This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

unknown infection

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Have a year old Gateway laptop running win 7 home. Has been freezing up for a while, now it is constantly filling up any and all data fields with dots-(password, search etc). It also causes pages to scroll to the end, making it totally useless. It does have MS Security essentials running, but apparently hasn't done a scan for some time. It also screams loudly at you when you boot up. Have tried System restore as well as Gateway repair on SafeMode to no effect. Have scanned with several programs that either showed nothing, or was unable to view or save the results
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)















  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Ran TDSKiller as instructed. No changes made to system. Here is the log; 20:00:55.0942 3504 TDSS rootkit removing tool [removed] Sep 26 2011 09:21:32 20:00:56.0473 3504 ============================================================ 20:00:56.0473 3504 Current date / time: 2011/09/26 20:00:56.0473 20:00:56.0473 3504 SystemInfo: 20:00:56.0473 3504 20:00:56.0473 3504 OS Version: 6.1.7600 ServicePack: 0.0 20:00:56.0473 3504 Product type: Workstation 20:00:56.0473 3504 ComputerName: KATHY 20:00:56.0473 3504 UserName: Kathy 20:00:56.0473 3504 Windows directory: C:\Windows 20:00:56.0473 3504 System windows directory: C:\Windows 20:00:56.0473 3504 Running under WOW64 20:00:56.0473 3504 Processor architecture: Intel x64 20:00:56.0473 3504 Number of processors: 2 20:00:56.0473 3504 Page size: 0x1000 20:00:56.0473 3504 Boot type: Normal boot 20:00:56.0473 3504 ============================================================ 20:00:58.0953 3504 Initialize success 20:01:03.0851 0796 ============================================================ 20:01:03.0851 0796 Scan started 20:01:03.0851 0796 Mode: Manual; 20:01:03.0851 0796 ============================================================ 20:01:04.0585 0796 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys 20:01:04.0585 0796 1394ohci - ok 20:01:04.0616 0796 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys 20:01:04.0631 0796 ACPI - ok 20:01:04.0756 0796 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys 20:01:04.0756 0796 AcpiPmi - ok 20:01:04.0881 0796 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys 20:01:04.0897 0796 adp94xx - ok 20:01:05.0021 0796 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys 20:01:05.0037 0796 adpahci - ok 20:01:05.0099 0796 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys 20:01:05.0099 0796 adpu320 - ok 20:01:05.0224 0796 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\Windows\system32\drivers\afd.sys 20:01:05.0240 0796 AFD - ok 20:01:05.0365 0796 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys 20:01:05.0365 0796 agp440 - ok 20:01:05.0521 0796 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys 20:01:05.0521 0796 aliide - ok 20:01:05.0567 0796 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys 20:01:05.0567 0796 amdide - ok 20:01:05.0661 0796 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys 20:01:05.0661 0796 AmdK8 - ok 20:01:05.0677 0796 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys 20:01:05.0677 0796 AmdPPM - ok 20:01:05.0739 0796 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys 20:01:05.0755 0796 amdsata - ok 20:01:05.0879 0796 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys 20:01:05.0895 0796 amdsbs - ok 20:01:06.0020 0796 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys 20:01:06.0020 0796 amdxata - ok 20:01:06.0098 0796 ApfiltrService (9815014f3e30357168da272088c6f12f) C:\Windows\system32\DRIVERS\Apfiltr.sys 20:01:06.0098 0796 ApfiltrService - ok 20:01:06.0223 0796 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys 20:01:06.0223 0796 AppID - ok 20:01:06.0363 0796 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys 20:01:06.0363 0796 arc - ok 20:01:06.0379 0796 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys 20:01:06.0394 0796 arcsas - ok 20:01:06.0425 0796 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 20:01:06.0425 0796 AsyncMac - ok 20:01:06.0519 0796 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys 20:01:06.0535 0796 atapi - ok 20:01:06.0628 0796 athr (0acc06fcf46f64ed4f11e57ee461c1f4) C:\Windows\system32\DRIVERS\athrx.sys 20:01:06.0675 0796 athr - ok 20:01:06.0831 0796 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys 20:01:06.0847 0796 b06bdrv - ok 20:01:06.0987 0796 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 20:01:06.0987 0796 b57nd60a - ok 20:01:07.0190 0796 BCM43XX (9e84a931dbee0292e38ed672f6293a99) C:\Windows\system32\DRIVERS\bcmwl664.sys 20:01:07.0221 0796 BCM43XX - ok 20:01:07.0299 0796 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 20:01:07.0299 0796 Beep - ok 20:01:07.0346 0796 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 20:01:07.0346 0796 blbdrive - ok 20:01:07.0393 0796 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys 20:01:07.0408 0796 bowser - ok 20:01:07.0439 0796 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys 20:01:07.0439 0796 BrFiltLo - ok 20:01:07.0471 0796 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys 20:01:07.0471 0796 BrFiltUp - ok 20:01:07.0533 0796 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 20:01:07.0533 0796 Brserid - ok 20:01:07.0549 0796 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 20:01:07.0549 0796 BrSerWdm - ok 20:01:07.0627 0796 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 20:01:07.0627 0796 BrUsbMdm - ok 20:01:07.0689 0796 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 20:01:07.0689 0796 BrUsbSer - ok 20:01:07.0767 0796 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys 20:01:07.0767 0796 BTHMODEM - ok 20:01:07.0923 0796 CAXHWAZL (d1787e11c6a0078ddeaf8cf3ee2ab293) C:\Windows\system32\DRIVERS\CAXHWAZL.sys 20:01:07.0923 0796 CAXHWAZL - ok 20:01:07.0970 0796 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 20:01:07.0970 0796 cdfs - ok 20:01:08.0063 0796 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys 20:01:08.0079 0796 cdrom - ok 20:01:08.0204 0796 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys 20:01:08.0204 0796 circlass - ok 20:01:08.0266 0796 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 20:01:08.0266 0796 CLFS - ok 20:01:08.0329 0796 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 20:01:08.0329 0796 CmBatt - ok 20:01:08.0360 0796 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys 20:01:08.0360 0796 cmdide - ok 20:01:08.0391 0796 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys 20:01:08.0391 0796 CNG - ok 20:01:08.0516 0796 CnxtHdAudService (20f3f8674d7dee5d90a352b775d5d5ba) C:\Windows\system32\drivers\CHDRT64.sys 20:01:08.0547 0796 CnxtHdAudService - ok 20:01:08.0687 0796 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys 20:01:08.0687 0796 Compbatt - ok 20:01:08.0812 0796 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys 20:01:08.0812 0796 CompositeBus - ok 20:01:08.0921 0796 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys 20:01:08.0921 0796 crcdisk - ok 20:01:09.0093 0796 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys 20:01:09.0109 0796 DfsC - ok 20:01:09.0155 0796 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 20:01:09.0155 0796 discache - ok 20:01:09.0202 0796 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys 20:01:09.0202 0796 Disk - ok 20:01:09.0233 0796 DKbFltr - ok 20:01:09.0343 0796 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 20:01:09.0343 0796 drmkaud - ok 20:01:09.0436 0796 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys 20:01:09.0452 0796 DXGKrnl - ok 20:01:09.0561 0796 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys 20:01:09.0670 0796 ebdrv - ok 20:01:09.0826 0796 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys 20:01:09.0842 0796 elxstor - ok 20:01:09.0889 0796 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys 20:01:09.0889 0796 ErrDev - ok 20:01:09.0951 0796 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 20:01:09.0951 0796 exfat - ok 20:01:09.0982 0796 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 20:01:09.0982 0796 fastfat - ok 20:01:10.0013 0796 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys 20:01:10.0029 0796 fdc - ok 20:01:10.0060 0796 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 20:01:10.0060 0796 FileInfo - ok 20:01:10.0076 0796 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 20:01:10.0076 0796 Filetrace - ok 20:01:10.0107 0796 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys 20:01:10.0107 0796 flpydisk - ok 20:01:10.0154 0796 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys 20:01:10.0154 0796 FltMgr - ok 20:01:10.0263 0796 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 20:01:10.0263 0796 FsDepends - ok 20:01:10.0279 0796 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 20:01:10.0279 0796 Fs_Rec - ok 20:01:10.0341 0796 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys 20:01:10.0341 0796 fvevol - ok 20:01:10.0388 0796 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys 20:01:10.0388 0796 gagp30kx - ok 20:01:10.0450 0796 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 20:01:10.0450 0796 hcw85cir - ok 20:01:10.0544 0796 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys 20:01:10.0559 0796 HDAudBus - ok 20:01:10.0575 0796 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys 20:01:10.0575 0796 HidBatt - ok 20:01:10.0606 0796 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys 20:01:10.0606 0796 HidBth - ok 20:01:10.0622 0796 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys 20:01:10.0637 0796 HidIr - ok 20:01:10.0762 0796 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys 20:01:10.0778 0796 HidUsb - ok 20:01:10.0825 0796 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys 20:01:10.0825 0796 HpSAMD - ok 20:01:10.0918 0796 HSF_DPV (26c5d00321937e49b6bc91029947d094) C:\Windows\system32\DRIVERS\CAX_DPV.sys 20:01:10.0949 0796 HSF_DPV - ok 20:01:11.0043 0796 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys 20:01:11.0059 0796 HTTP - ok 20:01:11.0105 0796 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys 20:01:11.0105 0796 hwpolicy - ok 20:01:11.0199 0796 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys 20:01:11.0199 0796 i8042prt - ok 20:01:11.0246 0796 iaStor (1d004cb1da6323b1f55caef7f94b61d9) C:\Windows\system32\DRIVERS\iaStor.sys 20:01:11.0246 0796 iaStor - ok 20:01:11.0293 0796 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys 20:01:11.0308 0796 iaStorV - ok 20:01:11.0573 0796 igfx (2d18c9e1f23970de32d78d3b1cdda0a7) C:\Windows\system32\DRIVERS\igdkmd64.sys 20:01:11.0729 0796 igfx - ok 20:01:11.0792 0796 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys 20:01:11.0792 0796 iirsp - ok 20:01:11.0854 0796 IntcHdmiAddService (88a20fa54c73ded4e8dac764e9130ae9) C:\Windows\system32\drivers\IntcHdmi.sys 20:01:11.0854 0796 IntcHdmiAddService - ok 20:01:11.0870 0796 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys 20:01:11.0870 0796 intelide - ok 20:01:11.0901 0796 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 20:01:11.0901 0796 intelppm - ok 20:01:12.0041 0796 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys 20:01:12.0041 0796 IpFilterDriver - ok 20:01:12.0057 0796 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys 20:01:12.0057 0796 IPMIDRV - ok 20:01:12.0088 0796 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 20:01:12.0104 0796 IPNAT - ok 20:01:12.0135 0796 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 20:01:12.0135 0796 IRENUM - ok 20:01:12.0166 0796 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys 20:01:12.0166 0796 isapnp - ok 20:01:12.0213 0796 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys 20:01:12.0213 0796 iScsiPrt - ok 20:01:12.0338 0796 k57nd60a (249ee2d26cb1530f3bede0ac8b9e3099) C:\Windows\system32\DRIVERS\k57nd60a.sys 20:01:12.0338 0796 k57nd60a - ok 20:01:12.0463 0796 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys 20:01:12.0463 0796 kbdclass - ok 20:01:12.0494 0796 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys 20:01:12.0509 0796 kbdhid - ok 20:01:12.0556 0796 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys 20:01:12.0556 0796 KSecDD - ok 20:01:12.0603 0796 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys 20:01:12.0603 0796 KSecPkg - ok 20:01:12.0634 0796 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 20:01:12.0634 0796 ksthunk - ok 20:01:12.0681 0796 L1E (2ac603c3188c704cfce353659aa7ad71) C:\Windows\system32\DRIVERS\L1E62x64.sys 20:01:12.0697 0796 L1E - ok 20:01:12.0743 0796 LHidFilt (b6552d382ff070b4ed34cbd6737277c0) C:\Windows\system32\DRIVERS\LHidFilt.Sys 20:01:12.0743 0796 LHidFilt - ok 20:01:12.0821 0796 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 20:01:12.0821 0796 lltdio - ok 20:01:12.0899 0796 LMouFilt (73c1f563ab73d459dffe682d66476558) C:\Windows\system32\DRIVERS\LMouFilt.Sys 20:01:12.0899 0796 LMouFilt - ok 20:01:13.0040 0796 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys 20:01:13.0040 0796 LSI_FC - ok 20:01:13.0087 0796 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys 20:01:13.0087 0796 LSI_SAS - ok 20:01:13.0165 0796 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys 20:01:13.0180 0796 LSI_SAS2 - ok 20:01:13.0243 0796 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys 20:01:13.0243 0796 LSI_SCSI - ok 20:01:13.0289 0796 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 20:01:13.0289 0796 luafv - ok 20:01:13.0336 0796 mdmxsdk (e4f44ec214b3e381e1fc844a02926666) C:\Windows\system32\DRIVERS\mdmxsdk.sys 20:01:13.0336 0796 mdmxsdk - ok 20:01:13.0383 0796 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys 20:01:13.0383 0796 megasas - ok 20:01:13.0414 0796 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys 20:01:13.0430 0796 MegaSR - ok 20:01:13.0445 0796 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 20:01:13.0461 0796 Modem - ok 20:01:13.0477 0796 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 20:01:13.0477 0796 monitor - ok 20:01:13.0586 0796 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys 20:01:13.0586 0796 mouclass - ok 20:01:13.0617 0796 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 20:01:13.0633 0796 mouhid - ok 20:01:13.0648 0796 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys 20:01:13.0648 0796 mountmgr - ok 20:01:13.0695 0796 MpFilter (c177a7ebf5e8a0b596f618870516cab8) C:\Windows\system32\DRIVERS\MpFilter.sys 20:01:13.0695 0796 MpFilter - ok 20:01:13.0726 0796 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys 20:01:13.0726 0796 mpio - ok 20:01:13.0757 0796 MpNWMon (8fbf6b31fe8af1833d93c5913d5b4d55) C:\Windows\system32\DRIVERS\MpNWMon.sys 20:01:13.0757 0796 MpNWMon - ok 20:01:13.0804 0796 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 20:01:13.0820 0796 mpsdrv - ok 20:01:13.0851 0796 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys 20:01:13.0851 0796 MRxDAV - ok 20:01:13.0882 0796 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys 20:01:13.0882 0796 mrxsmb - ok 20:01:13.0929 0796 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys 20:01:13.0929 0796 mrxsmb10 - ok 20:01:13.0976 0796 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys 20:01:13.0976 0796 mrxsmb20 - ok 20:01:14.0007 0796 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys 20:01:14.0038 0796 msahci - ok 20:01:14.0069 0796 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys 20:01:14.0085 0796 msdsm - ok 20:01:14.0116 0796 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 20:01:14.0116 0796 Msfs - ok 20:01:14.0132 0796 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 20:01:14.0147 0796 mshidkmdf - ok 20:01:14.0163 0796 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys 20:01:14.0163 0796 msisadrv - ok 20:01:14.0272 0796 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 20:01:14.0272 0796 MSKSSRV - ok 20:01:14.0288 0796 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 20:01:14.0288 0796 MSPCLOCK - ok 20:01:14.0350 0796 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 20:01:14.0350 0796 MSPQM - ok 20:01:14.0381 0796 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys 20:01:14.0381 0796 MsRPC - ok 20:01:14.0413 0796 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys 20:01:14.0413 0796 mssmbios - ok 20:01:14.0444 0796 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 20:01:14.0444 0796 MSTEE - ok 20:01:14.0475 0796 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys 20:01:14.0475 0796 MTConfig - ok 20:01:14.0506 0796 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 20:01:14.0522 0796 Mup - ok 20:01:14.0631 0796 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 20:01:14.0647 0796 NativeWifiP - ok 20:01:14.0725 0796 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys 20:01:14.0756 0796 NDIS - ok 20:01:14.0881 0796 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 20:01:14.0881 0796 NdisCap - ok 20:01:14.0912 0796 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 20:01:14.0912 0796 NdisTapi - ok 20:01:14.0943 0796 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys 20:01:14.0943 0796 Ndisuio - ok 20:01:14.0974 0796 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys 20:01:14.0974 0796 NdisWan - ok 20:01:15.0005 0796 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys 20:01:15.0021 0796 NDProxy - ok 20:01:15.0052 0796 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 20:01:15.0068 0796 NetBIOS - ok 20:01:15.0099 0796 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys 20:01:15.0115 0796 NetBT - ok 20:01:15.0505 0796 netw5v64 (64428dfdaf6e88366cb51f45a79c5f69) C:\Windows\system32\DRIVERS\netw5v64.sys 20:01:15.0614 0796 netw5v64 - ok 20:01:15.0661 0796 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys 20:01:15.0661 0796 nfrd960 - ok 20:01:15.0692 0796 NisDrv (5f7d72cbcdd025af1f38fdeee5646968) C:\Windows\system32\DRIVERS\NisDrvWFP.sys 20:01:15.0707 0796 NisDrv - ok 20:01:15.0739 0796 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 20:01:15.0739 0796 Npfs - ok 20:01:15.0785 0796 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 20:01:15.0785 0796 nsiproxy - ok 20:01:15.0863 0796 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys 20:01:15.0910 0796 Ntfs - ok 20:01:15.0988 0796 NTIDrvr (64ddd0dee976302f4bd93e5efcc2f013) C:\Windows\system32\drivers\NTIDrvr.sys 20:01:16.0004 0796 NTIDrvr - ok 20:01:16.0035 0796 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 20:01:16.0051 0796 Null - ok 20:01:16.0097 0796 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys 20:01:16.0097 0796 nvraid - ok 20:01:16.0144 0796 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys 20:01:16.0144 0796 nvstor - ok 20:01:16.0191 0796 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys 20:01:16.0191 0796 nv_agp - ok 20:01:16.0222 0796 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys 20:01:16.0222 0796 ohci1394 - ok 20:01:16.0269 0796 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys 20:01:16.0269 0796 Parport - ok 20:01:16.0300 0796 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys 20:01:16.0300 0796 partmgr - ok 20:01:16.0394 0796 pavboot (8a0f8a9580d9f2fc512a35d5709088a9) C:\Windows\system32\drivers\pavboot64.sys 20:01:16.0409 0796 pavboot - ok 20:01:16.0456 0796 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys 20:01:16.0472 0796 pci - ok 20:01:16.0519 0796 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys 20:01:16.0519 0796 pciide - ok 20:01:16.0550 0796 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys 20:01:16.0550 0796 pcmcia - ok 20:01:16.0581 0796 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 20:01:16.0581 0796 pcw - ok 20:01:16.0612 0796 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 20:01:16.0643 0796 PEAUTH - ok 20:01:16.0815 0796 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys 20:01:16.0815 0796 PptpMiniport - ok 20:01:16.0846 0796 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys 20:01:16.0846 0796 Processor - ok 20:01:16.0893 0796 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys 20:01:16.0909 0796 Psched - ok 20:01:16.0940 0796 pwdrvio (9e97e62098fa1238d189181aab13c402) C:\Windows\system32\pwdrvio.sys 20:01:16.0955 0796 pwdrvio - ok 20:01:16.0987 0796 pwdspio (1a8011b9bd9b5cb53783e7f91109b946) C:\Windows\system32\pwdspio.sys 20:01:17.0002 0796 pwdspio - ok 20:01:17.0236 0796 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys 20:01:17.0283 0796 ql2300 - ok 20:01:17.0642 0796 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys 20:01:17.0657 0796 ql40xx - ok 20:01:18.0250 0796 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 20:01:18.0250 0796 QWAVEdrv - ok 20:01:18.0406 0796 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 20:01:18.0406 0796 RasAcd - ok 20:01:18.0469 0796 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 20:01:18.0469 0796 RasAgileVpn - ok 20:01:18.0500 0796 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys 20:01:18.0500 0796 Rasl2tp - ok 20:01:18.0531 0796 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 20:01:18.0531 0796 RasPppoe - ok 20:01:18.0562 0796 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 20:01:18.0562 0796 RasSstp - ok 20:01:18.0593 0796 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys 20:01:18.0593 0796 rdbss - ok 20:01:18.0625 0796 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys 20:01:18.0625 0796 rdpbus - ok 20:01:18.0656 0796 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 20:01:18.0656 0796 RDPCDD - ok 20:01:18.0687 0796 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 20:01:18.0687 0796 RDPENCDD - ok 20:01:18.0718 0796 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 20:01:18.0718 0796 RDPREFMP - ok 20:01:18.0749 0796 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys 20:01:18.0749 0796 RDPWD - ok 20:01:18.0827 0796 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys 20:01:18.0843 0796 rdyboost - ok 20:01:18.0874 0796 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 20:01:18.0890 0796 rspndr - ok 20:01:18.0952 0796 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys 20:01:18.0952 0796 sbp2port - ok 20:01:18.0999 0796 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys 20:01:18.0999 0796 scfilter - ok 20:01:19.0139 0796 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 20:01:19.0155 0796 secdrv - ok 20:01:19.0249 0796 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys 20:01:19.0249 0796 Serenum - ok 20:01:19.0327 0796 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys 20:01:19.0327 0796 Serial - ok 20:01:19.0358 0796 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys 20:01:19.0358 0796 sermouse - ok 20:01:19.0389 0796 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys 20:01:19.0389 0796 sffdisk - ok 20:01:19.0405 0796 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys 20:01:19.0405 0796 sffp_mmc - ok 20:01:19.0436 0796 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys 20:01:19.0436 0796 sffp_sd - ok 20:01:19.0451 0796 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys 20:01:19.0451 0796 sfloppy - ok 20:01:19.0467 0796 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys 20:01:19.0483 0796 SiSRaid2 - ok 20:01:19.0498 0796 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys 20:01:19.0498 0796 SiSRaid4 - ok 20:01:19.0529 0796 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 20:01:19.0545 0796 Smb - ok 20:01:19.0576 0796 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 20:01:19.0576 0796 spldr - ok 20:01:19.0639 0796 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys 20:01:19.0639 0796 srv - ok 20:01:19.0670 0796 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys 20:01:19.0685 0796 srv2 - ok 20:01:19.0732 0796 SrvHsfHDA (0c4540311e11664b245a263e1154cef8) C:\Windows\system32\DRIVERS\VSTAZL6.SYS 20:01:19.0748 0796 SrvHsfHDA - ok 20:01:19.0810 0796 SrvHsfV92 (02071d207a9858fbe3a48cbfd59c4a04) C:\Windows\system32\DRIVERS\VSTDPV6.SYS 20:01:19.0857 0796 SrvHsfV92 - ok 20:01:19.0888 0796 SrvHsfWinac (18e40c245dbfaf36fd0134a7ef2df396) C:\Windows\system32\DRIVERS\VSTCNXT6.SYS 20:01:19.0919 0796 SrvHsfWinac - ok 20:01:20.0013 0796 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys 20:01:20.0013 0796 srvnet - ok 20:01:20.0091 0796 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys 20:01:20.0091 0796 stexstor - ok 20:01:20.0138 0796 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys 20:01:20.0138 0796 swenum - ok 20:01:20.0325 0796 Tcpip (b9d87c7707f058ac652a398cd28de14b) C:\Windows\system32\drivers\tcpip.sys 20:01:20.0403 0796 Tcpip - ok 20:01:20.0497 0796 TCPIP6 (b9d87c7707f058ac652a398cd28de14b) C:\Windows\system32\DRIVERS\tcpip.sys 20:01:20.0512 0796 TCPIP6 - ok 20:01:20.0590 0796 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys 20:01:20.0590 0796 tcpipreg - ok 20:01:20.0621 0796 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 20:01:20.0621 0796 TDPIPE - ok 20:01:20.0637 0796 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys 20:01:20.0637 0796 TDTCP - ok 20:01:20.0668 0796 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys 20:01:20.0668 0796 tdx - ok 20:01:20.0684 0796 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys 20:01:20.0684 0796 TermDD - ok 20:01:20.0731 0796 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys 20:01:20.0746 0796 tssecsrv - ok 20:01:20.0824 0796 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys 20:01:20.0824 0796 tunnel - ok 20:01:20.0871 0796 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys 20:01:20.0871 0796 uagp35 - ok 20:01:20.0933 0796 UBHelper (2e22c1fd397a5a9ffef55e9d1fc96c00) C:\Windows\system32\drivers\UBHelper.sys 20:01:20.0949 0796 UBHelper - ok 20:01:20.0980 0796 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys 20:01:20.0980 0796 udfs - ok 20:01:21.0027 0796 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys 20:01:21.0027 0796 uliagpkx - ok 20:01:21.0058 0796 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys 20:01:21.0074 0796 umbus - ok 20:01:21.0089 0796 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys 20:01:21.0089 0796 UmPass - ok 20:01:21.0136 0796 usbccgp (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys 20:01:21.0152 0796 usbccgp - ok 20:01:21.0183 0796 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys 20:01:21.0183 0796 usbcir - ok 20:01:21.0230 0796 usbehci (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys 20:01:21.0230 0796 usbehci - ok 20:01:21.0323 0796 usbhub (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys 20:01:21.0323 0796 usbhub - ok 20:01:21.0401 0796 usbohci (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys 20:01:21.0401 0796 usbohci - ok 20:01:21.0464 0796 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 20:01:21.0479 0796 usbprint - ok 20:01:21.0526 0796 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS 20:01:21.0526 0796 USBSTOR - ok 20:01:21.0573 0796 usbuhci (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\DRIVERS\usbuhci.sys 20:01:21.0573 0796 usbuhci - ok 20:01:21.0698 0796 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\System32\Drivers\usbvideo.sys 20:01:21.0698 0796 usbvideo - ok 20:01:21.0776 0796 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys 20:01:21.0776 0796 vdrvroot - ok 20:01:21.0823 0796 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 20:01:21.0823 0796 vga - ok 20:01:21.0869 0796 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 20:01:21.0869 0796 VgaSave - ok 20:01:21.0916 0796 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys 20:01:21.0916 0796 vhdmp - ok 20:01:21.0947 0796 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys 20:01:21.0947 0796 viaide - ok 20:01:21.0979 0796 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys 20:01:21.0979 0796 volmgr - ok 20:01:22.0010 0796 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys 20:01:22.0010 0796 volmgrx - ok 20:01:22.0041 0796 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys 20:01:22.0041 0796 volsnap - ok 20:01:22.0072 0796 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys 20:01:22.0088 0796 vsmraid - ok 20:01:22.0119 0796 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys 20:01:22.0119 0796 vwifibus - ok 20:01:22.0166 0796 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys 20:01:22.0181 0796 vwififlt - ok 20:01:22.0213 0796 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys 20:01:22.0228 0796 vwifimp - ok 20:01:22.0259 0796 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys 20:01:22.0259 0796 WacomPen - ok 20:01:22.0306 0796 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 20:01:22.0306 0796 WANARP - ok 20:01:22.0322 0796 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 20:01:22.0322 0796 Wanarpv6 - ok 20:01:22.0400 0796 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys 20:01:22.0400 0796 Wd - ok 20:01:22.0447 0796 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 20:01:22.0447 0796 Wdf01000 - ok 20:01:22.0509 0796 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 20:01:22.0509 0796 WfpLwf - ok 20:01:22.0540 0796 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 20:01:22.0540 0796 WIMMount - ok 20:01:22.0587 0796 winachsf (a6ea7a3fc4b00f48535b506db1e86efd) C:\Windows\system32\DRIVERS\CAX_CNXT.sys 20:01:22.0618 0796 winachsf - ok 20:01:22.0774 0796 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys 20:01:22.0790 0796 WmiAcpi - ok 20:01:22.0837 0796 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 20:01:22.0837 0796 ws2ifsl - ok 20:01:22.0883 0796 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys 20:01:22.0883 0796 WudfPf - ok 20:01:22.0946 0796 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys 20:01:22.0961 0796 WUDFRd - ok 20:01:23.0008 0796 XAudio (e8f3fa126a06f8e7088f63757112a186) C:\Windows\system32\DRIVERS\XAudio64.sys 20:01:23.0008 0796 XAudio - ok 20:01:23.0055 0796 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 20:01:23.0071 0796 \Device\Harddisk0\DR0 - ok 20:01:23.0071 0796 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1 20:01:23.0788 0796 \Device\Harddisk1\DR1 - ok 20:01:23.0866 0796 Boot (0x1200) (494b3add681ab709b71d1bdbc8375bad) \Device\Harddisk0\DR0\Partition0 20:01:23.0866 0796 \Device\Harddisk0\DR0\Partition0 - ok 20:01:23.0866 0796 Boot (0x1200) (e5aef13337fc12b9ead53129c6c98b55) \Device\Harddisk0\DR0\Partition1 20:01:23.0882 0796 \Device\Harddisk0\DR0\Partition1 - ok 20:01:23.0897 0796 Boot (0x1200) (78004db6ffbafc6939c7fecf185aa4de) \Device\Harddisk0\DR0\Partition2 20:01:23.0897 0796 \Device\Harddisk0\DR0\Partition2 - ok 20:01:23.0913 0796 Boot (0x1200) (fca94c5f84c4686e23725d26c7b33ad0) \Device\Harddisk1\DR1\Partition0 20:01:23.0913 0796 \Device\Harddisk1\DR1\Partition0 - ok 20:01:23.0913 0796 ============================================================ 20:01:23.0913 0796 Scan finished 20:01:23.0913 0796 ============================================================ 20:01:23.0944 3736 Detected object count: 0 20:01:23.0944 3736 Actual detected object count: 0 20:02:17.0577 2972 ============================================================ 20:02:17.0577 2972 Scan started 20:02:17.0577 2972 Mode: Manual; 20:02:17.0577 2972 ============================================================ 20:02:17.0905 2972 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys 20:02:17.0905 2972 1394ohci - ok 20:02:17.0952 2972 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys 20:02:17.0952 2972 ACPI - ok 20:02:17.0967 2972 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys 20:02:17.0967 2972 AcpiPmi - ok 20:02:18.0014 2972 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys 20:02:18.0014 2972 adp94xx - ok 20:02:18.0045 2972 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys 20:02:18.0045 2972 adpahci - ok 20:02:18.0076 2972 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys 20:02:18.0076 2972 adpu320 - ok 20:02:18.0139 2972 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\Windows\system32\drivers\afd.sys 20:02:18.0139 2972 AFD - ok 20:02:18.0248 2972 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys 20:02:18.0264 2972 agp440 - ok 20:02:18.0279 2972 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys 20:02:18.0279 2972 aliide - ok 20:02:18.0357 2972 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys 20:02:18.0357 2972 amdide - ok 20:02:18.0404 2972 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys 20:02:18.0420 2972 AmdK8 - ok 20:02:18.0435 2972 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys 20:02:18.0435 2972 AmdPPM - ok 20:02:18.0482 2972 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys 20:02:18.0482 2972 amdsata - ok 20:02:18.0513 2972 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys 20:02:18.0513 2972 amdsbs - ok 20:02:18.0622 2972 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys 20:02:18.0622 2972 amdxata - ok 20:02:18.0669 2972 ApfiltrService (9815014f3e30357168da272088c6f12f) C:\Windows\system32\DRIVERS\Apfiltr.sys 20:02:18.0669 2972 ApfiltrService - ok 20:02:18.0778 2972 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys 20:02:18.0778 2972 AppID - ok 20:02:18.0810 2972 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys 20:02:18.0810 2972 arc - ok 20:02:18.0919 2972 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys 20:02:18.0919 2972 arcsas - ok 20:02:18.0934 2972 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 20:02:18.0934 2972 AsyncMac - ok 20:02:18.0981 2972 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys 20:02:18.0981 2972 atapi - ok 20:02:19.0059 2972 athr (0acc06fcf46f64ed4f11e57ee461c1f4) C:\Windows\system32\DRIVERS\athrx.sys 20:02:19.0075 2972 athr - ok 20:02:19.0200 2972 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys 20:02:19.0200 2972 b06bdrv - ok 20:02:19.0231 2972 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 20:02:19.0231 2972 b57nd60a - ok 20:02:19.0387 2972 BCM43XX (9e84a931dbee0292e38ed672f6293a99) C:\Windows\system32\DRIVERS\bcmwl664.sys 20:02:19.0402 2972 BCM43XX - ok 20:02:19.0449 2972 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 20:02:19.0449 2972 Beep - ok 20:02:19.0465 2972 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 20:02:19.0480 2972 blbdrive - ok 20:02:19.0512 2972 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys 20:02:19.0512 2972 bowser - ok 20:02:19.0605 2972 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys 20:02:19.0605 2972 BrFiltLo - ok 20:02:19.0621 2972 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys 20:02:19.0621 2972 BrFiltUp - ok 20:02:19.0652 2972 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 20:02:19.0652 2972 Brserid - ok 20:02:19.0668 2972 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 20:02:19.0668 2972 BrSerWdm - ok 20:02:19.0683 2972 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 20:02:19.0683 2972 BrUsbMdm - ok 20:02:19.0699 2972 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 20:02:19.0699 2972 BrUsbSer - ok 20:02:19.0714 2972 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys 20:02:19.0714 2972 BTHMODEM - ok 20:02:19.0839 2972 CAXHWAZL (d1787e11c6a0078ddeaf8cf3ee2ab293) C:\Windows\system32\DRIVERS\CAXHWAZL.sys 20:02:19.0839 2972 CAXHWAZL - ok 20:02:19.0886 2972 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 20:02:19.0886 2972 cdfs - ok 20:02:19.0980 2972 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys 20:02:19.0980 2972 cdrom - ok 20:02:20.0011 2972 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys 20:02:20.0011 2972 circlass - ok 20:02:20.0104 2972 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 20:02:20.0104 2972 CLFS - ok 20:02:20.0167 2972 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 20:02:20.0167 2972 CmBatt - ok 20:02:20.0245 2972 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys 20:02:20.0245 2972 cmdide - ok 20:02:20.0307 2972 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys 20:02:20.0307 2972 CNG - ok 20:02:20.0401 2972 CnxtHdAudService (20f3f8674d7dee5d90a352b775d5d5ba) C:\Windows\system32\drivers\CHDRT64.sys 20:02:20.0401 2972 CnxtHdAudService - ok 20:02:20.0432 2972 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys 20:02:20.0448 2972 Compbatt - ok 20:02:20.0510 2972 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys 20:02:20.0510 2972 CompositeBus - ok 20:02:20.0572 2972 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys 20:02:20.0572 2972 crcdisk - ok 20:02:20.0666 2972 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys 20:02:20.0666 2972 DfsC - ok 20:02:20.0728 2972 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 20:02:20.0728 2972 discache - ok 20:02:20.0775 2972 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys 20:02:20.0775 2972 Disk - ok 20:02:20.0775 2972 DKbFltr - ok 20:02:20.0900 2972 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 20:02:20.0900 2972 drmkaud - ok 20:02:20.0962 2972 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys 20:02:20.0978 2972 DXGKrnl - ok 20:02:21.0103 2972 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys 20:02:21.0118 2972 ebdrv - ok 20:02:21.0212 2972 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys 20:02:21.0212 2972 elxstor - ok 20:02:21.0243 2972 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys 20:02:21.0243 2972 ErrDev - ok 20:02:21.0306 2972 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 20:02:21.0306 2972 exfat - ok 20:02:21.0337 2972 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 20:02:21.0337 2972 fastfat - ok 20:02:21.0352 2972 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys 20:02:21.0352 2972 fdc - ok 20:02:21.0493 2972 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 20:02:21.0493 2972 FileInfo - ok 20:02:21.0524 2972 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 20:02:21.0524 2972 Filetrace - ok 20:02:21.0633 2972 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys 20:02:21.0633 2972 flpydisk - ok 20:02:21.0664 2972 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys 20:02:21.0664 2972 FltMgr - ok 20:02:21.0789 2972 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 20:02:21.0789 2972 FsDepends - ok 20:02:21.0805 2972 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 20:02:21.0805 2972 Fs_Rec - ok 20:02:21.0898 2972 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys 20:02:21.0898 2972 fvevol - ok 20:02:21.0945 2972 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys 20:02:21.0945 2972 gagp30kx - ok 20:02:21.0992 2972 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 20:02:21.0992 2972 hcw85cir - ok 20:02:22.0023 2972 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys 20:02:22.0023 2972 HDAudBus - ok 20:02:22.0039 2972 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys 20:02:22.0039 2972 HidBatt - ok 20:02:22.0054 2972 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys 20:02:22.0054 2972 HidBth - ok 20:02:22.0070 2972 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys 20:02:22.0070 2972 HidIr - ok 20:02:22.0101 2972 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys 20:02:22.0101 2972 HidUsb - ok 20:02:22.0164 2972 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys 20:02:22.0164 2972 HpSAMD - ok 20:02:22.0242 2972 HSF_DPV (26c5d00321937e49b6bc91029947d094) C:\Windows\system32\DRIVERS\CAX_DPV.sys 20:02:22.0242 2972 HSF_DPV - ok 20:02:22.0351 2972 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys 20:02:22.0351 2972 HTTP - ok 20:02:22.0382 2972 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys 20:02:22.0382 2972 hwpolicy - ok 20:02:22.0398 2972 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys 20:02:22.0398 2972 i8042prt - ok 20:02:22.0554 2972 iaStor (1d004cb1da6323b1f55caef7f94b61d9) C:\Windows\system32\DRIVERS\iaStor.sys 20:02:22.0554 2972 iaStor - ok 20:02:22.0600 2972 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys 20:02:22.0600 2972 iaStorV - ok 20:02:22.0850 2972 igfx (2d18c9e1f23970de32d78d3b1cdda0a7) C:\Windows\system32\DRIVERS\igdkmd64.sys 20:02:22.0897 2972 igfx - ok 20:02:22.0959 2972 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys 20:02:22.0959 2972 iirsp - ok 20:02:23.0022 2972 IntcHdmiAddService (88a20fa54c73ded4e8dac764e9130ae9) C:\Windows\system32\drivers\IntcHdmi.sys 20:02:23.0022 2972 IntcHdmiAddService - ok 20:02:23.0068 2972 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys 20:02:23.0068 2972 intelide - ok 20:02:23.0084 2972 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 20:02:23.0084 2972 intelppm - ok 20:02:23.0115 2972 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys 20:02:23.0115 2972 IpFilterDriver - ok 20:02:23.0131 2972 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys 20:02:23.0131 2972 IPMIDRV - ok 20:02:23.0146 2972 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 20:02:23.0146 2972 IPNAT - ok 20:02:23.0178 2972 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 20:02:23.0178 2972 IRENUM - ok 20:02:23.0209 2972 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys 20:02:23.0209 2972 isapnp - ok 20:02:23.0256 2972 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys 20:02:23.0256 2972 iScsiPrt - ok 20:02:23.0302 2972 k57nd60a (249ee2d26cb1530f3bede0ac8b9e3099) C:\Windows\system32\DRIVERS\k57nd60a.sys 20:02:23.0302 2972 k57nd60a - ok 20:02:23.0396 2972 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys 20:02:23.0396 2972 kbdclass - ok 20:02:23.0412 2972 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys 20:02:23.0412 2972 kbdhid - ok 20:02:23.0443 2972 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys 20:02:23.0443 2972 KSecDD - ok 20:02:23.0490 2972 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys 20:02:23.0490 2972 KSecPkg - ok 20:02:23.0536 2972 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 20:02:23.0536 2972 ksthunk - ok 20:02:23.0583 2972 L1E (2ac603c3188c704cfce353659aa7ad71) C:\Windows\system32\DRIVERS\L1E62x64.sys 20:02:23.0583 2972 L1E - ok 20:02:23.0630 2972 LHidFilt (b6552d382ff070b4ed34cbd6737277c0) C:\Windows\system32\DRIVERS\LHidFilt.Sys 20:02:23.0630 2972 LHidFilt - ok 20:02:23.0677 2972 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 20:02:23.0677 2972 lltdio - ok 20:02:23.0708 2972 LMouFilt (73c1f563ab73d459dffe682d66476558) C:\Windows\system32\DRIVERS\LMouFilt.Sys 20:02:23.0708 2972 LMouFilt - ok 20:02:23.0755 2972 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys 20:02:23.0755 2972 LSI_FC - ok 20:02:23.0786 2972 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys 20:02:23.0786 2972 LSI_SAS - ok 20:02:23.0817 2972 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys 20:02:23.0817 2972 LSI_SAS2 - ok 20:02:23.0833 2972 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys 20:02:23.0833 2972 LSI_SCSI - ok 20:02:23.0864 2972 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 20:02:23.0864 2972 luafv - ok 20:02:23.0895 2972 mdmxsdk (e4f44ec214b3e381e1fc844a02926666) C:\Windows\system32\DRIVERS\mdmxsdk.sys 20:02:23.0911 2972 mdmxsdk - ok 20:02:23.0942 2972 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys 20:02:23.0942 2972 megasas - ok 20:02:23.0973 2972 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys 20:02:23.0973 2972 MegaSR - ok 20:02:23.0989 2972 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 20:02:23.0989 2972 Modem - ok 20:02:24.0020 2972 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 20:02:24.0020 2972 monitor - ok 20:02:24.0036 2972 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys 20:02:24.0036 2972 mouclass - ok 20:02:24.0051 2972 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 20:02:24.0051 2972 mouhid - ok 20:02:24.0067 2972 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys 20:02:24.0067 2972 mountmgr - ok 20:02:24.0114 2972 MpFilter (c177a7ebf5e8a0b596f618870516cab8) C:\Windows\system32\DRIVERS\MpFilter.sys 20:02:24.0114 2972 MpFilter - ok 20:02:24.0145 2972 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys 20:02:24.0145 2972 mpio - ok 20:02:24.0176 2972 MpNWMon (8fbf6b31fe8af1833d93c5913d5b4d55) C:\Windows\system32\DRIVERS\MpNWMon.sys 20:02:24.0176 2972 MpNWMon - ok 20:02:24.0223 2972 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 20:02:24.0223 2972 mpsdrv - ok 20:02:24.0254 2972 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys 20:02:24.0254 2972 MRxDAV - ok 20:02:24.0285 2972 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys 20:02:24.0285 2972 mrxsmb - ok 20:02:24.0332 2972 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys 20:02:24.0332 2972 mrxsmb10 - ok 20:02:24.0348 2972 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys 20:02:24.0363 2972 mrxsmb20 - ok 20:02:24.0394 2972 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys 20:02:24.0394 2972 msahci - ok 20:02:24.0441 2972 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys 20:02:24.0441 2972 msdsm - ok 20:02:24.0457 2972 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 20:02:24.0472 2972 Msfs - ok 20:02:24.0488 2972 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 20:02:24.0488 2972 mshidkmdf - ok 20:02:24.0504 2972 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys 20:02:24.0504 2972 msisadrv - ok 20:02:24.0613 2972 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 20:02:24.0613 2972 MSKSSRV - ok 20:02:24.0628 2972 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 20:02:24.0628 2972 MSPCLOCK - ok 20:02:24.0644 2972 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 20:02:24.0644 2972 MSPQM - ok 20:02:24.0675 2972 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys 20:02:24.0675 2972 MsRPC - ok 20:02:24.0706 2972 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys 20:02:24.0706 2972 mssmbios - ok 20:02:24.0738 2972 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 20:02:24.0738 2972 MSTEE - ok 20:02:24.0753 2972 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys 20:02:24.0769 2972 MTConfig - ok 20:02:24.0800 2972 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 20:02:24.0800 2972 Mup - ok 20:02:24.0847 2972 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 20:02:24.0847 2972 NativeWifiP - ok 20:02:24.0909 2972 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys 20:02:24.0909 2972 NDIS - ok 20:02:24.0925 2972 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 20:02:24.0925 2972 NdisCap - ok 20:02:24.0956 2972 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 20:02:24.0956 2972 NdisTapi - ok 20:02:24.0972 2972 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys 20:02:24.0972 2972 Ndisuio - ok 20:02:24.0987 2972 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys 20:02:25.0003 2972 NdisWan - ok 20:02:25.0018 2972 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys 20:02:25.0018 2972 NDProxy - ok 20:02:25.0050 2972 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 20:02:25.0050 2972 NetBIOS - ok 20:02:25.0065 2972 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys 20:02:25.0081 2972 NetBT - ok 20:02:25.0299 2972 netw5v64 (64428dfdaf6e88366cb51f45a79c5f69) C:\Windows\system32\DRIVERS\netw5v64.sys 20:02:25.0330 2972 netw5v64 - ok 20:02:25.0377 2972 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys 20:02:25.0377 2972 nfrd960 - ok 20:02:25.0424 2972 NisDrv (5f7d72cbcdd025af1f38fdeee5646968) C:\Windows\system32\DRIVERS\NisDrvWFP.sys 20:02:25.0424 2972 NisDrv - ok 20:02:25.0455 2972 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 20:02:25.0455 2972 Npfs - ok 20:02:25.0486 2972 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 20:02:25.0486 2972 nsiproxy - ok 20:02:25.0564 2972 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys 20:02:25.0580 2972 Ntfs - ok 20:02:25.0627 2972 NTIDrvr (64ddd0dee976302f4bd93e5efcc2f013) C:\Windows\system32\drivers\NTIDrvr.sys 20:02:25.0627 2972 NTIDrvr - ok 20:02:25.0658 2972 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 20:02:25.0658 2972 Null - ok 20:02:25.0705 2972 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys 20:02:25.0705 2972 nvraid - ok 20:02:25.0720 2972 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys 20:02:25.0720 2972 nvstor - ok 20:02:25.0752 2972 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys 20:02:25.0752 2972 nv_agp - ok 20:02:25.0767 2972 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys 20:02:25.0767 2972 ohci1394 - ok 20:02:25.0798 2972 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys 20:02:25.0798 2972 Parport - ok 20:02:25.0814 2972 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys 20:02:25.0814 2972 partmgr - ok 20:02:25.0861 2972 pavboot (8a0f8a9580d9f2fc512a35d5709088a9) C:\Windows\system32\drivers\pavboot64.sys 20:02:25.0861 2972 pavboot - ok 20:02:25.0908 2972 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys 20:02:25.0908 2972 pci - ok 20:02:25.0923 2972 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys 20:02:25.0923 2972 pciide - ok 20:02:25.0954 2972 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys 20:02:25.0954 2972 pcmcia - ok 20:02:25.0986 2972 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 20:02:25.0986 2972 pcw - ok 20:02:26.0017 2972 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 20:02:26.0032 2972 PEAUTH - ok 20:02:26.0157 2972 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys 20:02:26.0157 2972 PptpMiniport - ok 20:02:26.0188 2972 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys 20:02:26.0188 2972 Processor - ok 20:02:26.0220 2972 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys 20:02:26.0220 2972 Psched - ok 20:02:26.0251 2972 pwdrvio (9e97e62098fa1238d189181aab13c402) C:\Windows\system32\pwdrvio.sys 20:02:26.0266 2972 pwdrvio - ok 20:02:26.0298 2972 pwdspio (1a8011b9bd9b5cb53783e7f91109b946) C:\Windows\system32\pwdspio.sys 20:02:26.0298 2972 pwdspio - ok 20:02:26.0376 2972 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys 20:02:26.0391 2972 ql2300 - ok 20:02:26.0422 2972 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys 20:02:26.0422 2972 ql40xx - ok 20:02:26.0454 2972 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 20:02:26.0454 2972 QWAVEdrv - ok 20:02:26.0485 2972 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 20:02:26.0485 2972 RasAcd - ok 20:02:26.0516 2972 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 20:02:26.0516 2972 RasAgileVpn - ok 20:02:26.0563 2972 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys 20:02:26.0563 2972 Rasl2tp - ok 20:02:26.0610 2972 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 20:02:26.0610 2972 RasPppoe - ok 20:02:26.0656 2972 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 20:02:26.0656 2972 RasSstp - ok 20:02:26.0703 2972 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys 20:02:26.0703 2972 rdbss - ok 20:02:26.0734 2972 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys 20:02:26.0734 2972 rdpbus - ok 20:02:26.0766 2972 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 20:02:26.0766 2972 RDPCDD - ok 20:02:26.0953 2972 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 20:02:26.0953 2972 RDPENCDD - ok 20:02:27.0343 2972 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 20:02:27.0343 2972 RDPREFMP - ok 20:02:27.0577 2972 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys 20:02:27.0577 2972 RDPWD - ok 20:02:27.0795 2972 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys 20:02:27.0795 2972 rdyboost - ok 20:02:28.0029 2972 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 20:02:28.0029 2972 rspndr - ok 20:02:28.0232 2972 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys 20:02:28.0232 2972 sbp2port - ok 20:02:28.0482 2972 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys 20:02:28.0482 2972 scfilter - ok 20:02:28.0528 2972 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 20:02:28.0528 2972 secdrv - ok 20:02:28.0575 2972 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys 20:02:28.0575 2972 Serenum - ok 20:02:28.0591 2972 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys 20:02:28.0606 2972 Serial - ok 20:02:28.0622 2972 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys 20:02:28.0622 2972 sermouse - ok 20:02:28.0684 2972 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys 20:02:28.0684 2972 sffdisk - ok 20:02:28.0809 2972 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys 20:02:28.0809 2972 sffp_mmc - ok 20:02:28.0825 2972 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys 20:02:28.0840 2972 sffp_sd - ok 20:02:28.0872 2972 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys 20:02:28.0872 2972 sfloppy - ok 20:02:28.0950 2972 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys 20:02:28.0965 2972 SiSRaid2 - ok 20:02:29.0059 2972 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys 20:02:29.0059 2972 SiSRaid4 - ok 20:02:29.0121 2972 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 20:02:29.0121 2972 Smb - ok 20:02:29.0215 2972 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 20:02:29.0215 2972 spldr - ok 20:02:29.0293 2972 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys 20:02:29.0293 2972 srv - ok 20:02:29.0371 2972 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys 20:02:29.0371 2972 srv2 - ok 20:02:29.0480 2972 SrvHsfHDA (0c4540311e11664b245a263e1154cef8) C:\Windows\system32\DRIVERS\VSTAZL6.SYS 20:02:29.0480 2972 SrvHsfHDA - ok 20:02:29.0527 2972 SrvHsfV92 (02071d207a9858fbe3a48cbfd59c4a04) C:\Windows\system32\DRIVERS\VSTDPV6.SYS 20:02:29.0542 2972 SrvHsfV92 - ok 20:02:29.0574 2972 SrvHsfWinac (18e40c245dbfaf36fd0134a7ef2df396) C:\Windows\system32\DRIVERS\VSTCNXT6.SYS 20:02:29.0574 2972 SrvHsfWinac - ok 20:02:29.0652 2972 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys 20:02:29.0652 2972 srvnet - ok 20:02:29.0683 2972 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys 20:02:29.0683 2972 stexstor - ok 20:02:29.0714 2972 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys 20:02:29.0714 2972 swenum - ok 20:02:29.0792 2972 Tcpip (b9d87c7707f058ac652a398cd28de14b) C:\Windows\system32\drivers\tcpip.sys 20:02:29.0808 2972 Tcpip - ok 20:02:29.0886 2972 TCPIP6 (b9d87c7707f058ac652a398cd28de14b) C:\Windows\system32\DRIVERS\tcpip.sys 20:02:29.0901 2972 TCPIP6 - ok 20:02:29.0948 2972 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys 20:02:29.0948 2972 tcpipreg - ok 20:02:29.0979 2972 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 20:02:29.0979 2972 TDPIPE - ok 20:02:29.0995 2972 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys 20:02:29.0995 2972 TDTCP - ok 20:02:30.0026 2972 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys 20:02:30.0026 2972 tdx - ok 20:02:30.0042 2972 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys 20:02:30.0042 2972 TermDD - ok 20:02:30.0088 2972 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys 20:02:30.0088 2972 tssecsrv - ok 20:02:30.0120 2972 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys 20:02:30.0120 2972 tunnel - ok 20:02:30.0151 2972 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys 20:02:30.0151 2972 uagp35 - ok 20:02:30.0182 2972 UBHelper (2e22c1fd397a5a9ffef55e9d1fc96c00) C:\Windows\system32\drivers\UBHelper.sys 20:02:30.0182 2972 UBHelper - ok 20:02:30.0229 2972 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys 20:02:30.0229 2972 udfs - ok 20:02:30.0260 2972 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys 20:02:30.0260 2972 uliagpkx - ok 20:02:30.0307 2972 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys 20:02:30.0307 2972 umbus - ok 20:02:30.0322 2972 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys 20:02:30.0322 2972 UmPass - ok 20:02:30.0432 2972 usbccgp (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys 20:02:30.0432 2972 usbccgp - ok 20:02:30.0478 2972 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys 20:02:30.0478 2972 usbcir - ok 20:02:30.0525 2972 usbehci (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys 20:02:30.0525 2972 usbehci - ok 20:02:30.0572 2972 usbhub (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys 20:02:30.0572 2972 usbhub - ok 20:02:30.0603 2972 usbohci (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys 20:02:30.0603 2972 usbohci - ok 20:02:30.0650 2972 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 20:02:30.0650 2972 usbprint - ok 20:02:30.0681 2972 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS 20:02:30.0681 2972 USBSTOR - ok 20:02:30.0728 2972 usbuhci (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\DRIVERS\usbuhci.sys 20:02:30.0728 2972 usbuhci - ok 20:02:30.0775 2972 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\System32\Drivers\usbvideo.sys 20:02:30.0775 2972 usbvideo - ok 20:02:30.0822 2972 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys 20:02:30.0822 2972 vdrvroot - ok 20:02:30.0853 2972 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 20:02:30.0853 2972 vga - ok 20:02:30.0884 2972 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 20:02:30.0884 2972 VgaSave - ok 20:02:30.0900 2972 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys 20:02:30.0900 2972 vhdmp - ok 20:02:30.0915 2972 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys 20:02:30.0915 2972 viaide - ok 20:02:30.0978 2972 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys 20:02:30.0978 2972 volmgr - ok 20:02:31.0009 2972 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys 20:02:31.0009 2972 volmgrx - ok 20:02:31.0040 2972 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys 20:02:31.0040 2972 volsnap - ok 20:02:31.0071 2972 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys 20:02:31.0071 2972 vsmraid - ok 20:02:31.0102 2972 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys 20:02:31.0102 2972 vwifibus - ok 20:02:31.0134 2972 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys 20:02:31.0134 2972 vwififlt - ok 20:02:31.0149 2972 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys 20:02:31.0149 2972 vwifimp - ok 20:02:31.0196 2972 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys 20:02:31.0196 2972 WacomPen - ok 20:02:31.0212 2972 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 20:02:31.0212 2972 WANARP - ok 20:02:31.0227 2972 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 20:02:31.0227 2972 Wanarpv6 - ok 20:02:31.0290 2972 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys 20:02:31.0290 2972 Wd - ok 20:02:31.0336 2972 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 20:02:31.0336 2972 Wdf01000 - ok 20:02:31.0399 2972 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 20:02:31.0399 2972 WfpLwf - ok 20:02:31.0430 2972 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 20:02:31.0430 2972 WIMMount - ok 20:02:31.0477 2972 winachsf (a6ea7a3fc4b00f48535b506db1e86efd) C:\Windows\system32\DRIVERS\CAX_CNXT.sys 20:02:31.0477 2972 winachsf - ok 20:02:31.0555 2972 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys 20:02:31.0555 2972 WmiAcpi - ok 20:02:31.0602 2972 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 20:02:31.0602 2972 ws2ifsl - ok 20:02:31.0633 2972 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys 20:02:31.0633 2972 WudfPf - ok 20:02:31.0664 2972 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys 20:02:31.0664 2972 WUDFRd - ok 20:02:31.0711 2972 XAudio (e8f3fa126a06f8e7088f63757112a186) C:\Windows\system32\DRIVERS\XAudio64.sys 20:02:31.0711 2972 XAudio - ok 20:02:31.0758 2972 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 20:02:31.0773 2972 \Device\Harddisk0\DR0 - ok 20:02:31.0773 2972 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1 20:02:32.0491 2972 \Device\Harddisk1\DR1 - ok 20:02:32.0553 2972 Boot (0x1200) (494b3add681ab709b71d1bdbc8375bad) \Device\Harddisk0\DR0\Partition0 20:02:32.0553 2972 \Device\Harddisk0\DR0\Partition0 - ok 20:02:32.0569 2972 Boot (0x1200) (e5aef13337fc12b9ead53129c6c98b55) \Device\Harddisk0\DR0\Partition1 20:02:32.0569 2972 \Device\Harddisk0\DR0\Partition1 - ok 20:02:32.0600 2972 Boot (0x1200) (78004db6ffbafc6939c7fecf185aa4de) \Device\Harddisk0\DR0\Partition2 20:02:32.0600 2972 \Device\Harddisk0\DR0\Partition2 - ok 20:02:32.0600 2972 Boot (0x1200) (fca94c5f84c4686e23725d26c7b33ad0) \Device\Harddisk1\DR1\Partition0 20:02:32.0600 2972 \Device\Harddisk1\DR1\Partition0 - ok 20:02:32.0600 2972 ============================================================ 20:02:32.0600 2972 Scan finished 20:02:32.0600 2972 ============================================================ 20:02:32.0631 3156 Detected object count: 0 20:02:32.0631 3156 Actual detected object count: 0
Hadn't, but here they are;


OTL logfile created on: 27/09/2011 7:32:50 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = F:\
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.93 Gb Total Physical Memory | 2.81 Gb Available Physical Memory | 71.53% Memory free
7.86 Gb Paging File | 6.74 Gb Available in Paging File | 85.80% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 97.65 Gb Total Space | 55.80 Gb Free Space | 57.15% Space Free | Partition Type: NTFS
Drive E: | 123.42 Gb Total Space | 122.21 Gb Free Space | 99.02% Space Free | Partition Type: NTFS
Drive F: | 7.45 Gb Total Space | 7.37 Gb Free Space | 98.88% Space Free | Partition Type: FAT32

Computer Name: KATHY | User Name: Kathy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - F:\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbarsvc.exe (COMPANYVERS_NAME)
PRC - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbrmon.exe (VER_COMPANY_NAME)
PRC - C:\Windows\PLFSetI.exe ()
PRC - C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe (Suyin)
PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
PRC - C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe (Acer Incorporated)
PRC - C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)


========== Modules (No Company Name) ==========

MOD - C:\Windows\PLFSetI.exe ()
MOD - C:\Program Files (x86)\VideoWebCamera\VWC_ENG.dll ()
MOD - C:\Program Files (x86)\VideoWebCamera\sy_Utility.dll ()
MOD - C:\Program Files (x86)\VideoWebCamera\Image.dll ()
MOD - c:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll ()
MOD - C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\sqlite3.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (NisSrv) – C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (ePowerSvc) – C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (Updater Service) – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer)
SRV - (DailyBibleGuideService) – C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbarsvc.exe (COMPANYVERS_NAME)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (Greg_Service) – C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe (Acer Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\Gateway Games\Gateway Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (HsfXAudioService) – C:\Windows\SysWOW64\XAudio64.dll (Conexant Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (pwdrvio) – C:\Windows\SysNative\pwdrvio.sys ()
DRV:64bit: - (pwdspio) – C:\Windows\SysNative\pwdspio.sys ()
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (CnxtHdAudService) – C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (IntcHdmiAddService) Intel® – C:\Windows\SysNative\drivers\IntcHdmi.sys (Intel® Corporation)
DRV:64bit: - (pavboot) – C:\Windows\SysNative\drivers\pavboot64.sys (Panda Security, S.L.)
DRV:64bit: - (k57nd60a) Broadcom NetLink ™ – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20) – C:\Windows\SysNative\drivers\L1E62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (LMouFilt) – C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) – C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (netw5v64) Intel® – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (ApfiltrService) – C:\Windows\SysNative\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (XAudio) – C:\Windows\SysNative\drivers\XAudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (HSF_DPV) – C:\Windows\SysNative\drivers\CAX_DPV.sys (Conexant Systems, Inc.)
DRV:64bit: - (CAXHWAZL) – C:\Windows\SysNative\drivers\CAXHWAZL.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\drivers\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\drivers\mdmxsdk.sys (Conexant)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…80z1h5a4451u595
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…80z1h5a4451u595
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…80z1h5a4451u595
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.swiftcurrentonline.com/
IE - HKCU\..\URLSearchHook: {f15ff29f-85a1-43cd-9674-e5ba40016c97} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..network.proxy.type: 0

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@DailyBibleGuide.com/Plugin: C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\NP2vStub.dll (MindSpark)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files (x86)\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security, S.L.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DailyBibleGuide\bar\1.bin [2011/09/03 17:26:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/09/03 17:27:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/09/24 10:00:03 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/09/03 17:27:57 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/09/03 17:27:11 | 000,000,000 | —D | M]

[2011/09/24 09:55:14 | 000,000,000 | —D | M] (No name found) – C:\Users\Kathy\AppData\Roaming\mozilla\Extensions
[2011/09/24 10:00:03 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/09/03 17:26:14 | 000,000,000 | —D | M] (DailyBibleGuide) – C:\PROGRAM FILES (X86)\DAILYBIBLEGUIDE\BAR\1.BIN
[2011/09/03 00:01:45 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2009/11/06 10:37:19 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npCouponPrinter.dll
[2009/11/06 10:37:20 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/09/02 17:25:59 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2009/06/10 15:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Search Assistant BHO) - {0631bff0-6846-48ca-982d-d62d7f376e97} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vSrcAs.dll (COMPANYVERS_NAME)
O2 - BHO: (Toolbar BHO) - {beea7fa9-d1f4-49a2-9b1f-6fb7a2d9bc2a} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbar.dll (MindSpark)
O3 - HKLM\..\Toolbar: (DailyBibleGuide) - {2a942ab7-2073-49bc-a7e1-77e93835889a} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbar.dll (MindSpark)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (DailyBibleGuide) - {2A942AB7-2073-49BC-A7E1-77E93835889A} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbar.dll (MindSpark)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [CLMLServer] c:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DailyBibleGuide Browser Plugin Loader] C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbrmon.exe (VER_COMPANY_NAME)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [PDVD8LanguageShortcut] c:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RemoteControl8] c:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] c:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VideoWebCamera] C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe (Suyin)
O4 - Startup: C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SetPointUpgrade.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 172.16.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A82BEE7E-BF74-43BF-8CA8-D547EBDE8BE1}: DhcpNameServer = 172.16.1.254
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/09/27 19:27:17 | 000,000,000 | R–D | C] – C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 8
[2011/09/26 20:00:56 | 000,111,408 | —- | C] (Kaspersky Lab, GERT) – C:\Windows\SysNative\drivers\87609825.sys
[2011/09/26 09:22:32 | 001,548,080 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Kathy\Desktop\TDSSKiller.exe
[2011/09/25 15:47:48 | 000,000,000 | —D | C] – C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/09/25 15:47:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/09/24 17:00:36 | 000,000,000 | —D | C] – C:\Users\Kathy\AppData\Roaming\Malwarebytes
[2011/09/24 17:00:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/09/24 17:00:29 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/09/24 17:00:26 | 000,025,416 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/09/24 17:00:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/09/24 11:53:58 | 000,033,800 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\pavboot64.sys
[2011/09/24 11:53:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Panda Security
[2011/09/24 11:31:53 | 000,200,976 | —- | C] (Trend Micro Inc.) – C:\Windows\SysWow64\drivers\tmcomm.sys
[2011/09/24 10:14:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\VS Revo Group
[2011/09/24 10:14:12 | 000,000,000 | —D | C] – C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
[2011/09/24 09:54:55 | 000,000,000 | —D | C] – C:\Users\Kathy\AppData\Local\Mozilla
[2011/09/24 09:54:54 | 000,000,000 | —D | C] – C:\Users\Kathy\AppData\Roaming\Mozilla
[2011/09/23 18:00:13 | 000,000,000 | —D | C] – C:\Users\Kathy\AppData\Roaming\Memeo
[2011/09/23 08:39:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Maps4PC_0cEI
[2011/09/14 21:52:39 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2011/09/04 21:59:41 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2011/09/04 21:59:41 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2011/09/04 21:59:41 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2011/09/04 21:59:41 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2011/09/04 21:59:41 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2011/09/04 21:59:41 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2011/09/04 21:59:41 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2011/09/04 21:59:41 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[2011/09/04 14:50:54 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbport.sys
[2011/09/04 14:50:54 | 000,007,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbd.sys
[2011/09/04 14:50:46 | 002,566,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\esent.dll
[2011/09/04 14:50:45 | 001,686,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\esent.dll
[2011/09/04 14:50:45 | 000,187,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\storport.sys
[2011/09/04 14:50:45 | 000,107,904 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdsata.sys
[2011/09/04 14:50:45 | 000,027,008 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdxata.sys
[2011/09/04 14:50:44 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fsutil.exe
[2011/09/04 14:50:44 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fsutil.exe
[2011/09/04 07:38:56 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xmllite.dll
[2011/09/04 07:38:54 | 000,212,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbctrac.dll
[2011/09/04 07:38:54 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccp32.dll
[2011/09/04 07:38:54 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccu32.dll
[2011/09/04 07:38:54 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccr32.dll
[2011/09/04 07:38:53 | 000,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbcjt32.dll
[2011/09/04 07:38:53 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccp32.dll
[2011/09/04 07:38:53 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccu32.dll
[2011/09/04 07:38:53 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccr32.dll
[2011/09/04 07:38:52 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbctrac.dll
[2011/09/04 07:38:40 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe
[2011/09/04 07:38:40 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe
[2011/09/04 07:38:39 | 002,870,272 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2011/09/04 07:38:38 | 002,614,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2011/09/04 07:38:37 | 000,961,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CPFilters.dll
[2011/09/04 07:38:36 | 000,723,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/09/04 07:38:36 | 000,642,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CPFilters.dll
[2011/09/04 07:38:36 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/09/04 07:38:35 | 001,118,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sbe.dll
[2011/09/04 07:38:35 | 000,259,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mpg2splt.ax
[2011/09/04 07:38:34 | 000,850,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\sbe.dll
[2011/09/04 07:38:34 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2011/09/04 07:38:33 | 000,148,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\t2embed.dll
[2011/09/04 07:38:33 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\t2embed.dll
[2011/09/04 07:38:29 | 002,085,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ole32.dll
[2011/09/04 07:38:26 | 001,169,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskschd.dll
[2011/09/04 07:38:26 | 000,524,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmicmiplugin.dll
[2011/09/04 07:38:26 | 000,496,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\taskschd.dll
[2011/09/04 07:38:26 | 000,473,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskcomp.dll
[2011/09/04 07:38:26 | 000,464,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\taskeng.exe
[2011/09/04 07:38:26 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\taskcomp.dll
[2011/09/04 07:38:26 | 000,285,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\schtasks.exe
[2011/09/04 07:38:26 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\schtasks.exe
[2011/09/04 07:38:19 | 002,228,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssrch.dll
[2011/09/04 07:38:18 | 002,326,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tquery.dll
[2011/09/04 07:38:18 | 001,553,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tquery.dll
[2011/09/04 07:38:18 | 001,401,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssrch.dll
[2011/09/04 07:38:16 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssvp.dll
[2011/09/04 07:38:16 | 000,491,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssph.dll
[2011/09/04 07:38:16 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchProtocolHost.exe
[2011/09/04 07:38:15 | 000,779,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssvp.dll
[2011/09/04 07:38:15 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssph.dll
[2011/09/04 07:38:14 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssphtb.dll
[2011/09/04 07:38:14 | 000,113,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchFilterHost.exe
[2011/09/04 07:38:14 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msscntrs.dll
[2011/09/04 07:38:14 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msscntrs.dll
[2011/09/04 07:38:11 | 000,483,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\StructuredQuery.dll
[2011/09/04 07:38:01 | 001,975,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CertEnroll.dll
[2011/09/04 07:38:00 | 001,320,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CertEnroll.dll
[2011/09/04 07:37:51 | 000,422,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc_isv.dll
[2011/09/04 07:37:51 | 000,369,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc.dll
[2011/09/04 07:37:51 | 000,365,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_isv.dll
[2011/09/04 07:37:50 | 000,424,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc.dll
[2011/09/04 07:37:50 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_isv.exe
[2011/09/04 07:37:50 | 000,356,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate.exe
[2011/09/04 07:37:50 | 000,306,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_ssp.exe
[2011/09/04 07:37:50 | 000,305,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2011/09/04 07:37:49 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_isv.exe
[2011/09/04 07:37:49 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate.exe
[2011/09/04 07:37:49 | 000,121,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc_ssp_isv.dll
[2011/09/04 07:37:49 | 000,121,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\secproc_ssp.dll
[2011/09/04 07:37:48 | 000,280,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_ssp.exe
[2011/09/04 07:37:48 | 000,277,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2011/09/04 07:37:48 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_ssp_isv.dll
[2011/09/04 07:37:48 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_ssp.dll
[2011/09/04 07:37:38 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSNP.ax
[2011/09/04 07:37:37 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/09/04 07:37:37 | 000,552,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msdri.dll
[2011/09/04 07:37:37 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/09/04 07:37:37 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2011/09/04 07:37:29 | 000,476,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2011/09/04 07:37:29 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/09/04 07:37:25 | 000,633,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\comctl32.dll
[2011/09/04 07:37:22 | 000,852,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/09/04 07:37:21 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/09/04 07:37:21 | 000,612,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/09/04 07:37:18 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winlogon.exe
[2011/09/04 07:37:17 | 000,662,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2011/09/04 07:37:17 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2011/09/04 07:37:12 | 000,264,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\upnp.dll
[2011/09/04 07:37:12 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\upnp.dll
[2011/09/04 07:37:10 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\davclnt.dll
[2011/09/04 07:37:10 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wscapi.dll
[2011/09/04 07:37:10 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wscapi.dll
[2011/09/04 07:37:10 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\slwga.dll
[2011/09/04 07:37:10 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\slwga.dll
[2011/09/04 07:37:07 | 001,359,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfc42u.dll
[2011/09/04 07:37:06 | 001,395,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfc42.dll
[2011/09/04 07:37:06 | 001,137,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc42.dll
[2011/09/04 07:37:05 | 001,164,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc42u.dll
[2011/09/04 07:37:04 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rtutils.dll
[2011/09/04 07:36:55 | 000,367,104 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2011/09/04 07:36:54 | 000,294,912 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2011/09/04 07:36:54 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fontsub.dll
[2011/09/04 07:36:54 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fontsub.dll
[2011/09/04 07:36:54 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2011/09/04 07:36:54 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2011/09/04 07:36:53 | 001,837,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2011/09/04 07:36:52 | 004,068,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mf.dll
[2011/09/04 07:36:52 | 001,888,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2011/09/04 07:36:52 | 001,540,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2011/09/04 07:36:52 | 000,902,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2011/09/04 07:36:50 | 003,181,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mf.dll
[2011/09/04 07:36:49 | 001,863,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ExplorerFrame.dll
[2011/09/04 07:36:48 | 001,619,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2011/09/04 07:36:48 | 001,495,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ExplorerFrame.dll
[2011/09/04 07:36:48 | 000,265,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/09/04 07:36:48 | 000,257,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfreadwrite.dll
[2011/09/04 07:36:48 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsRasterService.dll
[2011/09/04 07:36:48 | 000,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfps.dll
[2011/09/04 07:36:48 | 000,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfreadwrite.dll
[2011/09/04 07:36:48 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2011/09/04 07:36:48 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsRasterService.dll
[2011/09/04 07:36:42 | 000,082,944 | —- | C] (Radius Inc.) – C:\Windows\SysWow64\iccvid.dll
[2011/09/04 07:36:42 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2011/09/04 07:36:41 | 000,395,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\webio.dll
[2011/09/04 07:36:40 | 000,314,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\webio.dll
[2011/09/04 07:36:22 | 000,356,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dnsapi.dll
[2011/09/04 07:36:21 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dnscacheugc.exe
[2011/09/04 07:36:21 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dnscacheugc.exe
[2011/09/04 07:36:07 | 001,572,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\quartz.dll
[2011/09/04 07:36:07 | 001,328,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2011/09/04 07:36:07 | 001,024,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmpmde.dll
[2011/09/04 07:36:07 | 000,738,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmpmde.dll
[2011/09/04 07:36:06 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\avifil32.dll
[2011/09/04 07:36:06 | 000,084,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mciavi32.dll
[2011/09/04 07:36:05 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2011/09/04 07:36:05 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/09/04 07:35:54 | 001,739,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2011/09/04 07:35:43 | 001,446,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2011/09/04 07:35:41 | 000,640,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.efi
[2011/09/04 07:35:41 | 000,603,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.exe
[2011/09/04 07:35:41 | 000,556,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.efi
[2011/09/04 07:35:41 | 000,518,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.exe
[2011/09/04 07:35:41 | 000,020,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kdusb.dll
[2011/09/04 07:35:41 | 000,019,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kd1394.dll
[2011/09/04 07:35:41 | 000,017,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kdcom.dll
[2011/09/04 07:35:39 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/09/04 07:35:38 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc40.dll
[2011/09/04 07:35:38 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc40u.dll
[2011/09/04 07:35:37 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msasn1.dll
[2011/09/04 07:35:36 | 000,422,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2011/09/04 07:35:35 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2011/09/04 07:35:35 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2011/09/04 07:35:35 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2011/09/04 07:35:35 | 000,214,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2011/09/04 07:35:34 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2011/09/04 07:35:33 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2011/09/04 07:35:33 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2011/09/04 07:35:33 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2011/09/04 07:35:33 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2011/09/04 07:35:33 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2011/09/04 07:35:33 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2011/09/04 07:35:33 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/09/04 07:35:33 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/09/04 07:35:31 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2011/09/04 07:35:31 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2011/09/04 07:35:31 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2011/09/04 07:35:31 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2011/09/04 07:35:31 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/09/04 07:35:31 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/09/04 07:35:31 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2011/09/04 07:35:31 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2011/09/04 07:35:31 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2011/09/04 07:35:31 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2011/09/04 07:35:31 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2011/09/04 07:35:31 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2011/09/04 07:35:31 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2011/09/04 07:35:30 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2011/09/04 07:35:30 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2011/09/04 07:35:30 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2011/09/04 07:35:30 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2011/09/04 07:35:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/09/04 07:35:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/09/04 07:35:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/09/04 07:35:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/09/04 07:35:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/09/04 07:35:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2011/09/04 07:35:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2011/09/04 07:35:30 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2011/09/04 07:35:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/09/04 07:35:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2011/09/04 07:35:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2011/09/04 07:35:30 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2011/09/04 07:35:29 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2011/09/04 07:35:29 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2011/09/04 07:35:29 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2011/09/04 07:35:29 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2011/09/04 07:35:29 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2011/09/04 07:35:29 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2011/09/04 07:35:28 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2011/09/04 07:35:25 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\drvinst.exe
[2011/09/04 07:35:25 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\devrtl.dll
[2011/09/04 07:35:23 | 003,138,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2011/09/04 07:35:22 | 002,690,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2011/09/04 07:35:21 | 001,097,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2011/09/04 07:35:21 | 001,034,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2011/09/04 07:35:15 | 000,267,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\FXSCOVER.exe
[2011/09/04 07:35:13 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\prevhost.exe
[2011/09/04 07:35:13 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\prevhost.exe
[2011/09/04 07:35:12 | 014,627,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmp.dll
[2011/09/04 07:35:10 | 011,406,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmp.dll
[2011/09/04 07:35:09 | 012,625,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmploc.DLL
[2011/09/04 07:35:09 | 012,625,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmploc.DLL
[2011/09/04 07:35:05 | 000,112,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2011/09/04 07:35:01 | 000,720,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbc32.dll
[2011/09/04 07:35:01 | 000,573,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbc32.dll
[2011/09/04 07:34:39 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/09/04 07:34:37 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/09/04 07:34:37 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/09/04 07:34:37 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/09/04 07:34:37 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/09/04 07:34:36 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/09/04 07:34:36 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/09/04 07:34:35 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/09/04 07:34:35 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/09/04 07:34:35 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/09/04 07:34:35 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/09/04 07:34:34 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/09/04 07:34:34 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/09/04 07:34:33 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/09/04 07:34:33 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/09/04 07:34:30 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\sscore.dll
[2011/09/04 07:34:27 | 005,507,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/09/04 07:34:26 | 003,957,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2011/09/04 07:34:26 | 003,902,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2011/09/03 20:45:56 | 000,220,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2011/09/03 20:45:55 | 000,139,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cabview.dll
[2011/09/03 20:45:55 | 000,132,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cabview.dll
[2011/09/03 19:18:51 | 000,000,000 | —D | C] – C:\Windows\Panther
[2011/09/03 19:17:20 | 000,000,000 | —D | C] – C:\Windows\SysNative\oem
[2011/09/03 19:02:24 | 000,000,000 | -H-D | C] – C:\$WINDOWS.~Q
[2011/09/03 18:58:30 | 000,000,000 | -H-D | C] – C:\$INPLACE.~TR
[2011/09/03 17:23:11 | 000,000,000 | -HSD | C] – C:\Users\Kathy\AppData\Local\Temporary Internet Files
[2011/09/03 17:23:11 | 000,000,000 | -HSD | C] – C:\Users\Kathy\Templates
[2011/09/03 17:23:11 | 000,000,000 | -HSD | C] – C:\Users\Kathy\Start Menu
[2011/09/03 17:23:11 | 000,000,000 | -HSD | C] – C:\Users\Kathy\SendTo
[2011/09/03 17:23:11 | 000,000,000 | -HSD | C] – C:\Users\Kathy\Recent
[2011/09/03 17:23:11 | 000,000,000 | -HSD | C] – C:\Users\Kathy\PrintHood
[2011/09/03 17:23:11 | 000,000,000 | -HSD | C] – C:\Users\Kathy\NetHood
[2011/09/03 17:23:11 | 000,000,000 | -HSD | C] – C:\Users\Kathy\Documents\My Videos
[2011/09/03 17:23:11 | 000,000,000 | -HSD | C] – C:\Users\Kathy\Documents\My Pictures
[2011/09/03 17:23:11 | 000,000,000 | -HSD | C] – C:\Users\Kathy\Documents\My Music
[2011/09/03 17:23:11 | 000,000,000 | -HSD | C] – C:\Users\Kathy\My Documents
[2011/09/03 17:23:11 | 000,000,000 | -HSD | C] – C:\Users\Kathy\Local Settings
[2011/09/03 17:23:11 | 000,000,000 | -HSD | C] – C:\Users\Kathy\AppData\Local\History
[2011/09/03 17:23:11 | 000,000,000 | -HSD | C] – C:\Users\Kathy\Cookies
[2011/09/03 17:23:11 | 000,000,000 | -HSD | C] – C:\Users\Kathy\Application Data
[2011/09/03 17:23:11 | 000,000,000 | -HSD | C] – C:\Users\Kathy\AppData\Local\Application Data
[2011/09/03 17:23:11 | 000,000,000 | —D | C] – C:\Users\Kathy\AppData\Local\Temp
[2011/09/03 17:23:11 | 000,000,000 | —D | C] – C:\Users\Kathy\AppData\Local\Microsoft
[2011/09/03 17:23:11 | 000,000,000 | —D | C] – C:\Users\Kathy\AppData\Roaming\Media Center Programs
[2011/09/03 17:23:10 | 000,000,000 | –SD | C] – C:\Users\Kathy\AppData\Roaming\Microsoft
[2011/09/03 17:23:10 | 000,000,000 | R–D | C] – C:\Users\Kathy\Videos
[2011/09/03 17:23:10 | 000,000,000 | R–D | C] – C:\Users\Kathy\Saved Games
[2011/09/03 17:23:10 | 000,000,000 | R–D | C] – C:\Users\Kathy\Pictures
[2011/09/03 17:23:10 | 000,000,000 | R–D | C] – C:\Users\Kathy\Music
[2011/09/03 17:23:10 | 000,000,000 | R–D | C] – C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/09/03 17:23:10 | 000,000,000 | R–D | C] – C:\Users\Kathy\Links
[2011/09/03 17:23:10 | 000,000,000 | R–D | C] – C:\Users\Kathy\Favorites
[2011/09/03 17:23:10 | 000,000,000 | R–D | C] – C:\Users\Kathy\Downloads
[2011/09/03 17:23:10 | 000,000,000 | R–D | C] – C:\Users\Kathy\Documents
[2011/09/03 17:23:10 | 000,000,000 | R–D | C] – C:\Users\Kathy\Desktop
[2011/09/03 17:23:10 | 000,000,000 | R–D | C] – C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/09/03 17:23:10 | 000,000,000 | -H-D | C] – C:\Users\Kathy\AppData
[2011/09/03 17:21:42 | 000,000,000 | —D | C] – C:\Program Files\Apoint2K
[2011/09/03 17:21:28 | 000,000,000 | —D | C] – C:\Program Files\CONEXANT
[2011/09/03 17:20:09 | 000,000,000 | —D | C] – C:\Windows\Prefetch

========== Files - Modified Within 30 Days ==========

[2011/09/27 19:35:31 | 000,717,260 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/09/27 19:35:31 | 000,621,742 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/09/27 19:35:31 | 000,108,792 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/09/27 19:27:02 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/09/27 19:26:45 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/09/27 19:26:38 | 3165,331,456 | -HS- | M] () – C:\hiberfil.sys
[2011/09/27 19:26:12 | 000,020,816 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/09/27 19:26:12 | 000,020,816 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/09/26 20:00:56 | 000,111,408 | —- | M] (Kaspersky Lab, GERT) – C:\Windows\SysNative\drivers\87609825.sys
[2011/09/26 09:22:32 | 001,548,080 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Kathy\Desktop\TDSSKiller.exe
[2011/09/25 15:47:48 | 000,002,975 | —- | M] () – C:\Users\Kathy\Desktop\HiJackThis.lnk
[2011/09/24 17:00:29 | 000,001,116 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/24 11:36:26 | 000,158,819 | —- | M] () – C:\Users\Kathy\AppData\Local\census.cache
[2011/09/24 11:36:21 | 000,094,176 | —- | M] () – C:\Users\Kathy\AppData\Local\ars.cache
[2011/09/24 11:30:49 | 000,000,036 | —- | M] () – C:\Users\Kathy\AppData\Local\housecall.guid.cache
[2011/09/24 11:02:03 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/09/24 10:14:13 | 000,001,271 | —- | M] () – C:\Users\Kathy\Desktop\Revo Uninstaller.lnk
[2011/09/24 09:34:25 | 000,001,444 | —- | M] () – C:\Users\Kathy\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/09/24 09:33:31 | 000,000,632 | RHS- | M] () – C:\Users\Kathy\ntuser.pol
[2011/09/05 07:16:51 | 000,381,800 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/09/03 17:53:57 | 000,039,252 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2011/09/03 17:53:57 | 000,039,252 | —- | M] () – C:\Windows\SysNative\license.rtf
[2011/09/03 17:44:15 | 000,022,744 | —- | M] () – C:\Windows\SysNative\emptyregdb.dat
[2011/09/03 17:22:14 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_LMouFilt_01005.Wdf
[2011/09/03 17:22:14 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_LHidFilt_01005.Wdf
[2011/09/03 17:21:46 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_Kernel_Apfiltr_01007.Wdf
[2011/09/03 16:22:54 | 000,003,042 | —- | M] () – C:\Users\Kathy\Desktop\Windows Compatibility Report.htm
[2011/09/03 16:19:05 | 000,026,430 | —- | M] () – C:\Windows\diagwrn.xml
[2011/09/03 16:19:05 | 000,001,890 | —- | M] () – C:\Windows\diagerr.xml
[2011/08/31 17:00:50 | 000,025,416 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2011/09/25 15:47:48 | 000,002,975 | —- | C] () – C:\Users\Kathy\Desktop\HiJackThis.lnk
[2011/09/24 17:00:29 | 000,001,116 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/24 11:36:26 | 000,158,819 | —- | C] () – C:\Users\Kathy\AppData\Local\census.cache
[2011/09/24 11:36:21 | 000,094,176 | —- | C] () – C:\Users\Kathy\AppData\Local\ars.cache
[2011/09/24 11:30:49 | 000,000,036 | —- | C] () – C:\Users\Kathy\AppData\Local\housecall.guid.cache
[2011/09/24 10:14:13 | 000,001,271 | —- | C] () – C:\Users\Kathy\Desktop\Revo Uninstaller.lnk
[2011/09/24 09:34:25 | 000,001,416 | —- | C] () – C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011/09/24 09:34:20 | 000,001,450 | —- | C] () – C:\Users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/09/24 09:33:30 | 000,000,632 | RHS- | C] () – C:\Users\Kathy\ntuser.pol
[2011/09/03 19:17:20 | 000,000,024 | RH– | C] () – C:\Windows\DELL_version
[2011/09/03 17:44:15 | 000,022,744 | —- | C] () – C:\Windows\SysNative\emptyregdb.dat
[2011/09/03 17:23:11 | 000,000,290 | —- | C] () – C:\Users\Kathy\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/09/03 17:23:11 | 000,000,272 | —- | C] () – C:\Users\Kathy\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/09/03 17:22:47 | 000,001,345 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/09/03 17:22:46 | 000,001,326 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011/09/03 17:22:14 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_LMouFilt_01005.Wdf
[2011/09/03 17:22:14 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_LHidFilt_01005.Wdf
[2011/09/03 17:21:46 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_Kernel_Apfiltr_01007.Wdf
[2011/09/03 16:04:52 | 000,003,042 | —- | C] () – C:\Users\Kathy\Desktop\Windows Compatibility Report.htm
[2011/09/03 16:01:47 | 000,026,430 | —- | C] () – C:\Windows\diagwrn.xml
[2011/09/03 16:01:47 | 000,001,890 | —- | C] () – C:\Windows\diagerr.xml
[2011/08/10 10:42:47 | 000,000,060 | —- | C] () – C:\Windows\wininit.ini
[2011/01/23 15:35:01 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/06/12 08:27:28 | 000,000,760 | —- | C] () – C:\Users\Kathy\AppData\Roaming\setup_ldm.iss
[2010/05/31 16:52:42 | 000,023,142 | —- | C] () – C:\Windows\hpqins15.dat
[2010/05/24 16:03:38 | 000,162,102 | —- | C] () – C:\Windows\hphins25.dat
[2010/05/24 16:03:38 | 000,000,349 | —- | C] () – C:\Windows\hphmdl25.dat
[2010/05/11 20:51:07 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2010/05/09 20:25:39 | 000,000,031 | —- | C] () – C:\Windows\warhead.ini
[2010/02/21 09:53:29 | 000,001,227 | —- | C] () – C:\Windows\WPatchProgress.ini
[2010/02/21 09:20:01 | 000,200,704 | —- | C] () – C:\Windows\PLFSetI.exe
[2010/02/21 09:20:01 | 000,000,323 | —- | C] () – C:\Windows\PidList.ini
[2009/10/28 13:40:57 | 000,000,189 | —- | C] () – C:\Windows\Prelaunch.ini
[2009/10/28 13:40:57 | 000,000,169 | —- | C] () – C:\Windows\WisLangCode.ini
[2009/10/28 13:40:57 | 000,000,147 | —- | C] () – C:\Windows\WisPriority.ini
[2009/09/02 18:52:46 | 000,982,220 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2009/09/02 18:52:46 | 000,439,300 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2009/09/02 18:52:46 | 000,134,592 | —- | C] () – C:\Windows\SysWow64\igfcg500.bin
[2009/09/02 18:52:46 | 000,092,216 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2009/07/13 23:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 20:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 20:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 18:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 17:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 15:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\Windows\SysWow64\OUTLPERF.INI

========== LOP Check ==========

[2011/09/03 17:38:08 | 000,000,000 | —D | M] – C:\Users\Kathy\AppData\Roaming\DriverCure
[2011/09/03 17:38:08 | 000,000,000 | —D | M] – C:\Users\Kathy\AppData\Roaming\Foxit Software
[2011/09/23 18:00:13 | 000,000,000 | —D | M] – C:\Users\Kathy\AppData\Roaming\Memeo
[2011/09/03 17:38:10 | 000,000,000 | —D | M] – C:\Users\Kathy\AppData\Roaming\ParetoLogic
[2010/12/07 11:51:22 | 000,000,420 | —- | M] () – C:\Windows\Tasks\ParetoLogic Registration3.job
[2010/12/07 11:51:01 | 000,000,442 | —- | M] () – C:\Windows\Tasks\ParetoLogic Update Version3.job
[2010/12/07 11:50:59 | 000,000,400 | —- | M] () – C:\Windows\Tasks\PC Health Advisor Defrag.job
[2009/07/13 23:08:49 | 000,010,210 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/07/13 19:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2009/07/27 14:40:53 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/09/27 19:26:38 | 3165,331,456 | -HS- | M] () – C:\hiberfil.sys
[2005/09/23 00:39:38 | 000,894,976 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2011/09/27 19:26:44 | 4220,444,672 | -HS- | M] () – C:\pagefile.sys
[2009/12/09 03:46:07 | 000,006,821 | RHS- | M] () – C:\Patch.rev
[2010/05/08 20:07:49 | 000,000,194 | RHS- | M] () – C:\Preload.rev
[2011/09/26 20:02:33 | 000,153,770 | —- | M] () – C:\TDSSKiller.2.6.1.0_26.09.2011_20.00.55_log.txt

< %systemroot%\Fonts\*.com >
[2009/07/13 23:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 23:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 23:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 23:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 14:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 22:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/05/08 20:21:45 | 000,000,221 | -HS- | M] () – C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
[2011/09/24 09:34:25 | 000,000,221 | -HS- | M] () – C:\Users\Kathy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/09/26 09:22:32 | 001,548,080 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Kathy\Desktop\TDSSKiller.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2009/06/10 15:20:04 | 000,000,802 | —- | M] () – C:\Windows\ADDINS\FXSEXT.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2011/09/24 09:34:24 | 000,000,402 | -HS- | M] () – C:\Users\Kathy\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >



OTL Extras logfile created on: 27/09/2011 7:32:50 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = F:\
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.93 Gb Total Physical Memory | 2.81 Gb Available Physical Memory | 71.53% Memory free
7.86 Gb Paging File | 6.74 Gb Available in Paging File | 85.80% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 97.65 Gb Total Space | 55.80 Gb Free Space | 57.15% Space Free | Partition Type: NTFS
Drive E: | 123.42 Gb Total Space | 122.21 Gb Free Space | 99.02% Space Free | Partition Type: NTFS
Drive F: | 7.45 Gb Total Space | 7.37 Gb Free Space | 98.88% Space Free | Partition Type: FAT32

Computer Name: KATHY | User Name: Kathy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{23170F69-40C1-2702-0465-000001000000}" = 7-Zip 4.65 (x64 edition)
"{42738DB0-FC3E-4672-A99B-9372F5696E30}" = Microsoft Security Client
"{650AF771-456D-418F-BFC7-F6FFC9D0235C}" = HP Deskjet 3050 J610 series Basic Device Software
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{9E8918B7-099C-4E0D-926A-9D2C4B13C27F}" = HP Deskjet D2500 Printer Driver Software 13.0 Rel. 3
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{F3F18612-7B5D-4C05-86C9-AB50F6F71727}" = KhalInstallWrapper
"{FEB2C4AA-661E-483F-9626-21A8ACFD10F2}" = HP Deskjet 3050 J610 series Product Improvement Study
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"CCleaner" = CCleaner
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"Microsoft Security Client" = Microsoft Security Essentials

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Gateway Power Management
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6D9021DC-CF1B-4148-8C80-6D8E8A8A33EB}" = Video Web Camera
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Gateway Recovery Management
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA468551-1794-42FE-B504-C41D75EEBDF2}_is1" = Partition Wizard Home Edition 5.0
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{D09CF7CB-BD48-490E-B2A4-288C89178265}" = D2500
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skypeâ„¢ 4.2
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{E5463D0F-30FF-46C7-929D-70609605061C}" = DJ_SF_03_D2500_Software_Min
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Gateway Updater
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}" = HP Deskjet 3050 J610 series Help
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Audio Bible Ambassador_is1" = Audio Bible Ambassador 1.0
"BackWeb-8876480 Uninstaller" = Logitech Desktop Messenger
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"DailyBibleGuidebar Uninstall" = DailyBibleGuide
"Foxit Reader" = Foxit Reader
"Gateway InfoCentre" = Gateway InfoCentre
"Gateway Registration" = Gateway Registration
"Gateway Screensaver" = Gateway ScreenSaver
"Gateway Welcome Center" = Welcome Center
"HP Photo Creations" = HP Photo Creations
"Identity Card" = Identity Card
"InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Gateway MyBackup
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Mozilla Firefox 6.0.2 (x86 en-US)" = Mozilla Firefox 6.0.2 (x86 en-US)
"Revo Uninstaller" = Revo Uninstaller 1.93
"WildTangent gateway Master Uninstall" = Gateway Games

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 04/09/2011 4:41:55 PM | Computer Name = Kathy | Source = Application Error | ID = 1000
Description = Faulting application name: GregHSRW.exe, version: 1.0.2001.0, time
stamp: 0x2a425e19 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x74576a34 Faulting process id: 0x724 Faulting application
start time: 0x01cc6b42daf333d4 Faulting application path: C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe
Faulting
module path: unknown Report Id: 52f3d6cb-d736-11e0-8ddb-00262d8dc08b

Error - 04/09/2011 4:41:58 PM | Computer Name = Kathy | Source = Application Error | ID = 1000
Description = Faulting application name: IScheduleSvc.exe, version: 2.0.0.29, time
stamp: 0x4ab9f801 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x74576a34 Faulting process id: 0x7a4 Faulting application
start time: 0x01cc6b42db7fa504 Faulting application path: C:\Program Files (x86)\NewTech
Infosystems\Gateway MyBackup\IScheduleSvc.exe Faulting module path: unknown Report
Id: 54ba7da0-d736-11e0-8ddb-00262d8dc08b

Error - 04/09/2011 4:42:03 PM | Computer Name = Kathy | Source = Application Error | ID = 1000
Description = Faulting application name: UpdaterService.exe, version: 1.0.0.6, time
stamp: 0x4a4de121 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x74576a34 Faulting process id: 0x424 Faulting application
start time: 0x01cc6b42dc39505a Faulting application path: C:\Program Files\Gateway\Gateway
Updater\UpdaterService.exe Faulting module path: unknown Report Id: 57d327db-d736-11e0-8ddb-00262d8dc08b

Error - 04/09/2011 4:42:04 PM | Computer Name = Kathy | Source = Application Error | ID = 1000
Description = Faulting application name: IAANTMon.exe, version: 8.9.0.1023, time
stamp: 0x4a287cc7 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x74576a34 Faulting process id: 0x514 Faulting application
start time: 0x01cc6b42dc537f7d Faulting application path: C:\Program Files (x86)\Intel\Intel
Matrix Storage Manager\IAANTMon.exe Faulting module path: unknown Report Id: 5866bd2c-d736-11e0-8ddb-00262d8dc08b

Error - 23/09/2011 7:59:46 PM | Computer Name = Kathy | Source = ESENT | ID = 215
Description = WinMail (1324) WindowsMail0: The backup has been stopped because it
was halted by the client or the connection with the client failed.

Error - 23/09/2011 7:59:53 PM | Computer Name = Kathy | Source = ESENT | ID = 215
Description = WinMail (2548) WindowsMail0: The backup has been stopped because it
was halted by the client or the connection with the client failed.

Error - 24/09/2011 11:34:15 AM | Computer Name = Kathy | Source = ESENT | ID = 215
Description = WinMail (3424) WindowsMail0: The backup has been stopped because it
was halted by the client or the connection with the client failed.

Error - 24/09/2011 11:34:22 AM | Computer Name = Kathy | Source = ESENT | ID = 215
Description = WinMail (3760) WindowsMail0: The backup has been stopped because it
was halted by the client or the connection with the client failed.

Error - 24/09/2011 11:41:40 AM | Computer Name = Kathy | Source = MsiInstaller | ID = 11730
Description =

Error - 24/09/2011 11:38:15 PM | Computer Name = Kathy | Source = EventSystem | ID = 4621
Description =

[ System Events ]
Error - 04/03/2011 10:48:01 PM | Computer Name = Kathy | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 04/03/2011 10:48:08 PM | Computer Name = Kathy | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 04/03/2011 10:48:14 PM | Computer Name = Kathy | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 04/03/2011 10:48:21 PM | Computer Name = Kathy | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 04/03/2011 10:48:27 PM | Computer Name = Kathy | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 04/03/2011 10:48:34 PM | Computer Name = Kathy | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 04/03/2011 10:48:40 PM | Computer Name = Kathy | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 04/03/2011 10:48:47 PM | Computer Name = Kathy | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 04/03/2011 10:48:53 PM | Computer Name = Kathy | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.

Error - 04/03/2011 10:49:00 PM | Computer Name = Kathy | Source = cdrom | ID = 262155
Description = The driver detected a controller error on \Device\CdRom0.


< End of report >
Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Here is the combofix log; ComboFix 11-09-28.06 - Kathy 28/09/2011 19:20:19.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.2.1033.18.4025.2809 [GMT -6:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\DailyBibleGuideEI c:\windows\bwUnin-8.1.1.50-8876480SL.exe . . ((((((((((((((((((((((((( Files Created from 2011-08-28 to 2011-09-29 ))))))))))))))))))))))))))))))) . . 2011-09-29 01:25 . 2011-09-29 01:25 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-09-28 20:57 . 2011-09-12 23:26 9049936 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F3180953-8BE3-41AB-8F28-F2516EB9DB10}\mpengine.dll 2011-09-27 02:00 . 2011-09-27 02:00 111408 —-a-w- c:\windows\system32\drivers\87609825.sys 2011-09-25 21:47 . 2011-09-25 21:47 ——– d—–w- c:\program files (x86)\Trend Micro 2011-09-24 23:00 . 2011-09-24 23:00 ——– d—–w- c:\programdata\Malwarebytes 2011-09-24 23:00 . 2011-08-31 23:00 25416 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-09-24 23:00 . 2011-09-24 23:00 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-09-24 17:53 . 2009-06-30 16:37 33800 —-a-w- c:\windows\system32\drivers\pavboot64.sys 2011-09-24 17:53 . 2011-09-24 17:53 ——– d—–w- c:\program files (x86)\Panda Security 2011-09-24 17:31 . 2011-06-21 04:09 200976 —-a-w- c:\windows\SysWow64\drivers\tmcomm.sys 2011-09-24 16:14 . 2011-09-24 16:14 ——– d—–w- c:\program files (x86)\VS Revo Group 2011-09-23 14:39 . 2011-09-23 14:39 ——– d—–w- c:\program files (x86)\Maps4PC_0cEI 2011-09-15 03:52 . 2011-09-15 03:52 ——– d—–w- c:\windows\PCHEALTH 2011-09-08 21:17 . 2011-01-30 22:06 601424 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6DB4A42F-95F8-45F0-A06A-0B0336F73014}\gapaengine.dll 2011-09-05 04:02 . 2009-09-10 06:28 311808 —-a-w- c:\windows\system32\msv1_0.dll 2011-09-05 04:02 . 2009-09-10 05:52 257024 —-a-w- c:\windows\SysWow64\msv1_0.dll 2011-09-05 03:59 . 2009-11-25 18:47 99176 —-a-w- c:\windows\SysWow64\PresentationHostProxy.dll 2011-09-05 03:59 . 2009-11-25 18:47 49472 —-a-w- c:\windows\SysWow64\netfxperf.dll 2011-09-05 03:59 . 2009-11-25 18:47 48960 —-a-w- c:\windows\system32\netfxperf.dll 2011-09-05 03:59 . 2009-11-25 18:47 297808 —-a-w- c:\windows\SysWow64\mscoree.dll 2011-09-05 03:59 . 2009-11-25 18:47 295264 —-a-w- c:\windows\SysWow64\PresentationHost.exe 2011-09-05 03:59 . 2009-11-25 18:47 1130824 —-a-w- c:\windows\SysWow64\dfshim.dll 2011-09-05 03:59 . 2009-11-25 18:47 109912 —-a-w- c:\windows\system32\PresentationHostProxy.dll 2011-09-05 03:59 . 2009-11-25 18:47 444752 —-a-w- c:\windows\system32\mscoree.dll 2011-09-05 03:59 . 2009-11-25 18:47 320352 —-a-w- c:\windows\system32\PresentationHost.exe 2011-09-05 03:59 . 2009-11-25 18:47 1942856 —-a-w- c:\windows\system32\dfshim.dll 2011-09-04 19:13 . 2010-09-14 06:45 367104 —-a-w- c:\windows\system32\wcncsvc.dll 2011-09-04 19:13 . 2010-09-14 06:07 276992 —-a-w- c:\windows\SysWow64\wcncsvc.dll 2011-09-04 15:31 . 2010-03-04 04:40 184832 —-a-w- c:\windows\system32\drivers\usbvideo.sys 2011-09-04 15:31 . 2010-03-04 04:32 243712 —-a-w- c:\windows\system32\drivers\ks.sys 2011-09-04 13:39 . 2011-07-09 05:14 2048 —-a-w- c:\windows\system32\tzres.dll 2011-09-04 13:39 . 2011-07-09 04:30 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2011-09-04 13:37 . 2011-04-25 02:44 499712 —-a-w- c:\windows\system32\drivers\afd.sys 2011-09-04 13:36 . 2010-08-21 06:29 558592 —-a-w- c:\windows\system32\spoolsv.exe 2011-09-04 13:35 . 2010-10-27 05:16 1739176 —-a-w- c:\windows\system32\ntdll.dll 2011-09-04 02:45 . 2009-12-29 08:03 220672 —-a-w- c:\windows\system32\wintrust.dll 2011-09-04 02:45 . 2010-01-09 07:19 139264 —-a-w- c:\windows\system32\cabview.dll 2011-09-04 02:45 . 2010-01-09 06:52 132608 —-a-w- c:\windows\SysWow64\cabview.dll 2011-09-04 02:45 . 2009-12-29 06:55 172032 —-a-w- c:\windows\SysWow64\wintrust.dll 2011-09-04 01:18 . 2011-09-03 23:57 ——– d—–w- c:\windows\Panther 2011-09-04 01:17 . 2011-09-03 23:30 ——– d—–w- c:\windows\system32\oem 2011-09-04 01:02 . 2011-09-03 23:45 ——– d—–w- C:\$WINDOWS.~Q 2011-09-04 00:58 . 2011-09-04 01:00 ——– d—–w- C:\$INPLACE.~TR 2011-09-03 23:38 . 2011-09-03 23:38 ——– d—–w- c:\users\Default\AppData\Local\Microsoft Help 2011-09-03 23:23 . 2011-09-24 15:33 ——– d—–w- c:\users\Kathy 2011-09-03 23:23 . 2011-09-25 01:02 ——– d—–w- c:\users\KATHY P 2011-09-03 23:23 . 2011-09-24 15:31 ——– d—–w- c:\users\kids 2011-09-03 23:21 . 2011-09-03 23:21 ——– d—–w- c:\program files\Apoint2K 2011-09-03 23:21 . 2011-09-03 23:25 ——– d—–w- c:\program files\CONEXANT . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-09-24 17:02 . 2011-05-24 00:54 404640 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-09-12 23:26 . 2010-05-14 03:20 9049936 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-07-16 04:32 . 2011-09-04 13:35 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2011-07-13 04:53 . 2011-08-02 03:53 8578896 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{f15ff29f-85a1-43cd-9674-e5ba40016c97}"= "c:\program files (x86)\DailyBibleGuide\bar\1.bin\2vSrcAs.dll" [2011-06-29 62864] . [HKEY_CLASSES_ROOT\clsid\{f15ff29f-85a1-43cd-9674-e5ba40016c97}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2010-05-13 26192168] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe" [2009-09-24 244480] "CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2009-06-04 103720] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208] "hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-23 150528] "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2009-11-01 1094736] "PDVD8LanguageShortcut"="c:\program files (x86)\CyberLink\PowerDVD8\Language\Language.exe" [2009-04-16 50472] "RemoteControl8"="c:\program files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe" [2009-04-16 91432] "UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504] "VideoWebCamera"="c:\program files (x86)\VideoWebCamera\VideoWebCamera.exe" [2009-11-10 1519743] "DailyBibleGuide Browser Plugin Loader"="c:\progra~2\DAILYB~1\bar\1.bin\2vbrmon.exe" [2011-06-29 30096] . c:\users\Kathy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ SetPointUpgrade.lnk - c:\users\KATHY P\AppData\Local\Temp\Logitech\SetPoint_1\Setup.exe [N/A] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-07 136176] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-07 136176] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x] R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272] R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [x] R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [x] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot64.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 DailyBibleGuideService;DailyBibleGuideService;c:\program files (x86)\DailyBibleGuide\bar\1.bin\2vbarsvc.exe [2011-06-29 42504] S2 ePowerSvc;Acer ePower Service;c:\program files\Gateway\Gateway Power Management\ePowerSvc.exe [2009-09-30 844320] S2 Greg_Service;GRegService;c:\program files (x86)\Gateway\Registration\GregHSRW.exe [2009-08-28 1150496] S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [2009-07-14 27136] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe [2009-09-24 62720] S2 Updater Service;Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [2009-07-04 240160] S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys [x] S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [x] S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2011-09-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-07 18:59] . 2011-08-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-07 18:59] . 2010-12-07 c:\windows\Tasks\ParetoLogic Registration3.job - c:\windows\system32\rundll32.exe [2009-07-13 01:14] . 2010-12-07 c:\windows\Tasks\ParetoLogic Update Version3.job - c:\program files (x86)\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2009-10-12 05:01] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-03 159232] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-03 380928] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-03 358912] "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-05-22 295936] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576] "Acer ePower Management"="c:\program files\Gateway\Gateway Power Management\ePowerTray.exe" [2009-09-30 823840] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2009-10-09 508472] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736] "PLFSetI"="c:\windows\PLFSetI.exe" [2009-11-20 200704] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.swiftcurrentonline.com/ mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\micros~1\OFFICE11\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html TCP: DhcpNameServer = 172.16.1.254 FF - ProfilePath - c:\users\Kathy\AppData\Roaming\Mozilla\Firefox\Profiles\415172rv.default\ FF - prefs.js: network.proxy.type - 0 . - - - - ORPHANS REMOVED - - - - . WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) AddRemove-BackWeb-8876480 Uninstaller - c:\windows\BWUnin-8.1.1.50-8876480SL.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10v_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10v_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10v.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe c:\program files (x86)\DailyBibleGuide\bar\1.bin\2vbrmon.exe . ************************************************************************** . Completion time: 2011-09-28 19:31:36 - machine was rebooted ComboFix-quarantined-files.txt 2011-09-29 01:31 . Pre-Run: 60,448,862,208 bytes free Post-Run: 60,172,812,288 bytes free . - - End Of File - - 678A2C202400945680EC546279D09E4C
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.









Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Here is malware bytes log, eset to follow shortly; Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 7830 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 29/09/2011 6:57:17 PM mbam-log-2011-09-29 (18-57-17).txt Scan type: Quick scan Objects scanned: 210082 Time elapsed: 2 minute(s), 21 second(s) Memory Processes Infected: 2 Memory Modules Infected: 1 Registry Keys Infected: 1 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: c:\program files (x86)\dailybibleguide\bar\1.bin\2vbarsvc.exe (Adware.MyWebSearch) -> 1612 -> Unloaded process successfully. c:\program files (x86)\dailybibleguide\bar\1.bin\2vbrmon.exe (Adware.MyWebSearch) -> 3452 -> Unloaded process successfully. Memory Modules Infected: c:\program files (x86)\dailybibleguide\bar\1.bin\2vbrstub.dll (Adware.MyWebSearch) -> Delete on reboot. Registry Keys Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DailyBibleGuideService (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DailyBibleGuide Browser Plugin Loader (Adware.MyWebSearch) -> Value: DailyBibleGuide Browser Plugin Loader -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\program files (x86)\dailybibleguide\bar\1.bin\2vbarsvc.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files (x86)\dailybibleguide\bar\1.bin\2vbrmon.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files (x86)\dailybibleguide\bar\1.bin\2vbrstub.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
This is all I'm getting from Eset; No results. No details. It quits at 50%. Doesn't paste in. Sorry, I'll have to try again after work tomorrow. It shuts down at 50% and not giving me anything. Have tried twice tonight. Getting to late now to try again.
If it won't run,try this one instead.

BitDefender Online Virus and Malware Scan here:
http://www.bitdefender.com/scan8/ie.html
* Click on I Agree.
* An ActiveX warning box will appear, click on Install.
* Under Select What You Want To Check For Viruses.
* Please Check My Computer and Click Ok
* Now Click On Click Here To Scan
* Next, Click on Click here to export the scan report
Here is Bitdefender log; QuickScan Beta 32-bit v0.9.9.99 ——————————- Scan date: Fri Sep 30 18:08:06 2011 Machine ID: A5C9BC50 No infection found. ——————- Processes ——— hpwuSchd Application 3628 C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe CyberLink MediaLibray Service 3612 C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe DefaultSettingEXE Application 2720 C:\Windows\PLFSetI.exe Gateway MyBackup 3604 C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe HP Digital Imaging 2660 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe HP Smart Web Printing 3652 C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_clipbook.exe PowerDVD RC Service 3784 C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe RAID Event Monitor 2464 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe Skype 2764 C:\Program Files (x86)\Skype\Phone\Skype.exe Video Web Camera 3808 C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe Windows® Internet Explorer 2096 C:\Program Files (x86)\Internet Explorer\iexplore.exe Windows® Internet Explorer 4008 C:\Program Files (x86)\Internet Explorer\iexplore.exe Windows® Internet Explorer 4064 C:\Program Files (x86)\Internet Explorer\iexplore.exe Network activity —————- Process iexplore.exe (2096) connected on port 443 (HTTP over SSL) –> 209.85.225.95 Process iexplore.exe (2096) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (2096) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (2096) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (2096) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (2096) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (2096) connected on port 80 (HTTP) –> 66.235.142.14 Autoruns and critical files ————————— hpwuSchd Application C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe CyberLink MediaLibray Service C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe Gateway MyBackup C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe HP Digital Imaging C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe HpqSRmon Application C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe Internet Explorer C:\Program Files (x86)\Internet Explorer Launch Manager C:\Program Files (x86)\Launch Manager\LManager.exe MUI StartMenu Application c:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe PowerDVD Language Application c:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe PowerDVD RC Service C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe Skype C:\Program Files (x86)\Skype\Phone\Skype.exe Video Web Camera C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe Windows® Internet Explorer c:\windows\syswow64\webcheck.dll (verified) Microsoft® Windows® Operating System c:\windows\system32\userinit.exe Browser plugins ————— BitDefender QuickScan C:\Windows\Downloaded Program Files\qsax.dll Coupons Inc., Coupon Printer Manager C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll Coupons Inc., Coupon Printer Manager C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll Facebook Photo Uploader 5 C:\Windows\Downloaded Program Files\PhotoUploader55.ocx Foxit Reader Plugin for Mozilla C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll Google Update C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll HP Smart Web Printing C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll HP Smart Web Printing C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll Microsoft® Windows Live ID C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll Microsoft® Windows Live ID C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL Microsoft® Windows Live ID C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL MindSpark Toolbar Platform Plugin Stub C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\NP2vStub.dll NPSWF32.dll C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll Panda ActiveScan 2.0 C:\Program Files (x86)\Panda Security\ActiveScan 2.0\npwrapper.dll Panda ActiveScan 2.0 C:\Windows\Downloaded Program Files\as2stubie.dll Silverlight Plug-In C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll Windows® Internet Explorer c:\windows\syswow64\ieframe.dll (verified) Microsoft® Windows® Operating System C:\Windows\system32\mswsock.dll (verified) Microsoft® Windows® Operating System C:\Windows\system32\napinsp.dll (verified) Microsoft® Windows® Operating System C:\Windows\system32\NLAapi.dll (verified) Microsoft® Windows® Operating System C:\Windows\system32\pnrpnsp.dll (verified) Microsoft® Windows® Operating System C:\Windows\System32\winrnr.dll Scan —- MD5: 37ca368b4c9e402e39fa52dd58d0ebd9 C:\Program Files (x86)\CyberLink\Power2Go\MSVCP71.dll MD5: 69173e71cae33f2cf242dab067672aa4 C:\Program Files (x86)\CyberLink\Power2Go\MSVCR71.dll MD5: eb7022a733078c97e32b518fcb24919c C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vSrcAs.dll MD5: 770b5419e1cdcfb818af341d2ed9b372 C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\NP2vStub.dll MD5: 1a02fc0f35e1236136a2af0bae2d1a0e C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll MD5: c44d560e441f091ea3b72f778ec60de2 C:\Program Files (x86)\Gateway Games\Gateway Game Console\GameConsoleService.exe MD5: 87bbf47f728aeee862f9823d5b4c0bbc C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll MD5: 5dd2d09a0804cf1a9443f5a3d6fe01b0 C:\Program Files (x86)\HP\Digital Imaging\bin\hpotra08.dll MD5: d9225db92d870038f1cb95b26408bbc7 C:\Program Files (x86)\HP\Digital Imaging\bin\hpotra08.rsc MD5: 384eaa703f243b6d51798ba921b799ea C:\Program Files (x86)\HP\Digital Imaging\bin\hpotradd.dll MD5: af7038413c6506180fae58b0194a2f23 C:\Program Files (x86)\HP\Digital Imaging\bin\HpqCPTA.dll MD5: 1dae5c46d42b02a6d5862e1482efb390 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll MD5: 4909501f53da2eb6603848944c45f524 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddcmn.dll MD5: 99e8eef42fe2f4af29b08c3355dd7685 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll MD5: 2c9a49f4a54fd09df13f1847ea2aedad C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddusr.dll MD5: b0a41262968dd6fce3933527892d4a24 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqmif08.dll MD5: 3c69ce161c7007e9ad53a325492d446a C:\Program Files (x86)\HP\Digital Imaging\bin\hpqrif08.dll MD5: 72860972f8196ebb3c896f53d2b95470 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe MD5: 00e86a80ca56510d2c9f09e8c6cc25c6 C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRTA.dll MD5: c23c087cebabb8b5cd6eb8dba08eb7f7 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtao08.dll MD5: b54921381a950c8215fb363b485c432b C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe MD5: 0caf25acc9c2e8c5a5682ebdcfd01708 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.rsc MD5: 4e2bfc88c6e482ea9483e6fbac3eb52e C:\Program Files (x86)\HP\Digital Imaging\bin\hpquio08.dll MD5: b4febbac47297242f04ef7f14fe6df99 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusg.dll MD5: e5e697ab8431ee8144030f81f66d9853 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqxml2.dll MD5: b07b569af5665fcb388ea4b6a0756a10 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\ClipBookDBComponent.dll MD5: a9956c8ec5d16acef896f043a80a9fb6 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_Operation.dll MD5: 6f8a654af50f13b0abdda731527f65ad C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll MD5: ac592074ac7d67ea52b9426ebee09c96 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll MD5: d749e8b62d7c2f6844f4995bb71b172a C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.dll MD5: dd0343e035d76940c52fc0c65e0e3ef0 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll MD5: fa979bd1b2fbd8d7d409532461c846d6 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll MD5: 2151d95bba7d8766ba8b5bd1f595fb3a C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll MD5: 2c9983d248c2c4d56ea275bfaffffdb1 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\xre\components\hpNeoLogging.dll MD5: dba01e33b18fd8592da0f47b99edb2d4 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\xre\components\hpXRE.dll MD5: 6966f7c128106c942f6787e78388a210 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\xre\components\js3250.dll MD5: 34ef8080d4591a495f94e95d37c04b09 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\xre\components\MOZCRT19.dll MD5: 63d5682fe31278f4eab4bf93db523886 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\xre\components\nspr4.dll MD5: 350d6d825023a4a58cf2691e2f7ca848 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\xre\components\nss3.dll MD5: 15dd623207d99f6e33d8e1b656c59e75 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\xre\components\nssutil3.dll MD5: f86062027e3e27652978cf2ac2dcf99d C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\xre\components\plc4.dll MD5: 3071da2e0aa382df856fa5eaf2f0c716 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\xre\components\plds4.dll MD5: a1474e9488527c9aed975725d6ff3449 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\xre\components\smime3.dll MD5: 0a6152534ea55f45bc29c4d17ecbeb49 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\xre\components\sqlite3.dll MD5: cad799dd070c782d02686d06dc980ac1 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\xre\components\ssl3.dll MD5: 2fbe5087b17225f035150e2f2bf7d6d0 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\xre\components\xpcom.dll MD5: 72596213ebdecb7ef1ee933df071a32b C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\xre\components\xul.dll MD5: 10cbadbb78ceee801e07f70910acc2a9 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\RsrcLoaderLib.dll MD5: f36fa84c7c1f4107433b76bd38a4389f C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\SatelliteENU.dll MD5: c6157a1233be84d05a194f46022ef619 C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\UtilityLib.dll MD5: fc4c561550e5407ffa29d4f6c69b272f C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\ENU\IAAMon_ENU.dll MD5: 984bdac9f4fc9993ce8d3a7d7da3e9a5 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\ISDI.dll MD5: 73f898c8c895f98db555e802f9bc8444 C:\Program Files (x86)\Internet Explorer\ieproxy.dll MD5: a3ab0a260049be22ab52e302d9220a92 C:\Program Files (x86)\Internet Explorer\iexplore.exe MD5: 56d1890d74a8999f756e338210846af1 C:\Program Files (x86)\Launch Manager\LManager.exe MD5: 32c9e8f42348343d72013165ea86a3c6 C:\Program Files (x86)\Microsoft Security Client\Antimalware\MpOAv.dll MD5: c3e42cbf8215171a524d123a54ae3233 C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll MD5: 2c55ccd17f459a212957ea8a88e2ecb4 C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll MD5: f73d480ae7a41cf4e8dd9e9af9869320 C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll MD5: dc96b858535f2b6c1b7e571f6b7dd003 C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe MD5: 14e66f603fb187713aeb02ad3b0390cf C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe MD5: 88d51f26487a6b48b71e974252cd3a67 C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\MUI\0409\lang.dll MD5: bd8146312ffe5f51da66e7725e989e36 C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\sqlite3.dll MD5: f73b2b26f2ca84e3e37813299fe06c28 C:\Program Files (x86)\Panda Security\ActiveScan 2.0\npwrapper.dll MD5: b0ad95433fbebe095be12eea3f8f3641 C:\Program Files (x86)\VideoWebCamera\Image.dll MD5: 59da2da8f8ef44dd525d80769d482d65 C:\Program Files (x86)\VideoWebCamera\sy_Utility.dll MD5: 900240c1821fbe3b5c76c29ec8200deb C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe MD5: 4ce47653ed2805b138187e081d3fc4b6 C:\Program Files (x86)\VideoWebCamera\VWC_ENG.dll MD5: 0a888754c63c3a5d8cd8f7492c62b40d C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL MD5: fb67aa8ac61b9365add546139a21bed6 C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe MD5: 157e9e498206a3366baa7e4697bdd947 C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe MD5: 566ddd5d82520da01d75f81428ac4c38 C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe MD5: 823451876778f382b23afe20ef2ddc20 C:\Windows\Downloaded Program Files\qsax.dll MD5: 47c071994c3f649f23d9cd075ac9304a C:\Windows\ehome\ehRecvr.exe MD5: 0862495e0c825893db75ef44faea8e93 C:\Windows\Explorer.exe MD5: fbfa45b2d8abb107c79e0ca0f8ed0a6d C:\Windows\PLFSetI.exe MD5: 5f3bdb02d64443efca7dd9248619c962 C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll MD5: 225e83f591113adec764afba0ab12593 C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll MD5: cb44e805bb7c0c9bc3b8a66a59bb300a C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll MD5: 0a58da99321d95944e796541a716cbf5 C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll MD5: ea93d50a341350321c96208f651408d0 C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll MD5: 61490bbf4d7c399bd42af6b63960fb92 C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll MD5: 267aff1ea665dbe422276601989efff3 C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll MD5: 792fc8e77dc71a5f095c32d3a5c78ea1 C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll MD5: 84cb9832f03a6aa1929636f5d9e7e298 C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll MD5: 3927fdfe073338428a24160e427e87a3 C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll MD5: 56b798396b5ad9fb064528b638a6008f C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll MD5: 77895ba5c5cdcfef66419a03b6a4cdad C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll MD5: 88955bce0a301ca342562be24415d9cc C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll MD5: 308823c5a58a4022fedd8f4db3f99a25 C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll MD5: 75959d7e5ef8fd7e7e17f40f63f3cc66 C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll MD5: 2ff5b43393e8f2c46135ac33e842b076 C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll MD5: a5750894aefe1d57cf8c460ea4065748 C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll MD5: b3758364d42bbdba18383f010fb7cfcd C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll MD5: 20f76c488929b6288733888bffe62f65 C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll MD5: 11e5a68a159bf13bcf0538bec894e0ce C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll MD5: 5cccf830959345f0b8bcc2a0dfac11b5 C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll MD5: daef44b6ff4aec4533bab3761310d4a5 C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll MD5: 62ad339f7420b022509edac1d9fd7ba1 C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll MD5: c13d2932297d3597fea7b6902efc117d C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll MD5: cdc1f7b46fc7b0b8c88df0cfbda2eb2c C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll MD5: 69ac43aae61eec7625726b377ccaaa13 C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll MD5: 5710b9bd7a3e4f716402b8119004eb48 C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll MD5: a2903ece1d115fea38bb07e01c122b5e C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll MD5: 53831de9162c6c2378574b59eb786bf1 C:\Windows\system32\corpol.dll MD5: 11cdf138552bfec115b60ed6dc3aceb6 C:\Windows\system32\DEVRTL.dll MD5: 62390f4ace9e2b63e3ca26b7f7497897 C:\Windows\system32\dnsapi.DLL MD5: 2af58d15edc06ec6fdacce1f19482bbf C:\Windows\system32\Explorer.exe MD5: 8898c95862d03d16b2a06db4db6bb6b2 C:\Windows\system32\explorerframe.dll MD5: 1af33024aa44c4d264dda65239588622 C:\Windows\system32\IEFRAME.dll MD5: 7a5b62016655d022cdf74d84bd4992f9 C:\Windows\system32\IEUI.dll MD5: 8f3b77391e30e351a0ad76c90bbc3b51 C:\Windows\system32\igdumd32.dll MD5: 6b449cdd4eabc2d5a125ada90b500c22 C:\Windows\system32\igdumdx32.dll MD5: 74c76bb54b26ce50c4bc755f92687c63 C:\Windows\system32\MFC42.DLL MD5: f1e43c5257d31e3eeaf19114117b40f7 C:\Windows\system32\msfeeds.dll MD5: 126b75d50756fe204283d418ae1a66df C:\Windows\system32\MSVCIRT.dll MD5: f6de558619784f4b44d47b9dfdc65916 C:\Windows\system32\MSVCR71.dll MD5: bd669749eaeff96773b5f8d0a43e0068 C:\Windows\System32\msxml3.dll MD5: 5764c381949147ebcfb9a7134e2abf06 C:\Windows\system32\ODBC32.dll MD5: 21cf5c7d8d727dcc337a1d251b6135f4 C:\Windows\system32\schannel.DLL MD5: 71402c7923f6b7f8acb48e50f35463e7 C:\Windows\system32\SearchIndexer.exe MD5: 8d908f346eedd752005a32787a6dcafa C:\Windows\System32\StructuredQuery.dll MD5: 7271b48b193c9624416bd5006cd8b92f C:\Windows\system32\tquery.dll MD5: 6d9b75275c3e3a5f51aef81affadb2b6 C:\Windows\System32\wcncsvc.dll MD5: bb5ec38f8d4600119b4720bc5d4211f1 C:\Windows\System32\webclnt.dll MD5: 4fb96aacf2f05c7357546becd7678863 C:\Windows\system32\webio.dll MD5: cc9bbcfc715fbedf7ae476106fe653e9 C:\Windows\system32\WINHTTP.dll MD5: 9967bce6cf289223adc2fbf311c6a78f C:\Windows\system32\wmp.dll MD5: fa05241c7bc7ebcc36af78299d0d37fe C:\Windows\system32\wmploc.dll MD5: 0c2ae180d8c35f723ba13a16aa9ac453 C:\Windows\system32\xmllite.dll MD5: e702ed19c332c1f12c1403d100e2f4f3 C:\Windows\syswow64\CFGMGR32.dll MD5: b8473011f59a6aa2b35e84aa19d707cf C:\Windows\SysWOW64\d3d10_1.dll MD5: 029e2a480ce2020df097e535a2311712 C:\Windows\SysWOW64\d3d10_1core.dll MD5: 6c9c05d5344b9ab80e9180fc859bc45a C:\Windows\syswow64\DEVOBJ.dll MD5: 1af33024aa44c4d264dda65239588622 c:\windows\syswow64\ieframe.dll MD5: 71be8f11b0993ae4f22e6866f3bd2032 C:\Windows\SysWOW64\iepeers.dll MD5: 3ab38b9bc2376194f7280f416e655e05 C:\Windows\syswow64\iertutil.dll MD5: 0bd0665d8bfd321d3b5a898ed09d1df3 C:\Windows\SysWOW64\jscript.dll MD5: 4ea99f1644627b1ebad99d0b93cdee1c C:\Windows\syswow64\kernel32.dll MD5: 2bf12696f4ac8afcfc06ead6f8d2db4c C:\Windows\syswow64\KERNELBASE.dll MD5: c09b9238479d17274a8cfb9216bcca09 C:\Windows\SysWOW64\Macromed\Flash\Flash10v.ocx MD5: 5ad4e19d583fa285f4b5ccb7784a28c2 C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll MD5: a56ebb1297f12728cf8ee028b7964e06 C:\Windows\SysWOW64\mshtml.dll MD5: 5ed76a46eff78575f99d3bf3302889cf C:\Windows\SysWOW64\ntdll.dll MD5: e2c2d8c982316c8abf800c6ce3f28fab C:\Windows\syswow64\ole32.dll MD5: 06333b8d05d4f3a2af25eb14fc0a1dff C:\Windows\syswow64\OLEAUT32.dll MD5: 3995ae73d8f31c2433981240ceec193b C:\Windows\syswow64\urlmon.dll MD5: 177df28315bf4300ecb5cbeeee961292 c:\windows\syswow64\webcheck.dll MD5: ee0d7471ebf9ce40cc4a203b1f90f028 C:\Windows\syswow64\WININET.dll MD5: 447256d1c026654c5cd3cc17e7b20631 C:\Windows\SysWOW64\XAudio64.dll MD5: 0c2ae180d8c35f723ba13a16aa9ac453 C:\Windows\SysWOW64\XmlLite.dll MD5: d5e459bed3db9cf7fc6cc1455f177d2d C:\Windows\WinSxS\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d1cb102c435421d e\ATL80.DLL MD5: 0b3595a4ff0b36d68e5fc67fd7d70fdc C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9 a\MSVCP80.dll MD5: c9564cf4976e7e96b4052737aa2492b4 C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9 a\MSVCR80.dll MD5: 64eca1f64e4a988a6c5c93f3e5d66236 C:\Windows\WinSxS\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.21022.8_none_bdf22a22ab9e15d5\ATL90.DLL MD5: b9030d821e099c79de1c9125b790e2da C:\Windows\WinSxS\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.21022.8_none_b81d038aaf540e86\mfc90u.dll MD5: 2229324ce0374811ca64a19ee62f130b C:\Windows\WinSxS\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e 1\MFC90ENU.DLL MD5: d3ead1cf16ba729a7f7c9a5d94aa7c05 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7600.16661_none_ebfb56996c72aefc\COMCTL32.dll MD5: 4b8dd8541c0e26602005dd0137333615 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll No file uploaded. Scan finished - communication took 3 sec Total traffic - 0.01 MB sent, 0.70 KB recvd Scanned 383 files and modules - 17 seconds ==============================================================================
I am not seeing any sign of infection in the logs and the automated scanners are not picking up anything,You could try posting in our Windows forum or maybe it would be best to back up any important data and restore back to factory settings.
please do the following to clean up the tools we have used,simplty delete the others.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI