This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

So Slow ! [Solved]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has been running very slow and has great difficulty connecting to the internet no matter what browser i use. I restored a previous Erunt registry to a known good restore point and all seemed fine but now 24hrs later back to square one, so slow !!

Malwarebytes and avast shows up nothing, and i'm using another computer to post this topic as i cannot get on the net with the problem one.

Also i checked the event log and there are lots of event 1000 DCOM errors ? I can post the exact message if helps ?

I ran OTL but it only produced 1 log

see below

thanks in advance
ED


OTL logfile created on: 30/01/2012 19:11:28 - Run 6
OTL by OldTimer - Version 3.2.31.0 Folder = H:\
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1022.00 Mb Total Physical Memory | 348.34 Mb Available Physical Memory | 34.08% Memory free
1.65 Gb Paging File | 0.93 Gb Available in Paging File | 56.29% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.45 Gb Total Space | 20.34 Gb Free Space | 27.32% Space Free | Partition Type: NTFS
Drive G: | 149.05 Gb Total Space | 110.14 Gb Free Space | 73.90% Space Free | Partition Type: NTFS
Drive H: | 3.68 Gb Total Space | 2.90 Gb Free Space | 78.77% Space Free | Partition Type: FAT32

Computer Name: MAINCOMPUTER | User Name: Lee Edgar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - H:\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Java\jre6\bin\javaw.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
PRC - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\fppdis3a.exe (FinePrint Software, LLC)
PRC - C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\KHAL2\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation)
PRC - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Unlocker\UnlockerAssistant.exe ()
PRC - C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)
PRC - C:\Program Files\A4Tech\Mouse\Amoumain.exe (A4Tech Co.,Ltd.)
PRC - C:\Program Files\A4Tech\Keyboard\Ikeymain.exe (A4Tech Co.,Ltd.)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
PRC - C:\WINDOWS\SYSTEM32\DSentry.exe (Dell - Advanced Desktop Engineering)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Alwil Software\Avast5\defs\12013000\algo.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll ()
MOD - C:\WINDOWS\SYSTEM32\quartz.dll ()
MOD - C:\WINDOWS\SYSTEM32\qdvd.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\ASL.dll ()
MOD - C:\Program Files\Logitech\SetPoint\khalwrapper.dll ()
MOD - C:\WINDOWS\SYSTEM32\qedit.dll ()
MOD - C:\WINDOWS\SYSTEM32\msdmo.dll ()
MOD - C:\WINDOWS\SYSTEM32\devenum.dll ()
MOD - C:\Program Files\FinePixViewer\wia_register_event.dll ()
MOD - C:\Program Files\Unlocker\UnlockerAssistant.exe ()
MOD - C:\Program Files\Unlocker\UnlockerHook.dll ()
MOD - C:\Program Files\SpywareGuard\sgmain.exe ()
MOD - C:\Program Files\SpywareGuard\sgbhp.exe ()
MOD - C:\Program Files\SpywareGuard\spywareguard.dll ()


========== Win32 Services (SafeList) ==========

SRV - (SecureSrv) – File not found
SRV - (SeaPort) – File not found
SRV - (Pml Driver HPZ12) – File not found
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (pdfFactory Pro Dispatcher v3) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe (FinePrint Software, LLC)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (LBTServ) – C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (EPSON_EB_RPCV4_01) EPSON V5 Service4(01) – C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION)
SRV - (UxTuneUp) – C:\WINDOWS\SYSTEM32\uxtuneup.dll (TuneUp Software GmbH)
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) – C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
SRV - (UPHClean) – C:\Program Files\UPHClean\uphclean.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (dtsoftbus01) – C:\WINDOWS\SYSTEM32\DRIVERS\dtsoftbus01.sys (DT Soft Ltd)
DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (pbfilter) – C:\Program Files\PeerBlock\pbfilter.sys ()
DRV - (BVRPMPR5) – C:\WINDOWS\SYSTEM32\DRIVERS\BVRPMPR5.SYS (Avanquest Software)
DRV - (fssfltr) – C:\WINDOWS\SYSTEM32\DRIVERS\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (nmwcd) – C:\WINDOWS\SYSTEM32\DRIVERS\ccdcmb.sys (Nokia)
DRV - (WinDriver6) – C:\WINDOWS\SYSTEM32\DRIVERS\windrvr6.sys (Jungo)
DRV - (FilterService) – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) Logitech QuickCam E3500(UVC) – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\SYSTEM32\DRIVERS\lvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\SYSTEM32\DRIVERS\LVPr2Mon.sys ()
DRV - (LUsbFilt) – C:\WINDOWS\SYSTEM32\DRIVERS\LUsbFilt.sys (Logitech, Inc.)
DRV - (LMouKE) – C:\WINDOWS\SYSTEM32\DRIVERS\LMouKE.Sys (Logitech, Inc.)
DRV - (LMouFilt) – C:\WINDOWS\SYSTEM32\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\SYSTEM32\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV - (L8042mou) – C:\WINDOWS\SYSTEM32\DRIVERS\L8042mou.Sys (Logitech, Inc.)
DRV - (L8042Kbd) – C:\WINDOWS\SYSTEM32\DRIVERS\L8042Kbd.sys (Logitech, Inc.)
DRV - (PCANDIS5) – C:\WINDOWS\SYSTEM32\PCANDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (LVUSBSta) – C:\WINDOWS\SYSTEM32\DRIVERS\LVUSBSta.sys (Logitech Inc.)
DRV - (pccsmcfd) – C:\WINDOWS\SYSTEM32\DRIVERS\pccsmcfd.sys (Nokia)
DRV - (s117obex) – C:\WINDOWS\SYSTEM32\DRIVERS\s117obex.sys (MCCI Corporation)
DRV - (s117mdm) – C:\WINDOWS\SYSTEM32\DRIVERS\s117mdm.sys (MCCI Corporation)
DRV - (s117mgmt) Sony Ericsson Device 117 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\s117mgmt.sys (MCCI Corporation)
DRV - (s117unic) Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\s117unic.sys (MCCI Corporation)
DRV - (s117nd5) Sony Ericsson Device 117 USB Ethernet Emulation SEMC117 (NDIS) – C:\WINDOWS\SYSTEM32\DRIVERS\s117nd5.sys (MCCI Corporation)
DRV - (s117mdfl) – C:\WINDOWS\SYSTEM32\DRIVERS\s117mdfl.sys (MCCI Corporation)
DRV - (s117bus) Sony Ericsson Device 117 driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\s117bus.sys (MCCI Corporation)
DRV - (vaxscsi) – C:\WINDOWS\System32\Drivers\vaxscsi.sys (Alcohol Soft Co., Ltd.)
DRV - (SE27mdm) – C:\WINDOWS\SYSTEM32\DRIVERS\SE27mdm.sys (MCCI)
DRV - (SE27mdfl) – C:\WINDOWS\SYSTEM32\DRIVERS\SE27mdfl.sys (MCCI)
DRV - (SE27bus) Sony Ericsson Device 039 Driver driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\SE27bus.sys (MCCI)
DRV - (LHidKe) – C:\WINDOWS\SYSTEM32\DRIVERS\LHidKE.Sys (Logitech, Inc.)
DRV - (LHidUsbK) – C:\WINDOWS\SYSTEM32\DRIVERS\LHidUsbK.sys (Logitech, Inc.)
DRV - (Amps2prt) – C:\WINDOWS\SYSTEM32\DRIVERS\Amps2prt.sys (A4Tech Co.,Ltd.)
DRV - (iAimFP4) – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys (Intel® Corporation)
DRV - (iAimFP3) – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys (Intel® Corporation)
DRV - (iAimTV4) – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys (Intel® Corporation)
DRV - (iAimTV3) – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys (Intel® Corporation)
DRV - (iAimTV1) – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys (Intel® Corporation)
DRV - (iAimTV0) – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys (Intel® Corporation)
DRV - (iAimFP0) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys (Intel® Corporation)
DRV - (iAimFP1) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys (Intel® Corporation)
DRV - (iAimFP2) – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys (Intel® Corporation)
DRV - (i81x) – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys (Intel® Corporation)
DRV - (alcan5wn) SpeedTouch USB ADSL PPP Networking Driver (NDISWAN) – C:\WINDOWS\SYSTEM32\DRIVERS\alcan5wn.sys (THOMSON)
DRV - (alcaudsl) – C:\WINDOWS\SYSTEM32\DRIVERS\alcaudsl.sys (THOMSON)
DRV - (Machnm32) – C:\WINDOWS\SYSTEM32\Machnm32.sys ()
DRV - (bcm4sbxp) – C:\WINDOWS\SYSTEM32\DRIVERS\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BCMModem) – C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (DCamUSBSQTECH) Dual-Mode DSC(2770) – C:\WINDOWS\SYSTEM32\DRIVERS\SQCaptur.sys (Service & Quality Technology.)
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (EL90XBC) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)
DRV - (DLPortIO) – C:\WINDOWS\SYSTEM32\DRIVERS\DLPORTIO.SYS ()
DRV - (Aspi32) – C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: ""
FF - prefs.js..browser.search.defaultenginename: "Web Search…"
FF - prefs.js..browser.search.defaulturl: ""
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.selectedEngineURL: ""
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 44
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:[removed]
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:[removed]
FF - prefs.js..extensions.enabledItems: {e3f6c2cc-d8db-498c-af6c-499fb211db97}:1.10.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {34EFA911-B536-4C08-BECE-CD5E55C875B0}:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0
FF - prefs.js..extensions.enabledItems: {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.7.3
FF - prefs.js..extensions.enabledItems: {40a1f5d7-afc2-498f-b264-02668d616ff6}:1.1
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [removed]:1.1.3
FF - prefs.js..keyword.URL: "http://vshare.toolbarhome.com/search.aspx?srch=ku&q;="

FF - user.js..keyword.enabled: 1

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\electronicarts.com/GameFacePlugin: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/12/18 10:22:23 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/04/24 13:09:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Extensions
[2012/01/07 14:39:18 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions
[2010/05/11 10:20:25 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/22 15:34:08 | 000,000,000 | —D | M] (Mega Manager Integration) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{40a1f5d7-afc2-498f-b264-02668d616ff6}
[2011/12/27 16:09:44 | 000,000,000 | —D | M] (uTorrentBar Community Toolbar) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2009/09/15 18:29:11 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011/01/18 19:28:06 | 000,000,000 | —D | M] (User Agent Switcher) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2012/01/07 14:39:18 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\staged
[2011/05/07 14:30:37 | 000,000,000 | —D | M] (vShare) – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\extensions\vshare@toolbar
[2010/05/14 14:53:24 | 000,001,819 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\searchplugins\bing.xml
[2011/05/07 14:30:46 | 000,001,583 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Mozilla\Firefox\Profiles\ndizvsja.default\searchplugins\web-search.xml
[2011/12/18 10:22:23 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
() (No name found) – C:\DOCUMENTS AND SETTINGS\LEE EDGAR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\NDIZVSJA.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\LEE EDGAR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\NDIZVSJA.DEFAULT\EXTENSIONS\{9C51BD27-6ED8-4000-A2BF-36CB95C0C947}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\LEE EDGAR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\NDIZVSJA.DEFAULT\EXTENSIONS\[removed]
[2010/05/15 07:57:36 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U30 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = c:\program files\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprpjplug.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Unity Player (Enabled) = C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprjplug.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google Search = C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Gmail = C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2011/12/28 00:22:04 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Phone\IEPlugin\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll File not found
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-A1FB-F862B587B57D} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {8B68564D-53FD-4293-B80C-993A9F3988EE} - No CLSID value found.
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] "rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent File not found
O4 - HKLM..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe (Dell - Advanced Desktop Engineering)
O4 - HKLM..\Run: [iKeyWorks] C:\Program Files\A4Tech\Keyboard\Ikeymain.exe (A4Tech Co.,Ltd.)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [pdfFactory Pro Dispatcher v3] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe (FinePrint Software, LLC)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [WheelMouse] C:\Program Files\A4Tech\Mouse\Amoumain.exe (A4Tech Co.,Ltd.)
O4 - HKCU..\Run: [1FD8AD20A0FC13D0E02DDB23BA6E0414053DB401._service_run] C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Facebook Update] C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [JaGeXDaemon] C:\.jagex_cache_32\jagc.jar ()
O4 - HKCU..\Run: [JagexProperties] C:\.jagex_cache_32\jagd.jar ()
O4 - HKCU..\Run: [LDM] \Program\ File not found
O4 - HKCU..\Run: [NBJ] C:\Program Files\Ahead\Nero BackItUp\NBJ.exe (Ahead Software AG)
O4 - HKCU..\Run: [PrinterShare] C:\Program Files\PrinterShare\paConsole.exe (PrinterAnywhere)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe (Logitech)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\Lee Edgar\Start Menu\Programs\Startup\.jagex_runescape_preferences.jar ()
O4 - Startup: C:\Documents and Settings\Lee Edgar\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\Lee Edgar\Start Menu\Programs\Startup\Logitech . Product Registration.lnk = C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe (Leader Technologies/Logitech)
O4 - Startup: C:\Documents and Settings\Lee Edgar\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Download Link Using Mega Manager… - C:\Program Files\Megaupload\Mega Manager\mm_file.htm ()
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Phone\IEPlugin\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: securesuite.co.uk ([www] https in Trusted sites)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.microsoft.com/Dcode/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Monopoly/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} http://pcpitstop.com/internet/pcpConnCheck.cab (iCC Class)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {32505657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1} http://launcher.station.sony.com/weblaunch…ebInstaller.cab (SonyOnlineInstallerX)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase1140.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} https://secure.footprint.net/kingsisle/stat…ameLauncher.CAB (Wizard101GameLauncher)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {8BC53B30-32E4-4ED3-BEF9-DB761DB77453} http://u3.sandisk.com/download/apps/LPInstaller.CAB (CInstallLPCtrl Object)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} http://download.microsoft.com/download/Pow…N-US/msorun.cab (IEAnimBehaviorFactory Class)
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (Reg Error: Key error.)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadblocker.com/activex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/2.9.2.0…inAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{64A446F9-8064-4AB7-962B-1F0510437B72}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\bw+0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw+0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw00s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw-0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw10s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw20s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw30s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw40s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw50s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw60s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw70s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw80s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bw90s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwa0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwb0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwc0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwd0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwe0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwf0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwg0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwh0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwi0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwj0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwk0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwl0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwm0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwn0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwo0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwp0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwq0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwr0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bws0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwt0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwu0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwv0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bww0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwx0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwy0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0 {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\bwz0s {f1b5ba50-5002-468d-8565-1d301f6e6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\offline-8876480 {F1B5BA50-5002-468D-8565-1D301F6E6521} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (BackWeb Technologies Inc. )
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logitech\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\SYSTEM32\uxtuneup.dll (TuneUp Software GmbH)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\SYSTEM32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.SP54 - SP5X_32.DLL File not found
Drivers32: VIDC.SP55 - SP5X_32.DLL File not found
Drivers32: VIDC.SP56 - SP5X_32.DLL File not found
Drivers32: VIDC.SP57 - SP5X_32.DLL File not found
Drivers32: VIDC.SP58 - SP5X_32.DLL File not found
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2012/01/29 16:44:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Start Menu\Programs\Google Chrome
[2012/01/29 16:27:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\LogiShrd
[2012/01/29 16:23:06 | 000,199,192 | —- | C] (Logitech Inc.) – C:\WINDOWS\System32\lvci12101110.dll
[2012/01/29 16:21:58 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2012/01/28 10:12:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\temp
[2006/10/28 15:10:12 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\Lee Edgar\Application Data\pcouffin.sys

========== Files - Modified Within 30 Days ==========

[2012/01/30 19:18:02 | 000,000,892 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/30 19:05:46 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012/01/30 18:38:01 | 000,000,994 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-10512063-1881097818-1119676352-1006UA.job
[2012/01/30 18:34:35 | 000,000,430 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{497F6515-09E8-4C56-A584-629BB37D8D0F}.job
[2012/01/30 17:47:52 | 000,001,014 | —- | M] () – C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-10512063-1881097818-1119676352-1006UA.job
[2012/01/30 17:47:09 | 000,000,992 | —- | M] () – C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-10512063-1881097818-1119676352-1006Core.job
[2012/01/30 15:37:00 | 000,000,942 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-10512063-1881097818-1119676352-1006Core.job
[2012/01/30 10:51:34 | 000,000,294 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-10512063-1881097818-1119676352-1006.job
[2012/01/30 10:51:34 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-10512063-1881097818-1119676352-1006.job
[2012/01/30 01:18:01 | 000,000,888 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/29 19:11:42 | 000,005,120 | —- | M] () – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/29 16:45:09 | 000,002,316 | —- | M] () – C:\Documents and Settings\Lee Edgar\Desktop\Google Chrome.lnk
[2012/01/29 16:45:09 | 000,002,294 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/01/29 16:29:02 | 000,001,646 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Logitech Vid HD.lnk
[2012/01/29 16:26:02 | 000,000,853 | —- | M] () – C:\Documents and Settings\Lee Edgar\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
[2012/01/29 16:22:31 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\logiflt.iad
[2012/01/29 16:20:46 | 000,001,850 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Logitech Webcam Software.lnk
[2012/01/29 16:14:53 | 000,035,298 | —- | M] () – C:\Documents and Settings\Lee Edgar\Start Menu\Programs\Startup\.jagex_runescape_preferences.jar
[2012/01/29 16:11:50 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2012/01/29 16:07:37 | 000,552,440 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2012/01/29 16:07:37 | 000,101,466 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2012/01/29 16:03:28 | 000,000,164 | —- | M] () – C:\WINDOWS\System32\FppLicense3.ini
[2012/01/29 16:02:34 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2012/01/29 15:23:24 | 013,631,488 | —- | M] () – C:\Documents and Settings\Lee Edgar\ntuser.bak
[2012/01/27 17:19:22 | 000,000,398 | —- | M] () – C:\WINDOWS\tasks\1-Click Maintenance.job
[2012/01/27 11:58:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/01/24 14:12:43 | 000,297,669 | —- | M] () – C:\Documents and Settings\Lee Edgar\My Documents\the-anti-bride-124.jpg
[2012/01/24 14:12:16 | 000,034,499 | —- | M] () – C:\Documents and Settings\Lee Edgar\My Documents\The Anti-Bride-143 - Copy.jpg
[2012/01/24 14:11:52 | 000,032,730 | —- | M] () – C:\Documents and Settings\Lee Edgar\My Documents\untitled.jpg
[2012/01/23 22:19:54 | 025,954,497 | —- | M] () – C:\Documents and Settings\Lee Edgar\My Documents\Lee.zip
[2012/01/11 03:28:29 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/01/09 17:11:47 | 000,130,416 | —- | M] () – C:\Documents and Settings\Lee Edgar\My Documents\bookmarks_09_01_2012.html
[2012/01/07 15:15:55 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl

========== Files Created - No Company Name ==========

[2012/01/29 19:08:06 | 000,005,120 | —- | C] () – C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/29 16:45:09 | 000,002,316 | —- | C] () – C:\Documents and Settings\Lee Edgar\Desktop\Google Chrome.lnk
[2012/01/29 16:45:09 | 000,002,294 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/01/29 16:29:02 | 000,001,646 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Logitech Vid HD.lnk
[2012/01/29 16:26:01 | 000,000,853 | —- | C] () – C:\Documents and Settings\Lee Edgar\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
[2012/01/29 16:23:34 | 000,266,828 | —- | C] () – C:\WINDOWS\System32\drivers\LVAFT.cfg
[2012/01/29 16:20:46 | 000,001,850 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Logitech Webcam Software.lnk
[2012/01/24 14:12:45 | 000,297,669 | —- | C] () – C:\Documents and Settings\Lee Edgar\My Documents\the-anti-bride-124.jpg
[2012/01/24 14:12:19 | 000,034,499 | —- | C] () – C:\Documents and Settings\Lee Edgar\My Documents\The Anti-Bride-143 - Copy.jpg
[2012/01/24 14:12:07 | 000,032,730 | —- | C] () – C:\Documents and Settings\Lee Edgar\My Documents\untitled.jpg
[2012/01/09 17:11:47 | 000,130,416 | —- | C] () – C:\Documents and Settings\Lee Edgar\My Documents\bookmarks_09_01_2012.html
[2011/09/16 15:50:45 | 000,000,013 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\RSBuddy Login.ini
[2011/08/31 05:45:00 | 000,000,000 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\RSBot_Accounts.ini
[2011/06/02 12:23:28 | 000,000,086 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\RSBuddy_billscoft.ini
[2011/05/06 20:39:59 | 000,000,081 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\RSBuddy_dannyedgar123.ini
[2011/05/05 20:24:41 | 000,151,515 | —- | C] () – C:\Program Files\hosts.zip
[2011/02/25 13:24:42 | 000,000,000 | —- | C] () – C:\WINDOWS\Protector Eclipse.ini
[2011/01/01 13:36:58 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2010/12/06 13:58:56 | 002,496,715 | —- | C] () – C:\WINDOWS\System32\abgx360.exe
[2010/09/08 14:57:47 | 000,000,053 | —- | C] () – C:\WINDOWS\webica.ini
[2010/06/13 16:39:17 | 000,000,125 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2010/03/19 08:02:26 | 000,000,164 | —- | C] () – C:\WINDOWS\System32\FppLicense3.ini
[2010/03/19 08:01:51 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\fppent3a.dll
[2009/12/28 20:18:54 | 000,110,120 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/11/20 23:51:22 | 000,001,353 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2009/11/19 19:57:14 | 000,000,000 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\dm.ini
[2009/10/07 01:46:36 | 000,025,752 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/10/07 01:23:08 | 000,013,584 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/09/10 19:16:37 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/09/04 16:35:54 | 000,004,594 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2009/09/04 16:35:51 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2009/05/29 19:40:06 | 000,000,029 | —- | C] () – C:\WINDOWS\DEBUGSM.INI
[2009/05/29 18:50:27 | 000,111,932 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2009/05/29 18:50:27 | 000,001,146 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2009/05/29 18:50:27 | 000,001,136 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2009/05/29 18:50:27 | 000,001,120 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2009/05/29 18:50:27 | 000,001,107 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2009/05/29 18:50:27 | 000,001,104 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2009/05/29 18:50:27 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2009/05/29 18:50:26 | 000,031,053 | —- | C] () – C:\WINDOWS\System32\EPPICPattern131.dat
[2009/05/29 18:50:26 | 000,027,417 | —- | C] () – C:\WINDOWS\System32\EPPICPattern121.dat
[2009/05/29 18:50:26 | 000,026,154 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2009/05/29 18:50:26 | 000,024,903 | —- | C] () – C:\WINDOWS\System32\EPPICPattern3.dat
[2009/05/29 18:50:26 | 000,021,390 | —- | C] () – C:\WINDOWS\System32\EPPICPattern5.dat
[2009/05/29 18:50:26 | 000,020,148 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2009/05/29 18:50:26 | 000,011,811 | —- | C] () – C:\WINDOWS\System32\EPPICPattern4.dat
[2009/05/29 18:50:26 | 000,004,943 | —- | C] () – C:\WINDOWS\System32\EPPICPattern6.dat
[2009/05/29 18:50:26 | 000,001,139 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2009/05/29 18:50:26 | 000,001,139 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2009/05/29 18:50:26 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2009/05/29 18:50:26 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2009/05/29 18:45:51 | 000,000,025 | —- | C] () – C:\WINDOWS\CDE SX400DEFGIPS.ini
[2009/05/03 16:18:19 | 000,082,289 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008/12/17 20:51:13 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2008/12/01 13:34:34 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\SGSTDREG.dll
[2008/12/01 13:34:30 | 000,131,072 | —- | C] () – C:\WINDOWS\System32\SGRegister.dll
[2008/05/29 11:17:22 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\SageEventHandler.exe
[2008/05/29 11:16:30 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\SGTBAR32.DLL
[2008/05/29 11:16:28 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\SGSTAT32.DLL
[2008/05/29 11:16:14 | 000,282,624 | —- | C] () – C:\WINDOWS\System32\SGList32.dll
[2008/05/29 11:16:10 | 000,278,528 | —- | C] () – C:\WINDOWS\System32\SGTool32.dll
[2008/05/29 11:16:06 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\SGIntl32.dll
[2008/05/29 11:16:04 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\SGHelp32.dll
[2008/05/29 11:16:04 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\SGDt32.dll
[2008/05/29 11:16:02 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\SGAPPBAR.DLL
[2008/05/29 11:16:00 | 000,245,760 | —- | C] () – C:\WINDOWS\System32\SGSchemeXml.dll
[2008/05/29 11:15:52 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\SGSchemeXP.dll
[2008/05/29 11:15:50 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\SGSchemeDefault.dll
[2008/05/29 11:15:46 | 000,221,184 | —- | C] () – C:\WINDOWS\System32\SGSchemeManager.dll
[2008/05/29 11:15:40 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\SGCom32.dll
[2008/05/29 11:15:04 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\SGWebBrowser.dll
[2008/05/15 18:40:21 | 000,163,840 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\fontdb.mdb
[2008/05/15 18:40:21 | 000,000,231 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/03/12 19:28:43 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2007/12/07 21:19:24 | 000,001,298 | —- | C] () – C:\WINDOWS\ARCHPR.INI
[2007/12/04 13:22:58 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\SageFolderBrowser.dll
[2007/11/12 16:12:54 | 000,000,000 | —- | C] () – C:\WINDOWS\MSDraw.ini
[2007/11/10 14:14:20 | 000,015,840 | —- | C] () – C:\WINDOWS\System32\Machnm1.exe
[2007/11/10 14:14:20 | 000,002,304 | —- | C] () – C:\WINDOWS\System32\Machnm32.sys
[2007/05/08 13:26:59 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2007/02/25 12:48:02 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2006/12/03 11:04:03 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\default_user_class.dat_BAK_13980
[2006/12/03 11:04:03 | 000,008,192 | —- | C] () – C:\WINDOWS\System32\default_user_class.dat
[2006/11/01 14:50:40 | 000,126,976 | R— | C] () – C:\WINDOWS\System32\PDFInstall.exe
[2006/11/01 14:41:16 | 001,712,128 | —- | C] () – C:\WINDOWS\System32\SGRep32.dll
[2006/10/28 15:10:13 | 000,087,608 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\ezpinst.exe
[2006/10/28 15:10:13 | 000,007,824 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\pcouffin.cat
[2006/10/28 15:10:12 | 000,001,144 | —- | C] () – C:\Documents and Settings\Lee Edgar\Application Data\pcouffin.inf
[2006/09/26 19:37:54 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2006/09/07 20:58:16 | 000,696,320 | —- | C] () – C:\Program Files\Common Files\XCMHook.dll
[2006/09/07 20:58:16 | 000,024,576 | —- | C] () – C:\Program Files\Common Files\XCPCMenu.exe
[2006/08/19 11:21:38 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/08/19 10:56:35 | 000,000,059 | —- | C] () – C:\WINDOWS\WININIT.INI
[2006/07/29 21:23:21 | 000,737,280 | —- | C] () – C:\WINDOWS\dbplugin.exe
[2006/07/29 21:23:20 | 000,933,888 | —- | C] () – C:\WINDOWS\npdbplug.dll
[2006/07/25 21:57:50 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/05/09 18:46:51 | 000,118,784 | —- | C] () – C:\WINDOWS\ShowBmp.exe
[2006/05/09 18:46:51 | 000,001,325 | —- | C] () – C:\WINDOWS\Remove.ini
[2006/04/20 19:13:52 | 000,001,115 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/04/20 18:34:17 | 000,002,215 | —- | C] () – C:\WINDOWS\CDPR.INI
[2006/03/05 13:51:06 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/10/03 18:14:38 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/10/03 08:16:04 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2005/09/23 22:43:24 | 003,596,288 | R— | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/09/23 22:43:24 | 000,159,744 | R— | C] () – C:\WINDOWS\System32\ssleay32.dll
[2005/09/23 22:43:22 | 000,831,488 | R— | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/09/23 22:43:22 | 000,524,288 | R— | C] () – C:\WINDOWS\System32\divxsm.exe
[2005/09/23 22:43:22 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\dtu100.dll
[2005/06/03 07:06:04 | 000,212,992 | —- | C] () – C:\WINDOWS\System32\SGSchemeConfig.dll
[2005/05/11 20:46:12 | 000,001,001 | —- | C] () – C:\WINDOWS\psmplay.ini
[2005/05/10 18:57:48 | 000,000,559 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2005/05/10 17:31:07 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\ESICOMMN.DLL
[2005/02/23 17:37:09 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlsz.INI
[2005/01/07 22:06:34 | 000,077,824 | —- | C] () – C:\WINDOWS\pysoft_uninstaller.exe
[2004/10/30 09:52:37 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/10/06 16:40:55 | 000,005,606 | —- | C] () – C:\WINDOWS\System32\stci.dll
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\ADFUUD.SYS
[2004/09/09 16:43:14 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2004/03/02 22:17:34 | 000,552,440 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2004/03/02 22:17:34 | 000,101,466 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2004/03/02 22:17:20 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/03/02 22:17:05 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/03/02 22:06:12 | 000,000,550 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/03/09 20:31:04 | 000,561,152 | —- | C] () – C:\WINDOWS\System32\hpotscl.dll
[2002/09/03 09:05:08 | 000,446,904 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2002/09/03 08:56:30 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2002/08/29 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2002/08/29 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2002/08/29 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2002/08/29 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2002/08/29 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2002/08/29 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2002/08/29 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT
[2000/06/29 16:24:14 | 000,003,584 | —- | C] () – C:\WINDOWS\System32\drivers\DLPORTIO.SYS
[1996/04/03 19:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2010/08/28 16:20:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2009/09/10 16:31:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2006/09/08 21:27:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Bluetooth
[2011/12/27 17:13:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/05/29 18:49:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2011/06/26 08:33:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Greentram
[2011/10/08 09:55:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallEngine
[2011/05/01 19:31:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Media Get LLC
[2010/04/15 22:13:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OviInstallerCache
[2010/04/15 22:33:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2012/01/10 09:26:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PrinterShare
[2011/10/08 09:54:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sage
[2010/06/13 16:39:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2008/08/14 19:07:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2007/07/23 20:08:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SPAMfighter
[2006/09/11 18:31:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2009/05/29 18:57:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UDL
[2004/08/19 18:09:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2010/03/13 15:06:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2009/12/25 07:27:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/11/07 19:41:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\.minecraft
[2011/11/14 17:36:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\abgx360
[2008/03/28 20:18:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\AutoTransfer
[2009/09/10 16:40:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\AVGTOOLBAR
[2008/06/01 08:57:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Azureus
[2011/04/12 11:23:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\BabylonToolbar
[2008/05/15 18:48:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\BorWare
[2010/03/02 07:36:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/05/16 12:49:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\com.imoneymanager.imm.2184A5AABEFD9A95272C652C16767C2B5E7A1512.1
[2011/12/28 19:40:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\DAEMON Tools Lite
[2011/07/03 13:47:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Electronic Arts
[2011/08/03 16:25:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\EPSON
[2010/08/01 13:47:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\FixIt
[2010/08/04 16:49:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\FUJIFILM
[2011/01/01 13:37:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\GamesCafe
[2010/07/04 18:53:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\GameTuts
[2010/09/02 20:05:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\GARMIN
[2011/12/15 19:53:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\gtk-2.0
[2011/05/11 23:10:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\HTC
[2011/05/11 23:08:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2010/11/21 19:00:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\ICAClient
[2009/05/24 19:58:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Image Zone Express
[2011/01/20 21:37:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\ImgBurn
[2011/12/28 16:58:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\KeePass
[2004/03/06 21:39:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Leadertech
[2008/06/01 08:57:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\MailWasherPro
[2011/01/19 23:13:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Megaupload
[2010/04/15 22:35:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Nokia
[2011/05/11 23:10:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Outlook
[2010/04/15 22:33:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\PC Suite
[2010/06/25 13:49:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\SmartDraw
[2011/12/27 11:01:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Sony
[2010/06/05 16:38:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Sony Online Entertainment
[2007/07/23 20:09:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\SPAMfighter
[2009/02/17 21:06:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Spectaculator
[2008/09/30 20:14:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\SpinTop
[2011/12/28 19:55:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Sports Interactive
[2009/09/23 21:30:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\TeamViewer
[2006/09/09 19:18:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Teleca
[2004/03/10 17:33:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Template
[2006/09/25 21:44:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\TuneUp Software
[2008/10/23 17:06:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\TuxPaint
[2010/10/25 16:21:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2004/08/19 18:09:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Ulead Systems
[2011/04/12 11:33:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Uniblue
[2011/07/23 13:54:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Unity
[2012/01/29 08:17:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\uTorrent
[2011/12/02 20:57:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Vso
[2011/05/30 10:26:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Lee Edgar\Application Data\Windows Search
[2012/01/27 17:19:22 | 000,000,398 | —- | M] () – C:\WINDOWS\Tasks\1-Click Maintenance.job
[2012/01/30 17:47:09 | 000,000,992 | —- | M] () – C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-10512063-1881097818-1119676352-1006Core.job
[2012/01/30 17:47:52 | 000,001,014 | —- | M] () – C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-10512063-1881097818-1119676352-1006UA.job
[2012/01/30 18:34:35 | 000,000,430 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{497F6515-09E8-4C56-A584-629BB37D8D0F}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/03/09 19:11:55 | 000,504,058 | —- | M] () – C:\4D53082D.gpd
[2004/11/01 17:48:40 | 000,000,211 | —- | M] () – C:\Boot.bak
[2011/05/30 12:01:04 | 000,000,281 | -HS- | M] () – C:\BOOT.INI
[2002/09/03 08:38:46 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2004/08/03 22:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2002/09/03 08:59:58 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/12/17 20:57:15 | 000,000,133 | —- | M] () – C:\DeletePrintJobs.cmd
[2004/03/02 22:09:36 | 000,004,275 | RH– | M] () – C:\DELL.SDR
[2008/05/29 19:04:00 | 000,004,300 | —- | M] () – C:\hotfix.txt
[2009/05/25 08:53:48 | 000,000,488 | —- | M] () – C:\hpfr5550.xml
[2009/05/24 21:31:33 | 000,000,796 | -H– | M] () – C:\hpothb07.dat
[2009/05/24 21:31:33 | 000,001,495 | -H– | M] () – C:\hpothb07.tif
[2002/09/03 08:59:58 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2004/03/02 22:38:12 | 000,000,454 | -H– | M] () – C:\IPH.PH
[2002/09/03 08:59:58 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/11/01 17:39:33 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/06/01 15:26:41 | 000,250,048 | RHS- | M] () – C:\NTLDR
[2006/09/07 21:03:30 | 000,000,456 | -H– | M] () – C:\os100944.bin
[2012/01/29 16:02:35 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2008/05/29 19:04:00 | 000,624,768 | —- | M] (Microsoft Corporation) – C:\q828133.exe
[2010/06/03 08:12:24 | 000,000,026 | —- | M] () – C:\register.js
[2004/05/04 21:39:47 | 000,000,016 | —- | M] () – C:\win2.log

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2002/09/03 08:59:02 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\DESKTOP.INI

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 10:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/11/28 18:01:25 | 000,041,184 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2008/02/20 16:50:28 | 000,903,680 | —- | M] (Jan Kolarik & Ondrej Vaverka) – C:\WINDOWS\Protector Eclipse.scr
[2010/04/16 23:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2006/06/28 21:04:42 | 000,001,618 | -H– | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2011/05/05 20:24:42 | 000,151,515 | —- | M] () – C:\Program Files\hosts.zip

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2002/09/03 08:47:18 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\DEFAULT.SAV
[2002/09/03 08:47:18 | 000,602,112 | —- | M] () – C:\WINDOWS\System32\config\SOFTWARE.SAV
[2002/09/03 08:47:18 | 000,380,928 | —- | M] () – C:\WINDOWS\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/06/01 15:34:37 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\DESKTOP.INI

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2004/11/01 17:55:39 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI
[2004/03/05 21:16:51 | 000,000,079 | —- | M] () – C:\Documents and Settings\Lee Edgar\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2009/09/10 19:21:43 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Lee Edgar\Desktop\ATF-Cleaner.exe
[2009/09/09 22:12:35 | 000,085,504 | —- | M] () – C:\Documents and Settings\Lee Edgar\Desktop\Inherit.exe
[2007/09/10 13:17:56 | 002,414,704 | —- | M] (Radica Games Limited) – C:\Documents and Settings\Lee Edgar\Desktop\Patch001.exe
[2011/12/28 15:47:00 | 000,446,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lee Edgar\Desktop\TFC.exe

< %PROGRAMFILES%\Common Files\*.* >
[2000/01/14 14:46:26 | 000,696,320 | —- | M] () – C:\Program Files\Common Files\XCMHook.dll
[2000/01/14 14:46:28 | 000,024,576 | —- | M] () – C:\Program Files\Common Files\XCPCMenu.exe

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-01-30 03:00:25

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$hf_mig$\KB932168\KB932168] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB933729\KB933729] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\$hf_mig$\KB943460\KB943460] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\System.EnterpriseServices] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\IEExecRemote] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP283.tmp\ZAP283.tmp] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPA0.tmp\ZAPA0.tmp] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\assembly\tmp\tmp] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Cache\Adobe Reader 6.0.1\Adobe Reader 6.0.1] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Config\Config] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Connection Wizard\Connection Wizard] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Debug\UserMode\UserMode] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Downloaded Program Files\CONFLICT.1\CONFLICT.1] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\ftpcache\ftpcache] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Help\SBSI\Training\WXPPer\Cbz\Cbz] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Help\SBSI\Training\WXPPer\Lib\Lib] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Help\SBSI\Training\WXPPer\Wave\Wave] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\IME\IMEJP\APPLETS\APPLETS] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\IME\IMEJP98\IMEJP98] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\00002109411090400000000000F01FEC\12.0.4518\12.0.4518] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\00002109440090400000000000F01FEC\12.0.4518\12.0.4518] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\00002109511090400000000000F01FEC\12.0.4518\12.0.4518] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\00002109711090400000000000F01FEC\12.0.4518\12.0.4518] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\00002109910090400000000000F01FEC\12.0.4518\12.0.4518] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\00002109B10090400000000000F01FEC\12.0.4518\12.0.4518] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\00002109F100A0C00000000000F01FEC\12.0.4518\12.0.4518] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\00002109F100C0400000000000F01FEC\12.0.4518\12.0.4518] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\0DC1503A46F231838AD88BCDDC8E8F7C\3.2.30729\3.2.30729] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\D7314F9862C648A4DB8BE2A5B47BE100\1.0.0\1.0.0] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Installer\$PatchCache$\Managed\DC3BF90CC0D3D2F398A9A6D1762F70F3\2.2.30729\2.2.30729] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\LastGood(2)\INF\INF] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\Bind Logs\Bind Logs] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\Temporary ASP.NET Files] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Minidump\Minidump] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\MSAPPS\MSINFO\MSINFO] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\MUI\MUI] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\ErrorRep\UserDumps\UserDumps] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\BATCH\BATCH] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\Config\CheckPoint\CheckPoint] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\HelpFiles\HelpFiles] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\InstalledSKUs\InstalledSKUs] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\System\DFS\DFS] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PCHealth\HelpCtr\Temp\Temp] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\PIF\PIF] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Registration\CRMLog\CRMLog] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\REPAIR\Backup\ServiceState\ServiceState] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution.old\AuthCabs\Downloaded\Downloaded] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SoftwareDistribution.old\Download\355f788b6de8a3ec79e9aa172e6317f1\backup\backup] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\Sun\Java\Deployment\Deployment] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SxsCaPendDel\SxsCaPendDel] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\1025\1025] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\1028\1028] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\1031\1031] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\1037\1037] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\1041\1041] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\1042\1042] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\1054\1054] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\2052\2052] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\3076\3076] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\3COM_DMI\3COM_DMI] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\Adobe\update\update] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\TempDir\TempDir] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Identities\{8D32DF8B-D3B8-4783-A0C5-FE37E2FC8659}\{8D32DF8B-D3B8-4783-A0C5-FE37E2FC8659}] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\Credentials\Credentials] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\MMC\MMC] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\SystemCertificates\My\Certificates\Certificates] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\SystemCertificates\My\CRLs\CRLs] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Microsoft\SystemCertificates\My\CTLs\CTLs] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Application Data\Sun\Java\Deployment\javaws\cache\cache] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Desktop\Desktop] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Application Data\Microsoft\CD Burning\CD Burning] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Application Data\Microsoft\Credentials\Credentials] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\My Documents\My Pictures\Dell Image Expert Images\Dell Image Expert Images] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\NetHood\NetHood] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\PrintHood\PrintHood] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\DHCP\DHCP] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\DRIVERS\DISDN\DISDN] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\EXPORT\EXPORT] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\FxsTmp\FxsTmp] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\INETSRV\INETSRV] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\Macromed\update\update] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\MUI\DISPSPEC\DISPSPEC] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\NtmsData\Export\Export] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\OOBE\HTML\ISPSGNUP\ISPSGNUP] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\OOBE\HTML\OEMCUST\OEMCUST] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\OOBE\HTML\OEMHW\OEMHW] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\OOBE\HTML\OEMREG\OEMREG] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\OOBE\SAMPLE\SAMPLE] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\ShellExt\ShellExt] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\WBEM\MOF\BAD\BAD] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\WBEM\MOF\GOOD\GOOD] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\WBEM\SNMP\SNMP] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\WINS\WINS] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\SYSTEM32\XIRCOM\XIRCOM] -> \Device\__max++>\^ -> Mount Point
[C:\WINDOWS\WinSxS\InstallTemp\InstallTemp] -> \Device\__max++>\^ -> Mount Point

< End of report >
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!





Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.




Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Hi Patndoris

Many thanks for your reply, I would just like to update you. Over the last couple of days whilst waiting for a reply (that did not mean to sound ungrateful as i know you give your time for free and are very busy) I ran a full system scan with Malwarebytes and it did find some infections which i let it remove and reboot and as a result the computer has been working much better until now/today. When i launch google chrome it is just hanging and the page wont load until i shutdown and restart so maybe all is not well ? I have pasted the log I ran a couple of days ago for you to see.

Also the 2 scans you have asked me to perform have reported nothing but again i have pasted these as you requested

Many Thanks
ED


Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.02.01.02

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Lee Edgar :: MAINCOMPUTER [administrator]

01/02/2012 10:01:48
mbam-log-2012-02-01 (10-01-48).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 376543
Time elapsed: 3 hour(s), 16 minute(s), 21 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 9
C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Xenocode\Sandbox\Eclipse\0.0.2.0\2010.03.29T04.09\Virtual\STUBEXE\7.1.280\@DESKTOP@\Eclipse.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Xenocode\Sandbox\Horizon\2.0.2.3\2011.06.30T17.33\Native\STUBEXE\8.0.1112\@PROGRAMFILES@\COMMON~1\MICROS~1\DW\DW20.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Xenocode\Sandbox\Horizon\2.0.4.0\2011.07.22T06.51\Native\STUBEXE\8.0.1112\@PROGRAMFILES@\COMMON~1\MICROS~1\DW\DW20.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Xenocode\Sandbox\Updater\1.0.0.0\2010.05.10T06.09\Native\STUBEXE\7.1.280\@DESKTOP@\Eclipse.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Lee Edgar\Local Settings\Application Data\Xenocode\Sandbox\Updater\1.0.0.0\2010.05.10T06.09\Virtual\STUBEXE\7.1.280\@APPDIR@\Updater.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\U.B. Funkeys\MegaByte\wdreg_gui.exe (Trojan.Agent) -> Quarantined and deleted successfully.
G:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP336\A0054194.exe (Adware.Agent) -> Quarantined and deleted successfully.
G:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP336\A0054195.exe (Adware.Agent) -> Quarantined and deleted successfully.
G:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP336\A0054196.exe (Adware.Agent) -> Quarantined and deleted successfully.

(end)

19:06:58.0062 3644 TDSS rootkit removing tool [removed] Feb 1 2012 09:28:49
19:06:58.0218 3644 ============================================================
19:06:58.0218 3644 Current date / time: 2012/02/02 19:06:58.0218
19:06:58.0218 3644 SystemInfo:
19:06:58.0218 3644
19:06:58.0218 3644 OS Version: 5.1.2600 ServicePack: 3.0
19:06:58.0218 3644 Product type: Workstation
19:06:58.0218 3644 ComputerName: MAINCOMPUTER
19:06:58.0218 3644 UserName: Lee Edgar
19:06:58.0218 3644 Windows directory: C:\WINDOWS
19:06:58.0218 3644 System windows directory: C:\WINDOWS
19:06:58.0218 3644 Processor architecture: Intel x86
19:06:58.0218 3644 Number of processors: 1
19:06:58.0218 3644 Page size: 0x1000
19:06:58.0218 3644 Boot type: Normal boot
19:06:58.0218 3644 ============================================================
19:07:00.0218 3644 Drive \Device\Harddisk0\DR0 - Size: 0x12A05F2000 (74.51 Gb), SectorSize: 0x200, Cylinders: 0x25FE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
19:07:00.0234 3644 Drive \Device\Harddisk1\DR1 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
19:07:00.0250 3644 \Device\Harddisk0\DR0:
19:07:00.0250 3644 MBR used
19:07:00.0250 3644 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x17886, BlocksNum 0x94E7137
19:07:00.0250 3644 \Device\Harddisk1\DR1:
19:07:00.0250 3644 MBR used
19:07:00.0250 3644 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x6, StartLBA 0x3F, BlocksNum 0x12A18A82
19:07:00.0515 3644 Initialize success
19:07:00.0515 3644 ============================================================
19:07:58.0875 3056 ============================================================
19:07:58.0890 3056 Scan started
19:07:58.0890 3056 Mode: Manual;
19:07:58.0890 3056 ============================================================
19:07:59.0250 3056 Aavmker4 (b6de0336f9f4b687b4ff57939f7b657a) C:\WINDOWS\system32\drivers\Aavmker4.sys
19:07:59.0250 3056 Aavmker4 - ok
19:07:59.0312 3056 Abiosdsk - ok
19:07:59.0421 3056 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\System32\DRIVERS\ABP480N5.SYS
19:07:59.0421 3056 abp480n5 - ok
19:07:59.0625 3056 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
19:07:59.0640 3056 ACPI - ok
19:07:59.0828 3056 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
19:07:59.0828 3056 ACPIEC - ok
19:07:59.0921 3056 Ad-Watch Connect Filter - ok
19:07:59.0984 3056 Ad-Watch Real-Time Scanner - ok
19:08:00.0046 3056 Ad-Watch Registry Filter - ok
19:08:00.0140 3056 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\System32\DRIVERS\adpu160m.sys
19:08:00.0140 3056 adpu160m - ok
19:08:00.0250 3056 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys
19:08:00.0250 3056 aeaudio - ok
19:08:00.0421 3056 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
19:08:00.0437 3056 aec - ok
19:08:00.0625 3056 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
19:08:00.0625 3056 AFD - ok
19:08:00.0734 3056 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\System32\DRIVERS\agp440.sys
19:08:00.0750 3056 agp440 - ok
19:08:00.0906 3056 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\System32\DRIVERS\agpCPQ.sys
19:08:00.0906 3056 agpCPQ - ok
19:08:01.0109 3056 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\System32\DRIVERS\aha154x.sys
19:08:01.0109 3056 Aha154x - ok
19:08:01.0218 3056 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\System32\DRIVERS\aic78u2.sys
19:08:01.0218 3056 aic78u2 - ok
19:08:01.0390 3056 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\System32\DRIVERS\aic78xx.sys
19:08:01.0390 3056 aic78xx - ok
19:08:01.0546 3056 alcan5wn (0940030d5a5869067ccc03e3b0b8dec7) C:\WINDOWS\system32\DRIVERS\alcan5wn.sys
19:08:01.0546 3056 alcan5wn - ok
19:08:01.0609 3056 alcaudsl (4c9577888c53243e2991456f510488a1) C:\WINDOWS\system32\DRIVERS\alcaudsl.sys
19:08:01.0609 3056 alcaudsl - ok
19:08:01.0828 3056 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\System32\DRIVERS\aliide.sys
19:08:01.0828 3056 AliIde - ok
19:08:01.0953 3056 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\System32\DRIVERS\alim1541.sys
19:08:01.0953 3056 alim1541 - ok
19:08:02.0093 3056 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\System32\DRIVERS\amdagp.sys
19:08:02.0093 3056 amdagp - ok
19:08:02.0250 3056 Amps2prt (a6215b60b98ba023ec5606a360d502af) C:\WINDOWS\system32\DRIVERS\Amps2prt.sys
19:08:02.0250 3056 Amps2prt - ok
19:08:02.0375 3056 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\System32\DRIVERS\amsint.sys
19:08:02.0375 3056 amsint - ok
19:08:02.0562 3056 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\System32\DRIVERS\asc.sys
19:08:02.0562 3056 asc - ok
19:08:02.0671 3056 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\System32\DRIVERS\asc3350p.sys
19:08:02.0671 3056 asc3350p - ok
19:08:02.0859 3056 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\System32\DRIVERS\asc3550.sys
19:08:02.0859 3056 asc3550 - ok
19:08:02.0984 3056 Aspi32 (b979979ab8027f7f53fb16ec4229b7db) C:\WINDOWS\system32\drivers\Aspi32.sys
19:08:02.0984 3056 Aspi32 - ok
19:08:03.0156 3056 aswFsBlk (054df24c92b55427e0757cfff160e4f2) C:\WINDOWS\system32\drivers\aswFsBlk.sys
19:08:03.0156 3056 aswFsBlk - ok
19:08:03.0265 3056 aswMon2 (ef0e9ad83380724bd6fbbb51d2d0f5b8) C:\WINDOWS\system32\drivers\aswMon2.sys
19:08:03.0265 3056 aswMon2 - ok
19:08:03.0421 3056 aswRdr (352d5a48ebab35a7693b048679304831) C:\WINDOWS\system32\drivers\aswRdr.sys
19:08:03.0421 3056 aswRdr - ok
19:08:03.0531 3056 aswSnx (8d34d2b24297e27d93e847319abfdec4) C:\WINDOWS\system32\drivers\aswSnx.sys
19:08:03.0562 3056 aswSnx - ok
19:08:03.0718 3056 aswSP (010012597333da1f46c3243f33f8409e) C:\WINDOWS\system32\drivers\aswSP.sys
19:08:03.0734 3056 aswSP - ok
19:08:03.0906 3056 aswTdi (f9f84364416658e9786235904d448d37) C:\WINDOWS\system32\drivers\aswTdi.sys
19:08:03.0906 3056 aswTdi - ok
19:08:04.0000 3056 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
19:08:04.0000 3056 AsyncMac - ok
19:08:04.0156 3056 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
19:08:04.0156 3056 atapi - ok
19:08:04.0218 3056 Atdisk - ok
19:08:04.0312 3056 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
19:08:04.0312 3056 Atmarpc - ok
19:08:04.0375 3056 ATWPKT2 - ok
19:08:04.0546 3056 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
19:08:04.0546 3056 audstub - ok
19:08:04.0671 3056 bcm4sbxp (b60f57b4d9cdbc663cc03eb8af7ec34e) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
19:08:04.0671 3056 bcm4sbxp - ok
19:08:04.0921 3056 BCMModem (2b028f4b6812bc236d9dc1b9fea9853a) C:\WINDOWS\system32\DRIVERS\BCMSM.sys
19:08:04.0953 3056 BCMModem - ok
19:08:05.0125 3056 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
19:08:05.0125 3056 Beep - ok
19:08:05.0203 3056 BlueletAudio - ok
19:08:05.0281 3056 BlueletSCOAudio - ok
19:08:05.0390 3056 BT - ok
19:08:05.0453 3056 BTCOMM - ok
19:08:05.0515 3056 Btcsrusb - ok
19:08:05.0609 3056 BthEnum (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys
19:08:05.0609 3056 BthEnum - ok
19:08:05.0734 3056 BTHidEnum - ok
19:08:05.0796 3056 BTHidMgr - ok
19:08:05.0906 3056 BTHMODEM (fca6f069597b62d42495191ace3fc6c1) C:\WINDOWS\system32\DRIVERS\bthmodem.sys
19:08:05.0906 3056 BTHMODEM - ok
19:08:06.0078 3056 BthPan (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys
19:08:06.0078 3056 BthPan - ok
19:08:06.0187 3056 BTHPORT (662bfd909447dd9cc15b1a1c366583b4) C:\WINDOWS\system32\Drivers\BTHport.sys
19:08:06.0203 3056 BTHPORT - ok
19:08:06.0359 3056 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys
19:08:06.0359 3056 BTHUSB - ok
19:08:06.0421 3056 BTKRNBDG - ok
19:08:06.0515 3056 BVRPMPR5 (248dfa5762dde38dfddbbd44149e9d7a) C:\WINDOWS\system32\drivers\BVRPMPR5.SYS
19:08:06.0515 3056 BVRPMPR5 - ok
19:08:06.0656 3056 bvrp_pci - ok
19:08:06.0718 3056 Ca533av - ok
19:08:06.0828 3056 catchme - ok
19:08:07.0000 3056 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\System32\DRIVERS\cbidf2k.sys
19:08:07.0000 3056 cbidf - ok
19:08:07.0093 3056 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
19:08:07.0093 3056 cbidf2k - ok
19:08:07.0187 3056 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
19:08:07.0187 3056 CCDECODE - ok
19:08:07.0406 3056 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\System32\DRIVERS\cd20xrnt.sys
19:08:07.0562 3056 cd20xrnt - ok
19:08:07.0703 3056 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
19:08:07.0703 3056 Cdaudio - ok
19:08:07.0828 3056 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
19:08:07.0843 3056 Cdfs - ok
19:08:08.0000 3056 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
19:08:08.0000 3056 Cdrom - ok
19:08:08.0062 3056 Changer - ok
19:08:08.0203 3056 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\System32\DRIVERS\cmdide.sys
19:08:08.0203 3056 CmdIde - ok
19:08:08.0390 3056 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\System32\DRIVERS\cpqarray.sys
19:08:08.0390 3056 Cpqarray - ok
19:08:08.0468 3056 CSRBC01 - ok
19:08:08.0593 3056 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\System32\DRIVERS\dac2w2k.sys
19:08:08.0593 3056 dac2w2k - ok
19:08:08.0765 3056 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\System32\DRIVERS\dac960nt.sys
19:08:08.0781 3056 dac960nt - ok
19:08:08.0875 3056 DCamUSBSQTECH (100ff3d9e16afb3163bd6f9aaaab7c55) C:\WINDOWS\system32\Drivers\SQcaptur.sys
19:08:08.0875 3056 DCamUSBSQTECH - ok
19:08:09.0046 3056 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
19:08:09.0046 3056 Disk - ok
19:08:09.0140 3056 DLPortIO (1d95d36db805787d54eb50e45ed4af40) C:\WINDOWS\system32\DRIVERS\DLPortIO.SYS
19:08:09.0140 3056 DLPortIO - ok
19:08:09.0328 3056 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
19:08:09.0359 3056 dmboot - ok
19:08:09.0531 3056 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
19:08:09.0546 3056 dmio - ok
19:08:09.0640 3056 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
19:08:09.0640 3056 dmload - ok
19:08:09.0781 3056 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
19:08:09.0796 3056 DMusic - ok
19:08:09.0968 3056 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\System32\DRIVERS\dpti2o.sys
19:08:09.0968 3056 dpti2o - ok
19:08:10.0078 3056 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
19:08:10.0078 3056 drmkaud - ok
19:08:10.0593 3056 dtsoftbus01 (fb38473835476a6fb272215a1d972af9) C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys
19:08:10.0593 3056 dtsoftbus01 - ok
19:08:10.0687 3056 dvd43llh (1fc1eed3ea0c3a0ecf8a95b97e1b4831) C:\WINDOWS\system32\DRIVERS\dvd43llh.sys
19:08:10.0687 3056 dvd43llh - ok
19:08:10.0859 3056 EL90XBC (6e883bf518296a40959131c2304af714) C:\WINDOWS\system32\DRIVERS\el90xbc5.sys
19:08:10.0859 3056 EL90XBC - ok
19:08:10.0968 3056 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
19:08:10.0968 3056 Fastfat - ok
19:08:11.0140 3056 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
19:08:11.0140 3056 Fdc - ok
19:08:11.0218 3056 FilterService (b73ec688c29f81f9da0fcf63682b3ecb) C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys
19:08:11.0218 3056 FilterService - ok
19:08:11.0359 3056 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
19:08:11.0359 3056 Fips - ok
19:08:11.0437 3056 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
19:08:11.0437 3056 Flpydisk - ok
19:08:11.0593 3056 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
19:08:11.0593 3056 FltMgr - ok
19:08:11.0703 3056 fssfltr (e0087225b137e57239ff40f8ae82059b) C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys
19:08:11.0703 3056 fssfltr - ok
19:08:11.0812 3056 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
19:08:11.0812 3056 Fs_Rec - ok
19:08:11.0921 3056 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
19:08:11.0921 3056 Ftdisk - ok
19:08:12.0109 3056 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
19:08:12.0109 3056 GEARAspiWDM - ok
19:08:12.0218 3056 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
19:08:12.0218 3056 Gpc - ok
19:08:12.0375 3056 HidBth (7bd2de4c85eb4241eed57672b16a7d8d) C:\WINDOWS\system32\DRIVERS\hidbth.sys
19:08:12.0375 3056 HidBth - ok
19:08:12.0468 3056 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
19:08:12.0468 3056 HidUsb - ok
19:08:12.0609 3056 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\System32\DRIVERS\hpn.sys
19:08:12.0625 3056 hpn - ok
19:08:12.0718 3056 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
19:08:12.0718 3056 HPZid412 - ok
19:08:12.0875 3056 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
19:08:12.0875 3056 HPZipr12 - ok
19:08:12.0968 3056 HPZius12 (ca990306ed4ef732af9695bff24fc96f) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
19:08:12.0968 3056 HPZius12 - ok
19:08:13.0078 3056 HTCAND32 - ok
19:08:13.0156 3056 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
19:08:13.0187 3056 HTTP - ok
19:08:13.0343 3056 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
19:08:13.0343 3056 i2omgmt - ok
19:08:13.0453 3056 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\System32\DRIVERS\i2omp.sys
19:08:13.0453 3056 i2omp - ok
19:08:13.0593 3056 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
19:08:13.0593 3056 i8042prt - ok
19:08:13.0703 3056 i81x (06b7ef73ba5f302eecc294cdf7e19702) C:\WINDOWS\system32\DRIVERS\i81xnt5.sys
19:08:13.0718 3056 i81x - ok
19:08:13.0859 3056 iAimFP0 (7b5b44efe5eb9dadfb8ee29700885d23) C:\WINDOWS\system32\DRIVERS\wADV01nt.sys
19:08:13.0859 3056 iAimFP0 - ok
19:08:14.0000 3056 iAimFP1 (eb1f6bab6c22ede0ba551b527475f7e9) C:\WINDOWS\system32\DRIVERS\wADV02NT.sys
19:08:14.0000 3056 iAimFP1 - ok
19:08:14.0062 3056 iAimFP2 (03ce989d846c1aa81145cb22fcb86d06) C:\WINDOWS\system32\DRIVERS\wADV05NT.sys
19:08:14.0078 3056 iAimFP2 - ok
19:08:14.0234 3056 iAimFP3 (525849b4469de021d5d61b4db9be3a9d) C:\WINDOWS\system32\DRIVERS\wSiINTxx.sys
19:08:14.0250 3056 iAimFP3 - ok
19:08:14.0343 3056 iAimFP4 (589c2bcdb5bd602bf7b63d210407ef8c) C:\WINDOWS\system32\DRIVERS\wVchNTxx.sys
19:08:14.0343 3056 iAimFP4 - ok
19:08:14.0484 3056 iAimTV0 (d83bdd5c059667a2f647a6be5703a4d2) C:\WINDOWS\system32\DRIVERS\wATV01nt.sys
19:08:14.0484 3056 iAimTV0 - ok
19:08:14.0562 3056 iAimTV1 (ed968d23354daa0d7c621580c012a1f6) C:\WINDOWS\system32\DRIVERS\wATV02NT.sys
19:08:14.0562 3056 iAimTV1 - ok
19:08:14.0640 3056 iAimTV3 (d738273f218a224c1ddac04203f27a84) C:\WINDOWS\system32\DRIVERS\wATV04nt.sys
19:08:14.0640 3056 iAimTV3 - ok
19:08:14.0718 3056 iAimTV4 (0052d118995cbab152daabe6106d1442) C:\WINDOWS\system32\DRIVERS\wCh7xxNT.sys
19:08:14.0718 3056 iAimTV4 - ok
19:08:14.0937 3056 ialm (44b7d5a4f2bd9fe21aea0bb0bace38c4) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
19:08:15.0000 3056 ialm - ok
19:08:15.0140 3056 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
19:08:15.0156 3056 Imapi - ok
19:08:15.0250 3056 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\System32\DRIVERS\ini910u.sys
19:08:15.0250 3056 ini910u - ok
19:08:15.0390 3056 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\System32\DRIVERS\intelide.sys
19:08:15.0390 3056 IntelIde - ok
19:08:15.0468 3056 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
19:08:15.0468 3056 intelppm - ok
19:08:15.0609 3056 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
19:08:15.0609 3056 ip6fw - ok
19:08:15.0718 3056 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
19:08:15.0718 3056 IpFilterDriver - ok
19:08:15.0828 3056 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
19:08:15.0828 3056 IpInIp - ok
19:08:15.0968 3056 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
19:08:15.0984 3056 IpNat - ok
19:08:16.0093 3056 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
19:08:16.0093 3056 IPSec - ok
19:08:16.0234 3056 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
19:08:16.0250 3056 IRENUM - ok
19:08:16.0328 3056 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
19:08:16.0328 3056 isapnp - ok
19:08:16.0468 3056 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
19:08:16.0468 3056 Kbdclass - ok
19:08:16.0546 3056 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
19:08:16.0546 3056 kbdhid - ok
19:08:16.0703 3056 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
19:08:16.0703 3056 kmixer - ok
19:08:16.0843 3056 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
19:08:16.0843 3056 KSecDD - ok
19:08:17.0046 3056 L8042Kbd (0c6e346cde730cf1356dd69ad6e9bc42) C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys
19:08:17.0062 3056 L8042Kbd - ok
19:08:17.0140 3056 L8042mou (8a5993705add14352c9a279fa8338334) C:\WINDOWS\system32\DRIVERS\L8042mou.Sys
19:08:17.0140 3056 L8042mou - ok
19:08:17.0281 3056 lbrtfdc - ok
19:08:17.0343 3056 LHidFilt (7f9c7b28cf1c859e1c42619eea946dc8) C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
19:08:17.0359 3056 LHidFilt - ok
19:08:17.0421 3056 LHidKe (31b582394da3290dff300f10952e9a4d) C:\WINDOWS\system32\DRIVERS\LHidKE.Sys
19:08:17.0421 3056 LHidKe - ok
19:08:17.0562 3056 LHidUsbK (cbd1c6bff70e170cec6e1502e7fcfef6) C:\WINDOWS\system32\Drivers\LHidUsbK.Sys
19:08:17.0578 3056 LHidUsbK - ok
19:08:17.0656 3056 LMouFilt (ab33792a87285344f43b5ce23421bab0) C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys
19:08:17.0656 3056 LMouFilt - ok
19:08:17.0812 3056 LMouKE (9837e55673818ecd8febb47f7f77521a) C:\WINDOWS\system32\DRIVERS\LMouKE.Sys
19:08:17.0828 3056 LMouKE - ok
19:08:17.0906 3056 LUsbFilt (77030525cd86a93f1af34fa9b96d33ce) C:\WINDOWS\system32\Drivers\LUsbFilt.Sys
19:08:17.0937 3056 LUsbFilt - ok
19:08:18.0078 3056 LVPr2Mon (1a7db7a00a4b0d8da24cd691a4547291) C:\WINDOWS\system32\Drivers\LVPr2Mon.sys
19:08:18.0078 3056 LVPr2Mon - ok
19:08:18.0171 3056 LVRS (37072ec9299e825f4335cc554b6fac6a) C:\WINDOWS\system32\DRIVERS\lvrs.sys
19:08:18.0171 3056 LVRS - ok
19:08:18.0328 3056 LVUSBSta (5f987fc1aad215ec2c60cf07719b1cce) C:\WINDOWS\system32\drivers\LVUSBSta.sys
19:08:18.0343 3056 LVUSBSta - ok
19:08:18.0718 3056 LVUVC (a240e42a7402e927a71b6e8aa4629b13) C:\WINDOWS\system32\DRIVERS\lvuvc.sys
19:08:18.0968 3056 LVUVC - ok
19:08:19.0093 3056 Machnm32 (fd65bef5ff8275711d9a56f0b8bb43f1) C:\WINDOWS\system32\Machnm32.sys
19:08:19.0328 3056 Machnm32 - ok
19:08:19.0500 3056 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
19:08:19.0500 3056 mnmdd - ok
19:08:19.0578 3056 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
19:08:19.0578 3056 Modem - ok
19:08:19.0734 3056 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
19:08:19.0734 3056 MODEMCSA - ok
19:08:19.0828 3056 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
19:08:19.0828 3056 Mouclass - ok
19:08:19.0968 3056 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
19:08:19.0968 3056 mouhid - ok
19:08:20.0046 3056 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
19:08:20.0046 3056 MountMgr - ok
19:08:20.0234 3056 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\System32\DRIVERS\mraid35x.sys
19:08:20.0234 3056 mraid35x - ok
19:08:20.0343 3056 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
19:08:20.0343 3056 MRxDAV - ok
19:08:20.0531 3056 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
19:08:20.0578 3056 MRxSmb - ok
19:08:20.0734 3056 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
19:08:20.0734 3056 Msfs - ok
19:08:20.0812 3056 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
19:08:20.0812 3056 MSKSSRV - ok
19:08:20.0953 3056 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
19:08:20.0953 3056 MSPCLOCK - ok
19:08:21.0093 3056 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
19:08:21.0093 3056 MSPQM - ok
19:08:21.0234 3056 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
19:08:21.0250 3056 mssmbios - ok
19:08:21.0328 3056 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
19:08:21.0328 3056 MSTEE - ok
19:08:21.0375 3056 MTK - ok
19:08:21.0453 3056 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
19:08:21.0453 3056 Mup - ok
19:08:21.0609 3056 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
19:08:21.0609 3056 NABTSFEC - ok
19:08:21.0765 3056 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
19:08:21.0765 3056 NDIS - ok
19:08:21.0953 3056 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
19:08:21.0953 3056 NdisIP - ok
19:08:22.0093 3056 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
19:08:22.0109 3056 NdisTapi - ok
19:08:22.0234 3056 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
19:08:22.0234 3056 Ndisuio - ok
19:08:22.0406 3056 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
19:08:22.0406 3056 NdisWan - ok
19:08:22.0484 3056 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
19:08:22.0484 3056 NDProxy - ok
19:08:22.0625 3056 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
19:08:22.0640 3056 NetBIOS - ok
19:08:22.0718 3056 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
19:08:22.0718 3056 NetBT - ok
19:08:22.0875 3056 nmwcd (28e36e677849174c910faaead3e60e9e) C:\WINDOWS\system32\drivers\ccdcmb.sys
19:08:22.0875 3056 nmwcd - ok
19:08:23.0015 3056 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
19:08:23.0015 3056 Npfs - ok
19:08:23.0109 3056 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
19:08:23.0171 3056 Ntfs - ok
19:08:23.0359 3056 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
19:08:23.0359 3056 Null - ok
19:08:23.0500 3056 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
19:08:23.0562 3056 nv - ok
19:08:23.0671 3056 NvNdis - ok
19:08:23.0765 3056 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
19:08:23.0765 3056 NwlnkFlt - ok
19:08:23.0875 3056 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
19:08:23.0875 3056 NwlnkFwd - ok
19:08:23.0968 3056 omci (53d5f1278d9edb21689bbbcecc09108d) C:\WINDOWS\system32\DRIVERS\omci.sys
19:08:23.0984 3056 omci - ok
19:08:24.0125 3056 P3 (c90018bafdc7098619a4a95b046b30f3) C:\WINDOWS\system32\DRIVERS\p3.sys
19:08:24.0125 3056 P3 - ok
19:08:24.0265 3056 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
19:08:24.0281 3056 Parport - ok
19:08:24.0359 3056 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
19:08:24.0359 3056 PartMgr - ok
19:08:24.0546 3056 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
19:08:24.0546 3056 ParVdm - ok
19:08:24.0640 3056 pbfilter (61a5701e3f543861b21bbe0932c4cc03) C:\Program Files\PeerBlock\pbfilter.sys
19:08:24.0640 3056 pbfilter - ok
19:08:24.0765 3056 PCANDIS5 (2f9806b52cb3748b1e49222744b28e3c) C:\WINDOWS\system32\PCANDIS5.SYS
19:08:24.0765 3056 PCANDIS5 - ok
19:08:24.0906 3056 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
19:08:24.0906 3056 pccsmcfd - ok
19:08:25.0000 3056 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
19:08:25.0000 3056 PCI - ok
19:08:25.0125 3056 PCIDump - ok
19:08:25.0203 3056 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
19:08:25.0203 3056 PCIIde - ok
19:08:25.0328 3056 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
19:08:25.0328 3056 Pcmcia - ok
19:08:25.0453 3056 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys
19:08:25.0453 3056 pcouffin - ok
19:08:25.0593 3056 PDCOMP - ok
19:08:25.0640 3056 PDFRAME - ok
19:08:25.0718 3056 PDRELI - ok
19:08:25.0750 3056 PDRFRAME - ok
19:08:25.0828 3056 pepifilter - ok
19:08:25.0906 3056 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\System32\DRIVERS\perc2.sys
19:08:25.0906 3056 perc2 - ok
19:08:26.0015 3056 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\System32\DRIVERS\perc2hib.sys
19:08:26.0015 3056 perc2hib - ok
19:08:26.0140 3056 pfc - ok
19:08:26.0203 3056 PID_PEPI - ok
19:08:26.0343 3056 PORTIO64 - ok
19:08:26.0468 3056 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
19:08:26.0484 3056 PptpMiniport - ok
19:08:26.0640 3056 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
19:08:26.0640 3056 Processor - ok
19:08:26.0718 3056 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
19:08:26.0718 3056 PSched - ok
19:08:26.0875 3056 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
19:08:26.0875 3056 Ptilink - ok
19:08:26.0984 3056 PxHelp20 (0457e25bb122b854e267cf552dcdc370) C:\WINDOWS\system32\DRIVERS\PxHelp20.sys
19:08:26.0984 3056 PxHelp20 - ok
19:08:27.0156 3056 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\System32\DRIVERS\ql1080.sys
19:08:27.0156 3056 ql1080 - ok
19:08:27.0281 3056 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\System32\DRIVERS\ql10wnt.sys
19:08:27.0281 3056 Ql10wnt - ok
19:08:27.0406 3056 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\System32\DRIVERS\ql12160.sys
19:08:27.0406 3056 ql12160 - ok
19:08:27.0578 3056 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\System32\DRIVERS\ql1240.sys
19:08:27.0578 3056 ql1240 - ok
19:08:27.0656 3056 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\System32\DRIVERS\ql1280.sys
19:08:27.0656 3056 ql1280 - ok
19:08:27.0859 3056 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
19:08:27.0859 3056 RasAcd - ok
19:08:27.0984 3056 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
19:08:27.0984 3056 Rasl2tp - ok
19:08:28.0140 3056 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
19:08:28.0156 3056 RasPppoe - ok
19:08:28.0328 3056 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
19:08:28.0328 3056 Raspti - ok
19:08:28.0406 3056 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
19:08:28.0421 3056 Rdbss - ok
19:08:28.0593 3056 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
19:08:28.0593 3056 RDPCDD - ok
19:08:28.0703 3056 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
19:08:28.0703 3056 rdpdr - ok
19:08:28.0859 3056 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
19:08:28.0859 3056 RDPWD - ok
19:08:28.0968 3056 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
19:08:28.0968 3056 redbook - ok
19:08:29.0078 3056 RFCOMM (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys
19:08:29.0093 3056 RFCOMM - ok
19:08:29.0156 3056 RimUsb (f17713d108aca124a139fde877eef68a) C:\WINDOWS\system32\Drivers\RimUsb.sys
19:08:29.0171 3056 RimUsb - ok
19:08:29.0265 3056 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
19:08:29.0281 3056 ROOTMODEM - ok
19:08:29.0359 3056 rspndr (743d7d59767073a617b1dcc6c546f234) C:\WINDOWS\system32\DRIVERS\rspndr.sys
19:08:29.0359 3056 rspndr - ok
19:08:29.0515 3056 s117bus (1f561844318914e7eb6e54673a4cc54c) C:\WINDOWS\system32\DRIVERS\s117bus.sys
19:08:29.0515 3056 s117bus - ok
19:08:29.0609 3056 s117mdfl (ba93eec3cdf6a63b77ae66221aa4f902) C:\WINDOWS\system32\DRIVERS\s117mdfl.sys
19:08:29.0609 3056 s117mdfl - ok
19:08:29.0750 3056 s117mdm (cba12fd8a8ee5b5cdfbbae2381cd6703) C:\WINDOWS\system32\DRIVERS\s117mdm.sys
19:08:29.0750 3056 s117mdm - ok
19:08:29.0937 3056 s117mgmt (bd6483e64b1da17e812b34bcdefd9459) C:\WINDOWS\system32\DRIVERS\s117mgmt.sys
19:08:29.0953 3056 s117mgmt - ok
19:08:30.0062 3056 s117nd5 (c7ca36c3054b4cd47a1f6611b046e2f9) C:\WINDOWS\system32\DRIVERS\s117nd5.sys
19:08:30.0062 3056 s117nd5 - ok
19:08:30.0218 3056 s117obex (e290b3a6b58fb72ca97dd48d64e4fc1c) C:\WINDOWS\system32\DRIVERS\s117obex.sys
19:08:30.0218 3056 s117obex - ok
19:08:30.0312 3056 s117unic (5c4d1ba23c7511ac880e8ba7baa80dba) C:\WINDOWS\system32\DRIVERS\s117unic.sys
19:08:30.0312 3056 s117unic - ok
19:08:30.0390 3056 SABProcEnum - ok
19:08:30.0453 3056 SASDIFSV (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
19:08:30.0453 3056 SASDIFSV - ok
19:08:30.0515 3056 SASKUTIL (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
19:08:30.0515 3056 SASKUTIL - ok
19:08:30.0671 3056 SE27bus (59a9eb4073a39895af314780d0a032fa) C:\WINDOWS\system32\DRIVERS\SE27bus.sys
19:08:30.0671 3056 SE27bus - ok
19:08:30.0750 3056 SE27mdfl (d53e7e53107d1796825540129f8fe89f) C:\WINDOWS\system32\DRIVERS\SE27mdfl.sys
19:08:30.0750 3056 SE27mdfl - ok
19:08:30.0890 3056 SE27mdm (2afa2f65a6e91da5b5070e734769827e) C:\WINDOWS\system32\DRIVERS\SE27mdm.sys
19:08:30.0890 3056 SE27mdm - ok
19:08:31.0046 3056 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
19:08:31.0046 3056 Secdrv - ok
19:08:31.0125 3056 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
19:08:31.0125 3056 serenum - ok
19:08:31.0203 3056 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
19:08:31.0203 3056 Serial - ok
19:08:31.0296 3056 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
19:08:31.0296 3056 Sfloppy - ok
19:08:31.0359 3056 Simbad - ok
19:08:31.0421 3056 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\System32\DRIVERS\sisagp.sys
19:08:31.0421 3056 sisagp - ok
19:08:31.0562 3056 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
19:08:31.0562 3056 SLIP - ok
19:08:31.0750 3056 smwdm (31fd0707c7dbe715234f2823b27214fe) C:\WINDOWS\system32\drivers\smwdm.sys
19:08:31.0828 3056 smwdm - ok
19:08:32.0000 3056 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\System32\DRIVERS\sparrow.sys
19:08:32.0000 3056 Sparrow - ok
19:08:32.0125 3056 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
19:08:32.0140 3056 splitter - ok
19:08:32.0250 3056 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
19:08:32.0250 3056 sr - ok
19:08:32.0406 3056 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
19:08:32.0421 3056 Srv - ok
19:08:32.0515 3056 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
19:08:32.0515 3056 streamip - ok
19:08:32.0656 3056 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
19:08:32.0656 3056 swenum - ok
19:08:32.0734 3056 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
19:08:32.0734 3056 swmidi - ok
19:08:32.0906 3056 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\System32\DRIVERS\symc810.sys
19:08:32.0906 3056 symc810 - ok
19:08:33.0031 3056 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\System32\DRIVERS\symc8xx.sys
19:08:33.0031 3056 symc8xx - ok
19:08:33.0187 3056 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\System32\DRIVERS\sym_hi.sys
19:08:33.0187 3056 sym_hi - ok
19:08:33.0281 3056 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\System32\DRIVERS\sym_u3.sys
19:08:33.0296 3056 sym_u3 - ok
19:08:33.0421 3056 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
19:08:33.0421 3056 sysaudio - ok
19:08:33.0515 3056 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
19:08:33.0531 3056 Tcpip - ok
19:08:33.0671 3056 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
19:08:33.0671 3056 TDPIPE - ok
19:08:33.0765 3056 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
19:08:33.0765 3056 TDTCP - ok
19:08:33.0921 3056 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
19:08:33.0921 3056 TermDD - ok
19:08:34.0093 3056 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\System32\DRIVERS\toside.sys
19:08:34.0093 3056 TosIde - ok
19:08:34.0234 3056 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
19:08:34.0234 3056 Udfs - ok
19:08:34.0390 3056 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\System32\DRIVERS\ultra.sys
19:08:34.0390 3056 ultra - ok
19:08:34.0500 3056 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
19:08:34.0515 3056 Update - ok
19:08:34.0671 3056 USBAAPL (1df89c499bf45d878b87ebd4421d462d) C:\WINDOWS\system32\Drivers\usbaapl.sys
19:08:34.0687 3056 USBAAPL - ok
19:08:34.0765 3056 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
19:08:34.0781 3056 usbaudio - ok
19:08:35.0062 3056 USBCamera - ok
19:08:35.0171 3056 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
19:08:35.0171 3056 usbccgp - ok
19:08:35.0328 3056 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
19:08:35.0328 3056 usbehci - ok
19:08:35.0453 3056 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
19:08:35.0453 3056 usbhub - ok
19:08:35.0609 3056 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
19:08:35.0625 3056 usbprint - ok
19:08:35.0718 3056 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
19:08:35.0718 3056 usbscan - ok
19:08:35.0906 3056 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
19:08:35.0906 3056 USBSTOR - ok
19:08:36.0000 3056 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
19:08:36.0000 3056 usbuhci - ok
19:08:36.0171 3056 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
19:08:36.0171 3056 usbvideo - ok
19:08:36.0296 3056 vad_multi - ok
19:08:36.0421 3056 vaxscsi (92cebc2bc7be2c8d49391b365569f306) C:\WINDOWS\System32\Drivers\vaxscsi.sys
19:08:36.0421 3056 vaxscsi - ok
19:08:36.0562 3056 VComm - ok
19:08:36.0625 3056 VcommMgr - ok
19:08:36.0718 3056 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
19:08:36.0734 3056 VgaSave - ok
19:08:36.0875 3056 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\System32\DRIVERS\viaagp.sys
19:08:36.0875 3056 viaagp - ok
19:08:37.0000 3056 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\System32\DRIVERS\viaide.sys
19:08:37.0015 3056 ViaIde - ok
19:08:37.0140 3056 viamraid - ok
19:08:37.0296 3056 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
19:08:37.0312 3056 VolSnap - ok
19:08:37.0484 3056 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
19:08:37.0500 3056 Wanarp - ok
19:08:37.0562 3056 wanatw - ok
19:08:37.0671 3056 Wdf01000 (bbcfeab7e871cddac2d397ee7fa91fdc) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
19:08:37.0703 3056 Wdf01000 - ok
19:08:37.0843 3056 WDICA - ok
19:08:37.0953 3056 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
19:08:37.0968 3056 wdmaud - ok
19:08:38.0140 3056 WinDriver6 (94e4312d546048bf31604a8b2ad13fc0) C:\WINDOWS\system32\drivers\windrvr6.sys
19:08:38.0156 3056 WinDriver6 - ok
19:08:38.0343 3056 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
19:08:38.0359 3056 WpdUsb - ok
19:08:38.0546 3056 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
19:08:38.0546 3056 WS2IFSL - ok
19:08:38.0656 3056 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
19:08:38.0656 3056 WSTCODEC - ok
19:08:38.0859 3056 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
19:08:38.0859 3056 WudfPf - ok
19:08:39.0031 3056 {6080A529-897E-4629-A488-ABA0C29B635E} (61002db7b6efb5711685b9d79b8e8ce6) C:\WINDOWS\system32\drivers\ialmsbw.sys
19:08:39.0031 3056 {6080A529-897E-4629-A488-ABA0C29B635E} - ok
19:08:39.0250 3056 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} (35ce2baa708ea038ab72359de87bab87) C:\WINDOWS\system32\drivers\ialmkchw.sys
19:08:39.0250 3056 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} - ok
19:08:39.0296 3056 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
19:08:39.0468 3056 \Device\Harddisk0\DR0 - ok
19:08:39.0484 3056 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1
19:08:39.0984 3056 \Device\Harddisk1\DR1 - ok
19:08:40.0015 3056 Boot (0x1200) (a7cdfd43ba1c913a2bdf2ea18680f4d8) \Device\Harddisk0\DR0\Partition0
19:08:40.0015 3056 \Device\Harddisk0\DR0\Partition0 - ok
19:08:40.0046 3056 Boot (0x1200) (95e6f1233b25629be68ef4056d5f0abe) \Device\Harddisk1\DR1\Partition0
19:08:40.0046 3056 \Device\Harddisk1\DR1\Partition0 - ok
19:08:40.0046 3056 ============================================================
19:08:40.0046 3056 Scan finished
19:08:40.0046 3056 ============================================================
19:08:40.0062 3572 Detected object count: 0
19:08:40.0062 3572 Actual detected object count: 0
19:16:24.0453 2700 Deinitialize success

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.02.02.06

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Lee Edgar :: MAINCOMPUTER [administrator]

02/02/2012 19:17:39
mbam-log-2012-02-02 (19-17-39).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 250800
Time elapsed: 14 minute(s), 8 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
I know sometimes we get a little backed up here in the forum and we can't get to all the logs as fast as we wish we could. I appreciate your understanding that we donate our time :)

Malwarebytes is a great tool, and I'm glad you went ahead and ran it. It's one of the tools I encourage users to have on their machines, and one that I recommend you update and run on a regular basis. Though, I'm sorry to hear that it didn't remove all the problems and you are having trouble again already. Since it did find some trojans in the initial run, I think we should go ahead with a more aggressive tool that will look in additional places. Be patient, as we may need to do several steps, but we'll see if we can't get you running better here shortly.


Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click anywhere Combofix's window while it is running. That may cause it to stall. I actually recommend that you do not do ANYTHING else on your computer while it is running as it may cause Combofix not to run properly. (It is not unusual for Combofix to reboot the machine as a part of it's run. Please do not be alarmed if this happens.)
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Currently computer seems fine


here is the log



ComboFix 12-02-03.02 - Lee Edgar 03/02/2012 17:26:49.8.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
.
((((((((((((((((((((((((( Files Created from 2012-01-03 to 2012-02-03 )))))))))))))))))))))))))))))))
.
.
2012-02-01 15:44 . 2012-02-01 15:44 ——– d—–w- C:\epson
2012-01-29 16:27 . 2012-01-29 16:27 ——– d—–w- c:\documents and settings\Lee Edgar\Local Settings\Application Data\LogiShrd
2012-01-29 16:23 . 2009-10-07 08:43 199192 —-a-w- c:\windows\system32\lvci12101110.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-07 15:15 . 2011-08-11 06:19 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-27 17:14 . 2011-12-27 17:14 239168 —-a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-12-18 10:21 . 2003-03-18 20:14 499712 —-a-w- c:\windows\system32\msvcp71.dll
2011-12-18 10:21 . 2003-02-21 04:42 348160 —-a-w- c:\windows\system32\msvcr71.dll
2011-12-10 15:24 . 2009-04-09 21:01 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-28 18:01 . 2010-08-28 16:22 41184 —-a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2009-09-10 18:38 199816 —-a-w- c:\windows\system32\aswBoot.exe
2011-11-28 17:53 . 2011-03-15 20:30 435032 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-28 17:53 . 2009-09-10 18:39 314456 —-a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2009-09-10 18:39 34392 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2009-09-10 18:39 52952 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2009-09-10 18:39 111320 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2011-11-28 17:51 . 2009-09-10 18:39 105176 —-a-w- c:\windows\system32\drivers\aswmon.sys
2011-11-28 17:51 . 2009-09-10 18:39 20568 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-28 17:48 . 2009-09-10 18:39 30808 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2011-11-25 21:57 . 2002-08-29 05:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-11-23 13:25 . 2002-08-29 05:00 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-18 12:35 . 2002-08-29 05:00 60416 —-a-w- c:\windows\system32\packager.exe
2011-11-16 14:21 . 2004-07-26 20:15 354816 —-a-w- c:\windows\system32\winhttp.dll
2011-11-16 14:21 . 2002-08-29 05:00 152064 —-a-w- c:\windows\system32\schannel.dll
2011-11-10 05:54 . 2010-05-15 07:57 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-11-10 03:27 . 2011-02-24 19:14 73728 —-a-w- c:\windows\system32\javacpl.cpl
2000-01-14 14:46 . 2006-09-07 20:58 24576 ——w- c:\program files\Common Files\XCPCMenu.exe
2000-01-14 14:46 . 2006-09-07 20:58 696320 ——w- c:\program files\Common Files\XCMHook.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 —-a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="\Program\" [X]
"1FD8AD20A0FC13D0E02DDB23BA6E0414053DB401._service_run"="c:\documents and settings\Lee Edgar\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" [2012-01-20 1047024]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-11-10 3514176]
"Facebook Update"="c:\documents and settings\Lee Edgar\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" [2011-10-20 137536]
"PrinterShare"="c:\program files\PrinterShare\paConsole.exe" [2011-09-08 1124352]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-04-14 1957888]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-12-18 4616064]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-11-28 3744552]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-12-18 296056]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2003-08-13 28672]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"iKeyWorks"="c:\progra~1\A4Tech\Keyboard\Ikeymain.exe" [2004-08-31 61440]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"pdfFactory Pro Dispatcher v3"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" [2010-03-18 614400]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"WheelMouse"="c:\progra~1\A4Tech\Mouse\Amoumain.exe" [2004-09-01 147456]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
.
c:\documents and settings\Lee Edgar\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ExifLauncher2.lnk - c:\program files\FinePixViewer\QuickDCF2.exe [2010-8-4 303104]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-6-11 450560]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2006-6-11 813584]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-08-11 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 12:28 72208 —-a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^Lee Edgar^Start Menu^Programs^Startup^.jagex_runescape_preferences.jar]
path=c:\documents and settings\Lee Edgar\Start Menu\Programs\Startup\.jagex_runescape_preferences.jar
backup=c:\windows\pss\.jagex_runescape_preferences.jarStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JaGeXDaemon]
2012-02-01 13:23 35298 —-a-w- c:\.jagex_cache_32\jagc.jar
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JagexProperties]
2011-07-10 14:27 29816 —-a-w- c:\.jagex_cache_32\jagd.jar
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe"
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Orange\\Livebox\\RGWREPAIR.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\PrinterShare\\paConsole.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Lee Edgar\\Local Settings\\Application Data\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
"c:\\Program Files\\Logitech\\Vid HD\\Vid.exe"=
"c:\\WINDOWS\\SYSTEM32\\mmc.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16193:TCP"= 16193:TCP:BitComet 16193 TCP
"16193:UDP"= 16193:UDP:BitComet 16193 UDP
"55064:TCP"= 55064:TCP:bitcomet 55064 tcp
"55064:UDP"= 55064:UDP:bitcomet 55064 udp
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R2 Ca533av;Icatch(IV) Video Camera Device;c:\windows\system32\Drivers\Ca533av.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-05-07 136176]
R3 Amps2prt;A4Tech PS/2 Port Mouse Driver;c:\windows\system32\DRIVERS\Amps2prt.sys [2004-08-25 9984]
R3 BTCOMM;BTCOMM;c:\windows\system32\drivers\Btcomm.sys [x]
R3 BTKRNBDG;Bluetooth COM Bridge;c:\windows\system32\DRIVERS\btkrnbdg.sys [x]
R3 CSRBC01;%CSRBC01.SvcDesc%;c:\windows\system32\Drivers\csrbc01.sys [x]
R3 DLPortIO;DriverLINX Port I/O Driver;c:\windows\system32\DRIVERS\DLPortIO.SYS [2000-06-29 3584]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-05-07 136176]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [x]
R3 MTK;Media Technology Kernel Driver;c:\windows\system32\Drivers\mtk.sys [x]
R3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys [2010-11-06 19056]
R3 PORTIO64;PORTIO64;c:\docume~1\LEEEDG~1\LOCALS~1\Temp\PIOAD6.tmp [x]
R3 SecureSrv;SecureSrv; [x]
R3 vad_multi;Windigo Virtual Audio Device (WDM);c:\windows\system32\drivers\vadmulti.sys [x]
R3 vaxscsi;vaxscsi;c:\windows\System32\Drivers\vaxscsi.sys [2006-08-10 223128]
R3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe [2008-04-14 14336]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-12-27 239168]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-08-11 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-08-11 67664]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-19 116608]
S2 aswFsBlk;aswFsBlk; [x]
S2 pdfFactory Pro Dispatcher v3;pdfFactory Pro Dispatcher v3;c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe [2010-03-18 614400]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2006-12-16 47360]
.
.
— Other Services/Drivers In Memory —
.
*Deregistered* - uphcleanhlp
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-03 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-04-26 21:51]
.
2012-02-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
2012-02-02 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-10512063-1881097818-1119676352-1006Core.job
- c:\documents and settings\Lee Edgar\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-10-20 16:42]
.
2012-02-03 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-10512063-1881097818-1119676352-1006UA.job
- c:\documents and settings\Lee Edgar\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-10-20 16:42]
.
2012-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-07 18:38]
.
2012-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-07 18:38]
.
2012-02-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-10512063-1881097818-1119676352-1006Core.job
- c:\documents and settings\Lee Edgar\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-05-18 23:44]
.
2012-02-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-10512063-1881097818-1119676352-1006UA.job
- c:\documents and settings\Lee Edgar\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-05-18 23:44]
.
2012-02-03 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-10512063-1881097818-1119676352-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-01-30 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-10512063-1881097818-1119676352-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-02-02 c:\windows\Tasks\User_Feed_Synchronization-{497F6515-09E8-4C56-A584-629BB37D8D0F}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
IE: Download Link Using Mega Manager… - c:\program files\Megaupload\Mega Manager\mm_file.htm
Trusted Zone: securesuite.co.uk\www
TCP: DhcpNameServer = 192.168.0.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} - hxxps://secure.footprint.net/kingsisle/static/themes/wizard101A/activex/Wizard101GameLauncher.CAB
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-02-03 17:52
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
C:\## aswSnx private storage
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\PORTIO64]
"ImagePath"="\??\c:\docume~1\LEEEDG~1\LOCALS~1\Temp\PIOAD6.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-10512063-1881097818-1119676352-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:2a,d9,db,11,cc,c7,6e,95,52,b5,58,cb,a0,cf,e4,ad,27,de,53,33,93,32,9f,
ab,3a,83,12,94,c7,4b,50,8d,67,ec,61,46,52,f3,d8,a0,97,05,fc,c5,b7,1e,48,5d,\
"??"=hex:56,52,75,73,36,e9,4b,67,3c,6b,47,2a,09,08,ac,8b
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(692)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
- - - - - - - > 'explorer.exe'(1120)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\UPHClean\uphclean.exe
c:\windows\system32\wscntfy.exe
c:\windows\BCMSMMSG.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\SpywareGuard\sgbhp.exe
.
**************************************************************************
.
Completion time: 2012-02-03 18:11:41 - machine was rebooted
ComboFix-quarantined-files.txt 2012-02-03 18:11
.
Pre-Run: 20,924,801,024 bytes free
Post-Run: 21,167,288,320 bytes free
.
- - End Of File - - 391872B11C08B05BC47D618AE76D9E25
Glad to hear things are running better at the moment. Let's get an online scan to make sure there is nothing else we need to address.



This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.

Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked, and the option Scan unwanted applications is checked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.
Glad to hear things are running better. I'll leave the thread open for a few days in case things act up again, but seems like things look good right now.


The following will implement some cleanup procedures as well as reset System Restore points:
  • Click Start > Run
  • Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]

If there are any remaining tools or logs on your desktop you can right-click and delete them.



Great job! Your logs appear to be malware free and you do not appear to be experiencing any malware related problems.
Please follow these simple steps in order to keep your computer malware free and secure:

Visit Microsoft's Windows Update Site Frequently
It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Use and Update your AntiVirus Software
It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall
I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this. Simply using a Firewall in its default configuration can lower your risk greatly.

Use only one antivirus and one firewall on your machine
Having more than one anti-virus program and one firewall on your machine, even if only one is running, can cause conflicts and slowdowns in the performance of the machine.

If you need more information on free anti-virus or firewall options please let me know and I will give you some recommendations.

Make your Internet Explorer more secure
This can be done by following these simple instructions:
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click once on the Security tab
3. Click once on the Internet icon so it becomes highlighted.
4. Click once on the Custom Level button.
5. Change the Download signed ActiveX controls to Prompt
6. Change the Download unsigned ActiveX controls to Disable
7. Change the Initialize and script ActiveX controls not marked as safe to Disable
8. Change the Installation of desktop items to Prompt
9. Change the Launching programs and files in an IFRAME to Prompt
10. Change the Navigate sub-frames across different domains to Prompt
11. When all these settings have been made, click on the OK button.
12. If it prompts you as to whether or not you want to save the settings, press the Yes button.
13. Next press the Apply button and then the OK to exit the Internet Properties page.

Keep your Java, Adobe Reader and Adobe Flash Up to Date
Older versions of these programs can contain security vulnerabilities. It is very important to keep them updated.

Update and Run Malwarebytes Anti-Malware
Scan your computer with this program on a regular basis just as you would an antivirus software making sure you update definitions each time you scan.

To simplify making sure you have the latest version of many of your security programs and applications, you may want to consider:
Secunia's Personal Software Inspector (PSI). It is a free utility that scans your computer for installed applications and checks to see if they have the latest security patches and updates. If it finds any applications with possible security issues, links and/or instructions are provided for the necessariy updates.

Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.

I would suggest you read:
Tony Klein's excellent article: How I got Infected in the First Place
PC Safety and Security–What Do I Need?
How to Prevent Malware

Good luck & Happy surfing!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI