This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

virus removal [Solved]

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello:

My computer was infected with the VISTA 2011 virus some weeks ago. I cleaned it up using Malwarebytes and Superantispyware but want to make sure everything is gone.

I ran OTL two times. I did not realize the first time that the instructions said to run as administrator. I do not see the Extras.txt file of my second run so I am submitting the first run of Extras and second run of OTL.txt.

OTL logfile created on: 12/30/2011 12:49:03 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Nando\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19170)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.94 Gb Total Physical Memory | 1.95 Gb Available Physical Memory | 49.65% Memory free
8.05 Gb Paging File | 5.80 Gb Available in Paging File | 72.09% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.14 Gb Total Space | 163.81 Gb Free Space | 57.45% Space Free | Partition Type: NTFS
Drive D: | 12.95 Gb Total Space | 2.43 Gb Free Space | 18.76% Space Free | Partition Type: NTFS

Computer Name: NANDO-LAPTOP | User Name: Nando | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Nando\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe ()
PRC - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
PRC - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Users\Nando\Desktop\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Users\Nando\Desktop\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
PRC - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Shop To Win\ShopToWin.exe (Jackpot Rewards)
PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Comsift\Comsift Service\Comsiftservice.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\AVG Secure Search\9.0.0.23\AVG Secure Search_toolbar.dll ()
MOD - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-52.dll ()
MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-52.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-50.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\CLTinyDB.dll ()
MOD - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\CLCapEngine.dll ()
MOD - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\CLSchMgr.dll ()
MOD - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\CLCapSvcps.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (XAudioService) – C:\Windows\SysNative\DRIVERS\xaudio64.exe (Conexant Systems, Inc.)
SRV - (vToolbarUpdater) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe ()
SRV - (MBAMService) – C:\Users\Nando\Desktop\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (PCToolsSSDMonitorSvc) – C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (PMBDeviceInfoProvider) – C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (LiveUpdate) – c:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (Com4Qlb) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
SRV - (Comsift Service) – C:\Program Files (x86)\Comsift\Comsift Service\Comsiftservice.exe ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\DRIVERS\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\DRIVERS\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\DRIVERS\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\DRIVERS\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\DRIVERS\AVGIDSFilter.Sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSEH) – C:\Windows\SysNative\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\DRIVERS\AVGIDSDriver.Sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HSFHWAZL) – C:\Windows\SysNative\DRIVERS\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\DRIVERS\bcmwl664.sys (Broadcom Corp.)
DRV:64bit: - (BCM43XV) – C:\Windows\SysNative\DRIVERS\bcmwl664.sys (Broadcom Corp.)
DRV:64bit: - (HdAudAddService) – C:\Windows\SysNative\drivers\CHDART64.sys (Conexant Systems Inc.)
DRV:64bit: - (rimmptsk) – C:\Windows\SysNative\DRIVERS\rimmpx64.sys (REDC)
DRV:64bit: - (rismxdp) – C:\Windows\SysNative\DRIVERS\rixdpx64.sys (REDC)
DRV:64bit: - (rimsptsk) – C:\Windows\SysNative\DRIVERS\rimspx64.sys (REDC)
DRV:64bit: - (HpqRemHid) – C:\Windows\SysNative\DRIVERS\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (XAudio) – C:\Windows\SysNative\DRIVERS\xaudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (ApfiltrService) – C:\Windows\SysNative\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV:64bit: - (HSF_DPV) – C:\Windows\SysNative\DRIVERS\CAX_DPV.sys (Conexant Systems, Inc.)
DRV:64bit: - (CAXHWAZL) – C:\Windows\SysNative\DRIVERS\CAXHWAZL.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\DRIVERS\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (HpqKbFiltr) – C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (BrSerIf) – C:\Windows\SysNative\DRIVERS\BrSerIf.sys (Brother Industries Ltd.)
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\DRIVERS\mdmxsdk.sys (Conexant)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Musicnotes.com/Musicnotes Viewer,version=1.18.4: C:\Program Files\Musicnotes\npmusicn64.dll (Musicnotes, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Musicnotes.com/Musicnotes Viewer,version=1.18.4: C:\Program Files (x86)\Musicnotes\npmusicn.dll (Musicnotes, Inc.)
FF - HKLM\Software\MozillaPlugins\@Sibelius.com/Scorch Plugin,version=6.1.5.22: C:\Program Files (x86)\Musicnotes\npsibelius.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/03/07 16:14:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2011/12/28 22:52:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\9.0.0.23\ [2011/12/28 22:52:30 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/03/07 16:14:31 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Java Deployment Toolkit 7.0.0.147 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 7 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Musicnotes (Enabled) = C:\Program Files (x86)\Musicnotes\npmusicn.dll
CHR - plugin: ScorchPlugin (Enabled) = C:\Program Files (x86)\Musicnotes\npsibelius.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg64.dll (Google Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Shop to Win) - {3A90A078-4BB9-4568-9557-CDEEFCAE68A0} - C:\Program Files (x86)\Shop to Win 22\Shop to Win 22.dll (Shop To Win, LLC)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Fast Search) - {5AB7104A-B71F-49AD-9154-F7F8806AE848} - C:\Program Files (x86)\Surf Canyon\surfcanyon.dll (Surf Canyon Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\9.0.0.23\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\9.0.0.23\AVG Secure Search_toolbar.dll ()
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe File not found
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [NvSvc] C:\Windows\SysNative\nvsvc64.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Users\Nando\Desktop\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [SSDMonitor] C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKCU..\Run: [Shop To Win] C:\Program Files (x86)\Shop To Win\ShopToWin.exe (Jackpot Rewards)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.1.0)
O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{782025A6-9DD6-47D2-A122-2AB87DD5D2B7}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A6222EA1-2033-413C-B5E7-C27F1E5CD06E}: DhcpNameServer = 172.16.2.5 172.18.82.11 4.2.2.2
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\9.0.1\ViProtocol.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\SYSWOW64\Userinit.exe) -C:\WINDOWS\SysWOW64\userinit.exe (Microsoft Corporation)
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\HPOrganicDk.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/11/19 15:48:18 | 000,000,047 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2005/09/11 10:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O33 - MountPoints2\{4874b439-ca97-11df-afee-001d725ed412}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL http://www.garmin.com/agent
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\WINDOWS\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/30 12:20:53 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Nando\Desktop\OTL.exe
[2011/12/28 23:07:02 | 000,000,000 | —D | C] – C:\Users\Nando\AppData\Roaming\AVG2012
[2011/12/28 22:52:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2012
[2011/12/28 22:52:16 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2011/12/28 22:52:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVG Secure Search
[2011/12/28 22:52:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG Secure Search
[2011/12/28 22:52:08 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2011/12/28 22:51:28 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\AVG
[2011/12/28 22:50:43 | 000,000,000 | —D | C] – C:\ProgramData\AVG2012
[2011/12/28 22:50:43 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\AVG
[2011/12/28 22:49:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG
[2011/12/28 22:44:47 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2011/12/20 21:59:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Steam
[2011/12/20 21:59:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2011/12/20 21:59:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Steam
[2011/12/20 21:20:40 | 000,000,000 | —D | C] – C:\Users\Nando\Documents\ShopToWin
[2011/12/20 21:20:15 | 000,000,000 | —D | C] – C:\Users\Nando\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Shop to Win 22
[2011/12/20 21:19:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Shop to Win 22
[2011/12/20 21:19:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Shop To Win
[2011/12/18 16:29:27 | 001,653,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2011/12/18 16:29:27 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2011/12/18 11:25:00 | 000,000,000 | —D | C] – C:\Windows\SysWow64\spool
[2011/12/18 11:24:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Portable Devices
[2011/12/18 11:24:58 | 000,000,000 | —D | C] – C:\Program Files\Windows Portable Devices
[2011/12/18 11:20:32 | 000,449,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2011/12/18 11:20:32 | 000,369,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2011/12/18 11:20:29 | 001,209,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2011/12/18 11:20:29 | 000,411,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PhotoMetadataHandler.dll
[2011/12/18 11:20:29 | 000,262,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxdiagn.dll
[2011/12/18 11:20:29 | 000,245,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2011/12/18 11:20:29 | 000,195,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dxdiagn.dll
[2011/12/18 11:20:28 | 000,792,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2011/12/18 11:20:28 | 000,519,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2011/12/18 11:20:28 | 000,328,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxdiag.exe
[2011/12/18 11:20:28 | 000,321,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PhotoMetadataHandler.dll
[2011/12/18 11:20:28 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dxdiag.exe
[2011/12/18 11:19:19 | 000,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WPDShextAutoplay.exe
[2011/12/18 11:19:19 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WPDShextAutoplay.exe
[2011/12/18 11:19:18 | 000,037,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\BthMtpContextHandler.dll
[2011/12/18 11:19:14 | 002,727,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wpdshext.dll
[2011/12/18 11:19:14 | 000,573,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wpd_ci.dll
[2011/12/18 11:19:14 | 000,295,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WpdMtp.dll
[2011/12/18 11:19:14 | 000,110,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WPDShServiceObj.dll
[2011/12/18 11:19:14 | 000,077,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PortableDeviceConnectApi.dll
[2011/12/18 11:19:14 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WpdMtpUS.dll
[2011/12/18 11:19:14 | 000,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PortableDeviceConnectApi.dll
[2011/12/18 11:19:14 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WpdUsb.sys
[2011/12/18 11:19:14 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WpdConns.dll
[2011/12/18 11:19:13 | 000,453,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PortableDeviceApi.dll
[2011/12/18 11:19:13 | 000,433,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WPDSp.dll
[2011/12/18 11:19:13 | 000,350,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WPDSp.dll
[2011/12/18 11:19:13 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PortableDeviceWMDRM.dll
[2011/12/18 11:19:13 | 000,214,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PortableDeviceTypes.dll
[2011/12/18 11:19:13 | 000,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PortableDeviceWMDRM.dll
[2011/12/18 11:19:13 | 000,113,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PortableDeviceClassExtension.dll
[2011/12/18 11:19:13 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PortableDeviceClassExtension.dll
[2011/12/18 10:42:01 | 000,103,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2011/12/18 10:42:01 | 000,092,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2011/12/18 10:42:00 | 003,815,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIRibbon.dll
[2011/12/18 10:42:00 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIRibbonRes.dll
[2011/12/18 10:42:00 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIRibbonRes.dll
[2011/12/18 10:41:59 | 003,023,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIRibbon.dll
[2011/12/17 20:47:26 | 000,479,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2011/12/17 20:47:26 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/12/17 20:47:24 | 001,555,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2011/12/17 20:47:00 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2011/12/17 20:46:59 | 000,316,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msshsq.dll
[2011/12/17 20:46:58 | 000,451,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2011/12/17 20:46:26 | 000,834,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2011/12/17 20:46:26 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsRasterService.dll
[2011/12/17 20:46:25 | 003,068,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xpsservices.dll
[2011/12/17 20:46:25 | 002,002,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2011/12/17 20:46:25 | 001,257,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MFH264Dec.dll
[2011/12/17 20:46:25 | 000,979,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MFH264Dec.dll
[2011/12/17 20:46:24 | 000,566,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2011/12/17 20:46:24 | 000,287,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2011/12/17 20:46:24 | 000,047,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2011/12/17 20:46:23 | 001,461,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\OpcServices.dll
[2011/12/17 20:46:23 | 001,268,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2011/12/17 20:46:23 | 000,625,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2011/12/17 20:46:23 | 000,327,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2011/12/17 20:46:23 | 000,196,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/12/17 20:46:22 | 001,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xpsservices.dll
[2011/12/17 20:46:22 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\OpcServices.dll
[2011/12/17 20:46:22 | 000,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MFHEAACdec.dll
[2011/12/17 20:46:22 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MFHEAACdec.dll
[2011/12/17 20:46:22 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsRasterService.dll
[2011/12/17 20:46:21 | 003,548,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mf.dll
[2011/12/17 20:46:21 | 001,032,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\printfilterpipelinesvc.exe
[2011/12/17 20:46:21 | 000,377,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfmp4src.dll
[2011/12/17 20:46:21 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winspool.drv
[2011/12/17 20:46:21 | 000,345,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfreadwrite.dll
[2011/12/17 20:46:21 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfmp4src.dll
[2011/12/17 20:46:21 | 000,261,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfreadwrite.dll
[2011/12/17 20:46:20 | 002,873,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mf.dll
[2011/12/17 20:46:20 | 001,204,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\shdocvw.dll
[2011/12/17 20:46:20 | 000,748,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\stobject.dll
[2011/12/17 20:46:20 | 000,278,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfplat.dll
[2011/12/17 20:46:20 | 000,209,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfplat.dll
[2011/12/17 20:46:18 | 000,195,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfps.dll
[2011/12/17 20:46:17 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\printfilterpipelineprxy.dll
[2011/12/17 20:46:13 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfps.dll
[2011/12/17 20:46:13 | 000,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfpmp.exe
[2011/12/17 20:45:55 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAutomationCore.dll
[2011/12/17 20:45:54 | 000,735,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAutomationCore.dll
[2011/12/17 20:45:54 | 000,332,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2011/12/17 20:45:54 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\oleaccrc.dll
[2011/12/17 20:45:54 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaccrc.dll
[2011/12/17 20:45:52 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/12/17 20:45:38 | 000,180,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xmllite.dll
[2011/12/17 20:45:31 | 000,559,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/12/17 20:45:31 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/12/17 20:45:29 | 000,174,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2011/12/17 20:45:29 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/12/17 20:45:29 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/12/17 20:45:28 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2011/12/17 20:45:27 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/12/17 20:45:27 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/12/17 20:45:27 | 000,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2011/12/17 20:45:27 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2011/12/17 20:45:27 | 000,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2011/12/17 20:45:27 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2011/12/17 20:45:27 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/12/17 20:45:26 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2011/12/17 20:45:25 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2011/12/17 20:45:25 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/12/17 20:45:25 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/12/17 20:45:25 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/12/17 20:45:25 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/12/17 20:45:25 | 000,056,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/12/17 20:45:24 | 001,538,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/12/17 20:45:24 | 000,710,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/12/17 20:45:23 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/12/17 20:45:23 | 000,219,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/12/17 20:45:23 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/12/17 20:45:22 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/12/17 20:45:18 | 000,479,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/12/17 20:45:08 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2011/12/17 20:45:08 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2011/12/17 20:45:08 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2011/12/17 20:45:08 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2011/12/17 20:43:46 | 004,699,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/12/17 20:33:31 | 000,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/12/17 20:33:31 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/12/17 20:33:31 | 000,289,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011/12/17 20:33:31 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011/12/17 20:33:31 | 000,100,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Mpeg2Data.ax
[2011/12/17 20:33:31 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSDvbNP.ax
[2011/12/17 20:33:31 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Mpeg2Data.ax
[2011/12/17 20:33:31 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSDvbNP.ax
[2011/12/17 15:21:34 | 000,000,000 | —D | C] – C:\Windows\SysWow64\vi-VN
[2011/12/17 15:21:34 | 000,000,000 | —D | C] – C:\Windows\SysWow64\eu-ES
[2011/12/17 15:21:34 | 000,000,000 | —D | C] – C:\Windows\SysNative\eu-ES
[2011/12/17 15:21:34 | 000,000,000 | —D | C] – C:\Windows\SysWow64\ca-ES
[2011/12/17 15:21:34 | 000,000,000 | —D | C] – C:\Windows\SysNative\ca-ES
[2011/12/17 15:21:33 | 000,000,000 | —D | C] – C:\Windows\SysNative\vi-VN
[2011/12/17 12:57:17 | 000,000,000 | —D | C] – C:\Windows\SysNative\EventProviders
[2011/12/17 11:10:46 | 000,000,000 | —D | C] – C:\Users\Nando\AppData\Roaming\TestApp
[2011/12/17 10:58:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registry Mechanic
[2011/12/17 10:57:46 | 000,000,000 | —D | C] – C:\Users\Nando\AppData\Roaming\Product_RM
[2011/12/17 08:52:46 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Topckit_2011
[2011/12/16 23:32:40 | 000,000,000 | —D | C] – C:\Users\Nando\AppData\Roaming\FreeFileViewer
[2011/12/16 23:06:28 | 000,000,000 | —D | C] – C:\ProgramData\W3i
[2011/12/16 23:06:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\File Type Assistant
[2011/12/16 23:06:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeFileViewer
[2011/12/16 23:06:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\FreeFileViewer
[2011/12/16 23:05:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Free Offers from Freeze.com
[2011/12/16 23:05:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Surf Canyon
[2011/12/08 19:02:52 | 000,000,000 | —D | C] – C:\Users\Nando\AppData\Local\confobj90
[2011/12/07 18:41:31 | 000,252,296 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2011/12/07 18:41:31 | 000,188,808 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2011/12/07 18:41:31 | 000,188,808 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2011/12/03 09:36:22 | 000,499,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSVCP71.DLL
[2011/12/03 09:36:22 | 000,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSVCR71.DLL
[2011/12/03 09:36:21 | 001,060,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MFC71.DLL
[2011/12/03 09:36:18 | 001,017,208 | —- | C] (CyberLink Corp.) – C:\Windows\SysWow64\CLVSD.ax
[2011/12/03 09:36:17 | 000,000,000 | —D | C] – C:\Program Files\Cucusoft
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/30 12:50:55 | 000,703,388 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/12/30 12:50:55 | 000,604,502 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/12/30 12:50:55 | 000,104,170 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/12/30 12:45:17 | 000,027,335 | —- | M] () – C:\Users\Nando\AppData\Roaming\nvModes.001
[2011/12/30 12:44:35 | 000,000,243 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2011/12/30 12:44:03 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/30 12:43:16 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/30 12:43:16 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/30 12:42:56 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/30 12:21:02 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Nando\Desktop\OTL.exe
[2011/12/30 12:15:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/29 23:29:32 | 000,000,680 | —- | M] () – C:\Users\Nando\AppData\Local\d3d9caps.dat
[2011/12/29 22:15:15 | 085,491,386 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2011/12/29 22:14:49 | 000,020,592 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2011/12/29 22:11:56 | 000,000,266 | —- | M] () – C:\Windows\tasks\RMSchedule.job
[2011/12/28 22:52:34 | 000,000,872 | —- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2011/12/28 22:51:28 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2011/12/28 22:51:28 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2011/12/28 16:09:29 | 000,000,697 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2011/12/27 11:43:38 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/12/27 11:42:44 | 000,000,419 | —- | M] () – C:\Windows\BRWMARK.INI
[2011/12/27 11:42:44 | 000,000,027 | —- | M] () – C:\Windows\BRPP2KA.INI
[2011/12/21 12:11:05 | 561,550,750 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/12/20 21:59:33 | 000,000,828 | —- | M] () – C:\Users\Public\Desktop\Steam.lnk
[2011/12/18 16:28:24 | 002,744,532 | —- | M] () – C:\Windows\SysNative\drivers\Cat.DB
[2011/12/18 15:16:57 | 000,002,341 | —- | M] () – C:\Users\Nando\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/12/18 11:28:43 | 000,343,440 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/18 11:24:10 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2011/12/18 11:23:32 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2011/12/17 11:10:47 | 000,002,296 | —- | M] () – C:\Users\Nando\Desktop\sdsetup[1].exe.lnk
[2011/12/17 11:04:34 | 000,000,552 | —- | M] () – C:\Users\Nando\AppData\Local\d3d8caps.dat
[2011/12/17 10:58:14 | 000,000,970 | —- | M] () – C:\Users\Public\Desktop\PC Tools Registry Mechanic.lnk
[2011/12/17 10:57:47 | 000,002,306 | —- | M] () – C:\Users\Nando\Desktop\rminstall[1].exe.lnk
[2011/12/17 09:14:06 | 000,001,212 | —- | M] () – C:\Users\Nando\Desktop\exefix_vista.reg
[2011/12/17 09:06:24 | 000,000,732 | —- | M] () – C:\Users\Nando\AppData\Local\d3d9caps64.dat
[2011/12/17 08:52:47 | 000,000,857 | —- | M] () – C:\Users\Public\Desktop\Topckit_2011.lnk
[2011/12/16 23:05:48 | 000,001,777 | —- | M] () – C:\Users\Nando\Desktop\Free Music Downloads.lnk
[2011/12/15 19:47:05 | 000,000,334 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForNando.job
[2011/12/14 23:16:54 | 000,002,025 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2011/12/14 20:09:07 | 000,010,492 | -HS- | M] () – C:\ProgramData\ux2b0dfc1t117w1mm6c04
[2011/12/14 20:09:06 | 000,010,492 | -HS- | M] () – C:\Users\Nando\AppData\Local\ux2b0dfc1t117w1mm6c04
[2011/12/12 14:07:00 | 000,040,408 | —- | M] () – C:\Windows\SysNative\CleanMFT64.exe
[2011/12/10 15:24:08 | 000,023,152 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/12/07 18:41:20 | 000,627,600 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2011/12/07 18:41:20 | 000,252,296 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2011/12/07 18:41:20 | 000,188,808 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2011/12/07 18:41:20 | 000,188,808 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2011/12/05 18:46:03 | 000,025,600 | —- | M] () – C:\Users\Nando\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/03 09:36:22 | 000,001,002 | —- | M] () – C:\Users\Public\Desktop\Cucusoft DVD Ripper + Video Converter Ultimate.lnk
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/29 22:15:15 | 085,491,386 | —- | C] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2011/12/29 22:14:48 | 000,020,592 | —- | C] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2011/12/28 22:52:34 | 000,000,872 | —- | C] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2011/12/28 22:51:28 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2011/12/28 22:51:28 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2011/12/28 16:09:29 | 000,000,697 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2011/12/21 12:11:05 | 561,550,750 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/12/20 21:59:33 | 000,000,828 | —- | C] () – C:\Users\Public\Desktop\Steam.lnk
[2011/12/18 11:24:10 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2011/12/18 11:23:32 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2011/12/17 11:10:47 | 000,002,296 | —- | C] () – C:\Users\Nando\Desktop\sdsetup[1].exe.lnk
[2011/12/17 11:04:34 | 000,000,552 | —- | C] () – C:\Users\Nando\AppData\Local\d3d8caps.dat
[2011/12/17 10:58:14 | 000,000,970 | —- | C] () – C:\Users\Public\Desktop\PC Tools Registry Mechanic.lnk
[2011/12/17 10:57:47 | 000,002,306 | —- | C] () – C:\Users\Nando\Desktop\rminstall[1].exe.lnk
[2011/12/17 09:06:24 | 000,000,732 | —- | C] () – C:\Users\Nando\AppData\Local\d3d9caps64.dat
[2011/12/17 08:52:47 | 000,000,857 | —- | C] () – C:\Users\Public\Desktop\Topckit_2011.lnk
[2011/12/16 23:05:48 | 000,001,777 | —- | C] () – C:\Users\Nando\Desktop\Free Music Downloads.lnk
[2011/12/14 20:01:53 | 000,010,492 | -HS- | C] () – C:\Users\Nando\AppData\Local\ux2b0dfc1t117w1mm6c04
[2011/12/14 20:01:53 | 000,010,492 | -HS- | C] () – C:\ProgramData\ux2b0dfc1t117w1mm6c04
[2011/12/03 09:36:22 | 000,001,002 | —- | C] () – C:\Users\Public\Desktop\Cucusoft DVD Ripper + Video Converter Ultimate.lnk
[2011/01/26 22:04:57 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/10/09 22:56:19 | 000,000,000 | —- | C] () – C:\Windows\iplayer.INI
[2010/07/17 18:52:34 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2010/07/17 18:52:32 | 000,348,160 | —- | C] () – C:\Windows\SysWow64\cdga.dll
[2010/05/05 19:16:35 | 000,000,680 | —- | C] () – C:\Users\Nando\AppData\Local\d3d9caps.dat
[2010/04/06 18:27:03 | 000,047,616 | —- | C] () – C:\Windows\SysWow64\pdf995mon64.dll
[2010/04/06 18:27:03 | 000,000,142 | —- | C] () – C:\Windows\wpd99.drv
[2010/03/13 11:53:13 | 000,763,832 | —- | C] () – C:\Windows\BDTSupport.dll.old
[2010/03/07 16:14:19 | 000,023,114 | —- | C] () – C:\Windows\hpqins15.dat
[2010/03/06 22:47:17 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2010/03/06 22:46:53 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2010/03/06 22:46:32 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2010/03/04 20:15:04 | 000,027,335 | —- | C] () – C:\Users\Nando\AppData\Roaming\nvModes.001
[2010/03/04 20:09:34 | 000,000,419 | —- | C] () – C:\Windows\BRWMARK.INI
[2010/03/04 20:09:34 | 000,000,027 | —- | C] () – C:\Windows\BRPP2KA.INI
[2010/03/03 16:54:45 | 000,027,335 | —- | C] () – C:\Users\Nando\AppData\Roaming\nvModes.dat
[2010/03/02 04:16:00 | 000,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2010/02/28 20:02:59 | 000,025,600 | —- | C] () – C:\Users\Nando\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/22 12:19:56 | 000,101,632 | —- | C] () – C:\Windows\hpqins13.dat
[2008/01/20 21:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2006/11/02 10:37:05 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 07:37:14 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2006/11/02 07:24:17 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 07:18:17 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 04:47:54 | 000,043,131 | —- | C] () – C:\Windows\mib.bin

========== LOP Check ==========

[2011/12/28 23:07:02 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\AVG2012
[2011/12/16 23:32:44 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\FreeFileViewer
[2011/09/12 16:49:48 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\Helios
[2010/04/06 18:27:51 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\pdf995
[2011/07/16 16:46:17 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\PlayFirst
[2011/12/17 10:57:46 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\Product_RM
[2011/12/18 11:47:53 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\Registry Mechanic
[2010/05/27 19:27:18 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\TaxCut
[2011/12/17 11:10:46 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\TestApp
[2011/07/16 16:44:50 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\WildTangent
[2011/12/29 22:11:56 | 000,000,266 | —- | M] () – C:\Windows\Tasks\RMSchedule.job
[2011/12/30 12:40:47 | 000,032,536 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/01/30 21:36:06 | 000,000,434 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{A178F131-5775-4EDE-B6A0-A3D250D9CA70}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/11/19 15:48:18 | 000,000,047 | —- | M] () – C:\AUTOEXEC.BAT
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/02/22 11:29:01 | 000,000,384 | -H– | M] () – C:\IPH.PH
[2006/12/02 02:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2011/12/30 12:42:38 | 245,358,591 | -HS- | M] () – C:\pagefile.sys
[2011/12/20 21:15:18 | 000,000,370 | —- | M] () – C:\rkill.log
[2011/12/20 21:20:42 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.6.22.0_20.12.2011_21.20.19_log.txt
[2011/12/20 21:28:16 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.6.22.0_20.12.2011_21.28.05_log.txt

< %systemroot%\Fonts\*.com >
[2006/11/02 10:06:41 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 10:06:41 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 10:06:41 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2011/12/17 14:48:06 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 16:35:48 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/04/16 23:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 22:21:59 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2011/05/24 18:09:34 | 000,003,072 | —- | M] () – C:\Windows\system32\Cache.db

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/19 18:59:19 | 000,000,286 | -HS- | M] () – C:\Users\Nando\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/12/30 12:21:02 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Nando\Desktop\OTL.exe
[2010/12/12 16:20:00 | 000,512,992 | —- | M] () – C:\Users\Nando\Desktop\sdsetup[1].exe
[2008/08/05 11:35:52 | 027,141,384 | —- | M] (Maxis, a division of Electronic Arts Inc.) – C:\Users\Nando\Desktop\SporeApp.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 165 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 157 bytes -> C:\ProgramData\TEMP:D1B5B4F1
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8

< End of report >


OTL Extras logfile created on: 12/30/2011 12:24:03 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Nando\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19170)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.94 Gb Total Physical Memory | 1.53 Gb Available Physical Memory | 38.95% Memory free
8.09 Gb Paging File | 5.51 Gb Available in Paging File | 68.08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.14 Gb Total Space | 163.34 Gb Free Space | 57.28% Space Free | Partition Type: NTFS
Drive D: | 12.95 Gb Total Space | 2.43 Gb Free Space | 18.76% Space Free | Partition Type: NTFS

Computer Name: NANDO-LAPTOP | User Name: Nando | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = D7 9C 35 A7 FA BC CC 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)
"C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{15133EB3-BAC9-474C-8F3F-B154E486D15C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{198930C5-8707-4EBA-8068-56C3B40AC958}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{215E8087-6F61-4A2B-BC04-41E8E1429FAA}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{39350F15-CF71-4204-9EEA-D280D6F79EC8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3AE7C3FE-2358-4EDD-B7AC-7DF51F14D970}" = lport=139 | protocol=6 | dir=in | app=system |
"{462EF7E1-F0B5-47A4-AC22-41016C40F218}" = rport=139 | protocol=6 | dir=out | app=system |
"{489BED90-9315-49B8-9884-4D2DF3EEAA1D}" = rport=137 | protocol=17 | dir=out | app=system |
"{54790C89-38F2-4594-874C-1CAC651DF2E8}" = rport=445 | protocol=6 | dir=out | app=system |
"{551785C4-899D-4F0F-9C41-AD37CACB9BE9}" = rport=138 | protocol=17 | dir=out | app=system |
"{56345D86-61B4-42F3-9ED2-4BBE2C53830E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{624DE384-7D94-42D1-ABF0-A1FB656C5B1F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9D94C86C-4B1C-496B-A969-647E3DA1DDCE}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{A9AF15C5-982F-4E28-B605-39979390CF8C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A9BE3B48-2459-46A6-BC8D-FBC7C24BF610}" = lport=445 | protocol=6 | dir=in | app=system |
"{BE72380F-F0BE-449C-B6E4-2A8D2CD73F97}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C9EC8183-ACA2-4BC4-A3AA-8D1838BB6A16}" = lport=138 | protocol=17 | dir=in | app=system |
"{D3939D16-5274-4531-90F5-3453B230C01F}" = lport=137 | protocol=17 | dir=in | app=system |
"{E13498DC-A6C6-46E1-9908-4CACCEDB3D44}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{EBB28CC8-E07B-4248-B46E-B0BF50C65116}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FFC6A871-2C4E-402F-99BF-20C9E0596505}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05377A32-4DF3-40BF-BC42-617A590E1F78}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{0B9AEFC6-0715-410E-B23D-F06839F1A148}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{109647F6-8FDA-479B-B52D-DE2AC5911B61}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{10CD19CB-B12A-4088-BCB3-975B1D4E0BE6}" = dir=in | app=c:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{11B73F2B-ED14-4AF3-85A6-025E1A67039D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{22EC7A86-E344-411E-B39E-EFDFBF5A6482}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{2F7B2ECF-7F5C-49CE-A6D8-55CA7CD841DD}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{302650D1-FECF-4BD9-914E-2D573C5119AE}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{3197B78D-043F-4BA9-9405-8285904A61E9}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{32CBB9C1-3A11-4D00-94C9-9D32BF0BA653}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{416D7402-714F-4290-99D4-AABB3CD5BB8C}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{4ABD36B7-B516-4B2B-9846-334220638AB7}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{5A735C20-3FA4-48CD-ABE7-3FD036B17215}" = dir=in | app=c:\program files (x86)\hp\quickplay\qpservice.exe |
"{5C4329C8-1FB4-40E9-ABDA-6EC7E0F4BB07}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{61F7AD8E-139E-42B7-9C5C-A7BD525CFFBC}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{74606898-9BF7-4492-814D-DB7F0BE8FE7F}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{75A591D0-61D9-4D1A-852C-619D342EA3AF}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{7EC89CF2-59BC-47F9-A740-25E6193D4B8B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqsudi.exe |
"{9480CE52-8E38-4CE8-8C2C-C8DCB9E8039D}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{994FDA5B-6A99-44D9-B78D-98C669C66986}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{A3ED1A51-F422-4E40-8557-1A2459E3444E}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpsapp.exe |
"{A42972CF-C3D8-47DD-954C-95D54A3EA0CB}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{A63327CF-0C72-4639-AD8F-700B5C701A3F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A816440F-685A-45C5-9DAB-6427F13E0C93}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{A86FE271-78A0-4E9A-83E1-806609A23B33}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{AC5911B7-43B2-46EE-BBC2-3BFC4F624A82}" = dir=in | app=c:\program files (x86)\hp\quickplay\qp.exe |
"{ADF4889E-426E-4957-A315-4FBBF52243CB}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |
"{C4F099C9-90DF-4323-B044-A2A15C6D7204}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpse.exe |
"{C9F24E41-583D-49A6-8A13-82BCB4B9D178}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{DA6D66EA-81F4-495D-AABB-D0AAC3D073C1}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{DED927DF-B9DE-4F68-81B3-D33123CB6504}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{E1A31D5B-F679-4E5D-8CBC-08B6BAF4D9C7}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{EC8E8471-F49F-473E-A62B-66AFB26956AF}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{F2F05428-15BD-4F78-BBF6-F9EADCBC276D}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"TCP Query User{31824B3D-BEA6-4578-A666-24E985B2F3D9}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |
"UDP Query User{5828C114-88E7-40A6-8FFE-84271B674D7A}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E543634-7E25-4B8F-8D5B-97880E5E5088}" = Bonjour
"{11192F89-510C-4E23-A62A-D3BEA9139596}" = HP QuickTouch 1.00 C3
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
"{26A24AE4-039D-4CA4-87B4-2F86417001FF}" = Java™ 7 Update 1 (64-bit)
"{28D73032-5DAA-4F83-B154-85105DBCCB92}" = iTunes
"{41B19F41-8A6F-4422-AD69-CF3B408F382C}" = AVG 2012
"{439760BC-7737-4386-9B1D-A90A3E8A22EA}" = Apple Mobile Device Support
"{64A3A4F4-B792-11D6-A78A-00B0D0170000}" = Java™ SE Development Kit 7 (64-bit)
"{64A3A4F4-B792-11D6-A78A-00B0D0170010}" = Java™ SE Development Kit 7 Update 1 (64-bit)
"{6D830209-41C2-4D6B-BA25-4EF98807D9FB}" = AVG 2012
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{90B5B05F-AFDA-4922-A153-45B14200BA77}" = SPBBC 64bit
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Touch Pad Driver
"{A348C751-0EFF-4B9D-8065-B5339BEFBE27}" = HP Help and Support
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"AVG" = AVG 2012
"Broadcom 802.11b Network Adapter" = Broadcom 802.11 Wireless LAN Adapter
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Cucusoft Ultimate DVD + Video Converter Suite_is1" = Cucusoft Ultimate DVD + Video Converter Suite [removed]
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Drivers" = NVIDIA Drivers

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0F907A69-6332-4F87-AD74-3C91A627D2C6}" = H&R; Block Virginia 2009
"{11BB336F-0E58-4977-B866-F24FA334616B}" = HP Active Support Library
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2284D904-C138-4B58-93EC-5C362AB5130A}" = The Sims™ Life Stories
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{250E9609-E830-43EB-B379-DAB7546A2422}" = muvee autoProducer 6.1
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check
"{26A24AE4-039D-4CA4-87B4-2F83217000FF}" = Java™ 7
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{32A3A4F4-B792-11D6-A78A-00B0D0170000}" = Java™ SE Development Kit 7
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1
"{38EAC694-0D90-445F-8C17-8B50ADFE3162}" = Slingbox Flash Tour
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40049394-98C6-409D-878D-E418B872D5D0}" = Comsift Service
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{53A19323-917A-4822-B27E-A57D1EF6E9FC}" = H&R; Block Deluxe + Efile + State 2009
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.52.02
"{5D87C09F-512F-474A-A306-0FE3B89C396F}" = RuneScape Launcher 1.0.4
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}" = Safari
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92A196AE-9B4D-499C-94D4-18FA2061B3CE}_is1" = Shop To Win
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{97F4D62E-5AEB-4649-BABF-4712C6EF6845}" = DeductionPro 2009
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.5
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{B53620C0-3A83-4F50-A7AB-175DB64C1CE3}" = HP User Guides 0090
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}" = PMB
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{B6EC7388-E277-4A5B-8C8F-71067A41BA64}" = TextPad 5
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}" = Skype™ 5.3
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"AIM_6" = AIM 6
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"Cucusoft Ultimate DVD + Video Converter Suite_is1" = Cucusoft Ultimate DVD + Video Converter Suite [removed]
"FreeFileViewer_is1" = Free File Viewer 2011
"Google Chrome" = Google Chrome
"Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InterActual Player" = InterActual Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"McAfee Security Scan" = McAfee Security Scan Plus
"Musicnotes Combined Installer_is1" = Musicnotes Software Suite 1.4.3
"Pdf995" = Pdf995 (installed by H&R; Block)
"PdfEdit995" = PdfEdit995 (installed by H&R; Block)
"Picasa 3" = Picasa 3
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"Registry Mechanic_is1" = PC Tools Registry Mechanic 11.0
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.6
"Surf Canyon" = Fast Search
"TI-83 Plus Flash Debugger" = TI-83 Plus Flash Debugger
"Trusted Software Assistant_is1" = File Type Assistant
"ViewpointMediaPlayer" = Viewpoint Media Player
"WildTangent hp Master Uninstall" = My HP Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"Yahoo! Software Update" = Yahoo! Software Update

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/12/2011 11:06:14 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 681802

Error - 2/12/2011 11:06:14 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 681802

Error - 2/12/2011 11:06:15 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2/12/2011 11:06:15 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 682894

Error - 2/12/2011 11:06:15 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 682894

Error - 2/12/2011 11:06:17 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2/12/2011 11:06:17 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 684642

Error - 2/12/2011 11:06:17 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 684642

Error - 2/12/2011 11:06:18 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2/12/2011 11:06:18 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 685905

[ Media Center Events ]
Error - 9/17/2010 9:02:48 PM | Computer Name = Nando-Laptop | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ OSession Events ]
Error - 12/8/2011 5:24:45 PM | Computer Name = Nando-Laptop | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6565.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 816
seconds with 420 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 6/1/2010 6:18:25 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.

Error - 6/1/2010 6:18:26 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.

Error - 6/1/2010 6:18:27 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.

Error - 6/1/2010 6:18:28 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.

Error - 6/1/2010 6:18:28 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.

Error - 6/1/2010 6:18:29 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.

Error - 6/1/2010 6:18:30 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.

Error - 6/1/2010 6:18:31 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.

Error - 6/1/2010 6:18:31 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.

Error - 6/1/2010 6:18:32 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.


< End of report >
Hi fernipascual,

That's fine. You don't need to right click and run as administrator because OTL will automatically ask you to elevate it to run with administrator rights :).

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
===================================================

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan.
    • If Malicious objects are found, DO NOT cure them.
    • Choose Skip then click on Continue.
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
Hello NoodleTech: Here it is. aswMBR version 0.9.9.1124 Copyright© 2011 AVAST Software Run date: 2011-12-30 23:37:49 —————————– 23:37:49.051 OS Version: Windows x64 6.0.6002 Service Pack 2 23:37:49.051 Number of processors: 2 586 0x6802 23:37:49.051 ComputerName: NANDO-LAPTOP UserName: Nando 23:37:50.782 Initialize success 23:38:46.479 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3 23:38:46.479 Disk 0 Vendor: FUJITSU_MHZ2320BH_G2 8909 Size: 305245MB BusType: 3 23:38:46.494 Disk 0 MBR read successfully 23:38:46.494 Disk 0 MBR scan 23:38:46.494 Disk 0 unknown MBR code 23:38:46.494 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 291986 MB offset 63 23:38:46.525 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 13256 MB offset 597987495 23:38:46.541 Service scanning 23:38:49.068 Modules scanning 23:38:49.068 Disk 0 trace - called modules: 23:38:49.068 ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys 23:38:49.068 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004a4b060] 23:38:49.084 3 CLASSPNP.SYS[fffffa6000fd3c33] -> nt!IofCallDriver -> [0xfffffa80048c0520] 23:38:49.084 5 acpi.sys[fffffa60008f9fde] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-3[0xfffffa80048c7940] 23:38:49.099 Scan finished successfully 23:39:35.229 Disk 0 MBR has been saved successfully to "C:\Users\Nando\Desktop\MBR.dat" 23:39:35.244 The log file has been saved successfully to "C:\Users\Nando\Desktop\aswMBR.txt" 23:40:43.0066 7040 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16 23:40:43.0394 7040 ============================================================ 23:40:43.0394 7040 Current date / time: 2011/12/30 23:40:43.0394 23:40:43.0394 7040 SystemInfo: 23:40:43.0394 7040 23:40:43.0394 7040 OS Version: 6.0.6002 ServicePack: 2.0 23:40:43.0394 7040 Product type: Workstation 23:40:43.0394 7040 ComputerName: NANDO-LAPTOP 23:40:43.0394 7040 UserName: Nando 23:40:43.0394 7040 Windows directory: C:\Windows 23:40:43.0394 7040 System windows directory: C:\Windows 23:40:43.0394 7040 Running under WOW64 23:40:43.0394 7040 Processor architecture: Intel x64 23:40:43.0394 7040 Number of processors: 2 23:40:43.0394 7040 Page size: 0x1000 23:40:43.0394 7040 Boot type: Normal boot 23:40:43.0394 7040 ============================================================ 23:40:44.0938 7040 Initialize success 23:40:58.0744 6712 ============================================================ 23:40:58.0744 6712 Scan started 23:40:58.0744 6712 Mode: Manual; 23:40:58.0744 6712 ============================================================ 23:40:59.0321 6712 ACPI (1965aaffab07e3fb03c77f81beba3547) C:\Windows\system32\drivers\acpi.sys 23:40:59.0321 6712 ACPI - ok 23:40:59.0415 6712 adp94xx (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys 23:40:59.0446 6712 adp94xx - ok 23:40:59.0555 6712 adpahci (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys 23:40:59.0555 6712 adpahci - ok 23:40:59.0649 6712 adpu160m (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys 23:40:59.0649 6712 adpu160m - ok 23:40:59.0711 6712 adpu320 (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys 23:40:59.0711 6712 adpu320 - ok 23:40:59.0805 6712 AFD (0cc146c4addea45791b18b1e2659f4a9) C:\Windows\system32\drivers\afd.sys 23:40:59.0820 6712 AFD - ok 23:40:59.0945 6712 agp440 (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys 23:40:59.0945 6712 agp440 - ok 23:40:59.0976 6712 aic78xx (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys 23:40:59.0992 6712 aic78xx - ok 23:41:00.0023 6712 aliide (157d0898d4b73f075ce9fa26b482df98) C:\Windows\system32\drivers\aliide.sys 23:41:00.0023 6712 aliide - ok 23:41:00.0039 6712 amdide (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys 23:41:00.0039 6712 amdide - ok 23:41:00.0101 6712 AmdK8 (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\DRIVERS\amdk8.sys 23:41:00.0101 6712 AmdK8 - ok 23:41:00.0210 6712 ApfiltrService (709b9ebbf89d70c61b83b809e70a41a2) C:\Windows\system32\DRIVERS\Apfiltr.sys 23:41:00.0226 6712 ApfiltrService - ok 23:41:00.0320 6712 arc (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys 23:41:00.0320 6712 arc - ok 23:41:00.0366 6712 arcsas (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys 23:41:00.0366 6712 arcsas - ok 23:41:00.0476 6712 AsyncMac (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys 23:41:00.0491 6712 AsyncMac - ok 23:41:00.0522 6712 atapi (e68d9b3a3905619732f7fe039466a623) C:\Windows\system32\drivers\atapi.sys 23:41:00.0522 6712 atapi - ok 23:41:00.0647 6712 AVGIDSDriver (fa46adf6e497cf185160f09e603ce2a3) C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys 23:41:00.0647 6712 AVGIDSDriver - ok 23:41:00.0694 6712 AVGIDSEH (d6b93e5d8b96a66f55a4d2ee7f24667c) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys 23:41:00.0694 6712 AVGIDSEH - ok 23:41:00.0772 6712 AVGIDSFilter (ff6551f1ab0da3b30c9dec923f21b504) C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys 23:41:00.0772 6712 AVGIDSFilter - ok 23:41:00.0850 6712 Avgldx64 (979cf8912449a10b987218bff80a1fa3) C:\Windows\system32\DRIVERS\avgldx64.sys 23:41:00.0866 6712 Avgldx64 - ok 23:41:00.0912 6712 Avgmfx64 (36b1a5843695766eac714daffc5b84d1) C:\Windows\system32\DRIVERS\avgmfx64.sys 23:41:00.0912 6712 Avgmfx64 - ok 23:41:00.0975 6712 Avgrkx64 (1102239fb724527f1febbbbccf6bf313) C:\Windows\system32\DRIVERS\avgrkx64.sys 23:41:00.0975 6712 Avgrkx64 - ok 23:41:01.0068 6712 Avgtdia (11f36d3ea82d9db9aa05a476a210551b) C:\Windows\system32\DRIVERS\avgtdia.sys 23:41:01.0084 6712 Avgtdia - ok 23:41:01.0193 6712 BCM43XV (d81deba25f4b4340d2647bf3af67b2f3) C:\Windows\system32\DRIVERS\bcmwl664.sys 23:41:01.0224 6712 BCM43XV - ok 23:41:01.0302 6712 BCM43XX (d81deba25f4b4340d2647bf3af67b2f3) C:\Windows\system32\DRIVERS\bcmwl664.sys 23:41:01.0318 6712 BCM43XX - ok 23:41:01.0458 6712 blbdrive (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys 23:41:01.0458 6712 blbdrive - ok 23:41:01.0521 6712 bowser (2348447a80920b2493a9b582a23e81e1) C:\Windows\system32\DRIVERS\bowser.sys 23:41:01.0521 6712 bowser - ok 23:41:01.0583 6712 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys 23:41:01.0583 6712 BrFiltLo - ok 23:41:01.0599 6712 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys 23:41:01.0614 6712 BrFiltUp - ok 23:41:01.0677 6712 Brserid (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys 23:41:01.0677 6712 Brserid - ok 23:41:01.0786 6712 BrSerIf (80e52ef092f3dad03e0ee15e64f97245) C:\Windows\system32\DRIVERS\BrSerIf.sys 23:41:01.0786 6712 BrSerIf - ok 23:41:01.0817 6712 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys 23:41:01.0817 6712 BrSerWdm - ok 23:41:01.0848 6712 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys 23:41:01.0848 6712 BrUsbMdm - ok 23:41:01.0895 6712 BrUsbSer (601cb966fffebc6806626dc8e7aa0ef2) C:\Windows\system32\DRIVERS\BrUsbSer.sys 23:41:01.0895 6712 BrUsbSer - ok 23:41:01.0973 6712 BTHMODEM (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys 23:41:01.0973 6712 BTHMODEM - ok 23:41:02.0098 6712 CAXHWAZL (e387475e1e8947e82abfe91556cf4e1e) C:\Windows\system32\DRIVERS\CAXHWAZL.sys 23:41:02.0114 6712 CAXHWAZL - ok 23:41:02.0145 6712 cdfs (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys 23:41:02.0160 6712 cdfs - ok 23:41:02.0192 6712 cdrom (c025aa69be3d0d25c7a2e746ef6f94fc) C:\Windows\system32\DRIVERS\cdrom.sys 23:41:02.0207 6712 cdrom - ok 23:41:02.0270 6712 circlass (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\drivers\circlass.sys 23:41:02.0285 6712 circlass - ok 23:41:02.0316 6712 CLFS (3dca9a18b204939cfb24bea53e31eb48) C:\Windows\system32\CLFS.sys 23:41:02.0332 6712 CLFS - ok 23:41:02.0457 6712 CmBatt (b52d9a14ce4101577900a364ba86f3df) C:\Windows\system32\DRIVERS\CmBatt.sys 23:41:02.0457 6712 CmBatt - ok 23:41:02.0488 6712 cmdide (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys 23:41:02.0488 6712 cmdide - ok 23:41:02.0566 6712 Compbatt (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\DRIVERS\compbatt.sys 23:41:02.0566 6712 Compbatt - ok 23:41:02.0628 6712 crcdisk (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys 23:41:02.0644 6712 crcdisk - ok 23:41:02.0816 6712 DfsC (8b722ba35205c71e7951cdc4cdbade19) C:\Windows\system32\Drivers\dfsc.sys 23:41:02.0816 6712 DfsC - ok 23:41:02.0925 6712 disk (b0107e40ecdb5fa692ebf832f295d905) C:\Windows\system32\drivers\disk.sys 23:41:02.0940 6712 disk - ok 23:41:03.0065 6712 drmkaud (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys 23:41:03.0065 6712 drmkaud - ok 23:41:03.0128 6712 DXGKrnl (b8e554e502d5123bc111f99d6a2181b4) C:\Windows\System32\drivers\dxgkrnl.sys 23:41:03.0159 6712 DXGKrnl - ok 23:41:03.0346 6712 E1G60 (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys 23:41:03.0346 6712 E1G60 - ok 23:41:03.0471 6712 Ecache (5f94962be5a62db6e447ff6470c4f48a) C:\Windows\system32\drivers\ecache.sys 23:41:03.0471 6712 Ecache - ok 23:41:03.0580 6712 elxstor (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys 23:41:03.0580 6712 elxstor - ok 23:41:03.0642 6712 ErrDev (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys 23:41:03.0642 6712 ErrDev - ok 23:41:03.0705 6712 exfat (486844f47b6636044a42454614ed4523) C:\Windows\system32\drivers\exfat.sys 23:41:03.0705 6712 exfat - ok 23:41:03.0783 6712 fastfat (1a4bee34277784619ddaf0422c0c6e23) C:\Windows\system32\drivers\fastfat.sys 23:41:03.0798 6712 fastfat - ok 23:41:03.0892 6712 fdc (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys 23:41:03.0908 6712 fdc - ok 23:41:03.0939 6712 FileInfo (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys 23:41:03.0939 6712 FileInfo - ok 23:41:04.0001 6712 Filetrace (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys 23:41:04.0001 6712 Filetrace - ok 23:41:04.0064 6712 flpydisk (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 23:41:04.0079 6712 flpydisk - ok 23:41:04.0126 6712 FltMgr (e3041bc26d6930d61f42aedb79c91720) C:\Windows\system32\drivers\fltmgr.sys 23:41:04.0126 6712 FltMgr - ok 23:41:04.0282 6712 Fs_Rec (29d99e860a1ca0a03c6a733fdd0da703) C:\Windows\system32\drivers\Fs_Rec.sys 23:41:04.0282 6712 Fs_Rec - ok 23:41:04.0329 6712 gagp30kx (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys 23:41:04.0329 6712 gagp30kx - ok 23:41:04.0391 6712 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 23:41:04.0407 6712 GEARAspiWDM - ok 23:41:04.0578 6712 HdAudAddService (730998bf8b5d23c94628cfbbdcec93c7) C:\Windows\system32\drivers\CHDART64.sys 23:41:04.0610 6712 HdAudAddService - ok 23:41:04.0797 6712 HDAudBus (f942c5820205f2fb453243edfec82a3d) C:\Windows\system32\DRIVERS\HDAudBus.sys 23:41:04.0812 6712 HDAudBus - ok 23:41:04.0828 6712 HidBth (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys 23:41:04.0828 6712 HidBth - ok 23:41:04.0859 6712 HidIr (4e77a77e2c986e8f88f996bb3e1ad829) C:\Windows\system32\drivers\hidir.sys 23:41:04.0859 6712 HidIr - ok 23:41:04.0906 6712 HidUsb (443bdd2d30bb4f00795c797e2cf99edf) C:\Windows\system32\DRIVERS\hidusb.sys 23:41:04.0906 6712 HidUsb - ok 23:41:04.0984 6712 HpCISSs (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys 23:41:04.0984 6712 HpCISSs - ok 23:41:05.0031 6712 HpqKbFiltr (0ecc54fd34d6a089c300846b011e81d6) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys 23:41:05.0031 6712 HpqKbFiltr - ok 23:41:05.0031 6712 HpqRemHid (e53d53d66d61794af8160741946d0b43) C:\Windows\system32\DRIVERS\HpqRemHid.sys 23:41:05.0031 6712 HpqRemHid - ok 23:41:05.0140 6712 HSFHWAZL (57ba73b5b321291e5114cb21350e1ea0) C:\Windows\system32\DRIVERS\VSTAZL6.SYS 23:41:05.0140 6712 HSFHWAZL - ok 23:41:05.0218 6712 HSF_DPV (1e260b33f6555146a0b826f047238c00) C:\Windows\system32\DRIVERS\CAX_DPV.sys 23:41:05.0249 6712 HSF_DPV - ok 23:41:05.0343 6712 HTTP (098f1e4e5c9cb5b0063a959063631610) C:\Windows\system32\drivers\HTTP.sys 23:41:05.0374 6712 HTTP - ok 23:41:05.0436 6712 i2omp (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys 23:41:05.0436 6712 i2omp - ok 23:41:05.0483 6712 i8042prt (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys 23:41:05.0483 6712 i8042prt - ok 23:41:05.0514 6712 iaStorV (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys 23:41:05.0514 6712 iaStorV - ok 23:41:05.0592 6712 iirsp (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys 23:41:05.0592 6712 iirsp - ok 23:41:05.0670 6712 intelide (df797a12176f11b2d301c5b234bb200e) C:\Windows\system32\drivers\intelide.sys 23:41:05.0670 6712 intelide - ok 23:41:05.0733 6712 intelppm (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys 23:41:05.0733 6712 intelppm - ok 23:41:05.0795 6712 IpFilterDriver (d8aabc341311e4780d6fce8c73c0ad81) C:\Windows\system32\DRIVERS\ipfltdrv.sys 23:41:05.0795 6712 IpFilterDriver - ok 23:41:05.0826 6712 IpInIp - ok 23:41:05.0858 6712 IPMIDRV (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys 23:41:05.0858 6712 IPMIDRV - ok 23:41:05.0889 6712 IPNAT (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys 23:41:05.0889 6712 IPNAT - ok 23:41:05.0936 6712 IRENUM (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys 23:41:05.0936 6712 IRENUM - ok 23:41:05.0998 6712 isapnp (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys 23:41:05.0998 6712 isapnp - ok 23:41:06.0060 6712 iScsiPrt (e4fdf99599f27ec25d2cf6d754243520) C:\Windows\system32\DRIVERS\msiscsi.sys 23:41:06.0076 6712 iScsiPrt - ok 23:41:06.0107 6712 iteatapi (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys 23:41:06.0123 6712 iteatapi - ok 23:41:06.0170 6712 iteraid (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys 23:41:06.0170 6712 iteraid - ok 23:41:06.0216 6712 kbdclass (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys 23:41:06.0216 6712 kbdclass - ok 23:41:06.0232 6712 kbdhid (dbdf75d51464fbc47d0104ec3d572c05) C:\Windows\system32\DRIVERS\kbdhid.sys 23:41:06.0232 6712 kbdhid - ok 23:41:06.0310 6712 KSecDD (476e2c1dcea45895994bef11c2a98715) C:\Windows\system32\Drivers\ksecdd.sys 23:41:06.0326 6712 KSecDD - ok 23:41:06.0372 6712 ksthunk (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys 23:41:06.0372 6712 ksthunk - ok 23:41:06.0482 6712 lltdio (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys 23:41:06.0482 6712 lltdio - ok 23:41:06.0528 6712 LSI_FC (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys 23:41:06.0528 6712 LSI_FC - ok 23:41:06.0544 6712 LSI_SAS (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys 23:41:06.0544 6712 LSI_SAS - ok 23:41:06.0575 6712 LSI_SCSI (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys 23:41:06.0575 6712 LSI_SCSI - ok 23:41:06.0638 6712 luafv (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys 23:41:06.0638 6712 luafv - ok 23:41:06.0700 6712 MBAMProtector (79da94b35371b9e7104460c7693dcb2c) C:\Windows\system32\drivers\mbam.sys 23:41:06.0700 6712 MBAMProtector - ok 23:41:06.0794 6712 mdmxsdk (e4f44ec214b3e381e1fc844a02926666) C:\Windows\system32\DRIVERS\mdmxsdk.sys 23:41:06.0794 6712 mdmxsdk - ok 23:41:06.0856 6712 megasas (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys 23:41:06.0856 6712 megasas - ok 23:41:06.0934 6712 MegaSR (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys 23:41:06.0934 6712 MegaSR - ok 23:41:07.0012 6712 Modem (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys 23:41:07.0012 6712 Modem - ok 23:41:07.0028 6712 monitor (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys 23:41:07.0028 6712 monitor - ok 23:41:07.0074 6712 mouclass (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys 23:41:07.0074 6712 mouclass - ok 23:41:07.0152 6712 mouhid (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys 23:41:07.0152 6712 mouhid - ok 23:41:07.0184 6712 MountMgr (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys 23:41:07.0199 6712 MountMgr - ok 23:41:07.0230 6712 mpio (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys 23:41:07.0230 6712 mpio - ok 23:41:07.0277 6712 mpsdrv (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys 23:41:07.0277 6712 mpsdrv - ok 23:41:07.0324 6712 Mraid35x (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys 23:41:07.0324 6712 Mraid35x - ok 23:41:07.0355 6712 MRxDAV (7c1de4aa96dc0c071611f9e7de02a68d) C:\Windows\system32\drivers\mrxdav.sys 23:41:07.0355 6712 MRxDAV - ok 23:41:07.0433 6712 mrxsmb (1485811b320ff8c7edad1caebb1c6c2b) C:\Windows\system32\DRIVERS\mrxsmb.sys 23:41:07.0433 6712 mrxsmb - ok 23:41:07.0464 6712 mrxsmb10 (3b929a60c833fc615fd97fba82bc7632) C:\Windows\system32\DRIVERS\mrxsmb10.sys 23:41:07.0480 6712 mrxsmb10 - ok 23:41:07.0496 6712 mrxsmb20 (c64ab3e1f53b4f5b5bb6d796b2d7bec3) C:\Windows\system32\DRIVERS\mrxsmb20.sys 23:41:07.0496 6712 mrxsmb20 - ok 23:41:07.0542 6712 msahci (1ac860612b85d8e85ee257d372e39f4d) C:\Windows\system32\drivers\msahci.sys 23:41:07.0542 6712 msahci - ok 23:41:07.0589 6712 msdsm (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys 23:41:07.0589 6712 msdsm - ok 23:41:07.0683 6712 Msfs (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys 23:41:07.0683 6712 Msfs - ok 23:41:07.0730 6712 msisadrv (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys 23:41:07.0730 6712 msisadrv - ok 23:41:07.0792 6712 MSKSSRV (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys 23:41:07.0792 6712 MSKSSRV - ok 23:41:07.0808 6712 MSPCLOCK (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys 23:41:07.0808 6712 MSPCLOCK - ok 23:41:07.0854 6712 MSPQM (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys 23:41:07.0854 6712 MSPQM - ok 23:41:07.0917 6712 MsRPC (dc6ccf440cdede4293db41c37a5060a5) C:\Windows\system32\drivers\MsRPC.sys 23:41:07.0917 6712 MsRPC - ok 23:41:07.0979 6712 mssmbios (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys 23:41:07.0979 6712 mssmbios - ok 23:41:07.0995 6712 MSTEE (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys 23:41:07.0995 6712 MSTEE - ok 23:41:08.0026 6712 Mup (0cc49f78d8aca0877d885f149084e543) C:\Windows\system32\Drivers\mup.sys 23:41:08.0026 6712 Mup - ok 23:41:08.0088 6712 NativeWifiP (2007b826c4acd94ae32232b41f0842b9) C:\Windows\system32\DRIVERS\nwifi.sys 23:41:08.0104 6712 NativeWifiP - ok 23:41:08.0198 6712 NDIS (65950e07329fcee8e6516b17c8d0abb6) C:\Windows\system32\drivers\ndis.sys 23:41:08.0213 6712 NDIS - ok 23:41:08.0322 6712 NdisTapi (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys 23:41:08.0322 6712 NdisTapi - ok 23:41:08.0354 6712 Ndisuio (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys 23:41:08.0354 6712 Ndisuio - ok 23:41:08.0400 6712 NdisWan (f8158771905260982ce724076419ef19) C:\Windows\system32\DRIVERS\ndiswan.sys 23:41:08.0400 6712 NdisWan - ok 23:41:08.0432 6712 NDProxy (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys 23:41:08.0432 6712 NDProxy - ok 23:41:08.0447 6712 NetBIOS (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys 23:41:08.0447 6712 NetBIOS - ok 23:41:08.0510 6712 netbt (fc2c792ebddc8e28df939d6a92c83d61) C:\Windows\system32\DRIVERS\netbt.sys 23:41:08.0510 6712 netbt - ok 23:41:08.0588 6712 nfrd960 (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys 23:41:08.0588 6712 nfrd960 - ok 23:41:08.0650 6712 Npfs (b298874f8e0ea93f06ec40aa8d146478) C:\Windows\system32\drivers\Npfs.sys 23:41:08.0666 6712 Npfs - ok 23:41:08.0712 6712 nsiproxy (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys 23:41:08.0712 6712 nsiproxy - ok 23:41:08.0806 6712 Ntfs (bac869dfb98e499ba4d9bb1fb43270e1) C:\Windows\system32\drivers\Ntfs.sys 23:41:08.0837 6712 Ntfs - ok 23:41:08.0915 6712 Null (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys 23:41:08.0915 6712 Null - ok 23:41:09.0009 6712 NVENETFD (99ed33f7fe39026a477893d92aea5ef0) C:\Windows\system32\DRIVERS\nvmfdx64.sys 23:41:09.0024 6712 NVENETFD - ok 23:41:09.0617 6712 nvlddmkm (b4c176b60e1fba3dc5cbca6a40f8e40f) C:\Windows\system32\DRIVERS\nvlddmkm.sys 23:41:09.0758 6712 nvlddmkm - ok 23:41:09.0851 6712 nvraid (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys 23:41:09.0851 6712 nvraid - ok 23:41:09.0898 6712 nvsmu (76b304c8156779d4d39530118acf1d1a) C:\Windows\system32\DRIVERS\nvsmu.sys 23:41:09.0898 6712 nvsmu - ok 23:41:09.0929 6712 nvstor (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys 23:41:09.0929 6712 nvstor - ok 23:41:09.0960 6712 nv_agp (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys 23:41:09.0960 6712 nv_agp - ok 23:41:09.0976 6712 NwlnkFlt - ok 23:41:09.0976 6712 NwlnkFwd - ok 23:41:10.0054 6712 ohci1394 (b5b1ce65ac15bbd11c0619e3ef7cfc28) C:\Windows\system32\DRIVERS\ohci1394.sys 23:41:10.0054 6712 ohci1394 - ok 23:41:10.0148 6712 Parport (aecd57f94c887f58919f307c35498ea0) C:\Windows\system32\drivers\parport.sys 23:41:10.0148 6712 Parport - ok 23:41:10.0226 6712 partmgr (f9b5eda4c17a2be7663f064dbf0fe254) C:\Windows\system32\drivers\partmgr.sys 23:41:10.0226 6712 partmgr - ok 23:41:10.0257 6712 pci (47ab1e0fc9d0e12bb53ba246e3a0906d) C:\Windows\system32\drivers\pci.sys 23:41:10.0257 6712 pci - ok 23:41:10.0350 6712 pciide (2657f6c0b78c36d95034be109336e382) C:\Windows\system32\drivers\pciide.sys 23:41:10.0350 6712 pciide - ok 23:41:10.0444 6712 pcmcia (037661f3d7c507c9993b7010ceee6288) C:\Windows\system32\drivers\pcmcia.sys 23:41:10.0444 6712 pcmcia - ok 23:41:10.0506 6712 PEAUTH (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys 23:41:10.0522 6712 PEAUTH - ok 23:41:10.0647 6712 PptpMiniport (23386e9952025f5f21c368971e2e7301) C:\Windows\system32\DRIVERS\raspptp.sys 23:41:10.0662 6712 PptpMiniport - ok 23:41:10.0756 6712 Processor (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\drivers\processr.sys 23:41:10.0756 6712 Processor - ok 23:41:10.0818 6712 PSched (c5ab7f0809392d0da027f4a2a81bfa31) C:\Windows\system32\DRIVERS\pacer.sys 23:41:10.0818 6712 PSched - ok 23:41:10.0881 6712 ql2300 (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys 23:41:10.0928 6712 ql2300 - ok 23:41:10.0974 6712 ql40xx (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys 23:41:10.0974 6712 ql40xx - ok 23:41:11.0021 6712 QWAVEdrv (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys 23:41:11.0021 6712 QWAVEdrv - ok 23:41:11.0099 6712 RasAcd (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys 23:41:11.0099 6712 RasAcd - ok 23:41:11.0162 6712 Rasl2tp (ac7bc4d42a7e558718dfdec599bbfc2c) C:\Windows\system32\DRIVERS\rasl2tp.sys 23:41:11.0162 6712 Rasl2tp - ok 23:41:11.0208 6712 RasPppoe (4517fbf8b42524afe4ede1de102aae3e) C:\Windows\system32\DRIVERS\raspppoe.sys 23:41:11.0208 6712 RasPppoe - ok 23:41:11.0286 6712 RasSstp (c6a593b51f34c33e5474539544072527) C:\Windows\system32\DRIVERS\rassstp.sys 23:41:11.0302 6712 RasSstp - ok 23:41:11.0396 6712 rdbss (322db5c6b55e8d8ee8d6f358b2aaabb1) C:\Windows\system32\DRIVERS\rdbss.sys 23:41:11.0396 6712 rdbss - ok 23:41:11.0442 6712 RDPCDD (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys 23:41:11.0458 6712 RDPCDD - ok 23:41:11.0505 6712 rdpdr (c045d1fb111c28df0d1be8d4bda22c06) C:\Windows\system32\drivers\rdpdr.sys 23:41:11.0505 6712 rdpdr - ok 23:41:11.0536 6712 RDPENCDD (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys 23:41:11.0536 6712 RDPENCDD - ok 23:41:11.0692 6712 RDPWD (b1d741c87cea8d7282146366cc9c3f81) C:\Windows\system32\drivers\RDPWD.sys 23:41:11.0692 6712 RDPWD - ok 23:41:11.0770 6712 rimmptsk (ea67debad5eeb97a5003011145b6fd19) C:\Windows\system32\DRIVERS\rimmpx64.sys 23:41:11.0770 6712 rimmptsk - ok 23:41:11.0801 6712 rimsptsk (bb9edc55b0b8cb4fcd713428820e0776) C:\Windows\system32\DRIVERS\rimspx64.sys 23:41:11.0801 6712 rimsptsk - ok 23:41:11.0879 6712 rismxdp (481c3fdeacaae04b74c58288dbc91df9) C:\Windows\system32\DRIVERS\rixdpx64.sys 23:41:11.0879 6712 rismxdp - ok 23:41:11.0926 6712 rspndr (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys 23:41:11.0926 6712 rspndr - ok 23:41:12.0004 6712 sbp2port (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys 23:41:12.0004 6712 sbp2port - ok 23:41:12.0129 6712 sdbus (be100bc2be2513314c717bb2c4cfff10) C:\Windows\system32\DRIVERS\sdbus.sys 23:41:12.0129 6712 sdbus - ok 23:41:12.0222 6712 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 23:41:12.0222 6712 secdrv - ok 23:41:12.0269 6712 Serenum (f71bfe7ac6c52273b7c82cbf1bb2a222) C:\Windows\system32\drivers\serenum.sys 23:41:12.0269 6712 Serenum - ok 23:41:12.0332 6712 Serial (e62fac91ee288db29a9696a9d279929c) C:\Windows\system32\drivers\serial.sys 23:41:12.0332 6712 Serial - ok 23:41:12.0378 6712 sermouse (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys 23:41:12.0378 6712 sermouse - ok 23:41:12.0488 6712 sffdisk (3a19c899bcf0ea24cfec2038e6a489db) C:\Windows\system32\DRIVERS\sffdisk.sys 23:41:12.0488 6712 sffdisk - ok 23:41:12.0534 6712 sffp_mmc (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys 23:41:12.0534 6712 sffp_mmc - ok 23:41:12.0597 6712 sffp_sd (fdca63a2eee528585eb66ceac183ec22) C:\Windows\system32\DRIVERS\sffp_sd.sys 23:41:12.0597 6712 sffp_sd - ok 23:41:12.0628 6712 sfloppy (6b7838c94135768bd455cbdc23e39e5f) C:\Windows\system32\drivers\sfloppy.sys 23:41:12.0628 6712 sfloppy - ok 23:41:12.0690 6712 SiSRaid2 (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys 23:41:12.0706 6712 SiSRaid2 - ok 23:41:12.0768 6712 SiSRaid4 (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys 23:41:12.0768 6712 SiSRaid4 - ok 23:41:12.0846 6712 Smb (290b6f6a0ec4fcdfc90f5cb6d7020473) C:\Windows\system32\DRIVERS\smb.sys 23:41:12.0846 6712 Smb - ok 23:41:12.0940 6712 spldr (386c3c63f00a7040c7ec5e384217e89d) C:\Windows\system32\drivers\spldr.sys 23:41:12.0940 6712 spldr - ok 23:41:13.0049 6712 srv (880a57fccb571ebd063d4dd50e93e46d) C:\Windows\system32\DRIVERS\srv.sys 23:41:13.0065 6712 srv - ok 23:41:13.0112 6712 srv2 (a1ad14a6d7a37891fffeca35ebbb0730) C:\Windows\system32\DRIVERS\srv2.sys 23:41:13.0112 6712 srv2 - ok 23:41:13.0143 6712 srvnet (4bed62f4fa4d8300973f1151f4c4d8a7) C:\Windows\system32\DRIVERS\srvnet.sys 23:41:13.0143 6712 srvnet - ok 23:41:13.0268 6712 swenum (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys 23:41:13.0268 6712 swenum - ok 23:41:13.0299 6712 Symc8xx (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys 23:41:13.0299 6712 Symc8xx - ok 23:41:13.0361 6712 SymIM - ok 23:41:13.0377 6712 SymIMMP - ok 23:41:13.0408 6712 Sym_hi (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys 23:41:13.0424 6712 Sym_hi - ok 23:41:13.0486 6712 Sym_u3 (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys 23:41:13.0486 6712 Sym_u3 - ok 23:41:13.0595 6712 Tcpip (2cc45d932bd193cd4117321d469ad6b2) C:\Windows\system32\drivers\tcpip.sys 23:41:13.0626 6712 Tcpip - ok 23:41:13.0689 6712 Tcpip6 (2cc45d932bd193cd4117321d469ad6b2) C:\Windows\system32\DRIVERS\tcpip.sys 23:41:13.0689 6712 Tcpip6 - ok 23:41:13.0736 6712 tcpipreg (c7e72a4071ee0200e3c075dacfb2b334) C:\Windows\system32\drivers\tcpipreg.sys 23:41:13.0736 6712 tcpipreg - ok 23:41:13.0767 6712 TDPIPE (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys 23:41:13.0767 6712 TDPIPE - ok 23:41:13.0845 6712 TDTCP (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys 23:41:13.0860 6712 TDTCP - ok 23:41:13.0907 6712 tdx (458919c8c42e398dc4802178d5ffee27) C:\Windows\system32\DRIVERS\tdx.sys 23:41:13.0907 6712 tdx - ok 23:41:13.0954 6712 TermDD (8c19678d22649ec002ef2282eae92f98) C:\Windows\system32\DRIVERS\termdd.sys 23:41:13.0970 6712 TermDD - ok 23:41:13.0985 6712 TfFsMon - ok 23:41:14.0001 6712 TfNetMon - ok 23:41:14.0016 6712 TFSysMon - ok 23:41:14.0079 6712 tssecsrv (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys 23:41:14.0079 6712 tssecsrv - ok 23:41:14.0141 6712 tunmp (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys 23:41:14.0141 6712 tunmp - ok 23:41:14.0266 6712 tunnel (30a9b3f45ad081bffc3bcaa9c812b609) C:\Windows\system32\DRIVERS\tunnel.sys 23:41:14.0266 6712 tunnel - ok 23:41:14.0313 6712 uagp35 (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys 23:41:14.0313 6712 uagp35 - ok 23:41:14.0360 6712 udfs (faf2640a2a76ed03d449e443194c4c34) C:\Windows\system32\DRIVERS\udfs.sys 23:41:14.0360 6712 udfs - ok 23:41:14.0422 6712 uliagpkx (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys 23:41:14.0422 6712 uliagpkx - ok 23:41:14.0516 6712 uliahci (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys 23:41:14.0516 6712 uliahci - ok 23:41:14.0578 6712 UlSata (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys 23:41:14.0656 6712 UlSata - ok 23:41:14.0687 6712 ulsata2 (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys 23:41:14.0703 6712 ulsata2 - ok 23:41:14.0750 6712 umbus (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys 23:41:14.0750 6712 umbus - ok 23:41:14.0906 6712 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys 23:41:14.0921 6712 USBAAPL64 - ok 23:41:15.0046 6712 usbccgp (07e3498fc60834219d2356293da0fecc) C:\Windows\system32\DRIVERS\usbccgp.sys 23:41:15.0046 6712 usbccgp - ok 23:41:15.0077 6712 usbcir (9247f7e0b65852c1f6631480984d6ed2) C:\Windows\system32\drivers\usbcir.sys 23:41:15.0077 6712 usbcir - ok 23:41:15.0093 6712 usbehci (827e44de934a736ea31e91d353eb126f) C:\Windows\system32\DRIVERS\usbehci.sys 23:41:15.0093 6712 usbehci - ok 23:41:15.0140 6712 usbhub (bb35cd80a2ececfadc73569b3d70c7d1) C:\Windows\system32\DRIVERS\usbhub.sys 23:41:15.0140 6712 usbhub - ok 23:41:15.0155 6712 usbohci (e406b003a354776d317762694956b0fc) C:\Windows\system32\DRIVERS\usbohci.sys 23:41:15.0155 6712 usbohci - ok 23:41:15.0233 6712 usbprint (28b693b6d31e7b9332c1bdcefef228c1) C:\Windows\system32\DRIVERS\usbprint.sys 23:41:15.0233 6712 usbprint - ok 23:41:15.0327 6712 usbscan (ea0bf666868964fbe8cb10e50c97b9f1) C:\Windows\system32\DRIVERS\usbscan.sys 23:41:15.0327 6712 usbscan - ok 23:41:15.0405 6712 USBSTOR (b854c1558fca0c269a38663e8b59b581) C:\Windows\system32\DRIVERS\USBSTOR.SYS 23:41:15.0405 6712 USBSTOR - ok 23:41:15.0483 6712 usbuhci (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys 23:41:15.0483 6712 usbuhci - ok 23:41:15.0576 6712 usbvideo (fc33099877790d51b0927b7039059855) C:\Windows\system32\Drivers\usbvideo.sys 23:41:15.0576 6712 usbvideo - ok 23:41:15.0639 6712 vga (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys 23:41:15.0639 6712 vga - ok 23:41:15.0686 6712 VgaSave (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys 23:41:15.0686 6712 VgaSave - ok 23:41:15.0732 6712 viaide (8294b6c3fdb6c33f24e150de647ecdaa) C:\Windows\system32\drivers\viaide.sys 23:41:15.0732 6712 viaide - ok 23:41:15.0810 6712 volmgr (2b7e885ed951519a12c450d24535dfca) C:\Windows\system32\drivers\volmgr.sys 23:41:15.0810 6712 volmgr - ok 23:41:15.0888 6712 volmgrx (cec5ac15277d75d9e5dec2e1c6eaf877) C:\Windows\system32\drivers\volmgrx.sys 23:41:15.0904 6712 volmgrx - ok 23:41:15.0966 6712 volsnap (5280aada24ab36b01a84a6424c475c8d) C:\Windows\system32\drivers\volsnap.sys 23:41:15.0966 6712 volsnap - ok 23:41:16.0029 6712 vsmraid (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys 23:41:16.0029 6712 vsmraid - ok 23:41:16.0122 6712 WacomPen (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys 23:41:16.0122 6712 WacomPen - ok 23:41:16.0185 6712 Wanarp (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys 23:41:16.0185 6712 Wanarp - ok 23:41:16.0200 6712 Wanarpv6 (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys 23:41:16.0200 6712 Wanarpv6 - ok 23:41:16.0263 6712 Wd (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys 23:41:16.0263 6712 Wd - ok 23:41:16.0341 6712 Wdf01000 (d02e7e4567da1e7582fbf6a91144b0df) C:\Windows\system32\drivers\Wdf01000.sys 23:41:16.0356 6712 Wdf01000 - ok 23:41:16.0434 6712 winachsf (cbdeb4b3b5cf8c49acc221d45f1c50c1) C:\Windows\system32\DRIVERS\CAX_CNXT.sys 23:41:16.0466 6712 winachsf - ok 23:41:16.0512 6712 WmiAcpi (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\DRIVERS\wmiacpi.sys 23:41:16.0512 6712 WmiAcpi - ok 23:41:16.0559 6712 WpdUsb (5e2401b3fc1089c90e081291357371a9) C:\Windows\system32\DRIVERS\wpdusb.sys 23:41:16.0559 6712 WpdUsb - ok 23:41:16.0653 6712 ws2ifsl (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys 23:41:16.0653 6712 ws2ifsl - ok 23:41:16.0762 6712 WUDFRd (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys 23:41:16.0762 6712 WUDFRd - ok 23:41:16.0840 6712 XAudio (f7c55995b234a8a8791c4a2a62d9ac61) C:\Windows\system32\DRIVERS\xaudio64.sys 23:41:16.0840 6712 XAudio - ok 23:41:16.0918 6712 MBR (0x1B8) (1a1a06f62e891045814007163c1c76c3) \Device\Harddisk0\DR0 23:41:16.0949 6712 \Device\Harddisk0\DR0 - ok 23:41:16.0965 6712 Boot (0x1200) (f9e5db3c76df4feef814066ccc06d8d7) \Device\Harddisk0\DR0\Partition0 23:41:16.0965 6712 \Device\Harddisk0\DR0\Partition0 - ok 23:41:16.0965 6712 Boot (0x1200) (c76173725873215031b30167263f1acc) \Device\Harddisk0\DR0\Partition1 23:41:16.0965 6712 \Device\Harddisk0\DR0\Partition1 - ok 23:41:16.0965 6712 ============================================================ 23:41:16.0965 6712 Scan finished 23:41:16.0965 6712 ============================================================ 23:41:16.0996 7088 Detected object count: 0 23:41:16.0996 7088 Actual detected object count: 0 23:41:50.0630 1140 Deinitialize success

Attachments:

Next, Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications

====================================================


Double click on ComboFix.exe & follow the prompts.


  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
combofix is freezing the computer midway throught the scanning process. I had to force shut down. I removed AVG thinking that could help. Same result. Please let me know what you suggest I do next. Thanks
Hi fernipascual,

Run OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :Files
    C:\Users\Nando\AppData\Local\confobj90
    C:\ProgramData\ux2b0dfc1t117w1mm6c04
    C:\Users\Nando\AppData\Local\ux2b0dfc1t117w1mm6c04
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Hello NoodleTech: Here is the log. Thanks All processes killed ========== FILES ========== C:\Users\Nando\AppData\Local\confobj90 folder moved successfully. C:\ProgramData\ux2b0dfc1t117w1mm6c04 moved successfully. C:\Users\Nando\AppData\Local\ux2b0dfc1t117w1mm6c04 moved successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Nando ->Temp folder emptied: 175001268 bytes ->Temporary Internet Files folder emptied: 117412316 bytes ->Java cache emptied: 96543690 bytes ->Google Chrome cache emptied: 0 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 914 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 22016 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 233528 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 2168416 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 644 bytes RecycleBin emptied: 2534 bytes Total Files Cleaned = 373.00 mb OTL by OldTimer - Version 3.2.31.0 log created on 12312011_171704 Files\Folders moved on Reboot… C:\Users\Nando\AppData\Local\Temp\ehmsas.txt moved successfully. File\Folder C:\Users\Nando\AppData\Local\Temp\~DF176.tmp not found! File\Folder C:\Users\Nando\AppData\Local\Temp\~DF1B7.tmp not found! File\Folder C:\Users\Nando\AppData\Local\Temp\~DF9D.tmp not found! File\Folder C:\Users\Nando\AppData\Local\Temp\~DFA3.tmp not found! C:\Users\Nando\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VM0NHTZJ\index[1].htm moved successfully. C:\Users\Nando\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JWV99CCK\s-BiyweUPV0v-yRb-cjciFQlYEbsez9cZjKsNMjLOwM[1].eot moved successfully. C:\Users\Nando\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\H9XC3IHD\iframe[1].htm moved successfully. C:\Users\Nando\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\EXBZ4AYZ\APH4jr0uSos5wiut5cpjrnZ2MAKAc2x4R1uOSeegc5U[1].eot moved successfully. C:\Users\Nando\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\EXBZ4AYZ\embed[1].htm moved successfully. C:\Users\Nando\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5AQAXFX6\calendars[1].htm moved successfully. C:\Users\Nando\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5AQAXFX6\mG3vnf_-L6iZJRUt2i1SMg[1].eot moved successfully. C:\Users\Nando\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5AQAXFX6\plusone_gadget[1].htm moved successfully. C:\Users\Nando\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2O0DIDWL\fastbutton[3].htm moved successfully. C:\Users\Nando\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. C:\Users\Nando\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully. File move failed. C:\Windows\SysNative\OLDB935.tmp scheduled to be moved on reboot. Registry entries deleted on Reboot…
As it's going throught the scan process it also freezes at a point that says the output is on c:\32788R22FWJFW but when I go to c: it's not a file. Doubleclicking on the name, opens up a new window of c: I've attached a screenshot.
Hi fernipascual, Sorry, I should have clarified that for you. Happy new year :)!! I need you to open Malwarebytes Antimalware, update it, run a quick scan, remove found threats, then post the log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI