This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected Computer - Hijack This Log [Solved]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey guys, my computer has been pretty bad lately. Lots of alerts that I have trojans from AVG, and random pop-ups. Can you guys help me out?


Heres my hijack this log.


===============================


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:28:33 PM, on 7/20/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\Pete\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://feed.helperbar.com/?publisher=OPENC…babsrc=lnkry_nt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
O2 - BHO: uTorrentBar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll
O3 - Toolbar: (no name) - !{ae07101b-46d4-4a98-af68-0333ea26e113} - (no file)
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Pete\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - https://juniper.net/dana-cached/sc/JuniperSetupClient.cab
O18 - Protocol: intu-help-qb3 - {C5E479EA-0A65-4B05-8C6C-2FC8CC682EB4} - C:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - Unknown owner - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (file missing)
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: O2FLASH - Unknown owner - C:\Windows\system32\DRIVERS\o2flash.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TOSHIBA HDD Protection (Thpsrv) - Unknown owner - C:\Windows\system32\ThpSrv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

–
End of file - 11714 bytes
Hello Montijoar and welcome back to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Download and run OTL
  • download OTL to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • click Scan all users.
  • under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    consrv.dll
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT

  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • you may need two posts to fit them both in.
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Logs to include with next post:

OTL.txt
Extras.txt
aswMBR log


Thanks

Satchfan
Hey satchfan thankyou very much for the help.

Here is OTL

================================


OTL logfile created on: 7/21/2012 3:39:12 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\Pete\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 1.34 Gb Available Physical Memory | 35.84% Memory free
7.49 Gb Paging File | 5.08 Gb Available in Paging File | 67.72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 372.51 Gb Total Space | 232.41 Gb Free Space | 62.39% Space Free | Partition Type: NTFS

Computer Name: JOCELIN-ARRIK | User Name: Pete | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found –
PRC - [2012/07/21 15:10:04 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\Pete\Desktop\OTL.exe
PRC - [2012/07/18 22:16:44 | 000,913,888 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012/07/11 16:34:17 | 001,536,712 | —- | M] (Adobe Systems, Inc.) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
PRC - [2012/04/26 05:33:16 | 002,743,104 | —- | M] (DT Soft Ltd) – C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
PRC - [2012/01/27 17:08:30 | 002,077,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgtray.exe
PRC - [2011/08/02 12:20:42 | 001,242,448 | —- | M] (Valve Corporation) – C:\Program Files (x86)\Steam\Steam.exe
PRC - [2011/07/28 16:08:12 | 001,259,376 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/07/15 09:56:21 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
PRC - [2010/06/24 20:47:07 | 000,066,872 | —- | M] () – C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2010/01/15 05:49:20 | 000,255,536 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2009/10/13 22:39:42 | 000,024,576 | —- | M] (Intuit) – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
PRC - [2009/07/13 18:14:45 | 000,020,480 | —- | M] () – \\.\globalroot\systemroot\svchost.exe
PRC - [2009/07/13 18:14:45 | 000,020,480 | —- | M] () – \\.\globalroot\systemroot\svchost.exe
PRC - [2009/07/13 18:14:45 | 000,020,480 | —- | M] () – \\.\globalroot\systemroot\svchost.exe
PRC - [2009/07/13 18:14:45 | 000,020,480 | —- | M] () – \\.\globalroot\systemroot\svchost.exe


========== Modules (No Company Name) ==========

MOD - [2012/07/18 22:16:44 | 002,003,424 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012/07/11 16:34:16 | 009,465,032 | —- | M] () – C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll
MOD - [2012/06/19 13:38:23 | 020,313,384 | —- | M] () – C:\Program Files (x86)\Steam\bin\libcef.dll
MOD - [2012/06/19 13:38:15 | 001,099,576 | —- | M] () – C:\Program Files (x86)\Steam\bin\avcodec-53.dll
MOD - [2012/06/19 13:38:15 | 000,895,312 | —- | M] () – C:\Program Files (x86)\Steam\bin\chromehtml.dll
MOD - [2012/06/19 13:38:15 | 000,190,776 | —- | M] () – C:\Program Files (x86)\Steam\bin\avformat-53.dll
MOD - [2012/06/19 13:38:15 | 000,123,192 | —- | M] () – C:\Program Files (x86)\Steam\bin\avutil-51.dll
MOD - [2011/07/28 16:09:42 | 000,096,112 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011/07/28 16:08:12 | 001,259,376 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
MOD - [2011/06/24 22:56:36 | 000,087,328 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 22:56:14 | 001,241,888 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010/11/20 05:19:56 | 000,232,448 | —- | M] () – \\.\globalroot\systemroot\syswow64\mswsock.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2009/08/18 03:36:20 | 000,203,264 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2009/07/08 10:41:02 | 000,531,520 | —- | M] (TOSHIBA Corporation) [Auto | Running] – C:\Windows\SysNative\ThpSrv.exe – (Thpsrv)
SRV:64bit: - [2007/02/12 17:43:44 | 000,065,536 | —- | M] (O2Micro International) [Auto | Running] – C:\Windows\SysNative\drivers\o2flash.exe – (O2FLASH)
SRV - [2012/07/18 22:16:44 | 000,113,120 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/07/11 16:34:17 | 000,250,056 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/05/18 19:02:04 | 000,529,232 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2012/01/12 11:43:34 | 000,655,624 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2010/07/15 09:56:21 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/06/24 20:47:07 | 000,066,872 | —- | M] () [Auto | Running] – C:\Windows\SysWOW64\PnkBstrA.exe – (PnkBstrA)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/01/15 05:49:20 | 000,227,232 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe – (McComponentHostService)
SRV - [2009/10/29 02:02:00 | 003,407,292 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\Windows\SysWOW64\GameMon.des – (npggsvc)
SRV - [2009/10/13 22:39:42 | 000,024,576 | —- | M] (Intuit) [Auto | Running] – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe – (QBCFMonitorService)
SRV - [2009/07/23 21:10:38 | 000,061,440 | —- | M] (Intuit Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe – (QBFCService)
SRV - [2009/06/10 14:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/06/06 13:18:20 | 000,560,184 | —- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\sptd.sys – (sptd)
DRV:64bit: - [2012/02/29 23:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/09/13 19:34:02 | 000,035,664 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\Windows\SysNative\drivers\avgmfx64.sys – (AvgMfx64)
DRV:64bit: - [2011/05/24 21:02:34 | 000,317,520 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgtdia.sys – (AvgTdiA)
DRV:64bit: - [2011/05/10 08:06:08 | 000,051,712 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2011/03/10 23:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/10 23:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/01/15 09:21:04 | 000,036,352 | —- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\VClone.sys – (VClone)
DRV:64bit: - [2011/01/13 23:51:56 | 000,030,840 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Gun64.sys – (Gun)
DRV:64bit: - [2010/12/16 15:58:14 | 000,040,816 | —- | M] (Elaborate Bytes AG) [Kernel | System | Running] – C:\Windows\SysNative\drivers\ElbyCDIO.sys – (ElbyCDIO)
DRV:64bit: - [2010/11/20 06:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 04:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/20 02:37:42 | 000,109,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2010/07/15 09:55:39 | 000,269,904 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgldx64.sys – (AvgLdx64)
DRV:64bit: - [2010/01/25 07:06:48 | 000,620,576 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\rtl819xp.sys – (rtl819xpn64) Realtek RTL8190/RTL8192E 802.11n Wireless LAN (Mini-)
DRV:64bit: - [2010/01/25 07:06:48 | 000,620,576 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\rtl819xp.sys – (rtl819xp) Realtek RTL8190\RTL8192E 802.11n Wireless LAN (Mini-)
DRV:64bit: - [2009/11/13 09:47:38 | 000,067,072 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\L1C62x64.sys – (L1C)
DRV:64bit: - [2009/08/18 04:48:48 | 006,037,504 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmdag.sys – (atikmdag)
DRV:64bit: - [2009/08/03 18:29:08 | 000,686,080 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CHDRT64.sys – (CnxtHdAudService)
DRV:64bit: - [2009/07/13 18:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 18:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 18:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 17:35:32 | 000,012,288 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\serscan.sys – (StillCam)
DRV:64bit: - [2009/06/29 17:16:20 | 000,014,784 | —- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\Thpevm.sys – (Thpevm)
DRV:64bit: - [2009/06/29 11:25:22 | 000,034,880 | —- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\thpdrv.sys – (Thpdrv)
DRV:64bit: - [2009/06/10 14:01:11 | 001,485,312 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\VSTDPV6.SYS – (SrvHsfV92)
DRV:64bit: - [2009/06/10 14:01:11 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\VSTCNXT6.SYS – (SrvHsfWinac)
DRV:64bit: - [2009/06/10 14:01:11 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\VSTAZL6.SYS – (SrvHsfHDA)
DRV:64bit: - [2009/06/10 13:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 13:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 13:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 13:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2009/03/10 17:27:04 | 000,069,536 | —- | M] (O2Micro ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\o2mdgx64.sys – (O2MDGRDR)
DRV:64bit: - [2007/11/09 06:00:30 | 000,026,968 | —- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\TVALZ_O.SYS – (TVALZ)
DRV - [2009/07/13 18:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
DRV - [2005/01/01 02:43:08 | 000,004,682 | —- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\npptNT2.sys – (NPPTNT2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2786678


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://feed.helperbar.com/?publisher=OPENC…babsrc=lnkry_nt
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 4F F3 B7 92 00 92 CC 01 [binary data]
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes\{274127B3-DF86-4E2A-B831-3E7212A1DD0B}: "URL" = http://websearch.ask.com/redirect?client=i…CE-67C91BFE3FFF
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes\{A9E18AC0-B8FF-4044-ADBE-2F562F5BD88D}: "URL" = http://ws.infospace.com/playsushi_tbar/ws/…w={searchTerms}
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2786678
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=IEFM1&q="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..keyword.URL: "http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=US&userid=2ad75993-39a7-4b76-b14b-0899ab600fa5&affid=110774&searchtype=ds&babsrc=lnkry&q="


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@gametap.com/npdd,version=1.0: C:\Program Files (x86)\Downloader\npdd.dll (Metaboli)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.3.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.3.1: C:\Program Files (x86)\Oracle\JavaFX 2.0 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\Pete\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll File not found
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Pete\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files (x86)\AVG\AVG9\Firefox [2011/09/13 19:34:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/04/04 14:56:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/07/18 22:16:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/28 10:31:26 | 000,000,000 | —D | M]

[2012/06/26 12:19:54 | 000,000,000 | —D | M] (No name found) – C:\Users\Pete\AppData\Roaming\mozilla\Extensions
[2012/07/18 16:42:10 | 000,000,000 | —D | M] (No name found) – C:\Users\Pete\AppData\Roaming\mozilla\Firefox\Profiles\39ea4nyv.default\extensions
[2012/07/18 16:42:10 | 000,000,000 | —D | M] (uTorrentBar Community Toolbar) – C:\Users\Pete\AppData\Roaming\mozilla\Firefox\Profiles\39ea4nyv.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2012/07/08 10:10:47 | 000,000,000 | —D | M] ("Codec-V") – C:\Users\Pete\AppData\Roaming\mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]
[2012/06/22 20:05:14 | 000,002,343 | —- | M] () – C:\Users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\searchplugins\askcom.xml
[2012/06/06 13:01:28 | 000,002,519 | —- | M] () – C:\Users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\searchplugins\Search_Results.xml
[2012/06/23 11:28:19 | 000,002,474 | —- | M] () – C:\Users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\searchplugins\Web Search.xml
[2012/06/26 12:19:54 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/04/04 14:56:45 | 000,000,000 | —D | M] (DivX Plus Web Player HTML5 ) – C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
[2011/07/17 11:27:16 | 000,330,316 | —- | M] () (No name found) – C:\USERS\PETE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\39EA4NYV.DEFAULT\EXTENSIONS\[removed]
[2012/07/18 22:16:44 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/10/17 18:41:11 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/06/06 13:01:28 | 000,002,519 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
[2011/11/14 14:28:00 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.searchnu.com/406
CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://www.ask.com/?l=dis&o=APN10111cr&gct=hp
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\19.0.1084.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\19.0.1084.56\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\19.0.1084.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Downloader Detector (Enabled) = C:\Program Files (x86)\Downloader\npdd.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U3 (Enabled) = C:\Program Files (x86)\Oracle\JavaFX 2.0 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.30.255 (Enabled) = C:\Windows\system32\npDeployJava1.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Pete\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Pete\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: YouTube = C:\Users\Pete\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Google Search = C:\Users\Pete\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: Google Search = C:\Users\Pete\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Codec-V = C:\Users\Pete\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpnbdefcbnoefmmcpelplabbkfmfhlho\1.14.36_0\
CHR - Extension: Codec-V = C:\Users\Pete\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpnbdefcbnoefmmcpelplabbkfmfhlho\1.17.48_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Pete\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Gmail = C:\Users\Pete\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\
CHR - Extension: Gmail = C:\Users\Pete\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 14:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - !{ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..\Run: [ThpSrv] C:\Windows\SysNative\thpsrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKU\S-1-5-19..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun File not found
O4 - HKU\S-1-5-20..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun File not found
O4 - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000..\Run: [DAEMON Tools Pro Agent] C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000..\Run: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent File not found
O4 - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000..\Run: [Facebook Update] C:\Users\Pete\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\System32\winrnr.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.3.1)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8B4401F4-F963-4303-AB34-FB34474D6F42}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\intu-help-qb3 - No CLSID value found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\qbwc - No CLSID value found
O18 - Protocol\Handler\intu-help-qb3 {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - C:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{62d85b3e-3d37-11e1-aa4d-00238be545b8}\Shell - "" = AutoRun
O33 - MountPoints2\{62d85b3e-3d37-11e1-aa4d-00238be545b8}\Shell\AutoRun\command - "" = E:\autorun.exe
O33 - MountPoints2\{663f2668-50c8-11df-b7d0-00238be545b8}\Shell - "" = AutoRun
O33 - MountPoints2\{663f2668-50c8-11df-b7d0-00238be545b8}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{71fbaa3a-8ee9-11e1-a8a7-00238be545b8}\Shell - "" = AutoRun
O33 - MountPoints2\{71fbaa3a-8ee9-11e1-a8a7-00238be545b8}\Shell\AutoRun\command - "" = F:\Setup.exe
O33 - MountPoints2\{71fbaa3a-8ee9-11e1-a8a7-00238be545b8}\Shell\setup\command - "" = F:\setup.exe
O33 - MountPoints2\{b0595c36-1e71-11df-897d-00238be545b8}\Shell - "" = AutoRun
O33 - MountPoints2\{b0595c36-1e71-11df-897d-00238be545b8}\Shell\AutoRun\command - "" = F:\MI.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\MI.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/07/21 15:09:55 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Users\Pete\Desktop\OTL.exe
[2012/07/20 19:10:57 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\svchost.exe
[2012/07/20 13:30:48 | 000,000,000 | —D | C] – C:\c774baca38044aeb2e6250e48a751daf
[2012/07/20 13:30:14 | 000,000,000 | —D | C] – C:\66bab871d1c4b24af42e95e990d178
[2012/07/18 23:58:02 | 000,000,000 | -HSD | C] – C:\Windows\SysWow64\%APPDATA%
[2012/07/10 12:10:25 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3r.dll
[2012/07/10 12:10:25 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msxml3r.dll
[2012/07/10 12:10:23 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2012/07/10 12:09:58 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cdosys.dll
[2012/07/10 12:09:57 | 001,133,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdosys.dll
[2012/06/23 11:35:35 | 000,000,000 | —D | C] – C:\Users\Pete\AppData\Local\Macromedia
[2012/06/22 20:04:48 | 000,000,000 | —D | C] – C:\Users\Pete\AppData\Local\APN
[2012/06/22 20:04:39 | 000,000,000 | —D | C] – C:\Users\Pete\AppData\Roaming\NCH Software
[2012/06/22 20:04:39 | 000,000,000 | —D | C] – C:\ProgramData\NCH Software
[2012/06/22 20:04:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
[2012/06/22 20:04:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audio Related Programs
[2012/06/22 20:04:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\NCH Software
[2012/06/22 19:53:04 | 000,000,000 | —D | C] – C:\Users\Pete\Desktop\Arrik DROID
[2012/06/21 21:39:59 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/21 21:39:58 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/21 21:39:58 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/21 21:39:34 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/21 21:39:34 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/21 21:39:34 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/21 21:39:16 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/21 21:39:16 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe

========== Files - Modified Within 30 Days ==========

[2012/07/21 15:34:18 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/21 15:13:43 | 000,000,000 | —- | M] () – C:\Users\Pete\AppData\Local\prvlcl.dat
[2012/07/21 15:13:07 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/21 15:11:18 | 000,014,832 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/21 15:11:18 | 000,014,832 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/21 15:10:14 | 101,926,143 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2012/07/21 15:10:04 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\Pete\Desktop\OTL.exe
[2012/07/21 15:03:50 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/21 15:03:11 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/07/21 15:03:04 | 3018,596,352 | -HS- | M] () – C:\hiberfil.sys
[2012/07/20 22:08:02 | 000,000,924 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3216521362-3930712179-4014682732-1000UA.job
[2012/07/18 22:16:47 | 000,002,048 | —- | M] () – C:\Users\Pete\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/07/15 17:21:26 | 000,000,450 | -H– | M] () – C:\Windows\tasks\Norton Security Scan for Pete.job
[2012/07/15 16:08:00 | 000,000,902 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3216521362-3930712179-4014682732-1000Core.job
[2012/07/15 11:03:50 | 000,000,366 | —- | M] () – C:\Windows\tasks\Driver Fetch.job
[2012/07/11 18:19:22 | 000,000,183 | —- | M] () – C:\Windows\SysWow64\msxkwn.vxp
[2012/07/11 18:03:34 | 000,000,061 | —- | M] () – C:\Windows\TaxACT11.ini
[2012/07/11 16:34:16 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/07/11 16:34:16 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/07/11 15:23:25 | 000,434,048 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/30 02:48:42 | 000,863,246 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/30 02:48:42 | 000,719,870 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/30 02:48:42 | 000,144,228 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/26 21:53:23 | 000,000,866 | —- | M] () – C:\Users\Public\Desktop\Cache Cleaner.lnk
[2012/06/26 12:43:23 | 000,001,137 | —- | M] () – C:\Users\Pete\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk

========== Files Created - No Company Name ==========

[2012/07/18 23:47:45 | 000,232,960 | —- | C] () – C:\Windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\U\00000008.@
[2012/07/18 23:47:43 | 000,080,896 | —- | C] () – C:\Windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\U\80000064.@
[2012/07/18 23:47:43 | 000,000,804 | —- | C] () – C:\Windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\L\00000004.@
[2012/07/18 23:47:40 | 000,092,160 | —- | C] () – C:\Windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\U\80000032.@
[2012/07/18 23:47:12 | 000,001,632 | —- | C] () – C:\Windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\U\000000cb.@
[2012/07/18 23:47:10 | 000,016,896 | —- | C] () – C:\Windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\U\80000000.@
[2012/07/18 23:46:38 | 000,002,048 | —- | C] () – C:\Windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\U\00000004.@
[2012/06/26 12:43:23 | 000,001,137 | —- | C] () – C:\Users\Pete\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/06/22 20:04:33 | 000,001,134 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WavePad Sound Editor.lnk
[2012/02/20 16:01:21 | 000,000,145 | —- | C] () – C:\Users\Pete\.appletviewer
[2012/01/22 18:33:25 | 000,000,061 | —- | C] () – C:\Windows\TaxACT11.ini
[2012/01/12 11:29:53 | 000,000,600 | —- | C] () – C:\Users\Pete\AppData\Local\PUTTY.RND
[2012/01/10 12:08:18 | 000,002,048 | -HS- | C] () – C:\Windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\@
[2012/01/10 12:08:18 | 000,002,048 | -HS- | C] () – C:\Users\Pete\AppData\Local\{86b67214-cacf-3544-f67a-920439385c0d}\@
[2011/01/05 21:42:08 | 000,000,048 | —- | C] () – C:\Windows\TaxACT10.ini
[2010/07/10 21:39:25 | 007,114,752 | —- | C] () – C:\Users\Pete\Critical Thinking 5.1 (Backup Jul 10,2010 09 39 PM).QBB
[2010/06/15 23:05:23 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/05/13 22:23:10 | 000,007,597 | —- | C] () – C:\Users\Pete\AppData\Local\Resmon.ResmonCfg
[2010/03/31 15:58:29 | 000,000,000 | —- | C] () – C:\Users\Pete\AppData\Local\prvlcl.dat
[2010/02/22 17:36:08 | 000,004,608 | —- | C] () – C:\Users\Pete\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/20 16:25:27 | 000,000,632 | RHS- | C] () – C:\Users\Pete\ntuser.pol

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/25 23:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/25 22:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 18:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/25 22:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/30 22:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/25 22:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/24 23:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/24 23:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/25 23:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 05:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/02 23:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/24 22:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/24 22:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/30 23:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/02 22:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2009/10/30 23:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/02 22:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 18:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/30 23:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/25 23:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/02 23:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[2010/11/20 06:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: SVCHOST.EXE >
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 18:14:45 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=2CEFF13ACE25A40BD8D97654944297CD – C:\Windows\svchost.exe
[2009/07/13 18:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 18:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 18:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 18:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 05:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 05:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 18:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 18:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 06:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 06:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010/11/20 06:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 06:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 18:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 00:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/27 23:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: TOSHIBA MK4055GSX ATA Device
Partitions: 2
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 0.00GB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 373.00GB
Starting Offset: 105906176
Hidden sectors: 0


========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\System32\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\System32\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction

< End of report >
Extras


======================================


OTL Extras logfile created on: 7/21/2012 3:39:12 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\Pete\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 1.34 Gb Available Physical Memory | 35.84% Memory free
7.49 Gb Paging File | 5.08 Gb Available in Paging File | 67.72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 372.51 Gb Total Space | 232.41 Gb Free Space | 62.39% Space Free | Partition Type: NTFS

Computer Name: JOCELIN-ARRIK | User Name: Pete | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_USERS\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{26A24AE4-039D-4CA4-87B4-2F86416026FF}" = Java™ 6 Update 26 (64-bit)
"{7D220A57-969F-4D09-9297-D48195A8ABDD}" = HP Deskjet 3050 J610 series Basic Device Software
"{860B418B-F90B-465A-BC1D-04B518045C72}" = HP Deskjet 3050 J610 series Product Improvement Study
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{94A90C69-71C1-470A-88F5-AA47ECC96B40}" = TOSHIBA HDD Protection
"{9ACF3FDB-C8E6-444C-8C64-13A221F7BFFD}" = Microsoft SQL Server Native Client
"{B636C9B9-A3F2-4DCE-ADCC-72E095018385}" = Microsoft SQL Server VSS Writer
"{B8AD779A-82DA-4365-A7D0-AD3DCFC55CFF}" = Apple Mobile Device Support
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240CD}" = WinZip 16.0
"{CF8FFD12-602B-422D-AF1D-511B411E7632}" = iTunes
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"CNXT_AUDIO" = Conexant HD Audio
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{06A9E630-DBA6-4D92-9DE7-A235AA6496C7}" = QuickBooks
"{0700E22B-A423-40A5-BD20-04BF618CA0F9}" = QuickBooks Premier: Accountant Edition 2010
"{1111706F-666A-4037-7777-203328764D10}" = JavaFX 2.0.3
"{2222706F-666A-4037-7777-203328764D10}" = JavaFX 2.0.3 SDK
"{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java™ 6 Update 30
"{26A24AE4-039D-4CA4-87B4-2F83217003FF}" = Java™ 7 Update 3
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{32A3A4F4-B792-11D6-A78A-00B0D0170030}" = Java™ SE Development Kit 7 Update 3
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{5A3F6A80-7913-475E-8B96-477A952CFA43}" = SupportSoft Assisted Service
"{5D96E2B1-D9AC-46E0-9073-425C5F63E338}" = Touch and Launch
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B4AD1A9-E73A-4184-9D6B-072F8A3C5EBA}" = VoiceOver Kit
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7694E0B1-2332-448B-9235-929F84B41E3F}" = Active@ ISO Burner
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{81F1814D-8658-72CC-D370-A08E1014EF03}" = Pandora
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{99011A6E-5200-11DE-BDB8-7ACD56D89593}" = Rosetta Stone Version 3
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.1
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B6EC7388-E277-4A5B-8C8F-71067A41BA64}" = TextPad 5
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}" = HP Deskjet 3050 J610 series Help
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"AudibleDownloadManager" = Audible Download Manager
"AVG9Uninstall" = AVG Free 9.0
"com.pandora.desktop.FB9956FD96E03239939108614098AD95535EE674.1" = Pandora
"DAEMON Tools Pro" = DAEMON Tools Pro
"DivX Setup" = DivX Setup
"Downloader" = Downloader
"ESET Online Scanner" = ESET Online Scanner v3
"Google Chrome" = Google Chrome
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Photo Creations" = HP Photo Creations
"Juniper_Setup_Client Activex Control" = Juniper Networks Setup Client Activex Control
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Microsoft Visual Studio 2005 Tools for Office Runtime
"Mozilla Firefox 14.0.1 (x86 en-US)" = Mozilla Firefox 14.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NSS" = Norton Security Scan
"Origin" = Origin
"Premiumplay Codec-C" = Premiumplay Codec-C
"Steam App 620" = Portal 2
"TaxACT 2011 - 1040 Edition" = TaxACT 2011 - 1040 Edition
"TaxACT 2011 California" = TaxACT 2011 California
"uTorrent" = µTorrent
"uTorrentBar Toolbar" = uTorrentBar Toolbar
"VirtualCloneDrive" = VirtualCloneDrive
"WavePad" = WavePad Sound Editor
"Zoo Tycoon 1.0" = Zoo Tycoon: Complete Collection

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager
"Juniper_Networks_Cache_Cleaner 6.5.0" = Juniper Networks Cache Cleaner 6.5.0
"Juniper_Setup_Client" = Juniper Networks Setup Client

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 7/20/2012 9:52:32 PM | Computer Name = Jocelin-Arrik | Source = MSSQL$MSSMLBIZ | ID = 5173
Description = One or more files do not match the primary file of the database. If
you are attempting to attach a database, retry the operation with the correct files.
If this is an existing database, the file may be corrupted and should be restored
from a backup.

Error - 7/20/2012 9:52:34 PM | Computer Name = Jocelin-Arrik | Source = MsiInstaller | ID = 10005
Description =

Error - 7/20/2012 10:10:11 PM | Computer Name = Jocelin-Arrik | Source = MSSQL$MSSMLBIZ | ID = 5173
Description = One or more files do not match the primary file of the database. If
you are attempting to attach a database, retry the operation with the correct files.
If this is an existing database, the file may be corrupted and should be restored
from a backup.

Error - 7/20/2012 10:10:11 PM | Computer Name = Jocelin-Arrik | Source = MSSQL$MSSMLBIZ | ID = 5173
Description = One or more files do not match the primary file of the database. If
you are attempting to attach a database, retry the operation with the correct files.
If this is an existing database, the file may be corrupted and should be restored
from a backup.

Error - 7/21/2012 2:48:28 AM | Computer Name = Jocelin-Arrik | Source = MSSQL$MSSMLBIZ | ID = 5173
Description = One or more files do not match the primary file of the database. If
you are attempting to attach a database, retry the operation with the correct files.
If this is an existing database, the file may be corrupted and should be restored
from a backup.

Error - 7/21/2012 2:48:28 AM | Computer Name = Jocelin-Arrik | Source = MSSQL$MSSMLBIZ | ID = 5173
Description = One or more files do not match the primary file of the database. If
you are attempting to attach a database, retry the operation with the correct files.
If this is an existing database, the file may be corrupted and should be restored
from a backup.

Error - 7/21/2012 2:48:31 AM | Computer Name = Jocelin-Arrik | Source = MsiInstaller | ID = 10005
Description =

Error - 7/21/2012 6:03:48 PM | Computer Name = Jocelin-Arrik | Source = MSSQL$MSSMLBIZ | ID = 5173
Description = One or more files do not match the primary file of the database. If
you are attempting to attach a database, retry the operation with the correct files.
If this is an existing database, the file may be corrupted and should be restored
from a backup.

Error - 7/21/2012 6:03:48 PM | Computer Name = Jocelin-Arrik | Source = MSSQL$MSSMLBIZ | ID = 5173
Description = One or more files do not match the primary file of the database. If
you are attempting to attach a database, retry the operation with the correct files.
If this is an existing database, the file may be corrupted and should be restored
from a backup.

Error - 7/21/2012 6:36:42 PM | Computer Name = Jocelin-Arrik | Source = Application Hang | ID = 1002
Description = The program OTL.exe version 3.2.54.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: ec4 Start Time:
01cd678d9961086a Termination Time: 47 Application Path: C:\Users\Pete\Desktop\OTL.exe

Report
Id:

[ System Events ]
Error - 7/20/2012 10:10:01 PM | Computer Name = Jocelin-Arrik | Source = Service Control Manager | ID = 7003
Description = The IKE and AuthIP IPsec Keying Modules service depends the following
service: BFE. This service might not be installed.

Error - 7/20/2012 10:10:02 PM | Computer Name = Jocelin-Arrik | Source = Service Control Manager | ID = 7023
Description = The Function Discovery Resource Publication service terminated with
the following error: %%-2147024891

Error - 7/20/2012 10:10:04 PM | Computer Name = Jocelin-Arrik | Source = Service Control Manager | ID = 7003
Description = The IPsec Policy Agent service depends the following service: BFE.
This service might not be installed.

Error - 7/21/2012 2:49:10 AM | Computer Name = Jocelin-Arrik | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Microsoft SQL Server 2005 Express Edition Service Pack 4
(KB2463332).

Error - 7/21/2012 6:03:11 PM | Computer Name = Jocelin-Arrik | Source = atikmdag | ID = 52236
Description = CPLIB :: General - Invalid Parameter

Error - 7/21/2012 6:03:11 PM | Computer Name = Jocelin-Arrik | Source = atikmdag | ID = 43029
Description = Display is not active

Error - 7/21/2012 6:03:25 PM | Computer Name = Jocelin-Arrik | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060

Error - 7/21/2012 6:03:28 PM | Computer Name = Jocelin-Arrik | Source = Service Control Manager | ID = 7003
Description = The IKE and AuthIP IPsec Keying Modules service depends the following
service: BFE. This service might not be installed.

Error - 7/21/2012 6:03:30 PM | Computer Name = Jocelin-Arrik | Source = Service Control Manager | ID = 7023
Description = The Function Discovery Resource Publication service terminated with
the following error: %%-2147024891

Error - 7/21/2012 6:03:32 PM | Computer Name = Jocelin-Arrik | Source = Service Control Manager | ID = 7003
Description = The IPsec Policy Agent service depends the following service: BFE.
This service might not be installed.


< End of report >
and that last one ====================== aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-07-21 19:34:34 —————————– 19:34:34.764 OS Version: Windows x64 6.1.7601 Service Pack 1 19:34:34.764 Number of processors: 2 586 0x301 19:34:34.764 ComputerName: JOCELIN-ARRIK UserName: Pete 19:34:42.649 Initialize success 19:36:56.636 AVAST engine defs: 12072101 19:37:25.557 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-4 19:37:25.557 Disk 0 Vendor: TOSHIBA_MK4055GSX FG011M Size: 381554MB BusType: 11 19:37:25.557 Device \Driver\atapi -> MajorFunction fffffa80050235e8 19:37:25.577 Disk 0 MBR read successfully 19:37:25.587 Disk 0 MBR scan 19:37:25.597 Disk 0 Windows 7 default MBR code 19:37:25.597 Disk 0 MBR hidden 19:37:25.607 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 19:37:25.617 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 381452 MB offset 206848 19:37:25.647 Disk 0 scanning C:\Windows\system32\drivers 19:37:49.544 Service scanning 19:38:37.847 Modules scanning 19:38:37.862 Disk 0 trace - called modules: 19:38:37.862 ntoskrnl.exe CLASSPNP.SYS disk.sys thpdrv.sys >>UNKNOWN [0xfffffa80050235e8]<< 19:38:37.894 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004af1790] 19:38:37.909 3 CLASSPNP.SYS[fffff88001baa43f] -> nt!IofCallDriver -> \Device\THPDRV1[0xfffffa8004aef060] 19:38:37.925 5 thpdrv.sys[fffff88001af30d0] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-4[0xfffffa80044e8060] 19:38:37.925 \Driver\atapi[0xfffffa8004ff0060] -> IRP_MJ_CREATE -> 0xfffffa80050235e8 19:38:42.033 AVAST engine scan C:\Windows 19:38:46.048 AVAST engine scan C:\Windows\system32 19:42:16.352 File: C:\Windows\assembly\GAC_32\Desktop.ini **INFECTED** Win32:Sirefef-PL [Rtk] 19:42:21.243 File: C:\Windows\assembly\GAC_64\Desktop.ini **INFECTED** Win32:Sirefef-PL [Rtk] 19:44:26.785 AVAST engine scan C:\Windows\system32\drivers 19:44:45.914 AVAST engine scan C:\Users\Pete 19:59:22.311 Disk 0 MBR has been saved successfully to "C:\Users\Pete\Desktop\MBR.dat" 19:59:22.321 The log file has been saved successfully to "C:\Users\Pete\Desktop\aswMBR.txt"
A couple of observations before we start:

FIRST

P2P - I see you have P2P software, (uTorrent), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

NEXT

Ask Toolbar

Uninstall Ask Toolbar if it was not installed on purpose.

See here for more info.

If you choose to follow my recommendation then please uninstall the following programs if present:

Ask Toolbar or anything related to Ask

===================================================

You have a very nasty infection there so let’s get started cleaning it up.

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
    IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
    IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
    IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2786678
    IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
    IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
    IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://feed.helperbar.com/?publisher=OPENC…babsrc=lnkry_nt
    IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
    IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
    IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
    IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
    IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes\{274127B3-DF86-4E2A-B831-3E7212A1DD0B}: "URL" = http://websearch.ask.com/redirect?client=i…CE-67C91BFE3FFF
    IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
    IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes\{A9E18AC0-B8FF-4044-ADBE-2F562F5BD88D}: "URL" = http://ws.infospace.com/playsushi_tbar/ws/…w={searchTerms}
    IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2786678
    CHR - homepage: http://www.searchnu.com/406
    O3:64bit: - HKLM\..\Toolbar: (no name) - !{ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
    O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - !{ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O4 - HKU\S-1-5-19..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun File not found
    O4 - HKU\S-1-5-20..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun File not found
    O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
    O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\System32\winrnr.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\System32\winrnr.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\System32\winrnr.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\winrnr.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\System32\winrnr.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\System32\winrnr.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\System32\winrnr.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\System32\winrnr.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\System32\winrnr.dll File not found
    O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16:64bit: - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
    O18:64bit: - Protocol\Handler\intu-help-qb3 - No CLSID value found
    O18:64bit: - Protocol\Handler\qbwc - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • post a new OTL log (don't check the boxes beside LOP Check or Purity this time)

===================================================

Please run these in the order requested.

Run TDSSKiller

Please download TDSSKiller.zip
  • extract it to your desktop
  • double click TDSSKiller.exe
  • press Start Scan

    only if Malicious objects are found then ensure Cure is selected. Do not change it to Delete or Quarantine as it may delete infected files that are required for Windows to operate properly.

  • click Continue > Reboot now

  • copy and paste the log in your next reply
  • a copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_*** (*** denotes version & date)

======================================================

Download and run ComboFix

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It MUST be saved directly to your desktop. Choose save as and then make sure you choose Desktop

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • when finished, it will produce a report for you.
  • please post the C:\ComboFix.txt for further review.
Logs to include in the next post:

OTL fix log
New OTL log
TDSSKiller log
ComboFix.txt


Please copy/paste them in your reply, not attach them.

Thanks

Satchfan
Before I post the logs, seems like I can't find Ask Toolbar on my Programs and Features list. Any specific way to get it removed? I uninstalled utorrent. Thank you for the suggestions. Logs coming up.
I ran otl. My computer restarted and everything however now it cannot connect to the internet. The error brought up says "windows could not automatically detect this networks proxy settings." I have no clue how to fix it.
OTL Fix Log


======


OTL logfile created on: 7/21/2012 3:39:12 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Users\Pete\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 1.34 Gb Available Physical Memory | 35.84% Memory free
7.49 Gb Paging File | 5.08 Gb Available in Paging File | 67.72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 372.51 Gb Total Space | 232.41 Gb Free Space | 62.39% Space Free | Partition Type: NTFS

Computer Name: JOCELIN-ARRIK | User Name: Pete | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found –
PRC - [2012/07/21 15:10:04 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\Pete\Desktop\OTL.exe
PRC - [2012/07/18 22:16:44 | 000,913,888 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012/07/11 16:34:17 | 001,536,712 | —- | M] (Adobe Systems, Inc.) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
PRC - [2012/04/26 05:33:16 | 002,743,104 | —- | M] (DT Soft Ltd) – C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
PRC - [2012/01/27 17:08:30 | 002,077,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgtray.exe
PRC - [2011/08/02 12:20:42 | 001,242,448 | —- | M] (Valve Corporation) – C:\Program Files (x86)\Steam\Steam.exe
PRC - [2011/07/28 16:08:12 | 001,259,376 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/07/15 09:56:21 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
PRC - [2010/06/24 20:47:07 | 000,066,872 | —- | M] () – C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2010/01/15 05:49:20 | 000,255,536 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2009/10/13 22:39:42 | 000,024,576 | —- | M] (Intuit) – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
PRC - [2009/07/13 18:14:45 | 000,020,480 | —- | M] () – \\.\globalroot\systemroot\svchost.exe
PRC - [2009/07/13 18:14:45 | 000,020,480 | —- | M] () – \\.\globalroot\systemroot\svchost.exe
PRC - [2009/07/13 18:14:45 | 000,020,480 | —- | M] () – \\.\globalroot\systemroot\svchost.exe
PRC - [2009/07/13 18:14:45 | 000,020,480 | —- | M] () – \\.\globalroot\systemroot\svchost.exe


========== Modules (No Company Name) ==========

MOD - [2012/07/18 22:16:44 | 002,003,424 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012/07/11 16:34:16 | 009,465,032 | —- | M] () – C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll
MOD - [2012/06/19 13:38:23 | 020,313,384 | —- | M] () – C:\Program Files (x86)\Steam\bin\libcef.dll
MOD - [2012/06/19 13:38:15 | 001,099,576 | —- | M] () – C:\Program Files (x86)\Steam\bin\avcodec-53.dll
MOD - [2012/06/19 13:38:15 | 000,895,312 | —- | M] () – C:\Program Files (x86)\Steam\bin\chromehtml.dll
MOD - [2012/06/19 13:38:15 | 000,190,776 | —- | M] () – C:\Program Files (x86)\Steam\bin\avformat-53.dll
MOD - [2012/06/19 13:38:15 | 000,123,192 | —- | M] () – C:\Program Files (x86)\Steam\bin\avutil-51.dll
MOD - [2011/07/28 16:09:42 | 000,096,112 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011/07/28 16:08:12 | 001,259,376 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
MOD - [2011/06/24 22:56:36 | 000,087,328 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 22:56:14 | 001,241,888 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010/11/20 05:19:56 | 000,232,448 | —- | M] () – \\.\globalroot\systemroot\syswow64\mswsock.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2009/08/18 03:36:20 | 000,203,264 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2009/07/08 10:41:02 | 000,531,520 | —- | M] (TOSHIBA Corporation) [Auto | Running] – C:\Windows\SysNative\ThpSrv.exe – (Thpsrv)
SRV:64bit: - [2007/02/12 17:43:44 | 000,065,536 | —- | M] (O2Micro International) [Auto | Running] – C:\Windows\SysNative\drivers\o2flash.exe – (O2FLASH)
SRV - [2012/07/18 22:16:44 | 000,113,120 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/07/11 16:34:17 | 000,250,056 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/05/18 19:02:04 | 000,529,232 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2012/01/12 11:43:34 | 000,655,624 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2010/07/15 09:56:21 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/06/24 20:47:07 | 000,066,872 | —- | M] () [Auto | Running] – C:\Windows\SysWOW64\PnkBstrA.exe – (PnkBstrA)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/01/15 05:49:20 | 000,227,232 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe – (McComponentHostService)
SRV - [2009/10/29 02:02:00 | 003,407,292 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\Windows\SysWOW64\GameMon.des – (npggsvc)
SRV - [2009/10/13 22:39:42 | 000,024,576 | —- | M] (Intuit) [Auto | Running] – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe – (QBCFMonitorService)
SRV - [2009/07/23 21:10:38 | 000,061,440 | —- | M] (Intuit Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe – (QBFCService)
SRV - [2009/06/10 14:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/06/06 13:18:20 | 000,560,184 | —- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\sptd.sys – (sptd)
DRV:64bit: - [2012/02/29 23:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/09/13 19:34:02 | 000,035,664 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\Windows\SysNative\drivers\avgmfx64.sys – (AvgMfx64)
DRV:64bit: - [2011/05/24 21:02:34 | 000,317,520 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgtdia.sys – (AvgTdiA)
DRV:64bit: - [2011/05/10 08:06:08 | 000,051,712 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2011/03/10 23:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/10 23:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/01/15 09:21:04 | 000,036,352 | —- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\VClone.sys – (VClone)
DRV:64bit: - [2011/01/13 23:51:56 | 000,030,840 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Gun64.sys – (Gun)
DRV:64bit: - [2010/12/16 15:58:14 | 000,040,816 | —- | M] (Elaborate Bytes AG) [Kernel | System | Running] – C:\Windows\SysNative\drivers\ElbyCDIO.sys – (ElbyCDIO)
DRV:64bit: - [2010/11/20 06:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 04:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/20 02:37:42 | 000,109,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2010/07/15 09:55:39 | 000,269,904 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgldx64.sys – (AvgLdx64)
DRV:64bit: - [2010/01/25 07:06:48 | 000,620,576 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\rtl819xp.sys – (rtl819xpn64) Realtek RTL8190/RTL8192E 802.11n Wireless LAN (Mini-)
DRV:64bit: - [2010/01/25 07:06:48 | 000,620,576 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\rtl819xp.sys – (rtl819xp) Realtek RTL8190\RTL8192E 802.11n Wireless LAN (Mini-)
DRV:64bit: - [2009/11/13 09:47:38 | 000,067,072 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\L1C62x64.sys – (L1C)
DRV:64bit: - [2009/08/18 04:48:48 | 006,037,504 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmdag.sys – (atikmdag)
DRV:64bit: - [2009/08/03 18:29:08 | 000,686,080 | —- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CHDRT64.sys – (CnxtHdAudService)
DRV:64bit: - [2009/07/13 18:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 18:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 18:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 17:35:32 | 000,012,288 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\serscan.sys – (StillCam)
DRV:64bit: - [2009/06/29 17:16:20 | 000,014,784 | —- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\Thpevm.sys – (Thpevm)
DRV:64bit: - [2009/06/29 11:25:22 | 000,034,880 | —- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\thpdrv.sys – (Thpdrv)
DRV:64bit: - [2009/06/10 14:01:11 | 001,485,312 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\VSTDPV6.SYS – (SrvHsfV92)
DRV:64bit: - [2009/06/10 14:01:11 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\VSTCNXT6.SYS – (SrvHsfWinac)
DRV:64bit: - [2009/06/10 14:01:11 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\VSTAZL6.SYS – (SrvHsfHDA)
DRV:64bit: - [2009/06/10 13:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 13:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 13:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 13:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2009/03/10 17:27:04 | 000,069,536 | —- | M] (O2Micro ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\o2mdgx64.sys – (O2MDGRDR)
DRV:64bit: - [2007/11/09 06:00:30 | 000,026,968 | —- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\TVALZ_O.SYS – (TVALZ)
DRV - [2009/07/13 18:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
DRV - [2005/01/01 02:43:08 | 000,004,682 | —- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\npptNT2.sys – (NPPTNT2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2786678


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://feed.helperbar.com/?publisher=OPENC…babsrc=lnkry_nt
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 4F F3 B7 92 00 92 CC 01 [binary data]
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.helperbar.com/?publisher=OPENC…q={searchTerms}
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes\{274127B3-DF86-4E2A-B831-3E7212A1DD0B}: "URL" = http://websearch.ask.com/redirect?client=i…CE-67C91BFE3FFF
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes\{A9E18AC0-B8FF-4044-ADBE-2F562F5BD88D}: "URL" = http://ws.infospace.com/playsushi_tbar/ws/…w={searchTerms}
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2786678
IE - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=IEFM1&q="
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..keyword.URL: "http://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=US&userid=2ad75993-39a7-4b76-b14b-0899ab600fa5&affid=110774&searchtype=ds&babsrc=lnkry&q="


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@gametap.com/npdd,version=1.0: C:\Program Files (x86)\Downloader\npdd.dll (Metaboli)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.3.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.3.1: C:\Program Files (x86)\Oracle\JavaFX 2.0 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\Pete\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll File not found
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Pete\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files (x86)\AVG\AVG9\Firefox [2011/09/13 19:34:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/04/04 14:56:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/07/18 22:16:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/28 10:31:26 | 000,000,000 | —D | M]

[2012/06/26 12:19:54 | 000,000,000 | —D | M] (No name found) – C:\Users\Pete\AppData\Roaming\mozilla\Extensions
[2012/07/18 16:42:10 | 000,000,000 | —D | M] (No name found) – C:\Users\Pete\AppData\Roaming\mozilla\Firefox\Profiles\39ea4nyv.default\extensions
[2012/07/18 16:42:10 | 000,000,000 | —D | M] (uTorrentBar Community Toolbar) – C:\Users\Pete\AppData\Roaming\mozilla\Firefox\Profiles\39ea4nyv.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2012/07/08 10:10:47 | 000,000,000 | —D | M] ("Codec-V") – C:\Users\Pete\AppData\Roaming\mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]
[2012/06/22 20:05:14 | 000,002,343 | —- | M] () – C:\Users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\searchplugins\askcom.xml
[2012/06/06 13:01:28 | 000,002,519 | —- | M] () – C:\Users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\searchplugins\Search_Results.xml
[2012/06/23 11:28:19 | 000,002,474 | —- | M] () – C:\Users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\searchplugins\Web Search.xml
[2012/06/26 12:19:54 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/04/04 14:56:45 | 000,000,000 | —D | M] (DivX Plus Web Player HTML5 ) – C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
[2011/07/17 11:27:16 | 000,330,316 | —- | M] () (No name found) – C:\USERS\PETE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\39EA4NYV.DEFAULT\EXTENSIONS\[removed]
[2012/07/18 22:16:44 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/10/17 18:41:11 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/06/06 13:01:28 | 000,002,519 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
[2011/11/14 14:28:00 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.searchnu.com/406
CHR - default_search_provider: Search Results (Enabled)
CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&a…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://www.ask.com/?l=dis&o=APN10111cr&gct=hp
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\19.0.1084.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\19.0.1084.56\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\19.0.1084.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Downloader Detector (Enabled) = C:\Program Files (x86)\Downloader\npdd.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U3 (Enabled) = C:\Program Files (x86)\Oracle\JavaFX 2.0 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.30.255 (Enabled) = C:\Windows\system32\npDeployJava1.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Pete\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Pete\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: YouTube = C:\Users\Pete\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Google Search = C:\Users\Pete\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: Google Search = C:\Users\Pete\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Codec-V = C:\Users\Pete\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpnbdefcbnoefmmcpelplabbkfmfhlho\1.14.36_0\
CHR - Extension: Codec-V = C:\Users\Pete\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpnbdefcbnoefmmcpelplabbkfmfhlho\1.17.48_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Pete\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: Gmail = C:\Users\Pete\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\
CHR - Extension: Gmail = C:\Users\Pete\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 14:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - !{ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..\Run: [ThpSrv] C:\Windows\SysNative\thpsrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKU\S-1-5-19..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun File not found
O4 - HKU\S-1-5-20..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun File not found
O4 - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000..\Run: [DAEMON Tools Pro Agent] C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000..\Run: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent File not found
O4 - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000..\Run: [Facebook Update] C:\Users\Pete\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\System32\winrnr.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-3216521362-3930712179-4014682732-1000\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.3.1)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://juniper.net/dana-cached/sc/JuniperSetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8B4401F4-F963-4303-AB34-FB34474D6F42}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\intu-help-qb3 - No CLSID value found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\qbwc - No CLSID value found
O18 - Protocol\Handler\intu-help-qb3 {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - C:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{62d85b3e-3d37-11e1-aa4d-00238be545b8}\Shell - "" = AutoRun
O33 - MountPoints2\{62d85b3e-3d37-11e1-aa4d-00238be545b8}\Shell\AutoRun\command - "" = E:\autorun.exe
O33 - MountPoints2\{663f2668-50c8-11df-b7d0-00238be545b8}\Shell - "" = AutoRun
O33 - MountPoints2\{663f2668-50c8-11df-b7d0-00238be545b8}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{71fbaa3a-8ee9-11e1-a8a7-00238be545b8}\Shell - "" = AutoRun
O33 - MountPoints2\{71fbaa3a-8ee9-11e1-a8a7-00238be545b8}\Shell\AutoRun\command - "" = F:\Setup.exe
O33 - MountPoints2\{71fbaa3a-8ee9-11e1-a8a7-00238be545b8}\Shell\setup\command - "" = F:\setup.exe
O33 - MountPoints2\{b0595c36-1e71-11df-897d-00238be545b8}\Shell - "" = AutoRun
O33 - MountPoints2\{b0595c36-1e71-11df-897d-00238be545b8}\Shell\AutoRun\command - "" = F:\MI.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\MI.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/07/21 15:09:55 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Users\Pete\Desktop\OTL.exe
[2012/07/20 19:10:57 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\svchost.exe
[2012/07/20 13:30:48 | 000,000,000 | —D | C] – C:\c774baca38044aeb2e6250e48a751daf
[2012/07/20 13:30:14 | 000,000,000 | —D | C] – C:\66bab871d1c4b24af42e95e990d178
[2012/07/18 23:58:02 | 000,000,000 | -HSD | C] – C:\Windows\SysWow64\%APPDATA%
[2012/07/10 12:10:25 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msxml3r.dll
[2012/07/10 12:10:25 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msxml3r.dll
[2012/07/10 12:10:23 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2012/07/10 12:09:58 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cdosys.dll
[2012/07/10 12:09:57 | 001,133,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdosys.dll
[2012/06/23 11:35:35 | 000,000,000 | —D | C] – C:\Users\Pete\AppData\Local\Macromedia
[2012/06/22 20:04:48 | 000,000,000 | —D | C] – C:\Users\Pete\AppData\Local\APN
[2012/06/22 20:04:39 | 000,000,000 | —D | C] – C:\Users\Pete\AppData\Roaming\NCH Software
[2012/06/22 20:04:39 | 000,000,000 | —D | C] – C:\ProgramData\NCH Software
[2012/06/22 20:04:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
[2012/06/22 20:04:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audio Related Programs
[2012/06/22 20:04:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\NCH Software
[2012/06/22 19:53:04 | 000,000,000 | —D | C] – C:\Users\Pete\Desktop\Arrik DROID
[2012/06/21 21:39:59 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/21 21:39:58 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/21 21:39:58 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/21 21:39:34 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/21 21:39:34 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/21 21:39:34 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/21 21:39:16 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/21 21:39:16 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe

========== Files - Modified Within 30 Days ==========

[2012/07/21 15:34:18 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/21 15:13:43 | 000,000,000 | —- | M] () – C:\Users\Pete\AppData\Local\prvlcl.dat
[2012/07/21 15:13:07 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/21 15:11:18 | 000,014,832 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/21 15:11:18 | 000,014,832 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/21 15:10:14 | 101,926,143 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2012/07/21 15:10:04 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\Pete\Desktop\OTL.exe
[2012/07/21 15:03:50 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/21 15:03:11 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/07/21 15:03:04 | 3018,596,352 | -HS- | M] () – C:\hiberfil.sys
[2012/07/20 22:08:02 | 000,000,924 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3216521362-3930712179-4014682732-1000UA.job
[2012/07/18 22:16:47 | 000,002,048 | —- | M] () – C:\Users\Pete\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/07/15 17:21:26 | 000,000,450 | -H– | M] () – C:\Windows\tasks\Norton Security Scan for Pete.job
[2012/07/15 16:08:00 | 000,000,902 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3216521362-3930712179-4014682732-1000Core.job
[2012/07/15 11:03:50 | 000,000,366 | —- | M] () – C:\Windows\tasks\Driver Fetch.job
[2012/07/11 18:19:22 | 000,000,183 | —- | M] () – C:\Windows\SysWow64\msxkwn.vxp
[2012/07/11 18:03:34 | 000,000,061 | —- | M] () – C:\Windows\TaxACT11.ini
[2012/07/11 16:34:16 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/07/11 16:34:16 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/07/11 15:23:25 | 000,434,048 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/30 02:48:42 | 000,863,246 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/30 02:48:42 | 000,719,870 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/30 02:48:42 | 000,144,228 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/26 21:53:23 | 000,000,866 | —- | M] () – C:\Users\Public\Desktop\Cache Cleaner.lnk
[2012/06/26 12:43:23 | 000,001,137 | —- | M] () – C:\Users\Pete\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk

========== Files Created - No Company Name ==========

[2012/07/18 23:47:45 | 000,232,960 | —- | C] () – C:\Windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\U\00000008.@
[2012/07/18 23:47:43 | 000,080,896 | —- | C] () – C:\Windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\U\80000064.@
[2012/07/18 23:47:43 | 000,000,804 | —- | C] () – C:\Windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\L\00000004.@
[2012/07/18 23:47:40 | 000,092,160 | —- | C] () – C:\Windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\U\80000032.@
[2012/07/18 23:47:12 | 000,001,632 | —- | C] () – C:\Windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\U\000000cb.@
[2012/07/18 23:47:10 | 000,016,896 | —- | C] () – C:\Windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\U\80000000.@
[2012/07/18 23:46:38 | 000,002,048 | —- | C] () – C:\Windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\U\00000004.@
[2012/06/26 12:43:23 | 000,001,137 | —- | C] () – C:\Users\Pete\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/06/22 20:04:33 | 000,001,134 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WavePad Sound Editor.lnk
[2012/02/20 16:01:21 | 000,000,145 | —- | C] () – C:\Users\Pete\.appletviewer
[2012/01/22 18:33:25 | 000,000,061 | —- | C] () – C:\Windows\TaxACT11.ini
[2012/01/12 11:29:53 | 000,000,600 | —- | C] () – C:\Users\Pete\AppData\Local\PUTTY.RND
[2012/01/10 12:08:18 | 000,002,048 | -HS- | C] () – C:\Windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\@
[2012/01/10 12:08:18 | 000,002,048 | -HS- | C] () – C:\Users\Pete\AppData\Local\{86b67214-cacf-3544-f67a-920439385c0d}\@
[2011/01/05 21:42:08 | 000,000,048 | —- | C] () – C:\Windows\TaxACT10.ini
[2010/07/10 21:39:25 | 007,114,752 | —- | C] () – C:\Users\Pete\Critical Thinking 5.1 (Backup Jul 10,2010 09 39 PM).QBB
[2010/06/15 23:05:23 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/05/13 22:23:10 | 000,007,597 | —- | C] () – C:\Users\Pete\AppData\Local\Resmon.ResmonCfg
[2010/03/31 15:58:29 | 000,000,000 | —- | C] () – C:\Users\Pete\AppData\Local\prvlcl.dat
[2010/02/22 17:36:08 | 000,004,608 | —- | C] () – C:\Users\Pete\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/20 16:25:27 | 000,000,632 | RHS- | C] () – C:\Users\Pete\ntuser.pol

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/25 23:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/25 22:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 18:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/25 22:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/30 22:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/25 22:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/24 23:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/24 23:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/25 23:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 05:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/02 23:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/24 22:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/24 22:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/30 23:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/02 22:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2009/10/30 23:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/02 22:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 18:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/30 23:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/25 23:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/02 23:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[2010/11/20 06:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: SVCHOST.EXE >
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 18:14:45 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=2CEFF13ACE25A40BD8D97654944297CD – C:\Windows\svchost.exe
[2009/07/13 18:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 18:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 18:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 18:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 05:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 05:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 18:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 18:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 06:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 06:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010/11/20 06:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 06:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 18:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 00:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/27 23:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: TOSHIBA MK4055GSX ATA Device
Partitions: 2
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 0.00GB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 373.00GB
Starting Offset: 105906176
Hidden sectors: 0


========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\System32\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\System32\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction

< End of report >













=====================================

TDS Killer Log


====================================

13:55:57.0549 1212 TDSS rootkit removing tool [removed] Jul 16 2012 22:10:11
13:55:58.0059 1212 ============================================================
13:55:58.0059 1212 Current date / time: 2012/07/22 13:55:58.0059
13:55:58.0059 1212 SystemInfo:
13:55:58.0059 1212
13:55:58.0059 1212 OS Version: 6.1.7601 ServicePack: 1.0
13:55:58.0059 1212 Product type: Workstation
13:55:58.0059 1212 ComputerName: JOCELIN-ARRIK
13:55:58.0059 1212 UserName: Pete
13:55:58.0059 1212 Windows directory: C:\Windows
13:55:58.0059 1212 System windows directory: C:\Windows
13:55:58.0059 1212 Running under WOW64
13:55:58.0059 1212 Processor architecture: Intel x64
13:55:58.0059 1212 Number of processors: 2
13:55:58.0059 1212 Page size: 0x1000
13:55:58.0059 1212 Boot type: Normal boot
13:55:58.0059 1212 ============================================================
13:55:59.0367 1212 Drive \Device\Harddisk0\DR0 - Size: 0x5D27216000 (372.61 Gb), SectorSize: 0x200, Cylinders: 0xBE01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
13:55:59.0383 1212 ============================================================
13:55:59.0383 1212 \Device\Harddisk0\DR0:
13:55:59.0383 1212 MBR partitions:
13:55:59.0383 1212 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
13:55:59.0383 1212 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x2E906000
13:55:59.0383 1212 ============================================================
13:55:59.0414 1212 C: <-> \Device\Harddisk0\DR0\Partition1
13:55:59.0414 1212 ============================================================
13:55:59.0414 1212 Initialize success
13:55:59.0414 1212 ============================================================
13:56:14.0624 4108 ============================================================
13:56:14.0624 4108 Scan started
13:56:14.0624 4108 Mode: Manual;
13:56:14.0624 4108 ============================================================
13:56:15.0139 4108 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
13:56:15.0139 4108 1394ohci - ok
13:56:15.0295 4108 ACDaemon - ok
13:56:15.0373 4108 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
13:56:15.0388 4108 ACPI - ok
13:56:15.0419 4108 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
13:56:15.0435 4108 AcpiPmi - ok
13:56:15.0575 4108 AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
13:56:15.0575 4108 AdobeFlashPlayerUpdateSvc - ok
13:56:15.0638 4108 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
13:56:15.0653 4108 adp94xx - ok
13:56:15.0700 4108 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
13:56:15.0716 4108 adpahci - ok
13:56:15.0763 4108 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
13:56:15.0763 4108 adpu320 - ok
13:56:15.0794 4108 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
13:56:15.0794 4108 AeLookupSvc - ok
13:56:15.0887 4108 Afc (6ccd1135320109d6b219f1a6e04ad9f6) C:\Windows\syswow64\drivers\Afc.sys
13:56:15.0887 4108 Afc - ok
13:56:15.0950 4108 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
13:56:15.0965 4108 AFD - ok
13:56:16.0012 4108 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
13:56:16.0012 4108 agp440 - ok
13:56:16.0043 4108 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
13:56:16.0043 4108 ALG - ok
13:56:16.0090 4108 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
13:56:16.0106 4108 aliide - ok
13:56:16.0184 4108 AMD External Events Utility (d696f317bd465a602566f8e1dcce15f7) C:\Windows\system32\atiesrxx.exe
13:56:16.0184 4108 AMD External Events Utility - ok
13:56:16.0184 4108 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
13:56:16.0199 4108 amdide - ok
13:56:16.0246 4108 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
13:56:16.0262 4108 AmdK8 - ok
13:56:16.0309 4108 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
13:56:16.0309 4108 AmdPPM - ok
13:56:16.0371 4108 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
13:56:16.0371 4108 amdsata - ok
13:56:16.0418 4108 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
13:56:16.0418 4108 amdsbs - ok
13:56:16.0433 4108 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
13:56:16.0433 4108 amdxata - ok
13:56:16.0527 4108 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
13:56:16.0527 4108 AppID - ok
13:56:16.0558 4108 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
13:56:16.0558 4108 AppIDSvc - ok
13:56:16.0589 4108 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
13:56:16.0605 4108 Appinfo - ok
13:56:16.0745 4108 Apple Mobile Device (7ef47644b74ebe721cc32211d3c35e76) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
13:56:16.0745 4108 Apple Mobile Device - ok
13:56:16.0792 4108 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
13:56:16.0808 4108 arc - ok
13:56:16.0823 4108 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
13:56:16.0823 4108 arcsas - ok
13:56:16.0979 4108 aspnet_state (9217d874131ae6ff8f642f124f00a555) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
13:56:16.0979 4108 aspnet_state - ok
13:56:17.0026 4108 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
13:56:17.0026 4108 AsyncMac - ok
13:56:17.0057 4108 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
13:56:17.0057 4108 atapi - ok
13:56:17.0307 4108 atikmdag (52bd95caa9cae8977fe043e9ad6d2d0e) C:\Windows\system32\DRIVERS\atikmdag.sys
13:56:17.0447 4108 atikmdag - ok
13:56:17.0603 4108 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
13:56:17.0619 4108 AudioEndpointBuilder - ok
13:56:17.0619 4108 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
13:56:17.0635 4108 AudioSrv - ok
13:56:17.0775 4108 avg9wd (c4d15594db5be042d3346ea58df87d89) C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
13:56:17.0775 4108 avg9wd - ok
13:56:17.0837 4108 AvgLdx64 (b447db072bf939db9e07bef2adf4ecbd) C:\Windows\System32\Drivers\avgldx64.sys
13:56:17.0837 4108 AvgLdx64 - ok
13:56:17.0900 4108 AvgMfx64 (0db5a749acd8e66091736f88c40207bd) C:\Windows\System32\Drivers\avgmfx64.sys
13:56:17.0900 4108 AvgMfx64 - ok
13:56:17.0947 4108 AvgTdiA (8aa68c0ba2b84fd7eb3e1f10bbfc825b) C:\Windows\System32\Drivers\avgtdia.sys
13:56:17.0947 4108 AvgTdiA - ok
13:56:17.0993 4108 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
13:56:18.0009 4108 AxInstSV - ok
13:56:18.0087 4108 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
13:56:18.0103 4108 b06bdrv - ok
13:56:18.0165 4108 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
13:56:18.0165 4108 b57nd60a - ok
13:56:18.0212 4108 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
13:56:18.0212 4108 BDESVC - ok
13:56:18.0243 4108 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
13:56:18.0243 4108 Beep - ok
13:56:18.0305 4108 BITS (1ea7969e3271cbc59e1730697dc74682) C:\Windows\System32\qmgr.dll
13:56:18.0321 4108 BITS - ok
13:56:18.0352 4108 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
13:56:18.0368 4108 blbdrive - ok
13:56:18.0430 4108 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
13:56:18.0446 4108 bowser - ok
13:56:18.0493 4108 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
13:56:18.0508 4108 BrFiltLo - ok
13:56:18.0508 4108 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
13:56:18.0508 4108 BrFiltUp - ok
13:56:18.0555 4108 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
13:56:18.0555 4108 Browser - ok
13:56:18.0586 4108 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
13:56:18.0586 4108 Brserid - ok
13:56:18.0617 4108 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
13:56:18.0617 4108 BrSerWdm - ok
13:56:18.0649 4108 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
13:56:18.0664 4108 BrUsbMdm - ok
13:56:18.0680 4108 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
13:56:18.0680 4108 BrUsbSer - ok
13:56:18.0695 4108 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
13:56:18.0695 4108 BTHMODEM - ok
13:56:18.0758 4108 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
13:56:18.0758 4108 bthserv - ok
13:56:18.0789 4108 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
13:56:18.0789 4108 cdfs - ok
13:56:18.0867 4108 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
13:56:18.0867 4108 cdrom - ok
13:56:18.0929 4108 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
13:56:18.0945 4108 CertPropSvc - ok
13:56:18.0992 4108 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
13:56:18.0992 4108 circlass - ok
13:56:19.0039 4108 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
13:56:19.0039 4108 CLFS - ok
13:56:19.0085 4108 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:56:19.0101 4108 clr_optimization_v2.0.50727_32 - ok
13:56:19.0148 4108 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
13:56:19.0148 4108 clr_optimization_v2.0.50727_64 - ok
13:56:19.0273 4108 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:56:19.0273 4108 clr_optimization_v4.0.30319_32 - ok
13:56:19.0304 4108 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
13:56:19.0304 4108 clr_optimization_v4.0.30319_64 - ok
13:56:19.0351 4108 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
13:56:19.0351 4108 CmBatt - ok
13:56:19.0397 4108 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
13:56:19.0397 4108 cmdide - ok
13:56:19.0475 4108 CNG (9ac4f97c2d3e93367e2148ea940cd2cd) C:\Windows\system32\Drivers\cng.sys
13:56:19.0491 4108 CNG - ok
13:56:19.0616 4108 CnxtHdAudService (a731dbd4cfd4d70d81d197c48d745711) C:\Windows\system32\drivers\CHDRT64.sys
13:56:19.0631 4108 CnxtHdAudService - ok
13:56:19.0678 4108 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
13:56:19.0678 4108 Compbatt - ok
13:56:19.0741 4108 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
13:56:19.0741 4108 CompositeBus - ok
13:56:19.0756 4108 COMSysApp - ok
13:56:19.0787 4108 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
13:56:19.0787 4108 crcdisk - ok
13:56:19.0850 4108 CryptSvc (4f5414602e2544a4554d95517948b705) C:\Windows\system32\cryptsvc.dll
13:56:19.0850 4108 CryptSvc - ok
13:56:19.0897 4108 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
13:56:19.0912 4108 DcomLaunch - ok
13:56:19.0975 4108 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
13:56:19.0975 4108 defragsvc - ok
13:56:20.0006 4108 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
13:56:20.0021 4108 DfsC - ok
13:56:20.0084 4108 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
13:56:20.0084 4108 Dhcp - ok
13:56:20.0115 4108 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
13:56:20.0115 4108 discache - ok
13:56:20.0162 4108 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
13:56:20.0162 4108 Disk - ok
13:56:20.0224 4108 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
13:56:20.0240 4108 Dnscache - ok
13:56:20.0287 4108 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
13:56:20.0302 4108 dot3svc - ok
13:56:20.0333 4108 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
13:56:20.0349 4108 DPS - ok
13:56:20.0396 4108 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
13:56:20.0396 4108 drmkaud - ok
13:56:20.0489 4108 dump_wmimmc - ok
13:56:20.0567 4108 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
13:56:20.0583 4108 DXGKrnl - ok
13:56:20.0630 4108 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
13:56:20.0630 4108 EapHost - ok
13:56:20.0770 4108 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
13:56:20.0848 4108 ebdrv - ok
13:56:20.0973 4108 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
13:56:20.0973 4108 EFS - ok
13:56:21.0098 4108 ElbyCDIO (a05fc7eca0966ebb70e4d17b855a853b) C:\Windows\system32\Drivers\ElbyCDIO.sys
13:56:21.0098 4108 ElbyCDIO - ok
13:56:21.0160 4108 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
13:56:21.0176 4108 elxstor - ok
13:56:21.0207 4108 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
13:56:21.0223 4108 ErrDev - ok
13:56:21.0285 4108 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
13:56:21.0285 4108 EventSystem - ok
13:56:21.0316 4108 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
13:56:21.0316 4108 exfat - ok
13:56:21.0347 4108 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
13:56:21.0347 4108 fastfat - ok
13:56:21.0425 4108 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
13:56:21.0441 4108 Fax - ok
13:56:21.0472 4108 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
13:56:21.0472 4108 fdc - ok
13:56:21.0503 4108 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
13:56:21.0503 4108 fdPHost - ok
13:56:21.0519 4108 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
13:56:21.0519 4108 FDResPub - ok
13:56:21.0535 4108 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
13:56:21.0535 4108 FileInfo - ok
13:56:21.0550 4108 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
13:56:21.0550 4108 Filetrace - ok
13:56:21.0706 4108 FLEXnet Licensing Service (bb0667b0171b632b97ea759515476f07) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
13:56:21.0706 4108 FLEXnet Licensing Service - ok
13:56:21.0737 4108 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
13:56:21.0737 4108 flpydisk - ok
13:56:21.0800 4108 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
13:56:21.0800 4108 FltMgr - ok
13:56:21.0878 4108 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
13:56:21.0893 4108 FontCache - ok
13:56:21.0956 4108 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
13:56:21.0971 4108 FontCache3.0.0.0 - ok
13:56:22.0018 4108 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
13:56:22.0018 4108 FsDepends - ok
13:56:22.0049 4108 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys
13:56:22.0049 4108 Fs_Rec - ok
13:56:22.0127 4108 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
13:56:22.0127 4108 fvevol - ok
13:56:22.0143 4108 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
13:56:22.0143 4108 gagp30kx - ok
13:56:22.0205 4108 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
13:56:22.0205 4108 GEARAspiWDM - ok
13:56:22.0283 4108 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
13:56:22.0283 4108 gpsvc - ok
13:56:22.0393 4108 Gun (4f7e0a173348a60e003d3c5f51c5808e) C:\Windows\system32\Gun64.sys
13:56:22.0393 4108 Gun - ok
13:56:22.0533 4108 gupdate (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
13:56:22.0533 4108 gupdate - ok
13:56:22.0533 4108 gupdatem (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
13:56:22.0549 4108 gupdatem - ok
13:56:22.0564 4108 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
13:56:22.0580 4108 hcw85cir - ok
13:56:22.0642 4108 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
13:56:22.0658 4108 HdAudAddService - ok
13:56:22.0689 4108 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
13:56:22.0705 4108 HDAudBus - ok
13:56:22.0720 4108 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
13:56:22.0736 4108 HidBatt - ok
13:56:22.0751 4108 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
13:56:22.0751 4108 HidBth - ok
13:56:22.0783 4108 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
13:56:22.0783 4108 HidIr - ok
13:56:22.0814 4108 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
13:56:22.0814 4108 hidserv - ok
13:56:22.0892 4108 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
13:56:22.0892 4108 HidUsb - ok
13:56:22.0939 4108 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
13:56:22.0939 4108 hkmsvc - ok
13:56:22.0985 4108 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
13:56:22.0985 4108 HomeGroupListener - ok
13:56:23.0048 4108 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
13:56:23.0048 4108 HomeGroupProvider - ok
13:56:23.0095 4108 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
13:56:23.0095 4108 HpSAMD - ok
13:56:23.0173 4108 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
13:56:23.0173 4108 HTTP - ok
13:56:23.0219 4108 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
13:56:23.0235 4108 hwpolicy - ok
13:56:23.0313 4108 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
13:56:23.0313 4108 i8042prt - ok
13:56:23.0360 4108 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
13:56:23.0375 4108 iaStorV - ok
13:56:23.0485 4108 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
13:56:23.0485 4108 idsvc - ok
13:56:23.0516 4108 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
13:56:23.0516 4108 iirsp - ok
13:56:23.0625 4108 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
13:56:23.0641 4108 IKEEXT - ok
13:56:23.0687 4108 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
13:56:23.0687 4108 intelide - ok
13:56:23.0734 4108 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
13:56:23.0734 4108 intelppm - ok
13:56:23.0765 4108 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
13:56:23.0765 4108 IPBusEnum - ok
13:56:23.0812 4108 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:56:23.0812 4108 IpFilterDriver - ok
13:56:23.0859 4108 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
13:56:23.0859 4108 IPMIDRV - ok
13:56:23.0921 4108 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
13:56:23.0921 4108 IPNAT - ok
13:56:24.0140 4108 iPod Service (50d6ccc6ff5561f9f56946b3e6164fb8) C:\Program Files\iPod\bin\iPodService.exe
13:56:24.0155 4108 iPod Service - ok
13:56:24.0218 4108 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
13:56:24.0218 4108 IRENUM - ok
13:56:24.0296 4108 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
13:56:24.0296 4108 isapnp - ok
13:56:24.0358 4108 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
13:56:24.0358 4108 iScsiPrt - ok
13:56:24.0389 4108 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
13:56:24.0389 4108 kbdclass - ok
13:56:24.0452 4108 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
13:56:24.0452 4108 kbdhid - ok
13:56:24.0514 4108 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
13:56:24.0514 4108 KeyIso - ok
13:56:24.0561 4108 KSecDD (97a7070aea4c058b6418519e869a63b4) C:\Windows\system32\Drivers\ksecdd.sys
13:56:24.0561 4108 KSecDD - ok
13:56:24.0608 4108 KSecPkg (26c43a7c2862447ec59deda188d1da07) C:\Windows\system32\Drivers\ksecpkg.sys
13:56:24.0608 4108 KSecPkg - ok
13:56:24.0623 4108 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
13:56:24.0623 4108 ksthunk - ok
13:56:24.0686 4108 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
13:56:24.0686 4108 KtmRm - ok
13:56:24.0748 4108 L1C (9c46a5421de9d116c47155317cabb522) C:\Windows\system32\DRIVERS\L1C62x64.sys
13:56:24.0748 4108 L1C - ok
13:56:24.0826 4108 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\system32\srvsvc.dll
13:56:24.0826 4108 LanmanServer - ok
13:56:24.0873 4108 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll
13:56:24.0873 4108 LanmanWorkstation - ok
13:56:24.0935 4108 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
13:56:24.0935 4108 lltdio - ok
13:56:24.0998 4108 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
13:56:25.0013 4108 lltdsvc - ok
13:56:25.0029 4108 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
13:56:25.0029 4108 lmhosts - ok
13:56:25.0076 4108 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
13:56:25.0076 4108 LSI_FC - ok
13:56:25.0107 4108 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
13:56:25.0107 4108 LSI_SAS - ok
13:56:25.0138 4108 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
13:56:25.0138 4108 LSI_SAS2 - ok
13:56:25.0154 4108 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
13:56:25.0154 4108 LSI_SCSI - ok
13:56:25.0201 4108 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
13:56:25.0201 4108 luafv - ok
13:56:25.0325 4108 McComponentHostService (f453d1e6d881e8f8717e20ccd4199e85) C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
13:56:25.0341 4108 McComponentHostService - ok
13:56:25.0372 4108 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
13:56:25.0372 4108 megasas - ok
13:56:25.0403 4108 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
13:56:25.0403 4108 MegaSR - ok
13:56:25.0435 4108 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
13:56:25.0435 4108 MMCSS - ok
13:56:25.0450 4108 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
13:56:25.0450 4108 Modem - ok
13:56:25.0497 4108 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
13:56:25.0497 4108 monitor - ok
13:56:25.0544 4108 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
13:56:25.0544 4108 mouclass - ok
13:56:25.0622 4108 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
13:56:25.0622 4108 mouhid - ok
13:56:25.0669 4108 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
13:56:25.0669 4108 mountmgr - ok
13:56:25.0762 4108 MozillaMaintenance (46297fa8e30a6007f14118fc2b942fbc) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
13:56:25.0762 4108 MozillaMaintenance - ok
13:56:25.0793 4108 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
13:56:25.0809 4108 mpio - ok
13:56:25.0825 4108 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
13:56:25.0825 4108 mpsdrv - ok
13:56:25.0871 4108 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
13:56:25.0871 4108 MRxDAV - ok
13:56:25.0918 4108 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
13:56:25.0918 4108 mrxsmb - ok
13:56:25.0965 4108 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:56:25.0981 4108 mrxsmb10 - ok
13:56:25.0981 4108 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:56:25.0996 4108 mrxsmb20 - ok
13:56:26.0043 4108 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
13:56:26.0043 4108 msahci - ok
13:56:26.0059 4108 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
13:56:26.0059 4108 msdsm - ok
13:56:26.0090 4108 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
13:56:26.0090 4108 MSDTC - ok
13:56:26.0137 4108 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
13:56:26.0137 4108 Msfs - ok
13:56:26.0168 4108 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
13:56:26.0168 4108 mshidkmdf - ok
13:56:26.0183 4108 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
13:56:26.0183 4108 msisadrv - ok
13:56:26.0230 4108 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
13:56:26.0246 4108 MSiSCSI - ok
13:56:26.0246 4108 msiserver - ok
13:56:26.0293 4108 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
13:56:26.0293 4108 MSKSSRV - ok
13:56:26.0308 4108 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
13:56:26.0308 4108 MSPCLOCK - ok
13:56:26.0339 4108 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
13:56:26.0339 4108 MSPQM - ok
13:56:26.0402 4108 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
13:56:26.0402 4108 MsRPC - ok
13:56:26.0449 4108 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
13:56:26.0449 4108 mssmbios - ok
13:56:26.0589 4108 MSSQL$MSSMLBIZ - ok
13:56:26.0636 4108 MSSQLServerADHelper (c06ea83f6fc2959e897c117255b6b1d5) c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqladhlp90.exe
13:56:26.0636 4108 MSSQLServerADHelper - ok
13:56:26.0698 4108 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
13:56:26.0698 4108 MSTEE - ok
13:56:26.0729 4108 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
13:56:26.0729 4108 MTConfig - ok
13:56:26.0761 4108 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
13:56:26.0761 4108 Mup - ok
13:56:26.0823 4108 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
13:56:26.0839 4108 napagent - ok
13:56:26.0901 4108 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
13:56:26.0901 4108 NativeWifiP - ok
13:56:26.0995 4108 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
13:56:27.0010 4108 NDIS - ok
13:56:27.0057 4108 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
13:56:27.0073 4108 NdisCap - ok
13:56:27.0119 4108 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
13:56:27.0119 4108 NdisTapi - ok
13:56:27.0182 4108 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
13:56:27.0182 4108 Ndisuio - ok
13:56:27.0229 4108 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
13:56:27.0229 4108 NdisWan - ok
13:56:27.0275 4108 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
13:56:27.0275 4108 NDProxy - ok
13:56:27.0338 4108 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
13:56:27.0338 4108 NetBIOS - ok
13:56:27.0385 4108 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
13:56:27.0400 4108 NetBT - ok
13:56:27.0447 4108 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
13:56:27.0447 4108 Netlogon - ok
13:56:27.0478 4108 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
13:56:27.0478 4108 Netman - ok
13:56:27.0619 4108 NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:56:27.0619 4108 NetMsmqActivator - ok
13:56:27.0634 4108 NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:56:27.0634 4108 NetPipeActivator - ok
13:56:27.0665 4108 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
13:56:27.0681 4108 netprofm - ok
13:56:27.0697 4108 NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:56:27.0697 4108 NetTcpActivator - ok
13:56:27.0712 4108 NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:56:27.0712 4108 NetTcpPortSharing - ok
13:56:27.0775 4108 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
13:56:27.0775 4108 nfrd960 - ok
13:56:27.0821 4108 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
13:56:27.0837 4108 NlaSvc - ok
13:56:27.0853 4108 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
13:56:27.0853 4108 Npfs - ok
13:56:27.0899 4108 npggsvc - ok
13:56:27.0899 4108 NPPTNT2 - ok
13:56:27.0931 4108 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
13:56:27.0931 4108 nsi - ok
13:56:27.0962 4108 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
13:56:27.0962 4108 nsiproxy - ok
13:56:28.0133 4108 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
13:56:28.0196 4108 Ntfs - ok
13:56:28.0305 4108 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
13:56:28.0305 4108 Null - ok
13:56:28.0352 4108 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
13:56:28.0352 4108 nvraid - ok
13:56:28.0383 4108 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
13:56:28.0383 4108 nvstor - ok
13:56:28.0399 4108 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
13:56:28.0414 4108 nv_agp - ok
13:56:28.0477 4108 O2FLASH (d955d5de998db2476bf0892be3a96c26) C:\Windows\system32\DRIVERS\o2flash.exe
13:56:28.0477 4108 O2FLASH - ok
13:56:28.0477 4108 O2MDGRDR (df8f89fee23477b94007f2aaf95c15a9) C:\Windows\system32\DRIVERS\o2mdgx64.sys
13:56:28.0477 4108 O2MDGRDR - ok
13:56:28.0679 4108 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
13:56:28.0679 4108 odserv - ok
13:56:28.0726 4108 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
13:56:28.0726 4108 ohci1394 - ok
13:56:28.0789 4108 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:56:28.0804 4108 ose - ok
13:56:28.0835 4108 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
13:56:28.0835 4108 p2pimsvc - ok
13:56:28.0867 4108 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
13:56:28.0867 4108 p2psvc - ok
13:56:28.0898 4108 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
13:56:28.0898 4108 Parport - ok
13:56:28.0929 4108 partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys
13:56:28.0929 4108 partmgr - ok
13:56:28.0960 4108 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
13:56:28.0976 4108 PcaSvc - ok
13:56:29.0007 4108 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
13:56:29.0023 4108 pci - ok
13:56:29.0023 4108 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
13:56:29.0023 4108 pciide - ok
13:56:29.0054 4108 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
13:56:29.0069 4108 pcmcia - ok
13:56:29.0085 4108 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
13:56:29.0085 4108 pcw - ok
13:56:29.0116 4108 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
13:56:29.0132 4108 PEAUTH - ok
13:56:29.0194 4108 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
13:56:29.0194 4108 PerfHost - ok
13:56:29.0303 4108 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
13:56:29.0319 4108 pla - ok
13:56:29.0366 4108 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll
13:56:29.0366 4108 PlugPlay - ok
13:56:29.0397 4108 PnkBstrA - ok
13:56:29.0444 4108 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
13:56:29.0444 4108 PNRPAutoReg - ok
13:56:29.0459 4108 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
13:56:29.0475 4108 PNRPsvc - ok
13:56:29.0522 4108 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
13:56:29.0537 4108 PolicyAgent - ok
13:56:29.0569 4108 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
13:56:29.0569 4108 Power - ok
13:56:29.0678 4108 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
13:56:29.0678 4108 PptpMiniport - ok
13:56:29.0709 4108 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
13:56:29.0709 4108 Processor - ok
13:56:29.0740 4108 ProfSvc (53e83f1f6cf9d62f32801cf66d8352a8) C:\Windows\system32\profsvc.dll
13:56:29.0756 4108 ProfSvc - ok
13:56:29.0803 4108 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
13:56:29.0803 4108 ProtectedStorage - ok
13:56:29.0849 4108 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
13:56:29.0849 4108 Psched - ok
13:56:30.0005 4108 QBCFMonitorService (a669e8cba095a4f34a62cbd5fda002c9) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
13:56:30.0005 4108 QBCFMonitorService - ok
13:56:30.0146 4108 QBFCService (6bee1814470dc12fa20c53dfc3c97ebb) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
13:56:30.0161 4108 QBFCService - ok
13:56:30.0333 4108 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
13:56:30.0349 4108 ql2300 - ok
13:56:30.0442 4108 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
13:56:30.0442 4108 ql40xx - ok
13:56:30.0489 4108 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
13:56:30.0489 4108 QWAVE - ok
13:56:30.0489 4108 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
13:56:30.0505 4108 QWAVEdrv - ok
13:56:30.0520 4108 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
13:56:30.0520 4108 RasAcd - ok
13:56:30.0567 4108 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
13:56:30.0567 4108 RasAgileVpn - ok
13:56:30.0598 4108 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
13:56:30.0598 4108 RasAuto - ok
13:56:30.0629 4108 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
13:56:30.0645 4108 Rasl2tp - ok
13:56:30.0707 4108 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
13:56:30.0707 4108 RasMan - ok
13:56:30.0754 4108 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
13:56:30.0770 4108 RasPppoe - ok
13:56:30.0785 4108 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
13:56:30.0785 4108 RasSstp - ok
13:56:30.0832 4108 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
13:56:30.0848 4108 rdbss - ok
13:56:30.0863 4108 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
13:56:30.0863 4108 rdpbus - ok
13:56:31.0347 4108 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
13:56:31.0347 4108 RDPCDD - ok
13:56:31.0394 4108 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
13:56:31.0394 4108 RDPENCDD - ok
13:56:31.0409 4108 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
13:56:31.0409 4108 RDPREFMP - ok
13:56:31.0456 4108 RDPWD (e61608aa35e98999af9aaeeea6114b0a) C:\Windows\system32\drivers\RDPWD.sys
13:56:31.0456 4108 RDPWD - ok
13:56:31.0519 4108 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
13:56:31.0519 4108 rdyboost - ok
13:56:31.0581 4108 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
13:56:31.0581 4108 RemoteAccess - ok
13:56:31.0612 4108 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
13:56:31.0612 4108 RemoteRegistry - ok
13:56:31.0612 4108 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
13:56:31.0628 4108 RpcEptMapper - ok
13:56:31.0659 4108 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
13:56:31.0659 4108 RpcLocator - ok
13:56:31.0737 4108 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
13:56:31.0737 4108 RpcSs - ok
13:56:31.0799 4108 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
13:56:31.0799 4108 rspndr - ok
13:56:31.0893 4108 rtl819xp (72fe8d2644dd8dfdad3d787fbf13d1f1) C:\Windows\system32\DRIVERS\rtl819xp.sys
13:56:31.0909 4108 rtl819xp - ok
13:56:31.0940 4108 rtl819xpn64 (72fe8d2644dd8dfdad3d787fbf13d1f1) C:\Windows\system32\DRIVERS\rtl819xp.sys
13:56:31.0940 4108 rtl819xpn64 - ok
13:56:31.0987 4108 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
13:56:31.0987 4108 SamSs - ok
13:56:32.0033 4108 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
13:56:32.0033 4108 sbp2port - ok
13:56:32.0065 4108 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
13:56:32.0065 4108 SCardSvr - ok
13:56:32.0111 4108 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
13:56:32.0127 4108 scfilter - ok
13:56:32.0189 4108 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
13:56:32.0205 4108 Schedule - ok
13:56:32.0252 4108 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
13:56:32.0252 4108 SCPolicySvc - ok
13:56:32.0330 4108 sdbus (111e0ebc0ad79cb0fa014b907b231cf0) C:\Windows\system32\drivers\sdbus.sys
13:56:32.0330 4108 sdbus - ok
13:56:32.0377 4108 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
13:56:32.0377 4108 SDRSVC - ok
13:56:32.0439 4108 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
13:56:32.0439 4108 secdrv - ok
13:56:32.0470 4108 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
13:56:32.0486 4108 seclogon - ok
13:56:32.0501 4108 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
13:56:32.0517 4108 SENS - ok
13:56:32.0533 4108 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
13:56:32.0533 4108 SensrSvc - ok
13:56:32.0548 4108 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
13:56:32.0548 4108 Serenum - ok
13:56:32.0595 4108 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
13:56:32.0595 4108 Serial - ok
13:56:32.0642 4108 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
13:56:32.0642 4108 sermouse - ok
13:56:32.0689 4108 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
13:56:32.0689 4108 SessionEnv - ok
13:56:32.0735 4108 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
13:56:32.0735 4108 sffdisk - ok
13:56:32.0751 4108 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
13:56:32.0767 4108 sffp_mmc - ok
13:56:32.0782 4108 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\DRIVERS\sffp_sd.sys
13:56:32.0782 4108 sffp_sd - ok
13:56:32.0798 4108 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
13:56:32.0813 4108 sfloppy - ok
13:56:32.0860 4108 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
13:56:32.0876 4108 ShellHWDetection - ok
13:56:32.0891 4108 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
13:56:32.0891 4108 SiSRaid2 - ok
13:56:32.0923 4108 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
13:56:32.0923 4108 SiSRaid4 - ok
13:56:32.0969 4108 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
13:56:32.0985 4108 Smb - ok
13:56:33.0047 4108 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
13:56:33.0047 4108 SNMPTRAP - ok
13:56:33.0063 4108 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
13:56:33.0063 4108 spldr - ok
13:56:33.0110 4108 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
13:56:33.0125 4108 Spooler - ok
13:56:33.0281 4108 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
13:56:33.0375 4108 sppsvc - ok
13:56:33.0469 4108 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
13:56:33.0469 4108 sppuinotify - ok
13:56:33.0578 4108 sptd (a15860e920b02c9a7ce8f3a6c2ff1e3a) C:\Windows\System32\Drivers\sptd.sys
13:56:33.0578 4108 sptd - ok
13:56:33.0671 4108 SQLBrowser (b2ec3e1deac5f0a764bd3486d213a0af) c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
13:56:33.0671 4108 SQLBrowser - ok
13:56:33.0812 4108 SQLWriter (3c432a96363097870995e2a3c8b66abd) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
13:56:33.0812 4108 SQLWriter - ok
13:56:33.0874 4108 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
13:56:33.0874 4108 srv - ok
13:56:33.0905 4108 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
13:56:33.0905 4108 srv2 - ok
13:56:33.0968 4108 SrvHsfHDA (0c4540311e11664b245a263e1154cef8) C:\Windows\system32\DRIVERS\VSTAZL6.SYS
13:56:33.0983 4108 SrvHsfHDA - ok
13:56:34.0046 4108 SrvHsfV92 (02071d207a9858fbe3a48cbfd59c4a04) C:\Windows\system32\DRIVERS\VSTDPV6.SYS
13:56:34.0061 4108 SrvHsfV92 - ok
13:56:34.0327 4108 SrvHsfWinac (18e40c245dbfaf36fd0134a7ef2df396) C:\Windows\system32\DRIVERS\VSTCNXT6.SYS
13:56:34.0327 4108 SrvHsfWinac - ok
13:56:34.0373 4108 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
13:56:34.0373 4108 srvnet - ok
13:56:34.0405 4108 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
13:56:34.0405 4108 SSDPSRV - ok
13:56:34.0420 4108 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
13:56:34.0420 4108 SstpSvc - ok
13:56:34.0529 4108 Steam Client Service - ok
13:56:34.0561 4108 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
13:56:34.0561 4108 stexstor - ok
13:56:34.0623 4108 StillCam (decacb6921ded1a38642642685d77dac) C:\Windows\system32\DRIVERS\serscan.sys
13:56:34.0623 4108 StillCam - ok
13:56:34.0701 4108 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
13:56:34.0701 4108 stisvc - ok
13:56:34.0748 4108 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
13:56:34.0748 4108 swenum - ok
13:56:34.0826 4108 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
13:56:34.0841 4108 swprv - ok
13:56:34.0935 4108 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
13:56:34.0966 4108 SysMain - ok
13:56:35.0091 4108 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
13:56:35.0107 4108 TabletInputService - ok
13:56:35.0153 4108 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
13:56:35.0169 4108 TapiSrv - ok
13:56:35.0185 4108 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
13:56:35.0185 4108 TBS - ok
13:56:35.0341 4108 Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys
13:56:35.0356 4108 Tcpip - ok
13:56:35.0559 4108 TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys
13:56:35.0575 4108 TCPIP6 - ok
13:56:35.0699 4108 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
13:56:35.0699 4108 tcpipreg - ok
13:56:35.0762 4108 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
13:56:35.0762 4108 TDPIPE - ok
13:56:35.0824 4108 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
13:56:35.0824 4108 TDTCP - ok
13:56:35.0855 4108 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
13:56:35.0855 4108 tdx - ok
13:56:35.0902 4108 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
13:56:35.0902 4108 TermDD - ok
13:56:35.0933 4108 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
13:56:35.0949 4108 TermService - ok
13:56:35.0980 4108 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
13:56:35.0980 4108 Themes - ok
13:56:36.0074 4108 Thpdrv (c013f6acaa9761f571bd28dada7c157d) C:\Windows\system32\DRIVERS\thpdrv.sys
13:56:36.0089 4108 Thpdrv - ok
13:56:36.0121 4108 Thpevm (b4e609047434ed948af7bdef2fa66e38) C:\Windows\system32\DRIVERS\Thpevm.SYS
13:56:36.0136 4108 Thpevm - ok
13:56:36.0199 4108 Thpsrv (6146eac71ae3c9da17b0e33632082b7b) C:\Windows\system32\ThpSrv.exe
13:56:36.0214 4108 Thpsrv - ok
13:56:36.0261 4108 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
13:56:36.0261 4108 THREADORDER - ok
13:56:36.0323 4108 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
13:56:36.0323 4108 TrkWks - ok
13:56:36.0401 4108 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
13:56:36.0417 4108 TrustedInstaller - ok
13:56:36.0464 4108 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
13:56:36.0464 4108 tssecsrv - ok
13:56:36.0511 4108 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
13:56:36.0526 4108 TsUsbFlt - ok
13:56:36.0589 4108 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
13:56:36.0589 4108 tunnel - ok
13:56:36.0651 4108 TVALZ (9a744cc3d804ec38a6c2c65bc3c6fcd8) C:\Windows\system32\DRIVERS\TVALZ_O.SYS
13:56:36.0651 4108 TVALZ - ok
13:56:36.0667 4108 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
13:56:36.0667 4108 uagp35 - ok
13:56:36.0729 4108 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
13:56:36.0729 4108 udfs - ok
13:56:36.0776 4108 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
13:56:36.0776 4108 UI0Detect - ok
13:56:36.0823 4108 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
13:56:36.0823 4108 uliagpkx - ok
13:56:36.0901 4108 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
13:56:36.0901 4108 umbus - ok
13:56:36.0932 4108 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
13:56:36.0932 4108 UmPass - ok
13:56:36.0963 4108 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
13:56:36.0979 4108 upnphost - ok
13:56:37.0025 4108 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys
13:56:37.0041 4108 USBAAPL64 - ok
13:56:37.0072 4108 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
13:56:37.0088 4108 usbccgp - ok
13:56:37.0138 4108 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
13:56:37.0148 4108 usbcir - ok
13:56:37.0168 4108 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
13:56:37.0168 4108 usbehci - ok
13:56:37.0218 4108 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
13:56:37.0228 4108 usbhub - ok
13:56:37.0268 4108 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\DRIVERS\usbohci.sys
13:56:37.0268 4108 usbohci - ok
13:56:37.0368 4108 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
13:56:37.0398 4108 usbprint - ok
13:56:37.0498 4108 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
13:56:37.0498 4108 usbscan - ok
13:56:37.0518 4108 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:56:37.0518 4108 USBSTOR - ok
13:56:37.0528 4108 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
13:56:37.0528 4108 usbuhci - ok
13:56:37.0588 4108 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys
13:56:37.0598 4108 usbvideo - ok
13:56:37.0678 4108 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
13:56:37.0678 4108 UxSms - ok
13:56:37.0728 4108 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
13:56:37.0728 4108 VaultSvc - ok
13:56:37.0808 4108 VClone (fd911873c0bb6945fa38c16e9a2b58f9) C:\Windows\system32\DRIVERS\VClone.sys
13:56:37.0808 4108 VClone - ok
13:56:37.0868 4108 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
13:56:37.0878 4108 vdrvroot - ok
13:56:37.0938 4108 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
13:56:37.0948 4108 vds - ok
13:56:38.0018 4108 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
13:56:38.0038 4108 vga - ok
13:56:38.0068 4108 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
13:56:38.0068 4108 VgaSave - ok
13:56:38.0198 4108 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
13:56:38.0198 4108 vhdmp - ok
13:56:38.0228 4108 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
13:56:38.0228 4108 viaide - ok
13:56:38.0248 4108 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
13:56:38.0248 4108 volmgr - ok
13:56:38.0308 4108 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
13:56:38.0308 4108 volmgrx - ok
13:56:38.0348 4108 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
13:56:38.0348 4108 volsnap - ok
13:56:38.0378 4108 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
13:56:38.0378 4108 vsmraid - ok
13:56:38.0468 4108 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
13:56:38.0488 4108 VSS - ok
13:56:38.0598 4108 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
13:56:38.0608 4108 vwifibus - ok
13:56:38.0658 4108 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
13:56:38.0658 4108 vwififlt - ok
13:56:38.0698 4108 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
13:56:38.0708 4108 W32Time - ok
13:56:38.0728 4108 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
13:56:38.0728 4108 WacomPen - ok
13:56:38.0788 4108 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
13:56:38.0788 4108 WANARP - ok
13:56:38.0798 4108 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
13:56:38.0798 4108 Wanarpv6 - ok
13:56:38.0938 4108 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
13:56:38.0948 4108 WatAdminSvc - ok
13:56:39.0038 4108 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
13:56:39.0058 4108 wbengine - ok
13:56:39.0165 4108 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
13:56:39.0180 4108 WbioSrvc - ok
13:56:39.0243 4108 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
13:56:39.0243 4108 wcncsvc - ok
13:56:39.0258 4108 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
13:56:39.0258 4108 WcsPlugInService - ok
13:56:39.0305 4108 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
13:56:39.0321 4108 Wd - ok
13:56:39.0352 4108 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
13:56:39.0367 4108 Wdf01000 - ok
13:56:39.0367 4108 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
13:56:39.0383 4108 WdiServiceHost - ok
13:56:39.0383 4108 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
13:56:39.0383 4108 WdiSystemHost - ok
13:56:39.0430 4108 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
13:56:39.0445 4108 WebClient - ok
13:56:39.0461 4108 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
13:56:39.0461 4108 Wecsvc - ok
13:56:39.0492 4108 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
13:56:39.0492 4108 wercplsupport - ok
13:56:39.0539 4108 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
13:56:39.0555 4108 WerSvc - ok
13:56:39.0617 4108 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
13:56:39.0617 4108 WfpLwf - ok
13:56:39.0633 4108 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
13:56:39.0633 4108 WIMMount - ok
13:56:39.0648 4108 WinHttpAutoProxySvc - ok
13:56:39.0711 4108 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
13:56:39.0711 4108 Winmgmt - ok
13:56:39.0804 4108 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
13:56:39.0835 4108 WinRM - ok
13:56:39.0991 4108 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
13:56:40.0007 4108 Wlansvc - ok
13:56:40.0069 4108 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
13:56:40.0069 4108 WmiAcpi - ok
13:56:40.0132 4108 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
13:56:40.0132 4108 wmiApSrv - ok
13:56:40.0163 4108 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
13:56:40.0179 4108 WPCSvc - ok
13:56:40.0210 4108 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
13:56:40.0225 4108 WPDBusEnum - ok
13:56:40.0272 4108 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
13:56:40.0272 4108 ws2ifsl - ok
13:56:40.0272 4108 WSearch - ok
13:56:40.0569 4108 wuauserv (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll
13:56:40.0647 4108 wuauserv - ok
13:56:40.0818 4108 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
13:56:40.0818 4108 WudfPf - ok
13:56:40.0865 4108 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
13:56:40.0865 4108 WUDFRd - ok
13:56:40.0912 4108 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
13:56:40.0912 4108 wudfsvc - ok
13:56:40.0959 4108 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
13:56:40.0974 4108 WwanSvc - ok
13:56:41.0005 4108 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
13:56:41.0037 4108 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected
13:56:41.0037 4108 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0)
13:56:41.0068 4108 Boot (0x1200) (cf29f54119d101324293c8c935f9b59a) \Device\Harddisk0\DR0\Partition0
13:56:41.0068 4108 \Device\Harddisk0\DR0\Partition0 - ok
13:56:41.0068 4108 Boot (0x1200) (a59a3e8ba36e84e957812fffa5b774c9) \Device\Harddisk0\DR0\Partition1
13:56:41.0083 4108 \Device\Harddisk0\DR0\Partition1 - ok
13:56:41.0083 4108 ============================================================
13:56:41.0083 4108 Scan finished
13:56:41.0083 4108 ============================================================
13:56:41.0099 1504 Detected object count: 1
13:56:41.0099 1504 Actual detected object count: 1
13:57:06.0475 1504 \Device\Harddisk0\DR0\# - copied to quarantine
13:57:06.0475 1504 \Device\Harddisk0\DR0 - copied to quarantine
13:57:06.0505 1504 \Device\Harddisk0\DR0\TDLFS\cmd.dll - copied to quarantine
13:57:06.0505 1504 \Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine
13:57:06.0515 1504 \Device\Harddisk0\DR0\TDLFS\sub.dll - copied to quarantine
13:57:06.0515 1504 \Device\Harddisk0\DR0\TDLFS\subx.dll - copied to quarantine
13:57:06.0525 1504 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine
13:57:06.0535 1504 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine
13:57:06.0535 1504 \Device\Harddisk0\DR0\TDLFS\servers.dat - copied to quarantine
13:57:06.0535 1504 \Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine
13:57:06.0535 1504 \Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine
13:57:06.0545 1504 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine
13:57:06.0545 1504 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine
13:57:06.0545 1504 \Device\Harddisk0\DR0\TDLFS\s - copied to quarantine
13:57:06.0565 1504 \Device\Harddisk0\DR0\TDLFS\ldrm - copied to quarantine
13:57:06.0575 1504 \Device\Harddisk0\DR0\TDLFS\u - copied to quarantine
13:57:06.0795 1504 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - will be cured on reboot
13:57:06.0795 1504 \Device\Harddisk0\DR0 - ok
13:57:06.0825 1504 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - User select action: Cure
13:57:19.0897 2112 Deinitialize success
Combo Fix Log ComboFix 12-07-21.01 - Pete 07/22/2012 14:39:52.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3838.2587 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed] c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\chrome.manifest c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\chrome\content\background.html c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\chrome\content\browser.xul c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\chrome\content\crossrider.js c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\chrome\content\crossriderapi.js c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\chrome\content\dialog.js c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\chrome\content\options.js c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\chrome\content\options.xul c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\chrome\content\search_dialog.xul c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\chrome\content\update.html c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\defaults\preferences\prefs.js c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\chrome.manifest c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\chrome\content\background.html c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\chrome\content\browser.xul c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\chrome\content\crossrider.js c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\chrome\content\crossriderapi.js c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\chrome\content\dialog.js c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\chrome\content\options.js c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\chrome\content\options.xul c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\chrome\content\search_dialog.xul c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\chrome\content\update.html c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\defaults\preferences\prefs.js c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\install.rdf c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\locale\en-US\translations.dtd c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\skin\button1.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\skin\button2.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\skin\button3.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\skin\button4.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\skin\button5.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\skin\crossrider_statusbar.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\skin\icon24.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\skin\icon48.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\skin\panelarrow-up.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\skin\popup.css c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\skin\popup.html c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\skin\popup_binding.xml c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\skin\skin.css c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\firefox-production\skin\update.css c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\install.rdf c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\locale\en-US\translations.dtd c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\skin\button1.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\skin\button2.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\skin\button3.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\skin\button4.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\skin\button5.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\skin\crossrider_statusbar.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\skin\icon128.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\skin\icon16.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\skin\icon24.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\skin\icon48.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\skin\panelarrow-up.png c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\skin\popup.css c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\skin\popup.html c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\skin\popup_binding.xml c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\skin\skin.css c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\extensions\[removed]\skin\update.css c:\windows\assembly\GAC_32\Desktop.ini c:\windows\assembly\GAC_64\Desktop.ini c:\windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\@ c:\windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\L\00000004.@ c:\windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\L\201d3dde c:\windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\n c:\windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\U\00000004.@ c:\windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\U\00000008.@ c:\windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\U\000000cb.@ c:\windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\U\80000000.@ c:\windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\U\80000032.@ c:\windows\Installer\{86b67214-cacf-3544-f67a-920439385c0d}\U\80000064.@ c:\windows\svchost.exe . . ((((((((((((((((((((((((( Files Created from 2012-06-22 to 2012-07-22 ))))))))))))))))))))))))))))))) . . 2012-07-22 21:52 . 2012-07-22 21:52 ——– d—–w- c:\users\Guest.JOCELIN-ARRIK\AppData\Local\temp 2012-07-22 21:52 . 2012-07-22 21:52 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-07-22 20:57 . 2012-07-22 20:57 ——– d—–w- C:\TDSSKiller_Quarantine 2012-07-22 20:50 . 2012-07-22 20:50 ——– d—–w- c:\program files (x86)\7-Zip 2012-07-22 19:57 . 2012-07-22 19:57 ——– d—–w- C:\_OTL 2012-07-20 20:30 . 2012-07-20 20:30 ——– d—–w- C:\c774baca38044aeb2e6250e48a751daf 2012-07-20 20:30 . 2012-07-20 20:30 ——– d—–w- C:\66bab871d1c4b24af42e95e990d178 2012-07-19 06:58 . 2012-07-19 06:58 ——– d-sh–w- c:\windows\SysWow64\%APPDATA% 2012-07-11 20:22 . 2012-06-12 03:08 3148800 —-a-w- c:\windows\system32\win32k.sys 2012-07-10 19:09 . 2012-06-06 06:05 1499136 —-a-w- c:\program files\Common Files\System\ado\msado15.dll 2012-07-10 19:09 . 2012-06-06 05:05 1019904 —-a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll 2012-07-10 19:09 . 2012-06-06 06:05 495616 —-a-w- c:\program files\Common Files\System\ado\msadox.dll 2012-07-10 19:09 . 2012-06-06 06:05 61440 —-a-w- c:\program files\Common Files\System\ado\msador15.dll 2012-07-10 19:09 . 2012-06-06 06:05 466944 —-a-w- c:\program files\Common Files\System\ado\msadomd.dll 2012-07-10 19:09 . 2012-06-06 06:05 258048 —-a-w- c:\program files\Common Files\System\msadc\msadco.dll 2012-07-10 19:09 . 2012-06-06 05:05 57344 —-a-w- c:\program files (x86)\Common Files\System\ado\msador15.dll 2012-07-10 19:09 . 2012-06-06 05:05 352256 —-a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll 2012-07-10 19:09 . 2012-06-06 05:03 805376 —-a-w- c:\windows\SysWow64\cdosys.dll 2012-07-10 19:09 . 2012-06-06 06:02 1133568 —-a-w- c:\windows\system32\cdosys.dll 2012-07-10 19:09 . 2012-06-06 05:05 143360 —-a-w- c:\program files (x86)\Common Files\System\ado\msjro.dll 2012-07-10 19:09 . 2012-06-06 05:05 372736 —-a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll 2012-07-10 19:09 . 2012-06-06 05:05 212992 —-a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll 2012-06-23 18:35 . 2012-06-23 18:35 ——– d—–w- c:\users\Pete\AppData\Local\Macromedia 2012-06-23 03:04 . 2012-06-23 03:04 ——– d—–w- c:\users\Pete\AppData\Local\APN 2012-06-23 03:04 . 2012-06-23 03:04 ——– d—–w- c:\users\Pete\AppData\Roaming\NCH Software 2012-06-23 03:04 . 2012-06-23 03:04 ——– d—–w- c:\programdata\NCH Software 2012-06-23 03:04 . 2012-06-23 03:04 ——– d—–w- c:\program files (x86)\NCH Software . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-11 23:34 . 2012-03-31 17:07 426184 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-07-11 23:34 . 2011-07-23 04:55 70344 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-07-11 20:06 . 2010-02-09 23:36 59701280 —-a-w- c:\windows\system32\MRT.exe 2012-06-06 20:18 . 2010-05-12 22:20 560184 —-a-w- c:\windows\system32\drivers\sptd.sys 2012-06-02 22:19 . 2012-06-22 04:39 38424 —-a-w- c:\windows\system32\wups.dll 2012-06-02 22:19 . 2012-06-22 04:39 2428952 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-02 22:19 . 2012-06-22 04:39 44056 —-a-w- c:\windows\system32\wups2.dll 2012-06-02 22:19 . 2012-06-22 04:39 57880 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2012-06-22 04:39 186752 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-02 22:19 . 2012-06-22 04:39 701976 —-a-w- c:\windows\system32\wuapi.dll 2012-06-02 22:15 . 2012-06-22 04:39 2622464 —-a-w- c:\windows\system32\wucltux.dll 2012-06-02 22:15 . 2012-06-22 04:39 36864 —-a-w- c:\windows\system32\wuapp.exe 2012-06-02 22:15 . 2012-06-22 04:39 99840 —-a-w- c:\windows\system32\wudriver.dll 2012-05-15 04:01 . 2012-06-13 06:21 1188864 —-a-w- c:\windows\system32\wininet.dll 2012-05-15 03:59 . 2012-06-13 06:21 64512 —-a-w- c:\windows\system32\jsproxy.dll 2012-05-15 03:03 . 2012-06-13 06:21 981504 —-a-w- c:\windows\SysWow64\wininet.dll 2012-05-04 11:06 . 2012-06-13 06:21 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-05-04 10:03 . 2012-06-13 06:21 3968368 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-05-04 10:03 . 2012-06-13 06:21 3913072 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-05-01 05:40 . 2012-06-13 06:21 209920 —-a-w- c:\windows\system32\profsvc.dll 2012-04-28 03:55 . 2012-06-13 06:21 210944 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-26 05:41 . 2012-06-13 06:21 77312 —-a-w- c:\windows\system32\rdpwsx.dll 2012-04-26 05:41 . 2012-06-13 06:21 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-04-26 05:34 . 2012-06-13 06:21 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-04-24 05:37 . 2012-06-13 06:20 184320 —-a-w- c:\windows\system32\cryptsvc.dll 2012-04-24 05:37 . 2012-06-13 06:20 140288 —-a-w- c:\windows\system32\cryptnet.dll 2012-04-24 05:37 . 2012-06-13 06:20 1462272 —-a-w- c:\windows\system32\crypt32.dll 2012-04-24 04:36 . 2012-06-13 06:20 1158656 —-a-w- c:\windows\SysWow64\crypt32.dll 2012-04-24 04:36 . 2012-06-13 06:20 140288 —-a-w- c:\windows\SysWow64\cryptsvc.dll 2012-04-24 04:36 . 2012-06-13 06:20 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\steam.exe" [2011-08-02 1242448] "Facebook Update"="c:\users\Pete\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-11 138096] "DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2012-04-26 3111744] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296] "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376] "HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-04 135664] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-11 250056] R3 dump_wmimmc;dump_wmimmc;c:\program files (x86)\softnyxGame\GunBoundIS\GameGuard\dump_wmimmc.sys [x] R3 Gun;Gun;c:\windows\system32\Gun64.sys [2011-01-14 30840] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-04 135664] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-19 113120] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [x] R3 rtl819xp;Realtek RTL8190\RTL8192E 802.11n Wireless LAN (Mini-)PCI NIC NT Driver;c:\windows\system32\DRIVERS\rtl819xp.sys [2010-01-25 620576] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-03 1255736] S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x] S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys [2009-06-29 34880] S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [2009-06-30 14784] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 203264] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2009-11-13 67072] S3 O2MDGRDR;O2MDGRDR;c:\windows\system32\DRIVERS\o2mdgx64.sys [2009-03-11 69536] S3 rtl819xpn64;Realtek RTL8190/RTL8192E 802.11n Wireless LAN (Mini-)PCI NIC NT Driver;c:\windows\system32\DRIVERS\rtl819xp.sys [2010-01-25 620576] S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864] S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312] S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864] . . Contents of the 'Scheduled Tasks' folder . 2012-07-22 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 23:34] . 2012-07-15 c:\windows\Tasks\Driver Fetch.job - c:\program files (x86)\Driver Fetch\2.1.0.0\DriverFetch.exe [2010-02-23 20:08] . 2012-07-21 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3216521362-3930712179-4014682732-1000Core.job - c:\users\Pete\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-01 23:03] . 2012-07-22 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3216521362-3930712179-4014682732-1000UA.job - c:\users\Pete\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-01 23:03] . 2012-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-04 21:53] . 2012-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-04 21:53] . 2012-07-16 c:\windows\Tasks\Norton Security Scan for Pete.job - c:\progra~2\NORTON~2\Engine\361~1.11\Nss.exe [2011-12-29 09:45] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ThpSrv"="c:\windows\system32\thpsrv" [X] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2009-07-20 503864] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "NCInstallQueue"="netman.dll" [2009-07-14 360448] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\system32\blank.htm uSearchAssistant = TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q= FF - prefs.js: browser.search.selectedEngine - Web Search FF - prefs.js: browser.startup.homepage - www.google.com FF - prefs.js: keyword.URL - hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=US&userid=2ad75993-39a7-4b76-b14b-0899ab600fa5&affid=110774&searchtype=ds&babsrc=lnkry&q= FF - user.js: yahoo.homepage.dontask - true);user_pref(general.useragent.extra.brc, BRI/1 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKCU-Run-EA Core - c:\program files (x86)\Electronic Arts\EADM\Core.exe WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file) AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe AddRemove-Origin - c:\program files (x86)\Origin\OriginUninstall.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-3216521362-3930712179-4014682732-1000\Software\SecuROM\License information*] "datasecu"=hex:87,ae,4b,bc,8d,62,d7,27,42,0c,c3,9b,f0,8a,78,4a,c9,c8,28,90,50, f5,0f,f3,b7,5f,c2,80,96,0e,9b,44,db,ac,df,1b,22,0b,33,c8,c8,ab,f3,7f,87,a9,\ "rkeysecu"=hex:5b,96,6e,02,e2,9d,c7,e6,a9,2f,9a,0f,80,ef,cd,60 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\windows\system32\DRIVERS\o2flash.exe c:\windows\SysWOW64\PnkBstrA.exe c:\program files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe . ************************************************************************** . Completion time: 2012-07-22 15:00:45 - machine was rebooted ComboFix-quarantined-files.txt 2012-07-22 22:00 . Pre-Run: 250,563,940,352 bytes free Post-Run: 250,235,711,488 bytes free . - - End Of File - - 2E67ED9A7411A7F081117FA98E338F8C
Thanks for the logs and well done with the network connection.


Open ComboFix

Please do the following:
  • close any open browsers.
  • close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
  • open notepad and copy/paste the text in the codebox below into it:
DirLook:: 
C:\c774baca38044aeb2e6250e48a751daf
C:\66bab871d1c4b24af42e95e990d178

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.

Can you tell me how your computer is now

Satchfan
Hey Satchfan, heres the log ======================================== ComboFix 12-07-25.04 - Pete 07/24/2012 15:32:24.2.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3838.2317 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Pete\Desktop\CFScript.txt SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2012-06-24 to 2012-07-24 ))))))))))))))))))))))))))))))) . . 2012-07-24 22:42 . 2012-07-24 22:42 ——– d—–w- c:\users\Guest\AppData\Local\temp 2012-07-24 22:42 . 2012-07-24 22:42 ——– d—–w- c:\users\Guest.JOCELIN-ARRIK\AppData\Local\temp 2012-07-24 22:42 . 2012-07-24 22:42 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-07-24 22:42 . 2012-07-24 22:42 ——– d—–w- c:\users\Arrik\AppData\Local\temp 2012-07-22 21:10 . 2012-07-22 21:10 ——– d—–w- c:\users\Pete\AppData\Roaming\AVG9 2012-07-22 20:57 . 2012-07-22 20:57 ——– d—–w- C:\TDSSKiller_Quarantine 2012-07-22 20:50 . 2012-07-22 20:50 ——– d—–w- c:\program files (x86)\7-Zip 2012-07-22 19:57 . 2012-07-22 19:57 ——– d—–w- C:\_OTL 2012-07-20 20:30 . 2012-07-20 20:30 ——– d—–w- C:\c774baca38044aeb2e6250e48a751daf 2012-07-20 20:30 . 2012-07-20 20:30 ——– d—–w- C:\66bab871d1c4b24af42e95e990d178 2012-07-19 06:58 . 2012-07-19 06:58 ——– d-sh–w- c:\windows\SysWow64\%APPDATA% 2012-07-11 20:22 . 2012-06-12 03:08 3148800 —-a-w- c:\windows\system32\win32k.sys 2012-07-10 19:09 . 2012-06-06 06:05 1499136 —-a-w- c:\program files\Common Files\System\ado\msado15.dll 2012-07-10 19:09 . 2012-06-06 05:05 1019904 —-a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll 2012-07-10 19:09 . 2012-06-06 06:05 495616 —-a-w- c:\program files\Common Files\System\ado\msadox.dll 2012-07-10 19:09 . 2012-06-06 06:05 61440 —-a-w- c:\program files\Common Files\System\ado\msador15.dll 2012-07-10 19:09 . 2012-06-06 06:05 466944 —-a-w- c:\program files\Common Files\System\ado\msadomd.dll 2012-07-10 19:09 . 2012-06-06 06:05 258048 —-a-w- c:\program files\Common Files\System\msadc\msadco.dll 2012-07-10 19:09 . 2012-06-06 05:05 57344 —-a-w- c:\program files (x86)\Common Files\System\ado\msador15.dll 2012-07-10 19:09 . 2012-06-06 05:05 352256 —-a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll 2012-07-10 19:09 . 2012-06-06 05:03 805376 —-a-w- c:\windows\SysWow64\cdosys.dll 2012-07-10 19:09 . 2012-06-06 06:02 1133568 —-a-w- c:\windows\system32\cdosys.dll 2012-07-10 19:09 . 2012-06-06 05:05 143360 —-a-w- c:\program files (x86)\Common Files\System\ado\msjro.dll 2012-07-10 19:09 . 2012-06-06 05:05 372736 —-a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll 2012-07-10 19:09 . 2012-06-06 05:05 212992 —-a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-11 23:34 . 2012-03-31 17:07 426184 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-07-11 23:34 . 2011-07-23 04:55 70344 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-07-11 20:06 . 2010-02-09 23:36 59701280 —-a-w- c:\windows\system32\MRT.exe 2012-06-06 20:18 . 2010-05-12 22:20 560184 —-a-w- c:\windows\system32\drivers\sptd.sys 2012-06-02 22:19 . 2012-06-22 04:39 38424 —-a-w- c:\windows\system32\wups.dll 2012-06-02 22:19 . 2012-06-22 04:39 2428952 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-02 22:19 . 2012-06-22 04:39 44056 —-a-w- c:\windows\system32\wups2.dll 2012-06-02 22:19 . 2012-06-22 04:39 57880 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2012-06-22 04:39 186752 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-02 22:19 . 2012-06-22 04:39 701976 —-a-w- c:\windows\system32\wuapi.dll 2012-06-02 22:15 . 2012-06-22 04:39 2622464 —-a-w- c:\windows\system32\wucltux.dll 2012-06-02 22:15 . 2012-06-22 04:39 36864 —-a-w- c:\windows\system32\wuapp.exe 2012-06-02 22:15 . 2012-06-22 04:39 99840 —-a-w- c:\windows\system32\wudriver.dll 2012-05-15 04:01 . 2012-06-13 06:21 1188864 —-a-w- c:\windows\system32\wininet.dll 2012-05-15 03:59 . 2012-06-13 06:21 64512 —-a-w- c:\windows\system32\jsproxy.dll 2012-05-15 03:03 . 2012-06-13 06:21 981504 —-a-w- c:\windows\SysWow64\wininet.dll 2012-05-04 11:06 . 2012-06-13 06:21 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-05-04 10:03 . 2012-06-13 06:21 3968368 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-05-04 10:03 . 2012-06-13 06:21 3913072 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-05-01 05:40 . 2012-06-13 06:21 209920 —-a-w- c:\windows\system32\profsvc.dll 2012-04-28 03:55 . 2012-06-13 06:21 210944 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-26 05:41 . 2012-06-13 06:21 77312 —-a-w- c:\windows\system32\rdpwsx.dll 2012-04-26 05:41 . 2012-06-13 06:21 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-04-26 05:34 . 2012-06-13 06:21 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe . . (((((((((((((((((((((((((((((((((((((((((((( Look ))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . —- Directory of C:\66bab871d1c4b24af42e95e990d178 —- . 2012-07-20 20:30 . 2012-07-20 20:30 788 —ha-w- c:\66bab871d1c4b24af42e95e990d178\$shtdwn$.req 2010-12-11 16:57 . 2010-12-11 16:57 57447776 —-a-w- c:\66bab871d1c4b24af42e95e990d178\hotfixexpress\files\sqlexpr.exe 2010-12-11 10:34 . 2010-12-11 10:34 2124 —-a-w- c:\66bab871d1c4b24af42e95e990d178\hotfixexpress.inf 2010-12-11 10:34 . 2010-12-11 10:34 534 —-a-w- c:\66bab871d1c4b24af42e95e990d178\master.inf 2010-12-11 01:29 . 2010-12-11 01:29 140640 —-a-w- c:\66bab871d1c4b24af42e95e990d178\sqlcmd.exe 2010-12-11 01:29 . 2010-12-11 01:29 529760 —-a-w- c:\66bab871d1c4b24af42e95e990d178\sqldiscoveryapi.dll 2010-12-11 01:29 . 2010-12-11 01:29 226656 —-a-w- c:\66bab871d1c4b24af42e95e990d178\sqlsetupvista.dll 2010-12-11 01:20 . 2010-12-11 01:20 23904 —-a-w- c:\66bab871d1c4b24af42e95e990d178\sqlcmd.rll 2010-12-11 01:17 . 2010-12-11 01:17 50528 —-a-w- c:\66bab871d1c4b24af42e95e990d178\osql.exe 2010-12-11 00:55 . 2010-12-11 00:55 2542944 —-a-w- c:\66bab871d1c4b24af42e95e990d178\hotfix.exe 2010-12-11 00:55 . 2010-12-11 00:55 52576 —-a-w- c:\66bab871d1c4b24af42e95e990d178\1033\hotfix.rll 2010-12-11 00:55 . 2010-12-11 00:55 60256 —-a-w- c:\66bab871d1c4b24af42e95e990d178\1033\sqlse.rll 2010-12-11 00:37 . 2010-12-11 00:37 124256 —-a-w- c:\66bab871d1c4b24af42e95e990d178\batchparser90.dll 2010-12-10 16:04 . 2010-12-10 16:04 1002 —-a-w- c:\66bab871d1c4b24af42e95e990d178\1033\eula.txt 2010-12-10 16:04 . 2010-12-10 16:04 1306 —-a-w- c:\66bab871d1c4b24af42e95e990d178\1033\finalsql2005information.rtf 2010-12-10 16:04 . 2010-12-10 16:04 116104 —-a-w- c:\66bab871d1c4b24af42e95e990d178\1033\sqlhotfix.chm 2005-10-14 09:44 . 2005-10-14 09:44 15064 —-a-w- c:\66bab871d1c4b24af42e95e990d178\osql.rll 2005-10-14 06:26 . 2005-10-14 06:26 548864 —-a-w- c:\66bab871d1c4b24af42e95e990d178\msvcp80.dll 2005-10-14 06:26 . 2005-10-14 06:26 626688 —-a-w- c:\66bab871d1c4b24af42e95e990d178\msvcr80.dll . —- Directory of C:\c774baca38044aeb2e6250e48a751daf —- . 2010-12-11 09:27 . 2010-12-11 09:27 5542400 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\sqlrun.msi 2010-12-11 09:24 . 2010-12-11 09:24 5180928 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\sqlrun_tools.msi 2010-12-11 09:23 . 2010-12-11 09:23 6642688 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\sqlrun_sql.msi 2010-12-11 09:23 . 2010-12-11 09:23 2650 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\sqlrun_sql.ini 2010-12-11 09:06 . 2010-12-11 09:06 9260032 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\sqlsupport.msi 2010-12-11 09:06 . 2010-12-11 09:06 1292288 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\sqlwriter.msi 2010-12-11 09:06 . 2010-12-11 09:06 3610624 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\sqlncli.msi 2010-12-11 07:19 . 2010-12-11 07:19 6577152 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\sqlncli_x64.msi 2010-12-11 07:19 . 2010-12-11 07:19 3281920 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\sqlwriter_x64.msi 2010-12-11 01:32 . 2010-12-11 01:32 166240 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\xmlrw.dll 2010-12-11 01:32 . 2010-12-11 01:32 192352 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\xmlsub.dll 2010-12-11 01:32 . 2010-12-11 01:32 166240 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\xmlrw.dll 2010-12-11 01:32 . 2010-12-11 01:32 166240 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\xmlrw.dll 2010-12-11 01:32 . 2010-12-11 01:32 120160 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\xmlrwbin.dll 2010-12-11 01:32 . 2010-12-11 01:32 47968 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\xpadsi90.exe 2010-12-11 01:32 . 2010-12-11 01:32 37216 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\xplog70.dll 2010-12-11 01:32 . 2010-12-11 01:32 53600 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\xpqueue.dll 2010-12-11 01:32 . 2010-12-11 01:32 69984 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\xprepl.dll 2010-12-11 01:32 . 2010-12-11 01:32 18784 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\xpsqlbot.dll 2010-12-11 01:32 . 2010-12-11 01:32 297312 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\xpstar90.dll 2010-12-11 01:30 . 2010-12-11 01:30 83808 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\tablediff.exe 2010-12-11 01:30 . 2010-12-11 01:30 87392 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\sqlwep.dll 2010-12-11 01:30 . 2010-12-11 01:30 39264 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\ssradd.dll 2010-12-11 01:30 . 2010-12-11 01:30 39776 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\ssravg.dll 2010-12-11 01:30 . 2010-12-11 01:30 25952 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\ssrdown.dll 2010-12-11 01:30 . 2010-12-11 01:30 37728 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\ssrmax.dll 2010-12-11 01:30 . 2010-12-11 01:30 37728 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\ssrmin.dll 2010-12-11 01:30 . 2010-12-11 01:30 26976 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\ssrpub.dll 2010-12-11 01:30 . 2010-12-11 01:30 25952 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\ssrup.dll 2010-12-11 01:30 . 2010-12-11 01:30 96096 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\sqlwtsn.exe 2010-12-11 01:30 . 2010-12-11 01:30 610656 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\svrenumapi.dll 2010-12-11 01:29 . 2010-12-11 01:29 2151264 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup.exe 2010-12-11 01:29 . 2010-12-11 01:29 672096 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\sqlcu.dll 2010-12-11 01:29 . 2010-12-11 01:29 173920 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\spresolv.dll 2010-12-11 01:29 . 2010-12-11 01:29 145248 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\sqldistx.dll 2010-12-11 01:29 . 2010-12-11 01:29 191328 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\sqlmergx.dll 2010-12-11 01:29 . 2010-12-11 01:29 44384 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\sqladhlp90.exe 2010-12-11 01:29 . 2010-12-11 01:29 46432 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\sqlboot.dll 2010-12-11 01:29 . 2010-12-11 01:29 238944 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\sqlbrowser.exe 2010-12-11 01:29 . 2010-12-11 01:29 65888 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\sqldumper.exe 2010-12-11 01:29 . 2010-12-11 01:29 24416 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\sqlftacct.dll 2010-12-11 01:29 . 2010-12-11 01:29 234848 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\sqlmgmprovider.dll 2010-12-11 01:29 . 2010-12-11 01:29 120672 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\sqlprov.exe 2010-12-11 01:29 . 2010-12-11 01:29 1242976 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\sqlsac.exe 2010-12-11 01:29 . 2010-12-11 01:29 15200 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\sqlsecacctchg.dll 2010-12-11 01:29 . 2010-12-11 01:29 137056 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\sqlsqm.exe 2010-12-11 01:29 . 2010-12-11 01:29 88928 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\sqlsvcsync.dll 2010-12-11 01:29 . 2010-12-11 01:29 140640 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\sqlcmd.exe 2010-12-11 01:29 . 2010-12-11 01:29 1072480 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\sqldiag.exe 2010-12-11 01:29 . 2010-12-11 01:29 499040 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\sqlmanager.dll 2010-12-11 01:29 . 2010-12-11 01:29 104800 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\sqlsvc90.dll 2010-12-11 01:29 . 2010-12-11 01:29 348000 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\sqlaccess.dll 2010-12-11 01:29 . 2010-12-11 01:29 46432 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\sqlboot.dll 2010-12-11 01:29 . 2010-12-11 01:29 75104 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\sqlmaint.exe 2010-12-11 01:29 . 2010-12-11 01:29 14176 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\sqlos.dll 2010-12-11 01:29 . 2010-12-11 01:29 29293408 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\sqlservr.exe 2010-12-11 01:29 . 2010-12-11 01:29 104800 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\sqlsvc90.dll 2010-12-11 01:29 . 2010-12-11 01:29 64864 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\system\sqlctr90.dll 2010-12-11 01:29 . 2010-12-11 01:29 79712 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\sac.exe 2010-12-11 01:20 . 2010-12-11 01:20 202592 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup.rll 2010-12-11 01:20 . 2010-12-11 01:20 281952 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\resources\1033\replres.rll 2010-12-11 01:20 . 2010-12-11 01:20 23904 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\resources\1033\sqlcmd.rll 2010-12-11 01:20 . 2010-12-11 01:20 51552 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\resources\1033\sqldiag.rll 2010-12-11 01:20 . 2010-12-11 01:20 144224 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\resources\1033\sqlmanager.rll 2010-12-11 01:20 . 2010-12-11 01:20 281952 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\common files\microsoft shared\database replication\resources\1033\replres.rll 2010-12-11 01:20 . 2010-12-11 01:20 1738080 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\res\1033\sqlevn70.rll 2010-12-11 01:20 . 2010-12-11 01:20 19296 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\res\1033\sqlmaint.rll 2010-12-11 01:20 . 2010-12-11 01:20 151904 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\res\1033\xpstar90.rll 2010-12-11 01:19 . 2010-12-11 01:19 644448 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\rdistcom.dll 2010-12-11 01:19 . 2010-12-11 01:19 110944 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\replerrx.dll 2010-12-11 01:19 . 2010-12-11 01:19 269664 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\replisapi.dll 2010-12-11 01:19 . 2010-12-11 01:19 317792 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\replmerg.exe 2010-12-11 01:19 . 2010-12-11 01:19 551776 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\replprov.dll 2010-12-11 01:19 . 2010-12-11 01:19 783200 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\replrec.dll 2010-12-11 01:19 . 2010-12-11 01:19 405344 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\replsub.dll 2010-12-11 01:19 . 2010-12-11 01:19 98144 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\replsync.dll 2010-12-11 01:17 . 2010-12-11 01:17 50528 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\osql.exe 2010-12-11 01:17 . 2010-12-11 01:17 55648 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\odsole70.dll 2010-12-11 01:16 . 2010-12-11 01:16 1625440 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\microsoft.sqlserver.replication.dll 2010-12-11 01:16 . 2010-12-11 01:16 196960 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\msgprox.dll 2010-12-11 01:16 . 2010-12-11 01:16 67424 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\gac\microsoft.sqlserver.regsvrenum.dll 2010-12-11 01:16 . 2010-12-11 01:16 554848 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\gac\microsoft.sqlserver.rmo.dll 2010-12-11 01:16 . 2010-12-11 01:16 38752 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\gac\microsoft.sqlserver.servicebrokerenum.dll 2010-12-11 01:16 . 2010-12-11 01:16 1603424 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\gac\microsoft.sqlserver.smo.dll 2010-12-11 01:16 . 2010-12-11 01:16 218976 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\gac\microsoft.sqlserver.smoenum.dll 2010-12-11 01:16 . 2010-12-11 01:16 919392 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\gac\microsoft.sqlserver.sqlenum.dll 2010-12-11 01:16 . 2010-12-11 01:16 42848 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\gac\microsoft.sqlserver.wmienum.dll 2010-12-11 01:16 . 2010-12-11 01:16 67424 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\microsoft.sqlserver.regsvrenum.dll 2010-12-11 01:16 . 2010-12-11 01:16 1625440 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\microsoft.sqlserver.replication.dll 2010-12-11 01:16 . 2010-12-11 01:16 554848 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\microsoft.sqlserver.rmo.dll 2010-12-11 01:16 . 2010-12-11 01:16 38752 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\microsoft.sqlserver.servicebrokerenum.dll 2010-12-11 01:16 . 2010-12-11 01:16 1603424 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\microsoft.sqlserver.smo.dll 2010-12-11 01:16 . 2010-12-11 01:16 218976 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\microsoft.sqlserver.smoenum.dll 2010-12-11 01:16 . 2010-12-11 01:16 919392 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\microsoft.sqlserver.sqlenum.dll 2010-12-11 01:16 . 2010-12-11 01:16 42848 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\microsoft.sqlserver.wmienum.dll 2010-12-11 01:16 . 2010-12-11 01:16 74592 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\microsoft.sqlserver.mgdsqldumper.dll 2010-12-11 01:16 . 2010-12-11 01:16 20320 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\msasxpress.dll 2010-12-11 01:16 . 2010-12-11 01:16 866656 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\msxmlsql.dll 2010-12-11 01:12 . 2010-12-11 01:12 359776 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\gac\microsoft.sqlserver.batchparser.dll 2010-12-11 01:12 . 2010-12-11 01:12 153440 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\gac\microsoft.sqlserver.connectioninfo.dll 2010-12-11 01:12 . 2010-12-11 01:12 153440 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\microsoft.sqlserver.connectioninfo.dll 2010-12-11 01:12 . 2010-12-11 01:12 444256 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\microsoft.sqlsac.public.dll 2010-12-11 01:10 . 2010-12-11 01:10 137056 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\gac\microsoft.analysisservices.deploymentengine.dll 2010-12-11 01:10 . 2010-12-11 01:10 1214304 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\gac\microsoft.analysisservices.dll 2010-12-11 01:10 . 2010-12-11 01:10 34656 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\gac\microsoft.datawarehouse.interfaces.dll 2010-12-11 01:10 . 2010-12-11 01:10 132960 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\microsoft.netenterpriseservers.exceptionmessagebox.dll 2010-12-11 01:10 . 2010-12-11 01:10 29024 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\mergetxt.dll 2010-12-11 01:10 . 2010-12-11 01:10 542560 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft.net\adomd.net\microsoft.analysisservices.adomdclient.dll 2010-12-11 01:10 . 2010-12-11 01:10 542560 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft.net\adomd.net\90\microsoft.analysisservices.adomdclient.dll 2010-12-11 00:55 . 2010-12-11 00:55 13664 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\isacctchange.dll 2010-12-11 00:43 . 2010-12-11 00:43 67424 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\distrib.exe 2010-12-11 00:39 . 2010-12-11 00:39 1036128 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\dbghelp.dll 2010-12-11 00:39 . 2010-12-11 00:39 1036128 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\dbghelp.dll 2010-12-11 00:39 . 2010-12-11 00:39 1036128 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\dbghelp.dll 2010-12-11 00:37 . 2010-12-11 00:37 124256 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\batchparser90.dll 2010-12-11 00:37 . 2010-12-11 00:37 65376 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\bcp.exe 2010-12-11 00:37 . 2010-12-11 00:37 124256 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\batchparser90.dll 2010-12-10 20:11 . 2010-12-10 20:11 524288 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\data\mssqlsystemresource1.ldf 2010-12-10 20:11 . 2010-12-10 20:11 40173568 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\data\mssqlsystemresource1.mdf 2010-12-10 17:55 . 2010-12-10 17:55 1221345 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\install\sqlagent90_msdb_upgrade.sql 2010-12-10 17:46 . 2010-12-10 17:46 141098 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\sqlwep-xp.mof 2010-12-10 17:44 . 2010-12-10 17:44 10863 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\sqlctr.h 2010-12-10 17:44 . 2010-12-10 17:44 49786 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\sqlctr.ini 2010-12-10 16:04 . 2010-12-10 16:04 647770 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\install\sysdbupg.sql 2010-12-10 16:04 . 2010-12-10 16:04 156306 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\install\sysdbupg_uninstall.sql 2010-12-10 16:04 . 2010-12-10 16:04 16346 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\license.txt 2010-12-10 16:04 . 2010-12-10 16:04 19883 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\requirementssqlexp2005.htm 2010-12-10 16:04 . 2010-12-10 16:04 16346 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\eula\license_expr_enu.txt 2010-12-02 06:15 . 2010-12-02 06:15 24691 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\resources\1033\sqlcm.xml 2010-10-10 16:08 . 2010-10-10 16:08 2664960 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\msxml6_x64.msi 2010-10-10 02:00 . 2010-10-10 02:00 1521152 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\msxml6.msi 2010-09-19 03:51 . 2010-09-19 03:51 32255 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\template.ini 2010-09-19 03:49 . 2010-09-19 03:49 921656 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\images\autorun_silver_bground.png 2010-09-19 03:49 . 2010-09-19 03:49 411320 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\images\splash.bmp 2010-09-19 03:43 . 2010-09-19 03:43 5565 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\install\failoveranalysis.sql 2010-09-19 03:35 . 2010-09-19 03:35 89854 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\readmesqlexp2005.htm 2010-09-19 03:35 . 2010-09-19 03:35 1682069 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\help\1033\setupsql9.chm 2010-09-19 03:35 . 2010-09-19 03:35 157200 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\en\microsoft.sqlserver.connectioninfo.xml 2010-09-19 03:35 . 2010-09-19 03:35 82996 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\en\microsoft.sqlserver.replication.xml 2010-09-19 03:35 . 2010-09-19 03:35 554428 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\en\microsoft.sqlserver.rmo.xml 2010-09-19 03:35 . 2010-09-19 03:35 3728264 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\en\microsoft.sqlserver.smo.xml 2010-09-19 03:35 . 2010-09-19 03:35 49709 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\en\microsoft.sqlserver.smoenum.xml 2010-09-19 03:35 . 2010-09-19 03:35 264382 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\en\microsoft.sqlserver.sqlenum.xml 2010-09-19 03:35 . 2010-09-19 03:35 498705 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft.net\adomd.net\90\en\microsoft.analysisservices.adomdclient.xml 2010-09-19 03:35 . 2010-09-19 03:35 15815 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\1033\finish.rtf 2010-09-19 03:35 . 2010-09-19 03:35 216618 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\resources\1033\cmptmgr9.chm 2008-08-11 18:49 . 2008-08-11 18:49 4567040 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\80\tools\binn\sqldmo.dll 2005-10-14 09:53 . 2005-10-14 09:53 57560 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\common files\microsoft shared\sql debugging\ssdebugps.dll 2005-10-14 09:50 . 2005-10-14 09:50 40664 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\semmap90.dll 2005-10-14 09:50 . 2005-10-14 09:50 50904 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\setupex.dll 2005-10-14 09:50 . 2005-10-14 09:50 29912 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\sqlscm90.dll 2005-10-14 09:50 . 2005-10-14 09:50 29912 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\sqlscm90.dll 2005-10-14 09:49 . 2005-10-14 09:49 19160 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\sqlresld90.dll 2005-10-14 09:49 . 2005-10-14 09:49 19160 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\sqlresld90.dll 2005-10-14 09:49 . 2005-10-14 09:49 19160 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\sqlresld90.dll 2005-10-14 09:49 . 2005-10-14 09:49 17624 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\sqlresourceloader.dll 2005-10-14 09:49 . 2005-10-14 09:49 17624 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\sqlresourceloader.dll 2005-10-14 09:48 . 2005-10-14 09:48 201944 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\sqlcu.rll 2005-10-14 09:47 . 2005-10-14 09:47 16600 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\resources\1033\semmap90.rll 2005-10-14 09:46 . 2005-10-14 09:46 9432 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\resources\1033\sqlsvc90.rll 2005-10-14 09:46 . 2005-10-14 09:46 9432 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\res\1033\sqlsvc90.rll 2005-10-14 09:46 . 2005-10-14 09:46 11992 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\resources\1033\sqladevn90.rll 2005-10-14 09:46 . 2005-10-14 09:46 11992 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\res\1033\xplog70.rll 2005-10-14 09:46 . 2005-10-14 09:46 49880 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\resources\1033\msxmlsql.rll 2005-10-14 09:46 . 2005-10-14 09:46 43736 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\microsoft.sqlserver.sqltdiagm.dll 2005-10-14 09:46 . 2005-10-14 09:46 355032 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\80\tools\binn\msvcr71.dll 2005-10-14 09:45 . 2005-10-14 09:45 84696 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\msclusterlib.dll 2005-10-14 09:45 . 2005-10-14 09:45 21208 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\opends60.dll 2005-10-14 09:45 . 2005-10-14 09:45 20184 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\gac\microsoft.sqlserver.sstring.dll 2005-10-14 09:45 . 2005-10-14 09:45 20184 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\microsoft.sqlserver.sstring.dll 2005-10-14 09:44 . 2005-10-14 09:44 18648 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\res\1033\odsole70.rll 2005-10-14 09:44 . 2005-10-14 09:44 16600 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\resources\1033\bcp.rll 2005-10-14 09:44 . 2005-10-14 09:44 15064 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\resources\1033\osql.rll 2005-10-14 09:44 . 2005-10-14 09:44 11992 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\resources\1033\sbevent.rll 2005-10-14 09:44 . 2005-10-14 09:44 12504 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\resources\1033\axscphst90.rll 2005-10-14 09:43 . 2005-10-14 09:43 133848 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\microsoft.exceptionmessagebox.dll 2005-10-14 09:43 . 2005-10-14 09:43 133848 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\microsoft.exceptionmessagebox.dll 2005-10-14 09:42 . 2005-10-14 09:42 47832 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\microsoft.sqlserver.replication.businesslogicsupport.dll 2005-10-14 09:42 . 2005-10-14 09:42 47832 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\microsoft.sqlserver.replication.businesslogicsupport.dll 2005-10-14 09:42 . 2005-10-14 09:42 16600 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\microsoft.sqlserver.instapi.dll 2005-10-14 09:37 . 2005-10-14 09:37 35032 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\instapi.dll 2005-10-14 09:37 . 2005-10-14 09:37 35032 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\instapi.dll 2005-10-14 09:31 . 2005-10-14 09:31 42712 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\axscphst90.dll 2005-10-14 09:31 . 2005-10-14 09:31 40664 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\custsat.dll 2005-10-14 08:06 . 2005-10-14 08:06 4194304 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\data\master.mdf 2005-10-14 08:06 . 2005-10-14 08:06 524288 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\data\mastlog.ldf 2005-10-14 08:06 . 2005-10-14 08:06 1245184 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\data\model.mdf 2005-10-14 08:06 . 2005-10-14 08:06 524288 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\data\modellog.ldf 2005-10-14 08:06 . 2005-10-14 08:06 4653056 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\data\msdbdata.mdf 2005-10-14 08:06 . 2005-10-14 08:06 524288 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\data\msdblog.ldf 2005-10-14 06:41 . 2005-10-14 06:41 22980 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\sqlmgmprovider.mof 2005-10-14 06:41 . 2005-10-14 06:41 23138 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\sqlmgmproviderxpsp2up.mof 2005-10-14 06:41 . 2005-10-14 06:41 19942 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\resources\1033\sqlmgmprovider.mfl 2005-10-14 06:33 . 2005-10-14 06:33 140306 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\binn\sqlwep-uni.mof 2005-10-14 06:26 . 2005-10-14 06:26 548864 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\msvcp80.dll 2005-10-14 06:26 . 2005-10-14 06:26 626688 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\msvcr80.dll 2005-10-14 06:25 . 2005-10-14 06:25 14719 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\install\repl_master.sql 2005-09-30 01:14 . 2005-09-30 01:14 585728 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\80\tools\binn\resources\1033\sqldmo.rll 2005-09-23 14:02 . 2005-09-23 14:02 7436 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\3kn09qps.lm8\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0.cat 2005-09-23 14:02 . 2005-09-23 14:02 7436 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\manifests\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0.cat 2005-09-23 14:02 . 2005-09-23 14:02 7447 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\3ggml9qs.lm8\8.0.50727.42.cat 2005-09-23 14:02 . 2005-09-23 14:02 7447 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\policies\2ggml9qs.lm8\8.0.50727.42.cat 2005-09-23 14:02 . 2005-09-23 14:02 7441 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\3kfkwlwq.lm8\8.0.50727.42.cat 2005-09-23 14:02 . 2005-09-23 14:02 7441 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\policies\2kfkwlwq.lm8\8.0.50727.42.cat 2005-09-23 14:02 . 2005-09-23 14:02 7441 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\77wtistq.lm8\8.0.50727.42.cat 2005-09-23 14:02 . 2005-09-23 14:02 7441 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\policies\67wtistq.lm8\8.0.50727.42.cat 2005-09-23 14:02 . 2005-09-23 14:02 7423 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\bql1q2cs.lm8\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2.cat 2005-09-23 14:02 . 2005-09-23 14:02 7423 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\manifests\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd.cat 2005-09-23 14:02 . 2005-09-23 14:02 7423 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\manifests\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2.cat 2005-09-23 14:02 . 2005-09-23 14:02 7423 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\r6hpravq.lm8\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd.cat 2005-09-23 14:02 . 2005-09-23 14:02 7423 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\jwfvlhtq.lm8\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841.cat 2005-09-23 14:02 . 2005-09-23 14:02 7423 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\manifests\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841.cat 2005-09-23 14:02 . 2005-09-23 14:02 7441 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\policies\y8ww3aes.lm8\8.0.50727.42.cat 2005-09-23 14:02 . 2005-09-23 14:02 7441 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\z8ww3aes.lm8\8.0.50727.42.cat 2005-09-23 14:01 . 2005-09-23 14:01 2370 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\bql1q2cs.lm8\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2.manifest 2005-09-23 14:01 . 2005-09-23 14:01 1868 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\manifests\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd.manifest 2005-09-23 14:01 . 2005-09-23 14:01 2370 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\manifests\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2.manifest 2005-09-23 14:01 . 2005-09-23 14:01 1868 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\r6hpravq.lm8\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd.manifest 2005-09-23 08:16 . 2005-09-23 08:16 718 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\3ggml9qs.lm8\8.0.50727.42.policy 2005-09-23 08:16 . 2005-09-23 08:16 1238 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\3kn09qps.lm8\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0.manifest 2005-09-23 08:16 . 2005-09-23 08:16 1238 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\manifests\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_3415f6d0.manifest 2005-09-23 08:16 . 2005-09-23 08:16 718 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\policies\2ggml9qs.lm8\8.0.50727.42.policy 2005-09-23 08:16 . 2005-09-23 08:16 712 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\policies\y8ww3aes.lm8\8.0.50727.42.policy 2005-09-23 08:16 . 2005-09-23 08:16 712 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\z8ww3aes.lm8\8.0.50727.42.policy 2005-09-23 08:16 . 2005-09-23 08:16 57344 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\system32\mfcm80u.dll 2005-09-23 08:16 . 2005-09-23 08:16 57344 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\9ql1q2cs.lm8\mfcm80u.dll 2005-09-23 08:16 . 2005-09-23 08:16 57344 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\bql1q2cs.lm8\mfcm80u.dll 2005-09-23 08:16 . 2005-09-23 08:16 69632 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\system32\mfcm80.dll 2005-09-23 08:16 . 2005-09-23 08:16 69632 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\9ql1q2cs.lm8\mfcm80.dll 2005-09-23 08:16 . 2005-09-23 08:16 69632 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\bql1q2cs.lm8\mfcm80.dll 2005-09-23 08:16 . 2005-09-23 08:16 1079808 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\system32\mfc80u.dll 2005-09-23 08:16 . 2005-09-23 08:16 1079808 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\9ql1q2cs.lm8\mfc80u.dll 2005-09-23 08:16 . 2005-09-23 08:16 1079808 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\bql1q2cs.lm8\mfc80u.dll 2005-09-23 08:16 . 2005-09-23 08:16 1093632 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\system32\mfc80.dll 2005-09-23 08:16 . 2005-09-23 08:16 1093632 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\9ql1q2cs.lm8\mfc80.dll 2005-09-23 08:16 . 2005-09-23 08:16 1093632 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\bql1q2cs.lm8\mfc80.dll 2005-09-23 07:58 . 2005-09-23 07:58 40960 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\system32\mfc80chs.dll 2005-09-23 07:58 . 2005-09-23 07:58 45056 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\system32\mfc80cht.dll 2005-09-23 07:58 . 2005-09-23 07:58 65536 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\system32\mfc80deu.dll 2005-09-23 07:58 . 2005-09-23 07:58 57344 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\system32\mfc80enu.dll 2005-09-23 07:58 . 2005-09-23 07:58 61440 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\system32\mfc80esp.dll 2005-09-23 07:58 . 2005-09-23 07:58 61440 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\system32\mfc80fra.dll 2005-09-23 07:58 . 2005-09-23 07:58 61440 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\system32\mfc80ita.dll 2005-09-23 07:58 . 2005-09-23 07:58 49152 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\system32\mfc80jpn.dll 2005-09-23 07:58 . 2005-09-23 07:58 49152 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\system32\mfc80kor.dll 2005-09-23 07:58 . 2005-09-23 07:58 40960 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\1kn09qps.lm8\mfc80chs.dll 2005-09-23 07:58 . 2005-09-23 07:58 45056 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\1kn09qps.lm8\mfc80cht.dll 2005-09-23 07:58 . 2005-09-23 07:58 65536 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\1kn09qps.lm8\mfc80deu.dll 2005-09-23 07:58 . 2005-09-23 07:58 57344 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\1kn09qps.lm8\mfc80enu.dll 2005-09-23 07:58 . 2005-09-23 07:58 61440 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\1kn09qps.lm8\mfc80esp.dll 2005-09-23 07:58 . 2005-09-23 07:58 61440 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\1kn09qps.lm8\mfc80fra.dll 2005-09-23 07:58 . 2005-09-23 07:58 61440 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\1kn09qps.lm8\mfc80ita.dll 2005-09-23 07:58 . 2005-09-23 07:58 49152 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\1kn09qps.lm8\mfc80jpn.dll 2005-09-23 07:58 . 2005-09-23 07:58 49152 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\1kn09qps.lm8\mfc80kor.dll 2005-09-23 07:58 . 2005-09-23 07:58 40960 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\3kn09qps.lm8\mfc80chs.dll 2005-09-23 07:58 . 2005-09-23 07:58 45056 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\3kn09qps.lm8\mfc80cht.dll 2005-09-23 07:58 . 2005-09-23 07:58 65536 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\3kn09qps.lm8\mfc80deu.dll 2005-09-23 07:58 . 2005-09-23 07:58 57344 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\3kn09qps.lm8\mfc80enu.dll 2005-09-23 07:58 . 2005-09-23 07:58 61440 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\3kn09qps.lm8\mfc80esp.dll 2005-09-23 07:58 . 2005-09-23 07:58 61440 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\3kn09qps.lm8\mfc80fra.dll 2005-09-23 07:58 . 2005-09-23 07:58 61440 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\3kn09qps.lm8\mfc80ita.dll 2005-09-23 07:58 . 2005-09-23 07:58 49152 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\3kn09qps.lm8\mfc80jpn.dll 2005-09-23 07:58 . 2005-09-23 07:58 49152 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\3kn09qps.lm8\mfc80kor.dll 2005-09-23 06:49 . 2005-09-23 06:49 95744 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\system32\atl80.dll 2005-09-23 06:49 . 2005-09-23 06:49 712 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\77wtistq.lm8\8.0.50727.42.policy 2005-09-23 06:49 . 2005-09-23 06:49 95744 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\hwfvlhtq.lm8\atl80.dll 2005-09-23 06:49 . 2005-09-23 06:49 95744 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\jwfvlhtq.lm8\atl80.dll 2005-09-23 06:49 . 2005-09-23 06:49 464 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\jwfvlhtq.lm8\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841.manifest 2005-09-23 06:49 . 2005-09-23 06:49 464 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\manifests\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_6e805841.manifest 2005-09-23 06:49 . 2005-09-23 06:49 712 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\policies\67wtistq.lm8\8.0.50727.42.policy 2005-09-23 06:48 . 2005-09-23 06:48 114688 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\system32\ansi\atl80.dll 2005-09-23 06:48 . 2005-09-23 06:48 712 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\3kfkwlwq.lm8\8.0.50727.42.policy 2005-09-23 06:48 . 2005-09-23 06:48 712 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\policies\2kfkwlwq.lm8\8.0.50727.42.policy 2005-09-23 06:48 . 2005-09-23 06:48 479232 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\system32\msvcm80.dll 2005-09-23 06:48 . 2005-09-23 06:48 548864 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\system32\msvcp80.dll 2005-09-23 06:48 . 2005-09-23 06:48 479232 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\p6hpravq.lm8\msvcm80.dll 2005-09-23 06:48 . 2005-09-23 06:48 548864 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\p6hpravq.lm8\msvcp80.dll 2005-09-23 06:48 . 2005-09-23 06:48 479232 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\r6hpravq.lm8\msvcm80.dll 2005-09-23 06:48 . 2005-09-23 06:48 548864 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\r6hpravq.lm8\msvcp80.dll 2005-09-23 06:48 . 2005-09-23 06:48 626688 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\system32\msvcr80.dll 2005-09-23 06:48 . 2005-09-23 06:48 626688 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\p6hpravq.lm8\msvcr80.dll 2005-09-23 06:48 . 2005-09-23 06:48 626688 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\windows\winsxs\r6hpravq.lm8\msvcr80.dll 2005-09-22 07:11 . 2005-09-22 07:11 31744 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\libertysql.msp 2005-09-22 07:11 . 2005-09-22 07:11 35840 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\msde2000.msp 2005-09-19 00:33 . 2005-09-19 00:33 522 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\microsoft.vc80.crt.manifest 2005-09-15 07:08 . 2005-09-15 07:08 1139896 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\install\instmsdb.sql 2005-08-11 07:11 . 2005-08-11 07:11 4236 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\splash.hta 2005-08-09 07:13 . 2005-08-09 07:13 13933 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\default.hta 2005-08-08 07:09 . 2005-08-08 07:09 9062 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\mdf_ndf_dbfiles.ico 2005-08-08 07:09 . 2005-08-08 07:09 9062 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\shared\transaction_logfile.ico 2005-08-08 07:09 . 2005-08-08 07:09 12543 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\schemas\sqlserver\2004\bulkload\format\bulkloadschema.xsd 2005-08-05 07:07 . 2005-08-05 07:07 5441 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\schemas\sqlserver\2004\07\queryprocessor\memorygrantschema.xsd 2005-08-05 07:07 . 2005-08-05 07:07 60399 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\schemas\sqlserver\2004\07\showplan\showplanxml.xsd 2005-08-04 07:16 . 2005-08-04 07:16 50418 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\schemas\sqlserver\2004\07\dta\dtaschema.xsd 2005-07-29 07:13 . 2005-07-29 07:13 13314 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\default.htm 2005-07-27 07:11 . 2005-07-27 07:11 55296 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\system\sqlservermanager.msc 2005-07-27 07:11 . 2005-07-27 07:11 2198 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\install\xpstar.sql 2005-07-27 07:10 . 2005-07-27 07:10 31258 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\en\microsoft.exceptionmessagebox.xml 2005-07-18 07:10 . 2005-07-18 07:10 20790 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\images\browse_cd.gif 2005-07-18 07:10 . 2005-07-18 07:10 18463 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\images\license_agreement.gif 2005-07-18 07:10 . 2005-07-18 07:10 19347 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\images\newsgroup.gif 2005-07-18 07:10 . 2005-07-18 07:10 18463 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\images\release_notes.gif 2005-07-18 07:10 . 2005-07-18 07:10 18647 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\images\server.gif 2005-07-18 07:10 . 2005-07-18 07:10 17888 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\images\setup.gif 2005-07-18 07:10 . 2005-07-18 07:10 19347 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\images\sql_website.gif 2005-07-13 07:12 . 2005-07-13 07:12 4351 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\en\microsoft.sqlserver.servicebrokerenum.xml 2005-07-11 07:11 . 2005-07-11 07:11 98 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\install\dbengine_hotfix_install.sql 2005-07-11 07:11 . 2005-07-11 07:11 102 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\install\dbengine_hotfix_uninstall.sql 2005-07-08 06:36 . 2005-07-08 06:36 12701 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\install\sqldmo.sql 2005-07-07 07:23 . 2005-07-07 07:23 2844 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\install\web.sql 2005-06-27 20:53 . 2005-06-27 20:53 2101214 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\80\tools\binn\sqldmo80.hlp 2005-06-27 20:53 . 2005-06-27 20:53 84938 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\80\tools\binn\sqldmo80.cnt 2005-06-20 07:10 . 2005-06-20 07:10 6709 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\install\procsyst.sql 2005-06-13 20:19 . 2005-06-13 20:19 54 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\autorun.inf 2005-06-13 20:19 . 2005-06-13 20:19 9062 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup.ico 2005-06-13 20:19 . 2005-06-13 20:19 1406 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\autorun.ico 2005-06-13 19:38 . 2005-06-13 19:38 36527 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\install\u_tables.sql 2005-06-13 19:38 . 2005-06-13 19:38 5924 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\install\oledbsch.sql 2005-06-13 19:35 . 2005-06-13 19:35 68 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\x86\install\odsole.sql 2005-06-13 19:15 . 2005-06-13 19:15 9553 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\schemas\sqlserver\2004\soap\options\sqlsoapoptions.xsd 2005-06-13 19:15 . 2005-06-13 19:15 2354 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\schemas\sqlserver\2004\soap\types\sqlsoaptypes.xsd 2005-06-13 19:15 . 2005-06-13 19:15 2735 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\schemas\sqlserver\2004\soap\types\sqlmessage\sqlmessage.xsd 2005-06-13 19:15 . 2005-06-13 19:15 4001 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\schemas\sqlserver\2004\soap\types\sqlparameter\sqlparameter.xsd 2005-06-13 19:15 . 2005-06-13 19:15 3103 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\schemas\sqlserver\2004\soap\types\sqlresultstream\sqlresultstream.xsd 2005-06-13 19:15 . 2005-06-13 19:15 1987 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\schemas\sqlserver\2004\soap\types\sqlrowcount\sqlrowcount.xsd 2005-06-13 19:15 . 2005-06-13 19:15 2430 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\schemas\sqlserver\2004\soap\types\sqltransaction\sqltransaction.xsd 2005-06-13 19:15 . 2005-06-13 19:15 9229 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\tools\binn\schemas\sqlserver\2004\sqltypes\sqltypes.xsd 2005-06-13 18:47 . 2005-06-13 18:47 6363 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\sdk\assemblies\en\microsoft.sqlserver.wmienum.xml 2005-06-13 18:46 . 2005-06-13 18:46 28080 —-a-w- c:\c774baca38044aeb2e6250e48a751daf\setup\program files\microsoft sql server\90\com\en\microsoft.sqlserver.replication.businesslogicsupport.xml . . ((((((((((((((((((((((((((((( SnapShot@2012-07-22_21.54.38 ))))))))))))))))))))))))))))))))))))))))) . + 2010-02-09 23:50 . 2012-07-24 22:48 65534 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2012-07-24 22:48 53842 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2010-02-09 21:52 . 2012-07-24 22:48 25704 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3216521362-3930712179-4014682732-1000_UserData.bin + 2009-07-14 05:30 . 2012-07-23 03:05 86016 c:\windows\system32\DriverStore\infpub.dat - 2009-07-14 05:30 . 2012-05-05 18:43 86016 c:\windows\system32\DriverStore\infpub.dat - 2010-02-09 19:23 . 2012-07-22 20:41 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2010-02-09 19:23 . 2012-07-24 22:23 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2012-07-22 20:41 . 2012-07-22 20:41 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2012-07-22 20:41 . 2012-07-24 22:23 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2012-07-22 20:41 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2012-07-24 22:23 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-02-08 23:56 . 2012-07-24 22:25 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2010-02-08 23:56 . 2012-07-22 21:01 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2010-02-08 23:56 . 2012-07-24 22:25 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2010-02-08 23:56 . 2012-07-22 21:01 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-02-25 02:20 . 2012-07-23 06:06 2290 c:\windows\system32\wdi\ERCQueuedResolutions.dat - 2012-07-22 21:53 . 2012-07-22 21:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-07-24 22:44 . 2012-07-24 22:44 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-07-24 22:44 . 2012-07-24 22:44 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2012-07-22 21:53 . 2012-07-22 21:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2009-07-14 05:30 . 2012-07-23 03:05 143360 c:\windows\system32\DriverStore\infstrng.dat - 2009-07-14 05:30 . 2012-05-05 18:43 143360 c:\windows\system32\DriverStore\infstrng.dat - 2009-07-14 05:01 . 2012-07-22 21:52 402792 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 05:01 . 2012-07-24 22:43 402792 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2011-07-23 06:22 . 2012-07-24 22:43 2013416 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3216521362-3930712179-4014682732-1000-12288.dat - 2011-07-23 06:22 . 2012-07-22 21:52 2013416 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3216521362-3930712179-4014682732-1000-12288.dat + 2010-12-11 09:06 . 2010-12-11 09:06 9260032 c:\windows\Installer\56fae.msi . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\steam.exe" [2011-08-02 1242448] "Facebook Update"="c:\users\Pete\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-11 138096] "DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2012-04-26 3111744] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296] "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376] "HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-04 135664] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-11 250056] R3 dump_wmimmc;dump_wmimmc;c:\program files (x86)\softnyxGame\GunBoundIS\GameGuard\dump_wmimmc.sys [x] R3 Gun;Gun;c:\windows\system32\Gun64.sys [2011-01-14 30840] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-04 135664] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-19 113120] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [x] R3 rtl819xp;Realtek RTL8190\RTL8192E 802.11n Wireless LAN (Mini-)PCI NIC NT Driver;c:\windows\system32\DRIVERS\rtl819xp.sys [2010-01-25 620576] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-03 1255736] S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x] S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys [2009-06-29 34880] S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [2009-06-30 14784] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 203264] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2009-11-13 67072] S3 O2MDGRDR;O2MDGRDR;c:\windows\system32\DRIVERS\o2mdgx64.sys [2009-03-11 69536] S3 rtl819xpn64;Realtek RTL8190/RTL8192E 802.11n Wireless LAN (Mini-)PCI NIC NT Driver;c:\windows\system32\DRIVERS\rtl819xp.sys [2010-01-25 620576] S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864] S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312] S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864] . . Contents of the 'Scheduled Tasks' folder . 2012-07-24 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 23:34] . 2012-07-15 c:\windows\Tasks\Driver Fetch.job - c:\program files (x86)\Driver Fetch\2.1.0.0\DriverFetch.exe [2010-02-23 20:08] . 2012-07-22 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3216521362-3930712179-4014682732-1000Core.job - c:\users\Pete\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-01 23:03] . 2012-07-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3216521362-3930712179-4014682732-1000UA.job - c:\users\Pete\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-01 23:03] . 2012-07-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-04 21:53] . 2012-07-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-04 21:53] . 2012-07-16 c:\windows\Tasks\Norton Security Scan for Pete.job - c:\progra~2\NORTON~2\Engine\361~1.11\Nss.exe [2011-12-29 09:45] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ThpSrv"="c:\windows\system32\thpsrv" [X] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2009-07-20 503864] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "NCInstallQueue"="netman.dll" [2009-07-14 360448] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\system32\blank.htm uSearchAssistant = TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Pete\AppData\Roaming\Mozilla\Firefox\Profiles\39ea4nyv.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q= FF - prefs.js: browser.search.selectedEngine - Web Search FF - prefs.js: browser.startup.homepage - www.google.com FF - prefs.js: keyword.URL - hxxp://feed.helperbar.com/?publisher=OPENCANDY&dpid=OPENCANDYAPRIL&co=US&userid=2ad75993-39a7-4b76-b14b-0899ab600fa5&affid=110774&searchtype=ds&babsrc=lnkry&q= FF - user.js: yahoo.homepage.dontask - true);user_pref(general.useragent.extra.brc, BRI/1 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file) . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-3216521362-3930712179-4014682732-1000\Software\SecuROM\License information*] "datasecu"=hex:87,ae,4b,bc,8d,62,d7,27,42,0c,c3,9b,f0,8a,78,4a,c9,c8,28,90,50, f5,0f,f3,b7,5f,c2,80,96,0e,9b,44,db,ac,df,1b,22,0b,33,c8,c8,ab,f3,7f,87,a9,\ "rkeysecu"=hex:5b,96,6e,02,e2,9d,c7,e6,a9,2f,9a,0f,80,ef,cd,60 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\windows\system32\DRIVERS\o2flash.exe c:\windows\SysWOW64\PnkBstrA.exe c:\program files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe . ************************************************************************** . Completion time: 2012-07-24 15:53:02 - machine was rebooted ComboFix-quarantined-files.txt 2012-07-24 22:53 ComboFix2.txt 2012-07-22 22:00 . Pre-Run: 248,903,712,768 bytes free Post-Run: 248,553,508,864 bytes free . - - End Of File - - A15ADD8C12EC6A2F4D3356D928CE7B13 ================================================== so far its running great! No more pop-ups or weird behavior, looks to be running very smoothly! Thanks!!
That’s looking good.

A couple more scans to be sure and then we can clean up.

Run Malwarebytes’ Anti-Malware

I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:
  • start Malwarebytes-Anti-Malware and update it, (“Update” tab}
  • once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
  • when the scan is complete, click OK, then Show Results to view the results.
  • be sure that everything is checked, and click Remove Selected.
  • when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

============================================

Run ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.

ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.

3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Note - when ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.

NOTE. If Eset doesn't find any threats, it won't produce a log.

Satchfan
It has been several days since I posted with a request for scans. Please let me know if you are having problems and still need help. Thanks Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI