Solved "Trojan, Alureon, Winrscmde"

EJF

Member
I am running Vista Home Premium 64bit which has been running perfectly until a week ago when I started getting flashing messages on the bottom of the screen reading "Microsoft Windows".
After running several different malware removal programs, like Hijackthis, Security Essentials, Spybot, Super Anti-Virus, etc., the only one that found the bug in "svchost" was Malwarebytes.
It removed the "Trojan, Alureon, Winrscmde" in both regular mode and safe mode, but keeps coming back.
I have deleted the svchost file in both regular mode and safe mode and it comes back.
Trying the numerous fixes splattered across the internet has accomplished nothing but frustration.
The "svchost" bug has been around since at least 2009 and it is hard to believe that it can not be stopped.
I right clicked on the svchost file, selected media info and found the following:
Graphic interface created by Atak_Snajpera
MediaInfo library created by Zenitram
Homepage: MediaInfo
Support: MediaInfo(Lib) 0.7 - Reading information about media files - Doom9's Forum
Does this mean the malware came from SourceForge?
If anyone knows how to fix this problem, please let me know.
 

My Computer

System One

  • Manufacturer/Model
    MSI/MS7390
    CPU
    AMD Athlon 64 X2 5000
    Motherboard
    MSI K9N SLI-F
    Memory
    Crucial 2048 MBs
    Graphics Card(s)
    ATI Radeon X1550 Series
    Sound Card
    Realtek
    Monitor(s) Displays
    Trinitron
    Screen Resolution
    1600 x 1200 pixels
    Hard Drives
    Western Digital 500 GB
    Western Digital 9 GB
    Maxtor 80 GB External
    Case
    Power Up 5511 Mid Tower ATX Case with 450w Power Supply
    Cooling
    Five Fans
    Keyboard
    Dell QuietKey
    Mouse
    Logitech - Optical
    Internet Speed
    1536 Kb/sec
Hello EJF and welcome to the forums :party:

Can you post the MBAM log for us please? Then we'll have a better idea of what we're dealing with :) Plus any other logs that found anything.

I've used MediaInfo in the past and I've had no problems with it. MediaInfo is a little tool that provides information about media files, it's nothing to be worried about :) It won't work on .exe files, so that's why it isn't displaying anything of use - I've included a MediaInfo log below, just to give you an idea of what it is:

Code:
General
Unique ID                                : 157975856625607031949463150552648332548 (0x76D90B142BFEE675CC058F39EA353504)
Complete name                            : [Th3avatar]_Steins;Gate_NCOP_(1280x720_Blu-Ray_FLAC)_[54BFA0D7].mkv
Format                                   : Matroska
Format version                           : Version 2
File size                                : 107 MiB
Duration                                 : 1mn 35s
Overall bit rate mode                    : Variable
Overall bit rate                         : 9 481 Kbps
Movie name                               : Steins;Gate - NCOP
Encoded date                             : UTC 2012-02-12 11:35:59
Writing application                      : mkvmerge v5.3.0 ('I could have danced') built on Feb  9 2012 10:17:19
Writing library                          : libebml v1.2.2 + libmatroska v1.3.0
Attachment                               : Yes

Video
ID                                       : 1
Format                                   : AVC
Format/Info                              : Advanced Video Codec
Format profile                           : [email protected]
Format settings, CABAC                   : Yes
Format settings, ReFrames                : 11 frames
Codec ID                                 : V_MPEG4/ISO/AVC
Duration                                 : 1mn 35s
Width                                    : 1 280 pixels
Height                                   : 720 pixels
Display aspect ratio                     : 16:9
Frame rate                               : 23.976 fps
Color space                              : YUV
Chroma subsampling                       : 4:2:0
Bit depth                                : 8 bits
Scan type                                : Progressive
Title                                    : [H264]
Writing library                          : x264 core 120 r2127 f33c8cb
Encoding settings                        : cabac=1 / ref=12 / deblock=1:1:1 / analyse=0x3:0x133 / me=umh / subme=10 / psy=1 / psy_rd=1.00:0.00 / mixed_ref=1 / me_range=24 / chroma_me=1 / trellis=2 / 8x8dct=1 / cqm=0 / deadzone=21,11 / fast_pskip=0 / chroma_qp_offset=-4 / threads=8 / sliced_threads=0 / nr=0 / decimate=0 / interlaced=0 / bluray_compat=0 / constrained_intra=0 / bframes=12 / b_pyramid=1 / b_adapt=2 / b_bias=0 / direct=3 / weightb=1 / open_gop=0 / weightp=2 / keyint=250 / keyint_min=23 / scenecut=40 / intra_refresh=0 / rc=crf / mbtree=0 / crf=17.0 / qcomp=0.60 / qpmin=10 / qpmax=51 / qpstep=4 / ip_ratio=1.40 / pb_ratio=1.30 / aq=1:0.50
Language                                 : Japanese

Audio
ID                                       : 2
Format                                   : FLAC
Format/Info                              : Free Lossless Audio Codec
Codec ID                                 : A_FLAC
Duration                                 : 1mn 35s
Bit rate mode                            : Variable
Channel(s)                               : 2 channels
Sampling rate                            : 48.0 KHz
Bit depth                                : 24 bits
Title                                    : [FLAC 2.0]
Writing library                          : libFLAC 1.2.1 (UTC 2007-09-17)
Language                                 : Japanese

Text
ID                                       : 3
Format                                   : ASS
Codec ID                                 : S_TEXT/ASS
Codec ID/Info                            : Advanced Sub Station Alpha
Compression mode                         : Lossless
Title                                    : [ASS]
Language                                 : English

Please note, this isn't my log. I copied it from pastebin.

Tom
 

My Computer

System One

  • Manufacturer/Model
    Build #1
    CPU
    Intel Core i7 3770K @4.4GHz
    Motherboard
    ASUS P8Z77-V PRO
    Memory
    Corsair Vengeance 2x4GB DDR3 1600MHz Low Profile (White)
    Graphics Card(s)
    Gigabyte Radeon HD 7850 (2GB GDDR5)
    Sound Card
    Integrated on motherboard
    Monitor(s) Displays
    23" LG LCD/LED IPS
    Screen Resolution
    1920*1080
    Hard Drives
    Samsung EVO 128GB SSD
    Seagate Barracuda 2TB 7200rpm
    2x500GB Seagate FreeAgent 5400rpm
    PSU
    Corsair TX650W V2 (80+ Bronze)
    Case
    NZXT Phantom 410
    Cooling
    Corsair H100 Water Cooler, 1x140mm and 1x120mm stock fans
    Keyboard
    Microsoft Desktop 2000 Wireless Keyboard
    Mouse
    Microsoft Desktop 2000 Wireless Mouse
    Internet Speed
    95 Mb/s Download 70 Mb/s Upload
As per your request.

Malwarebytes Anti-Malware 1.61.0.1400
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Database version: v2012.06.13.04

Windows Vista Service Pack 2 x64 NTFS (Safe Mode)
Internet Explorer 9.0.8112.16421
ED :: ED-PC [administrator]

6/16/2012 6:52:23 AM
mbam-log-2012-06-16 (06-52-23).txt

Scan type: Custom scan
Scan options enabled: File System | Heuristics/Shuriken | PUP | PUM
Scan options disabled: Memory | Startup | Registry | Heuristics/Extra | P2P
Objects scanned: 1
Time elapsed: 9 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.

(end)
 

My Computer

System One

  • Manufacturer/Model
    MSI/MS7390
    CPU
    AMD Athlon 64 X2 5000
    Motherboard
    MSI K9N SLI-F
    Memory
    Crucial 2048 MBs
    Graphics Card(s)
    ATI Radeon X1550 Series
    Sound Card
    Realtek
    Monitor(s) Displays
    Trinitron
    Screen Resolution
    1600 x 1200 pixels
    Hard Drives
    Western Digital 500 GB
    Western Digital 9 GB
    Maxtor 80 GB External
    Case
    Power Up 5511 Mid Tower ATX Case with 450w Power Supply
    Cooling
    Five Fans
    Keyboard
    Dell QuietKey
    Mouse
    Logitech - Optical
    Internet Speed
    1536 Kb/sec
Thanks for the log. Yeah, that's definitely malicious. The real svchost.exe is found in %SYSTEMROOT%\system32 (usually C:\Windows\System32), if you have this file anywhere else, the chances are that it's malicious.

Does MBAM pick anything else up if you run a full scan? Your MBAM definitions are also out of date, I would suggest updating them :)

Tom
 

My Computer

System One

  • Manufacturer/Model
    Build #1
    CPU
    Intel Core i7 3770K @4.4GHz
    Motherboard
    ASUS P8Z77-V PRO
    Memory
    Corsair Vengeance 2x4GB DDR3 1600MHz Low Profile (White)
    Graphics Card(s)
    Gigabyte Radeon HD 7850 (2GB GDDR5)
    Sound Card
    Integrated on motherboard
    Monitor(s) Displays
    23" LG LCD/LED IPS
    Screen Resolution
    1920*1080
    Hard Drives
    Samsung EVO 128GB SSD
    Seagate Barracuda 2TB 7200rpm
    2x500GB Seagate FreeAgent 5400rpm
    PSU
    Corsair TX650W V2 (80+ Bronze)
    Case
    NZXT Phantom 410
    Cooling
    Corsair H100 Water Cooler, 1x140mm and 1x120mm stock fans
    Keyboard
    Microsoft Desktop 2000 Wireless Keyboard
    Mouse
    Microsoft Desktop 2000 Wireless Mouse
    Internet Speed
    95 Mb/s Download 70 Mb/s Upload
I ran a full scan with SuperAntiSpyware by mistake and discovered the following.
Now I will run MalwareBytes and post the results.

SUPERAntiSpyware Scan Log
SUPERAntiSpyware.com | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!

Generated 06/16/2012 at 08:23 PM

Application Version : 5.0.1150

Core Rules Database Version : 8750
Trace Rules Database Version: 6562

Scan type : Complete Scan
Total Scan Time : 01:07:50

Operating System Information
Windows Vista Home Premium 64-bit, Service Pack 2 (Build 6.00.6002)
UAC Off - Administrator

Memory items scanned : 572
Memory threats detected : 0
Registry items scanned : 65767
Registry threats detected : 0
File items scanned : 109033
File threats detected : 3

Trojan.Agent/Gen-Decay
C:\PROGRAM FILES (X86)\ADOBE\READER 10.0\READER\READER_SL.EXE
C:\WINDOWS\INSTALLER\$PATCHCACHE$\MANAGED\68AB67CA7DA73301B744AA0100000010\10.1.0\READER_SL.EXE

PUP.CNETInstaller
C:\USERS\PUBLIC\DOWNLOADS\CNET_REGCLEANER630_EXE.EXE
 

My Computer

System One

  • Manufacturer/Model
    MSI/MS7390
    CPU
    AMD Athlon 64 X2 5000
    Motherboard
    MSI K9N SLI-F
    Memory
    Crucial 2048 MBs
    Graphics Card(s)
    ATI Radeon X1550 Series
    Sound Card
    Realtek
    Monitor(s) Displays
    Trinitron
    Screen Resolution
    1600 x 1200 pixels
    Hard Drives
    Western Digital 500 GB
    Western Digital 9 GB
    Maxtor 80 GB External
    Case
    Power Up 5511 Mid Tower ATX Case with 450w Power Supply
    Cooling
    Five Fans
    Keyboard
    Dell QuietKey
    Mouse
    Logitech - Optical
    Internet Speed
    1536 Kb/sec
And here is the Malwarebytes log.

Malwarebytes Anti-Malware 1.61.0.1400
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Database version: v2012.06.16.08

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
ED :: ED-PC [administrator]

6/16/2012 8:52:24 PM
mbam-log-2012-06-16 (20-52-24).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 430194
Time elapsed: 1 hour(s), 10 minute(s), 26 second(s)

Memory Processes Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> 3864 -> Delete on reboot.

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> Delete on reboot.

(end)
 

My Computer

System One

  • Manufacturer/Model
    MSI/MS7390
    CPU
    AMD Athlon 64 X2 5000
    Motherboard
    MSI K9N SLI-F
    Memory
    Crucial 2048 MBs
    Graphics Card(s)
    ATI Radeon X1550 Series
    Sound Card
    Realtek
    Monitor(s) Displays
    Trinitron
    Screen Resolution
    1600 x 1200 pixels
    Hard Drives
    Western Digital 500 GB
    Western Digital 9 GB
    Maxtor 80 GB External
    Case
    Power Up 5511 Mid Tower ATX Case with 450w Power Supply
    Cooling
    Five Fans
    Keyboard
    Dell QuietKey
    Mouse
    Logitech - Optical
    Internet Speed
    1536 Kb/sec
I ran a full scan with SuperAntiSpyware by mistake and discovered the following.
Now I will run MalwareBytes and post the results.

SUPERAntiSpyware Scan Log
SUPERAntiSpyware.com | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!

Generated 06/16/2012 at 08:23 PM

Application Version : 5.0.1150

Core Rules Database Version : 8750
Trace Rules Database Version: 6562

Scan type : Complete Scan
Total Scan Time : 01:07:50

Operating System Information
Windows Vista Home Premium 64-bit, Service Pack 2 (Build 6.00.6002)
UAC Off - Administrator

Memory items scanned : 572
Memory threats detected : 0
Registry items scanned : 65767
Registry threats detected : 0
File items scanned : 109033
File threats detected : 3

Trojan.Agent/Gen-Decay
C:\PROGRAM FILES (X86)\ADOBE\READER 10.0\READER\READER_SL.EXE
C:\WINDOWS\INSTALLER\$PATCHCACHE$\MANAGED\68AB67CA7DA73301B744AA0100000010\10.1.0\READER_SL.EXE

PUP.CNETInstaller
C:\USERS\PUBLIC\DOWNLOADS\CNET_REGCLEANER630_EXE.EXE

I wouldn't be worried about those Adobe Reader files, they appear to be false positives:

Trojan.agent/gen-decay? - SUPERAntiSpyware.com

And here is the Malwarebytes log.

Malwarebytes Anti-Malware 1.61.0.1400
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Database version: v2012.06.16.08

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
ED :: ED-PC [administrator]

6/16/2012 8:52:24 PM
mbam-log-2012-06-16 (20-52-24).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 430194
Time elapsed: 1 hour(s), 10 minute(s), 26 second(s)

Memory Processes Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> 3864 -> Delete on reboot.

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> Delete on reboot.

(end)

It's back again :( I'm not allowed to help with malware removal, so I'm going to ask an expert to assist you with this. In the mean time, I would suggest you back up all of your files. I would also like you to run DDS in preparation for this expert - she'll get you to run it anyway so we might as well save some time and run it before hand:

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
---------------------------------------------------

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:

http://www.vistax64.com/tutorials/289032-screenshots-files-upload-post-vista-forums.html


Tom
 

My Computer

System One

  • Manufacturer/Model
    Build #1
    CPU
    Intel Core i7 3770K @4.4GHz
    Motherboard
    ASUS P8Z77-V PRO
    Memory
    Corsair Vengeance 2x4GB DDR3 1600MHz Low Profile (White)
    Graphics Card(s)
    Gigabyte Radeon HD 7850 (2GB GDDR5)
    Sound Card
    Integrated on motherboard
    Monitor(s) Displays
    23" LG LCD/LED IPS
    Screen Resolution
    1920*1080
    Hard Drives
    Samsung EVO 128GB SSD
    Seagate Barracuda 2TB 7200rpm
    2x500GB Seagate FreeAgent 5400rpm
    PSU
    Corsair TX650W V2 (80+ Bronze)
    Case
    NZXT Phantom 410
    Cooling
    Corsair H100 Water Cooler, 1x140mm and 1x120mm stock fans
    Keyboard
    Microsoft Desktop 2000 Wireless Keyboard
    Mouse
    Microsoft Desktop 2000 Wireless Mouse
    Internet Speed
    95 Mb/s Download 70 Mb/s Upload
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_30
Run by ED at 9:54:46 on 2012-06-17
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4094.2616 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files (x86)\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\locator.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\mobsync.exe
-netsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uSearch Bar = Preserve
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: {D071359C-30AD-4645-9B78-7A3283571F25} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: {FB858B22-55E2-413f-87F5-30ADC5552151} - C:\Program Files (x86)\PlotSoft\PDFill\DownloadPDF.exe
Trusted Zone: microsoft.com
Trusted Zone: microsoft.com\*.windowsupdate
Trusted Zone: msn.com\www
Trusted Zone: update.microsoft.com
Trusted Zone: windowsupdate.microsoft.com
Trusted Zone: windowsupdates.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
TCP: DhcpNameServer = 68.237.161.12 71.250.0.12
TCP: Interfaces\{A0769753-1693-4781-8497-D622E206BFB8} : DhcpNameServer = 68.237.161.12 71.250.0.12
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: {D071359C-30AD-4645-9B78-7A3283571F25} - No File
BHO-X64: Freecause Shopping BHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
IE-X64: {FB858B22-55E2-413f-87F5-30ADC5552151} - C:\Program Files (x86)\PlotSoft\PDFill\DownloadPDF.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\ED\AppData\Roaming\Mozilla\Firefox\Profiles\eh6kxwdy.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?AF=110806&tt=270312_bext_fix&babsrc=adbartrp&mntrId=6ac83d39000000000000001d92ab714c&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll
FF - plugin: C:\Users\ED\AppData\Roaming\Mozilla\Firefox\Profiles\eh6kxwdy.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\npGarmin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=110806
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 6ac83d39000000000000001d92ab714c
FF - user.js: extensions.BabylonToolbar_i.hardId - 6ac83d39000000000000001d92ab714c
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15426
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1716:06:33
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
============= SERVICES / DRIVERS ===============
.
R0 fltsrv;Acronis Storage Filter Management;C:\Windows\system32\DRIVERS\fltsrv.sys --> C:\Windows\system32\DRIVERS\fltsrv.sys [?]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R0 vididr;Acronis Virtual Disk;C:\Windows\system32\DRIVERS\vididr.sys --> C:\Windows\system32\DRIVERS\vididr.sys [?]
R0 vidsflt67;Acronis Disk Storage Filter (67);C:\Windows\system32\DRIVERS\vsflt67.sys --> C:\Windows\system32\DRIVERS\vsflt67.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files (x86)\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files (x86)\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files (x86)\SASCore64.exe [2011-8-11 140672]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
R2 afcdpsrv;Acronis Nonstop Backup Service;C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2012-6-2 3459024]
R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2011-6-27 21504]
R2 syncagentsrv;Acronis Sync Agent Service;C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [2012-4-27 5914912]
R3 afcdp;afcdp;C:\Windows\system32\DRIVERS\afcdp.sys --> C:\Windows\system32\DRIVERS\afcdp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2011-6-28 89920]
S3 MatSvc;Microsoft Automated Troubleshooting Service;C:\Program Files\Microsoft Fix it Center\Matsvc.exe [2011-6-13 343856]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-4-24 113120]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2011-6-27 19968]
S3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2012-4-10 164528]
S3 wimmount;wimmount;C:\Windows\system32\DRIVERS\wimmount.sys --> C:\Windows\system32\DRIVERS\wimmount.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
.
=============== File Associations ===============
.
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
2012-06-12 21:14:57 955840 ----a-w- C:\Windows\System32\npDeployJava1.dll
2012-06-12 21:14:57 839096 ----a-w- C:\Windows\System32\deployJava1.dll
2012-06-03 10:31:45 455552 ----a-w- C:\Program Files (x86)\SSUPDATE64.EXE
2012-06-03 10:31:44 4786048 ----a-w- C:\Program Files (x86)\SUPERANTISPYWARE.EXE
2012-06-03 00:38:56 367200 ----a-w- C:\Windows\System32\drivers\afcdp.sys
2012-06-03 00:38:26 1294432 ----a-w- C:\Windows\System32\drivers\tdrpman.sys
2012-06-03 00:38:18 994912 ----a-w- C:\Windows\System32\drivers\timntr.sys
2012-06-03 00:37:52 211552 ----a-w- C:\Windows\System32\drivers\vididr.sys
2012-06-03 00:37:51 146528 ----a-w- C:\Windows\System32\drivers\vsflt67.sys
2012-06-03 00:37:42 320096 ----a-w- C:\Windows\System32\drivers\snapman.sys
2012-06-03 00:37:41 137312 ----a-w- C:\Windows\System32\drivers\fltsrv.sys
2012-05-05 11:21:42 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-05 11:21:42 419488 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-05-05 11:21:12 8744608 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-05-02 00:46:28 4472832 ----a-w- C:\Windows\SysWow64\GPhotos.scr
2012-04-14 14:09:46 142944 ----a-w- C:\Windows\System32\drivers\vsflt61.sys
2012-04-04 19:56:40 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-03-21 00:44:12 98688 ----a-w- C:\Windows\System32\drivers\NisDrvWFP.sys
2012-03-21 00:44:12 203888 ----a-w- C:\Windows\System32\drivers\MpFilter.sys
2011-08-11 23:38:04 140672 ----a-w- C:\Program Files (x86)\SASCore64.exe
2011-07-22 16:26:56 14928 ----a-w- C:\Program Files (x86)\sasdifsv64.sys
2011-07-20 20:55:40 313728 ----a-w- C:\Program Files (x86)\RUNSAS.EXE
2011-07-19 00:08:58 210816 ----a-w- C:\Program Files (x86)\SASCTXMN64.DLL
2011-07-12 21:55:18 12368 ----a-w- C:\Program Files (x86)\saskutil64.sys
2011-05-04 17:52:35 533888 ----a-w- C:\Program Files (x86)\Uninstall.exe
2011-05-04 17:52:29 46464 ----a-w- C:\Program Files (x86)\SASTask.exe
2004-05-07 22:31:40 348160 ----a-w- C:\Program Files (x86)\msvcr71.dll
.
============= FINISH: 9:59:49.44 ===============

Sorry, I have tried numerous times to attach the zip file to this forum with no success.
My menu does not have a paperclip for attaching a file and my Paint program menu does not have the same menu as is shown in the instructions you referenced.
Any other suggestions?
 

My Computer

System One

  • Manufacturer/Model
    MSI/MS7390
    CPU
    AMD Athlon 64 X2 5000
    Motherboard
    MSI K9N SLI-F
    Memory
    Crucial 2048 MBs
    Graphics Card(s)
    ATI Radeon X1550 Series
    Sound Card
    Realtek
    Monitor(s) Displays
    Trinitron
    Screen Resolution
    1600 x 1200 pixels
    Hard Drives
    Western Digital 500 GB
    Western Digital 9 GB
    Maxtor 80 GB External
    Case
    Power Up 5511 Mid Tower ATX Case with 450w Power Supply
    Cooling
    Five Fans
    Keyboard
    Dell QuietKey
    Mouse
    Logitech - Optical
    Internet Speed
    1536 Kb/sec
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_30
Run by ED at 9:54:46 on 2012-06-17
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4094.2616 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files (x86)\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\locator.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\mobsync.exe
-netsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uSearch Bar = Preserve
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: {D071359C-30AD-4645-9B78-7A3283571F25} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: {FB858B22-55E2-413f-87F5-30ADC5552151} - C:\Program Files (x86)\PlotSoft\PDFill\DownloadPDF.exe
Trusted Zone: microsoft.com
Trusted Zone: microsoft.com\*.windowsupdate
Trusted Zone: msn.com\www
Trusted Zone: update.microsoft.com
Trusted Zone: windowsupdate.microsoft.com
Trusted Zone: windowsupdates.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
TCP: DhcpNameServer = 68.237.161.12 71.250.0.12
TCP: Interfaces\{A0769753-1693-4781-8497-D622E206BFB8} : DhcpNameServer = 68.237.161.12 71.250.0.12
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: {D071359C-30AD-4645-9B78-7A3283571F25} - No File
BHO-X64: Freecause Shopping BHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
IE-X64: {FB858B22-55E2-413f-87F5-30ADC5552151} - C:\Program Files (x86)\PlotSoft\PDFill\DownloadPDF.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\ED\AppData\Roaming\Mozilla\Firefox\Profiles\eh6kxwdy.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?AF=110806&tt=270312_bext_fix&babsrc=adbartrp&mntrId=6ac83d39000000000000001d92ab714c&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll
FF - plugin: C:\Users\ED\AppData\Roaming\Mozilla\Firefox\Profiles\eh6kxwdy.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\npGarmin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=110806
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 6ac83d39000000000000001d92ab714c
FF - user.js: extensions.BabylonToolbar_i.hardId - 6ac83d39000000000000001d92ab714c
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15426
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1716:06:33
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
============= SERVICES / DRIVERS ===============
.
R0 fltsrv;Acronis Storage Filter Management;C:\Windows\system32\DRIVERS\fltsrv.sys --> C:\Windows\system32\DRIVERS\fltsrv.sys [?]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R0 vididr;Acronis Virtual Disk;C:\Windows\system32\DRIVERS\vididr.sys --> C:\Windows\system32\DRIVERS\vididr.sys [?]
R0 vidsflt67;Acronis Disk Storage Filter (67);C:\Windows\system32\DRIVERS\vsflt67.sys --> C:\Windows\system32\DRIVERS\vsflt67.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files (x86)\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files (x86)\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files (x86)\SASCore64.exe [2011-8-11 140672]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
R2 afcdpsrv;Acronis Nonstop Backup Service;C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2012-6-2 3459024]
R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2011-6-27 21504]
R2 syncagentsrv;Acronis Sync Agent Service;C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [2012-4-27 5914912]
R3 afcdp;afcdp;C:\Windows\system32\DRIVERS\afcdp.sys --> C:\Windows\system32\DRIVERS\afcdp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2011-6-28 89920]
S3 MatSvc;Microsoft Automated Troubleshooting Service;C:\Program Files\Microsoft Fix it Center\Matsvc.exe [2011-6-13 343856]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-4-24 113120]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2011-6-27 19968]
S3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2012-4-10 164528]
S3 wimmount;wimmount;C:\Windows\system32\DRIVERS\wimmount.sys --> C:\Windows\system32\DRIVERS\wimmount.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
.
=============== File Associations ===============
.
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
2012-06-12 21:14:57 955840 ----a-w- C:\Windows\System32\npDeployJava1.dll
2012-06-12 21:14:57 839096 ----a-w- C:\Windows\System32\deployJava1.dll
2012-06-03 10:31:45 455552 ----a-w- C:\Program Files (x86)\SSUPDATE64.EXE
2012-06-03 10:31:44 4786048 ----a-w- C:\Program Files (x86)\SUPERANTISPYWARE.EXE
2012-06-03 00:38:56 367200 ----a-w- C:\Windows\System32\drivers\afcdp.sys
2012-06-03 00:38:26 1294432 ----a-w- C:\Windows\System32\drivers\tdrpman.sys
2012-06-03 00:38:18 994912 ----a-w- C:\Windows\System32\drivers\timntr.sys
2012-06-03 00:37:52 211552 ----a-w- C:\Windows\System32\drivers\vididr.sys
2012-06-03 00:37:51 146528 ----a-w- C:\Windows\System32\drivers\vsflt67.sys
2012-06-03 00:37:42 320096 ----a-w- C:\Windows\System32\drivers\snapman.sys
2012-06-03 00:37:41 137312 ----a-w- C:\Windows\System32\drivers\fltsrv.sys
2012-05-05 11:21:42 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-05 11:21:42 419488 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-05-05 11:21:12 8744608 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-05-02 00:46:28 4472832 ----a-w- C:\Windows\SysWow64\GPhotos.scr
2012-04-14 14:09:46 142944 ----a-w- C:\Windows\System32\drivers\vsflt61.sys
2012-04-04 19:56:40 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-03-21 00:44:12 98688 ----a-w- C:\Windows\System32\drivers\NisDrvWFP.sys
2012-03-21 00:44:12 203888 ----a-w- C:\Windows\System32\drivers\MpFilter.sys
2011-08-11 23:38:04 140672 ----a-w- C:\Program Files (x86)\SASCore64.exe
2011-07-22 16:26:56 14928 ----a-w- C:\Program Files (x86)\sasdifsv64.sys
2011-07-20 20:55:40 313728 ----a-w- C:\Program Files (x86)\RUNSAS.EXE
2011-07-19 00:08:58 210816 ----a-w- C:\Program Files (x86)\SASCTXMN64.DLL
2011-07-12 21:55:18 12368 ----a-w- C:\Program Files (x86)\saskutil64.sys
2011-05-04 17:52:35 533888 ----a-w- C:\Program Files (x86)\Uninstall.exe
2011-05-04 17:52:29 46464 ----a-w- C:\Program Files (x86)\SASTask.exe
2004-05-07 22:31:40 348160 ----a-w- C:\Program Files (x86)\msvcr71.dll
.
============= FINISH: 9:59:49.44 ===============

Sorry, I have tried numerous times to attach the zip file to this forum with no success.
My menu does not have a paperclip for attaching a file and my Paint program menu does not have the same menu as is shown in the instructions you referenced.
Any other suggestions?

Don't worry about attach.txt for now, if our expert needs it then she'll be able to guide you through attaching it :) When waiting for her to come, please be be patient and bear in mind that there are significant time differences between the various helpers here.
 

My Computer

System One

  • Manufacturer/Model
    Build #1
    CPU
    Intel Core i7 3770K @4.4GHz
    Motherboard
    ASUS P8Z77-V PRO
    Memory
    Corsair Vengeance 2x4GB DDR3 1600MHz Low Profile (White)
    Graphics Card(s)
    Gigabyte Radeon HD 7850 (2GB GDDR5)
    Sound Card
    Integrated on motherboard
    Monitor(s) Displays
    23" LG LCD/LED IPS
    Screen Resolution
    1920*1080
    Hard Drives
    Samsung EVO 128GB SSD
    Seagate Barracuda 2TB 7200rpm
    2x500GB Seagate FreeAgent 5400rpm
    PSU
    Corsair TX650W V2 (80+ Bronze)
    Case
    NZXT Phantom 410
    Cooling
    Corsair H100 Water Cooler, 1x140mm and 1x120mm stock fans
    Keyboard
    Microsoft Desktop 2000 Wireless Keyboard
    Mouse
    Microsoft Desktop 2000 Wireless Mouse
    Internet Speed
    95 Mb/s Download 70 Mb/s Upload
Take your time.
This 77 year old body moves slowly.
Thank you for your understanding.
 

My Computer

System One

  • Manufacturer/Model
    MSI/MS7390
    CPU
    AMD Athlon 64 X2 5000
    Motherboard
    MSI K9N SLI-F
    Memory
    Crucial 2048 MBs
    Graphics Card(s)
    ATI Radeon X1550 Series
    Sound Card
    Realtek
    Monitor(s) Displays
    Trinitron
    Screen Resolution
    1600 x 1200 pixels
    Hard Drives
    Western Digital 500 GB
    Western Digital 9 GB
    Maxtor 80 GB External
    Case
    Power Up 5511 Mid Tower ATX Case with 450w Power Supply
    Cooling
    Five Fans
    Keyboard
    Dell QuietKey
    Mouse
    Logitech - Optical
    Internet Speed
    1536 Kb/sec
Hi, EJF.

Tom must be a mind reader. :)

Seeing as you have Acronis installed, you have the option of reverting to a back-up prior to time the messages began last week or, we can try the following:


Please follow these instructions carefully.

Download ComboFix from one of the following locations:

Link 1
Link 2


!!! IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your antivirus and anti-malware security applications. If not disabled, these programs will likely interfere with cleanup process. This can usually be accomplished by a right-click on the icon in the System Tray.

    Note: If you are unsure how to disable your security software, see the instructions in this topic at Tech Support Forum: How to disable your security applications.

    [*] If infections are found, ComboFix will automatically reboot the machine to complete the removal process. Please ensure all opened windows are closed before proceeding.
    [*]Double-click ComboFix.exe on your desktop and follow the prompts.
    [*]As part of the process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it is strongly recommended to have this pre-installed on your machine before doing any malware removal. The Recovery Console will allow you to start up the computer in a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.



Please note: If the Microsoft Windows Recovery Console is already installed on the computer, ComboFix will continue the malware removal procedures.


  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console.
  • When prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    CF_RC1.png

  • After the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    CF_RC2.png

  • Click "Yes" to continue scanning for malware.
  • When finished, a log will be produced. Please include the C:\ComboFix.txt in your next reply.


The Attach.txt doesn't need to be zipped and attached. You can open the file and copy/paste the results as a reply.
 

My Computer

Requested log follows.
I checked C://Windows and the svchost.exe file is still there.


ComboFix 12-06-16.02 - ED 06/17/2012 15:59:00.1.2 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4094.2290 [GMT -4:00]
Running from: c:\users\ED\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Uninstall.exe
c:\windows\svchost.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-05-17 to 2012-06-17 )))))))))))))))))))))))))))))))
.
.
2012-06-17 20:27 . 2012-06-17 20:27 69000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2362A73-D103-44CA-99C3-8D67F9D370EE}\offreg.dll
2012-06-17 20:24 . 2012-06-17 20:24 35664 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2362A73-D103-44CA-99C3-8D67F9D370EE}\MpKsl21290fa7.sys
2012-06-17 20:20 . 2012-06-17 20:27 -------- d-----w- c:\users\ED\AppData\Local\temp
2012-06-17 20:20 . 2012-06-17 20:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-17 19:32 . 2012-06-17 19:32 -------- d-----w- c:\users\ED\AppData\Roaming\SpeedMaxPc
2012-06-17 19:32 . 2012-06-17 19:32 -------- d-----w- c:\users\ED\AppData\Roaming\DriverCure
2012-06-17 19:32 . 2012-06-17 19:51 -------- d-----w- c:\programdata\SpeedMaxPc
2012-06-17 19:21 . 2012-06-17 19:50 -------- d-----w- c:\users\ED\AppData\Roaming\ApplicationData
2012-06-17 11:49 . 2012-05-15 05:41 8955792 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E2362A73-D103-44CA-99C3-8D67F9D370EE}\mpengine.dll
2012-06-15 22:58 . 2012-06-15 22:58 770384 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll
2012-06-15 22:58 . 2012-06-15 22:58 421200 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll
2012-06-12 21:15 . 2012-06-12 21:14 955840 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-06-12 21:15 . 2012-06-12 21:14 839096 ----a-w- c:\windows\system32\deployJava1.dll
2012-06-12 21:14 . 2012-06-12 21:14 -------- d-----w- c:\program files\Java
2012-06-12 11:05 . 2012-06-12 11:05 -------- d-----w- c:\users\ED\AppData\Roaming\PeerNetworking
2012-06-11 17:29 . 2012-06-11 17:29 -------- d-----w- c:\program files (x86)\Native.x64
2012-06-11 17:29 . 2012-06-11 17:29 -------- d-----w- c:\program files (x86)\Native.x86
2012-06-11 17:29 . 2012-06-11 17:29 -------- d-----w- c:\program files (x86)\Resources
2012-06-11 17:28 . 2012-06-11 17:28 -------- dc----w- c:\program files (x86)\Staging
2012-06-11 17:28 . 2012-06-16 13:21 -------- d-----w- c:\users\ED\AppData\Local\Paint.NET
2012-06-11 14:03 . 2012-02-09 17:17 927800 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F55D364B-4968-4B32-ACF6-E1946DEC7DA3}\gapaengine.dll
2012-06-11 14:03 . 2012-05-15 05:41 8955792 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-06-11 13:57 . 2012-06-11 13:57 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2012-06-11 13:57 . 2012-06-11 13:58 -------- d-----w- c:\program files\Microsoft Security Client
2012-06-11 13:08 . 2012-06-17 00:55 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2012-06-11 13:08 . 2012-06-17 00:55 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-06-08 19:43 . 2012-06-08 19:43 -------- d-----w- C:\xampp
2012-06-07 13:17 . 2012-06-07 13:17 -------- d-----w- c:\windows\.rsrc
2012-06-06 00:39 . 2012-06-16 10:49 -------- d-----w- c:\windows\recyclebin
2012-06-03 00:38 . 2012-06-03 00:38 367200 ----a-w- c:\windows\system32\drivers\afcdp.sys
2012-06-03 00:38 . 2012-06-03 00:38 -------- d-----w- c:\users\ED\AppData\Roaming\EB1605EB-DFAA-42D9-9953-1C833F26410A
2012-06-03 00:38 . 2012-06-03 00:38 994912 ----a-w- c:\windows\system32\drivers\timntr.sys
2012-06-03 00:37 . 2012-06-03 00:37 211552 ----a-w- c:\windows\system32\drivers\vididr.sys
2012-06-03 00:37 . 2012-06-03 00:37 146528 ----a-w- c:\windows\system32\drivers\vsflt67.sys
2012-05-20 14:06 . 2012-05-20 14:07 -------- d-----w- c:\users\ED\AppData\Local\Replace Text
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-12 11:10 . 2011-06-06 17:18 164880 ---ha-w- c:\users\ED\AppData\Roaming\Microsoft\Virtual PC\VPCKeyboard.dll
2012-06-03 10:31 . 2011-08-12 18:22 455552 ----a-w- c:\program files (x86)\SSUPDATE64.EXE
2012-06-03 10:31 . 2011-12-09 00:44 4786048 ----a-w- c:\program files (x86)\SUPERANTISPYWARE.EXE
2012-06-03 00:38 . 2012-04-14 14:10 1294432 ----a-w- c:\windows\system32\drivers\tdrpman.sys
2012-06-03 00:37 . 2011-12-16 21:26 320096 ----a-w- c:\windows\system32\drivers\snapman.sys
2012-06-03 00:37 . 2012-04-14 14:09 137312 ----a-w- c:\windows\system32\drivers\fltsrv.sys
2012-05-05 11:21 . 2012-04-11 11:09 419488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-05-05 11:21 . 2012-04-07 00:55 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-05 11:21 . 2012-04-04 12:47 8744608 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2012-05-02 00:46 . 2012-05-02 00:46 4472832 ----a-w- c:\windows\SysWow64\GPhotos.scr
2012-04-14 14:09 . 2012-04-14 14:09 142944 ----a-w- c:\windows\system32\drivers\vsflt61.sys
2012-04-04 19:56 . 2011-12-29 02:04 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-21 00:44 . 2012-03-21 00:44 98688 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2012-03-21 00:44 . 2012-03-21 00:44 203888 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2011-10-07 21:05 . 2011-10-07 21:05 934496 ----a-w- c:\program files (x86)\PaintDotNet.exe
2011-10-07 21:05 . 2011-10-07 21:05 85600 ----a-w- c:\program files (x86)\PaintDotNet.SystemLayer.Native.x64.dll
2011-10-07 21:05 . 2011-10-07 21:05 82016 ----a-w- c:\program files (x86)\PaintDotNet.SystemLayer.Native.x86.dll
2011-10-07 21:05 . 2011-10-07 21:05 544256 ----a-w- c:\program files (x86)\wiaaut.dll
2011-10-07 21:05 . 2011-10-07 21:05 49152 ----a-w- c:\program files (x86)\Interop.WIA.dll
2011-10-07 21:05 . 2011-10-07 21:05 366176 ----a-w- c:\program files (x86)\PaintDotNet.Resources.dll
2011-10-07 21:05 . 2011-10-07 21:05 339552 ----a-w- c:\program files (x86)\PaintDotNet.Core.dll
2011-10-07 21:05 . 2011-10-07 21:05 329824 ----a-w- c:\program files (x86)\PaintDotNet.SystemLayer.dll
2011-10-07 21:05 . 2011-10-07 21:05 28768 ----a-w- c:\program files (x86)\SetupNgen.exe
2011-10-07 21:05 . 2011-10-07 21:05 23648 ----a-w- c:\program files (x86)\ShellExtension_x64.dll
2011-10-07 21:05 . 2011-10-07 21:05 21600 ----a-w- c:\program files (x86)\ShellExtension_x86.dll
2011-10-07 21:05 . 2011-10-07 21:05 208480 ----a-w- c:\program files (x86)\PaintDotNet.Effects.dll
2011-10-07 21:05 . 2011-10-07 21:05 200704 ----a-w- c:\program files (x86)\ICSharpCode.SharpZipLib.dll
2011-10-07 21:05 . 2011-10-07 21:05 19040 ----a-w- c:\program files (x86)\WiaProxy32.exe
2011-10-07 21:05 . 2011-10-07 21:05 174688 ----a-w- c:\program files (x86)\PaintDotNet.Base.dll
2011-10-07 21:05 . 2011-10-07 21:05 163936 ----a-w- c:\program files (x86)\PaintDotNet.Data.dll
2011-10-07 21:05 . 2011-10-07 21:05 15456 ----a-w- c:\program files (x86)\UpdateMonitor.exe
2011-10-07 21:05 . 2011-10-07 21:05 14432 ----a-w- c:\program files (x86)\PdnRepair.exe
2011-08-11 23:38 . 2011-08-11 23:38 140672 ----a-w- c:\program files (x86)\SASCore64.exe
2011-07-22 16:26 . 2011-07-22 16:26 14928 ----a-w- c:\program files (x86)\sasdifsv64.sys
2011-07-20 20:55 . 2011-07-20 20:55 313728 ----a-w- c:\program files (x86)\RUNSAS.EXE
2011-07-19 00:08 . 2011-07-19 00:08 210816 ----a-w- c:\program files (x86)\SASCTXMN64.DLL
2011-07-12 21:55 . 2011-07-12 21:55 12368 ----a-w- c:\program files (x86)\saskutil64.sys
2011-05-04 17:52 . 2011-05-04 17:52 46464 ----a-w- c:\program files (x86)\SASTask.exe
2004-05-07 22:31 . 2004-05-07 22:31 348160 ----a-w- c:\program files (x86)\msvcr71.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 138240]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0smrgdf c:\program files (x86)\iolo\System Mechanic 4\
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
S2 !SASCORE;SAS Core Service;c:\program files (x86)\SASCORE64.EXE [2011-08-11 140672]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 afcdpsrv;Acronis Nonstop Backup Service;c:\program files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [2012-06-03 3459024]
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSL21290FA7
.
Contents of the 'Scheduled Tasks' folder
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
Trusted Zone: microsoft.com
Trusted Zone: microsoft.com\*.windowsupdate
Trusted Zone: msn.com\www
Trusted Zone: update.microsoft.com
Trusted Zone: windowsupdate.microsoft.com
Trusted Zone: windowsupdates.com
TCP: DhcpNameServer = 68.237.161.12 71.250.0.12
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
FF - ProfilePath - c:\users\ED\AppData\Roaming\Mozilla\Firefox\Profiles\eh6kxwdy.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?AF=110806&tt=270312_bext_fix&babsrc=adbartrp&mntrId=6ac83d39000000000000001d92ab714c&q=
FF - prefs.js: network.proxy.type - 0
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=110806
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 6ac83d39000000000000001d92ab714c
FF - user.js: extensions.BabylonToolbar_i.hardId - 6ac83d39000000000000001d92ab714c
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15426
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1716:06
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers- - (no file)
ShellIconOverlayIdentifiers- - (no file)
ShellIconOverlayIdentifiers- - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
c:\\.\globalroot\systemroot\svchost.exe
.
**************************************************************************
.
Completion time: 2012-06-17 16:33:50 - machine was rebooted
ComboFix-quarantined-files.txt 2012-06-17 20:33
.
Pre-Run: 78,471,200,768 bytes free
Post-Run: 80,803,655,680 bytes free
.
- - End Of File - - CD0D3239C01335D6F11458E95ADC1F2A
 

My Computer

System One

  • Manufacturer/Model
    MSI/MS7390
    CPU
    AMD Athlon 64 X2 5000
    Motherboard
    MSI K9N SLI-F
    Memory
    Crucial 2048 MBs
    Graphics Card(s)
    ATI Radeon X1550 Series
    Sound Card
    Realtek
    Monitor(s) Displays
    Trinitron
    Screen Resolution
    1600 x 1200 pixels
    Hard Drives
    Western Digital 500 GB
    Western Digital 9 GB
    Maxtor 80 GB External
    Case
    Power Up 5511 Mid Tower ATX Case with 450w Power Supply
    Cooling
    Five Fans
    Keyboard
    Dell QuietKey
    Mouse
    Logitech - Optical
    Internet Speed
    1536 Kb/sec
Hi, EFJ.

That was a start and gave me additional information. There will be a few more stages to go and I still want to see a copy/paste of the Attach.txt log. I'm seeing indications of software I want to provide recommendations on later. First, however, let's move on to the next step.

Please download the TDSSKiller.exe by Kaspersky... save it to your Desktop. <-Important!!!

  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista - W7 users: Right-click and select "Run As Administrator".
    If TDSSKiller does not run... rename it. Right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. ektfhtw.com).
    If you don't see file extensions, please see: How to change the file extension.
  • Click the Start Scan button. Do not use the computer during the scan!
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the "Scan results - Select action for found objects" and offer 3 options.
    • Ensure Cure (default) is selected... then click Continue > Reboot now to finish the cleaning process.
  • A log file named TDSSKiller_version_dd.mm.yyyy_hh.mm.ss_log.txt will be created and saved to the root directory. (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.
 

My Computer

I have to send the attach.txt log now or I will forget. :D
Now I will do the next step.

.
Code:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Home Premium 
Boot Device: \Device\HarddiskVolume3
Install Date: 5/24/2011 12:50:25 PM
System Uptime: 6/17/2012 7:36:08 AM (2 hours ago)
.
Motherboard: MSI |  | MS-7390
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ | CPU 1 | 2612/200mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 149 GiB total, 74.177 GiB free.
D: is FIXED (NTFS) - 8 GiB total, 6.276 GiB free.
E: is Removable
F: is FIXED (NTFS) - 149 GiB total, 90.873 GiB free.
P: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP630: 5/31/2012 3:41:51 PM - Scheduled Checkpoint
RP455: 6/2/2012 9:23:49 AM - Windows Backup
RP631: 6/2/2012 8:37:54 PM - Device Driver Package Install: Acronis Acronis Devices
RP632: 6/3/2012 11:00:08 AM - Windows Backup
RP633: 6/4/2012 5:30:36 PM - Scheduled Checkpoint
RP634: 6/5/2012 12:05:59 PM - Scheduled Checkpoint
RP635: 6/7/2012 6:05:41 PM - Scheduled Checkpoint
RP636: 6/10/2012 11:00:08 AM - Windows Backup
RP638: 6/11/2012 1:28:22 PM - Paint.NET v3.5.10
RP639: 6/12/2012 5:14:12 PM - Installed Java(TM) 7 Update 5 (64-bit)
RP640: 6/14/2012 7:20:16 AM - Scheduled Checkpoint
RP641: 6/15/2012 7:18:39 AM - Scheduled Checkpoint
RP642: 6/16/2012 7:31:15 AM - Scheduled Checkpoint
.
==== Installed Programs ======================
.
.
Acronis True Image Home 2012
Adaptec Easy CD Creator 4
Adobe Reader X (10.1.3)
Audacity 1.3.14 (Unicode)
Canon iP2700 series User Registration
Canon Utilities Solution Menu
CDBurnerXP
Compatibility Pack for the 2007 Office system
D3DX10
FileZilla Client 3.5.3
Foxit Reader
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Indeo® software
Inkscape 0.48.2
iolo technologies' System Mechanic 4
Java(TM) 6 Update 30
Junk Mail filter update
K-Lite Codec Pack 7.0.0 (Standard)
LAME v3.99.3 (for Windows)
Malwarebytes Anti-Malware version 1.61.0.1400
MapSource
MapSource - City Select North America v6
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Silverlight
Microsoft Tool Web Package:diskpart.exe
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Works
Mozilla Firefox 13.0.1 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
MSVCRT_amd64
OpenOffice.org 3.3
PhotoScape
Picasa 3
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Segoe UI
UniConvertor
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Media Player Firefox Plugin
.
==== Event Viewer Messages From Past Week ========
.
6/17/2012 7:49:22 AM, Error: Microsoft Antimalware [2001]  - Microsoft Antimalware has encountered an error trying to update signatures.      New Signature Version:       Previous Signature Version: 1.127.1739.0      Update Source: Microsoft Update Server      Update Stage: Search      Source Path: Default URL      Signature Type: AntiVirus      Update Type: Full      User: NT AUTHORITY\SYSTEM      Current Engine Version:       Previous Engine Version: 1.1.8403.0      Error code: 0x80080005      Error description: Server execution failed 
6/17/2012 7:48:52 AM, Error: Service Control Manager [7023]  - The Windows Update service terminated with the following error:  The system cannot find the file specified.
6/17/2012 7:38:31 AM, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  Cdr4_2K Cdralwnt UimBus Uim_IM
6/17/2012 7:38:31 AM, Error: Service Control Manager [7022]  - The Diagnostic System Host service hung on starting.
6/17/2012 7:37:00 AM, Error: Service Control Manager [7000]  - The Vstor2 WS60 Virtual Storage Driver service failed to start due to the following error:  The system cannot find the path specified.
6/17/2012 7:37:00 AM, Error: Service Control Manager [7000]  - The Cdralw2k service failed to start due to the following error:  This driver has been blocked from loading
6/17/2012 7:36:57 AM, Error: Application Popup [1060]  - \SystemRoot\SysWow64\Drivers\Cdralw2k.SYS has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
6/17/2012 7:36:56 AM, Error: NETLOGON [3095]  - This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration.
6/17/2012 7:36:38 AM, Error: Microsoft-Windows-Dhcp-Client [1002]  - The IP address lease 192.168.1.101 for the Network Card with network address 001D92AB714C has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
6/17/2012 7:36:21 AM, Error: Application Popup [1060]  - \SystemRoot\SysWow64\Drivers\Cdralwnt.SYS has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
6/17/2012 7:36:16 AM, Error: Application Popup [1060]  - \SystemRoot\SysWow64\Drivers\Cdr4_2K.SYS has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
6/16/2012 8:37:17 PM, Error: Microsoft Antimalware [2001]  - Microsoft Antimalware has encountered an error trying to update signatures.      New Signature Version:       Previous Signature Version: 1.127.1739.0      Update Source: Microsoft Update Server      Update Stage: Search      Source Path: Default URL      Signature Type: AntiVirus      Update Type: Full      User: NT AUTHORITY\SYSTEM      Current Engine Version:       Previous Engine Version: 1.1.8403.0      Error code: 0x80080005      Error description: Server execution failed 
6/16/2012 7:05:00 AM, Error: Microsoft Antimalware [2001]  - Microsoft Antimalware has encountered an error trying to update signatures.      New Signature Version:       Previous Signature Version: 1.127.1739.0      Update Source: Microsoft Update Server      Update Stage: Search      Source Path: Default URL      Signature Type: AntiVirus      Update Type: Full      User: NT AUTHORITY\SYSTEM      Current Engine Version:       Previous Engine Version: 1.1.8403.0      Error code: 0x80080005      Error description: Server execution failed 
6/16/2012 6:53:58 AM, Error: Microsoft-Windows-PrintSpooler [19]  - The print spooler failed to share printer Canon iP2700 series with shared resource name Canon iP2700 series. Error 2114. The printer cannot be used by others on the network.
6/16/2012 6:46:02 AM, Error: Microsoft Antimalware [2001]  - Microsoft Antimalware has encountered an error trying to update signatures.      New Signature Version:       Previous Signature Version: 1.127.1739.0      Update Source: Microsoft Update Server      Update Stage: Search      Source Path: Default URL      Signature Type: AntiVirus      Update Type: Full      User: NT AUTHORITY\SYSTEM      Current Engine Version:       Previous Engine Version: 1.1.8403.0      Error code: 0x8007043c      Error description: This service cannot be started in Safe Mode 
6/16/2012 6:46:02 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
6/16/2012 6:36:52 AM, Error: Service Control Manager [7001]  - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:  The dependency service or group failed to start.
6/16/2012 6:36:46 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
6/16/2012 6:36:45 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
6/16/2012 6:36:41 AM, Error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  AFD Cdr4_2K Cdralwnt DfsC MpFilter NetBIOS netbt nsiproxy PSched RasAcd rdbss SASDIFSV SASKUTIL Smb spldr tdx UimBus Uim_IM vmm Wanarpv6 ws2ifsl
6/16/2012 6:36:41 AM, Error: Service Control Manager [7001]  - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.
6/16/2012 6:36:41 AM, Error: Service Control Manager [7001]  - The WebDav Client Redirector Driver service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error:  A device attached to the system is not functioning.
6/16/2012 6:36:41 AM, Error: Service Control Manager [7001]  - The WebClient service depends on the WebDav Client Redirector Driver service which failed to start because of the following error:  The dependency service or group failed to start.
6/16/2012 6:36:41 AM, Error: Service Control Manager [7001]  - The TCP/IP NetBIOS Helper service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error:  A device attached to the system is not functioning.
6/16/2012 6:36:41 AM, Error: Service Control Manager [7001]  - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error:  A device attached to the system is not functioning.
6/16/2012 6:36:41 AM, Error: Service Control Manager [7001]  - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error:  The dependency service or group failed to start.
6/16/2012 6:36:41 AM, Error: Service Control Manager [7001]  - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error:  The dependency service or group failed to start.
6/16/2012 6:36:41 AM, Error: Service Control Manager [7001]  - The Network Store Interface Service service depends on the NSI proxy service service which failed to start because of the following error:  A device attached to the system is not functioning.
6/16/2012 6:36:41 AM, Error: Service Control Manager [7001]  - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.
6/16/2012 6:36:41 AM, Error: Service Control Manager [7001]  - The Network Connections service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.
6/16/2012 6:36:41 AM, Error: Service Control Manager [7001]  - The Netlogon service depends on the Workstation service which failed to start because of the following error:  The dependency service or group failed to start.
6/16/2012 6:36:41 AM, Error: Service Control Manager [7001]  - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error:  The dependency service or group failed to start.
6/16/2012 6:36:41 AM, Error: Service Control Manager [7001]  - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error:  A device attached to the system is not functioning.
6/16/2012 6:36:41 AM, Error: Service Control Manager [7001]  - The DHCP Client service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error:  A device attached to the system is not functioning.
6/16/2012 6:36:41 AM, Error: Service Control Manager [7001]  - The Computer Browser service depends on the Server service which failed to start because of the following error:  The dependency service or group failed to start.
6/16/2012 6:36:05 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
6/16/2012 6:36:05 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
6/16/2012 6:36:04 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
6/16/2012 6:35:53 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
6/16/2012 6:35:39 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
6/15/2012 9:45:51 PM, Error: Microsoft Antimalware [2001]  - Microsoft Antimalware has encountered an error trying to update signatures.      New Signature Version:       Previous Signature Version: 1.127.1739.0      Update Source: Microsoft Update Server      Update Stage: Search      Source Path: Default URL      Signature Type: AntiVirus      Update Type: Full      User: NT AUTHORITY\SYSTEM      Current Engine Version:       Previous Engine Version: 1.1.8403.0      Error code: 0x80080005      Error description: Server execution failed 
6/15/2012 9:09:24 PM, Error: Microsoft Antimalware [2001]  - Microsoft Antimalware has encountered an error trying to update signatures.      New Signature Version:       Previous Signature Version: 1.127.1739.0      Update Source: Microsoft Update Server      Update Stage: Search      Source Path: Default URL      Signature Type: AntiVirus      Update Type: Full      User: NT AUTHORITY\SYSTEM      Current Engine Version:       Previous Engine Version: 1.1.8403.0      Error code: 0x80080005      Error description: Server execution failed 
6/15/2012 8:56:18 PM, Error: EventLog [6008]  - The previous system shutdown at 8:43:10 PM on 6/15/2012 was unexpected.
6/15/2012 8:04:46 PM, Error: EventLog [6008]  - The previous system shutdown at 8:00:30 PM on 6/15/2012 was unexpected.
6/15/2012 6:52:25 AM, Error: Microsoft Antimalware [2001]  - Microsoft Antimalware has encountered an error trying to update signatures.      New Signature Version:       Previous Signature Version: 1.127.1739.0      Update Source: Microsoft Update Server      Update Stage: Search      Source Path: Default URL      Signature Type: AntiVirus      Update Type: Full      User: NT AUTHORITY\SYSTEM      Current Engine Version:       Previous Engine Version: 1.1.8403.0      Error code: 0x80080005      Error description: Server execution failed 
6/14/2012 6:23:32 AM, Error: Microsoft Antimalware [2001]  - Microsoft Antimalware has encountered an error trying to update signatures.      New Signature Version:       Previous Signature Version: 1.127.1739.0      Update Source: Microsoft Update Server      Update Stage: Search      Source Path: Default URL      Signature Type: AntiVirus      Update Type: Full      User: NT AUTHORITY\SYSTEM      Current Engine Version:       Previous Engine Version: 1.1.8403.0      Error code: 0x80080005      Error description: Server execution failed 
6/14/2012 6:12:30 AM, Error: Microsoft-Windows-Dhcp-Client [1002]  - The IP address lease 192.168.1.100 for the Network Card with network address 001D92AB714C has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
6/14/2012 2:47:33 PM, Error: Microsoft Antimalware [2001]  - Microsoft Antimalware has encountered an error trying to update signatures.      New Signature Version:       Previous Signature Version: 1.127.1739.0      Update Source: Microsoft Update Server      Update Stage: Search      Source Path: Default URL      Signature Type: AntiVirus      Update Type: Full      User: NT AUTHORITY\SYSTEM      Current Engine Version:       Previous Engine Version: 1.1.8403.0      Error code: 0x80080005      Error description: Server execution failed 
6/13/2012 7:32:24 AM, Error: Microsoft Antimalware [2001]  - Microsoft Antimalware has encountered an error trying to update signatures.      New Signature Version:       Previous Signature Version: 1.127.1739.0      Update Source: Microsoft Update Server      Update Stage: Search      Source Path: Default URL      Signature Type: AntiVirus      Update Type: Full      User: NT AUTHORITY\SYSTEM      Current Engine Version:       Previous Engine Version: 1.1.8403.0      Error code: 0x80080005      Error description: Server execution failed 
6/13/2012 4:16:58 PM, Error: Microsoft Antimalware [2001]  - Microsoft Antimalware has encountered an error trying to update signatures.      New Signature Version:       Previous Signature Version: 1.127.1739.0      Update Source: Microsoft Update Server      Update Stage: Search      Source Path: Default URL      Signature Type: AntiVirus      Update Type: Full      User: NT AUTHORITY\SYSTEM      Current Engine Version:       Previous Engine Version: 1.1.8403.0      Error code: 0x80080005      Error description: Server execution failed 
6/12/2012 5:30:10 AM, Error: Microsoft Antimalware [1119]  - Microsoft Antimalware has encountered a critical error when taking action on malware or other potentially unwanted software.  For more information please see the following: [URL="http://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:DOS/Alureon.A&threatid=2147636949"]Encyclopedia entry: Trojan:DOS/Alureon.A - Learn more about malware - Microsoft Malware Protection Center[/URL]      Name: Trojan:DOS/Alureon.A      ID: 2147636949      Severity: Severe      Category: Trojan      Path: rootkit:_Alureon->Mbr::Alureon      Detection Origin: Unknown      Detection Type: Concrete      Detection Source: System      User: NT AUTHORITY\SYSTEM      Process Name: Unknown      Action: Quarantine      Action Status:  To finish removing malware and other potentially unwanted software, restart the computer.      To see how to finish removing malware and other potentially unwanted software, see the support article on the Microsoft Security website.       Error Code: 0x80070032      Error description: The request is not supported.       Signature Version: AV: 1.127.1739.0, AS: 1.127.1739.0, NIS: 11.0.0.0      Engine Version: AM: 1.1.8403.0, NIS: 2.0.8001.0
6/11/2012 9:59:14 AM, Error: Microsoft Antimalware [2001]  - Microsoft Antimalware has encountered an error trying to update signatures.      New Signature Version:       Previous Signature Version: 0.0.0.0      Update Source: Microsoft Update Server      Update Stage: Search      Source Path: Default URL      Signature Type: AntiVirus      Update Type: Full      User: NT AUTHORITY\SYSTEM      Current Engine Version:       Previous Engine Version: 0.0.0.0      Error code: 0x80080005      Error description: Server execution failed 
6/11/2012 10:18:28 AM, Error: Microsoft Antimalware [1119]  - Microsoft Antimalware has encountered a critical error when taking action on malware or other potentially unwanted software.  For more information please see the following: [URL="http://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:DOS/Alureon.A&threatid=2147636949"]Encyclopedia entry: Trojan:DOS/Alureon.A - Learn more about malware - Microsoft Malware Protection Center[/URL]      Name: Trojan:DOS/Alureon.A      ID: 2147636949      Severity: Severe      Category: Trojan      Path: rootkit:_Alureon->Mbr::Alureon      Detection Origin: Unknown      Detection Type: Concrete      Detection Source: System      User: NT AUTHORITY\SYSTEM      Process Name: Unknown      Action: Quarantine      Action Status:  To finish removing malware and other potentially unwanted software, restart the computer.      To see how to finish removing malware and other potentially unwanted software, see the support article on the Microsoft Security website.       Error Code: 0x80070032      Error description: The request is not supported.       Signature Version: AV: 1.127.1739.0, AS: 1.127.1739.0, NIS: 11.0.0.0      Engine Version: AM: 1.1.8403.0, NIS: 2.0.8001.0
.
==== End Of File ===========================
 

My Computer

System One

  • Manufacturer/Model
    MSI/MS7390
    CPU
    AMD Athlon 64 X2 5000
    Motherboard
    MSI K9N SLI-F
    Memory
    Crucial 2048 MBs
    Graphics Card(s)
    ATI Radeon X1550 Series
    Sound Card
    Realtek
    Monitor(s) Displays
    Trinitron
    Screen Resolution
    1600 x 1200 pixels
    Hard Drives
    Western Digital 500 GB
    Western Digital 9 GB
    Maxtor 80 GB External
    Case
    Power Up 5511 Mid Tower ATX Case with 450w Power Supply
    Cooling
    Five Fans
    Keyboard
    Dell QuietKey
    Mouse
    Logitech - Optical
    Internet Speed
    1536 Kb/sec
Code:
21:31:58.0402 4784    TDSS rootkit removing tool 2.7.40.0 Jun 15 2012 15:13:31
21:31:58.0777 4784    ============================================================
21:31:58.0777 4784    Current date / time: 2012/06/17 21:31:58.0777
21:31:58.0777 4784    SystemInfo:
21:31:58.0777 4784    
21:31:58.0777 4784    OS Version: 6.0.6002 ServicePack: 2.0
21:31:58.0777 4784    Product type: Workstation
21:31:58.0777 4784    ComputerName: ED-PC
21:31:58.0777 4784    UserName: ED
21:31:58.0777 4784    Windows directory: C:\Windows
21:31:58.0777 4784    System windows directory: C:\Windows
21:31:58.0777 4784    Running under WOW64
21:31:58.0777 4784    Processor architecture: Intel x64
21:31:58.0777 4784    Number of processors: 2
21:31:58.0777 4784    Page size: 0x1000
21:31:58.0777 4784    Boot type: Normal boot
21:31:58.0777 4784    ============================================================
21:31:59.0761 4784    Drive \Device\Harddisk0\DR0 - Size: 0x21F516000 (8.49 Gb), SectorSize: 0x200, Cylinders: 0x454, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:31:59.0761 4784    Drive \Device\Harddisk1\DR1 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:31:59.0761 4784    Drive \Device\Harddisk2\DR2 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:31:59.0777 4784    ============================================================
21:31:59.0777 4784    \Device\Harddisk0\DR0:
21:31:59.0777 4784    MBR partitions:
21:31:59.0777 4784    \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x10F9315
21:31:59.0777 4784    \Device\Harddisk1\DR1:
21:31:59.0777 4784    MBR partitions:
21:31:59.0777 4784    \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x12A19000
21:31:59.0777 4784    \Device\Harddisk2\DR2:
21:31:59.0777 4784    MBR partitions:
21:31:59.0777 4784    \Device\Harddisk2\DR2\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x12A18800
21:31:59.0777 4784    ============================================================
21:31:59.0792 4784    C: <-> \Device\Harddisk2\DR2\Partition0
21:31:59.0824 4784    D: <-> \Device\Harddisk0\DR0\Partition0
21:31:59.0839 4784    F: <-> \Device\Harddisk1\DR1\Partition0
21:31:59.0839 4784    ============================================================
21:31:59.0839 4784    Initialize success
21:31:59.0839 4784    ============================================================
21:32:04.0308 0288    ============================================================
21:32:04.0308 0288    Scan started
21:32:04.0308 0288    Mode: Manual; 
21:32:04.0308 0288    ============================================================
21:32:04.0777 0288    !SASCORE        (7d9d615201a483d6fa99491c2e655a5a) C:\Program Files (x86)\SASCORE64.EXE
21:32:04.0792 0288    !SASCORE - ok
21:32:04.0949 0288    ACPI            (1965aaffab07e3fb03c77f81beba3547) C:\Windows\system32\drivers\acpi.sys
21:32:04.0964 0288    ACPI - ok
21:32:05.0199 0288    AcrSch2Svc      (0b3601ecea5d6d41ccae143355892061) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
21:32:05.0230 0288    AcrSch2Svc - ok
21:32:05.0371 0288    AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
21:32:05.0371 0288    AdobeARMservice - ok
21:32:05.0527 0288    adp94xx         (9137451d37ba1c325cd6c2def3d2d692) C:\Windows\system32\drivers\adp94xx.sys
21:32:05.0527 0288    adp94xx - ok
21:32:05.0574 0288    adpahci         (01f80898df5cc7df19b3b11351846263) C:\Windows\system32\drivers\adpahci.sys
21:32:05.0574 0288    adpahci - ok
21:32:05.0605 0288    adpu160m        (da001db13fff45dfe9109936e265b7cc) C:\Windows\system32\drivers\adpu160m.sys
21:32:05.0621 0288    adpu160m - ok
21:32:05.0636 0288    adpu320         (2b10c35c5b7c5c0c28f572e035319602) C:\Windows\system32\drivers\adpu320.sys
21:32:05.0652 0288    adpu320 - ok
21:32:05.0667 0288    AeLookupSvc     (0f421175574bfe0bf2f4d8e910a253bb) C:\Windows\System32\aelupsvc.dll
21:32:05.0683 0288    AeLookupSvc - ok
21:32:05.0730 0288    afcdp           (b794dd8acc5cc76177156463dab4bebb) C:\Windows\system32\DRIVERS\afcdp.sys
21:32:05.0746 0288    afcdp - ok
21:32:06.0089 0288    afcdpsrv        (5555e5ce43de53fe4c2f19a1163c49a0) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
21:32:06.0183 0288    afcdpsrv - ok
21:32:06.0574 0288    AFD             (0cc146c4addea45791b18b1e2659f4a9) C:\Windows\system32\drivers\afd.sys
21:32:06.0589 0288    AFD - ok
21:32:06.0621 0288    agp440          (5ccdd13bc602ae33cd8b62d33c29ab72) C:\Windows\system32\drivers\agp440.sys
21:32:06.0621 0288    agp440 - ok
21:32:06.0652 0288    aic78xx         (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys
21:32:06.0652 0288    aic78xx - ok
21:32:06.0683 0288    ALG             (5922f4f59b7868f3d74bbbbeb7b825a3) C:\Windows\System32\alg.exe
21:32:06.0699 0288    ALG - ok
21:32:06.0714 0288    aliide          (157d0898d4b73f075ce9fa26b482df98) C:\Windows\system32\drivers\aliide.sys
21:32:06.0714 0288    aliide - ok
21:32:06.0714 0288    amdide          (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys
21:32:06.0714 0288    amdide - ok
21:32:06.0777 0288    AmdK8           (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\DRIVERS\amdk8.sys
21:32:06.0777 0288    AmdK8 - ok
21:32:06.0777 0288    Appinfo         (9c37b3fd5615477cb9a0cd116cf43f5c) C:\Windows\System32\appinfo.dll
21:32:06.0792 0288    Appinfo - ok
21:32:06.0808 0288    arc             (2e8623f2fed998a97129a3db919551c8) C:\Windows\system32\drivers\arc.sys
21:32:06.0808 0288    arc - ok
21:32:06.0839 0288    arcsas          (741a003c041a3ec480a2e71af71e9654) C:\Windows\system32\drivers\arcsas.sys
21:32:06.0839 0288    arcsas - ok
21:32:06.0871 0288    AsyncMac        (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys
21:32:06.0871 0288    AsyncMac - ok
21:32:06.0917 0288    atapi           (e68d9b3a3905619732f7fe039466a623) C:\Windows\system32\drivers\atapi.sys
21:32:06.0917 0288    atapi - ok
21:32:06.0996 0288    Ati External Event Utility (3e7054ea6dcc7ad42b5b480a8998cc90) C:\Windows\system32\Ati2evxx.exe
21:32:07.0011 0288    Ati External Event Utility - ok
21:32:07.0277 0288    atikmdag        (0500b413a138e2f68dc00f30cfb8e181) C:\Windows\system32\DRIVERS\atikmdag.sys
21:32:07.0386 0288    atikmdag - ok
21:32:07.0527 0288    AudioEndpointBuilder (79318c744693ec983d20e9337a2f8196) C:\Windows\System32\Audiosrv.dll
21:32:07.0542 0288    AudioEndpointBuilder - ok
21:32:07.0542 0288    AudioSrv        (79318c744693ec983d20e9337a2f8196) C:\Windows\System32\Audiosrv.dll
21:32:07.0558 0288    AudioSrv - ok
21:32:07.0589 0288    Beep - ok
21:32:07.0652 0288    BFE             (ffb96c2589ffa60473ead78b39fbde29) C:\Windows\System32\bfe.dll
21:32:07.0667 0288    BFE - ok
21:32:07.0746 0288    BITS            (6d316f4859634071cc25c4fd4589ad2c) C:\Windows\system32\qmgr.dll
21:32:07.0761 0288    BITS - ok
21:32:07.0792 0288    blbdrive - ok
21:32:07.0855 0288    bowser          (2348447a80920b2493a9b582a23e81e1) C:\Windows\system32\DRIVERS\bowser.sys
21:32:07.0855 0288    bowser - ok
21:32:07.0886 0288    BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys
21:32:07.0886 0288    BrFiltLo - ok
21:32:07.0933 0288    BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys
21:32:07.0933 0288    BrFiltUp - ok
21:32:08.0089 0288    Browser         (a1b39de453433b115b4ea69ee0343816) C:\Windows\System32\browser.dll
21:32:08.0089 0288    Browser - ok
21:32:08.0136 0288    Brserid         (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys
21:32:08.0136 0288    Brserid - ok
21:32:08.0152 0288    BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys
21:32:08.0152 0288    BrSerWdm - ok
21:32:08.0167 0288    BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys
21:32:08.0167 0288    BrUsbMdm - ok
21:32:08.0183 0288    BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys
21:32:08.0183 0288    BrUsbSer - ok
21:32:08.0199 0288    BTHMODEM        (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys
21:32:08.0199 0288    BTHMODEM - ok
21:32:08.0214 0288    catchme - ok
21:32:08.0277 0288    cdfs            (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys
21:32:08.0277 0288    cdfs - ok
21:32:08.0277 0288    Cdr4_2K - ok
21:32:08.0292 0288    Cdralw2k - ok
21:32:08.0308 0288    Cdralwnt - ok
21:32:08.0480 0288    cdrom           (c025aa69be3d0d25c7a2e746ef6f94fc) C:\Windows\system32\DRIVERS\cdrom.sys
21:32:08.0511 0288    cdrom - ok
21:32:08.0589 0288    CertPropSvc     (5a268127633c7ee2a7fb87f39d748d56) C:\Windows\System32\certprop.dll
21:32:08.0589 0288    CertPropSvc - ok
21:32:08.0605 0288    circlass        (f28f00596824058bc61d5edf434c9b82) C:\Windows\system32\drivers\circlass.sys
21:32:08.0605 0288    circlass - ok
21:32:08.0667 0288    CLFS            (3dca9a18b204939cfb24bea53e31eb48) C:\Windows\system32\CLFS.sys
21:32:08.0667 0288    CLFS - ok
21:32:08.0746 0288    clr_optimization_v2.0.50727_32 (8ee772032e2fe80a924f3b8dd5082194) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
21:32:08.0746 0288    clr_optimization_v2.0.50727_32 - ok
21:32:08.0792 0288    clr_optimization_v2.0.50727_64 (ce07a466201096f021cd09d631b21540) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
21:32:08.0808 0288    clr_optimization_v2.0.50727_64 - ok
21:32:08.0839 0288    clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
21:32:08.0839 0288    clr_optimization_v4.0.30319_32 - ok
21:32:08.0871 0288    clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
21:32:08.0886 0288    clr_optimization_v4.0.30319_64 - ok
21:32:08.0902 0288    cmdide          (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys
21:32:08.0902 0288    cmdide - ok
21:32:08.0917 0288    Compbatt        (0e77a445640bf310817f60941c50560c) C:\Windows\system32\drivers\compbatt.sys
21:32:08.0917 0288    Compbatt - ok
21:32:08.0917 0288    COMSysApp - ok
21:32:08.0949 0288    crcdisk         (b1192dcd5b9cf46beed0e2a9e5bcf59a) C:\Windows\system32\drivers\crcdisk.sys
21:32:08.0949 0288    crcdisk - ok
21:32:09.0011 0288    CryptSvc        (18918613e63f387cde4d95ca7d49dcf7) C:\Windows\system32\cryptsvc.dll
21:32:09.0027 0288    CryptSvc - ok
21:32:09.0121 0288    DcomLaunch      (cf8b9a3a5e7dc57724a89d0c3e8cf9ef) C:\Windows\system32\rpcss.dll
21:32:09.0121 0288    DcomLaunch - ok
21:32:09.0214 0288    DfsC            (8b722ba35205c71e7951cdc4cdbade19) C:\Windows\system32\Drivers\dfsc.sys
21:32:09.0214 0288    DfsC - ok
21:32:09.0417 0288    DFSR            (c647f468f7de343df8c143655c5557d4) C:\Windows\system32\DFSR.exe
21:32:09.0511 0288    DFSR - ok
21:32:09.0621 0288    Dhcp            (3ed0321127ce70acdaabbf77e157c2a7) C:\Windows\System32\dhcpcsvc.dll
21:32:09.0636 0288    Dhcp - ok
21:32:09.0714 0288    disk            (b0107e40ecdb5fa692ebf832f295d905) C:\Windows\system32\drivers\disk.sys
21:32:09.0714 0288    disk - ok
21:32:09.0761 0288    Dnscache        (06230f1b721494a6df8d47fd395bb1b0) C:\Windows\System32\dnsrslvr.dll
21:32:09.0761 0288    Dnscache - ok
21:32:09.0824 0288    dot3svc         (1a7156dd1e850e9914e5e991e3225b94) C:\Windows\System32\dot3svc.dll
21:32:09.0824 0288    dot3svc - ok
21:32:09.0886 0288    DPS             (1583b39790db3eaec7edb0cb0140c708) C:\Windows\system32\dps.dll
21:32:09.0886 0288    DPS - ok
21:32:09.0917 0288    drmkaud         (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys
21:32:09.0917 0288    drmkaud - ok
21:32:09.0996 0288    DXGKrnl         (b8e554e502d5123bc111f99d6a2181b4) C:\Windows\System32\drivers\dxgkrnl.sys
21:32:10.0011 0288    DXGKrnl - ok
21:32:10.0027 0288    E1G60           (d57fe09b575545738a73a0c193d0616a) C:\Windows\system32\DRIVERS\E1G6032E.sys
21:32:10.0042 0288    E1G60 - ok
21:32:10.0089 0288    EapHost         (c2303883fd9be49dc36a6400643002ea) C:\Windows\System32\eapsvc.dll
21:32:10.0089 0288    EapHost - ok
21:32:10.0152 0288    Ecache          (5f94962be5a62db6e447ff6470c4f48a) C:\Windows\system32\drivers\ecache.sys
21:32:10.0152 0288    Ecache - ok
21:32:10.0199 0288    ehRecvr         (14ce384d2e27b64c256bda4dc39c312d) C:\Windows\ehome\ehRecvr.exe
21:32:10.0214 0288    ehRecvr - ok
21:32:10.0246 0288    ehSched         (b93159c1313d66fdfbbe876f5189cd52) C:\Windows\ehome\ehsched.exe
21:32:10.0246 0288    ehSched - ok
21:32:10.0277 0288    ehstart         (f5ee2527d74449868e3c3227a59bcd28) C:\Windows\ehome\ehstart.dll
21:32:10.0277 0288    ehstart - ok
21:32:10.0308 0288    elxstor         (3d6298aff3fe06c0616ce5d090a3eeaa) C:\Windows\system32\drivers\elxstor.sys
21:32:10.0324 0288    elxstor - ok
21:32:10.0386 0288    EMDMgmt         (a9b18b63a4fd6baab83326706d857fab) C:\Windows\system32\emdmgmt.dll
21:32:10.0386 0288    EMDMgmt - ok
21:32:10.0464 0288    EventSystem     (e12f22b73f153dece721cd45ec05b4af) C:\Windows\system32\es.dll
21:32:10.0464 0288    EventSystem - ok
21:32:10.0542 0288    exfat           (486844f47b6636044a42454614ed4523) C:\Windows\system32\drivers\exfat.sys
21:32:10.0542 0288    exfat - ok
21:32:10.0589 0288    fastfat         (1a4bee34277784619ddaf0422c0c6e23) C:\Windows\system32\drivers\fastfat.sys
21:32:10.0605 0288    fastfat - ok
21:32:10.0652 0288    fdc             (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys
21:32:10.0652 0288    fdc - ok
21:32:10.0683 0288    fdPHost         (bb9267acacd8b7533dd936c34a0cba5e) C:\Windows\system32\fdPHost.dll
21:32:10.0683 0288    fdPHost - ok
21:32:10.0714 0288    FDResPub        (300c80931eabbe1db7591c516efe8d0f) C:\Windows\system32\fdrespub.dll
21:32:10.0714 0288    FDResPub - ok
21:32:10.0761 0288    FileInfo        (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys
21:32:10.0761 0288    FileInfo - ok
21:32:10.0792 0288    Filetrace       (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys
21:32:10.0792 0288    Filetrace - ok
21:32:10.0839 0288    flpydisk        (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
21:32:10.0839 0288    flpydisk - ok
21:32:10.0902 0288    FltMgr          (e3041bc26d6930d61f42aedb79c91720) C:\Windows\system32\drivers\fltmgr.sys
21:32:10.0902 0288    FltMgr - ok
21:32:10.0964 0288    fltsrv          (d4463a74e1bfbf3fb9b4fc6cf5390152) C:\Windows\system32\DRIVERS\fltsrv.sys
21:32:10.0964 0288    fltsrv - ok
21:32:11.0042 0288    FontCache       (be1c5bd1ca7ed015bc6fa1ae67e592c8) C:\Windows\system32\FntCache.dll
21:32:11.0058 0288    FontCache - ok
21:32:11.0167 0288    FontCache3.0.0.0 (bc5b0be5af3510b0fd8c140ee42c6d3e) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
21:32:11.0167 0288    FontCache3.0.0.0 - ok
21:32:11.0214 0288    Fs_Rec          (29d99e860a1ca0a03c6a733fdd0da703) C:\Windows\system32\drivers\Fs_Rec.sys
21:32:11.0214 0288    Fs_Rec - ok
21:32:11.0246 0288    gagp30kx        (b54520cc7b4b55134d7527b1cd3fc1f2) C:\Windows\system32\drivers\gagp30kx.sys
21:32:11.0246 0288    gagp30kx - ok
21:32:11.0324 0288    gpsvc           (a0e1b575ba8f504968cd40c0faeb2384) C:\Windows\System32\gpsvc.dll
21:32:11.0339 0288    gpsvc - ok
21:32:11.0355 0288    grmnusb         (2ed7ff3e1ada4092632393781518b3a7) C:\Windows\system32\drivers\grmnusb.sys
21:32:11.0355 0288    grmnusb - ok
21:32:11.0464 0288    gusvc           (c1b577b2169900f4cf7190c39f085794) C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
21:32:11.0480 0288    gusvc - ok
21:32:11.0527 0288    HdAudAddService (68e732382b32417ff61fd663259b4b09) C:\Windows\system32\drivers\HdAudio.sys
21:32:11.0527 0288    HdAudAddService - ok
21:32:11.0621 0288    HDAudBus        (f942c5820205f2fb453243edfec82a3d) C:\Windows\system32\DRIVERS\HDAudBus.sys
21:32:11.0636 0288    HDAudBus - ok
21:32:11.0667 0288    HidBth          (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys
21:32:11.0667 0288    HidBth - ok
21:32:11.0683 0288    HidIr           (4e77a77e2c986e8f88f996bb3e1ad829) C:\Windows\system32\drivers\hidir.sys
21:32:11.0683 0288    HidIr - ok
21:32:11.0714 0288    hidserv         (59361d38a297755d46a540e450202b2a) C:\Windows\System32\hidserv.dll
21:32:11.0714 0288    hidserv - ok
21:32:11.0761 0288    HidUsb          (443bdd2d30bb4f00795c797e2cf99edf) C:\Windows\system32\DRIVERS\hidusb.sys
21:32:11.0761 0288    HidUsb - ok
21:32:11.0824 0288    hkmsvc          (b12f367ea39c0795fd57e31242ce1a5a) C:\Windows\system32\kmsvc.dll
21:32:11.0839 0288    hkmsvc - ok
21:32:11.0855 0288    HpCISSs         (8edc820115df1e04763b2923676ea5b2) C:\Windows\system32\drivers\hpcisss.sys
21:32:11.0855 0288    HpCISSs - ok
21:32:11.0933 0288    HTTP            (098f1e4e5c9cb5b0063a959063631610) C:\Windows\system32\drivers\HTTP.sys
21:32:11.0949 0288    HTTP - ok
21:32:11.0996 0288    i2omp           (f2901763845570ecac48e6a50ec50812) C:\Windows\system32\drivers\i2omp.sys
21:32:11.0996 0288    i2omp - ok
21:32:12.0027 0288    i8042prt        (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys
21:32:12.0027 0288    i8042prt - ok
21:32:12.0074 0288    iaStorV         (72c3ee7ea3cd75a772e62ae0e5df8b8c) C:\Windows\system32\drivers\iastorv.sys
21:32:12.0089 0288    iaStorV - ok
21:32:12.0246 0288    idsvc           (749f5f8cedca70f2a512945325fc489d) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
21:32:12.0261 0288    idsvc - ok
21:32:12.0277 0288    iirsp           (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys
21:32:12.0277 0288    iirsp - ok
21:32:12.0339 0288    IKEEXT          (0c9ea6e654e7b0471741e343a6c671af) C:\Windows\System32\ikeext.dll
21:32:12.0355 0288    IKEEXT - ok
21:32:12.0371 0288    intelide        (36a266c673812878996f72b200203fbb) C:\Windows\system32\drivers\intelide.sys
21:32:12.0371 0288    intelide - ok
21:32:12.0386 0288    intelppm        (cd802075728e514548841dcc3f8b0220) C:\Windows\system32\DRIVERS\intelppm.sys
21:32:12.0386 0288    intelppm - ok
21:32:12.0433 0288    IPBusEnum       (5624bc1bc5eeb49c0ab76a8114f05ea3) C:\Windows\system32\ipbusenum.dll
21:32:12.0433 0288    IPBusEnum - ok
21:32:12.0464 0288    IpFilterDriver  (d8aabc341311e4780d6fce8c73c0ad81) C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:32:12.0464 0288    IpFilterDriver - ok
21:32:12.0511 0288    iphlpsvc        (bf0dbfa9792c5c14fa00f61c75116c1b) C:\Windows\System32\iphlpsvc.dll
21:32:12.0527 0288    iphlpsvc - ok
21:32:12.0527 0288    IpInIp - ok
21:32:12.0558 0288    IPMIDRV         (eacdbbe429c6d170bdeee0effcbc317b) C:\Windows\system32\drivers\ipmidrv.sys
21:32:12.0558 0288    IPMIDRV - ok
21:32:12.0589 0288    IPNAT           (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys
21:32:12.0589 0288    IPNAT - ok
21:32:12.0621 0288    IRENUM          (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys
21:32:12.0621 0288    IRENUM - ok
21:32:12.0636 0288    isapnp          (d3bb520b31f28c1a065cd058e762ee73) C:\Windows\system32\drivers\isapnp.sys
21:32:12.0636 0288    isapnp - ok
21:32:12.0699 0288    iScsiPrt        (e4fdf99599f27ec25d2cf6d754243520) C:\Windows\system32\DRIVERS\msiscsi.sys
21:32:12.0699 0288    iScsiPrt - ok
21:32:12.0714 0288    iteatapi        (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys
21:32:12.0714 0288    iteatapi - ok
21:32:12.0746 0288    iteraid         (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys
21:32:12.0746 0288    iteraid - ok
21:32:12.0777 0288    kbdclass        (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys
21:32:12.0777 0288    kbdclass - ok
21:32:12.0792 0288    kbdhid          (2b08052372c1f0dffc31cdd6e5abc4b5) C:\Windows\system32\DRIVERS\kbdhid.sys
21:32:12.0792 0288    kbdhid - ok
21:32:12.0839 0288    KeyIso          (40348dcec0712ed42231c5f90a69a690) C:\Windows\system32\lsass.exe
21:32:12.0839 0288    KeyIso - ok
21:32:12.0871 0288    KSecDD          (476e2c1dcea45895994bef11c2a98715) C:\Windows\system32\Drivers\ksecdd.sys
21:32:12.0871 0288    KSecDD - ok
21:32:12.0917 0288    ksthunk         (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys
21:32:12.0917 0288    ksthunk - ok
21:32:12.0980 0288    KtmRm           (1faf6926f3416d3da05c5b265491bdae) C:\Windows\system32\msdtckrm.dll
21:32:13.0011 0288    KtmRm - ok
21:32:13.0105 0288    LanmanServer    (50c7a3cb427e9bb5ed0708a669956ab5) C:\Windows\System32\srvsvc.dll
21:32:13.0105 0288    LanmanServer - ok
21:32:13.0167 0288    LanmanWorkstation (caf86fc1388be1e470f1a7b43e348adb) C:\Windows\System32\wkssvc.dll
21:32:13.0167 0288    LanmanWorkstation - ok
21:32:13.0214 0288    lltdio          (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys
21:32:13.0214 0288    lltdio - ok
21:32:13.0246 0288    lltdsvc         (961ccbd0b1ccb5675d64976fae37d092) C:\Windows\System32\lltdsvc.dll
21:32:13.0246 0288    lltdsvc - ok
21:32:13.0261 0288    lmhosts         (a47f8080cacc23c91fe823ad19aa5612) C:\Windows\System32\lmhsvc.dll
21:32:13.0261 0288    lmhosts - ok
21:32:13.0292 0288    LSI_FC          (1572f8d999c0ab4376afdce058a78df9) C:\Windows\system32\drivers\lsi_fc.sys
21:32:13.0292 0288    LSI_FC - ok
21:32:13.0324 0288    LSI_SAS         (64470979c3e3c9ff60edfb5230c56e0e) C:\Windows\system32\drivers\lsi_sas.sys
21:32:13.0324 0288    LSI_SAS - ok
21:32:13.0339 0288    LSI_SCSI        (4ced7d3b54bfc5bbae75c4a73c7f7428) C:\Windows\system32\drivers\lsi_scsi.sys
21:32:13.0339 0288    LSI_SCSI - ok
21:32:13.0402 0288    luafv           (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys
21:32:13.0402 0288    luafv - ok
21:32:13.0699 0288    MatSvc          (ec470d91ef06a59397edc18d48899cc5) C:\Program Files\Microsoft Fix it Center\Matsvc.exe
21:32:13.0714 0288    MatSvc - ok
21:32:13.0730 0288    Mcx2Svc         (76a58df02bd4ea29f189b82d0bef17f8) C:\Windows\system32\Mcx2Svc.dll
21:32:13.0730 0288    Mcx2Svc - ok
21:32:13.0746 0288    megasas         (2f631c2939d5f2e8958935ee701d70d7) C:\Windows\system32\drivers\megasas.sys
21:32:13.0746 0288    megasas - ok
21:32:13.0792 0288    MMCSS           (3cbe4995e80e13ccfbc42e5dcf3ac81a) C:\Windows\system32\mmcss.dll
21:32:13.0792 0288    MMCSS - ok
21:32:13.0824 0288    Modem           (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys
21:32:13.0824 0288    Modem - ok
21:32:13.0855 0288    monitor         (6f7e338a173e75f2034aacf88217840a) C:\Windows\system32\DRIVERS\monitor.sys
21:32:13.0855 0288    monitor - ok
21:32:13.0917 0288    mouclass        (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys
21:32:13.0917 0288    mouclass - ok
21:32:13.0949 0288    mouhid          (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys
21:32:13.0949 0288    mouhid - ok
21:32:13.0996 0288    MountMgr        (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys
21:32:13.0996 0288    MountMgr - ok
21:32:14.0121 0288    MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
21:32:14.0121 0288    MozillaMaintenance - ok
21:32:14.0183 0288    MpFilter        (94c66ededcdb6a126880472f9a704d8e) C:\Windows\system32\DRIVERS\MpFilter.sys
21:32:14.0183 0288    MpFilter - ok
21:32:14.0214 0288    mpio            (ed48eac719ee28db773359eb1b06e2b5) C:\Windows\system32\drivers\mpio.sys
21:32:14.0230 0288    mpio - ok
21:32:14.0324 0288    MpKsle6be6eba   (0ebb390b7aeec45ec061d9870a34fd42) C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{C7944C4F-1B1E-4CB3-87FF-266576DC0293}\MpKsle6be6eba.sys
21:32:14.0324 0288    MpKsle6be6eba - ok
21:32:14.0386 0288    mpsdrv          (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys
21:32:14.0386 0288    mpsdrv - ok
21:32:14.0449 0288    MpsSvc          (897e3baf68ba406a61682ae39c83900c) C:\Windows\system32\mpssvc.dll
21:32:14.0464 0288    MpsSvc - ok
21:32:14.0496 0288    Mraid35x        (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys
21:32:14.0496 0288    Mraid35x - ok
21:32:14.0527 0288    MRxDAV          (7c1de4aa96dc0c071611f9e7de02a68d) C:\Windows\system32\drivers\mrxdav.sys
21:32:14.0542 0288    MRxDAV - ok
21:32:14.0589 0288    mrxsmb          (1485811b320ff8c7edad1caebb1c6c2b) C:\Windows\system32\DRIVERS\mrxsmb.sys
21:32:14.0589 0288    mrxsmb - ok
21:32:14.0652 0288    mrxsmb10        (3b929a60c833fc615fd97fba82bc7632) C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:32:14.0652 0288    mrxsmb10 - ok
21:32:14.0667 0288    mrxsmb20        (c64ab3e1f53b4f5b5bb6d796b2d7bec3) C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:32:14.0683 0288    mrxsmb20 - ok
21:32:14.0699 0288    msahci          (eeadf970795148bfbb1db3abcc89c16b) C:\Windows\system32\drivers\msahci.sys
21:32:14.0699 0288    msahci - ok
21:32:14.0714 0288    msdsm           (96d7c0a1b98434c6e4ff0c2e26a0e20a) C:\Windows\system32\drivers\msdsm.sys
21:32:14.0714 0288    msdsm - ok
21:32:14.0761 0288    MSDTC           (7ec02ce772f068ed0beafa3da341a9bc) C:\Windows\System32\msdtc.exe
21:32:14.0761 0288    MSDTC - ok
21:32:14.0824 0288    Msfs            (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys
21:32:14.0824 0288    Msfs - ok
21:32:14.0855 0288    msisadrv        (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys
21:32:14.0855 0288    msisadrv - ok
21:32:14.0917 0288    MSiSCSI         (366b0c1f4478b519c181e37d43dcda32) C:\Windows\system32\iscsiexe.dll
21:32:14.0933 0288    MSiSCSI - ok
21:32:14.0949 0288    msiserver - ok
21:32:14.0980 0288    MSKSSRV         (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys
21:32:14.0980 0288    MSKSSRV - ok
21:32:15.0058 0288    MsMpSvc         (59faaf2c83c8169ea20f9e335e418907) C:\Program Files\Microsoft Security Client\MsMpEng.exe
21:32:15.0074 0288    MsMpSvc - ok
21:32:15.0089 0288    MSPCLOCK        (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys
21:32:15.0089 0288    MSPCLOCK - ok
21:32:15.0105 0288    MSPQM           (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys
21:32:15.0105 0288    MSPQM - ok
21:32:15.0167 0288    MsRPC           (dc6ccf440cdede4293db41c37a5060a5) C:\Windows\system32\drivers\MsRPC.sys
21:32:15.0167 0288    MsRPC - ok
21:32:15.0230 0288    mssmbios        (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys
21:32:15.0230 0288    mssmbios - ok
21:32:15.0277 0288    MSTEE           (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys
21:32:15.0277 0288    MSTEE - ok
21:32:15.0324 0288    Mup             (0cc49f78d8aca0877d885f149084e543) C:\Windows\system32\Drivers\mup.sys
21:32:15.0324 0288    Mup - ok
21:32:15.0371 0288    napagent        (a5b10c845e7538c60c0f5d87a57cb3f5) C:\Windows\system32\qagentRT.dll
21:32:15.0386 0288    napagent - ok
21:32:15.0433 0288    NativeWifiP     (2007b826c4acd94ae32232b41f0842b9) C:\Windows\system32\DRIVERS\nwifi.sys
21:32:15.0449 0288    NativeWifiP - ok
21:32:15.0527 0288    NDIS            (65950e07329fcee8e6516b17c8d0abb6) C:\Windows\system32\drivers\ndis.sys
21:32:15.0542 0288    NDIS - ok
21:32:15.0589 0288    NdisTapi        (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys
21:32:15.0589 0288    NdisTapi - ok
21:32:15.0605 0288    Ndisuio         (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys
21:32:15.0605 0288    Ndisuio - ok
21:32:15.0652 0288    NdisWan         (f8158771905260982ce724076419ef19) C:\Windows\system32\DRIVERS\ndiswan.sys
21:32:15.0667 0288    NdisWan - ok
21:32:15.0683 0288    NDProxy         (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys
21:32:15.0683 0288    NDProxy - ok
21:32:15.0714 0288    NetBIOS         (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys
21:32:15.0714 0288    NetBIOS - ok
21:32:15.0777 0288    netbt           (fc2c792ebddc8e28df939d6a92c83d61) C:\Windows\system32\DRIVERS\netbt.sys
21:32:15.0792 0288    netbt - ok
21:32:15.0824 0288    Netlogon        (40348dcec0712ed42231c5f90a69a690) C:\Windows\system32\lsass.exe
21:32:15.0824 0288    Netlogon - ok
21:32:15.0902 0288    Netman          (9b63b29defc0f3115a559d2597bf5d75) C:\Windows\System32\netman.dll
21:32:15.0902 0288    Netman - ok
21:32:15.0933 0288    netprofm        (7846d0136cc2b264926a73047ba7688a) C:\Windows\System32\netprofm.dll
21:32:15.0933 0288    netprofm - ok
21:32:16.0027 0288    NetTcpPortSharing (74751dda198165947fd7454d83f49825) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
21:32:16.0027 0288    NetTcpPortSharing - ok
21:32:16.0074 0288    nfrd960         (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys
21:32:16.0074 0288    nfrd960 - ok
21:32:16.0121 0288    NisDrv          (91b4e0273d2f6c24ef845f2b41311289) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
21:32:16.0121 0288    NisDrv - ok
21:32:16.0214 0288    NisSrv          (10a43829a9e606af3eef25a1c1665923) C:\Program Files\Microsoft Security Client\NisSrv.exe
21:32:16.0214 0288    NisSrv - ok
21:32:16.0277 0288    NlaSvc          (f145bf4c4668e7e312069f81ef847cfc) C:\Windows\System32\nlasvc.dll
21:32:16.0292 0288    NlaSvc - ok
21:32:16.0339 0288    Npfs            (b298874f8e0ea93f06ec40aa8d146478) C:\Windows\system32\drivers\Npfs.sys
21:32:16.0339 0288    Npfs - ok
21:32:16.0386 0288    nsi             (acb62baa1c319b17752553df3026eeeb) C:\Windows\system32\nsisvc.dll
21:32:16.0386 0288    nsi - ok
21:32:16.0402 0288    nsiproxy        (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys
21:32:16.0402 0288    nsiproxy - ok
21:32:16.0511 0288    Ntfs            (bac869dfb98e499ba4d9bb1fb43270e1) C:\Windows\system32\drivers\Ntfs.sys
21:32:16.0558 0288    Ntfs - ok
21:32:16.0683 0288    NtmsSvc         (96e310ec2bb1fc55fa4d32839aa990a2) C:\Windows\system32\ntmssvc.dll
21:32:16.0699 0288    NtmsSvc - ok
21:32:16.0746 0288    Null            (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys
21:32:16.0746 0288    Null - ok
21:32:16.0855 0288    NVENETFD        (98350606682594521d56eccb5d01ecf7) C:\Windows\system32\DRIVERS\nvmfdx64.sys
21:32:16.0855 0288    NVENETFD - ok
21:32:16.0917 0288    nvraid          (840eeb44dc49317a6161961f7682cd99) C:\Windows\system32\drivers\nvraid.sys
21:32:16.0917 0288    nvraid - ok
21:32:16.0933 0288    nvstor          (94c5334040a5d500897f4c5fd12aeede) C:\Windows\system32\drivers\nvstor.sys
21:32:16.0933 0288    nvstor - ok
21:32:16.0964 0288    nv_agp          (aa1b6c86a4763502e20b65c025f39bad) C:\Windows\system32\drivers\nv_agp.sys
21:32:16.0980 0288    nv_agp - ok
21:32:16.0980 0288    NwlnkFlt - ok
21:32:16.0980 0288    NwlnkFwd - ok
21:32:17.0042 0288    ohci1394        (b5b1ce65ac15bbd11c0619e3ef7cfc28) C:\Windows\system32\DRIVERS\ohci1394.sys
21:32:17.0042 0288    ohci1394 - ok
21:32:17.0121 0288    p2pimsvc        (9ae31d2e1d15c10d91318e0ec149ceac) C:\Windows\system32\p2psvc.dll
21:32:17.0136 0288    p2pimsvc - ok
21:32:17.0152 0288    p2psvc          (9ae31d2e1d15c10d91318e0ec149ceac) C:\Windows\system32\p2psvc.dll
21:32:17.0152 0288    p2psvc - ok
21:32:17.0214 0288    Parport         (4c6a7fd04ddf4db88791048382e3edb1) C:\Windows\system32\DRIVERS\parport.sys
21:32:17.0214 0288    Parport - ok
21:32:17.0246 0288    partmgr         (f9b5eda4c17a2be7663f064dbf0fe254) C:\Windows\system32\drivers\partmgr.sys
21:32:17.0246 0288    partmgr - ok
21:32:17.0292 0288    PcaSvc          (9ab157b374192ff276c1628fbdba2b0e) C:\Windows\System32\pcasvc.dll
21:32:17.0308 0288    PcaSvc - ok
21:32:17.0355 0288    pci             (47ab1e0fc9d0e12bb53ba246e3a0906d) C:\Windows\system32\drivers\pci.sys
21:32:17.0355 0288    pci - ok
21:32:17.0386 0288    pciide          (2657f6c0b78c36d95034be109336e382) C:\Windows\system32\drivers\pciide.sys
21:32:17.0386 0288    pciide - ok
21:32:17.0417 0288    pcmcia          (037661f3d7c507c9993b7010ceee6288) C:\Windows\system32\drivers\pcmcia.sys
21:32:17.0433 0288    pcmcia - ok
21:32:17.0480 0288    PEAUTH          (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys
21:32:17.0496 0288    PEAUTH - ok
21:32:17.0589 0288    PerfHost        (0ed8727ea0172860f47258456c06caea) C:\Windows\SysWow64\perfhost.exe
21:32:17.0589 0288    PerfHost - ok
21:32:17.0683 0288    pla             (e9e68c1a0f25cf4a7ac966eea74ee89e) C:\Windows\system32\pla.dll
21:32:17.0699 0288    pla - ok
21:32:17.0761 0288    PlugPlay        (fe6b0f59215c9fd9f9d26539c58c8b82) C:\Windows\system32\umpnpmgr.dll
21:32:17.0761 0288    PlugPlay - ok
21:32:17.0855 0288    PNRPAutoReg     (9ae31d2e1d15c10d91318e0ec149ceac) C:\Windows\system32\p2psvc.dll
21:32:17.0855 0288    PNRPAutoReg - ok
21:32:17.0871 0288    PNRPsvc         (9ae31d2e1d15c10d91318e0ec149ceac) C:\Windows\system32\p2psvc.dll
21:32:17.0871 0288    PNRPsvc - ok
21:32:17.0949 0288    PolicyAgent     (89a5560671c2d8b4a4b51f3e1aa069d8) C:\Windows\System32\ipsecsvc.dll
21:32:17.0949 0288    PolicyAgent - ok
21:32:18.0214 0288    PptpMiniport    (23386e9952025f5f21c368971e2e7301) C:\Windows\system32\DRIVERS\raspptp.sys
21:32:18.0230 0288    PptpMiniport - ok
21:32:18.0246 0288    Processor       (6bc78e5f12cbb74e7930aaaa4a0db387) C:\Windows\system32\drivers\processr.sys
21:32:18.0246 0288    Processor - ok
21:32:18.0292 0288    ProfSvc         (e058ce4fc2449d8bfa14739c83b7ff2a) C:\Windows\system32\profsvc.dll
21:32:18.0324 0288    ProfSvc - ok
21:32:18.0386 0288    ProtectedStorage (40348dcec0712ed42231c5f90a69a690) C:\Windows\system32\lsass.exe
21:32:18.0386 0288    ProtectedStorage - ok
21:32:18.0464 0288    PSched          (c5ab7f0809392d0da027f4a2a81bfa31) C:\Windows\system32\DRIVERS\pacer.sys
21:32:18.0464 0288    PSched - ok
21:32:18.0542 0288    ql2300          (4a29d25704917161bad9b4659a248dfd) C:\Windows\system32\drivers\ql2300.sys
21:32:18.0558 0288    ql2300 - ok
21:32:18.0589 0288    ql40xx          (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys
21:32:18.0589 0288    ql40xx - ok
21:32:18.0652 0288    QWAVE           (90574842c3da781e279061a3eff91f07) C:\Windows\system32\qwave.dll
21:32:18.0652 0288    QWAVE - ok
21:32:18.0667 0288    QWAVEdrv        (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys
21:32:18.0667 0288    QWAVEdrv - ok
21:32:18.0996 0288    R300            (0500b413a138e2f68dc00f30cfb8e181) C:\Windows\system32\DRIVERS\atikmdag.sys
21:32:19.0027 0288    R300 - ok
21:32:19.0167 0288    RasAcd          (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys
21:32:19.0167 0288    RasAcd - ok
21:32:19.0214 0288    RasAuto         (b2ae18f847d07f0044404ddf7cb04497) C:\Windows\System32\rasauto.dll
21:32:19.0214 0288    RasAuto - ok
21:32:19.0261 0288    Rasl2tp         (ac7bc4d42a7e558718dfdec599bbfc2c) C:\Windows\system32\DRIVERS\rasl2tp.sys
21:32:19.0261 0288    Rasl2tp - ok
21:32:19.0292 0288    RasMan          (3ad83e4046c43be510de681588acb8af) C:\Windows\System32\rasmans.dll
21:32:19.0308 0288    RasMan - ok
21:32:19.0371 0288    RasPppoe        (4517fbf8b42524afe4ede1de102aae3e) C:\Windows\system32\DRIVERS\raspppoe.sys
21:32:19.0371 0288    RasPppoe - ok
21:32:19.0402 0288    RasSstp         (c6a593b51f34c33e5474539544072527) C:\Windows\system32\DRIVERS\rassstp.sys
21:32:19.0402 0288    RasSstp - ok
21:32:19.0464 0288    rdbss           (322db5c6b55e8d8ee8d6f358b2aaabb1) C:\Windows\system32\DRIVERS\rdbss.sys
21:32:19.0496 0288    rdbss - ok
21:32:19.0542 0288    RDPCDD          (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys
21:32:19.0542 0288    RDPCDD - ok
21:32:19.0605 0288    rdpdr           (2d98dda8edce73df99854bf3692ccc87) C:\Windows\system32\drivers\rdpdr.sys
21:32:19.0636 0288    rdpdr - ok
21:32:19.0636 0288    RDPENCDD        (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys
21:32:19.0652 0288    RDPENCDD - ok
21:32:19.0699 0288    RDPWD           (b1d741c87cea8d7282146366cc9c3f81) C:\Windows\system32\drivers\RDPWD.sys
21:32:19.0699 0288    RDPWD - ok
21:32:19.0761 0288    RemoteAccess    (c612b9557da73f70d41f8a6fbc8e5344) C:\Windows\System32\mprdim.dll
21:32:19.0761 0288    RemoteAccess - ok
21:32:19.0824 0288    RemoteRegistry  (44b9d8ec2f3ef3a0efb00857af70d861) C:\Windows\system32\regsvc.dll
21:32:19.0839 0288    RemoteRegistry - ok
21:32:19.0855 0288    RpcLocator      (f46c457840d4b7a4daafee739ce04102) C:\Windows\system32\locator.exe
21:32:19.0855 0288    RpcLocator - ok
21:32:19.0949 0288    RpcSs           (cf8b9a3a5e7dc57724a89d0c3e8cf9ef) C:\Windows\system32\rpcss.dll
21:32:19.0949 0288    RpcSs - ok
21:32:19.0996 0288    rspndr          (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys
21:32:19.0996 0288    rspndr - ok
21:32:20.0058 0288    SamSs           (40348dcec0712ed42231c5f90a69a690) C:\Windows\system32\lsass.exe
21:32:20.0058 0288    SamSs - ok
21:32:20.0199 0288    SASDIFSV        (3289766038db2cb14d07dc84392138d5) C:\Program Files (x86)\SASDIFSV64.SYS
21:32:20.0199 0288    SASDIFSV - ok
21:32:20.0214 0288    SASKUTIL        (58a38e75f3316a83c23df6173d41f2b5) C:\Program Files (x86)\SASKUTIL64.SYS
21:32:20.0214 0288    SASKUTIL - ok
21:32:20.0277 0288    SbieDrv         (0fe05dd9bbf0782e2bbf0977f2034616) C:\Program Files\Sandboxie\SbieDrv.sys
21:32:20.0292 0288    SbieDrv - ok
21:32:20.0308 0288    SbieSvc         (c970c7b2fd2e811525d4578d50b535f5) C:\Program Files\Sandboxie\SbieSvc.exe
21:32:20.0308 0288    SbieSvc - ok
21:32:20.0355 0288    sbp2port        (8c8862dc7417d89b375492c981c491f7) C:\Windows\system32\DRIVERS\sbp2port.sys
21:32:20.0355 0288    sbp2port - ok
21:32:20.0417 0288    SCardSvr        (fd1cdcf108d5ef3366f00d18b70fb89b) C:\Windows\System32\SCardSvr.dll
21:32:20.0417 0288    SCardSvr - ok
21:32:20.0511 0288    Schedule        (0f838c811ad295d2a4489b9993096c63) C:\Windows\system32\schedsvc.dll
21:32:20.0527 0288    Schedule - ok
21:32:20.0589 0288    SCPolicySvc     (5a268127633c7ee2a7fb87f39d748d56) C:\Windows\System32\certprop.dll
21:32:20.0589 0288    SCPolicySvc - ok
21:32:20.0636 0288    SDRSVC          (4ff71b076a7760fe75ea5ae2d0ee0018) C:\Windows\System32\SDRSVC.dll
21:32:20.0652 0288    SDRSVC - ok
21:32:20.0683 0288    secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
21:32:20.0683 0288    secdrv - ok
21:32:20.0683 0288    seclogon        (5acdcbc67fcf894a1815b9f96d704490) C:\Windows\system32\seclogon.dll
21:32:20.0699 0288    seclogon - ok
21:32:20.0746 0288    SENS            (90973a64b96cd647ff81c79443618eed) C:\Windows\system32\sens.dll
21:32:20.0746 0288    SENS - ok
21:32:20.0792 0288    Serenum         (2449316316411d65bd2c761a6ffb2ce2) C:\Windows\system32\DRIVERS\serenum.sys
21:32:20.0792 0288    Serenum - ok
21:32:20.0839 0288    Serial          (4b438170be2fc8e0bd35ee87a960f84f) C:\Windows\system32\DRIVERS\serial.sys
21:32:20.0839 0288    Serial - ok
21:32:20.0886 0288    sermouse        (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys
21:32:20.0886 0288    sermouse - ok
21:32:20.0980 0288    SessionEnv      (a8e4a4407a09f35dccc3771af590b0c4) C:\Windows\system32\sessenv.dll
21:32:20.0980 0288    SessionEnv - ok
21:32:20.0996 0288    sffdisk         (541b32f8d6b2dcb92ec43bab267e79ea) C:\Windows\system32\drivers\sffdisk.sys
21:32:20.0996 0288    sffdisk - ok
21:32:21.0011 0288    sffp_mmc        (446e7cca3325c7e0ae0fde7f73cdd9c2) C:\Windows\system32\drivers\sffp_mmc.sys
21:32:21.0027 0288    sffp_mmc - ok
21:32:21.0105 0288    sffp_sd         (67edc221348911e895af51c57d9a3725) C:\Windows\system32\drivers\sffp_sd.sys
21:32:21.0105 0288    sffp_sd - ok
21:32:21.0152 0288    sfloppy         (6b7838c94135768bd455cbdc23e39e5f) C:\Windows\system32\drivers\sfloppy.sys
21:32:21.0152 0288    sfloppy - ok
21:32:21.0214 0288    SharedAccess    (4c5aee179da7e1ee9a9ccb9da289af34) C:\Windows\System32\ipnathlp.dll
21:32:21.0214 0288    SharedAccess - ok
21:32:21.0277 0288    ShellHWDetection (56793271ecdedd350c5add305603e963) C:\Windows\System32\shsvcs.dll
21:32:21.0292 0288    ShellHWDetection - ok
21:32:21.0308 0288    SiSRaid2        (08dda16573fa44f8b13afe74597ad2e5) C:\Windows\system32\drivers\sisraid2.sys
21:32:21.0308 0288    SiSRaid2 - ok
21:32:21.0339 0288    SiSRaid4        (c52259e9daaf3890d572d87ffee0979e) C:\Windows\system32\drivers\sisraid4.sys
21:32:21.0339 0288    SiSRaid4 - ok
21:32:21.0496 0288    slsvc           (a9a27a8e257b45a604fdad4f26fe7241) C:\Windows\system32\SLsvc.exe
21:32:21.0527 0288    slsvc - ok
21:32:21.0667 0288    SLUINotify      (fd74b4b7c2088e390a30c85a896fc3af) C:\Windows\system32\SLUINotify.dll
21:32:21.0667 0288    SLUINotify - ok
21:32:21.0746 0288    Smb             (290b6f6a0ec4fcdfc90f5cb6d7020473) C:\Windows\system32\DRIVERS\smb.sys
21:32:21.0746 0288    Smb - ok
21:32:21.0808 0288    snapman         (f26aad9adfc9b62ac59a004a913c92da) C:\Windows\system32\DRIVERS\snapman.sys
21:32:21.0824 0288    snapman - ok
21:32:21.0839 0288    SNMPTRAP        (f8f47f38909823b1af28d60b96340cff) C:\Windows\System32\snmptrap.exe
21:32:21.0855 0288    SNMPTRAP - ok
21:32:21.0886 0288    spldr           (386c3c63f00a7040c7ec5e384217e89d) C:\Windows\system32\drivers\spldr.sys
21:32:21.0886 0288    spldr - ok
21:32:21.0949 0288    Spooler         (f66ff751e7efc816d266977939ef5dc3) C:\Windows\System32\spoolsv.exe
21:32:21.0949 0288    Spooler - ok
21:32:22.0027 0288    srv             (880a57fccb571ebd063d4dd50e93e46d) C:\Windows\system32\DRIVERS\srv.sys
21:32:22.0042 0288    srv - ok
21:32:22.0105 0288    srv2            (a1ad14a6d7a37891fffeca35ebbb0730) C:\Windows\system32\DRIVERS\srv2.sys
21:32:22.0121 0288    srv2 - ok
21:32:22.0167 0288    srvnet          (4bed62f4fa4d8300973f1151f4c4d8a7) C:\Windows\system32\DRIVERS\srvnet.sys
21:32:22.0167 0288    srvnet - ok
21:32:22.0246 0288    SSDPSRV         (192c74646ec5725aef3f80d19ff75f6a) C:\Windows\System32\ssdpsrv.dll
21:32:22.0261 0288    SSDPSRV - ok
21:32:22.0308 0288    SstpSvc         (2ee3fa0308e6185ba64a9a7f2e74332b) C:\Windows\system32\sstpsvc.dll
21:32:22.0324 0288    SstpSvc - ok
21:32:22.0386 0288    stisvc          (15825c1fbfb8779992cb65087f316af5) C:\Windows\System32\wiaservc.dll
21:32:22.0402 0288    stisvc - ok
21:32:22.0417 0288    swenum          (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys
21:32:22.0417 0288    swenum - ok
21:32:22.0480 0288    swprv           (6de37f4de19d4efd9c48c43addbc949a) C:\Windows\System32\swprv.dll
21:32:22.0496 0288    swprv - ok
21:32:22.0511 0288    Symc8xx         (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys
21:32:22.0511 0288    Symc8xx - ok
21:32:22.0527 0288    Sym_hi          (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys
21:32:22.0527 0288    Sym_hi - ok
21:32:22.0542 0288    Sym_u3          (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys
21:32:22.0542 0288    Sym_u3 - ok
21:32:22.0886 0288    syncagentsrv    (caaeb44422474ed5c13d988ae7ca4a1c) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
21:32:22.0980 0288    syncagentsrv - ok
21:32:23.0167 0288    SysMain         (92d7a8b0f87b036f17d25885937897a6) C:\Windows\system32\sysmain.dll
21:32:23.0183 0288    SysMain - ok
21:32:23.0214 0288    TabletInputService (005ce42567f9113a3bccb3b20073b029) C:\Windows\System32\TabSvc.dll
21:32:23.0214 0288    TabletInputService - ok
21:32:23.0277 0288    TapiSrv         (cc2562b4d55e0b6a4758c65407f63b79) C:\Windows\System32\tapisrv.dll
21:32:23.0277 0288    TapiSrv - ok
21:32:23.0339 0288    TBS             (cdbe8d7c1e201b911cdc346d06617fb5) C:\Windows\System32\tbssvc.dll
21:32:23.0339 0288    TBS - ok
21:32:23.0464 0288    Tcpip           (73bed5067ed53a9df05fa8eab42578d0) C:\Windows\system32\drivers\tcpip.sys
21:32:23.0480 0288    Tcpip - ok
21:32:23.0496 0288    Tcpip6          (73bed5067ed53a9df05fa8eab42578d0) C:\Windows\system32\DRIVERS\tcpip.sys
21:32:23.0511 0288    Tcpip6 - ok
21:32:23.0542 0288    tcpipreg        (848f87c604b5e674602498cb51067db6) C:\Windows\system32\drivers\tcpipreg.sys
21:32:23.0542 0288    tcpipreg - ok
21:32:23.0589 0288    TDPIPE          (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys
21:32:23.0589 0288    TDPIPE - ok
21:32:23.0714 0288    tdrpman         (7bc43335c778370fd0040d5224d8edeb) C:\Windows\system32\DRIVERS\tdrpman.sys
21:32:23.0730 0288    tdrpman - ok
21:32:23.0824 0288    TDTCP           (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys
21:32:23.0855 0288    TDTCP - ok
21:32:23.0980 0288    tdx             (458919c8c42e398dc4802178d5ffee27) C:\Windows\system32\DRIVERS\tdx.sys
21:32:23.0996 0288    tdx - ok
21:32:24.0011 0288    TermDD          (8c19678d22649ec002ef2282eae92f98) C:\Windows\system32\DRIVERS\termdd.sys
21:32:24.0027 0288    TermDD - ok
21:32:24.0089 0288    TermService     (5cdd30bc217082dac71a9878d9bfd566) C:\Windows\System32\termsrv.dll
21:32:24.0105 0288    TermService - ok
21:32:24.0152 0288    Themes          (56793271ecdedd350c5add305603e963) C:\Windows\system32\shsvcs.dll
21:32:24.0167 0288    Themes - ok
21:32:24.0214 0288    THREADORDER     (3cbe4995e80e13ccfbc42e5dcf3ac81a) C:\Windows\system32\mmcss.dll
21:32:24.0214 0288    THREADORDER - ok
21:32:24.0292 0288    timounter       (7d68eab50df8b71408b645ba8581800e) C:\Windows\system32\DRIVERS\timntr.sys
21:32:24.0308 0288    timounter - ok
21:32:24.0339 0288    TrkWks          (f4689f05af472a651a7b1b7b02d200e7) C:\Windows\System32\trkwks.dll
21:32:24.0355 0288    TrkWks - ok
21:32:24.0402 0288    TrustedInstaller (66328b08ef5a9305d8ede36b93930369) C:\Windows\servicing\TrustedInstaller.exe
21:32:24.0417 0288    TrustedInstaller - ok
21:32:24.0449 0288    tssecsrv        (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys
21:32:24.0449 0288    tssecsrv - ok
21:32:24.0496 0288    tunmp           (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys
21:32:24.0511 0288    tunmp - ok
21:32:24.0511 0288    tunnel          (30a9b3f45ad081bffc3bcaa9c812b609) C:\Windows\system32\DRIVERS\tunnel.sys
21:32:24.0511 0288    tunnel - ok
21:32:24.0542 0288    uagp35          (e4722dfbd6232acf17543ef2c2dce8d2) C:\Windows\system32\drivers\uagp35.sys
21:32:24.0558 0288    uagp35 - ok
21:32:24.0589 0288    udfs            (faf2640a2a76ed03d449e443194c4c34) C:\Windows\system32\DRIVERS\udfs.sys
21:32:24.0605 0288    udfs - ok
21:32:24.0667 0288    ufad-ws60 - ok
21:32:24.0699 0288    UI0Detect       (060507c4113391394478f6953a79eedc) C:\Windows\system32\UI0Detect.exe
21:32:24.0714 0288    UI0Detect - ok
21:32:24.0746 0288    UimBus          (49b13845f0dbe39b47fc91dc46b2170a) C:\Windows\system32\DRIVERS\uimx64.sys
21:32:24.0761 0288    UimBus - ok
21:32:24.0792 0288    Uim_IM          (dd46bec773c011eaa5e502c43a73a1cc) C:\Windows\system32\Drivers\Uim_IMx64.sys
21:32:24.0824 0288    Uim_IM - ok
21:32:24.0839 0288    uliagpkx        (5663d7696abbe71f8c9d915c5374118a) C:\Windows\system32\drivers\uliagpkx.sys
21:32:24.0839 0288    uliagpkx - ok
21:32:24.0871 0288    uliahci         (6030b68e86a30d1b315b51c4d7778b16) C:\Windows\system32\drivers\uliahci.sys
21:32:24.0886 0288    uliahci - ok
21:32:24.0917 0288    UlSata          (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys
21:32:24.0933 0288    UlSata - ok
21:32:24.0980 0288    ulsata2         (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys
21:32:24.0996 0288    ulsata2 - ok
21:32:25.0027 0288    umbus           (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys
21:32:25.0042 0288    umbus - ok
21:32:25.0089 0288    upnphost        (7093799ff80e9deca0680d2e3535be60) C:\Windows\System32\upnphost.dll
21:32:25.0105 0288    upnphost - ok
21:32:25.0136 0288    usbccgp         (66627c6008319def7909f21fb75a8991) C:\Windows\system32\DRIVERS\usbccgp.sys
21:32:25.0136 0288    usbccgp - ok
21:32:25.0183 0288    usbcir          (9247f7e0b65852c1f6631480984d6ed2) C:\Windows\system32\drivers\usbcir.sys
21:32:25.0183 0288    usbcir - ok
21:32:25.0214 0288    usbehci         (827e44de934a736ea31e91d353eb126f) C:\Windows\system32\DRIVERS\usbehci.sys
21:32:25.0214 0288    usbehci - ok
21:32:25.0277 0288    usbhub          (bb35cd80a2ececfadc73569b3d70c7d1) C:\Windows\system32\DRIVERS\usbhub.sys
21:32:25.0292 0288    usbhub - ok
21:32:25.0339 0288    usbohci         (e406b003a354776d317762694956b0fc) C:\Windows\system32\DRIVERS\usbohci.sys
21:32:25.0339 0288    usbohci - ok
21:32:25.0371 0288    usbprint        (28b693b6d31e7b9332c1bdcefef228c1) C:\Windows\system32\DRIVERS\usbprint.sys
21:32:25.0371 0288    usbprint - ok
21:32:25.0386 0288    USBSTOR         (b854c1558fca0c269a38663e8b59b581) C:\Windows\system32\DRIVERS\USBSTOR.SYS
21:32:25.0386 0288    USBSTOR - ok
21:32:25.0402 0288    usbuhci         (7bf55d2538740b25936e93553e5d190d) C:\Windows\system32\DRIVERS\usbuhci.sys
21:32:25.0402 0288    usbuhci - ok
21:32:25.0449 0288    UxSms           (d76e231e4850bb3f88a3d9a78df191e3) C:\Windows\System32\uxsms.dll
21:32:25.0449 0288    UxSms - ok
21:32:25.0527 0288    vds             (294945381dfa7ce58cecf0a9896af327) C:\Windows\System32\vds.exe
21:32:25.0527 0288    vds - ok
21:32:25.0542 0288    vga             (2998dc48905e9b4821ad8fd75b3e070c) C:\Windows\system32\DRIVERS\vgapnp.sys
21:32:25.0558 0288    vga - ok
21:32:25.0589 0288    VgaSave         (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys
21:32:25.0589 0288    VgaSave - ok
21:32:25.0605 0288    viaide          (8294b6c3fdb6c33f24e150de647ecdaa) C:\Windows\system32\drivers\viaide.sys
21:32:25.0605 0288    viaide - ok
21:32:25.0667 0288    vididr          (acbcbd8421920d20f1f40b6f76a4c213) C:\Windows\system32\DRIVERS\vididr.sys
21:32:25.0683 0288    vididr - ok
21:32:25.0730 0288    vidsflt67       (905dd422d28a32face8ae695b3823843) C:\Windows\system32\DRIVERS\vsflt67.sys
21:32:25.0746 0288    vidsflt67 - ok
21:32:25.0792 0288    vmm             (b2e25db5a6a178c056342abd747b7326) C:\Windows\system32\Drivers\vmm.sys
21:32:25.0792 0288    vmm - ok
21:32:25.0792 0288    VMnetAdapter - ok
21:32:25.0855 0288    volmgr          (2b7e885ed951519a12c450d24535dfca) C:\Windows\system32\drivers\volmgr.sys
21:32:25.0855 0288    volmgr - ok
21:32:25.0933 0288    volmgrx         (cec5ac15277d75d9e5dec2e1c6eaf877) C:\Windows\system32\drivers\volmgrx.sys
21:32:25.0933 0288    volmgrx - ok
21:32:26.0011 0288    volsnap         (5280aada24ab36b01a84a6424c475c8d) C:\Windows\system32\drivers\volsnap.sys
21:32:26.0011 0288    volsnap - ok
21:32:26.0042 0288    VPCNetS2        (6bdca00fc57cc40da3c8e88b2cea21ab) C:\Windows\system32\DRIVERS\VMNetSrv.sys
21:32:26.0042 0288    VPCNetS2 - ok
21:32:26.0074 0288    vsmraid         (410ae2c141142c58bc617fc2c677f8b0) C:\Windows\system32\drivers\vsmraid.sys
21:32:26.0074 0288    vsmraid - ok
21:32:26.0199 0288    VSS             (b75232dad33bfd95bf6f0a3e6bff51e1) C:\Windows\system32\vssvc.exe
21:32:26.0246 0288    VSS - ok
21:32:26.0308 0288    vstor2-ws60 - ok
21:32:26.0355 0288    W32Time         (f14a7de2ea41883e250892e1e5230a9a) C:\Windows\system32\w32time.dll
21:32:26.0371 0288    W32Time - ok
21:32:26.0417 0288    WacomPen        (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys
21:32:26.0433 0288    WacomPen - ok
21:32:26.0464 0288    Wanarp          (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
21:32:26.0480 0288    Wanarp - ok
21:32:26.0480 0288    Wanarpv6        (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
21:32:26.0480 0288    Wanarpv6 - ok
21:32:26.0511 0288    wcncsvc         (b4e4c37d0aa6100090a53213ee2bf1c1) C:\Windows\System32\wcncsvc.dll
21:32:26.0527 0288    wcncsvc - ok
21:32:26.0558 0288    WcsPlugInService (ea4b369560e986f19d93f45a881484ac) C:\Windows\System32\WcsPlugInService.dll
21:32:26.0558 0288    WcsPlugInService - ok
21:32:26.0574 0288    Wd              (59b501b0a04c9672142b7ffa2bdbf663) C:\Windows\system32\drivers\wd.sys
21:32:26.0574 0288    Wd - ok
21:32:26.0667 0288    Wdf01000        (d02e7e4567da1e7582fbf6a91144b0df) C:\Windows\system32\drivers\Wdf01000.sys
21:32:26.0683 0288    Wdf01000 - ok
21:32:26.0730 0288    WdiServiceHost  (c5efda73ebfca8b02a094898de0a9276) C:\Windows\system32\wdi.dll
21:32:26.0746 0288    WdiServiceHost - ok
21:32:26.0746 0288    WdiSystemHost   (c5efda73ebfca8b02a094898de0a9276) C:\Windows\system32\wdi.dll
21:32:26.0746 0288    WdiSystemHost - ok
21:32:26.0792 0288    WebClient       (3e6d05381cf35f75ebb055544a8ed9ac) C:\Windows\System32\webclnt.dll
21:32:26.0808 0288    WebClient - ok
21:32:26.0871 0288    Wecsvc          (8d40bc587993f876658bf9fb0f7d3462) C:\Windows\system32\wecsvc.dll
21:32:26.0871 0288    Wecsvc - ok
21:32:26.0902 0288    wercplsupport   (9c980351d7e96288ea0c23ae232bd065) C:\Windows\System32\wercplsupport.dll
21:32:26.0902 0288    wercplsupport - ok
21:32:26.0949 0288    WerSvc          (66b9ecebc46683f47edc06333c075fef) C:\Windows\System32\WerSvc.dll
21:32:26.0949 0288    WerSvc - ok
21:32:26.0980 0288    wimmount        (17291a612431d3e8b731a932dd88e8db) C:\Windows\system32\DRIVERS\wimmount.sys
21:32:26.0980 0288    wimmount - ok
21:32:27.0074 0288    WinDefend - ok
21:32:27.0074 0288    WinHttpAutoProxySvc - ok
21:32:27.0167 0288    Winmgmt         (d2e7296ed1bd26d8db2799770c077a02) C:\Windows\system32\wbem\WMIsvc.dll
21:32:27.0167 0288    Winmgmt - ok
21:32:27.0308 0288    WinRM           (6cbb0c68f13b9c2ec1b16f5fa5e7c869) C:\Windows\system32\WsmSvc.dll
21:32:27.0386 0288    WinRM - ok
21:32:27.0542 0288    Wlansvc         (ec339c8115e91baed835957e9a677f16) C:\Windows\System32\wlansvc.dll
21:32:27.0558 0288    Wlansvc - ok
21:32:27.0730 0288    wlidsvc         (2bacd71123f42cea603f4e205e1ae337) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
21:32:27.0761 0288    wlidsvc - ok
21:32:27.0871 0288    WmiAcpi         (ae34218455d5dc12d1e45de85f160346) C:\Windows\system32\drivers\wmiacpi.sys
21:32:27.0871 0288    WmiAcpi - ok
21:32:27.0964 0288    wmiApSrv        (21fa389e65a852698b6a1341f36ee02d) C:\Windows\system32\wbem\WmiApSrv.exe
21:32:27.0964 0288    wmiApSrv - ok
21:32:28.0027 0288    WPCSvc          (cbc156c913f099e6680d1df9307db7a8) C:\Windows\System32\wpcsvc.dll
21:32:28.0042 0288    WPCSvc - ok
21:32:28.0074 0288    WPDBusEnum      (490a18b4e4d53dc10879deaa8e8b70d9) C:\Windows\system32\wpdbusenum.dll
21:32:28.0074 0288    WPDBusEnum - ok
21:32:28.0105 0288    WpdUsb          (5e2401b3fc1089c90e081291357371a9) C:\Windows\system32\DRIVERS\wpdusb.sys
21:32:28.0105 0288    WpdUsb - ok
21:32:28.0339 0288    WPFFontCache_v0400 (991e2c2cf3bc204c2bb2ee1476149e4e) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
21:32:28.0355 0288    WPFFontCache_v0400 - ok
21:32:28.0402 0288    ws2ifsl         (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys
21:32:28.0402 0288    ws2ifsl - ok
21:32:28.0449 0288    wscsvc          (9ea3e6d0ef7a5c2b9181961052a4b01a) C:\Windows\system32\wscsvc.dll
21:32:28.0464 0288    wscsvc - ok
21:32:28.0464 0288    WSearch - ok
21:32:28.0605 0288    wuauserv        (fb3796754fe00f0bdc87a36f164a5f4d) C:\Windows\system32\wuaueng.dll
21:32:28.0636 0288    wuauserv - ok
21:32:28.0792 0288    WUDFRd          (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys
21:32:28.0792 0288    WUDFRd - ok
21:32:28.0808 0288    wudfsvc         (6cbd51ff913c851d56ed9dc7f2a27dde) C:\Windows\System32\WUDFSvc.dll
21:32:28.0824 0288    wudfsvc - ok
21:32:28.0839 0288    MBR (0x1B8)     (59c2b344794001fc04cf60bd6bcbd2b7) \Device\Harddisk0\DR0
21:32:29.0074 0288    \Device\Harddisk0\DR0 - ok
21:32:29.0074 0288    MBR (0x1B8)     (5c616939100b85e558da92b899a0fc36) \Device\Harddisk1\DR1
21:32:29.0261 0288    \Device\Harddisk1\DR1 - ok
21:32:29.0261 0288    MBR (0x1B8)     (5c616939100b85e558da92b899a0fc36) \Device\Harddisk2\DR2
21:32:29.0292 0288    \Device\Harddisk2\DR2 ( Rootkit.Boot.Pihar.c ) - infected
21:32:29.0292 0288    \Device\Harddisk2\DR2 - detected Rootkit.Boot.Pihar.c (0)
21:32:29.0292 0288    Boot (0x1200)   (b70df37b99e1eaf0cdc45438ac5005c1) \Device\Harddisk0\DR0\Partition0
21:32:29.0292 0288    \Device\Harddisk0\DR0\Partition0 - ok
21:32:29.0292 0288    Boot (0x1200)   (815295f4983feefe938cb860a0157580) \Device\Harddisk1\DR1\Partition0
21:32:29.0292 0288    \Device\Harddisk1\DR1\Partition0 - ok
21:32:29.0339 0288    Boot (0x1200)   (28f79354ee89415f668c5d91cdcb5a39) \Device\Harddisk2\DR2\Partition0
21:32:29.0339 0288    \Device\Harddisk2\DR2\Partition0 - ok
21:32:29.0339 0288    ============================================================
21:32:29.0339 0288    Scan finished
21:32:29.0339 0288    ============================================================
21:32:29.0355 1244    Detected object count: 1
21:32:29.0355 1244    Actual detected object count: 1
21:33:58.0980 1244    \Device\Harddisk2\DR2\# - copied to quarantine
21:33:58.0996 1244    \Device\Harddisk2\DR2 - copied to quarantine
21:33:59.0074 1244    \Device\Harddisk2\DR2\TDLFS\cmd.dll - copied to quarantine
21:33:59.0167 1244    \Device\Harddisk2\DR2\TDLFS\cmd64.dll - copied to quarantine
21:33:59.0230 1244    \Device\Harddisk2\DR2\TDLFS\drv32 - copied to quarantine
21:34:00.0464 1244    \Device\Harddisk2\DR2\TDLFS\drv64 - copied to quarantine
21:34:00.0558 1244    \Device\Harddisk2\DR2\TDLFS\servers.dat - copied to quarantine
21:34:00.0652 1244    \Device\Harddisk2\DR2\TDLFS\config.ini - copied to quarantine
21:34:00.0746 1244    \Device\Harddisk2\DR2\TDLFS\ldr16 - copied to quarantine
21:34:01.0292 1244    \Device\Harddisk2\DR2\TDLFS\ldr32 - copied to quarantine
21:34:01.0449 1244    \Device\Harddisk2\DR2\TDLFS\ldr64 - copied to quarantine
21:34:01.0542 1244    \Device\Harddisk2\DR2\TDLFS\s - copied to quarantine
21:34:01.0636 1244    \Device\Harddisk2\DR2\TDLFS\ldrm - copied to quarantine
21:34:01.0730 1244    \Device\Harddisk2\DR2\TDLFS\u - copied to quarantine
21:34:01.0933 1244    \Device\Harddisk2\DR2 ( Rootkit.Boot.Pihar.c ) - will be cured on reboot
21:34:01.0933 1244    \Device\Harddisk2\DR2 - ok
21:34:03.0464 1244    \Device\Harddisk2\DR2 ( Rootkit.Boot.Pihar.c ) - User select action: Cure 
21:34:12.0152 5072    Deinitialize success
 

My Computer

System One

  • Manufacturer/Model
    MSI/MS7390
    CPU
    AMD Athlon 64 X2 5000
    Motherboard
    MSI K9N SLI-F
    Memory
    Crucial 2048 MBs
    Graphics Card(s)
    ATI Radeon X1550 Series
    Sound Card
    Realtek
    Monitor(s) Displays
    Trinitron
    Screen Resolution
    1600 x 1200 pixels
    Hard Drives
    Western Digital 500 GB
    Western Digital 9 GB
    Maxtor 80 GB External
    Case
    Power Up 5511 Mid Tower ATX Case with 450w Power Supply
    Cooling
    Five Fans
    Keyboard
    Dell QuietKey
    Mouse
    Logitech - Optical
    Internet Speed
    1536 Kb/sec
Good job, EFJ!!!

I won't be online much longer today but am subscribed to your topic so will know when you've had a chance to accomplish the next step --

Please go here to run an on-line scan from ESET.

  • Note: It is easiest if you use Internet explorer for this scan. (If you use an alternate browser, it will be necessary to download the ESET Smart Installer)
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
 

My Computer

Hey Corrine,
This morning while talking to Jesus(my morning prayers), I asked him to get me out of this mess.
I am not a religious fanatic, but whenever I think to ask for his help, he usually responds. :D
Before turning on the power to our computers this morning, he gave me the idea to disconnect from the internet first, which I did.
I checked the windows folder to see if svchost was still there and it was, so I right clicked the file, deleted it to the recycle bin and emptied the bin.
Next, I ran Malwarebytes which detected a couple of "pup" malware.
After removing them and restarting my computer, I checked again to see if svchost was in my windows folder and it was not.
I re-connected to the internet and again looked for the svchost file in windows and it is no longer there.
My Microsoft Security Essentials is once again functioning normal.
It appears to me that the problem malware may be on the Verizon Server and I will notify Verizon.
Only time will tell if this solution is permanent, therefore I will not close this thread for a couple of days.
So, stay tuned to this ongoing saga, "as the computer churns". :)
 

My Computer

System One

  • Manufacturer/Model
    MSI/MS7390
    CPU
    AMD Athlon 64 X2 5000
    Motherboard
    MSI K9N SLI-F
    Memory
    Crucial 2048 MBs
    Graphics Card(s)
    ATI Radeon X1550 Series
    Sound Card
    Realtek
    Monitor(s) Displays
    Trinitron
    Screen Resolution
    1600 x 1200 pixels
    Hard Drives
    Western Digital 500 GB
    Western Digital 9 GB
    Maxtor 80 GB External
    Case
    Power Up 5511 Mid Tower ATX Case with 450w Power Supply
    Cooling
    Five Fans
    Keyboard
    Dell QuietKey
    Mouse
    Logitech - Optical
    Internet Speed
    1536 Kb/sec
Hi, EJF.

I'm happy to hear that your computer seems to be running well now. That is great news. Considering the nature of the infection, however, I would still like to see the requested ESET on-line scan results.
 

My Computer

Hi Corrine,
Attached you will find the ESET log as requested.
The svchost file in the windows folder has not returned yet.
Let me know what you recommend after reviewing this log.

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=37f7ba17940e4c4ca0df4a9c4918f51a
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2012-06-19 07:14:06
# local_time=2012-06-19 03:14:06 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=5892 16776574 100 56 0 176717588 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=662731
# found=24
# cleaned=0
# scan_time=14363
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
C:\Documents and Settings\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
C:\ProgramData\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
C:\TDSSKiller_Quarantine\17.06.2012_21.31.58\mbr0000\tdlfs0000\tsk0001.dta Win64/Olmarik.AK trojan (unable to clean) 00000000000000000000000000000000 I
C:\TDSSKiller_Quarantine\17.06.2012_21.31.58\mbr0000\tdlfs0000\tsk0003.dta Win64/Olmarik.AK trojan (unable to clean) 00000000000000000000000000000000 I
C:\Users\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
C:\Users\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
C:\Windows.old\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
C:\Windows.old\Documents and Settings\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
C:\Windows.old\ProgramData\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
C:\Windows.old\Users\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
C:\Windows.old\Users\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
D:\ED-PC\Backup Set 2011-12-15 085751\Backup Files 2012-06-18 100914\Backup files 1.zip Win64/Olmarik.AK trojan (unable to clean) 00000000000000000000000000000000 I
F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
F:\Documents and Settings\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
F:\ProgramData\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
F:\Users\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
F:\Users\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
F:\Users\Public\Downloads\cnet_RegCleaner630_exe.exe a variant of Win32/InstallCore.D application (unable to clean) 00000000000000000000000000000000 I
F:\Windows.old\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
F:\Windows.old\Documents and Settings\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
F:\Windows.old\ProgramData\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
F:\Windows.old\Users\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
F:\Windows.old\Users\All Users\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I
 

My Computer

System One

  • Manufacturer/Model
    MSI/MS7390
    CPU
    AMD Athlon 64 X2 5000
    Motherboard
    MSI K9N SLI-F
    Memory
    Crucial 2048 MBs
    Graphics Card(s)
    ATI Radeon X1550 Series
    Sound Card
    Realtek
    Monitor(s) Displays
    Trinitron
    Screen Resolution
    1600 x 1200 pixels
    Hard Drives
    Western Digital 500 GB
    Western Digital 9 GB
    Maxtor 80 GB External
    Case
    Power Up 5511 Mid Tower ATX Case with 450w Power Supply
    Cooling
    Five Fans
    Keyboard
    Dell QuietKey
    Mouse
    Logitech - Optical
    Internet Speed
    1536 Kb/sec
Back
Top