TechSpot

[A] Svchost.exe malware help blue screening

By aznsaik0
Jun 7, 2012
  1. Hello, I am having lots of trouble getting ridding of this rootkit/malware. I'm not sure what exactly it is either. Malwarebytes picks up the virus but it wont get rid of it after a restart. I've tried using ComboFix and rkill, but I'm not sure if I did it right. Someone please help!'
    [​IMG]
     
  2. Broni

    Broni Malware Annihilator Posts: 52,892   +344

    Welcome aboard [​IMG]

    Please, complete all steps listed here: http://www.techspot.com/vb/topic58138.html
    Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
    Attached logs won't be reviewed.

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ===================================================

    Never run Combofix on your own.
     
  3. aznsaik0

    aznsaik0 TS Rookie Topic Starter

    2012/06/07 00:02:22 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 50607, Process: svchost.exe)
    2012/06/07 00:02:22 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 50610, Process: svchost.exe)
    2012/06/07 00:19:39 -0700JUSTIN-PCJustinMESSAGEStarting protection
    2012/06/07 00:19:40 -0700JUSTIN-PCJustinMESSAGEProtection started successfully
    2012/06/07 00:19:43 -0700JUSTIN-PCJustinMESSAGEStarting IP protection
    2012/06/07 00:19:45 -0700JUSTIN-PCJustinMESSAGEIP Protection started successfully
    2012/06/07 00:20:32 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 49682, Process: svchost.exe)
    2012/06/07 00:20:40 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 49751, Process: svchost.exe)
    2012/06/07 00:26:10 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 50927, Process: svchost.exe)
    2012/06/07 00:26:26 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 50991, Process: svchost.exe)
    2012/06/07 00:26:34 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51009, Process: svchost.exe)
    2012/06/07 00:27:22 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51167, Process: svchost.exe)
    2012/06/07 00:27:30 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51179, Process: svchost.exe)
    2012/06/07 00:27:46 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 51205, Process: svchost.exe)
    2012/06/07 00:27:54 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 51380, Process: svchost.exe)
    2012/06/07 00:28:10 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51426, Process: svchost.exe)
    2012/06/07 00:29:14 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51640, Process: svchost.exe)
    2012/06/07 00:29:14 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51647, Process: svchost.exe)
    2012/06/07 00:29:14 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51648, Process: svchost.exe)
    2012/06/07 00:30:10 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51777, Process: svchost.exe)
    2012/06/07 00:31:14 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52027, Process: svchost.exe)
    2012/06/07 00:31:39 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52109, Process: svchost.exe)
    2012/06/07 00:32:27 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52247, Process: svchost.exe)
    2012/06/07 00:33:07 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52377, Process: svchost.exe)
    2012/06/07 00:33:07 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52416, Process: svchost.exe)
    2012/06/07 00:33:15 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52469, Process: svchost.exe)
    2012/06/07 00:33:23 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52472, Process: svchost.exe)
    2012/06/07 00:34:27 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52769, Process: svchost.exe)
    2012/06/07 00:35:31 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52785, Process: svchost.exe)
    2012/06/07 00:36:27 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52873, Process: svchost.exe)
    2012/06/07 00:37:07 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 53020, Process: svchost.exe)
    2012/06/07 00:38:27 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 53294, Process: svchost.exe)
    2012/06/07 00:41:16 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 53848, Process: svchost.exe)
    2012/06/07 00:41:16 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 53851, Process: svchost.exe)
    2012/06/07 00:41:24 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 53854, Process: svchost.exe)
    2012/06/07 00:41:32 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 53881, Process: svchost.exe)
    2012/06/07 00:43:16 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 54367, Process: svchost.exe)
    2012/06/07 00:44:20 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 54612, Process: svchost.exe)
    2012/06/07 00:44:20 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 54615, Process: svchost.exe)
    2012/06/07 00:46:12 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 55128, Process: svchost.exe)
    2012/06/07 00:46:28 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 55156, Process: svchost.exe)
    2012/06/07 00:47:08 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 55371, Process: svchost.exe)
    2012/06/07 00:47:08 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 55375, Process: svchost.exe)
    2012/06/07 00:47:48 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 55508, Process: svchost.exe)
    2012/06/07 00:49:17 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 55866, Process: svchost.exe)
    2012/06/07 00:49:17 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 55869, Process: svchost.exe)
    2012/06/07 00:50:13 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56072, Process: svchost.exe)
    2012/06/07 00:50:21 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56075, Process: svchost.exe)
    2012/06/07 00:50:37 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56078, Process: svchost.exe)
    2012/06/07 00:51:09 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56227, Process: svchost.exe)
    2012/06/07 00:51:25 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56383, Process: svchost.exe)
    2012/06/07 00:51:57 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56414, Process: svchost.exe)
    2012/06/07 00:52:29 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56633, Process: svchost.exe)
    2012/06/07 00:52:37 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56666, Process: svchost.exe)
    2012/06/07 00:52:53 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56697, Process: svchost.exe)
    2012/06/07 00:53:25 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56867, Process: svchost.exe)
    2012/06/07 00:53:33 -0700JUSTIN-PCJustinIP-BLOCK89.108.64.196 (Type: outgoing, Port: 56914, Process: svchost.exe)
    2012/06/07 00:54:05 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 57034, Process: svchost.exe)
    2012/06/07 00:54:21 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 57113, Process: svchost.exe)
    2012/06/07 00:55:41 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 57452, Process: svchost.exe)
    2012/06/07 00:56:13 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 57609, Process: svchost.exe)
    2012/06/07 00:56:21 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 57642, Process: svchost.exe)
    2012/06/07 00:56:29 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 57666, Process: svchost.exe)
    2012/06/07 00:56:29 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 57673, Process: svchost.exe)
    2012/06/07 00:57:42 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 57911, Process: svchost.exe)
    2012/06/07 00:58:06 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 57916, Process: svchost.exe)
    2012/06/07 00:58:06 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 57939, Process: svchost.exe)
    2012/06/07 01:00:38 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 58211, Process: svchost.exe)
    2012/06/07 01:00:38 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 58215, Process: svchost.exe)
    2012/06/07 01:01:10 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 58250, Process: svchost.exe)
    2012/06/07 01:03:34 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 58970, Process: svchost.exe)
    2012/06/07 01:03:42 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 58990, Process: svchost.exe)
    2012/06/07 01:04:14 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59040, Process: svchost.exe)
    2012/06/07 01:04:30 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59074, Process: svchost.exe)
    2012/06/07 01:04:30 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59077, Process: svchost.exe)
    2012/06/07 01:06:14 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59308, Process: svchost.exe)
    2012/06/07 01:07:42 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59649, Process: svchost.exe)
    2012/06/07 01:07:42 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59662, Process: svchost.exe)
    2012/06/07 01:07:51 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59676, Process: svchost.exe)
    2012/06/07 01:07:51 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59687, Process: svchost.exe)
    2012/06/07 01:08:15 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59761, Process: svchost.exe)
    2012/06/07 01:08:31 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59788, Process: svchost.exe)
    2012/06/07 01:08:47 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59878, Process: svchost.exe)
    2012/06/07 01:08:47 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59914, Process: svchost.exe)
    2012/06/07 01:10:07 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 60214, Process: svchost.exe)
    2012/06/07 01:10:39 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 60344, Process: svchost.exe)
    2012/06/07 01:11:19 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 60438, Process: svchost.exe)
    2012/06/07 01:11:27 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 60484, Process: svchost.exe)
    2012/06/07 01:11:27 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 60485, Process: svchost.exe)
    2012/06/07 01:12:07 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 60727, Process: svchost.exe)
    2012/06/07 01:15:27 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 61280, Process: svchost.exe)
    2012/06/07 01:15:35 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 61295, Process: svchost.exe)
    2012/06/07 01:16:23 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 61478, Process: svchost.exe)
    2012/06/07 01:16:23 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 61482, Process: svchost.exe)
    2012/06/07 01:16:23 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 61485, Process: svchost.exe)
    2012/06/07 01:18:15 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 61802, Process: svchost.exe)
    2012/06/07 01:18:31 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 61821, Process: svchost.exe)
    2012/06/07 01:18:39 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 61831, Process: svchost.exe)
    2012/06/07 01:18:39 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 61834, Process: svchost.exe)
    2012/06/07 01:19:27 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 61928, Process: svchost.exe)
    2012/06/07 01:19:35 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 61931, Process: svchost.exe)
    2012/06/07 01:20:08 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 61987, Process: svchost.exe)
    2012/06/07 01:20:24 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 62000, Process: svchost.exe)
    2012/06/07 01:20:32 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 62056, Process: svchost.exe)
    2012/06/07 01:21:04 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 62142, Process: svchost.exe)
    2012/06/07 01:21:36 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 62305, Process: svchost.exe)
    2012/06/07 01:22:16 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 62419, Process: svchost.exe)
    2012/06/07 01:22:32 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 62510, Process: svchost.exe)
    2012/06/07 01:22:40 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 62514, Process: svchost.exe)
    2012/06/07 01:22:40 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 62522, Process: svchost.exe)
    2012/06/07 01:22:48 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 62563, Process: svchost.exe)
    2012/06/07 01:23:28 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 62737, Process: svchost.exe)
    2012/06/07 01:24:24 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 62965, Process: svchost.exe)
    2012/06/07 01:24:24 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 63001, Process: svchost.exe)
    2012/06/07 01:24:40 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 63018, Process: svchost.exe)
    2012/06/07 01:24:40 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 63024, Process: svchost.exe)
    2012/06/07 01:25:44 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 63334, Process: svchost.exe)
    2012/06/07 01:26:08 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 63446, Process: svchost.exe)
    2012/06/07 01:26:32 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 63513, Process: svchost.exe)
    2012/06/07 01:26:39 -0700JUSTIN-PCJustinMESSAGEExecuting scheduled update: Daily
    2012/06/07 01:26:44 -0700JUSTIN-PCJustinMESSAGEScheduled update executed successfully: database updated from version v2012.06.06.05 to version v2012.06.07.02
    2012/06/07 01:26:44 -0700JUSTIN-PCJustinMESSAGEStarting database refresh
    2012/06/07 01:26:44 -0700JUSTIN-PCJustinMESSAGEStopping IP protection
    2012/06/07 01:28:18 -0700JUSTIN-PCJustinMESSAGEIP Protection stopped
    2012/06/07 01:28:20 -0700JUSTIN-PCJustinMESSAGEDatabase refreshed successfully
    2012/06/07 01:28:20 -0700JUSTIN-PCJustinMESSAGEStarting IP protection
    2012/06/07 01:28:21 -0700JUSTIN-PCJustinMESSAGEIP Protection started successfully
    2012/06/07 01:29:16 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 64359, Process: svchost.exe)
    2012/06/07 01:29:24 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 64438, Process: svchost.exe)
    2012/06/07 01:33:08 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 65332, Process: svchost.exe)
    2012/06/07 01:33:40 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 65336, Process: svchost.exe)
    2012/06/07 01:33:40 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 65339, Process: svchost.exe)
    2012/06/07 01:34:20 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 65355, Process: svchost.exe)
    2012/06/07 01:34:20 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 65358, Process: svchost.exe)
    2012/06/07 01:35:08 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 65383, Process: svchost.exe)
    2012/06/07 15:23:25 -0700JUSTIN-PCJustinMESSAGEStarting protection
    2012/06/07 15:23:27 -0700JUSTIN-PCJustinMESSAGEProtection started successfully
    2012/06/07 15:23:30 -0700JUSTIN-PCJustinMESSAGEStarting IP protection
    2012/06/07 15:23:31 -0700JUSTIN-PCJustinMESSAGEIP Protection started successfully
    2012/06/07 15:27:15 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 50356, Process: svchost.exe)
    2012/06/07 15:27:23 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 50371, Process: svchost.exe)
    2012/06/07 15:36:20 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51104, Process: svchost.exe)
    2012/06/07 15:38:04 -0700JUSTIN-PCJustinIP-BLOCK173.236.56.93 (Type: outgoing, Port: 51186, Process: svchost.exe)
    2012/06/07 15:38:04 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51190, Process: svchost.exe)
    2012/06/07 15:38:21 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51202, Process: svchost.exe)
    2012/06/07 15:38:37 -0700JUSTIN-PCJustinIP-BLOCK173.236.56.93 (Type: outgoing, Port: 51215, Process: svchost.exe)
    2012/06/07 15:39:17 -0700JUSTIN-PCJustinIP-BLOCK173.236.56.93 (Type: outgoing, Port: 51436, Process: svchost.exe)

    _______________________________________________________________________________________________________

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft Windows 7 Ultimate
    Boot Device: \Device\HarddiskVolume1
    Install Date: 7/14/2011 4:16:56 PM
    System Uptime: 6/7/2012 3:20:58 PM (0 hours ago)
    .
    Motherboard: Gigabyte Technology Co., Ltd. | | GA-880GA-UD3H
    Processor: AMD Phenom(tm) II X6 1100T Processor | Socket M2 | 3314/200mhz
    .
    ==== Disk Partitions =========================
    .
    A: is Removable
    C: is FIXED (NTFS) - 931 GiB total, 756.89 GiB free.
    D: is CDROM ()
    E: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID:
    Description: Universal Serial Bus (USB) Controller
    Device ID: PCI\VEN_1033&DEV_0194&SUBSYS_50071458&REV_04\4&5B6B27D&0&0048
    Manufacturer:
    Name: Universal Serial Bus (USB) Controller
    PNP Device ID: PCI\VEN_1033&DEV_0194&SUBSYS_50071458&REV_04\4&5B6B27D&0&0048
    Service:
    .
    ==== System Restore Points ===================
    .
    RP167: 5/28/2012 12:56:37 AM - Scheduled Checkpoint
    RP168: 6/5/2012 11:49:10 PM - avast! Free Antivirus Setup
    RP169: 6/6/2012 4:35:28 PM - avast! Free Antivirus Setup
    RP170: 6/6/2012 5:14:59 PM - avast! Free Antivirus Setup
    RP171: 6/6/2012 5:18:29 PM - Removed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    RP172: 6/6/2012 5:19:15 PM - Removed Skype Click to Call
    RP173: 6/6/2012 5:20:11 PM - Removed Skype Click to Call
    .
    ==== Installed Programs ======================
    .
    Update for Microsoft Office 2007 (KB2508958)
    µTorrent
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Reader X (10.1.3)
    AIM 7
    AOL Messaging Toolbar
    Apple Application Support
    Apple Software Update
    Battlefield 3™
    Battlefield: Bad Company 2
    Battlelog Web Plugins
    Call of Duty(R) - World at War(TM)
    Counter-Strike
    Counter-Strike: Global Offensive Beta
    Counter-Strike: Source
    DAEMON Tools Lite
    Day of Defeat: Source
    DivX Setup
    Dota 2
    Download Updater (AOL LLC)
    EasySaver B9.1214.1
    ESN Sonar
    EVGA Precision 2.1.2
    EVGA Precision X 3.0.2
    F.lux
    FBDownloader IE Add-on
    FrostWire 5.2.9
    Garry's Mod
    Google Chrome
    Java Auto Updater
    Java(TM) 6 Update 29
    Killing Floor
    League of Legends
    Left 4 Dead 2
    Malwarebytes Anti-Malware version 1.61.0.1400
    MapleStory
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Access MUI (English) 2007
    Microsoft Office Access Setup Metadata MUI (English) 2007
    Microsoft Office Enterprise 2007
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Groove MUI (English) 2007
    Microsoft Office Groove Setup Metadata MUI (English) 2007
    Microsoft Office InfoPath MUI (English) 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office Outlook MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Publisher MUI (English) 2007
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Silverlight
    Microsoft VC9 runtime libraries
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    Music Rescue
    Need For Speed™ World
    NVIDIA 3D Vision Controller Driver
    NVIDIA PhysX
    NVIDIA Stereoscopic 3D Driver
    ooVoo
    Origin
    Pando Media Booster
    PunkBuster Services
    QuickTime
    Realtek Ethernet Controller Driver
    Sanctum
    Security Update for 2007 Microsoft Office System (KB2288621)
    Security Update for 2007 Microsoft Office System (KB2288931)
    Security Update for 2007 Microsoft Office System (KB2345043)
    Security Update for 2007 Microsoft Office System (KB2553074)
    Security Update for 2007 Microsoft Office System (KB2553089)
    Security Update for 2007 Microsoft Office System (KB2553090)
    Security Update for 2007 Microsoft Office System (KB2584063)
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB976321)
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft Office Access 2007 (KB979440)
    Security Update for Microsoft Office Excel 2007 (KB2553073)
    Security Update for Microsoft Office Groove 2007 (KB2552997)
    Security Update for Microsoft Office InfoPath 2007 (KB2510061)
    Security Update for Microsoft Office InfoPath 2007 (KB979441)
    Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
    Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
    Security Update for Microsoft Office Publisher 2007 (KB2284697)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Security Update for Microsoft Office Word 2007 (KB2344993)
    Skype™ 5.8
    Spybot - Search & Destroy
    StarCraft II
    Steam
    System Requirements Lab CYRI
    Update for 2007 Microsoft Office System (KB2284654)
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office 2007 System (KB2539530)
    Update for Microsoft Office Access 2007 Help (KB963663)
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office Infopath 2007 Help (KB963662)
    Update for Microsoft Office OneNote 2007 (KB980729)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Outlook 2007 (KB2583910)
    Update for Microsoft Office Outlook 2007 Help (KB963677)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Publisher 2007 Help (KB963667)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 Help (KB963665)
    Update for Outlook 2007 Junk Email Filter (KB2596560)
    VC80CRTRedist - 8.0.50727.6195
    VirtualDJ PRO Full
    Windows Movie Maker 2.6
    WinRAR 4.01 (32-bit)
    Zombie Panic Source
    .
    ==== Event Viewer Messages From Past Week ========
    .
    6/7/2012 3:21:22 PM, Error: Service Control Manager [7023] - The Windows Defender service terminated with the following error: The specified module could not be found.
    6/7/2012 12:16:35 AM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
    6/7/2012 12:16:15 AM, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
    6/7/2012 12:09:12 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service VSS with arguments "" in order to run the server: {E579AB5F-1CC4-44B4-BED9-DE0991FF0623}
    6/7/2012 12:05:11 AM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
    6/7/2012 12:05:05 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
    6/7/2012 12:05:05 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
    6/7/2012 12:05:05 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
    6/7/2012 12:05:05 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
    6/7/2012 12:05:04 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    6/7/2012 12:04:56 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
    6/7/2012 12:04:46 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD CSC DfsC discache NetBIOS NetBT nsiproxy Psched rdbss spldr tdx Wanarpv6 WfpLwf ws2ifsl
    6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
    6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
    6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
    6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
    6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
    6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The Network Connections service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
    6/6/2012 5:47:30 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000007e (0xffffffffc0000005, 0xfffff8800cb00fe4, 0xfffff8800ba905c8, 0xfffff8800ba8fe30). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-32120-01.
    6/6/2012 5:47:29 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD CSC DfsC discache NetBIOS NetBT nsiproxy Psched rdbss spldr tdx Wanarpv6 WfpLwf
    6/6/2012 5:30:28 PM, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
    6/6/2012 5:30:28 PM, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
    6/6/2012 5:27:51 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x00000000000000dc, 0x0000000000000002, 0x0000000000000001, 0xfffff80002eabf95). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-24835-01.
    6/6/2012 5:24:30 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff800031673fa, 0x0000000000000001, 0x0000000000000018). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-25537-01.
    6/6/2012 5:12:46 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x0000000000075503, 0x0000000000000002, 0x0000000000000001, 0xfffff80002e69f95). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-24663-01.
    6/6/2012 5:10:15 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff800031813fa, 0x0000000000000001, 0x0000000000000018). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-26176-01.
    6/6/2012 4:25:23 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff80002e65703, 0x0000000000000000, 0x000000007efa0000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-20170-01.
    6/6/2012 3:55:12 PM, Error: Service Control Manager [7023] - The Peer Name Resolution Protocol service terminated with the following error: %%-2140993535
    6/6/2012 3:55:12 PM, Error: Service Control Manager [7001] - The Peer Networking Grouping service depends on the Peer Name Resolution Protocol service which failed to start because of the following error: %%-2140993535
    6/6/2012 3:55:12 PM, Error: Microsoft-Windows-PNRPSvc [102] - The Peer Name Resolution Protocol cloud did not start because the creation of the default identity failed with error code: 0x80630801.
    6/6/2012 12:43:49 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff80002eac703, 0x0000000000000000, 0x000000007efa0000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-30934-01.
    6/6/2012 12:40:42 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000019 (0x0000000000000003, 0xfffff8000300fbb0, 0xfffff8000300fbb0, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-30763-01.
    6/6/2012 11:41:40 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff80002eaa703, 0x0000000000000000, 0x000000007efa0000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-19094-01.
    6/6/2012 11:27:42 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000116 (0xfffffa80095914e0, 0xfffff8801496f1a4, 0xffffffffc000009a, 0x0000000000000004). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-17628-01.
    6/5/2012 12:14:00 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR2.
    6/5/2012 11:38:51 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff80002ea6703, 0x0000000000000000, 0x000000007efa0000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060512-24554-01.
    6/4/2012 7:42:25 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1.
    .
    ==== End Of File ===========================
    .
    DDS (Ver_2011-08-26.01) - NTFSAMD64
    Internet Explorer: 9.0.8112.16421
    Run by Justin at 15:50:08 on 2012-06-07
    Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.8190.5572 [GMT -7:00]
    .
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE
    C:\Windows\SysWOW64\PnkBstrA.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files (x86)\AIM\aim.exe
    C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
    C:\Program Files (x86)\Steam\Steam.exe
    C:\Users\Justin\Local Settings\Apps\F.lux\flux.exe
    C:\Program Files (x86)\Skype\Phone\Skype.exe
    C:\Program Files (x86)\oovoo\ooVoo.exe
    C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
    C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome.exe
    -netsvcs
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\rundll32.exe
    C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Windows\system32\wuauclt.exe
    C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.ask.com/?l=dis&o=APN10379&gct=hp
    uInternet Settings,ProxyOverride = *.local
    uURLSearchHooks: AOL Messaging Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
    uURLSearchHooks: H - No File
    mURLSearchHooks: AOL Messaging Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: FBDownloader BHO: {553318da-d010-469e-84b1-496563cae1bf} - C:\Program Files (x86)\HTTO Group, Ltd\FBDownloader IE Add-on\FBDownloader.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO: AOL Messaging Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    TB: AOL Messaging Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
    uRun: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US
    uRun: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
    uRun: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
    uRun: [F.lux] "C:\Users\Justin\Local Settings\Apps\F.lux\flux.exe" /noshow
    uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
    uRun: [ooVoo.exe] C:\program files (x86)\oovoo\oovoo.exe /minimized
    mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
    mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    StartupFolder: C:\Users\Justin\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
    mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.4.26.0.cab
    TCP: DhcpNameServer = 10.0.0.1
    TCP: Interfaces\{33137353-D12F-4305-9D68-3937A18FD63F} : DhcpNameServer = 10.0.0.1
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO-X64: AcroIEHelperStub - No File
    BHO-X64: FBDownloader BHO: {553318DA-D010-469E-84B1-496563CAE1BF} - C:\Program Files (x86)\HTTO Group, Ltd\FBDownloader IE Add-on\FBDownloader.dll
    BHO-X64: FBDownloader - No File
    BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO-X64: AOL Messaging Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
    BHO-X64: AOL Messaging Toolbar Loader - No File
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    TB-X64: AOL Messaging Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
    mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
    mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
    mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    Hosts: 127.0.0.1www.spywareinfo.com
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
    R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-4-3 63928]
    R2 ES lite Service;ES lite Service for program management.;C:\Program Files (x86)\Gigabyte\EasySaver\essvr.exe [2011-7-14 68136]
    R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-6-6 654408]
    R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-3-18 1262400]
    R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-5-15 382272]
    R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
    R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
    R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-2-29 158856]
    S3 Gun;Gun;C:\Game\SoftnyxGame\GunboundIS\Gun64.sys [2012-5-5 45176]
    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
    .
    =============== File Associations ===============
    .
    inffile=%SystemRoot%\SysWow64\NOTEPAD.EXE %1
    VBEFile=%SystemRoot%\SysWow64\WScript.exe "%1" %*
    VBSFile=%SystemRoot%\SysWow64\WScript.exe "%1" %*
    .
    =============== Created Last 30 ================
    .
    2012-06-07 22:22:1720480----a-w-C:\Windows\svchost.exe
    2012-06-07 07:17:46--------d-----w-C:\$RECYCLE.BIN
    2012-06-07 07:09:08--------d-----w-C:\ComboFix
    2012-06-07 03:49:4898816----a-w-C:\Windows\sed.exe
    2012-06-07 03:49:48518144----a-w-C:\Windows\SWREG.exe
    2012-06-07 03:49:48256000----a-w-C:\Windows\PEV.exe
    2012-06-07 03:49:48208896----a-w-C:\Windows\MBR.exe
    2012-06-07 00:53:03--------d-----w-C:\Users\Justin\AppData\Roaming\Malwarebytes
    2012-06-07 00:52:58--------d-----w-C:\ProgramData\Malwarebytes
    2012-06-07 00:52:5724904----a-w-C:\Windows\System32\drivers\mbam.sys
    2012-06-07 00:52:57--------d-----w-C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2012-06-07 00:44:35--------d-----w-C:\Program Files (x86)\EVGA Precision X
    2012-06-06 07:51:02--------d-----w-C:\ProgramData\Spybot - Search & Destroy
    2012-06-06 07:51:02--------d-----w-C:\Program Files (x86)\Spybot - Search & Destroy
    2012-06-06 06:49:21--------d-----w-C:\ProgramData\AVAST Software
    2012-06-06 06:49:21--------d-----w-C:\Program Files\AVAST Software
    2012-05-23 23:50:41--------d-----w-C:\Users\Justin\AppData\Roaming\LolClient2
    2012-05-15 09:21:50423744----a-w-C:\Windows\SysWow64\nvStreaming.exe
    2012-05-13 21:34:24--------d-----w-C:\Windows\8A809006C25A4A3A9DAB94659BCDB107.TMP
    2012-05-12 06:22:55419488----a-w-C:\Windows\SysWow64\FlashPlayerApp.exe
    .
    ==================== Find3M ====================
    .
    2012-06-07 22:21:2125640----a-w-C:\Windows\gdrv.sys
    2012-06-03 23:23:40283304----a-w-C:\Windows\SysWow64\PnkBstrB.xtr
    2012-06-03 23:23:40283304----a-w-C:\Windows\SysWow64\PnkBstrB.exe
    2012-06-03 23:23:23280904----a-w-C:\Windows\SysWow64\PnkBstrB.ex0
    2012-05-15 09:29:47889664----a-w-C:\Windows\System32\nvvsvc.exe
    2012-05-15 09:29:4663296----a-w-C:\Windows\System32\nvshext.dll
    2012-05-15 09:29:46118080----a-w-C:\Windows\System32\nvmctray.dll
    2012-05-15 09:29:452621723----a-w-C:\Windows\System32\nvcoproc.bin
    2012-05-15 09:29:253149632----a-w-C:\Windows\System32\nvsvc64.dll
    2012-05-15 09:28:426151488----a-w-C:\Windows\System32\nvcpl.dll
    2012-05-12 06:22:5570304----a-w-C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-04-18 17:08:0831040----a-w-C:\Windows\System32\nvhdap64.dll
    2012-04-18 17:08:03188736----a-w-C:\Windows\System32\drivers\nvhda64v.sys
    2012-04-18 17:08:021451840----a-w-C:\Windows\System32\nvhdagenco6420103.dll
    .
    ============= FINISH: 15:50:37.99 ===============
     
  4. aznsaik0

    aznsaik0 TS Rookie Topic Starter

    bump???
     
  5. Broni

    Broni Malware Annihilator Posts: 52,892   +344

    Instead of bumping...

    Please, complete all steps listed here: http://www.techspot.com/vb/topic58138.html
    Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
    Attached logs won't be reviewed.
     
  6. aznsaik0

    aznsaik0 TS Rookie Topic Starter

    Please tell me if I am missing anything

    Malwarebytes Anti-Malware (Trial) 1.61.0.1400
    www.malwarebytes.org

    Database version: v2012.06.15.02

    Windows 7 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Justin :: JUSTIN-PC [administrator]

    Protection: Enabled

    6/15/2012 12:41:05 PM
    mbam-log-2012-06-15 (12-47-39).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 228936
    Time elapsed: 1 minute(s), 54 second(s)

    Memory Processes Detected: 1
    C:\Windows\svchost.exe (Trojan.Agent) -> 4316 -> No action taken.

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 1
    C:\Windows\svchost.exe (Trojan.Agent) -> No action taken.

    (end)
    __
     
  7. Broni

    Broni Malware Annihilator Posts: 52,892   +344

    You posted DDS logs already so I'm deleting them.

    GMER log is missing.
     
  8. Broni

    Broni Malware Annihilator Posts: 52,892   +344

    Your MBAM log says "No action taken".
    Re-run it, fix all issues and post new log.
     
  9. aznsaik0

    aznsaik0 TS Rookie Topic Starter

    GMER didnt produce a log, so im assuming no changes? Wil re-run mbam.
     
  10. aznsaik0

    aznsaik0 TS Rookie Topic Starter

    Malwarebytes Anti-Malware (Trial) 1.61.0.1400
    www.malwarebytes.org

    Database version: v2012.06.17.03

    Windows 7 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Justin :: JUSTIN-PC [administrator]

    Protection: Enabled

    6/17/2012 2:48:16 PM
    mbam-log-2012-06-17 (14-48-16).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 229306
    Time elapsed: 1 minute(s), 39 second(s)

    Memory Processes Detected: 1
    C:\Windows\svchost.exe (Trojan.Agent) -> 4472 -> Delete on reboot.

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 1
    C:\Windows\svchost.exe (Trojan.Agent) -> Delete on reboot.

    (end)
     
  11. Broni

    Broni Malware Annihilator Posts: 52,892   +344

    For x32 (x86) bit systems download Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    To enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:

      • Startup Repair
        System Restore
        Windows Complete PC Restore
        Windows Memory Diagnostic Tool
        Command Prompt
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.
     
  12. Broni

    Broni Malware Annihilator Posts: 52,892   +344

    Reopened.
     
  13. aznsaik0

    aznsaik0 TS Rookie Topic Starter

    Scan result of Farbar Recovery Scan Tool Version: 30-06-2012 04
    Ran by SYSTEM at 30-06-2012 10:18:45
    Running from F:\
    Windows 7 Ultimate (X64) OS Language: English(US)
    The current controlset is ControlSet001

    ========================== Registry (Whitelisted) =============

    HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [31072 2008-10-25] (Microsoft Corporation)
    HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-28] ()
    HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-07-05] (Apple Inc.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
    HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-01] (Apple Inc.)
    HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-01-16] (Apple Inc.)
    HKLM-x32\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462408 2012-04-04] (Malwarebytes Corporation)
    HKU\Justin\...\Run: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US [4321112 2012-02-29] (AOL Inc.)
    HKU\Justin\...\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3077528 2011-07-14] ()
    HKU\Justin\...\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent [1242448 2011-08-03] (Valve Corporation)
    HKU\Justin\...\Run: [F.lux] "C:\Users\Justin\Local Settings\Apps\F.lux\flux.exe" /noshow [966656 2009-08-28] ()
    HKU\Justin\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17148552 2012-02-29] (Skype Technologies S.A.)
    Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
    Startup: C:\Users\Justin\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
    ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

    ==================== Services (Whitelisted) ======

    2 ES lite Service; "C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE" [68136 2009-08-24] ()
    2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [654408 2012-04-04] (Malwarebytes Corporation)
    2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-02-18] ()
    2 WinDefend; C:\Program Files (x86)\Windows Defender\mpsvc.dll [x]

    ========================== Drivers (Whitelisted) =============

    1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [279616 2011-11-29] (DT Soft Ltd)
    3 gdrv; \??\C:\Windows\gdrv.sys [25640 2012-06-30] (Windows (R) Server 2003 DDK provider)
    3 Gun; \??\C:\Game\SoftnyxGame\GunBoundIS\Gun64.sys [45176 2012-05-05] ()
    3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-04-04] (Malwarebytes Corporation)
    3 catchme; \??\C:\ComboFix\catchme.sys [x]

    ========================== NetSvcs (Whitelisted) ===========


    ============ One Month Created Files and Folders ==============

    2012-06-30 09:08 - 2012-06-30 09:08 - 00285816 ____A C:\Windows\Minidump\063012-20748-01.dmp
    2012-06-30 08:55 - 2012-06-30 08:55 - 00292736 ____A C:\Windows\Minidump\063012-19172-01.dmp
    2012-06-29 01:39 - 2012-06-29 01:39 - 00000000 ____D C:\Users\Justin\Desktop\RGSC
    2012-06-29 01:37 - 2012-06-29 01:39 - 222070843 ____A C:\Users\Justin\Desktop\RGSC.rar
    2012-06-29 01:36 - 2012-06-29 01:36 - 00001843 ____A C:\lanoire6-29-2012 2-36-52 AM.log
    2012-06-28 21:38 - 2008-07-12 07:18 - 04992520 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_39.dll
    2012-06-28 21:38 - 2008-07-12 07:18 - 01942552 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_39.dll
    2012-06-28 21:38 - 2008-07-12 07:18 - 00540688 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_39.dll
    2012-06-28 19:01 - 2012-06-28 19:01 - 02796287 ____A C:\Users\Justin\Desktop\RGSC_1_1_3_0.rar
    2012-06-28 18:55 - 2012-06-28 18:55 - 00000000 ____D C:\Users\Justin\Documents\Rockstar Games
    2012-06-24 12:45 - 2012-06-24 12:46 - 00000288 ____A C:\Windows\SysWOW64\msexcr.ini
    2012-06-24 01:10 - 2012-06-24 01:10 - 00292704 ____A C:\Windows\Minidump\062412-23368-01.dmp
    2012-06-24 00:10 - 2012-06-24 00:11 - 00285256 ____A C:\Windows\Minidump\062412-50965-01.dmp
    2012-06-24 00:06 - 2012-06-24 00:06 - 00286760 ____A C:\Windows\Minidump\062412-20124-01.dmp
    2012-06-24 00:00 - 2012-06-24 00:01 - 00292736 ____A C:\Windows\Minidump\062412-19312-01.dmp
    2012-06-22 00:16 - 2012-06-22 00:40 - 13287340 ____A C:\Users\Justin\Desktop\megamix.mp3
    2012-06-22 00:02 - 2012-06-22 00:02 - 00000000 ____D C:\Users\Justin\AppData\Roaming\Azureus
    2012-06-21 10:52 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
    2012-06-21 10:52 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
    2012-06-21 10:52 - 2012-06-02 14:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
    2012-06-21 10:52 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
    2012-06-21 10:52 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
    2012-06-21 10:52 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
    2012-06-21 10:52 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
    2012-06-21 10:52 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
    2012-06-21 10:52 - 2012-06-02 14:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
    2012-06-19 16:12 - 2012-06-19 16:12 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
    2012-06-17 13:52 - 2009-07-13 17:14 - 00020480 ____A (Microsoft Corporation) C:\Windows\svchost.exe
    2012-06-17 13:10 - 2012-06-17 13:10 - 00000000 ____A C:\Users\Justin\Desktop\gmer.log
    2012-06-15 11:31 - 2012-06-15 11:31 - 00291072 ____A C:\Windows\Minidump\061512-19500-01.dmp
    2012-06-14 23:33 - 2012-06-14 23:33 - 00287464 ____A C:\Windows\Minidump\061512-18220-01.dmp
    2012-06-12 12:39 - 2012-06-12 12:39 - 00284752 ____A C:\Windows\Minidump\061212-16270-01.dmp
    2012-06-12 12:34 - 2012-06-12 12:35 - 00284752 ____A C:\Windows\Minidump\061212-18673-01.dmp
    2012-06-12 12:27 - 2012-06-12 12:27 - 00285536 ____A C:\Windows\Minidump\061212-16941-01.dmp
    2012-06-12 12:09 - 2012-06-12 12:09 - 00284592 ____A C:\Windows\Minidump\061212-17097-01.dmp
    2012-06-12 11:03 - 2012-06-12 11:03 - 00284672 ____A C:\Windows\Minidump\061212-16707-01.dmp
    2012-06-11 15:19 - 2012-06-11 15:19 - 00284688 ____A C:\Windows\Minidump\061112-15818-01.dmp
    2012-06-07 14:38 - 2012-06-07 14:38 - 00302592 ____A C:\Users\Justin\Desktop\gktwy3y7.exe
    2012-06-07 00:33 - 2012-06-06 23:17 - 00000027 ____A C:\Windows\System32\Drivers\etc\hosts.20120607-013318.backup
    2012-06-07 00:14 - 2012-06-07 00:14 - 00001258 ____A C:\Users\Justin\Desktop\Spybot - Search & Destroy.lnk
    2012-06-07 00:10 - 2012-06-07 00:10 - 16409960 ____A (Safer Networking Limited ) C:\Users\Justin\Desktop\spybotsd162.exe
    2012-06-06 23:09 - 2012-06-06 23:19 - 00000000 ____D C:\ComboFix
    2012-06-06 23:00 - 2012-06-24 00:04 - 00000498 ____A C:\rkill.log
    2012-06-06 22:59 - 2012-06-06 23:00 - 01012656 ____A C:\Users\Justin\Desktop\rkill.exe
    2012-06-06 22:41 - 2012-06-06 22:41 - 00291488 ____A C:\Windows\Minidump\060612-19094-01.dmp
    2012-06-06 22:27 - 2012-06-06 22:27 - 00792912 ____A C:\Windows\Minidump\060612-17628-01.dmp
    2012-06-06 19:49 - 2012-06-06 23:09 - 00000000 ____D C:\Qoobox
    2012-06-06 19:49 - 2012-06-06 20:01 - 00000000 ____D C:\Windows\ERDNT
    2012-06-06 19:49 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe
    2012-06-06 19:49 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe
    2012-06-06 19:49 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
    2012-06-06 19:49 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
    2012-06-06 19:49 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
    2012-06-06 19:49 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe
    2012-06-06 19:49 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe
    2012-06-06 19:49 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe
    2012-06-06 19:47 - 2012-06-06 22:43 - 04538022 ____R (Swearware) C:\Users\Justin\Desktop\ComboFix.exe
    2012-06-06 16:53 - 2012-06-06 16:53 - 00000000 ____D C:\Users\Justin\AppData\Roaming\Malwarebytes
    2012-06-06 16:52 - 2012-06-06 16:52 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Justin\Desktop\mbam-setup-1.61.0.1400.exe
    2012-06-06 16:52 - 2012-06-06 16:52 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-06-06 16:52 - 2012-06-06 16:52 - 00000000 ____D C:\Users\All Users\Malwarebytes
    2012-06-06 16:52 - 2012-06-06 16:52 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2012-06-06 16:52 - 2012-04-04 14:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-06-06 16:47 - 2012-06-06 16:47 - 00285616 ____A C:\Windows\Minidump\060612-32120-01.dmp
    2012-06-06 16:44 - 2012-06-06 16:44 - 00001088 ____A C:\Users\Justin\Desktop\EVGA Precision X.lnk
    2012-06-06 16:44 - 2012-06-06 16:44 - 00000000 ____D C:\Program Files (x86)\EVGA Precision X
    2012-06-06 16:36 - 2012-05-15 02:48 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
    2012-06-06 16:36 - 2012-05-15 02:48 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
    2012-06-06 16:36 - 2012-05-15 02:48 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
    2012-06-06 16:36 - 2012-05-15 02:48 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
    2012-06-06 16:36 - 2012-05-15 02:48 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
    2012-06-06 16:36 - 2012-05-15 02:48 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
    2012-06-06 16:36 - 2012-05-15 02:48 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
    2012-06-06 16:36 - 2012-05-15 02:48 - 08105280 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
    2012-06-06 16:36 - 2012-05-15 02:48 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
    2012-06-06 16:36 - 2012-05-15 02:48 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
    2012-06-06 16:36 - 2012-05-15 02:48 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
    2012-06-06 16:36 - 2012-05-15 02:48 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
    2012-06-06 16:36 - 2012-05-15 02:48 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
    2012-06-06 16:36 - 2012-05-15 02:48 - 02368832 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
    2012-06-06 16:36 - 2012-05-15 02:48 - 00818496 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
    2012-06-06 16:36 - 2012-05-15 02:48 - 00364352 ____A (NVIDIA Corporation) C:\Windows\System32\nvdecodemft.dll
    2012-06-06 16:36 - 2012-05-15 02:48 - 00301376 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvdecodemft.dll
    2012-06-06 16:36 - 2012-05-15 02:48 - 00246592 ____A (NVIDIA Corporation) C:\Windows\System32\nvinitx.dll
    2012-06-06 16:36 - 2012-05-15 02:48 - 00202048 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
    2012-06-06 16:36 - 2012-04-18 09:08 - 00188736 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvhda64v.sys
    2012-06-06 16:36 - 2012-04-18 09:08 - 00031040 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdap64.dll
    2012-06-06 16:27 - 2012-06-06 16:27 - 00285336 ____A C:\Windows\Minidump\060612-24835-01.dmp
    2012-06-06 16:24 - 2012-06-06 16:24 - 00287520 ____A C:\Windows\Minidump\060612-25537-01.dmp
    2012-06-06 16:12 - 2012-06-06 16:12 - 00284520 ____A C:\Windows\Minidump\060612-24663-01.dmp
    2012-06-06 16:10 - 2012-06-06 16:10 - 00292440 ____A C:\Windows\Minidump\060612-26176-01.dmp
    2012-06-06 15:36 - 2012-06-06 15:36 - 00000000 ____A C:\Windows\SysWOW64\config.nt
    2012-06-06 15:36 - 2012-03-06 15:15 - 00258520 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe
    2012-06-06 15:25 - 2012-06-06 15:25 - 00288728 ____A C:\Windows\Minidump\060612-20170-01.dmp
    2012-06-06 00:00 - 2012-06-07 00:29 - 00000273 ____A C:\Windows\wininit.ini
    2012-06-05 23:51 - 2012-06-07 00:34 - 00000000 ____D C:\Users\All Users\Spybot - Search & Destroy
    2012-06-05 23:51 - 2012-06-07 00:16 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy
    2012-06-05 22:49 - 2012-06-06 16:16 - 00000000 ____D C:\Users\All Users\AVAST Software
    2012-06-05 22:49 - 2012-06-06 15:35 - 00000000 ____D C:\Program Files\AVAST Software
    2012-06-05 22:44 - 2012-06-05 22:48 - 74761776 ____A C:\Users\Justin\Desktop\avast_free_antivirus_setup.exe
    2012-06-05 22:38 - 2012-06-05 22:38 - 00285560 ____A C:\Windows\Minidump\060512-24554-01.dmp


    ============ 3 Months Modified Files ========================
     
  14. Broni

    Broni Malware Annihilator Posts: 52,892   +344

    I still need COMPLETE log.
     
  15. aznsaik0

    aznsaik0 TS Rookie Topic Starter

    Shall I rerun FRST???
     
  16. Broni

    Broni Malware Annihilator Posts: 52,892   +344

    Yes.
     
  17. Broni

    Broni Malware Annihilator Posts: 52,892   +344

    Reopened.
     
  18. aznsaik0

    aznsaik0 TS Rookie Topic Starter

    Scan result of Farbar Recovery Scan Tool Version: 30-06-2012 04
    Ran by SYSTEM at 12-07-2012 21:23:30
    Running from F:\
    Windows 7 Ultimate (X64) OS Language: English(US)
    The current controlset is ControlSet001

    ========================== Registry (Whitelisted) =============

    HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [31072 2008-10-25] (Microsoft Corporation)
    HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-28] ()
    HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-07-05] (Apple Inc.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
    HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-01] (Apple Inc.)
    HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-01-16] (Apple Inc.)
    HKLM-x32\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462408 2012-04-04] (Malwarebytes Corporation)
    HKU\Justin\...\Run: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US [4321112 2012-02-29] (AOL Inc.)
    HKU\Justin\...\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3077528 2011-07-14] ()
    HKU\Justin\...\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent [1242448 2011-08-03] (Valve Corporation)
    HKU\Justin\...\Run: [F.lux] "C:\Users\Justin\Local Settings\Apps\F.lux\flux.exe" /noshow [966656 2009-08-28] ()
    HKU\Justin\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17148552 2012-02-29] (Skype Technologies S.A.)
    HKU\Justin\...\Run: [Google Update] "C:\Users\Justin\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-07-14] (Google Inc.)
    Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
    Startup: C:\Users\Justin\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
    ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

    ==================== Services (Whitelisted) ======

    2 ES lite Service; "C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE" [68136 2009-08-24] ()
    2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [654408 2012-04-04] (Malwarebytes Corporation)
    2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-02-18] ()
    2 WinDefend; C:\Program Files (x86)\Windows Defender\mpsvc.dll [x]

    ========================== Drivers (Whitelisted) =============

    1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [279616 2011-11-29] (DT Soft Ltd)
    3 gdrv; \??\C:\Windows\gdrv.sys [25640 2012-07-12] (Windows (R) Server 2003 DDK provider)
    3 Gun; \??\C:\Game\SoftnyxGame\GunBoundIS\Gun64.sys [45176 2012-05-05] ()
    3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-04-04] (Malwarebytes Corporation)
    3 catchme; \??\C:\ComboFix\catchme.sys [x]

    ========================== NetSvcs (Whitelisted) ===========


    ============ One Month Created Files and Folders ==============

    2012-07-12 11:02 - 2012-07-12 11:02 - 00285376 ____A C:\Windows\Minidump\071212-29016-01.dmp
    2012-07-12 10:56 - 2012-07-12 10:56 - 00284584 ____A C:\Windows\Minidump\071212-19890-01.dmp
    2012-07-09 22:36 - 2012-07-09 22:36 - 00288464 ____A C:\Windows\Minidump\070912-27424-01.dmp
    2012-07-04 17:06 - 2012-07-04 17:06 - 00000278 ____A C:\Users\Justin\Desktop\128kbps.pls
    2012-07-02 20:50 - 2012-07-02 20:50 - 00285136 ____A C:\Windows\Minidump\070212-39421-01.dmp
    2012-07-02 10:27 - 2012-07-02 10:27 - 00284512 ____A C:\Windows\Minidump\070212-18236-01.dmp
    2012-07-01 19:32 - 2012-07-01 19:32 - 00284512 ____A C:\Windows\Minidump\070112-17472-01.dmp
    2012-07-01 14:59 - 2012-07-01 14:59 - 00285712 ____A C:\Windows\Minidump\070112-21512-01.dmp
    2012-06-30 19:13 - 2012-06-30 19:13 - 00284672 ____A C:\Windows\Minidump\063012-17612-01.dmp
    2012-06-30 19:11 - 2012-06-30 19:11 - 00284592 ____A C:\Windows\Minidump\063012-19032-01.dmp
    2012-06-30 19:02 - 2012-06-30 19:02 - 00284752 ____A C:\Windows\Minidump\063012-18548-01.dmp
    2012-06-30 18:00 - 2012-06-30 18:00 - 00284944 ____A C:\Windows\Minidump\063012-26239-01.dmp
    2012-06-30 10:15 - 2012-07-09 22:40 - 00000000 ____D C:\FRST
    2012-06-30 09:08 - 2012-06-30 09:08 - 00285816 ____A C:\Windows\Minidump\063012-20748-01.dmp
    2012-06-30 08:55 - 2012-06-30 08:55 - 00292736 ____A C:\Windows\Minidump\063012-19172-01.dmp
    2012-06-29 01:39 - 2012-06-29 01:39 - 00000000 ____D C:\Users\Justin\Desktop\RGSC
    2012-06-29 01:37 - 2012-06-29 01:39 - 222070843 ____A C:\Users\Justin\Desktop\RGSC.rar
    2012-06-29 01:36 - 2012-06-29 01:36 - 00001843 ____A C:\lanoire6-29-2012 2-36-52 AM.log
    2012-06-28 21:38 - 2008-07-12 07:18 - 04992520 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_39.dll
    2012-06-28 21:38 - 2008-07-12 07:18 - 01942552 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_39.dll
    2012-06-28 21:38 - 2008-07-12 07:18 - 00540688 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_39.dll
    2012-06-28 19:01 - 2012-06-28 19:01 - 02796287 ____A C:\Users\Justin\Desktop\RGSC_1_1_3_0.rar
    2012-06-28 18:55 - 2012-06-28 18:55 - 00000000 ____D C:\Users\Justin\Documents\Rockstar Games
    2012-06-24 12:45 - 2012-06-24 12:46 - 00000288 ____A C:\Windows\SysWOW64\msexcr.ini
    2012-06-24 01:10 - 2012-06-24 01:10 - 00292704 ____A C:\Windows\Minidump\062412-23368-01.dmp
    2012-06-24 00:10 - 2012-06-24 00:11 - 00285256 ____A C:\Windows\Minidump\062412-50965-01.dmp
    2012-06-24 00:06 - 2012-06-24 00:06 - 00286760 ____A C:\Windows\Minidump\062412-20124-01.dmp
    2012-06-24 00:00 - 2012-06-24 00:01 - 00292736 ____A C:\Windows\Minidump\062412-19312-01.dmp
    2012-06-22 00:16 - 2012-06-22 00:40 - 13287340 ____A C:\Users\Justin\Desktop\megamix.mp3
    2012-06-22 00:02 - 2012-06-22 00:02 - 00000000 ____D C:\Users\Justin\AppData\Roaming\Azureus
    2012-06-21 10:52 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
    2012-06-21 10:52 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
    2012-06-21 10:52 - 2012-06-02 14:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
    2012-06-21 10:52 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
    2012-06-21 10:52 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
    2012-06-21 10:52 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
    2012-06-21 10:52 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
    2012-06-21 10:52 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
    2012-06-21 10:52 - 2012-06-02 14:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
    2012-06-19 16:12 - 2012-06-19 16:12 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
    2012-06-17 13:52 - 2009-07-13 17:14 - 00020480 ____A (Microsoft Corporation) C:\Windows\svchost.exe
    2012-06-17 13:10 - 2012-06-17 13:10 - 00000000 ____A C:\Users\Justin\Desktop\gmer.log
    2012-06-15 11:31 - 2012-06-15 11:31 - 00291072 ____A C:\Windows\Minidump\061512-19500-01.dmp
    2012-06-14 23:33 - 2012-06-14 23:33 - 00287464 ____A C:\Windows\Minidump\061512-18220-01.dmp
    2012-06-12 12:39 - 2012-06-12 12:39 - 00284752 ____A C:\Windows\Minidump\061212-16270-01.dmp
    2012-06-12 12:34 - 2012-06-12 12:35 - 00284752 ____A C:\Windows\Minidump\061212-18673-01.dmp
    2012-06-12 12:27 - 2012-06-12 12:27 - 00285536 ____A C:\Windows\Minidump\061212-16941-01.dmp
    2012-06-12 12:09 - 2012-06-12 12:09 - 00284592 ____A C:\Windows\Minidump\061212-17097-01.dmp
    2012-06-12 11:03 - 2012-06-12 11:03 - 00284672 ____A C:\Windows\Minidump\061212-16707-01.dmp

    ============ 3 Months Modified Files ========================

    2012-07-12 15:58 - 2011-07-14 15:35 - 00000237 ____A C:\service.log
    2012-07-12 15:58 - 2011-07-14 15:18 - 01190591 ____A C:\Windows\WindowsUpdate.log
    2012-07-12 15:16 - 2011-07-14 15:39 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-312835093-3087082948-3825595922-1000UA.job
    2012-07-12 15:01 - 2009-07-13 21:13 - 00730448 ____A C:\Windows\System32\PerfStringBackup.INI
    2012-07-12 15:00 - 2009-07-13 20:45 - 00013424 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2012-07-12 15:00 - 2009-07-13 20:45 - 00013424 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2012-07-12 14:55 - 2011-07-14 17:07 - 00025640 ____A (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
    2012-07-12 14:55 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2012-07-12 14:55 - 2009-07-13 20:51 - 00088028 ____A C:\Windows\setupact.log
    2012-07-12 11:02 - 2012-07-12 11:02 - 00285376 ____A C:\Windows\Minidump\071212-29016-01.dmp
    2012-07-12 11:02 - 2011-09-03 21:20 - 534257664 ____A C:\Windows\MEMORY.DMP
    2012-07-12 10:56 - 2012-07-12 10:56 - 00284584 ____A C:\Windows\Minidump\071212-19890-01.dmp
    2012-07-12 00:16 - 2011-07-14 15:39 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-312835093-3087082948-3825595922-1000Core.job
    2012-07-11 18:17 - 2011-07-14 15:40 - 00002364 ____A C:\Users\Justin\Desktop\Google Chrome.lnk
    2012-07-09 22:36 - 2012-07-09 22:36 - 00288464 ____A C:\Windows\Minidump\070912-27424-01.dmp
    2012-07-04 17:06 - 2012-07-04 17:06 - 00000278 ____A C:\Users\Justin\Desktop\128kbps.pls
    2012-07-02 22:15 - 2011-07-14 15:24 - 00288614 ____A C:\Windows\DirectX.log
    2012-07-02 20:50 - 2012-07-02 20:50 - 00285136 ____A C:\Windows\Minidump\070212-39421-01.dmp
    2012-07-02 10:28 - 2009-07-13 21:08 - 00032630 ____A C:\Windows\Tasks\SCHEDLGU.TXT
    2012-07-02 10:27 - 2012-07-02 10:27 - 00284512 ____A C:\Windows\Minidump\070212-18236-01.dmp
    2012-07-01 19:32 - 2012-07-01 19:32 - 00284512 ____A C:\Windows\Minidump\070112-17472-01.dmp
    2012-07-01 14:59 - 2012-07-01 14:59 - 00285712 ____A C:\Windows\Minidump\070112-21512-01.dmp
    2012-06-30 19:13 - 2012-06-30 19:13 - 00284672 ____A C:\Windows\Minidump\063012-17612-01.dmp
    2012-06-30 19:11 - 2012-06-30 19:11 - 00284592 ____A C:\Windows\Minidump\063012-19032-01.dmp
    2012-06-30 19:02 - 2012-06-30 19:02 - 00284752 ____A C:\Windows\Minidump\063012-18548-01.dmp
    2012-06-30 18:04 - 2012-06-06 23:00 - 00000545 ____A C:\rkill.log
    2012-06-30 18:00 - 2012-06-30 18:00 - 00284944 ____A C:\Windows\Minidump\063012-26239-01.dmp
    2012-06-30 09:08 - 2012-06-30 09:08 - 00285816 ____A C:\Windows\Minidump\063012-20748-01.dmp
    2012-06-30 08:55 - 2012-06-30 08:55 - 00292736 ____A C:\Windows\Minidump\063012-19172-01.dmp
    2012-06-29 01:39 - 2012-06-29 01:37 - 222070843 ____A C:\Users\Justin\Desktop\RGSC.rar
    2012-06-29 01:36 - 2012-06-29 01:36 - 00001843 ____A C:\lanoire6-29-2012 2-36-52 AM.log
    2012-06-28 19:01 - 2012-06-28 19:01 - 02796287 ____A C:\Users\Justin\Desktop\RGSC_1_1_3_0.rar
    2012-06-24 12:46 - 2012-06-24 12:45 - 00000288 ____A C:\Windows\SysWOW64\msexcr.ini
    2012-06-24 01:10 - 2012-06-24 01:10 - 00292704 ____A C:\Windows\Minidump\062412-23368-01.dmp
    2012-06-24 00:11 - 2012-06-24 00:10 - 00285256 ____A C:\Windows\Minidump\062412-50965-01.dmp
    2012-06-24 00:06 - 2012-06-24 00:06 - 00286760 ____A C:\Windows\Minidump\062412-20124-01.dmp
    2012-06-24 00:02 - 2012-05-11 22:22 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2012-06-24 00:02 - 2011-07-18 06:30 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2012-06-24 00:01 - 2012-06-24 00:00 - 00292736 ____A C:\Windows\Minidump\062412-19312-01.dmp
    2012-06-22 00:43 - 2011-12-09 19:44 - 00005632 ____A C:\Users\Justin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2012-06-22 00:40 - 2012-06-22 00:16 - 13287340 ____A C:\Users\Justin\Desktop\megamix.mp3
    2012-06-19 10:45 - 2011-07-14 17:05 - 00066850 ____A C:\Windows\PFRO.log
    2012-06-17 13:10 - 2012-06-17 13:10 - 00000000 ____A C:\Users\Justin\Desktop\gmer.log
    2012-06-15 11:31 - 2012-06-15 11:31 - 00291072 ____A C:\Windows\Minidump\061512-19500-01.dmp
    2012-06-14 23:33 - 2012-06-14 23:33 - 00287464 ____A C:\Windows\Minidump\061512-18220-01.dmp
    2012-06-13 22:37 - 2011-07-14 15:42 - 00001080 ___AH C:\IPH.PH
    2012-06-12 12:39 - 2012-06-12 12:39 - 00284752 ____A C:\Windows\Minidump\061212-16270-01.dmp
    2012-06-12 12:35 - 2012-06-12 12:34 - 00284752 ____A C:\Windows\Minidump\061212-18673-01.dmp
    2012-06-12 12:27 - 2012-06-12 12:27 - 00285536 ____A C:\Windows\Minidump\061212-16941-01.dmp
    2012-06-12 12:09 - 2012-06-12 12:09 - 00284592 ____A C:\Windows\Minidump\061212-17097-01.dmp
    2012-06-12 11:03 - 2012-06-12 11:03 - 00284672 ____A C:\Windows\Minidump\061212-16707-01.dmp
    2012-06-11 15:19 - 2012-06-11 15:19 - 00284688 ____A C:\Windows\Minidump\061112-15818-01.dmp
    2012-06-07 14:38 - 2012-06-07 14:38 - 00302592 ____A C:\Users\Justin\Desktop\gktwy3y7.exe
    2012-06-07 00:29 - 2012-06-06 00:00 - 00000273 ____A C:\Windows\wininit.ini
    2012-06-07 00:14 - 2012-06-07 00:14 - 00001258 ____A C:\Users\Justin\Desktop\Spybot - Search & Destroy.lnk
    2012-06-07 00:10 - 2012-06-07 00:10 - 16409960 ____A (Safer Networking Limited ) C:\Users\Justin\Desktop\spybotsd162.exe
    2012-06-06 23:17 - 2012-06-07 00:33 - 00000027 ____A C:\Windows\System32\Drivers\etc\hosts.20120607-013318.backup
    2012-06-06 23:17 - 2009-07-13 18:34 - 00000215 ____A C:\Windows\system.ini
    2012-06-06 23:00 - 2012-06-06 22:59 - 01012656 ____A C:\Users\Justin\Desktop\rkill.exe
    2012-06-06 22:43 - 2012-06-06 19:47 - 04538022 ____R (Swearware) C:\Users\Justin\Desktop\ComboFix.exe
    2012-06-06 22:41 - 2012-06-06 22:41 - 00291488 ____A C:\Windows\Minidump\060612-19094-01.dmp
    2012-06-06 22:27 - 2012-06-06 22:27 - 00792912 ____A C:\Windows\Minidump\060612-17628-01.dmp
    2012-06-06 16:52 - 2012-06-06 16:52 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Justin\Desktop\mbam-setup-1.61.0.1400.exe
    2012-06-06 16:52 - 2012-06-06 16:52 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-06-06 16:47 - 2012-06-06 16:47 - 00285616 ____A C:\Windows\Minidump\060612-32120-01.dmp
    2012-06-06 16:44 - 2012-06-06 16:44 - 00001088 ____A C:\Users\Justin\Desktop\EVGA Precision X.lnk
    2012-06-06 16:27 - 2012-06-06 16:27 - 00285336 ____A C:\Windows\Minidump\060612-24835-01.dmp
    2012-06-06 16:24 - 2012-06-06 16:24 - 00287520 ____A C:\Windows\Minidump\060612-25537-01.dmp
    2012-06-06 16:12 - 2012-06-06 16:12 - 00284520 ____A C:\Windows\Minidump\060612-24663-01.dmp
    2012-06-06 16:10 - 2012-06-06 16:10 - 00292440 ____A C:\Windows\Minidump\060612-26176-01.dmp
    2012-06-06 15:36 - 2012-06-06 15:36 - 00000000 ____A C:\Windows\SysWOW64\config.nt
    2012-06-06 15:25 - 2012-06-06 15:25 - 00288728 ____A C:\Windows\Minidump\060612-20170-01.dmp
    2012-06-05 22:48 - 2012-06-05 22:44 - 74761776 ____A C:\Users\Justin\Desktop\avast_free_antivirus_setup.exe
    2012-06-05 22:38 - 2012-06-05 22:38 - 00285560 ____A C:\Windows\Minidump\060512-24554-01.dmp
    2012-06-03 15:23 - 2011-07-14 21:40 - 00283304 ____A C:\Windows\SysWOW64\PnkBstrB.xtr
    2012-06-03 15:23 - 2011-07-14 21:39 - 00283304 ____A C:\Windows\SysWOW64\PnkBstrB.exe
    2012-06-03 15:23 - 2011-07-14 21:39 - 00280904 ____A C:\Windows\SysWOW64\PnkBstrB.ex0
    2012-06-02 14:19 - 2012-06-21 10:52 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
    2012-06-02 14:19 - 2012-06-21 10:52 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
    2012-06-02 14:19 - 2012-06-21 10:52 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
    2012-06-02 14:19 - 2012-06-21 10:52 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
    2012-06-02 14:19 - 2012-06-21 10:52 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
    2012-06-02 14:19 - 2012-06-21 10:52 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
    2012-06-02 14:15 - 2012-06-21 10:52 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
    2012-06-02 14:15 - 2012-06-21 10:52 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
    2012-06-02 14:15 - 2012-06-21 10:52 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
    2012-05-15 02:48 - 2012-06-06 16:36 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
    2012-05-15 02:48 - 2012-06-06 16:36 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
    2012-05-15 02:48 - 2012-06-06 16:36 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
    2012-05-15 02:48 - 2012-06-06 16:36 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
    2012-05-15 02:48 - 2012-06-06 16:36 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
    2012-05-15 02:48 - 2012-06-06 16:36 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
    2012-05-15 02:48 - 2012-06-06 16:36 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
    2012-05-15 02:48 - 2012-06-06 16:36 - 08105280 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
    2012-05-15 02:48 - 2012-06-06 16:36 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
    2012-05-15 02:48 - 2012-06-06 16:36 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
    2012-05-15 02:48 - 2012-06-06 16:36 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
    2012-05-15 02:48 - 2012-06-06 16:36 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
    2012-05-15 02:48 - 2012-06-06 16:36 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
    2012-05-15 02:48 - 2012-06-06 16:36 - 02368832 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
    2012-05-15 02:48 - 2012-06-06 16:36 - 00818496 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
    2012-05-15 02:48 - 2012-06-06 16:36 - 00364352 ____A (NVIDIA Corporation) C:\Windows\System32\nvdecodemft.dll
    2012-05-15 02:48 - 2012-06-06 16:36 - 00301376 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvdecodemft.dll
    2012-05-15 02:48 - 2012-06-06 16:36 - 00246592 ____A (NVIDIA Corporation) C:\Windows\System32\nvinitx.dll
    2012-05-15 02:48 - 2012-06-06 16:36 - 00202048 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
    2012-05-15 02:48 - 2012-03-18 00:35 - 00949056 ____A (NVIDIA Corporation) C:\Windows\System32\nvumdshimx.dll
    2012-05-15 02:48 - 2012-03-18 00:35 - 00068928 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
    2012-05-15 02:48 - 2012-03-18 00:35 - 00061248 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
    2012-05-15 02:48 - 2011-10-23 00:16 - 01738048 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco64.dll
    2012-05-15 02:48 - 2011-10-23 00:16 - 01468224 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco64.dll
    2012-05-15 02:48 - 2011-07-14 22:37 - 10194752 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2umx.dll
    2012-05-15 02:48 - 2011-07-14 18:30 - 15322432 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
    2012-05-15 02:48 - 2011-07-14 15:19 - 02741568 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi64.dll
    2012-05-15 02:48 - 2011-07-14 15:19 - 00014324 ____A C:\Windows\System32\nvinfo.pb
    2012-05-15 01:29 - 2012-03-18 00:36 - 02621723 ____A C:\Windows\System32\nvcoproc.bin
    2012-05-15 01:29 - 2011-01-16 16:13 - 03149632 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc64.dll
    2012-05-15 01:29 - 2011-01-16 16:13 - 00889664 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    2012-05-15 01:29 - 2011-01-16 16:13 - 00118080 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
    2012-05-15 01:29 - 2011-01-16 16:13 - 00063296 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
    2012-05-15 01:28 - 2011-01-16 16:13 - 06151488 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
    2012-05-15 01:21 - 2012-05-15 01:21 - 00423744 ____A C:\Windows\SysWOW64\nvStreaming.exe
    2012-05-01 17:12 - 2012-05-01 17:12 - 00001219 ____A C:\Users\Justin\Desktop\FrostWire 5.2.9.lnk
    2012-04-18 09:08 - 2012-06-06 16:36 - 00188736 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvhda64v.sys
    2012-04-18 09:08 - 2012-06-06 16:36 - 00031040 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdap64.dll
    2012-04-18 09:08 - 2012-03-18 00:35 - 01451840 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdagenco6420103.dll


    ========================= Known DLLs (Whitelisted) ============


    ========================= Bamital & volsnap Check ============

    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== EXE ASSOCIATION =====================

    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK

    ========================= Memory info ======================

    Percentage of memory in use: 10%
    Total physical RAM: 8189.55 MB
    Available physical RAM: 7345.01 MB
    Total Pagefile: 8187.7 MB
    Available Pagefile: 7339.44 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.9 MB

    ======================= Partitions =========================

    2 Drive c: () (Fixed) (Total:931.41 GB) (Free:739.83 GB) NTFS
    4 Drive f: (KINGSTON) (Removable) (Total:3.73 GB) (Free:3.73 GB) FAT32
    5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    6 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

    Disk ### Status Size Free Dyn Gpt
    -------- ------------- ------- ------- --- ---
    Disk 0 Online 931 GB 0 B
    Disk 1 Online 3826 MB 0 B

    Partitions of Disk 0:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 100 MB 1024 KB
    Partition 2 Primary 931 GB 101 MB

    ==================================================================================

    Disk: 0
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 1 Y System Rese NTFS Partition 100 MB Healthy

    ==================================================================================

    Disk: 0
    Partition 2
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 2 C NTFS Partition 931 GB Healthy

    ==================================================================================

    Partitions of Disk 1:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 3825 MB 568 KB

    ==================================================================================

    Disk: 1
    Partition 1
    Type : 0B
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 3 F KINGSTON FAT32 Removable 3825 MB Healthy

    ==================================================================================

    ==========================================================

    Last Boot: 2012-07-08 14:24

    ======================= End Of Log ==========================
     
  19. Broni

    Broni Malware Annihilator Posts: 52,892   +344

    Restart normally.

    Download TDSSKiller and save it to your desktop.
    • Extract (unzip) its contents to your desktop.
    • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
     
  20. aznsaik0

    aznsaik0 TS Rookie Topic Starter

    16:00:10.0655 3828TDSS rootkit removing tool 2.7.46.0 Jul 16 2012 22:10:11
    16:00:11.0137 3828============================================================
    16:00:11.0137 3828Current date / time: 2012/07/17 16:00:11.0137
    16:00:11.0137 3828SystemInfo:
    16:00:11.0137 3828
    16:00:11.0137 3828OS Version: 6.1.7600 ServicePack: 0.0
    16:00:11.0137 3828Product type: Workstation
    16:00:11.0137 3828ComputerName: JUSTIN-PC
    16:00:11.0137 3828UserName: Justin
    16:00:11.0137 3828Windows directory: C:\Windows
    16:00:11.0137 3828System windows directory: C:\Windows
    16:00:11.0137 3828Running under WOW64
    16:00:11.0137 3828Processor architecture: Intel x64
    16:00:11.0137 3828Number of processors: 6
    16:00:11.0137 3828Page size: 0x1000
    16:00:11.0137 3828Boot type: Normal boot
    16:00:11.0137 3828============================================================
    16:00:12.0196 3828Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1F8B1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040
    16:00:12.0199 3828============================================================
    16:00:12.0199 3828\Device\Harddisk0\DR0:
    16:00:12.0199 3828MBR partitions:
    16:00:12.0199 3828\Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
    16:00:12.0199 3828\Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800
    16:00:12.0199 3828============================================================
    16:00:12.0214 3828C: <-> \Device\Harddisk0\DR0\Partition1
    16:00:12.0214 3828============================================================
    16:00:12.0214 3828Initialize success
    16:00:12.0214 3828============================================================
    16:00:13.0595 1788============================================================
    16:00:13.0595 1788Scan started
    16:00:13.0595 1788Mode: Manual;
    16:00:13.0595 1788============================================================
    16:00:14.0911 17881394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
    16:00:14.0913 17881394ohci - ok
    16:00:14.0955 1788ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
    16:00:14.0958 1788ACPI - ok
    16:00:14.0970 1788AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
    16:00:14.0970 1788AcpiPmi - ok
    16:00:15.0072 1788AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    16:00:15.0072 1788AdobeARMservice - ok
    16:00:15.0175 1788AdobeFlashPlayerUpdateSvc (990dc6edc9f933194d7cd4e65146bc94) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    16:00:15.0178 1788AdobeFlashPlayerUpdateSvc - ok
    16:00:15.0203 1788adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
    16:00:15.0208 1788adp94xx - ok
    16:00:15.0224 1788adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
    16:00:15.0227 1788adpahci - ok
    16:00:15.0237 1788adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
    16:00:15.0239 1788adpu320 - ok
    16:00:15.0260 1788AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
    16:00:15.0261 1788AeLookupSvc - ok
    16:00:15.0309 1788AFD (6ef20ddf3172e97d69f596fb90602f29) C:\Windows\system32\drivers\afd.sys
    16:00:15.0314 1788AFD - ok
    16:00:15.0326 1788agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
    16:00:15.0327 1788agp440 - ok
    16:00:15.0340 1788ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
    16:00:15.0341 1788ALG - ok
    16:00:15.0357 1788aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
    16:00:15.0357 1788aliide - ok
    16:00:15.0362 1788amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
    16:00:15.0363 1788amdide - ok
    16:00:15.0372 1788AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
    16:00:15.0373 1788AmdK8 - ok
    16:00:15.0394 1788AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
    16:00:15.0395 1788AmdPPM - ok
    16:00:15.0430 1788amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
    16:00:15.0431 1788amdsata - ok
    16:00:15.0448 1788amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
    16:00:15.0450 1788amdsbs - ok
    16:00:15.0461 1788amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
    16:00:15.0462 1788amdxata - ok
    16:00:15.0481 1788AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
    16:00:15.0482 1788AppID - ok
    16:00:15.0494 1788AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
    16:00:15.0494 1788AppIDSvc - ok
    16:00:15.0514 1788Appinfo (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
    16:00:15.0515 1788Appinfo - ok
    16:00:15.0588 1788Apple Mobile Device (3debbecf665dcdde3a95d9b902010817) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    16:00:15.0589 1788Apple Mobile Device - ok
    16:00:15.0617 1788AppMgmt (4aba3e75a76195a3e38ed2766c962899) C:\Windows\System32\appmgmts.dll
    16:00:15.0619 1788AppMgmt - ok
    16:00:15.0637 1788arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
    16:00:15.0638 1788arc - ok
    16:00:15.0651 1788arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
    16:00:15.0652 1788arcsas - ok
    16:00:15.0677 1788AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
    16:00:15.0677 1788AsyncMac - ok
    16:00:15.0683 1788atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
    16:00:15.0684 1788atapi - ok
    16:00:15.0709 1788AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
    16:00:15.0716 1788AudioEndpointBuilder - ok
    16:00:15.0720 1788AudioSrv (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
    16:00:15.0723 1788AudioSrv - ok
    16:00:15.0745 1788AxInstSV (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
    16:00:15.0747 1788AxInstSV - ok
    16:00:15.0770 1788b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
    16:00:15.0775 1788b06bdrv - ok
    16:00:15.0800 1788b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
    16:00:15.0802 1788b57nd60a - ok
    16:00:15.0817 1788BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
    16:00:15.0819 1788BDESVC - ok
    16:00:15.0831 1788Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
    16:00:15.0831 1788Beep - ok
    16:00:15.0872 1788BFE (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
    16:00:15.0879 1788BFE - ok
    16:00:15.0916 1788BITS (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\system32\qmgr.dll
    16:00:15.0924 1788BITS - ok
    16:00:15.0956 1788blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
    16:00:15.0957 1788blbdrive - ok
    16:00:16.0028 1788Bonjour Service (ebbcd5dfbb1de70e8f4af8fa59e401fd) C:\Program Files\Bonjour\mDNSResponder.exe
    16:00:16.0032 1788Bonjour Service - ok
    16:00:16.0068 1788bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
    16:00:16.0069 1788bowser - ok
    16:00:16.0082 1788BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
    16:00:16.0083 1788BrFiltLo - ok
    16:00:16.0094 1788BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
    16:00:16.0094 1788BrFiltUp - ok
    16:00:16.0155 1788BridgeMP (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys
    16:00:16.0156 1788BridgeMP - ok
    16:00:16.0171 1788Browser (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
    16:00:16.0172 1788Browser - ok
    16:00:16.0191 1788Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
    16:00:16.0194 1788Brserid - ok
    16:00:16.0208 1788BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
    16:00:16.0208 1788BrSerWdm - ok
    16:00:16.0219 1788BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
    16:00:16.0219 1788BrUsbMdm - ok
    16:00:16.0231 1788BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
    16:00:16.0231 1788BrUsbSer - ok
    16:00:16.0251 1788BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
    16:00:16.0252 1788BTHMODEM - ok
    16:00:16.0268 1788bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
    16:00:16.0269 1788bthserv - ok
    16:00:16.0307 1788catchme - ok
    16:00:16.0336 1788cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
    16:00:16.0337 1788cdfs - ok
    16:00:16.0400 1788cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
    16:00:16.0402 1788cdrom - ok
    16:00:16.0426 1788CertPropSvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
    16:00:16.0427 1788CertPropSvc - ok
    16:00:16.0441 1788circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
    16:00:16.0442 1788circlass - ok
    16:00:16.0464 1788CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
    16:00:16.0468 1788CLFS - ok
    16:00:16.0511 1788clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    16:00:16.0514 1788clr_optimization_v2.0.50727_32 - ok
    16:00:16.0566 1788clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
    16:00:16.0569 1788clr_optimization_v2.0.50727_64 - ok
    16:00:16.0633 1788clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    16:00:16.0667 1788clr_optimization_v4.0.30319_32 - ok
    16:00:16.0695 1788clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
    16:00:16.0697 1788clr_optimization_v4.0.30319_64 - ok
    16:00:16.0716 1788CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
    16:00:16.0716 1788CmBatt - ok
    16:00:16.0721 1788cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
    16:00:16.0721 1788cmdide - ok
    16:00:16.0739 1788CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
    16:00:16.0743 1788CNG - ok
    16:00:16.0746 1788Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
    16:00:16.0746 1788Compbatt - ok
    16:00:16.0755 1788CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
    16:00:16.0756 1788CompositeBus - ok
    16:00:16.0767 1788COMSysApp - ok
    16:00:16.0784 1788crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
    16:00:16.0785 1788crcdisk - ok
    16:00:16.0806 1788CryptSvc (8c57411b66282c01533cb776f98ad384) C:\Windows\system32\cryptsvc.dll
    16:00:16.0808 1788CryptSvc - ok
    16:00:16.0831 1788CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
    16:00:16.0836 1788CSC - ok
    16:00:16.0863 1788CscService (873fbf927c06e5cee04dec617502f8fd) C:\Windows\System32\cscsvc.dll
    16:00:16.0869 1788CscService - ok
    16:00:16.0899 1788DcomLaunch (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
    16:00:16.0905 1788DcomLaunch - ok
    16:00:16.0927 1788defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
    16:00:16.0930 1788defragsvc - ok
    16:00:16.0971 1788DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
    16:00:16.0972 1788DfsC - ok
    16:00:16.0995 1788Dhcp (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
    16:00:16.0998 1788Dhcp - ok
    16:00:17.0012 1788discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
    16:00:17.0013 1788discache - ok
    16:00:17.0037 1788Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
    16:00:17.0037 1788Disk - ok
    16:00:17.0065 1788Dnscache (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
    16:00:17.0067 1788Dnscache - ok
    16:00:17.0098 1788dot3svc (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
    16:00:17.0101 1788dot3svc - ok
    16:00:17.0117 1788DPS (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
    16:00:17.0119 1788DPS - ok
    16:00:17.0152 1788drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
    16:00:17.0152 1788drmkaud - ok
    16:00:17.0194 1788dtsoftbus01 (400582b09e0bb557d0ec28a945150eeb) C:\Windows\system32\DRIVERS\dtsoftbus01.sys
    16:00:17.0195 1788dtsoftbus01 - ok
    16:00:17.0245 1788DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
    16:00:17.0249 1788DXGKrnl - ok
    16:00:17.0264 1788EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
    16:00:17.0266 1788EapHost - ok
    16:00:17.0346 1788ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
    16:00:17.0374 1788ebdrv - ok
    16:00:17.0443 1788EFS (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\System32\lsass.exe
    16:00:17.0444 1788EFS - ok
    16:00:17.0503 1788ehRecvr (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
    16:00:17.0510 1788ehRecvr - ok
    16:00:17.0531 1788ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
    16:00:17.0533 1788ehSched - ok
    16:00:17.0583 1788elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
    16:00:17.0589 1788elxstor - ok
    16:00:17.0594 1788ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
    16:00:17.0595 1788ErrDev - ok
    16:00:17.0659 1788ES lite Service (b8fa96995726d1fa58476e352c02ad82) C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE
    16:00:17.0660 1788ES lite Service - ok
    16:00:17.0694 1788EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
    16:00:17.0698 1788EventSystem - ok
    16:00:17.0722 1788exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
    16:00:17.0724 1788exfat - ok
    16:00:17.0742 1788fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
    16:00:17.0744 1788fastfat - ok
    16:00:17.0772 1788Fax (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
    16:00:17.0779 1788Fax - ok
    16:00:17.0786 1788fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
    16:00:17.0787 1788fdc - ok
    16:00:17.0796 1788fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
    16:00:17.0796 1788fdPHost - ok
    16:00:17.0808 1788FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
    16:00:17.0809 1788FDResPub - ok
    16:00:17.0819 1788FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
    16:00:17.0819 1788FileInfo - ok
    16:00:17.0832 1788Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
    16:00:17.0833 1788Filetrace - ok
    16:00:17.0838 1788flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
    16:00:17.0838 1788flpydisk - ok
    16:00:17.0929 1788FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
    16:00:17.0932 1788FltMgr - ok
    16:00:17.0986 1788FontCache (cb5e4b9c319e3c6bb363eb7e58a4a051) C:\Windows\system32\FntCache.dll
    16:00:17.0996 1788FontCache - ok
    16:00:18.0060 1788FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    16:00:18.0061 1788FontCache3.0.0.0 - ok
    16:00:18.0079 1788FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
    16:00:18.0080 1788FsDepends - ok
    16:00:18.0086 1788Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
    16:00:18.0086 1788Fs_Rec - ok
    16:00:18.0121 1788fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
    16:00:18.0123 1788fvevol - ok
    16:00:18.0162 1788gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
    16:00:18.0163 1788gagp30kx - ok
    16:00:18.0201 1788gdrv (7907e14f9bcf3a4689c9a74a1a873cb6) C:\Windows\gdrv.sys
    16:00:18.0201 1788gdrv - ok
    16:00:18.0245 1788GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
    16:00:18.0245 1788GEARAspiWDM - ok
    16:00:18.0277 1788gpsvc (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
    16:00:18.0284 1788gpsvc - ok
    16:00:18.0361 1788Gun (721ce1551f8198714f3cabfe2147939b) C:\Game\SoftnyxGame\GunBoundIS\Gun64.sys
    16:00:18.0361 1788Gun - ok
    16:00:18.0373 1788hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
    16:00:18.0374 1788hcw85cir - ok
    16:00:18.0411 1788HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
    16:00:18.0414 1788HdAudAddService - ok
    16:00:18.0439 1788HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
    16:00:18.0441 1788HDAudBus - ok
    16:00:18.0448 1788HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
    16:00:18.0449 1788HidBatt - ok
    16:00:18.0463 1788HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
    16:00:18.0465 1788HidBth - ok
    16:00:18.0468 1788HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
    16:00:18.0469 1788HidIr - ok
    16:00:18.0494 1788hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\System32\hidserv.dll
    16:00:18.0495 1788hidserv - ok
    16:00:18.0519 1788HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
    16:00:18.0520 1788HidUsb - ok
    16:00:18.0543 1788hkmsvc (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
    16:00:18.0545 1788hkmsvc - ok
    16:00:18.0560 1788HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
    16:00:18.0563 1788HomeGroupListener - ok
    16:00:18.0587 1788HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
    16:00:18.0590 1788HomeGroupProvider - ok
    16:00:18.0608 1788HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
    16:00:18.0609 1788HpSAMD - ok
    16:00:18.0638 1788HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
    16:00:18.0645 1788HTTP - ok
    16:00:18.0661 1788hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
    16:00:18.0661 1788hwpolicy - ok
    16:00:18.0685 1788i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
    16:00:18.0686 1788i8042prt - ok
    16:00:18.0718 1788iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
    16:00:18.0722 1788iaStorV - ok
    16:00:18.0807 1788idsvc (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
    16:00:18.0815 1788idsvc - ok
    16:00:18.0829 1788iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
    16:00:18.0830 1788iirsp - ok
    16:00:18.0862 1788IKEEXT (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
    16:00:18.0871 1788IKEEXT - ok
    16:00:18.0881 1788intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
    16:00:18.0881 1788intelide - ok
    16:00:18.0908 1788intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
    16:00:18.0909 1788intelppm - ok
    16:00:18.0924 1788IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
    16:00:18.0926 1788IPBusEnum - ok
    16:00:18.0948 1788IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
    16:00:18.0949 1788IpFilterDriver - ok
    16:00:18.0976 1788iphlpsvc (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
    16:00:18.0981 1788iphlpsvc - ok
    16:00:18.0995 1788IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
    16:00:18.0997 1788IPMIDRV - ok
    16:00:19.0011 1788IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
    16:00:19.0012 1788IPNAT - ok
    16:00:19.0105 1788iPod Service (ee4c2a137c7088911a8919effc9812e7) C:\Program Files\iPod\bin\iPodService.exe
    16:00:19.0113 1788iPod Service - ok
    16:00:19.0126 1788IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
    16:00:19.0127 1788IRENUM - ok
    16:00:19.0137 1788isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
    16:00:19.0138 1788isapnp - ok
    16:00:19.0150 1788iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
    16:00:19.0152 1788iScsiPrt - ok
    16:00:19.0168 1788kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
    16:00:19.0169 1788kbdclass - ok
    16:00:19.0188 1788kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
    16:00:19.0189 1788kbdhid - ok
    16:00:19.0207 1788KeyIso (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
    16:00:19.0208 1788KeyIso - ok
    16:00:19.0221 1788KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
    16:00:19.0221 1788KSecDD - ok
    16:00:19.0257 1788KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
    16:00:19.0259 1788KSecPkg - ok
    16:00:19.0264 1788ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
    16:00:19.0265 1788ksthunk - ok
    16:00:19.0286 1788KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
    16:00:19.0290 1788KtmRm - ok
    16:00:19.0343 1788LanmanServer (81f1d04d4d0e433099365127375fd501) C:\Windows\System32\srvsvc.dll
    16:00:19.0347 1788LanmanServer - ok
    16:00:19.0370 1788LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
    16:00:19.0372 1788LanmanWorkstation - ok
    16:00:19.0404 1788lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
    16:00:19.0405 1788lltdio - ok
    16:00:19.0425 1788lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
    16:00:19.0428 1788lltdsvc - ok
    16:00:19.0442 1788lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
    16:00:19.0443 1788lmhosts - ok
    16:00:19.0464 1788LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
    16:00:19.0465 1788LSI_FC - ok
    16:00:19.0478 1788LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
    16:00:19.0479 1788LSI_SAS - ok
    16:00:19.0492 1788LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
    16:00:19.0493 1788LSI_SAS2 - ok
    16:00:19.0507 1788LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
    16:00:19.0508 1788LSI_SCSI - ok
    16:00:19.0532 1788luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
    16:00:19.0533 1788luafv - ok
    16:00:19.0579 1788MBAMProtector (dbc08862a71459e74f7538b432c114cc) C:\Windows\system32\drivers\mbam.sys
    16:00:19.0580 1788MBAMProtector - ok
    16:00:19.0682 1788MBAMService (ba400ed640bca1eae5c727ae17c10207) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    16:00:19.0688 1788MBAMService - ok
    16:00:19.0706 1788Mcx2Svc (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
    16:00:19.0708 1788Mcx2Svc - ok
    16:00:19.0722 1788megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
    16:00:19.0723 1788megasas - ok
    16:00:19.0741 1788MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
    16:00:19.0744 1788MegaSR - ok
    16:00:19.0802 1788Microsoft Office Groove Audit Service (7c4c76b39d5525c4a465e0be32528e19) C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
    16:00:19.0803 1788Microsoft Office Groove Audit Service - ok
    16:00:19.0829 1788MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
    16:00:19.0831 1788MMCSS - ok
    16:00:19.0834 1788Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
    16:00:19.0835 1788Modem - ok
    16:00:19.0855 1788monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
    16:00:19.0855 1788monitor - ok
    16:00:19.0877 1788mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
    16:00:19.0878 1788mouclass - ok
    16:00:19.0900 1788mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
    16:00:19.0901 1788mouhid - ok
    16:00:19.0915 1788mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
    16:00:19.0915 1788mountmgr - ok
    16:00:19.0926 1788mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
    16:00:19.0927 1788mpio - ok
    16:00:19.0937 1788mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
    16:00:19.0939 1788mpsdrv - ok
    16:00:19.0975 1788MpsSvc (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
    16:00:19.0983 1788MpsSvc - ok
    16:00:20.0003 1788MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
    16:00:20.0004 1788MRxDAV - ok
    16:00:20.0035 1788mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
    16:00:20.0036 1788mrxsmb - ok
    16:00:20.0068 1788mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
    16:00:20.0070 1788mrxsmb10 - ok
    16:00:20.0081 1788mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
    16:00:20.0083 1788mrxsmb20 - ok
    16:00:20.0100 1788msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
    16:00:20.0100 1788msahci - ok
    16:00:20.0113 1788msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
    16:00:20.0114 1788msdsm - ok
    16:00:20.0131 1788MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
    16:00:20.0133 1788MSDTC - ok
    16:00:20.0143 1788Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
    16:00:20.0144 1788Msfs - ok
    16:00:20.0152 1788mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
    16:00:20.0152 1788mshidkmdf - ok
    16:00:20.0155 1788msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
    16:00:20.0156 1788msisadrv - ok
    16:00:20.0183 1788MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
    16:00:20.0186 1788MSiSCSI - ok
    16:00:20.0188 1788msiserver - ok
    16:00:20.0203 1788MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
    16:00:20.0204 1788MSKSSRV - ok
    16:00:20.0219 1788MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
    16:00:20.0220 1788MSPCLOCK - ok
    16:00:20.0233 1788MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
    16:00:20.0233 1788MSPQM - ok
    16:00:20.0277 1788MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
    16:00:20.0280 1788MsRPC - ok
    16:00:20.0284 1788mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
    16:00:20.0285 1788mssmbios - ok
    16:00:20.0288 1788MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
    16:00:20.0288 1788MSTEE - ok
    16:00:20.0294 1788MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
    16:00:20.0295 1788MTConfig - ok
    16:00:20.0312 1788Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
    16:00:20.0312 1788Mup - ok
    16:00:20.0345 1788napagent (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
    16:00:20.0350 1788napagent - ok
    16:00:20.0376 1788NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
    16:00:20.0379 1788NativeWifiP - ok
     
  21. aznsaik0

    aznsaik0 TS Rookie Topic Starter

    16:00:20.0419 1788NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
    16:00:20.0427 1788NDIS - ok
    16:00:20.0450 1788NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
    16:00:20.0451 1788NdisCap - ok
    16:00:20.0469 1788NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
    16:00:20.0469 1788NdisTapi - ok
    16:00:20.0478 1788Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
    16:00:20.0479 1788Ndisuio - ok
    16:00:20.0494 1788NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
    16:00:20.0496 1788NdisWan - ok
    16:00:20.0508 1788NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
    16:00:20.0509 1788NDProxy - ok
    16:00:20.0512 1788NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
    16:00:20.0513 1788NetBIOS - ok
    16:00:20.0530 1788NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
    16:00:20.0533 1788NetBT - ok
    16:00:20.0556 1788Netlogon (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
    16:00:20.0557 1788Netlogon - ok
    16:00:20.0585 1788Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
    16:00:20.0589 1788Netman - ok
    16:00:20.0612 1788netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
    16:00:20.0617 1788netprofm - ok
    16:00:20.0671 1788NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
    16:00:20.0673 1788NetTcpPortSharing - ok
    16:00:20.0692 1788nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
    16:00:20.0693 1788nfrd960 - ok
    16:00:20.0713 1788NlaSvc (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
    16:00:20.0717 1788NlaSvc - ok
    16:00:20.0724 1788Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
    16:00:20.0725 1788Npfs - ok
    16:00:20.0735 1788nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
    16:00:20.0737 1788nsi - ok
    16:00:20.0745 1788nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
    16:00:20.0745 1788nsiproxy - ok
    16:00:20.0808 1788Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
    16:00:20.0823 1788Ntfs - ok
    16:00:20.0895 1788Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
    16:00:20.0895 1788Null - ok
    16:00:20.0941 1788NVHDA (102806b360d0e6bc6e55bf47ef655d43) C:\Windows\system32\drivers\nvhda64v.sys
    16:00:20.0941 1788NVHDA - ok
    16:00:21.0300 1788nvlddmkm (ba0b4889c40380a01ecdf84c227a89c9) C:\Windows\system32\DRIVERS\nvlddmkm.sys
    16:00:21.0357 1788nvlddmkm - ok
    16:00:21.0411 1788nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
    16:00:21.0413 1788nvraid - ok
    16:00:21.0429 1788nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
    16:00:21.0430 1788nvstor - ok
    16:00:21.0508 1788NVSvc (06633cf95bea62164c3bfca24bce6b11) C:\Windows\system32\nvvsvc.exe
    16:00:21.0516 1788NVSvc - ok
    16:00:21.0623 1788nvUpdatusService (53b629ce436b110c5689c2f6439e567b) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    16:00:21.0635 1788nvUpdatusService - ok
    16:00:21.0672 1788nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
    16:00:21.0674 1788nv_agp - ok
    16:00:21.0883 1788odserv (1f0e05dff4f5a833168e49be1256f002) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
    16:00:21.0887 1788odserv - ok
    16:00:21.0905 1788ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
    16:00:21.0906 1788ohci1394 - ok
    16:00:21.0941 1788ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
    16:00:21.0943 1788ose - ok
    16:00:21.0967 1788p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
    16:00:21.0971 1788p2pimsvc - ok
    16:00:21.0997 1788p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
    16:00:22.0002 1788p2psvc - ok
    16:00:22.0017 1788Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
    16:00:22.0018 1788Parport - ok
    16:00:22.0027 1788partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
    16:00:22.0027 1788partmgr - ok
    16:00:22.0039 1788PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
    16:00:22.0041 1788PcaSvc - ok
    16:00:22.0058 1788pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
    16:00:22.0060 1788pci - ok
    16:00:22.0068 1788pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
    16:00:22.0068 1788pciide - ok
    16:00:22.0086 1788pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
    16:00:22.0089 1788pcmcia - ok
    16:00:22.0101 1788pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
    16:00:22.0102 1788pcw - ok
    16:00:22.0126 1788PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
    16:00:22.0132 1788PEAUTH - ok
    16:00:22.0167 1788PeerDistSvc (b9b0a4299dd2d76a4243f75fd54dc680) C:\Windows\system32\peerdistsvc.dll
    16:00:22.0189 1788PeerDistSvc - ok
    16:00:22.0243 1788PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
    16:00:22.0245 1788PerfHost - ok
    16:00:22.0320 1788pla (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
    16:00:22.0333 1788pla - ok
    16:00:22.0380 1788PlugPlay (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
    16:00:22.0385 1788PlugPlay - ok
    16:00:22.0409 1788PnkBstrA - ok
    16:00:22.0429 1788PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
    16:00:22.0431 1788PNRPAutoReg - ok
    16:00:22.0448 1788PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
    16:00:22.0450 1788PNRPsvc - ok
    16:00:22.0481 1788PolicyAgent (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
    16:00:22.0486 1788PolicyAgent - ok
    16:00:22.0517 1788Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
    16:00:22.0519 1788Power - ok
    16:00:22.0564 1788PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
    16:00:22.0565 1788PptpMiniport - ok
    16:00:22.0574 1788Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
    16:00:22.0575 1788Processor - ok
    16:00:22.0593 1788ProfSvc (f381975e1f4346de875cb07339ce8d3a) C:\Windows\system32\profsvc.dll
    16:00:22.0595 1788ProfSvc - ok
    16:00:22.0608 1788ProtectedStorage (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
    16:00:22.0608 1788ProtectedStorage - ok
    16:00:22.0630 1788Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
    16:00:22.0631 1788Psched - ok
    16:00:22.0674 1788ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
    16:00:22.0688 1788ql2300 - ok
    16:00:22.0757 1788ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
    16:00:22.0758 1788ql40xx - ok
    16:00:22.0783 1788QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
    16:00:22.0786 1788QWAVE - ok
    16:00:22.0799 1788QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
    16:00:22.0800 1788QWAVEdrv - ok
    16:00:22.0806 1788RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
    16:00:22.0806 1788RasAcd - ok
    16:00:22.0828 1788RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
    16:00:22.0829 1788RasAgileVpn - ok
    16:00:22.0847 1788RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
    16:00:22.0849 1788RasAuto - ok
    16:00:22.0862 1788Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
    16:00:22.0863 1788Rasl2tp - ok
    16:00:22.0879 1788RasMan (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
    16:00:22.0883 1788RasMan - ok
    16:00:22.0894 1788RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
    16:00:22.0895 1788RasPppoe - ok
    16:00:22.0907 1788RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
    16:00:22.0908 1788RasSstp - ok
    16:00:22.0928 1788rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
    16:00:22.0931 1788rdbss - ok
    16:00:22.0934 1788rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
    16:00:22.0935 1788rdpbus - ok
    16:00:22.0948 1788RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
    16:00:22.0948 1788RDPCDD - ok
    16:00:22.0960 1788RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
    16:00:22.0961 1788RDPDR - ok
    16:00:22.0984 1788RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
    16:00:22.0984 1788RDPENCDD - ok
    16:00:22.0999 1788RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
    16:00:22.0999 1788RDPREFMP - ok
    16:00:23.0014 1788RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
    16:00:23.0016 1788RDPWD - ok
    16:00:23.0036 1788rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
    16:00:23.0038 1788rdyboost - ok
    16:00:23.0057 1788RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
    16:00:23.0059 1788RemoteAccess - ok
    16:00:23.0075 1788RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
    16:00:23.0077 1788RemoteRegistry - ok
    16:00:23.0090 1788RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
    16:00:23.0092 1788RpcEptMapper - ok
    16:00:23.0106 1788RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
    16:00:23.0107 1788RpcLocator - ok
    16:00:23.0134 1788RpcSs (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
    16:00:23.0137 1788RpcSs - ok
    16:00:23.0163 1788rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
    16:00:23.0164 1788rspndr - ok
    16:00:23.0214 1788RTL8167 (6d3c7e7d82d3dc92dc2a8b0df9f20f8a) C:\Windows\system32\DRIVERS\Rt64win7.sys
    16:00:23.0215 1788RTL8167 - ok
    16:00:23.0229 1788s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
    16:00:23.0229 1788s3cap - ok
    16:00:23.0239 1788SamSs (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
    16:00:23.0240 1788SamSs - ok
    16:00:23.0252 1788sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
    16:00:23.0253 1788sbp2port - ok
    16:00:23.0278 1788SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
    16:00:23.0281 1788SCardSvr - ok
    16:00:23.0289 1788scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
    16:00:23.0290 1788scfilter - ok
    16:00:23.0339 1788Schedule (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
    16:00:23.0350 1788Schedule - ok
    16:00:23.0372 1788SCPolicySvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
    16:00:23.0373 1788SCPolicySvc - ok
    16:00:23.0389 1788SDRSVC (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
    16:00:23.0392 1788SDRSVC - ok
    16:00:23.0417 1788secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
    16:00:23.0417 1788secdrv - ok
    16:00:23.0425 1788seclogon (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
    16:00:23.0427 1788seclogon - ok
    16:00:23.0438 1788SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\system32\sens.dll
    16:00:23.0440 1788SENS - ok
    16:00:23.0454 1788SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
    16:00:23.0455 1788SensrSvc - ok
    16:00:23.0468 1788Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
    16:00:23.0468 1788Serenum - ok
    16:00:23.0475 1788Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
    16:00:23.0476 1788Serial - ok
    16:00:23.0496 1788sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
    16:00:23.0496 1788sermouse - ok
    16:00:23.0516 1788SessionEnv (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
    16:00:23.0519 1788SessionEnv - ok
    16:00:23.0526 1788sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
    16:00:23.0526 1788sffdisk - ok
    16:00:23.0528 1788sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
    16:00:23.0529 1788sffp_mmc - ok
    16:00:23.0532 1788sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
    16:00:23.0532 1788sffp_sd - ok
    16:00:23.0536 1788sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
    16:00:23.0536 1788sfloppy - ok
    16:00:23.0570 1788SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
    16:00:23.0574 1788SharedAccess - ok
    16:00:23.0589 1788ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
    16:00:23.0593 1788ShellHWDetection - ok
    16:00:23.0615 1788SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
    16:00:23.0615 1788SiSRaid2 - ok
    16:00:23.0630 1788SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
    16:00:23.0631 1788SiSRaid4 - ok
    16:00:23.0716 1788SkypeUpdate (6128e98eaaed364ed1a32708d2fd22cb) C:\Program Files (x86)\Skype\Updater\Updater.exe
    16:00:23.0718 1788SkypeUpdate - ok
    16:00:23.0745 1788Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
    16:00:23.0746 1788Smb - ok
    16:00:23.0777 1788SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
    16:00:23.0779 1788SNMPTRAP - ok
    16:00:23.0784 1788spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
    16:00:23.0784 1788spldr - ok
    16:00:23.0822 1788Spooler (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
    16:00:23.0828 1788Spooler - ok
    16:00:23.0909 1788sppsvc (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
    16:00:23.0941 1788sppsvc - ok
    16:00:23.0994 1788sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
    16:00:23.0996 1788sppuinotify - ok
    16:00:24.0156 1788srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
    16:00:24.0160 1788srv - ok
    16:00:24.0178 1788srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
    16:00:24.0182 1788srv2 - ok
    16:00:24.0208 1788srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
    16:00:24.0210 1788srvnet - ok
    16:00:24.0232 1788SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
    16:00:24.0235 1788SSDPSRV - ok
    16:00:24.0254 1788SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
    16:00:24.0256 1788SstpSvc - ok
    16:00:24.0301 1788Steam Client Service - ok
    16:00:24.0397 1788Stereo Service (c354621b6b94e10ae7f5cdbe745feb86) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    16:00:24.0401 1788Stereo Service - ok
    16:00:24.0424 1788stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
    16:00:24.0425 1788stexstor - ok
    16:00:24.0457 1788stisvc (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
    16:00:24.0464 1788stisvc - ok
    16:00:24.0482 1788storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
    16:00:24.0482 1788storflt - ok
    16:00:24.0488 1788storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
    16:00:24.0489 1788storvsc - ok
    16:00:24.0498 1788swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
    16:00:24.0499 1788swenum - ok
    16:00:24.0523 1788swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
    16:00:24.0528 1788swprv - ok
    16:00:24.0578 1788SysMain (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
    16:00:24.0595 1788SysMain - ok
    16:00:24.0670 1788TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
    16:00:24.0673 1788TabletInputService - ok
    16:00:24.0696 1788TapiSrv (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
    16:00:24.0700 1788TapiSrv - ok
    16:00:24.0717 1788TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
    16:00:24.0718 1788TBS - ok
    16:00:24.0797 1788Tcpip (b9d87c7707f058ac652a398cd28de14b) C:\Windows\system32\drivers\tcpip.sys
    16:00:24.0814 1788Tcpip - ok
    16:00:24.0884 1788TCPIP6 (b9d87c7707f058ac652a398cd28de14b) C:\Windows\system32\DRIVERS\tcpip.sys
    16:00:24.0891 1788TCPIP6 - ok
    16:00:24.0923 1788tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
    16:00:24.0924 1788tcpipreg - ok
    16:00:24.0931 1788TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
    16:00:24.0931 1788TDPIPE - ok
    16:00:24.0951 1788TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
    16:00:24.0951 1788TDTCP - ok
    16:00:24.0966 1788tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
    16:00:24.0967 1788tdx - ok
    16:00:24.0974 1788TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
    16:00:24.0975 1788TermDD - ok
    16:00:25.0003 1788TermService (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
    16:00:25.0010 1788TermService - ok
    16:00:25.0019 1788Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
    16:00:25.0020 1788Themes - ok
    16:00:25.0046 1788THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
    16:00:25.0047 1788THREADORDER - ok
    16:00:25.0058 1788TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
    16:00:25.0060 1788TrkWks - ok
    16:00:25.0089 1788TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
    16:00:25.0091 1788TrustedInstaller - ok
    16:00:25.0105 1788tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
    16:00:25.0106 1788tssecsrv - ok
    16:00:25.0126 1788tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
    16:00:25.0128 1788tunnel - ok
    16:00:25.0140 1788uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
    16:00:25.0141 1788uagp35 - ok
    16:00:25.0162 1788udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
    16:00:25.0165 1788udfs - ok
    16:00:25.0179 1788UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
    16:00:25.0181 1788UI0Detect - ok
    16:00:25.0195 1788uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
    16:00:25.0196 1788uliagpkx - ok
    16:00:25.0226 1788umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
    16:00:25.0227 1788umbus - ok
    16:00:25.0236 1788UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
    16:00:25.0236 1788UmPass - ok
    16:00:25.0261 1788UmRdpService (af0ac98ee5077eb844413eb54287fde3) C:\Windows\System32\umrdp.dll
    16:00:25.0264 1788UmRdpService - ok
    16:00:25.0286 1788upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
    16:00:25.0291 1788upnphost - ok
    16:00:25.0331 1788USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys
    16:00:25.0332 1788USBAAPL64 - ok
    16:00:25.0367 1788usbccgp (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys
    16:00:25.0368 1788usbccgp - ok
    16:00:25.0388 1788usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
    16:00:25.0389 1788usbcir - ok
    16:00:25.0417 1788usbehci (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys
    16:00:25.0418 1788usbehci - ok
    16:00:25.0434 1788usbhub (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys
    16:00:25.0438 1788usbhub - ok
    16:00:25.0448 1788usbohci (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\DRIVERS\usbohci.sys
    16:00:25.0448 1788usbohci - ok
    16:00:25.0461 1788usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
    16:00:25.0461 1788usbprint - ok
    16:00:25.0475 1788USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS
    16:00:25.0476 1788USBSTOR - ok
    16:00:25.0502 1788usbuhci (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\drivers\usbuhci.sys
    16:00:25.0503 1788usbuhci - ok
    16:00:25.0513 1788UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
    16:00:25.0514 1788UxSms - ok
    16:00:25.0525 1788VaultSvc (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
    16:00:25.0526 1788VaultSvc - ok
    16:00:25.0539 1788vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
    16:00:25.0539 1788vdrvroot - ok
    16:00:25.0565 1788vds (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
    16:00:25.0571 1788vds - ok
    16:00:25.0583 1788vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
    16:00:25.0584 1788vga - ok
    16:00:25.0599 1788VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
    16:00:25.0600 1788VgaSave - ok
    16:00:25.0619 1788vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
    16:00:25.0622 1788vhdmp - ok
    16:00:25.0624 1788viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
    16:00:25.0625 1788viaide - ok
    16:00:25.0641 1788vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
    16:00:25.0643 1788vmbus - ok
    16:00:25.0653 1788VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
    16:00:25.0653 1788VMBusHID - ok
    16:00:25.0664 1788volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
    16:00:25.0664 1788volmgr - ok
    16:00:25.0680 1788volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
    16:00:25.0683 1788volmgrx - ok
    16:00:25.0700 1788volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
    16:00:25.0703 1788volsnap - ok
    16:00:25.0729 1788vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
    16:00:25.0731 1788vsmraid - ok
    16:00:25.0780 1788VSS (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
    16:00:25.0795 1788VSS - ok
    16:00:25.0857 1788vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
    16:00:25.0858 1788vwifibus - ok
    16:00:25.0874 1788W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
    16:00:25.0879 1788W32Time - ok
    16:00:25.0891 1788WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
    16:00:25.0892 1788WacomPen - ok
    16:00:25.0910 1788WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
    16:00:25.0911 1788WANARP - ok
    16:00:25.0913 1788Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
    16:00:25.0914 1788Wanarpv6 - ok
    16:00:25.0977 1788WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
    16:00:25.0989 1788WatAdminSvc - ok
    16:00:26.0030 1788wbengine (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
    16:00:26.0044 1788wbengine - ok
    16:00:26.0073 1788WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
    16:00:26.0077 1788WbioSrvc - ok
    16:00:26.0107 1788wcncsvc (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
    16:00:26.0111 1788wcncsvc - ok
    16:00:26.0122 1788WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
    16:00:26.0124 1788WcsPlugInService - ok
    16:00:26.0137 1788Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
    16:00:26.0138 1788Wd - ok
    16:00:26.0163 1788Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
    16:00:26.0168 1788Wdf01000 - ok
    16:00:26.0183 1788WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
    16:00:26.0185 1788WdiServiceHost - ok
    16:00:26.0187 1788WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
    16:00:26.0189 1788WdiSystemHost - ok
    16:00:26.0244 1788WebClient (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
    16:00:26.0247 1788WebClient - ok
    16:00:26.0273 1788Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
    16:00:26.0276 1788Wecsvc - ok
    16:00:26.0292 1788wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
    16:00:26.0294 1788wercplsupport - ok
    16:00:26.0308 1788WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
    16:00:26.0310 1788WerSvc - ok
    16:00:26.0323 1788WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
    16:00:26.0324 1788WfpLwf - ok
    16:00:26.0334 1788WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
    16:00:26.0334 1788WIMMount - ok
    16:00:26.0361 1788WinDefend - ok
    16:00:26.0365 1788WinHttpAutoProxySvc - ok
    16:00:26.0413 1788Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
    16:00:26.0416 1788Winmgmt - ok
    16:00:26.0479 1788WinRM (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
    16:00:26.0498 1788WinRM - ok
    16:00:26.0557 1788WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
    16:00:26.0558 1788WinUsb - ok
    16:00:26.0601 1788Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
    16:00:26.0610 1788Wlansvc - ok
    16:00:26.0623 1788WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
    16:00:26.0624 1788WmiAcpi - ok
    16:00:26.0663 1788wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
    16:00:26.0665 1788wmiApSrv - ok
    16:00:26.0685 1788WMPNetworkSvc - ok
    16:00:26.0696 1788WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
    16:00:26.0698 1788WPCSvc - ok
    16:00:26.0714 1788WPDBusEnum (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
    16:00:26.0716 1788WPDBusEnum - ok
    16:00:26.0729 1788ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
    16:00:26.0729 1788ws2ifsl - ok
    16:00:26.0753 1788wscsvc (8f9f3969933c02da96eb0f84576db43e) C:\Windows\system32\wscsvc.dll
    16:00:26.0755 1788wscsvc - ok
    16:00:26.0758 1788WSearch - ok
    16:00:26.0838 1788wuauserv (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll
    16:00:26.0860 1788wuauserv - ok
    16:00:26.0900 1788WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
    16:00:26.0901 1788WudfPf - ok
    16:00:26.0914 1788WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
    16:00:26.0916 1788WUDFRd - ok
    16:00:26.0926 1788wudfsvc (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
    16:00:26.0928 1788wudfsvc - ok
    16:00:26.0945 1788WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
    16:00:26.0949 1788WwanSvc - ok
    16:00:26.0965 1788MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
    16:00:26.0984 1788\Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected
    16:00:26.0984 1788\Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0)
    16:00:27.0012 1788Boot (0x1200) (1ca5653cd1d791d37167e8d13011c817) \Device\Harddisk0\DR0\Partition0
    16:00:27.0013 1788\Device\Harddisk0\DR0\Partition0 - ok
    16:00:27.0023 1788Boot (0x1200) (5ff3be391070404df62dbcb26e4cd7d5) \Device\Harddisk0\DR0\Partition1
    16:00:27.0024 1788\Device\Harddisk0\DR0\Partition1 - ok
    16:00:27.0024 1788============================================================
    16:00:27.0024 1788Scan finished
    16:00:27.0024 1788============================================================
    16:00:27.0031 3968Detected object count: 1
    16:00:27.0031 3968Actual detected object count: 1
    16:00:49.0748 3968\Device\Harddisk0\DR0\# - copied to quarantine
    16:00:49.0748 3968\Device\Harddisk0\DR0 - copied to quarantine
    16:00:50.0027 3968\Device\Harddisk0\DR0\TDLFS\cmd.dll - copied to quarantine
    16:00:50.0029 3968\Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine
    16:00:50.0035 3968\Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine
    16:00:50.0039 3968\Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine
    16:00:50.0040 3968\Device\Harddisk0\DR0\TDLFS\servers.dat - copied to quarantine
    16:00:50.0040 3968\Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine
    16:00:50.0041 3968\Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine
    16:00:50.0042 3968\Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine
    16:00:50.0043 3968\Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine
    16:00:50.0044 3968\Device\Harddisk0\DR0\TDLFS\s - copied to quarantine
    16:00:50.0044 3968\Device\Harddisk0\DR0\TDLFS\ldrm - copied to quarantine
    16:00:50.0045 3968\Device\Harddisk0\DR0\TDLFS\u - copied to quarantine
    16:00:50.0050 3968\Device\Harddisk0\DR0\TDLFS\ph.dll - copied to quarantine
    16:00:50.0140 3968\Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - will be cured on reboot
    16:00:50.0155 3968\Device\Harddisk0\DR0 - ok
    16:00:55.0710 3968\Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - User select action: Cure
    16:01:18.0524 3980Deinitialize success
     
  22. Broni

    Broni Malware Annihilator Posts: 52,892   +344

    Good :)

    Update MBAM, post new log.

    Next....

    • Download RogueKiller on the desktop
    • Close all the running programs
    • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • A report (RKreport.txt) should open. Post its content in your next reply. (RKreport could also be found on your desktop)
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

    ======================================

    Download aswMBR to your desktop.
    Double click the aswMBR.exe to run it.
    If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
    Click the "Scan" button to start scan.
    On completion of the scan click "Save log", save it to your desktop and post in your next reply.

    NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.
     
  23. aznsaik0

    aznsaik0 TS Rookie Topic Starter

    Malwarebytes Anti-Malware 1.62.0.1300
    www.malwarebytes.org

    Database version: v2012.07.17.15

    Windows 7 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Justin :: JUSTIN-PC [administrator]

    Protection: Enabled

    7/17/2012 5:03:27 PM
    mbam-log-2012-07-17 (17-07-19).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 239962
    Time elapsed: 2 minute(s), 48 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 1
    C:\Users\Justin\AppData\Local\Temp\.exe (Trojan.Agent) -> No action taken.

    (end)
     
  24. aznsaik0

    aznsaik0 TS Rookie Topic Starter

    RogueKiller V7.6.4 [07/17/2012] by Tigzy
    mail: tigzyRK<at>gmail<dot>com
    Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Blog: http://tigzyrk.blogspot.com
    Operating System: Windows 7 (6.1.7600 ) 64 bits version
    Started in : Normal mode
    User: Justin [Admin rights]
    Mode: Scan -- Date: 07/17/2012 17:08:25
    ¤¤¤ Bad processes: 0 ¤¤¤
    ¤¤¤ Registry Entries: 5 ¤¤¤
    [SUSP PATH] RunAsStdUser Task.job @ : C:\Users\Justin\AppData\Local\cheerychickenSA\bin\1.0.7.0\CheeryChickenSA.exe -> FOUND
    [HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
    [HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
    [HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
    [HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
    ¤¤¤ Particular Files / Folders: ¤¤¤
    ¤¤¤ Driver: [NOT LOADED] ¤¤¤
    ¤¤¤ Infection : ¤¤¤
    ¤¤¤ HOSTS File: ¤¤¤
    127.0.0.1 localhost
    127.0.0.1www.007guard.com
    127.0.0.1007guard.com
    127.0.0.1008i.com
    127.0.0.1www.008k.com
    127.0.0.1008k.com
    127.0.0.1www.00hq.com
    127.0.0.100hq.com
    127.0.0.1010402.com
    127.0.0.1www.032439.com
    127.0.0.1032439.com
    127.0.0.1www.0scan.com
    127.0.0.10scan.com
    127.0.0.11000gratisproben.com
    127.0.0.1www.1000gratisproben.com
    127.0.0.11001namen.com
    127.0.0.1www.1001namen.com
    127.0.0.1www.100888290cs.com
    127.0.0.1100888290cs.com
    127.0.0.1100sexlinks.com
    [...]
    ¤¤¤ MBR Check: ¤¤¤
    +++++ PhysicalDrive0: SAMSUNG HD103SJ ATA Device +++++
    --- User ---
    [MBR] 78f33fdd9332190a16726ff0f4328421
    [BSP] 95d42fcc6c073633fa29b11d35047033 : Windows 7 MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
    1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 953767 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!
    Finished : << RKreport[1].txt >>
    RKreport[1].txt
     
  25. aznsaik0

    aznsaik0 TS Rookie Topic Starter

    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-07-17 17:09:41
    -----------------------------
    17:09:41.522 OS Version: Windows x64 6.1.7600
    17:09:41.522 Number of processors: 6 586 0xA00
    17:09:41.523 ComputerName: JUSTIN-PC UserName: Justin
    17:09:42.254 Initialize success
    17:10:22.383 AVAST engine defs: 12071701
    17:10:30.653 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
    17:10:30.654 Disk 0 Vendor: SAMSUNG_HD103SJ 1AJ10001 Size: 953869MB BusType: 3
    17:10:30.666 Disk 0 MBR read successfully
    17:10:30.667 Disk 0 MBR scan
    17:10:30.669 Disk 0 Windows 7 default MBR code
    17:10:30.690 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
    17:10:30.735 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848
    17:10:30.774 Disk 0 scanning C:\Windows\system32\drivers
    17:10:35.869 Service scanning
    17:10:48.078 Modules scanning
    17:10:48.082 Disk 0 trace - called modules:
    17:10:48.097 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
    17:10:48.099 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007b09060]
    17:10:48.425 3 CLASSPNP.SYS[fffff8800100143f] -> nt!IofCallDriver -> [0xfffffa800785a580]
    17:10:48.428 5 ACPI.sys[fffff88000f21781] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800783c060]
    17:10:49.190 AVAST engine scan C:\Windows
    17:10:51.566 AVAST engine scan C:\Windows\system32
    17:12:45.659 AVAST engine scan C:\Windows\system32\drivers
    17:12:51.760 AVAST engine scan C:\Users\Justin
    17:13:32.097 Disk 0 MBR has been saved successfully to "C:\Users\Justin\Desktop\MBR.dat"
    17:13:32.101 The log file has been saved successfully to "C:\Users\Justin\Desktop\aswMBR.txt"
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...