This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Yet another "recommended for you" pop-up guy [Solved]

137 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Looks like you guys are being overrun by these, but I figured I'll play it safe and not try to "retrofit" your answers to someone else to fit my situation. It seems to be the standard "scroll-up pop-up" in an iPhone frame, most of the time. Occasionally it's a different frame, or just a small "recommended for you" box in the lower right. On occasion, when click on links, it'll "redirect" me to some random sales site. This pop-up has actually been on my computer for a bit, but for awhile, it only seemed to pop up on one site - so I figured it was some sort of issue with that site rather than with my computer. But now it seems to show up periodically no matter where I am. It's still not overly common, and it doesn't appear to be slowing my system down any, but I'm not happy with the frequency increasing. Malwarebytes, Ad-Aware and Spybot don't seem to notice it. Lemme know what you need from me - I'm in your capable/culpable hands. :)
Hello Ratchet and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Download and run OTL
  • download OTL to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • click Scan all users.
  • under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    consrv.dll
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT

  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • you may need two posts to fit them both in.
===================================================

Run aswMBR

  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Logs to include with next post:

OTL.txt
Extras.txt
aswMBR log


Thanks

Satchfan
Thanks for taking me on, satchfan. I'm a jazz fan too, if that's a Louis Armstrong reference. :)

Here are the scan logs you requested.

OTL.txt

OTL logfile created on: 5/16/2012 7:53:41 PM - Run 1
OTL by OldTimer - Version 3.2.43.0 Folder = C:\Users\alf\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.98 Gb Total Physical Memory | 4.79 Gb Available Physical Memory | 80.09% Memory free
11.96 Gb Paging File | 10.00 Gb Available in Paging File | 83.57% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 918.22 Gb Total Space | 691.33 Gb Free Space | 75.29% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Drive H: | 3.81 Gb Total Space | 3.76 Gb Free Space | 98.66% Space Free | Partition Type: FAT32

Computer Name: ALF-PC | User Name: alf | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/05/16 19:48:48 | 000,595,456 | —- | M] (OldTimer Tools) – C:\Users\alf\Desktop\OTL.exe
PRC - [2012/05/11 22:49:08 | 002,152,688 | —- | M] (Lavasoft Limited) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2012/05/11 22:49:08 | 001,191,728 | —- | M] (Lavasoft Limited) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2012/02/14 17:03:14 | 024,246,216 | —- | M] (Dropbox, Inc.) – C:\Users\alf\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2012/01/03 06:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/10/01 09:30:22 | 000,219,496 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011/10/01 09:30:18 | 000,508,776 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2011/08/18 10:05:54 | 002,751,808 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
PRC - [2011/08/18 10:05:46 | 001,692,480 | —- | M] (SoftThinks SAS) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
PRC - [2011/08/01 12:56:48 | 000,460,096 | —- | M] (SoftThinks - Dell) – C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
PRC - [2011/06/16 07:55:12 | 006,276,408 | —- | M] (Yahoo! Inc.) – C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2010/11/17 09:35:34 | 000,514,544 | —- | M] () – C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
PRC - [2010/09/13 17:32:32 | 000,013,336 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/09/13 17:32:30 | 000,283,160 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2010/03/10 15:26:30 | 000,237,568 | —- | M] (Alcor Micro Corp.) – C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe
PRC - [2009/01/26 16:31:16 | 002,144,088 | RHS- | M] (Safer Networking Limited) – C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/01/26 16:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe


========== Modules (No Company Name) ==========

MOD - [2012/05/13 03:39:25 | 000,014,336 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\220b0516e45e7f9bbf6a631490c1243a\IAStorCommon.ni.dll
MOD - [2012/05/13 03:39:24 | 000,475,136 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\6c30b231f838269283ee449bbc98b202\IAStorUtil.ni.dll
MOD - [2012/05/13 03:37:44 | 011,833,344 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\1a690902e9a6293de228c16fab21e2f7\System.Web.ni.dll
MOD - [2012/05/13 03:37:41 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
MOD - [2012/05/13 03:37:26 | 012,433,408 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\90555968565afd59bce4b0974e9903bd\System.Windows.Forms.ni.dll
MOD - [2012/05/13 03:37:22 | 001,590,784 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\69f6e582cb79f107c61308b468c1a215\System.Drawing.ni.dll
MOD - [2012/05/13 03:37:15 | 003,347,968 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
MOD - [2012/05/13 03:37:12 | 005,452,800 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012/05/13 03:37:10 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012/05/13 03:37:09 | 007,967,232 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012/05/13 03:37:05 | 011,492,864 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2011/08/18 10:05:54 | 002,751,808 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
MOD - [2011/06/24 22:56:36 | 000,087,328 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 22:56:14 | 001,241,888 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/06/16 07:55:10 | 000,925,696 | —- | M] () – C:\Program Files (x86)\Yahoo!\Messenger\yui.dll
MOD - [2011/06/16 07:55:10 | 000,078,336 | —- | M] () – C:\Program Files (x86)\Yahoo!\Messenger\pcre.dll
MOD - [2010/11/24 21:44:02 | 000,375,280 | —- | M] () – c:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\SQLite352.dll
MOD - [2010/11/20 21:24:09 | 000,232,448 | —- | M] () – \\?\globalroot\systemroot\syswow64\mswsock.DLL
MOD - [2010/11/20 21:24:09 | 000,232,448 | —- | M] () – \\.\globalroot\systemroot\syswow64\mswsock.dll
MOD - [2010/11/17 09:35:34 | 000,514,544 | —- | M] () – C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/01/05 06:57:46 | 000,203,776 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV - [2012/05/11 22:49:08 | 002,152,688 | —- | M] (Lavasoft Limited) [Auto | Running] – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service)
SRV - [2012/05/06 10:59:08 | 000,129,976 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/01/03 06:10:42 | 000,063,928 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/10/01 09:30:22 | 000,219,496 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe – (sftvsa)
SRV - [2011/10/01 09:30:18 | 000,508,776 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe – (sftlist)
SRV - [2011/08/18 10:05:46 | 001,692,480 | —- | M] (SoftThinks SAS) [Auto | Running] – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe – (SftService)
SRV - [2011/07/22 21:22:57 | 001,045,256 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2010/11/25 04:34:18 | 000,219,632 | —- | M] (Sonic Solutions) [Auto | Stopped] – C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe – (RoxWatch12)
SRV - [2010/11/25 04:33:18 | 001,116,656 | —- | M] (Sonic Solutions) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe – (RoxMediaDB12OEM)
SRV - [2010/09/13 17:32:32 | 000,013,336 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc) Intel®
SRV - [2010/08/25 19:28:54 | 002,823,000 | —- | M] (Dell, Inc.) [Auto | Running] – C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe – (NOBU)
SRV - [2010/03/18 15:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 15:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/03/01 00:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/11/03 13:06:56 | 000,069,376 | —- | M] (Lavasoft AB) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\Lbd.sys – (Lbd)
DRV:64bit: - [2011/10/01 09:30:22 | 000,022,376 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftvollh.sys – (Sftvol)
DRV:64bit: - [2011/10/01 09:30:18 | 000,268,648 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftplaylh.sys – (Sftplay)
DRV:64bit: - [2011/10/01 09:30:18 | 000,025,960 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftredirlh.sys – (Sftredir)
DRV:64bit: - [2011/10/01 09:30:10 | 000,764,264 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Sftfslh.sys – (Sftfs)
DRV:64bit: - [2011/07/22 23:01:41 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/07/22 23:01:41 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/05/10 08:06:08 | 000,051,712 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2011/01/05 07:37:16 | 008,283,136 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmdag.sys – (amdkmdag)
DRV:64bit: - [2011/01/05 06:19:40 | 000,294,400 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2010/11/20 21:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/20 21:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 21:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010/11/17 16:04:32 | 000,115,216 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AtihdW76.sys – (AtiHDAudioService)
DRV:64bit: - [2010/10/15 19:28:18 | 000,317,440 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud) Intel®
DRV:64bit: - [2010/09/21 21:59:38 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (MEIx64) Intel®
DRV:64bit: - [2010/09/14 06:24:26 | 000,437,272 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2010/06/08 06:36:18 | 000,406,056 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\k57nd60a.sys – (k57nd60a) Broadcom NetLink ™
DRV:64bit: - [2010/05/20 17:42:44 | 003,058,168 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\BCMWL664.SYS – (BCM43XX)
DRV:64bit: - [2010/03/19 02:00:00 | 000,055,856 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2010/02/27 09:32:14 | 000,158,976 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2009/07/13 19:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 19:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 19:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 14:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 14:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 14:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 14:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2006/11/01 11:51:00 | 000,151,656 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\WimFltr.sys – (WimFltr)
DRV - [2011/12/23 23:49:45 | 000,017,152 | —- | M] () [Kernel | On_Demand | Running] – C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys – (Lavasoft Kernexplorer)
DRV - [2009/07/13 19:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {49606DC7-976D-4030-A74E-9FB5C842FA68}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {49606DC7-976D-4030-A74E-9FB5C842FA68}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2109051053-2815559744-1473108664-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKU\S-1-5-21-2109051053-2815559744-1473108664-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/1
IE - HKU\S-1-5-21-2109051053-2815559744-1473108664-1001\..\SearchScopes,DefaultScope = {49606DC7-976D-4030-A74E-9FB5C842FA68}
IE - HKU\S-1-5-21-2109051053-2815559744-1473108664-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2109051053-2815559744-1473108664-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"


FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/05/15 19:54:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011/08/05 21:19:44 | 000,000,000 | —D | M] (No name found) – C:\Users\alf\AppData\Roaming\Mozilla\Extensions
[2012/05/01 20:56:40 | 000,000,000 | —D | M] (No name found) – C:\Users\alf\AppData\Roaming\Mozilla\Firefox\Profiles\y0ok9hyo.default\extensions
[2012/01/26 07:02:11 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\alf\AppData\Roaming\Mozilla\Firefox\Profiles\y0ok9hyo.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/03/27 06:52:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/05/06 10:59:07 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/03/12 22:38:32 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/03/12 22:38:32 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}

O1 HOSTS File: ([2011/12/15 10:20:51 | 000,001,398 | RHS- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 66.197.194.231 www.google-analytics.com.
O1 - Hosts: 66.197.194.231 ad-emea.doubleclick.net.
O1 - Hosts: 66.197.194.231 www.statcounter.com.
O1 - Hosts: 69.72.252.254 www.google-analytics.com.
O1 - Hosts: 69.72.252.254 ad-emea.doubleclick.net.
O1 - Hosts: 69.72.252.254 www.statcounter.com.
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RunDLLEntry_EptMon] C:\Windows\SysNative\EptMon64.DLL (Creative Technology Ltd.)
O4:64bit: - HKLM..\Run: [RunDLLEntry_THXCfg] C:\Windows\SysNative\THXCfg64.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AccuWeatherWidget] C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe (Dell, Inc.)
O4 - HKLM..\Run: [Dell Registration] C:\Program Files (x86)\System Registration\prodreg.exe (Dell, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [ShwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe (Alcor Micro Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [THX Audio Control Panel] C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKU\S-1-5-21-2109051053-2815559744-1473108664-1001..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKU\S-1-5-21-2109051053-2815559744-1473108664-1001..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Users\alf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\alf\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{700A4AAE-2A32-4FD5-8A46-C8E71E3971DB}: DhcpNameServer = 10.0.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E6702BC4-C0B4-4622-B79E-739436A0FAD7}: DhcpNameServer = 10.0.1.1
O18:64bit: - Protocol\Handler\cozi - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\cozi {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll (Cozi Group, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKU\.DEFAULT\…exe [@ = 622] – "C:\Users\alf\AppData\Local\eal.exe" -a "%1" %*
O37 - HKU\S-1-5-18\…exe [@ = 622] – "C:\Users\alf\AppData\Local\eal.exe" -a "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=consrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/05/16 19:51:14 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\alf\Desktop\aswMBR.exe
[2012/05/16 19:48:47 | 000,595,456 | —- | C] (OldTimer Tools) – C:\Users\alf\Desktop\OTL.exe
[2012/05/15 19:56:38 | 000,000,000 | –SD | C] – C:\ComboFix
[2012/05/15 19:50:49 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/05/15 19:50:47 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/05/15 19:50:47 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/05/15 19:50:38 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012/05/15 19:49:38 | 000,000,000 | —D | C] – C:\Qoobox
[2012/05/15 08:24:53 | 000,000,000 | —D | C] – C:\Users\alf\AppData\Local\{BD61425F-1F2E-4572-B981-53F53D5A4057}
[2012/05/15 03:04:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/05/15 03:03:15 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2012/05/15 03:03:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2012/05/14 20:24:29 | 000,000,000 | —D | C] – C:\Users\alf\AppData\Local\{DECDE9A9-9254-4F6D-A035-0BDEC133DAEC}
[2012/05/14 20:24:19 | 000,000,000 | —D | C] – C:\Users\alf\AppData\Local\{7BBB2244-B5FD-4A5B-9C9D-19C6B52A2311}
[2012/05/13 07:28:40 | 000,000,000 | —D | C] – C:\Windows\en
[2012/05/13 07:14:51 | 000,000,000 | —D | C] – C:\Users\alf\AppData\Local\{65DF1811-D1A1-4183-ACF3-0C5A3D3B80FD}
[2012/05/12 08:47:01 | 001,544,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2012/05/12 08:46:59 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/05/12 08:46:59 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/05/12 08:46:59 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/05/06 10:59:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Maintenance Service
[2012/05/06 10:59:11 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla

========== Files - Modified Within 30 Days ==========

[2012/05/16 19:51:58 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\alf\Desktop\aswMBR.exe
[2012/05/16 19:48:48 | 000,595,456 | —- | M] (OldTimer Tools) – C:\Users\alf\Desktop\OTL.exe
[2012/05/16 19:47:07 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/05/16 09:30:00 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/05/16 09:09:05 | 000,021,296 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/16 09:09:05 | 000,021,296 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/16 08:53:51 | 000,000,888 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/05/16 08:53:51 | 000,000,354 | —- | M] () – C:\Windows\tasks\At48.job
[2012/05/16 08:53:51 | 000,000,352 | —- | M] () – C:\Windows\tasks\At47.job
[2012/05/15 22:35:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At46.job
[2012/05/15 22:35:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At45.job
[2012/05/15 21:37:41 | 000,000,354 | —- | M] () – C:\Windows\tasks\At44.job
[2012/05/15 21:37:41 | 000,000,352 | —- | M] () – C:\Windows\tasks\At43.job
[2012/05/15 20:35:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At42.job
[2012/05/15 20:35:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At41.job
[2012/05/15 20:01:55 | 000,000,408 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2012/05/15 20:01:36 | 523,063,295 | -HS- | M] () – C:\hiberfil.sys
[2012/05/15 19:35:00 | 000,000,354 | —- | M] () – C:\Windows\tasks\At40.job
[2012/05/15 19:35:00 | 000,000,352 | —- | M] () – C:\Windows\tasks\At39.job
[2012/05/15 18:52:50 | 000,000,354 | —- | M] () – C:\Windows\tasks\At38.job
[2012/05/15 18:52:50 | 000,000,354 | —- | M] () – C:\Windows\tasks\At36.job
[2012/05/15 18:52:50 | 000,000,354 | —- | M] () – C:\Windows\tasks\At34.job
[2012/05/15 18:52:50 | 000,000,354 | —- | M] () – C:\Windows\tasks\At32.job
[2012/05/15 18:52:50 | 000,000,354 | —- | M] () – C:\Windows\tasks\At30.job
[2012/05/15 18:52:50 | 000,000,354 | —- | M] () – C:\Windows\tasks\At28.job
[2012/05/15 18:52:50 | 000,000,354 | —- | M] () – C:\Windows\tasks\At26.job
[2012/05/15 18:52:50 | 000,000,352 | —- | M] () – C:\Windows\tasks\At37.job
[2012/05/15 18:52:50 | 000,000,352 | —- | M] () – C:\Windows\tasks\At35.job
[2012/05/15 18:52:50 | 000,000,352 | —- | M] () – C:\Windows\tasks\At33.job
[2012/05/15 18:52:50 | 000,000,352 | —- | M] () – C:\Windows\tasks\At31.job
[2012/05/15 18:52:50 | 000,000,352 | —- | M] () – C:\Windows\tasks\At29.job
[2012/05/15 18:52:50 | 000,000,352 | —- | M] () – C:\Windows\tasks\At27.job
[2012/05/15 18:52:50 | 000,000,352 | —- | M] () – C:\Windows\tasks\At25.job
[2012/05/14 22:49:20 | 000,000,064 | —- | M] () – C:\Windows\SysWow64\rp_stats.dat
[2012/05/14 22:49:20 | 000,000,044 | —- | M] () – C:\Windows\SysWow64\rp_rules.dat
[2012/05/13 03:39:30 | 000,780,156 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/05/13 03:39:30 | 000,660,732 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/05/13 03:39:30 | 000,121,402 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/05/13 03:33:31 | 000,319,000 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2012/05/15 20:01:55 | 000,000,408 | —- | C] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2012/05/15 19:50:49 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/05/15 19:50:48 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/05/15 19:50:47 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/05/15 19:50:47 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/05/15 19:50:47 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/12/30 23:51:53 | 000,000,064 | —- | C] () – C:\Windows\SysWow64\rp_stats.dat
[2011/12/30 23:51:53 | 000,000,044 | —- | C] () – C:\Windows\SysWow64\rp_rules.dat
[2011/12/16 06:31:07 | 000,000,112 | —- | C] () – C:\ProgramData\HAnPgxsJL.dat
[2011/12/14 17:51:51 | 000,012,478 | -HS- | C] () – C:\ProgramData\2172905584
[2011/12/14 17:43:10 | 000,012,466 | -HS- | C] () – C:\Users\alf\AppData\Local\370173d2u587h743k306j0xyi3v8
[2011/12/14 17:43:10 | 000,012,466 | -HS- | C] () – C:\ProgramData\370173d2u587h743k306j0xyi3v8
[2011/07/22 23:05:51 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011/07/22 22:52:00 | 000,002,975 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/07/22 21:23:23 | 000,001,264 | —- | C] () – C:\Windows\THXCfg_SP_APOIM.ini
[2011/07/22 21:23:23 | 000,001,247 | —- | C] () – C:\Windows\THXCfg_HP_APOIM.ini
[2011/07/22 21:23:23 | 000,001,247 | —- | C] () – C:\Windows\THXCfg_APOIM.ini
[2011/07/22 21:23:21 | 000,177,664 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2011/07/22 21:23:21 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2011/02/10 10:10:51 | 000,773,880 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: CONSRV.DLL >
[2009/07/13 19:39:46 | 000,054,272 | —- | M] (Microsoft Corporation) MD5=4D7CDE615A0F534BD5E359951829554B – C:\Windows\SysNative\consrv.dll
[2009/07/13 19:39:46 | 000,054,272 | —- | M] (Microsoft Corporation) MD5=4D7CDE615A0F534BD5E359951829554B – C:\Windows\system64\consrv.dll

< MD5 for: EXPLORER.EXE >
[2011/07/22 23:01:43 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/07/22 23:01:43 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/07/22 23:01:43 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/07/22 23:01:43 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 21:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/07/22 23:01:43 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/07/22 23:01:43 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 21:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: SVCHOST.EXE >
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 19:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 19:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 19:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 19:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\system64\svchost.exe
[2009/07/13 19:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 21:23:55 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 21:23:55 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010/11/20 21:24:28 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 21:24:28 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\system64\userinit.exe
[2010/11/20 21:24:28 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010/11/20 21:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 21:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\system64\winlogon.exe
[2010/11/20 21:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD10EALX-759BA1
Partitions: 3
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: HP Photosmart C5500 USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model:
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE3 -
Interface type: USB
Media Type:
Model:
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE4 -
Interface type: USB
Media Type:
Model:
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE5 - Removable Media
Interface type: USB
Media Type: Removable Media
Model:
Partitions: 1
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 0.00GB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 13.00GB
Starting Offset: 41943040
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 918.00GB
Starting Offset: 14266925056
Hidden sectors: 0


DeviceID: Disk #5, Partition #0
PartitionType: Unknown
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 4.00GB
Starting Offset: 97280
Hidden sectors: 0


========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\system64] -> \systemroot\system32 -> Mount Point

========== Alternate Data Streams ==========

@Alternate Data Stream - 76 bytes -> C:\Users\alf\Documents\music docs:Roxio EMC Stream

< End of report >
Extras.txt

OTL Extras logfile created on: 5/16/2012 7:53:41 PM - Run 1
OTL by OldTimer - Version 3.2.43.0 Folder = C:\Users\alf\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.98 Gb Total Physical Memory | 4.79 Gb Available Physical Memory | 80.09% Memory free
11.96 Gb Paging File | 10.00 Gb Available in Paging File | 83.57% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 918.22 Gb Total Space | 691.33 Gb Free Space | 75.29% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Drive H: | 3.81 Gb Total Space | 3.76 Gb Free Space | 98.66% Space Free | Partition Type: FAT32

Computer Name: ALF-PC | User Name: alf | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl[@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_USERS\.DEFAULT\SOFTWARE\Classes\]
.exe [@ = 622] – "C:\Users\alf\AppData\Local\eal.exe" -a "%1" %*

[HKEY_USERS\S-1-5-18\SOFTWARE\Classes\]
.exe [@ = 622] – "C:\Users\alf\AppData\Local\eal.exe" -a "%1" %*

[HKEY_USERS\S-1-5-21-2109051053-2815559744-1473108664-1001\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\SysWow64\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\SysWow64\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0E241134-73FF-42F9-866D-5F86AD7EAF45}" = lport=137 | protocol=17 | dir=in | app=system |
"{0EC31C06-C95E-4892-80AA-2608C96FDCF6}" = rport=137 | protocol=17 | dir=out | app=system |
"{115FBF13-3564-4DD5-97C2-6158F1E3675D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{13865274-C3B9-41A9-88D5-787C36594185}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1395AB41-8579-439E-A4D9-6F4EF39A9417}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1C44A582-8998-4FF9-BF9C-4D6F8958DAAF}" = lport=139 | protocol=6 | dir=in | app=system |
"{36C4D855-EAB6-4A89-AFB5-AD4809B5AD44}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3CB0345D-1A97-4B9E-BD99-5A02C1307836}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3DD43FF6-4215-4C6F-AF33-F2DA2201C963}" = rport=10243 | protocol=6 | dir=out | app=system |
"{4C025E18-9D24-4F15-9EE0-B2B78A20273F}" = lport=2869 | protocol=6 | dir=in | app=system |
"{53C7396A-30B7-402C-9523-19B942A29C10}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6330469D-F3D3-4667-8158-B721C22BAD53}" = lport=445 | protocol=6 | dir=in | app=system |
"{6380FDFF-4214-4D1B-B4DD-39ACFAC06DEE}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6C2CC718-AD5F-4659-B3F1-78CCE9AC80B6}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{8C80DE66-9F02-491F-93C7-64299FC78FB9}" = lport=10243 | protocol=6 | dir=in | app=system |
"{8E7B9FD3-616C-44E0-98F7-5C7C9A654FDD}" = rport=139 | protocol=6 | dir=out | app=system |
"{9BC9359A-6932-49FE-88EE-3C6F01D9AAB2}" = lport=138 | protocol=17 | dir=in | app=system |
"{A6335DF7-C6D1-4A03-9B17-2DF1968F4636}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{B47A6F0D-DA35-431B-8A09-FCA253309C0B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BF08393C-EC4F-48AD-983A-3C8D22AA9215}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{C3CBBABD-3B1D-4989-97E8-F44AA11CFF24}" = rport=138 | protocol=17 | dir=out | app=system |
"{C758757E-DE86-4764-A037-6BDA89EA0C70}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{E1E892B5-6B36-4633-9A57-8C01397F4738}" = rport=445 | protocol=6 | dir=out | app=system |
"{E89C1961-4FB4-4544-88C7-C8B73B55262F}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{ECAA8FEE-19EE-4518-BEB5-55ACAD51DDF0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F5AE04C0-1A07-429B-A4C1-D6AAC54296E9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0242DD52-184B-403C-A030-BB275D524A6C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{03D1132E-386A-423B-83C9-B91CD63634FE}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{0566EC10-D0DA-474E-9800-3EB6D46407AD}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{1695067B-41F2-4251-864D-760DE2C99976}" = protocol=6 | dir=in | app=c:\users\alf\appdata\roaming\dropbox\bin\dropbox.exe |
"{1823A7B2-28A8-4E77-88E0-AF201E40EACC}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{1A4B067A-33F8-4018-8567-3AC3D3B9FB14}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{1DE47DED-EB93-4D2E-A128-BBF756F24E33}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{21793572-AD59-4003-BE90-B4EE77325080}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{26166BBB-03B2-46FA-96DC-34E9EA93E219}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{2862D8F7-219F-4832-AE36-D185B45DCE64}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2CF61154-B2F4-46EE-B0DD-8BEF76E82189}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2EAFC4E7-54CC-41C8-A1E2-72B82186A000}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{3937CCA6-512E-4E7E-873C-8BF39A01AA48}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{3EBBC08B-6D5C-4A56-881A-A138EAD53723}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{40E7AF23-B7B7-494E-808E-F1D9C83E018A}" = protocol=17 | dir=in | app=c:\users\alf\appdata\roaming\dropbox\bin\dropbox.exe |
"{45645C49-5ECF-4F06-8F84-4869A5045AAB}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{4B67A495-B841-44CB-956A-4367C6177F36}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{5047D2F0-39E4-46CA-98DD-B2EA4955691C}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{50DADEF8-C5DC-4B03-9E2E-B00E6141B599}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{624B1801-964F-4B43-88D6-91937F54E2DC}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{71F352DA-E9AC-4938-890D-5822AC66FF08}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{72F94D9C-920B-4984-9C33-17D0452003E3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{735464EE-071F-4273-A45A-CCA6C05F15E6}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{90C1F536-DA3C-4D8D-8802-DC4C4DE0CEB0}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{930E4C79-F567-4783-92A9-B0C7F333209B}" = dir=in | app=c:\program files\dell stage\musicstage\musicstageengine.exe |
"{9B6EC45C-03EC-4546-B641-678C02A43191}" = dir=in | app=c:\program files\dell stage\dell stage\stage_primary.exe |
"{BABD3CBF-D8A7-43B8-989F-374C315B5A33}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{C6E20E90-895A-4757-8576-1EB7A52FBC4D}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{C9006E2B-86EB-4BE9-8226-67ED00A49BF4}" = dir=in | app=c:\program files (x86)\dell\videostage\videostage.exe |
"{D487DF81-10B8-41AF-AA70-0F9DA08CF775}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{DEBAACEA-0ECE-4BA7-AA5A-A05E2EA81A81}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{E0380DE6-760E-481F-B4F7-4081973A1D0E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E2ADCE76-13D4-4C6F-9218-5444BA7E8CA9}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{E7F9417A-B669-4C26-AAE8-E64D2769D41D}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{EB4EBF11-01F1-45BC-B9DA-D292C6762EE1}" = protocol=6 | dir=out | app=system |
"{F2338D6E-39B9-43DF-9852-D78A42D6BB6E}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{F748C8A7-4821-419D-BFD3-C2608F42EF4D}" = dir=in | app=c:\program files\dell stage\dell stage\accuweather\accuweather.exe |
"{FC7C855D-86C4-4AC2-9087-9F5512C15F86}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{FE4DF66F-17BC-442B-89BB-335967F59269}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{26A24AE4-039D-4CA4-87B4-2F86416024FF}" = Java™ 6 Update 24 (64-bit)
"{5E11C972-1E76-45FE-8F92-14E0D1140B1B}" = iTunes
"{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}" = Roxio File Backup
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{6E3D4FFE-9614-4E58-9DE2-F9A036EAD491}" = ATI Catalyst Install Manager
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{83CB95E0-5518-AAC2-9B63-1FDBB4D51263}" = ATI AVIVO64 Codecs
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}" = RBVirtualFolder64Inst
"{C99B5E76-3EA1-9943-F394-1E9F9EC8B28C}" = ccc-utility64
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"DW WLAN Card" = DW WLAN Card
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{010A785B-F920-4350-821B-6309909C20BB}" = THX TruStudio PC
"{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}" = Microsoft Visual C++ 2005 Redistributable
"{0B043A05-B07C-9307-8CC8-0C72BC8895E2}" = CCC Help Polish
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{16D6AA4F-959B-306B-0747-CFBEFCC7A0DE}" = CCC Help Greek
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1C1473A1-1A26-4C8F-9548-A52D03066CE7}" = Catalyst Control Center - Branding
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{22076B10-37D9-7B32-AB5D-3F97D9E87E15}" = CCC Help Turkish
"{22813428-038B-8C98-5AF8-22B7EF1B6284}" = CCC Help Spanish
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A0F2CC5-3065-492C-8380-B03AA7106B1A}" = Dell Product Registration
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2BDCCC79-2352-1CD6-80D0-1E1948FEF262}" = CCC Help Italian
"{2D162142-12F7-4419-577C-7BB3204F799F}" = CCC Help Chinese Standard
"{2F4FB074-80B6-118F-42AD-27B6F275D884}" = CCC Help Chinese Traditional
"{3250260C-7A95-4632-893B-89657EB5545B}" = PhotoShowExpress
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{374EBC77-5E23-0B63-0B65-136AEFF98C1D}" = CCC Help Danish
"{375DBB30-93A7-11DF-6DF1-00CE5F8B1649}" = LP Recorder
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{400F29A3-58E9-4848-5BE1-01919F891D44}" = CCC Help Swedish
"{41068A8C-3F30-46B6-978A-EA692F28D1AF}" = Multimedia Card Reader
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6AFA3415-7B6A-EF20-225A-B1DC627BBAC5}" = CCC Help Korean
"{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}" = Roxio Creator Starter
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7746BFAA-2B5D-4FFD-A0E8-4558F4668105}" = Roxio Burn
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7EC66A95-AC2D-4127-940B-0445A526AB2F}" = Dell DataSafe Online
"{81C3E664-CA21-3C4B-312F-54DEB08EF1A5}" = Catalyst Control Center InstallProxy
"{820B6609-4C97-3A2B-B644-573B06A0F0CC}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{8279F213-ECD0-4C36-A8EC-670FC16218E3}" = CCC Help Dutch
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{91AF2672-F5BC-42CF-8037-A9D2F92BBCC0}" = Dell MusicStage
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{932D0FC7-6DF1-4136-A2EC-166E8DEFD6A4}" = Ad-Aware
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9842650A-98C5-A238-AC65-189F80285EBD}" = CCC Help Czech
"{9A00EC4E-27E1-42C4-98DD-662F32AC8870}" = Sonic CinePlayer Decoder Pack
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9F41678D-3934-EBBA-F85C-E1A97DB84407}" = CCC Help Thai
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A121EEDE-C68F-461D-91AA-D48BA226AF1C}" = Roxio Activation Module
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.3) MUI
"{ADDD9902-3576-7071-1196-24E37F15BB52}" = Catalyst Control Center Localization All
"{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CA0006CC-FB7D-6358-BF24-3394D509AB9C}" = CCC Help Japanese
"{CA04E3AD-FFAC-0EE9-3605-E9665EC05BF7}" = CCC Help Finnish
"{CCAE8CA3-5C96-FBF2-BD0F-27D4644217D3}" = CCC Help Portuguese
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C3}" = WinZip 15.5
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E0C8AC08-1B2C-AD87-E4CE-9C0A2618807E}" = CCC Help English
"{E2EBA7C0-8072-447F-856D-FFEE8D15B23B}" = Dell Stage
"{E4335E82-17B3-460F-9E70-39D9BC269DB3}" = Dell PhotoStage
"{E4F3A636-92E3-86C4-FA1E-19BC06CBB037}" = CCC Help German
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E5F6575A-7567-9230-2BE0-615A46E5721B}" = CCC Help Russian
"{E9656E99-F59E-F377-DC5F-477047CA4FCF}" = CCC Help French
"{EA1F3D6C-A6F5-4CDC-B0D3-9C56C06B4D29}" = Cozi
"{EF56258E-0326-48C5-A86C-3BAC26FC15DF}" = Roxio Creator Starter
"{F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}" = Roxio Creator Starter
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F16B7D69-784E-C12E-D42B-A1D69A38B752}" = CCC Help Hungarian
"{F47C37A4-7189-430A-B81D-739FF8A7A554}" = Consumer In-Home Service Agreement
"{FB85D440-98E6-B361-1727-DFD81F366943}" = ccc-core-static
"{FC4AAC27-3775-E69E-6DBB-381425D79A94}" = CCC Help Norwegian
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Acoustica CD/DVD Label Maker" = Acoustica CD/DVD Label Maker
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"GoldWave v5.58" = GoldWave v5.58
"Google Chrome" = Google Chrome
"InstallShield_{41068A8C-3F30-46B6-978A-EA692F28D1AF}" = Multimedia Card Reader
"InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}" = Dell VideoStage
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Mozilla Firefox 12.0 (x86 en-US)" = Mozilla Firefox 12.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"Picasa 3" = Picasa 3
"Play MPE Player 4.0" = Play MPE Player 4.0
"Spotify" = Spotify
"Winamp" = Winamp
"WinLiveSuite" = Windows Live Essentials
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2109051053-2815559744-1473108664-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/2/2012 4:15:42 PM | Computer Name = alf-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 9016

Error - 5/2/2012 4:45:49 PM | Computer Name = alf-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 5/2/2012 4:45:49 PM | Computer Name = alf-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 998

Error - 5/2/2012 4:45:49 PM | Computer Name = alf-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 998

Error - 5/2/2012 4:45:50 PM | Computer Name = alf-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 5/2/2012 4:45:50 PM | Computer Name = alf-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1997

Error - 5/2/2012 4:45:50 PM | Computer Name = alf-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1997

Error - 5/2/2012 4:45:51 PM | Computer Name = alf-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 5/2/2012 4:45:51 PM | Computer Name = alf-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2995

Error - 5/2/2012 4:45:51 PM | Computer Name = alf-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2995

[ Media Center Events ]
Error - 10/19/2011 12:03:08 AM | Computer Name = alf-PC | Source = MCUpdate | ID = 0
Description = 10:03:08 PM - Error connecting to the internet. 10:03:08 PM - Unable
to contact server..

Error - 10/23/2011 5:14:33 AM | Computer Name = alf-PC | Source = MCUpdate | ID = 0
Description = 3:14:32 AM - Error connecting to the internet. 3:14:32 AM - Unable
to contact server..

Error - 11/1/2011 12:53:12 AM | Computer Name = alf-PC | Source = MCUpdate | ID = 0
Description = 10:53:08 PM - Error connecting to the internet. 10:53:08 PM - Unable
to contact server..

Error - 11/7/2011 12:17:14 AM | Computer Name = alf-PC | Source = MCUpdate | ID = 0
Description = 9:17:12 PM - Error connecting to the internet. 9:17:12 PM - Unable
to contact server..

Error - 11/7/2011 12:43:27 PM | Computer Name = alf-PC | Source = MCUpdate | ID = 0
Description = 9:43:27 AM - Error connecting to the internet. 9:43:27 AM - Unable
to contact server..

Error - 11/7/2011 12:43:33 PM | Computer Name = alf-PC | Source = MCUpdate | ID = 0
Description = 9:43:32 AM - Error connecting to the internet. 9:43:32 AM - Unable
to contact server..

Error - 11/18/2011 12:54:15 PM | Computer Name = alf-PC | Source = MCUpdate | ID = 0
Description = 9:54:15 AM - Error connecting to the internet. 9:54:15 AM - Unable
to contact server..

Error - 11/18/2011 12:54:24 PM | Computer Name = alf-PC | Source = MCUpdate | ID = 0
Description = 9:54:20 AM - Error connecting to the internet. 9:54:20 AM - Unable
to contact server..

Error - 11/19/2011 12:24:03 AM | Computer Name = alf-PC | Source = MCUpdate | ID = 0
Description = 9:24:03 PM - Error connecting to the internet. 9:24:03 PM - Unable
to contact server..

Error - 11/22/2011 6:08:49 AM | Computer Name = alf-PC | Source = MCUpdate | ID = 0
Description = 3:08:47 AM - Error connecting to the internet. 3:08:47 AM - Unable
to contact server..

[ System Events ]
Error - 5/15/2012 10:01:45 PM | Computer Name = alf-PC | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060

Error - 5/15/2012 10:01:47 PM | Computer Name = alf-PC | Source = Service Control Manager | ID = 7003
Description = The IKE and AuthIP IPsec Keying Modules service depends the following
service: BFE. This service might not be installed.

Error - 5/15/2012 10:01:47 PM | Computer Name = alf-PC | Source = Service Control Manager | ID = 7003
Description = The IPsec Policy Agent service depends the following service: BFE.
This service might not be installed.

Error - 5/15/2012 10:01:47 PM | Computer Name = alf-PC | Source = Service Control Manager | ID = 7003
Description = The Internet Connection Sharing (ICS) service depends the following
service: BFE. This service might not be installed.

Error - 5/15/2012 10:01:47 PM | Computer Name = alf-PC | Source = Service Control Manager | ID = 7023
Description = The Windows Defender service terminated with the following error:
%%126

Error - 5/15/2012 10:04:00 PM | Computer Name = alf-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the SftService service.

Error - 5/15/2012 10:04:24 PM | Computer Name = alf-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Google
Update Service (gupdate) service to connect.

Error - 5/15/2012 10:04:24 PM | Computer Name = alf-PC | Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate) service failed to start due to
the following error: %%1053

Error - 5/15/2012 10:04:30 PM | Computer Name = alf-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the SftService service.

Error - 5/15/2012 10:05:46 PM | Computer Name = alf-PC | Source = Service Control Manager | ID = 7024
Description = The HomeGroup Listener service terminated with service-specific error
%%-2147023143.


< End of report >
aswMBR aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-05-16 20:03:54 —————————– 20:03:54.166 OS Version: Windows x64 6.1.7601 Service Pack 1 20:03:54.166 Number of processors: 8 586 0x2A07 20:03:54.167 ComputerName: ALF-PC UserName: alf 20:03:55.364 Initialize success 20:03:57.736 AVAST engine defs: 12051501 20:04:05.819 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 20:04:05.820 Disk 0 Vendor: WDC_WD10 17.0 Size: 953869MB BusType: 3 20:04:05.840 Disk 0 MBR read successfully 20:04:05.842 Disk 0 MBR scan 20:04:05.843 Disk 0 Windows VISTA default MBR code 20:04:05.849 Disk 0 Partition 1 00 DE Dell Utility DELL 4.1 39 MB offset 63 20:04:05.856 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 13566 MB offset 81920 20:04:05.858 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 940262 MB offset 27865088 20:04:05.881 Disk 0 scanning C:\Windows\system32\drivers 20:04:15.108 Service scanning 20:04:25.500 Modules scanning 20:04:25.503 Disk 0 trace - called modules: 20:04:25.523 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 20:04:25.526 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007ada790] 20:04:25.528 3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8005dd3050] 20:04:26.941 AVAST engine scan C:\Windows 20:04:38.138 AVAST engine scan C:\Windows\system32 20:04:45.314 File: C:\Windows\system32\consrv.dll **INFECTED** Win32:Sirefef-HO [Rtk] 20:05:26.495 File: C:\Windows\assembly\GAC_32\Desktop.ini **INFECTED** Win32:Sirefef-FQ [Drp] 20:05:27.778 File: C:\Windows\assembly\GAC_64\Desktop.ini **INFECTED** Win32:Sirefef-HO [Rtk] 20:06:15.854 AVAST engine scan C:\Windows\system32\drivers 20:06:22.095 AVAST engine scan C:\Users\alf 20:06:46.335 Disk 0 MBR has been saved successfully to "C:\Users\alf\Desktop\MBR.dat" 20:06:46.337 The log file has been saved successfully to "C:\Users\alf\Desktop\aswMBR.txt" …that can't be good.

I'm a jazz fan too, if that's a Louis Armstrong reference.

I do like Jazz but this is not a reference to "Satchmo" but to Joe Satriani who is known as "Joe Satch" :)

As you said, that isn't good and you have a very bad infection that can be very difficult to remove. Hopefully, you've caught it before it caused maximum damage.

Run TDSSKiller

Please download TDSSKiller.zip
  • extract it to your desktop
  • double click TDSSKiller.exe
  • press Start Scan
    • only if Malicious objects are found then ensure Cure is selected. Do not change it to Delete or Quarantine as it may delete infected files that are required for Windows to operate properly.
    • then click Continue > Reboot now
  • copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_*** (*** denotes version & date)
======================================================

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • see this Link for programs that need to be disabled and instruction on how to disable them.
  • remember to re-enable them when we're done.
  • double click on ComboFix.exe & follow the prompts.
  • as part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Please also remember to include the TDSSKiller log

Thanks

Satchfan
Wrong satch. :) TDSSKiller found nothing. Here's the log. 07:56:11.0644 8292 TDSS rootkit removing tool [removed] May 16 2012 07:37:57 07:56:12.0094 8292 ============================================================ 07:56:12.0094 8292 Current date / time: 2012/05/17 07:56:12.0094 07:56:12.0094 8292 SystemInfo: 07:56:12.0094 8292 07:56:12.0094 8292 OS Version: 6.1.7601 ServicePack: 1.0 07:56:12.0094 8292 Product type: Workstation 07:56:12.0094 8292 ComputerName: ALF-PC 07:56:12.0094 8292 UserName: alf 07:56:12.0094 8292 Windows directory: C:\Windows 07:56:12.0094 8292 System windows directory: C:\Windows 07:56:12.0094 8292 Running under WOW64 07:56:12.0094 8292 Processor architecture: Intel x64 07:56:12.0094 8292 Number of processors: 8 07:56:12.0094 8292 Page size: 0x1000 07:56:12.0094 8292 Boot type: Normal boot 07:56:12.0094 8292 ============================================================ 07:56:12.0376 8292 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 07:56:12.0399 8292 Drive \Device\Harddisk5\DR5 - Size: 0xF4500000 (3.82 Gb), SectorSize: 0x200, Cylinders: 0x1F2, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 07:56:12.0401 8292 ============================================================ 07:56:12.0401 8292 \Device\Harddisk0\DR0: 07:56:12.0401 8292 MBR partitions: 07:56:12.0401 8292 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x1A7F000 07:56:12.0401 8292 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1A93000, BlocksNum 0x72C73000 07:56:12.0401 8292 \Device\Harddisk5\DR5: 07:56:12.0402 8292 MBR partitions: 07:56:12.0402 8292 \Device\Harddisk5\DR5\Partition0: MBR, Type 0xC, StartLBA 0xBE, BlocksNum 0x7A0F42 07:56:12.0402 8292 ============================================================ 07:56:12.0429 8292 C: <-> \Device\Harddisk0\DR0\Partition1 07:56:12.0429 8292 ============================================================ 07:56:12.0429 8292 Initialize success 07:56:12.0429 8292 ============================================================ 07:56:30.0325 4992 ============================================================ 07:56:30.0325 4992 Scan started 07:56:30.0325 4992 Mode: Manual; 07:56:30.0325 4992 ============================================================ 07:56:30.0885 4992 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys 07:56:30.0886 4992 1394ohci - ok 07:56:30.0908 4992 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys 07:56:30.0910 4992 ACPI - ok 07:56:30.0922 4992 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys 07:56:30.0922 4992 AcpiPmi - ok 07:56:30.0994 4992 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 07:56:30.0995 4992 AdobeARMservice - ok 07:56:31.0014 4992 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys 07:56:31.0017 4992 adp94xx - ok 07:56:31.0030 4992 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys 07:56:31.0032 4992 adpahci - ok 07:56:31.0041 4992 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys 07:56:31.0042 4992 adpu320 - ok 07:56:31.0064 4992 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll 07:56:31.0064 4992 AeLookupSvc - ok 07:56:31.0123 4992 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys 07:56:31.0125 4992 AFD - ok 07:56:31.0137 4992 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys 07:56:31.0137 4992 agp440 - ok 07:56:31.0145 4992 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe 07:56:31.0146 4992 ALG - ok 07:56:31.0154 4992 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys 07:56:31.0154 4992 aliide - ok 07:56:31.0191 4992 AMD External Events Utility (11276158eeeeadf3eb154061bfc80a19) C:\Windows\system32\atiesrxx.exe 07:56:31.0192 4992 AMD External Events Utility - ok 07:56:31.0201 4992 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys 07:56:31.0201 4992 amdide - ok 07:56:31.0207 4992 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys 07:56:31.0208 4992 AmdK8 - ok 07:56:31.0452 4992 amdkmdag (df943a113060d3abfda4730ae4163d6f) C:\Windows\system32\DRIVERS\atikmdag.sys 07:56:31.0548 4992 amdkmdag - ok 07:56:31.0642 4992 amdkmdap (4003b34b4a83de29cd1c88eb6c869e58) C:\Windows\system32\DRIVERS\atikmpag.sys 07:56:31.0645 4992 amdkmdap - ok 07:56:31.0658 4992 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys 07:56:31.0658 4992 AmdPPM - ok 07:56:31.0666 4992 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys 07:56:31.0667 4992 amdsata - ok 07:56:31.0686 4992 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys 07:56:31.0687 4992 amdsbs - ok 07:56:31.0696 4992 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys 07:56:31.0696 4992 amdxata - ok 07:56:31.0717 4992 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys 07:56:31.0717 4992 AppID - ok 07:56:31.0736 4992 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll 07:56:31.0736 4992 AppIDSvc - ok 07:56:31.0741 4992 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll 07:56:31.0741 4992 Appinfo - ok 07:56:31.0805 4992 Apple Mobile Device (3debbecf665dcdde3a95d9b902010817) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 07:56:31.0806 4992 Apple Mobile Device - ok 07:56:31.0814 4992 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys 07:56:31.0815 4992 arc - ok 07:56:31.0829 4992 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys 07:56:31.0829 4992 arcsas - ok 07:56:31.0889 4992 aspnet_state (9217d874131ae6ff8f642f124f00a555) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 07:56:31.0890 4992 aspnet_state - ok 07:56:31.0910 4992 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 07:56:31.0910 4992 AsyncMac - ok 07:56:31.0941 4992 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys 07:56:31.0941 4992 atapi - ok 07:56:31.0972 4992 AtiHDAudioService (4bf5bca6e2608cd8a00bc4a6673a9f47) C:\Windows\system32\drivers\AtihdW76.sys 07:56:31.0973 4992 AtiHDAudioService - ok 07:56:32.0026 4992 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll 07:56:32.0030 4992 AudioEndpointBuilder - ok 07:56:32.0034 4992 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll 07:56:32.0036 4992 AudioSrv - ok 07:56:32.0071 4992 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll 07:56:32.0072 4992 AxInstSV - ok 07:56:32.0096 4992 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys 07:56:32.0100 4992 b06bdrv - ok 07:56:32.0123 4992 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 07:56:32.0126 4992 b57nd60a - ok 07:56:32.0251 4992 BCM43XX (8b5d16d20774fc3727f44e161be2c0ac) C:\Windows\system32\DRIVERS\bcmwl664.sys 07:56:32.0306 4992 BCM43XX - ok 07:56:32.0375 4992 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll 07:56:32.0376 4992 BDESVC - ok 07:56:32.0386 4992 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 07:56:32.0387 4992 Beep - ok 07:56:32.0430 4992 BITS (1ea7969e3271cbc59e1730697dc74682) C:\Windows\System32\qmgr.dll 07:56:32.0436 4992 BITS - ok 07:56:32.0448 4992 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 07:56:32.0449 4992 blbdrive - ok 07:56:32.0540 4992 Bonjour Service (ebbcd5dfbb1de70e8f4af8fa59e401fd) C:\Program Files\Bonjour\mDNSResponder.exe 07:56:32.0541 4992 Bonjour Service - ok 07:56:32.0577 4992 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys 07:56:32.0578 4992 bowser - ok 07:56:32.0586 4992 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys 07:56:32.0586 4992 BrFiltLo - ok 07:56:32.0600 4992 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys 07:56:32.0600 4992 BrFiltUp - ok 07:56:32.0613 4992 BridgeMP (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys 07:56:32.0613 4992 BridgeMP - ok 07:56:32.0636 4992 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll 07:56:32.0637 4992 Browser - ok 07:56:32.0661 4992 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 07:56:32.0663 4992 Brserid - ok 07:56:32.0671 4992 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 07:56:32.0672 4992 BrSerWdm - ok 07:56:32.0675 4992 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 07:56:32.0675 4992 BrUsbMdm - ok 07:56:32.0679 4992 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 07:56:32.0679 4992 BrUsbSer - ok 07:56:32.0692 4992 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys 07:56:32.0693 4992 BTHMODEM - ok 07:56:32.0702 4992 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll 07:56:32.0703 4992 bthserv - ok 07:56:32.0717 4992 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 07:56:32.0717 4992 cdfs - ok 07:56:32.0741 4992 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys 07:56:32.0742 4992 cdrom - ok 07:56:32.0758 4992 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll 07:56:32.0758 4992 CertPropSvc - ok 07:56:32.0773 4992 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys 07:56:32.0773 4992 circlass - ok 07:56:32.0800 4992 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 07:56:32.0810 4992 CLFS - ok 07:56:32.0849 4992 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 07:56:32.0850 4992 clr_optimization_v2.0.50727_32 - ok 07:56:32.0882 4992 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 07:56:32.0883 4992 clr_optimization_v2.0.50727_64 - ok 07:56:32.0929 4992 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 07:56:32.0929 4992 clr_optimization_v4.0.30319_32 - ok 07:56:32.0966 4992 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 07:56:32.0967 4992 clr_optimization_v4.0.30319_64 - ok 07:56:32.0969 4992 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\drivers\CmBatt.sys 07:56:32.0970 4992 CmBatt - ok 07:56:32.0988 4992 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys 07:56:32.0988 4992 cmdide - ok 07:56:33.0037 4992 CNG (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys 07:56:33.0045 4992 CNG - ok 07:56:33.0057 4992 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys 07:56:33.0058 4992 Compbatt - ok 07:56:33.0079 4992 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\DRIVERS\CompositeBus.sys 07:56:33.0079 4992 CompositeBus - ok 07:56:33.0089 4992 COMSysApp - ok 07:56:33.0104 4992 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys 07:56:33.0104 4992 crcdisk - ok 07:56:33.0133 4992 CryptSvc (15597883fbe9b056f276ada3ad87d9af) C:\Windows\system32\cryptsvc.dll 07:56:33.0134 4992 CryptSvc - ok 07:56:33.0258 4992 cvhsvc (72794d112cbaff3bc0c29bf7350d4741) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE 07:56:33.0261 4992 cvhsvc - ok 07:56:33.0327 4992 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll 07:56:33.0331 4992 DcomLaunch - ok 07:56:33.0371 4992 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll 07:56:33.0373 4992 defragsvc - ok 07:56:33.0407 4992 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys 07:56:33.0408 4992 DfsC - ok 07:56:33.0431 4992 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll 07:56:33.0433 4992 Dhcp - ok 07:56:33.0435 4992 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 07:56:33.0436 4992 discache - ok 07:56:33.0450 4992 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys 07:56:33.0451 4992 Disk - ok 07:56:33.0474 4992 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll 07:56:33.0475 4992 Dnscache - ok 07:56:33.0505 4992 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll 07:56:33.0507 4992 dot3svc - ok 07:56:33.0525 4992 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll 07:56:33.0526 4992 DPS - ok 07:56:33.0554 4992 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 07:56:33.0554 4992 drmkaud - ok 07:56:33.0596 4992 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys 07:56:33.0631 4992 DXGKrnl - ok 07:56:33.0670 4992 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll 07:56:33.0671 4992 EapHost - ok 07:56:33.0791 4992 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys 07:56:33.0826 4992 ebdrv - ok 07:56:33.0938 4992 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe 07:56:33.0939 4992 EFS - ok 07:56:34.0014 4992 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe 07:56:34.0048 4992 ehRecvr - ok 07:56:34.0072 4992 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe 07:56:34.0073 4992 ehSched - ok 07:56:34.0115 4992 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys 07:56:34.0118 4992 elxstor - ok 07:56:34.0195 4992 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys 07:56:34.0195 4992 ErrDev - ok 07:56:34.0224 4992 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll 07:56:34.0225 4992 EventSystem - ok 07:56:34.0235 4992 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 07:56:34.0236 4992 exfat - ok 07:56:34.0259 4992 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 07:56:34.0260 4992 fastfat - ok 07:56:34.0312 4992 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe 07:56:34.0321 4992 Fax - ok 07:56:34.0330 4992 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys 07:56:34.0330 4992 fdc - ok 07:56:34.0332 4992 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll 07:56:34.0332 4992 fdPHost - ok 07:56:34.0341 4992 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll 07:56:34.0341 4992 FDResPub - ok 07:56:34.0350 4992 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 07:56:34.0351 4992 FileInfo - ok 07:56:34.0363 4992 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 07:56:34.0363 4992 Filetrace - ok 07:56:34.0442 4992 FLEXnet Licensing Service (8669be94f63944e4f899c3950b520241) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 07:56:34.0451 4992 FLEXnet Licensing Service - ok 07:56:34.0479 4992 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys 07:56:34.0479 4992 flpydisk - ok 07:56:34.0500 4992 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys 07:56:34.0502 4992 FltMgr - ok 07:56:34.0562 4992 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll 07:56:34.0609 4992 FontCache - ok 07:56:34.0692 4992 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 07:56:34.0693 4992 FontCache3.0.0.0 - ok 07:56:34.0719 4992 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 07:56:34.0720 4992 FsDepends - ok 07:56:34.0770 4992 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys 07:56:34.0771 4992 Fs_Rec - ok 07:56:34.0800 4992 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys 07:56:34.0802 4992 fvevol - ok 07:56:34.0811 4992 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys 07:56:34.0812 4992 gagp30kx - ok 07:56:34.0848 4992 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 07:56:34.0848 4992 GEARAspiWDM - ok 07:56:34.0900 4992 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll 07:56:34.0923 4992 gpsvc - ok 07:56:35.0000 4992 gupdate - ok 07:56:35.0002 4992 gupdatem - ok 07:56:35.0061 4992 gusvc (c1b577b2169900f4cf7190c39f085794) C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe 07:56:35.0063 4992 gusvc - ok 07:56:35.0090 4992 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 07:56:35.0090 4992 hcw85cir - ok 07:56:35.0114 4992 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\DRIVERS\HDAudBus.sys 07:56:35.0115 4992 HDAudBus - ok 07:56:35.0121 4992 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys 07:56:35.0122 4992 HidBatt - ok 07:56:35.0136 4992 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys 07:56:35.0136 4992 HidBth - ok 07:56:35.0142 4992 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys 07:56:35.0143 4992 HidIr - ok 07:56:35.0150 4992 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\System32\hidserv.dll 07:56:35.0150 4992 hidserv - ok 07:56:35.0176 4992 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys 07:56:35.0177 4992 HidUsb - ok 07:56:35.0187 4992 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll 07:56:35.0188 4992 hkmsvc - ok 07:56:35.0207 4992 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll 07:56:35.0209 4992 HomeGroupListener - ok 07:56:35.0225 4992 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll 07:56:35.0227 4992 HomeGroupProvider - ok 07:56:35.0241 4992 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys 07:56:35.0241 4992 HpSAMD - ok 07:56:35.0281 4992 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys 07:56:35.0285 4992 HTTP - ok 07:56:35.0317 4992 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys 07:56:35.0317 4992 hwpolicy - ok 07:56:35.0336 4992 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys 07:56:35.0336 4992 i8042prt - ok 07:56:35.0373 4992 iaStor (f7ce9be72edac499b713eca6dae5d26f) C:\Windows\system32\drivers\iaStor.sys 07:56:35.0375 4992 iaStor - ok 07:56:35.0444 4992 IAStorDataMgrSvc (b25f192ea1f84a316eb7c19efcccf33d) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe 07:56:35.0444 4992 IAStorDataMgrSvc - ok 07:56:35.0477 4992 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys 07:56:35.0479 4992 iaStorV - ok 07:56:35.0570 4992 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 07:56:35.0600 4992 idsvc - ok 07:56:35.0616 4992 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys 07:56:35.0616 4992 iirsp - ok 07:56:35.0671 4992 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll 07:56:35.0676 4992 IKEEXT - ok 07:56:35.0691 4992 Impcd (dd587a55390ed2295bce6d36ad567da9) C:\Windows\system32\drivers\Impcd.sys 07:56:35.0693 4992 Impcd - ok 07:56:35.0802 4992 IntcAzAudAddService (235362d403d9d677514649d88db31914) C:\Windows\system32\drivers\RTKVHD64.sys 07:56:35.0835 4992 IntcAzAudAddService - ok 07:56:35.0927 4992 IntcDAud (fc727061c0f47c8059e88e05d5c8e381) C:\Windows\system32\DRIVERS\IntcDAud.sys 07:56:35.0929 4992 IntcDAud - ok 07:56:35.0936 4992 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys 07:56:35.0936 4992 intelide - ok 07:56:35.0946 4992 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 07:56:35.0946 4992 intelppm - ok 07:56:35.0960 4992 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll 07:56:35.0961 4992 IPBusEnum - ok 07:56:35.0975 4992 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys 07:56:35.0975 4992 IpFilterDriver - ok 07:56:36.0025 4992 iphlpsvc (a34a587fffd45fa649fba6d03784d257) C:\Windows\System32\iphlpsvc.dll 07:56:36.0029 4992 iphlpsvc - ok 07:56:36.0045 4992 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys 07:56:36.0046 4992 IPMIDRV - ok 07:56:36.0069 4992 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 07:56:36.0070 4992 IPNAT - ok 07:56:36.0146 4992 iPod Service (ee4c2a137c7088911a8919effc9812e7) C:\Program Files\iPod\bin\iPodService.exe 07:56:36.0149 4992 iPod Service - ok 07:56:36.0172 4992 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 07:56:36.0172 4992 IRENUM - ok 07:56:36.0178 4992 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys 07:56:36.0178 4992 isapnp - ok 07:56:36.0202 4992 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys 07:56:36.0204 4992 iScsiPrt - ok 07:56:36.0253 4992 k57nd60a (12e27942dbb7c91880163634b0d8a776) C:\Windows\system32\DRIVERS\k57nd60a.sys 07:56:36.0262 4992 k57nd60a - ok 07:56:36.0265 4992 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys 07:56:36.0266 4992 kbdclass - ok 07:56:36.0290 4992 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys 07:56:36.0290 4992 kbdhid - ok 07:56:36.0321 4992 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 07:56:36.0322 4992 KeyIso - ok 07:56:36.0337 4992 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys 07:56:36.0338 4992 KSecDD - ok 07:56:36.0348 4992 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys 07:56:36.0349 4992 KSecPkg - ok 07:56:36.0375 4992 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 07:56:36.0375 4992 ksthunk - ok 07:56:36.0403 4992 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll 07:56:36.0405 4992 KtmRm - ok 07:56:36.0429 4992 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\System32\srvsvc.dll 07:56:36.0431 4992 LanmanServer - ok 07:56:36.0453 4992 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll 07:56:36.0454 4992 LanmanWorkstation - ok 07:56:36.0570 4992 Lavasoft Ad-Aware Service (93b3ef77866490c7daba054f6cbfcd51) C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe 07:56:36.0579 4992 Lavasoft Ad-Aware Service - ok 07:56:36.0635 4992 Lavasoft Kernexplorer (9a7fa6371f68335fd3c3d6488bc5a9f8) C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys 07:56:36.0636 4992 Lavasoft Kernexplorer - ok 07:56:36.0742 4992 Lbd (c8b3131857931ae76798a741cc52b021) C:\Windows\system32\DRIVERS\Lbd.sys 07:56:36.0742 4992 Lbd - ok 07:56:36.0760 4992 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 07:56:36.0761 4992 lltdio - ok 07:56:36.0791 4992 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll 07:56:36.0793 4992 lltdsvc - ok 07:56:36.0804 4992 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll 07:56:36.0805 4992 lmhosts - ok 07:56:36.0832 4992 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys 07:56:36.0832 4992 LSI_FC - ok 07:56:36.0844 4992 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys 07:56:36.0845 4992 LSI_SAS - ok 07:56:36.0859 4992 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys 07:56:36.0859 4992 LSI_SAS2 - ok 07:56:36.0871 4992 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys 07:56:36.0872 4992 LSI_SCSI - ok 07:56:36.0881 4992 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 07:56:36.0882 4992 luafv - ok 07:56:36.0903 4992 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll 07:56:36.0903 4992 Mcx2Svc - ok 07:56:36.0920 4992 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys 07:56:36.0921 4992 megasas - ok 07:56:36.0938 4992 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys 07:56:36.0940 4992 MegaSR - ok 07:56:36.0957 4992 MEIx64 (1c6e73fc46b509eff9d0086aa37132df) C:\Windows\system32\DRIVERS\HECIx64.sys 07:56:36.0958 4992 MEIx64 - ok 07:56:36.0965 4992 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll 07:56:36.0965 4992 MMCSS - ok 07:56:36.0976 4992 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 07:56:36.0977 4992 Modem - ok 07:56:36.0999 4992 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 07:56:36.0999 4992 monitor - ok 07:56:37.0002 4992 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys 07:56:37.0003 4992 mouclass - ok 07:56:37.0026 4992 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 07:56:37.0027 4992 mouhid - ok 07:56:37.0034 4992 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys 07:56:37.0035 4992 mountmgr - ok 07:56:37.0089 4992 MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 07:56:37.0090 4992 MozillaMaintenance - ok 07:56:37.0102 4992 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys 07:56:37.0103 4992 mpio - ok 07:56:37.0112 4992 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 07:56:37.0112 4992 mpsdrv - ok 07:56:37.0128 4992 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys 07:56:37.0129 4992 MRxDAV - ok 07:56:37.0164 4992 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys 07:56:37.0165 4992 mrxsmb - ok 07:56:37.0208 4992 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys 07:56:37.0209 4992 mrxsmb10 - ok 07:56:37.0224 4992 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 07:56:37.0225 4992 mrxsmb20 - ok 07:56:37.0239 4992 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys 07:56:37.0239 4992 msahci - ok 07:56:37.0256 4992 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys 07:56:37.0257 4992 msdsm - ok 07:56:37.0275 4992 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe 07:56:37.0276 4992 MSDTC - ok 07:56:37.0288 4992 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 07:56:37.0288 4992 Msfs - ok 07:56:37.0294 4992 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 07:56:37.0294 4992 mshidkmdf - ok 07:56:37.0308 4992 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys 07:56:37.0309 4992 msisadrv - ok 07:56:37.0344 4992 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll 07:56:37.0345 4992 MSiSCSI - ok 07:56:37.0346 4992 msiserver - ok 07:56:37.0371 4992 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 07:56:37.0372 4992 MSKSSRV - ok 07:56:37.0378 4992 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 07:56:37.0378 4992 MSPCLOCK - ok 07:56:37.0394 4992 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 07:56:37.0394 4992 MSPQM - ok 07:56:37.0417 4992 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys 07:56:37.0427 4992 MsRPC - ok 07:56:37.0435 4992 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys 07:56:37.0435 4992 mssmbios - ok 07:56:37.0448 4992 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 07:56:37.0448 4992 MSTEE - ok 07:56:37.0456 4992 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys 07:56:37.0456 4992 MTConfig - ok 07:56:37.0466 4992 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 07:56:37.0466 4992 Mup - ok 07:56:37.0503 4992 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll 07:56:37.0506 4992 napagent - ok 07:56:37.0559 4992 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 07:56:37.0561 4992 NativeWifiP - ok 07:56:37.0625 4992 NDIS (c38b8ae57f78915905064a9a24dc1586) C:\Windows\system32\drivers\ndis.sys 07:56:37.0636 4992 NDIS - ok 07:56:37.0639 4992 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 07:56:37.0639 4992 NdisCap - ok 07:56:37.0660 4992 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 07:56:37.0660 4992 NdisTapi - ok 07:56:37.0667 4992 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys 07:56:37.0668 4992 Ndisuio - ok 07:56:37.0681 4992 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys 07:56:37.0682 4992 NdisWan - ok 07:56:37.0690 4992 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys 07:56:37.0691 4992 NDProxy - ok 07:56:37.0700 4992 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 07:56:37.0700 4992 NetBIOS - ok 07:56:37.0717 4992 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys 07:56:37.0719 4992 NetBT - ok 07:56:37.0754 4992 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 07:56:37.0755 4992 Netlogon - ok 07:56:37.0786 4992 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll 07:56:37.0789 4992 Netman - ok 07:56:37.0858 4992 NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 07:56:37.0859 4992 NetMsmqActivator - ok 07:56:37.0861 4992 NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 07:56:37.0861 4992 NetPipeActivator - ok 07:56:37.0889 4992 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll 07:56:37.0892 4992 netprofm - ok 07:56:37.0893 4992 NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 07:56:37.0894 4992 NetTcpActivator - ok 07:56:37.0896 4992 NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 07:56:37.0896 4992 NetTcpPortSharing - ok 07:56:37.0916 4992 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys 07:56:37.0917 4992 nfrd960 - ok 07:56:37.0940 4992 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll 07:56:37.0942 4992 NlaSvc - ok 07:56:38.0111 4992 NOBU (b9b72faaaa41d59b73b88fe3dd737ed1) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe 07:56:38.0122 4992 NOBU - ok 07:56:38.0186 4992 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 07:56:38.0186 4992 Npfs - ok 07:56:38.0195 4992 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll 07:56:38.0195 4992 nsi - ok 07:56:38.0197 4992 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 07:56:38.0198 4992 nsiproxy - ok 07:56:38.0273 4992 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys 07:56:38.0305 4992 Ntfs - ok 07:56:38.0357 4992 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 07:56:38.0358 4992 Null - ok 07:56:38.0383 4992 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys 07:56:38.0384 4992 nvraid - ok 07:56:38.0404 4992 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys 07:56:38.0405 4992 nvstor - ok 07:56:38.0420 4992 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys 07:56:38.0421 4992 nv_agp - ok 07:56:38.0434 4992 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys 07:56:38.0434 4992 ohci1394 - ok 07:56:38.0503 4992 ose (9d10f99a6712e28f8acd5641e3a7ea6b) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 07:56:38.0504 4992 ose - ok 07:56:38.0698 4992 osppsvc (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 07:56:38.0716 4992 osppsvc - ok 07:56:38.0771 4992 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll 07:56:38.0774 4992 p2pimsvc - ok 07:56:38.0807 4992 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll 07:56:38.0815 4992 p2psvc - ok 07:56:38.0859 4992 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\drivers\parport.sys 07:56:38.0859 4992 Parport - ok 07:56:38.0894 4992 partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys 07:56:38.0895 4992 partmgr - ok 07:56:38.0919 4992 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll 07:56:38.0920 4992 PcaSvc - ok 07:56:38.0946 4992 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys 07:56:38.0947 4992 pci - ok 07:56:38.0955 4992 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys 07:56:38.0955 4992 pciide - ok 07:56:38.0974 4992 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys 07:56:38.0976 4992 pcmcia - ok 07:56:38.0982 4992 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 07:56:38.0983 4992 pcw - ok 07:56:39.0018 4992 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 07:56:39.0030 4992 PEAUTH - ok 07:56:39.0097 4992 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe 07:56:39.0098 4992 PerfHost - ok 07:56:39.0173 4992 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll 07:56:39.0181 4992 pla - ok 07:56:39.0237 4992 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll 07:56:39.0239 4992 PlugPlay - ok 07:56:39.0242 4992 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll 07:56:39.0243 4992 PNRPAutoReg - ok 07:56:39.0263 4992 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll 07:56:39.0265 4992 PNRPsvc - ok 07:56:39.0308 4992 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll 07:56:39.0314 4992 PolicyAgent - ok 07:56:39.0339 4992 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll 07:56:39.0341 4992 Power - ok 07:56:39.0381 4992 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys 07:56:39.0381 4992 PptpMiniport - ok 07:56:39.0392 4992 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys 07:56:39.0392 4992 Processor - ok 07:56:39.0413 4992 ProfSvc (5c78838b4d166d1a27db3a8a820c799a) C:\Windows\system32\profsvc.dll 07:56:39.0414 4992 ProfSvc - ok 07:56:39.0446 4992 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 07:56:39.0446 4992 ProtectedStorage - ok 07:56:39.0468 4992 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys 07:56:39.0469 4992 Psched - ok 07:56:39.0490 4992 PxHlpa64 (87b04878a6d59d6c79251dc960c674c1) C:\Windows\system32\Drivers\PxHlpa64.sys 07:56:39.0491 4992 PxHlpa64 - ok 07:56:39.0561 4992 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys 07:56:39.0570 4992 ql2300 - ok 07:56:39.0636 4992 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys 07:56:39.0637 4992 ql40xx - ok 07:56:39.0659 4992 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll 07:56:39.0661 4992 QWAVE - ok 07:56:39.0675 4992 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 07:56:39.0675 4992 QWAVEdrv - ok 07:56:39.0682 4992 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 07:56:39.0682 4992 RasAcd - ok 07:56:39.0697 4992 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 07:56:39.0698 4992 RasAgileVpn - ok 07:56:39.0712 4992 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll 07:56:39.0714 4992 RasAuto - ok 07:56:39.0724 4992 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys 07:56:39.0725 4992 Rasl2tp - ok 07:56:39.0746 4992 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll 07:56:39.0749 4992 RasMan - ok 07:56:39.0760 4992 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 07:56:39.0760 4992 RasPppoe - ok 07:56:39.0770 4992 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 07:56:39.0770 4992 RasSstp - ok 07:56:39.0791 4992 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys 07:56:39.0793 4992 rdbss - ok 07:56:39.0800 4992 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\drivers\rdpbus.sys 07:56:39.0800 4992 rdpbus - ok 07:56:39.0806 4992 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 07:56:39.0806 4992 RDPCDD - ok 07:56:39.0818 4992 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 07:56:39.0818 4992 RDPENCDD - ok 07:56:39.0833 4992 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 07:56:39.0833 4992 RDPREFMP - ok 07:56:39.0874 4992 RDPWD (6d76e6433574b058adcb0c50df834492) C:\Windows\system32\drivers\RDPWD.sys 07:56:39.0875 4992 RDPWD - ok 07:56:39.0893 4992 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys 07:56:39.0895 4992 rdyboost - ok 07:56:39.0929 4992 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll 07:56:39.0930 4992 RemoteAccess - ok 07:56:39.0946 4992 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll 07:56:39.0948 4992 RemoteRegistry - ok 07:56:40.0070 4992 RoxMediaDB12OEM (3c957189b31c34d3ad21967b12b6aed7) C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe 07:56:40.0085 4992 RoxMediaDB12OEM - ok 07:56:40.0133 4992 RoxWatch12 (2b73088cc2ca757a172b425c9398e5bc) C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe 07:56:40.0134 4992 RoxWatch12 - ok 07:56:40.0210 4992 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll 07:56:40.0211 4992 RpcEptMapper - ok 07:56:40.0227 4992 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe 07:56:40.0228 4992 RpcLocator - ok 07:56:40.0252 4992 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll 07:56:40.0255 4992 RpcSs - ok 07:56:40.0310 4992 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 07:56:40.0311 4992 rspndr - ok 07:56:40.0347 4992 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 07:56:40.0347 4992 SamSs - ok 07:56:40.0359 4992 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys 07:56:40.0360 4992 sbp2port - ok 07:56:40.0452 4992 SBSDWSCService (794d4b48dfb6e999537c7c3947863463) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe 07:56:40.0456 4992 SBSDWSCService - ok 07:56:40.0480 4992 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll 07:56:40.0481 4992 SCardSvr - ok 07:56:40.0495 4992 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys 07:56:40.0496 4992 scfilter - ok 07:56:40.0551 4992 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll 07:56:40.0558 4992 Schedule - ok 07:56:40.0583 4992 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll 07:56:40.0584 4992 SCPolicySvc - ok 07:56:40.0595 4992 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll 07:56:40.0597 4992 SDRSVC - ok 07:56:40.0625 4992 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 07:56:40.0625 4992 secdrv - ok 07:56:40.0636 4992 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll 07:56:40.0637 4992 seclogon - ok 07:56:40.0650 4992 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll 07:56:40.0651 4992 SENS - ok 07:56:40.0665 4992 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll 07:56:40.0666 4992 SensrSvc - ok 07:56:40.0678 4992 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\drivers\serenum.sys 07:56:40.0678 4992 Serenum - ok 07:56:40.0691 4992 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\drivers\serial.sys 07:56:40.0692 4992 Serial - ok 07:56:40.0702 4992 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys 07:56:40.0702 4992 sermouse - ok 07:56:40.0717 4992 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll 07:56:40.0718 4992 SessionEnv - ok 07:56:40.0728 4992 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys 07:56:40.0729 4992 sffdisk - ok 07:56:40.0735 4992 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys 07:56:40.0735 4992 sffp_mmc - ok 07:56:40.0740 4992 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys 07:56:40.0740 4992 sffp_sd - ok 07:56:40.0743 4992 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys 07:56:40.0743 4992 sfloppy - ok 07:56:40.0803 4992 Sftfs (c6cc9297bd53e5229653303e556aa539) C:\Windows\system32\DRIVERS\Sftfslh.sys 07:56:40.0810 4992 Sftfs - ok 07:56:40.0908 4992 sftlist (13693b6354dd6e72dc5131da7d764b90) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe 07:56:40.0910 4992 sftlist - ok 07:56:40.0929 4992 Sftplay (390aa7bc52cee43f6790cdea1e776703) C:\Windows\system32\DRIVERS\Sftplaylh.sys 07:56:40.0932 4992 Sftplay - ok 07:56:40.0938 4992 Sftredir (617e29a0b0a2807466560d4c4e338d3e) C:\Windows\system32\DRIVERS\Sftredirlh.sys 07:56:40.0939 4992 Sftredir - ok 07:56:41.0022 4992 SftService (74ec60e20516aaa573be74f31175270f) C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE 07:56:41.0029 4992 SftService - ok 07:56:41.0104 4992 Sftvol (8f571f016fa1976f445147e9e6c8ae9b) C:\Windows\system32\DRIVERS\Sftvollh.sys 07:56:41.0104 4992 Sftvol - ok 07:56:41.0121 4992 sftvsa (c3cddd18f43d44ab713cf8c4916f7696) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe 07:56:41.0122 4992 sftvsa - ok 07:56:41.0154 4992 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll 07:56:41.0156 4992 SharedAccess - ok 07:56:41.0185 4992 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll 07:56:41.0188 4992 ShellHWDetection - ok 07:56:41.0206 4992 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys 07:56:41.0207 4992 SiSRaid2 - ok 07:56:41.0217 4992 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys 07:56:41.0218 4992 SiSRaid4 - ok 07:56:41.0244 4992 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 07:56:41.0245 4992 Smb - ok 07:56:41.0258 4992 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe 07:56:41.0259 4992 SNMPTRAP - ok 07:56:41.0261 4992 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 07:56:41.0261 4992 spldr - ok 07:56:41.0294 4992 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe 07:56:41.0296 4992 Spooler - ok 07:56:41.0419 4992 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe 07:56:41.0433 4992 sppsvc - ok 07:56:41.0466 4992 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll 07:56:41.0467 4992 sppuinotify - ok 07:56:41.0519 4992 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys 07:56:41.0522 4992 srv - ok 07:56:41.0548 4992 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys 07:56:41.0558 4992 srv2 - ok 07:56:41.0573 4992 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys 07:56:41.0574 4992 srvnet - ok 07:56:41.0603 4992 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll 07:56:41.0605 4992 SSDPSRV - ok 07:56:41.0612 4992 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll 07:56:41.0613 4992 SstpSvc - ok 07:56:41.0648 4992 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys 07:56:41.0648 4992 stexstor - ok 07:56:41.0695 4992 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll 07:56:41.0699 4992 stisvc - ok 07:56:41.0748 4992 stllssvr (7731f46ec0d687a931cba063e8f90ef0) C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe 07:56:41.0749 4992 stllssvr - ok 07:56:41.0757 4992 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys 07:56:41.0757 4992 swenum - ok 07:56:41.0796 4992 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll 07:56:41.0800 4992 swprv - ok 07:56:41.0869 4992 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll 07:56:41.0880 4992 SysMain - ok 07:56:41.0947 4992 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll 07:56:41.0948 4992 TabletInputService - ok 07:56:41.0970 4992 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll 07:56:41.0972 4992 TapiSrv - ok 07:56:41.0983 4992 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll 07:56:41.0984 4992 TBS - ok 07:56:42.0093 4992 Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys 07:56:42.0109 4992 Tcpip - ok 07:56:42.0230 4992 TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys 07:56:42.0237 4992 TCPIP6 - ok 07:56:42.0314 4992 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys 07:56:42.0314 4992 tcpipreg - ok 07:56:42.0319 4992 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 07:56:42.0320 4992 TDPIPE - ok 07:56:42.0356 4992 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys 07:56:42.0356 4992 TDTCP - ok 07:56:42.0366 4992 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys 07:56:42.0367 4992 tdx - ok 07:56:42.0377 4992 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\DRIVERS\termdd.sys 07:56:42.0378 4992 TermDD - ok 07:56:42.0413 4992 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll 07:56:42.0417 4992 TermService - ok 07:56:42.0432 4992 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll 07:56:42.0433 4992 Themes - ok 07:56:42.0457 4992 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll 07:56:42.0458 4992 THREADORDER - ok 07:56:42.0472 4992 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll 07:56:42.0473 4992 TrkWks - ok 07:56:42.0510 4992 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe 07:56:42.0512 4992 TrustedInstaller - ok 07:56:42.0516 4992 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys 07:56:42.0516 4992 tssecsrv - ok 07:56:42.0531 4992 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys 07:56:42.0531 4992 TsUsbFlt - ok 07:56:42.0533 4992 TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys 07:56:42.0534 4992 TsUsbGD - ok 07:56:42.0561 4992 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys 07:56:42.0562 4992 tunnel - ok 07:56:42.0568 4992 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys 07:56:42.0569 4992 uagp35 - ok 07:56:42.0592 4992 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys 07:56:42.0594 4992 udfs - ok 07:56:42.0616 4992 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe 07:56:42.0617 4992 UI0Detect - ok 07:56:42.0623 4992 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys 07:56:42.0624 4992 uliagpkx - ok 07:56:42.0649 4992 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys 07:56:42.0649 4992 umbus - ok 07:56:42.0653 4992 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys 07:56:42.0653 4992 UmPass - ok 07:56:42.0674 4992 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll 07:56:42.0685 4992 upnphost - ok 07:56:42.0721 4992 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys 07:56:42.0721 4992 USBAAPL64 - ok 07:56:42.0763 4992 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys 07:56:42.0764 4992 usbaudio - ok 07:56:42.0788 4992 usbccgp (19ad7990c0b67e48dac5b26f99628223) C:\Windows\system32\DRIVERS\usbccgp.sys 07:56:42.0789 4992 usbccgp - ok 07:56:42.0805 4992 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys 07:56:42.0805 4992 usbcir - ok 07:56:42.0817 4992 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys 07:56:42.0817 4992 usbehci - ok 07:56:42.0848 4992 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys 07:56:42.0852 4992 usbhub - ok 07:56:42.0864 4992 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys 07:56:42.0865 4992 usbohci - ok 07:56:42.0876 4992 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 07:56:42.0876 4992 usbprint - ok 07:56:42.0901 4992 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys 07:56:42.0901 4992 usbscan - ok 07:56:42.0922 4992 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS 07:56:42.0923 4992 USBSTOR - ok 07:56:42.0940 4992 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys 07:56:42.0940 4992 usbuhci - ok 07:56:42.0949 4992 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll 07:56:42.0950 4992 UxSms - ok 07:56:42.0988 4992 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 07:56:42.0989 4992 VaultSvc - ok 07:56:43.0000 4992 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys 07:56:43.0001 4992 vdrvroot - ok 07:56:43.0042 4992 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe 07:56:43.0045 4992 vds - ok 07:56:43.0058 4992 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 07:56:43.0058 4992 vga - ok 07:56:43.0063 4992 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 07:56:43.0064 4992 VgaSave - ok 07:56:43.0084 4992 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys 07:56:43.0085 4992 vhdmp - ok 07:56:43.0091 4992 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys 07:56:43.0092 4992 viaide - ok 07:56:43.0105 4992 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys 07:56:43.0106 4992 volmgr - ok 07:56:43.0134 4992 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys 07:56:43.0145 4992 volmgrx - ok 07:56:43.0166 4992 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys 07:56:43.0168 4992 volsnap - ok 07:56:43.0175 4992 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys 07:56:43.0176 4992 vsmraid - ok 07:56:43.0248 4992 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe 07:56:43.0258 4992 VSS - ok 07:56:43.0337 4992 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys 07:56:43.0338 4992 vwifibus - ok 07:56:43.0360 4992 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys 07:56:43.0361 4992 vwififlt - ok 07:56:43.0384 4992 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll 07:56:43.0387 4992 W32Time - ok 07:56:43.0395 4992 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys 07:56:43.0395 4992 WacomPen - ok 07:56:43.0419 4992 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 07:56:43.0419 4992 WANARP - ok 07:56:43.0421 4992 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 07:56:43.0421 4992 Wanarpv6 - ok 07:56:43.0521 4992 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe 07:56:43.0530 4992 WatAdminSvc - ok 07:56:43.0591 4992 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe 07:56:43.0601 4992 wbengine - ok 07:56:43.0643 4992 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll 07:56:43.0645 4992 WbioSrvc - ok 07:56:43.0674 4992 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll 07:56:43.0676 4992 wcncsvc - ok 07:56:43.0684 4992 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll 07:56:43.0685 4992 WcsPlugInService - ok 07:56:43.0690 4992 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys 07:56:43.0690 4992 Wd - ok 07:56:43.0724 4992 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 07:56:43.0734 4992 Wdf01000 - ok 07:56:43.0743 4992 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll 07:56:43.0744 4992 WdiServiceHost - ok 07:56:43.0745 4992 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll 07:56:43.0746 4992 WdiSystemHost - ok 07:56:43.0763 4992 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll 07:56:43.0765 4992 WebClient - ok 07:56:43.0785 4992 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll 07:56:43.0787 4992 Wecsvc - ok 07:56:43.0797 4992 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll 07:56:43.0798 4992 wercplsupport - ok 07:56:43.0819 4992 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll 07:56:43.0820 4992 WerSvc - ok 07:56:43.0837 4992 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 07:56:43.0838 4992 WfpLwf - ok 07:56:43.0876 4992 WimFltr (b14ef15bd757fa488f9c970eee9c0d35) C:\Windows\system32\DRIVERS\wimfltr.sys 07:56:43.0877 4992 WimFltr - ok 07:56:43.0882 4992 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 07:56:43.0883 4992 WIMMount - ok 07:56:43.0898 4992 WinDefend - ok 07:56:43.0901 4992 WinHttpAutoProxySvc - ok 07:56:43.0953 4992 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll 07:56:43.0955 4992 Winmgmt - ok 07:56:44.0046 4992 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll 07:56:44.0058 4992 WinRM - ok 07:56:44.0178 4992 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys 07:56:44.0178 4992 WinUsb - ok 07:56:44.0230 4992 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll 07:56:44.0259 4992 Wlansvc - ok 07:56:44.0302 4992 wlcrasvc (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 07:56:44.0302 4992 wlcrasvc - ok 07:56:44.0463 4992 wlidsvc (2bacd71123f42cea603f4e205e1ae337) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 07:56:44.0472 4992 wlidsvc - ok 07:56:44.0527 4992 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys 07:56:44.0527 4992 WmiAcpi - ok 07:56:44.0570 4992 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe 07:56:44.0572 4992 wmiApSrv - ok 07:56:44.0600 4992 WMPNetworkSvc - ok 07:56:44.0615 4992 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll 07:56:44.0616 4992 WPCSvc - ok 07:56:44.0632 4992 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll 07:56:44.0634 4992 WPDBusEnum - ok 07:56:44.0639 4992 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 07:56:44.0640 4992 ws2ifsl - ok 07:56:44.0659 4992 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\system32\wscsvc.dll 07:56:44.0660 4992 wscsvc - ok 07:56:44.0661 4992 WSearch - ok 07:56:44.0762 4992 wuauserv (9df12edbc698b0bc353b3ef84861e430) C:\Windows\system32\wuaueng.dll 07:56:44.0794 4992 wuauserv - ok 07:56:44.0834 4992 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys 07:56:44.0834 4992 WudfPf - ok 07:56:44.0871 4992 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys 07:56:44.0873 4992 WUDFRd - ok 07:56:44.0886 4992 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll 07:56:44.0887 4992 wudfsvc - ok 07:56:44.0904 4992 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll 07:56:44.0906 4992 WwanSvc - ok 07:56:44.0917 4992 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0 07:56:45.0103 4992 \Device\Harddisk0\DR0 - ok 07:56:45.0106 4992 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk5\DR5 07:56:45.0110 4992 \Device\Harddisk5\DR5 - ok 07:56:45.0112 4992 Boot (0x1200) (b47dd407cbb10e300a44fcdd62b43d98) \Device\Harddisk0\DR0\Partition0 07:56:45.0112 4992 \Device\Harddisk0\DR0\Partition0 - ok 07:56:45.0124 4992 Boot (0x1200) (27c6b8bb3bbf3b9ecd89175df41264ee) \Device\Harddisk0\DR0\Partition1 07:56:45.0125 4992 \Device\Harddisk0\DR0\Partition1 - ok 07:56:45.0127 4992 Boot (0x1200) (67618d338dc706b97ecec99f24ec168e) \Device\Harddisk5\DR5\Partition0 07:56:45.0128 4992 \Device\Harddisk5\DR5\Partition0 - ok 07:56:45.0128 4992 ============================================================ 07:56:45.0128 4992 Scan finished 07:56:45.0128 4992 ============================================================ 07:56:45.0132 8804 Detected object count: 0 07:56:45.0132 8804 Actual detected object count: 0
OK, nothing was found in that but I still want a ComboFix log.

Before running it, please do the following:

Spybot TeaTimer

Please disable this program and leave it disabled until we are done as it can interfere with some of the tools we use.
  • launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • on the left hand side, click on Tools, then click on the Resident Icon in the list.
  • uncheck the Resident TeaTimer (Protection of overall system settings) active box.
  • click on the System Startup icon in the List
  • uncheck the "TeaTimer" box and click OK at any prompts.
  • if Teatimer gives you a warning that changes were made, click Allow Change when prompted.
  • exit Spybot S&D.
(When we are finished, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup).

Thanks

Satchfan
Had a bit of an issue with ComboFix the first time I ran it. After finishing the scan, it told me it had to restart the computer. It specifically told me not to manually restart - it would do it for me. But then my machine said it couldn't restart without force-closing a program. (Apparently, I still had Yahoo IM up and running - I thought I had it turned off.) I waited to see ComboFix would do it for me, but after a lengthy pause, I chose to manually close it. At which point, it returned me to the desktop. I figured I had to wait until CF restarted, but again, nothing happened for a lengthy period of time. Not only that, but my mouse was then inactive. After waiting awhile, I went ahead and tabbed over to manually restart the computer. The computer restarted, CF started compiling a log, and then hit an error. This ended up closing CF, and at that point, I couldn't open any other program. I once again did a manual restart, which seems to have cleared out whatever that issue was. I ran CF again with no problems this time. But I thought I'd let you know about that issue in case it has any bearing on anything. Here's the CF log. ComboFix 12-05-17.05 - alf 05/17/2012 8:27.2.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6126.4649 [GMT -6:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116} SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . —- Previous Run ——- . c:\programdata\2172905584 c:\programdata\370173d2u587h743k306j0xyi3v8 c:\windows\assembly\GAC_32\Desktop.ini c:\windows\assembly\GAC_64\Desktop.ini c:\windows\system32\consrv.dll . . ((((((((((((((((((((((((( Files Created from 2012-04-17 to 2012-05-17 ))))))))))))))))))))))))))))))) . . 2012-05-17 14:39 . 2012-05-17 14:39 ——– d—–w- c:\users\Shere Khan\AppData\Local\temp 2012-05-17 14:39 . 2012-05-17 14:39 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-05-15 09:03 . 2012-05-15 09:03 ——– d—–w- c:\program files\Microsoft Silverlight 2012-05-15 09:03 . 2012-05-15 09:03 ——– d—–w- c:\program files (x86)\Microsoft Silverlight 2012-05-13 13:28 . 2012-05-13 13:28 ——– d—–w- c:\windows\en 2012-05-13 13:20 . 2012-05-13 13:20 15712 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\205fb6511cd310b02\MeshBetaRemover.exe 2012-05-13 13:20 . 2012-05-13 13:20 89944 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\203598731cd310b01\DSETUP.dll 2012-05-13 13:20 . 2012-05-13 13:20 537432 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\203598731cd310b01\DXSETUP.exe 2012-05-13 13:20 . 2012-05-13 13:20 1801048 —-a-w- c:\program files (x86)\Common Files\Windows Live\.cache\203598731cd310b01\dsetup32.dll 2012-05-12 14:47 . 2012-03-03 06:35 1544704 —-a-w- c:\windows\system32\DWrite.dll 2012-05-12 14:47 . 2012-03-03 05:31 1077248 —-a-w- c:\windows\SysWow64\DWrite.dll 2012-05-12 14:46 . 2012-03-31 06:05 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-05-12 14:46 . 2012-03-31 04:39 3968368 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-05-12 14:46 . 2012-03-31 04:39 3913072 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-05-12 14:46 . 2012-03-31 03:10 3146240 —-a-w- c:\windows\system32\win32k.sys 2012-05-12 14:46 . 2012-03-17 07:58 75120 —-a-w- c:\windows\system32\drivers\partmgr.sys 2012-05-12 14:46 . 2012-03-30 11:35 1918320 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-05-12 14:46 . 2012-03-31 05:42 1732096 —-a-w- c:\program files\Windows Journal\NBDoc.DLL 2012-05-12 14:46 . 2012-03-31 05:40 1402880 —-a-w- c:\program files\Windows Journal\JNWDRV.dll 2012-05-12 14:46 . 2012-03-31 05:40 1367552 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2012-05-12 14:46 . 2012-03-31 05:40 1393664 —-a-w- c:\program files\Windows Journal\JNTFiltr.dll 2012-05-12 14:46 . 2012-03-31 04:29 936960 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll 2012-05-06 16:59 . 2012-05-06 16:59 ——– d—–w- c:\program files (x86)\Mozilla Maintenance Service 2012-05-06 16:59 . 2012-05-06 16:59 157352 —-a-w- c:\program files (x86)\Mozilla Firefox\maintenanceservice_installer.exe 2012-05-06 16:59 . 2012-05-06 16:59 129976 —-a-w- c:\program files (x86)\Mozilla Firefox\maintenanceservice.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-04-04 21:56 . 2011-12-15 00:47 24904 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-03-22 19:12 . 2012-03-22 19:12 4435968 —-a-w- c:\windows\SysWow64\GPhotos.scr 2012-03-16 01:25 . 2011-07-23 03:15 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2012-03-09 00:50 . 2012-03-09 00:50 49016 —-a-w- c:\windows\SysWow64\sirenacm.dll 2012-03-09 00:37 . 2012-03-09 00:37 302448 —-a-w- c:\windows\WLXPGSS.SCR 2012-03-01 06:46 . 2012-04-13 09:01 23408 —-a-w- c:\windows\system32\drivers\fs_rec.sys 2012-03-01 06:38 . 2012-04-13 09:01 220672 —-a-w- c:\windows\system32\wintrust.dll 2012-03-01 06:33 . 2012-04-13 09:01 81408 —-a-w- c:\windows\system32\imagehlp.dll 2012-03-01 06:28 . 2012-04-13 09:01 5120 —-a-w- c:\windows\system32\wmi.dll 2012-03-01 05:37 . 2012-04-13 09:01 172544 —-a-w- c:\windows\SysWow64\wintrust.dll 2012-03-01 05:33 . 2012-04-13 09:01 159232 —-a-w- c:\windows\SysWow64\imagehlp.dll 2012-03-01 05:29 . 2012-04-13 09:01 5120 —-a-w- c:\windows\SysWow64\wmi.dll 2012-02-28 06:56 . 2012-04-13 09:04 2311168 —-a-w- c:\windows\system32\jscript9.dll 2012-02-28 06:49 . 2012-04-13 09:04 1390080 —-a-w- c:\windows\system32\wininet.dll 2012-02-28 06:48 . 2012-04-13 09:04 1493504 —-a-w- c:\windows\system32\inetcpl.cpl 2012-02-28 06:42 . 2012-04-13 09:04 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-02-28 01:18 . 2012-04-13 09:04 1799168 —-a-w- c:\windows\SysWow64\jscript9.dll 2012-02-28 01:11 . 2012-04-13 09:04 1427456 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2012-02-28 01:11 . 2012-04-13 09:04 1127424 —-a-w- c:\windows\SysWow64\wininet.dll 2012-02-28 01:03 . 2012-04-13 09:04 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\alf\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\alf\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\alf\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="c:\progra~2\Yahoo!\Messenger\YahooMessenger.exe" [2011-06-16 6276408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-09-13 283160] "ShwiconXP9106"="c:\program files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe" [2010-03-10 237568] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-05 336384] "THX Audio Control Panel"="c:\program files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" [2009-12-01 963584] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "Dell Registration"="c:\program files (x86)\System Registration\prodreg.exe" [2010-11-10 4144448] "Dell DataSafe Online"="c:\program files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe" [2010-08-26 1117528] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2012-04-04 35736] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112] "Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544] "AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2011-04-29 885760] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-01-17 421736] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] . c:\users\alf\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\alf\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-2-14 24246216] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-06 136176] R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-06 136176] R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [x] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-05-06 129976] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-13 13336] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2012-05-12 2152688] S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x] S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776] S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-08-18 1692480] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x] S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [2011-12-24 17152] S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496] . . Contents of the 'Scheduled Tasks' folder . 2012-05-17 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-11-03 04:49] . 2012-05-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-06 15:09] . 2012-05-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-06 15:09] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\alf\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\alf\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\alf\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\alf\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-06-23 10920552] "RunDLLEntry_THXCfg"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568] "RunDLLEntry_EptMon"="c:\windows\system32\RunDLL32.exe" [2009-07-14 45568] "DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2011-04-29 2055016] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 TCP: DhcpNameServer = 10.0.1.1 FF - ProfilePath - c:\users\alf\AppData\Roaming\Mozilla\Firefox\Profiles\y0ok9hyo.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Toolbar-Locked - (no file) HKLM-Run-combofix - c:\combofix\CF14675.3XE . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-05-17 08:40:25 ComboFix-quarantined-files.txt 2012-05-17 14:40 . Pre-Run: 743,924,142,080 bytes free Post-Run: 743,801,503,744 bytes free . - - End Of File - - FF2588B205251375EF0866F715410AA5
I actually HAD turned off TeaTimer, in the first part of your instructions. When I went to do the second part, "Teatimer" wasn't on the list given after clicking System StartUp.
Apologies.

I just saw it active in your OTL log.

Also, I notice you have previously run ComboFix which is not recommended. ComboFix is a VERY powerful tool that can reduce a computer to a useless piece of metal without expert guidance.

Please send the log from when you ran it. ComboFix logs are located at c:\combofix.txt, older logs are at c:\qoobox\combofix2.txt, c:\qoobox\ComboFix3.txt etc

Thanks

Satchfan
This is from your OTL log:

[2012/05/15 19:49:38 | 000,000,000 | —D | C] – C:\Qoobox

Are you saying that you didn't run it on the 15th and that there is no Qoobox folder at this location?
I did run it on the 15th. Part of my misbegotten attempt to find out the problem. I apologize, and should not have done so. Entering "C:\Qoobox" as an address takes me to folder I posted above.
Open ComboFix

Please do the following:
  • close any open browsers.
  • close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
  • open notepad and copy/paste the text in the codebox below into it:
File::
C:\Users\alf\AppData\Local\370173d2u587h743k306j0xyi3v8

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.

=============================================

Please also run aswMBR again and send a new log.

Can you tell me how your computer is running now.

Thanks

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI