This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Very slow start up and shut down

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My PC is starting up very slow and shutting down very slow, then drags some while in use. I am posting my OTL scan… My PC info under my member info to the left. thanks for the help.

OTL logfile created on: 1/17/2012 12:15:17 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Amy\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.17 Gb Available Physical Memory | 58.57% Memory free
4.00 Gb Paging File | 3.15 Gb Available in Paging File | 78.90% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 23.33 Gb Free Space | 31.31% Space Free | Partition Type: NTFS

Computer Name: AMY-PC | User Name: Amy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Amy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Amy\AppData\Local\Google\Update\1.3.21.79\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (NVIDIA Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Sprint\Sprint SmartView\SwiApiMuxCdma.exe (Sierra Wireless, Inc.)
PRC - C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe (Sprint)
PRC - C:\Program Files\Sprint\Sprint SmartView\RDVCHG.exe (C-motech Co.,Ltd)
PRC - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe (SmithMicro Inc.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe ()
PRC - C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Sprint\Sprint SmartView\Pac.dll ()
MOD - C:\Program Files\Sprint\Sprint SmartView\Eap.dll ()


========== Win32 Services (SafeList) ==========

SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (SprintRcAppSvc) – C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe (SmithMicro Inc.)
SRV - (CASprint) – C:\Program Files\Sprint\Sprint SmartView\ConAppsSvc.exe (SmithMicro Inc.)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (NvtlService) – C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe ()
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (dc3d) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (Nmea) – C:\Windows\System32\drivers\pctnullport.sys (PCTEL Inc.)
DRV - (PCTINDIS5) – C:\Windows\System32\PCTINDIS5.sys (Smith Micro Inc.)
DRV - (vmbus) – C:\Windows\system32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (RdpVideoMiniport) – C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (RMCAST) – C:\Windows\System32\drivers\rmcast.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (SWNC5E00) Sierra Wireless MUX NDIS Driver (#00) – C:\Windows\System32\drivers\SWNC5E00.sys (Sierra Wireless Inc.)
DRV - (swmx00) Sierra Wireless USB MUX Driver (#00) – C:\Windows\System32\drivers\swmx00.sys (Sierra Wireless Inc.)
DRV - (swmsflt) – C:\Windows\System32\drivers\swmsflt.sys ()
DRV - (NWADI) – C:\Windows\System32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys ()
DRV - (Serial) – C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (WDC_SAM) – C:\Windows\System32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (sscdserd) SAMSUNG CDMA Modem Diagnostic Serial Port (WDM) – C:\Windows\System32\drivers\sscdserd.sys (MCCI)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)
DRV - (RTL8023xp) – C:\Windows\System32\drivers\EG1032xp.sys (Linksys, A Division of Cisco Systems, Inc )


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = C:\Users\Amy\Desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://amyost.homestead.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 25 EF 16 03 EF EA CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://amyost.homestead.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.10.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..keyword.URL: "chrome://browser-region/locale/region.properties"


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Amy\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Amy\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2010/12/02 11:35:58 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\MSBuild\Mozilla Firefox\components [2012/01/15 17:53:52 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\MSBuild\Mozilla Firefox\plugins [2011/09/15 05:30:24 | 000,000,000 | —D | M]

[2010/05/03 20:07:28 | 000,000,000 | —D | M] (No name found) – C:\Users\Amy\AppData\Roaming\Mozilla\Extensions
[2012/01/15 17:53:38 | 000,000,000 | —D | M] (No name found) – C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\wkm8mbi8.default\extensions
[2012/01/15 17:53:54 | 000,000,000 | —D | M] (Zynga Community Toolbar) – C:\Users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\wkm8mbi8.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Amy\AppData\Local\Google\Chrome\Application\9.0.597.98\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Users\Amy\AppData\Local\Google\Chrome\Application\9.0.597.98\gears.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Amy\AppData\Local\Google\Chrome\Application\9.0.597.98\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.230.5 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U23 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Amy\AppData\Local\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Scorpion Solitaire = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnlfhfpojmehjcdldbclpgfclmdodpin\1_0\
CHR - Extension: Mahjongg Solitaire = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccklcogklfjbajdeimbknkplphkjbkhb\1_0\
CHR - Extension: Earthquake Alert = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceddfjkhemabgponojbabonhjpclgaja\0.4_0\
CHR - Extension: Solitaire Card Games = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkelcbhdkpcdiiancfjhjcpdinbbfolp\1.0.0.2_0\
CHR - Extension: Super Mario = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnkjbdmdgifgkcenpllpepgcgllapgpm\1_0\
CHR - Extension: Solitairey = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\dofbnmhnoodmmlhflbcihicmbnhhinhp\2.2.4_0\
CHR - Extension: Games.com = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\eciiciccngmnpknipagfcpdbpbejladh\0.0.0.3_0\
CHR - Extension: Namco Mahjong Butterfly = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdpljegkclkedmcmfpdfgomeoojlajaa\1.104_0\
CHR - Extension: World of Solitaire = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifbnllnaaaohekjkcpfdllhhjijnidgn\1.0.1_0\
CHR - Extension: Farty mcFart = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijghjfglokjbecncjijjocbmcbbhgpkc\1.2_0\
CHR - Extension: HuffingtonPost NewsGlide = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\khjialelnkjdomiblmnpcpjongleegef\0.3.2_0\
CHR - Extension: Just Solitaire = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcbhedoainjipdhgimhhajobmblbaopf\2.1_0\
CHR - Extension: Google Maps = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh\5.2.3_0\
CHR - Extension: Word\u00B2 = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpibnckjjeaabeepofhfmmpjmnomohee\2.5_0\
CHR - Extension: US Cities = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbljbaeppeadkjipnapacpommhijhbel\1_0\
CHR - Extension: Google Books = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb\0.0.0.6_0\
CHR - Extension: Word Scramble II = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnnoadpilbdgjcffnbflkahalmfflpdh\1_0\
CHR - Extension: Typing Game = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mobfbeogeanchbdhboilncgnkfkibjjg\1.0.3.0_0\
CHR - Extension: Mahjong Solitaire = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\neojceinbonpjjcokpokpeobkhcpiloc\1.0.0.1_0\
CHR - Extension: Demon Solitaire = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhmiblkonfdnknhmhegmeddkmljlnjbd\1_0\
CHR - Extension: Heavy Jumble = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nolnangifendohpjiagboafdlkfhbaml\1_0\
CHR - Extension: Puzzle Games from Big Fish Games = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\npolkgeaiepngllaancmiflhecgfdhnj\1.1_0\
CHR - Extension: Reversi = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\odhjkapjdlmmadkepnmlkpadnnnnoebm\0.0.0.3_0\
CHR - Extension: Draw My Thing = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\odpjeimbfolekeldhfddmbemmpiffkch\1.0_0\
CHR - Extension: Mysteriez! = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\phhpkfchfjfeicikkkajdojpjkapdpnd\1.0.1_0\
CHR - Extension: Gmail = C:\Users\Amy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2011/12/03 22:02:04 | 000,438,048 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15093 more lines…
O2 - BHO: (Reg Error: Value error.) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [RDVCHG] C:\Program Files\Sprint\Sprint SmartView\RDVCHG.exe (C-motech Co.,Ltd)
O4 - HKLM..\Run: [Sprint SmartView] C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe (Sprint)
O4 - HKCU..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\Program Files\IncrediMail\Bin\resources\WebMenuImg.htm ()
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{28AB4157-57D1-4951-820D-BE2B23AC05C4}: NameServer = 68.28.137.132 68.28.138.132
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/01/17 00:10:54 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Amy\Desktop\OTL.exe
[2012/01/16 13:50:06 | 000,000,000 | —D | C] – C:\ProgramData\RegCure
[2011/12/30 21:24:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
[2011/12/22 21:47:37 | 000,204,496 | —- | C] (Malwarebytes) – C:\Users\Amy\Desktop\StartUpLite.exe

========== Files - Modified Within 30 Days ==========

[2012/01/17 00:11:08 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Amy\Desktop\OTL.exe
[2012/01/17 00:03:00 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/16 23:58:36 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4154655496-4122381350-236684040-1000UA.job
[2012/01/16 23:58:26 | 000,002,385 | —- | M] () – C:\Users\Amy\Desktop\Google Chrome.lnk
[2012/01/16 23:43:00 | 000,000,848 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4154655496-4122381350-236684040-1000Core.job
[2012/01/16 23:35:03 | 000,017,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/16 23:35:03 | 000,017,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/16 23:34:34 | 000,623,940 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/01/16 23:34:34 | 000,106,316 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/01/16 23:28:02 | 000,000,499 | —- | M] () – C:\Windows\System32\drivers\etc\hosts.ics
[2012/01/16 23:26:09 | 000,001,072 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2012/01/16 23:25:59 | 000,000,876 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/16 23:22:54 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/01/16 23:22:15 | 1608,880,128 | -HS- | M] () – C:\hiberfil.sys
[2012/01/16 14:39:28 | 000,007,661 | —- | M] () – C:\Users\Amy\AppData\Local\Resmon.ResmonCfg
[2012/01/15 21:55:21 | 281,428,358 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/12/22 21:47:43 | 000,204,496 | —- | M] (Malwarebytes) – C:\Users\Amy\Desktop\StartUpLite.exe
[2011/12/18 06:57:09 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl

========== Files Created - No Company Name ==========

[2012/01/16 23:38:45 | 000,000,900 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4154655496-4122381350-236684040-1000UA.job
[2012/01/16 23:38:44 | 000,000,848 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4154655496-4122381350-236684040-1000Core.job
[2012/01/15 21:55:21 | 281,428,358 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/12/03 22:52:19 | 000,000,115 | —- | C] () – C:\Windows\wininit.ini
[2011/10/21 11:40:56 | 000,000,000 | —- | C] () – C:\Users\Amy\AppData\Local\{818FCAC6-A463-44AD-8B14-F719C1C3D1D7}
[2011/05/22 20:42:38 | 000,331,776 | —- | C] () – C:\Windows\System32\TwcToolbarIe7.dll
[2011/05/22 20:42:38 | 000,098,304 | —- | C] () – C:\Windows\System32\TwcToolbarBho.dll
[2011/05/20 01:28:24 | 000,080,896 | —- | C] () – C:\Windows\System32\RDVGHelper.exe
[2011/05/20 01:26:33 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011/04/14 17:03:40 | 000,003,565 | —- | C] () – C:\Windows\System32\RDDlg.dat
[2010/11/20 18:11:32 | 000,001,072 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2010/11/09 12:36:02 | 000,012,288 | —- | C] () – C:\Users\Amy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/22 14:31:43 | 000,000,035 | —- | C] () – C:\Windows\A5W.INI
[2010/07/22 11:48:30 | 000,007,661 | —- | C] () – C:\Users\Amy\AppData\Local\Resmon.ResmonCfg
[2010/06/08 15:36:06 | 000,037,248 | —- | C] () – C:\Windows\System32\drivers\swmsflt.sys
[2009/07/13 23:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 23:33:53 | 000,268,184 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 21:05:48 | 000,623,940 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/13 21:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/13 21:05:48 | 000,106,316 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/13 21:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/13 21:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/13 21:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/13 18:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 18:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[1997/11/10 14:18:48 | 000,010,240 | —- | C] () – C:\Windows\System32\vidx16.dll

========== LOP Check ==========

[2010/11/05 20:52:18 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\acccore
[2010/10/20 05:18:40 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\AVG10
[2010/05/03 13:30:28 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\Bytemobile
[2010/05/21 12:38:52 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\Pogo Games
[2011/01/29 23:27:13 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\RegistryKeys
[2010/11/23 21:44:58 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\Sierra Wireless
[2010/11/23 21:55:14 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\Sprint
[2011/01/17 12:59:51 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\SystemRequirementsLab
[2010/05/03 19:52:29 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\WeatherBug
[2010/08/07 20:35:26 | 000,000,000 | —D | M] – C:\Users\Amy\AppData\Roaming\WinPatrol
[2010/06/23 23:24:42 | 000,032,614 | —- | M] () – C:\Windows\Tasks\SCHEDLGU(58).TXT
[2011/12/12 06:34:59 | 000,032,616 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/02/10 06:00:11 | 000,229,148 | —- | M] () – C:\aaw7boot.log
[2009/06/10 16:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/02/11 14:09:42 | 000,000,211 | -H– | M] () – C:\Boot.BAK
[2010/05/03 16:58:46 | 000,000,355 | RHS- | M] () – C:\Boot.ini.saved
[2010/11/20 07:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2010/05/03 16:58:47 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/02/01 18:41:06 | 000,011,187 | —- | M] () – C:\ComboFix.txt
[2009/06/10 16:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2010/08/06 15:57:53 | 000,000,006 | —- | M] () – C:\dialogInfo.res
[2011/05/18 22:57:10 | 007,643,508 | —- | M] () – C:\drivers.log
[2010/05/03 13:16:42 | 000,203,836 | RHS- | M] () – C:\grldr
[2012/01/16 23:22:15 | 1608,880,128 | -HS- | M] () – C:\hiberfil.sys
[2009/06/18 20:41:32 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/11/05 20:51:36 | 000,000,808 | -H– | M] () – C:\IPH.PH
[2010/05/01 09:13:14 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2009/06/18 20:41:32 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2009/06/18 20:36:23 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/06/18 20:36:23 | 000,250,032 | RHS- | M] () – C:\ntldr
[2012/01/16 23:22:36 | 2145,177,600 | -HS- | M] () – C:\pagefile.sys
[2009/06/18 20:54:22 | 000,000,575 | —- | M] () – C:\RHDSetup.log
[2009/06/19 02:06:53 | 000,000,005 | —- | M] () – C:\testfile.txt
[2010/05/03 13:16:43 | 000,000,000 | RHS- | M] () – C:\winx.ld

< %systemroot%\Fonts\*.com >
[2009/07/13 23:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 23:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 23:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 23:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/11/20 07:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >
[2010/09/20 10:45:44 | 000,016,591 | —- | M] () – C:\Windows\system32\bg_bottom.jpg
[2011/04/11 15:37:04 | 000,023,992 | —- | M] () – C:\Windows\system32\bg_top.jpg
[2010/11/08 10:29:06 | 000,040,726 | —- | M] () – C:\Windows\system32\image_animation.jpg

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/11/28 13:01:25 | 000,041,184 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2010/11/23 19:48:34 | 000,001,654 | -HS- | M] () – C:\Users\Amy\AppData\Roaming\Microsoft\LastFlashConfig.wfc

< %PROGRAMFILES%\*.* >
[2009/07/13 23:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2011/04/26 11:45:20 | 000,058,368 | —- | M] () – C:\Windows\system32\Thumbs.db

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/20 05:57:02 | 000,000,221 | -HS- | M] () – C:\Users\Amy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/11/25 17:49:02 | 000,229,672 | —- | M] () – C:\Users\Amy\Desktop\CrucialScan(1).exe
[2011/08/07 09:39:24 | 000,589,656 | —- | M] (Google Inc.) – C:\Users\Amy\Desktop\GoogleEarthPluginSetup.exe
[2012/01/17 00:11:08 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Amy\Desktop\OTL.exe
[2011/12/22 21:47:43 | 000,204,496 | —- | M] (Malwarebytes) – C:\Users\Amy\Desktop\StartUpLite.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-11-24 12:34:17

========== Alternate Data Streams ==========

@Alternate Data Stream - 165 bytes -> C:\ProgramData\TEMP:D09AEE3D
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:72F57408

< End of report >

OTL Extras logfile created on: 1/17/2012 12:15:17 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Amy\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.17 Gb Available Physical Memory | 58.57% Memory free
4.00 Gb Paging File | 3.15 Gb Available in Paging File | 78.90% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 23.33 Gb Free Space | 31.31% Space Free | Partition Type: NTFS

Computer Name: AMY-PC | User Name: Amy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
"PolicyVersion" = 522

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\PublicProfile]
"DefaultOutboundAction" = 0
"DefaultInboundAction" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Sprint\Sprint SmartView\SwiApiMux.exe" = C:\Program Files\Sprint\Sprint SmartView\SwiApiMux.exe:*:Enabled:SwiApiMux – (Sierra Wireless, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18DB3375-0649-4EA3-959A-44F1ACD278BA}" = IncrediMail
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 29
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{4647BF57-21C4-4BC8-BA1B-E57A30EE1D31}" = Sprint SmartView
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{70DECFBF-9119-4434-B2D3-A3C283D15E45}" = WeatherBug
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{788A0222-5690-4212-AA9C-C48FD0E1C9AE}" = Photo Notifier and Animation Creator
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112930333}" = Lottso! Deluxe
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{942E5031-2BD6-4C1B-918C-C8A1CBAE7B8C}" = Microsoft IntelliPoint 8.2
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9E384B32-59C8-46EF-BEA6-4DC8F27CDB8E}" = InstallVC90Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.3.5
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4B1B985-F308-4DBA-BFD7-CCCB8839234B}" = HP Deskjet 1000 J110 series Basic Device Software
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AI RoboForm" = AI RoboForm (All Users)
"AIM_7" = AIM 7
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner
"Defraggler" = Defraggler
"DirectXMediaRuntime" = DirectX Media Runtime 5.1
"ESET Online Scanner" = ESET Online Scanner v3
"IncrediMail" = IncrediMail 2.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Merriam-Webster's Reference Library" = Merriam-Webster's Reference Library
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft IntelliPoint 8.2" = Microsoft IntelliPoint 8.2
"Mozilla Firefox 8.0 (x86 en-US)" = Mozilla Firefox 8.0 (x86 en-US)
"Photo Notifier and Animation Creator" = Photo Notifier and Animation Creator
"SystemRequirementsLab" = System Requirements Lab
"The Weather Channel Toolbar" = The Weather Channel Toolbar
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"727d1ea1876aa06e" = WowAceUpdater
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/15/2012 10:53:32 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 7042
Description =

Error - 1/15/2012 10:53:33 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 9002
Description =

Error - 1/15/2012 10:53:33 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 3029
Description =

Error - 1/15/2012 10:53:38 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 3029
Description =

Error - 1/15/2012 10:53:38 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 3028
Description =

Error - 1/15/2012 10:53:39 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 3058
Description =

Error - 1/15/2012 10:53:42 AM | Computer Name = Amy-PC | Source = Windows Search Service | ID = 7010
Description =

Error - 1/15/2012 8:51:18 PM | Computer Name = Amy-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 81c Start
Time: 01ccd3e861bf3210 Termination Time: 47 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id:

Error - 1/16/2012 11:46:09 AM | Computer Name = Amy-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\Sprint\Sprint
SmartView\OemDriverManager64.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 1/16/2012 11:48:53 AM | Computer Name = Amy-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program files\spybot
- search & destroy\DelZip179.dll" on line 8. The value "*" of attribute "language"
in element "assemblyIdentity" is invalid.

[ Media Center Events ]
Error - 5/21/2011 5:53:21 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 5:53:20 AM - Error connecting to the internet. 5:53:20 AM - Unable
to contact server..

Error - 5/21/2011 5:54:01 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 5:53:30 AM - Error connecting to the internet. 5:53:30 AM - Unable
to contact server..

Error - 5/23/2011 10:18:37 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 10:18:36 AM - Error connecting to the internet. 10:18:37 AM - Unable
to contact server..

Error - 5/23/2011 10:18:47 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 10:18:42 AM - Error connecting to the internet. 10:18:42 AM - Unable
to contact server..

Error - 5/31/2011 10:37:43 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 10:37:43 AM - Error connecting to the internet. 10:37:43 AM - Unable
to contact server..

Error - 5/31/2011 10:37:54 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 10:37:48 AM - Error connecting to the internet. 10:37:48 AM - Unable
to contact server..

Error - 6/3/2011 10:38:23 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 10:38:23 AM - Error connecting to the internet. 10:38:23 AM - Unable
to contact server..

Error - 6/3/2011 10:38:41 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 10:38:28 AM - Error connecting to the internet. 10:38:28 AM - Unable
to contact server..

Error - 7/16/2011 7:46:22 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 7:46:17 AM - Error connecting to the internet. 7:46:17 AM - Unable
to contact server..

Error - 8/5/2011 9:59:49 AM | Computer Name = Amy-PC | Source = MCUpdate | ID = 0
Description = 9:59:48 AM - Error connecting to the internet. 9:59:48 AM - Unable
to contact server..

[ System Events ]
Error - 1/16/2012 11:10:36 PM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Search service to connect.

Error - 1/16/2012 11:10:39 PM | Computer Name = Amy-PC | Source = DCOM | ID = 10005
Description =

Error - 1/16/2012 11:10:39 PM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7000
Description = The Windows Search service failed to start due to the following error:
%%1053

Error - 1/16/2012 11:58:48 PM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7001
Description = The Task Scheduler service depends on the Windows Event Log service
which failed to start because of the following error: %%1058

Error - 1/16/2012 11:59:07 PM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 1/17/2012 12:09:56 AM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7001
Description = The Task Scheduler service depends on the Windows Event Log service
which failed to start because of the following error: %%1058

Error - 1/17/2012 12:09:58 AM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 1/17/2012 12:14:31 AM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7001
Description = The Task Scheduler service depends on the Windows Event Log service
which failed to start because of the following error: %%1058

Error - 1/17/2012 12:14:34 AM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 1/17/2012 12:26:13 AM | Computer Name = Amy-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd


< End of report >
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!




Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
17:43:18.0890 1376 TDSS rootkit removing tool [removed] Jan 19 2012 13:09:04 17:43:20.0109 1376 ============================================================ 17:43:20.0109 1376 Current date / time: 2012/01/19 17:43:20.0109 17:43:20.0109 1376 SystemInfo: 17:43:20.0109 1376 17:43:20.0109 1376 OS Version: 6.1.7601 ServicePack: 1.0 17:43:20.0109 1376 Product type: Workstation 17:43:20.0109 1376 ComputerName: AMY-PC 17:43:20.0109 1376 UserName: Amy 17:43:20.0109 1376 Windows directory: C:\Windows 17:43:20.0109 1376 System windows directory: C:\Windows 17:43:20.0109 1376 Processor architecture: Intel x86 17:43:20.0109 1376 Number of processors: 2 17:43:20.0109 1376 Page size: 0x1000 17:43:20.0109 1376 Boot type: Normal boot 17:43:20.0109 1376 ============================================================ 17:43:24.0765 1376 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 17:43:24.0976 1376 Initialize success 17:43:32.0164 2824 ============================================================ 17:43:32.0164 2824 Scan started 17:43:32.0164 2824 Mode: Manual; 17:43:32.0164 2824 ============================================================ 17:43:34.0257 2824 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys 17:43:34.0375 2824 1394ohci - ok 17:43:35.0171 2824 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys 17:43:35.0367 2824 ACPI - ok 17:43:36.0101 2824 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys 17:43:36.0109 2824 AcpiPmi - ok 17:43:37.0351 2824 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys 17:43:37.0671 2824 adp94xx - ok 17:43:38.0570 2824 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys 17:43:38.0796 2824 adpahci - ok 17:43:39.0500 2824 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys 17:43:39.0617 2824 adpu320 - ok 17:43:40.0648 2824 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys 17:43:40.0898 2824 AFD - ok 17:43:41.0570 2824 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys 17:43:41.0609 2824 agp440 - ok 17:43:42.0304 2824 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys 17:43:42.0359 2824 aic78xx - ok 17:43:43.0039 2824 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys 17:43:43.0062 2824 aliide - ok 17:43:43.0710 2824 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys 17:43:43.0781 2824 amdagp - ok 17:43:44.0421 2824 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys 17:43:44.0437 2824 amdide - ok 17:43:45.0117 2824 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys 17:43:45.0156 2824 AmdK8 - ok 17:43:45.0820 2824 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys 17:43:45.0867 2824 AmdPPM - ok 17:43:46.0539 2824 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys 17:43:46.0593 2824 amdsata - ok 17:43:47.0296 2824 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys 17:43:47.0406 2824 amdsbs - ok 17:43:48.0000 2824 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys 17:43:48.0023 2824 amdxata - ok 17:43:48.0664 2824 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys 17:43:48.0695 2824 AppID - ok 17:43:49.0539 2824 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys 17:43:49.0593 2824 arc - ok 17:43:50.0164 2824 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys 17:43:50.0226 2824 arcsas - ok 17:43:50.0796 2824 aswFsBlk (054df24c92b55427e0757cfff160e4f2) C:\Windows\system32\drivers\aswFsBlk.sys 17:43:50.0812 2824 aswFsBlk - ok 17:43:51.0375 2824 aswMonFlt (258143605e77e4008f1758481d6a977d) C:\Windows\system32\drivers\aswMonFlt.sys 17:43:51.0421 2824 aswMonFlt - ok 17:43:52.0031 2824 aswRdr (352d5a48ebab35a7693b048679304831) C:\Windows\system32\drivers\aswRdr.sys 17:43:52.0054 2824 aswRdr - ok 17:43:52.0921 2824 aswSnx (8d34d2b24297e27d93e847319abfdec4) C:\Windows\system32\drivers\aswSnx.sys 17:43:53.0187 2824 aswSnx - ok 17:43:53.0945 2824 aswSP (010012597333da1f46c3243f33f8409e) C:\Windows\system32\drivers\aswSP.sys 17:43:54.0148 2824 aswSP - ok 17:43:54.0710 2824 aswTdi (f9f84364416658e9786235904d448d37) C:\Windows\system32\drivers\aswTdi.sys 17:43:54.0773 2824 aswTdi - ok 17:43:55.0335 2824 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys 17:43:55.0351 2824 AsyncMac - ok 17:43:55.0945 2824 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys 17:43:55.0945 2824 atapi - ok 17:43:56.0921 2824 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys 17:43:57.0187 2824 b06bdrv - ok 17:43:57.0937 2824 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys 17:43:58.0078 2824 b57nd60x - ok 17:43:58.0726 2824 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys 17:43:58.0734 2824 Beep - ok 17:43:59.0351 2824 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys 17:43:59.0382 2824 blbdrive - ok 17:44:00.0046 2824 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys 17:44:00.0093 2824 bowser - ok 17:44:00.0679 2824 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys 17:44:00.0703 2824 BrFiltLo - ok 17:44:01.0250 2824 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys 17:44:01.0250 2824 BrFiltUp - ok 17:44:02.0054 2824 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys 17:44:02.0234 2824 Brserid - ok 17:44:02.0859 2824 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys 17:44:02.0906 2824 BrSerWdm - ok 17:44:03.0531 2824 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys 17:44:03.0546 2824 BrUsbMdm - ok 17:44:04.0187 2824 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys 17:44:04.0203 2824 BrUsbSer - ok 17:44:04.0898 2824 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys 17:44:04.0937 2824 BTHMODEM - ok 17:44:05.0148 2824 catchme - ok 17:44:05.0742 2824 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys 17:44:05.0789 2824 cdfs - ok 17:44:06.0500 2824 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys 17:44:06.0578 2824 cdrom - ok 17:44:07.0226 2824 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys 17:44:07.0250 2824 circlass - ok 17:44:08.0000 2824 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys 17:44:08.0132 2824 CLFS - ok 17:44:08.0929 2824 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys 17:44:08.0945 2824 CmBatt - ok 17:44:09.0539 2824 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys 17:44:09.0554 2824 cmdide - ok 17:44:10.0335 2824 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys 17:44:10.0593 2824 CNG - ok 17:44:11.0140 2824 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys 17:44:11.0164 2824 Compbatt - ok 17:44:11.0742 2824 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys 17:44:11.0765 2824 CompositeBus - ok 17:44:12.0390 2824 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys 17:44:12.0414 2824 crcdisk - ok 17:44:13.0343 2824 CSC (3c2177a897b4ca2788c6fb0c3fd81d4b) C:\Windows\system32\drivers\csc.sys 17:44:13.0617 2824 CSC - ok 17:44:14.0203 2824 dc3d (7caaf4af453ef3582fef65dd72caa0aa) C:\Windows\system32\DRIVERS\dc3d.sys 17:44:14.0226 2824 dc3d - ok 17:44:14.0937 2824 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys 17:44:14.0984 2824 DfsC - ok 17:44:15.0593 2824 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys 17:44:15.0617 2824 discache - ok 17:44:16.0226 2824 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys 17:44:16.0257 2824 Disk - ok 17:44:16.0867 2824 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys 17:44:16.0875 2824 drmkaud - ok 17:44:17.0968 2824 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys 17:44:18.0437 2824 DXGKrnl - ok 17:44:21.0109 2824 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys 17:44:23.0179 2824 ebdrv - ok 17:44:24.0257 2824 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys 17:44:24.0617 2824 elxstor - ok 17:44:25.0257 2824 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys 17:44:25.0281 2824 ErrDev - ok 17:44:26.0078 2824 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys 17:44:26.0195 2824 exfat - ok 17:44:26.0929 2824 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys 17:44:27.0031 2824 fastfat - ok 17:44:27.0671 2824 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys 17:44:27.0687 2824 fdc - ok 17:44:28.0328 2824 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys 17:44:28.0375 2824 FileInfo - ok 17:44:29.0000 2824 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys 17:44:29.0023 2824 Filetrace - ok 17:44:29.0617 2824 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys 17:44:29.0640 2824 flpydisk - ok 17:44:30.0351 2824 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys 17:44:30.0500 2824 FltMgr - ok 17:44:31.0132 2824 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys 17:44:31.0164 2824 FsDepends - ok 17:44:31.0757 2824 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys 17:44:31.0773 2824 Fs_Rec - ok 17:44:32.0515 2824 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys 17:44:32.0648 2824 fvevol - ok 17:44:33.0265 2824 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys 17:44:33.0304 2824 gagp30kx - ok 17:44:34.0023 2824 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys 17:44:34.0046 2824 hcw85cir - ok 17:44:34.0820 2824 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys 17:44:35.0015 2824 HdAudAddService - ok 17:44:35.0734 2824 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys 17:44:35.0804 2824 HDAudBus - ok 17:44:36.0398 2824 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys 17:44:36.0414 2824 HidBatt - ok 17:44:37.0054 2824 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys 17:44:37.0117 2824 HidBth - ok 17:44:37.0703 2824 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys 17:44:37.0726 2824 HidIr - ok 17:44:38.0445 2824 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys 17:44:38.0468 2824 HidUsb - ok 17:44:39.0125 2824 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys 17:44:39.0171 2824 HpSAMD - ok 17:44:40.0093 2824 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys 17:44:40.0437 2824 HTTP - ok 17:44:41.0000 2824 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys 17:44:41.0015 2824 hwpolicy - ok 17:44:41.0687 2824 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys 17:44:41.0742 2824 i8042prt - ok 17:44:42.0546 2824 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys 17:44:42.0773 2824 iaStorV - ok 17:44:43.0406 2824 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys 17:44:43.0437 2824 iirsp - ok 17:44:44.0109 2824 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys 17:44:44.0132 2824 intelide - ok 17:44:44.0812 2824 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys 17:44:44.0859 2824 intelppm - ok 17:44:45.0531 2824 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys 17:44:45.0578 2824 IpFilterDriver - ok 17:44:46.0234 2824 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys 17:44:46.0281 2824 IPMIDRV - ok 17:44:46.0914 2824 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys 17:44:46.0984 2824 IPNAT - ok 17:44:47.0578 2824 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys 17:44:47.0601 2824 IRENUM - ok 17:44:48.0187 2824 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys 17:44:48.0218 2824 isapnp - ok 17:44:48.0960 2824 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys 17:44:49.0109 2824 iScsiPrt - ok 17:44:50.0226 2824 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys 17:44:50.0257 2824 kbdclass - ok 17:44:50.0859 2824 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys 17:44:50.0875 2824 kbdhid - ok 17:44:51.0539 2824 KSecDD (412cea1aa78cc02a447f5c9e62b32ff1) C:\Windows\system32\Drivers\ksecdd.sys 17:44:51.0601 2824 KSecDD - ok 17:44:52.0242 2824 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys 17:44:52.0335 2824 KSecPkg - ok 17:44:52.0476 2824 Lavasoft Kernexplorer - ok 17:44:53.0015 2824 Lbd - ok 17:44:54.0203 2824 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys 17:44:54.0234 2824 lltdio - ok 17:44:55.0515 2824 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys 17:44:55.0578 2824 LSI_FC - ok 17:44:56.0187 2824 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys 17:44:56.0250 2824 LSI_SAS - ok 17:44:56.0953 2824 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys 17:44:56.0992 2824 LSI_SAS2 - ok 17:44:57.0664 2824 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys 17:44:57.0750 2824 LSI_SCSI - ok 17:44:58.0429 2824 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys 17:44:58.0500 2824 luafv - ok 17:44:59.0109 2824 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys 17:44:59.0132 2824 megasas - ok 17:44:59.0882 2824 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys 17:45:00.0031 2824 MegaSR - ok 17:45:00.0640 2824 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys 17:45:00.0656 2824 Modem - ok 17:45:01.0226 2824 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys 17:45:01.0242 2824 monitor - ok 17:45:01.0859 2824 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys 17:45:01.0898 2824 mouclass - ok 17:45:02.0695 2824 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys 17:45:02.0718 2824 mouhid - ok 17:45:03.0390 2824 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys 17:45:03.0453 2824 mountmgr - ok 17:45:04.0179 2824 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys 17:45:04.0281 2824 mpio - ok 17:45:05.0031 2824 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys 17:45:05.0085 2824 mpsdrv - ok 17:45:05.0851 2824 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys 17:45:05.0960 2824 MRxDAV - ok 17:45:06.0695 2824 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys 17:45:06.0789 2824 mrxsmb - ok 17:45:07.0562 2824 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys 17:45:07.0718 2824 mrxsmb10 - ok 17:45:08.0343 2824 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys 17:45:08.0421 2824 mrxsmb20 - ok 17:45:09.0093 2824 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys 17:45:09.0117 2824 msahci - ok 17:45:09.0812 2824 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys 17:45:09.0890 2824 msdsm - ok 17:45:10.0531 2824 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys 17:45:10.0546 2824 Msfs - ok 17:45:11.0125 2824 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys 17:45:11.0132 2824 mshidkmdf - ok 17:45:11.0710 2824 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys 17:45:11.0718 2824 msisadrv - ok 17:45:12.0320 2824 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys 17:45:12.0335 2824 MSKSSRV - ok 17:45:12.0945 2824 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys 17:45:12.0960 2824 MSPCLOCK - ok 17:45:13.0523 2824 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys 17:45:13.0539 2824 MSPQM - ok 17:45:14.0226 2824 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys 17:45:14.0343 2824 MsRPC - ok 17:45:14.0976 2824 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys 17:45:15.0000 2824 mssmbios - ok 17:45:15.0601 2824 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys 17:45:15.0617 2824 MSTEE - ok 17:45:16.0250 2824 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys 17:45:16.0265 2824 MTConfig - ok 17:45:16.0937 2824 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys 17:45:16.0984 2824 Mup - ok 17:45:17.0812 2824 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys 17:45:17.0992 2824 NativeWifiP - ok 17:45:19.0093 2824 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys 17:45:19.0570 2824 NDIS - ok 17:45:20.0164 2824 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys 17:45:20.0179 2824 NdisCap - ok 17:45:20.0804 2824 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys 17:45:20.0828 2824 NdisTapi - ok 17:45:21.0421 2824 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys 17:45:21.0468 2824 Ndisuio - ok 17:45:22.0140 2824 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys 17:45:22.0226 2824 NdisWan - ok 17:45:22.0875 2824 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys 17:45:22.0906 2824 NDProxy - ok 17:45:23.0562 2824 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys 17:45:23.0585 2824 NetBIOS - ok 17:45:24.0351 2824 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys 17:45:24.0507 2824 NetBT - ok 17:45:25.0210 2824 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys 17:45:25.0250 2824 nfrd960 - ok 17:45:25.0960 2824 Nmea (b0d5188e282dc4edae7020f333427bc8) C:\Windows\system32\DRIVERS\pctnullport.sys 17:45:26.0000 2824 Nmea - ok 17:45:26.0640 2824 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys 17:45:26.0664 2824 Npfs - ok 17:45:27.0273 2824 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys 17:45:27.0296 2824 nsiproxy - ok 17:45:28.0781 2824 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys 17:45:29.0593 2824 Ntfs - ok 17:45:30.0171 2824 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys 17:45:30.0171 2824 Null - ok 17:45:38.0515 2824 nvlddmkm (847b1755f7757f825305a1ffe6dac3e9) C:\Windows\system32\DRIVERS\nvlddmkm.sys 17:45:45.0648 2824 nvlddmkm - ok 17:45:46.0484 2824 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys 17:45:46.0593 2824 nvraid - ok 17:45:47.0296 2824 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys 17:45:47.0398 2824 nvstor - ok 17:45:48.0195 2824 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys 17:45:48.0273 2824 nv_agp - ok 17:45:49.0070 2824 NWADI (93213c7ec08e01e37a935bf144e75df6) C:\Windows\system32\DRIVERS\NWADIenum.sys 17:45:49.0234 2824 NWADI - ok 17:45:49.0882 2824 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys 17:45:49.0929 2824 ohci1394 - ok 17:45:50.0671 2824 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys 17:45:50.0726 2824 Parport - ok 17:45:51.0343 2824 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys 17:45:51.0398 2824 partmgr - ok 17:45:51.0984 2824 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys 17:45:52.0000 2824 Parvdm - ok 17:45:52.0773 2824 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys 17:45:52.0890 2824 pci - ok 17:45:53.0546 2824 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys 17:45:53.0562 2824 pciide - ok 17:45:54.0273 2824 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys 17:45:54.0406 2824 pcmcia - ok 17:45:55.0015 2824 PCTINDIS5 (1e715247efffdda938c085913045d599) C:\Windows\system32\PCTINDIS5.SYS 17:45:55.0054 2824 PCTINDIS5 - ok 17:45:55.0656 2824 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys 17:45:55.0687 2824 pcw - ok 17:45:56.0679 2824 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys 17:45:57.0062 2824 PEAUTH - ok 17:45:57.0835 2824 Point32 (896d916de06f5502d301e8c4dc442ae8) C:\Windows\system32\DRIVERS\point32.sys 17:45:57.0867 2824 Point32 - ok 17:45:58.0570 2824 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys 17:45:58.0625 2824 PptpMiniport - ok 17:45:59.0242 2824 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys 17:45:59.0281 2824 Processor - ok 17:45:59.0992 2824 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys 17:46:00.0070 2824 Psched - ok 17:46:01.0656 2824 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys 17:46:02.0632 2824 ql2300 - ok 17:46:03.0320 2824 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys 17:46:03.0429 2824 ql40xx - ok 17:46:04.0117 2824 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys 17:46:04.0140 2824 QWAVEdrv - ok 17:46:04.0812 2824 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys 17:46:04.0828 2824 RasAcd - ok 17:46:05.0492 2824 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys 17:46:05.0531 2824 RasAgileVpn - ok 17:46:06.0242 2824 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys 17:46:06.0312 2824 Rasl2tp - ok 17:46:07.0046 2824 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys 17:46:07.0109 2824 RasPppoe - ok 17:46:07.0835 2824 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys 17:46:07.0890 2824 RasSstp - ok 17:46:08.0679 2824 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys 17:46:08.0843 2824 rdbss - ok 17:46:09.0445 2824 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys 17:46:09.0468 2824 rdpbus - ok 17:46:10.0046 2824 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys 17:46:10.0062 2824 RDPCDD - ok 17:46:10.0773 2824 RDPDR (b973fcfc50dc1434e1970a146f7e3885) C:\Windows\system32\drivers\rdpdr.sys 17:46:10.0859 2824 RDPDR - ok 17:46:11.0507 2824 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys 17:46:11.0515 2824 RDPENCDD - ok 17:46:12.0093 2824 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys 17:46:12.0109 2824 RDPREFMP - ok 17:46:12.0859 2824 RdpVideoMiniport (68a0387f58e226deee23d9715955572a) C:\Windows\system32\drivers\rdpvideominiport.sys 17:46:12.0875 2824 RdpVideoMiniport - ok 17:46:13.0593 2824 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys 17:46:13.0710 2824 RDPWD - ok 17:46:14.0414 2824 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys 17:46:14.0546 2824 rdyboost - ok 17:46:15.0250 2824 RMCAST (906dcfc5ebf4ec0433f8d4fffb0ba334) C:\Windows\system32\DRIVERS\RMCAST.sys 17:46:15.0328 2824 RMCAST - ok 17:46:16.0015 2824 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys 17:46:16.0062 2824 rspndr - ok 17:46:16.0695 2824 RTL8023xp (223d721e1334425df479b58123c9e886) C:\Windows\system32\DRIVERS\EG1032xp.sys 17:46:16.0750 2824 RTL8023xp - ok 17:46:17.0312 2824 s3cap (7fa7f2e249a5dcbb7970630e15e1f482) C:\Windows\system32\drivers\vms3cap.sys 17:46:17.0328 2824 s3cap - ok 17:46:17.0515 2824 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 17:46:17.0531 2824 SASDIFSV - ok 17:46:17.0671 2824 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 17:46:17.0718 2824 SASKUTIL - ok 17:46:18.0343 2824 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys 17:46:18.0406 2824 sbp2port - ok 17:46:19.0070 2824 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys 17:46:19.0093 2824 scfilter - ok 17:46:19.0757 2824 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 17:46:19.0781 2824 secdrv - ok 17:46:20.0437 2824 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys 17:46:20.0460 2824 Serenum - ok 17:46:21.0117 2824 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys 17:46:21.0179 2824 Serial - ok 17:46:21.0789 2824 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys 17:46:21.0804 2824 sermouse - ok 17:46:22.0476 2824 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys 17:46:22.0492 2824 sffdisk - ok 17:46:23.0132 2824 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys 17:46:23.0140 2824 sffp_mmc - ok 17:46:23.0765 2824 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys 17:46:23.0781 2824 sffp_sd - ok 17:46:24.0398 2824 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys 17:46:24.0429 2824 sfloppy - ok 17:46:25.0164 2824 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys 17:46:25.0210 2824 sisagp - ok 17:46:25.0843 2824 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys 17:46:25.0875 2824 SiSRaid2 - ok 17:46:26.0562 2824 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys 17:46:26.0632 2824 SiSRaid4 - ok 17:46:27.0296 2824 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys 17:46:27.0359 2824 Smb - ok 17:46:28.0085 2824 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys 17:46:28.0101 2824 spldr - ok 17:46:28.0992 2824 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys 17:46:29.0210 2824 srv - ok 17:46:30.0132 2824 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys 17:46:30.0382 2824 srv2 - ok 17:46:32.0468 2824 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys 17:46:32.0570 2824 srvnet - ok 17:46:33.0523 2824 sscdbus (d5dffeaa1e15d4effabb9d9a3068ac5b) C:\Windows\system32\DRIVERS\sscdbus.sys 17:46:33.0679 2824 sscdbus - ok 17:46:35.0210 2824 sscdmdfl (8a1be0c347814f482f493aea619d57f6) C:\Windows\system32\DRIVERS\sscdmdfl.sys 17:46:35.0226 2824 sscdmdfl - ok 17:46:36.0062 2824 sscdmdm (5ab0b1987f682a59b15b78f84c6ad7d0) C:\Windows\system32\DRIVERS\sscdmdm.sys 17:46:36.0132 2824 sscdmdm - ok 17:46:36.0789 2824 sscdserd (751e66eb32efa80633b80f5d7ff0a1d8) C:\Windows\system32\DRIVERS\sscdserd.sys 17:46:36.0843 2824 sscdserd - ok 17:46:37.0546 2824 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys 17:46:37.0554 2824 stexstor - ok 17:46:38.0187 2824 storflt (472af0311073dceceaa8fa18ba2bdf89) C:\Windows\system32\drivers\vmstorfl.sys 17:46:38.0218 2824 storflt - ok 17:46:38.0835 2824 storvsc (dcaffd62259e0bdb433dd67b5bb37619) C:\Windows\system32\drivers\storvsc.sys 17:46:38.0867 2824 storvsc - ok 17:46:39.0476 2824 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys 17:46:39.0500 2824 swenum - ok 17:46:40.0171 2824 swmsflt (3d4776ab6520240ae06d277ac45bf836) C:\Windows\system32\DRIVERS\swmsflt.sys 17:46:40.0210 2824 swmsflt - ok 17:46:40.0929 2824 swmx00 (af88ae62b84d016eb5bdc12ddf1005a3) C:\Windows\system32\DRIVERS\swmx00.sys 17:46:41.0031 2824 swmx00 - ok 17:46:41.0804 2824 SWNC5E00 (68fa9dea71b307210045aea89310ef7f) C:\Windows\system32\DRIVERS\SWNC5E00.sys 17:46:41.0953 2824 SWNC5E00 - ok 17:46:42.0531 2824 Synth3dVsc - ok 17:46:44.0148 2824 Tcpip (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\drivers\tcpip.sys 17:46:45.0085 2824 Tcpip - ok 17:46:46.0718 2824 TCPIP6 (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\DRIVERS\tcpip.sys 17:46:46.0750 2824 TCPIP6 - ok 17:46:47.0445 2824 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys 17:46:47.0492 2824 tcpipreg - ok 17:46:48.0140 2824 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys 17:46:48.0164 2824 TDPIPE - ok 17:46:48.0820 2824 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys 17:46:48.0835 2824 TDTCP - ok 17:46:49.0492 2824 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys 17:46:49.0554 2824 tdx - ok 17:46:50.0179 2824 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys 17:46:50.0218 2824 TermDD - ok 17:46:50.0960 2824 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys 17:46:50.0984 2824 tssecsrv - ok 17:46:51.0593 2824 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys 17:46:51.0632 2824 TsUsbFlt - ok 17:46:52.0187 2824 tsusbhub - ok 17:46:52.0875 2824 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys 17:46:52.0945 2824 tunnel - ok 17:46:53.0625 2824 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys 17:46:53.0664 2824 uagp35 - ok 17:46:54.0437 2824 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys 17:46:54.0609 2824 udfs - ok 17:46:55.0304 2824 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys 17:46:55.0343 2824 uliagpkx - ok 17:46:56.0015 2824 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys 17:46:56.0046 2824 umbus - ok 17:46:56.0617 2824 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys 17:46:56.0632 2824 UmPass - ok 17:46:57.0289 2824 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\DRIVERS\usbccgp.sys 17:46:57.0351 2824 usbccgp - ok 17:46:58.0039 2824 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys 17:46:58.0109 2824 usbcir - ok 17:46:58.0757 2824 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\DRIVERS\usbehci.sys 17:46:58.0796 2824 usbehci - ok 17:46:59.0570 2824 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys 17:46:59.0742 2824 usbhub - ok 17:47:00.0312 2824 usbohci (e185d44fac515a18d9deddc23c2cdf44) C:\Windows\system32\drivers\usbohci.sys 17:47:00.0335 2824 usbohci - ok 17:47:00.0968 2824 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys 17:47:00.0992 2824 usbprint - ok 17:47:01.0593 2824 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys 17:47:01.0625 2824 usbscan - ok 17:47:02.0226 2824 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS 17:47:02.0281 2824 USBSTOR - ok 17:47:02.0890 2824 usbuhci (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\DRIVERS\usbuhci.sys 17:47:02.0914 2824 usbuhci - ok 17:47:03.0593 2824 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys 17:47:03.0625 2824 vdrvroot - ok 17:47:04.0320 2824 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys 17:47:04.0343 2824 vga - ok 17:47:04.0960 2824 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys 17:47:04.0984 2824 VgaSave - ok 17:47:05.0632 2824 VGPU - ok 17:47:06.0429 2824 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys 17:47:06.0562 2824 vhdmp - ok 17:47:07.0265 2824 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys 17:47:07.0304 2824 viaagp - ok 17:47:07.0968 2824 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys 17:47:08.0007 2824 ViaC7 - ok 17:47:08.0671 2824 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys 17:47:08.0687 2824 viaide - ok 17:47:09.0414 2824 vmbus (c2f2911156fdc7817c52829c86da494e) C:\Windows\system32\drivers\vmbus.sys 17:47:09.0554 2824 vmbus - ok 17:47:10.0148 2824 VMBusHID (d4d77455211e204f370d08f4963063ce) C:\Windows\system32\drivers\VMBusHID.sys 17:47:10.0164 2824 VMBusHID - ok 17:47:10.0796 2824 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys 17:47:10.0851 2824 volmgr - ok 17:47:11.0625 2824 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys 17:47:11.0820 2824 volmgrx - ok 17:47:12.0601 2824 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys 17:47:12.0773 2824 volsnap - ok 17:47:13.0484 2824 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys 17:47:13.0585 2824 vsmraid - ok 17:47:14.0187 2824 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys 17:47:14.0203 2824 vwifibus - ok 17:47:14.0882 2824 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys 17:47:14.0921 2824 vwififlt - ok 17:47:15.0539 2824 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys 17:47:15.0562 2824 WacomPen - ok 17:47:16.0210 2824 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys 17:47:16.0273 2824 WANARP - ok 17:47:16.0382 2824 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys 17:47:16.0390 2824 Wanarpv6 - ok 17:47:17.0187 2824 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys 17:47:17.0203 2824 Wd - ok 17:47:17.0789 2824 WDC_SAM (d6efaf429fd30c5df613d220e344cce7) C:\Windows\system32\DRIVERS\wdcsam.sys 17:47:17.0804 2824 WDC_SAM - ok 17:47:18.0703 2824 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 17:47:19.0023 2824 Wdf01000 - ok 17:47:19.0796 2824 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys 17:47:19.0804 2824 WfpLwf - ok 17:47:20.0367 2824 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys 17:47:20.0382 2824 WIMMount - ok 17:47:21.0140 2824 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys 17:47:21.0148 2824 WmiAcpi - ok 17:47:21.0820 2824 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys 17:47:21.0835 2824 ws2ifsl - ok 17:47:22.0578 2824 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys 17:47:22.0632 2824 WudfPf - ok 17:47:23.0312 2824 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys 17:47:23.0421 2824 WUDFRd - ok 17:47:24.0375 2824 yukonw7 (30b73eb97218a16cbc6de535782a1b35) C:\Windows\system32\DRIVERS\yk62x86.sys 17:47:24.0617 2824 yukonw7 - ok 17:47:25.0000 2824 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 17:47:25.0031 2824 \Device\Harddisk0\DR0 - ok 17:47:25.0039 2824 Boot (0x1200) (a887eceed9923fbaea5597262b35a47f) \Device\Harddisk0\DR0\Partition0 17:47:25.0046 2824 \Device\Harddisk0\DR0\Partition0 - ok 17:47:25.0046 2824 ============================================================ 17:47:25.0046 2824 Scan finished 17:47:25.0046 2824 ============================================================ 17:47:25.0101 2392 Detected object count: 0 17:47:25.0101 2392 Actual detected object count: 0
Fantastic! That scan looks clean. So far things look good. First, let me tell you that different scans look in different places. We use different tools to ensure that we get a good look at the machine to ensure that we don't miss anything. So please be patient while we do a few more scans. There is also the possibility that the slowness isn't the result of malware, but we'll consider that possibility later.

I see you have Malwarebytes already on your machine. Please run it by right-clicking and choosing Run as Administrator on the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.




This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.

Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked, and the option Scan unwanted applications is checked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.
I clicked to run MWB and got the following error message… "Runtime error '5': Invalid procedure call or argument" and all I can do is close the error box. (I got this error when right clicking to run as admin and then I tried to just open it regularly and got the same message).
  • Download and run mbam-clean.exe from here
  • It will ask to restart your computer, please allow it to do so very important
  • After the computer restarts, temporarily disable your Anti-Virus and download the latest version of Malwarebytes' Anti-Malware from here and save it to your desktop
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


If you continue to have trouble, just let me know and move on to running ESET
Malwarebytes Anti-Malware 1.60.0.1800 www.malwarebytes.org Database version: v2012.01.19.04 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 9.0.8112.16421 Amy :: AMY-PC [administrator] 1/19/2012 8:18:11 PM mbam-log-2012-01-19 (20-18-11).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 203955 Time elapsed: 29 minute(s), 32 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Well, the good news is that it doesn't look malware related. Let's check a couple of other security related things. First, can you please go to Start > Control Panel > Windows Update and click on Check for Updates in the left hand column. If there are any critical updates you definitely want to install those. For best performance, I also typically install optional updates as well, but that is up to you. After installing any critical updates, please return to the Windows Update screen and check again to see if there are any new updates to install as they build upon each other. If not then you can close that out. I see that you have CCleaner on the machine. This is a great tool for looking at what you have running at startup and choosing to disable what you may not need. There are many programs that you may not actually need to run at startup. For instance, since I regularly check for updates to Adobe and Java products, I choose not to run those at startup. Quicktime is another one you don't necessarily need to run at startup. I do know that many machines where I work that had not updated Malwarebytes were experiencing very slow startup. Did updating that seem to make any difference in boot speed?
I checked for updates, there were not any critical, but I did install the important ones. I had already turned off most of the start up items that tended to pull resources. I posted in the hardware/windows section to see if maybe it is a BIOS or related issue. Thank you so much for your time and help, I will post here if we do figure out the issue. Thanks again. :-)
I'm glad to hear you posted in the Windows forum, that was going to be where I directed you next :) Please feel free to post back if you need further assistance. Good luck!!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI