This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PC non responsive, slow, self rebooting.....

68 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Yeah :clap: , its all back to its oringinal glory as far as i can see, my IE has gone back to its original home page and the pc is fine. How did it get through anyway? is it from downloading things? Thanks for your help Doris, i guess were ready for a clean up?
Oh, now now. We can't clean up until we do the Malwarebytes and ESET scan again just to be 100% sure. Then we will do clean up :)

I see you have Malwarebytes already on your machine. Please run it by right-clicking and choosing Run as Administrator on the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.


Go here to run an online scannner from ESET.
  • Note: For browsers other than Internet Explorer, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
hi, eset didn't produce a log it said there was nothing found it did take me a couple of attempts to finish the scan however as it shut itself off after the first try at 97%, malwarebytes also found nothing, but the laptop is doing pretty much the same as the pc was, non responsive browser pages and just closing down pages on its own and is getting worse, when i went onto IE to view this page Babylon came up again aswell!!. The only thing that has connected to both pc and laptop is my digital camera,my phone and the memory stick. Do you think that it could possibly be some connection, would the usb ports need cleaning? its really frustrating not to find any malware when the behavior is that of such.
You've just told me something very important! You've had 3 external devices connected to these machines and now the symptoms are the same. It is very likely that one or more of these devices are infected.

Please do not plug any of these devices into the laptop until directed to do so. We need to remove the infections from the machine and then install a program to help remove the infection and protect those devices. I would also caution you not to plug them into the desktop or you will likely reinfect it as well.


Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal.

Double click ComboFix.exe to run it. It will prompt you that an update is available - please allow it to update.

Follow all prompts. Post the C:\ComboFix.txt when it has completed.


We will probably need to script out Babylon again so please make sure to leave the icon on your desktop. Do not run any other tools after Combofix although you may reboot and use the computer if you need to, just don't plug any other devices into it. That is very important!
It maybe coincidence and i know people say phones cant have viruses but my phone which is a HTC Desire HD which is only 9mths old has also recently been misbehaving , the battery is draining in a half day, when i take a call i have to take the battery out after the call has ended because the screen goes black and the phone is unusable, im just grasping at straws but its all fitting into place. I had this kind of problem some time ago when the ipod was carrying an infection and it kept reinfecting the pc. I havent plugged in the ipod to my pc but it may have been plugged into this laptop. ComboFix 12-07-26.03 - Lisa 25/07/2012 17:16:30.3.1 - x86 Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.766.267 [GMT 1:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2012-06-25 to 2012-07-25 ))))))))))))))))))))))))))))))) . . 2012-07-25 16:24 . 2012-07-25 16:25 ——– d—–w- c:\users\Lisa\AppData\Local\temp 2012-07-25 16:24 . 2012-07-25 16:24 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-07-24 21:53 . 2012-07-24 21:53 ——– d—–w- c:\program files\ESET 2012-07-24 14:59 . 2012-06-29 08:44 6891424 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{30305682-A63D-4BE4-8B42-BA658871BB45}\mpengine.dll 2012-07-23 20:30 . 2012-07-23 20:30 ——– d—–w- c:\programdata\Kaspersky Lab 2012-07-23 20:30 . 2012-07-23 20:30 ——– d—–w- c:\program files\Kaspersky Lab 2012-07-12 22:50 . 2012-06-12 02:40 2345984 —-a-w- c:\windows\system32\win32k.sys 2012-07-12 22:50 . 2010-02-11 07:10 293376 —-a-w- c:\windows\system32\browserchoice.exe 2012-07-12 16:20 . 2012-06-02 04:45 134000 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2012-07-12 16:20 . 2012-06-02 04:40 369336 —-a-w- c:\windows\system32\drivers\cng.sys 2012-07-12 16:20 . 2012-06-02 04:39 219136 —-a-w- c:\windows\system32\ncrypt.dll 2012-07-12 16:20 . 2012-06-02 04:45 67440 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2012-07-12 16:20 . 2012-06-02 04:40 225280 —-a-w- c:\windows\system32\schannel.dll 2012-07-12 16:20 . 2012-06-06 05:05 1390080 —-a-w- c:\windows\system32\msxml6.dll 2012-07-12 16:20 . 2012-06-06 05:05 1236992 —-a-w- c:\windows\system32\msxml3.dll 2012-07-12 16:20 . 2010-06-26 03:24 2048 —-a-w- c:\windows\system32\msxml3r.dll 2012-07-12 16:20 . 2012-06-06 05:05 1019904 —-a-w- c:\program files\Common Files\System\ado\msado15.dll 2012-07-12 16:20 . 2012-06-06 05:03 805376 —-a-w- c:\windows\system32\cdosys.dll 2012-07-12 16:19 . 2012-06-06 05:05 352256 —-a-w- c:\program files\Common Files\System\ado\msadomd.dll 2012-07-12 16:19 . 2012-06-06 05:05 57344 —-a-w- c:\program files\Common Files\System\ado\msador15.dll 2012-07-12 16:19 . 2012-06-06 05:05 212992 —-a-w- c:\program files\Common Files\System\msadc\msadco.dll 2012-07-12 16:19 . 2012-06-06 05:05 143360 —-a-w- c:\program files\Common Files\System\ado\msjro.dll 2012-07-12 16:19 . 2012-06-06 05:05 372736 —-a-w- c:\program files\Common Files\System\ado\msadox.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-03 16:21 . 2012-01-30 12:48 54232 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2012-07-03 16:21 . 2012-05-06 20:39 44784 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2012-07-03 16:21 . 2012-01-30 12:48 21256 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-07-03 16:21 . 2012-01-30 12:48 353688 —-a-w- c:\windows\system32\drivers\aswSP.sys 2012-07-03 16:21 . 2012-01-30 12:48 721000 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2012-07-03 16:21 . 2012-01-30 12:48 57656 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-07-03 16:21 . 2012-01-30 12:47 41224 —-a-w- c:\windows\avastSS.scr 2012-07-03 16:21 . 2012-01-30 12:47 227648 —-a-w- c:\windows\system32\aswBoot.exe 2012-07-03 12:46 . 2012-01-30 11:53 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-06-02 22:19 . 2012-06-19 15:11 53784 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2012-06-19 15:11 45080 —-a-w- c:\windows\system32\wups2.dll 2012-06-02 22:19 . 2012-06-19 15:11 35864 —-a-w- c:\windows\system32\wups.dll 2012-06-02 22:19 . 2012-06-19 15:11 577048 —-a-w- c:\windows\system32\wuapi.dll 2012-06-02 22:19 . 2012-06-19 15:11 1933848 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-02 22:12 . 2012-06-19 15:11 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-06-02 22:12 . 2012-06-19 15:11 88576 —-a-w- c:\windows\system32\wudriver.dll 2012-06-02 14:19 . 2012-06-19 15:10 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-02 14:12 . 2012-06-19 15:10 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-05-31 11:25 . 2012-02-12 16:07 237072 ——w- c:\windows\system32\MpSigStub.exe 2012-05-27 21:51 . 2012-05-27 21:51 74752 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe 2012-05-27 21:51 . 2012-05-27 21:51 161792 —-a-w- c:\windows\system32\msls31.dll 2012-05-27 21:51 . 2012-05-27 21:51 86528 —-a-w- c:\windows\system32\iesysprep.dll 2012-05-27 21:51 . 2012-05-27 21:51 76800 —-a-w- c:\windows\system32\SetIEInstalledDate.exe 2012-05-27 21:51 . 2012-05-27 21:51 48640 —-a-w- c:\windows\system32\mshtmler.dll 2012-05-27 21:51 . 2012-05-27 21:51 110592 —-a-w- c:\windows\system32\IEAdvpack.dll 2012-05-27 21:51 . 2012-05-27 21:51 63488 —-a-w- c:\windows\system32\tdc.ocx 2012-05-27 21:51 . 2012-05-27 21:51 367104 —-a-w- c:\windows\system32\html.iec 2012-05-27 21:51 . 2012-05-27 21:51 74752 —-a-w- c:\windows\system32\iesetup.dll 2012-05-27 21:51 . 2012-05-27 21:51 23552 —-a-w- c:\windows\system32\licmgr10.dll 2012-05-27 21:51 . 2012-05-27 21:51 420864 —-a-w- c:\windows\system32\vbscript.dll 2012-05-27 21:51 . 2012-05-27 21:51 152064 —-a-w- c:\windows\system32\wextract.exe 2012-05-27 21:51 . 2012-05-27 21:51 150528 —-a-w- c:\windows\system32\iexpress.exe 2012-05-27 21:51 . 2012-05-27 21:51 11776 —-a-w- c:\windows\system32\mshta.exe 2012-05-27 21:51 . 2012-05-27 21:51 101888 —-a-w- c:\windows\system32\admparse.dll 2012-05-27 21:51 . 2012-05-27 21:51 35840 —-a-w- c:\windows\system32\imgutil.dll 2012-05-01 04:44 . 2012-06-13 23:41 164352 —-a-w- c:\windows\system32\profsvc.dll 2012-04-28 03:17 . 2012-06-13 23:42 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-07-03 16:21 121528 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Facebook Update"="c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-12 138096] "KSS"="c:\program files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe" [2012-04-25 202296] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-07-03 4273976] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "TWebCamera"="c:\program files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2009-08-11 2446648] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2012-07-03 973488] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x] S2 KSS;Kaspersky Security Scan Service;c:\program files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [x] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x] S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2012-07-25 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000Core.job - c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-02-01 16:20] . 2012-07-25 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000UA.job - c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-02-01 16:20] . 2012-07-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000Core.job - c:\users\Lisa\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-30 11:49] . 2012-07-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000UA.job - c:\users\Lisa\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-30 11:49] . . ——- Supplementary Scan ——- . uInternet Settings,ProxyOverride = *.local IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = [removed] [removed] . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-07-25 17:29:52 ComboFix-quarantined-files.txt 2012-07-25 16:29 ComboFix2.txt 2012-07-23 12:21 ComboFix3.txt 2012-07-22 23:40 . Pre-Run: 211,185,537,024 bytes free Post-Run: 211,044,110,336 bytes free . - - End Of File - - 19841F72533122EF6CA2B4BB3EF443B5
Interestingly, I'm not seeing Babylon on the scan results of Combofix for the laptop this time. Can you please run me a fresh DDS scan? Just in case you don't still have it on your desktop here are the instructions again:


Download and Run DDS by sUBs

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt and Attach.txt



I'd also like to have you do this scan. This is just so we can get a log it's not a fix. I just want to ensure you don't have a rootkit hiding on the machine.


Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.




I'd also like you to go ahead and do the following:


Download Flash_Disinfector.exe by sUBs from HERE and save it to your desktop.
  • Right-click and choose Run as Administrator on Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.


And just for the record, phones absolutely can become infected!
I figured that about phones seeing as they are just mini pcs now. I thought i should mention as i couldnt see babylon either, its on the IE page, on the top there is only a small search bar, if i click on it a drop down menu appears of the history and at the bottom are 3 search choices, 1: Search the web (babylon) 2: Bing 3: uTorrentControl2 Customised web search,thought this may assist. . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 Run by [removed] at 0:19:42 on 2012-07-26 Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.766.149 [GMT 1:00] . AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\iPod\bin\iPodService.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\notepad.exe C:\Windows\explorer.exe C:\Windows\system32\taskhost.exe C:\Users\Lisa\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Lisa\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Lisa\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Lisa\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\rundll32.exe C:\Users\Lisa\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll uRun: [Facebook Update] "c:\users\lisa\appdata\local\facebook\update\FacebookUpdate.exe" /c /nocrashserver uRun: [KSS] "c:\program files\kaspersky lab\kaspersky security scan 2.0\kss.exe" /autorun mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [TWebCamera] "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~1\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office12\REFIEBAR.DLL DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{3A38CA1A-8A0F-4B64-A7D2-74F5E09F122E} : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{506E067B-D9B7-4F7B-AA19-FE0C4218FDBB} : DhcpNameServer = [removed] [removed] TCP: Interfaces\{506E067B-D9B7-4F7B-AA19-FE0C4218FDBB}\35B4957383935383 : DhcpNameServer = 192.168.0.1 TCP: Interfaces\{506E067B-D9B7-4F7B-AA19-FE0C4218FDBB}\4514C4B44514C4B4D2436464449364 : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{506E067B-D9B7-4F7B-AA19-FE0C4218FDBB}\C6963756E6564777F627B6 : DhcpNameServer = 192.168.1.1 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll . ============= SERVICES / DRIVERS =============== . R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-1-30 721000] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-1-30 353688] R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-8-18 176128] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-1-30 21256] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-1-30 57656] R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-7-10 44808] R2 KSS;Kaspersky Security Scan Service;c:\program files\kaspersky lab\kaspersky security scan 2.0\kss.exe [2012-4-25 202296] R3 PGEffect;Pangu effect driver;c:\windows\system32\drivers\PGEffect.sys [2012-2-4 24064] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2012-1-30 167936] R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\drivers\rtl8192se.sys [2012-1-30 859136] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 62464] S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232] S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2010-11-20 52224] S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2012-4-10 1343400] . =============== Created Last 30 ================ . 2012-07-25 16:30:02 ——– d-sh–w- C:\$RECYCLE.BIN 2012-07-25 16:29:55 ——– d—–w- c:\users\lisa\appdata\local\temp 2012-07-24 21:53:32 ——– d—–w- c:\program files\ESET 2012-07-24 14:59:57 6891424 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{30305682-a63d-4be4-8b42-ba658871bb45}\mpengine.dll 2012-07-23 20:30:37 ——– d—–w- c:\programdata\Kaspersky Lab 2012-07-23 20:30:37 ——– d—–w- c:\program files\Kaspersky Lab 2012-07-22 23:24:45 98816 —-a-w- c:\windows\sed.exe 2012-07-22 23:24:45 518144 —-a-w- c:\windows\SWREG.exe 2012-07-22 23:24:45 256000 —-a-w- c:\windows\PEV.exe 2012-07-22 23:24:45 208896 —-a-w- c:\windows\MBR.exe 2012-07-12 22:50:16 2345984 —-a-w- c:\windows\system32\win32k.sys 2012-07-12 22:50:06 293376 —-a-w- c:\windows\system32\browserchoice.exe 2012-07-12 16:20:32 369336 —-a-w- c:\windows\system32\drivers\cng.sys 2012-07-12 16:20:32 134000 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2012-07-12 16:20:31 219136 —-a-w- c:\windows\system32\ncrypt.dll 2012-07-12 16:20:30 67440 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2012-07-12 16:20:30 225280 —-a-w- c:\windows\system32\schannel.dll 2012-07-12 16:20:16 1390080 —-a-w- c:\windows\system32\msxml6.dll 2012-07-12 16:20:14 1236992 —-a-w- c:\windows\system32\msxml3.dll 2012-07-12 16:20:13 2048 —-a-w- c:\windows\system32\msxml3r.dll 2012-07-12 16:20:03 1019904 —-a-w- c:\program files\common files\system\ado\msado15.dll 2012-07-12 16:20:00 805376 —-a-w- c:\windows\system32\cdosys.dll 2012-07-12 16:19:58 352256 —-a-w- c:\program files\common files\system\ado\msadomd.dll 2012-07-12 16:19:56 57344 —-a-w- c:\program files\common files\system\ado\msador15.dll 2012-07-12 16:19:54 212992 —-a-w- c:\program files\common files\system\msadc\msadco.dll 2012-07-12 16:19:53 372736 —-a-w- c:\program files\common files\system\ado\msadox.dll 2012-07-12 16:19:53 143360 —-a-w- c:\program files\common files\system\ado\msjro.dll . ==================== Find3M ==================== . 2012-07-03 16:21:53 721000 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2012-07-03 16:21:53 57656 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-07-03 16:21:53 44784 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2012-07-03 16:21:32 41224 —-a-w- c:\windows\avastSS.scr 2012-07-03 12:46:44 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-06-02 22:12:32 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-06-02 22:12:13 88576 —-a-w- c:\windows\system32\wudriver.dll 2012-06-02 14:19:42 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-02 14:12:20 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-06-02 08:33:25 1800192 —-a-w- c:\windows\system32\jscript9.dll 2012-06-02 08:25:08 1129472 —-a-w- c:\windows\system32\wininet.dll 2012-06-02 08:25:03 1427968 —-a-w- c:\windows\system32\inetcpl.cpl 2012-06-02 08:20:33 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2012-06-02 08:16:52 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-05-31 11:25:14 237072 ——w- c:\windows\system32\MpSigStub.exe 2012-05-01 04:44:12 164352 —-a-w- c:\windows\system32\profsvc.dll 2012-04-28 03:17:07 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys . ============= FINISH: 0:20:46.92 ===============
. UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows 7 Professional Boot Device: \Device\HarddiskVolume1 Install Date: 30/01/2012 10:00:36 System Uptime: 25/07/2012 12:20:14 (12 hours ago) . Motherboard: TOSHIBA | | NBWAE Processor: AMD Sempron™ SI-42 | Socket M2/S1G1 | 1050/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 233 GiB total, 195.954 GiB free. F: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP44: 19/06/2012 16:10:22 - Windows Update RP45: 19/06/2012 16:16:34 - Windows Update RP46: 26/06/2012 22:31:55 - Windows Update RP47: 01/07/2012 16:12:33 - Windows Update RP48: 06/07/2012 22:18:49 - Windows Update RP49: 12/07/2012 17:08:22 - Windows Update RP50: 12/07/2012 23:47:31 - Windows Update RP51: 18/07/2012 20:37:06 - Windows Update RP52: 23/07/2012 00:25:03 - ComboFix created restore point RP53: 24/07/2012 15:58:24 - Windows Update . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) Adobe AIR Adobe Reader X (10.1.3) Apple Application Support Apple Mobile Device Support Apple Software Update avast! Free Antivirus Bonjour ESET Online Scanner v3 Facebook Video Calling 1.2.0.159 Google Chrome iTunes Kaspersky Security Scan MagicDisc 2.7.106 Malwarebytes Anti-Malware version 1.62.0.1300 McAfee Security Scan Plus Microsoft .NET Framework 4 Client Profile Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Picasa 3 Realtek 8136 8168 8169 Ethernet Driver Realtek WLAN Driver Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft Office 2007 suites (KB2596666) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2596786) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition TOSHIBA Web Camera Application Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Access 2007 Help (KB963663) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Infopath 2007 Help (KB963662) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 (KB2596598) 32-Bit Edition Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2687310) 32-Bit Edition Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Yontoo 1.10.02 . ==== Event Viewer Messages From Past Week ======== . 25/07/2012 17:25:40, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 25/07/2012 17:08:53, Error: atikmdag [43029] - Display is not active 25/07/2012 17:08:50, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service. 25/07/2012 11:02:49, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000007f (0x00000008, 0x801dc000, 0x00000000, 0x00000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 072512-29031-01. 25/07/2012 11:02:25, Error: Service Control Manager [7023] - The Offline Files service terminated with the following error: The system cannot find the path specified. 25/07/2012 11:02:22, Error: atikmdag [52236] - CPLIB :: General - Invalid Parameter 24/07/2012 22:42:31, Error: NetBT [4307] - Initialization failed because the transport refused to open initial addresses. 20/07/2012 00:02:49, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR5. 19/07/2012 23:53:28, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR4. 19/07/2012 23:28:57, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Lisa-PC\Lisa SID (S-1-5-21-3561299463-2961446174-593319071-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. . ==== End Of File ===========================
it found nothing in tdsskiller but heres the report if you need it: 00:35:40.0514 4072 TDSS rootkit removing tool [removed] Jul 24 2012 13:16:32 00:35:40.0643 4072 ============================================================ 00:35:40.0643 4072 Current date / time: 2012/07/26 00:35:40.0643 00:35:40.0643 4072 SystemInfo: 00:35:40.0643 4072 00:35:40.0643 4072 OS Version: 6.1.7601 ServicePack: 1.0 00:35:40.0643 4072 Product type: Workstation 00:35:40.0643 4072 ComputerName: LISA-PC 00:35:40.0644 4072 UserName: Lisa 00:35:40.0644 4072 Windows directory: C:\Windows 00:35:40.0644 4072 System windows directory: C:\Windows 00:35:40.0644 4072 Processor architecture: Intel x86 00:35:40.0644 4072 Number of processors: 1 00:35:40.0644 4072 Page size: 0x1000 00:35:40.0644 4072 Boot type: Normal boot 00:35:40.0644 4072 ============================================================ 00:35:41.0806 4072 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 00:35:41.0821 4072 ============================================================ 00:35:41.0821 4072 \Device\Harddisk0\DR0: 00:35:41.0821 4072 MBR partitions: 00:35:41.0821 4072 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 00:35:41.0821 4072 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x1D192800 00:35:41.0821 4072 ============================================================ 00:35:41.0868 4072 C: <-> \Device\Harddisk0\DR0\Partition1 00:35:41.0868 4072 ============================================================ 00:35:41.0868 4072 Initialize success 00:35:41.0868 4072 ============================================================ 00:35:45.0761 1812 ============================================================ 00:35:45.0761 1812 Scan started 00:35:45.0761 1812 Mode: Manual; 00:35:45.0761 1812 ============================================================ 00:35:46.0737 1812 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys 00:35:46.0737 1812 1394ohci - ok 00:35:46.0800 1812 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys 00:35:46.0803 1812 ACPI - ok 00:35:46.0872 1812 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys 00:35:46.0873 1812 AcpiPmi - ok 00:35:47.0004 1812 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe 00:35:47.0005 1812 AdobeARMservice - ok 00:35:47.0082 1812 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\drivers\adp94xx.sys 00:35:47.0086 1812 adp94xx - ok 00:35:47.0138 1812 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\drivers\adpahci.sys 00:35:47.0141 1812 adpahci - ok 00:35:47.0177 1812 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\drivers\adpu320.sys 00:35:47.0179 1812 adpu320 - ok 00:35:47.0214 1812 AeLookupSvc (8b5eefeec1e6d1a72a06c526628ad161) C:\Windows\System32\aelupsvc.dll 00:35:47.0215 1812 AeLookupSvc - ok 00:35:47.0282 1812 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys 00:35:47.0286 1812 AFD - ok 00:35:47.0370 1812 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys 00:35:47.0371 1812 agp440 - ok 00:35:47.0401 1812 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\drivers\djsvs.sys 00:35:47.0403 1812 aic78xx - ok 00:35:47.0457 1812 ALG (18a54e132947cd98fea9accc57f98f13) C:\Windows\System32\alg.exe 00:35:47.0458 1812 ALG - ok 00:35:47.0499 1812 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys 00:35:47.0500 1812 aliide - ok 00:35:47.0543 1812 AMD External Events Utility (b19505648f033393e907e2e419fde8b3) C:\Windows\system32\atiesrxx.exe 00:35:47.0546 1812 AMD External Events Utility - ok 00:35:47.0589 1812 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys 00:35:47.0590 1812 amdagp - ok 00:35:47.0615 1812 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys 00:35:47.0616 1812 amdide - ok 00:35:47.0638 1812 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\drivers\amdk8.sys 00:35:47.0639 1812 AmdK8 - ok 00:35:47.0671 1812 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys 00:35:47.0672 1812 AmdPPM - ok 00:35:47.0728 1812 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys 00:35:47.0730 1812 amdsata - ok 00:35:47.0763 1812 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\drivers\amdsbs.sys 00:35:47.0765 1812 amdsbs - ok 00:35:47.0791 1812 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys 00:35:47.0792 1812 amdxata - ok 00:35:47.0820 1812 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys 00:35:47.0822 1812 AppID - ok 00:35:47.0865 1812 AppIDSvc (62a9c86cb6085e20db4823e4e97826f5) C:\Windows\System32\appidsvc.dll 00:35:47.0866 1812 AppIDSvc - ok 00:35:47.0907 1812 Appinfo (fb1959012294d6ad43e5304df65e3c26) C:\Windows\System32\appinfo.dll 00:35:47.0909 1812 Appinfo - ok 00:35:48.0036 1812 Apple Mobile Device (7ef47644b74ebe721cc32211d3c35e76) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 00:35:48.0038 1812 Apple Mobile Device - ok 00:35:48.0083 1812 AppMgmt (a45d184df6a8803da13a0b329517a64a) C:\Windows\System32\appmgmts.dll 00:35:48.0086 1812 AppMgmt - ok 00:35:48.0214 1812 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\drivers\arc.sys 00:35:48.0216 1812 arc - ok 00:35:48.0248 1812 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\drivers\arcsas.sys 00:35:48.0250 1812 arcsas - ok 00:35:48.0297 1812 aswFsBlk (1c1f3d6dddc046c920c493a779649f66) C:\Windows\system32\drivers\aswFsBlk.sys 00:35:48.0298 1812 aswFsBlk - ok 00:35:48.0338 1812 aswMonFlt (a48d8015af2a0d8b4937613ffbfd28de) C:\Windows\system32\drivers\aswMonFlt.sys 00:35:48.0339 1812 aswMonFlt - ok 00:35:48.0387 1812 aswRdr (4a951beba9e49410cde478b6f6abb252) C:\Windows\System32\Drivers\aswrdr2.sys 00:35:48.0388 1812 aswRdr - ok 00:35:48.0440 1812 aswSnx (73dbcf808e00580f2a47f93dd9b03876) C:\Windows\system32\drivers\aswSnx.sys 00:35:48.0446 1812 aswSnx - ok 00:35:48.0479 1812 aswSP (6cbd7d3a33f498d09c831cdd732da2e0) C:\Windows\system32\drivers\aswSP.sys 00:35:48.0484 1812 aswSP - ok 00:35:48.0512 1812 aswTdi (7109a9aa551f37cd168c02368465957e) C:\Windows\system32\drivers\aswTdi.sys 00:35:48.0513 1812 aswTdi - ok 00:35:48.0566 1812 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys 00:35:48.0567 1812 AsyncMac - ok 00:35:48.0589 1812 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys 00:35:48.0590 1812 atapi - ok 00:35:48.0842 1812 atikmdag (04f09923a393e4e0e8453a8f78361e73) C:\Windows\system32\DRIVERS\atikmdag.sys 00:35:48.0902 1812 atikmdag - ok 00:35:49.0014 1812 AudioEndpointBuilder (ce3b4e731638d2ef62fcb419be0d39f0) C:\Windows\System32\Audiosrv.dll 00:35:49.0020 1812 AudioEndpointBuilder - ok 00:35:49.0033 1812 Audiosrv (ce3b4e731638d2ef62fcb419be0d39f0) C:\Windows\System32\Audiosrv.dll 00:35:49.0038 1812 Audiosrv - ok 00:35:49.0187 1812 avast! Antivirus (2f7c0f3e39c45e0127fb78b2f18a41f3) C:\Program Files\AVAST Software\Avast\AvastSvc.exe 00:35:49.0188 1812 avast! Antivirus - ok 00:35:49.0266 1812 AxInstSV (6e30d02aac9cac84f421622e3a2f6178) C:\Windows\System32\AxInstSV.dll 00:35:49.0268 1812 AxInstSV - ok 00:35:49.0400 1812 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\drivers\bxvbdx.sys 00:35:49.0404 1812 b06bdrv - ok 00:35:49.0446 1812 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys 00:35:49.0448 1812 b57nd60x - ok 00:35:49.0504 1812 BDESVC (ee1e9c3bb8228ae423dd38db69128e71) C:\Windows\System32\bdesvc.dll 00:35:49.0506 1812 BDESVC - ok 00:35:49.0531 1812 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys 00:35:49.0532 1812 Beep - ok 00:35:49.0585 1812 BFE (1e2bac209d184bb851e1a187d8a29136) C:\Windows\System32\bfe.dll 00:35:49.0591 1812 BFE - ok 00:35:49.0686 1812 BITS (e585445d5021971fae10393f0f1c3961) C:\Windows\system32\qmgr.dll 00:35:49.0695 1812 BITS - ok 00:35:49.0729 1812 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys 00:35:49.0730 1812 blbdrive - ok 00:35:49.0845 1812 Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe 00:35:49.0849 1812 Bonjour Service - ok 00:35:49.0931 1812 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys 00:35:49.0933 1812 bowser - ok 00:35:49.0953 1812 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\BrFiltLo.sys 00:35:49.0954 1812 BrFiltLo - ok 00:35:49.0995 1812 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\BrFiltUp.sys 00:35:49.0996 1812 BrFiltUp - ok 00:35:50.0045 1812 BridgeMP (77361d72a04f18809d0efb6cceb74d4b) C:\Windows\system32\DRIVERS\bridge.sys 00:35:50.0047 1812 BridgeMP - ok 00:35:50.0231 1812 Browser (6e11f33d14d020f58d5e02e4d67dfa19) C:\Windows\System32\browser.dll 00:35:50.0233 1812 Browser - ok 00:35:50.0513 1812 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys 00:35:50.0516 1812 Brserid - ok 00:35:50.0575 1812 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys 00:35:50.0576 1812 BrSerWdm - ok 00:35:50.0612 1812 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys 00:35:50.0613 1812 BrUsbMdm - ok 00:35:50.0635 1812 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys 00:35:50.0638 1812 BrUsbSer - ok 00:35:50.0658 1812 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\drivers\bthmodem.sys 00:35:50.0659 1812 BTHMODEM - ok 00:35:50.0712 1812 bthserv (1df19c96eef6c29d1c3e1a8678e07190) C:\Windows\system32\bthserv.dll 00:35:50.0714 1812 bthserv - ok 00:35:50.0844 1812 catchme - ok 00:35:50.0890 1812 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys 00:35:50.0892 1812 cdfs - ok 00:35:50.0937 1812 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\DRIVERS\cdrom.sys 00:35:50.0940 1812 cdrom - ok 00:35:50.0977 1812 CertPropSvc (319c6b309773d063541d01df8ac6f55f) C:\Windows\System32\certprop.dll 00:35:50.0980 1812 CertPropSvc - ok 00:35:51.0022 1812 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\drivers\circlass.sys 00:35:51.0023 1812 circlass - ok 00:35:51.0058 1812 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys 00:35:51.0062 1812 CLFS - ok 00:35:51.0155 1812 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 00:35:51.0158 1812 clr_optimization_v2.0.50727_32 - ok 00:35:51.0253 1812 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 00:35:51.0256 1812 clr_optimization_v4.0.30319_32 - ok 00:35:51.0295 1812 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys 00:35:51.0296 1812 CmBatt - ok 00:35:51.0318 1812 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys 00:35:51.0319 1812 cmdide - ok 00:35:51.0364 1812 CNG (247b4ce2dab1160cd422d532d5241e1f) C:\Windows\system32\Drivers\cng.sys 00:35:51.0368 1812 CNG - ok 00:35:51.0404 1812 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys 00:35:51.0405 1812 Compbatt - ok 00:35:51.0449 1812 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\DRIVERS\CompositeBus.sys 00:35:51.0450 1812 CompositeBus - ok 00:35:51.0474 1812 COMSysApp - ok 00:35:51.0499 1812 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\drivers\crcdisk.sys 00:35:51.0500 1812 crcdisk - ok 00:35:51.0571 1812 CryptSvc (06e771aa596b8761107ab57e99f128d7) C:\Windows\system32\cryptsvc.dll 00:35:51.0574 1812 CryptSvc - ok 00:35:51.0627 1812 CscService (15f93b37f6801943360d9eb42485d5d3) C:\Windows\System32\cscsvc.dll 00:35:51.0633 1812 CscService - ok 00:35:51.0690 1812 DcomLaunch (7660f01d3b38aca1747e397d21d790af) C:\Windows\system32\rpcss.dll 00:35:51.0699 1812 DcomLaunch - ok 00:35:51.0744 1812 defragsvc (8d6e10a2d9a5eed59562d9b82cf804e1) C:\Windows\System32\defragsvc.dll 00:35:51.0747 1812 defragsvc - ok 00:35:51.0801 1812 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys 00:35:51.0803 1812 DfsC - ok 00:35:51.0863 1812 Dhcp (e9e01eb683c132f7fa27cd607b8a2b63) C:\Windows\system32\dhcpcore.dll 00:35:51.0867 1812 Dhcp - ok 00:35:51.0883 1812 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys 00:35:51.0884 1812 discache - ok 00:35:51.0959 1812 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\drivers\disk.sys 00:35:51.0960 1812 Disk - ok 00:35:52.0003 1812 dmvsc (2a958ef85db1b61ffca65044fa4bce9e) C:\Windows\system32\drivers\dmvsc.sys 00:35:52.0004 1812 dmvsc - ok 00:35:52.0048 1812 Dnscache (33ef4861f19a0736b11314aad9ae28d0) C:\Windows\System32\dnsrslvr.dll 00:35:52.0051 1812 Dnscache - ok 00:35:52.0105 1812 dot3svc (366ba8fb4b7bb7435e3b9eacb3843f67) C:\Windows\System32\dot3svc.dll 00:35:52.0110 1812 dot3svc - ok 00:35:52.0147 1812 DPS (8ec04ca86f1d68da9e11952eb85973d6) C:\Windows\system32\dps.dll 00:35:52.0150 1812 DPS - ok 00:35:52.0207 1812 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys 00:35:52.0208 1812 drmkaud - ok 00:35:52.0277 1812 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys 00:35:52.0283 1812 DXGKrnl - ok 00:35:52.0333 1812 EapHost (8600142fa91c1b96367d3300ad0f3f3a) C:\Windows\System32\eapsvc.dll 00:35:52.0336 1812 EapHost - ok 00:35:52.0488 1812 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\drivers\evbdx.sys 00:35:52.0511 1812 ebdrv - ok 00:35:52.0617 1812 EFS (81951f51e318aecc2d68559e47485cc4) C:\Windows\System32\lsass.exe 00:35:52.0620 1812 EFS - ok 00:35:52.0690 1812 ehRecvr (a8c362018efc87beb013ee28f29c0863) C:\Windows\ehome\ehRecvr.exe 00:35:52.0695 1812 ehRecvr - ok 00:35:52.0724 1812 ehSched (d389bff34f80caede417bf9d1507996a) C:\Windows\ehome\ehsched.exe 00:35:52.0727 1812 ehSched - ok 00:35:52.0821 1812 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\drivers\elxstor.sys 00:35:52.0826 1812 elxstor - ok 00:35:52.0848 1812 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys 00:35:52.0849 1812 ErrDev - ok 00:35:52.0918 1812 EventSystem (f6916efc29d9953d5d0df06882ae8e16) C:\Windows\system32\es.dll 00:35:52.0922 1812 EventSystem - ok 00:35:52.0950 1812 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys 00:35:52.0952 1812 exfat - ok 00:35:52.0986 1812 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys 00:35:52.0988 1812 fastfat - ok 00:35:53.0063 1812 Fax (967ea5b213e9984cbe270205df37755b) C:\Windows\system32\fxssvc.exe 00:35:53.0071 1812 Fax - ok 00:35:53.0115 1812 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\drivers\fdc.sys 00:35:53.0116 1812 fdc - ok 00:35:53.0136 1812 fdPHost (f3222c893bd2f5821a0179e5c71e88fb) C:\Windows\system32\fdPHost.dll 00:35:53.0138 1812 fdPHost - ok 00:35:53.0157 1812 FDResPub (7dbe8cbfe79efbdeb98c9fb08d3a9a5b) C:\Windows\system32\fdrespub.dll 00:35:53.0160 1812 FDResPub - ok 00:35:53.0187 1812 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys 00:35:53.0188 1812 FileInfo - ok 00:35:53.0226 1812 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys 00:35:53.0228 1812 Filetrace - ok 00:35:53.0257 1812 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\drivers\flpydisk.sys 00:35:53.0258 1812 flpydisk - ok 00:35:53.0305 1812 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys 00:35:53.0307 1812 FltMgr - ok 00:35:53.0373 1812 FontCache (b3a5ec6b6b6673db7e87c2bcdbddc074) C:\Windows\system32\FntCache.dll 00:35:53.0382 1812 FontCache - ok 00:35:53.0510 1812 FontCache3.0.0.0 (e56f39f6b7fda0ac77a79b0fd3de1a2f) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 00:35:53.0513 1812 FontCache3.0.0.0 - ok 00:35:53.0559 1812 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys 00:35:53.0560 1812 FsDepends - ok 00:35:53.0602 1812 Fs_Rec (7dae5ebcc80e45d3253f4923dc424d05) C:\Windows\system32\drivers\Fs_Rec.sys 00:35:53.0603 1812 Fs_Rec - ok 00:35:53.0649 1812 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys 00:35:53.0651 1812 fvevol - ok 00:35:53.0685 1812 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\drivers\gagp30kx.sys 00:35:53.0687 1812 gagp30kx - ok 00:35:53.0721 1812 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 00:35:53.0722 1812 GEARAspiWDM - ok 00:35:53.0781 1812 gpsvc (e897eaf5ed6ba41e081060c9b447a673) C:\Windows\System32\gpsvc.dll 00:35:53.0788 1812 gpsvc - ok 00:35:53.0915 1812 gusvc (c1b577b2169900f4cf7190c39f085794) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 00:35:53.0917 1812 gusvc - ok 00:35:53.0965 1812 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys 00:35:53.0966 1812 hcw85cir - ok 00:35:54.0059 1812 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys 00:35:54.0070 1812 HdAudAddService - ok 00:35:54.0122 1812 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\DRIVERS\HDAudBus.sys 00:35:54.0125 1812 HDAudBus - ok 00:35:54.0161 1812 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\drivers\HidBatt.sys 00:35:54.0162 1812 HidBatt - ok 00:35:54.0179 1812 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\drivers\hidbth.sys 00:35:54.0183 1812 HidBth - ok 00:35:54.0226 1812 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\drivers\hidir.sys 00:35:54.0227 1812 HidIr - ok 00:35:54.0258 1812 hidserv (2bc6f6a1992b3a77f5f41432ca6b3b6b) C:\Windows\System32\hidserv.dll 00:35:54.0261 1812 hidserv - ok 00:35:54.0294 1812 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys 00:35:54.0296 1812 HidUsb - ok 00:35:54.0320 1812 hkmsvc (196b4e3f4cccc24af836ce58facbb699) C:\Windows\system32\kmsvc.dll 00:35:54.0325 1812 hkmsvc - ok 00:35:54.0360 1812 HomeGroupListener (6658f4404de03d75fe3ba09f7aba6a30) C:\Windows\system32\ListSvc.dll 00:35:54.0367 1812 HomeGroupListener - ok 00:35:54.0404 1812 HomeGroupProvider (dbc02d918fff1cad628acbe0c0eaa8e8) C:\Windows\system32\provsvc.dll 00:35:54.0413 1812 HomeGroupProvider - ok 00:35:54.0461 1812 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys 00:35:54.0462 1812 HpSAMD - ok 00:35:54.0499 1812 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys 00:35:54.0507 1812 HTTP - ok 00:35:54.0537 1812 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys 00:35:54.0538 1812 hwpolicy - ok 00:35:54.0587 1812 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys 00:35:54.0589 1812 i8042prt - ok 00:35:54.0645 1812 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys 00:35:54.0650 1812 iaStorV - ok 00:35:54.0789 1812 idsvc (c521d7eb6497bb1af6afa89e322fb43c) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 00:35:54.0800 1812 idsvc - ok 00:35:54.0847 1812 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\drivers\iirsp.sys 00:35:54.0848 1812 iirsp - ok 00:35:54.0908 1812 IKEEXT (f95622f161474511b8d80d6b093aa610) C:\Windows\System32\ikeext.dll 00:35:54.0919 1812 IKEEXT - ok 00:35:54.0946 1812 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys 00:35:54.0947 1812 intelide - ok 00:35:55.0002 1812 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\drivers\intelppm.sys 00:35:55.0003 1812 intelppm - ok 00:35:55.0041 1812 IPBusEnum (acb364b9075a45c0736e5c47be5cae19) C:\Windows\system32\ipbusenum.dll 00:35:55.0045 1812 IPBusEnum - ok 00:35:55.0096 1812 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys 00:35:55.0099 1812 IpFilterDriver - ok 00:35:55.0167 1812 iphlpsvc (4d65a07b795d6674312f879d09aa7663) C:\Windows\System32\iphlpsvc.dll 00:35:55.0175 1812 iphlpsvc - ok 00:35:55.0210 1812 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys 00:35:55.0212 1812 IPMIDRV - ok 00:35:55.0243 1812 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys 00:35:55.0245 1812 IPNAT - ok 00:35:55.0361 1812 iPod Service (57edb35ea2feca88f8b17c0c095c9a56) C:\Program Files\iPod\bin\iPodService.exe 00:35:55.0368 1812 iPod Service - ok 00:35:55.0408 1812 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys 00:35:55.0409 1812 IRENUM - ok 00:35:55.0438 1812 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys 00:35:55.0439 1812 isapnp - ok 00:35:55.0477 1812 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys 00:35:55.0480 1812 iScsiPrt - ok 00:35:55.0526 1812 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys 00:35:55.0528 1812 kbdclass - ok 00:35:55.0553 1812 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys 00:35:55.0555 1812 kbdhid - ok 00:35:55.0595 1812 KeyIso (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 00:35:55.0598 1812 KeyIso - ok 00:35:55.0630 1812 KSecDD (b7895b4182c0d16f6efadeb8081e8d36) C:\Windows\system32\Drivers\ksecdd.sys 00:35:55.0632 1812 KSecDD - ok 00:35:55.0674 1812 KSecPkg (d30159ac9237519fbc62c6ec247d2d46) C:\Windows\system32\Drivers\ksecpkg.sys 00:35:55.0677 1812 KSecPkg - ok 00:35:55.0929 1812 KSS (e47ffca0909871ac1bff0d446ff63ca9) C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe 00:35:55.0932 1812 KSS - ok 00:35:55.0984 1812 KtmRm (89a7b9cc98d0d80c6f31b91c0a310fcd) C:\Windows\system32\msdtckrm.dll 00:35:56.0011 1812 KtmRm - ok 00:35:56.0098 1812 LanmanServer (d64af876d53eca3668bb97b51b4e70ab) C:\Windows\System32\srvsvc.dll 00:35:56.0106 1812 LanmanServer - ok 00:35:56.0182 1812 LanmanWorkstation (58405e4f68ba8e4057c6e914f326aba2) C:\Windows\System32\wkssvc.dll 00:35:56.0200 1812 LanmanWorkstation - ok 00:35:56.0253 1812 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys 00:35:56.0256 1812 lltdio - ok 00:35:56.0306 1812 lltdsvc (5700673e13a2117fa3b9020c852c01e2) C:\Windows\System32\lltdsvc.dll 00:35:56.0313 1812 lltdsvc - ok 00:35:56.0334 1812 lmhosts (55ca01ba19d0006c8f2639b6c045e08b) C:\Windows\System32\lmhsvc.dll 00:35:56.0340 1812 lmhosts - ok 00:35:56.0379 1812 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\drivers\lsi_fc.sys 00:35:56.0381 1812 LSI_FC - ok 00:35:56.0425 1812 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\drivers\lsi_sas.sys 00:35:56.0426 1812 LSI_SAS - ok 00:35:56.0454 1812 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\drivers\lsi_sas2.sys 00:35:56.0457 1812 LSI_SAS2 - ok 00:35:56.0507 1812 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\drivers\lsi_scsi.sys 00:35:56.0509 1812 LSI_SCSI - ok 00:35:56.0536 1812 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys 00:35:56.0539 1812 luafv - ok 00:35:56.0711 1812 McComponentHostService (f453d1e6d881e8f8717e20ccd4199e85) C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe 00:35:56.0714 1812 McComponentHostService - ok 00:35:56.0749 1812 Mcx2Svc (bfb9ee8ee977efe85d1a3105abef6dd1) C:\Windows\system32\Mcx2Svc.dll 00:35:56.0754 1812 Mcx2Svc - ok 00:35:56.0780 1812 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\drivers\megasas.sys 00:35:56.0782 1812 megasas - ok 00:35:56.0828 1812 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\drivers\MegaSR.sys 00:35:56.0831 1812 MegaSR - ok 00:35:56.0915 1812 Microsoft Office Groove Audit Service (123271bd5237ab991dc5c21fdf8835eb) C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe 00:35:56.0916 1812 Microsoft Office Groove Audit Service - ok 00:35:56.0952 1812 MMCSS (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll 00:35:56.0962 1812 MMCSS - ok 00:35:56.0986 1812 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys 00:35:56.0988 1812 Modem - ok 00:35:57.0040 1812 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys 00:35:57.0042 1812 monitor - ok 00:35:57.0072 1812 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys 00:35:57.0077 1812 mouclass - ok 00:35:57.0134 1812 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys 00:35:57.0135 1812 mouhid - ok 00:35:57.0164 1812 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys 00:35:57.0167 1812 mountmgr - ok 00:35:57.0201 1812 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys 00:35:57.0203 1812 mpio - ok 00:35:57.0233 1812 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys 00:35:57.0235 1812 mpsdrv - ok 00:35:57.0289 1812 MpsSvc (9835584e999d25004e1ee8e5f3e3b881) C:\Windows\system32\mpssvc.dll 00:35:57.0307 1812 MpsSvc - ok 00:35:57.0339 1812 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys 00:35:57.0343 1812 MRxDAV - ok 00:35:57.0387 1812 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys 00:35:57.0387 1812 mrxsmb - ok 00:35:57.0418 1812 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys 00:35:57.0434 1812 mrxsmb10 - ok 00:35:57.0449 1812 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys 00:35:57.0465 1812 mrxsmb20 - ok 00:35:57.0496 1812 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys 00:35:57.0496 1812 msahci - ok 00:35:57.0527 1812 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys 00:35:57.0527 1812 msdsm - ok 00:35:57.0559 1812 MSDTC (e1bce74a3bd9902b72599c0192a07e27) C:\Windows\System32\msdtc.exe 00:35:57.0605 1812 MSDTC - ok 00:35:57.0680 1812 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys 00:35:57.0682 1812 Msfs - ok 00:35:57.0707 1812 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys 00:35:57.0710 1812 mshidkmdf - ok 00:35:57.0735 1812 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys 00:35:57.0736 1812 msisadrv - ok 00:35:57.0775 1812 MSiSCSI (90f7d9e6b6f27e1a707d4a297f077828) C:\Windows\system32\iscsiexe.dll 00:35:57.0782 1812 MSiSCSI - ok 00:35:57.0796 1812 msiserver - ok 00:35:57.0841 1812 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys 00:35:57.0843 1812 MSKSSRV - ok 00:35:57.0922 1812 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys 00:35:57.0924 1812 MSPCLOCK - ok 00:35:57.0967 1812 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys 00:35:57.0969 1812 MSPQM - ok 00:35:57.0999 1812 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys 00:35:58.0002 1812 MsRPC - ok 00:35:58.0036 1812 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys 00:35:58.0038 1812 mssmbios - ok 00:35:58.0079 1812 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys 00:35:58.0080 1812 MSTEE - ok 00:35:58.0095 1812 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\drivers\MTConfig.sys 00:35:58.0096 1812 MTConfig - ok 00:35:58.0123 1812 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys 00:35:58.0125 1812 Mup - ok 00:35:58.0176 1812 napagent (61d57a5d7c6d9afe10e77dae6e1b445e) C:\Windows\system32\qagentRT.dll 00:35:58.0187 1812 napagent - ok 00:35:58.0396 1812 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys 00:35:58.0404 1812 NativeWifiP - ok 00:35:58.0461 1812 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys 00:35:58.0467 1812 NDIS - ok 00:35:58.0496 1812 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys 00:35:58.0499 1812 NdisCap - ok 00:35:58.0535 1812 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys 00:35:58.0537 1812 NdisTapi - ok 00:35:58.0572 1812 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys 00:35:58.0574 1812 Ndisuio - ok 00:35:58.0604 1812 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys 00:35:58.0607 1812 NdisWan - ok 00:35:58.0634 1812 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys 00:35:58.0636 1812 NDProxy - ok 00:35:58.0661 1812 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys 00:35:58.0661 1812 NetBIOS - ok 00:35:58.0692 1812 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys 00:35:58.0692 1812 NetBT - ok 00:35:58.0739 1812 Netlogon (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 00:35:58.0739 1812 Netlogon - ok 00:35:58.0786 1812 Netman (7cccfca7510684768da22092d1fa4db2) C:\Windows\System32\netman.dll 00:35:58.0801 1812 Netman - ok 00:35:58.0848 1812 netprofm (8c338238c16777a802d6a9211eb2ba50) C:\Windows\System32\netprofm.dll 00:35:58.0848 1812 netprofm - ok 00:35:58.0957 1812 NetTcpPortSharing (f476ec40033cdb91efbe73eb99b8362d) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 00:35:58.0957 1812 NetTcpPortSharing - ok 00:35:59.0004 1812 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\drivers\nfrd960.sys 00:35:59.0004 1812 nfrd960 - ok 00:35:59.0051 1812 NlaSvc (912084381d30d8b89ec4e293053f4710) C:\Windows\System32\nlasvc.dll 00:35:59.0051 1812 NlaSvc - ok 00:35:59.0082 1812 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys 00:35:59.0082 1812 Npfs - ok 00:35:59.0113 1812 nsi (ba387e955e890c8a88306d9b8d06bf17) C:\Windows\system32\nsisvc.dll 00:35:59.0113 1812 nsi - ok 00:35:59.0144 1812 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys 00:35:59.0144 1812 nsiproxy - ok 00:35:59.0246 1812 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys 00:35:59.0256 1812 Ntfs - ok 00:35:59.0277 1812 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys 00:35:59.0278 1812 Null - ok 00:35:59.0321 1812 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys 00:35:59.0322 1812 nvraid - ok 00:35:59.0356 1812 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys 00:35:59.0359 1812 nvstor - ok 00:35:59.0394 1812 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys 00:35:59.0396 1812 nv_agp - ok 00:35:59.0535 1812 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 00:35:59.0539 1812 odserv - ok 00:35:59.0569 1812 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys 00:35:59.0571 1812 ohci1394 - ok 00:35:59.0612 1812 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 00:35:59.0613 1812 ose - ok 00:35:59.0658 1812 p2pimsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll 00:35:59.0666 1812 p2pimsvc - ok 00:35:59.0724 1812 p2psvc (59c3ddd501e39e006dac31bf55150d91) C:\Windows\system32\p2psvc.dll 00:35:59.0733 1812 p2psvc - ok 00:35:59.0774 1812 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\drivers\parport.sys 00:35:59.0776 1812 Parport - ok 00:35:59.0825 1812 partmgr (3f34a1b4c5f6475f320c275e63afce9b) C:\Windows\system32\drivers\partmgr.sys 00:35:59.0827 1812 partmgr - ok 00:35:59.0852 1812 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\drivers\parvdm.sys 00:35:59.0854 1812 Parvdm - ok 00:35:59.0905 1812 PcaSvc (358ab7956d3160000726574083dfc8a6) C:\Windows\System32\pcasvc.dll 00:35:59.0911 1812 PcaSvc - ok 00:35:59.0936 1812 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys 00:35:59.0939 1812 pci - ok 00:35:59.0963 1812 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys 00:35:59.0964 1812 pciide - ok 00:36:00.0007 1812 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\drivers\pcmcia.sys 00:36:00.0010 1812 pcmcia - ok 00:36:00.0038 1812 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys 00:36:00.0040 1812 pcw - ok 00:36:00.0089 1812 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys 00:36:00.0104 1812 PEAUTH - ok 00:36:00.0175 1812 PeerDistSvc (af4d64d2a57b9772cf3801950b8058a6) C:\Windows\system32\peerdistsvc.dll 00:36:00.0198 1812 PeerDistSvc - ok 00:36:00.0325 1812 PGEffect (1b5011dd8d57f53aed31ff0f7d635802) C:\Windows\system32\DRIVERS\pgeffect.sys 00:36:00.0325 1812 PGEffect - ok 00:36:00.0434 1812 pla (414bba67a3ded1d28437eb66aeb8a720) C:\Windows\system32\pla.dll 00:36:00.0466 1812 pla - ok 00:36:00.0590 1812 PlugPlay (ec7bc28d207da09e79b3e9faf8b232ca) C:\Windows\system32\umpnpmgr.dll 00:36:00.0606 1812 PlugPlay - ok 00:36:00.0637 1812 PNRPAutoReg (63ff8572611249931eb16bb8eed6afc8) C:\Windows\system32\pnrpauto.dll 00:36:00.0653 1812 PNRPAutoReg - ok 00:36:00.0684 1812 PNRPsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll 00:36:00.0684 1812 PNRPsvc - ok 00:36:00.0746 1812 PolicyAgent (53946b69ba0836bd95b03759530c81ec) C:\Windows\System32\ipsecsvc.dll 00:36:00.0746 1812 PolicyAgent - ok 00:36:00.0822 1812 Power (f87d30e72e03d579a5199ccb3831d6ea) C:\Windows\system32\umpo.dll 00:36:00.0829 1812 Power - ok 00:36:00.0906 1812 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys 00:36:00.0908 1812 PptpMiniport - ok 00:36:00.0934 1812 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\drivers\processr.sys 00:36:00.0937 1812 Processor - ok 00:36:00.0988 1812 ProfSvc (cadefac453040e370a1bdff3973be00d) C:\Windows\system32\profsvc.dll 00:36:00.0994 1812 ProfSvc - ok 00:36:01.0036 1812 ProtectedStorage (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 00:36:01.0040 1812 ProtectedStorage - ok 00:36:01.0091 1812 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys 00:36:01.0093 1812 Psched - ok 00:36:01.0170 1812 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\drivers\ql2300.sys 00:36:01.0182 1812 ql2300 - ok 00:36:01.0313 1812 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\drivers\ql40xx.sys 00:36:01.0316 1812 ql40xx - ok 00:36:01.0357 1812 QWAVE (31ac809e7707eb580b2bdb760390765a) C:\Windows\system32\qwave.dll 00:36:01.0365 1812 QWAVE - ok 00:36:01.0392 1812 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys 00:36:01.0395 1812 QWAVEdrv - ok 00:36:01.0424 1812 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys 00:36:01.0426 1812 RasAcd - ok 00:36:01.0471 1812 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys 00:36:01.0473 1812 RasAgileVpn - ok 00:36:01.0514 1812 RasAuto (a60f1839849c0c00739787fd5ec03f13) C:\Windows\System32\rasauto.dll 00:36:01.0521 1812 RasAuto - ok 00:36:01.0555 1812 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys 00:36:01.0557 1812 Rasl2tp - ok 00:36:01.0600 1812 RasMan (cb9e04dc05eacf5b9a36ca276d475006) C:\Windows\System32\rasmans.dll 00:36:01.0610 1812 RasMan - ok 00:36:01.0643 1812 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys 00:36:01.0646 1812 RasPppoe - ok 00:36:01.0679 1812 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys 00:36:01.0682 1812 RasSstp - ok 00:36:01.0715 1812 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys 00:36:01.0720 1812 rdbss - ok 00:36:01.0736 1812 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys 00:36:01.0739 1812 rdpbus - ok 00:36:01.0756 1812 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys 00:36:01.0758 1812 RDPCDD - ok 00:36:01.0801 1812 RDPDR (b973fcfc50dc1434e1970a146f7e3885) C:\Windows\system32\drivers\rdpdr.sys 00:36:01.0816 1812 RDPDR - ok 00:36:01.0832 1812 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys 00:36:01.0848 1812 RDPENCDD - ok 00:36:01.0863 1812 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys 00:36:01.0879 1812 RDPREFMP - ok 00:36:01.0910 1812 RDPWD (f031683e6d1fea157abb2ff260b51e61) C:\Windows\system32\drivers\RDPWD.sys 00:36:01.0910 1812 RDPWD - ok 00:36:01.0957 1812 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys 00:36:01.0957 1812 rdyboost - ok 00:36:01.0988 1812 RemoteAccess (7b5e1419717fac363a31cc302895217a) C:\Windows\System32\mprdim.dll 00:36:02.0004 1812 RemoteAccess - ok 00:36:02.0035 1812 RemoteRegistry (cb9a8683f4ef2bf99e123d79950d7935) C:\Windows\system32\regsvc.dll 00:36:02.0050 1812 RemoteRegistry - ok 00:36:02.0082 1812 RpcEptMapper (78d072f35bc45d9e4e1b61895c152234) C:\Windows\System32\RpcEpMap.dll 00:36:02.0097 1812 RpcEptMapper - ok 00:36:02.0113 1812 RpcLocator (94d36c0e44677dd26981d2bfeef2a29d) C:\Windows\system32\locator.exe 00:36:02.0113 1812 RpcLocator - ok 00:36:02.0160 1812 RpcSs (7660f01d3b38aca1747e397d21d790af) C:\Windows\system32\rpcss.dll 00:36:02.0160 1812 RpcSs - ok 00:36:02.0206 1812 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys 00:36:02.0222 1812 rspndr - ok 00:36:02.0269 1812 RTL8167 (26a9d6227d12b9d9da5a81bb9b55d810) C:\Windows\system32\DRIVERS\Rt86win7.sys 00:36:02.0269 1812 RTL8167 - ok 00:36:02.0350 1812 rtl8192se (fd0b1d3ce2e7debd0ae8456494d21488) C:\Windows\system32\DRIVERS\rtl8192se.sys 00:36:02.0358 1812 rtl8192se - ok 00:36:02.0393 1812 s3cap (7fa7f2e249a5dcbb7970630e15e1f482) C:\Windows\system32\drivers\vms3cap.sys 00:36:02.0394 1812 s3cap - ok 00:36:02.0434 1812 SamSs (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 00:36:02.0438 1812 SamSs - ok 00:36:02.0478 1812 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys 00:36:02.0480 1812 sbp2port - ok 00:36:02.0518 1812 SCardSvr (8fc518ffe9519c2631d37515a68009c4) C:\Windows\System32\SCardSvr.dll 00:36:02.0526 1812 SCardSvr - ok 00:36:02.0548 1812 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys 00:36:02.0550 1812 scfilter - ok 00:36:02.0611 1812 Schedule (a04bb13f8a72f8b6e8b4071723e4e336) C:\Windows\system32\schedsvc.dll 00:36:02.0622 1812 Schedule - ok 00:36:02.0660 1812 SCPolicySvc (319c6b309773d063541d01df8ac6f55f) C:\Windows\System32\certprop.dll 00:36:02.0661 1812 SCPolicySvc - ok 00:36:02.0697 1812 SDRSVC (08236c4bce5edd0a0318a438af28e0f7) C:\Windows\System32\SDRSVC.dll 00:36:02.0710 1812 SDRSVC - ok 00:36:02.0745 1812 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 00:36:02.0746 1812 secdrv - ok 00:36:02.0768 1812 seclogon (a59b3a4442c52060cc7a85293aa3546f) C:\Windows\system32\seclogon.dll 00:36:02.0777 1812 seclogon - ok 00:36:02.0813 1812 SENS (dcb7fcdcc97f87360f75d77425b81737) C:\Windows\system32\sens.dll 00:36:02.0819 1812 SENS - ok 00:36:02.0844 1812 SensrSvc (50087fe1ee447009c9cc2997b90de53f) C:\Windows\system32\sensrsvc.dll 00:36:02.0850 1812 SensrSvc - ok 00:36:02.0871 1812 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\drivers\serenum.sys 00:36:02.0872 1812 Serenum - ok 00:36:02.0901 1812 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\drivers\serial.sys 00:36:02.0903 1812 Serial - ok 00:36:02.0919 1812 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\drivers\sermouse.sys 00:36:02.0921 1812 sermouse - ok 00:36:02.0980 1812 SessionEnv (4ae380f39a0032eab7dd953030b26d28) C:\Windows\system32\sessenv.dll 00:36:02.0996 1812 SessionEnv - ok 00:36:03.0011 1812 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys 00:36:03.0013 1812 sffdisk - ok 00:36:03.0028 1812 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys 00:36:03.0029 1812 sffp_mmc - ok 00:36:03.0045 1812 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys 00:36:03.0047 1812 sffp_sd - ok 00:36:03.0062 1812 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\drivers\sfloppy.sys 00:36:03.0063 1812 sfloppy - ok 00:36:03.0121 1812 SharedAccess (d1a079a0de2ea524513b6930c24527a2) C:\Windows\System32\ipnathlp.dll 00:36:03.0129 1812 SharedAccess - ok 00:36:03.0169 1812 ShellHWDetection (414da952a35bf5d50192e28263b40577) C:\Windows\System32\shsvcs.dll 00:36:03.0180 1812 ShellHWDetection - ok 00:36:03.0224 1812 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys 00:36:03.0225 1812 sisagp - ok 00:36:03.0267 1812 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\drivers\SiSRaid2.sys 00:36:03.0268 1812 SiSRaid2 - ok 00:36:03.0302 1812 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\drivers\sisraid4.sys 00:36:03.0304 1812 SiSRaid4 - ok 00:36:03.0328 1812 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys 00:36:03.0331 1812 Smb - ok 00:36:03.0438 1812 SNMPTRAP (6a984831644eca1a33ffeae4126f4f37) C:\Windows\System32\snmptrap.exe 00:36:03.0454 1812 SNMPTRAP - ok 00:36:03.0470 1812 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys 00:36:03.0485 1812 spldr - ok 00:36:03.0548 1812 Spooler (866a43013535dc8587c258e43579c764) C:\Windows\System32\spoolsv.exe 00:36:03.0563 1812 Spooler - ok 00:36:03.0766 1812 sppsvc (cf87a1de791347e75b98885214ced2b8) C:\Windows\system32\sppsvc.exe 00:36:03.0813 1812 sppsvc - ok 00:36:03.0953 1812 sppuinotify (b0180b20b065d89232a78a40fe56eaa6) C:\Windows\system32\sppuinotify.dll 00:36:03.0953 1812 sppuinotify - ok 00:36:04.0052 1812 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys 00:36:04.0058 1812 srv - ok 00:36:04.0111 1812 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys 00:36:04.0117 1812 srv2 - ok 00:36:04.0169 1812 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys 00:36:04.0173 1812 srvnet - ok 00:36:04.0227 1812 SSDPSRV (d887c9fd02ac9fa880f6e5027a43e118) C:\Windows\System32\ssdpsrv.dll 00:36:04.0235 1812 SSDPSRV - ok 00:36:04.0266 1812 SstpSvc (d318f23be45d5e3a107469eb64815b50) C:\Windows\system32\sstpsvc.dll 00:36:04.0273 1812 SstpSvc - ok 00:36:04.0308 1812 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\drivers\stexstor.sys 00:36:04.0309 1812 stexstor - ok 00:36:04.0372 1812 StiSvc (e1fb3706030fb4578a0d72c2fc3689e4) C:\Windows\System32\wiaservc.dll 00:36:04.0382 1812 StiSvc - ok 00:36:04.0426 1812 storflt (472af0311073dceceaa8fa18ba2bdf89) C:\Windows\system32\drivers\vmstorfl.sys 00:36:04.0427 1812 storflt - ok 00:36:04.0460 1812 StorSvc (0bf669f0a910beda4a32258d363af2a5) C:\Windows\system32\storsvc.dll 00:36:04.0467 1812 StorSvc - ok 00:36:04.0504 1812 storvsc (dcaffd62259e0bdb433dd67b5bb37619) C:\Windows\system32\drivers\storvsc.sys 00:36:04.0505 1812 storvsc - ok 00:36:04.0543 1812 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys 00:36:04.0544 1812 swenum - ok 00:36:04.0603 1812 swprv (a28bd92df340e57b024ba433165d34d7) C:\Windows\System32\swprv.dll 00:36:04.0612 1812 swprv - ok 00:36:04.0669 1812 SysMain (36650d618ca34c9d357dfd3d89b2c56f) C:\Windows\system32\sysmain.dll 00:36:04.0688 1812 SysMain - ok 00:36:04.0715 1812 TabletInputService (763fecdc3d30c815fe72dd57936c6cd1) C:\Windows\System32\TabSvc.dll 00:36:04.0724 1812 TabletInputService - ok 00:36:04.0760 1812 TapiSrv (613bf4820361543956909043a265c6ac) C:\Windows\System32\tapisrv.dll 00:36:04.0768 1812 TapiSrv - ok 00:36:04.0800 1812 TBS (b799d9fdb26111737f58288d8dc172d9) C:\Windows\System32\tbssvc.dll 00:36:04.0807 1812 TBS - ok 00:36:04.0927 1812 Tcpip (7fa2e0f8b072bd04b77b421480b6cc22) C:\Windows\system32\drivers\tcpip.sys 00:36:04.0938 1812 Tcpip - ok 00:36:04.0975 1812 TCPIP6 (7fa2e0f8b072bd04b77b421480b6cc22) C:\Windows\system32\DRIVERS\tcpip.sys 00:36:04.0986 1812 TCPIP6 - ok 00:36:05.0033 1812 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys 00:36:05.0033 1812 tcpipreg - ok 00:36:05.0064 1812 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys 00:36:05.0080 1812 TDPIPE - ok 00:36:05.0111 1812 TDTCP (2c2c5afe7ee4f620d69c23c0617651a8) C:\Windows\system32\drivers\tdtcp.sys 00:36:05.0111 1812 TDTCP - ok 00:36:05.0142 1812 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys 00:36:05.0142 1812 tdx - ok 00:36:05.0174 1812 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\DRIVERS\termdd.sys 00:36:05.0174 1812 TermDD - ok 00:36:05.0236 1812 TermService (382c804c92811be57829d8e550a900e2) C:\Windows\System32\termsrv.dll 00:36:05.0236 1812 TermService - ok 00:36:05.0267 1812 Themes (42fb6afd6b79d9fe07381609172e7ca4) C:\Windows\system32\themeservice.dll 00:36:05.0267 1812 Themes - ok 00:36:05.0314 1812 THREADORDER (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll 00:36:05.0314 1812 THREADORDER - ok 00:36:05.0361 1812 TrkWks (4792c0378db99a9bc2ae2de6cfff0c3a) C:\Windows\System32\trkwks.dll 00:36:05.0376 1812 TrkWks - ok 00:36:05.0439 1812 TrustedInstaller (2c49b175aee1d4364b91b531417fe583) C:\Windows\servicing\TrustedInstaller.exe 00:36:05.0439 1812 TrustedInstaller - ok 00:36:05.0470 1812 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys 00:36:05.0470 1812 tssecsrv - ok 00:36:05.0501 1812 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys 00:36:05.0501 1812 TsUsbFlt - ok 00:36:05.0556 1812 TsUsbGD (01246f0baad7b68ec0f472aa41e33282) C:\Windows\system32\drivers\TsUsbGD.sys 00:36:05.0557 1812 TsUsbGD - ok 00:36:05.0606 1812 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys 00:36:05.0609 1812 tunnel - ok 00:36:05.0658 1812 TVALZ (792a8b80f8188aba4b2be271583f3e46) C:\Windows\system32\DRIVERS\TVALZ_O.SYS 00:36:05.0659 1812 TVALZ - ok 00:36:05.0677 1812 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\drivers\uagp35.sys 00:36:05.0679 1812 uagp35 - ok 00:36:05.0714 1812 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys 00:36:05.0720 1812 udfs - ok 00:36:05.0770 1812 UI0Detect (8344fd4fce927880aa1aa7681d4927e5) C:\Windows\system32\UI0Detect.exe 00:36:05.0777 1812 UI0Detect - ok 00:36:05.0813 1812 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys 00:36:05.0815 1812 uliagpkx - ok 00:36:05.0857 1812 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\DRIVERS\umbus.sys 00:36:05.0859 1812 umbus - ok 00:36:05.0891 1812 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\drivers\umpass.sys 00:36:05.0892 1812 UmPass - ok 00:36:05.0932 1812 UmRdpService (409994a8eaceee4e328749c0353527a0) C:\Windows\System32\umrdp.dll 00:36:05.0941 1812 UmRdpService - ok 00:36:05.0999 1812 upnphost (833fbb672460efce8011d262175fad33) C:\Windows\System32\upnphost.dll 00:36:06.0008 1812 upnphost - ok 00:36:06.0052 1812 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\DRIVERS\usbccgp.sys 00:36:06.0055 1812 usbccgp - ok 00:36:06.0099 1812 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys 00:36:06.0103 1812 usbcir - ok 00:36:06.0139 1812 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\DRIVERS\usbehci.sys 00:36:06.0141 1812 usbehci - ok 00:36:06.0202 1812 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys 00:36:06.0207 1812 usbhub - ok 00:36:06.0237 1812 usbohci (e185d44fac515a18d9deddc23c2cdf44) C:\Windows\system32\DRIVERS\usbohci.sys 00:36:06.0239 1812 usbohci - ok 00:36:06.0270 1812 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\drivers\usbprint.sys 00:36:06.0272 1812 usbprint - ok 00:36:06.0314 1812 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS 00:36:06.0316 1812 USBSTOR - ok 00:36:06.0356 1812 usbuhci (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\drivers\usbuhci.sys 00:36:06.0358 1812 usbuhci - ok 00:36:06.0408 1812 usbvideo (45f4e7bf43db40a6c6b4d92c76cbc3f2) C:\Windows\system32\Drivers\usbvideo.sys 00:36:06.0412 1812 usbvideo - ok 00:36:06.0446 1812 UxSms (081e6e1c91aec36758902a9f727cd23c) C:\Windows\System32\uxsms.dll 00:36:06.0454 1812 UxSms - ok 00:36:06.0499 1812 VaultSvc (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 00:36:06.0504 1812 VaultSvc - ok 00:36:06.0543 1812 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys 00:36:06.0543 1812 vdrvroot - ok 00:36:06.0621 1812 vds (c3cd30495687c2a2f66a65ca6fd89be9) C:\Windows\System32\vds.exe 00:36:06.0637 1812 vds - ok 00:36:06.0668 1812 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys 00:36:06.0668 1812 vga - ok 00:36:06.0699 1812 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys 00:36:06.0699 1812 VgaSave - ok 00:36:06.0730 1812 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys 00:36:06.0730 1812 vhdmp - ok 00:36:06.0793 1812 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys 00:36:06.0793 1812 viaagp - ok 00:36:06.0824 1812 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\drivers\viac7.sys 00:36:06.0824 1812 ViaC7 - ok 00:36:06.0855 1812 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys 00:36:06.0855 1812 viaide - ok 00:36:06.0917 1812 vmbus (c2f2911156fdc7817c52829c86da494e) C:\Windows\system32\drivers\vmbus.sys 00:36:06.0917 1812 vmbus - ok 00:36:06.0949 1812 VMBusHID (d4d77455211e204f370d08f4963063ce) C:\Windows\system32\drivers\VMBusHID.sys 00:36:06.0949 1812 VMBusHID - ok 00:36:06.0980 1812 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys 00:36:06.0980 1812 volmgr - ok 00:36:07.0042 1812 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys 00:36:07.0042 1812 volmgrx - ok 00:36:07.0089 1812 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys 00:36:07.0089 1812 volsnap - ok 00:36:07.0150 1812 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\drivers\vsmraid.sys 00:36:07.0152 1812 vsmraid - ok 00:36:07.0228 1812 VSS (209a3b1901b83aeb8527ed211cce9e4c) C:\Windows\system32\vssvc.exe 00:36:07.0242 1812 VSS - ok 00:36:07.0266 1812 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\system32\DRIVERS\vwifibus.sys 00:36:07.0269 1812 vwifibus - ok 00:36:07.0325 1812 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys 00:36:07.0327 1812 vwififlt - ok 00:36:07.0360 1812 W32Time (55187fd710e27d5095d10a472c8baf1c) C:\Windows\system32\w32time.dll 00:36:07.0375 1812 W32Time - ok 00:36:07.0410 1812 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\drivers\wacompen.sys 00:36:07.0412 1812 WacomPen - ok 00:36:07.0460 1812 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys 00:36:07.0463 1812 WANARP - ok 00:36:07.0476 1812 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys 00:36:07.0478 1812 Wanarpv6 - ok 00:36:07.0609 1812 WatAdminSvc (353a04c273ec58475d8633e75ccd5604) C:\Windows\system32\Wat\WatAdminSvc.exe 00:36:07.0619 1812 WatAdminSvc - ok 00:36:07.0698 1812 wbengine (691e3285e53dca558e1a84667f13e15a) C:\Windows\system32\wbengine.exe 00:36:07.0723 1812 wbengine - ok 00:36:07.0758 1812 WbioSrvc (9614b5d29dc76ac3c29f6d2d3aa70e67) C:\Windows\System32\wbiosrvc.dll 00:36:07.0767 1812 WbioSrvc - ok 00:36:07.0814 1812 wcncsvc (34eee0dfaadb4f691d6d5308a51315dc) C:\Windows\System32\wcncsvc.dll 00:36:07.0825 1812 wcncsvc - ok 00:36:07.0854 1812 WcsPlugInService (5d930b6357a6d2af4d7653bdabbf352f) C:\Windows\System32\WcsPlugInService.dll 00:36:07.0863 1812 WcsPlugInService - ok 00:36:07.0945 1812 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\drivers\wd.sys 00:36:07.0947 1812 Wd - ok 00:36:07.0991 1812 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 00:36:08.0006 1812 Wdf01000 - ok 00:36:08.0032 1812 WdiServiceHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll 00:36:08.0039 1812 WdiServiceHost - ok 00:36:08.0053 1812 WdiSystemHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll 00:36:08.0061 1812 WdiSystemHost - ok 00:36:08.0106 1812 WebClient (a9d880f97530d5b8fee278923349929d) C:\Windows\System32\webclnt.dll 00:36:08.0106 1812 WebClient - ok 00:36:08.0153 1812 Wecsvc (760f0afe937a77cff27153206534f275) C:\Windows\system32\wecsvc.dll 00:36:08.0168 1812 Wecsvc - ok 00:36:08.0184 1812 wercplsupport (ac804569bb2364fb6017370258a4091b) C:\Windows\System32\wercplsupport.dll 00:36:08.0199 1812 wercplsupport - ok 00:36:08.0246 1812 WerSvc (08e420d873e4fd85241ee2421b02c4a4) C:\Windows\System32\WerSvc.dll 00:36:08.0246 1812 WerSvc - ok 00:36:08.0293 1812 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys 00:36:08.0293 1812 WfpLwf - ok 00:36:08.0324 1812 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys 00:36:08.0324 1812 WIMMount - ok 00:36:08.0418 1812 WinDefend (3fae8f94296001c32eab62cd7d82e0fd) C:\Program Files\Windows Defender\mpsvc.dll 00:36:08.0433 1812 WinDefend - ok 00:36:08.0449 1812 WinHttpAutoProxySvc - ok 00:36:08.0511 1812 Winmgmt (f62e510b6ad4c21eb9fe8668ed251826) C:\Windows\system32\wbem\WMIsvc.dll 00:36:08.0527 1812 Winmgmt - ok 00:36:08.0605 1812 WinRM (1b91cd34ea3a90ab6a4ef0550174f4cc) C:\Windows\system32\WsmSvc.dll 00:36:08.0636 1812 WinRM - ok 00:36:08.0745 1812 Wlansvc (16935c98ff639d185086a3529b1f2067) C:\Windows\System32\wlansvc.dll 00:36:08.0763 1812 Wlansvc - ok 00:36:08.0816 1812 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys 00:36:08.0817 1812 WmiAcpi - ok 00:36:08.0892 1812 wmiApSrv (6eb6b66517b048d87dc1856ddf1f4c3f) C:\Windows\system32\wbem\WmiApSrv.exe 00:36:08.0896 1812 wmiApSrv - ok 00:36:09.0022 1812 WMPNetworkSvc (3b40d3a61aa8c21b88ae57c58ab3122e) C:\Program Files\Windows Media Player\wmpnetwk.exe 00:36:09.0032 1812 WMPNetworkSvc - ok 00:36:09.0068 1812 WPCSvc (a2f0ec770a92f2b3f9de6d518e11409c) C:\Windows\System32\wpcsvc.dll 00:36:09.0075 1812 WPCSvc - ok 00:36:09.0114 1812 WPDBusEnum (aa53356d60af47eacc85bc617a4f3f66) C:\Windows\system32\wpdbusenum.dll 00:36:09.0122 1812 WPDBusEnum - ok 00:36:09.0187 1812 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys 00:36:09.0189 1812 ws2ifsl - ok 00:36:09.0222 1812 wscsvc (6f5d49efe0e7164e03ae773a3fe25340) C:\Windows\system32\wscsvc.dll 00:36:09.0231 1812 wscsvc - ok 00:36:09.0246 1812 WSearch - ok 00:36:09.0371 1812 wuauserv (fc3ec24fce372c89423e015a2ac1a31e) C:\Windows\system32\wuaueng.dll 00:36:09.0404 1812 wuauserv - ok 00:36:09.0524 1812 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys 00:36:09.0527 1812 WudfPf - ok 00:36:09.0552 1812 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys 00:36:09.0554 1812 WUDFRd - ok 00:36:09.0607 1812 wudfsvc (8d1e1e529a2c9e9b6a85b55a345f7629) C:\Windows\System32\WUDFSvc.dll 00:36:09.0615 1812 wudfsvc - ok 00:36:09.0643 1812 WwanSvc (ff2d745b560f7c71b31f30f4d49f73d2) C:\Windows\System32\wwansvc.dll 00:36:09.0654 1812 WwanSvc - ok 00:36:09.0712 1812 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 00:36:09.0899 1812 \Device\Harddisk0\DR0 - ok 00:36:09.0915 1812 Boot (0x1200) (ac2913c368527d0ce00ddde910a96bc1) \Device\Harddisk0\DR0\Partition0 00:36:09.0915 1812 \Device\Harddisk0\DR0\Partition0 - ok 00:36:09.0931 1812 Boot (0x1200) (35e3c33afff627f50cc6f43f0e227058) \Device\Harddisk0\DR0\Partition1 00:36:09.0931 1812 \Device\Harddisk0\DR0\Partition1 - ok 00:36:09.0931 1812 ============================================================ 00:36:09.0931 1812 Scan finished 00:36:09.0931 1812 ============================================================ 00:36:09.0962 0472 Detected object count: 0 00:36:09.0962 0472 Actual detected object count: 0
OTL scans are obviously quite long and do take a bit longer to analyze but I think I'm going to need to take a look at one on this laptop. Different scans look in different places and sometimes something that doesn't show in one log may show in another. Hopefully, once you complete the steps for Flash Disinfector, we will have stopped any reinfection from reoccuring from any infected USB devices. (Let me know how things seem on that front please).

What I don't like is some of the errors I'm seeing in the event log, combined with what I'm hearing that you are seeing in your browsers but we aren't seeing in the logs. Some of the errors are showing that something is trying to interact with your desktop and that could be the result of malware. Just because we aren't seeing it in the logs we've run, given the symptoms you are still experiencing, I do feel we need to dig deeper.

I'd also like to suggest that you might want to consider uninstalling Yontoo via Control Panel, Programs and Features. While many feel this is a legitimate program, there is much debate about this in the malware fighting community. The choice is certainly yours, but I can tell you that if it were me, I would not want this on my machine. It is often associated with search bars, and allows the manipulation of how pages in your browser may appear without your consent.


OTL Custom Scan

  • Download OTL to your desktop.
  • Right-click and choose Run as Administrator on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hi, the flash disinfector didnt ask me to do anything, i ran it but nothing happened so i assume it does it behind the scenes? I tried to uninstall yontoo but it said "setup initialization error"
Here are the scans:


logfile created on: 26/07/2012 11:57:51 - Run 1
OTL by OldTimer - Version 3.2.54.1 Folder = C:\Users\Lisa\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

766.42 Mb Total Physical Memory | 315.54 Mb Available Physical Memory | 41.17% Memory free
1.75 Gb Paging File | 0.99 Gb Available in Paging File | 56.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.79 Gb Total Space | 196.03 Gb Free Space | 84.21% Space Free | Partition Type: NTFS

Computer Name: LISA-PC | User Name: Lisa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Lisa\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\qtscript4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\qtgui4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\qtnetwork4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\qtsql4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\qtdeclarative4.dll ()
MOD - C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\qtcore4.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()


========== Win32 Services (SafeList) ==========

SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (KSS) – C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Kaspersky Lab ZAO)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (catchme) – C:\Users\Lisa\AppData\Local\Temp\catchme.sys File not found
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (dmvsc) – C:\Windows\System32\drivers\dmvsc.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbGD) – C:\Windows\System32\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (rtl8192se) – C:\Windows\System32\drivers\rtl8192se.sys (Realtek Semiconductor Corporation )
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (PGEffect) – C:\Windows\System32\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV - (TVALZ) – C:\Windows\System32\drivers\TVALZ_O.SYS (TOSHIBA Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3072253

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9F 0B 64 1E BB 6A CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}…000701a04ecee4d
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT3072253
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Lisa\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Lisa\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Lisa\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)


[2012/05/27 22:43:16 | 000,000,000 | —D | M] (No name found) – C:\Users\Lisa\AppData\Roaming\mozilla\Extensions
[2012/05/27 22:21:06 | 000,000,000 | —D | M] (No name found) – C:\Users\Lisa\AppData\Roaming\mozilla\Firefox\extensions
[2012/05/27 22:21:11 | 000,000,000 | —D | M] (uTorrentControl2 Community Toolbar) – C:\Users\Lisa\AppData\Roaming\mozilla\Firefox\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}

========== Chrome ==========

CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Lisa\AppData\Local\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Lisa\AppData\Local\Google\Chrome\Application\20.0.1132.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Lisa\AppData\Local\Google\Chrome\Application\20.0.1132.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Lisa\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Lisa\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: avast! WebRep = C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1456_0\
CHR - Extension: Gmail = C:\Users\Lisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/07/23 13:17:32 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [KSS] C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Kaspersky Lab ZAO)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\System32\GPhotos.scr (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3A38CA1A-8A0F-4B64-A7D2-74F5E09F122E}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{506E067B-D9B7-4F7B-AA19-FE0C4218FDBB}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/07/26 11:50:05 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Users\Lisa\Desktop\OTL.exe
[2012/07/26 00:32:36 | 000,000,000 | —D | C] – C:\Users\Lisa\Desktop\tdsskiller
[2012/07/25 17:30:02 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/07/25 17:29:55 | 000,000,000 | —D | C] – C:\Users\Lisa\AppData\Local\temp
[2012/07/25 17:24:42 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/07/24 22:53:32 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2012/07/23 21:31:50 | 000,000,000 | —D | C] – C:\Users\Lisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan
[2012/07/23 21:30:37 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2012/07/23 21:30:37 | 000,000,000 | —D | C] – C:\Program Files\Kaspersky Lab
[2012/07/23 12:47:46 | 004,585,817 | R— | C] (Swearware) – C:\Users\Lisa\Desktop\ComboFix.exe
[2012/07/23 00:24:45 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/07/23 00:24:45 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/07/23 00:24:45 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/07/23 00:23:14 | 000,000,000 | —D | C] – C:\Qoobox
[2012/07/23 00:22:18 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/07/20 00:03:10 | 000,607,260 | R— | C] (Swearware) – C:\Users\Lisa\Desktop\dds1.scr
[2012/07/19 23:54:18 | 000,607,260 | R— | C] (Swearware) – C:\Users\Lisa\Desktop\dds.scr
[2012/07/19 22:16:49 | 000,000,000 | —D | C] – C:\Users\Lisa\Desktop\New folder
[2012/07/12 23:54:49 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/07/12 23:54:47 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/07/12 23:54:46 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2012/07/12 23:54:46 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/07/12 23:54:44 | 001,800,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/07/12 23:54:43 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/07/12 23:54:39 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/07/12 23:50:16 | 002,345,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/07/12 23:50:06 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\browserchoice.exe
[2012/07/12 17:20:31 | 000,219,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncrypt.dll
[2012/07/12 17:20:13 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml3r.dll
[2012/07/12 17:20:00 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdosys.dll

========== Files - Modified Within 30 Days ==========

[2012/07/26 11:50:08 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\Lisa\Desktop\OTL.exe
[2012/07/26 11:49:08 | 000,132,597 | —- | M] () – C:\Users\Lisa\Desktop\Flash_Disinfector.exe
[2012/07/26 11:44:19 | 000,021,504 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/26 11:44:19 | 000,021,504 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/26 11:41:46 | 000,628,460 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/07/26 11:41:46 | 000,110,612 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/07/26 11:36:10 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/07/26 11:36:05 | 602,738,688 | -HS- | M] () – C:\hiberfil.sys
[2012/07/26 00:19:02 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000UA.job
[2012/07/26 00:14:59 | 002,117,108 | —- | M] () – C:\Users\Lisa\Desktop\tdsskiller.zip
[2012/07/25 23:26:08 | 000,000,922 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000UA.job
[2012/07/25 20:19:03 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000Core.job
[2012/07/25 17:25:16 | 000,000,900 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000Core.job
[2012/07/25 17:13:43 | 004,585,817 | R— | M] (Swearware) – C:\Users\Lisa\Desktop\ComboFix.exe
[2012/07/25 11:02:18 | 118,992,102 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/07/24 20:17:59 | 000,001,067 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/23 21:31:19 | 000,001,047 | —- | M] () – C:\Users\Lisa\Desktop\Kaspersky Security Scan.lnk
[2012/07/23 13:17:32 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2012/07/19 23:57:43 | 000,607,260 | R— | M] (Swearware) – C:\Users\Lisa\Desktop\dds1.scr
[2012/07/19 23:48:01 | 000,607,260 | R— | M] (Swearware) – C:\Users\Lisa\Desktop\dds.scr
[2012/07/13 22:00:27 | 000,409,752 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/07/12 17:26:16 | 000,002,354 | —- | M] () – C:\Users\Lisa\Desktop\Google Chrome.lnk
[2012/07/10 00:30:49 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2012/07/03 17:21:54 | 000,054,232 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2012/07/03 17:21:53 | 000,721,000 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2012/07/03 17:21:53 | 000,353,688 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2012/07/03 17:21:53 | 000,057,656 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2012/07/03 17:21:53 | 000,044,784 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswRdr2.sys
[2012/07/03 17:21:53 | 000,021,256 | —- | M] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2012/07/03 17:21:32 | 000,041,224 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2012/07/03 17:21:28 | 000,227,648 | —- | M] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2012/07/03 13:46:44 | 000,022,344 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2012/07/26 11:49:07 | 000,132,597 | —- | C] () – C:\Users\Lisa\Desktop\Flash_Disinfector.exe
[2012/07/26 00:14:57 | 002,117,108 | —- | C] () – C:\Users\Lisa\Desktop\tdsskiller.zip
[2012/07/24 20:17:59 | 000,001,067 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/23 21:31:50 | 000,001,047 | —- | C] () – C:\Users\Lisa\Desktop\Kaspersky Security Scan.lnk
[2012/07/23 00:24:45 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/07/23 00:24:45 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/07/23 00:24:45 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/07/23 00:24:45 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/07/23 00:24:45 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/01/30 11:51:22 | 000,073,728 | —- | C] () – C:\Windows\System32\RtNicProp32.dll
[2012/01/30 01:52:01 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/11/20 22:29:26 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe

========== LOP Check ==========

[2012/05/27 22:32:26 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\Babylon
[2012/01/30 13:21:23 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\DAEMON Tools Lite
[2012/06/04 12:31:53 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\Media Finder
[2012/03/11 01:42:36 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\Oberon Media
[2012/06/03 19:17:54 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\uTorrent
[2012/01/30 11:51:03 | 000,000,000 | —D | M] – C:\Users\Lisa\AppData\Roaming\WinBatch
[2012/07/25 17:25:16 | 000,000,900 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000Core.job
[2012/07/25 23:26:08 | 000,000,922 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3561299463-2961446174-593319071-1000UA.job
[2012/05/20 13:25:39 | 000,032,638 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2009/06/10 22:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2012/07/25 17:29:52 | 000,010,993 | —- | M] () – C:\ComboFix.txt
[2009/06/10 22:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2012/07/26 11:36:05 | 602,738,688 | -HS- | M] () – C:\hiberfil.sys
[2012/07/26 11:36:06 | 1073,741,824 | -HS- | M] () – C:\pagefile.sys
[2012/07/26 00:35:33 | 000,128,282 | —- | M] () – C:\TDSSKiller.2.7.48.0_26.07.2012_00.33.41_log.txt
[2012/07/26 00:43:46 | 000,122,058 | —- | M] () – C:\TDSSKiller.2.7.48.0_26.07.2012_00.35.40_log.txt
[2012/05/27 22:43:00 | 000,003,031 | —- | M] () – C:\user.js

< %systemroot%\Fonts\*.com >
[2009/07/14 05:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 05:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 05:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 05:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 22:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 02:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
[2010/11/20 22:29:21 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/07/03 17:21:32 | 000,041,224 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 05:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/05/28 09:33:41 | 000,000,221 | -HS- | M] () – C:\Users\Lisa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/07/25 17:13:43 | 004,585,817 | R— | M] (Swearware) – C:\Users\Lisa\Desktop\ComboFix.exe
[2012/07/26 11:49:08 | 000,132,597 | —- | M] () – C:\Users\Lisa\Desktop\Flash_Disinfector.exe
[2012/07/26 11:50:08 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\Lisa\Desktop\OTL.exe
[2012/02/20 01:04:39 | 014,874,472 | —- | M] (Google Inc.) – C:\Users\Lisa\Desktop\picasa39-setup.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-07-24 15:00:13

========== Alternate Data Streams ==========

@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:EFC181EC

< End of report >


OTL Extras logfile created on: 26/07/2012 11:57:51 - Run 1
OTL by OldTimer - Version 3.2.54.1 Folder = C:\Users\Lisa\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

766.42 Mb Total Physical Memory | 315.54 Mb Available Physical Memory | 41.17% Memory free
1.75 Gb Paging File | 0.99 Gb Available in Paging File | 56.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232.79 Gb Total Space | 196.03 Gb Free Space | 84.21% Space Free | Partition Type: NTFS

Computer Name: LISA-PC | User Name: Lisa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0D9F98AE-135E-4CFB-97C7-8179661BDB50}" = lport=138 | protocol=17 | dir=in | app=system |
"{33FA33A7-C25E-4951-BE9C-21375C65CFE7}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{3571EA0B-A938-49B9-82E9-4B0F72AA337A}" = rport=10243 | protocol=6 | dir=out | app=system |
"{3863AC59-B673-44EE-8EED-56C4E61C7233}" = lport=2869 | protocol=6 | dir=in | app=system |
"{3E8EA66C-6221-497E-A566-098BC99D77DA}" = rport=138 | protocol=17 | dir=out | app=system |
"{507D66F5-61DF-43CD-ACEF-EA20FF06B207}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{53F5C71F-EC6B-435B-9787-B08AEFB6A708}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{5EC45837-D73C-49C3-8008-E0A525F539F0}" = lport=445 | protocol=6 | dir=in | app=system |
"{6F30B55D-7CD6-4074-9A45-48EF005675A6}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7F1BCBCD-110B-4BB1-B5CC-65728FC7BA2B}" = lport=139 | protocol=6 | dir=in | app=system |
"{86459B98-7401-4D28-A063-389052486C0A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{8D38E741-DF92-4157-9A7B-4CBAFEEF29F0}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{97076DFE-3514-4235-9AE3-CB7094AE8AA4}" = rport=137 | protocol=17 | dir=out | app=system |
"{A4B9F3E2-B051-491F-A894-439037D13C5A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A7B866E4-79AB-46B9-A742-3F868B765A9A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{C27F7B14-F18F-47DE-940D-6452A603ECDF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C814C4AB-E868-452E-9456-46CE80E8C972}" = lport=137 | protocol=17 | dir=in | app=system |
"{D13072AA-095D-4E80-9D71-81B3D861661D}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{DAE67A92-4BA1-41F5-8E5F-5D648861CF3D}" = rport=139 | protocol=6 | dir=out | app=system |
"{E9A4F9B8-31E1-4AD5-93D9-046653C6C557}" = lport=10243 | protocol=6 | dir=in | app=system |
"{EA6CFE87-CA5D-4176-B18E-2462854ACDE1}" = rport=445 | protocol=6 | dir=out | app=system |
"{EE406BA0-40E2-4D2F-A5F6-94742DE18F55}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0672A0C3-23C9-4D93-A319-4E5A6069E2C6}" = dir=in | app=c:\users\lisa\appdata\local\facebook\video\skype\facebookvideocalling.exe |
"{06AB405E-3447-4BB8-A5F3-08C9C88073BC}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1787127B-1466-4420-B749-A6077FA9C8AB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{17D54D04-F530-408D-AE3C-514223A3B106}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{1A8F4740-150F-4FB7-970B-631D335E78C8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{21B02CD0-3B00-4C2C-A274-68F658DA682A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{2D0617E3-89FB-4D61-9AD4-0BF6AA34B403}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{369CB4BC-BE01-4481-86B8-638BA1D39359}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{3C3794FD-F3ED-4689-8940-7B1F7B9AD389}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{52C63C3D-B3CE-409B-85C2-DB007039641F}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{591357A3-3A1C-4924-865F-357EBE0592CC}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{639A8FC4-4463-49F4-BDF4-65CE5D517A4B}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{6E66E2C9-4F81-4290-AD2A-14C3017B8FEC}" = protocol=6 | dir=out | app=system |
"{7BB5DB91-36F5-49BA-8D62-04680FE6806C}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{80ADEFF0-6B7D-4D99-AD7D-FE3A3A9C761D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8393EF96-1280-4C26-A73B-651E06467F4C}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{90EBC870-6BF7-41B8-ACE7-5E2CA62DE3E3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{984C0526-B922-4FB1-AB19-A4DC1FF62CF2}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{9BD3AEBA-73FF-48DF-892D-C44FCD6DFF33}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A863F45D-10E8-47C4-B1E1-338B6601A7DE}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{B9296E07-74E6-4979-B07B-98E3A4008D46}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C19B892F-19E1-431E-B576-E0CFE8E8FF3F}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D2D66C9A-0B56-4525-8686-475AC263E1A0}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D9A019D4-1424-43D8-9284-8718102D000C}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{F09D3EFD-FB45-4F72-AF10-7F1F23349B19}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0FB630AB-7BD8-40AE-B223-60397D57C3C9}" = Realtek WLAN Driver
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{23B8A91D-680B-462B-87AD-3D70F7341731}" = iTunes
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{56009CA3-423B-41F8-884A-E5B049534F15}" = Kaspersky Security Scan
"{5E6F6CF3-BACC-4144-868C-E14622C658F3}" = TOSHIBA Web Camera Application
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}" = Apple Mobile Device Support
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"Adobe AIR" = Adobe AIR
"avast" = avast! Free Antivirus
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ESET Online Scanner" = ESET Online Scanner v3
"InstallWIX_{56009CA3-423B-41F8-884A-E5B049534F15}" = Kaspersky Security Scan
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Picasa 3" = Picasa 3

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 25/07/2012 12:08:52 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 25/07/2012 12:08:52 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4602981

Error - 25/07/2012 12:08:52 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4602981

Error - 25/07/2012 12:08:53 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 25/07/2012 12:08:53 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4604666

Error - 25/07/2012 12:08:53 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4604666

Error - 25/07/2012 12:08:54 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 25/07/2012 12:08:54 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4605883

Error - 25/07/2012 12:08:54 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4605883

Error - 25/07/2012 12:08:56 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 25/07/2012 12:08:56 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4607224

Error - 25/07/2012 12:08:56 | Computer Name = Lisa-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4607224

Error - 25/07/2012 12:26:23 | Computer Name = Lisa-PC | Source = Google Update | ID = 20
Description =

Error - 26/07/2012 06:37:42 | Computer Name = Lisa-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 25/07/2012 08:51:02 | Computer Name = Lisa-PC | Source = atikmdag | ID = 43029
Description = Display is not active

Error - 25/07/2012 12:08:50 | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the Wlansvc service.

Error - 25/07/2012 12:08:53 | Computer Name = Lisa-PC | Source = atikmdag | ID = 43029
Description = Display is not active

Error - 25/07/2012 12:16:14 | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 25/07/2012 12:21:11 | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 25/07/2012 12:25:40 | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 25/07/2012 15:11:27 | Computer Name = Lisa-PC | Source = DCOM | ID = 10010
Description =

Error - 26/07/2012 06:36:09 | Computer Name = Lisa-PC | Source = atikmdag | ID = 52236
Description = CPLIB :: General - Invalid Parameter

Error - 26/07/2012 06:36:09 | Computer Name = Lisa-PC | Source = atikmdag | ID = 43029
Description = Display is not active

Error - 26/07/2012 06:36:12 | Computer Name = Lisa-PC | Source = Service Control Manager | ID = 7023
Description = The Offline Files service terminated with the following error: %%3


< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI