Jump to content


 

Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with TR/ATRAPS.GEN


  • Please log in to reply
11 replies to this topic

#1 chipk1

chipk1

    New Member

  • Members
  • Pip
  • 8 posts

Posted 11 August 2012 - 07:17 AM

I need help please. I was duped by a fake Flash Player update. I am running Windows 7. Avira keeps popping up warnings about TR/ATRAPS.GEN and TR/ATRAPS.GEN2. I restarted in safe mode and did complete Avira scan and I found some stuff and quarantined it but still have the infection. Below is the Avira log:



Avira Free Antivirus
Report file date: Friday, August 10, 2012 20:40

Scanning for 4085665 virus strains and unwanted programs.

The program is running as an unrestricted full version.
Online services are available.

Licensee : Avira AntiVir Personal - Free Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows 7 Home Premium
Windows version : (Service Pack 1) [6.1.7601]
Boot mode : Safe mode
Username : Chip
Computer name : CHIPS-DESKTOP

Version information:
BUILD.DAT : 12.0.0.1167 40870 Bytes 7/18/2012 20:07:00
AVSCAN.EXE : 12.3.0.33 468472 Bytes 8/9/2012 00:44:30
AVSCAN.DLL : 12.3.0.15 54736 Bytes 5/2/2012 19:31:39
LUKE.DLL : 12.3.0.15 68304 Bytes 5/2/2012 05:31:47
AVSCPLR.DLL : 12.3.0.14 97032 Bytes 5/2/2012 04:13:36
AVREG.DLL : 12.3.0.17 232200 Bytes 5/14/2012 22:24:33
VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 00:18:34
VBASE001.VDF : 7.11.0.0 13342208 Bytes 12/14/2010 05:23:21
VBASE002.VDF : 7.11.19.170 14374912 Bytes 12/20/2011 05:32:24
VBASE003.VDF : 7.11.21.238 4472832 Bytes 2/1/2012 15:58:50
VBASE004.VDF : 7.11.26.44 4329472 Bytes 3/28/2012 16:43:53
VBASE005.VDF : 7.11.34.116 4034048 Bytes 6/29/2012 21:21:21
VBASE006.VDF : 7.11.34.117 2048 Bytes 6/29/2012 21:21:21
VBASE007.VDF : 7.11.34.118 2048 Bytes 6/29/2012 21:21:22
VBASE008.VDF : 7.11.34.119 2048 Bytes 6/29/2012 21:21:22
VBASE009.VDF : 7.11.34.120 2048 Bytes 6/29/2012 21:21:22
VBASE010.VDF : 7.11.34.121 2048 Bytes 6/29/2012 21:21:22
VBASE011.VDF : 7.11.34.122 2048 Bytes 6/29/2012 21:21:22
VBASE012.VDF : 7.11.34.123 2048 Bytes 6/29/2012 21:21:22
VBASE013.VDF : 7.11.34.124 2048 Bytes 6/29/2012 21:21:22
VBASE014.VDF : 7.11.38.18 2554880 Bytes 7/30/2012 00:43:48
VBASE015.VDF : 7.11.38.70 556032 Bytes 7/31/2012 00:43:40
VBASE016.VDF : 7.11.38.143 171008 Bytes 8/2/2012 00:43:49
VBASE017.VDF : 7.11.38.221 178176 Bytes 8/6/2012 00:44:04
VBASE018.VDF : 7.11.39.37 168448 Bytes 8/8/2012 00:44:19
VBASE019.VDF : 7.11.39.89 131072 Bytes 8/9/2012 00:44:15
VBASE020.VDF : 7.11.39.90 2048 Bytes 8/9/2012 00:44:15
VBASE021.VDF : 7.11.39.91 2048 Bytes 8/9/2012 00:44:15
VBASE022.VDF : 7.11.39.92 2048 Bytes 8/9/2012 00:44:15
VBASE023.VDF : 7.11.39.93 2048 Bytes 8/9/2012 00:44:16
VBASE024.VDF : 7.11.39.94 2048 Bytes 8/9/2012 00:44:16
VBASE025.VDF : 7.11.39.95 2048 Bytes 8/9/2012 00:44:16
VBASE026.VDF : 7.11.39.96 2048 Bytes 8/9/2012 00:44:16
VBASE027.VDF : 7.11.39.97 2048 Bytes 8/9/2012 00:44:16
VBASE028.VDF : 7.11.39.98 2048 Bytes 8/9/2012 00:44:17
VBASE029.VDF : 7.11.39.99 2048 Bytes 8/9/2012 00:44:17
VBASE030.VDF : 7.11.39.100 2048 Bytes 8/9/2012 00:44:17
VBASE031.VDF : 7.11.39.112 32256 Bytes 8/9/2012 00:44:17
Engine version : 8.2.10.132
AEVDF.DLL : 8.1.2.10 102772 Bytes 7/10/2012 21:22:18
AESCRIPT.DLL : 8.1.4.42 459129 Bytes 8/10/2012 00:44:23
AESCN.DLL : 8.1.8.2 131444 Bytes 2/16/2012 22:11:36
AESBX.DLL : 8.2.5.12 606578 Bytes 6/14/2012 21:21:16
AERDL.DLL : 8.1.9.15 639348 Bytes 1/21/2012 05:22:40
AEPACK.DLL : 8.3.0.24 811381 Bytes 8/8/2012 00:44:09
AEOFFICE.DLL : 8.1.2.42 201083 Bytes 7/19/2012 21:23:06
AEHEUR.DLL : 8.1.4.86 5165429 Bytes 8/10/2012 00:44:22
AEHELP.DLL : 8.1.23.2 258422 Bytes 6/28/2012 21:21:22
AEGEN.DLL : 8.1.5.34 434548 Bytes 7/19/2012 21:23:03
AEEXP.DLL : 8.1.0.74 86387 Bytes 8/4/2012 00:44:10
AEEMU.DLL : 8.1.3.2 393587 Bytes 7/10/2012 21:22:17
AECORE.DLL : 8.1.27.4 201078 Bytes 8/8/2012 00:44:08
AEBB.DLL : 8.1.1.0 53618 Bytes 1/21/2012 05:22:35
AVWINLL.DLL : 12.3.0.15 27344 Bytes 5/2/2012 04:59:21
AVPREF.DLL : 12.3.0.15 51920 Bytes 5/2/2012 04:44:31
AVREP.DLL : 12.3.0.15 179208 Bytes 5/2/2012 04:13:35
AVARKT.DLL : 12.3.0.15 211408 Bytes 5/2/2012 04:21:32
AVEVTLOG.DLL : 12.3.0.15 169168 Bytes 5/2/2012 04:28:49
SQLITE3.DLL : 3.7.0.1 398288 Bytes 4/17/2012 03:11:02
AVSMTP.DLL : 12.3.0.32 63480 Bytes 8/9/2012 00:44:30
NETNT.DLL : 12.3.0.15 17104 Bytes 5/2/2012 05:33:29
RCIMAGE.DLL : 12.3.0.31 4445944 Bytes 8/9/2012 00:44:17
RCTEXT.DLL : 12.3.0.31 97784 Bytes 8/9/2012 00:44:17

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: C:\Program Files\Avira\AntiVir Desktop\sysscan.avp
Logging.............................: default
Primary action......................: Interactive
Secondary action....................: Ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, E:, J:,
Process scan........................: on
Extended process scan...............: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: extended

Start of the scan: Friday, August 10, 2012 20:40

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
Master boot sector HD2
[INFO] No virus was found!
Master boot sector HD3
[INFO] No virus was found!
Master boot sector HD4
[INFO] No virus was found!
Master boot sector HD5
[INFO] No virus was found!
Master boot sector HD6
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'E:\'
[INFO] No virus was found!
Boot sector 'J:\'
[INFO] No virus was found!

Starting search for hidden objects.
The driver could not be initialized.

The scan of running processes will be started
Scan process 'avscan.exe' - '81' Module(s) have been scanned
Scan process 'avcenter.exe' - '116' Module(s) have been scanned
Scan process 'ctfmon.exe' - '19' Module(s) have been scanned
Scan process 'Explorer.EXE' - '167' Module(s) have been scanned
Scan process 'svchost.exe' - '28' Module(s) have been scanned
Scan process 'svchost.exe' - '49' Module(s) have been scanned
Scan process 'svchost.exe' - '26' Module(s) have been scanned
Scan process 'svchost.exe' - '24' Module(s) have been scanned
Scan process 'svchost.exe' - '30' Module(s) have been scanned
Scan process 'svchost.exe' - '51' Module(s) have been scanned
Scan process 'lsm.exe' - '16' Module(s) have been scanned
Scan process 'lsass.exe' - '67' Module(s) have been scanned
Scan process 'services.exe' - '31' Module(s) have been scanned
Scan process 'winlogon.exe' - '23' Module(s) have been scanned
Scan process 'csrss.exe' - '16' Module(s) have been scanned
Scan process 'wininit.exe' - '21' Module(s) have been scanned
Scan process 'csrss.exe' - '16' Module(s) have been scanned
Scan process 'smss.exe' - '2' Module(s) have been scanned

Starting to scan executable files (registry).
C:\Program Files\FreeDNS Update\uninst.exe
[WARNING] Invalid end of file
The registry was scanned ( '2449' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\android-sdk-windows\platforms\android-10\images\system.img
[WARNING] Invalid compressed data
C:\Program Files\DebugMode\Wax 2.0\uninst.exe
[WARNING] Invalid end of file
C:\Program Files\FreeDNS Update\uninst.exe
[WARNING] Invalid end of file
C:\Users\Chip\android-sdks\platforms\android-10\images\system.img
[WARNING] Invalid compressed data
C:\Users\Chip\AppData\Local\Temp\jar_cache3500652609893943515.tmp
[0] Archive type: ZIP
--> gkkracaqufbru/dqjssaajb.class
[DETECTION] Contains recognition pattern of the EXP/CVE-2010-0840.A.25 exploit
--> gkkracaqufbru/erasq.class
[DETECTION] Contains recognition pattern of the EXP/CVE-2010-0840.A.6 exploit
--> gkkracaqufbru/mwnbpvgwhyptwcabakrsbrq.class
[DETECTION] Contains recognition pattern of the EXP/CVE-2010-0840.A.45 exploit
--> gkkracaqufbru/nswcvrkfhtdrulqnhryjcfjr.class
[DETECTION] Contains recognition pattern of the EXP/2011-3544.CP exploit
--> gkkracaqufbru/qhknpkwuyfmjssaa.class
[DETECTION] Contains recognition pattern of the EXP/2011-3544.CQ exploit
--> gkkracaqufbru/qvtrcgwpvlbhvkrawrmgdb.class
[DETECTION] Contains recognition pattern of the EXP/CVE-2010-0840.A.3 exploit
--> gkkracaqufbru/vnmcwfjpluelhlewrvywytede.class
[DETECTION] Contains recognition pattern of the EXP/2011-3544.DK exploit
--> gkkracaqufbru/wqbvvn.class
[DETECTION] Contains recognition pattern of the EXP/CVE-2010-0840.A.37 exploit
C:\Users\Chip\AppData\Local\Temp\jar_cache7019246649383283283.tmp
[0] Archive type: ZIP
--> kewuhgpmcnwfw/jyvkawh.class
[DETECTION] Contains recognition pattern of the EXP/CVE20113544.BK exploit
--> kewuhgpmcnwfw/ppudlsbmpsjraswh.class
[DETECTION] Contains recognition pattern of the EXP/CVE20113544.BK.1 exploit
C:\Users\Chip\AppData\Local\Temp\IM_33C9.tmp\terms.7z
[WARNING] The archive header is damaged
C:\Users\Chip\AppData\Local\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\L\00000004.@
[DETECTION] Is the TR/ZAccess.H Trojan
C:\Users\Chip\AppData\Local\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\00000004.@
[DETECTION] Is the TR/ZAccess.H Trojan
C:\Users\Chip\AppData\Local\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\00000008.@
[DETECTION] Is the TR/Cutwail.jhg Trojan
C:\Users\Chip\AppData\Local\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\000000cb.@
[DETECTION] Is the TR/Sirefef.A.37 Trojan
C:\Users\Chip\AppData\Local\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\80000000.@
[DETECTION] Is the TR/ATRAPS.Gen Trojan
C:\Users\Chip\AppData\Local\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\80000032.@
[DETECTION] Is the TR/ATRAPS.Gen2 Trojan
C:\Users\Chip\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\3d30f927-4318d2cd
[0] Archive type: ZIP
--> json/Option.class
[DETECTION] Contains recognition pattern of the EXP/JAVA.Tequari.Gen exploit
--> json/Search.class
[DETECTION] Contains recognition pattern of the EXP/CVE-2010-0840 exploit
--> json/SP.class
[DETECTION] Contains recognition pattern of the EXP/Blacole.BE exploit
--> json/ThreadParser.class
[DETECTION] Contains recognition pattern of the EXP/Blacole.BF exploit
--> json/XSLT.class
[DETECTION] Contains recognition pattern of the EXP/2010-0840.FI exploit
C:\Users\Chip\Downloads\avira_free_antivirus_en.exe
[WARNING] The file is password protected
C:\Users\Chip\Downloads\gnucash-2.4.8-setup.exe
[WARNING] Invalid end of file
C:\Users\Chip\Downloads\Sony Vegas PRO 10.0c+Keygen(works with windows7) [ kk ]\Sony Vegas PRO 10.0c+Keygen(works with windows7) [ kk ].rar
[0] Archive type: RAR
--> x32\x32.rar
[1] Archive type: RAR
--> Keygen.exe
[DETECTION] Is the TR/Offend.6906603.1 Trojan
--> x64\x64.rar
[1] Archive type: RAR
--> Keygen.exe
[DETECTION] Is the TR/Offend.6906603.1 Trojan
C:\Windows\Installer\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\00000004.@
[DETECTION] Is the TR/ZAccess.H Trojan
C:\Windows\Installer\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\00000008.@
[DETECTION] Is the TR/Cutwail.jhg Trojan
C:\Windows\Installer\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\000000cb.@
[DETECTION] Is the TR/Sirefef.A.37 Trojan
C:\Windows\Installer\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\80000000.@
[DETECTION] Is the TR/ATRAPS.Gen Trojan
C:\Windows\Installer\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\80000032.@
[DETECTION] Is the TR/ATRAPS.Gen2 Trojan
Begin scan in 'E:\' <video>
Begin scan in 'J:\' <My Book>
J:\backup 11-22-11\Chip\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\3d30f927-4318d2cd
[0] Archive type: ZIP
--> json/Option.class
[DETECTION] Contains recognition pattern of the EXP/JAVA.Tequari.Gen exploit
--> json/Search.class
[DETECTION] Contains recognition pattern of the EXP/CVE-2010-0840 exploit
--> json/SP.class
[DETECTION] Contains recognition pattern of the EXP/Blacole.BE exploit
--> json/ThreadParser.class
[DETECTION] Contains recognition pattern of the EXP/Blacole.BF exploit
--> json/XSLT.class
[DETECTION] Contains recognition pattern of the EXP/2010-0840.FI exploit
J:\RECYCLER\S-1-5-21-247885549-1470356406-1262074541-1008\De2\EK040\EK040-08 - Gerry & The Pacemakers - How Do You Do It To Me.zip
[WARNING] Error no files to extract
J:\RECYCLER\S-1-5-21-247885549-1470356406-1262074541-1008\De2\EK040\EK040-11 - Black, Cilla - You're My World.zip
[WARNING] Invalid compressed data
J:\RECYCLER\S-1-5-21-247885549-1470356406-1262074541-1008\De2\EK041\EK041-06 - Moody Blues, The - Go Now.zip
[WARNING] Error no files to extract
J:\RECYCLER\S-1-5-21-247885549-1470356406-1262074541-1008\De2\EK041\EK041-08- Baldry, Long John - Let The Heartache Begin .zip
[WARNING] Invalid compressed data
J:\RECYCLER\S-1-5-21-247885549-1470356406-1262074541-1008\De2\EK041\EK041-14 - Troggs, The - With A Girl Like You.zip
[WARNING] Error no files to extract
J:\RECYCLER\S-1-5-21-247885549-1470356406-1262074541-1008\De2\EK042\EK042-02 - Fox, Samantha - Touch Me.zip
[WARNING] Invalid compressed data
J:\RECYCLER\S-1-5-21-247885549-1470356406-1262074541-1008\De2\EK042\EK042-04 - Lauper, Cyndi - Time After Time.zip
[WARNING] Error no files to extract
J:\RECYCLER\S-1-5-21-247885549-1470356406-1262074541-1008\De2\EK042\EK042-05 - Douglas, Carl - Kung Fu Fighting.zip
[WARNING] Invalid compressed data
J:\RECYCLER\S-1-5-21-247885549-1470356406-1262074541-1008\De2\ek047\ek047-02 - marley, bob - could you be loved.zip
[WARNING] Invalid compressed data
J:\RECYCLER\S-1-5-21-247885549-1470356406-1262074541-1008\De2\ek047\ek047-14 - staton, candi- young hearts run free.zip
[WARNING] Invalid compressed data
J:\RECYCLER\S-1-5-21-247885549-1470356406-1262074541-1008\De2\ek048\ek048-07 - go west - we close our eyes.zip
[WARNING] Invalid compressed data
J:\RECYCLER\S-1-5-21-247885549-1470356406-1262074541-1008\De2\ek049\ek049-01 - minute_your_gone,_the - richard,_cliff.zip
[WARNING] Error no files to extract
J:\RECYCLER\S-1-5-21-247885549-1470356406-1262074541-1008\De2\ek049\ek049-03 - it's_all_in_the_game - richard,_cliff.zip
[WARNING] Invalid compressed data
J:\RECYCLER\S-1-5-21-247885549-1470356406-1262074541-1008\De2\ek050\ek050-14 - francis, connie - carolina moon.zip
[WARNING] Error no files to extract
J:\RECYCLER\S-1-5-21-247885549-1470356406-1262074541-1008\De2\ek052\ek052-17 - fire_brigade - move,_the.zip
[WARNING] Error no files to extract
J:\RECYCLER\S-1-5-21-247885549-1470356406-1262074541-1008\De2\ek053\ek053-02 - beach boys, the - wouldn't it be nice.zip
[WARNING] Invalid compressed data

Beginning disinfection:
J:\backup 11-22-11\Chip\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\3d30f927-4318d2cd
[DETECTION] Contains recognition pattern of the EXP/2010-0840.FI exploit
[NOTE] The file was moved to the quarantine directory under the name '1f81935e.qua'.
C:\Windows\Installer\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\80000032.@
[DETECTION] Is the TR/ATRAPS.Gen2 Trojan
[NOTE] The file was moved to the quarantine directory under the name '79b9dcd1.qua'.
C:\Windows\Installer\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\80000000.@
[DETECTION] Is the TR/ATRAPS.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '3c3df1ef.qua'.
C:\Windows\Installer\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\000000cb.@
[DETECTION] Is the TR/Sirefef.A.37 Trojan
[NOTE] The file was moved to the quarantine directory under the name '4326c38e.qua'.
C:\Windows\Installer\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\00000008.@
[DETECTION] Is the TR/Cutwail.jhg Trojan
[NOTE] The file was moved to the quarantine directory under the name '0f9eefc4.qua'.
C:\Windows\Installer\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\00000004.@
[DETECTION] Is the TR/ZAccess.H Trojan
[NOTE] The file was moved to the quarantine directory under the name '7386af94.qua'.
C:\Users\Chip\Downloads\Sony Vegas PRO 10.0c+Keygen(works with windows7) [ kk ]\Sony Vegas PRO 10.0c+Keygen(works with windows7) [ kk ].rar
[DETECTION] Is the TR/Offend.6906603.1 Trojan
[NOTE] The file was moved to the quarantine directory under the name '5e1e8099.qua'.
C:\Users\Chip\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\3d30f927-4318d2cd
[DETECTION] Contains recognition pattern of the EXP/2010-0840.FI exploit
[NOTE] The file was moved to the quarantine directory under the name '47bbbb2f.qua'.
C:\Users\Chip\AppData\Local\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\80000032.@
[DETECTION] Is the TR/ATRAPS.Gen2 Trojan
[NOTE] The file was moved to the quarantine directory under the name '2be89753.qua'.
C:\Users\Chip\AppData\Local\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\80000000.@
[DETECTION] Is the TR/ATRAPS.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '5a51aec6.qua'.
C:\Users\Chip\AppData\Local\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\000000cb.@
[DETECTION] Is the TR/Sirefef.A.37 Trojan
[NOTE] The file was moved to the quarantine directory under the name '544b9e01.qua'.
C:\Users\Chip\AppData\Local\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\00000008.@
[DETECTION] Is the TR/Cutwail.jhg Trojan
[NOTE] The file was moved to the quarantine directory under the name '1162e743.qua'.
C:\Users\Chip\AppData\Local\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\00000004.@
[DETECTION] Is the TR/ZAccess.H Trojan
[NOTE] The file was moved to the quarantine directory under the name '1869e3e8.qua'.
C:\Users\Chip\AppData\Local\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\L\00000004.@
[DETECTION] Is the TR/ZAccess.H Trojan
[NOTE] The file was moved to the quarantine directory under the name '4028fa81.qua'.
C:\Users\Chip\AppData\Local\Temp\jar_cache7019246649383283283.tmp
[DETECTION] Contains recognition pattern of the EXP/CVE20113544.BK.1 exploit
[NOTE] The file was moved to the quarantine directory under the name '6c128302.qua'.
C:\Users\Chip\AppData\Local\Temp\jar_cache3500652609893943515.tmp
[DETECTION] Contains recognition pattern of the EXP/CVE-2010-0840.A.25 exploit
[NOTE] The file was moved to the quarantine directory under the name '52ece3d8.qua'.


End of the scan: Saturday, August 11, 2012 07:46
Used time: 3:40:06 Hour(s)

The scan has been done completely.

58665 Scanned directories
2886746 Files were scanned
38 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 Files were deleted
0 Viruses and unwanted programs were repaired
18 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
2886708 Files not concerned
25880 Archives were scanned
27 Warnings
18 Notes

Edited by chipk1, 11 August 2012 - 07:24 AM.


 

  • BC Ads
  • BleepingComputer.com

#2 narenxp

narenxp

    Forum Addict

  • BC Advisor
  • PipPipPipPipPipPip
  • 16,365 posts
  • Gender:Male
  • Location:India

Posted 11 August 2012 - 08:48 AM

Download

TDSSkiller

Launch it.Click on change parameters-Select TDLFS file system

Click on "Scan".Please post the LOG report(log file should be in your C drive)

Do not change the default options on scan results

Download

aswMBR

Launch it, allow it to download latest Avast! virus definitions
Click the "Scan" button to start scan.After scan finishes,click on Save log

Post the log results here

Download

ESET online scanner

Install it

Click on START,it should download the virus definitions
When scan gets completed,click on LIST of found threats

Export the list to desktop,copy the contents of the text file in your reply

#3 chipk1

chipk1

    New Member

  • Members
  • Pip
  • 8 posts

Posted 11 August 2012 - 05:14 PM

Here are the log files. Thanks


10:00:16.0451 5256 TDSS rootkit removing tool 2.7.48.0 Jul 24 2012 13:16:32
10:00:17.0098 5256 ============================================================
10:00:17.0098 5256 Current date / time: 2012/08/11 10:00:17.0098
10:00:17.0098 5256 SystemInfo:
10:00:17.0098 5256
10:00:17.0099 5256 OS Version: 6.1.7601 ServicePack: 1.0
10:00:17.0099 5256 Product type: Workstation
10:00:17.0099 5256 ComputerName: CHIPS-DESKTOP
10:00:17.0100 5256 UserName: Chip
10:00:17.0100 5256 Windows directory: C:\Windows
10:00:17.0100 5256 System windows directory: C:\Windows
10:00:17.0100 5256 Processor architecture: Intel x86
10:00:17.0100 5256 Number of processors: 2
10:00:17.0100 5256 Page size: 0x1000
10:00:17.0100 5256 Boot type: Normal boot
10:00:17.0100 5256 ============================================================
10:00:18.0344 5256 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xFC59, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000050
10:00:18.0344 5256 Drive \Device\Harddisk1\DR1 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
10:00:18.0349 5256 Drive \Device\Harddisk2\DR2 - Size: 0xE8B6F00000 (930.86 Gb), SectorSize: 0x200, Cylinders: 0x1DAAB, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
10:00:18.0914 5256 ============================================================
10:00:18.0914 5256 \Device\Harddisk0\DR0:
10:00:18.0914 5256 MBR partitions:
10:00:18.0914 5256 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
10:00:18.0914 5256 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x3A353000
10:00:18.0914 5256 \Device\Harddisk1\DR1:
10:00:18.0914 5256 MBR partitions:
10:00:18.0914 5256 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x1D1C4800
10:00:18.0914 5256 \Device\Harddisk2\DR2:
10:00:18.0915 5256 MBR partitions:
10:00:18.0915 5256 \Device\Harddisk2\DR2\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x745B7000
10:00:18.0915 5256 ============================================================
10:00:18.0967 5256 C: <-> \Device\Harddisk0\DR0\Partition1
10:00:18.0993 5256 J: <-> \Device\Harddisk2\DR2\Partition0
10:00:18.0994 5256 E: <-> \Device\Harddisk1\DR1\Partition0
10:00:19.0022 5256 ============================================================
10:00:19.0022 5256 Initialize success
10:00:19.0022 5256 ============================================================
10:00:51.0161 4892 ============================================================
10:00:51.0161 4892 Scan started
10:00:51.0161 4892 Mode: Manual; TDLFS;
10:00:51.0161 4892 ============================================================
10:00:52.0476 4892 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
10:00:52.0490 4892 1394ohci - ok
10:00:52.0585 4892 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
10:00:52.0603 4892 ACPI - ok
10:00:52.0654 4892 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
10:00:52.0656 4892 AcpiPmi - ok
10:00:52.0744 4892 adfs (73685e15ef8b0bd9c30f1af413f13d49) C:\Windows\system32\drivers\adfs.sys
10:00:52.0749 4892 adfs - ok
10:00:52.0907 4892 AdobeARMservice (11a52cf7b265631deeb24c6149309eff) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
10:00:52.0908 4892 AdobeARMservice - ok
10:00:53.0215 4892 AdobeFlashPlayerUpdateSvc (f19c98ad81d2c0e1bbfd8153d2c80ee8) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
10:00:53.0227 4892 AdobeFlashPlayerUpdateSvc - ok
10:00:53.0491 4892 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
10:00:53.0512 4892 adp94xx - ok
10:00:53.0558 4892 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
10:00:53.0571 4892 adpahci - ok
10:00:53.0596 4892 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
10:00:53.0609 4892 adpu320 - ok
10:00:53.0640 4892 AeLookupSvc (8b5eefeec1e6d1a72a06c526628ad161) C:\Windows\System32\aelupsvc.dll
10:00:53.0643 4892 AeLookupSvc - ok
10:00:53.0708 4892 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys
10:00:53.0731 4892 AFD - ok
10:00:53.0840 4892 AgereSoftModem (7e10e3bb9b258ad8a9300f91214d67b9) C:\Windows\system32\DRIVERS\AGRSM.sys
10:00:53.0895 4892 AgereSoftModem - ok
10:00:53.0911 4892 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
10:00:53.0914 4892 agp440 - ok
10:00:53.0944 4892 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
10:00:53.0948 4892 aic78xx - ok
10:00:53.0976 4892 ALG (18a54e132947cd98fea9accc57f98f13) C:\Windows\System32\alg.exe
10:00:53.0980 4892 ALG - ok
10:00:53.0999 4892 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
10:00:54.0000 4892 aliide - ok
10:00:54.0036 4892 amacpi (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\DRIVERS\null.sys
10:00:54.0038 4892 amacpi - ok
10:00:54.0055 4892 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
10:00:54.0058 4892 amdagp - ok
10:00:54.0079 4892 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
10:00:54.0080 4892 amdide - ok
10:00:54.0101 4892 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
10:00:54.0103 4892 AmdK8 - ok
10:00:54.0121 4892 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
10:00:54.0125 4892 AmdPPM - ok
10:00:54.0167 4892 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys
10:00:54.0181 4892 amdsata - ok
10:00:54.0204 4892 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
10:00:54.0214 4892 amdsbs - ok
10:00:54.0224 4892 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys
10:00:54.0226 4892 amdxata - ok
10:00:54.0333 4892 AntiVirSchedulerService (0a1cc583e8147004e4ad4625d7fbf88c) C:\Program Files\Avira\AntiVir Desktop\sched.exe
10:00:54.0335 4892 AntiVirSchedulerService - ok
10:00:54.0390 4892 AntiVirService (c9a36ef935aced86aedf93e97e606911) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
10:00:54.0391 4892 AntiVirService - ok
10:00:54.0432 4892 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
10:00:54.0439 4892 AppID - ok
10:00:54.0466 4892 AppIDSvc (62a9c86cb6085e20db4823e4e97826f5) C:\Windows\System32\appidsvc.dll
10:00:54.0471 4892 AppIDSvc - ok
10:00:54.0500 4892 Appinfo (fb1959012294d6ad43e5304df65e3c26) C:\Windows\System32\appinfo.dll
10:00:54.0505 4892 Appinfo - ok
10:00:54.0611 4892 Apple Mobile Device (3debbecf665dcdde3a95d9b902010817) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
10:00:54.0613 4892 Apple Mobile Device - ok
10:00:54.0653 4892 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
10:00:54.0666 4892 arc - ok
10:00:54.0690 4892 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
10:00:54.0702 4892 arcsas - ok
10:00:54.0807 4892 aspnet_state (776acefa0ca9df0faa51a5fb2f435705) C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
10:00:54.0810 4892 aspnet_state - ok
10:00:54.0831 4892 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
10:00:54.0833 4892 AsyncMac - ok
10:00:54.0866 4892 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
10:00:54.0871 4892 atapi - ok
10:00:54.0943 4892 AudioEndpointBuilder (ce3b4e731638d2ef62fcb419be0d39f0) C:\Windows\System32\Audiosrv.dll
10:00:54.0973 4892 AudioEndpointBuilder - ok
10:00:54.0987 4892 Audiosrv (ce3b4e731638d2ef62fcb419be0d39f0) C:\Windows\System32\Audiosrv.dll
10:00:54.0995 4892 Audiosrv - ok
10:00:55.0048 4892 avgntflt (d5541f0afb767e85fc412fc609d96a74) C:\Windows\system32\DRIVERS\avgntflt.sys
10:00:55.0061 4892 avgntflt - ok
10:00:55.0102 4892 avipbb (7d967a682d4694df7fa57d63a2db01fe) C:\Windows\system32\DRIVERS\avipbb.sys
10:00:55.0114 4892 avipbb - ok
10:00:55.0132 4892 avkmgr (53e56450da16a1a7f0d002f511113f67) C:\Windows\system32\DRIVERS\avkmgr.sys
10:00:55.0136 4892 avkmgr - ok
10:00:55.0179 4892 AxInstSV (6e30d02aac9cac84f421622e3a2f6178) C:\Windows\System32\AxInstSV.dll
10:00:55.0193 4892 AxInstSV - ok
10:00:55.0266 4892 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
10:00:55.0292 4892 b06bdrv - ok
10:00:55.0329 4892 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
10:00:55.0340 4892 b57nd60x - ok
10:00:55.0371 4892 BDESVC (ee1e9c3bb8228ae423dd38db69128e71) C:\Windows\System32\bdesvc.dll
10:00:55.0384 4892 BDESVC - ok
10:00:55.0397 4892 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
10:00:55.0399 4892 Beep - ok
10:00:55.0421 4892 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
10:00:55.0424 4892 blbdrive - ok
10:00:55.0536 4892 Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe
10:00:55.0547 4892 Bonjour Service - ok
10:00:55.0681 4892 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
10:00:55.0689 4892 bowser - ok
10:00:55.0743 4892 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
10:00:55.0745 4892 BrFiltLo - ok
10:00:55.0797 4892 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
10:00:55.0803 4892 BrFiltUp - ok
10:00:55.0853 4892 Browser (6e11f33d14d020f58d5e02e4d67dfa19) C:\Windows\System32\browser.dll
10:00:55.0859 4892 Browser - ok
10:00:55.0910 4892 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
10:00:55.0935 4892 Brserid - ok
10:00:55.0964 4892 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
10:00:55.0968 4892 BrSerWdm - ok
10:00:55.0987 4892 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
10:00:55.0990 4892 BrUsbMdm - ok
10:00:56.0005 4892 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
10:00:56.0008 4892 BrUsbSer - ok
10:00:56.0032 4892 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
10:00:56.0038 4892 BTHMODEM - ok
10:00:56.0079 4892 bthserv (1df19c96eef6c29d1c3e1a8678e07190) C:\Windows\system32\bthserv.dll
10:00:56.0093 4892 bthserv - ok
10:00:56.0132 4892 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
10:00:56.0139 4892 cdfs - ok
10:00:56.0177 4892 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\DRIVERS\cdrom.sys
10:00:56.0191 4892 cdrom - ok
10:00:56.0248 4892 CertPropSvc (319c6b309773d063541d01df8ac6f55f) C:\Windows\System32\certprop.dll
10:00:56.0252 4892 CertPropSvc - ok
10:00:56.0270 4892 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
10:00:56.0274 4892 circlass - ok
10:00:56.0310 4892 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
10:00:56.0321 4892 CLFS - ok
10:00:56.0377 4892 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
10:00:56.0384 4892 clr_optimization_v2.0.50727_32 - ok
10:00:56.0585 4892 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
10:00:56.0592 4892 clr_optimization_v4.0.30319_32 - ok
10:00:56.0617 4892 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
10:00:56.0619 4892 CmBatt - ok
10:00:56.0989 4892 cmdAgent (d95bc532839d710bf6eb3f5e32314b3e) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
10:00:57.0067 4892 cmdAgent - ok
10:00:57.0332 4892 cmdGuard (544747035c7fa83d9e9d0a13f6e58bc4) C:\Windows\system32\DRIVERS\cmdguard.sys
10:00:57.0353 4892 cmdGuard - ok
10:00:57.0380 4892 cmdHlp (7faba2d3b4912b8762d1fec63ad12525) C:\Windows\system32\DRIVERS\cmdhlp.sys
10:00:57.0383 4892 cmdHlp - ok
10:00:57.0408 4892 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
10:00:57.0409 4892 cmdide - ok
10:00:57.0667 4892 CNG (247b4ce2dab1160cd422d532d5241e1f) C:\Windows\system32\Drivers\cng.sys
10:00:57.0709 4892 CNG - ok
10:00:57.0733 4892 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
10:00:57.0735 4892 Compbatt - ok
10:00:57.0790 4892 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
10:00:57.0792 4892 CompositeBus - ok
10:00:57.0818 4892 COMSysApp - ok
10:00:57.0885 4892 cpuz135 - ok
10:00:57.0905 4892 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
10:00:57.0907 4892 crcdisk - ok
10:00:58.0165 4892 CryptSvc (06e771aa596b8761107ab57e99f128d7) C:\Windows\system32\cryptsvc.dll
10:00:58.0171 4892 CryptSvc - ok
10:00:58.0519 4892 DcomLaunch (7660f01d3b38aca1747e397d21d790af) C:\Windows\system32\rpcss.dll
10:00:58.0543 4892 DcomLaunch - ok
10:00:58.0625 4892 defragsvc (8d6e10a2d9a5eed59562d9b82cf804e1) C:\Windows\System32\defragsvc.dll
10:00:58.0639 4892 defragsvc - ok
10:00:58.0707 4892 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
10:00:58.0718 4892 DfsC - ok
10:00:58.0807 4892 Dhcp (e9e01eb683c132f7fa27cd607b8a2b63) C:\Windows\system32\dhcpcore.dll
10:00:58.0828 4892 Dhcp - ok
10:00:58.0855 4892 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
10:00:58.0858 4892 discache - ok
10:00:58.0916 4892 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
10:00:58.0919 4892 Disk - ok
10:00:59.0024 4892 Dnscache (33ef4861f19a0736b11314aad9ae28d0) C:\Windows\System32\dnsrslvr.dll
10:00:59.0035 4892 Dnscache - ok
10:00:59.0086 4892 dot3svc (366ba8fb4b7bb7435e3b9eacb3843f67) C:\Windows\System32\dot3svc.dll
10:00:59.0104 4892 dot3svc - ok
10:00:59.0147 4892 DPS (8ec04ca86f1d68da9e11952eb85973d6) C:\Windows\system32\dps.dll
10:00:59.0155 4892 DPS - ok
10:00:59.0179 4892 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
10:00:59.0181 4892 drmkaud - ok
10:00:59.0269 4892 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
10:00:59.0305 4892 DXGKrnl - ok
10:00:59.0332 4892 EapHost (8600142fa91c1b96367d3300ad0f3f3a) C:\Windows\System32\eapsvc.dll
10:00:59.0345 4892 EapHost - ok
10:00:59.0606 4892 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
10:00:59.0740 4892 ebdrv - ok
10:00:59.0849 4892 EFS (81951f51e318aecc2d68559e47485cc4) C:\Windows\System32\lsass.exe
10:00:59.0851 4892 EFS - ok
10:00:59.0960 4892 ehRecvr (a8c362018efc87beb013ee28f29c0863) C:\Windows\ehome\ehRecvr.exe
10:00:59.0977 4892 ehRecvr - ok
10:00:59.0999 4892 ehSched (d389bff34f80caede417bf9d1507996a) C:\Windows\ehome\ehsched.exe
10:01:00.0000 4892 ehSched - ok
10:01:00.0052 4892 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
10:01:00.0080 4892 elxstor - ok
10:01:00.0098 4892 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
10:01:00.0099 4892 ErrDev - ok
10:01:00.0153 4892 EventSystem (f6916efc29d9953d5d0df06882ae8e16) C:\Windows\system32\es.dll
10:01:00.0166 4892 EventSystem - ok
10:01:00.0190 4892 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
10:01:00.0202 4892 exfat - ok
10:01:00.0223 4892 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
10:01:00.0234 4892 fastfat - ok
10:01:00.0312 4892 Fax (967ea5b213e9984cbe270205df37755b) C:\Windows\system32\fxssvc.exe
10:01:00.0334 4892 Fax - ok
10:01:00.0357 4892 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
10:01:00.0360 4892 fdc - ok
10:01:00.0371 4892 fdPHost (f3222c893bd2f5821a0179e5c71e88fb) C:\Windows\system32\fdPHost.dll
10:01:00.0375 4892 fdPHost - ok
10:01:00.0390 4892 FDResPub (7dbe8cbfe79efbdeb98c9fb08d3a9a5b) C:\Windows\system32\fdrespub.dll
10:01:00.0393 4892 FDResPub - ok
10:01:00.0408 4892 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
10:01:00.0412 4892 FileInfo - ok
10:01:00.0426 4892 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
10:01:00.0428 4892 Filetrace - ok
10:01:00.0709 4892 FLEXnet Licensing Service (1f63900e2eb00101b9aca2b7a870704e) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
10:01:00.0750 4892 FLEXnet Licensing Service - ok
10:01:00.0767 4892 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
10:01:00.0769 4892 flpydisk - ok
10:01:00.0801 4892 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
10:01:00.0820 4892 FltMgr - ok
10:01:00.0919 4892 FontCache (b3a5ec6b6b6673db7e87c2bcdbddc074) C:\Windows\system32\FntCache.dll
10:01:00.0967 4892 FontCache - ok
10:01:01.0011 4892 FontCache3.0.0.0 (e56f39f6b7fda0ac77a79b0fd3de1a2f) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
10:01:01.0013 4892 FontCache3.0.0.0 - ok
10:01:01.0036 4892 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
10:01:01.0040 4892 FsDepends - ok
10:01:01.0077 4892 Fs_Rec (7dae5ebcc80e45d3253f4923dc424d05) C:\Windows\system32\drivers\Fs_Rec.sys
10:01:01.0079 4892 Fs_Rec - ok
10:01:01.0150 4892 Futuremark SystemInfo Service (a33bcf3fab19db7d0b501036722f311b) C:\Program Files\Futuremark\Futuremark SystemInfo\FMSISvc.exe
10:01:01.0162 4892 Futuremark SystemInfo Service - ok
10:01:01.0212 4892 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
10:01:01.0231 4892 fvevol - ok
10:01:01.0260 4892 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
10:01:01.0266 4892 gagp30kx - ok
10:01:01.0303 4892 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
10:01:01.0307 4892 GEARAspiWDM - ok
10:01:01.0382 4892 gpsvc (e897eaf5ed6ba41e081060c9b447a673) C:\Windows\System32\gpsvc.dll
10:01:01.0415 4892 gpsvc - ok
10:01:01.0557 4892 HauppaugeTVServer (19fee61c78b50d70ba8900150d2a3a8a) C:\PROGRA~1\WinTV\HCWTVS~1.EXE
10:01:01.0606 4892 HauppaugeTVServer - ok
10:01:01.0749 4892 hcwPP2 (9436fbf3ca45a0fb726856b409734d7a) C:\Windows\system32\DRIVERS\hcwPP2.sys
10:01:01.0758 4892 hcwPP2 - ok
10:01:01.0814 4892 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys
10:01:01.0837 4892 HdAudAddService - ok
10:01:01.0876 4892 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys
10:01:01.0881 4892 HDAudBus - ok
10:01:01.0901 4892 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
10:01:01.0904 4892 HidBatt - ok
10:01:01.0928 4892 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
10:01:01.0941 4892 HidBth - ok
10:01:01.0957 4892 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
10:01:01.0960 4892 HidIr - ok
10:01:01.0988 4892 hidserv (2bc6f6a1992b3a77f5f41432ca6b3b6b) C:\Windows\system32\hidserv.dll
10:01:01.0993 4892 hidserv - ok
10:01:02.0021 4892 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys
10:01:02.0024 4892 HidUsb - ok
10:01:02.0063 4892 hkmsvc (196b4e3f4cccc24af836ce58facbb699) C:\Windows\system32\kmsvc.dll
10:01:02.0078 4892 hkmsvc - ok
10:01:02.0149 4892 HomeGroupListener (6658f4404de03d75fe3ba09f7aba6a30) C:\Windows\system32\ListSvc.dll
10:01:02.0171 4892 HomeGroupListener - ok
10:01:02.0222 4892 HomeGroupProvider (dbc02d918fff1cad628acbe0c0eaa8e8) C:\Windows\system32\provsvc.dll
10:01:02.0232 4892 HomeGroupProvider - ok
10:01:02.0259 4892 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
10:01:02.0264 4892 HpSAMD - ok
10:01:02.0342 4892 HTCAND32 (950cc1e6ae3a6cd23e0945cde089b02c) C:\Windows\system32\Drivers\ANDROIDUSB.sys
10:01:02.0345 4892 HTCAND32 - ok
10:01:02.0393 4892 htcnprot (339adefad60353f960e3ca67ce468c24) C:\Windows\system32\DRIVERS\htcnprot.sys
10:01:02.0396 4892 htcnprot - ok
10:01:02.0600 4892 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
10:01:02.0632 4892 HTTP - ok
10:01:02.0664 4892 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
10:01:02.0666 4892 hwpolicy - ok
10:01:02.0724 4892 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
10:01:02.0737 4892 i8042prt - ok
10:01:03.0140 4892 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys
10:01:03.0166 4892 iaStorV - ok
10:01:03.0313 4892 IDriverT (1cf03c69b49acb70c722df92755c0c8c) C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
10:01:03.0317 4892 IDriverT - ok
10:01:03.0663 4892 idsvc (c521d7eb6497bb1af6afa89e322fb43c) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
10:01:03.0727 4892 idsvc - ok
10:01:03.0951 4892 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
10:01:03.0954 4892 iirsp - ok
10:01:04.0165 4892 IKEEXT (f95622f161474511b8d80d6b093aa610) C:\Windows\System32\ikeext.dll
10:01:04.0263 4892 IKEEXT - ok
10:01:04.0315 4892 inspect (aa686b40a4f837bc66ad3183b2bbd981) C:\Windows\system32\DRIVERS\inspect.sys
10:01:04.0319 4892 inspect - ok
10:01:04.0653 4892 IntcAzAudAddService (516e2292f266c2f30089b5479c355858) C:\Windows\system32\drivers\RTKVHDA.sys
10:01:04.0813 4892 IntcAzAudAddService - ok
10:01:04.0932 4892 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
10:01:04.0935 4892 intelide - ok
10:01:04.0970 4892 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
10:01:04.0974 4892 intelppm - ok
10:01:05.0026 4892 IPBusEnum (acb364b9075a45c0736e5c47be5cae19) C:\Windows\system32\ipbusenum.dll
10:01:05.0040 4892 IPBusEnum - ok
10:01:05.0054 4892 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
10:01:05.0068 4892 IpFilterDriver - ok
10:01:05.0088 4892 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
10:01:05.0094 4892 IPMIDRV - ok
10:01:05.0113 4892 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
10:01:05.0125 4892 IPNAT - ok
10:01:05.0220 4892 iPod Service (49918803b661367023bf325cf602afdc) C:\Program Files\iPod\bin\iPodService.exe
10:01:05.0236 4892 iPod Service - ok
10:01:05.0284 4892 iPodDrv - ok
10:01:05.0311 4892 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
10:01:05.0313 4892 IRENUM - ok
10:01:05.0349 4892 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
10:01:05.0354 4892 isapnp - ok
10:01:05.0522 4892 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
10:01:05.0539 4892 iScsiPrt - ok
10:01:05.0584 4892 ISODisk (96f2f5884d02535e2d4dfc849836f4a6) C:\Windows\system32\drivers\ISODisk.sys
10:01:05.0594 4892 ISODisk - ok
10:01:05.0654 4892 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
10:01:05.0662 4892 kbdclass - ok
10:01:05.0688 4892 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\DRIVERS\kbdhid.sys
10:01:05.0691 4892 kbdhid - ok
10:01:05.0726 4892 KeyIso (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
10:01:05.0729 4892 KeyIso - ok
10:01:05.0765 4892 KSecDD (b7895b4182c0d16f6efadeb8081e8d36) C:\Windows\system32\Drivers\ksecdd.sys
10:01:05.0770 4892 KSecDD - ok
10:01:05.0799 4892 KSecPkg (d30159ac9237519fbc62c6ec247d2d46) C:\Windows\system32\Drivers\ksecpkg.sys
10:01:05.0811 4892 KSecPkg - ok
10:01:05.0856 4892 KtmRm (89a7b9cc98d0d80c6f31b91c0a310fcd) C:\Windows\system32\msdtckrm.dll
10:01:05.0878 4892 KtmRm - ok
10:01:05.0922 4892 LanmanServer (d64af876d53eca3668bb97b51b4e70ab) C:\Windows\system32\srvsvc.dll
10:01:05.0943 4892 LanmanServer - ok
10:01:05.0977 4892 LanmanWorkstation (58405e4f68ba8e4057c6e914f326aba2) C:\Windows\System32\wkssvc.dll
10:01:05.0989 4892 LanmanWorkstation - ok
10:01:06.0039 4892 Lavasoft Kernexplorer - ok
10:01:06.0095 4892 LHidFilt (7f9c7b28cf1c859e1c42619eea946dc8) C:\Windows\system32\DRIVERS\LHidFilt.Sys
10:01:06.0099 4892 LHidFilt - ok
10:01:06.0137 4892 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
10:01:06.0141 4892 lltdio - ok
10:01:06.0182 4892 lltdsvc (5700673e13a2117fa3b9020c852c01e2) C:\Windows\System32\lltdsvc.dll
10:01:06.0215 4892 lltdsvc - ok
10:01:06.0232 4892 lmhosts (55ca01ba19d0006c8f2639b6c045e08b) C:\Windows\System32\lmhsvc.dll
10:01:06.0236 4892 lmhosts - ok
10:01:06.0261 4892 LMouFilt (ab33792a87285344f43b5ce23421bab0) C:\Windows\system32\DRIVERS\LMouFilt.Sys
10:01:06.0264 4892 LMouFilt - ok
10:01:06.0312 4892 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
10:01:06.0323 4892 LSI_FC - ok
10:01:06.0348 4892 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
10:01:06.0360 4892 LSI_SAS - ok
10:01:06.0380 4892 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
10:01:06.0385 4892 LSI_SAS2 - ok
10:01:06.0413 4892 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
10:01:06.0424 4892 LSI_SCSI - ok
10:01:06.0450 4892 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
10:01:06.0456 4892 luafv - ok
10:01:06.0485 4892 LUsbFilt (77030525cd86a93f1af34fa9b96d33ce) C:\Windows\system32\Drivers\LUsbFilt.Sys
10:01:06.0488 4892 LUsbFilt - ok
10:01:06.0529 4892 mcdbus (8fd868e32459ece2a1bb0169f513d31e) C:\Windows\system32\DRIVERS\mcdbus.sys
10:01:06.0542 4892 mcdbus - ok
10:01:06.0601 4892 Mcx2Svc (bfb9ee8ee977efe85d1a3105abef6dd1) C:\Windows\system32\Mcx2Svc.dll
10:01:06.0616 4892 Mcx2Svc - ok
10:01:06.0636 4892 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
10:01:06.0642 4892 megasas - ok
10:01:06.0676 4892 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
10:01:06.0692 4892 MegaSR - ok
10:01:06.0779 4892 Microsoft Office Groove Audit Service (fafe367d032ed82e9332b4c741a20216) C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
10:01:06.0785 4892 Microsoft Office Groove Audit Service - ok
10:01:06.0816 4892 MMCSS (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll
10:01:06.0821 4892 MMCSS - ok
10:01:06.0838 4892 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
10:01:06.0839 4892 Modem - ok
10:01:06.0854 4892 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
10:01:06.0855 4892 monitor - ok
10:01:06.0895 4892 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
10:01:06.0899 4892 mouclass - ok
10:01:06.0917 4892 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
10:01:06.0920 4892 mouhid - ok
10:01:06.0975 4892 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
10:01:06.0989 4892 mountmgr - ok
10:01:07.0039 4892 MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
10:01:07.0050 4892 MozillaMaintenance - ok
10:01:07.0106 4892 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
10:01:07.0114 4892 mpio - ok
10:01:07.0129 4892 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
10:01:07.0135 4892 mpsdrv - ok
10:01:07.0169 4892 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
10:01:07.0182 4892 MRxDAV - ok
10:01:07.0227 4892 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
10:01:07.0236 4892 mrxsmb - ok
10:01:07.0287 4892 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
10:01:07.0304 4892 mrxsmb10 - ok
10:01:07.0332 4892 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
10:01:07.0344 4892 mrxsmb20 - ok
10:01:07.0355 4892 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
10:01:07.0358 4892 msahci - ok
10:01:07.0383 4892 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
10:01:07.0396 4892 msdsm - ok
10:01:07.0428 4892 MSDTC (e1bce74a3bd9902b72599c0192a07e27) C:\Windows\System32\msdtc.exe
10:01:07.0439 4892 MSDTC - ok
10:01:07.0479 4892 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
10:01:07.0481 4892 Msfs - ok
10:01:07.0500 4892 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
10:01:07.0501 4892 mshidkmdf - ok
10:01:07.0530 4892 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
10:01:07.0532 4892 msisadrv - ok
10:01:07.0573 4892 MSiSCSI (90f7d9e6b6f27e1a707d4a297f077828) C:\Windows\system32\iscsiexe.dll
10:01:07.0584 4892 MSiSCSI - ok
10:01:07.0592 4892 msiserver - ok
10:01:07.0628 4892 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
10:01:07.0630 4892 MSKSSRV - ok
10:01:07.0663 4892 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
10:01:07.0680 4892 MSPCLOCK - ok
10:01:07.0740 4892 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
10:01:07.0752 4892 MSPQM - ok
10:01:07.0844 4892 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
10:01:07.0871 4892 MsRPC - ok
10:01:07.0912 4892 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
10:01:07.0913 4892 mssmbios - ok
10:01:08.0068 4892 MSSQL$SQLEXPRESS - ok
10:01:08.0195 4892 MSSQLServerADHelper100 (f1761c8fb2b25a32c6d63e36bb88c3ae) C:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE
10:01:08.0198 4892 MSSQLServerADHelper100 - ok
10:01:08.0229 4892 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
10:01:08.0231 4892 MSTEE - ok
10:01:08.0245 4892 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
10:01:08.0247 4892 MTConfig - ok
10:01:08.0266 4892 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
10:01:08.0269 4892 Mup - ok
10:01:08.0353 4892 napagent (61d57a5d7c6d9afe10e77dae6e1b445e) C:\Windows\system32\qagentRT.dll
10:01:08.0393 4892 napagent - ok
10:01:08.0493 4892 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
10:01:08.0506 4892 NativeWifiP - ok
10:01:08.0616 4892 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
10:01:08.0650 4892 NDIS - ok
10:01:08.0702 4892 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
10:01:08.0705 4892 NdisCap - ok
10:01:08.0741 4892 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
10:01:08.0743 4892 NdisTapi - ok
10:01:08.0800 4892 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
10:01:08.0803 4892 Ndisuio - ok
10:01:08.0847 4892 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
10:01:08.0860 4892 NdisWan - ok
10:01:08.0913 4892 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
10:01:08.0916 4892 NDProxy - ok
10:01:08.0992 4892 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
10:01:08.0995 4892 NetBIOS - ok
10:01:09.0060 4892 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys
10:01:09.0069 4892 NetBT - ok
10:01:09.0107 4892 Netlogon (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
10:01:09.0110 4892 Netlogon - ok
10:01:09.0198 4892 Netman (7cccfca7510684768da22092d1fa4db2) C:\Windows\System32\netman.dll
10:01:09.0216 4892 Netman - ok
10:01:09.0377 4892 NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
10:01:09.0384 4892 NetMsmqActivator - ok
10:01:09.0390 4892 NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
10:01:09.0393 4892 NetPipeActivator - ok
10:01:09.0464 4892 netprofm (8c338238c16777a802d6a9211eb2ba50) C:\Windows\System32\netprofm.dll
10:01:09.0481 4892 netprofm - ok
10:01:09.0488 4892 NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
10:01:09.0490 4892 NetTcpActivator - ok
10:01:09.0504 4892 NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
10:01:09.0506 4892 NetTcpPortSharing - ok
10:01:09.0578 4892 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
10:01:09.0581 4892 nfrd960 - ok
10:01:09.0720 4892 NlaSvc (912084381d30d8b89ec4e293053f4710) C:\Windows\System32\nlasvc.dll
10:01:09.0733 4892 NlaSvc - ok
10:01:09.0756 4892 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
10:01:09.0760 4892 Npfs - ok
10:01:09.0809 4892 nsi (ba387e955e890c8a88306d9b8d06bf17) C:\Windows\system32\nsisvc.dll
10:01:09.0813 4892 nsi - ok
10:01:09.0855 4892 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
10:01:09.0857 4892 nsiproxy - ok
10:01:10.0289 4892 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys
10:01:10.0342 4892 Ntfs - ok
10:01:10.0394 4892 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
10:01:10.0395 4892 Null - ok
10:01:10.0456 4892 NVENETFD (b5e37e31c053bc9950455a257526514b) C:\Windows\system32\DRIVERS\nvm62x32.sys
10:01:10.0508 4892 NVENETFD - ok
10:01:11.0325 4892 nvlddmkm (b0881dda5a8160422561ffab7f0008b1) C:\Windows\system32\DRIVERS\nvlddmkm.sys
10:01:11.0768 4892 nvlddmkm - ok
10:01:11.0912 4892 NVNET (5bf9c11586f4764446407f509f1beca8) C:\Windows\system32\DRIVERS\nvmf6232.sys
10:01:11.0928 4892 NVNET - ok
10:01:11.0971 4892 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys
10:01:11.0983 4892 nvraid - ok
10:01:12.0006 4892 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys
10:01:12.0017 4892 nvstor - ok
10:01:12.0061 4892 nvstor32 (01cb6251cb805abec096ef004b2239c5) C:\Windows\system32\DRIVERS\nvstor32.sys
10:01:12.0069 4892 nvstor32 - ok
10:01:12.0100 4892 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys
10:01:12.0112 4892 nv_agp - ok
10:01:12.0197 4892 odserv (84de1dd996b48b05ace31ad015fa108a) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
10:01:12.0225 4892 odserv - ok
10:01:12.0244 4892 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
10:01:12.0250 4892 ohci1394 - ok
10:01:12.0346 4892 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
10:01:12.0355 4892 ose - ok
10:01:12.0462 4892 p2pimsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll
10:01:12.0482 4892 p2pimsvc - ok
10:01:12.0592 4892 p2psvc (59c3ddd501e39e006dac31bf55150d91) C:\Windows\system32\p2psvc.dll
10:01:12.0612 4892 p2psvc - ok
10:01:12.0637 4892 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
10:01:12.0651 4892 Parport - ok
10:01:12.0689 4892 partmgr (3f34a1b4c5f6475f320c275e63afce9b) C:\Windows\system32\drivers\partmgr.sys
10:01:12.0693 4892 partmgr - ok
10:01:12.0713 4892 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
10:01:12.0716 4892 Parvdm - ok
10:01:12.0785 4892 PassThru Service (5fbcc9eeefaca3019d5bd5979618f298) C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
10:01:12.0787 4892 PassThru Service - ok
10:01:12.0815 4892 PcaSvc (358ab7956d3160000726574083dfc8a6) C:\Windows\System32\pcasvc.dll
10:01:12.0825 4892 PcaSvc - ok
10:01:12.0858 4892 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
10:01:12.0870 4892 pci - ok
10:01:12.0880 4892 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
10:01:12.0883 4892 pciide - ok
10:01:12.0910 4892 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
10:01:12.0919 4892 pcmcia - ok
10:01:12.0938 4892 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
10:01:12.0942 4892 pcw - ok
10:01:13.0019 4892 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
10:01:13.0051 4892 PEAUTH - ok
10:01:13.0275 4892 pla (414bba67a3ded1d28437eb66aeb8a720) C:\Windows\system32\pla.dll
10:01:13.0356 4892 pla - ok
10:01:13.0566 4892 PlugPlay (ec7bc28d207da09e79b3e9faf8b232ca) C:\Windows\system32\umpnpmgr.dll
10:01:13.0583 4892 PlugPlay - ok
10:01:13.0611 4892 PNRPAutoReg (63ff8572611249931eb16bb8eed6afc8) C:\Windows\system32\pnrpauto.dll
10:01:13.0625 4892 PNRPAutoReg - ok
10:01:13.0720 4892 PNRPsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll
10:01:13.0725 4892 PNRPsvc - ok
10:01:13.0823 4892 PolicyAgent (53946b69ba0836bd95b03759530c81ec) C:\Windows\System32\ipsecsvc.dll
10:01:13.0838 4892 PolicyAgent - ok
10:01:13.0893 4892 Power (f87d30e72e03d579a5199ccb3831d6ea) C:\Windows\system32\umpo.dll
10:01:13.0905 4892 Power - ok
10:01:13.0986 4892 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
10:01:14.0000 4892 PptpMiniport - ok
10:01:14.0055 4892 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
10:01:14.0058 4892 Processor - ok
10:01:14.0109 4892 ProfSvc (43ca4ccc22d52fb58e8988f0198851d0) C:\Windows\system32\profsvc.dll
10:01:14.0123 4892 ProfSvc - ok
10:01:14.0175 4892 ProtectedStorage (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
10:01:14.0178 4892 ProtectedStorage - ok
10:01:14.0223 4892 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
10:01:14.0237 4892 Psched - ok
10:01:14.0393 4892 QBCFMonitorService (27e26a7dbc17860630ce5065019c348f) C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
10:01:14.0394 4892 QBCFMonitorService - ok
10:01:14.0465 4892 QBFCService (6bee1814470dc12fa20c53dfc3c97ebb) C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
10:01:14.0468 4892 QBFCService - ok
10:01:15.0226 4892 QBVSS (147552e28311db3e86188a356a7a9f9c) C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe
10:01:15.0255 4892 QBVSS - ok
10:01:16.0246 4892 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
10:01:16.0309 4892 ql2300 - ok
10:01:16.0458 4892 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
10:01:16.0470 4892 ql40xx - ok
10:01:16.0541 4892 QuickBooksDB21 - ok
10:01:16.0579 4892 QWAVE (31ac809e7707eb580b2bdb760390765a) C:\Windows\system32\qwave.dll
10:01:16.0596 4892 QWAVE - ok
10:01:16.0609 4892 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
10:01:16.0612 4892 QWAVEdrv - ok
10:01:16.0623 4892 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
10:01:16.0624 4892 RasAcd - ok
10:01:16.0656 4892 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
10:01:16.0659 4892 RasAgileVpn - ok
10:01:16.0690 4892 RasAuto (a60f1839849c0c00739787fd5ec03f13) C:\Windows\System32\rasauto.dll
10:01:16.0704 4892 RasAuto - ok
10:01:16.0731 4892 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
10:01:16.0742 4892 Rasl2tp - ok
10:01:16.0812 4892 RasMan (cb9e04dc05eacf5b9a36ca276d475006) C:\Windows\System32\rasmans.dll
10:01:16.0828 4892 RasMan - ok
10:01:16.0848 4892 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
10:01:16.0860 4892 RasPppoe - ok
10:01:16.0883 4892 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
10:01:16.0895 4892 RasSstp - ok
10:01:16.0934 4892 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
10:01:16.0954 4892 rdbss - ok
10:01:17.0001 4892 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
10:01:17.0003 4892 rdpbus - ok
10:01:17.0034 4892 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
10:01:17.0035 4892 RDPCDD - ok
10:01:17.0054 4892 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
10:01:17.0056 4892 RDPENCDD - ok
10:01:17.0075 4892 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
10:01:17.0078 4892 RDPREFMP - ok
10:01:17.0258 4892 RDPWD (f031683e6d1fea157abb2ff260b51e61) C:\Windows\system32\drivers\RDPWD.sys
10:01:17.0275 4892 RDPWD - ok
10:01:17.0380 4892 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
10:01:17.0391 4892 rdyboost - ok
10:01:17.0432 4892 RemoteAccess (7b5e1419717fac363a31cc302895217a) C:\Windows\System32\mprdim.dll
10:01:17.0445 4892 RemoteAccess - ok
10:01:17.0470 4892 RemoteRegistry (cb9a8683f4ef2bf99e123d79950d7935) C:\Windows\system32\regsvc.dll
10:01:17.0483 4892 RemoteRegistry - ok
10:01:17.0506 4892 RpcEptMapper (78d072f35bc45d9e4e1b61895c152234) C:\Windows\System32\RpcEpMap.dll
10:01:17.0514 4892 RpcEptMapper - ok
10:01:17.0528 4892 RpcLocator (94d36c0e44677dd26981d2bfeef2a29d) C:\Windows\system32\locator.exe
10:01:17.0532 4892 RpcLocator - ok
10:01:17.0586 4892 RpcSs (7660f01d3b38aca1747e397d21d790af) C:\Windows\system32\rpcss.dll
10:01:17.0594 4892 RpcSs - ok
10:01:17.0657 4892 RsFx0105 (6a7360e36cbd636972aeef0dd292a946) C:\Windows\system32\DRIVERS\RsFx0105.sys
10:01:17.0670 4892 RsFx0105 - ok
10:01:17.0720 4892 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
10:01:17.0724 4892 rspndr - ok
10:01:17.0757 4892 SamSs (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
10:01:17.0763 4892 SamSs - ok
10:01:17.0810 4892 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
10:01:17.0824 4892 sbp2port - ok
10:01:17.0849 4892 SCardSvr (8fc518ffe9519c2631d37515a68009c4) C:\Windows\System32\SCardSvr.dll
10:01:17.0861 4892 SCardSvr - ok
10:01:17.0909 4892 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
10:01:17.0912 4892 scfilter - ok
10:01:18.0011 4892 Schedule (a04bb13f8a72f8b6e8b4071723e4e336) C:\Windows\system32\schedsvc.dll
10:01:18.0054 4892 Schedule - ok
10:01:18.0089 4892 SCPolicySvc (319c6b309773d063541d01df8ac6f55f) C:\Windows\System32\certprop.dll
10:01:18.0091 4892 SCPolicySvc - ok
10:01:18.0132 4892 SDRSVC (08236c4bce5edd0a0318a438af28e0f7) C:\Windows\System32\SDRSVC.dll
10:01:18.0145 4892 SDRSVC - ok
10:01:18.0169 4892 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
10:01:18.0172 4892 secdrv - ok
10:01:18.0191 4892 seclogon (a59b3a4442c52060cc7a85293aa3546f) C:\Windows\system32\seclogon.dll
10:01:18.0197 4892 seclogon - ok
10:01:18.0217 4892 SENS (dcb7fcdcc97f87360f75d77425b81737) C:\Windows\System32\sens.dll
10:01:18.0233 4892 SENS - ok
10:01:18.0260 4892 SensrSvc (50087fe1ee447009c9cc2997b90de53f) C:\Windows\system32\sensrsvc.dll
10:01:18.0276 4892 SensrSvc - ok
10:01:18.0293 4892 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
10:01:18.0299 4892 Serenum - ok
10:01:18.0323 4892 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
10:01:18.0335 4892 Serial - ok
10:01:18.0356 4892 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
10:01:18.0359 4892 sermouse - ok
10:01:18.0423 4892 SessionEnv (4ae380f39a0032eab7dd953030b26d28) C:\Windows\system32\sessenv.dll
10:01:18.0436 4892 SessionEnv - ok
10:01:18.0456 4892 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
10:01:18.0458 4892 sffdisk - ok
10:01:18.0469 4892 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
10:01:18.0472 4892 sffp_mmc - ok
10:01:18.0496 4892 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
10:01:18.0498 4892 sffp_sd - ok
10:01:18.0510 4892 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
10:01:18.0513 4892 sfloppy - ok
10:01:18.0585 4892 ShellHWDetection (414da952a35bf5d50192e28263b40577) C:\Windows\System32\shsvcs.dll
10:01:18.0608 4892 ShellHWDetection - ok
10:01:18.0629 4892 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
10:01:18.0634 4892 sisagp - ok
10:01:18.0658 4892 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
10:01:18.0661 4892 SiSRaid2 - ok
10:01:18.0684 4892 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
10:01:18.0698 4892 SiSRaid4 - ok
10:01:18.0723 4892 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
10:01:18.0737 4892 Smb - ok
10:01:18.0782 4892 SNMPTRAP (6a984831644eca1a33ffeae4126f4f37) C:\Windows\System32\snmptrap.exe
10:01:18.0787 4892 SNMPTRAP - ok
10:01:18.0801 4892 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
10:01:18.0803 4892 spldr - ok
10:01:18.0849 4892 Spooler (866a43013535dc8587c258e43579c764) C:\Windows\System32\spoolsv.exe
10:01:18.0861 4892 Spooler - ok
10:01:19.0393 4892 sppsvc (cf87a1de791347e75b98885214ced2b8) C:\Windows\system32\sppsvc.exe
10:01:19.0575 4892 sppsvc - ok
10:01:19.0868 4892 sppuinotify (b0180b20b065d89232a78a40fe56eaa6) C:\Windows\system32\sppuinotify.dll
10:01:19.0874 4892 sppuinotify - ok
10:01:20.0049 4892 SQLAgent$SQLEXPRESS (a892134c28777978ecde8283dc57ac0f) C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE
10:01:20.0086 4892 SQLAgent$SQLEXPRESS - ok
10:01:20.0298 4892 SQLBrowser (10d936dced9eacd1a1b3fcdda6d7a4eb) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
10:01:20.0303 4892 SQLBrowser - ok
10:01:20.0372 4892 SQLWriter (135cdccc167ef0c250125bbd3abe18d5) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
10:01:20.0373 4892 SQLWriter - ok
10:01:20.0501 4892 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys
10:01:20.0531 4892 srv - ok
10:01:20.0591 4892 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys
10:01:20.0619 4892 srv2 - ok
10:01:20.0693 4892 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys
10:01:20.0699 4892 srvnet - ok
10:01:20.0752 4892 ssadbus (6d83ff6722baf7e82a4521dbec363e5a) C:\Windows\system32\DRIVERS\ssadbus.sys
10:01:20.0765 4892 ssadbus - ok
10:01:20.0826 4892 ssadmdfl (5ae42e90f99749e0e35b9989a2d0275c) C:\Windows\system32\DRIVERS\ssadmdfl.sys
10:01:20.0827 4892 ssadmdfl - ok
10:01:20.0841 4892 ssadmdm (9285d8aba50a4d6482b1574448f9eb76) C:\Windows\system32\DRIVERS\ssadmdm.sys
10:01:20.0849 4892 ssadmdm - ok
10:01:20.0887 4892 SSDPSRV (d887c9fd02ac9fa880f6e5027a43e118) C:\Windows\System32\ssdpsrv.dll
10:01:20.0916 4892 SSDPSRV - ok
10:01:21.0033 4892 ssmdrv (a36ee93698802cd899f98bfd553d8185) C:\Windows\system32\DRIVERS\ssmdrv.sys
10:01:21.0041 4892 ssmdrv - ok
10:01:21.0110 4892 SstpSvc (d318f23be45d5e3a107469eb64815b50) C:\Windows\system32\sstpsvc.dll
10:01:21.0118 4892 SstpSvc - ok
10:01:21.0153 4892 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
10:01:21.0156 4892 stexstor - ok
10:01:21.0249 4892 StiSvc (e1fb3706030fb4578a0d72c2fc3689e4) C:\Windows\System32\wiaservc.dll
10:01:21.0287 4892 StiSvc - ok
10:01:21.0321 4892 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys
10:01:21.0323 4892 swenum - ok
10:01:21.0385 4892 swprv (a28bd92df340e57b024ba433165d34d7) C:\Windows\System32\swprv.dll
10:01:21.0405 4892 swprv - ok
10:01:21.0660 4892 SysMain (36650d618ca34c9d357dfd3d89b2c56f) C:\Windows\system32\sysmain.dll
10:01:21.0708 4892 SysMain - ok
10:01:21.0753 4892 TabletInputService (763fecdc3d30c815fe72dd57936c6cd1) C:\Windows\System32\TabSvc.dll
10:01:21.0760 4892 TabletInputService - ok
10:01:21.0925 4892 TapiSrv (613bf4820361543956909043a265c6ac) C:\Windows\System32\tapisrv.dll
10:01:21.0940 4892 TapiSrv - ok
10:01:21.0988 4892 TBS (b799d9fdb26111737f58288d8dc172d9) C:\Windows\System32\tbssvc.dll
10:01:21.0994 4892 TBS - ok
10:01:22.0188 4892 Tcpip (7fa2e0f8b072bd04b77b421480b6cc22) C:\Windows\system32\drivers\tcpip.sys
10:01:22.0249 4892 Tcpip - ok
10:01:22.0275 4892 TCPIP6 (7fa2e0f8b072bd04b77b421480b6cc22) C:\Windows\system32\DRIVERS\tcpip.sys
10:01:22.0286 4892 TCPIP6 - ok
10:01:22.0332 4892 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
10:01:22.0334 4892 tcpipreg - ok
10:01:22.0373 4892 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
10:01:22.0375 4892 TDPIPE - ok
10:01:22.0411 4892 TDTCP (2c2c5afe7ee4f620d69c23c0617651a8) C:\Windows\system32\drivers\tdtcp.sys
10:01:22.0414 4892 TDTCP - ok
10:01:22.0448 4892 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys
10:01:22.0461 4892 tdx - ok
10:01:22.0794 4892 TeamViewer7 (33966a658ff37e0c65d46e59f37e2380) C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
10:01:22.0912 4892 TeamViewer7 - ok
10:01:23.0049 4892 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys
10:01:23.0052 4892 TermDD - ok
10:01:23.0128 4892 TermService (382c804c92811be57829d8e550a900e2) C:\Windows\System32\termsrv.dll
10:01:23.0158 4892 TermService - ok
10:01:23.0188 4892 Themes (42fb6afd6b79d9fe07381609172e7ca4) C:\Windows\system32\themeservice.dll
10:01:23.0194 4892 Themes - ok
10:01:23.0217 4892 THREADORDER (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll
10:01:23.0220 4892 THREADORDER - ok
10:01:23.0243 4892 TrkWks (4792c0378db99a9bc2ae2de6cfff0c3a) C:\Windows\System32\trkwks.dll
10:01:23.0254 4892 TrkWks - ok
10:01:23.0319 4892 TrustedInstaller (2c49b175aee1d4364b91b531417fe583) C:\Windows\servicing\TrustedInstaller.exe
10:01:23.0334 4892 TrustedInstaller - ok
10:01:23.0355 4892 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
10:01:23.0358 4892 tssecsrv - ok
10:01:23.0393 4892 TSUSB2 (f13e12fc0e9e1d02b6b679a3a08f6c4d) C:\Windows\system32\DRIVERS\TSUSB2.sys
10:01:23.0397 4892 TSUSB2 - ok
10:01:23.0439 4892 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
10:01:23.0443 4892 TsUsbFlt - ok
10:01:23.0499 4892 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
10:01:23.0511 4892 tunnel - ok
10:01:23.0535 4892 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
10:01:23.0540 4892 uagp35 - ok
10:01:23.0583 4892 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
10:01:23.0600 4892 udfs - ok
10:01:23.0631 4892 UI0Detect (8344fd4fce927880aa1aa7681d4927e5) C:\Windows\system32\UI0Detect.exe
10:01:23.0647 4892 UI0Detect - ok
10:01:23.0708 4892 UimBus (16264d4a7f052a7cc516b23e00b14213) C:\Windows\system32\DRIVERS\UimBus.sys
10:01:23.0711 4892 UimBus - ok
10:01:23.0760 4892 Uim_IM (811e4296913821ce402b9e6629740350) C:\Windows\system32\Drivers\Uim_IM.sys
10:01:23.0782 4892 Uim_IM - ok
10:01:23.0805 4892 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
10:01:23.0809 4892 uliagpkx - ok
10:01:23.0853 4892 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\DRIVERS\umbus.sys
10:01:23.0857 4892 umbus - ok
10:01:23.0874 4892 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
10:01:23.0875 4892 UmPass - ok
10:01:23.0918 4892 upnphost (833fbb672460efce8011d262175fad33) C:\Windows\System32\upnphost.dll
10:01:23.0944 4892 upnphost - ok
10:01:24.0001 4892 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\Windows\system32\Drivers\usbaapl.sys
10:01:24.0005 4892 USBAAPL - ok
10:01:24.0045 4892 usbaudio (1d9f2bd026e8e2d45033a4df3f16b78c) C:\Windows\system32\drivers\usbaudio.sys
10:01:24.0059 4892 usbaudio - ok
10:01:24.0155 4892 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\DRIVERS\usbccgp.sys
10:01:24.0169 4892 usbccgp - ok
10:01:24.0252 4892 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys
10:01:24.0257 4892 usbcir - ok
10:01:24.0292 4892 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\DRIVERS\usbehci.sys
10:01:24.0294 4892 usbehci - ok
10:01:24.0349 4892 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys
10:01:24.0365 4892 usbhub - ok
10:01:24.0403 4892 usbohci (e185d44fac515a18d9deddc23c2cdf44) C:\Windows\system32\DRIVERS\usbohci.sys
10:01:24.0407 4892 usbohci - ok
10:01:24.0433 4892 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
10:01:24.0436 4892 usbprint - ok
10:01:24.0450 4892 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
10:01:24.0454 4892 usbscan - ok
10:01:24.0489 4892 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS
10:01:24.0494 4892 USBSTOR - ok
10:01:24.0515 4892 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys
10:01:24.0519 4892 usbuhci - ok
10:01:24.0536 4892 UxSms (081e6e1c91aec36758902a9f727cd23c) C:\Windows\System32\uxsms.dll
10:01:24.0541 4892 UxSms - ok
10:01:24.0583 4892 VaultSvc (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe
10:01:24.0585 4892 VaultSvc - ok
10:01:24.0625 4892 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
10:01:24.0627 4892 vdrvroot - ok
10:01:24.0705 4892 vds (c3cd30495687c2a2f66a65ca6fd89be9) C:\Windows\System32\vds.exe
10:01:24.0714 4892 vds - ok
10:01:24.0733 4892 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
10:01:24.0737 4892 vga - ok
10:01:24.0751 4892 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
10:01:24.0754 4892 VgaSave - ok
10:01:24.0773 4892 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
10:01:24.0785 4892 vhdmp - ok
10:01:24.0835 4892 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
10:01:24.0839 4892 viaagp - ok
10:01:24.0849 4892 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
10:01:24.0853 4892 ViaC7 - ok
10:01:24.0861 4892 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
10:01:24.0863 4892 viaide - ok
10:01:24.0888 4892 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
10:01:24.0892 4892 volmgr - ok
10:01:24.0988 4892 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
10:01:25.0012 4892 volmgrx - ok
10:01:25.0079 4892 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
10:01:25.0106 4892 volsnap - ok
10:01:25.0164 4892 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
10:01:25.0177 4892 vsmraid - ok
10:01:25.0387 4892 VSS (209a3b1901b83aeb8527ed211cce9e4c) C:\Windows\system32\vssvc.exe
10:01:25.0434 4892 VSS - ok
10:01:25.0454 4892 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
10:01:25.0456 4892 vwifibus - ok
10:01:25.0504 4892 W32Time (55187fd710e27d5095d10a472c8baf1c) C:\Windows\system32\w32time.dll
10:01:25.0537 4892 W32Time - ok
10:01:25.0564 4892 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
10:01:25.0567 4892 WacomPen - ok
10:01:25.0666 4892 wampapache (53ea061ecc67223a430f153c3682ad54) c:\wamp\bin\apache\apache2.2.17\bin\httpd.exe
10:01:25.0668 4892 wampapache - ok
10:01:25.0722 4892 wampmysqld - ok
10:01:25.0784 4892 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
10:01:25.0797 4892 WANARP - ok
10:01:25.0808 4892 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
10:01:25.0809 4892 Wanarpv6 - ok
10:01:26.0173 4892 WatAdminSvc (353a04c273ec58475d8633e75ccd5604) C:\Windows\system32\Wat\WatAdminSvc.exe
10:01:26.0252 4892 WatAdminSvc - ok
10:01:26.0705 4892 wbengine (691e3285e53dca558e1a84667f13e15a) C:\Windows\system32\wbengine.exe
10:01:26.0770 4892 wbengine - ok
10:01:26.0808 4892 WbioSrvc (9614b5d29dc76ac3c29f6d2d3aa70e67) C:\Windows\System32\wbiosrvc.dll
10:01:26.0828 4892 WbioSrvc - ok
10:01:26.0886 4892 wcncsvc (34eee0dfaadb4f691d6d5308a51315dc) C:\Windows\System32\wcncsvc.dll
10:01:26.0910 4892 wcncsvc - ok
10:01:26.0936 4892 WcsPlugInService (5d930b6357a6d2af4d7653bdabbf352f) C:\Windows\System32\WcsPlugInService.dll
10:01:26.0942 4892 WcsPlugInService - ok
10:01:27.0005 4892 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
10:01:27.0007 4892 Wd - ok
10:01:27.0057 4892 WDC_SAM (d6efaf429fd30c5df613d220e344cce7) C:\Windows\system32\DRIVERS\wdcsam.sys
10:01:27.0059 4892 WDC_SAM - ok
10:01:27.0107 4892 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
10:01:27.0134 4892 Wdf01000 - ok
10:01:27.0153 4892 WdiServiceHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll
10:01:27.0165 4892 WdiServiceHost - ok
10:01:27.0170 4892 WdiSystemHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll
10:01:27.0174 4892 WdiSystemHost - ok
10:01:27.0228 4892 WebClient (a9d880f97530d5b8fee278923349929d) C:\Windows\System32\webclnt.dll
10:01:27.0245 4892 WebClient - ok
10:01:27.0269 4892 Wecsvc (760f0afe937a77cff27153206534f275) C:\Windows\system32\wecsvc.dll
10:01:27.0289 4892 Wecsvc - ok
10:01:27.0310 4892 wercplsupport (ac804569bb2364fb6017370258a4091b) C:\Windows\System32\wercplsupport.dll
10:01:27.0325 4892 wercplsupport - ok
10:01:27.0356 4892 WerSvc (08e420d873e4fd85241ee2421b02c4a4) C:\Windows\System32\WerSvc.dll
10:01:27.0361 4892 WerSvc - ok
10:01:27.0384 4892 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
10:01:27.0386 4892 WfpLwf - ok
10:01:27.0401 4892 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
10:01:27.0404 4892 WIMMount - ok
10:01:27.0420 4892 WinHttpAutoProxySvc - ok
10:01:27.0473 4892 Winmgmt (f62e510b6ad4c21eb9fe8668ed251826) C:\Windows\system32\wbem\WMIsvc.dll
10:01:27.0484 4892 Winmgmt - ok
10:01:27.0598 4892 WinRM (1b91cd34ea3a90ab6a4ef0550174f4cc) C:\Windows\system32\WsmSvc.dll
10:01:27.0656 4892 WinRM - ok
10:01:27.0740 4892 WinUsb (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys
10:01:27.0743 4892 WinUsb - ok
10:01:27.0826 4892 Wlansvc (16935c98ff639d185086a3529b1f2067) C:\Windows\System32\wlansvc.dll
10:01:27.0872 4892 Wlansvc - ok
10:01:28.0075 4892 wlidsvc (0a70f4022ec2e14c159efc4f69aa2477) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
10:01:28.0141 4892 wlidsvc - ok
10:01:28.0234 4892 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
10:01:28.0236 4892 WmiAcpi - ok
10:01:28.0292 4892 wmiApSrv (6eb6b66517b048d87dc1856ddf1f4c3f) C:\Windows\system32\wbem\WmiApSrv.exe
10:01:28.0304 4892 wmiApSrv - ok
10:01:28.0443 4892 WMPNetworkSvc (3b40d3a61aa8c21b88ae57c58ab3122e) C:\Program Files\Windows Media Player\wmpnetwk.exe
10:01:28.0482 4892 WMPNetworkSvc - ok
10:01:28.0510 4892 WPCSvc (a2f0ec770a92f2b3f9de6d518e11409c) C:\Windows\System32\wpcsvc.dll
10:01:28.0515 4892 WPCSvc - ok
10:01:28.0556 4892 WPDBusEnum (aa53356d60af47eacc85bc617a4f3f66) C:\Windows\system32\wpdbusenum.dll
10:01:28.0570 4892 WPDBusEnum - ok
10:01:28.0594 4892 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
10:01:28.0596 4892 ws2ifsl - ok
10:01:28.0642 4892 WSDPrintDevice (553f6ccd7c58eb98d4a8fbdaf283d7a9) C:\Windows\system32\DRIVERS\WSDPrint.sys
10:01:28.0644 4892 WSDPrintDevice - ok
10:01:28.0651 4892 WSearch - ok
10:01:28.0731 4892 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
10:01:28.0737 4892 WudfPf - ok
10:01:28.0893 4892 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
10:01:28.0907 4892 WUDFRd - ok
10:01:28.0957 4892 wudfsvc (8d1e1e529a2c9e9b6a85b55a345f7629) C:\Windows\System32\WUDFSvc.dll
10:01:28.0964 4892 wudfsvc - ok
10:01:28.0999 4892 WwanSvc (ff2d745b560f7c71b31f30f4d49f73d2) C:\Windows\System32\wwansvc.dll
10:01:29.0025 4892 WwanSvc - ok
10:01:29.0084 4892 xusb21 (c26c68bcbac1f33f890c226769759209) C:\Windows\system32\DRIVERS\xusb21.sys
10:01:29.0096 4892 xusb21 - ok
10:01:29.0120 4892 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
10:01:29.0360 4892 \Device\Harddisk0\DR0 - ok
10:01:29.0369 4892 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
10:01:29.0415 4892 \Device\Harddisk1\DR1 ( TDSS File System ) - warning
10:01:29.0415 4892 \Device\Harddisk1\DR1 - detected TDSS File System (1)
10:01:29.0422 4892 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk2\DR2
10:01:30.0007 4892 \Device\Harddisk2\DR2 - ok
10:01:30.0013 4892 Boot (0x1200) (b7ca23615dcd1c33c3ddb1fa4735417e) \Device\Harddisk0\DR0\Partition0
10:01:30.0015 4892 \Device\Harddisk0\DR0\Partition0 - ok
10:01:30.0051 4892 Boot (0x1200) (7bbc965ca5b73160132a1cce4b88774a) \Device\Harddisk0\DR0\Partition1
10:01:30.0054 4892 \Device\Harddisk0\DR0\Partition1 - ok
10:01:30.0060 4892 Boot (0x1200) (c2103941a051edaccf3cb9205d54f6c1) \Device\Harddisk1\DR1\Partition0
10:01:30.0061 4892 \Device\Harddisk1\DR1\Partition0 - ok
10:01:30.0074 4892 Boot (0x1200) (e5f5228065742fcbab1e720b3f2aa509) \Device\Harddisk2\DR2\Partition0
10:01:30.0076 4892 \Device\Harddisk2\DR2\Partition0 - ok
10:01:30.0078 4892 ============================================================
10:01:30.0078 4892 Scan finished
10:01:30.0078 4892 ============================================================
10:01:30.0114 5640 Detected object count: 1
10:01:30.0114 5640 Actual detected object count: 1
10:01:59.0209 5640 \Device\Harddisk1\DR1 ( TDSS File System ) - skipped by user
10:01:59.0209 5640 \Device\Harddisk1\DR1 ( TDSS File System ) - User select action: Skip
10:09:17.0815 4492 Deinitialize success



aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-08-11 10:05:27
-----------------------------
10:05:27.062 OS Version: Windows 6.1.7601 Service Pack 1
10:05:27.062 Number of processors: 2 586 0x2B01
10:05:27.072 ComputerName: CHIPS-DESKTOP UserName: Chip
10:05:32.419 Initialize success
10:06:27.330 AVAST engine defs: 12081100
10:06:42.246 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T1L0-2
10:06:42.252 Disk 0 Vendor: WDC_WD5000AAKB-00H8A0 05.04E05 Size: 476940MB BusType: 3
10:06:42.261 Disk 1 \Device\Harddisk1\DR1 -> \Device\0000005c
10:06:42.268 Disk 1 Vendor: WDC_WD25 10.0 Size: 238475MB BusType: 3
10:06:42.277 Disk 2 \Device\Harddisk2\DR2 -> \Device\00000070
10:06:42.284 Disk 2 Vendor: Size: 238475MB BusType: 0
10:06:42.300 Disk 0 MBR read successfully
10:06:42.306 Disk 0 MBR scan
10:06:42.340 Disk 0 Windows 7 default MBR code
10:06:42.352 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
10:06:42.399 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 476838 MB offset 206848
10:06:42.424 Disk 0 scanning sectors +976771072
10:06:42.507 Disk 0 scanning C:\Windows\system32\drivers
10:07:01.758 Service scanning
10:07:38.734 Modules scanning
10:07:49.986 Disk 0 trace - called modules:
10:07:50.007 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
10:07:50.016 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85dff030]
10:07:50.026 3 CLASSPNP.SYS[88c0459e] -> nt!IofCallDriver -> [0x857bf918]
10:07:50.036 5 ACPI.sys[889a43d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T1L0-2[0x857333d0]
10:07:51.556 AVAST engine scan C:\Windows
10:07:56.079 AVAST engine scan C:\Windows\system32
10:15:31.878 AVAST engine scan C:\Windows\system32\drivers
10:15:54.798 AVAST engine scan C:\Users\Chip
11:21:06.445 AVAST engine scan C:\ProgramData
11:27:14.287 Scan finished successfully
11:28:34.297 Disk 0 MBR has been saved successfully to "C:\MBR.dat"
11:28:34.306 The log file has been saved successfully to "C:\aswMBR.txt"



C:\Users\Chip\AppData\Local\TempDIR\BetterInstaller.exe a variant of Win32/Somoto.A application cleaned by deleting - quarantined
C:\Users\Chip\AppData\Local\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\n Win32/Sirefef.EV trojan cleaned by deleting (after the next restart) - quarantined
C:\Users\Chip\AppData\Local\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\00000004.@ Win32/Conedex.D trojan cleaned by deleting - quarantined
C:\Users\Chip\AppData\Local\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\U\000000cb.@ Win32/Conedex.E trojan cleaned by deleting - quarantined
C:\Users\Chip\Documents\wordpress themes\FreeYouTubeDownloaderInstaller.exe a variant of Win32/Somoto.A application cleaned by deleting - quarantined
C:\Users\Chip\Downloads\FreeYouTubeDownloaderInstaller.exe a variant of Win32/Somoto.A application cleaned by deleting - quarantined
C:\Windows\Installer\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}\n Win32/Sirefef.EV trojan cleaned by deleting - quarantined

#4 narenxp

narenxp

    Forum Addict

  • BC Advisor
  • PipPipPipPipPipPip
  • 16,365 posts
  • Gender:Male
  • Location:India

Posted 11 August 2012 - 05:20 PM

Download

systemlook

Launch it and copy this script and paste in the BOX

:filefind
services.exe
:folderfind
{a78ab9a9-0b8b-ea57-bcc8-d78057205226}

Click on LOOK,post the generated log

Download

http://www.techspot.com/downloads/4716-malwarebytes-anti-malware.html

Install,update and run a full scan

Click on SHOW results.Select all infections and remove it

Reboot the PC and scan MBAM once in regular mode until you get a clean log

Download

mini toolbox

Checkmark following boxes:

Flush DNS
Report IE Proxy Settings
Reset IE Proxy Settings
Report FF Proxy Settings
Reset FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries
List last 10 Event Viewer log
List Installed Programs
List Users, Partitions and Memory size

Click Go and post the result.

Download

FSS

Checkmark all the boxes

Click on "Scan".
Please copy and paste the log to your reply.


Download

adware cleaner

Launch it click on Delete

post the generated log

#5 chipk1

chipk1

    New Member

  • Members
  • Pip
  • 8 posts

Posted 11 August 2012 - 10:43 PM

Here you go. Not getting anymore Avira warnings!

SystemLook 30.07.11 by jpshortstuff
Log created at 18:26 on 11/08/2012 by Chip
Administrator - Elevation successful

========== filefind ==========

Searching for "services.exe"
C:\Windows\System32\services.exe --a---- 259072 bytes [23:11 13/07/2009] [00:12 11/08/2012] 5F1B6A9C35D3D5CA72D6D6FDEF9747D6
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe --a---- 259072 bytes [23:11 13/07/2009] [01:14 14/07/2009] 5F1B6A9C35D3D5CA72D6D6FDEF9747D6

========== folderfind ==========

Searching for "{a78ab9a9-0b8b-ea57-bcc8-d78057205226}"
C:\Users\Chip\AppData\Local\{a78ab9a9-0b8b-ea57-bcc8-d78057205226} d--hs-- [12:07 11/01/2012]
C:\Windows\Installer\{a78ab9a9-0b8b-ea57-bcc8-d78057205226} d--hs-- [12:07 11/01/2012]

-= EOF =-


MiniToolBox by Farbar Version: 23-07-2012
Ran by Chip (administrator) on 11-08-2012 at 22:47:30
Microsoft Windows 7 Home Premium Service Pack 1 (X86)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ==============================


"Reset FF Proxy Settings": Firefox Proxy settings were reset.

========================= Hosts content: =================================


127.0.0.1 localhost
127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 ereg.adobe.com
127.0.0.1 activate.wip3.adobe.com
127.0.0.1 wip3.adobe.com
127.0.0.1 3dns-3.adobe.com
127.0.0.1 3dns-2.adobe.com
127.0.0.1 adobe-dns.adobe.com
127.0.0.1 adobe-dns-2.adobe.com
127.0.0.1 adobe-dns-3.adobe.com
127.0.0.1 ereg.wip3.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 activate-sjc0.adobe.com
127.0.0.1 adobe.activate.com
127.0.0.1 adobeereg.com
127.0.0.1 www.adobeereg.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 125.252.224.90

There are 3 more lines starting with "127.0.0.1"

========================= IP Configuration: ================================

NVIDIA nForce 10/100 Mbps Ethernet = Local Area Connection (Connected)


# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global defaultcurhoplimit=64 icmpredirects=enabled taskoffload=enabled


popd
# End of IPv4 configuration



Windows IP Configuration

Host Name . . . . . . . . . . . . : Chips-desktop
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : NVIDIA nForce 10/100 Mbps Ethernet
Physical Address. . . . . . . . . : 00-17-31-10-6E-C9
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::ad41:1aed:9331:577%10(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.1.3(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Saturday, August 11, 2012 10:31:54 PM
Lease Expires . . . . . . . . . . : Sunday, August 12, 2012 2:11:42 PM
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DHCPv6 IAID . . . . . . . . . . . : 234886961
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-15-07-4F-91-00-17-31-10-6E-C9
DNS Servers . . . . . . . . . . . : 208.67.222.222
208.67.220.220
NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.{0B943DEC-EAAF-426E-8AA1-820EE1756ECF}:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 9:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Server: resolver1.opendns.com
Address: 208.67.222.222

Name: google.com
Addresses: 2607:f8b0:4002:802::1007
74.125.130.100
74.125.130.101
74.125.130.102
74.125.130.113
74.125.130.138
74.125.130.139


Pinging google.com [74.125.130.139] with 32 bytes of data:
Reply from 74.125.130.139: bytes=32 time=34ms TTL=44
Reply from 74.125.130.139: bytes=32 time=33ms TTL=44

Ping statistics for 74.125.130.139:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 33ms, Maximum = 34ms, Average = 33ms
Server: resolver1.opendns.com
Address: 208.67.222.222

Name: yahoo.com
Addresses: 98.139.183.24
209.191.122.70
72.30.38.140


Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=262ms TTL=45
Reply from 98.139.183.24: bytes=32 time=113ms TTL=45

Ping statistics for 98.139.183.24:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 113ms, Maximum = 262ms, Average = 187ms
Server: resolver1.opendns.com
Address: 208.67.222.222

Name: bleepingcomputer.com
Address: 208.43.87.2


Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:
Reply from 208.43.87.2: Destination host unreachable.
Reply from 208.43.87.2: Destination host unreachable.

Ping statistics for 208.43.87.2:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=64
Reply from 127.0.0.1: bytes=32 time<1ms TTL=64

Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
10...00 17 31 10 6e c9 ......NVIDIA nForce 10/100 Mbps Ethernet
1...........................Software Loopback Interface 1
11...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
12...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.3 20
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
192.168.1.0 255.255.255.0 On-link 192.168.1.3 276
192.168.1.3 255.255.255.255 On-link 192.168.1.3 276
192.168.1.255 255.255.255.255 On-link 192.168.1.3 276
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.1.3 276
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.1.3 276
===========================================================================
Persistent Routes:
None

IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
1 306 ::1/128 On-link
10 276 fe80::/64 On-link
10 276 fe80::ad41:1aed:9331:577/128
On-link
1 306 ff00::/8 On-link
10 276 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================

Catalog5 01 mswsock.dll [File Not found] ()
ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"

Catalog5 02 C:\Windows\system32\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\system32\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\system32\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 mswsock.dll [File Not found] ()
ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"

Catalog5 06 C:\Windows\System32\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog9 01 mswsock.dll [File Not found] ()
Catalog9 02 mswsock.dll [File Not found] ()
Catalog9 03 mswsock.dll [File Not found] ()
Catalog9 04 mswsock.dll [File Not found] ()
Catalog9 05 mswsock.dll [File Not found] ()
Catalog9 06 mswsock.dll [File Not found] ()
Catalog9 07 mswsock.dll [File Not found] ()
Catalog9 08 mswsock.dll [File Not found] ()
Catalog9 09 mswsock.dll [File Not found] ()
Catalog9 10 mswsock.dll [File Not found] ()
Catalog9 11 mswsock.dll [File Not found] ()
Catalog9 12 mswsock.dll [File Not found] ()
Catalog9 13 mswsock.dll [File Not found] ()
Catalog9 14 mswsock.dll [File Not found] ()
Catalog9 15 mswsock.dll [File Not found] ()
Catalog9 16 mswsock.dll [File Not found] ()
Catalog9 17 mswsock.dll [File Not found] ()
Catalog9 18 mswsock.dll [File Not found] ()
Catalog9 19 mswsock.dll [File Not found] ()
Catalog9 20 mswsock.dll [File Not found] ()

========================= Event log errors: ===============================

Application errors:
==================
Error: (08/11/2012 10:34:58 PM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks":
Returning NULL QBWinInstance Handle

Error: (08/11/2012 10:34:58 PM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks":
Returning NULL QBWinInstance Handle

Error: (08/11/2012 10:34:58 PM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks":
Returning NULL QBWinInstance Handle

Error: (08/11/2012 06:11:04 PM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks":
Returning NULL QBWinInstance Handle

Error: (08/11/2012 06:11:04 PM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks":
Returning NULL QBWinInstance Handle

Error: (08/11/2012 06:11:04 PM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks":
Returning NULL QBWinInstance Handle

Error: (08/11/2012 08:40:05 AM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks Pro 2011":
DBConnPool::HandleConnectionError errorCode:-6069, dbCode:-103 from file:'.\.\src\ConnPool.cpp' at line 1038 from function:'DBMgr::DBConnPool::init'

Error: (08/11/2012 08:40:05 AM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks Pro 2011":
Connection String:CON=QBConnectionPool-Probe-QB_CHIPS-DESKTOP_21;;DBF=C:\Users\Public\Documents\Intuit\QuickBooks\Company Files\Chip's Lawn Care.QBW;CommLinks="ShMem,tcpip(IP=192.168.1.3;TO=5;DOBROADCAST=NONE;port=55343)";ServerName=QB_CHIPS-DESKTOP_21;DBN=f166455f9e4b4eee9490846823079a97

Error: (08/11/2012 08:40:05 AM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks Pro 2011":
Connection Error:Invalid user ID or password

Error: (08/11/2012 07:54:11 AM) (Source: QuickBooks) (User: )
Description: An unexpected error has occured in "QuickBooks":
Returning NULL QBWinInstance Handle


System errors:
=============
Error: (08/11/2012 10:34:20 PM) (Source: Service Control Manager) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error:
%%-2147024891

Error: (08/11/2012 10:34:20 PM) (Source: Service Control Manager) (User: )
Description: The Function Discovery Resource Publication service terminated with the following error:
%%-2147024891

Error: (08/11/2012 10:34:08 PM) (Source: Service Control Manager) (User: )
Description: The Windows Media Player Network Sharing Service service failed to start due to the following error:
%%1053

Error: (08/11/2012 10:34:08 PM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Media Player Network Sharing Service service to connect.

Error: (08/11/2012 10:33:19 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (08/11/2012 10:32:26 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
Null
UimBus
Uim_IM

Error: (08/11/2012 10:32:02 PM) (Source: Service Control Manager) (User: )
Description: The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

Error: (08/11/2012 10:31:57 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service terminated with the following error:
%%1060

Error: (08/11/2012 10:31:55 PM) (Source: Service Control Manager) (User: )
Description: The Function Discovery Resource Publication service terminated with the following error:
%%-2147024891

Error: (08/11/2012 10:31:55 PM) (Source: Service Control Manager) (User: )
Description: The iPodDrv service failed to start due to the following error:
%%2


Microsoft Office Sessions:
=========================

=========================== Installed Programs ============================

µTorrent (Version: 2.2.0)
7-Zip 9.20
Adobe AIR (Version: 2.5.1.17730)
Adobe Anchor Service CS4 (Version: 2.0)
Adobe Bridge CS4 (Version: 3)
Adobe CMaps CS4 (Version: 2.0)
Adobe Color - Photoshop Specific CS4 (Version: 2.0)
Adobe Color EU Extra Settings CS4 (Version: 2.0)
Adobe Color JA Extra Settings CS4 (Version: 2.0)
Adobe Color NA Recommended Settings CS4 (Version: 2.0)
Adobe Color Video Profiles CS CS4 (Version: 2.0)
Adobe Community Help (Version: 3.4.980)
Adobe CSI CS4 (Version: 1)
Adobe Default Language CS4 (Version: 2.0)
Adobe Device Central CS4 (Version: 2)
Adobe Dreamweaver CS5 (Version: 11.0)
Adobe Dreamweaver CS5.5 (Version: 11.5)
Adobe Drive CS4 (Version: 1)
Adobe ExtendScript Toolkit CS4 (Version: 3.0.0)
Adobe Extension Manager CS4 (Version: 2.0)
Adobe Flash Player 11 ActiveX (Version: 11.3.300.270)
Adobe Flash Player 11 Plugin (Version: 11.3.300.270)
Adobe Fonts All (Version: 2.0)
Adobe Linguistics CS4 (Version: 4.0.0)
Adobe Media Player (Version: 1.8)
Adobe Output Module (Version: 2.0)
Adobe PDF Library Files CS4 (Version: 9.0)
Adobe Photoshop CS4 (Version: 11.0)
Adobe Photoshop CS4 Support (Version: 11.0)
Adobe Reader X (10.1.0) (Version: 10.1.0)
Adobe Search for Help (Version: 1.0)
Adobe Service Manager Extension (Version: 1.0)
Adobe Setup (Version: 2.0)
Adobe Type Support CS4 (Version: 9.0)
Adobe Update Manager CS4 (Version: 6.0.0)
Adobe Widget Browser (Version: 2.0 Build 230)
Adobe Widget Browser (Version: 2.0.230)
Adobe WinSoft Linguistics Plugin (Version: 1.1)
Adobe XMP Panels CS4 (Version: 2.0)
AdobeColorCommonSetCMYK (Version: 2.0)
AdobeColorCommonSetRGB (Version: 2.0)
Amazon Kindle
Any DVD Cloner Platinum 1.1.1
Apple Application Support (Version: 2.1.6)
Apple Mobile Device Support (Version: 4.0.0.97)
Apple Software Update (Version: 2.1.3.127)
Audacity 1.3.12 (Unicode)
Aura Software Manager 1.0.3
Aura Video Converter 1.3.1
Avira Free Antivirus (Version: 12.0.0.1167)
Bonjour (Version: 3.0.0.10)
Camtasia Studio 7 (Version: 7.0.0)
Canon MP Navigator EX 4.0
Canon MP495 series MP Drivers
Canon MP495 series User Registration
Canon My Printer
CCleaner (Version: 3.14)
COMODO Internet Security (Version: 5.3.50343.1263)
Conduit Engine (Version: )
Connect (Version: 1.0.0.1)
Coupon Printer for Windows (Version: 5.0.0.1)
Crystal Reports for Visual Studio (Version: 12.51.0.240)
D3DX10 (Version: 15.4.2368.0902)
DebugMode Wax 2.0
Digital Cable Advisor (Version: 1.0.0.0)
Documents To Go Desktop for Android (Version: 3.0000.025)
Dotfuscator Software Services - Community Edition (Version: 5.0.2300.0)
DVD Architect Pro 5.0 (Version: 5.0.180)
DVD Architect Studio 5.0 (Version: 5.0.128)
e-Sword (Version: 10.00.0005)
erLT (Version: 1.20.0137)
ESET Online Scanner v3
ffdshow [rev 2527] [2008-12-19] (Version: 1.0)
FileZilla Client 3.5.2 (Version: 3.5.2)
Free YouTube Downloader 3.5.124
FreeDNS Update 1.8.4 (Version: 1.8.4)
Futuremark SystemInfo (Version: 4.2.0)
FXCM Micro Trading Station II (Version: 111711)
Google Chrome (Version: 21.0.1180.75)
Hauppauge English Help Files and Resources
Hauppauge WinTV
Hauppauge WinTV Scheduler
Hauppauge WinTV TV Services
HTC BMP USB Driver (Version: 1.0.5375)
HTC Driver Installer (Version: 3.0.0.005)
Hulu Desktop (Version: 0.9.14)
Internet TV for Windows Media Center (Version: 4.2.2.0)
InterVideo FilterSDK for Hauppauge
iSEEK AnswerWorks English Runtime (Version: 010.000.0101)
ISODisk 1.1
iTunes (Version: 10.5.3.3)
Java Auto Updater (Version: 2.0.7.1)
Java™ 6 Update 32 (Version: 6.0.320)
Kies mini (Version: 1.00.0000)
kuler (Version: 2.0)
Lock Poker (Version: 5.0)
Logitech Harmony Remote Software (Version: 0.6.0201)
MagicDisc 2.7.106
Malwarebytes Anti-Malware version 1.62.0.1300 (Version: 1.62.0.1300)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Multi-Targeting Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools (Version: 2.0.50217.0)
Microsoft ASP.NET MVC 2 (Version: 2.0.50217.0)
Microsoft Flight Simulator X (Version: 10.0.61355.0)
Microsoft Flight Simulator X Service Pack 1 (Version: 10.0.61355.0)
Microsoft Flight Simulator X Service Pack 2 (Version: 10.0.61472.0)
Microsoft Help Viewer 1.0 (Version: 1.0.30319)
Microsoft IntelliType Pro 8.2 (Version: 8.20.469.0)
Microsoft Office 2007 Primary Interop Assemblies (Version: 12.0.4518.1014)
Microsoft Office Access MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Enterprise 2007 (Version: 12.0.4518.1014)
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Groove MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proof (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proof (French) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Word MUI (English) 2007 (Version: 12.0.4518.1014)
Microsoft Silverlight (Version: 4.1.10329.0)
Microsoft Silverlight 3 SDK (Version: 3.0.40818.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft SQL Server 2008
Microsoft SQL Server 2008 Browser (Version: 10.3.5500.0)
Microsoft SQL Server 2008 Common Files (Version: 10.3.5500.0)
Microsoft SQL Server 2008 Database Engine Services (Version: 10.3.5500.0)
Microsoft SQL Server 2008 Database Engine Shared (Version: 10.3.5500.0)
Microsoft SQL Server 2008 Native Client (Version: 10.3.5500.0)
Microsoft SQL Server 2008 R2 Data-Tier Application Framework (Version: 10.50.1447.4)
Microsoft SQL Server 2008 R2 Data-Tier Application Project (Version: 10.50.1447.4)
Microsoft SQL Server 2008 R2 Management Objects (Version: 10.50.1447.4)
Microsoft SQL Server 2008 R2 Transact-SQL Language Service (Version: 10.50.1447.4)
Microsoft SQL Server 2008 RsFx Driver (Version: 10.3.5500.0)
Microsoft SQL Server 2008 Setup Support Files (Version: 10.3.5500.0)
Microsoft SQL Server Compact 3.5 SP2 ENU (Version: 3.5.8080.0)
Microsoft SQL Server Database Publishing Wizard 1.4 (Version: 10.1.2512.8)
Microsoft SQL Server System CLR Types (Version: 10.50.1447.4)
Microsoft SQL Server VSS Writer (Version: 10.3.5500.0)
Microsoft Sync Framework Runtime v1.0 SP1 (x86) (Version: 1.0.3010.0)
Microsoft Sync Framework SDK v1.0 SP1 (Version: 1.0.3010.0)
Microsoft Sync Framework Services v1.0 SP1 (x86) (Version: 1.0.3010.0)
Microsoft Sync Services for ADO.NET v2.0 SP1 (x86) (Version: 2.0.3010.0)
Microsoft Team Foundation Server 2010 Object Model - ENU (Version: 10.0.30319)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.50727.42)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Runtime - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual F# 2.0 Runtime (Version: 10.0.30319)
Microsoft Visual Studio 2005 Tools for Office Runtime
Microsoft Visual Studio 2005 Tools for Office Runtime (Version: 8.0.60940.0)
Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (Version: 10.0.30319)
Microsoft Visual Studio 2010 Office Developer Tools (x86) (Version: 10.0.30319)
Microsoft Visual Studio 2010 Professional - ENU (Version: 10.0.30319)
Microsoft Visual Studio 2010 SharePoint Developer Tools (Version: 10.0.30319)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (Version: 10.0.30319)
Microsoft Visual Studio Macro Tools (Version: 9.0.30729)
Microsoft Windows XP Video Decoder Checkup Utility
Microsoft_VC80_CRT_x86 (Version: 1.00.0000)
Microsoft_VC80_CRT_x86 (Version: 8.0.50727.4053)
Microsoft_VC80_MFC_x86 (Version: 8.0.50727.4053)
Microsoft_VC80_MFCLOC_x86 (Version: 8.0.50727.4053)
Microsoft_VC90_ATL_x86 (Version: 1.00.0000)
Microsoft_VC90_CRT_x86 (Version: 1.00.0000)
Microsoft_VC90_MFC_x86 (Version: 1.00.0000)
Microsoft_VC90_MFCLOC_x86 (Version: 1.00.0000)
Mozilla Firefox 12.0 (x86 en-US) (Version: 12.0)
Mozilla Maintenance Service (Version: 12.0)
Mozilla Thunderbird 14.0 (x86 en-US) (Version: 14.0)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT Redists (Version: 1.0)
MSXML 4.0 SP2 Parser and SDK (Version: 4.20.9818.0)
MSXML 4.0 SP3 Parser (KB2721691) (Version: 4.30.2114.0)
MSXML 4.0 SP3 Parser (KB973685) (Version: 4.30.2107.0)
MSXML 4.0 SP3 Parser (Version: 4.30.2100.0)
NetBeans IDE 6.9.1 (Version: 6.9.1)
Netflix in Windows Media Center (Version: 3.3.101.0)
NewBlue Cartoonr for Vegas
NewBlue VideoFX for Sony Vegas MSPS
Notepad++ (Version: 5.8.7)
NVIDIA Drivers (Version: 1.6)
Octoshape add-in for Adobe Flash Player
Octoshape Streaming Services
OpenOffice.org 3.3 (Version: 3.3.9567)
PDF Settings CS4 (Version: 9.0)
Photobie -- photo editing software from Photobie Design
Photoshop Camera Raw (Version: 5.0)
PlayReady PC Runtime x86 (Version: 1.3.0)
QuickBooks (Version: 21.0.4011.904)
QuickBooks Pro 2011 (Version: 21.0.4011.904)
Quicken 2012 (Version: 21.1.4.22)
QuickTime (Version: 7.71.80.42)
Realtek High Definition Audio Driver (Version: 6.0.1.6316)
RemoteDepositWebClient (Version: 3.01.01.04)
SAMSUNG USB Driver for Mobile Phones (Version: 1.3.1800.0)
Service Pack 3 for SQL Server 2008 (KB2546951) (Version: 10.3.5500.0)
Sony Vocal Eraser (Version: 1.00)
Sound Forge Audio Studio 10.0 (Version: 10.0.152)
Sql Server Customer Experience Improvement Program (Version: 10.3.5500.0)
Suite Shared Configuration CS4 (Version: 1.0)
TalkShoe Live! 2.0
TeamViewer 7 (Version: 7.0.12313)
TrayGear 3.0
Ulead GIF Animator 5 TBYB
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2687310) 32-Bit Edition
uTorrentBar Toolbar (Version: 6.2.7.3)
Vegas Movie Studio HD Platinum 10.0 (Version: 10.0.179)
Vegas Pro 10.0 (Version: 10.0.469)
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU (Version: 4.0.8080.0)
WampServer 2.1
Web Deployment Tool (Version: 1.1.0618)
Windows Driver Package - Digital Check Corporation (TSUSB2) USB (04/02/2010 1.10.0000) (Version: 04/02/2010 1.10.0000)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3508.1109)
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Movie Maker (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live Photo Gallery (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Media Center Add-in for Flash (Version: 4.1.2.0)
Windows Media Player Firefox Plugin (Version: 1.0.0.8)
X-Lite 4 (Version: 41.6.3214)
Xvid Video Codec (Version: 1.3.0)

========================= Memory info: ===================================

Percentage of memory in use: 51%
Total physical RAM: 1982.55 MB
Available physical RAM: 963.06 MB
Total Pagefile: 3965.11 MB
Available Pagefile: 2403.09 MB
Total Virtual: 2047.88 MB
Available Virtual: 1933.84 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:465.66 GB) (Free:300.47 GB) NTFS
3 Drive e: (video) (Fixed) (Total:232.88 GB) (Free:231.34 GB) NTFS
4 Drive f: (X16-81637VS2010ProMSDN) (CDROM) (Total:2.19 GB) (Free:0 GB) UDF
5 Drive i: (WD SmartWare) (CDROM) (Total:0.6 GB) (Free:0 GB) UDF
6 Drive j: (My Book) (Fixed) (Total:930.86 GB) (Free:862.85 GB) NTFS

========================= Users: ========================================

User accounts for \\CHIPS-DESKTOP

Administrator Chip Guest
QBDataServiceUser21


**** End of log ****


Farbar Service Scanner Version: 06-08-2012
Ran by Chip (administrator) on 11-08-2012 at 22:50:00
Running from "C:\Users\Chip\Downloads"
Microsoft Windows 7 Home Premium Service Pack 1 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============
mpsdrv Service is not running. Checking service configuration:
The start type of mpsdrv service is OK.
The ImagePath of mpsdrv service is OK.

MpsSvc Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.

bfe Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open bfe registry key. The service key does not exist.


Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============
wscsvc Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.


Windows Update:
============
wuauserv Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.

BITS Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open BITS registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open BITS registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open BITS registry key. The service key does not exist.


Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============
Checking Start type of SharedAccess: ATTENTION!=====> Unable to retrieve start type of SharedAccess. The value does not exist.
Checking ImagePath of SharedAccess: ATTENTION!=====> Unable to retrieve ImagePath of SharedAccess. The value does not exist.
Checking ServiceDll of SharedAccess: ATTENTION!=====> Unable to retrieve ServiceDll of SharedAccess. The value does not exist.


File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcore.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\system32\dnsrslvr.dll => MD5 is legit
C:\Windows\system32\mpssvc.dll => MD5 is legit
C:\Windows\system32\bfe.dll => MD5 is legit
C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll => MD5 is legit
C:\Windows\system32\vssvc.exe => MD5 is legit
C:\Windows\system32\wscsvc.dll => MD5 is legit
C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\system32\wuaueng.dll => MD5 is legit
C:\Windows\system32\qmgr.dll => MD5 is legit
C:\Windows\system32\es.dll => MD5 is legit
C:\Windows\system32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\system32\ipnathlp.dll => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit


**** End of log ****


# AdwCleaner v1.800 - Logfile created 08/11/2012 at 22:51:15
# Updated 01/08/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (32 bits)
# User : Chip - CHIPS-DESKTOP
# Running from : C:\Users\Chip\Downloads\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Users\Chip\AppData\Local\Conduit
Folder Deleted : C:\Users\Chip\AppData\Local\TempDir
Folder Deleted : C:\Users\Chip\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Chip\AppData\LocalLow\ConduitEngine
Folder Deleted : C:\Users\Chip\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Chip\AppData\LocalLow\uTorrentBar
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\ConduitEngine
Folder Deleted : C:\Program Files\uTorrentBar
File Deleted : C:\Users\Chip\AppData\Roaming\Mozilla\Firefox\Profiles\vi8ttgd4.default\searchplugins\MyStart Search.xml

***** [Registry] *****

[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2786678
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\conduitEngine
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\IM
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\Zugo
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\Incredibar.IncredibarHlpr
Key Deleted : HKLM\SOFTWARE\Classes\Incredibar.IncredibarHlpr.1
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\conduitEngine
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentBar Toolbar
Key Deleted : HKLM\SOFTWARE\uTorrentBar

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A1E97674-046F-4146-A754-18082A9C49A1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{91EE21FF-2CA8-4919-B068-B7B193AFE3B1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6DB06070-ED1F-41CC-9A8C-BB80C8237AC0}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1E97674-046F-4146-A754-18082A9C49A1}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1E97674-046F-4146-A754-18082A9C49A1}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{30F9B915-B755-4826-820B-08FBA6BD249D}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.7601.17514

[OK] Registry is clean.

-\\ Mozilla Firefox v12.0 (en-US)

Profile name : default
File : C:\Users\Chip\AppData\Roaming\Mozilla\Firefox\Profiles\vi8ttgd4.default\prefs.js

C:\Users\Chip\AppData\Roaming\Mozilla\Firefox\Profiles\vi8ttgd4.default\user.js ... Deleted !

Deleted : user_pref("extensions.incredibar_i.aflt", "orgnl");
Deleted : user_pref("extensions.incredibar_i.dfltLng", "");
Deleted : user_pref("extensions.incredibar_i.did", "10616");
Deleted : user_pref("extensions.incredibar_i.excTlbr", "false");
Deleted : user_pref("extensions.incredibar_i.hardId", "88dd1912000000000000001731106ec9");
Deleted : user_pref("extensions.incredibar_i.id", "88dd1912000000000000001731106ec9");
Deleted : user_pref("extensions.incredibar_i.installerproductid", "26");
Deleted : user_pref("extensions.incredibar_i.instlDay", "15396");
Deleted : user_pref("extensions.incredibar_i.instlRef", "");
Deleted : user_pref("extensions.incredibar_i.ms_url_id", "");
Deleted : user_pref("extensions.incredibar_i.newTab", false);
Deleted : user_pref("extensions.incredibar_i.ppd", "26");
Deleted : user_pref("extensions.incredibar_i.prdct", "incredibar");
Deleted : user_pref("extensions.incredibar_i.productid", "26");
Deleted : user_pref("extensions.incredibar_i.prtnrId", "Incredibar");
Deleted : user_pref("extensions.incredibar_i.smplGrp", "none");
Deleted : user_pref("extensions.incredibar_i.tlbrId", "base");
Deleted : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6PQpxfae58&loc=IB[...]
Deleted : user_pref("extensions.incredibar_i.upn2", "6PQpxfae58");
Deleted : user_pref("extensions.incredibar_i.upn2n", "92542439084289334");
Deleted : user_pref("extensions.incredibar_i.vrsn", "1.5.3.27");
Deleted : user_pref("extensions.incredibar_i.vrsnTs", "1.5.3.2721:14:43");
Deleted : user_pref("extensions.incredibar_i.vrsni", "1.5.3.27");

-\\ Google Chrome v21.0.1180.75

File : C:\Users\Chip\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted : "homepage": "hxxp://mystart.incredibar.com/mb123?a=6PQpxfae58&i=26",
Deleted : "description": "The fastest way to search the web.",
Deleted : "homepage": "hxxp://mystart.incredibar.com/mb123?a=6PQpxfae58&i=26",

*************************

AdwCleaner[S1].txt - [7039 octets] - [11/08/2012 22:51:15]

########## EOF - C:\AdwCleaner[S1].txt - [7167 octets] ##########

#6 narenxp

narenxp

    Forum Addict

  • BC Advisor
  • PipPipPipPipPipPip
  • 16,365 posts
  • Gender:Male
  • Location:India

Posted 12 August 2012 - 04:30 AM

Open your C drive

On top,click on Organize-folder and search options

Click on View tab and scroll down

Check mark Show hidden files
Uncheck Hide operating system files


Click ok,now go to

C:\Users\Chip\AppData\Local\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}
C:\Windows\Installer\{a78ab9a9-0b8b-ea57-bcc8-d78057205226}

delete the folders

Post the new system look log

Download

MpsSvc
BFE
wscsvc
defender
wuauserv
BITS
Sharedaccess

Launch them ,click YES when you get UAC prompt

restart the PC


Download

Windows repair tool

Extract and launch the Repair_Windows.exe file

Click on Start repairs tab-click on Start

check mark following options alone

Reset registry permissions
reset file permissions
Repair WMI
Repair Windows Firewall.
Remove Policies Set By Infections
Repair Winsock & DNS Cache
Repair hosts


Checkmark Restart System When Finished option
click the Start button

System should restart after repair

Post the FSS log

#7 chipk1

chipk1

    New Member

  • Members
  • Pip
  • 8 posts

Posted 12 August 2012 - 07:37 AM

Farbar Service Scanner Version: 06-08-2012
Ran by Chip (administrator) on 12-08-2012 at 08:38:33
Running from "C:\Users\Chip\Downloads"
Microsoft Windows 7 Home Premium Service Pack 1 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcore.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\system32\dnsrslvr.dll => MD5 is legit
C:\Windows\system32\mpssvc.dll => MD5 is legit
C:\Windows\system32\bfe.dll => MD5 is legit
C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll => MD5 is legit
C:\Windows\system32\vssvc.exe => MD5 is legit
C:\Windows\system32\wscsvc.dll => MD5 is legit
C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\system32\wuaueng.dll => MD5 is legit
C:\Windows\system32\qmgr.dll => MD5 is legit
C:\Windows\system32\es.dll => MD5 is legit
C:\Windows\system32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\system32\ipnathlp.dll => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit


**** End of log ****

#8 narenxp

narenxp

    Forum Addict

  • BC Advisor
  • PipPipPipPipPipPip
  • 16,365 posts
  • Gender:Male
  • Location:India

Posted 12 August 2012 - 08:08 AM

Download

systemlook

Launch it and copy this script and paste in the BOX

:filefind
services.exe.old
:folderfind
{a78ab9a9-0b8b-ea57-bcc8-d78057205226}

Click on LOOK,post the generated log

#9 chipk1

chipk1

    New Member

  • Members
  • Pip
  • 8 posts

Posted 12 August 2012 - 08:30 AM

SystemLook 30.07.11 by jpshortstuff
Log created at 09:20 on 12/08/2012 by Chip
Administrator - Elevation successful

========== filefind ==========

Searching for "services.exe.old"
No files found.

========== folderfind ==========

Searching for "{a78ab9a9-0b8b-ea57-bcc8-d78057205226}"
No folders found.

-= EOF =-

#10 narenxp

narenxp

    Forum Addict

  • BC Advisor
  • PipPipPipPipPipPip
  • 16,365 posts
  • Gender:Male
  • Location:India

Posted 12 August 2012 - 09:12 AM

That looks good

Download

TFC

Launch it,it will close all running programs

click on START,it should ask for reboot

Turn off your system restore,restart the PC,create a new restore point

http://windows.microsoft.com/en-US/windows7/Turn-System-Restore-on-or-off

update your flash player

Update your JAVA from here

http://java.com/en/download/inc/windows_upgrade_xpi.jsp

Update your antivirus frequently,do not click on suspicious links

Safe surfing :)

#11 chipk1

chipk1

    New Member

  • Members
  • Pip
  • 8 posts

Posted 12 August 2012 - 09:58 AM

Thanks! You rock!

#12 narenxp

narenxp

    Forum Addict

  • BC Advisor
  • PipPipPipPipPipPip
  • 16,365 posts
  • Gender:Male
  • Location:India

Posted 12 August 2012 - 10:01 AM

You're most welcome :)




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users