1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Laptop issues arriving again: Error, unexpected restart: etc.

Discussion in 'Malware and Virus Removal Archive' started by Unfadeable21, 2010/11/21.

Thread Status:
Not open for further replies.
  1. 2010/11/21
    Unfadeable21

    Unfadeable21 Well-Known Member Thread Starter

    Joined:
    2010/07/05
    Messages:
    53
    Likes Received:
    0
    [Inactive] Laptop issues arriving again: Error, unexpected restart: etc.

    Hello my good friends, back again. During Chem class last friday, my laptop unexpectedly shut off and restarted stating a error log. Then this morning again. My laptop seems to be bugged or messed up again and at the worst time possible since I have a ending semester paper coming up. So I have read the forum rules and here are my logs needed for evaluation. Thanks again and hope to hear from you all good helpers soon.

    David.

    MALWARE BYTES LOG:
    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 5163

    Windows 6.1.7600
    Internet Explorer 8.0.7600.16385

    11/21/2010 3:11:48 PM
    mbam-log-2010-11-21 (15-11-48).txt

    Scan type: Quick scan
    Objects scanned: 147702
    Time elapsed: 5 minute(s), 41 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    GMER LOG:
    GMER 1.0.15.15530 - http://www.gmer.net
    Rootkit scan 2010-11-21 15:47:19
    Windows 6.1.7600
    Running: 9r18beji.exe


    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00243372ae81
    Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002643aa052e
    Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00243372ae81 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002643aa052e (not active ControlSet)

    ---- EOF - GMER 1.0.15 ----
     
  2. 2010/11/21
    Unfadeable21

    Unfadeable21 Well-Known Member Thread Starter

    Joined:
    2010/07/05
    Messages:
    53
    Likes Received:
    0
    MBR LOG:

    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows 7 Home Premium Edition
    Windows Information: (build 7600), 64-bit
    Base Board Manufacturer: Sony Corporation
    BIOS Manufacturer: American Megatrends Inc.
    System Manufacturer: Sony Corporation
    System Product Name: VGN-FW510F
    Logical Drives Mask: 0x00000074

    Kernel Drivers (total 189):
    0x03206000 \SystemRoot\system32\ntoskrnl.exe
    0x037E2000 \SystemRoot\system32\hal.dll
    0x00BC9000 \SystemRoot\system32\kdcom.dll
    0x00C22000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
    0x00C66000 \SystemRoot\system32\PSHED.dll
    0x00C7A000 \SystemRoot\system32\CLFS.SYS
    0x00CD8000 \SystemRoot\system32\CI.dll
    0x00E8D000 \SystemRoot\system32\drivers\Wdf01000.sys
    0x00F31000 \SystemRoot\system32\drivers\WDFLDR.SYS
    0x00F40000 \SystemRoot\system32\DRIVERS\ACPI.sys
    0x00F97000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
    0x00FA0000 \SystemRoot\system32\DRIVERS\msisadrv.sys
    0x00FAA000 \SystemRoot\system32\DRIVERS\pci.sys
    0x00FDD000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
    0x00FEA000 \SystemRoot\System32\drivers\partmgr.sys
    0x00E00000 \SystemRoot\system32\DRIVERS\compbatt.sys
    0x00E09000 \SystemRoot\system32\DRIVERS\BATTC.SYS
    0x00E15000 \SystemRoot\system32\DRIVERS\volmgr.sys
    0x00E2A000 \SystemRoot\System32\drivers\volmgrx.sys
    0x00D98000 \SystemRoot\System32\drivers\mountmgr.sys
    0x0104C000 \SystemRoot\system32\DRIVERS\iaStor.sys
    0x01168000 \SystemRoot\system32\DRIVERS\amdxata.sys
    0x01173000 \SystemRoot\system32\drivers\fltmgr.sys
    0x011BF000 \SystemRoot\system32\drivers\fileinfo.sys
    0x011D3000 \SystemRoot\System32\Drivers\PxHlpa64.sys
    0x0124A000 \SystemRoot\System32\Drivers\Ntfs.sys
    0x01499000 \SystemRoot\System32\Drivers\msrpc.sys
    0x014F7000 \SystemRoot\System32\Drivers\ksecdd.sys
    0x01511000 \SystemRoot\System32\Drivers\cng.sys
    0x01584000 \SystemRoot\System32\drivers\pcw.sys
    0x01595000 \SystemRoot\System32\Drivers\Fs_Rec.sys
    0x0166A000 \SystemRoot\system32\drivers\ndis.sys
    0x0175C000 \SystemRoot\system32\drivers\NETIO.SYS
    0x017BC000 \SystemRoot\System32\Drivers\ksecpkg.sys
    0x01600000 \SystemRoot\system32\DRIVERS\volsnap.sys
    0x0164C000 \SystemRoot\System32\Drivers\spldr.sys
    0x0159F000 \SystemRoot\System32\drivers\rdyboost.sys
    0x01654000 \SystemRoot\System32\Drivers\mup.sys
    0x017E7000 \SystemRoot\system32\DRIVERS\klbg.sys
    0x017F5000 \SystemRoot\System32\drivers\hwpolicy.sys
    0x01400000 \SystemRoot\System32\DRIVERS\fvevol.sys
    0x0143A000 \SystemRoot\system32\DRIVERS\disk.sys
    0x01450000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
    0x02B3D000 \SystemRoot\system32\DRIVERS\cdrom.sys
    0x02B67000 \SystemRoot\system32\DRIVERS\klif.sys
    0x02BC4000 \SystemRoot\System32\Drivers\Null.SYS
    0x02BCD000 \SystemRoot\System32\Drivers\Beep.SYS
    0x02BD4000 \SystemRoot\System32\drivers\vga.sys
    0x015D9000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
    0x02BE2000 \SystemRoot\System32\drivers\watchdog.sys
    0x02BF2000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0x02A00000 \SystemRoot\system32\drivers\rdpencdd.sys
    0x0148E000 \SystemRoot\system32\drivers\rdprefmp.sys
    0x013ED000 \SystemRoot\System32\Drivers\Msfs.SYS
    0x01200000 \SystemRoot\System32\Drivers\Npfs.SYS
    0x03800000 \SystemRoot\System32\drivers\tcpip.sys
    0x01000000 \SystemRoot\System32\drivers\fwpkclnt.sys
    0x01211000 \SystemRoot\system32\DRIVERS\tdx.sys
    0x0122F000 \SystemRoot\system32\DRIVERS\TDI.SYS
    0x00DB2000 \SystemRoot\System32\DRIVERS\netbt.sys
    0x03ABD000 \SystemRoot\system32\DRIVERS\kl1.sys
    0x03A00000 \SystemRoot\system32\drivers\afd.sys
    0x03A8A000 \SystemRoot\system32\DRIVERS\wfplwf.sys
    0x03A93000 \SystemRoot\system32\DRIVERS\pacer.sys
    0x03FE6000 \SystemRoot\system32\DRIVERS\vwififlt.sys
    0x0123C000 \SystemRoot\system32\DRIVERS\klim6.sys
    0x011DF000 \SystemRoot\system32\DRIVERS\netbios.sys
    0x00C00000 \SystemRoot\system32\DRIVERS\wanarp.sys
    0x040EB000 \SystemRoot\system32\DRIVERS\termdd.sys
    0x040FF000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
    0x04109000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
    0x04113000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0x04164000 \SystemRoot\system32\drivers\nsiproxy.sys
    0x04170000 \SystemRoot\system32\DRIVERS\mssmbios.sys
    0x0417B000 \SystemRoot\System32\drivers\discache.sys
    0x0418A000 \SystemRoot\System32\Drivers\dfsc.sys
    0x041A8000 \SystemRoot\system32\DRIVERS\blbdrive.sys
    0x041B9000 \SystemRoot\system32\DRIVERS\tunnel.sys
    0x04696000 \SystemRoot\system32\DRIVERS\atikmdag.sys
    0x04CAD000 \SystemRoot\System32\drivers\dxgkrnl.sys
    0x04DA1000 \SystemRoot\System32\drivers\dxgmms1.sys
    0x04600000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
    0x04624000 \SystemRoot\system32\DRIVERS\usbuhci.sys
    0x04631000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0x04DE7000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0x0545B000 \SystemRoot\system32\DRIVERS\NETw5s64.sys
    0x05B08000 \SystemRoot\system32\DRIVERS\vwifibus.sys
    0x05B15000 \SystemRoot\system32\DRIVERS\yk62x64.sys
    0x05B78000 \SystemRoot\system32\DRIVERS\1394ohci.sys
    0x05BB6000 \SystemRoot\system32\DRIVERS\risdsn64.sys
    0x05BCE000 \SystemRoot\system32\DRIVERS\rimssn64.sys
    0x05400000 \SystemRoot\system32\DRIVERS\i8042prt.sys
    0x0541E000 \SystemRoot\system32\DRIVERS\kbdclass.sys
    0x04000000 \SystemRoot\system32\DRIVERS\Apfiltr.sys
    0x0542D000 \SystemRoot\system32\DRIVERS\klmouflt.sys
    0x05437000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0x05446000 \SystemRoot\system32\DRIVERS\SFEP.sys
    0x04043000 \SystemRoot\system32\DRIVERS\intelppm.sys
    0x05449000 \SystemRoot\system32\DRIVERS\CmBatt.sys
    0x05BEC000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
    0x04059000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
    0x0406F000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0x0544E000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0x04093000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0x040C2000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0x041DF000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0x05C19000 \SystemRoot\system32\DRIVERS\rassstp.sys
    0x05C33000 \SystemRoot\system32\DRIVERS\swenum.sys
    0x05C35000 \SystemRoot\system32\DRIVERS\ks.sys
    0x05C78000 \SystemRoot\system32\DRIVERS\umbus.sys
    0x05C8A000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0x05CE4000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0x05CF9000 \SystemRoot\system32\drivers\RtHDMIVX.sys
    0x05D2B000 \SystemRoot\system32\drivers\portcls.sys
    0x05D68000 \SystemRoot\system32\drivers\drmk.sys
    0x05D8A000 \SystemRoot\system32\drivers\ksthunk.sys
    0x0780D000 \SystemRoot\system32\drivers\RTKVHD64.sys
    0x079C9000 \SystemRoot\system32\DRIVERS\usbccgp.sys
    0x079E6000 \SystemRoot\system32\DRIVERS\USBD.SYS
    0x05D90000 \SystemRoot\System32\Drivers\usbvideo.sys
    0x079E8000 \SystemRoot\system32\DRIVERS\ArcSoftKsUFilter.sys
    0x000F0000 \SystemRoot\System32\win32k.sys
    0x079F2000 \SystemRoot\System32\drivers\Dxapi.sys
    0x05DBE000 \SystemRoot\System32\Drivers\crashdmp.sys
    0x02A09000 \SystemRoot\System32\Drivers\dump_iaStor.sys
    0x05DCC000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
    0x05DDF000 \SystemRoot\system32\DRIVERS\monitor.sys
    0x005E0000 \SystemRoot\System32\TSDDD.dll
    0x007C0000 \SystemRoot\System32\cdd.dll
    0x02432000 \SystemRoot\system32\drivers\luafv.sys
    0x02455000 \SystemRoot\system32\drivers\WudfPf.sys
    0x02476000 \SystemRoot\system32\DRIVERS\lltdio.sys
    0x0248B000 \SystemRoot\system32\DRIVERS\nwifi.sys
    0x024DE000 \SystemRoot\system32\DRIVERS\ndisuio.sys
    0x024F1000 \SystemRoot\system32\DRIVERS\rspndr.sys
    0x02509000 \SystemRoot\system32\DRIVERS\vwifimp.sys
    0x02513000 \SystemRoot\system32\drivers\HTTP.sys
    0x025DB000 \SystemRoot\system32\DRIVERS\bowser.sys
    0x02400000 \SystemRoot\System32\drivers\mpsdrv.sys
    0x06E73000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0x06EA0000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
    0x06EEE000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
    0x06F11000 \SystemRoot\system32\drivers\peauth.sys
    0x06FB7000 \SystemRoot\System32\Drivers\secdrv.SYS
    0x06FC2000 \SystemRoot\System32\DRIVERS\srvnet.sys
    0x06E00000 \SystemRoot\System32\drivers\tcpipreg.sys
    0x0968B000 \SystemRoot\System32\DRIVERS\srv2.sys
    0x096F2000 \SystemRoot\System32\DRIVERS\srv.sys
    0x09788000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
    0x775F0000 \Windows\System32\ntdll.dll
    0x48550000 \Windows\System32\smss.exe
    0xFF910000 \Windows\System32\apisetschema.dll
    0xFF600000 \Windows\System32\autochk.exe
    0xFF890000 \Windows\System32\gdi32.dll
    0xFF630000 \Windows\System32\iertutil.dll
    0xFF620000 \Windows\System32\lpk.dll
    0xFF5D0000 \Windows\System32\ws2_32.dll
    0xFF450000 \Windows\System32\urlmon.dll
    0xFF380000 \Windows\System32\usp10.dll
    0xFF2E0000 \Windows\System32\clbcatq.dll
    0x777C0000 \Windows\System32\psapi.dll
    0xFF2B0000 \Windows\System32\imm32.dll
    0xFF0A0000 \Windows\System32\ole32.dll
    0xFEF90000 \Windows\System32\msctf.dll
    0xFEE60000 \Windows\System32\wininet.dll
    0xFE0D0000 \Windows\System32\shell32.dll
    0xFDEF0000 \Windows\System32\setupapi.dll
    0xFDED0000 \Windows\System32\sechost.dll
    0xFDDF0000 \Windows\System32\advapi32.dll
    0x774F0000 \Windows\System32\user32.dll
    0xFDD50000 \Windows\System32\comdlg32.dll
    0xFDD00000 \Windows\System32\Wldap32.dll
    0xFDC20000 \Windows\System32\oleaut32.dll
    0xFDB80000 \Windows\System32\msvcrt.dll
    0xFDA50000 \Windows\System32\rpcrt4.dll
    0xFDA30000 \Windows\System32\imagehlp.dll
    0xFD9B0000 \Windows\System32\difxapi.dll
    0xFD930000 \Windows\System32\shlwapi.dll
    0x777B0000 \Windows\System32\normaliz.dll
    0xFD920000 \Windows\System32\nsi.dll
    0x773D0000 \Windows\System32\kernel32.dll
    0xFD900000 \Windows\System32\devobj.dll
    0xFD8C0000 \Windows\System32\cfgmgr32.dll
    0xFD820000 \Windows\System32\comctl32.dll
    0xFD7B0000 \Windows\System32\KernelBase.dll
    0xFD640000 \Windows\System32\crypt32.dll
    0xFD600000 \Windows\System32\wintrust.dll
    0xFD5F0000 \Windows\System32\msasn1.dll
    0x76770000 \Windows\SysWOW64\normaliz.dll

    Processes (total 86):
    0 System Idle Process
    4 System
    340 C:\Windows\System32\smss.exe
    520 csrss.exe
    584 C:\Windows\System32\wininit.exe
    604 csrss.exe
    656 C:\Windows\System32\services.exe
    672 C:\Windows\System32\lsass.exe
    680 C:\Windows\System32\lsm.exe
    796 C:\Windows\System32\svchost.exe
    880 C:\Windows\System32\svchost.exe
    928 C:\Windows\System32\atiesrxx.exe
    988 C:\Windows\System32\winlogon.exe
    356 C:\Windows\System32\svchost.exe
    812 C:\Windows\System32\svchost.exe
    1036 C:\Windows\System32\svchost.exe
    1168 C:\Windows\System32\svchost.exe
    1236 C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
    1304 C:\Windows\System32\atieclxx.exe
    1476 C:\Windows\System32\svchost.exe
    1620 C:\Windows\System32\spoolsv.exe
    1680 C:\Windows\System32\svchost.exe
    1780 C:\Program Files\SUPERAntiSpyware\SASCore64.exe
    1808 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
    1864 C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
    1916 C:\Windows\System32\svchost.exe
    1996 C:\PROGRA~2\McAfee\SITEAD~1\mcsacore.exe
    1708 C:\Windows\System32\rundll32.exe
    1092 C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
    1820 C:\Windows\SysWOW64\rundll32.exe
    2072 C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
    2184 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
    2220 C:\Program Files\Sony\VAIO Power Management\SPMService.exe
    2244 dllhost.exe
    2304 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
    2420 C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
    2452 C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
    2576 C:\Windows\System32\taskhost.exe
    2684 C:\Windows\System32\taskeng.exe
    2704 C:\Windows\System32\dwm.exe
    2756 C:\Program Files\Sony\VAIO Care\VAIOCareService.exe
    2808 C:\Windows\explorer.exe
    2956 C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    2140 C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
    1004 C:\Program Files\Apoint\Apoint.exe
    380 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    2608 C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
    2804 C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
    2516 C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
    3008 C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
    1048 C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe
    2508 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
    2316 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    3036 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    2396 C:\Program Files (x86)\Sony\SmartWi Connection Utility\CCP.exe
    1924 C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
    3332 C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWi.exe
    3400 C:\Program Files (x86)\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
    3600 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
    3840 C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
    3848 C:\Program Files (x86)\Sony\SmartWi Connection Utility\PowerManager.exe
    3344 C:\Windows\System32\SearchIndexer.exe
    3704 WmiPrvSE.exe
    4576 C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    4372 C:\Windows\System32\svchost.exe
    5020 WUDFHost.exe
    3996 C:\Program Files\Apoint\ApMsgFwd.exe
    4016 C:\Program Files\Apoint\Apvfb.exe
    304 C:\Program Files\Apoint\ApntEx.exe
    1324 C:\Windows\System32\conhost.exe
    5140 C:\Program Files\Windows Media Player\wmpnetwk.exe
    5180 C:\Program Files\Sony\VAIO Care\VCsystray.exe
    5476 C:\Windows\System32\svchost.exe
    5720 C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    5960 C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    664 C:\Windows\System32\svchost.exe
    1288 C:\Windows\System32\wuauclt.exe
    3764 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    4832 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\x64\klwtblfs.exe
    4680 C:\Windows\System32\svchost.exe
    2764 C:\Windows\System32\taskhost.exe
    5676 C:\Windows\System32\SearchProtocolHost.exe
    1408 C:\Windows\System32\audiodg.exe
    2156 C:\Windows\System32\SearchFilterHost.exe
    3824 C:\Users\owner\Downloads\MBRCheck.exe
    2916 C:\Windows\System32\conhost.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000001`f2e00000 (NTFS)

    PhysicalDrive0 Model Number: ST9500325AS, Rev: 0004SDM2

    Size Device Name MBR Status
    --------------------------------------------
    465 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
    SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79


    Done!

    DDS LOG:


    DDS (Ver_10-11-10.01) - NTFS_AMD64
    Run by owner at 15:50:52.57 on Sun 11/21/2010
    Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_22
    Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.4063.2497 [GMT -6:00]

    SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
    C:\Windows\system32\atieclxx.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
    C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe
    C:\Windows\system32\rundll32.exe
    C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
    C:\Windows\SysWOW64\rundll32.exe
    C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
    C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
    C:\Program Files\Sony\VAIO Power Management\SPMService.exe
    C:\Windows\SysWOW64\DllHost.exe
    C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
    C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
    C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Program Files\Sony\VAIO Care\VAIOCareService.exe
    C:\Windows\Explorer.EXE
    C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
    C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe
    C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
    C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
    C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe
    C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Program Files (x86)\Sony\SmartWi Connection Utility\CCP.exe
    C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
    C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWi.exe
    C:\Program Files (x86)\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
    C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe
    C:\Program Files (x86)\Sony\SmartWi Connection Utility\PowerManager.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\WUDFHost.exe
    C:\Program Files\Apoint\ApMsgFwd.exe
    C:\Program Files\Apoint\Apvfb.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\Windows\system32\conhost.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\Sony\VAIO Care\VCsystray.exe
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\system32\wuauclt.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\x64\klwtblfs.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\NOTEPAD.EXE
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Users\owner\Downloads\dds.scr
    C:\Windows\system32\conhost.exe
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uSearch Bar = Preserve
    uStart Page = hxxp://www.google.com/
    uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SNNT&bmod=SNNT
    mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=SNNT&bmod=SNNT
    mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=SNNT&bmod=SNNT
    uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
    BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
    TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
    mRun: [SmartWiHelper] "C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWiHelper.exe" /WindowsStartup
    mRun: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe "
    mRun: [SHTtray.exe] C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe
    mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe "
    mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe "
    mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe "
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe "
    uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
    IE: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - /105
    IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
    IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
    DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} - hxxp://esupport.sony.com/VaioInfo.CAB
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
    Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll
    Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll
    Notify: VESWinlogon - VESWinlogon.dll
    AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll
    BHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\x64\ievkbd.dll
    BHO-X64: IEVkbdBHO - No File
    BHO-X64: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll
    BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
    BHO-X64: URLRedirectionBHO - No File
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    BHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\x64\klwtbbho.dll
    BHO-X64: link filter bho - No File
    TB-X64: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll
    mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    mRun-x64: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe
    mRun-x64: [Apoint] %ProgramFiles%\Apoint\Apoint.exe
    mRun-x64: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe
    IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    AppInit_DLLs-X64: C:\PROGRA~2\KASPER~1\KASPER~1\x64\sbhook64.dll,C:\PROGRA~2\KASPER~1\KASPER~1\x64\kloehk.dll

    ================= FIREFOX ===================

    FF - ProfilePath - C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\kwt3iufs.default\
    FF - prefs.js: browser.search.selectedEngine - Secure Search
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=
    FF - component: C:\Program Files (x86)\McAfee\SiteAdvisor\components\McFFPlg.dll
    FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
    FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
    FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: C:\Program Files (x86)\Veetle\Player\npvlc.dll
    FF - plugin: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
    FF - plugin: C:\Program Files (x86)\Veetle\VLCBroadcast\npvbp.dll
    FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
    FF - plugin: C:\Users\owner\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll
    FF - plugin: C:\Users\owner\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
    FF - plugin: C:\Users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\kwt3iufs.default\extensions\activegs@freetoolsassociation.com\platform\WINNT_x86-msvc\plugins\npActiveGS.dll
    FF - plugin: C:\Windows\system32\C2MP\npdivx32.dll
    FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgbaam7a8h ", true);
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--fiqz9s ", true); // Traditional
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--fiqs8s ", true); // Simplified
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--j6w193g ", true);
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgberp4a5d4ar ", true);
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgberp4a5d4a87g ", true);
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgbqly7c0a67fbc ", true);
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgbqly7cvafr ", true);
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--kpry57d ", true); // Traditional
    C:\Program Files (x86)\Mozilla Firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--kprw13d ", true); // Simplified

    ============= SERVICES / DRIVERS ===============

    R0 KLBG;Kaspersky Lab Boot Guard Driver;C:\Windows\System32\drivers\klbg.sys [2009-10-14 40464]
    R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2009-9-8 55280]
    R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2009-11-3 27152]
    R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-17 14920]
    R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-17 12360]
    R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
    R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2010-6-29 128752]
    R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2009-9-4 203264]
    R2 AVP;Kaspersky Internet Security;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe [2009-10-20 340520]
    R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [2010-8-26 101048]
    R2 RtkAudioService;Realtek Audio Service;C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2009-9-4 189984]
    R2 SOHCImp;VAIO Media plus Content Importer;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [2009-9-8 120104]
    R2 SOHDBSvr;VAIO Media plus Database Manager;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [2009-9-8 70952]
    R2 SOHDms;VAIO Media plus Digital Media Server;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe [2009-9-8 427304]
    R2 SOHDs;VAIO Media plus Device Searcher;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [2009-9-8 75048]
    R2 SOHPlMgr;VAIO Media plus Playlist Manager;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [2009-9-8 91432]
    R2 uCamMonitor;CamMonitor;C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2009-9-8 104960]
    R2 VAIO Power Management;VAIO Power Management;C:\Program Files\Sony\VAIO Power Management\SPMService.exe [2010-11-8 411496]
    R2 VCFw;VAIO Content Folder Watcher;C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2009-7-22 642920]
    R2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2009-9-8 468264]
    R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;C:\Windows\System32\drivers\ArcSoftKsUFilter.sys [2009-9-8 19968]
    R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2009-10-2 21008]
    R3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETw5s64.sys [2009-12-18 6952960]
    R3 SFEP;Sony Firmware Extension Parser;C:\Windows\System32\drivers\SFEP.sys [2009-9-4 11392]
    R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\System32\drivers\vwifimp.sys [2009-7-13 17920]
    R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-6-10 389120]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 Roxio Upnp Server 10;Roxio Upnp Server 10;C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [2009-6-26 362992]
    S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2009-9-4 35104]
    S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETw5v64.sys [2009-6-7 5435904]
    S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
    S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;C:\Program Files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [2009-6-26 313840]
    S3 SampleCollector;Intel(R) Sample Collector;C:\Program Files\Sony\VAIO Care\collsvc.exe [2010-1-28 167424]
    S3 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [2009-9-8 357672]
    S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [2009-9-8 110888]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-2-26 1255736]

    =============== Created Last 30 ================

    2010-11-19 14:02:07 8199504 ----a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{8592DE7E-3675-4B37-8ECC-0EE8D407335C}\mpengine.dll
    2010-11-06 03:14:45 -------- d-----w- C:\Windows\PCHEALTH
    2010-11-06 03:11:50 -------- d-----w- C:\Program Files (x86)\Microsoft Analysis Services
    2010-11-04 03:52:15 -------- d-----w- C:\Users\owner\AppData\Roaming\SUPERAntiSpyware.com
    2010-11-04 03:52:11 -------- d-----w- C:\Program Files\SUPERAntiSpyware
    2010-10-27 15:18:14 961024 ----a-w- C:\Windows\System32\CPFilters.dll
    2010-10-27 15:18:14 641536 ----a-w- C:\Windows\SysWow64\CPFilters.dll
    2010-10-27 15:18:14 552960 ----a-w- C:\Windows\System32\msdri.dll
    2010-10-27 15:18:13 288256 ----a-w- C:\Windows\System32\MSNP.ax
    2010-10-27 15:18:13 258560 ----a-w- C:\Windows\System32\mpg2splt.ax
    2010-10-27 15:18:13 204288 ----a-w- C:\Windows\SysWow64\MSNP.ax
    2010-10-27 15:18:13 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
    2010-10-27 15:18:09 27008 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
    2010-10-26 02:34:30 206848 ----a-w- C:\Windows\System32\mfps.dll
    2010-10-26 02:34:29 257024 ----a-w- C:\Windows\System32\mfreadwrite.dll
    2010-10-26 02:34:29 196608 ----a-w- C:\Windows\SysWow64\mfreadwrite.dll
    2010-10-26 02:34:28 1888256 ----a-w- C:\Windows\System32\WMVDECOD.DLL
    2010-10-26 02:34:28 1619456 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
    2010-10-26 02:34:27 4068864 ----a-w- C:\Windows\System32\mf.dll
    2010-10-26 02:34:26 3181568 ----a-w- C:\Windows\SysWow64\mf.dll

    ==================== Find3M ====================

    2010-10-19 16:41:44 270720 ------w- C:\Windows\System32\MpSigStub.exe
    2010-09-15 09:50:37 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
    2010-09-10 05:35:44 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
    2010-09-10 05:35:43 347648 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
    2010-09-08 16:17:46 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
    2010-09-08 16:17:46 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
    2010-09-08 05:36:17 1192960 ----a-w- C:\Windows\System32\wininet.dll
    2010-09-08 05:34:34 57856 ----a-w- C:\Windows\System32\licmgr10.dll
    2010-09-08 04:30:04 978432 ----a-w- C:\Windows\SysWow64\wininet.dll
    2010-09-08 04:28:15 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll
    2010-09-08 04:16:38 482816 ----a-w- C:\Windows\System32\html.iec
    2010-09-08 03:35:30 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
    2010-09-08 03:22:31 386048 ----a-w- C:\Windows\SysWow64\html.iec
    2010-09-08 02:48:16 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2010-09-01 05:12:09 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
    2010-09-01 04:23:49 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
    2010-09-01 02:58:34 3123712 ----a-w- C:\Windows\System32\win32k.sys
    2010-08-31 04:32:30 954752 ----a-w- C:\Windows\SysWow64\mfc40.dll
    2010-08-31 04:32:30 954288 ----a-w- C:\Windows\SysWow64\mfc40u.dll
    2010-08-27 06:14:02 236032 ----a-w- C:\Windows\System32\srvsvc.dll
    2010-08-27 05:46:48 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
    2010-08-27 03:38:04 463360 ----a-w- C:\Windows\System32\drivers\srv.sys
    2010-08-27 03:37:48 402944 ----a-w- C:\Windows\System32\drivers\srv2.sys
    2010-08-27 03:37:26 161792 ----a-w- C:\Windows\System32\drivers\srvnet.sys
    2010-08-26 05:27:28 148992 ----a-w- C:\Windows\System32\t2embed.dll
    2010-08-26 04:39:58 109056 ----a-w- C:\Windows\SysWow64\t2embed.dll

    ============= FINISH: 15:52:17.17 ===============

    2ND DDS LOG:

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-11-10.01)

    Microsoft Windows 7 Home Premium
    Boot Device: \Device\HarddiskVolume2
    Install Date: 11/12/2009 5:15:16 PM
    System Uptime: 11/21/2010 1:27:04 PM (2 hours ago)

    Motherboard: Sony Corporation | | VAIO
    Processor: Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz | N/A | 2200/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 458 GiB total, 295.633 GiB free.
    E: is Removable
    F: is Removable
    G: is CDROM ()

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP125: 11/9/2010 8:00:49 AM - Windows Update
    RP126: 11/12/2010 12:33:15 AM - Windows Update
    RP127: 11/12/2010 9:20:16 AM - Windows Update
    RP128: 11/16/2010 10:35:04 AM - Windows Update
    RP129: 11/19/2010 8:01:19 AM - Windows Update

    ==== Installed Programs ======================


    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 9.4.0
    Adobe Shockwave Player 11.5
    Apple Application Support
    Apple Software Update
    Application Manager for VAIO
    ArcSoft Magic-i Visual Effects 2
    ArcSoft WebCam Companion 3
    Catalyst Control Center - Branding
    Catalyst Control Center Core Implementation
    Catalyst Control Center Graphics Full Existing
    Catalyst Control Center Graphics Full New
    Catalyst Control Center Graphics Light
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center Graphics Previews Vista
    Catalyst Control Center InstallProxy
    Catalyst Control Center Localization All
    ccc-core-static
    CCC Help Chinese Standard
    CCC Help Chinese Traditional
    CCC Help Czech
    CCC Help Danish
    CCC Help Dutch
    CCC Help English
    CCC Help Finnish
    CCC Help French
    CCC Help German
    CCC Help Greek
    CCC Help Hungarian
    CCC Help Italian
    CCC Help Japanese
    CCC Help Korean
    CCC Help Norwegian
    CCC Help Polish
    CCC Help Portuguese
    CCC Help Russian
    CCC Help Spanish
    CCC Help Swedish
    CCC Help Thai
    CCC Help Turkish
    CDex - Open Source Digital Audio CD Extractor
    Choice Guard
    Click to Disc
    Click to Disc Editor
    Compatibility Pack for the 2007 Office system
    ConvertHelper 2.2
    Definition update for Microsoft Office 2010 (KB982726)
    Facebook Plug-In
    Java Auto Updater
    Java(TM) 6 Update 22
    Junk Mail filter update
    Kaspersky Internet Security 2010
    Malwarebytes' Anti-Malware
    McAfee SiteAdvisor
    Media Player Codec Pack 3.9.5
    Microsoft Office Access MUI (English) 2010
    Microsoft Office Access Setup Metadata MUI (English) 2010
    Microsoft Office Excel MUI (English) 2010
    Microsoft Office OneNote MUI (English) 2010
    Microsoft Office Outlook MUI (English) 2010
    Microsoft Office PowerPoint MUI (English) 2010
    Microsoft Office Professional 2010
    Microsoft Office Proof (English) 2010
    Microsoft Office Proof (French) 2010
    Microsoft Office Proof (Spanish) 2010
    Microsoft Office Proofing (English) 2010
    Microsoft Office Publisher MUI (English) 2010
    Microsoft Office Shared MUI (English) 2010
    Microsoft Office Shared Setup Metadata MUI (English) 2010
    Microsoft Office Single Image 2010
    Microsoft Office Word MUI (English) 2010
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Works
    Mozilla Firefox (3.6.12)
    MSVCRT
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    Music Transfer
    Primo
    QuickBooks Financial Center
    QuickTime
    Realtek HDMI Audio Driver for ATI
    Realtek High Definition Audio Driver
    Roxio Central Audio
    Roxio Central Copy
    Roxio Central Core
    Roxio Central Data
    Roxio Central Tools
    Roxio Easy Media Creator 10 LJ
    Roxio Easy Media Creator Home
    Runtime
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
    Security Update for Microsoft Office 2010 (KB2289161)
    Security Update for Microsoft Word 2010 (KB2345000)
    Setting Utility Series
    SmartWi Connection Utility
    Sony Home Network Library
    Sony Picture Utility
    SopCast 3.2.9
    System Requirements Lab for Intel
    Update for Microsoft Office 2010 (KB2202188)
    Update for Microsoft OneNote 2010 (KB2288640)
    Update for Microsoft Outlook Social Connector (KB2289116)
    VAIO Care
    VAIO Content Metadata Intelligent Analyzing Manager
    VAIO Content Metadata Intelligent Network Service Manager
    VAIO Content Metadata Manager Settings
    VAIO Content Metadata XML Interface Library
    VAIO Content Monitoring Settings
    VAIO Control Center
    VAIO Data Restore Tool
    VAIO DVD Menu Data Basic
    VAIO Entertainment Platform
    VAIO Event Service
    VAIO Help and Support
    VAIO Media plus
    VAIO Media plus Opening Movie
    VAIO Movie Story
    VAIO Movie Story Template Data
    VAIO OOBE and Startup Assistant
    VAIO Original Function Settings
    VAIO Power Management
    VAIO Presentation Support
    VAIO Survey
    VAIO Update 4
    VAIO Wallpaper Contents
    Veetle TV 0.9.16
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    VLC media player 1.0.5
    Windows 7 Codec Pack 2.3.0
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Mail
    Windows Live Messenger
    Windows Live Movie Maker Beta
    Windows Live Photo Gallery
    Windows Live Sign-in Assistant
    Windows Live Sync
    Windows Live Upload Tool
    Windows Live Writer
    Windows Media Player Firefox Plugin

    ==== Event Viewer Messages From Past Week ========

    11/21/2010 12:18:53 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
    11/21/2010 12:18:52 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments " " in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
    11/21/2010 12:18:52 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments " " in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
    11/21/2010 12:18:51 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments " " in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
    11/21/2010 12:18:51 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments " " in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
    11/21/2010 12:18:50 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments " " in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    11/21/2010 12:18:44 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments " " in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
    11/21/2010 12:18:35 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD DfsC discache kl1 KLIF KLIM6 NetBIOS NetBT nsiproxy Psched rdbss SASDIFSV SASKUTIL spldr Tcpip tdx vwififlt Wanarpv6 WfpLwf
    11/21/2010 12:18:34 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    11/21/2010 12:18:34 PM, Error: Service Control Manager [7001] - The TCP/IP Registry Compatibility service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    11/21/2010 12:18:34 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
    11/21/2010 12:18:34 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
    11/21/2010 12:18:34 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
    11/21/2010 12:18:34 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    11/21/2010 12:18:34 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    11/21/2010 12:18:33 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
    11/21/2010 12:18:33 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
    11/21/2010 12:18:33 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    11/21/2010 12:18:33 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
    11/21/2010 11:51:56 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff88003a8e844, 0x0000000000000001, 0x0000000000000168). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 112110-24086-01.
    11/21/2010 1:27:26 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Roxio Upnp Server 10 service to connect.
    11/21/2010 1:27:20 PM, Error: atikmdag [52236] - CPLIB :: General - Invalid Parameter
    11/21/2010 1:27:20 PM, Error: atikmdag [43029] - Display is not active
    11/19/2010 3:20:21 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the VcmIAlzMgr service.
    11/19/2010 1:04:48 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x000000d1 (0x0000059400000000, 0x0000000000000002, 0x0000000000000008, 0x0000059400000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 111910-28314-01.

    ==== End Of File ===========================
     

  3. to hide this advert.

  4. 2010/11/21
    Unfadeable21

    Unfadeable21 Well-Known Member Thread Starter

    Joined:
    2010/07/05
    Messages:
    53
    Likes Received:
    0
    hopefully this is all the info required that you needed. Thanks and hope to hear from you soon my friends
     
  5. 2010/11/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    So far, I don't see anything malicious, but the Event Viewer has a quite a few errors from last couple of days.

    Download BlueScreenView (in Zip file)
    No installation required.
    Unzip downloaded file and double click on BlueScreenView.exe file to run the program.
    When scanning is done, go Edit>Select All.
    Go File>Save Selected Items, and save the report as BSOD.txt.
    Open BSOD.txt in Notepad, copy all content, and paste it into your next reply.
     
  6. 2010/11/21
    Unfadeable21

    Unfadeable21 Well-Known Member Thread Starter

    Joined:
    2010/07/05
    Messages:
    53
    Likes Received:
    0
    here ya go buddy and thanks for the quick timely reply

    BSOD LOG:

    ==================================================
    Dump File : 112110-24086-01.dmp
    Crash Time : 11/21/2010 11:51:55 AM
    Bug Check String : KMODE_EXCEPTION_NOT_HANDLED
    Bug Check Code : 0x0000001e
    Parameter 1 : ffffffff`c0000005
    Parameter 2 : fffff880`03a8e844
    Parameter 3 : 00000000`00000001
    Parameter 4 : 00000000`00000168
    Caused By Driver : kl1.sys
    Caused By Address : kl1.sys+60844
    File Description :
    Product Name :
    Company :
    File Version :
    Processor : x64
    Computer Name :
    Full Path : C:\Windows\Minidump\112110-24086-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7600
    ==================================================

    ==================================================
    Dump File : 111910-28314-01.dmp
    Crash Time : 11/19/2010 1:04:48 PM
    Bug Check String : DRIVER_IRQL_NOT_LESS_OR_EQUAL
    Bug Check Code : 0x000000d1
    Parameter 1 : 00000594`00000000
    Parameter 2 : 00000000`00000002
    Parameter 3 : 00000000`00000008
    Parameter 4 : 00000594`00000000
    Caused By Driver : tcpip.sys
    Caused By Address : tcpip.sys+3e190
    File Description :
    Product Name :
    Company :
    File Version :
    Processor : x64
    Computer Name :
    Full Path : C:\Windows\Minidump\111910-28314-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7600
    ==================================================

    ==================================================
    Dump File : 050710-19827-01.dmp
    Crash Time : 5/7/2010 5:40:39 PM
    Bug Check String : DRIVER_POWER_STATE_FAILURE
    Bug Check Code : 0x0000009f
    Parameter 1 : 00000000`00000003
    Parameter 2 : fffffa80`04684060
    Parameter 3 : fffff800`00b9c4d8
    Parameter 4 : fffffa80`081117d0
    Caused By Driver : ntoskrnl.exe
    Caused By Address : ntoskrnl.exe+70600
    File Description : NT Kernel & System
    Product Name : Microsoft® Windows® Operating System
    Company : Microsoft Corporation
    File Version : 6.1.7600.16617 (win7_gdr.100618-1621)
    Processor : x64
    Computer Name :
    Full Path : C:\Windows\Minidump\050710-19827-01.dmp
    Processors Count : 2
    Major Version : 15
    Minor Version : 7600
    ==================================================
     
  7. 2010/11/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Possibly Kaspersky is giving you fits.

    Try to reinstall it and give me an update on your computer behavior in a day, or two, or if anything unexpected happens.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.