Jump to content

WhiteSmoke


Recommended Posts

How do I remove WhiteSmoke pop ups from my daughter's computer? I ran Defogger and it didn't ask to re-boot so I forced a reboot. I then ran DDS and this is the log it created...

.

DDS (Ver_2011-06-23.01) - NTFSAMD64

Internet Explorer: 8.0.7600.16385

Run by Shelby at 8:42:03 on 2011-07-09

Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3891.2282 [GMT -5:00]

.

AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

============== Running Processes ===============

.

C:\windows\system32\wininit.exe

C:\windows\system32\lsm.exe

C:\windows\system32\svchost.exe -k DcomLaunch

C:\windows\system32\svchost.exe -k RPCSS

C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\windows\system32\svchost.exe -k netsvcs

C:\windows\system32\svchost.exe -k LocalService

C:\windows\system32\svchost.exe -k NetworkService

C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

C:\windows\System32\spoolsv.exe

C:\windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files (x86)\Bonjour\mDNSResponder.exe

C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\SymcPCCULaunchSvc.exe

C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe

C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe

C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE

C:\windows\system32\svchost.exe -k imgsvc

C:\windows\SysWOW64\svchost.exe -k svcboot_ufaucvfq

C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe

C:\windows\system32\ThpSrv.exe

C:\Windows\system32\TODDSrv.exe

C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe

C:\Program Files\TOSHIBA\TECO\TecoService.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\windows\system32\SearchIndexer.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\windows\system32\taskhost.exe

C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe

C:\windows\SysWOW64\svchost.exe

C:\Program Files (x86)\TeamViewer\Version6\TeamViewer.exe

C:\windows\system32\Dwm.exe

C:\windows\Explorer.EXE

C:\windows\system32\rundll32.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe

C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe

C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe

C:\Windows\System32\ThpSrv.exe

C:\Program Files\TOSHIBA\TECO\Teco.exe

C:\windows\system32\wbem\wmiprvse.exe

C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe

C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe

C:\Program Files\Microsoft IntelliPoint\ipoint.exe

C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files (x86)\WhiteSmoke\WSEnrichment.exe

C:\Program Files (x86)\WhiteSmoke\WSTray64.exe

C:\Program Files\Synaptics\SynTP\SynTPHelper.exe

C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe

C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe

C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe

C:\Program Files (x86)\iTunes\iTunesHelper.exe

"C:\windows\SysWOW64\svchost.exe"

C:\windows\system32\igfxext.exe

C:\windows\system32\igfxsrvc.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe

C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe

C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

C:\windows\System32\svchost.exe -k secsvcs

C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe

C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe

C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe

C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\Program Files (x86)\Internet Explorer\iexplore.exe

C:\windows\SysWOW64\Macromed\Flash\FlashUtil10l_ActiveX.exe

C:\windows\system32\SearchProtocolHost.exe

C:\windows\system32\SearchFilterHost.exe

C:\windows\system32\SearchProtocolHost.exe

C:\windows\system32\wbem\wmiprvse.exe

C:\windows\SysWOW64\cmd.exe

C:\windows\system32\conhost.exe

C:\windows\SysWOW64\cscript.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://whitesmokestart.com/?src=startpage&provider=bing&provider_name=bing&provider_code=Z052&partner_id=208&product_id=663&affiliate_id=&channel=9128&toolbar_id=202&toolbar_version=2.1.0&install_country=US&install_date=20110705&user_guid=2B93D2443E564E249647232649601A7B&machine_id=1cf040ecad92ded19e00f2146c17bffd&browser=IE&os=win&os_version=6.1-x64-SP0

mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSND&bmod=TSND

uInternet Settings,ProxyOverride = <local>

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll

BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL

BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO: TOSHIBA Media Controller Plug-in: {f3c88694-effa-4d78-b409-54b7b2535b14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll

TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background

uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

uRun: [LvfoZkfgayzPlby\AppData\Local\Temp\2604111823.exe] C:\Users\Shelby\AppData\Local\Temp\2604111823.exe

mRun: [TSleepSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe

mRun: [ToshibaAppPlace] "C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe"

mRun: [sVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL

mRun: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP

mRun: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe

mRun: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun

mRun: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60

mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe" UNATTENDED

mRun: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices

mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

StartupFolder: C:\Users\Shelby\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\LAUNCH~1.LNK - C:\Program Files (x86)\WhiteSmoke\WSEnrichment.exe

mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

mPolicies-system: PromptOnSecureDesktop = 0 (0x0)

IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab

TCP: DhcpNameServer = 192.168.11.1

TCP: Interfaces\{15D0859D-A926-4843-924E-1B21343A1FA5} : DhcpNameServer = 192.168.11.1

TCP: Interfaces\{C93871E8-349E-4786-B50D-6F8B0A4D0BBF} : DhcpNameServer = 192.168.11.1

TCP: Interfaces\{C93871E8-349E-4786-B50D-6F8B0A4D0BBF}\76275647E61623 : DhcpNameServer = 192.168.1.20

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO-X64: AcroIEHelperStub - No File

BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.6209.1142\swg.dll

BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLL

BHO-X64: URLRedirectionBHO - No File

BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"

BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO-X64: TOSHIBA Media Controller Plug-in: {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll

TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"

TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll

mRun-x64: [TSleepSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe

mRun-x64: [ToshibaAppPlace] "C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe"

mRun-x64: [sVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL

mRun-x64: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP

mRun-x64: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe

mRun-x64: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun

mRun-x64: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60

mRun-x64: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe" UNATTENDED

mRun-x64: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices

mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\Shelby\AppData\Roaming\Mozilla\Firefox\Profiles\0u9bqn31.default\

FF - prefs.js: browser.search.selectedEngine - Bing

FF - prefs.js: browser.startup.homepage - hxxp://whitesmokestart.com/?src=startpage&provider=bing&provider_name=bing&provider_code=Z052&partner_id=208&product_id=663&affiliate_id=&channel=9128&toolbar_id=202&toolbar_version=2.1.0&install_country=US&install_date=20110705&user_guid=2B93D2443E564E249647232649601A7B&machine_id=1cf040ecad92ded19e00f2146c17bffd&browser=FF&os=win&os_version=6.1-x64-SP0

FF - prefs.js: keyword.URL - hxxp://whitesmokestart.com/s/?src=addrbar&provider=bing&provider_name=bing&provider_code=Z052&partner_id=208&product_id=663&affiliate_id=&channel=9128&toolbar_id=202&toolbar_version=2.1.0&install_country=US&install_date=20110705&user_guid=2B93D2443E564E249647232649601A7B&machine_id=1cf040ecad92ded19e00f2146c17bffd&browser=FF&os=win&os_version=6.1-x64-SP0&q=

FF - prefs.js: network.proxy.type - 0

FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL

FF - plugin: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL

FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll

FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll

FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll

.

============= SERVICES / DRIVERS ===============

.

R0 Thpdrv;TOSHIBA HDD Protection Driver;C:\windows\system32\DRIVERS\thpdrv.sys --> C:\windows\system32\DRIVERS\thpdrv.sys [?]

R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;C:\windows\system32\DRIVERS\Thpevm.SYS --> C:\windows\system32\DRIVERS\Thpevm.SYS [?]

R0 unihoocx;unihoocx;C:\windows\system32\DRIVERS\unihoocx.sys --> C:\windows\system32\DRIVERS\unihoocx.sys [?]

R1 aswSnx;aswSnx;C:\windows\system32\drivers\aswSnx.sys --> C:\windows\system32\drivers\aswSnx.sys [?]

R1 aswSP;aswSP;C:\windows\system32\drivers\aswSP.sys --> C:\windows\system32\drivers\aswSP.sys [?]

R1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys --> C:\windows\system32\DRIVERS\vwififlt.sys [?]

R2 aswFsBlk;aswFsBlk;C:\windows\system32\drivers\aswFsBlk.sys --> C:\windows\system32\drivers\aswFsBlk.sys [?]

R2 aswMonFlt;aswMonFlt;\??\C:\windows\system32\drivers\aswMonFlt.sys --> C:\windows\system32\drivers\aswMonFlt.sys [?]

R2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-7-7 42184]

R2 Norton PC Checkup Application Launcher;Toshiba Laptop Checkup Application Launcher;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\SymcPCCULaunchSvc.exe [2010-9-15 103792]

R2 PCCUJobMgr;Common Client Job Manager Service;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe [2010-9-15 126392]

R2 svcboot_ufaucvfq;svcboot_ufaucvfq;C:\windows\system32\svchost.exe -k svcboot_ufaucvfq [2009-7-13 20992]

R2 TeamViewer6;TeamViewer 6;C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-3-17 2296696]

R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:\Program Files\TOSHIBA\TECO\TecoService.exe [2010-4-6 258928]

R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;C:\windows\system32\DRIVERS\TVALZFL.sys --> C:\windows\system32\DRIVERS\TVALZFL.sys [?]

R2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-9-15 2314240]

R3 HECIx64;Intel® Management Engine Interface;C:\windows\system32\DRIVERS\HECIx64.sys --> C:\windows\system32\DRIVERS\HECIx64.sys [?]

R3 Impcd;Impcd;C:\windows\system32\DRIVERS\Impcd.sys --> C:\windows\system32\DRIVERS\Impcd.sys [?]

R3 IntcDAud;Intel® Display Audio;C:\windows\system32\DRIVERS\IntcDAud.sys --> C:\windows\system32\DRIVERS\IntcDAud.sys [?]

R3 JMCR;JMCR;C:\windows\system32\DRIVERS\jmcr.sys --> C:\windows\system32\DRIVERS\jmcr.sys [?]

R3 PGEffect;Pangu effect driver;C:\windows\system32\DRIVERS\pgeffect.sys --> C:\windows\system32\DRIVERS\pgeffect.sys [?]

R3 RTL8167;Realtek 8167 NT Driver;C:\windows\system32\DRIVERS\Rt64win7.sys --> C:\windows\system32\DRIVERS\Rt64win7.sys [?]

R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;C:\windows\system32\DRIVERS\rtl8192se.sys --> C:\windows\system32\DRIVERS\rtl8192se.sys [?]

R3 TMachInfo;TMachInfo;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2010-9-15 51512]

R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-2-5 137560]

R3 TPCHSrv;TPCH Service;C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2010-3-31 835952]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-8-9 136176]

S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-2-28 183560]

S3 fssfltr;fssfltr;C:\windows\system32\DRIVERS\fssfltr.sys --> C:\windows\system32\DRIVERS\fssfltr.sys [?]

S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352]

S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-8-9 136176]

S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]

S3 USBAAPL64;Apple Mobile USB Driver;C:\windows\system32\Drivers\usbaapl64.sys --> C:\windows\system32\Drivers\usbaapl64.sys [?]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\system32\Wat\WatAdminSvc.exe --> C:\windows\system32\Wat\WatAdminSvc.exe [?]

S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]

.

=============== File Associations ===============

.

inffile=%SystemRoot%\SysWow64\NOTEPAD.EXE %1

VBEFile=%SystemRoot%\SysWow64\WScript.exe "%1" %*

VBSFile=%SystemRoot%\SysWow64\WScript.exe "%1" %*

.

=============== Created Last 30 ================

.

2011-07-09 13:03:39 -------- d-----w- C:\Users\Shelby\AppData\Local\{3927E1DB-325A-4EDB-987B-7A198DAE0979}

2011-07-09 03:13:05 -------- d-sh--w- C:\$RECYCLE.BIN

2011-07-09 02:14:05 -------- d-----w- C:\ComboFix

2011-07-08 23:12:31 98816 ----a-w- C:\windows\sed.exe

2011-07-08 23:12:31 518144 ----a-w- C:\windows\SWREG.exe

2011-07-08 23:12:31 256000 ----a-w- C:\windows\PEV.exe

2011-07-08 23:12:31 208896 ----a-w- C:\windows\MBR.exe

2011-07-08 20:14:46 -------- d-----w- C:\Users\Shelby\AppData\Local\{51F7C797-8BCD-46C8-9B54-E5DA5533868F}

2011-07-08 18:32:49 8873296 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{89565020-7924-4528-AACD-229C8ABB1CF3}\mpengine.dll

2011-07-07 20:49:31 -------- d-----w- C:\Users\Shelby\AppData\Local\{BF74D0EF-6705-4EA9-AF20-3498EA3A85B6}

2011-07-06 21:25:19 -------- d-----w- C:\Users\Shelby\AppData\Local\{54C5A50C-A33B-48F8-9B35-FC3809AF6685}

2011-07-05 22:23:35 -------- d-----w- C:\Program Files (x86)\Xvid

2011-07-05 22:16:36 -------- d-----w- C:\Users\Shelby\AppData\Roaming\WhiteSmoke

2011-07-05 22:16:28 2106216 ----a-w- C:\Program Files (x86)\Mozilla Firefox\D3DCompiler_43.dll

2011-07-05 22:16:27 1998168 ----a-w- C:\Program Files (x86)\Mozilla Firefox\d3dx9_43.dll

2011-07-05 22:16:09 -------- d-----w- C:\Program Files (x86)\WhiteSmoke

2011-07-02 13:53:09 -------- d-----w- C:\Users\Shelby\AppData\Local\{8895AE57-3A2C-4D4A-8530-66C1749031F6}

2011-06-28 03:42:15 -------- d-----w- C:\Users\Shelby\AppData\Local\{80BEAA41-67AA-410C-91CC-25CEDFB29C45}

2011-06-27 21:37:53 102400 ----a-w- C:\windows\System32\drivers\dfsc.sys

2011-06-27 21:37:51 499712 ----a-w- C:\windows\System32\drivers\afd.sys

2011-06-27 21:37:51 1896832 ----a-w- C:\windows\System32\drivers\tcpip.sys

2011-06-27 21:37:49 759296 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll

2011-06-27 21:37:49 1110528 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll

2011-06-27 21:37:42 287744 ----a-w- C:\windows\System32\drivers\mrxsmb10.sys

2011-06-27 21:37:42 126464 ----a-w- C:\windows\System32\drivers\mrxsmb20.sys

2011-06-27 21:37:41 157696 ----a-w- C:\windows\System32\drivers\mrxsmb.sys

2011-06-27 21:37:39 3133952 ----a-w- C:\windows\System32\win32k.sys

2011-06-27 21:35:06 976896 ----a-w- C:\windows\System32\inetcomm.dll

2011-06-27 21:35:04 740864 ----a-w- C:\windows\SysWow64\inetcomm.dll

2011-06-27 21:34:43 399872 ----a-w- C:\windows\System32\drivers\srv2.sys

2011-06-27 21:34:37 461312 ----a-w- C:\windows\System32\drivers\srv.sys

2011-06-27 21:34:36 161792 ----a-w- C:\windows\System32\drivers\srvnet.sys

2011-06-27 21:34:18 320512 ----a-w- C:\windows\System32\d3d10_1core.dll

2011-06-27 21:34:18 218624 ----a-w- C:\windows\SysWow64\d3d10_1core.dll

2011-06-27 21:34:17 197120 ----a-w- C:\windows\System32\d3d10_1.dll

2011-06-27 21:34:16 161792 ----a-w- C:\windows\SysWow64\d3d10_1.dll

2011-06-27 21:34:05 861184 ----a-w- C:\windows\System32\oleaut32.dll

2011-06-27 21:34:05 571904 ----a-w- C:\windows\SysWow64\oleaut32.dll

2011-06-27 00:16:28 -------- d-----w- C:\Users\Shelby\AppData\Local\{401713CA-699E-42E4-B825-C53C85182ABD}

2011-06-15 22:01:07 -------- d-----w- C:\Program Files\iPod

2011-06-15 22:01:06 -------- d-----w- C:\Program Files\iTunes

2011-06-15 22:01:06 -------- d-----w- C:\Program Files (x86)\iTunes

2011-06-15 21:56:32 -------- d-----w- C:\Users\Shelby\AppData\Local\{27F22EC6-5DDC-4519-AC82-B6C3AA406147}

.

==================== Find3M ====================

.

2011-07-04 11:43:53 40112 ----a-w- C:\windows\avastSS.scr

2011-07-04 11:36:56 600920 ----a-w- C:\windows\System32\drivers\aswSnx.sys

2011-07-04 11:32:24 64856 ----a-w- C:\windows\System32\drivers\aswMonFlt.sys

2011-06-27 21:12:22 404640 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl

2011-05-29 14:11:30 39984 ----a-w- C:\windows\SysWow64\drivers\mbamswissarmy.sys

2011-05-29 14:11:20 25912 ----a-w- C:\windows\System32\drivers\mbam.sys

2011-05-28 03:25:16 1638912 ----a-w- C:\windows\System32\mshtml.tlb

2011-05-28 03:00:02 1638912 ----a-w- C:\windows\SysWow64\mshtml.tlb

2011-05-25 00:14:10 270720 ------w- C:\windows\System32\MpSigStub.exe

2011-05-24 11:21:59 404992 ----a-w- C:\windows\System32\umpnpmgr.dll

2011-05-24 10:34:20 64512 ----a-w- C:\windows\SysWow64\devobj.dll

2011-05-24 10:34:20 44544 ----a-w- C:\windows\SysWow64\devrtl.dll

2011-05-24 10:34:00 145920 ----a-w- C:\windows\SysWow64\cfgmgr32.dll

2011-05-24 10:32:46 252928 ----a-w- C:\windows\SysWow64\drvinst.exe

2011-05-10 13:06:08 51712 ----a-w- C:\windows\System32\drivers\usbaapl64.sys

2011-05-10 13:06:08 4517664 ----a-w- C:\windows\System32\usbaaplrc.dll

2011-05-04 05:30:38 2326016 ----a-w- C:\windows\System32\tquery.dll

2011-05-04 05:28:07 779264 ----a-w- C:\windows\System32\mssvp.dll

2011-05-04 05:28:07 2228224 ----a-w- C:\windows\System32\mssrch.dll

2011-05-04 05:28:06 75264 ----a-w- C:\windows\System32\msscntrs.dll

2011-05-04 05:28:06 491520 ----a-w- C:\windows\System32\mssph.dll

2011-05-04 05:28:06 288256 ----a-w- C:\windows\System32\mssphtb.dll

2011-05-04 05:24:09 593408 ----a-w- C:\windows\System32\SearchIndexer.exe

2011-05-04 05:24:09 249856 ----a-w- C:\windows\System32\SearchProtocolHost.exe

2011-05-04 05:24:09 113664 ----a-w- C:\windows\System32\SearchFilterHost.exe

2011-05-04 04:53:10 1553920 ----a-w- C:\windows\SysWow64\tquery.dll

2011-05-04 04:52:59 666624 ----a-w- C:\windows\SysWow64\mssvp.dll

2011-05-04 04:52:59 59392 ----a-w- C:\windows\SysWow64\msscntrs.dll

2011-05-04 04:52:59 337408 ----a-w- C:\windows\SysWow64\mssph.dll

2011-05-04 04:52:59 197120 ----a-w- C:\windows\SysWow64\mssphtb.dll

2011-05-04 04:52:59 1401856 ----a-w- C:\windows\SysWow64\mssrch.dll

2011-05-04 04:52:12 86528 ----a-w- C:\windows\SysWow64\SearchFilterHost.exe

2011-05-04 04:52:12 428032 ----a-w- C:\windows\SysWow64\SearchIndexer.exe

2011-05-04 04:52:12 164352 ----a-w- C:\windows\SysWow64\SearchProtocolHost.exe

2011-04-22 20:18:47 27008 ----a-w- C:\windows\System32\drivers\Diskdump.sys

2011-04-22 20:18:28 1197056 ----a-w- C:\windows\System32\wininet.dll

2011-04-22 20:14:08 57856 ----a-w- C:\windows\System32\licmgr10.dll

2011-04-22 19:31:50 981504 ----a-w- C:\windows\SysWow64\wininet.dll

2011-04-22 19:31:26 44544 ----a-w- C:\windows\SysWow64\licmgr10.dll

2011-04-22 18:49:57 482816 ----a-w- C:\windows\System32\html.iec

2011-04-22 18:23:59 386048 ----a-w- C:\windows\SysWow64\html.iec

.

============= FINISH: 8:46:13.89 ===============

Link to post
Share on other sites

Hi and :welcome:

I see you have also run combofix. Can you please post me the log you can find at c:\combofix.txt?

This infection often comes with a rootkit, so lets run also a rootkit scan.

Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!

  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • If TDSSKiller does not run, try renaming it.
  • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
  • Click the Start Scan button.
  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
  • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.

Link to post
Share on other sites

Hi and :welcome:

I see you have also run combofix. Can you please post me the log you can find at c:\combofix.txt?

This infection often comes with a rootkit, so lets run also a rootkit scan.

Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!

  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • If TDSSKiller does not run, try renaming it.
  • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
  • Click the Start Scan button.
  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
  • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.

TDSSkiller contents:

2011/07/09 11:33:24.0273 9208 TDSS rootkit removing tool 2.5.9.0 Jul 1 2011 18:45:21

2011/07/09 11:33:26.0292 9208 ================================================================================

2011/07/09 11:33:26.0292 9208 SystemInfo:

2011/07/09 11:33:26.0292 9208

2011/07/09 11:33:26.0292 9208 OS Version: 6.1.7600 ServicePack: 0.0

2011/07/09 11:33:26.0292 9208 Product type: Workstation

2011/07/09 11:33:26.0292 9208 ComputerName: SHELBY-PC

2011/07/09 11:33:26.0292 9208 UserName: Shelby

2011/07/09 11:33:26.0292 9208 Windows directory: C:\windows

2011/07/09 11:33:26.0292 9208 System windows directory: C:\windows

2011/07/09 11:33:26.0292 9208 Running under WOW64

2011/07/09 11:33:26.0292 9208 Processor architecture: Intel x64

2011/07/09 11:33:26.0292 9208 Number of processors: 2

2011/07/09 11:33:26.0293 9208 Page size: 0x1000

2011/07/09 11:33:26.0293 9208 Boot type: Normal boot

2011/07/09 11:33:26.0293 9208 ================================================================================

2011/07/09 11:33:26.0586 9208 Initialize success

2011/07/09 11:33:30.0284 8304 ================================================================================

2011/07/09 11:33:30.0284 8304 Scan started

2011/07/09 11:33:30.0284 8304 Mode: Manual;

2011/07/09 11:33:30.0284 8304 ================================================================================

2011/07/09 11:33:30.0613 8304 1394ohci (969c91060cbb5d17cb8440b5f78b4c51) C:\windows\system32\DRIVERS\1394ohci.sys

2011/07/09 11:33:30.0732 8304 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\windows\system32\DRIVERS\ACPI.sys

2011/07/09 11:33:30.0839 8304 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\windows\system32\DRIVERS\acpipmi.sys

2011/07/09 11:33:30.0966 8304 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\windows\system32\DRIVERS\adp94xx.sys

2011/07/09 11:33:31.0083 8304 adpahci (597f78224ee9224ea1a13d6350ced962) C:\windows\system32\DRIVERS\adpahci.sys

2011/07/09 11:33:31.0197 8304 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\windows\system32\DRIVERS\adpu320.sys

2011/07/09 11:33:31.0360 8304 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\windows\system32\drivers\afd.sys

2011/07/09 11:33:31.0465 8304 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\windows\system32\DRIVERS\agp440.sys

2011/07/09 11:33:31.0576 8304 aliide (5812713a477a3ad7363c7438ca2ee038) C:\windows\system32\DRIVERS\aliide.sys

2011/07/09 11:33:31.0676 8304 amdide (1ff8b4431c353ce385c875f194924c0c) C:\windows\system32\DRIVERS\amdide.sys

2011/07/09 11:33:31.0781 8304 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\windows\system32\DRIVERS\amdk8.sys

2011/07/09 11:33:31.0868 8304 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\windows\system32\DRIVERS\amdppm.sys

2011/07/09 11:33:31.0980 8304 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\windows\system32\drivers\amdsata.sys

2011/07/09 11:33:32.0077 8304 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\windows\system32\DRIVERS\amdsbs.sys

2011/07/09 11:33:32.0195 8304 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\windows\system32\drivers\amdxata.sys

2011/07/09 11:33:32.0311 8304 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\windows\system32\drivers\appid.sys

2011/07/09 11:33:32.0454 8304 arc (c484f8ceb1717c540242531db7845c4e) C:\windows\system32\DRIVERS\arc.sys

2011/07/09 11:33:32.0563 8304 arcsas (019af6924aefe7839f61c830227fe79c) C:\windows\system32\DRIVERS\arcsas.sys

2011/07/09 11:33:32.0679 8304 aswFsBlk (55353cd0da287b2c3782485740965b54) C:\windows\system32\drivers\aswFsBlk.sys

2011/07/09 11:33:32.0815 8304 aswMonFlt (b38061cdefb71361e0c7547ac60527e8) C:\windows\system32\drivers\aswMonFlt.sys

2011/07/09 11:33:32.0911 8304 aswRdr (91e7aca95933633b2557f47cdfdb74c3) C:\windows\system32\drivers\aswRdr.sys

2011/07/09 11:33:33.0075 8304 aswSnx (2b15499f68fad60ce69264a327e9b0f0) C:\windows\system32\drivers\aswSnx.sys

2011/07/09 11:33:33.0172 8304 aswSP (4d939ecb19dc930056593390d1c87c43) C:\windows\system32\drivers\aswSP.sys

2011/07/09 11:33:33.0277 8304 aswTdi (d633426c5a207ce21767569aa4946891) C:\windows\system32\drivers\aswTdi.sys

2011/07/09 11:33:33.0362 8304 AsyncMac (769765ce2cc62867468cea93969b2242) C:\windows\system32\DRIVERS\asyncmac.sys

2011/07/09 11:33:33.0461 8304 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\windows\system32\DRIVERS\atapi.sys

2011/07/09 11:33:33.0599 8304 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\windows\system32\DRIVERS\bxvbda.sys

2011/07/09 11:33:33.0703 8304 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\windows\system32\DRIVERS\b57nd60a.sys

2011/07/09 11:33:33.0832 8304 Beep (16a47ce2decc9b099349a5f840654746) C:\windows\system32\drivers\Beep.sys

2011/07/09 11:33:33.0952 8304 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\windows\system32\DRIVERS\blbdrive.sys

2011/07/09 11:33:34.0105 8304 bowser (19d20159708e152267e53b66677a4995) C:\windows\system32\DRIVERS\bowser.sys

2011/07/09 11:33:34.0206 8304 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\windows\system32\DRIVERS\BrFiltLo.sys

2011/07/09 11:33:34.0317 8304 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\windows\system32\DRIVERS\BrFiltUp.sys

2011/07/09 11:33:34.0414 8304 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\windows\System32\Drivers\Brserid.sys

2011/07/09 11:33:34.0505 8304 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\windows\System32\Drivers\BrSerWdm.sys

2011/07/09 11:33:34.0605 8304 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\windows\System32\Drivers\BrUsbMdm.sys

2011/07/09 11:33:34.0683 8304 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\windows\System32\Drivers\BrUsbSer.sys

2011/07/09 11:33:34.0785 8304 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\windows\system32\DRIVERS\bthmodem.sys

2011/07/09 11:33:34.0973 8304 cdfs (b8bd2bb284668c84865658c77574381a) C:\windows\system32\DRIVERS\cdfs.sys

2011/07/09 11:33:35.0053 8304 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\windows\system32\DRIVERS\cdrom.sys

2011/07/09 11:33:35.0180 8304 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\windows\system32\DRIVERS\circlass.sys

2011/07/09 11:33:35.0278 8304 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\windows\system32\CLFS.sys

2011/07/09 11:33:35.0405 8304 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\windows\system32\DRIVERS\CmBatt.sys

2011/07/09 11:33:35.0494 8304 cmdide (e19d3f095812725d88f9001985b94edd) C:\windows\system32\DRIVERS\cmdide.sys

2011/07/09 11:33:35.0609 8304 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\windows\system32\Drivers\cng.sys

2011/07/09 11:33:35.0701 8304 Compbatt (102de219c3f61415f964c88e9085ad14) C:\windows\system32\DRIVERS\compbatt.sys

2011/07/09 11:33:35.0799 8304 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\windows\system32\DRIVERS\CompositeBus.sys

2011/07/09 11:33:35.0907 8304 crcdisk (1c827878a998c18847245fe1f34ee597) C:\windows\system32\DRIVERS\crcdisk.sys

2011/07/09 11:33:36.0072 8304 DfsC (9c253ce7311ca60fc11c774692a13208) C:\windows\system32\Drivers\dfsc.sys

2011/07/09 11:33:36.0172 8304 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\windows\system32\drivers\discache.sys

2011/07/09 11:33:36.0271 8304 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\windows\system32\DRIVERS\disk.sys

2011/07/09 11:33:36.0402 8304 drmkaud (9b19f34400d24df84c858a421c205754) C:\windows\system32\drivers\drmkaud.sys

2011/07/09 11:33:36.0531 8304 DXGKrnl (ebce0b0924835f635f620d19f0529dce) C:\windows\System32\drivers\dxgkrnl.sys

2011/07/09 11:33:36.0706 8304 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\windows\system32\DRIVERS\evbda.sys

2011/07/09 11:33:36.0888 8304 elxstor (0e5da5369a0fcaea12456dd852545184) C:\windows\system32\DRIVERS\elxstor.sys

2011/07/09 11:33:36.0979 8304 ErrDev (34a3c54752046e79a126e15c51db409b) C:\windows\system32\DRIVERS\errdev.sys

2011/07/09 11:33:37.0100 8304 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\windows\system32\drivers\exfat.sys

2011/07/09 11:33:37.0181 8304 fastfat (0adc83218b66a6db380c330836f3e36d) C:\windows\system32\drivers\fastfat.sys

2011/07/09 11:33:37.0280 8304 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\windows\system32\DRIVERS\fdc.sys

2011/07/09 11:33:37.0397 8304 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\windows\system32\drivers\fileinfo.sys

2011/07/09 11:33:37.0471 8304 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\windows\system32\drivers\filetrace.sys

2011/07/09 11:33:37.0538 8304 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\windows\system32\DRIVERS\flpydisk.sys

2011/07/09 11:33:37.0647 8304 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\windows\system32\drivers\fltmgr.sys

2011/07/09 11:33:37.0759 8304 FsDepends (d43703496149971890703b4b1b723eac) C:\windows\system32\drivers\FsDepends.sys

2011/07/09 11:33:37.0857 8304 fssfltr (6c06701bf1db05405804d7eb610991ce) C:\windows\system32\DRIVERS\fssfltr.sys

2011/07/09 11:33:37.0954 8304 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\windows\system32\drivers\Fs_Rec.sys

2011/07/09 11:33:38.0060 8304 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\windows\system32\DRIVERS\fvevol.sys

2011/07/09 11:33:38.0158 8304 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\windows\system32\DRIVERS\gagp30kx.sys

2011/07/09 11:33:38.0284 8304 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\windows\system32\DRIVERS\GEARAspiWDM.sys

2011/07/09 11:33:38.0456 8304 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\windows\system32\drivers\hcw85cir.sys

2011/07/09 11:33:38.0570 8304 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\windows\system32\drivers\HdAudio.sys

2011/07/09 11:33:38.0684 8304 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\windows\system32\DRIVERS\HDAudBus.sys

2011/07/09 11:33:38.0780 8304 HECIx64 (b6ac71aaa2b10848f57fc49d55a651af) C:\windows\system32\DRIVERS\HECIx64.sys

2011/07/09 11:33:38.0867 8304 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\windows\system32\DRIVERS\HidBatt.sys

2011/07/09 11:33:38.0948 8304 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\windows\system32\DRIVERS\hidbth.sys

2011/07/09 11:33:39.0039 8304 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\windows\system32\DRIVERS\hidir.sys

2011/07/09 11:33:39.0157 8304 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\windows\system32\DRIVERS\hidusb.sys

2011/07/09 11:33:39.0264 8304 HpSAMD (0886d440058f203eba0e1825e4355914) C:\windows\system32\DRIVERS\HpSAMD.sys

2011/07/09 11:33:39.0385 8304 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\windows\system32\drivers\HTTP.sys

2011/07/09 11:33:39.0480 8304 hwpolicy (f17766a19145f111856378df337a5d79) C:\windows\system32\drivers\hwpolicy.sys

2011/07/09 11:33:39.0579 8304 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\windows\system32\DRIVERS\i8042prt.sys

2011/07/09 11:33:39.0688 8304 iaStor (85977cd13fc16069ce0af7943a811775) C:\windows\system32\DRIVERS\iaStor.sys

2011/07/09 11:33:39.0821 8304 iaStorV (b75e45c564e944a2657167d197ab29da) C:\windows\system32\drivers\iaStorV.sys

2011/07/09 11:33:40.0175 8304 igfx (2a22ab054f4630d2ef4bab2853f6d5f6) C:\windows\system32\DRIVERS\igdkmd64.sys

2011/07/09 11:33:40.0497 8304 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\windows\system32\DRIVERS\iirsp.sys

2011/07/09 11:33:40.0607 8304 Impcd (dd587a55390ed2295bce6d36ad567da9) C:\windows\system32\DRIVERS\Impcd.sys

2011/07/09 11:33:40.0779 8304 IntcAzAudAddService (a73cc9bd3a7236e686be6667f0106c16) C:\windows\system32\drivers\RTKVHD64.sys

2011/07/09 11:33:40.0894 8304 IntcDAud (58cf58dee26c909bd6f977b61d246295) C:\windows\system32\DRIVERS\IntcDAud.sys

2011/07/09 11:33:40.0986 8304 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\windows\system32\DRIVERS\intelide.sys

2011/07/09 11:33:41.0090 8304 intelppm (ada036632c664caa754079041cf1f8c1) C:\windows\system32\DRIVERS\intelppm.sys

2011/07/09 11:33:41.0189 8304 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\windows\system32\DRIVERS\ipfltdrv.sys

2011/07/09 11:33:41.0290 8304 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\windows\system32\DRIVERS\IPMIDrv.sys

2011/07/09 11:33:41.0380 8304 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\windows\system32\drivers\ipnat.sys

2011/07/09 11:33:41.0501 8304 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\windows\system32\drivers\irenum.sys

2011/07/09 11:33:41.0603 8304 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\windows\system32\DRIVERS\isapnp.sys

2011/07/09 11:33:41.0692 8304 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\windows\system32\DRIVERS\msiscsi.sys

2011/07/09 11:33:41.0839 8304 JMCR (3a7d9638a50b45d1e20b9911961ab97c) C:\windows\system32\DRIVERS\jmcr.sys

2011/07/09 11:33:41.0938 8304 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\windows\system32\DRIVERS\kbdclass.sys

2011/07/09 11:33:42.0018 8304 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\windows\system32\DRIVERS\kbdhid.sys

2011/07/09 11:33:42.0115 8304 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\windows\system32\Drivers\ksecdd.sys

2011/07/09 11:33:42.0202 8304 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\windows\system32\Drivers\ksecpkg.sys

2011/07/09 11:33:42.0297 8304 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\windows\system32\drivers\ksthunk.sys

2011/07/09 11:33:42.0433 8304 lltdio (1538831cf8ad2979a04c423779465827) C:\windows\system32\DRIVERS\lltdio.sys

2011/07/09 11:33:42.0570 8304 LPCFilter (41e122f6d1448c94cc05196bc41d6bfb) C:\windows\system32\DRIVERS\LPCFilter.sys

2011/07/09 11:33:42.0677 8304 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\windows\system32\DRIVERS\lsi_fc.sys

2011/07/09 11:33:42.0780 8304 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\windows\system32\DRIVERS\lsi_sas.sys

2011/07/09 11:33:42.0881 8304 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\windows\system32\DRIVERS\lsi_sas2.sys

2011/07/09 11:33:42.0994 8304 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\windows\system32\DRIVERS\lsi_scsi.sys

2011/07/09 11:33:43.0103 8304 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\windows\system32\drivers\luafv.sys

2011/07/09 11:33:43.0199 8304 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\windows\system32\DRIVERS\megasas.sys

2011/07/09 11:33:43.0292 8304 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\windows\system32\DRIVERS\MegaSR.sys

2011/07/09 11:33:43.0386 8304 Modem (800ba92f7010378b09f9ed9270f07137) C:\windows\system32\drivers\modem.sys

2011/07/09 11:33:43.0472 8304 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\windows\system32\DRIVERS\monitor.sys

2011/07/09 11:33:43.0572 8304 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\windows\system32\DRIVERS\mouclass.sys

2011/07/09 11:33:43.0678 8304 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\windows\system32\DRIVERS\mouhid.sys

2011/07/09 11:33:43.0782 8304 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\windows\system32\drivers\mountmgr.sys

2011/07/09 11:33:43.0860 8304 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\windows\system32\DRIVERS\mpio.sys

2011/07/09 11:33:43.0960 8304 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\windows\system32\drivers\mpsdrv.sys

2011/07/09 11:33:44.0062 8304 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\windows\system32\drivers\mrxdav.sys

2011/07/09 11:33:44.0184 8304 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\windows\system32\DRIVERS\mrxsmb.sys

2011/07/09 11:33:44.0286 8304 mrxsmb10 (a8c2d7673c8a010569390c826a0efaf4) C:\windows\system32\DRIVERS\mrxsmb10.sys

2011/07/09 11:33:44.0398 8304 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\windows\system32\DRIVERS\mrxsmb20.sys

2011/07/09 11:33:44.0503 8304 msahci (5c37497276e3b3a5488b23a326a754b7) C:\windows\system32\DRIVERS\msahci.sys

2011/07/09 11:33:44.0583 8304 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\windows\system32\DRIVERS\msdsm.sys

2011/07/09 11:33:44.0700 8304 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\windows\system32\drivers\Msfs.sys

2011/07/09 11:33:44.0773 8304 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\windows\System32\drivers\mshidkmdf.sys

2011/07/09 11:33:44.0852 8304 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\windows\system32\DRIVERS\msisadrv.sys

2011/07/09 11:33:44.0967 8304 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\windows\system32\drivers\MSKSSRV.sys

2011/07/09 11:33:45.0067 8304 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\windows\system32\drivers\MSPCLOCK.sys

2011/07/09 11:33:45.0179 8304 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\windows\system32\drivers\MSPQM.sys

2011/07/09 11:33:45.0276 8304 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\windows\system32\drivers\MsRPC.sys

2011/07/09 11:33:45.0382 8304 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\windows\system32\DRIVERS\mssmbios.sys

2011/07/09 11:33:45.0477 8304 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\windows\system32\drivers\MSTEE.sys

2011/07/09 11:33:45.0556 8304 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\windows\system32\DRIVERS\MTConfig.sys

2011/07/09 11:33:45.0633 8304 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\windows\system32\Drivers\mup.sys

2011/07/09 11:33:45.0735 8304 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\windows\system32\DRIVERS\nwifi.sys

2011/07/09 11:33:45.0870 8304 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\windows\system32\drivers\ndis.sys

2011/07/09 11:33:45.0984 8304 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\windows\system32\DRIVERS\ndiscap.sys

2011/07/09 11:33:46.0082 8304 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\windows\system32\DRIVERS\ndistapi.sys

2011/07/09 11:33:46.0159 8304 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\windows\system32\DRIVERS\ndisuio.sys

2011/07/09 11:33:46.0226 8304 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\windows\system32\DRIVERS\ndiswan.sys

2011/07/09 11:33:46.0310 8304 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\windows\system32\drivers\NDProxy.sys

2011/07/09 11:33:46.0416 8304 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\windows\system32\DRIVERS\netbios.sys

2011/07/09 11:33:46.0515 8304 NetBT (9162b273a44ab9dce5b44362731d062a) C:\windows\system32\DRIVERS\netbt.sys

2011/07/09 11:33:46.0647 8304 nfrd960 (77889813be4d166cdab78ddba990da92) C:\windows\system32\DRIVERS\nfrd960.sys

2011/07/09 11:33:46.0756 8304 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\windows\system32\drivers\Npfs.sys

2011/07/09 11:33:46.0860 8304 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\windows\system32\drivers\nsiproxy.sys

2011/07/09 11:33:46.0992 8304 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\windows\system32\drivers\Ntfs.sys

2011/07/09 11:33:47.0097 8304 Null (9899284589f75fa8724ff3d16aed75c1) C:\windows\system32\drivers\Null.sys

2011/07/09 11:33:47.0221 8304 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\windows\system32\drivers\nvraid.sys

2011/07/09 11:33:47.0340 8304 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\windows\system32\drivers\nvstor.sys

2011/07/09 11:33:47.0452 8304 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\windows\system32\DRIVERS\nv_agp.sys

2011/07/09 11:33:47.0548 8304 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\windows\system32\DRIVERS\ohci1394.sys

2011/07/09 11:33:47.0672 8304 Parport (0086431c29c35be1dbc43f52cc273887) C:\windows\system32\DRIVERS\parport.sys

2011/07/09 11:33:47.0764 8304 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\windows\system32\drivers\partmgr.sys

2011/07/09 11:33:47.0869 8304 pci (5aab2b170536885de70a6cba8d7ce52b) C:\windows\system32\DRIVERS\pci.sys

2011/07/09 11:33:47.0951 8304 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\windows\system32\DRIVERS\pciide.sys

2011/07/09 11:33:48.0030 8304 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\windows\system32\DRIVERS\pcmcia.sys

2011/07/09 11:33:48.0126 8304 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\windows\system32\drivers\pcw.sys

2011/07/09 11:33:48.0219 8304 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\windows\system32\drivers\peauth.sys

2011/07/09 11:33:48.0357 8304 PGEffect (663962900e7fea522126ba287715bb4a) C:\windows\system32\DRIVERS\pgeffect.sys

2011/07/09 11:33:48.0458 8304 Point64 (b8d8ec78b0f9ed8e220506181274f3d3) C:\windows\system32\DRIVERS\point64.sys

2011/07/09 11:33:48.0573 8304 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\windows\system32\DRIVERS\raspptp.sys

2011/07/09 11:33:48.0668 8304 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\windows\system32\DRIVERS\processr.sys

2011/07/09 11:33:48.0792 8304 Psched (ee992183bd8eaefd9973f352e587a299) C:\windows\system32\DRIVERS\pacer.sys

2011/07/09 11:33:48.0939 8304 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\windows\system32\DRIVERS\ql2300.sys

2011/07/09 11:33:49.0066 8304 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\windows\system32\DRIVERS\ql40xx.sys

2011/07/09 11:33:49.0173 8304 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\windows\system32\drivers\qwavedrv.sys

2011/07/09 11:33:49.0271 8304 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\windows\system32\DRIVERS\rasacd.sys

2011/07/09 11:33:49.0367 8304 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\windows\system32\DRIVERS\AgileVpn.sys

2011/07/09 11:33:49.0457 8304 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\windows\system32\DRIVERS\rasl2tp.sys

2011/07/09 11:33:49.0544 8304 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\windows\system32\DRIVERS\raspppoe.sys

2011/07/09 11:33:49.0639 8304 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\windows\system32\DRIVERS\rassstp.sys

2011/07/09 11:33:49.0746 8304 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\windows\system32\DRIVERS\rdbss.sys

2011/07/09 11:33:49.0841 8304 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\windows\system32\DRIVERS\rdpbus.sys

2011/07/09 11:33:49.0935 8304 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\windows\system32\DRIVERS\RDPCDD.sys

2011/07/09 11:33:50.0050 8304 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\windows\system32\drivers\rdpencdd.sys

2011/07/09 11:33:50.0147 8304 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\windows\system32\drivers\rdprefmp.sys

2011/07/09 11:33:50.0246 8304 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\windows\system32\drivers\RDPWD.sys

2011/07/09 11:33:50.0801 8304 rdyboost (e5dc9ba9e439d6dbdd79f8caacb5bf01) C:\windows\system32\drivers\rdyboost.sys

2011/07/09 11:33:51.0024 8304 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\windows\system32\DRIVERS\rspndr.sys

2011/07/09 11:33:51.0135 8304 RTL8167 (7ea8d2eb9bbfd2ab8a3117a1e96d3b3a) C:\windows\system32\DRIVERS\Rt64win7.sys

2011/07/09 11:33:51.0258 8304 rtl8192se (7475548b0ba58eba4d12414fc9e9dfe6) C:\windows\system32\DRIVERS\rtl8192se.sys

2011/07/09 11:33:51.0365 8304 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\windows\system32\DRIVERS\sbp2port.sys

2011/07/09 11:33:51.0459 8304 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\windows\system32\DRIVERS\scfilter.sys

2011/07/09 11:33:51.0583 8304 sdbus (2c8d162efaf73abd36d8bcbb6340cae7) C:\windows\system32\DRIVERS\sdbus.sys

2011/07/09 11:33:51.0698 8304 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\windows\system32\drivers\secdrv.sys

2011/07/09 11:33:51.0806 8304 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\windows\system32\DRIVERS\serenum.sys

2011/07/09 11:33:51.0908 8304 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\windows\system32\DRIVERS\serial.sys

2011/07/09 11:33:52.0019 8304 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\windows\system32\DRIVERS\sermouse.sys

2011/07/09 11:33:52.0153 8304 sffdisk (a554811bcd09279536440c964ae35bbf) C:\windows\system32\DRIVERS\sffdisk.sys

2011/07/09 11:33:52.0231 8304 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\windows\system32\DRIVERS\sffp_mmc.sys

2011/07/09 11:33:52.0309 8304 sffp_sd (178298f767fe638c9fedcbdef58bb5e4) C:\windows\system32\DRIVERS\sffp_sd.sys

2011/07/09 11:33:52.0387 8304 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\windows\system32\DRIVERS\sfloppy.sys

2011/07/09 11:33:52.0977 8304 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\windows\system32\DRIVERS\SiSRaid2.sys

2011/07/09 11:33:53.0059 8304 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\windows\system32\DRIVERS\sisraid4.sys

2011/07/09 11:33:53.0161 8304 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\windows\system32\DRIVERS\smb.sys

2011/07/09 11:33:53.0293 8304 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\windows\system32\drivers\spldr.sys

2011/07/09 11:33:53.0431 8304 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\windows\system32\DRIVERS\srv.sys

2011/07/09 11:33:53.0556 8304 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\windows\system32\DRIVERS\srv2.sys

2011/07/09 11:33:53.0665 8304 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\windows\system32\DRIVERS\srvnet.sys

2011/07/09 11:33:53.0769 8304 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\windows\system32\DRIVERS\stexstor.sys

2011/07/09 11:33:53.0883 8304 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\windows\system32\DRIVERS\swenum.sys

2011/07/09 11:33:54.0036 8304 SynTP (470c47daba9ca3966f0ab3f835d7d135) C:\windows\system32\DRIVERS\SynTP.sys

2011/07/09 11:33:54.0223 8304 Tcpip (61dc720bb065d607d5823f13d2a64321) C:\windows\system32\drivers\tcpip.sys

2011/07/09 11:33:54.0451 8304 TCPIP6 (61dc720bb065d607d5823f13d2a64321) C:\windows\system32\DRIVERS\tcpip.sys

2011/07/09 11:33:54.0573 8304 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\windows\system32\drivers\tcpipreg.sys

2011/07/09 11:33:54.0669 8304 tdcmdpst (fd542b661bd22fa69ca789ad0ac58c29) C:\windows\system32\DRIVERS\tdcmdpst.sys

2011/07/09 11:33:54.0759 8304 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\windows\system32\drivers\tdpipe.sys

2011/07/09 11:33:54.0848 8304 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\windows\system32\drivers\tdtcp.sys

2011/07/09 11:33:54.0949 8304 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\windows\system32\DRIVERS\tdx.sys

2011/07/09 11:33:55.0074 8304 TermDD (c448651339196c0e869a355171875522) C:\windows\system32\DRIVERS\termdd.sys

2011/07/09 11:33:55.0193 8304 Thpdrv (c013f6acaa9761f571bd28dada7c157d) C:\windows\system32\DRIVERS\thpdrv.sys

2011/07/09 11:33:55.0291 8304 Thpevm (b4e609047434ed948af7bdef2fa66e38) C:\windows\system32\DRIVERS\Thpevm.SYS

2011/07/09 11:33:55.0483 8304 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\windows\system32\DRIVERS\tssecsrv.sys

2011/07/09 11:33:55.0568 8304 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\windows\system32\DRIVERS\tunnel.sys

2011/07/09 11:33:55.0659 8304 TVALZ (550b567f9364d8f7684c3fb3ea665a72) C:\windows\system32\DRIVERS\TVALZ_O.SYS

2011/07/09 11:33:55.0759 8304 TVALZFL (9c7191f4b2e49bff47a6c1144b5923fa) C:\windows\system32\DRIVERS\TVALZFL.sys

2011/07/09 11:33:55.0847 8304 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\windows\system32\DRIVERS\uagp35.sys

2011/07/09 11:33:55.0936 8304 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\windows\system32\DRIVERS\udfs.sys

2011/07/09 11:33:56.0065 8304 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\windows\system32\DRIVERS\uliagpkx.sys

2011/07/09 11:33:56.0163 8304 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\windows\system32\DRIVERS\umbus.sys

2011/07/09 11:33:56.0255 8304 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\windows\system32\DRIVERS\umpass.sys

2011/07/09 11:33:56.0351 8304 unihoocx (5d7be7f0e9ae0609f9dbc64631c189ce) C:\windows\system32\DRIVERS\unihoocx.sys

2011/07/09 11:33:56.0472 8304 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\windows\system32\Drivers\usbaapl64.sys

2011/07/09 11:33:56.0580 8304 usbccgp (537a4e03d7103c12d42dfd8ffdb5bdc9) C:\windows\system32\DRIVERS\usbccgp.sys

2011/07/09 11:33:56.0673 8304 usbcir (af0892a803fdda7492f595368e3b68e7) C:\windows\system32\DRIVERS\usbcir.sys

2011/07/09 11:33:56.0793 8304 usbehci (fbb21ebe49f6d560db37ac25fbc68e66) C:\windows\system32\drivers\usbehci.sys

2011/07/09 11:33:56.0904 8304 usbhub (6b7a8a99c4a459e73c286a6763ea24cc) C:\windows\system32\DRIVERS\usbhub.sys

2011/07/09 11:33:57.0028 8304 usbohci (8c88aa7617b4cbc2e4bed61d26b33a27) C:\windows\system32\drivers\usbohci.sys

2011/07/09 11:33:57.0113 8304 usbprint (73188f58fb384e75c4063d29413cee3d) C:\windows\system32\DRIVERS\usbprint.sys

2011/07/09 11:33:57.0220 8304 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\windows\system32\DRIVERS\USBSTOR.SYS

2011/07/09 11:33:57.0339 8304 usbuhci (0b5b3b2df3fd1709618acfa50b8392b0) C:\windows\system32\drivers\usbuhci.sys

2011/07/09 11:33:57.0437 8304 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\windows\System32\Drivers\usbvideo.sys

2011/07/09 11:33:57.0555 8304 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\windows\system32\DRIVERS\vdrvroot.sys

2011/07/09 11:33:57.0645 8304 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\windows\system32\DRIVERS\vgapnp.sys

2011/07/09 11:33:57.0724 8304 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\windows\System32\drivers\vga.sys

2011/07/09 11:33:57.0818 8304 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\windows\system32\DRIVERS\vhdmp.sys

2011/07/09 11:33:57.0916 8304 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\windows\system32\DRIVERS\viaide.sys

2011/07/09 11:33:58.0029 8304 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\windows\system32\DRIVERS\volmgr.sys

2011/07/09 11:33:58.0126 8304 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\windows\system32\drivers\volmgrx.sys

2011/07/09 11:33:58.0226 8304 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\windows\system32\DRIVERS\volsnap.sys

2011/07/09 11:33:58.0318 8304 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\windows\system32\DRIVERS\vsmraid.sys

2011/07/09 11:33:58.0441 8304 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\windows\system32\DRIVERS\vwifibus.sys

2011/07/09 11:33:58.0529 8304 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\windows\system32\DRIVERS\vwififlt.sys

2011/07/09 11:33:58.0640 8304 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\windows\system32\DRIVERS\wacompen.sys

2011/07/09 11:33:58.0746 8304 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\windows\system32\DRIVERS\wanarp.sys

2011/07/09 11:33:58.0774 8304 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\windows\system32\DRIVERS\wanarp.sys

2011/07/09 11:33:58.0909 8304 Wd (72889e16ff12ba0f235467d6091b17dc) C:\windows\system32\DRIVERS\wd.sys

2011/07/09 11:33:59.0017 8304 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\windows\system32\drivers\Wdf01000.sys

2011/07/09 11:33:59.0156 8304 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\windows\system32\DRIVERS\wfplwf.sys

2011/07/09 11:33:59.0251 8304 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\windows\system32\drivers\wimmount.sys

2011/07/09 11:33:59.0432 8304 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\windows\system32\DRIVERS\WinUsb.sys

2011/07/09 11:33:59.0552 8304 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\windows\system32\DRIVERS\wmiacpi.sys

2011/07/09 11:33:59.0665 8304 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\windows\system32\drivers\ws2ifsl.sys

2011/07/09 11:33:59.0788 8304 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\windows\system32\drivers\WudfPf.sys

2011/07/09 11:33:59.0886 8304 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\windows\system32\DRIVERS\WUDFRd.sys

2011/07/09 11:33:59.0970 8304 MBR (0x1B8) (5b5e648d12fcadc244c1ec30318e1eb9) \Device\Harddisk0\DR0

2011/07/09 11:34:00.0000 8304 Boot (0x1200) (46240bbcec9875540ca5acf38ae0ddc6) \Device\Harddisk0\DR0\Partition0

2011/07/09 11:34:00.0009 8304 ================================================================================

2011/07/09 11:34:00.0009 8304 Scan finished

2011/07/09 11:34:00.0009 8304 ================================================================================

2011/07/09 11:34:00.0027 8296 Detected object count: 0

2011/07/09 11:34:00.0027 8296 Actual detected object count: 0

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

ComboFix results...

ComboFix 11-07-05.03 - Shelby 07/08/2011 21:15:21.2.2 - x64

Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3891.2368 [GMT -5:00]

Running from: C:\Users\Shelby\Desktop\ComboFix.exe

Command switches used :: /killall

AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

C:\Users\Shelby\AppData\Local\Temp\424.tmp

---- Previous Run -------

C:\ProgramData\xp\EBLib.dll

C:\ProgramData\xp\TPwSav.sys

C:\Users\Shelby\AppData\Local\Microsoft\Windows\Temporary Internet Files\cookies.sqlite

((((((((((((((((((((((((( Files Created from 2011-06-09 to 2011-07-09 )))))))))))))))))))))))))))))))

2011-07-09 02:37:36 . 2011-07-09 02:37:36 -------- d-----w- C:\Users\Default\AppData\Local\temp

2011-07-08 20:14:46 . 2011-07-08 20:14:59 -------- d-----w- C:\Users\Shelby\AppData\Local\{51F7C797-8BCD-46C8-9B54-E5DA5533868F}

2011-07-08 18:32:49 . 2011-06-07 17:10:37 8873296 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{89565020-7924-4528-AACD-229C8ABB1CF3}\mpengine.dll

2011-07-07 20:49:31 . 2011-07-07 20:49:47 -------- d-----w- C:\Users\Shelby\AppData\Local\{BF74D0EF-6705-4EA9-AF20-3498EA3A85B6}

2011-07-06 21:25:19 . 2011-07-06 21:25:19 -------- d-----w- C:\Users\Shelby\AppData\Local\{54C5A50C-A33B-48F8-9B35-FC3809AF6685}

2011-07-05 22:23:35 . 2011-07-06 21:22:27 -------- d-----w- C:\Program Files (x86)\Xvid

2011-07-05 22:16:36 . 2011-07-09 02:41:04 -------- d-----w- C:\Users\Shelby\AppData\Roaming\WhiteSmoke

2011-07-05 22:16:28 . 2011-07-05 22:16:28 2106216 ----a-w- C:\Program Files (x86)\Mozilla Firefox\D3DCompiler_43.dll

2011-07-05 22:16:27 . 2011-07-05 22:16:28 1998168 ----a-w- C:\Program Files (x86)\Mozilla Firefox\d3dx9_43.dll

2011-07-05 22:16:09 . 2011-07-05 22:17:36 -------- d-----w- C:\Program Files (x86)\WhiteSmoke

2011-07-05 22:16:02 . 2011-07-05 22:16:03 -------- d-----w- C:\Program Files (x86)\WhiteSmoke Toolbar

2011-07-02 13:53:09 . 2011-07-02 13:53:21 -------- d-----w- C:\Users\Shelby\AppData\Local\{8895AE57-3A2C-4D4A-8530-66C1749031F6}

2011-06-28 03:42:15 . 2011-06-28 03:42:25 -------- d-----w- C:\Users\Shelby\AppData\Local\{80BEAA41-67AA-410C-91CC-25CEDFB29C45}

2011-06-27 21:37:53 . 2011-04-27 02:57:40 102400 ----a-w- C:\windows\system32\drivers\dfsc.sys

2011-06-27 21:37:51 . 2011-04-25 05:32:22 1896832 ----a-w- C:\windows\system32\drivers\tcpip.sys

2011-06-27 21:37:51 . 2011-04-25 02:44:02 499712 ----a-w- C:\windows\system32\drivers\afd.sys

2011-06-27 21:37:49 . 2011-04-29 05:47:12 1110528 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll

2011-06-27 21:37:49 . 2011-04-29 05:08:52 759296 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll

2011-06-27 21:37:42 . 2011-05-04 02:51:08 287744 ----a-w- C:\windows\system32\drivers\mrxsmb10.sys

2011-06-27 21:37:42 . 2011-05-04 02:51:05 126464 ----a-w- C:\windows\system32\drivers\mrxsmb20.sys

2011-06-27 21:37:41 . 2011-05-04 02:51:08 157696 ----a-w- C:\windows\system32\drivers\mrxsmb.sys

2011-06-27 21:37:39 . 2011-05-28 03:07:01 3133952 ----a-w- C:\windows\system32\win32k.sys

2011-06-27 21:35:06 . 2011-05-03 05:21:22 976896 ----a-w- C:\windows\system32\inetcomm.dll

2011-06-27 21:35:04 . 2011-05-03 04:50:29 740864 ----a-w- C:\windows\SysWow64\inetcomm.dll

2011-06-27 21:34:43 . 2011-04-29 03:12:54 399872 ----a-w- C:\windows\system32\drivers\srv2.sys

2011-06-27 21:34:37 . 2011-04-29 03:13:10 461312 ----a-w- C:\windows\system32\drivers\srv.sys

2011-06-27 21:34:36 . 2011-04-29 03:12:37 161792 ----a-w- C:\windows\system32\drivers\srvnet.sys

2011-06-27 21:34:18 . 2010-11-02 05:12:07 320512 ----a-w- C:\windows\system32\d3d10_1core.dll

2011-06-27 21:34:18 . 2010-11-02 04:35:34 218624 ----a-w- C:\windows\SysWow64\d3d10_1core.dll

2011-06-27 21:34:17 . 2011-01-17 06:17:00 197120 ----a-w- C:\windows\system32\d3d10_1.dll

2011-06-27 21:34:16 . 2011-01-17 05:38:38 161792 ----a-w- C:\windows\SysWow64\d3d10_1.dll

2011-06-27 21:34:05 . 2010-12-18 06:13:53 861184 ----a-w- C:\windows\system32\oleaut32.dll

2011-06-27 21:34:05 . 2010-12-18 05:31:23 571904 ----a-w- C:\windows\SysWow64\oleaut32.dll

2011-06-27 00:16:28 . 2011-06-27 15:35:56 -------- d-----w- C:\Users\Shelby\AppData\Local\{401713CA-699E-42E4-B825-C53C85182ABD}

2011-06-15 22:01:07 . 2011-06-15 22:01:07 -------- d-----w- C:\Program Files\iPod

2011-06-15 22:01:06 . 2011-06-15 22:01:37 -------- d-----w- C:\Program Files\iTunes

2011-06-15 22:01:06 . 2011-06-15 22:01:37 -------- d-----w- C:\Program Files (x86)\iTunes

2011-06-15 21:56:32 . 2011-06-16 22:39:21 -------- d-----w- C:\Users\Shelby\AppData\Local\{27F22EC6-5DDC-4519-AC82-B6C3AA406147}

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2011-07-04 11:43:53 . 2010-11-23 05:28:10 40112 ----a-w- C:\windows\avastSS.scr

2011-07-04 11:43:51 . 2010-11-23 05:28:10 199304 ----a-w- C:\windows\SysWow64\aswBoot.exe

2011-07-04 11:43:42 . 2011-05-30 13:26:06 253888 ----a-w- C:\windows\system32\aswBoot.exe

2011-07-04 11:36:56 . 2011-05-30 13:26:06 600920 ----a-w- C:\windows\system32\drivers\aswSnx.sys

2011-07-04 11:36:54 . 2010-11-23 05:28:20 288088 ----a-w- C:\windows\system32\drivers\aswSP.sys

2011-07-04 11:35:28 . 2010-11-23 05:28:20 45400 ----a-w- C:\windows\system32\drivers\aswTdi.sys

2011-07-04 11:32:35 . 2010-11-23 05:28:20 31064 ----a-w- C:\windows\system32\drivers\aswRdr.sys

2011-07-04 11:32:24 . 2010-11-23 05:28:19 64856 ----a-w- C:\windows\system32\drivers\aswMonFlt.sys

2011-07-04 11:32:14 . 2010-11-23 05:28:20 22360 ----a-w- C:\windows\system32\drivers\aswFsBlk.sys

2011-06-27 21:12:22 . 2011-05-21 23:28:05 404640 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl

2011-05-29 14:11:30 . 2010-12-11 05:52:16 39984 ----a-w- C:\windows\SysWow64\drivers\mbamswissarmy.sys

2011-05-29 14:11:20 . 2010-12-11 05:52:12 25912 ----a-w- C:\windows\system32\drivers\mbam.sys

2011-05-25 00:14:10 . 2010-11-23 05:29:12 270720 ------w- C:\windows\system32\MpSigStub.exe

2011-05-10 13:06:08 . 2011-05-10 13:06:08 51712 ----a-w- C:\windows\system32\drivers\usbaapl64.sys

2011-05-10 13:06:08 . 2011-05-10 13:06:08 4517664 ----a-w- C:\windows\system32\usbaaplrc.dll

2011-04-22 20:18:47 . 2011-05-25 00:26:35 27008 ----a-w- C:\windows\system32\drivers\Diskdump.sys

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{5981E3B7-0A86-42aa-AEA5-8BEBEBED5625}]

2011-05-20 16:51:20 349920 ----a-w- C:\Program Files (x86)\WhiteSmoke Toolbar\Toolbar32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]

"{A1B44986-221F-4e9f-95F9-47CD98AE6CEA}"= "C:\Program Files (x86)\WhiteSmoke Toolbar\Toolbar32.dll" [2011-05-20 16:51:20 349920]

[HKEY_CLASSES_ROOT\clsid\{a1b44986-221f-4e9f-95f9-47cd98ae6cea}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 07:54:18 4240760]

"swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-08-10 04:28:35 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"ToshibaAppPlace"="C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe" [2010-06-11 16:41:38 552960]

"SVPWUTIL"="C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2010-02-23 02:01:10 352256]

"HWSetup"="C:\Program Files\TOSHIBA\Utilities\HWSetup.exe" [2010-03-04 23:44:58 423936]

"KeNotify"="C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2009-12-25 22:21:16 34160]

"TWebCamera"="C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-24 08:54:48 2454840]

"ToshibaServiceStation"="C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 16:23:12 1294136]

"NortonOnlineBackupReminder"="C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe" [2010-06-03 01:51:46 3218792]

"BCSSync"="C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 20:54:26 91520]

"QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe" [2010-11-29 23:38:18 421888]

"iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" [2011-06-07 22:51:12 421160]

C:\Users\Shelby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Launch WhiteSmoke.lnk - C:\Program Files (x86)\WhiteSmoke\WSEnrichment.exe [2011-4-12 2162688]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 21:16:28 130384]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 22:27:14 138576]

R2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-08-10 04:28:43 136176]

R2 regi;regi;C:\windows\system32\drivers\regi.sys [x]

R3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 23:44:14 183560]

R3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-08-10 04:28:43 136176]

R3 JMCR;JMCR;C:\windows\system32\DRIVERS\jmcr.sys [x]

R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 03:34:24 4925184]

R3 Point64;Microsoft IntelliPoint Filter Driver;C:\windows\system32\DRIVERS\point64.sys [x]

R3 TMachInfo;TMachInfo;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 16:21:50 51512]

R3 USBAAPL64;Apple Mobile USB Driver;C:\windows\system32\Drivers\usbaapl64.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\system32\Wat\WatAdminSvc.exe [x]

Link to post
Share on other sites

Hi and :welcome:

I see you have also run combofix. Can you please post me the log you can find at c:\combofix.txt?

This infection often comes with a rootkit, so lets run also a rootkit scan.

Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!

  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • If TDSSKiller does not run, try renaming it.
  • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
  • Click the Start Scan button.
  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
  • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.

TDSSkiller contents:

2011/07/09 11:33:24.0273 9208 TDSS rootkit removing tool 2.5.9.0 Jul 1 2011 18:45:21

2011/07/09 11:33:26.0292 9208 ================================================================================

2011/07/09 11:33:26.0292 9208 SystemInfo:

2011/07/09 11:33:26.0292 9208

2011/07/09 11:33:26.0292 9208 OS Version: 6.1.7600 ServicePack: 0.0

2011/07/09 11:33:26.0292 9208 Product type: Workstation

2011/07/09 11:33:26.0292 9208 ComputerName: SHELBY-PC

2011/07/09 11:33:26.0292 9208 UserName: Shelby

2011/07/09 11:33:26.0292 9208 Windows directory: C:\windows

2011/07/09 11:33:26.0292 9208 System windows directory: C:\windows

2011/07/09 11:33:26.0292 9208 Running under WOW64

2011/07/09 11:33:26.0292 9208 Processor architecture: Intel x64

2011/07/09 11:33:26.0292 9208 Number of processors: 2

2011/07/09 11:33:26.0293 9208 Page size: 0x1000

2011/07/09 11:33:26.0293 9208 Boot type: Normal boot

2011/07/09 11:33:26.0293 9208 ================================================================================

2011/07/09 11:33:26.0586 9208 Initialize success

2011/07/09 11:33:30.0284 8304 ================================================================================

2011/07/09 11:33:30.0284 8304 Scan started

2011/07/09 11:33:30.0284 8304 Mode: Manual;

2011/07/09 11:33:30.0284 8304 ================================================================================

2011/07/09 11:33:30.0613 8304 1394ohci (969c91060cbb5d17cb8440b5f78b4c51) C:\windows\system32\DRIVERS\1394ohci.sys

2011/07/09 11:33:30.0732 8304 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\windows\system32\DRIVERS\ACPI.sys

2011/07/09 11:33:30.0839 8304 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\windows\system32\DRIVERS\acpipmi.sys

2011/07/09 11:33:30.0966 8304 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\windows\system32\DRIVERS\adp94xx.sys

2011/07/09 11:33:31.0083 8304 adpahci (597f78224ee9224ea1a13d6350ced962) C:\windows\system32\DRIVERS\adpahci.sys

2011/07/09 11:33:31.0197 8304 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\windows\system32\DRIVERS\adpu320.sys

2011/07/09 11:33:31.0360 8304 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\windows\system32\drivers\afd.sys

2011/07/09 11:33:31.0465 8304 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\windows\system32\DRIVERS\agp440.sys

2011/07/09 11:33:31.0576 8304 aliide (5812713a477a3ad7363c7438ca2ee038) C:\windows\system32\DRIVERS\aliide.sys

2011/07/09 11:33:31.0676 8304 amdide (1ff8b4431c353ce385c875f194924c0c) C:\windows\system32\DRIVERS\amdide.sys

2011/07/09 11:33:31.0781 8304 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\windows\system32\DRIVERS\amdk8.sys

2011/07/09 11:33:31.0868 8304 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\windows\system32\DRIVERS\amdppm.sys

2011/07/09 11:33:31.0980 8304 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\windows\system32\drivers\amdsata.sys

2011/07/09 11:33:32.0077 8304 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\windows\system32\DRIVERS\amdsbs.sys

2011/07/09 11:33:32.0195 8304 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\windows\system32\drivers\amdxata.sys

2011/07/09 11:33:32.0311 8304 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\windows\system32\drivers\appid.sys

2011/07/09 11:33:32.0454 8304 arc (c484f8ceb1717c540242531db7845c4e) C:\windows\system32\DRIVERS\arc.sys

2011/07/09 11:33:32.0563 8304 arcsas (019af6924aefe7839f61c830227fe79c) C:\windows\system32\DRIVERS\arcsas.sys

2011/07/09 11:33:32.0679 8304 aswFsBlk (55353cd0da287b2c3782485740965b54) C:\windows\system32\drivers\aswFsBlk.sys

2011/07/09 11:33:32.0815 8304 aswMonFlt (b38061cdefb71361e0c7547ac60527e8) C:\windows\system32\drivers\aswMonFlt.sys

2011/07/09 11:33:32.0911 8304 aswRdr (91e7aca95933633b2557f47cdfdb74c3) C:\windows\system32\drivers\aswRdr.sys

2011/07/09 11:33:33.0075 8304 aswSnx (2b15499f68fad60ce69264a327e9b0f0) C:\windows\system32\drivers\aswSnx.sys

2011/07/09 11:33:33.0172 8304 aswSP (4d939ecb19dc930056593390d1c87c43) C:\windows\system32\drivers\aswSP.sys

2011/07/09 11:33:33.0277 8304 aswTdi (d633426c5a207ce21767569aa4946891) C:\windows\system32\drivers\aswTdi.sys

2011/07/09 11:33:33.0362 8304 AsyncMac (769765ce2cc62867468cea93969b2242) C:\windows\system32\DRIVERS\asyncmac.sys

2011/07/09 11:33:33.0461 8304 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\windows\system32\DRIVERS\atapi.sys

2011/07/09 11:33:33.0599 8304 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\windows\system32\DRIVERS\bxvbda.sys

2011/07/09 11:33:33.0703 8304 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\windows\system32\DRIVERS\b57nd60a.sys

2011/07/09 11:33:33.0832 8304 Beep (16a47ce2decc9b099349a5f840654746) C:\windows\system32\drivers\Beep.sys

2011/07/09 11:33:33.0952 8304 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\windows\system32\DRIVERS\blbdrive.sys

2011/07/09 11:33:34.0105 8304 bowser (19d20159708e152267e53b66677a4995) C:\windows\system32\DRIVERS\bowser.sys

2011/07/09 11:33:34.0206 8304 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\windows\system32\DRIVERS\BrFiltLo.sys

2011/07/09 11:33:34.0317 8304 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\windows\system32\DRIVERS\BrFiltUp.sys

2011/07/09 11:33:34.0414 8304 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\windows\System32\Drivers\Brserid.sys

2011/07/09 11:33:34.0505 8304 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\windows\System32\Drivers\BrSerWdm.sys

2011/07/09 11:33:34.0605 8304 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\windows\System32\Drivers\BrUsbMdm.sys

2011/07/09 11:33:34.0683 8304 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\windows\System32\Drivers\BrUsbSer.sys

2011/07/09 11:33:34.0785 8304 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\windows\system32\DRIVERS\bthmodem.sys

2011/07/09 11:33:34.0973 8304 cdfs (b8bd2bb284668c84865658c77574381a) C:\windows\system32\DRIVERS\cdfs.sys

2011/07/09 11:33:35.0053 8304 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\windows\system32\DRIVERS\cdrom.sys

2011/07/09 11:33:35.0180 8304 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\windows\system32\DRIVERS\circlass.sys

2011/07/09 11:33:35.0278 8304 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\windows\system32\CLFS.sys

2011/07/09 11:33:35.0405 8304 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\windows\system32\DRIVERS\CmBatt.sys

2011/07/09 11:33:35.0494 8304 cmdide (e19d3f095812725d88f9001985b94edd) C:\windows\system32\DRIVERS\cmdide.sys

2011/07/09 11:33:35.0609 8304 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\windows\system32\Drivers\cng.sys

2011/07/09 11:33:35.0701 8304 Compbatt (102de219c3f61415f964c88e9085ad14) C:\windows\system32\DRIVERS\compbatt.sys

2011/07/09 11:33:35.0799 8304 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\windows\system32\DRIVERS\CompositeBus.sys

2011/07/09 11:33:35.0907 8304 crcdisk (1c827878a998c18847245fe1f34ee597) C:\windows\system32\DRIVERS\crcdisk.sys

2011/07/09 11:33:36.0072 8304 DfsC (9c253ce7311ca60fc11c774692a13208) C:\windows\system32\Drivers\dfsc.sys

2011/07/09 11:33:36.0172 8304 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\windows\system32\drivers\discache.sys

2011/07/09 11:33:36.0271 8304 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\windows\system32\DRIVERS\disk.sys

2011/07/09 11:33:36.0402 8304 drmkaud (9b19f34400d24df84c858a421c205754) C:\windows\system32\drivers\drmkaud.sys

2011/07/09 11:33:36.0531 8304 DXGKrnl (ebce0b0924835f635f620d19f0529dce) C:\windows\System32\drivers\dxgkrnl.sys

2011/07/09 11:33:36.0706 8304 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\windows\system32\DRIVERS\evbda.sys

2011/07/09 11:33:36.0888 8304 elxstor (0e5da5369a0fcaea12456dd852545184) C:\windows\system32\DRIVERS\elxstor.sys

2011/07/09 11:33:36.0979 8304 ErrDev (34a3c54752046e79a126e15c51db409b) C:\windows\system32\DRIVERS\errdev.sys

2011/07/09 11:33:37.0100 8304 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\windows\system32\drivers\exfat.sys

2011/07/09 11:33:37.0181 8304 fastfat (0adc83218b66a6db380c330836f3e36d) C:\windows\system32\drivers\fastfat.sys

2011/07/09 11:33:37.0280 8304 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\windows\system32\DRIVERS\fdc.sys

2011/07/09 11:33:37.0397 8304 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\windows\system32\drivers\fileinfo.sys

2011/07/09 11:33:37.0471 8304 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\windows\system32\drivers\filetrace.sys

2011/07/09 11:33:37.0538 8304 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\windows\system32\DRIVERS\flpydisk.sys

2011/07/09 11:33:37.0647 8304 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\windows\system32\drivers\fltmgr.sys

2011/07/09 11:33:37.0759 8304 FsDepends (d43703496149971890703b4b1b723eac) C:\windows\system32\drivers\FsDepends.sys

2011/07/09 11:33:37.0857 8304 fssfltr (6c06701bf1db05405804d7eb610991ce) C:\windows\system32\DRIVERS\fssfltr.sys

2011/07/09 11:33:37.0954 8304 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\windows\system32\drivers\Fs_Rec.sys

2011/07/09 11:33:38.0060 8304 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\windows\system32\DRIVERS\fvevol.sys

2011/07/09 11:33:38.0158 8304 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\windows\system32\DRIVERS\gagp30kx.sys

2011/07/09 11:33:38.0284 8304 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\windows\system32\DRIVERS\GEARAspiWDM.sys

2011/07/09 11:33:38.0456 8304 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\windows\system32\drivers\hcw85cir.sys

2011/07/09 11:33:38.0570 8304 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\windows\system32\drivers\HdAudio.sys

2011/07/09 11:33:38.0684 8304 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\windows\system32\DRIVERS\HDAudBus.sys

2011/07/09 11:33:38.0780 8304 HECIx64 (b6ac71aaa2b10848f57fc49d55a651af) C:\windows\system32\DRIVERS\HECIx64.sys

2011/07/09 11:33:38.0867 8304 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\windows\system32\DRIVERS\HidBatt.sys

2011/07/09 11:33:38.0948 8304 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\windows\system32\DRIVERS\hidbth.sys

2011/07/09 11:33:39.0039 8304 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\windows\system32\DRIVERS\hidir.sys

2011/07/09 11:33:39.0157 8304 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\windows\system32\DRIVERS\hidusb.sys

2011/07/09 11:33:39.0264 8304 HpSAMD (0886d440058f203eba0e1825e4355914) C:\windows\system32\DRIVERS\HpSAMD.sys

2011/07/09 11:33:39.0385 8304 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\windows\system32\drivers\HTTP.sys

2011/07/09 11:33:39.0480 8304 hwpolicy (f17766a19145f111856378df337a5d79) C:\windows\system32\drivers\hwpolicy.sys

2011/07/09 11:33:39.0579 8304 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\windows\system32\DRIVERS\i8042prt.sys

2011/07/09 11:33:39.0688 8304 iaStor (85977cd13fc16069ce0af7943a811775) C:\windows\system32\DRIVERS\iaStor.sys

2011/07/09 11:33:39.0821 8304 iaStorV (b75e45c564e944a2657167d197ab29da) C:\windows\system32\drivers\iaStorV.sys

2011/07/09 11:33:40.0175 8304 igfx (2a22ab054f4630d2ef4bab2853f6d5f6) C:\windows\system32\DRIVERS\igdkmd64.sys

2011/07/09 11:33:40.0497 8304 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\windows\system32\DRIVERS\iirsp.sys

2011/07/09 11:33:40.0607 8304 Impcd (dd587a55390ed2295bce6d36ad567da9) C:\windows\system32\DRIVERS\Impcd.sys

2011/07/09 11:33:40.0779 8304 IntcAzAudAddService (a73cc9bd3a7236e686be6667f0106c16) C:\windows\system32\drivers\RTKVHD64.sys

2011/07/09 11:33:40.0894 8304 IntcDAud (58cf58dee26c909bd6f977b61d246295) C:\windows\system32\DRIVERS\IntcDAud.sys

2011/07/09 11:33:40.0986 8304 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\windows\system32\DRIVERS\intelide.sys

2011/07/09 11:33:41.0090 8304 intelppm (ada036632c664caa754079041cf1f8c1) C:\windows\system32\DRIVERS\intelppm.sys

2011/07/09 11:33:41.0189 8304 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\windows\system32\DRIVERS\ipfltdrv.sys

2011/07/09 11:33:41.0290 8304 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\windows\system32\DRIVERS\IPMIDrv.sys

2011/07/09 11:33:41.0380 8304 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\windows\system32\drivers\ipnat.sys

2011/07/09 11:33:41.0501 8304 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\windows\system32\drivers\irenum.sys

2011/07/09 11:33:41.0603 8304 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\windows\system32\DRIVERS\isapnp.sys

2011/07/09 11:33:41.0692 8304 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\windows\system32\DRIVERS\msiscsi.sys

2011/07/09 11:33:41.0839 8304 JMCR (3a7d9638a50b45d1e20b9911961ab97c) C:\windows\system32\DRIVERS\jmcr.sys

2011/07/09 11:33:41.0938 8304 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\windows\system32\DRIVERS\kbdclass.sys

2011/07/09 11:33:42.0018 8304 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\windows\system32\DRIVERS\kbdhid.sys

2011/07/09 11:33:42.0115 8304 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\windows\system32\Drivers\ksecdd.sys

2011/07/09 11:33:42.0202 8304 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\windows\system32\Drivers\ksecpkg.sys

2011/07/09 11:33:42.0297 8304 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\windows\system32\drivers\ksthunk.sys

2011/07/09 11:33:42.0433 8304 lltdio (1538831cf8ad2979a04c423779465827) C:\windows\system32\DRIVERS\lltdio.sys

2011/07/09 11:33:42.0570 8304 LPCFilter (41e122f6d1448c94cc05196bc41d6bfb) C:\windows\system32\DRIVERS\LPCFilter.sys

2011/07/09 11:33:42.0677 8304 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\windows\system32\DRIVERS\lsi_fc.sys

2011/07/09 11:33:42.0780 8304 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\windows\system32\DRIVERS\lsi_sas.sys

2011/07/09 11:33:42.0881 8304 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\windows\system32\DRIVERS\lsi_sas2.sys

2011/07/09 11:33:42.0994 8304 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\windows\system32\DRIVERS\lsi_scsi.sys

2011/07/09 11:33:43.0103 8304 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\windows\system32\drivers\luafv.sys

2011/07/09 11:33:43.0199 8304 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\windows\system32\DRIVERS\megasas.sys

2011/07/09 11:33:43.0292 8304 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\windows\system32\DRIVERS\MegaSR.sys

2011/07/09 11:33:43.0386 8304 Modem (800ba92f7010378b09f9ed9270f07137) C:\windows\system32\drivers\modem.sys

2011/07/09 11:33:43.0472 8304 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\windows\system32\DRIVERS\monitor.sys

2011/07/09 11:33:43.0572 8304 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\windows\system32\DRIVERS\mouclass.sys

2011/07/09 11:33:43.0678 8304 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\windows\system32\DRIVERS\mouhid.sys

2011/07/09 11:33:43.0782 8304 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\windows\system32\drivers\mountmgr.sys

2011/07/09 11:33:43.0860 8304 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\windows\system32\DRIVERS\mpio.sys

2011/07/09 11:33:43.0960 8304 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\windows\system32\drivers\mpsdrv.sys

2011/07/09 11:33:44.0062 8304 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\windows\system32\drivers\mrxdav.sys

2011/07/09 11:33:44.0184 8304 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\windows\system32\DRIVERS\mrxsmb.sys

2011/07/09 11:33:44.0286 8304 mrxsmb10 (a8c2d7673c8a010569390c826a0efaf4) C:\windows\system32\DRIVERS\mrxsmb10.sys

2011/07/09 11:33:44.0398 8304 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\windows\system32\DRIVERS\mrxsmb20.sys

2011/07/09 11:33:44.0503 8304 msahci (5c37497276e3b3a5488b23a326a754b7) C:\windows\system32\DRIVERS\msahci.sys

2011/07/09 11:33:44.0583 8304 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\windows\system32\DRIVERS\msdsm.sys

2011/07/09 11:33:44.0700 8304 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\windows\system32\drivers\Msfs.sys

2011/07/09 11:33:44.0773 8304 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\windows\System32\drivers\mshidkmdf.sys

2011/07/09 11:33:44.0852 8304 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\windows\system32\DRIVERS\msisadrv.sys

2011/07/09 11:33:44.0967 8304 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\windows\system32\drivers\MSKSSRV.sys

2011/07/09 11:33:45.0067 8304 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\windows\system32\drivers\MSPCLOCK.sys

2011/07/09 11:33:45.0179 8304 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\windows\system32\drivers\MSPQM.sys

2011/07/09 11:33:45.0276 8304 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\windows\system32\drivers\MsRPC.sys

2011/07/09 11:33:45.0382 8304 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\windows\system32\DRIVERS\mssmbios.sys

2011/07/09 11:33:45.0477 8304 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\windows\system32\drivers\MSTEE.sys

2011/07/09 11:33:45.0556 8304 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\windows\system32\DRIVERS\MTConfig.sys

2011/07/09 11:33:45.0633 8304 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\windows\system32\Drivers\mup.sys

2011/07/09 11:33:45.0735 8304 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\windows\system32\DRIVERS\nwifi.sys

2011/07/09 11:33:45.0870 8304 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\windows\system32\drivers\ndis.sys

2011/07/09 11:33:45.0984 8304 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\windows\system32\DRIVERS\ndiscap.sys

2011/07/09 11:33:46.0082 8304 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\windows\system32\DRIVERS\ndistapi.sys

2011/07/09 11:33:46.0159 8304 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\windows\system32\DRIVERS\ndisuio.sys

2011/07/09 11:33:46.0226 8304 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\windows\system32\DRIVERS\ndiswan.sys

2011/07/09 11:33:46.0310 8304 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\windows\system32\drivers\NDProxy.sys

2011/07/09 11:33:46.0416 8304 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\windows\system32\DRIVERS\netbios.sys

2011/07/09 11:33:46.0515 8304 NetBT (9162b273a44ab9dce5b44362731d062a) C:\windows\system32\DRIVERS\netbt.sys

2011/07/09 11:33:46.0647 8304 nfrd960 (77889813be4d166cdab78ddba990da92) C:\windows\system32\DRIVERS\nfrd960.sys

2011/07/09 11:33:46.0756 8304 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\windows\system32\drivers\Npfs.sys

2011/07/09 11:33:46.0860 8304 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\windows\system32\drivers\nsiproxy.sys

2011/07/09 11:33:46.0992 8304 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\windows\system32\drivers\Ntfs.sys

2011/07/09 11:33:47.0097 8304 Null (9899284589f75fa8724ff3d16aed75c1) C:\windows\system32\drivers\Null.sys

2011/07/09 11:33:47.0221 8304 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\windows\system32\drivers\nvraid.sys

2011/07/09 11:33:47.0340 8304 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\windows\system32\drivers\nvstor.sys

2011/07/09 11:33:47.0452 8304 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\windows\system32\DRIVERS\nv_agp.sys

2011/07/09 11:33:47.0548 8304 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\windows\system32\DRIVERS\ohci1394.sys

2011/07/09 11:33:47.0672 8304 Parport (0086431c29c35be1dbc43f52cc273887) C:\windows\system32\DRIVERS\parport.sys

2011/07/09 11:33:47.0764 8304 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\windows\system32\drivers\partmgr.sys

2011/07/09 11:33:47.0869 8304 pci (5aab2b170536885de70a6cba8d7ce52b) C:\windows\system32\DRIVERS\pci.sys

2011/07/09 11:33:47.0951 8304 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\windows\system32\DRIVERS\pciide.sys

2011/07/09 11:33:48.0030 8304 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\windows\system32\DRIVERS\pcmcia.sys

2011/07/09 11:33:48.0126 8304 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\windows\system32\drivers\pcw.sys

2011/07/09 11:33:48.0219 8304 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\windows\system32\drivers\peauth.sys

2011/07/09 11:33:48.0357 8304 PGEffect (663962900e7fea522126ba287715bb4a) C:\windows\system32\DRIVERS\pgeffect.sys

2011/07/09 11:33:48.0458 8304 Point64 (b8d8ec78b0f9ed8e220506181274f3d3) C:\windows\system32\DRIVERS\point64.sys

2011/07/09 11:33:48.0573 8304 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\windows\system32\DRIVERS\raspptp.sys

2011/07/09 11:33:48.0668 8304 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\windows\system32\DRIVERS\processr.sys

2011/07/09 11:33:48.0792 8304 Psched (ee992183bd8eaefd9973f352e587a299) C:\windows\system32\DRIVERS\pacer.sys

2011/07/09 11:33:48.0939 8304 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\windows\system32\DRIVERS\ql2300.sys

2011/07/09 11:33:49.0066 8304 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\windows\system32\DRIVERS\ql40xx.sys

2011/07/09 11:33:49.0173 8304 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\windows\system32\drivers\qwavedrv.sys

2011/07/09 11:33:49.0271 8304 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\windows\system32\DRIVERS\rasacd.sys

2011/07/09 11:33:49.0367 8304 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\windows\system32\DRIVERS\AgileVpn.sys

2011/07/09 11:33:49.0457 8304 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\windows\system32\DRIVERS\rasl2tp.sys

2011/07/09 11:33:49.0544 8304 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\windows\system32\DRIVERS\raspppoe.sys

2011/07/09 11:33:49.0639 8304 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\windows\system32\DRIVERS\rassstp.sys

2011/07/09 11:33:49.0746 8304 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\windows\system32\DRIVERS\rdbss.sys

2011/07/09 11:33:49.0841 8304 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\windows\system32\DRIVERS\rdpbus.sys

2011/07/09 11:33:49.0935 8304 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\windows\system32\DRIVERS\RDPCDD.sys

2011/07/09 11:33:50.0050 8304 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\windows\system32\drivers\rdpencdd.sys

2011/07/09 11:33:50.0147 8304 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\windows\system32\drivers\rdprefmp.sys

2011/07/09 11:33:50.0246 8304 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\windows\system32\drivers\RDPWD.sys

2011/07/09 11:33:50.0801 8304 rdyboost (e5dc9ba9e439d6dbdd79f8caacb5bf01) C:\windows\system32\drivers\rdyboost.sys

2011/07/09 11:33:51.0024 8304 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\windows\system32\DRIVERS\rspndr.sys

2011/07/09 11:33:51.0135 8304 RTL8167 (7ea8d2eb9bbfd2ab8a3117a1e96d3b3a) C:\windows\system32\DRIVERS\Rt64win7.sys

2011/07/09 11:33:51.0258 8304 rtl8192se (7475548b0ba58eba4d12414fc9e9dfe6) C:\windows\system32\DRIVERS\rtl8192se.sys

2011/07/09 11:33:51.0365 8304 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\windows\system32\DRIVERS\sbp2port.sys

2011/07/09 11:33:51.0459 8304 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\windows\system32\DRIVERS\scfilter.sys

2011/07/09 11:33:51.0583 8304 sdbus (2c8d162efaf73abd36d8bcbb6340cae7) C:\windows\system32\DRIVERS\sdbus.sys

2011/07/09 11:33:51.0698 8304 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\windows\system32\drivers\secdrv.sys

2011/07/09 11:33:51.0806 8304 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\windows\system32\DRIVERS\serenum.sys

2011/07/09 11:33:51.0908 8304 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\windows\system32\DRIVERS\serial.sys

2011/07/09 11:33:52.0019 8304 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\windows\system32\DRIVERS\sermouse.sys

2011/07/09 11:33:52.0153 8304 sffdisk (a554811bcd09279536440c964ae35bbf) C:\windows\system32\DRIVERS\sffdisk.sys

2011/07/09 11:33:52.0231 8304 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\windows\system32\DRIVERS\sffp_mmc.sys

2011/07/09 11:33:52.0309 8304 sffp_sd (178298f767fe638c9fedcbdef58bb5e4) C:\windows\system32\DRIVERS\sffp_sd.sys

2011/07/09 11:33:52.0387 8304 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\windows\system32\DRIVERS\sfloppy.sys

2011/07/09 11:33:52.0977 8304 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\windows\system32\DRIVERS\SiSRaid2.sys

2011/07/09 11:33:53.0059 8304 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\windows\system32\DRIVERS\sisraid4.sys

2011/07/09 11:33:53.0161 8304 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\windows\system32\DRIVERS\smb.sys

2011/07/09 11:33:53.0293 8304 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\windows\system32\drivers\spldr.sys

2011/07/09 11:33:53.0431 8304 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\windows\system32\DRIVERS\srv.sys

2011/07/09 11:33:53.0556 8304 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\windows\system32\DRIVERS\srv2.sys

2011/07/09 11:33:53.0665 8304 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\windows\system32\DRIVERS\srvnet.sys

2011/07/09 11:33:53.0769 8304 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\windows\system32\DRIVERS\stexstor.sys

2011/07/09 11:33:53.0883 8304 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\windows\system32\DRIVERS\swenum.sys

2011/07/09 11:33:54.0036 8304 SynTP (470c47daba9ca3966f0ab3f835d7d135) C:\windows\system32\DRIVERS\SynTP.sys

2011/07/09 11:33:54.0223 8304 Tcpip (61dc720bb065d607d5823f13d2a64321) C:\windows\system32\drivers\tcpip.sys

2011/07/09 11:33:54.0451 8304 TCPIP6 (61dc720bb065d607d5823f13d2a64321) C:\windows\system32\DRIVERS\tcpip.sys

2011/07/09 11:33:54.0573 8304 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\windows\system32\drivers\tcpipreg.sys

2011/07/09 11:33:54.0669 8304 tdcmdpst (fd542b661bd22fa69ca789ad0ac58c29) C:\windows\system32\DRIVERS\tdcmdpst.sys

2011/07/09 11:33:54.0759 8304 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\windows\system32\drivers\tdpipe.sys

2011/07/09 11:33:54.0848 8304 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\windows\system32\drivers\tdtcp.sys

2011/07/09 11:33:54.0949 8304 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\windows\system32\DRIVERS\tdx.sys

2011/07/09 11:33:55.0074 8304 TermDD (c448651339196c0e869a355171875522) C:\windows\system32\DRIVERS\termdd.sys

2011/07/09 11:33:55.0193 8304 Thpdrv (c013f6acaa9761f571bd28dada7c157d) C:\windows\system32\DRIVERS\thpdrv.sys

2011/07/09 11:33:55.0291 8304 Thpevm (b4e609047434ed948af7bdef2fa66e38) C:\windows\system32\DRIVERS\Thpevm.SYS

2011/07/09 11:33:55.0483 8304 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\windows\system32\DRIVERS\tssecsrv.sys

2011/07/09 11:33:55.0568 8304 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\windows\system32\DRIVERS\tunnel.sys

2011/07/09 11:33:55.0659 8304 TVALZ (550b567f9364d8f7684c3fb3ea665a72) C:\windows\system32\DRIVERS\TVALZ_O.SYS

2011/07/09 11:33:55.0759 8304 TVALZFL (9c7191f4b2e49bff47a6c1144b5923fa) C:\windows\system32\DRIVERS\TVALZFL.sys

2011/07/09 11:33:55.0847 8304 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\windows\system32\DRIVERS\uagp35.sys

2011/07/09 11:33:55.0936 8304 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\windows\system32\DRIVERS\udfs.sys

2011/07/09 11:33:56.0065 8304 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\windows\system32\DRIVERS\uliagpkx.sys

2011/07/09 11:33:56.0163 8304 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\windows\system32\DRIVERS\umbus.sys

2011/07/09 11:33:56.0255 8304 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\windows\system32\DRIVERS\umpass.sys

2011/07/09 11:33:56.0351 8304 unihoocx (5d7be7f0e9ae0609f9dbc64631c189ce) C:\windows\system32\DRIVERS\unihoocx.sys

2011/07/09 11:33:56.0472 8304 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\windows\system32\Drivers\usbaapl64.sys

2011/07/09 11:33:56.0580 8304 usbccgp (537a4e03d7103c12d42dfd8ffdb5bdc9) C:\windows\system32\DRIVERS\usbccgp.sys

2011/07/09 11:33:56.0673 8304 usbcir (af0892a803fdda7492f595368e3b68e7) C:\windows\system32\DRIVERS\usbcir.sys

2011/07/09 11:33:56.0793 8304 usbehci (fbb21ebe49f6d560db37ac25fbc68e66) C:\windows\system32\drivers\usbehci.sys

2011/07/09 11:33:56.0904 8304 usbhub (6b7a8a99c4a459e73c286a6763ea24cc) C:\windows\system32\DRIVERS\usbhub.sys

2011/07/09 11:33:57.0028 8304 usbohci (8c88aa7617b4cbc2e4bed61d26b33a27) C:\windows\system32\drivers\usbohci.sys

2011/07/09 11:33:57.0113 8304 usbprint (73188f58fb384e75c4063d29413cee3d) C:\windows\system32\DRIVERS\usbprint.sys

2011/07/09 11:33:57.0220 8304 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\windows\system32\DRIVERS\USBSTOR.SYS

2011/07/09 11:33:57.0339 8304 usbuhci (0b5b3b2df3fd1709618acfa50b8392b0) C:\windows\system32\drivers\usbuhci.sys

2011/07/09 11:33:57.0437 8304 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\windows\System32\Drivers\usbvideo.sys

2011/07/09 11:33:57.0555 8304 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\windows\system32\DRIVERS\vdrvroot.sys

2011/07/09 11:33:57.0645 8304 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\windows\system32\DRIVERS\vgapnp.sys

2011/07/09 11:33:57.0724 8304 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\windows\System32\drivers\vga.sys

2011/07/09 11:33:57.0818 8304 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\windows\system32\DRIVERS\vhdmp.sys

2011/07/09 11:33:57.0916 8304 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\windows\system32\DRIVERS\viaide.sys

2011/07/09 11:33:58.0029 8304 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\windows\system32\DRIVERS\volmgr.sys

2011/07/09 11:33:58.0126 8304 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\windows\system32\drivers\volmgrx.sys

2011/07/09 11:33:58.0226 8304 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\windows\system32\DRIVERS\volsnap.sys

2011/07/09 11:33:58.0318 8304 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\windows\system32\DRIVERS\vsmraid.sys

2011/07/09 11:33:58.0441 8304 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\windows\system32\DRIVERS\vwifibus.sys

2011/07/09 11:33:58.0529 8304 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\windows\system32\DRIVERS\vwififlt.sys

2011/07/09 11:33:58.0640 8304 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\windows\system32\DRIVERS\wacompen.sys

2011/07/09 11:33:58.0746 8304 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\windows\system32\DRIVERS\wanarp.sys

2011/07/09 11:33:58.0774 8304 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\windows\system32\DRIVERS\wanarp.sys

2011/07/09 11:33:58.0909 8304 Wd (72889e16ff12ba0f235467d6091b17dc) C:\windows\system32\DRIVERS\wd.sys

2011/07/09 11:33:59.0017 8304 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\windows\system32\drivers\Wdf01000.sys

2011/07/09 11:33:59.0156 8304 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\windows\system32\DRIVERS\wfplwf.sys

2011/07/09 11:33:59.0251 8304 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\windows\system32\drivers\wimmount.sys

2011/07/09 11:33:59.0432 8304 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\windows\system32\DRIVERS\WinUsb.sys

2011/07/09 11:33:59.0552 8304 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\windows\system32\DRIVERS\wmiacpi.sys

2011/07/09 11:33:59.0665 8304 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\windows\system32\drivers\ws2ifsl.sys

2011/07/09 11:33:59.0788 8304 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\windows\system32\drivers\WudfPf.sys

2011/07/09 11:33:59.0886 8304 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\windows\system32\DRIVERS\WUDFRd.sys

2011/07/09 11:33:59.0970 8304 MBR (0x1B8) (5b5e648d12fcadc244c1ec30318e1eb9) \Device\Harddisk0\DR0

2011/07/09 11:34:00.0000 8304 Boot (0x1200) (46240bbcec9875540ca5acf38ae0ddc6) \Device\Harddisk0\DR0\Partition0

2011/07/09 11:34:00.0009 8304 ================================================================================

2011/07/09 11:34:00.0009 8304 Scan finished

2011/07/09 11:34:00.0009 8304 ================================================================================

2011/07/09 11:34:00.0027 8296 Detected object count: 0

2011/07/09 11:34:00.0027 8296 Actual detected object count: 0

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

ComboFix results...

ComboFix 11-07-05.03 - Shelby 07/08/2011 21:15:21.2.2 - x64

Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3891.2368 [GMT -5:00]

Running from: C:\Users\Shelby\Desktop\ComboFix.exe

Command switches used :: /killall

AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

C:\Users\Shelby\AppData\Local\Temp\424.tmp

---- Previous Run -------

C:\ProgramData\xp\EBLib.dll

C:\ProgramData\xp\TPwSav.sys

C:\Users\Shelby\AppData\Local\Microsoft\Windows\Temporary Internet Files\cookies.sqlite

((((((((((((((((((((((((( Files Created from 2011-06-09 to 2011-07-09 )))))))))))))))))))))))))))))))

2011-07-09 02:37:36 . 2011-07-09 02:37:36 -------- d-----w- C:\Users\Default\AppData\Local\temp

2011-07-08 20:14:46 . 2011-07-08 20:14:59 -------- d-----w- C:\Users\Shelby\AppData\Local\{51F7C797-8BCD-46C8-9B54-E5DA5533868F}

2011-07-08 18:32:49 . 2011-06-07 17:10:37 8873296 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{89565020-7924-4528-AACD-229C8ABB1CF3}\mpengine.dll

2011-07-07 20:49:31 . 2011-07-07 20:49:47 -------- d-----w- C:\Users\Shelby\AppData\Local\{BF74D0EF-6705-4EA9-AF20-3498EA3A85B6}

2011-07-06 21:25:19 . 2011-07-06 21:25:19 -------- d-----w- C:\Users\Shelby\AppData\Local\{54C5A50C-A33B-48F8-9B35-FC3809AF6685}

2011-07-05 22:23:35 . 2011-07-06 21:22:27 -------- d-----w- C:\Program Files (x86)\Xvid

2011-07-05 22:16:36 . 2011-07-09 02:41:04 -------- d-----w- C:\Users\Shelby\AppData\Roaming\WhiteSmoke

2011-07-05 22:16:28 . 2011-07-05 22:16:28 2106216 ----a-w- C:\Program Files (x86)\Mozilla Firefox\D3DCompiler_43.dll

2011-07-05 22:16:27 . 2011-07-05 22:16:28 1998168 ----a-w- C:\Program Files (x86)\Mozilla Firefox\d3dx9_43.dll

2011-07-05 22:16:09 . 2011-07-05 22:17:36 -------- d-----w- C:\Program Files (x86)\WhiteSmoke

2011-07-05 22:16:02 . 2011-07-05 22:16:03 -------- d-----w- C:\Program Files (x86)\WhiteSmoke Toolbar

2011-07-02 13:53:09 . 2011-07-02 13:53:21 -------- d-----w- C:\Users\Shelby\AppData\Local\{8895AE57-3A2C-4D4A-8530-66C1749031F6}

2011-06-28 03:42:15 . 2011-06-28 03:42:25 -------- d-----w- C:\Users\Shelby\AppData\Local\{80BEAA41-67AA-410C-91CC-25CEDFB29C45}

2011-06-27 21:37:53 . 2011-04-27 02:57:40 102400 ----a-w- C:\windows\system32\drivers\dfsc.sys

2011-06-27 21:37:51 . 2011-04-25 05:32:22 1896832 ----a-w- C:\windows\system32\drivers\tcpip.sys

2011-06-27 21:37:51 . 2011-04-25 02:44:02 499712 ----a-w- C:\windows\system32\drivers\afd.sys

2011-06-27 21:37:49 . 2011-04-29 05:47:12 1110528 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll

2011-06-27 21:37:49 . 2011-04-29 05:08:52 759296 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll

2011-06-27 21:37:42 . 2011-05-04 02:51:08 287744 ----a-w- C:\windows\system32\drivers\mrxsmb10.sys

2011-06-27 21:37:42 . 2011-05-04 02:51:05 126464 ----a-w- C:\windows\system32\drivers\mrxsmb20.sys

2011-06-27 21:37:41 . 2011-05-04 02:51:08 157696 ----a-w- C:\windows\system32\drivers\mrxsmb.sys

2011-06-27 21:37:39 . 2011-05-28 03:07:01 3133952 ----a-w- C:\windows\system32\win32k.sys

2011-06-27 21:35:06 . 2011-05-03 05:21:22 976896 ----a-w- C:\windows\system32\inetcomm.dll

2011-06-27 21:35:04 . 2011-05-03 04:50:29 740864 ----a-w- C:\windows\SysWow64\inetcomm.dll

2011-06-27 21:34:43 . 2011-04-29 03:12:54 399872 ----a-w- C:\windows\system32\drivers\srv2.sys

2011-06-27 21:34:37 . 2011-04-29 03:13:10 461312 ----a-w- C:\windows\system32\drivers\srv.sys

2011-06-27 21:34:36 . 2011-04-29 03:12:37 161792 ----a-w- C:\windows\system32\drivers\srvnet.sys

2011-06-27 21:34:18 . 2010-11-02 05:12:07 320512 ----a-w- C:\windows\system32\d3d10_1core.dll

2011-06-27 21:34:18 . 2010-11-02 04:35:34 218624 ----a-w- C:\windows\SysWow64\d3d10_1core.dll

2011-06-27 21:34:17 . 2011-01-17 06:17:00 197120 ----a-w- C:\windows\system32\d3d10_1.dll

2011-06-27 21:34:16 . 2011-01-17 05:38:38 161792 ----a-w- C:\windows\SysWow64\d3d10_1.dll

2011-06-27 21:34:05 . 2010-12-18 06:13:53 861184 ----a-w- C:\windows\system32\oleaut32.dll

2011-06-27 21:34:05 . 2010-12-18 05:31:23 571904 ----a-w- C:\windows\SysWow64\oleaut32.dll

2011-06-27 00:16:28 . 2011-06-27 15:35:56 -------- d-----w- C:\Users\Shelby\AppData\Local\{401713CA-699E-42E4-B825-C53C85182ABD}

2011-06-15 22:01:07 . 2011-06-15 22:01:07 -------- d-----w- C:\Program Files\iPod

2011-06-15 22:01:06 . 2011-06-15 22:01:37 -------- d-----w- C:\Program Files\iTunes

2011-06-15 22:01:06 . 2011-06-15 22:01:37 -------- d-----w- C:\Program Files (x86)\iTunes

2011-06-15 21:56:32 . 2011-06-16 22:39:21 -------- d-----w- C:\Users\Shelby\AppData\Local\{27F22EC6-5DDC-4519-AC82-B6C3AA406147}

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2011-07-04 11:43:53 . 2010-11-23 05:28:10 40112 ----a-w- C:\windows\avastSS.scr

2011-07-04 11:43:51 . 2010-11-23 05:28:10 199304 ----a-w- C:\windows\SysWow64\aswBoot.exe

2011-07-04 11:43:42 . 2011-05-30 13:26:06 253888 ----a-w- C:\windows\system32\aswBoot.exe

2011-07-04 11:36:56 . 2011-05-30 13:26:06 600920 ----a-w- C:\windows\system32\drivers\aswSnx.sys

2011-07-04 11:36:54 . 2010-11-23 05:28:20 288088 ----a-w- C:\windows\system32\drivers\aswSP.sys

2011-07-04 11:35:28 . 2010-11-23 05:28:20 45400 ----a-w- C:\windows\system32\drivers\aswTdi.sys

2011-07-04 11:32:35 . 2010-11-23 05:28:20 31064 ----a-w- C:\windows\system32\drivers\aswRdr.sys

2011-07-04 11:32:24 . 2010-11-23 05:28:19 64856 ----a-w- C:\windows\system32\drivers\aswMonFlt.sys

2011-07-04 11:32:14 . 2010-11-23 05:28:20 22360 ----a-w- C:\windows\system32\drivers\aswFsBlk.sys

2011-06-27 21:12:22 . 2011-05-21 23:28:05 404640 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl

2011-05-29 14:11:30 . 2010-12-11 05:52:16 39984 ----a-w- C:\windows\SysWow64\drivers\mbamswissarmy.sys

2011-05-29 14:11:20 . 2010-12-11 05:52:12 25912 ----a-w- C:\windows\system32\drivers\mbam.sys

2011-05-25 00:14:10 . 2010-11-23 05:29:12 270720 ------w- C:\windows\system32\MpSigStub.exe

2011-05-10 13:06:08 . 2011-05-10 13:06:08 51712 ----a-w- C:\windows\system32\drivers\usbaapl64.sys

2011-05-10 13:06:08 . 2011-05-10 13:06:08 4517664 ----a-w- C:\windows\system32\usbaaplrc.dll

2011-04-22 20:18:47 . 2011-05-25 00:26:35 27008 ----a-w- C:\windows\system32\drivers\Diskdump.sys

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{5981E3B7-0A86-42aa-AEA5-8BEBEBED5625}]

2011-05-20 16:51:20 349920 ----a-w- C:\Program Files (x86)\WhiteSmoke Toolbar\Toolbar32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]

"{A1B44986-221F-4e9f-95F9-47CD98AE6CEA}"= "C:\Program Files (x86)\WhiteSmoke Toolbar\Toolbar32.dll" [2011-05-20 16:51:20 349920]

[HKEY_CLASSES_ROOT\clsid\{a1b44986-221f-4e9f-95f9-47cd98ae6cea}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 07:54:18 4240760]

"swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-08-10 04:28:35 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"ToshibaAppPlace"="C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe" [2010-06-11 16:41:38 552960]

"SVPWUTIL"="C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2010-02-23 02:01:10 352256]

"HWSetup"="C:\Program Files\TOSHIBA\Utilities\HWSetup.exe" [2010-03-04 23:44:58 423936]

"KeNotify"="C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2009-12-25 22:21:16 34160]

"TWebCamera"="C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-24 08:54:48 2454840]

"ToshibaServiceStation"="C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 16:23:12 1294136]

"NortonOnlineBackupReminder"="C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe" [2010-06-03 01:51:46 3218792]

"BCSSync"="C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 20:54:26 91520]

"QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe" [2010-11-29 23:38:18 421888]

"iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" [2011-06-07 22:51:12 421160]

C:\Users\Shelby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Launch WhiteSmoke.lnk - C:\Program Files (x86)\WhiteSmoke\WSEnrichment.exe [2011-4-12 2162688]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 21:16:28 130384]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 22:27:14 138576]

R2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-08-10 04:28:43 136176]

R2 regi;regi;C:\windows\system32\drivers\regi.sys [x]

R3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 23:44:14 183560]

R3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-08-10 04:28:43 136176]

R3 JMCR;JMCR;C:\windows\system32\DRIVERS\jmcr.sys [x]

R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 03:34:24 4925184]

R3 Point64;Microsoft IntelliPoint Filter Driver;C:\windows\system32\DRIVERS\point64.sys [x]

R3 TMachInfo;TMachInfo;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 16:21:50 51512]

R3 USBAAPL64;Apple Mobile USB Driver;C:\windows\system32\Drivers\usbaapl64.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\system32\Wat\WatAdminSvc.exe [x]

Link to post
Share on other sites

Yes, that is possible. In that case, lets rerun it. Please delete any old copy you might still have and download it from one of the links below.

COMBOFIX

---------------

Please download ComboFix from one of these locations:


Bleepingcomputer
ForoSpyware

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Double click on Combofix.exe and follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, or if you are running Vista, ComboFix will continue it's malware removal procedures.

Query_RC.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

RC_successful.gif

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\Combofix.txt in your next reply.

Link to post
Share on other sites

ComboFix 11-07-10.02 - Shelby 07/10/2011 7:18.3.2 - x64

Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3891.2354 [GMT -5:00]

Running from: c:\users\Shelby\Desktop\ComboFix.exe

AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

* Created a new restore point

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

---- Previous Run -------

.

c:\users\Shelby\AppData\Local\Temp\424.tmp

.

.

((((((((((((((((((((((((( Files Created from 2011-06-10 to 2011-07-10 )))))))))))))))))))))))))))))))

.

.

2011-07-10 13:04 . 2011-07-10 13:04 -------- d-----w- c:\users\Default\AppData\Local\temp

2011-07-08 18:32 . 2011-06-07 17:10 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{89565020-7924-4528-AACD-229C8ABB1CF3}\mpengine.dll

2011-07-05 22:23 . 2011-07-06 21:22 -------- d-----w- c:\program files (x86)\Xvid

2011-07-05 22:16 . 2011-07-09 13:34 -------- d-----w- c:\users\Shelby\AppData\Roaming\WhiteSmoke

2011-07-05 22:16 . 2011-07-05 22:16 2106216 ----a-w- c:\program files (x86)\Mozilla Firefox\D3DCompiler_43.dll

2011-07-05 22:16 . 2011-07-05 22:16 1998168 ----a-w- c:\program files (x86)\Mozilla Firefox\d3dx9_43.dll

2011-07-05 22:16 . 2011-07-05 22:17 -------- d-----w- c:\program files (x86)\WhiteSmoke

2011-06-27 21:37 . 2011-04-27 02:57 102400 ----a-w- c:\windows\system32\drivers\dfsc.sys

2011-06-27 21:37 . 2011-04-25 05:32 1896832 ----a-w- c:\windows\system32\drivers\tcpip.sys

2011-06-27 21:37 . 2011-04-25 02:44 499712 ----a-w- c:\windows\system32\drivers\afd.sys

2011-06-27 21:37 . 2011-04-29 05:47 1110528 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll

2011-06-27 21:37 . 2011-04-29 05:08 759296 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll

2011-06-27 21:37 . 2011-05-04 02:51 287744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys

2011-06-27 21:37 . 2011-05-04 02:51 126464 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys

2011-06-27 21:37 . 2011-05-04 02:51 157696 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2011-06-27 21:37 . 2011-05-28 03:07 3133952 ----a-w- c:\windows\system32\win32k.sys

2011-06-27 21:35 . 2011-05-03 05:21 976896 ----a-w- c:\windows\system32\inetcomm.dll

2011-06-27 21:35 . 2011-05-03 04:50 740864 ----a-w- c:\windows\SysWow64\inetcomm.dll

2011-06-27 21:34 . 2011-04-29 03:12 399872 ----a-w- c:\windows\system32\drivers\srv2.sys

2011-06-27 21:34 . 2011-04-29 03:13 461312 ----a-w- c:\windows\system32\drivers\srv.sys

2011-06-27 21:34 . 2011-04-29 03:12 161792 ----a-w- c:\windows\system32\drivers\srvnet.sys

2011-06-27 21:34 . 2010-11-02 05:12 320512 ----a-w- c:\windows\system32\d3d10_1core.dll

2011-06-27 21:34 . 2010-11-02 04:35 218624 ----a-w- c:\windows\SysWow64\d3d10_1core.dll

2011-06-27 21:34 . 2011-01-17 06:17 197120 ----a-w- c:\windows\system32\d3d10_1.dll

2011-06-27 21:34 . 2011-01-17 05:38 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll

2011-06-27 21:34 . 2010-12-18 06:13 861184 ----a-w- c:\windows\system32\oleaut32.dll

2011-06-27 21:34 . 2010-12-18 05:31 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll

2011-06-15 22:01 . 2011-06-15 22:01 -------- d-----w- c:\program files\iPod

2011-06-15 22:01 . 2011-06-15 22:01 -------- d-----w- c:\program files\iTunes

2011-06-15 22:01 . 2011-06-15 22:01 -------- d-----w- c:\program files (x86)\iTunes

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-07-04 11:43 . 2010-11-23 05:28 40112 ----a-w- c:\windows\avastSS.scr

2011-07-04 11:43 . 2010-11-23 05:28 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe

2011-07-04 11:43 . 2011-05-30 13:26 253888 ----a-w- c:\windows\system32\aswBoot.exe

2011-07-04 11:36 . 2011-05-30 13:26 600920 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2011-07-04 11:36 . 2010-11-23 05:28 288088 ----a-w- c:\windows\system32\drivers\aswSP.sys

2011-07-04 11:35 . 2010-11-23 05:28 45400 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2011-07-04 11:32 . 2010-11-23 05:28 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2011-07-04 11:32 . 2010-11-23 05:28 64856 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys

2011-07-04 11:32 . 2010-11-23 05:28 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2011-06-27 21:12 . 2011-05-21 23:28 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2011-05-29 14:11 . 2010-12-11 05:52 39984 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys

2011-05-29 14:11 . 2010-12-11 05:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-05-25 00:14 . 2010-11-23 05:29 270720 ------w- c:\windows\system32\MpSigStub.exe

2011-05-10 13:06 . 2011-05-10 13:06 51712 ----a-w- c:\windows\system32\drivers\usbaapl64.sys

2011-05-10 13:06 . 2011-05-10 13:06 4517664 ----a-w- c:\windows\system32\usbaaplrc.dll

2011-04-22 20:18 . 2011-05-25 00:26 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys

.

.

((((((((((((((((((((((((((((( SnapShot@2011-07-09_02.41.32 )))))))))))))))))))))))))))))))))))))))))

.

- 2009-07-14 04:54 . 2011-07-09 02:40 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2009-07-14 04:54 . 2011-07-10 13:07 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-07-14 04:54 . 2011-07-09 02:40 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2009-07-14 04:54 . 2011-07-10 13:07 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2009-07-14 04:54 . 2011-07-10 13:07 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2009-07-14 04:54 . 2011-07-09 02:40 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2010-08-10 04:35 . 2011-07-09 13:35 36708 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 05:10 . 2011-07-09 13:35 45266 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

+ 2010-11-23 04:34 . 2011-07-09 13:35 10026 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4159739926-3857892584-1243141038-1000_UserData.bin

- 2010-11-23 01:27 . 2011-07-09 02:07 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2010-11-23 01:27 . 2011-07-09 04:27 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2010-11-23 01:27 . 2011-07-09 02:07 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2010-11-23 01:27 . 2011-07-09 04:27 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2009-07-14 04:54 . 2011-07-09 04:27 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2009-07-14 04:54 . 2011-07-09 02:07 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2010-11-23 04:31 . 2011-07-09 02:01 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2010-11-23 04:31 . 2011-07-10 14:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2010-11-23 04:31 . 2011-07-09 02:01 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2010-11-23 04:31 . 2011-07-10 14:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2011-07-10 13:07 . 2011-07-10 13:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

- 2011-07-09 02:39 . 2011-07-09 02:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2011-07-10 13:07 . 2011-07-10 13:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2011-07-09 02:39 . 2011-07-09 02:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2010-11-23 04:41 . 2011-07-10 12:52 269640 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin

+ 2009-07-14 05:01 . 2011-07-10 13:06 267732 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

- 2009-07-14 05:01 . 2011-07-09 02:39 267732 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

+ 2010-11-23 22:35 . 2011-07-10 13:06 2407332 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4159739926-3857892584-1243141038-1000-8192.dat

- 2010-11-23 22:35 . 2011-07-09 02:39 2407332 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-4159739926-3857892584-1243141038-1000-8192.dat

- 2009-07-14 02:34 . 2011-07-09 02:11 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat

+ 2009-07-14 02:34 . 2011-07-10 13:55 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760]

"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-08-10 39408]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"TSleepSrv"="%ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe" [bU]

"ToshibaAppPlace"="c:\program files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe" [2010-06-11 552960]

"SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2010-02-23 352256]

"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2010-03-04 423936]

"KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2009-12-25 34160]

"TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-24 2454840]

"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136]

"NortonOnlineBackupReminder"="c:\program files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe" [2010-06-03 3218792]

"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]

"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-06-07 421160]

.

c:\users\Shelby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Launch WhiteSmoke.lnk - c:\program files (x86)\WhiteSmoke\WSEnrichment.exe [2011-4-12 2162688]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]

"aux"=wdmaud.drv

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-10 136176]

R2 regi;regi;c:\windows\system32\drivers\regi.sys [x]

R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]

R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-10 136176]

R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]

R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]

R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x]

R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]

S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys [x]

S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [x]

S0 unihoocx;unihoocx;c:\windows\system32\DRIVERS\unihoocx.sys [x]

S1 aswSnx;aswSnx; [x]

S1 aswSP;aswSP; [x]

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]

S2 aswFsBlk;aswFsBlk; [x]

S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]

S2 Norton PC Checkup Application Launcher;Toshiba Laptop Checkup Application Launcher;c:\program files (x86)\Norton PC Checkup\Engine\2.0.3.198\SymcPCCULaunchSvc.exe [2010-01-29 103792]

S2 PCCUJobMgr;Common Client Job Manager Service;c:\program files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe [2009-08-24 126392]

S2 svcboot_ufaucvfq;svcboot_ufaucvfq;c:\windows\system32\svchost.exe [2009-07-14 27136]

S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-03-01 2296696]

S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-04-06 258928]

S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]

S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2009-10-01 2314240]

S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]

S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]

S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]

S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]

S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]

S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x]

S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-06 137560]

S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-03-31 835952]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

svcboot_ufaucvfq REG_MULTI_SZ svcboot_ufaucvfq

.

Contents of the 'Scheduled Tasks' folder

.

2011-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-10 04:28]

.

2011-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-10 04:28]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2011-07-04 11:43 134384 ----a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ThpSrv"="c:\windows\system32\thpsrv" [X]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-04-26 161304]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-04-26 386584]

"Persistence"="c:\windows\system32\igfxpers.exe" [2010-04-26 413208]

"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-03-20 10134560]

"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-03-20 896032]

"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]

"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-06 709976]

"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-22 2327952]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"LoadAppInit_DLLs"=0x0

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://whitesmokestart.com/?src=startpage&provider=bing&provider_name=bing&provider_code=Z052&partner_id=208&product_id=663&affiliate_id=&channel=9128&toolbar_id=202&toolbar_version=2.1.0&install_country=US&install_date=20110705&user_guid=2B93D2443E564E249647232649601A7B&machine_id=1cf040ecad92ded19e00f2146c17bffd&browser=IE&os=win&os_version=6.1-x64-SP0

mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSND&bmod=TSND

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = <local>

TCP: DhcpNameServer = 192.168.11.1

FF - ProfilePath - c:\users\Shelby\AppData\Roaming\Mozilla\Firefox\Profiles\0u9bqn31.default\

FF - prefs.js: browser.search.selectedEngine - Bing

FF - prefs.js: browser.startup.homepage - hxxp://whitesmokestart.com/?src=startpage&provider=bing&provider_name=bing&provider_code=Z052&partner_id=208&product_id=663&affiliate_id=&channel=9128&toolbar_id=202&toolbar_version=2.1.0&install_country=US&install_date=20110705&user_guid=2B93D2443E564E249647232649601A7B&machine_id=1cf040ecad92ded19e00f2146c17bffd&browser=FF&os=win&os_version=6.1-x64-SP0

FF - prefs.js: keyword.URL - hxxp://whitesmokestart.com/s/?src=addrbar&provider=bing&provider_name=bing&provider_code=Z052&partner_id=208&product_id=663&affiliate_id=&channel=9128&toolbar_id=202&toolbar_version=2.1.0&install_country=US&install_date=20110705&user_guid=2B93D2443E564E249647232649601A7B&machine_id=1cf040ecad92ded19e00f2146c17bffd&browser=FF&os=win&os_version=6.1-x64-SP0&q=

FF - prefs.js: network.proxy.type - 0

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-Locked - (no file)

Wow6432Node-HKCU-Run-LvfoZkfgayzPlby\AppData\Local\Temp\2604111823.exe - c:\users\Shelby\AppData\Local\Temp\2604111823.exe

Toolbar-Locked - (no file)

HKLM-Run-(Default) - (no file)

HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe

HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE

HKLM-Run-SmoothView - c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe

HKLM-Run-00TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe

HKLM-Run-SmartFaceVWatcher - c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe

HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe

HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe

HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe

HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe

.

.

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\services\PCCUJobMgr]

"ImagePath"="\"c:\program files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files (x86)\Norton PC Checkup\Engine\2.0.3.198\diMaster.dll\" /prefetch:1"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\S-1-5-21-4159739926-3857892584-1243141038-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="WindowsLiveMail.Email.1"

.

[HKEY_USERS\S-1-5-21-4159739926-3857892584-1243141038-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="WindowsLiveMail.VCard.1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.10"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files\Alwil Software\Avast5\AvastSvc.exe

c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\program files (x86)\Bonjour\mDNSResponder.exe

c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe

c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE

c:\program files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe

c:\program files (x86)\TeamViewer\Version6\TeamViewer.exe

c:\program files (x86)\Internet Explorer\iexplore.exe

.

**************************************************************************

.

Completion time: 2011-07-10 10:11:26 - machine was rebooted

ComboFix-quarantined-files.txt 2011-07-10 15:11

.

Pre-Run: 100,800,548,864 bytes free

Post-Run: 100,457,259,008 bytes free

.

- - End Of File - - 7B4471DD1929063EC4F01EEBC30FB0B8

Link to post
Share on other sites

Lets get rid of all WhiteSmoke leftovers ehre.

CF-SCRIPT

-------------

We need to execute a CF-script.

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Click Start > Run and in the box that opens type notepad and press enter. Copy/paste the text in the codebox below into it:



File::
c:\users\Shelby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Launch WhiteSmoke.lnk

Folder::
c:\program files (x86)\WhiteSmoke

DDS::
uStart Page = hxxp://whitesmokestart.com/?

Firefox::
FF - ProfilePath - c:\users\Shelby\AppData\Roaming\Mozilla\Firefox\Profiles\0u9bqn31.default\
FF - prefs.js: browser.startup.homepage - hxxp://whitesmokestart.com/?

NetSvc::
svcboot_ufaucvfq

Driver::
svcboot_ufaucvfq

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Link to post
Share on other sites

post-87304-0-63603700-1310335216.jpg

The computer seems to have locked up after the re-boot. There are two illegal operations on the screen. I attached a photo of the screen so you could see what they are. It says not to run any programs until ComboFix has finished but AIM automatically loads. Is that a problem for it?

Link to post
Share on other sites

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2011-06-23.01)

.

Microsoft Windows 7 Home Premium

Boot Device: \Device\HarddiskVolume1

Install Date: 11/22/2010 10:32:44 PM

System Uptime: 7/11/2011 12:24:43 PM (4 hours ago)

.

Motherboard: TOSHIBA | | NDU10

Processor: Intel® Pentium® CPU U5400 @ 1.20GHz | CPU | 1199/133mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 287 GiB total, 93.062 GiB free.

.

==== Disabled Device Manager Items =============

.

==== System Restore Points ===================

.

RP124: 7/5/2011 12:14:02 PM - Windows Update

RP125: 7/7/2011 1:22:07 PM - Windows Update

RP126: 7/8/2011 1:32:26 PM - Windows Update

RP127: 7/8/2011 4:47:27 PM - Removed Steam

RP128: 7/10/2011 7:17:00 AM - ComboFix created restore point

.

==== Installed Programs ======================

.

Adobe Flash Player 10 ActiveX

Adobe Flash Player 10 Plugin

Adobe Reader 9.3

Amazon Links

Apple Application Support

Apple Software Update

avast! Free Antivirus

Bejeweled 2 Deluxe

Bing Bar

Build-a-lot 2

Chuzzle Deluxe

Corel WinDVD

D3DX10

Definition update for Microsoft Office 2010 (KB982726)

Download Updater (AOL LLC)

FATE

Google Chrome

Google Toolbar for Internet Explorer

Google Update Helper

Intel® Graphics Media Accelerator Driver

Intel® Management Engine Components

Intel® Rapid Storage Technology

InterActual Player

Java 6 Update 17

Jewel Quest - Heritage

JMicron Flash Media Controller Driver

Junk Mail filter update

Malwarebytes' Anti-Malware version 1.51.0.1200

Mesh Runtime

Messenger Companion

Microsoft Office 2010

Microsoft Office Proof (English) 2010

Microsoft Office Proof (French) 2010

Microsoft Office Proof (Spanish) 2010

Microsoft Office Proofing (English) 2010

Microsoft Office Shared MUI (English) 2010

Microsoft Office Shared Setup Metadata MUI (English) 2010

Microsoft Office Word 2010

Microsoft Office Word MUI (English) 2010

Microsoft Silverlight

Microsoft SQL Server 2005 Compact Edition [ENU]

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Word 2010

Mozilla Firefox 5.0 (x86 en-US)

MSVCRT

MSVCRT_amd64

MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

Plants vs. Zombies

Polar Bowler

Quickbooks Financial Center

QuickTime

Realtek Ethernet Controller Driver For Windows 7

Realtek High Definition Audio Driver

Realtek WLAN Driver

Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)

Security Update for Microsoft Excel 2010 (KB2523021)

Security Update for Microsoft Office 2010 (KB2289078)

Security Update for Microsoft Office 2010 (KB2289161)

Security Update for Microsoft Word 2010 (KB2345000)

Skype Launcher

TeamViewer 6

Toshiba App Place

TOSHIBA Application Installer

TOSHIBA Assist

Toshiba Book Place

TOSHIBA Bulletin Board

TOSHIBA eco Utility

TOSHIBA Face Recognition

TOSHIBA Flash Cards Support Utility

TOSHIBA Hardware Setup

TOSHIBA HDD/SSD Alert

Toshiba Laptop Checkup

TOSHIBA Media Controller

TOSHIBA Media Controller Plug-in

Toshiba Online Backup

TOSHIBA Quality Application

TOSHIBA ReelTime

TOSHIBA Service Station

TOSHIBA Sleep Utility

TOSHIBA Supervisor Password

TOSHIBA Value Added Package

TOSHIBA Web Camera Application

ToshibaRegistration

Ulead Burn.Now 4.5

Ulead Burn.Now 4.5 SE

Update for Microsoft Office 2010 (KB2202188)

Update for Microsoft Office 2010 (KB2413186)

Update for Microsoft Office 2010 (KB2494150)

Update for Microsoft Office 2010 (KB2523113)

Utility Common Driver

Wheel of Fortune 2

WhiteSmoke

WildTangent Games

WildTangent ORB Game Console

Windows Live Communications Platform

Windows Live Essentials

Windows Live Installer

Windows Live Mail

Windows Live Mesh

Windows Live Mesh ActiveX Control for Remote Connections

Windows Live Messenger

Windows Live Messenger Companion Core

Windows Live Movie Maker

Windows Live Photo Common

Windows Live Photo Gallery

Windows Live PIMT Platform

Windows Live SOXE

Windows Live SOXE Definitions

Windows Live Sync

Windows Live UX Platform

Windows Live UX Platform Language Pack

Windows Live Writer

Windows Live Writer Resources

Zuma's Revenge

.

==== Event Viewer Messages From Past Week ========

.

7/9/2011 7:14:37 AM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.

7/9/2011 7:14:37 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}

7/9/2011 7:14:37 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}

7/9/2011 7:14:37 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}

7/9/2011 7:14:37 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}

7/9/2011 7:14:35 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

7/9/2011 7:14:30 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}

7/9/2011 7:14:14 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD aswRdr aswSnx aswSP aswTdi cdrom DfsC discache NetBIOS NetBT nsiproxy Psched rdbss spldr tdx vwififlt Wanarpv6 WfpLwf

7/9/2011 7:14:14 AM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.

7/9/2011 7:14:14 AM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.

7/9/2011 7:14:14 AM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.

7/9/2011 7:14:14 AM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.

7/9/2011 7:14:14 AM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.

7/9/2011 7:14:14 AM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.

7/9/2011 7:14:14 AM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.

7/9/2011 7:14:14 AM, Error: Service Control Manager [7001] - The Network Connections service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.

7/9/2011 7:14:14 AM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.

7/9/2011 7:14:14 AM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.

7/9/2011 7:14:14 AM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.

7/8/2011 9:13:11 PM, Error: Application Popup [1060] - \??\C:\32788R22FWJFW\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

7/8/2011 6:12:25 PM, Error: Microsoft-Windows-DNS-Client [1012] - There was an error while attempting to read the local hosts file.

7/8/2011 5:38:04 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.

7/8/2011 5:00:08 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: aswSnx aswSP aswTdi cdrom discache spldr Wanarpv6

7/10/2011 6:51:49 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom

7/10/2011 6:51:42 PM, Error: Service Control Manager [7000] - The regi service failed to start due to the following error: The system cannot find the file specified.

7/10/2011 4:40:18 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

7/10/2011 4:05:14 PM, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

7/10/2011 3:51:50 PM, Error: Service Control Manager [7034] - The svcboot_ufaucvfq service terminated unexpectedly. It has done this 1 time(s).

.

==== End Of File ===========================

Link to post
Share on other sites

Hi there, do you have any problem left at this point?

Your version of Adobe Reader is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Adobe components and update:

  • Download the latest version of Adobe Reader Version X. and save it to your desktop.
  • Uncheck the "Free McAfee Security plan Plus" option or any other Toolbar you are offered
  • Click the download button at the bottom.
  • If you use Internet Explorer and do not wish to install the ActiveX element, simply click on the click here to download link on the next page.
  • Remove all older version of Adobe Reader: Go to Add/remove and uninstall all versions of Adobe Reader, Acrobat Reader and Adobe Acrobat.
    If you are unsure of how to use Add or Remove Programs, the please see this tutorial:How To Remove An Installed Program From Your Computer
  • Then from your desktop double-click on Adobe Reader to install the newest version.
    If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
  • When the "Adobe Setup - Welcome" window opens, click the Install > button.
  • If offered to install a Toolbar, just uncheck the box before continuing unless you want it.

Your Adobe Reader is now up to date!

Your version of Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system.

  • Download the latest version of Java Runtime Environment (JRE) Version 6.
  • Look for "JDK 6 Update 26 (JDK or JRE).
  • Click the "Download JRE" button at the right.
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
    • Select "Windows x86 Offline" and click on jre-6u26-windows-i586.exe

    [*]Save it to your desktop

    [*]Close any programs you may have running - especially your web browser.

    [*]Uninstall all older versions of Java (any item with Java Runtime Environment, JRE or J2SE in the name).

    [*]Reboot your computer once all Java components are removed.

    [*]Install the newest version by double clicking (run as Administrator for Windows Vista/Seven) the downloaded file.

Please launch MBAM, update it and run a full scan. Post me the resulting log.

Link to post
Share on other sites

Adobe managed to sneak in a Norton tool. I never saw an option to not install it. I had to uninstall it.

Malwarebytes' Anti-Malware 1.51.0.1200

www.malwarebytes.org

Database version: 7085

Windows 6.1.7600

Internet Explorer 8.0.7600.16385

7/12/2011 9:50:39 AM

mbam-log-2011-07-12 (09-50-38).txt

Scan type: Full scan (C:\|)

Objects scanned: 299529

Time elapsed: 42 minute(s), 27 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

Yes, it is the Norton Security scan I believe. This is a tool that checks your protection and can be uninstalled easily.

Lets run one last scan before calling it clean.

ESET ONLINE SCANNER

----------------------------

I'd like us to scan your machine with ESET OnlineScan

  1. Hold down Control and click on this link to open ESET OnlineScan in a new window.
  2. Click the esetonlinebtn.png button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

    1. Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the esetsmartinstaller_enu.png
      icon on your desktop.

    3. Check "YES, I accept the Terms of Use."
    4. Click the Start button.
    5. Accept any security warnings from your browser.
    6. Under scan settings, check "Scan Archives" and "Remove found threats"
    7. Click Advanced settings and select the following:
      • Scan potentially unwanted applications
      • Scan for potentially unsafe applications
      • Enable Anti-Stealth technology

[*]ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.

[*]When the scan completes, click List Threats

[*]Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.

[*]Click the Back button.

[*]Click the Finish button.

Link to post
Share on other sites

These were only some leftover files. :)

ALL CLEAN

--------------

Your machine appears to be clean, please take the time to read below on how to secure the machine and take the necessary steps to keep it clean :)

Please do the following to remove the remaining programs from your PC:

  • Delete the tools used during the disinfection:
    • Click start > run and type combofix /uninstall, press enter. This will remove Combofix from your computer.
    • Delete DDS and TDSSkiller.

Please read these advices, in order to prevent reinfecting your PC:

  1. Install and update the following programs regularly:
    • an outbound firewall. If you are connected to the internet through a router, you are already behind a hardware firewall and as such you do not need an extra software firewall.
      A comprehensive tutorial and a list of possible firewalls can be found here.
    • an AntiVirus Software
      It is imperative that you update your AntiVirus Software on regular basis.If you do not update your AntiVirus Software then it will not be able to catch the latest threats.
    • an Anti-Spyware program
      Malware Byte's Anti Malware is an excellent Anti-Spyware scanner. It's scan times are usually under ten minutes, and has excellent detection and removal rates.
      SUPERAntiSpyware is another good scanner with high detection and removal rates.
      Both programs are free for non commercial home use but provide a resident and do not nag if you purchase the paid versions.
    • Spyware Blaster
      A tutorial for Spywareblaster can be found here. If you wish, the commercial version provides automatic updating.

[*]Keep Windows (and your other Microsoft software) up to date!

I cannot stress how important this is enough. Often holes are found in Internet Explorer or Windows itself that require patching. Sometimes these holes will allow an attacker unrestricted access to your computer.

Therefore, please, visit the Microsoft Update Website and follow the on screen instructions to setup Microsoft Update. Also follow the instructions to update your system. Please REBOOT and repeat this process until there are no more updates to install!!

[*]Keep your other software up to date as well

Software does not need to be made by Microsoft to be insecure. You can use the Secunia Online Software occasionally to help you check for out of date software on yourmachine.

[*]Stay up to date!

The MOST IMPORTANT part of any security setup is keeping the software up to date. Malware writers release new variants every single day. If your software updates don't keep up, then the malware will always be one step ahead. Not a good thing.

Some more links you might find of interest:

Please reply to this topic if you have read the above information. If your computer is working fine, this topic will be closed afterwards.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.