This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Searchqu virus?

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Some days ago my internet home page and my searches changed and were always redirected to searchqu. I managed to change them back and it seemed to work BUT I still think that I have a virus or something.

Everytime I run my computer, it always appears the same rundll error :(

There was a problem starting
C:UsersPatriciaAppDataLocalTempSRASSE~1.DLL
The specified module could not be found."


and I don't know how to get rid of it because my virus scanner did not pick anything up.

I have tried everything that I have seen on the internet with no success. Can someone PLEASE help me??

Here are the results of OTL:

OTL


OTL logfile created on: 09/04/2012 19:04:58 - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:UsersPatriciaDesktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000c0a | Country: España | Language: ESN | Date Format: dd/MM/yyyy

3,86 Gb Total Physical Memory | 1,75 Gb Available Physical Memory | 45,35% Memory free
7,71 Gb Paging File | 5,28 Gb Available in Paging File | 68,51% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files (x86)
Drive C: | 683,04 Gb Total Space | 578,47 Gb Free Space | 84,69% Space Free | Partition Type: NTFS

Computer Name: PATRICIA-PC | User Name: Patricia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:UsersPatriciaDesktopOTL.exe (OldTimer Tools)
PRC - C:WindowsSysWOW64MacromedFlashFlashUtil32_11_2_202_228_ActiveX.exe (Adobe Systems Incorporated)
PRC - C:Archivos de programaAVAST SoftwareAvastAvastUI.exe (AVAST Software)
PRC - C:Archivos de programaAVAST SoftwareAvastAvastSvc.exe (AVAST Software)
PRC - C:Program Files (x86)Emsisoft Anti-Malwarea2guard.exe (Emsi Software GmbH)
PRC - C:Program Files (x86)Emsisoft Anti-Malwarea2service.exe (Emsi Software GmbH)
PRC - C:Program Files (x86)NTIPackard Bell MyBackupIScheduleSvc.exe (NTI Corporation)
PRC - C:Program Files (x86)NTIPackard Bell MyBackupBackupManagerTray.exe (NTI Corporation)
PRC - C:Program Files (x86)MicrosoftBingBarSeaPort.EXE (Microsoft Corporation)
PRC - C:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exe (Intel Corporation)
PRC - C:Program Files (x86)IntelIntel® Management Engine ComponentsLMSLMS.exe (Intel Corporation)
PRC - C:Program Files (x86)NVIDIA CorporationNVIDIA Updatusdaemonu.exe (NVIDIA Corporation)
PRC - C:Program Files (x86)Launch ManagerLManager.exe (Dritek System Inc.)
PRC - C:Program Files (x86)Launch Managerdsiwmis.exe (Dritek System Inc.)
PRC - C:Program Files (x86)Launch ManagerLMworker.exe (Dritek System Inc.)
PRC - C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorIcon.exe (Intel Corporation)
PRC - C:Program Files (x86)Renesas ElectronicsUSB 3.0 Host Controller DriverApplicationnusb3mon.exe (Renesas Electronics Corporation)
PRC - C:Archivos de programaPackard BellPackard Bell UpdaterUpdaterService.exe (Acer Group)
PRC - C:Program Files (x86)Packard BellRegistrationGREGsvc.exe (Acer Incorporated)
PRC - c:Program Files (x86)AdobeElements Organizer 8.0PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:Program Files (x86)Spybot - Search & DestroyTeaTimer.exe (Safer Networking Limited)
PRC - C:Program Files (x86)Spybot - Search & DestroySDWinSec.exe (Safer Networking Ltd.)


========== Modules (No Company Name) ==========

MOD - C:WindowsassemblyNativeImages_v2.0.50727_32IAStorUtilc6b914d595e5b00ae54000
4a71c6c3a2IAStorUtil.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32System.Runtime.Remo#a1c4a635721f
85bef0ea4194b888b871System.Runtime.Remoting.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32System.Windows.Forms6c51e152e740
4188914c9fa4d8503ff9System.Windows.Forms.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32System.Drawingab87129c2b603f218e
4aa5300c9b1bddSystem.Drawing.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32WindowsBase47b9e7f070271ff50f988
f75ea68fa3eWindowsBase.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32System.Xml9866d1f6178e1cde25642f
1ac293ff8dSystem.Xml.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32System.Configuratione620323cacb5
b6bfd93fd28d263440e4System.Configuration.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32Systemfaf4e8730ecbd07570111bb7c3
b20565System.ni.dll ()
MOD - C:Program Files (x86)NTIPackard Bell MyBackupsqlite3.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32IAStorCommonebfad289d9759034cd3a
887802fadb5bIAStorCommon.ni.dll ()
MOD - C:WindowsassemblyNativeImages_v2.0.50727_32mscorliba1a82db68b3badc7c27ea1f6
579d22c5mscorlib.ni.dll ()
MOD - C:WindowsassemblyGAC_MSILSystem.Runtime.Remoting.resources2.0.0.0_es_b77a5c
561934e089System.Runtime.Remoting.resources.dll ()
MOD - C:WindowsassemblyGAC_MSILmscorlib.resources2.0.0.0_es_b77a5c561934e089msco
rlib.resources.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (avast! Firewall) – C:Program FilesAVAST SoftwareAvastafwServ.exe File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:WindowsSysWOW64MacromedFlashFlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (avast! Antivirus) – C:Archivos de programaAVAST SoftwareAvastAvastSvc.exe (AVAST Software)
SRV - (a2AntiMalware) – C:Program Files (x86)Emsisoft Anti-Malwarea2service.exe (Emsi Software GmbH)
SRV - (NTI IScheduleSvc) – C:Program Files (x86)NTIPackard Bell MyBackupIScheduleSvc.exe (NTI Corporation)
SRV - (Sony Ericsson PCCompanion) – C:Program Files (x86)Sony EricssonSony Ericsson PC CompanionPCCService.exe (Avanquest Software)
SRV - (FLEXnet Licensing Service) – C:Program Files (x86)Common FilesMacrovision SharedFLEXnet PublisherFNPLicensingService.exe (Acresso Software Inc.)
SRV - (BBSvc) – C:Program Files (x86)MicrosoftBingBarBBSvc.EXE (Microsoft Corporation.)
SRV - (wlidsvc) – C:Archivos de programaCommon FilesMicrosoft SharedWindows LiveWLIDSVC.EXE (Microsoft Corp.)
SRV - (SeaPort) – C:Program Files (x86)MicrosoftBingBarSeaPort.EXE (Microsoft Corporation)
SRV - (UNS) Intel® – C:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:Program Files (x86)IntelIntel® Management Engine ComponentsLMSLMS.exe (Intel Corporation)
SRV - (nvUpdatusService) – C:Program Files (x86)NVIDIA CorporationNVIDIA Updatusdaemonu.exe (NVIDIA Corporation)
SRV - (ePowerSvc) – C:Archivos de programaPackard BellPackard Bell Power ManagementePowerSvc.exe (Acer Incorporated)
SRV - (DsiWMIService) – C:Program Files (x86)Launch Managerdsiwmis.exe (Dritek System Inc.)
SRV - (GamesAppService) – C:Program Files (x86)WildTangent GamesAppGamesAppService.exe (WildTangent, Inc.)
SRV - (TurboBoost) Intel® – C:Archivos de programaIntelTurboBoostTurboBoost.exe (Intel® Corporation)
SRV - (wlcrasvc) – C:Archivos de programaWindows LiveMeshwlcrasvc.exe (Microsoft Corporation)
SRV - (IAStorDataMgrSvc) Intel® – C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorDataMgrSvc.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe (Microsoft Corporation)
SRV - (Updater Service) – C:Archivos de programaPackard BellPackard Bell UpdaterUpdaterService.exe (Acer Group)
SRV - (Nero BackItUp Scheduler 4.0) – C:Program Files (x86)Common FilesNeroNero BackItUp 4NBService.exe (Nero AG)
SRV - (osppsvc) – C:Archivos de programaCommon FilesMicrosoft SharedOfficeSoftwareProtectionPlatformOSPPSVC.EXE (Microsoft Corporation)
SRV - (GREGService) – C:Program Files (x86)Packard BellRegistrationGREGsvc.exe (Acer Incorporated)
SRV - (AdobeActiveFileMonitor8.0) – c:Program Files (x86)AdobeElements Organizer 8.0PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:WindowsMicrosoft.NETFrameworkv2.0.50727mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswSnx) – C:WindowsSysNativedriversaswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:WindowsSysNativedriversaswSP.sys (AVAST Software)
DRV:64bit: - (aswKbd) – C:WindowsSysNativedriversaswKbd.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:WindowsSysNativedriversaswRdr2.sys (AVAST Software)
DRV:64bit: - (aswTdi) – C:WindowsSysNativedriversaswTdi.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:WindowsSysNativedriversaswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:WindowsSysNativedriversaswFsBlk.sys (AVAST Software)
DRV:64bit: - (ggsemc) – C:WindowsSysNativedriversggsemc.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (ggflt) – C:WindowsSysNativedriversggflt.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (fssfltr) – C:WindowsSysNativedriversfssfltr.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:WindowsSysNativedriversamdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:WindowsSysNativedriversamdxata.sys (Advanced Micro Devices)
DRV:64bit: - (igfx) – C:WindowsSysNativedriversigdkmd64.sys (Intel Corporation)
DRV:64bit: - (bScsiMSa) – C:WindowsSysNativedriversbScsiMSa.sys (Broadcom Corporation)
DRV:64bit: - (nvpciflt) – C:WindowsSysNativedriversnvpciflt.sys (NVIDIA Corporation)
DRV:64bit: - (bScsiSDa) – C:WindowsSysNativedriversbScsiSDa.sys (Broadcom Corporation)
DRV:64bit: - (b57xdmp) – C:WindowsSysNativedriversb57xdmp.sys (Broadcom Corporation)
DRV:64bit: - (b57xdbd) – C:WindowsSysNativedriversb57xdbd.sys (Broadcom Corporation)
DRV:64bit: - (k57nd60a) Broadcom NetLink ™ – C:WindowsSysNativedriversk57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (PCTCore) – C:WindowsSysNativedriversPCTCore64.sys (PC Tools)
DRV:64bit: - (HpSAMD) – C:WindowsSysNativedriversHpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:WindowsSysNativedriversTsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (usbser) – C:WindowsSysNativedriversusbser.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:WindowsSysNativedriverssdbus.sys (Microsoft Corporation)
DRV:64bit: - (ETD) – C:WindowsSysNativedriversETD.sys (ELAN Microelectronics Corp.)
DRV:64bit: - (athr) – C:WindowsSysNativedriversathrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (MEIx64) Intel® – C:WindowsSysNativedriversHECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Sonido Intel® – C:WindowsSysNativedriversIntcDAud.sys (Intel® Corporation)
DRV:64bit: - (TurboB) – C:WindowsSysNativedriversTurboB.sys (Intel® Corporation)
DRV:64bit: - (nusb3xhc) – C:WindowsSysNativedriversnusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:WindowsSysNativedriversnusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (iaStor) – C:WindowsSysNativedriversiaStor.sys (Intel Corporation)
DRV:64bit: - (pctEFA) – C:WindowsSysNativedriverspctEFA64.sys (PC Tools)
DRV:64bit: - (pctDS) – C:WindowsSysNativedriverspctDS64.sys (PC Tools)
DRV:64bit: - (Revoflt) – C:WindowsSysNativedriversrevoflt.sys (VS Revo Group)
DRV:64bit: - (amdsbs) – C:WindowsSysNativedriversamdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:WindowsSysNativedriverslsi_sas2.sys (LSI Corporation)
DRV:64bit: - (Fs_Rec) – C:WindowsSysNativedriversfs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:WindowsSysNativedriversstexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:WindowsSysNativedriversevbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:WindowsSysNativedriversbxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:WindowsSysNativedriversb57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:WindowsSysNativedrivershcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (NTIDrvr) – C:WindowsSysNativedriversNTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) – C:WindowsSysNativedriversUBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (PxHlpa64) – C:WindowsSysNativedriversPxHlpa64.sys (Sonic Solutions)
DRV - (a2injectiondriver) – C:Program Files (x86)Emsisoft Anti-Malwarea2dix64.sys (Emsi Software GmbH)
DRV - (a2acc) – C:Program Files (x86)Emsisoft Anti-Malwarea2accx64.sys (Emsi Software GmbH)
DRV - (A2DDA) – C:Program Files (x86)Emsisoft Anti-Malwarea2ddax64.sys (Emsi Software GmbH)
DRV - (a2util) – C:Program Files (x86)Emsisoft Anti-Malwarea2util64.sys (Emsi Software GmbH)
DRV - (WIMMount) – C:WindowsSysWOW64driverswimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://packardbell.msn.com
IE:64bit: - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://packardbell.msn.com
IE:64bit: - HKLM..SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM..SearchScopes{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE:64bit: - HKLM..SearchScopes{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://packardbell.msn.com
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Local Page = C:WindowsSysWOW64blank.htm
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://packardbell.msn.com
IE - HKLM..SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM..SearchScopes{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM..SearchScopes{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}

IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://packardbell.msn.com
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.yahoo.es/
IE - HKCU..URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
IE - HKCU..SearchScopes,DefaultScope = {E4BEADF6-17DD-4BC9-9793-B06BEE4E453B}
IE - HKCU..SearchScopes{E4BEADF6-17DD-4BC9-9793-B06BEE4E453B}: "URL" = http://www.google.com/search?hl=en&q;={…1I7FDUM_esES477
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - user.js - File not found

FF:64bit: - [removed]/FlashPlayer: C:Windowssystem32MacromedFlashNPSWF64_11_2_202_228.dll File not found
FF:64bit: - [removed]/GENUINE: disabled File not found
FF:64bit: - [removed]/OfficeAuthz,version=14.0: C:PROGRA~1MICROS~2Office14NPAUTHZ.DLL (Microsoft Corporation)
FF - [removed]/FlashPlayer: C:WindowsSysWOW64MacromedFlashNPSWF32_11_2_202_228.dll ()
FF - [removed]/JavaPlugin: C:Program Files (x86)Javajre6binnew_pluginnpjp2.dll (Sun Microsystems, Inc.)
FF - [removed]/GENUINE: disabled File not found
FF - [removed]/NpCtrl,version=1.0: c:Program Files (x86)Microsoft Silverlight4.1.10111.0npctrl.dll ( Microsoft Corporation)
FF - [removed]/OfficeAuthz,version=14.0: C:PROGRA~2MICROS~3Office14NPAUTHZ.DLL (Microsoft Corporation)
FF - [removed]/SharePoint,version=14.0: C:PROGRA~2MICROS~3Office14NPSPWRAP.DLL (Microsoft Corporation)
FF - [removed]/WLPG,version=15.4.3502.0922: C:Program Files (x86)Windows LivePhoto GalleryNPWLPG.dll (Microsoft Corporation)
FF - [removed]/WLPG,version=15.4.3538.0513: C:Program Files (x86)Windows LivePhoto GalleryNPWLPG.dll (Microsoft Corporation)
FF - [removed]/PsndlCheck,version=1.00: C:Program Files (x86)SonyPLAYSTATION Network Downloadernppsndl.dll (Sony Computer Entertainment Inc.)
FF - [removed]/Media Go,version=1.0: C:Program Files (x86)SonyMedia Gonpmediago.dll (Sony Network Entertainment International LLC)
FF - [removed]/Google Update;version=3: C:Program Files (x86)GoogleUpdate1.3.21.111npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/Google Update;version=9: C:Program Files (x86)GoogleUpdate1.3.21.111npGoogleUpdate3.dll (Google Inc.)
FF - [removed]/GamesAppPresenceDetector,Version=1.0: C:Program Files (x86)WildTangent GamesAppBrowserIntegrationRegistered1NP_wtapp.dll ()
FF - HKLMSoftwareMozillaPluginsAdobe Reader: C:Program Files (x86)AdobeReader 9.0ReaderAIRnppdf32.dll (Adobe Systems Inc.)
FF - HKCUSoftwareMozillaPlugins@Skype Limited.com/Facebook Video Calling Plugin: C:UsersPatriciaAppDataLocalFacebookVideoSkypenpFacebookVideoCalling.dll (Skype Limited)

FF - [removed]: C:Program FilesAVAST SoftwareAvastWebRepFF [2012/03/10 20:04:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 11.0extensionsComponents: C:Program Files (x86)Mozilla Firefoxcomponents [2012/04/05 11:54:06 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 11.0extensionsPlugins: C:Program Files (x86)Mozilla Firefoxplugins

[2012/04/05 11:55:22 | 000,000,000 | —D | M] (No name found) – C:UsersPatriciaAppDataRoamingmozillaExtensions
[2012/04/05 11:54:06 | 000,000,000 | —D | M] (No name found) – C:Program Files (x86)Mozilla Firefoxextensions
[2012/03/13 06:38:06 | 000,097,208 | —- | M] (Mozilla Foundation) – C:Program Files (x86)mozilla firefoxcomponentsbrowsercomps.dll
[2012/03/13 07:06:36 | 000,002,252 | —- | M] () – C:Program Files (x86)mozilla firefoxsearchpluginsbing.xml
[2012/03/13 08:14:58 | 000,003,996 | —- | M] () – C:Program Files (x86)mozilla firefoxsearchpluginsdrae.xml
[2012/03/13 08:14:58 | 000,001,143 | —- | M] () – C:Program Files (x86)mozilla firefoxsearchpluginseBay-es.xml
[2012/03/30 18:56:18 | 000,002,519 | —- | M] () – C:Program Files (x86)mozilla firefoxsearchpluginsSearch_Results.xml
[2012/03/13 07:06:36 | 000,002,040 | —- | M] () – C:Program Files (x86)mozilla firefoxsearchpluginstwitter.xml
[2012/03/13 08:14:58 | 000,001,178 | —- | M] () – C:Program Files (x86)mozilla firefoxsearchpluginswikipedia-es.xml
[2012/03/13 08:14:58 | 000,001,102 | —- | M] () – C:Program Files (x86)mozilla firefoxsearchpluginsyahoo-es.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chr
o
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:Program Files (x86)GoogleChromeApplication18.0.1025.151ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:Program Files (x86)GoogleChromeApplication18.0.1025.151pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:Program Files (x86)GoogleChromeApplication18.0.1025.151gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:WindowsSysWOW64MacromedFlashNPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:Program Files (x86)AdobeReader 9.0ReaderBrowsernppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:Program Files (x86)Javajre6binnew_pluginnpdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:Program Files (x86)Javajre6binnew_pluginnpjp2.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:PROGRA~2MICROS~3Office14NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:PROGRA~2MICROS~3Office14NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:Program Files (x86)GoogleUpdate1.3.21.99npGoogleUpdate3.dll
CHR - plugin: Media Go Detector (Enabled) = C:Program Files (x86)SonyMedia Gonpmediago.dll
CHR - plugin: PlayStation®Network Downloader Check Plug-in (Enabled) = C:Program Files (x86)SonyPLAYSTATION Network Downloadernppsndl.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:Program Files (x86)WildTangent GamesAppBrowserIntegrationRegistered1NP_wtapp.dll
CHR - plugin: Windows Live Photo Gallery (Enabled) = C:Program Files (x86)Windows LivePhoto GalleryNPWLPG.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:UsersPatriciaAppDataLocalFacebookVideoSkypenpFacebookVideoCalling.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:Program Files (x86)Microsoft Silverlight4.0.60831.0npctrl.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:UsersPatriciaAppDataLocalGoogleChromeUser DataDefaultExtensionsblpcfgokakmgnkcojhhkbfbldkacnbeo4.2.5_0
CHR - Extension: Bu00FAsqueda de Google = C:UsersPatriciaAppDataLocalGoogleChromeUser DataDefaultExtensionscoobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR - Extension: avast! WebRep = C:UsersPatriciaAppDataLocalGoogleChromeUser DataDefaultExtensionsicmlaeflemplmjndnaapfdbbnpncnbda7.0.1426_0
CHR - Extension: Gmail = C:UsersPatriciaAppDataLocalGoogleChromeUser DataDefaultExtensionspjkljhegncpnkpknbcohdijeoejaedia7_0

O1 HOSTS File: ([2009/06/10 23:00:26 | 000,000,824 | —- | M]) - C:WindowsSysNativedriversetchosts
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:Archivos de programaAVAST SoftwareAvastaswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Archivos de programaCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:Archivos de programaMicrosoft OfficeOffice14URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:Program Files (x86)Spybot - Search & DestroySDHelper.dll (Safer Networking Limited)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Archivos de programaAVAST SoftwareAvastaswWebRepIE.dll (AVAST Software)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:Program Files (x86)MicrosoftBingBarBingExt.dll (Microsoft Corporation.)
O3:64bit: - HKLM..Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM..Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:Archivos de programaAVAST SoftwareAvastaswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM..Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM..Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM..Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:Program Files (x86)MicrosoftBingBarBingExt.dll (Microsoft Corporation.)
O3 - HKLM..Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Archivos de programaAVAST SoftwareAvastaswWebRepIE.dll (AVAST Software)
O3 - HKLM..Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955acaa0a7} - No CLSID value found.
O3 - HKLM..Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU..ToolbarWebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:Program Files (x86)GoogleGoogle ToolbarGoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..Run: [Acer ePower Management] C:Archivos de programaPackard BellPackard Bell Power ManagementePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..Run: [ETDCtrl] C:Archivos de programaElantechETDCtrl.exe (ELAN Microelectronics Corp.)
O4:64bit: - HKLM..Run: [HotKeysCmds] C:WindowsSysNativehkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..Run: [IgfxTray] C:WindowsSysNativeigfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:Program FilesIntelTurboBoostRunTBGadgetOnce.vbs" File not found
O4:64bit: - HKLM..Run: [Persistence] C:WindowsSysNativeigfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..Run: [RtHDVCpl] C:Program FilesRealtekAudioHDARAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..Run: [avast] C:Program FilesAVAST SoftwareAvastavastUI.exe (AVAST Software)
O4 - HKLM..Run: [BackupManagerTray] C:Program Files (x86)NTIPackard Bell MyBackupBackupManagerTray.exe (NTI Corporation)
O4 - HKLM..Run: [emsisoft anti-malware] c:program files (x86)emsisoft anti-malwarea2guard.exe (Emsi Software GmbH)
O4 - HKLM..Run: [IAStorIcon] C:Program Files (x86)IntelIntel® Rapid Storage TechnologyIAStorIcon.exe (Intel Corporation)
O4 - HKLM..Run: [LManager] C:Program Files (x86)Launch ManagerLManager.exe (Dritek System Inc.)
O4 - HKLM..Run: [NUSB3MON] C:Program Files (x86)Renesas ElectronicsUSB 3.0 Host Controller DriverApplicationnusb3mon.exe (Renesas Electronics Corporation)
O4 - HKCU..Run: [SpybotSD TeaTimer] C:Program Files (x86)Spybot - Search & DestroyTeaTimer.exe (Safer Networking Limited)
O4 - HKCU..RunOnce: [!SearchquDSFF] C:Windowssystem32RUNDLL32.EXE C:UsersPatriciaAppDataLocalTempSRASSE~1.DLL,_SetFirefoxAssets Search Results,Search_Results,http://dts.search-results.com/sr?src=ffb&appid;=361&systemid;=406&sr;=0&q;=, File not found
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoActiveDesktop = 1
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoActiveDesktopChanges = 1
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: ConsentPromptBehaviorAdmin = 5
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: ConsentPromptBehaviorUser = 3
O9:64bit: - Extra Button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Archivos de programaMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : &Enviar; a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Archivos de programaMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Notas &vinculadas; de OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Archivos de programaMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Notas &vinculadas; de OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Archivos de programaMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:Program Files (x86)Spybot - Search & DestroySDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5Catalog_Entries64\000000000008 [] - C:Archivos de programaCommon FilesMicrosoft SharedWindows LiveWLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5Catalog_Entries64\000000000009 [] - C:Archivos de programaCommon FilesMicrosoft SharedWindows LiveWLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - Protocol_Catalog9Catalog_Entries64\000000000001 - C:Program Files (x86)Common FilesPC ToolsLspPCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9Catalog_Entries64\000000000002 - C:Program Files (x86)Common FilesPC ToolsLspPCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9Catalog_Entries64\000000000003 - C:Program Files (x86)Common FilesPC ToolsLspPCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9Catalog_Entries64\000000000004 - C:Program Files (x86)Common FilesPC ToolsLspPCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9Catalog_Entries64\000000000005 - C:Program Files (x86)Common FilesPC ToolsLspPCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9Catalog_Entries64\000000000006 - C:Program Files (x86)Common FilesPC ToolsLspPCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9Catalog_Entries64\000000000018 - C:Program Files (x86)Common FilesPC ToolsLspPCTLsp64.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9Catalog_Entries\000000000001 - C:Program Files (x86)Common FilesPC ToolsLspPCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9Catalog_Entries\000000000002 - C:Program Files (x86)Common FilesPC ToolsLspPCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9Catalog_Entries\000000000003 - C:Program Files (x86)Common FilesPC ToolsLspPCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9Catalog_Entries\000000000004 - C:Program Files (x86)Common FilesPC ToolsLspPCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9Catalog_Entries\000000000005 - C:Program Files (x86)Common FilesPC ToolsLspPCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9Catalog_Entries\000000000006 - C:Program Files (x86)Common FilesPC ToolsLspPCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9Catalog_Entries\000000000018 - C:Program Files (x86)Common FilesPC ToolsLspPCTLsp.dll (PC Tools Research Pty Ltd.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = 192.168.1.1
O17 - HKLMSystemCCSServicesTcpipParametersInterfaces{593EFE90-293B-4E32-874D-1FD5730986B5}: DhcpNameServer = 192.168.1.1
O18:64bit: - ProtocolHandlerlivecall - No CLSID value found
O18:64bit: - ProtocolHandlerms-help - No CLSID value found
O18:64bit: - ProtocolHandlermsnim - No CLSID value found
O18:64bit: - ProtocolHandlerwlmailhtml - No CLSID value found
O18:64bit: - ProtocolHandlerwlpg - No CLSID value found
O18:64bit: - ProtocolFiltertext/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:Archivos de programaCommon FilesMicrosoft SharedOFFICE14MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (C:Windowssystem32nvinitx.dll) - C:WindowsSysNativenvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:WindowsSysWOW64nvinit.dll) - C:WindowsSysWOW64nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:Windowsexplorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:Windowssystem32userinit.exe) - C:WindowsSysNativeuserinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:WindowsSysNativeSystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:WindowsSysWow64explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:WindowsSysWow64userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - WinlogonNotifyigfxcui: DllName - (igfxdev.dll) - C:WindowsSysNativeigfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2{23c2b98c-66b6-11e1-9183-1c7508fa280c}Shell - "" = AutoRun
O33 - MountPoints2{23c2b98c-66b6-11e1-9183-1c7508fa280c}ShellAutoRuncommand - "" = E:starusb.exe
O33 - MountPoints2{2e3716e3-32ec-11e1-9827-1c7508fa280c}Shell - "" = AutoRun
O33 - MountPoints2{2e3716e3-32ec-11e1-9827-1c7508fa280c}ShellAutoRuncommand - "" = F:starusb.exe
O33 - MountPoints2{9d54b707-d2e6-11e0-9914-1c7508fa280c}Shell - "" = AutoRun
O33 - MountPoints2{9d54b707-d2e6-11e0-9914-1c7508fa280c}ShellAutoRuncommand - "" = E:Startme.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM..comfile [open] – "%1" %*
O35:64bit: - HKLM..exefile [open] – "%1" %*
O35 - HKLM..comfile [open] – "%1" %*
O35 - HKLM..exefile [open] – "%1" %*
O37:64bit: - HKLM…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM…exe [@ = exefile] – "%1" %*
O37 - HKLM…com [@ = comfile] – "%1" %*
O37 - HKLM…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:WindowsSystem32l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:WindowsSysWOW64l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:WindowsSysWow64l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:WindowsSysWow64iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/04/09 19:01:03 | 000,593,920 | —- | C] (OldTimer Tools) – C:UsersPatriciaDesktopOTL.exe
[2012/04/09 16:46:32 | 000,000,000 | —D | C] – C:UsersPatriciaAppDataRoamingVS Revo Group
[2012/04/09 16:10:54 | 000,000,000 | —D | C] – C:UsersPatriciaAppDataLocalVS Revo Group
[2012/04/09 16:10:50 | 000,031,800 | —- | C] (VS Revo Group) – C:WindowsSysNativedriversrevoflt.sys
[2012/04/09 16:10:50 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsRevo Uninstaller Pro
[2012/04/09 16:10:45 | 000,000,000 | —D | C] – C:Program FilesVS Revo Group
[2012/04/08 12:04:06 | 000,816,016 | —- | C] (PC Tools) – C:WindowsSysNativedriverspctEFA64.sys
[2012/04/08 12:04:06 | 000,452,872 | —- | C] (PC Tools) – C:WindowsSysNativedriverspctDS64.sys
[2012/04/08 12:04:04 | 000,331,368 | —- | C] (PC Tools) – C:WindowsSysNativedriverspctgntdi64.sys
[2012/04/08 12:04:04 | 000,136,168 | —- | C] (PC Tools) – C:WindowsSysNativedriverspctwfpfilter64.sys
[2012/04/08 12:03:59 | 000,257,232 | —- | C] (PC Tools) – C:WindowsSysNativedriversPCTCore64.sys
[2012/04/08 12:03:38 | 000,092,896 | —- | C] (PC Tools) – C:WindowsSysNativedriverspctplsg64.sys
[2012/04/08 12:02:57 | 000,000,000 | —D | C] – C:Program Files (x86)Common FilesPC Tools
[2012/04/08 11:31:01 | 000,000,000 | —D | C] – C:UsersPatriciaAppDataRoamingParetoLogic
[2012/04/08 11:31:01 | 000,000,000 | —D | C] – C:UsersPatriciaAppDataRoamingDriverCure[2012/04/08 11:30:13 | 000,000,000 | —D | C] – C:ProgramDataParetoLogic
[2012/04/07 19:27:58 | 000,000,000 | —D | C] – C:ProgramData{6AD8E59C-250C-4201-B5BA-56ADEF76FF46}
[2012/04/05 11:58:13 | 000,200,976 | —- | C] (Trend Micro Inc.) – C:WindowsSysWow64driverstmcomm.sys
[2012/04/05 11:54:50 | 000,000,000 | —D | C] – C:UsersPatriciaAppDataRoamingMozilla
[2012/04/03 16:01:40 | 000,000,000 | —D | C] – C:ProgramDataCodecv
[2012/04/01 15:44:29 | 000,000,000 | —D | C] – C:Program FilesCCleaner
[2012/04/01 15:24:25 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsEmsisoft Anti-Malware
[2012/03/31 12:09:11 | 000,000,000 | —D | C] – C:UsersPatriciaAppDataRoamingGoogle
[2012/03/30 18:55:05 | 000,000,000 | —D | C] – C:ProgramDataDivX
[2012/03/30 18:50:16 | 000,000,000 | —D | C] – C:ProgramDataPremium
[2012/03/30 18:50:16 | 000,000,000 | —D | C] – C:ProgramDataInstallMate
[2012/03/30 11:11:31 | 008,738,464 | —- | C] (Adobe Systems Incorporated) – C:WindowsSysWow64FlashPlayerInstaller.exe
[2012/03/30 10:34:55 | 000,418,464 | —- | C] (Adobe Systems Incorporated) – C:WindowsSysWow64FlashPlayerApp.exe
[2012/03/15 13:40:02 | 005,559,152 | —- | C] (Microsoft Corporation) – C:WindowsSysNativentoskrnl.exe
[2012/03/15 13:40:01 | 003,968,368 | —- | C] (Microsoft Corporation) – C:WindowsSysWow64ntkrnlpa.exe
[2012/03/15 13:40:00 | 003,913,584 | —- | C] (Microsoft Corporation) – C:WindowsSysWow64ntoskrnl.exe
[2012/03/14 23:58:55 | 000,000,000 | -HSD | C] – C:Config.Msi
[2012/03/14 12:39:02 | 001,544,192 | —- | C] (Microsoft Corporation) – C:WindowsSysNativeDWrite.dll
[2012/03/14 12:37:15 | 001,031,680 | —- | C] (Microsoft Corporation) – C:WindowsSysNativerdpcore.dll
[2012/03/14 12:37:15 | 000,826,880 | —- | C] (Microsoft Corporation) – C:WindowsSysWow64rdpcore.dll
[2012/03/14 12:37:14 | 000,149,504 | —- | C] (Microsoft Corporation) – C:WindowsSysNativerdpcorekmts.dll
[2012/03/14 12:37:14 | 000,009,216 | —- | C] (Microsoft Corporation) – C:WindowsSysNativerdrmemptylst.exe
[2012/03/14 12:37:13 | 000,077,312 | —- | C] (Microsoft Corporation) – C:WindowsSysNativerdpwsx.dll
[2012/03/14 12:11:39 | 000,000,000 | —D | C] – C:ProgramDataMicrosoftWindowsStart MenuProgramsavast! Free Antivirus
[1 C:Windows*.tmp files -> C:Windows*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/04/09 19:11:05 | 000,000,838 | —- | M] () – C:WindowstasksAdobe Flash Player Updater.job
[2012/04/09 18:46:00 | 000,001,104 | —- | M] () – C:WindowstasksGoogleUpdateTaskMachineUA.job
[2012/04/09 18:44:04 | 000,009,920 | -H– | M] () – C:WindowsSysNative7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/09 18:44:04 | 000,009,920 | -H– | M] () – C:WindowsSysNative7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/09 18:38:32 | 000,001,100 | —- | M] () – C:WindowstasksGoogleUpdateTaskMachineCore.job
[2012/04/09 18:35:56 | 000,000,206 | —- | M] () – C:WindowstasksAutoKMS.job
[2012/04/09 18:35:33 | 000,067,584 | –S- | M] () – C:Windowsbootstat.dat
[2012/04/09 16:58:07 | 3104,722,944 | -HS- | M] () – C:hiberfil.sys
[2012/04/09 16:55:08 | 000,593,920 | —- | M] (OldTimer Tools) – C:UsersPatriciaDesktopOTL.exe
[2012/04/09 16:10:51 | 000,001,089 | —- | M] () – C:UsersPublicDesktopRevo Uninstaller Pro.lnk
[2012/04/09 16:06:39 | 000,001,896 | —- | M] () – C:UsersPatriciaDocumentscc_20120409_160637.reg
[2012/04/09 16:06:22 | 000,002,764 | —- | M] () – C:UsersPatriciaDocumentscc_20120409_160620.reg
[2012/04/09 16:06:07 | 000,002,016 | —- | M] () – C:UsersPatriciaDocumentscc_20120409_160605.reg
[2012/04/09 16:05:44 | 000,010,338 | —- | M] () – C:UsersPatriciaDocumentscc_20120409_160540.reg
[2012/04/09 16:05:07 | 000,170,942 | —- | M] () – C:UsersPatriciaDocumentscc_20120409_160452.reg
[2012/04/09 15:47:40 | 000,001,853 | —- | M] () – C:UsersPublicDesktopavast! Free Antivirus.lnk
[2012/04/09 15:47:40 | 000,000,000 | —- | M] () – C:WindowsSysWow64config.nt
[2012/04/08 12:04:21 | 001,926,382 | —- | M] () – C:WindowsSysNativedriversCat.DB
[2012/04/08 11:18:36 | 000,001,274 | —- | M] () – C:UsersPatriciaAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupRecorte de pantalla y Selector de OneNote 2010.lnk
[2012/04/07 19:58:02 | 000,000,940 | —- | M] () – C:WindowstasksFacebookUpdateTaskUserS-1-5-21-1680525943-2408236732-211231575-1001UA.job
[2012/04/06 22:28:35 | 001,555,646 | —- | M] () – C:WindowsSysNativePerfStringBackup.INI
[2012/04/06 22:28:35 | 000,703,840 | —- | M] () – C:WindowsSysNativeperfh00A.dat
[2012/04/06 22:28:35 | 000,616,008 | —- | M] () – C:WindowsSysNativeperfh009.dat
[2012/04/06 22:28:35 | 000,137,806 | —- | M] () – C:WindowsSysNativeperfc00A.dat
[2012/04/06 22:28:35 | 000,106,388 | —- | M] () – C:WindowsSysNativeperfc009.dat
[2012/04/05 13:10:36 | 000,186,676 | —- | M] () – C:UsersPatriciaAppDataLocalcensus.cache
[2012/04/05 13:10:17 | 000,103,334 | —- | M] () – C:UsersPatriciaAppDataLocalars.cache
[2012/04/05 11:55:30 | 000,000,036 | —- | M] () – C:UsersPatriciaAppDataLocalhousecall.guid.cache
[2012/04/03 16:02:56 | 000,000,050 | —- | M] () – C:user.js
[2012/04/01 15:44:39 | 000,000,834 | —- | M] () – C:UsersPublicDesktopCCleaner.lnk
[2012/04/01 15:24:25 | 000,001,063 | —- | M] () – C:UsersPublicDesktopEmsisoft Anti-Malware.lnk
[2012/03/30 16:55:14 | 000,290,933 | —- | M] () – C:UsersPatriciaDesktopBeca%20Doctorado%20Grant_%202012.pdf
[2012/03/30 11:11:37 | 000,418,464 | —- | M] (Adobe Systems Incorporated) – C:WindowsSysWow64FlashPlayerApp.exe
[2012/03/30 11:11:37 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:WindowsSysWow64FlashPlayerCPLApp.cpl
[2012/03/30 11:11:31 | 008,738,464 | —- | M] (Adobe Systems Incorporated) – C:WindowsSysWow64FlashPlayerInstaller.exe
[2012/03/29 13:49:27 | 000,000,060 | —- | M] () – C:Windowswpd99.drv
[2012/03/27 22:58:00 | 000,000,918 | —- | M] () – C:WindowstasksFacebookUpdateTaskUserS-1-5-21-1680525943-2408236732-211231575-1001Core.job
[2012/03/15 17:12:44 | 000,000,510 | —- | M] () – C:settings.ini
[2012/03/15 14:35:21 | 000,436,872 | —- | M] () – C:WindowsSysNativeFNTCACHE.DAT
[1 C:Windows*.tmp files -> C:Windows*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/04/09 16:10:51 | 000,001,089 | —- | C] () – C:UsersPublicDesktopRevo Uninstaller Pro.lnk
[2012/04/09 16:06:39 | 000,001,896 | —- | C] () – C:UsersPatriciaDocumentscc_20120409_160637.reg
[2012/04/09 16:06:21 | 000,002,764 | —- | C] () – C:UsersPatriciaDocumentscc_20120409_160620.reg
[2012/04/09 16:06:06 | 000,002,016 | —- | C] () – C:UsersPatriciaDocumentscc_20120409_160605.reg
[2012/04/09 16:05:42 | 000,010,338 | —- | C] () – C:UsersPatriciaDocumentscc_20120409_160540.reg
[2012/04/09 16:04:56 | 000,170,942 | —- | C] () – C:UsersPatriciaDocumentscc_20120409_160452.reg
[2012/04/08 12:04:07 | 001,926,382 | —- | C] () – C:WindowsSysNativedriversCat.DB
[2012/04/05 13:10:36 | 000,186,676 | —- | C] () – C:UsersPatriciaAppDataLocalcensus.cache
[2012/04/05 13:10:17 | 000,103,334 | —- | C] () – C:UsersPatriciaAppDataLocalars.cache
[2012/04/05 11:55:30 | 000,000,036 | —- | C] () – C:UsersPatriciaAppDataLocalhousecall.guid.cache
[2012/04/05 11:54:09 | 000,001,114 | —- | C] () – C:ProgramDataMicrosoftWindowsStart MenuProgramsMozilla Firefox.lnk
[2012/04/03 16:02:56 | 000,000,050 | —- | C] () – C:user.js
[2012/04/01 15:44:39 | 000,000,834 | —- | C] () – C:UsersPublicDesktopCCleaner.lnk
[2012/04/01 15:24:25 | 000,001,063 | —- | C] () – C:UsersPublicDesktopEmsisoft Anti-Malware.lnk
[2012/03/30 16:55:14 | 000,290,933 | —- | C] () – C:UsersPatriciaDesktopBeca%20Doctorado%20Grant_%202012.pdf
[2012/03/30 10:34:57 | 000,000,838 | —- | C] () – C:WindowstasksAdobe Flash Player Updater.job
[2012/03/15 17:12:44 | 000,000,510 | —- | C] () – C:settings.ini
[2012/03/14 12:11:39 | 000,001,853 | —- | C] () – C:UsersPublicDesktopavast! Free Antivirus.lnk
[2011/10/01 16:10:15 | 000,000,496 | —- | C] () – C:Windowswininit.ini
[2011/10/01 12:35:16 | 000,001,466 | —- | C] () – C:WindowseReg.dat
[2011/08/30 13:20:24 | 000,077,824 | —- | C] () – C:WindowsSysWow64eautil.dll
[2011/08/29 16:43:41 | 000,000,028 | —- | C] () – C:Windowspdf995.ini
[2011/08/29 16:32:41 | 000,047,616 | —- | C] () – C:WindowsSysWow64pdf995mon64.dll
[2011/08/29 16:32:41 | 000,000,060 | —- | C] () – C:Windowswpd99.drv
[2011/08/22 19:01:48 | 000,000,135 | —- | C] () – C:WindowsAutoKMS.ini
[2011/01/06 06:09:23 | 000,960,940 | —- | C] () – C:WindowsSysWow64igkrng600.bin
[2011/01/06 06:09:21 | 000,207,376 | —- | C] () – C:WindowsSysWow64igfcg600m.bin
[2011/01/06 06:09:18 | 000,145,804 | —- | C] () – C:WindowsSysWow64igcompkrng600.bin

========== LOP Check ==========

[2012/04/08 11:31:01 | 000,000,000 | —D | M] – C:UsersPatriciaAppDataRoamingDriverCure
[2011/10/12 18:22:12 | 000,000,000 | —D | M] – C:UsersPatriciaAppDataRoamingEasy MP3 Recorder
[2012/04/09 16:20:26 | 000,000,000 | —D | M] – C:UsersPatriciaAppDataRoamingEasyJob Resume Builder
[2011/08/07 20:39:19 | 000,000,000 | —D | M] – C:UsersPatriciaAppDataRoamingFloodLightGames
[2011/11/25 17:35:56 | 000,000,000 | —D | M] – C:UsersPatriciaAppDataRoamingNokia
[2012/04/08 11:31:01 | 000,000,000 | —D | M] – C:UsersPatriciaAppDataRoamingParetoLogic
[2011/08/29 16:43:41 | 000,000,000 | —D | M] – C:UsersPatriciaAppDataRoamingpdf995
[2011/08/22 18:29:22 | 000,000,000 | —D | M] – C:UsersPatriciaAppDataRoamingSNS
[2011/12/17 14:36:55 | 000,000,000 | —D | M] – C:UsersPatriciaAppDataRoamingSony
[2012/04/07 11:44:04 | 000,000,000 | —D | M] – C:UsersPatriciaAppDataRoamingSpotify
[2012/04/09 16:46:32 | 000,000,000 | —D | M] – C:UsersPatriciaAppDataRoamingVS Revo Group
[2012/04/09 18:35:56 | 000,000,206 | —- | M] () – C:WindowsTasksAutoKMS.job
[2012/03/27 22:58:00 | 000,000,918 | —- | M] () – C:WindowsTasksFacebookUpdateTaskUserS-1-5-21-1680525943-2408236732-211231575-1001Core.job
[2012/04/07 19:58:02 | 000,000,940 | —- | M] () – C:WindowsTasksFacebookUpdateTaskUserS-1-5-21-1680525943-2408236732-211231575-1001UA.job
[2012/02/13 15:52:26 | 000,032,534 | —- | M] () – C:WindowsTasksSCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%*.* >
[2010/12/03 12:35:52 | 000,008,192 | RHS- | M] () – C:BOOTSECT.BAK
[2012/04/09 16:58:07 | 3104,722,944 | -HS- | M] () – C:hiberfil.sys
[2012/04/09 18:35:23 | 4139,630,592 | -HS- | M] () – C:pagefile.sys
[2012/03/15 17:12:44 | 000,000,510 | —- | M] () – C:settings.ini
[2012/04/03 16:02:56 | 000,000,050 | —- | M] () – C:user.js

< %systemroot%Fonts*.com >
[2009/07/14 07:32:31 | 000,026,040 | —- | M] () – C:WindowsFontsGlobalMonospace.CompositeFont
[2009/07/14 07:32:31 | 000,026,489 | —- | M] () – C:WindowsFontsGlobalSansSerif.CompositeFont
[2009/07/14 07:32:31 | 000,029,779 | —- | M] () – C:WindowsFontsGlobalSerif.CompositeFont
[2009/07/14 07:32:31 | 000,043,318 | —- | M] () – C:WindowsFontsGlobalUserInterface.CompositeFont

< %systemroot%Fonts*.dll >

< %systemroot%Fonts*.ini >
[2009/06/10 22:49:50 | 000,000,065 | —- | M] () – C:WindowsFontsdesktop.ini

< %systemroot%Fonts*.ini2 >

< %systemroot%Fonts*.exe >

< %systemroot%system32spoolprtprocsw32x86*.* >

< %systemroot%REPAIR*.bak1 >

< %systemroot%REPAIR*.ini >

< %systemroot%system32*.jpg >

< %systemroot%*.jpg >

< %systemroot%*.png >

< %systemroot%*.scr >
[2012/03/07 02:15:19 | 000,041,184 | —- | M] (AVAST Software) – C:WindowsavastSS.scr
[2011/05/13 16:42:24 | 000,302,448 | —- | M] (Microsoft Corporation) – C:WindowsWLXPGSS.SCR
[1 C:Windows*.tmp files -> C:Windows*.tmp -> ]

< %systemroot%*._sy >

< %APPDATA%AdobeUpdate*.* >

< %ALLUSERSPROFILE%Favorites*.* >

< %APPDATA%Microsoft*.* >

< %PROGRAMFILES%*.* >
[2009/07/14 06:54:24 | 000,000,174 | -HS- | M] () – C:Program Files (x86)desktop.ini

< %APPDATA%Update*.* >

< %systemroot%*. /mp /s >

< %systemroot%System32config*.sav >

< %PROGRAMFILES%bak. /s >

< %systemroot%system32bak. /s >

< %ALLUSERSPROFILE%Start Menu*.lnk /x >

< %systemroot%system32configsystemprofile*.dat /x >

< %systemroot%*.config >

< %systemroot%system32*.db >

< %PROGRAMFILES%Internet Explorer*.dat >

< %APPDATA%MicrosoftInternet ExplorerQuick Launch*.lnk /x >
[2011/08/23 14:47:07 | 000,000,319 | -HS- | M] () – C:UsersPatriciaAppDataRoamingMicrosoftInternet ExplorerQuick Launchdesktop.ini

< %USERPROFILE%Desktop*.exe >
[2012/04/09 16:55:08 | 000,593,920 | —- | M] (OldTimer Tools) – C:UsersPatriciaDesktopOTL.exe

< %PROGRAMFILES%Common Files*.* >

< %systemroot%*.src >

< %systemroot%install*.* >

< %systemroot%system32DLL*.* >

< %systemroot%system32HelpFiles*.* >

< %systemroot%system32rundll*.* >

< %systemroot%winn32*.* >

< %systemroot%Java*.* >

< %systemroot%system32test*.* >

< %systemroot%system32Rundll32*.* >

< %systemroot%AppPatchCustom*.* >

< HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU >

< HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 171 bytes -> C:ProgramDataTemp:DFC5A2B2

< End of report >

EXTRAS


OTL Extras logfile created on: 09/04/2012 19:04:58 - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:UsersPatriciaDesktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000c0a | Country: España | Language: ESN | Date Format: dd/MM/yyyy

3,86 Gb Total Physical Memory | 1,75 Gb Available Physical Memory | 45,35% Memory free
7,71 Gb Paging File | 5,28 Gb Available in Paging File | 68,51% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:Windows | %ProgramFiles% = C:Program Files (x86)
Drive C: | 683,04 Gb Total Space | 578,47 Gb Free Space | 84,69% Space Free | Partition Type: NTFS

Computer Name: PATRICIA-PC | User Name: Patricia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINESOFTWAREClasses]
.url[@ = InternetShortcut] – C:WindowsSysNativerundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINESOFTWAREClasses]
.cpl [@ = cplfile] – C:WindowsSysWow64control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%System32InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:WindowsSystem32rundll32.exe" "C:WindowsSystem32ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:WindowsSystem32rundll32.exe" "C:WindowsSystem32mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:Program Files (x86)VideoLANVLCvlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:Program Files (x86)VideoLANVLCvlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%System32control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%System32InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:Program Files (x86)VideoLANVLCvlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:Program Files (x86)VideoLANVLCvlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvcVol]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyPublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{029A4933-3F36-4E4F-AEC3-2207AB26463D}" = Broadcom Gigabit NetLink Controller
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{4710662C-8204-4334-A977-B1AC9E547819}" = Broadcom Card Reader Driver Installer
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4D668D4F-FAA2-4726-834C-31F4614F312E}" = MSVC80_x64_v2
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.5.7
"{680EDA59-9266-44B4-949E-0C24F65DFF82}" = Microsoft_VC100_CRT_SP1_x64
"{6DDCFF78-6F91-438C-9567-C5CAA9D7F56C}" = Windows Live Family Safety
"{8EB588BD-D398-40D0-ADF7-BE1CEEF7C116}" = Windows Live Remote Client Resources
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0C0A-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Spanish) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A679FBE4-BA2D-4514-8834-030982C8B31A}" = Windows Live Remote Service Resources
"{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}" = MSVC90_x64
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel de control de NVIDIA 266.19
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Controlador de gráficos 266.19
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.0.11
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}" = Monitor de la tecnología Intel® Turbo Boost 2.0
"{C3C912BB-BF4B-3788-8A19-DA5B999CE0C6}" = Microsoft .NET Framework 4 Client Profile ESN Language Pack
"{CEA21F20-DBF4-464C-8B81-28B8508AFDDD}" = Windows Live Family Safety
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"CCleaner" = CCleaner
"Elantech" = ETDWare PS/2-X64 8.0.6.0_WHQL
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile ESN Language Pack" = Paquete de idioma de Microsoft .NET Framework 4 Client Profile ESN
"WinRAR archiver" = WinRAR 4.01 (64-bit)

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{04668DF2-D32F-4555-9C7E-35523DCD6544}" = Control ActiveX de Windows Live Mesh para conexiones remotas
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}" = Backup Manager V3
"{0D261C88-454B-46FE-B43B-640E621BDA11}" = Windows Live Mail
"{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}" = PlayStation®Store
"{167A1F6A-9BF2-4B24-83DB-C6D659F680EA}" = Media Go
"{17DFE37C-064E-4834-AD8F-A4B2B4DF68F8}" = Adobe Photoshop Elements 8.0
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1A7F8DF6-5A3E-4CDF-BC82-BE26B407E21B}" = Los Sims Superstar
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20400DBD-E6DB-45B8-9B6B-1DD7033818EC}" = Nero InfoTool Help
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2348B586-C9AE-46CE-936C-A68E9426E214}" = Nero StartSmart Help
"{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java™ 6 Update 29
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Packard Bell Power Management
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{449CE12D-E2C7-4B97-B19E-55D163EA9435}" = Bing Bar
"{48C0DC5E-820A-44F2-890E-29B68EDD3C78}" = Windows Live Writer
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4D43D635-6FDA-4FA5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
"{5D273F60-0525-48BA-A5FB-D0CAA4A952AE}" = Windows Live Movie Maker
"{64EF903E-D00A-414C-94A4-FBA368FFCDC9}" = Packard Bell Social Networks
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-packardbell" = WildTangent Games App (Packard Bell Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{77477AEA-5757-47D8-8B33-939F43D82218}" = Windows Live UX Platform Language Pack
"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{78DAE910-CA72-450E-AD22-772CB1A00678}" = Windows Live Mesh
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{7D1C7B9F-2744-4388-B128-5C75B8BCCC84}" = Windows Live Essentials
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Packard Bell Recovery Management
"{83202942-84B3-4C50-8622-B8C0AA2D2885}" = Nero Express Help
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FF3891F-01B5-4A71-BFCD-20761890471C}" = Windows Live Messenger
"{90140000-0015-0C0A-0000-0000000FF1CE}" = Microsoft Office Access MUI (Spanish) 2010
"{90140000-0015-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{AA321CAB-5896-46B1-B18E-3EE82C88ABF1}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0C0A-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Spanish) 2010
"{90140000-0016-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{AA321CAB-5896-46B1-B18E-3EE82C88ABF1}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0C0A-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Spanish) 2010
"{90140000-0018-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{AA321CAB-5896-46B1-B18E-3EE82C88ABF1}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0C0A-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Spanish) 2010
"{90140000-0019-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{AA321CAB-5896-46B1-B18E-3EE82C88ABF1}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0C0A-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Spanish) 2010
"{90140000-001A-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{AA321CAB-5896-46B1-B18E-3EE82C88ABF1}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0C0A-0000-0000000FF1CE}" = Microsoft Office Word MUI (Spanish) 2010
"{90140000-001B-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{AA321CAB-5896-46B1-B18E-3EE82C88ABF1}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0403-0000-0000000FF1CE}" = Microsoft Office Proof (Catalan) 2010
"{90140000-001F-0403-0000-0000000FF1CE}_Office14.SingleImage_{F030E098-C2CC-4056-971E-4D3AB0F55517}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0416-0000-0000000FF1CE}" = Microsoft Office Proof (Portuguese (Brazil)) 2010
"{90140000-001F-0416-0000-0000000FF1CE}_Office14.SingleImage_{A7200E61-DC93-42E0-BB74-EE59021016EA}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-042D-0000-0000000FF1CE}" = Microsoft Office Proof (Basque) 2010
"{90140000-001F-042D-0000-0000000FF1CE}_Office14.SingleImage_{C6E07E58-897F-4686-A498-764B9D404F09}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0456-0000-0000000FF1CE}" = Microsoft Office Proof (Galician) 2010
"{90140000-001F-0456-0000-0000000FF1CE}_Office14.SingleImage_{6CA060C9-FAFB-4A51-B533-A6AEE1A325BE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0C0A-1000-0000000FF1CE}_Office14.SingleImage_{ED7E1546-A5BC-407C-8321-94D6DAF9B5A7}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0C0A-0000-0000000FF1CE}" = Microsoft Office Proofing (Spanish) 2010
"{90140000-002C-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DBE2E9A2-A47F-42A9-A1CF-3B6665A9714A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0C0A-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Spanish) 2010
"{90140000-006E-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{7FF53332-4A24-4F40-946E-C58B6326063C}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0C0A-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Spanish) 2010
"{90140000-00A1-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{AA321CAB-5896-46B1-B18E-3EE82C88ABF1}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{939C80FA-96C9-44A6-B318-8E7D8BD8481B}" = Messenger Companion
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{95140000-007A-0C0A-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{95140000-007D-0409-0000-0000000FF1CE}" = Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A41A708E-3BE6-4561-855D-44027C1CF0F8}" = Windows Live Photo Common
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA4BF92B-2AAF-11DA-9D78-000129760D75}" = HomeMedia
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.5.0 MUI
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6659DD8-00A7-4A24-BBFB-C1F6982E5D66}" = PlayStation®Network Downloader
"{BC30E5E7-047D-4232-A7E8-F2CB7CC7B2E0}_is1" = Emsisoft Anti-Malware
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}" = Nero Online Upgrade
"{CC019E3F-59D2-4486-8D4B-878105B62A71}" = Nero DiscSpeed Help
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E0B19DF7-B1C7-4937-82C4-0E4B1E346965}" = eBay Worldwide
"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E5C7D048-F9B4-4219-B323-8BDB01A2563D}" = Nero DriveSpeed Help
"{E727A662-AF9F-4DEE-81C5-F4A1686F3DFC}" = Windows Live Writer Resources
"{E85A4EFC-82F2-4CEE-8A8E-62FDAD353A66}" = Galería fotográfica de Windows Live
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Packard Bell Updater
"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony Ericsson PC Companion 2.02.002
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f3b75363-fa28-46b2-9d9f-112252157a7b}" = Nero 9 Essentials
"{F4041DCE-3FE1-4E18-8A9E-9DE65231EE36}" = Nero ControlCenter
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool
"Adobe AIR" = Adobe AIR
"Adobe Photoshop Elements 8.0" = Adobe Photoshop Elements 8.0
"avast" = avast! Free Antivirus
"Google Chrome" = Google Chrome
"Identity Card" = Identity Card
"InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}" = Packard Bell MyBackup
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"InstallShield_{64EF903E-D00A-414C-94A4-FBA368FFCDC9}" = Packard Bell Social Networks
"LManager" = Launch Manager
"Mozilla Firefox 11.0 (x86 es-ES)" = Mozilla Firefox 11.0 (x86 es-ES)
"Office14.SingleImage" = Microsoft Office Professional 2010
"Packard Bell Registration" = Packard Bell Registration
"Packard Bell Screensaver" = Packard Bell ScreenSaver
"Packard Bell Welcome Center" = Welcome Center
"Pdf995" = Pdf995
"Spotify" = Spotify
"Switch" = Switch, convertidor de audio
"Update Engine" = Sony Ericsson Update Engine
"VLC media player" = VLC media player 1.1.11
"WildTangent packardbell Master Uninstall" = Packard Bell Games
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.01 (32-bit)
"WT088216" = Agatha Christie - Death on the Nile
"WT088226" = Bejeweled 2 Deluxe
"WT088228" = Build-a-lot 2
"WT088235" = Chuzzle Deluxe
"WT088238" = Diner Dash 2 Restaurant Rescue
"WT088260" = Farm Frenzy
"WT088268" = Insaniquarium Deluxe
"WT088269" = Jewel Quest Solitaire 2
"WT088283" = Plants vs. Zombies
"WT088416" = FATE
"WT088420" = Final Drive Nitro
"WT088448" = John Deere Drive Green
"WT088452" = Penguins!
"WT088456" = Polar Bowler
"WT088460" = Polar Golfer
"WT088508" = Virtual Villagers 4 - The Tree of Life
"WT088531" = Zuma's Revenge

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"Spotify" = Spotify

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 15/03/2012 10:56:53 | Computer Name = Patricia-PC | Source = Application Error | ID = 1000
Description = Nombre de la aplicación con errores: iexplore.exe, versión: 9.0.8112.16421,
marca de tiempo: 0x4d76255d Nombre del módulo con errores: MSHTML.dll, versión:
9.0.8112.16441, marca de tiempo: 0x4ee81830 Código de excepción: 0xc0000005 Desplazamiento
de errores: 0x002bc833 Id. del proceso con errores: 0x18a8 Hora de inicio de la aplicación
con errores: 0x01cd02bbd95a4ca9 Ruta de acceso de la aplicación con errores: C:Program
Files (x86)Internet Exploreriexplore.exe Ruta de acceso del módulo con errores:
C:Windowssystem32MSHTML.dll Id. del informe: 19d35820-6eaf-11e1-880e-1c7508fa280c

Error - 19/03/2012 7:32:23 | Computer Name = Patricia-PC | Source = SideBySide | ID = 16842815
Description = Error al generar el contexto de activación para "c:Program Files
(x86)Common FilesAdobe AIRVersions1.0Adobe AIR.dll". Error en el archivo de
manifiesto o directiva "c:Program Files (x86)Common FilesAdobe AIRVersions1.0Adobe
AIR.dll" en la línea 3. El valor "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
del atributo "version" del elemento "assemblyIdentity" no es válido.

Error - 20/03/2012 6:01:48 | Computer Name = Patricia-PC | Source = SideBySide | ID = 16842815
Description = Error al generar el contexto de activación para "c:Program Files
(x86)Common FilesAdobe AIRVersions1.0Adobe AIR.dll". Error en el archivo de
manifiesto o directiva "c:Program Files (x86)Common FilesAdobe AIRVersions1.0Adobe
AIR.dll" en la línea 3. El valor "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
del atributo "version" del elemento "assemblyIdentity" no es válido.

Error - 20/03/2012 6:05:27 | Computer Name = Patricia-PC | Source = SideBySide | ID = 16842815
Description = Error al generar el contexto de activación para "c:program files
(x86)spybot - search & destroyDelZip179.dll". Error en el archivo de manifiesto
o directiva "c:program files (x86)spybot - search & destroyDelZip179.dll" en
la línea 8. El valor "*" del atributo "language" del elemento "assemblyIdentity"
no es válido.

Error - 21/03/2012 6:40:41 | Computer Name = Patricia-PC | Source = SideBySide | ID = 16842815
Description = Error al generar el contexto de activación para "c:Program Files
(x86)Common FilesAdobe AIRVersions1.0Adobe AIR.dll". Error en el archivo de
manifiesto o directiva "c:Program Files (x86)Common FilesAdobe AIRVersions1.0Adobe
AIR.dll" en la línea 3. El valor "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
del atributo "version" del elemento "assemblyIdentity" no es válido.

Error - 26/03/2012 16:16:42 | Computer Name = Patricia-PC | Source = SideBySide | ID = 16842815
Description = Error al generar el contexto de activación para "c:Program Files
(x86)Common FilesAdobe AIRVersions1.0Adobe AIR.dll". Error en el archivo de
manifiesto o directiva "c:Program Files (x86)Common FilesAdobe AIRVersions1.0Adobe
AIR.dll" en la línea 3. El valor "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
del atributo "version" del elemento "assemblyIdentity" no es válido.

Error - 26/03/2012 16:20:32 | Computer Name = Patricia-PC | Source = SideBySide | ID = 16842815
Description = Error al generar el contexto de activación para "c:program files
(x86)spybot - search & destroyDelZip179.dll". Error en el archivo de manifiesto
o directiva "c:program files (x86)spybot - search & destroyDelZip179.dll" en
la línea 8. El valor "*" del atributo "language" del elemento "assemblyIdentity"
no es válido.

Error - 28/03/2012 5:10:16 | Computer Name = Patricia-PC | Source = SideBySide | ID = 16842815
Description = Error al generar el contexto de activación para "c:Program Files
(x86)Common FilesAdobe AIRVersions1.0Adobe AIR.dll". Error en el archivo de
manifiesto o directiva "c:Program Files (x86)Common FilesAdobe AIRVersions1.0Adobe
AIR.dll" en la línea 3. El valor "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR"
del atributo "version" del elemento "assemblyIdentity" no es válido.

Error - 28/03/2012 5:13:57 | Computer Name = Patricia-PC | Source = SideBySide | ID = 16842815
Description = Error al generar el contexto de activación para "c:program files
(x86)spybot - search & destroyDelZip179.dll". Error en el archivo de manifiesto
o directiva "c:program files (x86)spybot - search & destroyDelZip179.dll" en
la línea 8. El valor "*" del atributo "language" del elemento "assemblyIdentity"
no es válido.

Error - 30/03/2012 11:01:42 | Computer Name = Patricia-PC | Source = Application Hang | ID = 1002
Description = El programa iexplore.exe, versión 9.0.8112.16421, dejó de interactuar
con Windows y se cerró. Para ver si hay más información disponible acerca del problema,
compruebe el historial de problemas en el panel de control Centro de actividades.

Identificador
de proceso: 1540 Hora de inicio: 01cd0e4fe907549d Hora de finalización: 44 Ruta de
acceso de la aplicación: C:Program Files (x86)Internet Exploreriexplore.exe Identificador
de informe:

[ System Events ]
Error - 02/12/2011 7:15:29 | Computer Name = Patricia-PC | Source = EventLog | ID = 6008
Description = El cierre anterior del sistema a las 12:13:43 del ?02/?12/?2011 resultó
inesperado.


< End of report >

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, pabegui

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.
Hi,

Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Allow it to update where necessary
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
===================================================

Please download TDSSKiller.zip and and extract it.
  • Run TDSSKiller.exe.
  • Click on Change Parameters
  • Put a check in the box of Detect TDLFS file system
  • Click Start scan.
  • When it is finished the utility outputs a list of detected objects with description.
    The utility automatically selects an action (Cure or Delete) for malicious objects.
    The utility prompts the user to select an action to apply to suspicious objects (Skip, by default). Let the options as it is and click Continue
  • Let reboot if needed and tell me if the tool needed a reboot.
  • Click on Report and post the contents of the text file that will open.

    Note: By default, the utility outputs the log into system disk (it is usually the disk with installed operating system, C:\) root folder. The Log have a name like: TDSSKiller.Version_Date_Time_log.txt.

===================================================

On your next reply please post :
aswMBR log
TDSS Killer log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi Conspire!!! Thanks for your help! There was a problem always that I scanned with aswMBR.exe. After three or four minutes it appeared the message "antiroot avast stops working and has to be closed". I couldn't get a report from it :S Here are the results of TDSKiller 08:54:16.0459 1316 TDSS rootkit removing tool [removed] Apr 10 2012 16:54:05 08:54:16.0677 1316 ============================================================ 08:54:16.0677 1316 Current date / time: 2012/04/11 08:54:16.0677 08:54:16.0677 1316 SystemInfo: 08:54:16.0677 1316 08:54:16.0677 1316 OS Version: 6.1.7601 ServicePack: 1.0 08:54:16.0677 1316 Product type: Workstation 08:54:16.0677 1316 ComputerName: PATRICIA-PC 08:54:16.0677 1316 UserName: Patricia 08:54:16.0677 1316 Windows directory: C:\Windows 08:54:16.0677 1316 System windows directory: C:\Windows 08:54:16.0677 1316 Running under WOW64 08:54:16.0677 1316 Processor architecture: Intel x64 08:54:16.0677 1316 Number of processors: 8 08:54:16.0677 1316 Page size: 0x1000 08:54:16.0677 1316 Boot type: Normal boot 08:54:16.0677 1316 ============================================================ 08:54:23.0526 1316 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 08:54:23.0526 1316 \Device\Harddisk0\DR0: 08:54:23.0526 1316 MBR used 08:54:23.0526 1316 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1F00800, BlocksNum 0x32000 08:54:23.0526 1316 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1F32800, BlocksNum 0x55613000 08:54:23.0557 1316 Initialize success 08:54:23.0557 1316 ============================================================ 08:54:43.0322 4308 ============================================================ 08:54:43.0322 4308 Scan started 08:54:43.0322 4308 Mode: Manual; TDLFS; 08:54:43.0322 4308 ============================================================ 08:54:43.0790 4308 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys 08:54:43.0790 4308 1394ohci - ok 08:54:43.0946 4308 a2acc (922ab7cc2c12c38dc2c4074af893d5fb) C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys 08:54:43.0962 4308 a2acc - ok 08:54:44.0086 4308 a2AntiMalware (5a65a77f7a4a091e896c21db4ef18e1f) C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe 08:54:44.0118 4308 a2AntiMalware - ok 08:54:44.0242 4308 A2DDA (3044d0f3feb9ffe8bc953d8f34b5b504) C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys 08:54:44.0242 4308 A2DDA - ok 08:54:44.0305 4308 a2injectiondriver (905cda5a8d86f733df8000909b4916ed) C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys 08:54:44.0305 4308 a2injectiondriver - ok 08:54:44.0430 4308 a2util (e41d79682a209f72f4f578cfd4a53952) C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys 08:54:44.0430 4308 a2util - ok 08:54:44.0570 4308 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys 08:54:44.0586 4308 ACPI - ok 08:54:44.0710 4308 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys 08:54:44.0710 4308 AcpiPmi - ok 08:54:44.0835 4308 AdobeActiveFileMonitor8.0 (34400005de52842c4d6d4ee978b4d7ce) c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe 08:54:44.0835 4308 AdobeActiveFileMonitor8.0 - ok 08:54:45.0007 4308 AdobeFlashPlayerUpdateSvc (0d4c486a24a711a45fd83acdf4d18506) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 08:54:45.0007 4308 AdobeFlashPlayerUpdateSvc - ok 08:54:45.0116 4308 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys 08:54:45.0132 4308 adp94xx - ok 08:54:45.0225 4308 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys 08:54:45.0241 4308 adpahci - ok 08:54:45.0303 4308 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys 08:54:45.0303 4308 adpu320 - ok 08:54:45.0428 4308 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll 08:54:45.0428 4308 AeLookupSvc - ok 08:54:45.0584 4308 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys 08:54:45.0584 4308 AFD - ok 08:54:45.0709 4308 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys 08:54:45.0709 4308 agp440 - ok 08:54:45.0834 4308 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe 08:54:45.0834 4308 ALG - ok 08:54:45.0943 4308 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys 08:54:45.0943 4308 aliide - ok 08:54:46.0052 4308 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys 08:54:46.0052 4308 amdide - ok 08:54:46.0130 4308 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys 08:54:46.0130 4308 AmdK8 - ok 08:54:46.0208 4308 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys 08:54:46.0208 4308 AmdPPM - ok 08:54:46.0302 4308 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys 08:54:46.0317 4308 amdsata - ok 08:54:46.0426 4308 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys 08:54:46.0426 4308 amdsbs - ok 08:54:46.0504 4308 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys 08:54:46.0504 4308 amdxata - ok 08:54:46.0598 4308 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys 08:54:46.0598 4308 AppID - ok 08:54:46.0676 4308 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll 08:54:46.0692 4308 AppIDSvc - ok 08:54:46.0723 4308 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll 08:54:46.0723 4308 Appinfo - ok 08:54:46.0801 4308 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys 08:54:46.0816 4308 arc - ok 08:54:46.0879 4308 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys 08:54:46.0894 4308 arcsas - ok 08:54:47.0004 4308 aswFsBlk (b9da213b5271db5fce962d827e6d620d) C:\Windows\system32\drivers\aswFsBlk.sys 08:54:47.0004 4308 aswFsBlk - ok 08:54:47.0144 4308 aswKbd (316271cc32fdfffcdb30677684906d5e) C:\Windows\system32\drivers\aswKbd.sys 08:54:47.0144 4308 aswKbd - ok 08:54:47.0253 4308 aswMonFlt (21c9835d0e5ad2ff0f16134bcb32cc71) C:\Windows\system32\drivers\aswMonFlt.sys 08:54:47.0253 4308 aswMonFlt - ok 08:54:47.0378 4308 aswRdr (1b96a5867abd4fa6135d8298fcccf9c6) C:\Windows\System32\Drivers\aswrdr2.sys 08:54:47.0378 4308 aswRdr - ok 08:54:47.0534 4308 aswSnx (6e98bb288696777a3a8a07a52b0eaee9) C:\Windows\system32\drivers\aswSnx.sys 08:54:47.0550 4308 aswSnx - ok 08:54:47.0674 4308 aswSP (d9fb49f16e4eb02efecae8cbfe4bcb4c) C:\Windows\system32\drivers\aswSP.sys 08:54:47.0690 4308 aswSP - ok 08:54:47.0815 4308 aswTdi (7352bb9a564b94bbd7c9cbf165f55006) C:\Windows\system32\drivers\aswTdi.sys 08:54:47.0830 4308 aswTdi - ok 08:54:47.0955 4308 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 08:54:47.0955 4308 AsyncMac - ok 08:54:48.0080 4308 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys 08:54:48.0080 4308 atapi - ok 08:54:48.0267 4308 athr (c8679a07267f030704168e45e27c3d43) C:\Windows\system32\DRIVERS\athrx.sys 08:54:48.0314 4308 athr - ok 08:54:48.0392 4308 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll 08:54:48.0408 4308 AudioEndpointBuilder - ok 08:54:48.0423 4308 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll 08:54:48.0439 4308 AudioSrv - ok 08:54:48.0532 4308 avast! Antivirus (4041d31508a2a084dfb42c595854090f) C:\Program Files\AVAST Software\Avast\AvastSvc.exe 08:54:48.0532 4308 avast! Antivirus - ok 08:54:48.0626 4308 avast! Firewall - ok 08:54:48.0688 4308 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll 08:54:48.0704 4308 AxInstSV - ok 08:54:48.0751 4308 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys 08:54:48.0766 4308 b06bdrv - ok 08:54:48.0844 4308 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 08:54:48.0844 4308 b57nd60a - ok 08:54:48.0969 4308 b57xdbd (2618e15514736fb469b105ce729b6d9d) C:\Windows\system32\DRIVERS\b57xdbd.sys 08:54:48.0969 4308 b57xdbd - ok 08:54:49.0063 4308 b57xdmp (baba4f0e2978b69b4e0b260ef7150dd6) C:\Windows\system32\DRIVERS\b57xdmp.sys 08:54:49.0078 4308 b57xdmp - ok 08:54:49.0203 4308 BBSvc (0d1ea7509f394d8b705b239ee71f5118) C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE 08:54:49.0203 4308 BBSvc - ok 08:54:49.0281 4308 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll 08:54:49.0297 4308 BDESVC - ok 08:54:49.0406 4308 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 08:54:49.0406 4308 Beep - ok 08:54:49.0515 4308 BFE (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll 08:54:49.0531 4308 BFE - ok 08:54:49.0656 4308 BITS (1ea7969e3271cbc59e1730697dc74682) C:\Windows\System32\qmgr.dll 08:54:49.0656 4308 BITS - ok 08:54:49.0765 4308 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 08:54:49.0780 4308 blbdrive - ok 08:54:49.0890 4308 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys 08:54:49.0890 4308 bowser - ok 08:54:49.0983 4308 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys 08:54:49.0983 4308 BrFiltLo - ok 08:54:50.0061 4308 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys 08:54:50.0061 4308 BrFiltUp - ok 08:54:50.0139 4308 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll 08:54:50.0139 4308 Browser - ok 08:54:50.0186 4308 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 08:54:50.0186 4308 Brserid - ok 08:54:50.0264 4308 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 08:54:50.0264 4308 BrSerWdm - ok 08:54:50.0342 4308 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 08:54:50.0342 4308 BrUsbMdm - ok 08:54:50.0420 4308 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 08:54:50.0420 4308 BrUsbSer - ok 08:54:50.0529 4308 bScsiMSa (65349b60f2f5325759525199e26da1a6) C:\Windows\system32\DRIVERS\bScsiMSa.sys 08:54:50.0529 4308 bScsiMSa - ok 08:54:50.0638 4308 bScsiSDa (e6cc56662f6c6b787a1fbea4cd247ae0) C:\Windows\system32\DRIVERS\bScsiSDa.sys 08:54:50.0654 4308 bScsiSDa - ok 08:54:50.0763 4308 BthEnum (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\DRIVERS\BthEnum.sys 08:54:50.0779 4308 BthEnum - ok 08:54:50.0857 4308 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys 08:54:50.0857 4308 BTHMODEM - ok 08:54:50.0966 4308 BthPan (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys 08:54:50.0966 4308 BthPan - ok 08:54:51.0044 4308 BTHPORT (64c198198501f7560ee41d8d1efa7952) C:\Windows\system32\Drivers\BTHport.sys 08:54:51.0060 4308 BTHPORT - ok 08:54:51.0138 4308 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll 08:54:51.0138 4308 bthserv - ok 08:54:51.0262 4308 BTHUSB (f188b7394d81010767b6df3178519a37) C:\Windows\system32\Drivers\BTHUSB.sys 08:54:51.0262 4308 BTHUSB - ok 08:54:51.0387 4308 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 08:54:51.0387 4308 cdfs - ok 08:54:51.0465 4308 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys 08:54:51.0465 4308 cdrom - ok 08:54:51.0528 4308 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll 08:54:51.0543 4308 CertPropSvc - ok 08:54:51.0574 4308 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys 08:54:51.0574 4308 circlass - ok 08:54:51.0699 4308 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 08:54:51.0699 4308 CLFS - ok 08:54:51.0808 4308 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 08:54:51.0808 4308 clr_optimization_v2.0.50727_32 - ok 08:54:51.0918 4308 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 08:54:51.0933 4308 clr_optimization_v2.0.50727_64 - ok 08:54:52.0105 4308 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 08:54:52.0105 4308 clr_optimization_v4.0.30319_32 - ok 08:54:52.0245 4308 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 08:54:52.0245 4308 clr_optimization_v4.0.30319_64 - ok 08:54:52.0308 4308 clwvd - ok 08:54:52.0339 4308 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 08:54:52.0354 4308 CmBatt - ok 08:54:52.0417 4308 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys 08:54:52.0417 4308 cmdide - ok 08:54:52.0542 4308 CNG (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys 08:54:52.0542 4308 CNG - ok 08:54:52.0666 4308 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys 08:54:52.0666 4308 Compbatt - ok 08:54:52.0744 4308 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys 08:54:52.0744 4308 CompositeBus - ok 08:54:52.0807 4308 COMSysApp - ok 08:54:52.0838 4308 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys 08:54:52.0838 4308 crcdisk - ok 08:54:52.0932 4308 CryptSvc (15597883fbe9b056f276ada3ad87d9af) C:\Windows\system32\cryptsvc.dll 08:54:52.0932 4308 CryptSvc - ok 08:54:52.0978 4308 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll 08:54:52.0994 4308 DcomLaunch - ok 08:54:53.0072 4308 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll 08:54:53.0072 4308 defragsvc - ok 08:54:53.0197 4308 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys 08:54:53.0212 4308 DfsC - ok 08:54:53.0322 4308 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll 08:54:53.0322 4308 Dhcp - ok 08:54:53.0446 4308 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 08:54:53.0446 4308 discache - ok 08:54:53.0556 4308 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys 08:54:53.0556 4308 Disk - ok 08:54:53.0634 4308 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll 08:54:53.0634 4308 Dnscache - ok 08:54:53.0680 4308 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll 08:54:53.0696 4308 dot3svc - ok 08:54:53.0758 4308 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll 08:54:53.0758 4308 DPS - ok 08:54:53.0836 4308 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 08:54:53.0836 4308 drmkaud - ok 08:54:53.0930 4308 DsiWMIService (470f7f19188ab45463f8b612d6dde7c8) C:\Program Files (x86)\Launch Manager\dsiwmis.exe 08:54:53.0946 4308 DsiWMIService - ok 08:54:54.0070 4308 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys 08:54:54.0086 4308 DXGKrnl - ok 08:54:54.0164 4308 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll 08:54:54.0164 4308 EapHost - ok 08:54:54.0258 4308 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys 08:54:54.0289 4308 ebdrv - ok 08:54:54.0351 4308 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe 08:54:54.0367 4308 EFS - ok 08:54:54.0476 4308 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe 08:54:54.0492 4308 ehRecvr - ok 08:54:54.0554 4308 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe 08:54:54.0554 4308 ehSched - ok 08:54:54.0632 4308 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys 08:54:54.0648 4308 elxstor - ok 08:54:54.0741 4308 ePowerSvc (f2e893846021cee30ac7612b5be66330) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe 08:54:54.0757 4308 ePowerSvc - ok 08:54:54.0819 4308 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys 08:54:54.0819 4308 ErrDev - ok 08:54:54.0944 4308 ETD (9d8739a2a2173c9d27c499a3fc6eda3f) C:\Windows\system32\DRIVERS\ETD.sys 08:54:54.0944 4308 ETD - ok 08:54:55.0069 4308 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll 08:54:55.0084 4308 EventSystem - ok 08:54:55.0131 4308 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 08:54:55.0147 4308 exfat - ok 08:54:55.0272 4308 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 08:54:55.0272 4308 fastfat - ok 08:54:55.0396 4308 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe 08:54:55.0412 4308 Fax - ok 08:54:55.0490 4308 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys 08:54:55.0490 4308 fdc - ok 08:54:55.0568 4308 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll 08:54:55.0584 4308 fdPHost - ok 08:54:55.0693 4308 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll 08:54:55.0693 4308 FDResPub - ok 08:54:55.0802 4308 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 08:54:55.0802 4308 FileInfo - ok 08:54:55.0880 4308 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 08:54:55.0896 4308 Filetrace - ok 08:54:56.0020 4308 FLEXnet Licensing Service (abedfd48ac042c6aaad32452e77217a1) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 08:54:56.0036 4308 FLEXnet Licensing Service - ok 08:54:56.0145 4308 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys 08:54:56.0145 4308 flpydisk - ok 08:54:56.0239 4308 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys 08:54:56.0254 4308 FltMgr - ok 08:54:56.0395 4308 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll 08:54:56.0410 4308 FontCache - ok 08:54:56.0535 4308 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 08:54:56.0535 4308 FontCache3.0.0.0 - ok 08:54:56.0613 4308 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 08:54:56.0613 4308 FsDepends - ok 08:54:56.0707 4308 fssfltr (dc0dce4ec2c5d2cf6472f9fd6aa9a7dc) C:\Windows\system32\DRIVERS\fssfltr.sys 08:54:56.0707 4308 fssfltr - ok 08:54:56.0878 4308 fsssvc (40cdfad174b3d5e80f95dda003c0b97f) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe 08:54:56.0894 4308 fsssvc - ok 08:54:57.0003 4308 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 08:54:57.0003 4308 Fs_Rec - ok 08:54:57.0175 4308 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys 08:54:57.0175 4308 fvevol - ok 08:54:57.0268 4308 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys 08:54:57.0284 4308 gagp30kx - ok 08:54:57.0393 4308 GamesAppService (c403c5db49a0f9aaf4f2128edc0106d8) C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe 08:54:57.0393 4308 GamesAppService - ok 08:54:57.0534 4308 ggflt (a4198f2bd8aa592cb90476277a81b5e1) C:\Windows\system32\DRIVERS\ggflt.sys 08:54:57.0534 4308 ggflt - ok 08:54:57.0612 4308 ggsemc (d266350bdaab9eb6c1aec370eeaaff3a) C:\Windows\system32\DRIVERS\ggsemc.sys 08:54:57.0612 4308 ggsemc - ok 08:54:57.0721 4308 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll 08:54:57.0736 4308 gpsvc - ok 08:54:57.0846 4308 GREGService (0191dee9b9eb7902af2cf4f67301095d) C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe 08:54:57.0846 4308 GREGService - ok 08:54:57.0924 4308 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 08:54:57.0924 4308 gupdate - ok 08:54:57.0955 4308 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 08:54:57.0955 4308 gupdatem - ok 08:54:58.0048 4308 gusvc (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe 08:54:58.0064 4308 gusvc - ok 08:54:58.0142 4308 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 08:54:58.0142 4308 hcw85cir - ok 08:54:58.0236 4308 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys 08:54:58.0236 4308 HdAudAddService - ok 08:54:58.0329 4308 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys 08:54:58.0345 4308 HDAudBus - ok 08:54:58.0454 4308 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys 08:54:58.0454 4308 HidBatt - ok 08:54:58.0548 4308 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys 08:54:58.0548 4308 HidBth - ok 08:54:58.0641 4308 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys 08:54:58.0641 4308 HidIr - ok 08:54:58.0750 4308 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll 08:54:58.0766 4308 hidserv - ok 08:54:58.0875 4308 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys 08:54:58.0875 4308 HidUsb - ok 08:54:58.0953 4308 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll 08:54:58.0953 4308 hkmsvc - ok 08:54:59.0062 4308 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll 08:54:59.0078 4308 HomeGroupListener - ok 08:54:59.0109 4308 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll 08:54:59.0109 4308 HomeGroupProvider - ok 08:54:59.0203 4308 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys 08:54:59.0203 4308 HpSAMD - ok 08:54:59.0328 4308 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys 08:54:59.0343 4308 HTTP - ok 08:54:59.0452 4308 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys 08:54:59.0452 4308 hwpolicy - ok 08:54:59.0484 4308 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys 08:54:59.0499 4308 i8042prt - ok 08:54:59.0577 4308 iaStor (f7ce9be72edac499b713eca6dae5d26f) C:\Windows\system32\DRIVERS\iaStor.sys 08:54:59.0593 4308 iaStor - ok 08:54:59.0671 4308 IAStorDataMgrSvc (b25f192ea1f84a316eb7c19efcccf33d) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe 08:54:59.0671 4308 IAStorDataMgrSvc - ok 08:54:59.0796 4308 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys 08:54:59.0811 4308 iaStorV - ok 08:54:59.0920 4308 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 08:54:59.0952 4308 idsvc - ok 08:55:00.0279 4308 igfx (553228e67639f52c9bd86362c0c64f85) C:\Windows\system32\DRIVERS\igdkmd64.sys 08:55:00.0498 4308 igfx - ok 08:55:00.0576 4308 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys 08:55:00.0576 4308 iirsp - ok 08:55:00.0700 4308 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll 08:55:00.0716 4308 IKEEXT - ok 08:55:00.0903 4308 IntcAzAudAddService (dd1fc331286a33f396945115ae4e5e8a) C:\Windows\system32\drivers\RTKVHD64.sys 08:55:00.0934 4308 IntcAzAudAddService - ok 08:55:01.0044 4308 IntcDAud (fc727061c0f47c8059e88e05d5c8e381) C:\Windows\system32\DRIVERS\IntcDAud.sys 08:55:01.0044 4308 IntcDAud - ok 08:55:01.0122 4308 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys 08:55:01.0122 4308 intelide - ok 08:55:01.0246 4308 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 08:55:01.0246 4308 intelppm - ok 08:55:01.0356 4308 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll 08:55:01.0371 4308 IPBusEnum - ok 08:55:01.0418 4308 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys 08:55:01.0418 4308 IpFilterDriver - ok 08:55:01.0496 4308 iphlpsvc (a34a587fffd45fa649fba6d03784d257) C:\Windows\System32\iphlpsvc.dll 08:55:01.0512 4308 iphlpsvc - ok 08:55:01.0558 4308 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys 08:55:01.0558 4308 IPMIDRV - ok 08:55:01.0652 4308 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 08:55:01.0652 4308 IPNAT - ok 08:55:01.0730 4308 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 08:55:01.0730 4308 IRENUM - ok 08:55:01.0824 4308 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys 08:55:01.0824 4308 isapnp - ok 08:55:01.0902 4308 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys 08:55:01.0917 4308 iScsiPrt - ok 08:55:02.0042 4308 k57nd60a (81458a917f8cc7a5171759218d64fa3a) C:\Windows\system32\DRIVERS\k57nd60a.sys 08:55:02.0042 4308 k57nd60a - ok 08:55:02.0151 4308 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys 08:55:02.0167 4308 kbdclass - ok 08:55:02.0245 4308 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys 08:55:02.0245 4308 kbdhid - ok 08:55:02.0276 4308 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 08:55:02.0292 4308 KeyIso - ok 08:55:02.0370 4308 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys 08:55:02.0370 4308 KSecDD - ok 08:55:02.0463 4308 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys 08:55:02.0463 4308 KSecPkg - ok 08:55:02.0572 4308 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 08:55:02.0588 4308 ksthunk - ok 08:55:02.0666 4308 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll 08:55:02.0682 4308 KtmRm - ok 08:55:02.0775 4308 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\system32\srvsvc.dll 08:55:02.0791 4308 LanmanServer - ok 08:55:02.0838 4308 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll 08:55:02.0853 4308 LanmanWorkstation - ok 08:55:02.0962 4308 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 08:55:02.0962 4308 lltdio - ok 08:55:03.0040 4308 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll 08:55:03.0056 4308 lltdsvc - ok 08:55:03.0087 4308 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll 08:55:03.0087 4308 lmhosts - ok 08:55:03.0228 4308 LMS (d7e0bed3ea21d7bddd410ade51708d90) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe 08:55:03.0228 4308 LMS - ok 08:55:03.0321 4308 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys 08:55:03.0337 4308 LSI_FC - ok 08:55:03.0430 4308 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys 08:55:03.0446 4308 LSI_SAS - ok 08:55:03.0524 4308 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys 08:55:03.0524 4308 LSI_SAS2 - ok 08:55:03.0602 4308 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys 08:55:03.0618 4308 LSI_SCSI - ok 08:55:03.0727 4308 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 08:55:03.0727 4308 luafv - ok 08:55:03.0805 4308 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll 08:55:03.0820 4308 Mcx2Svc - ok 08:55:03.0930 4308 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys 08:55:03.0930 4308 megasas - ok 08:55:04.0023 4308 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys 08:55:04.0023 4308 MegaSR - ok 08:55:04.0117 4308 MEIx64 (a6518dcc42f7a6e999bb3bea8fd87567) C:\Windows\system32\DRIVERS\HECIx64.sys 08:55:04.0117 4308 MEIx64 - ok 08:55:04.0226 4308 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll 08:55:04.0226 4308 MMCSS - ok 08:55:04.0273 4308 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 08:55:04.0273 4308 Modem - ok 08:55:04.0351 4308 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 08:55:04.0351 4308 monitor - ok 08:55:04.0460 4308 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys 08:55:04.0460 4308 mouclass - ok 08:55:04.0554 4308 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 08:55:04.0554 4308 mouhid - ok 08:55:04.0632 4308 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys 08:55:04.0632 4308 mountmgr - ok 08:55:04.0663 4308 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys 08:55:04.0663 4308 mpio - ok 08:55:04.0756 4308 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 08:55:04.0756 4308 mpsdrv - ok 08:55:04.0850 4308 MpsSvc (54ffc9c8898113ace189d4aa7199d2c1) C:\Windows\system32\mpssvc.dll 08:55:04.0866 4308 MpsSvc - ok 08:55:04.0912 4308 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys 08:55:04.0912 4308 MRxDAV - ok 08:55:05.0022 4308 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys 08:55:05.0022 4308 mrxsmb - ok 08:55:05.0100 4308 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys 08:55:05.0100 4308 mrxsmb10 - ok 08:55:05.0193 4308 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 08:55:05.0193 4308 mrxsmb20 - ok 08:55:05.0334 4308 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys 08:55:05.0334 4308 msahci - ok 08:55:05.0412 4308 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys 08:55:05.0427 4308 msdsm - ok 08:55:05.0505 4308 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe 08:55:05.0505 4308 MSDTC - ok 08:55:05.0630 4308 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 08:55:05.0646 4308 Msfs - ok 08:55:05.0724 4308 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 08:55:05.0724 4308 mshidkmdf - ok 08:55:05.0833 4308 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys 08:55:05.0833 4308 msisadrv - ok 08:55:05.0911 4308 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll 08:55:05.0911 4308 MSiSCSI - ok 08:55:05.0926 4308 msiserver - ok 08:55:05.0973 4308 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 08:55:05.0973 4308 MSKSSRV - ok 08:55:06.0051 4308 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 08:55:06.0051 4308 MSPCLOCK - ok 08:55:06.0129 4308 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 08:55:06.0129 4308 MSPQM - ok 08:55:06.0223 4308 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys 08:55:06.0223 4308 MsRPC - ok 08:55:06.0332 4308 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys 08:55:06.0332 4308 mssmbios - ok 08:55:06.0410 4308 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 08:55:06.0410 4308 MSTEE - ok 08:55:06.0504 4308 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys 08:55:06.0504 4308 MTConfig - ok 08:55:06.0582 4308 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 08:55:06.0582 4308 Mup - ok 08:55:06.0675 4308 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll 08:55:06.0706 4308 napagent - ok 08:55:06.0784 4308 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 08:55:06.0784 4308 NativeWifiP - ok 08:55:06.0909 4308 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys 08:55:06.0925 4308 NDIS - ok 08:55:07.0003 4308 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 08:55:07.0018 4308 NdisCap - ok 08:55:07.0096 4308 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 08:55:07.0096 4308 NdisTapi - ok 08:55:07.0221 4308 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys 08:55:07.0221 4308 Ndisuio - ok 08:55:07.0315 4308 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys 08:55:07.0315 4308 NdisWan - ok 08:55:07.0440 4308 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys 08:55:07.0440 4308 NDProxy - ok 08:55:07.0627 4308 Nero BackItUp Scheduler 4.0 (7d2633295eb6ff2b938185874884059d) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe 08:55:07.0642 4308 Nero BackItUp Scheduler 4.0 - ok 08:55:07.0767 4308 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 08:55:07.0767 4308 NetBIOS - ok 08:55:07.0861 4308 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys 08:55:07.0876 4308 NetBT - ok 08:55:07.0939 4308 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 08:55:07.0954 4308 Netlogon - ok 08:55:08.0001 4308 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll 08:55:08.0017 4308 Netman - ok 08:55:08.0126 4308 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll 08:55:08.0142 4308 netprofm - ok 08:55:08.0235 4308 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 08:55:08.0251 4308 NetTcpPortSharing - ok 08:55:08.0360 4308 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys 08:55:08.0360 4308 nfrd960 - ok 08:55:08.0485 4308 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll 08:55:08.0500 4308 NlaSvc - ok 08:55:08.0578 4308 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 08:55:08.0578 4308 Npfs - ok 08:55:08.0703 4308 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll 08:55:08.0703 4308 nsi - ok 08:55:08.0828 4308 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 08:55:08.0828 4308 nsiproxy - ok 08:55:08.0937 4308 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys 08:55:08.0968 4308 Ntfs - ok 08:55:09.0078 4308 NTI IScheduleSvc (d27a4546417ed7c4aea7b3420d4f1f50) C:\Program Files (x86)\NTI\Packard Bell MyBackup\IScheduleSvc.exe 08:55:09.0078 4308 NTI IScheduleSvc - ok 08:55:09.0202 4308 NTIDrvr (64ddd0dee976302f4bd93e5efcc2f013) C:\Windows\system32\drivers\NTIDrvr.sys 08:55:09.0202 4308 NTIDrvr - ok 08:55:09.0296 4308 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 08:55:09.0296 4308 Null - ok 08:55:09.0374 4308 nusb3hub (786db821bfd57c0551dbbe4f75384a7d) C:\Windows\system32\DRIVERS\nusb3hub.sys 08:55:09.0374 4308 nusb3hub - ok 08:55:09.0452 4308 nusb3xhc (daa8005caf745042bb427a1ed7433354) C:\Windows\system32\DRIVERS\nusb3xhc.sys 08:55:09.0468 4308 nusb3xhc - ok 08:55:09.0795 4308 nvlddmkm (3f3b01e39736e2e9e044b169aaefb485) C:\Windows\system32\DRIVERS\nvlddmkm.sys 08:55:10.0029 4308 nvlddmkm - ok 08:55:10.0138 4308 nvpciflt (714b50444d72e26739ed624f848ff36b) C:\Windows\system32\DRIVERS\nvpciflt.sys 08:55:10.0154 4308 nvpciflt - ok 08:55:10.0232 4308 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys 08:55:10.0232 4308 nvraid - ok 08:55:10.0326 4308 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys 08:55:10.0341 4308 nvstor - ok 08:55:10.0435 4308 NVSvc (a15cc332556c231c492e941bc476c5ae) C:\Windows\system32\nvvsvc.exe 08:55:10.0450 4308 NVSvc - ok 08:55:10.0575 4308 nvUpdatusService (d908d6da3c2eb864cd6dba0a52fa4de5) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe 08:55:10.0606 4308 nvUpdatusService - ok 08:55:10.0700 4308 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys 08:55:10.0700 4308 nv_agp - ok 08:55:10.0794 4308 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys 08:55:10.0794 4308 ohci1394 - ok 08:55:10.0903 4308 ose (9d10f99a6712e28f8acd5641e3a7ea6b) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 08:55:10.0903 4308 ose - ok 08:55:11.0106 4308 osppsvc (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 08:55:11.0215 4308 osppsvc - ok 08:55:11.0324 4308 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll 08:55:11.0340 4308 p2pimsvc - ok 08:55:11.0433 4308 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll 08:55:11.0433 4308 p2psvc - ok 08:55:11.0542 4308 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys 08:55:11.0542 4308 Parport - ok 08:55:11.0636 4308 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys 08:55:11.0636 4308 partmgr - ok 08:55:11.0714 4308 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll 08:55:11.0730 4308 PcaSvc - ok 08:55:11.0808 4308 pccsmcfd - ok 08:55:11.0886 4308 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys 08:55:11.0886 4308 pci - ok 08:55:12.0010 4308 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys 08:55:12.0010 4308 pciide - ok 08:55:12.0088 4308 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys 08:55:12.0104 4308 pcmcia - ok 08:55:12.0213 4308 PCTCore (8f38fffa9e7b9d547b7921efa8edff3c) C:\Windows\system32\drivers\PCTCore64.sys 08:55:12.0229 4308 PCTCore - ok 08:55:12.0338 4308 pctDS (ff43e3b1687e4e2140de6349ea5c7372) C:\Windows\system32\drivers\pctDS64.sys 08:55:12.0354 4308 pctDS - ok 08:55:12.0478 4308 pctEFA (60e9a05852af7e9cb11237c00aee4ccf) C:\Windows\system32\drivers\pctEFA64.sys 08:55:12.0494 4308 pctEFA - ok 08:55:12.0572 4308 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 08:55:12.0572 4308 pcw - ok 08:55:12.0666 4308 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 08:55:12.0681 4308 PEAUTH - ok 08:55:12.0775 4308 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe 08:55:12.0790 4308 PerfHost - ok 08:55:12.0884 4308 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll 08:55:12.0915 4308 pla - ok 08:55:12.0993 4308 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll 08:55:13.0009 4308 PlugPlay - ok 08:55:13.0071 4308 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll 08:55:13.0087 4308 PNRPAutoReg - ok 08:55:13.0212 4308 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll 08:55:13.0212 4308 PNRPsvc - ok 08:55:13.0305 4308 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll 08:55:13.0321 4308 PolicyAgent - ok 08:55:13.0414 4308 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll 08:55:13.0430 4308 Power - ok 08:55:13.0477 4308 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys 08:55:13.0492 4308 PptpMiniport - ok 08:55:13.0570 4308 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys 08:55:13.0570 4308 Processor - ok 08:55:13.0680 4308 ProfSvc (5c78838b4d166d1a27db3a8a820c799a) C:\Windows\system32\profsvc.dll 08:55:13.0695 4308 ProfSvc - ok 08:55:13.0742 4308 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 08:55:13.0742 4308 ProtectedStorage - ok 08:55:13.0867 4308 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys 08:55:13.0867 4308 Psched - ok 08:55:13.0960 4308 PxHlpa64 (fbf4db6d53585437e41a113300002a2b) C:\Windows\system32\Drivers\PxHlpa64.sys 08:55:13.0960 4308 PxHlpa64 - ok 08:55:14.0101 4308 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys 08:55:14.0132 4308 ql2300 - ok 08:55:14.0210 4308 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys 08:55:14.0226 4308 ql40xx - ok 08:55:14.0335 4308 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll 08:55:14.0350 4308 QWAVE - ok 08:55:14.0397 4308 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 08:55:14.0397 4308 QWAVEdrv - ok 08:55:14.0491 4308 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 08:55:14.0491 4308 RasAcd - ok 08:55:14.0569 4308 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 08:55:14.0569 4308 RasAgileVpn - ok 08:55:14.0678 4308 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll 08:55:14.0694 4308 RasAuto - ok 08:55:14.0756 4308 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys 08:55:14.0756 4308 Rasl2tp - ok 08:55:14.0850 4308 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll 08:55:14.0865 4308 RasMan - ok 08:55:14.0912 4308 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 08:55:14.0928 4308 RasPppoe - ok 08:55:15.0006 4308 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 08:55:15.0006 4308 RasSstp - ok 08:55:15.0084 4308 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys 08:55:15.0099 4308 rdbss - ok 08:55:15.0130 4308 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys 08:55:15.0146 4308 rdpbus - ok 08:55:15.0240 4308 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 08:55:15.0255 4308 RDPCDD - ok 08:55:15.0333 4308 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 08:55:15.0333 4308 RDPENCDD - ok 08:55:15.0427 4308 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 08:55:15.0427 4308 RDPREFMP - ok 08:55:15.0505 4308 RDPWD (6d76e6433574b058adcb0c50df834492) C:\Windows\system32\drivers\RDPWD.sys 08:55:15.0520 4308 RDPWD - ok 08:55:15.0630 4308 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys 08:55:15.0645 4308 rdyboost - ok 08:55:15.0723 4308 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll 08:55:15.0723 4308 RemoteAccess - ok 08:55:15.0754 4308 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll 08:55:15.0770 4308 RemoteRegistry - ok 08:55:15.0879 4308 Revoflt (9c3ac71a9934b884fac567a8807e9c4d) C:\Windows\system32\DRIVERS\revoflt.sys 08:55:15.0879 4308 Revoflt - ok 08:55:16.0004 4308 RFCOMM (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys 08:55:16.0004 4308 RFCOMM - ok 08:55:16.0082 4308 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll 08:55:16.0098 4308 RpcEptMapper - ok 08:55:16.0113 4308 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe 08:55:16.0129 4308 RpcLocator - ok 08:55:16.0222 4308 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll 08:55:16.0238 4308 RpcSs - ok 08:55:16.0316 4308 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 08:55:16.0316 4308 rspndr - ok 08:55:16.0394 4308 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 08:55:16.0394 4308 SamSs - ok 08:55:16.0503 4308 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys 08:55:16.0503 4308 sbp2port - ok 08:55:16.0644 4308 SBSDWSCService (794d4b48dfb6e999537c7c3947863463) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe 08:55:16.0659 4308 SBSDWSCService - ok 08:55:16.0753 4308 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll 08:55:16.0768 4308 SCardSvr - ok 08:55:16.0800 4308 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys 08:55:16.0815 4308 scfilter - ok 08:55:16.0909 4308 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll 08:55:16.0924 4308 Schedule - ok 08:55:17.0002 4308 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll 08:55:17.0002 4308 SCPolicySvc - ok 08:55:17.0049 4308 sdbus (111e0ebc0ad79cb0fa014b907b231cf0) C:\Windows\system32\drivers\sdbus.sys 08:55:17.0049 4308 sdbus - ok 08:55:17.0127 4308 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll 08:55:17.0143 4308 SDRSVC - ok 08:55:17.0252 4308 SeaPort (78779ee07231c658b483b1f38b5088df) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE 08:55:17.0252 4308 SeaPort - ok 08:55:17.0330 4308 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 08:55:17.0330 4308 secdrv - ok 08:55:17.0424 4308 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll 08:55:17.0424 4308 seclogon - ok 08:55:17.0470 4308 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll 08:55:17.0470 4308 SENS - ok 08:55:17.0533 4308 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll 08:55:17.0548 4308 SensrSvc - ok 08:55:17.0595 4308 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys 08:55:17.0595 4308 Serenum - ok 08:55:17.0673 4308 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys 08:55:17.0689 4308 Serial - ok 08:55:17.0767 4308 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys 08:55:17.0767 4308 sermouse - ok 08:55:17.0892 4308 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll 08:55:17.0907 4308 SessionEnv - ok 08:55:17.0985 4308 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys 08:55:17.0985 4308 sffdisk - ok 08:55:18.0063 4308 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys 08:55:18.0063 4308 sffp_mmc - ok 08:55:18.0141 4308 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys 08:55:18.0141 4308 sffp_sd - ok 08:55:18.0235 4308 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys 08:55:18.0235 4308 sfloppy - ok 08:55:18.0360 4308 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll 08:55:18.0375 4308 SharedAccess - ok 08:55:18.0484 4308 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll 08:55:18.0500 4308 ShellHWDetection - ok 08:55:18.0578 4308 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys 08:55:18.0594 4308 SiSRaid2 - ok 08:55:18.0594 4308 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys 08:55:18.0594 4308 SiSRaid4 - ok 08:55:18.0672 4308 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 08:55:18.0687 4308 Smb - ok 08:55:18.0781 4308 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe 08:55:18.0796 4308 SNMPTRAP - ok 08:55:18.0921 4308 Sony Ericsson PCCompanion (1a623f2b69e1f182f995f963c55db935) C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe 08:55:18.0921 4308 Sony Ericsson PCCompanion - ok 08:55:19.0015 4308 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 08:55:19.0015 4308 spldr - ok 08:55:19.0108 4308 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe 08:55:19.0124 4308 Spooler - ok 08:55:19.0296 4308 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe 08:55:19.0311 4308 sppsvc - ok 08:55:19.0405 4308 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll 08:55:19.0420 4308 sppuinotify - ok 08:55:19.0467 4308 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys 08:55:19.0483 4308 srv - ok 08:55:19.0592 4308 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys 08:55:19.0608 4308 srv2 - ok 08:55:19.0686 4308 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys 08:55:19.0686 4308 srvnet - ok 08:55:19.0779 4308 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll 08:55:19.0795 4308 SSDPSRV - ok 08:55:19.0810 4308 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll 08:55:19.0810 4308 SstpSvc - ok 08:55:19.0888 4308 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys 08:55:19.0904 4308 stexstor - ok 08:55:20.0013 4308 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll 08:55:20.0044 4308 stisvc - ok 08:55:20.0138 4308 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys 08:55:20.0138 4308 swenum - ok 08:55:20.0216 4308 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll 08:55:20.0232 4308 swprv - ok 08:55:20.0372 4308 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll 08:55:20.0403 4308 SysMain - ok 08:55:20.0466 4308 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll 08:55:20.0481 4308 TabletInputService - ok 08:55:20.0512 4308 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll 08:55:20.0528 4308 TapiSrv - ok 08:55:20.0622 4308 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll 08:55:20.0622 4308 TBS - ok 08:55:20.0746 4308 Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys 08:55:20.0778 4308 Tcpip - ok 08:55:20.0887 4308 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys 08:55:20.0918 4308 TCPIP6 - ok 08:55:20.0996 4308 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys 08:55:20.0996 4308 tcpipreg - ok 08:55:21.0090 4308 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 08:55:21.0090 4308 TDPIPE - ok 08:55:21.0168 4308 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys 08:55:21.0183 4308 TDTCP - ok 08:55:21.0292 4308 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys 08:55:21.0292 4308 tdx - ok 08:55:21.0339 4308 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys 08:55:21.0339 4308 TermDD - ok 08:55:21.0433 4308 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll 08:55:21.0448 4308 TermService - ok 08:55:21.0480 4308 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll 08:55:21.0480 4308 Themes - ok 08:55:21.0558 4308 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll 08:55:21.0573 4308 THREADORDER - ok 08:55:21.0604 4308 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll 08:55:21.0620 4308 TrkWks - ok 08:55:21.0698 4308 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe 08:55:21.0714 4308 TrustedInstaller - ok 08:55:21.0776 4308 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys 08:55:21.0776 4308 tssecsrv - ok 08:55:21.0885 4308 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys 08:55:21.0885 4308 TsUsbFlt - ok 08:55:22.0010 4308 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys 08:55:22.0010 4308 tunnel - ok 08:55:22.0119 4308 TurboB (48743b69ea47c020a792d8649f753f44) C:\Windows\system32\DRIVERS\TurboB.sys 08:55:22.0135 4308 TurboB - ok 08:55:22.0228 4308 TurboBoost (759f59e3ea3802ff23f93dcdb6fe9171) C:\Program Files\Intel\TurboBoost\TurboBoost.exe 08:55:22.0244 4308 TurboBoost - ok 08:55:22.0322 4308 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys 08:55:22.0322 4308 uagp35 - ok 08:55:22.0416 4308 UBHelper (2e22c1fd397a5a9ffef55e9d1fc96c00) C:\Windows\system32\drivers\UBHelper.sys 08:55:22.0416 4308 UBHelper - ok 08:55:22.0509 4308 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys 08:55:22.0509 4308 udfs - ok 08:55:22.0587 4308 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe 08:55:22.0603 4308 UI0Detect - ok 08:55:22.0650 4308 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys 08:55:22.0650 4308 uliagpkx - ok 08:55:22.0774 4308 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys 08:55:22.0774 4308 umbus - ok 08:55:22.0852 4308 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys 08:55:22.0852 4308 UmPass - ok 08:55:23.0008 4308 UNS (a678e5ddd974903dd71f503bdcaca218) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe 08:55:23.0040 4308 UNS - ok 08:55:23.0133 4308 Updater Service (f9ec9acd504d823d9b9ca98a4f8d3ca2) C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe 08:55:23.0133 4308 Updater Service - ok 08:55:23.0211 4308 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll 08:55:23.0227 4308 upnphost - ok 08:55:23.0274 4308 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys 08:55:23.0289 4308 usbccgp - ok 08:55:23.0367 4308 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys 08:55:23.0367 4308 usbcir - ok 08:55:23.0461 4308 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys 08:55:23.0461 4308 usbehci - ok 08:55:23.0554 4308 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys 08:55:23.0554 4308 usbhub - ok 08:55:23.0648 4308 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys 08:55:23.0648 4308 usbohci - ok 08:55:23.0742 4308 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 08:55:23.0742 4308 usbprint - ok 08:55:23.0851 4308 usbser (4acee387fa8fd39f83564fcd2fc234f2) C:\Windows\system32\drivers\usbser.sys 08:55:23.0851 4308 usbser - ok 08:55:23.0960 4308 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS 08:55:23.0976 4308 USBSTOR - ok 08:55:24.0054 4308 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys 08:55:24.0054 4308 usbuhci - ok 08:55:24.0132 4308 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys 08:55:24.0147 4308 usbvideo - ok 08:55:24.0210 4308 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll 08:55:24.0225 4308 UxSms - ok 08:55:24.0256 4308 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 08:55:24.0272 4308 VaultSvc - ok 08:55:24.0381 4308 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys 08:55:24.0381 4308 vdrvroot - ok 08:55:24.0475 4308 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe 08:55:24.0490 4308 vds - ok 08:55:24.0568 4308 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 08:55:24.0568 4308 vga - ok 08:55:24.0600 4308 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 08:55:24.0600 4308 VgaSave - ok 08:55:24.0693 4308 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys 08:55:24.0693 4308 vhdmp - ok 08:55:24.0771 4308 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys 08:55:24.0787 4308 viaide - ok 08:55:24.0865 4308 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys 08:55:24.0865 4308 volmgr - ok 08:55:25.0005 4308 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys 08:55:25.0005 4308 volmgrx - ok 08:55:25.0130 4308 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys 08:55:25.0130 4308 volsnap - ok 08:55:25.0224 4308 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys 08:55:25.0224 4308 vsmraid - ok 08:55:25.0348 4308 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe 08:55:25.0380 4308 VSS - ok 08:55:25.0442 4308 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys 08:55:25.0458 4308 vwifibus - ok 08:55:25.0473 4308 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys 08:55:25.0489 4308 vwififlt - ok 08:55:25.0598 4308 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll 08:55:25.0614 4308 W32Time - ok 08:55:25.0676 4308 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys 08:55:25.0692 4308 WacomPen - ok 08:55:25.0723 4308 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 08:55:25.0723 4308 WANARP - ok 08:55:25.0723 4308 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 08:55:25.0738 4308 Wanarpv6 - ok 08:55:25.0879 4308 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe 08:55:25.0910 4308 WatAdminSvc - ok 08:55:26.0004 4308 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe 08:55:26.0035 4308 wbengine - ok 08:55:26.0113 4308 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll 08:55:26.0128 4308 WbioSrvc - ok 08:55:26.0222 4308 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll 08:55:26.0238 4308 wcncsvc - ok 08:55:26.0300 4308 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll 08:55:26.0316 4308 WcsPlugInService - ok 08:55:26.0409 4308 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys 08:55:26.0409 4308 Wd - ok 08:55:26.0456 4308 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 08:55:26.0472 4308 Wdf01000 - ok 08:55:26.0534 4308 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll 08:55:26.0550 4308 WdiServiceHost - ok 08:55:26.0565 4308 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll 08:55:26.0565 4308 WdiSystemHost - ok 08:55:26.0628 4308 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll 08:55:26.0643 4308 WebClient - ok 08:55:26.0721 4308 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll 08:55:26.0737 4308 Wecsvc - ok 08:55:26.0799 4308 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll 08:55:26.0815 4308 wercplsupport - ok 08:55:26.0846 4308 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll 08:55:26.0862 4308 WerSvc - ok 08:55:26.0955 4308 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 08:55:26.0971 4308 WfpLwf - ok 08:55:26.0986 4308 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 08:55:26.0986 4308 WIMMount - ok 08:55:27.0049 4308 WinDefend - ok 08:55:27.0064 4308 WinHttpAutoProxySvc - ok 08:55:27.0205 4308 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll 08:55:27.0220 4308 Winmgmt - ok 08:55:27.0345 4308 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll 08:55:27.0376 4308 WinRM - ok 08:55:27.0470 4308 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys 08:55:27.0470 4308 WinUsb - ok 08:55:27.0610 4308 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll 08:55:27.0626 4308 Wlansvc - ok 08:55:27.0720 4308 wlcrasvc (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 08:55:27.0735 4308 wlcrasvc - ok 08:55:27.0860 4308 wlidsvc (2bacd71123f42cea603f4e205e1ae337) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 08:55:27.0891 4308 wlidsvc - ok 08:55:28.0000 4308 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys 08:55:28.0000 4308 WmiAcpi - ok 08:55:28.0110 4308 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe 08:55:28.0125 4308 wmiApSrv - ok 08:55:28.0203 4308 WMPNetworkSvc - ok 08:55:28.0281 4308 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll 08:55:28.0281 4308 WPCSvc - ok 08:55:28.0328 4308 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll 08:55:28.0344 4308 WPDBusEnum - ok 08:55:28.0422 4308 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 08:55:28.0422 4308 ws2ifsl - ok 08:55:28.0453 4308 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\System32\wscsvc.dll 08:55:28.0453 4308 wscsvc - ok 08:55:28.0500 4308 WSearch - ok 08:55:28.0609 4308 wuauserv (9df12edbc698b0bc353b3ef84861e430) C:\Windows\system32\wuaueng.dll 08:55:28.0624 4308 wuauserv - ok 08:55:28.0734 4308 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys 08:55:28.0734 4308 WudfPf - ok 08:55:28.0827 4308 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys 08:55:28.0827 4308 WUDFRd - ok 08:55:28.0905 4308 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll 08:55:28.0921 4308 wudfsvc - ok 08:55:28.0952 4308 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll 08:55:28.0968 4308 WwanSvc - ok 08:55:29.0030 4308 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 08:55:29.0935 4308 \Device\Harddisk0\DR0 - ok 08:55:29.0966 4308 Boot (0x1200) (cc4e378901d072339ca2b6951a9f26e6) \Device\Harddisk0\DR0\Partition0 08:55:29.0966 4308 \Device\Harddisk0\DR0\Partition0 - ok 08:55:29.0982 4308 Boot (0x1200) (09d7b22b2bf034ccb08f29e9a3a9e451) \Device\Harddisk0\DR0\Partition1 08:55:29.0982 4308 \Device\Harddisk0\DR0\Partition1 - ok 08:55:29.0982 4308 ============================================================ 08:55:29.0997 4308 Scan finished 08:55:29.0997 4308 ============================================================ 08:55:30.0013 1608 Detected object count: 0 08:55:30.0013 1608 Actual detected object count: 0
You're welcome :)

Appreciate the feedback.

Please read through these instructions to familarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide


Download ComboFix from one of these locations:

Link 1
Link 2



* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


====================================================


Double click on combofix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
Here is the report!! ComboFix 12-04-12.01 - Patricia 12/04/2012 16:09:21.1.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.34.3082.18.3948.2110 [GMT 2:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} AV: Emsisoft Anti-Malware *Disabled/Updated* {0ADC9F7D-20C1-240F-01E2-43466EBA893A} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Emsisoft Anti-Malware *Disabled/Updated* {B1BD7E99-06FB-2B81-3B52-7834153DC387} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2012-03-12 to 2012-04-12 ))))))))))))))))))))))))))))))) . . 2012-04-12 14:16 . 2012-04-12 14:16 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2012-04-12 14:16 . 2012-04-12 14:16 ——– d—–w- c:\users\Invitado\AppData\Local\temp 2012-04-12 14:16 . 2012-04-12 14:16 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-04-12 09:55 . 2012-04-12 09:55 69000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{43422B1B-DA2A-4767-8779-683A2354DD6C}\offreg.dll 2012-04-10 11:04 . 2012-03-14 03:27 8669240 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{43422B1B-DA2A-4767-8779-683A2354DD6C}\mpengine.dll 2012-04-09 14:46 . 2012-04-09 14:46 ——– d—–w- c:\users\Patricia\AppData\Roaming\VS Revo Group 2012-04-09 14:10 . 2012-04-09 14:10 ——– d—–w- c:\users\Patricia\AppData\Local\VS Revo Group 2012-04-09 14:10 . 2009-12-30 08:21 31800 —-a-w- c:\windows\system32\drivers\revoflt.sys 2012-04-09 14:10 . 2012-04-09 14:10 ——– d—–w- c:\program files\VS Revo Group 2012-04-08 10:04 . 2010-07-16 12:53 816016 —-a-w- c:\windows\system32\drivers\pctEFA64.sys 2012-04-08 10:04 . 2010-06-29 08:35 452872 —-a-w- c:\windows\system32\drivers\pctDS64.sys 2012-04-08 10:04 . 2010-11-17 08:20 331368 —-a-w- c:\windows\system32\drivers\pctgntdi64.sys 2012-04-08 10:04 . 2010-11-17 08:20 136168 —-a-w- c:\windows\system32\drivers\pctwfpfilter64.sys 2012-04-08 10:03 . 2010-11-25 08:43 257232 —-a-w- c:\windows\system32\drivers\PCTCore64.sys 2012-04-08 10:03 . 2010-11-25 08:42 92896 —-a-w- c:\windows\system32\drivers\pctplsg64.sys 2012-04-08 10:02 . 2012-04-09 13:45 ——– d—–w- c:\program files (x86)\Common Files\PC Tools 2012-04-08 09:31 . 2012-04-08 09:31 ——– d—–w- c:\users\Patricia\AppData\Roaming\ParetoLogic 2012-04-08 09:31 . 2012-04-08 09:31 ——– d—–w- c:\users\Patricia\AppData\Roaming\DriverCure 2012-04-08 09:30 . 2012-04-08 09:45 ——– d—–w- c:\programdata\ParetoLogic 2012-04-07 17:27 . 2012-04-07 17:27 ——– d—–w- c:\programdata\{6AD8E59C-250C-4201-B5BA-56ADEF76FF46} 2012-04-05 09:58 . 2011-06-21 04:09 200976 —-a-w- c:\windows\SysWow64\drivers\tmcomm.sys 2012-04-03 14:02 . 2012-04-03 14:02 50 —-a-w- C:\user.js 2012-04-01 13:44 . 2012-04-01 13:44 ——– d—–w- c:\program files\CCleaner 2012-03-30 16:55 . 2012-03-30 16:55 ——– d—–w- c:\programdata\DivX 2012-03-30 16:50 . 2012-04-03 14:12 ——– d—–w- c:\programdata\InstallMate 2012-03-30 16:50 . 2012-03-30 16:50 ——– d—–w- c:\programdata\Premium 2012-03-30 09:11 . 2012-03-30 09:11 8738464 —-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2012-03-30 08:34 . 2012-03-30 09:11 418464 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-03-15 11:40 . 2011-11-19 15:20 5559152 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-03-15 11:40 . 2011-11-19 14:50 3968368 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-03-15 11:40 . 2011-11-19 14:50 3913584 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-03-14 10:39 . 2012-02-03 04:34 3145728 —-a-w- c:\windows\system32\win32k.sys 2012-03-14 10:39 . 2012-02-10 06:36 1544192 —-a-w- c:\windows\system32\DWrite.dll 2012-03-14 10:39 . 2012-02-10 05:38 1077248 —-a-w- c:\windows\SysWow64\DWrite.dll 2012-03-14 10:37 . 2012-02-17 06:38 1031680 —-a-w- c:\windows\system32\rdpcore.dll 2012-03-14 10:37 . 2012-02-17 05:34 826880 —-a-w- c:\windows\SysWow64\rdpcore.dll 2012-03-14 10:37 . 2012-02-17 04:58 210944 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-03-14 10:37 . 2012-02-17 04:57 23552 —-a-w- c:\windows\system32\drivers\tdtcp.sys 2012-03-14 10:37 . 2012-01-25 06:38 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-03-14 10:37 . 2012-01-25 06:33 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-03-14 10:37 . 2012-01-25 06:38 77312 —-a-w- c:\windows\system32\rdpwsx.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-03-30 09:11 . 2011-08-22 18:37 70304 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-03-07 00:15 . 2011-09-23 17:33 41184 —-a-w- c:\windows\avastSS.scr 2012-03-07 00:15 . 2011-09-23 17:33 201352 —-a-w- c:\windows\SysWow64\aswBoot.exe 2012-03-07 00:15 . 2011-09-23 17:34 258520 —-a-w- c:\windows\system32\aswBoot.exe 2012-03-07 00:04 . 2011-09-23 17:34 819032 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2012-03-07 00:04 . 2011-09-23 17:34 337240 —-a-w- c:\windows\system32\drivers\aswSP.sys 2012-03-07 00:02 . 2012-02-26 11:46 28504 —-a-w- c:\windows\system32\drivers\aswKbd.sys 2012-03-07 00:02 . 2012-02-26 11:46 53080 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2012-03-07 00:01 . 2011-09-23 17:34 59224 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2012-03-07 00:01 . 2011-09-23 17:34 69976 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-03-07 00:01 . 2011-09-23 17:34 24408 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-02-23 07:18 . 2011-09-25 20:31 279656 ——w- c:\windows\system32\MpSigStub.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-09-14 283160] "BackupManagerTray"="c:\program files (x86)\NTI\Packard Bell MyBackup\BackupManagerTray.exe" [2012-01-05 295448] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288] "LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-12-09 1025616] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-07 4241512] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] "emsisoft anti-malware"="c:\program files (x86)\emsisoft anti-malware\a2guard.exe" [2012-02-01 3357584] . c:\users\Patricia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Recorte de pantalla y Selector de OneNote 2010.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2010-12-21 227712] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Servicio de Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-10-03 136176] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 253600] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-04-01 183560] R3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [x] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [x] R3 gupdatem;Servicio de Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-10-03 136176] R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [x] R3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [2011-06-29 155344] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-10-08 150016] R3 WatAdminSvc;Servicio de tecnologías de activación de Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [x] S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [x] S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS64.sys [x] S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA64.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S1 A2DDA;A2 Direct Disk Access Support Driver;c:\program files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [2011-05-19 23208] S1 a2injectiondriver;a2injectiondriver;c:\program files (x86)\Emsisoft Anti-Malware\a2dix64.sys [2011-11-02 41728] S1 a2util;a-squared Malware-IDS utility driver;c:\program files (x86)\Emsisoft Anti-Malware\a2util64.sys [2010-05-05 14720] S1 aswKbd;aswKbd; [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 a2AntiMalware;Emsisoft Anti-Malware 6.0 - Service;c:\program files (x86)\Emsisoft Anti-Malware\a2service.exe [2012-01-22 3025112] S2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-10-09 169312] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x] S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-12-09 311376] S2 ePowerSvc;Acer ePower Service;c:\program files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [2010-12-10 868224] S2 GREGService;GREGService;c:\program files (x86)\Packard Bell\Registration\GREGsvc.exe [2010-01-08 23584] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-14 13336] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NTI\Packard Bell MyBackup\IScheduleSvc.exe [2012-01-05 256536] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2010-12-12 1997416] S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x] S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-12-22 2656280] S2 Updater Service;Updater Service;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe [2010-01-29 243232] S3 a2acc;a2acc;c:\program files (x86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [2011-11-02 63880] S3 b57xdbd;Broadcom xD Picture Bus Driver Service;c:\windows\system32\DRIVERS\b57xdbd.sys [x] S3 b57xdmp;Broadcom xD Picture vstorp client drv;c:\windows\system32\DRIVERS\b57xdmp.sys [x] S3 bScsiMSa;bScsiMSa;c:\windows\system32\DRIVERS\bScsiMSa.sys [x] S3 bScsiSDa;bScsiSDa;c:\windows\system32\DRIVERS\bScsiSDa.sys [x] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x] S3 IntcDAud;Sonido Intel® para pantallas;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x] S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x] S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] . . Contents of the 'Scheduled Tasks' folder . 2012-04-12 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 09:11] . 2012-03-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1680525943-2408236732-211231575-1001Core.job - c:\users\Patricia\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-12-05 21:52] . 2012-04-12 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1680525943-2408236732-211231575-1001UA.job - c:\users\Patricia\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-12-05 21:52] . 2012-04-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-10-03 12:35] . 2012-04-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-10-03 12:35] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-03-07 00:15 135408 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-12-23 11725928] "Acer ePower Management"="c:\program files\Packard Bell\Packard Bell Power Management\ePowerTray.exe" [2010-12-10 860040] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-12-30 167960] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-12-30 391704] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-12-30 418328] "IntelTBRunOnce"="wscript.exe" [2009-07-14 168960] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 "AppInit_DLLs"=c:\windows\System32\nvinitx.dll . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.es/ uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://packardbell.msn.com mLocal Page = c:\windows\SysWOW64\blank.htm IE: &Enviar a OneNote - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 IE: E&xportar a Microsoft Excel - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 LSP: c:\program files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Patricia\AppData\Roaming\Mozilla\Firefox\Profiles\82mg0io0.default\ . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Toolbar-Locked - (no file) Toolbar-10 - (no file) HKLM-Run-ETDCtrl - c:\program files (x86)\Elantech\ETDCtrl.exe AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\programdata\{6AD8E59C-250C-4201-B5BA-56ADEF76FF46}\bm_installer.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_228_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_228.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-04-12 16:19:23 ComboFix-quarantined-files.txt 2012-04-12 14:19 . Pre-Run: 605.552.033.792 bytes libres Post-Run: 605.434.658.816 bytes libres . - - End Of File - - 067022967224B45AB1D613F8A7C39E33
Did CF manage to remove the dll error?

Let's check for remnants.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
===================================================

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as MyEsetScan. Alternatively, look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
  • Push the Back button.
  • Select Uninstall application on close check box and push [external image: Posted Image]
===================================================

Malwarebytes' Anti-Malware
Download Malwarebytes' Anti-Malware here and save to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program. (Note to Vista users, please right-click and select Run as Administrator.)
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

On your next reply please post :
ESET log
MBAM log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Yes, I still have the dll error. When ComboFix was being installed, it didn't appear anything related to Windows Recovery Console and I think I don't have it in my computer. Can this be a problem?? So..shall I download TFC, ESET and Malwarebytes' Anti-Malware??
I scanned with ESET and MBAM and there were no threats found. But I still have the dll error. I have RevoUninstaller and when I open the section Boot management I have: Location: Registry HKCU RunOnce !SearchquDSFF with this route: C:\Windows\system32\RUNDLL32.EXE C:\Users\Patricia\AppData\Local\Temp\SRASSE~1.DLL,_SetFirefoxAssets Search Results,Search_Results,http://dts.search-results.com/sr?src=ffb&appid=361&systemid=406&sr=0&q=, I try to delete it but it is impossible…. :(
Don't worry about the Recovery Console as it applies only to Windows XP.

Run the following fix should get rid of the problem.

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O4 - HKCU..\RunOnce: [!SearchquDSFF] C:\Windows\system32\RUNDLL32.EXE C:\Users\Patricia\AppData\Local\Temp\SRASSE~1.DLL,_SetFirefoxAssets Search Results,Search_Results,http://dts.search-results.com/sr?src=ffb&appid=361&systemid=406&sr=0&q=, File not found
    
    :Commands
    [EMPTYFLASH]
    [EMPTYTEMP]
    [RESETHOSTS]
    [CLEARALLRESTOREPOINTS]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post Fix OTL log as well as a new OTL log by rerunning it after reboot without custom scans script.
===================================================

On your next reply please post :
Fresh OTL log
Fix OTL log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Impossible to delete it!!! Don't know why :S I tried it several times and it remains the same. I copy here both reports. In the first one it is said that it was worked, but in the second one the dayam !SearchquDSFF appears again!!

Fix


All processes killed
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\\!SearchquDSFF deleted successfully.
========== COMMANDS ==========

[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Invitado
->Flash cache emptied: 0 bytes

User: Patricia
->Flash cache emptied: 945 bytes

User: Public

User: UpdatusUser

Total Flash Files Cleaned = 0,00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Invitado
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Patricia
->Temp folder emptied: 1055354 bytes
->Temporary Internet Files folder emptied: 45693913 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3171467 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 49554 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 48,00 mb

C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.39.2 log created on 04132012_152056

Files\Folders moved on Reboot…
C:\Users\Patricia\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Patricia\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\XZJX7KXE\iframe[1].htm moved successfully.
C:\Users\Patricia\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\QC9M8LUB\index[3].htm moved successfully.
C:\Users\Patricia\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\QC9M8LUB\mail[2].htm moved successfully.
C:\Users\Patricia\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\QC9M8LUB\mail[5].htm moved successfully.
C:\Users\Patricia\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2REM035M\bind[1].htm moved successfully.
C:\Users\Patricia\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2REM035M\bind[3].htm moved successfully.
C:\Users\Patricia\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2REM035M\Blank[1].htm moved successfully.
C:\Users\Patricia\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2REM035M\translate_google_com[1].htm moved successfully.
C:\Users\Patricia\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.
File move failed. C:\Windows\temp\dsiwmis.log scheduled to be moved on reboot.

Registry entries deleted on Reboot…

Scan

OTL logfile created on: 13/04/2012 16:23:19 - Run 5
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\Patricia\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000c0a | Country: España | Language: ESN | Date Format: dd/MM/yyyy

3,86 Gb Total Physical Memory | 1,93 Gb Available Physical Memory | 50,11% Memory free
7,71 Gb Paging File | 5,45 Gb Available in Paging File | 70,67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 683,04 Gb Total Space | 576,74 Gb Free Space | 84,44% Space Free | Partition Type: NTFS

Computer Name: PATRICIA-PC | User Name: Patricia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Patricia\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_228_ActiveX.exe (Adobe Systems Incorporated)
PRC - C:\Archivos de programa\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Archivos de programa\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe (Emsi Software GmbH)
PRC - C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe (Emsi Software GmbH)
PRC - C:\Program Files (x86)\NTI\Packard Bell MyBackup\IScheduleSvc.exe (NTI Corporation)
PRC - C:\Program Files (x86)\NTI\Packard Bell MyBackup\BackupManagerTray.exe (NTI Corporation)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LMworker.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Archivos de programa\Packard Bell\Packard Bell Updater\UpdaterService.exe (Acer Group)
PRC - C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe (Acer Incorporated)
PRC - c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\39cf4f0f0e6adca3403df6c641a73e15\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\262285b3d0afafc5059f3fe9be69bff5\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\8177623eac8f15cf95b587625439eac7\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\a1c4a635721f85bef0ea4194b888b871\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\47b9e7f070271ff50f988f75ea68fa3e\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\9866d1f6178e1cde25642f1ac293ff8d\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e620323cacb5b6bfd93fd28d263440e4\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\faf4e8730ecbd07570111bb7c3b20565\System.ni.dll ()
MOD - C:\Program Files (x86)\NTI\Packard Bell MyBackup\sqlite3.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\ebfad289d9759034cd3a887802fadb5b\IAStorCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting.resources\2.0.0.0_es_b77a5c561934e089\System.Runtime.Remoting.resources.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_es_b77a5c561934e089\mscorlib.resources.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (avast! Firewall) – C:\Program Files\AVAST Software\Avast\afwServ.exe File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (avast! Antivirus) – C:\Archivos de programa\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (a2AntiMalware) – C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe (Emsi Software GmbH)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NTI\Packard Bell MyBackup\IScheduleSvc.exe (NTI Corporation)
SRV - (Sony Ericsson PCCompanion) – C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe (Avanquest Software)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (wlidsvc) – C:\Archivos de programa\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (ePowerSvc) – C:\Archivos de programa\Packard Bell\Packard Bell Power Management\ePowerSvc.exe (Acer Incorporated)
SRV - (DsiWMIService) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (TurboBoost) Intel® – C:\Archivos de programa\Intel\TurboBoost\TurboBoost.exe (Intel® Corporation)
SRV - (wlcrasvc) – C:\Archivos de programa\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV - (IAStorDataMgrSvc) Intel® – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Updater Service) – C:\Archivos de programa\Packard Bell\Packard Bell Updater\UpdaterService.exe (Acer Group)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (osppsvc) – C:\Archivos de programa\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV - (GREGService) – C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (AdobeActiveFileMonitor8.0) – c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswKbd) – C:\Windows\SysNative\drivers\aswKbd.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (ggsemc) – C:\Windows\SysNative\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (ggflt) – C:\Windows\SysNative\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (bScsiMSa) – C:\Windows\SysNative\drivers\bScsiMSa.sys (Broadcom Corporation)
DRV:64bit: - (nvpciflt) – C:\Windows\SysNative\drivers\nvpciflt.sys (NVIDIA Corporation)
DRV:64bit: - (bScsiSDa) – C:\Windows\SysNative\drivers\bScsiSDa.sys (Broadcom Corporation)
DRV:64bit: - (b57xdmp) – C:\Windows\SysNative\drivers\b57xdmp.sys (Broadcom Corporation)
DRV:64bit: - (b57xdbd) – C:\Windows\SysNative\drivers\b57xdbd.sys (Broadcom Corporation)
DRV:64bit: - (k57nd60a) Broadcom NetLink ™ – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (PCTCore) – C:\Windows\SysNative\drivers\PCTCore64.sys (PC Tools)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (usbser) – C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (ETD) – C:\Windows\SysNative\drivers\ETD.sys (ELAN Microelectronics Corp.)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (MEIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Sonido Intel® – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (TurboB) – C:\Windows\SysNative\drivers\TurboB.sys (Intel® Corporation)
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (pctEFA) – C:\Windows\SysNative\drivers\pctEFA64.sys (PC Tools)
DRV:64bit: - (pctDS) – C:\Windows\SysNative\drivers\pctDS64.sys (PC Tools)
DRV:64bit: - (Revoflt) – C:\Windows\SysNative\drivers\revoflt.sys (VS Revo Group)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV - (a2injectiondriver) – C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys (Emsi Software GmbH)
DRV - (a2acc) – C:\Program Files (x86)\Emsisoft Anti-Malware\a2accx64.sys (Emsi Software GmbH)
DRV - (A2DDA) – C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys (Emsi Software GmbH)
DRV - (a2util) – C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys (Emsi Software GmbH)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://packardbell.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.es/
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {E4BEADF6-17DD-4BC9-9793-B06BEE4E453B}
IE - HKCU\..\SearchScopes\{E4BEADF6-17DD-4BC9-9793-B06BEE4E453B}: "URL" = http://www.google.com/search?hl=en&q;={…1I7FDUM_esES477
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_228.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_228.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00: C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Patricia\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/03/10 20:04:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/04/05 11:54:06 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2012/04/05 11:55:22 | 000,000,000 | —D | M] (No name found) – C:\Users\Patricia\AppData\Roaming\mozilla\Extensions
[2012/04/05 11:54:06 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/03/13 06:38:06 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/03/13 07:06:36 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/03/13 08:14:58 | 000,003,996 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\drae.xml
[2012/03/13 08:14:58 | 000,001,143 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-es.xml
[2012/03/30 18:56:18 | 000,002,519 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
[2012/03/13 07:06:36 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
[2012/03/13 08:14:58 | 000,001,178 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-es.xml
[2012/03/13 08:14:58 | 000,001,102 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-es.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\18.0.1025.151\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\18.0.1025.151\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\18.0.1025.151\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Media Go Detector (Enabled) = C:\Program Files (x86)\Sony\Media Go\npmediago.dll
CHR - plugin: PlayStation®Network Downloader Check Plug-in (Enabled) = C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll
CHR - plugin: Windows Live Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Patricia\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Patricia\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: B\u00FAsqueda de Google = C:\Users\Patricia\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: avast! WebRep = C:\Users\Patricia\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1426_0\
CHR - Extension: Gmail = C:\Users\Patricia\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/04/13 16:07:38 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Archivos de programa\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Archivos de programa\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Archivos de programa\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Archivos de programa\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Archivos de programa\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Archivos de programa\Packard Bell\Packard Bell Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Archivos de programa\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NTI\Packard Bell MyBackup\BackupManagerTray.exe (NTI Corporation)
O4 - HKLM..\Run: [emsisoft anti-malware] c:\program files (x86)\emsisoft anti-malware\a2guard.exe (Emsi Software GmbH)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\RunOnce: [!SearchquDSFF] C:\Windows\system32\RUNDLL32.EXE C:\Users\Patricia\AppData\Local\Temp\SRASSE~1.DLL,_SetFirefoxAssets Search Results,Search_Results,http://dts.search-results.com/sr?src=ffb&appid;=361&systemid;=406&sr;=0&q;=, File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:64bit: - Extra Button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : &Enviar; a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Notas &vinculadas; de OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Notas &vinculadas; de OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Archivos de programa\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Archivos de programa\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000018 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{593EFE90-293B-4E32-874D-1FD5730986B5}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Archivos de programa\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (C:\Windows\System32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/04/13 15:20:56 | 000,000,000 | —D | C] – C:\_OTL
[2012/04/13 12:29:20 | 000,000,000 | —D | C] – C:\Users\Patricia\AppData\Roaming\Malwarebytes
[2012/04/13 12:29:12 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/04/13 12:27:57 | 010,063,000 | —- | C] (Malwarebytes Corporation ) – C:\Users\Patricia\Desktop\mbam-setup-1.61.0.1400.exe
[2012/04/13 10:34:23 | 000,446,464 | —- | C] (OldTimer Tools) – C:\Users\Patricia\Desktop\TFC.exe
[2012/04/12 17:44:02 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2012/04/12 17:06:49 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/04/12 16:53:11 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/04/12 16:53:11 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/04/12 16:53:05 | 002,311,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/04/12 16:53:04 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/04/12 16:53:04 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/04/12 16:53:04 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/04/12 16:53:03 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/04/12 16:53:02 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/04/12 16:53:01 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/04/12 16:53:00 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/04/12 16:53:00 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/04/12 16:51:40 | 005,559,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/04/12 16:51:39 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/04/12 16:51:38 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/04/12 16:48:49 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imagehlp.dll
[2012/04/12 16:48:49 | 000,023,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fs_rec.sys
[2012/04/12 16:48:46 | 000,220,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2012/04/12 16:06:05 | 004,460,006 | R— | C] (Swearware) – C:\Users\Patricia\Desktop\ComboFix.exe
[2012/04/12 12:01:34 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/04/12 12:01:34 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/04/12 12:01:34 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/04/12 12:01:24 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012/04/12 11:58:59 | 000,000,000 | —D | C] – C:\Qoobox
[2012/04/11 08:45:22 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\Patricia\Desktop\aswMBR.exe
[2012/04/10 18:27:31 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2012/04/09 19:01:03 | 000,593,920 | —- | C] (OldTimer Tools) – C:\Users\Patricia\Desktop\OTL.exe
[2012/04/09 16:46:32 | 000,000,000 | —D | C] – C:\Users\Patricia\AppData\Roaming\VS Revo Group
[2012/04/09 16:10:54 | 000,000,000 | —D | C] – C:\Users\Patricia\AppData\Local\VS Revo Group
[2012/04/09 16:10:50 | 000,031,800 | —- | C] (VS Revo Group) – C:\Windows\SysNative\drivers\revoflt.sys
[2012/04/09 16:10:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
[2012/04/09 16:10:45 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2012/04/08 12:04:06 | 000,816,016 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctEFA64.sys
[2012/04/08 12:04:06 | 000,452,872 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctDS64.sys
[2012/04/08 12:04:04 | 000,331,368 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctgntdi64.sys
[2012/04/08 12:04:04 | 000,136,168 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctwfpfilter64.sys
[2012/04/08 12:03:59 | 000,257,232 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\PCTCore64.sys
[2012/04/08 12:03:38 | 000,092,896 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctplsg64.sys
[2012/04/08 12:02:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\PC Tools
[2012/04/08 11:31:01 | 000,000,000 | —D | C] – C:\Users\Patricia\AppData\Roaming\ParetoLogic
[2012/04/08 11:31:01 | 000,000,000 | —D | C] – C:\Users\Patricia\AppData\Roaming\DriverCure
[2012/04/08 11:30:13 | 000,000,000 | —D | C] – C:\ProgramData\ParetoLogic
[2012/04/07 19:27:58 | 000,000,000 | —D | C] – C:\ProgramData\{6AD8E59C-250C-4201-B5BA-56ADEF76FF46}
[2012/04/05 11:58:13 | 000,200,976 | —- | C] (Trend Micro Inc.) – C:\Windows\SysWow64\drivers\tmcomm.sys
[2012/04/05 11:54:50 | 000,000,000 | —D | C] – C:\Users\Patricia\AppData\Roaming\Mozilla
[2012/04/01 15:44:29 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2012/04/01 15:24:25 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
[2012/03/31 12:09:11 | 000,000,000 | —D | C] – C:\Users\Patricia\AppData\Roaming\Google
[2012/03/30 18:55:05 | 000,000,000 | —D | C] – C:\ProgramData\DivX
[2012/03/30 18:50:16 | 000,000,000 | —D | C] – C:\ProgramData\Premium
[2012/03/30 18:50:16 | 000,000,000 | —D | C] – C:\ProgramData\InstallMate
[2012/03/30 11:11:31 | 008,738,464 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2012/03/30 10:34:55 | 000,418,464 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/03/14 23:58:55 | 000,000,000 | —D | C] – C:\Config.Msi

========== Files - Modified Within 30 Days ==========

[2012/04/13 16:16:49 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/13 16:16:49 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/13 16:11:02 | 000,000,838 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/04/13 16:09:31 | 000,001,100 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/04/13 16:09:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/04/13 16:08:59 | 3104,722,944 | -HS- | M] () – C:\hiberfil.sys
[2012/04/13 16:07:38 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\Hosts
[2012/04/13 15:46:01 | 000,001,104 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/04/13 15:32:24 | 000,004,654 | —- | M] () – C:\Users\Patricia\Documents\cc_20120413_153221.reg
[2012/04/13 13:58:04 | 000,000,940 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1680525943-2408236732-211231575-1001UA.job
[2012/04/13 12:28:45 | 010,063,000 | —- | M] (Malwarebytes Corporation ) – C:\Users\Patricia\Desktop\mbam-setup-1.61.0.1400.exe
[2012/04/13 10:34:27 | 000,446,464 | —- | M] (OldTimer Tools) – C:\Users\Patricia\Desktop\TFC.exe
[2012/04/12 22:58:02 | 000,000,918 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1680525943-2408236732-211231575-1001Core.job
[2012/04/12 16:57:19 | 001,577,788 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/04/12 16:57:19 | 000,703,840 | —- | M] () – C:\Windows\SysNative\perfh00A.dat
[2012/04/12 16:57:19 | 000,616,008 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/04/12 16:57:19 | 000,137,806 | —- | M] () – C:\Windows\SysNative\perfc00A.dat
[2012/04/12 16:57:19 | 000,106,388 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/04/12 16:53:27 | 001,940,518 | —- | M] () – C:\Windows\SysNative\drivers\Cat.DB
[2012/04/12 16:06:27 | 004,460,006 | R— | M] (Swearware) – C:\Users\Patricia\Desktop\ComboFix.exe
[2012/04/12 13:42:04 | 000,000,060 | —- | M] () – C:\Windows\wpd99.drv
[2012/04/11 09:15:09 | 000,001,986 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2012/04/11 08:45:57 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\Patricia\Desktop\aswMBR.exe
[2012/04/10 18:27:30 | 838,972,486 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/04/10 10:44:30 | 000,002,670 | —- | M] () – C:\Users\Patricia\Documents\cc_20120410_104428.reg
[2012/04/10 10:44:12 | 000,013,084 | —- | M] () – C:\Users\Patricia\Documents\cc_20120410_104408.reg
[2012/04/09 16:55:08 | 000,593,920 | —- | M] (OldTimer Tools) – C:\Users\Patricia\Desktop\OTL.exe
[2012/04/09 16:10:51 | 000,001,089 | —- | M] () – C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2012/04/09 16:06:39 | 000,001,896 | —- | M] () – C:\Users\Patricia\Documents\cc_20120409_160637.reg
[2012/04/09 16:06:22 | 000,002,764 | —- | M] () – C:\Users\Patricia\Documents\cc_20120409_160620.reg
[2012/04/09 16:06:07 | 000,002,016 | —- | M] () – C:\Users\Patricia\Documents\cc_20120409_160605.reg
[2012/04/09 16:05:44 | 000,010,338 | —- | M] () – C:\Users\Patricia\Documents\cc_20120409_160540.reg
[2012/04/09 16:05:07 | 000,170,942 | —- | M] () – C:\Users\Patricia\Documents\cc_20120409_160452.reg
[2012/04/09 15:47:40 | 000,001,853 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012/04/09 15:47:40 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2012/04/08 11:18:36 | 000,001,274 | —- | M] () – C:\Users\Patricia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recorte de pantalla y Selector de OneNote 2010.lnk
[2012/04/05 13:10:36 | 000,186,676 | —- | M] () – C:\Users\Patricia\AppData\Local\census.cache
[2012/04/05 13:10:17 | 000,103,334 | —- | M] () – C:\Users\Patricia\AppData\Local\ars.cache
[2012/04/05 11:55:30 | 000,000,036 | —- | M] () – C:\Users\Patricia\AppData\Local\housecall.guid.cache
[2012/04/03 16:02:56 | 000,000,050 | —- | M] () – C:\user.js
[2012/04/01 15:44:39 | 000,000,834 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/04/01 15:24:25 | 000,001,063 | —- | M] () – C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
[2012/03/30 16:55:14 | 000,290,933 | —- | M] () – C:\Users\Patricia\Desktop\Beca%20Doctorado%20Grant_%202012.pdf
[2012/03/30 11:11:37 | 000,418,464 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/03/30 11:11:37 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/03/30 11:11:31 | 008,738,464 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2012/03/15 17:12:44 | 000,000,510 | —- | M] () – C:\settings.ini
[2012/03/15 14:35:21 | 000,436,872 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2012/04/13 15:32:23 | 000,004,654 | —- | C] () – C:\Users\Patricia\Documents\cc_20120413_153221.reg
[2012/04/12 12:01:34 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/04/12 12:01:34 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/04/12 12:01:34 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/04/12 12:01:34 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/04/12 12:01:34 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/04/10 18:27:30 | 838,972,486 | —- | C] () – C:\Windows\MEMORY.DMP
[2012/04/10 10:44:29 | 000,002,670 | —- | C] () – C:\Users\Patricia\Documents\cc_20120410_104428.reg
[2012/04/10 10:44:10 | 000,013,084 | —- | C] () – C:\Users\Patricia\Documents\cc_20120410_104408.reg
[2012/04/09 16:10:51 | 000,001,089 | —- | C] () – C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2012/04/09 16:06:39 | 000,001,896 | —- | C] () – C:\Users\Patricia\Documents\cc_20120409_160637.reg
[2012/04/09 16:06:21 | 000,002,764 | —- | C] () – C:\Users\Patricia\Documents\cc_20120409_160620.reg
[2012/04/09 16:06:06 | 000,002,016 | —- | C] () – C:\Users\Patricia\Documents\cc_20120409_160605.reg
[2012/04/09 16:05:42 | 000,010,338 | —- | C] () – C:\Users\Patricia\Documents\cc_20120409_160540.reg
[2012/04/09 16:04:56 | 000,170,942 | —- | C] () – C:\Users\Patricia\Documents\cc_20120409_160452.reg
[2012/04/08 12:04:07 | 001,940,518 | —- | C] () – C:\Windows\SysNative\drivers\Cat.DB
[2012/04/05 13:10:36 | 000,186,676 | —- | C] () – C:\Users\Patricia\AppData\Local\census.cache
[2012/04/05 13:10:17 | 000,103,334 | —- | C] () – C:\Users\Patricia\AppData\Local\ars.cache
[2012/04/05 11:55:30 | 000,000,036 | —- | C] () – C:\Users\Patricia\AppData\Local\housecall.guid.cache
[2012/04/05 11:54:09 | 000,001,114 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/04/03 16:02:56 | 000,000,050 | —- | C] () – C:\user.js
[2012/04/01 15:44:39 | 000,000,834 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/04/01 15:24:25 | 000,001,063 | —- | C] () – C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
[2012/03/30 16:55:14 | 000,290,933 | —- | C] () – C:\Users\Patricia\Desktop\Beca%20Doctorado%20Grant_%202012.pdf
[2012/03/30 10:34:57 | 000,000,838 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/03/15 17:12:44 | 000,000,510 | —- | C] () – C:\settings.ini
[2011/10/01 16:10:15 | 000,000,496 | —- | C] () – C:\Windows\wininit.ini
[2011/10/01 12:35:16 | 000,001,466 | —- | C] () – C:\Windows\eReg.dat
[2011/08/30 13:20:24 | 000,077,824 | —- | C] () – C:\Windows\SysWow64\eautil.dll
[2011/08/29 16:43:41 | 000,000,028 | —- | C] () – C:\Windows\pdf995.ini
[2011/08/29 16:32:41 | 000,047,616 | —- | C] () – C:\Windows\SysWow64\pdf995mon64.dll
[2011/08/29 16:32:41 | 000,000,060 | —- | C] () – C:\Windows\wpd99.drv
[2011/08/22 19:01:48 | 000,000,135 | —- | C] () – C:\Windows\AutoKMS.ini
[2011/01/06 06:09:23 | 000,960,940 | —- | C] () – C:\Windows\SysWow64\igkrng600.bin
[2011/01/06 06:09:21 | 000,207,376 | —- | C] () – C:\Windows\SysWow64\igfcg600m.bin
[2011/01/06 06:09:18 | 000,145,804 | —- | C] () – C:\Windows\SysWow64\igcompkrng600.bin

========== Alternate Data Streams ==========

@Alternate Data Stream - 171 bytes -> C:\ProgramData\Temp:DFC5A2B2

< End of report >
Let's try doing it outside Windows.

For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.


On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI