HeroWai Posted September 30, 2011 ID:480802 Share Posted September 30, 2011 I'm new to removing viruses and I've heard this forum can help me get rid of them. I'm not exactly sure that I have a virus. But I'd like an expert have a look. My desktop runs really slow sometimes and there's a svchost that malwarebytes keep detecting as a virus. Everytime it deletes it, it somehow manages to come back. Please tell me what to do. Link to post Share on other sites More sharing options...
LDTate Posted October 3, 2011 ID:481788 Share Posted October 3, 2011 Logs will be closed if you haven't replied within 3 days Please don't attach the scans / logs for these tools, use "copy/paste".DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.Please run a new MBAM scan being sure to update before scanning.Post the scan resultsAlso please describe how your computer behaves at the moment.Please don't attach the scans / logs, use "copy/paste". Link to post Share on other sites More sharing options...
HeroWai Posted October 4, 2011 Author ID:481989 Share Posted October 4, 2011 Malwarebytes' Anti-Malware 1.51.2.1300www.malwarebytes.orgDatabase version: 7831Windows 6.1.7601 Service Pack 1Internet Explorer 8.0.7601.1751410/3/2011 11:19:31 PMmbam-log-2011-10-03 (23-19-31).txtScan type: Full scan (C:\|D:\|)Objects scanned: 267407Time elapsed: 20 minute(s), 0 second(s)Memory Processes Infected: 0Memory Modules Infected: 0Registry Keys Infected: 0Registry Values Infected: 0Registry Data Items Infected: 0Folders Infected: 0Files Infected: 1Memory Processes Infected:(No malicious items detected)Memory Modules Infected:(No malicious items detected)Registry Keys Infected:(No malicious items detected)Registry Values Infected:(No malicious items detected)Registry Data Items Infected:(No malicious items detected)Folders Infected:(No malicious items detected)Files Infected:c:\Windows\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully. Link to post Share on other sites More sharing options...
LDTate Posted October 4, 2011 ID:482044 Share Posted October 4, 2011 Vista and Windows 7 users:1. These tools MUST be run from the executable. (.exe) every time you run them 2. With Admin Rights (Right click, choose "Run as Administrator")Download ComboFix from one of these locations:Link 1Link 2 If using this link, Right Click and select Save As.* IMPORTANT !!! Save ComboFix.exe to your DesktopDisable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective ProgramsDouble click on ComboFix.exe & follow the prompts.Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7. Note: If you have XP SP3, use the XP SP2 package.If Vista or Windows 7, skip the Recovery Console partAs part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:Click on Yes, to continue scanning for malware.When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.Notes:1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper. 4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.Give it atleast 20-30 minutes to finish if needed.Please do not attach the scan results from Combofx. Use copy/paste.Also please describe how your computer behaves at the moment. Link to post Share on other sites More sharing options...
HeroWai Posted October 6, 2011 Author ID:482801 Share Posted October 6, 2011 I downloaded Combofix and tried to run it. After the extracting this appeared.Is this suppose to happen? Was it still scanning? Link to post Share on other sites More sharing options...
LDTate Posted October 6, 2011 ID:482838 Share Posted October 6, 2011 Try it again and as long as there's drive activity, let it do it's thing.After 10-15 mins if you don't see "stages" running, then it's hung-up.If that happens:http://www.eset.eu/online-scannerGo here to run an online scannner from ESET.Click the green ESET Online Scanner button.Read the End User License Agreement and check the box: YES, I accept the Terms of Use.Click on the Start button next to it.You may receive an alert on the address bar that "This site might require the following ActiveX control...Click here to install...". Click on that alert and then click Insall ActiveX component.A new window will appear asking "Do you want to install this software?"".Answer Yes to download and install the ActiveX controls that allows the scan to run.Click Start.Check Remove found threats and Scan potentially unwanted applications.Click Scan to begin. If offered the option to get information or buy software. Just close the window. Wait for the scan to finishUse notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txtCopy and paste that log as a reply to this topic. Link to post Share on other sites More sharing options...
LDTate Posted October 10, 2011 ID:484300 Share Posted October 10, 2011 Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread. Thanks! Link to post Share on other sites More sharing options...
LDTate Posted October 11, 2011 ID:484502 Share Posted October 11, 2011 Topic reopened.Logs will be closed if you haven't replied within 3 days Link to post Share on other sites More sharing options...
HeroWai Posted October 11, 2011 Author ID:484545 Share Posted October 11, 2011 So I ran combofix again this time it worked.ComboFix 11-10-10.04 - Owner 10/10/2011 23:47:59.2.2 - x64Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4095.2742 [GMT -4:00]Running from: c:\users\Owner\Downloads\ComboFix.exeAV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}SP: Norton Internet Security *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}..((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))..c:\users\Owner\Documents\Downloads\CT2776682_BrotherSoft_Extreme.exec:\windows\svchost.exe..((((((((((((((((((((((((( Files Created from 2011-09-11 to 2011-10-11 )))))))))))))))))))))))))))))))..2011-09-30 16:17 . 2011-09-30 16:17 -------- d-----w- c:\program files (x86)\Common Files\Software Update Utility2011-09-30 16:14 . 2011-09-30 16:14 -------- d-----w- c:\users\Owner\AppData\Local\AOL OCP2011-09-30 16:14 . 2011-09-30 16:14 -------- d-----w- c:\programdata\Viewpoint2011-09-30 16:14 . 2007-04-16 17:07 180293 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npViewpoint.dll2011-09-30 16:14 . 2011-09-30 16:14 -------- d-----w- c:\program files (x86)\Viewpoint2011-09-30 16:14 . 2011-09-30 16:14 -------- d-----w- c:\programdata\acccore2011-09-30 16:14 . 2011-09-30 16:15 -------- d-----w- c:\programdata\AOL OCP2011-09-30 16:14 . 2011-09-30 16:14 -------- d-----w- c:\programdata\AOL2011-09-12 22:46 . 2011-09-12 22:56 -------- d-----w- c:\windows\vbSkinner2011-09-12 21:37 . 2011-09-13 18:21 -------- d-----w- c:\windows\system32\drivers\NISx642011-09-12 21:37 . 2011-09-12 21:37 -------- d-----w- c:\program files (x86)\Norton Internet Security2011-09-12 19:27 . 2011-09-12 22:02 -------- d-----w- c:\program files\Symantec2011-09-12 19:11 . 2011-09-12 19:11 -------- d-----w- c:\users\Owner\AppData\Roaming\Tific2011-09-12 19:11 . 2011-09-12 19:11 -------- d-----w- c:\users\Owner\AppData\Local\Symantec...(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2011-09-28 05:29 . 2011-06-05 22:37 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl2011-09-12 22:02 . 2011-06-05 22:06 174200 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS2011-08-31 21:00 . 2011-07-25 09:09 25416 ----a-w- c:\windows\system32\drivers\mbam.sys2011-07-22 05:22 . 2011-08-10 15:10 1638912 ----a-w- c:\windows\system32\mshtml.tlb2011-07-22 04:54 . 2011-08-10 15:10 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb2011-07-17 16:04 . 2011-08-17 19:15 4390376 ----a-w- c:\windows\SysWow64\GameMon.des2011-07-16 05:41 . 2011-08-10 15:10 362496 ----a-w- c:\windows\system32\wow64win.dll2011-07-16 05:41 . 2011-08-10 15:10 243200 ----a-w- c:\windows\system32\wow64.dll2011-07-16 05:41 . 2011-08-10 15:10 13312 ----a-w- c:\windows\system32\wow64cpu.dll2011-07-16 05:39 . 2011-08-10 15:10 16384 ----a-w- c:\windows\system32\ntvdm64.dll2011-07-16 05:37 . 2011-08-10 15:10 421888 ----a-w- c:\windows\system32\KernelBase.dll2011-07-16 05:21 . 2011-08-10 15:10 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll2011-07-16 04:29 . 2011-08-10 15:10 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll2011-07-16 04:26 . 2011-08-10 15:10 44032 ----a-w- c:\windows\apppatch\acwow64.dll2011-07-16 04:25 . 2011-08-10 15:10 25600 ----a-w- c:\windows\SysWow64\setup16.exe2011-07-16 04:24 . 2011-08-10 15:10 5120 ----a-w- c:\windows\SysWow64\wow32.dll2011-07-16 04:24 . 2011-08-10 15:10 272384 ----a-w- c:\windows\SysWow64\KernelBase.dll2011-07-16 04:15 . 2011-08-10 15:10 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 5120 ---ha-w- c:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-console-l1-1-0.dll2011-07-16 02:21 . 2011-08-10 15:10 7680 ----a-w- c:\windows\SysWow64\instnm.exe2011-07-16 02:21 . 2011-08-10 15:10 2048 ----a-w- c:\windows\SysWow64\user.exe2011-07-16 02:17 . 2011-08-10 15:10 6144 ---ha-w- c:\windows\SysWow64\api-ms-win-security-base-l1-1-0.dll2011-07-16 02:17 . 2011-08-10 15:10 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll2011-07-16 02:17 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll2011-07-16 02:17 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll..((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4.[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Aim"="c:\program files (x86)\AIM\aim.exe" [2011-05-03 4321112].[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]"ConsentPromptBehaviorAdmin"= 0 (0x0)"ConsentPromptBehaviorUser"= 3 (0x3)"EnableLUA"= 0 (0x0)"EnableUIADesktopToggle"= 0 (0x0)"PromptOnSecureDesktop"= 0 (0x0).[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]"Taskman"="".[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]"aux2"=wdmaud.drv.R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]R2 WPDBusEnum32;Portable Device Enumerator Service ;c:\windows\system32\iprtrmgr32.exe [x]R3 dump_wmimmc;dump_wmimmc;c:\ijji\ENGLISH\Gunz\GameGuard\dump_wmimmc.sys [x]R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]R3 rtl8192U;Realtek RTL8192u 802.11n Wireless LAN USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\rtl8192U.sys [x]R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\System32\Drivers\usbaapl64.sys [x]R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1206000.01D\SYMDS64.SYS [x]S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1206000.01D\SYMEFA64.SYS [x]S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20110929.001\BHDrvx64.sys [2011-09-29 1152632]S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20111010.030\IDSvia64.sys [2011-09-09 488568]S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1206000.01D\Ironx64.SYS [x]S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1206000.01D\SYMNETS.SYS [x]S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe [2011-04-17 130008]S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2011-04-01 428640]S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-09-12 136824]S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [x]S3 LVUVC64;Logitech Webcam 200(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [x]S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]..Contents of the 'Scheduled Tasks' folder..--------- x86-64 -----------..[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]"LoadAppInit_DLLs"=0x0.------- Supplementary Scan -------.uLocal Page = c:\windows\system32\blank.htmuStart Page = hxxp://www.google.com/mLocal Page = c:\windows\SysWOW64\blank.htmTCP: DhcpNameServer = 192.168.0.1FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\bjdentvq.default\FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/FF - prefs.js: network.proxy.http - 127.0.0.1FF - prefs.js: network.proxy.http_port - 64485FF - prefs.js: network.proxy.type - 0FF - Ext: Skype extension: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}FF - Ext: Aero Fox XL: {5c8bfb7c-9a54-11dc-8314-0800200c9a66} - %profile%\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}FF - Ext: Symantec IPS: {BBDA0591-3099-440a-AA10-41764D9DB4DB} - c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgnFF - Ext: Norton Toolbar: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62} - c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_2_3FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false..[HKEY_LOCAL_MACHINE\system\ControlSet001\services\NIS]"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\18.6.0.29\diMaster.dll\" /prefetch:1".[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]"ImagePath"="c:\windows\system32\GameMon.des -service".--------------------- LOCKED REGISTRY KEYS ---------------------.[HKEY_USERS\S-1-5-21-2050267592-1898014992-1162686773-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0E223454-2F23-9CBF-E71C-F862DFDF8051}*]"bbccbcpfanmoobpmfmdfmpihkdmjmdcbcbbe"=hex:61,62,66,64,6b,66,61,67,67,68,67,67, 66,62,6f,66,69,66,6a,6e,62,69,67,62,62,68,66,6d,61,70,70,6a,6d,63,00,75"abccbcpfanmoobpmfmcfloalajikhhioaf"=hex:61,62,61,64,65,64,69,64,69,68,63,69, 66,6d,6b,6f,63,6d,6c,67,69,61,62,67,6d,65,64,63,69,6b,6f,6d,6c,70,00,75.[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]@Denied: (A 2) (Everyone)@="FlashBroker""LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10r_ActiveX.exe,-101".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]"Enabled"=dword:00000001.[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10r_ActiveX.exe".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]@Denied: (A 2) (Everyone)@="Shockwave Flash Object".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10r.ocx""ThreadingModel"="Apartment".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]@="0".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]@="ShockwaveFlash.ShockwaveFlash.10".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10r.ocx, 1".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]@="{D27CDB6B-AE6D-11cf-96B8-444553540000}".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]@="1.0".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]@="ShockwaveFlash.ShockwaveFlash".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]@Denied: (A 2) (Everyone)@="Macromedia Flash Factory Object".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10r.ocx""ThreadingModel"="Apartment".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]@="FlashFactory.FlashFactory.1".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10r.ocx, 1".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]@="{D27CDB6B-AE6D-11cf-96B8-444553540000}".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]@="1.0".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]@="FlashFactory.FlashFactory".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]@Denied: (A 2) (Everyone)@="IFlashBroker4".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]@="{00020424-0000-0000-C000-000000000046}".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}""Version"="1.0".[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]@Denied: (Full) (Everyone).------------------------ Other Running Processes ------------------------.c:\\.\globalroot\systemroot\svchost.exec:\\.\globalroot\systemroot\svchost.exe.**************************************************************************.Completion time: 2011-10-10 23:55:31 - machine was rebootedComboFix-quarantined-files.txt 2011-10-11 03:55.Pre-Run: 442,674,786,304 bytes freePost-Run: 442,382,991,360 bytes free.- - End Of File - - B54CE01A39A3C8F3E4EC3D699643D6E7 Link to post Share on other sites More sharing options...
HeroWai Posted October 11, 2011 Author ID:484548 Share Posted October 11, 2011 My computer is fine at the moment. It usually starts slowing down during the night.I checked my ping using cmd with "ping -t google.com" when my computer was lagging. The pings jumped from 90-500+. Link to post Share on other sites More sharing options...
LDTate Posted October 11, 2011 ID:484561 Share Posted October 11, 2011 Copy/paste the text in the Codebox below into notepad:Here's how to do that:Click Start > Run type Notepad click OK.This will open an empty notepad file: Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text. KillAll::FireFox::FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\bjdentvq.default\FF - prefs.js: network.proxy.http - 127.0.0.1FF - prefs.js: network.proxy.http_port - 64485FF - prefs.js: network.proxy.type - 0FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}RegLock::[HKEY_USERS\S-1-5-21-2050267592-1898014992-1162686773-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0E223454-2F23-9CBF-E71C-F862DFDF8051}*][HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]Save this file to your desktop, Save this as "CFScript" Here's how to do that:1.Click File;2.Click Save As... Change the directory to your desktop;3.Change the Save as type to "All Files"; 4.Type in the file name: CFScript5.Click Save ...Drag CFScript.txt into ComboFix.exeThen post the results log using Copy / PasteAlso please describe how your computer behaves at the moment. Link to post Share on other sites More sharing options...
HeroWai Posted October 12, 2011 Author ID:485079 Share Posted October 12, 2011 ComboFix 11-10-11.05 - Owner 10/12/2011 6:55.3.2 - x64Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4095.3142 [GMT -4:00]Running from: c:\users\Owner\Downloads\ComboFix.exeCommand switches used :: c:\users\Owner\Desktop\CFScript.txtAV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}SP: Norton Internet Security *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}..((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))..c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\icon.pngc:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\install.rdfc:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}\preview.pngc:\windows\svchost.exe..((((((((((((((((((((((((( Files Created from 2011-09-12 to 2011-10-12 )))))))))))))))))))))))))))))))..2011-10-12 10:59 . 2011-10-12 10:59 -------- d-----w- c:\users\Default\AppData\Local\temp2011-10-07 03:55 . 2011-10-07 03:55 -------- d-----w- c:\program files (x86)\ESET2011-09-30 16:17 . 2011-09-30 16:17 -------- d-----w- c:\program files (x86)\Common Files\Software Update Utility2011-09-30 16:14 . 2011-09-30 16:14 -------- d-----w- c:\users\Owner\AppData\Local\AOL OCP2011-09-30 16:14 . 2011-09-30 16:14 -------- d-----w- c:\programdata\Viewpoint2011-09-30 16:14 . 2007-04-16 17:07 180293 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\npViewpoint.dll2011-09-30 16:14 . 2011-09-30 16:14 -------- d-----w- c:\program files (x86)\Viewpoint2011-09-30 16:14 . 2011-09-30 16:14 -------- d-----w- c:\programdata\acccore2011-09-30 16:14 . 2011-09-30 16:15 -------- d-----w- c:\programdata\AOL OCP2011-09-30 16:14 . 2011-09-30 16:14 -------- d-----w- c:\programdata\AOL2011-09-12 22:46 . 2011-09-12 22:56 -------- d-----w- c:\windows\vbSkinner2011-09-12 21:37 . 2011-09-13 18:21 -------- d-----w- c:\windows\system32\drivers\NISx642011-09-12 21:37 . 2011-09-12 21:37 -------- d-----w- c:\program files (x86)\Norton Internet Security2011-09-12 19:27 . 2011-09-12 22:02 -------- d-----w- c:\program files\Symantec2011-09-12 19:11 . 2011-09-12 19:11 -------- d-----w- c:\users\Owner\AppData\Roaming\Tific2011-09-12 19:11 . 2011-09-12 19:11 -------- d-----w- c:\users\Owner\AppData\Local\Symantec...(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2011-09-28 05:29 . 2011-06-05 22:37 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl2011-09-12 22:02 . 2011-06-05 22:06 174200 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS2011-08-31 21:00 . 2011-07-25 09:09 25416 ----a-w- c:\windows\system32\drivers\mbam.sys2011-07-22 05:22 . 2011-08-10 15:10 1638912 ----a-w- c:\windows\system32\mshtml.tlb2011-07-22 04:54 . 2011-08-10 15:10 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb2011-07-17 16:04 . 2011-08-17 19:15 4390376 ----a-w- c:\windows\SysWow64\GameMon.des2011-07-16 05:41 . 2011-08-10 15:10 362496 ----a-w- c:\windows\system32\wow64win.dll2011-07-16 05:41 . 2011-08-10 15:10 243200 ----a-w- c:\windows\system32\wow64.dll2011-07-16 05:41 . 2011-08-10 15:10 13312 ----a-w- c:\windows\system32\wow64cpu.dll2011-07-16 05:39 . 2011-08-10 15:10 16384 ----a-w- c:\windows\system32\ntvdm64.dll2011-07-16 05:37 . 2011-08-10 15:10 421888 ----a-w- c:\windows\system32\KernelBase.dll2011-07-16 05:21 . 2011-08-10 15:10 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll2011-07-16 05:21 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll2011-07-16 04:29 . 2011-08-10 15:10 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll2011-07-16 04:26 . 2011-08-10 15:10 44032 ----a-w- c:\windows\apppatch\acwow64.dll2011-07-16 04:25 . 2011-08-10 15:10 25600 ----a-w- c:\windows\SysWow64\setup16.exe2011-07-16 04:24 . 2011-08-10 15:10 5120 ----a-w- c:\windows\SysWow64\wow32.dll2011-07-16 04:24 . 2011-08-10 15:10 272384 ----a-w- c:\windows\SysWow64\KernelBase.dll2011-07-16 04:15 . 2011-08-10 15:10 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 5120 ---ha-w- c:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll2011-07-16 04:15 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-console-l1-1-0.dll2011-07-16 02:21 . 2011-08-10 15:10 7680 ----a-w- c:\windows\SysWow64\instnm.exe2011-07-16 02:21 . 2011-08-10 15:10 2048 ----a-w- c:\windows\SysWow64\user.exe2011-07-16 02:17 . 2011-08-10 15:10 6144 ---ha-w- c:\windows\SysWow64\api-ms-win-security-base-l1-1-0.dll2011-07-16 02:17 . 2011-08-10 15:10 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll2011-07-16 02:17 . 2011-08-10 15:10 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll2011-07-16 02:17 . 2011-08-10 15:10 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll..((((((((((((((((((((((((((((( SnapShot@2011-10-11_03.52.45 ))))))))))))))))))))))))))))))))))))))))).- 2009-07-14 04:54 . 2011-10-11 03:47 98304 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat+ 2009-07-14 04:54 . 2011-10-12 11:00 98304 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat+ 2011-10-12 10:49 . 2011-10-12 10:44 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012011101220111013\index.dat+ 2010-11-21 03:09 . 2011-10-11 15:02 36156 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin+ 2009-07-14 05:10 . 2011-10-12 10:44 44470 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin+ 2011-06-05 22:21 . 2011-10-12 10:44 10070 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2050267592-1898014992-1162686773-1001_UserData.bin+ 2011-06-06 21:23 . 2011-10-12 11:00 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat- 2011-06-06 21:23 . 2011-10-11 02:13 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat+ 2011-06-06 21:23 . 2011-10-12 11:00 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat- 2011-06-06 21:23 . 2011-10-11 02:13 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat+ 2011-06-06 21:23 . 2011-10-12 11:00 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat- 2011-06-06 21:23 . 2011-10-11 02:13 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat+ 2011-06-06 21:23 . 2011-10-12 11:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat- 2011-06-06 21:23 . 2011-10-11 03:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat- 2011-06-06 21:23 . 2011-10-11 03:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat+ 2011-06-06 21:23 . 2011-10-12 11:00 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat- 2011-10-11 03:52 . 2011-10-11 03:52 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat+ 2011-10-12 11:00 . 2011-10-12 11:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat- 2011-06-05 22:19 . 2011-10-11 03:47 262144 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat+ 2011-06-05 22:19 . 2011-10-12 10:55 262144 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat+ 2009-07-14 04:54 . 2011-10-12 11:00 114688 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat- 2009-07-14 04:54 . 2011-10-11 03:47 114688 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat- 2009-07-14 05:01 . 2011-10-11 03:51 276452 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat+ 2009-07-14 05:01 . 2011-10-12 10:59 276452 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat- 2009-07-14 04:54 . 2011-10-11 03:47 1835008 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat+ 2009-07-14 04:54 . 2011-10-12 11:00 1835008 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4.[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Aim"="c:\program files (x86)\AIM\aim.exe" [2011-05-03 4321112].[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]"ConsentPromptBehaviorAdmin"= 0 (0x0)"ConsentPromptBehaviorUser"= 3 (0x3)"EnableLUA"= 0 (0x0)"EnableUIADesktopToggle"= 0 (0x0)"PromptOnSecureDesktop"= 0 (0x0).[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]"aux2"=wdmaud.drv.R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]R2 WPDBusEnum32;Portable Device Enumerator Service ;c:\windows\system32\iprtrmgr32.exe [x]R3 dump_wmimmc;dump_wmimmc;c:\ijji\ENGLISH\Gunz\GameGuard\dump_wmimmc.sys [x]R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]R3 rtl8192U;Realtek RTL8192u 802.11n Wireless LAN USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\rtl8192U.sys [x]R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\System32\Drivers\usbaapl64.sys [x]R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1206000.01D\SYMDS64.SYS [x]S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1206000.01D\SYMEFA64.SYS [x]S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20110929.001\BHDrvx64.sys [2011-09-29 1152632]S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20111011.030\IDSvia64.sys [2011-09-09 488568]S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1206000.01D\Ironx64.SYS [x]S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1206000.01D\SYMNETS.SYS [x]S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe [2011-04-17 130008]S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2011-04-01 428640]S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-09-12 136824]S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys [x]S3 LVUVC64;Logitech Webcam 200(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys [x]S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]...--------- x86-64 -----------..------- Supplementary Scan -------.uLocal Page = c:\windows\system32\blank.htmuStart Page = hxxp://www.google.com/mLocal Page = c:\windows\SysWOW64\blank.htmTCP: DhcpNameServer = 192.168.0.1FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\bjdentvq.default\FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/FF - Ext: Skype extension: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}FF - Ext: Aero Fox XL: {5c8bfb7c-9a54-11dc-8314-0800200c9a66} - %profile%\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}FF - Ext: Symantec IPS: {BBDA0591-3099-440a-AA10-41764D9DB4DB} - c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgnFF - Ext: Norton Toolbar: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62} - c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_2_3FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false..[HKEY_LOCAL_MACHINE\system\ControlSet001\services\NIS]"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\18.6.0.29\diMaster.dll\" /prefetch:1".[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]"ImagePath"="c:\windows\system32\GameMon.des -service".--------------------- LOCKED REGISTRY KEYS ---------------------.[HKEY_USERS\S-1-5-21-2050267592-1898014992-1162686773-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0E223454-2F23-9CBF-E71C-F862DFDF8051}*]"bbccbcpfanmoobpmfmdfmpihkdmjmdcbcbbe"=hex:61,62,66,64,6b,66,61,67,67,68,67,67, 66,62,6f,66,69,66,6a,6e,62,69,67,62,62,68,66,6d,61,70,70,6a,6d,63,00,75"abccbcpfanmoobpmfmcfloalajikhhioaf"=hex:61,62,61,64,65,64,69,64,69,68,63,69, 66,6d,6b,6f,63,6d,6c,67,69,61,62,67,6d,65,64,63,69,6b,6f,6d,6c,70,00,75.[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]@Denied: (A 2) (Everyone)@="FlashBroker""LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10r_ActiveX.exe,-101".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]"Enabled"=dword:00000001.[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10r_ActiveX.exe".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]@Denied: (A 2) (Everyone)@="Shockwave Flash Object".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10r.ocx""ThreadingModel"="Apartment".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]@="0".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]@="ShockwaveFlash.ShockwaveFlash.10".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10r.ocx, 1".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]@="{D27CDB6B-AE6D-11cf-96B8-444553540000}".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]@="1.0".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]@="ShockwaveFlash.ShockwaveFlash".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]@Denied: (A 2) (Everyone)@="Macromedia Flash Factory Object".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10r.ocx""ThreadingModel"="Apartment".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]@="FlashFactory.FlashFactory.1".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10r.ocx, 1".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]@="{D27CDB6B-AE6D-11cf-96B8-444553540000}".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]@="1.0".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]@="FlashFactory.FlashFactory".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]@Denied: (A 2) (Everyone)@="IFlashBroker4".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]@="{00020424-0000-0000-C000-000000000046}".[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}""Version"="1.0".------------------------ Other Running Processes ------------------------.c:\\.\globalroot\systemroot\svchost.exec:\\.\globalroot\systemroot\svchost.exe.**************************************************************************.Completion time: 2011-10-12 07:02:39 - machine was rebootedComboFix-quarantined-files.txt 2011-10-12 11:02ComboFix2.txt 2011-10-11 03:55.Pre-Run: 441,277,775,872 bytes freePost-Run: 441,472,045,056 bytes free.- - End Of File - - C78BC7A0B9E18D28F8E7DB441BE4B846 Link to post Share on other sites More sharing options...
HeroWai Posted October 12, 2011 Author ID:485081 Share Posted October 12, 2011 How do I know if CFScript worked? It disappeared from my desktop after my computer restarted. Link to post Share on other sites More sharing options...
LDTate Posted October 12, 2011 ID:485123 Share Posted October 12, 2011 How do I know if CFScript worked? It disappeared from my desktop after my computer restarted.You can tell by the deletions.How's it running now? Link to post Share on other sites More sharing options...
HeroWai Posted October 13, 2011 Author ID:485219 Share Posted October 13, 2011 There are still times where it lags so much, I'm not able to go on any web pages. Link to post Share on other sites More sharing options...
LDTate Posted October 13, 2011 ID:485279 Share Posted October 13, 2011 You could try and uninstall Norton's and go with a different AV. Link to post Share on other sites More sharing options...
HeroWai Posted October 14, 2011 Author ID:485632 Share Posted October 14, 2011 So what about the svchost.exe that malwarebytes keeps picking up as a virus? Link to post Share on other sites More sharing options...
LDTate Posted October 14, 2011 ID:485691 Share Posted October 14, 2011 There are still times where it lags so much, I'm not able to go on any web pages.So what about the svchost.exe that malwarebytes keeps picking up as a virus?I was trying to answer your first question.Do this:Next:Note: if the Cure option is not there, please select 'Skip'. Please read carefully and follow these steps. Download TDSSKiller and save it to your Desktop.Extract its contents to your desktop.Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.If an infected file is detected, the default action will be Cure, click on Continue.If a suspicious file is detected, the default action will be Skip, click on Continue.It may ask you to reboot the computer to complete the process. Click on Reboot Now.If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.please post the contents of that log TDSSKiller log.Also please describe how your computer behaves at the moment. Link to post Share on other sites More sharing options...
HeroWai Posted October 14, 2011 Author ID:485807 Share Posted October 14, 2011 14:11:10.0230 3464 TDSS rootkit removing tool 2.6.9.0 Oct 14 2011 11:33:2414:11:11.0666 3464 ============================================================14:11:11.0666 3464 Current date / time: 2011/10/14 14:11:11.066614:11:11.0666 3464 SystemInfo:14:11:11.0666 3464 14:11:11.0666 3464 OS Version: 6.1.7601 ServicePack: 1.014:11:11.0666 3464 Product type: Workstation14:11:11.0666 3464 ComputerName: OWNER-PC14:11:11.0666 3464 UserName: Owner14:11:11.0666 3464 Windows directory: C:\Windows14:11:11.0666 3464 System windows directory: C:\Windows14:11:11.0666 3464 Running under WOW6414:11:11.0666 3464 Processor architecture: Intel x6414:11:11.0666 3464 Number of processors: 214:11:11.0666 3464 Page size: 0x100014:11:11.0666 3464 Boot type: Normal boot14:11:11.0666 3464 ============================================================14:11:12.0446 3464 Initialize success14:11:26.0049 3684 ============================================================14:11:26.0049 3684 Scan started14:11:26.0049 3684 Mode: Manual; SigCheck; TDLFS; 14:11:26.0049 3684 ============================================================14:11:27.0609 3684 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys14:11:27.0702 3684 1394ohci - ok14:11:27.0718 3684 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys14:11:27.0734 3684 ACPI - ok14:11:27.0749 3684 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys14:11:27.0812 3684 AcpiPmi - ok14:11:27.0858 3684 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys14:11:27.0874 3684 adp94xx - ok14:11:27.0890 3684 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys14:11:27.0905 3684 adpahci - ok14:11:27.0921 3684 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys14:11:27.0936 3684 adpu320 - ok14:11:27.0983 3684 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys14:11:28.0046 3684 AFD - ok14:11:28.0061 3684 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys14:11:28.0061 3684 agp440 - ok14:11:28.0108 3684 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys14:11:28.0124 3684 aliide - ok14:11:28.0155 3684 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys14:11:28.0170 3684 amdide - ok14:11:28.0202 3684 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys14:11:28.0217 3684 AmdK8 - ok14:11:28.0358 3684 amdkmdag (60216b0e704584de6d5a9f59e9c34c47) C:\Windows\system32\DRIVERS\atikmdag.sys14:11:28.0560 3684 amdkmdag - ok14:11:28.0592 3684 amdkmdap (6b4e9261b613b047a9a145f328889968) C:\Windows\system32\DRIVERS\atikmpag.sys14:11:28.0623 3684 amdkmdap - ok14:11:28.0638 3684 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys14:11:28.0670 3684 AmdPPM - ok14:11:28.0701 3684 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys14:11:28.0701 3684 amdsata - ok14:11:28.0732 3684 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys14:11:28.0748 3684 amdsbs - ok14:11:28.0748 3684 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys14:11:28.0763 3684 amdxata - ok14:11:28.0794 3684 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys14:11:28.0904 3684 AppID - ok14:11:28.0950 3684 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys14:11:28.0950 3684 arc - ok14:11:28.0982 3684 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys14:11:28.0982 3684 arcsas - ok14:11:29.0013 3684 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys14:11:29.0122 3684 AsyncMac - ok14:11:29.0138 3684 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys14:11:29.0153 3684 atapi - ok14:11:29.0216 3684 AtiHDAudioService (cbd14f698def12ee3557604b726cb8eb) C:\Windows\system32\drivers\AtihdW76.sys14:11:29.0262 3684 AtiHDAudioService - ok14:11:29.0403 3684 atikmdag (60216b0e704584de6d5a9f59e9c34c47) C:\Windows\system32\DRIVERS\atikmdag.sys14:11:29.0481 3684 atikmdag - ok14:11:29.0528 3684 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys14:11:29.0590 3684 b06bdrv - ok14:11:29.0621 3684 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys14:11:29.0652 3684 b57nd60a - ok14:11:29.0684 3684 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys14:11:29.0730 3684 Beep - ok14:11:29.0902 3684 BHDrvx64 (9e064b36ac74fb81ad04e0074c17b6be) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20110929.001\BHDrvx64.sys14:11:29.0918 3684 BHDrvx64 - ok14:11:29.0949 3684 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys14:11:29.0964 3684 blbdrive - ok14:11:29.0996 3684 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys14:11:30.0042 3684 bowser - ok14:11:30.0058 3684 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys14:11:30.0074 3684 BrFiltLo - ok14:11:30.0105 3684 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys14:11:30.0105 3684 BrFiltUp - ok14:11:30.0152 3684 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys14:11:30.0183 3684 Brserid - ok14:11:30.0214 3684 BrSerIf (34f6c504b150f99dae69d7073d2a4df4) C:\Windows\system32\DRIVERS\BrSerIf.sys14:11:30.0245 3684 BrSerIf - ok14:11:30.0261 3684 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys14:11:30.0276 3684 BrSerWdm - ok14:11:30.0308 3684 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys14:11:30.0323 3684 BrUsbMdm - ok14:11:30.0339 3684 BrUsbSer (601cb966fffebc6806626dc8e7aa0ef2) C:\Windows\system32\DRIVERS\BrUsbSer.sys14:11:30.0370 3684 BrUsbSer - ok14:11:30.0401 3684 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys14:11:30.0464 3684 BTHMODEM - ok14:11:30.0479 3684 catchme - ok14:11:30.0510 3684 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys14:11:30.0542 3684 cdfs - ok14:11:30.0588 3684 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys14:11:30.0604 3684 cdrom - ok14:11:30.0666 3684 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys14:11:30.0682 3684 circlass - ok14:11:30.0713 3684 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys14:11:30.0729 3684 CLFS - ok14:11:30.0760 3684 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\drivers\CmBatt.sys14:11:30.0791 3684 CmBatt - ok14:11:30.0807 3684 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys14:11:30.0822 3684 cmdide - ok14:11:30.0854 3684 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys14:11:30.0885 3684 CNG - ok14:11:30.0900 3684 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys14:11:30.0900 3684 Compbatt - ok14:11:30.0932 3684 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\DRIVERS\CompositeBus.sys14:11:30.0963 3684 CompositeBus - ok14:11:30.0978 3684 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys14:11:30.0994 3684 crcdisk - ok14:11:31.0025 3684 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys14:11:31.0072 3684 DfsC - ok14:11:31.0103 3684 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys14:11:31.0134 3684 discache - ok14:11:31.0166 3684 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys14:11:31.0166 3684 Disk - ok14:11:31.0212 3684 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys14:11:31.0228 3684 drmkaud - ok14:11:31.0259 3684 dump_wmimmc - ok14:11:31.0290 3684 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys14:11:31.0322 3684 DXGKrnl - ok14:11:31.0337 3684 E100B (a6db3a7828b456a574243066e2e77d8c) C:\Windows\system32\DRIVERS\efe5b32e.sys14:11:31.0353 3684 E100B - ok14:11:31.0384 3684 EagleX64 - ok14:11:31.0446 3684 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys14:11:31.0509 3684 ebdrv - ok14:11:31.0571 3684 eeCtrl (5e3a50930447f464c66032e05a4632f5) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys14:11:31.0587 3684 eeCtrl - ok14:11:31.0618 3684 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys14:11:31.0634 3684 elxstor - ok14:11:31.0665 3684 EraserUtilRebootDrv (dcb76ecc6b50a266fdc16e1963ab98ce) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys14:11:31.0680 3684 EraserUtilRebootDrv - ok14:11:31.0696 3684 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys14:11:31.0712 3684 ErrDev - ok14:11:31.0743 3684 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys14:11:31.0774 3684 exfat - ok14:11:31.0790 3684 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys14:11:31.0821 3684 fastfat - ok14:11:31.0852 3684 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys14:11:31.0883 3684 fdc - ok14:11:31.0914 3684 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys14:11:31.0930 3684 FileInfo - ok14:11:31.0930 3684 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys14:11:31.0977 3684 Filetrace - ok14:11:31.0992 3684 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys14:11:32.0008 3684 flpydisk - ok14:11:32.0024 3684 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys14:11:32.0039 3684 FltMgr - ok14:11:32.0055 3684 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys14:11:32.0070 3684 FsDepends - ok14:11:32.0070 3684 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys14:11:32.0086 3684 Fs_Rec - ok14:11:32.0117 3684 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys14:11:32.0133 3684 fvevol - ok14:11:32.0148 3684 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys14:11:32.0164 3684 gagp30kx - ok14:11:32.0180 3684 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys14:11:32.0226 3684 hcw85cir - ok14:11:32.0258 3684 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys14:11:32.0289 3684 HdAudAddService - ok14:11:32.0304 3684 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\DRIVERS\HDAudBus.sys14:11:32.0320 3684 HDAudBus - ok14:11:32.0351 3684 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys14:11:32.0367 3684 HidBatt - ok14:11:32.0382 3684 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys14:11:32.0414 3684 HidBth - ok14:11:32.0445 3684 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys14:11:32.0460 3684 HidIr - ok14:11:32.0492 3684 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys14:11:32.0507 3684 HidUsb - ok14:11:32.0538 3684 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys14:11:32.0554 3684 HpSAMD - ok14:11:32.0585 3684 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys14:11:32.0632 3684 HTTP - ok14:11:32.0663 3684 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys14:11:32.0663 3684 hwpolicy - ok14:11:32.0694 3684 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys14:11:32.0710 3684 i8042prt - ok14:11:32.0757 3684 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys14:11:32.0772 3684 iaStorV - ok14:11:32.0944 3684 IDSVia64 (0b97f1a640ad3d159a7b5d2164c42e50) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20111012.034\IDSvia64.sys14:11:32.0960 3684 IDSVia64 - ok14:11:33.0053 3684 igfx (a87261ef1546325b559374f5689cf5bc) C:\Windows\system32\DRIVERS\igdkmd64.sys14:11:33.0178 3684 igfx - ok14:11:33.0194 3684 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys14:11:33.0209 3684 iirsp - ok14:11:33.0225 3684 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys14:11:33.0240 3684 intelide - ok14:11:33.0256 3684 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys14:11:33.0287 3684 intelppm - ok14:11:33.0303 3684 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys14:11:33.0334 3684 IpFilterDriver - ok14:11:33.0350 3684 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys14:11:33.0350 3684 IPMIDRV - ok14:11:33.0381 3684 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys14:11:33.0412 3684 IPNAT - ok14:11:33.0443 3684 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys14:11:33.0490 3684 IRENUM - ok14:11:33.0490 3684 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys14:11:33.0506 3684 isapnp - ok14:11:33.0521 3684 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys14:11:33.0537 3684 iScsiPrt - ok14:11:33.0568 3684 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys14:11:33.0584 3684 kbdclass - ok14:11:33.0615 3684 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys14:11:33.0630 3684 kbdhid - ok14:11:33.0662 3684 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys14:11:33.0662 3684 KSecDD - ok14:11:33.0677 3684 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys14:11:33.0693 3684 KSecPkg - ok14:11:33.0708 3684 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys14:11:33.0755 3684 ksthunk - ok14:11:33.0786 3684 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys14:11:33.0818 3684 lltdio - ok14:11:33.0849 3684 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys14:11:33.0864 3684 LSI_FC - ok14:11:33.0880 3684 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys14:11:33.0880 3684 LSI_SAS - ok14:11:33.0896 3684 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys14:11:33.0911 3684 LSI_SAS2 - ok14:11:33.0927 3684 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys14:11:33.0942 3684 LSI_SCSI - ok14:11:33.0942 3684 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys14:11:33.0989 3684 luafv - ok14:11:34.0020 3684 LVRS64 (ef586b959f747e74c76603ff16ae417b) C:\Windows\system32\DRIVERS\lvrs64.sys14:11:34.0036 3684 LVRS64 - ok14:11:34.0114 3684 LVUVC64 (edf73bfa1bd24d74d1d64dc0ed28a7cd) C:\Windows\system32\DRIVERS\lvuvc64.sys14:11:34.0161 3684 LVUVC64 - ok14:11:34.0176 3684 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys14:11:34.0192 3684 megasas - ok14:11:34.0223 3684 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys14:11:34.0239 3684 MegaSR - ok14:11:34.0239 3684 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys14:11:34.0286 3684 Modem - ok14:11:34.0301 3684 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys14:11:34.0317 3684 monitor - ok14:11:34.0332 3684 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys14:11:34.0348 3684 mouclass - ok14:11:34.0364 3684 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys14:11:34.0395 3684 mouhid - ok14:11:34.0410 3684 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys14:11:34.0410 3684 mountmgr - ok14:11:34.0426 3684 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys14:11:34.0442 3684 mpio - ok14:11:34.0473 3684 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys14:11:34.0504 3684 mpsdrv - ok14:11:34.0520 3684 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys14:11:34.0551 3684 MRxDAV - ok14:11:34.0566 3684 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys14:11:34.0613 3684 mrxsmb - ok14:11:34.0660 3684 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys14:11:34.0660 3684 mrxsmb10 - ok14:11:34.0676 3684 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys14:11:34.0707 3684 mrxsmb20 - ok14:11:34.0722 3684 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys14:11:34.0738 3684 msahci - ok14:11:34.0738 3684 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys14:11:34.0754 3684 msdsm - ok14:11:34.0769 3684 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys14:11:34.0800 3684 Msfs - ok14:11:34.0816 3684 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys14:11:34.0847 3684 mshidkmdf - ok14:11:34.0847 3684 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys14:11:34.0863 3684 msisadrv - ok14:11:34.0894 3684 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys14:11:34.0925 3684 MSKSSRV - ok14:11:34.0941 3684 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys14:11:34.0988 3684 MSPCLOCK - ok14:11:35.0003 3684 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys14:11:35.0050 3684 MSPQM - ok14:11:35.0066 3684 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys14:11:35.0081 3684 MsRPC - ok14:11:35.0112 3684 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys14:11:35.0112 3684 mssmbios - ok14:11:35.0128 3684 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys14:11:35.0175 3684 MSTEE - ok14:11:35.0175 3684 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys14:11:35.0206 3684 MTConfig - ok14:11:35.0237 3684 MTsensor (03b7145c889603537e9ffeabb1ad1089) C:\Windows\system32\DRIVERS\ASACPI.sys14:11:35.0268 3684 MTsensor - ok14:11:35.0284 3684 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys14:11:35.0284 3684 Mup - ok14:11:35.0315 3684 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys14:11:35.0362 3684 NativeWifiP - ok14:11:35.0487 3684 NAVENG (2dbe90210de76be6e1653bb20ec70ec2) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20111013.019\ENG64.SYS14:11:35.0502 3684 NAVENG - ok14:11:35.0549 3684 NAVEX15 (346da70e203b8e2c850277713de8f71b) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20111013.019\EX64.SYS14:11:35.0565 3684 NAVEX15 - ok14:11:35.0612 3684 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys14:11:35.0627 3684 NDIS - ok14:11:35.0643 3684 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys14:11:35.0674 3684 NdisCap - ok14:11:35.0705 3684 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys14:11:35.0752 3684 NdisTapi - ok14:11:35.0799 3684 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys14:11:35.0830 3684 Ndisuio - ok14:11:35.0846 3684 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys14:11:35.0892 3684 NdisWan - ok14:11:35.0908 3684 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys14:11:35.0939 3684 NDProxy - ok14:11:35.0955 3684 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys14:11:35.0986 3684 NetBIOS - ok14:11:35.0986 3684 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys14:11:36.0017 3684 NetBT - ok14:11:36.0048 3684 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys14:11:36.0048 3684 nfrd960 - ok14:11:36.0095 3684 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys14:11:36.0126 3684 Npfs - ok14:11:36.0158 3684 NPPTNT2 - ok14:11:36.0189 3684 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys14:11:36.0220 3684 nsiproxy - ok14:11:36.0251 3684 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys14:11:36.0298 3684 Ntfs - ok14:11:36.0298 3684 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys14:11:36.0345 3684 Null - ok14:11:36.0376 3684 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys14:11:36.0392 3684 nvraid - ok14:11:36.0407 3684 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys14:11:36.0423 3684 nvstor - ok14:11:36.0438 3684 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys14:11:36.0454 3684 nv_agp - ok14:11:36.0470 3684 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys14:11:36.0501 3684 ohci1394 - ok14:11:36.0532 3684 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys14:11:36.0548 3684 Parport - ok14:11:36.0548 3684 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys14:11:36.0563 3684 partmgr - ok14:11:36.0594 3684 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys14:11:36.0610 3684 pci - ok14:11:36.0610 3684 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys14:11:36.0626 3684 pciide - ok14:11:36.0641 3684 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys14:11:36.0657 3684 pcmcia - ok14:11:36.0672 3684 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys14:11:36.0688 3684 pcw - ok14:11:36.0704 3684 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys14:11:36.0750 3684 PEAUTH - ok14:11:36.0797 3684 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys14:11:36.0860 3684 PptpMiniport - ok14:11:36.0875 3684 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys14:11:36.0891 3684 Processor - ok14:11:36.0922 3684 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys14:11:36.0969 3684 Psched - ok14:11:37.0000 3684 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys14:11:37.0047 3684 ql2300 - ok14:11:37.0062 3684 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys14:11:37.0062 3684 ql40xx - ok14:11:37.0094 3684 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys14:11:37.0109 3684 QWAVEdrv - ok14:11:37.0125 3684 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys14:11:37.0156 3684 RasAcd - ok14:11:37.0156 3684 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys14:11:37.0187 3684 RasAgileVpn - ok14:11:37.0203 3684 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys14:11:37.0250 3684 Rasl2tp - ok14:11:37.0265 3684 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys14:11:37.0312 3684 RasPppoe - ok14:11:37.0328 3684 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys14:11:37.0359 3684 RasSstp - ok14:11:37.0374 3684 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys14:11:37.0421 3684 rdbss - ok14:11:37.0437 3684 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\drivers\rdpbus.sys14:11:37.0452 3684 rdpbus - ok14:11:37.0468 3684 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys14:11:37.0499 3684 RDPCDD - ok14:11:37.0515 3684 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys14:11:37.0562 3684 RDPENCDD - ok14:11:37.0577 3684 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys14:11:37.0608 3684 RDPREFMP - ok14:11:37.0624 3684 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys14:11:37.0655 3684 RDPWD - ok14:11:37.0686 3684 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys14:11:37.0702 3684 rdyboost - ok14:11:37.0733 3684 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys14:11:37.0780 3684 rspndr - ok14:11:37.0827 3684 RTL8167 (16d4e350420baa7e63e16e3fc033e1f5) C:\Windows\system32\DRIVERS\Rt64win7.sys14:11:37.0842 3684 RTL8167 - ok14:11:37.0889 3684 rtl8192U (7c9cc15879866c1b6516afd785593e3f) C:\Windows\system32\DRIVERS\rtl8192U.sys14:11:37.0936 3684 rtl8192U - ok14:11:37.0952 3684 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys14:11:37.0967 3684 sbp2port - ok14:11:37.0983 3684 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys14:11:38.0014 3684 scfilter - ok14:11:38.0045 3684 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys14:11:38.0076 3684 secdrv - ok14:11:38.0108 3684 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys14:11:38.0123 3684 Serenum - ok14:11:38.0154 3684 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys14:11:38.0186 3684 Serial - ok14:11:38.0186 3684 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys14:11:38.0201 3684 sermouse - ok14:11:38.0232 3684 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys14:11:38.0248 3684 sffdisk - ok14:11:38.0264 3684 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys14:11:38.0295 3684 sffp_mmc - ok14:11:38.0310 3684 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys14:11:38.0326 3684 sffp_sd - ok14:11:38.0326 3684 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys14:11:38.0342 3684 sfloppy - ok14:11:38.0373 3684 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys14:11:38.0373 3684 SiSRaid2 - ok14:11:38.0404 3684 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys14:11:38.0404 3684 SiSRaid4 - ok14:11:38.0420 3684 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys14:11:38.0466 3684 Smb - ok14:11:38.0482 3684 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys14:11:38.0513 3684 spldr - ok14:11:38.0576 3684 SRTSP (90ef30c3867bcde4579c01a6d6e75a7a) C:\Windows\System32\Drivers\NISx64\1206000.01D\SRTSP64.SYS14:11:38.0591 3684 SRTSP - ok14:11:38.0622 3684 SRTSPX (c513e8a5e7978da49077f5484344ee1b) C:\Windows\system32\drivers\NISx64\1206000.01D\SRTSPX64.SYS14:11:38.0638 3684 SRTSPX - ok14:11:38.0654 3684 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys14:11:38.0716 3684 srv - ok14:11:38.0747 3684 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys14:11:38.0763 3684 srv2 - ok14:11:38.0794 3684 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys14:11:38.0825 3684 srvnet - ok14:11:38.0856 3684 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys14:11:38.0872 3684 stexstor - ok14:11:38.0888 3684 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys14:11:38.0903 3684 swenum - ok14:11:38.0981 3684 SymDS (6160145c7a87fc7672e8e3b886888176) C:\Windows\system32\drivers\NISx64\1206000.01D\SYMDS64.SYS14:11:38.0981 3684 SymDS - ok14:11:39.0028 3684 SymEFA (96aeed40d4d3521568b42027687e69e0) C:\Windows\system32\drivers\NISx64\1206000.01D\SYMEFA64.SYS14:11:39.0059 3684 SymEFA - ok14:11:39.0090 3684 SymEvent (21a1c2d694c3cf962d31f5e873ab3d6f) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS14:11:39.0106 3684 SymEvent - ok14:11:39.0122 3684 SymIM (3aa3b2df451da88c38ab00b19fa3562e) C:\Windows\system32\DRIVERS\SymIMv.sys14:11:39.0137 3684 SymIM - ok14:11:39.0168 3684 SymIRON (bd0d711d8cbfcaa19ca123306eaf53a5) C:\Windows\system32\drivers\NISx64\1206000.01D\Ironx64.SYS14:11:39.0168 3684 SymIRON - ok14:11:39.0200 3684 SymNetS (a6adb3d83023f8daa0f7b6fda785d83b) C:\Windows\System32\Drivers\NISx64\1206000.01D\SYMNETS.SYS14:11:39.0200 3684 SymNetS - ok14:11:39.0262 3684 Tcpip (f0e98c00a09fdf791525829a1d14240f) C:\Windows\system32\drivers\tcpip.sys14:11:39.0324 3684 Tcpip - ok14:11:39.0356 3684 TCPIP6 (f0e98c00a09fdf791525829a1d14240f) C:\Windows\system32\DRIVERS\tcpip.sys14:11:39.0387 3684 TCPIP6 - ok14:11:39.0418 3684 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys14:11:39.0465 3684 tcpipreg - ok14:11:39.0480 3684 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys14:11:39.0527 3684 TDPIPE - ok14:11:39.0543 3684 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys14:11:39.0574 3684 TDTCP - ok14:11:39.0605 3684 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys14:11:39.0621 3684 tdx - ok14:11:39.0636 3684 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\DRIVERS\termdd.sys14:11:39.0652 3684 TermDD - ok14:11:39.0683 3684 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys14:11:39.0714 3684 tssecsrv - ok14:11:39.0730 3684 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys14:11:39.0761 3684 TsUsbFlt - ok14:11:39.0777 3684 TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys14:11:39.0777 3684 TsUsbGD - ok14:11:39.0808 3684 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys14:11:39.0839 3684 tunnel - ok14:11:39.0855 3684 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys14:11:39.0870 3684 uagp35 - ok14:11:39.0886 3684 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys14:11:39.0933 3684 udfs - ok14:11:39.0964 3684 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys14:11:39.0964 3684 uliagpkx - ok14:11:39.0980 3684 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys14:11:39.0995 3684 umbus - ok14:11:40.0011 3684 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys14:11:40.0026 3684 UmPass - ok14:11:40.0073 3684 USBAAPL64 (54d4b48d443e7228bf64cf7cdc3118ac) C:\Windows\System32\Drivers\usbaapl64.sys14:11:40.0120 3684 USBAAPL64 - ok14:11:40.0151 3684 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys14:11:40.0167 3684 usbaudio - ok14:11:40.0198 3684 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys14:11:40.0245 3684 usbccgp - ok14:11:40.0260 3684 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys14:11:40.0276 3684 usbcir - ok14:11:40.0323 3684 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys14:11:40.0338 3684 usbehci - ok14:11:40.0354 3684 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys14:11:40.0385 3684 usbhub - ok14:11:40.0401 3684 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys14:11:40.0432 3684 usbohci - ok14:11:40.0463 3684 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys14:11:40.0479 3684 usbprint - ok14:11:40.0494 3684 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys14:11:40.0526 3684 usbscan - ok14:11:40.0557 3684 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS14:11:40.0588 3684 USBSTOR - ok14:11:40.0604 3684 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\DRIVERS\usbuhci.sys14:11:40.0619 3684 usbuhci - ok14:11:40.0666 3684 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys14:11:40.0682 3684 vdrvroot - ok14:11:40.0697 3684 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys14:11:40.0713 3684 vga - ok14:11:40.0744 3684 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys14:11:40.0775 3684 VgaSave - ok14:11:40.0791 3684 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys14:11:40.0806 3684 vhdmp - ok14:11:40.0822 3684 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys14:11:40.0838 3684 viaide - ok14:11:40.0853 3684 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys14:11:40.0869 3684 volmgr - ok14:11:40.0884 3684 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys14:11:40.0900 3684 volmgrx - ok14:11:40.0931 3684 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys14:11:40.0947 3684 volsnap - ok14:11:40.0962 3684 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys14:11:40.0978 3684 vsmraid - ok14:11:40.0994 3684 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys14:11:41.0009 3684 vwifibus - ok14:11:41.0025 3684 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys14:11:41.0056 3684 vwififlt - ok14:11:41.0072 3684 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys14:11:41.0072 3684 WacomPen - ok14:11:41.0118 3684 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys14:11:41.0150 3684 WANARP - ok14:11:41.0165 3684 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys14:11:41.0196 3684 Wanarpv6 - ok14:11:41.0228 3684 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys14:11:41.0243 3684 Wd - ok14:11:41.0259 3684 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys14:11:41.0290 3684 Wdf01000 - ok14:11:41.0306 3684 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys14:11:41.0337 3684 WfpLwf - ok14:11:41.0352 3684 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys14:11:41.0368 3684 WIMMount - ok14:11:41.0399 3684 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys14:11:41.0415 3684 WmiAcpi - ok14:11:41.0446 3684 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys14:11:41.0477 3684 ws2ifsl - ok14:11:41.0508 3684 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys14:11:41.0555 3684 WudfPf - ok14:11:41.0571 3684 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys14:11:41.0618 3684 WUDFRd - ok14:11:41.0633 3684 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR014:11:41.0727 3684 \Device\Harddisk0\DR0 ( TDSS File System ) - warning14:11:41.0727 3684 \Device\Harddisk0\DR0 - detected TDSS File System (1)14:11:41.0742 3684 Boot (0x1200) (bf8850365952c6225629482c48c763d3) \Device\Harddisk0\DR0\Partition014:11:41.0742 3684 \Device\Harddisk0\DR0\Partition0 - ok14:11:41.0742 3684 ============================================================14:11:41.0742 3684 Scan finished14:11:41.0742 3684 ============================================================14:11:41.0742 3676 Detected object count: 114:11:41.0742 3676 Actual detected object count: 114:13:01.0392 3676 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user14:13:01.0392 3676 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip Link to post Share on other sites More sharing options...
HeroWai Posted October 14, 2011 Author ID:485808 Share Posted October 14, 2011 As always it's fine when I start my computer but it'll probably slow down later on. I'll try to post when it does. Link to post Share on other sites More sharing options...
LDTate Posted October 14, 2011 ID:485809 Share Posted October 14, 2011 Please download Dr.Web CureIt . Save it to your desktop:Doubleclick the drweb-cureit.exe file and click Scan to run express scan. Click OK in the pop-up window to allow the scan.This will scan the files currently running in memory and if something is found, click the Yes button when it asks you if you want to cure it. This is only a short scan.Once the short scan has finished, select Complete scan.Click the green arrow at the right, and the scan will start.Click Yes to all if it asks if you want to cure/move the file.When the scan has finished, in the menu, click File and choose Save report listSave the report to your desktop. The report will be called DrWeb.csvNote:this report may need to be renamed to Dr.Web.txt in order to post it on the forum.Please post the Dr.Web.txt report in your next replyClose Dr.Web Cureit.Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.NOTE. During the scan, pop-up window will open asking for full version purchase. Simply close the window by clicking on the X in the upper right corner. Link to post Share on other sites More sharing options...
HeroWai Posted October 17, 2011 Author ID:486359 Share Posted October 17, 2011 The "save report list" was white so I couldn't save it. Link to post Share on other sites More sharing options...
LDTate Posted October 17, 2011 ID:486435 Share Posted October 17, 2011 Please download DDS by sUBs from one of the following links and save it to your desktop.DDS.scrDDS.pif[*]Disable any script blocking protection (How to Disable your Security Programs)[*]Double click DDS icon to run the tool (may take up to 3 minutes to run)[*]When done, DDS.txt will open. [*]After a few moments, attach.txt will open in a second window.[*]Save both reports to your desktop.---------------------------------------------------Post the contents of the DDS.txt in your next reply Link to post Share on other sites More sharing options...
HeroWai Posted October 17, 2011 Author ID:486474 Share Posted October 17, 2011 .DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_22Run by Owner at 9:52:59 on 2011-10-17Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4095.2809 [GMT -4:00].AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}SP: Norton Internet Security *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}.============== Running Processes ===============.C:\Windows\system32\wininit.exeC:\Windows\system32\lsm.exeC:\Windows\system32\svchost.exe -k DcomLaunchC:\Windows\system32\svchost.exe -k RPCSSC:\Windows\system32\atiesrxx.exeC:\Windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC:\Windows\System32\svchost.exe -k LocalSystemNetworkRestrictedC:\Windows\system32\svchost.exe -k netsvcsC:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exeC:\Windows\system32\svchost.exe -k LocalServiceC:\Windows\system32\atieclxx.exeC:\Windows\system32\svchost.exe -k NetworkServiceC:\Windows\System32\spoolsv.exeC:\Windows\system32\svchost.exe -k LocalServiceNoNetworkC:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Windows\system32\taskhost.exeC:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exeC:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exeC:\Windows\system32\svchost.exe -k imgsvcC:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exeC:\Windows\system32\SearchIndexer.exeC:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestrictedC:\Program Files\Windows Media Player\wmpnetwk.exeC:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonationC:\Windows\System32\svchost.exe -k LocalServicePeerNetC:\Program Files (x86)\Mozilla Firefox\firefox.exeC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Windows\system32\wbem\wmiprvse.exeC:\Windows\system32\vssvc.exeC:\Windows\System32\svchost.exe -k swprvC:\Windows\SysWOW64\NOTEPAD.EXEC:\Windows\system32\SearchProtocolHost.exeC:\Windows\system32\SearchFilterHost.exeC:\Windows\SysWOW64\cmd.exeC:\Windows\system32\conhost.exeC:\Windows\SysWOW64\cscript.exe.============== Pseudo HJT Report ===============.uStart Page = hxxp://www.google.com/BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllBHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dllBHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dllBHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\IPS\IPSBHO.DLLBHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dllBHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dllTB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dlluRun: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-USmPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)mPolicies-system: EnableLUA = 0 (0x0)mPolicies-system: EnableUIADesktopToggle = 0 (0x0)mPolicies-system: PromptOnSecureDesktop = 0 (0x0)IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dllDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cabDPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabTCP: DhcpNameServer = 192.168.0.1TCP: Interfaces\{4057281C-D5E6-47EB-9945-AFAF1A903F5A} : DhcpNameServer = 192.168.0.1TCP: Interfaces\{E18442BE-B811-40D3-932D-93AE698C8FCE} : DhcpNameServer = 192.168.0.250 208.67.222.222 208.67.220.220TCP: Interfaces\{E18442BE-B811-40D3-932D-93AE698C8FCE}\D61696E60736D2F60756E6 : DhcpNameServer = 188.229.88.7Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dllBHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllBHO-X64: AcroIEHelperStub - No FileBHO-X64: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dllBHO-X64: Increase performance and video formats for your HTML5 <video> - No FileBHO-X64: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dllBHO-X64: Symantec NCO BHO - No FileBHO-X64: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\IPS\IPSBHO.DLLBHO-X64: Symantec Intrusion Prevention - No FileBHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dllBHO-X64: SkypeIEPluginBHO - No FileBHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dllTB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll.================= FIREFOX ===================.FF - ProfilePath - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\bjdentvq.default\FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dllFF - component: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_2_3\components\coFFPlgn.dllFF - component: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\components\IPSFFPl.dllFF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dllFF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dllFF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dllFF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dllFF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dllFF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dllFF - plugin: C:\Program Files (x86)\Viewpoint\Viewpoint Media Player\npViewpoint.dllFF - plugin: C:\ProgramData\NexonUS\NGM\npNxGameUS.dllFF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dllFF - Ext: Skype extension: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}FF - Ext: Aero Fox XL: {5c8bfb7c-9a54-11dc-8314-0800200c9a66} - %profile%\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}FF - Ext: Symantec IPS: {BBDA0591-3099-440a-AA10-41764D9DB4DB} - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgnFF - Ext: Norton Toolbar: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62} - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_2_3.---- FIREFOX POLICIES ----FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false.============= SERVICES / DRIVERS ===============.R0 SymDS;Symantec Data Store;C:\Windows\system32\drivers\NISx64\1206000.01D\SYMDS64.SYS --> C:\Windows\system32\drivers\NISx64\1206000.01D\SYMDS64.SYS [?]R0 SymEFA;Symantec Extended File Attributes;C:\Windows\system32\drivers\NISx64\1206000.01D\SYMEFA64.SYS --> C:\Windows\system32\drivers\NISx64\1206000.01D\SYMEFA64.SYS [?]R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20110929.001\BHDrvx64.sys [2011-9-29 1152632]R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20111014.031\IDSviA64.sys [2011-10-14 488568]R1 SymIRON;Symantec Iron Driver;C:\Windows\system32\drivers\NISx64\1206000.01D\Ironx64.SYS --> C:\Windows\system32\drivers\NISx64\1206000.01D\Ironx64.SYS [?]R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\system32\Drivers\NISx64\1206000.01D\SYMNETS.SYS --> C:\Windows\system32\Drivers\NISx64\1206000.01D\SYMNETS.SYS [?]R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]R2 NIS;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccsvchst.exe [2011-9-12 130008]R2 UMVPFSrv;UMVPFSrv;C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2011-4-1 428640]R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-9-12 136824]R3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\system32\DRIVERS\lvrs64.sys --> C:\Windows\system32\DRIVERS\lvrs64.sys [?]R3 LVUVC64;Logitech Webcam 200(UVC);C:\Windows\system32\DRIVERS\lvuvc64.sys --> C:\Windows\system32\DRIVERS\lvuvc64.sys [?]R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]S2 WPDBusEnum32;Portable Device Enumerator Service ;C:\Windows\system32\iprtrmgr32.exe --> C:\Windows\system32\iprtrmgr32.exe [?]S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service --> C:\Windows\system32\GameMon.des -service [?]S3 rtl8192U;Realtek RTL8192u 802.11n Wireless LAN USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\rtl8192U.sys --> C:\Windows\system32\DRIVERS\rtl8192U.sys [?]S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?].=============== Created Last 30 ================.2011-10-14 20:35:17 -------- d-----w- C:\Users\Owner\DoctorWeb2011-10-13 23:00:28 -------- d-sh--w- C:\$RECYCLE.BIN2011-10-13 20:57:56 861696 ----a-w- C:\Windows\System32\oleaut32.dll2011-10-13 20:57:56 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll2011-10-13 20:57:56 331776 ----a-w- C:\Windows\System32\oleacc.dll2011-10-13 20:57:56 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll2011-10-11 03:45:32 98816 ----a-w- C:\Windows\sed.exe2011-10-11 03:45:32 518144 ----a-w- C:\Windows\SWREG.exe2011-10-11 03:45:32 256000 ----a-w- C:\Windows\PEV.exe2011-10-11 03:45:32 208896 ----a-w- C:\Windows\MBR.exe2011-10-07 03:55:47 -------- d-----w- C:\Program Files (x86)\ESET2011-09-30 16:17:30 -------- d-----w- C:\Program Files (x86)\Common Files\Software Update Utility2011-09-30 16:14:58 -------- d-----w- C:\Users\Owner\AppData\Local\AOL OCP2011-09-30 16:14:49 180293 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npViewpoint.dll2011-09-30 16:14:49 -------- d-----w- C:\ProgramData\Viewpoint2011-09-30 16:14:48 -------- d-----w- C:\ProgramData\acccore2011-09-30 16:14:48 -------- d-----w- C:\Program Files (x86)\Viewpoint.==================== Find3M ====================.2011-10-01 03:25:37 1638912 ----a-w- C:\Windows\System32\mshtml.tlb2011-10-01 02:42:56 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb2011-09-28 05:29:56 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl2011-09-12 22:02:04 174200 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS2011-09-06 03:03:17 3138048 ----a-w- C:\Windows\System32\win32k.sys2011-08-31 21:00:50 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys2011-08-20 05:37:58 1188864 ----a-w- C:\Windows\System32\wininet.dll2011-08-20 04:31:05 981504 ----a-w- C:\Windows\SysWow64\wininet.dll2011-08-17 05:26:46 613888 ----a-w- C:\Windows\System32\psisdecd.dll2011-08-17 05:25:08 108032 ----a-w- C:\Windows\System32\psisrndr.ax2011-08-17 04:24:12 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll2011-08-17 04:19:27 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax.============= FINISH: 9:53:14.63 =============== Link to post Share on other sites More sharing options...
LDTate Posted October 17, 2011 ID:486476 Share Posted October 17, 2011 Nothing bad there that I can see.Run a new Combofix scan Link to post Share on other sites More sharing options...
Recommended Posts