WiredWX Hobby Weather ToolsLog in

 


Comodo found something in an app I've used before

2 posters

descriptionComodo found something in an app I've used before - Page 2 EmptyRe: Comodo found something in an app I've used before

more_horiz
Update Your Java (JRE)

Old versions of Java have vulnerabilities that malware can use to infect your system.


First Verify your Java Version

If there are any other version(s) installed then update now.

Get the new version (if needed)

If your version is out of date install the newest version of the Sun Java Runtime Environment.

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close ALL open web browsers before starting the installation.

Remove any old versions

1. Download JavaRa and unzip the file to your Desktop.
2. Open JavaRA.exe and choose Remove Older Versions
3. Once complete exit JavaRA.

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
**********************************************
Update your Adobe Reader. get.adobe.com/reader.

Be sure to uncheck the Free McAfee Security Scan so it isn't installed.

**********************************************

  • Download RogueKiller on the desktop
  • Close all the running programs
  • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
  • Otherwise just double-click on RogueKiller.exe
  • Pre-scan will start. Let it finish.
  • Click on SCAN button.
  • A report (RKreport.txt) should open. Post its content in your next reply. (RKreport could also be found on your desktop)
  • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

*****************************************
SysProt Antirootkit

Download
SysProt Antirootkit from the link below (you will find it at the bottom
of the page under attachments, or you can get it from one of the
mirrors).

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.

  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select the following items.

    • Process << Selected
    • Kernel Modules << Selected
    • SSDT << Selected
    • Kernel Hooks << Selected
    • IRP Hooks << NOT Selected
    • Ports << NOT Selected
    • Hidden Files << Selected

  • At the bottom of the page

    • Hidden Objects Only << Selected

  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to. Open the text file and copy/paste the log here.

descriptionComodo found something in an app I've used before - Page 2 EmptyRe: Comodo found something in an app I've used before

more_horiz
RogueKiller V8.3.0 [Nov 18 2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website: http://tigzy.geekstogo.com/roguekiller.php
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : Arashmickey [Admin rights]
Mode : Scan -- Date : 11/19/2012 10:05:05

¤¤¤ Bad processes : 2 ¤¤¤
[SUSP PATH] Sound_Blaster_X-Fi_MB_Cleanup.0001 -- C:\Users\Arashmickey\AppData\Local\temp\Sound_Blaster_X-Fi_MB_Cleanup.0001 -> KILLED [TermProc]
[RESIDUE][DLL] rundll32.exe -- C:\Windows\System32\rundll32.exe : C:\Windows\system32\AmbRunE.dll -> KILLED [TermProc]

¤¤¤ Registry Entries : 16 ¤¤¤
[RUN][SUSP PATH] HKLM\[...]\Run : UpdReg (C:\Windows\Updreg.EXE) -> FOUND
[RUN][BLACKLISTDLL] HKLM\[...]\Run : RunDLLEntry (C:\Windows\system32\RunDLL32.exe C:\Windows\system32\AmbRunE.dll,RunDLLEntry) -> FOUND
[DNS] HKLM\[...]\ControlSet001\Services\Interfaces\{9DAF0BE6-4D6B-4313-811F-B86A713BDD4F} : NameServer (8.26.56.26,156.154.70.22) -> FOUND
[DNS] HKLM\[...]\ControlSet002\Services\Interfaces\{9DAF0BE6-4D6B-4313-811F-B86A713BDD4F} : NameServer (8.26.56.26,156.154.70.22) -> FOUND
[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
[HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyPics (0) -> FOUND
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyMusic (0) -> FOUND
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowHelp (0) -> FOUND
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> FOUND
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowSetProgramAccessAndDefaults (0) -> FOUND
[HJ SMENU] HKCU\[...]\Advanced : Start_TrackProgs (0) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤
SSDT[84] : NtCreateSection @ 0x8347206D -> HOOKED (Unknown @ 0x92370C66)
SSDT[299] : NtRequestWaitReplyPort @ 0x8348CA63 -> HOOKED (Unknown @ 0x92370C70)
SSDT[316] : NtSetContextThread @ 0x8352C745 -> HOOKED (Unknown @ 0x92370C6B)
SSDT[347] : NtSetSecurityObject @ 0x83450742 -> HOOKED (Unknown @ 0x92370C75)
SSDT[368] : NtSystemDebugControl @ 0x834D46BC -> HOOKED (Unknown @ 0x92370C7A)
SSDT[370] : NtTerminateProcess @ 0x834A9BFB -> HOOKED (Unknown @ 0x92370C07)

¤¤¤ HOSTS File: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: SAMSUNG HD103SJ ATA Device +++++
--- User ---
[MBR] dfaa4539d580ef34d1e18848275151b5
[BSP] 902a334320e02ed335b1ea24edbce380 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 199899 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600000 | Size: 753868 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[1]_S_11192012_02d1005.txt >>
RKreport[1]_S_11192012_02d1005.txt


descriptionComodo found something in an app I've used before - Page 2 EmptyRe: Comodo found something in an app I've used before

more_horiz
SysProt AntiRootkit v1.0.1.0
by swatkat

******************************************************************************************
******************************************************************************************

No Processes found

******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \??\C:\Users\Arashmickey\Desktop\SysProt\SysProtDrv.sys
Service Name: SysProtDrv.sys
Module Base: A60CF000
Module End: A60DA000
Hidden: No

Module Name: C:\Windows\system32\ntkrnlpa.exe
Service Name: ---
Module Base: 8324D000
Module End: 83660000
Hidden: No

Module Name: C:\Windows\system32\halmacpi.dll
Service Name: ---
Module Base: 83216000
Module End: 8324D000
Hidden: No

Module Name: C:\Windows\system32\kdcom.dll
Service Name: ---
Module Base: 80BB0000
Module End: 80BB8000
Hidden: No

Module Name: C:\Windows\system32\mcupdate_AuthenticAMD.dll
Service Name: ---
Module Base: 8C61F000
Module End: 8C62A000
Hidden: No

Module Name: C:\Windows\system32\PSHED.dll
Service Name: ---
Module Base: 8C62A000
Module End: 8C63B000
Hidden: No

Module Name: C:\Windows\system32\BOOTVID.dll
Service Name: ---
Module Base: 8C63B000
Module End: 8C643000
Hidden: No

Module Name: C:\Windows\system32\CLFS.SYS
Service Name: CLFS
Module Base: 8C643000
Module End: 8C685000
Hidden: No

Module Name: C:\Windows\system32\CI.dll
Service Name: ---
Module Base: 8C685000
Module End: 8C730000
Hidden: No

Module Name: C:\Windows\system32\drivers\Wdf01000.sys
Service Name: Wdf01000
Module Base: 8C730000
Module End: 8C7B1000
Hidden: No

Module Name: C:\Windows\system32\drivers\WDFLDR.SYS
Service Name: ---
Module Base: 8C7B1000
Module End: 8C7BF000
Hidden: No

Module Name: C:\Windows\system32\drivers\ACPI.sys
Service Name: ACPI
Module Base: 8C826000
Module End: 8C86E000
Hidden: No

Module Name: C:\Windows\system32\drivers\WMILIB.SYS
Service Name: ---
Module Base: 8C86E000
Module End: 8C877000
Hidden: No

Module Name: C:\Windows\system32\drivers\msisadrv.sys
Service Name: msisadrv
Module Base: 8C877000
Module End: 8C87F000
Hidden: No

Module Name: C:\Windows\system32\drivers\pci.sys
Service Name: pci
Module Base: 8C87F000
Module End: 8C8A9000
Hidden: No

Module Name: C:\Windows\system32\drivers\vdrvroot.sys
Service Name: vdrvroot
Module Base: 8C8A9000
Module End: 8C8B4000
Hidden: No

Module Name: C:\Windows\System32\drivers\partmgr.sys
Service Name: partmgr
Module Base: 8C8B4000
Module End: 8C8C5000
Hidden: No

Module Name: C:\Windows\system32\drivers\volmgr.sys
Service Name: volmgr
Module Base: 8C8C5000
Module End: 8C8D5000
Hidden: No

Module Name: C:\Windows\System32\drivers\volmgrx.sys
Service Name: volmgrx
Module Base: 8C8D5000
Module End: 8C920000
Hidden: No

Module Name: C:\Windows\system32\drivers\pciide.sys
Service Name: pciide
Module Base: 8C920000
Module End: 8C927000
Hidden: No

Module Name: C:\Windows\system32\drivers\PCIIDEX.SYS
Service Name: ---
Module Base: 8C927000
Module End: 8C935000
Hidden: No

Module Name: C:\Windows\System32\drivers\mountmgr.sys
Service Name: mountmgr
Module Base: 8C935000
Module End: 8C94B000
Hidden: No

Module Name: C:\Windows\system32\drivers\atapi.sys
Service Name: atapi
Module Base: 8C94B000
Module End: 8C954000
Hidden: No

Module Name: C:\Windows\system32\drivers\ataport.SYS
Service Name: ---
Module Base: 8C954000
Module End: 8C977000
Hidden: No

Module Name: C:\Windows\system32\drivers\amdxata.sys
Service Name: amdxata
Module Base: 8C977000
Module End: 8C980000
Hidden: No

Module Name: C:\Windows\system32\drivers\fltmgr.sys
Service Name: FltMgr
Module Base: 8C980000
Module End: 8C9B4000
Hidden: No

Module Name: C:\Windows\system32\drivers\fileinfo.sys
Service Name: FileInfo
Module Base: 8C9B4000
Module End: 8C9C5000
Hidden: No

Module Name: C:\Windows\System32\Drivers\Ntfs.sys
Service Name: ---
Module Base: 8CA10000
Module End: 8CB3F000
Hidden: No

Module Name: C:\Windows\System32\Drivers\msrpc.sys
Service Name: ---
Module Base: 8CB3F000
Module End: 8CB6A000
Hidden: No

Module Name: C:\Windows\System32\Drivers\ksecdd.sys
Service Name: KSecDD
Module Base: 8CB6A000
Module End: 8CB7D000
Hidden: No

Module Name: C:\Windows\System32\Drivers\cng.sys
Service Name: CNG
Module Base: 8CB7D000
Module End: 8CBDA000
Hidden: No

Module Name: C:\Windows\System32\drivers\pcw.sys
Service Name: pcw
Module Base: 8CBDA000
Module End: 8CBE8000
Hidden: No

Module Name: C:\Windows\System32\Drivers\Fs_Rec.sys
Service Name: ---
Module Base: 8CBE8000
Module End: 8CBF1000
Hidden: No

Module Name: C:\Windows\system32\drivers\ndis.sys
Service Name: NDIS
Module Base: 8CC36000
Module End: 8CCED000
Hidden: No

Module Name: C:\Windows\system32\drivers\NETIO.SYS
Service Name: ---
Module Base: 8CCED000
Module End: 8CD2B000
Hidden: No

Module Name: C:\Windows\System32\Drivers\ksecpkg.sys
Service Name: KSecPkg
Module Base: 8CD2B000
Module End: 8CD50000
Hidden: No

Module Name: C:\Windows\System32\drivers\tcpip.sys
Service Name: Tcpip
Module Base: 8CE33000
Module End: 8CF7F000
Hidden: No

Module Name: C:\Windows\System32\drivers\fwpkclnt.sys
Service Name: ---
Module Base: 8CF7F000
Module End: 8CFB0000
Hidden: No

Module Name: C:\Windows\system32\drivers\vmstorfl.sys
Service Name: storflt
Module Base: 8CFB0000
Module End: 8CFB9000
Hidden: No

Module Name: C:\Windows\system32\drivers\volsnap.sys
Service Name: volsnap
Module Base: 8CFB9000
Module End: 8CFF8000
Hidden: No

Module Name: C:\Windows\System32\Drivers\spldr.sys
Service Name: ---
Module Base: 8CFF8000
Module End: 8D000000
Hidden: No

Module Name: C:\Windows\System32\drivers\rdyboost.sys
Service Name: rdyboost
Module Base: 8CE00000
Module End: 8CE2D000
Hidden: No

Module Name: C:\Windows\System32\Drivers\mup.sys
Service Name: Mup
Module Base: 8CD50000
Module End: 8CD60000
Hidden: No

Module Name: C:\Windows\System32\drivers\hwpolicy.sys
Service Name: hwpolicy
Module Base: 8CD60000
Module End: 8CD68000
Hidden: No

Module Name: C:\Windows\System32\DRIVERS\fvevol.sys
Service Name: fvevol
Module Base: 8CD68000
Module End: 8CD9A000
Hidden: No

Module Name: C:\Windows\system32\drivers\disk.sys
Service Name: Disk
Module Base: 8CD9A000
Module End: 8CDAB000
Hidden: No

Module Name: C:\Windows\system32\drivers\CLASSPNP.SYS
Service Name: ---
Module Base: 8CDAB000
Module End: 8CDD0000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\AtiPcie.sys
Service Name: AtiPcie
Module Base: 8CDD0000
Module End: 8CDD8000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\cdrom.sys
Service Name: cdrom
Module Base: 8CC11000
Module End: 8CC30000
Hidden: No

Module Name: C:\Windows\System32\DRIVERS\cmdguard.sys
Service Name: cmdGuard
Module Base: 91231000
Module End: 912AC000
Hidden: No

Module Name: C:\Windows\System32\Drivers\Null.SYS
Service Name: ---
Module Base: 912AC000
Module End: 912B3000
Hidden: No

Module Name: C:\Windows\System32\Drivers\Beep.SYS
Service Name: ---
Module Base: 912B3000
Module End: 912BA000
Hidden: No

Module Name: C:\Windows\System32\drivers\vga.sys
Service Name: vga
Module Base: 912BA000
Module End: 912C6000
Hidden: No

Module Name: C:\Windows\System32\drivers\VIDEOPRT.SYS
Service Name: ---
Module Base: 912C6000
Module End: 912E7000
Hidden: No

Module Name: C:\Windows\System32\drivers\watchdog.sys
Service Name: ---
Module Base: 912E7000
Module End: 912F4000
Hidden: No

Module Name: C:\Windows\System32\DRIVERS\RDPCDD.sys
Service Name: RDPCDD
Module Base: 912F4000
Module End: 912FC000
Hidden: No

Module Name: C:\Windows\system32\drivers\rdpencdd.sys
Service Name: RDPENCDD
Module Base: 912FC000
Module End: 91304000
Hidden: No

Module Name: C:\Windows\system32\drivers\rdprefmp.sys
Service Name: RDPREFMP
Module Base: 91304000
Module End: 9130C000
Hidden: No

Module Name: C:\Windows\System32\Drivers\Msfs.SYS
Service Name: ---
Module Base: 9130C000
Module End: 91317000
Hidden: No

Module Name: C:\Windows\System32\Drivers\Npfs.SYS
Service Name: ---
Module Base: 91317000
Module End: 91325000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\tdx.sys
Service Name: tdx
Module Base: 91325000
Module End: 9133C000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\TDI.SYS
Service Name: ---
Module Base: 9133C000
Module End: 91348000
Hidden: No

Module Name: C:\Windows\System32\DRIVERS\cmdhlp.sys
Service Name: cmdHlp
Module Base: 91348000
Module End: 91352000
Hidden: No

Module Name: C:\Windows\system32\drivers\afd.sys
Service Name: AFD
Module Base: 91352000
Module End: 913AC000
Hidden: No

Module Name: C:\Windows\System32\DRIVERS\netbt.sys
Service Name: NetBT
Module Base: 913AC000
Module End: 913DE000
Hidden: No

Module Name: C:\Windows\system32\drivers\ws2ifsl.sys
Service Name: ws2ifsl
Module Base: 913DE000
Module End: 913E7000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\wfplwf.sys
Service Name: WfpLwf
Module Base: 913E7000
Module End: 913EE000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\pacer.sys
Service Name: Psched
Module Base: 91200000
Module End: 9121F000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\inspect.sys
Service Name: inspect
Module Base: 8C9C5000
Module End: 8C9DB000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\netbios.sys
Service Name: NetBIOS
Module Base: 9121F000
Module End: 9122D000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\serial.sys
Service Name: Serial
Module Base: 8C9DB000
Module End: 8C9F5000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\wanarp.sys
Service Name: WANARP
Module Base: 8C800000
Module End: 8C813000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\termdd.sys
Service Name: TermDD
Module Base: 913EE000
Module End: 913FF000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\ssmdrv.sys
Service Name: ssmdrv
Module Base: 8CE2D000
Module End: 8CE33000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\rdbss.sys
Service Name: rdbss
Module Base: 8C7BF000
Module End: 8C800000
Hidden: No

Module Name: C:\Windows\system32\drivers\nsiproxy.sys
Service Name: nsiproxy
Module Base: 8CBF1000
Module End: 8CBFB000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\mssmbios.sys
Service Name: mssmbios
Module Base: 8CA00000
Module End: 8CA0A000
Hidden: No

Module Name: C:\Windows\System32\drivers\discache.sys
Service Name: discache
Module Base: 8C813000
Module End: 8C81F000
Hidden: No

Module Name: C:\Windows\system32\drivers\csc.sys
Service Name: CSC
Module Base: 92027000
Module End: 9208B000
Hidden: No

Module Name: C:\Windows\System32\Drivers\dfsc.sys
Service Name: DfsC
Module Base: 9208B000
Module End: 920A3000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\blbdrive.sys
Service Name: blbdrive
Module Base: 920A3000
Module End: 920B1000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\avkmgr.sys
Service Name: avkmgr
Module Base: 920B1000
Module End: 920BD000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\avipbb.sys
Service Name: avipbb
Module Base: 920BD000
Module End: 920E0000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\AsrAppCharger.sys
Service Name: AsrAppCharger
Module Base: 920E0000
Module End: 920E7000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\tunnel.sys
Service Name: tunnel
Module Base: 920E7000
Module End: 92108000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\nvlddmkm.sys
Service Name: nvlddmkm
Module Base: 92E30000
Module End: 938A4000
Hidden: No

Module Name: C:\Windows\System32\Drivers\nvBridge.kmd
Service Name: ---
Module Base: 938A4000
Module End: 938A6000
Hidden: No

Module Name: C:\Windows\System32\drivers\dxgkrnl.sys
Service Name: DXGKrnl
Module Base: 938A6000
Module End: 9395D000
Hidden: No

Module Name: C:\Windows\System32\drivers\dxgmms1.sys
Service Name: ---
Module Base: 9395D000
Module End: 93996000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\HDAudBus.sys
Service Name: HDAudBus
Module Base: 93996000
Module End: 939B5000
Hidden: No

Module Name: C:\Windows\System32\Drivers\EtronXHCI.sys
Service Name: EtronXHCI
Module Base: 939B5000
Module End: 939C2000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\usbfilter.sys
Service Name: usbfilter
Module Base: 939C2000
Module End: 939C8000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\L1C62x86.sys
Service Name: L1C
Module Base: 939C8000
Module End: 939DA000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\usbohci.sys
Service Name: usbohci
Module Base: 939DA000
Module End: 939E4000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\USBPORT.SYS
Service Name: ---
Module Base: 92108000
Module End: 92153000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\usbehci.sys
Service Name: usbehci
Module Base: 939E4000
Module End: 939F3000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\serenum.sys
Service Name: Serenum
Module Base: 939F3000
Module End: 939FD000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\1394ohci.sys
Service Name: 1394ohci
Module Base: 92E00000
Module End: 92E2D000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\amdppm.sys
Service Name: AmdPPM
Module Base: 92153000
Module End: 92164000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\wmiacpi.sys
Service Name: WmiAcpi
Module Base: 92164000
Module End: 9216D000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\CompositeBus.sys
Service Name: CompositeBus
Module Base: 9216D000
Module End: 9217A000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\AgileVpn.sys
Service Name: RasAgileVpn
Module Base: 9217A000
Module End: 9218C000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\rasl2tp.sys
Service Name: Rasl2tp
Module Base: 9218C000
Module End: 921A4000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\ndistapi.sys
Service Name: NdisTapi
Module Base: 921A4000
Module End: 921AF000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\ndiswan.sys
Service Name: NdisWan
Module Base: 921AF000
Module End: 921D1000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\raspppoe.sys
Service Name: RasPppoe
Module Base: 921D1000
Module End: 921E9000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\raspptp.sys
Service Name: PptpMiniport
Module Base: 921E9000
Module End: 92200000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\rassstp.sys
Service Name: RasSstp
Module Base: 92000000
Module End: 92017000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\rdpbus.sys
Service Name: rdpbus
Module Base: 92017000
Module End: 92021000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\kbdclass.sys
Service Name: kbdclass
Module Base: 8C600000
Module End: 8C60D000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\mouclass.sys
Service Name: mouclass
Module Base: 8C60D000
Module End: 8C61A000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\swenum.sys
Service Name: swenum
Module Base: 92E2D000
Module End: 92E2F000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\ks.sys
Service Name: ---
Module Base: 95229000
Module End: 9525D000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\umbus.sys
Service Name: umbus
Module Base: 9525D000
Module End: 9526B000
Hidden: No

Module Name: C:\Windows\System32\Drivers\EtronHub3.sys
Service Name: EtronHub3
Module Base: 9526B000
Module End: 95273000
Hidden: No

Module Name: C:\Windows\System32\Drivers\USBD.SYS
Service Name: ---
Module Base: 95273000
Module End: 95275000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\usbhub.sys
Service Name: usbhub
Module Base: 95275000
Module End: 952B9000
Hidden: No

Module Name: C:\Windows\System32\Drivers\NDProxy.SYS
Service Name: ---
Module Base: 952B9000
Module End: 952CA000
Hidden: No

Module Name: C:\Windows\system32\drivers\nvhda32v.sys
Service Name: NVHDA
Module Base: 952CA000
Module End: 952F2000
Hidden: No

Module Name: C:\Windows\system32\drivers\portcls.sys
Service Name: ---
Module Base: 952F2000
Module End: 95321000
Hidden: No

Module Name: C:\Windows\system32\drivers\drmk.sys
Service Name: ---
Module Base: 95321000
Module End: 9533A000
Hidden: No

Module Name: C:\Windows\system32\drivers\RTKVHDA.sys
Service Name: IntcAzAudAddService
Module Base: 98415000
Module End: 986F5000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\hidusb.sys
Service Name: HidUsb
Module Base: 986F5000
Module End: 98700000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\HIDCLASS.SYS
Service Name: ---
Module Base: 98700000
Module End: 98713000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\HIDPARSE.SYS
Service Name: ---
Module Base: 98713000
Module End: 9871A000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\mouhid.sys
Service Name: mouhid
Module Base: 9871A000
Module End: 98725000
Hidden: No

Module Name: C:\Windows\System32\drivers\Dxapi.sys
Service Name: ---
Module Base: 98725000
Module End: 9872F000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\cdfs.sys
Service Name: cdfs
Module Base: 9872F000
Module End: 98745000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\usbccgp.sys
Service Name: usbccgp
Module Base: 98745000
Module End: 9875C000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\kbdhid.sys
Service Name: kbdhid
Module Base: 9875C000
Module End: 98768000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\monitor.sys
Service Name: monitor
Module Base: 98768000
Module End: 98773000
Hidden: No

Module Name: C:\Windows\system32\drivers\usbaudio.sys
Service Name: usbaudio
Module Base: 98773000
Module End: 98787000
Hidden: No

Module Name: C:\Windows\System32\Drivers\crashdmp.sys
Service Name: ---
Module Base: 98787000
Module End: 98794000
Hidden: No

Module Name: \SystemRoot\System32\Drivers\dump_dumpata.sys
Service Name: ---
Module Base: 98794000
Module End: 9879F000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: 9879F000
Module End: 987A8000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\dump_dumpfve.sys
Service Name: ---
Module Base: 987A8000
Module End: 987B9000
Hidden: Yes

Module Name: C:\Windows\system32\drivers\luafv.sys
Service Name: luafv
Module Base: 987B9000
Module End: 987D4000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\avgntflt.sys
Service Name: avgntflt
Module Base: 987D4000
Module End: 987EF000
Hidden: No

Module Name: \??\C:\Windows\system32\drivers\mbam.sys
Service Name: MBAMProtector
Module Base: 987EF000
Module End: 987F3000
Hidden: No

Module Name: C:\Windows\system32\drivers\WudfPf.sys
Service Name: WudfPf
Module Base: 98400000
Module End: 98414000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\lltdio.sys
Service Name: lltdio
Module Base: 9533A000
Module End: 9534A000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\rspndr.sys
Service Name: rspndr
Module Base: 9534A000
Module End: 9535D000
Hidden: No

Module Name: C:\Windows\system32\drivers\HTTP.sys
Service Name: HTTP
Module Base: 9535D000
Module End: 953E2000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\bowser.sys
Service Name: bowser
Module Base: 953E2000
Module End: 953FB000
Hidden: No

Module Name: C:\Windows\System32\drivers\mpsdrv.sys
Service Name: mpsdrv
Module Base: 95200000
Module End: 95212000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\mrxsmb.sys
Service Name: mrxsmb
Module Base: 8CDD8000
Module End: 8CDFB000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\mrxsmb10.sys
Service Name: mrxsmb10
Module Base: A5235000
Module End: A5270000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\mrxsmb20.sys
Service Name: mrxsmb20
Module Base: A5270000
Module End: A528B000
Hidden: No

Module Name: C:\Windows\system32\drivers\peauth.sys
Service Name: PEAUTH
Module Base: A52A3000
Module End: A533A000
Hidden: No

Module Name: C:\Windows\System32\Drivers\secdrv.SYS
Service Name: ---
Module Base: A533A000
Module End: A5344000
Hidden: No

Module Name: C:\Windows\System32\DRIVERS\srvnet.sys
Service Name: srvnet
Module Base: A5344000
Module End: A5365000
Hidden: No

Module Name: C:\Windows\System32\drivers\tcpipreg.sys
Service Name: tcpipreg
Module Base: A5365000
Module End: A5372000
Hidden: No

Module Name: C:\Windows\System32\DRIVERS\srv2.sys
Service Name: srv2
Module Base: A5372000
Module End: A53C2000
Hidden: No

Module Name: C:\Windows\System32\DRIVERS\srv.sys
Service Name: srv
Module Base: A6001000
Module End: A6053000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\LVPr2Mon.sys
Service Name: LVPr2Mon
Module Base: A6053000
Module End: A6058000
Hidden: No

Module Name: C:\Windows\system32\DRIVERS\asyncmac.sys
Service Name: AsyncMac
Module Base: A60C2000
Module End: A60CB000
Hidden: No

Module Name: \??\C:\Windows\system32\drivers\TrueSight.sys
Service Name: ---
Module Base: A60CB000
Module End: A60CF000
Hidden: Yes

******************************************************************************************
******************************************************************************************
No SSDT Hooks found

******************************************************************************************
******************************************************************************************
No Kernel Hooks found

******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: C:\Qoobox\BackEnv\AppData.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Cache.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Cookies.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Desktop.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Favorites.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\History.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Music.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\NetHood.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Personal.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Pictures.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\PrintHood.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Profiles.Folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Programs.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Recent.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SendTo.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SetPath.bat
Status: Access denied

Object: C:\Qoobox\BackEnv\StartMenu.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\StartUp.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SysPath.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Templates.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\VikPev00
Status: Access denied

Object: C:\Windows\CSC\v2.0.6\namespace
Status: Access denied

Object: C:\Windows\CSC\v2.0.6\pq
Status: Access denied

Object: C:\Windows\CSC\v2.0.6\sm
Status: Access denied

Object: C:\Windows\CSC\v2.0.6\temp
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
Status: Access denied

Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl
Status: Access denied

descriptionComodo found something in an app I've used before - Page 2 EmptyRe: Comodo found something in an app I've used before

more_horiz
Also:
roguekiller asked if I should wanted to close roguekiller without deleting anything, to which I said OK.
Sysprot said there was an error when attempting to scan SSDT, to which I said OK again, and it continued the scan.

Just FYI Smile...

descriptionComodo found something in an app I've used before - Page 2 EmptyRe: Comodo found something in an app I've used before

more_horiz
Is the computer working any better?

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the Comodo found something in an app I've used before - Page 2 EsetOnline button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on Comodo found something in an app I've used before - Page 2 EsetSmartInstall to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the Comodo found something in an app I've used before - Page 2 EsetSmartInstallDesktopIcon-1 icon on your desktop.

•Check Comodo found something in an app I've used before - Page 2 EsetAcceptTerms
•Click the Comodo found something in an app I've used before - Page 2 EsetStart button.
•Accept any security warnings from your browser.
•Check Comodo found something in an app I've used before - Page 2 EsetScanArchives
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push Comodo found something in an app I've used before - Page 2 EsetListThreats
•Push Comodo found something in an app I've used before - Page 2 EsetExport, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the Comodo found something in an app I've used before - Page 2 EsetBack button.
•Push Comodo found something in an app I've used before - Page 2 EsetFinish
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

descriptionComodo found something in an app I've used before - Page 2 EmptyRe: Comodo found something in an app I've used before

more_horiz
Thanks Dave! Maybe it's just me, but things do seem to run a bit more smoothly now. Before, my pc would freeze a couple times a day for 10 or 20 seconds, first the input, then sound & video. I tried updating drivers and scrubbing unnecessary programs & processes, but I had never figured out what actually caused it. In the past couple of days it has only happened once, so I'd call that an improvement at least. It's been there for almost as long as I remember though.

ESET took about 4 hours and came back with no infections at all Smile... I couldn't find the buttons to create the log file though.

Anything I ought to do next? I'll be happy to.

I'll get mbam through your affiliate link in a couple of weeks when I have some more money. That means I will have mbam, comodo, avira? Is that enough / too little / too much? Or should I use different firewall / antivirus?

Also, I already got the ebook in June last year, but I still wanted to send a 5 or 10 bucks - is there a way to do that, maybe a direct paypal donation? Otherwise, I suppose I could just buy the ebook again in a few months. I don't have much money but I do want to show my appreciation and help keep GeekPolice alive. You guys are tops!

descriptionComodo found something in an app I've used before - Page 2 EmptyRe: Comodo found something in an app I've used before

more_horiz
That means I will have mbam, comodo, avira? Is that enough / too little / too much? Or should I use different firewall / antivirus?

That sounds like a good combination. If Comodo starts acting up, just dump it and get another firewall.
but I still wanted to send a 5 or 10 bucks - is there a way to do that, maybe a direct paypal donation?

I don't think there is any procedure for accepting money for our services.
Let's do some cleanup.


To uninstall ComboFix


  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


Comodo found something in an app I've used before - Page 2 Combofix_uninstall_image

(Note: Make sure there's a space between the word ComboFix and the forward-slash.)


  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.

************************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.

Comodo found something in an app I've used before - Page 2 Diskcleanup2

Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.

Comodo found something in an app I've used before - Page 2 Diskcleanup

This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
*******************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!

descriptionComodo found something in an app I've used before - Page 2 EmptyRe: Comodo found something in an app I've used before

more_horiz
I just finished cleanup, using the links next. Thanks again for everything!

descriptionComodo found something in an app I've used before - Page 2 EmptyRe: Comodo found something in an app I've used before

more_horiz
Arashmickey wrote:
I just finished cleanup, using the links next. Thanks again for everything!

You're welcome. Stay safe.

descriptionComodo found something in an app I've used before - Page 2 EmptyRe: Comodo found something in an app I've used before

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum