This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cannot access search engines (google, etc) [Solved]

41 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi DJKara,

Next time you see that popup from Avast could you take a screen shot and show it to me please? Thanks.

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    FF - prefs.js..keyword.URL: "http://www.bing.com/search?pc=Z171&form=ZGAADF&install_date=20111116&q="
    [2011-11-17 04:19:53 | 000,001,945 | —- | M] () – C:\Users\HP\AppData\Roaming\Mozilla\Firefox\Profiles\xppp7i3m.default\searchplugins\bing-zugo.xml
    [2011-10-02 19:59:56 | 000,004,573 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\danawa-kr.xml
    [2011-10-02 19:59:56 | 000,007,980 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\daum-kr.xml
    [2011-10-02 19:59:56 | 000,004,262 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\naver-kr.xml
    [2011-10-02 19:59:56 | 000,001,196 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia-kr.xml
    [2011-10-02 19:59:56 | 000,001,103 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-kr.xml
    O4 - HKLM..\Run: [adobearm] C:\Windows\adobearm.exe File not found
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
OTL logfile created on: 2012-03-30 오전 4:04:02 - Run 3
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\HP\Desktop
Enterprise Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000412 | Country: 대한민국 | Language: KOR | Date Format: yyyy-MM-dd

2.97 Gb Total Physical Memory | 1.88 Gb Available Physical Memory | 63.31% Memory free
5.93 Gb Paging File | 4.74 Gb Available in Paging File | 79.83% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 110.61 Gb Total Space | 47.62 Gb Free Space | 43.06% Space Free | Partition Type: NTFS
Drive D: | 178.30 Gb Total Space | 171.73 Gb Free Space | 96.32% Space Free | Partition Type: NTFS
Drive E: | 9.18 Gb Total Space | 1.62 Gb Free Space | 17.60% Space Free | Partition Type: NTFS

Computer Name: HP-PC | User Name: HP | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\HP\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation)
PRC - C:\Program Files\Steam\Steam.exe (Valve Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Cisco\Cisco NAC Agent\NACAgent.exe (Cisco Systems, Inc.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
PRC - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
PRC - C:\Program Files\WTouch\WTouchUser.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\WTouch\WTouchService.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\vcsFPService.exe (Validity Sensors, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\AEstSrv.exe (Andrea Electronics Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Steam\bin\libcef.dll ()
MOD - C:\Program Files\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()


========== Win32 Services (SafeList) ==========

SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (NACAgent) – C:\Program Files\Cisco\Cisco NAC Agent\NACAgent.exe (Cisco Systems, Inc.)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (HssTrayService) – C:\Program Files\Hotspot Shield\bin\HssTrayService.exe ()
SRV - (HssWd) – C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
SRV - (HssSrv) – C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
SRV - (WTouchService) – C:\Program Files\WTouch\WTouchService.exe (Wacom Technology, Corp.)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\stacsv.exe (IDT, Inc.)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (vcsFPService) – C:\Windows\System32\vcsFPService.exe (Validity Sensors, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\AEstSrv.exe (Andrea Electronics Corporation)


========== Driver Services (SafeList) ==========

DRV - (VGPU) – System32\drivers\rdvgkmd.sys File not found
DRV - (USBCCID) – system32\DRIVERS\RtsUCcid.sys File not found
DRV - (tsusbhub) – system32\drivers\tsusbhub.sys File not found
DRV - (Synth3dVsc) – System32\drivers\synth3dvsc.sys File not found
DRV - (RtsUIR) – system32\DRIVERS\Rts516xIR.sys File not found
DRV - (EverestDriver) – C:\Program Files\Lavalys\EVEREST Home Edition\kerneld.wnt File not found
DRV - (EagleXNt) – C:\Windows\system32\drivers\EagleXNt.sys File not found
DRV - (EagleNT) – C:\Windows\system32\drivers\EagleNT.sys File not found
DRV - (catchme) – C:\Users\HP\AppData\Local\Temp\catchme.sys File not found
DRV - (ALSysIO) – C:\Users\HP\AppData\Local\Temp\ALSysIO.sys File not found
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr2.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (Mkd2kfNt) – C:\Windows\System32\drivers\Mkd2kfNT.sys (AhnLab, Inc.)
DRV - (Mkd2Nadr) – C:\Windows\System32\drivers\Mkd2Nadr.sys (AhnLab, Inc.)
DRV - (Mkd2Bthf) – C:\Windows\System32\drivers\Mkd2BthF.sys (AhnLab, Inc.)
DRV - (AhnRec2k) – C:\Windows\System32\drivers\AhnRec2k.sys (AhnLab, Inc.)
DRV - (AhnFlt2k) – C:\Windows\System32\drivers\AhnFlt2k.sys (AhnLab, Inc.)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (RdpVideoMiniport) – C:\Windows\System32\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV - (WinUSB) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (HssDrv) – C:\Windows\System32\drivers\HssDrv.sys (AnchorFree Inc.)
DRV - (taphss) – C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (Serial) – C:\Windows\System32\drivers\serial.sys (Brother Industries Ltd.)
DRV - (RSUSBSTOR) – C:\Windows\System32\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (WacomVTHid) – C:\Windows\System32\drivers\WacomVTHid.sys (Wacom Technology)
DRV - (wacomvhid) – C:\Windows\System32\drivers\wacomvhid.sys (Wacom Technology)
DRV - (WinDriver6) – C:\Windows\System32\drivers\windrvr6.sys (Jungo)
DRV - (hpdskflt) – C:\Windows\System32\drivers\hpdskflt.sys (Hewlett-Packard Corporation)
DRV - (Accelerometer) – C:\Windows\System32\drivers\Accelerometer.sys (Hewlett-Packard Corporation)
DRV - (wacommousefilter) – C:\Windows\System32\drivers\wacommousefilter.sys (Wacom Technology)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search, =
IE - HKLM\..\SearchScopes,DefaultScope =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=Z171&install;_date=20111116
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search, =
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.daum.net/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {313A863A-14AB-4171-B625-945C19559C78}:1.9.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@gomtv.com/gomtvx-plugin: C:\Program Files\Common Files\GRETECH\npgomtvx_nie.dll (Gretech Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.3.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.3.1: C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.com/NxGame: C:\ProgramData\Nexon\NGM\npnxgame.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-03-26 08:47:16 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-03-26 01:35:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-03-26 09:15:39 | 000,000,000 | —D | M]

[2010-12-22 13:08:39 | 000,000,000 | —D | M] (No name found) – C:\Users\HP\AppData\Roaming\mozilla\Extensions
[2012-01-08 09:09:37 | 000,000,000 | —D | M] (No name found) – C:\Users\HP\AppData\Roaming\mozilla\Firefox\Profiles\xppp7i3m.default\extensions
[2012-01-08 15:28:16 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010-12-22 13:11:42 | 000,000,000 | —D | M] (afurladvisor) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2012-03-26 08:47:16 | 000,000,000 | —D | M] (avast! WebRep) – C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
() (No name found) – C:\USERS\HP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XPPP7I3M.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012-03-18 06:09:36 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010-07-27 16:13:46 | 000,027,136 | —- | M] (NHN USA Inc.) – C:\Program Files\mozilla firefox\plugins\npijjiautoinstallpluginff.dll

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\HP\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.83\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.83\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.83\pdf.dll
CHR - plugin: ijji Auto Install Plugin for Mozilla (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: gomtvx NIE Module (Enabled) = C:\Program Files\Common Files\GRETECH\npgomtvx_nie.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: Java™ Platform SE 7 U3 (Enabled) = C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.30.255 (Enabled) = C:\Windows\system32\npDeployJava1.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\Nexon\NGM\npnxgame.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: avast! WebRep = C:\Users\HP\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1426_0\

O1 HOSTS File: ([2012-03-30 03:55:25 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [HncUpdate] C:\Program Files\Common Files\Hnc\HncUtils\HncUpdate.exe (Haansoft Inc.)
O4 - HKLM..\Run: [NACAgentUI] C:\Program Files\Cisco\Cisco NAC Agent\NACAgentUI.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation)
O4 - Startup: C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {063F7D71-5E0B-48F2-87D5-F63C5917947E} https://platform.nexon.com/activex/ahnlab/aosmgr.cab (Reg Error: Key error.)
O16 - DPF: {4D2D3A17-9B46-483C-A5F4-1DC471080009} https://resnet-cca1-cpl.reshsg.uci.edu/auth/taweb.cab (Cisco NAC Web Agent Control)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {8768D5EA-5412-4810-A032-09AD2A726C69} http://bgweb.nowcdn.co.kr/Bin/DownStarter2.cab (DownStarter2 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.3.1)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D452612B-B145-468A-9913-C15AB1D5A9BC}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-06-11 06:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012-03-26 09:16:52 | 000,000,000 | —D | C] – C:\Program Files\Oracle
[2012-03-26 09:16:11 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012-03-26 09:15:39 | 000,637,848 | —- | C] (Oracle Corporation) – C:\Windows\System32\npdeployJava1.dll
[2012-03-26 09:11:32 | 088,210,392 | —- | C] (Oracle Corporation) – C:\Users\HP\Desktop\jdk-7u3-windows-i586.exe
[2012-03-26 09:05:43 | 000,000,000 | —D | C] – C:\Users\HP\Desktop\JavaRa
[2012-03-26 08:48:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2012-03-26 08:48:15 | 000,020,696 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2012-03-26 08:48:11 | 000,337,880 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2012-03-26 08:48:08 | 000,044,376 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswRdr2.sys
[2012-03-26 08:48:06 | 000,053,848 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2012-03-26 08:48:04 | 000,612,184 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2012-03-26 08:48:00 | 000,057,688 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2012-03-26 08:47:00 | 000,041,184 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2012-03-26 08:46:59 | 000,201,352 | —- | C] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2012-03-26 08:46:49 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2012-03-26 08:46:49 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2012-03-26 06:13:43 | 000,000,000 | —D | C] – C:\_OTL
[2012-03-26 06:12:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012-03-26 06:12:12 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2012-03-26 06:11:36 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Users\HP\Desktop\erunt-setup.exe
[2012-03-26 01:45:07 | 000,593,920 | —- | C] (OldTimer Tools) – C:\Users\HP\Desktop\OTL.exe
[2012-03-26 01:40:22 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2012-03-26 01:40:22 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012-03-26 01:40:22 | 001,798,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012-03-26 01:40:22 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012-03-26 01:40:22 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2012-03-26 01:40:22 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2012-03-26 01:40:22 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2012-03-26 01:40:22 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2012-03-26 01:40:22 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2012-03-26 01:40:22 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012-03-26 01:40:22 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2012-03-26 01:40:22 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2012-03-26 01:40:22 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012-03-26 01:40:22 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2012-03-26 01:40:22 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2012-03-26 01:40:22 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2012-03-26 01:40:22 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2012-03-26 01:40:22 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2012-03-26 01:40:22 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2012-03-26 01:40:22 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2012-03-26 01:40:22 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2012-03-26 01:40:22 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2012-03-26 01:40:22 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2012-03-26 01:40:22 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2012-03-26 01:40:22 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2012-03-26 01:40:22 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2012-03-26 01:40:22 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2012-03-26 01:40:22 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2012-03-26 01:40:22 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2012-03-26 01:40:22 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012-03-26 01:40:22 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2012-03-26 01:40:22 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2012-03-26 01:40:22 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2012-03-26 01:40:22 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2012-03-26 01:40:22 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2012-03-26 01:40:22 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2012-03-26 01:40:22 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2012-03-26 01:37:23 | 000,481,584 | —- | C] (Microsoft Corporation) – C:\Users\HP\Desktop\IE9-Windows7-x86-enu.exe
[2012-03-26 01:33:08 | 001,832,544 | —- | C] (McAfee, Inc.) – C:\Users\HP\Desktop\MCPR.exe
[2012-03-25 09:47:17 | 000,000,000 | —D | C] – C:\Windows\temp
[2012-03-25 09:45:37 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012-03-25 09:17:05 | 000,000,000 | —D | C] – C:\ComboFix
[2012-03-25 06:42:03 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012-03-25 06:41:45 | 002,322,184 | —- | C] (ESET) – C:\Users\HP\Desktop\esetsmartinstaller_enu.exe
[2012-03-25 04:09:51 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012-03-25 04:09:51 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012-03-25 04:09:51 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012-03-25 04:09:45 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012-03-25 03:53:09 | 000,000,000 | —D | C] – C:\Qoobox
[2012-03-25 03:49:04 | 004,443,082 | R— | C] (Swearware) – C:\Users\HP\Desktop\ComboFix.exe
[2012-03-24 15:56:45 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{AD38D804-88BF-40D9-BA51-DF842EE015D8}
[2012-03-24 15:56:33 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{B7A87462-C223-4F87-B853-29C0838DFF37}
[2012-03-24 13:26:03 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\HP\Desktop\aswMBR.exe
[2012-03-24 13:20:51 | 000,607,260 | R— | C] (Swearware) – C:\Users\HP\Desktop\dds.com
[2012-03-24 06:36:41 | 000,014,664 | —- | C] (McAfee, Inc.) – C:\Windows\stinger.sys
[2012-03-24 06:35:23 | 000,000,000 | —D | C] – C:\Program Files\stinger
[2012-03-24 03:55:58 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{03429C96-A834-4891-AF0A-99CB9A8CE3B8}
[2012-03-24 03:55:45 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{AEA3B850-409A-4123-B81B-BE68232482A1}
[2012-03-23 04:07:35 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{06E11339-D8E7-4239-B75E-BB745467FE34}
[2012-03-22 16:50:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp
[2012-03-22 16:50:18 | 000,000,000 | —D | C] – C:\Program Files\Core Temp
[2012-03-22 13:54:22 | 000,527,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_7.dll
[2012-03-22 13:54:22 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_5.dll
[2012-03-22 13:54:21 | 000,239,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_7.dll
[2012-03-22 13:54:19 | 002,106,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_43.dll
[2012-03-22 13:54:19 | 001,868,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dcsx_43.dll
[2012-03-22 13:54:17 | 000,248,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx11_43.dll
[2012-03-22 13:54:16 | 000,470,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_43.dll
[2012-03-22 13:54:15 | 001,998,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_43.dll
[2012-03-22 13:54:14 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_4.dll
[2012-03-22 13:54:13 | 000,528,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_6.dll
[2012-03-22 13:54:13 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_6.dll
[2012-03-22 13:54:12 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_7.dll
[2012-03-22 13:54:10 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_5.dll
[2012-03-22 13:54:08 | 001,974,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_42.dll
[2012-03-22 13:54:08 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_5.dll
[2012-03-22 13:54:07 | 005,501,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dcsx_42.dll
[2012-03-22 13:54:07 | 000,235,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx11_42.dll
[2012-03-22 13:54:06 | 004,178,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_41.dll
[2012-03-22 13:54:06 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_42.dll
[2012-03-22 13:54:05 | 000,517,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_4.dll
[2012-03-22 13:54:05 | 000,235,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_4.dll
[2012-03-22 13:54:05 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_3.dll
[2012-03-22 13:54:05 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_6.dll
[2012-03-22 13:54:04 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_40.dll
[2012-03-22 13:54:04 | 002,036,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_40.dll
[2012-03-22 13:54:04 | 000,452,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_40.dll
[2012-03-22 13:54:03 | 000,514,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_3.dll
[2012-03-22 13:54:03 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_2.dll
[2012-03-22 13:54:03 | 000,235,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_3.dll
[2012-03-22 13:54:03 | 000,070,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_2.dll
[2012-03-22 13:54:03 | 000,023,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_5.dll
[2012-03-22 13:54:01 | 000,507,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_1.dll
[2012-03-22 13:54:01 | 000,065,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_0.dll
[2012-03-22 13:54:00 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_1.dll
[2012-03-22 13:54:00 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_4.dll
[2012-03-22 13:53:59 | 003,850,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_38.dll
[2012-03-22 13:53:59 | 001,491,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_38.dll
[2012-03-22 13:53:59 | 000,479,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_0.dll
[2012-03-22 13:53:59 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_38.dll
[2012-03-22 13:53:58 | 001,420,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_37.dll
[2012-03-22 13:53:58 | 000,462,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_37.dll
[2012-03-22 13:53:58 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_0.dll
[2012-03-22 13:53:58 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_3.dll
[2012-03-22 13:53:57 | 003,786,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_37.dll
[2012-03-22 13:53:57 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_10.dll
[2012-03-22 13:53:56 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_36.dll
[2012-03-22 13:53:56 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_36.dll
[2012-03-22 13:53:56 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_36.dll
[2012-03-22 13:53:54 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_9.dll
[2012-03-22 13:53:53 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_35.dll
[2012-03-22 13:53:53 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_35.dll
[2012-03-22 13:53:52 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_35.dll
[2012-03-22 13:53:51 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_34.dll
[2012-03-22 13:53:51 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_8.dll
[2012-03-22 13:53:51 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_2.dll
[2012-03-22 13:53:50 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_34.dll
[2012-03-22 13:53:50 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_34.dll
[2012-03-22 13:53:49 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_7.dll
[2012-03-22 13:53:49 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xinput1_3.dll
[2012-03-22 13:53:48 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_33.dll
[2012-03-22 13:53:47 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_33.dll
[2012-03-22 13:53:47 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_33.dll
[2012-03-22 13:53:46 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_6.dll
[2012-03-22 13:53:45 | 000,440,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10.dll
[2012-03-22 13:53:45 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_5.dll
[2012-03-22 13:53:44 | 003,426,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_32.dll
[2012-03-22 13:53:43 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_4.dll
[2012-03-22 13:53:43 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\x3daudio1_1.dll
[2012-03-22 13:53:42 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_3.dll
[2012-03-22 13:53:42 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xinput1_2.dll
[2012-03-22 13:53:41 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_2.dll
[2012-03-22 13:53:41 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xinput1_1.dll
[2012-03-22 13:53:37 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_1.dll
[2012-03-22 13:53:30 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_30.dll
[2012-03-22 13:53:28 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_0.dll
[2012-03-22 13:53:28 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\x3daudio1_0.dll
[2012-03-22 13:53:25 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_29.dll
[2012-03-22 13:53:25 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_28.dll
[2012-03-22 13:53:24 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_27.dll
[2012-03-22 13:53:24 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_26.dll
[2012-03-22 13:53:23 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_25.dll
[2012-03-22 13:53:23 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_24.dll
[2012-03-22 13:50:51 | 000,876,864 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvhdagenco3220103.dll
[2012-03-22 13:50:51 | 000,067,392 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvapo32v.dll
[2012-03-22 13:50:50 | 000,148,800 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\drivers\nvhda32v.sys
[2012-03-22 13:50:50 | 000,061,248 | —- | C] (Khronos Group) – C:\Windows\System32\OpenCL.dll
[2012-03-22 13:50:50 | 000,027,968 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvhdap32.dll
[2012-03-22 13:50:48 | 019,444,544 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvoglv32.dll
[2012-03-22 13:50:48 | 010,819,392 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\drivers\nvlddmkm.sys
[2012-03-22 13:50:48 | 000,881,984 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvgenco32.dll
[2012-03-22 13:50:47 | 001,000,256 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvdispco32.dll
[2012-03-22 13:50:46 | 005,892,928 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcuda.dll
[2012-03-22 13:50:46 | 002,517,312 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcuvid.dll
[2012-03-22 13:50:46 | 002,437,440 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcuvenc.dll
[2012-03-22 13:50:41 | 017,543,488 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcompiler.dll
[2012-03-22 13:50:20 | 000,000,000 | —D | C] – C:\Windows\System32\directx
[2012-03-22 13:31:54 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{8168CD97-9A23-4427-82BE-FDA313980261}
[2012-03-22 13:31:25 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{00E5D3AE-2CAA-4537-AF1A-2A1946CD434C}
[2012-03-22 08:57:27 | 000,000,000 | —D | C] – C:\ProgramData\RegInOut
[2012-03-22 08:57:23 | 000,000,000 | —D | C] – C:\Windows\RegInOut System Utilities
[2012-03-22 00:21:47 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{B7A45785-CABF-4C0C-9839-16439F7C507C}
[2012-03-22 00:21:05 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{FBF81C77-4A77-4D41-9BA9-23AB92171F1F}
[2012-03-21 06:54:54 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{99DC73F4-14ED-438D-AFBC-1C3BE31C4F96}
[2012-03-21 06:54:39 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{F55600A8-8392-4BE9-96A2-8B57D90217F4}
[2012-03-20 03:18:44 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{2F039A8F-421C-4C42-8E8F-D0B8D1F469D5}
[2012-03-20 03:18:30 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{2688C2E0-C258-4709-8314-856CD555CC28}
[2012-03-19 04:15:08 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{657CF891-17C7-41EA-96FE-ECCBE05B40F5}
[2012-03-19 04:14:56 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{1E795CEA-A667-4BF4-9976-52E0E3A0EDEA}
[2012-03-18 04:12:27 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{BAFFD651-32AA-46CB-8A3A-3778696D7A08}
[2012-03-17 02:37:58 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{B9617E96-1D18-42C1-9886-E924B906500B}
[2012-03-17 02:37:46 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{525A9230-76D4-4DCD-AC52-B16235B72601}
[2012-03-16 02:55:30 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{DB469B46-115C-485E-A4EB-226527DA54C0}
[2012-03-16 02:55:18 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{F3E5EF70-75EF-4D44-9EC0-6C901016C396}
[2012-03-15 03:01:41 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{7C0A185C-D9EF-4B42-AF13-271C6C0DEB25}
[2012-03-15 03:01:28 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{FFEB93F8-2B14-4B74-907F-D2EBA23F44C6}
[2012-03-14 18:00:33 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012-03-14 18:00:32 | 003,913,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012-03-14 04:49:00 | 002,343,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012-03-14 04:48:59 | 001,077,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2012-03-14 04:48:27 | 000,129,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcorekmts.dll
[2012-03-14 04:48:27 | 000,058,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpwsx.dll
[2012-03-14 04:48:27 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdrmemptylst.exe
[2012-03-14 04:48:24 | 000,919,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcorets.dll
[2012-03-14 04:48:24 | 000,826,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcore.dll
[2012-03-14 04:42:55 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{E618FC98-D12C-44A8-972E-BC98B22D68FD}
[2012-03-14 04:42:43 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{81D64C38-C37F-4337-9505-0A1A932EE4F1}
[2012-03-13 03:22:06 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{85C53300-C8E8-44EA-A019-E672A7EF6486}
[2012-03-13 03:21:54 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{D5B59B08-2B6A-4AC3-BA51-D8443046E47A}
[2012-03-10 03:29:58 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{1A8FBA77-E627-40F4-BB66-4E6760DF977C}
[2012-03-10 03:29:45 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{A24AA38C-6441-4362-BC00-CC4A04F8AED9}
[2012-03-09 09:02:52 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{B71C29A6-A159-441B-9BF6-5AD3090A4183}
[2012-03-09 09:02:36 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{59B7DFA4-16DF-4CF9-BA46-18706365877F}
[2012-03-08 03:51:47 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{FE127C6A-29B1-43AA-A53C-BF70A49FB09D}
[2012-03-08 03:51:13 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{041F476B-114E-4735-BD72-5FB6FA60FF9B}
[2012-03-07 03:31:01 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{45638CF8-743A-42A3-9570-BA897000E589}
[2012-03-07 03:30:45 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{06CC1E6A-C77C-4135-8B59-F853DD3ABAF3}
[2012-03-06 10:47:47 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{53EB42B5-1650-47A6-A276-129E56D684B9}
[2012-03-06 10:47:18 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{04263AB4-D308-47CE-8E82-D69B5C25BF53}
[2012-03-05 19:11:43 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{87315574-EDB8-4118-B296-0E40B2DF9ECB}
[2012-03-05 19:11:28 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{7680F0CB-38E1-4F3E-A98B-0C3B1F732C1F}
[2012-03-05 06:29:59 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{A4AE3AAA-D2B6-48C3-97C8-89B1BF373C8F}
[2012-03-05 06:29:45 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{92E1D5CB-DC52-4CD4-B7CF-0BDC46B8C405}
[2012-03-04 07:41:25 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{FF0DC55D-D0C8-4B28-AD38-134942FE3C20}
[2012-03-04 07:41:08 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{FDB16D65-4484-4202-AA25-DF1F0E07C8B0}
[2012-03-03 02:57:08 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{9BDF1174-0276-49C1-8611-7FD805EB0583}
[2012-03-03 02:56:59 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{483EF275-2FF8-484F-ABFD-AD44DEFA5F32}
[2012-03-02 08:54:24 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{B3456874-A00C-4A70-921C-4324F82E12CE}
[2012-03-02 08:54:12 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{704059F5-24CE-493A-9EE9-122228AE06C5}
[2012-03-01 18:30:17 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{33AE340B-3B50-4603-BA00-D3F6F3C9E744}
[2012-03-01 18:30:04 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{DDE619BA-BC92-4FB1-8088-ED9371F58CA2}
[2012-03-01 03:46:02 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{0E09CC39-CEEC-4C26-8972-6CB15294E82F}
[2012-03-01 03:45:45 | 000,000,000 | —D | C] – C:\Users\HP\AppData\Local\{AA879BE5-0D01-4D98-B11B-DDBAB1C4C9FA}
[2012-02-26 15:24:45 | 001,654,869 | —- | C] (Dynu Systems Inc.) – C:\ProgramData\DynuEncrypt.dll

========== Files - Modified Within 30 Days ==========

[2012-03-30 03:56:55 | 000,000,660 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-03-30 03:56:34 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012-03-30 03:56:28 | 2389,929,984 | -HS- | M] () – C:\hiberfil.sys
[2012-03-30 03:55:54 | 000,012,272 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012-03-30 03:55:54 | 000,012,272 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012-03-30 03:55:25 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2012-03-29 17:32:02 | 000,000,664 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-03-29 15:52:35 | 1851,108,682 | —- | M] () – C:\Windows\MEMORY.DMP
[2012-03-26 09:30:43 | 000,002,570 | —- | M] () – C:\Users\HP\Desktop\Attach.zip
[2012-03-26 09:15:26 | 000,173,960 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2012-03-26 09:15:26 | 000,173,960 | —- | M] (Oracle Corporation) – C:\Windows\System32\java.exe
[2012-03-26 09:12:54 | 088,210,392 | —- | M] (Oracle Corporation) – C:\Users\HP\Desktop\jdk-7u3-windows-i586.exe
[2012-03-26 09:05:31 | 000,160,350 | —- | M] () – C:\Users\HP\Desktop\JavaRa.zip
[2012-03-26 08:48:17 | 000,001,996 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012-03-26 08:48:00 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2012-03-26 08:46:09 | 074,761,776 | —- | M] () – C:\Users\HP\Desktop\avast_free_antivirus_setup.exe
[2012-03-26 06:14:59 | 000,000,000 | —- | M] () – C:\Windows\System32\cd.dat
[2012-03-26 06:12:18 | 000,001,076 | —- | M] () – C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012-03-26 06:12:13 | 000,000,896 | —- | M] () – C:\Users\HP\Desktop\NTREGOPT.lnk
[2012-03-26 06:12:13 | 000,000,877 | —- | M] () – C:\Users\HP\Desktop\ERUNT.lnk
[2012-03-26 06:11:40 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Users\HP\Desktop\erunt-setup.exe
[2012-03-26 01:45:09 | 000,593,920 | —- | M] (OldTimer Tools) – C:\Users\HP\Desktop\OTL.exe
[2012-03-26 01:43:11 | 000,001,409 | —- | M] () – C:\Users\HP\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012-03-26 01:40:22 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2012-03-26 01:40:22 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012-03-26 01:40:22 | 001,798,656 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012-03-26 01:40:22 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012-03-26 01:40:22 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2012-03-26 01:40:22 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2012-03-26 01:40:22 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2012-03-26 01:40:22 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2012-03-26 01:40:22 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2012-03-26 01:40:22 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012-03-26 01:40:22 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2012-03-26 01:40:22 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2012-03-26 01:40:22 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012-03-26 01:40:22 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2012-03-26 01:40:22 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2012-03-26 01:40:22 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2012-03-26 01:40:22 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2012-03-26 01:40:22 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2012-03-26 01:40:22 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2012-03-26 01:40:22 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2012-03-26 01:40:22 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2012-03-26 01:40:22 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2012-03-26 01:40:22 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2012-03-26 01:40:22 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2012-03-26 01:40:22 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2012-03-26 01:40:22 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2012-03-26 01:40:22 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2012-03-26 01:40:22 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2012-03-26 01:40:22 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2012-03-26 01:40:22 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2012-03-26 01:40:22 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012-03-26 01:40:22 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2012-03-26 01:40:22 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2012-03-26 01:40:22 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2012-03-26 01:40:22 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2012-03-26 01:40:22 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2012-03-26 01:40:22 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2012-03-26 01:40:22 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2012-03-26 01:37:23 | 000,481,584 | —- | M] (Microsoft Corporation) – C:\Users\HP\Desktop\IE9-Windows7-x86-enu.exe
[2012-03-26 01:33:08 | 001,832,544 | —- | M] (McAfee, Inc.) – C:\Users\HP\Desktop\MCPR.exe
[2012-03-25 10:27:35 | 000,337,137 | —- | M] () – C:\Users\HP\Desktop\FSS.exe
[2012-03-25 06:41:56 | 002,322,184 | —- | M] (ESET) – C:\Users\HP\Desktop\esetsmartinstaller_enu.exe
[2012-03-25 03:49:18 | 004,443,082 | R— | M] (Swearware) – C:\Users\HP\Desktop\ComboFix.exe
[2012-03-24 15:40:54 | 000,282,920 | —- | M] () – C:\Users\HP\Desktop\Disneyland Ticket.pdf
[2012-03-24 14:03:06 | 000,000,512 | —- | M] () – C:\Users\HP\Desktop\MBR.dat
[2012-03-24 13:26:09 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\HP\Desktop\aswMBR.exe
[2012-03-24 13:20:52 | 000,607,260 | R— | M] (Swearware) – C:\Users\HP\Desktop\dds.com
[2012-03-24 13:16:25 | 000,458,240 | —- | M] () – C:\Users\HP\Desktop\CKScanner.exe
[2012-03-24 06:36:41 | 000,014,664 | —- | M] (McAfee, Inc.) – C:\Windows\stinger.sys
[2012-03-23 11:07:59 | 000,000,765 | —- | M] () – C:\Windows\System32\drivers\etc\hosts.msn
[2012-03-22 16:50:19 | 000,001,103 | —- | M] () – C:\Users\HP\Desktop\Core Temp.lnk
[2012-03-22 09:02:29 | 000,000,967 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012-03-21 17:57:55 | 000,618,912 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012-03-21 17:57:55 | 000,409,586 | —- | M] () – C:\Windows\System32\perfh012.dat
[2012-03-21 17:57:55 | 000,107,232 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012-03-21 17:57:55 | 000,105,562 | —- | M] () – C:\Windows\System32\perfc012.dat
[2012-03-15 02:59:44 | 003,894,184 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012-03-07 09:15:19 | 000,041,184 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2012-03-07 09:15:14 | 000,201,352 | —- | M] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2012-03-07 09:03:51 | 000,612,184 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2012-03-07 09:03:38 | 000,337,880 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2012-03-07 09:02:14 | 000,044,376 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswRdr2.sys
[2012-03-07 09:01:53 | 000,053,848 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2012-03-07 09:01:48 | 000,057,688 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2012-03-07 09:01:30 | 000,020,696 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2012-03-05 06:30:13 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012-03-02 15:52:34 | 000,038,402 | —- | M] () – C:\Users\HP\Desktop\mms.sav
[2012-03-01 08:59:00 | 019,444,544 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvoglv32.dll
[2012-03-01 08:59:00 | 017,543,488 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvcompiler.dll
[2012-03-01 08:59:00 | 015,009,600 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvd3dum.dll
[2012-03-01 08:59:00 | 010,819,392 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\drivers\nvlddmkm.sys
[2012-03-01 08:59:00 | 007,713,088 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvwgf2um.dll
[2012-03-01 08:59:00 | 005,892,928 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvcuda.dll
[2012-03-01 08:59:00 | 002,517,312 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvcuvid.dll
[2012-03-01 08:59:00 | 002,437,440 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvcuvenc.dll
[2012-03-01 08:59:00 | 002,301,248 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvapi.dll
[2012-03-01 08:59:00 | 001,000,256 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvdispco32.dll
[2012-03-01 08:59:00 | 000,881,984 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvgenco32.dll
[2012-03-01 08:59:00 | 000,061,248 | —- | M] (Khronos Group) – C:\Windows\System32\OpenCL.dll
[2012-03-01 08:59:00 | 000,008,772 | —- | M] () – C:\Windows\System32\nvinfo.pb
[2012-03-01 05:56:41 | 003,881,792 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvcpl.dll
[2012-03-01 05:55:16 | 002,719,040 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvsvc.dll
[2012-03-01 05:53:47 | 000,108,352 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvmctray.dll
[2012-03-01 05:53:46 | 000,062,272 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvshext.dll
[2012-03-01 05:53:45 | 002,561,344 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvsvcr.dll

========== Files Created - No Company Name ==========

[2012-03-26 09:05:28 | 000,160,350 | —- | C] () – C:\Users\HP\Desktop\JavaRa.zip
[2012-03-26 08:48:17 | 000,001,996 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012-03-26 08:45:05 | 074,761,776 | —- | C] () – C:\Users\HP\Desktop\avast_free_antivirus_setup.exe
[2012-03-26 06:14:59 | 000,000,000 | —- | C] () – C:\Windows\System32\cd.dat
[2012-03-26 06:12:18 | 000,001,076 | —- | C] () – C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012-03-26 06:12:13 | 000,000,896 | —- | C] () – C:\Users\HP\Desktop\NTREGOPT.lnk
[2012-03-26 06:12:13 | 000,000,877 | —- | C] () – C:\Users\HP\Desktop\ERUNT.lnk
[2012-03-26 01:40:22 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2012-03-25 10:27:34 | 000,337,137 | —- | C] () – C:\Users\HP\Desktop\FSS.exe
[2012-03-25 04:09:51 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012-03-25 04:09:51 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012-03-25 04:09:51 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012-03-25 04:09:51 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012-03-25 04:09:51 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012-03-24 15:40:52 | 000,282,920 | —- | C] () – C:\Users\HP\Desktop\Disneyland Ticket.pdf
[2012-03-24 14:03:06 | 000,000,512 | —- | C] () – C:\Users\HP\Desktop\MBR.dat
[2012-03-24 13:25:23 | 000,002,570 | —- | C] () – C:\Users\HP\Desktop\Attach.zip
[2012-03-24 13:16:23 | 000,458,240 | —- | C] () – C:\Users\HP\Desktop\CKScanner.exe
[2012-03-24 09:11:32 | 1851,108,682 | —- | C] () – C:\Windows\MEMORY.DMP
[2012-03-22 16:50:19 | 000,001,103 | —- | C] () – C:\Users\HP\Desktop\Core Temp.lnk
[2012-03-22 09:02:29 | 000,000,967 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2011-11-17 04:21:27 | 000,000,064 | —- | C] () – C:\Windows\GPlrLanc.dat
[2011-11-06 10:50:52 | 000,000,140 | —- | C] () – C:\Windows\rar_crck.ini
[2011-09-19 16:32:31 | 000,220,052 | -H– | C] () – C:\Windows\System32\mlfcache.dat
[2011-09-19 16:07:46 | 000,015,360 | —- | C] () – C:\Windows\System32\bdmjpeg.dll
[2011-09-19 16:07:32 | 000,058,368 | —- | C] () – C:\Windows\System32\bdmpegv.dll
[2011-07-05 21:39:09 | 000,007,592 | —- | C] () – C:\Users\HP\AppData\Local\Resmon.ResmonCfg
[2011-06-23 11:49:20 | 000,080,896 | —- | C] () – C:\Windows\System32\RDVGHelper.exe
[2011-06-23 11:43:16 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011-05-26 09:44:12 | 000,002,291 | —- | C] () – C:\Users\HP\AppData\Roaming\MPQEditor.ini
[2011-01-03 10:48:38 | 000,000,262 | —- | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010-12-31 23:47:49 | 000,071,017 | —- | C] () – C:\Windows\System32\NeowizFifaDownloaderUninstall.exe
[2010-12-22 13:08:34 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010-12-21 17:42:02 | 000,014,632 | —- | C] () – C:\Windows\System32\WHIDCoinst.dll
[2010-12-21 17:19:08 | 000,000,075 | —- | C] () – C:\Windows\Hjimesv.ini
[2010-12-21 17:17:42 | 000,000,016 | —- | C] () – C:\Windows\System32\winhcfga.ini

< End of report >
Hi,

Please download TDSSKiller
  • Right-click and Run as Administrator TDSSKiller.exe
  • Press Change Parameters
  • Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.
  • Click on the Start Scan button
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
    • Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
  • Copy and paste the log in your next reply
    • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.
———-
Here is the log. Also, I've tested it on firefox and chrome and it is working! I hope this isn't temporary thing :) 10:04:57.0061 5692 TDSS rootkit removing tool [removed] Mar 26 2012 13:40:18 10:04:58.0232 5692 ============================================================ 10:04:58.0232 5692 Current date / time: 2012/03/30 10:04:58.0232 10:04:58.0232 5692 SystemInfo: 10:04:58.0232 5692 10:04:58.0233 5692 OS Version: 6.1.7601 ServicePack: 1.0 10:04:58.0233 5692 Product type: Workstation 10:04:58.0233 5692 ComputerName: HP-PC 10:04:58.0233 5692 UserName: HP 10:04:58.0233 5692 Windows directory: C:\Windows 10:04:58.0233 5692 System windows directory: C:\Windows 10:04:58.0233 5692 Processor architecture: Intel x86 10:04:58.0233 5692 Number of processors: 2 10:04:58.0233 5692 Page size: 0x1000 10:04:58.0233 5692 Boot type: Normal boot 10:04:58.0233 5692 ============================================================ 10:05:01.0132 5692 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 10:05:01.0233 5692 \Device\Harddisk0\DR0: 10:05:01.0361 5692 MBR used 10:05:01.0373 5692 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xDD36000 10:05:01.0373 5692 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0xDD36800, BlocksNum 0x16499000 10:05:01.0373 5692 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x241D0000, BlocksNum 0x125D000 10:05:01.0606 5692 Initialize success 10:05:01.0606 5692 ============================================================ 10:05:35.0397 2660 ============================================================ 10:05:35.0422 2660 Scan started 10:05:35.0422 2660 Mode: Manual; SigCheck; TDLFS; 10:05:35.0422 2660 ============================================================ 10:05:38.0174 2660 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys 10:05:39.0142 2660 1394ohci - ok 10:05:39.0316 2660 Accelerometer (3b10711ad8656c097e0d16a41b29c54c) C:\Windows\system32\DRIVERS\Accelerometer.sys 10:05:39.0342 2660 Accelerometer - ok 10:05:39.0425 2660 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys 10:05:39.0447 2660 ACPI - ok 10:05:39.0586 2660 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys 10:05:39.0735 2660 AcpiPmi - ok 10:05:39.0907 2660 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys 10:05:39.0970 2660 adp94xx - ok 10:05:40.0135 2660 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys 10:05:40.0188 2660 adpahci - ok 10:05:40.0302 2660 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys 10:05:40.0322 2660 adpu320 - ok 10:05:40.0431 2660 AeLookupSvc (8b5eefeec1e6d1a72a06c526628ad161) C:\Windows\System32\aelupsvc.dll 10:05:40.0648 2660 AeLookupSvc - ok 10:05:40.0850 2660 AESTFilters (827dbc22c96eecf6d36a13162fabafd3) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\aestsrv.exe 10:05:41.0132 2660 AESTFilters - ok 10:05:41.0275 2660 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys 10:05:41.0425 2660 AFD - ok 10:05:41.0616 2660 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys 10:05:41.0641 2660 agp440 - ok 10:05:41.0745 2660 AhnFlt2k (d069a80f81c371b49737eccdbbe0e7d1) C:\Windows\system32\Drivers\AhnFlt2k.sys 10:05:41.0965 2660 AhnFlt2k - ok 10:05:42.0127 2660 AhnRec2k (f67773c8d8a77fbcc484b09acac93662) C:\Windows\system32\Drivers\AhnRec2k.sys 10:05:42.0154 2660 AhnRec2k - ok 10:05:42.0377 2660 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys 10:05:42.0446 2660 aic78xx - ok 10:05:42.0661 2660 ALG (18a54e132947cd98fea9accc57f98f13) C:\Windows\System32\alg.exe 10:05:42.0878 2660 ALG - ok 10:05:43.0141 2660 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys 10:05:43.0222 2660 aliide - ok 10:05:43.0470 2660 ALSysIO - ok 10:05:43.0623 2660 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys 10:05:43.0653 2660 amdagp - ok 10:05:43.0713 2660 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys 10:05:43.0729 2660 amdide - ok 10:05:43.0857 2660 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys 10:05:43.0978 2660 AmdK8 - ok 10:05:44.0147 2660 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys 10:05:44.0234 2660 AmdPPM - ok 10:05:44.0429 2660 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys 10:05:44.0453 2660 amdsata - ok 10:05:44.0514 2660 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys 10:05:44.0535 2660 amdsbs - ok 10:05:44.0687 2660 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys 10:05:44.0710 2660 amdxata - ok 10:05:44.0783 2660 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys 10:05:44.0903 2660 AppID - ok 10:05:45.0045 2660 AppIDSvc (62a9c86cb6085e20db4823e4e97826f5) C:\Windows\System32\appidsvc.dll 10:05:45.0225 2660 AppIDSvc - ok 10:05:45.0388 2660 Appinfo (fb1959012294d6ad43e5304df65e3c26) C:\Windows\System32\appinfo.dll 10:05:45.0562 2660 Appinfo - ok 10:05:45.0698 2660 Apple Mobile Device (5aa788d5a2c6737bb9c45933985bc1b8) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 10:05:45.0716 2660 Apple Mobile Device - ok 10:05:45.0835 2660 AppMgmt (a45d184df6a8803da13a0b329517a64a) C:\Windows\System32\appmgmts.dll 10:05:46.0003 2660 AppMgmt - ok 10:05:46.0165 2660 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys 10:05:46.0186 2660 arc - ok 10:05:46.0252 2660 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys 10:05:46.0272 2660 arcsas - ok 10:05:46.0402 2660 aswFsBlk (0ae43c6c411254049279c2ee55630f95) C:\Windows\system32\drivers\aswFsBlk.sys 10:05:46.0476 2660 aswFsBlk - ok 10:05:46.0638 2660 aswMonFlt (6693141560b1615d8dccf0d8eb00087e) C:\Windows\system32\drivers\aswMonFlt.sys 10:05:46.0662 2660 aswMonFlt - ok 10:05:46.0727 2660 aswRdr (225013c16fe096714d71649ad7a20e8b) C:\Windows\System32\Drivers\aswrdr2.sys 10:05:46.0743 2660 aswRdr - ok 10:05:46.0885 2660 aswSnx (dcb199b967375753b5019ec15f008f53) C:\Windows\system32\drivers\aswSnx.sys 10:05:46.0946 2660 aswSnx - ok 10:05:47.0120 2660 aswSP (b32873e5a1443c0a1e322266e203bf10) C:\Windows\system32\drivers\aswSP.sys 10:05:47.0158 2660 aswSP - ok 10:05:47.0398 2660 aswTdi (6ff544175a9180c5d88534d3d9c9a9f7) C:\Windows\system32\drivers\aswTdi.sys 10:05:47.0451 2660 aswTdi - ok 10:05:47.0759 2660 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys 10:05:48.0002 2660 AsyncMac - ok 10:05:48.0276 2660 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys 10:05:48.0301 2660 atapi - ok 10:05:48.0414 2660 AudioEndpointBuilder (ce3b4e731638d2ef62fcb419be0d39f0) C:\Windows\System32\Audiosrv.dll 10:05:48.0608 2660 AudioEndpointBuilder - ok 10:05:48.0694 2660 Audiosrv (ce3b4e731638d2ef62fcb419be0d39f0) C:\Windows\System32\Audiosrv.dll 10:05:48.0838 2660 Audiosrv - ok 10:05:49.0083 2660 avast! Antivirus (4041d31508a2a084dfb42c595854090f) C:\Program Files\AVAST Software\Avast\AvastSvc.exe 10:05:49.0107 2660 avast! Antivirus - ok 10:05:49.0286 2660 AxInstSV (6e30d02aac9cac84f421622e3a2f6178) C:\Windows\System32\AxInstSV.dll 10:05:49.0427 2660 AxInstSV - ok 10:05:49.0576 2660 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys 10:05:49.0731 2660 b06bdrv - ok 10:05:49.0840 2660 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys 10:05:49.0955 2660 b57nd60x - ok 10:05:50.0104 2660 BCM43XX (eb7c2dadf52f50f69f198c14c3556dc1) C:\Windows\system32\DRIVERS\bcmwl6.sys 10:05:50.0275 2660 BCM43XX - ok 10:05:50.0415 2660 BDESVC (ee1e9c3bb8228ae423dd38db69128e71) C:\Windows\System32\bdesvc.dll 10:05:50.0583 2660 BDESVC - ok 10:05:50.0697 2660 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys 10:05:50.0850 2660 Beep - ok 10:05:51.0043 2660 BFE (1e2bac209d184bb851e1a187d8a29136) C:\Windows\System32\bfe.dll 10:05:51.0226 2660 BFE - ok 10:05:51.0446 2660 BITS (e585445d5021971fae10393f0f1c3961) C:\Windows\system32\qmgr.dll 10:05:51.0638 2660 BITS - ok 10:05:51.0796 2660 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys 10:05:51.0844 2660 blbdrive - ok 10:05:51.0976 2660 Bonjour Service (f832f1505ad8b83474bd9a5b1b985e01) C:\Program Files\Bonjour\mDNSResponder.exe 10:05:51.0997 2660 Bonjour Service - ok 10:05:52.0150 2660 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys 10:05:52.0241 2660 bowser - ok 10:05:52.0644 2660 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys 10:05:52.0883 2660 BrFiltLo - ok 10:05:53.0122 2660 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys 10:05:53.0265 2660 BrFiltUp - ok 10:05:53.0494 2660 BridgeMP (77361d72a04f18809d0efb6cceb74d4b) C:\Windows\system32\DRIVERS\bridge.sys 10:05:53.0636 2660 BridgeMP - ok 10:05:53.0789 2660 Browser (6e11f33d14d020f58d5e02e4d67dfa19) C:\Windows\System32\browser.dll 10:05:53.0939 2660 Browser - ok 10:05:54.0114 2660 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys 10:05:54.0259 2660 Brserid - ok 10:05:54.0405 2660 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys 10:05:54.0515 2660 BrSerWdm - ok 10:05:54.0666 2660 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys 10:05:54.0733 2660 BrUsbMdm - ok 10:05:54.0866 2660 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys 10:05:54.0951 2660 BrUsbSer - ok 10:05:55.0123 2660 BthEnum (2865a5c8e98c70c605f417908cebb3a4) C:\Windows\system32\drivers\BthEnum.sys 10:05:55.0260 2660 BthEnum - ok 10:05:55.0403 2660 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys 10:05:55.0486 2660 BTHMODEM - ok 10:05:55.0640 2660 BthPan (ad1872e5829e8a2c3b5b4b641c3eab0e) C:\Windows\system32\DRIVERS\bthpan.sys 10:05:55.0710 2660 BthPan - ok 10:05:55.0881 2660 BTHPORT (c2fbf6d271d9a94d839c416bf186ead9) C:\Windows\System32\Drivers\BTHport.sys 10:05:55.0997 2660 BTHPORT - ok 10:05:56.0159 2660 bthserv (1df19c96eef6c29d1c3e1a8678e07190) C:\Windows\system32\bthserv.dll 10:05:56.0308 2660 bthserv - ok 10:05:56.0451 2660 BTHUSB (c81e9413a25a439f436b1d4b6a0cf9e9) C:\Windows\System32\Drivers\BTHUSB.sys 10:05:56.0503 2660 BTHUSB - ok 10:05:56.0680 2660 catchme - ok 10:05:56.0971 2660 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys 10:05:57.0147 2660 cdfs - ok 10:05:57.0350 2660 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys 10:05:57.0485 2660 cdrom - ok 10:05:57.0661 2660 CertPropSvc (319c6b309773d063541d01df8ac6f55f) C:\Windows\System32\certprop.dll 10:05:57.0936 2660 CertPropSvc - ok 10:05:58.0143 2660 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys 10:05:58.0233 2660 circlass - ok 10:05:58.0391 2660 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys 10:05:58.0438 2660 CLFS - ok 10:05:58.0556 2660 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 10:05:58.0677 2660 clr_optimization_v2.0.50727_32 - ok 10:05:58.0840 2660 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 10:05:58.0942 2660 clr_optimization_v4.0.30319_32 - ok 10:05:59.0074 2660 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys 10:05:59.0146 2660 CmBatt - ok 10:05:59.0293 2660 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys 10:05:59.0320 2660 cmdide - ok 10:05:59.0386 2660 CNG (6427525d76f61d0c519b008d3680e8e7) C:\Windows\system32\Drivers\cng.sys 10:05:59.0453 2660 CNG - ok 10:05:59.0595 2660 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys 10:05:59.0622 2660 Compbatt - ok 10:05:59.0713 2660 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys 10:05:59.0810 2660 CompositeBus - ok 10:05:59.0876 2660 COMSysApp - ok 10:05:59.0955 2660 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys 10:05:59.0997 2660 crcdisk - ok 10:06:00.0203 2660 CryptSvc (a585bebf7d054bd9618eda0922d5484a) C:\Windows\system32\cryptsvc.dll 10:06:00.0357 2660 CryptSvc - ok 10:06:00.0502 2660 CSC (3c2177a897b4ca2788c6fb0c3fd81d4b) C:\Windows\system32\drivers\csc.sys 10:06:00.0610 2660 CSC - ok 10:06:00.0781 2660 CscService (15f93b37f6801943360d9eb42485d5d3) C:\Windows\System32\cscsvc.dll 10:06:00.0865 2660 CscService - ok 10:06:01.0018 2660 DcomLaunch (7660f01d3b38aca1747e397d21d790af) C:\Windows\system32\rpcss.dll 10:06:01.0204 2660 DcomLaunch - ok 10:06:01.0330 2660 defragsvc (8d6e10a2d9a5eed59562d9b82cf804e1) C:\Windows\System32\defragsvc.dll 10:06:01.0486 2660 defragsvc - ok 10:06:01.0645 2660 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys 10:06:01.0764 2660 DfsC - ok 10:06:01.0943 2660 Dhcp (e9e01eb683c132f7fa27cd607b8a2b63) C:\Windows\system32\dhcpcore.dll 10:06:02.0120 2660 Dhcp - ok 10:06:02.0252 2660 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys 10:06:02.0580 2660 discache - ok 10:06:02.0762 2660 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys 10:06:02.0832 2660 Disk - ok 10:06:03.0313 2660 Dnscache (33ef4861f19a0736b11314aad9ae28d0) C:\Windows\System32\dnsrslvr.dll 10:06:03.0494 2660 Dnscache - ok 10:06:03.0693 2660 dot3svc (366ba8fb4b7bb7435e3b9eacb3843f67) C:\Windows\System32\dot3svc.dll 10:06:03.0831 2660 dot3svc - ok 10:06:03.0988 2660 DPS (8ec04ca86f1d68da9e11952eb85973d6) C:\Windows\system32\dps.dll 10:06:04.0160 2660 DPS - ok 10:06:04.0318 2660 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys 10:06:04.0387 2660 drmkaud - ok 10:06:04.0546 2660 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys 10:06:04.0634 2660 DXGKrnl - ok 10:06:04.0753 2660 E1G60 (22ef8965101685add128f03a2b03ce16) C:\Windows\system32\DRIVERS\E1G60I32.sys 10:06:04.0808 2660 E1G60 - ok 10:06:04.0891 2660 EagleNT - ok 10:06:05.0007 2660 EagleXNt - ok 10:06:05.0148 2660 EapHost (8600142fa91c1b96367d3300ad0f3f3a) C:\Windows\System32\eapsvc.dll 10:06:05.0391 2660 EapHost - ok 10:06:05.0629 2660 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys 10:06:05.0952 2660 ebdrv - ok 10:06:06.0103 2660 EFS (81951f51e318aecc2d68559e47485cc4) C:\Windows\System32\lsass.exe 10:06:06.0223 2660 EFS - ok 10:06:06.0321 2660 ehRecvr (a8c362018efc87beb013ee28f29c0863) C:\Windows\ehome\ehRecvr.exe 10:06:06.0443 2660 ehRecvr - ok 10:06:06.0531 2660 ehSched (d389bff34f80caede417bf9d1507996a) C:\Windows\ehome\ehsched.exe 10:06:06.0691 2660 ehSched - ok 10:06:06.0829 2660 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys 10:06:06.0898 2660 elxstor - ok 10:06:07.0054 2660 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys 10:06:07.0146 2660 ErrDev - ok 10:06:07.0285 2660 EventSystem (f6916efc29d9953d5d0df06882ae8e16) C:\Windows\system32\es.dll 10:06:07.0590 2660 EventSystem - ok 10:06:07.0716 2660 EverestDriver - ok 10:06:07.0826 2660 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys 10:06:07.0975 2660 exfat - ok 10:06:08.0139 2660 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys 10:06:08.0344 2660 fastfat - ok 10:06:08.0504 2660 Fax (967ea5b213e9984cbe270205df37755b) C:\Windows\system32\fxssvc.exe 10:06:08.0616 2660 Fax - ok 10:06:08.0736 2660 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys 10:06:08.0813 2660 fdc - ok 10:06:08.0887 2660 fdPHost (f3222c893bd2f5821a0179e5c71e88fb) C:\Windows\system32\fdPHost.dll 10:06:09.0022 2660 fdPHost - ok 10:06:09.0233 2660 FDResPub (7dbe8cbfe79efbdeb98c9fb08d3a9a5b) C:\Windows\system32\fdrespub.dll 10:06:09.0363 2660 FDResPub - ok 10:06:09.0497 2660 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys 10:06:09.0546 2660 FileInfo - ok 10:06:09.0646 2660 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys 10:06:09.0786 2660 Filetrace - ok 10:06:09.0986 2660 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys 10:06:10.0082 2660 flpydisk - ok 10:06:10.0210 2660 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys 10:06:10.0267 2660 FltMgr - ok 10:06:10.0376 2660 FontCache (b3a5ec6b6b6673db7e87c2bcdbddc074) C:\Windows\system32\FntCache.dll 10:06:10.0564 2660 FontCache - ok 10:06:10.0696 2660 FontCache3.0.0.0 (e56f39f6b7fda0ac77a79b0fd3de1a2f) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 10:06:10.0750 2660 FontCache3.0.0.0 - ok 10:06:10.0847 2660 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys 10:06:10.0863 2660 FsDepends - ok 10:06:10.0955 2660 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys 10:06:10.0984 2660 Fs_Rec - ok 10:06:11.0128 2660 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys 10:06:11.0176 2660 fvevol - ok 10:06:11.0309 2660 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys 10:06:11.0333 2660 gagp30kx - ok 10:06:11.0437 2660 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 10:06:11.0526 2660 GEARAspiWDM - ok 10:06:11.0658 2660 gpsvc (e897eaf5ed6ba41e081060c9b447a673) C:\Windows\System32\gpsvc.dll 10:06:11.0852 2660 gpsvc - ok 10:06:12.0114 2660 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe 10:06:12.0163 2660 gupdate - ok 10:06:12.0317 2660 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe 10:06:12.0374 2660 gupdatem - ok 10:06:12.0710 2660 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys 10:06:12.0911 2660 hcw85cir - ok 10:06:13.0256 2660 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys 10:06:13.0463 2660 HdAudAddService - ok 10:06:13.0604 2660 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys 10:06:13.0766 2660 HDAudBus - ok 10:06:13.0899 2660 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys 10:06:14.0035 2660 HidBatt - ok 10:06:14.0197 2660 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys 10:06:14.0302 2660 HidBth - ok 10:06:14.0415 2660 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys 10:06:14.0500 2660 HidIr - ok 10:06:14.0623 2660 hidserv (2bc6f6a1992b3a77f5f41432ca6b3b6b) C:\Windows\System32\hidserv.dll 10:06:14.0787 2660 hidserv - ok 10:06:14.0954 2660 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys 10:06:15.0030 2660 HidUsb - ok 10:06:15.0155 2660 hkmsvc (196b4e3f4cccc24af836ce58facbb699) C:\Windows\system32\kmsvc.dll 10:06:15.0300 2660 hkmsvc - ok 10:06:15.0441 2660 HomeGroupListener (6658f4404de03d75fe3ba09f7aba6a30) C:\Windows\system32\ListSvc.dll 10:06:15.0567 2660 HomeGroupListener - ok 10:06:15.0721 2660 HomeGroupProvider (dbc02d918fff1cad628acbe0c0eaa8e8) C:\Windows\system32\provsvc.dll 10:06:15.0803 2660 HomeGroupProvider - ok 10:06:15.0951 2660 hpdskflt (24f3f496c18efc234777723a67a85f81) C:\Windows\system32\DRIVERS\hpdskflt.sys 10:06:15.0973 2660 hpdskflt - ok 10:06:16.0093 2660 HpqKbFiltr (1210960ff8928950d2a786895b0c424a) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys 10:06:16.0257 2660 HpqKbFiltr - ok 10:06:16.0381 2660 hpqwmiex (fdf273a845f1ffcceadf363aaf47582f) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe 10:06:16.0421 2660 hpqwmiex - ok 10:06:16.0556 2660 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys 10:06:16.0587 2660 HpSAMD - ok 10:06:16.0673 2660 hpsrv (6d0ac28c5bd8d8495f83f5929a45e559) C:\Windows\system32\Hpservice.exe 10:06:16.0748 2660 hpsrv - ok 10:06:16.0841 2660 HssDrv (4f28652ec514fa1ba473bc1a695a5c98) C:\Windows\system32\DRIVERS\HssDrv.sys 10:06:16.0887 2660 HssDrv - ok 10:06:17.0002 2660 HssSrv (5b350bdcc73fd3021a6c0a79915e7c23) C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe 10:06:17.0067 2660 HssSrv ( UnsignedFile.Multi.Generic ) - warning 10:06:17.0090 2660 HssSrv - detected UnsignedFile.Multi.Generic (1) 10:06:17.0156 2660 HssTrayService (6bec0a02ef4a123720303c33f077df82) C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE 10:06:17.0236 2660 HssTrayService ( UnsignedFile.Multi.Generic ) - warning 10:06:17.0236 2660 HssTrayService - detected UnsignedFile.Multi.Generic (1) 10:06:17.0315 2660 HssWd - ok 10:06:17.0522 2660 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys 10:06:17.0835 2660 HTTP - ok 10:06:18.0062 2660 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys 10:06:18.0131 2660 hwpolicy - ok 10:06:18.0328 2660 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys 10:06:18.0367 2660 i8042prt - ok 10:06:18.0523 2660 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys 10:06:18.0578 2660 iaStorV - ok 10:06:18.0712 2660 idsvc (c521d7eb6497bb1af6afa89e322fb43c) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 10:06:18.0793 2660 idsvc - ok 10:06:18.0946 2660 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys 10:06:19.0006 2660 iirsp - ok 10:06:19.0177 2660 IKEEXT (f95622f161474511b8d80d6b093aa610) C:\Windows\System32\ikeext.dll 10:06:19.0342 2660 IKEEXT - ok 10:06:19.0502 2660 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys 10:06:19.0533 2660 intelide - ok 10:06:19.0608 2660 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys 10:06:19.0666 2660 intelppm - ok 10:06:19.0765 2660 IPBusEnum (acb364b9075a45c0736e5c47be5cae19) C:\Windows\system32\ipbusenum.dll 10:06:19.0916 2660 IPBusEnum - ok 10:06:20.0058 2660 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys 10:06:20.0197 2660 IpFilterDriver - ok 10:06:20.0347 2660 iphlpsvc (4d65a07b795d6674312f879d09aa7663) C:\Windows\System32\iphlpsvc.dll 10:06:20.0504 2660 iphlpsvc - ok 10:06:20.0667 2660 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys 10:06:20.0764 2660 IPMIDRV - ok 10:06:20.0887 2660 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys 10:06:21.0086 2660 IPNAT - ok 10:06:21.0206 2660 iPod Service (8e5e5a8cc84da3f683e3bbc045138d52) C:\Program Files\iPod\bin\iPodService.exe 10:06:21.0311 2660 iPod Service - ok 10:06:21.0449 2660 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys 10:06:21.0548 2660 IRENUM - ok 10:06:21.0732 2660 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys 10:06:21.0777 2660 isapnp - ok 10:06:21.0938 2660 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys 10:06:21.0991 2660 iScsiPrt - ok 10:06:22.0184 2660 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys 10:06:22.0215 2660 kbdclass - ok 10:06:22.0406 2660 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\DRIVERS\kbdhid.sys 10:06:22.0575 2660 kbdhid - ok 10:06:22.0748 2660 KeyIso (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 10:06:22.0805 2660 KeyIso - ok 10:06:22.0930 2660 KSecDD (f4647bb23db9038a7536cf6b68f4207f) C:\Windows\system32\Drivers\ksecdd.sys 10:06:22.0956 2660 KSecDD - ok 10:06:23.0027 2660 KSecPkg (e73cae53bbb72ba26918492c6b4c229d) C:\Windows\system32\Drivers\ksecpkg.sys 10:06:23.0048 2660 KSecPkg - ok 10:06:23.0256 2660 KtmRm (89a7b9cc98d0d80c6f31b91c0a310fcd) C:\Windows\system32\msdtckrm.dll 10:06:23.0419 2660 KtmRm - ok 10:06:23.0590 2660 LanmanServer (d64af876d53eca3668bb97b51b4e70ab) C:\Windows\System32\srvsvc.dll 10:06:23.0739 2660 LanmanServer - ok 10:06:23.0885 2660 LanmanWorkstation (58405e4f68ba8e4057c6e914f326aba2) C:\Windows\System32\wkssvc.dll 10:06:24.0070 2660 LanmanWorkstation - ok 10:06:24.0240 2660 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys 10:06:24.0558 2660 lltdio - ok 10:06:24.0767 2660 lltdsvc (5700673e13a2117fa3b9020c852c01e2) C:\Windows\System32\lltdsvc.dll 10:06:24.0923 2660 lltdsvc - ok 10:06:25.0161 2660 lmhosts (55ca01ba19d0006c8f2639b6c045e08b) C:\Windows\System32\lmhsvc.dll 10:06:25.0356 2660 lmhosts - ok 10:06:25.0545 2660 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys 10:06:25.0604 2660 LSI_FC - ok 10:06:25.0735 2660 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys 10:06:25.0765 2660 LSI_SAS - ok 10:06:25.0841 2660 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys 10:06:25.0866 2660 LSI_SAS2 - ok 10:06:25.0959 2660 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys 10:06:25.0987 2660 LSI_SCSI - ok 10:06:26.0089 2660 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys 10:06:26.0364 2660 luafv - ok 10:06:26.0504 2660 Mcx2Svc (bfb9ee8ee977efe85d1a3105abef6dd1) C:\Windows\system32\Mcx2Svc.dll 10:06:26.0582 2660 Mcx2Svc - ok 10:06:26.0722 2660 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys 10:06:26.0744 2660 megasas - ok 10:06:26.0785 2660 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys 10:06:26.0814 2660 MegaSR - ok 10:06:26.0925 2660 Microsoft Office Groove Audit Service (123271bd5237ab991dc5c21fdf8835eb) C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe 10:06:26.0942 2660 Microsoft Office Groove Audit Service - ok 10:06:27.0117 2660 Mkd2Bthf (9674bcb361e0a2fc3790b6e0c4da17ce) C:\Windows\system32\drivers\Mkd2Bthf.sys 10:06:27.0163 2660 Mkd2Bthf - ok 10:06:27.0344 2660 Mkd2kfNt (b437f52f8a8b8e7bf5ec2e8139f0d3ec) C:\Windows\system32\drivers\Mkd2kfNt.sys 10:06:27.0385 2660 Mkd2kfNt - ok 10:06:27.0614 2660 Mkd2Nadr (e36fce12853677c055dfad6bb4b5d89f) C:\Windows\system32\drivers\Mkd2Nadr.sys 10:06:27.0649 2660 Mkd2Nadr - ok 10:06:27.0823 2660 MMCSS (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll 10:06:27.0980 2660 MMCSS - ok 10:06:28.0139 2660 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys 10:06:28.0324 2660 Modem - ok 10:06:28.0464 2660 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys 10:06:28.0554 2660 monitor - ok 10:06:28.0721 2660 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys 10:06:28.0743 2660 mouclass - ok 10:06:28.0836 2660 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys 10:06:28.0904 2660 mouhid - ok 10:06:29.0008 2660 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys 10:06:29.0038 2660 mountmgr - ok 10:06:29.0151 2660 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys 10:06:29.0169 2660 mpio - ok 10:06:29.0263 2660 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys 10:06:29.0408 2660 mpsdrv - ok 10:06:29.0538 2660 MpsSvc (9835584e999d25004e1ee8e5f3e3b881) C:\Windows\system32\mpssvc.dll 10:06:29.0682 2660 MpsSvc - ok 10:06:29.0855 2660 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys 10:06:29.0961 2660 MRxDAV - ok 10:06:30.0164 2660 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys 10:06:30.0284 2660 mrxsmb - ok 10:06:30.0429 2660 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys 10:06:30.0532 2660 mrxsmb10 - ok 10:06:30.0697 2660 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys 10:06:30.0763 2660 mrxsmb20 - ok 10:06:30.0912 2660 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys 10:06:30.0992 2660 msahci - ok 10:06:31.0133 2660 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys 10:06:31.0170 2660 msdsm - ok 10:06:31.0303 2660 MSDTC (e1bce74a3bd9902b72599c0192a07e27) C:\Windows\System32\msdtc.exe 10:06:31.0510 2660 MSDTC - ok 10:06:31.0621 2660 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys 10:06:31.0862 2660 Msfs - ok 10:06:32.0130 2660 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys 10:06:32.0266 2660 mshidkmdf - ok 10:06:32.0499 2660 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys 10:06:32.0564 2660 msisadrv - ok 10:06:32.0743 2660 MSiSCSI (90f7d9e6b6f27e1a707d4a297f077828) C:\Windows\system32\iscsiexe.dll 10:06:32.0904 2660 MSiSCSI - ok 10:06:33.0009 2660 msiserver - ok 10:06:33.0070 2660 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys 10:06:33.0243 2660 MSKSSRV - ok 10:06:33.0379 2660 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys 10:06:33.0538 2660 MSPCLOCK - ok 10:06:33.0663 2660 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys 10:06:33.0809 2660 MSPQM - ok 10:06:33.0964 2660 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys 10:06:33.0995 2660 MsRPC - ok 10:06:34.0200 2660 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys 10:06:34.0230 2660 mssmbios - ok 10:06:34.0297 2660 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys 10:06:34.0431 2660 MSTEE - ok 10:06:34.0567 2660 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys 10:06:34.0645 2660 MTConfig - ok 10:06:34.0838 2660 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys 10:06:34.0867 2660 Mup - ok 10:06:35.0038 2660 NACAgent (20f2516bfac46d34a3c36210d6455c72) C:\Program Files\Cisco\Cisco NAC Agent\NACAgent.exe 10:06:35.0095 2660 NACAgent - ok 10:06:35.0259 2660 napagent (61d57a5d7c6d9afe10e77dae6e1b445e) C:\Windows\system32\qagentRT.dll 10:06:35.0404 2660 napagent - ok 10:06:35.0557 2660 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys 10:06:35.0618 2660 NativeWifiP - ok 10:06:35.0801 2660 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys 10:06:35.0893 2660 NDIS - ok 10:06:36.0040 2660 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys 10:06:36.0187 2660 NdisCap - ok 10:06:36.0337 2660 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys 10:06:36.0459 2660 NdisTapi - ok 10:06:36.0605 2660 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys 10:06:36.0727 2660 Ndisuio - ok 10:06:36.0874 2660 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys 10:06:37.0169 2660 NdisWan - ok 10:06:37.0301 2660 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys 10:06:37.0636 2660 NDProxy - ok 10:06:37.0827 2660 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys 10:06:37.0987 2660 NetBIOS - ok 10:06:38.0200 2660 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys 10:06:38.0353 2660 NetBT - ok 10:06:38.0504 2660 Netlogon (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 10:06:38.0615 2660 Netlogon - ok 10:06:38.0754 2660 Netman (7cccfca7510684768da22092d1fa4db2) C:\Windows\System32\netman.dll 10:06:38.0900 2660 Netman - ok 10:06:39.0125 2660 netprofm (8c338238c16777a802d6a9211eb2ba50) C:\Windows\System32\netprofm.dll 10:06:39.0279 2660 netprofm - ok 10:06:39.0427 2660 NetTcpPortSharing (f476ec40033cdb91efbe73eb99b8362d) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 10:06:39.0452 2660 NetTcpPortSharing - ok 10:06:39.0553 2660 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys 10:06:39.0601 2660 nfrd960 - ok 10:06:39.0741 2660 NlaSvc (912084381d30d8b89ec4e293053f4710) C:\Windows\System32\nlasvc.dll 10:06:39.0906 2660 NlaSvc - ok 10:06:40.0046 2660 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys 10:06:40.0249 2660 Npfs - ok 10:06:40.0374 2660 nsi (ba387e955e890c8a88306d9b8d06bf17) C:\Windows\system32\nsisvc.dll 10:06:40.0544 2660 nsi - ok 10:06:40.0684 2660 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys 10:06:40.0833 2660 nsiproxy - ok 10:06:41.0071 2660 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys 10:06:41.0140 2660 Ntfs - ok 10:06:41.0325 2660 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys 10:06:41.0463 2660 Null - ok 10:06:41.0595 2660 NVHDA (3d7fb57354703809b5f0c23287fac1d6) C:\Windows\system32\drivers\nvhda32v.sys 10:06:41.0646 2660 NVHDA - ok 10:06:41.0971 2660 nvlddmkm (e891b3979f0cf2740c1b073f834221fe) C:\Windows\system32\DRIVERS\nvlddmkm.sys 10:06:42.0702 2660 nvlddmkm - ok 10:06:42.0860 2660 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys 10:06:42.0888 2660 nvraid - ok 10:06:42.0922 2660 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys 10:06:42.0943 2660 nvstor - ok 10:06:43.0022 2660 nvsvc (ae2de8e165dcb93a66b21748e6f913df) C:\Windows\system32\nvvsvc.exe 10:06:43.0104 2660 nvsvc - ok 10:06:43.0302 2660 nvUpdatusService (c78581c14699c46fe0f0817416383134) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 10:06:43.0438 2660 nvUpdatusService - ok 10:06:43.0613 2660 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys 10:06:43.0650 2660 nv_agp - ok 10:06:43.0758 2660 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 10:06:43.0837 2660 odserv - ok 10:06:43.0976 2660 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys 10:06:44.0079 2660 ohci1394 - ok 10:06:44.0309 2660 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 10:06:44.0411 2660 ose - ok 10:06:44.0555 2660 p2pimsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll 10:06:44.0683 2660 p2pimsvc - ok 10:06:44.0830 2660 p2psvc (59c3ddd501e39e006dac31bf55150d91) C:\Windows\system32\p2psvc.dll 10:06:44.0918 2660 p2psvc - ok 10:06:45.0072 2660 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys 10:06:45.0113 2660 Parport - ok 10:06:45.0202 2660 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys 10:06:45.0226 2660 partmgr - ok 10:06:45.0350 2660 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys 10:06:45.0445 2660 Parvdm - ok 10:06:45.0582 2660 PcaSvc (358ab7956d3160000726574083dfc8a6) C:\Windows\System32\pcasvc.dll 10:06:45.0663 2660 PcaSvc - ok 10:06:45.0958 2660 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys 10:06:45.0990 2660 pci - ok 10:06:46.0219 2660 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys 10:06:46.0245 2660 pciide - ok 10:06:46.0407 2660 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys 10:06:46.0456 2660 pcmcia - ok 10:06:46.0602 2660 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys 10:06:46.0636 2660 pcw - ok 10:06:46.0702 2660 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys 10:06:46.0887 2660 PEAUTH - ok 10:06:47.0061 2660 PeerDistSvc (af4d64d2a57b9772cf3801950b8058a6) C:\Windows\system32\peerdistsvc.dll 10:06:47.0245 2660 PeerDistSvc - ok 10:06:47.0795 2660 pla (414bba67a3ded1d28437eb66aeb8a720) C:\Windows\system32\pla.dll 10:06:48.0409 2660 pla - ok 10:06:48.0643 2660 PlugPlay (ec7bc28d207da09e79b3e9faf8b232ca) C:\Windows\system32\umpnpmgr.dll 10:06:48.0755 2660 PlugPlay - ok 10:06:48.0979 2660 PNRPAutoReg (63ff8572611249931eb16bb8eed6afc8) C:\Windows\system32\pnrpauto.dll 10:06:49.0094 2660 PNRPAutoReg - ok 10:06:49.0388 2660 PNRPsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll 10:06:49.0440 2660 PNRPsvc - ok 10:06:49.0637 2660 PolicyAgent (53946b69ba0836bd95b03759530c81ec) C:\Windows\System32\ipsecsvc.dll 10:06:49.0968 2660 PolicyAgent - ok 10:06:50.0243 2660 Power (f87d30e72e03d579a5199ccb3831d6ea) C:\Windows\system32\umpo.dll 10:06:50.0559 2660 Power - ok 10:06:50.0793 2660 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys 10:06:51.0007 2660 PptpMiniport - ok 10:06:51.0231 2660 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys 10:06:51.0347 2660 Processor - ok 10:06:51.0484 2660 ProfSvc (43ca4ccc22d52fb58e8988f0198851d0) C:\Windows\system32\profsvc.dll 10:06:51.0681 2660 ProfSvc - ok 10:06:51.0837 2660 ProtectedStorage (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 10:06:51.0936 2660 ProtectedStorage - ok 10:06:52.0095 2660 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys 10:06:52.0308 2660 Psched - ok 10:06:52.0750 2660 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys 10:06:53.0258 2660 ql2300 - ok 10:06:53.0450 2660 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys 10:06:53.0522 2660 ql40xx - ok 10:06:53.0691 2660 QWAVE (31ac809e7707eb580b2bdb760390765a) C:\Windows\system32\qwave.dll 10:06:53.0811 2660 QWAVE - ok 10:06:54.0072 2660 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys 10:06:54.0228 2660 QWAVEdrv - ok 10:06:54.0462 2660 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys 10:06:54.0630 2660 RasAcd - ok 10:06:54.0981 2660 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys 10:06:55.0351 2660 RasAgileVpn - ok 10:06:55.0555 2660 RasAuto (a60f1839849c0c00739787fd5ec03f13) C:\Windows\System32\rasauto.dll 10:06:55.0807 2660 RasAuto - ok 10:06:55.0954 2660 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys 10:06:56.0185 2660 Rasl2tp - ok 10:06:56.0372 2660 RasMan (cb9e04dc05eacf5b9a36ca276d475006) C:\Windows\System32\rasmans.dll 10:06:56.0807 2660 RasMan - ok 10:06:57.0046 2660 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys 10:06:57.0243 2660 RasPppoe - ok 10:06:57.0481 2660 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys 10:06:58.0043 2660 RasSstp - ok 10:06:58.0286 2660 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys 10:06:58.0823 2660 rdbss - ok 10:06:58.0943 2660 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys 10:06:59.0044 2660 rdpbus - ok 10:06:59.0229 2660 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys 10:06:59.0880 2660 RDPCDD - ok 10:07:00.0041 2660 RDPDR (b973fcfc50dc1434e1970a146f7e3885) C:\Windows\system32\drivers\rdpdr.sys 10:07:00.0154 2660 RDPDR - ok 10:07:00.0293 2660 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys 10:07:00.0428 2660 RDPENCDD - ok 10:07:00.0580 2660 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys 10:07:00.0733 2660 RDPREFMP - ok 10:07:00.0883 2660 RdpVideoMiniport (68a0387f58e226deee23d9715955572a) C:\Windows\system32\drivers\rdpvideominiport.sys 10:07:01.0039 2660 RdpVideoMiniport - ok 10:07:01.0210 2660 RDPWD (244c83332f44589ae98fc347f11b2693) C:\Windows\system32\drivers\RDPWD.sys 10:07:01.0320 2660 RDPWD - ok 10:07:01.0476 2660 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys 10:07:01.0516 2660 rdyboost - ok 10:07:01.0580 2660 RemoteAccess (7b5e1419717fac363a31cc302895217a) C:\Windows\System32\mprdim.dll 10:07:01.0735 2660 RemoteAccess - ok 10:07:01.0884 2660 RemoteRegistry (cb9a8683f4ef2bf99e123d79950d7935) C:\Windows\system32\regsvc.dll 10:07:02.0042 2660 RemoteRegistry - ok 10:07:02.0205 2660 RFCOMM (cb928d9e6daf51879dd6ba8d02f01321) C:\Windows\system32\DRIVERS\rfcomm.sys 10:07:02.0276 2660 RFCOMM - ok 10:07:02.0466 2660 RpcEptMapper (78d072f35bc45d9e4e1b61895c152234) C:\Windows\System32\RpcEpMap.dll 10:07:02.0743 2660 RpcEptMapper - ok 10:07:02.0881 2660 RpcLocator (94d36c0e44677dd26981d2bfeef2a29d) C:\Windows\system32\locator.exe 10:07:02.0943 2660 RpcLocator - ok 10:07:03.0096 2660 RpcSs (7660f01d3b38aca1747e397d21d790af) C:\Windows\system32\rpcss.dll 10:07:03.0517 2660 RpcSs - ok 10:07:03.0667 2660 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys 10:07:03.0805 2660 rspndr - ok 10:07:03.0945 2660 RSUSBSTOR (96f8dd546677aa5102150acc140377b3) C:\Windows\system32\Drivers\RtsUStor.sys 10:07:04.0070 2660 RSUSBSTOR - ok 10:07:04.0218 2660 RTL8167 (7dfd48e24479b68b258d8770121155a0) C:\Windows\system32\DRIVERS\Rt86win7.sys 10:07:04.0322 2660 RTL8167 - ok 10:07:04.0497 2660 RtsUIR - ok 10:07:04.0564 2660 s3cap (7fa7f2e249a5dcbb7970630e15e1f482) C:\Windows\system32\drivers\vms3cap.sys 10:07:04.0639 2660 s3cap - ok 10:07:04.0781 2660 SamSs (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 10:07:04.0823 2660 SamSs - ok 10:07:04.0942 2660 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys 10:07:04.0968 2660 sbp2port - ok 10:07:05.0123 2660 SCardSvr (8fc518ffe9519c2631d37515a68009c4) C:\Windows\System32\SCardSvr.dll 10:07:05.0275 2660 SCardSvr - ok 10:07:05.0464 2660 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys 10:07:05.0583 2660 scfilter - ok 10:07:05.0768 2660 Schedule (a04bb13f8a72f8b6e8b4071723e4e336) C:\Windows\system32\schedsvc.dll 10:07:05.0972 2660 Schedule - ok 10:07:06.0128 2660 SCPolicySvc (319c6b309773d063541d01df8ac6f55f) C:\Windows\System32\certprop.dll 10:07:06.0239 2660 SCPolicySvc - ok 10:07:06.0387 2660 SDRSVC (08236c4bce5edd0a0318a438af28e0f7) C:\Windows\System32\SDRSVC.dll 10:07:06.0547 2660 SDRSVC - ok 10:07:06.0700 2660 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 10:07:06.0869 2660 secdrv - ok 10:07:07.0001 2660 seclogon (a59b3a4442c52060cc7a85293aa3546f) C:\Windows\system32\seclogon.dll 10:07:07.0159 2660 seclogon - ok 10:07:07.0299 2660 SENS (dcb7fcdcc97f87360f75d77425b81737) C:\Windows\system32\sens.dll 10:07:07.0602 2660 SENS - ok 10:07:07.0739 2660 SensrSvc (50087fe1ee447009c9cc2997b90de53f) C:\Windows\system32\sensrsvc.dll 10:07:07.0854 2660 SensrSvc - ok 10:07:07.0995 2660 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys 10:07:08.0046 2660 Serenum - ok 10:07:08.0230 2660 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys 10:07:08.0278 2660 Serial - ok 10:07:08.0381 2660 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys 10:07:08.0420 2660 sermouse - ok 10:07:08.0602 2660 SessionEnv (4ae380f39a0032eab7dd953030b26d28) C:\Windows\system32\sessenv.dll 10:07:08.0750 2660 SessionEnv - ok 10:07:08.0919 2660 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys 10:07:09.0012 2660 sffdisk - ok 10:07:09.0163 2660 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys 10:07:09.0234 2660 sffp_mmc - ok 10:07:09.0383 2660 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys 10:07:09.0464 2660 sffp_sd - ok 10:07:09.0603 2660 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys 10:07:09.0691 2660 sfloppy - ok 10:07:09.0825 2660 SharedAccess (d1a079a0de2ea524513b6930c24527a2) C:\Windows\System32\ipnathlp.dll 10:07:09.0965 2660 SharedAccess - ok 10:07:10.0131 2660 ShellHWDetection (414da952a35bf5d50192e28263b40577) C:\Windows\System32\shsvcs.dll 10:07:10.0320 2660 ShellHWDetection - ok 10:07:10.0486 2660 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys 10:07:10.0511 2660 sisagp - ok 10:07:10.0574 2660 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys 10:07:10.0648 2660 SiSRaid2 - ok 10:07:10.0770 2660 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys 10:07:10.0801 2660 SiSRaid4 - ok 10:07:10.0860 2660 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys 10:07:10.0967 2660 Smb - ok 10:07:11.0194 2660 SNMPTRAP (6a984831644eca1a33ffeae4126f4f37) C:\Windows\System32\snmptrap.exe 10:07:11.0275 2660 SNMPTRAP - ok 10:07:11.0429 2660 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys 10:07:11.0454 2660 spldr - ok 10:07:11.0544 2660 Spooler (866a43013535dc8587c258e43579c764) C:\Windows\System32\spoolsv.exe 10:07:11.0707 2660 Spooler - ok 10:07:11.0922 2660 sppsvc (cf87a1de791347e75b98885214ced2b8) C:\Windows\system32\sppsvc.exe 10:07:12.0560 2660 sppsvc - ok 10:07:12.0709 2660 sppuinotify (b0180b20b065d89232a78a40fe56eaa6) C:\Windows\system32\sppuinotify.dll 10:07:12.0851 2660 sppuinotify - ok 10:07:13.0010 2660 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys 10:07:13.0132 2660 srv - ok 10:07:13.0295 2660 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys 10:07:13.0399 2660 srv2 - ok 10:07:13.0564 2660 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys 10:07:13.0599 2660 srvnet - ok 10:07:13.0692 2660 SSDPSRV (d887c9fd02ac9fa880f6e5027a43e118) C:\Windows\System32\ssdpsrv.dll 10:07:13.0865 2660 SSDPSRV - ok 10:07:14.0037 2660 SstpSvc (d318f23be45d5e3a107469eb64815b50) C:\Windows\system32\sstpsvc.dll 10:07:14.0205 2660 SstpSvc - ok 10:07:14.0388 2660 STacSV (05ae358cd777bf8857f512a18e1de7aa) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_8e7d5b9d3a91d8c5\STacSV.exe 10:07:14.0476 2660 STacSV - ok 10:07:14.0566 2660 Steam Client Service - ok 10:07:14.0657 2660 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys 10:07:14.0711 2660 stexstor - ok 10:07:14.0892 2660 STHDA (e69a606872650b46de54ec15dcc93529) C:\Windows\system32\DRIVERS\stwrt.sys 10:07:14.0952 2660 STHDA - ok 10:07:15.0139 2660 StiSvc (e1fb3706030fb4578a0d72c2fc3689e4) C:\Windows\System32\wiaservc.dll 10:07:15.0306 2660 StiSvc - ok 10:07:15.0442 2660 storflt (472af0311073dceceaa8fa18ba2bdf89) C:\Windows\system32\drivers\vmstorfl.sys 10:07:15.0465 2660 storflt - ok 10:07:15.0523 2660 StorSvc (0bf669f0a910beda4a32258d363af2a5) C:\Windows\system32\storsvc.dll 10:07:15.0642 2660 StorSvc - ok 10:07:15.0796 2660 storvsc (dcaffd62259e0bdb433dd67b5bb37619) C:\Windows\system32\drivers\storvsc.sys 10:07:15.0826 2660 storvsc - ok 10:07:15.0879 2660 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys 10:07:15.0897 2660 swenum - ok 10:07:16.0057 2660 swprv (a28bd92df340e57b024ba433165d34d7) C:\Windows\System32\swprv.dll 10:07:16.0199 2660 swprv - ok 10:07:16.0331 2660 Synth3dVsc - ok 10:07:16.0442 2660 SynTP (7a9025d8f7852b06d6d08ed536135e7e) C:\Windows\system32\DRIVERS\SynTP.sys 10:07:16.0498 2660 SynTP - ok 10:07:16.0646 2660 SysMain (36650d618ca34c9d357dfd3d89b2c56f) C:\Windows\system32\sysmain.dll 10:07:16.0817 2660 SysMain - ok 10:07:16.0937 2660 TabletInputService (763fecdc3d30c815fe72dd57936c6cd1) C:\Windows\System32\TabSvc.dll 10:07:17.0085 2660 TabletInputService - ok 10:07:17.0193 2660 taphss (0c3b2a9c4bd2dd9a6c2e4084314dd719) C:\Windows\system32\DRIVERS\taphss.sys 10:07:17.0218 2660 taphss - ok 10:07:17.0320 2660 TapiSrv (613bf4820361543956909043a265c6ac) C:\Windows\System32\tapisrv.dll 10:07:17.0656 2660 TapiSrv - ok 10:07:17.0792 2660 TBS (b799d9fdb26111737f58288d8dc172d9) C:\Windows\System32\tbssvc.dll 10:07:17.0920 2660 TBS - ok 10:07:18.0129 2660 Tcpip (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\drivers\tcpip.sys 10:07:18.0364 2660 Tcpip - ok 10:07:18.0664 2660 TCPIP6 (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\DRIVERS\tcpip.sys 10:07:18.0750 2660 TCPIP6 - ok 10:07:18.0953 2660 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys 10:07:19.0105 2660 tcpipreg - ok 10:07:19.0267 2660 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys 10:07:19.0331 2660 TDPIPE - ok 10:07:19.0478 2660 TDTCP (2c2c5afe7ee4f620d69c23c0617651a8) C:\Windows\system32\drivers\tdtcp.sys 10:07:19.0567 2660 TDTCP - ok 10:07:19.0718 2660 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys 10:07:19.0843 2660 tdx - ok 10:07:20.0026 2660 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys 10:07:20.0054 2660 TermDD - ok 10:07:20.0218 2660 TermService (382c804c92811be57829d8e550a900e2) C:\Windows\System32\termsrv.dll 10:07:20.0606 2660 TermService - ok 10:07:20.0742 2660 Themes (42fb6afd6b79d9fe07381609172e7ca4) C:\Windows\system32\themeservice.dll 10:07:20.0827 2660 Themes - ok 10:07:20.0958 2660 THREADORDER (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll 10:07:21.0116 2660 THREADORDER - ok 10:07:21.0272 2660 TrkWks (4792c0378db99a9bc2ae2de6cfff0c3a) C:\Windows\System32\trkwks.dll 10:07:21.0424 2660 TrkWks - ok 10:07:21.0558 2660 TrustedInstaller (2c49b175aee1d4364b91b531417fe583) C:\Windows\servicing\TrustedInstaller.exe 10:07:21.0751 2660 TrustedInstaller - ok 10:07:21.0911 2660 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys 10:07:22.0071 2660 tssecsrv - ok 10:07:22.0230 2660 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys 10:07:22.0325 2660 TsUsbFlt - ok 10:07:22.0521 2660 tsusbhub - ok 10:07:22.0753 2660 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys 10:07:22.0968 2660 tunnel - ok 10:07:23.0109 2660 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys 10:07:23.0159 2660 uagp35 - ok 10:07:23.0230 2660 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys 10:07:23.0360 2660 udfs - ok 10:07:23.0493 2660 UI0Detect (8344fd4fce927880aa1aa7681d4927e5) C:\Windows\system32\UI0Detect.exe 10:07:23.0552 2660 UI0Detect - ok 10:07:23.0662 2660 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys 10:07:23.0680 2660 uliagpkx - ok 10:07:23.0806 2660 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys 10:07:23.0908 2660 umbus - ok 10:07:24.0077 2660 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys 10:07:24.0159 2660 UmPass - ok 10:07:24.0322 2660 UmRdpService (409994a8eaceee4e328749c0353527a0) C:\Windows\System32\umrdp.dll 10:07:24.0410 2660 UmRdpService - ok 10:07:24.0547 2660 upnphost (833fbb672460efce8011d262175fad33) C:\Windows\System32\upnphost.dll 10:07:24.0687 2660 upnphost - ok 10:07:24.0849 2660 USBAAPL (5c2bdc152bbab34f36473deaf7713f22) C:\Windows\system32\Drivers\usbaapl.sys 10:07:24.0915 2660 USBAAPL - ok 10:07:25.0112 2660 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\DRIVERS\usbccgp.sys 10:07:25.0233 2660 usbccgp - ok 10:07:25.0341 2660 USBCCID - ok 10:07:25.0419 2660 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys 10:07:25.0510 2660 usbcir - ok 10:07:25.0667 2660 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\DRIVERS\usbehci.sys 10:07:25.0704 2660 usbehci - ok 10:07:25.0866 2660 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys 10:07:25.0937 2660 usbhub - ok 10:07:26.0142 2660 usbohci (e185d44fac515a18d9deddc23c2cdf44) C:\Windows\system32\drivers\usbohci.sys 10:07:26.0216 2660 usbohci - ok 10:07:26.0353 2660 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys 10:07:26.0444 2660 usbprint - ok 10:07:26.0601 2660 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS 10:07:26.0714 2660 USBSTOR - ok 10:07:26.0865 2660 usbuhci (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\DRIVERS\usbuhci.sys 10:07:26.0916 2660 usbuhci - ok 10:07:27.0071 2660 usbvideo (45f4e7bf43db40a6c6b4d92c76cbc3f2) C:\Windows\System32\Drivers\usbvideo.sys 10:07:27.0216 2660 usbvideo - ok 10:07:27.0378 2660 UxSms (081e6e1c91aec36758902a9f727cd23c) C:\Windows\System32\uxsms.dll 10:07:27.0675 2660 UxSms - ok 10:07:27.0816 2660 VaultSvc (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 10:07:27.0881 2660 VaultSvc - ok 10:07:28.0041 2660 vcsFPService (fcf1a2bddcdf9f317b9650800e61c397) C:\Windows\system32\vcsFPService.exe 10:07:28.0141 2660 vcsFPService - ok 10:07:28.0530 2660 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys 10:07:28.0556 2660 vdrvroot - ok 10:07:28.0710 2660 vds (c3cd30495687c2a2f66a65ca6fd89be9) C:\Windows\System32\vds.exe 10:07:28.0862 2660 vds - ok 10:07:28.0997 2660 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys 10:07:29.0113 2660 vga - ok 10:07:29.0252 2660 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys 10:07:29.0366 2660 VgaSave - ok 10:07:29.0498 2660 VGPU - ok 10:07:29.0584 2660 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys 10:07:29.0612 2660 vhdmp - ok 10:07:29.0672 2660 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys 10:07:29.0688 2660 viaagp - ok 10:07:29.0801 2660 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys 10:07:29.0896 2660 ViaC7 - ok 10:07:30.0052 2660 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys 10:07:30.0088 2660 viaide - ok 10:07:30.0173 2660 vmbus (c2f2911156fdc7817c52829c86da494e) C:\Windows\system32\drivers\vmbus.sys 10:07:30.0202 2660 vmbus - ok 10:07:30.0324 2660 VMBusHID (d4d77455211e204f370d08f4963063ce) C:\Windows\system32\drivers\VMBusHID.sys 10:07:30.0394 2660 VMBusHID - ok 10:07:30.0554 2660 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys 10:07:30.0582 2660 volmgr - ok 10:07:30.0685 2660 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys 10:07:30.0712 2660 volmgrx - ok 10:07:30.0827 2660 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys 10:07:30.0858 2660 volsnap - ok 10:07:30.0947 2660 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys 10:07:30.0966 2660 vsmraid - ok 10:07:31.0114 2660 VSS (209a3b1901b83aeb8527ed211cce9e4c) C:\Windows\system32\vssvc.exe 10:07:31.0349 2660 VSS - ok 10:07:31.0492 2660 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\system32\DRIVERS\vwifibus.sys 10:07:31.0577 2660 vwifibus - ok 10:07:31.0711 2660 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys 10:07:31.0782 2660 vwififlt - ok 10:07:31.0930 2660 W32Time (55187fd710e27d5095d10a472c8baf1c) C:\Windows\system32\w32time.dll 10:07:32.0183 2660 W32Time - ok 10:07:32.0332 2660 wacommousefilter (427a8bc96f16c40df81c2d2f4edd32dd) C:\Windows\system32\DRIVERS\wacommousefilter.sys 10:07:32.0353 2660 wacommousefilter - ok 10:07:32.0468 2660 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys 10:07:32.0557 2660 WacomPen - ok 10:07:32.0710 2660 wacomvhid (51d580f30d1a1f2ea4965af6abc2bcb2) C:\Windows\system32\DRIVERS\wacomvhid.sys 10:07:32.0745 2660 wacomvhid - ok 10:07:32.0964 2660 WacomVTHid (799c84ce3bd9600172aa53b4ead8357a) C:\Windows\system32\DRIVERS\WacomVTHid.sys 10:07:32.0995 2660 WacomVTHid - ok 10:07:33.0144 2660 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys 10:07:33.0272 2660 WANARP - ok 10:07:33.0333 2660 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys 10:07:33.0453 2660 Wanarpv6 - ok 10:07:33.0713 2660 WatAdminSvc (353a04c273ec58475d8633e75ccd5604) C:\Windows\system32\Wat\WatAdminSvc.exe 10:07:33.0860 2660 WatAdminSvc - ok 10:07:34.0056 2660 wbengine (691e3285e53dca558e1a84667f13e15a) C:\Windows\system32\wbengine.exe 10:07:34.0236 2660 wbengine - ok 10:07:34.0395 2660 WbioSrvc (9614b5d29dc76ac3c29f6d2d3aa70e67) C:\Windows\System32\wbiosrvc.dll 10:07:34.0554 2660 WbioSrvc - ok 10:07:34.0701 2660 wcncsvc (34eee0dfaadb4f691d6d5308a51315dc) C:\Windows\System32\wcncsvc.dll 10:07:34.0826 2660 wcncsvc - ok 10:07:35.0083 2660 WcsPlugInService (5d930b6357a6d2af4d7653bdabbf352f) C:\Windows\System32\WcsPlugInService.dll 10:07:35.0232 2660 WcsPlugInService - ok 10:07:35.0341 2660 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys 10:07:35.0389 2660 Wd - ok 10:07:35.0477 2660 Wdf01000 (73c5809c82828e34232f9811cb51490e) C:\Windows\system32\drivers\Wdf01000.sys 10:07:35.0485 2660 Suspicious file (Forged): C:\Windows\system32\drivers\Wdf01000.sys. Real md5: 73c5809c82828e34232f9811cb51490e, Fake md5: 9950e3d0f08141c7e89e64456ae7dc73 10:07:35.0486 2660 Wdf01000 ( Virus.Win32.Rloader.a ) - infected 10:07:35.0486 2660 Wdf01000 - detected Virus.Win32.Rloader.a (0) 10:07:35.0594 2660 WdiServiceHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll 10:07:35.0705 2660 WdiServiceHost - ok 10:07:35.0783 2660 WdiSystemHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll 10:07:35.0849 2660 WdiSystemHost - ok 10:07:35.0950 2660 WebClient (a9d880f97530d5b8fee278923349929d) C:\Windows\System32\webclnt.dll 10:07:36.0052 2660 WebClient - ok 10:07:36.0220 2660 Wecsvc (760f0afe937a77cff27153206534f275) C:\Windows\system32\wecsvc.dll 10:07:36.0369 2660 Wecsvc - ok 10:07:36.0515 2660 wercplsupport (ac804569bb2364fb6017370258a4091b) C:\Windows\System32\wercplsupport.dll 10:07:36.0672 2660 wercplsupport - ok 10:07:36.0837 2660 WerSvc (08e420d873e4fd85241ee2421b02c4a4) C:\Windows\System32\WerSvc.dll 10:07:36.0993 2660 WerSvc - ok 10:07:37.0134 2660 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys 10:07:37.0257 2660 WfpLwf - ok 10:07:37.0405 2660 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys 10:07:37.0449 2660 WIMMount - ok 10:07:37.0750 2660 WinDefend (3fae8f94296001c32eab62cd7d82e0fd) C:\Program Files\Windows Defender\mpsvc.dll 10:07:37.0946 2660 WinDefend - ok 10:07:38.0151 2660 WinDriver6 (451f905bc7bff9e1cff2e7ae76196b2c) C:\Windows\system32\drivers\windrvr6.sys 10:07:38.0288 2660 WinDriver6 - ok 10:07:38.0354 2660 WinHttpAutoProxySvc - ok 10:07:38.0485 2660 Winmgmt (f62e510b6ad4c21eb9fe8668ed251826) C:\Windows\system32\wbem\WMIsvc.dll 10:07:38.0629 2660 Winmgmt - ok 10:07:39.0170 2660 WinRM (1b91cd34ea3a90ab6a4ef0550174f4cc) C:\Windows\system32\WsmSvc.dll 10:07:39.0531 2660 WinRM - ok 10:07:39.0720 2660 WinUSB (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUSB.sys 10:07:39.0796 2660 WinUSB - ok 10:07:39.0946 2660 Wlansvc (16935c98ff639d185086a3529b1f2067) C:\Windows\System32\wlansvc.dll 10:07:40.0056 2660 Wlansvc - ok 10:07:40.0260 2660 wlidsvc (fb01d4ae207b9efdbabfc55dc95c7e31) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 10:07:40.0347 2660 wlidsvc - ok 10:07:40.0545 2660 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys 10:07:40.0580 2660 WmiAcpi - ok 10:07:40.0700 2660 wmiApSrv (6eb6b66517b048d87dc1856ddf1f4c3f) C:\Windows\system32\wbem\WmiApSrv.exe 10:07:40.0802 2660 wmiApSrv - ok 10:07:40.0947 2660 WMPNetworkSvc (3b40d3a61aa8c21b88ae57c58ab3122e) C:\Program Files\Windows Media Player\wmpnetwk.exe 10:07:41.0254 2660 WMPNetworkSvc - ok 10:07:41.0392 2660 WPCSvc (a2f0ec770a92f2b3f9de6d518e11409c) C:\Windows\System32\wpcsvc.dll 10:07:41.0497 2660 WPCSvc - ok 10:07:41.0634 2660 WPDBusEnum (aa53356d60af47eacc85bc617a4f3f66) C:\Windows\system32\wpdbusenum.dll 10:07:41.0750 2660 WPDBusEnum - ok 10:07:41.0873 2660 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys 10:07:42.0001 2660 ws2ifsl - ok 10:07:42.0233 2660 wscsvc (6f5d49efe0e7164e03ae773a3fe25340) C:\Windows\system32\wscsvc.dll 10:07:42.0326 2660 wscsvc - ok 10:07:42.0433 2660 WSearch - ok 10:07:42.0564 2660 WTouchService (241fd926852afa4ce70a38b78b542f68) C:\Program Files\WTouch\WTouchService.exe 10:07:42.0621 2660 WTouchService - ok 10:07:42.0970 2660 wuauserv (3026418a50c5b4761befa632cedb7406) C:\Windows\system32\wuaueng.dll 10:07:43.0220 2660 wuauserv - ok 10:07:43.0406 2660 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys 10:07:43.0551 2660 WudfPf - ok 10:07:43.0713 2660 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys 10:07:43.0849 2660 WUDFRd - ok 10:07:43.0992 2660 wudfsvc (8d1e1e529a2c9e9b6a85b55a345f7629) C:\Windows\System32\WUDFSvc.dll 10:07:44.0173 2660 wudfsvc - ok 10:07:44.0296 2660 WwanSvc (ff2d745b560f7c71b31f30f4d49f73d2) C:\Windows\System32\wwansvc.dll 10:07:44.0438 2660 WwanSvc - ok 10:07:44.0536 2660 MBR (0x1B8) (5c86adec17b739c437e145e3b3fc2e6d) \Device\Harddisk0\DR0 10:07:44.0632 2660 \Device\Harddisk0\DR0 - ok 10:07:44.0662 2660 Boot (0x1200) (286651bbac14d292be52150e4651847d) \Device\Harddisk0\DR0\Partition0 10:07:44.0664 2660 \Device\Harddisk0\DR0\Partition0 - ok 10:07:44.0682 2660 Boot (0x1200) (0a637dda12240d468913c0dd562a9089) \Device\Harddisk0\DR0\Partition1 10:07:44.0685 2660 \Device\Harddisk0\DR0\Partition1 - ok 10:07:44.0715 2660 Boot (0x1200) (f9c29f2f836c0e87db4b8c135325db3d) \Device\Harddisk0\DR0\Partition2 10:07:44.0718 2660 \Device\Harddisk0\DR0\Partition2 - ok 10:07:44.0719 2660 ============================================================ 10:07:44.0719 2660 Scan finished 10:07:44.0719 2660 ============================================================ 10:07:44.0723 5792 Detected object count: 3 10:07:44.0723 5792 Actual detected object count: 3 10:08:56.0685 5792 HssSrv ( UnsignedFile.Multi.Generic ) - skipped by user 10:08:56.0710 5792 HssSrv ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:08:56.0711 5792 HssTrayService ( UnsignedFile.Multi.Generic ) - skipped by user 10:08:56.0711 5792 HssTrayService ( UnsignedFile.Multi.Generic ) - User select action: Skip 10:08:56.0918 5792 C:\Windows\system32\drivers\Wdf01000.sys - copied to quarantine 10:09:25.0602 5792 Backup copy not found, trying to cure infected file.. 10:09:25.0614 5792 Cure success, using it.. 10:09:25.0656 5792 C:\Windows\system32\drivers\Wdf01000.sys - will be cured on reboot 10:09:25.0661 5792 Wdf01000 ( Virus.Win32.Rloader.a ) - User select action: Cure 10:09:45.0570 5416 Deinitialize success
Hi, Great! There was still one bad entry hiding in there so hopefully we have fixed your system up. Give it a good go around today and let me know a little bit later how you are doing. If everything seems on the up and up we can remove the tools we used and get you going. :)
Hi,

That is great!

Providing there are no other malware related problems…

IT APPEARS THAT YOUR LOGS ARE NOW CLEAN :D SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!! :D

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
———-

The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following text into the Run box as shown and click OK.
Combofix /Uninstall
(Note: There is a space between the ..X and the /U that needs to be there.)

[external image: Posted Image]
———-

Clean up with OTL:
  • Right-click and Run as Administrator OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
———-

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted using right-click > delete so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Enable Protected Mode in Internet Explorer. This helps Windows Vista users stay more protected from attack by running Internet Explorer with restricted privileges as well as reducing the ability to write, alter or destroy data on your system or install malicious code. To make sure this is running follow these steps:
  • Open Internet Explorer
  • Click on Tools > Internet Options
  • Press Security tab
  • Select Internet zone then place check next to Enable Protected Mode if not already done
  • Do the same for Local Intranet, Trusted Sites and Restricted Sites and then press Apply
  • Restart Internet Explorer and in the bottom right corner of your screen you will see Protected Mode: On showing you it is enabled.
3. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here. **There are firewalls listed in this tutorial that could be downloaded and used but I would personally only recommend using one of the following two below:
Online Armor Free
Agnitum Outpost Firewall Free

5. Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

6. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

7. WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

8.Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI