Hi,
I started noticing that google chrome would not load any websites, but firefox would. Also noticed that when I clicked on links after I searched on google, it would sometimes redirect me to a different webpage.
GMER did not find anything, so here are the other logs.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 5214
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
29/11/2010 11:44:25 AM
mbam-log-2010-11-29 (11-44-25).txt
Scan type: Quick scan
Objects scanned: 138269
Time elapsed: 3 minute(s), 29 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 9
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
C:\Windows\KMService.exe (RiskWare.Tool.CK) -> Unloaded process successfully.
Memory Modules Infected:
C:\Windows\$NtUninstallMTF197$\habhu.dll (Trojan.BHO) -> Delete on reboot.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{62b6849d-7425-4e9d-abfc-0995a3732355} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{fba8455b-efb2-4e02-91d8-19fca8ef3cc9} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{fba8455b-efb2-4e02-91d8-19fca8ef3cc9} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{fba8455b-efb2-4e02-91d8-19fca8ef3cc9} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fba8455b-efb2-4e02-91d8-19fca8ef3cc9} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Street-Ads (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e3c47a8a-fde2-4a01-a778-86d9c3b3052d} (Adware.AdRotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e3c47a8a-fde2-4a01-a778-86d9c3b3052d} (Adware.AdRotator) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bipro (Trojan.BHO) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Windows\KMService.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
C:\Windows\$NtUninstallMTF197$\habhu.dll (Trojan.BHO) -> Delete on reboot.
C:\Windows\$NtUninstallMTF197$\htlgv.dll (Adware.AdRotator) -> Delete on reboot.
DDS (Ver_10-11-27.01) - NTFS_AMD64
Run by Black at 12:05:34.65 on 29/11/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_22
Microsoft Windows 7 Professional 6.1.7600.0.1252.2.1033.18.1791.959 [GMT -5:00]
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe
C:\Windows\system32\notepad.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Black\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Google Update] "C:\Users\Black\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [gchk] C:\Windows\$NtUninstallMTF197$\upg.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
mRun-x64: [MSSE] "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
mRun-x64: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
================= FIREFOX ===================
FF - ProfilePath - C:\Users\Black\AppData\Roaming\Mozilla\Firefox\Profiles\ngapt9h6.default\
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Users\Black\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2010-3-25 173984]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-10-27 203776]
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2010-10-27 8012288]
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2010-10-27 287232]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\System32\drivers\MpNWMon.sys [2010-3-25 40832]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 KMService;KMService;C:\Windows\system32\srvany.exe --> C:\Windows\system32\srvany.exe [?]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-6-23 344680]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-11-19 1255736]
=============== Created Last 30 ================
2010-11-29 17:04:22 8199504 ----a-w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{31FE46D6-161F-475A-8A75-EAD6FBCAE944}\mpengine.dll
2010-11-29 16:39:58 -------- d-----w- C:\Users\Black\AppData\Roaming\Malwarebytes
2010-11-29 16:39:49 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2010-11-29 16:39:47 24664 ----a-w- C:\Windows\System32\drivers\mbam.sys
2010-11-29 16:39:47 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2010-11-29 16:39:47 -------- d-----w- C:\PROGRA~3\Malwarebytes
2010-11-24 14:11:37 7680 ----a-w- C:\Program Files\Internet Explorer\iecompat.dll
2010-11-24 14:11:37 7680 ----a-w- C:\Program Files (x86)\Internet Explorer\iecompat.dll
2010-11-20 14:01:41 311808 ----a-w- C:\Windows\System32\msv1_0.dll
2010-11-20 14:01:41 257024 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2010-11-19 16:31:00 -------- d-----w- C:\Users\Black\AppData\Local\Apps
2010-11-19 16:28:42 -------- d-----w- C:\Users\Black\AppData\Roaming\SPlayer
2010-11-19 16:28:30 -------- d-----w- C:\Program Files (x86)\SPlayer
2010-11-19 16:24:10 -------- d-----w- C:\Users\Black\AppData\Roaming\foobar2000
2010-11-19 16:23:59 -------- d-----w- C:\Program Files (x86)\foobar2000
2010-11-19 15:45:40 -------- d-----w- C:\Windows\SysWow64\Wat
2010-11-19 15:45:40 -------- d-----w- C:\Windows\System32\Wat
2010-11-19 15:32:57 8199504 ----a-w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2010-11-19 15:20:30 14336 ----a-w- C:\Windows\System32\drivers\sffp_sd.sys
2010-11-19 15:17:32 99176 ----a-w- C:\Windows\SysWow64\PresentationHostProxy.dll
2010-11-19 15:17:32 297808 ----a-w- C:\Windows\SysWow64\mscoree.dll
2010-11-19 15:17:32 295264 ----a-w- C:\Windows\SysWow64\PresentationHost.exe
2010-11-19 15:17:31 49472 ----a-w- C:\Windows\SysWow64\netfxperf.dll
2010-11-19 15:17:31 48960 ----a-w- C:\Windows\System32\netfxperf.dll
2010-11-19 15:17:31 444752 ----a-w- C:\Windows\System32\mscoree.dll
2010-11-19 15:17:31 320352 ----a-w- C:\Windows\System32\PresentationHost.exe
2010-11-19 15:17:31 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2010-11-19 15:17:31 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2010-11-19 15:17:31 109912 ----a-w- C:\Windows\System32\PresentationHostProxy.dll
2010-11-19 15:08:59 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2010-11-19 15:08:59 472808 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2010-11-19 15:05:26 469256 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\31c8810e1cb87fb30\InstallManager_WLE_WLE.exe
2010-11-19 15:03:45 15712 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\f60596a81cb87fa25\MeshBetaRemover.exe
2010-11-19 15:02:32 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\ca4e32f41cb87fa1d\DSETUP.dll
2010-11-19 15:02:32 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\ca4e32f41cb87fa1d\DXSETUP.exe
2010-11-19 15:02:32 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\ca4e32f41cb87fa1d\dsetup32.dll
2010-11-19 15:02:25 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\c640d3d11cb87fa1c\DSETUP.dll
2010-11-19 15:02:25 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\c640d3d11cb87fa1c\DXSETUP.exe
2010-11-19 15:02:25 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\c640d3d11cb87fa1c\dsetup32.dll
2010-11-19 15:00:36 6260088 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\84bab8e81cb87fa10\Silverlight.4.0.exe
2010-11-19 14:58:36 -------- d-----w- C:\Users\Black\AppData\Local\Windows Live
2010-11-19 14:58:35 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2010-11-19 14:58:03 257024 ----a-w- C:\Windows\System32\mfreadwrite.dll
2010-11-19 14:58:03 206848 ----a-w- C:\Windows\System32\mfps.dll
2010-11-19 14:58:03 196608 ----a-w- C:\Windows\SysWow64\mfreadwrite.dll
2010-11-19 14:58:02 4068864 ----a-w- C:\Windows\System32\mf.dll
2010-11-19 14:58:02 1888256 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2010-11-19 14:58:02 1619456 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2010-11-19 14:58:01 3181568 ----a-w- C:\Windows\SysWow64\mf.dll
2010-11-19 14:56:33 243712 ----a-w- C:\Windows\System32\drivers\ks.sys
2010-11-19 14:51:39 85936 ----a-w- C:\Windows\System32\drivers\scdemu.sys
2010-11-19 14:51:39 -------- d-----w- C:\Program Files (x86)\PowerISO
2010-11-19 14:44:30 -------- d-----w- C:\Program Files (x86)\VS Revo Group
2010-11-19 14:34:59 861184 ----a-w- C:\Windows\System32\oleaut32.dll
2010-11-19 14:34:59 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2010-11-19 14:34:58 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2010-11-19 14:34:58 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2010-11-19 14:34:58 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2010-11-19 14:34:58 243200 ----a-w- C:\Windows\System32\wow64.dll
2010-11-19 14:34:58 2048 ----a-w- C:\Windows\SysWow64\user.exe
2010-11-19 14:34:58 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2010-11-19 14:34:12 223448 ----a-w- C:\Windows\System32\drivers\fvevol.sys
2010-11-19 14:34:09 27008 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2010-11-19 14:31:05 8192 ----a-w- C:\Windows\SysWow64\srvany.exe
2010-11-19 14:20:07 -------- d-----w- C:\Program Files\Microsoft Synchronization Services
2010-11-19 14:17:31 558592 ----a-w- C:\Windows\System32\spoolsv.exe
2010-11-19 14:17:29 286720 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2010-11-19 14:17:29 157696 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2010-11-19 14:17:29 125952 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2010-11-19 14:17:25 82944 ----a-w- C:\Windows\SysWow64\iccvid.dll
2010-11-19 14:17:24 982600 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2010-11-19 14:17:24 144384 ----a-w- C:\Windows\System32\cdd.dll
2010-11-19 14:17:07 1024512 ----a-w- C:\Windows\System32\wmpmde.dll
2010-11-19 14:17:06 738816 ----a-w- C:\Windows\SysWow64\wmpmde.dll
2010-11-19 14:15:58 -------- d-----w- C:\Users\Black\AppData\Local\Microsoft Help
2010-11-19 14:08:33 -------- d-----w- C:\Users\Black\AppData\Local\Google
2010-11-19 14:07:43 -------- d-----w- C:\Users\Black\AppData\Local\Mozilla
2010-11-19 02:52:50 270720 ------w- C:\Windows\System32\MpSigStub.exe
2010-11-19 02:48:23 -------- d-----w- C:\Program Files (x86)\Microsoft Antimalware
2010-11-19 02:47:48 -------- d-sh--w- C:\Windows\Installer
2010-11-19 02:45:43 220672 ----a-w- C:\Windows\System32\wintrust.dll
2010-11-19 02:45:43 172032 ----a-w- C:\Windows\SysWow64\wintrust.dll
2010-11-19 02:45:42 139264 ----a-w- C:\Windows\System32\cabview.dll
2010-11-19 02:45:42 132608 ----a-w- C:\Windows\SysWow64\cabview.dll
2010-11-19 02:45:23 -------- d-----w- C:\Program Files\CCleaner
2010-11-19 02:43:27 -------- d-----w- C:\Windows\Panther
2010-11-19 02:28:32 -------- d-----w- C:\Program Files\Microsoft Security Essentials
2010-11-19 02:23:16 -------- d-----w- C:\Program Files (x86)\VideoLAN
2010-11-19 02:22:29 -------- d-----w- C:\Users\Black\AppData\Roaming\Dropbox
2010-11-19 02:21:25 -------- d-----w- C:\Users\Black\AppData\Roaming\uTorrent
2010-11-18 23:56:16 -------- d-----w- C:\Users\Black\AppData\Local\Diagnostics
2010-11-18 23:45:43 0 ----a-w- C:\Windows\ativpsrm.bin
2010-11-10 17:49:36 135568 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
==================== Find3M ====================
2010-10-27 09:00:16 8012288 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
2010-10-27 08:25:38 21422592 ----a-w- C:\Windows\System32\atio6axx.dll
2010-10-27 08:08:18 16281600 ----a-w- C:\Windows\SysWow64\atioglxx.dll
2010-10-27 07:55:32 143360 ----a-w- C:\Windows\System32\atiapfxx.exe
2010-10-27 07:55:24 547328 ----a-w- C:\Windows\SysWow64\aticfx32.dll
2010-10-27 07:54:24 645120 ----a-w- C:\Windows\System32\aticfx64.dll
2010-10-27 07:52:18 450560 ----a-w- C:\Windows\System32\ATIDEMGX.dll
2010-10-27 07:52:14 478208 ----a-w- C:\Windows\System32\atieclxx.exe
2010-10-27 07:51:38 203776 ----a-w- C:\Windows\System32\atiesrxx.exe
2010-10-27 07:50:30 120320 ----a-w- C:\Windows\System32\atitmm64.dll
2010-10-27 07:50:16 423424 ----a-w- C:\Windows\System32\atipdl64.dll
2010-10-27 07:50:10 356352 ----a-w- C:\Windows\SysWow64\atipdlxx.dll
2010-10-27 07:49:58 278528 ----a-w- C:\Windows\SysWow64\Oemdspif.dll
2010-10-27 07:49:54 16384 ----a-w- C:\Windows\System32\atimuixx.dll
2010-10-27 07:49:50 59392 ----a-w- C:\Windows\System32\atiedu64.dll
2010-10-27 07:49:46 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2010-10-27 07:46:58 4020736 ----a-w- C:\Windows\SysWow64\atidxx32.dll
2010-10-27 07:38:04 4744704 ----a-w- C:\Windows\System32\atidxx64.dll
2010-10-27 07:35:30 51200 ----a-w- C:\Windows\System32\aticalrt64.dll
2010-10-27 07:35:28 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
2010-10-27 07:35:20 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
2010-10-27 07:35:18 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll
2010-10-27 07:35:08 6815744 ----a-w- C:\Windows\System32\aticaldd64.dll
2010-10-27 07:33:52 5441536 ----a-w- C:\Windows\SysWow64\aticaldd.dll
2010-10-27 07:28:22 4094464 ----a-w- C:\Windows\SysWow64\atiumdag.dll
2010-10-27 07:22:04 5218304 ----a-w- C:\Windows\System32\atiumd64.dll
2010-10-27 07:15:00 58880 ----a-w- C:\Windows\System32\coinst.dll
2010-10-27 07:14:58 349184 ----a-w- C:\Windows\System32\atiadlxx.dll
2010-10-27 07:14:52 249856 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
2010-10-27 07:14:44 14848 ----a-w- C:\Windows\System32\atig6pxx.dll
2010-10-27 07:14:42 12800 ----a-w- C:\Windows\SysWow64\atiglpxx.dll
2010-10-27 07:14:42 12800 ----a-w- C:\Windows\System32\atiglpxx.dll
2010-10-27 07:14:38 31744 ----a-w- C:\Windows\System32\atig6txx.dll
2010-10-27 07:14:32 27136 ----a-w- C:\Windows\SysWow64\atigktxx.dll
2010-10-27 07:14:24 287232 ----a-w- C:\Windows\System32\drivers\atikmpag.sys
2010-10-27 07:13:44 39936 ----a-w- C:\Windows\System32\atiuxp64.dll
2010-10-27 07:13:36 30720 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
2010-10-27 07:13:30 37888 ----a-w- C:\Windows\System32\atiu9p64.dll
2010-10-27 07:13:24 28672 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
2010-10-27 07:12:56 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
2010-10-27 06:57:04 3221504 ----a-w- C:\Windows\System32\atiumd6a.dll
2010-10-27 06:50:10 3460096 ----a-w- C:\Windows\SysWow64\atiumdva.dll
2010-10-27 06:37:18 53760 ----a-w- C:\Windows\System32\atimpc64.dll
2010-10-27 06:37:18 53760 ----a-w- C:\Windows\System32\amdpcom64.dll
2010-10-27 06:37:14 52736 ----a-w- C:\Windows\SysWow64\atimpc32.dll
2010-10-27 06:37:14 52736 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
2010-09-21 19:49:02 252800 ----a-w- C:\Windows\System32\LIVESSP.DLL
2010-09-21 19:03:14 208768 ----a-w- C:\Windows\SysWow64\LIVESSP.DLL
2010-09-10 05:35:44 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2010-09-10 05:35:43 347648 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2010-09-08 05:36:17 1192960 ----a-w- C:\Windows\System32\wininet.dll
2010-09-08 05:34:34 57856 ----a-w- C:\Windows\System32\licmgr10.dll
2010-09-08 04:30:04 978432 ----a-w- C:\Windows\SysWow64\wininet.dll
2010-09-08 04:28:15 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll
2010-09-08 04:16:38 482816 ----a-w- C:\Windows\System32\html.iec
2010-09-08 03:35:30 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2010-09-08 03:22:31 386048 ----a-w- C:\Windows\SysWow64\html.iec
2010-09-08 02:48:16 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2010-09-01 05:12:09 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2010-09-01 04:23:49 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2010-09-01 02:58:34 3123712 ----a-w- C:\Windows\System32\win32k.sys
============= FINISH: 12:06:11.73 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-11-27.01)
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 18/11/2010 6:54:34 PM
System Uptime: 29/11/2010 11:45:18 AM (1 hours ago)
Motherboard: ASUSTeK Computer INC. | | M3A78-EM
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 5400+ | AM2 | 2800/200mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 74 GiB total, 53.074 GiB free.
D: is CDROM ()
E: is CDROM ()
==== Disabled Device Manager Items =============
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Realtek PCIe GBE Family Controller
Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_816810EC&REV_02\4&17AA8702&0&0030
Manufacturer: Realtek
Name: Realtek PCIe GBE Family Controller
PNP Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_816810EC&REV_02\4&17AA8702&0&0030
Service: RTL8167
==== System Restore Points ===================
RP13: 24/11/2010 9:52:36 AM - Windows Update
RP14: 25/11/2010 9:30:24 AM - Windows Update
RP15: 26/11/2010 10:24:00 AM - Revo Uninstaller's restore point - Google Chrome
RP16: 26/11/2010 10:44:02 AM - Windows Update
RP17: 26/11/2010 10:49:20 AM - Restore Operation
RP18: 26/11/2010 11:02:49 AM - Windows Update
RP19: 27/11/2010 5:42:25 PM - Windows Update
RP20: 28/11/2010 8:43:56 PM - Windows Update
==== Installed Programs ======================
Adobe Flash Player 10 Plugin
Adobe Reader X
foobar2000 v1.1.1
Google Chrome
Java Auto Updater
Java(TM) 6 Update 22
Malwarebytes' Anti-Malware
Microsoft Silverlight
Mozilla Firefox (3.6.12)
PowerISO
Revo Uninstaller 1.90
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
SPlayer
Street-Ads Browser Enhancer
==== Event Viewer Messages From Past Week ========
29/11/2010 11:45:40 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
29/11/2010 11:45:27 AM, Error: RTL8167 [5008] - Realtek PCIe GBE Family Controller : Has encountered an invalid network address.
29/11/2010 11:37:54 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
29/11/2010 11:36:28 AM, Error: Service Control Manager [7031] - The KMService service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
28/11/2010 8:33:41 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
28/11/2010 8:33:37 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff88006768910, 0x0000000000000000, 0xfffff8000287f6a6, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 112810-18330-01.
26/11/2010 11:07:56 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
26/11/2010 11:07:56 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Computer Browser service, but this action failed with the following error: An instance of the service is already running.
26/11/2010 11:06:57 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Server service, but this action failed with the following error: An instance of the service is already running.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7034] - The Application Information service terminated unexpectedly. It has done this 1 time(s).
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Windows Update service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The System Event Notification Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The IP Helper service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Group Policy Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Computer Browser service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Background Intelligent Transfer Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Application Experience service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
26/11/2010 10:52:37 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
26/11/2010 10:23:07 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
26/11/2010 10:12:01 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
26/11/2010 10:10:00 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
==== End Of File ===========================
Thanks in advance.
I started noticing that google chrome would not load any websites, but firefox would. Also noticed that when I clicked on links after I searched on google, it would sometimes redirect me to a different webpage.
GMER did not find anything, so here are the other logs.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 5214
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
29/11/2010 11:44:25 AM
mbam-log-2010-11-29 (11-44-25).txt
Scan type: Quick scan
Objects scanned: 138269
Time elapsed: 3 minute(s), 29 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 9
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
C:\Windows\KMService.exe (RiskWare.Tool.CK) -> Unloaded process successfully.
Memory Modules Infected:
C:\Windows\$NtUninstallMTF197$\habhu.dll (Trojan.BHO) -> Delete on reboot.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{62b6849d-7425-4e9d-abfc-0995a3732355} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{fba8455b-efb2-4e02-91d8-19fca8ef3cc9} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{fba8455b-efb2-4e02-91d8-19fca8ef3cc9} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{fba8455b-efb2-4e02-91d8-19fca8ef3cc9} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fba8455b-efb2-4e02-91d8-19fca8ef3cc9} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Street-Ads (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e3c47a8a-fde2-4a01-a778-86d9c3b3052d} (Adware.AdRotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e3c47a8a-fde2-4a01-a778-86d9c3b3052d} (Adware.AdRotator) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bipro (Trojan.BHO) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Windows\KMService.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
C:\Windows\$NtUninstallMTF197$\habhu.dll (Trojan.BHO) -> Delete on reboot.
C:\Windows\$NtUninstallMTF197$\htlgv.dll (Adware.AdRotator) -> Delete on reboot.
DDS (Ver_10-11-27.01) - NTFS_AMD64
Run by Black at 12:05:34.65 on 29/11/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_22
Microsoft Windows 7 Professional 6.1.7600.0.1252.2.1033.18.1791.959 [GMT -5:00]
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe
C:\Windows\system32\notepad.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Black\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Google Update] "C:\Users\Black\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [gchk] C:\Windows\$NtUninstallMTF197$\upg.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
mRun-x64: [MSSE] "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
mRun-x64: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
================= FIREFOX ===================
FF - ProfilePath - C:\Users\Black\AppData\Roaming\Mozilla\Firefox\Profiles\ngapt9h6.default\
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Users\Black\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2010-3-25 173984]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-10-27 203776]
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2010-10-27 8012288]
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2010-10-27 287232]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\System32\drivers\MpNWMon.sys [2010-3-25 40832]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 KMService;KMService;C:\Windows\system32\srvany.exe --> C:\Windows\system32\srvany.exe [?]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-6-23 344680]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-11-19 1255736]
=============== Created Last 30 ================
2010-11-29 17:04:22 8199504 ----a-w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\{31FE46D6-161F-475A-8A75-EAD6FBCAE944}\mpengine.dll
2010-11-29 16:39:58 -------- d-----w- C:\Users\Black\AppData\Roaming\Malwarebytes
2010-11-29 16:39:49 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2010-11-29 16:39:47 24664 ----a-w- C:\Windows\System32\drivers\mbam.sys
2010-11-29 16:39:47 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2010-11-29 16:39:47 -------- d-----w- C:\PROGRA~3\Malwarebytes
2010-11-24 14:11:37 7680 ----a-w- C:\Program Files\Internet Explorer\iecompat.dll
2010-11-24 14:11:37 7680 ----a-w- C:\Program Files (x86)\Internet Explorer\iecompat.dll
2010-11-20 14:01:41 311808 ----a-w- C:\Windows\System32\msv1_0.dll
2010-11-20 14:01:41 257024 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2010-11-19 16:31:00 -------- d-----w- C:\Users\Black\AppData\Local\Apps
2010-11-19 16:28:42 -------- d-----w- C:\Users\Black\AppData\Roaming\SPlayer
2010-11-19 16:28:30 -------- d-----w- C:\Program Files (x86)\SPlayer
2010-11-19 16:24:10 -------- d-----w- C:\Users\Black\AppData\Roaming\foobar2000
2010-11-19 16:23:59 -------- d-----w- C:\Program Files (x86)\foobar2000
2010-11-19 15:45:40 -------- d-----w- C:\Windows\SysWow64\Wat
2010-11-19 15:45:40 -------- d-----w- C:\Windows\System32\Wat
2010-11-19 15:32:57 8199504 ----a-w- C:\PROGRA~3\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2010-11-19 15:20:30 14336 ----a-w- C:\Windows\System32\drivers\sffp_sd.sys
2010-11-19 15:17:32 99176 ----a-w- C:\Windows\SysWow64\PresentationHostProxy.dll
2010-11-19 15:17:32 297808 ----a-w- C:\Windows\SysWow64\mscoree.dll
2010-11-19 15:17:32 295264 ----a-w- C:\Windows\SysWow64\PresentationHost.exe
2010-11-19 15:17:31 49472 ----a-w- C:\Windows\SysWow64\netfxperf.dll
2010-11-19 15:17:31 48960 ----a-w- C:\Windows\System32\netfxperf.dll
2010-11-19 15:17:31 444752 ----a-w- C:\Windows\System32\mscoree.dll
2010-11-19 15:17:31 320352 ----a-w- C:\Windows\System32\PresentationHost.exe
2010-11-19 15:17:31 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2010-11-19 15:17:31 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2010-11-19 15:17:31 109912 ----a-w- C:\Windows\System32\PresentationHostProxy.dll
2010-11-19 15:08:59 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2010-11-19 15:08:59 472808 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
2010-11-19 15:05:26 469256 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\31c8810e1cb87fb30\InstallManager_WLE_WLE.exe
2010-11-19 15:03:45 15712 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\f60596a81cb87fa25\MeshBetaRemover.exe
2010-11-19 15:02:32 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\ca4e32f41cb87fa1d\DSETUP.dll
2010-11-19 15:02:32 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\ca4e32f41cb87fa1d\DXSETUP.exe
2010-11-19 15:02:32 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\ca4e32f41cb87fa1d\dsetup32.dll
2010-11-19 15:02:25 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\c640d3d11cb87fa1c\DSETUP.dll
2010-11-19 15:02:25 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\c640d3d11cb87fa1c\DXSETUP.exe
2010-11-19 15:02:25 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\c640d3d11cb87fa1c\dsetup32.dll
2010-11-19 15:00:36 6260088 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\84bab8e81cb87fa10\Silverlight.4.0.exe
2010-11-19 14:58:36 -------- d-----w- C:\Users\Black\AppData\Local\Windows Live
2010-11-19 14:58:35 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2010-11-19 14:58:03 257024 ----a-w- C:\Windows\System32\mfreadwrite.dll
2010-11-19 14:58:03 206848 ----a-w- C:\Windows\System32\mfps.dll
2010-11-19 14:58:03 196608 ----a-w- C:\Windows\SysWow64\mfreadwrite.dll
2010-11-19 14:58:02 4068864 ----a-w- C:\Windows\System32\mf.dll
2010-11-19 14:58:02 1888256 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2010-11-19 14:58:02 1619456 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2010-11-19 14:58:01 3181568 ----a-w- C:\Windows\SysWow64\mf.dll
2010-11-19 14:56:33 243712 ----a-w- C:\Windows\System32\drivers\ks.sys
2010-11-19 14:51:39 85936 ----a-w- C:\Windows\System32\drivers\scdemu.sys
2010-11-19 14:51:39 -------- d-----w- C:\Program Files (x86)\PowerISO
2010-11-19 14:44:30 -------- d-----w- C:\Program Files (x86)\VS Revo Group
2010-11-19 14:34:59 861184 ----a-w- C:\Windows\System32\oleaut32.dll
2010-11-19 14:34:59 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2010-11-19 14:34:58 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2010-11-19 14:34:58 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2010-11-19 14:34:58 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2010-11-19 14:34:58 243200 ----a-w- C:\Windows\System32\wow64.dll
2010-11-19 14:34:58 2048 ----a-w- C:\Windows\SysWow64\user.exe
2010-11-19 14:34:58 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2010-11-19 14:34:12 223448 ----a-w- C:\Windows\System32\drivers\fvevol.sys
2010-11-19 14:34:09 27008 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2010-11-19 14:31:05 8192 ----a-w- C:\Windows\SysWow64\srvany.exe
2010-11-19 14:20:07 -------- d-----w- C:\Program Files\Microsoft Synchronization Services
2010-11-19 14:17:31 558592 ----a-w- C:\Windows\System32\spoolsv.exe
2010-11-19 14:17:29 286720 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2010-11-19 14:17:29 157696 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2010-11-19 14:17:29 125952 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2010-11-19 14:17:25 82944 ----a-w- C:\Windows\SysWow64\iccvid.dll
2010-11-19 14:17:24 982600 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2010-11-19 14:17:24 144384 ----a-w- C:\Windows\System32\cdd.dll
2010-11-19 14:17:07 1024512 ----a-w- C:\Windows\System32\wmpmde.dll
2010-11-19 14:17:06 738816 ----a-w- C:\Windows\SysWow64\wmpmde.dll
2010-11-19 14:15:58 -------- d-----w- C:\Users\Black\AppData\Local\Microsoft Help
2010-11-19 14:08:33 -------- d-----w- C:\Users\Black\AppData\Local\Google
2010-11-19 14:07:43 -------- d-----w- C:\Users\Black\AppData\Local\Mozilla
2010-11-19 02:52:50 270720 ------w- C:\Windows\System32\MpSigStub.exe
2010-11-19 02:48:23 -------- d-----w- C:\Program Files (x86)\Microsoft Antimalware
2010-11-19 02:47:48 -------- d-sh--w- C:\Windows\Installer
2010-11-19 02:45:43 220672 ----a-w- C:\Windows\System32\wintrust.dll
2010-11-19 02:45:43 172032 ----a-w- C:\Windows\SysWow64\wintrust.dll
2010-11-19 02:45:42 139264 ----a-w- C:\Windows\System32\cabview.dll
2010-11-19 02:45:42 132608 ----a-w- C:\Windows\SysWow64\cabview.dll
2010-11-19 02:45:23 -------- d-----w- C:\Program Files\CCleaner
2010-11-19 02:43:27 -------- d-----w- C:\Windows\Panther
2010-11-19 02:28:32 -------- d-----w- C:\Program Files\Microsoft Security Essentials
2010-11-19 02:23:16 -------- d-----w- C:\Program Files (x86)\VideoLAN
2010-11-19 02:22:29 -------- d-----w- C:\Users\Black\AppData\Roaming\Dropbox
2010-11-19 02:21:25 -------- d-----w- C:\Users\Black\AppData\Roaming\uTorrent
2010-11-18 23:56:16 -------- d-----w- C:\Users\Black\AppData\Local\Diagnostics
2010-11-18 23:45:43 0 ----a-w- C:\Windows\ativpsrm.bin
2010-11-10 17:49:36 135568 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
==================== Find3M ====================
2010-10-27 09:00:16 8012288 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
2010-10-27 08:25:38 21422592 ----a-w- C:\Windows\System32\atio6axx.dll
2010-10-27 08:08:18 16281600 ----a-w- C:\Windows\SysWow64\atioglxx.dll
2010-10-27 07:55:32 143360 ----a-w- C:\Windows\System32\atiapfxx.exe
2010-10-27 07:55:24 547328 ----a-w- C:\Windows\SysWow64\aticfx32.dll
2010-10-27 07:54:24 645120 ----a-w- C:\Windows\System32\aticfx64.dll
2010-10-27 07:52:18 450560 ----a-w- C:\Windows\System32\ATIDEMGX.dll
2010-10-27 07:52:14 478208 ----a-w- C:\Windows\System32\atieclxx.exe
2010-10-27 07:51:38 203776 ----a-w- C:\Windows\System32\atiesrxx.exe
2010-10-27 07:50:30 120320 ----a-w- C:\Windows\System32\atitmm64.dll
2010-10-27 07:50:16 423424 ----a-w- C:\Windows\System32\atipdl64.dll
2010-10-27 07:50:10 356352 ----a-w- C:\Windows\SysWow64\atipdlxx.dll
2010-10-27 07:49:58 278528 ----a-w- C:\Windows\SysWow64\Oemdspif.dll
2010-10-27 07:49:54 16384 ----a-w- C:\Windows\System32\atimuixx.dll
2010-10-27 07:49:50 59392 ----a-w- C:\Windows\System32\atiedu64.dll
2010-10-27 07:49:46 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2010-10-27 07:46:58 4020736 ----a-w- C:\Windows\SysWow64\atidxx32.dll
2010-10-27 07:38:04 4744704 ----a-w- C:\Windows\System32\atidxx64.dll
2010-10-27 07:35:30 51200 ----a-w- C:\Windows\System32\aticalrt64.dll
2010-10-27 07:35:28 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
2010-10-27 07:35:20 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
2010-10-27 07:35:18 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll
2010-10-27 07:35:08 6815744 ----a-w- C:\Windows\System32\aticaldd64.dll
2010-10-27 07:33:52 5441536 ----a-w- C:\Windows\SysWow64\aticaldd.dll
2010-10-27 07:28:22 4094464 ----a-w- C:\Windows\SysWow64\atiumdag.dll
2010-10-27 07:22:04 5218304 ----a-w- C:\Windows\System32\atiumd64.dll
2010-10-27 07:15:00 58880 ----a-w- C:\Windows\System32\coinst.dll
2010-10-27 07:14:58 349184 ----a-w- C:\Windows\System32\atiadlxx.dll
2010-10-27 07:14:52 249856 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
2010-10-27 07:14:44 14848 ----a-w- C:\Windows\System32\atig6pxx.dll
2010-10-27 07:14:42 12800 ----a-w- C:\Windows\SysWow64\atiglpxx.dll
2010-10-27 07:14:42 12800 ----a-w- C:\Windows\System32\atiglpxx.dll
2010-10-27 07:14:38 31744 ----a-w- C:\Windows\System32\atig6txx.dll
2010-10-27 07:14:32 27136 ----a-w- C:\Windows\SysWow64\atigktxx.dll
2010-10-27 07:14:24 287232 ----a-w- C:\Windows\System32\drivers\atikmpag.sys
2010-10-27 07:13:44 39936 ----a-w- C:\Windows\System32\atiuxp64.dll
2010-10-27 07:13:36 30720 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
2010-10-27 07:13:30 37888 ----a-w- C:\Windows\System32\atiu9p64.dll
2010-10-27 07:13:24 28672 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
2010-10-27 07:12:56 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
2010-10-27 06:57:04 3221504 ----a-w- C:\Windows\System32\atiumd6a.dll
2010-10-27 06:50:10 3460096 ----a-w- C:\Windows\SysWow64\atiumdva.dll
2010-10-27 06:37:18 53760 ----a-w- C:\Windows\System32\atimpc64.dll
2010-10-27 06:37:18 53760 ----a-w- C:\Windows\System32\amdpcom64.dll
2010-10-27 06:37:14 52736 ----a-w- C:\Windows\SysWow64\atimpc32.dll
2010-10-27 06:37:14 52736 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
2010-09-21 19:49:02 252800 ----a-w- C:\Windows\System32\LIVESSP.DLL
2010-09-21 19:03:14 208768 ----a-w- C:\Windows\SysWow64\LIVESSP.DLL
2010-09-10 05:35:44 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2010-09-10 05:35:43 347648 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2010-09-08 05:36:17 1192960 ----a-w- C:\Windows\System32\wininet.dll
2010-09-08 05:34:34 57856 ----a-w- C:\Windows\System32\licmgr10.dll
2010-09-08 04:30:04 978432 ----a-w- C:\Windows\SysWow64\wininet.dll
2010-09-08 04:28:15 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll
2010-09-08 04:16:38 482816 ----a-w- C:\Windows\System32\html.iec
2010-09-08 03:35:30 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2010-09-08 03:22:31 386048 ----a-w- C:\Windows\SysWow64\html.iec
2010-09-08 02:48:16 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2010-09-01 05:12:09 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2010-09-01 04:23:49 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2010-09-01 02:58:34 3123712 ----a-w- C:\Windows\System32\win32k.sys
============= FINISH: 12:06:11.73 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-11-27.01)
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 18/11/2010 6:54:34 PM
System Uptime: 29/11/2010 11:45:18 AM (1 hours ago)
Motherboard: ASUSTeK Computer INC. | | M3A78-EM
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 5400+ | AM2 | 2800/200mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 74 GiB total, 53.074 GiB free.
D: is CDROM ()
E: is CDROM ()
==== Disabled Device Manager Items =============
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Realtek PCIe GBE Family Controller
Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_816810EC&REV_02\4&17AA8702&0&0030
Manufacturer: Realtek
Name: Realtek PCIe GBE Family Controller
PNP Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_816810EC&REV_02\4&17AA8702&0&0030
Service: RTL8167
==== System Restore Points ===================
RP13: 24/11/2010 9:52:36 AM - Windows Update
RP14: 25/11/2010 9:30:24 AM - Windows Update
RP15: 26/11/2010 10:24:00 AM - Revo Uninstaller's restore point - Google Chrome
RP16: 26/11/2010 10:44:02 AM - Windows Update
RP17: 26/11/2010 10:49:20 AM - Restore Operation
RP18: 26/11/2010 11:02:49 AM - Windows Update
RP19: 27/11/2010 5:42:25 PM - Windows Update
RP20: 28/11/2010 8:43:56 PM - Windows Update
==== Installed Programs ======================
Adobe Flash Player 10 Plugin
Adobe Reader X
foobar2000 v1.1.1
Google Chrome
Java Auto Updater
Java(TM) 6 Update 22
Malwarebytes' Anti-Malware
Microsoft Silverlight
Mozilla Firefox (3.6.12)
PowerISO
Revo Uninstaller 1.90
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
SPlayer
Street-Ads Browser Enhancer
==== Event Viewer Messages From Past Week ========
29/11/2010 11:45:40 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
29/11/2010 11:45:27 AM, Error: RTL8167 [5008] - Realtek PCIe GBE Family Controller : Has encountered an invalid network address.
29/11/2010 11:37:54 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
29/11/2010 11:36:28 AM, Error: Service Control Manager [7031] - The KMService service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
28/11/2010 8:33:41 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
28/11/2010 8:33:37 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff88006768910, 0x0000000000000000, 0xfffff8000287f6a6, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 112810-18330-01.
26/11/2010 11:07:56 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
26/11/2010 11:07:56 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Computer Browser service, but this action failed with the following error: An instance of the service is already running.
26/11/2010 11:06:57 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Server service, but this action failed with the following error: An instance of the service is already running.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7034] - The Application Information service terminated unexpectedly. It has done this 1 time(s).
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Windows Update service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The System Event Notification Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The IP Helper service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Group Policy Client service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Computer Browser service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Background Intelligent Transfer Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
26/11/2010 11:05:56 AM, Error: Service Control Manager [7031] - The Application Experience service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
26/11/2010 10:52:37 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
26/11/2010 10:23:07 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
26/11/2010 10:12:01 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
26/11/2010 10:10:00 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
==== End Of File ===========================
Thanks in advance.