This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus locked computer [Solved]

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I opened an email (I thought I was expecting) saved download and scanned and nothing suspicious. The only other thing I downloaded earlier was google earth. Then a few minutes later I got pop ups saying infected and the popup went on to scan and find issues, I think this was part of the virus. My desktop stopped working so went in to safe mode via administrator and started to run Avira while scanning it picked up (similar to this wording) Worm autorun TR/spy agent bvnf And then my administrator desktop locked me out. I shut down re booted in safe mode and done a system restore and so far its working but have not gone into other desktop and staying with administrator desktop. results of scan….. . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 8.0.7601.17514 Run by [removed] at 23:50:26 on 2012-01-08 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.1965.909 [GMT 0:00] . AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt C:\Windows\System32\svchost.exe -k HPZ12 C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Program Files (x86)\Splashtop\Splashtop Connect\BackService.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\viakaraokesrv.exe C:\Program Files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe C:\Program Files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe C:\Windows\system32\svchost.exe -k HPService C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\svchost.exe -k swprv C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\sysWOW64\wbem\wmiprvse.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\Macromed\Flash\FlashUtil64_11_1_102_ActiveX.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\REGSVR32.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.starwebsearch.com/index.php?from=3 uURLSearchHooks: H - No File uURLSearchHooks: H - No File mURLSearchHooks: H - No File mWinlogon: Userinit=userinit.exe BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll mRun: [STCAgent] "C:\Program Files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe" mRun: [ZyngaGamesAgent] "C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" mRun: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun: [] StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Free YouTube to MP3 Converter - C:\Users\Colin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{070085F9-871D-440C-8055-CB166F23C919} : DhcpNameServer = [removed] [removed] Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll BHO-X64: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO-X64: 0x1 - No File TB-X64: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File mRun-x64: [STCAgent] "C:\Program Files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe" mRun-x64: [ZyngaGamesAgent] "C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" mRun-x64: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r mRun-x64: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min mRun-x64: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" mRun-x64: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun-x64: [(Default)] SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll . ============= SERVICES / DRIVERS =============== . R1 AppleCharger;AppleCharger;C:\Windows\system32\DRIVERS\AppleCharger.sys –> C:\Windows\system32\DRIVERS\AppleCharger.sys [?] R1 avkmgr;avkmgr;C:\Windows\system32\DRIVERS\avkmgr.sys –> C:\Windows\system32\DRIVERS\avkmgr.sys [?] R2 avgntflt;avgntflt;C:\Windows\system32\DRIVERS\avgntflt.sys –> C:\Windows\system32\DRIVERS\avgntflt.sys [?] R2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [2011-10-25 341288] R2 SCBackService;Splashtop Connect Service;C:\Program Files (x86)\Splashtop\Splashtop Connect\BackService.exe [2010-11-15 477000] R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-10-24 2655768] R2 VIAKaraokeService;VIA Karaoke digital mixer Service;C:\Windows\system32\viakaraokesrv.exe –> C:\Windows\system32\viakaraokesrv.exe [?] R2 WCUService_STC_FF;Splashtop Connect Firefox Software Updater Service;C:\Program Files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [2011-3-24 493384] R2 WCUService_STC_IE;Splashtop Connect IE Software Updater Service;C:\Program Files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe [2011-3-22 497480] R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1C62x64.sys –> C:\Windows\system32\DRIVERS\L1C62x64.sys [?] R3 MEIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys –> C:\Windows\system32\DRIVERS\HECIx64.sys [?] R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\system32\drivers\viahduaa.sys –> C:\Windows\system32\drivers\viahduaa.sys [?] S2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2011-10-28 86224] S2 AntiVirService;Avira Realtime Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2011-10-28 110032] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe –> system32\AppleChargerSrv.exe [?] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys –> C:\Windows\system32\drivers\TsUsbGD.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?] . =============== Created Last 30 ================ . 2012-01-08 23:46:29 69000 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9E5C25B9-59AC-4550-B5AB-200180DC8E68}\offreg.dll 2012-01-08 23:46:26 8822856 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9E5C25B9-59AC-4550-B5AB-200180DC8E68}\mpengine.dll 2011-12-16 23:41:51 ——– d—–w- C:\Users\Colin\AppData\Roaming\HpUpdate 2011-12-16 23:41:49 ——– d—–w- C:\Windows\Hewlett-Packard . ==================== Find3M ==================== . 2011-11-24 04:52:09 3145216 —-a-w- C:\Windows\System32\win32k.sys 2011-11-20 13:36:25 414368 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-11-05 05:41:43 1188864 —-a-w- C:\Windows\System32\wininet.dll 2011-11-05 05:32:50 2048 —-a-w- C:\Windows\System32\tzres.dll 2011-11-05 04:35:00 981504 —-a-w- C:\Windows\SysWow64\wininet.dll 2011-11-05 04:26:03 2048 —-a-w- C:\Windows\SysWow64\tzres.dll 2011-11-05 03:32:47 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2011-11-05 02:48:51 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-10-26 05:21:20 43520 —-a-w- C:\Windows\System32\csrsrv.dll 2011-10-25 15:50:32 17192 —-a-w- C:\Windows\System32\nitrolocalui2.dll 2011-10-25 15:50:30 28968 —-a-w- C:\Windows\System32\nitrolocalmon2.dll 2011-10-19 15:56:50 27760 —-a-w- C:\Windows\System32\drivers\avkmgr.sys 2011-10-19 15:56:49 97312 —-a-w- C:\Windows\System32\drivers\avgntflt.sys 2011-10-19 13:16:42 49152 —-a-r- C:\Windows\SysWow64\inetwh32.dll 2011-10-19 13:16:42 1044480 —-a-r- C:\Windows\SysWow64\roboex32.dll 2011-10-15 06:31:56 723456 —-a-w- C:\Windows\System32\EncDec.dll 2011-10-15 05:38:59 534528 —-a-w- C:\Windows\SysWow64\EncDec.dll . ============= FINISH: 23:57:23.07 ===============
Hello scudo and welcome back to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

==================================================

Please send the other part of the log, Attach.txt.

Thanks

Satchfan
Thank you for taking my case, to update you I ran adware scan yesterday and it quarantined the items below. Quarantined items: Description: c:\program files (x86)\yontoo layers runtime\yontooieclient.dll Family Name: Win32.Trojan.Agent Engine: 1 Clean status: Success Item ID: 0 Family ID: 936 MD5: c650f1d0aa6d26a2354ba3517bef5817 Description: c:\programdata\tarma installer\{889df117-14d1-44ee-9f31-c5fb5d47f68b}\_setupx.dll Family Name: Yontoo Engine: 3 Clean status: Success Item ID: 2 Family ID: 0 MD5: 809dc8341e40993d7cf3d2d2d0a4087f Scan and cleaning complete: Finished correctly after 2719 seconds
OK, I’ll ask for the Attach log later, if needed.

Meanwhile, please do the following:

Download and run OTL
  • download OTL to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • when the window appears, underneath Output at the top change it to Minimal Output.
  • check the boxes beside LOP Check and Purity Check.
  • under Custom Scan paste this in


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %appdata%\Microsoft\Windows\Start Menu\*.* /s
    %programdata%\Microsoft\Windows\Start Menu\*.* /s

  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • you may need two posts to fit them both in.
===================================================

Run aswMBR

Download aswMBR.exe to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
🖼Click to load external image (Posted Image)

On completion of the scan click save log, save it to your desktop and post in your next reply
🖼Click to load external image (Posted Image)

Logs to include with next post:

OTL.txt
Extras.txt
aswMBR log


I have to go out on business now so probably won't reply again until later today.

Thanks

Satchfan
OTL text……

OTL logfile created on: 13/01/2012 10:25:30 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Stan\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.92 Gb Total Physical Memory | 0.96 Gb Available Physical Memory | 49.98% Memory free
3.84 Gb Paging File | 2.61 Gb Available in Paging File | 68.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 870.39 Gb Free Space | 93.45% Space Free | Partition Type: NTFS
Drive D: | 245.97 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: SMITH | User Name: Colin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Stan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Messaging)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe (Splashtop Inc.)
PRC - C:\Program Files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe (Splashtop Inc.)
PRC - C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe (Splashtop Inc.)
PRC - C:\Program Files (x86)\Splashtop\Splashtop Connect\BackService.exe (Splashtop Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll ()
MOD - C:\Program Files (x86)\Mozilla Thunderbird\nsldap32v60.dll ()
MOD - C:\Program Files (x86)\Mozilla Thunderbird\nsldappr32v60.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (NitroReaderDriverReadSpool2) – C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe (Nitro PDF Software)
SRV:64bit: - (VIAKaraokeService) – C:\Windows\SysNative\ViakaraokeSrv.exe (VIA Technologies, Inc.)
SRV:64bit: - (AppleChargerSrv) – C:\Windows\SysNative\AppleChargerSrv.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (AntiVirSchedulerService) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (WCUService_STC_FF) – C:\Program Files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe (Splashtop Inc.)
SRV - (WCUService_STC_IE) – C:\Program Files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe (Splashtop Inc.)
SRV - (SCBackService) – C:\Program Files (x86)\Splashtop\Splashtop Connect\BackService.exe (Splashtop Inc.)
SRV - (HPSLPSVC) – C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:64bit: - (avkmgr) – C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH)
DRV:64bit: - (avipbb) – C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) – C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (AppleCharger) – C:\Windows\SysNative\drivers\AppleCharger.sys ()
DRV:64bit: - (VIAHdAudAddService) – C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (Lavasoft Kernexplorer) – C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {2877A654-1C9F-4cb5-8438-16022B2FDD9C} - No CLSID value found

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E0 E9 75 A5 9C 95 CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {2877A654-1C9F-4cb5-8438-16022B2FDD9C} - No CLSID value found
IE - HKCU\..\URLSearchHook: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF: C:\Program Files (x86)\Nitro PDF\Reader 2\npnitromozilla.dll ( )

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{91c612bf-2a7a-48b8-8c8c-6de28589b7a1}: C:\Program Files (x86)\Splashtop\Splashtop Connect for Firefox\{91c612bf-2a7a-48b8-8c8c-6de28589b7a1} [2011/10/24 11:06:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{91c612bf-2a7a-48b8-8c8c-6de28589b7a0}: C:\Program Files (x86)\Splashtop\Splashtop Connect for Firefox\{91c612bf-2a7a-48b8-8c8c-6de28589b7a0} [2011/10/24 11:06:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{d9284e50-81fc-11da-a72b-0800200c9a66}: C:\Program Files (x86)\Splashtop\Splashtop Connect for Firefox\{d9284e50-81fc-11da-a72b-0800200c9a66} [2011/10/24 11:06:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/10/28 19:26:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011/12/12 18:31:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins


O1 HOSTS File: ([2009/06/10 21:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [STCAgent] C:\Program Files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe (Splashtop Inc.)
O4 - HKLM..\Run: [ZyngaGamesAgent] C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe (Splashtop Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Colin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8:64bit: - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Colin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{070085F9-871D-440C-8055-CB166F23C919}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/07/30 03:07:12 | 000,000,038 | R— | M] () - D:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{7e6ae660-fe6d-11e0-b519-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{7e6ae660-fe6d-11e0-b519-806e6f6e6963}\Shell\AutoRun\command - "" = D:\LGE.EXE – [2009/12/30 20:24:26 | 003,892,532 | R— | M] (Macromedia, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/01/12 14:04:53 | 000,055,384 | —- | C] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2012/01/12 14:02:39 | 000,069,376 | —- | C] (Lavasoft AB) – C:\Windows\SysNative\drivers\Lbd.sys
[2012/01/12 14:02:39 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2012/01/12 14:02:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
[2012/01/12 14:02:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lavasoft
[2012/01/12 14:02:28 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2012/01/11 21:17:36 | 000,000,000 | —D | C] – C:\Users\Colin\Desktop\GooredFix Backups
[2012/01/11 21:16:37 | 001,572,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\quartz.dll
[2012/01/11 21:16:36 | 001,328,128 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\quartz.dll
[2012/01/11 21:16:36 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2012/01/11 21:16:36 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2012/01/11 21:16:33 | 000,918,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/01/11 21:16:33 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/01/11 21:16:31 | 001,731,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2012/01/11 21:16:29 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\packager.dll
[2012/01/11 21:16:29 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\packager.dll
[2012/01/11 21:06:09 | 000,000,000 | —D | C] – C:\Users\Colin\AppData\Local\ElevatedDiagnostics
[2011/12/25 09:45:26 | 000,000,000 | —D | C] – C:\Users\Colin\AppData\Roaming\Nitro PDF
[2011/12/16 23:41:51 | 000,000,000 | —D | C] – C:\Users\Colin\AppData\Roaming\HpUpdate
[2011/12/16 23:41:49 | 000,000,000 | —D | C] – C:\Windows\Hewlett-Packard
[2011/12/15 09:18:54 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2011/12/15 09:18:48 | 000,702,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/12/15 09:18:48 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/12/15 09:18:48 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/12/15 09:18:48 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/12/15 09:18:48 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/12/15 09:18:48 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/12/15 09:18:47 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/12/15 09:18:44 | 000,723,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/12/15 09:18:44 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll

========== Files - Modified Within 30 Days ==========

[2012/01/13 08:34:12 | 000,022,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/13 08:34:12 | 000,022,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/13 08:31:15 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/01/13 08:31:15 | 000,628,024 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/01/13 08:31:15 | 000,110,208 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/01/13 08:27:01 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/01/13 08:27:00 | 1545,674,752 | -HS- | M] () – C:\hiberfil.sys
[2012/01/12 14:04:53 | 000,055,384 | —- | M] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2012/01/12 14:04:52 | 000,016,432 | —- | M] () – C:\Windows\SysNative\lsdelete.exe
[2012/01/12 14:02:40 | 000,001,060 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2012/01/08 23:49:59 | 000,607,260 | R— | M] (Swearware) – C:\Users\Colin\Desktop\dds.scr
[2012/01/08 23:18:13 | 000,000,448 | —- | M] () – C:\ProgramData\yOXIZiPZMCY1Ej
[2012/01/08 23:15:26 | 000,000,296 | —- | M] () – C:\ProgramData\~yOXIZiPZMCY1Ej
[2012/01/08 23:15:26 | 000,000,200 | —- | M] () – C:\ProgramData\~yOXIZiPZMCY1Ejr
[2011/12/25 00:28:00 | 000,000,326 | —- | M] () – C:\Users\Colin\Desktop\HP Printer Diagnostic Tools.url
[2011/12/23 07:12:12 | 000,069,376 | —- | M] (Lavasoft AB) – C:\Windows\SysNative\drivers\Lbd.sys
[2011/12/15 12:54:13 | 000,414,040 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2012/01/12 15:02:50 | 000,016,432 | —- | C] () – C:\Windows\SysNative\lsdelete.exe
[2012/01/12 14:02:40 | 000,001,060 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2012/01/08 23:15:26 | 000,000,296 | —- | C] () – C:\ProgramData\~yOXIZiPZMCY1Ej
[2012/01/08 23:15:26 | 000,000,200 | —- | C] () – C:\ProgramData\~yOXIZiPZMCY1Ejr
[2012/01/08 23:15:22 | 000,000,448 | —- | C] () – C:\ProgramData\yOXIZiPZMCY1Ej
[2011/12/25 00:28:00 | 000,000,326 | —- | C] () – C:\Users\Colin\Desktop\HP Printer Diagnostic Tools.url
[2011/10/28 19:20:46 | 000,221,537 | —- | C] () – C:\Windows\hpoins19.dat
[2011/10/28 19:20:46 | 000,013,898 | —- | C] () – C:\Windows\hpomdl19.dat
[2011/10/24 11:10:06 | 000,008,192 | —- | C] () – C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2011/10/24 11:07:53 | 000,056,832 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2011/10/24 11:07:52 | 013,356,032 | —- | C] () – C:\Windows\SysWow64\ig4icd32.dll
[2011/10/24 11:07:52 | 000,963,116 | —- | C] () – C:\Windows\SysWow64\igkrng600.bin
[2011/10/24 11:07:52 | 000,218,304 | —- | C] () – C:\Windows\SysWow64\igfcg600m.bin
[2011/10/24 11:07:52 | 000,145,804 | —- | C] () – C:\Windows\SysWow64\igcompkrng600.bin
[2011/10/24 11:04:52 | 000,000,010 | —- | C] () – C:\Windows\GSetup.ini
[2009/08/27 07:04:14 | 000,207,400 | R— | C] () – C:\Windows\GSetup.exe
[2009/07/14 05:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 02:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 02:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/14 00:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 23:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 21:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 21:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/10/31 15:01:36 | 000,000,000 | —D | M] – C:\Users\Colin\AppData\Roaming\Azureus
[2011/11/01 15:50:53 | 000,000,000 | —D | M] – C:\Users\Colin\AppData\Roaming\DVDVideoSoft
[2011/11/01 15:50:47 | 000,000,000 | —D | M] – C:\Users\Colin\AppData\Roaming\DVDVideoSoftIEHelpers
[2011/12/25 09:45:26 | 000,000,000 | —D | M] – C:\Users\Colin\AppData\Roaming\Nitro PDF
[2011/10/24 11:06:25 | 000,000,000 | —D | M] – C:\Users\Colin\AppData\Roaming\Splashtop
[2009/07/14 05:08:49 | 000,029,796 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2012/01/13 08:26:57 | 000,000,489 | —- | M] () – C:\aaw7boot.log
[2011/10/24 11:10:33 | 000,000,180 | —- | M] () – C:\csb.log
[2012/01/13 08:27:00 | 1545,674,752 | -HS- | M] () – C:\hiberfil.sys
[2011/10/31 09:32:26 | 000,000,319 | —- | M] () – C:\hide fold back up.fhf
[2011/10/28 19:49:38 | 000,000,400 | —- | M] () – C:\InstallHelper.log
[2012/01/13 08:27:00 | 2060,902,400 | -HS- | M] () – C:\pagefile.sys
[2012/01/11 21:20:25 | 000,073,624 | —- | M] () – C:\TDSSKiller.2.7.0.0_11.01.2012_21.19.41_log.txt

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 04:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/10/28 17:50:39 | 000,000,221 | -HS- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< %appdata%\Microsoft\Windows\Start Menu\*.* /s >
[2011/10/24 10:29:28 | 000,000,174 | -HS- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
[2011/10/28 18:05:33 | 000,000,696 | -HS- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
[2011/10/24 10:29:29 | 000,001,409 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011/10/24 10:29:29 | 000,001,443 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/10/28 18:05:33 | 000,001,422 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Social Games.lnk
[2009/07/14 04:54:27 | 000,001,280 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk
[2009/07/14 04:54:32 | 000,000,678 | -HS- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
[2009/07/14 04:54:32 | 000,001,304 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk
[2009/07/14 04:49:38 | 000,000,262 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk
[2009/07/14 04:49:38 | 000,001,228 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk
[2009/07/14 04:54:02 | 000,000,704 | -HS- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
[2009/07/14 04:54:01 | 000,001,358 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk
[2009/07/14 04:54:00 | 000,001,258 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk
[2009/07/14 04:54:02 | 000,001,262 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk
[2009/07/14 04:54:00 | 000,001,250 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk
[2009/07/14 04:49:38 | 000,000,262 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk
[2009/07/14 04:49:38 | 000,000,262 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk
[2011/10/24 10:29:29 | 000,000,738 | -HS- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
[2011/10/24 10:29:29 | 000,001,493 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
[2009/07/14 04:54:59 | 000,001,306 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk
[2011/10/24 10:29:28 | 000,000,174 | -HS- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
[2011/10/28 22:08:13 | 000,002,333 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Karen's Power Tools\Replicator.lnk
[2009/07/14 04:49:38 | 000,000,318 | -HS- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
[2009/07/14 04:49:38 | 000,000,262 | —- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Help.lnk
[2011/10/24 10:29:28 | 000,000,174 | -HS- | M] () – C:\Users\Colin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini

< %programdata%\Microsoft\Windows\Start Menu\*.* /s >
[2009/07/14 05:01:14 | 000,001,282 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
[2009/07/14 05:01:14 | 000,000,442 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
[2011/10/28 19:25:24 | 000,001,321 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\HP Solution Center.lnk
[2009/07/14 04:49:40 | 000,001,266 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
[2011/10/24 18:27:13 | 000,001,130 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
[2011/10/24 11:09:03 | 000,001,214 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD VDeck.lnk
[2011/10/28 19:25:35 | 000,001,054 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR Registration.lnk
[2011/10/24 18:27:11 | 000,001,345 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/11/11 10:17:12 | 000,002,098 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
[2011/11/03 22:45:37 | 000,002,507 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nitro Reader 2.lnk
[2009/07/14 04:57:08 | 000,001,330 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
[2009/07/14 04:57:09 | 000,001,352 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
[2011/10/24 18:27:13 | 000,001,326 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2009/07/14 04:54:59 | 000,001,210 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
[2010/11/21 03:40:30 | 000,001,547 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2009/07/14 04:57:08 | 000,001,246 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
[2009/07/14 04:55:00 | 000,001,230 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk
[2011/10/24 18:27:10 | 000,001,726 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
[2009/07/14 04:54:23 | 000,001,266 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\displayswitch.lnk
[2011/10/24 18:27:06 | 000,001,364 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk
[2011/10/24 18:27:05 | 000,001,238 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk
[2009/07/14 04:54:32 | 000,001,242 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk
[2009/07/14 04:53:55 | 000,001,367 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk
[2011/10/24 18:27:10 | 000,001,272 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk
[2009/07/14 04:57:08 | 000,001,330 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk
[2011/10/24 18:27:10 | 000,001,351 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk
[2009/07/14 04:54:58 | 000,001,254 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sync Center.lnk
[2009/07/14 04:57:09 | 000,001,579 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk
[2009/07/14 04:54:58 | 000,001,322 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk
[2009/07/14 04:57:07 | 000,000,370 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
[2009/07/14 04:57:07 | 000,001,388 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Speech Recognition.lnk
[2009/07/14 04:55:00 | 000,001,248 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk
[2009/07/14 04:57:09 | 000,001,338 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
[2009/07/14 04:54:25 | 000,001,290 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\dfrgui.lnk
[2009/07/14 04:54:58 | 000,001,252 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk
[2009/07/14 04:53:50 | 000,001,242 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Resource Monitor.lnk
[2009/07/14 04:53:33 | 000,001,250 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Information.lnk
[2009/07/14 04:54:57 | 000,001,246 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Restore.lnk
[2009/07/14 04:54:29 | 000,001,268 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Task Scheduler.lnk
[2009/07/14 04:57:09 | 000,001,320 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer Reports.lnk
[2009/07/14 04:57:09 | 000,001,316 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer.lnk
[2011/10/24 18:27:13 | 000,000,343 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Desktop.ini
[2011/10/24 18:27:13 | 000,001,436 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\ShapeCollector.lnk
[2011/10/24 18:27:11 | 000,001,386 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\TabTip.lnk
[2011/10/24 18:27:06 | 000,001,316 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk
[2009/07/14 04:57:13 | 000,000,216 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini
[2009/07/14 05:32:31 | 000,001,989 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell (x86).lnk
[2009/07/14 04:57:13 | 000,001,468 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE (x86).lnk
[2009/07/14 04:57:13 | 000,001,468 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE.lnk
[2009/07/14 05:32:31 | 000,001,899 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
[2009/07/14 04:57:13 | 000,001,242 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk
[2009/07/14 04:54:21 | 000,001,294 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk
[2009/07/14 04:53:52 | 000,001,270 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Data Sources (ODBC).lnk
[2009/07/14 04:57:13 | 000,001,674 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
[2009/07/14 04:54:29 | 000,001,298 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk
[2009/07/14 04:54:22 | 000,001,274 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk
[2009/07/14 04:53:33 | 000,001,268 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk
[2011/10/29 15:49:41 | 000,001,539 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Microsoft .NET Framework 2.0 Configuration.lnk
[2009/07/14 04:53:50 | 000,001,232 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk
[2009/07/14 04:54:05 | 000,001,288 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 04:53:33 | 000,001,246 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk
[2009/07/14 04:54:29 | 000,001,262 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk
[2009/07/14 04:53:58 | 000,001,274 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk
[2009/07/14 05:32:31 | 000,002,741 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell Modules.lnk
[2011/10/29 18:26:52 | 000,001,269 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat 4.0\Acrobat Reader 4.0.lnk
[2011/10/29 18:26:52 | 000,001,034 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat 4.0\Uninstall Adobe Acrobat 4.0.lnk
[2011/10/29 18:28:42 | 000,001,184 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe\Photoshop 6.0\Adobe ImageReady 3.0.lnk
[2011/10/29 18:28:42 | 000,001,174 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe\Photoshop 6.0\Adobe Photoshop 6.0.lnk
[2011/10/28 18:28:50 | 000,002,067 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Desktop\Avira Free Antivirus Help.lnk
[2011/10/28 18:28:50 | 000,002,083 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Desktop\Avira on the Internet.lnk
[2011/10/28 18:28:50 | 000,001,200 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Desktop\Display readme.lnk
[2011/10/28 18:28:50 | 000,002,090 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Desktop\Start Avira Free Antivirus.lnk
[2011/10/31 09:38:21 | 000,000,082 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner Homepage.url
[2011/10/31 09:38:21 | 000,000,840 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner.lnk
[2011/10/31 09:38:21 | 000,000,603 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\Uninstall CCleaner.lnk
[2011/11/01 15:50:42 | 000,001,237 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Fix components.lnk
[2011/11/01 15:50:42 | 000,001,257 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Free Studio Manager.lnk
[2011/11/01 15:50:42 | 000,001,347 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Rocket Subscription.lnk
[2011/11/01 15:50:42 | 000,001,217 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Uninstall.lnk
[2011/11/01 15:50:41 | 000,001,319 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Programs\Free Audio CD Burner.lnk
[2011/11/01 15:50:42 | 000,001,422 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Programs\Free YouTube to MP3 Converter.lnk
[2011/10/28 19:48:55 | 000,002,061 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay\eBay Turbo Lister 2.lnk
[2011/10/31 08:40:12 | 000,001,031 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Hide Folder\Free Hide Folder Homepage.lnk
[2011/10/31 08:40:12 | 000,000,982 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Hide Folder\Free Hide Folder.lnk
[2011/10/31 08:40:12 | 000,000,989 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Hide Folder\Uninstall Free Hide Folder.lnk
[2011/10/24 18:27:06 | 000,000,352 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Chess.lnk
[2011/10/24 18:27:06 | 000,001,128 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Desktop.ini
[2009/07/14 04:55:00 | 000,000,364 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\FreeCell.lnk
[2009/07/14 04:54:59 | 000,000,258 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\GameExplorer.lnk
[2009/07/14 04:57:12 | 000,000,356 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Hearts.lnk
[2011/10/24 18:27:06 | 000,000,474 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Internet Backgammon.lnk
[2011/10/24 18:27:05 | 000,000,470 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Internet Checkers.lnk
[2011/10/24 18:27:06 | 000,000,466 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Internet Spades.lnk
[2011/10/24 18:27:06 | 000,000,360 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Mahjong.lnk
[2009/07/14 04:57:12 | 000,000,376 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Minesweeper.lnk
[2009/07/14 04:57:12 | 000,000,370 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\More Games from Microsoft.lnk
[2009/07/14 04:57:12 | 000,000,378 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Purble Place.lnk
[2009/07/14 04:55:01 | 000,000,368 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Solitaire.lnk
[2009/07/14 04:57:12 | 000,000,392 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Spider Solitaire.lnk
[2011/10/28 19:25:24 | 000,001,333 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Solution Center.lnk
[2011/12/16 23:42:02 | 000,002,109 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Update.lnk
[2011/10/28 19:25:18 | 000,001,055 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\Shop for HP Supplies.lnk
[2011/10/28 19:26:02 | 000,002,189 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Photosmart Essential 3.5\HP Photosmart Essential 3.5.lnk
[2011/10/28 19:26:02 | 000,002,363 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Photosmart Essential 3.5\Uninstall HP Photosmart Essential 3.5.lnk
[2011/10/28 19:26:13 | 000,002,421 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Smart Web Printing\HP Smart Web Printing Help.lnk
[2011/10/28 19:29:00 | 000,001,329 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\PSC All-In-One 1310 series\Add A Device.lnk
[2011/10/28 19:29:00 | 000,000,950 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\PSC All-In-One 1310 series\Help.lnk
[2011/10/28 19:29:00 | 000,001,119 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\PSC All-In-One 1310 series\Product Registration.lnk
[2011/10/28 19:29:00 | 000,001,349 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\PSC All-In-One 1310 series\Product Support Website.lnk
[2011/10/28 19:29:00 | 000,001,234 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\PSC All-In-One 1310 series\Readme.lnk
[2011/10/28 19:29:00 | 000,001,522 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\PSC All-In-One 1310 series\Uninstall.lnk
[2011/10/24 11:10:12 | 000,000,103 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel\desktop.ini
[2011/10/24 11:10:12 | 000,001,427 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel\Intel Control Center.lnk
[2011/10/31 09:37:18 | 000,002,315 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Karen's Power Tools\Replicator.lnk
[2012/01/12 14:02:40 | 000,002,014 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Ad-Aware Manual.lnk
[2012/01/12 14:02:40 | 000,002,055 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Ad-Aware Update.lnk
[2012/01/12 14:02:40 | 000,001,084 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Ad-Aware.lnk
[2012/01/12 14:02:40 | 000,002,093 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Lavasoft Homepage.lnk
[2012/01/12 14:02:40 | 000,000,950 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Uninstall Ad-Aware.lnk
[2012/01/12 14:02:40 | 000,001,858 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Toolbox\ThreatWork.lnk
[2009/07/14 04:57:07 | 000,001,304 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Backup and Restore Center.lnk
[2009/07/14 04:57:07 | 000,001,248 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Create Recovery Disc.lnk
[2009/07/14 04:57:09 | 000,000,606 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
[2009/07/14 04:57:09 | 000,001,212 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Remote Assistance.lnk
[2011/10/31 00:31:35 | 000,002,643 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Access 2007.lnk
[2011/10/29 15:49:40 | 000,002,655 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Excel 2007.lnk
[2011/10/29 15:49:41 | 000,002,697 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Groove 2007.lnk
[2011/10/31 00:32:11 | 000,002,687 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office InfoPath 2007.lnk
[2011/10/29 15:49:41 | 000,002,619 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office OneNote 2007.lnk
[2011/10/29 15:49:41 | 000,002,693 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Outlook 2007.lnk
[2011/10/29 15:49:41 | 000,002,645 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office PowerPoint 2007.lnk
[2011/10/29 15:49:41 | 000,002,611 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Publisher 2007.lnk
[2011/10/29 15:49:41 | 000,002,693 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Word 2007.lnk
[2011/10/29 15:49:41 | 000,002,647 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Digital Certificate for VBA Projects.lnk
[2011/10/29 15:49:41 | 000,002,627 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Clip Organizer.lnk
[2011/10/29 15:49:41 | 000,002,527 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2007 Language Settings.lnk
[2011/10/29 15:49:41 | 000,002,625 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Diagnostics.lnk
[2011/10/29 15:49:41 | 000,002,605 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Picture Manager.lnk
[2011/10/29 15:45:29 | 000,001,273 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2005\Visual Studio Tools\Visual Studio 2005 Remote Debugger Configuration Wizard.lnk
[2011/10/29 18:28:43 | 000,001,253 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
[2009/07/14 04:54:24 | 000,000,174 | -HS- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
[2011/10/28 19:24:56 | 000,002,099 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2011/11/02 08:59:37 | 000,002,000 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Downloader\Uninstall.lnk
[2011/11/02 08:59:37 | 000,000,063 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Downloader\Web site.url
[2011/11/02 08:59:37 | 000,000,072 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Downloader\YouTube Downloader Help.url
[2011/11/02 08:59:37 | 000,002,056 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Downloader\YouTube Downloader.lnk

< End of report >
OTL extras…….

OTL Extras logfile created on: 13/01/2012 10:25:30 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Stan\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.92 Gb Total Physical Memory | 0.96 Gb Available Physical Memory | 49.98% Memory free
3.84 Gb Paging File | 2.61 Gb Available in Paging File | 68.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 870.39 Gb Free Space | 93.45% Space Free | Partition Type: NTFS
Drive D: | 245.97 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: SMITH | User Name: Colin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64
"{5CF37F1F-7C84-421C-8E7A-C8859CCFEBD3}" = Nitro Reader 2
"{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers Runtime 1.10.01
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{B61ED343-0B14-4241-999C-490CB1A20DA4}" = HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"CCleaner" = CCleaner
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.51
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Shop for HP Supplies" = Shop for HP Supplies

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{09F25F86-F957-4051-8AB2-0E0D948BBB5D}" = 1310
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{104066F4-5897-4067-85D3-4C88B67CCF75}" = AIO_Scan
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 3.4
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{3B983EFD-6E37-4AD9-9A7D-8C83E61674F7}" = Splashtop Connect IE
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{3DECD372-76A1-4483-BF10-B547790A3261}" = ON_OFF Charge B11.0110.1
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{45D49CA7-D7D8-4659-B35A-EBD98C30AF28}" = Splashtop Connect for Firefox
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6D4553DF-2095-4D10-92C0-17934733B51D}" = 1310_Help
"{6D7E031C-4C05-4265-854A-FE9FDEA9984D}" = 1310Trb
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{8927E07C-97F7-4A54-88FB-D976F50DD46E}" = Turbo Lister 2
"{8E9976D2-E563-43DE-A51F-5AEBC38D1F08}" = Ad-Aware
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9F6B13E2-B93F-4203-9BD4-5DC18C9F9DEB}" = AIO_CDB_Software
"{ACEB2BAF-96DF-48FD-ADD5-43842D4C443D}" = Adobe AIR
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"Adobe Acrobat 4.0" = Adobe Acrobat 4.0
"Adobe AIR" = Adobe AIR
"Adobe Photoshop 6.0" = Adobe Photoshop 6.0
"Adobe SVG Viewer" = Adobe SVG Viewer
"Avira AntiVir Desktop" = Avira Free Antivirus
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Free Hide Folder" = Free Hide Folder
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.11.923
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"Karen's Replicator" = Karen's Replicator
"Mozilla Thunderbird 9.0.1 (x86 en-GB)" = Mozilla Thunderbird 9.0.1 (x86 en-GB)
"VLC media player" = VLC media player 1.1.11

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 09/01/2012 04:29:35 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =

Error - 09/01/2012 05:30:09 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =

Error - 09/01/2012 06:04:16 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =

Error - 11/01/2012 17:06:53 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =

Error - 11/01/2012 17:11:21 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =

Error - 11/01/2012 17:21:43 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =

Error - 11/01/2012 17:53:56 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =

Error - 12/01/2012 04:37:01 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =

Error - 12/01/2012 07:02:15 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =

Error - 13/01/2012 04:27:05 | Computer Name = Smith | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 11/01/2012 17:21:30 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Scheduler service failed to start due to the following error:
%%5

Error - 11/01/2012 17:21:31 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Realtime Protection service failed to start due to the following
error: %%5

Error - 11/01/2012 17:53:44 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Scheduler service failed to start due to the following error:
%%5

Error - 11/01/2012 17:53:44 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Realtime Protection service failed to start due to the following
error: %%5

Error - 12/01/2012 04:36:35 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Scheduler service failed to start due to the following error:
%%5

Error - 12/01/2012 04:36:36 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Realtime Protection service failed to start due to the following
error: %%5

Error - 12/01/2012 07:01:20 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Scheduler service failed to start due to the following error:
%%5

Error - 12/01/2012 07:01:20 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Realtime Protection service failed to start due to the following
error: %%5

Error - 13/01/2012 04:27:04 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Scheduler service failed to start due to the following error:
%%5

Error - 13/01/2012 04:27:04 | Computer Name = Smith | Source = Service Control Manager | ID = 7000
Description = The Avira Realtime Protection service failed to start due to the following
error: %%5


< End of report >
aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software Run date: 2012-01-13 10:36:01 —————————– 10:36:01.984 OS Version: Windows x64 6.1.7601 Service Pack 1 10:36:01.984 Number of processors: 2 586 0x2A07 10:36:01.984 ComputerName: SMITH UserName: Colin 10:36:03.887 Initialize success 10:36:52.450 AVAST engine defs: 12011201 10:37:18.081 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 10:37:18.081 Disk 0 Vendor: Hitachi_HDS721010CLA332 JP4OA3CF Size: 953869MB BusType: 3 10:37:18.081 Disk 0 MBR read successfully 10:37:18.096 Disk 0 MBR scan 10:37:18.096 Disk 0 Windows 7 default MBR code 10:37:18.096 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 10:37:18.112 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848 10:37:18.127 Service scanning 10:37:18.564 Service Wsthurvi C:\Windows\C:\Windows\system32\drivers\wimmount.sys **LOCKED** 123 10:37:19.079 Modules scanning 10:37:19.079 Disk 0 trace - called modules: 10:37:19.095 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys 10:37:19.095 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8003fea060] 10:37:19.609 3 CLASSPNP.SYS[fffff8800160143f] -> nt!IofCallDriver -> [0xfffffa8003eba520] 10:37:19.609 5 ACPI.sys[fffff88000f4a7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0xfffffa8003ec8680] 10:37:22.417 AVAST engine scan C:\Windows 10:37:24.570 AVAST engine scan C:\Windows\system32 10:38:15.613 AVAST engine scan C:\Windows\system32\drivers 10:38:22.009 AVAST engine scan C:\Users\Colin 10:38:59.138 AVAST engine scan C:\ProgramData 10:39:34.893 Scan finished successfully 10:39:57.950 Disk 0 MBR has been saved successfully to "C:\Users\Colin\Desktop\MBR.dat" 10:39:57.965 The log file has been saved successfully to "C:\Users\Colin\Desktop\aswMBR.txt" aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software Run date: 2012-01-13 10:36:01 —————————– 10:36:01.984 OS Version: Windows x64 6.1.7601 Service Pack 1 10:36:01.984 Number of processors: 2 586 0x2A07 10:36:01.984 ComputerName: SMITH UserName: Colin 10:36:03.887 Initialize success 10:36:52.450 AVAST engine defs: 12011201 10:37:18.081 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 10:37:18.081 Disk 0 Vendor: Hitachi_HDS721010CLA332 JP4OA3CF Size: 953869MB BusType: 3 10:37:18.081 Disk 0 MBR read successfully 10:37:18.096 Disk 0 MBR scan 10:37:18.096 Disk 0 Windows 7 default MBR code 10:37:18.096 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 10:37:18.112 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848 10:37:18.127 Service scanning 10:37:18.564 Service Wsthurvi C:\Windows\C:\Windows\system32\drivers\wimmount.sys **LOCKED** 123 10:37:19.079 Modules scanning 10:37:19.079 Disk 0 trace - called modules: 10:37:19.095 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys 10:37:19.095 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8003fea060] 10:37:19.609 3 CLASSPNP.SYS[fffff8800160143f] -> nt!IofCallDriver -> [0xfffffa8003eba520] 10:37:19.609 5 ACPI.sys[fffff88000f4a7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0xfffffa8003ec8680] 10:37:22.417 AVAST engine scan C:\Windows 10:37:24.570 AVAST engine scan C:\Windows\system32 10:38:15.613 AVAST engine scan C:\Windows\system32\drivers 10:38:22.009 AVAST engine scan C:\Users\Colin 10:38:59.138 AVAST engine scan C:\ProgramData 10:39:34.893 Scan finished successfully 10:39:57.950 Disk 0 MBR has been saved successfully to "C:\Users\Colin\Desktop\MBR.dat" 10:39:57.965 The log file has been saved successfully to "C:\Users\Colin\Desktop\aswMBR.txt" 10:41:14.764 Disk 0 MBR has been saved successfully to "C:\Users\Colin\Desktop\MBR.dat" 10:41:14.780 The log file has been saved successfully to "C:\Users\Colin\Desktop\aswMBR.txt" aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software Run date: 2012-01-13 10:36:01 —————————– 10:36:01.984 OS Version: Windows x64 6.1.7601 Service Pack 1 10:36:01.984 Number of processors: 2 586 0x2A07 10:36:01.984 ComputerName: SMITH UserName: Colin 10:36:03.887 Initialize success 10:36:52.450 AVAST engine defs: 12011201 10:37:18.081 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 10:37:18.081 Disk 0 Vendor: Hitachi_HDS721010CLA332 JP4OA3CF Size: 953869MB BusType: 3 10:37:18.081 Disk 0 MBR read successfully 10:37:18.096 Disk 0 MBR scan 10:37:18.096 Disk 0 Windows 7 default MBR code 10:37:18.096 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 10:37:18.112 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848 10:37:18.127 Service scanning 10:37:18.564 Service Wsthurvi C:\Windows\C:\Windows\system32\drivers\wimmount.sys **LOCKED** 123 10:37:19.079 Modules scanning 10:37:19.079 Disk 0 trace - called modules: 10:37:19.095 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys 10:37:19.095 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8003fea060] 10:37:19.609 3 CLASSPNP.SYS[fffff8800160143f] -> nt!IofCallDriver -> [0xfffffa8003eba520] 10:37:19.609 5 ACPI.sys[fffff88000f4a7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0xfffffa8003ec8680] 10:37:22.417 AVAST engine scan C:\Windows 10:37:24.570 AVAST engine scan C:\Windows\system32 10:38:15.613 AVAST engine scan C:\Windows\system32\drivers 10:38:22.009 AVAST engine scan C:\Users\Colin 10:38:59.138 AVAST engine scan C:\ProgramData 10:39:34.893 Scan finished successfully 10:39:57.950 Disk 0 MBR has been saved successfully to "C:\Users\Colin\Desktop\MBR.dat" 10:39:57.965 The log file has been saved successfully to "C:\Users\Colin\Desktop\aswMBR.txt" 10:41:14.764 Disk 0 MBR has been saved successfully to "C:\Users\Colin\Desktop\MBR.dat" 10:41:14.780 The log file has been saved successfully to "C:\Users\Colin\Desktop\aswMBR.txt" 10:41:52.251 Disk 0 MBR has been saved successfully to "C:\Users\Colin\Desktop\MBR.dat" 10:41:52.251 The log file has been saved successfully to "C:\Users\Colin\Desktop\aswMBR.txt"
Hi scudo

I'd like you to run a different couple of scans

Run TDSSKiller

Please download TDSSKiller.zip
  • extract it to your desktop
  • double click TDSSKiller.exe
  • press Start Scan

    only if Malicious objects are found then ensure Cure is selected
    then click Continue > Reboot now

  • copy and paste the log in your next reply
  • a copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_*** (*** denotes version & date)
===========================================================

Download and run ComboFix

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • when finished, it will produce a report for you.
  • please post the C:\ComboFix.txt and TDSSKiller log.
Thanks

Satchfan
TDSSKiller log…. 21:19:41.0163 1896 TDSS rootkit removing tool [removed] Jan 10 2012 09:14:26 21:19:41.0366 1896 ============================================================ 21:19:41.0366 1896 Current date / time: 2012/01/11 21:19:41.0366 21:19:41.0366 1896 SystemInfo: 21:19:41.0366 1896 21:19:41.0366 1896 OS Version: 6.1.7601 ServicePack: 1.0 21:19:41.0366 1896 Product type: Workstation 21:19:41.0366 1896 ComputerName: SMITH 21:19:41.0366 1896 UserName: Colin 21:19:41.0366 1896 Windows directory: C:\Windows 21:19:41.0366 1896 System windows directory: C:\Windows 21:19:41.0366 1896 Running under WOW64 21:19:41.0366 1896 Processor architecture: Intel x64 21:19:41.0366 1896 Number of processors: 2 21:19:41.0366 1896 Page size: 0x1000 21:19:41.0366 1896 Boot type: Normal boot 21:19:41.0366 1896 ============================================================ 21:19:42.0426 1896 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000, SectorSize: 0x200, Cylinders: 0x1F8B1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K', Flags 0x00000040 21:19:42.0458 1896 Initialize success 21:19:46.0233 2304 ============================================================ 21:19:46.0233 2304 Scan started 21:19:46.0233 2304 Mode: Manual; 21:19:46.0233 2304 ============================================================ 21:19:47.0730 2304 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys 21:19:47.0730 2304 1394ohci - ok 21:19:47.0762 2304 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys 21:19:47.0762 2304 ACPI - ok 21:19:47.0777 2304 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys 21:19:47.0777 2304 AcpiPmi - ok 21:19:47.0808 2304 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys 21:19:47.0808 2304 adp94xx - ok 21:19:47.0824 2304 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys 21:19:47.0824 2304 adpahci - ok 21:19:47.0840 2304 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys 21:19:47.0840 2304 adpu320 - ok 21:19:47.0886 2304 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys 21:19:47.0886 2304 AFD - ok 21:19:47.0964 2304 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys 21:19:47.0964 2304 agp440 - ok 21:19:48.0027 2304 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys 21:19:48.0027 2304 aliide - ok 21:19:48.0042 2304 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys 21:19:48.0042 2304 amdide - ok 21:19:48.0058 2304 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys 21:19:48.0058 2304 AmdK8 - ok 21:19:48.0074 2304 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys 21:19:48.0074 2304 AmdPPM - ok 21:19:48.0089 2304 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys 21:19:48.0105 2304 amdsata - ok 21:19:48.0105 2304 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys 21:19:48.0105 2304 amdsbs - ok 21:19:48.0120 2304 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys 21:19:48.0120 2304 amdxata - ok 21:19:48.0214 2304 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys 21:19:48.0214 2304 AppID - ok 21:19:48.0245 2304 AppleCharger (6be11ad81d4527d299f0cb5f3731aabc) C:\Windows\system32\DRIVERS\AppleCharger.sys 21:19:48.0245 2304 AppleCharger - ok 21:19:48.0276 2304 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys 21:19:48.0276 2304 arc - ok 21:19:48.0292 2304 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys 21:19:48.0292 2304 arcsas - ok 21:19:48.0323 2304 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 21:19:48.0323 2304 AsyncMac - ok 21:19:48.0339 2304 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys 21:19:48.0339 2304 atapi - ok 21:19:48.0417 2304 avgntflt (aa8f79a1bdfc03b3bc70c44ab00589b4) C:\Windows\system32\DRIVERS\avgntflt.sys 21:19:48.0417 2304 avgntflt - ok 21:19:48.0448 2304 avipbb (d959309ececca73fc79f8ef8521346b2) C:\Windows\system32\DRIVERS\avipbb.sys 21:19:48.0448 2304 avipbb - ok 21:19:48.0464 2304 avkmgr (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys 21:19:48.0464 2304 avkmgr - ok 21:19:48.0479 2304 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys 21:19:48.0495 2304 b06bdrv - ok 21:19:48.0526 2304 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 21:19:48.0526 2304 b57nd60a - ok 21:19:48.0557 2304 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 21:19:48.0557 2304 Beep - ok 21:19:48.0635 2304 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 21:19:48.0635 2304 blbdrive - ok 21:19:48.0666 2304 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys 21:19:48.0666 2304 bowser - ok 21:19:48.0666 2304 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys 21:19:48.0666 2304 BrFiltLo - ok 21:19:48.0682 2304 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys 21:19:48.0682 2304 BrFiltUp - ok 21:19:48.0682 2304 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 21:19:48.0698 2304 Brserid - ok 21:19:48.0713 2304 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 21:19:48.0713 2304 BrSerWdm - ok 21:19:48.0744 2304 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 21:19:48.0744 2304 BrUsbMdm - ok 21:19:48.0744 2304 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 21:19:48.0760 2304 BrUsbSer - ok 21:19:48.0760 2304 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys 21:19:48.0760 2304 BTHMODEM - ok 21:19:48.0776 2304 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 21:19:48.0791 2304 cdfs - ok 21:19:48.0838 2304 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys 21:19:48.0838 2304 cdrom - ok 21:19:48.0854 2304 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys 21:19:48.0854 2304 circlass - ok 21:19:48.0900 2304 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 21:19:48.0900 2304 CLFS - ok 21:19:48.0978 2304 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\drivers\CmBatt.sys 21:19:48.0994 2304 CmBatt - ok 21:19:49.0010 2304 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys 21:19:49.0010 2304 cmdide - ok 21:19:49.0025 2304 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys 21:19:49.0025 2304 CNG - ok 21:19:49.0041 2304 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys 21:19:49.0041 2304 Compbatt - ok 21:19:49.0056 2304 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\DRIVERS\CompositeBus.sys 21:19:49.0056 2304 CompositeBus - ok 21:19:49.0119 2304 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys 21:19:49.0119 2304 crcdisk - ok 21:19:49.0166 2304 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys 21:19:49.0166 2304 DfsC - ok 21:19:49.0181 2304 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 21:19:49.0181 2304 discache - ok 21:19:49.0228 2304 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys 21:19:49.0228 2304 Disk - ok 21:19:49.0275 2304 Dot4 (b42ed0320c6e41102fde0005154849bb) C:\Windows\system32\DRIVERS\Dot4.sys 21:19:49.0275 2304 Dot4 - ok 21:19:49.0290 2304 Dot4Print (e9f5969233c5d89f3c35e3a66a52a361) C:\Windows\system32\DRIVERS\Dot4Prt.sys 21:19:49.0290 2304 Dot4Print - ok 21:19:49.0306 2304 dot4usb (fd05a02b0370bc3000f402e543ca5814) C:\Windows\system32\DRIVERS\dot4usb.sys 21:19:49.0306 2304 dot4usb - ok 21:19:49.0353 2304 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 21:19:49.0353 2304 drmkaud - ok 21:19:49.0384 2304 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys 21:19:49.0400 2304 DXGKrnl - ok 21:19:49.0446 2304 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys 21:19:49.0493 2304 ebdrv - ok 21:19:49.0556 2304 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys 21:19:49.0556 2304 elxstor - ok 21:19:49.0587 2304 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys 21:19:49.0587 2304 ErrDev - ok 21:19:49.0634 2304 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 21:19:49.0634 2304 exfat - ok 21:19:49.0649 2304 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 21:19:49.0649 2304 fastfat - ok 21:19:49.0680 2304 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys 21:19:49.0680 2304 fdc - ok 21:19:49.0712 2304 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 21:19:49.0712 2304 FileInfo - ok 21:19:49.0727 2304 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 21:19:49.0727 2304 Filetrace - ok 21:19:49.0727 2304 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys 21:19:49.0727 2304 flpydisk - ok 21:19:49.0743 2304 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys 21:19:49.0743 2304 FltMgr - ok 21:19:49.0790 2304 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 21:19:49.0790 2304 FsDepends - ok 21:19:49.0805 2304 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 21:19:49.0805 2304 Fs_Rec - ok 21:19:49.0836 2304 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys 21:19:49.0836 2304 fvevol - ok 21:19:49.0852 2304 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys 21:19:49.0852 2304 gagp30kx - ok 21:19:49.0868 2304 gdrv - ok 21:19:49.0899 2304 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 21:19:49.0899 2304 hcw85cir - ok 21:19:49.0930 2304 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys 21:19:49.0930 2304 HdAudAddService - ok 21:19:49.0977 2304 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\DRIVERS\HDAudBus.sys 21:19:49.0977 2304 HDAudBus - ok 21:19:49.0977 2304 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys 21:19:49.0977 2304 HidBatt - ok 21:19:49.0992 2304 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys 21:19:49.0992 2304 HidBth - ok 21:19:49.0992 2304 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys 21:19:49.0992 2304 HidIr - ok 21:19:50.0055 2304 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys 21:19:50.0070 2304 HidUsb - ok 21:19:50.0133 2304 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys 21:19:50.0133 2304 HpSAMD - ok 21:19:50.0164 2304 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys 21:19:50.0164 2304 HTTP - ok 21:19:50.0180 2304 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys 21:19:50.0180 2304 hwpolicy - ok 21:19:50.0195 2304 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys 21:19:50.0195 2304 i8042prt - ok 21:19:50.0242 2304 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys 21:19:50.0242 2304 iaStorV - ok 21:19:50.0414 2304 igfx (174bcac474de13b2650e444cf124828e) C:\Windows\system32\DRIVERS\igdkmd64.sys 21:19:50.0538 2304 igfx - ok 21:19:50.0616 2304 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys 21:19:50.0616 2304 iirsp - ok 21:19:50.0632 2304 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys 21:19:50.0632 2304 intelide - ok 21:19:50.0648 2304 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 21:19:50.0663 2304 intelppm - ok 21:19:50.0679 2304 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys 21:19:50.0679 2304 IpFilterDriver - ok 21:19:50.0694 2304 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys 21:19:50.0694 2304 IPMIDRV - ok 21:19:50.0710 2304 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 21:19:50.0710 2304 IPNAT - ok 21:19:50.0741 2304 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 21:19:50.0741 2304 IRENUM - ok 21:19:50.0772 2304 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys 21:19:50.0772 2304 isapnp - ok 21:19:50.0788 2304 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys 21:19:50.0788 2304 iScsiPrt - ok 21:19:50.0819 2304 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys 21:19:50.0819 2304 kbdclass - ok 21:19:50.0866 2304 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys 21:19:50.0866 2304 kbdhid - ok 21:19:50.0897 2304 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys 21:19:50.0897 2304 KSecDD - ok 21:19:50.0913 2304 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys 21:19:50.0913 2304 KSecPkg - ok 21:19:50.0928 2304 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 21:19:50.0928 2304 ksthunk - ok 21:19:50.0960 2304 L1C (173666119d217e3739205c169e2bf0e5) C:\Windows\system32\DRIVERS\L1C62x64.sys 21:19:50.0960 2304 L1C - ok 21:19:51.0006 2304 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 21:19:51.0006 2304 lltdio - ok 21:19:51.0038 2304 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys 21:19:51.0038 2304 LSI_FC - ok 21:19:51.0100 2304 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys 21:19:51.0100 2304 LSI_SAS - ok 21:19:51.0100 2304 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys 21:19:51.0100 2304 LSI_SAS2 - ok 21:19:51.0116 2304 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys 21:19:51.0116 2304 LSI_SCSI - ok 21:19:51.0147 2304 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 21:19:51.0147 2304 luafv - ok 21:19:51.0162 2304 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys 21:19:51.0162 2304 megasas - ok 21:19:51.0194 2304 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys 21:19:51.0194 2304 MegaSR - ok 21:19:51.0225 2304 MEIx64 (1c6e73fc46b509eff9d0086aa37132df) C:\Windows\system32\DRIVERS\HECIx64.sys 21:19:51.0225 2304 MEIx64 - ok 21:19:51.0272 2304 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 21:19:51.0272 2304 Modem - ok 21:19:51.0318 2304 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 21:19:51.0318 2304 monitor - ok 21:19:51.0334 2304 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys 21:19:51.0334 2304 mouclass - ok 21:19:51.0365 2304 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 21:19:51.0365 2304 mouhid - ok 21:19:51.0381 2304 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys 21:19:51.0381 2304 mountmgr - ok 21:19:51.0396 2304 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys 21:19:51.0396 2304 mpio - ok 21:19:51.0412 2304 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 21:19:51.0412 2304 mpsdrv - ok 21:19:51.0443 2304 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys 21:19:51.0443 2304 MRxDAV - ok 21:19:51.0474 2304 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys 21:19:51.0474 2304 mrxsmb - ok 21:19:51.0521 2304 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys 21:19:51.0521 2304 mrxsmb10 - ok 21:19:51.0537 2304 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 21:19:51.0552 2304 mrxsmb20 - ok 21:19:51.0568 2304 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys 21:19:51.0568 2304 msahci - ok 21:19:51.0584 2304 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys 21:19:51.0584 2304 msdsm - ok 21:19:51.0615 2304 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 21:19:51.0615 2304 Msfs - ok 21:19:51.0630 2304 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 21:19:51.0630 2304 mshidkmdf - ok 21:19:51.0646 2304 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys 21:19:51.0646 2304 msisadrv - ok 21:19:51.0677 2304 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 21:19:51.0677 2304 MSKSSRV - ok 21:19:51.0724 2304 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 21:19:51.0724 2304 MSPCLOCK - ok 21:19:51.0740 2304 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 21:19:51.0740 2304 MSPQM - ok 21:19:51.0755 2304 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys 21:19:51.0755 2304 MsRPC - ok 21:19:51.0771 2304 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys 21:19:51.0771 2304 mssmbios - ok 21:19:51.0802 2304 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 21:19:51.0802 2304 MSTEE - ok 21:19:51.0802 2304 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys 21:19:51.0802 2304 MTConfig - ok 21:19:51.0818 2304 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 21:19:51.0818 2304 Mup - ok 21:19:51.0864 2304 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 21:19:51.0864 2304 NativeWifiP - ok 21:19:51.0927 2304 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys 21:19:51.0927 2304 NDIS - ok 21:19:51.0958 2304 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 21:19:51.0958 2304 NdisCap - ok 21:19:51.0974 2304 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 21:19:51.0974 2304 NdisTapi - ok 21:19:51.0989 2304 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys 21:19:52.0005 2304 Ndisuio - ok 21:19:52.0036 2304 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys 21:19:52.0036 2304 NdisWan - ok 21:19:52.0052 2304 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys 21:19:52.0052 2304 NDProxy - ok 21:19:52.0083 2304 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 21:19:52.0083 2304 NetBIOS - ok 21:19:52.0130 2304 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys 21:19:52.0130 2304 NetBT - ok 21:19:52.0176 2304 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys 21:19:52.0176 2304 nfrd960 - ok 21:19:52.0223 2304 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 21:19:52.0223 2304 Npfs - ok 21:19:52.0239 2304 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 21:19:52.0239 2304 nsiproxy - ok 21:19:52.0286 2304 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys 21:19:52.0301 2304 Ntfs - ok 21:19:52.0348 2304 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 21:19:52.0348 2304 Null - ok 21:19:52.0395 2304 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys 21:19:52.0395 2304 nvraid - ok 21:19:52.0410 2304 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys 21:19:52.0426 2304 nvstor - ok 21:19:52.0442 2304 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys 21:19:52.0457 2304 nv_agp - ok 21:19:52.0473 2304 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys 21:19:52.0473 2304 ohci1394 - ok 21:19:52.0520 2304 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys 21:19:52.0520 2304 Parport - ok 21:19:52.0535 2304 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys 21:19:52.0535 2304 partmgr - ok 21:19:52.0582 2304 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys 21:19:52.0582 2304 pci - ok 21:19:52.0598 2304 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys 21:19:52.0598 2304 pciide - ok 21:19:52.0629 2304 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys 21:19:52.0629 2304 pcmcia - ok 21:19:52.0644 2304 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 21:19:52.0644 2304 pcw - ok 21:19:52.0676 2304 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 21:19:52.0676 2304 PEAUTH - ok 21:19:52.0800 2304 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys 21:19:52.0800 2304 PptpMiniport - ok 21:19:52.0832 2304 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys 21:19:52.0832 2304 Processor - ok 21:19:52.0878 2304 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys 21:19:52.0878 2304 Psched - ok 21:19:52.0910 2304 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys 21:19:52.0925 2304 ql2300 - ok 21:19:52.0925 2304 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys 21:19:52.0925 2304 ql40xx - ok 21:19:52.0941 2304 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 21:19:52.0941 2304 QWAVEdrv - ok 21:19:52.0956 2304 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 21:19:52.0956 2304 RasAcd - ok 21:19:53.0034 2304 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 21:19:53.0050 2304 RasAgileVpn - ok 21:19:53.0081 2304 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys 21:19:53.0081 2304 Rasl2tp - ok 21:19:53.0097 2304 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 21:19:53.0097 2304 RasPppoe - ok 21:19:53.0112 2304 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 21:19:53.0112 2304 RasSstp - ok 21:19:53.0128 2304 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys 21:19:53.0128 2304 rdbss - ok 21:19:53.0144 2304 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\drivers\rdpbus.sys 21:19:53.0144 2304 rdpbus - ok 21:19:53.0159 2304 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 21:19:53.0159 2304 RDPCDD - ok 21:19:53.0190 2304 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 21:19:53.0206 2304 RDPENCDD - ok 21:19:53.0222 2304 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 21:19:53.0222 2304 RDPREFMP - ok 21:19:53.0237 2304 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys 21:19:53.0237 2304 RDPWD - ok 21:19:53.0284 2304 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys 21:19:53.0284 2304 rdyboost - ok 21:19:53.0300 2304 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 21:19:53.0315 2304 rspndr - ok 21:19:53.0331 2304 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys 21:19:53.0331 2304 sbp2port - ok 21:19:53.0362 2304 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys 21:19:53.0362 2304 scfilter - ok 21:19:53.0393 2304 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 21:19:53.0409 2304 secdrv - ok 21:19:53.0456 2304 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys 21:19:53.0456 2304 Serenum - ok 21:19:53.0487 2304 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys 21:19:53.0487 2304 Serial - ok 21:19:53.0502 2304 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys 21:19:53.0502 2304 sermouse - ok 21:19:53.0518 2304 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys 21:19:53.0518 2304 sffdisk - ok 21:19:53.0534 2304 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys 21:19:53.0534 2304 sffp_mmc - ok 21:19:53.0534 2304 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys 21:19:53.0534 2304 sffp_sd - ok 21:19:53.0549 2304 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys 21:19:53.0549 2304 sfloppy - ok 21:19:53.0580 2304 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys 21:19:53.0580 2304 SiSRaid2 - ok 21:19:53.0596 2304 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys 21:19:53.0596 2304 SiSRaid4 - ok 21:19:53.0627 2304 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 21:19:53.0627 2304 Smb - ok 21:19:53.0674 2304 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 21:19:53.0674 2304 spldr - ok 21:19:53.0721 2304 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys 21:19:53.0721 2304 srv - ok 21:19:53.0752 2304 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys 21:19:53.0752 2304 srv2 - ok 21:19:53.0768 2304 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys 21:19:53.0768 2304 srvnet - ok 21:19:53.0814 2304 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys 21:19:53.0814 2304 stexstor - ok 21:19:53.0846 2304 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys 21:19:53.0846 2304 swenum - ok 21:19:53.0924 2304 Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys 21:19:53.0939 2304 Tcpip - ok 21:19:53.0986 2304 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys 21:19:54.0002 2304 TCPIP6 - ok 21:19:54.0017 2304 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys 21:19:54.0017 2304 tcpipreg - ok 21:19:54.0064 2304 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 21:19:54.0064 2304 TDPIPE - ok 21:19:54.0064 2304 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys 21:19:54.0064 2304 TDTCP - ok 21:19:54.0080 2304 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys 21:19:54.0080 2304 tdx - ok 21:19:54.0095 2304 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\DRIVERS\termdd.sys 21:19:54.0095 2304 TermDD - ok 21:19:54.0126 2304 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys 21:19:54.0126 2304 tssecsrv - ok 21:19:54.0126 2304 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys 21:19:54.0142 2304 TsUsbFlt - ok 21:19:54.0142 2304 TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys 21:19:54.0142 2304 TsUsbGD - ok 21:19:54.0189 2304 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys 21:19:54.0189 2304 tunnel - ok 21:19:54.0220 2304 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys 21:19:54.0220 2304 uagp35 - ok 21:19:54.0236 2304 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys 21:19:54.0236 2304 udfs - ok 21:19:54.0267 2304 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys 21:19:54.0267 2304 uliagpkx - ok 21:19:54.0282 2304 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys 21:19:54.0282 2304 umbus - ok 21:19:54.0282 2304 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys 21:19:54.0298 2304 UmPass - ok 21:19:54.0345 2304 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys 21:19:54.0345 2304 usbccgp - ok 21:19:54.0376 2304 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys 21:19:54.0376 2304 usbcir - ok 21:19:54.0392 2304 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys 21:19:54.0392 2304 usbehci - ok 21:19:54.0438 2304 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys 21:19:54.0438 2304 usbhub - ok 21:19:54.0454 2304 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys 21:19:54.0454 2304 usbohci - ok 21:19:54.0470 2304 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 21:19:54.0470 2304 usbprint - ok 21:19:54.0501 2304 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys 21:19:54.0501 2304 usbscan - ok 21:19:54.0532 2304 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS 21:19:54.0532 2304 USBSTOR - ok 21:19:54.0563 2304 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys 21:19:54.0563 2304 usbuhci - ok 21:19:54.0594 2304 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys 21:19:54.0594 2304 vdrvroot - ok 21:19:54.0657 2304 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 21:19:54.0657 2304 vga - ok 21:19:54.0672 2304 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 21:19:54.0672 2304 VgaSave - ok 21:19:54.0704 2304 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys 21:19:54.0704 2304 vhdmp - ok 21:19:54.0782 2304 VIAHdAudAddService (279030ef4c22919f756269206e0e533f) C:\Windows\system32\drivers\viahduaa.sys 21:19:54.0797 2304 VIAHdAudAddService - ok 21:19:54.0828 2304 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys 21:19:54.0828 2304 viaide - ok 21:19:54.0860 2304 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys 21:19:54.0860 2304 volmgr - ok 21:19:54.0891 2304 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys 21:19:54.0891 2304 volmgrx - ok 21:19:54.0922 2304 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys 21:19:54.0922 2304 volsnap - ok 21:19:54.0969 2304 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys 21:19:54.0969 2304 vsmraid - ok 21:19:54.0984 2304 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys 21:19:54.0984 2304 vwifibus - ok 21:19:54.0984 2304 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys 21:19:54.0984 2304 WacomPen - ok 21:19:55.0047 2304 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 21:19:55.0047 2304 WANARP - ok 21:19:55.0047 2304 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 21:19:55.0047 2304 Wanarpv6 - ok 21:19:55.0109 2304 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys 21:19:55.0109 2304 Wd - ok 21:19:55.0140 2304 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 21:19:55.0140 2304 Wdf01000 - ok 21:19:55.0172 2304 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 21:19:55.0172 2304 WfpLwf - ok 21:19:55.0172 2304 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 21:19:55.0172 2304 WIMMount - ok 21:19:55.0265 2304 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys 21:19:55.0265 2304 WinUsb - ok 21:19:55.0296 2304 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys 21:19:55.0296 2304 WmiAcpi - ok 21:19:55.0343 2304 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 21:19:55.0343 2304 ws2ifsl - ok 21:19:55.0374 2304 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys 21:19:55.0374 2304 WudfPf - ok 21:19:55.0390 2304 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys 21:19:55.0390 2304 WUDFRd - ok 21:19:55.0421 2304 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 21:19:55.0484 2304 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - infected 21:19:55.0484 2304 \Device\Harddisk0\DR0 - detected Rootkit.Boot.SST.b (0) 21:19:55.0484 2304 Boot (0x1200) (a35e4288289d2ac68232eeb16f2d2d11) \Device\Harddisk0\DR0\Partition0 21:19:55.0484 2304 \Device\Harddisk0\DR0\Partition0 - ok 21:19:55.0515 2304 Boot (0x1200) (feaffca5396fb0248019b95c8155b261) \Device\Harddisk0\DR0\Partition1 21:19:55.0515 2304 \Device\Harddisk0\DR0\Partition1 - ok 21:19:55.0515 2304 ============================================================ 21:19:55.0515 2304 Scan finished 21:19:55.0515 2304 ============================================================ 21:19:55.0530 3536 Detected object count: 1 21:19:55.0530 3536 Actual detected object count: 1 21:20:18.0509 3536 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - will be cured on reboot 21:20:18.0540 3536 \Device\Harddisk0\DR0 - ok 21:20:18.0540 3536 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - User select action: Cure 21:20:25.0498 2736 Deinitialize success
Slight issue…. I left combo fix to run and came back a few minutes later and logged on (desktop requires password after a few minutes) the combo screen was flashing and jumping about the screen and I couldnt close it so shut down PC. I then rebooted and the same flashing combo screen appeared, then switched to admin desktop and the combo screen was running `preparing log`. When I tried to open the log I got this message… "C:\ComboFix.txt Illegal operation attempted on a reg key that has been marked for deletion" I then got the log opened and thought to copy/paste into a text document (I couldnt connect to the internet on admin but same message appeared, the same for a word document, and then the same again when I tried to connect to the internet. so switched back to my desktop to post this. Tried running again as I previously had adware live running, but the same problems, I got a log in admin but it wont allow me to access the internet or copy/paste onto a memory stick so I can send from my desktop.
Ok I hope this log is ok, if not I can try running again. ComboFix 12-01-13.05 - Colin 13/01/2012 23:05:25.2.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.1965.953 [GMT 0:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2011-12-13 to 2012-01-13 ))))))))))))))))))))))))))))))) . . 2012-01-13 23:11 . 2012-01-13 23:11 69000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6C7471D3-2F21-4F58-9931-CBEDAE321C5A}\offreg.dll 2012-01-13 23:08 . 2012-01-13 23:08 ——– d—–w- c:\users\Guest\AppData\Local\temp 2012-01-13 23:08 . 2012-01-13 23:08 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-01-13 13:56 . 2011-11-21 11:40 8822856 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6C7471D3-2F21-4F58-9931-CBEDAE321C5A}\mpengine.dll 2012-01-12 15:02 . 2012-01-12 14:04 16432 —-a-w- c:\windows\system32\lsdelete.exe 2012-01-12 14:04 . 2012-01-12 14:04 55384 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2012-01-12 14:02 . 2012-01-12 14:02 ——– dc—-w- c:\windows\system32\DRVSTORE 2012-01-12 14:02 . 2011-12-23 07:12 69376 —-a-w- c:\windows\system32\drivers\Lbd.sys 2012-01-12 14:02 . 2012-01-12 14:02 ——– d—–w- c:\program files (x86)\Lavasoft 2012-01-12 14:02 . 2012-01-12 14:02 ——– d—–w- c:\programdata\Lavasoft 2012-01-11 21:16 . 2011-10-26 05:25 1572864 —-a-w- c:\windows\system32\quartz.dll 2012-01-11 21:16 . 2011-10-26 05:25 366592 —-a-w- c:\windows\system32\qdvd.dll 2012-01-11 21:16 . 2011-10-26 04:32 514560 —-a-w- c:\windows\SysWow64\qdvd.dll 2012-01-11 21:16 . 2011-10-26 04:32 1328128 —-a-w- c:\windows\SysWow64\quartz.dll 2012-01-11 21:16 . 2011-11-17 06:41 1731920 —-a-w- c:\windows\system32\ntdll.dll 2012-01-11 21:16 . 2011-11-17 05:38 1292080 —-a-w- c:\windows\SysWow64\ntdll.dll 2012-01-11 21:16 . 2011-11-19 14:58 77312 —-a-w- c:\windows\system32\packager.dll 2012-01-11 21:16 . 2011-11-19 14:01 67072 —-a-w- c:\windows\SysWow64\packager.dll 2012-01-11 21:06 . 2012-01-11 21:07 ——– d—–w- c:\users\Colin\AppData\Local\ElevatedDiagnostics 2011-12-25 09:45 . 2011-12-25 09:45 ——– d—–w- c:\users\Colin\AppData\Roaming\Nitro PDF 2011-12-25 00:26 . 2011-12-25 00:32 ——– d–h–w- c:\users\Stan\AppData\Roaming\HpUpdate 2011-12-16 23:41 . 2012-01-08 23:47 ——– d—–w- c:\users\Colin\AppData\Roaming\HpUpdate 2011-12-16 23:41 . 2011-12-16 23:41 ——– d—–w- c:\windows\Hewlett-Packard . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-11-20 13:36 . 2011-10-28 21:25 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-10-25 15:50 . 2011-11-03 22:45 17192 —-a-w- c:\windows\system32\nitrolocalui2.dll 2011-10-25 15:50 . 2011-11-03 22:45 28968 —-a-w- c:\windows\system32\nitrolocalmon2.dll 2011-10-19 15:56 . 2011-10-28 18:28 27760 —-a-w- c:\windows\system32\drivers\avkmgr.sys 2011-10-19 15:56 . 2011-10-28 18:28 97312 —-a-w- c:\windows\system32\drivers\avgntflt.sys 2011-10-19 15:56 . 2011-10-28 18:28 130760 —-a-w- c:\windows\system32\drivers\avipbb.sys 2011-10-19 13:16 . 2011-10-19 13:16 49152 —-a-r- c:\windows\SysWow64\inetwh32.dll 2011-10-19 13:16 . 2011-10-19 13:16 1044480 —-a-r- c:\windows\SysWow64\roboex32.dll . . ((((((((((((((((((((((((((((( SnapShot@2012-01-13_22.36.48 ))))))))))))))))))))))))))))))))))))))))) . - 2009-07-14 04:54 . 2012-01-13 08:27 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2012-01-13 23:02 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2012-01-13 08:27 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-07-14 04:54 . 2012-01-13 23:02 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2012-01-13 08:27 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2012-01-13 23:02 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 05:10 . 2012-01-13 23:11 34176 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin - 2011-10-24 18:28 . 2012-01-13 22:23 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-10-24 18:28 . 2012-01-13 22:52 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-10-24 18:28 . 2012-01-13 22:23 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2011-10-24 18:28 . 2012-01-13 22:52 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2012-01-13 22:23 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2012-01-13 22:52 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2011-10-28 17:56 . 2012-01-13 22:35 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-10-28 17:56 . 2012-01-13 23:09 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:46 . 2012-01-13 22:42 92944 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat + 2011-10-28 17:56 . 2012-01-13 23:09 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2011-10-28 17:56 . 2012-01-13 22:35 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2011-10-28 17:56 . 2012-01-13 23:09 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2011-10-28 17:56 . 2012-01-13 22:35 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2011-10-24 11:39 . 2012-01-13 22:35 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-10-24 11:39 . 2012-01-13 23:09 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-10-24 11:39 . 2012-01-13 22:35 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-10-24 11:39 . 2012-01-13 23:09 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-10-30 11:42 . 2012-01-13 23:11 6990 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-806693270-4274982699-3587859652-1003_UserData.bin - 2012-01-13 22:35 . 2012-01-13 22:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-01-13 23:09 . 2012-01-13 23:09 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-01-13 23:09 . 2012-01-13 23:09 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2012-01-13 22:35 . 2012-01-13 22:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2009-07-14 02:36 . 2012-01-13 10:50 628024 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2012-01-13 22:39 628024 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2012-01-13 22:39 110208 c:\windows\system32\perfc009.dat - 2009-07-14 02:36 . 2012-01-13 10:50 110208 c:\windows\system32\perfc009.dat - 2009-07-14 05:01 . 2012-01-13 22:31 390744 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 05:01 . 2012-01-13 23:08 390744 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "STCAgent"="c:\program files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe" [2011-03-04 776064] "ZyngaGamesAgent"="c:\program files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" [2010-11-15 841544] "HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2010-12-27 3005552] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-10-19 258512] "hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" . R2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-10-19 86224] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x] R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2012-01-12 2152152] R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [2012-01-12 17152] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x] S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x] S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [2011-10-25 341288] S2 SCBackService;Splashtop Connect Service;c:\program files (x86)\Splashtop\Splashtop Connect\BackService.exe [2010-11-15 477000] S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-10-05 2655768] S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe [x] S2 WCUService_STC_FF;Splashtop Connect Firefox Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe [2011-03-24 493384] S2 WCUService_STC_IE;Splashtop Connect IE Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe [2011-03-22 497480] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x] S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-12 168216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-12 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-12 416024] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 IE: Free YouTube to MP3 Converter - c:\users\Colin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html TCP: DhcpNameServer = [removed] [removed] . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*] "value"="?\0a\06\1d\13\0e\15Ï" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe c:\program files (x86)\HP\Digital Imaging\bin\hpqbam08.exe c:\program files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe . ************************************************************************** . Completion time: 2012-01-13 23:13:36 - machine was rebooted ComboFix-quarantined-files.txt 2012-01-13 23:13 ComboFix2.txt 2012-01-13 22:38 . Pre-Run: 934,699,569,152 bytes free Post-Run: 934,391,570,432 bytes free . - - End Of File - - 360B183294BCBF407D9C4EE98F8182D9
08:47:54.0701 3616 TDSS rootkit removing tool [removed] Jan 13 2012 15:24:05 08:47:54.0841 3616 ============================================================ 08:47:54.0841 3616 Current date / time: 2012/01/14 08:47:54.0841 08:47:54.0841 3616 SystemInfo: 08:47:54.0841 3616 08:47:54.0841 3616 OS Version: 6.1.7601 ServicePack: 1.0 08:47:54.0841 3616 Product type: Workstation 08:47:54.0841 3616 ComputerName: SMITH 08:47:54.0841 3616 UserName: Colin 08:47:54.0841 3616 Windows directory: C:\Windows 08:47:54.0841 3616 System windows directory: C:\Windows 08:47:54.0841 3616 Running under WOW64 08:47:54.0841 3616 Processor architecture: Intel x64 08:47:54.0841 3616 Number of processors: 2 08:47:54.0841 3616 Page size: 0x1000 08:47:54.0841 3616 Boot type: Normal boot 08:47:54.0841 3616 ============================================================ 08:47:55.0605 3616 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000, SectorSize: 0x200, Cylinders: 0x1F8B1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K', Flags 0x00000040 08:47:55.0637 3616 Initialize success 08:48:00.0067 3716 ============================================================ 08:48:00.0067 3716 Scan started 08:48:00.0067 3716 Mode: Manual; 08:48:00.0067 3716 ============================================================ 08:48:00.0972 3716 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys 08:48:00.0972 3716 1394ohci - ok 08:48:01.0003 3716 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys 08:48:01.0003 3716 ACPI - ok 08:48:01.0003 3716 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys 08:48:01.0003 3716 AcpiPmi - ok 08:48:01.0034 3716 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys 08:48:01.0034 3716 adp94xx - ok 08:48:01.0050 3716 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys 08:48:01.0050 3716 adpahci - ok 08:48:01.0065 3716 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys 08:48:01.0065 3716 adpu320 - ok 08:48:01.0097 3716 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys 08:48:01.0112 3716 AFD - ok 08:48:01.0175 3716 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys 08:48:01.0175 3716 agp440 - ok 08:48:01.0206 3716 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys 08:48:01.0206 3716 aliide - ok 08:48:01.0206 3716 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys 08:48:01.0206 3716 amdide - ok 08:48:01.0221 3716 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys 08:48:01.0221 3716 AmdK8 - ok 08:48:01.0237 3716 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys 08:48:01.0237 3716 AmdPPM - ok 08:48:01.0253 3716 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys 08:48:01.0253 3716 amdsata - ok 08:48:01.0268 3716 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys 08:48:01.0268 3716 amdsbs - ok 08:48:01.0284 3716 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys 08:48:01.0284 3716 amdxata - ok 08:48:01.0377 3716 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys 08:48:01.0377 3716 AppID - ok 08:48:01.0393 3716 AppleCharger (6be11ad81d4527d299f0cb5f3731aabc) C:\Windows\system32\DRIVERS\AppleCharger.sys 08:48:01.0393 3716 AppleCharger - ok 08:48:01.0424 3716 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys 08:48:01.0424 3716 arc - ok 08:48:01.0424 3716 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys 08:48:01.0440 3716 arcsas - ok 08:48:01.0455 3716 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 08:48:01.0455 3716 AsyncMac - ok 08:48:01.0455 3716 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys 08:48:01.0455 3716 atapi - ok 08:48:01.0487 3716 avgntflt (aa8f79a1bdfc03b3bc70c44ab00589b4) C:\Windows\system32\DRIVERS\avgntflt.sys 08:48:01.0487 3716 avgntflt - ok 08:48:01.0565 3716 avipbb (d959309ececca73fc79f8ef8521346b2) C:\Windows\system32\DRIVERS\avipbb.sys 08:48:01.0565 3716 avipbb - ok 08:48:01.0580 3716 avkmgr (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys 08:48:01.0580 3716 avkmgr - ok 08:48:01.0611 3716 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys 08:48:01.0611 3716 b06bdrv - ok 08:48:01.0643 3716 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 08:48:01.0643 3716 b57nd60a - ok 08:48:01.0689 3716 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 08:48:01.0689 3716 Beep - ok 08:48:01.0783 3716 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 08:48:01.0783 3716 blbdrive - ok 08:48:01.0814 3716 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys 08:48:01.0814 3716 bowser - ok 08:48:01.0845 3716 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys 08:48:01.0845 3716 BrFiltLo - ok 08:48:01.0845 3716 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys 08:48:01.0845 3716 BrFiltUp - ok 08:48:01.0861 3716 BridgeMP (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys 08:48:01.0877 3716 BridgeMP - ok 08:48:01.0908 3716 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 08:48:01.0908 3716 Brserid - ok 08:48:01.0923 3716 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 08:48:01.0923 3716 BrSerWdm - ok 08:48:01.0939 3716 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 08:48:01.0939 3716 BrUsbMdm - ok 08:48:01.0939 3716 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 08:48:01.0939 3716 BrUsbSer - ok 08:48:01.0955 3716 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys 08:48:01.0955 3716 BTHMODEM - ok 08:48:01.0986 3716 catchme - ok 08:48:02.0048 3716 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 08:48:02.0064 3716 cdfs - ok 08:48:02.0204 3716 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys 08:48:02.0204 3716 cdrom - ok 08:48:02.0235 3716 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys 08:48:02.0235 3716 circlass - ok 08:48:02.0282 3716 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 08:48:02.0298 3716 CLFS - ok 08:48:02.0345 3716 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\drivers\CmBatt.sys 08:48:02.0345 3716 CmBatt - ok 08:48:02.0376 3716 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys 08:48:02.0376 3716 cmdide - ok 08:48:02.0407 3716 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys 08:48:02.0423 3716 CNG - ok 08:48:02.0438 3716 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys 08:48:02.0438 3716 Compbatt - ok 08:48:02.0485 3716 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\DRIVERS\CompositeBus.sys 08:48:02.0485 3716 CompositeBus - ok 08:48:02.0501 3716 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys 08:48:02.0501 3716 crcdisk - ok 08:48:02.0547 3716 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys 08:48:02.0547 3716 DfsC - ok 08:48:02.0563 3716 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 08:48:02.0563 3716 discache - ok 08:48:02.0625 3716 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys 08:48:02.0625 3716 Disk - ok 08:48:02.0657 3716 Dot4 (b42ed0320c6e41102fde0005154849bb) C:\Windows\system32\DRIVERS\Dot4.sys 08:48:02.0672 3716 Dot4 - ok 08:48:02.0703 3716 Dot4Print (e9f5969233c5d89f3c35e3a66a52a361) C:\Windows\system32\DRIVERS\Dot4Prt.sys 08:48:02.0703 3716 Dot4Print - ok 08:48:02.0719 3716 dot4usb (fd05a02b0370bc3000f402e543ca5814) C:\Windows\system32\DRIVERS\dot4usb.sys 08:48:02.0719 3716 dot4usb - ok 08:48:02.0750 3716 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 08:48:02.0750 3716 drmkaud - ok 08:48:02.0781 3716 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys 08:48:02.0781 3716 DXGKrnl - ok 08:48:02.0844 3716 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys 08:48:02.0875 3716 ebdrv - ok 08:48:02.0953 3716 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys 08:48:02.0969 3716 elxstor - ok 08:48:02.0984 3716 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys 08:48:02.0984 3716 ErrDev - ok 08:48:03.0015 3716 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 08:48:03.0015 3716 exfat - ok 08:48:03.0031 3716 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 08:48:03.0031 3716 fastfat - ok 08:48:03.0062 3716 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys 08:48:03.0062 3716 fdc - ok 08:48:03.0140 3716 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 08:48:03.0140 3716 FileInfo - ok 08:48:03.0156 3716 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 08:48:03.0156 3716 Filetrace - ok 08:48:03.0156 3716 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys 08:48:03.0156 3716 flpydisk - ok 08:48:03.0187 3716 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys 08:48:03.0187 3716 FltMgr - ok 08:48:03.0203 3716 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 08:48:03.0203 3716 FsDepends - ok 08:48:03.0218 3716 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 08:48:03.0218 3716 Fs_Rec - ok 08:48:03.0249 3716 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys 08:48:03.0249 3716 fvevol - ok 08:48:03.0312 3716 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys 08:48:03.0312 3716 gagp30kx - ok 08:48:03.0312 3716 gdrv - ok 08:48:03.0343 3716 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 08:48:03.0343 3716 hcw85cir - ok 08:48:03.0374 3716 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys 08:48:03.0374 3716 HdAudAddService - ok 08:48:03.0390 3716 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\DRIVERS\HDAudBus.sys 08:48:03.0390 3716 HDAudBus - ok 08:48:03.0405 3716 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys 08:48:03.0405 3716 HidBatt - ok 08:48:03.0421 3716 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys 08:48:03.0421 3716 HidBth - ok 08:48:03.0421 3716 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys 08:48:03.0421 3716 HidIr - ok 08:48:03.0468 3716 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys 08:48:03.0468 3716 HidUsb - ok 08:48:03.0546 3716 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys 08:48:03.0546 3716 HpSAMD - ok 08:48:03.0561 3716 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys 08:48:03.0577 3716 HTTP - ok 08:48:03.0593 3716 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys 08:48:03.0593 3716 hwpolicy - ok 08:48:03.0608 3716 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys 08:48:03.0608 3716 i8042prt - ok 08:48:03.0655 3716 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys 08:48:03.0655 3716 iaStorV - ok 08:48:03.0858 3716 igfx (174bcac474de13b2650e444cf124828e) C:\Windows\system32\DRIVERS\igdkmd64.sys 08:48:03.0967 3716 igfx - ok 08:48:04.0045 3716 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys 08:48:04.0045 3716 iirsp - ok 08:48:04.0061 3716 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys 08:48:04.0061 3716 intelide - ok 08:48:04.0076 3716 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 08:48:04.0076 3716 intelppm - ok 08:48:04.0123 3716 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys 08:48:04.0123 3716 IpFilterDriver - ok 08:48:04.0139 3716 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys 08:48:04.0139 3716 IPMIDRV - ok 08:48:04.0154 3716 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 08:48:04.0154 3716 IPNAT - ok 08:48:04.0170 3716 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 08:48:04.0170 3716 IRENUM - ok 08:48:04.0170 3716 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys 08:48:04.0170 3716 isapnp - ok 08:48:04.0201 3716 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys 08:48:04.0201 3716 iScsiPrt - ok 08:48:04.0263 3716 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys 08:48:04.0263 3716 kbdclass - ok 08:48:04.0263 3716 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys 08:48:04.0263 3716 kbdhid - ok 08:48:04.0295 3716 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys 08:48:04.0295 3716 KSecDD - ok 08:48:04.0310 3716 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys 08:48:04.0310 3716 KSecPkg - ok 08:48:04.0326 3716 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 08:48:04.0326 3716 ksthunk - ok 08:48:04.0357 3716 L1C (173666119d217e3739205c169e2bf0e5) C:\Windows\system32\DRIVERS\L1C62x64.sys 08:48:04.0357 3716 L1C - ok 08:48:04.0451 3716 Lavasoft Kernexplorer (9a7fa6371f68335fd3c3d6488bc5a9f8) C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys 08:48:04.0451 3716 Lavasoft Kernexplorer - ok 08:48:04.0497 3716 Lbd (c8b3131857931ae76798a741cc52b021) C:\Windows\system32\DRIVERS\Lbd.sys 08:48:04.0497 3716 Lbd - ok 08:48:04.0544 3716 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 08:48:04.0544 3716 lltdio - ok 08:48:04.0575 3716 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys 08:48:04.0591 3716 LSI_FC - ok 08:48:04.0591 3716 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys 08:48:04.0591 3716 LSI_SAS - ok 08:48:04.0607 3716 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys 08:48:04.0607 3716 LSI_SAS2 - ok 08:48:04.0622 3716 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys 08:48:04.0622 3716 LSI_SCSI - ok 08:48:04.0638 3716 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 08:48:04.0638 3716 luafv - ok 08:48:04.0669 3716 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys 08:48:04.0669 3716 megasas - ok 08:48:04.0700 3716 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys 08:48:04.0716 3716 MegaSR - ok 08:48:04.0731 3716 MEIx64 (1c6e73fc46b509eff9d0086aa37132df) C:\Windows\system32\DRIVERS\HECIx64.sys 08:48:04.0731 3716 MEIx64 - ok 08:48:04.0763 3716 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 08:48:04.0763 3716 Modem - ok 08:48:04.0794 3716 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 08:48:04.0794 3716 monitor - ok 08:48:04.0809 3716 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys 08:48:04.0809 3716 mouclass - ok 08:48:04.0872 3716 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 08:48:04.0872 3716 mouhid - ok 08:48:04.0903 3716 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys 08:48:04.0903 3716 mountmgr - ok 08:48:04.0919 3716 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys 08:48:04.0919 3716 mpio - ok 08:48:04.0934 3716 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 08:48:04.0934 3716 mpsdrv - ok 08:48:04.0965 3716 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys 08:48:04.0965 3716 MRxDAV - ok 08:48:04.0997 3716 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys 08:48:04.0997 3716 mrxsmb - ok 08:48:05.0012 3716 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys 08:48:05.0012 3716 mrxsmb10 - ok 08:48:05.0059 3716 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 08:48:05.0059 3716 mrxsmb20 - ok 08:48:05.0090 3716 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys 08:48:05.0090 3716 msahci - ok 08:48:05.0121 3716 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys 08:48:05.0121 3716 msdsm - ok 08:48:05.0137 3716 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 08:48:05.0137 3716 Msfs - ok 08:48:05.0168 3716 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 08:48:05.0168 3716 mshidkmdf - ok 08:48:05.0184 3716 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys 08:48:05.0184 3716 msisadrv - ok 08:48:05.0215 3716 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 08:48:05.0215 3716 MSKSSRV - ok 08:48:05.0246 3716 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 08:48:05.0246 3716 MSPCLOCK - ok 08:48:05.0246 3716 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 08:48:05.0246 3716 MSPQM - ok 08:48:05.0262 3716 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys 08:48:05.0277 3716 MsRPC - ok 08:48:05.0293 3716 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys 08:48:05.0293 3716 mssmbios - ok 08:48:05.0309 3716 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 08:48:05.0309 3716 MSTEE - ok 08:48:05.0324 3716 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys 08:48:05.0324 3716 MTConfig - ok 08:48:05.0340 3716 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 08:48:05.0355 3716 Mup - ok 08:48:05.0418 3716 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 08:48:05.0433 3716 NativeWifiP - ok 08:48:05.0465 3716 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys 08:48:05.0480 3716 NDIS - ok 08:48:05.0496 3716 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 08:48:05.0496 3716 NdisCap - ok 08:48:05.0511 3716 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 08:48:05.0511 3716 NdisTapi - ok 08:48:05.0543 3716 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys 08:48:05.0543 3716 Ndisuio - ok 08:48:05.0558 3716 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys 08:48:05.0558 3716 NdisWan - ok 08:48:05.0574 3716 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys 08:48:05.0574 3716 NDProxy - ok 08:48:05.0652 3716 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 08:48:05.0652 3716 NetBIOS - ok 08:48:05.0667 3716 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys 08:48:05.0667 3716 NetBT - ok 08:48:05.0714 3716 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys 08:48:05.0714 3716 nfrd960 - ok 08:48:05.0761 3716 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 08:48:05.0761 3716 Npfs - ok 08:48:05.0777 3716 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 08:48:05.0777 3716 nsiproxy - ok 08:48:05.0870 3716 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys 08:48:05.0886 3716 Ntfs - ok 08:48:05.0901 3716 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 08:48:05.0901 3716 Null - ok 08:48:05.0933 3716 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys 08:48:05.0933 3716 nvraid - ok 08:48:05.0964 3716 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys 08:48:05.0964 3716 nvstor - ok 08:48:05.0979 3716 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys 08:48:05.0979 3716 nv_agp - ok 08:48:06.0042 3716 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys 08:48:06.0042 3716 ohci1394 - ok 08:48:06.0089 3716 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys 08:48:06.0089 3716 Parport - ok 08:48:06.0104 3716 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys 08:48:06.0104 3716 partmgr - ok 08:48:06.0120 3716 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys 08:48:06.0120 3716 pci - ok 08:48:06.0135 3716 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys 08:48:06.0135 3716 pciide - ok 08:48:06.0167 3716 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys 08:48:06.0167 3716 pcmcia - ok 08:48:06.0198 3716 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 08:48:06.0198 3716 pcw - ok 08:48:06.0260 3716 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 08:48:06.0276 3716 PEAUTH - ok 08:48:06.0338 3716 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys 08:48:06.0338 3716 PptpMiniport - ok 08:48:06.0338 3716 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys 08:48:06.0354 3716 Processor - ok 08:48:06.0369 3716 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys 08:48:06.0369 3716 Psched - ok 08:48:06.0447 3716 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys 08:48:06.0463 3716 ql2300 - ok 08:48:06.0479 3716 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys 08:48:06.0479 3716 ql40xx - ok 08:48:06.0494 3716 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 08:48:06.0494 3716 QWAVEdrv - ok 08:48:06.0510 3716 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 08:48:06.0525 3716 RasAcd - ok 08:48:06.0557 3716 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 08:48:06.0557 3716 RasAgileVpn - ok 08:48:06.0572 3716 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys 08:48:06.0572 3716 Rasl2tp - ok 08:48:06.0588 3716 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 08:48:06.0588 3716 RasPppoe - ok 08:48:06.0650 3716 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 08:48:06.0650 3716 RasSstp - ok 08:48:06.0666 3716 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys 08:48:06.0666 3716 rdbss - ok 08:48:06.0681 3716 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\drivers\rdpbus.sys 08:48:06.0681 3716 rdpbus - ok 08:48:06.0697 3716 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 08:48:06.0697 3716 RDPCDD - ok 08:48:06.0728 3716 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 08:48:06.0728 3716 RDPENCDD - ok 08:48:06.0744 3716 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 08:48:06.0744 3716 RDPREFMP - ok 08:48:06.0759 3716 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys 08:48:06.0775 3716 RDPWD - ok 08:48:06.0853 3716 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys 08:48:06.0853 3716 rdyboost - ok 08:48:06.0900 3716 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 08:48:06.0915 3716 rspndr - ok 08:48:06.0931 3716 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys 08:48:06.0931 3716 sbp2port - ok 08:48:06.0947 3716 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys 08:48:06.0947 3716 scfilter - ok 08:48:06.0978 3716 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 08:48:06.0978 3716 secdrv - ok 08:48:06.0993 3716 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys 08:48:06.0993 3716 Serenum - ok 08:48:07.0056 3716 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys 08:48:07.0056 3716 Serial - ok 08:48:07.0087 3716 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys 08:48:07.0087 3716 sermouse - ok 08:48:07.0118 3716 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys 08:48:07.0118 3716 sffdisk - ok 08:48:07.0118 3716 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys 08:48:07.0118 3716 sffp_mmc - ok 08:48:07.0134 3716 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys 08:48:07.0134 3716 sffp_sd - ok 08:48:07.0134 3716 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys 08:48:07.0134 3716 sfloppy - ok 08:48:07.0181 3716 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys 08:48:07.0196 3716 SiSRaid2 - ok 08:48:07.0274 3716 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys 08:48:07.0290 3716 SiSRaid4 - ok 08:48:07.0321 3716 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 08:48:07.0321 3716 Smb - ok 08:48:07.0383 3716 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 08:48:07.0383 3716 spldr - ok 08:48:07.0415 3716 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys 08:48:07.0415 3716 srv - ok 08:48:07.0446 3716 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys 08:48:07.0446 3716 srv2 - ok 08:48:07.0461 3716 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys 08:48:07.0477 3716 srvnet - ok 08:48:07.0493 3716 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys 08:48:07.0508 3716 stexstor - ok 08:48:07.0555 3716 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys 08:48:07.0555 3716 swenum - ok 08:48:07.0617 3716 Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys 08:48:07.0649 3716 Tcpip - ok 08:48:07.0680 3716 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys 08:48:07.0680 3716 TCPIP6 - ok 08:48:07.0695 3716 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys 08:48:07.0695 3716 tcpipreg - ok 08:48:07.0727 3716 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 08:48:07.0727 3716 TDPIPE - ok 08:48:07.0789 3716 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys 08:48:07.0789 3716 TDTCP - ok 08:48:07.0805 3716 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys 08:48:07.0805 3716 tdx - ok 08:48:07.0820 3716 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\DRIVERS\termdd.sys 08:48:07.0820 3716 TermDD - ok 08:48:07.0851 3716 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys 08:48:07.0851 3716 tssecsrv - ok 08:48:07.0867 3716 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys 08:48:07.0867 3716 TsUsbFlt - ok 08:48:07.0883 3716 TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys 08:48:07.0883 3716 TsUsbGD - ok 08:48:07.0914 3716 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys 08:48:07.0914 3716 tunnel - ok 08:48:07.0945 3716 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys 08:48:07.0945 3716 uagp35 - ok 08:48:07.0976 3716 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys 08:48:07.0976 3716 udfs - ok 08:48:07.0992 3716 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys 08:48:07.0992 3716 uliagpkx - ok 08:48:08.0023 3716 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys 08:48:08.0023 3716 umbus - ok 08:48:08.0039 3716 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys 08:48:08.0039 3716 UmPass - ok 08:48:08.0085 3716 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys 08:48:08.0085 3716 usbccgp - ok 08:48:08.0132 3716 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys 08:48:08.0132 3716 usbcir - ok 08:48:08.0163 3716 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys 08:48:08.0163 3716 usbehci - ok 08:48:08.0179 3716 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys 08:48:08.0179 3716 usbhub - ok 08:48:08.0210 3716 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys 08:48:08.0210 3716 usbohci - ok 08:48:08.0226 3716 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 08:48:08.0226 3716 usbprint - ok 08:48:08.0257 3716 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys 08:48:08.0257 3716 usbscan - ok 08:48:08.0288 3716 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS 08:48:08.0288 3716 USBSTOR - ok 08:48:08.0351 3716 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys 08:48:08.0351 3716 usbuhci - ok 08:48:08.0382 3716 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys 08:48:08.0382 3716 vdrvroot - ok 08:48:08.0413 3716 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 08:48:08.0413 3716 vga - ok 08:48:08.0429 3716 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 08:48:08.0429 3716 VgaSave - ok 08:48:08.0444 3716 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys 08:48:08.0460 3716 vhdmp - ok 08:48:08.0569 3716 VIAHdAudAddService (279030ef4c22919f756269206e0e533f) C:\Windows\system32\drivers\viahduaa.sys 08:48:08.0585 3716 VIAHdAudAddService - ok 08:48:08.0600 3716 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys 08:48:08.0600 3716 viaide - ok 08:48:08.0616 3716 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys 08:48:08.0616 3716 volmgr - ok 08:48:08.0647 3716 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys 08:48:08.0647 3716 volmgrx - ok 08:48:08.0678 3716 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys 08:48:08.0678 3716 volsnap - ok 08:48:08.0741 3716 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys 08:48:08.0741 3716 vsmraid - ok 08:48:08.0756 3716 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys 08:48:08.0756 3716 vwifibus - ok 08:48:08.0772 3716 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys 08:48:08.0772 3716 WacomPen - ok 08:48:08.0803 3716 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 08:48:08.0803 3716 WANARP - ok 08:48:08.0819 3716 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 08:48:08.0819 3716 Wanarpv6 - ok 08:48:08.0850 3716 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys 08:48:08.0850 3716 Wd - ok 08:48:08.0881 3716 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 08:48:08.0881 3716 Wdf01000 - ok 08:48:08.0975 3716 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 08:48:08.0975 3716 WfpLwf - ok 08:48:08.0990 3716 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 08:48:08.0990 3716 WIMMount - ok 08:48:09.0053 3716 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys 08:48:09.0053 3716 WinUsb - ok 08:48:09.0068 3716 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys 08:48:09.0068 3716 WmiAcpi - ok 08:48:09.0084 3716 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 08:48:09.0084 3716 ws2ifsl - ok 08:48:09.0115 3716 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys 08:48:09.0115 3716 WudfPf - ok 08:48:09.0177 3716 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys 08:48:09.0177 3716 WUDFRd - ok 08:48:09.0209 3716 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 08:48:09.0255 3716 \Device\Harddisk0\DR0 - ok 08:48:09.0255 3716 Boot (0x1200) (a35e4288289d2ac68232eeb16f2d2d11) \Device\Harddisk0\DR0\Partition0 08:48:09.0255 3716 \Device\Harddisk0\DR0\Partition0 - ok 08:48:09.0302 3716 Boot (0x1200) (feaffca5396fb0248019b95c8155b261) \Device\Harddisk0\DR0\Partition1 08:48:09.0302 3716 \Device\Harddisk0\DR0\Partition1 - ok 08:48:09.0302 3716 ============================================================ 08:48:09.0302 3716 Scan finished 08:48:09.0302 3716 ============================================================ 08:48:09.0318 3840 Detected object count: 0 08:48:09.0318 3840 Actual detected object count: 0 08:48:40.0409 3868 Deinitialize success
Hi

That log and the ComboFix log looked good.

P2P - I see you have P2P software, (Azureus), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as as their main form of transport for spreading their filth.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

Download Malwarebytes-Anti-Malware

Click here
  • double-click mbam-setup.exe and follow the prompts to install the program.
  • at the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware. and Launch Malwarebytes' Anti-Malware, then click Finish..
  • if an update is found, it will download and install the latest version.
  • once the program has loaded, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

================================================

Run Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Logs to include with next post:

Mbam.txt
Checkup.txt


Please tell me if there are any remaining symptoms.

Thanks

Satchfan
I dont appear to have any issues now. I was confused re the Azureus programme as I never installed that, But as I got this PC as a present and my son knew I wanted a certain programme he has probably used that to obtain it. I have done a search and I cant find the programme (also tried Vuze) I did find a key generator so I am thinking that is what was showing up, All deleted now.

A couple of other questions.
1. When the virus installed I lost some files off the desktop and also my web favourites, neither is an issue as I do have an external back up but can I assume they will need to be reinstalled etc.
2. Avira I have been unable to update their files should I uninstall and then re install, I also appear to have conflict with avira and adware running and I am sure there is mention of windows defender. What should be on and what off?
In previous PCs I had this spot on but since upgrading to Win 7 I am still trying to find my way around to an extent.

Mbam text…


Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Database version: v2012.01.14.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Colin :: SMITH [administrator]

14/01/2012 16:24:53
mbam-log-2012-01-14 (16-24-53).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 213273
Time elapsed: 1 minute(s), 55 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 1
HKCU\Software\SkyMedia (Adware.SkyMedia) -> Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
C:\Users\Colin\Downloads\cnet_ScreenGrabPro_zip.exe (PUP.CNET.Adware.Bundle) -> Quarantined and deleted successfully.
C:\Users\Colin\Downloads\getreader.exe (PUP.BundleInstaller.OI) -> Quarantined and deleted successfully.

(end)
……………………………………………………………………..
………..


Check up….

Results of screen317's Security Check version 0.99.30
Windows 7 x64 (UAC is enabled)
Internet Explorer 8 Out of date!
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
Avira Free Antivirus
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:

Ad-Aware
Mozilla Firefox (for..)
Mozilla Thunderbird (x86 en-GB..)
````````````````````````````````
Process Check:
objlist.exe by Laurent

Ad-Aware AAWService.exe
Ad-Aware AAWTray.exe
Avira Antivir avgnt.exe
``````````End of Log````````````

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI