This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Redirect with TDSSKiller = No Internet

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I have used TDSS Killer on my computer and now I cannot access the Internet. I was getting the google redirect when I stumbled upon Kaspersky TDSSKiller. I downloaded Kaspersky TDSS removal tool and it found the malware and I hit "Cure." My computer then rebooted but now I do not get the internet when I open my browser. The icon on my computer shows that I am still connected however. I'd appreciate any help given and am willing to post logs and run sweeps/scans. Thanks to whoever helps with this issue.
Hi learn2beabum and welcome to WhatTheTech forums!
I'm Sunyata and I will be helping you with your computer problems.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts before I post them. This is to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my very best to keep it as short as possible.

Please read the following guidelines which will help to make cleaning your machine easier:

  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • The fixes I will give you are specific to your problem and should only be used for this issue on this machine.
  • Please make sure to carefully read any instructions posted. If you're not sure, please stop and ask!
  • Please stay with this thread until I tell you your machine appears to be clean. Absence of symptoms does not necessarily mean that all malware is gone.
  • PLEASE DO NOT install/uninstall any programs unless asked to.
  • PLEASE DO NOT run any malware scans other than those requested.
  • Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
  • I will reply back shortly with instructions

Note to Vista and Windows 7 users:
  • These tools MUST be run from the executable. (.exe) every time you run them
  • These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator")
Thank You Sunyata!!!

I realized I did not realize the "How to post" section and ran all (3) scans posted below. Please let me know if there are any other scans that may assist you. Thank you again for taking time out of your busy schedule to help on this issue!!!

DDS:

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 11:30:30.46 on Sun 02/12/2012
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_30
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3317.2609 [GMT -8:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\PROGRA~1\NORTON~3\NORTON~1\NPROTECT.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\PROGRA~1\NORTON~3\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\AVG\AVG2012\avgemcx.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Common Files\AOL\1234674321\ee\AOLSoftware.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Dell Support Center\gs_agent\dsc.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Norton SystemWorks Basic Edition\NswUiTray.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Logitech\Logitech Vid\vid.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Documents and Settings\Joan Sciarra\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.aol.com/
uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=5090123
mSearch Bar = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\6.3.2291.0\npwinext.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: @c:\program files\msn toolbar\platform\6.3.2291.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\6.3.2291.0\npwinext.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: {DE9C389F-3316-41A7-809B-AA305ED9D922} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Logitech Vid] "c:\program files\logitech\logitech vid\vid.exe" -bootmode
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb11.exe
mRun: [HPHUPD06] c:\program files\hp\{aac4fc36-8f89-4587-8dd3-ebc57c83374d}\hphupd06.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [HPHmon06] c:\windows\system32\hphmon06.exe
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [HostManager] c:\program files\common files\aol\1234674321\ee\AOLSoftware.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\logitech webcam software\LWS.exe" /hide
mRun: [NSWosCheck] "c:\program files\norton systemworks basic edition\osCheck.exe"
mRun: [NswUiTray] c:\program files\norton systemworks basic edition\NswUiTray.exe
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: []
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\joansc~1\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
IE: &AOL; Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-us\local\search.html
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: {5E638779-1818-4754-A595-EF1C63B87A56} - c:\program files\norton systemworks basic edition\norton cleanup\WCQuick.lnk
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: mswsock.dll
DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://supportcenter.timewarnercable.com/sdccommon/download/tgctlcm.cab
DPF: {445F47D7-E043-4BD6-82EB-7A1BD0EBA773} - hxxp://www.opinionguru.com/CopyGuardIE.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\joansc~1\applic~1\mozilla\firefox\profiles\j5ctwnnv.default\
FF - prefs.js: browser.search.selectedEngine - AOL Search
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com
FF - prefs.js: keyword.URL - hxxp://aolsearch.aol.com/aol/search?invocationType=client_searchbox&query;=
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\coffplgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll
FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
.
—- FIREFOX POLICIES —-
FF - user.js: general.useragent.extra.brc - BRI/1
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-7-11 32592]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-12-25 64512]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2012-2-12 295248]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-5-13 214024]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-12-23 2152152]
R2 NProtectService;Norton UnErase Protection;c:\progra~1\norton~3\norton~1\NPROTECT.EXE [2008-9-25 95600]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-7-11 16720]
S0 13514649;13514649;c:\windows\system32\drivers\09752093.sys –> c:\windows\system32\drivers\09752093.sys [?]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys –> c:\windows\system32\drivers\avgldx86.sys [?]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-1 135664]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-1 135664]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-12-23 15232]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-6-23 34248]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2011-6-12 31125880]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
.
=============== Created Last 30 ================
.
2012-02-12 08:20:44 295248 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2012-02-12 08:16:50 98816 —-a-w- c:\windows\sed.exe
2012-02-12 08:16:50 518144 —-a-w- c:\windows\SWREG.exe
2012-02-12 08:16:50 256000 —-a-w- c:\windows\PEV.exe
2012-02-12 08:16:50 208896 —-a-w- c:\windows\MBR.exe
2012-02-12 08:16:44 ——– d-s—w- C:\ComboFix
2012-02-12 05:19:19 ——– d—–w- C:\TDSSKiller_Quarantine
2012-02-05 17:55:25 0 –sha-w- c:\windows\system32\dds_trash_log.cmd
2012-01-16 00:56:20 ——– d—–w- c:\program files\Spybot - Search & Destroy
2012-01-16 00:56:20 ——– d—–w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2012-01-16 00:22:55 6784 —-a-w- c:\windows\system32\drivers\serscan.sys
2012-01-16 00:22:55 6784 —-a-w- c:\windows\system32\dllcache\serscan.sys
2012-01-16 00:21:44 ——– d—–w- c:\program files\Microsoft
2012-01-16 00:21:37 ——– d—–w- c:\program files\MSN Toolbar
2012-01-16 00:21:18 ——– d—–w- c:\program files\Bing Bar Installer
2012-01-16 00:18:52 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2012-01-16 00:18:52 15104 —-a-w- c:\windows\system32\dllcache\usbscan.sys
2012-01-16 00:18:49 ——– d—–w- c:\docume~1\joansc~1\applic~1\HpUpdate
2012-01-16 00:18:05 527208 ——w- c:\windows\system32\HPDiscoPM5412.dll
2012-01-16 00:17:57 1792872 —-a-w- c:\windows\system32\HPScanMiniDrv_OJ6500_E710nz.dll
2012-01-16 00:17:55 267112 —-a-w- c:\windows\system32\hpinksts5412LM.dll
2012-01-16 00:17:55 232296 —-a-w- c:\windows\system32\hpinksts5412.dll
2012-01-16 00:17:55 213864 —-a-w- c:\windows\system32\hpinkcoi5412.dll
.
==================== Find3M ====================
.
2011-11-25 00:08:05 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-23 13:29:56 1868544 —-a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 11:31:44.28 ===============

HiJackThis:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:56:29 PM, on 2/12/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\PROGRA~1\NORTON~3\NORTON~1\NPROTECT.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\PROGRA~1\NORTON~3\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\AVG\AVG2012\avgemcx.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Common Files\AOL\1234674321\ee\AOLSoftware.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Norton SystemWorks Basic Edition\NswUiTray.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Logitech\Logitech Vid\vid.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Joan Sciarra\Desktop\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=5090123
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=5090123
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: @C:\Program Files\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
O4 - HKLM\..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1234674321\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
O4 - HKLM\..\Run: [NSWosCheck] "C:\Program Files\Norton SystemWorks Basic Edition\osCheck.exe"
O4 - HKLM\..\Run: [NswUiTray] C:\Program Files\Norton SystemWorks Basic Edition\NswUiTray.exe
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\digital imaging\bin\hpqthb08.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: &AOL; Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd; to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks Basic Edition\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks Basic Edition\Norton Cleanup\WCQuick.lnk
O9 - Extra button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://supportcenter.timewarnercable.com/s…oad/tgctlcm.cab
O16 - DPF: {445F47D7-E043-4BD6-82EB-7A1BD0EBA773} (CopyGuardCtrl Class) - http://www.opinionguru.com/CopyGuardIE.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\hpboid.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~3\NORTON~1\NPROTECT.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~3\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe

–
End of file - 12027 bytes

OTL:

OTL logfile created on: 2/12/2012 12:49:02 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Joan Sciarra\Desktop\OTL
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.24 Gb Total Physical Memory | 2.62 Gb Available Physical Memory | 80.79% Memory free
5.08 Gb Paging File | 4.59 Gb Available in Paging File | 90.33% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 596.12 Gb Total Space | 494.69 Gb Free Space | 82.99% Space Free | Partition Type: NTFS
Drive I: | 1.86 Gb Total Space | 1.77 Gb Free Space | 95.25% Space Free | Partition Type: FAT

Computer Name: FAMILYROOM | User Name: Joan Sciarra | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Joan Sciarra\Desktop\OTL\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\Logitech\Logitech Vid\Vid.exe (Logitech Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\aol\1234674321\ee\aolsoftware.exe (AOL LLC)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Norton SystemWorks Basic Edition\Norton Utilities\Speed Disk\NOPDB.exe (Symantec Corporation)
PRC - C:\Program Files\Norton SystemWorks Basic Edition\Norton Utilities\NPROTECT.EXE (Symantec Corporation)
PRC - C:\Program Files\Norton SystemWorks Basic Edition\NswUiTray.exe (Symantec Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\aol\acs\AOLacsd.exe (AOL LLC)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Lavasoft\Ad-Aware\VipreBridge.dll ()
MOD - C:\Program Files\Lavasoft\Ad-Aware\RPAPI.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Defs\thorax.aaw ()
MOD - C:\Program Files\Lavasoft\Ad-Aware\Vipre.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Defs\Extended\libMachoUniv.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Defs\Extended\libBase64.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\70cacc44f0b4257f6037eda7a59a0aeb\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\af39f6e644af02873b9bae319f2bfb13\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_a2788732\mscorlib.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_bdb80c7a\system.drawing.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_5588a9a2\system.xml.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_86a2251c\system.windows.forms.dll ()
MOD - c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_31bfa973\system.dll ()
MOD - c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll ()
MOD - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files\Logitech\Logitech Vid\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Logitech\Logitech Vid\plugins\imageformats\qico4.dll ()
MOD - C:\Program Files\Logitech\Logitech Vid\plugins\imageformats\qgif4.dll ()
MOD - C:\Program Files\Logitech\Logitech Vid\SDL.dll ()
MOD - C:\Program Files\Logitech\Logitech Vid\qtxml4.dll ()
MOD - C:\Program Files\Logitech\Logitech Vid\QtWebKit4.dll ()
MOD - C:\Program Files\Logitech\Logitech Vid\qtsql4.dll ()
MOD - C:\Program Files\Logitech\Logitech Vid\QtNetwork4.dll ()
MOD - C:\Program Files\Logitech\Logitech Vid\QtOpenGL4.dll ()
MOD - C:\Program Files\Logitech\Logitech Vid\QtGui4.dll ()
MOD - C:\Program Files\Logitech\Logitech Vid\QtCore4.dll ()
MOD - C:\Program Files\Logitech\Logitech Vid\phonon4.dll ()
MOD - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
MOD - C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
MOD - c:\windows\assembly\gac\hpqisrtb\4.0.0.0__a53cf5803f4c3827\hpqisrtb.dll ()
MOD - c:\windows\assembly\gac\hpqcprsc\3.0.0.0__a53cf5803f4c3827\hpqcprsc.dll ()
MOD - c:\windows\assembly\gac\hpqcprsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqcprsc.resources.dll ()
MOD - c:\windows\assembly\gac\hpqietpz\3.0.0.0__a53cf5803f4c3827\hpqietpz.dll ()
MOD - c:\windows\assembly\gac\hpqptfnd\3.0.0.0__a53cf5803f4c3827\hpqptfnd.dll ()
MOD - c:\windows\assembly\gac\lead.wrapper\13.0.0.66__9cf889f53ea9b907\lead.wrapper.dll ()
MOD - c:\windows\assembly\gac\lead.drawing\13.0.0.66__9cf889f53ea9b907\lead.drawing.dll ()
MOD - c:\windows\assembly\gac\lead\13.0.0.66__9cf889f53ea9b907\lead.dll ()
MOD - c:\windows\assembly\gac\lead.windows.forms\13.0.0.66__9cf889f53ea9b907\lead.windows.forms.dll ()
MOD - c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll ()
MOD - c:\windows\assembly\gac\interop.hpqimgr\1.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll ()
MOD - c:\windows\assembly\gac\hpqtray\3.0.0.0__a53cf5803f4c3827\hpqtray.dll ()
MOD - c:\windows\assembly\gac\hpqtray.resources\3.0.0.0_en_a53cf5803f4c3827\hpqtray.resources.dll ()
MOD - c:\windows\assembly\gac\hpqimgrc\3.0.0.0__a53cf5803f4c3827\hpqimgrc.dll ()
MOD - c:\windows\assembly\gac\hpqgskin\3.0.0.0__a53cf5803f4c3827\hpqgskin.dll ()
MOD - c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll ()
MOD - c:\windows\assembly\gac\hpqfmrsc\3.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll ()
MOD - c:\windows\assembly\gac\hpqiface\3.0.0.0__a53cf5803f4c3827\hpqiface.dll ()
MOD - c:\windows\assembly\gac\hpqfmrsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqfmrsc.resources.dll ()
MOD - c:\windows\assembly\gac\hpqcmctl\3.0.0.0__a53cf5803f4c3827\hpqcmctl.dll ()
MOD - c:\windows\assembly\gac\hpqccrsc\3.0.0.0__a53cf5803f4c3827\hpqccrsc.dll ()
MOD - c:\windows\assembly\gac\hpqutils\3.0.0.0__a53cf5803f4c3827\hpqutils.dll ()
MOD - c:\windows\assembly\gac\hpqgldlg\3.0.0.0__a53cf5803f4c3827\hpqgldlg.dll ()
MOD - c:\windows\assembly\gac\hpqasset\3.0.0.0__a53cf5803f4c3827\hpqasset.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll ()
MOD - c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll ()
MOD - c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll ()
MOD - c:\windows\assembly\gac\accessibility\1.0.5000.0__b03f5f7f11d50a3a\accessibility.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (SupportSoft RemoteAssist) – C:\Program Files\Common Files\supportsoft\bin\ssrc.exe (SupportSoft, Inc.)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (sprtsvc_DellSupportCenter) SupportSoft Sprocket Service (DellSupportCenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (Speed Disk service) – C:\Program Files\Norton SystemWorks Basic Edition\Norton Utilities\Speed Disk\NOPDB.exe (Symantec Corporation)
SRV - (NProtectService) – C:\Program Files\Norton SystemWorks Basic Edition\Norton Utilities\NPROTECT.EXE (Symantec Corporation)
SRV - (pinger) – C:\WINDOWS\system32\lxda_device.dll (Oak Technology Inc.)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (HP Port Resolver) – C:\WINDOWS\system32\hpbpro.exe (Hewlett-Packard Company)
SRV - (HP Status Server) – C:\WINDOWS\system32\hpboid.exe (Hewlett-Packard Company)


========== Driver Services (SafeList) ==========

DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (FilterService) – C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) QuickCam Communicate Deluxe(UVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (SDdriver) – C:\WINDOWS\system32\drivers\SdDriver.SYS (Symantec Corporation)
DRV - (NPDriver) – C:\WINDOWS\system32\drivers\NPDRIVER.SYS (Symantec Corporation)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (lvpopflt) – C:\WINDOWS\system32\drivers\lvpopflt.sys (Logitech Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=5090123
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=5090123


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=5090123
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=5090123
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=5090123
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=5090123
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1674639757-3571052794-2677517888-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=5090123
IE - HKU\S-1-5-21-1674639757-3571052794-2677517888-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/hws/sb/dell-usuk/en/…html?channel=us
IE - HKU\S-1-5-21-1674639757-3571052794-2677517888-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com/hws/sb/dell-usuk/en/…html?channel=us
IE - HKU\S-1-5-21-1674639757-3571052794-2677517888-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/
IE - HKU\S-1-5-21-1674639757-3571052794-2677517888-1007\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-1674639757-3571052794-2677517888-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "AOL Search"
FF - prefs.js..browser.startup.homepage: "http://www.aol.com"
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3290
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://aolsearch.aol.com/aol/search?invocationType=client_searchbox&query;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/01/31 16:13:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2012/01/15 16:21:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2012/01/15 16:21:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/28 20:34:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/28 20:13:59 | 000,000,000 | —D | M]

[2009/01/31 14:57:51 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Joan Sciarra\Application Data\Mozilla\Extensions
[2011/02/12 15:53:08 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Joan Sciarra\Application Data\Mozilla\Firefox\Profiles\j5ctwnnv.default\extensions
[2010/06/27 18:34:09 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Joan Sciarra\Application Data\Mozilla\Firefox\Profiles\j5ctwnnv.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/02/04 11:57:59 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/02/04 11:58:00 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
[2012/01/31 16:13:38 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
[2011/01/28 13:55:02 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/12/20 23:24:52 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/11/10 05:54:13 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/12/20 20:30:41 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/20 20:30:41 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

Hosts file not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - No CLSID value found.
O3 - HKU\S-1-5-21-1674639757-3571052794-2677517888-1007\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-1674639757-3571052794-2677517888-1007\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-21-1674639757-3571052794-2677517888-1007\..\Toolbar\WebBrowser: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\aol\1234674321\ee\aolsoftware.exe (AOL LLC)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe (HP)
O4 - HKLM..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe (Hewlett-Packard)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [NSWosCheck] C:\Program Files\Norton SystemWorks Basic Edition\osCheck.exe (Symantec Corporation)
O4 - HKLM..\Run: [NswUiTray] C:\Program Files\Norton SystemWorks Basic Edition\NswUiTray.exe (Symantec Corporation)
O4 - HKU\S-1-5-21-1674639757-3571052794-2677517888-1007..\Run: [Logitech Vid] C:\Program Files\Logitech\Logitech Vid\vid.exe (Logitech Inc.)
O4 - HKU\S-1-5-21-1674639757-3571052794-2677517888-1007..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" File not found
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\digital imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1674639757-3571052794-2677517888-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1674639757-3571052794-2677517888-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: &AOL; Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html File not found
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks Basic Edition\Norton Cleanup\WCQuick.lnk ()
O9 - Extra 'Tools' menuitem : Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks Basic Edition\Norton Cleanup\WCQuick.lnk ()
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - mswsock.dll File not found
O15 - HKU\S-1-5-21-1674639757-3571052794-2677517888-1007\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKU\S-1-5-21-1674639757-3571052794-2677517888-1007\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\S-1-5-21-1674639757-3571052794-2677517888-1007\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} https://supportcenter.timewarnercable.com/s…oad/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {445F47D7-E043-4BD6-82EB-7A1BD0EBA773} http://www.opinionguru.com/CopyGuardIE.cab (CopyGuardCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 14:15:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: pinger - C:\WINDOWS\system32\lxda_device.dll (Oak Technology Inc.)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/02/12 12:42:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Joan Sciarra\Desktop\HiJackThis
[2012/02/12 12:42:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Joan Sciarra\Desktop\OTL
[2012/02/12 00:20:44 | 000,295,248 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2012/02/12 00:16:50 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2012/02/12 00:16:50 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2012/02/12 00:16:50 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2012/02/12 00:16:50 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2012/02/12 00:16:44 | 000,000,000 | –SD | C] – C:\ComboFix
[2012/02/12 00:16:06 | 000,000,000 | R–D | C] – C:\Documents and Settings\Joan Sciarra\Start Menu\Programs\Administrative Tools
[2012/02/11 23:51:16 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2012/02/11 23:49:22 | 000,000,000 | —D | C] – C:\Qoobox
[2012/02/11 23:22:53 | 000,025,471 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv10nt.sys
[2012/02/11 23:22:53 | 000,022,271 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\watv06nt.sys
[2012/02/11 23:22:52 | 000,011,935 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv11nt.sys
[2012/02/11 23:22:52 | 000,011,871 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv09nt.sys
[2012/02/11 23:22:52 | 000,011,807 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv07nt.sys
[2012/02/11 23:22:52 | 000,011,295 | —- | C] (Intel® Corporation) – C:\WINDOWS\System32\dllcache\wadv08nt.sys
[2012/02/11 23:22:51 | 000,404,990 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slntamr.sys
[2012/02/11 23:22:51 | 000,129,535 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slnt7554.sys
[2012/02/11 23:22:51 | 000,095,424 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slnthal.sys
[2012/02/11 23:22:51 | 000,013,776 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\recagent.sys
[2012/02/11 23:22:51 | 000,013,240 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\slwdmsup.sys
[2012/02/11 23:22:50 | 001,309,184 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\mtlstrm.sys
[2012/02/11 23:22:50 | 000,180,360 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\ntmtlfax.sys
[2012/02/11 23:22:50 | 000,126,686 | —- | C] (Smart Link) – C:\WINDOWS\System32\dllcache\mtlmnt5.sys
[2012/02/11 23:22:50 | 000,034,735 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1xsxx.sys
[2012/02/11 23:22:49 | 000,063,663 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1rvxx.sys
[2012/02/11 23:22:49 | 000,036,463 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1tuxx.sys
[2012/02/11 23:22:49 | 000,029,455 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1xbxx.sys
[2012/02/11 23:22:49 | 000,026,367 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1snxx.sys
[2012/02/11 23:22:49 | 000,021,343 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1ttxx.sys
[2012/02/11 23:22:48 | 000,056,623 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1btxx.sys
[2012/02/11 23:22:48 | 000,030,671 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1raxx.sys
[2012/02/11 23:22:48 | 000,012,047 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1pdxx.sys
[2012/02/11 23:22:48 | 000,011,615 | —- | C] (ATI Technologies Inc.) – C:\WINDOWS\System32\dllcache\ati1mdxx.sys
[2012/02/11 21:19:19 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2012/02/04 11:57:56 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/02/04 11:57:56 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/02/04 11:57:56 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/01/15 17:36:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Lavasoft
[2012/01/15 16:56:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2012/01/15 16:56:20 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2012/01/15 16:56:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2012/01/15 16:22:55 | 000,006,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\serscan.sys
[2012/01/15 16:21:44 | 000,000,000 | —D | C] – C:\Program Files\Microsoft
[2012/01/15 16:21:37 | 000,000,000 | —D | C] – C:\Program Files\MSN Toolbar
[2012/01/15 16:21:18 | 000,000,000 | —D | C] – C:\Program Files\Bing Bar Installer
[2012/01/15 16:18:52 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2012/01/15 16:18:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Joan Sciarra\Application Data\HpUpdate
[2012/01/15 16:18:05 | 000,527,208 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\HPDiscoPM5412.dll
[2012/01/15 16:17:57 | 001,792,872 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\HPScanMiniDrv_OJ6500_E710nz.dll
[2012/01/15 16:17:55 | 000,267,112 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hpinksts5412LM.dll
[2012/01/15 16:17:55 | 000,232,296 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hpinksts5412.dll
[2012/01/15 16:17:55 | 000,213,864 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\System32\hpinkcoi5412.dll
[2012/01/15 16:16:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\HP
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/02/12 12:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At26.job
[2012/02/12 12:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At25.job
[2012/02/12 12:23:10 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/12 12:23:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/12 11:29:30 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/02/12 11:29:13 | 000,000,486 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/02/12 11:29:01 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At24.job
[2012/02/12 11:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At23.job
[2012/02/12 11:28:56 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/02/12 11:28:55 | 3478,306,816 | -HS- | M] () – C:\hiberfil.sys
[2012/02/12 01:05:06 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\rp_stats.dat
[2012/02/12 01:05:06 | 000,000,044 | —- | M] () – C:\WINDOWS\System32\rp_rules.dat
[2012/02/12 00:59:22 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2012/02/12 00:59:19 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\logiflt.iad
[2012/02/11 23:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At48.job
[2012/02/11 23:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At47.job
[2012/02/11 20:40:09 | 000,000,460 | —- | M] () – C:\WINDOWS\tasks\At50.job
[2012/02/11 20:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At42.job
[2012/02/11 20:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At41.job
[2012/02/11 19:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At40.job
[2012/02/11 19:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At39.job
[2012/02/11 18:51:58 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/02/11 18:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At38.job
[2012/02/11 18:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At37.job
[2012/02/11 17:34:01 | 000,000,336 | —- | M] () – C:\WINDOWS\tasks\HP Usg Daily FY04.job
[2012/02/11 17:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At36.job
[2012/02/11 17:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At35.job
[2012/02/11 17:28:59 | 088,735,362 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/02/11 16:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At34.job
[2012/02/11 16:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At33.job
[2012/02/11 16:21:13 | 000,000,460 | —- | M] () – C:\WINDOWS\tasks\At51.job
[2012/02/11 15:34:44 | 000,000,000 | -HS- | M] () – C:\WINDOWS\System32\dds_trash_log.cmd
[2012/02/11 10:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At22.job
[2012/02/11 10:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At21.job
[2012/02/11 10:10:14 | 000,000,460 | —- | M] () – C:\WINDOWS\tasks\At49.job
[2012/02/11 09:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At20.job
[2012/02/11 09:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At19.job
[2012/02/10 21:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At44.job
[2012/02/10 21:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At43.job
[2012/02/10 15:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At32.job
[2012/02/10 15:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At31.job
[2012/02/10 14:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At30.job
[2012/02/10 14:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At29.job
[2012/02/10 14:00:47 | 000,000,460 | —- | M] () – C:\WINDOWS\tasks\At52.job
[2012/02/10 13:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At28.job
[2012/02/10 13:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At27.job
[2012/02/09 08:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At18.job
[2012/02/09 08:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At17.job
[2012/02/09 07:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At16.job
[2012/02/09 07:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At15.job
[2012/02/08 22:29:01 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At46.job
[2012/02/08 22:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At45.job
[2012/02/08 17:38:59 | 000,135,671 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/02/04 06:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At14.job
[2012/02/04 06:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At13.job
[2012/02/04 05:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At12.job
[2012/02/04 05:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At11.job
[2012/02/04 04:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At10.job
[2012/02/04 04:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At9.job
[2012/02/04 03:29:01 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At8.job
[2012/02/04 03:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At7.job
[2012/02/04 03:00:00 | 000,000,442 | —- | M] () – C:\WINDOWS\tasks\Norton Internet Security - Patrick Sciarra - Full System Scan.job
[2012/02/04 02:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At6.job
[2012/02/04 02:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At5.job
[2012/02/04 01:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2012/02/04 01:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2012/02/04 00:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2012/02/04 00:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2012/02/02 22:23:00 | 000,000,461 | —- | M] () – C:\Documents and Settings\Joan Sciarra\Desktop\Shortcut to DSCI1189.lnk
[2012/02/01 06:50:28 | 000,000,000 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Scan (Weekly Scan).job
[2012/01/30 12:00:00 | 000,000,340 | —- | M] () – C:\WINDOWS\tasks\Norton SystemWorks One Button Checkup.job
[2012/01/20 15:16:51 | 000,433,398 | —- | M] () – C:\Documents and Settings\Joan Sciarra\My Documents\Lil_HeirloomShower_Wishes_BrownOrange.pdf
[2012/01/15 17:37:01 | 000,000,797 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2012/01/15 16:24:55 | 000,000,666 | —- | M] () – C:\WINDOWS\tasks\hpwebreg_CN1AA3339605JW.job
[2012/01/15 16:18:03 | 000,001,957 | —- | M] () – C:\Documents and Settings\All Users\Desktop\HP Officejet 6500 E710n-z.lnk
[2012/01/15 16:18:01 | 000,000,920 | —- | M] () – C:\Documents and Settings\All Users\Desktop\HP Officejet 6500 E710n-z Scan.lnk
[2012/01/15 16:18:00 | 000,001,695 | —- | M] () – C:\Documents and Settings\All Users\Desktop\HP ePrintCenter - HP Officejet 6500 E710n-z.lnk
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/02/12 00:16:50 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/02/12 00:16:50 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/02/12 00:16:50 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/02/12 00:16:50 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/02/12 00:16:50 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/02/05 09:55:25 | 000,000,000 | -HS- | C] () – C:\WINDOWS\System32\dds_trash_log.cmd
[2012/02/02 22:23:17 | 000,000,461 | —- | C] () – C:\Documents and Settings\Joan Sciarra\Desktop\Shortcut to DSCI1189.lnk
[2012/01/21 20:00:28 | 000,000,000 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Scan (Weekly Scan).job
[2012/01/20 15:16:51 | 000,433,398 | —- | C] () – C:\Documents and Settings\Joan Sciarra\My Documents\Lil_HeirloomShower_Wishes_BrownOrange.pdf
[2012/01/15 17:37:01 | 000,000,797 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2012/01/15 16:24:54 | 000,000,666 | —- | C] () – C:\WINDOWS\tasks\hpwebreg_CN1AA3339605JW.job
[2012/01/15 16:21:53 | 000,001,077 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Default Manager.lnk
[2012/01/15 16:21:16 | 000,000,460 | —- | C] () – C:\WINDOWS\tasks\At52.job
[2012/01/15 16:21:16 | 000,000,460 | —- | C] () – C:\WINDOWS\tasks\At51.job
[2012/01/15 16:21:16 | 000,000,460 | —- | C] () – C:\WINDOWS\tasks\At50.job
[2012/01/15 16:21:16 | 000,000,460 | —- | C] () – C:\WINDOWS\tasks\At49.job
[2012/01/15 16:19:34 | 000,000,661 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\I.R.I.S. OCR Registration.lnk
[2012/01/15 16:18:03 | 000,001,957 | —- | C] () – C:\Documents and Settings\All Users\Desktop\HP Officejet 6500 E710n-z.lnk
[2012/01/15 16:18:01 | 000,000,920 | —- | C] () – C:\Documents and Settings\All Users\Desktop\HP Officejet 6500 E710n-z Scan.lnk
[2012/01/15 16:18:00 | 000,001,695 | —- | C] () – C:\Documents and Settings\All Users\Desktop\HP ePrintCenter - HP Officejet 6500 E710n-z.lnk
[2011/12/31 14:36:23 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/22 20:56:39 | 000,017,002 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\o4180vg17s40f0607sq75oakprp8h8ktxb58ch76jr3yh
[2011/12/17 15:33:38 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\Sfu2OE.com.b
[2011/12/16 15:08:32 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\I8knGK4T.dat
[2011/12/16 14:34:24 | 000,014,514 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\t3kq45l3wr8uuf
[2011/12/07 12:40:28 | 000,000,062 | —- | C] () – C:\Documents and Settings\All Users\Application Data\SgsD7yoLQGcUrt.lic
[2011/12/07 12:21:03 | 000,000,296 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~SgsD7yoLQGcUrt
[2011/12/07 12:21:03 | 000,000,184 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~SgsD7yoLQGcUrtr
[2011/12/07 12:21:00 | 000,000,520 | —- | C] () – C:\Documents and Settings\All Users\Application Data\SgsD7yoLQGcUrt
[2011/05/19 16:40:15 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\rp_stats.dat
[2011/05/19 16:40:15 | 000,000,044 | —- | C] () – C:\WINDOWS\System32\rp_rules.dat
[2010/10/27 15:39:08 | 000,001,940 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/08/13 11:21:59 | 000,000,612 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2010/08/09 15:19:06 | 000,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2009/08/16 18:55:51 | 000,000,056 | —- | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 14:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/07/12 09:55:19 | 000,082,289 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2009/07/03 19:46:45 | 000,094,264 | —- | C] () – C:\WINDOWS\HPHins03.dat.temp
[2009/07/03 19:46:45 | 000,002,655 | —- | C] () – C:\WINDOWS\hphmdl03.dat.temp
[2009/05/08 09:13:04 | 000,013,584 | —- | C] () – C:\WINDOWS\System32\drivers\iKeyLFT2.dll
[2009/04/30 15:00:12 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2009/03/15 15:54:20 | 000,004,608 | —- | C] () – C:\Documents and Settings\Joan Sciarra\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/14 10:21:55 | 000,000,004 | —- | C] () – C:\WINDOWS\msoffice.ini
[2009/01/31 14:13:08 | 000,000,135 | —- | C] () – C:\Documents and Settings\Joan Sciarra\Local Settings\Application Data\fusioncache.dat
[2009/01/31 10:24:50 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/01/31 09:30:42 | 000,094,264 | —- | C] () – C:\WINDOWS\HPHins03.dat
[2009/01/31 09:30:42 | 000,002,655 | —- | C] () – C:\WINDOWS\hphmdl03.dat
[2009/01/22 19:38:37 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/01/22 18:59:30 | 000,876,544 | —- | C] () – C:\WINDOWS\System32\TEACico2.dll
[2009/01/22 18:59:26 | 000,077,824 | —- | C] () – C:\WINDOWS\setpwr32.exe
[2009/01/22 18:59:21 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4820.dll
[2009/01/22 18:57:32 | 000,001,119 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2004/08/11 14:24:19 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/11 14:19:30 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/08/11 14:12:14 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/08/11 14:11:31 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2004/08/11 14:07:24 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/08/11 14:06:43 | 000,356,952 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/11 14:00:30 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/11 14:00:28 | 000,446,136 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/11 14:00:28 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/11 14:00:28 | 000,073,216 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/11 14:00:28 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/11 14:00:27 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/11 14:00:26 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/11 14:00:24 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2004/08/11 14:00:19 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/11 14:00:19 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/11 14:00:12 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/11 14:00:04 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/06/06 20:32:52 | 000,009,505 | —- | C] () – C:\WINDOWS\System32\hphmon06.dat

========== LOP Check ==========

[2011/12/23 16:29:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/09/04 14:04:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2012/02/11 17:29:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2009/01/22 19:36:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC-Doctor
[2009/01/22 19:36:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCDr
[2009/01/22 19:36:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2009/01/22 19:34:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2011/09/04 22:16:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Janet Sciarra\Application Data\AVG2012
[2011/12/28 20:24:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Janet Sciarra\Application Data\Viewpoint
[2011/09/04 14:05:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Joan Sciarra\Application Data\AVG2012
[2010/06/02 16:00:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Joan Sciarra\Application Data\MyPublisher
[2009/02/02 17:38:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Joan Sciarra\Application Data\Viewpoint
[2011/09/05 08:57:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Patrick Sciarra\Application Data\AVG2012
[2011/12/25 09:57:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Patrick Sciarra\Application Data\Qupyirm
[2011/12/22 21:02:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Patrick Sciarra\Application Data\Seih
[2011/11/24 16:14:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Patrick Sciarra\Application Data\TightVNC
[2009/02/03 22:29:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Patrick Sciarra\Application Data\Viewpoint
[2012/02/01 06:50:28 | 000,000,000 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Scan (Weekly Scan).job
[2012/02/12 11:29:13 | 000,000,486 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2012/02/04 00:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At1.job
[2012/02/04 04:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At10.job
[2012/02/04 05:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At11.job
[2012/02/04 05:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At12.job
[2012/02/04 06:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At13.job
[2012/02/04 06:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At14.job
[2012/02/09 07:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At15.job
[2012/02/09 07:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At16.job
[2012/02/09 08:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At17.job
[2012/02/09 08:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At18.job
[2012/02/11 09:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At19.job
[2012/02/04 00:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At2.job
[2012/02/11 09:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At20.job
[2012/02/11 10:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At21.job
[2012/02/11 10:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At22.job
[2012/02/12 11:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At23.job
[2012/02/12 11:29:01 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At24.job
[2012/02/12 12:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At25.job
[2012/02/12 12:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At26.job
[2012/02/10 13:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At27.job
[2012/02/10 13:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At28.job
[2012/02/10 14:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At29.job
[2012/02/04 01:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At3.job
[2012/02/10 14:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At30.job
[2012/02/10 15:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At31.job
[2012/02/10 15:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At32.job
[2012/02/11 16:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At33.job
[2012/02/11 16:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At34.job
[2012/02/11 17:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At35.job
[2012/02/11 17:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At36.job
[2012/02/11 18:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At37.job
[2012/02/11 18:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At38.job
[2012/02/11 19:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At39.job
[2012/02/04 01:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At4.job
[2012/02/11 19:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At40.job
[2012/02/11 20:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At41.job
[2012/02/11 20:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At42.job
[2012/02/10 21:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At43.job
[2012/02/10 21:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At44.job
[2012/02/08 22:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At45.job
[2012/02/08 22:29:01 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At46.job
[2012/02/11 23:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At47.job
[2012/02/11 23:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At48.job
[2012/02/11 10:10:14 | 000,000,460 | —- | M] () – C:\WINDOWS\Tasks\At49.job
[2012/02/04 02:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At5.job
[2012/02/11 20:40:09 | 000,000,460 | —- | M] () – C:\WINDOWS\Tasks\At50.job
[2012/02/11 16:21:13 | 000,000,460 | —- | M] () – C:\WINDOWS\Tasks\At51.job
[2012/02/10 14:00:47 | 000,000,460 | —- | M] () – C:\WINDOWS\Tasks\At52.job
[2012/02/04 02:29:00 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At6.job
[2012/02/04 03:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At7.job
[2012/02/04 03:29:01 | 000,000,348 | —- | M] () – C:\WINDOWS\Tasks\At8.job
[2012/02/04 04:29:00 | 000,000,346 | —- | M] () – C:\WINDOWS\Tasks\At9.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2012/01/15 16:26:35 | 000,025,478 | —- | M] () – C:\aaw7boot.log
[2004/08/11 14:15:00 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/01/31 08:01:03 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2004/08/11 14:15:00 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/01/22 19:01:10 | 000,007,907 | R— | M] () – C:\dell.sdr
[2012/02/12 11:28:55 | 3478,306,816 | -HS- | M] () – C:\hiberfil.sys
[2003/12/08 13:15:56 | 000,028,672 | R— | M] ( ) – C:\hpqimgrc.resources.dll
[2009/02/01 12:13:15 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2011/12/28 20:17:42 | 000,000,000 | —- | M] () – C:\install.rdf
[2004/08/11 14:15:00 | 000,000,000 | —- | M] () – C:\IO.SYS
[2004/08/11 14:15:00 | 000,000,000 | —- | M] () – C:\MSDOS.SYS
[2004/08/04 02:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/06/04 06:38:06 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/02/12 11:28:54 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2012/01/15 16:50:00 | 000,062,160 | —- | M] () – C:\TDSSKiller.2.7.1.0_15.01.2012_16.49.09_log.txt
[2012/02/11 21:22:01 | 000,063,708 | —- | M] () – C:\TDSSKiller.2.7.11.0_11.02.2012_21.18.53_log.txt
[2012/02/11 21:22:22 | 000,063,126 | —- | M] () – C:\TDSSKiller.2.7.11.0_11.02.2012_21.22.03_log.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/11 14:14:22 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 04:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 16:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 02:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2004/08/11 14:06:14 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2004/08/11 14:06:14 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2004/08/11 14:06:14 | 000,876,544 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/06/04 06:41:05 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/01/31 14:13:04 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Joan Sciarra\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/11 14:20:42 | 000,000,079 | —- | M] () – C:\Documents and Settings\Joan Sciarra\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/09/04 13:53:06 | 003,894,928 | —- | M] (AVG Technologies) – C:\Documents and Settings\Joan Sciarra\Desktop\avg_free_stb_all_2012_1796_cnet.exe
[2010/06/02 16:00:40 | 014,559,600 | —- | M] (MyPublisher) – C:\Documents and Settings\Joan Sciarra\Desktop\MyPublishersetup-USD-en-US-mypublisherDownload.exe
[2010/06/02 15:59:21 | 000,818,761 | —- | M] (MyPublisher) – C:\Documents and Settings\Joan Sciarra\Desktop\MyPublishersetup-USD-en-US.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-15 11:07:01

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB38549$] -> Error: Cannot create file handle -> Unknown point type

< End of report >

OTL Extras:

OTL Extras logfile created on: 2/12/2012 12:49:02 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Joan Sciarra\Desktop\OTL
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.24 Gb Total Physical Memory | 2.62 Gb Available Physical Memory | 80.79% Memory free
5.08 Gb Paging File | 4.59 Gb Available in Paging File | 90.33% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 596.12 Gb Total Space | 494.69 Gb Free Space | 82.99% Space Free | Partition Type: NTFS
Drive I: | 1.86 Gb Total Space | 1.77 Gb Free Space | 95.25% Space Free | Partition Type: FAT

Computer Name: FAMILYROOM | User Name: Joan Sciarra | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_USERS\S-1-5-21-1674639757-3571052794-2677517888-1007\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\aol\acs\AOLDial.exe" = C:\Program Files\Common Files\aol\acs\AOLDial.exe:*:Enabled:AOL Connectivity Service Dialer – (AOL LLC)
"C:\Program Files\Common Files\aol\acs\AOLacsd.exe" = C:\Program Files\Common Files\aol\acs\AOLacsd.exe:*:Enabled:AOL Connectivity Service – (AOL LLC)
"C:\Program Files\Common Files\aol\1233470088\ee\aolsoftware.exe" = C:\Program Files\Common Files\aol\1233470088\ee\aolsoftware.exe:*:Enabled:AOL Shared Components
"C:\Program Files\AOL 9.1\waol.exe" = C:\Program Files\AOL 9.1\waol.exe:*:Enabled:AOL
"C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe" = C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed – (AOL LLC)
"C:\Program Files\Common Files\aol\Loader\aolload.exe" = C:\Program Files\Common Files\aol\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\Program Files\Common Files\aol\System Information\sinf.exe" = C:\Program Files\Common Files\aol\System Information\sinf.exe:*:Enabled:AOL System Information – (AOL LLC)
"C:\Program Files\AOL 9.0\waol.exe" = C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL
"C:\Program Files\Common Files\aol\1234674321\ee\aolsoftware.exe" = C:\Program Files\Common Files\aol\1234674321\ee\aolsoftware.exe:*:Enabled:AOL Shared Components – (AOL LLC)
"C:\Program Files\AOL 9.5\waol.exe" = C:\Program Files\AOL 9.5\waol.exe:*:Enabled:AOL – (AOL, LLC.)
"C:\Program Files\AOL 9.5a\waol.exe" = C:\Program Files\AOL 9.5a\waol.exe:*:Enabled:AOL – (AOL, LLC.)
"C:\Documents and Settings\Joan Sciarra\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\Joan Sciarra\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player – (Octoshape ApS)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\TightVNC\vncviewer.exe" = C:\Program Files\TightVNC\vncviewer.exe:*:Enabled:TightVNC Viewer – (TightVNC Group)
"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgemcx.exe" = C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Logitech\Logitech Vid\Vid.exe" = C:\Program Files\Logitech\Logitech Vid\Vid.exe:*:Enabled:Logitech Vid – (Logitech Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{083E0D59-B6B4-4570-AA0A-37F5B4526CF5}" = AVG 2012
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{130E5108-547F-4482-91EE-F45C784E08C7}" = HP Officejet 6500 E710n-z Help
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{21E75254-410E-49C4-8981-2E1A2A2221F2}" = HP Diagnostic Assistant
"{2405665A-16C9-4D3A-B70E-F006220E1472}" = Overland
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 30
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{2BBC9458-07CA-4843-848B-5C8146E5EFA8}" = CreativeProjects
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AEF2F6C-F1D3-47CD-BF3B-A327F1FABE58}" = PSPrinters06
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{41254D7B-EADF-4078-AE4A-BD73B300EE86}" = Unload
"{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}" = Banctec Service Agreement
"{457791C5-D702-4143-A7B2-2744BE9573F2}" = HP Software Update
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EFC72DA-2314-4E5D-AC8E-1C954CDB8BBF}" = AVG 2012
"{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}" = Logitech Vid
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{595D0DE8-C38A-4432-B851-47DECC1A99BD}" = HP Unload DLL Patch
"{600AB648-F79B-41EC-B426-A49A7DB121EA}" = HP Officejet 6500 E710n-z Basic Device Software
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{623B8278-8CAD-45C1-B844-58B687C07805}" = Bing Bar Platform
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A7867BA-B7CA-4CC9-ACAB-85BA46865EE5}" = Norton Utilities
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{77364F85-6219-4CB8-AAA0-6D53368D683D}" = Connection Keep Alive
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{797EE0CA-8165-405C-B5CE-F11EC20F1BB0}" = Microsoft VC9 runtime libraries
"{82E04018-3AA6-48AC-B3E3-C12B4E6688AC}" = Super Fontastic
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E9976D2-E563-43DE-A51F-5AEBC38D1F08}" = Ad-Aware
"{9002CEE2-B9AD-4425-B85C-9680A159BEEB}" = Norton SystemWorks Basic Edition
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUSR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{928B06E4-DDAA-476A-926A-641620326327}" = Microsoft Search Enhancement Pack
"{981FB376-8418-4EA8-BBED-9DE5AA63E7D5}" = SkinsHP1
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}" = QuickProjects
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}" = PrintScreen
"{A1DCC235-DACC-4E1F-8D11-D630634B4AEF}" = PhotoGallery
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A760067A-C07E-1033-0000-A764AC000005}" = Avery Template
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}" = Photosmart 320,370,7400,8100,8400 Series
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AC96671C-2001-432C-9826-5266D84EF1DC}" = Logitech Webcam Software
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B3D5D4E0-E965-41C4-ABFD-A7B1AD0663C2}" = Director
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B45D9FEE-1AF4-46F3-9A83-2545F81547F5}" = CreativeProjectsTemplates
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{BCC992E5-5C81-4066-9B55-03DC10B24D21}" = InstantShare
"{BF018D2F-C788-4AB1-AB95-1280EAB8F13E}" = TrayApp
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{C7DACB79-D0BE-477B-B63F-4BBF33F39B7A}" = TWC Client ActiveX Controls
"{CA31120D-2101-484D-9FF1-195DE96FE346}" = Norton Cleanup
"{CA6BCA2F-EDEB-408F-850B-31404BE16A61}" = I.R.I.S. OCR
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEF294F4-6A80-463E-8F68-E4D3A80147A4}" = PS8400
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{EC8673DA-F96B-497E-B2DB-BC7B029FD680}" = BufferChm
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1362843-0E0E-4F74-8662-724CF101ADCE}" = Skype web features
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4F47155-5B4D-42AA-97F8-490BC52EA7F3}" = Destinations
"{F65787F3-B356-45EC-8DD0-0E6758EDBCEE}" = WebReg
"{FAABDC10-41B3-4A4C-A76E-C02CB9BE2A5E}" = HP Officejet 6500 E710n-z Product Improvement Study
"{FF26F7EA-BCEE-478C-9A1B-6B4F88717D73}" = CueTour
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AOL Emergency Connect Utility 1.0" = Uninstall AOL Emergency Connect Utility 1.0
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"AVG" = AVG 2012
"CK Becky Higgins' Creative Clips" = CK Becky Higgins' Creative Clips
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"HDMI" = Intel® Graphics Media Accelerator Driver
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Photo & Imaging" = HP Image Zone 4.0
"ie8" = Windows Internet Explorer 8
"lvdrivers_12.0" = Logitech Webcam Software Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 9.0.1 (x86 en-US)" = Mozilla Firefox 9.0.1 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MyPublisher" = MyPublisher
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"PROSet" = Intel® PRO Network Connections Drivers
"Summitfont_Font_Manager_BETA__.7" = Advanced Font Manager v1.3
"SymSetup.{9002CEE2-B9AD-4425-B85C-9680A159BEEB}" = Norton SystemWorks (Symantec Corporation)
"TightVNC" = TightVNC 2.0.4
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1674639757-3571052794-2677517888-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >

Attachments:

Hello learn2beabum

First,

please post that TDSSKiller log you ran that killed your connection.
It can usually be found in your root directory, (usually C:\ ) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt".

Next,

Please download Farbar Service Scanner and run it on the computer with the issue.

  • Make sure "Include All Files" option remains checked.
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.

Sunyata,

There are (3) TDSSKiller logs attached. Unsure why there are (3)…

TDSSKiller:

Log1:

16:49:09.0796 6016 TDSS rootkit removing tool 2.7.1.0 Jan 13 2012 15:24:05
16:49:10.0671 6016 ============================================================
16:49:10.0671 6016 Current date / time: 2012/01/15 16:49:10.0671
16:49:10.0671 6016 SystemInfo:
16:49:10.0671 6016
16:49:10.0671 6016 OS Version: 5.1.2600 ServicePack: 3.0
16:49:10.0671 6016 Product type: Workstation
16:49:10.0671 6016 ComputerName: FAMILYROOM
16:49:10.0671 6016 UserName: Patrick Sciarra
16:49:10.0671 6016 Windows directory: C:\WINDOWS
16:49:10.0671 6016 System windows directory: C:\WINDOWS
16:49:10.0671 6016 Processor architecture: Intel x86
16:49:10.0671 6016 Number of processors: 4
16:49:10.0671 6016 Page size: 0x1000
16:49:10.0671 6016 Boot type: Normal boot
16:49:10.0671 6016 ============================================================
16:49:21.0203 6016 Drive \Device\Harddisk0\DR0 - Size: 0x950B056000, SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K', Flags 0x00000054
16:49:21.0531 6016 Initialize success
16:49:25.0937 4108 ============================================================
16:49:25.0937 4108 Scan started
16:49:25.0937 4108 Mode: Manual;
16:49:25.0937 4108 ============================================================
16:49:27.0828 4108 Abiosdsk - ok
16:49:27.0890 4108 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
16:49:27.0906 4108 abp480n5 - ok
16:49:27.0953 4108 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
16:49:27.0953 4108 ACPI - ok
16:49:28.0000 4108 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
16:49:28.0000 4108 ACPIEC - ok
16:49:28.0171 4108 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
16:49:28.0187 4108 adpu160m - ok
16:49:28.0203 4108 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
16:49:28.0203 4108 aec - ok
16:49:28.0250 4108 AFD (18e83c3ffecdeeda041d1f4e96072ac9) C:\WINDOWS\System32\drivers\afd.sys
16:49:28.0640 4108 AFD - ok
16:49:28.0734 4108 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
16:49:28.0750 4108 agp440 - ok
16:49:28.0765 4108 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
16:49:28.0765 4108 agpCPQ - ok
16:49:28.0781 4108 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
16:49:28.0781 4108 Aha154x - ok
16:49:28.0796 4108 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
16:49:28.0796 4108 aic78u2 - ok
16:49:28.0812 4108 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
16:49:28.0812 4108 aic78xx - ok
16:49:28.0843 4108 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
16:49:28.0843 4108 AliIde - ok
16:49:28.0937 4108 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
16:49:28.0937 4108 alim1541 - ok
16:49:28.0953 4108 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
16:49:28.0953 4108 amdagp - ok
16:49:29.0046 4108 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
16:49:29.0046 4108 amsint - ok
16:49:29.0343 4108 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
16:49:29.0343 4108 asc - ok
16:49:29.0375 4108 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
16:49:29.0375 4108 asc3350p - ok
16:49:29.0437 4108 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
16:49:29.0437 4108 asc3550 - ok
16:49:29.0750 4108 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
16:49:29.0765 4108 AsyncMac - ok
16:49:29.0828 4108 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
16:49:29.0828 4108 atapi - ok
16:49:29.0875 4108 Atdisk - ok
16:49:29.0875 4108 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
16:49:29.0875 4108 Atmarpc - ok
16:49:29.0906 4108 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
16:49:29.0906 4108 audstub - ok
16:49:29.0968 4108 AVGIDSDriver (4fa401b33c1b50c816486f6951244a14) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
16:49:29.0968 4108 AVGIDSDriver - ok
16:49:29.0984 4108 AVGIDSEH (69578bc9d43d614c6b3455db4af19762) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
16:49:29.0984 4108 AVGIDSEH - ok
16:49:30.0015 4108 AVGIDSFilter (6df528406aa22201f392b9b19121cd6f) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
16:49:30.0015 4108 AVGIDSFilter - ok
16:49:30.0078 4108 AVGIDSShim (1e01c2166b5599802bcd61b9691f7476) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
16:49:30.0078 4108 AVGIDSShim - ok
16:49:30.0125 4108 Avgldx86 (bf8118cd5e2255387b715b534d64acd1) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
16:49:30.0125 4108 Avgldx86 - ok
16:49:30.0156 4108 Avgmfx86 (1c77ef67f196466adc9924cb288afe87) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
16:49:30.0156 4108 Avgmfx86 - ok
16:49:30.0171 4108 Avgrkx86 (f2038ed7284b79dcef581468121192a9) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
16:49:30.0171 4108 Avgrkx86 - ok
16:49:30.0203 4108 Avgtdix (a6d562b612216d8d02a35ebeb92366bd) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
16:49:30.0203 4108 Avgtdix - ok
16:49:30.0265 4108 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
16:49:30.0265 4108 Beep - ok
16:49:30.0265 4108 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
16:49:30.0265 4108 cbidf - ok
16:49:30.0281 4108 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
16:49:30.0281 4108 cbidf2k - ok
16:49:30.0328 4108 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
16:49:30.0328 4108 CCDECODE - ok
16:49:30.0328 4108 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
16:49:30.0328 4108 cd20xrnt - ok
16:49:30.0359 4108 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
16:49:30.0359 4108 Cdaudio - ok
16:49:30.0390 4108 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
16:49:30.0390 4108 Cdfs - ok
16:49:30.0421 4108 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
16:49:30.0421 4108 Cdrom - ok
16:49:30.0421 4108 Changer - ok
16:49:30.0453 4108 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
16:49:30.0453 4108 CmdIde - ok
16:49:30.0468 4108 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
16:49:30.0468 4108 Cpqarray - ok
16:49:30.0484 4108 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
16:49:30.0500 4108 dac2w2k - ok
16:49:30.0500 4108 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
16:49:30.0500 4108 dac960nt - ok
16:49:30.0515 4108 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
16:49:30.0515 4108 Disk - ok
16:49:30.0562 4108 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
16:49:30.0578 4108 dmboot - ok
16:49:30.0625 4108 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
16:49:30.0625 4108 dmio - ok
16:49:30.0656 4108 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
16:49:30.0656 4108 dmload - ok
16:49:30.0718 4108 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
16:49:30.0718 4108 DMusic - ok
16:49:30.0765 4108 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
16:49:30.0765 4108 dpti2o - ok
16:49:30.0781 4108 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
16:49:30.0781 4108 drmkaud - ok
16:49:30.0828 4108 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys
16:49:30.0828 4108 E100B - ok
16:49:30.0859 4108 e1express (34aaa3b298a852b3663e6e0d94d12945) C:\WINDOWS\system32\DRIVERS\e1e5132.sys
16:49:30.0859 4108 e1express - ok
16:49:30.0921 4108 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
16:49:30.0921 4108 Fastfat - ok
16:49:30.0968 4108 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
16:49:30.0968 4108 Fdc - ok
16:49:31.0015 4108 FilterService (a75ddc492d2d1d6558ad8003a4adb73a) C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys
16:49:31.0015 4108 FilterService - ok
16:49:31.0031 4108 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
16:49:31.0031 4108 Fips - ok
16:49:31.0031 4108 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
16:49:31.0031 4108 Flpydisk - ok
16:49:31.0109 4108 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
16:49:31.0109 4108 FltMgr - ok
16:49:31.0125 4108 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
16:49:31.0125 4108 Fs_Rec - ok
16:49:31.0140 4108 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
16:49:31.0140 4108 Ftdisk - ok
16:49:31.0171 4108 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
16:49:31.0171 4108 Gpc - ok
16:49:31.0453 4108 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
16:49:31.0453 4108 HDAudBus - ok
16:49:31.0578 4108 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
16:49:31.0578 4108 HidUsb - ok
16:49:31.0671 4108 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
16:49:31.0687 4108 hpn - ok
16:49:31.0734 4108 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
16:49:31.0734 4108 HPZid412 - ok
16:49:31.0796 4108 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
16:49:31.0796 4108 HPZipr12 - ok
16:49:31.0890 4108 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
16:49:31.0890 4108 HPZius12 - ok
16:49:32.0062 4108 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
16:49:32.0062 4108 HTTP - ok
16:49:32.0093 4108 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
16:49:32.0109 4108 i2omgmt - ok
16:49:32.0171 4108 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
16:49:32.0171 4108 i2omp - ok
16:49:32.0343 4108 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
16:49:32.0343 4108 i8042prt - ok
16:49:32.0531 4108 ialm (28423512370705aeda6a652fedb25468) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
16:49:32.0562 4108 ialm - ok
16:49:32.0656 4108 iaStor (997e8f5939f2d12cd9f2e6b395724c16) C:\WINDOWS\system32\drivers\iaStor.sys
16:49:32.0656 4108 iaStor - ok
16:49:32.0703 4108 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
16:49:32.0703 4108 Imapi - ok
16:49:32.0781 4108 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
16:49:32.0828 4108 ini910u - ok
16:49:33.0500 4108 IntcAzAudAddService (17bbbabb21f86b650b2626045a9d016c) C:\WINDOWS\system32\drivers\RtkHDAud.sys
16:49:33.0531 4108 IntcAzAudAddService - ok
16:49:33.0906 4108 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
16:49:33.0906 4108 IntelIde - ok
16:49:33.0937 4108 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
16:49:33.0937 4108 intelppm - ok
16:49:33.0968 4108 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
16:49:33.0968 4108 Ip6Fw - ok
16:49:33.0984 4108 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
16:49:33.0984 4108 IpFilterDriver - ok
16:49:34.0000 4108 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
16:49:34.0000 4108 IpInIp - ok
16:49:34.0093 4108 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
16:49:34.0093 4108 IpNat - ok
16:49:34.0093 4108 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
16:49:34.0093 4108 IPSec - ok
16:49:34.0140 4108 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
16:49:34.0140 4108 IRENUM - ok
16:49:34.0203 4108 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
16:49:34.0203 4108 isapnp - ok
16:49:34.0265 4108 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
16:49:34.0265 4108 Kbdclass - ok
16:49:34.0281 4108 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
16:49:34.0281 4108 kbdhid - ok
16:49:34.0343 4108 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
16:49:34.0343 4108 kmixer - ok
16:49:34.0375 4108 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
16:49:34.0375 4108 KSecDD - ok
16:49:34.0562 4108 Lavasoft Kernexplorer (6c4a3804510ad8e0f0c07b5be3d44ddb) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys
16:49:34.0562 4108 Lavasoft Kernexplorer - ok
16:49:34.0609 4108 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\WINDOWS\system32\DRIVERS\Lbd.sys
16:49:34.0609 4108 Lbd - ok
16:49:34.0640 4108 lbrtfdc - ok
16:49:34.0921 4108 lvpopflt (e1158b0cb852db0573922c92e6e564de) C:\WINDOWS\system32\DRIVERS\lvpopflt.sys
16:49:34.0937 4108 lvpopflt - ok
16:49:35.0000 4108 LVPr2Mon (c57c48fb9ae3efb9848af594e3123a63) C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys
16:49:35.0000 4108 LVPr2Mon - ok
16:49:35.0234 4108 LVRS (87ecce893d8aec5a9337b917742d339c) C:\WINDOWS\system32\DRIVERS\lvrs.sys
16:49:35.0234 4108 LVRS - ok
16:49:35.0296 4108 LVUSBSta (be5e104be263921d6842c555db6a5c23) C:\WINDOWS\system32\drivers\LVUSBSta.sys
16:49:35.0296 4108 LVUSBSta - ok
16:49:36.0265 4108 LVUVC (291f69b3dda0f033d2490c5ba5179f7c) C:\WINDOWS\system32\DRIVERS\lvuvc.sys
16:49:36.0296 4108 LVUVC - ok
16:49:36.0421 4108 MBAMSwissArmy - ok
16:49:36.0593 4108 mfehidk (168c565101fd5b9db694efdec91fafa9) C:\WINDOWS\system32\drivers\mfehidk.sys
16:49:36.0593 4108 mfehidk - ok
16:49:36.0625 4108 mferkdk (e0842f67dc9bc4d21d1e319610ebe9e5) C:\WINDOWS\system32\drivers\mferkdk.sys
16:49:36.0625 4108 mferkdk - ok
16:49:36.0687 4108 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
16:49:36.0687 4108 mnmdd - ok
16:49:36.0890 4108 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
16:49:36.0890 4108 Modem - ok
16:49:36.0937 4108 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
16:49:36.0937 4108 Mouclass - ok
16:49:37.0000 4108 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
16:49:37.0000 4108 mouhid - ok
16:49:37.0000 4108 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
16:49:37.0000 4108 MountMgr - ok
16:49:37.0062 4108 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
16:49:37.0078 4108 mraid35x - ok
16:49:37.0109 4108 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
16:49:37.0125 4108 MRxDAV - ok
16:49:37.0234 4108 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
16:49:37.0234 4108 MRxSmb - ok
16:49:37.0250 4108 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
16:49:37.0250 4108 Msfs - ok
16:49:37.0296 4108 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
16:49:37.0296 4108 MSKSSRV - ok
16:49:37.0343 4108 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
16:49:37.0343 4108 MSPCLOCK - ok
16:49:37.0375 4108 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
16:49:37.0375 4108 MSPQM - ok
16:49:37.0406 4108 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
16:49:37.0406 4108 mssmbios - ok
16:49:37.0453 4108 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
16:49:37.0453 4108 MSTEE - ok
16:49:37.0500 4108 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
16:49:37.0500 4108 Mup - ok
16:49:37.0546 4108 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
16:49:37.0546 4108 NABTSFEC - ok
16:49:37.0578 4108 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
16:49:37.0578 4108 NDIS - ok
16:49:37.0625 4108 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
16:49:37.0625 4108 NdisIP - ok
16:49:37.0656 4108 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
16:49:37.0656 4108 NdisTapi - ok
16:49:37.0718 4108 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
16:49:37.0718 4108 Ndisuio - ok
16:49:37.0750 4108 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
16:49:37.0750 4108 NdisWan - ok
16:49:37.0781 4108 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
16:49:37.0796 4108 NDProxy - ok
16:49:37.0796 4108 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
16:49:37.0796 4108 NetBIOS - ok
16:49:37.0843 4108 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
16:49:37.0843 4108 NetBT - ok
16:49:37.0890 4108 NPDriver (65194f525aef541eaa5056eb3d53a25b) C:\WINDOWS\system32\Drivers\NPDRIVER.SYS
16:49:37.0890 4108 NPDriver - ok
16:49:37.0890 4108 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
16:49:37.0906 4108 Npfs - ok
16:49:37.0937 4108 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
16:49:38.0000 4108 Ntfs - ok
16:49:38.0031 4108 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
16:49:38.0031 4108 Null - ok
16:49:38.0093 4108 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
16:49:38.0109 4108 nv - ok
16:49:38.0125 4108 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
16:49:38.0125 4108 NwlnkFlt - ok
16:49:38.0140 4108 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
16:49:38.0140 4108 NwlnkFwd - ok
16:49:38.0156 4108 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
16:49:38.0156 4108 Parport - ok
16:49:38.0171 4108 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
16:49:38.0171 4108 PartMgr - ok
16:49:38.0171 4108 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
16:49:38.0171 4108 ParVdm - ok
16:49:38.0187 4108 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
16:49:38.0187 4108 PCI - ok
16:49:38.0187 4108 PCIDump - ok
16:49:38.0203 4108 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
16:49:38.0203 4108 PCIIde - ok
16:49:38.0234 4108 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
16:49:38.0234 4108 Pcmcia - ok
16:49:38.0250 4108 PDCOMP - ok
16:49:38.0250 4108 PDFRAME - ok
16:49:38.0250 4108 PDRELI - ok
16:49:38.0265 4108 PDRFRAME - ok
16:49:38.0281 4108 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
16:49:38.0281 4108 perc2 - ok
16:49:38.0296 4108 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
16:49:38.0296 4108 perc2hib - ok
16:49:38.0328 4108 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
16:49:38.0328 4108 PptpMiniport - ok
16:49:38.0343 4108 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
16:49:38.0343 4108 PSched - ok
16:49:38.0343 4108 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
16:49:38.0343 4108 Ptilink - ok
16:49:38.0375 4108 PxHelp20 (03e0fe281823ba64b3782f5b38950e73) C:\WINDOWS\system32\Drivers\PxHelp20.sys
16:49:38.0375 4108 PxHelp20 - ok
16:49:38.0390 4108 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
16:49:38.0390 4108 ql1080 - ok
16:49:38.0406 4108 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
16:49:38.0406 4108 Ql10wnt - ok
16:49:38.0437 4108 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
16:49:38.0437 4108 ql12160 - ok
16:49:38.0453 4108 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
16:49:38.0453 4108 ql1240 - ok
16:49:38.0468 4108 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
16:49:38.0468 4108 ql1280 - ok
16:49:38.0500 4108 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
16:49:38.0500 4108 RasAcd - ok
16:49:38.0515 4108 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
16:49:38.0515 4108 Rasl2tp - ok
16:49:38.0515 4108 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
16:49:38.0515 4108 RasPppoe - ok
16:49:38.0531 4108 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
16:49:38.0531 4108 Raspti - ok
16:49:38.0562 4108 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
16:49:38.0562 4108 Rdbss - ok
16:49:38.0562 4108 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
16:49:38.0562 4108 RDPCDD - ok
16:49:38.0578 4108 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
16:49:38.0578 4108 rdpdr - ok
16:49:38.0640 4108 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
16:49:38.0656 4108 RDPWD - ok
16:49:38.0765 4108 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
16:49:38.0765 4108 redbook - ok
16:49:38.0796 4108 SDdriver (11b5e1da4566a68a881a7d73222f4c78) C:\WINDOWS\system32\Drivers\sddriver.sys
16:49:38.0812 4108 SDdriver - ok
16:49:38.0828 4108 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
16:49:38.0828 4108 Secdrv - ok
16:49:38.0859 4108 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
16:49:38.0859 4108 serenum - ok
16:49:38.0890 4108 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
16:49:38.0906 4108 Serial - ok
16:49:39.0046 4108 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
16:49:39.0062 4108 Sfloppy - ok
16:49:39.0093 4108 Simbad - ok
16:49:39.0156 4108 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
16:49:39.0156 4108 sisagp - ok
16:49:39.0203 4108 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
16:49:39.0203 4108 SLIP - ok
16:49:39.0250 4108 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
16:49:39.0250 4108 Sparrow - ok
16:49:39.0296 4108 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
16:49:39.0296 4108 splitter - ok
16:49:39.0328 4108 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
16:49:39.0328 4108 sr - ok
16:49:39.0390 4108 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
16:49:39.0390 4108 Srv - ok
16:49:39.0484 4108 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys
16:49:39.0484 4108 StillCam - ok
16:49:39.0515 4108 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
16:49:39.0515 4108 streamip - ok
16:49:39.0562 4108 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
16:49:39.0562 4108 swenum - ok
16:49:39.0578 4108 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
16:49:39.0578 4108 swmidi - ok
16:49:39.0625 4108 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
16:49:39.0625 4108 symc810 - ok
16:49:39.0656 4108 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
16:49:39.0656 4108 symc8xx - ok
16:49:39.0718 4108 SymEvent (a54ff04bd6e75dc4d8cb6f3e352635e0) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
16:49:39.0734 4108 SymEvent - ok
16:49:39.0765 4108 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
16:49:39.0765 4108 sym_hi - ok
16:49:39.0781 4108 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
16:49:39.0781 4108 sym_u3 - ok
16:49:39.0812 4108 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
16:49:39.0812 4108 sysaudio - ok
16:49:39.0890 4108 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
16:49:39.0890 4108 Tcpip - ok
16:49:39.0906 4108 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
16:49:39.0906 4108 TDPIPE - ok
16:49:39.0921 4108 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
16:49:39.0921 4108 TDTCP - ok
16:49:39.0953 4108 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
16:49:39.0953 4108 TermDD - ok
16:49:39.0984 4108 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
16:49:40.0000 4108 TosIde - ok
16:49:40.0015 4108 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
16:49:40.0015 4108 Udfs - ok
16:49:40.0046 4108 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
16:49:40.0046 4108 ultra - ok
16:49:40.0078 4108 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
16:49:40.0078 4108 Update - ok
16:49:40.0125 4108 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
16:49:40.0125 4108 usbaudio - ok
16:49:40.0187 4108 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
16:49:40.0187 4108 usbccgp - ok
16:49:40.0218 4108 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
16:49:40.0218 4108 usbehci - ok
16:49:40.0265 4108 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
16:49:40.0265 4108 usbhub - ok
16:49:40.0359 4108 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
16:49:40.0359 4108 usbprint - ok
16:49:40.0406 4108 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
16:49:40.0406 4108 usbscan - ok
16:49:40.0453 4108 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
16:49:40.0453 4108 USBSTOR - ok
16:49:40.0468 4108 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
16:49:40.0468 4108 usbuhci - ok
16:49:40.0515 4108 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
16:49:40.0515 4108 VgaSave - ok
16:49:40.0687 4108 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
16:49:40.0703 4108 viaagp - ok
16:49:40.0734 4108 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
16:49:40.0734 4108 ViaIde - ok
16:49:40.0765 4108 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
16:49:40.0781 4108 VolSnap - ok
16:49:41.0218 4108 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
16:49:41.0218 4108 Wanarp - ok
16:49:41.0359 4108 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINDOWS\system32\DRIVERS\wanatw4.sys
16:49:41.0359 4108 wanatw - ok
16:49:41.0484 4108 WDICA - ok
16:49:41.0531 4108 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
16:49:41.0531 4108 wdmaud - ok
16:49:41.0593 4108 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
16:49:41.0593 4108 WSTCODEC - ok
16:49:41.0640 4108 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
16:49:41.0640 4108 WudfPf - ok
16:49:41.0703 4108 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
16:49:41.0703 4108 WudfRd - ok
16:49:41.0718 4108 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
16:49:42.0593 4108 \Device\Harddisk0\DR0 - ok
16:49:42.0609 4108 Boot (0x1200) (b41806d52cf3a4007be7c67c9d7a6af2) \Device\Harddisk0\DR0\Partition0
16:49:42.0625 4108 \Device\Harddisk0\DR0\Partition0 - ok
16:49:42.0625 4108 ============================================================
16:49:42.0625 4108 Scan finished
16:49:42.0625 4108 ============================================================
16:49:42.0625 2216 Detected object count: 0
16:49:42.0625 2216 Actual detected object count: 0
16:50:00.0984 5912 Deinitialize success

Log 2:

21:18:53.0296 4316 TDSS rootkit removing tool 2.7.11.0 Feb 9 2012 10:12:57
21:18:53.0796 4316 ============================================================
21:18:53.0796 4316 Current date / time: 2012/02/11 21:18:53.0796
21:18:53.0796 4316 SystemInfo:
21:18:53.0796 4316
21:18:53.0796 4316 OS Version: 5.1.2600 ServicePack: 3.0
21:18:53.0796 4316 Product type: Workstation
21:18:53.0796 4316 ComputerName: FAMILYROOM
21:18:53.0812 4316 UserName: Janet Sciarra
21:18:53.0812 4316 Windows directory: C:\WINDOWS
21:18:53.0812 4316 System windows directory: C:\WINDOWS
21:18:53.0812 4316 Processor architecture: Intel x86
21:18:53.0812 4316 Number of processors: 4
21:18:53.0812 4316 Page size: 0x1000
21:18:53.0812 4316 Boot type: Normal boot
21:18:53.0812 4316 ============================================================
21:18:58.0421 4316 Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
21:18:58.0468 4316 \Device\Harddisk0\DR0:
21:18:58.0468 4316 MBR used
21:18:58.0468 4316 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x17886, BlocksNum 0x4A83B77A
21:18:58.0500 4316 Initialize success
21:18:58.0500 4316 ============================================================
21:19:01.0156 4392 ============================================================
21:19:01.0156 4392 Scan started
21:19:01.0156 4392 Mode: Manual;
21:19:01.0156 4392 ============================================================
21:19:02.0546 4392 Abiosdsk - ok
21:19:02.0625 4392 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
21:19:02.0625 4392 abp480n5 - ok
21:19:02.0687 4392 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
21:19:02.0687 4392 ACPI - ok
21:19:02.0718 4392 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
21:19:02.0718 4392 ACPIEC - ok
21:19:02.0734 4392 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
21:19:02.0734 4392 adpu160m - ok
21:19:02.0765 4392 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
21:19:02.0765 4392 aec - ok
21:19:02.0796 4392 AFD (18e83c3ffecdeeda041d1f4e96072ac9) C:\WINDOWS\System32\drivers\afd.sys
21:19:02.0828 4392 AFD ( Virus.Win32.ZAccess.k ) - infected
21:19:02.0828 4392 AFD - detected Virus.Win32.ZAccess.k (0)
21:19:02.0859 4392 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
21:19:02.0859 4392 agp440 - ok
21:19:02.0875 4392 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
21:19:02.0875 4392 agpCPQ - ok
21:19:02.0875 4392 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
21:19:02.0875 4392 Aha154x - ok
21:19:02.0906 4392 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
21:19:02.0906 4392 aic78u2 - ok
21:19:02.0906 4392 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
21:19:02.0921 4392 aic78xx - ok
21:19:02.0921 4392 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
21:19:02.0921 4392 AliIde - ok
21:19:02.0937 4392 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
21:19:02.0937 4392 alim1541 - ok
21:19:02.0937 4392 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
21:19:02.0937 4392 amdagp - ok
21:19:02.0953 4392 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
21:19:02.0953 4392 amsint - ok
21:19:02.0953 4392 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
21:19:02.0953 4392 asc - ok
21:19:02.0968 4392 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
21:19:02.0968 4392 asc3350p - ok
21:19:02.0968 4392 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
21:19:02.0968 4392 asc3550 - ok
21:19:03.0031 4392 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
21:19:03.0031 4392 AsyncMac - ok
21:19:03.0062 4392 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
21:19:03.0062 4392 atapi - ok
21:19:03.0078 4392 Atdisk - ok
21:19:03.0078 4392 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
21:19:03.0078 4392 Atmarpc - ok
21:19:03.0109 4392 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
21:19:03.0109 4392 audstub - ok
21:19:03.0171 4392 AVGIDSDriver (4fa401b33c1b50c816486f6951244a14) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
21:19:03.0187 4392 AVGIDSDriver - ok
21:19:03.0203 4392 AVGIDSEH (69578bc9d43d614c6b3455db4af19762) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
21:19:03.0203 4392 AVGIDSEH - ok
21:19:03.0234 4392 AVGIDSFilter (6df528406aa22201f392b9b19121cd6f) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
21:19:03.0234 4392 AVGIDSFilter - ok
21:19:03.0281 4392 AVGIDSShim (1e01c2166b5599802bcd61b9691f7476) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
21:19:03.0281 4392 AVGIDSShim - ok
21:19:03.0328 4392 Avgldx86 (bf8118cd5e2255387b715b534d64acd1) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
21:19:03.0328 4392 Avgldx86 - ok
21:19:03.0359 4392 Avgmfx86 (1c77ef67f196466adc9924cb288afe87) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
21:19:03.0359 4392 Avgmfx86 - ok
21:19:03.0390 4392 Avgrkx86 (f2038ed7284b79dcef581468121192a9) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
21:19:03.0390 4392 Avgrkx86 - ok
21:19:03.0406 4392 Avgtdix (a6d562b612216d8d02a35ebeb92366bd) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
21:19:03.0421 4392 Avgtdix - ok
21:19:03.0437 4392 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
21:19:03.0437 4392 Beep - ok
21:19:03.0453 4392 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
21:19:03.0453 4392 cbidf - ok
21:19:03.0453 4392 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
21:19:03.0453 4392 cbidf2k - ok
21:19:03.0484 4392 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
21:19:03.0484 4392 CCDECODE - ok
21:19:03.0500 4392 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
21:19:03.0500 4392 cd20xrnt - ok
21:19:03.0500 4392 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
21:19:03.0500 4392 Cdaudio - ok
21:19:03.0515 4392 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
21:19:03.0515 4392 Cdfs - ok
21:19:03.0546 4392 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
21:19:03.0546 4392 Cdrom - ok
21:19:03.0562 4392 Changer - ok
21:19:03.0578 4392 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
21:19:03.0578 4392 CmdIde - ok
21:19:03.0578 4392 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
21:19:03.0578 4392 Cpqarray - ok
21:19:03.0609 4392 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
21:19:03.0609 4392 dac2w2k - ok
21:19:03.0609 4392 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
21:19:03.0609 4392 dac960nt - ok
21:19:03.0625 4392 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
21:19:03.0625 4392 Disk - ok
21:19:03.0640 4392 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
21:19:03.0656 4392 dmboot - ok
21:19:03.0671 4392 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
21:19:03.0671 4392 dmio - ok
21:19:03.0671 4392 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
21:19:03.0671 4392 dmload - ok
21:19:03.0687 4392 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
21:19:03.0703 4392 DMusic - ok
21:19:03.0718 4392 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
21:19:03.0718 4392 dpti2o - ok
21:19:03.0718 4392 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
21:19:03.0718 4392 drmkaud - ok
21:19:03.0734 4392 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys
21:19:03.0734 4392 E100B - ok
21:19:03.0750 4392 e1express (34aaa3b298a852b3663e6e0d94d12945) C:\WINDOWS\system32\DRIVERS\e1e5132.sys
21:19:03.0750 4392 e1express - ok
21:19:03.0781 4392 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
21:19:03.0781 4392 Fastfat - ok
21:19:03.0796 4392 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
21:19:03.0796 4392 Fdc - ok
21:19:03.0843 4392 FilterService (a75ddc492d2d1d6558ad8003a4adb73a) C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys
21:19:03.0859 4392 FilterService - ok
21:19:03.0921 4392 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
21:19:03.0921 4392 Fips - ok
21:19:03.0921 4392 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
21:19:03.0937 4392 Flpydisk - ok
21:19:03.0953 4392 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
21:19:03.0953 4392 FltMgr - ok
21:19:03.0968 4392 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
21:19:03.0968 4392 Fs_Rec - ok
21:19:03.0968 4392 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
21:19:03.0984 4392 Ftdisk - ok
21:19:04.0000 4392 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
21:19:04.0000 4392 Gpc - ok
21:19:04.0046 4392 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
21:19:04.0046 4392 HDAudBus - ok
21:19:04.0062 4392 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
21:19:04.0062 4392 HidUsb - ok
21:19:04.0078 4392 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
21:19:04.0078 4392 hpn - ok
21:19:04.0140 4392 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
21:19:04.0156 4392 HPZid412 - ok
21:19:04.0156 4392 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
21:19:04.0171 4392 HPZipr12 - ok
21:19:04.0218 4392 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
21:19:04.0218 4392 HPZius12 - ok
21:19:04.0265 4392 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
21:19:04.0296 4392 HTTP - ok
21:19:04.0312 4392 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
21:19:04.0312 4392 i2omgmt - ok
21:19:04.0328 4392 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
21:19:04.0343 4392 i2omp - ok
21:19:04.0359 4392 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
21:19:04.0359 4392 i8042prt - ok
21:19:04.0484 4392 ialm (28423512370705aeda6a652fedb25468) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
21:19:04.0578 4392 ialm - ok
21:19:04.0671 4392 iaStor (997e8f5939f2d12cd9f2e6b395724c16) C:\WINDOWS\system32\drivers\iaStor.sys
21:19:04.0734 4392 iaStor - ok
21:19:04.0750 4392 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
21:19:04.0750 4392 Imapi - ok
21:19:04.0812 4392 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
21:19:04.0812 4392 ini910u - ok
21:19:04.0937 4392 IntcAzAudAddService (17bbbabb21f86b650b2626045a9d016c) C:\WINDOWS\system32\drivers\RtkHDAud.sys
21:19:05.0031 4392 IntcAzAudAddService - ok
21:19:05.0046 4392 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
21:19:05.0062 4392 IntelIde - ok
21:19:05.0093 4392 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
21:19:05.0093 4392 intelppm - ok
21:19:05.0109 4392 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
21:19:05.0109 4392 Ip6Fw - ok
21:19:05.0218 4392 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
21:19:05.0218 4392 IpFilterDriver - ok
21:19:05.0390 4392 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
21:19:05.0390 4392 IpInIp - ok
21:19:05.0500 4392 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
21:19:05.0531 4392 IpNat - ok
21:19:05.0562 4392 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
21:19:05.0562 4392 IPSec - ok
21:19:05.0593 4392 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
21:19:05.0593 4392 IRENUM - ok
21:19:05.0609 4392 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
21:19:05.0609 4392 isapnp - ok
21:19:05.0625 4392 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
21:19:05.0625 4392 Kbdclass - ok
21:19:05.0640 4392 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
21:19:05.0640 4392 kbdhid - ok
21:19:05.0656 4392 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
21:19:05.0656 4392 kmixer - ok
21:19:05.0703 4392 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
21:19:05.0703 4392 KSecDD - ok
21:19:05.0796 4392 Lavasoft Kernexplorer (6c4a3804510ad8e0f0c07b5be3d44ddb) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys
21:19:05.0812 4392 Lavasoft Kernexplorer - ok
21:19:05.0859 4392 Lbd (336abe8721cbc3110f1c6426da633417) C:\WINDOWS\system32\DRIVERS\Lbd.sys
21:19:05.0859 4392 Lbd - ok
21:19:05.0859 4392 lbrtfdc - ok
21:19:05.0953 4392 lvpopflt (e1158b0cb852db0573922c92e6e564de) C:\WINDOWS\system32\DRIVERS\lvpopflt.sys
21:19:05.0984 4392 lvpopflt - ok
21:19:06.0031 4392 LVPr2Mon (c57c48fb9ae3efb9848af594e3123a63) C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys
21:19:06.0046 4392 LVPr2Mon - ok
21:19:06.0078 4392 LVRS (87ecce893d8aec5a9337b917742d339c) C:\WINDOWS\system32\DRIVERS\lvrs.sys
21:19:06.0093 4392 LVRS - ok
21:19:06.0140 4392 LVUSBSta (be5e104be263921d6842c555db6a5c23) C:\WINDOWS\system32\drivers\LVUSBSta.sys
21:19:06.0140 4392 LVUSBSta - ok
21:19:06.0265 4392 LVUVC (291f69b3dda0f033d2490c5ba5179f7c) C:\WINDOWS\system32\DRIVERS\lvuvc.sys
21:19:06.0375 4392 LVUVC - ok
21:19:06.0390 4392 MBAMSwissArmy - ok
21:19:06.0453 4392 mfehidk (168c565101fd5b9db694efdec91fafa9) C:\WINDOWS\system32\drivers\mfehidk.sys
21:19:06.0453 4392 mfehidk - ok
21:19:06.0484 4392 mferkdk (e0842f67dc9bc4d21d1e319610ebe9e5) C:\WINDOWS\system32\drivers\mferkdk.sys
21:19:06.0484 4392 mferkdk - ok
21:19:06.0500 4392 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
21:19:06.0500 4392 mnmdd - ok
21:19:06.0515 4392 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
21:19:06.0515 4392 Modem - ok
21:19:06.0531 4392 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
21:19:06.0531 4392 Mouclass - ok
21:19:06.0593 4392 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
21:19:06.0593 4392 mouhid - ok
21:19:06.0593 4392 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
21:19:06.0593 4392 MountMgr - ok
21:19:06.0625 4392 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
21:19:06.0625 4392 mraid35x - ok
21:19:06.0640 4392 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
21:19:06.0640 4392 MRxDAV - ok
21:19:06.0671 4392 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
21:19:06.0671 4392 MRxSmb - ok
21:19:06.0687 4392 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
21:19:06.0687 4392 Msfs - ok
21:19:06.0718 4392 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
21:19:06.0718 4392 MSKSSRV - ok
21:19:06.0734 4392 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
21:19:06.0734 4392 MSPCLOCK - ok
21:19:06.0750 4392 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
21:19:06.0750 4392 MSPQM - ok
21:19:06.0750 4392 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
21:19:06.0750 4392 mssmbios - ok
21:19:06.0765 4392 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
21:19:06.0765 4392 MSTEE - ok
21:19:06.0781 4392 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
21:19:06.0781 4392 Mup - ok
21:19:06.0796 4392 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
21:19:06.0796 4392 NABTSFEC - ok
21:19:06.0812 4392 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
21:19:06.0812 4392 NDIS - ok
21:19:06.0828 4392 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
21:19:06.0828 4392 NdisIP - ok
21:19:06.0843 4392 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
21:19:06.0953 4392 NdisTapi - ok
21:19:06.0984 4392 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
21:19:06.0984 4392 Ndisuio - ok
21:19:06.0984 4392 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
21:19:07.0000 4392 NdisWan - ok
21:19:07.0031 4392 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
21:19:07.0046 4392 NDProxy - ok
21:19:07.0062 4392 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
21:19:07.0062 4392 NetBIOS - ok
21:19:07.0093 4392 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
21:19:07.0093 4392 NetBT - ok
21:19:07.0140 4392 NPDriver (65194f525aef541eaa5056eb3d53a25b) C:\WINDOWS\system32\Drivers\NPDRIVER.SYS
21:19:07.0171 4392 NPDriver - ok
21:19:07.0187 4392 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
21:19:07.0187 4392 Npfs - ok
21:19:07.0203 4392 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
21:19:07.0218 4392 Ntfs - ok
21:19:07.0250 4392 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
21:19:07.0250 4392 Null - ok
21:19:07.0312 4392 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
21:19:07.0359 4392 nv - ok
21:19:07.0375 4392 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
21:19:07.0375 4392 NwlnkFlt - ok
21:19:07.0390 4392 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
21:19:07.0390 4392 NwlnkFwd - ok
21:19:07.0406 4392 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
21:19:07.0406 4392 Parport - ok
21:19:07.0406 4392 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
21:19:07.0406 4392 PartMgr - ok
21:19:07.0421 4392 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
21:19:07.0437 4392 ParVdm - ok
21:19:07.0437 4392 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
21:19:07.0437 4392 PCI - ok
21:19:07.0437 4392 PCIDump - ok
21:19:07.0453 4392 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
21:19:07.0453 4392 PCIIde - ok
21:19:07.0468 4392 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
21:19:07.0468 4392 Pcmcia - ok
21:19:07.0484 4392 PDCOMP - ok
21:19:07.0484 4392 PDFRAME - ok
21:19:07.0500 4392 PDRELI - ok
21:19:07.0500 4392 PDRFRAME - ok
21:19:07.0515 4392 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
21:19:07.0515 4392 perc2 - ok
21:19:07.0531 4392 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
21:19:07.0531 4392 perc2hib - ok
21:19:07.0578 4392 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
21:19:07.0578 4392 PptpMiniport - ok
21:19:07.0578 4392 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
21:19:07.0578 4392 PSched - ok
21:19:07.0593 4392 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
21:19:07.0593 4392 Ptilink - ok
21:19:07.0625 4392 PxHelp20 (03e0fe281823ba64b3782f5b38950e73) C:\WINDOWS\system32\Drivers\PxHelp20.sys
21:19:07.0625 4392 PxHelp20 - ok
21:19:07.0640 4392 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
21:19:07.0640 4392 ql1080 - ok
21:19:07.0656 4392 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
21:19:07.0656 4392 Ql10wnt - ok
21:19:07.0671 4392 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
21:19:07.0671 4392 ql12160 - ok
21:19:07.0671 4392 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
21:19:07.0671 4392 ql1240 - ok
21:19:07.0687 4392 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
21:19:07.0687 4392 ql1280 - ok
21:19:07.0687 4392 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
21:19:07.0703 4392 RasAcd - ok
21:19:07.0718 4392 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
21:19:07.0718 4392 Rasl2tp - ok
21:19:07.0734 4392 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
21:19:07.0734 4392 RasPppoe - ok
21:19:07.0734 4392 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
21:19:07.0734 4392 Raspti - ok
21:19:07.0750 4392 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
21:19:07.0750 4392 Rdbss - ok
21:19:07.0765 4392 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
21:19:07.0765 4392 RDPCDD - ok
21:19:07.0765 4392 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
21:19:07.0781 4392 rdpdr - ok
21:19:07.0812 4392 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
21:19:07.0828 4392 RDPWD - ok
21:19:07.0859 4392 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
21:19:07.0859 4392 redbook - ok
21:19:07.0906 4392 SDdriver (11b5e1da4566a68a881a7d73222f4c78) C:\WINDOWS\system32\Drivers\sddriver.sys
21:19:07.0906 4392 SDdriver - ok
21:19:07.0937 4392 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
21:19:07.0984 4392 Secdrv - ok
21:19:08.0000 4392 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
21:19:08.0000 4392 serenum - ok
21:19:08.0031 4392 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
21:19:08.0031 4392 Serial - ok
21:19:08.0046 4392 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
21:19:08.0046 4392 Sfloppy - ok
21:19:08.0062 4392 Simbad - ok
21:19:08.0093 4392 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
21:19:08.0093 4392 sisagp - ok
21:19:08.0109 4392 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
21:19:08.0109 4392 SLIP - ok
21:19:08.0125 4392 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
21:19:08.0125 4392 Sparrow - ok
21:19:08.0156 4392 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
21:19:08.0156 4392 splitter - ok
21:19:08.0171 4392 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
21:19:08.0171 4392 sr - ok
21:19:08.0187 4392 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
21:19:08.0203 4392 Srv - ok
21:19:08.0234 4392 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys
21:19:08.0234 4392 StillCam - ok
21:19:08.0250 4392 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
21:19:08.0250 4392 streamip - ok
21:19:08.0281 4392 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
21:19:08.0281 4392 swenum - ok
21:19:08.0281 4392 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
21:19:08.0281 4392 swmidi - ok
21:19:08.0328 4392 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
21:19:08.0328 4392 symc810 - ok
21:19:08.0343 4392 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
21:19:08.0343 4392 symc8xx - ok
21:19:08.0375 4392 SymEvent (a54ff04bd6e75dc4d8cb6f3e352635e0) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
21:19:08.0390 4392 SymEvent - ok
21:19:08.0406 4392 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
21:19:08.0406 4392 sym_hi - ok
21:19:08.0421 4392 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
21:19:08.0421 4392 sym_u3 - ok
21:19:08.0453 4392 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
21:19:08.0453 4392 sysaudio - ok
21:19:08.0515 4392 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
21:19:08.0546 4392 Tcpip - ok
21:19:08.0562 4392 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
21:19:08.0562 4392 TDPIPE - ok
21:19:08.0578 4392 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
21:19:08.0578 4392 TDTCP - ok
21:19:08.0609 4392 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
21:19:08.0609 4392 TermDD - ok
21:19:08.0640 4392 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
21:19:08.0640 4392 TosIde - ok
21:19:08.0671 4392 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
21:19:08.0671 4392 Udfs - ok
21:19:08.0703 4392 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
21:19:08.0703 4392 ultra - ok
21:19:08.0718 4392 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
21:19:08.0718 4392 Update - ok
21:19:08.0750 4392 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
21:19:08.0750 4392 usbaudio - ok
21:19:08.0765 4392 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
21:19:08.0765 4392 usbccgp - ok
21:19:08.0781 4392 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
21:19:08.0781 4392 usbehci - ok
21:19:08.0796 4392 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
21:19:08.0796 4392 usbhub - ok
21:19:08.0796 4392 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
21:19:08.0796 4392 usbprint - ok
21:19:08.0843 4392 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
21:19:08.0875 4392 usbscan - ok
21:19:08.0890 4392 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
21:19:08.0890 4392 USBSTOR - ok
21:19:08.0906 4392 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
21:19:08.0921 4392 usbuhci - ok
21:19:08.0921 4392 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
21:19:08.0937 4392 VgaSave - ok
21:19:08.0968 4392 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
21:19:08.0968 4392 viaagp - ok
21:19:08.0984 4392 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
21:19:08.0984 4392 ViaIde - ok
21:19:09.0000 4392 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
21:19:09.0000 4392 VolSnap - ok
21:19:09.0015 4392 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
21:19:09.0015 4392 Wanarp - ok
21:19:09.0078 4392 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINDOWS\system32\DRIVERS\wanatw4.sys
21:19:09.0078 4392 wanatw - ok
21:19:09.0078 4392 WDICA - ok
21:19:09.0125 4392 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
21:19:09.0125 4392 wdmaud - ok
21:19:09.0187 4392 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
21:19:09.0187 4392 WSTCODEC - ok
21:19:09.0218 4392 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
21:19:09.0250 4392 WudfPf - ok
21:19:09.0281 4392 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
21:19:09.0281 4392 WudfRd - ok
21:19:09.0312 4392 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
21:19:09.0468 4392 \Device\Harddisk0\DR0 - ok
21:19:09.0468 4392 Boot (0x1200) (b41806d52cf3a4007be7c67c9d7a6af2) \Device\Harddisk0\DR0\Partition0
21:19:09.0468 4392 \Device\Harddisk0\DR0\Partition0 - ok
21:19:09.0468 4392 ============================================================
21:19:09.0468 4392 Scan finished
21:19:09.0468 4392 ============================================================
21:19:09.0484 6080 Detected object count: 1
21:19:09.0484 6080 Actual detected object count: 1
21:19:19.0703 6080 C:\WINDOWS\System32\drivers\afd.sys - copied to quarantine
21:19:19.0734 6080 VerifyFileNameVersionInfo: GetFileVersionInfoSizeW(C:\WINDOWS\system32\drivers\afd.sys) error 1813
21:19:20.0562 6080 Backup copy found, using it..
21:19:20.0578 6080 C:\WINDOWS\System32\drivers\afd.sys - will be cured on reboot
21:19:21.0625 6080 AFD ( Virus.Win32.ZAccess.k ) - User select action: Cure
21:22:01.0921 4748 Deinitialize success

Log 3:

21:22:03.0562 0492 TDSS rootkit removing tool 2.7.11.0 Feb 9 2012 10:12:57
21:22:04.0015 0492 ============================================================
21:22:04.0031 0492 Current date / time: 2012/02/11 21:22:04.0015
21:22:04.0031 0492 SystemInfo:
21:22:04.0031 0492
21:22:04.0031 0492 OS Version: 5.1.2600 ServicePack: 3.0
21:22:04.0031 0492 Product type: Workstation
21:22:04.0031 0492 ComputerName: FAMILYROOM
21:22:04.0031 0492 UserName: Janet Sciarra
21:22:04.0031 0492 Windows directory: C:\WINDOWS
21:22:04.0031 0492 System windows directory: C:\WINDOWS
21:22:04.0031 0492 Processor architecture: Intel x86
21:22:04.0031 0492 Number of processors: 4
21:22:04.0031 0492 Page size: 0x1000
21:22:04.0031 0492 Boot type: Normal boot
21:22:04.0031 0492 ============================================================
21:22:04.0250 0492 Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
21:22:04.0281 0492 \Device\Harddisk0\DR0:
21:22:04.0281 0492 MBR used
21:22:04.0281 0492 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x17886, BlocksNum 0x4A83B77A
21:22:04.0328 0492 Initialize success
21:22:04.0328 0492 ============================================================
21:22:05.0500 5560 ============================================================
21:22:05.0500 5560 Scan started
21:22:05.0500 5560 Mode: Manual;
21:22:05.0500 5560 ============================================================
21:22:06.0796 5560 13514649 (58169ffb207940d4d84b4e85db02cc1e) C:\WINDOWS\system32\drivers\09752093.sys
21:22:06.0812 5560 Abiosdsk - ok
21:22:06.0875 5560 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
21:22:06.0875 5560 abp480n5 - ok
21:22:06.0921 5560 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
21:22:06.0937 5560 ACPI - ok
21:22:06.0968 5560 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
21:22:06.0968 5560 ACPIEC - ok
21:22:06.0968 5560 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
21:22:06.0968 5560 adpu160m - ok
21:22:07.0000 5560 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
21:22:07.0000 5560 aec - ok
21:22:07.0046 5560 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\system32\drivers\tsk37.tmp
21:22:07.0046 5560 Suspicious file (NoAccess): C:\WINDOWS\system32\drivers\tsk37.tmp. md5: 1e44bc1e83d8fd2305f8d452db109cf9
21:22:07.0078 5560 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
21:22:07.0078 5560 agp440 - ok
21:22:07.0093 5560 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
21:22:07.0093 5560 agpCPQ - ok
21:22:07.0093 5560 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
21:22:07.0093 5560 Aha154x - ok
21:22:07.0109 5560 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
21:22:07.0109 5560 aic78u2 - ok
21:22:07.0109 5560 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
21:22:07.0109 5560 aic78xx - ok
21:22:07.0125 5560 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
21:22:07.0125 5560 AliIde - ok
21:22:07.0156 5560 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
21:22:07.0156 5560 alim1541 - ok
21:22:07.0171 5560 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
21:22:07.0171 5560 amdagp - ok
21:22:07.0171 5560 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
21:22:07.0171 5560 amsint - ok
21:22:07.0187 5560 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
21:22:07.0187 5560 asc - ok
21:22:07.0187 5560 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
21:22:07.0187 5560 asc3350p - ok
21:22:07.0187 5560 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
21:22:07.0203 5560 asc3550 - ok
21:22:07.0234 5560 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
21:22:07.0234 5560 AsyncMac - ok
21:22:07.0250 5560 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
21:22:07.0265 5560 atapi - ok
21:22:07.0265 5560 Atdisk - ok
21:22:07.0296 5560 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
21:22:07.0296 5560 Atmarpc - ok
21:22:07.0312 5560 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
21:22:07.0312 5560 audstub - ok
21:22:07.0390 5560 AVGIDSDriver (4fa401b33c1b50c816486f6951244a14) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
21:22:07.0390 5560 AVGIDSDriver - ok
21:22:07.0406 5560 AVGIDSEH (69578bc9d43d614c6b3455db4af19762) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
21:22:07.0406 5560 AVGIDSEH - ok
21:22:07.0437 5560 AVGIDSFilter (6df528406aa22201f392b9b19121cd6f) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
21:22:07.0437 5560 AVGIDSFilter - ok
21:22:07.0515 5560 AVGIDSShim (1e01c2166b5599802bcd61b9691f7476) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
21:22:07.0515 5560 AVGIDSShim - ok
21:22:07.0609 5560 Avgldx86 (bf8118cd5e2255387b715b534d64acd1) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
21:22:07.0609 5560 Avgldx86 - ok
21:22:07.0718 5560 Avgmfx86 (1c77ef67f196466adc9924cb288afe87) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
21:22:07.0718 5560 Avgmfx86 - ok
21:22:07.0765 5560 Avgrkx86 (f2038ed7284b79dcef581468121192a9) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
21:22:07.0765 5560 Avgrkx86 - ok
21:22:07.0875 5560 Avgtdix (a6d562b612216d8d02a35ebeb92366bd) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
21:22:07.0875 5560 Avgtdix - ok
21:22:07.0906 5560 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
21:22:07.0906 5560 Beep - ok
21:22:07.0984 5560 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
21:22:07.0984 5560 cbidf - ok
21:22:08.0000 5560 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
21:22:08.0000 5560 cbidf2k - ok
21:22:08.0031 5560 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
21:22:08.0031 5560 CCDECODE - ok
21:22:08.0046 5560 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
21:22:08.0046 5560 cd20xrnt - ok
21:22:08.0062 5560 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
21:22:08.0062 5560 Cdaudio - ok
21:22:08.0078 5560 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
21:22:08.0078 5560 Cdfs - ok
21:22:08.0125 5560 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
21:22:08.0125 5560 Cdrom - ok
21:22:08.0156 5560 Changer - ok
21:22:08.0187 5560 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
21:22:08.0187 5560 CmdIde - ok
21:22:08.0203 5560 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
21:22:08.0203 5560 Cpqarray - ok
21:22:08.0203 5560 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
21:22:08.0203 5560 dac2w2k - ok
21:22:08.0218 5560 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
21:22:08.0218 5560 dac960nt - ok
21:22:08.0234 5560 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
21:22:08.0234 5560 Disk - ok
21:22:08.0296 5560 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
21:22:08.0296 5560 dmboot - ok
21:22:08.0296 5560 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
21:22:08.0296 5560 dmio - ok
21:22:08.0312 5560 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
21:22:08.0312 5560 dmload - ok
21:22:08.0328 5560 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
21:22:08.0328 5560 DMusic - ok
21:22:08.0343 5560 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
21:22:08.0343 5560 dpti2o - ok
21:22:08.0375 5560 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
21:22:08.0375 5560 drmkaud - ok
21:22:08.0375 5560 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys
21:22:08.0375 5560 E100B - ok
21:22:08.0421 5560 e1express (34aaa3b298a852b3663e6e0d94d12945) C:\WINDOWS\system32\DRIVERS\e1e5132.sys
21:22:08.0421 5560 e1express - ok
21:22:08.0437 5560 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
21:22:08.0437 5560 Fastfat - ok
21:22:08.0468 5560 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
21:22:08.0468 5560 Fdc - ok
21:22:08.0500 5560 FilterService (a75ddc492d2d1d6558ad8003a4adb73a) C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys
21:22:08.0500 5560 FilterService - ok
21:22:08.0500 5560 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
21:22:08.0500 5560 Fips - ok
21:22:08.0515 5560 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
21:22:08.0515 5560 Flpydisk - ok
21:22:08.0546 5560 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
21:22:08.0546 5560 FltMgr - ok
21:22:08.0546 5560 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
21:22:08.0546 5560 Fs_Rec - ok
21:22:08.0562 5560 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
21:22:08.0562 5560 Ftdisk - ok
21:22:08.0578 5560 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
21:22:08.0578 5560 Gpc - ok
21:22:08.0609 5560 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
21:22:08.0625 5560 HDAudBus - ok
21:22:08.0640 5560 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
21:22:08.0640 5560 HidUsb - ok
21:22:08.0656 5560 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
21:22:08.0656 5560 hpn - ok
21:22:08.0687 5560 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
21:22:08.0703 5560 HPZid412 - ok
21:22:08.0703 5560 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
21:22:08.0703 5560 HPZipr12 - ok
21:22:08.0750 5560 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
21:22:08.0750 5560 HPZius12 - ok
21:22:08.0796 5560 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
21:22:08.0812 5560 HTTP - ok
21:22:08.0828 5560 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
21:22:08.0828 5560 i2omgmt - ok
21:22:08.0859 5560 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
21:22:08.0859 5560 i2omp - ok
21:22:08.0890 5560 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
21:22:08.0890 5560 i8042prt - ok
21:22:08.0984 5560 ialm (28423512370705aeda6a652fedb25468) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
21:22:09.0015 5560 ialm - ok
21:22:09.0062 5560 iaStor (997e8f5939f2d12cd9f2e6b395724c16) C:\WINDOWS\system32\drivers\iaStor.sys
21:22:09.0062 5560 iaStor - ok
21:22:09.0062 5560 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
21:22:09.0062 5560 Imapi - ok
21:22:09.0125 5560 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
21:22:09.0125 5560 ini910u - ok
21:22:09.0234 5560 IntcAzAudAddService (17bbbabb21f86b650b2626045a9d016c) C:\WINDOWS\system32\drivers\RtkHDAud.sys
21:22:09.0265 5560 IntcAzAudAddService - ok
21:22:09.0312 5560 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
21:22:09.0312 5560 IntelIde - ok
21:22:09.0343 5560 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
21:22:09.0343 5560 intelppm - ok
21:22:09.0375 5560 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
21:22:09.0375 5560 Ip6Fw - ok
21:22:09.0390 5560 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
21:22:09.0390 5560 IpFilterDriver - ok
21:22:09.0406 5560 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
21:22:09.0406 5560 IpInIp - ok
21:22:09.0437 5560 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
21:22:09.0437 5560 IpNat - ok
21:22:09.0437 5560 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
21:22:09.0437 5560 IPSec - ok
21:22:09.0484 5560 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
21:22:09.0484 5560 IRENUM - ok
21:22:09.0484 5560 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
21:22:09.0484 5560 isapnp - ok
21:22:09.0515 5560 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
21:22:09.0515 5560 Kbdclass - ok
21:22:09.0515 5560 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
21:22:09.0515 5560 kbdhid - ok
21:22:09.0546 5560 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
21:22:09.0546 5560 kmixer - ok
21:22:09.0562 5560 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
21:22:09.0562 5560 KSecDD - ok
21:22:09.0656 5560 Lavasoft Kernexplorer (6c4a3804510ad8e0f0c07b5be3d44ddb) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys
21:22:09.0656 5560 Lavasoft Kernexplorer - ok
21:22:09.0687 5560 Lbd (336abe8721cbc3110f1c6426da633417) C:\WINDOWS\system32\DRIVERS\Lbd.sys
21:22:09.0687 5560 Lbd - ok
21:22:09.0703 5560 lbrtfdc - ok
21:22:09.0765 5560 lvpopflt (e1158b0cb852db0573922c92e6e564de) C:\WINDOWS\system32\DRIVERS\lvpopflt.sys
21:22:09.0781 5560 lvpopflt - ok
21:22:09.0843 5560 LVPr2Mon (c57c48fb9ae3efb9848af594e3123a63) C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys
21:22:09.0843 5560 LVPr2Mon - ok
21:22:09.0890 5560 LVRS (87ecce893d8aec5a9337b917742d339c) C:\WINDOWS\system32\DRIVERS\lvrs.sys
21:22:09.0890 5560 LVRS - ok
21:22:09.0953 5560 LVUSBSta (be5e104be263921d6842c555db6a5c23) C:\WINDOWS\system32\drivers\LVUSBSta.sys
21:22:09.0953 5560 LVUSBSta - ok
21:22:10.0093 5560 LVUVC (291f69b3dda0f033d2490c5ba5179f7c) C:\WINDOWS\system32\DRIVERS\lvuvc.sys
21:22:10.0140 5560 LVUVC - ok
21:22:10.0156 5560 MBAMSwissArmy - ok
21:22:10.0187 5560 mfehidk (168c565101fd5b9db694efdec91fafa9) C:\WINDOWS\system32\drivers\mfehidk.sys
21:22:10.0187 5560 mfehidk - ok
21:22:10.0218 5560 mferkdk (e0842f67dc9bc4d21d1e319610ebe9e5) C:\WINDOWS\system32\drivers\mferkdk.sys
21:22:10.0218 5560 mferkdk - ok
21:22:10.0218 5560 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
21:22:10.0218 5560 mnmdd - ok
21:22:10.0234 5560 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
21:22:10.0234 5560 Modem - ok
21:22:10.0250 5560 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
21:22:10.0250 5560 Mouclass - ok
21:22:10.0296 5560 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
21:22:10.0296 5560 mouhid - ok
21:22:10.0296 5560 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
21:22:10.0296 5560 MountMgr - ok
21:22:10.0343 5560 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
21:22:10.0343 5560 mraid35x - ok
21:22:10.0343 5560 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
21:22:10.0343 5560 MRxDAV - ok
21:22:10.0390 5560 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
21:22:10.0390 5560 MRxSmb - ok
21:22:10.0390 5560 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
21:22:10.0406 5560 Msfs - ok
21:22:10.0437 5560 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
21:22:10.0437 5560 MSKSSRV - ok
21:22:10.0453 5560 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
21:22:10.0453 5560 MSPCLOCK - ok
21:22:10.0468 5560 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
21:22:10.0468 5560 MSPQM - ok
21:22:10.0468 5560 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
21:22:10.0468 5560 mssmbios - ok
21:22:10.0484 5560 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
21:22:10.0484 5560 MSTEE - ok
21:22:10.0500 5560 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
21:22:10.0500 5560 Mup - ok
21:22:10.0515 5560 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
21:22:10.0515 5560 NABTSFEC - ok
21:22:10.0531 5560 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
21:22:10.0531 5560 NDIS - ok
21:22:10.0546 5560 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
21:22:10.0546 5560 NdisIP - ok
21:22:10.0562 5560 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
21:22:10.0562 5560 NdisTapi - ok
21:22:10.0578 5560 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
21:22:10.0578 5560 Ndisuio - ok
21:22:10.0578 5560 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
21:22:10.0593 5560 NdisWan - ok
21:22:10.0625 5560 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
21:22:10.0625 5560 NDProxy - ok
21:22:10.0625 5560 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
21:22:10.0625 5560 NetBIOS - ok
21:22:10.0656 5560 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
21:22:10.0656 5560 NetBT - ok
21:22:10.0718 5560 NPDriver (65194f525aef541eaa5056eb3d53a25b) C:\WINDOWS\system32\Drivers\NPDRIVER.SYS
21:22:10.0718 5560 NPDriver - ok
21:22:10.0718 5560 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
21:22:10.0734 5560 Npfs - ok
21:22:10.0750 5560 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
21:22:10.0750 5560 Ntfs - ok
21:22:10.0765 5560 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
21:22:10.0765 5560 Null - ok
21:22:10.0828 5560 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
21:22:10.0843 5560 nv - ok
21:22:10.0859 5560 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
21:22:10.0859 5560 NwlnkFlt - ok
21:22:10.0875 5560 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
21:22:10.0875 5560 NwlnkFwd - ok
21:22:10.0890 5560 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
21:22:10.0890 5560 Parport - ok
21:22:10.0890 5560 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
21:22:10.0890 5560 PartMgr - ok
21:22:10.0906 5560 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
21:22:10.0906 5560 ParVdm - ok
21:22:10.0906 5560 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
21:22:10.0906 5560 PCI - ok
21:22:10.0921 5560 PCIDump - ok
21:22:10.0921 5560 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
21:22:10.0921 5560 PCIIde - ok
21:22:10.0968 5560 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
21:22:10.0968 5560 Pcmcia - ok
21:22:10.0984 5560 PDCOMP - ok
21:22:10.0984 5560 PDFRAME - ok
21:22:11.0000 5560 PDRELI - ok
21:22:11.0000 5560 PDRFRAME - ok
21:22:11.0015 5560 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
21:22:11.0015 5560 perc2 - ok
21:22:11.0031 5560 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
21:22:11.0031 5560 perc2hib - ok
21:22:11.0062 5560 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
21:22:11.0062 5560 PptpMiniport - ok
21:22:11.0062 5560 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
21:22:11.0062 5560 PSched - ok
21:22:11.0078 5560 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
21:22:11.0078 5560 Ptilink - ok
21:22:11.0093 5560 PxHelp20 (03e0fe281823ba64b3782f5b38950e73) C:\WINDOWS\system32\Drivers\PxHelp20.sys
21:22:11.0093 5560 PxHelp20 - ok
21:22:11.0109 5560 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
21:22:11.0109 5560 ql1080 - ok
21:22:11.0125 5560 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
21:22:11.0125 5560 Ql10wnt - ok
21:22:11.0140 5560 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
21:22:11.0140 5560 ql12160 - ok
21:22:11.0140 5560 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
21:22:11.0140 5560 ql1240 - ok
21:22:11.0156 5560 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
21:22:11.0156 5560 ql1280 - ok
21:22:11.0156 5560 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
21:22:11.0156 5560 RasAcd - ok
21:22:11.0171 5560 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
21:22:11.0171 5560 Rasl2tp - ok
21:22:11.0187 5560 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
21:22:11.0187 5560 RasPppoe - ok
21:22:11.0187 5560 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
21:22:11.0187 5560 Raspti - ok
21:22:11.0203 5560 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
21:22:11.0203 5560 Rdbss - ok
21:22:11.0203 5560 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
21:22:11.0203 5560 RDPCDD - ok
21:22:11.0234 5560 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
21:22:11.0234 5560 rdpdr - ok
21:22:11.0281 5560 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
21:22:11.0281 5560 RDPWD - ok
21:22:11.0312 5560 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
21:22:11.0312 5560 redbook - ok
21:22:11.0359 5560 SDdriver (11b5e1da4566a68a881a7d73222f4c78) C:\WINDOWS\system32\Drivers\sddriver.sys
21:22:11.0359 5560 SDdriver - ok
21:22:11.0375 5560 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
21:22:11.0375 5560 Secdrv - ok
21:22:11.0406 5560 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
21:22:11.0406 5560 serenum - ok
21:22:11.0437 5560 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
21:22:11.0437 5560 Serial - ok
21:22:11.0437 5560 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
21:22:11.0437 5560 Sfloppy - ok
21:22:11.0453 5560 Simbad - ok
21:22:11.0484 5560 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
21:22:11.0500 5560 sisagp - ok
21:22:11.0500 5560 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
21:22:11.0500 5560 SLIP - ok
21:22:11.0515 5560 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
21:22:11.0515 5560 Sparrow - ok
21:22:11.0546 5560 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
21:22:11.0546 5560 splitter - ok
21:22:11.0562 5560 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
21:22:11.0578 5560 sr - ok
21:22:11.0593 5560 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
21:22:11.0593 5560 Srv - ok
21:22:11.0625 5560 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys
21:22:11.0640 5560 StillCam - ok
21:22:11.0640 5560 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
21:22:11.0640 5560 streamip - ok
21:22:11.0656 5560 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
21:22:11.0656 5560 swenum - ok
21:22:11.0656 5560 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
21:22:11.0671 5560 swmidi - ok
21:22:11.0687 5560 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
21:22:11.0687 5560 symc810 - ok
21:22:11.0703 5560 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
21:22:11.0703 5560 symc8xx - ok
21:22:11.0734 5560 SymEvent (a54ff04bd6e75dc4d8cb6f3e352635e0) C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
21:22:11.0734 5560 SymEvent - ok
21:22:11.0765 5560 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
21:22:11.0765 5560 sym_hi - ok
21:22:11.0781 5560 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
21:22:11.0781 5560 sym_u3 - ok
21:22:11.0812 5560 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
21:22:11.0812 5560 sysaudio - ok
21:22:11.0875 5560 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
21:22:11.0875 5560 Tcpip - ok
21:22:11.0875 5560 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
21:22:11.0875 5560 TDPIPE - ok
21:22:11.0921 5560 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
21:22:11.0921 5560 TDTCP - ok
21:22:11.0921 5560 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
21:22:11.0921 5560 TermDD - ok
21:22:11.0968 5560 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
21:22:11.0968 5560 TosIde - ok
21:22:12.0000 5560 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
21:22:12.0000 5560 Udfs - ok
21:22:12.0031 5560 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
21:22:12.0031 5560 ultra - ok
21:22:12.0046 5560 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
21:22:12.0046 5560 Update - ok
21:22:12.0078 5560 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
21:22:12.0078 5560 usbaudio - ok
21:22:12.0093 5560 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
21:22:12.0093 5560 usbccgp - ok
21:22:12.0109 5560 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
21:22:12.0109 5560 usbehci - ok
21:22:12.0125 5560 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
21:22:12.0125 5560 usbhub - ok
21:22:12.0125 5560 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
21:22:12.0125 5560 usbprint - ok
21:22:12.0171 5560 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
21:22:12.0171 5560 usbscan - ok
21:22:12.0187 5560 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
21:22:12.0187 5560 USBSTOR - ok
21:22:12.0203 5560 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
21:22:12.0203 5560 usbuhci - ok
21:22:12.0218 5560 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
21:22:12.0218 5560 VgaSave - ok
21:22:12.0234 5560 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
21:22:12.0234 5560 viaagp - ok
21:22:12.0250 5560 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
21:22:12.0250 5560 ViaIde - ok
21:22:12.0265 5560 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
21:22:12.0281 5560 VolSnap - ok
21:22:12.0281 5560 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
21:22:12.0281 5560 Wanarp - ok
21:22:12.0343 5560 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINDOWS\system32\DRIVERS\wanatw4.sys
21:22:12.0343 5560 wanatw - ok
21:22:12.0343 5560 WDICA - ok
21:22:12.0359 5560 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
21:22:12.0359 5560 wdmaud - ok
21:22:12.0421 5560 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
21:22:12.0421 5560 WSTCODEC - ok
21:22:12.0453 5560 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
21:22:12.0468 5560 WudfPf - ok
21:22:12.0484 5560 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
21:22:12.0484 5560 WudfRd - ok
21:22:12.0500 5560 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
21:22:12.0781 5560 \Device\Harddisk0\DR0 - ok
21:22:12.0796 5560 Boot (0x1200) (b41806d52cf3a4007be7c67c9d7a6af2) \Device\Harddisk0\DR0\Partition0
21:22:12.0796 5560 \Device\Harddisk0\DR0\Partition0 - ok
21:22:12.0796 5560 ============================================================
21:22:12.0796 5560 Scan finished
21:22:12.0796 5560 ============================================================
21:22:12.0812 6044 Detected object count: 0
21:22:12.0812 6044 Actual detected object count: 0
21:22:22.0656 4664 Deinitialize success
Sunyata, The Farbar scan as requested. Please note this computer was taken from the original owner to be "fixed" so the IPs are different. Connected through my router established internet connection but at their home the behavior is different. I'm hoping to clear this machine of all malware with your expert advice. Farbar: Farbar Service Scanner Version: 13-02-2012 Ran by [removed] (administrator) on 13-02-2012 at 18:57:30 Running from "C:\Documents and Settings\Joan Sciarra\Desktop\Farbar" Microsoft Windows XP Professional Service Pack 3 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Yahoo IP is accessible. File Check: ======== C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit C:\WINDOWS\system32\svchost.exe => MD5 is legit C:\WINDOWS\system32\rpcss.dll => MD5 is legit C:\WINDOWS\system32\services.exe => MD5 is legit Extra List: ======= Avgtdix(10) Gpc(6) IPSec(4) NetBT(5) PSched(7) Tcpip(3) 0x0900000004000000010000000200000003000000080000000A0000000500000006000000070000 00 IpSec Tag value is correct. **** End of log ****
Hello learn2beabum

It looks like you are infected with the ZeroAccess rootkit. One of the capabilities of this infection includes a "backdoor." Backdoors are very dangerous because they use advanced techniques as a means of accessing a computer system that bypasses security mechanisms. They can gain unauthorized access to your computer and take control of it without your knowledge, stealing sensitive information which they send back to the hacker.

If your computer was used for online banking, has credit card information or other sensitive data on it, all passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised. They should be changed by using a different computer and not the infected one. If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified of the possible security breach. Please read How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud for more information.

We can remove what we see that needs to be removed, but I cannot guarantee that we can get your computer completely clean. With this type of infection, the hacker may have left other means to access your computer that we cannot detect. The only way to guarantee a clean computer after such an infection is to "flatten" it. This means we must do a low-level reformat of your drive and re-install the operating system.




Please respond how you wish to proceed: Malware removal, or OS reinstall.




If you wish to proceed with malware removal, please do the following:

Please read through these instructions to familarize yourself with what to expect when this tool runs

Please download ComboFix from one of the following locations:

  • LINK 1
  • LINK 2
**IMPORTANT! Save ComboFix to your Desktop. Read the following thoroughly
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link :How to Disable your Security Programs
  • Double click on 'ComboFix.exe' & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message box:



[external image: Posted Image]


Click on 'Yes', to continue scanning for malware.

When finished, it will produce a log for you.
Please include the contents of C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making Internet Explorer the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please let me know.
5. ComboFix disconnects your machine from the internet. The connection is automatically restored before ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


In your next reply please post the log created by ComboFix.
Sunyata,

I'd like to attempt Malware Removal.

I downloaded ComboFix as indicated and had it run through it's process. Microsoft Windows Recovery was downloaded and installed by ComboFix. It then proceeded to scan the system and located the Trojan but asked to reboot. Upon reboot, ComboFix intialized and ran through all stages and proceed with delete (4) files but hung for 2+ hours. I ended up shutting down the system and re-running ComboFix but arrived at the same hung state.

The C: drive did contain the ComboFix log. Though there was a ComboFix icon that looped back to C: when double clicked.
Hello learn2beabum

The C: drive did contain the ComboFix log.

Please post the output from all the ComboFix runs…

Output from your latest run should be in:

C:\ComboFix.txt

Output from all your previous runs should be in:

C:\Qoobox\ComboFix2.txt
C:\Qoobox\ComboFix3.txt
…
etc

Hello learn2beabum

The C: drive did contain the ComboFix log.

Please post the output from all the ComboFix runs…

Output from your latest run should be in:

C:\ComboFix.txt

Output from all your previous runs should be in:

C:\Qoobox\ComboFix2.txt
C:\Qoobox\ComboFix3.txt
…
etc


Hello Sunyata,

When I said The C: drive did contain the ComboFix log. I intended but omitted there were NO logs available in either the C: or C:\Qoobox. The closest file resembling a log was a catchme.txt.

I have attempted to run ComboFix again but I do not believe it can complete a Full Run of the "Fix". When initiated the program starts and detects rootkit activity and prompts for a restart. The restart does not occur automatically, one has to power down the system and restart. Upon attempting to login to the designated user account, ComboFix self populates and runs through the "stages". It quarantines some files and never progresses further…

I apologize for not re-reading my previous post regarding the ComboFix log. Looking forward to our next step.
Hello learn2beabum

there were NO logs available in either the C: or C:\Qoobox.

Gotcha, thanks. :thumbup:

Let's try running ComboFix in safe mode…
  • Please restart your computer and boot into Safe Mode (without networking)

    To get into the Windows Safe mode, as the computer is booting keep tapping your "F8 Key" which should bring up the "Windows Advanced Options Menu" . Use your arrow keys to move to "Safe Mode" and press your Enter key.

  • Run ComboFix from there.
  • Boot back into normal mode.
  • Please post the log back here.

Also, please post the contents C:\Qoobox\ComboFix-quarantined-files.txt after this ComboFix run.
Launched into safe mode. The ComboFix scan ran and noticed zeroaccess rootkit activity. It asked to restart and I logged into safe mode once again. The scan never completed and remained hung after attempting to delete some files. I could not locate any logs once again. Below is the catchme.txt file located in C:\Qoobox\Quarantined\catchme.txt ——– 2012-02-15 - 22:52:39 ————- ——– 2012-02-15 - 22:54:30 ————- file zipped: C:\WINDOWS\$NtUninstallKB38549$\3012947006 -> _3012947006_.zip -> 3012947006 ( 0 bytes ) error: C:\WINDOWS\$NtUninstallKB38549$\3012947006 is not a PE file kill file error: C:\WINDOWS\$NtUninstallKB38549$\3012947006, The file can not be accessed by the system. ——– 2012-02-15 - 23:13:49 ————- ——– 2012-02-16 - 19:08:03 ————- file zipped: C:\WINDOWS\$NtUninstallKB38549$\3355596859 -> _3355596859_.zip -> 3355596859 ( 0 bytes ) error: C:\WINDOWS\$NtUninstallKB38549$\3355596859 is not a PE file kill file error: C:\WINDOWS\$NtUninstallKB38549$\3355596859, The file can not be accessed by the system. ——– 2012-02-16 - 20:41:15 ————- ——– 2012-02-16 - 20:59:37 ————- ——– 2012-02-16 - 22:04:08 ————- file zipped: C:\WINDOWS\$NtUninstallKB38549$\3852886895 -> _3852886895_.zip -> 3852886895 ( 0 bytes ) error: C:\WINDOWS\$NtUninstallKB38549$\3852886895 is not a PE file kill file error: C:\WINDOWS\$NtUninstallKB38549$\3852886895, The file can not be accessed by the system. ——– 2012-02-16 - 22:13:54 ————- file zipped: C:\WINDOWS\$NtUninstallKB38549$\3852886895 -> _3852886895_.zip -> 3852886895.1 ( 0 bytes ) error: C:\WINDOWS\$NtUninstallKB38549$\3852886895 is not a PE file kill file error: C:\WINDOWS\$NtUninstallKB38549$\3852886895, The file can not be accessed by the system.
Hello learn2beabum

Please download SystemLook by jpshortstuff from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :dir
    C:\Qoobox /s
    C:\WINDOWS\$NtUninstallKB38549$ /s
    
    :reg
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems /s

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Next, we need to run an OTL Fix

  • Please reopen [external image: Posted Image].
  • Copy and Paste the following code into the [external image: Posted Image] textbox. Do not include the word "Code"

    :Services
    pinger
    
    :OTL
    O4 - HKLM..\Run: [] File not found
    O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
    O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html File not found
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [2011/12/16 14:34:24 | 000,014,514 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\t3kq45l3wr8uuf
    [2011/12/07 12:40:28 | 000,000,062 | —- | C] () – C:\Documents and Settings\All Users\Application Data\SgsD7yoLQGcUrt.lic
    [2011/12/07 12:21:03 | 000,000,296 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~SgsD7yoLQGcUrt
    [2011/12/07 12:21:03 | 000,000,184 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~SgsD7yoLQGcUrtr
    [2011/12/07 12:21:00 | 000,000,520 | —- | C] () – C:\Documents and Settings\All Users\Application Data\SgsD7yoLQGcUrt
    
    :Files
    C:\WINDOWS\system32\lxda_device.dll
    C:\WINDOWS\System32\dds_trash_log.cmd
    C:\WINDOWS\tasks\At*.job
    
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [resethosts]
    [Reboot]

  • Push [external image: Posted Image]
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click [external image: Posted Image].
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
How is the machine behaving now? Are there still issues?
Sunyata, It seems as though our work went for naught the hard drive took a nose dive (e.g. unmountable boot volume). This was a previous issue I was unaware of until notified by the hard drives owner. Unfortunately it will be replaced via warranty. I thank you for your time and assistance with this issue it was greatly appreciated. Thanks to all the tech contributors for their tireless efforts.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI