This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

hijack this log, viruses, blue screen, problems

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

โ€ขRefrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
โ€ขIf you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
โ€ขEven if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
โ€ขPlease reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post




Please do the following.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.







[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scanโ€ฆclick on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following โ€ฆ
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<โ€” ROOKIT" entries


If GMER won't run try with devices unchecked.If still no go try in safe mode.



In your next reply please post the following.
  • Both OTL logs
  • GMER log
OK,do not attach any more logs,copy/paste them directly into your post You have only posted 2 logs,Extras.txt and GMER,you need to post OTL.txt,re run OTL if you need to
OTL Extras logfile created on: 11/13/2010 7:46:15 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = c:\Users\kristyn\Downloads
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 60.00% Memory free
7.00 Gb Paging File | 5.00 Gb Available in Paging File | 73.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 229.83 Gb Total Space | 79.90 Gb Free Space | 34.76% Space Free | Partition Type: NTFS
Drive D: | 875.44 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: KRISTY-PC | User Name: kristyn | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] โ€“ C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] โ€“ C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] โ€“ "%1" %*
cmdfile [open] โ€“ "%1" %*
comfile [open] โ€“ "%1" %*
cplfile [cplopen] โ€“ %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] โ€“ "%1" %*
helpfile [open] โ€“ Reg Error: Key error.
hlpfile [open] โ€“ %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] โ€“ %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] โ€“ "%1" %*
regfile [merge] โ€“ Reg Error: Key error.
scrfile [config] โ€“ "%1"
scrfile [install] โ€“ rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] โ€“ "%1" /S
txtfile โ€“ Reg Error: Key error.
Unknown [openas] โ€“ %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] โ€“ cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] โ€“ %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] โ€“ %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{224BEEA6-C652-4C9E-B2F3-D034E54D7FD9}" = lport=999 | protocol=6 | dir=in | app=c:\windows\windowsmobile\wmdhost.exe |
"{274D94DA-6830-46B7-98DA-89F83457250C}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=c:\windows\system32\svchost.exe |
"{2CD2CEE7-7F9B-45BE-8D3B-CFFAF7B09D5F}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=c:\windows\system32\svchost.exe |
"{2F2605A9-EB0C-4FA2-B20C-AE6060670582}" = lport=5678 | protocol=6 | dir=in | app=c:\windows\windowsmobile\wmdhost.exe |
"{2F4FA6A6-5333-4E71-9542-0476A9820B27}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=c:\windows\system32\svchost.exe |
"{39784BEC-123E-4B02-98EF-80398FF2C60E}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=c:\windows\system32\svchost.exe |
"{4594EC05-5DBA-4E13-8442-47EA6AF19338}" = lport=26675 | protocol=6 | dir=in | name=windows mobile-based device connectivity - desktop airsync (tcp-in) |
"{8B96CD1C-CBFB-41F3-AE69-917608F05179}" = lport=999 | protocol=6 | dir=in | app=c:\windows\windowsmobile\wmdhost.exe |
"{ABBE954F-2F5B-4B4C-835E-B0736BF52859}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=c:\windows\system32\svchost.exe |
"{D0AE0B1F-EF9D-4262-BE46-1DC2A94B595B}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=c:\windows\system32\svchost.exe |
"{EE0BBD06-A03B-4226-990B-C42C8F156880}" = lport=26675 | protocol=6 | dir=in | name=windows mobile-based device connectivity - desktop airsync (tcp-in) |
"{F705AAA0-1193-44E1-9301-01D29F06DC75}" = lport=5678 | protocol=6 | dir=in | app=c:\windows\windowsmobile\wmdhost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{08572416-D41D-470D-9093-68A3D57062F2}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{229313D4-0EBF-4AA8-8367-51A9CDD410C3}" = protocol=17 | dir=out | svc=wcescomm | app=c:\windows\system32\svchost.exe |
"{26D25C4D-5451-4398-B48C-DDB6E7F91C1F}" = protocol=6 | dir=in | svc=wcescomm | app=c:\windows\system32\svchost.exe |
"{27B72672-8968-4A75-A26A-8615A73D53A1}" = protocol=6 | dir=out | svc=rapimgr | app=c:\windows\system32\svchost.exe |
"{39DC0A1F-3649-4328-9080-EFB911E0BA36}" = protocol=17 | dir=out | svc=wcescomm | app=c:\windows\system32\svchost.exe |
"{3A657343-5E1B-496F-A5CF-973247F06ECA}" = protocol=6 | dir=out | svc=rapimgr | app=c:\windows\system32\svchost.exe |
"{3AA2B44F-4F57-4D0A-B963-441B1FBC6374}" = protocol=6 | dir=out | svc=wcescomm | app=c:\windows\system32\svchost.exe |
"{542E782C-C16A-4012-802B-408458FC2242}" = dir=in | app=c:\program files\myspace\im\myspaceim.exe |
"{626A043B-FD97-4DF3-BA60-FA6BA5235E0E}" = protocol=17 | dir=out | svc=wcescomm | app=c:\windows\system32\svchost.exe |
"{66483E92-DDC3-40DB-9412-8A314D408FC7}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{68C37B74-7320-4FC5-95CD-F6028818F5E2}" = protocol=17 | dir=out | svc=rapimgr | app=c:\windows\system32\svchost.exe |
"{6BF9BEE0-5053-4EE9-A283-AEF426BF16EB}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{6FF8D0F4-D0C9-4E2F-AA4E-EDDB5710681B}" = protocol=6 | dir=out | svc=rapimgr | app=c:\windows\system32\svchost.exe |
"{71B94B62-215A-4D14-BBE2-3587FBC42BB5}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{7B561B36-222A-4607-AF5A-3FE60535AEB5}" = protocol=17 | dir=out | svc=rapimgr | app=c:\windows\system32\svchost.exe |
"{7D3A2F4D-E492-4B94-B0A1-C1F0C30B3523}" = protocol=6 | dir=in | svc=wcescomm | app=c:\windows\system32\svchost.exe |
"{86200D71-0DC4-481D-B67C-BB6A3C634EDB}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{867AC1EA-1797-4F6F-B7F6-2189558D4EC5}" = protocol=17 | dir=out | svc=rapimgr | app=c:\windows\system32\svchost.exe |
"{91568559-3C73-4B46-A802-140F05594CA6}" = protocol=17 | dir=out | svc=rapimgr | app=c:\windows\system32\svchost.exe |
"{97967AB5-4232-4625-A998-1CFE47F9C471}" = protocol=17 | dir=out | svc=wcescomm | app=c:\windows\system32\svchost.exe |
"{A0909879-4F07-494B-B441-82D85298C6F0}" = protocol=6 | dir=in | svc=wcescomm | app=c:\windows\system32\svchost.exe |
"{A451A7CC-FFC0-4939-AB2E-E90947942D2E}" = protocol=6 | dir=out | svc=wcescomm | app=c:\windows\system32\svchost.exe |
"{A76B29F3-C68C-4B51-89D5-C9C41C189165}" = protocol=6 | dir=out | svc=rapimgr | app=c:\windows\system32\svchost.exe |
"{A7AB0565-8A20-4EA3-A7F3-7B0750F31BCF}" = protocol=17 | dir=out | svc=rapimgr | app=c:\windows\system32\svchost.exe |
"{B1033DF9-E681-44D2-AA68-EFFD94616A6C}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B4BE510E-9343-4B25-8D4B-D468849A18D0}" = protocol=6 | dir=in | svc=wcescomm | app=c:\windows\system32\svchost.exe |
"{B5770332-7E81-4946-BB1B-4DC14F2254BD}" = protocol=6 | dir=out | svc=wcescomm | app=c:\windows\system32\svchost.exe |
"{B8DB2CDC-8185-4524-8857-402016689354}" = protocol=17 | dir=out | svc=wcescomm | app=c:\windows\system32\svchost.exe |
"{C05B2879-8031-47FF-966E-D1320611B321}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C5D93CE7-7EDE-48AA-8944-C653BDCC641D}" = protocol=6 | dir=out | svc=wcescomm | app=c:\windows\system32\svchost.exe |
"{C936AECC-5DCF-41F1-BACD-3EB4C3B107CB}" = protocol=6 | dir=out | svc=wcescomm | app=c:\windows\system32\svchost.exe |
"{DB038357-81C1-4D72-BDA7-62D1F5CA8299}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{F763C314-E5D6-4214-A70B-2F3529789173}" = protocol=6 | dir=in | svc=wcescomm | app=c:\windows\system32\svchost.exe |
"{FD564A5A-C190-45C2-937D-46B4386B6516}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{FF189232-65D1-41D8-AECB-461A110AAAB2}" = protocol=6 | dir=out | svc=rapimgr | app=c:\windows\system32\svchost.exe |
"TCP Query User{237B4350-D97A-4B7E-B004-3718D6921CDD}C:\program files\itunes\itunes.exe" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{46E9FA61-4F70-4248-998A-66BDFE59EC56}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{52CB409C-9405-4C94-9EDC-CEE8AF5E9E00}C:\programdata\552284\sm552_2185.exe" = protocol=6 | dir=in | app=c:\programdata\552284\sm552_2185.exe |
"TCP Query User{7D90F81E-11D9-4F99-B6B8-68E43AEE983F}C:\program files\bitwise\bitwise.exe" = protocol=6 | dir=in | app=c:\program files\bitwise\bitwise.exe |
"TCP Query User{E8ECD356-5420-4B6A-A456-FEFE8FA647C6}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{050B073D-5E51-48FA-8FAC-BA166B5C4BCA}C:\program files\bitwise\bitwise.exe" = protocol=17 | dir=in | app=c:\program files\bitwise\bitwise.exe |
"UDP Query User{073534FE-5D60-43A2-BFD0-CACD93402A48}C:\program files\itunes\itunes.exe" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"UDP Query User{0BFFD6E1-B346-4E16-8CB7-B7AC5E03A003}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{F04F39F1-8ADF-4A5C-9EA3-1D9A66B0EEC0}C:\programdata\552284\sm552_2185.exe" = protocol=17 | dir=in | app=c:\programdata\552284\sm552_2185.exe |
"UDP Query User{F38F6A8F-3FF3-46FC-B5F5-D30303372C1A}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{08C0729E-3E50-11DF-9D81-005056806466}" = Google Earth
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20ACB2F8-3BCA-45A8-80A2-9D3CB5C25F43}" = Safari
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Javaโ„ข 6 Update 11
"{27F00C63-449B-2FAB-CBE8-24AB80E17449}" = Acrobat.com
"{2A8E4833-F483-4074-B4DB-F295F7901A8D}" = MobileMe Control Panel
"{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0150160}" = J2SE Runtime Environment 5.0 Update 16
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Javaโ„ข 6 Update 7
"{54A4839E-87F8-4BD1-9682-A349E9943F0A}" = Amazon Unbox Video
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{856C155E-4A74-4041-B026-04F96FFD1BCD}" = ZIP Reader 8.00.0018
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.0
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B26B00DA-2E5D-4CF2-83C5-911198C0F009}" = GoodSync
"{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}" = Microsoft Corporation
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skypeโ„ข 4.2
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DDCD95B5-7230-462F-9889-7EBBEE74123C}" = Microsoft Forefront Client Security Antimalware Service
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E8B56B38-A826-11DB-8C83-0011430C73A4}" = Microsoft Forefront Client Security State Assessment Service
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AI RoboForm" = AI RoboForm (All Users)
"avast5" = avast! Free Antivirus
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"HDMI" = Intelยฎ Graphics Media Accelerator Driver
"InstallShield_{54A4839E-87F8-4BD1-9682-A349E9943F0A}" = Amazon Unbox Video
"IObit Security 360_is1" = IObit Security 360
"Jeyo Mobile Companion 2.1_is1" = Jeyo Mobile Companion 2.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Sight Words Sentence Builder for Windows_is1" = Sight Words Sentence Builder for Windows 1.1
"Souptoys" = Souptoys
"WinRAR archiver" = WinRAR archiver
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 7/19/2009 3:00:31 PM | Computer Name = Kristy-PC | Source = avast! | ID = 33554522
Description =

Error - 7/23/2009 10:53:35 PM | Computer Name = Kristy-PC | Source = avast! | ID = 33554522
Description =

Error - 7/27/2009 10:04:22 PM | Computer Name = Kristy-PC | Source = avast! | ID = 33554522
Description =

Error - 9/6/2009 3:13:13 PM | Computer Name = Kristy-PC | Source = avast! | ID = 33554522
Description =

Error - 9/16/2009 7:08:27 AM | Computer Name = Kristy-PC | Source = avast! | ID = 33554522
Description =

Error - 9/29/2009 6:49:49 AM | Computer Name = Kristy-PC | Source = avast! | ID = 33554522
Description =

Error - 10/21/2009 7:34:51 AM | Computer Name = Kristy-PC | Source = avast! | ID = 33554522
Description =

Error - 11/29/2009 12:05:26 AM | Computer Name = Kristy-PC | Source = avast! | ID = 33554522
Description =

Error - 1/14/2010 11:29:42 PM | Computer Name = Kristy-PC | Source = avast! | ID = 33554522
Description =

Error - 2/3/2010 9:13:19 PM | Computer Name = Kristy-PC | Source = avast! | ID = 33554522
Description =

[ Application Events ]
Error - 11/13/2010 11:45:22 AM | Computer Name = Kristy-PC | Source = MsiInstaller | ID = 11606
Description =

Error - 11/13/2010 4:45:17 PM | Computer Name = Kristy-PC | Source = MsiInstaller | ID = 11606
Description =

Error - 11/13/2010 4:45:17 PM | Computer Name = Kristy-PC | Source = MsiInstaller | ID = 11606
Description =

Error - 11/13/2010 5:06:46 PM | Computer Name = Kristy-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18904, time stamp
0x4b835fec, faulting module Flash10e.ocx, version 10.0.45.2, time stamp 0x4b5f8faa,
exception code 0xc0000005, fault offset 0x000d3327, process id 0x1678, application
start time 0x01cb8340af30e0ce.

Error - 11/13/2010 5:34:15 PM | Computer Name = Kristy-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 11/13/2010 5:34:15 PM | Computer Name = Kristy-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 11/13/2010 9:44:37 PM | Computer Name = Kristy-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.6001.18904 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: c Start Time: 01cb82f6fc81a98e Termination Time: 118

Error - 11/13/2010 9:44:57 PM | Computer Name = Kristy-PC | Source = MsiInstaller | ID = 11606
Description =

Error - 11/13/2010 9:44:57 PM | Computer Name = Kristy-PC | Source = MsiInstaller | ID = 11606
Description =

Error - 11/13/2010 9:47:05 PM | Computer Name = Kristy-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

[ Media Center Events ]
Error - 6/5/2009 11:49:19 PM | Computer Name = Kristy-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 2/28/2010 6:47:53 AM | Computer Name = Kristy-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 4/6/2010 6:54:01 PM | Computer Name = Kristy-PC | Source = MCUpdate | ID = 0
Description = Failed to wait on MCUpdate mutex with exception: 'The wait completed
due to an abandoned mutex.'.

[ System Events ]
Error - 9/30/2010 5:46:50 PM | Computer Name = Kristy-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 9/30/2010 5:47:10 PM | Computer Name = Kristy-PC | Source = DCOM | ID = 10016
Description =

Error - 9/30/2010 5:47:46 PM | Computer Name = Kristy-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 9/30/2010 5:51:13 PM | Computer Name = Kristy-PC | Source = FcsSas | ID = 141078
Description = Forefront Client Security State Assessment Service policy applied
with errors. Reverted to the following settings: Schedule Type: Interval Time: 12 Parameter

Error - 9/30/2010 6:00:42 PM | Computer Name = Kristy-PC | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =

Error - 10/1/2010 4:01:40 AM | Computer Name = Kristy-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =

Error - 10/1/2010 4:02:28 AM | Computer Name = Kristy-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =

Error - 10/1/2010 4:04:33 AM | Computer Name = Kristy-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =

Error - 10/1/2010 1:01:40 PM | Computer Name = Kristy-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 11:57:50 AM on 10/1/2010 was unexpected.

Error - 10/1/2010 1:03:06 PM | Computer Name = Kristy-PC | Source = Service Control Manager | ID = 7000
Description =


< End of report >
OTL logfile created on: 11/13/2010 10:14:14 PM - Run 2
OTL by OldTimer - Version 3.2.17.3 Folder = c:\Users\kristyn\Downloads
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 48.00% Memory free
7.00 Gb Paging File | 5.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 229.83 Gb Total Space | 79.32 Gb Free Space | 34.51% Space Free | Partition Type: NTFS
Drive D: | 875.44 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: KRISTY-PC | User Name: kristyn | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - c:\Users\kristyn\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\IObit\IObit Security 360\is360tray.exe (IObit)
PRC - C:\Program Files\IObit\IObit Security 360\is360srv.exe (IObit)
PRC - C:\ProgramData\OfficeGuardianV2\UACProxy.exe (Storage Appliance Corp.)
PRC - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MSASCui.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe (Amazon.com)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Forefront\Client Security\Client\SSA\FcsSas.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - c:\Users\kristyn\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (avast! Web Scanner) โ€“ C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) โ€“ C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) โ€“ C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (Apple Mobile Device) โ€“ C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (IS360service) โ€“ C:\Program Files\IObit\IObit Security 360\is360srv.exe (IObit)
SRV - (CFUACProxy_officeguardianv2) โ€“ C:\ProgramData\OfficeGuardianV2\UACProxy.exe (Storage Appliance Corp.)
SRV - (FCSAM) โ€“ c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (ADVService) โ€“ C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe (Amazon.com)
SRV - (WinHttpAutoProxySvc) โ€“ winhttp.dll (Microsoft Corporation)
SRV - (SBSDWSCService) โ€“ C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (YahooAUService) โ€“ C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (WinDefend) โ€“ C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WcesComm) โ€“ C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) โ€“ C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (FcsSas) โ€“ C:\Program Files\Microsoft Forefront\Client Security\Client\SSA\FcsSas.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) โ€“ C:\Windows\System32\DRIVERS\LV302V32.SYS File not found
DRV - (PCTINDIS5) โ€“ C:\Windows\System32\PCTINDIS5.SYS File not found
DRV - (NwlnkFwd) โ€“ C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) โ€“ C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (LVUSBSta) โ€“ C:\Windows\System32\DRIVERS\LVUSBSta.sys File not found
DRV - (IpInIp) โ€“ C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) โ€“ C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (aswTdi) โ€“ C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswSP) โ€“ C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) โ€“ C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMonFlt) โ€“ C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) โ€“ C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (VX3000) โ€“ C:\Windows\System32\drivers\VX3000.sys (Microsoft Corporation)
DRV - (PCASp50) โ€“ C:\Windows\System32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (swmsflt) โ€“ C:\Windows\System32\drivers\swmsflt.sys ()
DRV - (igfx) โ€“ C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (NETw4v32) Intelยฎ โ€“ C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (motmodem) โ€“ C:\Windows\System32\drivers\motmodem.sys (Motorola)
DRV - (viaide) โ€“ C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) โ€“ C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) โ€“ C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (iaStor) โ€“ C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (nvstor) โ€“ C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) NVIDIA nForceโ„ข โ€“ C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (rismxdp) โ€“ C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (ql2300) โ€“ C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) โ€“ C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) โ€“ C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) โ€“ C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) โ€“ C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) โ€“ C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) โ€“ C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) โ€“ C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) โ€“ C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) โ€“ C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) โ€“ C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) โ€“ C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nfrd960) โ€“ C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) โ€“ C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) โ€“ C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (aic78xx) โ€“ C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) โ€“ C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) โ€“ C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) โ€“ C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) โ€“ C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) โ€“ C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) โ€“ C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) โ€“ C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) โ€“ C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) โ€“ C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) โ€“ C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) โ€“ C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) โ€“ C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) โ€“ C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) โ€“ C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (WSDPrintDevice) โ€“ C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (WINUSB) โ€“ C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) โ€“ C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) โ€“ C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) โ€“ C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) โ€“ C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) โ€“ C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) โ€“ C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) โ€“ C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (HSF_DPV) โ€“ C:\Windows\System32\drivers\VSTDPV3.SYS (Conexant Systems, Inc.)
DRV - (HSFHWAZL) โ€“ C:\Windows\System32\drivers\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (winachsf) โ€“ C:\Windows\System32\drivers\VSTCNXT3.SYS (Conexant Systems, Inc.)
DRV - (ntrigdigi) โ€“ C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intelยฎ โ€“ C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (bcm4sbxp) โ€“ C:\Windows\System32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (rimsptsk) โ€“ C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) โ€“ C:\Windows\System32\drivers\rimmptsk.sys (REDC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C0 5E 4B F8 1B 82 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



Hosts file not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Javaโ„ข Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [IObit Security 360] C:\Program Files\IObit\IObit Security 360\IS360tray.exe (IObit)
O4 - HKLM..\Run: [Microsoft Forefront Client Security Antimalware Service] c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [CyberDefender Registry Cleaner] File not found
O4 - HKCU..\Run: [DoubleMySpeed Registry Cleaner] c:\program files\cyberdefender\registry scanner\Startcdrc.exe File not found
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashโ€ฆr/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] 1.1.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | โ€”- | M] () - C:\autoexec.bat โ€“ [ NTFS ]
O33 - MountPoints2\{535fbd0a-107e-11df-ac49-001fe2d9785b}\Shell - "" = AutoRun
O33 - MountPoints2\{535fbd0a-107e-11df-ac49-001fe2d9785b}\Shell\AutoRun\command - "" = F:\StartClickFreeBackup.exe โ€“ File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] โ€“ "%1" %*
O35 - HKLM\..exefile [open] โ€“ "%1" %*
O37 - HKLM\โ€ฆcom [@ = comfile] โ€“ "%1" %*
O37 - HKLM\โ€ฆexe [@ = exefile] โ€“ "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: aux - wdmaud.drv (Microsoft Corporation)
Drivers32: aux1 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux2 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux3 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux4 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux5 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux6 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux7 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux8 - wdmaud.drv (Microsoft Corporation)
Drivers32: aux9 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi - wdmaud.drv (Microsoft Corporation)
Drivers32: midi1 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi2 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi3 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi4 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi5 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi6 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi7 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi8 - wdmaud.drv (Microsoft Corporation)
Drivers32: midi9 - wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - midimap.dll (Microsoft Corporation)
Drivers32: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer1 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer2 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer3 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer4 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer5 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer6 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer7 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer8 - wdmaud.drv (Microsoft Corporation)
Drivers32: mixer9 - wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32: MSVideo - vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - VfWWDM32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - lvcodec2.dll File not found
Drivers32: VIDC.IYUV - iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YUY2 - msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVU9 - tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - msyuv.dll (Microsoft Corporation)
Drivers32: wave - wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave2 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave3 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave4 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave5 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave6 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave7 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave8 - wdmaud.drv (Microsoft Corporation)
Drivers32: wave9 - wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/11/13 20:01:23 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\AppData\Roaming\WinRAR
[2010/11/13 14:56:54 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\AppData\Roaming\Souptoys
[2010/11/13 14:56:54 | 000,000,000 | โ€”D | C] โ€“ C:\ProgramData\Souptoys
[2010/11/13 14:56:37 | 000,000,000 | โ€”D | C] โ€“ C:\Users\Public\Documents\Playsets
[2010/11/13 14:56:36 | 000,000,000 | โ€”D | C] โ€“ C:\ProgramData\Souptoys2
[2010/11/13 14:56:34 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Souptoys
[2010/11/13 14:40:30 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Sight Words Sentence Builder
[2010/11/13 14:00:33 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\AppData\Roaming\IObit
[2010/11/13 14:00:30 | 000,000,000 | โ€”D | C] โ€“ C:\ProgramData\IObit
[2010/11/13 14:00:14 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\IObit
[2010/11/13 09:05:23 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\AppData\Roaming\Malwarebytes
[2010/11/13 09:04:59 | 000,038,224 | โ€”- | C] (Malwarebytes Corporation) โ€“ C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/11/13 09:04:55 | 000,020,952 | โ€”- | C] (Malwarebytes Corporation) โ€“ C:\Windows\System32\drivers\mbam.sys
[2010/11/13 09:04:54 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Malwarebytes' Anti-Malware
[2010/11/11 21:18:39 | 000,000,000 | โ€”D | C] โ€“ C:\ProgramData\Spybot - Search & Destroy
[2010/11/11 21:18:39 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Spybot - Search & Destroy
[2010/11/07 06:47:43 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\AppData\Local\Apple
[2010/11/02 18:27:15 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\AppData\Roaming\PeerNetworking
[2010/10/28 11:00:07 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\AppData\Local\Adobe
[2010/10/28 10:09:28 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\x
[2010/10/28 09:58:51 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\Office Genuine Advantage
[2010/10/28 08:49:59 | 020,617,000 | โ€”- | C] (Skype Technologies S.A.) โ€“ C:\Users\kristyn\Documents\SkypeSetupFull.exe
[2010/10/28 08:49:57 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\Documents\ryan
[2010/10/28 08:49:54 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\Documents\MySpaceIM Pics
[2010/10/28 08:49:53 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\Documents\My Google Gadgets
[2010/10/28 08:49:53 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\Documents\My Albums
[2010/10/28 08:49:47 | 003,371,384 | โ€”- | C] (Malwarebytes Corporation ) โ€“ C:\Users\kristyn\Documents\mbam-setup.exe
[2010/10/28 08:49:41 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\Documents\Downloads
[2010/10/28 08:49:39 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\Documents\Documents on Kristyn's MOTO Q 9h
[2010/10/28 08:49:37 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\Documents\Collage Projects
[2010/10/28 08:49:31 | 003,480,997 | โ€”- | C] (BitWise Communications, LLC ) โ€“ C:\Users\kristyn\Documents\BitWiseSetup.exe
[2010/10/28 08:49:26 | 003,001,016 | โ€”- | C] (Siber Systems) โ€“ C:\Users\kristyn\Documents\AiRoboForm-cnetc.exe
[2010/10/28 08:49:26 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\Documents\angel
[2010/10/28 08:49:16 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\Desktop\My Pictures
[2010/10/28 08:49:05 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\Desktop\Adobe Reader 9 Installer
[2010/10/28 08:48:59 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\calendars
[2010/10/28 08:48:19 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\.SunDownloadManager
[2010/10/28 08:40:39 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\AppData\Roaming\Yahoo!
[2010/10/28 08:40:39 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\AppData\Local\Yahoo
[2010/10/28 08:38:05 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\AppData\Roaming\Adobe
[2010/10/28 08:36:30 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\Documents\My RoboForm Data
[2010/10/28 08:36:22 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\AppData\Roaming\Apple Computer
[2010/10/28 08:36:19 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\AppData\Local\Apple Computer
[2010/10/28 08:36:13 | 000,000,000 | Rโ€“D | C] โ€“ C:\Users\kristyn\Searches
[2010/10/28 08:36:09 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\AppData\Roaming\Identities
[2010/10/28 08:36:06 | 000,000,000 | Rโ€“D | C] โ€“ C:\Users\kristyn\Contacts
[2010/10/28 08:36:05 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\AppData\Local\VirtualStore
[2010/10/28 08:35:59 | 000,000,000 | -HSD | C] โ€“ C:\Users\kristyn\AppData\Local\Temporary Internet Files
[2010/10/28 08:35:59 | 000,000,000 | -HSD | C] โ€“ C:\Users\kristyn\Templates
[2010/10/28 08:35:59 | 000,000,000 | -HSD | C] โ€“ C:\Users\kristyn\Start Menu
[2010/10/28 08:35:59 | 000,000,000 | -HSD | C] โ€“ C:\Users\kristyn\SendTo
[2010/10/28 08:35:59 | 000,000,000 | -HSD | C] โ€“ C:\Users\kristyn\Recent
[2010/10/28 08:35:59 | 000,000,000 | -HSD | C] โ€“ C:\Users\kristyn\PrintHood
[2010/10/28 08:35:59 | 000,000,000 | -HSD | C] โ€“ C:\Users\kristyn\NetHood
[2010/10/28 08:35:59 | 000,000,000 | -HSD | C] โ€“ C:\Users\kristyn\Documents\My Videos
[2010/10/28 08:35:59 | 000,000,000 | -HSD | C] โ€“ C:\Users\kristyn\Documents\My Pictures
[2010/10/28 08:35:59 | 000,000,000 | -HSD | C] โ€“ C:\Users\kristyn\Documents\My Music
[2010/10/28 08:35:59 | 000,000,000 | -HSD | C] โ€“ C:\Users\kristyn\My Documents
[2010/10/28 08:35:59 | 000,000,000 | -HSD | C] โ€“ C:\Users\kristyn\Local Settings
[2010/10/28 08:35:59 | 000,000,000 | -HSD | C] โ€“ C:\Users\kristyn\AppData\Local\History
[2010/10/28 08:35:59 | 000,000,000 | -HSD | C] โ€“ C:\Users\kristyn\Cookies
[2010/10/28 08:35:59 | 000,000,000 | -HSD | C] โ€“ C:\Users\kristyn\Application Data
[2010/10/28 08:35:59 | 000,000,000 | -HSD | C] โ€“ C:\Users\kristyn\AppData\Local\Application Data
[2010/10/28 08:35:58 | 000,000,000 | โ€“SD | C] โ€“ C:\Users\kristyn\AppData\Roaming\Microsoft
[2010/10/28 08:35:58 | 000,000,000 | Rโ€“D | C] โ€“ C:\Users\kristyn\Videos
[2010/10/28 08:35:58 | 000,000,000 | Rโ€“D | C] โ€“ C:\Users\kristyn\Saved Games
[2010/10/28 08:35:58 | 000,000,000 | Rโ€“D | C] โ€“ C:\Users\kristyn\Pictures
[2010/10/28 08:35:58 | 000,000,000 | Rโ€“D | C] โ€“ C:\Users\kristyn\Music
[2010/10/28 08:35:58 | 000,000,000 | Rโ€“D | C] โ€“ C:\Users\kristyn\Links
[2010/10/28 08:35:58 | 000,000,000 | Rโ€“D | C] โ€“ C:\Users\kristyn\Favorites
[2010/10/28 08:35:58 | 000,000,000 | Rโ€“D | C] โ€“ C:\Users\kristyn\Downloads
[2010/10/28 08:35:58 | 000,000,000 | Rโ€“D | C] โ€“ C:\Users\kristyn\Documents
[2010/10/28 08:35:58 | 000,000,000 | Rโ€“D | C] โ€“ C:\Users\kristyn\Desktop
[2010/10/28 08:35:58 | 000,000,000 | -H-D | C] โ€“ C:\Users\kristyn\AppData
[2010/10/28 08:35:58 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\AppData\Local\Temp
[2010/10/28 08:35:58 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\Roaming
[2010/10/28 08:35:58 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\AppData\Local\Microsoft
[2010/10/28 08:35:58 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\AppData\Roaming\Media Center Programs
[2010/10/28 08:35:58 | 000,000,000 | โ€”D | C] โ€“ C:\Users\kristyn\AppData\Roaming\Macromedia
[2010/10/27 12:50:38 | 000,000,000 | -HSD | C] โ€“ C:\ProgramData\SMGHNYE
[2010/10/27 12:50:08 | 000,000,000 | -HSD | C] โ€“ C:\ProgramData\552284
[14 C:\Users\kristyn\Documents\*.tmp files -> C:\Users\kristyn\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2078/11/26 04:47:22 | 000,058,672 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\07012009a 016.JPG
[2078/11/26 04:47:14 | 000,058,038 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\07012009a 015.JPG
[2078/11/26 04:47:04 | 000,058,993 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\07012009a 014.JPG
[2078/11/26 04:46:48 | 000,058,621 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\07012009a 013.JPG
[2078/11/26 04:46:38 | 000,058,721 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\07012009a 012.JPG
[2078/11/26 04:46:20 | 000,058,713 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\07012009a 011.JPG
[2078/11/26 04:46:10 | 000,059,189 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\07012009a 010.JPG
[2078/11/26 04:46:00 | 000,059,229 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\07012009a 009.JPG
[2078/11/26 04:45:48 | 000,059,227 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\07012009a 008.JPG
[2078/11/26 04:45:38 | 000,059,392 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\07012009a 007.JPG
[2078/11/26 04:45:24 | 000,060,053 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\07012009a 006.JPG
[2078/11/26 04:45:14 | 000,060,016 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\07012009a 005.JPG
[2078/11/26 04:45:00 | 000,059,610 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\07012009a 004.JPG
[2078/11/24 11:26:04 | 000,058,862 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 058.JPG
[2078/11/24 10:52:32 | 000,060,027 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 057.JPG
[2078/11/24 10:52:20 | 000,060,109 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 056.JPG
[2078/11/24 10:50:24 | 000,060,539 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 055.JPG
[2078/11/24 10:50:10 | 000,059,396 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 054.JPG
[2078/11/24 09:37:56 | 000,059,711 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 053.JPG
[2078/11/24 09:37:44 | 000,059,761 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 052.JPG
[2078/11/24 09:37:12 | 000,060,927 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 051.JPG
[2078/11/24 09:36:58 | 000,061,157 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 050.JPG
[2078/11/24 09:33:46 | 000,059,094 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 049.JPG
[2078/11/24 09:31:54 | 000,060,832 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 048.JPG
[2078/11/24 09:17:00 | 000,059,973 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 046.JPG
[2078/11/24 09:16:44 | 000,060,058 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 045.JPG
[2078/11/24 09:16:32 | 000,059,285 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 044.JPG
[2078/11/24 09:07:10 | 000,060,055 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 043.JPG
[2078/11/24 09:06:54 | 000,059,263 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 042.JPG
[2078/11/24 09:04:46 | 000,058,995 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 041.JPG
[2078/11/24 08:41:22 | 000,059,723 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 040.JPG
[2078/11/24 08:41:12 | 000,059,683 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 039.JPG
[2078/11/24 08:39:48 | 000,060,551 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 038.JPG
[2078/11/24 08:18:32 | 000,060,520 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 037.JPG
[2078/11/24 07:39:12 | 000,061,741 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 035.JPG
[2078/11/24 07:05:24 | 000,058,657 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 034.JPG
[2078/11/24 07:04:16 | 000,059,995 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 033.JPG
[2078/11/24 07:03:56 | 000,058,979 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 032.JPG
[2078/11/24 07:01:48 | 000,059,296 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 031.JPG
[2078/11/24 06:59:06 | 000,058,936 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 030.JPG
[2078/11/24 05:26:24 | 000,060,419 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 029.JPG
[2078/11/24 05:26:10 | 000,060,641 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 028.JPG
[2078/11/24 05:26:00 | 000,060,425 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 027.JPG
[2078/11/11 15:10:20 | 000,058,893 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 026.JPG
[2078/11/11 15:08:56 | 000,058,979 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 025.JPG
[2078/11/11 15:08:18 | 000,058,506 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 024.JPG
[2078/11/11 15:08:08 | 000,059,444 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 023.JPG
[2078/11/11 15:07:56 | 000,059,125 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 022.JPG
[2078/11/11 14:43:54 | 000,057,359 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 021.JPG
[2078/11/11 14:42:54 | 000,059,187 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 020.JPG
[2078/11/11 14:42:40 | 000,058,715 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 019.JPG
[2078/11/11 14:42:08 | 000,059,474 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 018.JPG
[2078/11/11 14:41:28 | 000,059,290 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 017.JPG
[2078/11/11 14:41:16 | 000,059,223 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 016.JPG
[2078/11/11 14:40:44 | 000,060,623 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 015.JPG
[2078/11/11 14:40:14 | 000,061,016 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 014.JPG
[2078/11/11 14:39:30 | 000,060,868 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 013.JPG
[2078/11/11 14:39:04 | 000,059,050 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 012.JPG
[2078/11/11 14:38:48 | 000,059,418 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 011.JPG
[2078/11/11 14:38:26 | 000,059,348 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 010.JPG
[2078/11/11 14:38:12 | 000,059,386 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 009.JPG
[2078/11/11 14:37:50 | 000,058,618 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 008.JPG
[2078/11/11 14:37:36 | 000,059,020 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 007.JPG
[2078/11/11 14:37:20 | 000,059,177 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 006.JPG
[2078/11/11 14:36:58 | 000,059,214 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 005.JPG
[2078/11/11 14:36:44 | 000,058,822 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 004.JPG
[2078/11/11 14:30:40 | 000,059,491 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 003.JPG
[2078/11/11 14:29:50 | 000,057,371 | โ€”- | M] () โ€“ C:\Users\kristyn\Documents\070109 002.JPG
[2010/11/13 22:17:59 | 000,000,424 | -Hโ€“ | M] () โ€“ C:\Windows\tasks\User_Feed_Synchronization-{EF181C9C-A97E-4F97-AF98-3186403252C7}.job
[2010/11/13 22:15:00 | 000,000,416 | -Hโ€“ | M] () โ€“ C:\Windows\tasks\User_Feed_Synchronization-{A45ABC42-C9BC-4516-BD9D-9B67032392E0}.job
[2010/11/13 22:14:00 | 000,000,886 | โ€”- | M] () โ€“ C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/13 21:25:59 | 000,003,680 | -Hโ€“ | M] () โ€“ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/13 21:25:59 | 000,003,680 | -Hโ€“ | M] () โ€“ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/13 21:12:06 | 000,000,680 | โ€”- | M] () โ€“ C:\Users\kristyn\AppData\Local\d3d9caps.dat
[2010/11/13 20:26:06 | 000,000,882 | โ€”- | M] () โ€“ C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/13 20:25:50 | 000,067,584 | โ€“S- | M] () โ€“ C:\Windows\bootstat.dat
[2010/11/13 20:25:46 | 3747,655,680 | -HS- | M] () โ€“ C:\hiberfil.sys
[2010/11/13 20:24:49 | 000,000,836 | โ€”- | M] () โ€“ C:\Windows\bthservsdp.dat
[2010/11/13 20:06:51 | 360,549,407 | โ€”- | M] () โ€“ C:\Windows\MEMORY.DMP
[2010/11/13 14:56:43 | 000,001,513 | โ€”- | M] () โ€“ C:\Users\Public\Desktop\Souptoys Playsets.lnk
[2010/11/13 14:56:37 | 000,000,897 | โ€”- | M] () โ€“ C:\Users\Public\Desktop\Toybox.lnk
[2010/11/13 14:40:44 | 000,000,952 | โ€”- | M] () โ€“ C:\Users\kristyn\Desktop\Sight Words Sentence Builder.lnk
[2010/11/13 14:00:37 | 000,000,873 | โ€”- | M] () โ€“ C:\Users\Public\Desktop\IObit Security 360.lnk
[2010/11/13 14:00:37 | 000,000,135 | โ€”- | M] () โ€“ C:\Users\kristyn\Desktop\IObit Freeware.url
[2010/11/13 09:05:04 | 000,000,818 | โ€”- | M] () โ€“ C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/13 07:46:43 | 000,000,422 | -Hโ€“ | M] () โ€“ C:\Windows\tasks\User_Feed_Synchronization-{AFD52921-7C36-4FC1-AAD4-F0EA44948EB2}.job
[2010/11/11 21:20:27 | 000,001,079 | โ€”- | M] () โ€“ C:\Users\kristyn\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/11/11 21:20:27 | 000,001,055 | โ€”- | M] () โ€“ C:\Users\kristyn\Desktop\Spybot - Search & Destroy.lnk
[2010/11/07 20:49:48 | 000,631,848 | โ€”- | M] () โ€“ C:\Windows\System32\perfh009.dat
[2010/11/07 20:49:48 | 000,108,626 | โ€”- | M] () โ€“ C:\Windows\System32\perfc009.dat
[2010/11/07 06:30:22 | 000,001,796 | โ€”- | M] () โ€“ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/11/07 06:30:20 | 000,002,577 | โ€”- | M] () โ€“ C:\Windows\System32\config.nt
[2010/11/02 18:54:36 | 000,000,193 | โ€”- | M] () โ€“ C:\Users\kristyn\Desktop\Yahoo! Messenger 10 - Chat, Instant message, SMS, Video Call, PC Calls.url
[2010/11/02 18:27:16 | 000,024,206 | โ€”- | M] () โ€“ C:\Users\kristyn\AppData\Roaming\UserTile.png
[2010/10/31 21:29:54 | 000,000,376 | โ€”- | M] () โ€“ C:\Windows\ODBC.INI
[2010/10/31 21:17:12 | 000,011,264 | โ€”- | M] () โ€“ C:\Users\kristyn\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/28 08:48:07 | 000,002,413 | โ€”- | M] () โ€“ C:\Users\Public\Desktop\iTunes.lnk
[2010/10/28 08:38:41 | 000,000,938 | โ€”- | M] () โ€“ C:\Users\kristyn\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/10/28 08:37:58 | 000,000,943 | โ€”- | M] () โ€“ C:\Users\kristyn\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/10/28 08:36:00 | 000,000,632 | RHS- | M] () โ€“ C:\Users\kristyn\ntuser.pol
[2010/10/19 14:51:33 | 000,222,080 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Windows\System32\MpSigStub.exe
[14 C:\Users\kristyn\Documents\*.tmp files -> C:\Users\kristyn\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/11/13 14:56:43 | 000,001,513 | โ€”- | C] () โ€“ C:\Users\Public\Desktop\Souptoys Playsets.lnk
[2010/11/13 14:56:37 | 000,000,897 | โ€”- | C] () โ€“ C:\Users\Public\Desktop\Toybox.lnk
[2010/11/13 14:40:44 | 000,000,952 | โ€”- | C] () โ€“ C:\Users\kristyn\Desktop\Sight Words Sentence Builder.lnk
[2010/11/13 14:00:37 | 000,000,873 | โ€”- | C] () โ€“ C:\Users\Public\Desktop\IObit Security 360.lnk
[2010/11/13 14:00:37 | 000,000,135 | โ€”- | C] () โ€“ C:\Users\kristyn\Desktop\IObit Freeware.url
[2010/11/13 09:05:04 | 000,000,818 | โ€”- | C] () โ€“ C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/11 21:20:27 | 000,001,079 | โ€”- | C] () โ€“ C:\Users\kristyn\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/11/11 21:20:27 | 000,001,055 | โ€”- | C] () โ€“ C:\Users\kristyn\Desktop\Spybot - Search & Destroy.lnk
[2010/11/02 18:27:16 | 000,024,206 | โ€”- | C] () โ€“ C:\Users\kristyn\AppData\Roaming\UserTile.png
[2010/11/01 02:00:55 | 000,000,680 | โ€”- | C] () โ€“ C:\Users\kristyn\AppData\Local\d3d9caps.dat
[2010/10/28 10:59:54 | 000,011,264 | โ€”- | C] () โ€“ C:\Users\kristyn\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/28 10:09:28 | 000,005,949 | โ€”- | C] () โ€“ C:\Users\kristyn\_setup.xml
[2010/10/28 08:50:05 | 000,000,162 | -Hโ€“ | C] () โ€“ C:\Users\kristyn\Documents\~$w to cope with your abuser.doc
[2010/10/28 08:50:05 | 000,000,162 | -Hโ€“ | C] () โ€“ C:\Users\kristyn\Documents\~$purchased all of these for uploads to my new mp3 player.doc
[2010/10/28 08:50:05 | 000,000,162 | -Hโ€“ | C] () โ€“ C:\Users\kristyn\Documents\~$ladya.doc
[2010/10/28 08:50:05 | 000,000,162 | -Hโ€“ | C] () โ€“ C:\Users\kristyn\Documents\~$ammy Nominees 2000.doc
[2010/10/28 08:50:04 | 005,154,304 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\WindowsDefender.msi
[2010/10/28 08:50:04 | 000,141,091 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\w_geta04.pdf
[2010/10/28 08:50:04 | 000,080,896 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\Wrap up.doc
[2010/10/28 08:50:04 | 000,032,768 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\Write the names down of the last 21 people that wrote on your wall.doc
[2010/10/28 08:49:57 | 000,207,360 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\Questionskristynsharpe.doc
[2010/10/28 08:49:57 | 000,207,360 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\Questions.doc
[2010/10/28 08:49:57 | 000,055,755 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\Photo on 2010-07-04 at 14.19.jpg
[2010/10/28 08:49:57 | 000,025,600 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\resume.doc
[2010/10/28 08:49:55 | 000,352,256 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\phonenumbers.xls
[2010/10/28 08:49:54 | 001,495,945 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\phone080909.xml
[2010/10/28 08:49:54 | 000,893,815 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\myphone080109.xml
[2010/10/28 08:49:53 | 000,147,456 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\movie quiz.doc
[2010/10/28 08:49:53 | 000,005,473 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\me1..jpg
[2010/10/28 08:49:43 | 000,506,287 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\MagiCall2_PPC_Eng.CAB
[2010/10/28 08:49:43 | 000,217,667 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\march 09.xps
[2010/10/28 08:49:43 | 000,199,944 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\MagiCall2_SP_Eng.CAB
[2010/10/28 08:49:43 | 000,081,408 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\ladya.doc
[2010/10/28 08:49:43 | 000,025,600 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\Kristyn Sharpe resume.doc
[2010/10/28 08:49:42 | 002,247,123 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\JMC_WindowsMobile_Setup_2.1.zip
[2010/10/28 08:49:42 | 000,217,725 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\jan 09.xps
[2010/10/28 08:49:42 | 000,132,608 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\I purchased all of these for uploads to my new mp3 player.doc
[2010/10/28 08:49:42 | 000,049,664 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\How to cope with your abuser.doc
[2010/10/28 08:49:42 | 000,028,672 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\Grammy Nominees 2000.doc
[2010/10/28 08:49:42 | 000,025,600 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\I return movies.doc
[2010/10/28 08:49:42 | 000,024,576 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\Introduction.doc
[2010/10/28 08:49:42 | 000,024,049 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\jimmy.jpg
[2010/10/28 08:49:41 | 000,671,774 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\flyer4mail.jpg
[2010/10/28 08:49:41 | 000,538,984 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\form_aa151402[1].pdf
[2010/10/28 08:49:41 | 000,220,096 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\feb 09.xps
[2010/10/28 08:49:41 | 000,034,816 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\ETB_direct_deposit.pdf
[2010/10/28 08:49:41 | 000,020,182 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\ew2.pdf
[2010/10/28 08:49:41 | 000,019,968 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\Elvis number one5.doc
[2010/10/28 08:49:38 | 000,190,464 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\Disney Vacation Planner.xls
[2010/10/28 08:49:37 | 000,351,232 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\diconversation.doc
[2010/10/28 08:49:37 | 000,224,648 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\dec 08.xps
[2010/10/28 08:49:37 | 000,121,344 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\DiningOptions.doc
[2010/10/28 08:49:37 | 000,058,880 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\Cover.doc
[2010/10/28 08:49:37 | 000,055,808 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\DiscountAirline.doc
[2010/10/28 08:49:27 | 001,430,713 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\attachments_2009_02_13.zip
[2010/10/28 08:49:27 | 000,082,944 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\Answers to Your Questions.doc
[2010/10/28 08:49:27 | 000,067,072 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\birthdays.doc
[2010/10/28 08:49:26 | 000,133,632 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\Animal.doc
[2010/10/28 08:49:25 | 001,295,064 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\action_plan_englisha.pdf
[2010/10/28 08:49:25 | 000,075,794 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\adobe.jpg
[2010/10/28 08:49:25 | 000,061,216 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\addpoc.pdf
[2010/10/28 08:49:24 | 001,295,064 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\action_plan_english.pdf
[2010/10/28 08:49:24 | 000,297,865 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\28363-r.rtf
[2010/10/28 08:49:24 | 000,259,161 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\2008TaxReturn.PDF
[2010/10/28 08:49:24 | 000,058,672 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\07012009a 016.JPG
[2010/10/28 08:49:24 | 000,058,038 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\07012009a 015.JPG
[2010/10/28 08:49:24 | 000,021,453 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\1222bill.pdf
[2010/10/28 08:49:23 | 000,059,392 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\07012009a 007.JPG
[2010/10/28 08:49:23 | 000,059,229 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\07012009a 009.JPG
[2010/10/28 08:49:23 | 000,059,227 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\07012009a 008.JPG
[2010/10/28 08:49:23 | 000,059,189 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\07012009a 010.JPG
[2010/10/28 08:49:23 | 000,058,993 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\07012009a 014.JPG
[2010/10/28 08:49:23 | 000,058,721 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\07012009a 012.JPG
[2010/10/28 08:49:23 | 000,058,713 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\07012009a 011.JPG
[2010/10/28 08:49:23 | 000,058,621 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\07012009a 013.JPG
[2010/10/28 08:49:22 | 000,061,157 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 050.JPG
[2010/10/28 08:49:22 | 000,060,927 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 051.JPG
[2010/10/28 08:49:22 | 000,060,832 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 048.JPG
[2010/10/28 08:49:22 | 000,060,539 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 055.JPG
[2010/10/28 08:49:22 | 000,060,109 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 056.JPG
[2010/10/28 08:49:22 | 000,060,053 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\07012009a 006.JPG
[2010/10/28 08:49:22 | 000,060,027 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 057.JPG
[2010/10/28 08:49:22 | 000,060,016 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\07012009a 005.JPG
[2010/10/28 08:49:22 | 000,059,761 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 052.JPG
[2010/10/28 08:49:22 | 000,059,711 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 053.JPG
[2010/10/28 08:49:22 | 000,059,610 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\07012009a 004.JPG
[2010/10/28 08:49:22 | 000,059,396 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 054.JPG
[2010/10/28 08:49:22 | 000,059,094 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 049.JPG
[2010/10/28 08:49:22 | 000,058,862 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 058.JPG
[2010/10/28 08:49:22 | 000,027,135 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\07012009a 003.JPG
[2010/10/28 08:49:21 | 000,061,741 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 035.JPG
[2010/10/28 08:49:21 | 000,060,641 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 028.JPG
[2010/10/28 08:49:21 | 000,060,551 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 038.JPG
[2010/10/28 08:49:21 | 000,060,520 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 037.JPG
[2010/10/28 08:49:21 | 000,060,425 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 027.JPG
[2010/10/28 08:49:21 | 000,060,419 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 029.JPG
[2010/10/28 08:49:21 | 000,060,058 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 045.JPG
[2010/10/28 08:49:21 | 000,060,055 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 043.JPG
[2010/10/28 08:49:21 | 000,059,995 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 033.JPG
[2010/10/28 08:49:21 | 000,059,973 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 046.JPG
[2010/10/28 08:49:21 | 000,059,723 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 040.JPG
[2010/10/28 08:49:21 | 000,059,683 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 039.JPG
[2010/10/28 08:49:21 | 000,059,444 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 023.JPG
[2010/10/28 08:49:21 | 000,059,296 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 031.JPG
[2010/10/28 08:49:21 | 000,059,285 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 044.JPG
[2010/10/28 08:49:21 | 000,059,263 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 042.JPG
[2010/10/28 08:49:21 | 000,058,995 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 041.JPG
[2010/10/28 08:49:21 | 000,058,979 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 032.JPG
[2010/10/28 08:49:21 | 000,058,979 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 025.JPG
[2010/10/28 08:49:21 | 000,058,936 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 030.JPG
[2010/10/28 08:49:21 | 000,058,893 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 026.JPG
[2010/10/28 08:49:21 | 000,058,657 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 034.JPG
[2010/10/28 08:49:21 | 000,058,506 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 024.JPG
[2010/10/28 08:49:21 | 000,058,305 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 036.JPG
[2010/10/28 08:49:20 | 000,061,016 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 014.JPG
[2010/10/28 08:49:20 | 000,060,868 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 013.JPG
[2010/10/28 08:49:20 | 000,060,623 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 015.JPG
[2010/10/28 08:49:20 | 000,059,491 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 003.JPG
[2010/10/28 08:49:20 | 000,059,474 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 018.JPG
[2010/10/28 08:49:20 | 000,059,418 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 011.JPG
[2010/10/28 08:49:20 | 000,059,386 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 009.JPG
[2010/10/28 08:49:20 | 000,059,348 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 010.JPG
[2010/10/28 08:49:20 | 000,059,290 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 017.JPG
[2010/10/28 08:49:20 | 000,059,223 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 016.JPG
[2010/10/28 08:49:20 | 000,059,214 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 005.JPG
[2010/10/28 08:49:20 | 000,059,187 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 020.JPG
[2010/10/28 08:49:20 | 000,059,177 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 006.JPG
[2010/10/28 08:49:20 | 000,059,125 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 022.JPG
[2010/10/28 08:49:20 | 000,059,050 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 012.JPG
[2010/10/28 08:49:20 | 000,059,020 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 007.JPG
[2010/10/28 08:49:20 | 000,058,822 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 004.JPG
[2010/10/28 08:49:20 | 000,058,715 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 019.JPG
[2010/10/28 08:49:20 | 000,058,618 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 008.JPG
[2010/10/28 08:49:20 | 000,057,371 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 002.JPG
[2010/10/28 08:49:20 | 000,057,359 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 021.JPG
[2010/10/28 08:49:18 | 005,029,934 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\070109 001.AVI
[2010/10/28 08:49:18 | 001,065,602 | โ€”- | C] () โ€“ C:\Users\kristyn\Documents\014.JPG
[2010/10/28 08:49:18 | 000,000,193 | โ€”- | C] () โ€“ C:\Users\kristyn\Desktop\Yahoo! Messenger 10 - Chat, Instant message, SMS, Video Call, PC Calls.url
[2010/10/28 08:49:15 | 003,231,565 | โ€”- | C] () โ€“ C:\Users\kristyn\Desktop\MOV-0004.rar
[2010/10/28 08:49:13 | 002,247,123 | โ€”- | C] () โ€“ C:\Users\kristyn\Desktop\JMC_WindowsMobile_Setup_2.1.zip
[2010/10/28 08:43:22 | 000,000,422 | -Hโ€“ | C] () โ€“ C:\Windows\tasks\User_Feed_Synchronization-{AFD52921-7C36-4FC1-AAD4-F0EA44948EB2}.job
[2010/10/28 08:38:41 | 000,000,938 | โ€”- | C] () โ€“ C:\Users\kristyn\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/10/28 08:37:58 | 000,000,943 | โ€”- | C] () โ€“ C:\Users\kristyn\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/10/28 08:36:00 | 000,000,632 | RHS- | C] () โ€“ C:\Users\kristyn\ntuser.pol
[2010/10/28 08:35:58 | 000,000,258 | โ€”- | C] () โ€“ C:\Users\kristyn\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2010/10/28 08:35:58 | 000,000,240 | โ€”- | C] () โ€“ C:\Users\kristyn\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2009/08/03 15:07:42 | 000,403,816 | โ€”- | C] () โ€“ C:\Windows\System32\OGACheckControl.dll
[2009/06/26 16:21:02 | 000,015,498 | โ€”- | C] () โ€“ C:\Windows\VX3000.ini
[2009/02/22 19:58:14 | 000,000,056 | -Hโ€“ | C] () โ€“ C:\ProgramData\ezsidmv.dat
[2009/01/15 16:03:06 | 000,026,760 | Rโ€” | C] () โ€“ C:\Windows\System32\drivers\swmsflt.sys
[2008/12/18 20:48:12 | 000,000,376 | โ€”- | C] () โ€“ C:\Windows\ODBC.INI
[2008/11/12 10:07:24 | 000,000,419 | โ€”- | C] () โ€“ C:\Windows\BRWMARK.INI
[2008/11/12 10:07:24 | 000,000,027 | โ€”- | C] () โ€“ C:\Windows\BRPP2KA.INI
[2008/11/12 10:04:19 | 000,000,226 | โ€”- | C] () โ€“ C:\Windows\Brpfx04a.ini
[2008/11/12 10:04:19 | 000,000,094 | โ€”- | C] () โ€“ C:\Windows\brpcfx.ini
[2008/11/12 10:02:11 | 000,000,009 | โ€”- | C] () โ€“ C:\Windows\Brfaxrx.ini
[2008/11/12 10:02:08 | 000,106,496 | โ€”- | C] () โ€“ C:\Windows\System32\BrMuSNMP.dll
[2008/02/11 19:55:18 | 000,147,456 | โ€”- | C] () โ€“ C:\Windows\System32\igfxCoIn_v1437.dll
[2006/11/02 06:35:32 | 000,005,632 | โ€”- | C] () โ€“ C:\Windows\System32\sysprepMCE.dll
[2006/11/02 01:40:29 | 000,013,750 | โ€”- | C] () โ€“ C:\Windows\System32\pacerprf.ini
[2006/11/02 01:10:15 | 000,002,000 | โ€”- | C] () โ€“ C:\Windows\System32\keyboard.drv
[2005/05/06 19:06:00 | 000,016,480 | โ€”- | C] () โ€“ C:\Windows\System32\rixdicon.dll
[2003/01/07 15:05:08 | 000,002,695 | โ€”- | C] () โ€“ C:\Windows\System32\OUTLPERF.INI

========== LOP Check ==========

[2010/11/13 14:00:33 | 000,000,000 | โ€”D | M] โ€“ C:\Users\kristyn\AppData\Roaming\IObit
[2010/11/02 18:27:15 | 000,000,000 | โ€”D | M] โ€“ C:\Users\kristyn\AppData\Roaming\PeerNetworking
[2010/11/13 14:56:54 | 000,000,000 | โ€”D | M] โ€“ C:\Users\kristyn\AppData\Roaming\Souptoys
[2010/11/13 20:24:49 | 000,032,548 | โ€”- | M] () โ€“ C:\Windows\Tasks\SCHEDLGU.TXT
[2010/11/13 22:15:00 | 000,000,416 | -Hโ€“ | M] () โ€“ C:\Windows\Tasks\User_Feed_Synchronization-{A45ABC42-C9BC-4516-BD9D-9B67032392E0}.job
[2010/11/13 07:46:43 | 000,000,422 | -Hโ€“ | M] () โ€“ C:\Windows\Tasks\User_Feed_Synchronization-{AFD52921-7C36-4FC1-AAD4-F0EA44948EB2}.job
[2010/11/13 22:17:59 | 000,000,424 | -Hโ€“ | M] () โ€“ C:\Windows\Tasks\User_Feed_Synchronization-{EF181C9C-A97E-4F97-AF98-3186403252C7}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 15:43:36 | 000,000,024 | โ€”- | M] () โ€“ C:\autoexec.bat
[2006/11/02 03:53:57 | 000,438,840 | RHS- | M] () โ€“ C:\bootmgr
[2008/11/07 18:29:38 | 000,008,192 | R-S- | M] () โ€“ C:\BOOTSECT.BAK
[2010/11/12 18:17:57 | 000,003,152 | โ€”- | M] () โ€“ C:\CD3rdPartyWrapper.log
[2006/09/18 15:43:37 | 000,000,010 | โ€”- | M] () โ€“ C:\config.sys
[2010/11/13 20:25:46 | 3747,655,680 | -HS- | M] () โ€“ C:\hiberfil.sys
[2010/04/24 13:01:15 | 000,115,224 | โ€”- | M] () โ€“ C:\img2-001.raw
[2010/06/01 01:10:22 | 000,230,424 | โ€”- | M] () โ€“ C:\img2-002.raw
[2010/11/13 20:25:44 | 4061,384,704 | -HS- | M] () โ€“ C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/11/02 06:37:12 | 000,026,040 | โ€”- | M] () โ€“ C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 06:37:12 | 000,026,489 | โ€”- | M] () โ€“ C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 06:37:12 | 000,029,779 | โ€”- | M] () โ€“ C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 06:37:12 | 000,030,808 | โ€”- | M] () โ€“ C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 15:37:34 | 000,000,065 | โ€”- | M] () โ€“ C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 06:35:48 | 000,022,528 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2007/04/09 13:23:54 | 000,028,552 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Windows\System32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/09/07 09:12:17 | 000,038,848 | โ€”- | M] (AVAST Software) โ€“ C:\Windows\avastSS.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/12/10 09:43:22 | 000,000,174 | -HS- | M] () โ€“ C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/11/07 18:29:07 | 006,610,944 | โ€”- | M] () โ€“ C:\Windows\System32\config\COMPONENTS.SAV
[2008/11/07 18:29:00 | 000,102,400 | โ€”- | M] () โ€“ C:\Windows\System32\config\DEFAULT.SAV
[2008/11/07 18:29:07 | 000,020,480 | โ€”- | M] () โ€“ C:\Windows\System32\config\SECURITY.SAV
[2008/11/07 18:29:30 | 015,560,704 | โ€”- | M] () โ€“ C:\Windows\System32\config\SOFTWARE.SAV
[2008/11/07 18:29:35 | 006,012,928 | โ€”- | M] () โ€“ C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >
[2009/09/20 15:57:15 | 000,000,000 | โ€”D | M] โ€“ C:\Windows\System32\config\systemprofile\AppData\Local\IsolatedStorage\yz4uggjr.lex\juozz3oo.qom\Url.baos234cgu3y3glozyjwicytydpaxc2n\Url.x3upfl5pwc2qpjifbyrh04mtwz3rn4cm\Files\bak

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/10/28 08:38:42 | 000,000,286 | -HS- | M] () โ€“ C:\Users\kristyn\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2009/06/26 16:21:02 | 000,013,023 | โ€”- | M] () โ€“ C:\Windows\VX3000.src

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >
[2010/04/21 11:55:20 | 000,008,192 | โ€”- | M] () โ€“ C:\Windows\security\database\edb.chk
[2010/04/21 11:54:50 | 001,048,576 | โ€”- | M] () โ€“ C:\Windows\security\database\edb.log
[2010/03/22 13:02:40 | 001,048,576 | โ€”- | M] () โ€“ C:\Windows\security\database\edbres00001.jrs
[2010/03/22 13:02:41 | 001,048,576 | โ€”- | M] () โ€“ C:\Windows\security\database\edbres00002.jrs
[2010/04/21 11:54:50 | 001,056,768 | โ€”- | M] () โ€“ C:\Windows\security\database\tmp.edb

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2010/10/28 08:36:13 | 000,000,402 | -HS- | M] () โ€“ C:\Users\kristyn\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-13 09:02:13

========== Alternate Data Streams ==========

@Alternate Data Stream - 64 bytes -> C:\Users\kristyn\Documents\070109 001.AVI:TOC.WMV

< End of report >
Please do the following

SPYBOT TEATIMER
  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the Resident Icon in the list.
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • Click on the "System Startup" icon in the List
  • Uncheck the "TeaTimer" box and "OK" any prompts.
  • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
  • Exit Spybot S&D when done and reboot your computer.
    (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]




Next


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O4 - HKCU..\Run: [CyberDefender Registry Cleaner] File not found
    O4 - HKCU..\Run: [DoubleMySpeed Registry Cleaner] c:\program files\cyberdefender\registry scanner\Startcdrc.exe File not found
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] 1.1.1.1
    O33 - MountPoints2\{535fbd0a-107e-11df-ac49-001fe2d9785b}\Shell - "" = AutoRun
    O33 - MountPoints2\{535fbd0a-107e-11df-ac49-001fe2d9785b}\Shell\AutoRun\command - "" = F:\StartClickFreeBackup.exe โ€“ File not found
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [resethosts]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )



Next



Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
All processes killed
Error: Unable to interpret in the current context!
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\CyberDefender Registry Cleaner deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\DoubleMySpeed Registry Cleaner deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{535fbd0a-107e-11df-ac49-001fe2d9785b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{535fbd0a-107e-11df-ac49-001fe2d9785b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{535fbd0a-107e-11df-ac49-001fe2d9785b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{535fbd0a-107e-11df-ac49-001fe2d9785b}\ not found.
File F:\StartClickFreeBackup.exe not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
c:\Users\kristyn\Downloads\cmd.bat deleted successfully.
c:\Users\kristyn\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41085 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Guest
->Temp folder emptied: 857356 bytes
->Temporary Internet Files folder emptied: 147499653 bytes
->Flash cache emptied: 4560 bytes

User: kristyn
->Temp folder emptied: 2429323 bytes
->Temporary Internet Files folder emptied: 75524344 bytes
->Java cache emptied: 1651748 bytes
->Flash cache emptied: 77830 bytes

User: Public

User: ryan
->Temp folder emptied: 817418 bytes
->Temporary Internet Files folder emptied: 59749239 bytes
->Flash cache emptied: 18884 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 97250660 bytes
RecycleBin emptied: 170 bytes

Total Files Cleaned = 368.00 mb


OTL by OldTimer - Version 3.2.17.3 log created on 11142010_161219

Files\Folders moved on Rebootโ€ฆ
C:\Users\kristyn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FBYPF67E\blank[2].html moved successfully.
C:\Users\kristyn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\FBYPF67E\iframe[2].htm moved successfully.
C:\Users\kristyn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\CJ8P2EYR\blank[2].html moved successfully.
C:\Users\kristyn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\CJ8P2EYR\like[1].htm moved successfully.
C:\Users\kristyn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\8861Q9UJ\blank[1].html moved successfully.
C:\Users\kristyn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\8861Q9UJ\openmail.app[1].htm moved successfully.
C:\Users\kristyn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\8861Q9UJ\openmail.app[2].htm moved successfully.
C:\Users\kristyn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1WTSLWNG\launch[2].htm moved successfully.
C:\Users\kristyn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\0CKHNHHJ\index[1].htm moved successfully.
C:\Users\kristyn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
File move failed. C:\Windows\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.
File move failed. C:\Windows\temp\Amazon Digital Video\Servicelog.adv scheduled to be moved on reboot.
File\Folder C:\Windows\temp\TMP0000002D7208E74BF7278ED5 not found!

Registry entries deleted on Rebootโ€ฆ
2010/11/14 16:33:29.0742 TDSS rootkit removing tool 2.4.7.0 Nov 8 2010 10:52:22 2010/11/14 16:33:29.0742 ================================================================================ 2010/11/14 16:33:29.0742 SystemInfo: 2010/11/14 16:33:29.0742 2010/11/14 16:33:29.0742 OS Version: 6.0.6000 ServicePack: 0.0 2010/11/14 16:33:29.0743 Product type: Workstation 2010/11/14 16:33:29.0743 ComputerName: KRISTY-PC 2010/11/14 16:33:29.0744 UserName: kristyn 2010/11/14 16:33:29.0744 Windows directory: C:\Windows 2010/11/14 16:33:29.0744 System windows directory: C:\Windows 2010/11/14 16:33:29.0744 Processor architecture: Intel x86 2010/11/14 16:33:29.0744 Number of processors: 2 2010/11/14 16:33:29.0744 Page size: 0x1000 2010/11/14 16:33:29.0744 Boot type: Normal boot 2010/11/14 16:33:29.0744 ================================================================================ 2010/11/14 16:33:31.0378 Initialize success 2010/11/14 16:33:43.0682 ================================================================================ 2010/11/14 16:33:43.0682 Scan started 2010/11/14 16:33:43.0682 Mode: Manual; 2010/11/14 16:33:43.0682 ================================================================================ 2010/11/14 16:33:44.0471 ACPI (84fc6df81212d16be5c4f441682feccc) C:\Windows\system32\drivers\acpi.sys 2010/11/14 16:33:44.0591 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys 2010/11/14 16:33:44.0737 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys 2010/11/14 16:33:44.0830 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys 2010/11/14 16:33:44.0941 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys 2010/11/14 16:33:45.0296 AFD (5d24caf8efd924a875698ff28384db8b) C:\Windows\system32\drivers\afd.sys 2010/11/14 16:33:45.0520 agp440 (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys 2010/11/14 16:33:45.0625 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 2010/11/14 16:33:45.0767 aliide (3a99cb23a2d326fd532618705d6e3048) C:\Windows\system32\drivers\aliide.sys 2010/11/14 16:33:45.0908 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys 2010/11/14 16:33:46.0057 amdide (4333c133dbd71c7d7fe4fb1b83f9ee3e) C:\Windows\system32\drivers\amdide.sys 2010/11/14 16:33:46.0216 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys 2010/11/14 16:33:46.0291 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys 2010/11/14 16:33:46.0472 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys 2010/11/14 16:33:46.0630 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys 2010/11/14 16:33:46.0777 aswFsBlk (a0d86b8ac93ef95620420c7a24ac5344) C:\Windows\system32\drivers\aswFsBlk.sys 2010/11/14 16:33:46.0899 aswMonFlt (bd9119468c32b7ecd1e0544d3f286a73) C:\Windows\system32\drivers\aswMonFlt.sys 2010/11/14 16:33:47.0053 aswRdr (69823954bbd461a73d69774928c9737e) C:\Windows\system32\drivers\aswRdr.sys 2010/11/14 16:33:47.0140 aswSP (7ecc2776638b04553f9a85bd684c3abf) C:\Windows\system32\drivers\aswSP.sys 2010/11/14 16:33:47.0960 aswTdi (095ed820a926aa8189180b305e1bcfc9) C:\Windows\system32\drivers\aswTdi.sys 2010/11/14 16:33:48.0108 AsyncMac (e86cf7ce67d5de898f27ef884dc357d8) C:\Windows\system32\DRIVERS\asyncmac.sys 2010/11/14 16:33:48.0282 atapi (b35cfcef838382ab6490b321c87edf17) C:\Windows\system32\drivers\atapi.sys 2010/11/14 16:33:48.0498 bcm4sbxp (08015d34f6fdd0b355805bad978497c3) C:\Windows\system32\DRIVERS\bcm4sbxp.sys 2010/11/14 16:33:48.0658 Beep (ac3dd1708b22761ebd7cbe14dcc3b5d7) C:\Windows\system32\drivers\Beep.sys 2010/11/14 16:33:48.0897 bowser (913cd06fbe9105ce6077e90fd4418561) C:\Windows\system32\DRIVERS\bowser.sys 2010/11/14 16:33:49.0006 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 2010/11/14 16:33:49.0085 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 2010/11/14 16:33:49.0322 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 2010/11/14 16:33:49.0454 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 2010/11/14 16:33:49.0567 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 2010/11/14 16:33:49.0649 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 2010/11/14 16:33:49.0751 BthEnum (cf97c2d6a011ee9403b42191b5f95ba8) C:\Windows\system32\DRIVERS\BthEnum.sys 2010/11/14 16:33:49.0915 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\DRIVERS\bthmodem.sys 2010/11/14 16:33:50.0046 BthPan (b8c3d9ddf85fd197c3e5f849fef71144) C:\Windows\system32\DRIVERS\bthpan.sys 2010/11/14 16:33:50.0175 BTHPORT (b4ce8000aab30a9ab16cd0fb3db4d7cf) C:\Windows\system32\Drivers\BTHport.sys 2010/11/14 16:33:50.0263 BTHUSB (9a4ddc8544c1459aa2a118a8858dade3) C:\Windows\system32\Drivers\BTHUSB.sys 2010/11/14 16:33:50.0395 cdfs (6c3a437fc873c6f6a4fc620b6888cb86) C:\Windows\system32\DRIVERS\cdfs.sys 2010/11/14 16:33:50.0554 cdrom (8d1866e61af096ae8b582454f5e4d303) C:\Windows\system32\DRIVERS\cdrom.sys 2010/11/14 16:33:50.0709 circlass (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys 2010/11/14 16:33:50.0848 CLFS (1b84fd0937d3b99af9ba38ddff3daf54) C:\Windows\system32\CLFS.sys 2010/11/14 16:33:50.0937 CmBatt (ed97ad3df1b9005989eaf149bf06c821) C:\Windows\system32\DRIVERS\CmBatt.sys 2010/11/14 16:33:51.0025 cmdide (dfb94a6fc3a26972b0461ab5f1d8272b) C:\Windows\system32\drivers\cmdide.sys 2010/11/14 16:33:51.0115 Compbatt (722936afb75a7f509662b69b5632f48a) C:\Windows\system32\DRIVERS\compbatt.sys 2010/11/14 16:33:51.0188 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys 2010/11/14 16:33:51.0248 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys 2010/11/14 16:33:51.0387 DfsC (a7179de59ae269ab70345527894ccd7c) C:\Windows\system32\Drivers\dfsc.sys 2010/11/14 16:33:51.0558 disk (841af4c4d41d3e3b2f244e976b0f7963) C:\Windows\system32\drivers\disk.sys 2010/11/14 16:33:51.0787 drmkaud (ee472cd2c01f6f8e8aa1fa06ffef61b6) C:\Windows\system32\drivers\drmkaud.sys 2010/11/14 16:33:51.0928 DXGKrnl (334988883de69adb27e2cf9f9715bbdb) C:\Windows\System32\drivers\dxgkrnl.sys 2010/11/14 16:33:52.0100 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys 2010/11/14 16:33:52.0343 Ecache (0efc7531b936ee57fdb4e837664c509f) C:\Windows\system32\drivers\ecache.sys 2010/11/14 16:33:52.0476 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys 2010/11/14 16:33:52.0713 fastfat (84a317cb0b3954d3768cdcd018dbf670) C:\Windows\system32\drivers\fastfat.sys 2010/11/14 16:33:52.0894 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys 2010/11/14 16:33:53.0032 FileInfo (65773d6115c037ffd7ef8280ae85eb9d) C:\Windows\system32\drivers\fileinfo.sys 2010/11/14 16:33:53.0085 Filetrace (c226dd0de060745f3e042f58dcf78402) C:\Windows\system32\drivers\filetrace.sys 2010/11/14 16:33:53.0181 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys 2010/11/14 16:33:53.0261 FltMgr (a6a8da7ae4d53394ab22ac3ab6d3f5d3) C:\Windows\system32\drivers\fltmgr.sys 2010/11/14 16:33:53.0349 Fs_Rec (66a078591208baa210c7634b11eb392c) C:\Windows\system32\drivers\Fs_Rec.sys 2010/11/14 16:33:53.0438 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys 2010/11/14 16:33:53.0546 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 2010/11/14 16:33:53.0783 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys 2010/11/14 16:33:53.0925 HDAudBus (0db613a7e427b5663563677796fd5258) C:\Windows\system32\DRIVERS\HDAudBus.sys 2010/11/14 16:33:54.0101 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 2010/11/14 16:33:54.0190 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 2010/11/14 16:33:54.0304 HidUsb (3c64042b95e583b366ba4e5d2450235e) C:\Windows\system32\DRIVERS\hidusb.sys 2010/11/14 16:33:54.0452 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys 2010/11/14 16:33:54.0567 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS 2010/11/14 16:33:54.0712 HSF_DPV (ec36f1d542ed4252390d446bf6d4dfd0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS 2010/11/14 16:33:54.0903 HTTP (ea24fe637d974a8a31bc650f478e3533) C:\Windows\system32\drivers\HTTP.sys 2010/11/14 16:33:55.0008 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys 2010/11/14 16:33:55.0159 i8042prt (1c9ee072baa3abb460b91d7ee9152660) C:\Windows\system32\DRIVERS\i8042prt.sys 2010/11/14 16:33:55.0263 iaStor (fd7f9d74c2b35dbda400804a3f5ed5d8) C:\Windows\system32\drivers\iastor.sys 2010/11/14 16:33:55.0354 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys 2010/11/14 16:33:55.0618 igfx (9378d57e2b96c0a185d844770ad49948) C:\Windows\system32\DRIVERS\igdkmd32.sys 2010/11/14 16:33:55.0842 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 2010/11/14 16:33:55.0997 intelide (988981c840084f480ba9e3319cebde1b) C:\Windows\system32\drivers\intelide.sys 2010/11/14 16:33:56.0325 intelppm (ce44cc04262f28216dd4341e9e36a16f) C:\Windows\system32\DRIVERS\intelppm.sys 2010/11/14 16:33:56.0535 IpFilterDriver (880c6f86cc3f551b8fea2c11141268c0) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2010/11/14 16:33:57.0049 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys 2010/11/14 16:33:57.0135 IPNAT (10077c35845101548037df04fd1a420b) C:\Windows\system32\DRIVERS\ipnat.sys 2010/11/14 16:33:57.0263 IRENUM (a82f328f4792304184642d6d397bb1e3) C:\Windows\system32\drivers\irenum.sys 2010/11/14 16:33:57.0390 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys 2010/11/14 16:33:57.0451 iScsiPrt (4dca456d4d5723f8fa9c6760d240b0df) C:\Windows\system32\DRIVERS\msiscsi.sys 2010/11/14 16:33:57.0536 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 2010/11/14 16:33:57.0606 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 2010/11/14 16:33:57.0686 kbdclass (b076b2ab806b3f696dab21375389101c) C:\Windows\system32\DRIVERS\kbdclass.sys 2010/11/14 16:33:57.0796 kbdhid (ed61dbc6603f612b7338283edbacbc4b) C:\Windows\system32\DRIVERS\kbdhid.sys 2010/11/14 16:33:57.0980 KSecDD (0a829977b078dea11641fc2af87ceade) C:\Windows\system32\Drivers\ksecdd.sys 2010/11/14 16:33:58.0128 lltdio (fd015b4f95daa2b712f0e372a116fbad) C:\Windows\system32\DRIVERS\lltdio.sys 2010/11/14 16:33:58.0450 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys 2010/11/14 16:33:58.0528 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys 2010/11/14 16:33:58.0604 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys 2010/11/14 16:33:58.0700 luafv (42885bb44b6e065b8575a8dd6c430c52) C:\Windows\system32\drivers\luafv.sys 2010/11/14 16:33:58.0898 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys 2010/11/14 16:33:58.0989 Modem (21755967298a46fb6adfec9db6012211) C:\Windows\system32\drivers\modem.sys 2010/11/14 16:33:59.0107 monitor (7446e104a5fe5987ca9e4983fbac4f97) C:\Windows\system32\DRIVERS\monitor.sys 2010/11/14 16:33:59.0190 motmodem (fe80c18ba448ddd76b7bead9eb203d37) C:\Windows\system32\DRIVERS\motmodem.sys 2010/11/14 16:33:59.0261 mouclass (5fba13c1a1841b0885d316ed3589489d) C:\Windows\system32\DRIVERS\mouclass.sys 2010/11/14 16:33:59.0406 mouhid (b569b5c5d3bde545df3a6af512cccdba) C:\Windows\system32\DRIVERS\mouhid.sys 2010/11/14 16:33:59.0490 MountMgr (01f1e5a3e4877c931cbb31613fec16a6) C:\Windows\system32\drivers\mountmgr.sys 2010/11/14 16:33:59.0558 MpFilter (fbc56c853814eaa196e22edf596a4ebd) C:\Windows\system32\DRIVERS\MpFilter.sys 2010/11/14 16:33:59.0684 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys 2010/11/14 16:33:59.0798 mpsdrv (6e7a7f0c1193ee5648443fe2d4b789ec) C:\Windows\system32\drivers\mpsdrv.sys 2010/11/14 16:33:59.0878 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 2010/11/14 16:33:59.0966 MRxDAV (1d8828b98ee309d65e006f0829e280e5) C:\Windows\system32\drivers\mrxdav.sys 2010/11/14 16:34:00.0099 mrxsmb (8af705ce1bb907932157fab821170f27) C:\Windows\system32\DRIVERS\mrxsmb.sys 2010/11/14 16:34:00.0190 mrxsmb10 (47e13ab23371be3279eef22bbfa2c1be) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2010/11/14 16:34:00.0254 mrxsmb20 (90b3fc7bd6b3d7ee7635debba2187f66) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2010/11/14 16:34:00.0340 msahci (f0ec3a4e0693a34b148723b4da31668c) C:\Windows\system32\drivers\msahci.sys 2010/11/14 16:34:00.0452 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys 2010/11/14 16:34:00.0598 Msfs (729eafefd4e7417165f353a18dbe947d) C:\Windows\system32\drivers\Msfs.sys 2010/11/14 16:34:00.0685 msisadrv (5f454a16a5146cd91a176d70f0cfa3ec) C:\Windows\system32\drivers\msisadrv.sys 2010/11/14 16:34:00.0771 MSKSSRV (892cedefa7e0ffe7be8da651b651d047) C:\Windows\system32\drivers\MSKSSRV.sys 2010/11/14 16:34:00.0852 MSPCLOCK (ae2cb1da69b2676b4cee2a501af5871c) C:\Windows\system32\drivers\MSPCLOCK.sys 2010/11/14 16:34:00.0942 MSPQM (f910da84fa90c44a3addb7cd874463fd) C:\Windows\system32\drivers\MSPQM.sys 2010/11/14 16:34:01.0002 MsRPC (84571c0ae07647ba38d493f5f0015df7) C:\Windows\system32\drivers\MsRPC.sys 2010/11/14 16:34:01.0090 mssmbios (4385c80ede885e25492d408cad91bd6f) C:\Windows\system32\DRIVERS\mssmbios.sys 2010/11/14 16:34:01.0123 MSTEE (c826dd1373f38afd9ca46ec3c436a14e) C:\Windows\system32\drivers\MSTEE.sys 2010/11/14 16:34:01.0190 Mup (fa7aa70050cf5e2d15de00941e5665e5) C:\Windows\system32\Drivers\mup.sys 2010/11/14 16:34:01.0326 NativeWifiP (6da4a0fc7c0e83df0cb3cfd0a514c3bc) C:\Windows\system32\DRIVERS\nwifi.sys 2010/11/14 16:34:01.0490 NDIS (227c11e1e7cf6ef8afb2a238d209760c) C:\Windows\system32\drivers\ndis.sys 2010/11/14 16:34:01.0756 NdisTapi (81659cdcbd0f9a9e07e6878ad8c78d3f) C:\Windows\system32\DRIVERS\ndistapi.sys 2010/11/14 16:34:01.0842 Ndisuio (5de5ee546bf40838ebe0e01cb629df64) C:\Windows\system32\DRIVERS\ndisuio.sys 2010/11/14 16:34:01.0934 NdisWan (397402adcbb8946223a1950101f6cd94) C:\Windows\system32\DRIVERS\ndiswan.sys 2010/11/14 16:34:02.0065 NDProxy (1b24fa907af283199a81b3bb37e5e526) C:\Windows\system32\drivers\NDProxy.sys 2010/11/14 16:34:02.0169 NetBIOS (356dbb9f98e8dc1028dd3092fceeb877) C:\Windows\system32\DRIVERS\netbios.sys 2010/11/14 16:34:02.0297 netbt (e3a168912e7eefc3bd3b814720d68b41) C:\Windows\system32\DRIVERS\netbt.sys 2010/11/14 16:34:02.0583 NETw4v32 (6522dd40a5f67ced020bd81b856613fb) C:\Windows\system32\DRIVERS\NETw4v32.sys 2010/11/14 16:34:02.0754 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 2010/11/14 16:34:02.0888 Npfs (4f9832beb9fafd8ceb0e541f1323b26e) C:\Windows\system32\drivers\Npfs.sys 2010/11/14 16:34:02.0991 nsiproxy (b488dfec274de1fc9d653870ef2587be) C:\Windows\system32\drivers\nsiproxy.sys 2010/11/14 16:34:03.0138 Ntfs (37430aa7a66d7a63407adc2c0d05e9f6) C:\Windows\system32\drivers\Ntfs.sys 2010/11/14 16:34:03.0249 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 2010/11/14 16:34:03.0324 Null (ec5efb3c60f1b624648344a328bce596) C:\Windows\system32\drivers\Null.sys 2010/11/14 16:34:03.0412 nvraid (6f785db62a6d8f3fafd3e5695277e849) C:\Windows\system32\drivers\nvraid.sys 2010/11/14 16:34:03.0528 nvstor (4a5fcab82d9bf6af8a023a66802fe9e9) C:\Windows\system32\drivers\nvstor.sys 2010/11/14 16:34:03.0607 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys 2010/11/14 16:34:03.0832 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\DRIVERS\ohci1394.sys 2010/11/14 16:34:03.0944 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 2010/11/14 16:34:04.0027 partmgr (555a5b2c8022983bc7467bc925b222ee) C:\Windows\system32\drivers\partmgr.sys 2010/11/14 16:34:04.0081 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 2010/11/14 16:34:04.0175 PCASp50 (1961590aa191b6b7dcf18a6a693af7b8) C:\Windows\system32\Drivers\PCASp50.sys 2010/11/14 16:34:04.0364 pci (1085d75657807e0e8b32f9e19a1647c3) C:\Windows\system32\drivers\pci.sys 2010/11/14 16:34:04.0424 pciide (20b869152448f80ac49cf10264e91f5e) C:\Windows\system32\drivers\pciide.sys 2010/11/14 16:34:04.0510 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 2010/11/14 16:34:04.0756 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 2010/11/14 16:34:05.0062 PptpMiniport (6c359ac71d7b550a0d41f9db4563ce05) C:\Windows\system32\DRIVERS\raspptp.sys 2010/11/14 16:34:05.0132 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys 2010/11/14 16:34:05.0320 PSched (2c8bae55247c4e09352e870292e4d1ab) C:\Windows\system32\DRIVERS\pacer.sys 2010/11/14 16:34:05.0617 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys 2010/11/14 16:34:05.0753 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 2010/11/14 16:34:05.0871 QWAVEdrv (d2b3e2b7426dc23e185fbc73c8936c12) C:\Windows\system32\drivers\qwavedrv.sys 2010/11/14 16:34:05.0957 RasAcd (bd7b30f55b3649506dd8b3d38f571d2a) C:\Windows\system32\DRIVERS\rasacd.sys 2010/11/14 16:34:06.0114 Rasl2tp (88587dd843e2059848995b407b67f6cf) C:\Windows\system32\DRIVERS\rasl2tp.sys 2010/11/14 16:34:06.0244 RasPppoe (ccf4e9c6cbbac81437f88cb2ae0b6c96) C:\Windows\system32\DRIVERS\raspppoe.sys 2010/11/14 16:34:06.0342 rdbss (54129c5d9581bbec8bd1ebd3ba813f47) C:\Windows\system32\DRIVERS\rdbss.sys 2010/11/14 16:34:06.0532 RDPCDD (794585276b5d7fca9f3fc15543f9f0b9) C:\Windows\system32\DRIVERS\RDPCDD.sys 2010/11/14 16:34:06.0613 rdpdr (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys 2010/11/14 16:34:06.0777 RDPENCDD (980b56e2e273e19d3a9d72d5c420f008) C:\Windows\system32\drivers\rdpencdd.sys 2010/11/14 16:34:06.0932 RDPWD (8830e790a74a96605faba74f9665bb3c) C:\Windows\system32\drivers\RDPWD.sys 2010/11/14 16:34:07.0077 RFCOMM (7ec90c316177ba3f1bce92005264b447) C:\Windows\system32\DRIVERS\rfcomm.sys 2010/11/14 16:34:07.0159 rimmptsk (7a6648b61661b1421ffab762e391e33f) C:\Windows\system32\DRIVERS\rimmptsk.sys 2010/11/14 16:34:07.0267 rimsptsk (d0a35b7670aa3558eaab483f64446496) C:\Windows\system32\DRIVERS\rimsptsk.sys 2010/11/14 16:34:07.0361 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\Windows\system32\DRIVERS\RimSerial.sys 2010/11/14 16:34:07.0488 rismxdp (6c1f93c0760c9f79a1869d07233df39d) C:\Windows\system32\DRIVERS\rixdptsk.sys 2010/11/14 16:34:07.0572 ROOTMODEM (d49d61312b273de069584d48c81c8b1d) C:\Windows\system32\Drivers\RootMdm.sys 2010/11/14 16:34:07.0694 rspndr (97e939d2128fec5d5a3e6e79b290a2f4) C:\Windows\system32\DRIVERS\rspndr.sys 2010/11/14 16:34:07.0804 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 2010/11/14 16:34:08.0001 sdbus (7b3973cc28b8aa3e9e2e5d53e720e2c9) C:\Windows\system32\DRIVERS\sdbus.sys 2010/11/14 16:34:08.0133 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2010/11/14 16:34:08.0232 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 2010/11/14 16:34:08.0301 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 2010/11/14 16:34:08.0511 sermouse (450accd77ec5cea720c1cdb9e26b953b) C:\Windows\system32\drivers\sermouse.sys 2010/11/14 16:34:08.0679 sffdisk (51cf56aa8bcc241f134b420b8f850406) C:\Windows\system32\DRIVERS\sffdisk.sys 2010/11/14 16:34:08.0771 sffp_mmc (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys 2010/11/14 16:34:08.0875 sffp_sd (8b08cab1267b2c377883fc9e56981f90) C:\Windows\system32\DRIVERS\sffp_sd.sys 2010/11/14 16:34:08.0952 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 2010/11/14 16:34:09.0039 sisagp (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys 2010/11/14 16:34:09.0115 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys 2010/11/14 16:34:09.0200 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys 2010/11/14 16:34:09.0303 Smb (ac0d90738adb51a6fd12ff00874a2162) C:\Windows\system32\DRIVERS\smb.sys 2010/11/14 16:34:09.0453 spldr (426f9b029aa9162ceccf65369457d046) C:\Windows\system32\drivers\spldr.sys 2010/11/14 16:34:09.0548 srv (038579c35f7cad4a4bbf735dbf83277d) C:\Windows\system32\DRIVERS\srv.sys 2010/11/14 16:34:09.0666 srv2 (6971a757af8cb5e2cbcbb76cc530db6c) C:\Windows\system32\DRIVERS\srv2.sys 2010/11/14 16:34:09.0755 srvnet (9e1a4603b874eebce0298113951abefb) C:\Windows\system32\DRIVERS\srvnet.sys 2010/11/14 16:34:09.0887 StillCam (7a95b5deb594616f1693486b8161411e) C:\Windows\system32\DRIVERS\serscan.sys 2010/11/14 16:34:10.0003 swenum (1379bdb336f8158c176a465e30759f57) C:\Windows\system32\DRIVERS\swenum.sys 2010/11/14 16:34:10.0147 swmsflt (57bbaef27dc790160245b43eb6dcd576) C:\Windows\System32\drivers\swmsflt.sys 2010/11/14 16:34:10.0242 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 2010/11/14 16:34:10.0353 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 2010/11/14 16:34:10.0444 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 2010/11/14 16:34:10.0606 Tcpip (4a82fa8f0df67aa354580c3faaf8bde3) C:\Windows\system32\drivers\tcpip.sys 2010/11/14 16:34:10.0784 Tcpip6 (4a82fa8f0df67aa354580c3faaf8bde3) C:\Windows\system32\DRIVERS\tcpip.sys 2010/11/14 16:34:10.0903 tcpipreg (5ce0c4a7b12d0067dad527d72b68c726) C:\Windows\system32\drivers\tcpipreg.sys 2010/11/14 16:34:10.0960 TDPIPE (964248aef49c31fa6a93201a73ffaf50) C:\Windows\system32\drivers\tdpipe.sys 2010/11/14 16:34:11.0026 TDTCP (7d2c1ae1648a60fce4aa0f7982e419d3) C:\Windows\system32\drivers\tdtcp.sys 2010/11/14 16:34:11.0086 tdx (ab4fde8af4a0270a46a001c08cbce1c2) C:\Windows\system32\DRIVERS\tdx.sys 2010/11/14 16:34:11.0158 TermDD (2c549bd9dd091fbfaa0a2a48e82ec2fb) C:\Windows\system32\DRIVERS\termdd.sys 2010/11/14 16:34:11.0365 tssecsrv (29f0eca726f0d51f7e048bdb0b372f29) C:\Windows\system32\DRIVERS\tssecsrv.sys 2010/11/14 16:34:11.0458 tunmp (65e953bc0084d44498b51f59784d2a82) C:\Windows\system32\DRIVERS\tunmp.sys 2010/11/14 16:34:11.0522 tunnel (4a39bda5e0fd30bdf4884f9d33ae6105) C:\Windows\system32\DRIVERS\tunnel.sys 2010/11/14 16:34:11.0562 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys 2010/11/14 16:34:11.0688 udfs (6348da98707ceda8a0dfb05820e17732) C:\Windows\system32\DRIVERS\udfs.sys 2010/11/14 16:34:11.0822 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys 2010/11/14 16:34:11.0905 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys 2010/11/14 16:34:11.0983 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 2010/11/14 16:34:12.0084 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 2010/11/14 16:34:12.0246 umbus (3fb78f1d1dd86d87bececd9dffa24dd9) C:\Windows\system32\DRIVERS\umbus.sys 2010/11/14 16:34:12.0354 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\Windows\system32\Drivers\usbaapl.sys 2010/11/14 16:34:12.0476 usbaudio (f6bf998ae33e3fb6c7d27f0560f1173f) C:\Windows\system32\drivers\usbaudio.sys 2010/11/14 16:34:12.0554 usbccgp (b0ba9caffe9b0555ec0317f30cb79cd2) C:\Windows\system32\DRIVERS\usbccgp.sys 2010/11/14 16:34:12.0626 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 2010/11/14 16:34:12.0749 usbehci (c9fcd05b0a80ea08c2768e5a279b14de) C:\Windows\system32\DRIVERS\usbehci.sys 2010/11/14 16:34:12.0906 usbhub (5e44f7d957f7560da06bfe6b84b58a35) C:\Windows\system32\DRIVERS\usbhub.sys 2010/11/14 16:34:13.0011 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 2010/11/14 16:34:13.0072 usbprint (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\DRIVERS\usbprint.sys 2010/11/14 16:34:13.0218 usbscan (b1f95285c08ddfe00c0b955462637ec7) C:\Windows\system32\DRIVERS\usbscan.sys 2010/11/14 16:34:13.0338 USBSTOR (7887ce56934e7f104e98c975f47353c5) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2010/11/14 16:34:13.0451 usbuhci (d864735b0bfcb65440960a0b7cc1a38d) C:\Windows\system32\DRIVERS\usbuhci.sys 2010/11/14 16:34:13.0522 usbvideo (0a6b81f01bc86399482e27e6fda7b33b) C:\Windows\system32\Drivers\usbvideo.sys 2010/11/14 16:34:13.0624 usb_rndisx (db4721908daa0383ee82ffe430aebae1) C:\Windows\system32\DRIVERS\usb8023x.sys 2010/11/14 16:34:13.0768 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys 2010/11/14 16:34:13.0847 VgaSave (17a8f877314e4067f8c8172cc6d9101c) C:\Windows\System32\drivers\vga.sys 2010/11/14 16:34:13.0960 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys 2010/11/14 16:34:14.0055 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys 2010/11/14 16:34:14.0122 viaide (58c8d5ac5c3eef40e7e704a5ced7987d) C:\Windows\system32\drivers\viaide.sys 2010/11/14 16:34:14.0236 volmgr (103e84c95832d0ed93507997cc7b54e8) C:\Windows\system32\drivers\volmgr.sys 2010/11/14 16:34:14.0302 volmgrx (294da8d3f965f6a8db934a83c7b461ff) C:\Windows\system32\drivers\volmgrx.sys 2010/11/14 16:34:14.0422 volsnap (80dc0c9bcb579ed9815001a4d37cbfd5) C:\Windows\system32\drivers\volsnap.sys 2010/11/14 16:34:14.0515 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys 2010/11/14 16:34:14.0708 VX3000 (e26744e5dd71a16e80d4dd5a286b8423) C:\Windows\system32\DRIVERS\VX3000.sys 2010/11/14 16:34:14.0912 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 2010/11/14 16:34:14.0989 Wanarp (6798c1209a53b5a0ded8d437c45145ff) C:\Windows\system32\DRIVERS\wanarp.sys 2010/11/14 16:34:15.0061 Wanarpv6 (6798c1209a53b5a0ded8d437c45145ff) C:\Windows\system32\DRIVERS\wanarp.sys 2010/11/14 16:34:15.0174 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys 2010/11/14 16:34:15.0402 Wdf01000 (7b5f66e4a2219c7d9daf9e738480e534) C:\Windows\system32\drivers\Wdf01000.sys 2010/11/14 16:34:15.0582 winachsf (5c7bdcf5864db00323fe2d90fa26a8a2) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS 2010/11/14 16:34:15.0906 WINUSB (086d2e78eecd6195667282adc6ca109f) C:\Windows\system32\DRIVERS\WinUSB.SYS 2010/11/14 16:34:16.0011 WmiAcpi (17eac0d023a65fa9b02114cc2baacad5) C:\Windows\system32\DRIVERS\wmiacpi.sys 2010/11/14 16:34:16.0152 WpdUsb (2d27171b16a577ef14c1273668753485) C:\Windows\system32\DRIVERS\wpdusb.sys 2010/11/14 16:34:16.0262 ws2ifsl (84620aecdcfd2a7a14e6263927d8c0ed) C:\Windows\system32\drivers\ws2ifsl.sys 2010/11/14 16:34:16.0361 WSDPrintDevice (f01f25b4227ad8d717c21f25f62b43c8) C:\Windows\system32\DRIVERS\WSDPrint.sys 2010/11/14 16:34:16.0489 WUDFRd (a2aafcc8a204736296d937c7c545b53f) C:\Windows\system32\DRIVERS\WUDFRd.sys 2010/11/14 16:34:16.0697 ================================================================================ 2010/11/14 16:34:16.0697 Scan finished 2010/11/14 16:34:16.0697 ================================================================================ 2010/11/14 16:34:37.0797 ================================================================================ 2010/11/14 16:34:37.0797 Scan started 2010/11/14 16:34:37.0797 Mode: Manual; 2010/11/14 16:34:37.0797 ================================================================================ 2010/11/14 16:34:38.0288 ACPI (84fc6df81212d16be5c4f441682feccc) C:\Windows\system32\drivers\acpi.sys 2010/11/14 16:34:38.0377 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys 2010/11/14 16:34:38.0434 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys 2010/11/14 16:34:38.0529 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys 2010/11/14 16:34:38.0602 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys 2010/11/14 16:34:38.0770 AFD (5d24caf8efd924a875698ff28384db8b) C:\Windows\system32\drivers\afd.sys 2010/11/14 16:34:38.0895 agp440 (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys 2010/11/14 16:34:38.0967 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 2010/11/14 16:34:39.0031 aliide (3a99cb23a2d326fd532618705d6e3048) C:\Windows\system32\drivers\aliide.sys 2010/11/14 16:34:39.0083 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys 2010/11/14 16:34:39.0132 amdide (4333c133dbd71c7d7fe4fb1b83f9ee3e) C:\Windows\system32\drivers\amdide.sys 2010/11/14 16:34:39.0225 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys 2010/11/14 16:34:39.0267 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys 2010/11/14 16:34:39.0347 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys 2010/11/14 16:34:39.0394 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys 2010/11/14 16:34:39.0463 aswFsBlk (a0d86b8ac93ef95620420c7a24ac5344) C:\Windows\system32\drivers\aswFsBlk.sys 2010/11/14 16:34:39.0552 aswMonFlt (bd9119468c32b7ecd1e0544d3f286a73) C:\Windows\system32\drivers\aswMonFlt.sys 2010/11/14 16:34:39.0595 aswRdr (69823954bbd461a73d69774928c9737e) C:\Windows\system32\drivers\aswRdr.sys 2010/11/14 16:34:39.0672 aswSP (7ecc2776638b04553f9a85bd684c3abf) C:\Windows\system32\drivers\aswSP.sys 2010/11/14 16:34:39.0724 aswTdi (095ed820a926aa8189180b305e1bcfc9) C:\Windows\system32\drivers\aswTdi.sys 2010/11/14 16:34:39.0783 AsyncMac (e86cf7ce67d5de898f27ef884dc357d8) C:\Windows\system32\DRIVERS\asyncmac.sys 2010/11/14 16:34:39.0857 atapi (b35cfcef838382ab6490b321c87edf17) C:\Windows\system32\drivers\atapi.sys 2010/11/14 16:34:40.0051 bcm4sbxp (08015d34f6fdd0b355805bad978497c3) C:\Windows\system32\DRIVERS\bcm4sbxp.sys 2010/11/14 16:34:40.0111 Beep (ac3dd1708b22761ebd7cbe14dcc3b5d7) C:\Windows\system32\drivers\Beep.sys 2010/11/14 16:34:40.0230 bowser (913cd06fbe9105ce6077e90fd4418561) C:\Windows\system32\DRIVERS\bowser.sys 2010/11/14 16:34:40.0287 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 2010/11/14 16:34:40.0328 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 2010/11/14 16:34:40.0419 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 2010/11/14 16:34:40.0507 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 2010/11/14 16:34:40.0553 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 2010/11/14 16:34:40.0591 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 2010/11/14 16:34:40.0660 BthEnum (cf97c2d6a011ee9403b42191b5f95ba8) C:\Windows\system32\DRIVERS\BthEnum.sys 2010/11/14 16:34:40.0746 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\DRIVERS\bthmodem.sys 2010/11/14 16:34:40.0800 BthPan (b8c3d9ddf85fd197c3e5f849fef71144) C:\Windows\system32\DRIVERS\bthpan.sys 2010/11/14 16:34:40.0861 BTHPORT (b4ce8000aab30a9ab16cd0fb3db4d7cf) C:\Windows\system32\Drivers\BTHport.sys 2010/11/14 16:34:40.0927 BTHUSB (9a4ddc8544c1459aa2a118a8858dade3) C:\Windows\system32\Drivers\BTHUSB.sys 2010/11/14 16:34:41.0015 cdfs (6c3a437fc873c6f6a4fc620b6888cb86) C:\Windows\system32\DRIVERS\cdfs.sys 2010/11/14 16:34:41.0063 cdrom (8d1866e61af096ae8b582454f5e4d303) C:\Windows\system32\DRIVERS\cdrom.sys 2010/11/14 16:34:41.0140 circlass (da8e0afc7baa226c538ef53ac2f90897) C:\Windows\system32\drivers\circlass.sys 2010/11/14 16:34:41.0212 CLFS (1b84fd0937d3b99af9ba38ddff3daf54) C:\Windows\system32\CLFS.sys 2010/11/14 16:34:41.0312 CmBatt (ed97ad3df1b9005989eaf149bf06c821) C:\Windows\system32\DRIVERS\CmBatt.sys 2010/11/14 16:34:41.0368 cmdide (dfb94a6fc3a26972b0461ab5f1d8272b) C:\Windows\system32\drivers\cmdide.sys 2010/11/14 16:34:41.0413 Compbatt (722936afb75a7f509662b69b5632f48a) C:\Windows\system32\DRIVERS\compbatt.sys 2010/11/14 16:34:41.0479 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys 2010/11/14 16:34:41.0534 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys 2010/11/14 16:34:41.0660 DfsC (a7179de59ae269ab70345527894ccd7c) C:\Windows\system32\Drivers\dfsc.sys 2010/11/14 16:34:41.0734 disk (841af4c4d41d3e3b2f244e976b0f7963) C:\Windows\system32\drivers\disk.sys 2010/11/14 16:34:41.0862 drmkaud (ee472cd2c01f6f8e8aa1fa06ffef61b6) C:\Windows\system32\drivers\drmkaud.sys 2010/11/14 16:34:41.0948 DXGKrnl (334988883de69adb27e2cf9f9715bbdb) C:\Windows\System32\drivers\dxgkrnl.sys 2010/11/14 16:34:42.0054 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys 2010/11/14 16:34:42.0131 Ecache (0efc7531b936ee57fdb4e837664c509f) C:\Windows\system32\drivers\ecache.sys 2010/11/14 16:34:42.0240 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys 2010/11/14 16:34:42.0358 fastfat (84a317cb0b3954d3768cdcd018dbf670) C:\Windows\system32\drivers\fastfat.sys 2010/11/14 16:34:42.0503 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys 2010/11/14 16:34:42.0587 FileInfo (65773d6115c037ffd7ef8280ae85eb9d) C:\Windows\system32\drivers\fileinfo.sys 2010/11/14 16:34:42.0628 Filetrace (c226dd0de060745f3e042f58dcf78402) C:\Windows\system32\drivers\filetrace.sys 2010/11/14 16:34:42.0679 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys 2010/11/14 16:34:42.0759 FltMgr (a6a8da7ae4d53394ab22ac3ab6d3f5d3) C:\Windows\system32\drivers\fltmgr.sys 2010/11/14 16:34:42.0846 Fs_Rec (66a078591208baa210c7634b11eb392c) C:\Windows\system32\drivers\Fs_Rec.sys 2010/11/14 16:34:42.0891 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys 2010/11/14 16:34:43.0010 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 2010/11/14 16:34:43.0136 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys 2010/11/14 16:34:43.0211 HDAudBus (0db613a7e427b5663563677796fd5258) C:\Windows\system32\DRIVERS\HDAudBus.sys 2010/11/14 16:34:43.0265 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 2010/11/14 16:34:43.0343 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 2010/11/14 16:34:43.0405 HidUsb (3c64042b95e583b366ba4e5d2450235e) C:\Windows\system32\DRIVERS\hidusb.sys 2010/11/14 16:34:43.0505 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys 2010/11/14 16:34:43.0577 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS 2010/11/14 16:34:43.0676 HSF_DPV (ec36f1d542ed4252390d446bf6d4dfd0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS 2010/11/14 16:34:43.0823 HTTP (ea24fe637d974a8a31bc650f478e3533) C:\Windows\system32\drivers\HTTP.sys 2010/11/14 16:34:43.0906 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys 2010/11/14 16:34:43.0968 i8042prt (1c9ee072baa3abb460b91d7ee9152660) C:\Windows\system32\DRIVERS\i8042prt.sys 2010/11/14 16:34:44.0061 iaStor (fd7f9d74c2b35dbda400804a3f5ed5d8) C:\Windows\system32\drivers\iastor.sys 2010/11/14 16:34:44.0118 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys 2010/11/14 16:34:44.0281 igfx (9378d57e2b96c0a185d844770ad49948) C:\Windows\system32\DRIVERS\igdkmd32.sys 2010/11/14 16:34:44.0428 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 2010/11/14 16:34:44.0539 intelide (988981c840084f480ba9e3319cebde1b) C:\Windows\system32\drivers\intelide.sys 2010/11/14 16:34:44.0611 intelppm (ce44cc04262f28216dd4341e9e36a16f) C:\Windows\system32\DRIVERS\intelppm.sys 2010/11/14 16:34:44.0699 IpFilterDriver (880c6f86cc3f551b8fea2c11141268c0) C:\Windows\system32\DRIVERS\ipfltdrv.sys 2010/11/14 16:34:44.0814 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys 2010/11/14 16:34:44.0877 IPNAT (10077c35845101548037df04fd1a420b) C:\Windows\system32\DRIVERS\ipnat.sys 2010/11/14 16:34:44.0929 IRENUM (a82f328f4792304184642d6d397bb1e3) C:\Windows\system32\drivers\irenum.sys 2010/11/14 16:34:45.0002 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys 2010/11/14 16:34:45.0082 iScsiPrt (4dca456d4d5723f8fa9c6760d240b0df) C:\Windows\system32\DRIVERS\msiscsi.sys 2010/11/14 16:34:45.0133 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 2010/11/14 16:34:45.0180 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 2010/11/14 16:34:45.0236 kbdclass (b076b2ab806b3f696dab21375389101c) C:\Windows\system32\DRIVERS\kbdclass.sys 2010/11/14 16:34:45.0283 kbdhid (ed61dbc6603f612b7338283edbacbc4b) C:\Windows\system32\DRIVERS\kbdhid.sys 2010/11/14 16:34:45.0410 KSecDD (0a829977b078dea11641fc2af87ceade) C:\Windows\system32\Drivers\ksecdd.sys 2010/11/14 16:34:45.0535 lltdio (fd015b4f95daa2b712f0e372a116fbad) C:\Windows\system32\DRIVERS\lltdio.sys 2010/11/14 16:34:45.0637 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys 2010/11/14 16:34:45.0715 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys 2010/11/14 16:34:45.0757 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys 2010/11/14 16:34:45.0809 luafv (42885bb44b6e065b8575a8dd6c430c52) C:\Windows\system32\drivers\luafv.sys 2010/11/14 16:34:45.0940 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys 2010/11/14 16:34:45.0998 Modem (21755967298a46fb6adfec9db6012211) C:\Windows\system32\drivers\modem.sys 2010/11/14 16:34:46.0082 monitor (7446e104a5fe5987ca9e4983fbac4f97) C:\Windows\system32\DRIVERS\monitor.sys 2010/11/14 16:34:46.0133 motmodem (fe80c18ba448ddd76b7bead9eb203d37) C:\Windows\system32\DRIVERS\motmodem.sys 2010/11/14 16:34:46.0202 mouclass (5fba13c1a1841b0885d316ed3589489d) C:\Windows\system32\DRIVERS\mouclass.sys 2010/11/14 16:34:46.0259 mouhid (b569b5c5d3bde545df3a6af512cccdba) C:\Windows\system32\DRIVERS\mouhid.sys 2010/11/14 16:34:46.0354 MountMgr (01f1e5a3e4877c931cbb31613fec16a6) C:\Windows\system32\drivers\mountmgr.sys 2010/11/14 16:34:46.0423 MpFilter (fbc56c853814eaa196e22edf596a4ebd) C:\Windows\system32\DRIVERS\MpFilter.sys 2010/11/14 16:34:46.0471 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys 2010/11/14 16:34:46.0573 mpsdrv (6e7a7f0c1193ee5648443fe2d4b789ec) C:\Windows\system32\drivers\mpsdrv.sys 2010/11/14 16:34:46.0698 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 2010/11/14 16:34:46.0774 MRxDAV (1d8828b98ee309d65e006f0829e280e5) C:\Windows\system32\drivers\mrxdav.sys 2010/11/14 16:34:46.0897 mrxsmb (8af705ce1bb907932157fab821170f27) C:\Windows\system32\DRIVERS\mrxsmb.sys 2010/11/14 16:34:46.0943 mrxsmb10 (47e13ab23371be3279eef22bbfa2c1be) C:\Windows\system32\DRIVERS\mrxsmb10.sys 2010/11/14 16:34:47.0016 mrxsmb20 (90b3fc7bd6b3d7ee7635debba2187f66) C:\Windows\system32\DRIVERS\mrxsmb20.sys 2010/11/14 16:34:47.0093 msahci (f0ec3a4e0693a34b148723b4da31668c) C:\Windows\system32\drivers\msahci.sys 2010/11/14 16:34:47.0176 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys 2010/11/14 16:34:47.0263 Msfs (729eafefd4e7417165f353a18dbe947d) C:\Windows\system32\drivers\Msfs.sys 2010/11/14 16:34:47.0414 msisadrv (5f454a16a5146cd91a176d70f0cfa3ec) C:\Windows\system32\drivers\msisadrv.sys 2010/11/14 16:34:47.0480 MSKSSRV (892cedefa7e0ffe7be8da651b651d047) C:\Windows\system32\drivers\MSKSSRV.sys 2010/11/14 16:34:47.0561 MSPCLOCK (ae2cb1da69b2676b4cee2a501af5871c) C:\Windows\system32\drivers\MSPCLOCK.sys 2010/11/14 16:34:47.0606 MSPQM (f910da84fa90c44a3addb7cd874463fd) C:\Windows\system32\drivers\MSPQM.sys 2010/11/14 16:34:47.0699 MsRPC (84571c0ae07647ba38d493f5f0015df7) C:\Windows\system32\drivers\MsRPC.sys 2010/11/14 16:34:47.0754 mssmbios (4385c80ede885e25492d408cad91bd6f) C:\Windows\system32\DRIVERS\mssmbios.sys 2010/11/14 16:34:47.0827 MSTEE (c826dd1373f38afd9ca46ec3c436a14e) C:\Windows\system32\drivers\MSTEE.sys 2010/11/14 16:34:47.0910 Mup (fa7aa70050cf5e2d15de00941e5665e5) C:\Windows\system32\Drivers\mup.sys 2010/11/14 16:34:48.0024 NativeWifiP (6da4a0fc7c0e83df0cb3cfd0a514c3bc) C:\Windows\system32\DRIVERS\nwifi.sys 2010/11/14 16:34:48.0130 NDIS (227c11e1e7cf6ef8afb2a238d209760c) C:\Windows\system32\drivers\ndis.sys 2010/11/14 16:34:48.0204 NdisTapi (81659cdcbd0f9a9e07e6878ad8c78d3f) C:\Windows\system32\DRIVERS\ndistapi.sys 2010/11/14 16:34:48.0273 Ndisuio (5de5ee546bf40838ebe0e01cb629df64) C:\Windows\system32\DRIVERS\ndisuio.sys 2010/11/14 16:34:48.0366 NdisWan (397402adcbb8946223a1950101f6cd94) C:\Windows\system32\DRIVERS\ndiswan.sys 2010/11/14 16:34:48.0429 NDProxy (1b24fa907af283199a81b3bb37e5e526) C:\Windows\system32\drivers\NDProxy.sys 2010/11/14 16:34:48.0478 NetBIOS (356dbb9f98e8dc1028dd3092fceeb877) C:\Windows\system32\DRIVERS\netbios.sys 2010/11/14 16:34:48.0540 netbt (e3a168912e7eefc3bd3b814720d68b41) C:\Windows\system32\DRIVERS\netbt.sys 2010/11/14 16:34:48.0735 NETw4v32 (6522dd40a5f67ced020bd81b856613fb) C:\Windows\system32\DRIVERS\NETw4v32.sys 2010/11/14 16:34:48.0874 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 2010/11/14 16:34:48.0941 Npfs (4f9832beb9fafd8ceb0e541f1323b26e) C:\Windows\system32\drivers\Npfs.sys 2010/11/14 16:34:48.0990 nsiproxy (b488dfec274de1fc9d653870ef2587be) C:\Windows\system32\drivers\nsiproxy.sys 2010/11/14 16:34:49.0103 Ntfs (37430aa7a66d7a63407adc2c0d05e9f6) C:\Windows\system32\drivers\Ntfs.sys 2010/11/14 16:34:49.0213 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 2010/11/14 16:34:49.0255 Null (ec5efb3c60f1b624648344a328bce596) C:\Windows\system32\drivers\Null.sys 2010/11/14 16:34:49.0310 nvraid (6f785db62a6d8f3fafd3e5695277e849) C:\Windows\system32\drivers\nvraid.sys 2010/11/14 16:34:49.0360 nvstor (4a5fcab82d9bf6af8a023a66802fe9e9) C:\Windows\system32\drivers\nvstor.sys 2010/11/14 16:34:49.0427 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys 2010/11/14 16:34:49.0608 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\DRIVERS\ohci1394.sys 2010/11/14 16:34:49.0705 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 2010/11/14 16:34:49.0747 partmgr (555a5b2c8022983bc7467bc925b222ee) C:\Windows\system32\drivers\partmgr.sys 2010/11/14 16:34:49.0790 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 2010/11/14 16:34:49.0918 PCASp50 (1961590aa191b6b7dcf18a6a693af7b8) C:\Windows\system32\Drivers\PCASp50.sys 2010/11/14 16:34:49.0995 pci (1085d75657807e0e8b32f9e19a1647c3) C:\Windows\system32\drivers\pci.sys 2010/11/14 16:34:50.0066 pciide (20b869152448f80ac49cf10264e91f5e) C:\Windows\system32\drivers\pciide.sys 2010/11/14 16:34:50.0108 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 2010/11/14 16:34:50.0284 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 2010/11/14 16:34:50.0582 PptpMiniport (6c359ac71d7b550a0d41f9db4563ce05) C:\Windows\system32\DRIVERS\raspptp.sys 2010/11/14 16:34:50.0619 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys 2010/11/14 16:34:50.0751 PSched (2c8bae55247c4e09352e870292e4d1ab) C:\Windows\system32\DRIVERS\pacer.sys 2010/11/14 16:34:50.0826 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys 2010/11/14 16:34:50.0951 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 2010/11/14 16:34:51.0024 QWAVEdrv (d2b3e2b7426dc23e185fbc73c8936c12) C:\Windows\system32\drivers\qwavedrv.sys 2010/11/14 16:34:51.0165 RasAcd (bd7b30f55b3649506dd8b3d38f571d2a) C:\Windows\system32\DRIVERS\rasacd.sys 2010/11/14 16:34:51.0279 Rasl2tp (88587dd843e2059848995b407b67f6cf) C:\Windows\system32\DRIVERS\rasl2tp.sys 2010/11/14 16:34:51.0346 RasPppoe (ccf4e9c6cbbac81437f88cb2ae0b6c96) C:\Windows\system32\DRIVERS\raspppoe.sys 2010/11/14 16:34:51.0406 rdbss (54129c5d9581bbec8bd1ebd3ba813f47) C:\Windows\system32\DRIVERS\rdbss.sys 2010/11/14 16:34:51.0442 RDPCDD (794585276b5d7fca9f3fc15543f9f0b9) C:\Windows\system32\DRIVERS\RDPCDD.sys 2010/11/14 16:34:51.0520 rdpdr (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys 2010/11/14 16:34:51.0619 RDPENCDD (980b56e2e273e19d3a9d72d5c420f008) C:\Windows\system32\drivers\rdpencdd.sys 2010/11/14 16:34:51.0674 RDPWD (8830e790a74a96605faba74f9665bb3c) C:\Windows\system32\drivers\RDPWD.sys 2010/11/14 16:34:51.0765 RFCOMM (7ec90c316177ba3f1bce92005264b447) C:\Windows\system32\DRIVERS\rfcomm.sys 2010/11/14 16:34:51.0835 rimmptsk (7a6648b61661b1421ffab762e391e33f) C:\Windows\system32\DRIVERS\rimmptsk.sys 2010/11/14 16:34:51.0932 rimsptsk (d0a35b7670aa3558eaab483f64446496) C:\Windows\system32\DRIVERS\rimsptsk.sys 2010/11/14 16:34:52.0004 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\Windows\system32\DRIVERS\RimSerial.sys 2010/11/14 16:34:52.0052 rismxdp (6c1f93c0760c9f79a1869d07233df39d) C:\Windows\system32\DRIVERS\rixdptsk.sys 2010/11/14 16:34:52.0116 ROOTMODEM (d49d61312b273de069584d48c81c8b1d) C:\Windows\system32\Drivers\RootMdm.sys 2010/11/14 16:34:52.0225 rspndr (97e939d2128fec5d5a3e6e79b290a2f4) C:\Windows\system32\DRIVERS\rspndr.sys 2010/11/14 16:34:52.0291 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 2010/11/14 16:34:52.0433 sdbus (7b3973cc28b8aa3e9e2e5d53e720e2c9) C:\Windows\system32\DRIVERS\sdbus.sys 2010/11/14 16:34:52.0531 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 2010/11/14 16:34:52.0608 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 2010/11/14 16:34:52.0654 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 2010/11/14 16:34:52.0731 sermouse (450accd77ec5cea720c1cdb9e26b953b) C:\Windows\system32\drivers\sermouse.sys 2010/11/14 16:34:52.0959 sffdisk (51cf56aa8bcc241f134b420b8f850406) C:\Windows\system32\DRIVERS\sffdisk.sys 2010/11/14 16:34:53.0024 sffp_mmc (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys 2010/11/14 16:34:53.0084 sffp_sd (8b08cab1267b2c377883fc9e56981f90) C:\Windows\system32\DRIVERS\sffp_sd.sys 2010/11/14 16:34:53.0128 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 2010/11/14 16:34:53.0259 sisagp (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys 2010/11/14 16:34:53.0310 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys 2010/11/14 16:34:53.0365 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys 2010/11/14 16:34:53.0457 Smb (ac0d90738adb51a6fd12ff00874a2162) C:\Windows\system32\DRIVERS\smb.sys 2010/11/14 16:34:53.0562 spldr (426f9b029aa9162ceccf65369457d046) C:\Windows\system32\drivers\spldr.sys 2010/11/14 16:34:53.0690 srv (038579c35f7cad4a4bbf735dbf83277d) C:\Windows\system32\DRIVERS\srv.sys 2010/11/14 16:34:53.0765 srv2 (6971a757af8cb5e2cbcbb76cc530db6c) C:\Windows\system32\DRIVERS\srv2.sys 2010/11/14 16:34:53.0809 srvnet (9e1a4603b874eebce0298113951abefb) C:\Windows\system32\DRIVERS\srvnet.sys 2010/11/14 16:34:53.0907 StillCam (7a95b5deb594616f1693486b8161411e) C:\Windows\system32\DRIVERS\serscan.sys 2010/11/14 16:34:54.0045 swenum (1379bdb336f8158c176a465e30759f57) C:\Windows\system32\DRIVERS\swenum.sys 2010/11/14 16:34:54.0123 swmsflt (57bbaef27dc790160245b43eb6dcd576) C:\Windows\System32\drivers\swmsflt.sys 2010/11/14 16:34:54.0196 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 2010/11/14 16:34:54.0250 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 2010/11/14 16:34:54.0353 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 2010/11/14 16:34:54.0527 Tcpip (4a82fa8f0df67aa354580c3faaf8bde3) C:\Windows\system32\drivers\tcpip.sys 2010/11/14 16:34:54.0671 Tcpip6 (4a82fa8f0df67aa354580c3faaf8bde3) C:\Windows\system32\DRIVERS\tcpip.sys 2010/11/14 16:34:54.0778 tcpipreg (5ce0c4a7b12d0067dad527d72b68c726) C:\Windows\system32\drivers\tcpipreg.sys 2010/11/14 16:34:54.0847 TDPIPE (964248aef49c31fa6a93201a73ffaf50) C:\Windows\system32\drivers\tdpipe.sys 2010/11/14 16:34:54.0902 TDTCP (7d2c1ae1648a60fce4aa0f7982e419d3) C:\Windows\system32\drivers\tdtcp.sys 2010/11/14 16:34:54.0950 tdx (ab4fde8af4a0270a46a001c08cbce1c2) C:\Windows\system32\DRIVERS\tdx.sys 2010/11/14 16:34:55.0031 TermDD (2c549bd9dd091fbfaa0a2a48e82ec2fb) C:\Windows\system32\DRIVERS\termdd.sys 2010/11/14 16:34:55.0230 tssecsrv (29f0eca726f0d51f7e048bdb0b372f29) C:\Windows\system32\DRIVERS\tssecsrv.sys 2010/11/14 16:34:55.0300 tunmp (65e953bc0084d44498b51f59784d2a82) C:\Windows\system32\DRIVERS\tunmp.sys 2010/11/14 16:34:55.0347 tunnel (4a39bda5e0fd30bdf4884f9d33ae6105) C:\Windows\system32\DRIVERS\tunnel.sys 2010/11/14 16:34:55.0395 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys 2010/11/14 16:34:55.0498 udfs (6348da98707ceda8a0dfb05820e17732) C:\Windows\system32\DRIVERS\udfs.sys 2010/11/14 16:34:55.0620 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys 2010/11/14 16:34:55.0680 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys 2010/11/14 16:34:55.0725 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 2010/11/14 16:34:55.0793 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 2010/11/14 16:34:55.0910 umbus (3fb78f1d1dd86d87bececd9dffa24dd9) C:\Windows\system32\DRIVERS\umbus.sys 2010/11/14 16:34:56.0051 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\Windows\system32\Drivers\usbaapl.sys 2010/11/14 16:34:56.0119 usbaudio (f6bf998ae33e3fb6c7d27f0560f1173f) C:\Windows\system32\drivers\usbaudio.sys 2010/11/14 16:34:56.0163 usbccgp (b0ba9caffe9b0555ec0317f30cb79cd2) C:\Windows\system32\DRIVERS\usbccgp.sys 2010/11/14 16:34:56.0257 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 2010/11/14 16:34:56.0314 usbehci (c9fcd05b0a80ea08c2768e5a279b14de) C:\Windows\system32\DRIVERS\usbehci.sys 2010/11/14 16:34:56.0381 usbhub (5e44f7d957f7560da06bfe6b84b58a35) C:\Windows\system32\DRIVERS\usbhub.sys 2010/11/14 16:34:56.0433 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 2010/11/14 16:34:56.0481 usbprint (b51e52acf758be00ef3a58ea452fe360) C:\Windows\system32\DRIVERS\usbprint.sys 2010/11/14 16:34:56.0594 usbscan (b1f95285c08ddfe00c0b955462637ec7) C:\Windows\system32\DRIVERS\usbscan.sys 2010/11/14 16:34:56.0658 USBSTOR (7887ce56934e7f104e98c975f47353c5) C:\Windows\system32\DRIVERS\USBSTOR.SYS 2010/11/14 16:34:56.0716 usbuhci (d864735b0bfcb65440960a0b7cc1a38d) C:\Windows\system32\DRIVERS\usbuhci.sys 2010/11/14 16:34:56.0784 usbvideo (0a6b81f01bc86399482e27e6fda7b33b) C:\Windows\system32\Drivers\usbvideo.sys 2010/11/14 16:34:56.0922 usb_rndisx (db4721908daa0383ee82ffe430aebae1) C:\Windows\system32\DRIVERS\usb8023x.sys 2010/11/14 16:34:57.0033 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys 2010/11/14 16:34:57.0101 VgaSave (17a8f877314e4067f8c8172cc6d9101c) C:\Windows\System32\drivers\vga.sys 2010/11/14 16:34:57.0147 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys 2010/11/14 16:34:57.0242 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys 2010/11/14 16:34:57.0298 viaide (58c8d5ac5c3eef40e7e704a5ced7987d) C:\Windows\system32\drivers\viaide.sys 2010/11/14 16:34:57.0367 volmgr (103e84c95832d0ed93507997cc7b54e8) C:\Windows\system32\drivers\volmgr.sys 2010/11/14 16:34:57.0423 volmgrx (294da8d3f965f6a8db934a83c7b461ff) C:\Windows\system32\drivers\volmgrx.sys 2010/11/14 16:34:57.0542 volsnap (80dc0c9bcb579ed9815001a4d37cbfd5) C:\Windows\system32\drivers\volsnap.sys 2010/11/14 16:34:57.0612 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys 2010/11/14 16:34:57.0762 VX3000 (e26744e5dd71a16e80d4dd5a286b8423) C:\Windows\system32\DRIVERS\VX3000.sys 2010/11/14 16:34:57.0943 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 2010/11/14 16:34:58.0012 Wanarp (6798c1209a53b5a0ded8d437c45145ff) C:\Windows\system32\DRIVERS\wanarp.sys 2010/11/14 16:34:58.0051 Wanarpv6 (6798c1209a53b5a0ded8d437c45145ff) C:\Windows\system32\DRIVERS\wanarp.sys 2010/11/14 16:34:58.0216 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys 2010/11/14 16:34:58.0299 Wdf01000 (7b5f66e4a2219c7d9daf9e738480e534) C:\Windows\system32\drivers\Wdf01000.sys 2010/11/14 16:34:58.0468 winachsf (5c7bdcf5864db00323fe2d90fa26a8a2) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS 2010/11/14 16:34:58.0693 WINUSB (086d2e78eecd6195667282adc6ca109f) C:\Windows\system32\DRIVERS\WinUSB.SYS 2010/11/14 16:34:58.0777 WmiAcpi (17eac0d023a65fa9b02114cc2baacad5) C:\Windows\system32\DRIVERS\wmiacpi.sys 2010/11/14 16:34:58.0927 WpdUsb (2d27171b16a577ef14c1273668753485) C:\Windows\system32\DRIVERS\wpdusb.sys 2010/11/14 16:34:59.0026 ws2ifsl (84620aecdcfd2a7a14e6263927d8c0ed) C:\Windows\system32\drivers\ws2ifsl.sys 2010/11/14 16:34:59.0093 WSDPrintDevice (f01f25b4227ad8d717c21f25f62b43c8) C:\Windows\system32\DRIVERS\WSDPrint.sys 2010/11/14 16:34:59.0187 WUDFRd (a2aafcc8a204736296d937c7c545b53f) C:\Windows\system32\DRIVERS\WUDFRd.sys 2010/11/14 16:34:59.0381 ================================================================================ 2010/11/14 16:34:59.0381 Scan finished 2010/11/14 16:34:59.0381 ================================================================================ 2010/11/14 16:35:15.0423 Deinitialize success
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
ComboFix 10-11-14.02 - kristyn 11/15/2010 6:58.1.2 - x86
Microsoftยฎ Windows Vistaโ„ข Home Premium 6.0.6000.0.1252.1.1033.18.3573.2182 [GMT -6:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Microsoft Forefront Client Security *On-access scanning disabled* (Updated) {926A3D4F-E4E7-4F47-9902-4EDD55FFE1AF}
SP: avast! Antivirus *disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: Microsoft Forefront Client Security *disabled* (Updated) {926A3D4F-E4E7-4F47-9902-4EDD55FFE1AE}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2010-10-15 to 2010-11-15 )))))))))))))))))))))))))))))))
.

2010-11-15 13:04 . 2010-11-15 13:04 โ€”โ€”โ€“ dโ€”โ€“w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2010-11-15 13:04 . 2010-11-15 13:04 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\ryan\AppData\Local\temp
2010-11-15 13:04 . 2010-11-15 13:04 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Guest\AppData\Local\temp
2010-11-15 13:04 . 2010-11-15 13:04 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Default\AppData\Local\temp
2010-11-15 12:55 . 2010-11-15 12:55 โ€”โ€”โ€“ dโ€”โ€“w- C:\32788R22FWJFW
2010-11-15 12:41 . 2010-10-07 23:21 6146896 โ€”-a-w- c:\programdata\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Definition Updates\{71010F41-A76B-4E28-A484-14225130B3F2}\mpengine.dll
2010-11-14 22:12 . 2010-11-14 22:12 โ€”โ€”โ€“ dโ€”โ€“w- C:\_OTL
2010-11-13 20:56 . 2010-11-13 20:56 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Souptoys
2010-11-13 20:56 . 2010-11-13 20:56 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Souptoys
2010-11-13 20:40 . 2010-11-13 20:40 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Sight Words Sentence Builder
2010-11-13 20:00 . 2010-11-13 20:00 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\IObit
2010-11-13 20:00 . 2010-11-13 20:00 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\IObit
2010-11-13 15:04 . 2010-04-29 21:39 38224 โ€”-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-13 15:04 . 2010-04-29 21:39 20952 โ€”-a-w- c:\windows\system32\drivers\mbam.sys
2010-11-13 15:04 . 2010-11-13 15:05 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Malwarebytes' Anti-Malware
2010-11-12 12:09 . 2010-10-07 23:21 6146896 โ€”-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{46D1176C-F04D-4555-A012-9C9BFA08C3AC}\mpengine.dll
2010-11-12 03:18 . 2010-11-13 05:35 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Spybot - Search & Destroy
2010-11-12 03:18 . 2010-11-12 13:50 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\Spybot - Search & Destroy
2010-10-28 14:35 . 2010-10-28 16:09 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\kristyn
2010-10-27 18:50 . 2010-10-27 18:50 โ€”โ€”โ€“ d-shโ€“w- c:\programdata\SMGHNYE
2010-10-27 18:50 . 2010-11-07 16:31 โ€”โ€”โ€“ d-shโ€“w- c:\programdata\552284

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-19 20:51 . 2009-10-03 14:02 222080 โ€”โ€”w- c:\windows\system32\MpSigStub.exe
2010-10-07 23:21 . 2009-08-14 12:20 6146896 โ€”-a-w- c:\programdata\Microsoft\Microsoft Forefront\Client Security\Client\Antimalware\Definition Updates\Backup\mpengine.dll
2010-09-08 16:17 . 2010-09-08 16:17 94208 โ€”-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 16:17 . 2010-09-08 16:17 69632 โ€”-a-w- c:\windows\system32\QuickTime.qts
2010-09-07 15:12 . 2010-07-10 03:02 38848 โ€”-a-w- c:\windows\avastSS.scr
2010-09-07 15:11 . 2009-08-14 12:05 167592 โ€”-a-w- c:\windows\system32\aswBoot.exe
2010-09-07 14:52 . 2009-08-14 12:05 46672 โ€”-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-09-07 14:52 . 2009-08-14 12:05 165584 โ€”-a-w- c:\windows\system32\drivers\aswSP.sys
2010-09-07 14:47 . 2009-08-14 12:05 23376 โ€”-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-09-07 14:47 . 2009-08-14 12:05 50768 โ€”-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-09-07 14:47 . 2009-08-14 12:05 17744 โ€”-a-w- c:\windows\system32\drivers\aswFsBlk.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-11-08 1232896]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 2159104]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2010-01-24 160592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-25 136600]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]
"Microsoft Forefront Client Security Antimalware Service"="c:\program files\Microsoft Forefront\Client Security\Client\Antimalware\MSASCui.exe" [2010-01-19 1033600]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-09-08 47904]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2010-06-12 1280344]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FCSAM]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

R2 FCSAM;Microsoft Forefront Client Security Antimalware Service;c:\program files\Microsoft Forefront\Client Security\Client\Antimalware\MsMpEng.exe [2010-01-19 16880]
R2 gupdate1c98fc81ab179ca;Google Update Service (gupdate1c98fc81ab179ca);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 133104]
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2006-11-02 16896]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-09-07 50768]
S2 CFUACProxy_officeguardianv2;CFUACProxy_officeguardianv2;c:\programdata\OfficeGuardianV2\UACProxy.exe [2010-05-05 87944]
S2 FcsSas;Microsoft Forefront Client Security State Assessment Service;c:\program files\Microsoft Forefront\Client Security\Client\SSA\FcsSas.exe [2007-04-06 73120]
S2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\IS360srv.exe [2010-06-12 312152]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder

2010-11-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 23:49]

2010-11-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 23:49]

2010-11-15 c:\windows\Tasks\User_Feed_Synchronization-{A45ABC42-C9BC-4516-BD9D-9B67032392E0}.job
- c:\windows\system32\msfeedssync.exe [2010-03-30 04:54]

2010-11-14 c:\windows\Tasks\User_Feed_Synchronization-{AFD52921-7C36-4FC1-AAD4-F0EA44948EB2}.job
- c:\windows\system32\msfeedssync.exe [2010-03-30 04:54]

2010-11-15 c:\windows\Tasks\User_Feed_Synchronization-{EF181C9C-A97E-4F97-AF98-3186403252C7}.job
- c:\windows\system32\msfeedssync.exe [2010-03-30 04:54]
.
.
โ€”โ€”- Supplementary Scan โ€”โ€”-
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-15 07:04
Windows 6.0.6000 NTFS

scanning hidden processes โ€ฆ

scanning hidden autostart entries โ€ฆ

scanning hidden files โ€ฆ

scan completed successfully
hidden files: 0

**************************************************************************
.
โ€”โ€”โ€”โ€”โ€”โ€”โ€” LOCKED REGISTRY KEYS โ€”โ€”โ€”โ€”โ€”โ€”โ€”

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-11-15 07:06:46
ComboFix-quarantined-files.txt 2010-11-15 13:06

Pre-Run: 85,985,808,384 bytes free
Post-Run: 85,483,343,872 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=10 Sets=1,2,3,4,5,6,7,8,9,10
- - End Of File - - F38E78AB3C544BC8D0A5B2397FD96C86
did i do this correctly? i see: SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} however seems to be disabled

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI