Unsolved
This post is more than 5 years old
6 Posts
0
2104
May 24th, 2010 20:00
Internet Explorer running in background, one always comes back when I end process tree
Theres always 3 iexplore.exe*32 when I start my computer. When I end the process one always comes back. I read somewhere about avenger and followed the instructions to remove them. At first it seem to work but then they came back. I installed hijackthis and got this log.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:28:29 PM, on 5/24/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Windows\SysWOW64\explorer.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10b.exe
C:\Program Files (x86)\AIM\aim.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\SysWOW64\msiexec.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
O4 - HKLM\..\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe
O4 - HKLM\..\RunOnce: [STToasterLauncher] C:\program files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe
O4 - HKCU\..\Run: [svchost] C:\Users\Blade\AppData\Roaming\Microsoft\svchost.exe
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\WINDOWS\System32\StikyNot.exe
O4 - HKCU\..\Run: [StartServiceSNDKBKWW] C:\Users\Blade\AppData\Local\SNDKBKWW\StartService.exe
O4 - HKCU\..\Run: [Cerberus] C:\Users\Blade\AppData\Roaming\Cerberus\server.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TabletServicePen - Unknown owner - C:\Windows\system32\Pen_Tablet.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: WTouch Service (WTouchService) - Wacom Technology, Corp. - C:\Program Files\WTouch\WTouchService.exe
O23 - Service: Zune Wireless Configuration Service (ZuneWlanCfgSvc) - Unknown owner - c:\Windows\system32\ZuneWlanCfgSvc.exe (file missing)
--
End of file - 10352 bytes


BladeRaver
6 Posts
0
May 25th, 2010 10:00
Can anyone help me out? I'd appreciate it, Thanks.
bamajim
10.4K Posts
0
May 25th, 2010 18:00
There are a few legitamate reasons that iexplorer would run in the background. But let's take a look
1. Go HERE and download FileLister.
Rt Click ->> Extract all ->> And extract it to your Desktop
Additional help on extracting zip files can be found HERE
Open the File Lister Folder.
Note: Leave the FileLister.vbe file in the folder and run it from there.
When the program is fnished it will produce a log for you Files.txt
Which will be located in the default location from which FileLister was run(the FileLister folder)
Copy and paste the contents of that log in your reply.
BladeRaver
6 Posts
0
May 26th, 2010 06:00
Thanks for the response. Here is the log files.txt
---------------------------------------------------------------------
+++++++++++++++++++++++++++
+ File Lister Version 1.1.4 +
+ +
+ By bamajim / SpywareHammer.com +
+++++++++++++++++++++++++++
Report ran on --->>> 5/26/2010 8:33:51 AM
====== Running Processes ======
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Program Files\DellTPad\Apoint.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\WINDOWS\System32\StikyNot.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Windows\SysWOW64\explorer.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\System32\WScript.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
====== BHO's ======
BHO: (NO NAME) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
====== System Keys (some whitelisted items will not be shown)======
Winlogon\Userinit = C:\Windows\system32\userinit.exe,
Winlogon\Shell = explorer.exe
====== HKLM\~\Run Keys ======
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
[Apoint] = C:\Program Files\DellTPad\Apoint.exe
[IgfxTray] = C:\Windows\system32\igfxtray.exe
[HotKeysCmds] = C:\Windows\system32\hkcmd.exe
[Persistence] = C:\Windows\system32\igfxpers.exe
[Broadcom Wireless Manager UI] = C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe
[SysTrayApp] = C:\Program Files\IDT\WDM\sttray64.exe
[QuickSet] = C:\Program Files\Dell\QuickSet\QuickSet.exe
[CanonMyPrinter] = C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
====== HKCU\~\Run Keys ======
[AdobeBridge] =
[svchost] = C:\Users\Blade\AppData\Roaming\Microsoft\svchost.exe
[RESTART_STICKY_NOTES] = C:\WINDOWS\System32\StikyNot.exe
[StartServiceSNDKBKWW] = C:\Users\Blade\AppData\Local\SNDKBKWW\StartService.exe
[Cerberus] = C:\Users\Blade\AppData\Roaming\Cerberus\server.exe
====== DNS Info (List may be empty) ======
ICSDomain = mshome.net
SyncDomainWithMembership = 1
NV Hostname = Blade-PC
DataBasePath = %SystemRoot%\System32\drivers\etc
ForwardBroadcasts = 0
IPEnableRouter = 0
Hostname = Blade-PC
UseDomainNameDevolution = 1
EnableICMPRedirect = 1
DeadGWDetectDefault = 1
DontAddDefaultGatewayDefault = 0
EnableWsd = 1
QualifyingDestinationThreshold = 3
DhcpNameServer = 10.91.32.10 10.91.32.15
DhcpDomain = academic.iadtdetroit.com
====== Folders and Files from "%\" and "%\Windows" Created Last 60 Days ======
4/2/2010 9:49:07 PM 1373710560 C:\ijji
4/2/2010 9:49:07 PM 1373710560 C:\ijji\ENGLISH
4/2/2010 9:58:04 PM 270546448 C:\ijji\ENGLISH\Gunz
4/2/2010 9:58:04 PM 0 C:\ijji\ENGLISH\Gunz\CUSTOM
4/2/2010 9:58:04 PM 0 C:\ijji\ENGLISH\Gunz\CUSTOM\CROSSHAIR
4/2/2010 9:59:10 PM 5705543 C:\ijji\ENGLISH\Gunz\GameGuard
4/2/2010 9:59:04 PM 6224 C:\ijji\ENGLISH\Gunz\ijjigame
4/2/2010 9:59:04 PM 6224 C:\ijji\ENGLISH\Gunz\ijjigame\hul
4/2/2010 9:58:04 PM 9677128 C:\ijji\ENGLISH\Gunz\Interface
4/2/2010 9:58:04 PM 71194371 C:\ijji\ENGLISH\Gunz\Maps
4/2/2010 9:58:05 PM 46668780 C:\ijji\ENGLISH\Gunz\Model
4/2/2010 9:58:06 PM 9020190 C:\ijji\ENGLISH\Gunz\Model\NPC
4/2/2010 9:58:06 PM 22673321 C:\ijji\ENGLISH\Gunz\Quest
4/2/2010 9:58:06 PM 22673321 C:\ijji\ENGLISH\Gunz\Quest\Maps
4/2/2010 9:58:08 PM 1932 C:\ijji\ENGLISH\Gunz\Shader
4/2/2010 9:58:07 PM 62123722 C:\ijji\ENGLISH\Gunz\Sound
4/2/2010 9:58:08 PM 15878635 C:\ijji\ENGLISH\Gunz\Sound\Effect
4/2/2010 9:58:08 PM 10248410 C:\ijji\ENGLISH\Gunz\Sound\Effect\quest
4/2/2010 9:49:07 PM 1100398232 C:\ijji\ENGLISH\u_sf
4/2/2010 9:49:08 PM 1089727371 C:\ijji\ENGLISH\u_sf\data
4/2/2010 9:49:08 PM 459164893 C:\ijji\ENGLISH\u_sf\data\area
4/2/2010 9:49:18 PM 28373400 C:\ijji\ENGLISH\u_sf\data\clan
4/2/2010 9:49:22 PM 6912822 C:\ijji\ENGLISH\u_sf\data\effect
4/2/2010 9:49:23 PM 149074306 C:\ijji\ENGLISH\u_sf\data\force
4/2/2010 9:49:27 PM 269198752 C:\ijji\ENGLISH\u_sf\data\lobby
4/2/2010 9:49:38 PM 106518045 C:\ijji\ENGLISH\u_sf\data\menu
4/2/2010 9:49:40 PM 24 C:\ijji\ENGLISH\u_sf\data\save
4/2/2010 9:49:41 PM 2002081 C:\ijji\ENGLISH\u_sf\data\scr
4/2/2010 9:49:41 PM 27 C:\ijji\ENGLISH\u_sf\data\screenshot
4/2/2010 9:49:41 PM 28758663 C:\ijji\ENGLISH\u_sf\data\sound
4/2/2010 9:49:43 PM 39722483 C:\ijji\ENGLISH\u_sf\data\weapon
4/2/2010 9:49:08 PM 1267712 C:\ijji\ENGLISH\u_sf\redist
4/2/2010 9:49:46 PM 2417720 C:\ijji\ENGLISH\xfire
5/24/2010 8:52:36 PM 680 32 C:\avenger.txt
5/24/2010 8:57:00 PM 204 32 C:\mbzxz.txt
5/24/2010 8:43:25 PM 280 32 C:\WINDOWS\setupact.log
5/24/2010 8:43:25 PM 0 32 C:\WINDOWS\setuperr.log
5/24/2010 5:37:48 PM 22583 32 C:\WINDOWS\WindowsUpdate.log
3/26/2010 2:08:02 PM 2475216 C:\WINDOWS\System32\CanonIJ Uninstaller Information
3/26/2010 2:08:02 PM 2475216 C:\WINDOWS\System32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2600_series
3/26/2010 2:08:02 PM 1461880 C:\WINDOWS\System32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2600_series\RES
3/26/2010 2:08:02 PM 1441792 C:\WINDOWS\System32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2600_series\RES\DLL
3/26/2010 2:08:03 PM 20088 C:\WINDOWS\System32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2600_series\RES\STRING
4/7/2010 9:56:17 PM 2404648 C:\WINDOWS\System32\WTablet
3/26/2010 2:07:50 PM 269824 32 C:\WINDOWS\System32\CNMLM97.DLL
4/7/2010 9:56:36 PM 7543592 32 C:\WINDOWS\System32\PenTablet.cpl
4/7/2010 9:56:41 PM 1595175 32 C:\WINDOWS\System32\PenTablet.znc
4/7/2010 9:56:07 PM 456 32 C:\WINDOWS\System32\PenTabletUserDefaults.xml
4/7/2010 9:56:13 PM 490280 32 C:\WINDOWS\System32\Pen_Tablet.dll
4/7/2010 9:56:09 PM 5556520 32 C:\WINDOWS\System32\Pen_Tablet.exe
4/7/2010 9:56:07 PM 456 32 C:\WINDOWS\System32\TouchTabletUserDefaults.xml
4/7/2010 9:57:13 PM 290088 32 C:\WINDOWS\System32\Touch_Tablet.dll
====== "\Administrator & All Users\Startup" Last 60 Days======
====== "\Program Files" Last 60 Days======
3/26/2010 2:08:14 PM 2532002 C:\Program Files\Canon
3/26/2010 2:07:35 PM 9920559 C:\Program Files\CanonBJ
3/31/2010 11:39:53 AM 12818232 C:\Program Files\Rainmeter
4/7/2010 9:57:09 PM 7030326 C:\Program Files\WTouch
======"Drivers" Modified Last 60 Days======
====== Files Deleted under "%Temp%" ======
32 Files deleted
======"All Users\Application Data" Last 60 Days======
====== HKLM\~\ShellServiceObjectDelayLoad======
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} -
====== HKLM\~\SharedTaskScheduler======
======HKLM\~\msconfig\startupreg======
HKLM\Software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
HKLM\Software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager
HKLM\Software\microsoft\shared tools\msconfig\startupreg\Dell DataSafe Online
HKLM\Software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter
HKLM\Software\microsoft\shared tools\msconfig\startupreg\msnmsgr
HKLM\Software\microsoft\shared tools\msconfig\startupreg\Zune Launcher
====== Services ( Services that are Whitelisted are not shown) ======
1394ohci (1394 OHCI Compliant Host Controller)- C:\Windows\system32\DRIVERS\1394ohci.sys - Manual/Stopped
AcpiPmi (ACPI Power Meter Driver)- C:\Windows\system32\DRIVERS\acpipmi.sys - Manual/Stopped
adfs (adfs)- C:\Windows\system32\drivers\adfs.sys - Auto/Running
adp94xx (adp94xx)- C:\Windows\system32\DRIVERS\adp94xx.sys - Manual/Stopped
adpahci (adpahci)- C:\Windows\system32\DRIVERS\adpahci.sys - Manual/Stopped
amdide (amdide)- C:\Windows\system32\DRIVERS\amdide.sys - Manual/Stopped
amdsata (amdsata)- C:\Windows\system32\DRIVERS\amdsata.sys - Manual/Stopped
amdsbs (amdsbs)- C:\Windows\system32\DRIVERS\amdsbs.sys - Manual/Stopped
amdxata (amdxata)- C:\Windows\system32\DRIVERS\amdxata.sys - Boot/Running
ApfiltrService (Alps Touch Pad Filter Driver for Windows XP/Vista x64)- C:\Windows\system32\DRIVERS\Apfiltr.sys - Manual/Stopped
AppID (AppID Driver)- C:\Windows\system32\drivers\appid.sys - Manual/Stopped
arcsas (arcsas)- C:\Windows\system32\DRIVERS\arcsas.sys - Manual/Stopped
b06bdrv (Broadcom NetXtreme II VBD)- C:\Windows\system32\DRIVERS\bxvbda.sys - Manual/Stopped
b57nd60a (Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0)- C:\Windows\system32\DRIVERS\b57nd60a.sys - Manual/Stopped
BCM42RLY (BCM42RLY)- C:\Windows\system32\drivers\BCM42RLY.sys - Manual/Running
BCM43XX (Dell Wireless WLAN Card Driver)- C:\Windows\system32\DRIVERS\bcmwl664.sys - Manual/Stopped
blbdrive (blbdrive)- C:\Windows\system32\DRIVERS\blbdrive.sys - System/Running
bowser (Browser Support Driver)- C:\Windows\system32\DRIVERS\bowser.sys - Manual/Running
BrFiltLo (Brother USB Mass-Storage Lower Filter Driver)- C:\Windows\system32\DRIVERS\BrFiltLo.sys - Manual/Stopped
BrFiltUp (Brother USB Mass-Storage Upper Filter Driver)- C:\Windows\system32\DRIVERS\BrFiltUp.sys - Manual/Stopped
Brserid (Brother MFC Serial Port Interface Driver (WDM))- C:\Windows\system32\Drivers\Brserid.sys - Manual/Stopped
BrSerWdm (Brother WDM Serial driver)- C:\Windows\system32\Drivers\BrSerWdm.sys - Manual/Stopped
BrUsbMdm (Brother MFC USB Fax Only Modem)- C:\Windows\system32\Drivers\BrUsbMdm.sys - Manual/Stopped
BrUsbSer (Brother MFC USB Serial WDM Driver)- C:\Windows\system32\Drivers\BrUsbSer.sys - Manual/Stopped
circlass (Consumer IR Devices)- C:\Windows\system32\DRIVERS\circlass.sys - Manual/Stopped
CLFS (Common Log (CLFS))- C:\Windows\system32\CLFS.sys - Boot/Running
CNG (CNG)- C:\Windows\system32\Drivers\cng.sys - Boot/Running
CompositeBus (Composite Bus Enumerator Driver)- C:\Windows\system32\DRIVERS\CompositeBus.sys - Manual/Stopped
CtClsFlt (Creative Camera Class Upper Filter Driver)- C:\Windows\system32\DRIVERS\CtClsFlt.sys - Manual/Stopped
DfsC (DFS Namespace Client Driver)- C:\Windows\system32\Drivers\dfsc.sys - System/Running
discache (System Attribute Cache)- C:\Windows\system32\drivers\discache.sys - System/Running
DXGKrnl (LDDM Graphics Subsystem)- C:\Windows\system32\drivers\dxgkrnl.sys - Manual/Stopped
ebdrv (Broadcom NetXtreme II 10 GigE VBD)- C:\Windows\system32\DRIVERS\evbda.sys - Manual/Stopped
elxstor (elxstor)- C:\Windows\system32\DRIVERS\elxstor.sys - Manual/Stopped
ErrDev (Microsoft Hardware Error Device Driver)- C:\Windows\system32\DRIVERS\errdev.sys - Manual/Stopped
FileInfo (File Information FS MiniFilter)- C:\Windows\system32\drivers\fileinfo.sys - Boot/Running
Filetrace (Filetrace)- C:\Windows\system32\drivers\filetrace.sys - Manual/Stopped
FsDepends (File System Dependency Minifilter)- C:\Windows\system32\drivers\FsDepends.sys - Manual/Stopped
fvevol (Bitlocker Drive Encryption Filter Driver)- C:\Windows\system32\DRIVERS\fvevol.sys - Boot/Running
gagp30kx (Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms)- C:\Windows\system32\DRIVERS\gagp30kx.sys - Manual/Stopped
hcw85cir (Hauppauge Consumer Infrared Receiver)- C:\Windows\system32\drivers\hcw85cir.sys - Manual/Stopped
HidBth (Microsoft Bluetooth HID Miniport)- C:\Windows\system32\DRIVERS\hidbth.sys - Manual/Stopped
HidIr (Microsoft Infrared HID Driver)- C:\Windows\system32\DRIVERS\hidir.sys - Manual/Stopped
HpSAMD (HpSAMD)- C:\Windows\system32\DRIVERS\HpSAMD.sys - Manual/Stopped
hwpolicy (Hardware Policy Driver)- C:\Windows\system32\drivers\hwpolicy.sys - Boot/Running
iaStorV (iaStorV)- C:\Windows\system32\DRIVERS\iaStorV.sys - Manual/Stopped
igfx (igfx)- C:\Windows\system32\DRIVERS\igdkmd64.sys - Manual/Stopped
IPMIDRV (IPMIDRV)- C:\Windows\system32\DRIVERS\IPMIDrv.sys - Manual/Stopped
iScsiPrt (iScsiPort Driver)- C:\Windows\system32\DRIVERS\msiscsi.sys - Manual/Stopped
KSecPkg (KSecPkg)- C:\Windows\system32\Drivers\ksecpkg.sys - Boot/Running
lltdio (Link-Layer Topology Discovery Mapper I/O Driver)- C:\Windows\system32\DRIVERS\lltdio.sys - Auto/Running
LSI_FC (LSI_FC)- C:\Windows\system32\DRIVERS\lsi_fc.sys - Manual/Stopped
LSI_SAS (LSI_SAS)- C:\Windows\system32\DRIVERS\lsi_sas.sys - Manual/Stopped
LSI_SAS2 (LSI_SAS2)- C:\Windows\system32\DRIVERS\lsi_sas2.sys - Manual/Stopped
LSI_SCSI (LSI_SCSI)- C:\Windows\system32\DRIVERS\lsi_scsi.sys - Manual/Stopped
luafv (UAC File Virtualization)- C:\Windows\system32\drivers\luafv.sys - Auto/Running
megasas (megasas)- C:\Windows\system32\DRIVERS\megasas.sys - Manual/Stopped
MegaSR (MegaSR)- C:\Windows\system32\DRIVERS\MegaSR.sys - Manual/Stopped
mpio (mpio)- C:\Windows\system32\DRIVERS\mpio.sys - Manual/Stopped
mpsdrv (Windows Firewall Authorization Driver)- C:\Windows\system32\drivers\mpsdrv.sys - Manual/Running
mrxsmb10 (SMB 1.x MiniRedirector)- C:\Windows\system32\DRIVERS\mrxsmb10.sys - Manual/Running
mrxsmb20 (SMB 2.0 MiniRedirector)- C:\Windows\system32\DRIVERS\mrxsmb20.sys - Manual/Running
msahci (msahci)- C:\Windows\system32\DRIVERS\msahci.sys - Boot/Running
msdsm (msdsm)- C:\Windows\system32\DRIVERS\msdsm.sys - Manual/Stopped
mshidkmdf (Pass-through HID to KMDF Filter Driver)- C:\Windows\system32\drivers\mshidkmdf.sys - Manual/Stopped
msisadrv (msisadrv)- C:\Windows\system32\DRIVERS\msisadrv.sys - Boot/Running
MsRPC (MsRPC)- C:\Windows\system32\drivers\MsRPC.sys - Manual/Stopped
MTConfig (Microsoft Input Configuration Driver)- C:\Windows\system32\DRIVERS\MTConfig.sys - Manual/Stopped
NativeWifiP (NativeWiFi Filter)- C:\Windows\system32\DRIVERS\nwifi.sys - Manual/Running
NdisCap (NDIS Capture LightWeight Filter)- C:\Windows\system32\DRIVERS\ndiscap.sys - Manual/Stopped
nfrd960 (nfrd960)- C:\Windows\system32\DRIVERS\nfrd960.sys - Manual/Stopped
nsiproxy (NSI proxy service driver.)- C:\Windows\system32\drivers\nsiproxy.sys - System/Running
nvstor (nvstor)- C:\Windows\system32\DRIVERS\nvstor.sys - Manual/Stopped
pcw (Performance Counters for Windows Driver)- C:\Windows\system32\drivers\pcw.sys - Boot/Running
PEAUTH (PEAUTH)- C:\Windows\system32\drivers\peauth.sys - Auto/Running
PxHlpa64 (PxHlpa64)- C:\Windows\system32\Drivers\PxHlpa64.sys - Boot/Running
ql2300 (ql2300)- C:\Windows\system32\DRIVERS\ql2300.sys - Manual/Stopped
ql40xx (ql40xx)- C:\Windows\system32\DRIVERS\ql40xx.sys - Manual/Stopped
QWAVEdrv (QWAVE driver)- C:\Windows\system32\drivers\qwavedrv.sys - Manual/Stopped
RasAgileVpn (WAN Miniport (IKEv2))- C:\Windows\system32\DRIVERS\AgileVpn.sys - Manual/Stopped
rdpbus (Remote Desktop Device Redirector Bus Driver)- C:\Windows\system32\DRIVERS\rdpbus.sys - Manual/Stopped
RDPENCDD (RDP Encoder Mirror Driver)- C:\Windows\system32\drivers\rdpencdd.sys - System/Running
RDPREFMP (Reflector Display Driver used to gain access to graphics data)- C:\Windows\system32\drivers\rdprefmp.sys - System/Running
rdyboost (ReadyBoost)- C:\Windows\system32\drivers\rdyboost.sys - Boot/Running
rspndr (Link-Layer Topology Discovery Responder)- C:\Windows\system32\DRIVERS\rspndr.sys - Auto/Running
RSUSBSTOR (RtsUStor.Sys Realtek USB Card Reader)- C:\Windows\system32\Drivers\RtsUStor.sys - Manual/Stopped
RTL8167 (Realtek 8167 NT Driver)- C:\Windows\system32\DRIVERS\Rt64win7.sys - Manual/Stopped
sbp2port (sbp2port)- C:\Windows\system32\DRIVERS\sbp2port.sys - Manual/Stopped
scfilter (Smart card PnP Class Filter Driver)- C:\Windows\system32\DRIVERS\scfilter.sys - Manual/Stopped
sermouse (Serial Mouse Driver)- C:\Windows\system32\DRIVERS\sermouse.sys - Manual/Stopped
sffdisk (SFF Storage Class Driver)- C:\Windows\system32\DRIVERS\sffdisk.sys - Manual/Stopped
sffp_mmc (SFF Storage Protocol Driver for MMC)- C:\Windows\system32\DRIVERS\sffp_mmc.sys - Manual/Stopped
sffp_sd (SFF Storage Protocol Driver for SDBus)- C:\Windows\system32\DRIVERS\sffp_sd.sys - Manual/Stopped
SiSRaid2 (SiSRaid2)- C:\Windows\system32\DRIVERS\SiSRaid2.sys - Manual/Stopped
SiSRaid4 (SiSRaid4)- C:\Windows\system32\DRIVERS\sisraid4.sys - Manual/Stopped
spldr (Security Processor Loader Driver)- C:\Windows\system32\drivers\spldr.sys - Boot/Running
srv2 (Server SMB 2.xxx Driver)- C:\Windows\system32\DRIVERS\srv2.sys - Manual/Running
srvnet (srvnet)- C:\Windows\system32\DRIVERS\srvnet.sys - Manual/Running
stexstor (stexstor)- C:\Windows\system32\DRIVERS\stexstor.sys - Manual/Stopped
STHDA (IDT High Definition Audio CODEC)- C:\Windows\system32\DRIVERS\stwrt64.sys - Manual/Stopped
TCPIP6 (Microsoft IPv6 Protocol Driver)- C:\Windows\system32\DRIVERS\tcpip.sys - Manual/Stopped
tcpipreg (TCP/IP Registry Compatibility)- C:\Windows\system32\drivers\tcpipreg.sys - Auto/Running
tdx (NetIO Legacy TDI Support Driver)- C:\Windows\system32\DRIVERS\tdx.sys - System/Running
tssecsrv (Remote Desktop Services Security Filter Driver)- C:\Windows\system32\DRIVERS\tssecsrv.sys - Manual/Stopped
tunnel (Microsoft Tunnel Miniport Adapter Driver)- C:\Windows\system32\DRIVERS\tunnel.sys - Manual/Stopped
uagp35 (Microsoft AGPv3.5 Filter)- C:\Windows\system32\DRIVERS\uagp35.sys - Manual/Stopped
uliagpkx (Uli AGP Bus Filter)- C:\Windows\system32\DRIVERS\uliagpkx.sys - Manual/Stopped
umbus (UMBus Enumerator Driver)- C:\Windows\system32\DRIVERS\umbus.sys - Manual/Stopped
UmPass (Microsoft UMPass Driver)- C:\Windows\system32\DRIVERS\umpass.sys - Manual/Stopped
usbcir (eHome Infrared Receiver (USBCIR))- C:\Windows\system32\DRIVERS\usbcir.sys - Manual/Stopped
usbvideo (USB Video Device (WDM))- C:\Windows\system32\Drivers\usbvideo.sys - Manual/Stopped
vdrvroot (Microsoft Virtual Drive Enumerator Driver)- C:\Windows\system32\DRIVERS\vdrvroot.sys - Boot/Running
vhdmp (vhdmp)- C:\Windows\system32\DRIVERS\vhdmp.sys - Manual/Stopped
volmgr (Volume Manager Driver)- C:\Windows\system32\DRIVERS\volmgr.sys - Boot/Running
volmgrx (Dynamic Volume Manager)- C:\Windows\system32\drivers\volmgrx.sys - Boot/Running
vsmraid (vsmraid)- C:\Windows\system32\DRIVERS\vsmraid.sys - Manual/Stopped
vwifibus (Virtual WiFi Bus Driver)- C:\Windows\system32\DRIVERS\vwifibus.sys - Manual/Stopped
vwififlt (Virtual WiFi Filter Driver)- C:\Windows\system32\DRIVERS\vwififlt.sys - System/Running
wacommousefilter (Wacom Mouse Filter Driver)- C:\Windows\system32\DRIVERS\wacommousefilter.sys - Manual/Stopped
WacomPen (Wacom Serial Pen HID Driver)- C:\Windows\system32\DRIVERS\wacompen.sys - Manual/Stopped
Wanarpv6 (Remote Access IPv6 ARP Driver)- C:\Windows\system32\DRIVERS\wanarp.sys - System/Running
Wdf01000 (Kernel Mode Driver Frameworks service)- C:\Windows\system32\drivers\Wdf01000.sys - Boot/Running
WfpLwf (WFP Lightweight Filter)- C:\Windows\system32\DRIVERS\wfplwf.sys - System/Running
WimFltr (WimFltr)- C:\Windows\system32\DRIVERS\wimfltr.sys - Manual/Stopped
WIMMount (WIMMount)- C:\Windows\system32\drivers\wimmount.sys - Manual/Stopped
WinUSB (WinUSB)- C:\Windows\system32\DRIVERS\WinUSB.sys - Manual/Stopped
WmiAcpi (Microsoft Windows Management Interface for ACPI)- C:\Windows\system32\DRIVERS\wmiacpi.sys - Manual/Stopped
====== Uninstall List ======
A file named 'UNI.txt' was created and saved to
FileListers default location. Post the results if requested.
======== Other Info ========
TOTAL PHYSICAL RAM: 4256 MB
Boot Info
OS Type: Microsoft Windows 7 Home Premium
Build: 6.1.7600
Service Pack: 0.0
====== Files with Hidden Attributes======
A file named 'Hidden.txt' was created and saved to
FileListers default location. Post the results if requested.
==End of Report==
bamajim
10.4K Posts
0
May 28th, 2010 09:00
1. Rerun Hijackthis (scan only) and place checks beside the following entries
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O4 - HKCU\..\Run: [svchost] C:\Users\Blade\AppData\Roaming\Microsoft\svchost.exe
O4 - HKCU\..\Run: [Cerberus] C:\Users\Blade\AppData\Roaming\Cerberus\server.exe
Close all other open windows except Hijackthis and Select " Fix checked"
Close Hijackthis ->> Do Not Reboot
1. Rerun Avenger
2. Copyall the text contained in the bold below to your Clipboard by highlighting it and pressing (Ctrl+C):
Files to delete:
C:\Users\Blade\AppData\Roaming\Microsoft\svchost.exe
C:\Users\Blade\AppData\Roaming\Cerberus\server.exe
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
3. Now, start The Avenger program by clicking on its icon on your desktop.
4. The Avenger will automatically do the following:
5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log
BladeRaver
6 Posts
0
May 30th, 2010 21:00
did as instructed and here are the logs, thanks again.
-------------------------------------------------------
avenger
________________________________
+++++++++++++++++++++++++++
+ File Lister Version 1.1.4 +
+ +
+ By bamajim / SpywareHammer.com +
+++++++++++++++++++++++++++
Report ran on --->>> 5/26/2010 8:33:51 AM
====== Running Processes ======
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Program Files\DellTPad\Apoint.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\WINDOWS\System32\StikyNot.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Windows\SysWOW64\explorer.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\System32\WScript.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
====== BHO's ======
BHO: (NO NAME) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
====== System Keys (some whitelisted items will not be shown)======
Winlogon\Userinit = C:\Windows\system32\userinit.exe,
Winlogon\Shell = explorer.exe
====== HKLM\~\Run Keys ======
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
[Apoint] = C:\Program Files\DellTPad\Apoint.exe
[IgfxTray] = C:\Windows\system32\igfxtray.exe
[HotKeysCmds] = C:\Windows\system32\hkcmd.exe
[Persistence] = C:\Windows\system32\igfxpers.exe
[Broadcom Wireless Manager UI] = C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe
[SysTrayApp] = C:\Program Files\IDT\WDM\sttray64.exe
[QuickSet] = C:\Program Files\Dell\QuickSet\QuickSet.exe
[CanonMyPrinter] = C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
====== HKCU\~\Run Keys ======
[AdobeBridge] =
[svchost] = C:\Users\Blade\AppData\Roaming\Microsoft\svchost.exe
[RESTART_STICKY_NOTES] = C:\WINDOWS\System32\StikyNot.exe
[StartServiceSNDKBKWW] = C:\Users\Blade\AppData\Local\SNDKBKWW\StartService.exe
[Cerberus] = C:\Users\Blade\AppData\Roaming\Cerberus\server.exe
====== DNS Info (List may be empty) ======
ICSDomain = mshome.net
SyncDomainWithMembership = 1
NV Hostname = Blade-PC
DataBasePath = %SystemRoot%\System32\drivers\etc
ForwardBroadcasts = 0
IPEnableRouter = 0
Hostname = Blade-PC
UseDomainNameDevolution = 1
EnableICMPRedirect = 1
DeadGWDetectDefault = 1
DontAddDefaultGatewayDefault = 0
EnableWsd = 1
QualifyingDestinationThreshold = 3
DhcpNameServer = 10.91.32.10 10.91.32.15
DhcpDomain = academic.iadtdetroit.com
====== Folders and Files from "%\" and "%\Windows" Created Last 60 Days ======
4/2/2010 9:49:07 PM 1373710560 C:\ijji
4/2/2010 9:49:07 PM 1373710560 C:\ijji\ENGLISH
4/2/2010 9:58:04 PM 270546448 C:\ijji\ENGLISH\Gunz
4/2/2010 9:58:04 PM 0 C:\ijji\ENGLISH\Gunz\CUSTOM
4/2/2010 9:58:04 PM 0 C:\ijji\ENGLISH\Gunz\CUSTOM\CROSSHAIR
4/2/2010 9:59:10 PM 5705543 C:\ijji\ENGLISH\Gunz\GameGuard
4/2/2010 9:59:04 PM 6224 C:\ijji\ENGLISH\Gunz\ijjigame
4/2/2010 9:59:04 PM 6224 C:\ijji\ENGLISH\Gunz\ijjigame\hul
4/2/2010 9:58:04 PM 9677128 C:\ijji\ENGLISH\Gunz\Interface
4/2/2010 9:58:04 PM 71194371 C:\ijji\ENGLISH\Gunz\Maps
4/2/2010 9:58:05 PM 46668780 C:\ijji\ENGLISH\Gunz\Model
4/2/2010 9:58:06 PM 9020190 C:\ijji\ENGLISH\Gunz\Model\NPC
4/2/2010 9:58:06 PM 22673321 C:\ijji\ENGLISH\Gunz\Quest
4/2/2010 9:58:06 PM 22673321 C:\ijji\ENGLISH\Gunz\Quest\Maps
4/2/2010 9:58:08 PM 1932 C:\ijji\ENGLISH\Gunz\Shader
4/2/2010 9:58:07 PM 62123722 C:\ijji\ENGLISH\Gunz\Sound
4/2/2010 9:58:08 PM 15878635 C:\ijji\ENGLISH\Gunz\Sound\Effect
4/2/2010 9:58:08 PM 10248410 C:\ijji\ENGLISH\Gunz\Sound\Effect\quest
4/2/2010 9:49:07 PM 1100398232 C:\ijji\ENGLISH\u_sf
4/2/2010 9:49:08 PM 1089727371 C:\ijji\ENGLISH\u_sf\data
4/2/2010 9:49:08 PM 459164893 C:\ijji\ENGLISH\u_sf\data\area
4/2/2010 9:49:18 PM 28373400 C:\ijji\ENGLISH\u_sf\data\clan
4/2/2010 9:49:22 PM 6912822 C:\ijji\ENGLISH\u_sf\data\effect
4/2/2010 9:49:23 PM 149074306 C:\ijji\ENGLISH\u_sf\data\force
4/2/2010 9:49:27 PM 269198752 C:\ijji\ENGLISH\u_sf\data\lobby
4/2/2010 9:49:38 PM 106518045 C:\ijji\ENGLISH\u_sf\data\menu
4/2/2010 9:49:40 PM 24 C:\ijji\ENGLISH\u_sf\data\save
4/2/2010 9:49:41 PM 2002081 C:\ijji\ENGLISH\u_sf\data\scr
4/2/2010 9:49:41 PM 27 C:\ijji\ENGLISH\u_sf\data\screenshot
4/2/2010 9:49:41 PM 28758663 C:\ijji\ENGLISH\u_sf\data\sound
4/2/2010 9:49:43 PM 39722483 C:\ijji\ENGLISH\u_sf\data\weapon
4/2/2010 9:49:08 PM 1267712 C:\ijji\ENGLISH\u_sf\redist
4/2/2010 9:49:46 PM 2417720 C:\ijji\ENGLISH\xfire
5/24/2010 8:52:36 PM 680 32 C:\avenger.txt
5/24/2010 8:57:00 PM 204 32 C:\mbzxz.txt
5/24/2010 8:43:25 PM 280 32 C:\WINDOWS\setupact.log
5/24/2010 8:43:25 PM 0 32 C:\WINDOWS\setuperr.log
5/24/2010 5:37:48 PM 22583 32 C:\WINDOWS\WindowsUpdate.log
3/26/2010 2:08:02 PM 2475216 C:\WINDOWS\System32\CanonIJ Uninstaller Information
3/26/2010 2:08:02 PM 2475216 C:\WINDOWS\System32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2600_series
3/26/2010 2:08:02 PM 1461880 C:\WINDOWS\System32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2600_series\RES
3/26/2010 2:08:02 PM 1441792 C:\WINDOWS\System32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2600_series\RES\DLL
3/26/2010 2:08:03 PM 20088 C:\WINDOWS\System32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2600_series\RES\STRING
4/7/2010 9:56:17 PM 2404648 C:\WINDOWS\System32\WTablet
3/26/2010 2:07:50 PM 269824 32 C:\WINDOWS\System32\CNMLM97.DLL
4/7/2010 9:56:36 PM 7543592 32 C:\WINDOWS\System32\PenTablet.cpl
4/7/2010 9:56:41 PM 1595175 32 C:\WINDOWS\System32\PenTablet.znc
4/7/2010 9:56:07 PM 456 32 C:\WINDOWS\System32\PenTabletUserDefaults.xml
4/7/2010 9:56:13 PM 490280 32 C:\WINDOWS\System32\Pen_Tablet.dll
4/7/2010 9:56:09 PM 5556520 32 C:\WINDOWS\System32\Pen_Tablet.exe
4/7/2010 9:56:07 PM 456 32 C:\WINDOWS\System32\TouchTabletUserDefaults.xml
4/7/2010 9:57:13 PM 290088 32 C:\WINDOWS\System32\Touch_Tablet.dll
====== "\Administrator & All Users\Startup" Last 60 Days======
====== "\Program Files" Last 60 Days======
3/26/2010 2:08:14 PM 2532002 C:\Program Files\Canon
3/26/2010 2:07:35 PM 9920559 C:\Program Files\CanonBJ
3/31/2010 11:39:53 AM 12818232 C:\Program Files\Rainmeter
4/7/2010 9:57:09 PM 7030326 C:\Program Files\WTouch
======"Drivers" Modified Last 60 Days======
====== Files Deleted under "%Temp%" ======
32 Files deleted
======"All Users\Application Data" Last 60 Days======
====== HKLM\~\ShellServiceObjectDelayLoad======
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} -
====== HKLM\~\SharedTaskScheduler======
======HKLM\~\msconfig\startupreg======
HKLM\Software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
HKLM\Software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager
HKLM\Software\microsoft\shared tools\msconfig\startupreg\Dell DataSafe Online
HKLM\Software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter
HKLM\Software\microsoft\shared tools\msconfig\startupreg\msnmsgr
HKLM\Software\microsoft\shared tools\msconfig\startupreg\Zune Launcher
====== Services ( Services that are Whitelisted are not shown) ======
1394ohci (1394 OHCI Compliant Host Controller)- C:\Windows\system32\DRIVERS\1394ohci.sys - Manual/Stopped
AcpiPmi (ACPI Power Meter Driver)- C:\Windows\system32\DRIVERS\acpipmi.sys - Manual/Stopped
adfs (adfs)- C:\Windows\system32\drivers\adfs.sys - Auto/Running
adp94xx (adp94xx)- C:\Windows\system32\DRIVERS\adp94xx.sys - Manual/Stopped
adpahci (adpahci)- C:\Windows\system32\DRIVERS\adpahci.sys - Manual/Stopped
amdide (amdide)- C:\Windows\system32\DRIVERS\amdide.sys - Manual/Stopped
amdsata (amdsata)- C:\Windows\system32\DRIVERS\amdsata.sys - Manual/Stopped
amdsbs (amdsbs)- C:\Windows\system32\DRIVERS\amdsbs.sys - Manual/Stopped
amdxata (amdxata)- C:\Windows\system32\DRIVERS\amdxata.sys - Boot/Running
ApfiltrService (Alps Touch Pad Filter Driver for Windows XP/Vista x64)- C:\Windows\system32\DRIVERS\Apfiltr.sys - Manual/Stopped
AppID (AppID Driver)- C:\Windows\system32\drivers\appid.sys - Manual/Stopped
arcsas (arcsas)- C:\Windows\system32\DRIVERS\arcsas.sys - Manual/Stopped
b06bdrv (Broadcom NetXtreme II VBD)- C:\Windows\system32\DRIVERS\bxvbda.sys - Manual/Stopped
b57nd60a (Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0)- C:\Windows\system32\DRIVERS\b57nd60a.sys - Manual/Stopped
BCM42RLY (BCM42RLY)- C:\Windows\system32\drivers\BCM42RLY.sys - Manual/Running
BCM43XX (Dell Wireless WLAN Card Driver)- C:\Windows\system32\DRIVERS\bcmwl664.sys - Manual/Stopped
blbdrive (blbdrive)- C:\Windows\system32\DRIVERS\blbdrive.sys - System/Running
bowser (Browser Support Driver)- C:\Windows\system32\DRIVERS\bowser.sys - Manual/Running
BrFiltLo (Brother USB Mass-Storage Lower Filter Driver)- C:\Windows\system32\DRIVERS\BrFiltLo.sys - Manual/Stopped
BrFiltUp (Brother USB Mass-Storage Upper Filter Driver)- C:\Windows\system32\DRIVERS\BrFiltUp.sys - Manual/Stopped
Brserid (Brother MFC Serial Port Interface Driver (WDM))- C:\Windows\system32\Drivers\Brserid.sys - Manual/Stopped
BrSerWdm (Brother WDM Serial driver)- C:\Windows\system32\Drivers\BrSerWdm.sys - Manual/Stopped
BrUsbMdm (Brother MFC USB Fax Only Modem)- C:\Windows\system32\Drivers\BrUsbMdm.sys - Manual/Stopped
BrUsbSer (Brother MFC USB Serial WDM Driver)- C:\Windows\system32\Drivers\BrUsbSer.sys - Manual/Stopped
circlass (Consumer IR Devices)- C:\Windows\system32\DRIVERS\circlass.sys - Manual/Stopped
CLFS (Common Log (CLFS))- C:\Windows\system32\CLFS.sys - Boot/Running
CNG (CNG)- C:\Windows\system32\Drivers\cng.sys - Boot/Running
CompositeBus (Composite Bus Enumerator Driver)- C:\Windows\system32\DRIVERS\CompositeBus.sys - Manual/Stopped
CtClsFlt (Creative Camera Class Upper Filter Driver)- C:\Windows\system32\DRIVERS\CtClsFlt.sys - Manual/Stopped
DfsC (DFS Namespace Client Driver)- C:\Windows\system32\Drivers\dfsc.sys - System/Running
discache (System Attribute Cache)- C:\Windows\system32\drivers\discache.sys - System/Running
DXGKrnl (LDDM Graphics Subsystem)- C:\Windows\system32\drivers\dxgkrnl.sys - Manual/Stopped
ebdrv (Broadcom NetXtreme II 10 GigE VBD)- C:\Windows\system32\DRIVERS\evbda.sys - Manual/Stopped
elxstor (elxstor)- C:\Windows\system32\DRIVERS\elxstor.sys - Manual/Stopped
ErrDev (Microsoft Hardware Error Device Driver)- C:\Windows\system32\DRIVERS\errdev.sys - Manual/Stopped
FileInfo (File Information FS MiniFilter)- C:\Windows\system32\drivers\fileinfo.sys - Boot/Running
Filetrace (Filetrace)- C:\Windows\system32\drivers\filetrace.sys - Manual/Stopped
FsDepends (File System Dependency Minifilter)- C:\Windows\system32\drivers\FsDepends.sys - Manual/Stopped
fvevol (Bitlocker Drive Encryption Filter Driver)- C:\Windows\system32\DRIVERS\fvevol.sys - Boot/Running
gagp30kx (Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms)- C:\Windows\system32\DRIVERS\gagp30kx.sys - Manual/Stopped
hcw85cir (Hauppauge Consumer Infrared Receiver)- C:\Windows\system32\drivers\hcw85cir.sys - Manual/Stopped
HidBth (Microsoft Bluetooth HID Miniport)- C:\Windows\system32\DRIVERS\hidbth.sys - Manual/Stopped
HidIr (Microsoft Infrared HID Driver)- C:\Windows\system32\DRIVERS\hidir.sys - Manual/Stopped
HpSAMD (HpSAMD)- C:\Windows\system32\DRIVERS\HpSAMD.sys - Manual/Stopped
hwpolicy (Hardware Policy Driver)- C:\Windows\system32\drivers\hwpolicy.sys - Boot/Running
iaStorV (iaStorV)- C:\Windows\system32\DRIVERS\iaStorV.sys - Manual/Stopped
igfx (igfx)- C:\Windows\system32\DRIVERS\igdkmd64.sys - Manual/Stopped
IPMIDRV (IPMIDRV)- C:\Windows\system32\DRIVERS\IPMIDrv.sys - Manual/Stopped
iScsiPrt (iScsiPort Driver)- C:\Windows\system32\DRIVERS\msiscsi.sys - Manual/Stopped
KSecPkg (KSecPkg)- C:\Windows\system32\Drivers\ksecpkg.sys - Boot/Running
lltdio (Link-Layer Topology Discovery Mapper I/O Driver)- C:\Windows\system32\DRIVERS\lltdio.sys - Auto/Running
LSI_FC (LSI_FC)- C:\Windows\system32\DRIVERS\lsi_fc.sys - Manual/Stopped
LSI_SAS (LSI_SAS)- C:\Windows\system32\DRIVERS\lsi_sas.sys - Manual/Stopped
LSI_SAS2 (LSI_SAS2)- C:\Windows\system32\DRIVERS\lsi_sas2.sys - Manual/Stopped
LSI_SCSI (LSI_SCSI)- C:\Windows\system32\DRIVERS\lsi_scsi.sys - Manual/Stopped
luafv (UAC File Virtualization)- C:\Windows\system32\drivers\luafv.sys - Auto/Running
megasas (megasas)- C:\Windows\system32\DRIVERS\megasas.sys - Manual/Stopped
MegaSR (MegaSR)- C:\Windows\system32\DRIVERS\MegaSR.sys - Manual/Stopped
mpio (mpio)- C:\Windows\system32\DRIVERS\mpio.sys - Manual/Stopped
mpsdrv (Windows Firewall Authorization Driver)- C:\Windows\system32\drivers\mpsdrv.sys - Manual/Running
mrxsmb10 (SMB 1.x MiniRedirector)- C:\Windows\system32\DRIVERS\mrxsmb10.sys - Manual/Running
mrxsmb20 (SMB 2.0 MiniRedirector)- C:\Windows\system32\DRIVERS\mrxsmb20.sys - Manual/Running
msahci (msahci)- C:\Windows\system32\DRIVERS\msahci.sys - Boot/Running
msdsm (msdsm)- C:\Windows\system32\DRIVERS\msdsm.sys - Manual/Stopped
mshidkmdf (Pass-through HID to KMDF Filter Driver)- C:\Windows\system32\drivers\mshidkmdf.sys - Manual/Stopped
msisadrv (msisadrv)- C:\Windows\system32\DRIVERS\msisadrv.sys - Boot/Running
MsRPC (MsRPC)- C:\Windows\system32\drivers\MsRPC.sys - Manual/Stopped
MTConfig (Microsoft Input Configuration Driver)- C:\Windows\system32\DRIVERS\MTConfig.sys - Manual/Stopped
NativeWifiP (NativeWiFi Filter)- C:\Windows\system32\DRIVERS\nwifi.sys - Manual/Running
NdisCap (NDIS Capture LightWeight Filter)- C:\Windows\system32\DRIVERS\ndiscap.sys - Manual/Stopped
nfrd960 (nfrd960)- C:\Windows\system32\DRIVERS\nfrd960.sys - Manual/Stopped
nsiproxy (NSI proxy service driver.)- C:\Windows\system32\drivers\nsiproxy.sys - System/Running
nvstor (nvstor)- C:\Windows\system32\DRIVERS\nvstor.sys - Manual/Stopped
pcw (Performance Counters for Windows Driver)- C:\Windows\system32\drivers\pcw.sys - Boot/Running
PEAUTH (PEAUTH)- C:\Windows\system32\drivers\peauth.sys - Auto/Running
PxHlpa64 (PxHlpa64)- C:\Windows\system32\Drivers\PxHlpa64.sys - Boot/Running
ql2300 (ql2300)- C:\Windows\system32\DRIVERS\ql2300.sys - Manual/Stopped
ql40xx (ql40xx)- C:\Windows\system32\DRIVERS\ql40xx.sys - Manual/Stopped
QWAVEdrv (QWAVE driver)- C:\Windows\system32\drivers\qwavedrv.sys - Manual/Stopped
RasAgileVpn (WAN Miniport (IKEv2))- C:\Windows\system32\DRIVERS\AgileVpn.sys - Manual/Stopped
rdpbus (Remote Desktop Device Redirector Bus Driver)- C:\Windows\system32\DRIVERS\rdpbus.sys - Manual/Stopped
RDPENCDD (RDP Encoder Mirror Driver)- C:\Windows\system32\drivers\rdpencdd.sys - System/Running
RDPREFMP (Reflector Display Driver used to gain access to graphics data)- C:\Windows\system32\drivers\rdprefmp.sys - System/Running
rdyboost (ReadyBoost)- C:\Windows\system32\drivers\rdyboost.sys - Boot/Running
rspndr (Link-Layer Topology Discovery Responder)- C:\Windows\system32\DRIVERS\rspndr.sys - Auto/Running
RSUSBSTOR (RtsUStor.Sys Realtek USB Card Reader)- C:\Windows\system32\Drivers\RtsUStor.sys - Manual/Stopped
RTL8167 (Realtek 8167 NT Driver)- C:\Windows\system32\DRIVERS\Rt64win7.sys - Manual/Stopped
sbp2port (sbp2port)- C:\Windows\system32\DRIVERS\sbp2port.sys - Manual/Stopped
scfilter (Smart card PnP Class Filter Driver)- C:\Windows\system32\DRIVERS\scfilter.sys - Manual/Stopped
sermouse (Serial Mouse Driver)- C:\Windows\system32\DRIVERS\sermouse.sys - Manual/Stopped
sffdisk (SFF Storage Class Driver)- C:\Windows\system32\DRIVERS\sffdisk.sys - Manual/Stopped
sffp_mmc (SFF Storage Protocol Driver for MMC)- C:\Windows\system32\DRIVERS\sffp_mmc.sys - Manual/Stopped
sffp_sd (SFF Storage Protocol Driver for SDBus)- C:\Windows\system32\DRIVERS\sffp_sd.sys - Manual/Stopped
SiSRaid2 (SiSRaid2)- C:\Windows\system32\DRIVERS\SiSRaid2.sys - Manual/Stopped
SiSRaid4 (SiSRaid4)- C:\Windows\system32\DRIVERS\sisraid4.sys - Manual/Stopped
spldr (Security Processor Loader Driver)- C:\Windows\system32\drivers\spldr.sys - Boot/Running
srv2 (Server SMB 2.xxx Driver)- C:\Windows\system32\DRIVERS\srv2.sys - Manual/Running
srvnet (srvnet)- C:\Windows\system32\DRIVERS\srvnet.sys - Manual/Running
stexstor (stexstor)- C:\Windows\system32\DRIVERS\stexstor.sys - Manual/Stopped
STHDA (IDT High Definition Audio CODEC)- C:\Windows\system32\DRIVERS\stwrt64.sys - Manual/Stopped
TCPIP6 (Microsoft IPv6 Protocol Driver)- C:\Windows\system32\DRIVERS\tcpip.sys - Manual/Stopped
tcpipreg (TCP/IP Registry Compatibility)- C:\Windows\system32\drivers\tcpipreg.sys - Auto/Running
tdx (NetIO Legacy TDI Support Driver)- C:\Windows\system32\DRIVERS\tdx.sys - System/Running
tssecsrv (Remote Desktop Services Security Filter Driver)- C:\Windows\system32\DRIVERS\tssecsrv.sys - Manual/Stopped
tunnel (Microsoft Tunnel Miniport Adapter Driver)- C:\Windows\system32\DRIVERS\tunnel.sys - Manual/Stopped
uagp35 (Microsoft AGPv3.5 Filter)- C:\Windows\system32\DRIVERS\uagp35.sys - Manual/Stopped
uliagpkx (Uli AGP Bus Filter)- C:\Windows\system32\DRIVERS\uliagpkx.sys - Manual/Stopped
umbus (UMBus Enumerator Driver)- C:\Windows\system32\DRIVERS\umbus.sys - Manual/Stopped
UmPass (Microsoft UMPass Driver)- C:\Windows\system32\DRIVERS\umpass.sys - Manual/Stopped
usbcir (eHome Infrared Receiver (USBCIR))- C:\Windows\system32\DRIVERS\usbcir.sys - Manual/Stopped
usbvideo (USB Video Device (WDM))- C:\Windows\system32\Drivers\usbvideo.sys - Manual/Stopped
vdrvroot (Microsoft Virtual Drive Enumerator Driver)- C:\Windows\system32\DRIVERS\vdrvroot.sys - Boot/Running
vhdmp (vhdmp)- C:\Windows\system32\DRIVERS\vhdmp.sys - Manual/Stopped
volmgr (Volume Manager Driver)- C:\Windows\system32\DRIVERS\volmgr.sys - Boot/Running
volmgrx (Dynamic Volume Manager)- C:\Windows\system32\drivers\volmgrx.sys - Boot/Running
vsmraid (vsmraid)- C:\Windows\system32\DRIVERS\vsmraid.sys - Manual/Stopped
vwifibus (Virtual WiFi Bus Driver)- C:\Windows\system32\DRIVERS\vwifibus.sys - Manual/Stopped
vwififlt (Virtual WiFi Filter Driver)- C:\Windows\system32\DRIVERS\vwififlt.sys - System/Running
wacommousefilter (Wacom Mouse Filter Driver)- C:\Windows\system32\DRIVERS\wacommousefilter.sys - Manual/Stopped
WacomPen (Wacom Serial Pen HID Driver)- C:\Windows\system32\DRIVERS\wacompen.sys - Manual/Stopped
Wanarpv6 (Remote Access IPv6 ARP Driver)- C:\Windows\system32\DRIVERS\wanarp.sys - System/Running
Wdf01000 (Kernel Mode Driver Frameworks service)- C:\Windows\system32\drivers\Wdf01000.sys - Boot/Running
WfpLwf (WFP Lightweight Filter)- C:\Windows\system32\DRIVERS\wfplwf.sys - System/Running
WimFltr (WimFltr)- C:\Windows\system32\DRIVERS\wimfltr.sys - Manual/Stopped
WIMMount (WIMMount)- C:\Windows\system32\drivers\wimmount.sys - Manual/Stopped
WinUSB (WinUSB)- C:\Windows\system32\DRIVERS\WinUSB.sys - Manual/Stopped
WmiAcpi (Microsoft Windows Management Interface for ACPI)- C:\Windows\system32\DRIVERS\wmiacpi.sys - Manual/Stopped
====== Uninstall List ======
A file named 'UNI.txt' was created and saved to
FileListers default location. Post the results if requested.
======== Other Info ========
TOTAL PHYSICAL RAM: 4256 MB
Boot Info
OS Type: Microsoft Windows 7 Home Premium
Build: 6.1.7600
Service Pack: 0.0
====== Files with Hidden Attributes======
A file named 'Hidden.txt' was created and saved to
FileListers default location. Post the results if requested.
==End of Report==
--------------------------------------------------------------
Hijackthis
_______________________________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:28:29 PM, on 5/24/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Windows\SysWOW64\explorer.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWow64\Macromed\Flash\FlashUtil10b.exe
C:\Program Files (x86)\AIM\aim.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\SysWOW64\msiexec.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
O4 - HKLM\..\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe
O4 - HKLM\..\RunOnce: [STToasterLauncher] C:\program files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe
O4 - HKCU\..\Run: [svchost] C:\Users\Blade\AppData\Roaming\Microsoft\svchost.exe
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\WINDOWS\System32\StikyNot.exe
O4 - HKCU\..\Run: [StartServiceSNDKBKWW] C:\Users\Blade\AppData\Local\SNDKBKWW\StartService.exe
O4 - HKCU\..\Run: [Cerberus] C:\Users\Blade\AppData\Roaming\Cerberus\server.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TabletServicePen - Unknown owner - C:\Windows\system32\Pen_Tablet.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: WTouch Service (WTouchService) - Wacom Technology, Corp. - C:\Program Files\WTouch\WTouchService.exe
O23 - Service: Zune Wireless Configuration Service (ZuneWlanCfgSvc) - Unknown owner - c:\Windows\system32\ZuneWlanCfgSvc.exe (file missing)
--
End of file - 10352 bytes
bamajim
10.4K Posts
0
May 31st, 2010 07:00
The reports you poste are from
Report ran on --->>> 5/26/2010 8:33:51 AM
And
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:28:29 PM, on 5/24/2010
Could you Rerun The reports and post the current logs.
BladeRaver
6 Posts
0
May 31st, 2010 10:00
Thats odd. I reran the reports. I got a error invalid script for avenger. I did just rerun the logs at 5/31/2010 12:25 pm
*edit* I forgot to run as administrator. Trying Avenger again.
---still got a invalid script with avenger-----
_____________________________________________________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:36:05 PM, on 5/31/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
O4 - HKLM\..\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe
O4 - HKLM\..\RunOnce: [STToasterLauncher] C:\program files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\WINDOWS\System32\StikyNot.exe
O4 - HKCU\..\Run: [StartServiceSNDKBKWW] C:\Users\Blade\AppData\Local\SNDKBKWW\StartService.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TabletServicePen - Unknown owner - C:\Windows\system32\Pen_Tablet.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: WTouch Service (WTouchService) - Wacom Technology, Corp. - C:\Program Files\WTouch\WTouchService.exe
O23 - Service: Zune Wireless Configuration Service (ZuneWlanCfgSvc) - Unknown owner - c:\Windows\system32\ZuneWlanCfgSvc.exe (file missing)
--
End of file - 9942 bytes
-----------------------------------------------------------------------------
------------------------------------------------------------------------------
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////
Platform: Windows NT 6.1 (build 7600)
Mon May 24 20:52:36 2010
20:52:36: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!
//////////////////////////////////////////
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////
Platform: Windows NT 6.1 (build 7600)
Fri May 28 20:47:26 2010
20:47:26: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!
//////////////////////////////////////////
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////
Platform: Windows NT 6.1 (build 7600)
Fri May 28 20:47:44 2010
20:47:44: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!
//////////////////////////////////////////
bamajim
10.4K Posts
0
June 7th, 2010 08:00
We may have to do this manually
Rerun FileLister and post a fresh log
BladeRaver
6 Posts
0
June 7th, 2010 11:00
Reran filelister and here is the result
----------------------------------------------------
+++++++++++++++++++++++++++
+ File Lister Version 1.1.4 +
+ +
+ By bamajim / SpywareHammer.com +
+++++++++++++++++++++++++++
Report ran on --->>> 6/7/2010 1:38:01 PM
====== Running Processes ======
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Program Files\DellTPad\Apoint.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\WINDOWS\System32\StikyNot.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\System32\WScript.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
====== BHO's ======
BHO: (NO NAME) - {DBC80044-A445-435b-BC74-9C25C1C588A9} -
====== System Keys (some whitelisted items will not be shown)======
Winlogon\Userinit = C:\Windows\system32\userinit.exe,
Winlogon\Shell = explorer.exe
====== HKLM\~\Run Keys ======
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
[Apoint] = C:\Program Files\DellTPad\Apoint.exe
[IgfxTray] = C:\Windows\system32\igfxtray.exe
[HotKeysCmds] = C:\Windows\system32\hkcmd.exe
[Persistence] = C:\Windows\system32\igfxpers.exe
[Broadcom Wireless Manager UI] = C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe
[SysTrayApp] = C:\Program Files\IDT\WDM\sttray64.exe
[QuickSet] = C:\Program Files\Dell\QuickSet\QuickSet.exe
[CanonMyPrinter] = C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
====== HKCU\~\Run Keys ======
[AdobeBridge] =
[RESTART_STICKY_NOTES] = C:\WINDOWS\System32\StikyNot.exe
[StartServiceSNDKBKWW] = C:\Users\Blade\AppData\Local\SNDKBKWW\StartService.exe
====== DNS Info (List may be empty) ======
ICSDomain = mshome.net
SyncDomainWithMembership = 1
NV Hostname = Blade-PC
DataBasePath = %SystemRoot%\System32\drivers\etc
ForwardBroadcasts = 0
IPEnableRouter = 0
Hostname = Blade-PC
UseDomainNameDevolution = 1
EnableICMPRedirect = 1
DeadGWDetectDefault = 1
DontAddDefaultGatewayDefault = 0
EnableWsd = 1
QualifyingDestinationThreshold = 3
DhcpNameServer = 10.91.32.10 10.91.32.15
DhcpDomain = academic.iadtdetroit.com
====== Folders and Files from "%\" and "%\Windows" Created Last 60 Days ======
5/27/2010 1:47:33 PM 2916 32 C:\aaw7boot.log
5/24/2010 8:52:36 PM 2064 32 C:\avenger.txt
5/24/2010 8:57:00 PM 204 32 C:\mbzxz.txt
5/31/2010 12:39:49 PM 248 32 C:\rhsaey.txt
5/31/2010 12:21:04 PM 248 32 C:\sbsjhxk.txt
5/28/2010 8:48:38 PM 248 32 C:\wtvanf.txt
5/27/2010 9:36:06 PM 1802 32 C:\WINDOWS\setupact.log
5/27/2010 9:36:06 PM 0 32 C:\WINDOWS\setuperr.log
5/24/2010 5:37:48 PM 134544 32 C:\WINDOWS\WindowsUpdate.log
5/27/2010 1:05:48 PM 78858 C:\WINDOWS\System32\DRVSTORE
5/27/2010 1:05:48 PM 78858 C:\WINDOWS\System32\DRVSTORE\lbd_B03EF9FD94112EB728974311A5279D0DF297C31C
4/7/2010 9:56:17 PM 2404648 C:\WINDOWS\System32\WTablet
5/27/2010 1:44:27 PM 15880 32 C:\WINDOWS\System32\lsdelete.exe
4/7/2010 9:56:36 PM 7543592 32 C:\WINDOWS\System32\PenTablet.cpl
4/7/2010 9:56:41 PM 1595175 32 C:\WINDOWS\System32\PenTablet.znc
4/7/2010 9:56:07 PM 456 32 C:\WINDOWS\System32\PenTabletUserDefaults.xml
4/7/2010 9:56:13 PM 490280 32 C:\WINDOWS\System32\Pen_Tablet.dll
4/7/2010 9:56:09 PM 5556520 32 C:\WINDOWS\System32\Pen_Tablet.exe
4/7/2010 9:56:07 PM 456 32 C:\WINDOWS\System32\TouchTabletUserDefaults.xml
4/7/2010 9:57:13 PM 290088 32 C:\WINDOWS\System32\Touch_Tablet.dll
====== "\Administrator & All Users\Startup" Last 60 Days======
====== "\Program Files" Last 60 Days======
4/7/2010 9:57:09 PM 7030326 C:\Program Files\WTouch
======"Drivers" Modified Last 60 Days======
5/27/2010 1:05:45 PM 95024 32 C:\WINDOWS\System32\drivers\SBREDrv.sys
====== Files Deleted under "%Temp%" ======
15 Files deleted
======"All Users\Application Data" Last 60 Days======
====== HKLM\~\ShellServiceObjectDelayLoad======
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} -
====== HKLM\~\SharedTaskScheduler======
======HKLM\~\msconfig\startupreg======
HKLM\Software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
HKLM\Software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager
HKLM\Software\microsoft\shared tools\msconfig\startupreg\Dell DataSafe Online
HKLM\Software\microsoft\shared tools\msconfig\startupreg\DellSupportCenter
HKLM\Software\microsoft\shared tools\msconfig\startupreg\msnmsgr
HKLM\Software\microsoft\shared tools\msconfig\startupreg\Zune Launcher
====== Services ( Services that are Whitelisted are not shown) ======
1394ohci (1394 OHCI Compliant Host Controller)- C:\Windows\system32\DRIVERS\1394ohci.sys - Manual/Stopped
AcpiPmi (ACPI Power Meter Driver)- C:\Windows\system32\DRIVERS\acpipmi.sys - Manual/Stopped
adfs (adfs)- C:\Windows\system32\drivers\adfs.sys - Auto/Running
adp94xx (adp94xx)- C:\Windows\system32\DRIVERS\adp94xx.sys - Manual/Stopped
adpahci (adpahci)- C:\Windows\system32\DRIVERS\adpahci.sys - Manual/Stopped
amdide (amdide)- C:\Windows\system32\DRIVERS\amdide.sys - Manual/Stopped
amdsata (amdsata)- C:\Windows\system32\DRIVERS\amdsata.sys - Manual/Stopped
amdsbs (amdsbs)- C:\Windows\system32\DRIVERS\amdsbs.sys - Manual/Stopped
amdxata (amdxata)- C:\Windows\system32\DRIVERS\amdxata.sys - Boot/Running
ApfiltrService (Alps Touch Pad Filter Driver for Windows XP/Vista x64)- C:\Windows\system32\DRIVERS\Apfiltr.sys - Manual/Running
AppID (AppID Driver)- C:\Windows\system32\drivers\appid.sys - Manual/Stopped
arcsas (arcsas)- C:\Windows\system32\DRIVERS\arcsas.sys - Manual/Stopped
b06bdrv (Broadcom NetXtreme II VBD)- C:\Windows\system32\DRIVERS\bxvbda.sys - Manual/Stopped
b57nd60a (Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0)- C:\Windows\system32\DRIVERS\b57nd60a.sys - Manual/Stopped
BCM42RLY (BCM42RLY)- C:\Windows\system32\drivers\BCM42RLY.sys - Manual/Running
BCM43XX (Dell Wireless WLAN Card Driver)- C:\Windows\system32\DRIVERS\bcmwl664.sys - Manual/Running
blbdrive (blbdrive)- C:\Windows\system32\DRIVERS\blbdrive.sys - System/Running
bowser (Browser Support Driver)- C:\Windows\system32\DRIVERS\bowser.sys - Manual/Running
BrFiltLo (Brother USB Mass-Storage Lower Filter Driver)- C:\Windows\system32\DRIVERS\BrFiltLo.sys - Manual/Stopped
BrFiltUp (Brother USB Mass-Storage Upper Filter Driver)- C:\Windows\system32\DRIVERS\BrFiltUp.sys - Manual/Stopped
Brserid (Brother MFC Serial Port Interface Driver (WDM))- C:\Windows\system32\Drivers\Brserid.sys - Manual/Stopped
BrSerWdm (Brother WDM Serial driver)- C:\Windows\system32\Drivers\BrSerWdm.sys - Manual/Stopped
BrUsbMdm (Brother MFC USB Fax Only Modem)- C:\Windows\system32\Drivers\BrUsbMdm.sys - Manual/Stopped
BrUsbSer (Brother MFC USB Serial WDM Driver)- C:\Windows\system32\Drivers\BrUsbSer.sys - Manual/Stopped
circlass (Consumer IR Devices)- C:\Windows\system32\DRIVERS\circlass.sys - Manual/Stopped
CLFS (Common Log (CLFS))- C:\Windows\system32\CLFS.sys - Boot/Running
CNG (CNG)- C:\Windows\system32\Drivers\cng.sys - Boot/Running
CompositeBus (Composite Bus Enumerator Driver)- C:\Windows\system32\DRIVERS\CompositeBus.sys - Manual/Running
CtClsFlt (Creative Camera Class Upper Filter Driver)- C:\Windows\system32\DRIVERS\CtClsFlt.sys - Manual/Running
DfsC (DFS Namespace Client Driver)- C:\Windows\system32\Drivers\dfsc.sys - System/Running
discache (System Attribute Cache)- C:\Windows\system32\drivers\discache.sys - System/Running
DXGKrnl (LDDM Graphics Subsystem)- C:\Windows\system32\drivers\dxgkrnl.sys - Manual/Running
ebdrv (Broadcom NetXtreme II 10 GigE VBD)- C:\Windows\system32\DRIVERS\evbda.sys - Manual/Stopped
elxstor (elxstor)- C:\Windows\system32\DRIVERS\elxstor.sys - Manual/Stopped
ErrDev (Microsoft Hardware Error Device Driver)- C:\Windows\system32\DRIVERS\errdev.sys - Manual/Stopped
FileInfo (File Information FS MiniFilter)- C:\Windows\system32\drivers\fileinfo.sys - Boot/Running
Filetrace (Filetrace)- C:\Windows\system32\drivers\filetrace.sys - Manual/Stopped
FsDepends (File System Dependency Minifilter)- C:\Windows\system32\drivers\FsDepends.sys - Manual/Stopped
fvevol (Bitlocker Drive Encryption Filter Driver)- C:\Windows\system32\DRIVERS\fvevol.sys - Boot/Running
gagp30kx (Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms)- C:\Windows\system32\DRIVERS\gagp30kx.sys - Manual/Stopped
hcw85cir (Hauppauge Consumer Infrared Receiver)- C:\Windows\system32\drivers\hcw85cir.sys - Manual/Stopped
HidBth (Microsoft Bluetooth HID Miniport)- C:\Windows\system32\DRIVERS\hidbth.sys - Manual/Stopped
HidIr (Microsoft Infrared HID Driver)- C:\Windows\system32\DRIVERS\hidir.sys - Manual/Stopped
HpSAMD (HpSAMD)- C:\Windows\system32\DRIVERS\HpSAMD.sys - Manual/Stopped
hwpolicy (Hardware Policy Driver)- C:\Windows\system32\drivers\hwpolicy.sys - Boot/Running
iaStorV (iaStorV)- C:\Windows\system32\DRIVERS\iaStorV.sys - Manual/Stopped
igfx (igfx)- C:\Windows\system32\DRIVERS\igdkmd64.sys - Manual/Running
IPMIDRV (IPMIDRV)- C:\Windows\system32\DRIVERS\IPMIDrv.sys - Manual/Stopped
iScsiPrt (iScsiPort Driver)- C:\Windows\system32\DRIVERS\msiscsi.sys - Manual/Stopped
KSecPkg (KSecPkg)- C:\Windows\system32\Drivers\ksecpkg.sys - Boot/Running
Lbd (Lbd)- C:\Windows\system32\DRIVERS\Lbd.sys - Boot/Running
lltdio (Link-Layer Topology Discovery Mapper I/O Driver)- C:\Windows\system32\DRIVERS\lltdio.sys - Auto/Running
LSI_FC (LSI_FC)- C:\Windows\system32\DRIVERS\lsi_fc.sys - Manual/Stopped
LSI_SAS (LSI_SAS)- C:\Windows\system32\DRIVERS\lsi_sas.sys - Manual/Stopped
LSI_SAS2 (LSI_SAS2)- C:\Windows\system32\DRIVERS\lsi_sas2.sys - Manual/Stopped
LSI_SCSI (LSI_SCSI)- C:\Windows\system32\DRIVERS\lsi_scsi.sys - Manual/Stopped
luafv (UAC File Virtualization)- C:\Windows\system32\drivers\luafv.sys - Auto/Running
megasas (megasas)- C:\Windows\system32\DRIVERS\megasas.sys - Manual/Stopped
MegaSR (MegaSR)- C:\Windows\system32\DRIVERS\MegaSR.sys - Manual/Stopped
mpio (mpio)- C:\Windows\system32\DRIVERS\mpio.sys - Manual/Stopped
mpsdrv (Windows Firewall Authorization Driver)- C:\Windows\system32\drivers\mpsdrv.sys - Manual/Running
mrxsmb10 (SMB 1.x MiniRedirector)- C:\Windows\system32\DRIVERS\mrxsmb10.sys - Manual/Running
mrxsmb20 (SMB 2.0 MiniRedirector)- C:\Windows\system32\DRIVERS\mrxsmb20.sys - Manual/Running
msahci (msahci)- C:\Windows\system32\DRIVERS\msahci.sys - Boot/Running
msdsm (msdsm)- C:\Windows\system32\DRIVERS\msdsm.sys - Manual/Stopped
mshidkmdf (Pass-through HID to KMDF Filter Driver)- C:\Windows\system32\drivers\mshidkmdf.sys - Manual/Stopped
msisadrv (msisadrv)- C:\Windows\system32\DRIVERS\msisadrv.sys - Boot/Running
MsRPC (MsRPC)- C:\Windows\system32\drivers\MsRPC.sys - Manual/Stopped
MTConfig (Microsoft Input Configuration Driver)- C:\Windows\system32\DRIVERS\MTConfig.sys - Manual/Stopped
NativeWifiP (NativeWiFi Filter)- C:\Windows\system32\DRIVERS\nwifi.sys - Manual/Running
NdisCap (NDIS Capture LightWeight Filter)- C:\Windows\system32\DRIVERS\ndiscap.sys - Manual/Stopped
nfrd960 (nfrd960)- C:\Windows\system32\DRIVERS\nfrd960.sys - Manual/Stopped
nsiproxy (NSI proxy service driver.)- C:\Windows\system32\drivers\nsiproxy.sys - System/Running
nvstor (nvstor)- C:\Windows\system32\DRIVERS\nvstor.sys - Manual/Stopped
pcw (Performance Counters for Windows Driver)- C:\Windows\system32\drivers\pcw.sys - Boot/Running
PEAUTH (PEAUTH)- C:\Windows\system32\drivers\peauth.sys - Auto/Running
PxHlpa64 (PxHlpa64)- C:\Windows\system32\Drivers\PxHlpa64.sys - Boot/Running
ql2300 (ql2300)- C:\Windows\system32\DRIVERS\ql2300.sys - Manual/Stopped
ql40xx (ql40xx)- C:\Windows\system32\DRIVERS\ql40xx.sys - Manual/Stopped
QWAVEdrv (QWAVE driver)- C:\Windows\system32\drivers\qwavedrv.sys - Manual/Stopped
RasAgileVpn (WAN Miniport (IKEv2))- C:\Windows\system32\DRIVERS\AgileVpn.sys - Manual/Running
rdpbus (Remote Desktop Device Redirector Bus Driver)- C:\Windows\system32\DRIVERS\rdpbus.sys - Manual/Stopped
RDPENCDD (RDP Encoder Mirror Driver)- C:\Windows\system32\drivers\rdpencdd.sys - System/Running
RDPREFMP (Reflector Display Driver used to gain access to graphics data)- C:\Windows\system32\drivers\rdprefmp.sys - System/Running
rdyboost (ReadyBoost)- C:\Windows\system32\drivers\rdyboost.sys - Boot/Running
rspndr (Link-Layer Topology Discovery Responder)- C:\Windows\system32\DRIVERS\rspndr.sys - Auto/Running
RSUSBSTOR (RtsUStor.Sys Realtek USB Card Reader)- C:\Windows\system32\Drivers\RtsUStor.sys - Manual/Stopped
RTL8167 (Realtek 8167 NT Driver)- C:\Windows\system32\DRIVERS\Rt64win7.sys - Manual/Running
sbp2port (sbp2port)- C:\Windows\system32\DRIVERS\sbp2port.sys - Manual/Stopped
scfilter (Smart card PnP Class Filter Driver)- C:\Windows\system32\DRIVERS\scfilter.sys - Manual/Stopped
sermouse (Serial Mouse Driver)- C:\Windows\system32\DRIVERS\sermouse.sys - Manual/Stopped
sffdisk (SFF Storage Class Driver)- C:\Windows\system32\DRIVERS\sffdisk.sys - Manual/Stopped
sffp_mmc (SFF Storage Protocol Driver for MMC)- C:\Windows\system32\DRIVERS\sffp_mmc.sys - Manual/Stopped
sffp_sd (SFF Storage Protocol Driver for SDBus)- C:\Windows\system32\DRIVERS\sffp_sd.sys - Manual/Stopped
SiSRaid2 (SiSRaid2)- C:\Windows\system32\DRIVERS\SiSRaid2.sys - Manual/Stopped
SiSRaid4 (SiSRaid4)- C:\Windows\system32\DRIVERS\sisraid4.sys - Manual/Stopped
spldr (Security Processor Loader Driver)- C:\Windows\system32\drivers\spldr.sys - Boot/Running
srv2 (Server SMB 2.xxx Driver)- C:\Windows\system32\DRIVERS\srv2.sys - Manual/Running
srvnet (srvnet)- C:\Windows\system32\DRIVERS\srvnet.sys - Manual/Running
stexstor (stexstor)- C:\Windows\system32\DRIVERS\stexstor.sys - Manual/Stopped
STHDA (IDT High Definition Audio CODEC)- C:\Windows\system32\DRIVERS\stwrt64.sys - Manual/Running
TCPIP6 (Microsoft IPv6 Protocol Driver)- C:\Windows\system32\DRIVERS\tcpip.sys - Manual/Stopped
tcpipreg (TCP/IP Registry Compatibility)- C:\Windows\system32\drivers\tcpipreg.sys - Auto/Running
tdx (NetIO Legacy TDI Support Driver)- C:\Windows\system32\DRIVERS\tdx.sys - System/Running
tssecsrv (Remote Desktop Services Security Filter Driver)- C:\Windows\system32\DRIVERS\tssecsrv.sys - Manual/Stopped
tunnel (Microsoft Tunnel Miniport Adapter Driver)- C:\Windows\system32\DRIVERS\tunnel.sys - Manual/Running
uagp35 (Microsoft AGPv3.5 Filter)- C:\Windows\system32\DRIVERS\uagp35.sys - Manual/Stopped
uliagpkx (Uli AGP Bus Filter)- C:\Windows\system32\DRIVERS\uliagpkx.sys - Manual/Stopped
umbus (UMBus Enumerator Driver)- C:\Windows\system32\DRIVERS\umbus.sys - Manual/Running
UmPass (Microsoft UMPass Driver)- C:\Windows\system32\DRIVERS\umpass.sys - Manual/Stopped
usbcir (eHome Infrared Receiver (USBCIR))- C:\Windows\system32\DRIVERS\usbcir.sys - Manual/Stopped
usbvideo (USB Video Device (WDM))- C:\Windows\system32\Drivers\usbvideo.sys - Manual/Running
vdrvroot (Microsoft Virtual Drive Enumerator Driver)- C:\Windows\system32\DRIVERS\vdrvroot.sys - Boot/Running
vhdmp (vhdmp)- C:\Windows\system32\DRIVERS\vhdmp.sys - Manual/Stopped
volmgr (Volume Manager Driver)- C:\Windows\system32\DRIVERS\volmgr.sys - Boot/Running
volmgrx (Dynamic Volume Manager)- C:\Windows\system32\drivers\volmgrx.sys - Boot/Running
vsmraid (vsmraid)- C:\Windows\system32\DRIVERS\vsmraid.sys - Manual/Stopped
vwifibus (Virtual WiFi Bus Driver)- C:\Windows\system32\DRIVERS\vwifibus.sys - Manual/Running
vwififlt (Virtual WiFi Filter Driver)- C:\Windows\system32\DRIVERS\vwififlt.sys - System/Running
wacommousefilter (Wacom Mouse Filter Driver)- C:\Windows\system32\DRIVERS\wacommousefilter.sys - Manual/Stopped
WacomPen (Wacom Serial Pen HID Driver)- C:\Windows\system32\DRIVERS\wacompen.sys - Manual/Stopped
Wanarpv6 (Remote Access IPv6 ARP Driver)- C:\Windows\system32\DRIVERS\wanarp.sys - System/Running
Wdf01000 (Kernel Mode Driver Frameworks service)- C:\Windows\system32\drivers\Wdf01000.sys - Boot/Running
WfpLwf (WFP Lightweight Filter)- C:\Windows\system32\DRIVERS\wfplwf.sys - System/Running
WimFltr (WimFltr)- C:\Windows\system32\DRIVERS\wimfltr.sys - Manual/Stopped
WIMMount (WIMMount)- C:\Windows\system32\drivers\wimmount.sys - Manual/Stopped
WinUSB (WinUSB)- C:\Windows\system32\DRIVERS\WinUSB.sys - Manual/Stopped
WmiAcpi (Microsoft Windows Management Interface for ACPI)- C:\Windows\system32\DRIVERS\wmiacpi.sys - Manual/Running
====== Uninstall List ======
A file named 'UNI.txt' was created and saved to
FileListers default location. Post the results if requested.
======== Other Info ========
TOTAL PHYSICAL RAM: 4256 MB
Boot Info
OS Type: Microsoft Windows 7 Home Premium
Build: 6.1.7600
Service Pack: 0.0
====== Files with Hidden Attributes======
A file named 'Hidden.txt' was created and saved to
FileListers default location. Post the results if requested.
==End of Report==
bamajim
10.4K Posts
0
June 7th, 2010 12:00
You do have a couple of files I would like to look at.
Please go HERE
Put Your Name, and Dell HJT forum and In the file to submit box, click Browse.
Using Windows Explorer
Locate the file
In the comments tell them that I asked you to upload the file
Then Select Send File.
Repeat the process for
C:\rhsaey.txt