21:46 ——– d—–w- c:\documents and settings\All Users\Uniblue
2013-03-09 10:43 . 2013-03-09 10:43 ——– d—–w- c:\documents and settings\mark\Application Data\DDMSettings
2013-03-09 10:41 . 2013-03-09 10:43 ——– d—–w- c:\documents and settings\mark\Application Data\DivX
2013-03-09 08:46 . 2013-03-09 10:41 ——– d—–w- c:\program files\Common Files\DivX Shared
2013-03-09 08:34 . 2013-03-09 10:42 ——– d—–w- c:\program files\DivX
2013-03-09 08:33 . 2013-03-09 10:42 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX
2013-03-09 08:23 . 2013-03-09 09:01 ——– d—–w- c:\program files\VIO Player
2013-03-09 08:20 . 2013-04-03 21:47 ——– d—–w- c:\documents and settings\mark\Application Data\DefaultTab
2013-03-09 08:17 . 2013-03-09 08:17 ——– d—–w- c:\documents and settings\All Users\Application Data\APN
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-04 22:30 . 2010-01-01 05:59 16608 —-a-w- c:\windows\gdrv.sys
2012-07-19 00:06 . 2012-04-16 23:00 136672 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{6492E171-2427-4932-B414-33574A089F5E}]
2013-02-28 16:24 109568 —-a-w- c:\program files\SingAlong\singalng.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-09-19 455968]
"Browser Infrastructure Helper"="c:\documents and settings\mark\Local Settings\Application Data\Smartbar\Application\QuickShare.exe" [2013-02-10 13824]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-10 8429568]
"nwiz"="nwiz.exe" [2007-05-10 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-10 81920]
"GEST"="c:\program files\GIGABYTE\GEST\RUN.exe" [2007-12-14 236040]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-19 16844800]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-08-29 1966080]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-01-22 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-02-15 417792]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-11-19 2598520]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-03-22 74752]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2013-01-30 450560]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2013-02-13 1263952]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-1-1 113664]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\WS_FTP\\WS_FTP95.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Program Files\\FinalMediaPlayer\\FMPCheckForUpdates.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2009\\3dsmax.exe"=
"d:\\9eagle9\\EQuake3D.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Outlook Express\\msimn.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3306:TCP"= 3306:TCP:mysql
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [4/19/2012 5:50 AM 24896]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 3:48 AM 31952]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [9/7/2010 3:48 AM 250080]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [9/7/2010 3:49 AM 301920]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2/14/2012 5:53 AM 193288]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [5/26/2010 1:38 PM 4497704]
R2 WTouchService;WTouch Service;c:\program files\WTouch\WTouchService.exe [5/26/2010 1:38 PM 113448]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [12/23/2011 2:32 PM 142176]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilterx.sys [12/23/2011 2:32 PM 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [12/23/2011 2:32 PM 17232]
R3 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\GEST\GSvr.exe [1/1/2010 5:00 PM 47624]
R3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTWlanU.sys [11/22/2012 1:08 PM 915432]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\avgidsagent.exe [11/2/2012 3:51 AM 5174392]
S2 mi-raysat_3dsMax2009_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit;c:\program files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe [3/10/2008 12:04 AM 65536]
S3 Cdadmbupfvplend;Cdadmbupfvplend;c:\windows\system32\drivers\netbios.sys [4/14/2008 11:00 PM 34688]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys –> c:\windows\system32\DRIVERS\wg111v2.sys [?]
S4 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [8/25/2010 8:59 PM 29416]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-09-19 10:46 451872 -c–a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-04-04 c:\windows\Tasks\Final Media Player Update Checker.job
- c:\program files\FinalMediaPlayer\FMPCheckForUpdates.exe [2011-05-18 06:50]
.
2013-04-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-04-24 06:18]
.
2013-04-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-04-24 06:18]
.
2013-04-04 c:\windows\Tasks\Sing Along Update.job
- c:\program files\SingAlong\SingalngUpdater.exe [2013-02-28 16:24]
.
2013-04-04 c:\windows\Tasks\User_Feed_Synchronization-{7CF1AE61-4DD4-4FCE-B165-7885BCCE74C1}.job
- c:\windows\system32\msfeedssync.exe [2009-03-07 17:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://yahoo.com/
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ptec/defaults/su/*http://www.yahoo.com
IE: &Download with &DAP - c:\progra~1\DAP\dapextie.htm
IE: Download &all with DAP - c:\progra~1\DAP\dapextie2.htm
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
TCP: DhcpNameServer = 192.168.0.1
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
Name-Space Handler: HTTPS\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
DPF: {C53BDC3D-19A0-4062-BF34-0897A4E6A6A2} - hxxps://plugin.wildpockets.com/common/WildPocketsLoader-15079.cab
FF - ProfilePath - c:\documents and settings\mark\Application Data\Mozilla\Firefox\Profiles\0r02yzpl.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://au.search.yahoo.com/search?ei=UTF-8&fr=w3i&type=W3i_DS,157,0_0,Search,20130310,17023,0,53,0&p=
FF - ExtSQL: 2013-03-09 19:21; [removed]; c:\documents and settings\mark\Application Data\Mozilla\Firefox\Profiles\0r02yzpl.default\extensions\[removed]
FF - ExtSQL: 2013-03-09 21:41; {23fcfd51-4958-4f00-80a3-ae97e717ed8b}; c:\program files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF - ExtSQL: 2013-03-28 22:15; [removed]; c:\program files\SingAlong\FF
FF - ExtSQL: 2013-03-28 22:16; {1fcbcf80-4afa-4a9e-bcaf-892dee3334b8}; c:\documents and settings\mark\Application Data\Mozilla\Firefox\Profiles\0r02yzpl.default\extensions\{1fcbcf80-4afa-4a9e-bcaf-892dee3334b8}
FF - ExtSQL: !HIDDEN! 2010-01-16 11:34; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - user.js: extensions.autoDisableScopes - 0
FF - user.js: extensions.shownSelectionUI - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-05 09:30
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2013-04-05 09:32:07
ComboFix-quarantined-files.txt 2013-04-04 22:32
ComboFix2.txt 2013-04-03 21:49
.
Pre-Run: 4,114,104,320 bytes free
Post-Run: 4,109,615,104 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 6394A4D183B13E1DDAB423262FD037EF
Hello, markoid.

You're welcome, and thank you for the CF log. Glad you were able to install Recovery Console.

Please continue with the following tasks

1. Remove µTorrent

I see that you have µTorrent on your computer. µTorrent is a P2P (peer to peer) program. P2P programs are a major conduit for malicious software. Some P2P programs will expose your personal information to others by default. Some of the P2P programs themselves contain spyware and divulge your internet activities as well as use your computer's resources without your knowledge. Even if you are using a safe P2P program, downloaded files from uncertified sources are often infected. It is strongly recommend that you uninstall any P2P programs you have on your system. You can uninstall your P2P programs from the Programs list. Should you decide to keep the program, be aware that you will most likely be reinfected.

Please take the time to read through the following articles:

The Dangers of P2P File Sharing HERE
P2P Programs: Popular and Perilous by Robert P. Lipschutz and John Clyman HERE

2. Uninstall Programs

We need to uninstall: DefaultTab, InstallerQ Updater and Quickshare.
  • Click Start and select Control Panel.
  • When the Control Panel window opens, click on Uninstall a program found under the Programs category.
  • If you are using the Classic View of the Control Panel, then you would double-click on the Programs and Features icon instead.
  • Look through the list of programs, locate DefaultTab, and then left-click on it once to highlight it.
  • Click on the Uninstall button.
  • When asked if you are sure you want to uninstall, click Yes.
  • The program will uninstall, and when completed you will be back at the list of programs installed on your computer.
  • Repeat these steps to uninstall the other 2 programs.
  • When finished, close the Programs and Features screen.
3. Uninstall Toolbars from Internet Explorer/Firefox

If any of these programs (DefaultTab, Quickshare, or Smartbar Toolbar) still appear in your browser, continue as follows:

To remove from Internet Explorer
  • Open Internet Explorer.
  • Click Tools > Manage Add-ons.
  • In the Manage Add-ons window, under Add-on Types (found on left side) highlight Toolbars and Extensions.
  • Under the Show: drop-down menu (found on left side) make sure All add-ons is selected.
  • Highlight the programs/toolbar you wish to remove, and select Disable.
  • The Disable add-on window may pop up to warn you that related services and add-ons will also be disabled. Click Disable.
  • Click Close to dismiss the add-ons window.
To remove from FireFox
  • Open FireFox.
  • Click Tools > Add-ons.
  • In the Add-ons Manager tab, select the Extensions.
  • Select the toolbar you wish to remove.
  • Click Disable.
  • Click Restart now if it pops up. Your tabs will be saved and restored after the restart.
4. Reset Your Home Page and Default Search Engine

Removing toolbars during the clean-up process may have changed your browser settings (homepage, default search engines). If so, please follow the instructions found HERE.


Please run the following scan


Very Important!

Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix and can cause unpredictable results.

Please open Notepad:
  • Start > Run.
  • Type notepad in the Open field
  • Click OK.
  • Copy and paste the text inside the code box below:
ClearJavaCache::

File::
c:\documents and settings\mark\Local Settings\Application Data\Smartbar\Application\QuickShare.exe

Folder::
c:\documents and settings\mark\Local Settings\Application Data\Smartbar
c:\documents and settings\mark\Application Data\DefaultTab

Firefox::
FF - ProfilePath - c:\documents and settings\mark\Application Data\Mozilla\Firefox\Profiles\0r02yzpl.default\
FF - ExtSQL: 2013-03-09 19:21; [removed]; c:\documents and settings\mark\Application Data\Mozilla\Firefox\Profiles\0r02yzpl.default\extensions\[removed]

DDS::
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ptec/defaults/su/*http://www.yahoo.com

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Browser Infrastructure Helper"-
  • Save this as CFScript.txt to your desktop and change the "Save as type" to All Files.
  • Drag the CFScript.txt into ComboFix.exe as shown in the screenshot below:

[external image: Posted Image]

  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, ComboFix will produce a log for you. Copy and paste the contents of the log in your next reply.
WARNING
  • Do not mouse-click ComboFix's window while it is running. This may cause it to stall.
  • Do not attempt to surf the internet while ComboFix is scanning.
Very Important! Make sure you re-enable your security programs when ComboFix is finished.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI