This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

rootkit.boot.pihar.b won't go away [Solved]

120 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

after many issues i did a factory reset on my computer. when i went back online i found that i still had a google redirect going on so i looked into it and ended up downloading tdsskiller. upon running it, rootkit.boot.pihar.b came up and i clicked clean and was prompted to reboot. upon rebooting i ran tdsskiller again and the same rootkit.boot.pihar.b came up. any help would be greatly appreciated as i would hate to have done a factory reset for nothing. here is a copy of the tdsskiller log. i'm going to download one of the three programs from the pinned "are you infected" topic and post it after. 12:56:54.0290 4960 ============================================================ 12:56:54.0290 4960 Current date / time: 2012/04/26 12:56:54.0290 12:56:54.0290 4960 SystemInfo: 12:56:54.0290 4960 12:56:54.0290 4960 OS Version: 6.1.7600 ServicePack: 0.0 12:56:54.0290 4960 Product type: Workstation 12:56:54.0290 4960 ComputerName: JEFFREY-PC 12:56:54.0290 4960 UserName: Jeffrey 12:56:54.0290 4960 Windows directory: C:\Windows 12:56:54.0290 4960 System windows directory: C:\Windows 12:56:54.0290 4960 Running under WOW64 12:56:54.0290 4960 Processor architecture: Intel x64 12:56:54.0290 4960 Number of processors: 8 12:56:54.0290 4960 Page size: 0x1000 12:56:54.0290 4960 Boot type: Normal boot 12:56:54.0290 4960 ============================================================ 12:56:55.0803 4960 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 12:56:55.0819 4960 ============================================================ 12:56:55.0819 4960 \Device\Harddisk0\DR0: 12:56:55.0819 4960 MBR partitions: 12:56:55.0819 4960 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x1D4C000 12:56:55.0819 4960 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1D60000, BlocksNum 0x729A65B0 12:56:55.0819 4960 ============================================================ 12:56:55.0850 4960 C: <-> \Device\Harddisk0\DR0\Partition1 12:56:55.0850 4960 ============================================================ 12:56:55.0850 4960 Initialize success 12:56:55.0850 4960 ============================================================ 12:56:56.0801 4612 ============================================================ 12:56:56.0801 4612 Scan started 12:56:56.0801 4612 Mode: Manual; 12:56:56.0801 4612 ============================================================ 12:56:58.0034 4612 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys 12:56:58.0034 4612 1394ohci - ok 12:56:58.0065 4612 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys 12:56:58.0081 4612 ACPI - ok 12:56:58.0096 4612 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys 12:56:58.0096 4612 AcpiPmi - ok 12:56:58.0205 4612 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys 12:56:58.0221 4612 adp94xx - ok 12:56:58.0268 4612 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys 12:56:58.0283 4612 adpahci - ok 12:56:58.0299 4612 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys 12:56:58.0315 4612 adpu320 - ok 12:56:58.0393 4612 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll 12:56:58.0393 4612 AeLookupSvc - ok 12:56:58.0502 4612 AERTFilters (3ac22a3dfa8a050e35f0e3cd99d0cdf2) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe 12:56:58.0533 4612 AERTFilters - ok 12:56:58.0564 4612 AFD (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys 12:56:58.0580 4612 AFD - ok 12:56:58.0595 4612 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys 12:56:58.0595 4612 agp440 - ok 12:56:58.0627 4612 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe 12:56:58.0627 4612 ALG - ok 12:56:58.0627 4612 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys 12:56:58.0642 4612 aliide - ok 12:56:58.0642 4612 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys 12:56:58.0642 4612 amdide - ok 12:56:58.0642 4612 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys 12:56:58.0642 4612 AmdK8 - ok 12:56:58.0658 4612 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys 12:56:58.0658 4612 AmdPPM - ok 12:56:58.0658 4612 amdsata (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys 12:56:58.0673 4612 amdsata - ok 12:56:58.0689 4612 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys 12:56:58.0689 4612 amdsbs - ok 12:56:58.0705 4612 amdxata (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys 12:56:58.0705 4612 amdxata - ok 12:56:58.0720 4612 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys 12:56:58.0720 4612 AppID - ok 12:56:58.0751 4612 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll 12:56:58.0751 4612 AppIDSvc - ok 12:56:58.0767 4612 Appinfo (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll 12:56:58.0783 4612 Appinfo - ok 12:56:58.0783 4612 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys 12:56:58.0783 4612 arc - ok 12:56:58.0798 4612 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys 12:56:58.0814 4612 arcsas - ok 12:56:58.0829 4612 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 12:56:58.0829 4612 AsyncMac - ok 12:56:58.0845 4612 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys 12:56:58.0845 4612 atapi - ok 12:56:58.0907 4612 AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll 12:56:58.0939 4612 AudioEndpointBuilder - ok 12:56:58.0939 4612 AudioSrv (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll 12:56:58.0954 4612 AudioSrv - ok 12:56:58.0970 4612 AxInstSV (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll 12:56:58.0985 4612 AxInstSV - ok 12:56:59.0032 4612 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys 12:56:59.0048 4612 b06bdrv - ok 12:56:59.0063 4612 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 12:56:59.0079 4612 b57nd60a - ok 12:56:59.0095 4612 BCM42RLY (e001dd475a7c27ebe5a0db45c11bad71) C:\Windows\system32\drivers\BCM42RLY.sys 12:56:59.0126 4612 BCM42RLY - ok 12:56:59.0313 4612 BCM43XX (37394d3553e220fb732c21e217e1bd8b) C:\Windows\system32\DRIVERS\bcmwl664.sys 12:56:59.0360 4612 BCM43XX - ok 12:56:59.0516 4612 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll 12:56:59.0516 4612 BDESVC - ok 12:56:59.0531 4612 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 12:56:59.0547 4612 Beep - ok 12:56:59.0609 4612 BFE (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll 12:56:59.0625 4612 BFE - ok 12:56:59.0719 4612 BITS (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll 12:56:59.0734 4612 BITS - ok 12:56:59.0765 4612 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 12:56:59.0765 4612 blbdrive - ok 12:56:59.0781 4612 bowser (91ce0d3dc57dd377e690a2d324022b08) C:\Windows\system32\DRIVERS\bowser.sys 12:56:59.0797 4612 bowser - ok 12:56:59.0812 4612 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys 12:56:59.0812 4612 BrFiltLo - ok 12:56:59.0828 4612 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys 12:56:59.0828 4612 BrFiltUp - ok 12:56:59.0859 4612 Browser (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll 12:56:59.0859 4612 Browser - ok 12:56:59.0890 4612 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 12:56:59.0906 4612 Brserid - ok 12:56:59.0921 4612 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 12:56:59.0921 4612 BrSerWdm - ok 12:56:59.0921 4612 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 12:56:59.0937 4612 BrUsbMdm - ok 12:56:59.0937 4612 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 12:56:59.0937 4612 BrUsbSer - ok 12:56:59.0953 4612 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys 12:56:59.0953 4612 BTHMODEM - ok 12:56:59.0968 4612 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll 12:56:59.0968 4612 bthserv - ok 12:56:59.0984 4612 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 12:56:59.0984 4612 cdfs - ok 12:57:00.0015 4612 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys 12:57:00.0015 4612 cdrom - ok 12:57:00.0046 4612 CertPropSvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll 12:57:00.0046 4612 CertPropSvc - ok 12:57:00.0093 4612 cfwids (274ce03459896006f7a5069266e0469e) C:\Windows\system32\drivers\cfwids.sys 12:57:00.0124 4612 cfwids - ok 12:57:00.0140 4612 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys 12:57:00.0140 4612 circlass - ok 12:57:00.0171 4612 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 12:57:00.0171 4612 CLFS - ok 12:57:00.0218 4612 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 12:57:00.0233 4612 clr_optimization_v2.0.50727_32 - ok 12:57:00.0265 4612 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 12:57:00.0265 4612 clr_optimization_v2.0.50727_64 - ok 12:57:00.0280 4612 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 12:57:00.0280 4612 CmBatt - ok 12:57:00.0280 4612 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys 12:57:00.0296 4612 cmdide - ok 12:57:00.0327 4612 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys 12:57:00.0327 4612 CNG - ok 12:57:00.0343 4612 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys 12:57:00.0343 4612 Compbatt - ok 12:57:00.0358 4612 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys 12:57:00.0358 4612 CompositeBus - ok 12:57:00.0358 4612 COMSysApp - ok 12:57:00.0374 4612 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys 12:57:00.0374 4612 crcdisk - ok 12:57:00.0421 4612 CryptSvc (8c57411b66282c01533cb776f98ad384) C:\Windows\system32\cryptsvc.dll 12:57:00.0421 4612 CryptSvc - ok 12:57:00.0483 4612 DcomLaunch (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll 12:57:00.0499 4612 DcomLaunch - ok 12:57:00.0530 4612 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll 12:57:00.0545 4612 defragsvc - ok 12:57:00.0561 4612 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys 12:57:00.0561 4612 DfsC - ok 12:57:00.0592 4612 Dhcp (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll 12:57:00.0608 4612 Dhcp - ok 12:57:00.0608 4612 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 12:57:00.0608 4612 discache - ok 12:57:00.0623 4612 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys 12:57:00.0623 4612 Disk - ok 12:57:00.0655 4612 Dnscache (676108c4e3aa6f6b34633748bd0bebd9) C:\Windows\System32\dnsrslvr.dll 12:57:00.0655 4612 Dnscache - ok 12:57:00.0748 4612 DockLoginService (0840abbbdf438691ee65a20040635cbe) C:\Program Files\Dell\DellDock\DockLogin.exe 12:57:00.0811 4612 DockLoginService - ok 12:57:00.0826 4612 dot3svc (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll 12:57:00.0842 4612 dot3svc - ok 12:57:00.0857 4612 DPS (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll 12:57:00.0857 4612 DPS - ok 12:57:00.0873 4612 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 12:57:00.0873 4612 drmkaud - ok 12:57:00.0967 4612 DXGKrnl (7cb7d2b73813ce05c7bc0f5f95d27cec) C:\Windows\System32\drivers\dxgkrnl.sys 12:57:00.0998 4612 DXGKrnl - ok 12:57:01.0013 4612 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll 12:57:01.0029 4612 EapHost - ok 12:57:01.0247 4612 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys 12:57:01.0294 4612 ebdrv - ok 12:57:01.0403 4612 EFS (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\System32\lsass.exe 12:57:01.0419 4612 EFS - ok 12:57:01.0513 4612 ehRecvr (b91d81b3b54a54ccafc03733dbc2e29e) C:\Windows\ehome\ehRecvr.exe 12:57:01.0528 4612 ehRecvr - ok 12:57:01.0559 4612 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe 12:57:01.0559 4612 ehSched - ok 12:57:01.0622 4612 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys 12:57:01.0637 4612 elxstor - ok 12:57:01.0653 4612 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys 12:57:01.0653 4612 ErrDev - ok 12:57:01.0715 4612 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll 12:57:01.0715 4612 EventSystem - ok 12:57:01.0747 4612 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 12:57:01.0762 4612 exfat - ok 12:57:01.0778 4612 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 12:57:01.0793 4612 fastfat - ok 12:57:01.0856 4612 Fax (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe 12:57:01.0871 4612 Fax - ok 12:57:01.0871 4612 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys 12:57:01.0887 4612 fdc - ok 12:57:01.0903 4612 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll 12:57:01.0918 4612 fdPHost - ok 12:57:01.0981 4612 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll 12:57:01.0981 4612 FDResPub - ok 12:57:01.0996 4612 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 12:57:01.0996 4612 FileInfo - ok 12:57:02.0012 4612 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 12:57:02.0012 4612 Filetrace - ok 12:57:02.0012 4612 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys 12:57:02.0027 4612 flpydisk - ok 12:57:02.0043 4612 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys 12:57:02.0043 4612 FltMgr - ok 12:57:02.0137 4612 FontCache (8ac4cb4ea61e41009fae9ae7b2b5da3a) C:\Windows\system32\FntCache.dll 12:57:02.0168 4612 FontCache - ok 12:57:02.0230 4612 FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 12:57:02.0246 4612 FontCache3.0.0.0 - ok 12:57:02.0277 4612 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 12:57:02.0277 4612 FsDepends - ok 12:57:02.0293 4612 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 12:57:02.0293 4612 Fs_Rec - ok 12:57:02.0308 4612 fvevol (b8b2a6e1558f8f5de5ce431c5b2c7b09) C:\Windows\system32\DRIVERS\fvevol.sys 12:57:02.0324 4612 fvevol - ok 12:57:02.0355 4612 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys 12:57:02.0355 4612 gagp30kx - ok 12:57:02.0417 4612 gpsvc (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll 12:57:02.0449 4612 gpsvc - ok 12:57:02.0464 4612 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 12:57:02.0464 4612 hcw85cir - ok 12:57:02.0495 4612 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys 12:57:02.0495 4612 HDAudBus - ok 12:57:02.0511 4612 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys 12:57:02.0511 4612 HidBatt - ok 12:57:02.0527 4612 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys 12:57:02.0527 4612 HidBth - ok 12:57:02.0527 4612 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys 12:57:02.0527 4612 HidIr - ok 12:57:02.0542 4612 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll 12:57:02.0542 4612 hidserv - ok 12:57:02.0542 4612 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys 12:57:02.0542 4612 HidUsb - ok 12:57:02.0558 4612 hkmsvc (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll 12:57:02.0573 4612 hkmsvc - ok 12:57:02.0589 4612 HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll 12:57:02.0605 4612 HomeGroupListener - ok 12:57:02.0636 4612 HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll 12:57:02.0636 4612 HomeGroupProvider - ok 12:57:02.0651 4612 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys 12:57:02.0651 4612 HpSAMD - ok 12:57:02.0698 4612 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys 12:57:02.0714 4612 HTTP - ok 12:57:02.0729 4612 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys 12:57:02.0729 4612 hwpolicy - ok 12:57:02.0745 4612 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys 12:57:02.0745 4612 i8042prt - ok 12:57:02.0807 4612 iaStor (1d004cb1da6323b1f55caef7f94b61d9) C:\Windows\system32\DRIVERS\iaStor.sys 12:57:02.0854 4612 iaStor - ok 12:57:02.0885 4612 iaStorV (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys 12:57:02.0901 4612 iaStorV - ok 12:57:03.0026 4612 idsvc (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 12:57:03.0041 4612 idsvc - ok 12:57:03.0057 4612 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys 12:57:03.0057 4612 iirsp - ok 12:57:03.0151 4612 IKEEXT (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll 12:57:03.0166 4612 IKEEXT - ok 12:57:03.0291 4612 IntcAzAudAddService (d42d651676883181400e22957a7e0b1e) C:\Windows\system32\drivers\RTKVHD64.sys 12:57:03.0338 4612 IntcAzAudAddService - ok 12:57:03.0463 4612 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys 12:57:03.0463 4612 intelide - ok 12:57:03.0494 4612 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 12:57:03.0494 4612 intelppm - ok 12:57:03.0525 4612 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll 12:57:03.0525 4612 IPBusEnum - ok 12:57:03.0541 4612 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys 12:57:03.0541 4612 IpFilterDriver - ok 12:57:03.0603 4612 iphlpsvc (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll 12:57:03.0619 4612 iphlpsvc - ok 12:57:03.0619 4612 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys 12:57:03.0634 4612 IPMIDRV - ok 12:57:03.0650 4612 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 12:57:03.0650 4612 IPNAT - ok 12:57:03.0665 4612 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 12:57:03.0665 4612 IRENUM - ok 12:57:03.0681 4612 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys 12:57:03.0681 4612 isapnp - ok 12:57:03.0712 4612 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys 12:57:03.0728 4612 iScsiPrt - ok 12:57:03.0775 4612 k57nd60a (249ee2d26cb1530f3bede0ac8b9e3099) C:\Windows\system32\DRIVERS\k57nd60a.sys 12:57:03.0837 4612 k57nd60a - ok 12:57:03.0837 4612 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys 12:57:03.0837 4612 kbdclass - ok 12:57:03.0853 4612 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys 12:57:03.0853 4612 kbdhid - ok 12:57:03.0884 4612 KeyIso (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe 12:57:03.0899 4612 KeyIso - ok 12:57:03.0899 4612 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys 12:57:03.0899 4612 KSecDD - ok 12:57:03.0915 4612 KSecPkg (bbe1bf6d9b661c354d4857d5fadb943b) C:\Windows\system32\Drivers\ksecpkg.sys 12:57:03.0915 4612 KSecPkg - ok 12:57:03.0915 4612 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 12:57:03.0915 4612 ksthunk - ok 12:57:03.0977 4612 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll 12:57:03.0993 4612 KtmRm - ok 12:57:04.0055 4612 LanmanServer (c926920b8978de6acfe9e15c709e9b57) C:\Windows\system32\srvsvc.dll 12:57:04.0055 4612 LanmanServer - ok 12:57:04.0149 4612 LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll 12:57:04.0165 4612 LanmanWorkstation - ok 12:57:04.0196 4612 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 12:57:04.0196 4612 lltdio - ok 12:57:04.0243 4612 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll 12:57:04.0258 4612 lltdsvc - ok 12:57:04.0274 4612 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll 12:57:04.0274 4612 lmhosts - ok 12:57:04.0289 4612 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys 12:57:04.0305 4612 LSI_FC - ok 12:57:04.0321 4612 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys 12:57:04.0321 4612 LSI_SAS - ok 12:57:04.0321 4612 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys 12:57:04.0336 4612 LSI_SAS2 - ok 12:57:04.0336 4612 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys 12:57:04.0352 4612 LSI_SCSI - ok 12:57:04.0383 4612 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 12:57:04.0383 4612 luafv - ok 12:57:04.0477 4612 McAfee SiteAdvisor Service (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 12:57:04.0477 4612 McAfee SiteAdvisor Service - ok 12:57:04.0477 4612 McMPFSvc (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 12:57:04.0492 4612 McMPFSvc - ok 12:57:04.0492 4612 mcmscsvc (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 12:57:04.0492 4612 mcmscsvc - ok 12:57:04.0508 4612 McNaiAnn (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 12:57:04.0508 4612 McNaiAnn - ok 12:57:04.0508 4612 McNASvc (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 12:57:04.0508 4612 McNASvc - ok 12:57:04.0570 4612 McODS (dd01bf24dd6bf70a90549f9a7bb2d1eb) C:\Program Files\McAfee\VirusScan\mcods.exe 12:57:04.0617 4612 McODS - ok 12:57:04.0617 4612 McProxy (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 12:57:04.0617 4612 McProxy - ok 12:57:04.0664 4612 McShield (e998e3b12101288d716558466cbf6ae1) C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe 12:57:04.0711 4612 McShield - ok 12:57:04.0726 4612 Mcx2Svc (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll 12:57:04.0726 4612 Mcx2Svc - ok 12:57:04.0742 4612 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys 12:57:04.0742 4612 megasas - ok 12:57:04.0757 4612 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys 12:57:04.0757 4612 MegaSR - ok 12:57:04.0820 4612 mfeapfk (01884cb7655c8908b43ff5e364fe6fd2) C:\Windows\system32\drivers\mfeapfk.sys 12:57:04.0851 4612 mfeapfk - ok 12:57:04.0898 4612 mfeavfk (dab9a9cdfb04e4d68924492aa043019d) C:\Windows\system32\drivers\mfeavfk.sys 12:57:04.0945 4612 mfeavfk - ok 12:57:04.0991 4612 mfeavfk01 - ok 12:57:05.0007 4612 mfefire (b26782c3d6045b4464017d7926877560) C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe 12:57:05.0069 4612 mfefire - ok 12:57:05.0101 4612 mfefirek (ce9a3680675c0907ade16404ca967b49) C:\Windows\system32\drivers\mfefirek.sys 12:57:05.0163 4612 mfefirek - ok 12:57:05.0491 4612 mfehidk (60cf67458dd29cd17e77f2327b1a9a54) C:\Windows\system32\drivers\mfehidk.sys 12:57:05.0553 4612 mfehidk - ok 12:57:05.0569 4612 mfenlfk (a8129cfb919347f8533c934b365e9202) C:\Windows\system32\DRIVERS\mfenlfk.sys 12:57:05.0600 4612 mfenlfk - ok 12:57:05.0600 4612 mferkdet (5041fa2bd2b3a2693b015771bfbf6dca) C:\Windows\system32\drivers\mferkdet.sys 12:57:05.0631 4612 mferkdet - ok 12:57:05.0662 4612 mfevtp (723a5eb6cef7f408c3d0f15a82a6bff8) C:\Windows\system32\mfevtps.exe 12:57:05.0725 4612 mfevtp - ok 12:57:05.0740 4612 mfewfpk (919c56db14a0e1e2ab6da5d2821dc26e) C:\Windows\system32\drivers\mfewfpk.sys 12:57:05.0771 4612 mfewfpk - ok 12:57:05.0803 4612 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll 12:57:05.0803 4612 MMCSS - ok 12:57:05.0834 4612 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 12:57:05.0834 4612 Modem - ok 12:57:05.0849 4612 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 12:57:05.0865 4612 monitor - ok 12:57:05.0865 4612 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys 12:57:05.0865 4612 mouclass - ok 12:57:05.0881 4612 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 12:57:05.0881 4612 mouhid - ok 12:57:05.0896 4612 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys 12:57:05.0912 4612 mountmgr - ok 12:57:05.0974 4612 MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 12:57:06.0037 4612 MozillaMaintenance - ok 12:57:06.0037 4612 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys 12:57:06.0052 4612 mpio - ok 12:57:06.0052 4612 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 12:57:06.0052 4612 mpsdrv - ok 12:57:06.0115 4612 MpsSvc (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll 12:57:06.0130 4612 MpsSvc - ok 12:57:06.0146 4612 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys 12:57:06.0161 4612 MRxDAV - ok 12:57:06.0177 4612 mrxsmb (cfdcd8ca87c2a657debc150ac35b5e08) C:\Windows\system32\DRIVERS\mrxsmb.sys 12:57:06.0177 4612 mrxsmb - ok 12:57:06.0193 4612 mrxsmb10 (1bee517b220b7f024f411aec1571dd5a) C:\Windows\system32\DRIVERS\mrxsmb10.sys 12:57:06.0208 4612 mrxsmb10 - ok 12:57:06.0208 4612 mrxsmb20 (6b2d5fef385828b6e485c1c90afb8195) C:\Windows\system32\DRIVERS\mrxsmb20.sys 12:57:06.0224 4612 mrxsmb20 - ok 12:57:06.0224 4612 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys 12:57:06.0224 4612 msahci - ok 12:57:06.0239 4612 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys 12:57:06.0239 4612 msdsm - ok 12:57:06.0271 4612 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe 12:57:06.0271 4612 MSDTC - ok 12:57:06.0271 4612 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 12:57:06.0271 4612 Msfs - ok 12:57:06.0286 4612 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 12:57:06.0286 4612 mshidkmdf - ok 12:57:06.0302 4612 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys 12:57:06.0302 4612 msisadrv - ok 12:57:06.0317 4612 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll 12:57:06.0333 4612 MSiSCSI - ok 12:57:06.0333 4612 msiserver - ok 12:57:06.0349 4612 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 12:57:06.0349 4612 MSKSSRV - ok 12:57:06.0364 4612 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 12:57:06.0364 4612 MSPCLOCK - ok 12:57:06.0364 4612 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 12:57:06.0364 4612 MSPQM - ok 12:57:06.0395 4612 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys 12:57:06.0395 4612 MsRPC - ok 12:57:06.0411 4612 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys 12:57:06.0411 4612 mssmbios - ok 12:57:06.0427 4612 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 12:57:06.0427 4612 MSTEE - ok 12:57:06.0427 4612 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys 12:57:06.0427 4612 MTConfig - ok 12:57:06.0442 4612 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 12:57:06.0442 4612 Mup - ok 12:57:06.0489 4612 napagent (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll 12:57:06.0489 4612 napagent - ok 12:57:06.0520 4612 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 12:57:06.0536 4612 NativeWifiP - ok 12:57:06.0583 4612 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys 12:57:06.0614 4612 NDIS - ok 12:57:06.0629 4612 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 12:57:06.0629 4612 NdisCap - ok 12:57:06.0629 4612 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 12:57:06.0645 4612 NdisTapi - ok 12:57:06.0645 4612 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys 12:57:06.0645 4612 Ndisuio - ok 12:57:06.0661 4612 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys 12:57:06.0661 4612 NdisWan - ok 12:57:06.0676 4612 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys 12:57:06.0676 4612 NDProxy - ok 12:57:06.0676 4612 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 12:57:06.0676 4612 NetBIOS - ok 12:57:06.0692 4612 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys 12:57:06.0707 4612 NetBT - ok 12:57:06.0723 4612 Netlogon (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe 12:57:06.0723 4612 Netlogon - ok 12:57:06.0770 4612 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll 12:57:06.0785 4612 Netman - ok 12:57:06.0817 4612 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll 12:57:06.0832 4612 netprofm - ok 12:57:06.0910 4612 netr7364 (81b8d0c1ce44a7fdbd596b693783950c) C:\Windows\system32\DRIVERS\netr7364.sys 12:57:06.0926 4612 netr7364 - ok 12:57:07.0019 4612 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 12:57:07.0019 4612 NetTcpPortSharing - ok 12:57:07.0051 4612 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys 12:57:07.0051 4612 nfrd960 - ok 12:57:07.0082 4612 NlaSvc (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll 12:57:07.0097 4612 NlaSvc - ok 12:57:07.0097 4612 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 12:57:07.0113 4612 Npfs - ok 12:57:07.0113 4612 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll 12:57:07.0113 4612 nsi - ok 12:57:07.0129 4612 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 12:57:07.0129 4612 nsiproxy - ok 12:57:07.0238 4612 Ntfs (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys 12:57:07.0269 4612 Ntfs - ok 12:57:07.0378 4612 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 12:57:07.0394 4612 Null - ok 12:57:08.0018 4612 nvlddmkm (51bd7ef17f0b525994ad5b3748c8288b) C:\Windows\system32\DRIVERS\nvlddmkm.sys 12:57:08.0080 4612 nvlddmkm - ok 12:57:08.0189 4612 nvraid (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys 12:57:08.0205 4612 nvraid - ok 12:57:08.0221 4612 nvstor (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys 12:57:08.0236 4612 nvstor - ok 12:57:08.0283 4612 nvsvc (fce8537bf5d504680212d536a3bfe5e2) C:\Windows\system32\nvvsvc.exe 12:57:08.0330 4612 nvsvc - ok 12:57:08.0361 4612 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys 12:57:08.0361 4612 nv_agp - ok 12:57:08.0361 4612 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys 12:57:08.0361 4612 ohci1394 - ok 12:57:08.0423 4612 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll 12:57:08.0423 4612 p2pimsvc - ok 12:57:08.0470 4612 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll 12:57:08.0486 4612 p2psvc - ok 12:57:08.0501 4612 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys 12:57:08.0501 4612 Parport - ok 12:57:08.0517 4612 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys 12:57:08.0533 4612 partmgr - ok 12:57:08.0548 4612 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll 12:57:08.0548 4612 PcaSvc - ok 12:57:08.0579 4612 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys 12:57:08.0595 4612 pci - ok 12:57:08.0595 4612 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys 12:57:08.0611 4612 pciide - ok 12:57:08.0626 4612 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys 12:57:08.0626 4612 pcmcia - ok 12:57:08.0642 4612 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 12:57:08.0642 4612 pcw - ok 12:57:08.0673 4612 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 12:57:08.0704 4612 PEAUTH - ok 12:57:08.0782 4612 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe 12:57:08.0798 4612 PerfHost - ok 12:57:08.0907 4612 pla (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll 12:57:08.0938 4612 pla - ok 12:57:09.0001 4612 PlugPlay (23157d583244400e1d7fbaee2e4b31b7) C:\Windows\system32\umpnpmgr.dll 12:57:09.0016 4612 PlugPlay - ok 12:57:09.0016 4612 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll 12:57:09.0063 4612 PNRPAutoReg - ok 12:57:09.0079 4612 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll 12:57:09.0079 4612 PNRPsvc - ok 12:57:09.0219 4612 PolicyAgent (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll 12:57:09.0219 4612 PolicyAgent - ok 12:57:09.0235 4612 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll 12:57:09.0235 4612 Power - ok 12:57:09.0313 4612 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys 12:57:09.0328 4612 PptpMiniport - ok 12:57:09.0359 4612 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys 12:57:09.0359 4612 Processor - ok 12:57:09.0391 4612 ProfSvc (f381975e1f4346de875cb07339ce8d3a) C:\Windows\system32\profsvc.dll 12:57:09.0406 4612 ProfSvc - ok 12:57:09.0422 4612 ProtectedStorage (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe 12:57:09.0422 4612 ProtectedStorage - ok 12:57:09.0453 4612 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys 12:57:09.0469 4612 Psched - ok 12:57:09.0469 4612 PxHlpa64 (4712cc14e720ecccc0aa16949d18aaf1) C:\Windows\system32\Drivers\PxHlpa64.sys 12:57:09.0515 4612 PxHlpa64 - ok 12:57:09.0640 4612 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys 12:57:09.0656 4612 ql2300 - ok 12:57:10.0545 4612 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys 12:57:10.0576 4612 ql40xx - ok 12:57:10.0810 4612 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll 12:57:10.0826 4612 QWAVE - ok 12:57:10.0826 4612 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 12:57:10.0841 4612 QWAVEdrv - ok 12:57:10.0841 4612 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 12:57:10.0841 4612 RasAcd - ok 12:57:10.0873 4612 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 12:57:10.0873 4612 RasAgileVpn - ok 12:57:10.0888 4612 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll 12:57:10.0904 4612 RasAuto - ok 12:57:10.0935 4612 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys 12:57:10.0935 4612 Rasl2tp - ok 12:57:10.0966 4612 RasMan (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll 12:57:10.0982 4612 RasMan - ok 12:57:10.0982 4612 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 12:57:10.0997 4612 RasPppoe - ok 12:57:10.0997 4612 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 12:57:10.0997 4612 RasSstp - ok 12:57:11.0029 4612 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys 12:57:11.0029 4612 rdbss - ok 12:57:11.0044 4612 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys 12:57:11.0044 4612 rdpbus - ok 12:57:11.0060 4612 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 12:57:11.0060 4612 RDPCDD - ok 12:57:11.0091 4612 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 12:57:11.0091 4612 RDPENCDD - ok 12:57:11.0107 4612 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 12:57:11.0107 4612 RDPREFMP - ok 12:57:11.0138 4612 RDPWD (074ac702d8b8b660b0e1371555995386) C:\Windows\system32\drivers\RDPWD.sys 12:57:11.0169 4612 RDPWD - ok 12:57:11.0185 4612 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys 12:57:11.0185 4612 rdyboost - ok 12:57:11.0216 4612 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll 12:57:11.0216 4612 RemoteAccess - ok 12:57:11.0263 4612 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll 12:57:11.0263 4612 RemoteRegistry - ok 12:57:11.0434 4612 RoxMediaDB10 (05fc44d32a144925eae45570029fd6e1) c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe 12:57:11.0497 4612 RoxMediaDB10 - ok 12:57:11.0512 4612 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll 12:57:11.0512 4612 RpcEptMapper - ok 12:57:11.0528 4612 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe 12:57:11.0528 4612 RpcLocator - ok 12:57:11.0575 4612 RpcSs (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll 12:57:11.0575 4612 RpcSs - ok 12:57:11.0606 4612 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 12:57:11.0621 4612 rspndr - ok 12:57:11.0621 4612 RxFilter - ok 12:57:11.0621 4612 SamSs (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe 12:57:11.0621 4612 SamSs - ok 12:57:11.0653 4612 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys 12:57:11.0653 4612 sbp2port - ok 12:57:11.0684 4612 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll 12:57:11.0684 4612 SCardSvr - ok 12:57:11.0699 4612 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys 12:57:11.0699 4612 scfilter - ok 12:57:11.0777 4612 Schedule (ec56b171f85c7e855e7b0588ac503eea) C:\Windows\system32\schedsvc.dll 12:57:11.0809 4612 Schedule - ok 12:57:11.0824 4612 SCPolicySvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll 12:57:11.0824 4612 SCPolicySvc - ok 12:57:11.0840 4612 SDRSVC (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll 12:57:11.0855 4612 SDRSVC - ok 12:57:11.0949 4612 SeaPort (d358e077a0a05d9b12da22d137ee8464) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 12:57:11.0965 4612 SeaPort - ok 12:57:11.0980 4612 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 12:57:11.0980 4612 secdrv - ok 12:57:12.0011 4612 seclogon (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll 12:57:12.0011 4612 seclogon - ok 12:57:12.0074 4612 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll 12:57:12.0089 4612 SENS - ok 12:57:12.0121 4612 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll 12:57:12.0121 4612 SensrSvc - ok 12:57:12.0136 4612 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys 12:57:12.0136 4612 Serenum - ok 12:57:12.0152 4612 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys 12:57:12.0152 4612 Serial - ok 12:57:12.0152 4612 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys 12:57:12.0167 4612 sermouse - ok 12:57:12.0167 4612 SessionEnv (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll 12:57:12.0183 4612 SessionEnv - ok 12:57:12.0214 4612 SessionLauncher - ok 12:57:12.0230 4612 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys 12:57:12.0230 4612 sffdisk - ok 12:57:12.0230 4612 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys 12:57:12.0245 4612 sffp_mmc - ok 12:57:12.0245 4612 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys 12:57:12.0245 4612 sffp_sd - ok 12:57:12.0261 4612 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys 12:57:12.0261 4612 sfloppy - ok 12:57:12.0308 4612 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll 12:57:12.0323 4612 SharedAccess - ok 12:57:12.0370 4612 ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll 12:57:12.0370 4612 ShellHWDetection - ok 12:57:12.0386 4612 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys 12:57:12.0401 4612 SiSRaid2 - ok 12:57:12.0401 4612 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys 12:57:12.0417 4612 SiSRaid4 - ok 12:57:12.0433 4612 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 12:57:12.0448 4612 Smb - ok 12:57:12.0479 4612 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe 12:57:12.0479 4612 SNMPTRAP - ok 12:57:12.0495 4612 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 12:57:12.0495 4612 spldr - ok 12:57:12.0589 4612 Spooler (89e8550c5862999fcf482ea562b0e98e) C:\Windows\System32\spoolsv.exe 12:57:12.0604 4612 Spooler - ok 12:57:12.0854 4612 sppsvc (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe 12:57:12.0854 4612 sppsvc - ok 12:57:12.0963 4612 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll 12:57:12.0979 4612 sppuinotify - ok 12:57:13.0072 4612 sprtsvc_DellComms (d630b6f2e8379b6f10dc16e82a426552) C:\Program Files (x86)\Dell\DellComms\bin\sprtsvc.exe 12:57:13.0150 4612 sprtsvc_DellComms - ok 12:57:13.0213 4612 srv (ec8f67289105bf270498095f14963464) C:\Windows\system32\DRIVERS\srv.sys 12:57:13.0228 4612 srv - ok 12:57:13.0259 4612 srv2 (f773d2ed090b7baa1c1a034f3ca476c8) C:\Windows\system32\DRIVERS\srv2.sys 12:57:13.0259 4612 srv2 - ok 12:57:13.0275 4612 srvnet (26e84d3649019c3244622e654dfcd75b) C:\Windows\system32\DRIVERS\srvnet.sys 12:57:13.0275 4612 srvnet - ok 12:57:13.0306 4612 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll 12:57:13.0322 4612 SSDPSRV - ok 12:57:13.0322 4612 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll 12:57:13.0322 4612 SstpSvc - ok 12:57:13.0353 4612 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys 12:57:13.0353 4612 stexstor - ok 12:57:13.0415 4612 stisvc (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll 12:57:13.0431 4612 stisvc - ok 12:57:13.0525 4612 stllssvr (ff5eb78af7dfb68c2fb363537aaf753e) c:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe 12:57:13.0587 4612 stllssvr - ok 12:57:13.0603 4612 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys 12:57:13.0603 4612 swenum - ok 12:57:13.0634 4612 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll 12:57:13.0634 4612 swprv - ok 12:57:13.0774 4612 SysMain (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll 12:57:13.0790 4612 SysMain - ok 12:57:13.0899 4612 TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll 12:57:13.0915 4612 TabletInputService - ok 12:57:13.0946 4612 TapiSrv (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll 12:57:13.0961 4612 TapiSrv - ok 12:57:13.0961 4612 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll 12:57:13.0977 4612 TBS - ok 12:57:14.0149 4612 Tcpip (912107716bab424c7870e8e6af5e07e1) C:\Windows\system32\drivers\tcpip.sys 12:57:14.0180 4612 Tcpip - ok 12:57:14.0305 4612 TCPIP6 (912107716bab424c7870e8e6af5e07e1) C:\Windows\system32\DRIVERS\tcpip.sys 12:57:14.0320 4612 TCPIP6 - ok 12:57:14.0351 4612 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys 12:57:14.0367 4612 tcpipreg - ok 12:57:14.0383 4612 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 12:57:14.0383 4612 TDPIPE - ok 12:57:14.0398 4612 TDTCP (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys 12:57:14.0461 4612 TDTCP - ok 12:57:14.0461 4612 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys 12:57:14.0461 4612 tdx - ok 12:57:14.0476 4612 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys 12:57:14.0476 4612 TermDD - ok 12:57:14.0539 4612 TermService (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll 12:57:14.0554 4612 TermService - ok 12:57:14.0570 4612 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll 12:57:14.0585 4612 Themes - ok 12:57:14.0617 4612 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll 12:57:14.0617 4612 THREADORDER - ok 12:57:14.0632 4612 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll 12:57:14.0632 4612 TrkWks - ok 12:57:14.0695 4612 TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe 12:57:14.0695 4612 TrustedInstaller - ok 12:57:14.0710 4612 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys 12:57:14.0710 4612 tssecsrv - ok 12:57:14.0726 4612 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys 12:57:14.0741 4612 tunnel - ok 12:57:14.0741 4612 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys 12:57:14.0757 4612 uagp35 - ok 12:57:14.0788 4612 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys 12:57:14.0788 4612 udfs - ok 12:57:14.0819 4612 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe 12:57:14.0835 4612 UI0Detect - ok 12:57:14.0851 4612 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys 12:57:14.0851 4612 uliagpkx - ok 12:57:14.0851 4612 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys 12:57:14.0851 4612 umbus - ok 12:57:14.0866 4612 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys 12:57:14.0866 4612 UmPass - ok 12:57:14.0897 4612 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll 12:57:14.0913 4612 upnphost - ok 12:57:14.0929 4612 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys 12:57:14.0929 4612 usbccgp - ok 12:57:14.0960 4612 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys 12:57:14.0960 4612 usbcir - ok 12:57:14.0975 4612 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys 12:57:14.0975 4612 usbehci - ok 12:57:15.0007 4612 usbhub (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys 12:57:15.0022 4612 usbhub - ok 12:57:15.0022 4612 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys 12:57:15.0038 4612 usbohci - ok 12:57:15.0038 4612 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 12:57:15.0053 4612 usbprint - ok 12:57:15.0053 4612 USBSTOR (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS 12:57:15.0053 4612 USBSTOR - ok 12:57:15.0069 4612 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys 12:57:15.0085 4612 usbuhci - ok 12:57:15.0100 4612 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll 12:57:15.0100 4612 UxSms - ok 12:57:15.0163 4612 VaultSvc (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe 12:57:15.0163 4612 VaultSvc - ok 12:57:15.0163 4612 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys 12:57:15.0178 4612 vdrvroot - ok 12:57:15.0225 4612 vds (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe 12:57:15.0241 4612 vds - ok 12:57:15.0241 4612 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 12:57:15.0256 4612 vga - ok 12:57:15.0256 4612 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 12:57:15.0256 4612 VgaSave - ok 12:57:15.0272 4612 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys 12:57:15.0272 4612 vhdmp - ok 12:57:15.0287 4612 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys 12:57:15.0287 4612 viaide - ok 12:57:15.0287 4612 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys 12:57:15.0287 4612 volmgr - ok 12:57:15.0319 4612 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys 12:57:15.0319 4612 volmgrx - ok 12:57:15.0334 4612 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys 12:57:15.0334 4612 volsnap - ok 12:57:15.0365 4612 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys 12:57:15.0381 4612 vsmraid - ok 12:57:15.0490 4612 VSS (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe 12:57:15.0521 4612 VSS - ok 12:57:15.0631 4612 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys 12:57:15.0646 4612 vwifibus - ok 12:57:15.0662 4612 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys 12:57:15.0662 4612 vwififlt - ok 12:57:15.0709 4612 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll 12:57:15.0724 4612 W32Time - ok 12:57:15.0740 4612 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys 12:57:15.0755 4612 WacomPen - ok 12:57:15.0755 4612 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 12:57:15.0755 4612 WANARP - ok 12:57:15.0771 4612 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 12:57:15.0771 4612 Wanarpv6 - ok 12:57:15.0849 4612 wbengine (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe 12:57:15.0880 4612 wbengine - ok 12:57:15.0958 4612 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll 12:57:15.0974 4612 WbioSrvc - ok 12:57:16.0005 4612 wcncsvc (8321c2ca3b62b61b293cda3451984468) C:\Windows\System32\wcncsvc.dll 12:57:16.0021 4612 wcncsvc - ok 12:57:16.0021 4612 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll 12:57:16.0036 4612 WcsPlugInService - ok 12:57:16.0036 4612 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys 12:57:16.0052 4612 Wd - ok 12:57:16.0099 4612 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 12:57:16.0114 4612 Wdf01000 - ok 12:57:16.0130 4612 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll 12:57:16.0130 4612 WdiServiceHost - ok 12:57:16.0145 4612 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll 12:57:16.0145 4612 WdiSystemHost - ok 12:57:16.0177 4612 WebClient (8a438cbb8c032a0c798b0c642ffbe572) C:\Windows\System32\webclnt.dll 12:57:16.0192 4612 WebClient - ok 12:57:16.0208 4612 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll 12:57:16.0223 4612 Wecsvc - ok 12:57:16.0223 4612 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll 12:57:16.0239 4612 wercplsupport - ok 12:57:16.0255 4612 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll 12:57:16.0255 4612 WerSvc - ok 12:57:16.0286 4612 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 12:57:16.0286 4612 WfpLwf - ok 12:57:16.0286 4612 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 12:57:16.0286 4612 WIMMount - ok 12:57:16.0333 4612 WinDefend - ok 12:57:16.0333 4612 WinHttpAutoProxySvc - ok 12:57:16.0411 4612 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll 12:57:16.0411 4612 Winmgmt - ok 12:57:16.0567 4612 WinRM (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll 12:57:16.0598 4612 WinRM - ok 12:57:16.0738 4612 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll 12:57:16.0769 4612 Wlansvc - ok 12:57:16.0847 4612 wltrysvc (13b0a570e1ae451c92da550085d72cf3) C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE 12:57:16.0894 4612 wltrysvc - ok 12:57:16.0910 4612 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys 12:57:16.0925 4612 WmiAcpi - ok 12:57:16.0988 4612 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe 12:57:17.0003 4612 wmiApSrv - ok 12:57:17.0035 4612 WMPNetworkSvc - ok 12:57:17.0050 4612 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll 12:57:17.0050 4612 WPCSvc - ok 12:57:17.0081 4612 WPDBusEnum (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll 12:57:17.0097 4612 WPDBusEnum - ok 12:57:17.0113 4612 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 12:57:17.0113 4612 ws2ifsl - ok 12:57:17.0144 4612 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\System32\wscsvc.dll 12:57:17.0144 4612 wscsvc - ok 12:57:17.0144 4612 WSearch - ok 12:57:17.0315 4612 wuauserv (38340204a2d0228f1e87740fc5e554a7) C:\Windows\system32\wuaueng.dll 12:57:17.0315 4612 wuauserv - ok 12:57:17.0409 4612 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys 12:57:17.0409 4612 WudfPf - ok 12:57:17.0425 4612 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys 12:57:17.0440 4612 WUDFRd - ok 12:57:17.0456 4612 wudfsvc (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll 12:57:17.0456 4612 wudfsvc - ok 12:57:17.0503 4612 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll 12:57:17.0518 4612 WwanSvc - ok 12:57:17.0549 4612 MBR (0x1B8) (faf3db026c90f586e5993588661e2612) \Device\Harddisk0\DR0 12:57:17.0565 4612 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - infected 12:57:17.0565 4612 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.b (0) 12:57:17.0596 4612 Boot (0x1200) (a5c682221bb3be9ca89446427c662f59) \Device\Harddisk0\DR0\Partition0 12:57:17.0596 4612 \Device\Harddisk0\DR0\Partition0 - ok 12:57:17.0612 4612 Boot (0x1200) (2173d9f00b8f5ffc95b7fde2a9e0227f) \Device\Harddisk0\DR0\Partition1 12:57:17.0612 4612 \Device\Harddisk0\DR0\Partition1 - ok 12:57:17.0612 4612 ============================================================ 12:57:17.0612 4612 Scan finished 12:57:17.0612 4612 ============================================================ 12:57:17.0627 3696 Detected object count: 1 12:57:17.0627 3696 Actual detected object count: 1 12:57:20.0623 3696 \Device\Harddisk0\DR0\# - copied to quarantine 12:57:20.0623 3696 \Device\Harddisk0\DR0 - copied to quarantine 12:57:20.0669 3696 \Device\Harddisk0\DR0\TDLFS\ph.dll - copied to quarantine 12:57:24.0928 3696 \Device\Harddisk0\DR0\TDLFS\phx.dll - copied to quarantine 12:57:29.0234 3696 \Device\Harddisk0\DR0\TDLFS\sub.dll - copied to quarantine 12:57:29.0265 3696 \Device\Harddisk0\DR0\TDLFS\subx.dll - copied to quarantine 12:57:29.0359 3696 \Device\Harddisk0\DR0\TDLFS\phd - copied to quarantine 12:57:33.0820 3696 \Device\Harddisk0\DR0\TDLFS\phdx - copied to quarantine 12:57:33.0883 3696 \Device\Harddisk0\DR0\TDLFS\phs - copied to quarantine 12:57:33.0883 3696 \Device\Harddisk0\DR0\TDLFS\phdata - copied to quarantine 12:57:33.0883 3696 \Device\Harddisk0\DR0\TDLFS\phld - copied to quarantine 12:57:33.0883 3696 \Device\Harddisk0\DR0\TDLFS\phln - copied to quarantine 12:57:38.0126 3696 \Device\Harddisk0\DR0\TDLFS\phlx - copied to quarantine 12:57:42.0385 3696 \Device\Harddisk0\DR0\TDLFS\phm - copied to quarantine 12:57:42.0416 3696 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - will be cured on reboot 12:57:42.0416 3696 \Device\Harddisk0\DR0 - ok 12:57:42.0416 3696 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - User select action: Cure 12:58:36.0408 4764 Deinitialize success ty for any help that can be given. i look forward to resolving this frustrating issue :thumbup:
ok here are the two logs from OTL

OTL logfile created on: 4/26/2012 1:39:17 PM - Run 1
OTL by OldTimer - Version 3.2.42.1 Folder = C:\Users\Jeffrey\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.99 Gb Total Physical Memory | 5.47 Gb Available Physical Memory | 68.45% Memory free
15.98 Gb Paging File | 13.16 Gb Available in Paging File | 82.37% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 916.82 Gb Total Space | 884.62 Gb Free Space | 96.49% Space Free | Partition Type: NTFS
Drive D: | 47.96 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: JEFFREY-PC | User Name: Jeffrey | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Jeffrey\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe (Alcor Micro Corp.)
PRC - \\.\globalroot\systemroot\svchost.exe ()
PRC - \\.\globalroot\systemroot\svchost.exe ()
PRC - \\.\globalroot\systemroot\svchost.exe ()
PRC - C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Dell\DellComms\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files (x86)\Dell\DellComms\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV:64bit: - (mfevtp) – C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV:64bit: - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:64bit: - (McProxy) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNASvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNaiAnn) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (mcmscsvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McMPFSvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (wltrysvc) – C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AERTFilters) – C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (RoxMediaDB10) – c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCom\RoxMediaDB10.exe (Sonic Solutions)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (sprtsvc_DellComms) SupportSoft Sprocket Service (DellComms) – C:\Program Files (x86)\Dell\DellComms\bin\sprtsvc.exe (SupportSoft, Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (mfehidk) – C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfefirek) – C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) – C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) – C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) – C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) – C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfenlfk) – C:\Windows\SysNative\drivers\mfenlfk.sys (McAfee, Inc.)
DRV:64bit: - (cfwids) – C:\Windows\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:64bit: - (BCM42RLY) – C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (k57nd60a) Broadcom NetLink ™ – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (netr7364) – C:\Windows\SysNative\drivers\netr7364.sys (Ralink Technology, Corp.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (RxFilter) – C:\Windows\SysWOW64\drivers\RxFilter.sys (Sonic Solutions)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {BB3CD05B-CE76-421B-9D22-4F90AFCC84BE}
IE:64bit: - HKLM\..\SearchScopes\{BB3CD05B-CE76-421B-9D22-4F90AFCC84BE}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {21D8C4A7-970D-4552-B93C-DF45A08E608F}
IE - HKLM\..\SearchScopes\{21D8C4A7-970D-4552-B93C-DF45A08E608F}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {21D8C4A7-970D-4552-B93C-DF45A08E608F}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~2\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\3.0.40624.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/04/26 11:54:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012/04/26 11:54:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/04/26 06:36:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2012/04/26 06:36:35 | 000,000,000 | —D | M] (No name found) – C:\Users\Jeffrey\AppData\Roaming\Mozilla\Extensions
[2012/04/26 06:36:04 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/04/26 11:54:27 | 000,000,000 | —D | M] (McAfee ScriptScan for Firefox) – C:\PROGRAM FILES (X86)\COMMON FILES\MCAFEE\SYSTEMCORE
[2012/04/26 11:54:27 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR
[2012/04/20 21:19:34 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/04/20 21:18:25 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/04/20 21:18:25 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/04/26 05:08:54 | 000,000,882 | RH– | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 94.63.147.16 www.google.com
O1 - Hosts: 94.63.147.17 www.bing.com
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120426062939.dll (McAfee, Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120426103358.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe File not found
O4 - HKLM..\Run: [DellComms] C:\Program Files (x86)\Dell\DellComms\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [ShwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe (Alcor Micro Corp.)
O4 - HKLM..\RunOnceEx: [ContentMerger] c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCom\ContentMerger10.exe (Sonic Solutions)
O4 - Startup: C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FA6CD502-6B10-4BFF-AE2B-4F70894A85D1}: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (GTGina.dll) - File not found
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/02/28 23:42:20 | 000,000,051 | R— | M] () - D:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{59036be1-c297-11de-976d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{59036be1-c297-11de-976d-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Setup.exe – [2005/11/02 04:07:14 | 002,141,184 | R— | M] (Linksys)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/04/26 13:37:47 | 000,595,968 | —- | C] (OldTimer Tools) – C:\Users\Jeffrey\Desktop\OTL.exe
[2012/04/26 12:30:23 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2012/04/26 12:24:27 | 000,000,000 | —D | C] – C:\Windows\Sun
[2012/04/26 12:09:28 | 000,000,000 | —D | C] – C:\Users\Jeffrey\Documents\Autoruns
[2012/04/26 11:53:10 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2012/04/26 11:52:34 | 000,000,000 | —D | C] – C:\Users\Jeffrey\Documents\tdsskiller
[2012/04/26 10:54:46 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_39.dll
[2012/04/26 10:54:46 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_39.dll
[2012/04/26 10:54:46 | 000,509,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_2.dll
[2012/04/26 10:54:46 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_39.dll
[2012/04/26 10:54:46 | 000,068,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_1.dll
[2012/04/26 10:52:15 | 000,000,000 | —D | C] – C:\Riot Games
[2012/04/26 10:52:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
[2012/04/26 06:43:34 | 000,000,000 | —D | C] – C:\Users\Jeffrey\Desktop\LeagueOfLegends
[2012/04/26 06:43:20 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\PMB Files
[2012/04/26 06:43:19 | 000,000,000 | —D | C] – C:\ProgramData\PMB Files
[2012/04/26 06:42:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Pando Networks
[2012/04/26 06:36:28 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\Mozilla
[2012/04/26 06:36:28 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\Mozilla
[2012/04/26 06:36:14 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2012/04/26 06:36:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Maintenance Service
[2012/04/26 06:36:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012/04/26 06:30:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/04/26 06:29:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\McAfee.com
[2012/04/26 06:29:39 | 000,010,248 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeclnk.sys
[2012/04/26 06:29:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\McAfee
[2012/04/26 06:29:11 | 000,487,296 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfefirek.sys
[2012/04/26 06:29:11 | 000,289,664 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfewfpk.sys
[2012/04/26 06:29:11 | 000,229,528 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeavfk.sys
[2012/04/26 06:29:11 | 000,100,912 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mferkdet.sys
[2012/04/26 06:29:11 | 000,075,936 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfenlfk.sys
[2012/04/26 06:29:11 | 000,065,264 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\cfwids.sys
[2012/04/26 06:29:06 | 000,000,000 | —D | C] – C:\Program Files\Common Files\McAfee
[2012/04/26 06:29:05 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[2012/04/26 06:29:05 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2012/04/26 06:29:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\McAfee
[2012/04/26 06:13:47 | 000,162,192 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\mfevtps.exe
[2012/04/26 06:13:44 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2012/04/26 06:08:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Compact Wireless-G USB Adapter Wireless Network Monitor
[2012/04/26 06:07:40 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\CyberLink
[2012/04/26 06:05:04 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\Dell
[2012/04/26 06:04:57 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\SupportSoft
[2012/04/26 06:04:56 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\Stardock_Corporation
[2012/04/26 06:04:43 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Searches
[2012/04/26 06:04:43 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/04/26 06:04:43 | 000,000,000 | -H-D | C] – C:\Users\Jeffrey\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012/04/26 06:04:36 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\Identities
[2012/04/26 06:04:34 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Contacts
[2012/04/26 06:04:33 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\VirtualStore
[2012/04/26 06:02:09 | 000,000,000 | –SD | C] – C:\Users\Jeffrey\AppData\Roaming\Microsoft
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Videos
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Saved Games
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Pictures
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Music
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Links
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Favorites
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Downloads
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Documents
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Desktop
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\AppData\Local\Temporary Internet Files
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Templates
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Start Menu
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\SendTo
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Recent
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\PrintHood
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\NetHood
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Documents\My Videos
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Documents\My Pictures
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Documents\My Music
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\My Documents
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Local Settings
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\AppData\Local\History
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Cookies
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Application Data
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\AppData\Local\Application Data
[2012/04/26 06:02:09 | 000,000,000 | -H-D | C] – C:\Users\Jeffrey\AppData
[2012/04/26 06:02:09 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\Temp
[2012/04/26 06:02:09 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\Microsoft
[2012/04/26 06:02:09 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\Media Center Programs
[2012/04/26 05:59:19 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\svchost.exe
[2012/04/26 05:58:04 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2012/04/26 05:39:16 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\Macromedia
[2012/04/26 05:39:13 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\Adobe
[2012/04/26 05:12:59 | 001,031,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcore.dll
[2012/04/26 05:12:59 | 000,826,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpcore.dll
[2012/04/26 05:12:48 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2012/04/26 05:12:48 | 000,139,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cabview.dll
[2012/04/26 05:12:48 | 000,132,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cabview.dll
[2012/04/26 05:12:48 | 000,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2012/04/26 05:12:48 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe

========== Files - Modified Within 30 Days ==========

[2012/04/26 13:37:53 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Users\Jeffrey\Desktop\OTL.exe
[2012/04/26 13:06:41 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/26 13:06:41 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/26 13:06:12 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/04/26 13:06:12 | 000,615,122 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/04/26 13:06:12 | 000,103,496 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/04/26 13:02:10 | 000,001,830 | —- | M] () – C:\Users\Public\Desktop\McAfee Security Center.lnk
[2012/04/26 12:59:29 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/04/26 12:59:25 | 2140,495,871 | -HS- | M] () – C:\hiberfil.sys
[2012/04/26 12:30:20 | 470,465,247 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/04/26 12:24:44 | 000,302,080 | —- | M] () – C:\ProgramData\XkFcjVGVgWJhiQK.exe
[2012/04/26 10:54:46 | 000,001,722 | —- | M] () – C:\Users\Public\Desktop\Play League of Legends.lnk
[2012/04/26 06:36:17 | 000,001,136 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/04/26 06:08:03 | 000,001,361 | —- | M] () – C:\Windows\SysWow64\WLAN.INI
[2012/04/26 06:04:58 | 000,001,984 | —- | M] () – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
[2012/04/26 05:59:51 | 000,039,252 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2012/04/26 05:59:51 | 000,039,252 | —- | M] () – C:\Windows\SysNative\license.rtf
[2012/04/26 05:39:02 | 000,001,443 | —- | M] () – C:\Users\Jeffrey\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

========== Files Created - No Company Name ==========

[2012/04/26 12:30:20 | 470,465,247 | —- | C] () – C:\Windows\MEMORY.DMP
[2012/04/26 12:26:47 | 000,302,080 | —- | C] () – C:\ProgramData\XkFcjVGVgWJhiQK.exe
[2012/04/26 10:54:46 | 000,001,722 | —- | C] () – C:\Users\Public\Desktop\Play League of Legends.lnk
[2012/04/26 06:36:17 | 000,001,148 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/04/26 06:36:17 | 000,001,136 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/04/26 06:30:21 | 000,001,830 | —- | C] () – C:\Users\Public\Desktop\McAfee Security Center.lnk
[2012/04/26 06:04:58 | 000,001,984 | —- | C] () – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
[2012/04/26 06:04:48 | 000,001,415 | —- | C] () – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012/04/26 06:04:45 | 000,001,449 | —- | C] () – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/04/26 06:02:20 | 000,001,979 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Help Documentation.lnk
[2012/04/26 06:02:09 | 000,001,802 | —- | C] () – C:\Users\Jeffrey\Desktop\Free year of music from Dell.lnk
[2012/04/26 06:02:09 | 000,000,290 | —- | C] () – C:\Users\Jeffrey\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/04/26 06:02:09 | 000,000,272 | —- | C] () – C:\Users\Jeffrey\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012/04/26 05:58:00 | 2140,495,871 | -HS- | C] () – C:\hiberfil.sys
[2012/04/26 05:39:02 | 000,001,443 | —- | C] () – C:\Users\Jeffrey\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

========== LOP Check ==========

[2009/07/14 01:08:49 | 000,004,390 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2009/10/26 22:22:13 | 000,003,836 | RH– | M] () – C:\dell.sdr
[2012/04/26 12:59:25 | 2140,495,871 | -HS- | M] () – C:\hiberfil.sys
[2006/12/02 00:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2012/04/26 12:59:27 | 4285,652,991 | -HS- | M] () – C:\pagefile.sys
[2012/04/26 11:53:43 | 000,121,838 | —- | M] () – C:\TDSSKiller.2.7.33.0_26.04.2012_11.52.38_log.txt
[2012/04/26 11:56:59 | 000,121,658 | —- | M] () – C:\TDSSKiller.2.7.33.0_26.04.2012_11.55.52_log.txt
[2012/04/26 12:06:46 | 000,121,658 | —- | M] () – C:\TDSSKiller.2.7.33.0_26.04.2012_12.00.28_log.txt
[2012/04/26 12:19:03 | 000,121,576 | —- | M] () – C:\TDSSKiller.2.7.33.0_26.04.2012_12.14.22_log.txt
[2012/04/26 12:53:54 | 000,121,584 | —- | M] () – C:\TDSSKiller.2.7.33.0_26.04.2012_12.53.18_log.txt
[2012/04/26 12:58:36 | 000,121,658 | —- | M] () – C:\TDSSKiller.2.7.33.0_26.04.2012_12.56.52_log.txt

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/07/10 13:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/04/26 05:39:02 | 000,000,221 | -HS- | M] () – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/04/26 13:37:53 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Users\Jeffrey\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >

and the extra


OTL Extras logfile created on: 4/26/2012 1:39:17 PM - Run 1
OTL by OldTimer - Version 3.2.42.1 Folder = C:\Users\Jeffrey\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.99 Gb Total Physical Memory | 5.47 Gb Available Physical Memory | 68.45% Memory free
15.98 Gb Paging File | 13.16 Gb Available in Paging File | 82.37% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 916.82 Gb Total Space | 884.62 Gb Free Space | 96.49% Space Free | Partition Type: NTFS
Drive D: | 47.96 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: JEFFREY-PC | User Name: Jeffrey | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1A198FCD-A1FF-42AA-83ED-00616AB0A42E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{98215FE4-F64E-4BAB-BCAA-37CBC64A5EDB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{29A22D4B-D3CC-4EBD-AAC4-A81908B97F22}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{505BF410-877F-4476-82F7-85B69819004E}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{6D3F338E-A271-4D6F-B7ED-A7F0D492840B}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{7D6437E5-B6AD-422C-AF64-CAE0AA89DB4F}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{9026F649-37A4-4063-971E-508F6FE2D10E}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{993AB2F3-BEBA-4718-A5AB-79B65EE7873A}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{A9D490DC-B842-42EF-90CF-556C5D89312F}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{ADBA1662-9F66-49C6-8906-4D9C02C16349}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{C36B7A92-0844-49C5-844B-A6D163E80B1C}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{CE50553F-8E65-431B-8CE1-CE7BAC932E0F}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd dx\powerdvd.exe |
"{E03FF433-36E2-4AC8-A484-5016B1E9CA4C}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{F817C26A-7A2C-4B48-8008-3F3484F1B6ED}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02AD9D20-03D2-4DE0-8793-E8253026AD86}" = EMCGadgets64
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{26A24AE4-039D-4CA4-87B4-2F86416014FF}" = Java™ 6 Update 14 (64-bit)
"{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}" = Roxio File Backup
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{DB9C43F7-0B0F-4E43-9E6B-F945C71C469E}" = VD64Inst
"{E60B7350-EA5F-41E0-9D6F-E508781E36D2}" = Dell Dock
"Dell Wireless WLAN Card Utility" = Dell Wireless WLAN Card Utility
"NVIDIA Drivers" = NVIDIA Drivers

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Central Data
"{098122AB-C605-4853-B441-C0A4EB359B75}" = DirectXInstallService
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Central Tools
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 14
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{351DE0AB-7787-4497-9A7A-4AA9E3A4E290}" = Dell Communications (Support Software)
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}" = Banctec Service Agreement
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{537BF16E-7412-448C-95D8-846E85A1D817}" = Roxio Easy CD and DVD Burning
"{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack
"{612B5D2E-8084-4102-91DE-24281E4EFB2C}" = Roxio Easy CD and DVD Burning
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Central Audio
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
"{9F0A32A5-4EBF-4B9D-A3CD-31579F2E1400}" = Multimedia Card Reader
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.2
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Central Copy
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{EC877639-07AB-495C-BFD1-D63AF9140810}" = Roxio Activation Module
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Central Core
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F855C3AE-992D-4B84-A09D-07103CDCDAC2}" = Compact Wireless-G USB Adapter
"{FDB46DE7-9045-47BB-970A-3E4ED5369E03}" = EMC 10 Content
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"InstallShield_{9F0A32A5-4EBF-4B9D-A3CD-31579F2E1400}" = Multimedia Card Reader
"Mozilla Firefox 12.0 (x86 en-US)" = Mozilla Firefox 12.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSC" = McAfee SecurityCenter
"WinLiveSuite_Wave3" = Windows Live Essentials

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/26/2012 5:42:49 AM | Computer Name = Jeffrey-PC | Source = Microsoft-Windows-CAPI2 | ID = 4101
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/E0AB059420725493056062023670F7CD2EFC6666.crt>
with error: This operation returned because the timeout period expired. .

Error - 4/26/2012 7:35:55 AM | Computer Name = Jeffrey-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "c:\program files (x86)\windows
live\photo gallery\MovieMaker.Exe".Error in manifest or policy file "c:\program
files (x86)\windows live\photo gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 4/26/2012 7:36:30 AM | Computer Name = Jeffrey-PC | Source = SideBySide | ID = 16842811
Description = Activation context generation failed for "c:\program files (x86)\microsoft\search
enhancement pack\search helper\searchhelper.dll".Error in manifest or policy file
"c:\program files (x86)\microsoft\search enhancement pack\search helper\searchhelper.dll"
on line 2. Invalid Xml syntax.

Error - 4/26/2012 11:53:44 AM | Computer Name = Jeffrey-PC | Source = EventSystem | ID = 4622
Description =

Error - 4/26/2012 12:06:47 PM | Computer Name = Jeffrey-PC | Source = EventSystem | ID = 4621
Description =

[ Broadcom Wireless LAN Events ]
Error - 4/26/2012 6:05:13 AM | Computer Name = Jeffrey-PC | Source = WLAN-Tray | ID = 0
Description = 05:05:13, Thu, Apr 26, 12 Error - Unable to get current user admin
status

Error - 4/26/2012 6:06:00 AM | Computer Name = Jeffrey-PC | Source = WLAN-Tray | ID = 0
Description = 05:06:00, Thu, Apr 26, 12 Error - Unable to get current user admin
status

Error - 4/26/2012 6:07:36 AM | Computer Name = Jeffrey-PC | Source = WLAN-Tray | ID = 0
Description = 05:07:36, Thu, Apr 26, 12 Error - Unable to switch user context, authentication
information not set correctly

[ System Events ]
Error - 4/26/2012 5:15:12 AM | Computer Name = Jeffrey-PC | Source = Service Control Manager | ID = 7000
Description = The SessionLauncher service failed to start due to the following error:
%%2

Error - 4/26/2012 5:15:26 AM | Computer Name = Jeffrey-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
RxFilter

Error - 4/26/2012 5:17:38 AM | Computer Name = Jeffrey-PC | Source = Service Control Manager | ID = 7000
Description = The SessionLauncher service failed to start due to the following error:
%%2

Error - 4/26/2012 5:17:49 AM | Computer Name = Jeffrey-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
RxFilter

Error - 4/26/2012 5:22:28 AM | Computer Name = Jeffrey-PC | Source = Service Control Manager | ID = 7000
Description = The SessionLauncher service failed to start due to the following error:
%%2

Error - 4/26/2012 5:22:30 AM | Computer Name = Jeffrey-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
RxFilter

Error - 4/26/2012 11:54:38 AM | Computer Name = Jeffrey-PC | Source = Service Control Manager | ID = 7000
Description = The SessionLauncher service failed to start due to the following error:
%%2

Error - 4/26/2012 11:54:42 AM | Computer Name = Jeffrey-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
RxFilter

Error - 4/26/2012 11:57:50 AM | Computer Name = Jeffrey-PC | Source = Service Control Manager | ID = 7000
Description = The SessionLauncher service failed to start due to the following error:
%%2

Error - 4/26/2012 11:57:54 AM | Computer Name = Jeffrey-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
RxFilter


< End of report >
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Having said that….Let's get going!! :thumbup:
———-

Run TDSSKiller again and post the new log to your next reply. :)
tyvm. i'm grateful for any help that can be given. here is the new tdsskiller log 14:22:49.0057 3548 TDSS rootkit removing tool [removed] Apr 24 2012 18:43:43 14:22:50.0211 3548 ============================================================ 14:22:50.0211 3548 Current date / time: 2012/04/26 14:22:50.0211 14:22:50.0211 3548 SystemInfo: 14:22:50.0211 3548 14:22:50.0211 3548 OS Version: 6.1.7600 ServicePack: 0.0 14:22:50.0211 3548 Product type: Workstation 14:22:50.0211 3548 ComputerName: JEFFREY-PC 14:22:50.0211 3548 UserName: Jeffrey 14:22:50.0211 3548 Windows directory: C:\Windows 14:22:50.0211 3548 System windows directory: C:\Windows 14:22:50.0211 3548 Running under WOW64 14:22:50.0211 3548 Processor architecture: Intel x64 14:22:50.0211 3548 Number of processors: 8 14:22:50.0211 3548 Page size: 0x1000 14:22:50.0211 3548 Boot type: Normal boot 14:22:50.0211 3548 ============================================================ 14:22:51.0537 3548 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 14:22:51.0569 3548 ============================================================ 14:22:51.0569 3548 \Device\Harddisk0\DR0: 14:22:51.0569 3548 MBR partitions: 14:22:51.0569 3548 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x1D4C000 14:22:51.0569 3548 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1D60000, BlocksNum 0x729A65B0 14:22:51.0569 3548 ============================================================ 14:22:51.0600 3548 C: <-> \Device\Harddisk0\DR0\Partition1 14:22:51.0600 3548 ============================================================ 14:22:51.0600 3548 Initialize success 14:22:51.0600 3548 ============================================================ 14:22:52.0754 6352 ============================================================ 14:22:52.0754 6352 Scan started 14:22:52.0754 6352 Mode: Manual; 14:22:52.0754 6352 ============================================================ 14:22:53.0971 6352 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys 14:22:53.0987 6352 1394ohci - ok 14:22:54.0002 6352 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys 14:22:54.0002 6352 ACPI - ok 14:22:54.0018 6352 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys 14:22:54.0033 6352 AcpiPmi - ok 14:22:54.0065 6352 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys 14:22:54.0080 6352 adp94xx - ok 14:22:54.0096 6352 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys 14:22:54.0111 6352 adpahci - ok 14:22:54.0127 6352 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys 14:22:54.0127 6352 adpu320 - ok 14:22:54.0158 6352 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll 14:22:54.0158 6352 AeLookupSvc - ok 14:22:54.0221 6352 AERTFilters (3ac22a3dfa8a050e35f0e3cd99d0cdf2) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe 14:22:54.0221 6352 AERTFilters - ok 14:22:54.0252 6352 AFD (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys 14:22:54.0267 6352 AFD - ok 14:22:54.0267 6352 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys 14:22:54.0267 6352 agp440 - ok 14:22:54.0299 6352 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe 14:22:54.0299 6352 ALG - ok 14:22:54.0314 6352 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys 14:22:54.0314 6352 aliide - ok 14:22:54.0314 6352 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys 14:22:54.0314 6352 amdide - ok 14:22:54.0330 6352 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys 14:22:54.0330 6352 AmdK8 - ok 14:22:54.0330 6352 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys 14:22:54.0330 6352 AmdPPM - ok 14:22:54.0345 6352 amdsata (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys 14:22:54.0345 6352 amdsata - ok 14:22:54.0361 6352 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys 14:22:54.0361 6352 amdsbs - ok 14:22:54.0361 6352 amdxata (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys 14:22:54.0361 6352 amdxata - ok 14:22:54.0377 6352 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys 14:22:54.0377 6352 AppID - ok 14:22:54.0377 6352 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll 14:22:54.0392 6352 AppIDSvc - ok 14:22:54.0408 6352 Appinfo (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll 14:22:54.0408 6352 Appinfo - ok 14:22:54.0408 6352 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys 14:22:54.0408 6352 arc - ok 14:22:54.0423 6352 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys 14:22:54.0423 6352 arcsas - ok 14:22:54.0423 6352 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 14:22:54.0423 6352 AsyncMac - ok 14:22:54.0439 6352 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys 14:22:54.0439 6352 atapi - ok 14:22:54.0486 6352 AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll 14:22:54.0501 6352 AudioEndpointBuilder - ok 14:22:54.0501 6352 AudioSrv (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll 14:22:54.0517 6352 AudioSrv - ok 14:22:54.0533 6352 AxInstSV (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll 14:22:54.0533 6352 AxInstSV - ok 14:22:54.0579 6352 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys 14:22:54.0579 6352 b06bdrv - ok 14:22:54.0626 6352 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 14:22:54.0626 6352 b57nd60a - ok 14:22:54.0642 6352 BCM42RLY (e001dd475a7c27ebe5a0db45c11bad71) C:\Windows\system32\drivers\BCM42RLY.sys 14:22:54.0642 6352 BCM42RLY - ok 14:22:54.0845 6352 BCM43XX (37394d3553e220fb732c21e217e1bd8b) C:\Windows\system32\DRIVERS\bcmwl664.sys 14:22:54.0845 6352 BCM43XX - ok 14:22:54.0969 6352 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll 14:22:54.0969 6352 BDESVC - ok 14:22:54.0985 6352 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 14:22:54.0985 6352 Beep - ok 14:22:55.0079 6352 BFE (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll 14:22:55.0094 6352 BFE - ok 14:22:55.0188 6352 BITS (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll 14:22:55.0203 6352 BITS - ok 14:22:55.0250 6352 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 14:22:55.0250 6352 blbdrive - ok 14:22:55.0281 6352 bowser (91ce0d3dc57dd377e690a2d324022b08) C:\Windows\system32\DRIVERS\bowser.sys 14:22:55.0297 6352 bowser - ok 14:22:55.0297 6352 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys 14:22:55.0313 6352 BrFiltLo - ok 14:22:55.0313 6352 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys 14:22:55.0313 6352 BrFiltUp - ok 14:22:55.0344 6352 Browser (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll 14:22:55.0344 6352 Browser - ok 14:22:55.0359 6352 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 14:22:55.0375 6352 Brserid - ok 14:22:55.0375 6352 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 14:22:55.0375 6352 BrSerWdm - ok 14:22:55.0375 6352 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 14:22:55.0375 6352 BrUsbMdm - ok 14:22:55.0391 6352 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 14:22:55.0391 6352 BrUsbSer - ok 14:22:55.0391 6352 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys 14:22:55.0391 6352 BTHMODEM - ok 14:22:55.0422 6352 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll 14:22:55.0422 6352 bthserv - ok 14:22:55.0422 6352 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 14:22:55.0422 6352 cdfs - ok 14:22:55.0437 6352 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys 14:22:55.0437 6352 cdrom - ok 14:22:55.0469 6352 CertPropSvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll 14:22:55.0469 6352 CertPropSvc - ok 14:22:55.0500 6352 cfwids (274ce03459896006f7a5069266e0469e) C:\Windows\system32\drivers\cfwids.sys 14:22:55.0500 6352 cfwids - ok 14:22:55.0500 6352 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys 14:22:55.0500 6352 circlass - ok 14:22:55.0547 6352 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 14:22:55.0547 6352 CLFS - ok 14:22:55.0609 6352 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 14:22:55.0609 6352 clr_optimization_v2.0.50727_32 - ok 14:22:55.0640 6352 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 14:22:55.0640 6352 clr_optimization_v2.0.50727_64 - ok 14:22:55.0656 6352 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 14:22:55.0656 6352 CmBatt - ok 14:22:55.0656 6352 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys 14:22:55.0656 6352 cmdide - ok 14:22:55.0687 6352 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys 14:22:55.0703 6352 CNG - ok 14:22:55.0703 6352 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys 14:22:55.0703 6352 Compbatt - ok 14:22:55.0718 6352 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys 14:22:55.0718 6352 CompositeBus - ok 14:22:55.0718 6352 COMSysApp - ok 14:22:55.0734 6352 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys 14:22:55.0734 6352 crcdisk - ok 14:22:55.0781 6352 CryptSvc (8c57411b66282c01533cb776f98ad384) C:\Windows\system32\cryptsvc.dll 14:22:55.0781 6352 CryptSvc - ok 14:22:55.0874 6352 DcomLaunch (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll 14:22:55.0874 6352 DcomLaunch - ok 14:22:55.0921 6352 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll 14:22:55.0921 6352 defragsvc - ok 14:22:55.0937 6352 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys 14:22:55.0937 6352 DfsC - ok 14:22:55.0968 6352 Dhcp (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll 14:22:55.0983 6352 Dhcp - ok 14:22:55.0983 6352 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 14:22:55.0983 6352 discache - ok 14:22:55.0999 6352 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys 14:22:55.0999 6352 Disk - ok 14:22:56.0015 6352 Dnscache (676108c4e3aa6f6b34633748bd0bebd9) C:\Windows\System32\dnsrslvr.dll 14:22:56.0015 6352 Dnscache - ok 14:22:56.0108 6352 DockLoginService (0840abbbdf438691ee65a20040635cbe) C:\Program Files\Dell\DellDock\DockLogin.exe 14:22:56.0108 6352 DockLoginService - ok 14:22:56.0139 6352 dot3svc (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll 14:22:56.0139 6352 dot3svc - ok 14:22:56.0342 6352 DPS (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll 14:22:56.0342 6352 DPS - ok 14:22:56.0358 6352 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 14:22:56.0358 6352 drmkaud - ok 14:22:56.0451 6352 DXGKrnl (7cb7d2b73813ce05c7bc0f5f95d27cec) C:\Windows\System32\drivers\dxgkrnl.sys 14:22:56.0451 6352 DXGKrnl - ok 14:22:56.0498 6352 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll 14:22:56.0498 6352 EapHost - ok 14:22:56.0717 6352 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys 14:22:56.0748 6352 ebdrv - ok 14:22:56.0888 6352 EFS (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\System32\lsass.exe 14:22:56.0888 6352 EFS - ok 14:22:57.0013 6352 ehRecvr (b91d81b3b54a54ccafc03733dbc2e29e) C:\Windows\ehome\ehRecvr.exe 14:22:57.0013 6352 ehRecvr - ok 14:22:57.0044 6352 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe 14:22:57.0044 6352 ehSched - ok 14:22:57.0122 6352 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys 14:22:57.0122 6352 elxstor - ok 14:22:57.0122 6352 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys 14:22:57.0122 6352 ErrDev - ok 14:22:57.0185 6352 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll 14:22:57.0200 6352 EventSystem - ok 14:22:57.0216 6352 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 14:22:57.0231 6352 exfat - ok 14:22:57.0247 6352 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 14:22:57.0263 6352 fastfat - ok 14:22:57.0341 6352 Fax (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe 14:22:57.0341 6352 Fax - ok 14:22:57.0356 6352 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys 14:22:57.0356 6352 fdc - ok 14:22:57.0372 6352 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll 14:22:57.0372 6352 fdPHost - ok 14:22:57.0387 6352 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll 14:22:57.0387 6352 FDResPub - ok 14:22:57.0403 6352 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 14:22:57.0403 6352 FileInfo - ok 14:22:57.0434 6352 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 14:22:57.0434 6352 Filetrace - ok 14:22:57.0434 6352 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys 14:22:57.0434 6352 flpydisk - ok 14:22:57.0450 6352 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys 14:22:57.0450 6352 FltMgr - ok 14:22:57.0559 6352 FontCache (8ac4cb4ea61e41009fae9ae7b2b5da3a) C:\Windows\system32\FntCache.dll 14:22:57.0575 6352 FontCache - ok 14:22:57.0653 6352 FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 14:22:57.0653 6352 FontCache3.0.0.0 - ok 14:22:57.0684 6352 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 14:22:57.0684 6352 FsDepends - ok 14:22:57.0684 6352 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys 14:22:57.0684 6352 Fs_Rec - ok 14:22:57.0699 6352 fvevol (b8b2a6e1558f8f5de5ce431c5b2c7b09) C:\Windows\system32\DRIVERS\fvevol.sys 14:22:57.0715 6352 fvevol - ok 14:22:57.0731 6352 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys 14:22:57.0731 6352 gagp30kx - ok 14:22:57.0793 6352 gpsvc (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll 14:22:57.0809 6352 gpsvc - ok 14:22:57.0824 6352 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 14:22:57.0824 6352 hcw85cir - ok 14:22:57.0840 6352 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys 14:22:57.0855 6352 HDAudBus - ok 14:22:57.0855 6352 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys 14:22:57.0855 6352 HidBatt - ok 14:22:57.0871 6352 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys 14:22:57.0871 6352 HidBth - ok 14:22:57.0887 6352 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys 14:22:57.0887 6352 HidIr - ok 14:22:57.0887 6352 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll 14:22:57.0887 6352 hidserv - ok 14:22:57.0902 6352 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys 14:22:57.0902 6352 HidUsb - ok 14:22:57.0949 6352 hkmsvc (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll 14:22:57.0949 6352 hkmsvc - ok 14:22:57.0980 6352 HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll 14:22:57.0980 6352 HomeGroupListener - ok 14:22:58.0027 6352 HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll 14:22:58.0027 6352 HomeGroupProvider - ok 14:22:58.0043 6352 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys 14:22:58.0043 6352 HpSAMD - ok 14:22:58.0105 6352 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys 14:22:58.0121 6352 HTTP - ok 14:22:58.0136 6352 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys 14:22:58.0136 6352 hwpolicy - ok 14:22:58.0152 6352 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys 14:22:58.0152 6352 i8042prt - ok 14:22:58.0214 6352 iaStor (1d004cb1da6323b1f55caef7f94b61d9) C:\Windows\system32\DRIVERS\iaStor.sys 14:22:58.0214 6352 iaStor - ok 14:22:58.0277 6352 iaStorV (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys 14:22:58.0277 6352 iaStorV - ok 14:22:58.0401 6352 idsvc (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 14:22:58.0417 6352 idsvc - ok 14:22:58.0433 6352 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys 14:22:58.0433 6352 iirsp - ok 14:22:58.0511 6352 IKEEXT (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll 14:22:58.0526 6352 IKEEXT - ok 14:22:58.0651 6352 IntcAzAudAddService (d42d651676883181400e22957a7e0b1e) C:\Windows\system32\drivers\RTKVHD64.sys 14:22:58.0667 6352 IntcAzAudAddService - ok 14:22:58.0791 6352 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys 14:22:58.0791 6352 intelide - ok 14:22:58.0823 6352 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 14:22:58.0823 6352 intelppm - ok 14:22:58.0854 6352 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll 14:22:58.0854 6352 IPBusEnum - ok 14:22:58.0869 6352 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys 14:22:58.0869 6352 IpFilterDriver - ok 14:22:58.0932 6352 iphlpsvc (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll 14:22:58.0932 6352 iphlpsvc - ok 14:22:58.0947 6352 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys 14:22:58.0947 6352 IPMIDRV - ok 14:22:58.0963 6352 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 14:22:58.0963 6352 IPNAT - ok 14:22:58.0979 6352 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 14:22:58.0979 6352 IRENUM - ok 14:22:58.0979 6352 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys 14:22:58.0979 6352 isapnp - ok 14:22:59.0010 6352 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys 14:22:59.0010 6352 iScsiPrt - ok 14:22:59.0072 6352 k57nd60a (249ee2d26cb1530f3bede0ac8b9e3099) C:\Windows\system32\DRIVERS\k57nd60a.sys 14:22:59.0088 6352 k57nd60a - ok 14:22:59.0088 6352 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys 14:22:59.0088 6352 kbdclass - ok 14:22:59.0088 6352 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys 14:22:59.0088 6352 kbdhid - ok 14:22:59.0135 6352 KeyIso (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe 14:22:59.0135 6352 KeyIso - ok 14:22:59.0150 6352 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys 14:22:59.0150 6352 KSecDD - ok 14:22:59.0166 6352 KSecPkg (bbe1bf6d9b661c354d4857d5fadb943b) C:\Windows\system32\Drivers\ksecpkg.sys 14:22:59.0166 6352 KSecPkg - ok 14:22:59.0166 6352 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 14:22:59.0166 6352 ksthunk - ok 14:22:59.0197 6352 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll 14:22:59.0213 6352 KtmRm - ok 14:22:59.0259 6352 LanmanServer (c926920b8978de6acfe9e15c709e9b57) C:\Windows\system32\srvsvc.dll 14:22:59.0259 6352 LanmanServer - ok 14:22:59.0291 6352 LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll 14:22:59.0306 6352 LanmanWorkstation - ok 14:22:59.0306 6352 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 14:22:59.0306 6352 lltdio - ok 14:22:59.0353 6352 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll 14:22:59.0353 6352 lltdsvc - ok 14:22:59.0369 6352 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll 14:22:59.0369 6352 lmhosts - ok 14:22:59.0400 6352 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys 14:22:59.0400 6352 LSI_FC - ok 14:22:59.0415 6352 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys 14:22:59.0415 6352 LSI_SAS - ok 14:22:59.0431 6352 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys 14:22:59.0431 6352 LSI_SAS2 - ok 14:22:59.0447 6352 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys 14:22:59.0447 6352 LSI_SCSI - ok 14:22:59.0447 6352 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 14:22:59.0462 6352 luafv - ok 14:22:59.0556 6352 McAfee SiteAdvisor Service (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 14:22:59.0556 6352 McAfee SiteAdvisor Service - ok 14:22:59.0571 6352 McMPFSvc (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 14:22:59.0587 6352 McMPFSvc - ok 14:22:59.0587 6352 mcmscsvc (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 14:22:59.0587 6352 mcmscsvc - ok 14:22:59.0587 6352 McNaiAnn (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 14:22:59.0603 6352 McNaiAnn - ok 14:22:59.0603 6352 McNASvc (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 14:22:59.0603 6352 McNASvc - ok 14:22:59.0665 6352 McODS (dd01bf24dd6bf70a90549f9a7bb2d1eb) C:\Program Files\McAfee\VirusScan\mcods.exe 14:22:59.0665 6352 McODS - ok 14:22:59.0681 6352 McProxy (acb01bf1a905356ab7f978c7fe852209) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe 14:22:59.0681 6352 McProxy - ok 14:22:59.0712 6352 McShield (e998e3b12101288d716558466cbf6ae1) C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe 14:22:59.0712 6352 McShield - ok 14:22:59.0743 6352 Mcx2Svc (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll 14:22:59.0743 6352 Mcx2Svc - ok 14:22:59.0743 6352 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys 14:22:59.0759 6352 megasas - ok 14:22:59.0774 6352 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys 14:22:59.0774 6352 MegaSR - ok 14:22:59.0821 6352 mfeapfk (01884cb7655c8908b43ff5e364fe6fd2) C:\Windows\system32\drivers\mfeapfk.sys 14:22:59.0821 6352 mfeapfk - ok 14:22:59.0883 6352 mfeavfk (dab9a9cdfb04e4d68924492aa043019d) C:\Windows\system32\drivers\mfeavfk.sys 14:22:59.0883 6352 mfeavfk - ok 14:22:59.0915 6352 mfeavfk01 - ok 14:22:59.0946 6352 mfefire (b26782c3d6045b4464017d7926877560) C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe 14:22:59.0946 6352 mfefire - ok 14:22:59.0993 6352 mfefirek (ce9a3680675c0907ade16404ca967b49) C:\Windows\system32\drivers\mfefirek.sys 14:22:59.0993 6352 mfefirek - ok 14:23:00.0055 6352 mfehidk (60cf67458dd29cd17e77f2327b1a9a54) C:\Windows\system32\drivers\mfehidk.sys 14:23:00.0055 6352 mfehidk - ok 14:23:00.0086 6352 mfenlfk (a8129cfb919347f8533c934b365e9202) C:\Windows\system32\DRIVERS\mfenlfk.sys 14:23:00.0086 6352 mfenlfk - ok 14:23:00.0102 6352 mferkdet (5041fa2bd2b3a2693b015771bfbf6dca) C:\Windows\system32\drivers\mferkdet.sys 14:23:00.0102 6352 mferkdet - ok 14:23:00.0117 6352 mfevtp (723a5eb6cef7f408c3d0f15a82a6bff8) C:\Windows\system32\mfevtps.exe 14:23:00.0117 6352 mfevtp - ok 14:23:00.0149 6352 mfewfpk (919c56db14a0e1e2ab6da5d2821dc26e) C:\Windows\system32\drivers\mfewfpk.sys 14:23:00.0164 6352 mfewfpk - ok 14:23:00.0180 6352 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll 14:23:00.0195 6352 MMCSS - ok 14:23:00.0227 6352 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 14:23:00.0227 6352 Modem - ok 14:23:00.0242 6352 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 14:23:00.0242 6352 monitor - ok 14:23:00.0258 6352 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys 14:23:00.0258 6352 mouclass - ok 14:23:00.0273 6352 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 14:23:00.0273 6352 mouhid - ok 14:23:00.0305 6352 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys 14:23:00.0305 6352 mountmgr - ok 14:23:00.0367 6352 MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 14:23:00.0367 6352 MozillaMaintenance - ok 14:23:00.0383 6352 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys 14:23:00.0398 6352 mpio - ok 14:23:00.0398 6352 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 14:23:00.0398 6352 mpsdrv - ok 14:23:00.0476 6352 MpsSvc (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll 14:23:00.0492 6352 MpsSvc - ok 14:23:00.0507 6352 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys 14:23:00.0507 6352 MRxDAV - ok 14:23:00.0507 6352 mrxsmb (cfdcd8ca87c2a657debc150ac35b5e08) C:\Windows\system32\DRIVERS\mrxsmb.sys 14:23:00.0523 6352 mrxsmb - ok 14:23:00.0539 6352 mrxsmb10 (1bee517b220b7f024f411aec1571dd5a) C:\Windows\system32\DRIVERS\mrxsmb10.sys 14:23:00.0539 6352 mrxsmb10 - ok 14:23:00.0554 6352 mrxsmb20 (6b2d5fef385828b6e485c1c90afb8195) C:\Windows\system32\DRIVERS\mrxsmb20.sys 14:23:00.0554 6352 mrxsmb20 - ok 14:23:00.0570 6352 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys 14:23:00.0570 6352 msahci - ok 14:23:00.0570 6352 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys 14:23:00.0570 6352 msdsm - ok 14:23:00.0601 6352 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe 14:23:00.0601 6352 MSDTC - ok 14:23:00.0601 6352 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 14:23:00.0601 6352 Msfs - ok 14:23:00.0617 6352 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 14:23:00.0617 6352 mshidkmdf - ok 14:23:00.0632 6352 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys 14:23:00.0632 6352 msisadrv - ok 14:23:00.0663 6352 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll 14:23:00.0663 6352 MSiSCSI - ok 14:23:00.0663 6352 msiserver - ok 14:23:00.0679 6352 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 14:23:00.0695 6352 MSKSSRV - ok 14:23:00.0695 6352 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 14:23:00.0695 6352 MSPCLOCK - ok 14:23:00.0695 6352 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 14:23:00.0695 6352 MSPQM - ok 14:23:00.0726 6352 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys 14:23:00.0726 6352 MsRPC - ok 14:23:00.0726 6352 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys 14:23:00.0726 6352 mssmbios - ok 14:23:00.0726 6352 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 14:23:00.0726 6352 MSTEE - ok 14:23:00.0741 6352 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys 14:23:00.0741 6352 MTConfig - ok 14:23:00.0741 6352 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 14:23:00.0741 6352 Mup - ok 14:23:00.0788 6352 napagent (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll 14:23:00.0804 6352 napagent - ok 14:23:00.0835 6352 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 14:23:00.0835 6352 NativeWifiP - ok 14:23:00.0913 6352 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys 14:23:00.0929 6352 NDIS - ok 14:23:00.0944 6352 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 14:23:00.0944 6352 NdisCap - ok 14:23:00.0960 6352 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 14:23:00.0960 6352 NdisTapi - ok 14:23:00.0960 6352 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys 14:23:00.0960 6352 Ndisuio - ok 14:23:00.0975 6352 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys 14:23:00.0991 6352 NdisWan - ok 14:23:00.0991 6352 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys 14:23:00.0991 6352 NDProxy - ok 14:23:00.0991 6352 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 14:23:00.0991 6352 NetBIOS - ok 14:23:01.0007 6352 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys 14:23:01.0007 6352 NetBT - ok 14:23:01.0022 6352 Netlogon (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe 14:23:01.0022 6352 Netlogon - ok 14:23:01.0069 6352 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll 14:23:01.0085 6352 Netman - ok 14:23:01.0116 6352 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll 14:23:01.0116 6352 netprofm - ok 14:23:01.0194 6352 netr7364 (81b8d0c1ce44a7fdbd596b693783950c) C:\Windows\system32\DRIVERS\netr7364.sys 14:23:01.0209 6352 netr7364 - ok 14:23:01.0287 6352 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 14:23:01.0303 6352 NetTcpPortSharing - ok 14:23:01.0319 6352 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys 14:23:01.0319 6352 nfrd960 - ok 14:23:01.0521 6352 NlaSvc (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll 14:23:01.0521 6352 NlaSvc - ok 14:23:01.0521 6352 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 14:23:01.0537 6352 Npfs - ok 14:23:01.0553 6352 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll 14:23:01.0553 6352 nsi - ok 14:23:01.0553 6352 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 14:23:01.0553 6352 nsiproxy - ok 14:23:01.0677 6352 Ntfs (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys 14:23:01.0709 6352 Ntfs - ok 14:23:01.0818 6352 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 14:23:01.0818 6352 Null - ok 14:23:02.0535 6352 nvlddmkm (51bd7ef17f0b525994ad5b3748c8288b) C:\Windows\system32\DRIVERS\nvlddmkm.sys 14:23:02.0567 6352 nvlddmkm - ok 14:23:02.0645 6352 nvraid (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys 14:23:02.0660 6352 nvraid - ok 14:23:02.0676 6352 nvstor (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys 14:23:02.0676 6352 nvstor - ok 14:23:02.0738 6352 nvsvc (fce8537bf5d504680212d536a3bfe5e2) C:\Windows\system32\nvvsvc.exe 14:23:02.0738 6352 nvsvc - ok 14:23:02.0769 6352 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys 14:23:02.0769 6352 nv_agp - ok 14:23:02.0769 6352 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys 14:23:02.0769 6352 ohci1394 - ok 14:23:02.0832 6352 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll 14:23:02.0832 6352 p2pimsvc - ok 14:23:02.0879 6352 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll 14:23:02.0879 6352 p2psvc - ok 14:23:02.0894 6352 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys 14:23:02.0894 6352 Parport - ok 14:23:02.0910 6352 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys 14:23:02.0910 6352 partmgr - ok 14:23:02.0957 6352 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll 14:23:02.0972 6352 PcaSvc - ok 14:23:02.0988 6352 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys 14:23:02.0988 6352 pci - ok 14:23:03.0003 6352 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys 14:23:03.0003 6352 pciide - ok 14:23:03.0019 6352 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys 14:23:03.0019 6352 pcmcia - ok 14:23:03.0035 6352 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 14:23:03.0035 6352 pcw - ok 14:23:03.0081 6352 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 14:23:03.0081 6352 PEAUTH - ok 14:23:03.0175 6352 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe 14:23:03.0175 6352 PerfHost - ok 14:23:03.0284 6352 pla (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll 14:23:03.0315 6352 pla - ok 14:23:03.0378 6352 PlugPlay (23157d583244400e1d7fbaee2e4b31b7) C:\Windows\system32\umpnpmgr.dll 14:23:03.0393 6352 PlugPlay - ok 14:23:03.0393 6352 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll 14:23:03.0393 6352 PNRPAutoReg - ok 14:23:03.0425 6352 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll 14:23:03.0425 6352 PNRPsvc - ok 14:23:03.0471 6352 PolicyAgent (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll 14:23:03.0487 6352 PolicyAgent - ok 14:23:03.0503 6352 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll 14:23:03.0503 6352 Power - ok 14:23:03.0565 6352 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys 14:23:03.0565 6352 PptpMiniport - ok 14:23:03.0581 6352 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys 14:23:03.0581 6352 Processor - ok 14:23:03.0612 6352 ProfSvc (f381975e1f4346de875cb07339ce8d3a) C:\Windows\system32\profsvc.dll 14:23:03.0627 6352 ProfSvc - ok 14:23:03.0643 6352 ProtectedStorage (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe 14:23:03.0643 6352 ProtectedStorage - ok 14:23:03.0674 6352 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys 14:23:03.0690 6352 Psched - ok 14:23:03.0705 6352 PxHlpa64 (4712cc14e720ecccc0aa16949d18aaf1) C:\Windows\system32\Drivers\PxHlpa64.sys 14:23:03.0705 6352 PxHlpa64 - ok 14:23:03.0830 6352 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys 14:23:03.0846 6352 ql2300 - ok 14:23:03.0924 6352 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys 14:23:03.0924 6352 ql40xx - ok 14:23:03.0971 6352 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll 14:23:03.0971 6352 QWAVE - ok 14:23:03.0986 6352 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 14:23:03.0986 6352 QWAVEdrv - ok 14:23:03.0986 6352 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 14:23:03.0986 6352 RasAcd - ok 14:23:04.0017 6352 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 14:23:04.0017 6352 RasAgileVpn - ok 14:23:04.0033 6352 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll 14:23:04.0033 6352 RasAuto - ok 14:23:04.0049 6352 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys 14:23:04.0049 6352 Rasl2tp - ok 14:23:04.0095 6352 RasMan (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll 14:23:04.0111 6352 RasMan - ok 14:23:04.0111 6352 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 14:23:04.0127 6352 RasPppoe - ok 14:23:04.0127 6352 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 14:23:04.0127 6352 RasSstp - ok 14:23:04.0158 6352 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys 14:23:04.0158 6352 rdbss - ok 14:23:04.0173 6352 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys 14:23:04.0173 6352 rdpbus - ok 14:23:04.0189 6352 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 14:23:04.0189 6352 RDPCDD - ok 14:23:04.0189 6352 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 14:23:04.0205 6352 RDPENCDD - ok 14:23:04.0205 6352 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 14:23:04.0205 6352 RDPREFMP - ok 14:23:04.0251 6352 RDPWD (074ac702d8b8b660b0e1371555995386) C:\Windows\system32\drivers\RDPWD.sys 14:23:04.0251 6352 RDPWD - ok 14:23:04.0283 6352 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys 14:23:04.0283 6352 rdyboost - ok 14:23:04.0314 6352 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll 14:23:04.0314 6352 RemoteAccess - ok 14:23:04.0329 6352 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll 14:23:04.0329 6352 RemoteRegistry - ok 14:23:04.0517 6352 RoxMediaDB10 (05fc44d32a144925eae45570029fd6e1) c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe 14:23:04.0532 6352 RoxMediaDB10 - ok 14:23:04.0563 6352 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll 14:23:04.0563 6352 RpcEptMapper - ok 14:23:04.0579 6352 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe 14:23:04.0579 6352 RpcLocator - ok 14:23:04.0626 6352 RpcSs (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll 14:23:04.0641 6352 RpcSs - ok 14:23:04.0688 6352 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 14:23:04.0688 6352 rspndr - ok 14:23:04.0688 6352 RxFilter - ok 14:23:04.0704 6352 SamSs (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe 14:23:04.0704 6352 SamSs - ok 14:23:04.0735 6352 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys 14:23:04.0735 6352 sbp2port - ok 14:23:04.0751 6352 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll 14:23:04.0751 6352 SCardSvr - ok 14:23:04.0766 6352 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys 14:23:04.0766 6352 scfilter - ok 14:23:04.0844 6352 Schedule (ec56b171f85c7e855e7b0588ac503eea) C:\Windows\system32\schedsvc.dll 14:23:04.0860 6352 Schedule - ok 14:23:04.0875 6352 SCPolicySvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll 14:23:04.0875 6352 SCPolicySvc - ok 14:23:04.0891 6352 SDRSVC (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll 14:23:04.0907 6352 SDRSVC - ok 14:23:05.0016 6352 SeaPort (d358e077a0a05d9b12da22d137ee8464) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 14:23:05.0031 6352 SeaPort - ok 14:23:05.0047 6352 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 14:23:05.0047 6352 secdrv - ok 14:23:05.0078 6352 seclogon (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll 14:23:05.0078 6352 seclogon - ok 14:23:05.0109 6352 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll 14:23:05.0109 6352 SENS - ok 14:23:05.0125 6352 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll 14:23:05.0125 6352 SensrSvc - ok 14:23:05.0141 6352 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys 14:23:05.0141 6352 Serenum - ok 14:23:05.0156 6352 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys 14:23:05.0156 6352 Serial - ok 14:23:05.0187 6352 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys 14:23:05.0187 6352 sermouse - ok 14:23:05.0203 6352 SessionEnv (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll 14:23:05.0203 6352 SessionEnv - ok 14:23:05.0234 6352 SessionLauncher - ok 14:23:05.0250 6352 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys 14:23:05.0250 6352 sffdisk - ok 14:23:05.0250 6352 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys 14:23:05.0250 6352 sffp_mmc - ok 14:23:05.0250 6352 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys 14:23:05.0265 6352 sffp_sd - ok 14:23:05.0265 6352 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys 14:23:05.0265 6352 sfloppy - ok 14:23:05.0312 6352 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll 14:23:05.0312 6352 SharedAccess - ok 14:23:05.0359 6352 ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll 14:23:05.0359 6352 ShellHWDetection - ok 14:23:05.0375 6352 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys 14:23:05.0375 6352 SiSRaid2 - ok 14:23:05.0375 6352 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys 14:23:05.0375 6352 SiSRaid4 - ok 14:23:05.0406 6352 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 14:23:05.0406 6352 Smb - ok 14:23:05.0421 6352 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe 14:23:05.0421 6352 SNMPTRAP - ok 14:23:05.0421 6352 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 14:23:05.0421 6352 spldr - ok 14:23:05.0468 6352 Spooler (89e8550c5862999fcf482ea562b0e98e) C:\Windows\System32\spoolsv.exe 14:23:05.0468 6352 Spooler - ok 14:23:05.0687 6352 sppsvc (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe 14:23:05.0702 6352 sppsvc - ok 14:23:05.0811 6352 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll 14:23:05.0811 6352 sppuinotify - ok 14:23:05.0905 6352 sprtsvc_DellComms (d630b6f2e8379b6f10dc16e82a426552) C:\Program Files (x86)\Dell\DellComms\bin\sprtsvc.exe 14:23:05.0905 6352 sprtsvc_DellComms - ok 14:23:05.0967 6352 srv (ec8f67289105bf270498095f14963464) C:\Windows\system32\DRIVERS\srv.sys 14:23:05.0967 6352 srv - ok 14:23:06.0014 6352 srv2 (f773d2ed090b7baa1c1a034f3ca476c8) C:\Windows\system32\DRIVERS\srv2.sys 14:23:06.0014 6352 srv2 - ok 14:23:06.0030 6352 srvnet (26e84d3649019c3244622e654dfcd75b) C:\Windows\system32\DRIVERS\srvnet.sys 14:23:06.0045 6352 srvnet - ok 14:23:06.0077 6352 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll 14:23:06.0077 6352 SSDPSRV - ok 14:23:06.0092 6352 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll 14:23:06.0092 6352 SstpSvc - ok 14:23:06.0108 6352 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys 14:23:06.0108 6352 stexstor - ok 14:23:06.0170 6352 stisvc (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll 14:23:06.0186 6352 stisvc - ok 14:23:06.0264 6352 stllssvr (ff5eb78af7dfb68c2fb363537aaf753e) c:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe 14:23:06.0264 6352 stllssvr - ok 14:23:06.0279 6352 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys 14:23:06.0279 6352 swenum - ok 14:23:06.0326 6352 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll 14:23:06.0326 6352 swprv - ok 14:23:06.0435 6352 SysMain (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll 14:23:06.0451 6352 SysMain - ok 14:23:06.0576 6352 TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll 14:23:06.0576 6352 TabletInputService - ok 14:23:06.0623 6352 TapiSrv (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll 14:23:06.0623 6352 TapiSrv - ok 14:23:06.0654 6352 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll 14:23:06.0654 6352 TBS - ok 14:23:06.0825 6352 Tcpip (912107716bab424c7870e8e6af5e07e1) C:\Windows\system32\drivers\tcpip.sys 14:23:06.0841 6352 Tcpip - ok 14:23:06.0981 6352 TCPIP6 (912107716bab424c7870e8e6af5e07e1) C:\Windows\system32\DRIVERS\tcpip.sys 14:23:06.0997 6352 TCPIP6 - ok 14:23:07.0044 6352 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys 14:23:07.0044 6352 tcpipreg - ok 14:23:07.0059 6352 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 14:23:07.0059 6352 TDPIPE - ok 14:23:07.0091 6352 TDTCP (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys 14:23:07.0091 6352 TDTCP - ok 14:23:07.0106 6352 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys 14:23:07.0106 6352 tdx - ok 14:23:07.0106 6352 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys 14:23:07.0106 6352 TermDD - ok 14:23:07.0169 6352 TermService (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll 14:23:07.0184 6352 TermService - ok 14:23:07.0200 6352 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll 14:23:07.0200 6352 Themes - ok 14:23:07.0231 6352 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll 14:23:07.0231 6352 THREADORDER - ok 14:23:07.0247 6352 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll 14:23:07.0247 6352 TrkWks - ok 14:23:07.0309 6352 TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe 14:23:07.0309 6352 TrustedInstaller - ok 14:23:07.0325 6352 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys 14:23:07.0325 6352 tssecsrv - ok 14:23:07.0340 6352 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys 14:23:07.0340 6352 tunnel - ok 14:23:07.0356 6352 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys 14:23:07.0356 6352 uagp35 - ok 14:23:07.0371 6352 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys 14:23:07.0371 6352 udfs - ok 14:23:07.0387 6352 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe 14:23:07.0387 6352 UI0Detect - ok 14:23:07.0418 6352 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys 14:23:07.0418 6352 uliagpkx - ok 14:23:07.0418 6352 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys 14:23:07.0418 6352 umbus - ok 14:23:07.0449 6352 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys 14:23:07.0465 6352 UmPass - ok 14:23:07.0512 6352 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll 14:23:07.0527 6352 upnphost - ok 14:23:07.0543 6352 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys 14:23:07.0543 6352 usbccgp - ok 14:23:07.0559 6352 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys 14:23:07.0559 6352 usbcir - ok 14:23:07.0559 6352 usbehci (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys 14:23:07.0559 6352 usbehci - ok 14:23:07.0590 6352 usbhub (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys 14:23:07.0590 6352 usbhub - ok 14:23:07.0605 6352 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys 14:23:07.0605 6352 usbohci - ok 14:23:07.0637 6352 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 14:23:07.0637 6352 usbprint - ok 14:23:07.0637 6352 USBSTOR (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS 14:23:07.0637 6352 USBSTOR - ok 14:23:07.0668 6352 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys 14:23:07.0668 6352 usbuhci - ok 14:23:07.0683 6352 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll 14:23:07.0683 6352 UxSms - ok 14:23:07.0715 6352 VaultSvc (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe 14:23:07.0715 6352 VaultSvc - ok 14:23:07.0730 6352 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys 14:23:07.0730 6352 vdrvroot - ok 14:23:07.0777 6352 vds (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe 14:23:07.0793 6352 vds - ok 14:23:07.0808 6352 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 14:23:07.0808 6352 vga - ok 14:23:07.0808 6352 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 14:23:07.0808 6352 VgaSave - ok 14:23:07.0824 6352 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys 14:23:07.0839 6352 vhdmp - ok 14:23:07.0839 6352 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys 14:23:07.0839 6352 viaide - ok 14:23:07.0839 6352 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys 14:23:07.0839 6352 volmgr - ok 14:23:07.0871 6352 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys 14:23:07.0871 6352 volmgrx - ok 14:23:07.0886 6352 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys 14:23:07.0902 6352 volsnap - ok 14:23:07.0902 6352 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys 14:23:07.0917 6352 vsmraid - ok 14:23:08.0058 6352 VSS (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe 14:23:08.0073 6352 VSS - ok 14:23:08.0198 6352 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys 14:23:08.0198 6352 vwifibus - ok 14:23:08.0214 6352 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys 14:23:08.0214 6352 vwififlt - ok 14:23:08.0261 6352 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll 14:23:08.0276 6352 W32Time - ok 14:23:08.0276 6352 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys 14:23:08.0276 6352 WacomPen - ok 14:23:08.0307 6352 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 14:23:08.0307 6352 WANARP - ok 14:23:08.0307 6352 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys 14:23:08.0307 6352 Wanarpv6 - ok 14:23:08.0401 6352 wbengine (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe 14:23:08.0417 6352 wbengine - ok 14:23:08.0495 6352 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll 14:23:08.0495 6352 WbioSrvc - ok 14:23:08.0526 6352 wcncsvc (8321c2ca3b62b61b293cda3451984468) C:\Windows\System32\wcncsvc.dll 14:23:08.0526 6352 wcncsvc - ok 14:23:08.0541 6352 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll 14:23:08.0541 6352 WcsPlugInService - ok 14:23:08.0557 6352 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys 14:23:08.0557 6352 Wd - ok 14:23:08.0604 6352 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 14:23:08.0604 6352 Wdf01000 - ok 14:23:08.0619 6352 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll 14:23:08.0635 6352 WdiServiceHost - ok 14:23:08.0635 6352 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll 14:23:08.0635 6352 WdiSystemHost - ok 14:23:08.0651 6352 WebClient (8a438cbb8c032a0c798b0c642ffbe572) C:\Windows\System32\webclnt.dll 14:23:08.0666 6352 WebClient - ok 14:23:08.0682 6352 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll 14:23:08.0697 6352 Wecsvc - ok 14:23:08.0697 6352 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll 14:23:08.0713 6352 wercplsupport - ok 14:23:08.0729 6352 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll 14:23:08.0729 6352 WerSvc - ok 14:23:08.0760 6352 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 14:23:08.0760 6352 WfpLwf - ok 14:23:08.0760 6352 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 14:23:08.0760 6352 WIMMount - ok 14:23:08.0807 6352 WinDefend - ok 14:23:08.0807 6352 WinHttpAutoProxySvc - ok 14:23:08.0885 6352 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll 14:23:08.0885 6352 Winmgmt - ok 14:23:09.0041 6352 WinRM (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll 14:23:09.0056 6352 WinRM - ok 14:23:09.0212 6352 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll 14:23:09.0228 6352 Wlansvc - ok 14:23:09.0306 6352 wltrysvc (13b0a570e1ae451c92da550085d72cf3) C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE 14:23:09.0306 6352 wltrysvc - ok 14:23:09.0337 6352 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys 14:23:09.0337 6352 WmiAcpi - ok 14:23:09.0415 6352 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe 14:23:09.0415 6352 wmiApSrv - ok 14:23:09.0446 6352 WMPNetworkSvc - ok 14:23:09.0462 6352 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll 14:23:09.0477 6352 WPCSvc - ok 14:23:09.0493 6352 WPDBusEnum (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll 14:23:09.0493 6352 WPDBusEnum - ok 14:23:09.0509 6352 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 14:23:09.0509 6352 ws2ifsl - ok 14:23:09.0524 6352 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\System32\wscsvc.dll 14:23:09.0540 6352 wscsvc - ok 14:23:09.0540 6352 WSearch - ok 14:23:09.0711 6352 wuauserv (38340204a2d0228f1e87740fc5e554a7) C:\Windows\system32\wuaueng.dll 14:23:09.0727 6352 wuauserv - ok 14:23:09.0821 6352 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys 14:23:09.0821 6352 WudfPf - ok 14:23:09.0836 6352 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys 14:23:09.0836 6352 WUDFRd - ok 14:23:09.0852 6352 wudfsvc (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll 14:23:09.0852 6352 wudfsvc - ok 14:23:09.0883 6352 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll 14:23:09.0883 6352 WwanSvc - ok 14:23:09.0930 6352 MBR (0x1B8) (faf3db026c90f586e5993588661e2612) \Device\Harddisk0\DR0 14:23:09.0945 6352 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - infected 14:23:09.0945 6352 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.b (0) 14:23:09.0977 6352 Boot (0x1200) (a5c682221bb3be9ca89446427c662f59) \Device\Harddisk0\DR0\Partition0 14:23:09.0977 6352 \Device\Harddisk0\DR0\Partition0 - ok 14:23:09.0992 6352 Boot (0x1200) (2173d9f00b8f5ffc95b7fde2a9e0227f) \Device\Harddisk0\DR0\Partition1 14:23:09.0992 6352 \Device\Harddisk0\DR0\Partition1 - ok 14:23:09.0992 6352 ============================================================ 14:23:09.0992 6352 Scan finished 14:23:09.0992 6352 ============================================================ 14:23:10.0008 7048 Detected object count: 1 14:23:10.0008 7048 Actual detected object count: 1 14:23:15.0234 7048 \Device\Harddisk0\DR0\# - copied to quarantine 14:23:15.0249 7048 \Device\Harddisk0\DR0 - copied to quarantine 14:23:15.0296 7048 \Device\Harddisk0\DR0\TDLFS\ph.dll - copied to quarantine 14:23:19.0617 7048 \Device\Harddisk0\DR0\TDLFS\phx.dll - copied to quarantine 14:23:23.0923 7048 \Device\Harddisk0\DR0\TDLFS\sub.dll - copied to quarantine 14:23:23.0954 7048 \Device\Harddisk0\DR0\TDLFS\subx.dll - copied to quarantine 14:23:24.0017 7048 \Device\Harddisk0\DR0\TDLFS\phd - copied to quarantine 14:23:28.0728 7048 \Device\Harddisk0\DR0\TDLFS\phdx - copied to quarantine 14:23:28.0759 7048 \Device\Harddisk0\DR0\TDLFS\phs - copied to quarantine 14:23:28.0775 7048 \Device\Harddisk0\DR0\TDLFS\phdata - copied to quarantine 14:23:28.0806 7048 \Device\Harddisk0\DR0\TDLFS\phld - copied to quarantine 14:23:28.0806 7048 \Device\Harddisk0\DR0\TDLFS\phln - copied to quarantine 14:23:33.0174 7048 \Device\Harddisk0\DR0\TDLFS\phlx - copied to quarantine 14:23:37.0479 7048 \Device\Harddisk0\DR0\TDLFS\phm - copied to quarantine 14:23:37.0479 7048 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - will be cured on reboot 14:23:37.0479 7048 \Device\Harddisk0\DR0 - ok 14:23:37.0495 7048 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - User select action: Cure 14:23:49.0944 1448 Deinitialize success
Hi,

Alrighty….

Please download ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
    FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
    O1 - Hosts: 94.63.147.16		www.google.com
    O1 - Hosts: 94.63.147.17		www.bing.com
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4 - Startup: C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
    O33 - MountPoints2\{59036be1-c297-11de-976d-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{59036be1-c297-11de-976d-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Setup.exe – [2005/11/02 04:07:14 | 002,141,184 | R— | M] (Linksys)
    [2012/04/26 06:42:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Pando Networks
    [2012/04/26 12:24:44 | 000,302,080 | —- | M] () – C:\ProgramData\XkFcjVGVgWJhiQK.exe
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
ok here's the log

OTL logfile created on: 4/26/2012 2:42:29 PM - Run 3
OTL by OldTimer - Version 3.2.42.1 Folder = C:\Users\Jeffrey\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.99 Gb Total Physical Memory | 6.62 Gb Available Physical Memory | 82.80% Memory free
15.98 Gb Paging File | 14.38 Gb Available in Paging File | 90.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 916.82 Gb Total Space | 884.00 Gb Free Space | 96.42% Space Free | Partition Type: NTFS
Drive D: | 47.96 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: JEFFREY-PC | User Name: Jeffrey | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Jeffrey\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe (Alcor Micro Corp.)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Dell\DellComms\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files (x86)\Dell\DellComms\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)


========== Modules (No Company Name) ==========


========== Win32 Services (SafeList) ==========

SRV:64bit: - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV:64bit: - (mfevtp) – C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV:64bit: - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:64bit: - (McProxy) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNASvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNaiAnn) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (mcmscsvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McMPFSvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (wltrysvc) – C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AERTFilters) – C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (RoxMediaDB10) – c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCom\RoxMediaDB10.exe (Sonic Solutions)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (sprtsvc_DellComms) SupportSoft Sprocket Service (DellComms) – C:\Program Files (x86)\Dell\DellComms\bin\sprtsvc.exe (SupportSoft, Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (mfehidk) – C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfefirek) – C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) – C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) – C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) – C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) – C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfenlfk) – C:\Windows\SysNative\drivers\mfenlfk.sys (McAfee, Inc.)
DRV:64bit: - (cfwids) – C:\Windows\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:64bit: - (BCM42RLY) – C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (k57nd60a) Broadcom NetLink ™ – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (netr7364) – C:\Windows\SysNative\drivers\netr7364.sys (Ralink Technology, Corp.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (RxFilter) – C:\Windows\SysWOW64\drivers\RxFilter.sys (Sonic Solutions)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {BB3CD05B-CE76-421B-9D22-4F90AFCC84BE}
IE:64bit: - HKLM\..\SearchScopes\{BB3CD05B-CE76-421B-9D22-4F90AFCC84BE}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {21D8C4A7-970D-4552-B93C-DF45A08E608F}
IE - HKLM\..\SearchScopes\{21D8C4A7-970D-4552-B93C-DF45A08E608F}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {21D8C4A7-970D-4552-B93C-DF45A08E608F}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~2\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\3.0.40624.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/04/26 11:54:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012/04/26 11:54:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/04/26 06:36:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2012/04/26 06:36:35 | 000,000,000 | —D | M] (No name found) – C:\Users\Jeffrey\AppData\Roaming\Mozilla\Extensions
[2012/04/26 06:36:04 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/04/26 11:54:27 | 000,000,000 | —D | M] (McAfee ScriptScan for Firefox) – C:\PROGRAM FILES (X86)\COMMON FILES\MCAFEE\SYSTEMCORE
[2012/04/26 11:54:27 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR
[2012/04/20 21:19:34 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/04/20 21:18:25 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/04/20 21:18:25 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/04/26 05:08:54 | 000,000,882 | RH– | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 94.63.147.16 www.google.com
O1 - Hosts: 94.63.147.17 www.bing.com
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120426062939.dll (McAfee, Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120426103358.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe File not found
O4 - HKLM..\Run: [DellComms] C:\Program Files (x86)\Dell\DellComms\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [ShwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe (Alcor Micro Corp.)
O4 - HKLM..\RunOnceEx: [ContentMerger] c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCom\ContentMerger10.exe (Sonic Solutions)
O4 - Startup: C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O4 - Startup: C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files (x86)\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FA6CD502-6B10-4BFF-AE2B-4F70894A85D1}: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (GTGina.dll) - File not found
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/02/28 23:42:20 | 000,000,051 | R— | M] () - D:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{59036be1-c297-11de-976d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{59036be1-c297-11de-976d-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Setup.exe – [2005/11/02 04:07:14 | 002,141,184 | R— | M] (Linksys)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/04/26 14:37:31 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012/04/26 14:36:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012/04/26 14:36:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\ERUNT
[2012/04/26 14:32:41 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\Microsoft Games
[2012/04/26 13:37:47 | 000,595,968 | —- | C] (OldTimer Tools) – C:\Users\Jeffrey\Desktop\OTL.exe
[2012/04/26 12:30:23 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2012/04/26 12:24:27 | 000,000,000 | —D | C] – C:\Windows\Sun
[2012/04/26 12:09:28 | 000,000,000 | —D | C] – C:\Users\Jeffrey\Documents\Autoruns
[2012/04/26 11:53:10 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2012/04/26 11:52:34 | 000,000,000 | —D | C] – C:\Users\Jeffrey\Documents\tdsskiller
[2012/04/26 10:54:46 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_39.dll
[2012/04/26 10:54:46 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_39.dll
[2012/04/26 10:54:46 | 000,509,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_2.dll
[2012/04/26 10:54:46 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_39.dll
[2012/04/26 10:54:46 | 000,068,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_1.dll
[2012/04/26 10:52:15 | 000,000,000 | —D | C] – C:\Riot Games
[2012/04/26 10:52:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
[2012/04/26 06:43:34 | 000,000,000 | —D | C] – C:\Users\Jeffrey\Desktop\LeagueOfLegends
[2012/04/26 06:43:20 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\PMB Files
[2012/04/26 06:43:19 | 000,000,000 | —D | C] – C:\ProgramData\PMB Files
[2012/04/26 06:42:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Pando Networks
[2012/04/26 06:36:28 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\Mozilla
[2012/04/26 06:36:28 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\Mozilla
[2012/04/26 06:36:14 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2012/04/26 06:36:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Maintenance Service
[2012/04/26 06:36:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012/04/26 06:30:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/04/26 06:29:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\McAfee.com
[2012/04/26 06:29:39 | 000,010,248 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeclnk.sys
[2012/04/26 06:29:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\McAfee
[2012/04/26 06:29:11 | 000,487,296 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfefirek.sys
[2012/04/26 06:29:11 | 000,289,664 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfewfpk.sys
[2012/04/26 06:29:11 | 000,229,528 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeavfk.sys
[2012/04/26 06:29:11 | 000,100,912 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mferkdet.sys
[2012/04/26 06:29:11 | 000,075,936 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfenlfk.sys
[2012/04/26 06:29:11 | 000,065,264 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\cfwids.sys
[2012/04/26 06:29:06 | 000,000,000 | —D | C] – C:\Program Files\Common Files\McAfee
[2012/04/26 06:29:05 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[2012/04/26 06:29:05 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2012/04/26 06:29:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\McAfee
[2012/04/26 06:13:47 | 000,162,192 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\mfevtps.exe
[2012/04/26 06:13:44 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2012/04/26 06:08:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Compact Wireless-G USB Adapter Wireless Network Monitor
[2012/04/26 06:07:40 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\CyberLink
[2012/04/26 06:05:04 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\Dell
[2012/04/26 06:04:57 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\SupportSoft
[2012/04/26 06:04:56 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\Stardock_Corporation
[2012/04/26 06:04:43 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Searches
[2012/04/26 06:04:43 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/04/26 06:04:43 | 000,000,000 | -H-D | C] – C:\Users\Jeffrey\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012/04/26 06:04:36 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\Identities
[2012/04/26 06:04:34 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Contacts
[2012/04/26 06:04:33 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\VirtualStore
[2012/04/26 06:02:09 | 000,000,000 | –SD | C] – C:\Users\Jeffrey\AppData\Roaming\Microsoft
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Videos
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Saved Games
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Pictures
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Music
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Links
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Favorites
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Downloads
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Documents
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Desktop
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\AppData\Local\Temporary Internet Files
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Templates
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Start Menu
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\SendTo
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Recent
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\PrintHood
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\NetHood
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Documents\My Videos
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Documents\My Pictures
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Documents\My Music
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\My Documents
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Local Settings
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\AppData\Local\History
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Cookies
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Application Data
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\AppData\Local\Application Data
[2012/04/26 06:02:09 | 000,000,000 | -H-D | C] – C:\Users\Jeffrey\AppData
[2012/04/26 06:02:09 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\Temp
[2012/04/26 06:02:09 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\Microsoft
[2012/04/26 06:02:09 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\Media Center Programs
[2012/04/26 05:59:19 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\svchost.exe
[2012/04/26 05:58:04 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2012/04/26 05:39:16 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\Macromedia
[2012/04/26 05:39:13 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\Adobe
[2012/04/26 05:12:59 | 001,031,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcore.dll
[2012/04/26 05:12:59 | 000,826,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpcore.dll
[2012/04/26 05:12:48 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2012/04/26 05:12:48 | 000,139,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cabview.dll
[2012/04/26 05:12:48 | 000,132,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cabview.dll
[2012/04/26 05:12:48 | 000,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2012/04/26 05:12:48 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe

========== Files - Modified Within 30 Days ==========

[2012/04/26 14:41:47 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/04/26 14:41:42 | 2140,495,871 | -HS- | M] () – C:\hiberfil.sys
[2012/04/26 14:37:14 | 000,001,110 | —- | M] () – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/04/26 14:36:59 | 000,000,930 | —- | M] () – C:\Users\Jeffrey\Desktop\NTREGOPT.lnk
[2012/04/26 14:36:59 | 000,000,911 | —- | M] () – C:\Users\Jeffrey\Desktop\ERUNT.lnk
[2012/04/26 14:31:48 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/26 14:31:48 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/26 14:30:48 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/04/26 14:30:48 | 000,615,122 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/04/26 14:30:48 | 000,103,496 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/04/26 14:28:58 | 000,001,830 | —- | M] () – C:\Users\Public\Desktop\McAfee Security Center.lnk
[2012/04/26 13:37:53 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Users\Jeffrey\Desktop\OTL.exe
[2012/04/26 12:30:20 | 470,465,247 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/04/26 12:24:44 | 000,302,080 | —- | M] () – C:\ProgramData\XkFcjVGVgWJhiQK.exe
[2012/04/26 10:54:46 | 000,001,722 | —- | M] () – C:\Users\Public\Desktop\Play League of Legends.lnk
[2012/04/26 06:36:17 | 000,001,136 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/04/26 06:08:03 | 000,001,361 | —- | M] () – C:\Windows\SysWow64\WLAN.INI
[2012/04/26 06:04:58 | 000,001,984 | —- | M] () – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
[2012/04/26 05:59:51 | 000,039,252 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2012/04/26 05:59:51 | 000,039,252 | —- | M] () – C:\Windows\SysNative\license.rtf
[2012/04/26 05:39:02 | 000,001,443 | —- | M] () – C:\Users\Jeffrey\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

========== Files Created - No Company Name ==========

[2012/04/26 14:37:14 | 000,001,110 | —- | C] () – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/04/26 14:36:59 | 000,000,930 | —- | C] () – C:\Users\Jeffrey\Desktop\NTREGOPT.lnk
[2012/04/26 14:36:59 | 000,000,911 | —- | C] () – C:\Users\Jeffrey\Desktop\ERUNT.lnk
[2012/04/26 12:30:20 | 470,465,247 | —- | C] () – C:\Windows\MEMORY.DMP
[2012/04/26 12:26:47 | 000,302,080 | —- | C] () – C:\ProgramData\XkFcjVGVgWJhiQK.exe
[2012/04/26 10:54:46 | 000,001,722 | —- | C] () – C:\Users\Public\Desktop\Play League of Legends.lnk
[2012/04/26 06:36:17 | 000,001,148 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/04/26 06:36:17 | 000,001,136 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/04/26 06:30:21 | 000,001,830 | —- | C] () – C:\Users\Public\Desktop\McAfee Security Center.lnk
[2012/04/26 06:04:58 | 000,001,984 | —- | C] () – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
[2012/04/26 06:04:48 | 000,001,415 | —- | C] () – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012/04/26 06:04:45 | 000,001,449 | —- | C] () – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/04/26 06:02:20 | 000,001,979 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Help Documentation.lnk
[2012/04/26 06:02:09 | 000,001,802 | —- | C] () – C:\Users\Jeffrey\Desktop\Free year of music from Dell.lnk
[2012/04/26 06:02:09 | 000,000,290 | —- | C] () – C:\Users\Jeffrey\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/04/26 06:02:09 | 000,000,272 | —- | C] () – C:\Users\Jeffrey\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012/04/26 05:58:00 | 2140,495,871 | -HS- | C] () – C:\hiberfil.sys
[2012/04/26 05:39:02 | 000,001,443 | —- | C] () – C:\Users\Jeffrey\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

< End of report >


btw erunt tried to do its start up thing and then i got some error message about not having access to some file so i just hit ok
Hmmmm… Doesn't look like the fix took. Please run the same set of instructions that I provided earlier for OTL and post the newly made log. :)
now i'm supposed to have the purity check and the other one on for the first scan right? but not the second?
ok cuz your instructions said i shouldn't have them on the scan after the reboot but didn't say anything about the one before the reboot so i thought they had to be checked for it. i've redone the fix and rebooted. waiting on the log for the after reboot scan now
ok i'm still doing the second scan but i just got this message from the windows activity center saying all my anti spyware stuff just turned off. is that normal?
ok here's the log

OTL logfile created on: 4/26/2012 3:06:15 PM - Run 5
OTL by OldTimer - Version 3.2.42.1 Folder = C:\Users\Jeffrey\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.99 Gb Total Physical Memory | 6.65 Gb Available Physical Memory | 83.25% Memory free
15.98 Gb Paging File | 14.44 Gb Available in Paging File | 90.36% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 916.82 Gb Total Space | 884.31 Gb Free Space | 96.45% Space Free | Partition Type: NTFS
Drive D: | 47.96 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: JEFFREY-PC | User Name: Jeffrey | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Jeffrey\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe (Alcor Micro Corp.)
PRC - \\.\globalroot\systemroot\svchost.exe ()
PRC - \\.\globalroot\systemroot\svchost.exe ()
PRC - \\.\globalroot\systemroot\svchost.exe ()
PRC - C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Dell\DellComms\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files (x86)\Dell\DellComms\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV:64bit: - (mfevtp) – C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV:64bit: - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:64bit: - (McProxy) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNASvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNaiAnn) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (mcmscsvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McMPFSvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (wltrysvc) – C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AERTFilters) – C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (RoxMediaDB10) – c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCom\RoxMediaDB10.exe (Sonic Solutions)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (sprtsvc_DellComms) SupportSoft Sprocket Service (DellComms) – C:\Program Files (x86)\Dell\DellComms\bin\sprtsvc.exe (SupportSoft, Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (mfehidk) – C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfefirek) – C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) – C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) – C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) – C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) – C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfenlfk) – C:\Windows\SysNative\drivers\mfenlfk.sys (McAfee, Inc.)
DRV:64bit: - (cfwids) – C:\Windows\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:64bit: - (BCM42RLY) – C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (k57nd60a) Broadcom NetLink ™ – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (netr7364) – C:\Windows\SysNative\drivers\netr7364.sys (Ralink Technology, Corp.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (RxFilter) – C:\Windows\SysWOW64\drivers\RxFilter.sys (Sonic Solutions)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {BB3CD05B-CE76-421B-9D22-4F90AFCC84BE}
IE:64bit: - HKLM\..\SearchScopes\{BB3CD05B-CE76-421B-9D22-4F90AFCC84BE}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {21D8C4A7-970D-4552-B93C-DF45A08E608F}
IE - HKLM\..\SearchScopes\{21D8C4A7-970D-4552-B93C-DF45A08E608F}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {21D8C4A7-970D-4552-B93C-DF45A08E608F}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~2\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\3.0.40624.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/04/26 11:54:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012/04/26 11:54:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/04/26 06:36:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2012/04/26 06:36:35 | 000,000,000 | —D | M] (No name found) – C:\Users\Jeffrey\AppData\Roaming\Mozilla\Extensions
[2012/04/26 06:36:04 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/04/26 11:54:27 | 000,000,000 | —D | M] (McAfee ScriptScan for Firefox) – C:\PROGRAM FILES (X86)\COMMON FILES\MCAFEE\SYSTEMCORE
[2012/04/26 11:54:27 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR
[2012/04/20 21:19:34 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/04/20 21:18:25 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/04/20 21:18:25 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/04/26 05:08:54 | 000,000,882 | RH– | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 94.63.147.16 www.google.com
O1 - Hosts: 94.63.147.17 www.bing.com
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120426062939.dll (McAfee, Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120426103358.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe File not found
O4 - HKLM..\Run: [DellComms] C:\Program Files (x86)\Dell\DellComms\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [ShwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe (Alcor Micro Corp.)
O4 - HKLM..\RunOnceEx: [ContentMerger] c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCom\ContentMerger10.exe (Sonic Solutions)
O4 - Startup: C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O4 - Startup: C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files (x86)\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FA6CD502-6B10-4BFF-AE2B-4F70894A85D1}: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (GTGina.dll) - File not found
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/02/28 23:42:20 | 000,000,051 | R— | M] () - D:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{59036be1-c297-11de-976d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{59036be1-c297-11de-976d-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Setup.exe – [2005/11/02 04:07:14 | 002,141,184 | R— | M] (Linksys)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/04/26 14:37:31 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012/04/26 14:36:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012/04/26 14:36:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\ERUNT
[2012/04/26 14:32:41 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\Microsoft Games
[2012/04/26 13:37:47 | 000,595,968 | —- | C] (OldTimer Tools) – C:\Users\Jeffrey\Desktop\OTL.exe
[2012/04/26 12:30:23 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2012/04/26 12:24:27 | 000,000,000 | —D | C] – C:\Windows\Sun
[2012/04/26 12:09:28 | 000,000,000 | —D | C] – C:\Users\Jeffrey\Documents\Autoruns
[2012/04/26 11:53:10 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2012/04/26 11:52:34 | 000,000,000 | —D | C] – C:\Users\Jeffrey\Documents\tdsskiller
[2012/04/26 10:54:46 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DX9_39.dll
[2012/04/26 10:54:46 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_39.dll
[2012/04/26 10:54:46 | 000,509,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAudio2_2.dll
[2012/04/26 10:54:46 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_39.dll
[2012/04/26 10:54:46 | 000,068,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XAPOFX1_1.dll
[2012/04/26 10:52:15 | 000,000,000 | —D | C] – C:\Riot Games
[2012/04/26 10:52:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
[2012/04/26 06:43:34 | 000,000,000 | —D | C] – C:\Users\Jeffrey\Desktop\LeagueOfLegends
[2012/04/26 06:43:20 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\PMB Files
[2012/04/26 06:43:19 | 000,000,000 | —D | C] – C:\ProgramData\PMB Files
[2012/04/26 06:42:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Pando Networks
[2012/04/26 06:36:28 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\Mozilla
[2012/04/26 06:36:28 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\Mozilla
[2012/04/26 06:36:14 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2012/04/26 06:36:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Maintenance Service
[2012/04/26 06:36:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012/04/26 06:30:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/04/26 06:29:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\McAfee.com
[2012/04/26 06:29:39 | 000,010,248 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeclnk.sys
[2012/04/26 06:29:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\McAfee
[2012/04/26 06:29:11 | 000,487,296 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfefirek.sys
[2012/04/26 06:29:11 | 000,289,664 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfewfpk.sys
[2012/04/26 06:29:11 | 000,229,528 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfeavfk.sys
[2012/04/26 06:29:11 | 000,100,912 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mferkdet.sys
[2012/04/26 06:29:11 | 000,075,936 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\mfenlfk.sys
[2012/04/26 06:29:11 | 000,065,264 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\cfwids.sys
[2012/04/26 06:29:06 | 000,000,000 | —D | C] – C:\Program Files\Common Files\McAfee
[2012/04/26 06:29:05 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[2012/04/26 06:29:05 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2012/04/26 06:29:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\McAfee
[2012/04/26 06:13:47 | 000,162,192 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\mfevtps.exe
[2012/04/26 06:13:44 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2012/04/26 06:08:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Compact Wireless-G USB Adapter Wireless Network Monitor
[2012/04/26 06:07:40 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\CyberLink
[2012/04/26 06:05:04 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\Dell
[2012/04/26 06:04:57 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\SupportSoft
[2012/04/26 06:04:56 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\Stardock_Corporation
[2012/04/26 06:04:43 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Searches
[2012/04/26 06:04:43 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/04/26 06:04:43 | 000,000,000 | -H-D | C] – C:\Users\Jeffrey\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012/04/26 06:04:36 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\Identities
[2012/04/26 06:04:34 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Contacts
[2012/04/26 06:04:33 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\VirtualStore
[2012/04/26 06:02:09 | 000,000,000 | –SD | C] – C:\Users\Jeffrey\AppData\Roaming\Microsoft
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Videos
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Saved Games
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Pictures
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Music
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Links
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Favorites
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Downloads
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Documents
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\Desktop
[2012/04/26 06:02:09 | 000,000,000 | R–D | C] – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\AppData\Local\Temporary Internet Files
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Templates
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Start Menu
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\SendTo
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Recent
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\PrintHood
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\NetHood
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Documents\My Videos
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Documents\My Pictures
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Documents\My Music
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\My Documents
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Local Settings
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\AppData\Local\History
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Cookies
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\Application Data
[2012/04/26 06:02:09 | 000,000,000 | -HSD | C] – C:\Users\Jeffrey\AppData\Local\Application Data
[2012/04/26 06:02:09 | 000,000,000 | -H-D | C] – C:\Users\Jeffrey\AppData
[2012/04/26 06:02:09 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\Temp
[2012/04/26 06:02:09 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Local\Microsoft
[2012/04/26 06:02:09 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\Media Center Programs
[2012/04/26 05:59:19 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\svchost.exe
[2012/04/26 05:58:04 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2012/04/26 05:39:16 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\Macromedia
[2012/04/26 05:39:13 | 000,000,000 | —D | C] – C:\Users\Jeffrey\AppData\Roaming\Adobe
[2012/04/26 05:12:59 | 001,031,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcore.dll
[2012/04/26 05:12:59 | 000,826,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpcore.dll
[2012/04/26 05:12:48 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2012/04/26 05:12:48 | 000,139,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cabview.dll
[2012/04/26 05:12:48 | 000,132,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cabview.dll
[2012/04/26 05:12:48 | 000,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2012/04/26 05:12:48 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe

========== Files - Modified Within 30 Days ==========

[2012/04/26 15:03:26 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/04/26 15:03:22 | 2140,495,871 | -HS- | M] () – C:\hiberfil.sys
[2012/04/26 14:49:12 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/26 14:49:12 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/26 14:47:45 | 000,713,888 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/04/26 14:47:45 | 000,615,122 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/04/26 14:47:45 | 000,103,496 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/04/26 14:46:09 | 000,001,830 | —- | M] () – C:\Users\Public\Desktop\McAfee Security Center.lnk
[2012/04/26 14:37:14 | 000,001,110 | —- | M] () – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/04/26 14:36:59 | 000,000,930 | —- | M] () – C:\Users\Jeffrey\Desktop\NTREGOPT.lnk
[2012/04/26 14:36:59 | 000,000,911 | —- | M] () – C:\Users\Jeffrey\Desktop\ERUNT.lnk
[2012/04/26 13:37:53 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Users\Jeffrey\Desktop\OTL.exe
[2012/04/26 12:30:20 | 470,465,247 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/04/26 12:24:44 | 000,302,080 | —- | M] () – C:\ProgramData\XkFcjVGVgWJhiQK.exe
[2012/04/26 10:54:46 | 000,001,722 | —- | M] () – C:\Users\Public\Desktop\Play League of Legends.lnk
[2012/04/26 06:36:17 | 000,001,136 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/04/26 06:08:03 | 000,001,361 | —- | M] () – C:\Windows\SysWow64\WLAN.INI
[2012/04/26 06:04:58 | 000,001,984 | —- | M] () – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
[2012/04/26 05:59:51 | 000,039,252 | —- | M] () – C:\Windows\SysWow64\license.rtf
[2012/04/26 05:59:51 | 000,039,252 | —- | M] () – C:\Windows\SysNative\license.rtf
[2012/04/26 05:39:02 | 000,001,443 | —- | M] () – C:\Users\Jeffrey\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

========== Files Created - No Company Name ==========

[2012/04/26 14:37:14 | 000,001,110 | —- | C] () – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/04/26 14:36:59 | 000,000,930 | —- | C] () – C:\Users\Jeffrey\Desktop\NTREGOPT.lnk
[2012/04/26 14:36:59 | 000,000,911 | —- | C] () – C:\Users\Jeffrey\Desktop\ERUNT.lnk
[2012/04/26 12:30:20 | 470,465,247 | —- | C] () – C:\Windows\MEMORY.DMP
[2012/04/26 12:26:47 | 000,302,080 | —- | C] () – C:\ProgramData\XkFcjVGVgWJhiQK.exe
[2012/04/26 10:54:46 | 000,001,722 | —- | C] () – C:\Users\Public\Desktop\Play League of Legends.lnk
[2012/04/26 06:36:17 | 000,001,148 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/04/26 06:36:17 | 000,001,136 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/04/26 06:30:21 | 000,001,830 | —- | C] () – C:\Users\Public\Desktop\McAfee Security Center.lnk
[2012/04/26 06:04:58 | 000,001,984 | —- | C] () – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
[2012/04/26 06:04:48 | 000,001,415 | —- | C] () – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012/04/26 06:04:45 | 000,001,449 | —- | C] () – C:\Users\Jeffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/04/26 06:02:20 | 000,001,979 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Help Documentation.lnk
[2012/04/26 06:02:09 | 000,001,802 | —- | C] () – C:\Users\Jeffrey\Desktop\Free year of music from Dell.lnk
[2012/04/26 06:02:09 | 000,000,290 | —- | C] () – C:\Users\Jeffrey\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/04/26 06:02:09 | 000,000,272 | —- | C] () – C:\Users\Jeffrey\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012/04/26 05:58:00 | 2140,495,871 | -HS- | C] () – C:\hiberfil.sys
[2012/04/26 05:39:02 | 000,001,443 | —- | C] () – C:\Users\Jeffrey\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI