Hi, when someone has a moment, I am needing some expert assistance to deal with this issue. Spybot located it, but does not seem to be able to completely remove it - as it comes back after a restart. I have disconnected the infected PC from the internet and am working from a laptop. Per the sticky topic at the head of the forum, I have pasted the dds output below. My appologies in advance if I overlooked a step or instruction for posting issues. Thank you for your time.

Please run the following:

  • Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool.
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
    • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
    • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.

Please run the following

Refer to the ComboFix User's Guide

  1. Download ComboFix from the following location:
    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  2. Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  3. Double click on ComboFix.exe & follow the prompts.
  4. Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  5. When finished, it shall produce a log for you. Post that log in your next reply
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  6. Ensure your AntiVirus and AntiSpyware applications are re-enabled.

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

Hi again. I was unable to disable all of the norton services as they were grayed out in my services menu. Rather than fight through that, I've temporarily uninstalled Norton Antivirus so that I could run ComboFix.

  • Staff

Please run the following:

Please download TDSSKiller.zip

  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • when the window opens, click on Change Parameters
  • under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”
  • click OK
  • Press Start Scan
    • If Malicious objects are found then ensure Cure is selected
    • If TDLFS File System/TDSS File system is found then ensure Cure is selected (if cure is not available, choose skip)
    • Then click Continue > Reboot now

    [*]Copy and paste the log in your next reply

    • A copy of the log will be saved automatically to the root of the drive (typically C:\)


Please download Malwarebytes Anti-Rootkit and save it to your desktop.

  • Be sure to print out and follow the instructions provided on that same page for performing a scan.
  • Caution: This is a beta version so also read the disclaimer and back up all your data before using.
  • When the scan completes, click on the Cleanup button to remove any threats found and reboot the computer if prompted to do so.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • If there are problems with Internet access, Windows Update, Windows Firewall or other system issues, run the fixdamage tool located in the folder Malwarebytes Anti-Rootkit was run from and reboot your computer.
  • Two files (mbar-log-YYYY-MM-DD, system-log.txt) will be created and saved within that same folder.
  • Copy and paste the contents of these two log files in your next reply.

Note: Further documentation can be found in the ReadMe.rtf file which is located in the Malwarebytes Anti-Rootkit folder.

TDSS Killer...

17:13:55.0988 3840 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys

17:13:55.0988 3840 mrxsmb10 - ok

17:13:56.0003 3840 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys

17:13:56.0003 3840 mrxsmb20 - ok

17:13:56.0019 3840 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys

17:13:56.0019 3840 msahci - ok

17:13:56.0034 3840 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys

17:13:56.0034 3840 msdsm - ok

17:13:56.0050 3840 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe

17:13:56.0050 3840 MSDTC - ok

17:13:56.0050 3840 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys

17:13:56.0050 3840 Msfs - ok

17:13:56.0066 3840 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys

17:13:56.0066 3840 mshidkmdf - ok

17:13:56.0081 3840 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys

17:13:56.0081 3840 msisadrv - ok

17:13:56.0097 3840 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll

17:13:56.0097 3840 MSiSCSI - ok

17:13:56.0097 3840 msiserver - ok

17:13:56.0112 3840 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys

17:13:56.0112 3840 MSKSSRV - ok

17:13:56.0112 3840 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys

17:13:56.0112 3840 MSPCLOCK - ok

17:13:56.0128 3840 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys

17:13:56.0128 3840 MSPQM - ok

17:13:56.0159 3840 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys

17:13:56.0159 3840 MsRPC - ok

17:13:56.0159 3840 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys

17:13:56.0159 3840 mssmbios - ok

17:13:56.0175 3840 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys

17:13:56.0175 3840 MSTEE - ok

17:13:56.0175 3840 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys

17:13:56.0190 3840 MTConfig - ok

17:13:56.0206 3840 [ 2219A3D695405E7BA2186BA6B9EDE14A ] MTsensor C:\Windows\system32\DRIVERS\ASACPI.sys

17:13:56.0206 3840 MTsensor - ok

17:13:56.0222 3840 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys

17:13:56.0222 3840 Mup - ok

17:13:56.0253 3840 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll

17:13:56.0253 3840 napagent - ok

17:13:56.0268 3840 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys

17:13:56.0268 3840 NativeWifiP - ok

17:13:56.0315 3840 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys

17:13:56.0315 3840 NDIS - ok

17:13:56.0331 3840 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys

17:13:56.0331 3840 NdisCap - ok

17:13:56.0346 3840 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys

17:13:56.0346 3840 NdisTapi - ok

17:13:56.0378 3840 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys

17:13:56.0378 3840 Ndisuio - ok

17:13:56.0393 3840 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys

17:13:56.0393 3840 NdisWan - ok

17:13:56.0409 3840 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys

17:13:56.0409 3840 NDProxy - ok

17:13:56.0409 3840 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys

17:13:56.0424 3840 NetBIOS - ok

17:13:56.0440 3840 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys

17:13:56.0440 3840 NetBT - ok

17:13:56.0456 3840 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe

17:13:56.0456 3840 Netlogon - ok

17:13:56.0487 3840 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll

17:13:56.0487 3840 Netman - ok

17:13:56.0502 3840 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll

17:13:56.0502 3840 netprofm - ok

17:13:56.0518 3840 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe

17:13:56.0518 3840 NetTcpPortSharing - ok

17:13:56.0534 3840 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys

17:13:56.0534 3840 nfrd960 - ok

17:13:56.0549 3840 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll

17:13:56.0549 3840 NlaSvc - ok

17:13:56.0565 3840 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys

17:13:56.0565 3840 Npfs - ok

17:13:56.0565 3840 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll

17:13:56.0565 3840 nsi - ok

17:13:56.0580 3840 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys

17:13:56.0580 3840 nsiproxy - ok

17:13:56.0612 3840 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys

17:13:56.0643 3840 Ntfs - ok

17:13:56.0658 3840 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys

17:13:56.0658 3840 Null - ok

17:13:56.0674 3840 [ A85B4F2EF3A7304A5399EF0526423040 ] NVENETFD C:\Windows\system32\DRIVERS\nvm62x64.sys

17:13:56.0674 3840 NVENETFD - ok

17:13:56.0846 3840 [ 5104BAC2DA2A5BDD86AC6B0708B00F06 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys

17:13:56.0892 3840 nvlddmkm - ok

17:13:56.0939 3840 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys

17:13:56.0939 3840 nvraid - ok

17:13:56.0955 3840 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys

17:13:56.0955 3840 nvstor - ok

17:13:57.0002 3840 [ DDFAFCE89A5C93D04712B86F94E9FCBA ] nvsvc C:\Windows\system32\nvvsvc.exe

17:13:57.0017 3840 nvsvc - ok

17:13:57.0048 3840 [ 84E035225474E48CD3A6A3CE52332095 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

17:13:57.0048 3840 nvUpdatusService - ok

17:13:57.0064 3840 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys

17:13:57.0064 3840 nv_agp - ok

17:13:57.0126 3840 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE

17:13:57.0126 3840 odserv - ok

17:13:57.0142 3840 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys

17:13:57.0142 3840 ohci1394 - ok

17:13:57.0173 3840 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE

17:13:57.0173 3840 ose - ok

17:13:57.0204 3840 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll

17:13:57.0204 3840 p2pimsvc - ok

17:13:57.0220 3840 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll

17:13:57.0236 3840 p2psvc - ok

17:13:57.0251 3840 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys

17:13:57.0251 3840 Parport - ok

17:13:57.0267 3840 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys

17:13:57.0282 3840 partmgr - ok

17:13:57.0282 3840 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll

17:13:57.0298 3840 PcaSvc - ok

17:13:57.0298 3840 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys

17:13:57.0298 3840 pci - ok

17:13:57.0314 3840 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys

17:13:57.0314 3840 pciide - ok

17:13:57.0314 3840 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys

17:13:57.0329 3840 pcmcia - ok

17:13:57.0329 3840 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys

17:13:57.0329 3840 pcw - ok

17:13:57.0345 3840 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys

17:13:57.0345 3840 PEAUTH - ok

17:13:57.0392 3840 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll

17:13:57.0423 3840 PeerDistSvc - ok

17:13:57.0454 3840 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe

17:13:57.0454 3840 PerfHost - ok

17:13:57.0501 3840 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll

17:13:57.0516 3840 pla - ok

17:13:57.0548 3840 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll

17:13:57.0548 3840 PlugPlay - ok

17:13:57.0563 3840 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll

17:13:57.0563 3840 PNRPAutoReg - ok

17:13:57.0579 3840 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll

17:13:57.0579 3840 PNRPsvc - ok

17:13:57.0610 3840 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll

17:13:57.0610 3840 PolicyAgent - ok

17:13:57.0626 3840 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll

17:13:57.0626 3840 Power - ok

17:13:57.0641 3840 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys

17:13:57.0641 3840 PptpMiniport - ok

17:13:57.0657 3840 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys

17:13:57.0657 3840 Processor - ok

17:13:57.0688 3840 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll

17:13:57.0688 3840 ProfSvc - ok

17:13:57.0704 3840 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe

17:13:57.0704 3840 ProtectedStorage - ok

17:13:57.0719 3840 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys

17:13:57.0719 3840 Psched - ok

17:13:57.0735 3840 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys

17:13:57.0766 3840 ql2300 - ok

17:13:57.0766 3840 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys

17:13:57.0766 3840 ql40xx - ok

17:13:57.0797 3840 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll

17:13:57.0797 3840 QWAVE - ok

17:13:57.0813 3840 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys

17:13:57.0813 3840 QWAVEdrv - ok

17:13:57.0828 3840 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys

17:13:57.0828 3840 RasAcd - ok

17:13:57.0844 3840 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys

17:13:57.0844 3840 RasAgileVpn - ok

17:13:57.0844 3840 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll

17:13:57.0844 3840 RasAuto - ok

17:13:57.0875 3840 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys

17:13:57.0875 3840 Rasl2tp - ok

17:13:57.0891 3840 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll

17:13:57.0891 3840 RasMan - ok

17:13:57.0906 3840 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys

17:13:57.0906 3840 RasPppoe - ok

17:13:57.0906 3840 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys

17:13:57.0906 3840 RasSstp - ok

17:13:57.0938 3840 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys

17:13:57.0938 3840 rdbss - ok

17:13:57.0953 3840 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys

17:13:57.0953 3840 rdpbus - ok

17:13:57.0969 3840 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys

17:13:57.0969 3840 RDPCDD - ok

17:13:57.0984 3840 [ 1B6163C503398B23FF8B939C67747683 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys

17:13:57.0984 3840 RDPDR - ok

17:13:58.0000 3840 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys

17:13:58.0000 3840 RDPENCDD - ok

17:13:58.0016 3840 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys

17:13:58.0016 3840 RDPREFMP - ok

17:13:58.0031 3840 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys

17:13:58.0031 3840 RDPWD - ok

17:13:58.0047 3840 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys

17:13:58.0047 3840 rdyboost - ok

17:13:58.0078 3840 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll

17:13:58.0078 3840 RemoteAccess - ok

17:13:58.0078 3840 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll

17:13:58.0094 3840 RemoteRegistry - ok

17:13:58.0109 3840 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll

17:13:58.0109 3840 RpcEptMapper - ok

17:13:58.0125 3840 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe

17:13:58.0140 3840 RpcLocator - ok

17:13:58.0156 3840 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll

17:13:58.0156 3840 RpcSs - ok

17:13:58.0156 3840 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys

17:13:58.0172 3840 rspndr - ok

17:13:58.0187 3840 [ EE082E06A82FF630351D1E0EBBD3D8D0 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys

17:13:58.0187 3840 RTL8167 - ok

17:13:58.0203 3840 [ E60C0A09F997826C7627B244195AB581 ] s3cap C:\Windows\system32\drivers\vms3cap.sys

17:13:58.0203 3840 s3cap - ok

17:13:58.0218 3840 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe

17:13:58.0218 3840 SamSs - ok

17:13:58.0234 3840 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys

17:13:58.0234 3840 sbp2port - ok

17:13:58.0281 3840 [ 794D4B48DFB6E999537C7C3947863463 ] SBSDWSCService C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe

17:13:58.0281 3840 SBSDWSCService - ok

17:13:58.0296 3840 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll

17:13:58.0296 3840 SCardSvr - ok

17:13:58.0312 3840 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys

17:13:58.0328 3840 scfilter - ok

17:13:58.0343 3840 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll

17:13:58.0359 3840 Schedule - ok

17:13:58.0374 3840 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll

17:13:58.0374 3840 SCPolicySvc - ok

17:13:58.0406 3840 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll

17:13:58.0406 3840 SDRSVC - ok

17:13:58.0421 3840 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys

17:13:58.0421 3840 secdrv - ok

17:13:58.0437 3840 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll

17:13:58.0437 3840 seclogon - ok

17:13:58.0452 3840 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll

17:13:58.0452 3840 SENS - ok

17:13:58.0468 3840 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll

17:13:58.0468 3840 SensrSvc - ok

17:13:58.0484 3840 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys

17:13:58.0484 3840 Serenum - ok

17:13:58.0484 3840 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys

17:13:58.0484 3840 Serial - ok

17:13:58.0499 3840 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys

17:13:58.0499 3840 sermouse - ok

17:13:58.0530 3840 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll

17:13:58.0530 3840 SessionEnv - ok

17:13:58.0546 3840 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys

17:13:58.0546 3840 sffdisk - ok

17:13:58.0546 3840 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys

17:13:58.0562 3840 sffp_mmc - ok

17:13:58.0562 3840 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys

17:13:58.0562 3840 sffp_sd - ok

17:13:58.0577 3840 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys

17:13:58.0577 3840 sfloppy - ok

17:13:58.0593 3840 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll

17:13:58.0593 3840 SharedAccess - ok

17:13:58.0608 3840 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll

17:13:58.0608 3840 ShellHWDetection - ok

17:13:58.0624 3840 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys

17:13:58.0624 3840 SiSRaid2 - ok

17:13:58.0640 3840 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys

17:13:58.0640 3840 SiSRaid4 - ok

17:13:58.0655 3840 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys

17:13:58.0655 3840 Smb - ok

17:13:58.0686 3840 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe

17:13:58.0686 3840 SNMPTRAP - ok

17:13:58.0686 3840 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys

17:13:58.0686 3840 spldr - ok

17:13:58.0718 3840 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe

17:13:58.0718 3840 Spooler - ok

17:13:58.0764 3840 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe

17:13:58.0796 3840 sppsvc - ok

17:13:58.0827 3840 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll

17:13:58.0827 3840 sppuinotify - ok

17:13:58.0842 3840 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys

17:13:58.0842 3840 srv - ok

17:13:58.0858 3840 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys

17:13:58.0874 3840 srv2 - ok

17:13:58.0874 3840 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys

17:13:58.0889 3840 srvnet - ok

17:13:58.0905 3840 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll

17:13:58.0905 3840 SSDPSRV - ok

17:13:58.0920 3840 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll

17:13:58.0920 3840 SstpSvc - ok

17:13:58.0967 3840 [ F0359F7CE712D69ACEF0886BDB4792ED ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

17:13:58.0967 3840 Stereo Service - ok

17:13:58.0983 3840 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys

17:13:58.0983 3840 stexstor - ok

17:13:58.0998 3840 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll

17:13:58.0998 3840 stisvc - ok

17:13:59.0014 3840 [ 7785DC213270D2FC066538DAF94087E7 ] storflt C:\Windows\system32\drivers\vmstorfl.sys

17:13:59.0014 3840 storflt - ok

17:13:59.0045 3840 [ C40841817EF57D491F22EB103DA587CC ] StorSvc C:\Windows\system32\storsvc.dll

17:13:59.0045 3840 StorSvc - ok

17:13:59.0061 3840 [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc C:\Windows\system32\drivers\storvsc.sys

17:13:59.0061 3840 storvsc - ok

17:13:59.0076 3840 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys

17:13:59.0076 3840 swenum - ok

17:13:59.0092 3840 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll

17:13:59.0092 3840 swprv - ok

17:13:59.0139 3840 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll

17:13:59.0170 3840 SysMain - ok

17:13:59.0170 3840 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll

17:13:59.0170 3840 TabletInputService - ok

17:13:59.0186 3840 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll

17:13:59.0201 3840 TapiSrv - ok

17:13:59.0217 3840 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll

17:13:59.0217 3840 TBS - ok

17:13:59.0248 3840 [ 37608401DFDB388CAF66917F6B2D6FB0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys

17:13:59.0264 3840 Tcpip - ok

17:13:59.0295 3840 [ 37608401DFDB388CAF66917F6B2D6FB0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys

17:13:59.0295 3840 TCPIP6 - ok

17:13:59.0310 3840 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys

17:13:59.0310 3840 tcpipreg - ok

17:13:59.0326 3840 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys

17:13:59.0326 3840 TDPIPE - ok

17:13:59.0342 3840 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys

17:13:59.0342 3840 TDTCP - ok

17:13:59.0357 3840 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys

17:13:59.0357 3840 tdx - ok

17:13:59.0373 3840 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys

17:13:59.0373 3840 TermDD - ok

17:13:59.0388 3840 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll

17:13:59.0404 3840 TermService - ok

17:13:59.0420 3840 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll

17:13:59.0420 3840 Themes - ok

17:13:59.0420 3840 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll

17:13:59.0420 3840 THREADORDER - ok

17:13:59.0482 3840 [ 4DE3FAEE834E9EF5151A71866F6DB55D ] TivoBeacon2 C:\Program Files (x86)\TiVo\Desktop\TiVoBeacon.exe

17:13:59.0498 3840 TivoBeacon2 - ok

17:13:59.0513 3840 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll

17:13:59.0513 3840 TrkWks - ok

17:13:59.0544 3840 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe

17:13:59.0544 3840 TrustedInstaller - ok

17:13:59.0560 3840 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys

17:13:59.0560 3840 tssecsrv - ok

17:13:59.0591 3840 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys

17:13:59.0591 3840 TsUsbFlt - ok

17:13:59.0607 3840 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys

17:13:59.0622 3840 tunnel - ok

17:13:59.0622 3840 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys

17:13:59.0622 3840 uagp35 - ok

17:13:59.0638 3840 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys

17:13:59.0654 3840 udfs - ok

17:13:59.0669 3840 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe

17:13:59.0669 3840 UI0Detect - ok

17:13:59.0685 3840 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys

17:13:59.0685 3840 uliagpkx - ok

17:13:59.0700 3840 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys

17:13:59.0700 3840 umbus - ok

17:13:59.0716 3840 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys

17:13:59.0716 3840 UmPass - ok

17:13:59.0732 3840 [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService C:\Windows\System32\umrdp.dll

17:13:59.0732 3840 UmRdpService - ok

17:13:59.0747 3840 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll

17:13:59.0747 3840 upnphost - ok

17:13:59.0763 3840 [ FB251567F41BC61988B26731DEC19E4B ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys

17:13:59.0778 3840 USBAAPL64 - ok

17:13:59.0778 3840 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys

17:13:59.0778 3840 usbccgp - ok

17:13:59.0810 3840 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys

17:13:59.0810 3840 usbcir - ok

17:13:59.0810 3840 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys

17:13:59.0810 3840 usbehci - ok

17:13:59.0841 3840 [ 68BAD03835873D4BBBDE95CBB135A395 ] UsbFltr C:\Windows\system32\Drivers\UsbFltr.sys

17:13:59.0841 3840 UsbFltr - ok

17:13:59.0856 3840 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys

17:13:59.0856 3840 usbhub - ok

17:13:59.0856 3840 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys

17:13:59.0856 3840 usbohci - ok

17:13:59.0872 3840 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys

17:13:59.0872 3840 usbprint - ok

17:13:59.0888 3840 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS

17:13:59.0888 3840 USBSTOR - ok

17:13:59.0888 3840 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys

17:13:59.0888 3840 usbuhci - ok

17:13:59.0903 3840 USTOR2K - ok

17:13:59.0919 3840 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll

17:13:59.0919 3840 UxSms - ok

17:13:59.0919 3840 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe

17:13:59.0919 3840 VaultSvc - ok

17:13:59.0950 3840 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys

17:13:59.0950 3840 vdrvroot - ok

17:13:59.0981 3840 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe

17:13:59.0997 3840 vds - ok

17:13:59.0997 3840 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys

17:14:00.0012 3840 vga - ok

17:14:00.0012 3840 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys

17:14:00.0012 3840 VgaSave - ok

17:14:00.0044 3840 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys

17:14:00.0044 3840 vhdmp - ok

17:14:00.0059 3840 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys

17:14:00.0059 3840 viaide - ok

17:14:00.0075 3840 [ 86EA3E79AE350FEA5331A1303054005F ] vmbus C:\Windows\system32\drivers\vmbus.sys

17:14:00.0075 3840 vmbus - ok

17:14:00.0075 3840 [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys

17:14:00.0090 3840 VMBusHID - ok

17:14:00.0106 3840 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys

17:14:00.0106 3840 volmgr - ok

17:14:00.0137 3840 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys

17:14:00.0137 3840 volmgrx - ok

17:14:00.0153 3840 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys

17:14:00.0153 3840 volsnap - ok

17:14:00.0168 3840 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys

17:14:00.0168 3840 vsmraid - ok

17:14:00.0200 3840 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe

17:14:00.0231 3840 VSS - ok

17:14:00.0231 3840 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys

17:14:00.0231 3840 vwifibus - ok

17:14:00.0278 3840 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll

17:14:00.0278 3840 W32Time - ok

17:14:00.0278 3840 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys

17:14:00.0293 3840 WacomPen - ok

17:14:00.0309 3840 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys

17:14:00.0309 3840 WANARP - ok

17:14:00.0309 3840 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys

17:14:00.0309 3840 Wanarpv6 - ok

17:14:00.0340 3840 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe

17:14:00.0371 3840 WatAdminSvc - ok

17:14:00.0402 3840 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe

17:14:00.0434 3840 wbengine - ok

17:14:00.0449 3840 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll

17:14:00.0449 3840 WbioSrvc - ok

17:14:00.0480 3840 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll

17:14:00.0480 3840 wcncsvc - ok

17:14:00.0480 3840 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll

17:14:00.0480 3840 WcsPlugInService - ok

17:14:00.0496 3840 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys

17:14:00.0496 3840 Wd - ok

17:14:00.0527 3840 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys

17:14:00.0543 3840 Wdf01000 - ok

17:14:00.0543 3840 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll

17:14:00.0558 3840 WdiServiceHost - ok

17:14:00.0558 3840 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll

17:14:00.0558 3840 WdiSystemHost - ok

17:14:00.0574 3840 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll

17:14:00.0574 3840 WebClient - ok

17:14:00.0590 3840 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll

17:14:00.0590 3840 Wecsvc - ok

17:14:00.0605 3840 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll

17:14:00.0605 3840 wercplsupport - ok

17:14:00.0621 3840 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll

17:14:00.0621 3840 WerSvc - ok

17:14:00.0636 3840 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys

17:14:00.0636 3840 WfpLwf - ok

17:14:00.0652 3840 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys

17:14:00.0652 3840 WIMMount - ok

17:14:00.0652 3840 WinDefend - ok

17:14:00.0668 3840 WinHttpAutoProxySvc - ok

17:14:00.0699 3840 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll

17:14:00.0699 3840 Winmgmt - ok

17:14:00.0746 3840 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll

17:14:00.0761 3840 WinRM - ok

17:14:00.0792 3840 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll

17:14:00.0808 3840 Wlansvc - ok

17:14:00.0839 3840 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys

17:14:00.0839 3840 WmiAcpi - ok

17:14:00.0870 3840 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe

17:14:00.0870 3840 wmiApSrv - ok

17:14:00.0886 3840 WMPNetworkSvc - ok

17:14:00.0902 3840 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll

17:14:00.0902 3840 WPCSvc - ok

17:14:00.0933 3840 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll

17:14:00.0933 3840 WPDBusEnum - ok

17:14:00.0948 3840 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys

17:14:00.0948 3840 ws2ifsl - ok

17:14:00.0964 3840 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll

17:14:00.0964 3840 wscsvc - ok

17:14:00.0980 3840 WSearch - ok

17:14:01.0026 3840 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll

17:14:01.0042 3840 wuauserv - ok

17:14:01.0058 3840 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys

17:14:01.0058 3840 WudfPf - ok

17:14:01.0073 3840 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys

17:14:01.0073 3840 WUDFRd - ok

17:14:01.0104 3840 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll

17:14:01.0104 3840 wudfsvc - ok

17:14:01.0120 3840 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll

17:14:01.0120 3840 WwanSvc - ok

17:14:01.0120 3840 ================ Scan global ===============================

17:14:01.0136 3840 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll

17:14:01.0167 3840 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll

17:14:01.0182 3840 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll

17:14:01.0198 3840 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll

17:14:01.0214 3840 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe

17:14:01.0214 3840 [Global] - ok

17:14:01.0214 3840 ================ Scan MBR ==================================

17:14:01.0214 3840 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk2\DR2

17:14:01.0307 3840 \Device\Harddisk2\DR2 - ok

17:14:01.0323 3840 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0

17:14:01.0323 3840 Suspicious mbr (Forged): \Device\Harddisk0\DR0

17:14:01.0370 3840 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected

17:14:01.0370 3840 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0)

17:14:01.0432 3840 \Device\Harddisk0\DR0 ( TDSS File System ) - warning

17:14:01.0432 3840 \Device\Harddisk0\DR0 - detected TDSS File System (1)

17:14:01.0432 3840 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1

17:14:01.0635 3840 \Device\Harddisk1\DR1 - ok

17:14:01.0635 3840 ================ Scan VBR ==================================

17:14:01.0635 3840 [ B1FE8DBABFD3A74283B7D3E455C52A3D ] \Device\Harddisk2\DR2\Partition1

17:14:01.0635 3840 \Device\Harddisk2\DR2\Partition1 - ok

17:14:01.0635 3840 [ 16EFC8C64E0CF222BA05584B82E62A82 ] \Device\Harddisk0\DR0\Partition1

17:14:01.0635 3840 \Device\Harddisk0\DR0\Partition1 - ok

17:14:01.0635 3840 [ 94D9420588193CF908B782161F6A7BFC ] \Device\Harddisk0\DR0\Partition2

17:14:01.0635 3840 \Device\Harddisk0\DR0\Partition2 - ok

17:14:01.0635 3840 [ E69EB3FEE1D4493D8900E2FF4CE2E6A8 ] \Device\Harddisk1\DR1\Partition1

17:14:01.0635 3840 \Device\Harddisk1\DR1\Partition1 - ok

17:14:01.0635 3840 ============================================================

17:14:01.0635 3840 Scan finished

17:14:01.0635 3840 ============================================================

17:14:01.0650 3424 Detected object count: 2

17:14:01.0650 3424 Actual detected object count: 2

17:14:36.0829 3424 \Device\Harddisk0\DR0\# - copied to quarantine

17:14:36.0829 3424 \Device\Harddisk0\DR0 - copied to quarantine

17:14:36.0875 3424 \Device\Harddisk0\DR0\TDLFS\cmd.dll - copied to quarantine

17:14:36.0875 3424 \Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine

17:14:36.0875 3424 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine

17:14:36.0891 3424 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine

17:14:36.0891 3424 \Device\Harddisk0\DR0\TDLFS\servers.dat - copied to quarantine

17:14:36.0891 3424 \Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine

17:14:36.0891 3424 \Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine

17:14:36.0891 3424 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine

17:14:36.0891 3424 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine

17:14:36.0891 3424 \Device\Harddisk0\DR0\TDLFS\s - copied to quarantine

17:14:36.0891 3424 \Device\Harddisk0\DR0\TDLFS\ldrm - copied to quarantine

17:14:36.0891 3424 \Device\Harddisk0\DR0\TDLFS\u - copied to quarantine

17:14:36.0922 3424 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - will be cured on reboot

17:14:36.0922 3424 \Device\Harddisk0\DR0 - ok

17:14:42.0523 3424 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - User select action: Cure

17:14:42.0523 3424 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user

17:14:42.0523 3424 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip

17:15:16.0843 3820 Deinitialize success

17:16:44.0622 2536 TDSS rootkit removing tool Oct 31 2012 21:47:35

17:16:44.0732 2536 ============================================================

17:16:44.0732 2536 Current date / time: 2012/12/02 17:16:44.0732

17:16:44.0732 2536 SystemInfo:

17:16:44.0732 2536

17:16:44.0732 2536 OS Version: 6.1.7601 ServicePack: 1.0

17:16:44.0732 2536 Product type: Workstation

17:16:44.0732 2536 ComputerName: JOE-PC

17:16:44.0732 2536 UserName: Joe

17:16:44.0732 2536 Windows directory: C:\Windows

17:16:44.0732 2536 System windows directory: C:\Windows

17:16:44.0732 2536 Running under WOW64

17:16:44.0732 2536 Processor architecture: Intel x64

17:16:44.0732 2536 Number of processors: 8

17:16:44.0732 2536 Page size: 0x1000

17:16:44.0732 2536 Boot type: Normal boot

17:16:44.0732 2536 ============================================================

17:16:45.0621 2536 BG loaded

17:16:45.0917 2536 Drive \Device\Harddisk2\DR2 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040

17:16:45.0917 2536 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040

17:16:45.0933 2536 Drive \Device\Harddisk1\DR1 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040

17:16:45.0948 2536 ============================================================

17:16:45.0948 2536 \Device\Harddisk2\DR2:

17:16:45.0948 2536 MBR partitions:

17:16:45.0948 2536 \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x74705800

17:16:45.0948 2536 \Device\Harddisk0\DR0:

17:16:45.0948 2536 MBR partitions:

17:16:45.0948 2536 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000

17:16:45.0948 2536 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800

17:16:45.0948 2536 \Device\Harddisk1\DR1:

17:16:45.0948 2536 MBR partitions:

17:16:45.0948 2536 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x254297C1

17:16:45.0948 2536 ============================================================

17:16:45.0995 2536 C: <-> \Device\Harddisk0\DR0\Partition2

17:16:46.0026 2536 E: <-> \Device\Harddisk1\DR1\Partition1

17:16:46.0026 2536 F: <-> \Device\Harddisk2\DR2\Partition1

17:16:46.0026 2536 ============================================================

17:16:46.0026 2536 Initialize success

17:16:46.0026 2536 ============================================================

Malwarebytes Anti-Rootkit


Database version: v2012.12.02.04

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 9.0.8112.16421

Joe :: JOE-PC [administrator]

12/2/2012 5:26:16 PM

mbar-log-2012-12-02 (17-26-16).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken

Scan options disabled: PUP | PUM | P2P

Objects scanned: 27175

Time elapsed: 4 minute(s), 43 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)


Malwarebytes Anti-Rootkit


Database version: v2012.12.02.04

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 9.0.8112.16421

Joe :: JOE-PC [administrator]

12/2/2012 5:34:45 PM

mbar-log-2012-12-02 (17-34-45).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken

Scan options disabled: PUP | PUM | P2P

Objects scanned: 27164

Time elapsed: 4 minute(s), 51 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)


  • Staff

Please run the following:

Please download Junkware Removal Tool to your desktop.

  • Shutdown your antivirus to avoid any conflicts.
  • Right-mouse click JRT.exe and select Run as administrator
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message


Download AdwCleaner from here and save it to your desktop.

  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply


Go here to run an online scanner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish

Junkware Removal Tool (JRT) by Thisisu

Version: 3.7.4 (12.02.2012:1)

OS: Windows 7 Professional x64

Ran by Joe on Sun 12/02/2012 at 19:21:39.91

Blog: http://thisisudax.blogspot.com


~~~ Services

~~~ Registry Values

~~~ Registry Keys

Successfully deleted: [Registry Key] "hkey_local_machine\software\classes\appid\escort.dll"

Successfully deleted: [Registry Key] "hkey_local_machine\software\classes\appid\escortapp.dll"

Successfully deleted: [Registry Key] "hkey_local_machine\software\classes\appid\escorteng.dll"

Successfully deleted: [Registry Key] "hkey_local_machine\software\classes\appid\escortlbr.dll"

Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{afbcb7e0-f91a-4951-9f31-58fee57a25c4}

~~~ Files

Successfully deleted: [File] "C:\Users\Joe\appdata\local\funmoods-speeddial.crx"

~~~ Folders

Successfully deleted: [Folder] "C:\Users\Joe\appdata\locallow\minibar"

~~~ Event Viewer Logs were cleared


Scan was completed on Sun 12/02/2012 at 19:23:53.91

End of JRT log


# AdwCleaner v2.011 - Logfile created 12/02/2012 at 19:27:00

# Updated 02/12/2012 by Xplode

# Operating system : Windows 7 Professional Service Pack 1 (64 bits)

# User : Joe - JOE-PC

# Boot Mode : Normal

# Running from : C:\Users\Joe\Desktop\AdwCleaner.exe

# Option [Delete]

***** [services] *****

***** [Files / Folders] *****

***** [Registry] *****

Key Deleted : HKCU\Software\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}

Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{CA17D76B-F91D-4659-A7FD-A9F7ED375CDD}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}

Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136}

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj

***** [internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16455

[OK] Registry is clean.

-\\ Google Chrome v [unable to get version]

File : C:\Users\Joe\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.


AdwCleaner[s1].txt - [2578 octets] - [02/12/2012 19:27:00]

########## EOF - C:\AdwCleaner[s1].txt - [2638 octets] ##########

ESET Results...

C:\ProgramData\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm

C:\ProgramData\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric1.zip Win32/Bagle.gen.zip worm

C:\ProgramData\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric2.zip Win32/Bagle.gen.zip worm

C:\TDSSKiller_Quarantine\02.12.2012_17.13.33\mbr0000\tdlfs0000\tsk0000.dta a variant of Win32/Olmarik.AYI trojan

C:\TDSSKiller_Quarantine\02.12.2012_17.13.33\mbr0000\tdlfs0000\tsk0001.dta a variant of Win64/Olmarik.AM trojan

C:\TDSSKiller_Quarantine\02.12.2012_17.13.33\mbr0000\tdlfs0000\tsk0002.dta a variant of Win32/Rootkit.Kryptik.QM trojan

C:\TDSSKiller_Quarantine\02.12.2012_17.13.33\mbr0000\tdlfs0000\tsk0003.dta Win64/Olmarik.AN trojan

C:\TDSSKiller_Quarantine\02.12.2012_17.13.33\mbr0000\tdlfs0000\tsk0007.dta Win32/Olmarik.AFK trojan

C:\TDSSKiller_Quarantine\02.12.2012_17.13.33\mbr0000\tdlfs0000\tsk0008.dta Win64/Olmarik.AK trojan

C:\Users\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm

C:\Users\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric1.zip Win32/Bagle.gen.zip worm

C:\Users\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric2.zip Win32/Bagle.gen.zip worm

C:\Users\Joe\AppData\Local\AOL\AIM\update\install.exe Win32/OpenCandy application

F:\Users\Joe\Documents\Installers\vlcmediaplayer-setup.exe Win32/DownloadAdmin.A.Gen application

F:\Users\Joe\Documents\Installers\WormsArmageddon-dm.exe a variant of Win32/Adware.Trymedia.A application

  • Staff

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".

Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:

Press the WinKey + R to open a run box, type Notepad > click OK.

This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

C:\ProgramData\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric1.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric2.zip
C:\Users\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip
C:\Users\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric1.zip
C:\Users\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric2.zip


Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:

1.Click File;

2.Click Save As... Change the directory to your desktop;

3.Change the Save as type to "All Files";

4.Type in the file name: CFScript

5.Click Save ...


  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


Please advise how the computer is running and if there are any outstanding issues

I am in the process of running various malware/virus scans now. I will let you know tomorrow if anything else pops up. Thanks for all of your help Catbyte. I may yet be persuaded that cats are better than dogs.

ComboFix 12-12-01.02 - Joe 12/03/2012 18:33:35.2.8 - x64

Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8182.6595 [GMT -6:00]

Running from: c:\users\Joe\Desktop\ComboFix.exe

Command switches used :: c:\users\Joe\Desktop\CFScript.txt

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



"c:\programdata\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip"

"c:\programdata\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric1.zip"

"c:\programdata\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric2.zip"

"c:\users\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip"

"c:\users\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric1.zip"

"c:\users\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric2.zip"






((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))



c:\programdata\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip

c:\programdata\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric1.zip

c:\programdata\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric2.zip

c:\users\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip

c:\users\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric1.zip

c:\users\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric2.zip






((((((((((((((((((((((((( Files Created from 2012-11-04 to 2012-12-04 )))))))))))))))))))))))))))))))



2012-12-04 00:36 . 2012-12-04 00:36 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-12-04 00:23 . 2012-12-04 00:23 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D9912CB4-54D9-4ACC-BB50-85CC8C111901}\offreg.dll

2012-12-03 01:35 . 2012-11-19 07:01 9125352 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D9912CB4-54D9-4ACC-BB50-85CC8C111901}\mpengine.dll

2012-12-03 01:21 . 2012-12-03 01:21 -------- d-----w- c:\windows\ERUNT

2012-12-03 01:21 . 2012-12-03 01:21 -------- d-----w- C:\JRT

2012-12-02 23:14 . 2012-12-02 23:14 -------- d-----w- C:\TDSSKiller_Quarantine

2012-12-02 04:45 . 2012-12-02 04:45 -------- d-----w- c:\users\Joe\AppData\Roaming\Malwarebytes

2012-12-02 04:45 . 2012-12-02 04:45 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-12-02 04:45 . 2012-12-02 04:45 -------- d-----w- c:\programdata\Malwarebytes

2012-12-02 04:45 . 2012-09-30 01:54 25928 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-12-02 04:10 . 2012-12-02 04:10 -------- d-----w- c:\program files (x86)\PC Tools

2012-12-02 04:08 . 2012-12-02 04:51 -------- d-----w- c:\program files (x86)\Common Files\PC Tools

2012-12-02 04:08 . 2012-11-01 21:35 253256 ----a-w- c:\windows\system32\drivers\PCTSD64.sys

2012-12-02 04:08 . 2012-12-02 04:44 -------- d-----w- c:\programdata\PC Tools

2012-12-02 04:08 . 2012-12-02 04:08 -------- d-----w- c:\users\Joe\AppData\Roaming\TestApp

2012-11-19 23:07 . 2012-11-19 23:07 -------- d-----w- c:\programdata\OptiTex

2012-11-17 23:29 . 2012-11-17 23:30 -------- d-----w- c:\users\UpdatusUser

2012-11-17 23:29 . 2012-11-17 23:30 -------- d-----w- c:\program files (x86)\NVIDIA Corporation

2012-11-17 23:29 . 2012-12-04 00:12 -------- d-----w- c:\programdata\NVIDIA

2012-11-17 23:29 . 2012-10-02 19:51 3293544 ----a-w- c:\windows\system32\nvsvc64.dll

2012-11-17 23:29 . 2012-10-02 19:51 6200680 ----a-w- c:\windows\system32\nvcpl.dll

2012-11-17 23:29 . 2012-10-02 19:50 891240 ----a-w- c:\windows\system32\nvvsvc.exe

2012-11-17 23:29 . 2012-10-02 19:50 63336 ----a-w- c:\windows\system32\nvshext.dll

2012-11-17 23:29 . 2012-10-02 19:50 2557800 ----a-w- c:\windows\system32\nvsvcr.dll

2012-11-17 23:29 . 2012-10-02 19:50 118120 ----a-w- c:\windows\system32\nvmctray.dll

2012-11-14 12:10 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys

2012-11-14 12:10 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys

2012-11-14 12:10 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui

2012-11-14 12:10 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll

2012-11-14 12:05 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll

2012-11-14 12:05 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll

2012-11-14 12:05 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys

2012-11-14 12:05 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys

2012-11-14 12:05 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe

2012-11-14 12:05 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll

2012-11-14 12:05 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll

2012-11-14 12:02 . 2012-10-03 17:56 1914248 ----a-w- c:\windows\system32\drivers\tcpip.sys

2012-11-14 12:02 . 2012-10-03 17:44 70656 ----a-w- c:\windows\system32\nlaapi.dll

2012-11-14 12:02 . 2012-10-03 17:44 303104 ----a-w- c:\windows\system32\nlasvc.dll

2012-11-14 12:02 . 2012-10-03 17:44 246272 ----a-w- c:\windows\system32\netcorehc.dll

2012-11-14 12:02 . 2012-10-03 17:44 18944 ----a-w- c:\windows\system32\netevent.dll

2012-11-14 12:02 . 2012-10-03 17:44 216576 ----a-w- c:\windows\system32\ncsi.dll

2012-11-14 12:02 . 2012-10-03 17:42 569344 ----a-w- c:\windows\system32\iphlpsvc.dll

2012-11-14 12:02 . 2012-10-03 16:42 18944 ----a-w- c:\windows\SysWow64\netevent.dll

2012-11-14 12:02 . 2012-10-03 16:42 175104 ----a-w- c:\windows\SysWow64\netcorehc.dll

2012-11-14 12:02 . 2012-10-03 16:42 156672 ----a-w- c:\windows\SysWow64\ncsi.dll

2012-11-14 12:02 . 2012-10-03 16:07 45568 ----a-w- c:\windows\system32\drivers\tcpipreg.sys

2012-11-14 12:02 . 2012-01-13 07:12 52224 ----a-w- c:\windows\SysWow64\nlaapi.dll

2012-11-14 11:56 . 2012-09-25 22:47 78336 ----a-w- c:\windows\SysWow64\synceng.dll

2012-11-14 11:56 . 2012-09-25 22:46 95744 ----a-w- c:\windows\system32\synceng.dll

2012-11-14 11:53 . 2012-10-09 18:17 55296 ----a-w- c:\windows\system32\dhcpcsvc6.dll

2012-11-14 11:53 . 2012-10-09 18:17 226816 ----a-w- c:\windows\system32\dhcpcore6.dll

2012-11-14 11:53 . 2012-10-09 17:40 44032 ----a-w- c:\windows\SysWow64\dhcpcsvc6.dll

2012-11-14 11:53 . 2012-10-09 17:40 193536 ----a-w- c:\windows\SysWow64\dhcpcore6.dll

2012-11-14 11:53 . 2012-10-18 18:25 3149824 ----a-w- c:\windows\system32\win32k.sys

2012-11-06 23:33 . 2012-11-06 23:33 -------- d-----w- c:\windows\[systemFolder]

2012-11-06 01:56 . 2012-11-06 01:56 -------- d-----w- c:\users\Joe\AppData\Roaming\CocotronLibrary




(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))


2012-11-19 14:06 . 2012-08-16 01:46 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2012-11-19 14:06 . 2012-08-16 01:46 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2012-11-14 12:06 . 2012-08-16 00:03 66395536 ----a-w- c:\windows\system32\MRT.exe

2012-10-16 08:38 . 2012-11-28 11:04 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll

2012-10-16 08:38 . 2012-11-28 11:04 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll

2012-10-16 07:39 . 2012-11-28 11:04 561664 ----a-w- c:\windows\apppatch\AcLayers.dll

2012-10-11 03:23 . 2012-10-11 03:23 1867112 ----a-w- c:\windows\SysWow64\nvcuvenc.dll

2012-10-11 03:23 . 2012-10-11 03:23 18252136 ----a-w- c:\windows\system32\nvd3dumx.dll

2012-10-11 03:23 . 2012-10-11 03:23 1482600 ----a-w- c:\windows\system32\nvdispgenco64.dll

2012-10-11 03:23 . 2012-10-11 03:23 6127464 ----a-w- c:\windows\SysWow64\nvopencl.dll

2012-10-11 03:23 . 2012-10-11 03:23 2574696 ----a-w- c:\windows\SysWow64\nvcuvid.dll

2012-10-11 03:23 . 2012-10-11 03:23 25256296 ----a-w- c:\windows\system32\nvcompiler.dll

2012-10-11 03:23 . 2012-10-11 03:23 7414632 ----a-w- c:\windows\system32\nvopencl.dll

2012-10-11 03:23 . 2012-10-11 03:23 2731880 ----a-w- c:\windows\system32\nvapi64.dll

2012-10-11 03:23 . 2012-10-11 03:23 14922600 ----a-w- c:\windows\system32\nvwgf2umx.dll

2012-10-11 03:23 . 2012-10-11 03:23 9146728 ----a-w- c:\windows\system32\nvcuda.dll

2012-10-11 03:23 . 2012-10-11 03:23 7697768 ----a-w- c:\windows\SysWow64\nvcuda.dll

2012-10-11 03:23 . 2012-10-11 03:23 2218344 ----a-w- c:\windows\system32\nvcuvenc.dll

2012-10-11 03:23 . 2012-10-11 03:23 12501352 ----a-w- c:\windows\SysWow64\nvwgf2um.dll

2012-10-11 03:22 . 2012-10-11 03:22 2428776 ----a-w- c:\windows\SysWow64\nvapi.dll

2012-10-11 03:22 . 2012-10-11 03:22 26331496 ----a-w- c:\windows\system32\nvoglv64.dll

2012-10-11 03:22 . 2012-02-10 03:43 1760104 ----a-w- c:\windows\system32\nvdispco64.dll

2012-10-11 03:22 . 2012-10-11 03:22 15309160 ----a-w- c:\windows\SysWow64\nvd3dum.dll

2012-10-11 03:22 . 2012-10-11 03:22 2747240 ----a-w- c:\windows\system32\nvcuvid.dll

2012-10-11 03:22 . 2012-10-11 03:22 19906920 ----a-w- c:\windows\SysWow64\nvoglv32.dll

2012-10-11 03:22 . 2012-10-11 03:22 13443944 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys

2012-10-11 03:22 . 2012-10-11 03:22 17559912 ----a-w- c:\windows\SysWow64\nvcompiler.dll

2012-10-02 19:15 . 2012-10-02 19:15 430952 ----a-w- c:\windows\SysWow64\nvStreaming.exe

2012-09-14 19:19 . 2012-10-10 10:08 2048 ----a-w- c:\windows\system32\tzres.dll

2012-09-14 18:28 . 2012-10-10 10:08 2048 ----a-w- c:\windows\SysWow64\tzres.dll



((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))



*Note* empty entries & legit default entries are not shown




"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

"Calendarscope"="c:\program files (x86)\Calendarscope\csde.exe" [2012-09-17 2848696]

"TivoTransfer"="c:\program files (x86)\TiVo\Desktop\TiVoTransfer.exe" [2010-08-24 608528]

"TranscodingService"="c:\program files (x86)\TiVo\Desktop\Plus\\TranscodingService.exe" [2010-08-24 856336]

"TivoNotify"="c:\program files (x86)\TiVo\Desktop\TiVoNotify.exe" [2010-08-24 437520]

"TivoServer"="c:\program files (x86)\TiVo\Desktop\TiVoServer.exe" [2010-08-24 2264336]



"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]

"Memeo Backup Premium"="c:\program files (x86)\Memeo\AutoBackupPro\MemeoLauncher2.exe" [2012-04-14 131072]



"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)


R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-30 676936]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-30 25928]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-04-25 52736]

R3 USTOR2K;USB Mass Storage Windows Driver;c:\windows\system32\DRIVERS\ustor2k.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-08-16 1255736]

R4 TivoBeacon2;TiVo Beacon Service;c:\program files (x86)\TiVo\Desktop\TiVoBeacon.exe [2010-08-24 1104656]

S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x]

S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-30 399432]

S2 MemeoBackgroundService;MemeoBackgroundService;c:\program files (x86)\Memeo\AutoBackupPro\MemeoBackgroundService.exe [2010-03-22 25824]

S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]

S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]

S3 UsbFltr;WayTech USB Filter Driver;c:\windows\system32\Drivers\UsbFltr.sys [2007-04-09 12288]



Contents of the 'Scheduled Tasks' folder


2012-11-19 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job

- c:\program files (x86)\Spybot - Search & Destroy\SpybotSD.exe [2012-08-16 22:31]



--------- X64 Entries -----------




"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-06-11 12503184]


------- Supplementary Scan -------


uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://www.yahoo.com/

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = *.local;<local>

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000

Trusted Zone: comiclife.com

TCP: DhcpNameServer =


- - - - ORPHANS REMOVED - - - -



WebBrowser-{A13C2648-91D4-4BF3-BC6D-0079707C4389} - (no file)




--------------------- LOCKED REGISTRY KEYS ---------------------



@Denied: (A 2) (Everyone)














@Denied: (A 2) (Everyone)











@Denied: (A 2) (Everyone)














@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"













@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx, 1"












@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"










@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx, 1"












@Denied: (A 2) (Everyone)











@Denied: (Full) (Everyone)


Completion time: 2012-12-03 18:37:16

ComboFix-quarantined-files.txt 2012-12-04 00:37


Pre-Run: 913,705,095,168 bytes free

Post-Run: 913,320,488,960 bytes free


- - End Of File - - 90565DE443915274D1CF697C2A87EE33

  • Staff

please update Adobe Reader and Java, then let me know if there are any outstanding issues

Visit ADOBE and download the latest version of Acrobat Reader (version XI)

Having the latest updates ensures there are no security vulnerabilities in your system.


javaicon.jpgYour Java is out of date.

Java™ 7 Update 7can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.

An update should begin; > follow the prompts.

  • Staff

We just have some housekeeping to do now,

Please do the following:

You can delete the DDS, TDSSKiller, JRT and aswMBR logs and programs from your desktop.


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Press the WinKey +R to open a run box
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.



  • Double click on adwcleaner.exe to run the tool.
  • Click on Uninstall.
  • Confirm with yes.

If there are any logs/tools remaining on your desktop > right click and delete them.


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.
  • Keep Windows updated by regularly checking their website at :
    This will ensure your computer has always the latest security updates available installed on your computer.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

    [*]Download TFC to your desktop

    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean

    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

    [*]WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:

    • Green to go
    • Yellow for caution
    • Red to stop

    WOT has an addon available for both Firefox and IE

    [*]Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

    [*]ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

    [*]In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:

    PC Safety and Security--What Do I Need?.

    [*]Simple and easy ways to keep your computer safe and secure on the Internet

Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

