This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

unusally high system mem being used [Solved]

64 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i did a scan with avg on my computer and it found that a root-kit called win32 : smsSend-ig was present.
i have not been able to remove it. Also the svc host is taking up a lot of memory. even more so when i connect to the internet with either firefox or chrome

here is the log file from hijackthis

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:16:53 PM, on 13/06/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16446)
Boot mode: Normal

Running processes:
C:\Program Files\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
c:\Program Files\Bioscrypt\VeriSoft\Bin\AsGHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Users\user1\AppData\Local\Akamai\netsession_win.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Users\user1\AppData\Local\Akamai\netsession_win.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Windows\system32\conime.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:9421;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.7.2.3\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.7.2.3\IPS\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O2 - BHO: VeriSoft Access Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Bioscrypt\VeriSoft\Bin\ItIEAddIn.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.7.2.3\coIEPlg.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\BIOSCR~1\VeriSoft\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Programs\PartyGaming.Net\PartyPokerNet\RunPF.exe
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Programs\PartyGaming.Net\PartyPokerNet\RunPF.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.1.0\ViProtocol.dll
O20 - AppInit_DLLs: APSHook.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: JSMWS - Unknown owner - C:\Users\user1\AppData\Local\Temp\JSMWS.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: QMY - Unknown owner - C:\Users\user1\AppData\Local\Temp\QMY.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: UCXIU - Unknown owner - C:\Users\user1\AppData\Local\Temp\UCXIU.exe (file missing)
O23 - Service: vToolbarUpdater11.1.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe
O23 - Service: ZNT - Unknown owner - C:\Users\user1\AppData\Local\Temp\ZNT.exe (file missing)

–
End of file - 11638 bytes



….. I know that i should not have 3 virus programs running but i put them on in hopes at least one would be able to fix the issue, and i planed to uninstall them after one had fixed it ……

Thank you.
Hello comp_problems and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your log now and will reply with instructions shortly

Satchfan
Hello again comp_problems

Run DDS

Please download DDS by sUBs from one of the following links and save it to your desktop.

DDS.scr
DDS.pif

  • disable any script blocking protection (How to Disable your Security Programs)
  • double click DDS icon to run the tool (may take up to 3 minutes to run)
  • when done, DDS.txt will open.
  • after a few moments, attach.txt will open in a second window.
  • save both reports to your desktop.
  • Post the contents of the DDS.txt and Attach.txt reports in your next reply
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Please include the following in your next post :

DDS.txt
Attach.txt
aswMBR log


Thanks

Satchfan
hello , and thank you for helping. I can't download DDS, as when i click on it only a blank page comes up. ? i will post the aswmbr in a few hours when it is done thank you.
Disable you antivirus program(s) if you are having a problem with aswMBR as it shouldn't take long to run.

Also, try downloading DDS with the programs disabled.

Please also do the following:

Run HijackThis
  • click on Config and then on the Misc Tools button
  • if you're viewing HijackThis from the Main Menu, click on Open the Misc Tools Section
  • click on the Open Uninstall Manager button
  • click the Save List button.
Copy and paste that list here.

Thanks

Satchfan
hello Satchfan, thank you again, here is the aswmbr log, also when i booted up my computer avg found C;\program files\bioscrypt\verisoft\bin\asghost.exe and flagged it as malware and put it in the virus vault i am going to run HJT after i make this post and try do download DDS again aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-06-15 00:11:50 —————————– 00:11:50.724 OS Version: Windows 6.0.6002 Service Pack 2 00:11:50.724 Number of processors: 2 586 0xF0A 00:11:50.724 ComputerName: USER1-PC UserName: user1 00:12:02.361 Initialize success 00:21:31.835 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 00:21:31.851 Disk 0 Vendor: TOSHIBA_ DK02 Size: 190782MB BusType: 3 00:21:31.867 Disk 0 MBR read successfully 00:21:31.867 Disk 0 MBR scan 00:21:31.882 Disk 0 Windows VISTA default MBR code 00:21:31.882 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 182221 MB offset 63 00:21:31.913 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 8558 MB offset 373189950 00:21:31.913 Disk 0 scanning sectors +390716865 00:21:31.991 Disk 0 scanning C:\Windows\system32\drivers 00:21:57.341 Service scanning 00:22:55.779 Modules scanning 00:23:28.133 Disk 0 trace - called modules: 00:23:28.165 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll iaStor.sys 00:23:28.165 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85c3f0e0] 00:23:28.165 3 CLASSPNP.SYS[889aa8b3] -> nt!IofCallDriver -> [0x84887aa0] 00:23:28.180 5 acpi.sys[806926bc] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x85225030] 00:23:28.180 Scan finished successfully 00:27:24.941 Disk 0 MBR has been saved successfully to "C:\Users\user1\Desktop\MBR.dat" 00:27:24.957 The log file has been saved successfully to "C:\Users\user1\Desktop\aswMBR.txt" hello and thank you again,
here is the HJT list Update for Microsoft Office 2007 (KB2508958) Activation Assistant for the 2007 Microsoft Office suites ActiveCheck component for HP Active Support Library Adobe AIR Adobe AIR Adobe Anchor Service CS4 Adobe Bridge CS4 Adobe CMaps CS4 Adobe Color - Photoshop Specific CS4 Adobe Color EU Extra Settings CS4 Adobe Color JA Extra Settings CS4 Adobe Color NA Recommended Settings CS4 Adobe Color Video Profiles CS CS4 Adobe CSI CS4 Adobe Default Language CS4 Adobe Device Central CS4 Adobe Dreamweaver CS4 Adobe Dreamweaver CS4 Adobe Drive CS4 Adobe Dynamiclink Support Adobe ExtendScript Toolkit CS4 Adobe Extension Manager CS4 Adobe Flash CS4 Adobe Flash CS4 Extension - Flash Lite STI en Adobe Flash CS4 Professional Adobe Flash CS4 STI-en Adobe Flash Player 10 ActiveX Adobe Flash Player 11 Plugin Adobe Fonts All Adobe Linguistics CS4 Adobe Media Encoder CS4 Adobe Media Player Adobe Media Player Adobe Output Module Adobe PDF Library Files CS4 Adobe Photoshop CS4 Adobe Photoshop CS4 Adobe Photoshop CS4 Adobe Photoshop CS4 Support Adobe Reader 8 Adobe Search for Help Adobe Service Manager Extension Adobe Setup Adobe Setup Adobe Setup Adobe Type Support CS4 Adobe Update Manager CS4 Adobe WinSoft Linguistics Plugin Adobe XMP Panels CS4 AdobeColorCommonSetCMYK AdobeColorCommonSetRGB Akamai NetSession Interface Service AuthenTec Fingerprint Sensor Minimum Install AVG 2012 AVG 2012 AVG 2012 AVG 2012 AVG 2012 CCleaner Connect CSE HTML Validator Professional v9.03 Trial ESU for Microsoft Vista HiJackThis Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Active Support Library HP Active Support Library 32 bit components HP Customer Experience Enhancements HP Doc Viewer HP Easy Setup - Frontend HP Help and Support HP Photosmart Essential 2.0 HP Quick Launch Buttons 6.20 B1 HP QuickPlay 3.2 HP Total Care Advisor HP Update HP User Guides 0057 HP Wireless Assistant HPAsset component for HP Active Support Library HPNetworkAssistant Intel Matrix Storage Manager Java™ 7 Update 4 JavaFX 2.1.0 kuler Logitech Vid Logitech Webcam Software Malwarebytes Anti-Malware version 1.61.0.1400 Maple 12 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Client Profile Microsoft Choice Guard Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Home and Student 2007 Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Works Motorola SM56 Data Fax Modem Mozilla Firefox 4.0.1 (x86 en-US) MSCU for Microsoft Vista MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) My HP Games Norton Bootable Recovery Tool Wizard Norton Internet Security NoteTab Pro 6 Trial (Remove only) NVIDIA Drivers PDF Settings CS4 Photoshop Camera Raw Pixel Bender Toolkit PVSonyDll QuickTime 3.0 Realtek High Definition Audio Driver Rhapsody Rhapsody Player Engine Roxio Activation Module Roxio Creator Audio Roxio Creator Basic v9 Roxio Creator Copy Roxio Creator Data Roxio Creator EasyArchive Roxio Creator Tools Roxio Express Labeler 3 Roxio MyDVD Basic v9 Scratch Live 2.4.1 (9) Seagate Manager Installer Seagate Manager Installer Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition Security Update for Windows Media Encoder (KB2447961) Security Update for Windows Media Encoder (KB979332) SmartSound Common Data SmartSound Common Data SmartSound Quicktracks 5 SmartSound Quicktracks 5 Suite Shared Configuration CS4 Synaptics Pointing Device Driver Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) VeriSoft Access Manager VLC media player 1.0.0 Vuze WBFS Manager 2.5 Windows 7 USB/DVD Download Tool Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Essentials Windows Live Messenger Windows Live Sign-in Assistant Windows Live Upload Tool Windows Media Encoder 9 Series Windows Media Encoder 9 Series Windows Media Player Firefox Plugin WinRAR archiver
hello, here is the DDS report . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.4.1 Run by [removed] at 21:31:08 on 2012-06-16 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2046.1078 [GMT -7:00] . AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} AV: AVG Anti-Virus 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton Internet Security *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\System32\svchost.exe -k Cognizance C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\AVG\AVG2012\avgwdsvc.exe C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Windows\system32\DllHost.exe C:\Windows\ehome\ehsched.exe C:\Windows\ehome\ehRecvr.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe C:\Program Files\HP\HP Software Update\hpwuschd2.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe C:\Program Files\AVG\AVG2012\avgtray.exe C:\Program Files\AVG Secure Search\vprot.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe C:\Program Files\AVG\AVG2012\avgcfgex.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\conime.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.ca/ uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=73&bd=Pavilion&pf=laptop mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=73&bd=Pavilion&pf=laptop mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=73&bd=Pavilion&pf=laptop uInternet Settings,ProxyOverride = 127.0.0.1:9421; BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - c:\program files\avg\avg2012\avgdtiex.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\18.7.2.3\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\18.7.2.3\ips\IPSBHO.DLL BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\11.1.0.7\AVG Secure Search_toolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll BHO: VeriSoft Access Manager: {df21f1db-80c6-11d3-9483-b03d0ec10000} - c:\program files\bioscrypt\verisoft\bin\ItIEAddIn.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\18.7.2.3\coIEPlg.dll TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\11.1.0.7\AVG Secure Search_toolbar.dll {e7df6bff-55a5-4eb7-a673-4ed3e9456d39} uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [SMSERIAL] c:\program files\motorola\smserial\sm56hlpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe" mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe mRun: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe mRun: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe mRun: [CognizanceTS] rundll32.exe c:\progra~1\bioscr~1\verisoft\bin\ASTSVCC.dll,RegisterModule mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [] mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray mRun: [MaxMenuMgr] "c:\program files\seagate\seagatemanager\freeagent status\StxMenuMgr.exe" mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe" mRun: [vProt] "c:\program files\avg secure search\vprot.exe" mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {F4430FE8-2638-42e5-B849-800749B94EED} - c:\programs\partygaming.net\partypokernet\RunPF.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - c:\program files\avg\avg2012\avgdtiex.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL Trusted Zone: real.com\rhap-app-4-0 Trusted Zone: real.com\rhapreg TCP: DhcpNameServer = 192.168.1.254 [removed] TCP: Interfaces\{71147865-9F2B-4375-81FF-7040448863D3} : DhcpNameServer = 192.168.1.254 [removed] TCP: Interfaces\{7F82E9EA-52E0-4D8F-8D6E-3BE7AF6CBD09} : DhcpNameServer = 192.168.1.254 [removed] Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\11.1.0\ViProtocol.dll AppInit_DLLs: APSHook.dll LSA: Notification Packages = scecli ASWLNPkg . ================= FIREFOX =================== . FF - ProfilePath - c:\users\user1\appdata\roaming\mozilla\firefox\profiles\xgr1i5ft.default\ FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B5e9c1a30-4149-4f26-9dfa-544da23d6f86%7D&mid=7aa62d989ef347d08734d15262db890e-88a4f364e0e103582cc36f5ee7705057d3f9c953&ds=AVG&v=11.1.0.7&lang=en&pr=pr&d=2012-05-28%2011%3A16%3A56&sap=ku&q= FF - plugin: c:\program files\common files\avg secure search\sitesafetyinstaller\11.1.0\npsitesafety.dll FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll FF - plugin: c:\users\user1\appdata\local\google\update\1.3.21.111\npGoogleUpdate3.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_233.dll FF - plugin: c:\windows\system32\npDeployJava1.dll FF - plugin: c:\windows\system32\npmproxy.dll . ============= SERVICES / DRIVERS =============== . R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2012-4-19 24896] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2012-1-31 31952] R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nis\1207020.003\symds.sys [2012-6-11 340088] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1207020.003\symefa.sys [2012-6-11 744568] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2012-2-22 235216] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-12-23 41040] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2012-3-19 301248] R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_18.1.0.37\definitions\bashdefs\20120531.001\BHDrvx86.sys [2012-6-5 821880] R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_18.1.0.37\definitions\ipsdefs\20120613.007\IDSvix86.sys [2012-6-13 368248] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nis\1207020.003\ironx86.sys [2012-6-11 136312] R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\nis\1207020.003\symtdiv.sys [2012-6-11 331384] R2 ASBroker;Logon Session Broker;c:\windows\system32\svchost.exe -k Cognizance [2009-6-1 21504] R2 ASChannel;Local Communication Channel;c:\windows\system32\svchost.exe -k Cognizance [2009-6-1 21504] R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2012-2-14 193288] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2009-6-1 21504] R2 FreeAgentGoNext Service;Seagate Service;c:\program files\seagate\seagatemanager\sync\FreeAgentService.exe [2009-5-1 181544] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-2-25 654408] R2 NIS;Norton Internet Security;c:\program files\norton internet security\engine\18.7.2.3\ccsvchst.exe [2012-6-11 130008] R2 vToolbarUpdater11.1.0;vToolbarUpdater11.1.0;c:\program files\common files\avg secure search\vtoolbarupdater\11.1.0\ToolbarUpdater.exe [2012-5-28 935480] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2011-12-23 139856] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilterx.sys [2011-12-23 24144] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2011-12-23 17232] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-6-3 106656] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-2-25 22344] S2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\avgidsagent.exe [2012-4-30 5106744] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-18 253088] S3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\system32\drivers\HCW85BDA.sys [2011-6-29 1603712] S3 JSMWS;JSMWS;c:\users\user1\appdata\local\temp\jsmws.exe –> c:\users\user1\appdata\local\temp\JSMWS.exe [?] S3 QMY;QMY;c:\users\user1\appdata\local\temp\qmy.exe –> c:\users\user1\appdata\local\temp\QMY.exe [?] S3 UCXIU;UCXIU;c:\users\user1\appdata\local\temp\ucxiu.exe –> c:\users\user1\appdata\local\temp\UCXIU.exe [?] S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S3 ZNT;ZNT;c:\users\user1\appdata\local\temp\znt.exe –> c:\users\user1\appdata\local\temp\ZNT.exe [?] . =============== Created Last 30 ================ . 2012-06-13 22:13:07 388096 —-a-r- c:\users\user1\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2012-06-13 22:13:03 ——– d—–w- c:\program files\Trend Micro 2012-06-13 21:54:24 ——– d—–w- c:\windows\pss 2012-06-13 21:36:04 ——– d—–w- c:\program files\CCleaner 2012-06-13 21:30:39 180736 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-06-13 18:34:53 2045440 —-a-w- c:\windows\system32\win32k.sys 2012-06-12 20:26:03 984064 —-a-w- c:\windows\system32\crypt32.dll 2012-06-12 20:26:03 133120 —-a-w- c:\windows\system32\cryptsvc.dll 2012-06-12 20:26:02 98304 —-a-w- c:\windows\system32\cryptnet.dll 2012-06-12 05:46:32 331384 —-a-w- c:\windows\system32\drivers\nis\1207020.003\symtdiv.sys 2012-06-12 05:46:31 299640 —-a-w- c:\windows\system32\drivers\nis\1207020.003\symnets.sys 2012-06-12 05:46:29 744568 —-a-w- c:\windows\system32\drivers\nis\1207020.003\symefa.sys 2012-06-12 05:46:29 340088 —-a-w- c:\windows\system32\drivers\nis\1207020.003\symds.sys 2012-06-12 05:46:27 516216 —-a-w- c:\windows\system32\drivers\nis\1207020.003\srtsp.sys 2012-06-12 05:46:27 50168 —-a-w- c:\windows\system32\drivers\nis\1207020.003\srtspx.sys 2012-06-12 05:46:26 136312 —-a-w- c:\windows\system32\drivers\nis\1207020.003\ironx86.sys 2012-06-12 05:43:43 ——– d—–w- c:\windows\system32\drivers\nis\1207020.003 2012-06-11 06:17:21 ——– d—–w- c:\program files\Oracle 2012-06-11 06:16:52 772504 —-a-w- c:\windows\system32\npDeployJava1.dll 2012-06-11 02:46:25 ——– d—–w- C:\ComboFix 2012-06-10 22:18:41 ——– d—–w- c:\programdata\AVAST Software 2012-06-10 22:18:41 ——– d—–w- c:\program files\AVAST Software 2012-06-10 20:42:01 ——– d—–w- C:\TDSSKiller_Quarantine 2012-06-05 22:03:02 40056 —-a-w- c:\windows\system32\drivers\SeratoUsb.sys 2012-06-05 22:02:48 61440 —-a-r- c:\users\user1\appdata\roaming\microsoft\installer\{8d084419-7570-4350-a4d2-c358e5e7f3ac}\NewShortcut7_B56E5B51EA954C948003CC703E2AFAD5.exe 2012-06-05 22:02:48 61440 —-a-r- c:\users\user1\appdata\roaming\microsoft\installer\{8d084419-7570-4350-a4d2-c358e5e7f3ac}\NewShortcut1_9046FC1E1C604E8F87F08E640274C274.exe 2012-06-05 22:02:17 ——– d—–w- c:\program files\Serato 2012-05-28 18:19:59 ——– d—–w- c:\users\user1\appdata\roaming\AVG2012 2012-05-28 18:17:39 ——– d—–w- c:\users\user1\appdata\local\AVG Secure Search 2012-05-28 18:16:54 ——– d—–w- c:\programdata\AVG Secure Search 2012-05-28 18:16:42 ——– d—–w- c:\program files\common files\AVG Secure Search 2012-05-28 18:16:41 ——– d—–w- c:\program files\AVG Secure Search 2012-05-28 18:16:01 ——– d–h–w- c:\programdata\Common Files 2012-05-28 18:14:54 ——– d–h–w- C:\$AVG 2012-05-28 18:14:54 ——– d—–w- c:\windows\system32\drivers\AVG 2012-05-28 18:14:54 ——– d—–w- c:\programdata\AVG2012 2012-05-28 18:12:39 ——– d—–w- c:\program files\AVG 2012-05-28 18:08:10 ——– d—–w- c:\programdata\MFAData . ==================== Find3M ==================== . 2012-05-17 22:45:37 1800192 —-a-w- c:\windows\system32\jscript9.dll 2012-05-17 22:35:47 1129472 —-a-w- c:\windows\system32\wininet.dll 2012-05-17 22:35:39 1427968 —-a-w- c:\windows\system32\inetcpl.cpl 2012-05-17 22:29:45 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2012-05-17 22:24:45 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-04-19 11:50:26 24896 —-a-w- c:\windows\system32\drivers\avgidshx.sys 2012-04-19 01:02:05 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-04-19 01:02:05 418464 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-04-05 01:47:02 687504 —-a-w- c:\windows\system32\deployJava1.dll 2012-04-04 22:56:40 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-04-03 08:16:12 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-04-03 08:16:11 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-03-30 12:39:11 905600 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-03-20 23:28:50 53120 —-a-w- c:\windows\system32\drivers\partmgr.sys 2012-03-19 12:17:28 301248 —-a-w- c:\windows\system32\drivers\avgtdix.sys . ============= FINISH: 21:32:17.38 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 11/06/2007 12:51:48 AM System Uptime: 16/06/2012 8:55:03 PM (1 hours ago) . Motherboard: Quanta | | 30D2 Processor: Intel® Core™2 Duo CPU T7300 @ 2.00GHz | U2E1 | 2001/800mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 178 GiB total, 17.471 GiB free. D: is FIXED (NTFS) - 8 GiB total, 1.812 GiB free. E: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) Activation Assistant for the 2007 Microsoft Office suites ActiveCheck component for HP Active Support Library Adobe AIR Adobe Anchor Service CS4 Adobe Bridge CS4 Adobe CMaps CS4 Adobe Color - Photoshop Specific CS4 Adobe Color EU Extra Settings CS4 Adobe Color JA Extra Settings CS4 Adobe Color NA Recommended Settings CS4 Adobe Color Video Profiles CS CS4 Adobe CSI CS4 Adobe Default Language CS4 Adobe Device Central CS4 Adobe Dreamweaver CS4 Adobe Drive CS4 Adobe Dynamiclink Support Adobe ExtendScript Toolkit CS4 Adobe Extension Manager CS4 Adobe Flash CS4 Adobe Flash CS4 Extension - Flash Lite STI en Adobe Flash CS4 Professional Adobe Flash CS4 STI-en Adobe Flash Player 10 ActiveX Adobe Flash Player 11 Plugin Adobe Fonts All Adobe Linguistics CS4 Adobe Media Encoder CS4 Adobe Media Player Adobe Output Module Adobe PDF Library Files CS4 Adobe Photoshop CS4 Adobe Photoshop CS4 Support Adobe Reader 8 Adobe Search for Help Adobe Service Manager Extension Adobe Setup Adobe Type Support CS4 Adobe Update Manager CS4 Adobe WinSoft Linguistics Plugin Adobe XMP Panels CS4 AdobeColorCommonSetCMYK AdobeColorCommonSetRGB Akamai NetSession Interface Akamai NetSession Interface Service AuthenTec Fingerprint Sensor Minimum Install AVG 2012 CCleaner Connect CSE HTML Validator Professional v9.03 Trial ESU for Microsoft Vista FileZilla Client 3.3.1 Google Chrome HiJackThis Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Active Support Library HP Active Support Library 32 bit components HP Customer Experience Enhancements HP Doc Viewer HP Easy Setup - Frontend HP Help and Support HP Photosmart Essential 2.0 HP Photosmart Essential2.5 HP Quick Launch Buttons 6.20 B1 HP QuickPlay 3.2 HP Total Care Advisor HP Update HP User Guides 0057 HP Wireless Assistant HPAsset component for HP Active Support Library HPNetworkAssistant Intel Matrix Storage Manager Java Auto Updater Java™ 7 Update 4 JavaFX 2.1.0 kuler LightScribe 1.4.136.1 Logitech Vid Logitech Webcam Software Malwarebytes Anti-Malware version 1.61.0.1400 Maple 12 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Works Motorola SM56 Data Fax Modem Mozilla Firefox 4.0.1 (x86 en-US) MSCU for Microsoft Vista MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) My HP Games Norton Bootable Recovery Tool Wizard Norton Internet Security NoteTab Pro 6 Trial (Remove only) NVIDIA Drivers PDF Settings CS4 Photoshop Camera Raw Pixel Bender Toolkit PSSWCORE PVSonyDll QuickTime 3.0 Realtek High Definition Audio Driver Rhapsody Rhapsody Player Engine Roxio Activation Module Roxio Creator Audio Roxio Creator Basic v9 Roxio Creator Copy Roxio Creator Data Roxio Creator EasyArchive Roxio Creator Tools Roxio Express Labeler 3 Roxio MyDVD Basic v9 Scratch Live 2.4.1 (9) Seagate Manager Installer Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition Security Update for Windows Media Encoder (KB2447961) Security Update for Windows Media Encoder (KB979332) SmartSound Common Data SmartSound Quicktracks 5 Suite Shared Configuration CS4 Synaptics Pointing Device Driver Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) VeriSoft Access Manager VLC media player 1.0.0 Vuze WBFS Manager 2.5 Windows 7 USB/DVD Download Tool Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Messenger Windows Live Sign-in Assistant Windows Live Upload Tool Windows Media Encoder 9 Series Windows Media Player Firefox Plugin WinRAR archiver . ==== Event Viewer Messages From Past Week ======== . 16/06/2012 8:59:35 PM, Error: Service Control Manager [7022] - The CyberLink Background Capture Service (CBCS) service hung on starting. 16/06/2012 8:59:35 PM, Error: Service Control Manager [7001] - The CyberLink Task Scheduler (CTS) service depends on the CyberLink Background Capture Service (CBCS) service which failed to start because of the following error: After starting, the service hung in a start-pending state. 16/06/2012 8:57:55 PM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 16/06/2012 8:57:55 PM, Error: Service Control Manager [7000] - The MCSTRM service failed to start due to the following error: The system cannot find the file specified. 14/06/2012 8:59:46 AM, Error: NETw4v32 [5005] - Intel® Wireless WiFi Link 4965AGN : Has encountered an internal error and has failed. 14/06/2012 8:59:45 AM, Error: NETw4v32 [5002] - Intel® Wireless WiFi Link 4965AGN : Has determined that the network adapter is not functioning properly. 13/06/2012 9:32:08 AM, Error: Service Control Manager [7031] - The Windows Modules Installer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 13/06/2012 2:25:59 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the avgwd service. 13/06/2012 11:06:39 AM, Error: Service Control Manager [7043] - The Windows Update service did not shut down properly after receiving a preshutdown control. 12/06/2012 8:53:18 AM, Error: EventLog [6008] - The previous system shutdown at 8:49:22 AM on 12/06/2012 was unexpected. 12/06/2012 8:45:50 PM, Error: SRTSP [5] - Error loading Symantec real time Anti-Virus driver. 12/06/2012 8:45:50 PM, Error: SRTSP [4] - Error loading virus definitions. 12/06/2012 8:45:09 PM, Error: Service Control Manager [7043] - The Group Policy Client service did not shut down properly after receiving a preshutdown control. 12/06/2012 8:20:52 AM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit. 11/06/2012 11:02:00 AM, Error: Service Control Manager [7034] - The vToolbarUpdater11.1.0 service terminated unexpectedly. It has done this 1 time(s). 10/06/2012 7:40:29 PM, Error: Service Control Manager [7034] - The Process Monitor service terminated unexpectedly. It has done this 1 time(s). 10/06/2012 11:44:56 AM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. 10/06/2012 11:34:18 AM, Error: EventLog [6008] - The previous system shutdown at 11:28:51 AM on 10/06/2012 was unexpected. 10/06/2012 11:25:40 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Modules Installer service to connect. 10/06/2012 11:25:40 AM, Error: Service Control Manager [7000] - The Windows Modules Installer service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 10/06/2012 11:25:38 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service TrustedInstaller with arguments "" in order to run the server: {752073A1-23F2-4396-85F0-8FDB879ED0ED} . ==== End Of File =========================== thank you for helping
Hello again

aswMBR is clean but there are some nasties in the DDS log so we'll need another scan.

First, a couple of observations:

P2P - I see you have P2P software, (Vuze), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

Antivirus information

I’m not surprised that you are having high memory usage and other problems as you are running 2 antiviruses.

You can not run two real-time antiviruses at the same time. Although many have different methods of searching for and recognising threats, they will all be 'fighting' in memory to kick each other out, rendering them all ineffective.

Please uninstall either Norton Security Suite or AVG.

Note: if you uninstall Norton, you will have to enable the Windows firewall.

To turn on Windows firewall:
  • open Windows Firewall by clicking Start, Control Panel, Security, and then Windows Firewall.
  • click Turn Windows Firewall on or off. If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
  • click On (recommended), and then OK.
===================================================

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, as they may otherwise interfere with our tools. See here for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Satchfan
hello Satchfan.
thank you again for your help.
the high memory use was already an issue before i installed AVG. I installed it because norton was not catching or flagging anything as suspicious.


here is the pop up results from combofix


ComboFix 12-06-16.02 - user1 17/06/2012 11:05:40.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2046.849 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: AVG Anti-Virus 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Norton Internet Security *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\9E4BD2E73D.sys
c:\users\user1\AppData\Roaming\212B13
c:\users\user1\AppData\Roaming\698e8de9c79e614b8d6a96b5ce9682e6-i686.cache-2
.
.
((((((((((((((((((((((((( Files Created from 2012-05-17 to 2012-06-17 )))))))))))))))))))))))))))))))
.
.
2012-06-17 18:18 . 2012-06-17 18:18 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-06-17 05:59 . 2012-06-17 05:59 ——– d—–w- c:\users\user1\.swt
2012-06-13 22:13 . 2012-06-13 22:13 388096 —-a-r- c:\users\user1\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-06-13 22:13 . 2012-06-13 22:13 ——– d—–w- c:\program files\Trend Micro
2012-06-13 21:36 . 2012-06-13 21:36 ——– d—–w- c:\program files\CCleaner
2012-06-13 21:30 . 2012-05-01 14:03 180736 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-13 18:34 . 2012-05-15 19:51 2045440 —-a-w- c:\windows\system32\win32k.sys
2012-06-12 20:26 . 2012-04-23 16:00 984064 —-a-w- c:\windows\system32\crypt32.dll
2012-06-12 20:26 . 2012-04-23 16:00 133120 —-a-w- c:\windows\system32\cryptsvc.dll
2012-06-12 20:26 . 2012-04-23 16:00 98304 —-a-w- c:\windows\system32\cryptnet.dll
2012-06-12 05:43 . 2012-06-12 15:51 ——– d—–w- c:\windows\system32\drivers\NIS\1207020.003
2012-06-11 06:25 . 2012-06-11 06:25 ——– d—–w- c:\program files\Common Files\Java
2012-06-11 06:17 . 2012-06-11 06:17 ——– d—–w- c:\program files\Oracle
2012-06-11 06:16 . 2012-04-05 01:47 772504 —-a-w- c:\windows\system32\npDeployJava1.dll
2012-06-10 22:18 . 2012-06-14 05:13 ——– d—–w- c:\programdata\AVAST Software
2012-06-10 22:18 . 2012-06-10 22:18 ——– d—–w- c:\program files\AVAST Software
2012-06-10 20:42 . 2012-06-10 22:11 ——– d—–w- C:\TDSSKiller_Quarantine
2012-06-05 22:03 . 2012-02-27 20:56 40056 —-a-w- c:\windows\system32\drivers\SeratoUsb.sys
2012-06-05 22:02 . 2012-06-05 22:02 61440 —-a-r- c:\users\user1\AppData\Roaming\Microsoft\Installer\{8D084419-7570-4350-A4D2-C358E5E7F3AC}\NewShortcut7_B56E5B51EA954C948003CC703E2AFAD5.exe
2012-06-05 22:02 . 2012-06-05 22:02 61440 —-a-r- c:\users\user1\AppData\Roaming\Microsoft\Installer\{8D084419-7570-4350-A4D2-C358E5E7F3AC}\NewShortcut1_9046FC1E1C604E8F87F08E640274C274.exe
2012-06-05 22:02 . 2012-06-05 22:02 ——– d—–w- c:\program files\Serato
2012-05-28 18:19 . 2012-05-28 18:19 ——– d—–w- c:\users\user1\AppData\Roaming\AVG2012
2012-05-28 18:17 . 2012-05-28 18:17 ——– d—–w- c:\users\user1\AppData\Local\AVG Secure Search
2012-05-28 18:16 . 2012-05-28 18:18 ——– d—–w- c:\programdata\AVG Secure Search
2012-05-28 18:16 . 2012-05-28 18:16 ——– d—–w- c:\program files\Common Files\AVG Secure Search
2012-05-28 18:16 . 2012-05-28 18:17 ——– d—–w- c:\program files\AVG Secure Search
2012-05-28 18:16 . 2012-05-28 18:16 ——– d–h–w- c:\programdata\Common Files
2012-05-28 18:14 . 2012-06-17 17:53 ——– d—–w- c:\windows\system32\drivers\AVG
2012-05-28 18:14 . 2012-06-17 03:57 ——– d—–w- c:\programdata\AVG2012
2012-05-28 18:14 . 2012-05-28 18:14 ——– d—–w- C:\$AVG
2012-05-28 18:12 . 2012-05-28 18:12 ——– d—–w- c:\program files\AVG
2012-05-28 18:08 . 2012-06-17 17:54 ——– d—–w- c:\programdata\MFAData
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-19 11:50 . 2012-04-19 11:50 24896 —-a-w- c:\windows\system32\drivers\avgidshx.sys
2012-04-19 01:02 . 2012-04-19 01:02 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-19 01:02 . 2012-04-19 01:02 418464 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-05 01:47 . 2011-01-25 20:07 687504 —-a-w- c:\windows\system32\deployJava1.dll
2012-04-04 22:56 . 2012-02-26 01:33 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-04-03 08:16 . 2012-05-10 21:17 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-03 08:16 . 2012-05-10 21:17 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-03-30 12:39 . 2012-05-10 21:22 905600 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-03-20 23:28 . 2012-05-10 21:22 53120 —-a-w- c:\windows\system32\drivers\partmgr.sys
2011-04-14 16:26 . 2012-05-04 02:38 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-05-28 18:16 2068536 —-a-w- c:\program files\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll" [2012-05-28 2068536]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 729088]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 827392]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-06-09 7539232]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 174872]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-04-24 176128]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 159744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 317128]
"CognizanceTS"="c:\progra~1\BIOSCR~1\VeriSoft\Bin\ASTSVCC.dll" [2003-12-22 17920]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-10-03 13826664]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-05-01 185640]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-04-05 2587008]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-05-28 1104440]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\APSHook.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^user1^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\user1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface]
2012-05-08 07:31 3331872 —-a-w- c:\users\user1\AppData\Local\Akamai\netsession_win.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-19 07:33 125952 —-a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2012-04-18 23:22 116648 —-atw- c:\users\user1\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-04-17 05:12 3872080 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-17 18:07 252296 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-19 253088]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASBroker ASChannel
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2012-06-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-19 01:02]
.
2012-06-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2829460781-2310491692-1321307309-1000Core.job
- c:\users\user1\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-18 23:22]
.
2012-06-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2829460781-2310491692-1321307309-1000UA.job
- c:\users\user1\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-18 23:22]
.
2012-06-14 c:\windows\Tasks\HPCeeScheduleForuser1.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2007-05-12 21:23]
.
2012-06-12 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - user1.job
- c:\program files\Norton Internet Security\Engine\18.7.2.3\navw32.exe [2012-06-12 00:01]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=73&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = 127.0.0.1:9421;
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
TCP: DhcpNameServer = 192.168.1.254 [removed]
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\11.1.0\ViProtocol.dll
FF - ProfilePath - c:\users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\xgr1i5ft.default\
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B5e9c1a30-4149-4f26-9dfa-544da23d6f86%7D&mid=7aa62d989ef347d08734d15262db890e-88a4f364e0e103582cc36f5ee7705057d3f9c953&ds=AVG&v=11.1.0.7&lang=en&pr=pr&d=2012-05-28%2011%3A16%3A56&sap=ku&q=
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
SafeBoot-81168428.sys
SafeBoot-95464943.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-06-17 11:27
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
c:\users\user1\AppData\Local\Temp\catchme.dll 53248 bytes executable
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\18.7.2.3\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2829460781-2310491692-1321307309-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2C047963-C4B7-CB61-8EFE-97C02034D95E}*]
"maempodnllmlinbpimhfgnglnd"=hex:69,61,63,62,61,6c,6f,68,6e,61,6c,63,6e,62,64,
6a,66,62,00,00
"fbfeflkekefcolkhaoplglocojjmekmalhmaomojdphm"=hex:66,61,70,61,61,69,6c,6a,61,
70,6d,66,00,ef
"naolbblgmbclmknmkincbldopoaj"=hex:69,61,6e,61,66,69,67,6c,6a,61,70,6f,65,6f,
6b,70,6c,62,00,60
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'Explorer.exe'(3692)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG2012\avgrsx.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\program files\AVG\AVG2012\avgwdsvc.exe
c:\program files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
c:\program files\AVG\AVG2012\avgemcx.exe
c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe
c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe
c:\windows\system32\DllHost.exe
c:\windows\system32\conime.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehsched.exe
c:\windows\ehome\ehRecvr.exe
c:\windows\ehome\ehPrivJob.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
.
**************************************************************************
.
Completion time: 2012-06-17 11:37:04 - machine was rebooted
ComboFix-quarantined-files.txt 2012-06-17 18:36
.
Pre-Run: 20,938,788,864 bytes free
Post-Run: 20,528,844,800 bytes free
.
- - End Of File - - 22DF83263408B12E9003CD259C24F33A



the saved file combofix.txt will not let me open it up or access it. it says
illegal operation attempted on a registry key marked for deletion so i have included it as an attachment i hope that helps.


thank you.

Attachments:

Update: I tried to uninstall Avg twice and both times it is still there when i reboot the system. i used the uninstall programs feature in the control panel to try and remove this. thank you very much for your help
Let’s try removing AVG.

Run AppRemover

Please download AppRemover and save it to your desktop.
  • double click on AppRemover.exe to run it.
  • uncheck "Enable anonymous usage statistics. No personal data will be recorded."
  • click on the Next button.
  • click on "Remove Security Application" or "Clean Up a Failed Uninstall" depending on what you want to do. (you want the failed uninstall)
  • click on the Next button.
  • a scan begins, please wait. Once done, click on the Next button.
  • now you should have a list of your installed programs, choose the one you want to remove, ie AVG 2012 and click on the Next button.
  • follow the last step and reboot if asked to do so.
If there was more than one version, please remove them all.

===================================================

Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

===================================================

Run Security Check

Download Security Check by screen317 from here or here.
  • save it to your Desktop.
  • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • a Notepad document should open automatically called checkup.txt; please post the contents of that document.
Logs to include with the next post:

Mbam.txt
Checkup.txt


Please copy and paste them into the post, not attach them. Thanks.

Assuming that AVG is now uninstalled, can you tell me if there is any improvement and if there are any oustanding problems.

Satchfan
hello satchfan, and thank you again for helping.

i tried unistalling avg again from the control panel and it worked. i did this befor i saw the progam you suggested. i ran it anyway and it didn't find avg. so i think it's gone now.

here are the log files

Results of screen317's Security Check version 0.99.42
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Norton Internet Security
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.61.0.1400
CCleaner
JavaFX 2.1.0
Java™ 7 Update 4
Java version out of Date!
Adobe Flash Player 10 Flash Player out of Date!
Adobe Flash Player 11.2.202.233
Adobe Reader 8 Adobe Reader out of Date!
Mozilla Firefox (4.0.1)
Google Chrome 19.0.1084.52
Google Chrome 19.0.1084.56
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0 %
````````````````````End of Log``````````````````````





here is the Mbam report


Malwarebytes Anti-Malware (Trial) 1.61.0.1400
www.malwarebytes.org

Database version: v2012.06.18.07

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
user1 :: USER1-PC [administrator]

Protection: Enabled

18/06/2012 2:24:06 PM
mbam-log-2012-06-18 (14-24-06).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 207526
Time elapsed: 6 minute(s), 42 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)




also i forgot to mention that the orignial virius report flagged a flie that jureg.exe (java6.31). after reading online i found that it was an old copy of java that was suscpect to infection. then i downloaded a the newest version and deleted the old one with file assassin tool in Mbam and then when i used aswmbr it no longer found the file.


also i am curious about what you said that DDS found. you mentioned that it found some nasties… did combofix fix them?… and if so, what were they?, so i can be on the look out for suspicious behaivour from my computer as i think a second computer on the network is infected as well. I ran aswmbr on it and came up with the same file flagged. but for now i will just focus on the original computer and its problems..


Thank you very much.
Hi

Most of the bad entries appear to have gone but I’d like another scan to check

First, let’s empty your temporary files.

Download TFC to your desktop
  • close any open windows.
  • double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • click the Start button to begin the process.
  • allow TFC to run uninterrupted.
  • the program should not take long to finish it's job
  • once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
=======================================

I noticed that you had run TDSSKiller. Can you send the previous results. The old TDSSKiller report can be found in your root directory, (usually C:\ folder) and will reflect the date that it was run

Please also run DDS again and send a new log.

Thanks

satchfan
hello satchfan. I downloaded TFC.exe and tried to run it twice, both times with antivirus software turned off and both times when i clicked start it immediately went to the blue screen of death… here is the log file from tdsskiler 13:39:53.0062 2400 TDSS rootkit removing tool [removed] May 21 2012 16:40:16 13:39:55.0065 2400 ============================================================ 13:39:55.0065 2400 Current date / time: 2012/06/10 13:39:55.0065 13:39:55.0065 2400 SystemInfo: 13:39:55.0065 2400 13:39:55.0065 2400 OS Version: 6.0.6002 ServicePack: 2.0 13:39:55.0065 2400 Product type: Workstation 13:39:55.0066 2400 ComputerName: USER1-PC 13:39:55.0066 2400 UserName: user1 13:39:55.0066 2400 Windows directory: C:\Windows 13:39:55.0066 2400 System windows directory: C:\Windows 13:39:55.0066 2400 Processor architecture: Intel x86 13:39:55.0066 2400 Number of processors: 2 13:39:55.0066 2400 Page size: 0x1000 13:39:55.0066 2400 Boot type: Normal boot 13:39:55.0066 2400 ============================================================ 13:39:57.0429 2400 Drive \Device\Harddisk0\DR0 - Size: 0x2E93E36000 (186.31 Gb), SectorSize: 0x200, Cylinders: 0x5F01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 13:39:57.0460 2400 ============================================================ 13:39:57.0460 2400 \Device\Harddisk0\DR0: 13:39:57.0476 2400 MBR partitions: 13:39:57.0476 2400 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x163E6CFF 13:39:57.0476 2400 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x163E6D3E, BlocksNum 0x10B7083 13:39:57.0476 2400 ============================================================ 13:39:57.0507 2400 C: <-> \Device\Harddisk0\DR0\Partition0 13:39:57.0554 2400 D: <-> \Device\Harddisk0\DR0\Partition1 13:39:57.0554 2400 ============================================================ 13:39:57.0554 2400 Initialize success 13:39:57.0554 2400 ============================================================ 13:40:07.0446 4048 ============================================================ 13:40:07.0446 4048 Scan started 13:40:07.0446 4048 Mode: Manual; 13:40:07.0446 4048 ============================================================ 13:40:10.0088 4048 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 13:40:10.0111 4048 ACPI - ok 13:40:10.0173 4048 adfs (6d7f09cd92a9fef3a8efce66231fdd79) C:\Windows\system32\drivers\adfs.sys 13:40:10.0207 4048 adfs - ok 13:40:10.0363 4048 AdobeFlashPlayerUpdateSvc (459ac130c6ab892b1cd5d7544626efc5) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 13:40:10.0368 4048 AdobeFlashPlayerUpdateSvc - ok 13:40:10.0472 4048 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys 13:40:10.0483 4048 adp94xx - ok 13:40:10.0539 4048 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys 13:40:10.0547 4048 adpahci - ok 13:40:10.0571 4048 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys 13:40:10.0575 4048 adpu160m - ok 13:40:10.0598 4048 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys 13:40:10.0603 4048 adpu320 - ok 13:40:10.0928 4048 AeLookupSvc (9d1fda9e086ba64e3c93c9de32461bcf) C:\Windows\System32\aelupsvc.dll 13:40:10.0930 4048 AeLookupSvc - ok 13:40:11.0041 4048 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys 13:40:11.0088 4048 AFD - ok 13:40:11.0151 4048 agp440 (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys 13:40:11.0151 4048 agp440 - ok 13:40:11.0213 4048 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 13:40:11.0213 4048 aic78xx - ok 13:40:11.0589 4048 Akamai (c775d704feb2b600a5bf7b0b088546af) c:\program files\common files\akamai/netsession_win_80c2ffa.dll 13:40:11.0589 4048 Suspicious file (Hidden): c:\program files\common files\akamai/netsession_win_80c2ffa.dll. md5: c775d704feb2b600a5bf7b0b088546af 13:40:11.0596 4048 Akamai ( HiddenFile.Multi.Generic ) - warning 13:40:11.0596 4048 Akamai - detected HiddenFile.Multi.Generic (1) 13:40:11.0749 4048 ALG (a1545b731579895d8cc44fc0481c1192) C:\Windows\System32\alg.exe 13:40:11.0751 4048 ALG - ok 13:40:11.0805 4048 aliide (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys 13:40:11.0807 4048 aliide - ok 13:40:11.0854 4048 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys 13:40:11.0856 4048 amdagp - ok 13:40:11.0861 4048 amdide (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys 13:40:11.0863 4048 amdide - ok 13:40:11.0904 4048 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys 13:40:11.0931 4048 AmdK7 - ok 13:40:11.0966 4048 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys 13:40:12.0018 4048 AmdK8 - ok 13:40:12.0115 4048 Appinfo (c6d704c7f0434dc791aac37cac4b6e14) C:\Windows\System32\appinfo.dll 13:40:12.0116 4048 Appinfo - ok 13:40:12.0153 4048 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys 13:40:12.0156 4048 arc - ok 13:40:12.0178 4048 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys 13:40:12.0181 4048 arcsas - ok 13:40:12.0302 4048 ASBroker (2eeda27c19259c2340324ef7180d086b) c:\Program Files\Bioscrypt\VeriSoft\Bin\ASWLNPkg.dll 13:40:12.0305 4048 ASBroker - ok 13:40:12.0421 4048 ASChannel (bb3c0521ecca4bb17ac55eb640df0fa5) c:\Program Files\Bioscrypt\VeriSoft\Bin\AsChnl.dll 13:40:12.0425 4048 ASChannel - ok 13:40:12.0498 4048 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 13:40:12.0550 4048 AsyncMac - ok 13:40:12.0591 4048 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 13:40:12.0593 4048 atapi - ok 13:40:12.0626 4048 ATSWPDRV (fb2162aff83d519cd77431a1bc5ee0ed) C:\Windows\system32\DRIVERS\ATSwpDrv.sys 13:40:12.0630 4048 ATSWPDRV - ok 13:40:12.0742 4048 AudioEndpointBuilder (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll 13:40:12.0750 4048 AudioEndpointBuilder - ok 13:40:12.0755 4048 Audiosrv (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll 13:40:12.0758 4048 Audiosrv - ok 13:40:13.0265 4048 AVGIDSAgent (ba60fd7a64b9759a14c0fba4a9ed4c7b) C:\Program Files\AVG\AVG2012\avgidsagent.exe 13:40:13.0296 4048 AVGIDSAgent - ok 13:40:13.0460 4048 AVGIDSDriver (1074f787080068c71303b61fae7e7ca4) C:\Windows\system32\DRIVERS\avgidsdriverx.sys 13:40:13.0464 4048 AVGIDSDriver - ok 13:40:13.0486 4048 AVGIDSFilter (61a7e0b02f82cff3db2445bbe50b3589) C:\Windows\system32\DRIVERS\avgidsfilterx.sys 13:40:13.0511 4048 AVGIDSFilter - ok 13:40:13.0540 4048 AVGIDSHX (d63d83659eedf60b3a3e620281a888e5) C:\Windows\system32\DRIVERS\avgidshx.sys 13:40:13.0542 4048 AVGIDSHX - ok 13:40:13.0550 4048 AVGIDSShim (baf975b72062f53d327788e99d64197e) C:\Windows\system32\DRIVERS\avgidsshimx.sys 13:40:13.0552 4048 AVGIDSShim - ok 13:40:13.0581 4048 Avgldx86 (dda6a2a18841e4c9172bb85958b8d948) C:\Windows\system32\DRIVERS\avgldx86.sys 13:40:13.0587 4048 Avgldx86 - ok 13:40:13.0607 4048 Avgmfx86 (ccdd61545aaea265977e4b1efdc74e8c) C:\Windows\system32\DRIVERS\avgmfx86.sys 13:40:13.0610 4048 Avgmfx86 - ok 13:40:13.0679 4048 Avgrkx86 (1fd90b28d2c3100bf4500199c8ad6358) C:\Windows\system32\DRIVERS\avgrkx86.sys 13:40:13.0681 4048 Avgrkx86 - ok 13:40:13.0722 4048 Avgtdix (1263f2554ace925c237a40b4c568d815) C:\Windows\system32\DRIVERS\avgtdix.sys 13:40:13.0730 4048 Avgtdix - ok 13:40:13.0852 4048 avgwd (ea1145debcd508fd25bd1e95c4346929) C:\Program Files\AVG\AVG2012\avgwdsvc.exe 13:40:13.0854 4048 avgwd - ok 13:40:13.0950 4048 BCM43XV (cf6a67c90951e3e763d2135dede44b85) C:\Windows\system32\DRIVERS\bcmwl6.sys 13:40:13.0988 4048 BCM43XV - ok 13:40:14.0071 4048 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 13:40:14.0074 4048 Beep - ok 13:40:14.0170 4048 BFE (c789af0f724fda5852fb9a7d3a432381) C:\Windows\System32\bfe.dll 13:40:14.0177 4048 BFE - ok 13:40:14.0435 4048 BHDrvx86 (a503d32ae26f77cb942aed530112edaa) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20120531.001\BHDrvx86.sys 13:40:14.0452 4048 BHDrvx86 - ok 13:40:14.0581 4048 BITS (93952506c6d67330367f7e7934b6a02f) C:\Windows\System32\qmgr.dll 13:40:14.0598 4048 BITS - ok 13:40:14.0633 4048 blbdrive - ok 13:40:14.0689 4048 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys 13:40:14.0722 4048 bowser - ok 13:40:14.0787 4048 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 13:40:14.0790 4048 BrFiltLo - ok 13:40:14.0808 4048 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 13:40:14.0811 4048 BrFiltUp - ok 13:40:14.0872 4048 Browser (a3629a0c4226f9e9c72faaeebc3ad33c) C:\Windows\System32\browser.dll 13:40:14.0875 4048 Browser - ok 13:40:14.0912 4048 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 13:40:14.0916 4048 Brserid - ok 13:40:14.0935 4048 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 13:40:14.0995 4048 BrSerWdm - ok 13:40:15.0021 4048 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 13:40:15.0023 4048 BrUsbMdm - ok 13:40:15.0030 4048 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 13:40:15.0054 4048 BrUsbSer - ok 13:40:15.0086 4048 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 13:40:15.0089 4048 BTHMODEM - ok 13:40:15.0167 4048 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 13:40:15.0169 4048 cdfs - ok 13:40:15.0236 4048 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 13:40:15.0263 4048 cdrom - ok 13:40:15.0345 4048 CertPropSvc (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll 13:40:15.0347 4048 CertPropSvc - ok 13:40:15.0398 4048 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\DRIVERS\circlass.sys 13:40:15.0423 4048 circlass - ok 13:40:15.0639 4048 CLCapSvc (dbafc6734c054feef9087754bd80f847) C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe 13:40:15.0639 4048 CLCapSvc - ok 13:40:15.0717 4048 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 13:40:15.0717 4048 CLFS - ok 13:40:15.0811 4048 clr_optimization_v2.0.50727_32 (8ee772032e2fe80a924f3b8dd5082194) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 13:40:15.0811 4048 clr_optimization_v2.0.50727_32 - ok 13:40:15.0928 4048 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 13:40:15.0957 4048 clr_optimization_v4.0.30319_32 - ok 13:40:16.0003 4048 CLSched (e67f8f036fd882e4ab62501c0d45b536) C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe 13:40:16.0338 4048 CLSched - ok 13:40:16.0435 4048 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys 13:40:16.0455 4048 CmBatt - ok 13:40:16.0489 4048 cmdide (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys 13:40:16.0491 4048 cmdide - ok 13:40:16.0552 4048 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys 13:40:16.0554 4048 Compbatt - ok 13:40:16.0558 4048 COMSysApp - ok 13:40:16.0585 4048 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys 13:40:16.0587 4048 crcdisk - ok 13:40:16.0617 4048 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys 13:40:16.0637 4048 Crusoe - ok 13:40:16.0692 4048 CryptSvc (fb27772beaf8e1d28ccd825c09da939b) C:\Windows\system32\cryptsvc.dll 13:40:16.0694 4048 CryptSvc - ok 13:40:16.0798 4048 DcomLaunch (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll 13:40:16.0812 4048 DcomLaunch - ok 13:40:16.0873 4048 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys 13:40:16.0875 4048 DfsC - ok 13:40:16.0966 4048 Dhcp (9028559c132146fb75eb7acf384b086a) C:\Windows\System32\dhcpcsvc.dll 13:40:16.0971 4048 Dhcp - ok 13:40:17.0037 4048 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 13:40:17.0039 4048 disk - ok 13:40:17.0121 4048 Dnscache (57d762f6f5974af0da2be88a3349baaa) C:\Windows\System32\dnsrslvr.dll 13:40:17.0137 4048 Dnscache - ok 13:40:17.0199 4048 dot3svc (324fd74686b1ef5e7c19a8af49e748f6) C:\Windows\System32\dot3svc.dll 13:40:17.0199 4048 dot3svc - ok 13:40:17.0246 4048 DPS (a622e888f8aa2f6b49e9bc466f0e5def) C:\Windows\system32\dps.dll 13:40:17.0261 4048 DPS - ok 13:40:17.0324 4048 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 13:40:17.0355 4048 drmkaud - ok 13:40:17.0449 4048 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 13:40:17.0464 4048 DXGKrnl - ok 13:40:17.0527 4048 E100B (c0b00e55cf82d122d25983c7a6a53dea) C:\Windows\system32\DRIVERS\e100b325.sys 13:40:17.0558 4048 E100B - ok 13:40:17.0620 4048 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys 13:40:17.0637 4048 E1G60 - ok 13:40:17.0677 4048 eabfiltr (e88b0cfcecf745211bba87f44f85d0dd) C:\Windows\system32\DRIVERS\eabfiltr.sys 13:40:17.0711 4048 eabfiltr - ok 13:40:17.0767 4048 EapHost (c0b95e40d85cd807d614e264248a45b9) C:\Windows\System32\eapsvc.dll 13:40:17.0770 4048 EapHost - ok 13:40:17.0846 4048 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 13:40:17.0849 4048 Ecache - ok 13:40:18.0021 4048 eeCtrl (fce87ba643d5e9a8b6e0378508d1b22d) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 13:40:18.0052 4048 eeCtrl - ok 13:40:18.0158 4048 ehRecvr (9be3744d295a7701eb425332014f0797) C:\Windows\ehome\ehRecvr.exe 13:40:18.0166 4048 ehRecvr - ok 13:40:18.0199 4048 ehSched (ad1870c8e5d6dd340c829e6074bf3c3f) C:\Windows\ehome\ehsched.exe 13:40:18.0203 4048 ehSched - ok 13:40:18.0220 4048 ehstart (c27c4ee8926e74aa72efcab24c5242c3) C:\Windows\ehome\ehstart.dll 13:40:18.0221 4048 ehstart - ok 13:40:18.0291 4048 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys 13:40:18.0299 4048 elxstor - ok 13:40:18.0378 4048 EMDMgmt (4e6b23dfc917ea39306b529b773950f4) C:\Windows\system32\emdmgmt.dll 13:40:18.0391 4048 EMDMgmt - ok 13:40:18.0555 4048 EraserUtilRebootDrv (115dc729465a8c386615207f28875255) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 13:40:18.0559 4048 EraserUtilRebootDrv - ok 13:40:18.0659 4048 EventSystem (67058c46504bc12d821f38cf99b7b28f) C:\Windows\system32\es.dll 13:40:18.0659 4048 EventSystem - ok 13:40:18.0784 4048 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 13:40:18.0799 4048 exfat - ok 13:40:18.0846 4048 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 13:40:18.0846 4048 fastfat - ok 13:40:18.0940 4048 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys 13:40:18.0971 4048 fdc - ok 13:40:19.0018 4048 fdPHost (6629b5f0e98151f4afdd87567ea32ba3) C:\Windows\system32\fdPHost.dll 13:40:19.0018 4048 fdPHost - ok 13:40:19.0049 4048 FDResPub (89ed56dce8e47af40892778a5bd31fd2) C:\Windows\system32\fdrespub.dll 13:40:19.0049 4048 FDResPub - ok 13:40:19.0174 4048 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 13:40:19.0174 4048 FileInfo - ok 13:40:19.0198 4048 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 13:40:19.0217 4048 Filetrace - ok 13:40:19.0320 4048 FLEXnet Licensing Service (1f63900e2eb00101b9aca2b7a870704e) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 13:40:19.0357 4048 FLEXnet Licensing Service - ok 13:40:19.0396 4048 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys 13:40:19.0398 4048 flpydisk - ok 13:40:19.0471 4048 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 13:40:19.0476 4048 FltMgr - ok 13:40:19.0649 4048 FontCache (8ce364388c8eca59b14b539179276d44) C:\Windows\system32\FntCache.dll 13:40:19.0666 4048 FontCache - ok 13:40:19.0777 4048 FontCache3.0.0.0 (c7fbdd1ed42f82bfa35167a5c9803ea3) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 13:40:19.0781 4048 FontCache3.0.0.0 - ok 13:40:19.0897 4048 FreeAgentGoNext Service (07af7870abf051ebbae8a8a92ff34abe) C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe 13:40:19.0900 4048 FreeAgentGoNext Service - ok 13:40:19.0982 4048 Fs_Rec (b972a66758577e0bfd1de0f91aaa27b5) C:\Windows\system32\drivers\Fs_Rec.sys 13:40:20.0028 4048 Fs_Rec - ok 13:40:20.0076 4048 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys 13:40:20.0078 4048 gagp30kx - ok 13:40:20.0130 4048 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 13:40:20.0132 4048 GEARAspiWDM - ok 13:40:20.0275 4048 gpsvc (cd5d0aeee35dfd4e986a5aa1500a6e66) C:\Windows\System32\gpsvc.dll 13:40:20.0275 4048 gpsvc - ok 13:40:20.0337 4048 HBtnKey (93aee3434935fc2f805fefd8dc5ed1b4) C:\Windows\system32\DRIVERS\cpqbttn.sys 13:40:20.0337 4048 HBtnKey - ok 13:40:20.0556 4048 HCW85BDA (206a4ef7c882c3f9676139065d57245c) C:\Windows\system32\drivers\HCW85BDA.sys 13:40:20.0618 4048 HCW85BDA - ok 13:40:20.0793 4048 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys 13:40:20.0800 4048 HdAudAddService - ok 13:40:20.0884 4048 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 13:40:20.0926 4048 HDAudBus - ok 13:40:20.0964 4048 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 13:40:20.0966 4048 HidBth - ok 13:40:21.0012 4048 HidIr (d8df3722d5e961baa1292aa2f12827e2) C:\Windows\system32\DRIVERS\hidir.sys 13:40:21.0015 4048 HidIr - ok 13:40:21.0065 4048 hidserv (84067081f3318162797385e11a8f0582) C:\Windows\system32\hidserv.dll 13:40:21.0067 4048 hidserv - ok 13:40:21.0109 4048 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 13:40:21.0111 4048 HidUsb - ok 13:40:21.0177 4048 hkmsvc (d8ad255b37da92434c26e4876db7d418) C:\Windows\system32\kmsvc.dll 13:40:21.0181 4048 hkmsvc - ok 13:40:21.0308 4048 HP Health Check Service (a19b0bb5a7eb6df2dd4a0711d36955ee) c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe 13:40:21.0310 4048 HP Health Check Service - ok 13:40:21.0362 4048 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys 13:40:21.0364 4048 HpCISSs - ok 13:40:21.0433 4048 hpqwmiex (04c1dcbb226c6ae647b794833ce3ceb6) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe 13:40:21.0435 4048 hpqwmiex - ok 13:40:21.0502 4048 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS 13:40:21.0559 4048 HSFHWAZL - ok 13:40:21.0697 4048 HSF_DPV (ec36f1d542ed4252390d446bf6d4dfd0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS 13:40:21.0797 4048 HSF_DPV - ok 13:40:21.0875 4048 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 13:40:21.0922 4048 HTTP - ok 13:40:21.0985 4048 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys 13:40:21.0985 4048 i2omp - ok 13:40:22.0078 4048 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 13:40:22.0078 4048 i8042prt - ok 13:40:22.0203 4048 IAANTMON (582f2d900a3ac34c98fbdc2c0abef6b9) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe 13:40:22.0219 4048 IAANTMON - ok 13:40:22.0452 4048 ialm (496db78e6a0c4c44023d9a92b4a7ac31) C:\Windows\system32\DRIVERS\igdkmd32.sys 13:40:22.0480 4048 ialm - ok 13:40:22.0657 4048 iaStor (fd7f9d74c2b35dbda400804a3f5ed5d8) C:\Windows\system32\DRIVERS\iaStor.sys 13:40:22.0660 4048 iaStor - ok 13:40:22.0711 4048 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys 13:40:22.0717 4048 iaStorV - ok 13:40:22.0833 4048 IDriverT (6f95324909b502e2651442c1548ab12f) C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe 13:40:23.0051 4048 IDriverT - ok 13:40:23.0276 4048 idsvc (98477b08e61945f974ed9fdc4cb6bdab) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 13:40:23.0320 4048 idsvc - ok 13:40:23.0554 4048 IDSVix86 (f9069ce7a7b9f9ba75d009b0ce3d7601) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20120608.001\IDSvix86.sys 13:40:23.0569 4048 IDSVix86 - ok 13:40:23.0710 4048 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 13:40:23.0710 4048 iirsp - ok 13:40:23.0788 4048 IKEEXT (9908d8a397b76cd8d31d0d383c5773c9) C:\Windows\System32\ikeext.dll 13:40:23.0788 4048 IKEEXT - ok 13:40:24.0035 4048 IntcAzAudAddService (1f10ed6f98c57efb4e7fb9972b2dbb71) C:\Windows\system32\drivers\RTKVHDA.sys 13:40:24.0294 4048 IntcAzAudAddService - ok 13:40:24.0514 4048 intelide (97469037714070e45194ed318d636401) C:\Windows\system32\drivers\intelide.sys 13:40:24.0516 4048 intelide - ok 13:40:24.0586 4048 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 13:40:24.0589 4048 intelppm - ok 13:40:24.0644 4048 IPBusEnum (9ac218c6e6105477484c6fdbe7d409a4) C:\Windows\system32\ipbusenum.dll 13:40:24.0648 4048 IPBusEnum - ok 13:40:24.0710 4048 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 13:40:24.0713 4048 IpFilterDriver - ok 13:40:24.0783 4048 iphlpsvc (1998bd97f950680bb55f55a7244679c2) C:\Windows\System32\iphlpsvc.dll 13:40:24.0789 4048 iphlpsvc - ok 13:40:24.0793 4048 IpInIp - ok 13:40:24.0837 4048 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys 13:40:24.0840 4048 IPMIDRV - ok 13:40:24.0922 4048 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 13:40:24.0922 4048 IPNAT - ok 13:40:24.0953 4048 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 13:40:24.0969 4048 IRENUM - ok 13:40:25.0016 4048 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys 13:40:25.0016 4048 isapnp - ok 13:40:25.0109 4048 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 13:40:25.0109 4048 iScsiPrt - ok 13:40:25.0141 4048 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 13:40:25.0141 4048 iteatapi - ok 13:40:25.0203 4048 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 13:40:25.0203 4048 iteraid - ok 13:40:25.0281 4048 JSMWS - ok 13:40:25.0343 4048 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 13:40:25.0343 4048 kbdclass - ok 13:40:25.0390 4048 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 13:40:25.0390 4048 kbdhid - ok 13:40:25.0407 4048 KeyIso (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe 13:40:25.0422 4048 KeyIso - ok 13:40:25.0490 4048 KSecDD (2b2f1638466e8cb091400c9019cc730e) C:\Windows\system32\Drivers\ksecdd.sys 13:40:25.0510 4048 KSecDD - ok 13:40:25.0597 4048 KtmRm (8078f8f8f7a79e2e6b494523a828c585) C:\Windows\system32\msdtckrm.dll 13:40:25.0605 4048 KtmRm - ok 13:40:25.0666 4048 LanmanServer (1bf5eebfd518dd7298434d8c862f825d) C:\Windows\system32\srvsvc.dll 13:40:25.0671 4048 LanmanServer - ok 13:40:25.0737 4048 LanmanWorkstation (1db69705b695b987082c8baec0c6b34f) C:\Windows\System32\wkssvc.dll 13:40:25.0743 4048 LanmanWorkstation - ok 13:40:25.0831 4048 LightScribeService (559c9b7800fac92fc515cd0003d7c631) C:\Program Files\Common Files\LightScribe\LSSrvc.exe 13:40:25.0833 4048 LightScribeService - ok 13:40:25.0918 4048 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 13:40:25.0951 4048 lltdio - ok 13:40:25.0996 4048 lltdsvc (2d5a428872f1442631d0959a34abff63) C:\Windows\System32\lltdsvc.dll 13:40:26.0037 4048 lltdsvc - ok 13:40:26.0074 4048 lmhosts (35d40113e4a5b961b6ce5c5857702518) C:\Windows\System32\lmhsvc.dll 13:40:26.0076 4048 lmhosts - ok 13:40:26.0115 4048 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys 13:40:26.0118 4048 LSI_FC - ok 13:40:26.0139 4048 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys 13:40:26.0142 4048 LSI_SAS - ok 13:40:26.0200 4048 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys 13:40:26.0203 4048 LSI_SCSI - ok 13:40:26.0259 4048 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 13:40:26.0286 4048 luafv - ok 13:40:26.0363 4048 LVPr2Mon (c57c48fb9ae3efb9848af594e3123a63) C:\Windows\system32\DRIVERS\LVPr2Mon.sys 13:40:26.0366 4048 LVPr2Mon - ok 13:40:26.0509 4048 LVPrcSrv (5c7b88695ce461d8bda4fe0c0e57e71d) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe 13:40:26.0511 4048 LVPrcSrv - ok 13:40:26.0573 4048 MBAMProtector (fb097bbc1a18f044bd17bd2fccf97865) C:\Windows\system32\drivers\mbam.sys 13:40:26.0597 4048 MBAMProtector - ok 13:40:26.0792 4048 MBAMService (ba400ed640bca1eae5c727ae17c10207) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 13:40:26.0808 4048 MBAMService - ok 13:40:26.0917 4048 McComponentHostService (f453d1e6d881e8f8717e20ccd4199e85) C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe 13:40:26.0917 4048 McComponentHostService - ok 13:40:26.0933 4048 MCSTRM - ok 13:40:26.0964 4048 Mcx2Svc (aef9babb8a506bc4ce0451a64aaded46) C:\Windows\system32\Mcx2Svc.dll 13:40:26.0969 4048 Mcx2Svc - ok 13:40:27.0027 4048 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys 13:40:27.0029 4048 megasas - ok 13:40:27.0083 4048 MMCSS (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll 13:40:27.0085 4048 MMCSS - ok 13:40:27.0133 4048 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 13:40:27.0136 4048 Modem - ok 13:40:27.0200 4048 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 13:40:27.0216 4048 monitor - ok 13:40:27.0260 4048 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 13:40:27.0262 4048 mouclass - ok 13:40:27.0286 4048 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 13:40:27.0288 4048 mouhid - ok 13:40:27.0361 4048 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 13:40:27.0364 4048 MountMgr - ok 13:40:27.0400 4048 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys 13:40:27.0403 4048 mpio - ok 13:40:27.0463 4048 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 13:40:27.0518 4048 mpsdrv - ok 13:40:27.0613 4048 MpsSvc (5de62c6e9108f14f6794060a9bdecaec) C:\Windows\system32\mpssvc.dll 13:40:27.0623 4048 MpsSvc - ok 13:40:27.0677 4048 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 13:40:27.0680 4048 Mraid35x - ok 13:40:27.0727 4048 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 13:40:27.0744 4048 MRxDAV - ok 13:40:27.0790 4048 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys 13:40:27.0888 4048 mrxsmb - ok 13:40:27.0971 4048 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys 13:40:28.0002 4048 mrxsmb10 - ok 13:40:28.0034 4048 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 13:40:28.0049 4048 mrxsmb20 - ok 13:40:28.0080 4048 msahci (742aed7939e734c36b7e8d6228ce26b7) C:\Windows\system32\drivers\msahci.sys 13:40:28.0080 4048 msahci - ok 13:40:28.0112 4048 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys 13:40:28.0127 4048 msdsm - ok 13:40:28.0174 4048 MSDTC (fd7520cc3a80c5fc8c48852bb24c6ded) C:\Windows\System32\msdtc.exe 13:40:28.0190 4048 MSDTC - ok 13:40:28.0252 4048 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 13:40:28.0252 4048 Msfs - ok 13:40:28.0299 4048 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 13:40:28.0299 4048 msisadrv - ok 13:40:28.0361 4048 MSiSCSI (85466c0757a23d9a9aecdc0755203cb2) C:\Windows\system32\iscsiexe.dll 13:40:28.0361 4048 MSiSCSI - ok 13:40:28.0361 4048 msiserver - ok 13:40:28.0439 4048 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 13:40:28.0487 4048 MSKSSRV - ok 13:40:28.0509 4048 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 13:40:28.0531 4048 MSPCLOCK - ok 13:40:28.0569 4048 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 13:40:28.0604 4048 MSPQM - ok 13:40:28.0660 4048 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 13:40:28.0665 4048 MsRPC - ok 13:40:28.0722 4048 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 13:40:28.0725 4048 mssmbios - ok 13:40:28.0739 4048 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 13:40:28.0741 4048 MSTEE - ok 13:40:28.0798 4048 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 13:40:28.0800 4048 Mup - ok 13:40:28.0878 4048 napagent (e4eaf0c5c1b41b5c83386cf212ca9584) C:\Windows\system32\qagentRT.dll 13:40:28.0882 4048 napagent - ok 13:40:28.0960 4048 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 13:40:28.0989 4048 NativeWifiP - ok 13:40:29.0228 4048 NAVENG (f11033730b38260b6892e837c457fb4b) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20120609.016\NAVENG.SYS 13:40:29.0229 4048 NAVENG - ok 13:40:29.0438 4048 NAVEX15 (4e4e7c0259d3bb97de24a636c0e06aba) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20120609.016\NAVEX15.SYS 13:40:29.0450 4048 NAVEX15 - ok 13:40:29.0665 4048 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 13:40:29.0681 4048 NDIS - ok 13:40:29.0743 4048 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 13:40:29.0743 4048 NdisTapi - ok 13:40:29.0774 4048 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 13:40:29.0774 4048 Ndisuio - ok 13:40:29.0806 4048 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 13:40:29.0806 4048 NdisWan - ok 13:40:29.0868 4048 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 13:40:29.0884 4048 NDProxy - ok 13:40:29.0899 4048 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 13:40:29.0946 4048 NetBIOS - ok 13:40:30.0008 4048 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 13:40:30.0040 4048 netbt - ok 13:40:30.0060 4048 Netlogon (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe 13:40:30.0062 4048 Netlogon - ok 13:40:30.0134 4048 Netman (c8052711daecc48b982434c5116ca401) C:\Windows\System32\netman.dll 13:40:30.0142 4048 Netman - ok 13:40:30.0207 4048 netprofm (2ef3bbe22e5a5acd1428ee387a0d0172) C:\Windows\System32\netprofm.dll 13:40:30.0213 4048 netprofm - ok 13:40:30.0345 4048 NetTcpPortSharing (d6c4e4a39a36029ac0813d476fbd0248) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 13:40:30.0349 4048 NetTcpPortSharing - ok 13:40:30.0569 4048 NETw4v32 (1d73499a6664b4da05d750ff83fdb274) C:\Windows\system32\DRIVERS\NETw4v32.sys 13:40:30.0695 4048 NETw4v32 - ok 13:40:30.0854 4048 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 13:40:30.0856 4048 nfrd960 - ok 13:40:31.0023 4048 NIS (e78a365cc3e0fbfc018a33dce01909f8) C:\Program Files\Norton Internet Security\Engine\18.7.1.3\ccSvcHst.exe 13:40:31.0024 4048 NIS - ok 13:40:31.0111 4048 NlaSvc (2997b15415f9bbe05b5a4c1c85e0c6a2) C:\Windows\System32\nlasvc.dll 13:40:31.0126 4048 NlaSvc - ok 13:40:31.0173 4048 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 13:40:31.0220 4048 Npfs - ok 13:40:31.0267 4048 nsi (8bb86f0c7eea2bded6fe095d0b4ca9bd) C:\Windows\system32\nsisvc.dll 13:40:31.0267 4048 nsi - ok 13:40:31.0345 4048 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 13:40:31.0345 4048 nsiproxy - ok 13:40:31.0501 4048 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 13:40:31.0532 4048 Ntfs - ok 13:40:31.0579 4048 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 13:40:31.0579 4048 ntrigdigi - ok 13:40:31.0621 4048 NuidFltr (cf7e041663119e09d2e118521ada9300) C:\Windows\system32\DRIVERS\NuidFltr.sys 13:40:31.0624 4048 NuidFltr - ok 13:40:31.0685 4048 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 13:40:31.0687 4048 Null - ok 13:40:32.0533 4048 nvlddmkm (24000b817cc84ac1555f41929879af5a) C:\Windows\system32\DRIVERS\nvlddmkm.sys 13:40:32.0915 4048 nvlddmkm - ok 13:40:33.0150 4048 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys 13:40:33.0150 4048 nvraid - ok 13:40:33.0163 4048 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys 13:40:33.0166 4048 nvstor - ok 13:40:33.0231 4048 nvsvc (c4d17f11526f87bc762f31da5bd2580b) C:\Windows\system32\nvvsvc.exe 13:40:33.0234 4048 nvsvc - ok 13:40:33.0264 4048 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys 13:40:33.0269 4048 nv_agp - ok 13:40:33.0273 4048 NwlnkFlt - ok 13:40:33.0279 4048 NwlnkFwd - ok 13:40:33.0446 4048 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 13:40:33.0456 4048 odserv - ok 13:40:33.0527 4048 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys 13:40:33.0530 4048 ohci1394 - ok 13:40:33.0587 4048 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 13:40:33.0591 4048 ose - ok 13:40:33.0728 4048 p2pimsvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll 13:40:33.0743 4048 p2pimsvc - ok 13:40:33.0751 4048 p2psvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll 13:40:33.0756 4048 p2psvc - ok 13:40:33.0798 4048 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 13:40:33.0832 4048 Parport - ok 13:40:33.0883 4048 partmgr (b9c2b89f08670e159f7181891e449cd9) C:\Windows\system32\drivers\partmgr.sys 13:40:33.0886 4048 partmgr - ok 13:40:33.0912 4048 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 13:40:34.0009 4048 Parvdm - ok 13:40:34.0063 4048 PcaSvc (c6276ad11f4bb49b58aa1ed88537f14a) C:\Windows\System32\pcasvc.dll 13:40:34.0066 4048 PcaSvc - ok 13:40:34.0131 4048 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 13:40:34.0136 4048 pci - ok 13:40:34.0188 4048 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\DRIVERS\pciide.sys 13:40:34.0188 4048 pciide - ok 13:40:34.0219 4048 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 13:40:34.0219 4048 pcmcia - ok 13:40:34.0359 4048 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 13:40:34.0390 4048 PEAUTH - ok 13:40:34.0656 4048 PID_PEPI (dd184d9adfe2a8a21741dbdfe9e22f5c) C:\Windows\system32\DRIVERS\LV302V32.SYS 13:40:34.0702 4048 PID_PEPI - ok 13:40:34.0927 4048 pla (b1689df169143f57053f795390c99db3) C:\Windows\system32\pla.dll 13:40:34.0962 4048 pla - ok 13:40:35.0066 4048 PlugPlay (c5e7f8a996ec0a82d508fd9064a5569e) C:\Windows\system32\umpnpmgr.dll 13:40:35.0073 4048 PlugPlay - ok 13:40:35.0213 4048 PNRPAutoReg (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll 13:40:35.0219 4048 PNRPAutoReg - ok 13:40:35.0227 4048 PNRPsvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll 13:40:35.0234 4048 PNRPsvc - ok 13:40:35.0296 4048 PolicyAgent (d0494460421a03cd5225cca0059aa146) C:\Windows\System32\ipsecsvc.dll 13:40:35.0305 4048 PolicyAgent - ok 13:40:35.0391 4048 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 13:40:35.0394 4048 PptpMiniport - ok 13:40:35.0432 4048 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys 13:40:35.0434 4048 Processor - ok 13:40:35.0496 4048 ProfSvc (0508faa222d28835310b7bfca7a77346) C:\Windows\system32\profsvc.dll 13:40:35.0502 4048 ProfSvc - ok 13:40:35.0559 4048 ProtectedStorage (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe 13:40:35.0561 4048 ProtectedStorage - ok 13:40:35.0629 4048 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 13:40:35.0631 4048 PSched - ok 13:40:35.0662 4048 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\Windows\system32\Drivers\PxHelp20.sys 13:40:35.0665 4048 PxHelp20 - ok 13:40:35.0805 4048 QCDonner (b1ad87b4c97b6b59fcd075001e76865f) C:\Windows\system32\DRIVERS\LVCD.sys 13:40:35.0867 4048 QCDonner - ok 13:40:35.0992 4048 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys 13:40:36.0023 4048 ql2300 - ok 13:40:36.0101 4048 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 13:40:36.0101 4048 ql40xx - ok 13:40:36.0179 4048 QMY - ok 13:40:36.0257 4048 QWAVE (e9ecae663f47e6cb43962d18ab18890f) C:\Windows\system32\qwave.dll 13:40:36.0257 4048 QWAVE - ok 13:40:36.0303 4048 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 13:40:36.0305 4048 QWAVEdrv - ok 13:40:36.0353 4048 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 13:40:36.0356 4048 RasAcd - ok 13:40:36.0417 4048 RasAuto (f6a452eb4ceadbb51c9e0ee6b3ecef0f) C:\Windows\System32\rasauto.dll 13:40:36.0422 4048 RasAuto - ok 13:40:36.0499 4048 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 13:40:36.0503 4048 Rasl2tp - ok 13:40:36.0637 4048 RasMan (75d47445d70ca6f9f894b032fbc64fcf) C:\Windows\System32\rasmans.dll 13:40:36.0644 4048 RasMan - ok 13:40:36.0699 4048 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 13:40:36.0701 4048 RasPppoe - ok 13:40:36.0764 4048 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 13:40:36.0767 4048 RasSstp - ok 13:40:36.0830 4048 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 13:40:36.0837 4048 rdbss - ok 13:40:36.0887 4048 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 13:40:36.0889 4048 RDPCDD - ok 13:40:36.0949 4048 rdpdr (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys 13:40:36.0961 4048 rdpdr - ok 13:40:36.0966 4048 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 13:40:36.0968 4048 RDPENCDD - ok 13:40:37.0048 4048 RDPWD (79c6df8477250f5c54f7c5ae1d6b814e) C:\Windows\system32\drivers\RDPWD.sys 13:40:37.0181 4048 RDPWD - ok 13:40:37.0280 4048 RemoteAccess (bcdd6b4804d06b1f7ebf29e53a57ece9) C:\Windows\System32\mprdim.dll 13:40:37.0296 4048 RemoteAccess - ok 13:40:37.0343 4048 RemoteRegistry (9e6894ea18daff37b63e1005f83ae4ab) C:\Windows\system32\regsvc.dll 13:40:37.0343 4048 RemoteRegistry - ok 13:40:37.0405 4048 rimmptsk (355aac141b214bef1dbc1483afd9bd50) C:\Windows\system32\DRIVERS\rimmptsk.sys 13:40:37.0405 4048 rimmptsk - ok 13:40:37.0452 4048 rimsptsk (a4216c71dd4f60b26418ccfd99cd0815) C:\Windows\system32\DRIVERS\rimsptsk.sys 13:40:37.0452 4048 rimsptsk - ok 13:40:37.0483 4048 rismxdp (c663af77e2f4eabf8eb08b388d2f1f36) C:\Windows\system32\DRIVERS\rixdptsk.sys 13:40:37.0483 4048 rismxdp - ok 13:40:37.0686 4048 RoxMediaDB9 (08fb7d968805001c7adcbb14b0651fa2) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe 13:40:37.0840 4048 RoxMediaDB9 - ok 13:40:37.0872 4048 RpcLocator (5123f83cbc4349d065534eeb6bbdc42b) C:\Windows\system32\locator.exe 13:40:37.0874 4048 RpcLocator - ok 13:40:37.0981 4048 RpcSs (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll 13:40:37.0986 4048 RpcSs - ok 13:40:38.0114 4048 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 13:40:38.0143 4048 rspndr - ok 13:40:38.0219 4048 RTL8169 (71b7026d61293c1e91145bdad11c53bf) C:\Windows\system32\DRIVERS\Rtlh86.sys 13:40:38.0223 4048 RTL8169 - ok 13:40:38.0252 4048 SamSs (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe 13:40:38.0254 4048 SamSs - ok 13:40:38.0314 4048 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 13:40:38.0318 4048 sbp2port - ok 13:40:38.0393 4048 SCardSvr (77b7a11a0c3d78d3386398fbbea1b632) C:\Windows\System32\SCardSvr.dll 13:40:38.0398 4048 SCardSvr - ok 13:40:38.0517 4048 Schedule (1a58069db21d05eb2ab58ee5753ebe8d) C:\Windows\system32\schedsvc.dll 13:40:38.0529 4048 Schedule - ok 13:40:38.0574 4048 SCPolicySvc (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll 13:40:38.0575 4048 SCPolicySvc - ok 13:40:38.0635 4048 sdbus (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys 13:40:38.0639 4048 sdbus - ok 13:40:38.0699 4048 SDRSVC (716313d9f6b0529d03f726d5aaf6f191) C:\Windows\System32\SDRSVC.dll 13:40:38.0704 4048 SDRSVC - ok 13:40:38.0719 4048 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 13:40:38.0721 4048 secdrv - ok 13:40:38.0775 4048 seclogon (fd5199d4d8a521005e4b5ee7fe00fa9b) C:\Windows\system32\seclogon.dll 13:40:38.0778 4048 seclogon - ok 13:40:38.0789 4048 SENS (a9bbab5759771e523f55563d6cbe140f) C:\Windows\System32\sens.dll 13:40:38.0794 4048 SENS - ok 13:40:38.0865 4048 SeratoUsb (5e28961c1c26c01f2d9c9256aa194e85) C:\Windows\system32\Drivers\SeratoUsb.sys 13:40:39.0021 4048 SeratoUsb - ok 13:40:39.0052 4048 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 13:40:39.0052 4048 Serenum - ok 13:40:39.0099 4048 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 13:40:39.0130 4048 Serial - ok 13:40:39.0177 4048 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 13:40:39.0177 4048 sermouse - ok 13:40:39.0255 4048 SessionEnv (d2193326f729b163125610dbf3e17d57) C:\Windows\system32\sessenv.dll 13:40:39.0255 4048 SessionEnv - ok 13:40:39.0317 4048 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys 13:40:39.0333 4048 sffdisk - ok 13:40:39.0349 4048 sffp_mmc (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys 13:40:39.0349 4048 sffp_mmc - ok 13:40:39.0366 4048 sffp_sd (9f66a46c55d6f1ccabc79bb7afccc545) C:\Windows\system32\DRIVERS\sffp_sd.sys 13:40:39.0370 4048 sffp_sd - ok 13:40:39.0394 4048 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 13:40:39.0421 4048 sfloppy - ok 13:40:39.0484 4048 SharedAccess (e1499bd0ff76b1b2fbbf1af339d91165) C:\Windows\System32\ipnathlp.dll 13:40:39.0491 4048 SharedAccess - ok 13:40:39.0562 4048 ShellHWDetection (c7230fbee14437716701c15be02c27b8) C:\Windows\System32\shsvcs.dll 13:40:39.0568 4048 ShellHWDetection - ok 13:40:39.0612 4048 sisagp (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys 13:40:39.0614 4048 sisagp - ok 13:40:39.0645 4048 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys 13:40:39.0648 4048 SiSRaid2 - ok 13:40:39.0675 4048 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys 13:40:39.0678 4048 SiSRaid4 - ok 13:40:39.0971 4048 slsvc (862bb4cbc05d80c5b45be430e5ef872f) C:\Windows\system32\SLsvc.exe 13:40:40.0040 4048 slsvc - ok 13:40:40.0227 4048 SLUINotify (6edc422215cd78aa8a9cde6b30abbd35) C:\Windows\system32\SLUINotify.dll 13:40:40.0231 4048 SLUINotify - ok 13:40:40.0304 4048 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 13:40:40.0308 4048 Smb - ok 13:40:40.0419 4048 smserial (3850aba97b31094f93bcbe94d6abbe22) C:\Windows\system32\DRIVERS\smserial.sys 13:40:40.0465 4048 smserial - ok 13:40:40.0530 4048 SNMPTRAP (2a146a055b4401c16ee62d18b8e2a032) C:\Windows\System32\snmptrap.exe 13:40:40.0533 4048 SNMPTRAP - ok 13:40:40.0590 4048 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 13:40:40.0593 4048 spldr - ok 13:40:40.0646 4048 Spooler (8554097e5136c3bf9f69fe578a1b35f4) C:\Windows\System32\spoolsv.exe 13:40:40.0651 4048 Spooler - ok 13:40:40.0769 4048 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys 13:40:40.0769 4048 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505 13:40:40.0785 4048 sptd ( LockedFile.Multi.Generic ) - warning 13:40:40.0785 4048 sptd - detected LockedFile.Multi.Generic (1) 13:40:40.0902 4048 SRTSP (83726cf02eced69138948083e06b6eac) C:\Windows\System32\Drivers\NIS\1207010.003\SRTSP.SYS 13:40:40.0915 4048 SRTSP - ok 13:40:40.0937 4048 SRTSPX (4e7eab2e5615d39cf1f1df9c71e5e225) C:\Windows\system32\drivers\NIS\1207010.003\SRTSPX.SYS 13:40:40.0940 4048 SRTSPX - ok 13:40:41.0013 4048 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys 13:40:41.0021 4048 srv - ok 13:40:41.0107 4048 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys 13:40:41.0112 4048 srv2 - ok 13:40:41.0140 4048 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys 13:40:41.0144 4048 srvnet - ok 13:40:41.0200 4048 SSDPSRV (03d50b37234967433a5ea5ba72bc0b62) C:\Windows\System32\ssdpsrv.dll 13:40:41.0206 4048 SSDPSRV - ok 13:40:41.0285 4048 SstpSvc (6f1a32e7b7b30f004d9a20afadb14944) C:\Windows\system32\sstpsvc.dll 13:40:41.0289 4048 SstpSvc - ok 13:40:41.0392 4048 stisvc (5de7d67e49b88f5f07f3e53c4b92a352) C:\Windows\System32\wiaservc.dll 13:40:41.0403 4048 stisvc - ok 13:40:41.0511 4048 stllssvr (a9a23c8af361f7a93fd632e91a8c346f) C:\Program Files\Common Files\SureThing Shared\stllssvr.exe 13:40:41.0515 4048 stllssvr - ok 13:40:41.0581 4048 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 13:40:41.0584 4048 swenum - ok 13:40:41.0667 4048 swprv (f21fd248040681cca1fb6c9a03aaa93d) C:\Windows\System32\swprv.dll 13:40:41.0676 4048 swprv - ok 13:40:41.0719 4048 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 13:40:41.0721 4048 Symc8xx - ok 13:40:41.0918 4048 SymDS (9bbeb8c6258e72d62e7560e6667aad39) C:\Windows\system32\drivers\NIS\1207010.003\SYMDS.SYS 13:40:41.0918 4048 SymDS - ok 13:40:42.0012 4048 SymEFA (d5c02629c02a820a7e71bca3d44294a3) C:\Windows\system32\drivers\NIS\1207010.003\SYMEFA.SYS 13:40:42.0027 4048 SymEFA - ok 13:40:42.0152 4048 SymEvent (ab33c3b196197ca467cbdda717860dba) C:\Windows\system32\Drivers\SYMEVENT.SYS 13:40:42.0152 4048 SymEvent - ok 13:40:42.0230 4048 SymIM (8d49cdbb93c3e58e1bfc39fb29444c0a) C:\Windows\system32\DRIVERS\SymIMv.sys 13:40:42.0230 4048 SymIM - ok 13:40:42.0261 4048 SymIRON (a73399804d5d4a8b20ba60fcf70c9f1f) C:\Windows\system32\drivers\NIS\1207010.003\Ironx86.SYS 13:40:42.0261 4048 SymIRON - ok 13:40:42.0355 4048 SYMTDIv (d42a7229e333af725f1445f785e4658d) C:\Windows\System32\Drivers\NIS\1207010.003\SYMTDIV.SYS 13:40:42.0355 4048 SYMTDIv - ok 13:40:42.0402 4048 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 13:40:42.0417 4048 Sym_hi - ok 13:40:42.0448 4048 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 13:40:42.0448 4048 Sym_u3 - ok 13:40:42.0503 4048 SynTP (8327106d1c93e9a7b98e63b9fcc24bb7) C:\Windows\system32\DRIVERS\SynTP.sys 13:40:42.0510 4048 SynTP - ok 13:40:42.0600 4048 SysMain (9a51b04e9886aa4ee90093586b0ba88d) C:\Windows\system32\sysmain.dll 13:40:42.0611 4048 SysMain - ok 13:40:42.0650 4048 TabletInputService (2dca225eae15f42c0933e998ee0231c3) C:\Windows\System32\TabSvc.dll 13:40:42.0654 4048 TabletInputService - ok 13:40:42.0725 4048 TapiSrv (d7673e4b38ce21ee54c59eeeb65e2483) C:\Windows\System32\tapisrv.dll 13:40:42.0733 4048 TapiSrv - ok 13:40:42.0790 4048 TBS (cb05822cd9cc6c688168e113c603dbe7) C:\Windows\System32\tbssvc.dll 13:40:42.0794 4048 TBS - ok 13:40:42.0898 4048 Tcpip (27d470dabc77bc60d0a3b0e4deb6cb91) C:\Windows\system32\drivers\tcpip.sys 13:40:42.0918 4048 Tcpip - ok 13:40:42.0930 4048 Tcpip6 (27d470dabc77bc60d0a3b0e4deb6cb91) C:\Windows\system32\DRIVERS\tcpip.sys 13:40:42.0938 4048 Tcpip6 - ok 13:40:43.0016 4048 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys 13:40:43.0046 4048 tcpipreg - ok 13:40:43.0093 4048 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 13:40:43.0126 4048 TDPIPE - ok 13:40:43.0149 4048 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 13:40:43.0152 4048 TDTCP - ok 13:40:43.0266 4048 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 13:40:43.0270 4048 tdx - ok 13:40:43.0331 4048 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 13:40:43.0333 4048 TermDD - ok 13:40:43.0421 4048 TermService (bb95da09bef6e7a131bff3ba5032090d) C:\Windows\System32\termsrv.dll 13:40:43.0433 4048 TermService - ok 13:40:43.0490 4048 Themes (c7230fbee14437716701c15be02c27b8) C:\Windows\system32\shsvcs.dll 13:40:43.0493 4048 Themes - ok 13:40:43.0540 4048 THREADORDER (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll 13:40:43.0543 4048 THREADORDER - ok 13:40:43.0568 4048 TrkWks (ec74e77d0eb004bd3a809b5f8fb8c2ce) C:\Windows\System32\trkwks.dll 13:40:43.0573 4048 TrkWks - ok 13:40:43.0629 4048 TrustedInstaller (97d9d6a04e3ad9b6c626b9931db78dba) C:\Windows\servicing\TrustedInstaller.exe 13:40:43.0630 4048 TrustedInstaller - ok 13:40:43.0669 4048 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 13:40:43.0671 4048 tssecsrv - ok 13:40:43.0772 4048 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 13:40:43.0788 4048 tunmp - ok 13:40:43.0819 4048 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 13:40:43.0866 4048 tunnel - ok 13:40:43.0913 4048 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys 13:40:43.0928 4048 uagp35 - ok 13:40:43.0991 4048 UCXIU - ok 13:40:44.0101 4048 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 13:40:44.0107 4048 udfs - ok 13:40:44.0167 4048 UI0Detect (ecef404f62863755951e09c802c94ad5) C:\Windows\system32\UI0Detect.exe 13:40:44.0170 4048 UI0Detect - ok 13:40:44.0207 4048 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys 13:40:44.0209 4048 uliagpkx - ok 13:40:44.0247 4048 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys 13:40:44.0253 4048 uliahci - ok 13:40:44.0281 4048 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 13:40:44.0285 4048 UlSata - ok 13:40:44.0329 4048 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 13:40:44.0333 4048 ulsata2 - ok 13:40:44.0388 4048 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 13:40:44.0414 4048 umbus - ok 13:40:44.0470 4048 upnphost (68308183f4ae0be7bf8ecd07cb297999) C:\Windows\System32\upnphost.dll 13:40:44.0478 4048 upnphost - ok 13:40:44.0559 4048 usbaudio (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys 13:40:44.0562 4048 usbaudio - ok 13:40:44.0672 4048 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 13:40:44.0675 4048 usbccgp - ok 13:40:44.0713 4048 usbcir (47b9770ea21436de4ad5aea7926e0900) C:\Windows\system32\DRIVERS\usbcir.sys 13:40:44.0726 4048 usbcir - ok 13:40:44.0784 4048 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 13:40:44.0787 4048 usbehci - ok 13:40:44.0850 4048 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 13:40:44.0856 4048 usbhub - ok 13:40:44.0895 4048 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 13:40:44.0898 4048 usbohci - ok 13:40:44.0949 4048 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 13:40:44.0951 4048 usbprint - ok 13:40:45.0108 4048 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys 13:40:45.0124 4048 usbscan - ok 13:40:45.0155 4048 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 13:40:45.0171 4048 USBSTOR - ok 13:40:45.0218 4048 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 13:40:45.0218 4048 usbuhci - ok 13:40:45.0296 4048 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys 13:40:45.0311 4048 usbvideo - ok 13:40:45.0358 4048 UxSms (1509e705f3ac1d474c92454a5c2dd81f) C:\Windows\System32\uxsms.dll 13:40:45.0358 4048 UxSms - ok 13:40:45.0467 4048 vds (cd88d1b7776dc17a119049742ec07eb4) C:\Windows\System32\vds.exe 13:40:45.0483 4048 vds - ok 13:40:45.0545 4048 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys 13:40:45.0557 4048 vga - ok 13:40:45.0606 4048 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 13:40:45.0609 4048 VgaSave - ok 13:40:45.0645 4048 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys 13:40:45.0648 4048 viaagp - ok 13:40:45.0673 4048 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys 13:40:45.0675 4048 ViaC7 - ok 13:40:45.0701 4048 viaide (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys 13:40:45.0703 4048 viaide - ok 13:40:45.0759 4048 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 13:40:45.0762 4048 volmgr - ok 13:40:45.0825 4048 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 13:40:45.0833 4048 volmgrx - ok 13:40:45.0905 4048 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 13:40:45.0911 4048 volsnap - ok 13:40:45.0953 4048 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys 13:40:45.0957 4048 vsmraid - ok 13:40:46.0170 4048 VSS (db3d19f850c6eb32bdcb9bc0836acddb) C:\Windows\system32\vssvc.exe 13:40:46.0194 4048 VSS - ok 13:40:46.0418 4048 vToolbarUpdater11.1.0 (5fa45791413acce628d5361458f32dde) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe 13:40:46.0433 4048 vToolbarUpdater11.1.0 - ok 13:40:46.0636 4048 W32Time (96ea68b9eb310a69c25ebb0282b2b9de) C:\Windows\system32\w32time.dll 13:40:46.0645 4048 W32Time - ok 13:40:46.0707 4048 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 13:40:46.0728 4048 WacomPen - ok 13:40:46.0795 4048 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 13:40:46.0810 4048 Wanarp - ok 13:40:46.0810 4048 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 13:40:46.0810 4048 Wanarpv6 - ok 13:40:46.0857 4048 wcncsvc (a3cd60fd826381b49f03832590e069af) C:\Windows\System32\wcncsvc.dll 13:40:46.0857 4048 wcncsvc - ok 13:40:46.0919 4048 WcsPlugInService (11bcb7afcdd7aadacb5746f544d3a9c7) C:\Windows\System32\WcsPlugInService.dll 13:40:46.0919 4048 WcsPlugInService - ok 13:40:46.0935 4048 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys 13:40:46.0951 4048 Wd - ok 13:40:46.0997 4048 WDC_SAM (d6efaf429fd30c5df613d220e344cce7) C:\Windows\system32\DRIVERS\wdcsam.sys 13:40:46.0997 4048 WDC_SAM - ok 13:40:47.0100 4048 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 13:40:47.0112 4048 Wdf01000 - ok 13:40:47.0176 4048 WdiServiceHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll 13:40:47.0180 4048 WdiServiceHost - ok 13:40:47.0184 4048 WdiSystemHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll 13:40:47.0187 4048 WdiSystemHost - ok 13:40:47.0255 4048 WebClient (04c37d8107320312fbae09926103d5e2) C:\Windows\System32\webclnt.dll 13:40:47.0262 4048 WebClient - ok 13:40:47.0326 4048 Wecsvc (ae3736e7e8892241c23e4ebbb7453b60) C:\Windows\system32\wecsvc.dll 13:40:47.0332 4048 Wecsvc - ok 13:40:47.0372 4048 wercplsupport (670ff720071ed741206d69bd995ea453) C:\Windows\System32\wercplsupport.dll 13:40:47.0376 4048 wercplsupport - ok 13:40:47.0428 4048 WerSvc (32b88481d3b326da6deb07b1d03481e7) C:\Windows\System32\WerSvc.dll 13:40:47.0433 4048 WerSvc - ok 13:40:47.0582 4048 winachsf (5c7bdcf5864db00323fe2d90fa26a8a2) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS 13:40:47.0596 4048 winachsf - ok 13:40:47.0744 4048 WinDefend (4575aa12561c5648483403541d0d7f2b) C:\Program Files\Windows Defender\mpsvc.dll 13:40:47.0777 4048 WinDefend - ok 13:40:47.0785 4048 WinHttpAutoProxySvc - ok 13:40:47.0893 4048 Winmgmt (6b2a1d0e80110e3d04e6863c6e62fd8a) C:\Windows\system32\wbem\WMIsvc.dll 13:40:47.0894 4048 Winmgmt - ok 13:40:48.0199 4048 WinRM (7cfe68bdc065e55aa5e8421607037511) C:\Windows\system32\WsmSvc.dll 13:40:48.0227 4048 WinRM - ok 13:40:48.0345 4048 Wlansvc (c008405e4feeb069e30da1d823910234) C:\Windows\System32\wlansvc.dll 13:40:48.0359 4048 Wlansvc - ok 13:40:48.0460 4048 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys 13:40:48.0462 4048 WmiAcpi - ok 13:40:48.0593 4048 wmiApSrv (43be3875207dcb62a85c8c49970b66cc) C:\Windows\system32\wbem\WmiApSrv.exe 13:40:48.0596 4048 wmiApSrv - ok 13:40:48.0877 4048 WMPNetworkSvc (3978704576a121a9204f8cc49a301a9b) C:\Program Files\Windows Media Player\wmpnetwk.exe 13:40:48.0896 4048 WMPNetworkSvc - ok 13:40:48.0941 4048 WPCSvc (cfc5a04558f5070cee3e3a7809f3ff52) C:\Windows\System32\wpcsvc.dll 13:40:48.0947 4048 WPCSvc - ok 13:40:49.0006 4048 WPDBusEnum (801fbdb89d472b3c467eb112a0fc9246) C:\Windows\system32\wpdbusenum.dll 13:40:49.0011 4048 WPDBusEnum - ok 13:40:49.0132 4048 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys 13:40:49.0135 4048 WpdUsb - ok 13:40:49.0438 4048 WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 13:40:49.0454 4048 WPFFontCache_v0400 - ok 13:40:49.0532 4048 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 13:40:49.0535 4048 ws2ifsl - ok 13:40:49.0578 4048 wscsvc (1ca6c40261ddc0425987980d0cd2aaab) C:\Windows\System32\wscsvc.dll 13:40:49.0582 4048 wscsvc - ok 13:40:49.0588 4048 WSearch - ok 13:40:49.0782 4048 wuauserv (6298277b73c77fa99106b271a7525163) C:\Windows\system32\wuaueng.dll 13:40:49.0798 4048 wuauserv - ok 13:40:49.0972 4048 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 13:40:50.0003 4048 WUDFRd - ok 13:40:50.0097 4048 wudfsvc (575a4190d989f64732119e4114045a4f) C:\Windows\System32\WUDFSvc.dll 13:40:50.0097 4048 wudfsvc - ok 13:40:50.0202 4048 ZNT - ok 13:40:50.0241 4048 MBR (0x1B8) (ab2261d98ab453077a8fc300866b802f) \Device\Harddisk0\DR0 13:40:50.0504 4048 \Device\Harddisk0\DR0 - ok 13:40:50.0508 4048 Boot (0x1200) (6edb2abb308240b8dcd628be83d2bc30) \Device\Harddisk0\DR0\Partition0 13:40:50.0509 4048 \Device\Harddisk0\DR0\Partition0 - ok 13:40:50.0525 4048 Boot (0x1200) (2bafbc1c313ec492cc5904f6d4d8ad1c) \Device\Harddisk0\DR0\Partition1 13:40:50.0527 4048 \Device\Harddisk0\DR0\Partition1 - ok 13:40:50.0527 4048 ============================================================ 13:40:50.0527 4048 Scan finished 13:40:50.0527 4048 ============================================================ 13:40:50.0538 3524 Detected object count: 2 13:40:50.0538 3524 Actual detected object count: 2 13:42:02.0268 3524 c:\program files\common files\akamai/netsession_win_80c2ffa.dll - copied to quarantine 13:42:02.0270 3524 Akamai ( HiddenFile.Multi.Generic ) - User select action: Quarantine 13:42:02.0270 3524 sptd ( LockedFile.Multi.Generic ) - skipped by user 13:42:02.0270 3524 sptd ( LockedFile.Multi.Generic ) - User select action: Skip 13:42:17.0393 4308 ============================================================ 13:42:17.0393 4308 Scan started 13:42:17.0393 4308 Mode: Manual; SigCheck; TDLFS; 13:42:17.0393 4308 ============================================================ 13:42:17.0968 4308 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 13:42:18.0127 4308 ACPI - ok 13:42:18.0158 4308 adfs (6d7f09cd92a9fef3a8efce66231fdd79) C:\Windows\system32\drivers\adfs.sys 13:42:18.0189 4308 adfs - ok 13:42:18.0283 4308 AdobeFlashPlayerUpdateSvc (459ac130c6ab892b1cd5d7544626efc5) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 13:42:18.0299 4308 AdobeFlashPlayerUpdateSvc - ok 13:42:18.0345 4308 adp94xx (2edc5bbac6c651ece337bde8ed97c9fb) C:\Windows\system32\drivers\adp94xx.sys 13:42:18.0361 4308 adp94xx - ok 13:42:18.0470 4308 adpahci (b84088ca3cdca97da44a984c6ce1ccad) C:\Windows\system32\drivers\adpahci.sys 13:42:18.0486 4308 adpahci - ok 13:42:18.0548 4308 adpu160m (7880c67bccc27c86fd05aa2afb5ea469) C:\Windows\system32\drivers\adpu160m.sys 13:42:18.0564 4308 adpu160m - ok 13:42:18.0595 4308 adpu320 (9ae713f8e30efc2abccd84904333df4d) C:\Windows\system32\drivers\adpu320.sys 13:42:18.0596 4308 adpu320 - ok 13:42:18.0631 4308 AeLookupSvc (9d1fda9e086ba64e3c93c9de32461bcf) C:\Windows\System32\aelupsvc.dll 13:42:18.0980 4308 AeLookupSvc - ok 13:42:19.0038 4308 AFD (3911b972b55fea0478476b2e777b29fa) C:\Windows\system32\drivers\afd.sys 13:42:19.0131 4308 AFD - ok 13:42:19.0171 4308 agp440 (ef23439cdd587f64c2c1b8825cead7d8) C:\Windows\system32\drivers\agp440.sys 13:42:19.0188 4308 agp440 - ok 13:42:19.0233 4308 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 13:42:19.0249 4308 aic78xx - ok 13:42:19.0743 4308 Akamai (c775d704feb2b600a5bf7b0b088546af) c:\program files\common files\akamai/netsession_win_80c2ffa.dll 13:42:19.0743 4308 Suspicious file (Hidden): c:\program files\common files\akamai/netsession_win_80c2ffa.dll. md5: c775d704feb2b600a5bf7b0b088546af 13:42:19.0759 4308 Akamai ( HiddenFile.Multi.Generic ) - warning 13:42:19.0759 4308 Akamai - detected HiddenFile.Multi.Generic (1) 13:42:19.0915 4308 ALG (a1545b731579895d8cc44fc0481c1192) C:\Windows\System32\alg.exe 13:42:19.0961 4308 ALG - ok 13:42:20.0008 4308 aliide (90395b64600ebb4552e26e178c94b2e4) C:\Windows\system32\drivers\aliide.sys 13:42:20.0024 4308 aliide - ok 13:42:20.0071 4308 amdagp (2b13e304c9dfdfa5eb582f6a149fa2c7) C:\Windows\system32\drivers\amdagp.sys 13:42:20.0086 4308 amdagp - ok 13:42:20.0086 4308 amdide (0577df1d323fe75a739c787893d300ea) C:\Windows\system32\drivers\amdide.sys 13:42:20.0102 4308 amdide - ok 13:42:20.0133 4308 AmdK7 (dc487885bcef9f28eece6fac0e5ddfc5) C:\Windows\system32\drivers\amdk7.sys 13:42:20.0357 4308 AmdK7 - ok 13:42:20.0441 4308 AmdK8 (0ca0071da4315b00fc1328ca86b425da) C:\Windows\system32\drivers\amdk8.sys 13:42:20.0495 4308 AmdK8 - ok 13:42:20.0546 4308 Appinfo (c6d704c7f0434dc791aac37cac4b6e14) C:\Windows\System32\appinfo.dll 13:42:20.0647 4308 Appinfo - ok 13:42:20.0699 4308 arc (5f673180268bb1fdb69c99b6619fe379) C:\Windows\system32\drivers\arc.sys 13:42:20.0715 4308 arc - ok 13:42:20.0738 4308 arcsas (957f7540b5e7f602e44648c7de5a1c05) C:\Windows\system32\drivers\arcsas.sys 13:42:20.0754 4308 arcsas - ok 13:42:20.0848 4308 ASBroker (2eeda27c19259c2340324ef7180d086b) c:\Program Files\Bioscrypt\VeriSoft\Bin\ASWLNPkg.dll 13:42:20.0866 4308 ASBroker ( UnsignedFile.Multi.Generic ) - warning 13:42:20.0866 4308 ASBroker - detected UnsignedFile.Multi.Generic (1) 13:42:20.0913 4308 ASChannel (bb3c0521ecca4bb17ac55eb640df0fa5) c:\Program Files\Bioscrypt\VeriSoft\Bin\AsChnl.dll 13:42:20.0932 4308 ASChannel ( UnsignedFile.Multi.Generic ) - warning 13:42:20.0932 4308 ASChannel - detected UnsignedFile.Multi.Generic (1) 13:42:20.0986 4308 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 13:42:21.0052 4308 AsyncMac - ok 13:42:21.0108 4308 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 13:42:21.0125 4308 atapi - ok 13:42:21.0172 4308 ATSWPDRV (fb2162aff83d519cd77431a1bc5ee0ed) C:\Windows\system32\DRIVERS\ATSwpDrv.sys 13:42:21.0736 4308 ATSWPDRV - ok 13:42:21.0814 4308 AudioEndpointBuilder (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll 13:42:21.0853 4308 AudioEndpointBuilder - ok 13:42:21.0858 4308 Audiosrv (68e2a1a0407a66cf50da0300852424ab) C:\Windows\System32\Audiosrv.dll 13:42:21.0886 4308 Audiosrv - ok 13:42:22.0488 4308 AVGIDSAgent (ba60fd7a64b9759a14c0fba4a9ed4c7b) C:\Program Files\AVG\AVG2012\avgidsagent.exe 13:42:22.0640 4308 AVGIDSAgent - ok 13:42:22.0881 4308 AVGIDSDriver (1074f787080068c71303b61fae7e7ca4) C:\Windows\system32\DRIVERS\avgidsdriverx.sys 13:42:22.0897 4308 AVGIDSDriver - ok 13:42:22.0913 4308 AVGIDSFilter (61a7e0b02f82cff3db2445bbe50b3589) C:\Windows\system32\DRIVERS\avgidsfilterx.sys 13:42:22.0928 4308 AVGIDSFilter - ok 13:42:22.0928 4308 AVGIDSHX (d63d83659eedf60b3a3e620281a888e5) C:\Windows\system32\DRIVERS\avgidshx.sys 13:42:22.0944 4308 AVGIDSHX - ok 13:42:22.0959 4308 AVGIDSShim (baf975b72062f53d327788e99d64197e) C:\Windows\system32\DRIVERS\avgidsshimx.sys 13:42:22.0975 4308 AVGIDSShim - ok 13:42:23.0006 4308 Avgldx86 (dda6a2a18841e4c9172bb85958b8d948) C:\Windows\system32\DRIVERS\avgldx86.sys 13:42:23.0022 4308 Avgldx86 - ok 13:42:23.0037 4308 Avgmfx86 (ccdd61545aaea265977e4b1efdc74e8c) C:\Windows\system32\DRIVERS\avgmfx86.sys 13:42:23.0053 4308 Avgmfx86 - ok 13:42:23.0115 4308 Avgrkx86 (1fd90b28d2c3100bf4500199c8ad6358) C:\Windows\system32\DRIVERS\avgrkx86.sys 13:42:23.0131 4308 Avgrkx86 - ok 13:42:23.0178 4308 Avgtdix (1263f2554ace925c237a40b4c568d815) C:\Windows\system32\DRIVERS\avgtdix.sys 13:42:23.0193 4308 Avgtdix - ok 13:42:23.0284 4308 avgwd (ea1145debcd508fd25bd1e95c4346929) C:\Program Files\AVG\AVG2012\avgwdsvc.exe 13:42:23.0300 4308 avgwd - ok 13:42:23.0364 4308 BCM43XV (cf6a67c90951e3e763d2135dede44b85) C:\Windows\system32\DRIVERS\bcmwl6.sys 13:42:23.0472 4308 BCM43XV - ok 13:42:23.0530 4308 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 13:42:23.0575 4308 Beep - ok 13:42:23.0680 4308 BFE (c789af0f724fda5852fb9a7d3a432381) C:\Windows\System32\bfe.dll 13:42:23.0724 4308 BFE - ok 13:42:24.0008 4308 BHDrvx86 (a503d32ae26f77cb942aed530112edaa) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20120531.001\BHDrvx86.sys 13:42:24.0043 4308 BHDrvx86 - ok 13:42:24.0185 4308 BITS (93952506c6d67330367f7e7934b6a02f) C:\Windows\System32\qmgr.dll 13:42:24.0279 4308 BITS - ok 13:42:24.0310 4308 blbdrive - ok 13:42:24.0373 4308 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys 13:42:24.0482 4308 bowser - ok 13:42:24.0529 4308 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 13:42:24.0575 4308 BrFiltLo - ok 13:42:24.0591 4308 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 13:42:24.0638 4308 BrFiltUp - ok 13:42:24.0716 4308 Browser (a3629a0c4226f9e9c72faaeebc3ad33c) C:\Windows\System32\browser.dll 13:42:24.0853 4308 Browser - ok 13:42:24.0899 4308 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 13:42:24.0966 4308 Brserid - ok 13:42:24.0993 4308 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 13:42:25.0060 4308 BrSerWdm - ok 13:42:25.0093 4308 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 13:42:25.0172 4308 BrUsbMdm - ok 13:42:25.0203 4308 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 13:42:25.0265 4308 BrUsbSer - ok 13:42:25.0288 4308 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 13:42:25.0355 4308 BTHMODEM - ok 13:42:25.0416 4308 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 13:42:25.0486 4308 cdfs - ok 13:42:25.0566 4308 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 13:42:25.0629 4308 cdrom - ok 13:42:25.0675 4308 CertPropSvc (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll 13:42:25.0726 4308 CertPropSvc - ok 13:42:25.0750 4308 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\DRIVERS\circlass.sys 13:42:25.0801 4308 circlass - ok 13:42:26.0004 4308 CLCapSvc (dbafc6734c054feef9087754bd80f847) C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe 13:42:26.0004 4308 CLCapSvc ( UnsignedFile.Multi.Generic ) - warning 13:42:26.0004 4308 CLCapSvc - detected UnsignedFile.Multi.Generic (1) 13:42:26.0082 4308 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 13:42:26.0098 4308 CLFS - ok 13:42:26.0176 4308 clr_optimization_v2.0.50727_32 (8ee772032e2fe80a924f3b8dd5082194) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 13:42:26.0207 4308 clr_optimization_v2.0.50727_32 - ok 13:42:26.0316 4308 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 13:42:26.0332 4308 clr_optimization_v4.0.30319_32 - ok 13:42:26.0347 4308 CLSched (e67f8f036fd882e4ab62501c0d45b536) C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe 13:42:26.0364 4308 CLSched ( UnsignedFile.Multi.Generic ) - warning 13:42:26.0364 4308 CLSched - detected UnsignedFile.Multi.Generic (1) 13:42:26.0423 4308 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys 13:42:26.0538 4308 CmBatt - ok 13:42:26.0577 4308 cmdide (45201046c776ffdaf3fc8a0029c581c8) C:\Windows\system32\drivers\cmdide.sys 13:42:26.0592 4308 cmdide - ok 13:42:26.0611 4308 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys 13:42:26.0628 4308 Compbatt - ok 13:42:26.0631 4308 COMSysApp - ok 13:42:26.0640 4308 crcdisk (2a213ae086bbec5e937553c7d9a2b22c) C:\Windows\system32\drivers\crcdisk.sys 13:42:26.0656 4308 crcdisk - ok 13:42:26.0677 4308 Crusoe (22a7f883508176489f559ee745b5bf5d) C:\Windows\system32\drivers\crusoe.sys 13:42:26.0747 4308 Crusoe - ok 13:42:26.0808 4308 CryptSvc (fb27772beaf8e1d28ccd825c09da939b) C:\Windows\system32\cryptsvc.dll 13:42:26.0853 4308 CryptSvc - ok 13:42:26.0943 4308 DcomLaunch (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll 13:42:27.0025 4308 DcomLaunch - ok 13:42:27.0089 4308 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys 13:42:27.0147 4308 DfsC - ok 13:42:27.0197 4308 Dhcp (9028559c132146fb75eb7acf384b086a) C:\Windows\System32\dhcpcsvc.dll 13:42:27.0239 4308 Dhcp - ok 13:42:27.0296 4308 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 13:42:27.0314 4308 disk - ok 13:42:27.0418 4308 Dnscache (57d762f6f5974af0da2be88a3349baaa) C:\Windows\System32\dnsrslvr.dll 13:42:27.0512 4308 Dnscache - ok 13:42:27.0606 4308 dot3svc (324fd74686b1ef5e7c19a8af49e748f6) C:\Windows\System32\dot3svc.dll 13:42:27.0652 4308 dot3svc - ok 13:42:27.0699 4308 DPS (a622e888f8aa2f6b49e9bc466f0e5def) C:\Windows\system32\dps.dll 13:42:27.0746 4308 DPS - ok 13:42:27.0793 4308 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 13:42:27.0840 4308 drmkaud - ok 13:42:27.0919 4308 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 13:42:27.0961 4308 DXGKrnl - ok 13:42:28.0006 4308 E100B (c0b00e55cf82d122d25983c7a6a53dea) C:\Windows\system32\DRIVERS\e100b325.sys 13:42:28.0096 4308 E100B - ok 13:42:28.0126 4308 E1G60 (f88fb26547fd2ce6d0a5af2985892c48) C:\Windows\system32\DRIVERS\E1G60I32.sys 13:42:28.0224 4308 E1G60 - ok 13:42:28.0279 4308 eabfiltr (e88b0cfcecf745211bba87f44f85d0dd) C:\Windows\system32\DRIVERS\eabfiltr.sys 13:42:28.0329 4308 eabfiltr - ok 13:42:28.0384 4308 EapHost (c0b95e40d85cd807d614e264248a45b9) C:\Windows\System32\eapsvc.dll 13:42:28.0410 4308 EapHost - ok 13:42:28.0519 4308 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 13:42:28.0538 4308 Ecache - ok 13:42:28.0696 4308 eeCtrl (fce87ba643d5e9a8b6e0378508d1b22d) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 13:42:28.0718 4308 eeCtrl - ok 13:42:28.0847 4308 ehRecvr (9be3744d295a7701eb425332014f0797) C:\Windows\ehome\ehRecvr.exe 13:42:28.0906 4308 ehRecvr - ok 13:42:28.0972 4308 ehSched (ad1870c8e5d6dd340c829e6074bf3c3f) C:\Windows\ehome\ehsched.exe 13:42:29.0050 4308 ehSched - ok 13:42:29.0066 4308 ehstart (c27c4ee8926e74aa72efcab24c5242c3) C:\Windows\ehome\ehstart.dll 13:42:29.0112 4308 ehstart - ok 13:42:29.0175 4308 elxstor (e8f3f21a71720c84bcf423b80028359f) C:\Windows\system32\drivers\elxstor.sys 13:42:29.0190 4308 elxstor - ok 13:42:29.0378 4308 EMDMgmt (4e6b23dfc917ea39306b529b773950f4) C:\Windows\system32\emdmgmt.dll 13:42:29.0477 4308 EMDMgmt - ok 13:42:29.0699 4308 EraserUtilRebootDrv (115dc729465a8c386615207f28875255) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 13:42:29.0714 4308 EraserUtilRebootDrv - ok 13:42:29.0797 4308 EventSystem (67058c46504bc12d821f38cf99b7b28f) C:\Windows\system32\es.dll 13:42:29.0841 4308 EventSystem - ok 13:42:29.0938 4308 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 13:42:30.0023 4308 exfat - ok 13:42:30.0083 4308 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 13:42:30.0140 4308 fastfat - ok 13:42:30.0169 4308 fdc (63bdada84951b9c03e641800e176898a) C:\Windows\system32\DRIVERS\fdc.sys 13:42:30.0231 4308 fdc - ok 13:42:30.0279 4308 fdPHost (6629b5f0e98151f4afdd87567ea32ba3) C:\Windows\system32\fdPHost.dll 13:42:30.0308 4308 fdPHost - ok 13:42:30.0347 4308 FDResPub (89ed56dce8e47af40892778a5bd31fd2) C:\Windows\system32\fdrespub.dll 13:42:30.0418 4308 FDResPub - ok 13:42:30.0541 4308 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 13:42:30.0557 4308 FileInfo - ok 13:42:30.0588 4308 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 13:42:30.0650 4308 Filetrace - ok 13:42:30.0760 4308 FLEXnet Licensing Service (1f63900e2eb00101b9aca2b7a870704e) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 13:42:30.0791 4308 FLEXnet Licensing Service - ok 13:42:30.0853 4308 flpydisk (6603957eff5ec62d25075ea8ac27de68) C:\Windows\system32\DRIVERS\flpydisk.sys 13:42:30.0916 4308 flpydisk - ok 13:42:30.0978 4308 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 13:42:30.0994 4308 FltMgr - ok 13:42:31.0110 4308 FontCache (8ce364388c8eca59b14b539179276d44) C:\Windows\system32\FntCache.dll 13:42:31.0216 4308 FontCache - ok 13:42:31.0351 4308 FontCache3.0.0.0 (c7fbdd1ed42f82bfa35167a5c9803ea3) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 13:42:31.0368 4308 FontCache3.0.0.0 - ok 13:42:31.0500 4308 FreeAgentGoNext Service (07af7870abf051ebbae8a8a92ff34abe) C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe 13:42:31.0515 4308 FreeAgentGoNext Service - ok 13:42:31.0671 4308 Fs_Rec (b972a66758577e0bfd1de0f91aaa27b5) C:\Windows\system32\drivers\Fs_Rec.sys 13:42:31.0732 4308 Fs_Rec - ok 13:42:31.0777 4308 gagp30kx (4e1cd0a45c50a8882616cae5bf82f3c5) C:\Windows\system32\drivers\gagp30kx.sys 13:42:31.0795 4308 gagp30kx - ok 13:42:31.0861 4308 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 13:42:31.0875 4308 GEARAspiWDM - ok 13:42:31.0972 4308 gpsvc (cd5d0aeee35dfd4e986a5aa1500a6e66) C:\Windows\System32\gpsvc.dll 13:42:32.0031 4308 gpsvc - ok 13:42:32.0087 4308 HBtnKey (93aee3434935fc2f805fefd8dc5ed1b4) C:\Windows\system32\DRIVERS\cpqbttn.sys 13:42:32.0103 4308 HBtnKey - ok 13:42:32.0263 4308 HCW85BDA (206a4ef7c882c3f9676139065d57245c) C:\Windows\system32\drivers\HCW85BDA.sys 13:42:32.0413 4308 HCW85BDA - ok 13:42:32.0680 4308 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys 13:42:32.0799 4308 HdAudAddService - ok 13:42:32.0885 4308 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 13:42:32.0949 4308 HDAudBus - ok 13:42:32.0980 4308 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 13:42:33.0025 4308 HidBth - ok 13:42:33.0071 4308 HidIr (d8df3722d5e961baa1292aa2f12827e2) C:\Windows\system32\DRIVERS\hidir.sys 13:42:33.0112 4308 HidIr - ok 13:42:33.0167 4308 hidserv (84067081f3318162797385e11a8f0582) C:\Windows\system32\hidserv.dll 13:42:33.0233 4308 hidserv - ok 13:42:33.0268 4308 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 13:42:33.0312 4308 HidUsb - ok 13:42:33.0365 4308 hkmsvc (d8ad255b37da92434c26e4876db7d418) C:\Windows\system32\kmsvc.dll 13:42:33.0416 4308 hkmsvc - ok 13:42:33.0595 4308 HP Health Check Service (a19b0bb5a7eb6df2dd4a0711d36955ee) c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe 13:42:33.0602 4308 HP Health Check Service ( UnsignedFile.Multi.Generic ) - warning 13:42:33.0602 4308 HP Health Check Service - detected UnsignedFile.Multi.Generic (1) 13:42:33.0649 4308 HpCISSs (df353b401001246853763c4b7aaa6f50) C:\Windows\system32\drivers\hpcisss.sys 13:42:33.0665 4308 HpCISSs - ok 13:42:33.0735 4308 hpqwmiex (04c1dcbb226c6ae647b794833ce3ceb6) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe 13:42:33.0743 4308 hpqwmiex ( UnsignedFile.Multi.Generic ) - warning 13:42:33.0743 4308 hpqwmiex - detected UnsignedFile.Multi.Generic (1) 13:42:33.0790 4308 HSFHWAZL (46d67209550973257601a533e2ac5785) C:\Windows\system32\DRIVERS\VSTAZL3.SYS 13:42:33.0847 4308 HSFHWAZL - ok 13:42:33.0940 4308 HSF_DPV (ec36f1d542ed4252390d446bf6d4dfd0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS 13:42:34.0027 4308 HSF_DPV - ok 13:42:34.0092 4308 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 13:42:34.0184 4308 HTTP - ok 13:42:34.0246 4308 i2omp (324c2152ff2c61abae92d09f3cca4d63) C:\Windows\system32\drivers\i2omp.sys 13:42:34.0262 4308 i2omp - ok 13:42:34.0316 4308 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 13:42:34.0358 4308 i8042prt - ok 13:42:34.0549 4308 IAANTMON (582f2d900a3ac34c98fbdc2c0abef6b9) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe 13:42:34.0571 4308 IAANTMON - ok 13:42:34.0709 4308 ialm (496db78e6a0c4c44023d9a92b4a7ac31) C:\Windows\system32\DRIVERS\igdkmd32.sys 13:42:34.0785 4308 ialm - ok 13:42:34.0958 4308 iaStor (fd7f9d74c2b35dbda400804a3f5ed5d8) C:\Windows\system32\DRIVERS\iaStor.sys 13:42:34.0976 4308 iaStor - ok 13:42:35.0027 4308 iaStorV (c957bf4b5d80b46c5017bf0101e6c906) C:\Windows\system32\drivers\iastorv.sys 13:42:35.0045 4308 iaStorV - ok 13:42:35.0186 4308 IDriverT (6f95324909b502e2651442c1548ab12f) C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe 13:42:35.0218 4308 IDriverT ( UnsignedFile.Multi.Generic ) - warning 13:42:35.0218 4308 IDriverT - detected UnsignedFile.Multi.Generic (1) 13:42:35.0389 4308 idsvc (98477b08e61945f974ed9fdc4cb6bdab) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 13:42:35.0436 4308 idsvc - ok 13:42:35.0672 4308 IDSVix86 (f9069ce7a7b9f9ba75d009b0ce3d7601) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20120608.001\IDSvix86.sys 13:42:35.0697 4308 IDSVix86 - ok 13:42:36.0522 4308 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 13:42:36.0538 4308 iirsp - ok 13:42:36.0771 4308 IKEEXT (9908d8a397b76cd8d31d0d383c5773c9) C:\Windows\System32\ikeext.dll 13:42:36.0896 4308 IKEEXT - ok 13:42:39.0805 4308 IntcAzAudAddService (1f10ed6f98c57efb4e7fb9972b2dbb71) C:\Windows\system32\drivers\RTKVHDA.sys 13:42:39.0915 4308 IntcAzAudAddService - ok 13:42:41.0406 4308 intelide (97469037714070e45194ed318d636401) C:\Windows\system32\drivers\intelide.sys 13:42:41.0421 4308 intelide - ok 13:42:41.0593 4308 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 13:42:41.0655 4308 intelppm - ok 13:42:41.0827 4308 IPBusEnum (9ac218c6e6105477484c6fdbe7d409a4) C:\Windows\system32\ipbusenum.dll 13:42:41.0838 4308 IPBusEnum - ok 13:42:42.0013 4308 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 13:42:42.0077 4308 IpFilterDriver - ok 13:42:42.0343 4308 iphlpsvc (1998bd97f950680bb55f55a7244679c2) C:\Windows\System32\iphlpsvc.dll 13:42:42.0471 4308 iphlpsvc - ok 13:42:42.0475 4308 IpInIp - ok 13:42:42.0539 4308 IPMIDRV (40f34f8aba2a015d780e4b09138b6c17) C:\Windows\system32\drivers\ipmidrv.sys 13:42:42.0611 4308 IPMIDRV - ok 13:42:42.0667 4308 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 13:42:42.0716 4308 IPNAT - ok 13:42:42.0815 4308 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 13:42:42.0881 4308 IRENUM - ok 13:42:42.0928 4308 isapnp (350fca7e73cf65bcef43fae1e4e91293) C:\Windows\system32\drivers\isapnp.sys 13:42:42.0944 4308 isapnp - ok 13:42:43.0084 4308 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 13:42:43.0100 4308 iScsiPrt - ok 13:42:43.0131 4308 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 13:42:43.0147 4308 iteatapi - ok 13:42:43.0193 4308 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 13:42:43.0225 4308 iteraid - ok 13:42:43.0349 4308 JSMWS - ok 13:42:43.0452 4308 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 13:42:43.0480 4308 kbdclass - ok 13:42:43.0561 4308 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 13:42:43.0610 4308 kbdhid - ok 13:42:43.0707 4308 KeyIso (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe 13:42:43.0777 4308 KeyIso - ok 13:42:44.0106 4308 KSecDD (2b2f1638466e8cb091400c9019cc730e) C:\Windows\system32\Drivers\ksecdd.sys 13:42:44.0167 4308 KSecDD - ok 13:42:44.0281 4308 KtmRm (8078f8f8f7a79e2e6b494523a828c585) C:\Windows\system32\msdtckrm.dll 13:42:44.0323 4308 KtmRm - ok 13:42:44.0404 4308 LanmanServer (1bf5eebfd518dd7298434d8c862f825d) C:\Windows\system32\srvsvc.dll 13:42:44.0497 4308 LanmanServer - ok 13:42:44.0653 4308 LanmanWorkstation (1db69705b695b987082c8baec0c6b34f) C:\Windows\System32\wkssvc.dll 13:42:44.0747 4308 LanmanWorkstation - ok 13:42:44.0934 4308 LightScribeService (559c9b7800fac92fc515cd0003d7c631) C:\Program Files\Common Files\LightScribe\LSSrvc.exe 13:42:44.0934 4308 LightScribeService ( UnsignedFile.Multi.Generic ) - warning 13:42:44.0934 4308 LightScribeService - detected UnsignedFile.Multi.Generic (1) 13:42:45.0082 4308 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 13:42:45.0134 4308 lltdio - ok 13:42:45.0246 4308 lltdsvc (2d5a428872f1442631d0959a34abff63) C:\Windows\System32\lltdsvc.dll 13:42:45.0294 4308 lltdsvc - ok 13:42:45.0362 4308 lmhosts (35d40113e4a5b961b6ce5c5857702518) C:\Windows\System32\lmhsvc.dll 13:42:45.0423 4308 lmhosts - ok 13:42:45.0517 4308 LSI_FC (a2262fb9f28935e862b4db46438c80d2) C:\Windows\system32\drivers\lsi_fc.sys 13:42:45.0535 4308 LSI_FC - ok 13:42:45.0569 4308 LSI_SAS (30d73327d390f72a62f32c103daf1d6d) C:\Windows\system32\drivers\lsi_sas.sys 13:42:45.0611 4308 LSI_SAS - ok 13:42:45.0644 4308 LSI_SCSI (e1e36fefd45849a95f1ab81de0159fe3) C:\Windows\system32\drivers\lsi_scsi.sys 13:42:45.0688 4308 LSI_SCSI - ok 13:42:45.0747 4308 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 13:42:45.0800 4308 luafv - ok 13:42:45.0958 4308 LVPr2Mon (c57c48fb9ae3efb9848af594e3123a63) C:\Windows\system32\DRIVERS\LVPr2Mon.sys 13:42:45.0990 4308 LVPr2Mon - ok 13:42:46.0442 4308 LVPrcSrv (5c7b88695ce461d8bda4fe0c0e57e71d) C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe 13:42:46.0458 4308 LVPrcSrv - ok 13:42:46.0573 4308 MBAMProtector (fb097bbc1a18f044bd17bd2fccf97865) C:\Windows\system32\drivers\mbam.sys 13:42:46.0589 4308 MBAMProtector - ok 13:42:47.0027 4308 MBAMService (ba400ed640bca1eae5c727ae17c10207) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 13:42:47.0082 4308 MBAMService - ok 13:42:47.0193 4308 McComponentHostService (f453d1e6d881e8f8717e20ccd4199e85) C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe 13:42:47.0213 4308 McComponentHostService - ok 13:42:47.0217 4308 MCSTRM - ok 13:42:47.0267 4308 Mcx2Svc (aef9babb8a506bc4ce0451a64aaded46) C:\Windows\system32\Mcx2Svc.dll 13:42:47.0284 4308 Mcx2Svc - ok 13:42:47.0329 4308 megasas (d153b14fc6598eae8422a2037553adce) C:\Windows\system32\drivers\megasas.sys 13:42:47.0346 4308 megasas - ok 13:42:47.0371 4308 MMCSS (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll 13:42:47.0413 4308 MMCSS - ok 13:42:47.0479 4308 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 13:42:47.0543 4308 Modem - ok 13:42:47.0590 4308 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 13:42:47.0637 4308 monitor - ok 13:42:47.0668 4308 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 13:42:47.0684 4308 mouclass - ok 13:42:47.0715 4308 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 13:42:47.0746 4308 mouhid - ok 13:42:47.0808 4308 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 13:42:47.0824 4308 MountMgr - ok 13:42:47.0871 4308 mpio (583a41f26278d9e0ea548163d6139397) C:\Windows\system32\drivers\mpio.sys 13:42:47.0886 4308 mpio - ok 13:42:47.0949 4308 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 13:42:47.0964 4308 mpsdrv - ok 13:42:48.0042 4308 MpsSvc (5de62c6e9108f14f6794060a9bdecaec) C:\Windows\system32\mpssvc.dll 13:42:48.0077 4308 MpsSvc - ok 13:42:48.0108 4308 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 13:42:48.0125 4308 Mraid35x - ok 13:42:48.0171 4308 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 13:42:48.0217 4308 MRxDAV - ok 13:42:48.0264 4308 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys 13:42:48.0316 4308 mrxsmb - ok 13:42:48.0378 4308 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys 13:42:48.0441 4308 mrxsmb10 - ok 13:42:48.0477 4308 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 13:42:48.0497 4308 mrxsmb20 - ok 13:42:48.0528 4308 msahci (742aed7939e734c36b7e8d6228ce26b7) C:\Windows\system32\drivers\msahci.sys 13:42:48.0545 4308 msahci - ok 13:42:48.0583 4308 msdsm (3fc82a2ae4cc149165a94699183d3028) C:\Windows\system32\drivers\msdsm.sys 13:42:48.0601 4308 msdsm - ok 13:42:48.0659 4308 MSDTC (fd7520cc3a80c5fc8c48852bb24c6ded) C:\Windows\System32\msdtc.exe 13:42:48.0714 4308 MSDTC - ok 13:42:48.0768 4308 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 13:42:48.0807 4308 Msfs - ok 13:42:48.0832 4308 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 13:42:48.0852 4308 msisadrv - ok 13:42:48.0906 4308 MSiSCSI (85466c0757a23d9a9aecdc0755203cb2) C:\Windows\system32\iscsiexe.dll 13:42:48.0936 4308 MSiSCSI - ok 13:42:48.0940 4308 msiserver - ok 13:42:48.0990 4308 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 13:42:49.0035 4308 MSKSSRV - ok 13:42:49.0083 4308 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 13:42:49.0114 4308 MSPCLOCK - ok 13:42:49.0146 4308 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 13:42:49.0208 4308 MSPQM - ok 13:42:49.0270 4308 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 13:42:49.0286 4308 MsRPC - ok 13:42:49.0348 4308 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 13:42:49.0364 4308 mssmbios - ok 13:42:49.0395 4308 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 13:42:49.0442 4308 MSTEE - ok 13:42:49.0489 4308 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 13:42:49.0504 4308 Mup - ok 13:42:49.0582 4308 napagent (e4eaf0c5c1b41b5c83386cf212ca9584) C:\Windows\system32\qagentRT.dll 13:42:49.0613 4308 napagent - ok 13:42:49.0676 4308 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 13:42:49.0718 4308 NativeWifiP - ok 13:42:50.0101 4308 NAVENG (f11033730b38260b6892e837c457fb4b) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20120609.016\NAVENG.SYS 13:42:50.0118 4308 NAVENG - ok 13:42:50.0252 4308 NAVEX15 (4e4e7c0259d3bb97de24a636c0e06aba) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20120609.016\NAVEX15.SYS 13:42:50.0326 4308 NAVEX15 - ok 13:42:50.0538 4308 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 13:42:50.0574 4308 NDIS - ok 13:42:50.0652 4308 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 13:42:50.0699 4308 NdisTapi - ok 13:42:50.0730 4308 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 13:42:50.0762 4308 Ndisuio - ok 13:42:50.0793 4308 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 13:42:50.0840 4308 NdisWan - ok 13:42:50.0886 4308 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 13:42:50.0918 4308 NDProxy - ok 13:42:50.0949 4308 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 13:42:50.0964 4308 NetBIOS - ok 13:42:51.0042 4308 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 13:42:51.0074 4308 netbt - ok 13:42:51.0120 4308 Netlogon (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe 13:42:51.0152 4308 Netlogon - ok 13:42:51.0194 4308 Netman (c8052711daecc48b982434c5116ca401) C:\Windows\System32\netman.dll 13:42:51.0251 4308 Netman - ok 13:42:51.0323 4308 netprofm (2ef3bbe22e5a5acd1428ee387a0d0172) C:\Windows\System32\netprofm.dll 13:42:51.0374 4308 netprofm - ok 13:42:51.0475 4308 NetTcpPortSharing (d6c4e4a39a36029ac0813d476fbd0248) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 13:42:51.0494 4308 NetTcpPortSharing - ok 13:42:51.0696 4308 NETw4v32 (1d73499a6664b4da05d750ff83fdb274) C:\Windows\system32\DRIVERS\NETw4v32.sys 13:42:51.0887 4308 NETw4v32 - ok 13:42:52.0056 4308 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 13:42:52.0073 4308 nfrd960 - ok 13:42:52.0254 4308 NIS (e78a365cc3e0fbfc018a33dce01909f8) C:\Program Files\Norton Internet Security\Engine\18.7.1.3\ccSvcHst.exe 13:42:52.0301 4308 NIS - ok 13:42:52.0363 4308 NlaSvc (2997b15415f9bbe05b5a4c1c85e0c6a2) C:\Windows\System32\nlasvc.dll 13:42:52.0410 4308 NlaSvc - ok 13:42:52.0488 4308 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 13:42:52.0550 4308 Npfs - ok 13:42:52.0597 4308 nsi (8bb86f0c7eea2bded6fe095d0b4ca9bd) C:\Windows\system32\nsisvc.dll 13:42:52.0675 4308 nsi - ok 13:42:52.0717 4308 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 13:42:52.0748 4308 nsiproxy - ok 13:42:52.0884 4308 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 13:42:52.0942 4308 Ntfs - ok 13:42:52.0975 4308 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 13:42:53.0046 4308 ntrigdigi - ok 13:42:53.0095 4308 NuidFltr (cf7e041663119e09d2e118521ada9300) C:\Windows\system32\DRIVERS\NuidFltr.sys 13:42:53.0110 4308 NuidFltr - ok 13:42:53.0173 4308 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 13:42:53.0213 4308 Null - ok 13:42:54.0119 4308 nvlddmkm (24000b817cc84ac1555f41929879af5a) C:\Windows\system32\DRIVERS\nvlddmkm.sys 13:42:56.0077 4308 nvlddmkm - ok 13:42:56.0237 4308 nvraid (e69e946f80c1c31c53003bfbf50cbb7c) C:\Windows\system32\drivers\nvraid.sys 13:42:56.0255 4308 nvraid - ok 13:42:56.0279 4308 nvstor (9e0ba19a28c498a6d323d065db76dffc) C:\Windows\system32\drivers\nvstor.sys 13:42:56.0297 4308 nvstor - ok 13:42:56.0361 4308 nvsvc (c4d17f11526f87bc762f31da5bd2580b) C:\Windows\system32\nvvsvc.exe 13:42:56.0378 4308 nvsvc - ok 13:42:56.0408 4308 nv_agp (07c186427eb8fcc3d8d7927187f260f7) C:\Windows\system32\drivers\nv_agp.sys 13:42:56.0428 4308 nv_agp - ok 13:42:56.0433 4308 NwlnkFlt - ok 13:42:56.0444 4308 NwlnkFwd - ok 13:42:56.0604 4308 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 13:42:56.0635 4308 odserv - ok 13:42:56.0700 4308 ohci1394 (6f310e890d46e246e0e261a63d9b36b4) C:\Windows\system32\DRIVERS\ohci1394.sys 13:42:56.0738 4308 ohci1394 - ok 13:42:56.0788 4308 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 13:42:56.0806 4308 ose - ok 13:42:56.0962 4308 p2pimsvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll 13:42:57.0087 4308 p2pimsvc - ok 13:42:57.0087 4308 p2psvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll 13:42:57.0150 4308 p2psvc - ok 13:42:57.0196 4308 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 13:42:57.0243 4308 Parport - ok 13:42:57.0274 4308 partmgr (b9c2b89f08670e159f7181891e449cd9) C:\Windows\system32\drivers\partmgr.sys 13:42:57.0306 4308 partmgr - ok 13:42:57.0321 4308 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 13:42:57.0369 4308 Parvdm - ok 13:42:57.0423 4308 PcaSvc (c6276ad11f4bb49b58aa1ed88537f14a) C:\Windows\System32\pcasvc.dll 13:42:57.0482 4308 PcaSvc - ok 13:42:57.0562 4308 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 13:42:57.0584 4308 pci - ok 13:42:57.0653 4308 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\DRIVERS\pciide.sys 13:42:57.0671 4308 pciide - ok 13:42:57.0699 4308 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 13:42:57.0720 4308 pcmcia - ok 13:42:57.0814 4308 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 13:42:57.0999 4308 PEAUTH - ok 13:42:58.0242 4308 PID_PEPI (dd184d9adfe2a8a21741dbdfe9e22f5c) C:\Windows\system32\DRIVERS\LV302V32.SYS 13:42:58.0391 4308 PID_PEPI - ok 13:42:58.0656 4308 pla (b1689df169143f57053f795390c99db3) C:\Windows\system32\pla.dll 13:42:58.0797 4308 pla - ok 13:42:58.0955 4308 PlugPlay (c5e7f8a996ec0a82d508fd9064a5569e) C:\Windows\system32\umpnpmgr.dll 13:42:58.0985 4308 PlugPlay - ok 13:42:59.0116 4308 PNRPAutoReg (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll 13:42:59.0149 4308 PNRPAutoReg - ok 13:42:59.0156 4308 PNRPsvc (0c8e8e61ad1eb0b250b846712c917506) C:\Windows\system32\p2psvc.dll 13:42:59.0203 4308 PNRPsvc - ok 13:42:59.0268 4308 PolicyAgent (d0494460421a03cd5225cca0059aa146) C:\Windows\System32\ipsecsvc.dll 13:42:59.0363 4308 PolicyAgent - ok 13:42:59.0451 4308 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 13:42:59.0502 4308 PptpMiniport - ok 13:42:59.0548 4308 Processor (0e3cef5d28b40cf273281d620c50700a) C:\Windows\system32\drivers\processr.sys 13:42:59.0618 4308 Processor - ok 13:42:59.0670 4308 ProfSvc (0508faa222d28835310b7bfca7a77346) C:\Windows\system32\profsvc.dll 13:42:59.0698 4308 ProfSvc - ok 13:42:59.0747 4308 ProtectedStorage (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe 13:42:59.0765 4308 ProtectedStorage - ok 13:42:59.0832 4308 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 13:42:59.0867 4308 PSched - ok 13:42:59.0894 4308 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\Windows\system32\Drivers\PxHelp20.sys 13:42:59.0910 4308 PxHelp20 - ok 13:43:00.0007 4308 QCDonner (b1ad87b4c97b6b59fcd075001e76865f) C:\Windows\system32\DRIVERS\LVCD.sys 13:43:00.0116 4308 QCDonner - ok 13:43:00.0210 4308 ql2300 (ccdac889326317792480c0a67156a1ec) C:\Windows\system32\drivers\ql2300.sys 13:43:00.0288 4308 ql2300 - ok 13:43:00.0366 4308 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 13:43:00.0382 4308 ql40xx - ok 13:43:00.0460 4308 QMY - ok 13:43:00.0513 4308 QWAVE (e9ecae663f47e6cb43962d18ab18890f) C:\Windows\system32\qwave.dll 13:43:00.0550 4308 QWAVE - ok 13:43:00.0605 4308 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 13:43:00.0637 4308 QWAVEdrv - ok 13:43:00.0698 4308 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 13:43:00.0728 4308 RasAcd - ok 13:43:00.0791 4308 RasAuto (f6a452eb4ceadbb51c9e0ee6b3ecef0f) C:\Windows\System32\rasauto.dll 13:43:00.0842 4308 RasAuto - ok 13:43:00.0887 4308 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 13:43:00.0918 4308 Rasl2tp - ok 13:43:00.0993 4308 RasMan (75d47445d70ca6f9f894b032fbc64fcf) C:\Windows\System32\rasmans.dll 13:43:01.0041 4308 RasMan - ok 13:43:01.0086 4308 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 13:43:01.0133 4308 RasPppoe - ok 13:43:01.0194 4308 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 13:43:01.0223 4308 RasSstp - ok 13:43:01.0289 4308 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 13:43:01.0319 4308 rdbss - ok 13:43:01.0375 4308 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 13:43:01.0416 4308 RDPCDD - ok 13:43:01.0498 4308 rdpdr (e8bd98d46f2ed77132ba927fccb47d8b) C:\Windows\system32\drivers\rdpdr.sys 13:43:01.0592 4308 rdpdr - ok 13:43:01.0608 4308 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 13:43:01.0639 4308 RDPENCDD - ok 13:43:01.0686 4308 RDPWD (79c6df8477250f5c54f7c5ae1d6b814e) C:\Windows\system32\drivers\RDPWD.sys 13:43:01.0764 4308 RDPWD - ok 13:43:01.0810 4308 RemoteAccess (bcdd6b4804d06b1f7ebf29e53a57ece9) C:\Windows\System32\mprdim.dll 13:43:01.0842 4308 RemoteAccess - ok 13:43:01.0904 4308 RemoteRegistry (9e6894ea18daff37b63e1005f83ae4ab) C:\Windows\system32\regsvc.dll 13:43:01.0951 4308 RemoteRegistry - ok 13:43:01.0998 4308 rimmptsk (355aac141b214bef1dbc1483afd9bd50) C:\Windows\system32\DRIVERS\rimmptsk.sys 13:43:02.0030 4308 rimmptsk - ok 13:43:02.0051 4308 rimsptsk (a4216c71dd4f60b26418ccfd99cd0815) C:\Windows\system32\DRIVERS\rimsptsk.sys 13:43:02.0106 4308 rimsptsk - ok 13:43:02.0130 4308 rismxdp (c663af77e2f4eabf8eb08b388d2f1f36) C:\Windows\system32\DRIVERS\rixdptsk.sys 13:43:02.0197 4308 rismxdp - ok 13:43:02.0382 4308 RoxMediaDB9 (08fb7d968805001c7adcbb14b0651fa2) C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe 13:43:02.0455 4308 RoxMediaDB9 ( UnsignedFile.Multi.Generic ) - warning 13:43:02.0455 4308 RoxMediaDB9 - detected UnsignedFile.Multi.Generic (1) 13:43:02.0488 4308 RpcLocator (5123f83cbc4349d065534eeb6bbdc42b) C:\Windows\system32\locator.exe 13:43:02.0536 4308 RpcLocator - ok 13:43:02.0630 4308 RpcSs (3b5b4d53fec14f7476ca29a20cc31ac9) C:\Windows\system32\rpcss.dll 13:43:02.0663 4308 RpcSs - ok 13:43:02.0759 4308 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 13:43:02.0804 4308 rspndr - ok 13:43:02.0849 4308 RTL8169 (71b7026d61293c1e91145bdad11c53bf) C:\Windows\system32\DRIVERS\Rtlh86.sys 13:43:02.0917 4308 RTL8169 - ok 13:43:02.0962 4308 SamSs (a3e186b4b935905b829219502557314e) C:\Windows\system32\lsass.exe 13:43:02.0979 4308 SamSs - ok 13:43:03.0031 4308 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 13:43:03.0049 4308 sbp2port - ok 13:43:03.0095 4308 SCardSvr (77b7a11a0c3d78d3386398fbbea1b632) C:\Windows\System32\SCardSvr.dll 13:43:03.0143 4308 SCardSvr - ok 13:43:03.0245 4308 Schedule (1a58069db21d05eb2ab58ee5753ebe8d) C:\Windows\system32\schedsvc.dll 13:43:03.0356 4308 Schedule - ok 13:43:03.0418 4308 SCPolicySvc (312ec3e37a0a1f2006534913e37b4423) C:\Windows\System32\certprop.dll 13:43:03.0434 4308 SCPolicySvc - ok 13:43:03.0480 4308 sdbus (8f36b54688c31eed4580129040c6a3d3) C:\Windows\system32\DRIVERS\sdbus.sys 13:43:03.0512 4308 sdbus - ok 13:43:03.0574 4308 SDRSVC (716313d9f6b0529d03f726d5aaf6f191) C:\Windows\System32\SDRSVC.dll 13:43:03.0633 4308 SDRSVC - ok 13:43:03.0663 4308 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 13:43:03.0729 4308 secdrv - ok 13:43:03.0777 4308 seclogon (fd5199d4d8a521005e4b5ee7fe00fa9b) C:\Windows\system32\seclogon.dll 13:43:03.0824 4308 seclogon - ok 13:43:03.0848 4308 SENS (a9bbab5759771e523f55563d6cbe140f) C:\Windows\System32\sens.dll 13:43:03.0880 4308 SENS - ok 13:43:03.0915 4308 SeratoUsb (5e28961c1c26c01f2d9c9256aa194e85) C:\Windows\system32\Drivers\SeratoUsb.sys 13:43:03.0933 4308 SeratoUsb - ok 13:43:03.0955 4308 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 13:43:04.0001 4308 Serenum - ok 13:43:04.0023 4308 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 13:43:04.0090 4308 Serial - ok 13:43:04.0140 4308 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 13:43:04.0170 4308 sermouse - ok 13:43:04.0234 4308 SessionEnv (d2193326f729b163125610dbf3e17d57) C:\Windows\system32\sessenv.dll 13:43:04.0265 4308 SessionEnv - ok 13:43:04.0318 4308 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\DRIVERS\sffdisk.sys 13:43:04.0342 4308 sffdisk - ok 13:43:04.0395 4308 sffp_mmc (8fd08a310645fe872eeec6e08c6bf3ee) C:\Windows\system32\drivers\sffp_mmc.sys 13:43:04.0441 4308 sffp_mmc - ok 13:43:04.0482 4308 sffp_sd (9f66a46c55d6f1ccabc79bb7afccc545) C:\Windows\system32\DRIVERS\sffp_sd.sys 13:43:04.0526 4308 sffp_sd - ok 13:43:04.0554 4308 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 13:43:04.0629 4308 sfloppy - ok 13:43:04.0707 4308 SharedAccess (e1499bd0ff76b1b2fbbf1af339d91165) C:\Windows\System32\ipnathlp.dll 13:43:04.0754 4308 SharedAccess - ok 13:43:04.0817 4308 ShellHWDetection (c7230fbee14437716701c15be02c27b8) C:\Windows\System32\shsvcs.dll 13:43:04.0926 4308 ShellHWDetection - ok 13:43:04.0973 4308 sisagp (d2a595d6eebeeaf4334f8e50efbc9931) C:\Windows\system32\drivers\sisagp.sys 13:43:05.0004 4308 sisagp - ok 13:43:05.0019 4308 SiSRaid2 (cedd6f4e7d84e9f98b34b3fe988373aa) C:\Windows\system32\drivers\sisraid2.sys 13:43:05.0051 4308 SiSRaid2 - ok 13:43:05.0066 4308 SiSRaid4 (df843c528c4f69d12ce41ce462e973a7) C:\Windows\system32\drivers\sisraid4.sys 13:43:05.0082 4308 SiSRaid4 - ok 13:43:05.0375 4308 slsvc (862bb4cbc05d80c5b45be430e5ef872f) C:\Windows\system32\SLsvc.exe 13:43:05.0628 4308 slsvc - ok 13:43:05.0844 4308 SLUINotify (6edc422215cd78aa8a9cde6b30abbd35) C:\Windows\system32\SLUINotify.dll 13:43:05.0890 4308 SLUINotify - ok 13:43:06.0007 4308 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 13:43:06.0044 4308 Smb - ok 13:43:06.0153 4308 smserial (3850aba97b31094f93bcbe94d6abbe22) C:\Windows\system32\DRIVERS\smserial.sys 13:43:06.0262 4308 smserial - ok 13:43:06.0293 4308 SNMPTRAP (2a146a055b4401c16ee62d18b8e2a032) C:\Windows\System32\snmptrap.exe 13:43:06.0309 4308 SNMPTRAP - ok 13:43:06.0371 4308 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 13:43:06.0387 4308 spldr - ok 13:43:06.0434 4308 Spooler (8554097e5136c3bf9f69fe578a1b35f4) C:\Windows\System32\spoolsv.exe 13:43:06.0480 4308 Spooler - ok 13:43:06.0574 4308 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys 13:43:06.0574 4308 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505 13:43:06.0574 4308 sptd ( LockedFile.Multi.Generic ) - warning 13:43:06.0574 4308 sptd - detected LockedFile.Multi.Generic (1) 13:43:06.0734 4308 SRTSP (83726cf02eced69138948083e06b6eac) C:\Windows\System32\Drivers\NIS\1207010.003\SRTSP.SYS 13:43:06.0765 4308 SRTSP - ok 13:43:06.0810 4308 SRTSPX (4e7eab2e5615d39cf1f1df9c71e5e225) C:\Windows\system32\drivers\NIS\1207010.003\SRTSPX.SYS 13:43:06.0825 4308 SRTSPX - ok 13:43:06.0902 4308 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys 13:43:06.0961 4308 srv - ok 13:43:07.0022 4308 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys 13:43:07.0081 4308 srv2 - ok 13:43:07.0113 4308 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys 13:43:07.0134 4308 srvnet - ok 13:43:07.0188 4308 SSDPSRV (03d50b37234967433a5ea5ba72bc0b62) C:\Windows\System32\ssdpsrv.dll 13:43:07.0245 4308 SSDPSRV - ok 13:43:07.0300 4308 SstpSvc (6f1a32e7b7b30f004d9a20afadb14944) C:\Windows\system32\sstpsvc.dll 13:43:07.0321 4308 SstpSvc - ok 13:43:07.0408 4308 stisvc (5de7d67e49b88f5f07f3e53c4b92a352) C:\Windows\System32\wiaservc.dll 13:43:07.0476 4308 stisvc - ok 13:43:07.0599 4308 stllssvr (a9a23c8af361f7a93fd632e91a8c346f) C:\Program Files\Common Files\SureThing Shared\stllssvr.exe 13:43:07.0615 4308 stllssvr - ok 13:43:07.0669 4308 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 13:43:07.0710 4308 swenum - ok 13:43:07.0804 4308 swprv (f21fd248040681cca1fb6c9a03aaa93d) C:\Windows\System32\swprv.dll 13:43:07.0851 4308 swprv - ok 13:43:07.0882 4308 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 13:43:07.0898 4308 Symc8xx - ok 13:43:08.0038 4308 SymDS (9bbeb8c6258e72d62e7560e6667aad39) C:\Windows\system32\drivers\NIS\1207010.003\SYMDS.SYS 13:43:08.0054 4308 SymDS - ok 13:43:08.0147 4308 SymEFA (d5c02629c02a820a7e71bca3d44294a3) C:\Windows\system32\drivers\NIS\1207010.003\SYMEFA.SYS 13:43:08.0178 4308 SymEFA - ok 13:43:08.0243 4308 SymEvent (ab33c3b196197ca467cbdda717860dba) C:\Windows\system32\Drivers\SYMEVENT.SYS 13:43:08.0261 4308 SymEvent - ok 13:43:08.0327 4308 SymIM (8d49cdbb93c3e58e1bfc39fb29444c0a) C:\Windows\system32\DRIVERS\SymIMv.sys 13:43:08.0341 4308 SymIM - ok 13:43:08.0373 4308 SymIRON (a73399804d5d4a8b20ba60fcf70c9f1f) C:\Windows\system32\drivers\NIS\1207010.003\Ironx86.SYS 13:43:08.0390 4308 SymIRON - ok 13:43:08.0429 4308 SYMTDIv (d42a7229e333af725f1445f785e4658d) C:\Windows\System32\Drivers\NIS\1207010.003\SYMTDIV.SYS 13:43:08.0455 4308 SYMTDIv - ok 13:43:08.0502 4308 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 13:43:08.0519 4308 Sym_hi - ok 13:43:08.0559 4308 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 13:43:08.0575 4308 Sym_u3 - ok 13:43:08.0663 4308 SynTP (8327106d1c93e9a7b98e63b9fcc24bb7) C:\Windows\system32\DRIVERS\SynTP.sys 13:43:08.0685 4308 SynTP - ok 13:43:08.0774 4308 SysMain (9a51b04e9886aa4ee90093586b0ba88d) C:\Windows\system32\sysmain.dll 13:43:08.0816 4308 SysMain - ok 13:43:08.0867 4308 TabletInputService (2dca225eae15f42c0933e998ee0231c3) C:\Windows\System32\TabSvc.dll 13:43:08.0900 4308 TabletInputService - ok 13:43:08.0970 4308 TapiSrv (d7673e4b38ce21ee54c59eeeb65e2483) C:\Windows\System32\tapisrv.dll 13:43:09.0003 4308 TapiSrv - ok 13:43:09.0064 4308 TBS (cb05822cd9cc6c688168e113c603dbe7) C:\Windows\System32\tbssvc.dll 13:43:09.0103 4308 TBS - ok 13:43:09.0215 4308 Tcpip (27d470dabc77bc60d0a3b0e4deb6cb91) C:\Windows\system32\drivers\tcpip.sys 13:43:09.0374 4308 Tcpip - ok 13:43:09.0390 4308 Tcpip6 (27d470dabc77bc60d0a3b0e4deb6cb91) C:\Windows\system32\DRIVERS\tcpip.sys 13:43:09.0499 4308 Tcpip6 - ok 13:43:09.0561 4308 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys 13:43:09.0671 4308 tcpipreg - ok 13:43:09.0717 4308 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 13:43:09.0749 4308 TDPIPE - ok 13:43:09.0780 4308 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 13:43:09.0796 4308 TDTCP - ok 13:43:09.0840 4308 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 13:43:09.0895 4308 tdx - ok 13:43:09.0947 4308 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 13:43:09.0966 4308 TermDD - ok 13:43:10.0052 4308 TermService (bb95da09bef6e7a131bff3ba5032090d) C:\Windows\System32\termsrv.dll 13:43:10.0092 4308 TermService - ok 13:43:10.0150 4308 Themes (c7230fbee14437716701c15be02c27b8) C:\Windows\system32\shsvcs.dll 13:43:10.0171 4308 Themes - ok 13:43:10.0228 4308 THREADORDER (1076ffcffaae8385fd62dfcb25ac4708) C:\Windows\system32\mmcss.dll 13:43:10.0257 4308 THREADORDER - ok 13:43:10.0285 4308 TrkWks (ec74e77d0eb004bd3a809b5f8fb8c2ce) C:\Windows\System32\trkwks.dll 13:43:10.0330 4308 TrkWks - ok 13:43:10.0389 4308 TrustedInstaller (97d9d6a04e3ad9b6c626b9931db78dba) C:\Windows\servicing\TrustedInstaller.exe 13:43:10.0413 4308 TrustedInstaller - ok 13:43:10.0442 4308 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 13:43:10.0473 4308 tssecsrv - ok 13:43:10.0506 4308 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 13:43:10.0561 4308 tunmp - ok 13:43:10.0592 4308 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 13:43:10.0636 4308 tunnel - ok 13:43:10.0684 4308 uagp35 (c3ade15414120033a36c0f293d4a4121) C:\Windows\system32\drivers\uagp35.sys 13:43:10.0700 4308 uagp35 - ok 13:43:10.0775 4308 UCXIU - ok 13:43:10.0867 4308 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 13:43:10.0899 4308 udfs - ok 13:43:10.0945 4308 UI0Detect (ecef404f62863755951e09c802c94ad5) C:\Windows\system32\UI0Detect.exe 13:43:10.0977 4308 UI0Detect - ok 13:43:11.0023 4308 uliagpkx (75e6890ebfce0841d3291b02e7a8bdb0) C:\Windows\system32\drivers\uliagpkx.sys 13:43:11.0039 4308 uliagpkx - ok 13:43:11.0070 4308 uliahci (3cd4ea35a6221b85dcc25daa46313f8d) C:\Windows\system32\drivers\uliahci.sys 13:43:11.0086 4308 uliahci - ok 13:43:11.0117 4308 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 13:43:11.0133 4308 UlSata - ok 13:43:11.0179 4308 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 13:43:11.0195 4308 ulsata2 - ok 13:43:11.0257 4308 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 13:43:11.0289 4308 umbus - ok 13:43:11.0352 4308 upnphost (68308183f4ae0be7bf8ecd07cb297999) C:\Windows\System32\upnphost.dll 13:43:11.0404 4308 upnphost - ok 13:43:11.0446 4308 usbaudio (32db9517628ff0d070682aab61e688f0) C:\Windows\system32\drivers\usbaudio.sys 13:43:11.0486 4308 usbaudio - ok 13:43:11.0543 4308 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 13:43:11.0605 4308 usbccgp - ok 13:43:11.0658 4308 usbcir (47b9770ea21436de4ad5aea7926e0900) C:\Windows\system32\DRIVERS\usbcir.sys 13:43:11.0689 4308 usbcir - ok 13:43:11.0743 4308 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 13:43:11.0770 4308 usbehci - ok 13:43:11.0838 4308 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 13:43:11.0867 4308 usbhub - ok 13:43:11.0911 4308 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 13:43:11.0987 4308 usbohci - ok 13:43:12.0022 4308 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 13:43:12.0055 4308 usbprint - ok 13:43:12.0098 4308 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys 13:43:12.0123 4308 usbscan - ok 13:43:12.0156 4308 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 13:43:12.0190 4308 USBSTOR - ok 13:43:12.0244 4308 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 13:43:12.0269 4308 usbuhci - ok 13:43:12.0337 4308 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys 13:43:12.0405 4308 usbvideo - ok 13:43:12.0468 4308 UxSms (1509e705f3ac1d474c92454a5c2dd81f) C:\Windows\System32\uxsms.dll 13:43:12.0499 4308 UxSms - ok 13:43:12.0639 4308 vds (cd88d1b7776dc17a119049742ec07eb4) C:\Windows\System32\vds.exe 13:43:12.0671 4308 vds - ok 13:43:12.0733 4308 vga (7d92be0028ecdedec74617009084b5ef) C:\Windows\system32\DRIVERS\vgapnp.sys 13:43:12.0811 4308 vga - ok 13:43:12.0858 4308 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 13:43:12.0889 4308 VgaSave - ok 13:43:12.0906 4308 viaagp (045d9961e591cf0674a920b6ba3ba5cb) C:\Windows\system32\drivers\viaagp.sys 13:43:12.0923 4308 viaagp - ok 13:43:12.0947 4308 ViaC7 (56a4de5f02f2e88182b0981119b4dd98) C:\Windows\system32\drivers\viac7.sys 13:43:12.0994 4308 ViaC7 - ok 13:43:13.0018 4308 viaide (fd2e3175fcada350c7ab4521dca187ec) C:\Windows\system32\drivers\viaide.sys 13:43:13.0035 4308 viaide - ok 13:43:13.0090 4308 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 13:43:13.0109 4308 volmgr - ok 13:43:13.0171 4308 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 13:43:13.0197 4308 volmgrx - ok 13:43:13.0265 4308 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 13:43:13.0289 4308 volsnap - ok 13:43:13.0327 4308 vsmraid (d984439746d42b30fc65a4c3546c6829) C:\Windows\system32\drivers\vsmraid.sys 13:43:13.0346 4308 vsmraid - ok 13:43:13.0474 4308 VSS (db3d19f850c6eb32bdcb9bc0836acddb) C:\Windows\system32\vssvc.exe 13:43:13.0619 4308 VSS - ok 13:43:13.0819 4308 vToolbarUpdater11.1.0 (5fa45791413acce628d5361458f32dde) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe 13:43:13.0874 4308 vToolbarUpdater11.1.0 - ok 13:43:14.0132 4308 W32Time (96ea68b9eb310a69c25ebb0282b2b9de) C:\Windows\system32\w32time.dll 13:43:14.0178 4308 W32Time - ok 13:43:14.0241 4308 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 13:43:14.0319 4308 WacomPen - ok 13:43:14.0381 4308 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 13:43:14.0428 4308 Wanarp - ok 13:43:14.0428 4308 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 13:43:14.0459 4308 Wanarpv6 - ok 13:43:14.0488 4308 wcncsvc (a3cd60fd826381b49f03832590e069af) C:\Windows\System32\wcncsvc.dll 13:43:14.0522 4308 wcncsvc - ok 13:43:14.0574 4308 WcsPlugInService (11bcb7afcdd7aadacb5746f544d3a9c7) C:\Windows\System32\WcsPlugInService.dll 13:43:14.0625 4308 WcsPlugInService - ok 13:43:14.0665 4308 Wd (afc5ad65b991c1e205cf25cfdbf7a6f4) C:\Windows\system32\drivers\wd.sys 13:43:14.0682 4308 Wd - ok 13:43:14.0720 4308 WDC_SAM (d6efaf429fd30c5df613d220e344cce7) C:\Windows\system32\DRIVERS\wdcsam.sys 13:43:14.0776 4308 WDC_SAM - ok 13:43:14.0861 4308 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 13:43:14.0896 4308 Wdf01000 - ok 13:43:14.0965 4308 WdiServiceHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll 13:43:15.0004 4308 WdiServiceHost - ok 13:43:15.0008 4308 WdiSystemHost (abfc76b48bb6c96e3338d8943c5d93b5) C:\Windows\system32\wdi.dll 13:43:15.0040 4308 WdiSystemHost - ok 13:43:15.0115 4308 WebClient (04c37d8107320312fbae09926103d5e2) C:\Windows\System32\webclnt.dll 13:43:15.0160 4308 WebClient - ok 13:43:15.0228 4308 Wecsvc (ae3736e7e8892241c23e4ebbb7453b60) C:\Windows\system32\wecsvc.dll 13:43:15.0292 4308 Wecsvc - ok 13:43:15.0317 4308 wercplsupport (670ff720071ed741206d69bd995ea453) C:\Windows\System32\wercplsupport.dll 13:43:15.0376 4308 wercplsupport - ok 13:43:15.0445 4308 WerSvc (32b88481d3b326da6deb07b1d03481e7) C:\Windows\System32\WerSvc.dll 13:43:15.0498 4308 WerSvc - ok 13:43:15.0576 4308 winachsf (5c7bdcf5864db00323fe2d90fa26a8a2) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS 13:43:15.0638 4308 winachsf - ok 13:43:15.0794 4308 WinDefend (4575aa12561c5648483403541d0d7f2b) C:\Program Files\Windows Defender\mpsvc.dll 13:43:15.0810 4308 WinDefend - ok 13:43:15.0826 4308 WinHttpAutoProxySvc - ok 13:43:15.0935 4308 Winmgmt (6b2a1d0e80110e3d04e6863c6e62fd8a) C:\Windows\system32\wbem\WMIsvc.dll 13:43:15.0950 4308 Winmgmt - ok 13:43:16.0088 4308 WinRM (7cfe68bdc065e55aa5e8421607037511) C:\Windows\system32\WsmSvc.dll 13:43:16.0151 4308 WinRM - ok 13:43:16.0245 4308 Wlansvc (c008405e4feeb069e30da1d823910234) C:\Windows\System32\wlansvc.dll 13:43:16.0304 4308 Wlansvc - ok 13:43:16.0419 4308 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys 13:43:16.0453 4308 WmiAcpi - ok 13:43:16.0552 4308 wmiApSrv (43be3875207dcb62a85c8c49970b66cc) C:\Windows\system32\wbem\WmiApSrv.exe 13:43:16.0599 4308 wmiApSrv - ok 13:43:16.0783 4308 WMPNetworkSvc (3978704576a121a9204f8cc49a301a9b) C:\Program Files\Windows Media Player\wmpnetwk.exe 13:43:16.0905 4308 WMPNetworkSvc - ok 13:43:16.0973 4308 WPCSvc (cfc5a04558f5070cee3e3a7809f3ff52) C:\Windows\System32\wpcsvc.dll 13:43:17.0084 4308 WPCSvc - ok 13:43:17.0131 4308 WPDBusEnum (801fbdb89d472b3c467eb112a0fc9246) C:\Windows\system32\wpdbusenum.dll 13:43:17.0209 4308 WPDBusEnum - ok 13:43:17.0302 4308 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys 13:43:17.0318 4308 WpdUsb - ok 13:43:17.0584 4308 WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 13:43:17.0627 4308 WPFFontCache_v0400 - ok 13:43:17.0710 4308 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 13:43:17.0742 4308 ws2ifsl - ok 13:43:17.0794 4308 wscsvc (1ca6c40261ddc0425987980d0cd2aaab) C:\Windows\System32\wscsvc.dll 13:43:17.0828 4308 wscsvc - ok 13:43:17.0833 4308 WSearch - ok 13:43:18.0034 4308 wuauserv (6298277b73c77fa99106b271a7525163) C:\Windows\system32\wuaueng.dll 13:43:18.0137 4308 wuauserv - ok 13:43:18.0388 4308 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 13:43:18.0457 4308 WUDFRd - ok 13:43:18.0515 4308 wudfsvc (575a4190d989f64732119e4114045a4f) C:\Windows\System32\WUDFSvc.dll 13:43:18.0546 4308 wudfsvc - ok 13:43:18.0637 4308 ZNT - ok 13:43:18.0669 4308 MBR (0x1B8) (ab2261d98ab453077a8fc300866b802f) \Device\Harddisk0\DR0 13:43:18.0965 4308 \Device\Harddisk0\DR0 - ok 13:43:18.0965 4308 Boot (0x1200) (6edb2abb308240b8dcd628be83d2bc30) \Device\Harddisk0\DR0\Partition0 13:43:18.0965 4308 \Device\Harddisk0\DR0\Partition0 - ok 13:43:18.0981 4308 Boot (0x1200) (2bafbc1c313ec492cc5904f6d4d8ad1c) \Device\Harddisk0\DR0\Partition1 13:43:18.0981 4308 \Device\Harddisk0\DR0\Partition1 - ok 13:43:18.0981 4308 ============================================================ 13:43:18.0981 4308 Scan finished 13:43:18.0981 4308 ============================================================ 13:43:18.0981 4964 Detected object count: 11 13:43:18.0981 4964 Actual detected object count: 11 14:46:43.0629 4964 c:\program files\common files\akamai/netsession_win_80c2ffa.dll - copied to quarantine 14:46:43.0723 4964 HKLM\SYSTEM\ControlSet001\services\Akamai - will be deleted on reboot 14:46:43.0757 4964 HKLM\SYSTEM\ControlSet003\services\Akamai - will be deleted on reboot 14:46:43.0805 4964 c:\program files\common files\akamai/netsession_win_80c2ffa.dll - will be deleted on reboot 14:46:43.0805 4964 Akamai ( HiddenFile.Multi.Generic ) - User select action: Delete 14:46:43.0807 4964 ASBroker ( UnsignedFile.Multi.Generic ) - skipped by user 14:46:43.0808 4964 ASBroker ( UnsignedFile.Multi.Generic ) - User select action: Skip 14:46:43.0809 4964 ASChannel ( UnsignedFile.Multi.Generic ) - skipped by user 14:46:43.0809 4964 ASChannel ( UnsignedFile.Multi.Generic ) - User select action: Skip 14:46:43.0811 4964 CLCapSvc ( UnsignedFile.Multi.Generic ) - skipped by user 14:46:43.0811 4964 CLCapSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip 14:46:43.0813 4964 CLSched ( UnsignedFile.Multi.Generic ) - skipped by user 14:46:43.0813 4964 CLSched ( UnsignedFile.Multi.Generic ) - User select action: Skip 14:46:43.0814 4964 HP Health Check Service ( UnsignedFile.Multi.Generic ) - skipped by user 14:46:43.0814 4964 HP Health Check Service ( UnsignedFile.Multi.Generic ) - User select action: Skip 14:46:43.0816 4964 hpqwmiex ( UnsignedFile.Multi.Generic ) - skipped by user 14:46:43.0816 4964 hpqwmiex ( UnsignedFile.Multi.Generic ) - User select action: Skip 14:46:43.0818 4964 IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user 14:46:43.0818 4964 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip 14:46:43.0819 4964 LightScribeService ( UnsignedFile.Multi.Generic ) - skipped by user 14:46:43.0820 4964 LightScribeService ( UnsignedFile.Multi.Generic ) - User select action: Skip 14:46:43.0822 4964 RoxMediaDB9 ( UnsignedFile.Multi.Generic ) - skipped by user 14:46:43.0822 4964 RoxMediaDB9 ( UnsignedFile.Multi.Generic ) - User select action: Skip 14:46:43.0824 4964 sptd ( LockedFile.Multi.Generic ) - skipped by user 14:46:43.0824 4964 sptd ( LockedFile.Multi.Generic ) - User select action: Skip 14:57:52.0464 4200 Deinitialize success thank you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI