This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer become unresponsive [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, for some reason, my computer became slower than its usual behavior, I updated and ran Malwarebytes Antimalware Virus Scan and it got nothing, so does my ESET Smart Sercurity 4 scan. I just want to make sure my computer is free from malware so somebody please help me analyse the log and see whether is my computer is clean or not. Thanks in advance. OTL log at below


OTL logfile created on: 6/4/2012 3:51:43 PM - Run 1
OTL by OldTimer - Version 3.2.46.0 Folder = C:\Users\User\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.98 Gb Total Physical Memory | 2.60 Gb Available Physical Memory | 65.33% Memory free
7.97 Gb Paging File | 6.23 Gb Available in Paging File | 78.27% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 200.00 Gb Total Space | 146.07 Gb Free Space | 73.03% Space Free | Partition Type: NTFS
Drive D: | 731.41 Gb Total Space | 627.79 Gb Free Space | 85.83% Space Free | Partition Type: NTFS

Computer Name: VINCENT-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\User\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - D:\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Razer\BlackWidow Ultimate\BlackWidowUltimateTray.exe (Razer USA Ltd)
PRC - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe (ESET)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Stardock\ObjectDockFree\ObjectDock.exe (Stardock)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Brother\Brmfcmon\BrMfcMon.exe (Brother Industries, Ltd.)


========== Modules (No Company Name) ==========

MOD - D:\Steam\bin\libcef.dll ()
MOD - D:\Steam\bin\mssvoice.asi ()
MOD - D:\Steam\bin\mssmp3.asi ()
MOD - D:\Steam\bin\chromehtml.dll ()
MOD - D:\Steam\bin\avutil-51.dll ()
MOD - D:\Steam\bin\avformat-53.dll ()
MOD - D:\Steam\bin\avcodec-53.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\eac8b316dbdcc6fdba0d80e76063643c\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\3b2b9f4ec1819e4b95792d92f56d26f9\IAStorCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\90555968565afd59bce4b0974e9903bd\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\69f6e582cb79f107c61308b468c1a215\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Stardock\ObjectDockFree\zlib.dll ()
MOD - C:\Program Files (x86)\Stardock\ObjectDockFree\CrashRpt.dll ()
MOD - C:\Program Files (x86)\Stardock\ObjectDockFree\DockShellHook.dll ()
MOD - C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (EhttpSrv) – C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe (ESET)
SRV:64bit: - (ekrn) – C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe (ESET)
SRV:64bit: - (Mcx2Svc) – C:\Windows\SysNative\Mcx2Svc.dll (Microsoft Corporation)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (AppleChargerSrv) – C:\Windows\SysNative\AppleChargerSrv.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (RemoteAccess) – C:\Windows\SysNative\mprdim.dll (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (McAfee SiteAdvisor Service) – c:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe (McAfee, Inc.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (npggsvc) – C:\Windows\SysWOW64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (IAStorDataMgrSvc) Intel® – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (RemoteAccess) – C:\Windows\SysWOW64\mprdim.dll (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (EtronHub3) – C:\Windows\SysNative\drivers\EtronHub3.sys (Etron Technology Inc)
DRV:64bit: - (EtronXHCI) – C:\Windows\SysNative\drivers\EtronXHCI.sys (Etron Technology Inc)
DRV:64bit: - (AppleCharger) – C:\Windows\SysNative\drivers\AppleCharger.sys ()
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (eamonm) – C:\Windows\SysNative\drivers\eamonm.sys (ESET)
DRV:64bit: - (ehdrv) – C:\Windows\SysNative\drivers\ehdrv.sys (ESET)
DRV:64bit: - (epfw) – C:\Windows\SysNative\drivers\epfw.sys (ESET)
DRV:64bit: - (epfwwfp) – C:\Windows\SysNative\drivers\epfwwfp.sys (ESET)
DRV:64bit: - (Epfwndis) – C:\Windows\SysNative\drivers\epfwndis.sys (ESET)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (udfs) – C:\Windows\SysNative\drivers\udfs.sys (Microsoft Corporation)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RzSynapse) – C:\Windows\SysNative\drivers\RzSynapse.sys (Razer USA Ltd)
DRV:64bit: - (VKbms) – C:\Windows\SysNative\drivers\VKbms.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (taphss) – C:\Windows\SysNative\drivers\taphss.sys (AnchorFree Inc)
DRV:64bit: - (MEIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (athur) – C:\Windows\SysNative\drivers\athurx.sys (Atheros Communications, Inc.)
DRV:64bit: - (vhidmini) – C:\Windows\SysNative\drivers\vHidDev.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (Abyssus) – C:\Windows\SysNative\drivers\Abyssus.sys (Razer (Asia-Pacific) Pte Ltd)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (crcdisk) – C:\Windows\SysNative\drivers\crcdisk.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ws2ifsl) – C:\Windows\SysNative\drivers\ws2ifsl.sys (Microsoft Corporation)
DRV:64bit: - (cdfs) – C:\Windows\SysNative\drivers\cdfs.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (gdrv) – C:\Windows\gdrv.sys (Windows ® Server 2003 DDK provider)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (NPPTNT2) – C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddrnw&s;=…hTerms}&f;=4
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://malaysia.msn.com/?rd=1&ucc;=MY&a;…cc=MY&opt;=0
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 8C 75 2D 35 EB 38 CD 01 [binary data]
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://start.facemoods.com/?a=ddrnw&s;=…hTerms}&f;=4
IE - HKCU\..\SearchScopes\{64698B9F-6D40-45CF-A006-B1FC456047B7}: "URL" = http://search.yahoo.com/search?fr=mcafee&p;={SearchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google Search"
FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=mcafee&p;="
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_235.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/02/24 20:54:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/08/24 15:23:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/13 20:48:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2011/04/20 23:17:32 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[removed]: C:\Users\User\AppData\Roaming\IDM\idmmzcc3

[2011/05/02 11:55:38 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\mozilla\Extensions
[2011/07/13 19:52:06 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\fi7452xl.default\extensions
[2012/03/02 14:57:13 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/06/03 11:46:29 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/06/12 21:33:58 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2012/03/02 14:57:13 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
[2012/02/24 20:54:27 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR
File not found (No name found) – C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/07/13 19:52:06 | 000,914,263 | —- | M] () (No name found) – C:\USERS\USER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\FI7452XL.DEFAULT\EXTENSIONS\[removed]
[2011/04/15 00:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/03/02 14:57:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010/01/01 16:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/06/25 09:14:07 | 000,002,048 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrch.xml
[2011/11/03 17:22:18 | 000,002,024 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\19.0.1084.52\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\19.0.1084.52\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\19.0.1084.52\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - Extension: SiteAdvisor = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\

O1 HOSTS File: ([2009/06/11 05:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2:64bit: - BHO: (no name) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - No CLSID value found.
O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [Razer Blackwidow Driver] C:\Program Files (x86)\Razer\BlackWidow Ultimate\BlackWidowUltimateTray.exe (Razer USA Ltd)
O4 - HKCU..\Run: [Steam] D:\Steam\steam.exe (Valve Corporation)
O4 - Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = C:\Program Files (x86)\Stardock\ObjectDockFree\ObjectDock.exe (Stardock)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6C82C38F-C1D9-4093-B0CE-F8E010A4FFC8}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B46CF462-51F3-4281-AE83-7B4481CB7C9E}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{c31ce406-8366-11e0-9fd0-1c6f65d28ce4}\Shell - "" = AutoRun
O33 - MountPoints2\{c31ce406-8366-11e0-9fd0-1c6f65d28ce4}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/06/04 14:19:35 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{80AA5EC0-17BA-4F72-A257-50748C63C0BC}
[2012/06/04 14:19:21 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{97D3896E-9515-4355-B0DB-B3A3F9F973C8}
[2012/05/29 11:44:51 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{F07D48CE-92EE-434D-8EE4-7728E8C84801}
[2012/05/29 11:44:39 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{FE5605FA-FE51-45CD-875B-7297C310F4BE}
[2012/05/28 23:44:11 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{77195409-B5C8-44B8-AF99-A808BE6A9602}
[2012/05/28 23:43:59 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{144CD892-33F4-4CB9-A1A4-A345AB227690}
[2012/05/28 12:47:46 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\NVIDIA
[2012/05/28 12:47:45 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TechPowerUp GPU-Z
[2012/05/28 12:47:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\GPU-Z
[2012/05/28 11:43:32 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{43E5DFF6-F37B-4202-988F-5F711BFC86A2}
[2012/05/28 11:43:20 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{E25DB835-73F1-4DC6-8C03-85C98C52DCF5}
[2012/05/27 23:42:49 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{341C299B-AF84-4B5F-9930-54F488316A8F}
[2012/05/27 23:42:38 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{59E65BB6-18D3-44EF-83B4-F2C583211C79}
[2012/05/27 11:42:21 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{6828B719-7C0F-40E1-AB47-5A456347B178}
[2012/05/27 11:41:58 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{CFC7C441-5F23-4C7D-B471-65741971EA3A}
[2012/05/26 21:00:12 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{BB7314F8-176B-494D-8D0A-F9CB2FA3E3E6}
[2012/05/26 21:00:01 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{C3FED71E-A3DB-4C33-845D-7D71C5E7B128}
[2012/05/26 15:07:10 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\ShanghaiAlice
[2012/05/26 08:59:44 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{DCE02D1B-53C4-4474-91E5-13970A3999DE}
[2012/05/26 08:59:29 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{C33E70A9-5E79-4720-8497-A4AF3BC46CE7}
[2012/05/25 13:10:18 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{90E19893-8B34-4769-832F-174C13F2FD42}
[2012/05/25 13:10:05 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{4A0AD7D6-7C4E-4E9A-A271-E2DAC04BE3DF}
[2012/05/24 14:34:53 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{C03946D1-E550-4D68-8B6F-8FE20C28D9EC}
[2012/05/24 14:34:41 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{EFA680AF-B856-4061-A177-2369A3F429AF}
[2012/05/23 14:54:14 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{DBB2FF37-EF06-4A9A-B3F0-D506924F0607}
[2012/05/23 14:53:36 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{D81F5C8E-4FB5-4CE7-AE01-68968CE50533}
[2012/05/22 14:46:39 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{715902CE-69FB-49D4-8061-F0759127C259}
[2012/05/22 14:46:01 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{6CF2AB6D-2C85-4C26-9CA3-1B07D2D31915}
[2012/05/21 17:14:50 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{B65D1FB2-1568-4ADE-81EB-67014B144E1F}
[2012/05/21 17:14:35 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{A99FD929-C19C-4858-BCE3-DEDE96BC579D}
[2012/05/20 18:22:13 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{B7587681-7A24-434E-9AD2-D89F1B5C626D}
[2012/05/20 18:21:44 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{4874F555-CCB8-4EDB-9F4C-D9CFFFDEA294}
[2012/05/19 21:25:11 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{32723947-1890-4450-AFDD-CD2DDDD13C6A}
[2012/05/19 21:24:59 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{BA523FA2-8E0C-46A5-9219-441AA23D2C8D}
[2012/05/19 09:24:43 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{938AC767-CAEC-4771-8B07-F9F357730FF8}
[2012/05/19 09:24:25 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{CF189451-99CD-42B3-B59B-123B77FFDA08}
[2012/05/18 14:07:32 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{853EACFD-735D-4B33-AB59-21A5A483CBC5}
[2012/05/18 14:07:17 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{89C600AC-6A1D-4A13-9357-79A74E8D46BC}
[2012/05/17 15:26:33 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{5EE0DAAD-2425-409A-B8ED-9D1EFCAFEFBF}
[2012/05/17 15:26:21 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{381BB2BA-385C-443C-86A1-F550D458656A}
[2012/05/16 22:46:26 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{6AEFC36F-73E3-4F09-B810-430EB55FE214}
[2012/05/16 22:46:14 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{52BF9F66-4548-40ED-9A63-F08D5DD974DC}
[2012/05/16 10:45:58 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{5FD26335-1CAC-45F4-BD74-80E9134F1DE6}
[2012/05/16 10:45:46 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{2609972D-6920-43A0-84F2-94B48D06A6CA}
[2012/05/15 22:00:52 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{97B543E9-3B76-40DA-81F9-34F0E0D42192}
[2012/05/15 22:00:40 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{D205FD78-02E6-450B-A14A-DBD285CCF11B}
[2012/05/15 10:00:11 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{92045F19-47F2-45BC-8EFA-FB909E4B4E98}
[2012/05/15 09:59:59 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{E36505D3-A2C8-44FE-A310-44F528B60D67}
[2012/05/14 15:25:30 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{A22B53A0-201B-468B-9665-CDD49FFAE4A8}
[2012/05/14 15:25:14 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{76CAF548-190C-45FB-8370-2E16304F1D1A}
[2012/05/13 13:55:35 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{5C2E3316-246E-4D21-80AD-28C2FF62A5B8}
[2012/05/13 13:55:22 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{439AE75F-8C73-4C95-B6B3-F01A38213952}
[2012/05/12 23:06:57 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{119795E2-8730-40C3-98C9-6E35DB0D0755}
[2012/05/12 23:06:46 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{7EAB5891-459B-42AA-A656-673A8CD6E9E8}
[2012/05/12 11:06:14 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{2975FEE0-0D4B-46EC-9E88-5390D90DD312}
[2012/05/12 11:05:45 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{49FEC1F3-1159-4D07-9080-347FF0994184}
[2012/05/11 13:35:25 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{8932B440-CB8D-4B00-8241-DA027428314A}
[2012/05/11 13:35:14 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{1C539C7A-888C-4A89-A27D-218E0A63A245}
[2012/05/10 14:43:43 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{4B6A7D31-9CEA-4D2B-AB79-19A36A5075EA}
[2012/05/10 14:43:31 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{55B8216B-73AA-41A3-87A4-97AFAEA4CFEE}
[2012/05/09 22:06:15 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{A7D46930-6490-4E94-A077-EA1CF2B8767F}
[2012/05/09 22:06:04 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{00750247-8C73-490E-9E4F-2525D7FD4430}
[2012/05/09 11:12:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/05/09 11:12:07 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2012/05/09 11:12:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2012/05/09 10:09:40 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/05/09 10:09:37 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/05/09 10:09:37 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/05/09 10:09:16 | 001,544,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2012/05/09 10:05:35 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{395E9BF5-7654-437D-A9E6-453CF51B55FE}
[2012/05/09 10:05:22 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{4720776B-168D-4676-ACAD-F0F64A2A3A46}
[2012/05/08 17:10:59 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{D6A67493-E5D7-47DA-A368-5211244A05E1}
[2012/05/08 17:10:44 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{1D146D7B-FC22-405D-86BE-28AD593E5D6D}
[2012/05/07 17:10:58 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{C7BD0C6C-6786-4825-930D-17F4E1CC5393}
[2012/05/07 17:10:46 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{863B4B2A-6029-426D-BB15-0336EB90B7BD}
[2012/05/06 12:48:40 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{AAC5414E-BE1C-47CF-BAA9-C47A6566A417}
[2012/05/06 12:48:23 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{4C6B0A5A-7166-45D2-84F7-1B5A45330910}
[2012/05/06 00:30:24 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{B47117F8-4E6E-426C-B303-AE92D0046737}
[2012/05/06 00:30:12 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\{382DEB02-F617-4D01-A0C1-05C9CD5A7ABC}

========== Files - Modified Within 30 Days ==========

[2012/06/04 15:35:33 | 000,015,008 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/04 15:35:33 | 000,015,008 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/04 15:28:05 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/04 15:28:01 | 3208,192,000 | -HS- | M] () – C:\hiberfil.sys
[2012/06/04 14:32:57 | 000,726,444 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/04 14:32:57 | 000,624,162 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/04 14:32:57 | 000,106,538 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/05/28 20:56:02 | 000,045,270 | —- | M] () – C:\Users\User\AppData\Roaming\room_v3.dat
[2012/05/09 10:30:25 | 000,419,720 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/05/06 00:34:31 | 000,419,488 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/05/06 00:34:31 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/05/06 00:34:23 | 008,744,608 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerInstaller.exe

========== Files Created - No Company Name ==========

[2011/12/21 14:15:54 | 000,000,032 | R— | C] () – C:\ProgramData\hash.dat
[2011/09/28 17:44:14 | 000,179,271 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/05/25 19:46:41 | 000,045,270 | —- | C] () – C:\Users\User\AppData\Roaming\room_v3.dat
[2011/05/15 13:38:25 | 000,000,033 | —- | C] () – C:\Windows\DownloadStudioScheduleMonitor.INI
[2011/05/08 11:58:59 | 000,000,025 | —- | C] () – C:\Windows\libem.INI
[2011/04/20 18:49:09 | 000,007,626 | —- | C] () – C:\Users\User\AppData\Local\resmon.resmoncfg
[2011/04/02 19:10:20 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2011/04/02 17:48:26 | 000,000,419 | —- | C] () – C:\Windows\BRWMARK.INI
[2011/04/02 09:50:58 | 000,000,389 | —- | C] () – C:\Users\User\AppData\Local\JunkAtx18.bin
[2011/04/02 09:39:52 | 000,046,742 | —- | C] () – C:\Users\User\AppData\Roaming\room.dat
[2011/04/02 09:27:49 | 000,000,014 | —- | C] () – C:\Users\User\AppData\Local\NetMailTmp.bin
[2011/03/30 16:10:53 | 000,008,192 | —- | C] () – C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2011/03/30 16:06:47 | 000,000,010 | —- | C] () – C:\Windows\GSetup.ini

========== LOP Check ==========

[2011/06/03 11:54:36 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\.minecraft
[2011/04/02 15:49:16 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\AVG10
[2011/05/08 11:58:59 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\BITS
[2011/05/01 11:23:39 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\DMCache
[2011/04/20 23:18:07 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\ESET
[2011/10/03 21:03:35 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\EurekaLog
[2011/05/08 12:15:18 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\FlashGet
[2011/05/08 11:58:46 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\FlashGetBHO
[2012/05/28 20:43:22 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\GarenaPlus
[2011/04/02 14:48:17 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\ImgBurn
[2011/06/17 20:41:35 | 000,000,000 | RHSD | M] – C:\Users\User\AppData\Roaming\install
[2011/09/18 17:32:34 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\LolClient2
[2011/06/25 00:51:25 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Mipony
[2011/12/24 09:53:52 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Mumble
[2012/05/26 15:07:10 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\ShanghaiAlice
[2011/03/31 13:40:50 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Stardock
[2011/11/12 14:41:43 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\SystemRequirementsLab
[2011/04/03 21:49:40 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Windows Live Writer
[2012/04/11 15:55:38 | 000,032,618 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2011/03/30 16:10:53 | 000,000,180 | —- | M] () – C:\csb.log
[2012/06/04 15:28:01 | 3208,192,000 | -HS- | M] () – C:\hiberfil.sys
[2011/03/30 16:09:12 | 000,000,189 | —- | M] () – C:\Install.log
[2012/06/04 15:28:03 | 4277,592,064 | -HS- | M] () – C:\pagefile.sys
[2011/03/30 16:08:47 | 000,002,128 | —- | M] () – C:\RHDSetup.log

< %systemroot%\Fonts\*.com >
[2009/07/14 13:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 13:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 13:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 13:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/11 04:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/03/08 18:37:20 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 12:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/17 23:20:58 | 000,000,221 | -HS- | M] () – C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >

OTL Extras logfile created on: 6/4/2012 3:51:43 PM - Run 1
OTL by OldTimer - Version 3.2.46.0 Folder = C:\Users\User\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.98 Gb Total Physical Memory | 2.60 Gb Available Physical Memory | 65.33% Memory free
7.97 Gb Paging File | 6.23 Gb Available in Paging File | 78.27% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 200.00 Gb Total Space | 146.07 Gb Free Space | 73.03% Space Free | Partition Type: NTFS
Drive D: | 731.41 Gb Total Space | 627.79 Gb Free Space | 85.83% Space Free | Partition Type: NTFS

Computer Name: VINCENT-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe" = C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3
"C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe" = C:\Program Files (x86)\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0980DB20-EA1C-41A5-97FA-2EC0AD00033B}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{185C93CD-76C4-4100-976B-12955ECA65ED}" = lport=2869 | protocol=6 | dir=in | app=system |
"{18AA3385-76D1-41D3-913F-69BB18A5C996}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{20B556C5-1017-4293-856D-727B10694894}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{2D4B76CF-184B-402D-99EA-1A1D696BD316}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{2D98D196-467D-4E56-8266-D066F6377359}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{3C3912C1-CCA5-4143-ADBE-3211AFFF65C3}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4F3F7D4C-94A0-420C-A801-DD6950D8AB3A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{501B46D9-6C4C-40ED-A96D-A1E435B5FC07}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{5A1498E1-8AB8-4A27-8EC6-6BBA8E9E666D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{5EA3B067-F1EE-4D4A-8213-11A5C0EC600E}" = lport=138 | protocol=17 | dir=in | app=system |
"{5F9A68DB-58FB-4532-BB8E-C8C1054D5CAE}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{617608D1-8A30-4D24-8AB8-7318C74DBCD1}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{68027352-E686-42F0-91B8-DDAB9ACD2176}" = rport=139 | protocol=6 | dir=out | app=system |
"{6A7F4F61-1245-4446-8FBF-10687AB4CDD6}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{705DE4F6-DCE2-4B96-BC68-CE5B69093468}" = rport=138 | protocol=17 | dir=out | app=system |
"{80F7C4EE-995C-47AB-8CB9-571D67511CA1}" = rport=10243 | protocol=6 | dir=out | app=system |
"{84B8D74A-7A41-4489-AF59-31266C5B8844}" = rport=137 | protocol=17 | dir=out | app=system |
"{9D0487DD-9E1C-4754-9651-2024E6AD58C3}" = lport=8370 | protocol=17 | dir=in | name=league of legends launcher |
"{9DDB864A-F836-49A5-9311-5B1E867CD079}" = lport=8370 | protocol=6 | dir=in | name=league of legends launcher |
"{A022EEE8-1508-4851-95F0-053A54E6F11E}" = lport=445 | protocol=6 | dir=in | app=system |
"{A2D8C91F-6C80-4572-9299-90481FD5F532}" = lport=139 | protocol=6 | dir=in | app=system |
"{AAA7E9CE-F29C-4A8A-9C15-0FC1EFB2AAFF}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{B6D4F802-6A6B-480A-B1EE-8986E230E98C}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{CA8C4B13-A013-4BDF-B419-A29DF1BE8915}" = rport=445 | protocol=6 | dir=out | app=system |
"{F75A27E1-3EE4-4593-8AF7-54ED78843527}" = lport=137 | protocol=17 | dir=in | app=system |
"{F7DF48C3-7CF8-48DF-B177-AAFB261E14CF}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FCB399FC-052B-4D74-A284-7136AB4D2B4B}" = lport=10243 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{026C1DE2-9CBB-4CB1-B56A-B506628C6881}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{030F9A1C-4319-4D15-830B-141A5507E88F}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{044DF8EA-56B5-462C-B06F-5B166791B1B1}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{0FE50DA5-906D-4BB4-AFFC-DDEF9F341CB0}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\spiral knights\java_vm\bin\javaw.exe |
"{10605CB2-25F2-4A3A-AD53-67D3214FD08A}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{1CFC6642-ED6C-489E-9764-3A7B58D91058}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\rusty hearts\clientlauncher.exe |
"{25799E53-E889-4D3F-8DE8-6A77FE256179}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{365FB8DE-0C77-4C41-9868-6B890DBB1C3F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{381758A3-E412-46A2-B539-B0495846A30F}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\grand theft auto iv\gtaiv\launchgtaiv.exe |
"{3B8A793D-A295-42C1-8A4E-7F6D155264DE}" = protocol=6 | dir=in | app=d:\garenalol\gamedata\apps\lol\air\lolclient.exe |
"{3F2F92C5-9F6C-404B-A592-985A1D7EA287}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\sonic generations\sonicgenerations.exe |
"{40D864EF-D028-49DC-9ECE-680E6C4AAC27}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{4A654429-F7EB-4CE1-B642-4C62B6BCAF4A}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{4B83BE7D-DB61-423D-B8D1-E3738F37A544}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{4C229D9C-C34F-42C4-A083-30E511F9A150}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{5467573B-C405-4612-9F7E-E74464846B93}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{56D9B11C-A42B-493C-8456-84D822962040}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{5D7D083F-7318-49CE-9072-3003126DCD38}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\sonic generations\configurationtool.exe |
"{618553FA-FA8E-45BB-8D96-86A19BEFCACB}" = protocol=17 | dir=in | app=c:\program files (x86)\garena messenger\apps\blackshot\blackshot\system\blackshot.exe |
"{626E1ABA-AB60-4574-9594-34E2348FFB96}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\grand theft auto iv\gtaiv\launchgtaiv.exe |
"{6C64527B-D7C8-45BB-9A51-4CED1DE7D886}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6D9F0DC0-4E63-4B55-A044-C4B6524D81DB}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{728C4FAC-0CC4-47ED-BBA1-576F168871E6}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\dota 2 beta\dota.exe |
"{744A2B10-CB73-4F61-BB3B-B630C1F30131}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{808360F0-FDF6-4B75-A080-3764296730CA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8100202B-14D5-4B22-ACA5-20C0BF60AF68}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{810C7C12-9D6E-4C20-9E51-6ED8643FC707}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\dota 2 test\dota.exe |
"{83854330-D453-46A8-8067-C2DFD8D9C7BE}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\sonic generations\configurationtool.exe |
"{8BB9FD51-3445-40DA-AA14-90BA9F4490E4}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8E363989-8497-44AC-8DEA-2A9B5D795418}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{905A9A7F-5EFC-4A80-84A8-2A31A63915F6}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\dota 2 beta\dota.exe |
"{9107661F-1AB4-46C5-9823-AA9C6D5A92C9}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{911AFB6C-5336-49CC-9D8D-8D38DC93C797}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{99306958-4475-4E80-836A-A92B98DD5148}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\sonic generations\sonicgenerations.exe |
"{99621324-DD84-4A2A-9B14-50888A2B6886}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{9E163051-6FF0-42ED-90B4-A87D3C83868A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{9E33AECF-03E1-4053-A227-E12FDFAA71E4}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{9ED3C59F-ECCC-40D0-8544-DDFE9C1AAEEF}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\spiral knights\java_vm\bin\javaw.exe |
"{A03BEA00-2B22-4BF2-85E4-D4F1AB67384A}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{A77A6195-CC0E-4C94-AFFE-AC33931CB300}" = protocol=6 | dir=in | app=d:\steam\steam.exe |
"{A9F5F60F-417D-4A65-9556-A0E4C2DC5694}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{AC90163A-3B61-4E94-9652-7024B3B4A3E6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{AE106125-867F-4BE7-89AF-9CAB2F09B1C7}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\skyrim\skyrimlauncher.exe |
"{B0E1AB43-A8CC-4F41-A973-9FD3D6C51BA4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B3DE07F5-C8C7-4150-8396-0A6CE16D327E}" = protocol=17 | dir=in | app=c:\program files (x86)\garena messenger\garenamessenger.exe |
"{B7DC5C29-A530-4B0A-9847-1FC7A54E8613}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{BB93E6C2-7E12-4D4F-87DC-4CE4DCB204A0}" = protocol=17 | dir=in | app=d:\garenalol\gamedata\apps\lol\game\league of legends.exe |
"{BD6F4D69-3C53-4BD7-81C3-9072C6875FCD}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{BE0C1B69-6E2C-433A-ACDE-85B74F885216}" = protocol=6 | dir=in | app=c:\program files (x86)\garena messenger\apps\blackshot\blackshot\system\blackshot.exe |
"{BFBAAFA5-16FC-4F1D-A12B-DFB3F78E40CD}" = protocol=17 | dir=in | app=d:\steam\steam.exe |
"{C491BD20-153F-4A0D-9550-F4BC3138C932}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{C565200F-ACD6-4193-8E58-4DF8D84F3D05}" = protocol=6 | dir=out | app=system |
"{C6BEC27C-D443-4F24-8074-0722C6E6FE44}" = protocol=6 | dir=in | app=c:\program files (x86)\garena messenger\garenamessenger.exe |
"{C938ED69-B393-4496-91AF-C9B02DB11A29}" = protocol=6 | dir=in | app=d:\garenalol\gamedata\apps\lol\game\league of legends.exe |
"{DBFB6128-D1BF-4BBF-9028-9999882CC5CB}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{DD732893-1962-415C-8549-6A9153B692B4}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{E1013C71-7879-4959-B1AB-4D33BFBCBDCD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{EBB9C621-AB19-4470-A5FC-C74E1CF74DC2}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\dota 2 test\dota.exe |
"{F4B01D2B-15C2-4A87-8E6D-2C9F2DA2103E}" = protocol=17 | dir=in | app=d:\garenalol\gamedata\apps\lol\air\lolclient.exe |
"{F6E4E2D9-5529-4DC1-A7E7-00A2D92E6CAE}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{FBF01833-072B-41F0-8C47-2A3CD34EBBD2}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{FC81CEBC-9C1B-4637-9874-A3E5B94AFF27}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\rusty hearts\clientlauncher.exe |
"TCP Query User{0370705C-3B9D-42D2-AFA7-FD39C9C43A9D}D:\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe" = protocol=6 | dir=in | app=d:\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe |
"TCP Query User{085DBB54-9F6F-4913-A992-C0C5F4219D43}D:\left 4 dead 2\left4dead2.exe" = protocol=6 | dir=in | app=d:\left 4 dead 2\left4dead2.exe |
"TCP Query User{1080DA86-8BE7-42D9-87B3-A397C6B3BBB2}G:\warcraft iii\war3.exe" = protocol=6 | dir=in | app=g:\warcraft iii\war3.exe |
"TCP Query User{57836C7F-7F6E-4191-95F1-BFC56A70F6DB}D:\warcraft iii\war3.exe" = protocol=6 | dir=in | app=d:\warcraft iii\war3.exe |
"TCP Query User{7855023C-4C6C-4658-B575-B93FF36F3D73}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"TCP Query User{8B6635BF-E0AF-4D36-B07E-D566F68D25E2}D:\portal 2\portal2.exe" = protocol=6 | dir=in | app=d:\portal 2\portal2.exe |
"TCP Query User{8EE98D43-70E0-4814-BC50-A23A03330BB1}C:\program files (x86)\garena messenger\room\garena_room.exe" = protocol=6 | dir=in | app=c:\program files (x86)\garena messenger\room\garena_room.exe |
"TCP Query User{B2CB7D37-57AE-47D8-BCC1-6D7407D65DCD}D:\electronic arts\crytek\crysis 2\bin32\crysis2.exe" = protocol=6 | dir=in | app=d:\electronic arts\crytek\crysis 2\bin32\crysis2.exe |
"TCP Query User{D3573C8C-D09A-43C4-B2FC-2FB067366AE9}C:\program files (x86)\garena messenger\apps\hon\hon.exe" = protocol=6 | dir=in | app=c:\program files (x86)\garena messenger\apps\hon\hon.exe |
"TCP Query User{D42A527C-74C8-402A-A1A3-2CF6AEB0BB60}C:\program files (x86)\garena\garena.exe" = protocol=6 | dir=in | app=c:\program files (x86)\garena\garena.exe |
"TCP Query User{E104F0F2-8D53-4F4D-AD97-0DA5286A8543}C:\users\user\downloads\honinstaller.exe" = protocol=6 | dir=in | app=c:\users\user\downloads\honinstaller.exe |
"TCP Query User{E768F654-A824-4D0B-B483-3B270DCDA47B}F:\warcraft iii\war3.exe" = protocol=6 | dir=in | app=f:\warcraft iii\war3.exe |
"UDP Query User{042AEAEF-DCE5-4248-96C5-1E7E02B882B8}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"UDP Query User{0AFCC263-DDE3-4BA4-B1BD-DABCC63B5610}G:\warcraft iii\war3.exe" = protocol=17 | dir=in | app=g:\warcraft iii\war3.exe |
"UDP Query User{0FA0BE32-5D48-41D3-B429-D3C72743A816}F:\warcraft iii\war3.exe" = protocol=17 | dir=in | app=f:\warcraft iii\war3.exe |
"UDP Query User{133CD9E4-F134-4C98-B36C-2F47C6698ABF}C:\program files (x86)\garena messenger\room\garena_room.exe" = protocol=17 | dir=in | app=c:\program files (x86)\garena messenger\room\garena_room.exe |
"UDP Query User{2B346F07-061D-4AF7-A17E-FE6EEEB0ED33}C:\program files (x86)\garena messenger\apps\hon\hon.exe" = protocol=17 | dir=in | app=c:\program files (x86)\garena messenger\apps\hon\hon.exe |
"UDP Query User{36A859F1-E72D-4148-8550-C2A446F56DF2}D:\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe" = protocol=17 | dir=in | app=d:\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe |
"UDP Query User{4E934D61-418F-4F65-AC07-AEC102B5118F}C:\users\user\downloads\honinstaller.exe" = protocol=17 | dir=in | app=c:\users\user\downloads\honinstaller.exe |
"UDP Query User{54AE9B04-76F6-4EE8-BC08-53ABA0E1B665}D:\left 4 dead 2\left4dead2.exe" = protocol=17 | dir=in | app=d:\left 4 dead 2\left4dead2.exe |
"UDP Query User{7CBB4484-B279-4220-BAB1-37D98BC9F99F}D:\warcraft iii\war3.exe" = protocol=17 | dir=in | app=d:\warcraft iii\war3.exe |
"UDP Query User{843D2822-2C5B-42DB-87A8-77C537128E51}D:\electronic arts\crytek\crysis 2\bin32\crysis2.exe" = protocol=17 | dir=in | app=d:\electronic arts\crytek\crysis 2\bin32\crysis2.exe |
"UDP Query User{8544ECFB-ED65-4A73-974F-53A4A82AEDC8}C:\program files (x86)\garena\garena.exe" = protocol=17 | dir=in | app=c:\program files (x86)\garena\garena.exe |
"UDP Query User{E917E9C6-7FD9-4C54-BF67-EB5146BA3BA3}D:\portal 2\portal2.exe" = protocol=17 | dir=in | app=d:\portal 2\portal2.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{02A5BD31-16AC-45DF-BE9F-A3167BC4AFB2}" = Windows Live Family Safety
"{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{439760BC-7737-4386-9B1D-A90A3E8A22EA}" = Apple Mobile Device Support
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{997C9EC4-B53D-479D-81B7-0AEC8D174BA1}" = iTunes
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 266.58
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver [removed]
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{C0D93E4E-0866-43C8-A104-BF41A803EA84}" = ESET Smart Security
"{CA0D2F09-F811-48D4-843E-C87696C6A9D9}" = Bonjour
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"CCleaner" = CCleaner
"Explorer Suite_is1" = Explorer Suite III
"GooglePinyin2" = 谷歌拼音输入法 2.6
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"WinRAR archiver" = WinRAR 4.00 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0A3A9522-EFA2-4C56-9138-101692C2A130}" = System Requirements Lab
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1F77C418-2C90-459C-BD33-B56A4182B9FA}" = System Requirements Lab CYRI
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2C13F8C1-570B-42A9-87B4-8C7903ECD602}" = ObjectDock Free
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{3DECD372-76A1-4483-BF10-B547790A3261}" = ON_OFF Charge B11.0110.1
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{486E5025-65BC-4ECE-9C2C-0F51D73060AC}" = Blackout Ragnarok Online
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}" = Brother MFL-Pro Suite DCP-195C
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7A2A107B-9695-423F-9462-8F17C178BD35}" = TP-LINK Wireless Client Utility
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{926CC8AE-8414-43DF-8EB4-CF26D9C3C663}" =
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3AC9740-66D4-412F-AE55-DD0428F78175}" = Razer BlackWidow Ultimate
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Crysis 2_is1" = Crysis 2
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ESET Online Scanner" = ESET Online Scanner v3
"HoN" = Garena - Heroes of Newerth
"im" = Garena Messenger
"ImgBurn" = ImgBurn
"InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}" = Etron USB3.0 Host Controller
"Left 4 Dead 2_is1" = Left 4 Dead 2
"LoL" = Garena - League of Legends
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"ObjectDock Free" = ObjectDock Free
"Steam App 12220" = Grand Theft Auto: Episodes from Liberty City
"Steam App 36630" = Rusty Hearts
"Steam App 570" = Dota 2
"Steam App 71340" = Sonic Generations
"Steam App 72850" = The Elder Scrolls V: Skyrim
"Steam App 99900" = Spiral Knights
"TechPowerUp GPU-Z" = TechPowerUp GPU-Z
"The Sims 3_is1" = The Sims 3
"WinLiveSuite" = Windows Live Essentials

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/24/2012 8:41:36 AM | Computer Name = Vincent-PC | Source = Application Error | ID = 1000
Description = Faulting application name: chrome.exe, version: 0.0.0.0, time stamp:
0x4d8a4b6a Faulting module name: chrome.dll, version: 12.0.712.0, time stamp: 0x4d8a4b26
Exception
code: 0x80000003 Fault offset: 0x005202f4 Faulting process id: 0xbe8 Faulting application
start time: 0x01cd39a9381f2626 Faulting application path: C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
Faulting
module path: C:\Users\User\AppData\Local\Google\Chrome\Application\12.0.712.0\chrome.dll
Report
Id: cc14d9e9-a59d-11e1-aad9-1c6f65d28ce4

Error - 5/25/2012 2:30:20 AM | Computer Name = Vincent-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "c:\program files (x86)\ESET\eset
online scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 5/25/2012 10:01:10 AM | Computer Name = Vincent-PC | Source = Application Error | ID = 1000
Description = Faulting application name: SonicGenerations.exe, version: 1.0.0.5,
time stamp: 0x4ed631a1 Faulting module name: ntdll.dll, version: 6.1.7601.17725,
time stamp: 0x4ec49b8f Exception code: 0xc0000005 Fault offset: 0x00038dc9 Faulting
process id: 0x1828 Faulting application start time: 0x01cd3a7cd5dbaec8 Faulting application
path: d:\steam\steamapps\common\sonic generations\SonicGenerations.exe Faulting
module path: C:\Windows\SysWOW64\ntdll.dll Report Id: 142430ae-a672-11e1-99cf-1c6f65d28ce4

Error - 5/25/2012 11:55:51 AM | Computer Name = Vincent-PC | Source = Application Error | ID = 1000
Description = Faulting application name: chrome.exe, version: 0.0.0.0, time stamp:
0x4d8a4b6a Faulting module name: chrome.dll, version: 12.0.712.0, time stamp: 0x4d8a4b26
Exception
code: 0x80000003 Fault offset: 0x00002fc0 Faulting process id: 0x1750 Faulting application
start time: 0x01cd3a8ba59370a9 Faulting application path: C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
Faulting
module path: C:\Users\User\AppData\Local\Google\Chrome\Application\12.0.712.0\chrome.dll
Report
Id: 19f20475-a682-11e1-99cf-1c6f65d28ce4

Error - 5/25/2012 12:36:32 PM | Computer Name = Vincent-PC | Source = Application Error | ID = 1000
Description = Faulting application name: chrome.exe, version: 0.0.0.0, time stamp:
0x4d8a4b6a Faulting module name: chrome.dll, version: 12.0.712.0, time stamp: 0x4d8a4b26
Exception
code: 0x80000003 Fault offset: 0x005202f4 Faulting process id: 0x2f0 Faulting application
start time: 0x01cd3a8ede3bdf62 Faulting application path: C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
Faulting
module path: C:\Users\User\AppData\Local\Google\Chrome\Application\12.0.712.0\chrome.dll
Report
Id: c8c61a22-a687-11e1-99cf-1c6f65d28ce4

Error - 5/25/2012 9:59:17 PM | Computer Name = Vincent-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "c:\program files (x86)\ESET\eset
online scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 5/26/2012 7:45:31 AM | Computer Name = Vincent-PC | Source = Application Error | ID = 1000
Description = Faulting application name: chrome.exe, version: 0.0.0.0, time stamp:
0x4d8a4b6a Faulting module name: chrome.dll, version: 12.0.712.0, time stamp: 0x4d8a4b26
Exception
code: 0x80000003 Fault offset: 0x00002fc0 Faulting process id: 0xee0 Faulting application
start time: 0x01cd3b34136381f9 Faulting application path: C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
Faulting
module path: C:\Users\User\AppData\Local\Google\Chrome\Application\12.0.712.0\chrome.dll
Report
Id: 4b982a3d-a728-11e1-99ef-1c6f65d28ce4

Error - 5/27/2012 12:09:08 AM | Computer Name = Vincent-PC | Source = Application Hang | ID = 1002
Description = The program TESV.exe version 1.5.26.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 8a0 Start Time:
01cd3bbdbc8bef53 Termination Time: 102 Application Path: d:\steam\steamapps\common\skyrim\TESV.exe

Report
Id:

Error - 5/27/2012 1:18:41 AM | Computer Name = Vincent-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "c:\program files (x86)\ESET\eset
online scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 5/29/2012 3:41:25 AM | Computer Name = Vincent-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "c:\program files (x86)\ESET\eset
online scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

[ System Events ]
Error - 5/23/2012 2:52:57 AM | Computer Name = Vincent-PC | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description = WLAN Extensibility Module has failed to start. Module Path: C:\Windows\system32\athExt.dll
Error
Code: 126

Error - 5/24/2012 2:33:40 AM | Computer Name = Vincent-PC | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description = WLAN Extensibility Module has failed to start. Module Path: C:\Windows\system32\athExt.dll
Error
Code: 126

Error - 5/25/2012 1:09:23 AM | Computer Name = Vincent-PC | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description = WLAN Extensibility Module has failed to start. Module Path: C:\Windows\system32\athExt.dll
Error
Code: 126

Error - 5/25/2012 8:58:39 PM | Computer Name = Vincent-PC | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description = WLAN Extensibility Module has failed to start. Module Path: C:\Windows\system32\athExt.dll
Error
Code: 126

Error - 5/26/2012 11:40:54 PM | Computer Name = Vincent-PC | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description = WLAN Extensibility Module has failed to start. Module Path: C:\Windows\system32\athExt.dll
Error
Code: 126

Error - 5/27/2012 10:45:04 PM | Computer Name = Vincent-PC | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description = WLAN Extensibility Module has failed to start. Module Path: C:\Windows\system32\athExt.dll
Error
Code: 126

Error - 5/28/2012 12:59:14 AM | Computer Name = Vincent-PC | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description = WLAN Extensibility Module has failed to start. Module Path: C:\Windows\system32\athExt.dll
Error
Code: 126

Error - 5/28/2012 10:19:42 PM | Computer Name = Vincent-PC | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description = WLAN Extensibility Module has failed to start. Module Path: C:\Windows\system32\athExt.dll
Error
Code: 126

Error - 6/4/2012 2:18:07 AM | Computer Name = Vincent-PC | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description = WLAN Extensibility Module has failed to start. Module Path: C:\Windows\system32\athExt.dll
Error
Code: 126

Error - 6/4/2012 3:28:08 AM | Computer Name = Vincent-PC | Source = Microsoft-Windows-WLAN-AutoConfig | ID = 10000
Description = WLAN Extensibility Module has failed to start. Module Path: C:\Windows\system32\athExt.dll
Error
Code: 126


< End of report >
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!

Figuring out why a system is slower than usual can be a bit tough. Is the system slower only when you are on the internet or is it also slower when you are doing things with your browser closed as well?

I'd also like to get a couple of other scans from you. Different tools look in different locations for malware and I want to be sure we look thoroughly if you feel your machine isn't behaving normally.


Download and Run DDS by sUBs

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt and Attach.txt






Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
Hi, thank you for the help here :notworthy: here's the logs from both DDS and TDSSKiller . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31 Run by [removed] at 11:35:30 on 2012-06-08 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4079.2393 [GMT 8:00] . AV: ESET Smart Security 4.2 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1} SP: ESET Smart Security 4.2 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: ESET Personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe C:\Windows\system32\nvvsvc.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskhost.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Google\Google Pinyin 2\GooglePinyinDaemon.exe C:\Program Files\Google\Google Pinyin 2\GooglePinyinService.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE C:\Windows\system32\rundll32.exe C:\Windows\system32\rundll32.exe C:\Windows\SysWOW64\rundll32.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files\ESET\ESET Smart Security\egui.exe C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k imgsvc D:\Steam\Steam.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\Stardock\ObjectDockFree\ObjectDock.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe C:\Program Files (x86)\Razer\BlackWidow Ultimate\BlackWidowUltimateTray.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Brother\Brmfcmon\BrMfcmon.exe C:\Program Files (x86)\Stardock\ObjectDockFree\Dock64.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Common Files\Steam\SteamService.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\servicing\TrustedInstaller.exe C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\rundll32.exe C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe c:\PROGRA~2\mcafee\SITEAD~1\saui.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyOverride = *.local mSearchAssistant = hxxp://start.facemoods.com/?a=ddrnw&s;={searchTerms}&f;=4 uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll mWinlogon: Userinit=userinit.exe, BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~4\Office12\GR469A~1.DLL BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" TB: {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - No File uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background uRun: [Steam] "D:\Steam\steam.exe" -silent mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe mRun: [Razer Blackwidow Driver] C:\Program Files (x86)\Razer\BlackWidow Ultimate\BlackWidowUltimateTray.exe mRun: [BrMfcWnd] C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN mRun: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" StartupFolder: C:\Users\User\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\STARDO~1.LNK - C:\Program Files (x86)\Stardock\ObjectDockFree\ObjectDock.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport; to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{6C82C38F-C1D9-4093-B0CE-F8E010A4FFC8} : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{B46CF462-51F3-4281-AE83-7B4481CB7C9E} : DhcpNameServer = 192.168.1.1 Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~4\Office12\GRA32A~1.DLL Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~4\Office12\GR469A~1.DLL BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office12\GR469A~1.DLL BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO-X64: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB-X64: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" TB-X64: {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - No File mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe mRun-x64: [Razer Blackwidow Driver] C:\Program Files (x86)\Razer\BlackWidow Ultimate\BlackWidowUltimateTray.exe mRun-x64: [BrMfcWnd] C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN mRun-x64: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~4\Office12\GR469A~1.DLL . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\fi7452xl.default\ FF - prefs.js: browser.search.selectedEngine - Secure Search FF - prefs.js: browser.startup.homepage - about:home FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p;= FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll . ============= SERVICES / DRIVERS =============== . R1 AppleCharger;AppleCharger;C:\Windows\system32\DRIVERS\AppleCharger.sys –> C:\Windows\system32\DRIVERS\AppleCharger.sys [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928] R2 eamonm;eamonm;C:\Windows\system32\DRIVERS\eamonm.sys –> C:\Windows\system32\DRIVERS\eamonm.sys [?] R2 ekrn;ESET Service;C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2011-1-12 810144] R2 epfwwfp;epfwwfp;C:\Windows\system32\DRIVERS\epfwwfp.sys –> C:\Windows\system32\DRIVERS\epfwwfp.sys [?] R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-3-30 13336] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [2012-2-23 103440] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-1-7 378984] R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-3-30 2655768] R3 Abyssus;Razer Abyssus;C:\Windows\system32\drivers\Abyssus.sys –> C:\Windows\system32\drivers\Abyssus.sys [?] R3 athur;Wireless Network Adapter Service;C:\Windows\system32\DRIVERS\athurx.sys –> C:\Windows\system32\DRIVERS\athurx.sys [?] R3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;C:\Windows\system32\Drivers\EtronHub3.sys –> C:\Windows\system32\Drivers\EtronHub3.sys [?] R3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;C:\Windows\system32\Drivers\EtronXHCI.sys –> C:\Windows\system32\Drivers\EtronXHCI.sys [?] R3 MEIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys –> C:\Windows\system32\DRIVERS\HECIx64.sys [?] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys –> C:\Windows\system32\drivers\nvhda64v.sys [?] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] R3 RzSynapse;Razer Driver;C:\Windows\system32\DRIVERS\RzSynapse.sys –> C:\Windows\system32\DRIVERS\RzSynapse.sys [?] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys –> C:\Windows\system32\DRIVERS\vwifimp.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe –> system32\AppleChargerSrv.exe [?] S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-2-28 183560] S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys –> C:\Windows\system32\DRIVERS\fssfltr.sys [?] S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-3-8 1492840] S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service –> C:\Windows\system32\GameMon.des -service [?] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?] S3 VKbms;Virtual HID Minidriver;C:\Windows\system32\DRIVERS\VKbms.sys –> C:\Windows\system32\DRIVERS\VKbms.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== Created Last 30 ================ . 2012-06-08 03:28:21 ——– d—–w- C:\Users\User\AppData\Local\{8C5091EA-4CE2-407D-8A30-5D302551707B} 2012-06-08 03:28:05 ——– d—–w- C:\Users\User\AppData\Local\{3189DBA3-38FD-418F-AA60-69F862EF6D1C} 2012-06-07 08:51:36 ——– d—–w- C:\Users\User\AppData\Local\{4454D4C3-F90C-4FD9-A7F0-0E175D727FF9} 2012-06-07 08:51:22 ——– d—–w- C:\Users\User\AppData\Local\{CC15AFC5-68CA-4116-884C-29B9E806DFC6} 2012-06-06 16:12:48 ——– d—–w- C:\Users\User\AppData\Local\{98BBAFDF-E586-4514-B971-EB4D5DA1022B} 2012-06-06 16:12:34 ——– d—–w- C:\Users\User\AppData\Local\{0BCC5415-A755-4A86-A550-E65487F9550D} 2012-06-06 04:14:04 8955792 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9220EB6C-0D69-4A67-819D-5935B9AC9DC3}\mpengine.dll 2012-06-06 04:12:15 ——– d—–w- C:\Users\User\AppData\Local\{A76DEF50-9B70-4487-B47D-E08E47046820} 2012-06-06 04:12:02 ——– d—–w- C:\Users\User\AppData\Local\{A3138275-2FE5-4B7F-A31C-DAED44CE5613} 2012-06-05 16:02:40 ——– d—–w- C:\Users\User\AppData\Local\{544FFB74-4EF8-4005-9FB7-624B51C2288A} 2012-06-05 16:02:29 ——– d—–w- C:\Users\User\AppData\Local\{D6A9D291-F8B2-4412-954F-E889A7593C8D} 2012-06-05 05:15:55 ——– d—–w- C:\Users\User\AppData\Roaming\Garena 2012-06-05 05:15:55 ——– d—–w- C:\ProgramData\Garena 2012-06-05 04:01:59 ——– d—–w- C:\Users\User\AppData\Local\{CEC2FD98-C46D-4A58-868C-358BFFA5ECE3} 2012-06-05 04:01:41 ——– d—–w- C:\Users\User\AppData\Local\{3F9D7E50-47EE-4DA5-8894-AD7769E065D2} 2012-06-04 06:19:35 ——– d—–w- C:\Users\User\AppData\Local\{80AA5EC0-17BA-4F72-A257-50748C63C0BC} 2012-06-04 06:19:21 ——– d—–w- C:\Users\User\AppData\Local\{97D3896E-9515-4355-B0DB-B3A3F9F973C8} 2012-05-29 03:44:51 ——– d—–w- C:\Users\User\AppData\Local\{F07D48CE-92EE-434D-8EE4-7728E8C84801} 2012-05-29 03:44:39 ——– d—–w- C:\Users\User\AppData\Local\{FE5605FA-FE51-45CD-875B-7297C310F4BE} 2012-05-28 15:44:11 ——– d—–w- C:\Users\User\AppData\Local\{77195409-B5C8-44B8-AF99-A808BE6A9602} 2012-05-28 15:43:59 ——– d—–w- C:\Users\User\AppData\Local\{144CD892-33F4-4CB9-A1A4-A345AB227690} 2012-05-28 04:47:46 ——– d—–w- C:\Users\User\AppData\Roaming\NVIDIA 2012-05-28 04:47:45 ——– d—–w- C:\Program Files (x86)\GPU-Z 2012-05-28 03:43:32 ——– d—–w- C:\Users\User\AppData\Local\{43E5DFF6-F37B-4202-988F-5F711BFC86A2} 2012-05-28 03:43:20 ——– d—–w- C:\Users\User\AppData\Local\{E25DB835-73F1-4DC6-8C03-85C98C52DCF5} 2012-05-27 15:42:49 ——– d—–w- C:\Users\User\AppData\Local\{341C299B-AF84-4B5F-9930-54F488316A8F} 2012-05-27 15:42:38 ——– d—–w- C:\Users\User\AppData\Local\{59E65BB6-18D3-44EF-83B4-F2C583211C79} 2012-05-27 03:42:21 ——– d—–w- C:\Users\User\AppData\Local\{6828B719-7C0F-40E1-AB47-5A456347B178} 2012-05-27 03:41:58 ——– d—–w- C:\Users\User\AppData\Local\{CFC7C441-5F23-4C7D-B471-65741971EA3A} 2012-05-26 13:00:12 ——– d—–w- C:\Users\User\AppData\Local\{BB7314F8-176B-494D-8D0A-F9CB2FA3E3E6} 2012-05-26 13:00:01 ——– d—–w- C:\Users\User\AppData\Local\{C3FED71E-A3DB-4C33-845D-7D71C5E7B128} 2012-05-26 07:07:10 ——– d—–w- C:\Users\User\AppData\Roaming\ShanghaiAlice 2012-05-26 00:59:44 ——– d—–w- C:\Users\User\AppData\Local\{DCE02D1B-53C4-4474-91E5-13970A3999DE} 2012-05-26 00:59:29 ——– d—–w- C:\Users\User\AppData\Local\{C33E70A9-5E79-4720-8497-A4AF3BC46CE7} 2012-05-25 05:10:18 ——– d—–w- C:\Users\User\AppData\Local\{90E19893-8B34-4769-832F-174C13F2FD42} 2012-05-25 05:10:05 ——– d—–w- C:\Users\User\AppData\Local\{4A0AD7D6-7C4E-4E9A-A271-E2DAC04BE3DF} 2012-05-24 06:34:53 ——– d—–w- C:\Users\User\AppData\Local\{C03946D1-E550-4D68-8B6F-8FE20C28D9EC} 2012-05-24 06:34:41 ——– d—–w- C:\Users\User\AppData\Local\{EFA680AF-B856-4061-A177-2369A3F429AF} 2012-05-23 06:54:14 ——– d—–w- C:\Users\User\AppData\Local\{DBB2FF37-EF06-4A9A-B3F0-D506924F0607} 2012-05-23 06:53:36 ——– d—–w- C:\Users\User\AppData\Local\{D81F5C8E-4FB5-4CE7-AE01-68968CE50533} 2012-05-22 06:46:39 ——– d—–w- C:\Users\User\AppData\Local\{715902CE-69FB-49D4-8061-F0759127C259} 2012-05-22 06:46:01 ——– d—–w- C:\Users\User\AppData\Local\{6CF2AB6D-2C85-4C26-9CA3-1B07D2D31915} 2012-05-21 09:14:50 ——– d—–w- C:\Users\User\AppData\Local\{B65D1FB2-1568-4ADE-81EB-67014B144E1F} 2012-05-21 09:14:35 ——– d—–w- C:\Users\User\AppData\Local\{A99FD929-C19C-4858-BCE3-DEDE96BC579D} 2012-05-20 10:22:13 ——– d—–w- C:\Users\User\AppData\Local\{B7587681-7A24-434E-9AD2-D89F1B5C626D} 2012-05-20 10:21:44 ——– d—–w- C:\Users\User\AppData\Local\{4874F555-CCB8-4EDB-9F4C-D9CFFFDEA294} 2012-05-19 13:25:11 ——– d—–w- C:\Users\User\AppData\Local\{32723947-1890-4450-AFDD-CD2DDDD13C6A} 2012-05-19 13:24:59 ——– d—–w- C:\Users\User\AppData\Local\{BA523FA2-8E0C-46A5-9219-441AA23D2C8D} 2012-05-19 01:24:43 ——– d—–w- C:\Users\User\AppData\Local\{938AC767-CAEC-4771-8B07-F9F357730FF8} 2012-05-19 01:24:25 ——– d—–w- C:\Users\User\AppData\Local\{CF189451-99CD-42B3-B59B-123B77FFDA08} 2012-05-18 06:07:32 ——– d—–w- C:\Users\User\AppData\Local\{853EACFD-735D-4B33-AB59-21A5A483CBC5} 2012-05-18 06:07:17 ——– d—–w- C:\Users\User\AppData\Local\{89C600AC-6A1D-4A13-9357-79A74E8D46BC} 2012-05-17 07:26:33 ——– d—–w- C:\Users\User\AppData\Local\{5EE0DAAD-2425-409A-B8ED-9D1EFCAFEFBF} 2012-05-17 07:26:21 ——– d—–w- C:\Users\User\AppData\Local\{381BB2BA-385C-443C-86A1-F550D458656A} 2012-05-16 14:46:26 ——– d—–w- C:\Users\User\AppData\Local\{6AEFC36F-73E3-4F09-B810-430EB55FE214} 2012-05-16 14:46:14 ——– d—–w- C:\Users\User\AppData\Local\{52BF9F66-4548-40ED-9A63-F08D5DD974DC} 2012-05-16 02:45:58 ——– d—–w- C:\Users\User\AppData\Local\{5FD26335-1CAC-45F4-BD74-80E9134F1DE6} 2012-05-16 02:45:46 ——– d—–w- C:\Users\User\AppData\Local\{2609972D-6920-43A0-84F2-94B48D06A6CA} 2012-05-15 14:00:52 ——– d—–w- C:\Users\User\AppData\Local\{97B543E9-3B76-40DA-81F9-34F0E0D42192} 2012-05-15 14:00:40 ——– d—–w- C:\Users\User\AppData\Local\{D205FD78-02E6-450B-A14A-DBD285CCF11B} 2012-05-15 02:00:11 ——– d—–w- C:\Users\User\AppData\Local\{92045F19-47F2-45BC-8EFA-FB909E4B4E98} 2012-05-15 01:59:59 ——– d—–w- C:\Users\User\AppData\Local\{E36505D3-A2C8-44FE-A310-44F528B60D67} 2012-05-14 07:25:30 ——– d—–w- C:\Users\User\AppData\Local\{A22B53A0-201B-468B-9665-CDD49FFAE4A8} 2012-05-14 07:25:14 ——– d—–w- C:\Users\User\AppData\Local\{76CAF548-190C-45FB-8370-2E16304F1D1A} 2012-05-13 05:55:35 ——– d—–w- C:\Users\User\AppData\Local\{5C2E3316-246E-4D21-80AD-28C2FF62A5B8} 2012-05-13 05:55:22 ——– d—–w- C:\Users\User\AppData\Local\{439AE75F-8C73-4C95-B6B3-F01A38213952} 2012-05-12 15:06:57 ——– d—–w- C:\Users\User\AppData\Local\{119795E2-8730-40C3-98C9-6E35DB0D0755} 2012-05-12 15:06:46 ——– d—–w- C:\Users\User\AppData\Local\{7EAB5891-459B-42AA-A656-673A8CD6E9E8} 2012-05-12 03:06:14 ——– d—–w- C:\Users\User\AppData\Local\{2975FEE0-0D4B-46EC-9E88-5390D90DD312} 2012-05-12 03:05:45 ——– d—–w- C:\Users\User\AppData\Local\{49FEC1F3-1159-4D07-9080-347FF0994184} 2012-05-11 05:35:25 ——– d—–w- C:\Users\User\AppData\Local\{8932B440-CB8D-4B00-8241-DA027428314A} 2012-05-11 05:35:14 ——– d—–w- C:\Users\User\AppData\Local\{1C539C7A-888C-4A89-A27D-218E0A63A245} 2012-05-10 06:43:43 ——– d—–w- C:\Users\User\AppData\Local\{4B6A7D31-9CEA-4D2B-AB79-19A36A5075EA} 2012-05-10 06:43:31 ——– d—–w- C:\Users\User\AppData\Local\{55B8216B-73AA-41A3-87A4-97AFAEA4CFEE} 2012-05-09 14:06:15 ——– d—–w- C:\Users\User\AppData\Local\{A7D46930-6490-4E94-A077-EA1CF2B8767F} 2012-05-09 14:06:04 ——– d—–w- C:\Users\User\AppData\Local\{00750247-8C73-490E-9E4F-2525D7FD4430} . ==================== Find3M ==================== . 2012-05-05 16:34:31 70304 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-05-05 16:34:31 419488 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-05-05 16:34:23 8744608 —-a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe 2012-04-04 07:56:40 24904 —-a-w- C:\Windows\System32\drivers\mbam.sys 2012-03-31 06:05:57 5559664 —-a-w- C:\Windows\System32\ntoskrnl.exe 2012-03-31 04:39:37 3968368 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2012-03-31 04:39:37 3913072 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe 2012-03-31 03:10:03 3146240 —-a-w- C:\Windows\System32\win32k.sys 2012-03-30 11:35:47 1918320 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2012-03-17 07:58:57 75120 —-a-w- C:\Windows\System32\drivers\partmgr.sys . ============= FINISH: 11:36:03.65 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 3/30/2011 4:05:34 PM System Uptime: 6/8/2012 11:27:06 AM (0 hours ago) . Motherboard: Gigabyte Technology Co., Ltd. | | HA65M-UD3H-B3 Processor: Intel® Core™ i5-2400 CPU @ 3.10GHz | Socket 1155 | 3301/100mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 200 GiB total, 145.06 GiB free. D: is FIXED (NTFS) - 731 GiB total, 627.092 GiB free. E: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP208: 5/9/2012 11:11:32 AM - Windows Update RP209: 5/16/2012 11:38:29 AM - Scheduled Checkpoint RP210: 5/17/2012 3:29:42 PM - Windows Update RP211: 5/18/2012 10:57:27 PM - Installed DirectX RP212: 5/22/2012 2:49:52 PM - Windows Update RP213: 5/26/2012 4:08:21 PM - Windows Update RP214: 6/4/2012 2:21:43 PM - Windows Update RP215: 6/4/2012 3:53:06 PM - OTL Restore Point - 6/4/2012 3:53:03 PM . ==== Installed Programs ====================== . . Adobe Reader X (10.1.3) Apple Application Support Apple Software Update Bing Bar Blackout Ragnarok Online Brother MFL-Pro Suite DCP-195C Crysis 2 D3DX10 Dota 2 ESET Online Scanner v3 Etron USB3.0 Host Controller Garena - Heroes of Newerth Garena - League of Legends Garena Messenger Google Chrome Grand Theft Auto: Episodes from Liberty City ImgBurn Intel® Control Center Intel® Management Engine Components Intel® Rapid Storage Technology Java Auto Updater Java™ 6 Update 31 Junk Mail filter update Left 4 Dead 2 Malwarebytes Anti-Malware version 1.61.0.1400 McAfee SiteAdvisor Mesh Runtime Messenger Companion Microsoft Games for Windows - LIVE Redistributable Microsoft Games for Windows Marketplace Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Mozilla Firefox 4.0.1 (x86 en-US) MSVCRT MSVCRT_amd64 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP2 Parser and SDK NVIDIA PhysX NVIDIA Stereoscopic 3D Driver ObjectDock Free ON_OFF Charge B11.0110.1 Pando Media Booster Project64 1.6 QuickTime Razer BlackWidow Ultimate Realtek Ethernet Controller Driver Realtek High Definition Audio Driver Rusty Hearts Security Update for 2007 Microsoft Office System (KB951550) Security Update for 2007 Microsoft Office System (KB951944) Security Update for 2007 Microsoft Office System (KB958439) Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft Office Excel 2007 (KB958437) Security Update for Microsoft Office system 2007 (KB951808) Security Update for Microsoft Office Word 2007 (KB950113) Security Update for Publisher 2007 (KB936646) Sonic Generations Spiral Knights Steam System Requirements Lab System Requirements Lab CYRI TechPowerUp GPU-Z The Elder Scrolls V: Skyrim The Sims 3 TP-LINK Wireless Client Utility Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2598290) 32-Bit Edition Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Update for Office 2007 (KB932080) Update for Outlook 2007 (KB937608) Visual Studio 2008 x64 Redistributables Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Mail Windows Live Mesh Windows Live Mesh ActiveX Control for Remote Connections Windows Live Messenger Windows Live Messenger Companion Core Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources . ==== Event Viewer Messages From Past Week ======== . 6/8/2012 11:27:23 AM, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\system32\athExt.dll Error Code: 126 6/5/2012 12:01:28 PM, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly. . ==== End Of File =========================== 11:36:56.0991 3376 TDSS rootkit removing tool [removed] May 21 2012 16:40:16 11:36:57.0731 3376 ============================================================ 11:36:57.0731 3376 Current date / time: 2012/06/08 11:36:57.0731 11:36:57.0731 3376 SystemInfo: 11:36:57.0731 3376 11:36:57.0731 3376 OS Version: 6.1.7601 ServicePack: 1.0 11:36:57.0731 3376 Product type: Workstation 11:36:57.0731 3376 ComputerName: VINCENT-PC 11:36:57.0731 3376 UserName: User 11:36:57.0731 3376 Windows directory: C:\Windows 11:36:57.0731 3376 System windows directory: C:\Windows 11:36:57.0731 3376 Running under WOW64 11:36:57.0731 3376 Processor architecture: Intel x64 11:36:57.0731 3376 Number of processors: 4 11:36:57.0731 3376 Page size: 0x1000 11:36:57.0731 3376 Boot type: Normal boot 11:36:57.0731 3376 ============================================================ 11:36:58.0973 3376 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1F8B1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040 11:36:58.0973 3376 ============================================================ 11:36:58.0973 3376 \Device\Harddisk0\DR0: 11:36:58.0973 3376 MBR partitions: 11:36:58.0973 3376 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 11:36:58.0973 3376 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x19000000 11:36:58.0973 3376 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x19032800, BlocksNum 0x5B6D3800 11:36:58.0973 3376 ============================================================ 11:36:59.0004 3376 C: <-> \Device\Harddisk0\DR0\Partition1 11:36:59.0051 3376 D: <-> \Device\Harddisk0\DR0\Partition2 11:36:59.0051 3376 ============================================================ 11:36:59.0051 3376 Initialize success 11:36:59.0051 3376 ============================================================ 11:37:13.0352 4576 ============================================================ 11:37:13.0352 4576 Scan started 11:37:13.0352 4576 Mode: Manual; 11:37:13.0352 4576 ============================================================ 11:37:15.0102 4576 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys 11:37:15.0104 4576 1394ohci - ok 11:37:15.0140 4576 Abyssus (cdf91e688d456b9702b2ea72c85f840c) C:\Windows\system32\drivers\Abyssus.sys 11:37:15.0141 4576 Abyssus - ok 11:37:15.0188 4576 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys 11:37:15.0194 4576 ACPI - ok 11:37:15.0208 4576 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys 11:37:15.0223 4576 AcpiPmi - ok 11:37:15.0308 4576 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 11:37:15.0309 4576 AdobeARMservice - ok 11:37:15.0348 4576 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys 11:37:15.0382 4576 adp94xx - ok 11:37:15.0424 4576 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys 11:37:15.0453 4576 adpahci - ok 11:37:15.0469 4576 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys 11:37:15.0471 4576 adpu320 - ok 11:37:15.0489 4576 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll 11:37:15.0490 4576 AeLookupSvc - ok 11:37:15.0532 4576 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys 11:37:15.0536 4576 AFD - ok 11:37:15.0546 4576 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys 11:37:15.0558 4576 agp440 - ok 11:37:15.0572 4576 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe 11:37:15.0574 4576 ALG - ok 11:37:15.0588 4576 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys 11:37:15.0597 4576 aliide - ok 11:37:15.0608 4576 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys 11:37:15.0616 4576 amdide - ok 11:37:15.0632 4576 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys 11:37:15.0640 4576 AmdK8 - ok 11:37:15.0651 4576 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys 11:37:15.0660 4576 AmdPPM - ok 11:37:15.0685 4576 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys 11:37:15.0686 4576 amdsata - ok 11:37:15.0723 4576 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys 11:37:15.0742 4576 amdsbs - ok 11:37:15.0748 4576 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys 11:37:15.0748 4576 amdxata - ok 11:37:15.0776 4576 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys 11:37:15.0777 4576 AppID - ok 11:37:15.0787 4576 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll 11:37:15.0788 4576 AppIDSvc - ok 11:37:15.0824 4576 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll 11:37:15.0826 4576 Appinfo - ok 11:37:15.0908 4576 Apple Mobile Device (20f6f19fe9e753f2780dc2fa083ad597) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 11:37:15.0912 4576 Apple Mobile Device - ok 11:37:15.0938 4576 AppleCharger (6be11ad81d4527d299f0cb5f3731aabc) C:\Windows\system32\DRIVERS\AppleCharger.sys 11:37:15.0938 4576 AppleCharger - ok 11:37:15.0953 4576 AppleChargerSrv (95ef7247c50c7241fdae39a9b3aff4ae) C:\Windows\system32\AppleChargerSrv.exe 11:37:15.0956 4576 AppleChargerSrv - ok 11:37:15.0979 4576 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys 11:37:15.0980 4576 arc - ok 11:37:16.0010 4576 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys 11:37:16.0011 4576 arcsas - ok 11:37:16.0069 4576 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 11:37:16.0069 4576 AsyncMac - ok 11:37:16.0087 4576 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys 11:37:16.0088 4576 atapi - ok 11:37:16.0225 4576 athur (36322190763845975e0d001e90687bf2) C:\Windows\system32\DRIVERS\athurx.sys 11:37:16.0245 4576 athur - ok 11:37:16.0327 4576 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll 11:37:16.0334 4576 AudioEndpointBuilder - ok 11:37:16.0341 4576 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll 11:37:16.0348 4576 AudioSrv - ok 11:37:16.0383 4576 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll 11:37:16.0385 4576 AxInstSV - ok 11:37:16.0421 4576 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys 11:37:16.0425 4576 b06bdrv - ok 11:37:16.0454 4576 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 11:37:16.0466 4576 b57nd60a - ok 11:37:16.0507 4576 BBSvc (825f81a6f7dd073509db101f0ba6dc59) C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE 11:37:16.0508 4576 BBSvc - ok 11:37:16.0533 4576 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll 11:37:16.0534 4576 BDESVC - ok 11:37:16.0556 4576 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 11:37:16.0557 4576 Beep - ok 11:37:16.0621 4576 BFE (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll 11:37:16.0630 4576 BFE - ok 11:37:16.0672 4576 BITS (1ea7969e3271cbc59e1730697dc74682) C:\Windows\System32\qmgr.dll 11:37:16.0683 4576 BITS - ok 11:37:16.0702 4576 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 11:37:16.0716 4576 blbdrive - ok 11:37:16.0805 4576 Bonjour Service (1c87705ccb2f60172b0fc86b5d82f00d) C:\Program Files (x86)\Bonjour\mDNSResponder.exe 11:37:16.0810 4576 Bonjour Service - ok 11:37:16.0840 4576 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys 11:37:16.0841 4576 bowser - ok 11:37:16.0865 4576 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys 11:37:16.0866 4576 BrFiltLo - ok 11:37:16.0879 4576 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys 11:37:16.0880 4576 BrFiltUp - ok 11:37:16.0913 4576 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll 11:37:16.0915 4576 Browser - ok 11:37:16.0938 4576 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 11:37:16.0941 4576 Brserid - ok 11:37:16.0954 4576 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 11:37:16.0954 4576 BrSerWdm - ok 11:37:16.0963 4576 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 11:37:16.0964 4576 BrUsbMdm - ok 11:37:16.0978 4576 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 11:37:16.0979 4576 BrUsbSer - ok 11:37:16.0996 4576 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys 11:37:17.0004 4576 BTHMODEM - ok 11:37:17.0024 4576 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll 11:37:17.0025 4576 bthserv - ok 11:37:17.0045 4576 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 11:37:17.0046 4576 cdfs - ok 11:37:17.0073 4576 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys 11:37:17.0075 4576 cdrom - ok 11:37:17.0100 4576 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll 11:37:17.0101 4576 CertPropSvc - ok 11:37:17.0113 4576 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys 11:37:17.0114 4576 circlass - ok 11:37:17.0143 4576 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 11:37:17.0147 4576 CLFS - ok 11:37:17.0204 4576 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 11:37:17.0208 4576 clr_optimization_v2.0.50727_32 - ok 11:37:17.0265 4576 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 11:37:17.0266 4576 clr_optimization_v2.0.50727_64 - ok 11:37:17.0334 4576 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 11:37:17.0337 4576 clr_optimization_v4.0.30319_32 - ok 11:37:17.0357 4576 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 11:37:17.0358 4576 clr_optimization_v4.0.30319_64 - ok 11:37:17.0367 4576 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 11:37:17.0378 4576 CmBatt - ok 11:37:17.0411 4576 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys 11:37:17.0423 4576 cmdide - ok 11:37:17.0537 4576 CNG (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys 11:37:17.0541 4576 CNG - ok 11:37:17.0552 4576 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys 11:37:17.0554 4576 Compbatt - ok 11:37:17.0573 4576 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys 11:37:17.0574 4576 CompositeBus - ok 11:37:17.0585 4576 COMSysApp - ok 11:37:17.0604 4576 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys 11:37:17.0605 4576 crcdisk - ok 11:37:17.0639 4576 CryptSvc (15597883fbe9b056f276ada3ad87d9af) C:\Windows\system32\cryptsvc.dll 11:37:17.0641 4576 CryptSvc - ok 11:37:17.0682 4576 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll 11:37:17.0692 4576 DcomLaunch - ok 11:37:17.0726 4576 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll 11:37:17.0731 4576 defragsvc - ok 11:37:17.0759 4576 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys 11:37:17.0760 4576 DfsC - ok 11:37:17.0778 4576 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll 11:37:17.0781 4576 Dhcp - ok 11:37:17.0795 4576 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 11:37:17.0811 4576 discache - ok 11:37:17.0838 4576 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys 11:37:17.0838 4576 Disk - ok 11:37:17.0869 4576 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll 11:37:17.0872 4576 Dnscache - ok 11:37:17.0919 4576 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll 11:37:17.0923 4576 dot3svc - ok 11:37:17.0945 4576 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll 11:37:17.0946 4576 DPS - ok 11:37:17.0974 4576 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 11:37:17.0975 4576 drmkaud - ok 11:37:18.0039 4576 dump_wmimmc - ok 11:37:18.0092 4576 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys 11:37:18.0097 4576 DXGKrnl - ok 11:37:18.0164 4576 EagleX64 - ok 11:37:18.0198 4576 eamonm (aca3fe4f18a945b7bf2618a79f6f670b) C:\Windows\system32\DRIVERS\eamonm.sys 11:37:18.0200 4576 eamonm - ok 11:37:18.0245 4576 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll 11:37:18.0247 4576 EapHost - ok 11:37:18.0455 4576 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys 11:37:18.0484 4576 ebdrv - ok 11:37:18.0556 4576 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe 11:37:18.0557 4576 EFS - ok 11:37:18.0608 4576 ehdrv (6672438bdcbfd87250d22112d458294d) C:\Windows\system32\DRIVERS\ehdrv.sys 11:37:18.0609 4576 ehdrv - ok 11:37:18.0671 4576 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe 11:37:18.0681 4576 ehRecvr - ok 11:37:18.0701 4576 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe 11:37:18.0703 4576 ehSched - ok 11:37:18.0786 4576 EhttpSrv (deb2b067745d92ff17a5068dfd2360bc) C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe 11:37:18.0788 4576 EhttpSrv - ok 11:37:18.0854 4576 ekrn (191d8eccc40f05b52fac0513f35ba01d) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe 11:37:18.0860 4576 ekrn - ok 11:37:18.0922 4576 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys 11:37:18.0930 4576 elxstor - ok 11:37:18.0949 4576 epfw (443805b5b11c859ac8ca35297648ff0c) C:\Windows\system32\DRIVERS\epfw.sys 11:37:18.0950 4576 epfw - ok 11:37:18.0972 4576 Epfwndis (66e61bc6c9f519a99275eb0f0e530bf4) C:\Windows\system32\DRIVERS\Epfwndis.sys 11:37:18.0972 4576 Epfwndis - ok 11:37:18.0994 4576 epfwwfp (f72c97f3d34ea5ec919c73e3901266bb) C:\Windows\system32\DRIVERS\epfwwfp.sys 11:37:18.0995 4576 epfwwfp - ok 11:37:19.0013 4576 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys 11:37:19.0014 4576 ErrDev - ok 11:37:19.0048 4576 EtronHub3 (6c17a702399b0205ab7836c2b45cd806) C:\Windows\system32\Drivers\EtronHub3.sys 11:37:19.0049 4576 EtronHub3 - ok 11:37:19.0064 4576 EtronXHCI (b5348a55cc9541ffa930e30bb0cc8ef6) C:\Windows\system32\Drivers\EtronXHCI.sys 11:37:19.0064 4576 EtronXHCI - ok 11:37:19.0500 4576 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll 11:37:19.0507 4576 EventSystem - ok 11:37:19.0529 4576 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 11:37:19.0569 4576 exfat - ok 11:37:19.0844 4576 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 11:37:19.0871 4576 fastfat - ok 11:37:19.0922 4576 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe 11:37:19.0932 4576 Fax - ok 11:37:19.0955 4576 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys 11:37:19.0974 4576 fdc - ok 11:37:19.0980 4576 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll 11:37:19.0995 4576 fdPHost - ok 11:37:20.0092 4576 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll 11:37:20.0092 4576 FDResPub - ok 11:37:20.0142 4576 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 11:37:20.0162 4576 FileInfo - ok 11:37:20.0222 4576 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 11:37:20.0242 4576 Filetrace - ok 11:37:20.0282 4576 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys 11:37:20.0282 4576 flpydisk - ok 11:37:20.0322 4576 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys 11:37:20.0352 4576 FltMgr - ok 11:37:20.0402 4576 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll 11:37:20.0412 4576 FontCache - ok 11:37:20.0492 4576 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 11:37:20.0492 4576 FontCache3.0.0.0 - ok 11:37:20.0549 4576 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 11:37:20.0565 4576 FsDepends - ok 11:37:20.0586 4576 fssfltr (07da62c960ddccc2d35836aeab4fc578) C:\Windows\system32\DRIVERS\fssfltr.sys 11:37:20.0587 4576 fssfltr - ok 11:37:20.0725 4576 fsssvc (28ddeeec44e988657b732cf404d504cb) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe 11:37:20.0737 4576 fsssvc - ok 11:37:20.0795 4576 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys 11:37:20.0810 4576 Fs_Rec - ok 11:37:20.0989 4576 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys 11:37:20.0992 4576 fvevol - ok 11:37:21.0009 4576 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys 11:37:21.0045 4576 gagp30kx - ok 11:37:21.0119 4576 gdrv (7907e14f9bcf3a4689c9a74a1a873cb6) C:\Windows\gdrv.sys 11:37:21.0119 4576 gdrv - ok 11:37:21.0149 4576 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 11:37:21.0150 4576 GEARAspiWDM - ok 11:37:21.0196 4576 GGSAFERDriver - ok 11:37:21.0246 4576 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll 11:37:21.0264 4576 gpsvc - ok 11:37:21.0283 4576 hamachi (1e6438d4ea6e1174a3b3b1edc4de660b) C:\Windows\system32\DRIVERS\hamachi.sys 11:37:21.0308 4576 hamachi - ok 11:37:21.0369 4576 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 11:37:21.0371 4576 hcw85cir - ok 11:37:21.0409 4576 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys 11:37:21.0413 4576 HdAudAddService - ok 11:37:21.0439 4576 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys 11:37:21.0441 4576 HDAudBus - ok 11:37:21.0453 4576 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys 11:37:21.0480 4576 HidBatt - ok 11:37:21.0485 4576 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys 11:37:21.0494 4576 HidBth - ok 11:37:21.0497 4576 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys 11:37:21.0510 4576 HidIr - ok 11:37:21.0540 4576 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll 11:37:21.0540 4576 hidserv - ok 11:37:21.0585 4576 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\drivers\hidusb.sys 11:37:21.0602 4576 HidUsb - ok 11:37:21.0621 4576 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll 11:37:21.0623 4576 hkmsvc - ok 11:37:21.0703 4576 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll 11:37:21.0706 4576 HomeGroupListener - ok 11:37:21.0735 4576 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll 11:37:21.0737 4576 HomeGroupProvider - ok 11:37:21.0857 4576 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys 11:37:21.0858 4576 HpSAMD - ok 11:37:21.0909 4576 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys 11:37:21.0943 4576 HTTP - ok 11:37:21.0970 4576 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys 11:37:21.0970 4576 hwpolicy - ok 11:37:21.0992 4576 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys 11:37:21.0993 4576 i8042prt - ok 11:37:22.0040 4576 iaStor (d7921d5a870b11cc1adab198a519d50a) C:\Windows\system32\DRIVERS\iaStor.sys 11:37:22.0076 4576 iaStor - ok 11:37:22.0156 4576 IAStorDataMgrSvc (8fff9083252c16fe3960173722605e9e) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe 11:37:22.0158 4576 IAStorDataMgrSvc - ok 11:37:22.0195 4576 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys 11:37:22.0214 4576 iaStorV - ok 11:37:22.0282 4576 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 11:37:22.0295 4576 idsvc - ok 11:37:22.0316 4576 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys 11:37:22.0318 4576 iirsp - ok 11:37:22.0411 4576 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll 11:37:22.0422 4576 IKEEXT - ok 11:37:22.0686 4576 IntcAzAudAddService (03076f51af9f78a272cccde03e9340ce) C:\Windows\system32\drivers\RTKVHD64.sys 11:37:22.0697 4576 IntcAzAudAddService - ok 11:37:22.0821 4576 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys 11:37:22.0822 4576 intelide - ok 11:37:22.0842 4576 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 11:37:22.0858 4576 intelppm - ok 11:37:22.0897 4576 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll 11:37:22.0900 4576 IPBusEnum - ok 11:37:22.0917 4576 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys 11:37:22.0919 4576 IpFilterDriver - ok 11:37:22.0959 4576 iphlpsvc (a34a587fffd45fa649fba6d03784d257) C:\Windows\System32\iphlpsvc.dll 11:37:22.0965 4576 iphlpsvc - ok 11:37:22.0976 4576 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys 11:37:22.0977 4576 IPMIDRV - ok 11:37:22.0992 4576 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 11:37:23.0002 4576 IPNAT - ok 11:37:23.0100 4576 iPod Service (b7cb0b121962cd89f98c0dd89331b0c0) C:\Program Files\iPod\bin\iPodService.exe 11:37:23.0105 4576 iPod Service - ok 11:37:23.0126 4576 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 11:37:23.0126 4576 IRENUM - ok 11:37:23.0139 4576 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys 11:37:23.0147 4576 isapnp - ok 11:37:23.0246 4576 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys 11:37:23.0261 4576 iScsiPrt - ok 11:37:23.0280 4576 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys 11:37:23.0282 4576 kbdclass - ok 11:37:23.0301 4576 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys 11:37:23.0301 4576 kbdhid - ok 11:37:23.0316 4576 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 11:37:23.0317 4576 KeyIso - ok 11:37:23.0354 4576 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys 11:37:23.0356 4576 KSecDD - ok 11:37:23.0382 4576 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys 11:37:23.0384 4576 KSecPkg - ok 11:37:23.0388 4576 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 11:37:23.0403 4576 ksthunk - ok 11:37:23.0464 4576 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll 11:37:23.0470 4576 KtmRm - ok 11:37:23.0524 4576 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\system32\srvsvc.dll 11:37:23.0528 4576 LanmanServer - ok 11:37:23.0549 4576 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll 11:37:23.0552 4576 LanmanWorkstation - ok 11:37:23.0577 4576 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 11:37:23.0593 4576 lltdio - ok 11:37:23.0631 4576 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll 11:37:23.0637 4576 lltdsvc - ok 11:37:23.0651 4576 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll 11:37:23.0653 4576 lmhosts - ok 11:37:23.0776 4576 LMS (0803906d607a9b83184447b75b60ecc2) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe 11:37:23.0781 4576 LMS - ok 11:37:23.0811 4576 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys 11:37:23.0828 4576 LSI_FC - ok 11:37:23.0850 4576 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys 11:37:23.0851 4576 LSI_SAS - ok 11:37:23.0866 4576 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys 11:37:23.0881 4576 LSI_SAS2 - ok 11:37:23.0909 4576 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys 11:37:23.0925 4576 LSI_SCSI - ok 11:37:23.0963 4576 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 11:37:23.0965 4576 luafv - ok 11:37:24.0022 4576 McAfee SiteAdvisor Service (be8c524313db75fa26fb2b0c0aaff88e) c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe 11:37:24.0024 4576 McAfee SiteAdvisor Service - ok 11:37:24.0083 4576 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll 11:37:24.0086 4576 Mcx2Svc - ok 11:37:24.0098 4576 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys 11:37:24.0099 4576 megasas - ok 11:37:24.0124 4576 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys 11:37:24.0148 4576 MegaSR - ok 11:37:24.0161 4576 MEIx64 (1c6e73fc46b509eff9d0086aa37132df) C:\Windows\system32\DRIVERS\HECIx64.sys 11:37:24.0161 4576 MEIx64 - ok 11:37:24.0259 4576 Microsoft Office Groove Audit Service (fafe367d032ed82e9332b4c741a20216) C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe 11:37:24.0263 4576 Microsoft Office Groove Audit Service - ok 11:37:24.0288 4576 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll 11:37:24.0290 4576 MMCSS - ok 11:37:24.0339 4576 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 11:37:24.0339 4576 Modem - ok 11:37:24.0364 4576 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 11:37:24.0380 4576 monitor - ok 11:37:24.0416 4576 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\drivers\mouclass.sys 11:37:24.0416 4576 mouclass - ok 11:37:24.0428 4576 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 11:37:24.0429 4576 mouhid - ok 11:37:24.0446 4576 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys 11:37:24.0447 4576 mountmgr - ok 11:37:24.0477 4576 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys 11:37:24.0482 4576 mpio - ok 11:37:24.0500 4576 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 11:37:24.0517 4576 mpsdrv - ok 11:37:24.0570 4576 MpsSvc (54ffc9c8898113ace189d4aa7199d2c1) C:\Windows\system32\mpssvc.dll 11:37:24.0579 4576 MpsSvc - ok 11:37:24.0614 4576 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys 11:37:24.0616 4576 MRxDAV - ok 11:37:24.0645 4576 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys 11:37:24.0647 4576 mrxsmb - ok 11:37:24.0691 4576 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys 11:37:24.0694 4576 mrxsmb10 - ok 11:37:24.0723 4576 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 11:37:24.0724 4576 mrxsmb20 - ok 11:37:24.0736 4576 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys 11:37:24.0752 4576 msahci - ok 11:37:24.0767 4576 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys 11:37:24.0782 4576 msdsm - ok 11:37:24.0801 4576 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe 11:37:24.0805 4576 MSDTC - ok 11:37:24.0825 4576 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 11:37:24.0826 4576 Msfs - ok 11:37:24.0834 4576 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 11:37:24.0835 4576 mshidkmdf - ok 11:37:24.0841 4576 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys 11:37:24.0854 4576 msisadrv - ok 11:37:24.0903 4576 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll 11:37:24.0907 4576 MSiSCSI - ok 11:37:24.0909 4576 msiserver - ok 11:37:24.0934 4576 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 11:37:24.0935 4576 MSKSSRV - ok 11:37:24.0944 4576 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 11:37:24.0945 4576 MSPCLOCK - ok 11:37:24.0948 4576 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 11:37:24.0963 4576 MSPQM - ok 11:37:25.0087 4576 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys 11:37:25.0092 4576 MsRPC - ok 11:37:25.0130 4576 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys 11:37:25.0132 4576 mssmbios - ok 11:37:25.0142 4576 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 11:37:25.0142 4576 MSTEE - ok 11:37:25.0149 4576 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys 11:37:25.0150 4576 MTConfig - ok 11:37:25.0172 4576 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 11:37:25.0172 4576 Mup - ok 11:37:25.0205 4576 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll 11:37:25.0211 4576 napagent - ok 11:37:25.0253 4576 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 11:37:25.0282 4576 NativeWifiP - ok 11:37:25.0344 4576 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys 11:37:25.0355 4576 NDIS - ok 11:37:25.0373 4576 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 11:37:25.0388 4576 NdisCap - ok 11:37:25.0411 4576 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 11:37:25.0412 4576 NdisTapi - ok 11:37:25.0451 4576 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys 11:37:25.0453 4576 Ndisuio - ok 11:37:25.0483 4576 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys 11:37:25.0499 4576 NdisWan - ok 11:37:25.0520 4576 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys 11:37:25.0548 4576 NDProxy - ok 11:37:25.0551 4576 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 11:37:25.0565 4576 NetBIOS - ok 11:37:25.0584 4576 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys 11:37:25.0586 4576 NetBT - ok 11:37:25.0601 4576 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 11:37:25.0602 4576 Netlogon - ok 11:37:25.0640 4576 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll 11:37:25.0645 4576 Netman - ok 11:37:25.0661 4576 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll 11:37:25.0666 4576 netprofm - ok 11:37:25.0792 4576 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 11:37:25.0793 4576 NetTcpPortSharing - ok 11:37:25.0805 4576 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys 11:37:25.0834 4576 nfrd960 - ok 11:37:25.0854 4576 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll 11:37:25.0857 4576 NlaSvc - ok 11:37:25.0870 4576 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 11:37:25.0878 4576 Npfs - ok 11:37:25.0907 4576 npggsvc - ok 11:37:25.0909 4576 NPPTNT2 - ok 11:37:25.0922 4576 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll 11:37:25.0923 4576 nsi - ok 11:37:25.0934 4576 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 11:37:25.0934 4576 nsiproxy - ok 11:37:26.0027 4576 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys 11:37:26.0053 4576 Ntfs - ok 11:37:26.0180 4576 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 11:37:26.0180 4576 Null - ok 11:37:26.0247 4576 NVHDA (857fb74754ebff94ee3ad40788740916) C:\Windows\system32\drivers\nvhda64v.sys 11:37:26.0248 4576 NVHDA - ok 11:37:26.0782 4576 nvlddmkm (f12c5f17d48d9f5c70e4408b3ccb5443) C:\Windows\system32\DRIVERS\nvlddmkm.sys 11:37:26.0834 4576 nvlddmkm - ok 11:37:26.0911 4576 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys 11:37:26.0912 4576 nvraid - ok 11:37:26.0928 4576 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys 11:37:26.0962 4576 nvstor - ok 11:37:27.0052 4576 NVSvc (8a55543c379b0582f0c33db447d1c892) C:\Windows\system32\nvvsvc.exe 11:37:27.0060 4576 NVSvc - ok 11:37:27.0108 4576 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys 11:37:27.0124 4576 nv_agp - ok 11:37:27.0325 4576 odserv (84de1dd996b48b05ace31ad015fa108a) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 11:37:27.0329 4576 odserv - ok 11:37:27.0345 4576 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys 11:37:27.0346 4576 ohci1394 - ok 11:37:27.0372 4576 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 11:37:27.0375 4576 ose - ok 11:37:27.0409 4576 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll 11:37:27.0418 4576 p2pimsvc - ok 11:37:27.0459 4576 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll 11:37:27.0465 4576 p2psvc - ok 11:37:27.0487 4576 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys 11:37:27.0504 4576 Parport - ok 11:37:27.0577 4576 partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys 11:37:27.0578 4576 partmgr - ok 11:37:27.0594 4576 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll 11:37:27.0597 4576 PcaSvc - ok 11:37:27.0611 4576 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys 11:37:27.0614 4576 pci - ok 11:37:27.0622 4576 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys 11:37:27.0636 4576 pciide - ok 11:37:27.0759 4576 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys 11:37:27.0762 4576 pcmcia - ok 11:37:27.0773 4576 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 11:37:27.0774 4576 pcw - ok 11:37:27.0803 4576 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 11:37:27.0811 4576 PEAUTH - ok 11:37:27.0873 4576 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe 11:37:27.0874 4576 PerfHost - ok 11:37:27.0953 4576 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll 11:37:27.0970 4576 pla - ok 11:37:28.0020 4576 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll 11:37:28.0026 4576 PlugPlay - ok 11:37:28.0058 4576 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll 11:37:28.0061 4576 PNRPAutoReg - ok 11:37:28.0083 4576 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll 11:37:28.0083 4576 PNRPsvc - ok 11:37:28.0114 4576 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll 11:37:28.0114 4576 PolicyAgent - ok 11:37:28.0145 4576 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll 11:37:28.0145 4576 Power - ok 11:37:28.0192 4576 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys 11:37:28.0192 4576 PptpMiniport - ok 11:37:28.0208 4576 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys 11:37:28.0223 4576 Processor - ok 11:37:28.0255 4576 ProfSvc (5c78838b4d166d1a27db3a8a820c799a) C:\Windows\system32\profsvc.dll 11:37:28.0255 4576 ProfSvc - ok 11:37:28.0270 4576 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 11:37:28.0270 4576 ProtectedStorage - ok 11:37:28.0317 4576 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys 11:37:28.0317 4576 Psched - ok 11:37:28.0364 4576 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys 11:37:28.0379 4576 ql2300 - ok 11:37:28.0457 4576 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys 11:37:28.0473 4576 ql40xx - ok 11:37:28.0489 4576 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll 11:37:28.0504 4576 QWAVE - ok 11:37:28.0504 4576 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 11:37:28.0504 4576 QWAVEdrv - ok 11:37:28.0535 4576 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 11:37:28.0535 4576 RasAcd - ok 11:37:28.0570 4576 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 11:37:28.0572 4576 RasAgileVpn - ok 11:37:28.0581 4576 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll 11:37:28.0584 4576 RasAuto - ok 11:37:28.0609 4576 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys 11:37:28.0631 4576 Rasl2tp - ok 11:37:28.0655 4576 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll 11:37:28.0660 4576 RasMan - ok 11:37:28.0668 4576 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 11:37:28.0669 4576 RasPppoe - ok 11:37:28.0679 4576 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 11:37:28.0689 4576 RasSstp - ok 11:37:28.0721 4576 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys 11:37:28.0725 4576 rdbss - ok 11:37:28.0735 4576 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys 11:37:28.0735 4576 rdpbus - ok 11:37:28.0743 4576 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 11:37:28.0744 4576 RDPCDD - ok 11:37:28.0767 4576 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 11:37:28.0767 4576 RDPENCDD - ok 11:37:28.0776 4576 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 11:37:28.0777 4576 RDPREFMP - ok 11:37:28.0809 4576 RDPWD (6d76e6433574b058adcb0c50df834492) C:\Windows\system32\drivers\RDPWD.sys 11:37:28.0812 4576 RDPWD - ok 11:37:28.0847 4576 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys 11:37:28.0851 4576 rdyboost - ok 11:37:28.0875 4576 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll 11:37:28.0880 4576 RemoteAccess - ok 11:37:28.0913 4576 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll 11:37:28.0917 4576 RemoteRegistry - ok 11:37:28.0933 4576 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll 11:37:28.0935 4576 RpcEptMapper - ok 11:37:28.0962 4576 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe 11:37:28.0963 4576 RpcLocator - ok 11:37:29.0001 4576 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll 11:37:29.0004 4576 RpcSs - ok 11:37:29.0019 4576 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 11:37:29.0028 4576 rspndr - ok 11:37:29.0064 4576 RTL8167 (712944c0a377e9b8743f95bd83e882d4) C:\Windows\system32\DRIVERS\Rt64win7.sys 11:37:29.0066 4576 RTL8167 - ok 11:37:29.0106 4576 RzSynapse (bedafaf4524c00edc068de3adf151f9d) C:\Windows\system32\DRIVERS\RzSynapse.sys 11:37:29.0108 4576 RzSynapse - ok 11:37:29.0129 4576 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 11:37:29.0130 4576 SamSs - ok 11:37:29.0295 4576 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys 11:37:29.0312 4576 sbp2port - ok 11:37:29.0334 4576 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll 11:37:29.0347 4576 SCardSvr - ok 11:37:29.0371 4576 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys 11:37:29.0372 4576 scfilter - ok 11:37:29.0511 4576 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll 11:37:29.0526 4576 Schedule - ok 11:37:29.0552 4576 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll 11:37:29.0553 4576 SCPolicySvc - ok 11:37:29.0574 4576 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll 11:37:29.0574 4576 SDRSVC - ok 11:37:29.0676 4576 SeaPort (cc781378e7eda615d2cdca3b17829fa4) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE 11:37:29.0678 4576 SeaPort - ok 11:37:29.0698 4576 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 11:37:29.0698 4576 secdrv - ok 11:37:29.0731 4576 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll 11:37:29.0734 4576 seclogon - ok 11:37:29.0755 4576 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll 11:37:29.0758 4576 SENS - ok 11:37:29.0771 4576 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll 11:37:29.0773 4576 SensrSvc - ok 11:37:29.0782 4576 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys 11:37:29.0797 4576 Serenum - ok 11:37:29.0823 4576 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys 11:37:29.0864 4576 Serial - ok 11:37:29.0890 4576 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys 11:37:29.0899 4576 sermouse - ok 11:37:29.0921 4576 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll 11:37:29.0923 4576 SessionEnv - ok 11:37:29.0947 4576 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys 11:37:29.0963 4576 sffdisk - ok 11:37:29.0975 4576 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys 11:37:29.0991 4576 sffp_mmc - ok 11:37:30.0003 4576 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys 11:37:30.0004 4576 sffp_sd - ok 11:37:30.0024 4576 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys 11:37:30.0039 4576 sfloppy - ok 11:37:30.0088 4576 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll 11:37:30.0094 4576 SharedAccess - ok 11:37:30.0157 4576 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll 11:37:30.0163 4576 ShellHWDetection - ok 11:37:30.0189 4576 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys 11:37:30.0216 4576 SiSRaid2 - ok 11:37:30.0235 4576 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys 11:37:30.0244 4576 SiSRaid4 - ok 11:37:30.0267 4576 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 11:37:30.0267 4576 Smb - ok 11:37:30.0288 4576 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe 11:37:30.0290 4576 SNMPTRAP - ok 11:37:30.0298 4576 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 11:37:30.0298 4576 spldr - ok 11:37:30.0322 4576 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe 11:37:30.0327 4576 Spooler - ok 11:37:30.0476 4576 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe 11:37:30.0508 4576 sppsvc - ok 11:37:30.0629 4576 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll 11:37:30.0633 4576 sppuinotify - ok 11:37:30.0675 4576 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys 11:37:30.0675 4576 srv - ok 11:37:30.0707 4576 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys 11:37:30.0722 4576 srv2 - ok 11:37:30.0753 4576 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys 11:37:30.0753 4576 srvnet - ok 11:37:30.0785 4576 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll 11:37:30.0800 4576 SSDPSRV - ok 11:37:30.0816 4576 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll 11:37:30.0816 4576 SstpSvc - ok 11:37:30.0863 4576 Steam Client Service - ok 11:37:30.0909 4576 Stereo Service (8c37c35fb2d9692dda0eddbca58bfe18) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 11:37:30.0909 4576 Stereo Service - ok 11:37:30.0987 4576 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys 11:37:30.0987 4576 stexstor - ok 11:37:31.0910 4576 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll 11:37:31.0924 4576 stisvc - ok 11:37:31.0947 4576 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys 11:37:31.0962 4576 swenum - ok 11:37:31.0999 4576 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll 11:37:32.0007 4576 swprv - ok 11:37:32.0115 4576 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll 11:37:32.0120 4576 SysMain - ok 11:37:32.0574 4576 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll 11:37:32.0595 4576 TabletInputService - ok 11:37:32.0626 4576 taphss (f33fdc72298df4bf9813a55d21f4eb31) C:\Windows\system32\DRIVERS\taphss.sys 11:37:32.0626 4576 taphss - ok 11:37:32.0938 4576 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll 11:37:32.0955 4576 TapiSrv - ok 11:37:32.0982 4576 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll 11:37:32.0985 4576 TBS - ok 11:37:33.0073 4576 Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys 11:37:33.0094 4576 Tcpip - ok 11:37:33.0393 4576 TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys 11:37:33.0393 4576 TCPIP6 - ok 11:37:33.0502 4576 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys 11:37:33.0502 4576 tcpipreg - ok 11:37:33.0518 4576 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 11:37:33.0549 4576 TDPIPE - ok 11:37:33.0596 4576 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys 11:37:33.0596 4576 TDTCP - ok 11:37:33.0642 4576 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys 11:37:33.0674 4576 tdx - ok 11:37:33.0749 4576 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys 11:37:33.0750 4576 TermDD - ok 11:37:33.0783 4576 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll 11:37:33.0793 4576 TermService - ok 11:37:33.0857 4576 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll 11:37:33.0859 4576 Themes - ok 11:37:33.0963 4576 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll 11:37:33.0965 4576 THREADORDER - ok 11:37:33.0994 4576 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll 11:37:33.0997 4576 TrkWks - ok 11:37:34.0064 4576 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe 11:37:34.0066 4576 TrustedInstaller - ok 11:37:34.0089 4576 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys 11:37:34.0090 4576 tssecsrv - ok 11:37:34.0166 4576 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys 11:37:34.0166 4576 TsUsbFlt - ok 11:37:34.0343 4576 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys 11:37:34.0344 4576 tunnel - ok 11:37:34.0357 4576 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys 11:37:34.0358 4576 uagp35 - ok 11:37:34.0503 4576 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys 11:37:34.0507 4576 udfs - ok 11:37:34.0532 4576 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe 11:37:34.0536 4576 UI0Detect - ok 11:37:34.0556 4576 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys 11:37:34.0572 4576 uliagpkx - ok 11:37:34.0594 4576 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys 11:37:34.0595 4576 umbus - ok 11:37:34.0604 4576 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys 11:37:34.0604 4576 UmPass - ok 11:37:34.0843 4576 UNS (eb79c6c91a99930015ef29ae7fa802d1) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe 11:37:34.0866 4576 UNS - ok 11:37:34.0964 4576 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll 11:37:34.0968 4576 upnphost - ok 11:37:35.0012 4576 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys 11:37:35.0013 4576 USBAAPL64 - ok 11:37:35.0090 4576 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys 11:37:35.0091 4576 usbccgp - ok 11:37:35.0122 4576 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys 11:37:35.0125 4576 usbcir - ok 11:37:35.0137 4576 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys 11:37:35.0138 4576 usbehci - ok 11:37:35.0192 4576 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys 11:37:35.0196 4576 usbhub - ok 11:37:35.0205 4576 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys 11:37:35.0205 4576 usbohci - ok 11:37:35.0237 4576 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys 11:37:35.0252 4576 usbprint - ok 11:37:35.0288 4576 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys 11:37:35.0290 4576 usbscan - ok 11:37:35.0310 4576 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS 11:37:35.0342 4576 USBSTOR - ok 11:37:35.0352 4576 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys 11:37:35.0352 4576 usbuhci - ok 11:37:35.0382 4576 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll 11:37:35.0384 4576 UxSms - ok 11:37:35.0404 4576 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 11:37:35.0406 4576 VaultSvc - ok 11:37:35.0434 4576 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys 11:37:35.0434 4576 vdrvroot - ok 11:37:35.0493 4576 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe 11:37:35.0501 4576 vds - ok 11:37:35.0531 4576 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 11:37:35.0532 4576 vga - ok 11:37:35.0543 4576 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 11:37:35.0543 4576 VgaSave - ok 11:37:35.0563 4576 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys 11:37:35.0578 4576 vhdmp - ok 11:37:35.0605 4576 vhidmini (1161acff728d97f75d74d2f1465f8a46) C:\Windows\system32\DRIVERS\vHidDev.sys 11:37:35.0605 4576 vhidmini - ok 11:37:35.0613 4576 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys 11:37:35.0625 4576 viaide - ok 11:37:35.0645 4576 VKbms (3b59bb6d10cf969dbe4db93d9ead7fb4) C:\Windows\system32\DRIVERS\VKbms.sys 11:37:35.0683 4576 VKbms - ok 11:37:35.0699 4576 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys 11:37:35.0723 4576 volmgr - ok 11:37:35.0752 4576 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys 11:37:35.0755 4576 volmgrx - ok 11:37:35.0767 4576 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys 11:37:35.0767 4576 volsnap - ok 11:37:35.0798 4576 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys 11:37:35.0814 4576 vsmraid - ok 11:37:35.0876 4576 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe 11:37:35.0892 4576 VSS - ok 11:37:35.0970 4576 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys 11:37:35.0970 4576 vwifibus - ok 11:37:35.0985 4576 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys 11:37:35.0985 4576 vwififlt - ok 11:37:36.0016 4576 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys 11:37:36.0032 4576 vwifimp - ok 11:37:36.0094 4576 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll 11:37:36.0110 4576 W32Time - ok 11:37:36.0110 4576 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys 11:37:36.0126 4576 WacomPen - ok 11:37:36.0141 4576 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 11:37:36.0157 4576 WANARP - ok 11:37:36.0157 4576 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 11:37:36.0157 4576 Wanarpv6 - ok 11:37:36.0266 4576 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe 11:37:36.0279 4576 WatAdminSvc - ok 11:37:36.0347 4576 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe 11:37:36.0363 4576 wbengine - ok 11:37:36.0400 4576 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll 11:37:36.0404 4576 WbioSrvc - ok 11:37:36.0471 4576 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll 11:37:36.0478 4576 wcncsvc - ok 11:37:36.0492 4576 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll 11:37:36.0496 4576 WcsPlugInService - ok 11:37:36.0523 4576 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys 11:37:36.0524 4576 Wd - ok 11:37:36.0559 4576 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 11:37:36.0568 4576 Wdf01000 - ok 11:37:36.0583 4576 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll 11:37:36.0585 4576 WdiServiceHost - ok 11:37:36.0588 4576 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll 11:37:36.0590 4576 WdiSystemHost - ok 11:37:36.0630 4576 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll 11:37:36.0636 4576 WebClient - ok 11:37:36.0660 4576 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll 11:37:36.0666 4576 Wecsvc - ok 11:37:36.0680 4576 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll 11:37:36.0683 4576 wercplsupport - ok 11:37:36.0716 4576 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll 11:37:36.0719 4576 WerSvc - ok 11:37:36.0729 4576 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 11:37:36.0744 4576 WfpLwf - ok 11:37:36.0779 4576 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 11:37:36.0794 4576 WIMMount - ok 11:37:36.0865 4576 WinDefend - ok 11:37:36.0871 4576 WinHttpAutoProxySvc - ok 11:37:36.0940 4576 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll 11:37:36.0943 4576 Winmgmt - ok 11:37:37.0042 4576 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll 11:37:37.0063 4576 WinRM - ok 11:37:37.0128 4576 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys 11:37:37.0138 4576 WinUsb - ok 11:37:37.0223 4576 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll 11:37:37.0235 4576 Wlansvc - ok 11:37:37.0289 4576 wlcrasvc (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 11:37:37.0289 4576 wlcrasvc - ok 11:37:37.0418 4576 wlidsvc (2bacd71123f42cea603f4e205e1ae337) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 11:37:37.0434 4576 wlidsvc - ok 11:37:37.0474 4576 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys 11:37:37.0483 4576 WmiAcpi - ok 11:37:37.0506 4576 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe 11:37:37.0508 4576 wmiApSrv - ok 11:37:37.0520 4576 WMPNetworkSvc - ok 11:37:37.0530 4576 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll 11:37:37.0532 4576 WPCSvc - ok 11:37:37.0557 4576 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll 11:37:37.0559 4576 WPDBusEnum - ok 11:37:37.0587 4576 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 11:37:37.0601 4576 ws2ifsl - ok 11:37:37.0606 4576 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\System32\wscsvc.dll 11:37:37.0609 4576 wscsvc - ok 11:37:37.0611 4576 WSearch - ok 11:37:37.0753 4576 wuauserv (9df12edbc698b0bc353b3ef84861e430) C:\Windows\system32\wuaueng.dll 11:37:37.0777 4576 wuauserv - ok 11:37:37.0832 4576 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys 11:37:37.0849 4576 WudfPf - ok 11:37:37.0897 4576 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys 11:37:37.0914 4576 WUDFRd - ok 11:37:37.0943 4576 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll 11:37:37.0946 4576 wudfsvc - ok 11:37:38.0148 4576 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll 11:37:38.0154 4576 WwanSvc - ok 11:37:38.0279 4576 X6va005 - ok 11:37:38.0306 4576 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 11:37:38.0484 4576 \Device\Harddisk0\DR0 - ok 11:37:38.0484 4576 Boot (0x1200) (b6cc74b81bece350f7d974e621a1ad74) \Device\Harddisk0\DR0\Partition0 11:37:38.0484 4576 \Device\Harddisk0\DR0\Partition0 - ok 11:37:38.0500 4576 Boot (0x1200) (75c7415782b3aab2f45e0507ea9ace27) \Device\Harddisk0\DR0\Partition1 11:37:38.0500 4576 \Device\Harddisk0\DR0\Partition1 - ok 11:37:38.0515 4576 Boot (0x1200) (6ab000e0bde00428d3a37a8ff0f6af70) \Device\Harddisk0\DR0\Partition2 11:37:38.0531 4576 \Device\Harddisk0\DR0\Partition2 - ok 11:37:38.0531 4576 ============================================================ 11:37:38.0531 4576 Scan finished 11:37:38.0531 4576 ============================================================ 11:37:38.0547 5364 Detected object count: 0 11:37:38.0547 5364 Actual detected object count: 0 Thank you again!
Well, I can see some adware, but nothing terrible in the logs. Since there are a couple items that should be addressed, let's go ahead and run a tool may remove the adware (but will allow us to do so if it doesn't) and will also remove anything that we haven't seen on the logs we've run.

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing anything, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hi, Here is the log produced by ComboFix ComboFix 12-06-08.02 - User 06/09/2012 12:31:20.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4079.2451 [GMT 8:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: ESET Smart Security 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1} FW: ESET Personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA} SP: ESET Smart Security 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\User\AppData\Local\Kosong.Bron.Tok.txt . . ((((((((((((((((((((((((( Files Created from 2012-05-09 to 2012-06-09 ))))))))))))))))))))))))))))))) . . 2012-06-09 04:35 . 2012-06-09 04:35 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-06-09 04:26 . 2012-05-08 17:02 8955792 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CF5FDC64-3C93-4803-AD4B-A52F446A3AE2}\mpengine.dll 2012-06-05 05:15 . 2012-06-05 05:15 ——– d—–w- c:\users\User\AppData\Roaming\Garena 2012-06-05 05:15 . 2012-06-05 05:15 ——– d—–w- c:\programdata\Garena 2012-05-28 04:47 . 2012-05-28 04:47 ——– d—–w- c:\users\User\AppData\Roaming\NVIDIA 2012-05-28 04:47 . 2012-05-28 04:47 ——– d—–w- c:\program files (x86)\GPU-Z 2012-05-26 07:07 . 2012-05-26 07:07 ——– d—–w- c:\users\User\AppData\Roaming\ShanghaiAlice . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-05-05 16:34 . 2012-03-30 12:38 419488 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-05-05 16:34 . 2011-05-15 06:28 70304 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-05-05 16:34 . 2012-04-16 12:33 8744608 —-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2012-04-04 07:56 . 2011-04-02 06:28 24904 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-03-31 06:05 . 2012-05-09 02:09 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-03-31 04:39 . 2012-05-09 02:09 3968368 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-03-31 04:39 . 2012-05-09 02:09 3913072 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-03-31 03:10 . 2012-05-09 02:09 3146240 —-a-w- c:\windows\system32\win32k.sys 2012-03-30 11:35 . 2012-05-09 02:08 1918320 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-03-17 07:58 . 2012-05-09 02:08 75120 —-a-w- c:\windows\system32\drivers\partmgr.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="d:\steam\steam.exe" [2012-01-14 1242448] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-11-05 283160] "Razer Blackwidow Driver"="c:\program files (x86)\Razer\BlackWidow Ultimate\BlackWidowUltimateTray.exe" [2011-03-08 883616] "BrMfcWnd"="c:\program files (x86)\Brother\Brmfcmon\BrMfcWnd.exe" [2009-05-26 1159168] "ControlCenter3"="c:\program files (x86)\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-08-18 421736] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] . c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Stardock ObjectDock.lnk - c:\program files (x86)\Stardock\ObjectDockFree\ObjectDock.exe [2010-10-7 3768176] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer4"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200804] Ime File REG_SZ GOOGLEPINYIN2.IME . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560] R3 dump_wmimmc;dump_wmimmc;c:\program files (x86)\Garena Messenger\Apps\BlackShot\BlackShot\system\GameGuard\dump_wmimmc.sys [x] R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x] R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena Messenger\Room\safedrv.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 VKbms;Virtual HID Minidriver;c:\windows\system32\DRIVERS\VKbms.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 X6va005;X6va005;c:\users\User\AppData\Local\Temp\005459.tmp [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x] S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x] S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2011-01-12 810144] S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-05 13336] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe [2012-01-13 103440] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-07 378984] S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-10-05 2655768] S3 Abyssus;Razer Abyssus;c:\windows\system32\drivers\Abyssus.sys [x] S3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys [x] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [x] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [x] S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 RzSynapse;Razer Driver;c:\windows\system32\DRIVERS\RzSynapse.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-01-04 11772520] "egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-01-12 2918656] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\fi7452xl.default\ FF - prefs.js: browser.search.selectedEngine - Secure Search FF - prefs.js: browser.startup.homepage - about:home FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p= . - - - - ORPHANS REMOVED - - - - . BHO-{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - (no file) . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va005] "ImagePath"="\??\c:\users\User\AppData\Local\Temp\005459.tmp" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-670447627-4047604258-835236124-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-670447627-4047604258-835236124-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_USERS\S-1-5-21-670447627-4047604258-835236124-1000\Software\SecuROM\License information*] "datasecu"=hex:02,48,e3,c2,44,04,d3,db,42,38,ff,a2,06,04,b2,5b,d8,97,50,84,d6, 70,4e,0b,04,c2,4b,46,34,08,ff,f5,7d,66,c1,5d,2c,2b,55,e1,b7,20,6f,c6,83,76,\ "rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE c:\windows\SysWOW64\rundll32.exe c:\program files (x86)\Brother\ControlCenter3\brccMCtl.exe c:\program files (x86)\Brother\Brmfcmon\BrMfcmon.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe . ************************************************************************** . Completion time: 2012-06-09 12:39:55 - machine was rebooted ComboFix-quarantined-files.txt 2012-06-09 04:39 . Pre-Run: 158,215,651,328 bytes free Post-Run: 157,676,400,640 bytes free . - - End Of File - - F8FB80DED0D6EE882A13A250BE8C0D8E I will report back to you about the computer later.
Let''s do a fresh ESET scan to be sure there is nothing else we will need to remove before we uninstall Combofix.




This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.


Go here to run an online scannner from ESET.
  • Note: For browsers other than Internet Explorer, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
Hi, this is the log from eset online scanner, but the log dosen't looked like a log for me, I dont know whether I did it right or not, but this is what i collected from the log.txt. Allow me to ask a question, why ESET online scanner when I already had the full licensed product of ESET Smart Sercurity 4? And there are 5 threats founded from the eset online scanner, but the weird thing is, 2 of them were from my original bought from Steam game Skyrim's launcher, perhaps it is a false alarm? ESETSmartInstaller@High as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK And here is the list of threat founded from the online scanner window, i copy and paste it here just in case C:\Program Files (x86)\GPU-Z\GPU-Z.exe probably a variant of Win32/Genetik trojan C:\Users\User\Downloads\GPU-Z.0.6.2.exe probably a variant of Win32/Genetik trojan D:\Blackout Ragnarok Online\Blackout RO.exe a variant of Win32/Packed.MoleboxUltra application D:\Steam\steamapps\common\skyrim\SkyrimLauncher.exe probably unknown CRYPT.WIN32 virus D:\Steam\steamapps\common\skyrim\TESV.exe probably unknown CRYPT.WIN32 virus
They very well could be false positives. Depending on where the files were obtained they could be legitimate or they could have been packaged with malware. Different scanners look for different trends in files. It doesn't mean they are malware, just that they exhibit "traits" of files that malware might exhibit.

To be on the safe side let's scan all these files at a third party site before we do anything. I'm sorry to have you have to go through this step for all 5 files, but since they could all be perfectly fine, I don't want to delete them if they are legitimate.

We need to get additional information about these files.

Please go to the following site:
http://www.virustotal.com/
Click on Choose File, and then upload the following file for analysis: (you will need to do them one at a time)

C:\Program Files (x86)\GPU-Z\GPU-Z.exe
C:\Users\User\Downloads\GPU-Z.0.6.2.exe
D:\Blackout Ragnarok Online\Blackout RO.exe
D:\Steam\steamapps\common\skyrim\SkyrimLauncher.exe
D:\Steam\steamapps\common\skyrim\TESV.exe


Then click Send File and allow the file to be scanned.

Please ensure the scan is complete and the results saved before submitting the next.
If a pop-up appears saying the file has been scanned already, please select the ReScan button.


Please copy and paste the links to each of the results here for me.
Ah, no need to be sorry, in fact I should be the one who should say sorry for letting you go through all these processes to help me :). Here is the results from virustotal

C:\Program Files (x86)\GPU-Z\GPU-Z.exe
https://www.virustotal.com/file/09ab6320140…sis/1339251532/

C:\Users\User\Downloads\GPU-Z.0.6.2.exe
https://www.virustotal.com/file/09ab6320140…sis/1339251723/

D:\Blackout Ragnarok Online\Blackout RO.exe
https://www.virustotal.com/file/c17ddade9bd…sis/1339251824/

D:\Steam\steamapps\common\skyrim\SkyrimLauncher.exe
https://www.virustotal.com/file/371b9163264…sis/1339252665/

D:\Steam\steamapps\common\skyrim\TESV.exe
https://www.virustotal.com/file/8be302150ab…sis/1339252491/

Aw, it seems like the "Blackout RO.exe" dosen't really seems like a false positive, or is it? It is my favorite online game though :(
I would definitely recommend removing the Blackout RO file as it does appear to be packaged with malware. You could certainly search for another download file and scan it at VirusTotal prior to using it to ensure it's clean. I understand how it is when you have a favorite game, but it's not worth risking your personal data or the security of your machine.


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
D:\Blackout Ragnarok Online\Blackout RO.exe

DDS::
mSearchAssistant = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
TB: {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - No File
TB-X64: {DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - No File


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe. ComboFix may request an update; please allow it.

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Hi, I had ran the Combofix, saw it deleted the Blackout RO.exe, but there are still remain files for the game, do i need to uninstall it? (It is installed via a setup, so maybe via "Program and Features" ?) Here is the log produced by Combofix: ComboFix 12-06-09.01 - User 06/09/2012 22:57:04.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4079.2390 [GMT 8:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\User\Desktop\CFScript.txt AV: ESET Smart Security 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1} FW: ESET Personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA} SP: ESET Smart Security 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "d:\blackout ragnarok online\Blackout RO.exe" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . d:\blackout ragnarok online\Blackout RO.exe . . ((((((((((((((((((((((((( Files Created from 2012-05-09 to 2012-06-09 ))))))))))))))))))))))))))))))) . . 2012-06-09 04:26 . 2012-05-08 17:02 8955792 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CF5FDC64-3C93-4803-AD4B-A52F446A3AE2}\mpengine.dll 2012-06-05 05:15 . 2012-06-05 05:15 ——– d—–w- c:\users\User\AppData\Roaming\Garena 2012-06-05 05:15 . 2012-06-05 05:15 ——– d—–w- c:\programdata\Garena 2012-05-28 04:47 . 2012-05-28 04:47 ——– d—–w- c:\users\User\AppData\Roaming\NVIDIA 2012-05-28 04:47 . 2012-05-28 04:47 ——– d—–w- c:\program files (x86)\GPU-Z 2012-05-26 07:07 . 2012-05-26 07:07 ——– d—–w- c:\users\User\AppData\Roaming\ShanghaiAlice . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-05-05 16:34 . 2012-03-30 12:38 419488 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-05-05 16:34 . 2011-05-15 06:28 70304 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-05-05 16:34 . 2012-04-16 12:33 8744608 —-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2012-04-04 07:56 . 2011-04-02 06:28 24904 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-03-31 06:05 . 2012-05-09 02:09 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-03-31 04:39 . 2012-05-09 02:09 3968368 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-03-31 04:39 . 2012-05-09 02:09 3913072 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-03-31 03:10 . 2012-05-09 02:09 3146240 —-a-w- c:\windows\system32\win32k.sys 2012-03-30 11:35 . 2012-05-09 02:08 1918320 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-03-17 07:58 . 2012-05-09 02:08 75120 —-a-w- c:\windows\system32\drivers\partmgr.sys . . ((((((((((((((((((((((((((((( SnapShot@2012-06-09_04.37.10 ))))))))))))))))))))))))))))))))))))))))) . + 2011-03-30 16:16 . 2012-06-09 05:03 40950 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2012-06-09 05:03 32678 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2011-03-30 16:16 . 2012-06-09 05:03 12802 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-670447627-4047604258-835236124-1000_UserData.bin + 2011-04-02 04:49 . 2012-06-09 15:01 3200 c:\windows\system32\wdi\ERCQueuedResolutions.dat - 2011-04-02 04:49 . 2012-06-06 17:17 3200 c:\windows\system32\wdi\ERCQueuedResolutions.dat + 2012-06-09 15:02 . 2012-06-09 15:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2012-06-09 04:36 . 2012-06-09 04:36 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2012-06-09 15:02 . 2012-06-09 15:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2009-07-14 05:01 . 2012-06-09 04:35 391404 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 05:01 . 2012-06-09 15:01 391404 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2011-03-31 05:54 . 2012-06-09 15:01 23330800 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-670447627-4047604258-835236124-1000-8192.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="d:\steam\steam.exe" [2012-01-14 1242448] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-11-05 283160] "Razer Blackwidow Driver"="c:\program files (x86)\Razer\BlackWidow Ultimate\BlackWidowUltimateTray.exe" [2011-03-08 883616] "BrMfcWnd"="c:\program files (x86)\Brother\Brmfcmon\BrMfcWnd.exe" [2009-05-26 1159168] "ControlCenter3"="c:\program files (x86)\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-08-18 421736] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] . c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Stardock ObjectDock.lnk - c:\program files (x86)\Stardock\ObjectDockFree\ObjectDock.exe [2010-10-7 3768176] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer4"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200804] Ime File REG_SZ GOOGLEPINYIN2.IME . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-10-05 2655768] R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560] R3 dump_wmimmc;dump_wmimmc;c:\program files (x86)\Garena Messenger\Apps\BlackShot\BlackShot\system\GameGuard\dump_wmimmc.sys [x] R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x] R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena Messenger\Room\safedrv.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 VKbms;Virtual HID Minidriver;c:\windows\system32\DRIVERS\VKbms.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] R3 X6va005;X6va005;c:\users\User\AppData\Local\Temp\005459.tmp [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x] S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928] S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x] S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [2011-01-12 810144] S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-05 13336] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe [2012-01-13 103440] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-07 378984] S3 Abyssus;Razer Abyssus;c:\windows\system32\drivers\Abyssus.sys [x] S3 athur;Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys [x] S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys [x] S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys [x] S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 RzSynapse;Razer Driver;c:\windows\system32\DRIVERS\RzSynapse.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-01-04 11772520] "egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-01-12 2918656] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\fi7452xl.default\ FF - prefs.js: browser.search.selectedEngine - Secure Search FF - prefs.js: browser.startup.homepage - about:home FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p= . - - - - ORPHANS REMOVED - - - - . BHO-{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - (no file) . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\X6va005] "ImagePath"="\??\c:\users\User\AppData\Local\Temp\005459.tmp" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-670447627-4047604258-835236124-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-670447627-4047604258-835236124-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_USERS\S-1-5-21-670447627-4047604258-835236124-1000\Software\SecuROM\License information*] "datasecu"=hex:02,48,e3,c2,44,04,d3,db,42,38,ff,a2,06,04,b2,5b,d8,97,50,84,d6, 70,4e,0b,04,c2,4b,46,34,08,ff,f5,7d,66,c1,5d,2c,2b,55,e1,b7,20,6f,c6,83,76,\ "rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE c:\windows\SysWOW64\rundll32.exe c:\program files (x86)\Brother\ControlCenter3\brccMCtl.exe c:\program files (x86)\Brother\Brmfcmon\BrMfcmon.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe . ************************************************************************** . Completion time: 2012-06-09 23:05:44 - machine was rebooted ComboFix-quarantined-files.txt 2012-06-09 15:05 ComboFix2.txt 2012-06-09 04:39 . Pre-Run: 157,367,279,616 bytes free Post-Run: 157,292,118,016 bytes free . - - End Of File - - 476C5940A9F4B959E21C9F66B0F45C9D
You can remove the program via programs and features and/or delete any remaining files manually for the game if you wish. The important part is that the infected file is removed.



The following will implement some cleanup procedures as well as reset System Restore points:
  • Click the Windows Key + R to open the Run box.
  • Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]

If there are any remaining tools or logs on your desktop you can right-click and delete them.


Great job! Your logs appear to be malware free and you do not appear to be experiencing any malware related problems.
Please follow these simple steps in order to keep your computer malware free and secure:

Use and Update your AntiVirus Software
It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall
I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this. Simply using a Firewall in its default configuration can lower your risk greatly.

Use only one antivirus and one firewall on your machine
Having more than one anti-virus program and one firewall on your machine, even if only one is running, can cause conflicts and slowdowns in the performance of the machine.

If you need more information on free anti-virus or firewall options please let me know and I will give you some recommendations.

Make your Internet Explorer more secure
This can be done by following these simple instructions:
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click once on the Security tab
3. Click once on the Internet icon so it becomes highlighted.
4. Click once on the Custom Level button.
5. Change the Download signed ActiveX controls to Prompt
6. Change the Download unsigned ActiveX controls to Disable
7. Change the Initialize and script ActiveX controls not marked as safe to Disable
8. Change the Installation of desktop items to Prompt
9. Change the Launching programs and files in an IFRAME to Prompt
10. Change the Navigate sub-frames across different domains to Prompt
11. When all these settings have been made, click on the OK button.
12. If it prompts you as to whether or not you want to save the settings, press the Yes button.
13. Next press the Apply button and then the OK to exit the Internet Properties page.

Keep your Java, Adobe Reader and Adobe Flash Up to Date
Older versions of these programs can contain security vulnerabilities. It is very important to keep them updated.

Update and Run Malwarebytes Anti-Malware
Scan your computer with this program on a regular basis just as you would an antivirus software making sure you update definitions each time you scan.

To simplify making sure you have the latest version of many of your security programs and applications, you may want to consider:
Secunia's Personal Software Inspector (PSI). It is a free utility that scans your computer for installed applications and checks to see if they have the latest security patches and updates. If it finds any applications with possible security issues, links and/or instructions are provided for the necessariy updates.

Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.

I would suggest you read:
Tony Klein's excellent article: How I got Infected in the First Place
PC Safety and Security–What Do I Need?
How to Prevent Malware

Good luck & Happy surfing!
Hi, thank you very very much for your help! Much appreciated it. But on the process of uninstalling Combofix i almost got freaked out, i typed the same thing on the Run box and it behaved almost as if it was going to run another Combofix scan again, but in the end it was a uninstall. And also by the way, the link for Tony Klein's article of "How I got infected in the First Place" is either out of date or broken, please let the administrator know about this :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI