This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possible virus - got notice from eBay to download file while logging i

93 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a feeling this isn't the correct log and it's the only one I can seem to locate. This appears to have been created in January. ESET said there were 4 files found, yet I don't see that in this log. :smack: ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=9dc6e1cfb1ec4f42b3e53181f6ac9da0 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-12-13 11:36:28 # local_time=2011-12-13 05:36:28 (-0600, Central Standard Time) # country="United States" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 70428870 70428870 0 0 # compatibility_mode=1024 16777215 100 0 0 0 0 0 # compatibility_mode=1792 16777215 100 0 1030355 1030355 0 0 # compatibility_mode=5892 16776638 100 56 1114140 160410561 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=231508 # found=0 # cleaned=0 # scan_time=7533 esets_scanner_update returned -1 esets_gle=1 esets_scanner_update returned -1 esets_gle=1 esets_scanner_update returned -1 esets_gle=1 esets_scanner_update returned -1 esets_gle=1 esets_scanner_update returned -1 esets_gle=1 Here is the MBAM Log Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Database version: v2012.04.10.01 Windows Vista Service Pack 2 x64 NTFS Internet Explorer 9.0.8112.16421 Ratopia :: ARWEN [administrator] 4/9/2012 10:29:03 PM mbam-log-2012-04-09 (22-29-03).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 207135 Time elapsed: 6 minute(s), 4 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Hi,

Let's try a different online scan.

Do an online scan with BitDefender QuickScan.
Please be patient as scanning may take some time. If you have problem running the scan, you might want to disable any real time protection that you have.
  • Click here to go to BitDefender QuickScan page.
  • For Firefox users:
    • Click on Free Scan Now. You will be prompted to install a plug-in. Please Allow. In case you get stuck, please refresh the page to try again.
    • A Software Installation window will appear. Click Install Now and the plugin will be installed as an Add-on.
    • Restart Firefox when done. Go back to the BitDefender QuickScan page again and click on Free Scan Now and proceed accordingly.
  • For Internet Explorer users:
    • Click on Free Scan Now. You will be prompted to install an ActiveX control. Please install.
    • The page will refresh. Click on Free Scan Now again and proceed accordingly.
  • When scan has completed, click on View report and a Notepad log shall open.
  • If there are any infections found, you will get a warning and the link to the report will be displayed as the number of infections. Click on it.
  • Post back the contents of this report. It can also be found at C:\Documents and Settings\\Application Data\QuickScan, is the Windows log-in name.
:D QuickScan 32-bit v0.9.9.114 ————————— Scan date: Tue Apr 10 06:37:45 2012 Machine ID: E457319D No infection found. ——————- Processes ——— Adobe® Flash® Player Installer/Uninstal 4320 C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_228_ActiveX.exe Google Chrome 3688 C:\Users\Ratopia\AppData\Local\Google\Chrome\Application\chrome.exe Google Chrome 3464 C:\Users\Ratopia\AppData\Local\Google\Chrome\Application\chrome.exe Google Chrome 2096 C:\Users\Ratopia\AppData\Local\Google\Chrome\Application\chrome.exe Google Chrome 3016 C:\Users\Ratopia\AppData\Local\Google\Chrome\Application\chrome.exe Google Chrome 4656 C:\Users\Ratopia\AppData\Local\Google\Chrome\Application\chrome.exe Google Chrome 5088 C:\Users\Ratopia\AppData\Local\Google\Chrome\Application\chrome.exe Microsoft® Windows® Operating System 4708 C:\Windows\SysWOW64\rundll32.exe (unsigned) SchedulerSvc.exe 2172 C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (verified) Acer eDataSecurity Management 1892 C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (verified) Adobe Acrobat Update Service 1760 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (verified) AOL 5104 C:\Program Files (x86)\AOL 9.1\shellmon.exe (verified) AOL 4776 C:\Program Files (x86)\AOL 9.1\waol.exe (verified) AOL Connectivity Service 1812 C:\Program Files (x86)\Common Files\aol\acs\AOLacsd.exe (verified) AOL Service Libraries 3996 C:\Program Files (x86)\Common Files\aol\1242688622\ee\aolsoftware.exe (verified) AOL TopSpeed 300 C:\Program Files (x86)\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe (verified) Avira Free Antivirus 1524 C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (verified) Avira Free Antivirus 1784 C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (verified) Avira Free Antivirus 1548 C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (verified) BackupSvc Application 2104 C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe (verified) Bing Bar 2304 C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (verified) CLHNService Module 1868 C:\Program Files (x86)\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe (verified) CyberLink MediaLibray Service 3780 C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (verified) CyberLink PowerCinema 3980 C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (verified) DefaultSettingEXE Application 3232 C:\Windows\PLFSetI.exe (verified) eDataSecurity MSN Hook Loader ( only fo 3324 C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe (verified) GoogleToolbarNotifier 248 C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (verified) Launch Manager 1744 C:\Program Files (x86)\Launch Manager\QtZgAcer.EXE (verified) LightScribe 1416 C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (verified) NTI Backup Now 5 3792 C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe (verified) NTI Backup Now 5 1844 C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe (verified) PCPitstopInfoCenter 1636 C:\Program Files (x86)\PCPitstop\Info Center\InfoCenter.exe (verified) RAID Event Monitor 2500 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (verified) RAID Monitor 2612 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (verified) RichVideo Module 2256 C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe (verified) Seagate FreeAgent™ Application 2296 C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe (verified) Sync 1108 C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe (verified) Windows® Internet Explorer 5588 C:\Program Files (x86)\Internet Explorer\iexplore.exe (verified) Windows® Internet Explorer 5632 C:\Program Files (x86)\Internet Explorer\iexplore.exe Network activity —————- Process chrome.exe (3016) connected on port 5222 (XMPP/Jabber) –> 209.85.225.125 Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> 66.220.151.82 Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 80 (HTTP) –> [removed] Process chrome.exe (3016) connected on port 80 (HTTP) –> [removed] Process chrome.exe (3016) connected on port 80 (HTTP) –> [removed] Process chrome.exe (3016) connected on port 80 (HTTP) –> [removed] Process chrome.exe (3016) connected on port 80 (HTTP) –> [removed] Process chrome.exe (3016) connected on port 80 (HTTP) –> [removed] Process chrome.exe (3016) connected on port 80 (HTTP) –> [removed] Process chrome.exe (3016) connected on port 80 (HTTP) –> [removed] Process chrome.exe (3016) connected on port 80 (HTTP) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3016) connected on port 443 (HTTP over SSL) –> [removed] Process chrome.exe (3464) connected on port 8890 –> [removed] Process chrome.exe (3464) connected on port 8890 –> [removed] Process aolsoftware.exe (3996) connected on port 80 (HTTP) –> 64.12.96.191 Process waol.exe (4776) connected on port 5190 (AIM/ICQ) –> 64.236.18.113 Process waol.exe (4776) connected on port 5190 (AIM/ICQ) –> 64.12.24.40 Process iexplore.exe (5632) connected on port 80 (HTTP) –> 74.125.227.17 Process iexplore.exe (5632) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (5632) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (5632) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (5632) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (5632) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (5632) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (5632) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (5632) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (5632) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (5632) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (5632) connected on port 80 (HTTP) –> [removed] Process iexplore.exe (5632) connected on port 80 (HTTP) –> [removed] Process Agentsvc.exe (1844) listens on ports: 10000 (Webmin) Process BackupSvc.exe (2104) listens on ports: 8384 Process SchedulerSvc.exe (2172) listens on ports: 5151 Autoruns and critical files ————————— Adobe® Flash® Player Update Service C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe AUTOBACK.EXE C:\Program Files (x86)\ERUNT\AUTOBACK.EXE (unsigned) launcher.exe C:\Program Files (x86)\Acer\Acer Assist\launcher.exe (unsigned) PowerReg C:\Program Files (x86)\Acer\Acer Registration\ACE1.exe (unsigned) QuickTime C:\Program Files (x86)\QuickTime\QTTask.exe (verified) Acer eAudio Management C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe (verified) Adobe Reader and Acrobat Manager C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (verified) AOL Service Libraries C:\Program Files (x86)\Common Files\aol\1242688622\ee\aolsoftware.exe (verified) Avira Free Antivirus C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (verified) CyberLink MediaLibray Service C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe (verified) CyberLink PowerCinema C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (verified) Default Manager C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (verified) Google Update C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (verified) Google Update C:\Users\Ratopia\AppData\Local\Google\Update\GoogleUpdate.exe (verified) GoogleToolbarNotifier C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (verified) Launch Manager C:\Program Files (x86)\Launch Manager\QtZgAcer.EXE (verified) Microsoft® Windows® Operating System C:\Windows\system32\browseui.dll (verified) Microsoft® Windows® Operating System C:\Windows\system32\PhotoScreensaver.scr (verified) Microsoft® Windows® Operating System c:\windows\system32\userinit.exe (verified) NTI Backup Now 5 C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe (verified) PCPitstopInfoCenter C:\Program Files (x86)\PCPitstop\Info Center\InfoCenter.exe (verified) Seagate FreeAgent™ Application C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe (verified) Windows® Internet Explorer c:\windows\syswow64\webcheck.dll Browser plugins ————— Bitdefender QuickScan C:\Windows\Downloaded Program Files\qsax.dll Google Toolbar for Internet Explorer c:\program files (x86)\google\google toolbar\googletoolbar_32.dll Google Update C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll Google Update C:\Users\Ratopia\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll Java™ Platform SE 6 U31 c:\program files (x86)\java\jre6\bin\jp2ssv.dll Java™ Platform SE 6 U31 C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll Java™ Platform SE 6 U31 C:\Program Files (x86)\Java\jre6\bin\ssv.dll NPSWF32_11_2_202_228.dll C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_228.dll (unsigned) Google Earth Plugin C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (unsigned) QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin.dll (unsigned) QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin2.dll (unsigned) QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin3.dll (unsigned) QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin4.dll (unsigned) QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin5.dll (unsigned) QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin6.dll (unsigned) QuickTime Plug-in 7.6.9 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin7.dll (verified) Acer eDataSecurity Management c:\program files (x86)\acer\empowering technology\edatasecurity\x86\edstoolbar.dll (verified) AcroIEHelperShim Library c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelpershim.dll (verified) Adobe Acrobat C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (verified) Adobe Acrobat C:\Program Files (x86)\Internet Explorer\plugins\nppdf32.dll (verified) AOL IE Toolbar c:\program files (x86)\aol toolbar\aoltb.dll (verified) BitDefender QuickScan C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll (verified) BrowserPlus (from Yahoo!) v2.9.8 C:\Users\Ratopia\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (verified) DivX Player Netscape Plugin C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll (verified) DivX Web Player C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (verified) DTX Toolbar C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\extensions\{23cd218f-af09-443f-bbb1-adb89fd5986d}\components\dtTransparency.dll (verified) DTX Toolbar C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\extensions\{23cd218f-af09-443f-bbb1-adb89fd5986d}\components\dtTransparency3.5.dll (verified) DTX Toolbar C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\extensions\{23cd218f-af09-443f-bbb1-adb89fd5986d}\components\dtTransparency3.6.dll (verified) eBay Enhanced Uploader, Wells and Layou C:\Windows\Downloaded Program Files\EPUWALcontrol.dll (verified) Microsoft Office Live Plug-in for Firef C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (verified) Microsoft® CoReXT c:\program files (x86)\common files\microsoft shared\windows live\windowslivelogin.dll (verified) Microsoft® Windows® Operating System C:\Windows\system32\mswsock.dll (verified) Microsoft® Windows® Operating System C:\Windows\system32\napinsp.dll (verified) Microsoft® Windows® Operating System C:\Windows\system32\NLAapi.dll (verified) Microsoft® Windows® Operating System C:\Windows\system32\pnrpnsp.dll (verified) Microsoft® Windows® Operating System C:\Windows\System32\winrnr.dll (verified) Oberon com adapter C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll (verified) PC Pitstop C:\Windows\Downloaded Program Files\PCPitstop.dll (verified) PC Pitstop C:\Windows\Downloaded Program Files\pcpitstop2.dll (verified) PC Pitstop C:\Windows\Downloaded Program Files\PCPitstop3D.dll (verified) PC Pitstop C:\Windows\Downloaded Program Files\pcpitstopAntiVirus.dll (verified) PC Pitstop C:\Windows\Downloaded Program Files\PCPitstopAntiVirus2.dll (verified) PC Pitstop DiskMD3 C:\Windows\Downloaded Program Files\DiskMD3Ctrl.dll (verified) Silverlight Plug-In C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll (verified) Sunbelt AntiMalware Common SDK Merge Mo C:\Windows\Downloaded Program Files\SBTE.DLL (verified) Sunbelt AntiMalware Common SDK Merge Mo C:\Windows\Downloaded Program Files\SPURSDOWNLOAD.DLL (verified) VIPRE Threat detection and remediation C:\Windows\Downloaded Program Files\VIPRE.DLL (verified) Windows Live™ Photo Gallery C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (verified) Windows Presentation Foundation C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (verified) Windows® Internet Explorer C:\Windows\SysWOW64\ieframe.dll (verified) Yahoo Application State Plugin C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (verified) Yahoo! Single Instance for Mail c:\program files (x86)\yahoo!\companion\installs\cpn\ytsingleinstance.dll (verified) Yahoo! Toolbar c:\program files (x86)\yahoo!\companion\installs\cpn\yt.dll Missing files ————- File not found: "c:\program files (x86)\microsoft\bingbar\bingext.dll" –> HKLM\Software\Classes\CLSID\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}\InprocServer32\"(default)" –> HKLM\Software\Classes\CLSID\{8dcb7100-df86-4384-8842-8fa844297b3f}\InprocServer32\"(default)" Scan —- MD5: 65a4ab204a22c67aa9f8091a4ed5002e C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\Common\CLRCEngine3.dll MD5: 19b2731afb82729f8ff10b082cd609b3 C:\Program Files (x86)\Acer\Acer Assist\launcher.exe MD5: cba663475ab6d117c164988ec2098c9e C:\Program Files (x86)\Acer\Acer Registration\ACE1.exe MD5: d6cb63830f7eaa3d447218ee5b506d66 C:\Program Files (x86)\AOL 9.1\resource.dll MD5: 84367a3c627a700fcf80b8e83151b376 C:\Program Files (x86)\Avira\AntiVir Desktop\aecore.dll MD5: ee0477f95aaf614c5cb14f324ca48c3d C:\Program Files (x86)\Avira\AntiVir Desktop\aeemu.dll MD5: 2ed1b2cece223ffe49355aa110030446 C:\Program Files (x86)\Avira\AntiVir Desktop\aeexp.dll MD5: 00ef393133e14d8b0079ebccd6315e51 C:\Program Files (x86)\Avira\AntiVir Desktop\aegen.dll MD5: a8e7ffe4a0e9259136eb3a449f4f2971 C:\Program Files (x86)\Avira\AntiVir Desktop\aehelp.dll MD5: 6708f382d9ec34a5be895d7c33da6fe3 C:\Program Files (x86)\Avira\AntiVir Desktop\aeheur.dll MD5: f1ef645a67a55f2c077a4b386c9f369d C:\Program Files (x86)\Avira\AntiVir Desktop\aeoffice.dll MD5: 16715b2ca5d0bdf7a641f35cb9cc1688 C:\Program Files (x86)\Avira\AntiVir Desktop\aepack.dll MD5: cf28139a8aecbf3bec26ca1a16fd69cf C:\Program Files (x86)\Avira\AntiVir Desktop\aerdl.dll MD5: 34a3cca76eff50f8b434efc2700c8787 C:\Program Files (x86)\Avira\AntiVir Desktop\aesbx.dll MD5: 011c74cf75ea6e0b5ab816e2d94f8257 C:\Program Files (x86)\Avira\AntiVir Desktop\aescn.dll MD5: bdb8395adb00c730118ea99ae747eb74 C:\Program Files (x86)\Avira\AntiVir Desktop\aescript.dll MD5: ae3896f436841be390b23cec79499f93 C:\Program Files (x86)\Avira\AntiVir Desktop\aevdf.dll MD5: 9a75e2bda8261184c19e85f2e32eefe5 c:\program files (x86)\avira\antivir desktop\avreg.dll MD5: 9f689e989ecb1e9e0c185111e572ea13 c:\program files (x86)\common files\aol\1242688622\ee\services\authentication\ver6_2_3_1\authentication.dll MD5: 7a4048d990aab3d98dd6572df94ebdc3 c:\program files (x86)\common files\aol\1242688622\ee\services\authentication\ver6_2_3_1\authenticationshadow.dll MD5: e1c92a255c47cd52075d98b2cb0e3aa3 c:\program files (x86)\common files\aol\1242688622\ee\services\http\ver3_1_2_1\http.dll MD5: f6b43ad86fccc66a254d3bb29ba94bd1 c:\program files (x86)\common files\aol\1242688622\ee\services\preferences\ver5_2_1_1\preferences.dll MD5: e8cfe3e528fda8ac613f9c0372fdd0a2 c:\program files (x86)\common files\aol\1242688622\ee\services\softwareUpdate\ver2_15_14_3\stic.dll MD5: 2424231bbd703a677d115c29983b4293 C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL MD5: 785f487a64950f3cb8e9f16253ba3b7b C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE MD5: 631289583481c45c7342efd57442b738 C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\vgx.dll MD5: e00de20f0f6bed5cd2160247ddc9443b C:\Program Files (x86)\ERUNT\AUTOBACK.EXE MD5: 2437be68d5a37a75fad51c5f0e9a03ed C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll MD5: 5b97ab550022b2783894c558fa2e1310 c:\program files (x86)\google\google toolbar\googletoolbar_32.dll MD5: 1e6b52abdf4082374de9d43cbd2f7e08 C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin.dll MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin2.dll MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin3.dll MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin4.dll MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin5.dll MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin6.dll MD5: 6c859c6fce6d694eafd7ea3ae66d54db C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin7.dll MD5: a9770771b622a871643ea2a4a3983e95 c:\program files (x86)\java\jre6\bin\jp2ssv.dll MD5: 34e3709244736b8976820f730e5a8815 C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll MD5: 8e6c86726b67d3faa3144849b9aac06c C:\Program Files (x86)\Java\jre6\bin\ssv.dll MD5: 1f5da01ab6b4db4b18790a06c43f1a44 C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\CdrMmc32.dll MD5: 40b87fe8a1a9a5ac9e5a91d96f212bcd C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe MD5: 0aee5668eb59912f32ff245bfa72465f C:\Program Files (x86)\QuickTime\QTTask.exe MD5: a54294f8e8ba9e96818b2e7516787409 C:\Users\Ratopia\AppData\Local\Google\Chrome\Application\18.0.1025.151\avcodec-53.dll MD5: 8909da40c7eb0a3c3a4eaf381c76996f C:\Users\Ratopia\AppData\Local\Google\Chrome\Application\18.0.1025.151\avformat-53.dll MD5: 974b7a8e6ff9bed4e04bb6363db053d7 C:\Users\Ratopia\AppData\Local\Google\Chrome\Application\18.0.1025.151\avutil-51.dll MD5: 84fa2b21e21cebb2e16123f2801c222c C:\Users\Ratopia\AppData\Local\Google\Chrome\Application\18.0.1025.151\chrome.dll MD5: 21ea4f30a44d80f0e6aa2277c79518ea C:\Users\Ratopia\AppData\Local\Google\Chrome\Application\18.0.1025.151\gcswf32.dll MD5: 011712aeb43d57ce35781e0678079707 C:\Users\Ratopia\AppData\Local\Google\Chrome\Application\18.0.1025.151\icudt.dll MD5: 4d010b8eccb33e9208743dd1f5006a9c C:\Users\Ratopia\AppData\Local\Google\Chrome\Application\18.0.1025.151\pdf.dll MD5: 60cfad439a85b0aab3e78fe673961b7e C:\Users\Ratopia\AppData\Local\Google\Chrome\Application\18.0.1025.151\ppGoogleNaClPluginChrome.dll MD5: c1bacec1225949b7d31f2900f9e7bbaf C:\Users\Ratopia\AppData\Local\Google\Chrome\Application\chrome.exe MD5: 1e6b52abdf4082374de9d43cbd2f7e08 C:\Users\Ratopia\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll MD5: db0f62390f8652992dda8de665a377c4 C:\Users\Ratopia\AppData\Local\Temp\{FAE490EA-81BC-4F74-A477-85144E34A9C2}\fpb.tmp MD5: d6804f089cbb6749e95124e7c4d80900 C:\Windows\AppPatch\AcLayers.DLL MD5: ce1b8c59da1e6eb97516de5aa5d37d49 C:\Windows\AppPatch\AcWow64.DLL MD5: ce45722a3393b63843de48f314cf6b3f C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll MD5: d709af78422f6f0ef09cd0b79cfe743f C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\137696d0416b65dbc1561152971488b4\System.Drawing.ni.dll MD5: a9bb8332bef887a0f4adc3c88cc35bfc C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\65450889f3742aada2a6c0cf8e6173e3\System.Windows.Forms.ni.dll MD5: e60cd8df35eb4a9c952af381fef51af3 C:\Windows\assembly\NativeImages_v2.0.50727_32\System\c50133cb67d7c013fa31e1ffb942060b\System.ni.dll MD5: 2a8c7ca8b40ca320bf88d0ff92da7cf8 C:\Windows\Downloaded Program Files\qsax.dll MD5: 17f41229e141db1412a3b174a567d71e C:\Windows\system32\d2d1.dll MD5: 1c0e15ea80a815494c0a3d471c823ccf C:\Windows\system32\d3d10_1.dll MD5: 8f14591f6dc35192e2844306a12d41ff C:\Windows\system32\d3d10_1core.dll MD5: 4a2e5e1e37aa56773bfd5bc82d36d2ec C:\Windows\system32\D3D10Warp.dll MD5: c790b4593c0b48bb1888880fe89bc09b C:\Windows\system32\DWrite.dll MD5: ff41e1ac301f51e16f61ad7c0f45467c C:\Windows\System32\msshsq.dll MD5: 3fcb7347d2de38488c85a31ea7838a3c C:\Windows\system32\WinSATAPI.dll MD5: 3a1c55c0c951f0fdc413d69f7adf2278 C:\Windows\SysWOW64\jscript.dll MD5: 075402ddf2cbeea5d3ea22754ce70a91 C:\Windows\SysWOW64\Macromed\Flash\Flash32_11_2_202_228.ocx MD5: 0d4c486a24a711a45fd83acdf4d18506 C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe MD5: db0f62390f8652992dda8de665a377c4 C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_228_ActiveX.dll MD5: c82f93131c1b5683cda85c72b02a011d C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_228_ActiveX.exe MD5: 045084e4f10d31e71057fe741d87fdb0 C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_228.dll MD5: 4b555106290bd117334e9a08761c035a C:\Windows\SysWOW64\rundll32.exe MD5: e2c48cd0132d4d1dc7d0df9a6bef686a C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.6195_none_cbf5e994470a1a8 f\MFC80U.DLL MD5: 28a09777d2d952122567a8a82f1a2c7b C:\Windows\WinSxS\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.6195_none_03ce2c722059 43d3\MFC80ENU.DLL No file uploaded. Scan finished - communication took 1 sec Total traffic - 0.00 MB sent, 0.24 KB recvd Scanned 548 files and modules - 35 seconds ==============================================================================
Things seem to be running better. I was freezing up on Facebook really bad, with Chrome and that didn't happen last night. I had used Firefox for a couple of years and had just done an update via their website and something just wasn't right so I uninstalled it, altogether, using the add/remove program and went back and downloaded the newest version and it wouldn't execute. I tried over and over and it would just close after it started to install. I wonder if the problems I was having were related to that? I take it I had a browser hijack with searchq? I believe that came up in the items to be removed in OTL, correct? Maybe I will retry executing it tonight when I get the chance and see what happens because I really like it a LOT better than Chrome. Thanks ! :thumbup:
Hi,

Glad to hear it is running better. Yes you had some searchqu on your system that luckily we were able to remove before it got too bad.

I would give Firefox another try and see if it runs. If not follow these instructions…

Download Revo Uninstaller
  • Double click the installation file on the desktop to run the installer.
  • Let it install to the default location.
  • Double click the new Revo Uninstaller Icon on the desktop to start the program.
You will now see a list of installed programs that Revo Uninstaller can remove.
  • Locate the program you are uninstalling <Mozzila Firefox>
  • Right Click the Icon then choose Uninstall.
  • Click yes to the warning and choose the Uninstall Mode
  • Choose the Advanced option and then click Next.
  • This will launch the programs built in uninstaller. Be patient it can take several seconds.
  • Once the uninstaller is done click Next.
  • Revo Uninstaller will now scan for leftover information. Be patient it can take several seconds.
  • Once this scan is done click Next.
  • You will then be presented of the leftover entries found by Revo Uninstaller
  • Look at ALL of the entries to ensure they relate to the uninstall.
  • Next click Select All > Delete to remove the entries.
  • Click Next.
  • If there are any program file folders left over you will be presented with a list to be removed.
  • Again look at ALL of the entries to ensure they are related to the uninstall.
  • Click Select All > Delete to remove the entries.
  • Click Finish to go back to the uninstall list.
  • Close the program
———-

Now once Firefox has been removed using Revo, please download and install a fresh copy from here.
Before I do the above, I wanted to let you know when I turned on the computer, I got an error message from ERUNT. Actually, it says ERNDT??? I am attaching it as a jpg and I hope that is ok. I will wait until I hear back from you before I proceed with the instructions for Firefox. Thanks !!
Go ahead with Revo uninstaller and then get a new copy of Firefox on your system. That warning has to do with ERUNT…don't worry about that right now. :)
OK, this is not working. I ran the program as directed and it found no Firefox program at all. I know there are several versions of setups on here but I did delete Firefox using the add/remove program in Control Panel, probably in January. That's when I started using Chrome. I am still getting strange popups and even got one when I came on here. It was from http:// sharethis. com/privacy without the spaces, of course. I tried to click it off and got redirected to a sharethis privacy website. :pullhair: Got that off the screen and came back here again. I have the exe file for Firefox on my desktop and it will not complete installation. Also, it asks for me to log in as administrator and asks for my password for that and I don't have a password, nor did I ever create it since I am the sole user of this computer. Now what? :huh:
Hi CoolCat,

Please download TDSSKiller
  • Right-click and Run as Administrator TDSSKiller.exe
  • Press Change Parameters
  • Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.
  • Click on the Start Scan button
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
    • Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
  • Copy and paste the log in your next reply
    • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.
———-

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.


Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-

In your next reply please post the logs made by TDSSKiller and ComboFix. :)
OK, lots going on here. LOL Ran the TDSSKiller and it showed 6 infections or suspicious files. When the window came up to click off what I wanted to do, there was no Cure option so I did as you instructed, then rebooted and located the log. The log is as follows. 21:03:09.0019 5324 TDSS rootkit removing tool [removed] Apr 10 2012 16:54:05 21:03:09.0175 5324 ============================================================ 21:03:09.0175 5324 Current date / time: 2012/04/12 21:03:09.0175 21:03:09.0175 5324 SystemInfo: 21:03:09.0175 5324 21:03:09.0175 5324 OS Version: 6.0.6002 ServicePack: 2.0 21:03:09.0175 5324 Product type: Workstation 21:03:09.0175 5324 ComputerName: ARWEN 21:03:09.0175 5324 UserName: Ratopia 21:03:09.0175 5324 Windows directory: C:\Windows 21:03:09.0175 5324 System windows directory: C:\Windows 21:03:09.0191 5324 Running under WOW64 21:03:09.0191 5324 Processor architecture: Intel x64 21:03:09.0191 5324 Number of processors: 2 21:03:09.0191 5324 Page size: 0x1000 21:03:09.0191 5324 Boot type: Normal boot 21:03:09.0191 5324 ============================================================ 21:03:09.0924 5324 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 21:03:09.0940 5324 \Device\Harddisk0\DR0: 21:03:09.0940 5324 MBR used 21:03:09.0940 5324 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1800800, BlocksNum 0x11E16800 21:03:09.0940 5324 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x13617000, BlocksNum 0x11700000 21:03:10.0033 5324 Initialize success 21:03:10.0033 5324 ============================================================ 21:05:50.0770 5896 ============================================================ 21:05:50.0770 5896 Scan started 21:05:50.0770 5896 Mode: Manual; SigCheck; TDLFS; 21:05:50.0770 5896 ============================================================ 21:05:51.0488 5896 ACPI (1965aaffab07e3fb03c77f81beba3547) C:\Windows\system32\drivers\acpi.sys 21:05:51.0613 5896 ACPI - ok 21:05:52.0190 5896 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 21:05:52.0221 5896 AdobeARMservice - ok 21:05:52.0331 5896 AdobeFlashPlayerUpdateSvc (0d4c486a24a711a45fd83acdf4d18506) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 21:05:52.0346 5896 AdobeFlashPlayerUpdateSvc - ok 21:05:52.0440 5896 adp94xx (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys 21:05:52.0830 5896 adp94xx - ok 21:05:52.0923 5896 adpahci (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys 21:05:52.0955 5896 adpahci - ok 21:05:53.0033 5896 adpu160m (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys 21:05:53.0048 5896 adpu160m - ok 21:05:53.0079 5896 adpu320 (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys 21:05:53.0095 5896 adpu320 - ok 21:05:53.0173 5896 AeLookupSvc (0f421175574bfe0bf2f4d8e910a253bb) C:\Windows\System32\aelupsvc.dll 21:05:53.0220 5896 AeLookupSvc - ok 21:05:53.0329 5896 AFD (c4f6ce6087760ad70960c9eb130e7943) C:\Windows\system32\drivers\afd.sys 21:05:53.0376 5896 AFD - ok 21:05:53.0454 5896 agp440 (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys 21:05:53.0470 5896 agp440 - ok 21:05:53.0548 5896 aic78xx (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys 21:05:53.0563 5896 aic78xx - ok 21:05:53.0579 5896 ALG (5922f4f59b7868f3d74bbbbeb7b825a3) C:\Windows\System32\alg.exe 21:05:53.0641 5896 ALG - ok 21:05:53.0704 5896 aliide (157d0898d4b73f075ce9fa26b482df98) C:\Windows\system32\drivers\aliide.sys 21:05:53.0719 5896 aliide - ok 21:05:53.0750 5896 amdide (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys 21:05:53.0766 5896 amdide - ok 21:05:53.0813 5896 AmdK8 (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys 21:05:53.0860 5896 AmdK8 - ok 21:05:53.0953 5896 AntiVirSchedulerService (72709089a54bdc1c5b16bc4a4b926567) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 21:05:53.0984 5896 AntiVirSchedulerService - ok 21:05:54.0031 5896 AntiVirService (42f88bfbb76f7a63e381829479b18518) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 21:05:54.0047 5896 AntiVirService - ok 21:05:54.0156 5896 AOL ACS (85180cf88c5ebad73b452a43a004ca51) C:\Program Files (x86)\Common Files\AOL\ACS\AOLAcsd.exe 21:05:54.0172 5896 AOL ACS - ok 21:05:54.0250 5896 Appinfo (9c37b3fd5615477cb9a0cd116cf43f5c) C:\Windows\System32\appinfo.dll 21:05:54.0296 5896 Appinfo - ok 21:05:54.0343 5896 arc (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys 21:05:54.0374 5896 arc - ok 21:05:54.0452 5896 arcsas (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys 21:05:54.0484 5896 arcsas - ok 21:05:54.0546 5896 AsyncMac (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys 21:05:54.0577 5896 AsyncMac - ok 21:05:54.0593 5896 atapi (1898fae8e07d97f2f6c2d5326c633fac) C:\Windows\system32\drivers\atapi.sys 21:05:54.0624 5896 atapi - ok 21:05:54.0702 5896 AudioEndpointBuilder (79318c744693ec983d20e9337a2f8196) C:\Windows\System32\Audiosrv.dll 21:05:54.0765 5896 AudioEndpointBuilder - ok 21:05:54.0780 5896 AudioSrv (79318c744693ec983d20e9337a2f8196) C:\Windows\System32\Audiosrv.dll 21:05:54.0811 5896 AudioSrv - ok 21:05:55.0014 5896 avgntflt (aa8f79a1bdfc03b3bc70c44ab00589b4) C:\Windows\system32\DRIVERS\avgntflt.sys 21:05:55.0092 5896 avgntflt - ok 21:05:55.0279 5896 avipbb (852e3c0a60d368c487949e55ad52a47f) C:\Windows\system32\DRIVERS\avipbb.sys 21:05:55.0311 5896 avipbb - ok 21:05:55.0404 5896 avkmgr (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys 21:05:55.0451 5896 avkmgr - ok 21:05:55.0545 5896 BBSvc (825f81a6f7dd073509db101f0ba6dc59) C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE 21:05:55.0591 5896 BBSvc - ok 21:05:55.0669 5896 Beep - ok 21:05:55.0747 5896 BFE (ffb96c2589ffa60473ead78b39fbde29) C:\Windows\System32\bfe.dll 21:05:55.0888 5896 BFE - ok 21:05:55.0997 5896 BITS (6d316f4859634071cc25c4fd4589ad2c) C:\Windows\system32\qmgr.dll 21:05:56.0122 5896 BITS - ok 21:05:56.0200 5896 blbdrive (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys 21:05:56.0247 5896 blbdrive - ok 21:05:56.0325 5896 bowser (2348447a80920b2493a9b582a23e81e1) C:\Windows\system32\DRIVERS\bowser.sys 21:05:56.0356 5896 bowser - ok 21:05:56.0450 5896 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys 21:05:56.0512 5896 BrFiltLo - ok 21:05:56.0543 5896 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys 21:05:56.0590 5896 BrFiltUp - ok 21:05:56.0637 5896 Browser (a1b39de453433b115b4ea69ee0343816) C:\Windows\System32\browser.dll 21:05:56.0699 5896 Browser - ok 21:05:56.0762 5896 Brserid (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys 21:05:56.0840 5896 Brserid - ok 21:05:56.0902 5896 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys 21:05:56.0980 5896 BrSerWdm - ok 21:05:57.0027 5896 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys 21:05:57.0089 5896 BrUsbMdm - ok 21:05:57.0167 5896 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys 21:05:57.0245 5896 BrUsbSer - ok 21:05:57.0292 5896 BTHMODEM (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys 21:05:57.0370 5896 BTHMODEM - ok 21:05:57.0464 5896 BUNAgentSvc (09e6affae6c0e9158bf05c7d08d0107a) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe 21:05:57.0479 5896 BUNAgentSvc ( UnsignedFile.Multi.Generic ) - warning 21:05:57.0479 5896 BUNAgentSvc - detected UnsignedFile.Multi.Generic (1) 21:05:57.0635 5896 catchme - ok 21:05:57.0745 5896 CAXHWAZL (cd69e6640bc4778eb4159d34a707106e) C:\Windows\system32\DRIVERS\CAXHWAZL.sys 21:05:57.0776 5896 CAXHWAZL - ok 21:05:57.0823 5896 cdfs (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys 21:05:57.0869 5896 cdfs - ok 21:05:57.0963 5896 cdrom (c025aa69be3d0d25c7a2e746ef6f94fc) C:\Windows\system32\DRIVERS\cdrom.sys 21:05:57.0994 5896 cdrom - ok 21:05:58.0057 5896 CertPropSvc (5a268127633c7ee2a7fb87f39d748d56) C:\Windows\System32\certprop.dll 21:05:58.0103 5896 CertPropSvc - ok 21:05:58.0150 5896 circlass (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\DRIVERS\circlass.sys 21:05:58.0197 5896 circlass - ok 21:05:58.0260 5896 CLFS (3dca9a18b204939cfb24bea53e31eb48) C:\Windows\system32\CLFS.sys 21:05:58.0322 5896 CLFS - ok 21:05:58.0416 5896 CLHNService (5ca9b1062c0c3e3ae19c23ad9d8a5048) C:\Program Files (x86)\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe 21:05:58.0462 5896 CLHNService ( UnsignedFile.Multi.Generic ) - warning 21:05:58.0462 5896 CLHNService - detected UnsignedFile.Multi.Generic (1) 21:05:58.0540 5896 clr_optimization_v2.0.50727_32 (8ee772032e2fe80a924f3b8dd5082194) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 21:05:58.0556 5896 clr_optimization_v2.0.50727_32 - ok 21:05:58.0634 5896 clr_optimization_v2.0.50727_64 (ce07a466201096f021cd09d631b21540) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 21:05:58.0665 5896 clr_optimization_v2.0.50727_64 - ok 21:05:58.0743 5896 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 21:05:58.0759 5896 clr_optimization_v4.0.30319_32 - ok 21:05:58.0821 5896 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 21:05:58.0837 5896 clr_optimization_v4.0.30319_64 - ok 21:05:58.0977 5896 CmBatt (b52d9a14ce4101577900a364ba86f3df) C:\Windows\system32\DRIVERS\CmBatt.sys 21:05:59.0024 5896 CmBatt - ok 21:05:59.0102 5896 cmdide (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys 21:05:59.0118 5896 cmdide - ok 21:05:59.0164 5896 Compbatt (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\DRIVERS\compbatt.sys 21:05:59.0180 5896 Compbatt - ok 21:05:59.0180 5896 COMSysApp - ok 21:05:59.0196 5896 crcdisk (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys 21:05:59.0211 5896 crcdisk - ok 21:05:59.0258 5896 CryptSvc (18918613e63f387cde4d95ca7d49dcf7) C:\Windows\system32\cryptsvc.dll 21:05:59.0305 5896 CryptSvc - ok 21:05:59.0383 5896 DcomLaunch (cf8b9a3a5e7dc57724a89d0c3e8cf9ef) C:\Windows\system32\rpcss.dll 21:05:59.0445 5896 DcomLaunch - ok 21:05:59.0555 5896 DfsC (8b722ba35205c71e7951cdc4cdbade19) C:\Windows\system32\Drivers\dfsc.sys 21:05:59.0570 5896 DfsC - ok 21:05:59.0726 5896 DFSR (c647f468f7de343df8c143655c5557d4) C:\Windows\system32\DFSR.exe 21:06:00.0132 5896 DFSR - ok 21:06:00.0257 5896 Dhcp (3ed0321127ce70acdaabbf77e157c2a7) C:\Windows\System32\dhcpcsvc.dll 21:06:00.0288 5896 Dhcp - ok 21:06:00.0335 5896 disk (b0107e40ecdb5fa692ebf832f295d905) C:\Windows\system32\drivers\disk.sys 21:06:00.0366 5896 disk - ok 21:06:00.0475 5896 DKbFltr (f655c320762177f39fcd9c85cfcd8bd8) C:\Windows\syswow64\Drivers\DKbFltr.sys 21:06:00.0491 5896 DKbFltr - ok 21:06:00.0600 5896 Dnscache (06230f1b721494a6df8d47fd395bb1b0) C:\Windows\System32\dnsrslvr.dll 21:06:00.0631 5896 Dnscache - ok 21:06:00.0662 5896 dot3svc (1a7156dd1e850e9914e5e991e3225b94) C:\Windows\System32\dot3svc.dll 21:06:00.0709 5896 dot3svc - ok 21:06:00.0803 5896 DPS (1583b39790db3eaec7edb0cb0140c708) C:\Windows\system32\dps.dll 21:06:00.0850 5896 DPS - ok 21:06:00.0881 5896 drmkaud (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys 21:06:00.0943 5896 drmkaud - ok 21:06:01.0037 5896 DXGKrnl (b8e554e502d5123bc111f99d6a2181b4) C:\Windows\System32\drivers\dxgkrnl.sys 21:06:01.0084 5896 DXGKrnl - ok 21:06:01.0193 5896 E1G60 (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys 21:06:01.0240 5896 E1G60 - ok 21:06:01.0302 5896 EapHost (c2303883fd9be49dc36a6400643002ea) C:\Windows\System32\eapsvc.dll 21:06:01.0333 5896 EapHost - ok 21:06:01.0427 5896 Ecache (5f94962be5a62db6e447ff6470c4f48a) C:\Windows\system32\drivers\ecache.sys 21:06:01.0442 5896 Ecache - ok 21:06:01.0520 5896 eDataSecurity Service (b1f2503e23425b386df0f3413b2596f3) C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe 21:06:01.0552 5896 eDataSecurity Service - ok 21:06:01.0598 5896 ehRecvr (14ce384d2e27b64c256bda4dc39c312d) C:\Windows\ehome\ehRecvr.exe 21:06:01.0676 5896 ehRecvr - ok 21:06:01.0692 5896 ehSched (b93159c1313d66fdfbbe876f5189cd52) C:\Windows\ehome\ehsched.exe 21:06:01.0723 5896 ehSched - ok 21:06:01.0786 5896 ehstart (f5ee2527d74449868e3c3227a59bcd28) C:\Windows\ehome\ehstart.dll 21:06:01.0833 5896 ehstart - ok 21:06:01.0911 5896 elxstor (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys 21:06:01.0942 5896 elxstor - ok 21:06:01.0989 5896 EMDMgmt (a9b18b63a4fd6baab83326706d857fab) C:\Windows\system32\emdmgmt.dll 21:06:02.0051 5896 EMDMgmt - ok 21:06:02.0129 5896 ErrDev (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys 21:06:02.0176 5896 ErrDev - ok 21:06:02.0254 5896 ETService (c0fe39b8f686b7c70a666e716cc12b49) C:\Program Files\Acer\Empowering Technology\Service\ETService.exe 21:06:02.0269 5896 ETService ( UnsignedFile.Multi.Generic ) - warning 21:06:02.0269 5896 ETService - detected UnsignedFile.Multi.Generic (1) 21:06:02.0347 5896 EventSystem (e12f22b73f153dece721cd45ec05b4af) C:\Windows\system32\es.dll 21:06:02.0441 5896 EventSystem - ok 21:06:02.0503 5896 exfat (486844f47b6636044a42454614ed4523) C:\Windows\system32\drivers\exfat.sys 21:06:02.0550 5896 exfat - ok 21:06:02.0659 5896 fastfat (1a4bee34277784619ddaf0422c0c6e23) C:\Windows\system32\drivers\fastfat.sys 21:06:02.0691 5896 fastfat - ok 21:06:02.0769 5896 fdc (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys 21:06:02.0831 5896 fdc - ok 21:06:02.0878 5896 fdPHost (bb9267acacd8b7533dd936c34a0cba5e) C:\Windows\system32\fdPHost.dll 21:06:02.0909 5896 fdPHost - ok 21:06:02.0971 5896 FDResPub (300c80931eabbe1db7591c516efe8d0f) C:\Windows\system32\fdrespub.dll 21:06:03.0034 5896 FDResPub - ok 21:06:03.0065 5896 FileInfo (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys 21:06:03.0096 5896 FileInfo - ok 21:06:03.0159 5896 Filetrace (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys 21:06:03.0221 5896 Filetrace - ok 21:06:03.0252 5896 flpydisk (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 21:06:03.0299 5896 flpydisk - ok 21:06:03.0393 5896 FltMgr (e3041bc26d6930d61f42aedb79c91720) C:\Windows\system32\drivers\fltmgr.sys 21:06:03.0408 5896 FltMgr - ok 21:06:03.0549 5896 FontCache (be1c5bd1ca7ed015bc6fa1ae67e592c8) C:\Windows\system32\FntCache.dll 21:06:03.0611 5896 FontCache - ok 21:06:03.0736 5896 FontCache3.0.0.0 (bc5b0be5af3510b0fd8c140ee42c6d3e) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 21:06:03.0752 5896 FontCache3.0.0.0 - ok 21:06:03.0861 5896 FreeAgentGoNext Service (9513b437b7adb1e6065b7f0d83d11ecf) C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe 21:06:03.0876 5896 FreeAgentGoNext Service - ok 21:06:03.0970 5896 Fs_Rec (5779b86cd8b32519fbecb136394d946a) C:\Windows\system32\drivers\Fs_Rec.sys 21:06:03.0986 5896 Fs_Rec - ok 21:06:04.0048 5896 gagp30kx (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys 21:06:04.0064 5896 gagp30kx - ok 21:06:04.0095 5896 gpsvc (a0e1b575ba8f504968cd40c0faeb2384) C:\Windows\System32\gpsvc.dll 21:06:04.0188 5896 gpsvc - ok 21:06:04.0313 5896 gupdate (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 21:06:04.0329 5896 gupdate - ok 21:06:04.0345 5896 gupdatem (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 21:06:04.0360 5896 gupdatem - ok 21:06:04.0423 5896 gusvc (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe 21:06:04.0454 5896 gusvc - ok 21:06:04.0563 5896 HdAudAddService (df45f8142dc6df9d18c39b3effbd0409) C:\Windows\system32\drivers\HdAudio.sys 21:06:04.0641 5896 HdAudAddService - ok 21:06:04.0703 5896 HDAudBus (f942c5820205f2fb453243edfec82a3d) C:\Windows\system32\DRIVERS\HDAudBus.sys 21:06:04.0828 5896 HDAudBus - ok 21:06:04.0906 5896 HidBth (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys 21:06:04.0969 5896 HidBth - ok 21:06:05.0031 5896 HidIr (5f47839455d01ff6403b008d481a6f5b) C:\Windows\system32\DRIVERS\hidir.sys 21:06:05.0078 5896 HidIr - ok 21:06:05.0140 5896 hidserv (59361d38a297755d46a540e450202b2a) C:\Windows\System32\hidserv.dll 21:06:05.0187 5896 hidserv - ok 21:06:05.0265 5896 HidUsb (443bdd2d30bb4f00795c797e2cf99edf) C:\Windows\system32\DRIVERS\hidusb.sys 21:06:05.0281 5896 HidUsb - ok 21:06:05.0343 5896 hkmsvc (b12f367ea39c0795fd57e31242ce1a5a) C:\Windows\system32\kmsvc.dll 21:06:05.0374 5896 hkmsvc - ok 21:06:05.0452 5896 HpCISSs (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys 21:06:05.0484 5896 HpCISSs - ok 21:06:05.0577 5896 HSFHWAZL (57ba73b5b321291e5114cb21350e1ea0) C:\Windows\system32\DRIVERS\VSTAZL6.SYS 21:06:05.0640 5896 HSFHWAZL - ok 21:06:05.0718 5896 HSF_DPV (ebdba99c2362457be429f024396b63be) C:\Windows\system32\DRIVERS\CAX_DPV.sys 21:06:05.0827 5896 HSF_DPV - ok 21:06:05.0952 5896 HTTP (098f1e4e5c9cb5b0063a959063631610) C:\Windows\system32\drivers\HTTP.sys 21:06:06.0061 5896 HTTP - ok 21:06:06.0170 5896 i2omp (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys 21:06:06.0186 5896 i2omp - ok 21:06:06.0264 5896 i8042prt (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys 21:06:06.0310 5896 i8042prt - ok 21:06:06.0388 5896 IAANTMON (3e42c4691aad4b1e8d0466f9cbf05cbe) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe 21:06:06.0420 5896 IAANTMON - ok 21:06:06.0513 5896 iaStor (fc28e90f2204d8fd147fa9bfa8a51c01) C:\Windows\system32\DRIVERS\iaStor.sys 21:06:06.0544 5896 iaStor - ok 21:06:06.0591 5896 iaStorV (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys 21:06:06.0607 5896 iaStorV - ok 21:06:06.0716 5896 idsvc (749f5f8cedca70f2a512945325fc489d) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 21:06:06.0779 5896 idsvc - ok 21:06:07.0122 5896 igfx (c6238c6abd6ac99f5d152da4e9439a3d) C:\Windows\system32\DRIVERS\igdkmd64.sys 21:06:08.0276 5896 igfx - ok 21:06:08.0370 5896 iirsp (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys 21:06:08.0386 5896 iirsp - ok 21:06:08.0448 5896 IKEEXT (0c9ea6e654e7b0471741e343a6c671af) C:\Windows\System32\ikeext.dll 21:06:08.0573 5896 IKEEXT - ok 21:06:08.0651 5896 int15 (8c7fa71cb1ebcd3ede8958d27b1bf0b4) C:\Windows\SysWOW64\drivers\int15_64.sys 21:06:08.0651 5896 int15 - ok 21:06:08.0807 5896 IntcAzAudAddService (6fdf709500c20362ffc5057f0d1e0c8d) C:\Windows\system32\drivers\RTKVHD64.sys 21:06:08.0994 5896 IntcAzAudAddService - ok 21:06:09.0119 5896 IntcHdmiAddService (c7c9720a5b0fd2b974fc4f72e405204b) C:\Windows\system32\drivers\IntcHdmi.sys 21:06:09.0150 5896 IntcHdmiAddService - ok 21:06:09.0197 5896 intelide (df797a12176f11b2d301c5b234bb200e) C:\Windows\system32\drivers\intelide.sys 21:06:09.0213 5896 intelide - ok 21:06:09.0259 5896 intelppm (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys 21:06:09.0322 5896 intelppm - ok 21:06:09.0369 5896 IPBusEnum (5624bc1bc5eeb49c0ab76a8114f05ea3) C:\Windows\system32\ipbusenum.dll 21:06:09.0415 5896 IPBusEnum - ok 21:06:09.0478 5896 IpFilterDriver (d8aabc341311e4780d6fce8c73c0ad81) C:\Windows\system32\DRIVERS\ipfltdrv.sys 21:06:09.0525 5896 IpFilterDriver - ok 21:06:09.0571 5896 iphlpsvc (bf0dbfa9792c5c14fa00f61c75116c1b) C:\Windows\System32\iphlpsvc.dll 21:06:09.0618 5896 iphlpsvc - ok 21:06:09.0665 5896 IpInIp - ok 21:06:09.0743 5896 IPMIDRV (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys 21:06:09.0805 5896 IPMIDRV - ok 21:06:09.0837 5896 IPNAT (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys 21:06:09.0899 5896 IPNAT - ok 21:06:09.0961 5896 IRENUM (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys 21:06:10.0024 5896 IRENUM - ok 21:06:10.0071 5896 isapnp (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys 21:06:10.0086 5896 isapnp - ok 21:06:10.0164 5896 iScsiPrt (49e4ccbf74783fce5d2cc1ff6480e1f4) C:\Windows\system32\DRIVERS\msiscsi.sys 21:06:10.0180 5896 iScsiPrt - ok 21:06:10.0227 5896 iteatapi (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys 21:06:10.0242 5896 iteatapi - ok 21:06:10.0274 5896 iteraid (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys 21:06:10.0305 5896 iteraid - ok 21:06:10.0352 5896 kbdclass (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys 21:06:10.0383 5896 kbdclass - ok 21:06:10.0398 5896 kbdhid (bf8783a5066cfecf45095459e8010fa7) C:\Windows\system32\DRIVERS\kbdhid.sys 21:06:10.0461 5896 kbdhid - ok 21:06:10.0492 5896 KeyIso (260bf9c43ee12c6898a9f5aab0fb0e5d) C:\Windows\system32\lsass.exe 21:06:10.0523 5896 KeyIso - ok 21:06:10.0617 5896 KSecDD (2758d174604f597bbc8a217ff667913d) C:\Windows\system32\Drivers\ksecdd.sys 21:06:10.0664 5896 KSecDD - ok 21:06:10.0742 5896 ksthunk (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys 21:06:10.0804 5896 ksthunk - ok 21:06:10.0882 5896 KtmRm (1faf6926f3416d3da05c5b265491bdae) C:\Windows\system32\msdtckrm.dll 21:06:10.0944 5896 KtmRm - ok 21:06:11.0022 5896 L1E (073508533e422ce8bcee234eb35ceebf) C:\Windows\system32\DRIVERS\L1E60x64.sys 21:06:11.0038 5896 L1E - ok 21:06:11.0100 5896 LanmanServer (50c7a3cb427e9bb5ed0708a669956ab5) C:\Windows\System32\srvsvc.dll 21:06:11.0163 5896 LanmanServer - ok 21:06:11.0225 5896 LanmanWorkstation (caf86fc1388be1e470f1a7b43e348adb) C:\Windows\System32\wkssvc.dll 21:06:11.0241 5896 LanmanWorkstation - ok 21:06:11.0303 5896 LightScribeService (793ff718477345cd5d232c50bed1e452) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe 21:06:11.0319 5896 LightScribeService ( UnsignedFile.Multi.Generic ) - warning 21:06:11.0319 5896 LightScribeService - detected UnsignedFile.Multi.Generic (1) 21:06:11.0397 5896 lltdio (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys 21:06:11.0459 5896 lltdio - ok 21:06:11.0522 5896 lltdsvc (961ccbd0b1ccb5675d64976fae37d092) C:\Windows\System32\lltdsvc.dll 21:06:11.0569 5896 lltdsvc - ok 21:06:11.0631 5896 lmhosts (a47f8080cacc23c91fe823ad19aa5612) C:\Windows\System32\lmhsvc.dll 21:06:11.0678 5896 lmhosts - ok 21:06:11.0740 5896 LSI_FC (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys 21:06:11.0756 5896 LSI_FC - ok 21:06:11.0803 5896 LSI_SAS (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys 21:06:11.0834 5896 LSI_SAS - ok 21:06:11.0865 5896 LSI_SCSI (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys 21:06:11.0896 5896 LSI_SCSI - ok 21:06:11.0943 5896 luafv (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys 21:06:11.0990 5896 luafv - ok 21:06:12.0037 5896 Mcx2Svc (76a58df02bd4ea29f189b82d0bef17f8) C:\Windows\system32\Mcx2Svc.dll 21:06:12.0068 5896 Mcx2Svc - ok 21:06:12.0130 5896 mdmxsdk (e4f44ec214b3e381e1fc844a02926666) C:\Windows\system32\DRIVERS\mdmxsdk.sys 21:06:12.0161 5896 mdmxsdk - ok 21:06:12.0239 5896 megasas (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys 21:06:12.0271 5896 megasas - ok 21:06:12.0317 5896 MegaSR (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys 21:06:12.0349 5896 MegaSR - ok 21:06:12.0380 5896 MMCSS (3cbe4995e80e13ccfbc42e5dcf3ac81a) C:\Windows\system32\mmcss.dll 21:06:12.0442 5896 MMCSS - ok 21:06:12.0505 5896 MobilityService - ok 21:06:12.0583 5896 Modem (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys 21:06:12.0630 5896 Modem - ok 21:06:12.0676 5896 monitor (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys 21:06:12.0723 5896 monitor - ok 21:06:12.0739 5896 mouclass (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys 21:06:12.0770 5896 mouclass - ok 21:06:12.0848 5896 mouhid (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys 21:06:12.0895 5896 mouhid - ok 21:06:12.0926 5896 MountMgr (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys 21:06:12.0957 5896 MountMgr - ok 21:06:13.0035 5896 mpio (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys 21:06:13.0066 5896 mpio - ok 21:06:13.0113 5896 mpsdrv (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys 21:06:13.0160 5896 mpsdrv - ok 21:06:13.0207 5896 MpsSvc (897e3baf68ba406a61682ae39c83900c) C:\Windows\system32\mpssvc.dll 21:06:13.0254 5896 MpsSvc - ok 21:06:13.0363 5896 Mraid35x (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys 21:06:13.0378 5896 Mraid35x - ok 21:06:13.0425 5896 MRxDAV (7c1de4aa96dc0c071611f9e7de02a68d) C:\Windows\system32\drivers\mrxdav.sys 21:06:13.0456 5896 MRxDAV - ok 21:06:13.0503 5896 mrxsmb (1485811b320ff8c7edad1caebb1c6c2b) C:\Windows\system32\DRIVERS\mrxsmb.sys 21:06:13.0550 5896 mrxsmb - ok 21:06:13.0628 5896 mrxsmb10 (3b929a60c833fc615fd97fba82bc7632) C:\Windows\system32\DRIVERS\mrxsmb10.sys 21:06:13.0675 5896 mrxsmb10 - ok 21:06:13.0722 5896 mrxsmb20 (c64ab3e1f53b4f5b5bb6d796b2d7bec3) C:\Windows\system32\DRIVERS\mrxsmb20.sys 21:06:13.0753 5896 mrxsmb20 - ok 21:06:13.0831 5896 msahci (1ac860612b85d8e85ee257d372e39f4d) C:\Windows\system32\drivers\msahci.sys 21:06:13.0847 5896 msahci - ok 21:06:13.0893 5896 msdsm (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys 21:06:13.0925 5896 msdsm - ok 21:06:13.0956 5896 MSDTC (7ec02ce772f068ed0beafa3da341a9bc) C:\Windows\System32\msdtc.exe 21:06:14.0003 5896 MSDTC - ok 21:06:14.0096 5896 Msfs (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys 21:06:14.0143 5896 Msfs - ok 21:06:14.0190 5896 msisadrv (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys 21:06:14.0205 5896 msisadrv - ok 21:06:14.0237 5896 MSiSCSI (366b0c1f4478b519c181e37d43dcda32) C:\Windows\system32\iscsiexe.dll 21:06:14.0299 5896 MSiSCSI - ok 21:06:14.0330 5896 msiserver - ok 21:06:14.0424 5896 MSKSSRV (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys 21:06:14.0471 5896 MSKSSRV - ok 21:06:14.0502 5896 MSPCLOCK (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys 21:06:14.0549 5896 MSPCLOCK - ok 21:06:14.0564 5896 MSPQM (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys 21:06:14.0627 5896 MSPQM - ok 21:06:14.0705 5896 MsRPC (dc6ccf440cdede4293db41c37a5060a5) C:\Windows\system32\drivers\MsRPC.sys 21:06:14.0736 5896 MsRPC - ok 21:06:14.0798 5896 mssmbios (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys 21:06:14.0814 5896 mssmbios - ok 21:06:14.0892 5896 MSTEE (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys 21:06:14.0954 5896 MSTEE - ok 21:06:15.0017 5896 Mup (0cc49f78d8aca0877d885f149084e543) C:\Windows\system32\Drivers\mup.sys 21:06:15.0048 5896 Mup - ok 21:06:15.0095 5896 napagent (a5b10c845e7538c60c0f5d87a57cb3f5) C:\Windows\system32\qagentRT.dll 21:06:15.0157 5896 napagent - ok 21:06:15.0391 5896 NativeWifiP (2007b826c4acd94ae32232b41f0842b9) C:\Windows\system32\DRIVERS\nwifi.sys 21:06:15.0438 5896 NativeWifiP - ok 21:06:15.0641 5896 NDIS (65950e07329fcee8e6516b17c8d0abb6) C:\Windows\system32\drivers\ndis.sys 21:06:15.0688 5896 NDIS - ok 21:06:15.0859 5896 NdisTapi (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys 21:06:16.0046 5896 NdisTapi - ok 21:06:16.0499 5896 Ndisuio (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys 21:06:16.0546 5896 Ndisuio - ok 21:06:16.0639 5896 NdisWan (f8158771905260982ce724076419ef19) C:\Windows\system32\DRIVERS\ndiswan.sys 21:06:16.0686 5896 NdisWan - ok 21:06:16.0733 5896 NDProxy (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys 21:06:16.0764 5896 NDProxy - ok 21:06:16.0858 5896 NetBIOS (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys 21:06:16.0920 5896 NetBIOS - ok 21:06:16.0983 5896 netbt (fc2c792ebddc8e28df939d6a92c83d61) C:\Windows\system32\DRIVERS\netbt.sys 21:06:17.0045 5896 netbt - ok 21:06:17.0076 5896 Netlogon (260bf9c43ee12c6898a9f5aab0fb0e5d) C:\Windows\system32\lsass.exe 21:06:17.0092 5896 Netlogon - ok 21:06:17.0154 5896 Netman (9b63b29defc0f3115a559d2597bf5d75) C:\Windows\System32\netman.dll 21:06:17.0232 5896 Netman - ok 21:06:17.0295 5896 netprofm (7846d0136cc2b264926a73047ba7688a) C:\Windows\System32\netprofm.dll 21:06:17.0341 5896 netprofm - ok 21:06:17.0435 5896 NetTcpPortSharing (74751dda198165947fd7454d83f49825) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 21:06:17.0466 5896 NetTcpPortSharing - ok 21:06:17.0654 5896 NETw5v64 (2bdcb7b7917380794c9d87ac2153ce33) C:\Windows\system32\DRIVERS\NETw5v64.sys 21:06:18.0200 5896 NETw5v64 - ok 21:06:18.0293 5896 nfrd960 (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys 21:06:18.0309 5896 nfrd960 - ok 21:06:18.0356 5896 NlaSvc (f145bf4c4668e7e312069f81ef847cfc) C:\Windows\System32\nlasvc.dll 21:06:18.0402 5896 NlaSvc - ok 21:06:18.0480 5896 Npfs (b298874f8e0ea93f06ec40aa8d146478) C:\Windows\system32\drivers\Npfs.sys 21:06:18.0543 5896 Npfs - ok 21:06:18.0605 5896 nsi (acb62baa1c319b17752553df3026eeeb) C:\Windows\system32\nsisvc.dll 21:06:18.0637 5896 nsi - ok 21:06:18.0699 5896 nsiproxy (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys 21:06:18.0746 5896 nsiproxy - ok 21:06:18.0839 5896 Ntfs (bac869dfb98e499ba4d9bb1fb43270e1) C:\Windows\system32\drivers\Ntfs.sys 21:06:18.0917 5896 Ntfs - ok 21:06:18.0964 5896 NTIBackupSvc (a2b6583a5652a385dff5e4f49ad48761) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe 21:06:18.0995 5896 NTIBackupSvc ( UnsignedFile.Multi.Generic ) - warning 21:06:18.0995 5896 NTIBackupSvc - detected UnsignedFile.Multi.Generic (1) 21:06:19.0120 5896 NTIDrvr (7d397449aaf52b0e7c79b64f6ad4473e) C:\Windows\system32\Drivers\NTIDrvr.sys 21:06:19.0136 5896 NTIDrvr - ok 21:06:19.0198 5896 NTISchedulerSvc (40b87fe8a1a9a5ac9e5a91d96f212bcd) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe 21:06:19.0229 5896 NTISchedulerSvc ( UnsignedFile.Multi.Generic ) - warning 21:06:19.0229 5896 NTISchedulerSvc - detected UnsignedFile.Multi.Generic (1) 21:06:19.0307 5896 Null (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys 21:06:19.0354 5896 Null - ok 21:06:19.0432 5896 nvraid (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys 21:06:19.0448 5896 nvraid - ok 21:06:19.0495 5896 nvstor (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys 21:06:19.0510 5896 nvstor - ok 21:06:19.0541 5896 nv_agp (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys 21:06:19.0573 5896 nv_agp - ok 21:06:19.0619 5896 NwlnkFlt - ok 21:06:19.0697 5896 NwlnkFwd - ok 21:06:19.0854 5896 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 21:06:19.0885 5896 odserv - ok 21:06:19.0994 5896 ohci1394 (7b58953e2f263421fdbb09a192712a85) C:\Windows\system32\drivers\ohci1394.sys 21:06:20.0056 5896 ohci1394 - ok 21:06:20.0134 5896 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 21:06:20.0166 5896 ose - ok 21:06:20.0259 5896 p2pimsvc (9ae31d2e1d15c10d91318e0ec149ceac) C:\Windows\system32\p2psvc.dll 21:06:20.0384 5896 p2pimsvc - ok 21:06:20.0431 5896 p2psvc (9ae31d2e1d15c10d91318e0ec149ceac) C:\Windows\system32\p2psvc.dll 21:06:20.0524 5896 p2psvc - ok 21:06:20.0634 5896 Parport (aecd57f94c887f58919f307c35498ea0) C:\Windows\system32\drivers\parport.sys 21:06:20.0727 5896 Parport - ok 21:06:20.0790 5896 partmgr (f9b5eda4c17a2be7663f064dbf0fe254) C:\Windows\system32\drivers\partmgr.sys 21:06:20.0805 5896 partmgr - ok 21:06:20.0852 5896 PcaSvc (9ab157b374192ff276c1628fbdba2b0e) C:\Windows\System32\pcasvc.dll 21:06:20.0914 5896 PcaSvc - ok 21:06:21.0008 5896 pci (47ab1e0fc9d0e12bb53ba246e3a0906d) C:\Windows\system32\drivers\pci.sys 21:06:21.0039 5896 pci - ok 21:06:21.0086 5896 pciide (8d618c829034479985a9ed56106cc732) C:\Windows\system32\drivers\pciide.sys 21:06:21.0102 5896 pciide - ok 21:06:21.0133 5896 pcmcia (037661f3d7c507c9993b7010ceee6288) C:\Windows\system32\drivers\pcmcia.sys 21:06:21.0149 5896 pcmcia - ok 21:06:21.0242 5896 PEAUTH (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys 21:06:21.0351 5896 PEAUTH - ok 21:06:21.0429 5896 PerfHost (0ed8727ea0172860f47258456c06caea) C:\Windows\SysWow64\perfhost.exe 21:06:21.0476 5896 PerfHost - ok 21:06:21.0570 5896 pla (e9e68c1a0f25cf4a7ac966eea74ee89e) C:\Windows\system32\pla.dll 21:06:21.0757 5896 pla - ok 21:06:21.0851 5896 PlugPlay (fe6b0f59215c9fd9f9d26539c58c8b82) C:\Windows\system32\umpnpmgr.dll 21:06:21.0913 5896 PlugPlay - ok 21:06:21.0960 5896 PNRPAutoReg (9ae31d2e1d15c10d91318e0ec149ceac) C:\Windows\system32\p2psvc.dll 21:06:21.0991 5896 PNRPAutoReg - ok 21:06:22.0007 5896 PNRPsvc (9ae31d2e1d15c10d91318e0ec149ceac) C:\Windows\system32\p2psvc.dll 21:06:22.0038 5896 PNRPsvc - ok 21:06:22.0131 5896 PolicyAgent (89a5560671c2d8b4a4b51f3e1aa069d8) C:\Windows\System32\ipsecsvc.dll 21:06:22.0225 5896 PolicyAgent - ok 21:06:22.0334 5896 PptpMiniport (23386e9952025f5f21c368971e2e7301) C:\Windows\system32\DRIVERS\raspptp.sys 21:06:22.0366 5896 PptpMiniport - ok 21:06:22.0428 5896 Processor (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\drivers\processr.sys 21:06:22.0459 5896 Processor - ok 21:06:22.0490 5896 ProfSvc (e058ce4fc2449d8bfa14739c83b7ff2a) C:\Windows\system32\profsvc.dll 21:06:22.0522 5896 ProfSvc - ok 21:06:22.0584 5896 ProtectedStorage (260bf9c43ee12c6898a9f5aab0fb0e5d) C:\Windows\system32\lsass.exe 21:06:22.0600 5896 ProtectedStorage - ok 21:06:22.0646 5896 PSched (c5ab7f0809392d0da027f4a2a81bfa31) C:\Windows\system32\DRIVERS\pacer.sys 21:06:22.0678 5896 PSched - ok 21:06:22.0771 5896 PSDFilter (2cfd31d41cde75328acaeee2d4f4b836) C:\Windows\system32\DRIVERS\psdfilter.sys 21:06:22.0787 5896 PSDFilter - ok 21:06:22.0834 5896 PSDNServ (51a585f999672d8bb07f22ae12b40846) C:\Windows\system32\DRIVERS\PSDNServ.sys 21:06:22.0849 5896 PSDNServ - ok 21:06:22.0865 5896 psdvdisk (db50d3f5c31b1a848b04f7f2a6ff2709) C:\Windows\system32\DRIVERS\PSDVdisk.sys 21:06:22.0880 5896 psdvdisk - ok 21:06:22.0990 5896 ql2300 (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys 21:06:23.0052 5896 ql2300 - ok 21:06:23.0192 5896 ql40xx (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys 21:06:23.0208 5896 ql40xx - ok 21:06:23.0270 5896 QWAVE (90574842c3da781e279061a3eff91f07) C:\Windows\system32\qwave.dll 21:06:23.0302 5896 QWAVE - ok 21:06:23.0380 5896 QWAVEdrv (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys 21:06:23.0395 5896 QWAVEdrv - ok 21:06:23.0458 5896 RasAcd (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys 21:06:23.0520 5896 RasAcd - ok 21:06:23.0567 5896 RasAuto (b2ae18f847d07f0044404ddf7cb04497) C:\Windows\System32\rasauto.dll 21:06:23.0629 5896 RasAuto - ok 21:06:23.0707 5896 Rasl2tp (ac7bc4d42a7e558718dfdec599bbfc2c) C:\Windows\system32\DRIVERS\rasl2tp.sys 21:06:23.0754 5896 Rasl2tp - ok 21:06:23.0801 5896 RasMan (3ad83e4046c43be510de681588acb8af) C:\Windows\System32\rasmans.dll 21:06:23.0863 5896 RasMan - ok 21:06:23.0941 5896 RasPppoe (4517fbf8b42524afe4ede1de102aae3e) C:\Windows\system32\DRIVERS\raspppoe.sys 21:06:23.0973 5896 RasPppoe - ok 21:06:24.0035 5896 RasSstp (c6a593b51f34c33e5474539544072527) C:\Windows\system32\DRIVERS\rassstp.sys 21:06:24.0066 5896 RasSstp - ok 21:06:24.0144 5896 rdbss (322db5c6b55e8d8ee8d6f358b2aaabb1) C:\Windows\system32\DRIVERS\rdbss.sys 21:06:24.0207 5896 rdbss - ok 21:06:24.0253 5896 RDPCDD (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys 21:06:24.0300 5896 RDPCDD - ok 21:06:24.0363 5896 rdpdr (c045d1fb111c28df0d1be8d4bda22c06) C:\Windows\system32\drivers\rdpdr.sys 21:06:24.0425 5896 rdpdr - ok 21:06:24.0503 5896 RDPENCDD (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys 21:06:24.0565 5896 RDPENCDD - ok 21:06:24.0644 5896 RDPWD (5c141fc457f1ac833664789235aca673) C:\Windows\system32\drivers\RDPWD.sys 21:06:24.0690 5896 RDPWD - ok 21:06:24.0737 5896 RemoteAccess (c612b9557da73f70d41f8a6fbc8e5344) C:\Windows\System32\mprdim.dll 21:06:24.0800 5896 RemoteAccess - ok 21:06:24.0862 5896 RemoteRegistry (44b9d8ec2f3ef3a0efb00857af70d861) C:\Windows\system32\regsvc.dll 21:06:24.0909 5896 RemoteRegistry - ok 21:06:24.0987 5896 Revoflt (9c3ac71a9934b884fac567a8807e9c4d) C:\Windows\system32\DRIVERS\revoflt.sys 21:06:25.0002 5896 Revoflt - ok 21:06:25.0096 5896 RichVideo (17e0bef5ca5c9ce52cc8082ac6ebc449) C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe 21:06:25.0112 5896 RichVideo - ok 21:06:25.0174 5896 RpcLocator (f46c457840d4b7a4daafee739ce04102) C:\Windows\system32\locator.exe 21:06:25.0221 5896 RpcLocator - ok 21:06:25.0268 5896 RpcSs (cf8b9a3a5e7dc57724a89d0c3e8cf9ef) C:\Windows\System32\rpcss.dll 21:06:25.0314 5896 RpcSs - ok 21:06:25.0392 5896 rspndr (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys 21:06:25.0439 5896 rspndr - ok 21:06:25.0502 5896 RTSTOR (4ad8464fece8ebe276d4a7d75e418452) C:\Windows\system32\drivers\RTSTOR64.SYS 21:06:25.0533 5896 RTSTOR - ok 21:06:25.0580 5896 SamSs (260bf9c43ee12c6898a9f5aab0fb0e5d) C:\Windows\system32\lsass.exe 21:06:25.0595 5896 SamSs - ok 21:06:25.0658 5896 sbp2port (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys 21:06:25.0689 5896 sbp2port - ok 21:06:25.0736 5896 SCardSvr (fd1cdcf108d5ef3366f00d18b70fb89b) C:\Windows\System32\SCardSvr.dll 21:06:25.0782 5896 SCardSvr - ok 21:06:25.0845 5896 Schedule (0f838c811ad295d2a4489b9993096c63) C:\Windows\system32\schedsvc.dll 21:06:25.0923 5896 Schedule - ok 21:06:25.0985 5896 SCPolicySvc (5a268127633c7ee2a7fb87f39d748d56) C:\Windows\System32\certprop.dll 21:06:26.0017 5896 SCPolicySvc - ok 21:06:26.0048 5896 SDRSVC (4ff71b076a7760fe75ea5ae2d0ee0018) C:\Windows\System32\SDRSVC.dll 21:06:26.0095 5896 SDRSVC - ok 21:06:26.0157 5896 SeaPort (cc781378e7eda615d2cdca3b17829fa4) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE 21:06:26.0173 5896 SeaPort - ok 21:06:26.0251 5896 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 21:06:26.0329 5896 secdrv - ok 21:06:26.0391 5896 seclogon (5acdcbc67fcf894a1815b9f96d704490) C:\Windows\system32\seclogon.dll 21:06:26.0438 5896 seclogon - ok 21:06:26.0500 5896 SENS (90973a64b96cd647ff81c79443618eed) C:\Windows\system32\sens.dll 21:06:26.0547 5896 SENS - ok 21:06:26.0625 5896 Serenum (f71bfe7ac6c52273b7c82cbf1bb2a222) C:\Windows\system32\drivers\serenum.sys 21:06:26.0687 5896 Serenum - ok 21:06:26.0765 5896 Serial (e62fac91ee288db29a9696a9d279929c) C:\Windows\system32\drivers\serial.sys 21:06:26.0843 5896 Serial - ok 21:06:26.0890 5896 sermouse (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys 21:06:26.0937 5896 sermouse - ok 21:06:27.0015 5896 SessionEnv (a8e4a4407a09f35dccc3771af590b0c4) C:\Windows\system32\sessenv.dll 21:06:27.0062 5896 SessionEnv - ok 21:06:27.0124 5896 sffdisk (14d4b4465193a87c127933978e8c4106) C:\Windows\system32\drivers\sffdisk.sys 21:06:27.0156 5896 sffdisk - ok 21:06:27.0218 5896 sffp_mmc (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys 21:06:27.0265 5896 sffp_mmc - ok 21:06:27.0312 5896 sffp_sd (35e59ebe4a01a0532ed67975161c7b82) C:\Windows\system32\drivers\sffp_sd.sys 21:06:27.0358 5896 sffp_sd - ok 21:06:27.0390 5896 sfloppy (6b7838c94135768bd455cbdc23e39e5f) C:\Windows\system32\drivers\sfloppy.sys 21:06:27.0452 5896 sfloppy - ok 21:06:27.0483 5896 SharedAccess (4c5aee179da7e1ee9a9ccb9da289af34) C:\Windows\System32\ipnathlp.dll 21:06:27.0561 5896 SharedAccess - ok 21:06:27.0795 5896 ShellHWDetection (56793271ecdedd350c5add305603e963) C:\Windows\System32\shsvcs.dll 21:06:27.0873 5896 ShellHWDetection - ok 21:06:27.0951 5896 SiSRaid2 (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys 21:06:27.0967 5896 SiSRaid2 - ok 21:06:28.0029 5896 SiSRaid4 (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys 21:06:28.0045 5896 SiSRaid4 - ok 21:06:28.0373 5896 slsvc (a9a27a8e257b45a604fdad4f26fe7241) C:\Windows\system32\SLsvc.exe 21:06:28.0763 5896 slsvc - ok 21:06:28.0841 5896 SLUINotify (fd74b4b7c2088e390a30c85a896fc3af) C:\Windows\system32\SLUINotify.dll 21:06:28.0872 5896 SLUINotify - ok 21:06:28.0934 5896 Smb (290b6f6a0ec4fcdfc90f5cb6d7020473) C:\Windows\system32\DRIVERS\smb.sys 21:06:28.0965 5896 Smb - ok 21:06:29.0043 5896 SNMPTRAP (f8f47f38909823b1af28d60b96340cff) C:\Windows\System32\snmptrap.exe 21:06:29.0059 5896 SNMPTRAP - ok 21:06:29.0121 5896 spldr (386c3c63f00a7040c7ec5e384217e89d) C:\Windows\system32\drivers\spldr.sys 21:06:29.0137 5896 spldr - ok 21:06:29.0215 5896 Spooler (f66ff751e7efc816d266977939ef5dc3) C:\Windows\System32\spoolsv.exe 21:06:29.0246 5896 Spooler - ok 21:06:29.0309 5896 srv (880a57fccb571ebd063d4dd50e93e46d) C:\Windows\system32\DRIVERS\srv.sys 21:06:29.0371 5896 srv - ok 21:06:29.0480 5896 srv2 (a1ad14a6d7a37891fffeca35ebbb0730) C:\Windows\system32\DRIVERS\srv2.sys 21:06:29.0496 5896 srv2 - ok 21:06:29.0558 5896 srvnet (4bed62f4fa4d8300973f1151f4c4d8a7) C:\Windows\system32\DRIVERS\srvnet.sys 21:06:29.0574 5896 srvnet - ok 21:06:29.0621 5896 SSDPSRV (192c74646ec5725aef3f80d19ff75f6a) C:\Windows\System32\ssdpsrv.dll 21:06:29.0652 5896 SSDPSRV - ok 21:06:29.0714 5896 SstpSvc (2ee3fa0308e6185ba64a9a7f2e74332b) C:\Windows\system32\sstpsvc.dll 21:06:29.0746 5896 SstpSvc - ok 21:06:29.0792 5896 stisvc (15825c1fbfb8779992cb65087f316af5) C:\Windows\System32\wiaservc.dll 21:06:29.0839 5896 stisvc - ok 21:06:29.0933 5896 swenum (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys 21:06:29.0948 5896 swenum - ok 21:06:30.0026 5896 swprv (6de37f4de19d4efd9c48c43addbc949a) C:\Windows\System32\swprv.dll 21:06:30.0089 5896 swprv - ok 21:06:30.0151 5896 Symc8xx (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys 21:06:30.0182 5896 Symc8xx - ok 21:06:30.0245 5896 Sym_hi (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys 21:06:30.0260 5896 Sym_hi - ok 21:06:30.0260 5896 Sym_u3 (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys 21:06:30.0292 5896 Sym_u3 - ok 21:06:30.0385 5896 SynTP (0f2e5efdf6730780afea6ec6bf8aacb0) C:\Windows\system32\DRIVERS\SynTP.sys 21:06:30.0416 5896 SynTP - ok 21:06:30.0494 5896 SysMain (92d7a8b0f87b036f17d25885937897a6) C:\Windows\system32\sysmain.dll 21:06:30.0557 5896 SysMain - ok 21:06:30.0635 5896 TabletInputService (005ce42567f9113a3bccb3b20073b029) C:\Windows\System32\TabSvc.dll 21:06:30.0666 5896 TabletInputService - ok 21:06:30.0697 5896 TapiSrv (cc2562b4d55e0b6a4758c65407f63b79) C:\Windows\System32\tapisrv.dll 21:06:30.0760 5896 TapiSrv - ok 21:06:30.0838 5896 TBS (cdbe8d7c1e201b911cdc346d06617fb5) C:\Windows\System32\tbssvc.dll 21:06:30.0869 5896 TBS - ok 21:06:30.0947 5896 Tcpip (2cc45d932bd193cd4117321d469ad6b2) C:\Windows\system32\drivers\tcpip.sys 21:06:31.0056 5896 Tcpip - ok 21:06:31.0181 5896 Tcpip6 (2cc45d932bd193cd4117321d469ad6b2) C:\Windows\system32\DRIVERS\tcpip.sys 21:06:31.0259 5896 Tcpip6 - ok 21:06:31.0384 5896 tcpipreg (c7e72a4071ee0200e3c075dacfb2b334) C:\Windows\system32\drivers\tcpipreg.sys 21:06:31.0446 5896 tcpipreg - ok 21:06:31.0524 5896 TcUsb (cbd13e809e81b07116c8d51aa199f69b) C:\Windows\system32\Drivers\tcusb.sys 21:06:31.0540 5896 TcUsb - ok 21:06:31.0587 5896 TDPIPE (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys 21:06:31.0633 5896 TDPIPE - ok 21:06:31.0649 5896 TDTCP (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys 21:06:31.0696 5896 TDTCP - ok 21:06:31.0758 5896 tdx (458919c8c42e398dc4802178d5ffee27) C:\Windows\system32\DRIVERS\tdx.sys 21:06:31.0805 5896 tdx - ok 21:06:31.0868 5896 TermDD (8c19678d22649ec002ef2282eae92f98) C:\Windows\system32\DRIVERS\termdd.sys 21:06:31.0883 5896 TermDD - ok 21:06:31.0946 5896 TermService (5cdd30bc217082dac71a9878d9bfd566) C:\Windows\System32\termsrv.dll 21:06:32.0024 5896 TermService - ok 21:06:32.0102 5896 Themes (56793271ecdedd350c5add305603e963) C:\Windows\system32\shsvcs.dll 21:06:32.0117 5896 Themes - ok 21:06:32.0148 5896 THREADORDER (3cbe4995e80e13ccfbc42e5dcf3ac81a) C:\Windows\system32\mmcss.dll 21:06:32.0180 5896 THREADORDER - ok 21:06:32.0258 5896 TrkWks (f4689f05af472a651a7b1b7b02d200e7) C:\Windows\System32\trkwks.dll 21:06:32.0289 5896 TrkWks - ok 21:06:32.0336 5896 TrustedInstaller (66328b08ef5a9305d8ede36b93930369) C:\Windows\servicing\TrustedInstaller.exe 21:06:32.0382 5896 TrustedInstaller - ok 21:06:32.0492 5896 tssecsrv (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys 21:06:32.0538 5896 tssecsrv - ok 21:06:32.0648 5896 tunmp (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys 21:06:32.0679 5896 tunmp - ok 21:06:32.0741 5896 tunnel (30a9b3f45ad081bffc3bcaa9c812b609) C:\Windows\system32\DRIVERS\tunnel.sys 21:06:32.0772 5896 tunnel - ok 21:06:32.0850 5896 uagp35 (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys 21:06:32.0866 5896 uagp35 - ok 21:06:32.0913 5896 UBHelper (00c8ce31657624a125fdb90efd554371) C:\Windows\system32\drivers\UBHelper.sys 21:06:32.0913 5896 UBHelper - ok 21:06:32.0975 5896 udfs (faf2640a2a76ed03d449e443194c4c34) C:\Windows\system32\DRIVERS\udfs.sys 21:06:33.0022 5896 udfs - ok 21:06:33.0069 5896 UI0Detect (060507c4113391394478f6953a79eedc) C:\Windows\system32\UI0Detect.exe 21:06:33.0116 5896 UI0Detect - ok 21:06:33.0194 5896 uliagpkx (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys 21:06:33.0209 5896 uliagpkx - ok 21:06:33.0303 5896 uliahci (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys 21:06:33.0319 5896 uliahci - ok 21:06:33.0365 5896 UlSata (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys 21:06:33.0397 5896 UlSata - ok 21:06:33.0475 5896 ulsata2 (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys 21:06:33.0490 5896 ulsata2 - ok 21:06:33.0537 5896 umbus (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys 21:06:33.0599 5896 umbus - ok 21:06:33.0662 5896 upnphost (7093799ff80e9deca0680d2e3535be60) C:\Windows\System32\upnphost.dll 21:06:33.0693 5896 upnphost - ok 21:06:33.0771 5896 usbccgp (07e3498fc60834219d2356293da0fecc) C:\Windows\system32\DRIVERS\usbccgp.sys 21:06:33.0818 5896 usbccgp - ok 21:06:33.0896 5896 usbcir (9247f7e0b65852c1f6631480984d6ed2) C:\Windows\system32\drivers\usbcir.sys 21:06:33.0974 5896 usbcir - ok 21:06:34.0067 5896 usbehci (827e44de934a736ea31e91d353eb126f) C:\Windows\system32\DRIVERS\usbehci.sys 21:06:34.0099 5896 usbehci - ok 21:06:34.0161 5896 usbhub (bb35cd80a2ececfadc73569b3d70c7d1) C:\Windows\system32\DRIVERS\usbhub.sys 21:06:34.0208 5896 usbhub - ok 21:06:34.0286 5896 usbohci (eba14ef0c07cec233f1529c698d0d154) C:\Windows\system32\drivers\usbohci.sys 21:06:34.0333 5896 usbohci - ok 21:06:34.0395 5896 usbprint (acfee697af477021bb3ec78c5431fed2) C:\Windows\system32\drivers\usbprint.sys 21:06:34.0442 5896 usbprint - ok 21:06:34.0473 5896 USBSTOR (b854c1558fca0c269a38663e8b59b581) C:\Windows\system32\DRIVERS\USBSTOR.SYS 21:06:34.0536 5896 USBSTOR - ok 21:06:34.0598 5896 usbuhci (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys 21:06:34.0629 5896 usbuhci - ok 21:06:34.0707 5896 usbvideo (fc33099877790d51b0927b7039059855) C:\Windows\system32\Drivers\usbvideo.sys 21:06:34.0770 5896 usbvideo - ok 21:06:34.0816 5896 UxSms (d76e231e4850bb3f88a3d9a78df191e3) C:\Windows\System32\uxsms.dll 21:06:34.0848 5896 UxSms - ok 21:06:34.0910 5896 vds (294945381dfa7ce58cecf0a9896af327) C:\Windows\System32\vds.exe 21:06:34.0972 5896 vds - ok 21:06:35.0284 5896 vga (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys 21:06:35.0362 5896 vga - ok 21:06:35.0628 5896 VgaSave (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys 21:06:35.0659 5896 VgaSave - ok 21:06:35.0706 5896 viaide (8294b6c3fdb6c33f24e150de647ecdaa) C:\Windows\system32\drivers\viaide.sys 21:06:35.0721 5896 viaide - ok 21:06:35.0768 5896 volmgr (2b7e885ed951519a12c450d24535dfca) C:\Windows\system32\drivers\volmgr.sys 21:06:35.0784 5896 volmgr - ok 21:06:35.0846 5896 volmgrx (cec5ac15277d75d9e5dec2e1c6eaf877) C:\Windows\system32\drivers\volmgrx.sys 21:06:35.0909 5896 volmgrx - ok 21:06:35.0971 5896 volsnap (5280aada24ab36b01a84a6424c475c8d) C:\Windows\system32\drivers\volsnap.sys 21:06:36.0002 5896 volsnap - ok 21:06:36.0049 5896 vsmraid (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys 21:06:36.0080 5896 vsmraid - ok 21:06:36.0158 5896 VSS (b75232dad33bfd95bf6f0a3e6bff51e1) C:\Windows\system32\vssvc.exe 21:06:36.0283 5896 VSS - ok 21:06:36.0361 5896 W32Time (f14a7de2ea41883e250892e1e5230a9a) C:\Windows\system32\w32time.dll 21:06:36.0423 5896 W32Time - ok 21:06:36.0486 5896 WacomPen (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys 21:06:36.0564 5896 WacomPen - ok 21:06:36.0658 5896 Wanarp (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys 21:06:36.0689 5896 Wanarp - ok 21:06:36.0689 5896 Wanarpv6 (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys 21:06:36.0720 5896 Wanarpv6 - ok 21:06:36.0782 5896 wanatw (eceb715bece47e101ddec06b11126066) C:\Windows\system32\DRIVERS\wanatw64.sys 21:06:36.0798 5896 wanatw - ok 21:06:36.0845 5896 wcncsvc (b4e4c37d0aa6100090a53213ee2bf1c1) C:\Windows\System32\wcncsvc.dll 21:06:36.0876 5896 wcncsvc - ok 21:06:36.0970 5896 WcsPlugInService (ea4b369560e986f19d93f45a881484ac) C:\Windows\System32\WcsPlugInService.dll 21:06:37.0001 5896 WcsPlugInService - ok 21:06:37.0048 5896 Wd (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys 21:06:37.0079 5896 Wd - ok 21:06:37.0188 5896 Wdf01000 (d02e7e4567da1e7582fbf6a91144b0df) C:\Windows\system32\drivers\Wdf01000.sys 21:06:37.0266 5896 Wdf01000 - ok 21:06:37.0375 5896 WdiServiceHost (c5efda73ebfca8b02a094898de0a9276) C:\Windows\system32\wdi.dll 21:06:37.0422 5896 WdiServiceHost - ok 21:06:37.0438 5896 WdiSystemHost (c5efda73ebfca8b02a094898de0a9276) C:\Windows\system32\wdi.dll 21:06:37.0469 5896 WdiSystemHost - ok 21:06:37.0516 5896 WebClient (3e6d05381cf35f75ebb055544a8ed9ac) C:\Windows\System32\webclnt.dll 21:06:37.0547 5896 WebClient - ok 21:06:37.0625 5896 Wecsvc (8d40bc587993f876658bf9fb0f7d3462) C:\Windows\system32\wecsvc.dll 21:06:37.0672 5896 Wecsvc - ok 21:06:37.0703 5896 wercplsupport (9c980351d7e96288ea0c23ae232bd065) C:\Windows\System32\wercplsupport.dll 21:06:37.0750 5896 wercplsupport - ok 21:06:37.0828 5896 WerSvc (66b9ecebc46683f47edc06333c075fef) C:\Windows\System32\WerSvc.dll 21:06:37.0859 5896 WerSvc - ok 21:06:37.0953 5896 winachsf (9e6c63f94d2c3d884a8936e448b1028b) C:\Windows\system32\DRIVERS\CAX_CNXT.sys 21:06:38.0015 5896 winachsf - ok 21:06:38.0109 5896 winbondcir (54d68b92dc59fbba95919c804a7c3e07) C:\Windows\system32\DRIVERS\winbondcir.sys 21:06:38.0124 5896 winbondcir - ok 21:06:38.0171 5896 WinDefend - ok 21:06:38.0187 5896 WinHttpAutoProxySvc - ok 21:06:38.0265 5896 Winmgmt (d2e7296ed1bd26d8db2799770c077a02) C:\Windows\system32\wbem\WMIsvc.dll 21:06:38.0327 5896 Winmgmt - ok 21:06:38.0421 5896 WinRM (6cbb0c68f13b9c2ec1b16f5fa5e7c869) C:\Windows\system32\WsmSvc.dll 21:06:38.0717 5896 WinRM - ok 21:06:38.0826 5896 Wlansvc (ec339c8115e91baed835957e9a677f16) C:\Windows\System32\wlansvc.dll 21:06:38.0889 5896 Wlansvc - ok 21:06:39.0060 5896 wlidsvc (7e47c328fc4768cb8beafbcfafa70362) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 21:06:39.0357 5896 wlidsvc - ok 21:06:39.0450 5896 WmiAcpi (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\DRIVERS\wmiacpi.sys 21:06:39.0482 5896 WmiAcpi - ok 21:06:39.0560 5896 wmiApSrv (21fa389e65a852698b6a1341f36ee02d) C:\Windows\system32\wbem\WmiApSrv.exe 21:06:39.0591 5896 wmiApSrv - ok 21:06:39.0638 5896 WMPNetworkSvc - ok 21:06:39.0731 5896 WMZuneComm (83b6ca03c846fcd47f9883d77d1eb27b) C:\Program Files\Zune\WMZuneComm.exe 21:06:39.0762 5896 WMZuneComm - ok 21:06:39.0840 5896 WPCSvc (cbc156c913f099e6680d1df9307db7a8) C:\Windows\System32\wpcsvc.dll 21:06:39.0903 5896 WPCSvc - ok 21:06:39.0965 5896 WPDBusEnum (490a18b4e4d53dc10879deaa8e8b70d9) C:\Windows\system32\wpdbusenum.dll 21:06:40.0012 5896 WPDBusEnum - ok 21:06:40.0090 5896 WpdUsb (5e2401b3fc1089c90e081291357371a9) C:\Windows\system32\DRIVERS\wpdusb.sys 21:06:40.0121 5896 WpdUsb - ok 21:06:40.0277 5896 WPFFontCache_v0400 (991e2c2cf3bc204c2bb2ee1476149e4e) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe 21:06:40.0387 5896 WPFFontCache_v0400 - ok 21:06:40.0496 5896 ws2ifsl (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys 21:06:40.0543 5896 ws2ifsl - ok 21:06:40.0605 5896 wscsvc (9ea3e6d0ef7a5c2b9181961052a4b01a) C:\Windows\system32\wscsvc.dll 21:06:40.0636 5896 wscsvc - ok 21:06:40.0667 5896 WSearch - ok 21:06:40.0792 5896 wuauserv (fb3796754fe00f0bdc87a36f164a5f4d) C:\Windows\system32\wuaueng.dll 21:06:40.0979 5896 wuauserv - ok 21:06:41.0089 5896 WUDFRd (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys 21:06:41.0135 5896 WUDFRd - ok 21:06:41.0182 5896 wudfsvc (6cbd51ff913c851d56ed9dc7f2a27dde) C:\Windows\System32\WUDFSvc.dll 21:06:41.0229 5896 wudfsvc - ok 21:06:41.0276 5896 XAudio (f22e443518bc599d12888daf292a56d8) C:\Windows\system32\DRIVERS\xaudio64.sys 21:06:41.0291 5896 XAudio - ok 21:06:41.0354 5896 XAudioService (963c27034bba4ac52a13f7a3c657c708) C:\Windows\system32\DRIVERS\xaudio64.exe 21:06:41.0385 5896 XAudioService - ok 21:06:41.0682 5896 ZuneNetworkSvc (67b787c34fb2888d01b130ae007042d8) C:\Program Files\Zune\ZuneNss.exe 21:06:42.0103 5896 ZuneNetworkSvc - ok 21:06:42.0196 5896 ZuneWlanCfgSvc (4d89fc1c20cf655739efac5da81a67bc) C:\Program Files\Zune\ZuneWlanCfgSvc.exe 21:06:42.0228 5896 ZuneWlanCfgSvc - ok 21:06:42.0337 5896 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796} (177590b0d2f8be513626bb8c8d6e6a08) C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\000.fcl 21:06:42.0352 5896 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796} - ok 21:06:42.0368 5896 MBR (0x1B8) (bb9d3a6a13c5010348da7c900bb6af50) \Device\Harddisk0\DR0 21:06:43.0070 5896 \Device\Harddisk0\DR0 - ok 21:06:43.0086 5896 Boot (0x1200) (3f256cfa09294ab4cd0f98064bb05f5b) \Device\Harddisk0\DR0\Partition0 21:06:43.0101 5896 \Device\Harddisk0\DR0\Partition0 - ok 21:06:43.0117 5896 Boot (0x1200) (f65951280bf5d09736a289129e57eed8) \Device\Harddisk0\DR0\Partition1 21:06:43.0117 5896 \Device\Harddisk0\DR0\Partition1 - ok 21:06:43.0117 5896 ============================================================ 21:06:43.0117 5896 Scan finished 21:06:43.0117 5896 ============================================================ 21:06:43.0133 5760 Detected object count: 6 21:06:43.0133 5760 Actual detected object count: 6 21:07:42.0749 5760 BUNAgentSvc ( UnsignedFile.Multi.Generic ) - skipped by user 21:07:42.0765 5760 BUNAgentSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip 21:07:42.0765 5760 CLHNService ( UnsignedFile.Multi.Generic ) - skipped by user 21:07:42.0765 5760 CLHNService ( UnsignedFile.Multi.Generic ) - User select action: Skip 21:07:42.0765 5760 ETService ( UnsignedFile.Multi.Generic ) - skipped by user 21:07:42.0765 5760 ETService ( UnsignedFile.Multi.Generic ) - User select action: Skip 21:07:42.0765 5760 LightScribeService ( UnsignedFile.Multi.Generic ) - skipped by user 21:07:42.0765 5760 LightScribeService ( UnsignedFile.Multi.Generic ) - User select action: Skip 21:07:42.0765 5760 NTIBackupSvc ( UnsignedFile.Multi.Generic ) - skipped by user 21:07:42.0765 5760 NTIBackupSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip 21:07:42.0765 5760 NTISchedulerSvc ( UnsignedFile.Multi.Generic ) - skipped by user 21:07:42.0765 5760 NTISchedulerSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip 21:07:51.0751 5440 Deinitialize success Then I ran ComboFix as instructed. Got an error in the blue ComboFix window (I've had this before on other ComboFix runs) that says "Failed to get data for 'EnableLUA' " Went ahead and let it run, then noticed it was deleting something during the 1st run. I went ahead and let it do that as I was not told not to. When I rebooted, during ComboFix creating the log I am about to post, this error message came up. The only option is to say OK and go on so I did a screen snip which I am including, clicked OK and it proceeded to create the log. Here is that log. Thank you!! ComboFix 12-04-12.03 - Ratopia 04/12/2012 21:24:16.1.2 - x64 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4024.2295 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Ratopia\AppData\Local\temp\RtkBtMnt.exe . . ((((((((((((((((((((((((( Files Created from 2012-03-13 to 2012-04-13 ))))))))))))))))))))))))))))))) . . 2012-04-13 02:34 . 2012-04-13 02:34 ——– d—–w- c:\users\Public\AppData\Local\temp 2012-04-13 02:34 . 2012-04-13 02:34 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-04-12 08:05 . 2012-03-06 06:44 4699520 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-04-12 08:05 . 2012-02-29 15:37 5632 —-a-w- c:\windows\system32\wmi.dll 2012-04-12 08:05 . 2012-02-29 15:37 219136 —-a-w- c:\windows\system32\wintrust.dll 2012-04-12 08:05 . 2012-02-29 15:35 78848 —-a-w- c:\windows\system32\imagehlp.dll 2012-04-12 08:05 . 2012-02-29 15:11 5120 —-a-w- c:\windows\SysWow64\wmi.dll 2012-04-12 08:05 . 2012-02-29 15:11 172032 —-a-w- c:\windows\SysWow64\wintrust.dll 2012-04-12 08:05 . 2012-02-29 15:09 157696 —-a-w- c:\windows\SysWow64\imagehlp.dll 2012-04-12 08:05 . 2012-02-29 13:52 16384 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-04-12 01:37 . 2012-04-12 01:37 ——– d—–w- c:\users\Ratopia\AppData\Local\VS Revo Group 2012-04-12 01:37 . 2009-12-30 15:21 31800 —-a-w- c:\windows\system32\drivers\revoflt.sys 2012-04-12 01:37 . 2012-04-12 01:37 ——– d—–w- c:\program files\VS Revo Group 2012-04-11 23:43 . 2012-03-01 11:01 2409784 —-a-w- c:\program files (x86)\Windows Mail\OESpamFilter.dat 2012-04-11 23:43 . 2012-03-01 11:01 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat 2012-04-09 11:53 . 2012-04-09 11:53 ——– d—–w- C:\_OTL 2012-04-09 11:50 . 2012-04-09 11:50 ——– d—–w- c:\program files (x86)\ERUNT 2012-04-04 23:20 . 2012-04-04 23:20 8738464 —-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2012-04-04 22:34 . 2012-04-04 23:20 418464 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-04-04 23:20 . 2011-05-15 23:58 70304 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-04-04 20:56 . 2009-05-26 22:53 24904 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-03-07 23:01 . 2010-06-28 21:17 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2012-02-16 02:06 . 2011-11-21 08:18 132320 —-a-w- c:\windows\system32\drivers\avipbb.sys 2012-02-14 16:49 . 2012-03-13 22:58 327680 —-a-w- c:\windows\system32\d3d10_1core.dll 2012-02-14 16:49 . 2012-03-13 22:58 196096 —-a-w- c:\windows\system32\d3d10_1.dll 2012-02-14 15:45 . 2012-03-13 22:58 219648 —-a-w- c:\windows\SysWow64\d3d10_1core.dll 2012-02-14 15:45 . 2012-03-13 22:58 160768 —-a-w- c:\windows\SysWow64\d3d10_1.dll 2012-02-13 14:38 . 2012-03-13 22:58 2002944 —-a-w- c:\windows\system32\d3d10warp.dll 2012-02-13 14:12 . 2012-03-13 22:58 1172480 —-a-w- c:\windows\SysWow64\d3d10warp.dll 2012-02-13 14:06 . 2012-03-13 22:58 834048 —-a-w- c:\windows\system32\d2d1.dll 2012-02-13 14:03 . 2012-03-13 22:58 1555968 —-a-w- c:\windows\system32\DWrite.dll 2012-02-13 13:47 . 2012-03-13 22:58 683008 —-a-w- c:\windows\SysWow64\d2d1.dll 2012-02-13 13:44 . 2012-03-13 22:58 1068544 —-a-w- c:\windows\SysWow64\DWrite.dll 2012-02-07 16:02 . 2012-02-07 16:02 1070352 —-a-w- c:\windows\SysWow64\MSCOMCTL.OCX 2012-02-02 15:34 . 2012-03-13 22:58 2765824 —-a-w- c:\windows\system32\win32k.sys 2012-02-01 04:03 . 2012-02-01 04:03 161792 —-a-w- c:\windows\SysWow64\msls31.dll 2012-02-01 04:03 . 2012-02-01 04:03 86528 —-a-w- c:\windows\SysWow64\iesysprep.dll 2012-02-01 04:03 . 2012-02-01 04:03 76800 —-a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2012-02-01 04:03 . 2012-02-01 04:03 74752 —-a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2012-02-01 04:03 . 2012-02-01 04:03 48640 —-a-w- c:\windows\SysWow64\mshtmler.dll 2012-02-01 04:03 . 2012-02-01 04:03 63488 —-a-w- c:\windows\SysWow64\tdc.ocx 2012-02-01 04:03 . 2012-02-01 04:03 367104 —-a-w- c:\windows\SysWow64\html.iec 2012-02-01 04:03 . 2012-02-01 04:03 74752 —-a-w- c:\windows\SysWow64\iesetup.dll 2012-02-01 04:03 . 2012-02-01 04:03 23552 —-a-w- c:\windows\SysWow64\licmgr10.dll 2012-02-01 04:03 . 2012-02-01 04:03 152064 —-a-w- c:\windows\SysWow64\wextract.exe 2012-02-01 04:03 . 2012-02-01 04:03 150528 —-a-w- c:\windows\SysWow64\iexpress.exe 2012-02-01 04:03 . 2012-02-01 04:03 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2012-02-01 04:03 . 2012-02-01 04:03 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2012-02-01 04:03 . 2012-02-01 04:03 11776 —-a-w- c:\windows\SysWow64\mshta.exe 2012-02-01 04:03 . 2012-02-01 04:03 35840 —-a-w- c:\windows\SysWow64\imgutil.dll 2012-02-01 04:03 . 2012-02-01 04:03 101888 —-a-w- c:\windows\SysWow64\admparse.dll 2012-02-01 04:03 . 2012-02-01 04:03 110592 —-a-w- c:\windows\SysWow64\IEAdvpack.dll 2012-02-01 04:03 . 2012-02-01 04:03 222208 —-a-w- c:\windows\system32\msls31.dll 2012-02-01 04:03 . 2012-02-01 04:03 91648 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-02-01 04:03 . 2012-02-01 04:03 89088 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-02-01 04:03 . 2012-02-01 04:03 49664 —-a-w- c:\windows\system32\imgutil.dll 2012-02-01 04:03 . 2012-02-01 04:03 48640 —-a-w- c:\windows\system32\mshtmler.dll 2012-02-01 04:03 . 2012-02-01 04:03 135168 —-a-w- c:\windows\system32\IEAdvpack.dll 2012-02-01 04:03 . 2012-02-01 04:03 12288 —-a-w- c:\windows\system32\mshta.exe 2012-02-01 04:03 . 2012-02-01 04:03 114176 —-a-w- c:\windows\system32\admparse.dll 2012-02-01 04:03 . 2012-02-01 04:03 111616 —-a-w- c:\windows\system32\iesysprep.dll 2012-02-01 04:03 . 2012-02-01 04:03 85504 —-a-w- c:\windows\system32\iesetup.dll 2012-02-01 04:03 . 2012-02-01 04:03 76800 —-a-w- c:\windows\system32\tdc.ocx 2012-02-01 04:03 . 2012-02-01 04:03 448512 —-a-w- c:\windows\system32\html.iec 2012-02-01 04:03 . 2012-02-01 04:03 603648 —-a-w- c:\windows\system32\vbscript.dll 2012-02-01 04:03 . 2012-02-01 04:03 30720 —-a-w- c:\windows\system32\licmgr10.dll 2012-02-01 04:03 . 2012-02-01 04:03 165888 —-a-w- c:\windows\system32\iexpress.exe 2012-02-01 04:03 . 2012-02-01 04:03 160256 —-a-w- c:\windows\system32\wextract.exe 2012-02-01 04:03 . 2012-02-01 04:03 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2012-01-29 05:09 . 2012-01-29 05:09 4393247 ——r- C:\ComboFix.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-07-30 01:52 121392 —-a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-08 68856] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "eAudio"="c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe" [2008-09-12 781824] "BkupTray"="c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-26 28672] "LManager"="c:\progra~2\LAUNCH~1\QtZgAcer.EXE" [2008-06-04 817672] "ArcadeDeluxeAgent"="c:\program files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2008-07-24 147456] "CLMLServer"="c:\program files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-07-24 167936] "Acer Assist Launcher"="c:\program files (x86)\Acer\Acer Assist\launcher.exe" [2007-11-19 1261568] "Acer Product Registration"="c:\program files (x86)\Acer\Acer Registration\ACE1.exe" [2007-11-26 3387392] "HostManager"="c:\program files (x86)\Common Files\AOL\1242688622\ee\AOLSoftware.exe" [2008-06-24 41824] "MaxMenuMgr"="c:\program files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-26 185640] "Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888] "Info Center"="c:\program files (x86)\PCPitstop\Info Center\InfoCenter.exe" [2011-08-03 24216] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-09-23 258512] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] . c:\users\Ratopia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ ERUNT AutoBackup.lnk - c:\program files (x86)\ERUNT\AUTOBACK.EXE [2005-10-20 38912] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 253600] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] . . Contents of the 'Scheduled Tasks' folder . 2012-04-13 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 23:20] . 2012-04-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-15 19:46] . 2012-04-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-15 19:46] . 2012-04-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854704829-886445271-3124620010-1000Core.job - c:\users\Ratopia\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-28 22:26] . 2012-04-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-854704829-886445271-3124620010-1000UA.job - c:\users\Ratopia\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-28 22:26] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-07-30 01:53 50736 —-a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\PSDProtect.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808] "ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-08-01 481792] "eDataSecurity Loader"="c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe" [2008-07-30 561200] "RtHDVCpl"="RAVCpl64.exe" [2008-09-18 6495264] "Skytel"="Skytel.exe" [2008-09-18 1833504] "PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1237288] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-12 162328] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-12 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-12 417304] "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2011-08-05 163552] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html TCP: DhcpNameServer = [removed] [removed] DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll . . [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}] "ImagePath"="\??\c:\program files (x86)\Acer Arcade Deluxe\PlayMovie\000.fcl" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] @Denied: (A 2) (Everyone) . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] @="Shockwave Flash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] @Denied: (A 2) (Everyone) @="" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] @="FlashBroker" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes] "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . ———————— Other Running Processes ———————— . c:\program files (x86)\Avira\AntiVir Desktop\sched.exe c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Common Files\AOL\ACS\AOLAcsd.exe c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe c:\program files (x86)\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe c:\program files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe c:\program files (x86)\Cyberlink\Shared files\RichVideo.exe c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe c:\program files (x86)\Launch Manager\QtZgAcer.EXE c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe . ************************************************************************** . Completion time: 2012-04-12 21:45:05 - machine was rebooted ComboFix-quarantined-files.txt 2012-04-13 02:45 ComboFix2.txt 2012-01-30 23:58 ComboFix3.txt 2012-01-30 21:56 ComboFix4.txt 2012-01-29 05:35 . Pre-Run: 66,932,305,920 bytes free Post-Run: 66,706,296,832 bytes free . - - End Of File - - 24A7F3809296C8EB002313D9E6530B8A

Attachments:

Hi CoolCat,

That log looked ok.

The error message you received I believe are related to an out of date driver on your system.

Do you have your Windows Vista CD or can you borrow one from a friend? If so, get it out as we may need this during the following steps:
  • Click on Start, type cmd in the Start Search bar.
  • Right click on Command Prompt at the top of the window and select Run as Administrator.
  • In the Command Prompt Window, type (or copy and paste) sfc /scannow and press Enter.
The scan may take some time, so be patient. Windows will repair any corrupted or missing files that it finds. If information from the installation CD is needed to repair the problem, you may be prompted to insert your Windows Vista CD.
I don't have a Windows CD - computer didn't come with one. Neither of my computers did. And I don't know anyone, here, because I just recently moved to this state from another… Now what? :(

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI