This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Blue screen crash, constant freezing, slow system

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi guys. I have a dell xps m1530 at most 2 years old, running vista home premium 32 bit with t9300 processor and 4 gb ram. In the past 3 or so months my system has gone very slow. It freezes every 3 minutes atleast for a good 20 odd seconds if i am on youtube whether i have one tab open or 10. If i try to get it working again by getting the task manager out or ALT n TAB to switch windows it crashes and brings up the blue screen. :smack: Very annoying. Please help :( I attach the Hijack log below. Looking forward to getting some serious help. Thanks
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:12:09, on 05/12/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19154)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe
C:\Windows\Explorer.EXE
C:\Program Files\BitDefender\BitDefender 2011\pchooklaunch32.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\explorer.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\excell\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\PROGRA~1\COMMON~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Bitdefender Toolbar - {381FFDE8-2394-4F90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2011\IEToolbar.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2011\ieshow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe"
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: TalkTalk Setup CD Reporting Tool.exe
O4 - Global Startup: Microsoft
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\excell\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\aestsrv.exe
O23 - Service: Acronis Nonstop Backup Service (afcdpsrv) - Acronis - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Advanced Networking Service (hnmsvc) - Dell Inc. - C:\Program Files\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\STacSV.exe
O23 - Service: BitDefender Update Server v2 (Update Server) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe
O23 - Service: BitDefender Desktop Update Service (Updatesrv) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe
O23 - Service: UltraVNC Server (uvnc_service) - UltraVNC - C:\ProgramData\UltraVNC\winvnc.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: Marvell Yukon Service (yksvc) - Unknown owner - RUNDLL32.EXE (file missing)

–
End of file - 8524 bytes
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)












  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hello mowman. Thanks for your reply. I appreciate the time you have spared to help me. Heres the log from TDSS first. 13:26:08.0739 5216 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44 13:26:09.0073 5216 ============================================================ 13:26:09.0073 5216 Current date / time: 2011/12/06 13:26:09.0073 13:26:09.0073 5216 SystemInfo: 13:26:09.0073 5216 13:26:09.0073 5216 OS Version: 6.0.6002 ServicePack: 2.0 13:26:09.0073 5216 Product type: Workstation 13:26:09.0073 5216 ComputerName: EXCELL-PC 13:26:09.0074 5216 UserName: excell 13:26:09.0074 5216 Windows directory: C:\Windows 13:26:09.0074 5216 System windows directory: C:\Windows 13:26:09.0075 5216 Processor architecture: Intel x86 13:26:09.0075 5216 Number of processors: 2 13:26:09.0075 5216 Page size: 0x1000 13:26:09.0075 5216 Boot type: Normal boot 13:26:09.0075 5216 ============================================================ 13:26:10.0375 5216 Initialize success 13:26:16.0729 5004 ============================================================ 13:26:16.0729 5004 Scan started 13:26:16.0729 5004 Mode: Manual; 13:26:16.0729 5004 ============================================================ 13:26:17.0672 5004 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 13:26:17.0677 5004 ACPI - ok 13:26:17.0871 5004 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys 13:26:17.0878 5004 adp94xx - ok 13:26:18.0032 5004 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys 13:26:18.0038 5004 adpahci - ok 13:26:18.0218 5004 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys 13:26:18.0221 5004 adpu160m - ok 13:26:18.0519 5004 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys 13:26:18.0551 5004 adpu320 - ok 13:26:18.0771 5004 afcdp (53696ad8ffc5fac51949a525ff65a689) C:\Windows\system32\DRIVERS\afcdp.sys 13:26:18.0772 5004 afcdp - ok 13:26:19.0010 5004 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys 13:26:19.0028 5004 AFD - ok 13:26:19.0157 5004 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys 13:26:19.0160 5004 agp440 - ok 13:26:19.0332 5004 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 13:26:19.0336 5004 aic78xx - ok 13:26:19.0455 5004 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys 13:26:19.0458 5004 aliide - ok 13:26:19.0567 5004 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys 13:26:19.0570 5004 amdagp - ok 13:26:19.0674 5004 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys 13:26:19.0676 5004 amdide - ok 13:26:19.0842 5004 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys 13:26:19.0846 5004 AmdK7 - ok 13:26:20.0036 5004 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys 13:26:20.0039 5004 AmdK8 - ok 13:26:20.0201 5004 ApfiltrService (a80230bd04f0b8bf05185b369bb1cbb8) C:\Windows\system32\DRIVERS\Apfiltr.sys 13:26:20.0212 5004 ApfiltrService - ok 13:26:20.0407 5004 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys 13:26:20.0410 5004 arc - ok 13:26:20.0576 5004 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys 13:26:20.0579 5004 arcsas - ok 13:26:20.0762 5004 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 13:26:20.0764 5004 AsyncMac - ok 13:26:20.0912 5004 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 13:26:20.0913 5004 atapi - ok 13:26:21.0152 5004 avc3 (a16df078cc2927005581054a3fdde00f) C:\Windows\system32\DRIVERS\avc3.sys 13:26:21.0180 5004 avc3 - ok 13:26:21.0387 5004 avckf (3dbfcdb49d7520a7425e59a143b8856b) C:\Windows\system32\DRIVERS\avckf.sys 13:26:21.0414 5004 avckf - ok 13:26:21.0509 5004 BCM42RLY - ok 13:26:21.0649 5004 BCM43XX (cdf7f28ffd693b1b4137845dd1ef1ccc) C:\Windows\system32\DRIVERS\bcmwl6.sys 13:26:21.0665 5004 BCM43XX - ok 13:26:21.0799 5004 bdfm (8d4efc5c378bffe34c298c92f37d3b14) C:\Windows\system32\DRIVERS\bdfm.sys 13:26:21.0801 5004 bdfm - ok 13:26:21.0924 5004 Bdfndisf (817fc12bc93a70b0449ebefaa4d6f4d2) c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys 13:26:21.0934 5004 Bdfndisf - ok 13:26:22.0040 5004 bdfsfltr (c3e025d46368e3d18085eef26ef6f6a1) C:\Windows\system32\DRIVERS\bdfsfltr.sys 13:26:22.0043 5004 bdfsfltr - ok 13:26:22.0186 5004 Bdftdif (c23a8547d5ea6d0c3589961bfb7ff6d3) C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys 13:26:22.0195 5004 Bdftdif - ok 13:26:22.0353 5004 bdselfpr (2daa9e807c11b4677cafc1e43a98f8ce) C:\Program Files\BitDefender\BitDefender 2011\bdselfpr.sys 13:26:22.0354 5004 bdselfpr - ok 13:26:22.0496 5004 Bdvedisk (375cd0b9f433465ec6f50d4df44e9448) C:\Windows\system32\DRIVERS\bdvedisk.sys 13:26:22.0505 5004 Bdvedisk - ok 13:26:22.0671 5004 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 13:26:22.0673 5004 Beep - ok 13:26:22.0814 5004 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys 13:26:22.0819 5004 blbdrive - ok 13:26:22.0943 5004 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys 13:26:22.0944 5004 bowser - ok 13:26:23.0070 5004 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 13:26:23.0073 5004 BrFiltLo - ok 13:26:23.0244 5004 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 13:26:23.0246 5004 BrFiltUp - ok 13:26:23.0404 5004 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 13:26:23.0409 5004 Brserid - ok 13:26:23.0668 5004 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 13:26:23.0735 5004 BrSerWdm - ok 13:26:23.0908 5004 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 13:26:23.0910 5004 BrUsbMdm - ok 13:26:24.0066 5004 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 13:26:24.0068 5004 BrUsbSer - ok 13:26:24.0256 5004 BthEnum (6d39c954799b63ba866910234cf7d726) C:\Windows\system32\DRIVERS\BthEnum.sys 13:26:24.0258 5004 BthEnum - ok 13:26:24.0392 5004 BTHMODEM (9a966a8e86d1771911ae34a20d11bff3) C:\Windows\system32\DRIVERS\bthmodem.sys 13:26:24.0394 5004 BTHMODEM - ok 13:26:24.0564 5004 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys 13:26:24.0567 5004 BthPan - ok 13:26:24.0728 5004 BTHPORT (611ff3f2f095c8d4a6d4cfd9dcc09793) C:\Windows\system32\Drivers\BTHport.sys 13:26:24.0747 5004 BTHPORT - ok 13:26:24.0875 5004 BTHUSB (d330803eab2a15caec7f011f1d4cb30e) C:\Windows\system32\Drivers\BTHUSB.sys 13:26:24.0883 5004 BTHUSB - ok 13:26:25.0079 5004 btwaudio (4a28e7bd365377d0512b7ef8c7596d2c) C:\Windows\system32\drivers\btwaudio.sys 13:26:25.0089 5004 btwaudio - ok 13:26:25.0245 5004 btwavdt (5ffde57253d665067b0886612817eb11) C:\Windows\system32\drivers\btwavdt.sys 13:26:25.0258 5004 btwavdt - ok 13:26:25.0438 5004 btwrchid (ab07dc8b05c31a4f95fc73019be9db15) C:\Windows\system32\DRIVERS\btwrchid.sys 13:26:25.0448 5004 btwrchid - ok 13:26:25.0586 5004 catchme - ok 13:26:25.0783 5004 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 13:26:25.0786 5004 cdfs - ok 13:26:25.0992 5004 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 13:26:25.0994 5004 cdrom - ok 13:26:26.0173 5004 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys 13:26:26.0176 5004 circlass - ok 13:26:26.0298 5004 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 13:26:26.0303 5004 CLFS - ok 13:26:26.0484 5004 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys 13:26:26.0486 5004 CmBatt - ok 13:26:26.0606 5004 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys 13:26:26.0607 5004 cmdide - ok 13:26:26.0735 5004 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys 13:26:26.0736 5004 Compbatt - ok 13:26:26.0858 5004 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys 13:26:26.0859 5004 crcdisk - ok 13:26:26.0983 5004 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys 13:26:26.0986 5004 Crusoe - ok 13:26:27.0218 5004 CtClsFlt (281b2b60b5cb449bcf0474eecf73ebec) C:\Windows\system32\DRIVERS\CtClsFlt.sys 13:26:27.0234 5004 CtClsFlt - ok 13:26:27.0466 5004 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys 13:26:27.0469 5004 DfsC - ok 13:26:27.0686 5004 DFUBTUSB - ok 13:26:27.0928 5004 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 13:26:27.0930 5004 disk - ok 13:26:28.0104 5004 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 13:26:28.0106 5004 drmkaud - ok 13:26:28.0268 5004 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 13:26:28.0271 5004 DXGKrnl - ok 13:26:28.0416 5004 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys 13:26:28.0419 5004 E1G60 - ok 13:26:28.0623 5004 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 13:26:28.0626 5004 Ecache - ok 13:26:28.0796 5004 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys 13:26:28.0803 5004 elxstor - ok 13:26:29.0017 5004 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys 13:26:29.0020 5004 ErrDev - ok 13:26:29.0344 5004 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 13:26:29.0349 5004 exfat - ok 13:26:29.0561 5004 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 13:26:29.0567 5004 fastfat - ok 13:26:29.0695 5004 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys 13:26:29.0699 5004 fdc - ok 13:26:29.0873 5004 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 13:26:29.0877 5004 FileInfo - ok 13:26:30.0068 5004 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 13:26:30.0070 5004 Filetrace - ok 13:26:30.0236 5004 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 13:26:30.0237 5004 flpydisk - ok 13:26:30.0391 5004 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 13:26:30.0394 5004 FltMgr - ok 13:26:30.0617 5004 fssfltr (d909075fa72c090f27aa926c32cb4612) C:\Windows\system32\DRIVERS\fssfltr.sys 13:26:30.0618 5004 fssfltr - ok 13:26:30.0759 5004 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 13:26:30.0761 5004 Fs_Rec - ok 13:26:30.0871 5004 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys 13:26:30.0875 5004 gagp30kx - ok 13:26:31.0061 5004 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys 13:26:31.0067 5004 HdAudAddService - ok 13:26:31.0256 5004 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 13:26:31.0265 5004 HDAudBus - ok 13:26:31.0418 5004 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 13:26:31.0420 5004 HidBth - ok 13:26:31.0599 5004 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 13:26:31.0601 5004 HidIr - ok 13:26:31.0781 5004 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 13:26:31.0783 5004 HidUsb - ok 13:26:31.0962 5004 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys 13:26:31.0964 5004 HpCISSs - ok 13:26:32.0109 5004 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 13:26:32.0116 5004 HTTP - ok 13:26:32.0247 5004 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys 13:26:32.0249 5004 i2omp - ok 13:26:32.0404 5004 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 13:26:32.0511 5004 i8042prt - ok 13:26:32.0799 5004 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys 13:26:32.0804 5004 iaStorV - ok 13:26:32.0952 5004 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 13:26:32.0956 5004 iirsp - ok 13:26:33.0067 5004 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 13:26:33.0069 5004 intelide - ok 13:26:33.0198 5004 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 13:26:33.0199 5004 intelppm - ok 13:26:33.0321 5004 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 13:26:33.0325 5004 IpFilterDriver - ok 13:26:33.0463 5004 IpInIp - ok 13:26:33.0537 5004 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys 13:26:33.0540 5004 IPMIDRV - ok 13:26:33.0600 5004 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 13:26:33.0603 5004 IPNAT - ok 13:26:33.0729 5004 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 13:26:33.0731 5004 IRENUM - ok 13:26:33.0832 5004 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys 13:26:33.0839 5004 isapnp - ok 13:26:33.0928 5004 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 13:26:33.0930 5004 iScsiPrt - ok 13:26:34.0060 5004 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 13:26:34.0063 5004 iteatapi - ok 13:26:34.0168 5004 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 13:26:34.0170 5004 iteraid - ok 13:26:34.0261 5004 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 13:26:34.0262 5004 kbdclass - ok 13:26:34.0355 5004 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 13:26:34.0357 5004 kbdhid - ok 13:26:34.0463 5004 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys 13:26:34.0470 5004 KSecDD - ok 13:26:34.0528 5004 Lavasoft Kernexplorer - ok 13:26:34.0678 5004 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 13:26:34.0680 5004 lltdio - ok 13:26:34.0828 5004 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys 13:26:34.0831 5004 LSI_FC - ok 13:26:34.0957 5004 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys 13:26:34.0960 5004 LSI_SAS - ok 13:26:35.0108 5004 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys 13:26:35.0110 5004 LSI_SCSI - ok 13:26:35.0253 5004 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 13:26:35.0256 5004 luafv - ok 13:26:35.0348 5004 MBAMProtector (69a6268d7f81e53d568ab4e7e991caf3) C:\Windows\system32\drivers\mbam.sys 13:26:35.0349 5004 MBAMProtector - ok 13:26:35.0415 5004 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys 13:26:35.0418 5004 megasas - ok 13:26:35.0558 5004 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys 13:26:35.0565 5004 MegaSR - ok 13:26:35.0661 5004 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 13:26:35.0663 5004 Modem - ok 13:26:35.0751 5004 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 13:26:35.0752 5004 monitor - ok 13:26:35.0844 5004 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 13:26:35.0846 5004 mouclass - ok 13:26:35.0931 5004 moufiltr (baa4ed3c323bee7ebc144c7d232220a8) C:\Windows\system32\DRIVERS\moufiltr.sys 13:26:35.0939 5004 moufiltr - ok 13:26:35.0990 5004 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 13:26:35.0991 5004 mouhid - ok 13:26:36.0086 5004 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 13:26:36.0087 5004 MountMgr - ok 13:26:36.0208 5004 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys 13:26:36.0211 5004 mpio - ok 13:26:36.0370 5004 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 13:26:36.0373 5004 mpsdrv - ok 13:26:36.0505 5004 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 13:26:36.0508 5004 Mraid35x - ok 13:26:36.0595 5004 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 13:26:36.0598 5004 MRxDAV - ok 13:26:36.0684 5004 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys 13:26:36.0686 5004 mrxsmb - ok 13:26:36.0841 5004 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys 13:26:36.0845 5004 mrxsmb10 - ok 13:26:36.0961 5004 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 13:26:36.0962 5004 mrxsmb20 - ok 13:26:37.0111 5004 msahci (5457dcfa7c0da43522f4d9d4049c1472) C:\Windows\system32\drivers\msahci.sys 13:26:37.0112 5004 msahci - ok 13:26:37.0172 5004 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys 13:26:37.0175 5004 msdsm - ok 13:26:37.0400 5004 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 13:26:37.0402 5004 Msfs - ok 13:26:37.0560 5004 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 13:26:37.0561 5004 msisadrv - ok 13:26:37.0748 5004 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 13:26:37.0751 5004 MSKSSRV - ok 13:26:37.0872 5004 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 13:26:37.0874 5004 MSPCLOCK - ok 13:26:37.0993 5004 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 13:26:37.0996 5004 MSPQM - ok 13:26:38.0114 5004 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 13:26:38.0117 5004 MsRPC - ok 13:26:38.0251 5004 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 13:26:38.0253 5004 mssmbios - ok 13:26:38.0570 5004 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 13:26:38.0572 5004 MSTEE - ok 13:26:38.0786 5004 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 13:26:38.0788 5004 Mup - ok 13:26:38.0996 5004 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 13:26:38.0998 5004 NativeWifiP - ok 13:26:39.0257 5004 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 13:26:39.0267 5004 NDIS - ok 13:26:39.0486 5004 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 13:26:39.0489 5004 NdisTapi - ok 13:26:39.0692 5004 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 13:26:39.0693 5004 Ndisuio - ok 13:26:39.0822 5004 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 13:26:39.0825 5004 NdisWan - ok 13:26:39.0916 5004 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 13:26:39.0918 5004 NDProxy - ok 13:26:40.0044 5004 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 13:26:40.0046 5004 NetBIOS - ok 13:26:40.0211 5004 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 13:26:40.0215 5004 netbt - ok 13:26:40.0475 5004 NETw4v32 (6522dd40a5f67ced020bd81b856613fb) C:\Windows\system32\DRIVERS\NETw4v32.sys 13:26:40.0574 5004 NETw4v32 - ok 13:26:40.0738 5004 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 13:26:40.0740 5004 nfrd960 - ok 13:26:40.0880 5004 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 13:26:40.0883 5004 Npfs - ok 13:26:41.0037 5004 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 13:26:41.0039 5004 nsiproxy - ok 13:26:41.0277 5004 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 13:26:41.0287 5004 Ntfs - ok 13:26:41.0402 5004 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 13:26:41.0405 5004 ntrigdigi - ok 13:26:41.0500 5004 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 13:26:41.0503 5004 Null - ok 13:26:42.0147 5004 nvlddmkm (bd409de5681c74c1de51d72427dc202d) C:\Windows\system32\DRIVERS\nvlddmkm.sys 13:26:42.0222 5004 nvlddmkm - ok 13:26:42.0393 5004 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys 13:26:42.0396 5004 nvraid - ok 13:26:42.0545 5004 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys 13:26:42.0547 5004 nvstor - ok 13:26:42.0625 5004 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys 13:26:42.0629 5004 nv_agp - ok 13:26:42.0663 5004 NwlnkFlt - ok 13:26:42.0841 5004 NwlnkFwd - ok 13:26:43.0012 5004 OEM02Dev (19cac780b858822055f46c58a111723c) C:\Windows\system32\DRIVERS\OEM02Dev.sys 13:26:43.0027 5004 OEM02Dev - ok 13:26:43.0130 5004 OEM02Vfx (86326062a90494bdd79ce383511d7d69) C:\Windows\system32\DRIVERS\OEM02Vfx.sys 13:26:43.0137 5004 OEM02Vfx - ok 13:26:43.0271 5004 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys 13:26:43.0273 5004 ohci1394 - ok 13:26:43.0397 5004 Packet (9d80e0be979c3edaf2863f23b88f4de6) C:\Windows\system32\DRIVERS\packet.sys 13:26:43.0398 5004 Packet - ok 13:26:43.0439 5004 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 13:26:43.0442 5004 Parport - ok 13:26:43.0569 5004 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 13:26:43.0571 5004 partmgr - ok 13:26:43.0729 5004 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 13:26:43.0730 5004 Parvdm - ok 13:26:43.0872 5004 PCD5SRVC{3F6A8B78-EC003E00-05040104} (42ede7d217325ff56cb8a9983cd7f73b) C:\PROGRA~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms 13:26:43.0929 5004 PCD5SRVC{3F6A8B78-EC003E00-05040104} - ok 13:26:44.0033 5004 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 13:26:44.0036 5004 pci - ok 13:26:44.0143 5004 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\DRIVERS\pciide.sys 13:26:44.0144 5004 pciide - ok 13:26:44.0257 5004 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 13:26:44.0261 5004 pcmcia - ok 13:26:44.0389 5004 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 13:26:44.0402 5004 PEAUTH - ok 13:26:44.0524 5004 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 13:26:44.0527 5004 PptpMiniport - ok 13:26:44.0632 5004 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys 13:26:44.0635 5004 Processor - ok 13:26:44.0779 5004 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 13:26:44.0782 5004 PSched - ok 13:26:44.0986 5004 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys 13:26:45.0004 5004 ql2300 - ok 13:26:45.0103 5004 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 13:26:45.0106 5004 ql40xx - ok 13:26:45.0208 5004 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 13:26:45.0210 5004 QWAVEdrv - ok 13:26:45.0340 5004 RapportCerberus_32301 (2fccc769cdba34c6ab6183aa4d2f7519) C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_32301.sys 13:26:45.0350 5004 RapportCerberus_32301 - ok 13:26:45.0460 5004 RapportEI (5074fe56c70b31909c6b3129280c4cf2) C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys 13:26:45.0461 5004 RapportEI - ok 13:26:45.0583 5004 RapportIaso (dd3e4610de9252a957c5bd19bdf47ac4) c:\programdata\trusteer\rapport\store\exts\rapportms\28896\rapportiaso.sys 13:26:45.0584 5004 RapportIaso - ok 13:26:45.0653 5004 RapportKELL (d6c7c196ad59375e9dde68d70db6e7a1) C:\Windows\system32\Drivers\RapportKELL.sys 13:26:45.0654 5004 RapportKELL - ok 13:26:45.0782 5004 RapportPG (1205f9ccc78d152a5cc509f5ee32800d) C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys 13:26:45.0784 5004 RapportPG - ok 13:26:45.0852 5004 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 13:26:45.0854 5004 RasAcd - ok 13:26:45.0954 5004 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 13:26:45.0957 5004 Rasl2tp - ok 13:26:46.0090 5004 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 13:26:46.0093 5004 RasPppoe - ok 13:26:46.0262 5004 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 13:26:46.0264 5004 RasSstp - ok 13:26:46.0365 5004 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 13:26:46.0370 5004 rdbss - ok 13:26:46.0456 5004 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 13:26:46.0458 5004 RDPCDD - ok 13:26:46.0485 5004 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys 13:26:46.0491 5004 rdpdr - ok 13:26:46.0578 5004 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 13:26:46.0580 5004 RDPENCDD - ok 13:26:46.0762 5004 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys 13:26:46.0766 5004 RDPWD - ok 13:26:47.0170 5004 RFCOMM (6482707f9f4da0ecbab43b2e0398a101) C:\Windows\system32\DRIVERS\rfcomm.sys 13:26:47.0175 5004 RFCOMM - ok 13:26:47.0300 5004 rimmptsk (c2ef513bbe069f0d4ee0938a76f975d3) C:\Windows\system32\DRIVERS\rimmptsk.sys 13:26:47.0308 5004 rimmptsk - ok 13:26:47.0472 5004 rimsptsk (c398bca91216755b098679a8da8a2300) C:\Windows\system32\DRIVERS\rimsptsk.sys 13:26:47.0481 5004 rimsptsk - ok 13:26:47.0605 5004 rismxdp (2a2554cb24506e0a0508fc395c4a1b42) C:\Windows\system32\DRIVERS\rixdptsk.sys 13:26:47.0614 5004 rismxdp - ok 13:26:47.0716 5004 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 13:26:47.0717 5004 rspndr - ok 13:26:47.0800 5004 SASDIFSV (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 13:26:47.0807 5004 SASDIFSV - ok 13:26:47.0824 5004 SASKUTIL (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 13:26:47.0833 5004 SASKUTIL - ok 13:26:47.0903 5004 SbieDrv (acd898d5494b8f3ec3c38cf12d225924) C:\Program Files\Sandboxie\SbieDrv.sys 13:26:47.0938 5004 SbieDrv - ok 13:26:48.0066 5004 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 13:26:48.0068 5004 sbp2port - ok 13:26:48.0190 5004 sdbus (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys 13:26:48.0192 5004 sdbus - ok 13:26:48.0305 5004 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 13:26:48.0306 5004 secdrv - ok 13:26:48.0639 5004 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 13:26:48.0641 5004 Serenum - ok 13:26:48.0782 5004 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 13:26:48.0785 5004 Serial - ok 13:26:49.0051 5004 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 13:26:49.0053 5004 sermouse - ok 13:26:49.0236 5004 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys 13:26:49.0238 5004 sffdisk - ok 13:26:49.0339 5004 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys 13:26:49.0342 5004 sffp_mmc - ok 13:26:49.0444 5004 sffp_sd (9f66a46c55d6f1ccabc79bb7afccc545) C:\Windows\system32\DRIVERS\sffp_sd.sys 13:26:49.0445 5004 sffp_sd - ok 13:26:49.0704 5004 sfloppy (c33bfbd6e9e41fcd9ffef9729e9faed6) C:\Windows\system32\DRIVERS\sfloppy.sys 13:26:49.0706 5004 sfloppy - ok 13:26:49.0861 5004 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys 13:26:49.0864 5004 sisagp - ok 13:26:50.0012 5004 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys 13:26:50.0014 5004 SiSRaid2 - ok 13:26:50.0190 5004 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys 13:26:50.0193 5004 SiSRaid4 - ok 13:26:50.0282 5004 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 13:26:50.0286 5004 Smb - ok 13:26:50.0451 5004 snapman (eb49860e776ce860dc3cfb9edb1ba517) C:\Windows\system32\DRIVERS\snapman.sys 13:26:50.0453 5004 snapman - ok 13:26:50.0542 5004 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 13:26:50.0543 5004 spldr - ok 13:26:50.0723 5004 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys 13:26:50.0727 5004 srv - ok 13:26:50.0819 5004 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys 13:26:50.0821 5004 srv2 - ok 13:26:51.0080 5004 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys 13:26:51.0082 5004 srvnet - ok 13:26:51.0270 5004 StarOpen (306521935042fc0a6988d528643619b3) C:\Windows\system32\drivers\StarOpen.sys 13:26:51.0279 5004 StarOpen - ok 13:26:51.0498 5004 STHDA (68a0d39e357dd7a234b1d4f1e844c615) C:\Windows\system32\DRIVERS\stwrt.sys 13:26:51.0521 5004 STHDA - ok 13:26:51.0621 5004 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 13:26:51.0622 5004 swenum - ok 13:26:51.0864 5004 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 13:26:51.0867 5004 Symc8xx - ok 13:26:52.0001 5004 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 13:26:52.0002 5004 Sym_hi - ok 13:26:52.0134 5004 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 13:26:52.0137 5004 Sym_u3 - ok 13:26:52.0319 5004 Tcpip (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys 13:26:52.0330 5004 Tcpip - ok 13:26:52.0508 5004 Tcpip6 (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys 13:26:52.0513 5004 Tcpip6 - ok 13:26:52.0674 5004 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys 13:26:52.0676 5004 tcpipreg - ok 13:26:52.0851 5004 TcUsb (53900527fa5e2ccc818c5894383772d1) C:\Windows\system32\Drivers\tcusb.sys 13:26:52.0852 5004 TcUsb - ok 13:26:53.0087 5004 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 13:26:53.0089 5004 TDPIPE - ok 13:26:53.0342 5004 tdrpman273 (431801fcc97034e04a6eff81136578d7) C:\Windows\system32\DRIVERS\tdrpm273.sys 13:26:53.0354 5004 tdrpman273 - ok 13:26:53.0497 5004 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 13:26:53.0500 5004 TDTCP - ok 13:26:53.0691 5004 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 13:26:53.0694 5004 tdx - ok 13:26:53.0869 5004 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 13:26:53.0871 5004 TermDD - ok 13:26:54.0085 5004 timounter (a34d7024bb7140ec785c86bc065d4f60) C:\Windows\system32\DRIVERS\timntr.sys 13:26:54.0091 5004 timounter - ok 13:26:54.0244 5004 Trufos (a919775c03303d0e0690b315d26a5e1d) C:\Windows\system32\DRIVERS\Trufos.sys 13:26:54.0246 5004 Trufos - ok 13:26:54.0374 5004 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 13:26:54.0375 5004 tssecsrv - ok 13:26:54.0594 5004 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 13:26:54.0596 5004 tunmp - ok 13:26:54.0729 5004 tunnel (119b8184e106baedc83fce5ddf3950da) C:\Windows\system32\DRIVERS\tunnel.sys 13:26:54.0731 5004 tunnel - ok 13:26:54.0813 5004 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys 13:26:54.0816 5004 uagp35 - ok 13:26:54.0880 5004 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 13:26:54.0885 5004 udfs - ok 13:26:55.0037 5004 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys 13:26:55.0040 5004 uliagpkx - ok 13:26:55.0264 5004 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys 13:26:55.0270 5004 uliahci - ok 13:26:55.0480 5004 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 13:26:55.0483 5004 UlSata - ok 13:26:55.0769 5004 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 13:26:55.0773 5004 ulsata2 - ok 13:26:56.0074 5004 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 13:26:56.0077 5004 umbus - ok 13:26:56.0117 5004 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 13:26:56.0121 5004 usbccgp - ok 13:26:56.0260 5004 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 13:26:56.0263 5004 usbcir - ok 13:26:56.0371 5004 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 13:26:56.0373 5004 usbehci - ok 13:26:56.0477 5004 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 13:26:56.0481 5004 usbhub - ok 13:26:56.0566 5004 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 13:26:56.0569 5004 usbohci - ok 13:26:56.0627 5004 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 13:26:56.0630 5004 usbprint - ok 13:26:56.0862 5004 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys 13:26:56.0865 5004 usbscan - ok 13:26:57.0026 5004 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 13:26:57.0029 5004 USBSTOR - ok 13:26:57.0164 5004 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 13:26:57.0167 5004 usbuhci - ok 13:26:57.0341 5004 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys 13:26:57.0346 5004 usbvideo - ok 13:26:57.0560 5004 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 13:26:57.0563 5004 vga - ok 13:26:57.0701 5004 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 13:26:57.0704 5004 VgaSave - ok 13:26:57.0829 5004 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys 13:26:57.0835 5004 viaagp - ok 13:26:57.0971 5004 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys 13:26:57.0974 5004 ViaC7 - ok 13:26:58.0127 5004 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys 13:26:58.0129 5004 viaide - ok 13:26:58.0294 5004 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 13:26:58.0295 5004 volmgr - ok 13:26:58.0445 5004 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 13:26:58.0450 5004 volmgrx - ok 13:26:58.0574 5004 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 13:26:58.0578 5004 volsnap - ok 13:26:58.0701 5004 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys 13:26:58.0704 5004 vsmraid - ok 13:26:58.0873 5004 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 13:26:58.0875 5004 WacomPen - ok 13:26:59.0092 5004 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 13:26:59.0095 5004 Wanarp - ok 13:26:59.0112 5004 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 13:26:59.0114 5004 Wanarpv6 - ok 13:26:59.0261 5004 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys 13:26:59.0263 5004 Wd - ok 13:26:59.0457 5004 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 13:26:59.0465 5004 Wdf01000 - ok 13:26:59.0761 5004 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys 13:26:59.0762 5004 WmiAcpi - ok 13:26:59.0944 5004 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 13:26:59.0946 5004 ws2ifsl - ok 13:27:00.0138 5004 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 13:27:00.0140 5004 WUDFRd - ok 13:27:00.0269 5004 yukonwlh (1a51df1a5c658d534ed980d18f7982de) C:\Windows\system32\DRIVERS\yk60x86.sys 13:27:00.0273 5004 yukonwlh - ok 13:27:00.0321 5004 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 13:27:00.0336 5004 \Device\Harddisk0\DR0 - ok 13:27:00.0340 5004 Boot (0x1200) (0c773c7bc7be3383b54e5a3cd0721d11) \Device\Harddisk0\DR0\Partition0 13:27:00.0341 5004 \Device\Harddisk0\DR0\Partition0 - ok 13:27:00.0343 5004 ============================================================ 13:27:00.0343 5004 Scan finished 13:27:00.0343 5004 ============================================================ 13:27:00.0353 0288 Detected object count: 0 13:27:00.0353 0288 Actual detected object count: 0
Heres my log from OTL.

OTL logfile created on: 06/12/2011 13:34:04 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\excell\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19154)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.50 Gb Total Physical Memory | 2.33 Gb Available Physical Memory | 66.69% Memory free
7.18 Gb Paging File | 5.96 Gb Available in Paging File | 82.98% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 120.24 Gb Free Space | 51.63% Space Free | Partition Type: NTFS

Computer Name: EXCELL-PC | User Name: excell | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\excell\Desktop\OTL(1).exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
PRC - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe (BitDefender S.R.L.)
PRC - C:\Program Files\BitDefender\BitDefender 2011\pchooklaunch32.exe (BitDefender S.R.L.)
PRC - C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe (BitDefender S.R.L.)
PRC - C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe (BitDefender S.R.L.)
PRC - C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Common Files\Dell\Advanced Networking Service\hnm_svc.exe (Dell Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\ProgramData\UltraVNC\winvnc.exe (UltraVNC)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Fingerprint Reader Suite\upeksvr.exe (UPEK Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Trusteer\Rapport\bin\js32.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\6d2f689baff5da3df134fdec0742a13c\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c1c06a392871267db27f7cbc40e1c4fb\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\28896\RapportMS.dll ()
MOD - C:\Program Files\BitDefender\BitDefender 2011\connector.dll ()
MOD - C:\Program Files\BitDefender\BitDefender 2011\txmlutil.dll ()
MOD - C:\Program Files\BitDefender\BitDefender 2011\framework.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Windows\System32\bcmwlrmt.dll ()


========== Win32 Services (SafeList) ==========

SRV - (afcdpsrv) – C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (RapportMgmtService) – C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Updatesrv) – C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe (BitDefender S.R.L.)
SRV - (VSSERV) – C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe (BitDefender S.R.L.)
SRV - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (Update Server) – C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe (BitDefender)
SRV - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (hnmsvc) – C:\Program Files\Common Files\Dell\Advanced Networking Service\hnm_svc.exe (Dell Inc.)
SRV - (dsl-fs-sync) – C:\Program Files\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe (SingleClick Systems)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (CinemaNow Service) – C:\Program Files\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe (CinemaNow, Inc.)
SRV - (uvnc_service) – C:\ProgramData\UltraVNC\winvnc.exe (UltraVNC)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\stacsv.exe (IDT, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Apache2.2) – C:\Program Files\Common Files\Dell\apache\bin\httpd.exe (Apache Software Foundation)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (dsl-db) – C:\Program Files\Common Files\Dell\MySQL\bin\mysqld.exe ()


========== Driver Services (SafeList) ==========

DRV - (afcdp) – C:\Windows\System32\drivers\afcdp.sys (Acronis)
DRV - (tdrpman273) Acronis Try&Decide; and Restore Points filter (build 273) – C:\Windows\system32\DRIVERS\tdrpm273.sys (Acronis)
DRV - (timounter) – C:\Windows\system32\DRIVERS\timntr.sys (Acronis)
DRV - (snapman) – C:\Windows\system32\DRIVERS\snapman.sys (Acronis)
DRV - (RapportCerberus_32301) – C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_32301.sys ()
DRV - (RapportEI) – C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys (Trusteer Ltd.)
DRV - (RapportPG) – C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys (Trusteer Ltd.)
DRV - (RapportKELL) – C:\Windows\System32\Drivers\RapportKELL.sys (Trusteer Ltd.)
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (RapportIaso) – c:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\28896\RapportIaso.sys (Trusteer Ltd.)
DRV - (Trufos) – C:\Windows\System32\drivers\trufos.sys (BitDefender S.R.L.)
DRV - (bdselfpr) – C:\Program Files\BitDefender\BitDefender 2011\bdselfpr.sys (BitDefender LLC)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SbieDrv) – C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV - (bdfsfltr) – C:\Windows\system32\DRIVERS\bdfsfltr.sys (BitDefender)
DRV - (avckf) – C:\Windows\System32\drivers\avckf.sys (BitDefender)
DRV - (avc3) – C:\Windows\System32\drivers\avc3.sys (BitDefender)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (Bdftdif) – C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys (BitDefender LLC)
DRV - (Bdfndisf) – c:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfndisf6.sys (BitDefender)
DRV - (bdfm) – C:\Windows\System32\drivers\bdfm.sys (BitDefender S.R.L. Bucharest, ROMANIA)
DRV - (Bdvedisk) – C:\Windows\System32\drivers\bdvedisk.sys (BitDefender)
DRV - (CtClsFlt) – C:\Windows\System32\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV - (PCD5SRVC{3F6A8B78-EC003E00-05040104}) – C:\Program Files\Dell Support Center\HWDiag\bin\pcd5srvc.pkms (PC-Doctor, Inc.)
DRV - (Packet) – C:\Windows\System32\drivers\packet.sys (SingleClick Systems)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (circlass) – C:\Windows\system32\drivers\circlass.sys ()
DRV - (Wd) – C:\Windows\system32\drivers\wd.sys ()
DRV - (sffp_mmc) – C:\Windows\system32\drivers\sffp_mmc.sys ()
DRV - (IPMIDRV) – C:\Windows\system32\drivers\ipmidrv.sys ()
DRV - (gagp30kx) – C:\Windows\system32\drivers\gagp30kx.sys ()
DRV - (uagp35) – C:\Windows\system32\drivers\uagp35.sys ()
DRV - (msdsm) – C:\Windows\system32\drivers\msdsm.sys ()
DRV - (mpio) – C:\Windows\system32\drivers\mpio.sys ()
DRV - (sermouse) – C:\Windows\system32\drivers\sermouse.sys ()
DRV - (i2omp) – C:\Windows\system32\drivers\i2omp.sys ()
DRV - (rdpdr) – C:\Windows\system32\drivers\rdpdr.sys ()
DRV - (nv_agp) – C:\Windows\system32\drivers\nv_agp.sys ()
DRV - (uliagpkx) – C:\Windows\system32\drivers\uliagpkx.sys ()
DRV - (viaagp) – C:\Windows\system32\drivers\viaagp.sys ()
DRV - (agp440) – C:\Windows\system32\drivers\agp440.sys ()
DRV - (isapnp) – C:\Windows\system32\drivers\isapnp.sys ()
DRV - (blbdrive) – C:\Windows\system32\drivers\blbdrive.sys ()
DRV - (AmdK8) – C:\Windows\system32\drivers\amdk8.sys ()
DRV - (ViaC7) – C:\Windows\system32\drivers\viac7.sys ()
DRV - (AmdK7) – C:\Windows\system32\drivers\amdk7.sys ()
DRV - (Processor) – C:\Windows\system32\drivers\processr.sys ()
DRV - (Crusoe) – C:\Windows\system32\drivers\crusoe.sys ()
DRV - (amdide) – C:\Windows\system32\drivers\amdide.sys ()
DRV - (ErrDev) – C:\Windows\system32\drivers\errdev.sys ()
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (OEM02Dev) – C:\Windows\System32\drivers\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (NETw4v32) Intel® – C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (OEM02Vfx) – C:\Windows\System32\drivers\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (moufiltr) – C:\Windows\System32\drivers\moufiltr.sys (Chic)
DRV - (pcmcia) – C:\Windows\system32\drivers\pcmcia.sys ()
DRV - (sbp2port) – C:\Windows\system32\drivers\sbp2port.sys ()
DRV - (HidBth) – C:\Windows\system32\drivers\hidbth.sys ()
DRV - (usbcir) eHome Infrared Receiver (USBCIR) – C:\Windows\system32\drivers\usbcir.sys ()
DRV - (usbohci) – C:\Windows\system32\drivers\usbohci.sys ()
DRV - (HidIr) – C:\Windows\system32\drivers\hidir.sys ()
DRV - (WacomPen) – C:\Windows\system32\drivers\wacompen.sys ()
DRV - (Serial) – C:\Windows\system32\drivers\serial.sys ()
DRV - (Parport) – C:\Windows\system32\drivers\parport.sys ()
DRV - (Serenum) – C:\Windows\system32\drivers\serenum.sys ()
DRV - (Parvdm) – C:\Windows\system32\drivers\parvdm.sys ()
DRV - (StarOpen) – C:\Windows\System32\drivers\StarOpen.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=WLETDF&PC;=WLEM&q;="
FF - prefs.js..browser.search.order.1: "eSnips Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20110323
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.5
FF - prefs.js..extensions.enabledItems: [removed]:1.1
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.3.0.7280
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:4.3
FF - prefs.js..extensions.enabledItems: [removed]:4.3
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..keyword.URL: "http://www.google.com/webhp?ie=UTF-8&oe;=UTF-8"

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@fluxdvd.com/NPAPIX: C:\Program Files\Common Files\fluxDVD\APIX\NPAPIX.dll ()
FF - HKLM\Software\MozillaPlugins\@fluxdvd.com/NPFluxBrowserHelper: C:\Program Files\Common Files\fluxDVD\BrowserIntegration\NPFluxBrowserHelper.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@protectdisc.com/NPMPDRM: C:\Program Files\Common Files\mpDRM\NPMPDRM.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{400F0BDB-6C49-43A4-BE1F-76D7327A604D}: C:\Program Files\Common Files\fluxDVD\Download Manager\Mozilla [2010/07/08 13:15:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/03/12 22:24:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/03/12 22:24:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\BitDefender\BitDefender 2011\bdaphffext\ [2011/10/13 09:38:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/01 19:44:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/01 21:04:25 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\BitDefender\BitDefender 2011\bdtbext\ [2011/10/13 09:38:39 | 000,000,000 | —D | M]

[2010/01/06 18:27:05 | 000,000,000 | —D | M] (No name found) – C:\Users\excell\AppData\Roaming\mozilla\Extensions
[2011/11/19 00:58:06 | 000,000,000 | —D | M] (No name found) – C:\Users\excell\AppData\Roaming\mozilla\Firefox\Profiles\a9zmt3eo.default\extensions
[2011/11/19 00:58:06 | 000,000,000 | —D | M] (WOT) – C:\Users\excell\AppData\Roaming\mozilla\Firefox\Profiles\a9zmt3eo.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/04/12 22:36:52 | 000,000,000 | —D | M] ("DVDVideoSoft Menu") – C:\Users\excell\AppData\Roaming\mozilla\Firefox\Profiles\a9zmt3eo.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011/11/14 01:17:42 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\excell\AppData\Roaming\mozilla\Firefox\Profiles\a9zmt3eo.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/02/02 18:20:33 | 000,001,832 | —- | M] () – C:\Users\excell\AppData\Roaming\Mozilla\Firefox\Profiles\a9zmt3eo.default\searchplugins\bing.xml
[2011/05/31 21:24:23 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/10/22 22:30:01 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2011/03/13 21:13:08 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/05/31 21:24:23 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/10/13 09:38:39 | 000,000,000 | —D | M] ("BitDefender Antiphishing Toolbar") – C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2011\BDAPHFFEXT
() (No name found) – C:\USERS\EXCELL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\A9ZMT3EO.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/10/01 19:44:19 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/04/14 04:08:00 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/09/05 11:15:55 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/09/05 11:15:55 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/09/05 11:15:55 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/09/05 11:15:55 | 000,001,180 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/01/23 23:07:42 | 000,002,029 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\esnips.xml
[2011/09/05 11:15:55 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\12.0.742.100\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files\Google\Chrome\Application\12.0.742.100\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\12.0.742.100\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Active Process Information eXchange (Enabled) = C:\Program Files\Common Files\fluxDVD\APIX\NPAPIX.dll
CHR - plugin: fluxDVD (Enabled) = C:\Program Files\Common Files\fluxDVD\BrowserIntegration\NPFluxBrowserHelper.dll
CHR - plugin: NPMPDRM License Acquisition Plugin (Enabled) = C:\Program Files\Common Files\mpDRM\NPMPDRM.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.51204.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\excell\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.4.6_0\
CHR - Extension: DivX HiQ = C:\Users\excell\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.1.94_0\
CHR - Extension: Poppit = C:\Users\excell\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\excell\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.1.94_0\

O1 HOSTS File: ([2011/05/10 00:13:23 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Download Manager Browser Helper Object) - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\Program Files\Common Files\fluxDVD\Download Manager\XEBDLHelper.dll (Protect Software GmbH)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (Bitdefender Toolbar) - {381FFDE8-2394-4F90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2011\ietoolbar.dll (BitDefender S.R.L.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [BDAgent] C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe (BitDefender S.R.L.)
O4 - HKLM..\Run: [BitDefender Antiphishing Helper] C:\Program Files\BitDefender\BitDefender 2011\ieshow.exe (BitDefender S.R.L.)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\excell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TalkTalk Setup CD Reporting Tool.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\excell\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Send image to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{01D64D59-6B85-4A90-BB3B-469C2805B384}: DhcpNameServer = 192.168.4.213
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1B44D521-0810-4B73-8CFD-B377454919B2}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7923B45B-D117-49D5-8B00-563C5BFA479A}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (vrlogon.dll) -C:\Windows\System32\vrlogon.dll (UPEK Inc.)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Users\excell\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\excell\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/06 13:31:55 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\excell\Desktop\OTL(1).exe
[2011/12/06 13:25:29 | 001,566,512 | —- | C] (Kaspersky Lab ZAO) – C:\Users\excell\Desktop\TDSSKiller.exe
[2011/12/06 13:20:53 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{1934613B-A121-4C77-B85A-47BF22F99058}
[2011/12/06 13:20:29 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{4BC06B6C-177D-46D4-ACC2-492123A37400}
[2011/12/05 13:49:00 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\excell\Desktop\HiJackThis.exe
[2011/12/05 13:37:34 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{B990A5A3-04EA-453F-A5A6-69DA58AB37DE}
[2011/12/05 13:37:22 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{07A35309-96DA-4BE1-BBA8-9984090DB56A}
[2011/12/04 22:35:19 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{00EBBD4D-8490-4F8B-8706-E30341E27BFD}
[2011/12/04 22:34:54 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{BE47D693-31B4-4BF2-A688-888658E14EB8}
[2011/12/03 23:07:44 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{1A1B5183-1CB7-4B32-9F2D-286DCABDDA8A}
[2011/12/03 23:07:32 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{9B48106B-8A98-4F21-A412-9B26BDBD73E7}
[2011/11/29 12:02:13 | 000,000,000 | —D | C] – C:\Windows\System32\Samsung_USB_Drivers
[2011/11/29 12:01:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung PC Studio 3
[2011/11/29 12:01:28 | 000,000,000 | —D | C] – C:\Program Files\Samsung
[2011/11/29 11:56:43 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{F0D56B0A-280B-48BE-9894-06F3C25A7B10}
[2011/11/29 11:56:32 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{6368D8B9-528D-471F-BE18-2933BDE9E84C}
[2011/11/28 20:11:21 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{D35BC3C0-0A3C-4728-BB6D-9BE2D21939ED}
[2011/11/28 20:11:10 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{2B9B8F17-2853-48C9-8CE9-C96B11BEB5DF}
[2011/11/27 22:49:43 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{F7473208-17E4-4D52-96E0-EF39AB09A983}
[2011/11/27 22:49:29 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{F1F0E061-3A11-4548-807A-AB2D18A3B4D6}
[2011/11/26 22:40:09 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{569D90AF-19DC-4B5A-9709-B4A4562A91D7}
[2011/11/26 22:39:58 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{30CBE63C-2423-451E-8D5F-B488E666D23A}
[2011/11/25 13:58:28 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{F1065BFE-994A-42F9-ADC2-7DD27CDC4A0C}
[2011/11/25 13:58:17 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{DF5604AF-126B-4B2E-9119-9D499D4753DF}
[2011/11/21 16:22:39 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{8DE4776C-7845-4FA9-9983-DB258BD3196F}
[2011/11/21 16:22:28 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{BAE91AD7-8065-4943-895B-7286288328C7}
[2011/11/20 15:24:54 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{D8D657B6-AC23-4A5C-B58C-B2B20D97260B}
[2011/11/20 15:24:42 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{DE644877-1FED-4010-A342-3B02C36FFD28}
[2011/11/19 14:01:16 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{B214D275-D811-4CB2-84B9-2CF1BCD006C6}
[2011/11/19 14:01:05 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{3D22AFE0-6A67-47B0-A2DC-A4767B0DB908}
[2011/11/18 21:57:36 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{F4814554-E93E-42CF-8679-51973FED78D3}
[2011/11/18 21:57:25 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{FE8D8779-6FE6-4EBC-A9C0-CEDF89B2D577}
[2011/11/18 09:56:57 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{196A9125-29BF-459C-B64F-FE09BFDAA745}
[2011/11/18 09:56:47 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{28323A67-D3E5-49CC-B042-34114F4A0599}
[2011/11/17 07:23:54 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{4CEC27D8-468A-457B-8576-B8552D5B1610}
[2011/11/17 02:51:05 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{845D1713-C42E-43F2-8A2B-CA068FB911E6}
[2011/11/16 13:08:55 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{F01D76E6-AF47-4C3E-B567-87C8715904C4}
[2011/11/16 13:08:43 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{EEEAD5FF-4AF5-42DC-A8DB-31F68AAA8D18}
[2011/11/16 05:02:28 | 000,167,968 | —- | C] (Acronis) – C:\Windows\System32\drivers\afcdp.sys
[2011/11/16 05:02:23 | 000,600,928 | —- | C] (Acronis) – C:\Windows\System32\drivers\timntr.sys
[2011/11/16 05:02:13 | 000,170,528 | —- | C] (Acronis) – C:\Windows\System32\drivers\snapman.sys
[2011/11/16 05:02:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis
[2011/11/16 05:01:50 | 000,000,000 | —D | C] – C:\Program Files\Acronis
[2011/11/16 04:59:47 | 000,000,000 | —D | C] – C:\ProgramData\Acronis
[2011/11/16 00:13:49 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{FE67FA55-391C-46A0-BB2E-B883E5DF9BF0}
[2011/11/16 00:13:38 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{BE40C651-3767-45CC-AD40-05B890DAF416}
[2011/11/15 16:17:22 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{80A72DA3-E314-45A8-9A26-7B7F5684C2C8}
[2011/11/15 11:08:42 | 000,752,128 | —- | C] (Acronis) – C:\Windows\System32\drivers\tdrpm273.sys
[2011/11/15 11:07:57 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Acronis
[2011/11/15 11:05:56 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Roaming\Acronis
[2011/11/15 10:59:10 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{70CBACFC-08BE-46D8-95AE-7DC9A07239A5}
[2011/11/14 22:51:39 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{B2D2A16B-1F31-4C6C-A9B6-C4B595079F3A}
[2011/11/14 22:51:12 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{1B6E735A-FCB0-4734-BBE9-88529CA8D052}
[2011/11/14 22:35:53 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Roaming\SUPERAntiSpyware.com
[2011/11/14 22:35:00 | 000,000,000 | —D | C] – C:\Windows\System32\AppLogs
[2011/11/14 22:34:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011/11/14 22:34:58 | 000,000,000 | —D | C] – C:\ProgramData\!SASCORE
[2011/11/14 22:34:49 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/11/14 22:34:48 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2011/11/14 19:57:22 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Roaming\Malwarebytes
[2011/11/14 19:57:12 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/11/14 19:57:08 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/11/14 19:57:08 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/11/14 07:44:01 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{8F3C8A28-4744-4B22-B1BD-DCB77888EC5B}
[2011/11/14 01:58:17 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Roaming\Auslogics
[2011/11/14 01:57:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
[2011/11/14 01:57:15 | 000,000,000 | —D | C] – C:\Program Files\Auslogics
[2011/11/13 23:21:54 | 000,000,000 | -H-D | C] – C:\Users\excell\Desktop\.picasaoriginals
[2011/11/13 20:58:26 | 000,000,000 | —D | C] – C:\Users\excell\Documents\WR DATA
[2011/11/13 18:39:19 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{567F5CCB-19CB-4D35-80AF-2D364B6B4AB6}
[2011/11/13 18:38:15 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{9C69CA42-E6BD-45BC-B5ED-8C0E81631932}
[2011/11/07 21:28:38 | 000,056,208 | —- | C] (Trusteer Ltd.) – C:\Windows\System32\drivers\RapportKELL.sys
[2011/11/07 17:39:24 | 000,000,000 | —D | C] – C:\Users\excell\Desktop\cd 3
[2011/11/07 16:59:02 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{783D071A-724D-4215-A2CB-4B4676DA964B}
[2011/11/07 16:58:50 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{557A81F4-7275-43BB-BABC-03DDF03A7FFB}
[2011/11/07 12:17:09 | 000,000,000 | —D | C] – C:\Users\excell\AppData\Local\{600724DB-1783-473A-B550-5577E1B63C17}
[2011/11/06 14:16:34 | 000,000,000 | —D | C] – C:\Users\excell\Documents\Stronghold - Crusader - Extreme

========== Files - Modified Within 30 Days ==========

[2011/12/06 13:31:56 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\excell\Desktop\OTL(1).exe
[2011/12/06 13:31:00 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/06 13:29:50 | 000,340,898 | —- | M] () – C:\ProgramData\nvModes.dat
[2011/12/06 13:29:49 | 000,340,898 | —- | M] () – C:\ProgramData\nvModes.001
[2011/12/06 13:29:47 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/06 13:29:37 | 000,004,784 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/06 13:29:37 | 000,004,784 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/06 13:29:28 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/06 13:29:26 | 3756,064,768 | -HS- | M] () – C:\hiberfil.sys
[2011/12/06 13:25:16 | 001,547,774 | —- | M] () – C:\Users\excell\Desktop\tdsskiller.zip
[2011/12/06 00:32:09 | 000,000,420 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{D0486C69-5E5B-4E65-BDF3-BB232D6413F3}.job
[2011/12/05 13:49:00 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\excell\Desktop\HiJackThis.exe
[2011/11/29 12:13:50 | 000,000,000 | —- | M] () – C:\ProgramData\LauncherAccess.dt
[2011/11/29 12:12:44 | 000,001,931 | —- | M] () – C:\Users\excell\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung PC Studio 3.lnk
[2011/11/29 12:01:29 | 000,000,773 | —- | M] () – C:\Users\Public\Desktop\Samsung PC Studio 3.lnk
[2011/11/24 12:33:42 | 001,566,512 | —- | M] (Kaspersky Lab ZAO) – C:\Users\excell\Desktop\TDSSKiller.exe
[2011/11/18 11:21:30 | 000,111,104 | —- | M] () – C:\Users\excell\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/16 22:04:20 | 000,609,806 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/11/16 22:04:20 | 000,109,468 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/11/16 05:02:28 | 000,167,968 | —- | M] (Acronis) – C:\Windows\System32\drivers\afcdp.sys
[2011/11/16 05:02:24 | 000,752,128 | —- | M] (Acronis) – C:\Windows\System32\drivers\tdrpm273.sys
[2011/11/16 05:02:23 | 000,600,928 | —- | M] (Acronis) – C:\Windows\System32\drivers\timntr.sys
[2011/11/16 05:02:13 | 000,170,528 | —- | M] (Acronis) – C:\Windows\System32\drivers\snapman.sys
[2011/11/16 05:02:03 | 000,001,006 | —- | M] () – C:\Users\Public\Desktop\Acronis True Image Home 2011.lnk
[2011/11/15 01:59:09 | 000,001,546 | —- | M] () – C:\Users\excell\Desktop\WinSetupFromUSB.lnk
[2011/11/14 22:34:58 | 000,001,802 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/14 19:57:13 | 000,000,908 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/14 01:57:31 | 000,001,041 | —- | M] () – C:\Users\excell\Desktop\Auslogics Disk Defrag.lnk
[2011/11/07 21:28:38 | 000,056,208 | —- | M] (Trusteer Ltd.) – C:\Windows\System32\drivers\RapportKELL.sys
[2011/11/07 18:22:51 | 000,004,314 | —- | M] () – C:\Users\excell\Documents\cd 3.mds

========== Files Created - No Company Name ==========

[2011/12/06 13:25:11 | 001,547,774 | —- | C] () – C:\Users\excell\Desktop\tdsskiller.zip
[2011/11/29 12:13:50 | 000,000,000 | —- | C] () – C:\ProgramData\LauncherAccess.dt
[2011/11/29 12:12:44 | 000,001,931 | —- | C] () – C:\Users\excell\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung PC Studio 3.lnk
[2011/11/29 12:01:47 | 000,005,632 | —- | C] () – C:\Windows\System32\drivers\StarOpen.sys
[2011/11/29 12:01:29 | 000,000,773 | —- | C] () – C:\Users\Public\Desktop\Samsung PC Studio 3.lnk
[2011/11/27 01:20:58 | 000,001,904 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Excel Viewer.lnk
[2011/11/16 05:02:03 | 000,001,006 | —- | C] () – C:\Users\Public\Desktop\Acronis True Image Home 2011.lnk
[2011/11/15 01:59:09 | 000,001,546 | —- | C] () – C:\Users\excell\Desktop\WinSetupFromUSB.lnk
[2011/11/15 01:59:09 | 000,000,644 | —- | C] () – C:\Users\excell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinSetupFromUSB.lnk
[2011/11/14 22:34:58 | 000,001,802 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/14 19:57:13 | 000,000,908 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/14 01:57:31 | 000,001,041 | —- | C] () – C:\Users\excell\Desktop\Auslogics Disk Defrag.lnk
[2011/11/07 18:22:51 | 000,004,314 | —- | C] () – C:\Users\excell\Documents\cd 3.mds
[2011/09/06 17:05:30 | 001,556,992 | —- | C] () – C:\Windows\is-IDBGI.exe
[2011/07/07 02:00:34 | 000,000,680 | —- | C] () – C:\Users\excell\AppData\Local\d3d9caps.dat
[2011/06/30 02:59:17 | 000,000,031 | —- | C] () – C:\Windows\System32\wsoviedsini.dll
[2011/06/30 02:57:55 | 000,000,530 | —- | C] () – C:\Windows\System32\tx14_ic.ini
[2011/05/10 04:39:34 | 000,001,574 | —- | C] () – C:\Windows\Sandboxie.ini
[2011/05/09 23:34:27 | 000,001,547 | —- | C] () – C:\ProgramData\search_result.xml
[2011/05/09 22:11:13 | 000,000,016 | —- | C] () – C:\Windows\System32\asdict.dat
[2011/05/09 04:19:15 | 000,972,250 | —- | C] () – C:\ProgramData\bdinstall.bin
[2011/05/07 20:53:18 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2011/05/07 20:53:18 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/05/07 20:53:18 | 000,089,088 | —- | C] () – C:\Windows\MBR.exe
[2011/05/07 20:53:18 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/05/07 20:53:18 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/04/19 22:22:52 | 000,000,064 | —- | C] () – C:\Windows\System32\rp_stats.dat
[2011/04/19 22:22:52 | 000,000,044 | —- | C] () – C:\Windows\System32\rp_rules.dat
[2011/03/29 08:00:00 | 000,080,896 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2011/03/24 19:35:18 | 000,243,200 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2011/03/24 19:28:12 | 000,631,808 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2011/03/02 10:43:46 | 000,175,616 | —- | C] () – C:\Windows\System32\unrar.dll
[2011/02/16 13:07:25 | 000,000,841 | —- | C] () – C:\Users\excell\AppData\Roaming\burnaware.ini
[2011/01/25 12:29:35 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2011/01/16 23:06:22 | 000,111,104 | —- | C] () – C:\Users\excell\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/15 21:26:25 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2011/01/15 21:26:25 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2011/01/07 15:01:00 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011/01/05 18:56:49 | 001,474,832 | —- | C] () – C:\Windows\System32\drivers\sfi.dat
[2010/07/08 12:23:49 | 000,340,898 | —- | C] () – C:\ProgramData\nvModes.001
[2010/07/08 11:08:27 | 000,340,898 | —- | C] () – C:\ProgramData\nvModes.dat
[2010/07/08 09:37:14 | 000,101,544 | —- | C] () – C:\Program Files\Common Files\LinkInstaller.exe
[2010/07/08 08:28:37 | 000,054,784 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2010/07/08 08:28:36 | 000,024,064 | —- | C] () – C:\Windows\System32\WLTRYSVC.EXE
[2010/07/07 19:10:38 | 000,002,140 | —- | C] () – C:\Windows\bthservsdp.dat
[2008/11/24 16:16:27 | 000,000,074 | RHS- | C] () – C:\Windows\CT4CET.bin
[2008/01/21 03:13:20 | 000,006,656 | —- | C] () – C:\Windows\System32\drivers\errdev.sys
[2008/01/21 03:11:16 | 000,045,568 | —- | C] () – C:\Windows\System32\drivers\blbdrive.sys
[2008/01/21 03:10:19 | 000,386,616 | —- | C] () – C:\Windows\System32\drivers\MegaSR.sys
[2008/01/21 02:23:23 | 000,096,312 | —- | C] () – C:\Windows\System32\drivers\lsi_scsi.sys
[2008/01/21 02:23:20 | 000,019,968 | —- | C] () – C:\Windows\System32\drivers\sermouse.sys
[2007/07/25 16:40:02 | 000,999,424 | —- | C] () – C:\Windows\System32\WLIHVUI.dll
[2007/01/31 13:50:32 | 000,913,408 | —- | C] () – C:\Windows\System32\xreglib.dll
[2006/11/03 17:25:56 | 000,389,120 | —- | C] () – C:\Windows\System32\btwhidcs.dll
[2006/11/02 12:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 12:47:37 | 000,256,680 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 12:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 10:33:01 | 000,609,806 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 10:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 10:33:01 | 000,109,468 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 10:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 10:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 09:38:56 | 000,013,568 | —- | C] () – C:\Windows\System32\drivers\BrFiltLo.sys
[2006/11/02 09:38:00 | 000,011,904 | —- | C] () – C:\Windows\System32\drivers\BrUsbSer.sys
[2006/11/02 09:37:31 | 000,012,160 | —- | C] () – C:\Windows\System32\drivers\BrUsbMdm.sys
[2006/11/02 09:37:24 | 000,005,248 | —- | C] () – C:\Windows\System32\drivers\BrFiltUp.sys
[2006/11/02 09:36:51 | 000,062,336 | —- | C] () – C:\Windows\System32\drivers\BrSerWdm.sys
[2006/11/02 09:22:06 | 000,071,808 | —- | C] () – C:\Windows\System32\drivers\BrSerId.sys
[2006/11/02 09:03:00 | 000,248,832 | —- | C] () – C:\Windows\System32\drivers\rdpdr.sys
[2006/11/02 08:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 08:55:22 | 000,029,184 | —- | C] () – C:\Windows\System32\drivers\hidbth.sys
[2006/11/02 08:55:09 | 000,068,608 | —- | C] () – C:\Windows\System32\drivers\usbcir.sys
[2006/11/02 08:55:08 | 000,035,328 | —- | C] () – C:\Windows\System32\drivers\circlass.sys
[2006/11/02 08:55:05 | 000,019,456 | —- | C] () – C:\Windows\System32\drivers\usbohci.sys
[2006/11/02 08:55:01 | 000,021,504 | —- | C] () – C:\Windows\System32\drivers\hidir.sys
[2006/11/02 08:54:05 | 000,022,072 | —- | C] () – C:\Windows\System32\drivers\wd.sys
[2006/11/02 08:52:52 | 000,020,608 | —- | C] () – C:\Windows\System32\drivers\wacompen.sys
[2006/11/02 08:52:40 | 000,094,776 | —- | C] () – C:\Windows\System32\drivers\msdsm.sys
[2006/11/02 08:52:38 | 000,105,016 | —- | C] () – C:\Windows\System32\drivers\mpio.sys
[2006/11/02 08:51:45 | 000,076,392 | —- | C] () – C:\Windows\System32\drivers\sbp2port.sys
[2006/11/02 08:51:40 | 000,012,288 | —- | C] () – C:\Windows\System32\drivers\sffp_mmc.sys
[2006/11/02 08:51:37 | 000,030,264 | —- | C] () – C:\Windows\System32\drivers\i2omp.sys
[2006/11/02 08:51:36 | 000,020,024 | —- | C] () – C:\Windows\System32\drivers\viaide.sys
[2006/11/02 08:51:36 | 000,017,976 | —- | C] () – C:\Windows\System32\drivers\amdide.sys
[2006/11/02 08:51:35 | 000,019,000 | —- | C] () – C:\Windows\System32\drivers\cmdide.sys
[2006/11/02 08:51:35 | 000,017,464 | —- | C] () – C:\Windows\System32\drivers\aliide.sys
[2006/11/02 08:51:30 | 000,083,456 | —- | C] () – C:\Windows\System32\drivers\serial.sys
[2006/11/02 08:51:30 | 000,079,360 | —- | C] () – C:\Windows\System32\drivers\parport.sys
[2006/11/02 08:51:25 | 000,017,920 | —- | C] () – C:\Windows\System32\drivers\serenum.sys
[2006/11/02 08:51:23 | 000,008,704 | —- | C] () – C:\Windows\System32\drivers\parvdm.sys
[2006/11/02 08:42:03 | 000,064,512 | —- | C] () – C:\Windows\System32\drivers\IPMIDrv.sys
[2006/11/02 08:35:13 | 000,167,528 | —- | C] () – C:\Windows\System32\drivers\pcmcia.sys
[2006/11/02 08:35:11 | 000,049,720 | —- | C] () – C:\Windows\System32\drivers\isapnp.sys
[2006/11/02 08:35:08 | 000,109,112 | —- | C] () – C:\Windows\System32\drivers\NV_AGP.SYS
[2006/11/02 08:35:08 | 000,060,984 | —- | C] () – C:\Windows\System32\drivers\ULIAGPKX.SYS
[2006/11/02 08:35:07 | 000,061,496 | —- | C] () – C:\Windows\System32\drivers\GAGP30KX.SYS
[2006/11/02 08:35:07 | 000,059,448 | —- | C] () – C:\Windows\System32\drivers\UAGP35.SYS
[2006/11/02 08:35:07 | 000,056,888 | —- | C] () – C:\Windows\System32\drivers\VIAAGP.SYS
[2006/11/02 08:35:06 | 000,057,400 | —- | C] () – C:\Windows\System32\drivers\AMDAGP.SYS
[2006/11/02 08:35:06 | 000,056,376 | —- | C] () – C:\Windows\System32\drivers\AGP440.sys
[2006/11/02 08:35:06 | 000,055,864 | —- | C] () – C:\Windows\System32\drivers\SISAGP.SYS
[2006/11/02 08:30:19 | 000,041,472 | —- | C] () – C:\Windows\System32\drivers\viac7.sys
[2006/11/02 08:30:18 | 000,044,032 | —- | C] () – C:\Windows\System32\drivers\amdk8.sys
[2006/11/02 08:30:18 | 000,041,472 | —- | C] () – C:\Windows\System32\drivers\amdk7.sys
[2006/11/02 08:30:18 | 000,040,960 | —- | C] () – C:\Windows\System32\drivers\processr.sys
[2006/11/02 08:30:18 | 000,040,960 | —- | C] () – C:\Windows\System32\drivers\crusoe.sys
[2006/11/02 08:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 07:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 07:36:50 | 000,020,608 | —- | C] () – C:\Windows\System32\drivers\ntrigdigi.sys
[2006/11/02 07:36:49 | 000,071,272 | —- | C] () – C:\Windows\System32\drivers\djsvs.sys
[2006/11/02 07:36:48 | 000,238,648 | —- | C] () – C:\Windows\System32\drivers\uliahci.sys
[2006/11/02 07:36:48 | 000,130,616 | —- | C] () – C:\Windows\System32\drivers\vsmraid.sys
[2006/11/02 07:36:48 | 000,106,088 | —- | C] () – C:\Windows\System32\drivers\ql40xx.sys
[2006/11/02 07:36:48 | 000,074,808 | —- | C] () – C:\Windows\System32\drivers\sisraid4.sys
[2006/11/02 07:36:48 | 000,041,016 | —- | C] () – C:\Windows\System32\drivers\sisraid2.sys
[2006/11/02 07:36:47 | 001,122,360 | —- | C] () – C:\Windows\System32\drivers\ql2300.sys
[2006/11/02 07:36:47 | 000,096,312 | —- | C] () – C:\Windows\System32\drivers\lsi_fc.sys
[2006/11/02 07:36:47 | 000,035,944 | —- | C] () – C:\Windows\System32\drivers\symc8xx.sys
[2006/11/02 07:36:47 | 000,034,920 | —- | C] () – C:\Windows\System32\drivers\sym_u3.sys
[2006/11/02 07:36:47 | 000,031,848 | —- | C] () – C:\Windows\System32\drivers\sym_hi.sys
[2006/11/02 07:36:46 | 000,115,816 | —- | C] () – C:\Windows\System32\drivers\ulsata2.sys
[2006/11/02 07:36:46 | 000,102,968 | —- | C] () – C:\Windows\System32\drivers\nvraid.sys
[2006/11/02 07:36:46 | 000,098,408 | —- | C] () – C:\Windows\System32\drivers\ulsata.sys
[2006/11/02 07:36:46 | 000,089,656 | —- | C] () – C:\Windows\System32\drivers\lsi_sas.sys
[2006/11/02 07:36:46 | 000,045,112 | —- | C] () – C:\Windows\System32\drivers\nvstor.sys
[2006/11/02 07:36:45 | 000,035,944 | —- | C] () – C:\Windows\System32\drivers\iteatapi.sys
[2006/11/02 07:36:45 | 000,033,384 | —- | C] () – C:\Windows\System32\drivers\Mraid35x.sys
[2006/11/02 07:36:45 | 000,031,288 | —- | C] () – C:\Windows\System32\drivers\megasas.sys
[2006/11/02 07:36:44 | 000,342,584 | —- | C] () – C:\Windows\System32\drivers\elxstor.sys
[2006/11/02 07:36:44 | 000,235,064 | —- | C] () – C:\Windows\System32\drivers\iaStorV.sys
[2006/11/02 07:36:44 | 000,079,928 | —- | C] () – C:\Windows\System32\drivers\arcsas.sys
[2006/11/02 07:36:44 | 000,079,416 | —- | C] () – C:\Windows\System32\drivers\arc.sys
[2006/11/02 07:36:44 | 000,045,160 | —- | C] () – C:\Windows\System32\drivers\nfrd960.sys
[2006/11/02 07:36:44 | 000,041,576 | —- | C] () – C:\Windows\System32\drivers\iirsp.sys
[2006/11/02 07:36:44 | 000,040,504 | —- | C] () – C:\Windows\System32\drivers\HpCISSs.sys
[2006/11/02 07:36:44 | 000,035,944 | —- | C] () – C:\Windows\System32\drivers\iteraid.sys
[2006/11/02 07:36:43 | 000,422,968 | —- | C] () – C:\Windows\System32\drivers\adp94xx.sys
[2006/11/02 07:36:43 | 000,300,600 | —- | C] () – C:\Windows\System32\drivers\adpahci.sys
[2006/11/02 07:36:43 | 000,149,560 | —- | C] () – C:\Windows\System32\drivers\adpu320.sys
[2006/11/02 07:36:43 | 000,101,432 | —- | C] () – C:\Windows\System32\drivers\adpu160m.sys
[2006/11/02 07:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2001/11/14 12:56:00 | 001,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll

========== LOP Check ==========

[2011/11/15 11:05:56 | 000,000,000 | —D | M] – C:\Users\excell\AppData\Roaming\Acronis
[2011/11/14 01:58:18 | 000,000,000 | —D | M] – C:\Users\excell\AppData\Roaming\Auslogics
[2011/10/27 17:43:42 | 000,000,000 | —D | M] – C:\Users\excell\AppData\Roaming\Azureus
[2011/05/09 05:15:34 | 000,000,000 | —D | M] – C:\Users\excell\AppData\Roaming\BitDefender
[2011/02/13 15:03:31 | 000,000,000 | —D | M] – C:\Users\excell\AppData\Roaming\Canneverbe Limited
[2011/04/12 22:36:51 | 000,000,000 | —D | M] – C:\Users\excell\AppData\Roaming\DVDVideoSoftIEHelpers
[2011/10/22 23:09:05 | 000,000,000 | —D | M] – C:\Users\excell\AppData\Roaming\go
[2011/10/11 13:46:19 | 000,000,000 | —D | M] – C:\Users\excell\AppData\Roaming\ImgBurn
[2011/01/23 23:07:44 | 000,000,000 | —D | M] – C:\Users\excell\AppData\Roaming\Logia
[2011/04/12 22:25:18 | 000,000,000 | —D | M] – C:\Users\excell\AppData\Roaming\NetMedia Providers
[2011/03/13 21:25:13 | 000,000,000 | —D | M] – C:\Users\excell\AppData\Roaming\OpenOffice.org
[2011/04/12 22:25:18 | 000,000,000 | —D | M] – C:\Users\excell\AppData\Roaming\Publish Providers
[2011/05/09 04:28:07 | 000,000,000 | —D | M] – C:\Users\excell\AppData\Roaming\QuickScan
[2011/04/12 22:25:24 | 000,000,000 | —D | M] – C:\Users\excell\AppData\Roaming\Sony
[2011/10/04 20:18:06 | 000,000,000 | —D | M] – C:\Users\excell\AppData\Roaming\TalkTalk
[2011/01/21 16:02:09 | 000,000,000 | —D | M] – C:\Users\excell\AppData\Roaming\Trusteer
[2011/12/06 13:28:33 | 000,032,554 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/12/06 00:32:09 | 000,000,420 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{D0486C69-5E5B-4E65-BDF3-BB232D6413F3}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2009/07/15 16:30:46 | 000,028,672 | R— | M] (Microsoft Corporation) – C:\setupSNK.exe


< MD5 for: EXPLORER.EXE >
[2008/10/29 06:20:29 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 06:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/30 03:59:17 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/11 06:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\System Volume Information\SystemRestore\FRStaging\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2009/04/11 06:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\ERDNT\cache\explorer.exe
[2009/04/11 06:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/11 06:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/28 02:15:02 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/21 02:24:24 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: SVCHOST.EXE >
[2008/01/21 02:23:43 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\ERDNT\cache\svchost.exe
[2008/01/21 02:23:43 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\System32\svchost.exe
[2008/01/21 02:23:43 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/01/21 02:24:49 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\ERDNT\cache\userinit.exe
[2008/01/21 02:24:49 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\System32\userinit.exe
[2008/01/21 02:24:49 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/04/11 06:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\ERDNT\cache\winlogon.exe
[2009/04/11 06:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/11 06:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/21 02:24:49 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< C:\Windows\assembly\tmp\U\*.* /s >

========== Files - Unicode (All) ==========
[2011/07/29 21:08:37 | 000,000,000 | —- | M] ()(C:\Windows\System32\?????) – C:\Windows\System32\獷楬汢捯污
[2011/07/29 14:32:52 | 000,000,000 | —- | C] ()(C:\Windows\System32\?????) – C:\Windows\System32\獷楬汢捯污

========== Alternate Data Streams ==========

@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:5D432CE3

< End of report >
And heres my log from OTL EXTRAS.


OTL Extras logfile created on: 06/12/2011 13:34:04 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\excell\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19154)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.50 Gb Total Physical Memory | 2.33 Gb Available Physical Memory | 66.69% Memory free
7.18 Gb Paging File | 5.96 Gb Available in Paging File | 82.98% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 120.24 Gb Free Space | 51.63% Space Free | Partition Type: NTFS

Computer Name: EXCELL-PC | User Name: excell | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 1
"FirewallOverride" = 1
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0E9E13B3-FACA-490F-AFD9-D26FC4197C1E}" = lport=40090 | protocol=6 | dir=in | name=streaming web cam |
"{47BA8AA2-0471-4025-BD03-6F08915EB408}" = lport=40080 | protocol=6 | dir=in | name=remote access media server |
"{4E8941FA-F75D-4C5F-A0CB-8544970E9E52}" = lport=40091 | protocol=6 | dir=in | name=streaming web cam |
"{65291BD3-563B-45B8-913D-8E1AAD211913}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{C9E1374E-F30D-4E57-9843-94D810D77E4B}" = lport=40092 | protocol=6 | dir=in | name=streaming web cam |
"{D3156189-E044-4FB0-963F-D5ADD801E9AD}" = lport=40093 | protocol=6 | dir=in | name=streaming web cam |
"{D567561E-0D2D-4253-9AC9-573D71E12E5C}" = lport=5900 | protocol=6 | dir=in | name=ultravnc server |
"{E05B0BE8-4C59-4D7F-A6E7-2D7E7EBD6AA3}" = lport=40094 | protocol=6 | dir=in | name=streaming web cam |
"{F9BEDF9F-9107-4E43-B77C-F8738CBA832D}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{088243D6-F91A-447C-883C-19FD10F1EB85}" = protocol=6 | dir=in | app=c:\program files\common files\dell\mysql\bin\mysql.exe |
"{1900E7E5-FBFD-4B4F-9BAD-887495CF44C2}" = protocol=6 | dir=in | app=c:\program files\common files\dell\remote access file sync service\dsl_fs_sync.exe |
"{20CE1EFC-35BD-4A0E-B36B-E0CF994D5E52}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{298AE3B9-2E38-4397-AD21-A76A46C29EA5}" = protocol=6 | dir=in | app=c:\program files\common files\dell\apache\php.exe |
"{48B7639D-8A9D-4B55-A45B-D4425A7B3304}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{578E79F0-9281-4B6D-9F53-B547B65E4CEA}" = protocol=17 | dir=in | app=c:\program files\common files\dell\remote access file sync service\dsl_fs_sync.exe |
"{5B14D628-A01E-4DCD-BB27-DA7C6602804E}" = protocol=6 | dir=in | app=c:\program files\common files\dell\apache\bin\httpd.exe |
"{63B74DE6-6F46-471E-99B7-55D28309BA44}" = protocol=17 | dir=in | app=c:\program files\common files\dell\vlc\vlc.exe |
"{648DF6D8-9E25-4C20-B628-227D6DB7BC06}" = protocol=17 | dir=in | app=c:\program files\common files\dell\advanced networking service\hnm_svc.exe |
"{6BFF1096-95A7-4948-9A42-64946860E322}" = protocol=6 | dir=in | app=c:\program files\common files\dell\mysql\bin\mysqld.exe |
"{6EF20F6A-4CC4-4E34-B6ED-00391D92377A}" = protocol=6 | dir=in | app=c:\program files\common files\dell\advanced networking service\hnm_svc.exe |
"{75CEBE0C-451F-4B3E-B791-E45440A08693}" = protocol=17 | dir=in | app=c:\programdata\ultravnc\winvnc.exe |
"{78A2A033-9F1A-480D-8B50-C6595C6813B7}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{78D277D7-9213-44DF-ACCE-37B756B4E999}" = protocol=6 | dir=in | app=c:\program files\common files\dell\vlc\vlc.exe |
"{881CC5DA-BECC-479E-A397-49E9F2BF264E}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{8F1991A2-850F-4B18-A3C6-59E11C543F90}" = protocol=17 | dir=in | app=c:\program files\common files\dell\mysql\bin\mysql.exe |
"{977F3602-66DC-4DA5-8153-C8B92BB83909}" = protocol=6 | dir=in | app=c:\programdata\ultravnc\winvnc.exe |
"{A0DF855B-1B6B-498B-9B69-A00B13DA3E9A}" = protocol=6 | dir=in | app=c:\program files\dell remote access\ezi_ra.exe |
"{B3EBB8F7-0CF3-4CAF-BAF7-656AEF92654E}" = protocol=17 | dir=in | app=c:\program files\cinemanow\cinemanow media manager\cinemanowshell.exe |
"{BCC9D43A-9EF9-4679-B1FF-FF6949F1F1DB}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{C407E501-6581-4168-87AD-2C1D4C302222}" = protocol=6 | dir=in | app=c:\program files\cinemanow\cinemanow media manager\cinemanowshell.exe |
"{C7EEC80C-61A8-4993-8DE1-2781416D198C}" = protocol=17 | dir=in | app=c:\program files\dell remote access\ezi_ra.exe |
"{CCC7CAA0-9F09-4FD9-A9A0-E1D944F5C09B}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{D1719A57-8A29-4AA1-B28A-0F56EDC343BE}" = protocol=17 | dir=in | app=c:\program files\cinemanow\cinemanow media manager\cnupdater.exe |
"{D98F3AF7-E313-4555-A3CE-E48FD9263F2C}" = protocol=6 | dir=in | app=c:\program files\cinemanow\cinemanow media manager\cnupdater.exe |
"{DA7DB965-5B06-4970-9C5F-10DBBD4ED801}" = protocol=17 | dir=in | app=c:\program files\common files\dell\apache\bin\httpd.exe |
"{E9D9EDB7-3752-4F59-84F1-1528ADD61EE2}" = protocol=17 | dir=in | app=c:\program files\common files\dell\apache\php.exe |
"{F5C92D96-CEFB-49A1-9C59-43CA6EFC80ED}" = protocol=17 | dir=in | app=c:\program files\common files\dell\mysql\bin\mysqld.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04A3A6B0-8E19-49BB-82FF-65C5A55F917D}" = Acronis True Image Home 2011
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP280_series" = Canon MP280 series MP Drivers
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1B0098FF-1816-4F42-8203-FA29F5735596}" = Samsung PC Studio 3
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 25
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{457443C1-D814-453A-BD25-121325F3C7AE}_is1" = How to Pass the Life in the UK Test CD-ROM
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B6AD248-D3BF-426A-8D64-847288154F13}" = QuickSet
"{4D7B2217-6055-4678-8E99-3FBECD0F65F9}" = CinemaNow Media Manager
"{4E5386F5-C0F6-4532-A54A-374865AEAB71}" = Cisco PEAP Module
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{53FA9A9F-3C19-4D43-AD6B-DEF365D469BA}" = Camtasia Studio 7
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.54.06
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{759142E8-25B0-42AE-B408-4215065D3F4B}" = Windows Live Family Safety
"{76F9CF97-FC4B-4E20-B363-D127C888448F}" = Cisco LEAP Module
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{82AF3E91-57E1-4754-84D0-40A46E2479AB}" = OpenOffice.org 3.3
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E7D7400-4F4F-409D-8F8A-43BF1DAC575A}" = TouchChip USB Driver 2.6
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A13E07E1-A423-44FB-9DEE-B24C75C1BAF2}" = WIDCOMM Bluetooth Software 6.0.1.3100
"{A2289997-10A3-48F2-AA03-99180D761661}" = Fingerprint Reader Suite 5.6
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B6CA7A3C-35FD-401F-9335-FFFD2BCD5FF3}" = BitDefender Total Security 2011
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BCB4C18A-ACA6-4383-8688-E19933A705DD}" = Microsoft SOAP Toolkit 3.0
"{BCF16F16-AC0E-4ABE-A9EF-412CF484BA51}" = Windows Live Family Safety
"{BF53252E-4AB2-4C7F-A0FD-6100755745E3}" = Cisco EAP-FAST Module
"{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio 3
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C73A3942-84C8-4597-9F9B-EE227DCBA758}" = Dell Dock
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E97C937C-AE21-453D-86A0-A231507543D1}" = ACID Music Studio 8.0
"{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}" = Samsung PC Studio 3 USB Driver Installer
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F5D7FAB5-A1FD-4DD3-983E-4155B09D7102}" = mCore
"{F66A31D9-7831-4FBA-BA02-C411C0047CC5}" = Dell Remote Access
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"BitDefender" = BitDefender Total Security 2011
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CCleaner" = CCleaner
"Creative OEM002" = Laptop Integrated Webcam Driver (1.04.01.1011)
"Dell Dock" = Dell Dock
"Dell Webcam Central" = Dell Webcam Central
"DivX Setup.divx.com" = DivX Setup
"ImgBurn" = ImgBurn
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 7.0.1 (x86 en-GB)" = Mozilla Firefox 7.0.1 (x86 en-GB)
"nLite_is1" = nLite 1.4.9.1
"NVIDIA Drivers" = NVIDIA Drivers
"Picasa 3" = Picasa 3
"ProInst" = Intel® PROSet/Wireless Software
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"Sandboxie" = Sandboxie 3.54 (32-bit)
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VLC media player 1.1.5
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Word Viewer 5.89" = Word Viewer 5.89
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Game Organizer" = EasyBits GO
"WinSetupFromUSB" = WinSetupFromUSB

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 25/11/2011 20:15:57 | Computer Name = excell-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 25/11/2011 20:15:57 | Computer Name = excell-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 25/11/2011 20:15:57 | Computer Name = excell-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 25/11/2011 20:15:57 | Computer Name = excell-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 25/11/2011 20:15:57 | Computer Name = excell-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 25/11/2011 20:15:57 | Computer Name = excell-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 25/11/2011 20:15:59 | Computer Name = excell-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 25/11/2011 20:15:59 | Computer Name = excell-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 25/11/2011 22:49:02 | Computer Name = excell-PC | Source = EventSystem | ID = 4621
Description =

Error - 26/11/2011 18:38:50 | Computer Name = excell-PC | Source = WinMgmt | ID = 10
Description =

[ Broadcom Wireless LAN Events ]
Error - 03/07/2011 08:56:41 | Computer Name = excell-PC | Source = WLAN-Tray | ID = 0
Description = 13:56:40, Sun, Jul 03, 11 Error - Unable to decrypt string

[ System Events ]
Error - 06/12/2011 09:30:23 | Computer Name = excell-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 06/12/2011 09:30:23 | Computer Name = excell-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 06/12/2011 09:30:23 | Computer Name = excell-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 06/12/2011 09:31:58 | Computer Name = excell-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 06/12/2011 09:33:24 | Computer Name = excell-PC | Source = netbt | ID = 4321
Description = The name "ANEELA-TOSH :0" could not be registered on the interface
with IP address 192.168.0.100. The computer with the IP address 192.168.0.102 did
not allow the name to be claimed by this computer.

Error - 06/12/2011 09:43:37 | Computer Name = excell-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 06/12/2011 09:43:37 | Computer Name = excell-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 06/12/2011 09:43:37 | Computer Name = excell-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 06/12/2011 09:43:37 | Computer Name = excell-PC | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 06/12/2011 09:43:53 | Computer Name = excell-PC | Source = netbt | ID = 4321
Description = The name "ANEELA-TOSH :0" could not be registered on the interface
with IP address 192.168.0.100. The computer with the IP address 192.168.0.102 did
not allow the name to be claimed by this computer.


< End of report >
Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Ok severe issues to report. I opened bit defender and individually turned off all the protection like anti spam, anti malware, antivirus, firewall etc as i couldnt see a disable option. Then i closed all the other windows and double clicked on combofix icon. A small window popped up and it started deleting files from c drive dont know what exactly. Then it disappeared randomly. I waited around half an hour for something to happen. Nothing did. So i opened the task manager to c if combofix was still running. It wasnt. So i double clicked on the icon again and same window popped up. Then it came up with an error "opening file for writing" and it said something about the iexplorer.exe. I am attaching the print screen of that error. It wouldnt let me retry. So i clicked ignore and it went on to scan or delete other things. Then it disappeared all together. After like 10 minutes it came up with a warning about bit defender n told me to disabled it. So i clicked ok and it came up with another warning and i rechecked all my protection n made sure it was turned off. So i clicked ok and then nothing happened for like 2 hours. This time i decided to wait around. Eventually it started the scan and showed " stage 1 completed". Over the next 4 hours it managed to get to stage 42 so i left it running and went to sleep. I woke up in the morning only to find what normally occurs after a blue screen crash. A black screen that says no bootable drives were detected. :angry: Raging! Was it due to the fact that i didnt disable bitdefender properly? If yes please tell me how i wd go about doing that. Thank u

Attachments:

Ok i am posting this from another computer. I have uninstalled bitdefender on my laptop and started running combofix. It seems to be running without any issues this time. I will post the log as soon as its done.
Ok my system rebooted itself after the scan. And once i logged in it wouldnt let me open anything. Kept comming up with the error "Cant access file registry marked for deletion" so i restarted again and it seems to be working fine. Heres the log from Combofix.


ComboFix 11-12-06.01 - excell 07/12/2011 16:15:44.6.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3581.2397 [GMT 0:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
c:\programdata\Roaming\Intel\Wireless\Settings\Settings.ini
c:\users\excell\Downloads\Laptop repairs - Nltd L2 + Ul30 Few Drvrs\New 7\Desktop_.ini
.
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\ERDNT\cache\userinit.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-11-07 to 2011-12-07 )))))))))))))))))))))))))))))))
.
.
2011-12-07 16:27 . 2011-12-07 21:03 ——– d—–w- c:\users\excell\AppData\Local\temp
2011-12-07 16:27 . 2011-12-07 16:27 ——– d—–w- c:\users\RA Media Server\AppData\Local\temp
2011-12-07 16:27 . 2011-12-07 16:27 ——– d—–w- c:\users\Public\AppData\Local\temp
2011-12-07 16:27 . 2011-12-07 16:27 ——– d—–w- c:\users\Guest\AppData\Local\temp
2011-12-07 16:27 . 2011-12-07 16:27 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-11-29 12:02 . 2011-11-29 12:05 ——– d—–w- c:\windows\system32\Samsung_USB_Drivers
2011-11-29 12:01 . 2006-07-24 16:05 5632 —-a-w- c:\windows\system32\drivers\StarOpen.sys
2011-11-29 12:01 . 2011-11-29 12:01 ——– d—–w- c:\program files\Samsung
2011-11-16 05:02 . 2011-11-16 05:02 167968 —-a-w- c:\windows\system32\drivers\afcdp.sys
2011-11-16 05:02 . 2011-11-16 05:02 600928 —-a-w- c:\windows\system32\drivers\timntr.sys
2011-11-16 05:02 . 2011-11-16 05:02 170528 —-a-w- c:\windows\system32\drivers\snapman.sys
2011-11-16 05:01 . 2011-11-16 05:01 ——– d—–w- c:\program files\Acronis
2011-11-15 11:08 . 2011-11-16 05:02 752128 —-a-w- c:\windows\system32\drivers\tdrpm273.sys
2011-11-15 11:07 . 2011-11-16 05:02 ——– d—–w- c:\program files\Common Files\Acronis
2011-11-14 22:35 . 2011-11-14 22:35 ——– d—–w- c:\users\excell\AppData\Roaming\SUPERAntiSpyware.com
2011-11-14 22:35 . 2011-11-14 22:35 ——– d—–w- c:\windows\system32\AppLogs
2011-11-14 22:34 . 2011-11-14 22:34 ——– d—–w- c:\programdata\!SASCORE
2011-11-14 22:34 . 2011-11-14 22:39 ——– d—–w- c:\program files\SUPERAntiSpyware
2011-11-14 22:34 . 2011-11-14 22:34 ——– d—–w- c:\programdata\SUPERAntiSpyware.com
2011-11-14 19:57 . 2011-11-14 19:57 ——– d—–w- c:\users\excell\AppData\Roaming\Malwarebytes
2011-11-14 19:57 . 2011-11-14 19:57 ——– d—–w- c:\programdata\Malwarebytes
2011-11-14 19:57 . 2011-11-14 19:57 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-11-14 19:57 . 2011-08-31 17:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-14 01:58 . 2011-11-14 01:58 ——– d—–w- c:\users\excell\AppData\Roaming\Auslogics
2011-11-14 01:57 . 2011-11-14 01:57 ——– d—–w- c:\program files\Auslogics
2011-11-09 16:37 . 2011-10-17 11:41 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-11-09 16:37 . 2011-09-20 21:02 905088 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-09 16:37 . 2011-09-30 15:57 707584 —-a-w- c:\program files\Common Files\System\wab32.dll
2011-11-07 21:28 . 2011-11-07 21:28 56208 —-a-w- c:\windows\system32\drivers\RapportKELL.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-07 16:13 . 2011-05-09 04:19 1310515 —-a-w- c:\programdata\bdinstall.bin
2011-09-30 23:06 . 2011-10-13 08:23 916480 —-a-w- c:\windows\system32\wininet.dll
2011-09-30 23:02 . 2011-10-13 08:23 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-09-30 23:01 . 2011-10-13 08:23 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-09-30 23:01 . 2011-10-13 08:23 109056 —-a-w- c:\windows\system32\iesysprep.dll
2011-09-30 23:01 . 2011-10-13 08:23 71680 —-a-w- c:\windows\system32\iesetup.dll
2011-09-30 22:07 . 2011-10-13 08:23 385024 —-a-w- c:\windows\system32\html.iec
2011-09-30 21:29 . 2011-10-13 08:23 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2011-09-30 21:28 . 2011-10-13 08:23 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2011-09-30 12:59 . 2010-06-24 11:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2010-07-08 09:37 . 2010-07-08 09:37 101544 —-a-w- c:\program files\Common Files\LinkInstaller.exe
2011-10-01 19:44 . 2011-09-05 11:16 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-09-10 15:50 2957312 —-a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-09-10 15:50 2957312 —-a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-12-08 3444736]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
c:\users\excell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TalkTalk Setup CD Reporting Tool.exe [2010-8-2 725768]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft\Internet Explorer\Quick Launch
How to Pass the Life in the UK Test CD-ROM.lnk - c:\program files\How to Pass the Life in the UK Test CD-ROM\index.hta [2011-6-11 6762]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickSet.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QuickSet.lnk
backup=c:\windows\pss\QuickSet.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Everyone Else^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk]
path=c:\users\Everyone Else\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
backup=c:\windows\pss\OpenOffice.org 3.3.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^excell^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk]
path=c:\users\excell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
backup=c:\windows\pss\OpenOffice.org 3.3.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2011-02-01 19:53 390720 —-a-w- c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-11-10 12:49 932288 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-30 15:45 35736 —-a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
2007-10-25 12:31 167936 —-a-w- c:\program files\DellTPad\Apoint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CinemaNowMediaManagerApp]
2008-09-05 09:43 2017640 ——w- c:\program files\CinemaNow\CinemaNow Media Manager\CinemaNowShell.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell Webcam Central]
2009-01-09 13:49 405639 ——w- c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dellsupportcenter]
2009-06-03 14:46 206064 —-a-w- c:\program files\Dell Support Center\bin\sprtcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-02-15 01:32 1230704 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2011-08-31 17:00 449608 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]
2011-08-31 17:00 1047208 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2010-06-01 10:17 5252408 ——w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2011-05-13 15:03 4283256 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEM02Mon.exe]
2007-05-09 17:01 36864 —-a-w- c:\windows\OEM02Mon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSQLLauncher]
2007-04-16 21:50 49168 —-a-w- c:\program files\Fingerprint Reader Suite\launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
2011-03-24 11:24 409320 —-a-w- c:\program files\Sandboxie\SbieCtrl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 —-a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2008-02-15 17:23 405504 —-a-w- c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-01-07 12:12 253672 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2011-02-01 19:52 5546376 —-a-w- c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
2009-04-11 06:28 2153472 —-a-w- c:\windows\System32\oobefldr.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-21 02:25 202240 —-a-w- c:\program files\Windows Media Player\wmpnscfg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiSpywareOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x]
R3 PCD5SRVC{3F6A8B78-EC003E00-05040104};PCD5SRVC{3F6A8B78-EC003E00-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [2008-11-04 22904]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 Apache2.2;Remote Access Media Server;c:\program files\Common Files\Dell\apache\bin\httpd.exe [2007-09-21 15872]
R4 CinemaNow Service;CinemaNow Service;c:\program files\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe [2008-09-05 137080]
R4 dsl-db;Remote Access DB;c:\program files\Common Files\Dell\MySQL\bin\mysqld.exe [2007-09-14 5730304]
R4 dsl-fs-sync;Remote Access File Sync Service;c:\program files\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe [2009-04-13 189680]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 RapportKELL;RapportKELL;c:\windows\System32\Drivers\RapportKELL.sys [2011-11-07 56208]
S0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\DRIVERS\tdrpm273.sys [2011-11-16 752128]
S1 RapportCerberus_32301;RapportCerberus_32301;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_32301.sys [2011-11-07 227312]
S1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [2011-11-07 71440]
S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [2011-11-07 164112]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-11-14 116608]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\aestsrv.exe [2007-09-20 73728]
S2 afcdpsrv;Acronis Nonstop Backup Service;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [2011-11-16 3246040]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [2011-11-07 931640]
S2 uvnc_service;UltraVNC Server;c:\programdata\UltraVNC\winvnc.exe [2008-08-31 1519168]
S2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32coinst,serviceStartProc [x]
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [2011-11-16 167968]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2008-12-30 144128]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-08-31 22216]
S3 RapportIaso;RapportIaso;c:\programdata\trusteer\rapport\store\exts\rapportms\28896\rapportiaso.sys [2011-08-24 21520]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - RAPPORTIASO
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-07 c:\windows\Tasks\User_Feed_Synchronization-{D0486C69-5E5B-4E65-BDF3-BB232D6413F3}.job
- c:\windows\system32\msfeedssync.exe [2011-10-13 21:29]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
mStart Page = about:blank
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Free YouTube to MP3 Converter - c:\users\excell\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\excell\AppData\Roaming\Mozilla\Firefox\Profiles\a9zmt3eo.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://www.google.com/webhp?ie=UTF-8&oe=UTF-8
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-eSnips_Downloader - c:\program files\Logia\eSnipsDownloader\eSnips_Downloader.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-07 21:03
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCD5SRVC{3F6A8B78-EC003E00-05040104}]
"ImagePath"="\??\c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'Explorer.exe'(3524)
c:\program files\Fingerprint Reader Suite\farchns.dll
c:\program files\Fingerprint Reader Suite\infra.dll
c:\windows\system32\btncopy.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvvsvc.exe
c:\program files\Sandboxie\SbieSvc.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Fingerprint Reader Suite\upeksvr.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\WLANExt.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\STacSV.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2011-12-07 21:05:20 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-07 21:05
ComboFix2.txt 2011-05-08 20:00
ComboFix3.txt 2011-05-07 21:10
.
Pre-Run: 129,562,492,928 bytes free
Post-Run: 126,754,553,856 bytes free
.
- - End Of File - - 3205EAB52B129ED32C96E3BE42D9B78D
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.









Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.


Also tell me how the computer is running now.
Heres my log from malwarebytes. Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8331 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.19154 07/12/2011 23:47:10 mbam-log-2011-12-07 (23-47-10).txt Scan type: Quick scan Objects scanned: 199643 Time elapsed: 3 minute(s), 3 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
And heres my log from ESET scanner. ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=612dac024938a1459673dbe8d95615b9 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-12-08 01:01:14 # local_time=2011-12-08 01:01:14 (+0000, GMT Standard Time) # country="United Kingdom" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=5892 16776573 100 95 3558150 160834828 0 0 # compatibility_mode=8192 67108863 100 0 3749 3749 0 0 # scanned=190961 # found=1 # cleaned=1 # scan_time=3974 C:\System Volume Information\SystemRestore\FRStaging\Users\excell\AppData\Local\temp\ICReinstall\cnet_audiocdcreator_demo_exe.exe a variant of Win32/InstallCore.D application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
The system seems to be running great now. I opened about 13 youtube tabs and let them run simultaneously for a minute as i switched back and forth and scrolled up and down. It didnt freeze for a second and it definitely didnt crash. No problems whatsoever. ^_^ Thanks a lot! Just one more thing, i used to be able to open a link in a new tab by clicking both left and right button at the same time on the mouse pad instead of right clicking and selecting OPEN NEW TAB, and the same to close a tab. But it doesnt let me do that anymore. Any idea how i could change that back?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI