This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware Problem [Solved]

43 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Daughters Computer has a malware problem, please help





OTL logfile created on: 12/15/2011 5:05:15 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\admin\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.96 Gb Total Physical Memory | 2.18 Gb Available Physical Memory | 54.93% Memory free
7.92 Gb Paging File | 6.11 Gb Available in Paging File | 77.16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 218.20 Gb Total Space | 118.43 Gb Free Space | 54.27% Space Free | Partition Type: NTFS

Computer Name: HAYLEY-PC | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========



OTL Extras logfile created on: 12/15/2011 5:05:15 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\admin\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.96 Gb Total Physical Memory | 2.18 Gb Available Physical Memory | 54.93% Memory free
7.92 Gb Paging File | 6.11 Gb Available in Paging File | 77.16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 218.20 Gb Total Space | 118.43 Gb Free Space | 54.27% Space Free | Partition Type: NTFS

Computer Name: HAYLEY-PC | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{26A24AE4-039D-4CA4-87B4-2F86416014FF}" = Java™ 6 Update 14 (64-bit)
"{3C5E60F1-0821-4B07-97EA-84EB5A927CF6}" = MobileMe Control Panel
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9C98CA38-4C1A-4AC8-B55C-169497C8826B}" = Apple Mobile Device Support
"{9CD0F7D3-B67F-4BF8-8784-D73AD229FF1E}" = iTunes
"{B4735ADA-2C32-4DB1-809C-D3D424343ED9}" = FastAccess
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{E60B7350-EA5F-41E0-9D6F-E508781E36D2}" = Dell Dock
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Dell V305" = Dell V305
"HDMI" = Intel® Graphics Media Accelerator Driver
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Dell Touchpad

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04F3038E-4120-44CC-B330-E05F737246A5}" = Roxio Update Manager
"{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}" = Microsoft Visual C++ 2005 Redistributable
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}" = Dell DataSafe Online
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 19
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}" = Banctec Service Agreement
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{67635FB6-2F63-4FFB-830B-D4C01597EBA4}" = Microsoft Office Suite Activation Assistant
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{820B6609-4C97-3A2B-B644-573B06A0F0CC}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISER_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A33E7B0C-B99C-4EC9-B702-8A328B161AF9}" = Roxio Burn
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}" = Roxio Burn
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AIM_7" = AIM 7
"AVG9Uninstall" = AVG Free 9.0
"Cool Edit Pro 2.0" = Cool Edit Pro 2.0
"Dell Webcam Central" = Dell Webcam Central
"Disney Toontown Online" = Disney Toontown Online
"ENTERPRISER" = Microsoft Office Enterprise 2007
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"LimeWire" = LimeWire 5.4.6
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.6.23)" = Mozilla Firefox (3.6.23)
"NSS" = Norton Security Scan
"RealPlayer 12.0" = RealPlayer
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"WinLiveSuite" = Windows Live Essentials
"World of Warcraft" = World of Warcraft

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/10/2011 9:54:30 AM | Computer Name = Hayley-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 17160

Error - 12/10/2011 9:54:30 AM | Computer Name = Hayley-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 17160

Error - 12/10/2011 9:54:31 AM | Computer Name = Hayley-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 12/10/2011 9:54:31 AM | Computer Name = Hayley-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 18158

Error - 12/10/2011 9:54:31 AM | Computer Name = Hayley-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 18158

Error - 12/10/2011 9:54:32 AM | Computer Name = Hayley-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 12/10/2011 9:54:32 AM | Computer Name = Hayley-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 19157

Error - 12/10/2011 9:54:32 AM | Computer Name = Hayley-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 19157

Error - 12/10/2011 9:54:33 AM | Computer Name = Hayley-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 12/10/2011 9:54:33 AM | Computer Name = Hayley-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 20155

[ System Events ]
Error - 12/14/2011 9:50:30 PM | Computer Name = Hayley-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume OS.

Error - 12/14/2011 9:53:58 PM | Computer Name = Hayley-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume C:.

Error - 12/14/2011 9:53:59 PM | Computer Name = Hayley-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume OS.

Error - 12/14/2011 9:53:59 PM | Computer Name = Hayley-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume C:.

Error - 12/14/2011 9:53:59 PM | Computer Name = Hayley-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume C:.

Error - 12/14/2011 9:53:59 PM | Computer Name = Hayley-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume C:.

Error - 12/14/2011 9:53:59 PM | Computer Name = Hayley-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume C:.

Error - 12/15/2011 5:54:04 PM | Computer Name = Hayley-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 4:41:28 PM on ?12/?15/?2011 was unexpected.

Error - 12/15/2011 5:54:18 PM | Computer Name = Hayley-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the dldtCATSCustConnectService
service to connect.

Error - 12/15/2011 5:54:18 PM | Computer Name = Hayley-PC | Source = Service Control Manager | ID = 7000
Description = The dldtCATSCustConnectService service failed to start due to the
following error: %%1053


< End of report >


PRC - C:\Users\admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks)
PRC - C:\Program Files (x86)\Dell V305\dldtmon.exe ()
PRC - C:\Program Files (x86)\Dell V305\dldtmsdmon.exe ()
PRC - C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe (Sensible Vision )
PRC - C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe (Sensible Vision )
PRC - c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe (Sensible Vision )
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\cc6713be0e405d5a89a2783103f7e771\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\7fb80e48899821b64471f8e7ac2d08b7\System.Web.Services.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d76221993c2fdfb991b8c12ae50a30eb\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e245eb9c1067cabd5673fe832d28613\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\275680f2b9db0501d53c50ea7d7a43f0\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e9ebeb7959f1c916ebf6fca8f7077d6c\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\95b9866ab6e4437ef5dc5855ebab4e33\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\1b31ced9bb880d94fff1c6d47c16a81e\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\SdbShared.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\SdbShared.XmlSerializers.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\SdbUI.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\CppUtils.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\BalloonWindow.dll ()
MOD - C:\Program Files (x86)\Dell V305\dldtmon.exe ()
MOD - C:\Program Files (x86)\Dell V305\dldtmsdmon.exe ()
MOD - C:\Program Files (x86)\Dell V305\dldtdrs.dll ()
MOD - C:\Program Files (x86)\Dell V305\dldtscw.dll ()
MOD - C:\Windows\SysWOW64\FAIEExtension.dll ()
MOD - C:\Windows\SysWOW64\FAib.dll ()
MOD - C:\Windows\SysWOW64\FACrashRpt.dll ()
MOD - C:\Program Files (x86)\Dell V305\dldtcaps.dll ()
MOD - C:\Program Files (x86)\Dell V305\dldtmonr.dll ()
MOD - C:\Program Files (x86)\Dell V305\app4r.monitor.core.dll ()
MOD - C:\Program Files (x86)\Dell V305\app4r.monitor.common.dll ()
MOD - C:\Program Files (x86)\Dell V305\app4r.devmons.mcmdevmon.dll ()
MOD - C:\Program Files (x86)\Dell V305\DLDTcfg.dll ()
MOD - C:\Program Files (x86)\Dell V305\app4r.devmons.mcmdevmon.autoplayutil.dll ()
MOD - C:\Program Files (x86)\Dell V305\dldtcnv4.dll ()
MOD - C:\Program Files (x86)\Dell V305\dldtdatr.dll ()
MOD - C:\Program Files (x86)\Dell V305\dldtcats.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (dldt_device) – C:\Windows\SysNative\dldtcoms.exe ( )
SRV:64bit: - (dldtCATSCustConnectService) – C:\Windows\SysNative\spool\DRIVERS\x64\3\\dldtserv.exe ()
SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (avg9wd) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Sound Blaster X-Fi MB Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe (Creative Labs)
SRV - (SftService) – C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.exe (SoftThinks)
SRV - (dldt_device) – C:\Windows\SysWow64\dldtcoms.exe ( )
SRV - (FAService) – c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe (Sensible Vision )
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (AvgMfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (AvgTdiA) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (AvgLdx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (MusCAudio) – C:\Windows\SysNative\drivers\MusCAudio.sys (Windows ® Codename Longhorn DDK provider)
DRV:64bit: - (dc3d) MS Hardware Device Detection Driver (HID) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (CtClsFlt) – C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (FACAP) – C:\Windows\SysNative\drivers\facap.sys (Sensible Vision )
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9E 09 2B 37 C9 BA CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========


FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.647: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.647: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files (x86)\AVG\AVG9\Firefox [2011/09/13 15:22:03 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/12/09 19:40:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/12/09 19:40:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/12/09 19:40:44 | 000,000,000 | —D | M]

[2011/12/09 19:40:44 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/07/15 19:46:44 | 000,083,248 | —- | M] (Pinball Corporation.) – C:\Program Files (x86)\mozilla firefox\plugins\npclntax_HBLiteSA.dll
[2011/12/03 14:39:24 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/12/03 14:39:24 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Reg Error: Value error.) - {14BCE457-AAA0-41EC-99FA-820494957F4b} - C:\Users\Hayley\AppData\Local\SecurityWMP.dll (CyberLink)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (FAIESSOHelper Class) - {A2F122DA-055F-4df7-8F24-7354DBDBA85B} - c:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll (Sensible Vision )
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [dldtamon] C:\Program Files (x86)\Dell V305\dldtamon.exe ()
O4:64bit: - HKLM..\Run: [dldtmon.exe] C:\Program Files (x86)\Dell V305\dldtmon.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [RunDLLEntry] C:\Windows\SysNative\AmbRunE.DLL (Creative Technology Ltd.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [FAStartup] File not found
O4 - HKLM..\Run: [FATrayAlert] c:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe (Sensible Vision )
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F30ADFB9-5A10-4B5D-AF7E-DABA6696136A}: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F86D2C0C-D1B9-41CF-8C2A-B6D47D6A4E89}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\FastAccess: DllName - (c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll) - c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll ()
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/15 17:02:56 | 000,000,000 | —D | C] – C:\Users\admin\Desktop\ED_CLEANUP
[2011/12/15 17:02:29 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\admin\Desktop\OTL.exe
[2011/12/14 20:51:27 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Mozilla
[2011/12/14 20:51:27 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\Mozilla
[2011/12/14 20:46:57 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Dell
[2011/12/14 20:46:42 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\DataSafeOnline
[2011/12/14 20:31:11 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Macromedia
[2011/12/14 20:31:09 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Adobe
[2011/12/14 20:28:28 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\Stardock_Corporation
[2011/12/14 20:28:22 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Malwarebytes
[2011/12/14 20:27:34 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Apple Computer
[2011/12/14 20:27:34 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\Apple Computer
[2011/12/14 20:27:32 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Real
[2011/12/14 20:27:26 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\SupportSoft
[2011/12/14 20:26:56 | 000,000,000 | R–D | C] – C:\Users\admin\Searches
[2011/12/14 20:26:56 | 000,000,000 | R–D | C] – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/12/14 20:26:56 | 000,000,000 | -H-D | C] – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/12/14 20:26:46 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Identities
[2011/12/14 20:26:43 | 000,000,000 | R–D | C] – C:\Users\admin\Contacts
[2011/12/14 20:26:42 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\VirtualStore
[2011/12/14 20:25:21 | 000,000,000 | -HSD | C] – C:\Users\admin\AppData\Local\Temporary Internet Files
[2011/12/14 20:25:21 | 000,000,000 | -HSD | C] – C:\Users\admin\Templates
[2011/12/14 20:25:21 | 000,000,000 | -HSD | C] – C:\Users\admin\Start Menu
[2011/12/14 20:25:21 | 000,000,000 | -HSD | C] – C:\Users\admin\SendTo
[2011/12/14 20:25:21 | 000,000,000 | -HSD | C] – C:\Users\admin\Recent
[2011/12/14 20:25:21 | 000,000,000 | -HSD | C] – C:\Users\admin\PrintHood
[2011/12/14 20:25:21 | 000,000,000 | -HSD | C] – C:\Users\admin\Local Settings
[2011/12/14 20:25:21 | 000,000,000 | -HSD | C] – C:\Users\admin\AppData\Local\History
[2011/12/14 20:25:21 | 000,000,000 | -HSD | C] – C:\Users\admin\AppData\Local\Application Data
[2011/12/14 20:25:20 | 000,000,000 | -HSD | C] – C:\Users\admin\NetHood
[2011/12/14 20:25:20 | 000,000,000 | -HSD | C] – C:\Users\admin\Documents\My Videos
[2011/12/14 20:25:20 | 000,000,000 | -HSD | C] – C:\Users\admin\Documents\My Pictures
[2011/12/14 20:25:20 | 000,000,000 | -HSD | C] – C:\Users\admin\Documents\My Music
[2011/12/14 20:25:20 | 000,000,000 | -HSD | C] – C:\Users\admin\My Documents
[2011/12/14 20:25:20 | 000,000,000 | -HSD | C] – C:\Users\admin\Cookies
[2011/12/14 20:25:20 | 000,000,000 | -HSD | C] – C:\Users\admin\Application Data
[2011/12/14 20:25:14 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\Temp
[2011/12/14 20:25:14 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\SoftThinks
[2011/12/14 20:25:14 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\Microsoft Help
[2011/12/14 20:25:14 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\Microsoft
[2011/12/14 20:25:14 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Media Center Programs
[2011/12/14 20:25:12 | 000,000,000 | –SD | C] – C:\Users\admin\AppData\Roaming\Microsoft
[2011/12/14 20:25:12 | 000,000,000 | R–D | C] – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/12/14 20:25:12 | 000,000,000 | R–D | C] – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/12/14 20:25:12 | 000,000,000 | R–D | C] – C:\Users\admin\Desktop
[2011/12/14 20:25:12 | 000,000,000 | R–D | C] – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/12/14 20:25:12 | 000,000,000 | -H-D | C] – C:\Users\admin\AppData
[2011/12/14 20:25:11 | 000,000,000 | R–D | C] – C:\Users\admin\Videos
[2011/12/14 20:25:11 | 000,000,000 | R–D | C] – C:\Users\admin\Saved Games
[2011/12/14 20:25:11 | 000,000,000 | R–D | C] – C:\Users\admin\Pictures
[2011/12/14 20:25:11 | 000,000,000 | R–D | C] – C:\Users\admin\Music
[2011/12/14 20:25:11 | 000,000,000 | R–D | C] – C:\Users\admin\Links
[2011/12/14 20:25:11 | 000,000,000 | R–D | C] – C:\Users\admin\Favorites
[2011/12/14 20:25:11 | 000,000,000 | R–D | C] – C:\Users\admin\Downloads
[2011/12/14 20:25:11 | 000,000,000 | R–D | C] – C:\Users\admin\Documents
[2010/01/23 18:48:33 | 000,364,544 | —- | C] ( ) – C:\Windows\SysWow64\dldtinpa.dll
[2010/01/23 18:48:33 | 000,339,968 | —- | C] ( ) – C:\Windows\SysWow64\dldtiesc.dll
[2010/01/23 18:48:32 | 000,647,168 | —- | C] ( ) – C:\Windows\SysWow64\dldtpmui.dll
[2010/01/23 18:48:29 | 001,105,920 | —- | C] ( ) – C:\Windows\SysWow64\dldtserv.dll
[2010/01/23 18:48:29 | 000,843,776 | —- | C] ( ) – C:\Windows\SysWow64\dldtusb1.dll
[2010/01/23 18:48:28 | 000,569,344 | —- | C] ( ) – C:\Windows\SysWow64\dldtlmpm.dll
[2010/01/23 18:48:28 | 000,053,248 | —- | C] ( ) – C:\Windows\SysWow64\dldtprox.dll
[2010/01/23 18:48:27 | 000,663,552 | —- | C] ( ) – C:\Windows\SysWow64\dldthbn3.dll
[2010/01/23 18:48:27 | 000,320,168 | —- | C] ( ) – C:\Windows\SysWow64\dldtih.exe
[2010/01/23 18:48:26 | 000,594,600 | —- | C] ( ) – C:\Windows\SysWow64\dldtcoms.exe
[2010/01/23 18:48:25 | 000,851,968 | —- | C] ( ) – C:\Windows\SysWow64\dldtcomc.dll
[2010/01/23 18:48:25 | 000,376,832 | —- | C] ( ) – C:\Windows\SysWow64\dldtcomm.dll
[2010/01/23 18:48:25 | 000,365,224 | —- | C] ( ) – C:\Windows\SysWow64\dldtcfg.exe

========== Files - Modified Within 30 Days ==========

[2011/12/15 17:02:29 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\admin\Desktop\OTL.exe
[2011/12/15 17:01:39 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/15 17:01:39 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/15 16:57:11 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/15 16:54:03 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/15 16:54:01 | 3190,050,816 | -HS- | M] () – C:\hiberfil.sys
[2011/12/15 16:53:22 | 000,003,288 | —- | M] () – C:\bootsqm.dat
[2011/12/15 16:41:34 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/14 20:44:59 | 000,001,399 | —- | M] () – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/14 20:28:33 | 000,001,980 | —- | M] () – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
[2011/12/14 20:04:02 | 000,624,178 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/12/14 20:04:02 | 000,106,522 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/12/14 20:04:01 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/12/14 19:24:23 | 000,012,478 | -HS- | M] () – C:\ProgramData\8eg5f05xlw3y02nepkh1213el776ogl54f8m
[2011/12/09 19:27:24 | 000,013,882 | -HS- | M] () – C:\ProgramData\nlxrgy8n4nqv0odc4cjr8n562o1a
[2011/12/01 22:13:30 | 000,002,515 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/11/30 23:11:32 | 000,000,440 | -H– | M] () – C:\ProgramData\m4LGK7u3ufqUX2
[2011/11/30 23:09:04 | 000,000,312 | -H– | M] () – C:\ProgramData\~m4LGK7u3ufqUX2
[2011/11/30 23:09:04 | 000,000,216 | -H– | M] () – C:\ProgramData\~m4LGK7u3ufqUX2r

========== Files Created - No Company Name ==========

[2011/12/15 16:53:22 | 000,003,288 | —- | C] () – C:\bootsqm.dat
[2011/12/14 20:44:52 | 000,001,405 | —- | C] () – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/12/14 20:30:59 | 000,001,399 | —- | C] () – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/14 20:28:33 | 000,001,980 | —- | C] () – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
[2011/12/14 20:27:11 | 000,001,411 | —- | C] () – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011/12/14 20:25:17 | 000,000,290 | —- | C] () – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/12/14 20:25:17 | 000,000,272 | —- | C] () – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/12/14 20:25:15 | 000,001,802 | —- | C] () – C:\Users\admin\Desktop\Free year of music from Dell.lnk
[2011/12/11 03:02:10 | 000,012,478 | -HS- | C] () – C:\ProgramData\8eg5f05xlw3y02nepkh1213el776ogl54f8m
[2011/12/09 19:22:25 | 000,013,882 | -HS- | C] () – C:\ProgramData\nlxrgy8n4nqv0odc4cjr8n562o1a
[2011/12/01 22:13:30 | 000,002,515 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2011/11/30 23:09:04 | 000,000,216 | -H– | C] () – C:\ProgramData\~m4LGK7u3ufqUX2r
[2011/11/30 23:09:03 | 000,000,312 | -H– | C] () – C:\ProgramData\~m4LGK7u3ufqUX2
[2011/11/30 23:08:58 | 000,000,440 | -H– | C] () – C:\ProgramData\m4LGK7u3ufqUX2
[2010/03/24 18:03:46 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/01/23 18:48:34 | 000,348,160 | —- | C] () – C:\Windows\SysWow64\DLDTinst.dll
[2010/01/23 18:48:34 | 000,335,872 | —- | C] () – C:\Windows\SysWow64\dldtcomx.dll
[2010/01/23 18:48:33 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\dldtjswr.dll
[2010/01/23 18:48:33 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\dldtinsr.dll
[2010/01/23 18:48:33 | 000,036,864 | —- | C] () – C:\Windows\SysWow64\dldtcur.dll
[2010/01/23 18:48:32 | 000,532,480 | —- | C] () – C:\Windows\SysWow64\dldtutil.dll
[2010/01/23 18:48:31 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\dldtinsb.dll
[2010/01/23 18:48:31 | 000,176,128 | —- | C] () – C:\Windows\SysWow64\dldtins.dll
[2010/01/23 18:48:30 | 000,086,016 | —- | C] () – C:\Windows\SysWow64\dldtcub.dll
[2010/01/23 18:48:30 | 000,077,824 | —- | C] () – C:\Windows\SysWow64\dldtcu.dll
[2009/12/25 21:33:23 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/12/05 23:47:20 | 000,982,220 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2009/12/05 23:47:19 | 000,134,592 | —- | C] () – C:\Windows\SysWow64\igfcg500.bin
[2009/12/05 23:47:19 | 000,092,216 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2009/12/05 23:47:18 | 000,433,024 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2009/07/15 12:45:34 | 000,782,336 | —- | C] () – C:\Windows\SysWow64\dldtdrs.dll
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/24 17:32:34 | 000,089,352 | —- | C] () – C:\Windows\SysWow64\FAIEExtension.dll
[2009/06/24 17:31:46 | 000,059,144 | —- | C] () – C:\Windows\SysWow64\FAib.dll
[2009/06/24 17:31:00 | 000,234,760 | —- | C] () – C:\Windows\SysWow64\FACrashRpt.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2009/05/14 13:57:38 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\dldtcaps.dll
[2008/01/22 02:05:12 | 000,077,906 | —- | C] () – C:\Windows\SysWow64\dldtcfg.dll
[2007/11/13 19:13:10 | 000,069,632 | —- | C] () – C:\Windows\SysWow64\dldtcnv4.dll

========== LOP Check ==========

[2011/05/11 11:51:46 | 000,032,640 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/12/15 16:53:22 | 000,003,288 | —- | M] () – C:\bootsqm.dat
[2009/12/05 23:53:53 | 000,003,558 | RH– | M] () – C:\dell.sdr
[2011/12/15 16:54:01 | 3190,050,816 | -HS- | M] () – C:\hiberfil.sys
[2011/10/24 18:08:21 | 000,001,057 | -H– | M] () – C:\IPH.PH
[2011/12/15 16:54:00 | 4253,405,184 | -HS- | M] () – C:\pagefile.sys
[2011/12/14 20:49:51 | 000,000,450 | —- | M] () – C:\rkill.log

< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/12/14 20:44:59 | 000,000,221 | -HS- | M] () – C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/12/15 17:02:29 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\admin\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< >

< >

< End of report >
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-


Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-16 15:52:00 —————————– 15:52:00.973 OS Version: Windows x64 6.1.7600 15:52:00.973 Number of processors: 2 586 0x170A 15:52:00.973 ComputerName: HAYLEY-PC UserName: admin 15:52:20.673 Initialze error C000010E - driver not loaded 15:52:20.705 write error "aswCmnB.dll". The process cannot access the file because it is being used by another process. 15:52:20.798 AVAST engine defs: 11121601 15:52:55.352 Service scanning 15:53:09.548 Modules scanning 15:53:09.548 Disk 0 trace - called modules: 15:53:09.548 15:53:20.501 AVAST engine scan C:\Windows 15:53:31.115 AVAST engine scan C:\Windows\system32 16:01:52.432 AVAST engine scan C:\Windows\system32\drivers 16:02:15.676 AVAST engine scan C:\Users\admin 16:03:20.899 The log file has been saved successfully to "C:\Users\admin\Desktop\aswMBR.txt" aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-16 15:52:00 —————————– 15:52:00.973 OS Version: Windows x64 6.1.7600 15:52:00.973 Number of processors: 2 586 0x170A 15:52:00.973 ComputerName: HAYLEY-PC UserName: admin 15:52:20.673 Initialze error C000010E - driver not loaded 15:52:20.705 write error "aswCmnB.dll". The process cannot access the file because it is being used by another process. 15:52:20.798 AVAST engine defs: 11121601 15:52:55.352 Service scanning 15:53:09.548 Modules scanning 15:53:09.548 Disk 0 trace - called modules: 15:53:09.548 15:53:20.501 AVAST engine scan C:\Windows 15:53:31.115 AVAST engine scan C:\Windows\system32 16:01:52.432 AVAST engine scan C:\Windows\system32\drivers 16:02:15.676 AVAST engine scan C:\Users\admin 16:03:20.899 The log file has been saved successfully to "C:\Users\admin\Desktop\aswMBR.txt" 16:05:00.054 AVAST engine scan C:\ProgramData 16:20:23.185 Scan finished successfully 16:30:36.131 The log file has been saved successfully to "C:\Users\admin\Desktop\aswMBR.txt"
Hi,

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-17 14:42:27 —————————– 14:42:27.864 OS Version: Windows x64 6.1.7600 14:42:27.864 Number of processors: 2 586 0x170A 14:42:27.864 ComputerName: HAYLEY-PC UserName: admin 14:42:29.143 Initialize success 14:42:35.009 AVAST engine defs: 11121601 14:42:44.025 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 14:42:44.025 Disk 0 Vendor: SAMSUNG_ 2AC1 Size: 238475MB BusType: 3 14:42:44.041 Disk 0 MBR read successfully 14:42:44.057 Disk 0 MBR scan 14:42:44.057 Disk 0 Windows VISTA default MBR code 14:42:44.057 Service scanning 14:42:45.414 Modules scanning 14:42:45.414 Disk 0 trace - called modules: 14:42:45.445 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 14:42:45.445 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004289430] 14:42:45.461 3 CLASSPNP.SYS[fffff8800145143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80040d2050] 14:42:46.958 AVAST engine scan C:\Windows 14:42:50.484 AVAST engine scan C:\Windows\system32 14:45:05.798 AVAST engine scan C:\Windows\system32\drivers 14:45:19.581 AVAST engine scan C:\Users\admin 14:46:33.106 AVAST engine scan C:\ProgramData 14:48:20.730 Scan finished successfully 14:55:39.405 Disk 0 MBR has been saved successfully to "C:\Users\admin\Desktop\MBR.dat" 14:55:39.405 The log file has been saved successfully to "C:\Users\admin\Desktop\aswMBR2.txt"
MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows 7 Home Premium Edition Windows Information: (build 7600), 64-bit Base Board Manufacturer: Dell Inc. BIOS Manufacturer: Dell Inc. System Manufacturer: Dell Inc. System Product Name: Inspiron 1750 Logical Drives Mask: 0x0000000c Kernel Drivers (total 150): 0x02A54000 \SystemRoot\system32\ntoskrnl.exe 0x02A0B000 \SystemRoot\system32\hal.dll 0x00B9E000 \SystemRoot\system32\kdcom.dll 0x00CCA000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x00D0E000 \SystemRoot\system32\PSHED.dll 0x00D22000 \SystemRoot\system32\CLFS.SYS 0x00C00000 \SystemRoot\system32\CI.dll 0x00E20000 \SystemRoot\system32\drivers\Wdf01000.sys 0x00EC4000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x00ED3000 \SystemRoot\system32\DRIVERS\ACPI.sys 0x00F2A000 \SystemRoot\system32\DRIVERS\WMILIB.SYS 0x00F33000 \SystemRoot\system32\DRIVERS\msisadrv.sys 0x00F3D000 \SystemRoot\system32\DRIVERS\pci.sys 0x00F70000 \SystemRoot\system32\DRIVERS\vdrvroot.sys 0x00F7D000 \SystemRoot\System32\drivers\partmgr.sys 0x00F92000 \SystemRoot\system32\DRIVERS\compbatt.sys 0x00F9B000 \SystemRoot\system32\DRIVERS\BATTC.SYS 0x00FA7000 \SystemRoot\system32\DRIVERS\volmgr.sys 0x00D80000 \SystemRoot\System32\drivers\volmgrx.sys 0x00FBC000 \SystemRoot\System32\drivers\mountmgr.sys 0x0103C000 \SystemRoot\system32\DRIVERS\iaStor.sys 0x01158000 \SystemRoot\system32\drivers\amdxata.sys 0x01163000 \SystemRoot\system32\drivers\fltmgr.sys 0x011AF000 \SystemRoot\system32\drivers\fileinfo.sys 0x011C3000 \SystemRoot\System32\Drivers\PxHlpa64.sys 0x01207000 \SystemRoot\System32\Drivers\Ntfs.sys 0x0149B000 \SystemRoot\System32\Drivers\msrpc.sys 0x014F9000 \SystemRoot\System32\Drivers\ksecdd.sys 0x01513000 \SystemRoot\System32\Drivers\cng.sys 0x01586000 \SystemRoot\System32\drivers\pcw.sys 0x01597000 \SystemRoot\System32\Drivers\Fs_Rec.sys 0x0164C000 \SystemRoot\system32\drivers\ndis.sys 0x0173E000 \SystemRoot\system32\drivers\NETIO.SYS 0x0179E000 \SystemRoot\System32\Drivers\ksecpkg.sys 0x01600000 \SystemRoot\system32\DRIVERS\volsnap.sys 0x017C9000 \SystemRoot\System32\Drivers\spldr.sys 0x015A1000 \SystemRoot\System32\drivers\rdyboost.sys 0x017D1000 \SystemRoot\System32\Drivers\mup.sys 0x017E3000 \SystemRoot\System32\drivers\hwpolicy.sys 0x01400000 \SystemRoot\System32\DRIVERS\fvevol.sys 0x0143A000 \SystemRoot\system32\DRIVERS\disk.sys 0x01450000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS 0x017EC000 \SystemRoot\system32\DRIVERS\avgrkx64.sys 0x01480000 \SystemRoot\system32\DRIVERS\AVGIDSEH.Sys 0x02BC8000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x02A00000 \SystemRoot\system32\DRIVERS\avgmfx64.sys 0x02A10000 \SystemRoot\System32\Drivers\Null.SYS 0x02A19000 \SystemRoot\System32\Drivers\Beep.SYS 0x02A20000 \SystemRoot\System32\drivers\vga.sys 0x02A2E000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x02A53000 \SystemRoot\System32\drivers\watchdog.sys 0x02A63000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x02A6C000 \SystemRoot\system32\drivers\rdpencdd.sys 0x02A75000 \SystemRoot\system32\drivers\rdprefmp.sys 0x02A7E000 \SystemRoot\System32\Drivers\Msfs.SYS 0x015DB000 \SystemRoot\System32\Drivers\Npfs.SYS 0x03802000 \SystemRoot\System32\drivers\tcpip.sys 0x013A9000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x011D0000 \SystemRoot\system32\DRIVERS\tdx.sys 0x02A89000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x03A08000 \SystemRoot\system32\DRIVERS\avgtdia.sys 0x03A68000 \SystemRoot\System32\DRIVERS\netbt.sys 0x03AAD000 \SystemRoot\system32\drivers\afd.sys 0x03B36000 \SystemRoot\system32\DRIVERS\wfplwf.sys 0x03B3F000 \SystemRoot\system32\DRIVERS\pacer.sys 0x03B65000 \SystemRoot\system32\DRIVERS\vwififlt.sys 0x03B7B000 \SystemRoot\system32\DRIVERS\netbios.sys 0x03B8A000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x03BA5000 \SystemRoot\system32\DRIVERS\termdd.sys 0x03CCB000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x03D1C000 \SystemRoot\system32\drivers\nsiproxy.sys 0x03D28000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x03D33000 \SystemRoot\System32\drivers\discache.sys 0x03D42000 \SystemRoot\System32\Drivers\dfsc.sys 0x03D60000 \SystemRoot\system32\DRIVERS\blbdrive.sys 0x03D71000 \SystemRoot\system32\DRIVERS\avgldx64.sys 0x03DBA000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x0464A000 \SystemRoot\system32\DRIVERS\igdkmd64.sys 0x03EBE000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x03FB2000 \SystemRoot\System32\drivers\dxgmms1.sys 0x03E00000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0x03E0D000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x03E63000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x03E74000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x0403A000 \SystemRoot\system32\DRIVERS\athrx.sys 0x041A8000 \SystemRoot\system32\DRIVERS\vwifibus.sys 0x04D49000 \SystemRoot\system32\DRIVERS\yk62x64.sys 0x041B5000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0x04DAD000 \SystemRoot\system32\DRIVERS\SynTP.sys 0x041D3000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x041D5000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x041E4000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x041F3000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys 0x04000000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0x04005000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0x0400E000 \SystemRoot\system32\DRIVERS\intelppm.sys 0x04024000 \SystemRoot\system32\DRIVERS\CompositeBus.sys 0x03E98000 \SystemRoot\system32\DRIVERS\AgileVpn.sys 0x04600000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x03EAE000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x03C00000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x04624000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x03C2F000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x03C50000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x04034000 \SystemRoot\system32\DRIVERS\swenum.sys 0x03C6A000 \SystemRoot\system32\DRIVERS\ks.sys 0x03CAD000 \SystemRoot\system32\DRIVERS\umbus.sys 0x04E69000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x04EC3000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x04ED8000 \SystemRoot\system32\DRIVERS\stwrt64.sys 0x04F53000 \SystemRoot\system32\DRIVERS\portcls.sys 0x04F90000 \SystemRoot\system32\DRIVERS\drmk.sys 0x04FB2000 \SystemRoot\system32\drivers\ksthunk.sys 0x04FB8000 \SystemRoot\System32\Drivers\RtsUStor.sys 0x04E00000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0x04E1D000 \SystemRoot\System32\Drivers\usbvideo.sys 0x03BB9000 \SystemRoot\system32\DRIVERS\CtClsFlt.sys 0x04E4B000 \SystemRoot\System32\Drivers\crashdmp.sys 0x02A96000 \SystemRoot\System32\Drivers\dump_iaStor.sys 0x03DE0000 \SystemRoot\System32\Drivers\dump_dumpfve.sys 0x00080000 \SystemRoot\System32\win32k.sys 0x04E59000 \SystemRoot\System32\drivers\Dxapi.sys 0x04FF2000 \SystemRoot\system32\DRIVERS\monitor.sys 0x005C0000 \SystemRoot\System32\TSDDD.dll 0x007A0000 \SystemRoot\System32\cdd.dll 0x01000000 \SystemRoot\system32\drivers\luafv.sys 0x00FD6000 \SystemRoot\system32\drivers\WudfPf.sys 0x03BE4000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x0267C000 \SystemRoot\system32\DRIVERS\nwifi.sys 0x026CF000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0x026E2000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x026FA000 \SystemRoot\system32\drivers\HTTP.sys 0x027C2000 \SystemRoot\system32\DRIVERS\bowser.sys 0x027E0000 \SystemRoot\System32\drivers\mpsdrv.sys 0x02600000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x0262D000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x00DDC000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x0463F000 \SystemRoot\system32\DRIVERS\AVGIDSFilter.Sys 0x044E0000 \SystemRoot\system32\drivers\peauth.sys 0x04586000 \SystemRoot\System32\Drivers\secdrv.SYS 0x04591000 \SystemRoot\System32\DRIVERS\srvnet.sys 0x045BE000 \SystemRoot\System32\drivers\tcpipreg.sys 0x045D0000 \SystemRoot\system32\DRIVERS\AVGIDSDriver.Sys 0x04400000 \SystemRoot\System32\DRIVERS\srv2.sys 0x064A8000 \SystemRoot\System32\DRIVERS\srv.sys 0x0653D000 \SystemRoot\System32\Drivers\fastfat.SYS 0x065E4000 \??\C:\Users\admin\AppData\Local\Temp\aswMBR.sys 0x76CB0000 \Windows\System32\ntdll.dll 0x47F70000 \Windows\System32\smss.exe 0xFEFD0000 \Windows\System32\apisetschema.dll Processes (total 81): 0 System Idle Process 4 System 300 C:\Windows\System32\smss.exe 356 C:\PROGRA~2\AVG\AVG2012\avgrsa.exe 388 C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe 616 csrss.exe 680 C:\Windows\System32\wininit.exe 692 csrss.exe 732 C:\Windows\System32\services.exe 764 C:\Windows\System32\winlogon.exe 804 C:\Windows\System32\lsass.exe 812 C:\Windows\System32\lsm.exe 912 C:\Windows\System32\svchost.exe 988 C:\Windows\System32\svchost.exe 344 C:\Windows\System32\svchost.exe 696 C:\Windows\System32\svchost.exe 568 C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe 1112 C:\Windows\System32\svchost.exe 1136 C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe 1336 C:\Windows\System32\svchost.exe 1432 C:\Program Files\Dell\DellDock\DockLogin.exe 1500 C:\Windows\System32\svchost.exe 1616 C:\Windows\System32\spoolsv.exe 1644 C:\Windows\System32\svchost.exe 1736 C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 1776 C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe 1808 C:\Program Files\Bonjour\mDNSResponder.exe 1852 C:\Windows\System32\dldtcoms.exe 1892 C:\Windows\System32\svchost.exe 1040 C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 1664 C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe 1832 C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe 2088 C:\Windows\System32\svchost.exe 2156 C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe 2336 C:\Windows\System32\dwm.exe 2376 C:\Windows\System32\taskhost.exe 2664 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 2704 C:\Windows\explorer.exe 2728 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE 2764 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe 2864 C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe 2208 C:\Windows\System32\svchost.exe 3428 WmiPrvSE.exe 3796 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 3808 C:\Program Files\IDT\WDM\sttray64.exe 3844 C:\Windows\System32\igfxtray.exe 3880 C:\Windows\System32\hkcmd.exe 3888 C:\Windows\System32\igfxpers.exe 4012 C:\Windows\System32\igfxsrvc.exe 3152 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe 2760 C:\Windows\System32\SearchIndexer.exe 3264 C:\Program Files\Dell\QuickSet\quickset.exe 3200 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe 3508 C:\Windows\System32\rundll32.exe 3516 C:\Program Files (x86)\Dell V305\dldtmon.exe 3492 C:\Program Files\Dell\DellDock\DellDock.exe 3688 C:\Program Files (x86)\Dell V305\dldtmsdmon.exe 3024 C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe 308 C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe 848 C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe 228 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe 1156 C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe 4116 C:\Program Files (x86)\iTunes\iTunesHelper.exe 4180 C:\Program Files (x86)\AVG\AVG2012\avgtray.exe 4220 C:\Program Files (x86)\AVG Secure Search\vprot.exe 4384 C:\Program Files\iPod\bin\iPodService.exe 2344 C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe 1224 C:\Program Files\Windows Media Player\wmpnetwk.exe 4104 C:\Windows\System32\wuauclt.exe 4972 C:\Windows\System32\audiodg.exe 4128 C:\Program Files (x86)\Internet Explorer\iexplore.exe 620 C:\Program Files (x86)\Internet Explorer\iexplore.exe 2164 C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe 3148 C:\Program Files (x86)\Internet Explorer\iexplore.exe 4580 C:\Windows\System32\SearchProtocolHost.exe 4688 C:\Windows\System32\SearchFilterHost.exe 2112 taskhost.exe 2612 dllhost.exe 4960 dllhost.exe 2632 C:\Users\admin\Desktop\MBRCheck.exe 4984 C:\Windows\System32\conhost.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000003`ac000000 (NTFS) PhysicalDrive0 Model Number: SAMSUNGHM250HI, Rev: 2AC101C4 Size Device Name MBR Status ——————————————– 232 GB \\.\PhysicalDrive0 Dell Inspiron MBR code detected SHA1: AE3E0A945D44C8EA304A19A8F50F69065C34344B Done!
Hi,

Thanks for re-running that. :)

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Right-click and Run as Administrator TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-
18:12:20.0353 1440 TDSS rootkit removing tool [removed] Dec 13 2011 10:39:31 18:12:20.0634 1440 ============================================================ 18:12:20.0634 1440 Current date / time: 2011/12/17 18:12:20.0634 18:12:20.0634 1440 SystemInfo: 18:12:20.0634 1440 18:12:20.0634 1440 OS Version: 6.1.7600 ServicePack: 0.0 18:12:20.0634 1440 Product type: Workstation 18:12:20.0634 1440 ComputerName: HAYLEY-PC 18:12:20.0634 1440 UserName: admin 18:12:20.0634 1440 Windows directory: C:\Windows 18:12:20.0634 1440 System windows directory: C:\Windows 18:12:20.0634 1440 Running under WOW64 18:12:20.0634 1440 Processor architecture: Intel x64 18:12:20.0634 1440 Number of processors: 2 18:12:20.0634 1440 Page size: 0x1000 18:12:20.0634 1440 Boot type: Normal boot 18:12:20.0634 1440 ============================================================ 18:12:21.0039 1440 Initialize success 18:12:44.0487 5328 ============================================================ 18:12:44.0487 5328 Scan started 18:12:44.0487 5328 Mode: Manual; 18:12:44.0487 5328 ============================================================ 18:12:45.0142 5328 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys 18:12:45.0142 5328 1394ohci - ok 18:12:45.0220 5328 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys 18:12:45.0236 5328 ACPI - ok 18:12:45.0283 5328 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys 18:12:45.0298 5328 AcpiPmi - ok 18:12:45.0376 5328 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys 18:12:45.0376 5328 adp94xx - ok 18:12:45.0517 5328 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys 18:12:45.0517 5328 adpahci - ok 18:12:45.0985 5328 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys 18:12:45.0985 5328 adpu320 - ok 18:12:46.0063 5328 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\Windows\system32\drivers\afd.sys 18:12:46.0063 5328 AFD - ok 18:12:46.0110 5328 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys 18:12:46.0110 5328 agp440 - ok 18:12:46.0188 5328 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys 18:12:46.0203 5328 aliide - ok 18:12:46.0234 5328 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys 18:12:46.0250 5328 amdide - ok 18:12:46.0312 5328 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys 18:12:46.0312 5328 AmdK8 - ok 18:12:46.0344 5328 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys 18:12:46.0344 5328 AmdPPM - ok 18:12:46.0406 5328 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys 18:12:46.0437 5328 amdsata - ok 18:12:46.0515 5328 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys 18:12:46.0515 5328 amdsbs - ok 18:12:46.0578 5328 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys 18:12:46.0593 5328 amdxata - ok 18:12:46.0656 5328 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys 18:12:46.0656 5328 AppID - ok 18:12:46.0827 5328 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys 18:12:46.0827 5328 arc - ok 18:12:46.0858 5328 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys 18:12:46.0858 5328 arcsas - ok 18:12:46.0968 5328 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 18:12:46.0968 5328 AsyncMac - ok 18:12:47.0046 5328 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys 18:12:47.0061 5328 atapi - ok 18:12:47.0358 5328 athr (e0fabc10635c670bd7d89fd214a405d7) C:\Windows\system32\DRIVERS\athrx.sys 18:12:47.0373 5328 athr - ok 18:12:47.0794 5328 AVGIDSDriver (e29ea1a0ec7ab9fa2dc7e75a03f12a4f) C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys 18:12:47.0794 5328 AVGIDSDriver - ok 18:12:47.0872 5328 AVGIDSEH (f823d184b8e8ffb8da3ead45dbf5bd6a) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys 18:12:47.0872 5328 AVGIDSEH - ok 18:12:47.0919 5328 AVGIDSFilter (ed2b25bd7fe35d1944211968842d30da) C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys 18:12:47.0919 5328 AVGIDSFilter - ok 18:12:48.0075 5328 Avgldx64 (979cf8912449a10b987218bff80a1fa3) C:\Windows\system32\DRIVERS\avgldx64.sys 18:12:48.0138 5328 Avgldx64 - ok 18:12:48.0278 5328 Avgmfx64 (36b1a5843695766eac714daffc5b84d1) C:\Windows\system32\DRIVERS\avgmfx64.sys 18:12:48.0278 5328 Avgmfx64 - ok 18:12:48.0434 5328 Avgrkx64 (1102239fb724527f1febbbbccf6bf313) C:\Windows\system32\DRIVERS\avgrkx64.sys 18:12:48.0434 5328 Avgrkx64 - ok 18:12:48.0481 5328 Avgtdia (11f36d3ea82d9db9aa05a476a210551b) C:\Windows\system32\DRIVERS\avgtdia.sys 18:12:48.0496 5328 Avgtdia - ok 18:12:48.0793 5328 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys 18:12:48.0824 5328 b06bdrv - ok 18:12:48.0933 5328 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 18:12:48.0933 5328 b57nd60a - ok 18:12:49.0058 5328 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 18:12:49.0058 5328 Beep - ok 18:12:49.0183 5328 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 18:12:49.0198 5328 blbdrive - ok 18:12:49.0464 5328 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys 18:12:49.0464 5328 bowser - ok 18:12:49.0620 5328 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys 18:12:49.0620 5328 BrFiltLo - ok 18:12:49.0682 5328 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys 18:12:49.0698 5328 BrFiltUp - ok 18:12:49.0822 5328 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 18:12:49.0838 5328 Brserid - ok 18:12:49.0854 5328 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 18:12:49.0869 5328 BrSerWdm - ok 18:12:49.0916 5328 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 18:12:49.0916 5328 BrUsbMdm - ok 18:12:50.0025 5328 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 18:12:50.0041 5328 BrUsbSer - ok 18:12:50.0166 5328 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys 18:12:50.0166 5328 BTHMODEM - ok 18:12:50.0290 5328 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 18:12:50.0290 5328 cdfs - ok 18:12:50.0353 5328 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys 18:12:50.0368 5328 cdrom - ok 18:12:50.0493 5328 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys 18:12:50.0493 5328 circlass - ok 18:12:50.0618 5328 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 18:12:50.0618 5328 CLFS - ok 18:12:50.0883 5328 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 18:12:50.0883 5328 CmBatt - ok 18:12:50.0946 5328 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys 18:12:50.0946 5328 cmdide - ok 18:12:51.0039 5328 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys 18:12:51.0055 5328 CNG - ok 18:12:51.0289 5328 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys 18:12:51.0289 5328 Compbatt - ok 18:12:51.0336 5328 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys 18:12:51.0367 5328 CompositeBus - ok 18:12:51.0414 5328 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys 18:12:51.0429 5328 crcdisk - ok 18:12:51.0523 5328 CtClsFlt (ed5cf92396a62f4c15110dcdb5e854d9) C:\Windows\system32\DRIVERS\CtClsFlt.sys 18:12:51.0523 5328 CtClsFlt - ok 18:12:51.0616 5328 dc3d (db0459afd124ce5ccb649e33f95d715f) C:\Windows\system32\DRIVERS\dc3d.sys 18:12:51.0616 5328 dc3d - ok 18:12:51.0679 5328 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys 18:12:51.0679 5328 DfsC - ok 18:12:51.0710 5328 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 18:12:51.0710 5328 discache - ok 18:12:51.0757 5328 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys 18:12:51.0757 5328 Disk - ok 18:12:51.0866 5328 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 18:12:51.0866 5328 drmkaud - ok 18:12:51.0928 5328 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys 18:12:51.0944 5328 DXGKrnl - ok 18:12:52.0053 5328 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys 18:12:52.0084 5328 ebdrv - ok 18:12:52.0240 5328 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys 18:12:52.0256 5328 elxstor - ok 18:12:52.0272 5328 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys 18:12:52.0272 5328 ErrDev - ok 18:12:52.0334 5328 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 18:12:52.0350 5328 exfat - ok 18:12:52.0412 5328 FACAP (2c1d443e14f376e8331f52f135dca9ef) C:\Windows\system32\DRIVERS\facap.sys 18:12:52.0412 5328 FACAP - ok 18:12:52.0443 5328 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 18:12:52.0443 5328 fastfat - ok 18:12:52.0490 5328 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys 18:12:52.0506 5328 fdc - ok 18:12:52.0615 5328 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 18:12:52.0615 5328 FileInfo - ok 18:12:52.0677 5328 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 18:12:52.0677 5328 Filetrace - ok 18:12:53.0379 5328 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys 18:12:53.0379 5328 flpydisk - ok 18:12:53.0442 5328 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys 18:12:53.0442 5328 FltMgr - ok 18:12:53.0473 5328 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 18:12:53.0488 5328 FsDepends - ok 18:12:53.0535 5328 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 18:12:53.0535 5328 Fs_Rec - ok 18:12:53.0629 5328 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys 18:12:53.0644 5328 fvevol - ok 18:12:53.0769 5328 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys 18:12:53.0769 5328 gagp30kx - ok 18:12:53.0910 5328 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 18:12:53.0910 5328 GEARAspiWDM - ok 18:12:54.0128 5328 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 18:12:54.0128 5328 hcw85cir - ok 18:12:54.0175 5328 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys 18:12:54.0175 5328 HDAudBus - ok 18:12:54.0237 5328 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys 18:12:54.0237 5328 HidBatt - ok 18:12:54.0300 5328 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys 18:12:54.0315 5328 HidBth - ok 18:12:54.0424 5328 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys 18:12:54.0424 5328 HidIr - ok 18:12:54.0502 5328 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys 18:12:54.0518 5328 HidUsb - ok 18:12:54.0705 5328 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys 18:12:54.0721 5328 HpSAMD - ok 18:12:54.0877 5328 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys 18:12:54.0892 5328 HTTP - ok 18:12:55.0111 5328 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys 18:12:55.0111 5328 hwpolicy - ok 18:12:55.0220 5328 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys 18:12:55.0236 5328 i8042prt - ok 18:12:55.0345 5328 iaStor (1d004cb1da6323b1f55caef7f94b61d9) C:\Windows\system32\DRIVERS\iaStor.sys 18:12:55.0345 5328 iaStor - ok 18:12:55.0563 5328 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys 18:12:55.0594 5328 iaStorV - ok 18:12:56.0967 5328 igfx (babd5f9b2bcc82ce556a0baf1ae208a7) C:\Windows\system32\DRIVERS\igdkmd64.sys 18:12:57.0123 5328 igfx - ok 18:12:57.0388 5328 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys 18:12:57.0404 5328 iirsp - ok 18:12:57.0513 5328 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys 18:12:57.0513 5328 intelide - ok 18:12:57.0654 5328 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 18:12:57.0654 5328 intelppm - ok 18:12:57.0700 5328 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys 18:12:57.0700 5328 IpFilterDriver - ok 18:12:57.0732 5328 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys 18:12:57.0747 5328 IPMIDRV - ok 18:12:57.0825 5328 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 18:12:57.0841 5328 IPNAT - ok 18:12:57.0950 5328 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 18:12:57.0966 5328 IRENUM - ok 18:12:57.0997 5328 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys 18:12:58.0012 5328 isapnp - ok 18:12:58.0137 5328 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys 18:12:58.0153 5328 iScsiPrt - ok 18:12:58.0200 5328 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys 18:12:58.0200 5328 kbdclass - ok 18:12:58.0246 5328 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys 18:12:58.0246 5328 kbdhid - ok 18:12:58.0324 5328 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys 18:12:58.0324 5328 KSecDD - ok 18:12:58.0402 5328 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys 18:12:58.0418 5328 KSecPkg - ok 18:12:58.0449 5328 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 18:12:58.0465 5328 ksthunk - ok 18:12:58.0605 5328 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 18:12:58.0605 5328 lltdio - ok 18:12:58.0714 5328 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys 18:12:58.0714 5328 LSI_FC - ok 18:12:58.0839 5328 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys 18:12:58.0839 5328 LSI_SAS - ok 18:12:58.0948 5328 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys 18:12:58.0964 5328 LSI_SAS2 - ok 18:12:59.0058 5328 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys 18:12:59.0073 5328 LSI_SCSI - ok 18:12:59.0167 5328 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 18:12:59.0167 5328 luafv - ok 18:12:59.0229 5328 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys 18:12:59.0229 5328 megasas - ok 18:12:59.0292 5328 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys 18:12:59.0323 5328 MegaSR - ok 18:12:59.0432 5328 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 18:12:59.0448 5328 Modem - ok 18:12:59.0526 5328 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 18:12:59.0526 5328 monitor - ok 18:12:59.0588 5328 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys 18:12:59.0588 5328 mouclass - ok 18:12:59.0666 5328 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 18:12:59.0682 5328 mouhid - ok 18:12:59.0744 5328 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys 18:12:59.0744 5328 mountmgr - ok 18:12:59.0853 5328 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys 18:12:59.0853 5328 mpio - ok 18:12:59.0947 5328 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 18:12:59.0947 5328 mpsdrv - ok 18:13:00.0040 5328 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys 18:13:00.0040 5328 MRxDAV - ok 18:13:00.0165 5328 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys 18:13:00.0181 5328 mrxsmb - ok 18:13:00.0321 5328 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys 18:13:00.0337 5328 mrxsmb10 - ok 18:13:00.0462 5328 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys 18:13:00.0462 5328 mrxsmb20 - ok 18:13:00.0508 5328 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys 18:13:00.0508 5328 msahci - ok 18:13:00.0571 5328 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys 18:13:00.0571 5328 msdsm - ok 18:13:00.0664 5328 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 18:13:00.0664 5328 Msfs - ok 18:13:00.0711 5328 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 18:13:00.0711 5328 mshidkmdf - ok 18:13:00.0774 5328 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys 18:13:00.0774 5328 msisadrv - ok 18:13:00.0820 5328 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 18:13:00.0836 5328 MSKSSRV - ok 18:13:00.0898 5328 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 18:13:00.0898 5328 MSPCLOCK - ok 18:13:00.0961 5328 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 18:13:00.0976 5328 MSPQM - ok 18:13:01.0054 5328 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys 18:13:01.0070 5328 MsRPC - ok 18:13:01.0164 5328 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys 18:13:01.0164 5328 mssmbios - ok 18:13:01.0226 5328 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 18:13:01.0226 5328 MSTEE - ok 18:13:01.0257 5328 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys 18:13:01.0273 5328 MTConfig - ok 18:13:01.0351 5328 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 18:13:01.0366 5328 Mup - ok 18:13:01.0460 5328 MusCAudio (23eb9109de7ae6e181ad3b31e086eeff) C:\Windows\system32\drivers\MusCAudio.sys 18:13:01.0476 5328 MusCAudio - ok 18:13:01.0741 5328 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 18:13:01.0756 5328 NativeWifiP - ok 18:13:01.0928 5328 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys 18:13:01.0944 5328 NDIS - ok 18:13:01.0990 5328 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 18:13:02.0006 5328 NdisCap - ok 18:13:02.0100 5328 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 18:13:02.0100 5328 NdisTapi - ok 18:13:02.0178 5328 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys 18:13:02.0178 5328 Ndisuio - ok 18:13:02.0271 5328 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys 18:13:02.0287 5328 NdisWan - ok 18:13:02.0349 5328 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys 18:13:02.0349 5328 NDProxy - ok 18:13:02.0427 5328 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 18:13:02.0427 5328 NetBIOS - ok 18:13:02.0568 5328 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys 18:13:02.0568 5328 NetBT - ok 18:13:02.0708 5328 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys 18:13:02.0708 5328 nfrd960 - ok 18:13:02.0770 5328 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 18:13:02.0770 5328 Npfs - ok 18:13:02.0802 5328 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 18:13:02.0802 5328 nsiproxy - ok 18:13:03.0238 5328 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys 18:13:03.0254 5328 Ntfs - ok 18:13:03.0582 5328 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 18:13:03.0582 5328 Null - ok 18:13:03.0722 5328 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys 18:13:03.0722 5328 nvraid - ok 18:13:03.0784 5328 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys 18:13:03.0784 5328 nvstor - ok 18:13:03.0816 5328 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys 18:13:03.0831 5328 nv_agp - ok 18:13:03.0972 5328 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys 18:13:03.0987 5328 ohci1394 - ok 18:13:04.0081 5328 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys 18:13:04.0096 5328 Parport - ok 18:13:04.0159 5328 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys 18:13:04.0174 5328 partmgr - ok 18:13:04.0284 5328 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys 18:13:04.0299 5328 pci - ok 18:13:04.0346 5328 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys 18:13:04.0346 5328 pciide - ok 18:13:04.0424 5328 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys 18:13:04.0440 5328 pcmcia - ok 18:13:04.0502 5328 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 18:13:04.0502 5328 pcw - ok 18:13:04.0627 5328 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 18:13:04.0627 5328 PEAUTH - ok 18:13:04.0892 5328 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys 18:13:04.0908 5328 PptpMiniport - ok 18:13:04.0970 5328 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys 18:13:04.0970 5328 Processor - ok 18:13:05.0079 5328 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys 18:13:05.0079 5328 Psched - ok 18:13:05.0173 5328 PxHlpa64 (87b04878a6d59d6c79251dc960c674c1) C:\Windows\system32\Drivers\PxHlpa64.sys 18:13:05.0173 5328 PxHlpa64 - ok 18:13:05.0391 5328 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys 18:13:05.0422 5328 ql2300 - ok 18:13:05.0469 5328 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys 18:13:05.0485 5328 ql40xx - ok 18:13:05.0516 5328 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 18:13:05.0516 5328 QWAVEdrv - ok 18:13:05.0594 5328 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 18:13:05.0610 5328 RasAcd - ok 18:13:05.0672 5328 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 18:13:05.0688 5328 RasAgileVpn - ok 18:13:05.0719 5328 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys 18:13:05.0734 5328 Rasl2tp - ok 18:13:05.0781 5328 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 18:13:05.0797 5328 RasPppoe - ok 18:13:05.0828 5328 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 18:13:05.0844 5328 RasSstp - ok 18:13:05.0922 5328 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys 18:13:05.0937 5328 rdbss - ok 18:13:05.0984 5328 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys 18:13:06.0000 5328 rdpbus - ok 18:13:06.0062 5328 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 18:13:06.0062 5328 RDPCDD - ok 18:13:06.0109 5328 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 18:13:06.0109 5328 RDPENCDD - ok 18:13:06.0140 5328 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 18:13:06.0140 5328 RDPREFMP - ok 18:13:06.0187 5328 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys 18:13:06.0202 5328 RDPWD - ok 18:13:06.0280 5328 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys 18:13:06.0296 5328 rdyboost - ok 18:13:06.0405 5328 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 18:13:06.0421 5328 rspndr - ok 18:13:06.0483 5328 RSUSBSTOR (4a25dc970c58104602ed274dacafd784) C:\Windows\system32\Drivers\RtsUStor.sys 18:13:06.0499 5328 RSUSBSTOR - ok 18:13:06.0577 5328 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys 18:13:06.0577 5328 sbp2port - ok 18:13:06.0655 5328 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys 18:13:06.0655 5328 scfilter - ok 18:13:06.0826 5328 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 18:13:06.0826 5328 secdrv - ok 18:13:06.0920 5328 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys 18:13:06.0936 5328 Serenum - ok 18:13:06.0982 5328 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys 18:13:06.0982 5328 Serial - ok 18:13:07.0060 5328 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys 18:13:07.0060 5328 sermouse - ok 18:13:07.0154 5328 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys 18:13:07.0154 5328 sffdisk - ok 18:13:07.0248 5328 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys 18:13:07.0248 5328 sffp_mmc - ok 18:13:07.0310 5328 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys 18:13:07.0310 5328 sffp_sd - ok 18:13:07.0372 5328 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys 18:13:07.0388 5328 sfloppy - ok 18:13:07.0497 5328 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys 18:13:07.0497 5328 SiSRaid2 - ok 18:13:07.0528 5328 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys 18:13:07.0544 5328 SiSRaid4 - ok 18:13:07.0606 5328 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 18:13:07.0606 5328 Smb - ok 18:13:07.0778 5328 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 18:13:07.0778 5328 spldr - ok 18:13:07.0840 5328 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys 18:13:07.0872 5328 srv - ok 18:13:07.0903 5328 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys 18:13:07.0918 5328 srv2 - ok 18:13:08.0043 5328 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys 18:13:08.0059 5328 srvnet - ok 18:13:08.0152 5328 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys 18:13:08.0168 5328 stexstor - ok 18:13:08.0277 5328 STHDA (02e784fa49032f84964db90a3ed81890) C:\Windows\system32\DRIVERS\stwrt64.sys 18:13:08.0293 5328 STHDA - ok 18:13:08.0355 5328 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys 18:13:08.0355 5328 swenum - ok 18:13:08.0433 5328 SynTP (3178b56219e0e4fb5f95299e49b83b44) C:\Windows\system32\DRIVERS\SynTP.sys 18:13:08.0449 5328 SynTP - ok 18:13:08.0636 5328 Tcpip (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\drivers\tcpip.sys 18:13:08.0683 5328 Tcpip - ok 18:13:08.0761 5328 TCPIP6 (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\DRIVERS\tcpip.sys 18:13:08.0776 5328 TCPIP6 - ok 18:13:08.0839 5328 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys 18:13:08.0854 5328 tcpipreg - ok 18:13:08.0932 5328 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 18:13:08.0948 5328 TDPIPE - ok 18:13:08.0964 5328 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys 18:13:08.0979 5328 TDTCP - ok 18:13:09.0042 5328 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys 18:13:09.0057 5328 tdx - ok 18:13:09.0073 5328 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys 18:13:09.0088 5328 TermDD - ok 18:13:09.0213 5328 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys 18:13:09.0213 5328 tssecsrv - ok 18:13:09.0291 5328 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys 18:13:09.0307 5328 tunnel - ok 18:13:09.0354 5328 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys 18:13:09.0354 5328 uagp35 - ok 18:13:09.0385 5328 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys 18:13:09.0400 5328 udfs - ok 18:13:09.0447 5328 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys 18:13:09.0463 5328 uliagpkx - ok 18:13:09.0525 5328 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys 18:13:09.0541 5328 umbus - ok 18:13:09.0572 5328 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys 18:13:09.0588 5328 UmPass - ok 18:13:09.0759 5328 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys 18:13:09.0775 5328 USBAAPL64 - ok 18:13:09.0900 5328 usbccgp (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys 18:13:09.0900 5328 usbccgp - ok 18:13:09.0993 5328 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys 18:13:10.0009 5328 usbcir - ok 18:13:10.0134 5328 usbehci (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys 18:13:10.0134 5328 usbehci - ok 18:13:10.0243 5328 usbhub (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys 18:13:10.0243 5328 usbhub - ok 18:13:10.0274 5328 usbohci (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys 18:13:10.0290 5328 usbohci - ok 18:13:10.0352 5328 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 18:13:10.0368 5328 usbprint - ok 18:13:10.0446 5328 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys 18:13:10.0446 5328 usbscan - ok 18:13:10.0508 5328 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS 18:13:10.0524 5328 USBSTOR - ok 18:13:10.0602 5328 usbuhci (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\DRIVERS\usbuhci.sys 18:13:10.0602 5328 usbuhci - ok 18:13:10.0648 5328 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\System32\Drivers\usbvideo.sys 18:13:10.0664 5328 usbvideo - ok 18:13:10.0726 5328 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys 18:13:10.0742 5328 vdrvroot - ok 18:13:10.0804 5328 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 18:13:10.0804 5328 vga - ok 18:13:10.0836 5328 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 18:13:10.0851 5328 VgaSave - ok 18:13:10.0945 5328 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys 18:13:10.0960 5328 vhdmp - ok 18:13:11.0054 5328 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys 18:13:11.0070 5328 viaide - ok 18:13:11.0116 5328 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys 18:13:11.0116 5328 volmgr - ok 18:13:11.0210 5328 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys 18:13:11.0210 5328 volmgrx - ok 18:13:11.0319 5328 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys 18:13:11.0319 5328 volsnap - ok 18:13:11.0460 5328 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys 18:13:11.0475 5328 vsmraid - ok 18:13:11.0569 5328 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys 18:13:11.0584 5328 vwifibus - ok 18:13:11.0616 5328 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys 18:13:11.0631 5328 vwififlt - ok 18:13:11.0709 5328 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys 18:13:11.0709 5328 WacomPen - ok 18:13:11.0787 5328 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 18:13:11.0803 5328 WANARP - ok 18:13:11.0818 5328 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 18:13:11.0818 5328 Wanarpv6 - ok 18:13:11.0974 5328 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys 18:13:11.0974 5328 Wd - ok 18:13:12.0130 5328 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 18:13:12.0146 5328 Wdf01000 - ok 18:13:12.0240 5328 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 18:13:12.0255 5328 WfpLwf - ok 18:13:12.0318 5328 WimFltr (b14ef15bd757fa488f9c970eee9c0d35) C:\Windows\system32\DRIVERS\wimfltr.sys 18:13:12.0318 5328 WimFltr - ok 18:13:12.0349 5328 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 18:13:12.0364 5328 WIMMount - ok 18:13:12.0505 5328 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys 18:13:12.0520 5328 WinUsb - ok 18:13:12.0614 5328 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys 18:13:12.0614 5328 WmiAcpi - ok 18:13:12.0739 5328 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 18:13:12.0739 5328 ws2ifsl - ok 18:13:12.0786 5328 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys 18:13:12.0801 5328 WudfPf - ok 18:13:12.0895 5328 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys 18:13:12.0910 5328 WUDFRd - ok 18:13:13.0004 5328 yukonw7 (79d9ce9614c955dd31aa2556b4014662) C:\Windows\system32\DRIVERS\yk62x64.sys 18:13:13.0004 5328 yukonw7 - ok 18:13:13.0066 5328 MBR (0x1B8) (cdb4de4bbd714f152979da2dcbef57eb) \Device\Harddisk0\DR0 18:13:13.0098 5328 \Device\Harddisk0\DR0 - ok 18:13:13.0098 5328 Boot (0x1200) (ce1660b4a78827026eab557be1bfe095) \Device\Harddisk0\DR0\Partition0 18:13:13.0113 5328 \Device\Harddisk0\DR0\Partition0 - ok 18:13:13.0129 5328 Boot (0x1200) (3f759e083daa0bfc53855744e15a6d5a) \Device\Harddisk0\DR0\Partition1 18:13:13.0129 5328 \Device\Harddisk0\DR0\Partition1 - ok 18:13:13.0129 5328 ============================================================ 18:13:13.0129 5328 Scan finished 18:13:13.0129 5328 ============================================================ 18:13:13.0144 5248 Detected object count: 0 18:13:13.0144 5248 Actual detected object count: 0
18:12:20.0353 1440 TDSS rootkit removing tool [removed] Dec 13 2011 10:39:31 18:12:20.0634 1440 ============================================================ 18:12:20.0634 1440 Current date / time: 2011/12/17 18:12:20.0634 18:12:20.0634 1440 SystemInfo: 18:12:20.0634 1440 18:12:20.0634 1440 OS Version: 6.1.7600 ServicePack: 0.0 18:12:20.0634 1440 Product type: Workstation 18:12:20.0634 1440 ComputerName: HAYLEY-PC 18:12:20.0634 1440 UserName: admin 18:12:20.0634 1440 Windows directory: C:\Windows 18:12:20.0634 1440 System windows directory: C:\Windows 18:12:20.0634 1440 Running under WOW64 18:12:20.0634 1440 Processor architecture: Intel x64 18:12:20.0634 1440 Number of processors: 2 18:12:20.0634 1440 Page size: 0x1000 18:12:20.0634 1440 Boot type: Normal boot 18:12:20.0634 1440 ============================================================ 18:12:21.0039 1440 Initialize success 18:12:44.0487 5328 ============================================================ 18:12:44.0487 5328 Scan started 18:12:44.0487 5328 Mode: Manual; 18:12:44.0487 5328 ============================================================ 18:12:45.0142 5328 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys 18:12:45.0142 5328 1394ohci - ok 18:12:45.0220 5328 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys 18:12:45.0236 5328 ACPI - ok 18:12:45.0283 5328 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys 18:12:45.0298 5328 AcpiPmi - ok 18:12:45.0376 5328 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys 18:12:45.0376 5328 adp94xx - ok 18:12:45.0517 5328 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys 18:12:45.0517 5328 adpahci - ok 18:12:45.0985 5328 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys 18:12:45.0985 5328 adpu320 - ok 18:12:46.0063 5328 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\Windows\system32\drivers\afd.sys 18:12:46.0063 5328 AFD - ok 18:12:46.0110 5328 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys 18:12:46.0110 5328 agp440 - ok 18:12:46.0188 5328 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys 18:12:46.0203 5328 aliide - ok 18:12:46.0234 5328 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys 18:12:46.0250 5328 amdide - ok 18:12:46.0312 5328 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys 18:12:46.0312 5328 AmdK8 - ok 18:12:46.0344 5328 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys 18:12:46.0344 5328 AmdPPM - ok 18:12:46.0406 5328 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys 18:12:46.0437 5328 amdsata - ok 18:12:46.0515 5328 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys 18:12:46.0515 5328 amdsbs - ok 18:12:46.0578 5328 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys 18:12:46.0593 5328 amdxata - ok 18:12:46.0656 5328 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys 18:12:46.0656 5328 AppID - ok 18:12:46.0827 5328 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys 18:12:46.0827 5328 arc - ok 18:12:46.0858 5328 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys 18:12:46.0858 5328 arcsas - ok 18:12:46.0968 5328 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 18:12:46.0968 5328 AsyncMac - ok 18:12:47.0046 5328 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys 18:12:47.0061 5328 atapi - ok 18:12:47.0358 5328 athr (e0fabc10635c670bd7d89fd214a405d7) C:\Windows\system32\DRIVERS\athrx.sys 18:12:47.0373 5328 athr - ok 18:12:47.0794 5328 AVGIDSDriver (e29ea1a0ec7ab9fa2dc7e75a03f12a4f) C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys 18:12:47.0794 5328 AVGIDSDriver - ok 18:12:47.0872 5328 AVGIDSEH (f823d184b8e8ffb8da3ead45dbf5bd6a) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys 18:12:47.0872 5328 AVGIDSEH - ok 18:12:47.0919 5328 AVGIDSFilter (ed2b25bd7fe35d1944211968842d30da) C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys 18:12:47.0919 5328 AVGIDSFilter - ok 18:12:48.0075 5328 Avgldx64 (979cf8912449a10b987218bff80a1fa3) C:\Windows\system32\DRIVERS\avgldx64.sys 18:12:48.0138 5328 Avgldx64 - ok 18:12:48.0278 5328 Avgmfx64 (36b1a5843695766eac714daffc5b84d1) C:\Windows\system32\DRIVERS\avgmfx64.sys 18:12:48.0278 5328 Avgmfx64 - ok 18:12:48.0434 5328 Avgrkx64 (1102239fb724527f1febbbbccf6bf313) C:\Windows\system32\DRIVERS\avgrkx64.sys 18:12:48.0434 5328 Avgrkx64 - ok 18:12:48.0481 5328 Avgtdia (11f36d3ea82d9db9aa05a476a210551b) C:\Windows\system32\DRIVERS\avgtdia.sys 18:12:48.0496 5328 Avgtdia - ok 18:12:48.0793 5328 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys 18:12:48.0824 5328 b06bdrv - ok 18:12:48.0933 5328 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 18:12:48.0933 5328 b57nd60a - ok 18:12:49.0058 5328 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 18:12:49.0058 5328 Beep - ok 18:12:49.0183 5328 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 18:12:49.0198 5328 blbdrive - ok 18:12:49.0464 5328 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys 18:12:49.0464 5328 bowser - ok 18:12:49.0620 5328 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys 18:12:49.0620 5328 BrFiltLo - ok 18:12:49.0682 5328 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys 18:12:49.0698 5328 BrFiltUp - ok 18:12:49.0822 5328 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 18:12:49.0838 5328 Brserid - ok 18:12:49.0854 5328 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 18:12:49.0869 5328 BrSerWdm - ok 18:12:49.0916 5328 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 18:12:49.0916 5328 BrUsbMdm - ok 18:12:50.0025 5328 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 18:12:50.0041 5328 BrUsbSer - ok 18:12:50.0166 5328 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys 18:12:50.0166 5328 BTHMODEM - ok 18:12:50.0290 5328 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 18:12:50.0290 5328 cdfs - ok 18:12:50.0353 5328 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys 18:12:50.0368 5328 cdrom - ok 18:12:50.0493 5328 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys 18:12:50.0493 5328 circlass - ok 18:12:50.0618 5328 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 18:12:50.0618 5328 CLFS - ok 18:12:50.0883 5328 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 18:12:50.0883 5328 CmBatt - ok 18:12:50.0946 5328 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys 18:12:50.0946 5328 cmdide - ok 18:12:51.0039 5328 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys 18:12:51.0055 5328 CNG - ok 18:12:51.0289 5328 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys 18:12:51.0289 5328 Compbatt - ok 18:12:51.0336 5328 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys 18:12:51.0367 5328 CompositeBus - ok 18:12:51.0414 5328 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys 18:12:51.0429 5328 crcdisk - ok 18:12:51.0523 5328 CtClsFlt (ed5cf92396a62f4c15110dcdb5e854d9) C:\Windows\system32\DRIVERS\CtClsFlt.sys 18:12:51.0523 5328 CtClsFlt - ok 18:12:51.0616 5328 dc3d (db0459afd124ce5ccb649e33f95d715f) C:\Windows\system32\DRIVERS\dc3d.sys 18:12:51.0616 5328 dc3d - ok 18:12:51.0679 5328 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys 18:12:51.0679 5328 DfsC - ok 18:12:51.0710 5328 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 18:12:51.0710 5328 discache - ok 18:12:51.0757 5328 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys 18:12:51.0757 5328 Disk - ok 18:12:51.0866 5328 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 18:12:51.0866 5328 drmkaud - ok 18:12:51.0928 5328 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys 18:12:51.0944 5328 DXGKrnl - ok 18:12:52.0053 5328 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys 18:12:52.0084 5328 ebdrv - ok 18:12:52.0240 5328 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys 18:12:52.0256 5328 elxstor - ok 18:12:52.0272 5328 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys 18:12:52.0272 5328 ErrDev - ok 18:12:52.0334 5328 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 18:12:52.0350 5328 exfat - ok 18:12:52.0412 5328 FACAP (2c1d443e14f376e8331f52f135dca9ef) C:\Windows\system32\DRIVERS\facap.sys 18:12:52.0412 5328 FACAP - ok 18:12:52.0443 5328 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 18:12:52.0443 5328 fastfat - ok 18:12:52.0490 5328 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys 18:12:52.0506 5328 fdc - ok 18:12:52.0615 5328 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 18:12:52.0615 5328 FileInfo - ok 18:12:52.0677 5328 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 18:12:52.0677 5328 Filetrace - ok 18:12:53.0379 5328 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys 18:12:53.0379 5328 flpydisk - ok 18:12:53.0442 5328 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys 18:12:53.0442 5328 FltMgr - ok 18:12:53.0473 5328 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 18:12:53.0488 5328 FsDepends - ok 18:12:53.0535 5328 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 18:12:53.0535 5328 Fs_Rec - ok 18:12:53.0629 5328 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys 18:12:53.0644 5328 fvevol - ok 18:12:53.0769 5328 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys 18:12:53.0769 5328 gagp30kx - ok 18:12:53.0910 5328 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 18:12:53.0910 5328 GEARAspiWDM - ok 18:12:54.0128 5328 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 18:12:54.0128 5328 hcw85cir - ok 18:12:54.0175 5328 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys 18:12:54.0175 5328 HDAudBus - ok 18:12:54.0237 5328 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys 18:12:54.0237 5328 HidBatt - ok 18:12:54.0300 5328 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys 18:12:54.0315 5328 HidBth - ok 18:12:54.0424 5328 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys 18:12:54.0424 5328 HidIr - ok 18:12:54.0502 5328 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys 18:12:54.0518 5328 HidUsb - ok 18:12:54.0705 5328 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys 18:12:54.0721 5328 HpSAMD - ok 18:12:54.0877 5328 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys 18:12:54.0892 5328 HTTP - ok 18:12:55.0111 5328 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys 18:12:55.0111 5328 hwpolicy - ok 18:12:55.0220 5328 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys 18:12:55.0236 5328 i8042prt - ok 18:12:55.0345 5328 iaStor (1d004cb1da6323b1f55caef7f94b61d9) C:\Windows\system32\DRIVERS\iaStor.sys 18:12:55.0345 5328 iaStor - ok 18:12:55.0563 5328 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys 18:12:55.0594 5328 iaStorV - ok 18:12:56.0967 5328 igfx (babd5f9b2bcc82ce556a0baf1ae208a7) C:\Windows\system32\DRIVERS\igdkmd64.sys 18:12:57.0123 5328 igfx - ok 18:12:57.0388 5328 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys 18:12:57.0404 5328 iirsp - ok 18:12:57.0513 5328 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys 18:12:57.0513 5328 intelide - ok 18:12:57.0654 5328 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 18:12:57.0654 5328 intelppm - ok 18:12:57.0700 5328 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys 18:12:57.0700 5328 IpFilterDriver - ok 18:12:57.0732 5328 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys 18:12:57.0747 5328 IPMIDRV - ok 18:12:57.0825 5328 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 18:12:57.0841 5328 IPNAT - ok 18:12:57.0950 5328 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 18:12:57.0966 5328 IRENUM - ok 18:12:57.0997 5328 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys 18:12:58.0012 5328 isapnp - ok 18:12:58.0137 5328 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys 18:12:58.0153 5328 iScsiPrt - ok 18:12:58.0200 5328 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys 18:12:58.0200 5328 kbdclass - ok 18:12:58.0246 5328 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys 18:12:58.0246 5328 kbdhid - ok 18:12:58.0324 5328 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys 18:12:58.0324 5328 KSecDD - ok 18:12:58.0402 5328 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys 18:12:58.0418 5328 KSecPkg - ok 18:12:58.0449 5328 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 18:12:58.0465 5328 ksthunk - ok 18:12:58.0605 5328 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 18:12:58.0605 5328 lltdio - ok 18:12:58.0714 5328 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys 18:12:58.0714 5328 LSI_FC - ok 18:12:58.0839 5328 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys 18:12:58.0839 5328 LSI_SAS - ok 18:12:58.0948 5328 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys 18:12:58.0964 5328 LSI_SAS2 - ok 18:12:59.0058 5328 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys 18:12:59.0073 5328 LSI_SCSI - ok 18:12:59.0167 5328 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 18:12:59.0167 5328 luafv - ok 18:12:59.0229 5328 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys 18:12:59.0229 5328 megasas - ok 18:12:59.0292 5328 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys 18:12:59.0323 5328 MegaSR - ok 18:12:59.0432 5328 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 18:12:59.0448 5328 Modem - ok 18:12:59.0526 5328 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 18:12:59.0526 5328 monitor - ok 18:12:59.0588 5328 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys 18:12:59.0588 5328 mouclass - ok 18:12:59.0666 5328 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 18:12:59.0682 5328 mouhid - ok 18:12:59.0744 5328 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys 18:12:59.0744 5328 mountmgr - ok 18:12:59.0853 5328 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys 18:12:59.0853 5328 mpio - ok 18:12:59.0947 5328 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 18:12:59.0947 5328 mpsdrv - ok 18:13:00.0040 5328 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys 18:13:00.0040 5328 MRxDAV - ok 18:13:00.0165 5328 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys 18:13:00.0181 5328 mrxsmb - ok 18:13:00.0321 5328 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys 18:13:00.0337 5328 mrxsmb10 - ok 18:13:00.0462 5328 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys 18:13:00.0462 5328 mrxsmb20 - ok 18:13:00.0508 5328 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys 18:13:00.0508 5328 msahci - ok 18:13:00.0571 5328 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys 18:13:00.0571 5328 msdsm - ok 18:13:00.0664 5328 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 18:13:00.0664 5328 Msfs - ok 18:13:00.0711 5328 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 18:13:00.0711 5328 mshidkmdf - ok 18:13:00.0774 5328 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys 18:13:00.0774 5328 msisadrv - ok 18:13:00.0820 5328 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 18:13:00.0836 5328 MSKSSRV - ok 18:13:00.0898 5328 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 18:13:00.0898 5328 MSPCLOCK - ok 18:13:00.0961 5328 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 18:13:00.0976 5328 MSPQM - ok 18:13:01.0054 5328 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys 18:13:01.0070 5328 MsRPC - ok 18:13:01.0164 5328 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys 18:13:01.0164 5328 mssmbios - ok 18:13:01.0226 5328 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 18:13:01.0226 5328 MSTEE - ok 18:13:01.0257 5328 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys 18:13:01.0273 5328 MTConfig - ok 18:13:01.0351 5328 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 18:13:01.0366 5328 Mup - ok 18:13:01.0460 5328 MusCAudio (23eb9109de7ae6e181ad3b31e086eeff) C:\Windows\system32\drivers\MusCAudio.sys 18:13:01.0476 5328 MusCAudio - ok 18:13:01.0741 5328 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 18:13:01.0756 5328 NativeWifiP - ok 18:13:01.0928 5328 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys 18:13:01.0944 5328 NDIS - ok 18:13:01.0990 5328 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 18:13:02.0006 5328 NdisCap - ok 18:13:02.0100 5328 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 18:13:02.0100 5328 NdisTapi - ok 18:13:02.0178 5328 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys 18:13:02.0178 5328 Ndisuio - ok 18:13:02.0271 5328 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys 18:13:02.0287 5328 NdisWan - ok 18:13:02.0349 5328 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys 18:13:02.0349 5328 NDProxy - ok 18:13:02.0427 5328 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 18:13:02.0427 5328 NetBIOS - ok 18:13:02.0568 5328 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys 18:13:02.0568 5328 NetBT - ok 18:13:02.0708 5328 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys 18:13:02.0708 5328 nfrd960 - ok 18:13:02.0770 5328 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 18:13:02.0770 5328 Npfs - ok 18:13:02.0802 5328 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 18:13:02.0802 5328 nsiproxy - ok 18:13:03.0238 5328 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys 18:13:03.0254 5328 Ntfs - ok 18:13:03.0582 5328 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 18:13:03.0582 5328 Null - ok 18:13:03.0722 5328 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys 18:13:03.0722 5328 nvraid - ok 18:13:03.0784 5328 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys 18:13:03.0784 5328 nvstor - ok 18:13:03.0816 5328 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys 18:13:03.0831 5328 nv_agp - ok 18:13:03.0972 5328 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys 18:13:03.0987 5328 ohci1394 - ok 18:13:04.0081 5328 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys 18:13:04.0096 5328 Parport - ok 18:13:04.0159 5328 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys 18:13:04.0174 5328 partmgr - ok 18:13:04.0284 5328 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys 18:13:04.0299 5328 pci - ok 18:13:04.0346 5328 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys 18:13:04.0346 5328 pciide - ok 18:13:04.0424 5328 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys 18:13:04.0440 5328 pcmcia - ok 18:13:04.0502 5328 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 18:13:04.0502 5328 pcw - ok 18:13:04.0627 5328 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 18:13:04.0627 5328 PEAUTH - ok 18:13:04.0892 5328 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys 18:13:04.0908 5328 PptpMiniport - ok 18:13:04.0970 5328 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys 18:13:04.0970 5328 Processor - ok 18:13:05.0079 5328 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys 18:13:05.0079 5328 Psched - ok 18:13:05.0173 5328 PxHlpa64 (87b04878a6d59d6c79251dc960c674c1) C:\Windows\system32\Drivers\PxHlpa64.sys 18:13:05.0173 5328 PxHlpa64 - ok 18:13:05.0391 5328 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys 18:13:05.0422 5328 ql2300 - ok 18:13:05.0469 5328 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys 18:13:05.0485 5328 ql40xx - ok 18:13:05.0516 5328 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 18:13:05.0516 5328 QWAVEdrv - ok 18:13:05.0594 5328 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 18:13:05.0610 5328 RasAcd - ok 18:13:05.0672 5328 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 18:13:05.0688 5328 RasAgileVpn - ok 18:13:05.0719 5328 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys 18:13:05.0734 5328 Rasl2tp - ok 18:13:05.0781 5328 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 18:13:05.0797 5328 RasPppoe - ok 18:13:05.0828 5328 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 18:13:05.0844 5328 RasSstp - ok 18:13:05.0922 5328 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys 18:13:05.0937 5328 rdbss - ok 18:13:05.0984 5328 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys 18:13:06.0000 5328 rdpbus - ok 18:13:06.0062 5328 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 18:13:06.0062 5328 RDPCDD - ok 18:13:06.0109 5328 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 18:13:06.0109 5328 RDPENCDD - ok 18:13:06.0140 5328 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 18:13:06.0140 5328 RDPREFMP - ok 18:13:06.0187 5328 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys 18:13:06.0202 5328 RDPWD - ok 18:13:06.0280 5328 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys 18:13:06.0296 5328 rdyboost - ok 18:13:06.0405 5328 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 18:13:06.0421 5328 rspndr - ok 18:13:06.0483 5328 RSUSBSTOR (4a25dc970c58104602ed274dacafd784) C:\Windows\system32\Drivers\RtsUStor.sys 18:13:06.0499 5328 RSUSBSTOR - ok 18:13:06.0577 5328 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys 18:13:06.0577 5328 sbp2port - ok 18:13:06.0655 5328 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys 18:13:06.0655 5328 scfilter - ok 18:13:06.0826 5328 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 18:13:06.0826 5328 secdrv - ok 18:13:06.0920 5328 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys 18:13:06.0936 5328 Serenum - ok 18:13:06.0982 5328 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys 18:13:06.0982 5328 Serial - ok 18:13:07.0060 5328 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys 18:13:07.0060 5328 sermouse - ok 18:13:07.0154 5328 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys 18:13:07.0154 5328 sffdisk - ok 18:13:07.0248 5328 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys 18:13:07.0248 5328 sffp_mmc - ok 18:13:07.0310 5328 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys 18:13:07.0310 5328 sffp_sd - ok 18:13:07.0372 5328 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys 18:13:07.0388 5328 sfloppy - ok 18:13:07.0497 5328 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys 18:13:07.0497 5328 SiSRaid2 - ok 18:13:07.0528 5328 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys 18:13:07.0544 5328 SiSRaid4 - ok 18:13:07.0606 5328 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 18:13:07.0606 5328 Smb - ok 18:13:07.0778 5328 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 18:13:07.0778 5328 spldr - ok 18:13:07.0840 5328 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys 18:13:07.0872 5328 srv - ok 18:13:07.0903 5328 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys 18:13:07.0918 5328 srv2 - ok 18:13:08.0043 5328 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys 18:13:08.0059 5328 srvnet - ok 18:13:08.0152 5328 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys 18:13:08.0168 5328 stexstor - ok 18:13:08.0277 5328 STHDA (02e784fa49032f84964db90a3ed81890) C:\Windows\system32\DRIVERS\stwrt64.sys 18:13:08.0293 5328 STHDA - ok 18:13:08.0355 5328 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys 18:13:08.0355 5328 swenum - ok 18:13:08.0433 5328 SynTP (3178b56219e0e4fb5f95299e49b83b44) C:\Windows\system32\DRIVERS\SynTP.sys 18:13:08.0449 5328 SynTP - ok 18:13:08.0636 5328 Tcpip (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\drivers\tcpip.sys 18:13:08.0683 5328 Tcpip - ok 18:13:08.0761 5328 TCPIP6 (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\DRIVERS\tcpip.sys 18:13:08.0776 5328 TCPIP6 - ok 18:13:08.0839 5328 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys 18:13:08.0854 5328 tcpipreg - ok 18:13:08.0932 5328 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 18:13:08.0948 5328 TDPIPE - ok 18:13:08.0964 5328 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys 18:13:08.0979 5328 TDTCP - ok 18:13:09.0042 5328 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys 18:13:09.0057 5328 tdx - ok 18:13:09.0073 5328 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys 18:13:09.0088 5328 TermDD - ok 18:13:09.0213 5328 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys 18:13:09.0213 5328 tssecsrv - ok 18:13:09.0291 5328 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys 18:13:09.0307 5328 tunnel - ok 18:13:09.0354 5328 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys 18:13:09.0354 5328 uagp35 - ok 18:13:09.0385 5328 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys 18:13:09.0400 5328 udfs - ok 18:13:09.0447 5328 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys 18:13:09.0463 5328 uliagpkx - ok 18:13:09.0525 5328 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys 18:13:09.0541 5328 umbus - ok 18:13:09.0572 5328 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys 18:13:09.0588 5328 UmPass - ok 18:13:09.0759 5328 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys 18:13:09.0775 5328 USBAAPL64 - ok 18:13:09.0900 5328 usbccgp (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys 18:13:09.0900 5328 usbccgp - ok 18:13:09.0993 5328 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys 18:13:10.0009 5328 usbcir - ok 18:13:10.0134 5328 usbehci (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys 18:13:10.0134 5328 usbehci - ok 18:13:10.0243 5328 usbhub (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys 18:13:10.0243 5328 usbhub - ok 18:13:10.0274 5328 usbohci (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys 18:13:10.0290 5328 usbohci - ok 18:13:10.0352 5328 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 18:13:10.0368 5328 usbprint - ok 18:13:10.0446 5328 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys 18:13:10.0446 5328 usbscan - ok 18:13:10.0508 5328 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS 18:13:10.0524 5328 USBSTOR - ok 18:13:10.0602 5328 usbuhci (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\DRIVERS\usbuhci.sys 18:13:10.0602 5328 usbuhci - ok 18:13:10.0648 5328 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\System32\Drivers\usbvideo.sys 18:13:10.0664 5328 usbvideo - ok 18:13:10.0726 5328 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys 18:13:10.0742 5328 vdrvroot - ok 18:13:10.0804 5328 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 18:13:10.0804 5328 vga - ok 18:13:10.0836 5328 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 18:13:10.0851 5328 VgaSave - ok 18:13:10.0945 5328 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys 18:13:10.0960 5328 vhdmp - ok 18:13:11.0054 5328 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys 18:13:11.0070 5328 viaide - ok 18:13:11.0116 5328 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys 18:13:11.0116 5328 volmgr - ok 18:13:11.0210 5328 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys 18:13:11.0210 5328 volmgrx - ok 18:13:11.0319 5328 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys 18:13:11.0319 5328 volsnap - ok 18:13:11.0460 5328 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys 18:13:11.0475 5328 vsmraid - ok 18:13:11.0569 5328 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys 18:13:11.0584 5328 vwifibus - ok 18:13:11.0616 5328 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys 18:13:11.0631 5328 vwififlt - ok 18:13:11.0709 5328 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys 18:13:11.0709 5328 WacomPen - ok 18:13:11.0787 5328 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 18:13:11.0803 5328 WANARP - ok 18:13:11.0818 5328 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 18:13:11.0818 5328 Wanarpv6 - ok 18:13:11.0974 5328 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys 18:13:11.0974 5328 Wd - ok 18:13:12.0130 5328 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 18:13:12.0146 5328 Wdf01000 - ok 18:13:12.0240 5328 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 18:13:12.0255 5328 WfpLwf - ok 18:13:12.0318 5328 WimFltr (b14ef15bd757fa488f9c970eee9c0d35) C:\Windows\system32\DRIVERS\wimfltr.sys 18:13:12.0318 5328 WimFltr - ok 18:13:12.0349 5328 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 18:13:12.0364 5328 WIMMount - ok 18:13:12.0505 5328 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys 18:13:12.0520 5328 WinUsb - ok 18:13:12.0614 5328 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys 18:13:12.0614 5328 WmiAcpi - ok 18:13:12.0739 5328 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 18:13:12.0739 5328 ws2ifsl - ok 18:13:12.0786 5328 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys 18:13:12.0801 5328 WudfPf - ok 18:13:12.0895 5328 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys 18:13:12.0910 5328 WUDFRd - ok 18:13:13.0004 5328 yukonw7 (79d9ce9614c955dd31aa2556b4014662) C:\Windows\system32\DRIVERS\yk62x64.sys 18:13:13.0004 5328 yukonw7 - ok 18:13:13.0066 5328 MBR (0x1B8) (cdb4de4bbd714f152979da2dcbef57eb) \Device\Harddisk0\DR0 18:13:13.0098 5328 \Device\Harddisk0\DR0 - ok 18:13:13.0098 5328 Boot (0x1200) (ce1660b4a78827026eab557be1bfe095) \Device\Harddisk0\DR0\Partition0 18:13:13.0113 5328 \Device\Harddisk0\DR0\Partition0 - ok 18:13:13.0129 5328 Boot (0x1200) (3f759e083daa0bfc53855744e15a6d5a) \Device\Harddisk0\DR0\Partition1 18:13:13.0129 5328 \Device\Harddisk0\DR0\Partition1 - ok 18:13:13.0129 5328 ============================================================ 18:13:13.0129 5328 Scan finished 18:13:13.0129 5328 ============================================================ 18:13:13.0144 5248 Detected object count: 0 18:13:13.0144 5248 Actual detected object count: 0
Hi psycho7244,

Please download and run ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9E 09 2B 37 C9 BA CC 01 [binary data]
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
    [2010/07/15 19:46:44 | 000,083,248 | —- | M] (Pinball Corporation.) – C:\Program Files (x86)\mozilla firefox\plugins\npclntax_HBLiteSA.dll
    O2 - BHO: (Reg Error: Value error.) - {14BCE457-AAA0-41EC-99FA-820494957F4b} - C:\Users\Hayley\AppData\Local\SecurityWMP.dll (CyberLink)
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4 - HKLM..\Run: [FAStartup] File not found
    O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
    O18:64bit: - Protocol\Handler\livecall - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
    O18:64bit: - Protocol\Handler\msnim - No CLSID value found
    O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
    O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
    O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
    O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    [2011/12/14 19:24:23 | 000,012,478 | -HS- | M] () – C:\ProgramData\8eg5f05xlw3y02nepkh1213el776ogl54f8m
    [2011/12/09 19:27:24 | 000,013,882 | -HS- | M] () – C:\ProgramData\nlxrgy8n4nqv0odc4cjr8n562o1a
    [2011/11/30 23:11:32 | 000,000,440 | -H– | M] () – C:\ProgramData\m4LGK7u3ufqUX2
    [2011/11/30 23:09:04 | 000,000,312 | -H– | M] () – C:\ProgramData\~m4LGK7u3ufqUX2
    [2011/11/30 23:09:04 | 000,000,216 | -H– | M] () – C:\ProgramData\~m4LGK7u3ufqUX2r
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [emptyjava]
    [emptyflash]
    [resethosts]
    [clearallrestorepoints]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
OTL logfile created on: 12/18/2011 7:15:59 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\admin\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.96 Gb Total Physical Memory | 2.41 Gb Available Physical Memory | 60.90% Memory free
7.92 Gb Paging File | 6.32 Gb Available in Paging File | 79.81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 218.20 Gb Total Space | 122.39 Gb Free Space | 56.09% Space Free | Partition Type: NTFS

Computer Name: HAYLEY-PC | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe ()
PRC - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
PRC - C:\Users\admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks)
PRC - C:\Program Files (x86)\Dell V305\dldtmon.exe ()
PRC - C:\Program Files (x86)\Dell V305\dldtmsdmon.exe ()
PRC - C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe (Sensible Vision )
PRC - C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe (Sensible Vision )
PRC - c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe (Sensible Vision )
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files (x86)\AVG Secure Search\9.0.0.21\AVG Secure Search_toolbar.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\cc6713be0e405d5a89a2783103f7e771\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\7fb80e48899821b64471f8e7ac2d08b7\System.Web.Services.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d76221993c2fdfb991b8c12ae50a30eb\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e245eb9c1067cabd5673fe832d28613\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\275680f2b9db0501d53c50ea7d7a43f0\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e9ebeb7959f1c916ebf6fca8f7077d6c\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\95b9866ab6e4437ef5dc5855ebab4e33\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\1b31ced9bb880d94fff1c6d47c16a81e\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\SdbShared.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\SdbShared.XmlSerializers.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\SdbUI.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\CppUtils.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\BalloonWindow.dll ()
MOD - C:\Program Files (x86)\Dell V305\dldtmon.exe ()
MOD - C:\Program Files (x86)\Dell V305\dldtmsdmon.exe ()
MOD - C:\Program Files (x86)\Dell V305\dldtdrs.dll ()
MOD - C:\Program Files (x86)\Dell V305\dldtscw.dll ()
MOD - C:\Windows\SysWOW64\FAIEExtension.dll ()
MOD - C:\Windows\SysWOW64\FAib.dll ()
MOD - C:\Windows\SysWOW64\FACrashRpt.dll ()
MOD - C:\Program Files (x86)\Dell V305\dldtcaps.dll ()
MOD - C:\Program Files (x86)\Dell V305\dldtmonr.dll ()
MOD - C:\Program Files (x86)\Dell V305\app4r.monitor.core.dll ()
MOD - C:\Program Files (x86)\Dell V305\app4r.monitor.common.dll ()
MOD - C:\Program Files (x86)\Dell V305\app4r.devmons.mcmdevmon.dll ()
MOD - C:\Program Files (x86)\Dell V305\DLDTcfg.dll ()
MOD - C:\Program Files (x86)\Dell V305\app4r.devmons.mcmdevmon.autoplayutil.dll ()
MOD - C:\Program Files (x86)\Dell V305\dldtcnv4.dll ()
MOD - C:\Program Files (x86)\Dell V305\dldtdatr.dll ()
MOD - C:\Program Files (x86)\Dell V305\dldtcats.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (dldt_device) – C:\Windows\SysNative\dldtcoms.exe ( )
SRV:64bit: - (dldtCATSCustConnectService) – C:\Windows\SysNative\spool\DRIVERS\x64\3\\dldtserv.exe ()
SRV:64bit: - (STacSV) – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (vToolbarUpdater) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe ()
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Sound Blaster X-Fi MB Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\XMBLicensing.exe (Creative Labs)
SRV - (SftService) – C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.exe (SoftThinks)
SRV - (dldt_device) – C:\Windows\SysWow64\dldtcoms.exe ( )
SRV - (FAService) – c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe (Sensible Vision )
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSEH) – C:\Windows\SysNative\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (MusCAudio) – C:\Windows\SysNative\drivers\MusCAudio.sys (Windows ® Codename Longhorn DDK provider)
DRV:64bit: - (dc3d) MS Hardware Device Detection Driver (HID) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (CtClsFlt) – C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (FACAP) – C:\Windows\SysNative\drivers\facap.sys (Sensible Vision )
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.647: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.647: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/12/09 19:40:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2011/12/16 06:08:03 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\9.0.0.21\ [2011/12/16 06:08:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/12/16 21:43:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/12/18 06:59:45 | 000,000,000 | —D | M]

[2011/12/16 21:47:28 | 000,000,000 | —D | M] (No name found) – C:\Users\admin\AppData\Roaming\Mozilla\Extensions
[2011/12/16 21:43:15 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/11/20 23:04:51 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/12/16 06:07:52 | 000,003,747 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2011/11/20 20:04:05 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/11/20 20:04:05 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2011/12/18 07:00:52 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\9.0.0.21\AVG Secure Search_toolbar.dll ()
O2 - BHO: (FAIESSOHelper Class) - {A2F122DA-055F-4df7-8F24-7354DBDBA85B} - c:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll (Sensible Vision )
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\9.0.0.21\AVG Secure Search_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O4:64bit: - HKLM..\Run: [dldtamon] C:\Program Files (x86)\Dell V305\dldtamon.exe ()
O4:64bit: - HKLM..\Run: [dldtmon.exe] C:\Program Files (x86)\Dell V305\dldtmon.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [RunDLLEntry] C:\Windows\SysNative\AmbRunE.DLL (Creative Technology Ltd.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [FAStartup] File not found
O4 - HKLM..\Run: [FATrayAlert] c:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe (Sensible Vision )
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F30ADFB9-5A10-4B5D-AF7E-DABA6696136A}: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F86D2C0C-D1B9-41CF-8C2A-B6D47D6A4E89}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\9.0.1\ViProtocol.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\FastAccess: DllName - (c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll) - c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll ()
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/12/18 06:59:44 | 000,000,000 | —D | C] – C:\_OTL
[2011/12/18 06:54:43 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/12/18 06:54:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2011/12/18 06:54:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\ERUNT
[2011/12/17 18:11:48 | 001,577,264 | —- | C] (Kaspersky Lab ZAO) – C:\Users\admin\Desktop\TDSSKiller.exe
[2011/12/17 18:11:12 | 000,000,000 | —D | C] – C:\Users\admin\Desktop\tdsskiller
[2011/12/16 15:45:09 | 001,916,416 | —- | C] (AVAST Software) – C:\Users\admin\Desktop\aswMBR.exe
[2011/12/16 06:17:12 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\AVG2012
[2011/12/16 06:08:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2012
[2011/12/16 06:07:54 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2011/12/16 06:07:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVG Secure Search
[2011/12/16 06:07:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG Secure Search
[2011/12/16 06:06:25 | 000,000,000 | —D | C] – C:\ProgramData\AVG2012
[2011/12/16 05:44:39 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2011/12/16 05:44:28 | 000,000,000 | —D | C] – C:\ProgramData\Temp
[2011/12/15 17:05:01 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2011/12/15 17:04:54 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/12/15 17:04:53 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/12/15 17:04:53 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/12/15 17:04:53 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/12/15 17:04:53 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/12/15 17:04:53 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/12/15 17:04:53 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/12/15 17:04:53 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/12/15 17:04:53 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/12/15 17:04:52 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/12/15 17:04:52 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/12/15 17:04:52 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/12/15 17:04:52 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/12/15 17:04:52 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/12/15 17:04:52 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/12/15 17:04:43 | 000,723,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/12/15 17:04:43 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/12/15 17:02:56 | 000,000,000 | —D | C] – C:\Users\admin\Desktop\ED_CLEANUP
[2011/12/15 17:02:29 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\admin\Desktop\OTL.exe
[2011/12/14 20:51:27 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Mozilla
[2011/12/14 20:51:27 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\Mozilla
[2011/12/14 20:46:57 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Dell
[2011/12/14 20:46:42 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\DataSafeOnline
[2011/12/14 20:31:11 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Macromedia
[2011/12/14 20:31:09 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Adobe
[2011/12/14 20:28:28 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\Stardock_Corporation
[2011/12/14 20:28:22 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Malwarebytes
[2011/12/14 20:27:34 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Apple Computer
[2011/12/14 20:27:34 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\Apple Computer
[2011/12/14 20:27:32 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Real
[2011/12/14 20:27:26 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\SupportSoft
[2011/12/14 20:26:56 | 000,000,000 | R–D | C] – C:\Users\admin\Searches
[2011/12/14 20:26:56 | 000,000,000 | R–D | C] – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/12/14 20:26:56 | 000,000,000 | -H-D | C] – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/12/14 20:26:46 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Identities
[2011/12/14 20:26:43 | 000,000,000 | R–D | C] – C:\Users\admin\Contacts
[2011/12/14 20:26:42 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\VirtualStore
[2011/12/14 20:25:21 | 000,000,000 | -HSD | C] – C:\Users\admin\AppData\Local\Temporary Internet Files
[2011/12/14 20:25:21 | 000,000,000 | -HSD | C] – C:\Users\admin\Templates
[2011/12/14 20:25:21 | 000,000,000 | -HSD | C] – C:\Users\admin\Start Menu
[2011/12/14 20:25:21 | 000,000,000 | -HSD | C] – C:\Users\admin\SendTo
[2011/12/14 20:25:21 | 000,000,000 | -HSD | C] – C:\Users\admin\Recent
[2011/12/14 20:25:21 | 000,000,000 | -HSD | C] – C:\Users\admin\PrintHood
[2011/12/14 20:25:21 | 000,000,000 | -HSD | C] – C:\Users\admin\Local Settings
[2011/12/14 20:25:21 | 000,000,000 | -HSD | C] – C:\Users\admin\AppData\Local\History
[2011/12/14 20:25:21 | 000,000,000 | -HSD | C] – C:\Users\admin\AppData\Local\Application Data
[2011/12/14 20:25:20 | 000,000,000 | -HSD | C] – C:\Users\admin\NetHood
[2011/12/14 20:25:20 | 000,000,000 | -HSD | C] – C:\Users\admin\Documents\My Videos
[2011/12/14 20:25:20 | 000,000,000 | -HSD | C] – C:\Users\admin\Documents\My Pictures
[2011/12/14 20:25:20 | 000,000,000 | -HSD | C] – C:\Users\admin\Documents\My Music
[2011/12/14 20:25:20 | 000,000,000 | -HSD | C] – C:\Users\admin\My Documents
[2011/12/14 20:25:20 | 000,000,000 | -HSD | C] – C:\Users\admin\Cookies
[2011/12/14 20:25:20 | 000,000,000 | -HSD | C] – C:\Users\admin\Application Data
[2011/12/14 20:25:14 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\Temp
[2011/12/14 20:25:14 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\SoftThinks
[2011/12/14 20:25:14 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\Microsoft Help
[2011/12/14 20:25:14 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Local\Microsoft
[2011/12/14 20:25:14 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\Media Center Programs
[2011/12/14 20:25:12 | 000,000,000 | –SD | C] – C:\Users\admin\AppData\Roaming\Microsoft
[2011/12/14 20:25:12 | 000,000,000 | R–D | C] – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/12/14 20:25:12 | 000,000,000 | R–D | C] – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/12/14 20:25:12 | 000,000,000 | R–D | C] – C:\Users\admin\Desktop
[2011/12/14 20:25:12 | 000,000,000 | R–D | C] – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/12/14 20:25:12 | 000,000,000 | -H-D | C] – C:\Users\admin\AppData
[2011/12/14 20:25:11 | 000,000,000 | R–D | C] – C:\Users\admin\Videos
[2011/12/14 20:25:11 | 000,000,000 | R–D | C] – C:\Users\admin\Saved Games
[2011/12/14 20:25:11 | 000,000,000 | R–D | C] – C:\Users\admin\Pictures
[2011/12/14 20:25:11 | 000,000,000 | R–D | C] – C:\Users\admin\Music
[2011/12/14 20:25:11 | 000,000,000 | R–D | C] – C:\Users\admin\Links
[2011/12/14 20:25:11 | 000,000,000 | R–D | C] – C:\Users\admin\Favorites
[2011/12/14 20:25:11 | 000,000,000 | R–D | C] – C:\Users\admin\Downloads
[2011/12/14 20:25:11 | 000,000,000 | R–D | C] – C:\Users\admin\Documents
[2010/01/23 18:48:33 | 000,364,544 | —- | C] ( ) – C:\Windows\SysWow64\dldtinpa.dll
[2010/01/23 18:48:33 | 000,339,968 | —- | C] ( ) – C:\Windows\SysWow64\dldtiesc.dll
[2010/01/23 18:48:32 | 000,647,168 | —- | C] ( ) – C:\Windows\SysWow64\dldtpmui.dll
[2010/01/23 18:48:29 | 001,105,920 | —- | C] ( ) – C:\Windows\SysWow64\dldtserv.dll
[2010/01/23 18:48:29 | 000,843,776 | —- | C] ( ) – C:\Windows\SysWow64\dldtusb1.dll
[2010/01/23 18:48:28 | 000,569,344 | —- | C] ( ) – C:\Windows\SysWow64\dldtlmpm.dll
[2010/01/23 18:48:28 | 000,053,248 | —- | C] ( ) – C:\Windows\SysWow64\dldtprox.dll
[2010/01/23 18:48:27 | 000,663,552 | —- | C] ( ) – C:\Windows\SysWow64\dldthbn3.dll
[2010/01/23 18:48:27 | 000,320,168 | —- | C] ( ) – C:\Windows\SysWow64\dldtih.exe
[2010/01/23 18:48:26 | 000,594,600 | —- | C] ( ) – C:\Windows\SysWow64\dldtcoms.exe
[2010/01/23 18:48:25 | 000,851,968 | —- | C] ( ) – C:\Windows\SysWow64\dldtcomc.dll
[2010/01/23 18:48:25 | 000,376,832 | —- | C] ( ) – C:\Windows\SysWow64\dldtcomm.dll
[2010/01/23 18:48:25 | 000,365,224 | —- | C] ( ) – C:\Windows\SysWow64\dldtcfg.exe

========== Files - Modified Within 30 Days ==========

[2011/12/18 07:19:51 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/18 07:19:51 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/18 07:12:36 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/18 07:11:42 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/18 07:11:38 | 3190,050,816 | -HS- | M] () – C:\hiberfil.sys
[2011/12/18 07:00:52 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\Hosts
[2011/12/18 06:55:10 | 084,521,634 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2011/12/18 06:54:39 | 000,033,852 | —- | M] () – C:\Windows\SysNative\drivers\Avg\iavichjg.avm
[2011/12/18 06:54:16 | 000,000,886 | —- | M] () – C:\Users\admin\Desktop\NTREGOPT.lnk
[2011/12/18 06:54:16 | 000,000,867 | —- | M] () – C:\Users\admin\Desktop\ERUNT.lnk
[2011/12/18 06:51:46 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/17 18:11:12 | 001,577,264 | —- | M] (Kaspersky Lab ZAO) – C:\Users\admin\Desktop\TDSSKiller.exe
[2011/12/17 15:00:43 | 000,080,384 | —- | M] () – C:\Users\admin\Desktop\MBRCheck.exe
[2011/12/17 14:30:15 | 341,441,471 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/12/16 21:43:18 | 000,001,100 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/12/16 15:45:14 | 001,916,416 | —- | M] (AVAST Software) – C:\Users\admin\Desktop\aswMBR.exe
[2011/12/16 06:08:03 | 000,000,927 | —- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2011/12/16 06:07:38 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\avg\incavi.avm
[2011/12/16 06:07:38 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\avg\iavichjw.avm
[2011/12/16 03:24:33 | 000,426,256 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/16 03:06:37 | 000,000,118 | —- | M] () – C:\Windows\SysNative\MRT.INI
[2011/12/15 17:02:29 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\admin\Desktop\OTL.exe
[2011/12/14 20:44:59 | 000,001,399 | —- | M] () – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/14 20:28:33 | 000,001,980 | —- | M] () – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
[2011/12/14 20:04:02 | 000,624,178 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/12/14 20:04:02 | 000,106,522 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/12/14 20:04:01 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/12/01 22:13:30 | 000,002,515 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk

========== Files Created - No Company Name ==========

[2011/12/18 06:54:16 | 000,000,886 | —- | C] () – C:\Users\admin\Desktop\NTREGOPT.lnk
[2011/12/18 06:54:16 | 000,000,867 | —- | C] () – C:\Users\admin\Desktop\ERUNT.lnk
[2011/12/17 15:00:43 | 000,080,384 | —- | C] () – C:\Users\admin\Desktop\MBRCheck.exe
[2011/12/16 21:43:18 | 000,001,112 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/12/16 06:08:03 | 000,000,927 | —- | C] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2011/12/14 20:44:52 | 000,001,405 | —- | C] () – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/12/14 20:30:59 | 000,001,399 | —- | C] () – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/14 20:28:33 | 000,001,980 | —- | C] () – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
[2011/12/14 20:27:11 | 000,001,411 | —- | C] () – C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011/12/14 20:25:17 | 000,000,290 | —- | C] () – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/12/14 20:25:17 | 000,000,272 | —- | C] () – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/12/14 20:25:15 | 000,001,802 | —- | C] () – C:\Users\admin\Desktop\Free year of music from Dell.lnk
[2011/12/01 22:13:30 | 000,002,515 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2011/11/11 00:31:41 | 000,118,784 | —- | C] () – C:\Windows\SysWow64\srrstr.dll
[2010/03/24 18:03:46 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/01/23 18:48:34 | 000,348,160 | —- | C] () – C:\Windows\SysWow64\DLDTinst.dll
[2010/01/23 18:48:34 | 000,335,872 | —- | C] () – C:\Windows\SysWow64\dldtcomx.dll
[2010/01/23 18:48:33 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\dldtjswr.dll
[2010/01/23 18:48:33 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\dldtinsr.dll
[2010/01/23 18:48:33 | 000,036,864 | —- | C] () – C:\Windows\SysWow64\dldtcur.dll
[2010/01/23 18:48:32 | 000,532,480 | —- | C] () – C:\Windows\SysWow64\dldtutil.dll
[2010/01/23 18:48:31 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\dldtinsb.dll
[2010/01/23 18:48:31 | 000,176,128 | —- | C] () – C:\Windows\SysWow64\dldtins.dll
[2010/01/23 18:48:30 | 000,086,016 | —- | C] () – C:\Windows\SysWow64\dldtcub.dll
[2010/01/23 18:48:30 | 000,077,824 | —- | C] () – C:\Windows\SysWow64\dldtcu.dll
[2009/12/25 21:33:23 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/12/05 23:47:20 | 000,982,220 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2009/12/05 23:47:19 | 000,134,592 | —- | C] () – C:\Windows\SysWow64\igfcg500.bin
[2009/12/05 23:47:19 | 000,092,216 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2009/12/05 23:47:18 | 000,433,024 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2009/07/15 12:45:34 | 000,782,336 | —- | C] () – C:\Windows\SysWow64\dldtdrs.dll
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/24 17:32:34 | 000,089,352 | —- | C] () – C:\Windows\SysWow64\FAIEExtension.dll
[2009/06/24 17:31:46 | 000,059,144 | —- | C] () – C:\Windows\SysWow64\FAib.dll
[2009/06/24 17:31:00 | 000,234,760 | —- | C] () – C:\Windows\SysWow64\FACrashRpt.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2009/05/14 13:57:38 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\dldtcaps.dll
[2008/01/22 02:05:12 | 000,077,906 | —- | C] () – C:\Windows\SysWow64\dldtcfg.dll
[2007/11/13 19:13:10 | 000,069,632 | —- | C] () – C:\Windows\SysWow64\dldtcnv4.dll

< End of report >
Hi,

When you ran the OTL fix there should have been another log created showing what was fixed. Do you have that still? If so please post that.
—————

I see that you have Malwarebytes on your system. Please open Malwarebytes, update it and then run a Quick Scan. Please save the log that is created for your next reply.
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



As a Vista/Win7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
  • Do not use this instance of your browser for anything besides doing this scan
  • When the scan is complete and the results saved, close that instance of your browser
  • Open a new one the usual way and post the results in this topic.


  • Right-click and Run as Administartor on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/
———-

In your next reply please post the OTL fix log (if you have it) and the logs made by Malwarebytes and ESET online scanner. :)
All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=\ deleted successfully.
C:\Program Files (x86)\Mozilla Firefox\plugins\npclntax_HBLiteSA.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{14BCE457-AAA0-41EC-99FA-820494957F4b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{14BCE457-AAA0-41EC-99FA-820494957F4b}\ not found.
File C:\Users\Hayley\AppData\Local\SecurityWMP.dll not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\FAStartup deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\grooveLocalGWS\ deleted successfully.
File Protocol\Handler\grooveLocalGWS - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
File Protocol\Handler\livecall - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
File Protocol\Handler\ms-help - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-itss\ deleted successfully.
File Protocol\Handler\ms-itss - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
File Protocol\Handler\msnim - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype4com\ deleted successfully.
File Protocol\Handler\skype4com - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype-ie-addon-data\ deleted successfully.
File Protocol\Handler\skype-ie-addon-data - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully.
File Protocol\Handler\wlmailhtml - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.
File Protocol\Handler\wlpg - No CLSID value found not found.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
C:\ProgramData\8eg5f05xlw3y02nepkh1213el776ogl54f8m moved successfully.
C:\ProgramData\nlxrgy8n4nqv0odc4cjr8n562o1a moved successfully.
C:\ProgramData\m4LGK7u3ufqUX2 moved successfully.
C:\ProgramData\~m4LGK7u3ufqUX2 moved successfully.
C:\ProgramData\~m4LGK7u3ufqUX2r moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\admin\Desktop\cmd.bat deleted successfully.
C:\Users\admin\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYJAVA]

User: admin
->Java cache emptied: 0 bytes

User: All Users

User: Default

User: Default User

User: Hayley
->Java cache emptied: 136722291 bytes

User: Public

Total Java Files Cleaned = 130.00 mb


[EMPTYFLASH]

User: admin
->Flash cache emptied: 405 bytes

User: All Users

User: Default

User: Default User

User: Hayley
->Flash cache emptied: 337055 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb

C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Restore point Set: OTL Restore Point

[EMPTYTEMP]

User: admin
->Temp folder emptied: 71959493 bytes
->Temporary Internet Files folder emptied: 55545683 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 7110507 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Hayley
->Temp folder emptied: 1766962779 bytes
->Temporary Internet Files folder emptied: 501625053 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 636611449 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 211716665 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50400 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 3,101.00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 12182011_065944

Files\Folders moved on Reboot…
C:\Users\admin\AppData\Local\Temp\Low\~DFF719F11584171E57.TMP moved successfully.
C:\Users\admin\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Users\admin\AppData\Local\Temp\~DF234CEF6E5EAC35D3.TMP not found!
File\Folder C:\Users\admin\AppData\Local\Temp\~DF55BBDD25E66991C9.TMP not found!
File\Folder C:\Users\admin\AppData\Local\Temp\~DF815002452A1E6181.TMP not found!
File\Folder C:\Users\admin\AppData\Local\Temp\~DFCD4EF784DCA22C14.TMP not found!
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\W6B30N6R\iframe[1].htm moved successfully.
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\Q4OEVP2J\index[2].php moved successfully.
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.

Registry entries deleted on Reboot…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI