Jump to content

Nephel

Members
  • Posts

    10
  • Joined

  • Last visited

Everything posted by Nephel

  1. Combofix Uninstalled Ahh again, Thank you so much for your help. I am very grateful for your assistance. Kind Regards James
  2. IS it ok to Reinstall AVG? ComboFix 11-07-12.05 - James 07/12/2011 10:00:09.1.2 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4095.3314 [GMT -4:00] Running from: c:\users\James\Desktop\ComboFix.exe SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\system32\drivers\fad.sys . . ((((((((((((((((((((((((( Files Created from 2011-06-12 to 2011-07-12 ))))))))))))))))))))))))))))))) . . 2011-07-12 14:03 . 2011-07-12 14:03 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-07-12 12:59 . 2011-07-12 13:01 -------- d-----w- c:\windows\system32\appmgmt 2011-07-11 04:02 . 2011-07-11 04:03 -------- d-----w- c:\program files (x86)\GSC 2.00 2011-07-11 04:02 . 2011-07-11 04:30 -------- d-----w- c:\users\James\AppData\Roaming\GSC 2.00 2011-07-10 01:44 . 2011-07-12 09:32 -------- d-----w- c:\program files\PeerBlock 2011-07-09 01:29 . 2011-07-09 01:29 -------- d--h--r- c:\users\James\AppData\Roaming\SecuROM 2011-07-09 01:13 . 2011-07-09 01:29 -------- d-----w- c:\users\James\AppData\Local\My Games 2011-07-09 01:12 . 2003-03-19 07:14 499712 ----a-w- c:\windows\SysWow64\MSVCP71.DLL 2011-07-09 01:12 . 2003-03-19 07:14 499712 ----a-w- c:\windows\system32\MSVCP71.DLL 2011-07-09 01:10 . 2004-01-12 04:00 348160 ----a-w- c:\windows\SysWow64\msvcr71.dll 2011-07-09 01:10 . 2004-01-12 04:00 348160 ----a-w- c:\windows\system32\msvcr71.dll 2011-07-09 01:01 . 2011-07-09 01:01 -------- d-----w- c:\program files (x86)\Firaxis Games 2011-07-08 11:42 . 2011-07-08 11:42 -------- d-----w- c:\program files (x86)\WinPcap 2011-07-08 03:26 . 2011-07-10 16:39 -------- d-----w- c:\users\James\AppData\Roaming\QuickScan 2011-07-08 01:07 . 2011-07-08 01:07 -------- d-----w- c:\program files (x86)\Marvell 2011-07-07 23:23 . 2011-07-07 23:23 -------- d-sh--w- c:\windows\system32\%APPDATA% 2011-07-06 06:24 . 2011-07-06 06:25 -------- d-----w- c:\users\James\AppData\Local\ElevatedDiagnostics 2011-07-05 09:13 . 2011-07-05 09:13 -------- d-----w- c:\users\James\AppData\Roaming\Malwarebytes 2011-07-05 09:13 . 2011-07-05 09:13 -------- d-----w- c:\programdata\Malwarebytes 2011-07-05 09:13 . 2011-05-29 13:11 39984 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys 2011-07-05 09:13 . 2011-07-05 09:13 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-07-05 09:13 . 2011-05-29 13:11 25912 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-07-05 09:11 . 2011-07-05 09:53 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2011-07-05 09:11 . 2011-07-05 09:13 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2011-07-04 12:26 . 2011-07-04 12:44 -------- d-----w- c:\users\James\AppData\Roaming\EveHQ 2011-07-04 02:41 . 2009-02-25 21:24 35840 ----a-r- c:\windows\system32\drivers\BVRPMPR5a64.SYS 2011-07-04 02:40 . 2011-07-04 02:47 -------- d-----w- C:\Netgear 2011-07-04 01:31 . 2011-07-04 01:31 55384 ----a-w- c:\windows\system32\drivers\SBREDrv.sys 2011-07-04 01:29 . 2011-07-12 13:01 -------- dc----w- c:\windows\system32\DRVSTORE 2011-07-04 01:29 . 2011-07-12 13:01 -------- d-----w- c:\programdata\Lavasoft 2011-07-02 20:36 . 2011-07-02 20:36 -------- d--h--w- c:\windows\msdownld.tmp 2011-06-28 22:20 . 2011-05-24 11:42 404480 ----a-w- c:\windows\system32\umpnpmgr.dll 2011-06-26 09:44 . 2011-06-26 09:44 2106216 ----a-w- c:\program files (x86)\Mozilla Firefox\D3DCompiler_43.dll 2011-06-26 09:44 . 2011-06-26 09:44 1998168 ----a-w- c:\program files (x86)\Mozilla Firefox\d3dx9_43.dll 2011-06-25 08:25 . 2011-06-28 21:38 -------- d-----w- c:\users\James\AppData\Roaming\EVEMon 2011-06-25 08:13 . 2011-06-25 08:13 -------- d-----w- c:\program files (x86)\EVEMon 2011-06-24 07:20 . 2011-06-24 07:22 -------- d-----w- c:\users\James\AppData\Roaming\Ventrilo 2011-06-24 07:20 . 2011-06-24 07:20 -------- d-----w- c:\program files\Ventrilo 2011-06-24 07:19 . 2011-06-24 07:19 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard 2011-06-24 04:23 . 2011-06-24 04:23 -------- d-----w- c:\users\James\AppData\Local\CCP 2011-06-24 03:41 . 2011-06-24 04:20 -------- d-----w- c:\users\James\AppData\Local\Microsoft Games 2011-06-24 01:06 . 2011-06-24 01:06 -------- d-----w- c:\program files (x86)\Microsoft Silverlight 2011-06-22 23:27 . 2011-06-22 23:27 -------- d-----w- c:\program files (x86)\CCP 2011-06-22 22:06 . 2011-06-28 19:33 -------- d-----w- c:\programdata\CCP 2011-06-21 19:55 . 2011-06-21 19:55 -------- d-----w- c:\users\James\AppData\Roaming\Perpetuum Planner 2011-06-20 19:19 . 2011-06-20 19:19 -------- d-----w- c:\program files (x86)\Google 2011-06-20 19:19 . 2011-06-20 19:19 -------- d-----w- c:\users\James\AppData\Local\Google 2011-06-16 00:10 . 2011-04-25 05:33 1923968 ----a-w- c:\windows\system32\drivers\tcpip.sys 2011-06-16 00:10 . 2011-04-25 02:34 499200 ----a-w- c:\windows\system32\drivers\afd.sys 2011-06-16 00:10 . 2011-04-27 02:40 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-06-16 00:10 . 2011-04-27 02:39 289280 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-06-16 00:10 . 2011-04-27 02:39 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-06-16 00:10 . 2011-05-28 03:06 3135488 ----a-w- c:\windows\system32\win32k.sys 2011-06-16 00:09 . 2011-04-29 03:06 467456 ----a-w- c:\windows\system32\drivers\srv.sys 2011-06-16 00:09 . 2011-04-29 03:05 410112 ----a-w- c:\windows\system32\drivers\srv2.sys 2011-06-16 00:09 . 2011-04-29 03:05 168448 ----a-w- c:\windows\system32\drivers\srvnet.sys 2011-06-16 00:09 . 2011-02-25 06:22 861696 ----a-w- c:\windows\system32\oleaut32.dll 2011-06-16 00:09 . 2011-02-25 05:34 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll 2011-06-16 00:09 . 2011-05-03 05:29 976896 ----a-w- c:\windows\system32\inetcomm.dll 2011-06-16 00:09 . 2011-05-03 04:30 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll 2011-06-13 21:30 . 2011-06-13 21:30 -------- d-----w- c:\users\UpdatusUser 2011-06-13 21:30 . 2011-06-13 21:31 -------- d-----w- c:\programdata\NVIDIA 2011-06-13 21:30 . 2011-06-13 21:30 -------- d-----w- c:\program files (x86)\NVIDIA Corporation 2011-06-13 21:29 . 2011-06-13 21:29 -------- d-----w- c:\programdata\NVIDIA Corporation . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-22 03:52 . 2011-05-22 03:52 43680 ----a-w- c:\windows\system32\drivers\lirsgt.sys 2011-05-22 03:52 . 2011-05-22 03:52 314016 ----a-w- c:\windows\system32\drivers\atksgt.sys 2011-05-21 02:35 . 2011-05-21 02:35 304744 ----a-w- c:\windows\SysWow64\nvStreaming.exe 2011-05-05 02:29 . 2011-04-05 08:54 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll 2011-04-22 22:15 . 2011-05-27 11:31 27520 ----a-w- c:\windows\system32\drivers\Diskdump.sys 2011-04-15 11:34 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll 2011-04-15 11:34 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Razer Naga Driver"="c:\program files (x86)\Razer\Naga\RazerNagaSysTray.exe" [2011-02-17 953744] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640] R3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;c:\windows\system32\drivers\BVRPMPR5a64.SYS [x] R3 dump_wmimmc;dump_wmimmc;c:\program files (x86)\NCsoft\Lineage II\system\GameGuard\dump_wmimmc.sys [x] R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [x] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x] R3 Synth3dVsc;Synth3dVsc; [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 tsusbhub;tsusbhub; [x] R3 VGPU;VGPU; [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-03-11 79360] R4 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-20 136176] R4 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-20 136176] R4 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] R4 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-04-08 2218600] S3 RTCore64;RTCore64;c:\program files (x86)\EVGA Precision\RTCore64.sys [2011-01-17 14440] S3 RzSynapse;Razer Driver;c:\windows\system32\DRIVERS\RzSynapse.sys [x] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2011-07-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-20 19:19] . 2011-07-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-20 19:19] . . --------- x86-64 ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ------- Supplementary Scan ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 209.18.47.61 209.18.47.62 FF - ProfilePath - c:\users\James\AppData\Roaming\Mozilla\Firefox\Profiles\4njngypd.default\ FF - user.js: yahoo.ytff.general.dontshowhpoffer - true . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-997304682-3190244857-24308984-1001\Software\SecuROM\License information*] "datasecu"=hex:75,0b,12,c5,5e,a1,b0,41,c2,7e,19,88,7e,4d,3e,f0,66,bf,3d,b2,2a, b9,2b,da,e5,93,7f,ff,d6,27,b8,bb,d7,1b,2e,5f,a7,d6,05,a9,b0,20,79,c3,0d,92,\ "rkeysecu"=hex:fe,4a,ef,4f,74,a5,e0,b5,d4,0f,49,c6,01,a8,5a,3e . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Other Running Processes ------------------------ . c:\program files (x86)\EVGA Precision\EVGAPrecision.exe . ************************************************************************** . Completion time: 2011-07-12 10:06:57 - machine was rebooted ComboFix-quarantined-files.txt 2011-07-12 14:06 . Pre-Run: 28,662,280,192 bytes free Post-Run: 28,375,412,736 bytes free . - - End Of File - - D03C276A1510A86F8D6182AC97C36F57
  3. Ok will do that for the Router... Thank you very Much for your time Mr Tate. I do appreciate it immensely.
  4. Like right now.. AVG isnt running nor is malware bytes.. but I can hear my HD doing work.. I have a raptor .. and it can get pretty audible.. so not sure what its doing. *grabs tin foil hat* just really paranoid now.. i hope is all that is
  5. Like clockwork for a few days since just before the 4th of July internet would drop connection. I started checking router logs and found the lan access from remote... a LOT of them.. so was naturally freaked out.. started doing what i could with almost no networking know how, to thwart my issue. I Closed several ports.. wasnt able to block a specific ip or mac address. But as I mentioned above ever since I switched to directly connected to modem i was able to watch them atempt a portscan and acquired their ip address.. then blocked that port. Not sure if malware can do that sort of thing or not.
  6. I havnet disconnected... however I wasnt when I gave an update.. I switched a few things.. mainly removed my wireless router .. Kinda nervous to use it at the moment. malwarebytes did detect something on one of my removeable drives and cleaned that.. a rt2platv156nocdgsg9.exe (PUP.Hacktool.Patcher) Did you find any type of malware.. or was this some random smo or bot that got ahold of muh ip for a few days?
  7. 2011/07/12 09:07:57.0682 2844 TDSS rootkit removing tool 2.5.11.0 Jul 11 2011 16:56:56 2011/07/12 09:07:59.0032 2844 ================================================================================ 2011/07/12 09:07:59.0032 2844 SystemInfo: 2011/07/12 09:07:59.0032 2844 2011/07/12 09:07:59.0032 2844 OS Version: 6.1.7601 ServicePack: 1.0 2011/07/12 09:07:59.0032 2844 Product type: Workstation 2011/07/12 09:07:59.0032 2844 ComputerName: NEPHEL 2011/07/12 09:07:59.0032 2844 UserName: James 2011/07/12 09:07:59.0032 2844 Windows directory: C:\Windows 2011/07/12 09:07:59.0032 2844 System windows directory: C:\Windows 2011/07/12 09:07:59.0032 2844 Running under WOW64 2011/07/12 09:07:59.0032 2844 Processor architecture: Intel x64 2011/07/12 09:07:59.0032 2844 Number of processors: 2 2011/07/12 09:07:59.0032 2844 Page size: 0x1000 2011/07/12 09:07:59.0032 2844 Boot type: Normal boot 2011/07/12 09:07:59.0032 2844 ================================================================================ 2011/07/12 09:07:59.0952 2844 Initialize success 2011/07/12 09:08:02.0792 1612 ================================================================================ 2011/07/12 09:08:02.0792 1612 Scan started 2011/07/12 09:08:02.0792 1612 Mode: Manual; 2011/07/12 09:08:02.0792 1612 ================================================================================ 2011/07/12 09:08:03.0942 1612 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys 2011/07/12 09:08:03.0972 1612 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys 2011/07/12 09:08:04.0012 1612 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys 2011/07/12 09:08:04.0062 1612 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys 2011/07/12 09:08:04.0102 1612 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys 2011/07/12 09:08:04.0122 1612 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys 2011/07/12 09:08:04.0182 1612 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys 2011/07/12 09:08:04.0212 1612 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys 2011/07/12 09:08:04.0232 1612 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys 2011/07/12 09:08:04.0252 1612 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys 2011/07/12 09:08:04.0272 1612 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys 2011/07/12 09:08:04.0282 1612 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys 2011/07/12 09:08:04.0312 1612 amdsata (6ec6d772eae38dc17c14aed9b178d24b) C:\Windows\system32\drivers\amdsata.sys 2011/07/12 09:08:04.0342 1612 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys 2011/07/12 09:08:04.0362 1612 amdxata (1142a21db581a84ea5597b03a26ebaa0) C:\Windows\system32\drivers\amdxata.sys 2011/07/12 09:08:04.0402 1612 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys 2011/07/12 09:08:04.0442 1612 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys 2011/07/12 09:08:04.0462 1612 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys 2011/07/12 09:08:04.0502 1612 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 2011/07/12 09:08:04.0522 1612 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys 2011/07/12 09:08:04.0572 1612 atksgt (fc0e8778c000291caf60eb88c011e931) C:\Windows\system32\DRIVERS\atksgt.sys 2011/07/12 09:08:04.0622 1612 Avgfwfd (705417fd6c165ccf926aca943b478d68) C:\Windows\system32\DRIVERS\avgfwd6a.sys 2011/07/12 09:08:04.0652 1612 AVGIDSDriver (eee718457f24f2154f23a7fad1a0cea3) C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys 2011/07/12 09:08:04.0672 1612 AVGIDSEH (1553b388e0f0462c25ad8f30c3c29e83) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys 2011/07/12 09:08:04.0692 1612 AVGIDSFilter (dca426a66739e75f51a72160dfb945ad) C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys 2011/07/12 09:08:04.0902 1612 Avgldx64 (ff7383388a7d2283dae5831abc2b0720) C:\Windows\system32\DRIVERS\avgldx64.sys 2011/07/12 09:08:04.0982 1612 Avgmfx64 (997d002827d3e3dcbbb25bf46db161ab) C:\Windows\system32\DRIVERS\avgmfx64.sys 2011/07/12 09:08:05.0022 1612 Avgrkx64 (bccfe3374c887075cde2ac8fdb1cb2f8) C:\Windows\system32\DRIVERS\avgrkx64.sys 2011/07/12 09:08:05.0052 1612 Avgtdia (0d49adcebe243b79366ea523b647519a) C:\Windows\system32\DRIVERS\avgtdia.sys 2011/07/12 09:08:05.0112 1612 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys 2011/07/12 09:08:05.0162 1612 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 2011/07/12 09:08:05.0192 1612 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 2011/07/12 09:08:05.0232 1612 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 2011/07/12 09:08:05.0262 1612 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys 2011/07/12 09:08:05.0292 1612 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys 2011/07/12 09:08:05.0302 1612 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys 2011/07/12 09:08:05.0332 1612 Bridge (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys 2011/07/12 09:08:05.0342 1612 BridgeMP (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys 2011/07/12 09:08:05.0362 1612 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 2011/07/12 09:08:05.0382 1612 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 2011/07/12 09:08:05.0402 1612 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 2011/07/12 09:08:05.0422 1612 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 2011/07/12 09:08:05.0432 1612 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys 2011/07/12 09:08:05.0482 1612 BVRPMPR5a64 (9887ca12f407d7fbc7f48f3678f5f0b6) C:\Windows\system32\drivers\BVRPMPR5a64.SYS 2011/07/12 09:08:05.0512 1612 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 2011/07/12 09:08:05.0542 1612 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys 2011/07/12 09:08:05.0572 1612 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys 2011/07/12 09:08:05.0602 1612 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 2011/07/12 09:08:05.0632 1612 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 2011/07/12 09:08:05.0672 1612 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys 2011/07/12 09:08:05.0712 1612 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys 2011/07/12 09:08:05.0742 1612 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys 2011/07/12 09:08:05.0762 1612 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys 2011/07/12 09:08:05.0792 1612 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys 2011/07/12 09:08:05.0852 1612 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys 2011/07/12 09:08:05.0912 1612 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys 2011/07/12 09:08:05.0942 1612 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 2011/07/12 09:08:05.0972 1612 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys 2011/07/12 09:08:06.0012 1612 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 2011/07/12 09:08:06.0102 1612 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys 2011/07/12 09:08:06.0202 1612 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys 2011/07/12 09:08:06.0302 1612 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys 2011/07/12 09:08:06.0342 1612 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys 2011/07/12 09:08:06.0372 1612 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 2011/07/12 09:08:06.0392 1612 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 2011/07/12 09:08:06.0422 1612 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys 2011/07/12 09:08:06.0442 1612 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 2011/07/12 09:08:06.0472 1612 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 2011/07/12 09:08:06.0492 1612 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys 2011/07/12 09:08:06.0522 1612 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys 2011/07/12 09:08:06.0552 1612 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 2011/07/12 09:08:06.0572 1612 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 2011/07/12 09:08:06.0612 1612 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys 2011/07/12 09:08:06.0632 1612 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys 2011/07/12 09:08:06.0692 1612 hamachi (1e6438d4ea6e1174a3b3b1edc4de660b) C:\Windows\system32\DRIVERS\hamachi.sys 2011/07/12 09:08:06.0712 1612 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 2011/07/12 09:08:06.0752 1612 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys 2011/07/12 09:08:06.0762 1612 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys 2011/07/12 09:08:06.0792 1612 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys 2011/07/12 09:08:06.0802 1612 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys 2011/07/12 09:08:06.0842 1612 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\drivers\hidusb.sys 2011/07/12 09:08:06.0882 1612 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys 2011/07/12 09:08:06.0932 1612 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys 2011/07/12 09:08:06.0982 1612 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys 2011/07/12 09:08:07.0022 1612 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys 2011/07/12 09:08:07.0062 1612 iaStorV (3df4395a7cf8b7a72a5f4606366b8c2d) C:\Windows\system32\drivers\iaStorV.sys 2011/07/12 09:08:07.0082 1612 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys 2011/07/12 09:08:07.0112 1612 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys 2011/07/12 09:08:07.0142 1612 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 2011/07/12 09:08:07.0162 1612 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2011/07/12 09:08:07.0192 1612 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys 2011/07/12 09:08:07.0222 1612 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 2011/07/12 09:08:07.0242 1612 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 2011/07/12 09:08:07.0262 1612 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys 2011/07/12 09:08:07.0292 1612 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys 2011/07/12 09:08:07.0322 1612 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys 2011/07/12 09:08:07.0342 1612 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys 2011/07/12 09:08:07.0362 1612 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys 2011/07/12 09:08:07.0392 1612 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys 2011/07/12 09:08:07.0422 1612 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 2011/07/12 09:08:07.0512 1612 lirsgt (156ab2e56dc3ca0b582e3362e07cded7) C:\Windows\system32\DRIVERS\lirsgt.sys 2011/07/12 09:08:07.0542 1612 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 2011/07/12 09:08:07.0582 1612 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys 2011/07/12 09:08:07.0612 1612 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys 2011/07/12 09:08:07.0632 1612 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys 2011/07/12 09:08:07.0652 1612 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys 2011/07/12 09:08:07.0672 1612 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 2011/07/12 09:08:07.0722 1612 MBAMProtector (ed49fd1373de93617a1f6d128d98fe4d) C:\Windows\system32\drivers\mbam.sys 2011/07/12 09:08:07.0772 1612 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys 2011/07/12 09:08:07.0802 1612 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys 2011/07/12 09:08:07.0822 1612 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 2011/07/12 09:08:07.0862 1612 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 2011/07/12 09:08:07.0902 1612 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys 2011/07/12 09:08:07.0922 1612 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 2011/07/12 09:08:07.0962 1612 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys 2011/07/12 09:08:07.0992 1612 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys 2011/07/12 09:08:08.0012 1612 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 2011/07/12 09:08:08.0052 1612 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys 2011/07/12 09:08:08.0092 1612 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys 2011/07/12 09:08:08.0132 1612 mrxsmb10 (2086d463bd371d8a37d153897430916d) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2011/07/12 09:08:08.0162 1612 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2011/07/12 09:08:08.0192 1612 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys 2011/07/12 09:08:08.0222 1612 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys 2011/07/12 09:08:08.0242 1612 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 2011/07/12 09:08:08.0262 1612 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 2011/07/12 09:08:08.0292 1612 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys 2011/07/12 09:08:08.0332 1612 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 2011/07/12 09:08:08.0342 1612 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 2011/07/12 09:08:08.0362 1612 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 2011/07/12 09:08:08.0402 1612 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys 2011/07/12 09:08:08.0432 1612 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys 2011/07/12 09:08:08.0452 1612 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 2011/07/12 09:08:08.0472 1612 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys 2011/07/12 09:08:08.0502 1612 MTsensor (03b7145c889603537e9ffeabb1ad1089) C:\Windows\system32\DRIVERS\ASACPI.sys 2011/07/12 09:08:08.0522 1612 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 2011/07/12 09:08:08.0562 1612 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 2011/07/12 09:08:08.0622 1612 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys 2011/07/12 09:08:08.0672 1612 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 2011/07/12 09:08:08.0702 1612 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 2011/07/12 09:08:08.0742 1612 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys 2011/07/12 09:08:08.0782 1612 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys 2011/07/12 09:08:08.0822 1612 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys 2011/07/12 09:08:08.0852 1612 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 2011/07/12 09:08:08.0892 1612 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys 2011/07/12 09:08:08.0942 1612 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys 2011/07/12 09:08:08.0992 1612 NPF (351533acc2a069b94e80bbfc177e8fdf) C:\Windows\system32\drivers\npf.sys 2011/07/12 09:08:09.0012 1612 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 2011/07/12 09:08:09.0062 1612 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 2011/07/12 09:08:09.0132 1612 Ntfs (05d78aa5cb5f3f5c31160bdb955d0b7c) C:\Windows\system32\drivers\Ntfs.sys 2011/07/12 09:08:09.0182 1612 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 2011/07/12 09:08:09.0432 1612 nvlddmkm (a963c2c276a97b088ded5d7a83be8052) C:\Windows\system32\DRIVERS\nvlddmkm.sys 2011/07/12 09:08:09.0672 1612 nvraid (5d9fd91f3d38dc9da01e3cb5fa89cd48) C:\Windows\system32\drivers\nvraid.sys 2011/07/12 09:08:09.0702 1612 nvstor (f7cd50fe7139f07e77da8ac8033d1832) C:\Windows\system32\drivers\nvstor.sys 2011/07/12 09:08:09.0752 1612 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys 2011/07/12 09:08:09.0772 1612 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys 2011/07/12 09:08:09.0852 1612 P17 (634347adebc790b8f07654a3ea8034fd) C:\Windows\system32\drivers\P17.sys 2011/07/12 09:08:09.0912 1612 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys 2011/07/12 09:08:10.0002 1612 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys 2011/07/12 09:08:10.0052 1612 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys 2011/07/12 09:08:10.0072 1612 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys 2011/07/12 09:08:10.0102 1612 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys 2011/07/12 09:08:10.0122 1612 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 2011/07/12 09:08:10.0162 1612 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 2011/07/12 09:08:10.0252 1612 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys 2011/07/12 09:08:10.0282 1612 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys 2011/07/12 09:08:10.0332 1612 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys 2011/07/12 09:08:10.0382 1612 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys 2011/07/12 09:08:10.0432 1612 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys 2011/07/12 09:08:10.0462 1612 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 2011/07/12 09:08:10.0482 1612 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 2011/07/12 09:08:10.0512 1612 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 2011/07/12 09:08:10.0552 1612 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys 2011/07/12 09:08:10.0582 1612 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 2011/07/12 09:08:10.0612 1612 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 2011/07/12 09:08:10.0642 1612 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys 2011/07/12 09:08:10.0682 1612 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys 2011/07/12 09:08:10.0702 1612 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 2011/07/12 09:08:10.0732 1612 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys 2011/07/12 09:08:10.0772 1612 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 2011/07/12 09:08:10.0792 1612 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 2011/07/12 09:08:10.0832 1612 RdpVideoMiniport (70cba1a0c98600a2aa1863479b35cb90) C:\Windows\system32\drivers\rdpvideominiport.sys 2011/07/12 09:08:10.0872 1612 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys 2011/07/12 09:08:10.0922 1612 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys 2011/07/12 09:08:10.0972 1612 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 2011/07/12 09:08:11.0002 1612 RTCore64 (98583b2f2efe12d2a167217a3838c498) C:\Program Files (x86)\EVGA Precision\RTCore64.sys 2011/07/12 09:08:11.0042 1612 RzSynapse (24510c4a77aba3b07aefa840db888637) C:\Windows\system32\DRIVERS\RzSynapse.sys 2011/07/12 09:08:11.0072 1612 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys 2011/07/12 09:08:11.0102 1612 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys 2011/07/12 09:08:11.0142 1612 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys 2011/07/12 09:08:11.0182 1612 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 2011/07/12 09:08:11.0212 1612 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys 2011/07/12 09:08:11.0232 1612 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys 2011/07/12 09:08:11.0262 1612 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys 2011/07/12 09:08:11.0312 1612 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys 2011/07/12 09:08:11.0332 1612 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys 2011/07/12 09:08:11.0362 1612 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys 2011/07/12 09:08:11.0382 1612 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys 2011/07/12 09:08:11.0412 1612 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys 2011/07/12 09:08:11.0432 1612 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys 2011/07/12 09:08:11.0462 1612 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 2011/07/12 09:08:11.0492 1612 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 2011/07/12 09:08:11.0542 1612 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys 2011/07/12 09:08:11.0572 1612 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys 2011/07/12 09:08:11.0602 1612 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys 2011/07/12 09:08:11.0632 1612 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys 2011/07/12 09:08:11.0662 1612 storflt (7785dc213270d2fc066538daf94087e7) C:\Windows\system32\drivers\vmstorfl.sys 2011/07/12 09:08:11.0692 1612 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys 2011/07/12 09:08:11.0712 1612 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys 2011/07/12 09:08:11.0822 1612 Tcpip (92ce29d95ac9dd2d0ee9061d551ba250) C:\Windows\system32\drivers\tcpip.sys 2011/07/12 09:08:11.0902 1612 TCPIP6 (92ce29d95ac9dd2d0ee9061d551ba250) C:\Windows\system32\DRIVERS\tcpip.sys 2011/07/12 09:08:11.0942 1612 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys 2011/07/12 09:08:11.0962 1612 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 2011/07/12 09:08:11.0982 1612 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys 2011/07/12 09:08:12.0022 1612 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys 2011/07/12 09:08:12.0062 1612 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys 2011/07/12 09:08:12.0122 1612 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys 2011/07/12 09:08:12.0162 1612 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys 2011/07/12 09:08:12.0222 1612 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys 2011/07/12 09:08:12.0242 1612 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys 2011/07/12 09:08:12.0282 1612 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys 2011/07/12 09:08:12.0332 1612 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys 2011/07/12 09:08:12.0352 1612 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys 2011/07/12 09:08:12.0382 1612 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys 2011/07/12 09:08:12.0412 1612 usbccgp (481dff26b4dca8f4cbac1f7dce1d6829) C:\Windows\system32\drivers\usbccgp.sys 2011/07/12 09:08:12.0452 1612 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys 2011/07/12 09:08:12.0482 1612 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys 2011/07/12 09:08:12.0512 1612 usbhub (dc96bd9ccb8403251bcf25047573558e) C:\Windows\system32\drivers\usbhub.sys 2011/07/12 09:08:12.0542 1612 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys 2011/07/12 09:08:12.0562 1612 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 2011/07/12 09:08:12.0592 1612 USBSTOR (d76510cfa0fc09023077f22c2f979d86) C:\Windows\system32\drivers\USBSTOR.SYS 2011/07/12 09:08:12.0612 1612 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys 2011/07/12 09:08:12.0642 1612 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys 2011/07/12 09:08:12.0662 1612 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 2011/07/12 09:08:12.0682 1612 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 2011/07/12 09:08:12.0732 1612 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys 2011/07/12 09:08:12.0772 1612 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys 2011/07/12 09:08:12.0792 1612 vmbus (86ea3e79ae350fea5331a1303054005f) C:\Windows\system32\drivers\vmbus.sys 2011/07/12 09:08:12.0822 1612 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys 2011/07/12 09:08:12.0852 1612 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys 2011/07/12 09:08:12.0892 1612 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys 2011/07/12 09:08:12.0922 1612 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys 2011/07/12 09:08:12.0952 1612 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys 2011/07/12 09:08:12.0982 1612 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys 2011/07/12 09:08:13.0012 1612 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys 2011/07/12 09:08:13.0042 1612 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 2011/07/12 09:08:13.0052 1612 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 2011/07/12 09:08:13.0092 1612 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys 2011/07/12 09:08:13.0122 1612 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 2011/07/12 09:08:13.0172 1612 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 2011/07/12 09:08:13.0192 1612 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 2011/07/12 09:08:13.0252 1612 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys 2011/07/12 09:08:13.0282 1612 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys 2011/07/12 09:08:13.0332 1612 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 2011/07/12 09:08:13.0382 1612 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys 2011/07/12 09:08:13.0402 1612 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys 2011/07/12 09:08:13.0462 1612 yukonw7 (b3eeacf62445e24fbb2cd4b0fb4db026) C:\Windows\system32\DRIVERS\yk62x64.sys 2011/07/12 09:08:13.0492 1612 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 2011/07/12 09:08:13.0552 1612 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1 2011/07/12 09:08:13.0562 1612 Boot (0x1200) (53c6825cdca81135fd94d63eeacce1c7) \Device\Harddisk0\DR0\Partition0 2011/07/12 09:08:13.0572 1612 Boot (0x1200) (947856b5b0e025bb384b6f6ce7b77bc8) \Device\Harddisk1\DR1\Partition0 2011/07/12 09:08:13.0582 1612 ================================================================================ 2011/07/12 09:08:13.0582 1612 Scan finished 2011/07/12 09:08:13.0582 1612 ================================================================================ 2011/07/12 09:08:13.0582 0496 Detected object count: 0 2011/07/12 09:08:13.0582 0496 Actual detected object count: 0 Computer seems to run normal... obviously a lil slow with the startup of new Internet windows.
  8. *update* I was receiving: [DoS attack: FIN Scan] attack packets in last 20 sec from ip ********, Tuesday, Jul 05,2011 05:51:24 [Admin login] from source 192.168.1.2, Tuesday, Jul 05,2011 05:50:21 [DoS attack: FIN Scan] attack packets in last 20 sec from ip ********, Tuesday, Jul 05,2011 05:49:25 as well as Smurf attack I have the IP address from where the Port scan came from.. I am not sure what your policy is on posting IP address so I did not.. better safe than sorry.
  9. I have Uninstalled Ad-aware and disabled AVG Internet security. An update as of a few days ago... I was constantly being disconnected.. so something/someone was messing with my connection.. I disabled the router and plugged directly into modem.. and watched my firewall logs... I found a Port scan coming from China.. I immediately blocked that port and have had no issues. But I do not feel by just blocking that one port this will stop.
  10. My internet keeps dropping very frequently. 4-5 times an hour... then will reconnect immediately. Disabled upnp on router switched pass and changed the mac address. No more lan access but i Still disconnect from internet. Any assistance would be greatly appreciated. . DDS (Ver_2011-06-23.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_25 Run by James at 22:34:09 on 2011-07-06 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.4095.2571 [GMT -4:00] . AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116} AV: AVG Internet Security 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Internet Security 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB} FW: AVG Firewall *Enabled* {621CC794-9486-F902-D092-0484E8EA828B} . ============== Running Processes =============== . C:\PROGRA~2\AVG\AVG10\avgchsva.exe C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe C:\Windows\system32\taskhost.exe C:\Windows\SysWOW64\svchost.exe -k Akamai C:\Program Files (x86)\AVG\AVG10\avgfws.exe C:\Program Files (x86)\AVG\AVG10\avgtray.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe C:\Windows\system32\taskeng.exe C:\Program Files (x86)\EVGA Precision\EVGAPrecision.exe C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\AVG\AVG10\avgam.exe C:\Program Files (x86)\AVG\AVG10\avgnsa.exe C:\Program Files (x86)\AVG\AVG10\avgemca.exe C:\Windows\system32\conhost.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\WUDFHost.exe C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Windows\system32\svchost.exe -k SDRSVC C:\PROGRA~2\AVG\AVG10\avgrsa.exe C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files (x86)\EVGA Precision\Bundle\OSDServer\RTSS.exe C:\Program Files (x86)\Yahoo!\Messenger\ymsgr_tray.exe C:\Windows\system32\conhost.exe C:\Program Files (x86)\AVG\AVG10\avgui.exe C:\Windows\system32\NOTEPAD.EXE C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uWindow Title = Internet Explorer, optimized for Bing and MSN mWinlogon: Userinit=userinit.exe, BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll uRun: [spybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll Trusted Zone: real.com\rhap-app-4-0 Trusted Zone: real.com\rhapreg DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{7CA998F3-20C6-49E4-83AA-5C5F9E68F968} : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{FBB7F7E9-C982-4379-83C0-EAF8EFCA7250} : DhcpNameServer = 192.168.1.1 Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll mRun-x64: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\James\AppData\Roaming\Mozilla\Firefox\Profiles\4njngypd.default\ FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox4\components\avgssff4.dll FF - plugin: C:\Program Files (x86)\Download Manager\npfpdlm.dll FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll . ---- FIREFOX POLICIES ---- FF - user.js: yahoo.ytff.general.dontshowhpoffer - true ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys --> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?] R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?] R0 Lbd;Lbd;C:\Windows\system32\DRIVERS\Lbd.sys --> C:\Windows\system32\DRIVERS\Lbd.sys [?] R1 Avgfwfd;AVG network filter service;C:\Windows\system32\DRIVERS\avgfwd6a.sys --> C:\Windows\system32\DRIVERS\avgfwd6a.sys [?] R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?] R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?] R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?] R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-13 20992] R2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG10\avgfws.exe [2011-3-9 2708024] R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-4-18 7398752] R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2011-2-8 269520] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-6-20 2151640] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-7-5 366640] R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys --> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?] R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys --> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?] R3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys [2011-7-3 17152] R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?] R3 RTCore64;RTCore64;C:\Program Files (x86)\EVGA Precision\RTCore64.sys [2011-1-17 14440] R3 RzSynapse;Razer Driver;C:\Windows\system32\DRIVERS\RzSynapse.sys --> C:\Windows\system32\DRIVERS\RzSynapse.sys [?] R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver;\??\C:\Windows\system32\drivers\BVRPMPR5a64.SYS --> C:\Windows\system32\drivers\BVRPMPR5a64.SYS [?] S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service --> C:\Windows\system32\GameMon.des -service [?] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?] S4 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-3-11 79360] S4 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-6-20 136176] S4 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-6-20 136176] S4 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-1-15 227232] S4 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-6-13 2218600] . =============== Created Last 30 ================ . 2011-07-06 06:24:21 -------- d-----w- C:\Users\James\AppData\Local\ElevatedDiagnostics 2011-07-05 09:13:30 -------- d-----w- C:\Users\James\AppData\Roaming\Malwarebytes 2011-07-05 09:13:23 39984 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys 2011-07-05 09:13:23 -------- d-----w- C:\ProgramData\Malwarebytes 2011-07-05 09:13:20 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys 2011-07-05 09:13:20 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2011-07-05 09:11:18 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy 2011-07-05 09:11:18 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2011-07-04 12:26:05 -------- d-----w- C:\Users\James\AppData\Roaming\EveHQ 2011-07-04 03:45:28 16432 ----a-w- C:\Windows\System32\lsdelete.exe 2011-07-04 02:41:16 35840 ----a-r- C:\Windows\System32\drivers\BVRPMPR5a64.SYS 2011-07-04 02:40:51 -------- d-----w- C:\Netgear 2011-07-04 01:31:39 55384 ----a-w- C:\Windows\System32\drivers\SBREDrv.sys 2011-07-04 01:29:54 69376 ----a-w- C:\Windows\System32\drivers\Lbd.sys 2011-07-04 01:29:52 -------- d-----w- C:\Program Files (x86)\Lavasoft 2011-07-02 20:36:12 -------- d--h--w- C:\Windows\msdownld.tmp 2011-06-28 22:20:25 64512 ----a-w- C:\Windows\SysWow64\devobj.dll 2011-06-26 09:44:48 2106216 ----a-w- C:\Program Files (x86)\Mozilla Firefox\D3DCompiler_43.dll 2011-06-26 09:44:48 1998168 ----a-w- C:\Program Files (x86)\Mozilla Firefox\d3dx9_43.dll 2011-06-25 08:25:52 -------- d-----w- C:\Users\James\AppData\Roaming\EVEMon 2011-06-25 08:13:01 -------- d-----w- C:\Program Files (x86)\EVEMon 2011-06-24 07:20:10 -------- d-----w- C:\Program Files\Ventrilo 2011-06-24 07:19:44 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard 2011-06-24 04:23:38 -------- d-----w- C:\Users\James\AppData\Local\CCP 2011-06-24 03:41:56 -------- d-----w- C:\Users\James\AppData\Local\Microsoft Games 2011-06-22 23:27:03 -------- d-----w- C:\Program Files (x86)\CCP 2011-06-22 22:06:24 -------- d-----w- C:\ProgramData\CCP 2011-06-21 19:55:11 -------- d-----w- C:\Users\James\AppData\Roaming\Perpetuum Planner 2011-06-20 19:19:07 -------- d-----w- C:\Users\James\AppData\Local\Google 2011-06-16 00:10:07 499200 ----a-w- C:\Windows\System32\drivers\afd.sys 2011-06-16 00:10:07 1923968 ----a-w- C:\Windows\System32\drivers\tcpip.sys 2011-06-16 00:10:04 289280 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys 2011-06-16 00:10:04 158208 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys 2011-06-16 00:10:04 128000 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys 2011-06-16 00:10:03 3135488 ----a-w- C:\Windows\System32\win32k.sys 2011-06-16 00:09:38 467456 ----a-w- C:\Windows\System32\drivers\srv.sys 2011-06-16 00:09:38 410112 ----a-w- C:\Windows\System32\drivers\srv2.sys 2011-06-16 00:09:38 168448 ----a-w- C:\Windows\System32\drivers\srvnet.sys 2011-06-16 00:09:37 861696 ----a-w- C:\Windows\System32\oleaut32.dll 2011-06-16 00:09:37 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll 2011-06-16 00:09:36 976896 ----a-w- C:\Windows\System32\inetcomm.dll 2011-06-16 00:09:36 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll 2011-06-13 21:30:17 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation 2011-06-13 21:29:26 -------- d-----w- C:\ProgramData\NVIDIA Corporation 2011-06-09 01:37:26 -------- d-----w- C:\Users\James\AppData\Local\Diagnostics . ==================== Find3M ==================== . 2011-05-24 11:42:55 404480 ----a-w- C:\Windows\System32\umpnpmgr.dll 2011-05-24 10:40:05 44544 ----a-w- C:\Windows\SysWow64\devrtl.dll 2011-05-24 10:39:38 145920 ----a-w- C:\Windows\SysWow64\cfgmgr32.dll 2011-05-24 10:37:54 252928 ----a-w- C:\Windows\SysWow64\drvinst.exe 2011-05-22 03:52:26 43680 ----a-w- C:\Windows\System32\drivers\lirsgt.sys 2011-05-22 03:52:26 314016 ----a-w- C:\Windows\System32\drivers\atksgt.sys 2011-05-21 02:35:28 304744 ----a-w- C:\Windows\SysWow64\nvStreaming.exe 2011-05-05 02:29:00 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll 2011-05-04 05:25:03 2315776 ----a-w- C:\Windows\System32\tquery.dll 2011-05-04 05:22:25 778752 ----a-w- C:\Windows\System32\mssvp.dll 2011-05-04 05:22:25 2223616 ----a-w- C:\Windows\System32\mssrch.dll 2011-05-04 05:22:24 75264 ----a-w- C:\Windows\System32\msscntrs.dll 2011-05-04 05:22:24 491520 ----a-w- C:\Windows\System32\mssph.dll 2011-05-04 05:22:24 288256 ----a-w- C:\Windows\System32\mssphtb.dll 2011-05-04 05:19:28 591872 ----a-w- C:\Windows\System32\SearchIndexer.exe 2011-05-04 05:19:28 249856 ----a-w- C:\Windows\System32\SearchProtocolHost.exe 2011-05-04 05:19:28 113664 ----a-w- C:\Windows\System32\SearchFilterHost.exe 2011-05-04 04:34:43 1549312 ----a-w- C:\Windows\SysWow64\tquery.dll 2011-05-04 04:32:02 666624 ----a-w- C:\Windows\SysWow64\mssvp.dll 2011-05-04 04:32:01 337408 ----a-w- C:\Windows\SysWow64\mssph.dll 2011-05-04 04:32:01 197120 ----a-w- C:\Windows\SysWow64\mssphtb.dll 2011-05-04 04:32:01 1401344 ----a-w- C:\Windows\SysWow64\mssrch.dll 2011-05-04 04:32:00 59392 ----a-w- C:\Windows\SysWow64\msscntrs.dll 2011-05-04 04:28:31 86528 ----a-w- C:\Windows\SysWow64\SearchFilterHost.exe 2011-05-04 04:28:31 427520 ----a-w- C:\Windows\SysWow64\SearchIndexer.exe 2011-05-04 04:28:31 164352 ----a-w- C:\Windows\SysWow64\SearchProtocolHost.exe 2011-04-22 22:15:29 27520 ----a-w- C:\Windows\System32\drivers\Diskdump.sys 2011-04-15 11:34:16 175616 ----a-w- C:\Windows\System32\msclmd.dll 2011-04-15 11:34:16 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll 2011-04-15 01:28:24 118864 ----a-w- C:\Windows\System32\drivers\AVGIDSDriver.sys 2011-04-09 07:02:55 5562240 ----a-w- C:\Windows\System32\ntoskrnl.exe 2011-04-09 06:58:56 142336 ----a-w- C:\Windows\System32\poqexec.exe 2011-04-09 06:02:25 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2011-04-09 06:02:25 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe 2011-04-09 05:56:38 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe 2011-04-08 03:19:38 117864 ----a-w- C:\Windows\System32\nvmctray.dll 2011-04-08 03:19:36 797288 ----a-w- C:\Windows\System32\easyUpdatusAPIU64.dll 2011-04-08 03:19:36 61032 ----a-w- C:\Windows\System32\nvshext.dll 2011-04-08 03:19:36 1012328 ----a-w- C:\Windows\System32\nvvsvc.exe 2011-04-08 03:19:26 6338152 ----a-w- C:\Windows\System32\nvcpl.dll 2011-04-08 03:19:08 3041384 ----a-w- C:\Windows\System32\nvsvc64.dll . ============= FINISH: 22:34:49.16 =============== I Could really use some help.. or if someone could redirect me to another board for help. Suspected Arp attack.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.