

InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
4251. |
Solve : Msn Photo.zip virus......PLs help? |
Answer» HI evil, the cleanup!.exe free up an addition of 32mb.
Here are some great tools to help you keep from getting infected again. Spybot Search & Destroy - A safe and effective spyware scanner. * Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers AVG Anti-Spyware Free Edition - Very reliable with a high detection rate. * AVG Anti-Spyware User Manual SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware Comodo BOClean - Stops trojans and many more malicious attacks. Use a Firewall - It can not be stressed enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. * Click here for a list of free firewalls. * Why WOULD I consider a third party firewall? * Understanding and Using Firewalls UPDATE!!! UPDATE!!! UPDATE!!! - If you do not have automatic updates enabled then visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. * Help with Windows updates Learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first PLACE? Let us know if anything else comes up.You are great!!! and you guys rock!!! Thank you evil No problem, glad it worked. |
|
4252. |
Solve : New Virus? |
Answer» I've heard of a new virus out called ronamonadona virus. Anyone heard of it or how prevalent it is?I searched for it, and found this: It is clearly extortion-ware, offering on the user's screen: "Welcome to MonaRonaDona; hi, my name is Mona RonaDona. i am a virus& i am here to Wreck Your PC." Where did you hear about it?Kim Komando ShowCould have named it Roseanne Roseannadana virus.Yes I have already been INVOLVED with this one. Removal instructions. First: Have HIJACKTHIS fix these entries (if found)
Download OTMoveIt2 by OldTimer.
Now, Double click to open OTMoveIt2 again. Click the green CleanupUp! button at the top. Note: it will need to access the internet to download a small script file. Please allow your Firewall to do so. When it finishes it will have deleted all of its qauarantines, as well as the OTMOVEIT2 program and all created folders. Reboot the computer. If any problems still exist due to the infection. Another tool to fix the Task Manager and other policies that this virus effects. Download to your Desktop this self-extracting ZIP archive FixPolicies.exe .
Could have named it Roseanne Roseannadana virus. This one only says " Nevermind "....... |
|
4253. |
Solve : WINDOWS folder in Reclying Bin?? |
Answer» Hello all, new here. |
|
4254. |
Solve : hijackthis? |
Answer» ok can someone please analyze this and tell me what i should be doing? I already submitted another forum about my computer not letting me dl anything and having corrupted files. Someone had refered me to getting hijackthis. I have no idea how to read this and what i should be doing with this program so here is what it gave me when i scaned my computer.
What DSS will do:
[file cleanup - saving space - attachment deleted by admin]2nd part [file cleanup - saving space - attachment deleted by admin]Go to www.java.com and download and uninstall the new version of Java. If you have any problems installing the new Java then let me know. Next go to add/remove programs and uninstall the following. Java 2 Runtime Environment Standard Edition v1.3.1 LiveReg LiveUpdate 1.6 Viewpoint Media Player WildTangent Updater WildTangent Web Driver Now go back here and try to run the Superantispyware, Dr Web and Online Scanner.ok i did what you told me and it let me dl superantispyware. However it kept stopping so i had to close it and restart the dl to get it dl all the way. OK, once we get the logs we will know what else may need to be done. |
|
4255. |
Solve : firewall settings change after every boot. help? |
Answer» for some REASON every time after i boot my vista home PREMIUM sp1 laptop after a couple of minutes of windows started, firewall and network SHARING settings change. every time i have to change it back. dunno why this is happening. appreciate any info. dunno if its related but have tis event viewer logs tat looked strange to me (among like 400 different ones in one minute -!? and even if its not related is it something ok? wat is it saying?) by the way, some time ago my computer was infected by backdoor:win32/refpron.A. supposedly it was removed. A Windows Filtering Platform filter has been changed. general tab Subject: Security ID: LOCAL SERVICE Account Name: NT AUTHORITY\LOCAL SERVICE PROCESS Information: Process ID: 1644 PROVIDER Information: ID: {decc16ca-3f33-4346-be1e-8fb4ae0f3d62} Name: Windows Firewall Change Information: Change Type: Delete Filter Information: ID: {0aa8b2a7-d8e6-4574-8b79-5389071e8fa2} Name: Port Scanning Prevention Filter Type: Boot-time Run-Time ID: 68324 Layer Information: ID: {7fb03b60-7b8d-4dfa-badd-980176fc4e12} Name: Outbound ICMP Error v6 Layer Run-Time ID: 34 Callout Information: ID: {00000000-0000-0000-0000-000000000000} Name: - Additional Information: Weight: 18446744073709551615 Conditions: Condition ID: {632ce23b-5167-435c-86d7-e903684aa80c} Match value: No flags set Condition value: 0x00000001 Condition ID: {0c1ba1af-5765-453f-af22-a8f791ac775b} Match value: Equal to Condition value: 0x0001 Filter Action: Block --------------------------------------------------------------------- details tab + System - Provider [ Name] Microsoft-Windows-Security-Auditing [ Guid] {54849625-5478-4994-a5ba-3e3b0328c30d} EventID 5447 Version 0 Level 0 Task 13573 Opcode 0 Keywords 0x8020000000000000 - TimeCreated [ SystemTime] 2009-05-24T19:44:53.406Z EventRecordID 483055 Correlation - Execution [ ProcessID] 636 [ ThreadID] 1004 Channel Security Security - EventData ProcessId 1644 UserSid S-1-5-19 UserName NT AUTHORITY\LOCAL SERVICE ProviderKey {DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62} ProviderName Windows Firewall ChangeType %%16385 FilterKey {0AA8B2A7-D8E6-4574-8B79-5389071E8FA2} FilterName Port Scanning Prevention Filter FilterType %%16386 FilterId 68324 LayerKey {7FB03B60-7B8D-4DFA-BADD-980176FC4E12} LayerName Outbound ICMP Error v6 Layer LayerId 34 Weight 18446744073709551615 Conditions Condition ID: {632ce23b-5167-435c-86d7-e903684aa80c} Match value: No flags set Condition value: 0x00000001 Condition ID: {0c1ba1af-5765-453f-af22-a8f791ac775b} Match value: Equal to Condition value: 0x0001 Action %%16389 CalloutKey {00000000-0000-0000-0000-000000000000} CalloutName - -------------------------------------------------------------------- --------------------------------------------------------------------log2 general tab A Windows Filtering Platform filter has been changed. Subject: Security ID: LOCAL SERVICE Account Name: NT AUTHORITY\LOCAL SERVICE Process Information: Process ID: 1644 Provider Information: ID: {decc16ca-3f33-4346-be1e-8fb4ae0f3d62} Name: Windows Firewall Change Information: Change Type: Delete Filter Information: ID: {0aa8b2a7-d8e6-4574-8b79-5389071e8fa2} Name: Port Scanning Prevention Filter Type: Boot-time Run-Time ID: 68324 Layer Information: ID: {7fb03b60-7b8d-4dfa-badd-980176fc4e12} Name: Outbound ICMP Error v6 Layer Run-Time ID: 34 Callout Information: ID: {00000000-0000-0000-0000-000000000000} Name: - Additional Information: Weight: 18446744073709551615 Conditions: Condition ID: {632ce23b-5167-435c-86d7-e903684aa80c} Match value: No flags set Condition value: 0x00000001 Condition ID: {0c1ba1af-5765-453f-af22-a8f791ac775b} Match value: Equal to Condition value: 0x0001 Filter Action: Block ------------------------------------------------------------------------------ details tab + System - Provider [ Name] Microsoft-Windows-Security-Auditing [ Guid] {54849625-5478-4994-a5ba-3e3b0328c30d} EventID 5447 Version 0 Level 0 Task 13573 Opcode 0 Keywords 0x8020000000000000 - TimeCreated [ SystemTime] 2009-05-24T19:44:53.406Z EventRecordID 483055 Correlation - Execution [ ProcessID] 636 [ ThreadID] 1004 Channel Security Security - EventData ProcessId 1644 UserSid S-1-5-19 UserName NT AUTHORITY\LOCAL SERVICE ProviderKey {DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62} ProviderName Windows Firewall ChangeType %%16385 FilterKey {0AA8B2A7-D8E6-4574-8B79-5389071E8FA2} FilterName Port Scanning Prevention Filter FilterType %%16386 FilterId 68324 LayerKey {7FB03B60-7B8D-4DFA-BADD-980176FC4E12} LayerName Outbound ICMP Error v6 Layer LayerId 34 Weight 18446744073709551615 Conditions Condition ID: {632ce23b-5167-435c-86d7-e903684aa80c} Match value: No flags set Condition value: 0x00000001 Condition ID: {0c1ba1af-5765-453f-af22-a8f791ac775b} Match value: Equal to Condition value: 0x0001 Action %%16389 CalloutKey {00000000-0000-0000-0000-000000000000} CalloutName - |
|
4256. |
Solve : Need help removing invisible virus files? |
Answer» Were getting there....
Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work. Delete the fixme.reg from the Desktop. ----------
---------- Run CCleaner and let me know how everything is now.Here is the safeboot repair log: Code: [Select]Reg export of SafeBoot key after repair: ======================== Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot] "AlternateShell"="cmd.exe" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\AppMgmt] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Base] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Boot Bus Extender] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Boot file system] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\CryptSvc] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\DcomLaunch] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmadmin] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmboot.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmio.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmload.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmserver] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\EventLog] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\File system] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Filter] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\HelpSvc] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Netlogon] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PCI Configuration] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PlugPlay] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PNP Filter] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Primary disk] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\procexp90.Sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PSEXESVC] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\RpcSs] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\SCSI Class] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\sermouse.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\sr.sys] @="FSFilter System Recovery" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\SRService] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\System Bus Extender] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vds] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vga.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vgasave.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\WdfLoadGroup] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\WinMgmt] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\WRConsumerService] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}] @="Universal Serial Bus controllers" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}] @="CD-ROM Drive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}] @="DiskDrive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}] @="Standard floppy disk controller" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}] @="Hdc" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] @="Keyboard" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}] @="Mouse" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}] @="PCMCIA Adapters" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}] @="SCSIAdapter" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}] @="System" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}] @="Floppy disk drive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] @="Volume shadow copy" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] @="Volume" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] @="HUMAN Interface Devices" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AFD] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AppMgmt] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Base] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Boot Bus Extender] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Boot file system] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Browser] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\CryptSvc] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\DcomLaunch] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Dhcp] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmadmin] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmboot.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmio.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmload.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmserver] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\DnsCache] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\EventLog] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\File system] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Filter] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\HelpSvc] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\ip6fw.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\ipnat.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LanmanServer] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LanmanWorkstation] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LmHosts] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Messenger] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NDIS] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NDIS Wrapper] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Ndisuio] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBIOS] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBIOSGroup] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBT] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetDDEGroup] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Netlogon] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetMan] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Network] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetworkProvider] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NtLmSsp] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PCI Configuration] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PlugPlay] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PNP Filter] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PNP_TDI] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Primary disk] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\procexp90.Sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PSEXESVC] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpcdd.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpdd.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpwd.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdsessmgr] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\RpcSs] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SCSI Class] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sermouse.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sharedaccess] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sr.sys] @="FSFilter System Recovery" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SRService] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Streams Drivers] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\System Bus Extender] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Tcpip] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\TDI] @="Driver Group" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\tdpipe.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\tdtcp.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\termservice] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\UploadMgr] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\vga.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\vgasave.sys] @="Driver" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WdfLoadGroup] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WinMgmt] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WRConsumerService] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WZCSVC] @="Service" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{36FC9E60-C465-11CF-8056-444553540000}] @="Universal Serial Bus controllers" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}] @="CD-ROM Drive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}] @="DiskDrive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}] @="Standard floppy disk controller" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}] @="Hdc" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}] @="Keyboard" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}] @="Mouse" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}] @="Net" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}] @="NetClient" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}] @="NetService" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}] @="NetTrans" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}] @="PCMCIA Adapters" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}] @="SCSIAdapter" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}] @="System" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}] @="Floppy disk drive" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}] @="Volume" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}] @="Human Interface Devices" ======================== HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\procexp90.Sys HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\PSEXESVC HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WdfLoadGroup HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WRConsumerService success message: fixme.reg was successfully entered into the registry. I ran CCleaner and the computer is running great. Sounds good. Have a look through this. Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Ok. Thank you very much for your help. |
|
4257. |
Solve : Possible Virus Infection on Laptop? |
Answer» Thanks SuperDave SpyBot found a number of items that SuperAntiSpyware didn't. So I will use both too.You're welcome. I will lock this thread. If you need it re-opened, PLEASE send me a pm.Let's run a few more scans to see what turns up. Please download aswMBR.exe ( 511KB ) to your desktop. Double click the aswMBR.exe to run it Click the "Scan" button to start scan Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives On completion of the scan click save log, save it to your desktop and post in your next reply aswMBR Scan results aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software Run date: 2011-12-07 15:56:50 ----------------------------- 15:56:50.413 OS Version: Windows x64 6.1.7601 Service Pack 1 15:56:50.413 Number of processors: 2 586 0x170A 15:56:50.413 ComputerName: RICHARDNEW-PC UserName: RichardNew 15:56:51.817 Initialize success 15:56:55.904 AVAST engine defs: 11120701 15:57:02.893 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 15:57:02.893 Disk 0 Vendor: TOSHIBA_ FG00 Size: 238475MB BusType: 3 15:57:02.940 Disk 0 MBR read successfully 15:57:02.940 Disk 0 MBR scan 15:57:02.940 Disk 0 unknown MBR code 15:57:02.956 Service scanning 15:57:04.266 Modules scanning 15:57:04.266 Disk 0 trace - called modules: 15:57:04.328 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys iaStor.sys hal.dll 15:57:04.328 1 NT!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80057e0790] 15:57:04.344 3 CLASSPNP.SYS[fffff880010c743f] -> nt!IofCallDriver -> [0xfffffa80057e0040] 15:57:04.344 5 hpdskflt.sys[fffff88002565289] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80047c7050] 15:57:05.561 AVAST engine scan C:\Windows 15:57:09.851 AVAST engine scan C:\Windows\system32 15:59:17.989 AVAST engine scan C:\Windows\system32\drivers 15:59:31.203 AVAST engine scan C:\Users\RichardNew 16:03:25.000 AVAST engine scan C:\ProgramData 17:24:51.334 Scan finished successfully 18:09:19.875 Disk 0 MBR has been saved successfully to "C:\Users\RichardNew\Desktop\MBR.dat" 18:09:19.891 The log file has been saved successfully to "C:\Users\RichardNew\Desktop\aswMBR.txt"
19:26:55.0086 4576TDSS rootkit removing tool 2.6.22.0 Dec 7 2011 13:21:06 19:26:55.0258 4576============================================================ 19:26:55.0258 4576Current date / time: 2011/12/07 19:26:55.0258 19:26:55.0258 4576SystemInfo: 19:26:55.0258 4576 19:26:55.0258 4576OS Version: 6.1.7601 ServicePack: 1.0 19:26:55.0258 4576Product type: Workstation 19:26:55.0258 4576ComputerName: RICHARDNEW-PC 19:26:55.0258 4576UserName: RichardNew 19:26:55.0258 4576Windows directory: C:\Windows 19:26:55.0258 4576System windows directory: C:\Windows 19:26:55.0258 4576Running under WOW64 19:26:55.0258 4576Processor architecture: Intel x64 19:26:55.0258 4576Number of processors: 2 19:26:55.0258 4576Page size: 0x1000 19:26:55.0258 4576Boot type: Normal boot 19:26:55.0258 4576============================================================ 19:26:55.0882 4576Initialize success 19:27:19.0812 5728============================================================ 19:27:19.0812 5728Scan started 19:27:19.0812 5728Mode: Manual; 19:27:19.0812 5728============================================================ 19:27:21.0107 57281394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys 19:27:21.0107 57281394ohci - ok 19:27:21.0201 5728Accelerometer (1cffe9c06e66a57dae1452e449a58240) C:\Windows\system32\DRIVERS\Accelerometer.sys 19:27:21.0201 5728Accelerometer - ok 19:27:21.0294 5728ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys 19:27:21.0294 5728ACPI - ok 19:27:21.0388 5728AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys 19:27:21.0388 5728AcpiPmi - ok 19:27:21.0622 5728adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys 19:27:21.0622 5728adp94xx - ok 19:27:21.0715 5728adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys 19:27:21.0715 5728adpahci - ok 19:27:21.0793 5728adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys 19:27:21.0793 5728adpu320 - ok 19:27:21.0934 5728AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys 19:27:21.0934 5728AFD - ok 19:27:22.0074 5728AgereSoftModem (af4748ef93416159459769a24a0053af) C:\Windows\system32\DRIVERS\agrsm64.sys 19:27:22.0090 5728AgereSoftModem - ok 19:27:22.0168 5728agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys 19:27:22.0168 5728agp440 - ok 19:27:22.0293 5728aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys 19:27:22.0293 5728aliide - ok 19:27:22.0386 5728amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys 19:27:22.0386 5728amdide - ok 19:27:22.0480 5728AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys 19:27:22.0480 5728AmdK8 - ok 19:27:22.0558 5728AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys 19:27:22.0558 5728AmdPPM - ok 19:27:22.0636 5728amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys 19:27:22.0651 5728amdsata - ok 19:27:22.0683 5728amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys 19:27:22.0683 5728amdsbs - ok 19:27:22.0729 5728amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys 19:27:22.0729 5728amdxata - ok 19:27:22.0823 5728AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys 19:27:22.0823 5728AppID - ok 19:27:22.0963 5728arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys 19:27:22.0979 5728arc - ok 19:27:23.0057 5728arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys 19:27:23.0057 5728arcsas - ok 19:27:23.0197 5728AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 19:27:23.0197 5728AsyncMac - ok 19:27:23.0244 5728atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys 19:27:23.0244 5728atapi - ok 19:27:23.0463 5728atikmdag (3efd964d52221360af0673cd61c2f4f5) C:\Windows\system32\drivers\atikmdag.sys 19:27:23.0572 5728atikmdag - ok 19:27:23.0697 5728AVGIDSEH (f823d184b8e8ffb8da3ead45dbf5bd6a) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys 19:27:23.0697 5728AVGIDSEH - ok 19:27:23.0806 5728Avgtdia (11f36d3ea82d9db9aa05a476a210551b) C:\Windows\system32\DRIVERS\avgtdia.sys 19:27:23.0806 5728Avgtdia - ok 19:27:23.0962 5728b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys 19:27:23.0962 5728b06bdrv - ok 19:27:24.0071 5728b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 19:27:24.0087 5728b57nd60a - ok 19:27:24.0258 5728BCM43XX (0e14a0071fe26a570bcaff5401014717) C:\Windows\system32\DRIVERS\bcmwl664.sys 19:27:24.0321 5728BCM43XX - ok 19:27:24.0414 5728Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 19:27:24.0414 5728Beep - ok 19:27:24.0523 5728blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 19:27:24.0523 5728blbdrive - ok 19:27:24.0617 5728bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys 19:27:24.0633 5728bowser - ok 19:27:24.0664 5728BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys 19:27:24.0664 5728BrFiltLo - ok 19:27:24.0726 5728BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys 19:27:24.0726 5728BrFiltUp - ok 19:27:24.0820 5728Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 19:27:24.0820 5728Brserid - ok 19:27:24.0898 5728BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 19:27:24.0898 5728BrSerWdm - ok 19:27:24.0976 5728BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 19:27:24.0976 5728BrUsbMdm - ok 19:27:24.0991 5728BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 19:27:24.0991 5728BrUsbSer - ok 19:27:25.0085 5728BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys 19:27:25.0085 5728BTHMODEM - ok 19:27:25.0210 5728cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 19:27:25.0210 5728cdfs - ok 19:27:25.0303 5728cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys 19:27:25.0303 5728cdrom - ok 19:27:25.0397 5728circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys 19:27:25.0397 5728circlass - ok 19:27:25.0444 5728CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 19:27:25.0444 5728CLFS - ok 19:27:25.0569 5728CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 19:27:25.0569 5728CmBatt - ok 19:27:25.0631 5728cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys 19:27:25.0631 5728cmdide - ok 19:27:25.0662 5728CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys 19:27:25.0662 5728CNG - ok 19:27:25.0818 5728Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys 19:27:25.0818 5728Compbatt - ok 19:27:25.0912 5728CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys 19:27:25.0927 5728CompositeBus - ok 19:27:26.0021 5728crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys 19:27:26.0021 5728crcdisk - ok 19:27:26.0161 5728DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys 19:27:26.0161 5728DfsC - ok 19:27:26.0239 5728discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 19:27:26.0239 5728discache - ok 19:27:26.0302 5728Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys 19:27:26.0302 5728Disk - ok 19:27:26.0411 5728drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 19:27:26.0411 5728drmkaud - ok 19:27:26.0520 5728DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys 19:27:26.0536 5728DXGKrnl - ok 19:27:26.0692 5728ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys 19:27:26.0754 5728ebdrv - ok 19:27:26.0879 5728elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys 19:27:26.0879 5728elxstor - ok 19:27:26.0973 5728enecir (524c79054636d2e5751169005006460b) C:\Windows\system32\DRIVERS\enecir.sys 19:27:26.0973 5728enecir - ok 19:27:27.0004 5728ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys 19:27:27.0004 5728ErrDev - ok 19:27:27.0113 5728exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 19:27:27.0113 5728exfat - ok 19:27:27.0191 5728fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 19:27:27.0207 5728fastfat - ok 19:27:27.0316 5728fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys 19:27:27.0316 5728fdc - ok 19:27:27.0394 5728FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 19:27:27.0394 5728FileInfo - ok 19:27:27.0409 5728Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 19:27:27.0409 5728Filetrace - ok 19:27:27.0519 5728flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys 19:27:27.0519 5728flpydisk - ok 19:27:27.0612 5728FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys 19:27:27.0612 5728FltMgr - ok 19:27:27.0721 5728FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 19:27:27.0737 5728FsDepends - ok 19:27:27.0768 5728Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 19:27:27.0784 5728Fs_Rec - ok 19:27:27.0862 5728fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys 19:27:27.0862 5728fvevol - ok 19:27:27.0955 5728gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys 19:27:27.0955 5728gagp30kx - ok 19:27:28.0049 5728GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 19:27:28.0049 5728GEARAspiWDM - ok 19:27:28.0174 5728hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 19:27:28.0174 5728hcw85cir - ok 19:27:28.0283 5728HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys 19:27:28.0283 5728HdAudAddService - ok 19:27:28.0377 5728HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys 19:27:28.0392 5728HDAudBus - ok 19:27:28.0408 5728HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys 19:27:28.0408 5728HidBatt - ok 19:27:28.0486 5728HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys 19:27:28.0501 5728HidBth - ok 19:27:28.0595 5728HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys 19:27:28.0595 5728HidIr - ok 19:27:28.0673 5728HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys 19:27:28.0673 5728HidUsb - ok 19:27:28.0782 5728hpdskflt (05712fddbd45a5864eb326faabc6a4e3) C:\Windows\system32\DRIVERS\hpdskflt.sys 19:27:28.0782 5728hpdskflt - ok 19:27:28.0876 5728HpqKbFiltr (9af482d058be59cc28bce52e7c4b747c) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys 19:27:28.0876 5728HpqKbFiltr - ok 19:27:29.0001 5728HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys 19:27:29.0001 5728HpSAMD - ok 19:27:29.0125 5728HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys 19:27:29.0141 5728HTTP - ok 19:27:29.0203 5728hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys 19:27:29.0219 5728hwpolicy - ok 19:27:29.0328 5728i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys 19:27:29.0328 5728i8042prt - ok 19:27:29.0437 5728iaStor (1d004cb1da6323b1f55caef7f94b61d9) C:\Windows\system32\DRIVERS\iaStor.sys 19:27:29.0437 5728iaStor - ok 19:27:29.0547 5728iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys 19:27:29.0547 5728iaStorV - ok 19:27:29.0827 5728igfx (3c3f27002abc69c5afe29cbe6cf7addf) C:\Windows\system32\DRIVERS\igdkmd64.sys 19:27:29.0999 5728igfx - ok 19:27:30.0077 5728iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys 19:27:30.0077 5728iirsp - ok 19:27:30.0186 5728IntcHdmiAddService (88a20fa54c73ded4e8dac764e9130ae9) C:\Windows\system32\drivers\IntcHdmi.sys 19:27:30.0186 5728IntcHdmiAddService - ok 19:27:30.0249 5728intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys 19:27:30.0249 5728intelide - ok 19:27:30.0311 5728intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 19:27:30.0327 5728intelppm - ok 19:27:30.0358 5728IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys 19:27:30.0358 5728IpFilterDriver - ok 19:27:30.0451 5728IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys 19:27:30.0451 5728IPMIDRV - ok 19:27:30.0498 5728IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 19:27:30.0498 5728IPNAT - ok 19:27:30.0592 5728IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 19:27:30.0592 5728IRENUM - ok 19:27:30.0654 5728isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys 19:27:30.0654 5728isapnp - ok 19:27:30.0701 5728iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys 19:27:30.0701 5728iScsiPrt - ok 19:27:30.0795 5728kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys 19:27:30.0795 5728kbdclass - ok 19:27:30.0873 5728kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys 19:27:30.0873 5728kbdhid - ok 19:27:30.0966 5728KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys 19:27:30.0966 5728KSecDD - ok 19:27:31.0013 5728KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys 19:27:31.0013 5728KSecPkg - ok 19:27:31.0091 5728ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 19:27:31.0091 5728ksthunk - ok 19:27:31.0231 5728lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 19:27:31.0231 5728lltdio - ok 19:27:31.0325 5728LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys 19:27:31.0325 5728LSI_FC - ok 19:27:31.0403 5728LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys 19:27:31.0419 5728LSI_SAS - ok 19:27:31.0497 5728LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys 19:27:31.0497 5728LSI_SAS2 - ok 19:27:31.0590 5728LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys 19:27:31.0590 5728LSI_SCSI - ok 19:27:31.0699 5728luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 19:27:31.0699 5728luafv - ok 19:27:31.0793 5728megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys 19:27:31.0793 5728megasas - ok 19:27:31.0824 5728MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys 19:27:31.0824 5728MegaSR - ok 19:27:31.0918 5728Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 19:27:31.0933 5728Modem - ok 19:27:31.0996 5728monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 19:27:31.0996 5728monitor - ok 19:27:32.0089 5728mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\drivers\mouclass.sys 19:27:32.0089 5728mouclass - ok 19:27:32.0199 5728mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 19:27:32.0199 5728mouhid - ok 19:27:32.0261 5728mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys 19:27:32.0261 5728mountmgr - ok 19:27:32.0355 5728mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys 19:27:32.0355 5728mpio - ok 19:27:32.0433 5728mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 19:27:32.0433 5728mpsdrv - ok 19:27:32.0511 5728MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys 19:27:32.0526 5728MRxDAV - ok 19:27:32.0604 5728mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys 19:27:32.0604 5728mrxsmb - ok 19:27:32.0682 5728mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys 19:27:32.0682 5728mrxsmb10 - ok 19:27:32.0760 5728mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 19:27:32.0760 5728mrxsmb20 - ok 19:27:32.0823 5728msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys 19:27:32.0823 5728msahci - ok 19:27:32.0901 5728msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys 19:27:32.0901 5728msdsm - ok 19:27:32.0979 5728Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 19:27:32.0979 5728Msfs - ok 19:27:33.0010 5728mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 19:27:33.0010 5728mshidkmdf - ok 19:27:33.0088 5728msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys 19:27:33.0088 5728msisadrv - ok 19:27:33.0181 5728MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 19:27:33.0181 5728MSKSSRV - ok 19:27:33.0259 5728MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 19:27:33.0259 5728MSPCLOCK - ok 19:27:33.0306 5728MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 19:27:33.0306 5728MSPQM - ok 19:27:33.0384 5728MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys 19:27:33.0384 5728MsRPC - ok 19:27:33.0462 5728mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys 19:27:33.0462 5728mssmbios - ok 19:27:33.0525 5728MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 19:27:33.0525 5728MSTEE - ok 19:27:33.0556 5728MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys 19:27:33.0556 5728MTConfig - ok 19:27:33.0649 5728Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 19:27:33.0649 5728Mup - ok 19:27:33.0790 5728NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 19:27:33.0790 5728NativeWifiP - ok 19:27:33.0899 5728NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys 19:27:33.0915 5728NDIS - ok 19:27:33.0993 5728NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 19:27:33.0993 5728NdisCap - ok 19:27:34.0071 5728NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 19:27:34.0071 5728NdisTapi - ok 19:27:34.0180 5728Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys 19:27:34.0180 5728Ndisuio - ok 19:27:34.0242 5728NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys 19:27:34.0242 5728NdisWan - ok 19:27:34.0273 5728NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys 19:27:34.0273 5728NDProxy - ok 19:27:34.0367 5728NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 19:27:34.0367 5728NetBIOS - ok 19:27:34.0398 5728NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys 19:27:34.0414 5728NetBT - ok 19:27:34.0695 5728netw5v64 (64428dfdaf6e88366cb51f45a79c5f69) C:\Windows\system32\DRIVERS\netw5v64.sys 19:27:34.0819 5728netw5v64 - ok 19:27:34.0882 5728nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys 19:27:34.0882 5728nfrd960 - ok 19:27:34.0960 5728Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 19:27:34.0960 5728Npfs - ok 19:27:34.0975 5728nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 19:27:34.0975 5728nsiproxy - ok 19:27:35.0085 5728Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys 19:27:35.0116 5728Ntfs - ok 19:27:35.0209 5728Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 19:27:35.0209 5728Null - ok 19:27:35.0303 5728nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys 19:27:35.0319 5728nvraid - ok 19:27:35.0397 5728nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys 19:27:35.0397 5728nvstor - ok 19:27:35.0428 5728nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys 19:27:35.0428 5728nv_agp - ok 19:27:35.0506 5728ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys 19:27:35.0506 5728ohci1394 - ok 19:27:35.0646 5728Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys 19:27:35.0646 5728Parport - ok 19:27:35.0677 5728partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys 19:27:35.0677 5728partmgr - ok 19:27:35.0724 5728pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys 19:27:35.0724 5728pci - ok 19:27:35.0755 5728pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys 19:27:35.0755 5728pciide - ok 19:27:35.0802 5728pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys 19:27:35.0818 5728pcmcia - ok 19:27:35.0896 5728pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 19:27:35.0896 5728pcw - ok 19:27:35.0974 5728PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 19:27:35.0989 5728PEAUTH - ok 19:27:36.0099 5728pgfilter - ok 19:27:36.0255 5728PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys 19:27:36.0255 5728PptpMiniport - ok 19:27:36.0333 5728Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys 19:27:36.0333 5728Processor - ok 19:27:36.0442 5728Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys 19:27:36.0442 5728Psched - ok 19:27:36.0535 5728ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys 19:27:36.0551 5728ql2300 - ok 19:27:36.0645 5728ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys 19:27:36.0645 5728ql40xx - ok 19:27:36.0723 5728QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 19:27:36.0723 5728QWAVEdrv - ok 19:27:36.0785 5728RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 19:27:36.0785 5728RasAcd - ok 19:27:36.0879 5728RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 19:27:36.0879 5728RasAgileVpn - ok 19:27:36.0972 5728Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys 19:27:36.0972 5728Rasl2tp - ok 19:27:37.0035 5728RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 19:27:37.0035 5728RasPppoe - ok 19:27:37.0128 5728RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 19:27:37.0128 5728RasSstp - ok 19:27:37.0191 5728rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys 19:27:37.0206 5728rdbss - ok 19:27:37.0284 5728rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys 19:27:37.0284 5728rdpbus - ok 19:27:37.0378 5728RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 19:27:37.0378 5728RDPCDD - ok 19:27:37.0456 5728RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 19:27:37.0456 5728RDPENCDD - ok 19:27:37.0549 5728RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 19:27:37.0549 5728RDPREFMP - ok 19:27:37.0627 5728RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys 19:27:37.0627 5728RDPWD - ok 19:27:37.0737 5728rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys 19:27:37.0737 5728rdyboost - ok 19:27:37.0815 5728RimUsb - ok 19:27:37.0893 5728RimVSerPort (c903d49655b4aae46673f0aaa6be0f58) C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys 19:27:37.0893 5728RimVSerPort - ok 19:27:37.0986 5728ROOTMODEM (388d3dd1a6457280f3badba9f3acd6b1) C:\Windows\system32\Drivers\RootMdm.sys 19:27:37.0986 5728ROOTMODEM - ok 19:27:38.0095 5728rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 19:27:38.0095 5728rspndr - ok 19:27:38.0220 5728RSUSBSTOR (a5df2f732a6c95554e548fcb6932bd31) C:\Windows\system32\Drivers\RtsUStor.sys 19:27:38.0236 5728RSUSBSTOR - ok 19:27:38.0329 5728RTL8167 (91296f0b2653281b2f11e0fce56aa427) C:\Windows\system32\DRIVERS\Rt64win7.sys 19:27:38.0329 5728RTL8167 - ok 19:27:38.0407 5728RtsUIR - ok 19:27:38.0454 5728SASDIFSV (99df79c258b3342b6c8a5f802998de56) C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS 19:27:38.0470 5728SASDIFSV - ok 19:27:38.0470 5728SASKUTIL (2859c35c0651e8eb0d86d48e740388f2) C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS 19:27:38.0470 5728SASKUTIL - ok 19:27:38.0548 5728sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys 19:27:38.0548 5728sbp2port - ok 19:27:38.0673 5728scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys 19:27:38.0673 5728scfilter - ok 19:27:38.0766 5728sdbus (111e0ebc0ad79cb0fa014b907b231cf0) C:\Windows\system32\drivers\sdbus.sys 19:27:38.0766 5728sdbus - ok 19:27:38.0844 5728secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 19:27:38.0844 5728secdrv - ok 19:27:38.0953 5728Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys 19:27:38.0953 5728Serenum - ok 19:27:38.0985 5728Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys 19:27:38.0985 5728Serial - ok 19:27:39.0063 5728sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys 19:27:39.0078 5728sermouse - ok 19:27:39.0156 5728sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys 19:27:39.0156 5728sffdisk - ok 19:27:39.0219 5728sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys 19:27:39.0234 5728sffp_mmc - ok 19:27:39.0234 5728sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys 19:27:39.0234 5728sffp_sd - ok 19:27:39.0343 5728sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys 19:27:39.0343 5728sfloppy - ok 19:27:39.0421 5728SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys 19:27:39.0421 5728SiSRaid2 - ok 19:27:39.0437 5728SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys 19:27:39.0437 5728SiSRaid4 - ok 19:27:39.0531 5728Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 19:27:39.0531 5728Smb - ok 19:27:39.0624 5728spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 19:27:39.0624 5728spldr - ok 19:27:39.0671 5728srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys 19:27:39.0671 5728srv - ok 19:27:39.0749 5728srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys 19:27:39.0749 5728srv2 - ok 19:27:39.0843 5728SrvHsfHDA (0c4540311e11664b245a263e1154cef8) C:\Windows\system32\DRIVERS\VSTAZL6.SYS 19:27:39.0843 5728SrvHsfHDA - ok 19:27:39.0952 5728SrvHsfV92 (02071d207a9858fbe3a48cbfd59c4a04) C:\Windows\system32\DRIVERS\VSTDPV6.SYS 19:27:39.0983 5728SrvHsfV92 - ok 19:27:40.0077 5728SrvHsfWinac (18e40c245dbfaf36fd0134a7ef2df396) C:\Windows\system32\DRIVERS\VSTCNXT6.SYS 19:27:40.0092 5728SrvHsfWinac - ok 19:27:40.0170 5728srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys 19:27:40.0170 5728srvnet - ok 19:27:40.0295 5728stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys 19:27:40.0295 5728stexstor - ok 19:27:40.0404 5728STHDA (8d1ce4322a35f840711b87927cb57c05) C:\Windows\system32\DRIVERS\stwrt64.sys 19:27:40.0420 5728STHDA - ok 19:27:40.0513 5728StillCam (decacb6921ded1a38642642685d77dac) C:\Windows\system32\DRIVERS\serscan.sys 19:27:40.0513 5728StillCam - ok 19:27:40.0560 5728swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys 19:27:40.0560 5728swenum - ok 19:27:40.0685 5728SynTP (924d711941956f7420a4925592be8253) C:\Windows\system32\DRIVERS\SynTP.sys 19:27:40.0685 5728SynTP - ok 19:27:40.0841 5728Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys 19:27:40.0872 5728Tcpip - ok 19:27:40.0997 5728TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys 19:27:41.0013 5728TCPIP6 - ok 19:27:41.0091 5728tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys 19:27:41.0091 5728tcpipreg - ok 19:27:41.0137 5728TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 19:27:41.0137 5728TDPIPE - ok 19:27:41.0184 5728TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys 19:27:41.0184 5728TDTCP - ok 19:27:41.0278 5728tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys 19:27:41.0278 5728tdx - ok 19:27:41.0325 5728TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys 19:27:41.0325 5728TermDD - ok 19:27:41.0418 5728tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys 19:27:41.0434 5728tssecsrv - ok 19:27:41.0527 5728TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys 19:27:41.0527 5728TsUsbFlt - ok 19:27:41.0637 5728tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys 19:27:41.0637 5728tunnel - ok 19:27:41.0699 5728uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys 19:27:41.0715 5728uagp35 - ok 19:27:41.0777 5728udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys 19:27:41.0793 5728udfs - ok 19:27:41.0839 5728uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys 19:27:41.0839 5728uliagpkx - ok 19:27:41.0949 5728umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys 19:27:41.0949 5728umbus - ok 19:27:42.0027 5728UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys 19:27:42.0027 5728UmPass - ok 19:27:42.0058 5728USBAAPL64 (54d4b48d443e7228bf64cf7cdc3118ac) C:\Windows\system32\Drivers\usbaapl64.sys 19:27:42.0058 5728USBAAPL64 - ok 19:27:42.0151 5728usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys 19:27:42.0151 5728usbccgp - ok 19:27:42.0229 5728USBCCID - ok 19:27:42.0307 5728usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys 19:27:42.0307 5728usbcir - ok 19:27:42.0401 5728usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys 19:27:42.0401 5728usbehci - ok 19:27:42.0479 5728usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys 19:27:42.0479 5728usbhub - ok 19:27:42.0573 5728usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys 19:27:42.0573 5728usbohci - ok 19:27:42.0651 5728usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 19:27:42.0651 5728usbprint - ok 19:27:42.0682 5728USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS 19:27:42.0682 5728USBSTOR - ok 19:27:42.0760 5728usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\DRIVERS\usbuhci.sys 19:27:42.0760 5728usbuhci - ok 19:27:42.0869 5728usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys 19:27:42.0869 5728usbvideo - ok 19:27:42.0978 5728vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys 19:27:42.0978 5728vdrvroot - ok 19:27:43.0072 5728vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 19:27:43.0072 5728vga - ok 19:27:43.0087 5728VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 19:27:43.0087 5728VgaSave - ok 19:27:43.0165 5728vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys 19:27:43.0181 5728vhdmp - ok 19:27:43.0243 5728viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys 19:27:43.0243 5728viaide - ok 19:27:43.0290 5728volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys 19:27:43.0290 5728volmgr - ok 19:27:43.0337 5728volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys 19:27:43.0337 5728volmgrx - ok 19:27:43.0446 5728volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys 19:27:43.0446 5728volsnap - ok 19:27:43.0524 5728vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys 19:27:43.0524 5728vsmraid - ok 19:27:43.0587 5728vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys 19:27:43.0587 5728vwifibus - ok 19:27:43.0711 5728vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys 19:27:43.0711 5728vwififlt - ok 19:27:43.0805 5728WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys 19:27:43.0805 5728WacomPen - ok 19:27:43.0930 5728WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 19:27:43.0930 5728WANARP - ok 19:27:43.0945 5728Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 19:27:43.0945 5728Wanarpv6 - ok 19:27:44.0055 5728Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys 19:27:44.0055 5728Wd - ok 19:27:44.0133 5728Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 19:27:44.0148 5728Wdf01000 - ok 19:27:44.0226 5728WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 19:27:44.0226 5728WfpLwf - ok 19:27:44.0257 5728WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 19:27:44.0257 5728WIMMount - ok 19:27:44.0413 5728WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys 19:27:44.0413 5728WinUsb - ok 19:27:44.0523 5728WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys 19:27:44.0523 5728WmiAcpi - ok 19:27:44.0632 5728ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 19:27:44.0632 5728ws2ifsl - ok 19:27:44.0741 5728WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys 19:27:44.0741 5728WudfPf - ok 19:27:44.0803 5728WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys 19:27:44.0803 5728WUDFRd - ok 19:27:44.0913 5728yukonw7 (b3eeacf62445e24fbb2cd4b0fb4db026) C:\Windows\system32\DRIVERS\yk62x64.sys 19:27:44.0928 5728yukonw7 - ok 19:27:44.0959 5728MBR (0x1B8) (8ca37966eb3c750d08ac01dcd8dda115) \Device\Harddisk0\DR0 19:27:44.0959 5728\Device\Harddisk0\DR0 - ok 19:27:44.0959 5728Boot (0x1200) (04dfb600a5d3c97f2dfd11dd84c1c8ac) \Device\Harddisk0\DR0\Partition0 19:27:44.0959 5728\Device\Harddisk0\DR0\Partition0 - ok 19:27:44.0975 5728Boot (0x1200) (5ec31804363fa57ade9e699acbdfa4fc) \Device\Harddisk0\DR0\Partition1 19:27:44.0975 5728\Device\Harddisk0\DR0\Partition1 - ok 19:27:45.0006 5728Boot (0x1200) (3c5b591e42ef80d39e7681c659ee5aa9) \Device\Harddisk0\DR0\Partition2 19:27:45.0006 5728\Device\Harddisk0\DR0\Partition2 - ok 19:27:45.0006 5728============================================================ 19:27:45.0006 5728Scan finished 19:27:45.0006 5728============================================================ 19:27:45.0037 5848Detected object count: 0 19:27:45.0037 5848Actual detected object count: 0 19:28:43.0272 4952============================================================ 19:28:43.0272 4952Scan started 19:28:43.0272 4952Mode: Manual; 19:28:43.0272 4952============================================================ 19:28:44.0208 49521394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys 19:28:44.0208 49521394ohci - ok 19:28:44.0271 4952Accelerometer (1cffe9c06e66a57dae1452e449a58240) C:\Windows\system32\DRIVERS\Accelerometer.sys 19:28:44.0271 4952Accelerometer - ok 19:28:44.0349 4952ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys 19:28:44.0364 4952ACPI - ok 19:28:44.0442 4952AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys 19:28:44.0442 4952AcpiPmi - ok 19:28:44.0489 4952adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys 19:28:44.0505 4952adp94xx - ok 19:28:44.0583 4952adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys 19:28:44.0583 4952adpahci - ok 19:28:44.0661 4952adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys 19:28:44.0676 4952adpu320 - ok 19:28:44.0723 4952AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys 19:28:44.0723 4952AFD - ok 19:28:44.0848 4952AgereSoftModem (af4748ef93416159459769a24a0053af) C:\Windows\system32\DRIVERS\agrsm64.sys 19:28:44.0863 4952AgereSoftModem - ok 19:28:44.0941 4952agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys 19:28:44.0941 4952agp440 - ok 19:28:45.0035 4952aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys 19:28:45.0035 4952aliide - ok 19:28:45.0097 4952amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys 19:28:45.0097 4952amdide - ok 19:28:45.0129 4952AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys 19:28:45.0129 4952AmdK8 - ok 19:28:45.0207 4952AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys 19:28:45.0207 4952AmdPPM - ok 19:28:45.0269 4952amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys 19:28:45.0269 4952amdsata - ok 19:28:45.0300 4952amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys 19:28:45.0300 4952amdsbs - ok 19:28:45.0378 4952amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys 19:28:45.0378 4952amdxata - ok 19:28:45.0409 4952AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys 19:28:45.0409 4952AppID - ok 19:28:45.0503 4952arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys 19:28:45.0503 4952arc - ok 19:28:45.0534 4952arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys 19:28:45.0534 4952arcsas - ok 19:28:45.0581 4952AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 19:28:45.0581 4952AsyncMac - ok 19:28:45.0612 4952atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys 19:28:45.0628 4952atapi - ok 19:28:45.0815 4952atikmdag (3efd964d52221360af0673cd61c2f4f5) C:\Windows\system32\drivers\atikmdag.sys 19:28:45.0862 4952atikmdag - ok 19:28:46.0018 4952AVGIDSEH (f823d184b8e8ffb8da3ead45dbf5bd6a) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys 19:28:46.0018 4952AVGIDSEH - ok 19:28:46.0065 4952Avgtdia (11f36d3ea82d9db9aa05a476a210551b) C:\Windows\system32\DRIVERS\avgtdia.sys 19:28:46.0065 4952Avgtdia - ok 19:28:46.0143 4952b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys 19:28:46.0143 4952b06bdrv - ok 19:28:46.0221 4952b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 19:28:46.0221 4952b57nd60a - ok 19:28:46.0377 4952BCM43XX (0e14a0071fe26a570bcaff5401014717) C:\Windows\system32\DRIVERS\bcmwl664.sys 19:28:46.0408 4952BCM43XX - ok 19:28:46.0486 4952Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 19:28:46.0486 4952Beep - ok 19:28:46.0517 4952blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 19:28:46.0517 4952blbdrive - ok 19:28:46.0611 4952bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys 19:28:46.0611 4952bowser - ok 19:28:46.0642 4952BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys 19:28:46.0642 4952BrFiltLo - ok 19:28:46.0735 4952BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys 19:28:46.0735 4952BrFiltUp - ok 19:28:46.0829 4952Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 19:28:46.0829 4952Brserid - ok 19:28:46.0907 4952BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 19:28:46.0907 4952BrSerWdm - ok 19:28:46.0923 4952BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 19:28:46.0923 4952BrUsbMdm - ok 19:28:47.0001 4952BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 19:28:47.0001 4952BrUsbSer - ok 19:28:47.0032 4952BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys 19:28:47.0032 4952BTHMODEM - ok 19:28:47.0125 4952cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 19:28:47.0125 4952cdfs - ok 19:28:47.0219 4952cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys 19:28:47.0219 4952cdrom - ok 19:28:47.0297 4952circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys 19:28:47.0297 4952circlass - ok 19:28:47.0375 4952CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 19:28:47.0375 4952CLFS - ok 19:28:47.0469 4952CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 19:28:47.0469 4952CmBatt - ok 19:28:47.0531 4952cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys 19:28:47.0531 4952cmdide - ok 19:28:47.0578 4952CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys 19:28:47.0578 4952CNG - ok 19:28:47.0656 4952Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys 19:28:47.0656 4952Compbatt - ok 19:28:47.0749 4952CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys 19:28:47.0749 4952CompositeBus - ok 19:28:47.0827 4952crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys 19:28:47.0827 4952crcdisk - ok 19:28:47.0937 4952DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys 19:28:47.0937 4952DfsC - ok 19:28:48.0030 4952discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 19:28:48.0030 4952discache - ok 19:28:48.0061 4952Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys 19:28:48.0061 4952Disk - ok 19:28:48.0155 4952drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 19:28:48.0155 4952drmkaud - ok 19:28:48.0249 4952DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys 19:28:48.0264 4952DXGKrnl - ok 19:28:48.0420 4952ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys 19:28:48.0451 4952ebdrv - ok 19:28:48.0561 4952elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys 19:28:48.0561 4952elxstor - ok 19:28:48.0639 4952enecir (524c79054636d2e5751169005006460b) C:\Windows\system32\DRIVERS\enecir.sys 19:28:48.0639 4952enecir - ok 19:28:48.0685 4952ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys 19:28:48.0685 4952ErrDev - ok 19:28:48.0779 4952exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 19:28:48.0795 4952exfat - ok 19:28:48.0873 4952fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 19:28:48.0873 4952fastfat - ok 19:28:48.0951 4952fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys 19:28:48.0951 4952fdc - ok 19:28:49.0044 4952FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 19:28:49.0044 4952FileInfo - ok 19:28:49.0091 4952Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 19:28:49.0091 4952Filetrace - ok 19:28:49.0138 4952flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys 19:28:49.0138 4952flpydisk - ok 19:28:49.0216 4952FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys 19:28:49.0216 4952FltMgr - ok 19:28:49.0294 4952FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 19:28:49.0294 4952FsDepends - ok 19:28:49.0325 4952Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 19:28:49.0325 4952Fs_Rec - ok 19:28:49.0419 4952fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys 19:28:49.0419 4952fvevol - ok 19:28:49.0497 4952gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys 19:28:49.0497 4952gagp30kx - ok 19:28:49.0575 4952GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 19:28:49.0575 4952GEARAspiWDM - ok 19:28:49.0637 4952hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 19:28:49.0637 4952hcw85cir - ok 19:28:49.0731 4952HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys 19:28:49.0731 4952HdAudAddService - ok 19:28:49.0793 4952HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys 19:28:49.0793 4952HDAudBus - ok 19:28:49.0871 4952HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys 19:28:49.0871 4952HidBatt - ok 19:28:49.0902 4952HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys 19:28:49.0902 4952HidBth - ok 19:28:49.0980 4952HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys 19:28:49.0980 4952HidIr - ok 19:28:50.0012 4952HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys 19:28:50.0012 4952HidUsb - ok 19:28:50.0090 4952hpdskflt (05712fddbd45a5864eb326faabc6a4e3) C:\Windows\system32\DRIVERS\hpdskflt.sys 19:28:50.0090 4952hpdskflt - ok 19:28:50.0152 4952HpqKbFiltr (9af482d058be59cc28bce52e7c4b747c) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys 19:28:50.0168 4952HpqKbFiltr - ok 19:28:50.0199 4952HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys 19:28:50.0199 4952HpSAMD - ok 19:28:50.0324 4952HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys 19:28:50.0324 4952HTTP - ok 19:28:50.0402 4952hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys 19:28:50.0402 4952hwpolicy - ok 19:28:50.0433 4952i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys 19:28:50.0433 4952i8042prt - ok 19:28:50.0542 4952iaStor (1d004cb1da6323b1f55caef7f94b61d9) C:\Windows\system32\DRIVERS\iaStor.sys 19:28:50.0542 4952iaStor - ok 19:28:50.0636 4952iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys 19:28:50.0651 4952iaStorV - ok 19:28:50.0916 4952igfx (3c3f27002abc69c5afe29cbe6cf7addf) C:\Windows\system32\DRIVERS\igdkmd64.sys 19:28:50.0979 4952igfx - ok 19:28:51.0150 4952iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys 19:28:51.0150 4952iirsp - ok 19:28:51.0244 4952IntcHdmiAddService (88a20fa54c73ded4e8dac764e9130ae9) C:\Windows\system32\drivers\IntcHdmi.sys 19:28:51.0244 4952IntcHdmiAddService - ok 19:28:51.0306 4952intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys 19:28:51.0306 4952intelide - ok 19:28:51.0338 4952intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 19:28:51.0338 4952intelppm - ok 19:28:51.0431 4952IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys 19:28:51.0431 4952IpFilterDriver - ok 19:28:51.0462 4952IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys 19:28:51.0462 4952IPMIDRV - ok 19:28:51.0540 4952IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 19:28:51.0540 4952IPNAT - ok 19:28:51.0618 4952IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 19:28:51.0634 4952IRENUM - ok 19:28:51.0712 4952isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys 19:28:51.0712 4952isapnp - ok 19:28:51.0743 4952iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys 19:28:51.0759 4952iScsiPrt - ok 19:28:51.0821 4952kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys 19:28:51.0821 4952kbdclass - ok 19:28:51.0868 4952kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys 19:28:51.0868 4952kbdhid - ok 19:28:51.0946 4952KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys 19:28:51.0946 4952KSecDD - ok 19:28:51.0977 4952KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys 19:28:51.0977 4952KSecPkg - ok 19:28:52.0055 4952ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 19:28:52.0055 4952ksthunk - ok 19:28:52.0102 4952lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 19:28:52.0102 4952lltdio - ok 19:28:52.0196 4952LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys 19:28:52.0196 4952LSI_FC - ok 19:28:52.0211 4952LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys 19:28:52.0211 4952LSI_SAS - ok 19:28:52.0289 4952LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys 19:28:52.0289 4952LSI_SAS2 - ok 19:28:52.0383 4952LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a)Save these instructions so you can have access to them while in Safe Mode. Please click here to download AVP Tool by Kaspersky.
•Then click on Scan at the to right hand Corner. •It will automatically Neutralize any objects found. •If some objects are left un-neutralized then click the button that says Neutralize all •If it says it cannot be neutralized then choose the delete option when prompted. •After that is done click on the reports button at the bottom and save it to file name it Kas. •Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply. Note: This tool will self uninstall when you close it so please save the log before closing it. I had a problem trying to save the log while in the SAFE MODE...It did say there were no threats. Is it important for you to see the log...? I can try again. Also please note that in the bottom right hand corner of the screen I get a "test mode" Rebuild 7601. Would this account for any instability...?Quote It did say there were no threats. Is it important for you to see the log...?No. If there were no threats I don't need to see it. Quote Also please note that in the bottom right hand corner of the screen I get a "test mode" Rebuild 7601. Would this account for any instability...?What do you mean by instability? My main problem is that programs. IE, etc sudeenly they start FLASHING o n and off and not responding can be read at the top of the program. It seems to happen to all programs and websites.All the scans are not picking up any infections. I would suspect that there is something wrong with the video card or some other piece of hardware in your computer. You could start another thread in the proper forum for the OS of your computer and perhaps, someone could help your there. |
|
4258. |
Solve : Taking charge? |
Answer» HI everyone! |
|
4259. |
Solve : Norton Anti-Virus2011? |
Answer» Hey guys. I'm new here and I thought I/d let you know that I have Norton Anti-Virus Security and it has to be one of the best out there! It's very easy to USE and it works very well at apprehending viruses. Aside from the COST, I think everyone who is currently dealing with viruses should use the free trial to their needs. Aside from the cost, I think everyone who is currently dealing with viruses should use the free trial to their needs.So, just use it during the free trial period, right? Quote from: reddevilggg on December 05, 2011, 03:47:00 AM I think you are the only person on this forum who would actually recommend Norton. There are better Anti-Viruses out there.Quote from: Allan on December 05, 2011, 05:29:53 AM NAV is an excellent product. It's among the best anti virus utilities available. I've got absolutely no idea why i wrote my first response, it was a shock when i just read it. Allan is right, of course. Now, where is my head............??I posted this a couple of weeks ago on another thread. Quote Maximum PC magazine just did a rating on av programs. They rated Norton as best of the paid programs with a 9+ rating and all of the free programs rated from 6 to 8. Based on that you usually, but not always, get what you pay for since McAfee was rated a 5.I say that the "right" antivirus is a combo of personal preference and detection. While another product may offer slightly more detection, some feel content with an AV that they prefer. Most modern AV solutions are similar in detection and on par with each other. KEYWORD: most. |
|
4260. |
Solve : Question about AVG Free 2012?? |
Answer» So, I kept getting threats from 'Trojan.fakealert' and I ssent them to the virus vault. I CLEARED the virus vault and today while scanning, it said in the scan RESULTS I have an infection called: Trojan Horse Generic26.xku So, I kept getting threats from 'Trojan.fakealert' and I ssent them to the virus vault. I cleared the virus vault and today while scanning, it said in the scan results I have an infection called: Trojan Horse Generic26.xkuAs long as it remains in the vault it is HARMLESS. Yes, you can clear the vault.Update your software protection. Microsoft Defender maybe Run SPYBOT, from safer-networking.org |
|
4261. |
Solve : Google redirrection virus? |
Answer» Quote I didn't try it YET. I wait for your answer... Please do not run any scans unless I ask you to do so. Save these instructions so you can have access to them while in Safe Mode. Please CLICK here to download AVP Tool by Kaspersky.
•Then click on Scan at the to right hand Corner. •It will automatically Neutralize any objects found. •If some objects are left un-neutralized then click the button that says Neutralize all •If it says it cannot be neutralized then choose the delete option when PROMPTED. •After that is done click on the reports button at the bottom and save it to file name it Kas. •Save it SOMEWHERE convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply. Note: This tool will self uninstall when you close it so please save the log before closing it.Well.... They didn't want to wait anymore... they took it to a repair shop... I guess it's their problem now Sorry for that But thank you for all your help.Too bad, I would loved to know how to clean it... and know what was this virus...Quote They didn't want to wait anymore... they took it to a repair shop...They'll just re-format it. I will lock this thread. If you need it re-opened, please send me a PM. |
|
4262. |
Solve : remove spyware removal, trojan rootkit? |
Answer» Go to this link to create a Rescue CD or to this site to create a Rescue USB. Carefully follow all the instructions for whichever method you choose.The rescue cds didn't work. But I will tell you this I was finally able to boot from my Windows cd and do a fresh INSTALL thank you guys for everything.You're welcome. It's too bad it had to come to that but some infections damage the FILES so badly that there's no other option. I will lock this thread. If you need it re-opened, PLEASE send me a PM. |
|
4263. |
Solve : relevant knowledge is back 3rd time? |
Answer» Quote can i just leave the programs you suggested to download?The only two that you should keep is SAS and MBAM. Update them and run them on a regular basis. Quote relevant knowledge is really bad for the computer?Just annoying. There no EVIDENCE of Relevant Knowledge on your computer. What's makes you think that it is there? You should uninstall the two programs listed below because they have some level of spyware. GamesBar 2.0.1.82 MyPoints Point FinderI'm assuming we are done. tyvmQuote from: darcomputer on December 13, 2011, 10:05:13 PM I'm assuming we are done. tyvmWe can run a whole bunch of scans but it would be for nothing if you're not having any PROBLEMS. Are you still having problems?except for facebook games yes tysoo very much, i have done as you said Quote from: darcomputer on December 14, 2011, 09:19:40 PM except for facebook games yes tysoo very much, i have done as you saidPlease explain the facebook games problem to me again.When playing The Sims on Facebook every 6 minutes i would be asked to reload. i now have a terrible problem. i thought the computer froze while updating my nvidia and then the computer started to turn itself off, checked and both video and ethernet controllers are gone. i'm on my FRIENDS laptop. computer. It went into safe mode last time i turned it on. haven't turned on today out of fear I have posted in the driver forum yesterday at 10am Waiting patiently. thank you for listening. i guess we're really done now, again thank you from the bottom of my heart for your help until next time You're welcome. I'm sorry I couldn't be more helpful. I will lock this thread. If you need it re-opened, please send me a pm. |
|
4264. |
Solve : McAfee app installed? |
Answer» I've just installed the LATEST FOXIT Reader - this download included "McAfee Security Scan Plus", which I suppose is a virus checking program. I am a bit wary of this - I already have Avira Anti Virus, and Malwarebyte, and Super Antispyware - I don't want to have a conflicting AV program. Is the McAfee app. any good or would it be best to uninstall? Advice appreciated. Uninstall it.McAfee Security Scan Plus actively CHECKS your computer for anti-virus software, firewall protection, and web security, and threats in your OPEN applications. |
|
4265. |
Solve : IRQL_NOT_LESS_OR_EQUAL caused by a virus .exe? |
Answer» Logs From OTL Combofix was detected as a malware.You need to turn off your protection. Please try it again. Quote I got a bosd while running scans using malware anti malbytesRe-boot in Safe Mode and try running MBAM.sorry for the delay again, im running the tests atm |
|
4266. |
Solve : Stupid Virus Removal Question? |
Answer» I have to sort through some old files and DISKS for WORK... But they were downloaded from a sketchy source. |
|
4267. |
Solve : whitesmoke toolbar virus trouble? |
Answer» ComboFix 11-03-13.02 - Connor 03/14/2011 17:28:33.3.2 - x64 R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616] R3 pctNdis;PC Tools Firewall Intermediate Filter Service;c:\windows\system32\DRIVERS\pctNdis64.sys R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe R3 X6va003;X6va003;c:\users\Connor\AppData\Local\Temp\003CFBB.tmp R3 X6va005;X6va005;c:\users\Connor\AppData\Local\Temp\005845B.tmp R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 47128] R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-10 369688] S1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi64.sys S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752] S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136] S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys [2007-07-24 14904] S2 CinemaNow Service;CinemaNow Service;c:\program files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe [2009-06-11 127352] S2 CwAltaService20;ContentWatch;c:\program files (x86)\ContentWatch\Internet Protection\cwsvc.exe [2010-11-16 2109440] S2 FastBootAgent;FastBootAgent;c:\windows\SysWOW64\Fast Boot\FastBootAgent.exe [2009-07-24 306232] S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2010-12-06 2101640] S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [2011-02-25 23680] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256] S2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe S2 vpnclient;PacketiX VPN Client;c:\program files (x86)\PacketiX VPN Client English\vpnclient.exe [2008-05-15 2478080] S2 WTouchService;WTouch Service;c:\program files\WTouch\WTouchService.exe [2009-11-24 127784] S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys S3 Neo_VPN;VPN Client Device Driver - VPN;c:\windows\system32\DRIVERS\Neo_0014.sys S3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys S3 PCTFW-PacketFilter;PCTools Firewall - PACKET filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter64.sys S3 pctNdisMP;PC Tools Driver;c:\windows\system32\DRIVERS\pctNdis64.sys S3 pctplfw;pctplfw;c:\windows\System32\drivers\pctplfw64.sys S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys . . --- Other Services/Drivers In Memory --- . *Deregistered* - pctESPInject . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] AkamaiREG_MULTI_SZ Akamai . . --------- x86-64 ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1] @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}" [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}] 2007-06-01 23:52159744----a-w-c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe" [BU] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 1436224] . ------- Supplementary Scan ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.bing.com/?pc=Z023&form=ZGAPHP mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 LSP: c:\windows\system32\cwalsp.dll Trusted Zone: cinemanow.com Trusted Zone: real.com\rhap-app-4-0 Trusted Zone: real.com\rhapreg Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - DPF: {E2729F99-A050-4F4D-AE9F-7492C5532F49} - hxxp://down.hangame.co.jp/jp/dist/hgtagent2/hgtagent2.cab DPF: {F8160836-0C11-4CA4-AD87-944542C7BCBD} - hxxp://down.hangame.co.jp/jp/purple/launcher/PubPlugin.cab FF - ProfilePath - c:\users\Connor\AppData\Roaming\Mozilla\Firefox\Profiles\ecx7ksuv.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/?pc=Z023&form=ZGAPHP FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z023&form=ZGAADF&q= FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF - Ext: Move Media Player: [emailprotected] - c:\users\Connor\AppData\Roaming\Move Networks FF - Ext: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - %profile%\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8} FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} FF - Ext: flashget3 Extension: {DB9127A2-3381-41ec-82B3-1B6ED4C6F29A} - %profile%\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A} FF - Ext: SyncPlaces: [emailprotected] - %profile%\extensions\[emailprotected] . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) WebBrowser-{D22F6F66-2F47-4184-8625-FBFA4CBDB7CE} - (no file) . . . [HKEY_LOCAL_MACHINE\system\ControlSet002\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . [HKEY_LOCAL_MACHINE\system\ControlSet002\services\X6va003] "ImagePath"="\??\c:\users\Connor\AppData\Local\Temp\003CFBB.tmp" . [HKEY_LOCAL_MACHINE\system\ControlSet002\services\X6va005] "ImagePath"="\??\c:\users\Connor\AppData\Local\Temp\005845B.tmp" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet002\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Other Running Processes ------------------------ . c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe c:\program files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe c:\program files\ATKGFNEX\GFNEXSrv.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe c:\program files (x86)\ASUS\ATK Hotkey\HControl.exe c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe c:\program files (x86)\ASUS\ATK Hotkey\ATKOSD.exe c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe c:\program files (x86)\ASUS\ATK Hotkey\KBFiltr.exe c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe c:\program files (x86)\ASUS\ATK Hotkey\WDC.exe c:\program files (x86)\ASUS\ASUS Live Update\ALU.exe . ************************************************************************** . Completion time: 2011-03-14 17:58:55 - machine was rebooted ComboFix-quarantined-files.txt 2011-03-14 21:58 ComboFix2.txt 2011-03-02 19:28 ComboFix3.txt 2011-03-01 00:27 . Pre-Run: 137,372,893,184 bytes free POST-Run: 137,028,952,064 bytes free . - - End Of File - - F509B404EEE2E4C542C804E8620E1182 Please download Rooter and Save it to your desktop.
Have tried all the above actions to remove Whitesmoke At first it looked like Malwarebytes took care of it but Whitesmoke never actually is removed. Have tried ComboFix (placed on desktop) and now OldTimer with your suggested fix code. Here is the results from OldTimer. Not sure yet if it worked, just trying to capture the text into the string. I will re-post the result if Whitesmoke is finally off my computer. Thanks for your time is helping folks on this, it is great that you do that. ....................................... ... All processes killed ========== OTL ========== ========== FILES ========== File\Folder C:\found.000 not found. File\Folder c:\users\Connor\AppData\Local\Temp\00199D8.tmp not found. ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\system\ControlSet002\services\X6va001\ not found. HKEY_LOCAL_MACHINE\system\ControlSet002\services\X6va001\\"ImagePath"|"\??\c:\users\Connor\AppData\Local\Temp\00199D8.tmp" /E : value set successfully! ========== SERVICES/DRIVERS ========== Error: No service named X6va001 was found to stop! Service\Driver key X6va001 not found. ========== COMMANDS ========== C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: All Users User: Anne ->Temp folder emptied: 61088 bytes ->Temporary Internet Files folder emptied: 119918476 bytes ->Java cache emptied: 144187 bytes ->Google Chrome cache emptied: 7385685 bytes ->Flash cache emptied: 83496 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56502 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public ->Temp folder emptied: 0 bytes User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1610 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 122.00 mb OTL by OldTimer - Version 3.2.31.0 log created on 12302011_101001 Files\Folders moved on Reboot... C:\Users\Anne\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\Anne\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully. C:\Users\Anne\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GPS4ZGF6\1053965053[1].htm moved successfully. C:\Users\Anne\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GPS4ZGF6\activityi;src=2542116;type=clien612;cat=chromx;u2=;u1=;ord=1;num=5615028436588[1].htm moved successfully. C:\Users\Anne\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CANMWGVQ\cJZKeOuBrn4kERxqtaUH3fY6323mHUZFJMgTvxaG2iE[1].eot moved successfully. Registry entries deleted on Reboot... |
|
4268. |
Solve : Cannot view hidden files.? |
Answer» Hi when I go into RIBBON and attempt to view hidden FILES it un-ticks itself. I have gone in file options STILL does not WORK and I have changed the regedit still not working. I had hear this may be caused by a virus so I did a system scan with bitdefender total security 2016 but the problem still persists. OS is win10.What ribbon? What exactly are we talking about?Ribbon as in the one in file explorer. |
|
4269. |
Solve : Question about ransomeware? |
Answer» I've just listened to an item on radio about "ransomware" and the effect it has on pcs attacked by this malware. I gather that it completely locks the pc and demands are made for money to unlock. I appreciate that common sense and good av and malware protection, kept up-to-date, can help avoid problems but if your pc does GET infected what can you do yourself about it? What would be the best course of action - if the SYSTEM is locked then presumably you're stymied? |
|
4270. |
Solve : browser redirecting to a site? |
Answer» this is what happens, when i type a key word onto the address bar of google chrome.and press enter it directs me to this |
|
4271. |
Solve : Sony VAIO Shut Down Today...Help? |
Answer» Quote Also it never asked so I never did reboot. Is this ok?Yup, that's ok. P2P - I see you have P2P software installed on your machine. (BitLord 2.0) We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation. Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares. I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs. ************************************************** Update Your Java (JRE) Old versions of Java have vulnerabilities that malware can use to infect your system. First Verify your Java Version If there are any other version(s) installed then update now. Get the new version (if needed) If your version is out of date install the newest version of the Sun Java Runtime Environment. Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update. Be sure to close ALL open web browsers before starting the installation. Remove any old versions 1. Download JavaRa and unzip the file to your Desktop. 2. Open JavaRA.exe and choose Remove Older Versions 3. Once complete exit JavaRA. Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer. *************************************************** Download OTL to your desktop. * Open OTL * Copy and Paste the following text in the codebox into the Custom Scans/Fixes window. Code: [Select]:OTL uURLSearchHooks: H - No File BHO: Complitly: {d27fc31c-6e3d-4305-8d53-acdaefa5f862} - c:\users\johnny ola\appdata\roaming\complitly\Complitly.dll mRun: [<NO NAME>] :COMMANDS [resethosts] [purity] [start explorer] * Click Run Fix * OTLI2 may ask to reboot the machine. Please do so if asked. * Click OK * A report will open. Copy and Paste that report in your next reply. **************************************************************** Download ComboFix by sUBs from one of the below links. Be sure to save it to the Desktop. link # 1 Link # 2 If you are using Firefox, make sure that your download settings are as follows: * Tools->Options->Main tab * Set to "Always ask me where to Save the files". Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Right-click combofix.exe and select Run as Administrator and follow the prompts. When finished, ComboFix will produce a log for you. Post the ComboFix login your next reply. NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.OK Dave, few things: 1) PC has been running fine until the issue this week, since, it has been slower and I have heard more grinding, so once we fix this issue, I'd like to know if the PC is fine or if it needs work. 2) Checked Java, was out of date, now it is up to date. 3) So can I delete: -Java RA -OTL -Combo fix? 4) Logs OTL Quote ========== OTL ========== Combofix Quote ComboFix 11-12-29.04 - Johnny Ola 12/29/2011 14:31:52.1.2 - x86Quote I have heard more grindingThat sounds like either your hard drive or one of the fans. Quote Java RAYou can uninstall/ delete Java RA. We'll remove the others when we're finished. SysProt Antirootkit Download SysProt Antirootkit from the link below (you will find it at the bottom of the page under attachments, or you can get it from one of the mirrors). http://sites.google.com/site/sysprotantirootkit/ Unzip it into a folder on your desktop.
2) Scan: Quote SysProt AntiRootkit v1.0.1.0See Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan COMPLETES, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt I unchecked remove found threats, is that ok?I just ran it, found nothing, but it didn't open any log, when I was done it asked if I wanted the 30 day trial.So, how's your computer running now?Pretty good, it got better last Friday. Can we call it clear, or is there another scan, any, we can do, just to be sure?Quote Pretty good, it got better last Friday.No. That's it. Your computer is clean. We can now do some cleanup. Update Your Java (JRE) Old versions of Java have vulnerabilities that malware can use to infect your system. First Verify your Java Version If there are any other version(s) installed then update now. Get the new version (if needed) If your version is out of date install the newest version of the Sun Java Runtime Environment. Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update. Be sure to close ALL open web browsers before starting the installation. Remove any old versions 1. Download JavaRa and unzip the file to your Desktop. 2. Open JavaRA.exe and choose Remove Older Versions 3. Once complete exit JavaRA. Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer. ******************************************************* To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
*************************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run UNINTERRUPTED until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ********************************************** Go to Microsoft Windows Update and get all CRITICAL updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! 1) Java is up to date 2) Typed in combofix as you requested, could not find anything 3) Ran OTL, cleared a few things, but had to go into downloads, program files, and uninstall to remove everything 4) TFC problems, first downloaded it, but had an error. Then downloaded it, get it to run, took nearly 10 minutes, did not finish, due to error. Question: 1) Is my PC safe, and clear? 2) Do I really need TFC, or can I just use CC Cleaner. Is it alarming that it did not work?Quote Is my PC safe, and clear?Yes. Quote Do I really need TFC, or can I just use CC Cleaner.Yes, you can use CCleaner and also do a disk clean up occasionally on your harddrive Quote Is it alarming that it did not work?Not really. I will lock this thread. If you need it re-opened, please send me a pm. |
|
4272. |
Solve : Can't Update Windows Updates? |
Answer» Is there still a problem with updating?Yes. It gets to "installing NUMBER 7 of 86" then freezes.I was speaking to a friend last NIGHT who re-furbishes COMPUTERS for schools and he said for almost a month they have been having trouble downloading updates for Windows 7. He said sometimes if you leave the computer on long enough you will get the updates.I'll give it a try. I'll leave it on all night.Just to give you a update, I restarted my computer and STARTED 80 updates over again. It's been 4 hours and its still at "installing update 1 of 80". |
|
4273. |
Solve : Question - Scan a HDD as an external drive?? |
Answer» Hi, Quote from above website.I personally have a USB 2.0 WD external 500GB HDD which takes around twice to thrice as long to complete file transfers when compared to my internal HDD, so.. I wouldn't be surprised at the statistics above. Note that the above statistics use external SATA. Here are a few professional links concerning SATA vs USB vs eSATA: http://www.wfu.edu/~yipcw/atg/disk/usb3/ http://blogs.gurulabs.com/dax/2009/07/esata-vs-sata-v.html http://www.rt.db.erau.edu/655s08/655webUSBSAT/index.htmYou might also try ClamWin Portable, which runs from a flash drive. If you GET it, update its virus definitions before running a virus scan. Ok, I will try it. So, If I run a scan of a HDD (That has an OS of another machine) as an external HDD on another machine, it's good ?Quote from: nasroo7 on December 24, 2011, 01:27:55 PM So, If I run a scan of a HDD (That has an OS of another machine) as an external HDD on another machine, it's good ?Well, running a scan in such a way may be necessary if the OS on the external HDD has already been seriously compromised by a virus to the extent where it is unusable.Quote from: Transfusion on December 23, 2011, 08:47:03 PM There is a difference between the transfer speed of direct SATA connection to the motherboard and connection via USB enclosure. Not really. Very few magnetic platter drives come very close to saturating ATA-6, which has a max speed of 133mbps. For SATA, while there is a higher maximum throughput, I doubt even a really fast SSD could fully saturate the 480mbps USB. The fact is, though, that the test you quote is somewhat stupidand not really a test. All it proves is that two drives from different manufacturers are likely to have different properties. A better test would be to use the same drive INTERNALLY and EXTERNALLY, rather than testing the speed difference between an external drive (which typically are built using 5200RPM drives) compared to a internal drive. Basically, the test isn't testing the bus speed the devices are connected to at all, merely the speeds of the devices. Quote I personally have a USB 2.0 WD external 500GB HDD which takes around twice to thrice as long to complete file transfers when compared to my internal HDDThat's because of the drives, not the bus (USB/SATA) being used. I have several IDE enclosures and I used to have a SATA enclosure and there was no marked difference in transfer speeds between when I used a drive in the enclosure or had them inside a computer (with the exception of when connected to a machine that only had USB 1.1, of course). A slow drive was slow regardless of whether it was plugged into the enclosure or not. And faster drives didn't seem affected by being connected via USB. Quote Here are a few professional links concerning SATA vs USB vs eSATA: Of course the ACTUAL Bus speeds between SATA and USB differ. But as far as I'm aware there aren't any drives made yet that can come close to saturating the USB bandwidth. As to the topic, though- it's usually better to scan outside the OS, which includes using the drive as an external in another machine. Primarily because if the system is infected you can't trust it for anything, including scans.I love you, BC, you keep continuing to supplement my knowledge and fill in the myriad of gaps that I have. I sincerely wish you a Merry Christmas! I do WONDER why http://techreport.com/articles.x/18077 claims that "Every hard drive we've tested saturates [USB 2.0's quoted 480Mbps.]" Even if I had a 5200 RPM external drive which presumably would never be able to saturate USB 2.0 it shouldn't spend twice as much time completing file transfers as my internal 5400 RPM drive...You got me thinking about USB 3.0 drives. That means... manufacturers claim that the transfer speed will be faster due to the fact that the enclosure supports USB 3.0(which BTW has a quoted max speed of 5Gbps, or 600MB/s) but in fact all they have to do is slip a 7200RPM drive in, which will clearly be an improvement over a 5200RPM one? And then charge an extreme premium for the USB 3.0 port? EDIT: I just realized 480 Mbps is 60 MegaBytes/second. USB 2.0 is half-duplex. So... only 30 MB/s max in both directions? Any 7200 RPM drive will easily saturate that...Quote Even if I had a 5200 RPM external drive which presumably would never be able to saturate USB 2.0 it shouldn't spend twice as much time completing file transfers as my internal 5400 RPM drive...It will if the external drive sucks. Quote You got me thinking about USB 3.0 drives. That means... manufacturers claim that the transfer speed will be faster due to the fact that the enclosure supports USB 3.0(which BTW has a quoted max speed of 5Gbps, or 600MB/s) but in fact all they have to do is slip a 7200RPM drive in, which will clearly be an improvement over a 5200RPM one? And then charge an extreme premium for the USB 3.0 port?Not really. While it seems that some drives can in fact saturate USB2 (though I'm not clear what my test with an external enclosure and a EIDE drive shows), it's more likely they can stick with the same internal drive and get a speed boost anyway. I think the RPM speed of the drive influences access time more than speed, also. Quote EDIT: I just realized 480 Mbps is 60 MegaBytes/second. USB 2.0 is half-duplex. So... only 30 MB/s max in both directions? Any 7200 RPM drive will easily saturate that...USB has a number of modes, which includes changing the upstream/downstream bandwidth. However even in that light there are a number of drives that come close to and even exceed USB's quoted maximum as a result of that. I've never actually seen these drives, though, and my only sources are the same types of sites that I tend to avoid (such as the one you linked). here are the results of some of the tests I did myself just now. using my C: (internal) drive versus one of my external drives. My internal drive had a average transfer rate of around 80MB (Megabytes) a second. This would definitely saturate USB2, so I was wrong about that. testing a external USB enclosed drive, it seemed to max out at around 30MB/s. Though it's hard to say what that means, since like the quoted test, my "test" is tainted since my external drive is a different brand, model, and even interface (my external is EIDE whereas the internal drive is SATA). Maxing out at 30 though seems to work with your theory, and it looks like Drives now do exceed USB2. Also, further research sort of clears of a confusion I had, the ATA-6 speed is in fact not 133 Megabits per second, but rather megabytes per second, so PATA is truly a 1-gigabit speed. That said, we have to wonder how it would apply in this sort of scenario. Obviously for tasks like transferring files and copying files it will be slower, but the fact is the OP is discussing performing a virus scan on the drive. This will almost always be slower when you run it on the system drive since there are any number of programs hooking drive accesses, such as anti-virus programs, which will slow down any and all disk access in that manner. Also, if the drive is infected you've got the issue that malware can be doing the same thing (much like virut, which will infect files as they are accessed) That's a good info here! Thank you a lot ! and Merry Christmas to all of you Quote Obviously for tasks like transferring files and copying files it will be slower, but the fact is the OP is discussing performing a virus scan on the drive. This will almost always be slower when you run it on the system drive since there are any number of programs hooking drive accesses, such as anti-virus programs, which will slow down any and all disk access in that manner. Also, if the drive is infected you've got the issue that malware can be doing the same thing (much like virut, which will infect files as they are accessed) Ok... So actually that answers my question on why it takes longer when the HDD is scanned internally, than when it's scanned externally. It makes sense to me now And it means also that it's better to scan an infected HDD externally? (More effective?) Quote My internal drive had a average transfer rate of around 80MB (Megabytes) a second. This would definitely saturate USB2, so I was wrong about that. testing a external USB enclosed drive, it seemed to max out at around 30MB/s. Though it's hard to say what that means, since like the quoted test, my "test" is tainted since my external drive is a different brand, model, and even interface (my external is EIDE whereas the internal drive is SATA). Maxing out at 30 though seems to work with your theory, and it looks like Drives now do exceed USB2. Quote There is a difference between the transfer speed of direct SATA connection to the motherboard and connection via USB enclosure. Actually, If I manage to transfer data from an internal HDD (diskAlpha) to a second internal HDD (DiskBeta), and then transfer the same data between the same disks, but from an internal HDD (DiskAlpha) to an EXternal HDD (diskBeta) The time difference would mean that the SPEED transfer data between SATA to SATA and between SATA to USB2.0 would be the reason? since the data was transferred between the two same HDDs, but with a different road? |
|
4274. |
Solve : Windows Infected... Trojan.Sharpro Nvidia?? |
Answer» Does CCleaner save a log somewhere? I have the portable version...ComboFix R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe R4 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-09-11 140672] S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe S2 ASMMAP64;ASMMAP64;c:\program files\ATKGFNEX\ASMMAP64.sys [2007-07-24 14904] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120] S2 rimspci;rimspci;c:\windows\system32\DRIVERS\rimspe64.sys S2 rixdpcie;rixdpcie;c:\windows\system32\DRIVERS\rixdpe64.sys S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248] S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2314240] S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2011-10-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3596009218-1777886604-2241043216-1000Core.job - c:\users\Nas\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-24 20:52] . 2011-10-28 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3596009218-1777886604-2241043216-1000UA.job - c:\users\Nas\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-24 20:52] . 2011-10-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-01 23:18] . 2011-10-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-01 23:18] . 2011-10-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3596009218-1777886604-2241043216-1000Core.job - c:\users\Nas\AppData\Local\Google\Update\GoogleUpdate.exe [2011-09-24 03:45] . 2011-10-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3596009218-1777886604-2241043216-1000UA.job - c:\users\Nas\AppData\Local\Google\Update\GoogleUpdate.exe [2011-09-24 03:45] . 2011-09-11 c:\windows\Tasks\One-Click Tweak.job - c:\program files (x86)\Advanced PC Tweaker\OneClick.exe [2011-09-11 15:14] . . --------- x86-64 ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1] @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}" [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}] 2007-06-02 00:52159744----a-w-c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RunDLLEntry"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568] "Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 660360] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ------- Supplementary Scan ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.bigseekpro.com/hypercam/{7617EF1E-D4A9-4651-9E2C-B654D3D11399} mStart Page = hxxp://www.bigseekpro.com/hypercam/{7617EF1E-D4A9-4651-9E2C-B654D3D11399} uInternet Settings,ProxyOverride = ;*.local TCP: DhcpNameServer = 65.32.5.111 65.32.5.112 TCP: Interfaces\{F23B2AFE-C1E7-481E-853C-7FDD2026B937}\6427565675966696: DhcpNameServer = 212.27.40.241 212.27.40.242 TCP: Interfaces\{F23B2AFE-C1E7-481E-853C-7FDD2026B937}\C496675626F687D214442383: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{F23B2AFE-C1E7-481E-853C-7FDD2026B937}\D4F657C616: DhcpNameServer = 65.32.5.111 65.32.5.112 FF - ProfilePath - c:\users\Nas\AppData\Roaming\Mozilla\Firefox\Profiles\74j0np1d.default\ FF - prefs.js: keyword.URL - hxxp://www.scanquery.com/?tmp=nemo_results_removelink&prt=ScnqryPB&keywords= FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 60394 FF - prefs.js: network.proxy.type - 0 FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} FF - Ext: Skype Click to Call: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} FF - Ext: PC SYNC 2 Synchronisation Extension: [emailprotected] - c:\program files (x86)\Nokia\Nokia PC Suite 7\bkmrksync . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKCU-Run-DisplayBackupOnline - c:\programdata\DisplayBackupOnline.dll Toolbar-Locked - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe AddRemove-ASUS_ScreenSaver_GSeries - c:\windows\system32\ASUS_ScreenSaver_GSeries.scr . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-3596009218-1777886604-2241043216-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýU†j] @Class="Shell" . [HKEY_USERS\S-1-5-21-3596009218-1777886604-2241043216-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ýU†j\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_USERS\S-1-5-21-3596009218-1777886604-2241043216-1000\Software\SecuROM\License information*] "datasecu"=hex:5f,c0,02,a7,b9,b5,32,30,09,db,e0,b1,67,ec,2d,bf,b4,ca,cd,08,42, 6c,f9,29,62,04,1f,e3,1f,f2,59,ed,b3,55,88,58,75,cf,c5,1e,0e,24,48,72,eb,39,\ "rkeysecu"=hex:1e,87,b4,a3,5d,ca,24,e3,33,c6,f6,5f,28,f5,86,96 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10s_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10s_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10s.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Windows CE Services] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Other Running Processes ------------------------ . c:\program files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files (x86)\ASUS\SmartLogon\sensorsrv.exe c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe c:\program files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe c:\program files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe . ************************************************************************** . Completion time: 2011-10-28 13:14:15 - machine was rebooted ComboFix-quarantined-files.txt 2011-10-28 17:14 . Pre-Run: 42,653,626,368 bytes free Post-Run: 42,405,965,824 bytes free . - - End Of File - - BD0511F92914382D46D414936F4C38BB HEre is it... I finished with those one... But couldn't find a log for CCLeaner... do you know if it saved somewhere? Thank youNo need for CCleaner log. ESET Online Scan Please run a free online scan with the ESET Online Scanner
The first time, ESET found one thread to remove, but when I wanted to save a log, Windows crashed... So I restarted Windows, and did another scan 5min later.... But he found more things... C:\Program Files (x86)\Advanced PC Tweaker\AdvancedPCTweaker.exea variant of Win32/Adware.AdvPCTweak application C:\Qoobox\Quarantine\C\ProgramData\DisplayBackupOnline.dll.vira variant of Win32/Kryptik.UNZ trojan C:\Qoobox\Quarantine\C\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\ya9829x9.default\extensions\{d8a7ef98-7e29-4def-8b9e-62d8eabdb471}\chrome.manifest.virWin32/TrojanDownloader.Tracur.F trojan C:\Qoobox\Quarantine\C\Users\Nas\AppData\Local\Activision\ActivisionUpdate\Activisionupdt32.dll.vira variant of Win32/Kryptik.UNZ trojan C:\Qoobox\Quarantine\C\Users\Nas\AppData\Local\Apple\AppleUpdate\Appleupdt32.dll.vira variant of Win32/Kryptik.UNZ trojan C:\Qoobox\Quarantine\C\Users\Nas\AppData\Roaming\Mozilla\Firefox\Profiles\74j0np1d.default\extensions\{d8a7ef98-7e29-4def-8b9e-62d8eabdb471}\chrome.manifest.virWin32/TrojanDownloader.Tracur.F trojan C:\Users\Nas\AppData\Local\Google\Chrome\User Data\Default\Default\dlihhkfjijkboimenpffikpdeinlfjnp\contentscript.jsWin32/TrojanDownloader.Tracur.F trojan C:\Users\Nas\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\34584228-2f069fa4Java/Agent.AC trojan C:\Users\Nas\Desktop\SAVE\Nas\Hack\ophcrack-win32-installer-3.3.1.exemultiple threats C:\Users\Nas\Downloads\AdvancedPCTweaker.exea variant of Win32/Adware.AdvPCTweak application C:\Users\Nas\Downloads\avc-free(2).exeWin32/OpenCandy application C:\Users\Nas\Downloads\cnet_mp3gain-win-1_2_5_exe.exea variant of Win32/InstallCore.D application C:\Users\Nas\Downloads\cnet_SubtitlesSynchSetup_exe.exea variant of Win32/InstallCore.D application C:\Users\Nas\Downloads\Fl.Studio.9.Prensboard.Com.rarWin32/OpenCandy application C:\Users\Nas\Downloads\packenergieettechnologieV22011EXIT.rara variant of Win32/Keygen.AS application C:\Users\Nas\Downloads\packenergieettechnologieV22011EXIT.rar.001.exea variant of Win32/Keygen.AS application C:\Users\Nas\Downloads\scripts_2010_by_leo.zipmultiple threats C:\Users\Nas\Downloads\slg.ab.rara variant of Win32/HackTool.Patcher.D application C:\Users\Nas\Downloads\software_informer.exeprobably a variant of Win32/SWInformer application C:\Users\Nas\Downloads\Fl Studio 9\flstudio_9.0.exeWin32/OpenCandy application C:\Users\Nas\Downloads\slg.ab\slg.ab\Patch\Patch.exea variant of Win32/HackTool.Patcher.D application C:\Users\Nas\Downloads\slg.abrio\slg.abrio\Patch\Patch.exea variant of Win32/HackTool.Patcher.D application C:\Windows\System32\srrstr.dlla variant of Win32/Kryptik.UNZ trojan C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M\upgrade[1].caba variant of Win32/Adware.OneStep.Z application C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA\upgrade[1].caba variant of Win32/Adware.OneStep.Z application C:\Windows\SysWOW64\srrstr.dlla variant of Win32/Kryptik.UNZ trojan C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M\upgrade[1].caba variant of Win32/Adware.OneStep.Z application C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA\upgrade[1].caba variant of Win32/Adware.OneStep.Z application Save these instructions so you can have access to them while in Safe Mode. Please click here to download AVP Tool by Kaspersky.
I'm sorry I didn't reply sooner. But actually I already ran this tool on another computer, and the scan took 24h to finish, and because I work with my laptop (From 9am to 8pm), I procrastinated to run it... And now it's been almost two months... What should I do ? Run it anyway? Or start over? Actually, the computer run fine, and there is no visible sign of infection. What is your advice? Thank you for all your help! You make the world a better place ! Quote Actually, the computer run fine, and there is no visible sign of infection.Sorry. I misunderstood. In that case we can do some cleanup. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how OFTEN you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ********************************************* Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. ********************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! OK, great! I try all of that. Do I absolutely have to uninstall combofix? And after I run all of that... I'm done with this laptop? there is no need of any log posting? Quote Do I absolutely have to uninstall combofix?Yes, you should uninstall ComboFix. You no longer need it and it should not be used unless an expert is helping your. You are done. There are no other logs to post. I will lock this thread. If you need it re-opened, please send me a pm. |
|
4275. |
Solve : 'Your computer is not protected!'? |
Answer» My friend has just rung and she is really spooked. She was sending an email off to someone, finished that, then a big square came up on the screen. A voice actually spoke and said 'Your computer is not protected. To fix this problem go to LINK removedand disappeared! Has anyone heard of this happening? Should she be really concerned (which she is)?[/color]Probably not a GOOD idea to leave that link there. Just a sales pitchAnytime we see that it's scareware. |
|
4276. |
Solve : how do I get driver robot off my computer???? |
Answer» I do not KNOW who in my family put this program on our desktop (hp windows vista) |
|
4277. |
Solve : Unreal situation with ASPIRE M? |
Answer» Hello, |
|
4278. |
Solve : Help with installing a free antivirus offline...? |
Answer» I need to install an antivirus on a laptop that does not have INTERNET CONNECTION. I need to transfer this file to it via pen drive. |
|
4279. |
Solve : Help !! ReImage has taken over our PC? |
Answer» Can anyone help me get this fecking ReImage MONSTER off my PC !! |
|
4280. |
Solve : Windows 7 virus cant find D drive? |
Answer» Hi, I have a dell notebook with Windows 7 Ultimate. Its infected with a virus whic has shut down the firewall and all anti virus programs. the D drive showed 0 files/empty, but when i tried to scan the drive, it was full. |
|
4281. |
Solve : Too many file threats? |
Answer» Quote I apologise for taking up your time.Not a problem. I love doing this. Is everything good with your computer now?Quote [.ShellClassInfo] Well yes, but not happy about the two files above being on my desktop really. What about the jrt text and esetmart... etc - just delete? Just one last question which is relating to Win 10, in Win 7 you could go into msconfig and start and delete anything you don't want STARTING up (some programs PUT themselves on there!) This Win 10 has a different set up - you just disable them?? Here's what I have on my currently, can any of them come off there do you think? [attachment deleted by admin to conserve space]Click Start> Computer> right click the C Drive and choose Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive) *************************************** This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments... This is a very CRUCIAL step so make sure you don't skip it. Download DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles. Double-click Delfix.exe to start the tool. Make sure the following items are checked:
Once finished a logfile will be created. You don't have to attach it to your next reply. ******************************************** I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Quote Click Start> Computer> right click the C Drive and choose Properties> enterI had to find another way of cleaning up as your instructions were not for Windows 10, but everything disappeared as you said. I had trouble with WOT, as it does not work with Windows 10, (I got an error message) It won't work with Edge https://www.mywot.com/en/forum/58220-mywot-for-windows-10-s-edge-browser and I am not using Chrome or Firefox.That's very possible that some programs won't run on Windows 10. It remains to be seen if they will be updated. OK and thanks, Dave You're welcome. I will lock this thread. If you need it re-opened, PLEASE send me a pm. |
|
4282. |
Solve : Malware Bytes & emergency update? |
Answer» my inbox has a message about MB's. emergency update concerning a threat, & they SUGGEST new installs for protection. Is this real, or a scam ? do the suggested updates COST anything ?SOUNDS like a scam. Rule of thumb is if any E-mail gives you a link and TRIES to get you to go to it, it is a scam. |
|
4283. |
Solve : Malwarebytes Restore Browser Page?? |
Answer» I have recently installed Malwarebytes and ran a couple of scans with it last NIGHT. It has only found two PUPs (That I qurantined) and nothing else so nothing really serious. I try to BROWSE with Firefox this morning and I recieved this page. |
|
4284. |
Solve : Please help me clean my daughters laptop? |
Answer» You're welcome. I will LOCK this THREAD. If you NEED it re-opened, PLEASE send me a pm. |
|
4285. |
Solve : Free Virus Protection.? |
Answer» Dell desktop PC running Windows 8.1 with malwarebytes. |
|
4286. |
Solve : Help with RCA Apollo? |
Answer» Hi I bought a cheap RCA appolo 2 in 1 to use for small time things, t caught a nasty virus and won't work anymore. So I let it sit, until my vaio got broken last NIGHT. Now I need some help with RCA tablet/laptop. I don't remember what virus it had but this is where I'm at, all the help I got online FAILED and it got to the point I turned it off once and when I booted it back up it gives me a blank black screen after the logo. Now if I touch the screen or move the mouse you can see the clicker with an HOURGLASS next to it so stuff is happening there for sure. But nothing else. So I tried to reset it, and then to totally reset it. It works to almost the end and then gives me and error saying it can't be reset. I had never made a save point on it either so I can't load it back to a previous point. Can anyone help me with this?? Please. Can you boot in Safe Mode?I deleted my post. Sorry.Quote from: Geek-9pm on MAY 31, 2016, 05:07:36 PM I deleted my post. Sorry.I know you regulars are TRYING to help and it's not a problem for me. |
|
4287. |
Solve : Phone call from Microsoft 2nd time?? |
Answer» I received a phone call today (same type of call as a couple of months ago) from someone claiming that Microsoft has been receiving several error reports from my computer. He guided me to my event viewer log to show me the errors etc. 2853 of them as you can see in the attached screen shot. Then he guided me to: |
|
4288. |
Solve : Infection damaged functionality of internet? |
Answer» So I believe I cleared it all out because the internet is the only issue so maybe the damage was left over. I can only RUN the internet on the Tor BROWSER now. When I tried mini TOOLBOX it says this |
|
4289. |
Solve : zone alarm software not compatible with Vista Home Basic ?? |
Answer» Zone Alarm SECURITY suite works on my XP PC right now, but will not work with my Vista PC even if it says Vista ready. Does that mean that I NEED to upgrade to Home Premium or ULTIMATE Vista maybe ? I talked to ZA. support they said to DOWNLOAD their lasted updated version which I did , but got the same results. I all ready bought this second archive ZA. version, so it would be great to get it run like my other XP ZA version running now If you can't get it to work on Vista you could always download and install MicroSoft Security Essentials ( below) It's free and very good. It's all I use on all my computers. |
|
4290. |
Solve : Seems as though Firefox is now being targeted by phishers? |
Answer» Just sharing this here to bring to the attention of all. I suspect the attachment has a payload to it to infect Firefox or the system as a whole, notice the URL and patch are not from Mozilla but instead eekumyoutube ( dot ) org. I was at Wowhead looking up a Reins of the swift Spectral Tiger Mount when all of a sudden one of the ads in the corner of wowhead took over and brought me to what you see in this screenshot. This is the first time ever i have seen Firefox targeted to try to trick someone into running a so called "patch". System I am on has no infections. AVG is clean and Malwarebytes shows clean to, so thats why I am thinking there is a rogue ad associated with wowheads website that trying to get people to click and infect themselves if on firefox. Perhaps this phishing is using the browser detection script in which depending on browser they have a number of different payloads to infect you with. In one case the user had even used their own personal E-mail, (connected to paypal, amazon, Steam, Facebook, etc.) so I went ahead and E-mailed his family members from his account confessing some rather questionable feelings. Laughing so hard, but yes in order to authenticate the info would be in the source. Shaking my head why they didnt just use an alias to stay hidden. Although to have an alias paypal I suppose they would have had to have had a stolen identity or some means of creating a alias that appears to be a real person with the rabbit hole going deeper into someone opening an account with a bank with fake id / stolen identity etc. Does .Net hide better against antimalware and antivirus's? Maybe I'm wrong, but I thought the basis of .Net was to make for better healthier programs that wont BSOD systems etc. Memory managements and tighter execution layer controls etc. So I always thought that if you want to make a program that is going to be naughty it was best to code it up in something that wasnt based around .Net that more readily would allow for you to target memory addresses outside of where the program should be operating etc and overflow conditions etc.Quote from: DaveLembke on July 05, 2016, 01:40:29 PM Laughing so hard, but yes in order to authenticate the info would be in the source. Shaking my head why they didnt just use an alias to stay hidden. Although to have an alias paypal I suppose they would have had to have had a stolen identity or some means of creating a alias that appears to be a real person with the rabbit hole going deeper into someone opening an account with a bank with fake id / stolen identity etc. For the most part they seem to be teenagers. I'm not certain what their goals are but in terms of Minecraft they were just trying to steal username/passwords. I don't know how those are valuable given that they can just be password reset and the MC username/password doesn't give access to the connected E-mail (or even let you know what that e-mail is). Quote Does .Net hide better against antimalware and antivirus's?The .net framework includes a lot of LIBRARY functions for features such as encryption. Typically the .NET program will have an encrypted resource which it decrypts, saves as an executable, and runs. Sometimes that inner executable is a straight-up RAT but other times it's another .NET program with the actual payload (eg. trying to read a password file and E-mail it). Quote Maybe I'm wrong, but I thought the basis of .Net was to make for better healthier programs that wont BSOD systems etc. Memory managements and tighter execution layer controls etc. So I always thought that if you want to make a program that is going to be naughty it was best to code it up in something that wasnt based around .Net that more readily would allow for you to target memory addresses outside of where the program should be operating etc and overflow conditions etc.Only driver software can BSOD. Running a .NET Executable doesn't "sandbox" it in any way beyond what would happen for a typical executable. unsafe{} and unchecked{} code blocks can be used to run C# code that uses pointers, pointer arithmetic, unbounded arithmetic operations, unchecked array access, etc. Win32 processes cannot access memory outside of their virtual address space- only driver software can access physical memory directly in that manner. Those abilities don't really matter except for exploits. If you run an executable it can read any file accessible to your user account which will include things like saved passwords for databases, Internet Explorer, Firefox profiles, Outlook, etc. and it can send an E-mail with that info if it wants. (Software firewall might see the E-mail I suppose). |
|
4291. |
Solve : IE webrep loader? |
Answer» How can I DELETE IE webrep loader I have tried a lot from the WEB and NONE of them seem to work.What are you using for AV? I'm using avast, I think that's where it came from.That's where it came from. You can always switch to MicroSoft SECURITY Essentials.Thanks Dave I might do that, I ran ccleaner from here last night and it cleared it out, have not used it for a LONG time. |
|
4292. |
Solve : Online Shopping Trouble? |
Answer» I have been having problems with ONLINE shopping. The last TWO orders I placed never arrived at the mail. After that I got a totally random audio message telling me to call the phone number provided and not to shop online until I did. This was while visiting a PORNOGRAPHY website.You could try calling the number but do not GIVE them any personal information. If it is legit they should already have all the information. You should also contact the company where you placed your purchases and INQUIRE about your orders. |
|
4293. |
Solve : Cannot enter to some websites? |
Answer» I cannot enter to some websites except FACEBOOK and Google websites etc. But it normal when I using internet with my other DEVICES in same 4G wifi router. Do you think that it is a malware issue? PPZ help me to fix this.Your post is not clear. |
|
4294. |
Solve : Files ending in .enc? |
Answer» The problem now is - I am in the middle of a newsletter done on publisher 2003, if I try to open it in publisher 2010 it is not up to DATE - in fact none of my 2003 newsletter will open now it is not installed. Hmmm. What to do - the newsletter is DUE to go out today or tomorrow Ok, good luck with that.Strange things happen, after I re-installed M/Soft Professional 2003, I then re-installed it, and all the problems vanished. |
|
4295. |
Solve : Forgive me for "bumping my thread, but: I lost track of Allan? |
Answer» I wanted to tell Allan just how wonderful his help was. |
|
4296. |
Solve : Is windows live mail dead?? |
Answer» I have been using WINDOWS live mail for a long time. Don't pay too much attention to me; i'm easily conmfused...Me too! The Windows Live Mail client will continue to work with OTHER email services but not with Outlook.com (Hotmail) because Outlook.com will STOP supporting the DeltaSync protocol that WLM uses to communicate with it. Even then, you can change WLM to access Outlook.com via IMAP and it will work then. I am still using WLM 2012 to access my Hotmail account and everything is still working but I suppose it's only a matter of time before it stops working. Once it stops working, I will probably switch to Thunderbird as my email client. |
|
4297. |
Solve : How to dissociate an already-hacked computer from your real identity..?? |
Answer» Let's say that you have a computer that is hiding behind a dedicated TOR Ethernet hotspot. Let's say that you have a computer that is hiding behind a dedicated Tor Ethernet hotspot. Code: [Select]What do you think..? My thoughts are that your a wanna be hacker, and a weak black hat trying to find a way to avoid getting caught. We cant help with this hiding and very questionable "SHADY" use. |
|
4298. |
Solve : Cannot get rid of pop-up? |
Answer» I have tried ccleaner, adware cleaner, superantispyware, malwarebytes but it's still here/ where did it come from. There now, that wasn't so hard. See you Harry. That's why your a genius As the man said " i'll be back "Quote from: harry 48 on September 29, 2016, 12:23:31 PM That's why your a geniusIt's good to see you're still around. How is life on the green isle?It's great, I'm fully retired now and enjoying it, how's life in Briton's colony Quote from: harry 48 on September 29, 2016, 01:19:17 PM It's great, I'm fully retired now and enjoying it, how's life in Briton's colonyWe call it Canada and we're about to DUMP the royalty. Everything is GOIND great. Retired for 15 yrs. and having a ball.Sure your future King and Queen are over to see how you are all keeping. My brother LIVES just outside Edmonton. |
|
4299. |
Solve : Got a problem in my folder that i cant open? |
Answer» C:\ProgramData is always closing everytime i open it, i thing its a kind of VIRUS, anyone knows how to remove it? i cant open regedit and task manager too.And everytime i PUT the word ProgramData or programdata in anywhere like browser, NOTEPAD, mword etc, it always closed, like the word ProgramData and Task Manager is BLOCK in my pcOh its fine now, thanks, i just restart my pc, thanks, already thank you in that Thank Geek-9pm button hehe, thanks ^_^ |
|
4300. |
Solve : no connection? |
Answer» ppData\Roaming\Kingsoft\office6\update\down\wpsupdate.exea variant of Win32/KingSoft.D potentially unwanted applicationcleaned by deleting is windows defender enough.It works for me on all my computers. Most of the crap going around is malware which WD protects against. Click START> Computer> right click the C Drive and choose Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the FREE space in C drive) *************************************** This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally USING some older restore point) and it'll make some other minor adjustments... This is a very crucial step so make sure you don't skip it. Download DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles. Double-click Delfix.exe to start the tool. Make sure the following items are checked:
Once finished a logfile will be created. You don't have to attach it to your next reply. ******************************************** I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|