guitar1969
Posts: 19 +0
Here's the latest FSS Log:
[FONT=Courier New]Farbar Service Scanner Version: 06-08-2012[/FONT]
[FONT=Courier New]Ran by MichaelH (administrator) on 16-08-2012 at 10:20:16[/FONT]
[FONT=Courier New]Running from "X:\Virus repairs 8 14 2012"[/FONT]
[FONT=Courier New]Microsoft Windows 7 Professional Service Pack 1 (X64)[/FONT]
[FONT=Courier New]Boot Mode: Normal[/FONT]
[FONT=Courier New]****************************************************************[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Internet Services:[/FONT]
[FONT=Courier New]============[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Connection Status:[/FONT]
[FONT=Courier New]==============[/FONT]
[FONT=Courier New]Localhost is accessible.[/FONT]
[FONT=Courier New]LAN connected.[/FONT]
[FONT=Courier New]Google IP is accessible.[/FONT]
[FONT=Courier New]Google.com is accessible.[/FONT]
[FONT=Courier New]Yahoo IP is accessible.[/FONT]
[FONT=Courier New]Yahoo.com is accessible.[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Windows Firewall:[/FONT]
[FONT=Courier New]=============[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Firewall Disabled Policy: [/FONT]
[FONT=Courier New]==================[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]System Restore:[/FONT]
[FONT=Courier New]============[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]System Restore Disabled Policy: [/FONT]
[FONT=Courier New]========================[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Action Center:[/FONT]
[FONT=Courier New]============[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Windows Update:[/FONT]
[FONT=Courier New]============[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Windows Autoupdate Disabled Policy: [/FONT]
[FONT=Courier New]============================[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Windows Defender:[/FONT]
[FONT=Courier New]==============[/FONT]
[FONT=Courier New]WinDefend Service is not running. Checking service configuration:[/FONT]
[FONT=Courier New]The start type of WinDefend service is set to Demand. The default start type is Auto.[/FONT]
[FONT=Courier New]The ImagePath of WinDefend service is OK.[/FONT]
[FONT=Courier New]The ServiceDll of WinDefend service is OK.[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Windows Defender Disabled Policy: [/FONT]
[FONT=Courier New]==========================[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender][/FONT]
[FONT=Courier New]"DisableAntiSpyware"=DWORD:1[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Other Services:[/FONT]
[FONT=Courier New]==============[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]File Check:[/FONT]
[FONT=Courier New]========[/FONT]
[FONT=Courier New]C:\Windows\System32\nsisvc.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\dhcpcore.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\drivers\afd.sys => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\drivers\tdx.sys => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\dnsrslvr.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\mpssvc.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\bfe.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\SDRSVC.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\vssvc.exe => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\wscsvc.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\wuaueng.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\qmgr.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\es.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\cryptsvc.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\svchost.exe => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\rpcss.dll => MD5 is legit[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]**** End of log ****[/FONT]
Does this look clean?
MSE is now updating again, along with Windows Update. I will check with the other forum regarding the bootup issue, but it only started yesterday during the cleaning process, so wondering if sometihng got wiped out - small price to pay for a clean computer.
[FONT=Courier New]Farbar Service Scanner Version: 06-08-2012[/FONT]
[FONT=Courier New]Ran by MichaelH (administrator) on 16-08-2012 at 10:20:16[/FONT]
[FONT=Courier New]Running from "X:\Virus repairs 8 14 2012"[/FONT]
[FONT=Courier New]Microsoft Windows 7 Professional Service Pack 1 (X64)[/FONT]
[FONT=Courier New]Boot Mode: Normal[/FONT]
[FONT=Courier New]****************************************************************[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Internet Services:[/FONT]
[FONT=Courier New]============[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Connection Status:[/FONT]
[FONT=Courier New]==============[/FONT]
[FONT=Courier New]Localhost is accessible.[/FONT]
[FONT=Courier New]LAN connected.[/FONT]
[FONT=Courier New]Google IP is accessible.[/FONT]
[FONT=Courier New]Google.com is accessible.[/FONT]
[FONT=Courier New]Yahoo IP is accessible.[/FONT]
[FONT=Courier New]Yahoo.com is accessible.[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Windows Firewall:[/FONT]
[FONT=Courier New]=============[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Firewall Disabled Policy: [/FONT]
[FONT=Courier New]==================[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]System Restore:[/FONT]
[FONT=Courier New]============[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]System Restore Disabled Policy: [/FONT]
[FONT=Courier New]========================[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Action Center:[/FONT]
[FONT=Courier New]============[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Windows Update:[/FONT]
[FONT=Courier New]============[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Windows Autoupdate Disabled Policy: [/FONT]
[FONT=Courier New]============================[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Windows Defender:[/FONT]
[FONT=Courier New]==============[/FONT]
[FONT=Courier New]WinDefend Service is not running. Checking service configuration:[/FONT]
[FONT=Courier New]The start type of WinDefend service is set to Demand. The default start type is Auto.[/FONT]
[FONT=Courier New]The ImagePath of WinDefend service is OK.[/FONT]
[FONT=Courier New]The ServiceDll of WinDefend service is OK.[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Windows Defender Disabled Policy: [/FONT]
[FONT=Courier New]==========================[/FONT]
[FONT=Courier New][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender][/FONT]
[FONT=Courier New]"DisableAntiSpyware"=DWORD:1[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]Other Services:[/FONT]
[FONT=Courier New]==============[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]File Check:[/FONT]
[FONT=Courier New]========[/FONT]
[FONT=Courier New]C:\Windows\System32\nsisvc.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\dhcpcore.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\drivers\afd.sys => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\drivers\tdx.sys => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\dnsrslvr.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\mpssvc.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\bfe.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\SDRSVC.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\vssvc.exe => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\wscsvc.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\wuaueng.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\qmgr.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\es.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\cryptsvc.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\svchost.exe => MD5 is legit[/FONT]
[FONT=Courier New]C:\Windows\System32\rpcss.dll => MD5 is legit[/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New] [/FONT]
[FONT=Courier New]**** End of log ****[/FONT]
Does this look clean?
MSE is now updating again, along with Windows Update. I will check with the other forum regarding the bootup issue, but it only started yesterday during the cleaning process, so wondering if sometihng got wiped out - small price to pay for a clean computer.