Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Google CAPTCHA challenge


  • This topic is locked This topic is locked
67 replies to this topic

#1 WilliamBuell

WilliamBuell

  • Members
  • 53 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NYC USA
  • Local time:01:19 AM

Posted 23 February 2012 - 02:03 PM

I am running Windows 7 on a Toshiba Qosmio Model Q7170 using Microsoft Essentials Antivirus, also paid version of Lavasoft Ad-Aware, Spybot Search & Destroy (batch scan only no teatimer), and malwarebytes.org free scanner.

I use Firefox with NOSCRIPT for Firefox, Chrome for Google Plus and Gmail, and occasional Internet Explorer.

I realize that tracking cookies are not malware but I wanted to see if I could totally eliminate them. I purchased Lavasoft Ad-Aware with the thought that it would
catch tracking cookies real-time but it only caught them during batch scans.

I configured Chrome and Firefox to reject cookies except for sites in the exception list.

My Firefox add-ins were Taco with Abine, Cookie Monster, Lavasoft Tool Bar, Ad-Block Plus and Cookie Monster

Every time I ran a Google search in Firefox I received a CAPTCHA challenge because a high level of activity was detected from my computer. When I searched from Chrome or I.E. there was
no Captcha challenge.

I have two accounts on my machine, a non-admin user acct where I work all day long and then the superadmin account created when I set up the Toshiba.

I disabled in Firefox the following add-ins and the Captcha Challenge stopped: Lavasoft tool bar, Cookie Monster, Ad-Block Plus, Cookie Monster

Regarding the CAPTCHA challenge, Google suggested HIJACKTHIS as well as Spybot Search and Destroy.

I also installed Nixory which I use only for a batch scan for cookies. I tried to integrate the Nixory active shield but it crashes on this machine.

Attached is the HIJACKTHIS log which I just now generated.

Oddly enough, today is the first day that I am getting NO tracking cookies in any of the scans.

I had some difficulty getting HijackThis to run as it did not have sufficient permissions. The instructions mention that in VISTA one simply right clicks and chooses
RUN AS SUPERVISOR. Obviously this option is not available in Windows 7.

Finally, I right clicked on the program and chose the CHECK FOR INCOMPATIBILITIES. It was not intuitively obvious but eventually I stumbled across the option to
RUN AS SUPERVISOR, and then HijackThis ran just fine.

Thanks in advance for checking the attached HijackThis log and for your feedback.



I

Attached Files


Edited by WilliamBuell, 23 February 2012 - 02:07 PM.


BC AdBot (Login to Remove)

 


#2 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:02:19 AM

Posted 23 February 2012 - 03:14 PM

Hello and Welcome to the forums!

My name is Gringo and I'll be glad to help you with your computer problems.

Somethings to remember while we are working together.

  • Do not run any other tool untill instructed to do so!
  • Please Do not Attach logs or put in code boxes.
  • Tell me about any problems that have occurred during the fix.
  • Tell me of any other symptoms you may be having as these can help also.
  • Do not run anything while running a fix.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

Click on the Watch Topic Button and select Immediate Notification and click on proceed, this will help you to get notified faster when I have replied and make the cleaning process faster.

In order for me to see the status of the infection I will need a new set of logs to start with.

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

DeFogger:

  • Please download DeFogger to your desktop.

    Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger may ask you to reboot the machine, if it does - click OK
Do not re-enable these drivers until otherwise instructed.

Download DDS:

  • Please download DDS by sUBs from one of the links below and save it to your desktop:

    Posted Image
    Download DDS and save it to your desktop

    Link1
    Link2
    Link3

    Please disable any anti-malware program that will block scripts from running before running DDS.

    • Double-Click on dds.scr and a command window will appear. This is normal.
    • Shortly after two logs will appear:
    • DDS.txt
    • Attach.txt
  • A window will open instructing you save & post the logs
  • Save the logs to a convenient place such as your desktop
  • Copy the contents of both logs & post in your next reply

information and logs:

  • In your next post I need the following

  • .logs from DDS
  • let me know of any problems you may have had

Gringo

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#3 WilliamBuell

WilliamBuell
  • Topic Starter

  • Members
  • 53 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NYC USA
  • Local time:01:19 AM

Posted 23 February 2012 - 03:56 PM

.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_30
Run by William at 15:52:54 on 2012-02-23
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6051.3770 [GMT -5:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\nvvsvc.exe
C:\windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\windows\system32\nvvsvc.exe
C:\windows\system32\WLANExt.exe
C:\windows\system32\conhost.exe
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe
C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
C:\windows\system32\ThpSrv.exe
C:\windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\taskhost.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\SymcPCCULaunchSvc.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\ThpSrv.exe
C:\Program Files\TOSHIBA\TECO\Teco.exe
C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\TOSHIBA\FlashCards\Hotkey\TcrdKBB.exe
C:\Program Files (x86)\Toshiba\Utilities\KeNotify.exe
C:\Program Files (x86)\Toshiba\TOSHIBA Sleep Utility\TSleepSrv.exe
C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Browny02\BrYNSvc.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\windows\system32\DllHost.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Users\Buell\Desktop\NixoryStandAlone\nixory-1.2.4-win32-standalone\nixory.exe
C:\Users\Buell\Desktop\NixoryStandAlone\nixory-1.2.4-win32-standalone\nixory.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\igfxsrvc.exe
C:\windows\SysWOW64\cmd.exe
C:\windows\system32\conhost.exe
C:\windows\SysWOW64\cscript.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.ask.com/?l=dis&o=100000018&gct=hp
uDefault_Page_URL = hxxp://start.toshiba.com
uInternet Settings,ProxyOverride = <local>
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO: PlusIEEventHelper Class: {551a852f-39a6-44a7-9c13-afbec9185a9d} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll
BHO: Ad-Aware Security Toolbar: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: TOSHIBA Media Controller Plug-in: {f3c88694-effa-4d78-b409-54b7b2535b14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
TB: Ad-Aware Security Toolbar: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
uRun: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
uRun: [Google Update] "C:\Users\William\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
mRun: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
mRun: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP
mRun: [KeNotify] "C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe" LPCM
mRun: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
mRun: [TSleepSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
mRun: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
mRun: [ToshibaAppPlace] "C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe"
mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe" UNATTENDED
mRun: [IndexSearch] "C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe"
mRun: [PaperPort PTD] "C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe"
mRun: [PPort12reminder] "C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
mRun: [PDFHook] C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe
mRun: [PDF5 Registry Controller] C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe
mRun: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun
mRun: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Ad-Aware Browsing Protection] "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
dRunOnce: [adaware] reg.exe delete "HKCU\Software\AppDataLow\Software\adaware" /f
dRunOnce: [adaware_XP] reg.exe delete "HKCU\Software\adaware" /f
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files (x86)\Paltalk Messenger\Paltalk.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
TCP: DhcpNameServer = 10.0.1.1
TCP: Interfaces\{7C51D7C5-B558-4C3F-9159-EEB0ED32C3C0} : DhcpNameServer = 10.0.1.1
TCP: Interfaces\{F1D9BEAA-4F24-4E86-A4DA-42EFF001186D} : DhcpNameServer = 100.100.0.102
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: C:\windows\SysWOW64\nvinit.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO-X64: PlusIEEventHelper Class: {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll
BHO-X64: Ad-Aware Security Toolbar: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll
BHO-X64: Ad-Aware Security Toolbar - No File
BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: TOSHIBA Media Controller Plug-in: {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
TB-X64: Ad-Aware Security Toolbar: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\adawaretb\adawareDx.dll
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB-X64: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
mRun-x64: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
mRun-x64: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP
mRun-x64: [KeNotify] "C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe" LPCM
mRun-x64: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
mRun-x64: [TSleepSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
mRun-x64: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
mRun-x64: [ToshibaAppPlace] "C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe"
mRun-x64: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe" UNATTENDED
mRun-x64: [IndexSearch] "C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe"
mRun-x64: [PaperPort PTD] "C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe"
mRun-x64: [PPort12reminder] "C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
mRun-x64: [PDFHook] C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe
mRun-x64: [PDF5 Registry Controller] C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe
mRun-x64: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun
mRun-x64: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [Ad-Aware Browsing Protection] "C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
IE-X64: {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files (x86)\Paltalk Messenger\Paltalk.exe
AppInit_DLLs-X64: C:\windows\SysWOW64\nvinit.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\William\AppData\Roaming\Mozilla\Firefox\Profiles\qrxsguuh.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.com
FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\William\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: C:\Users\William\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: C:\Users\William\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;C:\windows\system32\DRIVERS\Lbd.sys --> C:\windows\system32\DRIVERS\Lbd.sys [?]
R0 nvpciflt;nvpciflt;C:\windows\system32\DRIVERS\nvpciflt.sys --> C:\windows\system32\DRIVERS\nvpciflt.sys [?]
R0 Thpdrv;TOSHIBA HDD Protection Driver;C:\windows\system32\DRIVERS\thpdrv.sys --> C:\windows\system32\DRIVERS\thpdrv.sys [?]
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;C:\windows\system32\DRIVERS\Thpevm.SYS --> C:\windows\system32\DRIVERS\Thpevm.SYS [?]
R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\windows\system32\DRIVERS\tos_sps64.sys --> C:\windows\system32\DRIVERS\tos_sps64.sys [?]
R1 MpFilter;Microsoft Malware Protection Driver;C:\windows\system32\DRIVERS\MpFilter.sys --> C:\windows\system32\DRIVERS\MpFilter.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys --> C:\windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624]
R2 Norton PC Checkup Application Launcher;Toshiba Laptop Checkup Application Launcher;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\SymcPCCULaunchSvc.exe [2011-12-14 123320]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-12-14 1997416]
R2 PCCUJobMgr;Common Client Job Manager Service;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe [2011-12-14 126392]
R2 PDFProFiltSrvPP;PDFProFiltSrvPP;C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [2010-3-9 144672]
R2 RosettaStoneDaemon;RosettaStoneDaemon;C:\Program Files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe [2011-3-31 1646056]
R2 sbapifs;sbapifs;C:\windows\system32\DRIVERS\sbapifs.sys --> C:\windows\system32\DRIVERS\sbapifs.sys [?]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776]
R2 TeamViewer7;TeamViewer 7;C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-2-18 3027840]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:\Program Files\TOSHIBA\TECO\TecoService.exe [2011-5-24 294848]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;C:\windows\system32\DRIVERS\TVALZFL.sys --> C:\windows\system32\DRIVERS\TVALZFL.sys [?]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-12-14 2656280]
R3 BrYNSvc;BrYNSvc;C:\Program Files (x86)\Browny02\BrYNSvc.exe [2012-1-21 245760]
R3 CeKbFilter;CeKbFilter;C:\windows\system32\DRIVERS\CeKbFilter.sys --> C:\windows\system32\DRIVERS\CeKbFilter.sys [?]
R3 IntcDAud;Intel® Display Audio;C:\windows\system32\DRIVERS\IntcDAud.sys --> C:\windows\system32\DRIVERS\IntcDAud.sys [?]
R3 MEIx64;Intel® Management Engine Interface;C:\windows\system32\DRIVERS\HECIx64.sys --> C:\windows\system32\DRIVERS\HECIx64.sys [?]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\windows\system32\DRIVERS\MpNWMon.sys --> C:\windows\system32\DRIVERS\MpNWMon.sys [?]
R3 NisDrv;Microsoft Network Inspection System;C:\windows\system32\DRIVERS\NisDrvWFP.sys --> C:\windows\system32\DRIVERS\NisDrvWFP.sys [?]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\windows\system32\DRIVERS\nusb3hub.sys --> C:\windows\system32\DRIVERS\nusb3hub.sys [?]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\windows\system32\DRIVERS\nusb3xhc.sys --> C:\windows\system32\DRIVERS\nusb3xhc.sys [?]
R3 PGEffect;Pangu effect driver;C:\windows\system32\DRIVERS\pgeffect.sys --> C:\windows\system32\DRIVERS\pgeffect.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\windows\system32\DRIVERS\Rt64win7.sys --> C:\windows\system32\DRIVERS\Rt64win7.sys [?]
R3 Sftfs;Sftfs;C:\windows\system32\DRIVERS\Sftfslh.sys --> C:\windows\system32\DRIVERS\Sftfslh.sys [?]
R3 Sftplay;Sftplay;C:\windows\system32\DRIVERS\Sftplaylh.sys --> C:\windows\system32\DRIVERS\Sftplaylh.sys [?]
R3 Sftredir;Sftredir;C:\windows\system32\DRIVERS\Sftredirlh.sys --> C:\windows\system32\DRIVERS\Sftredirlh.sys [?]
R3 Sftvol;Sftvol;C:\windows\system32\DRIVERS\Sftvollh.sys --> C:\windows\system32\DRIVERS\Sftvollh.sys [?]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496]
R3 TMachInfo;TMachInfo;C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe [2011-12-14 57216]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2011-6-10 138152]
R3 TPCHSrv;TPCH Service;C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2011-7-1 828856]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-14 136176]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-12-23 2152152]
S3 BtFilter;Bluetooth LowerFilter Class Filter Driver;C:\windows\system32\DRIVERS\btfilter.sys --> C:\windows\system32\DRIVERS\btfilter.sys [?]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-14 136176]
S3 JMCR;JMCR;C:\windows\system32\DRIVERS\jmcr.sys --> C:\windows\system32\DRIVERS\jmcr.sys [?]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 ser2at;ATEN USB to Serial port driver;C:\windows\system32\DRIVERS\ser2at64.sys --> C:\windows\system32\DRIVERS\ser2at64.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\windows\system32\drivers\tsusbflt.sys --> C:\windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\system32\drivers\TsUsbGD.sys --> C:\windows\system32\drivers\TsUsbGD.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\system32\Wat\WatAdminSvc.exe --> C:\windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2012-02-23 16:22:45 69000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D38D744D-6441-4161-B623-BFEFF370DE62}\offreg.dll
2012-02-23 16:22:02 8643640 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D38D744D-6441-4161-B623-BFEFF370DE62}\mpengine.dll
2012-02-23 09:04:41 388096 ----a-r- C:\Users\William\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-02-23 08:56:53 -------- d-----w- C:\Program Files (x86)\Trend Micro
2012-02-23 04:08:41 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2012-02-23 04:08:41 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2012-02-21 11:09:49 -------- d-----w- C:\Users\William\AppData\Local\Diagnostics
2012-02-18 19:10:23 -------- d-----w- C:\Program Files (x86)\TeamViewer
2012-02-17 06:11:24 -------- d-----w- C:\Users\William\AppData\Roaming\Paltalk
2012-02-17 06:11:21 -------- d-----w- C:\windows\Paltalk Messenger
2012-02-17 06:11:20 -------- d-----w- C:\Program Files (x86)\Paltalk Messenger
2012-02-17 05:53:38 -------- d-----w- C:\Users\William\AppData\Local\APN
2012-02-16 09:14:44 -------- d-----w- C:\Program Files (x86)\Lame For Audacity
2012-02-16 09:05:57 -------- d-----w- C:\Program Files (x86)\Audacity 1.3 Beta (Unicode)
2012-02-15 07:59:10 -------- d-----w- C:\Users\William\AppData\Local\adaware
2012-02-15 07:58:58 -------- d-----w- C:\Program Files (x86)\adawaretb
2012-02-15 06:32:54 2382848 ----a-w- C:\windows\SysWow64\mshtml.tlb
2012-02-15 06:32:54 2382848 ----a-w- C:\windows\System32\mshtml.tlb
2012-02-15 06:32:13 141112 ----a-w- C:\Program Files (x86)\Internet Explorer\sqmapi.dll
2012-02-15 06:31:49 174392 ----a-w- C:\Program Files\Internet Explorer\sqmapi.dll
2012-02-15 06:31:08 304640 ----a-w- C:\Program Files\Internet Explorer\IEShims.dll
2012-02-15 06:30:52 194048 ----a-w- C:\Program Files (x86)\Internet Explorer\IEShims.dll
2012-02-15 06:30:35 2308096 ----a-w- C:\windows\System32\jscript9.dll
2012-02-15 06:29:14 1798656 ----a-w- C:\windows\SysWow64\jscript9.dll
2012-02-15 06:27:44 1427456 ----a-w- C:\windows\SysWow64\inetcpl.cpl
2012-02-15 06:27:28 1493504 ----a-w- C:\windows\System32\inetcpl.cpl
2012-02-15 06:27:04 1127424 ----a-w- C:\windows\SysWow64\wininet.dll
2012-02-15 06:26:47 1390080 ----a-w- C:\windows\System32\wininet.dll
2012-02-15 06:25:42 678912 ----a-w- C:\Program Files (x86)\Internet Explorer\iedvtool.dll
2012-02-15 06:25:26 887296 ----a-w- C:\Program Files\Internet Explorer\iedvtool.dll
2012-02-15 04:08:22 509952 ----a-w- C:\windows\System32\ntshrui.dll
2012-02-15 04:08:22 442880 ----a-w- C:\windows\SysWow64\ntshrui.dll
2012-02-15 04:08:21 515584 ----a-w- C:\windows\System32\timedate.cpl
2012-02-15 04:08:21 478720 ----a-w- C:\windows\SysWow64\timedate.cpl
2012-02-15 04:08:21 3145728 ----a-w- C:\windows\System32\win32k.sys
2012-02-15 04:08:20 498688 ----a-w- C:\windows\System32\drivers\afd.sys
2012-02-15 04:08:17 690688 ----a-w- C:\windows\SysWow64\msvcrt.dll
2012-02-15 04:08:17 634880 ----a-w- C:\windows\System32\msvcrt.dll
2012-02-14 23:32:32 72280 ----a-w- C:\windows\System32\drivers\sbapifs.sys
2012-02-11 08:31:16 -------- d-----w- C:\Users\William\AppData\Local\Sunbelt Software
2012-02-10 15:11:52 927800 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{358A79F5-A006-42C4-85F3-D16C84008660}\gapaengine.dll
2012-02-10 15:11:52 917840 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2012-02-09 19:46:00 16432 ----a-w- C:\windows\System32\lsdelete.exe
2012-02-09 18:17:22 55384 ----a-w- C:\windows\System32\drivers\SBREDrv.sys
2012-02-09 18:11:51 -------- d-----w- C:\ProgramData\Ad-Aware Browsing Protection
2012-02-09 18:11:50 -------- d-----w- C:\Program Files (x86)\Toolbar Cleaner
2012-02-09 18:11:41 69376 ----a-w- C:\windows\System32\drivers\Lbd.sys
2012-02-09 18:11:37 -------- d-----w- C:\Program Files (x86)\Lavasoft
2012-02-03 07:43:42 8643640 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-02-03 00:23:27 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2012-02-03 00:23:24 -------- d-----w- C:\Program Files\Microsoft Security Client
2012-02-02 21:11:39 -------- d-----w- C:\ProgramData\Toshiba Book Place
2012-02-02 21:01:31 -------- d-----w- C:\Users\William\AppData\Roaming\Book Place
2012-02-01 20:32:15 -------- d-----w- C:\Users\William\AppData\Roaming\Malwarebytes
2012-02-01 20:32:11 -------- d-----w- C:\ProgramData\Malwarebytes
2012-02-01 20:32:10 23152 ----a-w- C:\windows\System32\drivers\mbam.sys
2012-02-01 20:32:10 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-01-31 10:10:54 -------- d-----w- C:\Program Files (x86)\UEFI WinFlash
2012-01-31 02:46:57 -------- d-----w- C:\OldDell
2012-01-25 22:46:00 -------- d-----w- C:\Program Files (x86)\Common Files\Macrovision Shared
2012-01-25 22:45:15 -------- d-----w- C:\ProgramData\Rosetta Stone Backups
2012-01-25 22:45:15 -------- d-----w- C:\ProgramData\Rosetta Stone
2012-01-25 22:42:45 -------- d-----w- C:\ProgramData\RosettaStoneLtdServices
2012-01-25 22:42:45 -------- d-----w- C:\Program Files (x86)\RosettaStoneLtdServices
2012-01-25 22:42:25 -------- d-----w- C:\Program Files (x86)\Rosetta Stone
.
==================== Find3M ====================
.
2012-02-23 07:06:36 414368 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-14 07:42:35 472808 ----a-w- C:\windows\SysWow64\deployJava1.dll
2012-01-31 12:44:20 279656 ------w- C:\windows\System32\MpSigStub.exe
2011-12-14 19:41:48 20592 ----a-w- C:\windows\System32\drivers\CeKbFilter.sys
.
============= FINISH: 15:53:29.37 ===============

#4 WilliamBuell

WilliamBuell
  • Topic Starter

  • Members
  • 53 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NYC USA
  • Local time:01:19 AM

Posted 23 February 2012 - 03:57 PM

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 1/21/2012 12:09:01 PM
System Uptime: 2/23/2012 11:17:10 AM (4 hours ago)
.
Motherboard: TOSHIBA | | PGRAA
Processor: Intel® Core™ i5-2450M CPU @ 2.50GHz | CPU 1 | 775/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 580 GiB total, 523.575 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP28: 2/14/2012 2:42:04 AM - Removed Java™ 6 Update 30
RP29: 2/14/2012 2:42:24 AM - Installed Java™ 6 Update 30
RP30: 2/14/2012 2:14:02 PM - Windows Update
RP31: 2/15/2012 1:23:58 AM - Windows Update
RP32: 2/16/2012 3:00:13 AM - Windows Update
RP33: 2/19/2012 12:12:12 PM - Windows Update
RP34: 2/23/2012 3:00:13 AM - Windows Update
RP35: 2/23/2012 3:56:21 AM - Installed HiJackThis
RP36: 2/23/2012 4:04:10 AM - Installed HiJackThis
RP37: 2/23/2012 3:44:05 PM - GringoBleepingComputer
.
==== Installed Programs ======================
.
Ad-Aware
Ad-Aware Browsing Protection
Ad-Aware Security Toolbar
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Reader X (10.1.2) MUI
Amazon Links
Atheros Driver Installation Program
Audacity 1.3.14 (Unicode)
Brother MFL-Pro Suite HL-2280DW
CoPilot Health Management System
D3DX10
Google Chrome
Google Talk Plugin
Google Update Helper
HiJackThis
Intel® Management Engine Components
Intel® Processor Graphics
Intel® Rapid Storage Technology
iSEEK AnswerWorks English Runtime
Java Auto Updater
Java™ 6 Update 30
JMicron Flash Media Controller Driver
Junk Mail filter update
Label@Once 1.0
LAME v3.99.3 (for Windows)
Malwarebytes Anti-Malware version 1.60.1.1000
Mesh Runtime
Microsoft Office 2010
Microsoft Office Click-to-Run 2010
Microsoft Office Starter 2010 - English
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Mozilla Firefox 10.0.2 (x86 en-US)
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB973685)
Nuance PaperPort 12
Nuance PDF Viewer Plus
NVIDIA 3D Vision Controller Driver
NVIDIA PhysX
Paltalk Messenger
PlayReady PC Runtime x86
Quicken 2012
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Renesas Electronics USB 3.0 Host Controller Driver
Rosetta Stone Ltd Services
Rosetta Stone TOTALe
Scansoft PDF Professional
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Skype Launcher
Skype™ 5.5
Spybot - Search & Destroy
TeamViewer 7
Toshiba App Place
TOSHIBA Application Installer
TOSHIBA Assist
Toshiba Book Place
TOSHIBA Bulletin Board
TOSHIBA Face Recognition
TOSHIBA Flash Cards Support Utility
TOSHIBA Hardware Setup
Toshiba Laptop Checkup
TOSHIBA Media Controller
TOSHIBA Media Controller Plug-in
Toshiba Online Backup
TOSHIBA Quality Application
TOSHIBA Recovery Media Creator
TOSHIBA ReelTime
TOSHIBA Resolution+ Plug-in for Windows Media Player
TOSHIBA Service Station
TOSHIBA Sleep Utility
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
TOSHIBA VIDEO PLAYER
TOSHIBA Web Camera Application
TOSHIBARegistration
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Utility Common Driver
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
.
==== Event Viewer Messages From Past Week ========
.
2/23/2012 3:53:04 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
2/23/2012 2:03:57 AM, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
2/23/2012 2:03:37 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
2/22/2012 11:46:35 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
2/22/2012 11:30:59 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
2/21/2012 7:41:53 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
2/21/2012 6:48:45 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
2/21/2012 6:22:39 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
2/21/2012 6:04:37 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
2/21/2012 5:58:30 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
2/21/2012 2:59:03 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
2/21/2012 12:05:40 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
2/21/2012 11:42:34 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
2/20/2012 9:43:25 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
2/19/2012 12:01:36 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
2/18/2012 11:49:02 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
2/18/2012 1:25:07 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
2/17/2012 10:10:26 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
2/17/2012 1:13:22 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
.
==== End Of File ===========================

#5 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:02:19 AM

Posted 23 February 2012 - 04:03 PM

Hello

I Would like you to do the following.

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links. I want you to save it to the desktop and run it from there.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#6 WilliamBuell

WilliamBuell
  • Topic Starter

  • Members
  • 53 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NYC USA
  • Local time:01:19 AM

Posted 23 February 2012 - 05:11 PM

I logged into my second computer to ask you HOW LONG the COMBOFIX will run. It seems to have finished its first phase with no problems and it rebooted. Now it keeps displaying a blank window repeatedly that moves about the screen. Is this normal? How many hours should I let it run? How will I know if it is in an infinite loop? Also.... once it is all done will you be able to tell me anything about what was wrong with the computer or what malware was found? Thanks!

#7 WilliamBuell

WilliamBuell
  • Topic Starter

  • Members
  • 53 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NYC USA
  • Local time:01:19 AM

Posted 23 February 2012 - 05:48 PM

Sorry to post several times but I am beginning to feel quite nervous. Combofix seemed to finish properly and then rebooted the computer. Now that it has rebooted, it just keeps flashing what appear to be empty windows on the screen for what seems like an hour or two. Is this NORMAL? Should I just
let it run like that all night long or for 24 hours. How would I know if it is in an endless loop. Is there a strong possibility that my Toshiba will be useless and that I must send it back to the factory. The first thing I did when I got the machine was burn the 4 dvds of the OS image and a utility disk. Will I have some hope of restoring it back to out of the box condition. PLEASE give me some sort of answer. Nothing in the instructions indicate that it would spend hours doing this strange behavior. Is there any hope that reverting to the restore point would render the machine usable. I did send a HIJACKTHIS log with my initial post. I can only hope that you counsel people to run the COMBOFIX when you see something serious in the logs. Now that I read up on COMBOFIX I feel more and more nervous that it might render my machine unusable. Thanks for your feedback!

#8 WilliamBuell

WilliamBuell
  • Topic Starter

  • Members
  • 53 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NYC USA
  • Local time:01:19 AM

Posted 23 February 2012 - 06:31 PM

I have been doing a lot of Google searches on COMBOFIX to learn whether this behavior for several hours after reboot is normal. I did find someone with a problem who was given the following advice from Bleeping Computer:

Open Task Manager and look for the following ComboFix related processes (some have a .3XE extension):
PEV.exe
NirCmd.3XE
PEV.3XE
SED
GREP
any file that has the extension *.3XE

One at a time, right-click and select End Process. If doing that did not free ComboFix and allow it to continue, then you will need to reboot the computer manually.

=========

What I observe on the screen is a succession of windows the FIRST of which says C:\combofix and the SECOND Of which says pev.3XE

IS THIS NORMAL? Will the process come to a normal end of job? How will I know if it is necessary to kill tasks with the TASK MANAGER? Thanks!

#9 WilliamBuell

WilliamBuell
  • Topic Starter

  • Members
  • 53 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NYC USA
  • Local time:01:19 AM

Posted 23 February 2012 - 08:30 PM

Gringo! Thanks for the quick response to my message! I shutdown the computer and rebooted as ADMINISTRATOR. Now there is ONE screen which says

FIND3M - after about 5 minutes it assures me that the report will pop up shortly and be found at C:\COMBOFIX.TXT
at which point I shall log into bleepingcomputer from that machine and post the log here. Right now I am on an old Dell XP
running Ubuntu.

#10 WilliamBuell

WilliamBuell
  • Topic Starter

  • Members
  • 53 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NYC USA
  • Local time:01:19 AM

Posted 23 February 2012 - 08:41 PM

Thanks for the great advice, Gringo! Here is the COMBOFIX LOG -


ComboFix 12-02-23.01 - William 02/23/2012 16:31:29.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6051.3944 [GMT -5:00]
Running from: c:\users\Buell\Desktop\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\xp
c:\programdata\xp\EBLib.dll
c:\programdata\xp\TPwSav.sys
c:\windows\system32\Thumbs.db
.
.
((((((((((((((((((((((((( Files Created from 2012-01-24 to 2012-02-24 )))))))))))))))))))))))))))))))
.
.
2012-02-23 21:35 . 2012-02-24 01:24 -------- d-----w- c:\users\William\AppData\Local\temp
2012-02-23 21:35 . 2012-02-23 21:35 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-02-23 21:35 . 2012-02-23 21:35 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-23 16:22 . 2012-02-08 07:13 8643640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D38D744D-6441-4161-B623-BFEFF370DE62}\mpengine.dll
2012-02-23 09:04 . 2012-02-23 09:04 388096 ----a-r- c:\users\William\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-02-23 08:56 . 2012-02-23 08:56 -------- d-----w- c:\program files (x86)\Trend Micro
2012-02-23 07:06 . 2012-02-23 07:06 -------- d-----w- c:\windows\system32\Macromed
2012-02-23 04:08 . 2012-02-23 04:35 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-02-23 04:08 . 2012-02-23 04:10 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2012-02-21 11:09 . 2012-02-21 11:09 -------- d-----w- c:\users\William\AppData\Local\Diagnostics
2012-02-18 19:10 . 2012-02-18 19:10 -------- d-----w- c:\program files (x86)\TeamViewer
2012-02-17 06:11 . 2012-02-17 06:11 -------- d-----w- c:\users\William\AppData\Roaming\Paltalk
2012-02-17 06:11 . 2012-02-17 06:11 -------- d-----w- c:\windows\Paltalk Messenger
2012-02-17 06:11 . 2012-02-17 06:11 -------- d-----w- c:\program files (x86)\Paltalk Messenger
2012-02-17 05:53 . 2012-02-17 05:53 -------- d-----w- c:\users\William\AppData\Local\APN
2012-02-16 09:14 . 2012-02-16 09:14 -------- d-----w- c:\program files (x86)\Lame For Audacity
2012-02-16 09:05 . 2012-02-16 09:06 -------- d-----w- c:\program files (x86)\Audacity 1.3 Beta (Unicode)
2012-02-15 07:59 . 2012-02-16 04:08 -------- d-----w- c:\users\William\AppData\Local\adaware
2012-02-15 07:58 . 2012-02-15 07:59 -------- d-----w- c:\program files (x86)\adawaretb
2012-02-15 06:32 . 2011-12-14 06:57 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-02-15 06:32 . 2011-12-14 02:50 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2012-02-15 06:32 . 2011-12-14 03:32 141112 ----a-w- c:\program files (x86)\Internet Explorer\sqmapi.dll
2012-02-15 06:31 . 2011-12-14 07:47 174392 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2012-02-15 06:31 . 2011-12-14 07:01 304640 ----a-w- c:\program files\Internet Explorer\IEShims.dll
2012-02-15 06:30 . 2011-12-14 02:54 194048 ----a-w- c:\program files (x86)\Internet Explorer\IEShims.dll
2012-02-15 06:30 . 2011-12-14 07:11 2308096 ----a-w- c:\windows\system32\jscript9.dll
2012-02-15 06:29 . 2011-12-14 03:04 1798656 ----a-w- c:\windows\SysWow64\jscript9.dll
2012-02-15 06:27 . 2011-12-14 02:56 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2012-02-15 06:27 . 2011-12-14 07:03 1493504 ----a-w- c:\windows\system32\inetcpl.cpl
2012-02-15 06:27 . 2011-12-14 02:57 1127424 ----a-w- c:\windows\SysWow64\wininet.dll
2012-02-15 06:26 . 2011-12-14 07:04 1390080 ----a-w- c:\windows\system32\wininet.dll
2012-02-15 06:25 . 2011-12-14 02:59 678912 ----a-w- c:\program files (x86)\Internet Explorer\iedvtool.dll
2012-02-15 06:25 . 2011-12-14 07:07 887296 ----a-w- c:\program files\Internet Explorer\iedvtool.dll
2012-02-15 06:17 . 2012-02-15 06:17 -------- d-----w- c:\users\Buell
2012-02-15 04:08 . 2012-01-04 10:44 509952 ----a-w- c:\windows\system32\ntshrui.dll
2012-02-15 04:08 . 2012-01-04 08:58 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2012-02-15 04:08 . 2012-01-14 04:06 3145728 ----a-w- c:\windows\system32\win32k.sys
2012-02-15 04:08 . 2011-12-30 06:26 515584 ----a-w- c:\windows\system32\timedate.cpl
2012-02-15 04:08 . 2011-12-30 05:27 478720 ----a-w- c:\windows\SysWow64\timedate.cpl
2012-02-15 04:08 . 2011-12-28 03:59 498688 ----a-w- c:\windows\system32\drivers\afd.sys
2012-02-15 04:08 . 2011-12-16 08:46 634880 ----a-w- c:\windows\system32\msvcrt.dll
2012-02-15 04:08 . 2011-12-16 07:52 690688 ----a-w- c:\windows\SysWow64\msvcrt.dll
2012-02-14 23:32 . 2012-02-14 23:32 72280 ----a-w- c:\windows\system32\drivers\sbapifs.sys
2012-02-14 07:42 . 2012-02-14 07:42 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-02-14 07:42 . 2012-02-14 07:42 -------- d-----w- c:\program files (x86)\Java
2012-02-11 08:31 . 2012-02-11 08:31 -------- d-----w- c:\users\William\AppData\Local\Sunbelt Software
2012-02-10 15:11 . 2012-02-10 15:11 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{358A79F5-A006-42C4-85F3-D16C84008660}\gapaengine.dll
2012-02-10 15:11 . 2012-02-03 00:24 917840 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2012-02-09 19:46 . 2012-02-09 18:17 16432 ----a-w- c:\windows\system32\lsdelete.exe
2012-02-09 18:17 . 2012-02-09 18:17 55384 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2012-02-09 18:11 . 2012-02-23 21:38 -------- d-----w- c:\programdata\Ad-Aware Browsing Protection
2012-02-09 18:11 . 2012-02-09 18:11 -------- d-----w- c:\program files (x86)\Toolbar Cleaner
2012-02-09 18:11 . 2011-12-23 12:12 69376 ----a-w- c:\windows\system32\drivers\Lbd.sys
2012-02-09 18:11 . 2012-02-09 18:11 -------- d-----w- c:\programdata\Lavasoft
2012-02-09 18:11 . 2012-02-09 18:11 -------- d-----w- c:\program files (x86)\Lavasoft
2012-02-03 07:43 . 2012-02-08 07:13 8643640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-02-03 00:23 . 2012-02-03 00:23 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2012-02-03 00:23 . 2012-02-03 00:23 -------- d-----w- c:\program files\Microsoft Security Client
2012-02-02 21:11 . 2012-02-02 21:11 -------- d-----w- c:\programdata\Toshiba Book Place
2012-02-02 21:01 . 2012-02-06 07:21 -------- d-----w- c:\users\William\AppData\Roaming\Book Place
2012-02-01 20:32 . 2012-02-01 20:32 -------- d-----w- c:\users\William\AppData\Roaming\Malwarebytes
2012-02-01 20:32 . 2012-02-01 20:32 -------- d-----w- c:\programdata\Malwarebytes
2012-02-01 20:32 . 2012-02-16 03:59 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-02-01 20:32 . 2011-12-10 20:24 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-31 10:10 . 2012-01-31 10:10 -------- d-----w- c:\program files (x86)\UEFI WinFlash
2012-01-31 02:46 . 2012-01-31 13:56 -------- d-----w- C:\OldDell
2012-01-25 22:46 . 2012-01-25 22:46 -------- d-----w- c:\program files (x86)\Common Files\Macrovision Shared
2012-01-25 22:45 . 2012-01-25 22:45 -------- d-----w- c:\programdata\Rosetta Stone
2012-01-25 22:45 . 2012-01-25 22:45 -------- d-----w- c:\programdata\Rosetta Stone Backups
2012-01-25 22:42 . 2012-01-25 22:42 -------- d-----w- c:\programdata\RosettaStoneLtdServices
2012-01-25 22:42 . 2012-01-25 22:42 -------- d-----w- c:\program files (x86)\RosettaStoneLtdServices
2012-01-25 22:42 . 2012-01-25 22:42 -------- d-----w- c:\program files (x86)\Rosetta Stone
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-23 07:06 . 2011-11-25 03:04 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-14 07:42 . 2011-11-25 03:03 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-01-31 12:44 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe
2012-01-21 17:09 . 2011-03-29 02:36 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-12-14 23:50 . 2011-12-14 23:50 7162 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\ssl.dll
2011-12-14 23:50 . 2011-12-14 23:50 63229 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\spellchk.dll
2011-12-14 23:50 . 2011-12-14 23:50 61821 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\tcl.dll
2011-12-14 23:50 . 2011-12-14 23:50 43682 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\perl.dll
2011-12-14 23:50 . 2011-12-14 23:50 36068 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\xmppdisco.dll
2011-12-14 23:50 . 2011-12-14 23:50 30333 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\xmppconsole.dll
2011-12-14 23:50 . 2011-12-14 23:50 24487 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\themeedit.dll
2011-12-14 23:50 . 2011-12-14 23:50 24106 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\ticker.dll
2011-12-14 23:50 . 2011-12-14 23:50 23455 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\winprefs.dll
2011-12-14 23:50 . 2011-12-14 23:50 23390 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\pidginrc.dll
2011-12-14 23:50 . 2011-12-14 23:50 22901 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\win2ktrans.dll
2011-12-14 23:50 . 2011-12-14 23:50 19854 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\ssl-nss.dll
2011-12-14 23:50 . 2011-12-14 23:50 17951 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\timestamp_format.dll
2011-12-14 23:50 . 2011-12-14 23:50 13589 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\timestamp.dll
2011-12-14 23:50 . 2011-12-14 23:50 10624 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\statenotify.dll
2011-12-14 23:50 . 2011-12-14 23:50 10203 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\sendbutton.dll
2011-12-14 23:50 . 2011-12-14 23:50 10075 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\relnot.dll
2011-12-14 23:50 . 2011-12-14 23:50 10026 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\psychic.dll
2011-12-14 23:50 . 2011-12-14 23:50 96443 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\libsametime.dll
2011-12-14 23:50 . 2011-12-14 23:50 92138 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\libnovell.dll
2011-12-14 23:50 . 2011-12-14 23:50 9126 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\newline.dll
2011-12-14 23:50 . 2011-12-14 23:50 88548 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\libmyspace.dll
2011-12-14 23:50 . 2011-12-14 23:50 79922 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\libirc.dll
2011-12-14 23:50 . 2011-12-14 23:50 633718 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\perl\auto\Purple\Purple.dll
2011-12-14 23:50 . 2011-12-14 23:50 45348 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\libsimple.dll
2011-12-14 23:50 . 2011-12-14 23:50 39509 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\log_reader.dll
2011-12-14 23:50 . 2011-12-14 23:50 301681 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\libmsn.dll
2011-12-14 23:50 . 2011-12-14 23:50 22335 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\notify.dll
2011-12-14 23:50 . 2011-12-14 23:50 18502 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\libyahoo.dll
2011-12-14 23:50 . 2011-12-14 23:50 184224 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\libgg.dll
2011-12-14 23:50 . 2011-12-14 23:50 17519 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\libxmpp.dll
2011-12-14 23:50 . 2011-12-14 23:50 14951 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\libyahoojp.dll
2011-12-14 23:50 . 2011-12-14 23:50 149384 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\libsilc.dll
2011-12-14 23:50 . 2011-12-14 23:50 14905 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\markerline.dll
2011-12-14 23:50 . 2011-12-14 23:50 121476 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\libmxit.dll
2011-12-14 23:50 . 2011-12-14 23:50 11669 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\offlinemsg.dll
2011-12-14 23:50 . 2011-12-14 23:50 111843 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\perl\auto\Pidgin\Pidgin.dll
2011-12-14 23:50 . 2011-12-14 23:50 11163 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\libicq.dll
2011-12-14 23:50 . 2011-12-14 23:50 953091 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\pidgin.dll
2011-12-14 23:50 . 2011-12-14 23:50 8793 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\gtkbuddynote.dll
2011-12-14 23:50 . 2011-12-14 23:50 7899 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\buddynote.dll
2011-12-14 23:50 . 2011-12-14 23:50 7511 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\iconaway.dll
2011-12-14 23:50 . 2011-12-14 23:50 73584 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\libbonjour.dll
2011-12-14 23:50 . 2011-12-14 23:50 628663 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\libpurple.dll
2011-12-14 23:50 . 2011-12-14 23:50 49340 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\pidgin.exe
2011-12-14 23:50 . 2011-12-14 23:50 194434 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\libymsg.dll
2011-12-14 23:50 . 2011-12-14 23:50 19058 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\convcolors.dll
2011-12-14 23:50 . 2011-12-14 23:50 14574 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\autoaccept.dll
2011-12-14 23:50 . 2011-12-14 23:50 13528 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\history.dll
2011-12-14 23:50 . 2011-12-14 23:50 12665 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\idle.dll
2011-12-14 23:50 . 2011-12-14 23:50 12177 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\joinpart.dll
2011-12-14 23:50 . 2011-12-14 23:50 10860 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\extplacement.dll
2011-12-14 23:50 . 2011-12-14 23:50 10232 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\plugins\libaim.dll
2011-12-14 23:50 . 2011-12-14 23:50 338072 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\libjabber.dll
2011-12-14 23:50 . 2011-12-14 23:50 256017 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\liboscar.dll
2011-12-14 23:50 . 2011-12-14 23:50 866159 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\spellcheck\lib\enchant\libenchant_ispell.dll
2011-12-14 23:50 . 2011-12-14 23:50 67593 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\spellcheck\libenchant.dll
2011-12-14 23:50 . 2011-12-14 23:50 582656 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\exchndl.dll
2011-12-14 23:50 . 2011-12-14 23:50 475580 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\spellcheck\libgtkspell-0.dll
2011-12-14 23:50 . 2011-12-14 23:50 1332245 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\spellcheck\lib\enchant\libenchant_myspell.dll
2011-12-14 23:48 . 2011-12-14 23:48 417501 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\sqlite3.dll
2011-12-14 23:48 . 2011-12-14 23:48 414890 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\nssckbi.dll
2011-12-14 23:48 . 2011-12-14 23:48 333204 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\libnspr4.dll
2011-12-14 23:48 . 2011-12-14 23:48 31554 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\libplc4.dll
2011-12-14 23:48 . 2011-12-14 23:48 286885 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\freebl3.dll
2011-12-14 23:48 . 2011-12-14 23:48 26148 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\libplds4.dll
2011-12-14 23:48 . 2011-12-14 23:48 259132 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\softokn3.dll
2011-12-14 23:48 . 2011-12-14 23:48 232807 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\ssl3.dll
2011-12-14 23:48 . 2011-12-14 23:48 215727 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\smime3.dll
2011-12-14 23:48 . 2011-12-14 23:48 1290804 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\nss3.dll
2011-12-14 23:48 . 2011-12-14 23:48 128262 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\nssutil3.dll
2011-12-14 23:48 . 2011-12-14 23:48 2719062 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\libsilc-1-1-2.dll
2011-12-14 23:48 . 2011-12-14 23:48 173805 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\libmeanwhile-1.dll
2011-12-14 23:48 . 2011-12-14 23:48 1206642 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\libsilcclient-1-1-2.dll
2011-12-14 23:48 . 2011-12-14 23:48 77888 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\libsasl.dll
2011-12-14 23:48 . 2011-12-14 23:48 53322 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\sasl2\saslDIGESTMD5.dll
2011-12-14 23:48 . 2011-12-14 23:48 36935 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\sasl2\saslGSSAPI.dll
2011-12-14 23:48 . 2011-12-14 23:48 32840 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\sasl2\saslCRAMMD5.dll
2011-12-14 23:48 . 2011-12-14 23:48 32838 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\sasl2\saslPLAIN.dll
2011-12-14 23:48 . 2011-12-14 23:48 32838 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\sasl2\saslLOGIN.dll
2011-12-14 23:48 . 2011-12-14 23:48 28746 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\sasl2\saslANONYMOUS.dll
2011-12-14 23:48 . 2011-12-14 23:48 1213633 ----a-w- c:\users\Buell\AppData\Roaming\Microsoft\Windows\Pidgin\libxml2-2.dll
2011-12-14 19:41 . 2011-12-14 19:41 20592 ----a-w- c:\windows\system32\drivers\CeKbFilter.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
2011-12-21 15:44 87440 ----a-w- c:\program files (x86)\adawaretb\adawareDx.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{6c97a91e-4524-4019-86af-2aa2d567bf5c}"= "c:\program files (x86)\adawaretb\adawareDx.dll" [2011-12-21 87440]
.
[HKEY_CLASSES_ROOT\clsid\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2009-05-05 222496]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-10-13 17351304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2010-11-09 532480]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2011-03-10 423936]
"KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2010-08-16 34160]
"ITSecMng"="c:\program files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2011-04-02 80840]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2011-07-12 1298816]
"ToshibaAppPlace"="c:\program files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe" [2010-09-23 552960]
"NortonOnlineBackupReminder"="c:\program files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe" [2011-06-22 3218864]
"IndexSearch"="c:\program files (x86)\Nuance\PaperPort\IndexSearch.exe" [2010-03-09 46368]
"PaperPort PTD"="c:\program files (x86)\Nuance\PaperPort\pptd40nt.exe" [2010-03-09 29984]
"PPort12reminder"="c:\program files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" [2010-02-09 328992]
"PDFHook"="c:\program files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe" [2010-03-06 636192]
"PDF5 Registry Controller"="c:\program files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe" [2010-03-06 62752]
"ControlCenter4"="c:\program files (x86)\ControlCenter4\BrCcBoot.exe" [2010-10-26 139264]
"BrStsMon00"="c:\program files (x86)\Browny02\Brother\BrStMonW.exe" [2010-06-10 2621440]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2011-11-14 197288]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"adaware"="reg.exe delete HKCU\Software\AppDataLow\Software\adaware" [X]
"adaware_XP"="reg.exe delete HKCU\Software\adaware" [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-14 136176]
R3 BrYNSvc;BrYNSvc;c:\program files (x86)\Browny02\BrYNSvc.exe [2010-01-25 245760]
R3 BtFilter;Bluetooth LowerFilter Class Filter Driver;c:\windows\system32\DRIVERS\btfilter.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-14 136176]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 ser2at;ATEN USB to Serial port driver;c:\windows\system32\DRIVERS\ser2at64.sys [x]
R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2011-07-12 57216]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2011-06-10 138152]
R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2011-07-01 828856]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x]
S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys [x]
S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [x]
S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2012-02-09 2152152]
S2 Norton PC Checkup Application Launcher;Toshiba Laptop Checkup Application Launcher;c:\program files (x86)\Norton PC Checkup\Engine\2.0.13.11\SymcPCCULaunchSvc.exe [2011-07-19 123320]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-06-07 1997416]
S2 PCCUJobMgr;Common Client Job Manager Service;c:\program files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe [2011-07-19 126392]
S2 PDFProFiltSrvPP;PDFProFiltSrvPP;c:\program files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [2010-03-09 144672]
S2 RosettaStoneDaemon;RosettaStoneDaemon;c:\program files (x86)\RosettaStoneLtdServices\RosettaStoneDaemon.exe [2011-03-31 1646056]
S2 sbapifs;sbapifs;c:\windows\system32\DRIVERS\sbapifs.sys [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776]
S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-01-19 3027840]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2011-05-24 294848]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-02-01 2656280]
S3 CeKbFilter;CeKbFilter;c:\windows\system32\DRIVERS\CeKbFilter.sys [x]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-24 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\program files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-12-23 18:17]
.
2012-02-24 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\program files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-12-23 18:17]
.
2012-02-24 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\program files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-12-23 18:17]
.
2012-02-24 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\program files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-12-23 18:17]
.
2012-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-14 19:55]
.
2012-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-14 19:55]
.
2012-02-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3294224590-4182505347-2645279241-1001Core.job
- c:\users\William\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-21 17:13]
.
2012-02-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3294224590-4182505347-2645279241-1001UA.job
- c:\users\William\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-21 17:13]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ThpSrv"="c:\windows\system32\thpsrv" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-07-02 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-07-02 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-07-02 416024]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-04-28 11831400]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-04-18 2209896]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2011-06-10 710560]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.ask.com/?l=dis&o=100000018&gct=hp
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
TCP: DhcpNameServer = 10.0.1.1
FF - ProfilePath - c:\users\William\AppData\Roaming\Mozilla\Firefox\Profiles\qrxsguuh.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.com
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-TSleepSrv - %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
Toolbar-Locked - (no file)
HKLM-Run-(Default) - (no file)
HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-HSON - c:\program files (x86)\TOSHIBA\TBS\HSON.exe
HKLM-Run-TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe
HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe
HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCCUJobMgr]
"ImagePath"="\"c:\program files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files (x86)\Norton PC Checkup\Engine\2.0.13.11\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Completion time: 2012-02-23 20:29:52 - machine was rebooted
ComboFix-quarantined-files.txt 2012-02-24 01:29
.
Pre-Run: 562,699,554,816 bytes free
Post-Run: 562,291,212,288 bytes free
.
- - End Of File - - 031D1B4D8B4D076E95603F50663F68E0

#11 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:02:19 AM

Posted 23 February 2012 - 08:49 PM

Greetings

I want you to run these next,

tdsskiller:

Please read carefully and follow these steps.
  • Download TDSSKiller and save it to your Desktop.
  • doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • it will ask to download extra definitions - ALLOW IT
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.

If you have any problems running either one come back and let me know

please reply with the reports from TDSSKiller and aswMBR

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#12 WilliamBuell

WilliamBuell
  • Topic Starter

  • Members
  • 53 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NYC USA
  • Local time:01:19 AM

Posted 23 February 2012 - 09:08 PM

21:07:02.0085 3476 TDSS rootkit removing tool 2.7.13.0 Feb 15 2012 19:33:14
21:07:02.0326 3476 ============================================================
21:07:02.0326 3476 Current date / time: 2012/02/23 21:07:02.0326
21:07:02.0326 3476 SystemInfo:
21:07:02.0326 3476
21:07:02.0326 3476 OS Version: 6.1.7601 ServicePack: 1.0
21:07:02.0327 3476 Product type: Workstation
21:07:02.0327 3476 ComputerName: WILLIAM-PC
21:07:02.0327 3476 UserName: William
21:07:02.0327 3476 Windows directory: C:\windows
21:07:02.0327 3476 System windows directory: C:\windows
21:07:02.0327 3476 Running under WOW64
21:07:02.0327 3476 Processor architecture: Intel x64
21:07:02.0327 3476 Number of processors: 4
21:07:02.0327 3476 Page size: 0x1000
21:07:02.0327 3476 Boot type: Normal boot
21:07:02.0327 3476 ============================================================
21:07:02.0649 3476 Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:07:02.0660 3476 \Device\Harddisk0\DR0:
21:07:02.0660 3476 MBR used
21:07:02.0661 3476 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x4871F000
21:07:02.0677 3476 Initialize success
21:07:02.0677 3476 ============================================================
21:07:15.0149 5656 ============================================================
21:07:15.0149 5656 Scan started
21:07:15.0149 5656 Mode: Manual;
21:07:15.0149 5656 ============================================================
21:07:15.0548 5656 1394ohci (a87d604aea360176311474c87a63bb88) C:\windows\system32\drivers\1394ohci.sys
21:07:15.0555 5656 1394ohci - ok
21:07:15.0598 5656 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\windows\system32\drivers\ACPI.sys
21:07:15.0606 5656 ACPI - ok
21:07:15.0622 5656 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\windows\system32\drivers\acpipmi.sys
21:07:15.0624 5656 AcpiPmi - ok
21:07:15.0799 5656 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\windows\system32\drivers\adp94xx.sys
21:07:15.0810 5656 adp94xx - ok
21:07:15.0861 5656 adpahci (597f78224ee9224ea1a13d6350ced962) C:\windows\system32\drivers\adpahci.sys
21:07:15.0870 5656 adpahci - ok
21:07:15.0886 5656 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\windows\system32\drivers\adpu320.sys
21:07:15.0892 5656 adpu320 - ok
21:07:15.0968 5656 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\windows\system32\drivers\afd.sys
21:07:15.0977 5656 AFD - ok
21:07:16.0107 5656 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\windows\system32\drivers\agp440.sys
21:07:16.0110 5656 agp440 - ok
21:07:16.0146 5656 aliide (5812713a477a3ad7363c7438ca2ee038) C:\windows\system32\drivers\aliide.sys
21:07:16.0148 5656 aliide - ok
21:07:16.0158 5656 amdide (1ff8b4431c353ce385c875f194924c0c) C:\windows\system32\drivers\amdide.sys
21:07:16.0159 5656 amdide - ok
21:07:16.0181 5656 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\windows\system32\drivers\amdk8.sys
21:07:16.0183 5656 AmdK8 - ok
21:07:16.0194 5656 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\windows\system32\drivers\amdppm.sys
21:07:16.0196 5656 AmdPPM - ok
21:07:16.0214 5656 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\windows\system32\drivers\amdsata.sys
21:07:16.0216 5656 amdsata - ok
21:07:16.0241 5656 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\windows\system32\drivers\amdsbs.sys
21:07:16.0245 5656 amdsbs - ok
21:07:16.0275 5656 amdxata (540daf1cea6094886d72126fd7c33048) C:\windows\system32\drivers\amdxata.sys
21:07:16.0276 5656 amdxata - ok
21:07:16.0406 5656 AppID (89a69c3f2f319b43379399547526d952) C:\windows\system32\drivers\appid.sys
21:07:16.0409 5656 AppID - ok
21:07:16.0472 5656 arc (c484f8ceb1717c540242531db7845c4e) C:\windows\system32\drivers\arc.sys
21:07:16.0474 5656 arc - ok
21:07:16.0484 5656 arcsas (019af6924aefe7839f61c830227fe79c) C:\windows\system32\drivers\arcsas.sys
21:07:16.0486 5656 arcsas - ok
21:07:16.0517 5656 AsyncMac (769765ce2cc62867468cea93969b2242) C:\windows\system32\DRIVERS\asyncmac.sys
21:07:16.0520 5656 AsyncMac - ok
21:07:16.0550 5656 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\windows\system32\drivers\atapi.sys
21:07:16.0551 5656 atapi - ok
21:07:16.0758 5656 athr (b2931c83cfb12a3223a47b180473ae1a) C:\windows\system32\DRIVERS\athrx.sys
21:07:16.0792 5656 athr - ok
21:07:16.0937 5656 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\windows\system32\drivers\bxvbda.sys
21:07:16.0947 5656 b06bdrv - ok
21:07:16.0974 5656 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\windows\system32\DRIVERS\b57nd60a.sys
21:07:16.0979 5656 b57nd60a - ok
21:07:17.0007 5656 Beep (16a47ce2decc9b099349a5f840654746) C:\windows\system32\drivers\Beep.sys
21:07:17.0008 5656 Beep - ok
21:07:17.0136 5656 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\windows\system32\drivers\blbdrive.sys
21:07:17.0138 5656 blbdrive - ok
21:07:17.0164 5656 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\windows\system32\DRIVERS\bowser.sys
21:07:17.0168 5656 bowser - ok
21:07:17.0205 5656 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\windows\system32\drivers\BrFiltLo.sys
21:07:17.0207 5656 BrFiltLo - ok
21:07:17.0217 5656 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\windows\system32\drivers\BrFiltUp.sys
21:07:17.0219 5656 BrFiltUp - ok
21:07:17.0331 5656 BridgeMP (5c2f352a4e961d72518261257aae204b) C:\windows\system32\DRIVERS\bridge.sys
21:07:17.0335 5656 BridgeMP - ok
21:07:17.0354 5656 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\windows\System32\Drivers\Brserid.sys
21:07:17.0359 5656 Brserid - ok
21:07:17.0365 5656 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\windows\System32\Drivers\BrSerWdm.sys
21:07:17.0367 5656 BrSerWdm - ok
21:07:17.0375 5656 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\windows\System32\Drivers\BrUsbMdm.sys
21:07:17.0376 5656 BrUsbMdm - ok
21:07:17.0384 5656 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\windows\System32\Drivers\BrUsbSer.sys
21:07:17.0385 5656 BrUsbSer - ok
21:07:17.0427 5656 BtFilter (2347abbd13bada65826fdab4caafe357) C:\windows\system32\DRIVERS\btfilter.sys
21:07:17.0428 5656 BtFilter - ok
21:07:17.0457 5656 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\windows\system32\drivers\bthmodem.sys
21:07:17.0459 5656 BTHMODEM - ok
21:07:17.0490 5656 catchme - ok
21:07:17.0592 5656 cdfs (b8bd2bb284668c84865658c77574381a) C:\windows\system32\DRIVERS\cdfs.sys
21:07:17.0595 5656 cdfs - ok
21:07:17.0630 5656 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\windows\system32\DRIVERS\cdrom.sys
21:07:17.0634 5656 cdrom - ok
21:07:17.0674 5656 CeKbFilter (a965b206921c55f2d1481789d609b711) C:\windows\system32\DRIVERS\CeKbFilter.sys
21:07:17.0675 5656 CeKbFilter - ok
21:07:17.0804 5656 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\windows\system32\drivers\circlass.sys
21:07:17.0807 5656 circlass - ok
21:07:17.0844 5656 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\windows\system32\CLFS.sys
21:07:17.0853 5656 CLFS - ok
21:07:17.0971 5656 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\windows\system32\drivers\CmBatt.sys
21:07:17.0973 5656 CmBatt - ok
21:07:18.0014 5656 cmdide (e19d3f095812725d88f9001985b94edd) C:\windows\system32\drivers\cmdide.sys
21:07:18.0016 5656 cmdide - ok
21:07:18.0067 5656 CNG (c4943b6c962e4b82197542447ad599f4) C:\windows\system32\Drivers\cng.sys
21:07:18.0075 5656 CNG - ok
21:07:18.0157 5656 Compbatt (102de219c3f61415f964c88e9085ad14) C:\windows\system32\drivers\compbatt.sys
21:07:18.0158 5656 Compbatt - ok
21:07:18.0226 5656 CompositeBus (03edb043586cceba243d689bdda370a8) C:\windows\system32\drivers\CompositeBus.sys
21:07:18.0228 5656 CompositeBus - ok
21:07:18.0257 5656 crcdisk (1c827878a998c18847245fe1f34ee597) C:\windows\system32\drivers\crcdisk.sys
21:07:18.0259 5656 crcdisk - ok
21:07:18.0300 5656 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\windows\system32\Drivers\dfsc.sys
21:07:18.0303 5656 DfsC - ok
21:07:18.0313 5656 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\windows\system32\drivers\discache.sys
21:07:18.0313 5656 discache - ok
21:07:18.0362 5656 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\windows\system32\drivers\disk.sys
21:07:18.0365 5656 Disk - ok
21:07:18.0464 5656 drmkaud (9b19f34400d24df84c858a421c205754) C:\windows\system32\drivers\drmkaud.sys
21:07:18.0466 5656 drmkaud - ok
21:07:18.0508 5656 DXGKrnl (85dbf6ec7bdfa6187f4a1ec8f3145cd0) C:\windows\System32\drivers\dxgkrnl.sys
21:07:18.0520 5656 DXGKrnl - ok
21:07:18.0589 5656 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\windows\system32\drivers\evbda.sys
21:07:18.0626 5656 ebdrv - ok
21:07:18.0753 5656 elxstor (0e5da5369a0fcaea12456dd852545184) C:\windows\system32\drivers\elxstor.sys
21:07:18.0765 5656 elxstor - ok
21:07:18.0789 5656 ErrDev (34a3c54752046e79a126e15c51db409b) C:\windows\system32\drivers\errdev.sys
21:07:18.0791 5656 ErrDev - ok
21:07:18.0816 5656 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\windows\system32\drivers\exfat.sys
21:07:18.0821 5656 exfat - ok
21:07:18.0832 5656 fastfat (0adc83218b66a6db380c330836f3e36d) C:\windows\system32\drivers\fastfat.sys
21:07:18.0836 5656 fastfat - ok
21:07:18.0864 5656 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\windows\system32\drivers\fdc.sys
21:07:18.0866 5656 fdc - ok
21:07:18.0890 5656 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\windows\system32\drivers\fileinfo.sys
21:07:18.0891 5656 FileInfo - ok
21:07:18.0987 5656 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\windows\system32\drivers\filetrace.sys
21:07:18.0990 5656 Filetrace - ok
21:07:19.0030 5656 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\windows\system32\drivers\flpydisk.sys
21:07:19.0033 5656 flpydisk - ok
21:07:19.0064 5656 FltMgr (da6b67270fd9db3697b20fce94950741) C:\windows\system32\drivers\fltmgr.sys
21:07:19.0070 5656 FltMgr - ok
21:07:19.0090 5656 FsDepends (d43703496149971890703b4b1b723eac) C:\windows\system32\drivers\FsDepends.sys
21:07:19.0092 5656 FsDepends - ok
21:07:19.0112 5656 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\windows\system32\drivers\Fs_Rec.sys
21:07:19.0113 5656 Fs_Rec - ok
21:07:19.0217 5656 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\windows\system32\DRIVERS\fvevol.sys
21:07:19.0223 5656 fvevol - ok
21:07:19.0244 5656 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\windows\system32\drivers\gagp30kx.sys
21:07:19.0247 5656 gagp30kx - ok
21:07:19.0298 5656 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\windows\system32\drivers\hcw85cir.sys
21:07:19.0300 5656 hcw85cir - ok
21:07:19.0344 5656 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\windows\system32\drivers\HdAudio.sys
21:07:19.0353 5656 HdAudAddService - ok
21:07:19.0477 5656 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\windows\system32\drivers\HDAudBus.sys
21:07:19.0480 5656 HDAudBus - ok
21:07:19.0491 5656 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\windows\system32\drivers\HidBatt.sys
21:07:19.0493 5656 HidBatt - ok
21:07:19.0506 5656 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\windows\system32\drivers\hidbth.sys
21:07:19.0509 5656 HidBth - ok
21:07:19.0518 5656 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\windows\system32\drivers\hidir.sys
21:07:19.0520 5656 HidIr - ok
21:07:19.0530 5656 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\windows\system32\DRIVERS\hidusb.sys
21:07:19.0531 5656 HidUsb - ok
21:07:19.0565 5656 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\windows\system32\drivers\HpSAMD.sys
21:07:19.0567 5656 HpSAMD - ok
21:07:19.0596 5656 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\windows\system32\drivers\HTTP.sys
21:07:19.0605 5656 HTTP - ok
21:07:19.0619 5656 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\windows\system32\drivers\hwpolicy.sys
21:07:19.0619 5656 hwpolicy - ok
21:07:19.0734 5656 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\windows\system32\drivers\i8042prt.sys
21:07:19.0737 5656 i8042prt - ok
21:07:19.0782 5656 iaStor (d469b77687e12fe43e344806740b624d) C:\windows\system32\DRIVERS\iaStor.sys
21:07:19.0786 5656 iaStor - ok
21:07:19.0910 5656 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\windows\system32\drivers\iaStorV.sys
21:07:19.0920 5656 iaStorV - ok
21:07:20.0150 5656 igfx (93c8115d4baeb1bd047ab0a9b265ee7a) C:\windows\system32\DRIVERS\igdkmd64.sys
21:07:20.0352 5656 igfx - ok
21:07:20.0456 5656 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\windows\system32\drivers\iirsp.sys
21:07:20.0459 5656 iirsp - ok
21:07:20.0580 5656 IntcAzAudAddService (a1fa448078c94e4d011ebd241821ff9e) C:\windows\system32\drivers\RTKVHD64.sys
21:07:20.0603 5656 IntcAzAudAddService - ok
21:07:20.0733 5656 IntcDAud (fc727061c0f47c8059e88e05d5c8e381) C:\windows\system32\DRIVERS\IntcDAud.sys
21:07:20.0741 5656 IntcDAud - ok
21:07:20.0773 5656 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\windows\system32\drivers\intelide.sys
21:07:20.0775 5656 intelide - ok
21:07:20.0808 5656 intelppm (ada036632c664caa754079041cf1f8c1) C:\windows\system32\DRIVERS\intelppm.sys
21:07:20.0809 5656 intelppm - ok
21:07:20.0922 5656 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\windows\system32\DRIVERS\ipfltdrv.sys
21:07:20.0926 5656 IpFilterDriver - ok
21:07:20.0952 5656 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\windows\system32\drivers\IPMIDrv.sys
21:07:20.0965 5656 IPMIDRV - ok
21:07:20.0988 5656 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\windows\system32\drivers\ipnat.sys
21:07:20.0992 5656 IPNAT - ok
21:07:21.0022 5656 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\windows\system32\drivers\irenum.sys
21:07:21.0024 5656 IRENUM - ok
21:07:21.0040 5656 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\windows\system32\drivers\isapnp.sys
21:07:21.0042 5656 isapnp - ok
21:07:21.0069 5656 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\windows\system32\drivers\msiscsi.sys
21:07:21.0077 5656 iScsiPrt - ok
21:07:21.0189 5656 JMCR (935301dd8306ceeaef0b84dd6abffdc6) C:\windows\system32\DRIVERS\jmcr.sys
21:07:21.0193 5656 JMCR - ok
21:07:21.0235 5656 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\windows\system32\drivers\kbdclass.sys
21:07:21.0237 5656 kbdclass - ok
21:07:21.0273 5656 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\windows\system32\drivers\kbdhid.sys
21:07:21.0275 5656 kbdhid - ok
21:07:21.0381 5656 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\windows\system32\Drivers\ksecdd.sys
21:07:21.0383 5656 KSecDD - ok
21:07:21.0404 5656 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\windows\system32\Drivers\ksecpkg.sys
21:07:21.0407 5656 KSecPkg - ok
21:07:21.0445 5656 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\windows\system32\drivers\ksthunk.sys
21:07:21.0446 5656 ksthunk - ok
21:07:21.0609 5656 Lbd (c8b3131857931ae76798a741cc52b021) C:\windows\system32\DRIVERS\Lbd.sys
21:07:21.0611 5656 Lbd - ok
21:07:21.0665 5656 lltdio (1538831cf8ad2979a04c423779465827) C:\windows\system32\DRIVERS\lltdio.sys
21:07:21.0667 5656 lltdio - ok
21:07:21.0806 5656 LPCFilter (2825a71e7501cb33b3b9f856610c729d) C:\windows\system32\DRIVERS\LPCFilter.sys
21:07:21.0808 5656 LPCFilter - ok
21:07:21.0852 5656 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\windows\system32\drivers\lsi_fc.sys
21:07:21.0856 5656 LSI_FC - ok
21:07:21.0870 5656 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\windows\system32\drivers\lsi_sas.sys
21:07:21.0873 5656 LSI_SAS - ok
21:07:21.0898 5656 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\windows\system32\drivers\lsi_sas2.sys
21:07:21.0900 5656 LSI_SAS2 - ok
21:07:21.0911 5656 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\windows\system32\drivers\lsi_scsi.sys
21:07:21.0913 5656 LSI_SCSI - ok
21:07:21.0978 5656 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\windows\system32\drivers\luafv.sys
21:07:21.0981 5656 luafv - ok
21:07:22.0065 5656 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\windows\system32\drivers\megasas.sys
21:07:22.0067 5656 megasas - ok
21:07:22.0094 5656 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\windows\system32\drivers\MegaSR.sys
21:07:22.0101 5656 MegaSR - ok
21:07:22.0151 5656 MEIx64 (a6518dcc42f7a6e999bb3bea8fd87567) C:\windows\system32\DRIVERS\HECIx64.sys
21:07:22.0153 5656 MEIx64 - ok
21:07:22.0204 5656 Modem (800ba92f7010378b09f9ed9270f07137) C:\windows\system32\drivers\modem.sys
21:07:22.0206 5656 Modem - ok
21:07:22.0249 5656 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\windows\system32\DRIVERS\monitor.sys
21:07:22.0250 5656 monitor - ok
21:07:22.0339 5656 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\windows\system32\DRIVERS\mouclass.sys
21:07:22.0341 5656 mouclass - ok
21:07:22.0368 5656 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\windows\system32\DRIVERS\mouhid.sys
21:07:22.0370 5656 mouhid - ok
21:07:22.0395 5656 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\windows\system32\drivers\mountmgr.sys
21:07:22.0398 5656 mountmgr - ok
21:07:22.0469 5656 MpFilter (c177a7ebf5e8a0b596f618870516cab8) C:\windows\system32\DRIVERS\MpFilter.sys
21:07:22.0473 5656 MpFilter - ok
21:07:22.0542 5656 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\windows\system32\drivers\mpio.sys
21:07:22.0547 5656 mpio - ok
21:07:22.0566 5656 MpNWMon (8fbf6b31fe8af1833d93c5913d5b4d55) C:\windows\system32\DRIVERS\MpNWMon.sys
21:07:22.0568 5656 MpNWMon - ok
21:07:22.0579 5656 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\windows\system32\drivers\mpsdrv.sys
21:07:22.0580 5656 mpsdrv - ok
21:07:22.0601 5656 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\windows\system32\drivers\mrxdav.sys
21:07:22.0604 5656 MRxDAV - ok
21:07:22.0630 5656 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\windows\system32\DRIVERS\mrxsmb.sys
21:07:22.0633 5656 mrxsmb - ok
21:07:22.0689 5656 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\windows\system32\DRIVERS\mrxsmb10.sys
21:07:22.0696 5656 mrxsmb10 - ok
21:07:22.0717 5656 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\windows\system32\DRIVERS\mrxsmb20.sys
21:07:22.0720 5656 mrxsmb20 - ok
21:07:22.0793 5656 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\windows\system32\DRIVERS\msahci.sys
21:07:22.0794 5656 msahci - ok
21:07:22.0819 5656 msdsm (db801a638d011b9633829eb6f663c900) C:\windows\system32\drivers\msdsm.sys
21:07:22.0823 5656 msdsm - ok
21:07:22.0855 5656 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\windows\system32\drivers\Msfs.sys
21:07:22.0855 5656 Msfs - ok
21:07:22.0909 5656 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\windows\System32\drivers\mshidkmdf.sys
21:07:22.0910 5656 mshidkmdf - ok
21:07:22.0926 5656 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\windows\system32\drivers\msisadrv.sys
21:07:22.0927 5656 msisadrv - ok
21:07:23.0015 5656 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\windows\system32\drivers\MSKSSRV.sys
21:07:23.0017 5656 MSKSSRV - ok
21:07:23.0049 5656 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\windows\system32\drivers\MSPCLOCK.sys
21:07:23.0051 5656 MSPCLOCK - ok
21:07:23.0105 5656 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\windows\system32\drivers\MSPQM.sys
21:07:23.0107 5656 MSPQM - ok
21:07:23.0134 5656 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\windows\system32\drivers\MsRPC.sys
21:07:23.0141 5656 MsRPC - ok
21:07:23.0166 5656 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\windows\system32\drivers\mssmbios.sys
21:07:23.0167 5656 mssmbios - ok
21:07:23.0273 5656 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\windows\system32\drivers\MSTEE.sys
21:07:23.0275 5656 MSTEE - ok
21:07:23.0320 5656 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\windows\system32\drivers\MTConfig.sys
21:07:23.0322 5656 MTConfig - ok
21:07:23.0349 5656 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\windows\system32\Drivers\mup.sys
21:07:23.0350 5656 Mup - ok
21:07:23.0392 5656 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\windows\system32\DRIVERS\nwifi.sys
21:07:23.0398 5656 NativeWifiP - ok
21:07:23.0481 5656 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\windows\system32\drivers\ndis.sys
21:07:23.0496 5656 NDIS - ok
21:07:23.0583 5656 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\windows\system32\DRIVERS\ndiscap.sys
21:07:23.0586 5656 NdisCap - ok
21:07:23.0612 5656 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\windows\system32\DRIVERS\ndistapi.sys
21:07:23.0614 5656 NdisTapi - ok
21:07:23.0636 5656 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\windows\system32\DRIVERS\ndisuio.sys
21:07:23.0638 5656 Ndisuio - ok
21:07:23.0699 5656 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\windows\system32\DRIVERS\ndiswan.sys
21:07:23.0704 5656 NdisWan - ok
21:07:23.0780 5656 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\windows\system32\drivers\NDProxy.sys
21:07:23.0782 5656 NDProxy - ok
21:07:23.0815 5656 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\windows\system32\DRIVERS\netbios.sys
21:07:23.0817 5656 NetBIOS - ok
21:07:23.0845 5656 NetBT (09594d1089c523423b32a4229263f068) C:\windows\system32\DRIVERS\netbt.sys
21:07:23.0851 5656 NetBT - ok
21:07:23.0918 5656 nfrd960 (77889813be4d166cdab78ddba990da92) C:\windows\system32\drivers\nfrd960.sys
21:07:23.0920 5656 nfrd960 - ok
21:07:23.0994 5656 NisDrv (5f7d72cbcdd025af1f38fdeee5646968) C:\windows\system32\DRIVERS\NisDrvWFP.sys
21:07:23.0996 5656 NisDrv - ok
21:07:24.0075 5656 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\windows\system32\drivers\Npfs.sys
21:07:24.0078 5656 Npfs - ok
21:07:24.0135 5656 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\windows\system32\drivers\nsiproxy.sys
21:07:24.0136 5656 nsiproxy - ok
21:07:24.0234 5656 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\windows\system32\drivers\Ntfs.sys
21:07:24.0262 5656 Ntfs - ok
21:07:24.0284 5656 Null (9899284589f75fa8724ff3d16aed75c1) C:\windows\system32\drivers\Null.sys
21:07:24.0285 5656 Null - ok
21:07:24.0341 5656 nusb3hub (0ebc9d13cd96c15b1b18d8678a609e4b) C:\windows\system32\DRIVERS\nusb3hub.sys
21:07:24.0343 5656 nusb3hub - ok
21:07:24.0393 5656 nusb3xhc (7bdec000d56d485021d9c1e63c2f81ca) C:\windows\system32\DRIVERS\nusb3xhc.sys
21:07:24.0398 5656 nusb3xhc - ok
21:07:24.0701 5656 nvlddmkm (685cc16c261952f833ef56af4ec3bf0d) C:\windows\system32\DRIVERS\nvlddmkm.sys
21:07:24.0754 5656 nvlddmkm - ok
21:07:24.0856 5656 nvpciflt (d9c08f27936810db50363fdcf2496d0e) C:\windows\system32\DRIVERS\nvpciflt.sys
21:07:24.0857 5656 nvpciflt - ok
21:07:24.0894 5656 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\windows\system32\drivers\nvraid.sys
21:07:24.0899 5656 nvraid - ok
21:07:24.0912 5656 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\windows\system32\drivers\nvstor.sys
21:07:24.0917 5656 nvstor - ok
21:07:24.0949 5656 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\windows\system32\drivers\nv_agp.sys
21:07:24.0952 5656 nv_agp - ok
21:07:24.0971 5656 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\windows\system32\drivers\ohci1394.sys
21:07:24.0973 5656 ohci1394 - ok
21:07:25.0083 5656 Parport (0086431c29c35be1dbc43f52cc273887) C:\windows\system32\drivers\parport.sys
21:07:25.0086 5656 Parport - ok
21:07:25.0109 5656 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\windows\system32\drivers\partmgr.sys
21:07:25.0111 5656 partmgr - ok
21:07:25.0147 5656 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\windows\system32\drivers\pci.sys
21:07:25.0150 5656 pci - ok
21:07:25.0159 5656 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\windows\system32\DRIVERS\pciide.sys
21:07:25.0159 5656 pciide - ok
21:07:25.0184 5656 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\windows\system32\drivers\pcmcia.sys
21:07:25.0188 5656 pcmcia - ok
21:07:25.0213 5656 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\windows\system32\drivers\pcw.sys
21:07:25.0214 5656 pcw - ok
21:07:25.0336 5656 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\windows\system32\drivers\peauth.sys
21:07:25.0345 5656 PEAUTH - ok
21:07:25.0402 5656 PGEffect (91111cebbde8015e822c46120ed9537c) C:\windows\system32\DRIVERS\pgeffect.sys
21:07:25.0404 5656 PGEffect - ok
21:07:25.0479 5656 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\windows\system32\DRIVERS\raspptp.sys
21:07:25.0481 5656 PptpMiniport - ok
21:07:25.0579 5656 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\windows\system32\drivers\processr.sys
21:07:25.0582 5656 Processor - ok
21:07:25.0614 5656 Psched (0557cf5a2556bd58e26384169d72438d) C:\windows\system32\DRIVERS\pacer.sys
21:07:25.0616 5656 Psched - ok
21:07:25.0666 5656 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\windows\system32\drivers\ql2300.sys
21:07:25.0688 5656 ql2300 - ok
21:07:25.0717 5656 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\windows\system32\drivers\ql40xx.sys
21:07:25.0720 5656 ql40xx - ok
21:07:25.0815 5656 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\windows\system32\drivers\qwavedrv.sys
21:07:25.0817 5656 QWAVEdrv - ok
21:07:25.0828 5656 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\windows\system32\DRIVERS\rasacd.sys
21:07:25.0830 5656 RasAcd - ok
21:07:25.0867 5656 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\windows\system32\DRIVERS\AgileVpn.sys
21:07:25.0869 5656 RasAgileVpn - ok
21:07:25.0889 5656 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\windows\system32\DRIVERS\rasl2tp.sys
21:07:25.0892 5656 Rasl2tp - ok
21:07:25.0908 5656 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\windows\system32\DRIVERS\raspppoe.sys
21:07:25.0911 5656 RasPppoe - ok
21:07:26.0004 5656 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\windows\system32\DRIVERS\rassstp.sys
21:07:26.0008 5656 RasSstp - ok
21:07:26.0031 5656 rdbss (77f665941019a1594d887a74f301fa2f) C:\windows\system32\DRIVERS\rdbss.sys
21:07:26.0036 5656 rdbss - ok
21:07:26.0070 5656 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\windows\system32\drivers\rdpbus.sys
21:07:26.0072 5656 rdpbus - ok
21:07:26.0094 5656 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\windows\system32\DRIVERS\RDPCDD.sys
21:07:26.0095 5656 RDPCDD - ok
21:07:26.0221 5656 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\windows\system32\drivers\rdpencdd.sys
21:07:26.0222 5656 RDPENCDD - ok
21:07:26.0244 5656 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\windows\system32\drivers\rdprefmp.sys
21:07:26.0245 5656 RDPREFMP - ok
21:07:26.0258 5656 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\windows\system32\drivers\RDPWD.sys
21:07:26.0263 5656 RDPWD - ok
21:07:26.0299 5656 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\windows\system32\drivers\rdyboost.sys
21:07:26.0302 5656 rdyboost - ok
21:07:26.0429 5656 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\windows\system32\DRIVERS\rspndr.sys
21:07:26.0431 5656 rspndr - ok
21:07:26.0475 5656 RTL8167 (6d3c7e7d82d3dc92dc2a8b0df9f20f8a) C:\windows\system32\DRIVERS\Rt64win7.sys
21:07:26.0481 5656 RTL8167 - ok
21:07:26.0546 5656 sbapifs (db7f9394b2f2d446df14d46c61b0e94b) C:\windows\system32\DRIVERS\sbapifs.sys
21:07:26.0548 5656 sbapifs - ok
21:07:26.0656 5656 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\windows\system32\drivers\sbp2port.sys
21:07:26.0660 5656 sbp2port - ok
21:07:26.0704 5656 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\windows\system32\DRIVERS\scfilter.sys
21:07:26.0706 5656 scfilter - ok
21:07:26.0745 5656 sdbus (111e0ebc0ad79cb0fa014b907b231cf0) C:\windows\system32\DRIVERS\sdbus.sys
21:07:26.0748 5656 sdbus - ok
21:07:26.0777 5656 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\windows\system32\drivers\secdrv.sys
21:07:26.0778 5656 secdrv - ok
21:07:26.0906 5656 ser2at (9b9b2f0a0432d938c726ccb25d66cb1b) C:\windows\system32\DRIVERS\ser2at64.sys
21:07:26.0909 5656 ser2at - ok
21:07:26.0954 5656 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\windows\system32\DRIVERS\serenum.sys
21:07:26.0956 5656 Serenum - ok
21:07:26.0970 5656 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\windows\system32\drivers\serial.sys
21:07:26.0974 5656 Serial - ok
21:07:26.0984 5656 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\windows\system32\drivers\sermouse.sys
21:07:26.0987 5656 sermouse - ok
21:07:27.0002 5656 sffdisk (a554811bcd09279536440c964ae35bbf) C:\windows\system32\drivers\sffdisk.sys
21:07:27.0004 5656 sffdisk - ok
21:07:27.0012 5656 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\windows\system32\drivers\sffp_mmc.sys
21:07:27.0013 5656 sffp_mmc - ok
21:07:27.0021 5656 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\windows\system32\drivers\sffp_sd.sys
21:07:27.0022 5656 sffp_sd - ok
21:07:27.0030 5656 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\windows\system32\drivers\sfloppy.sys
21:07:27.0031 5656 sfloppy - ok
21:07:27.0071 5656 Sftfs (c6cc9297bd53e5229653303e556aa539) C:\windows\system32\DRIVERS\Sftfslh.sys
21:07:27.0074 5656 Sftfs - ok
21:07:27.0172 5656 Sftplay (390aa7bc52cee43f6790cdea1e776703) C:\windows\system32\DRIVERS\Sftplaylh.sys
21:07:27.0177 5656 Sftplay - ok
21:07:27.0196 5656 Sftredir (617e29a0b0a2807466560d4c4e338d3e) C:\windows\system32\DRIVERS\Sftredirlh.sys
21:07:27.0197 5656 Sftredir - ok
21:07:27.0223 5656 Sftvol (8f571f016fa1976f445147e9e6c8ae9b) C:\windows\system32\DRIVERS\Sftvollh.sys
21:07:27.0224 5656 Sftvol - ok
21:07:27.0275 5656 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\windows\system32\drivers\SiSRaid2.sys
21:07:27.0277 5656 SiSRaid2 - ok
21:07:27.0364 5656 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\windows\system32\drivers\sisraid4.sys
21:07:27.0367 5656 SiSRaid4 - ok
21:07:27.0389 5656 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\windows\system32\DRIVERS\smb.sys
21:07:27.0392 5656 Smb - ok
21:07:27.0412 5656 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\windows\system32\drivers\spldr.sys
21:07:27.0413 5656 spldr - ok
21:07:27.0443 5656 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\windows\system32\DRIVERS\srv.sys
21:07:27.0448 5656 srv - ok
21:07:27.0459 5656 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\windows\system32\DRIVERS\srv2.sys
21:07:27.0464 5656 srv2 - ok
21:07:27.0478 5656 srvnet (27e461f0be5bff5fc737328f749538c3) C:\windows\system32\DRIVERS\srvnet.sys
21:07:27.0480 5656 srvnet - ok
21:07:27.0521 5656 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\windows\system32\drivers\stexstor.sys
21:07:27.0522 5656 stexstor - ok
21:07:27.0635 5656 StillCam (decacb6921ded1a38642642685d77dac) C:\windows\system32\DRIVERS\serscan.sys
21:07:27.0637 5656 StillCam - ok
21:07:27.0676 5656 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\windows\system32\drivers\swenum.sys
21:07:27.0677 5656 swenum - ok
21:07:27.0756 5656 SynTP (f5b46df59feaa48a442aed7eeb754d4b) C:\windows\system32\DRIVERS\SynTP.sys
21:07:27.0771 5656 SynTP - ok
21:07:27.0924 5656 Tcpip (fc62769e7bff2896035aeed399108162) C:\windows\system32\drivers\tcpip.sys
21:07:27.0950 5656 Tcpip - ok
21:07:27.0992 5656 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\windows\system32\DRIVERS\tcpip.sys
21:07:28.0007 5656 TCPIP6 - ok
21:07:28.0030 5656 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\windows\system32\drivers\tcpipreg.sys
21:07:28.0031 5656 tcpipreg - ok
21:07:28.0163 5656 tdcmdpst (fd542b661bd22fa69ca789ad0ac58c29) C:\windows\system32\DRIVERS\tdcmdpst.sys
21:07:28.0164 5656 tdcmdpst - ok
21:07:28.0193 5656 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\windows\system32\drivers\tdpipe.sys
21:07:28.0195 5656 TDPIPE - ok
21:07:28.0207 5656 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\windows\system32\drivers\tdtcp.sys
21:07:28.0209 5656 TDTCP - ok
21:07:28.0233 5656 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\windows\system32\DRIVERS\tdx.sys
21:07:28.0236 5656 tdx - ok
21:07:28.0311 5656 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\windows\system32\drivers\termdd.sys
21:07:28.0313 5656 TermDD - ok
21:07:28.0446 5656 Thpdrv (7f35ca8296a52c7161088eb1d952e8ed) C:\windows\system32\DRIVERS\thpdrv.sys
21:07:28.0448 5656 Thpdrv - ok
21:07:28.0480 5656 Thpevm (b4e609047434ed948af7bdef2fa66e38) C:\windows\system32\DRIVERS\Thpevm.SYS
21:07:28.0481 5656 Thpevm - ok
21:07:28.0628 5656 Tosrfcom - ok
21:07:28.0660 5656 tosrfec (f5e3ac4cbcd154ee80849b21887fd0b0) C:\windows\system32\DRIVERS\tosrfec.sys
21:07:28.0661 5656 tosrfec - ok
21:07:28.0686 5656 Tosrfusb (7a0048693f98460ff537be31c741b927) C:\windows\system32\DRIVERS\tosrfusb.sys
21:07:28.0687 5656 Tosrfusb - ok
21:07:28.0741 5656 tos_sps64 (09ff7b0b1b5c3d225495cb6f5a9b39f8) C:\windows\system32\DRIVERS\tos_sps64.sys
21:07:28.0752 5656 tos_sps64 - ok
21:07:28.0866 5656 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\windows\system32\DRIVERS\tssecsrv.sys
21:07:28.0869 5656 tssecsrv - ok
21:07:28.0906 5656 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\windows\system32\drivers\tsusbflt.sys
21:07:28.0909 5656 TsUsbFlt - ok
21:07:28.0921 5656 TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\windows\system32\drivers\TsUsbGD.sys
21:07:28.0923 5656 TsUsbGD - ok
21:07:28.0971 5656 tunnel (3566a8daafa27af944f5d705eaa64894) C:\windows\system32\DRIVERS\tunnel.sys
21:07:28.0973 5656 tunnel - ok
21:07:29.0100 5656 TVALZ (550b567f9364d8f7684c3fb3ea665a72) C:\windows\system32\DRIVERS\TVALZ_O.SYS
21:07:29.0102 5656 TVALZ - ok
21:07:29.0138 5656 TVALZFL (9c7191f4b2e49bff47a6c1144b5923fa) C:\windows\system32\DRIVERS\TVALZFL.sys
21:07:29.0139 5656 TVALZFL - ok
21:07:29.0172 5656 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\windows\system32\drivers\uagp35.sys
21:07:29.0175 5656 uagp35 - ok
21:07:29.0202 5656 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\windows\system32\DRIVERS\udfs.sys
21:07:29.0209 5656 udfs - ok
21:07:29.0313 5656 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\windows\system32\drivers\uliagpkx.sys
21:07:29.0316 5656 uliagpkx - ok
21:07:29.0350 5656 umbus (dc54a574663a895c8763af0fa1ff7561) C:\windows\system32\DRIVERS\umbus.sys
21:07:29.0352 5656 umbus - ok
21:07:29.0374 5656 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\windows\system32\drivers\umpass.sys
21:07:29.0376 5656 UmPass - ok
21:07:29.0435 5656 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\windows\system32\drivers\usbaudio.sys
21:07:29.0438 5656 usbaudio - ok
21:07:29.0538 5656 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\windows\system32\DRIVERS\usbccgp.sys
21:07:29.0541 5656 usbccgp - ok
21:07:29.0589 5656 usbcir (af0892a803fdda7492f595368e3b68e7) C:\windows\system32\drivers\usbcir.sys
21:07:29.0593 5656 usbcir - ok
21:07:29.0614 5656 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\windows\system32\DRIVERS\usbehci.sys
21:07:29.0616 5656 usbehci - ok
21:07:29.0646 5656 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\windows\system32\drivers\usbhub.sys
21:07:29.0653 5656 usbhub - ok
21:07:29.0749 5656 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\windows\system32\drivers\usbohci.sys
21:07:29.0751 5656 usbohci - ok
21:07:29.0774 5656 usbprint (73188f58fb384e75c4063d29413cee3d) C:\windows\system32\drivers\usbprint.sys
21:07:29.0777 5656 usbprint - ok
21:07:29.0789 5656 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\windows\system32\DRIVERS\USBSTOR.SYS
21:07:29.0792 5656 USBSTOR - ok
21:07:29.0802 5656 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\windows\system32\drivers\usbuhci.sys
21:07:29.0803 5656 usbuhci - ok
21:07:29.0841 5656 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\windows\system32\Drivers\usbvideo.sys
21:07:29.0844 5656 usbvideo - ok
21:07:29.0868 5656 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\windows\system32\drivers\vdrvroot.sys
21:07:29.0869 5656 vdrvroot - ok
21:07:29.0963 5656 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\windows\system32\DRIVERS\vgapnp.sys
21:07:29.0965 5656 vga - ok
21:07:30.0000 5656 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\windows\System32\drivers\vga.sys
21:07:30.0002 5656 VgaSave - ok
21:07:30.0016 5656 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\windows\system32\drivers\vhdmp.sys
21:07:30.0021 5656 vhdmp - ok
21:07:30.0031 5656 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\windows\system32\drivers\viaide.sys
21:07:30.0033 5656 viaide - ok
21:07:30.0068 5656 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\windows\system32\drivers\volmgr.sys
21:07:30.0070 5656 volmgr - ok
21:07:30.0092 5656 volmgrx (a255814907c89be58b79ef2f189b843b) C:\windows\system32\drivers\volmgrx.sys
21:07:30.0098 5656 volmgrx - ok
21:07:30.0113 5656 volsnap (df8126bd41180351a093a3ad2fc8903b) C:\windows\system32\drivers\volsnap.sys
21:07:30.0118 5656 volsnap - ok
21:07:30.0229 5656 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\windows\system32\drivers\vsmraid.sys
21:07:30.0233 5656 vsmraid - ok
21:07:30.0268 5656 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\windows\system32\DRIVERS\vwifibus.sys
21:07:30.0270 5656 vwifibus - ok
21:07:30.0310 5656 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\windows\system32\DRIVERS\vwififlt.sys
21:07:30.0313 5656 vwififlt - ok
21:07:30.0331 5656 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\windows\system32\drivers\wacompen.sys
21:07:30.0333 5656 WacomPen - ok
21:07:30.0422 5656 WANARP (356afd78a6ed4457169241ac3965230c) C:\windows\system32\DRIVERS\wanarp.sys
21:07:30.0425 5656 WANARP - ok
21:07:30.0432 5656 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\windows\system32\DRIVERS\wanarp.sys
21:07:30.0434 5656 Wanarpv6 - ok
21:07:30.0498 5656 Wd (72889e16ff12ba0f235467d6091b17dc) C:\windows\system32\drivers\wd.sys
21:07:30.0500 5656 Wd - ok
21:07:30.0540 5656 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\windows\system32\drivers\Wdf01000.sys
21:07:30.0554 5656 Wdf01000 - ok
21:07:30.0664 5656 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\windows\system32\DRIVERS\wfplwf.sys
21:07:30.0666 5656 WfpLwf - ok
21:07:30.0699 5656 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\windows\system32\drivers\wimmount.sys
21:07:30.0701 5656 WIMMount - ok
21:07:30.0759 5656 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\windows\system32\drivers\wmiacpi.sys
21:07:30.0759 5656 WmiAcpi - ok
21:07:30.0854 5656 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\windows\system32\drivers\ws2ifsl.sys
21:07:30.0855 5656 ws2ifsl - ok
21:07:30.0892 5656 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\windows\system32\drivers\WudfPf.sys
21:07:30.0893 5656 WudfPf - ok
21:07:30.0917 5656 MBR (0x1B8) (5b5e648d12fcadc244c1ec30318e1eb9) \Device\Harddisk0\DR0
21:07:30.0974 5656 \Device\Harddisk0\DR0 - ok
21:07:30.0987 5656 Boot (0x1200) (2a5f24d37cbfd320d97ca803d5eebcc1) \Device\Harddisk0\DR0\Partition0
21:07:30.0989 5656 \Device\Harddisk0\DR0\Partition0 - ok
21:07:30.0990 5656 ============================================================
21:07:30.0990 5656 Scan finished
21:07:30.0990 5656 ============================================================
21:07:31.0007 1796 Detected object count: 0
21:07:31.0007 1796 Actual detected object count: 0

#13 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:02:19 AM

Posted 23 February 2012 - 09:10 PM

hello


That is only one of the reports can you send me the other one please


gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#14 WilliamBuell

WilliamBuell
  • Topic Starter

  • Members
  • 53 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NYC USA
  • Local time:01:19 AM

Posted 23 February 2012 - 09:14 PM

aswMBR version 0.9.9.1649 Copyright© 2011 AVAST Software
Run date: 2012-02-23 21:09:37
-----------------------------
21:09:37.814 OS Version: Windows x64 6.1.7601 Service Pack 1
21:09:37.814 Number of processors: 4 586 0x2A07
21:09:37.814 ComputerName: WILLIAM-PC UserName: William
21:09:38.861 Initialize success
21:10:24.884 AVAST engine defs: 12022301
21:10:39.657 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
21:10:39.657 Disk 0 Vendor: TOSHIBA_ MH00 Size: 610480MB BusType: 3
21:10:39.673 Disk 0 MBR read successfully
21:10:39.688 Disk 0 MBR scan
21:10:39.688 Disk 0 Windows VISTA default MBR code
21:10:39.704 Disk 0 Partition 1 80 (A) 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048
21:10:39.720 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 593470 MB offset 3074048
21:10:39.751 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 15509 MB offset 1218500608
21:10:39.798 Disk 0 scanning C:\windows\system32\drivers
21:10:46.880 Service scanning
21:11:10.623 Modules scanning
21:11:10.639 Disk 0 trace - called modules:
21:11:10.732 ntoskrnl.exe CLASSPNP.SYS disk.sys thpdrv.sys iaStor.sys hal.dll
21:11:10.748 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007edc060]
21:11:10.748 3 CLASSPNP.SYS[fffff8800160143f] -> nt!IofCallDriver -> \Device\THPDRV1[0xfffffa8007edb060]
21:11:10.764 5 thpdrv.sys[fffff88001b9e2b0] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800610a050]
21:11:11.824 AVAST engine scan C:\windows
21:11:14.289 AVAST engine scan C:\windows\system32
21:12:57.171 AVAST engine scan C:\windows\system32\drivers
21:13:05.268 AVAST engine scan C:\Users\William
21:13:38.714 Disk 0 MBR has been saved successfully to "C:\Users\William\Desktop\MBR.dat"
21:13:38.714 The log file has been saved successfully to "C:\Users\William\Desktop\aswMBRlog.txt"

#15 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:02:19 AM

Posted 23 February 2012 - 09:22 PM

Greetings

At this time I would like you to run this script for me and it is a good time to check out the computer to see if there is anything else that needs to be addressed.

:Run CFScript:

Open Notepad and copy/paste the text in the box into the window:

ClearJavaCache::

DDS::
uStart Page = hxxp://www.ask.com/?l=dis&o=100000018&gct=hp

Save it to your desktop as CFScript.txt

Refering to the picture above, drag CFScript.txt into ComboFix.exe
Posted Image
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following

  • report from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now after running the script?

Gringo

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users