This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe (High CPU and memory usage) [Closed]

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey guys, this is my second attempt at a post because my last one had a "connection time out" type of deal happen. So if this somehow double posts I apologize in advance. On to the good stuff. I've been having problems with my laptop being extremely slow because of PING.exe and a few others. I've tried resolving the issue by myself using programs such as Spybot Search and Destroy, Malwarebytes, SUPERantispyware and I believe a program named Rkill but to no avail. Please be aware, and bare with me. because I am not very computer savvy but I am good at following instructions =) A few other things: -Having issues with plugin-container.exe but I heard it's common with the new Firefox update, not too sure. -Also with svchost.exe(LocalSystemNetwork) -Have issues with my internet timing out, getting "connection timed out" type of message even if I am connected and running on the internet. The other computers in the household do not have this issue. -I keep getting random pop-ups to random sites while browsing and sometimes even when I'm watching a video on YouTube or something without even clicking on anything That should be it but if I think of anything else I'll be sure to let you guys know. Any help would be appreciated. Thanks in advance guys. I'll try keeping my eye on this post religiously unless I am at work.
Hello and Welcome to WhatTheTech Forums

My name is BlackPegasus and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested


Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.

=================
NEXT

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, it will open 2 reports, DDS.txt and attach.txt.
  • Save both reports to your desktop.
=================
NEXT

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


Summary of the logs I need from you in your next post:

DDS.Txt and attach.txt
aswMBR log
Security Check log
Hey BlackPegasus, thank you so much for helping. I'm not sure if this is important but when I was following your steps I launched aswMBR, and I thought it finished because the time on the left side wasnt moving. Well, I then proceeded to run the next two checks and they finished before aswMBR. Not sure if thats a problem but I thought I'd mention it. Nonetheless, here are my logs separated by a line of "="

aswMBR

aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-12-15 22:42:59
—————————–
22:42:59.548 OS Version: Windows x64 6.1.7600
22:42:59.548 Number of processors: 4 586 0x2505
22:42:59.549 ComputerName: EVOLUTIONMR-PC UserName: EvolutionMR
22:43:04.121 Initialize success
22:43:58.471 AVAST engine defs: 11121502
22:44:13.593 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
22:44:13.595 Disk 0 Vendor: ST950042 0001 Size: 476940MB BusType: 3
22:44:13.604 Disk 0 MBR read successfully
22:44:13.606 Disk 0 MBR scan
22:44:13.610 Disk 0 Windows VISTA default MBR code
22:44:13.613 Service scanning
22:44:14.923 Modules scanning
22:44:14.927 Disk 0 trace - called modules:
22:44:14.930
22:44:17.148 AVAST engine scan C:\windows
22:44:19.251 AVAST engine scan C:\windows\system32
22:44:27.730 File: C:\windows\system32\consrv.dll **INFECTED** Win64:Sirefef-C [Drp]
22:45:54.898 AVAST engine scan C:\windows\system32\drivers
22:46:08.166 AVAST engine scan C:\Users\EvolutionMR
22:51:40.897 Disk 0 MBR has been saved successfully to "C:\Users\EvolutionMR\Desktop\MBR.dat"
22:51:40.902 The log file has been saved successfully to "C:\Users\EvolutionMR\Desktop\aswMBR.txt"


aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-12-15 22:42:59
—————————–
22:42:59.548 OS Version: Windows x64 6.1.7600
22:42:59.548 Number of processors: 4 586 0x2505
22:42:59.549 ComputerName: EVOLUTIONMR-PC UserName: EvolutionMR
22:43:04.121 Initialize success
22:43:58.471 AVAST engine defs: 11121502
22:44:13.593 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
22:44:13.595 Disk 0 Vendor: ST950042 0001 Size: 476940MB BusType: 3
22:44:13.604 Disk 0 MBR read successfully
22:44:13.606 Disk 0 MBR scan
22:44:13.610 Disk 0 Windows VISTA default MBR code
22:44:13.613 Service scanning
22:44:14.923 Modules scanning
22:44:14.927 Disk 0 trace - called modules:
22:44:14.930
22:44:17.148 AVAST engine scan C:\windows
22:44:19.251 AVAST engine scan C:\windows\system32
22:44:27.730 File: C:\windows\system32\consrv.dll **INFECTED** Win64:Sirefef-C [Drp]
22:45:54.898 AVAST engine scan C:\windows\system32\drivers
22:46:08.166 AVAST engine scan C:\Users\EvolutionMR
22:51:40.897 Disk 0 MBR has been saved successfully to "C:\Users\EvolutionMR\Desktop\MBR.dat"
22:51:40.902 The log file has been saved successfully to "C:\Users\EvolutionMR\Desktop\aswMBR.txt"
22:57:21.649 AVAST engine scan C:\ProgramData
22:58:44.863 Scan finished successfully
22:59:00.551 Disk 0 MBR has been saved successfully to "C:\Users\EvolutionMR\Desktop\MBR.dat"
22:59:00.567 The log file has been saved successfully to "C:\Users\EvolutionMR\Desktop\aswMBR.txt"


==================================================

checkup

Results of screen317's Security Check version 0.99.28
Windows 7 x64 (UAC is enabled)
Internet Explorer 8 Out of date!
``````````````````````````````
Antivirus/Firewall Check:

Windows Security Center service is not running! This report may not be accurate!
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:

Ad-Aware
Malwarebytes' Anti-Malware
Java™ 6 Update 26
Java version out of date!
Adobe Reader 9 Adobe Reader out of date!
Mozilla Firefox (8.0.1)
````````````````````````````````
Process Check:
objlist.exe by Laurent

Ad-Aware AAWService.exe
Ad-Aware AAWTray.exe
``````````End of Log````````````


===========================================

DDS

.
DDS (Ver_11-03-05.01) - NTFS_AMD64
Run by [removed] at 22:27:18.18 on Wed 12/14/2011
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_26
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3891.1711 [GMT -6:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
C:\windows\System32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\ThpSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\windows\system32\wbem\unsecapp.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Program Files (x86)\Lavasoft\Ad-Aware\AWSC.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AWSC.exe
C:\windows\system32\svchost.exe -k HPService
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\ThpSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\TECO\Teco.exe
C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe
C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\TOSHIBA\FlashCards\Hotkey\TcrdKBB.exe
C:\windows\system32\igfxext.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\igfxsrvc.exe
C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\windows\system32\wuauclt.exe
C:\Windows\system32\WUDFHost.exe
C:\windows\SysWOW64\ping.exe
C:\windows\system32\conhost.exe
C:\windows\system32\taskhost.exe
C:\windows\system32\SearchProtocolHost.exe
C:\windows\system32\SearchFilterHost.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\DllHost.exe
C:\Users\EvolutionMR\Downloads\dds.scr
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/ig?brand=TSND&bmod=TSND
uDefault_Page_URL = hxxp://www.google.com/ig?brand=TSND&bmod=TSND
mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSND&bmod=TSND
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSND&bmod=TSND
uInternet Settings,ProxyOverride = ;*.local
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
mWinlogon: Userinit=userinit.exe,
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: TOSHIBA Media Controller Plug-in: {f3c88694-effa-4d78-b409-54b7b2535b14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [Best Buy pc app] C:\Users\EvolutionMR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Best Buy\Best Buy pc app.appref-ms
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
mRun: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP
mRun: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
mRun: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
mRun: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
mRun: [TSleepSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
dRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Notify: hretywa - C:\windows\system32\config\systemprofile\AppData\Local\hretywa.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg64.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File
mRun-x64: [(Default)]
mRun-x64: [IgfxTray] C:\windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] C:\windows\system32\hkcmd.exe
mRun-x64: [Persistence] C:\windows\system32\igfxpers.exe
mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
mRun-x64: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3
mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun-x64: [ThpSrv] C:\windows\system32\thpsrv /logon
mRun-x64: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun-x64: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
mRun-x64: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun-x64: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun-x64: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
mRun-x64: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
mRun-x64: [SmartFaceVWatcher] %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
mRun-x64: [IntelWirelessWiMAX] "C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe" /tasktray /nosplash
mRun-x64: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe
mRun-x64: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
mRun-x64: [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
mRun-x64: [TosReelTimeMonitor] %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\EVOLUT~1\AppData\Roaming\Mozilla\Firefox\Profiles\uh5qpyvv.default\
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R?2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [2010-6-7 408576]
R0 Lbd;Lbd;C:\Windows\System32\drivers\Lbd.sys [2011-9-5 69376]
R0 Thpdrv;TOSHIBA HDD Protection Driver;C:\Windows\System32\drivers\thpdrv.sys [2009-6-29 34880]
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;C:\Windows\System32\drivers\Thpevm.sys [2009-6-29 14784]
R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\Windows\System32\drivers\tos_sps64.sys [2010-11-10 482384]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-13 59904]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-7-18 140672]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-11-3 2152152]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-9-14 508264]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:\Program Files\TOSHIBA\TECO\TecoService.exe [2010-7-28 267192]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;C:\Windows\System32\drivers\TVALZFL.sys [2009-6-19 14472]
R2 UNS;Intel® Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-11-10 2320920]
R2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [2010-6-7 911872]
R3 bpenum;bpenum;C:\Windows\System32\drivers\bpenum.sys [2010-5-16 71168]
R3 bpusb;bpusb;C:\Windows\System32\drivers\bpusb.sys [2010-5-16 81920]
R3 HECIx64;Intel® Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-11-10 56344]
R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2010-2-26 158976]
R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-2-3 271872]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys [2011-9-5 17152]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2011-12-8 25416]
R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETwNs64.sys [2010-7-28 7821312]
R3 PGEffect;Pangu effect driver;C:\Windows\System32\drivers\PGEffect.sys [2010-11-10 35008]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-11-10 331880]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2010-9-14 760168]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2010-9-14 268648]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2010-9-14 25960]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2010-9-14 22376]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-9-14 219496]
R3 TMachInfo;TMachInfo;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2010-11-10 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-2-5 137560]
R3 TPCHSrv;TPCH Service;C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2010-7-22 822192]
R3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2011-5-10 51712]
R3 wdkmd;Intel WiDi KMD;C:\Windows\System32\drivers\WDKMD.sys [2010-6-18 39832]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-8-29 136176]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-8 366152]
S3 acpials;ALS Sensor Filter;C:\Windows\System32\drivers\acpials.sys [2009-7-14 9728]
S3 bpmp;Intel® Centrino® WiMAX 6050 Series;C:\Windows\System32\drivers\bpmp.sys [2010-5-16 175104]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-8-29 136176]
S3 JMCR;JMCR;C:\Windows\System32\drivers\jmcr.sys [2010-5-18 164464]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 PinnacleMarvinAVS;Pinnacle AVStream Service for MovieBox Deluxe, 500-USB and 700-USB;C:\Windows\System32\drivers\MarvinAVS64.sys [2007-5-9 484736]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-12-4 1255736]
.
=============== Created Last 30 ================
.
2011-12-08 08:47:12 ——– d—–w- C:\Users\EVOLUT~1\AppData\Roaming\SUPERAntiSpyware.com
2011-12-08 08:46:53 ——– d—–w- C:\PROGRA~3\!SASCORE
2011-12-08 08:46:46 ——– d—–w- C:\Program Files\SUPERAntiSpyware
2011-12-08 08:46:46 ——– d—–w- C:\PROGRA~3\SUPERAntiSpyware.com
2011-12-08 08:29:08 ——– d—–w- C:\Users\EVOLUT~1\AppData\Roaming\Malwarebytes
2011-12-08 08:28:58 ——– d—–w- C:\PROGRA~3\Malwarebytes
2011-12-08 08:28:55 25416 —-a-w- C:\windows\System32\drivers\mbam.sys
2011-12-08 08:28:55 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-12-04 17:25:36 ——– d—–we C:\windows\system64
2011-12-02 11:49:46 8822856 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{26A0E8C9-2584-45FC-8BA6-91C44BC6B167}\mpengine.dll
.
==================== Find3M ====================
.
2011-11-24 05:00:47 3141632 —-a-w- C:\windows\System32\win32k.sys
2011-11-05 05:26:29 1197568 —-a-w- C:\windows\System32\wininet.dll
2011-11-05 05:23:10 57856 —-a-w- C:\windows\System32\licmgr10.dll
2011-11-05 05:17:42 2048 —-a-w- C:\windows\System32\tzres.dll
2011-11-05 04:35:50 981504 —-a-w- C:\windows\SysWow64\wininet.dll
2011-11-05 04:34:15 44544 —-a-w- C:\windows\SysWow64\licmgr10.dll
2011-11-05 04:30:11 2048 —-a-w- C:\windows\SysWow64\tzres.dll
2011-11-05 04:07:32 482816 —-a-w- C:\windows\System32\html.iec
2011-11-05 03:28:41 386048 —-a-w- C:\windows\SysWow64\html.iec
2011-11-05 03:25:44 1638912 —-a-w- C:\windows\System32\mshtml.tlb
2011-11-05 02:55:38 1638912 —-a-w- C:\windows\SysWow64\mshtml.tlb
2011-11-03 18:06:56 69376 —-a-w- C:\windows\System32\drivers\Lbd.sys
2011-10-26 05:19:07 43520 —-a-w- C:\windows\System32\csrsrv.dll
2011-10-15 06:25:12 723456 —-a-w- C:\windows\System32\EncDec.dll
2011-10-15 05:48:52 534528 —-a-w- C:\windows\SysWow64\EncDec.dll
2011-09-29 16:24:44 1897328 —-a-w- C:\windows\System32\drivers\tcpip.sys
.
============= FINISH: 22:27:32.78 ===============


============================================================

Attach

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 11/30/2010 6:46:48 PM
System Uptime: 12/14/2011 4:52:29 PM (6 hours ago)
.
Motherboard: TOSHIBA | | NWQAA
Processor: Intel® Core™ i3 CPU M 370 @ 2.40GHz | CPU | 2399/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 453 GiB total, 359.781 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Intel® Centrino® WiMAX 6250
Device ID: {12110A2A-BBCC-418B-B9F4-76099D720767}\BPMP_8086_0186\1&1869C5E3&0&00
Manufacturer: Intel Corporation
Name: Intel® Centrino® WiMAX 6250
PNP Device ID: {12110A2A-BBCC-418B-B9F4-76099D720767}\BPMP_8086_0186\1&1869C5E3&0&00
Service: bpmp
.
==== System Restore Points ===================
.
RP151: 11/25/2011 5:49:12 AM - Windows Update
RP152: 11/29/2011 6:15:10 PM - Windows Update
RP153: 12/2/2011 5:49:15 AM - Windows Update
RP154: 12/6/2011 12:17:56 AM - Installed Ad-Aware
RP155: 12/6/2011 12:18:39 AM - Installed Ad-Aware
RP156: 12/14/2011 6:58:22 AM - Windows Update
RP158: 12/14/2011 7:01:35 AM - Scheduled Checkpoint
RP159: 12/14/2011 10:10:57 PM - OTL Restore Point - 12/14/2011 10:10:56 PM
.
==== Installed Programs ======================
.
Ad-Aware
Adobe AIR
Adobe Reader 9.3
AIO_CDA_ProductContext
AIO_CDA_Software
AIO_Scan
Apple Application Support
Apple Software Update
BufferChm
C4100
c4100_Help
Copy
Destinations
DeviceDiscovery
DocProc
Fax
Google Toolbar for Internet Explorer
Google Update Helper
GPBaseService2
HP Update
HPPhotoGadget
HPPhotoSmartDiscLabelContent1
HPPhotosmartEssential
HPProductAssistant
HPSSupply
Intel® Graphics Media Accelerator Driver
Intel® Management Engine Components
Intel® Rapid Storage Technology
Java Auto Updater
Java™ 6 Update 26
JMicron Flash Media Controller Driver
Junk Mail filter update
Label@Once 1.0
Malwarebytes' Anti-Malware version 1.51.2.1300
MarketResearch
Microsoft Choice Guard
Microsoft Office 2010
Microsoft Office Click-to-Run 2010
Microsoft Office Starter 2010 - English
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft WSE 3.0 Runtime
Mozilla Firefox 8.0.1 (x86 en-US)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Pinnacle Studio 14
QuickTime
Realtek Ethernet Controller Driver For Windows 7
Realtek High Definition Audio Driver
Scan
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Skype Toolbars
Skype™ 5.1
SmartWebPrinting
SolutionCenter
Spybot - Search & Destroy
StarCraft II
Status
The Sims™ 3
Toolbox
TOSHIBA Application Installer
TOSHIBA Assist
Toshiba Book Place
TOSHIBA Bulletin Board
TOSHIBA DVD PLAYER
TOSHIBA eco Utility
TOSHIBA Face Recognition
TOSHIBA Flash Cards Support Utility
TOSHIBA Hardware Setup
TOSHIBA HDD/SSD Alert
TOSHIBA Media Controller
TOSHIBA Media Controller Plug-in
TOSHIBA Quality Application
TOSHIBA ReelTime
TOSHIBA Service Station
TOSHIBA Sleep Utility
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
TOSHIBA Web Camera Application
ToshibaRegistration
TrayApp
UnloadSupport
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Utility Common Driver
WebReg
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
Yahoo! Toolbar
.
==== Event Viewer Messages From Past Week ========
.
12/8/2011 7:04:04 AM, Error: Service Control Manager [7022] - The Intel® PROSet/Wireless WiMAX Red Bend Device Management Service service hung on starting.
12/8/2011 3:00:17 AM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
12/8/2011 3:00:16 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
12/8/2011 3:00:16 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
12/8/2011 3:00:15 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
12/8/2011 3:00:07 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
12/8/2011 3:00:03 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: discache SASDIFSV SASKUTIL spldr Wanarpv6
12/8/2011 3:00:01 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
12/8/2011 3:00:01 AM, Error: Service Control Manager [7001] - The Client Virtualization Handler service depends on the Application Virtualization Client service which failed to start because of the following error: The dependency service or group failed to start.
12/8/2011 2:22:39 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: discache spldr Wanarpv6
12/8/2011 2:21:44 AM, Error: Service Control Manager [7043] - The Group Policy Client service did not shut down properly after receiving a preshutdown control.
12/14/2011 9:03:45 PM, Error: Service Control Manager [7034] - The MBAMService service terminated unexpectedly. It has done this 1 time(s).
12/14/2011 7:07:20 AM, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.
12/14/2011 7:06:57 AM, Error: Service Control Manager [7022] - The Intel® PROSet/Wireless WiMAX Red Bend Device Management Service service hung on starting.
12/14/2011 7:05:23 AM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.
12/14/2011 7:05:23 AM, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.
12/14/2011 7:05:23 AM, Error: Service Control Manager [7003] - The Internet Connection Sharing (ICS) service depends the following service: BFE. This service might not be installed.
12/14/2011 7:05:23 AM, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.
12/14/2011 7:01:06 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the FDResPub service.
12/14/2011 7:00:36 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the upnphost service.
12/14/2011 10:06:03 PM, Error: Microsoft-Windows-DNS-Client [1012] - There was an error while attempting to read the local hosts file.
12/11/2011 7:04:54 AM, Error: Service Control Manager [7022] - The Intel® PROSet/Wireless WiMAX Red Bend Device Management Service service hung on starting.
12/11/2011 1:03:41 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SSDPSRV service.
12/11/2011 1:03:11 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the FontCache service.
.
==== End Of File ===========================
Hello LexusISF,

Thank you for the logs. :thumbup:


Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon.
They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link
here

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
ComboFix 11-12-16.03 - EvolutionMR 12/16/2011 19:02:07.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3891.2506 [GMT -6:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116} SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\xp c:\programdata\xp\EBLib.dll c:\programdata\xp\TPwSav.sys c:\users\EvolutionMR\Documents\~WRL0779.tmp c:\users\EvolutionMR\Documents\~WRL1211.tmp c:\users\EvolutionMR\Documents\~WRL3601.tmp c:\users\EvolutionMR\Documents\~WRL4078.tmp c:\windows\system32\consrv.dll c:\windows\System64 . . ((((((((((((((((((((((((( Files Created from 2011-11-17 to 2011-12-17 ))))))))))))))))))))))))))))))) . . 2011-12-17 01:07 . 2011-12-17 01:07 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-12-08 08:47 . 2011-12-08 08:47 ——– d—–w- c:\users\EvolutionMR\AppData\Roaming\SUPERAntiSpyware.com 2011-12-08 08:46 . 2011-12-08 08:46 ——– d—–w- c:\programdata\!SASCORE 2011-12-08 08:46 . 2011-12-08 08:59 ——– d—–w- c:\program files\SUPERAntiSpyware 2011-12-08 08:46 . 2011-12-08 08:46 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2011-12-08 08:37 . 2011-12-08 08:37 ——– d—–w- c:\windows\SysWow64\config\systemprofile\Tracing 2011-12-08 08:29 . 2011-12-08 08:29 ——– d—–w- c:\users\EvolutionMR\AppData\Roaming\Malwarebytes 2011-12-08 08:28 . 2011-12-08 08:28 ——– d—–w- c:\programdata\Malwarebytes 2011-12-08 08:28 . 2011-12-08 08:28 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-12-08 08:28 . 2011-08-31 23:00 25416 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-12-02 11:49 . 2011-11-21 11:40 8822856 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{26A0E8C9-2584-45FC-8BA6-91C44BC6B167}\mpengine.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-09-29 16:24 . 2011-11-09 12:56 1897328 —-a-w- c:\windows\system32\drivers\tcpip.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-08-30 39408] "EA Core"="c:\program files (x86)\Electronic Arts\EADM\Core.exe" [2009-03-28 3325952] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-12-08 5495680] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2009-12-25 34160] "HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2010-03-05 423936] "SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2010-02-23 352256] "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136] "TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-05-02 2454840] "hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-10-09 421736] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2010-6-24 9216] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hretywa] 2011-12-10 07:50 11264 —-a-w- c:\windows\System32\config\systemprofile\AppData\Local\hretywa.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . 2;2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;c:\program files\Intel\WiMAX\Bin\DMAgent.exe [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-30 136176] R3 acpials;ALS Sensor Filter;c:\windows\system32\DRIVERS\acpials.sys [x] R3 bpmp;Intel® Centrino® WiMAX 6050 Series;c:\windows\system32\DRIVERS\bpmp.sys [x] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-30 136176] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 PinnacleMarvinAVS;Pinnacle AVStream Service for MovieBox Deluxe, 500-USB and 700-USB;c:\windows\system32\DRIVERS\MarvinAVS64.sys [x] R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys [x] S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [x] S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-12-08 140672] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-09-14 508264] S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-07-28 267192] S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-03-03 2320920] S2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;c:\program files\Intel\WiMAX\Bin\AppSrv.exe [2010-06-07 911872] S3 bpenum;bpenum;c:\windows\system32\DRIVERS\bpenum.sys [x] S3 bpusb;bpusb;c:\windows\system32\Drivers\bpusb.sys [x] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [x] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-09-14 219496] S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-06 137560] S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-07-23 822192] S3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2011-12-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-30 04:44] . 2011-12-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-30 04:44] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ThpSrv"="c:\windows\system32\thpsrv" [X] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-04-26 161304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-04-26 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-04-26 413208] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-03-22 10134560] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-03-22 896032] "IntelWirelessWiMAX"="c:\program files\Intel\WiMAX\Bin\WiMAXCU.exe" [2010-06-08 1441792] "TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-06 709976] "combofix"="c:\combofix\CF30967.3XE" [2009-07-14 344576] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ig?brand=TSND&bmod=TSND mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSND&bmod=TSND mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = ;*.local IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html TCP: DhcpNameServer = [removed] [removed] FF - ProfilePath - c:\users\EvolutionMR\AppData\Roaming\Mozilla\Firefox\Profiles\uh5qpyvv.default\ FF - user.js: yahoo.ytff.general.dontshowhpoffer - true . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKLM-Run-TSleepSrv - %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe Toolbar-Locked - (no file) HKLM-Run-(Default) - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE HKLM-Run-HSON - c:\program files (x86)\TOSHIBA\TBS\HSON.exe HKLM-Run-SmoothView - c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe HKLM-Run-00TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe HKLM-Run-SmartFaceVWatcher - c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe c:\program files (x86)\HP\Digital Imaging\bin\hpqbam08.exe c:\program files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe . ************************************************************************** . Completion time: 2011-12-16 19:14:34 - machine was rebooted ComboFix-quarantined-files.txt 2011-12-17 01:14 . Pre-Run: 391,624,654,848 bytes free Post-Run: 392,191,754,240 bytes free . - - End Of File - - 4BED3DE316080832F11168AC39BEBE48
Hello LexusISF,

Thanks for the log, I'm going through it now. Please download and run TDSSKiller and SystemLook.


Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
  • Only if Malicious objects are found then ensure Cure is selected
  • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
=================
NEXT

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    consrv.dll
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


Summary of the logs I need from you in your next post:
TDSSKiller log
SystemLook.txt
TDSS 21:46:27.0631 7768 TDSS rootkit removing tool [removed] Dec 13 2011 10:39:31 21:46:27.0953 7768 ============================================================ 21:46:27.0953 7768 Current date / time: 2011/12/16 21:46:27.0953 21:46:27.0953 7768 SystemInfo: 21:46:27.0953 7768 21:46:27.0953 7768 OS Version: 6.1.7600 ServicePack: 0.0 21:46:27.0953 7768 Product type: Workstation 21:46:27.0953 7768 ComputerName: EVOLUTIONMR-PC 21:46:27.0954 7768 UserName: EvolutionMR 21:46:27.0954 7768 Windows directory: C:\windows 21:46:27.0954 7768 System windows directory: C:\windows 21:46:27.0954 7768 Running under WOW64 21:46:27.0954 7768 Processor architecture: Intel x64 21:46:27.0954 7768 Number of processors: 4 21:46:27.0954 7768 Page size: 0x1000 21:46:27.0954 7768 Boot type: Normal boot 21:46:27.0954 7768 ============================================================ 21:46:28.0318 7768 Initialize success 21:46:35.0903 7884 ============================================================ 21:46:35.0903 7884 Scan started 21:46:35.0903 7884 Mode: Manual; 21:46:35.0903 7884 ============================================================ 21:46:37.0045 7884 1394ohci (969c91060cbb5d17cb8440b5f78b4c51) C:\windows\system32\DRIVERS\1394ohci.sys 21:46:37.0050 7884 1394ohci - ok 21:46:37.0119 7884 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\windows\system32\DRIVERS\ACPI.sys 21:46:37.0124 7884 ACPI - ok 21:46:37.0166 7884 acpials (12c5274cd87449a2a37a607cdb321922) C:\windows\system32\DRIVERS\acpials.sys 21:46:37.0168 7884 acpials - ok 21:46:37.0205 7884 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\windows\system32\DRIVERS\acpipmi.sys 21:46:37.0208 7884 AcpiPmi - ok 21:46:37.0236 7884 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\windows\system32\DRIVERS\adp94xx.sys 21:46:37.0243 7884 adp94xx - ok 21:46:37.0266 7884 adpahci (597f78224ee9224ea1a13d6350ced962) C:\windows\system32\DRIVERS\adpahci.sys 21:46:37.0272 7884 adpahci - ok 21:46:37.0295 7884 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\windows\system32\DRIVERS\adpu320.sys 21:46:37.0311 7884 adpu320 - ok 21:46:37.0370 7884 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\windows\system32\drivers\afd.sys 21:46:37.0379 7884 AFD - ok 21:46:37.0396 7884 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\windows\system32\DRIVERS\agp440.sys 21:46:37.0398 7884 agp440 - ok 21:46:37.0426 7884 aliide (5812713a477a3ad7363c7438ca2ee038) C:\windows\system32\DRIVERS\aliide.sys 21:46:37.0427 7884 aliide - ok 21:46:37.0458 7884 amdide (1ff8b4431c353ce385c875f194924c0c) C:\windows\system32\DRIVERS\amdide.sys 21:46:37.0460 7884 amdide - ok 21:46:37.0494 7884 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\windows\system32\DRIVERS\amdk8.sys 21:46:37.0497 7884 AmdK8 - ok 21:46:37.0514 7884 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\windows\system32\DRIVERS\amdppm.sys 21:46:37.0517 7884 AmdPPM - ok 21:46:37.0551 7884 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\windows\system32\drivers\amdsata.sys 21:46:37.0554 7884 amdsata - ok 21:46:37.0580 7884 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\windows\system32\DRIVERS\amdsbs.sys 21:46:37.0584 7884 amdsbs - ok 21:46:37.0608 7884 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\windows\system32\drivers\amdxata.sys 21:46:37.0610 7884 amdxata - ok 21:46:37.0623 7884 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\windows\system32\drivers\appid.sys 21:46:37.0624 7884 AppID - ok 21:46:37.0697 7884 arc (c484f8ceb1717c540242531db7845c4e) C:\windows\system32\DRIVERS\arc.sys 21:46:37.0701 7884 arc - ok 21:46:37.0717 7884 arcsas (019af6924aefe7839f61c830227fe79c) C:\windows\system32\DRIVERS\arcsas.sys 21:46:37.0719 7884 arcsas - ok 21:46:37.0738 7884 AsyncMac (769765ce2cc62867468cea93969b2242) C:\windows\system32\DRIVERS\asyncmac.sys 21:46:37.0740 7884 AsyncMac - ok 21:46:37.0772 7884 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\windows\system32\DRIVERS\atapi.sys 21:46:37.0774 7884 atapi - ok 21:46:37.0840 7884 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\windows\system32\DRIVERS\bxvbda.sys 21:46:37.0848 7884 b06bdrv - ok 21:46:37.0900 7884 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\windows\system32\DRIVERS\b57nd60a.sys 21:46:37.0906 7884 b57nd60a - ok 21:46:37.0974 7884 Beep (16a47ce2decc9b099349a5f840654746) C:\windows\system32\drivers\Beep.sys 21:46:37.0975 7884 Beep - ok 21:46:38.0017 7884 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\windows\system32\DRIVERS\blbdrive.sys 21:46:38.0019 7884 blbdrive - ok 21:46:38.0090 7884 bowser (19d20159708e152267e53b66677a4995) C:\windows\system32\DRIVERS\bowser.sys 21:46:38.0092 7884 bowser - ok 21:46:38.0145 7884 bpenum (f46dd257fad7d2d097ef32e72220a06c) C:\windows\system32\DRIVERS\bpenum.sys 21:46:38.0147 7884 bpenum - ok 21:46:38.0209 7884 bpmp (e82060aed0f28ed8909f2b07fa276185) C:\windows\system32\DRIVERS\bpmp.sys 21:46:38.0213 7884 bpmp - ok 21:46:38.0260 7884 bpusb (fc6313a5a45c1ae53d0491f0057d5a4d) C:\windows\system32\Drivers\bpusb.sys 21:46:38.0263 7884 bpusb - ok 21:46:38.0281 7884 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\windows\system32\DRIVERS\BrFiltLo.sys 21:46:38.0283 7884 BrFiltLo - ok 21:46:38.0303 7884 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\windows\system32\DRIVERS\BrFiltUp.sys 21:46:38.0305 7884 BrFiltUp - ok 21:46:38.0332 7884 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\windows\System32\Drivers\Brserid.sys 21:46:38.0338 7884 Brserid - ok 21:46:38.0349 7884 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\windows\System32\Drivers\BrSerWdm.sys 21:46:38.0350 7884 BrSerWdm - ok 21:46:38.0372 7884 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\windows\System32\Drivers\BrUsbMdm.sys 21:46:38.0375 7884 BrUsbMdm - ok 21:46:38.0421 7884 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\windows\System32\Drivers\BrUsbSer.sys 21:46:38.0422 7884 BrUsbSer - ok 21:46:38.0443 7884 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\windows\system32\DRIVERS\bthmodem.sys 21:46:38.0445 7884 BTHMODEM - ok 21:46:38.0472 7884 catchme - ok 21:46:38.0514 7884 cdfs (b8bd2bb284668c84865658c77574381a) C:\windows\system32\DRIVERS\cdfs.sys 21:46:38.0517 7884 cdfs - ok 21:46:38.0571 7884 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\windows\system32\DRIVERS\cdrom.sys 21:46:38.0575 7884 cdrom - ok 21:46:38.0645 7884 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\windows\system32\DRIVERS\circlass.sys 21:46:38.0647 7884 circlass - ok 21:46:38.0694 7884 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\windows\system32\CLFS.sys 21:46:38.0700 7884 CLFS - ok 21:46:38.0765 7884 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\windows\system32\DRIVERS\CmBatt.sys 21:46:38.0767 7884 CmBatt - ok 21:46:38.0796 7884 cmdide (e19d3f095812725d88f9001985b94edd) C:\windows\system32\DRIVERS\cmdide.sys 21:46:38.0798 7884 cmdide - ok 21:46:38.0835 7884 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\windows\system32\Drivers\cng.sys 21:46:38.0843 7884 CNG - ok 21:46:38.0898 7884 Compbatt (102de219c3f61415f964c88e9085ad14) C:\windows\system32\DRIVERS\compbatt.sys 21:46:38.0900 7884 Compbatt - ok 21:46:38.0933 7884 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\windows\system32\DRIVERS\CompositeBus.sys 21:46:38.0935 7884 CompositeBus - ok 21:46:38.0972 7884 crcdisk (1c827878a998c18847245fe1f34ee597) C:\windows\system32\DRIVERS\crcdisk.sys 21:46:38.0973 7884 crcdisk - ok 21:46:39.0057 7884 DfsC (9c253ce7311ca60fc11c774692a13208) C:\windows\system32\Drivers\dfsc.sys 21:46:39.0060 7884 DfsC - ok 21:46:39.0090 7884 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\windows\system32\drivers\discache.sys 21:46:39.0092 7884 discache - ok 21:46:39.0128 7884 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\windows\system32\DRIVERS\disk.sys 21:46:39.0131 7884 Disk - ok 21:46:39.0202 7884 Dot4 (b42ed0320c6e41102fde0005154849bb) C:\windows\system32\DRIVERS\Dot4.sys 21:46:39.0206 7884 Dot4 - ok 21:46:39.0254 7884 Dot4Print (85135ad27e79b689335c08167d917cde) C:\windows\system32\DRIVERS\Dot4Prt.sys 21:46:39.0256 7884 Dot4Print - ok 21:46:39.0301 7884 dot4usb (fd05a02b0370bc3000f402e543ca5814) C:\windows\system32\DRIVERS\dot4usb.sys 21:46:39.0303 7884 dot4usb - ok 21:46:39.0348 7884 drmkaud (9b19f34400d24df84c858a421c205754) C:\windows\system32\drivers\drmkaud.sys 21:46:39.0350 7884 drmkaud - ok 21:46:39.0398 7884 DXGKrnl (372117d46a16add8ca6e3ee3b3bdd57c) C:\windows\System32\drivers\dxgkrnl.sys 21:46:39.0424 7884 DXGKrnl - ok 21:46:39.0513 7884 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\windows\system32\DRIVERS\evbda.sys 21:46:39.0591 7884 ebdrv - ok 21:46:39.0656 7884 elxstor (0e5da5369a0fcaea12456dd852545184) C:\windows\system32\DRIVERS\elxstor.sys 21:46:39.0664 7884 elxstor - ok 21:46:39.0681 7884 ErrDev (34a3c54752046e79a126e15c51db409b) C:\windows\system32\DRIVERS\errdev.sys 21:46:39.0683 7884 ErrDev - ok 21:46:39.0701 7884 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\windows\system32\drivers\exfat.sys 21:46:39.0705 7884 exfat - ok 21:46:39.0742 7884 fastfat (0adc83218b66a6db380c330836f3e36d) C:\windows\system32\drivers\fastfat.sys 21:46:39.0746 7884 fastfat - ok 21:46:39.0773 7884 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\windows\system32\DRIVERS\fdc.sys 21:46:39.0778 7884 fdc - ok 21:46:39.0830 7884 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\windows\system32\drivers\fileinfo.sys 21:46:39.0832 7884 FileInfo - ok 21:46:39.0848 7884 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\windows\system32\drivers\filetrace.sys 21:46:39.0850 7884 Filetrace - ok 21:46:39.0862 7884 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\windows\system32\DRIVERS\flpydisk.sys 21:46:39.0863 7884 flpydisk - ok 21:46:39.0885 7884 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\windows\system32\drivers\fltmgr.sys 21:46:39.0890 7884 FltMgr - ok 21:46:39.0914 7884 FsDepends (d43703496149971890703b4b1b723eac) C:\windows\system32\drivers\FsDepends.sys 21:46:39.0916 7884 FsDepends - ok 21:46:39.0934 7884 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\windows\system32\drivers\Fs_Rec.sys 21:46:39.0936 7884 Fs_Rec - ok 21:46:39.0981 7884 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\windows\system32\DRIVERS\fvevol.sys 21:46:39.0986 7884 fvevol - ok 21:46:40.0007 7884 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\windows\system32\DRIVERS\gagp30kx.sys 21:46:40.0009 7884 gagp30kx - ok 21:46:40.0059 7884 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\windows\system32\DRIVERS\GEARAspiWDM.sys 21:46:40.0061 7884 GEARAspiWDM - ok 21:46:40.0144 7884 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\windows\system32\drivers\hcw85cir.sys 21:46:40.0146 7884 hcw85cir - ok 21:46:40.0170 7884 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\windows\system32\drivers\HdAudio.sys 21:46:40.0176 7884 HdAudAddService - ok 21:46:40.0214 7884 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\windows\system32\DRIVERS\HDAudBus.sys 21:46:40.0217 7884 HDAudBus - ok 21:46:40.0278 7884 HECIx64 (b6ac71aaa2b10848f57fc49d55a651af) C:\windows\system32\DRIVERS\HECIx64.sys 21:46:40.0281 7884 HECIx64 - ok 21:46:40.0293 7884 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\windows\system32\DRIVERS\HidBatt.sys 21:46:40.0294 7884 HidBatt - ok 21:46:40.0329 7884 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\windows\system32\DRIVERS\hidbth.sys 21:46:40.0332 7884 HidBth - ok 21:46:40.0364 7884 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\windows\system32\DRIVERS\hidir.sys 21:46:40.0366 7884 HidIr - ok 21:46:40.0402 7884 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\windows\system32\DRIVERS\hidusb.sys 21:46:40.0404 7884 HidUsb - ok 21:46:40.0449 7884 HpSAMD (0886d440058f203eba0e1825e4355914) C:\windows\system32\DRIVERS\HpSAMD.sys 21:46:40.0451 7884 HpSAMD - ok 21:46:40.0503 7884 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\windows\system32\drivers\HTTP.sys 21:46:40.0520 7884 HTTP - ok 21:46:40.0540 7884 hwpolicy (f17766a19145f111856378df337a5d79) C:\windows\system32\drivers\hwpolicy.sys 21:46:40.0541 7884 hwpolicy - ok 21:46:40.0561 7884 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\windows\system32\DRIVERS\i8042prt.sys 21:46:40.0564 7884 i8042prt - ok 21:46:40.0607 7884 iaStor (85977cd13fc16069ce0af7943a811775) C:\windows\system32\DRIVERS\iaStor.sys 21:46:40.0610 7884 iaStor - ok 21:46:40.0651 7884 iaStorV (b75e45c564e944a2657167d197ab29da) C:\windows\system32\drivers\iaStorV.sys 21:46:40.0657 7884 iaStorV - ok 21:46:40.0881 7884 igfx (2a22ab054f4630d2ef4bab2853f6d5f6) C:\windows\system32\DRIVERS\igdkmd64.sys 21:46:41.0043 7884 igfx - ok 21:46:41.0087 7884 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\windows\system32\DRIVERS\iirsp.sys 21:46:41.0089 7884 iirsp - ok 21:46:41.0142 7884 Impcd (dd587a55390ed2295bce6d36ad567da9) C:\windows\system32\DRIVERS\Impcd.sys 21:46:41.0146 7884 Impcd - ok 21:46:41.0221 7884 IntcAzAudAddService (490947a9aff7ca31ef2e08f5776105eb) C:\windows\system32\drivers\RTKVHD64.sys 21:46:41.0264 7884 IntcAzAudAddService - ok 21:46:41.0300 7884 IntcDAud (58cf58dee26c909bd6f977b61d246295) C:\windows\system32\DRIVERS\IntcDAud.sys 21:46:41.0304 7884 IntcDAud - ok 21:46:41.0314 7884 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\windows\system32\DRIVERS\intelide.sys 21:46:41.0315 7884 intelide - ok 21:46:41.0354 7884 intelppm (ada036632c664caa754079041cf1f8c1) C:\windows\system32\DRIVERS\intelppm.sys 21:46:41.0355 7884 intelppm - ok 21:46:41.0378 7884 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\windows\system32\DRIVERS\ipfltdrv.sys 21:46:41.0382 7884 IpFilterDriver - ok 21:46:41.0406 7884 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\windows\system32\DRIVERS\IPMIDrv.sys 21:46:41.0408 7884 IPMIDRV - ok 21:46:41.0421 7884 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\windows\system32\drivers\ipnat.sys 21:46:41.0423 7884 IPNAT - ok 21:46:41.0479 7884 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\windows\system32\drivers\irenum.sys 21:46:41.0481 7884 IRENUM - ok 21:46:41.0499 7884 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\windows\system32\DRIVERS\isapnp.sys 21:46:41.0501 7884 isapnp - ok 21:46:41.0524 7884 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\windows\system32\DRIVERS\msiscsi.sys 21:46:41.0528 7884 iScsiPrt - ok 21:46:41.0567 7884 JMCR (19496fe93696c929392f1595ed1f8bb3) C:\windows\system32\DRIVERS\jmcr.sys 21:46:41.0568 7884 JMCR - ok 21:46:41.0601 7884 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\windows\system32\DRIVERS\kbdclass.sys 21:46:41.0603 7884 kbdclass - ok 21:46:41.0624 7884 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\windows\system32\DRIVERS\kbdhid.sys 21:46:41.0626 7884 kbdhid - ok 21:46:41.0647 7884 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\windows\system32\Drivers\ksecdd.sys 21:46:41.0649 7884 KSecDD - ok 21:46:41.0668 7884 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\windows\system32\Drivers\ksecpkg.sys 21:46:41.0671 7884 KSecPkg - ok 21:46:41.0690 7884 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\windows\system32\drivers\ksthunk.sys 21:46:41.0692 7884 ksthunk - ok 21:46:41.0748 7884 lltdio (1538831cf8ad2979a04c423779465827) C:\windows\system32\DRIVERS\lltdio.sys 21:46:41.0750 7884 lltdio - ok 21:46:41.0802 7884 LPCFilter (41e122f6d1448c94cc05196bc41d6bfb) C:\windows\system32\DRIVERS\LPCFilter.sys 21:46:41.0804 7884 LPCFilter - ok 21:46:41.0827 7884 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\windows\system32\DRIVERS\lsi_fc.sys 21:46:41.0829 7884 LSI_FC - ok 21:46:41.0846 7884 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\windows\system32\DRIVERS\lsi_sas.sys 21:46:41.0849 7884 LSI_SAS - ok 21:46:41.0860 7884 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\windows\system32\DRIVERS\lsi_sas2.sys 21:46:41.0862 7884 LSI_SAS2 - ok 21:46:41.0899 7884 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\windows\system32\DRIVERS\lsi_scsi.sys 21:46:41.0902 7884 LSI_SCSI - ok 21:46:41.0923 7884 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\windows\system32\drivers\luafv.sys 21:46:41.0926 7884 luafv - ok 21:46:41.0971 7884 MarvinBus (024da28053d57e9e32bee52600576bbb) C:\windows\system32\DRIVERS\MarvinBus64.sys 21:46:41.0975 7884 MarvinBus - ok 21:46:42.0044 7884 MBAMProtector (23a854450dab5c9b7a42ab9be6f2e4bd) C:\windows\system32\drivers\mbam.sys 21:46:42.0046 7884 MBAMProtector - ok 21:46:42.0083 7884 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\windows\system32\DRIVERS\megasas.sys 21:46:42.0086 7884 megasas - ok 21:46:42.0107 7884 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\windows\system32\DRIVERS\MegaSR.sys 21:46:42.0112 7884 MegaSR - ok 21:46:42.0135 7884 Modem (800ba92f7010378b09f9ed9270f07137) C:\windows\system32\drivers\modem.sys 21:46:42.0137 7884 Modem - ok 21:46:42.0174 7884 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\windows\system32\DRIVERS\monitor.sys 21:46:42.0175 7884 monitor - ok 21:46:42.0193 7884 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\windows\system32\DRIVERS\mouclass.sys 21:46:42.0195 7884 mouclass - ok 21:46:42.0226 7884 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\windows\system32\DRIVERS\mouhid.sys 21:46:42.0228 7884 mouhid - ok 21:46:42.0253 7884 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\windows\system32\drivers\mountmgr.sys 21:46:42.0255 7884 mountmgr - ok 21:46:42.0280 7884 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\windows\system32\DRIVERS\mpio.sys 21:46:42.0283 7884 mpio - ok 21:46:42.0303 7884 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\windows\system32\drivers\mpsdrv.sys 21:46:42.0306 7884 mpsdrv - ok 21:46:42.0332 7884 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\windows\system32\drivers\mrxdav.sys 21:46:42.0335 7884 MRxDAV - ok 21:46:42.0376 7884 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\windows\system32\DRIVERS\mrxsmb.sys 21:46:42.0380 7884 mrxsmb - ok 21:46:42.0423 7884 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\windows\system32\DRIVERS\mrxsmb10.sys 21:46:42.0433 7884 mrxsmb10 - ok 21:46:42.0452 7884 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\windows\system32\DRIVERS\mrxsmb20.sys 21:46:42.0455 7884 mrxsmb20 - ok 21:46:42.0474 7884 msahci (5c37497276e3b3a5488b23a326a754b7) C:\windows\system32\DRIVERS\msahci.sys 21:46:42.0476 7884 msahci - ok 21:46:42.0496 7884 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\windows\system32\DRIVERS\msdsm.sys 21:46:42.0499 7884 msdsm - ok 21:46:42.0524 7884 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\windows\system32\drivers\Msfs.sys 21:46:42.0526 7884 Msfs - ok 21:46:42.0567 7884 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\windows\System32\drivers\mshidkmdf.sys 21:46:42.0569 7884 mshidkmdf - ok 21:46:42.0588 7884 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\windows\system32\DRIVERS\msisadrv.sys 21:46:42.0590 7884 msisadrv - ok 21:46:42.0631 7884 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\windows\system32\drivers\MSKSSRV.sys 21:46:42.0633 7884 MSKSSRV - ok 21:46:42.0667 7884 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\windows\system32\drivers\MSPCLOCK.sys 21:46:42.0669 7884 MSPCLOCK - ok 21:46:42.0714 7884 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\windows\system32\drivers\MSPQM.sys 21:46:42.0715 7884 MSPQM - ok 21:46:42.0743 7884 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\windows\system32\drivers\MsRPC.sys 21:46:42.0749 7884 MsRPC - ok 21:46:42.0766 7884 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\windows\system32\DRIVERS\mssmbios.sys 21:46:42.0766 7884 mssmbios - ok 21:46:42.0784 7884 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\windows\system32\drivers\MSTEE.sys 21:46:42.0786 7884 MSTEE - ok 21:46:42.0802 7884 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\windows\system32\DRIVERS\MTConfig.sys 21:46:42.0804 7884 MTConfig - ok 21:46:42.0827 7884 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\windows\system32\Drivers\mup.sys 21:46:42.0830 7884 Mup - ok 21:46:42.0879 7884 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\windows\system32\DRIVERS\nwifi.sys 21:46:42.0884 7884 NativeWifiP - ok 21:46:42.0939 7884 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\windows\system32\drivers\ndis.sys 21:46:42.0959 7884 NDIS - ok 21:46:42.0978 7884 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\windows\system32\DRIVERS\ndiscap.sys 21:46:42.0980 7884 NdisCap - ok 21:46:43.0016 7884 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\windows\system32\DRIVERS\ndistapi.sys 21:46:43.0019 7884 NdisTapi - ok 21:46:43.0039 7884 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\windows\system32\DRIVERS\ndisuio.sys 21:46:43.0042 7884 Ndisuio - ok 21:46:43.0060 7884 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\windows\system32\DRIVERS\ndiswan.sys 21:46:43.0064 7884 NdisWan - ok 21:46:43.0095 7884 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\windows\system32\drivers\NDProxy.sys 21:46:43.0097 7884 NDProxy - ok 21:46:43.0121 7884 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\windows\system32\DRIVERS\netbios.sys 21:46:43.0123 7884 NetBIOS - ok 21:46:43.0145 7884 NetBT (9162b273a44ab9dce5b44362731d062a) C:\windows\system32\DRIVERS\netbt.sys 21:46:43.0149 7884 NetBT - ok 21:46:43.0320 7884 NETwNs64 (eb43840babf5589e33186d094de7381d) C:\windows\system32\DRIVERS\NETwNs64.sys 21:46:43.0456 7884 NETwNs64 - ok 21:46:43.0490 7884 nfrd960 (77889813be4d166cdab78ddba990da92) C:\windows\system32\DRIVERS\nfrd960.sys 21:46:43.0493 7884 nfrd960 - ok 21:46:43.0532 7884 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\windows\system32\drivers\Npfs.sys 21:46:43.0534 7884 Npfs - ok 21:46:43.0550 7884 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\windows\system32\drivers\nsiproxy.sys 21:46:43.0552 7884 nsiproxy - ok 21:46:43.0616 7884 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\windows\system32\drivers\Ntfs.sys 21:46:43.0659 7884 Ntfs - ok 21:46:43.0679 7884 Null (9899284589f75fa8724ff3d16aed75c1) C:\windows\system32\drivers\Null.sys 21:46:43.0681 7884 Null - ok 21:46:43.0727 7884 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\windows\system32\drivers\nvraid.sys 21:46:43.0730 7884 nvraid - ok 21:46:43.0763 7884 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\windows\system32\drivers\nvstor.sys 21:46:43.0766 7884 nvstor - ok 21:46:43.0804 7884 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\windows\system32\DRIVERS\nv_agp.sys 21:46:43.0807 7884 nv_agp - ok 21:46:43.0862 7884 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\windows\system32\DRIVERS\ohci1394.sys 21:46:43.0863 7884 ohci1394 - ok 21:46:43.0918 7884 Parport (0086431c29c35be1dbc43f52cc273887) C:\windows\system32\DRIVERS\parport.sys 21:46:43.0921 7884 Parport - ok 21:46:43.0938 7884 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\windows\system32\drivers\partmgr.sys 21:46:43.0940 7884 partmgr - ok 21:46:43.0962 7884 pci (5aab2b170536885de70a6cba8d7ce52b) C:\windows\system32\DRIVERS\pci.sys 21:46:43.0966 7884 pci - ok 21:46:43.0981 7884 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\windows\system32\DRIVERS\pciide.sys 21:46:43.0982 7884 pciide - ok 21:46:44.0004 7884 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\windows\system32\DRIVERS\pcmcia.sys 21:46:44.0008 7884 pcmcia - ok 21:46:44.0032 7884 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\windows\system32\drivers\pcw.sys 21:46:44.0034 7884 pcw - ok 21:46:44.0061 7884 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\windows\system32\drivers\peauth.sys 21:46:44.0079 7884 PEAUTH - ok 21:46:44.0112 7884 PGEffect (663962900e7fea522126ba287715bb4a) C:\windows\system32\DRIVERS\pgeffect.sys 21:46:44.0113 7884 PGEffect - ok 21:46:44.0169 7884 PinnacleMarvinAVS (0050e6bec926c98ac6c16714ff1ad450) C:\windows\system32\DRIVERS\MarvinAVS64.sys 21:46:44.0176 7884 PinnacleMarvinAVS - ok 21:46:44.0227 7884 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\windows\system32\DRIVERS\raspptp.sys 21:46:44.0232 7884 PptpMiniport - ok 21:46:44.0255 7884 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\windows\system32\DRIVERS\processr.sys 21:46:44.0257 7884 Processor - ok 21:46:44.0282 7884 Psched (ee992183bd8eaefd9973f352e587a299) C:\windows\system32\DRIVERS\pacer.sys 21:46:44.0285 7884 Psched - ok 21:46:44.0347 7884 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\windows\system32\DRIVERS\ql2300.sys 21:46:44.0374 7884 ql2300 - ok 21:46:44.0387 7884 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\windows\system32\DRIVERS\ql40xx.sys 21:46:44.0390 7884 ql40xx - ok 21:46:44.0409 7884 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\windows\system32\drivers\qwavedrv.sys 21:46:44.0427 7884 QWAVEdrv - ok 21:46:44.0440 7884 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\windows\system32\DRIVERS\rasacd.sys 21:46:44.0441 7884 RasAcd - ok 21:46:44.0490 7884 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\windows\system32\DRIVERS\AgileVpn.sys 21:46:44.0492 7884 RasAgileVpn - ok 21:46:44.0566 7884 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\windows\system32\DRIVERS\rasl2tp.sys 21:46:44.0569 7884 Rasl2tp - ok 21:46:44.0591 7884 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\windows\system32\DRIVERS\raspppoe.sys 21:46:44.0594 7884 RasPppoe - ok 21:46:44.0608 7884 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\windows\system32\DRIVERS\rassstp.sys 21:46:44.0610 7884 RasSstp - ok 21:46:44.0633 7884 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\windows\system32\DRIVERS\rdbss.sys 21:46:44.0638 7884 rdbss - ok 21:46:44.0669 7884 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\windows\system32\DRIVERS\rdpbus.sys 21:46:44.0672 7884 rdpbus - ok 21:46:44.0705 7884 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\windows\system32\DRIVERS\RDPCDD.sys 21:46:44.0707 7884 RDPCDD - ok 21:46:44.0746 7884 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\windows\system32\drivers\rdpencdd.sys 21:46:44.0748 7884 RDPENCDD - ok 21:46:44.0774 7884 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\windows\system32\drivers\rdprefmp.sys 21:46:44.0775 7884 RDPREFMP - ok 21:46:44.0797 7884 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\windows\system32\drivers\RDPWD.sys 21:46:44.0801 7884 RDPWD - ok 21:46:44.0824 7884 rdyboost (e5dc9ba9e439d6dbdd79f8caacb5bf01) C:\windows\system32\drivers\rdyboost.sys 21:46:44.0828 7884 rdyboost - ok 21:46:44.0875 7884 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\windows\system32\DRIVERS\rspndr.sys 21:46:44.0878 7884 rspndr - ok 21:46:44.0932 7884 RTL8167 (ba3e57c89e6f63808d3f2b11e1a2ad3c) C:\windows\system32\DRIVERS\Rt64win7.sys 21:46:44.0937 7884 RTL8167 - ok 21:46:45.0016 7884 SASDIFSV (3289766038db2cb14d07dc84392138d5) C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS 21:46:45.0016 7884 SASDIFSV - ok 21:46:45.0057 7884 SASKUTIL (58a38e75f3316a83c23df6173d41f2b5) C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS 21:46:45.0058 7884 SASKUTIL - ok 21:46:45.0084 7884 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\windows\system32\DRIVERS\sbp2port.sys 21:46:45.0087 7884 sbp2port - ok 21:46:45.0106 7884 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\windows\system32\DRIVERS\scfilter.sys 21:46:45.0107 7884 scfilter - ok 21:46:45.0148 7884 sdbus (2c8d162efaf73abd36d8bcbb6340cae7) C:\windows\system32\DRIVERS\sdbus.sys 21:46:45.0151 7884 sdbus - ok 21:46:45.0189 7884 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\windows\system32\drivers\secdrv.sys 21:46:45.0190 7884 secdrv - ok 21:46:45.0207 7884 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\windows\system32\DRIVERS\serenum.sys 21:46:45.0208 7884 Serenum - ok 21:46:45.0233 7884 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\windows\system32\DRIVERS\serial.sys 21:46:45.0235 7884 Serial - ok 21:46:45.0248 7884 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\windows\system32\DRIVERS\sermouse.sys 21:46:45.0250 7884 sermouse - ok 21:46:45.0270 7884 sffdisk (a554811bcd09279536440c964ae35bbf) C:\windows\system32\DRIVERS\sffdisk.sys 21:46:45.0271 7884 sffdisk - ok 21:46:45.0283 7884 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\windows\system32\DRIVERS\sffp_mmc.sys 21:46:45.0284 7884 sffp_mmc - ok 21:46:45.0300 7884 sffp_sd (178298f767fe638c9fedcbdef58bb5e4) C:\windows\system32\DRIVERS\sffp_sd.sys 21:46:45.0302 7884 sffp_sd - ok 21:46:45.0313 7884 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\windows\system32\DRIVERS\sfloppy.sys 21:46:45.0314 7884 sfloppy - ok 21:46:45.0369 7884 Sftfs (a40abfdcb75f835fdf3ce0cc64e4250d) C:\windows\system32\DRIVERS\Sftfslh.sys 21:46:45.0386 7884 Sftfs - ok 21:46:45.0415 7884 Sftplay (411769ed1cb12d2b44217734347bdb7a) C:\windows\system32\DRIVERS\Sftplaylh.sys 21:46:45.0419 7884 Sftplay - ok 21:46:45.0441 7884 Sftredir (a14d0df34bbb00ea94da16193d0c7957) C:\windows\system32\DRIVERS\Sftredirlh.sys 21:46:45.0443 7884 Sftredir - ok 21:46:45.0461 7884 Sftvol (393b22addd89979eb1c60898f51c3648) C:\windows\system32\DRIVERS\Sftvollh.sys 21:46:45.0463 7884 Sftvol - ok 21:46:45.0508 7884 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\windows\system32\DRIVERS\SiSRaid2.sys 21:46:45.0510 7884 SiSRaid2 - ok 21:46:45.0526 7884 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\windows\system32\DRIVERS\sisraid4.sys 21:46:45.0529 7884 SiSRaid4 - ok 21:46:45.0541 7884 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\windows\system32\DRIVERS\smb.sys 21:46:45.0543 7884 Smb - ok 21:46:45.0588 7884 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\windows\system32\drivers\spldr.sys 21:46:45.0590 7884 spldr - ok 21:46:45.0637 7884 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\windows\system32\DRIVERS\srv.sys 21:46:45.0644 7884 srv - ok 21:46:45.0671 7884 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\windows\system32\DRIVERS\srv2.sys 21:46:45.0677 7884 srv2 - ok 21:46:45.0695 7884 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\windows\system32\DRIVERS\srvnet.sys 21:46:45.0698 7884 srvnet - ok 21:46:45.0736 7884 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\windows\system32\DRIVERS\stexstor.sys 21:46:45.0738 7884 stexstor - ok 21:46:45.0773 7884 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\windows\system32\DRIVERS\swenum.sys 21:46:45.0775 7884 swenum - ok 21:46:45.0836 7884 SynTP (470c47daba9ca3966f0ab3f835d7d135) C:\windows\system32\DRIVERS\SynTP.sys 21:46:45.0841 7884 SynTP - ok 21:46:45.0909 7884 Tcpip (f18f56efc0bfb9c87ba01c37b27f4da5) C:\windows\system32\drivers\tcpip.sys 21:46:45.0943 7884 Tcpip - ok 21:46:46.0008 7884 TCPIP6 (f18f56efc0bfb9c87ba01c37b27f4da5) C:\windows\system32\DRIVERS\tcpip.sys 21:46:46.0017 7884 TCPIP6 - ok 21:46:46.0041 7884 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\windows\system32\drivers\tcpipreg.sys 21:46:46.0043 7884 tcpipreg - ok 21:46:46.0091 7884 tdcmdpst (fd542b661bd22fa69ca789ad0ac58c29) C:\windows\system32\DRIVERS\tdcmdpst.sys 21:46:46.0093 7884 tdcmdpst - ok 21:46:46.0113 7884 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\windows\system32\drivers\tdpipe.sys 21:46:46.0114 7884 TDPIPE - ok 21:46:46.0126 7884 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\windows\system32\drivers\tdtcp.sys 21:46:46.0127 7884 TDTCP - ok 21:46:46.0145 7884 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\windows\system32\DRIVERS\tdx.sys 21:46:46.0148 7884 tdx - ok 21:46:46.0164 7884 TermDD (c448651339196c0e869a355171875522) C:\windows\system32\DRIVERS\termdd.sys 21:46:46.0166 7884 TermDD - ok 21:46:46.0233 7884 Thpdrv (c013f6acaa9761f571bd28dada7c157d) C:\windows\system32\DRIVERS\thpdrv.sys 21:46:46.0235 7884 Thpdrv - ok 21:46:46.0251 7884 Thpevm (b4e609047434ed948af7bdef2fa66e38) C:\windows\system32\DRIVERS\Thpevm.SYS 21:46:46.0253 7884 Thpevm - ok 21:46:46.0343 7884 tos_sps64 (09ff7b0b1b5c3d225495cb6f5a9b39f8) C:\windows\system32\DRIVERS\tos_sps64.sys 21:46:46.0349 7884 tos_sps64 - ok 21:46:46.0378 7884 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\windows\system32\DRIVERS\tssecsrv.sys 21:46:46.0380 7884 tssecsrv - ok 21:46:46.0416 7884 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\windows\system32\DRIVERS\tunnel.sys 21:46:46.0434 7884 tunnel - ok 21:46:46.0460 7884 TVALZ (550b567f9364d8f7684c3fb3ea665a72) C:\windows\system32\DRIVERS\TVALZ_O.SYS 21:46:46.0462 7884 TVALZ - ok 21:46:46.0507 7884 TVALZFL (9c7191f4b2e49bff47a6c1144b5923fa) C:\windows\system32\DRIVERS\TVALZFL.sys 21:46:46.0509 7884 TVALZFL - ok 21:46:46.0532 7884 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\windows\system32\DRIVERS\uagp35.sys 21:46:46.0534 7884 uagp35 - ok 21:46:46.0604 7884 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\windows\system32\DRIVERS\udfs.sys 21:46:46.0610 7884 udfs - ok 21:46:46.0646 7884 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\windows\system32\DRIVERS\uliagpkx.sys 21:46:46.0649 7884 uliagpkx - ok 21:46:46.0686 7884 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\windows\system32\DRIVERS\umbus.sys 21:46:46.0688 7884 umbus - ok 21:46:46.0708 7884 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\windows\system32\DRIVERS\umpass.sys 21:46:46.0710 7884 UmPass - ok 21:46:46.0757 7884 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\windows\system32\Drivers\usbaapl64.sys 21:46:46.0759 7884 USBAAPL64 - ok 21:46:46.0816 7884 usbaudio (77b01bc848298223a95d4ec23e1785a1) C:\windows\system32\drivers\usbaudio.sys 21:46:46.0818 7884 usbaudio - ok 21:46:46.0856 7884 usbccgp (537a4e03d7103c12d42dfd8ffdb5bdc9) C:\windows\system32\DRIVERS\usbccgp.sys 21:46:46.0858 7884 usbccgp - ok 21:46:46.0892 7884 usbcir (af0892a803fdda7492f595368e3b68e7) C:\windows\system32\DRIVERS\usbcir.sys 21:46:46.0894 7884 usbcir - ok 21:46:46.0919 7884 usbehci (fbb21ebe49f6d560db37ac25fbc68e66) C:\windows\system32\drivers\usbehci.sys 21:46:46.0921 7884 usbehci - ok 21:46:46.0961 7884 usbhub (6b7a8a99c4a459e73c286a6763ea24cc) C:\windows\system32\DRIVERS\usbhub.sys 21:46:46.0966 7884 usbhub - ok 21:46:46.0986 7884 usbohci (8c88aa7617b4cbc2e4bed61d26b33a27) C:\windows\system32\drivers\usbohci.sys 21:46:46.0987 7884 usbohci - ok 21:46:47.0008 7884 usbprint (73188f58fb384e75c4063d29413cee3d) C:\windows\system32\DRIVERS\usbprint.sys 21:46:47.0010 7884 usbprint - ok 21:46:47.0052 7884 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\windows\system32\DRIVERS\usbscan.sys 21:46:47.0054 7884 usbscan - ok 21:46:47.0088 7884 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\windows\system32\DRIVERS\USBSTOR.SYS 21:46:47.0090 7884 USBSTOR - ok 21:46:47.0102 7884 usbuhci (0b5b3b2df3fd1709618acfa50b8392b0) C:\windows\system32\drivers\usbuhci.sys 21:46:47.0104 7884 usbuhci - ok 21:46:47.0155 7884 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\windows\System32\Drivers\usbvideo.sys 21:46:47.0158 7884 usbvideo - ok 21:46:47.0206 7884 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\windows\system32\DRIVERS\vdrvroot.sys 21:46:47.0209 7884 vdrvroot - ok 21:46:47.0231 7884 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\windows\system32\DRIVERS\vgapnp.sys 21:46:47.0233 7884 vga - ok 21:46:47.0257 7884 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\windows\System32\drivers\vga.sys 21:46:47.0259 7884 VgaSave - ok 21:46:47.0279 7884 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\windows\system32\DRIVERS\vhdmp.sys 21:46:47.0283 7884 vhdmp - ok 21:46:47.0309 7884 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\windows\system32\DRIVERS\viaide.sys 21:46:47.0311 7884 viaide - ok 21:46:47.0330 7884 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\windows\system32\DRIVERS\volmgr.sys 21:46:47.0333 7884 volmgr - ok 21:46:47.0357 7884 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\windows\system32\drivers\volmgrx.sys 21:46:47.0362 7884 volmgrx - ok 21:46:47.0386 7884 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\windows\system32\DRIVERS\volsnap.sys 21:46:47.0391 7884 volsnap - ok 21:46:47.0412 7884 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\windows\system32\DRIVERS\vsmraid.sys 21:46:47.0415 7884 vsmraid - ok 21:46:47.0438 7884 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\windows\system32\DRIVERS\vwifibus.sys 21:46:47.0439 7884 vwifibus - ok 21:46:47.0461 7884 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\windows\system32\DRIVERS\vwififlt.sys 21:46:47.0463 7884 vwififlt - ok 21:46:47.0481 7884 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\windows\system32\DRIVERS\wacompen.sys 21:46:47.0482 7884 WacomPen - ok 21:46:47.0530 7884 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\windows\system32\DRIVERS\wanarp.sys 21:46:47.0533 7884 WANARP - ok 21:46:47.0550 7884 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\windows\system32\DRIVERS\wanarp.sys 21:46:47.0550 7884 Wanarpv6 - ok 21:46:47.0596 7884 Wd (72889e16ff12ba0f235467d6091b17dc) C:\windows\system32\DRIVERS\wd.sys 21:46:47.0598 7884 Wd - ok 21:46:47.0629 7884 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\windows\system32\drivers\Wdf01000.sys 21:46:47.0646 7884 Wdf01000 - ok 21:46:47.0682 7884 wdkmd (fe31110e39a0b11abae1ba43a2dc94f9) C:\windows\system32\DRIVERS\WDKMD.sys 21:46:47.0684 7884 wdkmd - ok 21:46:47.0721 7884 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\windows\system32\DRIVERS\wfplwf.sys 21:46:47.0722 7884 WfpLwf - ok 21:46:47.0743 7884 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\windows\system32\drivers\wimmount.sys 21:46:47.0745 7884 WIMMount - ok 21:46:47.0802 7884 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\windows\system32\DRIVERS\WinUsb.sys 21:46:47.0804 7884 WinUsb - ok 21:46:47.0816 7884 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\windows\system32\DRIVERS\wmiacpi.sys 21:46:47.0818 7884 WmiAcpi - ok 21:46:47.0845 7884 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\windows\system32\drivers\ws2ifsl.sys 21:46:47.0847 7884 ws2ifsl - ok 21:46:47.0895 7884 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\windows\system32\drivers\WudfPf.sys 21:46:47.0898 7884 WudfPf - ok 21:46:47.0916 7884 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\windows\system32\DRIVERS\WUDFRd.sys 21:46:47.0919 7884 WUDFRd - ok 21:46:47.0963 7884 MBR (0x1B8) (5b5e648d12fcadc244c1ec30318e1eb9) \Device\Harddisk0\DR0 21:46:47.0977 7884 \Device\Harddisk0\DR0 - ok 21:46:47.0992 7884 Boot (0x1200) (6f3318b2a54310af2a39a44e9d52e4b2) \Device\Harddisk0\DR0\Partition0 21:46:47.0994 7884 \Device\Harddisk0\DR0\Partition0 - ok 21:46:47.0994 7884 ============================================================ 21:46:47.0994 7884 Scan finished 21:46:47.0994 7884 ============================================================ 21:46:48.0003 7876 Detected object count: 0 21:46:48.0003 7876 Actual detected object count: 0 21:47:42.0135 7984 ============================================================ 21:47:42.0136 7984 Scan started 21:47:42.0136 7984 Mode: Manual; 21:47:42.0136 7984 ============================================================ 21:47:42.0566 7984 1394ohci (969c91060cbb5d17cb8440b5f78b4c51) C:\windows\system32\DRIVERS\1394ohci.sys 21:47:42.0567 7984 1394ohci - ok 21:47:42.0590 7984 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\windows\system32\DRIVERS\ACPI.sys 21:47:42.0591 7984 ACPI - ok 21:47:42.0613 7984 acpials (12c5274cd87449a2a37a607cdb321922) C:\windows\system32\DRIVERS\acpials.sys 21:47:42.0613 7984 acpials - ok 21:47:42.0625 7984 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\windows\system32\DRIVERS\acpipmi.sys 21:47:42.0626 7984 AcpiPmi - ok 21:47:42.0658 7984 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\windows\system32\DRIVERS\adp94xx.sys 21:47:42.0660 7984 adp94xx - ok 21:47:42.0676 7984 adpahci (597f78224ee9224ea1a13d6350ced962) C:\windows\system32\DRIVERS\adpahci.sys 21:47:42.0678 7984 adpahci - ok 21:47:42.0691 7984 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\windows\system32\DRIVERS\adpu320.sys 21:47:42.0692 7984 adpu320 - ok 21:47:42.0743 7984 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\windows\system32\drivers\afd.sys 21:47:42.0746 7984 AFD - ok 21:47:42.0769 7984 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\windows\system32\DRIVERS\agp440.sys 21:47:42.0769 7984 agp440 - ok 21:47:42.0784 7984 aliide (5812713a477a3ad7363c7438ca2ee038) C:\windows\system32\DRIVERS\aliide.sys 21:47:42.0784 7984 aliide - ok 21:47:42.0795 7984 amdide (1ff8b4431c353ce385c875f194924c0c) C:\windows\system32\DRIVERS\amdide.sys 21:47:42.0796 7984 amdide - ok 21:47:42.0817 7984 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\windows\system32\DRIVERS\amdk8.sys 21:47:42.0818 7984 AmdK8 - ok 21:47:42.0830 7984 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\windows\system32\DRIVERS\amdppm.sys 21:47:42.0830 7984 AmdPPM - ok 21:47:42.0882 7984 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\windows\system32\drivers\amdsata.sys 21:47:42.0883 7984 amdsata - ok 21:47:42.0900 7984 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\windows\system32\DRIVERS\amdsbs.sys 21:47:42.0902 7984 amdsbs - ok 21:47:42.0932 7984 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\windows\system32\drivers\amdxata.sys 21:47:42.0932 7984 amdxata - ok 21:47:42.0952 7984 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\windows\system32\drivers\appid.sys 21:47:42.0953 7984 AppID - ok 21:47:42.0974 7984 arc (c484f8ceb1717c540242531db7845c4e) C:\windows\system32\DRIVERS\arc.sys 21:47:42.0975 7984 arc - ok 21:47:42.0998 7984 arcsas (019af6924aefe7839f61c830227fe79c) C:\windows\system32\DRIVERS\arcsas.sys 21:47:42.0999 7984 arcsas - ok 21:47:43.0028 7984 AsyncMac (769765ce2cc62867468cea93969b2242) C:\windows\system32\DRIVERS\asyncmac.sys 21:47:43.0028 7984 AsyncMac - ok 21:47:43.0046 7984 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\windows\system32\DRIVERS\atapi.sys 21:47:43.0046 7984 atapi - ok 21:47:43.0081 7984 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\windows\system32\DRIVERS\bxvbda.sys 21:47:43.0083 7984 b06bdrv - ok 21:47:43.0098 7984 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\windows\system32\DRIVERS\b57nd60a.sys 21:47:43.0099 7984 b57nd60a - ok 21:47:43.0123 7984 Beep (16a47ce2decc9b099349a5f840654746) C:\windows\system32\drivers\Beep.sys 21:47:43.0124 7984 Beep - ok 21:47:43.0139 7984 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\windows\system32\DRIVERS\blbdrive.sys 21:47:43.0141 7984 blbdrive - ok 21:47:43.0181 7984 bowser (19d20159708e152267e53b66677a4995) C:\windows\system32\DRIVERS\bowser.sys 21:47:43.0182 7984 bowser - ok 21:47:43.0212 7984 bpenum (f46dd257fad7d2d097ef32e72220a06c) C:\windows\system32\DRIVERS\bpenum.sys 21:47:43.0213 7984 bpenum - ok 21:47:43.0235 7984 bpmp (e82060aed0f28ed8909f2b07fa276185) C:\windows\system32\DRIVERS\bpmp.sys 21:47:43.0236 7984 bpmp - ok 21:47:43.0262 7984 bpusb (fc6313a5a45c1ae53d0491f0057d5a4d) C:\windows\system32\Drivers\bpusb.sys 21:47:43.0262 7984 bpusb - ok 21:47:43.0282 7984 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\windows\system32\DRIVERS\BrFiltLo.sys 21:47:43.0283 7984 BrFiltLo - ok 21:47:43.0304 7984 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\windows\system32\DRIVERS\BrFiltUp.sys 21:47:43.0304 7984 BrFiltUp - ok 21:47:43.0322 7984 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\windows\System32\Drivers\Brserid.sys 21:47:43.0324 7984 Brserid - ok 21:47:43.0335 7984 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\windows\System32\Drivers\BrSerWdm.sys 21:47:43.0335 7984 BrSerWdm - ok 21:47:43.0346 7984 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\windows\System32\Drivers\BrUsbMdm.sys 21:47:43.0347 7984 BrUsbMdm - ok 21:47:43.0359 7984 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\windows\System32\Drivers\BrUsbSer.sys 21:47:43.0359 7984 BrUsbSer - ok 21:47:43.0384 7984 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\windows\system32\DRIVERS\bthmodem.sys 21:47:43.0384 7984 BTHMODEM - ok 21:47:43.0392 7984 catchme - ok 21:47:43.0416 7984 cdfs (b8bd2bb284668c84865658c77574381a) C:\windows\system32\DRIVERS\cdfs.sys 21:47:43.0417 7984 cdfs - ok 21:47:43.0440 7984 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\windows\system32\DRIVERS\cdrom.sys 21:47:43.0441 7984 cdrom - ok 21:47:43.0465 7984 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\windows\system32\DRIVERS\circlass.sys 21:47:43.0466 7984 circlass - ok 21:47:43.0496 7984 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\windows\system32\CLFS.sys 21:47:43.0498 7984 CLFS - ok 21:47:43.0526 7984 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\windows\system32\DRIVERS\CmBatt.sys 21:47:43.0527 7984 CmBatt - ok 21:47:43.0538 7984 cmdide (e19d3f095812725d88f9001985b94edd) C:\windows\system32\DRIVERS\cmdide.sys 21:47:43.0538 7984 cmdide - ok 21:47:43.0564 7984 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\windows\system32\Drivers\cng.sys 21:47:43.0567 7984 CNG - ok 21:47:43.0585 7984 Compbatt (102de219c3f61415f964c88e9085ad14) C:\windows\system32\DRIVERS\compbatt.sys 21:47:43.0586 7984 Compbatt - ok 21:47:43.0604 7984 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\windows\system32\DRIVERS\CompositeBus.sys 21:47:43.0604 7984 CompositeBus - ok 21:47:43.0626 7984 crcdisk (1c827878a998c18847245fe1f34ee597) C:\windows\system32\DRIVERS\crcdisk.sys 21:47:43.0627 7984 crcdisk - ok 21:47:43.0670 7984 DfsC (9c253ce7311ca60fc11c774692a13208) C:\windows\system32\Drivers\dfsc.sys 21:47:43.0671 7984 DfsC - ok 21:47:43.0703 7984 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\windows\system32\drivers\discache.sys 21:47:43.0704 7984 discache - ok 21:47:43.0725 7984 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\windows\system32\DRIVERS\disk.sys 21:47:43.0726 7984 Disk - ok 21:47:43.0766 7984 Dot4 (b42ed0320c6e41102fde0005154849bb) C:\windows\system32\DRIVERS\Dot4.sys 21:47:43.0767 7984 Dot4 - ok 21:47:43.0802 7984 Dot4Print (85135ad27e79b689335c08167d917cde) C:\windows\system32\DRIVERS\Dot4Prt.sys 21:47:43.0802 7984 Dot4Print - ok 21:47:43.0824 7984 dot4usb (fd05a02b0370bc3000f402e543ca5814) C:\windows\system32\DRIVERS\dot4usb.sys 21:47:43.0824 7984 dot4usb - ok 21:47:43.0846 7984 drmkaud (9b19f34400d24df84c858a421c205754) C:\windows\system32\drivers\drmkaud.sys 21:47:43.0846 7984 drmkaud - ok 21:47:43.0888 7984 DXGKrnl (372117d46a16add8ca6e3ee3b3bdd57c) C:\windows\System32\drivers\dxgkrnl.sys 21:47:43.0893 7984 DXGKrnl - ok 21:47:43.0978 7984 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\windows\system32\DRIVERS\evbda.sys 21:47:43.0994 7984 ebdrv - ok 21:47:44.0030 7984 elxstor (0e5da5369a0fcaea12456dd852545184) C:\windows\system32\DRIVERS\elxstor.sys 21:47:44.0033 7984 elxstor - ok 21:47:44.0055 7984 ErrDev (34a3c54752046e79a126e15c51db409b) C:\windows\system32\DRIVERS\errdev.sys 21:47:44.0055 7984 ErrDev - ok 21:47:44.0074 7984 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\windows\system32\drivers\exfat.sys 21:47:44.0075 7984 exfat - ok 21:47:44.0099 7984 fastfat (0adc83218b66a6db380c330836f3e36d) C:\windows\system32\drivers\fastfat.sys 21:47:44.0100 7984 fastfat - ok 21:47:44.0113 7984 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\windows\system32\DRIVERS\fdc.sys 21:47:44.0113 7984 fdc - ok 21:47:44.0138 7984 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\windows\system32\drivers\fileinfo.sys 21:47:44.0139 7984 FileInfo - ok 21:47:44.0156 7984 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\windows\system32\drivers\filetrace.sys 21:47:44.0156 7984 Filetrace - ok 21:47:44.0167 7984 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\windows\system32\DRIVERS\flpydisk.sys 21:47:44.0167 7984 flpydisk - ok 21:47:44.0193 7984 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\windows\system32\drivers\fltmgr.sys 21:47:44.0195 7984 FltMgr - ok 21:47:44.0213 7984 FsDepends (d43703496149971890703b4b1b723eac) C:\windows\system32\drivers\FsDepends.sys 21:47:44.0214 7984 FsDepends - ok 21:47:44.0234 7984 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\windows\system32\drivers\Fs_Rec.sys 21:47:44.0234 7984 Fs_Rec - ok 21:47:44.0265 7984 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\windows\system32\DRIVERS\fvevol.sys 21:47:44.0266 7984 fvevol - ok 21:47:44.0290 7984 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\windows\system32\DRIVERS\gagp30kx.sys 21:47:44.0291 7984 gagp30kx - ok 21:47:44.0326 7984 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\windows\system32\DRIVERS\GEARAspiWDM.sys 21:47:44.0326 7984 GEARAspiWDM - ok 21:47:44.0353 7984 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\windows\system32\drivers\hcw85cir.sys 21:47:44.0354 7984 hcw85cir - ok 21:47:44.0369 7984 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\windows\system32\drivers\HdAudio.sys 21:47:44.0371 7984 HdAudAddService - ok 21:47:44.0390 7984 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\windows\system32\DRIVERS\HDAudBus.sys 21:47:44.0392 7984 HDAudBus - ok 21:47:44.0421 7984 HECIx64 (b6ac71aaa2b10848f57fc49d55a651af) C:\windows\system32\DRIVERS\HECIx64.sys 21:47:44.0422 7984 HECIx64 - ok 21:47:44.0434 7984 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\windows\system32\DRIVERS\HidBatt.sys 21:47:44.0434 7984 HidBatt - ok 21:47:44.0447 7984 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\windows\system32\DRIVERS\hidbth.sys 21:47:44.0448 7984 HidBth - ok 21:47:44.0465 7984 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\windows\system32\DRIVERS\hidir.sys 21:47:44.0466 7984 HidIr - ok 21:47:44.0487 7984 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\windows\system32\DRIVERS\hidusb.sys 21:47:44.0487 7984 HidUsb - ok 21:47:44.0509 7984 HpSAMD (0886d440058f203eba0e1825e4355914) C:\windows\system32\DRIVERS\HpSAMD.sys 21:47:44.0510 7984 HpSAMD - ok 21:47:44.0539 7984 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\windows\system32\drivers\HTTP.sys 21:47:44.0543 7984 HTTP - ok 21:47:44.0559 7984 hwpolicy (f17766a19145f111856378df337a5d79) C:\windows\system32\drivers\hwpolicy.sys 21:47:44.0559 7984 hwpolicy - ok 21:47:44.0580 7984 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\windows\system32\DRIVERS\i8042prt.sys 21:47:44.0581 7984 i8042prt - ok 21:47:44.0626 7984 iaStor (85977cd13fc16069ce0af7943a811775) C:\windows\system32\DRIVERS\iaStor.sys 21:47:44.0629 7984 iaStor - ok 21:47:44.0662 7984 iaStorV (b75e45c564e944a2657167d197ab29da) C:\windows\system32\drivers\iaStorV.sys 21:47:44.0664 7984 iaStorV - ok 21:47:44.0850 7984 igfx (2a22ab054f4630d2ef4bab2853f6d5f6) C:\windows\system32\DRIVERS\igdkmd64.sys 21:47:44.0901 7984 igfx - ok 21:47:44.0924 7984 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\windows\system32\DRIVERS\iirsp.sys 21:47:44.0925 7984 iirsp - ok 21:47:44.0954 7984 Impcd (dd587a55390ed2295bce6d36ad567da9) C:\windows\system32\DRIVERS\Impcd.sys 21:47:44.0955 7984 Impcd - ok 21:47:45.0016 7984 IntcAzAudAddService (490947a9aff7ca31ef2e08f5776105eb) C:\windows\system32\drivers\RTKVHD64.sys 21:47:45.0028 7984 IntcAzAudAddService - ok 21:47:45.0062 7984 IntcDAud (58cf58dee26c909bd6f977b61d246295) C:\windows\system32\DRIVERS\IntcDAud.sys 21:47:45.0063 7984 IntcDAud - ok 21:47:45.0075 7984 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\windows\system32\DRIVERS\intelide.sys 21:47:45.0075 7984 intelide - ok 21:47:45.0092 7984 intelppm (ada036632c664caa754079041cf1f8c1) C:\windows\system32\DRIVERS\intelppm.sys 21:47:45.0092 7984 intelppm - ok 21:47:45.0108 7984 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\windows\system32\DRIVERS\ipfltdrv.sys 21:47:45.0109 7984 IpFilterDriver - ok 21:47:45.0120 7984 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\windows\system32\DRIVERS\IPMIDrv.sys 21:47:45.0121 7984 IPMIDRV - ok 21:47:45.0133 7984 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\windows\system32\drivers\ipnat.sys 21:47:45.0134 7984 IPNAT - ok 21:47:45.0159 7984 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\windows\system32\drivers\irenum.sys 21:47:45.0159 7984 IRENUM - ok 21:47:45.0171 7984 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\windows\system32\DRIVERS\isapnp.sys 21:47:45.0172 7984 isapnp - ok 21:47:45.0196 7984 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\windows\system32\DRIVERS\msiscsi.sys 21:47:45.0198 7984 iScsiPrt - ok 21:47:45.0230 7984 JMCR (19496fe93696c929392f1595ed1f8bb3) C:\windows\system32\DRIVERS\jmcr.sys 21:47:45.0231 7984 JMCR - ok 21:47:45.0248 7984 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\windows\system32\DRIVERS\kbdclass.sys 21:47:45.0249 7984 kbdclass - ok 21:47:45.0262 7984 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\windows\system32\DRIVERS\kbdhid.sys 21:47:45.0263 7984 kbdhid - ok 21:47:45.0294 7984 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\windows\system32\Drivers\ksecdd.sys 21:47:45.0295 7984 KSecDD - ok 21:47:45.0315 7984 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\windows\system32\Drivers\ksecpkg.sys 21:47:45.0316 7984 KSecPkg - ok 21:47:45.0329 7984 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\windows\system32\drivers\ksthunk.sys 21:47:45.0330 7984 ksthunk - ok 21:47:45.0353 7984 lltdio (1538831cf8ad2979a04c423779465827) C:\windows\system32\DRIVERS\lltdio.sys 21:47:45.0354 7984 lltdio - ok 21:47:45.0392 7984 LPCFilter (41e122f6d1448c94cc05196bc41d6bfb) C:\windows\system32\DRIVERS\LPCFilter.sys 21:47:45.0392 7984 LPCFilter - ok 21:47:45.0416 7984 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\windows\system32\DRIVERS\lsi_fc.sys 21:47:45.0417 7984 LSI_FC - ok 21:47:45.0430 7984 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\windows\system32\DRIVERS\lsi_sas.sys 21:47:45.0431 7984 LSI_SAS - ok 21:47:45.0444 7984 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\windows\system32\DRIVERS\lsi_sas2.sys 21:47:45.0444 7984 LSI_SAS2 - ok 21:47:45.0455 7984 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\windows\system32\DRIVERS\lsi_scsi.sys 21:47:45.0456 7984 LSI_SCSI - ok 21:47:45.0479 7984 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\windows\system32\drivers\luafv.sys 21:47:45.0480 7984 luafv - ok 21:47:45.0519 7984 MarvinBus (024da28053d57e9e32bee52600576bbb) C:\windows\system32\DRIVERS\MarvinBus64.sys 21:47:45.0521 7984 MarvinBus - ok 21:47:45.0559 7984 MBAMProtector (23a854450dab5c9b7a42ab9be6f2e4bd) C:\windows\system32\drivers\mbam.sys 21:47:45.0560 7984 MBAMProtector - ok 21:47:45.0574 7984 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\windows\system32\DRIVERS\megasas.sys 21:47:45.0575 7984 megasas - ok 21:47:45.0592 7984 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\windows\system32\DRIVERS\MegaSR.sys 21:47:45.0594 7984 MegaSR - ok 21:47:45.0606 7984 Modem (800ba92f7010378b09f9ed9270f07137) C:\windows\system32\drivers\modem.sys 21:47:45.0606 7984 Modem - ok 21:47:45.0619 7984 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\windows\system32\DRIVERS\monitor.sys 21:47:45.0620 7984 monitor - ok 21:47:45.0642 7984 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\windows\system32\DRIVERS\mouclass.sys 21:47:45.0643 7984 mouclass - ok 21:47:45.0667 7984 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\windows\system32\DRIVERS\mouhid.sys 21:47:45.0667 7984 mouhid - ok 21:47:45.0694 7984 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\windows\system32\drivers\mountmgr.sys 21:47:45.0694 7984 mountmgr - ok 21:47:45.0721 7984 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\windows\system32\DRIVERS\mpio.sys 21:47:45.0722 7984 mpio - ok 21:47:45.0744 7984 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\windows\system32\drivers\mpsdrv.sys 21:47:45.0745 7984 mpsdrv - ok 21:47:45.0758 7984 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\windows\system32\drivers\mrxdav.sys 21:47:45.0759 7984 MRxDAV - ok 21:47:45.0800 7984 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\windows\system32\DRIVERS\mrxsmb.sys 21:47:45.0801 7984 mrxsmb - ok 21:47:45.0845 7984 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\windows\system32\DRIVERS\mrxsmb10.sys 21:47:45.0846 7984 mrxsmb10 - ok 21:47:45.0868 7984 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\windows\system32\DRIVERS\mrxsmb20.sys 21:47:45.0869 7984 mrxsmb20 - ok 21:47:45.0890 7984 msahci (5c37497276e3b3a5488b23a326a754b7) C:\windows\system32\DRIVERS\msahci.sys 21:47:45.0890 7984 msahci - ok 21:47:45.0920 7984 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\windows\system32\DRIVERS\msdsm.sys 21:47:45.0922 7984 msdsm - ok 21:47:45.0949 7984 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\windows\system32\drivers\Msfs.sys 21:47:45.0949 7984 Msfs - ok 21:47:45.0966 7984 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\windows\System32\drivers\mshidkmdf.sys 21:47:45.0967 7984 mshidkmdf - ok 21:47:45.0996 7984 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\windows\system32\DRIVERS\msisadrv.sys 21:47:45.0996 7984 msisadrv - ok 21:47:46.0022 7984 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\windows\system32\drivers\MSKSSRV.sys 21:47:46.0023 7984 MSKSSRV - ok 21:47:46.0042 7984 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\windows\system32\drivers\MSPCLOCK.sys 21:47:46.0043 7984 MSPCLOCK - ok 21:47:46.0064 7984 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\windows\system32\drivers\MSPQM.sys 21:47:46.0064 7984 MSPQM - ok 21:47:46.0093 7984 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\windows\system32\drivers\MsRPC.sys 21:47:46.0095 7984 MsRPC - ok 21:47:46.0116 7984 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\windows\system32\DRIVERS\mssmbios.sys 21:47:46.0116 7984 mssmbios - ok 21:47:46.0134 7984 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\windows\system32\drivers\MSTEE.sys 21:47:46.0135 7984 MSTEE - ok 21:47:46.0152 7984 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\windows\system32\DRIVERS\MTConfig.sys 21:47:46.0153 7984 MTConfig - ok 21:47:46.0177 7984 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\windows\system32\Drivers\mup.sys 21:47:46.0178 7984 Mup - ok 21:47:46.0212 7984 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\windows\system32\DRIVERS\nwifi.sys 21:47:46.0214 7984 NativeWifiP - ok 21:47:46.0247 7984 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\windows\system32\drivers\ndis.sys 21:47:46.0252 7984 NDIS - ok 21:47:46.0279 7984 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\windows\system32\DRIVERS\ndiscap.sys 21:47:46.0279 7984 NdisCap - ok 21:47:46.0299 7984 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\windows\system32\DRIVERS\ndistapi.sys 21:47:46.0300 7984 NdisTapi - ok 21:47:46.0323 7984 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\windows\system32\DRIVERS\ndisuio.sys 21:47:46.0324 7984 Ndisuio - ok 21:47:46.0344 7984 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\windows\system32\DRIVERS\ndiswan.sys 21:47:46.0345 7984 NdisWan - ok 21:47:46.0363 7984 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\windows\system32\drivers\NDProxy.sys 21:47:46.0363 7984 NDProxy - ok 21:47:46.0380 7984 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\windows\system32\DRIVERS\netbios.sys 21:47:46.0380 7984 NetBIOS - ok 21:47:46.0404 7984 NetBT (9162b273a44ab9dce5b44362731d062a) C:\windows\system32\DRIVERS\netbt.sys 21:47:46.0406 7984 NetBT - ok 21:47:46.0555 7984 NETwNs64 (eb43840babf5589e33186d094de7381d) C:\windows\system32\DRIVERS\NETwNs64.sys 21:47:46.0594 7984 NETwNs64 - ok 21:47:46.0618 7984 nfrd960 (77889813be4d166cdab78ddba990da92) C:\windows\system32\DRIVERS\nfrd960.sys 21:47:46.0618 7984 nfrd960 - ok 21:47:46.0632 7984 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\windows\system32\drivers\Npfs.sys 21:47:46.0632 7984 Npfs - ok 21:47:46.0653 7984 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\windows\system32\drivers\nsiproxy.sys 21:47:46.0653 7984 nsiproxy - ok 21:47:46.0711 7984 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\windows\system32\drivers\Ntfs.sys 21:47:46.0719 7984 Ntfs - ok 21:47:46.0740 7984 Null (9899284589f75fa8724ff3d16aed75c1) C:\windows\system32\drivers\Null.sys 21:47:46.0741 7984 Null - ok 21:47:46.0780 7984 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\windows\system32\drivers\nvraid.sys 21:47:46.0781 7984 nvraid - ok 21:47:46.0808 7984 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\windows\system32\drivers\nvstor.sys 21:47:46.0809 7984 nvstor - ok 21:47:46.0832 7984 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\windows\system32\DRIVERS\nv_agp.sys 21:47:46.0833 7984 nv_agp - ok 21:47:46.0857 7984 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\windows\system32\DRIVERS\ohci1394.sys 21:47:46.0858 7984 ohci1394 - ok 21:47:46.0877 7984 Parport (0086431c29c35be1dbc43f52cc273887) C:\windows\system32\DRIVERS\parport.sys 21:47:46.0878 7984 Parport - ok 21:47:46.0900 7984 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\windows\system32\drivers\partmgr.sys 21:47:46.0901 7984 partmgr - ok 21:47:46.0924 7984 pci (5aab2b170536885de70a6cba8d7ce52b) C:\windows\system32\DRIVERS\pci.sys 21:47:46.0926 7984 pci - ok 21:47:46.0943 7984 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\windows\system32\DRIVERS\pciide.sys 21:47:46.0943 7984 pciide - ok 21:47:46.0966 7984 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\windows\system32\DRIVERS\pcmcia.sys 21:47:46.0968 7984 pcmcia - ok 21:47:46.0994 7984 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\windows\system32\drivers\pcw.sys 21:47:46.0995 7984 pcw - ok 21:47:47.0023 7984 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\windows\system32\drivers\peauth.sys 21:47:47.0027 7984 PEAUTH - ok 21:47:47.0066 7984 PGEffect (663962900e7fea522126ba287715bb4a) C:\windows\system32\DRIVERS\pgeffect.sys 21:47:47.0066 7984 PGEffect - ok 21:47:47.0114 7984 PinnacleMarvinAVS (0050e6bec926c98ac6c16714ff1ad450) C:\windows\system32\DRIVERS\MarvinAVS64.sys 21:47:47.0117 7984 PinnacleMarvinAVS - ok 21:47:47.0156 7984 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\windows\system32\DRIVERS\raspptp.sys 21:47:47.0157 7984 PptpMiniport - ok 21:47:47.0176 7984 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\windows\system32\DRIVERS\processr.sys 21:47:47.0177 7984 Processor - ok 21:47:47.0203 7984 Psched (ee992183bd8eaefd9973f352e587a299) C:\windows\system32\DRIVERS\pacer.sys 21:47:47.0204 7984 Psched - ok 21:47:47.0251 7984 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\windows\system32\DRIVERS\ql2300.sys 21:47:47.0259 7984 ql2300 - ok 21:47:47.0274 7984 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\windows\system32\DRIVERS\ql40xx.sys 21:47:47.0275 7984 ql40xx - ok 21:47:47.0296 7984 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\windows\system32\drivers\qwavedrv.sys 21:47:47.0297 7984 QWAVEdrv - ok 21:47:47.0308 7984 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\windows\system32\DRIVERS\rasacd.sys 21:47:47.0309 7984 RasAcd - ok 21:47:47.0328 7984 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\windows\system32\DRIVERS\AgileVpn.sys 21:47:47.0329 7984 RasAgileVpn - ok 21:47:47.0353 7984 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\windows\system32\DRIVERS\rasl2tp.sys 21:47:47.0354 7984 Rasl2tp - ok 21:47:47.0372 7984 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\windows\system32\DRIVERS\raspppoe.sys 21:47:47.0372 7984 RasPppoe - ok 21:47:47.0389 7984 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\windows\system32\DRIVERS\rassstp.sys 21:47:47.0389 7984 RasSstp - ok 21:47:47.0413 7984 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\windows\system32\DRIVERS\rdbss.sys 21:47:47.0415 7984 rdbss - ok 21:47:47.0433 7984 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\windows\system32\DRIVERS\rdpbus.sys 21:47:47.0434 7984 rdpbus - ok 21:47:47.0453 7984 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\windows\system32\DRIVERS\RDPCDD.sys 21:47:47.0453 7984 RDPCDD - ok 21:47:47.0469 7984 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\windows\system32\drivers\rdpencdd.sys 21:47:47.0470 7984 RDPENCDD - ok 21:47:47.0505 7984 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\windows\system32\drivers\rdprefmp.sys 21:47:47.0505 7984 RDPREFMP - ok 21:47:47.0518 7984 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\windows\system32\drivers\RDPWD.sys 21:47:47.0520 7984 RDPWD - ok 21:47:47.0555 7984 rdyboost (e5dc9ba9e439d6dbdd79f8caacb5bf01) C:\windows\system32\drivers\rdyboost.sys 21:47:47.0556 7984 rdyboost - ok 21:47:47.0582 7984 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\windows\system32\DRIVERS\rspndr.sys 21:47:47.0582 7984 rspndr - ok 21:47:47.0622 7984 RTL8167 (ba3e57c89e6f63808d3f2b11e1a2ad3c) C:\windows\system32\DRIVERS\Rt64win7.sys 21:47:47.0624 7984 RTL8167 - ok 21:47:47.0689 7984 SASDIFSV (3289766038db2cb14d07dc84392138d5) C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS 21:47:47.0689 7984 SASDIFSV - ok 21:47:47.0722 7984 SASKUTIL (58a38e75f3316a83c23df6173d41f2b5) C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS 21:47:47.0723 7984 SASKUTIL - ok 21:47:47.0749 7984 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\windows\system32\DRIVERS\sbp2port.sys 21:47:47.0750 7984 sbp2port - ok 21:47:47.0771 7984 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\windows\system32\DRIVERS\scfilter.sys 21:47:47.0771 7984 scfilter - ok 21:47:47.0788 7984 sdbus (2c8d162efaf73abd36d8bcbb6340cae7) C:\windows\system32\DRIVERS\sdbus.sys 21:47:47.0789 7984 sdbus - ok 21:47:47.0812 7984 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\windows\system32\drivers\secdrv.sys 21:47:47.0813 7984 secdrv - ok 21:47:47.0833 7984 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\windows\system32\DRIVERS\serenum.sys 21:47:47.0834 7984 Serenum - ok 21:47:47.0845 7984 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\windows\system32\DRIVERS\serial.sys 21:47:47.0847 7984 Serial - ok 21:47:47.0860 7984 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\windows\system32\DRIVERS\sermouse.sys 21:47:47.0861 7984 sermouse - ok 21:47:47.0882 7984 sffdisk (a554811bcd09279536440c964ae35bbf) C:\windows\system32\DRIVERS\sffdisk.sys 21:47:47.0882 7984 sffdisk - ok 21:47:47.0895 7984 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\windows\system32\DRIVERS\sffp_mmc.sys 21:47:47.0895 7984 sffp_mmc - ok 21:47:47.0915 7984 sffp_sd (178298f767fe638c9fedcbdef58bb5e4) C:\windows\system32\DRIVERS\sffp_sd.sys 21:47:47.0916 7984 sffp_sd - ok 21:47:47.0927 7984 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\windows\system32\DRIVERS\sfloppy.sys 21:47:47.0927 7984 sfloppy - ok 21:47:47.0968 7984 Sftfs (a40abfdcb75f835fdf3ce0cc64e4250d) C:\windows\system32\DRIVERS\Sftfslh.sys 21:47:47.0972 7984 Sftfs - ok 21:47:47.0997 7984 Sftplay (411769ed1cb12d2b44217734347bdb7a) C:\windows\system32\DRIVERS\Sftplaylh.sys 21:47:47.0999 7984 Sftplay - ok 21:47:48.0032 7984 Sftredir (a14d0df34bbb00ea94da16193d0c7957) C:\windows\system32\DRIVERS\Sftredirlh.sys 21:47:48.0033 7984 Sftredir - ok 21:47:48.0046 7984 Sftvol (393b22addd89979eb1c60898f51c3648) C:\windows\system32\DRIVERS\Sftvollh.sys 21:47:48.0048 7984 Sftvol - ok 21:47:48.0066 7984 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\windows\system32\DRIVERS\SiSRaid2.sys 21:47:48.0066 7984 SiSRaid2 - ok 21:47:48.0090 7984 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\windows\system32\DRIVERS\sisraid4.sys 21:47:48.0091 7984 SiSRaid4 - ok 21:47:48.0104 7984 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\windows\system32\DRIVERS\smb.sys 21:47:48.0105 7984 Smb - ok 21:47:48.0130 7984 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\windows\system32\drivers\spldr.sys 21:47:48.0130 7984 spldr - ok 21:47:48.0178 7984 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\windows\system32\DRIVERS\srv.sys 21:47:48.0181 7984 srv - ok 21:47:48.0202 7984 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\windows\system32\DRIVERS\srv2.sys 21:47:48.0205 7984 srv2 - ok 21:47:48.0228 7984 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\windows\system32\DRIVERS\srvnet.sys 21:47:48.0229 7984 srvnet - ok 21:47:48.0261 7984 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\windows\system32\DRIVERS\stexstor.sys 21:47:48.0261 7984 stexstor - ok 21:47:48.0289 7984 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\windows\system32\DRIVERS\swenum.sys 21:47:48.0290 7984 swenum - ok 21:47:48.0336 7984 SynTP (470c47daba9ca3966f0ab3f835d7d135) C:\windows\system32\DRIVERS\SynTP.sys 21:47:48.0338 7984 SynTP - ok 21:47:48.0410 7984 Tcpip (f18f56efc0bfb9c87ba01c37b27f4da5) C:\windows\system32\drivers\tcpip.sys 21:47:48.0419 7984 Tcpip - ok 21:47:48.0467 7984 TCPIP6 (f18f56efc0bfb9c87ba01c37b27f4da5) C:\windows\system32\DRIVERS\tcpip.sys 21:47:48.0476 7984 TCPIP6 - ok 21:47:48.0500 7984 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\windows\system32\drivers\tcpipreg.sys 21:47:48.0500 7984 tcpipreg - ok 21:47:48.0525 7984 tdcmdpst (fd542b661bd22fa69ca789ad0ac58c29) C:\windows\system32\DRIVERS\tdcmdpst.sys 21:47:48.0526 7984 tdcmdpst - ok 21:47:48.0547 7984 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\windows\system32\drivers\tdpipe.sys 21:47:48.0547 7984 TDPIPE - ok 21:47:48.0561 7984 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\windows\system32\drivers\tdtcp.sys 21:47:48.0562 7984 TDTCP - ok 21:47:48.0588 7984 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\windows\system32\DRIVERS\tdx.sys 21:47:48.0589 7984 tdx - ok 21:47:48.0606 7984 TermDD (c448651339196c0e869a355171875522) C:\windows\system32\DRIVERS\termdd.sys 21:47:48.0607 7984 TermDD - ok 21:47:48.0642 7984 Thpdrv (c013f6acaa9761f571bd28dada7c157d) C:\windows\system32\DRIVERS\thpdrv.sys 21:47:48.0643 7984 Thpdrv - ok 21:47:48.0661 7984 Thpevm (b4e609047434ed948af7bdef2fa66e38) C:\windows\system32\DRIVERS\Thpevm.SYS 21:47:48.0661 7984 Thpevm - ok 21:47:48.0711 7984 tos_sps64 (09ff7b0b1b5c3d225495cb6f5a9b39f8) C:\windows\system32\DRIVERS\tos_sps64.sys 21:47:48.0713 7984 tos_sps64 - ok 21:47:48.0737 7984 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\windows\system32\DRIVERS\tssecsrv.sys 21:47:48.0738 7984 tssecsrv - ok 21:47:48.0760 7984 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\windows\system32\DRIVERS\tunnel.sys 21:47:48.0761 7984 tunnel - ok 21:47:48.0787 7984 TVALZ (550b567f9364d8f7684c3fb3ea665a72) C:\windows\system32\DRIVERS\TVALZ_O.SYS 21:47:48.0788 7984 TVALZ - ok 21:47:48.0818 7984 TVALZFL (9c7191f4b2e49bff47a6c1144b5923fa) C:\windows\system32\DRIVERS\TVALZFL.sys 21:47:48.0818 7984 TVALZFL - ok 21:47:48.0842 7984 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\windows\system32\DRIVERS\uagp35.sys 21:47:48.0843 7984 uagp35 - ok 21:47:48.0880 7984 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\windows\system32\DRIVERS\udfs.sys 21:47:48.0882 7984 udfs - ok 21:47:48.0907 7984 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\windows\system32\DRIVERS\uliagpkx.sys 21:47:48.0908 7984 uliagpkx - ok 21:47:48.0938 7984 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\windows\system32\DRIVERS\umbus.sys 21:47:48.0939 7984 umbus - ok 21:47:48.0961 7984 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\windows\system32\DRIVERS\umpass.sys 21:47:48.0961 7984 UmPass - ok 21:47:48.0993 7984 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\windows\system32\Drivers\usbaapl64.sys 21:47:48.0994 7984 USBAAPL64 - ok 21:47:49.0019 7984 usbaudio (77b01bc848298223a95d4ec23e1785a1) C:\windows\system32\drivers\usbaudio.sys 21:47:49.0020 7984 usbaudio - ok 21:47:49.0067 7984 usbccgp (537a4e03d7103c12d42dfd8ffdb5bdc9) C:\windows\system32\DRIVERS\usbccgp.sys 21:47:49.0068 7984 usbccgp - ok 21:47:49.0082 7984 usbcir (af0892a803fdda7492f595368e3b68e7) C:\windows\system32\DRIVERS\usbcir.sys 21:47:49.0083 7984 usbcir - ok 21:47:49.0106 7984 usbehci (fbb21ebe49f6d560db37ac25fbc68e66) C:\windows\system32\drivers\usbehci.sys 21:47:49.0106 7984 usbehci - ok 21:47:49.0148 7984 usbhub (6b7a8a99c4a459e73c286a6763ea24cc) C:\windows\system32\DRIVERS\usbhub.sys 21:47:49.0150 7984 usbhub - ok 21:47:49.0172 7984 usbohci (8c88aa7617b4cbc2e4bed61d26b33a27) C:\windows\system32\drivers\usbohci.sys 21:47:49.0173 7984 usbohci - ok 21:47:49.0194 7984 usbprint (73188f58fb384e75c4063d29413cee3d) C:\windows\system32\DRIVERS\usbprint.sys 21:47:49.0195 7984 usbprint - ok 21:47:49.0222 7984 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\windows\system32\DRIVERS\usbscan.sys 21:47:49.0223 7984 usbscan - ok 21:47:49.0258 7984 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\windows\system32\DRIVERS\USBSTOR.SYS 21:47:49.0259 7984 USBSTOR - ok 21:47:49.0272 7984 usbuhci (0b5b3b2df3fd1709618acfa50b8392b0) C:\windows\system32\drivers\usbuhci.sys 21:47:49.0273 7984 usbuhci - ok 21:47:49.0308 7984 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\windows\System32\Drivers\usbvideo.sys 21:47:49.0309 7984 usbvideo - ok 21:47:49.0335 7984 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\windows\system32\DRIVERS\vdrvroot.sys 21:47:49.0336 7984 vdrvroot - ok 21:47:49.0360 7984 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\windows\system32\DRIVERS\vgapnp.sys 21:47:49.0360 7984 vga - ok 21:47:49.0386 7984 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\windows\System32\drivers\vga.sys 21:47:49.0386 7984 VgaSave - ok 21:47:49.0408 7984 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\windows\system32\DRIVERS\vhdmp.sys 21:47:49.0409 7984 vhdmp - ok 21:47:49.0423 7984 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\windows\system32\DRIVERS\viaide.sys 21:47:49.0424 7984 viaide - ok 21:47:49.0459 7984 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\windows\system32\DRIVERS\volmgr.sys 21:47:49.0460 7984 volmgr - ok 21:47:49.0486 7984 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\windows\system32\drivers\volmgrx.sys 21:47:49.0488 7984 volmgrx - ok 21:47:49.0514 7984 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\windows\system32\DRIVERS\volsnap.sys 21:47:49.0516 7984 volsnap - ok 21:47:49.0540 7984 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\windows\system32\DRIVERS\vsmraid.sys 21:47:49.0541 7984 vsmraid - ok 21:47:49.0566 7984 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\windows\system32\DRIVERS\vwifibus.sys 21:47:49.0567 7984 vwifibus - ok 21:47:49.0590 7984 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\windows\system32\DRIVERS\vwififlt.sys 21:47:49.0590 7984 vwififlt - ok 21:47:49.0606 7984 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\windows\system32\DRIVERS\wacompen.sys 21:47:49.0607 7984 WacomPen - ok 21:47:49.0626 7984 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\windows\system32\DRIVERS\wanarp.sys 21:47:49.0626 7984 WANARP - ok 21:47:49.0631 7984 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\windows\system32\DRIVERS\wanarp.sys 21:47:49.0632 7984 Wanarpv6 - ok 21:47:49.0654 7984 Wd (72889e16ff12ba0f235467d6091b17dc) C:\windows\system32\DRIVERS\wd.sys 21:47:49.0654 7984 Wd - ok 21:47:49.0692 7984 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\windows\system32\drivers\Wdf01000.sys 21:47:49.0696 7984 Wdf01000 - ok 21:47:49.0728 7984 wdkmd (fe31110e39a0b11abae1ba43a2dc94f9) C:\windows\system32\DRIVERS\WDKMD.sys 21:47:49.0729 7984 wdkmd - ok 21:47:49.0759 7984 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\windows\system32\DRIVERS\wfplwf.sys 21:47:49.0759 7984 WfpLwf - ok 21:47:49.0781 7984 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\windows\system32\drivers\wimmount.sys 21:47:49.0782 7984 WIMMount - ok 21:47:49.0815 7984 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\windows\system32\DRIVERS\WinUsb.sys 21:47:49.0815 7984 WinUsb - ok 21:47:49.0828 7984 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\windows\system32\DRIVERS\wmiacpi.sys 21:47:49.0829 7984 WmiAcpi - ok 21:47:49.0858 7984 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\windows\system32\drivers\ws2ifsl.sys 21:47:49.0859 7984 ws2ifsl - ok 21:47:49.0884 7984 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\windows\system32\drivers\WudfPf.sys 21:47:49.0885 7984 WudfPf - ok 21:47:49.0905 7984 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\windows\system32\DRIVERS\WUDFRd.sys 21:47:49.0906 7984 WUDFRd - ok 21:47:49.0927 7984 MBR (0x1B8) (5b5e648d12fcadc244c1ec30318e1eb9) \Device\Harddisk0\DR0 21:47:49.0941 7984 \Device\Harddisk0\DR0 - ok 21:47:49.0956 7984 Boot (0x1200) (6f3318b2a54310af2a39a44e9d52e4b2) \Device\Harddisk0\DR0\Partition0 21:47:49.0957 7984 \Device\Harddisk0\DR0\Partition0 - ok 21:47:49.0958 7984 ============================================================ 21:47:49.0958 7984 Scan finished 21:47:49.0958 7984 ============================================================ 21:47:49.0965 7976 Detected object count: 0 21:47:49.0965 7976 Actual detected object count: 0 21:49:08.0452 7688 Deinitialize success
system look SystemLook 30.07.11 by jpshortstuff Log created at 21:51 on 16/12/2011 by EvolutionMR Administrator - Elevation successful WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results. ========== filefind ========== Searching for "consrv.dll" No files found. -= EOF =-
Hello LexusISF,


Looks like you were infected with Zero Access Rootkit, but Combofix removed it. :thumbup: We still have alittle more to do.

Please go to one of the below sites to scan the following files:

Virus Total
jotti.org
Kaspersky Virus File Scanner


click on Browse, and upload the following file for analysis:
c:\windows\System32\config\systemprofile\AppData\Local\hretywa.dll

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.


Summary of the logs I need from you in your next post:

virustotal scan results
How is computer running now?
The laptop is running MUCH better. Imo, there is still a decent amount of CPU and memory usage over, but it's definitely better than it was. Thank you so much again =) File name: hretywa.dll Submission date: 2011-12-17 19:31:38 (UTC) Current status: finished Result: 8/ 43 (18.6%) VT Community not reviewed Safety score: - Compact Print results Antivirus Version Last Update Result AhnLab-V3 2011.12.17.00 2011.12.17 Trojan/Win32.Agent AntiVir 7.11.19.153 2011.12.16 TR/Spy.Gen Antiy-AVL 2.0.3.7 2011.12.17 - Avast 6.0.1289.0 2011.12.17 - AVG 10.0.0.1190 2011.12.17 - BitDefender 7.2 2011.12.17 Trojan.Spy.YGR ByteHero 1.0.0.1 2011.12.07 - CAT-QuickHeal 12.00 2011.12.17 - ClamAV 0.97.3.0 2011.12.17 - Commtouch 5.3.2.6 2011.12.17 - Comodo 10992 2011.12.17 - DrWeb 5.0.2.03300 2011.12.17 - Emsisoft 5.1.0.11 2011.12.17 Trojan-Spy!IK eSafe 7.0.17.0 2011.12.15 - eTrust-Vet 37.0.9628 2011.12.16 - F-Prot 4.6.5.141 2011.12.17 - F-Secure 9.0.16440.0 2011.12.17 Trojan.Spy.YGR Fortinet 4.3.388.0 2011.12.17 - GData 22 2011.12.17 Trojan.Spy.YGR Ikarus T3.1.1.109.0 2011.12.17 Trojan-Spy Jiangmin 13.0.900 2011.12.17 - K7AntiVirus 9.119.5696 2011.12.15 - Kaspersky 9.0.0.837 2011.12.17 - McAfee 5.400.0.1158 2011.12.17 - McAfee-GW-Edition 2010.1E 2011.12.17 Heuristic.BehavesLike.Win32.Spyware.J Microsoft 1.7903 2011.12.17 - NOD32 6720 2011.12.17 - Norman 6.07.13 2011.12.17 - nProtect 2011-12-17.01 2011.12.17 - Panda 10.0.3.5 2011.12.17 - PCTools 8.0.0.5 2011.12.17 - Prevx 3.0 2011.12.17 - Rising 23.88.03.02 2011.12.16 - Sophos 4.72.0 2011.12.17 - SUPERAntiSpyware 4.40.0.1006 2011.12.17 - Symantec 20111.2.0.82 2011.12.17 - TheHacker 6.7.0.1.360 2011.12.16 - TrendMicro 9.500.0.1008 2011.12.17 - TrendMicro-HouseCall 9.500.0.1008 2011.12.17 - VBA32 3.12.16.4 2011.12.14 - VIPRE 11267 2011.12.17 - ViRobot 2011.12.17.4831 2011.12.17 - VirusBuster 14.1.121.0 2011.12.17 - Additional information MD5 : 35b12f2ae9857ce6b6627aa0076a57d3 SHA1 : 19180d3f69dcf296d41dc2b1122b758b82563601 SHA256: de9f94c6cd3a44a78b1f28b5e2773febd625942b4cbc969d4a158f633926bb5c
Hello LexusISF,

One or more of the identified infections is a Backdoor Trojan.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files. I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall

However, if you do not have the resources to reinstall your computer and would like me to attempt to clean it, I will be happy to do so.
Should you decide to go ahead and clean the computer follow the instructions below.

Please let us know what you have decided to do in your next post.
=====================
Back Up registry with ERUNT

  • Please use the following link and download ERUNT to your desktop. HERE
  • Click on the erunt-setup.exe
  • Follow the prompts to install ERUNT
  • Choose language
  • A set up window will pop up. It will ask: Create ERUNT entry in to the Start up folder, answer NO

    [external image: Posted Image]
  • Backup your registry to the default location

Note: To restore your registry (if needed), go to the folder and start ERDNT.exe
=====================
NEXT

ComboFix - CFScript

This script is for this user and computer ONLY! Using this tool incorrectly could cause problems with your operating system… preventing it from ever starting again!
You will not have Internet access when you execute ComboFix. All open windows will need to be closed!

Open notepad and copy/paste the text in the quotebox below into it:

File::
c:\windows\System32\config\systemprofile\AppData\Local\hretywa.dll

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hretywa]


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
=====================
NEXT

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with he mbam log. Any remaining issues?
=====================
NEXT

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

Summary of the logs I need from you in your next post:

CFScript log
Malwarebytes' log
ESET log
How is the computer running?
Sorry I didn't respond earlier, had a busy weekend. I would like to try and fix my laptop, I'm crossing my fingers that it will actually be fine even though this trojan is a high risk. And to answer your question it is running a lot better, no more weird pop-ups or high usage. here are my logs. MBAM didn't really find anything Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8394 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 12/18/2011 8:03:39 PM mbam-log-2011-12-18 (20-03-39).txt Scan type: Quick scan Objects scanned: 179459 Time elapsed: 1 minute(s), 41 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Combo Fix================================= ComboFix 11-12-18.02 - EvolutionMR 12/18/2011 19:53:14.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3891.2777 [GMT -6:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\EvolutionMR\Desktop\CFScript.txt AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116} SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\windows\System32\config\systemprofile\AppData\Local\hretywa.dll" . . ((((((((((((((((((((((((( Files Created from 2011-11-19 to 2011-12-19 ))))))))))))))))))))))))))))))) . . 2011-12-19 01:57 . 2011-12-19 01:57 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-12-19 01:57 . 2011-12-19 01:57 ——– d—–w- c:\users\Administrator\AppData\Local\temp 2011-12-08 08:47 . 2011-12-08 08:47 ——– d—–w- c:\users\EvolutionMR\AppData\Roaming\SUPERAntiSpyware.com 2011-12-08 08:46 . 2011-12-08 08:46 ——– d—–w- c:\programdata\!SASCORE 2011-12-08 08:46 . 2011-12-08 08:59 ——– d—–w- c:\program files\SUPERAntiSpyware 2011-12-08 08:46 . 2011-12-08 08:46 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2011-12-08 08:37 . 2011-12-08 08:37 ——– d—–w- c:\windows\SysWow64\config\systemprofile\Tracing 2011-12-08 08:29 . 2011-12-08 08:29 ——– d—–w- c:\users\EvolutionMR\AppData\Roaming\Malwarebytes 2011-12-08 08:28 . 2011-12-08 08:28 ——– d—–w- c:\programdata\Malwarebytes 2011-12-08 08:28 . 2011-12-08 08:28 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2011-12-08 08:28 . 2011-08-31 23:00 25416 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-12-02 11:49 . 2011-11-21 11:40 8822856 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{26A0E8C9-2584-45FC-8BA6-91C44BC6B167}\mpengine.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-09-29 16:24 . 2011-11-09 12:56 1897328 —-a-w- c:\windows\system32\drivers\tcpip.sys . . ((((((((((((((((((((((((((((( SnapShot@2011-12-17_01.10.09 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-14 05:10 . 2011-12-17 01:11 40190 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2010-12-01 00:46 . 2011-12-19 01:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-12-01 00:46 . 2011-12-17 01:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-12-01 00:46 . 2011-12-17 01:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-12-01 00:46 . 2011-12-19 01:08 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-12-01 00:48 . 2011-12-17 01:11 8780 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3776537337-3933919168-1471804489-1000_UserData.bin + 2010-12-01 02:53 . 2011-12-18 22:33 244842 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin - 2009-07-14 02:36 . 2011-12-17 01:02 624856 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2011-12-17 01:12 624856 c:\windows\system32\perfh009.dat - 2009-07-14 02:36 . 2011-12-17 01:02 106942 c:\windows\system32\perfc009.dat + 2009-07-14 02:36 . 2011-12-17 01:12 106942 c:\windows\system32\perfc009.dat + 2011-12-19 01:49 . 2005-10-20 18:02 163328 c:\windows\ERDNT\12-18-2011\ERDNT.EXE + 2011-12-19 01:49 . 2011-12-19 01:49 1527808 c:\windows\ERDNT\12-18-2011\Users\00000002\UsrClass.dat + 2011-12-19 01:49 . 2011-12-19 01:49 1372160 c:\windows\ERDNT\12-18-2011\Users\00000001\NTUSER.DAT - 2009-07-14 02:34 . 2011-12-17 00:02 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT + 2009-07-14 02:34 . 2011-12-18 18:47 10223616 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-08-30 39408] "EA Core"="c:\program files (x86)\Electronic Arts\EADM\Core.exe" [2009-03-28 3325952] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-12-08 5495680] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2009-12-25 34160] "HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2010-03-05 423936] "SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2010-02-23 352256] "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136] "TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-05-02 2454840] "hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-10-09 421736] "Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2010-6-24 9216] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . 2;2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;c:\program files\Intel\WiMAX\Bin\DMAgent.exe [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-30 136176] R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152] R3 acpials;ALS Sensor Filter;c:\windows\system32\DRIVERS\acpials.sys [x] R3 bpmp;Intel® Centrino® WiMAX 6050 Series;c:\windows\system32\DRIVERS\bpmp.sys [x] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-30 136176] R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 PinnacleMarvinAVS;Pinnacle AVStream Service for MovieBox Deluxe, 500-USB and 700-USB;c:\windows\system32\DRIVERS\MarvinAVS64.sys [x] R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys [x] S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [x] S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-12-08 140672] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-09-14 508264] S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-07-28 267192] S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x] S2 UNS;Intel® Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-03-03 2320920] S2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;c:\program files\Intel\WiMAX\Bin\AppSrv.exe [2010-06-07 911872] S3 bpenum;bpenum;c:\windows\system32\DRIVERS\bpenum.sys [x] S3 bpusb;bpusb;c:\windows\system32\Drivers\bpusb.sys [x] S3 HECIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [x] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-09-14 219496] S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-06 137560] S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-07-23 822192] S3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - 65450454 *Deregistered* - 65450454 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2011-12-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-30 04:44] . 2011-12-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-08-30 04:44] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ThpSrv"="c:\windows\system32\thpsrv" [X] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-04-26 161304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-04-26 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-04-26 413208] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-03-22 10134560] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-03-22 896032] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "TPwrMain"="c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE" [BU] "HSON"="c:\program files (x86)\TOSHIBA\TBS\HSON.exe" [BU] "SmoothView"="c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe" [BU] "00TCrdMain"="c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe" [BU] "Teco"="c:\program files (x86)\TOSHIBA\TECO\Teco.exe" [BU] "TosWaitSrv"="c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe" [BU] "SmartFaceVWatcher"="c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [BU] "IntelWirelessWiMAX"="c:\program files\Intel\WiMAX\Bin\WiMAXCU.exe" [2010-06-08 1441792] "TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-06 709976] "TosNC"="c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe" [BU] "TosReelTimeMonitor"="c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe" [BU] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ig?brand=TSND&bmod=TSND mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSND&bmod=TSND mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = ;*.local IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html TCP: DhcpNameServer = [removed] [removed] FF - ProfilePath - c:\users\EvolutionMR\AppData\Roaming\Mozilla\Firefox\Profiles\uh5qpyvv.default\ FF - user.js: yahoo.ytff.general.dontshowhpoffer - true . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10h.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-12-18 19:58:42 ComboFix-quarantined-files.txt 2011-12-19 01:58 ComboFix2.txt 2011-12-17 01:14 . Pre-Run: 388,899,614,720 bytes free Post-Run: 388,850,696,192 bytes free . - - End Of File - - DB533897529EF1DE39CA47DB5D6D0B4C
Whoops, missed one. Here you go. ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=e123a3e0ef66c9478ad09b72857d1ffb # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-12-19 02:49:35 # local_time=2011-12-19 08:49:35 (-0600, Central Standard Time) # country="United States" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=5893 16776574 66 94 558245 75846282 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=152789 # found=4 # cleaned=0 # scan_time=3343 C:\Qoobox\Quarantine\C\Windows\System32\consrv.dll.vir Win64/Sirefef.E trojan (unable to clean) 00000000000000000000000000000000 I C:\Users\EvolutionMR\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\22d0205-7171a792 a variant of Java/TrojanDownloader.OpenConnection.AQ trojan (unable to clean) 00000000000000000000000000000000 I C:\Users\EvolutionMR\Desktop\Music To Be Organized\shocking silence benny banassi.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan (unable to clean) 00000000000000000000000000000000 I C:\Windows\assembly\temp\U\80000032.@ probably a variant of Win32/Olmarik.AVQ trojan (unable to clean) 00000000000000000000000000000000 I
Hello LexusISF,

ComboFix - CFScript

This script is for this user and computer ONLY! Using this tool incorrectly could cause problems with your operating system… preventing it from ever starting again!
You will not have Internet access when you execute ComboFix. All open windows will need to be closed!

Open notepad and copy/paste the text in the quotebox below into it:

File::
ipconfig /flushdns /c
C:\Users\EvolutionMR\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\22d0205-7171a792
C:\Users\EvolutionMR\Desktop\Music To Be Organized\shocking silence benny banassi.mp3
C:\Windows\assembly\temp\U\80000032.@


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

==================
Update Java:

Click your start button > Control Panel
  • If it isn't all ready please set the View by to small icons
  • Locate Java (it looks like a coffee cup) in the list
  • right click it and click "Run as administrator"
  • Click the Update tab
  • Click update now


Update Adobe:

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 9.3 first. Be sure to move any PDF documents to another folder first though.


Summary of the logs I need from you in your next post:
CFScript log
Do you have anymore issues with the computer?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI