MSE Problem
Whenever I try to start MSE, the interface opens, then closes immediately.
All the interface elements show up as red which seems to imply they have been disabled.
After trying to open MSE, Action Center tells me that the real time protection is turned off.
Any attempt to turn on the protection tells me the service can't be run, any attempt to enable the service results in it becoming disabled shortly after.[/quote]
The reason I added that bit in quotes is because as I was writing it, I ran MSE to check the error reports and it worked!
It seems ComboFix (at least, among other things) has fixed the MSE issue, MSE is updating now.
I can't thank you enough for the help in this matter, however I'm going to remain on the cautious side of things for a few days.
Your continued advice is always appreciated, below are the various logs.
OTL
All processes killed
========== OTL ==========
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Andey
->Temp folder emptied: 84740161 bytes
->Temporary Internet Files folder emptied: 1039079 bytes
->Java cache emptied: 2027 bytes
->FireFox cache emptied: 60584675 bytes
->Google Chrome cache emptied: 1937620 bytes
->Flash cache emptied: 1012 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Guest
User: Public
User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 57944 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 32902 bytes
RecycleBin emptied: 13229 bytes
Total Files Cleaned = 142.00 mb
OTL by OldTimer - Version 3.2.26.1 log created on 08012011_064909
Files\Folders moved on Reboot...
C:\Users\Andey\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
Registry entries deleted on Reboot...
MGADiag
QUOTE
Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->
Validation Code: 0
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-*****-*****-XMWW8
Windows Product Key Hash: IgQQt/zx/fI2+pWLg8pOBCYneWA=
Windows Product ID: 55041-092-0219592-86080
Windows Product ID Type: 6
Windows License Type: Volume MAK
Windows OS version: 6.1.7601.2.00010100.1.0.048
ID: {3E211007-CA99-4232-87CD-656CFABEECB7}(1)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Professional
Architecture: 0x00000009
Build lab: 7601.win7sp1_gdr.110408-1631
TTS Error:
Validation Diagnostic:
Resolution Status: N/A
Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 100 Genuine
Microsoft Office Home and Student 2007 - 100 Genuine
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_
025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3_E2AD56EA-
765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005_70AFE6BE-656-80070057_E2AD56EA-815-80070057
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data-->
Other data-->
Office Details: {3E211007-CA99-4232-87CD-656CFABEECB7}
1.9.0027.06.1.7601.2.00010100.1.0.048x6
4*****-
*****-*****-*****-BBBBB55041-092-0219592-860806S-1-5-
21-2192342847-1759636489-2174246189System manufacturer<
Model>System Product NameAmerican Megatrends Inc.130520110211000000.000000+000D9663D07018400FE0C09UserLCID>0409AUS Eastern Standard Time(GMT+10:00)03
100100Microsoft Office Home and Student 200712A27F00A03822DB4J5D0NGtp6sMCZqk7Iu
9ogm5pJ5c=81602-OEM-
6873022-486864
Spsys.log Content: 0x80070002
Licensing Data-->
Software licensing service version: 6.1.7601.17514
Name: Windows(R) 7, Professional edition
Description: Windows Operating System - Windows(R) 7, VOLUME_MAK channel
Activation ID: 9abf5984-9c16-46f2-ad1e-7fe15931a8dd
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 55041-00172-092-021959-03-3081-7600.0000-0892011
Installation ID: 021432526001643875756586908970123045213
285012730371796
Processor Certificate URL:
http://go.microsoft.com/fwlink/?LinkID=88338Machine Certificate URL:
http://go.microsoft.com/fwlink/?LinkID=88339Use License URL:
http://go.microsoft.com/fwlink/?LinkID=88341Product Key Certificate URL:
http://go.microsoft.com/fwlink/?LinkID=88340Partial Product Key: XMWW8
License Status: Licensed
Remaining Windows rearm count: 4
Trusted time: 1/08/2011 6:53:21 AM
Windows Activation Technologies-->
HrOffline: 0x00000000
HrOnline: 0x00000000
HealthStatus: 0x0000000000000000
Event Time Stamp: 6:26:2011 12:51
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:
HWID Data-->
HWID Hash Current: PgAAAAIAAgABAAEAAgACAAAABgABAAEAln1C0Qz
7dxZ86RpdGA/2RqyLDqfMRbFsoLWiZs76rCs2qJpbLnM=
OEM Activation 1.0 Data-->
N/A
OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes, but no SLIC table
Windows marker version: N/A
OEMID and OEMTableID Consistent: N/A
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC ALASKA A M I
FACP ALASKA A M I
HPET ALASKA A M I
MCFG ALASKA A M I
SSDT AMICPU PROC
ComboFix
ComboFix 11-07-31.04 - Andey 01/08/2011 6:57.1.8 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.61.1033.18.8172.5971 [GMT 10:00]
Running from: c:\users\Andey\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\ntuser.dat
e:\program files (x86)\Steam\Steam.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-06-28 to 2011-07-31 )))))))))))))))))))))))))))))))
.
.
2011-07-31 20:59 . 2011-07-31 20:59 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2011-07-31 20:59 . 2011-07-31 20:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-31 20:53 . 2011-07-31 20:53 -------- d-----w- C:\MGADiagToolOutput
2011-07-31 20:53 . 2011-07-31 20:53 -------- d-----w- c:\programdata\Office Genuine Advantage
2011-07-31 20:49 . 2011-07-31 20:49 -------- d-----w- C:\_OTL
2011-07-31 01:18 . 2011-07-31 01:18 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2011-07-31 01:18 . 2011-07-31 01:18 -------- d-----w- c:\program files\Microsoft Security Client
2011-07-30 19:16 . 2011-05-20 20:01 2560616 ----a-w- c:\windows\system32\nvsvcr.dll
2011-07-30 18:08 . 2011-07-30 18:08 -------- d-----w- c:\users\Guest
2011-07-30 17:50 . 2011-07-30 17:50 -------- d-----w- c:\program files (x86)\ESET
2011-07-30 15:27 . 2011-03-11 06:41 189824 ----a-w- c:\windows\system32\drivers\storport.sys
2011-07-30 15:27 . 2011-03-11 06:41 166272 ----a-w- c:\windows\system32\drivers\nvstor.sys
2011-07-30 15:27 . 2011-03-11 06:41 1659776 ----a-w- c:\windows\system32\drivers\ntfs.sys
2011-07-30 15:27 . 2011-03-11 06:41 148352 ----a-w- c:\windows\system32\drivers\nvraid.sys
2011-07-30 15:27 . 2011-03-11 06:41 410496 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2011-07-30 15:27 . 2011-03-11 06:41 27008 ----a-w- c:\windows\system32\drivers\amdxata.sys
2011-07-30 15:27 . 2011-03-11 06:41 107904 ----a-w- c:\windows\system32\drivers\amdsata.sys
2011-07-30 15:27 . 2011-03-11 06:33 2565632 ----a-w- c:\windows\system32\esent.dll
2011-07-30 15:27 . 2011-03-11 06:30 96768 ----a-w- c:\windows\system32\fsutil.exe
2011-07-30 15:27 . 2011-03-11 05:33 1699328 ----a-w- c:\windows\SysWow64\esent.dll
2011-07-30 15:27 . 2011-03-11 05:31 74240 ----a-w- c:\windows\SysWow64\fsutil.exe
2011-07-30 15:26 . 2011-04-28 03:55 552960 ----a-w- c:\windows\system32\drivers\bthport.sys
2011-07-30 15:26 . 2011-04-28 03:54 80384 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2011-07-30 15:25 . 2011-03-25 03:29 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys
2011-07-30 15:25 . 2011-03-25 03:29 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2011-07-30 15:25 . 2011-03-25 03:29 98816 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2011-07-30 15:25 . 2011-03-25 03:29 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2011-07-30 15:25 . 2011-03-25 03:29 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2011-07-30 15:25 . 2011-03-25 03:29 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2011-07-30 15:25 . 2011-03-25 03:28 7936 ----a-w- c:\windows\system32\drivers\usbd.sys
2011-07-30 12:22 . 2011-07-30 12:22 -------- d-----w- c:\users\Andey\AppData\Roaming\SUPERAntiSpyware.com
2011-07-30 12:22 . 2011-07-30 12:22 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-07-30 12:21 . 2011-07-30 12:21 -------- d-----w- c:\programdata\!SASCORE
2011-07-30 11:54 . 2011-07-30 11:54 -------- d-----w- C:\Rooter$
2011-07-30 08:48 . 2011-07-30 08:48 -------- d-----w- c:\users\Andey\AppData\Roaming\Malwarebytes
2011-07-30 08:47 . 2011-07-30 08:47 -------- d-----w- c:\programdata\Malwarebytes
2011-07-30 08:47 . 2011-07-06 09:52 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-30 08:47 . 2011-07-30 08:47 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-07-30 08:47 . 2011-07-06 09:52 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-30 07:30 . 2011-07-30 07:30 -------- d-----w- C:\$AVG
2011-07-30 07:09 . 2011-07-30 07:09 -------- d-----w- c:\users\Andey\AppData\Roaming\AVG10
2011-07-30 07:08 . 2011-07-30 07:08 -------- d--h--w- c:\programdata\Common Files
2011-07-30 07:08 . 2011-07-30 10:17 -------- d-----w- c:\programdata\AVG10
2011-07-30 07:08 . 2011-07-30 08:30 -------- d-----w- c:\windows\system32\drivers\AVG
2011-07-30 07:08 . 2011-07-30 07:08 -------- d-----w- c:\program files (x86)\AVG
2011-07-30 06:59 . 2011-07-30 08:31 -------- d-----w- c:\programdata\MFAData
2011-07-30 02:43 . 2011-07-30 02:43 63488 --sha-r- c:\windows\SysWow64\mlangy.dll
2011-07-28 12:24 . 2011-07-28 12:24 -------- d-----w- c:\users\Andey\AppData\Roaming\Processing
2011-07-27 10:51 . 2011-06-03 06:44 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-22 08:02 . 2011-07-22 08:02 -------- d-----w- c:\program files\iPod
2011-07-22 08:02 . 2011-07-22 08:02 -------- d-----w- c:\program files\iTunes
2011-07-22 08:02 . 2011-07-22 08:02 -------- d-----w- c:\program files (x86)\iTunes
2011-07-22 08:01 . 2011-07-22 08:01 -------- d-----w- c:\program files\Bonjour
2011-07-22 08:01 . 2011-07-22 08:01 -------- d-----w- c:\program files (x86)\Bonjour
2011-07-19 10:49 . 2011-07-19 10:49 -------- d-----w- c:\users\Andey\AppData\Local\CrashRpt
2011-07-19 10:49 . 2011-07-19 10:49 -------- d-----w- c:\users\Andey\AppData\Local\Arktos
2011-07-19 08:13 . 2011-07-19 08:13 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-17 07:13 . 2011-07-17 07:13 -------- d-----w- c:\users\Andey\AppData\Local\Microsoft_Corporation
2011-07-17 07:13 . 2011-07-17 07:13 -------- d-----w- c:\program files (x86)\Pixel Mine
2011-07-17 07:08 . 2011-07-17 07:08 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2011-07-17 07:08 . 2011-07-17 07:08 -------- d-----w- c:\program files (x86)\Microsoft SQL Server
2011-07-17 07:08 . 2011-07-17 07:08 -------- d-----w- c:\windows\SysWow64\1033
2011-07-17 07:06 . 2011-07-17 07:06 -------- d-----w- c:\program files (x86)\Microsoft SDKs
2011-07-17 07:06 . 2011-07-17 07:13 -------- d-----w- c:\program files (x86)\Microsoft Visual Studio 9.0
2011-07-17 07:06 . 2011-07-17 07:06 -------- d-----w- c:\program files (x86)\Common Files\Merge Modules
2011-07-17 07:05 . 2011-07-17 07:05 -------- d-----w- c:\program files (x86)\Microsoft Web Designer Tools
2011-07-15 07:08 . 2011-07-15 07:08 -------- d-----w- c:\program files (x86)\Microsoft Works Suite 2005
2011-07-15 05:56 . 2011-07-27 11:13 -------- d-----w- c:\program files (x86)\Microsoft Works
2011-07-15 05:55 . 2011-07-15 05:55 -------- d-----w- c:\users\Andey\AppData\Local\Microsoft Help
2011-07-15 05:55 . 2011-07-30 15:34 -------- d-----w- c:\programdata\Microsoft Help
2011-07-15 05:54 . 2011-07-15 05:54 -------- d-----r- C:\MSOCache
2011-07-12 01:34 . 2011-07-12 01:34 96104 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 01:34 . 2011-07-12 01:34 85864 ----a-w- c:\windows\system32\dnssd.dll
2011-07-12 01:34 . 2011-07-12 01:34 61288 ----a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 01:34 . 2011-07-12 01:34 212840 ----a-w- c:\windows\system32\dnssdX.dll
2011-07-12 01:20 . 2011-07-12 01:20 83816 ----a-w- c:\windows\SysWow64\dns-sd.exe
2011-07-12 01:20 . 2011-07-12 01:20 73064 ----a-w- c:\windows\SysWow64\dnssd.dll
2011-07-12 01:20 . 2011-07-12 01:20 50536 ----a-w- c:\windows\SysWow64\jdns_sd.dll
2011-07-12 01:20 . 2011-07-12 01:20 178536 ----a-w- c:\windows\SysWow64\dnssdX.dll
2011-07-10 07:01 . 2010-05-26 01:41 511328 ----a-w- c:\windows\system32\d3dx10_43.dll
2011-07-10 07:01 . 2010-05-26 01:41 470880 ----a-w- c:\windows\SysWow64\d3dx10_43.dll
2011-07-08 12:57 . 2011-07-08 12:57 -------- d-----w- c:\program files (x86)\Apple Software Update
2011-07-05 16:41 . 2011-07-05 16:41 -------- d-----w- c:\users\Andey\AppData\Local\Aspyr
2011-07-05 04:11 . 2011-07-05 04:11 -------- d-----w- c:\users\Andey\AppData\Local\ArmA 2 OA
2011-07-03 05:23 . 2005-06-14 17:00 102400 ----a-w- c:\windows\SysWow64\tsccvid.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-14 12:24 . 2011-03-29 07:32 280768 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-07-14 12:24 . 2011-03-26 23:40 280768 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-07-14 12:23 . 2011-03-26 23:40 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2011-06-22 08:17 . 2011-06-20 08:13 419840 ----a-w- c:\windows\system32\wrap_oal.dll
2011-06-22 08:17 . 2011-06-20 08:13 413696 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2011-06-22 08:17 . 2011-06-20 08:13 133632 ----a-w- c:\windows\system32\OpenAL32.dll
2011-06-22 08:17 . 2011-06-20 08:13 110592 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2011-06-19 09:09 . 2011-03-30 12:03 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-06-16 03:52 . 2011-06-16 03:52 16384 ----a-w- c:\windows\SysWow64\drivers\EIO64_xp.sys
2011-06-05 06:04 . 2011-03-26 23:40 75136 ----a-w- c:\windows\SysWow64\PnkBstrA.exe
2011-06-04 06:02 . 2011-04-03 02:20 2337865 ----a-w- c:\windows\SysWow64\pbsvc.exe
2011-06-03 05:57 . 2011-07-27 10:51 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-05-28 12:56 . 2011-05-28 12:56 71680 ----a-w- c:\windows\system32\frapsv64.dll
2011-05-28 12:56 . 2011-05-28 12:56 65536 ----a-w- c:\windows\SysWow64\frapsvid.dll
2011-05-20 20:01 . 2011-05-20 20:01 8863336 ----a-w- c:\windows\system32\nvwgf2umx.dll
2011-05-20 20:01 . 2011-05-20 20:01 7123560 ----a-w- c:\windows\system32\nvcuda.dll
2011-05-20 20:01 . 2011-05-20 20:01 67176 ----a-w- c:\windows\system32\OpenCL.dll
2011-05-20 20:01 . 2011-05-20 20:01 6555240 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2011-05-20 20:01 . 2011-05-20 20:01 57960 ----a-w- c:\windows\SysWow64\OpenCL.dll
2011-05-20 20:01 . 2011-05-20 20:01 5301352 ----a-w- c:\windows\SysWow64\nvcuda.dll
2011-05-20 20:01 . 2011-05-20 20:01 2943592 ----a-w- c:\windows\system32\nvcuvid.dll
2011-05-20 20:01 . 2011-05-20 20:01 2804328 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2011-05-20 20:01 . 2011-05-20 20:01 22286952 ----a-w- c:\windows\system32\nvoglv64.dll
2011-05-20 20:01 . 2011-05-20 20:01 2212968 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-05-20 20:01 . 2011-05-20 20:01 2082408 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2011-05-20 20:01 . 2011-05-20 20:01 18583144 ----a-w- c:\windows\system32\nvcompiler.dll
2011-05-20 20:01 . 2011-05-20 20:01 16456296 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2011-05-20 20:01 . 2011-05-20 20:01 15223912 ----a-w- c:\windows\system32\nvd3dumx.dll
2011-05-20 20:01 . 2011-05-20 20:01 1496168 ----a-w- c:\windows\system32\nvdispco6420150.dll
2011-05-20 20:01 . 2011-05-20 20:01 1427048 ----a-w- c:\windows\system32\nvgenco642090.dll
2011-05-20 20:01 . 2011-05-20 20:01 13206120 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2011-05-20 20:01 . 2011-05-20 20:01 13011560 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2011-05-20 20:01 . 2011-05-20 20:01 11992680 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2011-05-20 20:01 . 2011-04-14 09:37 2644584 ----a-w- c:\windows\system32\nvapi64.dll
2011-05-20 20:01 . 2011-04-07 13:19 117864 ----a-w- c:\windows\system32\nvmctray.dll
2011-05-20 20:01 . 2011-04-07 13:19 739432 ----a-w- c:\windows\system32\easyupdatusapiu64.dll
2011-05-20 20:01 . 2011-04-07 13:19 1016936 ----a-w- c:\windows\system32\nvvsvc.exe
2011-05-20 20:01 . 2011-04-07 13:19 6300776 ----a-w- c:\windows\system32\nvcpl.dll
2011-05-20 20:01 . 2011-04-07 13:19 3040872 ----a-w- c:\windows\system32\nvsvc64.dll
2011-05-20 20:01 . 2011-03-25 16:35 61544 ----a-w- c:\windows\system32\nvshext.dll
2011-05-20 20:01 . 2011-02-22 22:28 2335848 ----a-w- c:\windows\SysWow64\nvapi.dll
2011-05-09 22:06 . 2011-05-09 22:06 51712 ----a-w- c:\windows\system32\drivers\usbaapl64.sys
2011-05-09 22:06 . 2011-05-09 22:06 4517664 ----a-w- c:\windows\system32\usbaaplrc.dll
2011-05-03 05:29 . 2011-06-19 02:29 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-05-03 04:30 . 2011-06-19 02:29 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Andey\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Andey\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Andey\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="e:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"ASUS SmartDoctor"="c:\program files (x86)\ASUS\SmartDoctor\SmartDoctor.exe" [2002-01-05 1310720]
"SUPERAntiSpyware"="e:\program files\SuperAntiSpyware\SUPERAntiSpyware.exe" [2011-07-27 2988928]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"ASUS ShellProcess Execute"="c:\program files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\AsShellProcess.exe" [2010-09-28 252544]
"Logitech G35"="c:\program files (x86)\Logitech\G35\G35.exe" [2010-10-04 1811800]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-22 402432]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-05-25 1951112]
"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-11 1523360]
"CanonSolutionMenuEx"="c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-07-19 421736]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-01-19 43632]
.
c:\users\Andey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Andey\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-26 24176560]
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 ASNDIS4;ASNDIS4 Protocol Driver;c:\windows\system32\ASNDIS4.SYS
R3 ATHDFU;Atheros Valkyrie USB BootROM;c:\windows\system32\Drivers\AthDfu.sys
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-03-30 1436424]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys
R3 netr7364;RT73 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr7364.sys
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 mv91xx;mv91xx;c:\windows\system32\DRIVERS\mv91xx.sys
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys
S1 EIO64;EIO Driver;c:\windows\system32\DRIVERS\EIO64.sys
S1 SASDIFSV;SASDIFSV;e:\program files\SuperAntiSpyware\SASDIFSV64.SYS [2011-07-12 14928]
S1 SASKUTIL;SASKUTIL;e:\program files\SuperAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys
S2 !SASCORE;SAS Core Service;e:\program files\SuperAntiSpyware\SASCORE64.EXE [2011-05-04 128384]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2010-11-03 918144]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.13\aaHMSvc.exe [2010-12-02 915584]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2010-10-21 586880]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe [2010-10-27 52896]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-05-25 2275720]
S2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-20 2214504]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-04-07 378472]
S2 TabletServiceWacom;TabletServiceWacom;c:\program files\Tablet\Wacom\Wacom_Tablet.exe [2010-11-15 5716848]
S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys
S3 e1cexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver C;c:\windows\system32\DRIVERS\e1c62x64.sys
S3 ICCWDT;Intel(R) Watchdog Timer Driver (Intel(R) WDT);c:\windows\system32\DRIVERS\ICCWDT.sys
S3 LADF_DHP2;G35 DHP2 Filter Driver;c:\windows\system32\DRIVERS\ladfDHP2amd64.sys
S3 LADF_SBVM;G35 SBVM Filter Driver;c:\windows\system32\DRIVERS\ladfSBVMamd64.sys
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys
S3 netr28x;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\system32\DRIVERS\netr28x.sys
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys
S4 IOMap;IOMap;c:\windows\system32\drivers\IOMap64.sys
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2192342847-1759636489-2174246189-1000Core.job
- c:\users\Andey\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-23 01:57]
.
2011-07-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2192342847-1759636489-2174246189-1000UA.job
- c:\users\Andey\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-23 01:57]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Andey\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Andey\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Andey\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Andey\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2009-08-13 415752]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2009-08-13 4195848]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1680976]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-02 11545192]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
"AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2010-10-27 613536]
"AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2010-10-27 379040]
"PcRemote"="e:\program files (x86)\PCRemote\PCRemote.exe" [2011-04-24 3480576]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2726728]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MIF5BA~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Andey\AppData\Roaming\Mozilla\Firefox\Profiles\chg4ssdr.default\
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-Steam - e:\program files (x86)\Steam\steam.exe
Wow6432Node-HKCU-Run-PC Remote Controller - e:\program files (x86)\SilicMobile\PC Remote Controller\PC Remote Controller.exe
HKLM-Run-GamerOSD - c:\program files (x86)\ASUS\GamerOSD\GamerOSD.exe
AddRemove-BattlEye for OA - e:\program files (x86)\steam\steamapps\common\arma 2 operation arrowheadExpansion\BattlEye\UnInstallBE.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-Steam App 107900 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 12900 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 13210 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 13260 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 13520 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 13640 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 17330 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 17340 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 17460 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 19900 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 20540 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 240 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 24980 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 32430 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 33230 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 33910 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 33930 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 35140 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 4560 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 550 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 57300 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 620 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 65700 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 65720 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 6910 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 6980 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 91600 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 9340 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 97100 - e:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 99900 - e:\program files (x86)\Steam\steam.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2192342847-1759636489-2174246189-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-2192342847-1759636489-2174246189-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_USERS\S-1-5-21-2192342847-1759636489-2174246189-1000\Software\SecuROM\License information*]
"datasecu"=hex:98,d6,93,2f,90,4a,e3,3a,85,7a,40,40,2f,8c,7b,fb,d4,33,35,c2,4d,
42,5b,dd,61,c1,29,fd,40,c8,d9,87,be,26,b1,20,69,7a,2a,18,3f,b5,85,63,9e,4f,\
"rkeysecu"=hex:36,3e,2f,6e,ee,68,fb,6c,0b,07,7a,20,a2,6f,fc,a6
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-08-01 07:01:01
ComboFix-quarantined-files.txt 2011-07-31 21:01
.
Pre-Run: 42,688,180,224 bytes free
Post-Run: 42,297,233,408 bytes free
.
- - End Of File - - 7A72DE538AE430D077AB4C892C552DCB