This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cannot get rid of TR/ATRAPS.Gen2 [Closed]

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Computer got infected with "Security Shield 2012" fake antivirus software. With MBAM I have managed to get rid of the program itself, however, the trojan is still lurking in the background. Avira reports every minute or so that it has detected TR/ATRAPS.Gen2.

The downloaded files that trigger Avira appear in C:\Windows\assembly\temp\U\ and reapperas as soon as they are manually or automatically deleted.

These are the things I have done.

1. Told user to change all password she has ever typed in from that computer
2. Ran MBAM, in normal and safe mode, with or without chameleon
3. Ran SuperAntispyware
4. Ran a second antivirusprogram (Microsofts)
5. Ran Stinger, finds nothing
6. Ran rkill, did not find anything (but dropped a bunch of error about files being in use)
7. Ran TDSSKiller to kill malicious processes, finds nothing

I need some help from the Ninjas on this. Here is the HJT-log:
—

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 09:43:02, on 2012-07-24
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16446)
Boot mode: Normal

Running processes:
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
C:\Users\localuser\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files\ThinkPad\Bluetooth Software\Bluetooth Headset Helper.exe
C:\Users\localuser\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [IME14 CHT Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHT /Log
O4 - HKLM\..\Run: [IME14 JPN Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
O4 - HKLM\..\Run: [IME14 KOR Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /KOR /Log
O4 - HKLM\..\Run: [IME14 CHS Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHS /Log
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-18\..\Run: [Bomgar_Cleanup_ZD3364922511] cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-scc-00000000500D775F" & reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD3364922511 /f (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Bomgar_Cleanup_ZD3364922511] cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-scc-00000000500D775F" & reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD3364922511 /f (User 'Default user')
O4 - Startup: Dropbox.lnk = localuser\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Bomgar Jump Client [1343054732-1343061997] (bomgar-ps-1343054732-1343061997) - Bomgar - C:\ProgramData\bomgar-scc-00000000500D638B\bomgar-scc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: Intel® Identity Protection Technology Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cisco EnergyWise Enabler (PwmEWSvc) - Lenovo Group Limited - C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\Windows\system32\SAsrv.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\System Update\SUService.exe
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Mobile Broadband Service (WMCoreService) - Ericsson AB - C:\Program Files (x86)\Mobile Broadband drivers\WMCore\mini_WMCore.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 13290 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If asked whether you would like to update the Avast virus database please do.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

Please post the logs made by DDS and aswMBR. :)
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.4.1
Run by [removed] at 15:16:00 on 2012-07-24
Microsoft Windows 7 Professional 6.1.7601.1.1252.46.1033.18.4010.1769 [GMT 2:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
C:\ProgramData\bomgar-scc-00000000500D638B\bomgar-scc.exe
C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
C:\ProgramData\bomgar-scc-00000000500D638B\bomgar-scc.exe
C:\Windows\system32\CxAudMsg64.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE
C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Windows\SysWOW64\SAsrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Mobile Broadband drivers\WMCore\mini_WMCore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\rundll32.exe
C:\PROGRA~1\Lenovo\HOTKEY\MKRMSG.EXE
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
C:\Users\localuser\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\rundll32.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files\ThinkPad\Bluetooth Software\Bluetooth Headset Helper.exe
C:\Program Files\ThinkPad\Bluetooth Software\BtStackServer.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Lenovo\System Update\SUService.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
C:\ProgramData\bomgar-scc-00000000500D638B\bomgar-scc.exe
C:\ProgramData\bomgar-scc-00000000500D638B\bomgar-scc.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=LENP&bmod=LENP
uStart Page = about:blank
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
mRun: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
mRun: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [IME14 CHT Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHT /Log
mRun: [IME14 JPN Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
mRun: [IME14 KOR Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /KOR /Log
mRun: [IME14 CHS Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHS /Log
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
dRun: [Bomgar_Cleanup_ZD3364922511] cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-scc-00000000500D775F" & reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD3364922511 /f
StartupFolder: C:\Users\LOCALU~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\localuser\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\ThinkPad\Bluetooth Software\BTTray.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105
IE: Send image to &Bluetooth Device… - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
TCP: DhcpNameServer = 8.8.8.8 8.8.4.4
TCP: Interfaces\{11C61AE6-AB28-4FA0-AD35-674A50BF3AEF} : DhcpNameServer = 8.8.8.8 8.8.4.4
TCP: Interfaces\{11C61AE6-AB28-4FA0-AD35-674A50BF3AEF}\D4962796E64616 : DhcpNameServer = [removed] [removed]
TCP: Interfaces\{50DBCDFF-14CB-458B-ABA8-ECFD54AD103E} : DhcpNameServer = 8.8.8.8 8.8.4.4
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
mRun-x64: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
mRun-x64: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [IME14 CHT Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHT /Log
mRun-x64: [IME14 JPN Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
mRun-x64: [IME14 KOR Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /KOR /Log
mRun-x64: [IME14 CHS Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHS /Log
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
IE-X64: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\localuser\AppData\Roaming\Mozilla\Firefox\Profiles\55enxqpj.default\
FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\localuser\AppData\Roaming\Mozilla\plugins\npatgpc.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys –> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 avkmgr;avkmgr;C:\Windows\system32\DRIVERS\avkmgr.sys –> C:\Windows\system32\DRIVERS\avkmgr.sys [?]
R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\system32\DRIVERS\smiifx64.sys –> C:\Windows\system32\DRIVERS\smiifx64.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-4-4 63928]
R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2012-7-23 86224]
R2 AntiVirService;Avira Realtime Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2012-7-23 110032]
R2 avgntflt;avgntflt;C:\Windows\system32\DRIVERS\avgntflt.sys –> C:\Windows\system32\DRIVERS\avgntflt.sys [?]
R2 bomgar-ps-1343054732-1343061997;Bomgar Jump Client [1343054732-1343061997];C:\ProgramData\bomgar-scc-00000000500D638B\bomgar-scc.exe [2012-7-23 5371360]
R2 bomgar-scc-1343054732;Bomgar Support Customer Client [1343054732];C:\ProgramData\bomgar-scc-00000000500D638B\bomgar-scc.exe [2012-7-23 5371360]
R2 CxAudMsg;Conexant Audio Message Service;C:\Windows\system32\CxAudMsg64.exe –> C:\Windows\system32\CxAudMsg64.exe [?]
R2 ImeDictUpdateService;Microsoft IME Dictionary Update;C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE [2010-10-20 83312]
R2 jhi_service;Intel® Identity Protection Technology Host Interface Service;C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-2-24 212944]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;C:\Program Files\Lenovo\HOTKEY\micmute.exe [2011-12-13 101736]
R2 SAService;Conexant SmartAudio service;C:\Windows\System32\SASrv.exe [2012-3-27 446592]
R2 TPHKLOAD;Lenovo Hotkey Client Loader;C:\Program Files\Lenovo\HOTKEY\tphkload.exe [2011-12-13 145256]
R2 TPHKSVC;On Screen Display;C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe [2011-12-13 142696]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-3-27 2656280]
R2 WMCoreService;Mobile Broadband Service;C:\Program Files (x86)\Mobile Broadband drivers\WMCore\mini_WMCore.exe servicemode –> C:\Program Files (x86)\Mobile Broadband drivers\WMCore\mini_WMCore.exe servicemode [?]
R3 5U877;USB Video Device;C:\Windows\system32\DRIVERS\5U877.sys –> C:\Windows\system32\DRIVERS\5U877.sys [?]
R3 ecnssndis; Mobile Broadband Driver;C:\Windows\system32\Drivers\wwuss64.sys –> C:\Windows\system32\Drivers\wwuss64.sys [?]
R3 ecnssndisfltr; Mobile Broadband Driver Filter;C:\Windows\system32\Drivers\wwussf64.sys –> C:\Windows\system32\Drivers\wwussf64.sys [?]
R3 IntcDAud;Intel® Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys –> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 iwdbus;IWD Bus Enumerator;C:\Windows\system32\DRIVERS\iwdbus.sys –> C:\Windows\system32\DRIVERS\iwdbus.sys [?]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1C62x64.sys –> C:\Windows\system32\DRIVERS\L1C62x64.sys [?]
R3 l36wgps; Mobile Broadband GPS Port;C:\Windows\system32\DRIVERS\l36wgps64.sys –> C:\Windows\system32\DRIVERS\l36wgps64.sys [?]
R3 Mbm3CBus;F5521gw Mobile Broadband Device (WDM);C:\Windows\system32\DRIVERS\Mbm3CBus.sys –> C:\Windows\system32\DRIVERS\Mbm3CBus.sys [?]
R3 Mbm3DevMt; Mobile Broadband Device Management Driver (WDM);C:\Windows\system32\DRIVERS\Mbm3DevMt.sys –> C:\Windows\system32\DRIVERS\Mbm3DevMt.sys [?]
R3 Mbm3mdfl; Mobile Broadband Modem Port Filter;C:\Windows\system32\DRIVERS\Mbm3mdfl.sys –> C:\Windows\system32\DRIVERS\Mbm3mdfl.sys [?]
R3 Mbm3Mdm; Mobile Broadband Modem Port Driver;C:\Windows\system32\DRIVERS\Mbm3Mdm.sys –> C:\Windows\system32\DRIVERS\Mbm3Mdm.sys [?]
R3 MEIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys –> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETwNs64.sys –> C:\Windows\system32\DRIVERS\NETwNs64.sys [?]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
R3 TVTI2C;Lenovo SM bus driver;C:\Windows\system32\DRIVERS\Tvti2c.sys –> C:\Windows\system32\DRIVERS\Tvti2c.sys [?]
R3 WwanUsbServ;Mobile Broadband Driver;C:\Windows\system32\DRIVERS\WwanUsbMp64.sys –> C:\Windows\system32\DRIVERS\WwanUsbMp64.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys –> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-19 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-5-3 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-5-8 250056]
S3 BTWAMPFL;BTWAMPFL;C:\Windows\system32\DRIVERS\btwampfl.sys –> C:\Windows\system32\DRIVERS\btwampfl.sys [?]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys –> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys –> C:\Windows\system32\drivers\dmvsc.sys [?]
S3 intaud_WaveExtensible;Intel WiDi Audio Device;C:\Windows\system32\drivers\intelaud.sys –> C:\Windows\system32\drivers\intelaud.sys [?]
S3 mbamchameleon;mbamchameleon;\??\C:\Windows\system32\drivers\mbamchameleon.sys –> C:\Windows\system32\drivers\mbamchameleon.sys [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-8 129976]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-11-1 340240]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys –> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 Power Manager DBC Service;Power Manager DBC Service;C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe [2012-3-27 87400]
S3 PwmEWSvc;Cisco EnergyWise Enabler;C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.exe [2012-3-27 173416]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\system32\DRIVERS\RtsPStor.sys –> C:\Windows\system32\DRIVERS\RtsPStor.sys [?]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys –> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
2012-07-24 13:13:18 7680 —-a-w- C:\ProgramData\Z@!-338b26f6-55ae-4e5f-aac3-249b078d2052.tmp
2012-07-23 16:41:57 36168 —-a-w- C:\Windows\System32\drivers\mbamchameleon.sys
2012-07-23 16:27:35 16200 —-a-w- C:\Windows\stinger.sys
2012-07-23 16:27:23 ——– d—–w- C:\Program Files (x86)\stinger
2012-07-23 16:10:07 ——– d—–w- C:\ProgramData\bomgar-scc-00000000500D775F
2012-07-23 15:02:00 ——– d—–w- C:\Users\localuser\AppData\Roaming\Malwarebytes
2012-07-23 15:01:49 24904 —-a-w- C:\Windows\System32\drivers\mbam.sys
2012-07-23 15:01:49 ——– d—–w- C:\ProgramData\Malwarebytes
2012-07-23 15:01:49 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-23 14:45:31 ——– d—–w- C:\ProgramData\bomgar-scc-00000000500D638B
2012-07-23 12:35:48 328704 —-a-w- C:\Windows\System32\services.exe.61A0E60595D2A613
2012-07-23 12:32:48 328704 —-a-w- C:\Windows\System32\services.exe.EBF7920D05432F22
2012-07-23 12:30:11 328704 —-a-w- C:\Windows\System32\services.exe.FCD386B6264EF27F
2012-07-23 12:27:29 328704 —-a-w- C:\Windows\System32\services.exe.D7032D9A21253011
2012-07-23 12:24:37 328704 —-a-w- C:\Windows\System32\services.exe.1AC3F35A94E56C2F
2012-07-23 12:21:42 328704 —-a-w- C:\Windows\System32\services.exe.7A21BA99F9E3D32B
2012-07-23 12:19:03 328704 —-a-w- C:\Windows\System32\services.exe.6258B4F78CE415D0
2012-07-23 12:16:28 328704 —-a-w- C:\Windows\System32\services.exe.8DB816DA51868F45
2012-07-23 12:13:23 328704 —-a-w- C:\Windows\System32\services.exe.71A6DE147D9ED3B7
2012-07-23 12:08:02 328704 —-a-w- C:\Windows\System32\services.exe.DBF0200DF076256F
2012-07-23 12:03:22 328704 —-a-w- C:\Windows\System32\services.exe.71ACA87C9F2B809D
2012-07-23 11:59:17 328704 —-a-w- C:\Windows\System32\services.exe.F79FC5CEA2FEF976
2012-07-23 11:44:11 328704 —-a-w- C:\Windows\System32\services.exe.D2E28E5F31F3F80B
2012-07-23 11:38:33 328704 —-a-w- C:\Windows\System32\services.exe.AB44DD300D1FFBDC
2012-07-23 11:34:57 328704 —-a-w- C:\Windows\System32\services.exe.37970CA6ED35253E
2012-07-23 11:29:37 328704 —-a-w- C:\Windows\System32\services.exe.CF3C2F3505C08A10
2012-07-23 11:22:51 927800 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2012-07-23 11:22:51 927800 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{EC6B38F3-546C-447C-B40A-1234BA784B7A}\gapaengine.dll
2012-07-23 11:22:32 9133488 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{705173C0-0071-4FE6-B94F-F357E6D4157E}\mpengine.dll
2012-07-23 11:20:53 ——– d—–w- C:\Program Files (x86)\Microsoft Security Client
2012-07-23 11:20:50 ——– d—–w- C:\Program Files\Microsoft Security Client
2012-07-23 09:59:32 ——– d—–w- C:\Users\localuser\AppData\Roaming\Avira
2012-07-23 09:54:14 98848 —-a-w- C:\Windows\System32\drivers\avgntflt.sys
2012-07-23 09:54:14 27760 —-a-w- C:\Windows\System32\drivers\avkmgr.sys
2012-07-23 09:54:13 ——– d—–w- C:\ProgramData\Avira
2012-07-23 09:54:13 ——– d—–w- C:\Program Files (x86)\Avira
2012-07-23 07:40:05 ——– d-sh–w- C:\Windows\System32\%APPDATA%
2012-06-26 15:30:37 ——– d—–w- C:\Users\localuser\AppData\Local\Diagnostics
2012-06-25 15:33:05 ——– d—–w- C:\Users\localuser\AppData\Local\Apple Computer
.
==================== Find3M ====================
.
2012-07-23 09:05:05 70344 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-23 09:05:05 426184 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-06-02 22:15:31 2622464 —-a-w- C:\Windows\System32\wucltux.dll
2012-06-02 13:19:42 186752 —-a-w- C:\Windows\System32\wuwebv.dll
2012-06-02 13:15:12 36864 —-a-w- C:\Windows\System32\wuapp.exe
2012-05-18 02:06:48 2311680 —-a-w- C:\Windows\System32\jscript9.dll
2012-05-18 01:59:14 1392128 —-a-w- C:\Windows\System32\wininet.dll
2012-05-18 01:58:39 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl
2012-05-18 01:55:22 173056 —-a-w- C:\Windows\System32\ieUnatt.exe
2012-05-18 01:51:30 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2012-05-17 22:45:37 1800192 —-a-w- C:\Windows\SysWow64\jscript9.dll
2012-05-17 22:35:47 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll
2012-05-17 22:35:39 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-05-17 22:29:45 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-05-17 22:24:45 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2012-05-15 01:32:33 3146752 —-a-w- C:\Windows\System32\win32k.sys
2012-05-04 11:06:22 5559664 —-a-w- C:\Windows\System32\ntoskrnl.exe
2012-05-04 10:03:53 3968368 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03:50 3913072 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40:20 209920 —-a-w- C:\Windows\System32\profsvc.dll
2012-04-28 03:55:21 210944 —-a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-04-26 05:41:56 77312 —-a-w- C:\Windows\System32\rdpwsx.dll
2012-04-26 05:41:55 149504 —-a-w- C:\Windows\System32\rdpcorekmts.dll
2012-04-26 05:34:27 9216 —-a-w- C:\Windows\System32\rdrmemptylst.exe
.
============= FINISH: 15:16:41,29 ===============


.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 2012-05-02 11:29:06
System Uptime: 2012-07-24 09:40:44 (6 hours ago)
.
Motherboard: LENOVO | | 129882G
Processor: Intel® Core™ i3-2350M CPU @ 2.30GHz | CPU | 2300/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 281 GiB total, 229,555 GiB free.
Q: is FIXED (NTFS) - 16 GiB total, 2,304 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP55: 2012-06-28 08:31:19 - Windows Update
RP56: 2012-07-02 08:32:58 - Windows Update
RP57: 2012-07-05 09:23:46 - Windows Update
RP58: 2012-07-10 09:02:00 - Windows Update
RP59: 2012-07-12 09:23:14 - Windows Update
RP60: 2012-07-16 13:12:08 - Windows Update
RP61: 2012-07-23 08:22:02 - Windows Update
RP62: 2012-07-23 09:07:28 - Windows Update
RP63: 2012-07-23 11:59:49 - Removed System Update.
RP64: 2012-07-23 12:01:25 - Installed System Update.
.
==== Installed Programs ======================
.
ActiveX-kontroll för fjärranslutningar för Windows Live Mesh
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.3) - Svenska
Apple Application Support
Apple Software Update
Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
Avira Free Antivirus
BisonCam Twain Pro
Cisco WebEx Meetings
D3DX10
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Dropbox
Evernote v. 4.2.3
Integrated Camera Driver Installer Package Ver.1.1.0.1147
Intel PROSet Wireless
Intel® Control Center
Intel® Identity Protection Technology 1.1.2.0
Intel® Management Engine Components
Intel® Processor Graphics
Intel® WiDi
Java Auto Updater
Java™ 7 Update 4
JavaFX 2.1.0
Junk Mail filter update
Lenovo Patch Utility
Malwarebytes Anti-Malware version 1.62.0.1300
Mesh Runtime
Microsoft Office 2010 Language Pack Service Pack 1 (SP1)
Microsoft Office 2010 Proofing Tools Kit Service Pack 1 (SP1)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2010
Microsoft Office Home and Business 2010
Microsoft Office IME (Chinese (Simplified)) 2010
Microsoft Office IME (Chinese (Traditional)) 2010
Microsoft Office IME (Japanese) 2010
Microsoft Office IME (Korean) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office Language Pack 2010 - English
Microsoft Office O MUI (English) 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Proof (Arabic) 2010
Microsoft Office Proof (Basque) 2010
Microsoft Office Proof (Bulgarian) 2010
Microsoft Office Proof (Catalan) 2010
Microsoft Office Proof (Chinese (Simplified)) 2010
Microsoft Office Proof (Chinese (Traditional)) 2010
Microsoft Office Proof (Croatian) 2010
Microsoft Office Proof (Czech) 2010
Microsoft Office Proof (Danish) 2010
Microsoft Office Proof (Dutch) 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (Estonian) 2010
Microsoft Office Proof (Finnish) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Galician) 2010
Microsoft Office Proof (German) 2010
Microsoft Office Proof (Greek) 2010
Microsoft Office Proof (Gujarati) 2010
Microsoft Office Proof (Hebrew) 2010
Microsoft Office Proof (Hindi) 2010
Microsoft Office Proof (Hungarian) 2010
Microsoft Office Proof (Italian) 2010
Microsoft Office Proof (Japanese) 2010
Microsoft Office Proof (Kannada) 2010
Microsoft Office Proof (Kazakh) 2010
Microsoft Office Proof (Korean) 2010
Microsoft Office Proof (Latvian) 2010
Microsoft Office Proof (Lithuanian) 2010
Microsoft Office Proof (Marathi) 2010
Microsoft Office Proof (Norwegian (Bokmål)) 2010
Microsoft Office Proof (Norwegian (Nynorsk)) 2010
Microsoft Office Proof (Polish) 2010
Microsoft Office Proof (Portuguese (Brazil)) 2010
Microsoft Office Proof (Portuguese (Portugal)) 2010
Microsoft Office Proof (Punjabi) 2010
Microsoft Office Proof (Romanian) 2010
Microsoft Office Proof (Russian) 2010
Microsoft Office Proof (Serbian (Latin)) 2010
Microsoft Office Proof (Slovak) 2010
Microsoft Office Proof (Slovenian) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proof (Swedish) 2010
Microsoft Office Proof (Tamil) 2010
Microsoft Office Proof (Telugu) 2010
Microsoft Office Proof (Thai) 2010
Microsoft Office Proof (Turkish) 2010
Microsoft Office Proof (Ukrainian) 2010
Microsoft Office Proof (Urdu) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Proofing Kit 2010
Microsoft Office Proofing Tools Kit Compilation 2010
Microsoft Office ProofMUI (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office SharePoint Designer MUI (English) 2010
Microsoft Office Single Image 2010
Microsoft Office Word MUI (English) 2010
Microsoft Office X MUI (English) 2010
Microsoft SharePoint Designer 2010 Service Pack 1 (SP1)
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Mobile Broadband Drivers
Mozilla Firefox 12.0 (x86 sv-SE)
Mozilla Maintenance Service
MSVCRT
MSVCRT_amd64
QuickTime
Realtek PCIE Card Reader
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft Excel 2010 (KB2597166) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553091)
Security Update for Microsoft Office 2010 (KB2553096)
Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2596511) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2598039) 32-Bit Edition
Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition
Security Update for Microsoft SharePoint Workspace 2010 (KB2566445)
Security Update for Microsoft Visio Viewer 2010 (KB2597981) 32-Bit Edition
Skype™ 5.9
System Update
ThinkPad Power Manager
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553385) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596963) 32-Bit Edition
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2597091) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2589345) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Windows Live Communications Platform
Windows Live Essentials
Windows Live Fotogalleri
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Liven asennustyökalu
Windows Liven sähköposti
Windows Liven valokuvavalikoima
.
==== Event Viewer Messages From Past Week ========
.
2012-07-24 09:41:25, Error: Service Control Manager [7026] -
2012-07-23 17:54:55, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
2012-07-23 17:54:55, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
2012-07-23 17:54:51, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\IWMSSvc.dll Error Code: 21
2012-07-23 17:54:51, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
2012-07-23 17:54:41, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
2012-07-23 13:22:59, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.131.461.0 Update Source: Microsoft Malware Protection Center Update Stage: Install Source Path: http://go.microsoft.com/fwlink/?LinkID=187…5D-99752CCA7094 Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 1.1.8601.0 Error code: 0x80070714 Error description: The specified image file did not contain a resource section.
2012-07-23 13:22:59, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.131.461.0 Update Source: Microsoft Malware Protection Center Update Stage: Install Source Path: http://go.microsoft.com/fwlink/?LinkID=187…5D-99752CCA7094 Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 1.1.8601.0 Error code: 0x80070714 Error description: The specified image file did not contain a resource section.
2012-07-23 13:22:59, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.131.461.0 Update Source: Microsoft Malware Protection Center Update Stage: Install Source Path: http://go.microsoft.com/fwlink/?LinkID=187…5D-99752CCA7094 Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 1.1.8601.0 Error code: 0x80070714 Error description: The specified image file did not contain a resource section.
2012-07-23 13:22:59, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.131.461.0 Update Source: Microsoft Malware Protection Center Update Stage: Install Source Path: http://go.microsoft.com/fwlink/?LinkID=187…5D-99752CCA7094 Signature Type: AntiSpyware Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 1.1.8601.0 Error code: 0x80070714 Error description: The specified image file did not contain a resource section.
2012-07-23 13:22:59, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.131.461.0 Update Source: Microsoft Malware Protection Center Update Stage: Install Source Path: http://go.microsoft.com/fwlink/?LinkID=187…5D-99752CCA7094 Signature Type: AntiSpyware Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 1.1.8601.0 Error code: 0x80070714 Error description: The specified image file did not contain a resource section.
2012-07-23 13:22:36, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Install Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094 Signature Type: AntiVirus Update Type: Full User: SESTOL139\localuser Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80070652 Error description: Another installation is already in progress. Complete that installation before proceeding with this install.
2012-07-23 13:22:36, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Install Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094 Signature Type: AntiVirus Update Type: Full User: SESTOL139\localuser Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80070652 Error description: Another installation is already in progress. Complete that installation before proceeding with this install.
2012-07-23 13:22:36, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Install Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094 Signature Type: AntiSpyware Update Type: Full User: SESTOL139\localuser Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80070652 Error description: Another installation is already in progress. Complete that installation before proceeding with this install.
2012-07-23 13:22:36, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Malware Protection Center Update Stage: Install Source Path: http://go.microsoft.com/fwlink/?LinkID=121…5D-99752CCA7094 Signature Type: AntiSpyware Update Type: Full User: SESTOL139\localuser Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80070652 Error description: Another installation is already in progress. Complete that installation before proceeding with this install.
2012-07-23 13:22:33, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: Update Source: User Update Stage: Install Source Path: Signature Type: Update Type: User: SESTOL139\localuser Current Engine Version: Previous Engine Version: Error code: 0x80070652 Error description: Another installation is already in progress. Complete that installation before proceeding with this install.
2012-07-23 13:22:00, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80070424 Error description: The specified service does not exist as an installed service.
2012-07-23 13:21:18, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 0.0.0.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80070424 Error description: The specified service does not exist as an installed service.
2012-07-23 09:04:48, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Security Update for Windows 7 for x64-based Systems (KB2719985).
2012-07-23 09:04:48, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Security Update for Windows 7 for x64-based Systems (KB2718523).
2012-07-23 09:04:48, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Security Update for Windows 7 for x64-based Systems (KB2691442).
2012-07-23 09:04:48, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Security Update for Windows 7 for x64-based Systems (KB2655992).
2012-07-23 09:04:48, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Microsoft Browser Choice Screen Update for EEA Users of Windows 7 for x64-based Systems (KB976002).
2012-07-23 09:04:48, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Cumulative Security Update for Internet Explorer 9 for Windows 7 for x64-based Systems (KB2719177).
2012-07-23 09:00:50, Error: Microsoft Antimalware [2004] - Microsoft Antimalware has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures. Signatures Attempted: Current Error Code: 0x80070002 Error description: The system cannot find the file specified. Signature version: 1.129.991.0;1.129.991.0 Engine version: 1.1.8502.0
.
==== End Of File ===========================



aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-07-24 15:17:33
—————————–
15:17:33.687 OS Version: Windows x64 6.1.7601 Service Pack 1
15:17:33.687 Number of processors: 4 586 0x2A07
15:17:33.697 ComputerName: SESTOL139 UserName: localuser
15:17:35.807 Initialize success
15:20:57.521 AVAST engine defs: 12072400
15:21:59.554 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
15:21:59.554 Disk 0 Vendor: ST320LT0 0004 Size: 305245MB BusType: 3
15:21:59.574 Disk 0 MBR read successfully
15:21:59.574 Disk 0 MBR scan
15:21:59.584 Disk 0 unknown MBR code
15:21:59.594 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 1500 MB offset 2048
15:21:59.604 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 287743 MB offset 3074048
15:21:59.634 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 16000 MB offset 592371712
15:21:59.674 Disk 0 scanning C:\Windows\system32\drivers
15:22:09.124 Service scanning
15:22:27.612 Modules scanning
15:22:27.612 Disk 0 trace - called modules:
15:22:27.762 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
15:22:27.762 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007022060]
15:22:27.762 3 CLASSPNP.SYS[fffff88001dc643f] -> nt!IofCallDriver -> [0xfffffa8003cf4040]
15:22:27.772 5 ACPI.sys[fffff88000fa57a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0xfffffa8004b73050]
15:22:28.832 AVAST engine scan C:\Windows
15:22:31.982 AVAST engine scan C:\Windows\system32
15:26:38.677 AVAST engine scan C:\Windows\system32\drivers
15:26:49.387 AVAST engine scan C:\Users\localuser
15:34:09.528 AVAST engine scan C:\ProgramData
15:35:14.110 Scan finished successfully
15:35:26.962 Disk 0 MBR has been saved successfully to "C:\Users\localuser\Desktop\MBR.dat"
15:35:26.962 The log file has been saved successfully to "C:\Users\localuser\Desktop\aswMBR.txt"
Hi,

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
ComboFix 12-07-25.04 - localuser 2012-07-24 15:48:50.1.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.46.1033.18.4010.1610 [GMT 2:00] Körs från: c:\users\localuser\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6} SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Andra raderingar )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\Roaming c:\programdata\Z@!-45d0e4e8-e08f-4f62-90ac-f1f3b47d9c6d.tmp c:\windows\Installer\{d8014164-3546-6ede-ae8d-4a8662a67314}\@ c:\windows\Installer\{d8014164-3546-6ede-ae8d-4a8662a67314}\U\00000001.@ c:\windows\Installer\{d8014164-3546-6ede-ae8d-4a8662a67314}\U\80000000.@ c:\windows\Installer\{d8014164-3546-6ede-ae8d-4a8662a67314}\U\800000cb.@ Q:\Autorun.inf . . (((((((((((((((((((((((( Filer skapade från 2012-06-24 till 2012-07-24 )))))))))))))))))))))))))))))) . . 2012-07-24 13:52 . 2012-07-24 13:52 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-07-23 16:41 . 2012-07-23 16:41 36168 —-a-w- c:\windows\system32\drivers\mbamchameleon.sys 2012-07-23 16:27 . 2012-07-23 16:27 16200 —-a-w- c:\windows\stinger.sys 2012-07-23 16:27 . 2012-07-23 16:32 ——– d—–w- c:\program files (x86)\stinger 2012-07-23 16:10 . 2012-07-24 07:36 ——– d—–w- c:\programdata\bomgar-scc-00000000500D775F 2012-07-23 15:02 . 2012-07-23 15:02 ——– d—–w- c:\users\localuser\AppData\Roaming\Malwarebytes 2012-07-23 15:01 . 2012-07-23 15:01 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-07-23 15:01 . 2012-07-23 15:01 ——– d—–w- c:\programdata\Malwarebytes 2012-07-23 15:01 . 2012-07-03 11:46 24904 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-07-23 14:45 . 2012-07-24 13:55 ——– d—–w- c:\programdata\bomgar-scc-00000000500D638B 2012-07-23 12:35 . 2012-07-23 12:35 328704 —-a-w- c:\windows\system32\services.exe.61A0E60595D2A613 2012-07-23 12:32 . 2012-07-23 12:32 328704 —-a-w- c:\windows\system32\services.exe.EBF7920D05432F22 2012-07-23 12:30 . 2012-07-23 12:30 328704 —-a-w- c:\windows\system32\services.exe.FCD386B6264EF27F 2012-07-23 12:27 . 2012-07-23 12:27 328704 —-a-w- c:\windows\system32\services.exe.D7032D9A21253011 2012-07-23 12:24 . 2012-07-23 12:24 328704 —-a-w- c:\windows\system32\services.exe.1AC3F35A94E56C2F 2012-07-23 12:21 . 2012-07-23 12:21 328704 —-a-w- c:\windows\system32\services.exe.7A21BA99F9E3D32B 2012-07-23 12:19 . 2012-07-23 12:19 328704 —-a-w- c:\windows\system32\services.exe.6258B4F78CE415D0 2012-07-23 12:16 . 2012-07-23 12:16 328704 —-a-w- c:\windows\system32\services.exe.8DB816DA51868F45 2012-07-23 12:13 . 2012-07-23 12:13 328704 —-a-w- c:\windows\system32\services.exe.71A6DE147D9ED3B7 2012-07-23 12:08 . 2012-07-23 12:08 328704 —-a-w- c:\windows\system32\services.exe.DBF0200DF076256F 2012-07-23 12:03 . 2012-07-23 12:03 328704 —-a-w- c:\windows\system32\services.exe.71ACA87C9F2B809D 2012-07-23 11:59 . 2012-07-23 11:59 328704 —-a-w- c:\windows\system32\services.exe.F79FC5CEA2FEF976 2012-07-23 11:44 . 2012-07-23 11:44 328704 —-a-w- c:\windows\system32\services.exe.D2E28E5F31F3F80B 2012-07-23 11:38 . 2012-07-23 11:38 328704 —-a-w- c:\windows\system32\services.exe.AB44DD300D1FFBDC 2012-07-23 11:34 . 2012-07-23 11:34 328704 —-a-w- c:\windows\system32\services.exe.37970CA6ED35253E 2012-07-23 11:29 . 2012-07-23 11:29 328704 —-a-w- c:\windows\system32\services.exe.CF3C2F3505C08A10 2012-07-23 11:22 . 2012-02-09 12:17 927800 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2012-07-23 11:22 . 2012-02-09 12:17 927800 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EC6B38F3-546C-447C-B40A-1234BA784B7A}\gapaengine.dll 2012-07-23 11:22 . 2012-07-16 00:40 9133488 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{705173C0-0071-4FE6-B94F-F357E6D4157E}\mpengine.dll 2012-07-23 11:20 . 2012-07-23 12:35 ——– d—–w- c:\program files (x86)\Microsoft Security Client 2012-07-23 11:20 . 2012-07-23 12:35 ——– d—–w- c:\program files\Microsoft Security Client 2012-07-23 09:59 . 2012-07-23 09:59 ——– d—–w- c:\users\localuser\AppData\Roaming\Avira 2012-07-23 09:54 . 2012-05-02 13:24 27760 —-a-w- c:\windows\system32\drivers\avkmgr.sys 2012-07-23 09:54 . 2012-04-27 08:20 132832 —-a-w- c:\windows\system32\drivers\avipbb.sys 2012-07-23 09:54 . 2012-04-24 22:32 98848 —-a-w- c:\windows\system32\drivers\avgntflt.sys 2012-07-23 09:54 . 2012-07-23 09:54 ——– d—–w- c:\programdata\Avira 2012-07-23 09:54 . 2012-07-23 09:54 ——– d—–w- c:\program files (x86)\Avira 2012-07-23 07:40 . 2012-07-23 07:40 ——– d-sh–w- c:\windows\system32\%APPDATA% 2012-06-26 15:30 . 2012-06-26 15:30 ——– d—–w- c:\users\localuser\AppData\Local\Diagnostics 2012-06-25 15:33 . 2012-06-25 15:33 ——– d—–w- c:\users\localuser\AppData\Local\Apple Computer . . . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-23 09:05 . 2012-05-08 12:15 70344 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-07-23 09:05 . 2012-05-08 12:15 426184 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-06-15 06:18 . 2012-05-02 12:02 58957832 —-a-w- c:\windows\system32\MRT.exe 2012-06-02 22:19 . 2012-06-21 06:29 2428952 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-02 22:19 . 2012-06-21 06:29 57880 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2012-06-21 06:29 44056 —-a-w- c:\windows\system32\wups2.dll 2012-06-02 22:15 . 2012-06-21 06:29 2622464 —-a-w- c:\windows\system32\wucltux.dll 2012-06-02 13:19 . 2012-06-21 06:29 186752 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-02 13:15 . 2012-06-21 06:29 36864 —-a-w- c:\windows\system32\wuapp.exe 2012-05-18 02:47 . 2012-06-15 06:12 17807360 —-a-w- c:\windows\system32\mshtml.dll 2012-05-18 02:16 . 2012-06-15 06:12 10924032 —-a-w- c:\windows\system32\ieframe.dll 2012-05-18 02:06 . 2012-06-15 06:12 2311680 —-a-w- c:\windows\system32\jscript9.dll 2012-05-18 01:59 . 2012-06-15 06:12 1346048 —-a-w- c:\windows\system32\urlmon.dll 2012-05-18 01:59 . 2012-06-15 06:12 1392128 —-a-w- c:\windows\system32\wininet.dll 2012-05-18 01:58 . 2012-06-15 06:12 1494528 —-a-w- c:\windows\system32\inetcpl.cpl 2012-05-18 01:58 . 2012-06-15 06:12 237056 —-a-w- c:\windows\system32\url.dll 2012-05-18 01:56 . 2012-06-15 06:12 85504 —-a-w- c:\windows\system32\jsproxy.dll 2012-05-18 01:55 . 2012-06-15 06:12 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2012-05-18 01:55 . 2012-06-15 06:12 818688 —-a-w- c:\windows\system32\jscript.dll 2012-05-18 01:54 . 2012-06-15 06:12 2144768 —-a-w- c:\windows\system32\iertutil.dll 2012-05-18 01:51 . 2012-06-15 06:12 96768 —-a-w- c:\windows\system32\mshtmled.dll 2012-05-18 01:51 . 2012-06-15 06:12 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-05-18 01:47 . 2012-06-15 06:12 248320 —-a-w- c:\windows\system32\ieui.dll 2012-05-17 22:45 . 2012-06-15 06:12 1800192 —-a-w- c:\windows\SysWow64\jscript9.dll 2012-05-17 22:35 . 2012-06-15 06:12 1129472 —-a-w- c:\windows\SysWow64\wininet.dll 2012-05-17 22:35 . 2012-06-15 06:12 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2012-05-17 22:29 . 2012-06-15 06:12 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2012-05-17 22:24 . 2012-06-15 06:12 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2012-05-15 01:32 . 2012-06-14 06:15 3146752 —-a-w- c:\windows\system32\win32k.sys 2012-05-04 11:06 . 2012-06-14 06:15 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-05-04 10:03 . 2012-06-14 06:15 3968368 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-05-04 10:03 . 2012-06-14 06:15 3913072 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-05-02 09:29 . 2010-06-24 18:33 19352 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2012-05-01 05:40 . 2012-06-14 06:15 209920 —-a-w- c:\windows\system32\profsvc.dll 2012-04-28 03:55 . 2012-06-14 06:15 210944 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-26 05:41 . 2012-06-14 06:15 77312 —-a-w- c:\windows\system32\rdpwsx.dll 2012-04-26 05:41 . 2012-06-14 06:15 149504 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-04-26 05:34 . 2012-06-14 06:15 9216 —-a-w- c:\windows\system32\rdrmemptylst.exe . . ——- Sigcheck ——- Note: Unsigned files aren't necessarily malware. . [-] 2009-07-14 01:39 . !HASH: COULD NOT OPEN FILE !!!!! . 328704 . . [——] .. c:\windows\system32\services.exe . (((((((((((((((((((((((((((((((((( Startpunkter i registret ))))))))))))))))))))))))))))))))))))))))))))))) . . *Not* tomma poster & legitima standardposter visas inte. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-15 00:32 94208 —-a-w- c:\users\localuser\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-15 00:32 94208 —-a-w- c:\users\localuser\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-15 00:32 94208 —-a-w- c:\users\localuser\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-05-03 17355912] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "RotateImage"="c:\program files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe" [2008-10-30 55808] "PWMTRV"="c:\progra~2\ThinkPad\UTILIT~1\PWMTR64V.DLL" [2011-08-31 1629544] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712] "IME14 CHT Setup"="c:\progra~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE" [2010-01-20 80240] "IME14 JPN Setup"="c:\progra~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE" [2010-01-20 80240] "IME14 KOR Setup"="c:\progra~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE" [2010-01-20 80240] "IME14 CHS Setup"="c:\progra~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE" [2010-01-20 80240] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-18 421888] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-05-01 348624] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Bomgar_Cleanup_ZD3364922511"="rd" [X] . c:\users\localuser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\localuser\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2011-3-25 1219360] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200804] IME File REG_SZ IMSC14.IME . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0210804] IME File REG_SZ IMSCE14.IME . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200412] Ime File REG_SZ IMKR14.IME . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200411] Ime File REG_SZ imjp14.ime . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e00c0404] IME File REG_SZ IMTCP14.IME . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e00d0404] IME File REG_SZ IMTCC14.IME . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-05-03 158856] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-23 250056] R3 BTWAMPFL;BTWAMPFL;c:\windows\system32\DRIVERS\btwampfl.sys [2011-03-16 436776] R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2011-02-22 39976] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168] R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [2011-06-21 34200] R3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [2012-07-23 36168] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-21 129976] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-11-01 340240] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-20 98688] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2011-08-31 87400] R3 PwmEWSvc;Cisco EnergyWise Enabler;c:\program files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE [2011-08-31 173416] R3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [2010-12-08 329832] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-05-02 1255736] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2012-05-02 27760] S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiifx64.sys [2010-09-07 15472] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928] S2 AntiVirSchedulerService;Avira Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2012-05-01 86224] S2 bomgar-ps-1343054732-1343061997;Bomgar Jump Client [1343054732-1343061997];c:\programdata\bomgar-scc-00000000500D638B\bomgar-scc.exe [2012-05-20 07:36 5371360] S2 CxAudMsg;Conexant Audio Message Service;c:\windows\system32\CxAudMsg64.exe [2010-12-16 198784] S2 ImeDictUpdateService;Microsoft IME Dictionary Update;c:\program files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE [2010-10-20 83312] S2 jhi_service;Intel® Identity Protection Technology Host Interface Service;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe [2011-02-24 212944] S2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2011-07-12 101736] S2 SAService;Conexant SmartAudio service;c:\windows\system32\SAsrv.exe [x] S2 TPHKLOAD;Lenovo Hotkey Client Loader;c:\program files\LENOVO\HOTKEY\TPHKLOAD.exe [2011-07-12 145256] S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2011-07-12 142696] S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-02-22 2656280] S2 WMCoreService;Mobile Broadband Service;c:\program files (x86)\Mobile Broadband drivers\WMCore\mini_WMCore.exe servicemode [x] S3 5U877;USB Video Device;c:\windows\system32\DRIVERS\5U877.sys [2011-03-05 166016] S3 ecnssndis; Mobile Broadband Driver;c:\windows\system32\Drivers\wwuss64.sys [2010-02-24 26664] S3 ecnssndisfltr; Mobile Broadband Driver Filter;c:\windows\system32\Drivers\wwussf64.sys [2010-02-24 30248] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2011-08-23 317440] S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [2011-06-21 25496] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2011-03-23 77936] S3 l36wgps; Mobile Broadband GPS Port;c:\windows\system32\DRIVERS\l36wgps64.sys [2011-02-28 101416] S3 Mbm3CBus;F5521gw Mobile Broadband Device (WDM);c:\windows\system32\DRIVERS\Mbm3CBus.sys [2011-04-13 419400] S3 Mbm3DevMt; Mobile Broadband Device Management Driver (WDM);c:\windows\system32\DRIVERS\Mbm3DevMt.sys [2011-04-13 430664] S3 Mbm3mdfl; Mobile Broadband Modem Port Filter;c:\windows\system32\DRIVERS\Mbm3mdfl.sys [2011-04-13 19528] S3 Mbm3Mdm; Mobile Broadband Modem Port Driver;c:\windows\system32\DRIVERS\Mbm3Mdm.sys [2011-04-13 483400] S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344] S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2011-10-31 8615936] S3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\DRIVERS\Tvti2c.sys [2009-09-24 41536] S3 WwanUsbServ;Mobile Broadband Driver;c:\windows\system32\DRIVERS\WwanUsbMp64.sys [2011-04-06 286248] . . — Övriga tjänster/drivrutiner i minnet — . *NewlyCreated* - WS2IFSL . Innehåll i mappen 'Schemalagda aktiviteter': . 2012-07-24 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-08 09:05] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-15 00:32 97792 —-a-w- c:\users\localuser\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-15 00:32 97792 —-a-w- c:\users\localuser\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-15 00:32 97792 —-a-w- c:\users\localuser\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-15 00:32 97792 —-a-w- c:\users\localuser\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2011-04-26 310912] "ForteConfig"="c:\program files\Conexant\ForteConfig\fmapp.exe" [2010-10-26 49056] "IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-11-01 1935120] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-01-23 167704] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-01-23 392984] "Persistence"="c:\windows\system32\igfxpers.exe" [2012-01-23 417560] "IME14 CHT Setup"="c:\progra~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE" [2010-01-20 109424] "IME14 JPN Setup"="c:\progra~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE" [2010-01-20 109424] "IME14 KOR Setup"="c:\progra~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE" [2010-01-20 109424] "IME14 CHS Setup"="c:\progra~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE" [2010-01-20 109424] "Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2010-11-03 1580368] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Extra genomsökning ——- . uStart Page = about:blank uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105 IE: Send image to &Bluetooth Device… - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm TCP: DhcpNameServer = 8.8.8.8 8.8.4.4 FF - ProfilePath - c:\users\localuser\AppData\Roaming\Mozilla\Firefox\Profiles\55enxqpj.default\ . - - - - FÖRÄLDRALÖSA POSTER SOM TAGITS BORT - - - - . Toolbar-Locked - (no file) Toolbar-Locked - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe HKLM-Run-AcWin7Hlpr - c:\program files (x86)\Lenovo\Access Connections\AcTBenabler.exe . . . ——————— LÅSTA REGISTERNYCKLAR ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_265_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_265.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Andra processer som körs ———————— . c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\windows\SysWOW64\SAsrv.exe c:\program files (x86)\Mobile Broadband drivers\WMCore\mini_WMCore.exe c:\progra~1\Lenovo\HOTKEY\TPONSCR.EXE c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe c:\program files (x86)\Lenovo\System Update\SUService.exe . ************************************************************************** . Sluttid: 2012-07-24 15:59:02 - datorn startades om. ComboFix-quarantined-files.txt 2012-07-24 13:59 . Före genomsökningen: 246 229 860 352 bytes free Efter genomsökningen: 246 714 122 240 bytes free . - - End Of File - - CF016EDE569F5062835E189CD0E59312
Hi,

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • When the window opens, click on Change Parameters
  • Under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”
  • click OK
  • Press Start Scan
  • Do Not Attempt To Fix Anything Now. We just need to look over the report and be sure we are removing the correct
    items.
  • Attach the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-
17:16:45.0126 10364 TDSS rootkit removing tool [removed] Jul 24 2012 13:16:32 17:16:45.0266 10364 ============================================================ 17:16:45.0266 10364 Current date / time: 2012/07/25 17:16:45.0266 17:16:45.0266 10364 SystemInfo: 17:16:45.0266 10364 17:16:45.0266 10364 OS Version: 6.1.7601 ServicePack: 1.0 17:16:45.0266 10364 Product type: Workstation 17:16:45.0266 10364 ComputerName: SESTOL139 17:16:45.0266 10364 UserName: localuser 17:16:45.0266 10364 Windows directory: C:\Windows 17:16:45.0266 10364 System windows directory: C:\Windows 17:16:45.0266 10364 Running under WOW64 17:16:45.0266 10364 Processor architecture: Intel x64 17:16:45.0266 10364 Number of processors: 4 17:16:45.0266 10364 Page size: 0x1000 17:16:45.0266 10364 Boot type: Normal boot 17:16:45.0266 10364 ============================================================ 17:16:45.0836 10364 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 17:16:45.0846 10364 ============================================================ 17:16:45.0846 10364 \Device\Harddisk0\DR0: 17:16:45.0846 10364 MBR partitions: 17:16:45.0846 10364 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x2EE000 17:16:45.0846 10364 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x231FF800 17:16:45.0846 10364 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x234EE000, BlocksNum 0x1F40000 17:16:45.0846 10364 ============================================================ 17:16:45.0866 10364 C: <-> \Device\Harddisk0\DR0\Partition1 17:16:45.0906 10364 Q: <-> \Device\Harddisk0\DR0\Partition2 17:16:45.0906 10364 ============================================================ 17:16:45.0906 10364 Initialize success 17:16:45.0906 10364 ============================================================ 17:16:52.0145 11056 ============================================================ 17:16:52.0145 11056 Scan started 17:16:52.0145 11056 Mode: Manual; 17:16:52.0145 11056 ============================================================ 17:16:52.0665 11056 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys 17:16:52.0665 11056 1394ohci - ok 17:16:52.0695 11056 5U877 (f4af97702bad85bfef64b9a557f11b6f) C:\Windows\system32\DRIVERS\5U877.sys 17:16:52.0705 11056 5U877 - ok 17:16:52.0725 11056 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys 17:16:52.0745 11056 ACPI - ok 17:16:52.0765 11056 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys 17:16:52.0765 11056 AcpiPmi - ok 17:16:52.0855 11056 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 17:16:52.0855 11056 AdobeARMservice - ok 17:16:52.0995 11056 AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 17:16:52.0995 11056 AdobeFlashPlayerUpdateSvc - ok 17:16:53.0045 11056 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys 17:16:53.0075 11056 adp94xx - ok 17:16:53.0105 11056 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys 17:16:53.0125 11056 adpahci - ok 17:16:53.0145 11056 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys 17:16:53.0155 11056 adpu320 - ok 17:16:53.0175 11056 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll 17:16:53.0175 11056 AeLookupSvc - ok 17:16:53.0235 11056 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys 17:16:53.0255 11056 AFD - ok 17:16:53.0275 11056 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys 17:16:53.0275 11056 agp440 - ok 17:16:53.0291 11056 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe 17:16:53.0291 11056 ALG - ok 17:16:53.0307 11056 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys 17:16:53.0322 11056 aliide - ok 17:16:53.0322 11056 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys 17:16:53.0322 11056 amdide - ok 17:16:53.0353 11056 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys 17:16:53.0353 11056 AmdK8 - ok 17:16:53.0369 11056 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys 17:16:53.0369 11056 AmdPPM - ok 17:16:53.0385 11056 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys 17:16:53.0385 11056 amdsata - ok 17:16:53.0416 11056 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys 17:16:53.0416 11056 amdsbs - ok 17:16:53.0431 11056 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys 17:16:53.0431 11056 amdxata - ok 17:16:53.0509 11056 AntiVirSchedulerService (0a1cc583e8147004e4ad4625d7fbf88c) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 17:16:53.0509 11056 AntiVirSchedulerService - ok 17:16:53.0525 11056 AntiVirService (c9a36ef935aced86aedf93e97e606911) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 17:16:53.0541 11056 AntiVirService - ok 17:16:53.0572 11056 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys 17:16:53.0572 11056 AppID - ok 17:16:53.0587 11056 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll 17:16:53.0587 11056 AppIDSvc - ok 17:16:53.0587 11056 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll 17:16:53.0587 11056 Appinfo - ok 17:16:53.0634 11056 AppMgmt (4aba3e75a76195a3e38ed2766c962899) C:\Windows\System32\appmgmts.dll 17:16:53.0634 11056 AppMgmt - ok 17:16:53.0665 11056 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys 17:16:53.0681 11056 arc - ok 17:16:53.0697 11056 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys 17:16:53.0697 11056 arcsas - ok 17:16:53.0762 11056 aspnet_state (9217d874131ae6ff8f642f124f00a555) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 17:16:53.0772 11056 aspnet_state - ok 17:16:53.0792 11056 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys 17:16:53.0802 11056 AsyncMac - ok 17:16:53.0822 11056 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys 17:16:53.0822 11056 atapi - ok 17:16:53.0892 11056 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll 17:16:53.0922 11056 AudioEndpointBuilder - ok 17:16:53.0932 11056 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll 17:16:53.0932 11056 AudioSrv - ok 17:16:53.0962 11056 avgntflt (26e38b5a58c6c55fafbc563eeddb0867) C:\Windows\system32\DRIVERS\avgntflt.sys 17:16:53.0972 11056 avgntflt - ok 17:16:54.0012 11056 avipbb (9d1f00beff84cbbf46d7f052bc7e0565) C:\Windows\system32\DRIVERS\avipbb.sys 17:16:54.0022 11056 avipbb - ok 17:16:54.0042 11056 avkmgr (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys 17:16:54.0052 11056 avkmgr - ok 17:16:54.0102 11056 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll 17:16:54.0102 11056 AxInstSV - ok 17:16:54.0152 11056 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys 17:16:54.0172 11056 b06bdrv - ok 17:16:54.0222 11056 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys 17:16:54.0242 11056 b57nd60a - ok 17:16:54.0272 11056 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll 17:16:54.0272 11056 BDESVC - ok 17:16:54.0292 11056 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys 17:16:54.0292 11056 Beep - ok 17:16:54.0452 11056 BFE (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll 17:16:54.0462 11056 BFE - ok 17:16:54.0522 11056 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys 17:16:54.0522 11056 blbdrive - ok 17:16:54.0812 11056 bomgar-ps-1343054732-1343061997 (85afe0bcec17fefb71d48dd58da80c1b) C:\ProgramData\bomgar-scc-00000000500D638B\bomgar-scc.exe 17:16:54.0902 11056 bomgar-ps-1343054732-1343061997 - ok 17:16:55.0032 11056 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys 17:16:55.0032 11056 bowser - ok 17:16:55.0052 11056 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys 17:16:55.0052 11056 BrFiltLo - ok 17:16:55.0062 11056 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys 17:16:55.0062 11056 BrFiltUp - ok 17:16:55.0102 11056 BridgeMP (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys 17:16:55.0112 11056 BridgeMP - ok 17:16:55.0142 11056 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll 17:16:55.0152 11056 Browser - ok 17:16:55.0182 11056 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys 17:16:55.0192 11056 Brserid - ok 17:16:55.0202 11056 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys 17:16:55.0212 11056 BrSerWdm - ok 17:16:55.0222 11056 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys 17:16:55.0222 11056 BrUsbMdm - ok 17:16:55.0232 11056 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys 17:16:55.0232 11056 BrUsbSer - ok 17:16:55.0272 11056 BthEnum (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\DRIVERS\BthEnum.sys 17:16:55.0272 11056 BthEnum - ok 17:16:55.0292 11056 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys 17:16:55.0292 11056 BTHMODEM - ok 17:16:55.0312 11056 BthPan (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys 17:16:55.0322 11056 BthPan - ok 17:16:55.0372 11056 BTHPORT (64c198198501f7560ee41d8d1efa7952) C:\Windows\system32\Drivers\BTHport.sys 17:16:55.0392 11056 BTHPORT - ok 17:16:55.0422 11056 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll 17:16:55.0422 11056 bthserv - ok 17:16:55.0432 11056 BTHUSB (f188b7394d81010767b6df3178519a37) C:\Windows\system32\Drivers\BTHUSB.sys 17:16:55.0442 11056 BTHUSB - ok 17:16:55.0492 11056 BTWAMPFL (8767c8b416b6d583881f0fd7a0555135) C:\Windows\system32\DRIVERS\btwampfl.sys 17:16:55.0512 11056 BTWAMPFL - ok 17:16:55.0532 11056 btwaudio (ab95865207e68fe9245ba942ae20d09a) C:\Windows\system32\drivers\btwaudio.sys 17:16:55.0532 11056 btwaudio - ok 17:16:55.0552 11056 btwavdt (3cf91081b85241b624876cee7c1f5bbd) C:\Windows\system32\DRIVERS\btwavdt.sys 17:16:55.0552 11056 btwavdt - ok 17:16:55.0662 11056 btwdins (cead84b8e5902ae6c61f5b0f05c097ff) C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe 17:16:55.0692 11056 btwdins - ok 17:16:55.0702 11056 btwl2cap (b9354f9f111c64f2495b60f1e24cb453) C:\Windows\system32\DRIVERS\btwl2cap.sys 17:16:55.0712 11056 btwl2cap - ok 17:16:55.0722 11056 btwrchid (d08ea90b392c173dce0fdc0370d6bc9c) C:\Windows\system32\DRIVERS\btwrchid.sys 17:16:55.0732 11056 btwrchid - ok 17:16:55.0742 11056 catchme - ok 17:16:55.0772 11056 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys 17:16:55.0772 11056 cdfs - ok 17:16:55.0803 11056 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys 17:16:55.0819 11056 cdrom - ok 17:16:55.0850 11056 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll 17:16:55.0850 11056 CertPropSvc - ok 17:16:55.0881 11056 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys 17:16:55.0881 11056 circlass - ok 17:16:55.0913 11056 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys 17:16:55.0928 11056 CLFS - ok 17:16:55.0991 11056 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 17:16:55.0991 11056 clr_optimization_v2.0.50727_32 - ok 17:16:56.0022 11056 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 17:16:56.0022 11056 clr_optimization_v2.0.50727_64 - ok 17:16:56.0100 11056 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 17:16:56.0115 11056 clr_optimization_v4.0.30319_32 - ok 17:16:56.0147 11056 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 17:16:56.0162 11056 clr_optimization_v4.0.30319_64 - ok 17:16:56.0209 11056 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys 17:16:56.0209 11056 CmBatt - ok 17:16:56.0209 11056 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys 17:16:56.0225 11056 cmdide - ok 17:16:56.0271 11056 CNG (9ac4f97c2d3e93367e2148ea940cd2cd) C:\Windows\system32\Drivers\cng.sys 17:16:56.0287 11056 CNG - ok 17:16:56.0381 11056 CnxtHdAudService (290cd2777caf8a5e5499c7fc9e74cb87) C:\Windows\system32\drivers\CHDRT64.sys 17:16:56.0459 11056 CnxtHdAudService - ok 17:16:56.0599 11056 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys 17:16:56.0599 11056 Compbatt - ok 17:16:56.0615 11056 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\DRIVERS\CompositeBus.sys 17:16:56.0630 11056 CompositeBus - ok 17:16:56.0630 11056 COMSysApp - ok 17:16:56.0646 11056 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys 17:16:56.0646 11056 crcdisk - ok 17:16:56.0677 11056 CryptSvc (4f5414602e2544a4554d95517948b705) C:\Windows\system32\cryptsvc.dll 17:16:56.0693 11056 CryptSvc - ok 17:16:56.0724 11056 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys 17:16:56.0739 11056 CSC - ok 17:16:56.0802 11056 CscService (3ab183ab4d2c79dcf459cd2c1266b043) C:\Windows\System32\cscsvc.dll 17:16:56.0817 11056 CscService - ok 17:16:56.0864 11056 CxAudMsg (9d0d050170d47e778b624a28c90f23de) C:\Windows\system32\CxAudMsg64.exe 17:16:56.0864 11056 CxAudMsg - ok 17:16:56.0927 11056 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll 17:16:56.0942 11056 DcomLaunch - ok 17:16:56.0989 11056 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll 17:16:56.0989 11056 defragsvc - ok 17:16:57.0051 11056 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys 17:16:57.0051 11056 DfsC - ok 17:16:57.0083 11056 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll 17:16:57.0098 11056 Dhcp - ok 17:16:57.0114 11056 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys 17:16:57.0114 11056 discache - ok 17:16:57.0129 11056 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys 17:16:57.0129 11056 Disk - ok 17:16:57.0145 11056 dmvsc (5db085a8a6600be6401f2b24eecb5415) C:\Windows\system32\drivers\dmvsc.sys 17:16:57.0161 11056 dmvsc - ok 17:16:57.0176 11056 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll 17:16:57.0192 11056 Dnscache - ok 17:16:57.0207 11056 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll 17:16:57.0223 11056 dot3svc - ok 17:16:57.0239 11056 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll 17:16:57.0239 11056 DPS - ok 17:16:57.0254 11056 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys 17:16:57.0254 11056 drmkaud - ok 17:16:57.0332 11056 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys 17:16:57.0348 11056 DXGKrnl - ok 17:16:57.0363 11056 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll 17:16:57.0379 11056 EapHost - ok 17:16:57.0519 11056 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys 17:16:57.0597 11056 ebdrv - ok 17:16:57.0729 11056 ecnssndis (f88f2e5806fc405b0fa94b7947a5875e) C:\Windows\system32\Drivers\wwuss64.sys 17:16:57.0739 11056 ecnssndis - ok 17:16:57.0749 11056 ecnssndisfltr (c8cd88218efc28f7e44a9892b3e97f4d) C:\Windows\system32\Drivers\wwussf64.sys 17:16:57.0749 11056 ecnssndisfltr - ok 17:16:57.0769 11056 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe 17:16:57.0769 11056 EFS - ok 17:16:57.0839 11056 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe 17:16:57.0899 11056 ehRecvr - ok 17:16:57.0909 11056 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe 17:16:57.0919 11056 ehSched - ok 17:16:57.0979 11056 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys 17:16:57.0989 11056 elxstor - ok 17:16:57.0999 11056 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys 17:16:58.0009 11056 ErrDev - ok 17:16:58.0059 11056 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll 17:16:58.0069 11056 EventSystem - ok 17:16:58.0209 11056 EvtEng (532b8ff8e07f3772b086620377654f95) C:\Program Files\Intel\WiFi\bin\EvtEng.exe 17:16:58.0269 11056 EvtEng - ok 17:16:58.0439 11056 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys 17:16:58.0449 11056 exfat - ok 17:16:58.0469 11056 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys 17:16:58.0479 11056 fastfat - ok 17:16:58.0549 11056 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe 17:16:58.0609 11056 Fax - ok 17:16:58.0639 11056 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys 17:16:58.0639 11056 fdc - ok 17:16:58.0679 11056 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll 17:16:58.0679 11056 fdPHost - ok 17:16:58.0689 11056 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll 17:16:58.0689 11056 FDResPub - ok 17:16:58.0699 11056 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys 17:16:58.0709 11056 FileInfo - ok 17:16:58.0719 11056 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys 17:16:58.0719 11056 Filetrace - ok 17:16:58.0729 11056 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys 17:16:58.0729 11056 flpydisk - ok 17:16:58.0759 11056 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys 17:16:58.0769 11056 FltMgr - ok 17:16:58.0839 11056 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll 17:16:58.0869 11056 FontCache - ok 17:16:58.0939 11056 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 17:16:58.0939 11056 FontCache3.0.0.0 - ok 17:16:58.0959 11056 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys 17:16:58.0959 11056 FsDepends - ok 17:16:58.0979 11056 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys 17:16:58.0989 11056 Fs_Rec - ok 17:16:59.0029 11056 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys 17:16:59.0029 11056 fvevol - ok 17:16:59.0059 11056 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys 17:16:59.0069 11056 gagp30kx - ok 17:16:59.0119 11056 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll 17:16:59.0139 11056 gpsvc - ok 17:16:59.0159 11056 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys 17:16:59.0159 11056 hcw85cir - ok 17:16:59.0199 11056 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys 17:16:59.0209 11056 HdAudAddService - ok 17:16:59.0249 11056 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\DRIVERS\HDAudBus.sys 17:16:59.0259 11056 HDAudBus - ok 17:16:59.0269 11056 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys 17:16:59.0269 11056 HidBatt - ok 17:16:59.0279 11056 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys 17:16:59.0279 11056 HidBth - ok 17:16:59.0289 11056 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys 17:16:59.0289 11056 HidIr - ok 17:16:59.0299 11056 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\System32\hidserv.dll 17:16:59.0299 11056 hidserv - ok 17:16:59.0329 11056 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys 17:16:59.0329 11056 HidUsb - ok 17:16:59.0359 11056 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll 17:16:59.0359 11056 hkmsvc - ok 17:16:59.0389 11056 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll 17:16:59.0389 11056 HomeGroupListener - ok 17:16:59.0429 11056 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll 17:16:59.0429 11056 HomeGroupProvider - ok 17:16:59.0449 11056 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys 17:16:59.0449 11056 HpSAMD - ok 17:16:59.0549 11056 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys 17:16:59.0569 11056 HTTP - ok 17:16:59.0589 11056 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys 17:16:59.0589 11056 hwpolicy - ok 17:16:59.0599 11056 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys 17:16:59.0609 11056 i8042prt - ok 17:16:59.0649 11056 iaStor (26cf4275034214ecedd8ec17b0a18a99) C:\Windows\system32\DRIVERS\iaStor.sys 17:16:59.0649 11056 iaStor - ok 17:16:59.0679 11056 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys 17:16:59.0699 11056 iaStorV - ok 17:16:59.0729 11056 IBMPMDRV (72b253cdbcaa10e88aad0ba39cc83bcd) C:\Windows\system32\DRIVERS\ibmpmdrv.sys 17:16:59.0739 11056 IBMPMDRV - ok 17:16:59.0749 11056 IBMPMSVC (4925ffb084c9ad02e8eef01fb18bf5ac) C:\Windows\system32\ibmpmsvc.exe 17:16:59.0749 11056 IBMPMSVC - ok 17:16:59.0849 11056 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 17:16:59.0869 11056 idsvc - ok 17:17:00.0418 11056 igfx (f4f91789c7c7a159ce8215c1f69f2a85) C:\Windows\system32\DRIVERS\igdkmd64.sys 17:17:00.0605 11056 igfx - ok 17:17:00.0745 11056 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys 17:17:00.0745 11056 iirsp - ok 17:17:00.0823 11056 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll 17:17:00.0839 11056 IKEEXT - ok 17:17:00.0948 11056 ImeDictUpdateService (4552b448cf9c00ba2a94032af35bd9fc) C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE 17:17:00.0948 11056 ImeDictUpdateService - ok 17:17:00.0979 11056 intaud_WaveExtensible (caddf0927dac63edae48f5c35a61d87d) C:\Windows\system32\drivers\intelaud.sys 17:17:00.0979 11056 intaud_WaveExtensible - ok 17:17:01.0026 11056 IntcDAud (ae594cc17c33ac146739494615e14851) C:\Windows\system32\DRIVERS\IntcDAud.sys 17:17:01.0073 11056 IntcDAud - ok 17:17:01.0089 11056 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys 17:17:01.0089 11056 intelide - ok 17:17:01.0120 11056 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys 17:17:01.0120 11056 intelppm - ok 17:17:01.0151 11056 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll 17:17:01.0151 11056 IPBusEnum - ok 17:17:01.0167 11056 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys 17:17:01.0167 11056 IpFilterDriver - ok 17:17:01.0269 11056 iphlpsvc (a34a587fffd45fa649fba6d03784d257) C:\Windows\System32\iphlpsvc.dll 17:17:01.0269 11056 iphlpsvc - ok 17:17:01.0289 11056 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys 17:17:01.0289 11056 IPMIDRV - ok 17:17:01.0319 11056 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys 17:17:01.0319 11056 IPNAT - ok 17:17:01.0349 11056 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys 17:17:01.0349 11056 IRENUM - ok 17:17:01.0349 11056 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys 17:17:01.0359 11056 isapnp - ok 17:17:01.0379 11056 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys 17:17:01.0389 11056 iScsiPrt - ok 17:17:01.0419 11056 iwdbus (716f66336f10885d935b08174dc54242) C:\Windows\system32\DRIVERS\iwdbus.sys 17:17:01.0419 11056 iwdbus - ok 17:17:01.0499 11056 jhi_service (6c85719a21b3f62c2c76280f4bd36c7b) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe 17:17:01.0509 11056 jhi_service - ok 17:17:01.0529 11056 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys 17:17:01.0529 11056 kbdclass - ok 17:17:01.0549 11056 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys 17:17:01.0549 11056 kbdhid - ok 17:17:01.0579 11056 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 17:17:01.0579 11056 KeyIso - ok 17:17:01.0589 11056 KSecDD (97a7070aea4c058b6418519e869a63b4) C:\Windows\system32\Drivers\ksecdd.sys 17:17:01.0599 11056 KSecDD - ok 17:17:01.0609 11056 KSecPkg (26c43a7c2862447ec59deda188d1da07) C:\Windows\system32\Drivers\ksecpkg.sys 17:17:01.0619 11056 KSecPkg - ok 17:17:01.0629 11056 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys 17:17:01.0629 11056 ksthunk - ok 17:17:01.0679 11056 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll 17:17:01.0689 11056 KtmRm - ok 17:17:01.0719 11056 L1C (173666119d217e3739205c169e2bf0e5) C:\Windows\system32\DRIVERS\L1C62x64.sys 17:17:01.0729 11056 L1C - ok 17:17:01.0749 11056 l36wgps (c864875e87e6b790471516856fc1f5c2) C:\Windows\system32\DRIVERS\l36wgps64.sys 17:17:01.0749 11056 l36wgps - ok 17:17:01.0789 11056 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\System32\srvsvc.dll 17:17:01.0799 11056 LanmanServer - ok 17:17:01.0819 11056 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll 17:17:01.0829 11056 LanmanWorkstation - ok 17:17:01.0929 11056 LENOVO.MICMUTE (340288b3b2edc8afd5ff127df85142a7) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe 17:17:01.0929 11056 LENOVO.MICMUTE - ok 17:17:01.0939 11056 lenovo.smi (2b9d8555dc004e240082d18e7725ce20) C:\Windows\system32\DRIVERS\smiifx64.sys 17:17:01.0939 11056 lenovo.smi - ok 17:17:01.0969 11056 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys 17:17:01.0969 11056 lltdio - ok 17:17:02.0009 11056 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll 17:17:02.0029 11056 lltdsvc - ok 17:17:02.0039 11056 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll 17:17:02.0039 11056 lmhosts - ok 17:17:02.0079 11056 LMS (e7859ba062db5e23c6dd34ad66b09f50) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe 17:17:02.0089 11056 LMS - ok 17:17:02.0119 11056 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys 17:17:02.0139 11056 LSI_FC - ok 17:17:02.0169 11056 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys 17:17:02.0169 11056 LSI_SAS - ok 17:17:02.0179 11056 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys 17:17:02.0189 11056 LSI_SAS2 - ok 17:17:02.0199 11056 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys 17:17:02.0209 11056 LSI_SCSI - ok 17:17:02.0229 11056 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys 17:17:02.0239 11056 luafv - ok 17:17:02.0279 11056 mbamchameleon (4a0489f1cce69bb7371f8ea66efe78ec) C:\Windows\system32\drivers\mbamchameleon.sys 17:17:02.0289 11056 mbamchameleon - ok 17:17:02.0339 11056 Mbm3CBus (d8ba1ecbf0b9a4b4e1f3b7eb517d6c20) C:\Windows\system32\DRIVERS\Mbm3CBus.sys 17:17:02.0349 11056 Mbm3CBus - ok 17:17:02.0379 11056 Mbm3DevMt (01e60917101b309e15f30da26acf64f6) C:\Windows\system32\DRIVERS\Mbm3DevMt.sys 17:17:02.0399 11056 Mbm3DevMt - ok 17:17:02.0409 11056 Mbm3mdfl (6350a2ca21fb7b14432effdc61863aed) C:\Windows\system32\DRIVERS\Mbm3mdfl.sys 17:17:02.0409 11056 Mbm3mdfl - ok 17:17:02.0449 11056 Mbm3Mdm (9fc3a8713d148e15d0472e1c44dd0fda) C:\Windows\system32\DRIVERS\Mbm3Mdm.sys 17:17:02.0459 11056 Mbm3Mdm - ok 17:17:02.0489 11056 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll 17:17:02.0489 11056 Mcx2Svc - ok 17:17:02.0519 11056 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys 17:17:02.0519 11056 megasas - ok 17:17:02.0549 11056 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys 17:17:02.0559 11056 MegaSR - ok 17:17:02.0589 11056 MEIx64 (a6518dcc42f7a6e999bb3bea8fd87567) C:\Windows\system32\DRIVERS\HECIx64.sys 17:17:02.0589 11056 MEIx64 - ok 17:17:02.0609 11056 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll 17:17:02.0609 11056 MMCSS - ok 17:17:02.0619 11056 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys 17:17:02.0619 11056 Modem - ok 17:17:02.0639 11056 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys 17:17:02.0639 11056 monitor - ok 17:17:02.0669 11056 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys 17:17:02.0669 11056 mouclass - ok 17:17:02.0689 11056 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys 17:17:02.0699 11056 mouhid - ok 17:17:02.0709 11056 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys 17:17:02.0709 11056 mountmgr - ok 17:17:02.0779 11056 MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 17:17:02.0789 11056 MozillaMaintenance - ok 17:17:02.0829 11056 MpFilter (94c66ededcdb6a126880472f9a704d8e) C:\Windows\system32\DRIVERS\MpFilter.sys 17:17:02.0849 11056 MpFilter - ok 17:17:02.0859 11056 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys 17:17:02.0869 11056 mpio - ok 17:17:02.0889 11056 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys 17:17:02.0889 11056 mpsdrv - ok 17:17:02.0959 11056 MpsSvc (54ffc9c8898113ace189d4aa7199d2c1) C:\Windows\system32\mpssvc.dll 17:17:02.0989 11056 MpsSvc - ok 17:17:03.0019 11056 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys 17:17:03.0019 11056 MRxDAV - ok 17:17:03.0039 11056 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys 17:17:03.0049 11056 mrxsmb - ok 17:17:03.0079 11056 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys 17:17:03.0089 11056 mrxsmb10 - ok 17:17:03.0109 11056 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 17:17:03.0119 11056 mrxsmb20 - ok 17:17:03.0129 11056 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys 17:17:03.0129 11056 msahci - ok 17:17:03.0159 11056 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys 17:17:03.0159 11056 msdsm - ok 17:17:03.0179 11056 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe 17:17:03.0179 11056 MSDTC - ok 17:17:03.0209 11056 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys 17:17:03.0209 11056 Msfs - ok 17:17:03.0229 11056 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys 17:17:03.0229 11056 mshidkmdf - ok 17:17:03.0249 11056 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys 17:17:03.0249 11056 msisadrv - ok 17:17:03.0269 11056 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll 17:17:03.0279 11056 MSiSCSI - ok 17:17:03.0289 11056 msiserver - ok 17:17:03.0319 11056 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys 17:17:03.0329 11056 MSKSSRV - ok 17:17:03.0389 11056 MsMpSvc (59faaf2c83c8169ea20f9e335e418907) c:\Program Files\Microsoft Security Client\MsMpEng.exe 17:17:03.0389 11056 MsMpSvc - ok 17:17:03.0409 11056 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys 17:17:03.0419 11056 MSPCLOCK - ok 17:17:03.0419 11056 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys 17:17:03.0419 11056 MSPQM - ok 17:17:03.0459 11056 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys 17:17:03.0469 11056 MsRPC - ok 17:17:03.0479 11056 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys 17:17:03.0479 11056 mssmbios - ok 17:17:03.0499 11056 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys 17:17:03.0499 11056 MSTEE - ok 17:17:03.0499 11056 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys 17:17:03.0509 11056 MTConfig - ok 17:17:03.0519 11056 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys 17:17:03.0529 11056 Mup - ok 17:17:03.0599 11056 MyWiFiDHCPDNS (265937bc59819df1dab65e27c60f94c0) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe 17:17:03.0609 11056 MyWiFiDHCPDNS - ok 17:17:03.0649 11056 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll 17:17:03.0669 11056 napagent - ok 17:17:03.0709 11056 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys 17:17:03.0719 11056 NativeWifiP - ok 17:17:03.0789 11056 NDIS (c38b8ae57f78915905064a9a24dc1586) C:\Windows\system32\drivers\ndis.sys 17:17:03.0809 11056 NDIS - ok 17:17:03.0829 11056 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys 17:17:03.0829 11056 NdisCap - ok 17:17:03.0839 11056 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys 17:17:03.0839 11056 NdisTapi - ok 17:17:03.0859 11056 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys 17:17:03.0859 11056 Ndisuio - ok 17:17:03.0879 11056 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys 17:17:03.0889 11056 NdisWan - ok 17:17:03.0919 11056 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys 17:17:03.0919 11056 NDProxy - ok 17:17:03.0949 11056 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys 17:17:03.0949 11056 NetBIOS - ok 17:17:03.0969 11056 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys 17:17:03.0989 11056 NetBT - ok 17:17:04.0009 11056 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 17:17:04.0009 11056 Netlogon - ok 17:17:04.0059 11056 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll 17:17:04.0069 11056 Netman - ok 17:17:04.0149 11056 NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 17:17:04.0159 11056 NetMsmqActivator - ok 17:17:04.0159 11056 NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 17:17:04.0159 11056 NetPipeActivator - ok 17:17:04.0209 11056 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll 17:17:04.0229 11056 netprofm - ok 17:17:04.0239 11056 NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 17:17:04.0239 11056 NetTcpActivator - ok 17:17:04.0249 11056 NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 17:17:04.0249 11056 NetTcpPortSharing - ok 17:17:04.0619 11056 NETwNs64 (774c9eccef83ab8a3d1466f19809c95f) C:\Windows\system32\DRIVERS\NETwNs64.sys 17:17:04.0789 11056 NETwNs64 - ok 17:17:04.0919 11056 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys 17:17:04.0919 11056 nfrd960 - ok 17:17:04.0939 11056 NisDrv (91b4e0273d2f6c24ef845f2b41311289) C:\Windows\system32\DRIVERS\NisDrvWFP.sys 17:17:04.0949 11056 NisDrv - ok 17:17:05.0019 11056 NisSrv (10a43829a9e606af3eef25a1c1665923) c:\Program Files\Microsoft Security Client\NisSrv.exe 17:17:05.0029 11056 NisSrv - ok 17:17:05.0069 11056 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll 17:17:05.0079 11056 NlaSvc - ok 17:17:05.0099 11056 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys 17:17:05.0099 11056 Npfs - ok 17:17:05.0109 11056 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll 17:17:05.0109 11056 nsi - ok 17:17:05.0139 11056 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys 17:17:05.0139 11056 nsiproxy - ok 17:17:05.0239 11056 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys 17:17:05.0269 11056 Ntfs - ok 17:17:05.0349 11056 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys 17:17:05.0349 11056 Null - ok 17:17:05.0389 11056 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys 17:17:05.0399 11056 nvraid - ok 17:17:05.0429 11056 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys 17:17:05.0439 11056 nvstor - ok 17:17:05.0459 11056 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys 17:17:05.0469 11056 nv_agp - ok 17:17:05.0489 11056 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys 17:17:05.0489 11056 ohci1394 - ok 17:17:05.0549 11056 ose (9d10f99a6712e28f8acd5641e3a7ea6b) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 17:17:05.0559 11056 ose - ok 17:17:05.0799 11056 osppsvc (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 17:17:05.0889 11056 osppsvc - ok 17:17:05.0999 11056 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll 17:17:06.0009 11056 p2pimsvc - ok 17:17:06.0049 11056 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll 17:17:06.0069 11056 p2psvc - ok 17:17:06.0109 11056 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\drivers\parport.sys 17:17:06.0109 11056 Parport - ok 17:17:06.0129 11056 partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys 17:17:06.0129 11056 partmgr - ok 17:17:06.0159 11056 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll 17:17:06.0169 11056 PcaSvc - ok 17:17:06.0199 11056 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys 17:17:06.0199 11056 pci - ok 17:17:06.0219 11056 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys 17:17:06.0219 11056 pciide - ok 17:17:06.0239 11056 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys 17:17:06.0259 11056 pcmcia - ok 17:17:06.0269 11056 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys 17:17:06.0279 11056 pcw - ok 17:17:06.0319 11056 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys 17:17:06.0339 11056 PEAUTH - ok 17:17:06.0399 11056 PeerDistSvc (b9b0a4299dd2d76a4243f75fd54dc680) C:\Windows\system32\peerdistsvc.dll 17:17:06.0429 11056 PeerDistSvc - ok 17:17:06.0509 11056 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe 17:17:06.0509 11056 PerfHost - ok 17:17:06.0659 11056 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll 17:17:06.0689 11056 pla - ok 17:17:06.0799 11056 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll 17:17:06.0819 11056 PlugPlay - ok 17:17:06.0829 11056 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll 17:17:06.0839 11056 PNRPAutoReg - ok 17:17:06.0859 11056 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll 17:17:06.0859 11056 PNRPsvc - ok 17:17:06.0909 11056 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll 17:17:06.0919 11056 PolicyAgent - ok 17:17:06.0959 11056 Power (a2cca4fb273e6050f17a0a416cff2fcd) C:\Windows\system32\umpo.dll 17:17:06.0969 11056 Power - ok 17:17:07.0039 11056 Power Manager DBC Service (0bf1d6b41e4d4376be4e4fa31d1a88c0) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE 17:17:07.0039 11056 Power Manager DBC Service - ok 17:17:07.0089 11056 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys 17:17:07.0099 11056 PptpMiniport - ok 17:17:07.0129 11056 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys 17:17:07.0139 11056 Processor - ok 17:17:07.0169 11056 ProfSvc (53e83f1f6cf9d62f32801cf66d8352a8) C:\Windows\system32\profsvc.dll 17:17:07.0189 11056 ProfSvc - ok 17:17:07.0209 11056 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 17:17:07.0219 11056 ProtectedStorage - ok 17:17:07.0239 11056 psadd (05a4779e4994b21473edbe85aabe8030) C:\Windows\system32\DRIVERS\psadd.sys 17:17:07.0239 11056 psadd - ok 17:17:07.0279 11056 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys 17:17:07.0289 11056 Psched - ok 17:17:07.0319 11056 PwmEWSvc (d20bf8b293eb90e3c4ed2f38b51948a1) C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE 17:17:07.0319 11056 PwmEWSvc - ok 17:17:07.0379 11056 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys 17:17:07.0417 11056 ql2300 - ok 17:17:07.0507 11056 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys 17:17:07.0517 11056 ql40xx - ok 17:17:07.0547 11056 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll 17:17:07.0567 11056 QWAVE - ok 17:17:07.0577 11056 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys 17:17:07.0577 11056 QWAVEdrv - ok 17:17:07.0597 11056 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys 17:17:07.0597 11056 RasAcd - ok 17:17:07.0627 11056 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys 17:17:07.0627 11056 RasAgileVpn - ok 17:17:07.0647 11056 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll 17:17:07.0657 11056 RasAuto - ok 17:17:07.0667 11056 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys 17:17:07.0677 11056 Rasl2tp - ok 17:17:07.0717 11056 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll 17:17:07.0727 11056 RasMan - ok 17:17:07.0737 11056 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys 17:17:07.0747 11056 RasPppoe - ok 17:17:07.0767 11056 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys 17:17:07.0767 11056 RasSstp - ok 17:17:07.0807 11056 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys 17:17:07.0817 11056 rdbss - ok 17:17:07.0847 11056 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys 17:17:07.0847 11056 rdpbus - ok 17:17:07.0867 11056 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys 17:17:07.0867 11056 RDPCDD - ok 17:17:07.0897 11056 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys 17:17:07.0907 11056 RDPDR - ok 17:17:07.0937 11056 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys 17:17:07.0937 11056 RDPENCDD - ok 17:17:07.0947 11056 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys 17:17:07.0947 11056 RDPREFMP - ok 17:17:07.0977 11056 RDPWD (e61608aa35e98999af9aaeeea6114b0a) C:\Windows\system32\drivers\RDPWD.sys 17:17:07.0987 11056 RDPWD - ok 17:17:08.0017 11056 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys 17:17:08.0047 11056 rdyboost - ok 17:17:08.0147 11056 RegSrvc (7196be857e29007470ff9b689c7f29a7) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe 17:17:08.0167 11056 RegSrvc - ok 17:17:08.0227 11056 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll 17:17:08.0227 11056 RemoteAccess - ok 17:17:08.0247 11056 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll 17:17:08.0257 11056 RemoteRegistry - ok 17:17:08.0327 11056 RFCOMM (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys 17:17:08.0337 11056 RFCOMM - ok 17:17:08.0357 11056 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll 17:17:08.0357 11056 RpcEptMapper - ok 17:17:08.0377 11056 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe 17:17:08.0387 11056 RpcLocator - ok 17:17:08.0417 11056 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll 17:17:08.0417 11056 RpcSs - ok 17:17:08.0467 11056 RSPCIESTOR (ca327a84085f68200452e6761f943298) C:\Windows\system32\DRIVERS\RtsPStor.sys 17:17:08.0477 11056 RSPCIESTOR - ok 17:17:08.0517 11056 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys 17:17:08.0517 11056 rspndr - ok 17:17:08.0527 11056 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys 17:17:08.0537 11056 s3cap - ok 17:17:08.0557 11056 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 17:17:08.0557 11056 SamSs - ok 17:17:08.0557 11056 SAService - ok 17:17:08.0577 11056 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys 17:17:08.0587 11056 sbp2port - ok 17:17:08.0607 11056 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll 17:17:08.0627 11056 SCardSvr - ok 17:17:08.0637 11056 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys 17:17:08.0637 11056 scfilter - ok 17:17:08.0737 11056 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll 17:17:08.0767 11056 Schedule - ok 17:17:08.0787 11056 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll 17:17:08.0797 11056 SCPolicySvc - ok 17:17:08.0827 11056 sdbus (111e0ebc0ad79cb0fa014b907b231cf0) C:\Windows\system32\DRIVERS\sdbus.sys 17:17:08.0827 11056 sdbus - ok 17:17:08.0867 11056 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll 17:17:08.0867 11056 SDRSVC - ok 17:17:08.0937 11056 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys 17:17:08.0947 11056 secdrv - ok 17:17:08.0957 11056 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll 17:17:08.0957 11056 seclogon - ok 17:17:08.0987 11056 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\system32\sens.dll 17:17:08.0987 11056 SENS - ok 17:17:09.0007 11056 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll 17:17:09.0007 11056 SensrSvc - ok 17:17:09.0017 11056 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\drivers\serenum.sys 17:17:09.0017 11056 Serenum - ok 17:17:09.0047 11056 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\drivers\serial.sys 17:17:09.0047 11056 Serial - ok 17:17:09.0057 11056 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys 17:17:09.0067 11056 sermouse - ok 17:17:09.0087 11056 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll 17:17:09.0087 11056 SessionEnv - ok 17:17:09.0137 11056 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys 17:17:09.0147 11056 sffdisk - ok 17:17:09.0157 11056 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys 17:17:09.0167 11056 sffp_mmc - ok 17:17:09.0177 11056 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys 17:17:09.0187 11056 sffp_sd - ok 17:17:09.0207 11056 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys 17:17:09.0207 11056 sfloppy - ok 17:17:09.0277 11056 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll 17:17:09.0287 11056 SharedAccess - ok 17:17:09.0317 11056 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll 17:17:09.0377 11056 ShellHWDetection - ok 17:17:09.0407 11056 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys 17:17:09.0407 11056 SiSRaid2 - ok 17:17:09.0427 11056 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys 17:17:09.0427 11056 SiSRaid4 - ok 17:17:09.0517 11056 SkypeUpdate (579ba0a911ff5ea70cb604cd3b744b0a) C:\Program Files (x86)\Skype\Updater\Updater.exe 17:17:09.0527 11056 SkypeUpdate - ok 17:17:09.0547 11056 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys 17:17:09.0557 11056 Smb - ok 17:17:09.0587 11056 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe 17:17:09.0597 11056 SNMPTRAP - ok 17:17:09.0607 11056 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys 17:17:09.0617 11056 spldr - ok 17:17:09.0657 11056 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe 17:17:09.0717 11056 Spooler - ok 17:17:09.0867 11056 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe 17:17:09.0937 11056 sppsvc - ok 17:17:10.0047 11056 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll 17:17:10.0057 11056 sppuinotify - ok 17:17:10.0107 11056 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys 17:17:10.0117 11056 srv - ok 17:17:10.0167 11056 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys 17:17:10.0187 11056 srv2 - ok 17:17:10.0217 11056 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys 17:17:10.0227 11056 srvnet - ok 17:17:10.0267 11056 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll 17:17:10.0277 11056 SSDPSRV - ok 17:17:10.0287 11056 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll 17:17:10.0287 11056 SstpSvc - ok 17:17:10.0317 11056 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys 17:17:10.0317 11056 stexstor - ok 17:17:10.0357 11056 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll 17:17:10.0367 11056 stisvc - ok 17:17:10.0407 11056 storflt (7785dc213270d2fc066538daf94087e7) C:\Windows\system32\drivers\vmstorfl.sys 17:17:10.0407 11056 storflt - ok 17:17:10.0417 11056 StorSvc (c40841817ef57d491f22eb103da587cc) C:\Windows\system32\storsvc.dll 17:17:10.0417 11056 StorSvc - ok 17:17:10.0447 11056 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys 17:17:10.0447 11056 storvsc - ok 17:17:10.0537 11056 SUService (59b5a060a31bd4bab030c4fcd1048292) C:\Program Files (x86)\Lenovo\System Update\SUService.exe 17:17:10.0537 11056 SUService - ok 17:17:10.0547 11056 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys 17:17:10.0547 11056 swenum - ok 17:17:10.0587 11056 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll 17:17:10.0597 11056 swprv - ok 17:17:10.0687 11056 SynTP (ffdd13b42d4b106ac9fafbb0e1f7faa5) C:\Windows\system32\DRIVERS\SynTP.sys 17:17:10.0747 11056 SynTP - ok 17:17:10.0907 11056 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll 17:17:10.0957 11056 SysMain - ok 17:17:11.0017 11056 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll 17:17:11.0027 11056 TabletInputService - ok 17:17:11.0057 11056 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll 17:17:11.0067 11056 TapiSrv - ok 17:17:11.0087 11056 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll 17:17:11.0087 11056 TBS - ok 17:17:11.0197 11056 Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys 17:17:11.0227 11056 Tcpip - ok 17:17:11.0377 11056 TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys 17:17:11.0387 11056 TCPIP6 - ok 17:17:11.0457 11056 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys 17:17:11.0467 11056 tcpipreg - ok 17:17:11.0477 11056 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys 17:17:11.0487 11056 TDPIPE - ok 17:17:11.0507 11056 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys 17:17:11.0507 11056 TDTCP - ok 17:17:11.0537 11056 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys 17:17:11.0537 11056 tdx - ok 17:17:11.0537 11056 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\DRIVERS\termdd.sys 17:17:11.0547 11056 TermDD - ok 17:17:11.0597 11056 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll 17:17:11.0617 11056 TermService - ok 17:17:11.0627 11056 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll 17:17:11.0637 11056 Themes - ok 17:17:11.0667 11056 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll 17:17:11.0667 11056 THREADORDER - ok 17:17:11.0747 11056 TPHKLOAD (83415782d47f8064fcafea308abb2246) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe 17:17:11.0757 11056 TPHKLOAD - ok 17:17:11.0797 11056 TPHKSVC (c04bb65441913ab621c58a8bd3169b23) C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe 17:17:11.0807 11056 TPHKSVC - ok 17:17:11.0837 11056 TPM (dbcc20c02e8a3e43b03c304a4e40a84f) C:\Windows\system32\drivers\tpm.sys 17:17:11.0837 11056 TPM - ok 17:17:11.0867 11056 TPPWRIF (7165b5a9b4867f64a6d6935f57d4196b) C:\Windows\system32\drivers\Tppwr64v.sys 17:17:11.0877 11056 TPPWRIF - ok 17:17:11.0907 11056 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll 17:17:11.0907 11056 TrkWks - ok 17:17:11.0947 11056 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe 17:17:11.0957 11056 TrustedInstaller - ok 17:17:11.0967 11056 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys 17:17:11.0967 11056 tssecsrv - ok 17:17:11.0987 11056 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys 17:17:11.0987 11056 TsUsbFlt - ok 17:17:11.0997 11056 TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys 17:17:12.0007 11056 TsUsbGD - ok 17:17:12.0037 11056 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys 17:17:12.0047 11056 tunnel - ok 17:17:12.0067 11056 TVTI2C (4daae0413cd4e816258838e2fafb3147) C:\Windows\system32\DRIVERS\Tvti2c.sys 17:17:12.0077 11056 TVTI2C - ok 17:17:12.0087 11056 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys 17:17:12.0097 11056 uagp35 - ok 17:17:12.0117 11056 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys 17:17:12.0127 11056 udfs - ok 17:17:12.0157 11056 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe 17:17:12.0157 11056 UI0Detect - ok 17:17:12.0187 11056 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys 17:17:12.0187 11056 uliagpkx - ok 17:17:12.0227 11056 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys 17:17:12.0227 11056 umbus - ok 17:17:12.0257 11056 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys 17:17:12.0257 11056 UmPass - ok 17:17:12.0277 11056 UmRdpService (a293dcd756d04d8492a750d03b9a297c) C:\Windows\System32\umrdp.dll 17:17:12.0287 11056 UmRdpService - ok 17:17:12.0432 11056 UNS (e91f8afbd7fb96c94b266579d6bfa77a) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe 17:17:12.0479 11056 UNS - ok 17:17:12.0588 11056 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll 17:17:12.0603 11056 upnphost - ok 17:17:12.0635 11056 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys 17:17:12.0635 11056 usbaudio - ok 17:17:12.0666 11056 usbccgp (ebf228a52517042de4f38a40285bc8d9) C:\Windows\system32\DRIVERS\usbccgp.sys 17:17:12.0681 11056 usbccgp - ok 17:17:12.0697 11056 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys 17:17:12.0697 11056 usbcir - ok 17:17:12.0713 11056 usbehci (6b3d5e6a9da786ec755b00bc180c700b) C:\Windows\system32\drivers\usbehci.sys 17:17:12.0728 11056 usbehci - ok 17:17:12.0759 11056 usbhub (94abe9da48e466bbe84c73e0c6652ed1) C:\Windows\system32\DRIVERS\usbhub.sys 17:17:12.0791 11056 usbhub - ok 17:17:12.0806 11056 usbohci (660b2c08ce7103e71eaa26f85b0b0a56) C:\Windows\system32\drivers\usbohci.sys 17:17:12.0806 11056 usbohci - ok 17:17:12.0806 11056 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\drivers\usbprint.sys 17:17:12.0822 11056 usbprint - ok 17:17:12.0837 11056 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS 17:17:12.0853 11056 USBSTOR - ok 17:17:12.0869 11056 usbuhci (1529632fc96032d337b298f8a285d640) C:\Windows\system32\drivers\usbuhci.sys 17:17:12.0869 11056 usbuhci - ok 17:17:12.0884 11056 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\system32\Drivers\usbvideo.sys 17:17:12.0900 11056 usbvideo - ok 17:17:12.0931 11056 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll 17:17:12.0931 11056 UxSms - ok 17:17:12.0978 11056 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe 17:17:12.0978 11056 VaultSvc - ok 17:17:13.0009 11056 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys 17:17:13.0009 11056 vdrvroot - ok 17:17:13.0049 11056 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe 17:17:13.0069 11056 vds - ok 17:17:13.0089 11056 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys 17:17:13.0089 11056 vga - ok 17:17:13.0099 11056 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys 17:17:13.0099 11056 VgaSave - ok 17:17:13.0119 11056 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys 17:17:13.0129 11056 vhdmp - ok 17:17:13.0149 11056 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys 17:17:13.0149 11056 viaide - ok 17:17:13.0169 11056 vmbus (86ea3e79ae350fea5331a1303054005f) C:\Windows\system32\drivers\vmbus.sys 17:17:13.0179 11056 vmbus - ok 17:17:13.0199 11056 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys 17:17:13.0209 11056 VMBusHID - ok 17:17:13.0229 11056 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys 17:17:13.0229 11056 volmgr - ok 17:17:13.0279 11056 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys 17:17:13.0279 11056 volmgrx - ok 17:17:13.0319 11056 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys 17:17:13.0319 11056 volsnap - ok 17:17:13.0349 11056 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys 17:17:13.0349 11056 vsmraid - ok 17:17:13.0429 11056 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe 17:17:13.0449 11056 VSS - ok 17:17:13.0549 11056 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys 17:17:13.0549 11056 vwifibus - ok 17:17:13.0569 11056 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys 17:17:13.0579 11056 vwififlt - ok 17:17:13.0589 11056 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys 17:17:13.0589 11056 vwifimp - ok 17:17:13.0619 11056 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll 17:17:13.0639 11056 W32Time - ok 17:17:13.0659 11056 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys 17:17:13.0659 11056 WacomPen - ok 17:17:13.0689 11056 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 17:17:13.0689 11056 WANARP - ok 17:17:13.0699 11056 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys 17:17:13.0699 11056 Wanarpv6 - ok 17:17:13.0779 11056 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe 17:17:13.0849 11056 WatAdminSvc - ok 17:17:13.0919 11056 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe 17:17:13.0949 11056 wbengine - ok 17:17:14.0059 11056 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll 17:17:14.0059 11056 WbioSrvc - ok 17:17:14.0099 11056 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll 17:17:14.0109 11056 wcncsvc - ok 17:17:14.0119 11056 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll 17:17:14.0129 11056 WcsPlugInService - ok 17:17:14.0149 11056 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys 17:17:14.0149 11056 Wd - ok 17:17:14.0219 11056 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys 17:17:14.0229 11056 Wdf01000 - ok 17:17:14.0259 11056 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll 17:17:14.0269 11056 WdiServiceHost - ok 17:17:14.0279 11056 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll 17:17:14.0279 11056 WdiSystemHost - ok 17:17:14.0299 11056 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll 17:17:14.0319 11056 WebClient - ok 17:17:14.0339 11056 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll 17:17:14.0359 11056 Wecsvc - ok 17:17:14.0369 11056 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll 17:17:14.0389 11056 wercplsupport - ok 17:17:14.0419 11056 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll 17:17:14.0419 11056 WerSvc - ok 17:17:14.0469 11056 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys 17:17:14.0469 11056 WfpLwf - ok 17:17:14.0479 11056 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys 17:17:14.0479 11056 WIMMount - ok 17:17:14.0519 11056 WinDefend - ok 17:17:14.0529 11056 WinHttpAutoProxySvc - ok 17:17:14.0579 11056 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll 17:17:14.0589 11056 Winmgmt - ok 17:17:14.0699 11056 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll 17:17:14.0749 11056 WinRM - ok 17:17:14.0899 11056 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll 17:17:14.0929 11056 Wlansvc - ok 17:17:14.0979 11056 wlcrasvc (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 17:17:14.0989 11056 wlcrasvc - ok 17:17:15.0109 11056 wlidsvc (7e47c328fc4768cb8beafbcfafa70362) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 17:17:15.0149 11056 wlidsvc - ok 17:17:15.0199 11056 WMCoreService - ok 17:17:15.0319 11056 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys 17:17:15.0319 11056 WmiAcpi - ok 17:17:15.0369 11056 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe 17:17:15.0389 11056 wmiApSrv - ok 17:17:15.0389 11056 WMPNetworkSvc - ok 17:17:15.0419 11056 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll 17:17:15.0419 11056 WPCSvc - ok 17:17:15.0429 11056 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll 17:17:15.0449 11056 WPDBusEnum - ok 17:17:15.0459 11056 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys 17:17:15.0459 11056 ws2ifsl - ok 17:17:15.0479 11056 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\system32\wscsvc.dll 17:17:15.0489 11056 wscsvc - ok 17:17:15.0489 11056 WSearch - ok 17:17:15.0619 11056 wuauserv (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll 17:17:15.0659 11056 wuauserv - ok 17:17:15.0739 11056 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys 17:17:15.0749 11056 WudfPf - ok 17:17:15.0779 11056 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys 17:17:15.0779 11056 WUDFRd - ok 17:17:15.0799 11056 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll 17:17:15.0809 11056 wudfsvc - ok 17:17:15.0839 11056 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll 17:17:15.0859 11056 WwanSvc - ok 17:17:15.0909 11056 WwanUsbServ (aa0a3a08a501237cd5bc4cfbfb64b3d6) C:\Windows\system32\DRIVERS\WwanUsbMp64.sys 17:17:15.0919 11056 WwanUsbServ - ok 17:17:15.0959 11056 MBR (0x1B8) (13b96b893e779ca56840a3a6ed81db9e) \Device\Harddisk0\DR0 17:17:16.0189 11056 \Device\Harddisk0\DR0 - ok 17:17:16.0189 11056 Boot (0x1200) (b0e3205cb67d02d7cba4897d2f11c0f4) \Device\Harddisk0\DR0\Partition0 17:17:16.0199 11056 \Device\Harddisk0\DR0\Partition0 - ok 17:17:16.0199 11056 Boot (0x1200) (414b7138f2e84943e26830da6c6a0e3d) \Device\Harddisk0\DR0\Partition1 17:17:16.0209 11056 \Device\Harddisk0\DR0\Partition1 - ok 17:17:16.0239 11056 Boot (0x1200) (b7a2c1fad2fb4a2e37c6c4e96c2ab97b) \Device\Harddisk0\DR0\Partition2 17:17:16.0249 11056 \Device\Harddisk0\DR0\Partition2 - ok 17:17:16.0249 11056 ============================================================ 17:17:16.0249 11056 Scan finished 17:17:16.0249 11056 ============================================================ 17:17:16.0259 9416 Detected object count: 0 17:17:16.0259 9416 Actual detected object count: 0
FRST

Download Farbar Recovery Scan Tool and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Won't get physical access to the laptop to put in a USB stick until Monday. Will post the log then. Have a great weekend and thanks for all your help so far. /Matti
—— Scan result of Farbar Recovery Scan Tool Version: 25-07-2012 01 Ran by [removed] at 01-08-2012 14:06:19 Running from F:\ Windows 7 Professional Service Pack 1 (X64) OS Language: English(US) The current controlset is ControlSet001 ========================== Registry (Whitelisted) ============= HKLM\…\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2789160 2011-05-19] (Synaptics Incorporated) HKLM\…\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [310912 2011-04-26] (Conexant Systems, Inc.) HKLM\…\Run: [ForteConfig] C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-25] () HKLM\…\Run: [AcWin7Hlpr] C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe [x] HKLM\…\Run: [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray [1935120 2011-11-01] (Intel® Corporation) HKLM\…\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [167704 2012-01-23] (Intel Corporation) HKLM\…\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [392984 2012-01-23] (Intel Corporation) HKLM\…\Run: [Persistence] C:\Windows\system32\igfxpers.exe [417560 2012-01-23] (Intel Corporation) HKLM\…\Run: [IME14 CHT Setup] C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHT /Log [110896 2012-03-13] (Microsoft Corporation) HKLM\…\Run: [IME14 JPN Setup] C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log [110896 2012-03-13] (Microsoft Corporation) HKLM\…\Run: [IME14 KOR Setup] C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /KOR /Log [110896 2012-03-13] (Microsoft Corporation) HKLM\…\Run: [IME14 CHS Setup] C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHS /Log [110896 2012-03-13] (Microsoft Corporation) HKLM\…\Run: [Logitech Download Assistant] C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch [1580368 2010-11-03] (Logitech, Inc.) HKLM-x32\…\Run: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.) HKLM-x32\…\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor [1629544 2011-08-31] (Lenovo Group Limited) HKLM-x32\…\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated) HKLM-x32\…\Run: [IME14 CHT Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHT /Log [81200 2012-03-13] (Microsoft Corporation) HKLM-x32\…\Run: [IME14 JPN Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log [81200 2012-03-13] (Microsoft Corporation) HKLM-x32\…\Run: [IME14 KOR Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /KOR /Log [81200 2012-03-13] (Microsoft Corporation) HKLM-x32\…\Run: [IME14 CHS Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHS /Log [81200 2012-03-13] (Microsoft Corporation) HKLM-x32\…\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.) HKLM-x32\…\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2012-02-20] (Apple Inc.) HKLM-x32\…\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-04-18] (Apple Inc.) HKLM-x32\…\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [348624 2012-05-01] (Avira Operations GmbH & Co. KG) HKU\localuser\…\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17355912 2012-05-02] (Skype Technologies S.A.) HKLM\…\Runonce: [uninstall-{583A4C50-25BD-476F-AEA4-21835170AEB3}] msiexec /quiet /x {23ED47CE-A835-4A48-AB3B-FC1B83EDA637} [x] Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation) Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 8.8.4.4 Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.) Startup: C:\Users\localuser\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> (No File) ==================== Services (Whitelisted) ====== 2 AntiVirSchedulerService; "C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe" [86224 2012-05-01] (Avira Operations GmbH & Co. KG) 2 AntiVirService; "C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe" [110032 2012-05-01] (Avira Operations GmbH & Co. KG) 2 bomgar-ps-1343054732-1343061997; "C:\ProgramData\bomgar-scc-00000000500D638B\bomgar-scc.exe" -pinned elevated [5371360 2012-05-19] (Bomgar) 2 btwdins; C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe [968480 2011-03-24] (Broadcom Corporation.) 2 CxAudMsg; C:\Windows\system32\CxAudMsg64.exe [198784 2010-12-16] (Conexant Systems Inc.) 2 IBMPMSVC; C:\Windows\System32\ibmpmsvc.exe [48704 2012-02-29] (Lenovo.) 2 ImeDictUpdateService; "C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE" [83312 2010-10-20] (Microsoft Corporation) 2 LENOVO.MICMUTE; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [101736 2011-07-11] (Lenovo Group Limited) 2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation) 3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-11-01] () 3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation) 3 Power Manager DBC Service; "C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE" [87400 2011-08-31] (Lenovo) 3 PwmEWSvc; C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE [173416 2011-08-31] (Lenovo Group Limited) 2 SAService; C:\Windows\SysWow64\SAsrv.exe [446592 2011-01-06] (Conexant Systems, Inc.) 2 SUService; "C:\Program Files (x86)\Lenovo\System Update\SUService.exe" [34104 2012-05-11] (Lenovo Group Limited) 2 TPHKLOAD; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [145256 2011-07-11] (Lenovo Group Limited) 2 TPHKSVC; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [142696 2011-07-11] (Lenovo Group Limited) 2 UNS; "C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe" [2656280 2011-02-21] (Intel Corporation) 2 WMCoreService; C:\Program Files (x86)\Mobile Broadband drivers\WMCore\mini_WMCore.exe servicemode [594984 2011-04-07] (Ericsson AB) ========================== Drivers (Whitelisted) ============= 3 5U877; C:\Windows\System32\Drivers\5U877.sys [166016 2011-03-04] (Ricoh co.,Ltd.) 2 avgntflt; C:\Windows\System32\Drivers\avgntflt.sys [98848 2012-04-24] (Avira GmbH) 1 avipbb; C:\Windows\System32\Drivers\avipbb.sys [132832 2012-04-27] (Avira GmbH) 1 avkmgr; C:\Windows\System32\Drivers\avkmgr.sys [27760 2012-05-02] (Avira GmbH) 3 ecnssndis; C:\Windows\System32\Drivers\wwuss64.sys [26664 2010-02-23] (Ericsson AB) 3 ecnssndisfltr; C:\Windows\System32\Drivers\wwussf64.sys [30248 2010-02-23] (Ericsson AB) 3 l36wgps; C:\Windows\System32\DRIVERS\l36wgps64.sys [101416 2011-02-28] (Ericsson AB) 3 mbamchameleon; C:\Windows\System32\Drivers\mbamchameleon.sys [36168 2012-07-23] () 3 Mbm3CBus; C:\Windows\System32\Drivers\Mbm3CBus.sys [419400 2011-04-13] (MCCI Corporation) 3 Mbm3DevMt; C:\Windows\System32\Drivers\Mbm3DevMt.sys [430664 2011-04-13] (MCCI Corporation) 3 Mbm3mdfl; C:\Windows\System32\Drivers\Mbm3mdfl.sys [19528 2011-04-13] (MCCI Corporation) 3 Mbm3Mdm; C:\Windows\System32\Drivers\Mbm3Mdm.sys [483400 2011-04-13] (MCCI Corporation) 3 TVTI2C; C:\Windows\System32\Drivers\TVTI2C.sys [41536 2009-09-24] (Lenovo (United States) Inc.) 3 WwanUsbServ; C:\Windows\System32\DRIVERS\WwanUsbMp64.sys [286248 2011-04-06] (Ericsson AB) 3 catchme; \??\C:\ComboFix\catchme.sys [x] ========================== NetSvcs (Whitelisted) =========== ============ One Month Created Files and Folders ============== 2012-08-01 00:17 - 2012-08-01 03:49 - 00011754 ____A C:\Users\localuser\Desktop\Ta bort från johanna.xlsx 2012-07-31 00:14 - 2012-07-31 00:14 - 02125312 ____A C:\Users\localuser\Desktop\Whiteboard_jan-maj2012.xls 2012-07-25 07:15 - 2012-07-25 07:16 - 02117108 ____A C:\Users\localuser\Downloads\tdsskiller.zip 2012-07-25 06:27 - 2012-07-25 06:27 - 01080898 ____A C:\Users\localuser\Desktop\Flop Deals.pptx 2012-07-25 06:18 - 2012-07-25 06:18 - 00027016 ____A C:\Users\localuser\Desktop\Danger categories and no-go deals.xlsx 2012-07-24 06:05 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-07-24 06:03 - 2010-02-23 00:16 - 00294912 ____A (Microsoft Corporation) C:\Windows\System32\browserchoice.exe 2012-07-24 06:01 - 2012-06-02 04:12 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-07-24 06:01 - 2012-06-02 04:05 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-07-24 06:01 - 2012-06-02 04:05 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-07-24 06:01 - 2012-06-02 04:04 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-07-24 06:01 - 2012-06-02 04:04 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-07-24 06:01 - 2012-06-02 04:03 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-07-24 06:01 - 2012-06-02 04:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-07-24 06:01 - 2012-06-02 04:00 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-07-24 06:01 - 2012-06-02 03:59 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-07-24 06:01 - 2012-06-02 03:57 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-07-24 06:01 - 2012-06-02 03:57 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-07-24 06:01 - 2012-06-02 03:54 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-07-24 06:01 - 2012-06-02 01:07 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-07-24 06:01 - 2012-06-02 00:33 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-07-24 06:01 - 2012-06-02 00:26 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-07-24 06:01 - 2012-06-02 00:25 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-07-24 06:01 - 2012-06-02 00:25 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-07-24 06:01 - 2012-06-02 00:23 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-07-24 06:01 - 2012-06-02 00:21 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-07-24 06:01 - 2012-06-02 00:20 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-07-24 06:01 - 2012-06-02 00:19 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-07-24 06:01 - 2012-06-02 00:19 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-07-24 06:01 - 2012-06-02 00:17 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-07-24 06:01 - 2012-06-02 00:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-07-24 06:01 - 2012-06-02 00:14 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-07-24 06:00 - 2012-06-02 04:49 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-07-24 06:00 - 2012-06-02 04:17 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-07-24 06:00 - 2012-06-02 00:43 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-07-24 05:59 - 2012-07-24 05:59 - 00027450 ____A C:\ComboFix.txt 2012-07-24 05:48 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe 2012-07-24 05:48 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe 2012-07-24 05:48 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2012-07-24 05:48 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2012-07-24 05:48 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2012-07-24 05:48 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe 2012-07-24 05:48 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe 2012-07-24 05:48 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe 2012-07-24 05:47 - 2012-07-24 05:59 - 00000000 ___AD C:\Qoobox 2012-07-24 05:47 - 2012-07-24 05:57 - 00000000 ____D C:\Windows\erdnt 2012-07-24 05:14 - 2012-07-24 05:13 - 00607260 ____R (Swearware) C:\Users\localuser\Desktop\dds.com 2012-07-23 22:48 - 2012-07-26 23:16 - 00000000 ____D C:\Users\localuser\Desktop\Anti-Malware 2012-07-23 08:41 - 2012-07-23 08:41 - 00036168 ____A C:\Windows\System32\Drivers\mbamchameleon.sys 2012-07-23 08:27 - 2012-07-23 08:32 - 00000000 ____D C:\Program Files (x86)\stinger 2012-07-23 08:27 - 2012-07-23 08:27 - 00016200 ____A (McAfee, Inc.) C:\Windows\stinger.sys 2012-07-23 08:21 - 2012-07-23 08:23 - 00000361 ____A C:\rkill.log 2012-07-23 08:10 - 2012-07-23 23:36 - 00000000 ____D C:\Users\All Users\bomgar-scc-00000000500D775F 2012-07-23 07:02 - 2012-07-23 07:02 - 00000000 ____D C:\Users\localuser\AppData\Roaming\Malwarebytes 2012-07-23 07:01 - 2012-07-23 07:01 - 00000000 ____D C:\Users\All Users\Malwarebytes 2012-07-23 07:01 - 2012-07-23 07:01 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2012-07-23 07:01 - 2012-07-03 03:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2012-07-23 06:45 - 2012-08-01 03:53 - 00000000 ____D C:\Users\All Users\bomgar-scc-00000000500D638B 2012-07-23 04:35 - 2012-07-23 04:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.61A0E60595D2A613 2012-07-23 04:32 - 2012-07-23 04:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBF7920D05432F22 2012-07-23 04:30 - 2012-07-23 04:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FCD386B6264EF27F 2012-07-23 04:27 - 2012-07-23 04:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D7032D9A21253011 2012-07-23 04:24 - 2012-07-23 04:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1AC3F35A94E56C2F 2012-07-23 04:21 - 2012-07-23 04:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7A21BA99F9E3D32B 2012-07-23 04:19 - 2012-07-23 04:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6258B4F78CE415D0 2012-07-23 04:16 - 2012-07-23 04:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8DB816DA51868F45 2012-07-23 04:13 - 2012-07-23 04:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.71A6DE147D9ED3B7 2012-07-23 04:08 - 2012-07-23 04:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DBF0200DF076256F 2012-07-23 04:03 - 2012-07-23 04:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.71ACA87C9F2B809D 2012-07-23 03:59 - 2012-07-23 03:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F79FC5CEA2FEF976 2012-07-23 03:44 - 2012-07-23 03:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D2E28E5F31F3F80B 2012-07-23 03:38 - 2012-07-23 03:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AB44DD300D1FFBDC 2012-07-23 03:34 - 2012-07-23 03:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.37970CA6ED35253E 2012-07-23 03:29 - 2012-07-23 03:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CF3C2F3505C08A10 2012-07-23 03:20 - 2012-07-23 04:35 - 00000000 ____D C:\Program Files\Microsoft Security Client 2012-07-23 03:20 - 2012-07-23 04:35 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client 2012-07-23 03:20 - 2012-07-23 03:20 - 12631936 ____A (Microsoft Corporation) C:\Users\localuser\Downloads\mseinstall(1).exe 2012-07-23 03:18 - 2012-07-23 03:18 - 10297728 ____A (Microsoft Corporation) C:\Users\localuser\Downloads\mseinstall.exe 2012-07-23 01:59 - 2012-07-23 01:59 - 11158744 ____A (Lenovo ) C:\Users\localuser\Downloads\systemupdate43-2012-5-11.exe 2012-07-23 01:59 - 2012-07-23 01:59 - 00000000 ____D C:\Users\localuser\AppData\Roaming\Avira 2012-07-23 01:54 - 2012-07-23 01:54 - 00002081 ____A C:\Users\Public\Desktop\Avira Control Center.lnk 2012-07-23 01:54 - 2012-07-23 01:54 - 00000000 ____D C:\Users\All Users\Avira 2012-07-23 01:54 - 2012-07-23 01:54 - 00000000 ____D C:\Program Files (x86)\Avira 2012-07-23 01:54 - 2012-05-02 05:24 - 00027760 ____A (Avira GmbH) C:\Windows\System32\Drivers\avkmgr.sys 2012-07-23 01:54 - 2012-04-27 00:20 - 00132832 ____A (Avira GmbH) C:\Windows\System32\Drivers\avipbb.sys 2012-07-23 01:54 - 2012-04-24 14:32 - 00098848 ____A (Avira GmbH) C:\Windows\System32\Drivers\avgntflt.sys 2012-07-23 01:52 - 2012-07-23 01:53 - 99218336 ____A C:\Users\localuser\Downloads\avira_free_antivirus_en.exe 2012-07-23 01:49 - 2012-07-23 01:49 - 00603648 ____A (iS3, Inc.) C:\Users\localuser\Downloads\sz-remover.exe 2012-07-22 23:40 - 2012-07-22 23:40 - 00000000 __SHD C:\Windows\System32\%APPDATA% 2012-07-22 23:37 - 2012-08-01 03:05 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2012-07-22 23:07 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2012-07-22 23:07 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2012-07-22 23:07 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll 2012-07-22 23:07 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll 2012-07-22 23:07 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2012-07-22 23:07 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2012-07-22 23:07 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys 2012-07-22 23:07 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys 2012-07-22 23:07 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys 2012-07-22 23:07 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll 2012-07-22 23:07 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2012-07-22 23:07 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2012-07-22 23:07 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2012-07-22 23:07 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2012-07-22 23:07 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2012-07-22 23:07 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll 2012-07-22 23:07 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2012-07-22 23:06 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll 2012-07-22 23:06 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2012-07-16 23:34 - 2012-07-16 23:34 - 00023593 ____A C:\Users\localuser\Desktop\Jonas_Konton.xlsx 2012-07-16 23:32 - 2012-07-16 23:32 - 00028623 ____A C:\Users\localuser\Desktop\Jens_Konton.xlsx 2012-07-16 03:47 - 2012-07-16 03:47 - 00048427 ____A C:\Users\localuser\Downloads\report1342439236470.xls 2012-07-11 06:20 - 2012-07-11 06:20 - 00011942 ____A C:\Users\localuser\Desktop\Activation deals.xlsx 2012-07-11 00:18 - 2012-07-12 05:32 - 00468978 ____A C:\Users\localuser\Desktop\Security Door.pptx 2012-07-10 22:38 - 2012-07-10 22:38 - 00767649 ____A C:\Users\localuser\Desktop\Testimonial - Black Label - Diner - Rijswijk - Restaurant Niven - EN.pptx 2012-07-10 22:06 - 2012-07-10 22:21 - 00551694 ____A C:\Users\localuser\Desktop\Halkkörning.pptx 2012-07-04 04:36 - 2012-07-04 04:36 - 00000652 ____A C:\Users\localuser\Downloads\finished-deal-codes-by-salesforce-report.01650866.csv 2012-07-04 04:36 - 2012-07-04 04:36 - 00000652 ____A C:\Users\localuser\Downloads\finished-deal-codes-by-salesforce-report.01650866(1).csv 2012-07-04 01:16 - 2012-07-04 01:16 - 00029254 ____A C:\Users\localuser\Downloads\finished-deal-codes-by-deal-report.7548471.csv 2012-07-04 01:15 - 2012-07-04 01:15 - 00000000 ____A C:\Users\localuser\Downloads\finished-deal-codes-by-deal-report.7753438.csv 2012-07-04 01:14 - 2012-07-04 01:14 - 00009674 ____A C:\Users\localuser\Downloads\report1341393120271.xls 2012-07-04 01:11 - 2012-07-04 01:11 - 00002951 ____A C:\Users\localuser\Desktop\Microsoft Excel 2010.lnk ============ 3 Months Modified Files ======================== 2012-08-01 03:53 - 2012-03-27 11:23 - 01624950 ____A C:\Windows\WindowsUpdate.log 2012-08-01 03:53 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2012-08-01 03:53 - 2009-07-13 20:51 - 00053041 ____A C:\Windows\setupact.log 2012-08-01 03:50 - 2010-11-20 19:47 - 00455376 ____A C:\Windows\PFRO.log 2012-08-01 03:49 - 2012-08-01 00:17 - 00011754 ____A C:\Users\localuser\Desktop\Ta bort från johanna.xlsx 2012-08-01 03:05 - 2012-07-22 23:37 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2012-07-31 22:06 - 2009-07-13 21:13 - 00782096 ____A C:\Windows\System32\PerfStringBackup.INI 2012-07-31 00:14 - 2012-07-31 00:14 - 02125312 ____A C:\Users\localuser\Desktop\Whiteboard_jan-maj2012.xls 2012-07-29 22:49 - 2009-07-13 20:45 - 00031296 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2012-07-29 22:49 - 2009-07-13 20:45 - 00031296 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2012-07-27 08:05 - 2012-05-08 04:15 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2012-07-27 08:05 - 2012-05-08 04:15 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2012-07-25 07:16 - 2012-07-25 07:15 - 02117108 ____A C:\Users\localuser\Downloads\tdsskiller.zip 2012-07-25 06:27 - 2012-07-25 06:27 - 01080898 ____A C:\Users\localuser\Desktop\Flop Deals.pptx 2012-07-25 06:18 - 2012-07-25 06:18 - 00027016 ____A C:\Users\localuser\Desktop\Danger categories and no-go deals.xlsx 2012-07-24 06:09 - 2009-07-13 20:45 - 00341544 ____A C:\Windows\System32\FNTCACHE.DAT 2012-07-24 06:01 - 2012-05-02 04:02 - 59701280 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2012-07-24 05:59 - 2012-07-24 05:59 - 00027450 ____A C:\ComboFix.txt 2012-07-24 05:55 - 2009-07-13 18:34 - 00000215 ____A C:\Windows\system.ini 2012-07-24 05:13 - 2012-07-24 05:14 - 00607260 ____R (Swearware) C:\Users\localuser\Desktop\dds.com 2012-07-23 08:41 - 2012-07-23 08:41 - 00036168 ____A C:\Windows\System32\Drivers\mbamchameleon.sys 2012-07-23 08:27 - 2012-07-23 08:27 - 00016200 ____A (McAfee, Inc.) C:\Windows\stinger.sys 2012-07-23 08:23 - 2012-07-23 08:21 - 00000361 ____A C:\rkill.log 2012-07-23 04:35 - 2012-07-23 04:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.61A0E60595D2A613 2012-07-23 04:35 - 2012-05-02 04:13 - 00001945 ____A C:\Windows\epplauncher.mif 2012-07-23 04:32 - 2012-07-23 04:32 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.EBF7920D05432F22 2012-07-23 04:30 - 2012-07-23 04:30 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.FCD386B6264EF27F 2012-07-23 04:27 - 2012-07-23 04:27 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D7032D9A21253011 2012-07-23 04:24 - 2012-07-23 04:24 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.1AC3F35A94E56C2F 2012-07-23 04:21 - 2012-07-23 04:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.7A21BA99F9E3D32B 2012-07-23 04:19 - 2012-07-23 04:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.6258B4F78CE415D0 2012-07-23 04:16 - 2012-07-23 04:16 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.8DB816DA51868F45 2012-07-23 04:13 - 2012-07-23 04:13 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.71A6DE147D9ED3B7 2012-07-23 04:08 - 2012-07-23 04:08 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.DBF0200DF076256F 2012-07-23 04:03 - 2012-07-23 04:03 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.71ACA87C9F2B809D 2012-07-23 03:59 - 2012-07-23 03:59 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F79FC5CEA2FEF976 2012-07-23 03:44 - 2012-07-23 03:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.D2E28E5F31F3F80B 2012-07-23 03:38 - 2012-07-23 03:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AB44DD300D1FFBDC 2012-07-23 03:34 - 2012-07-23 03:34 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.37970CA6ED35253E 2012-07-23 03:29 - 2012-07-23 03:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.CF3C2F3505C08A10 2012-07-23 03:20 - 2012-07-23 03:20 - 12631936 ____A (Microsoft Corporation) C:\Users\localuser\Downloads\mseinstall(1).exe 2012-07-23 03:20 - 2012-03-27 11:34 - 00787942 ____A C:\Windows\SysWOW64\PerfStringBackup.INI 2012-07-23 03:18 - 2012-07-23 03:18 - 10297728 ____A (Microsoft Corporation) C:\Users\localuser\Downloads\mseinstall.exe 2012-07-23 01:59 - 2012-07-23 01:59 - 11158744 ____A (Lenovo ) C:\Users\localuser\Downloads\systemupdate43-2012-5-11.exe 2012-07-23 01:54 - 2012-07-23 01:54 - 00002081 ____A C:\Users\Public\Desktop\Avira Control Center.lnk 2012-07-23 01:53 - 2012-07-23 01:52 - 99218336 ____A C:\Users\localuser\Downloads\avira_free_antivirus_en.exe 2012-07-23 01:49 - 2012-07-23 01:49 - 00603648 ____A (iS3, Inc.) C:\Users\localuser\Downloads\sz-remover.exe 2012-07-16 23:34 - 2012-07-16 23:34 - 00023593 ____A C:\Users\localuser\Desktop\Jonas_Konton.xlsx 2012-07-16 23:32 - 2012-07-16 23:32 - 00028623 ____A C:\Users\localuser\Desktop\Jens_Konton.xlsx 2012-07-16 03:47 - 2012-07-16 03:47 - 00048427 ____A C:\Users\localuser\Downloads\report1342439236470.xls 2012-07-12 05:32 - 2012-07-11 00:18 - 00468978 ____A C:\Users\localuser\Desktop\Security Door.pptx 2012-07-11 06:20 - 2012-07-11 06:20 - 00011942 ____A C:\Users\localuser\Desktop\Activation deals.xlsx 2012-07-10 22:38 - 2012-07-10 22:38 - 00767649 ____A C:\Users\localuser\Desktop\Testimonial - Black Label - Diner - Rijswijk - Restaurant Niven - EN.pptx 2012-07-10 22:21 - 2012-07-10 22:06 - 00551694 ____A C:\Users\localuser\Desktop\Halkkörning.pptx 2012-07-04 04:36 - 2012-07-04 04:36 - 00000652 ____A C:\Users\localuser\Downloads\finished-deal-codes-by-salesforce-report.01650866.csv 2012-07-04 04:36 - 2012-07-04 04:36 - 00000652 ____A C:\Users\localuser\Downloads\finished-deal-codes-by-salesforce-report.01650866(1).csv 2012-07-04 01:16 - 2012-07-04 01:16 - 00029254 ____A C:\Users\localuser\Downloads\finished-deal-codes-by-deal-report.7548471.csv 2012-07-04 01:15 - 2012-07-04 01:15 - 00000000 ____A C:\Users\localuser\Downloads\finished-deal-codes-by-deal-report.7753438.csv 2012-07-04 01:14 - 2012-07-04 01:14 - 00009674 ____A C:\Users\localuser\Downloads\report1341393120271.xls 2012-07-04 01:11 - 2012-07-04 01:11 - 00002951 ____A C:\Users\localuser\Desktop\Microsoft Excel 2010.lnk 2012-07-03 03:46 - 2012-07-23 07:01 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2012-06-21 01:50 - 2012-06-19 04:03 - 01101048 ____A C:\Users\localuser\Desktop\testimonial_BS.pptx 2012-06-15 03:40 - 2012-06-15 03:40 - 00024576 ____A C:\Users\localuser\Downloads\Toki Drobnjakovic.xls 2012-06-12 09:11 - 2012-06-12 04:57 - 00011983 ____A C:\Users\localuser\Desktop\Hotell med restauranger_inkl._restauranglänker.xlsx 2012-06-11 19:08 - 2012-07-24 06:05 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-06-08 21:43 - 2012-07-22 23:07 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2012-06-08 20:41 - 2012-07-22 23:07 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2012-06-05 22:06 - 2012-07-22 23:07 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll 2012-06-05 22:06 - 2012-07-22 23:07 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll 2012-06-05 22:02 - 2012-07-22 23:06 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll 2012-06-05 21:05 - 2012-07-22 23:07 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2012-06-05 21:05 - 2012-07-22 23:07 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2012-06-05 21:03 - 2012-07-22 23:06 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2012-06-05 08:54 - 2012-06-05 06:17 - 00017407 ____A C:\Users\localuser\Desktop\Golf_konton_Sverige.xlsx 2012-06-05 00:10 - 2012-06-05 00:10 - 00717416 ____A C:\Users\localuser\Desktop\TRO20120522.pptx 2012-06-04 00:01 - 2012-06-04 00:01 - 00014562 ____A C:\Users\localuser\Desktop\shopping_Local.xlsx 2012-06-02 14:19 - 2012-06-20 22:29 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2012-06-02 14:19 - 2012-06-20 22:29 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2012-06-02 14:19 - 2012-06-20 22:29 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2012-06-02 14:19 - 2012-06-20 22:29 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll 2012-06-02 14:19 - 2012-06-20 22:29 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll 2012-06-02 14:15 - 2012-06-20 22:29 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2012-06-02 14:15 - 2012-06-20 22:29 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2012-06-02 05:19 - 2012-06-20 22:29 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2012-06-02 05:15 - 2012-06-20 22:29 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2012-06-02 04:49 - 2012-07-24 06:00 - 17807360 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-06-02 04:17 - 2012-07-24 06:00 - 10924032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-06-02 04:12 - 2012-07-24 06:01 - 02311680 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-06-02 04:05 - 2012-07-24 06:01 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-06-02 04:05 - 2012-07-24 06:01 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-06-02 04:04 - 2012-07-24 06:01 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-06-02 04:04 - 2012-07-24 06:01 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-06-02 04:03 - 2012-07-24 06:01 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-06-02 04:01 - 2012-07-24 06:01 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-06-02 04:00 - 2012-07-24 06:01 - 00818688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-06-02 03:59 - 2012-07-24 06:01 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-06-02 03:57 - 2012-07-24 06:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-06-02 03:57 - 2012-07-24 06:01 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-06-02 03:54 - 2012-07-24 06:01 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-06-02 01:07 - 2012-07-24 06:01 - 12314624 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-06-02 00:43 - 2012-07-24 06:00 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-06-02 00:33 - 2012-07-24 06:01 - 01800192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-06-02 00:26 - 2012-07-24 06:01 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-06-02 00:25 - 2012-07-24 06:01 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-06-02 00:25 - 2012-07-24 06:01 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-06-02 00:23 - 2012-07-24 06:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-06-02 00:21 - 2012-07-24 06:01 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-06-02 00:20 - 2012-07-24 06:01 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-06-02 00:19 - 2012-07-24 06:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-06-02 00:19 - 2012-07-24 06:01 - 00716800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-06-02 00:17 - 2012-07-24 06:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-06-02 00:16 - 2012-07-24 06:01 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-06-02 00:14 - 2012-07-24 06:01 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-06-01 21:50 - 2012-07-22 23:07 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys 2012-06-01 21:48 - 2012-07-22 23:07 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys 2012-06-01 21:48 - 2012-07-22 23:07 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys 2012-06-01 21:45 - 2012-07-22 23:07 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll 2012-06-01 21:44 - 2012-07-22 23:07 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2012-06-01 20:40 - 2012-07-22 23:07 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2012-06-01 20:40 - 2012-07-22 23:07 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2012-06-01 20:39 - 2012-07-22 23:07 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2012-06-01 20:34 - 2012-07-22 23:07 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2012-06-01 04:23 - 2012-06-01 04:23 - 00026238 ____A C:\Users\localuser\Desktop\Provision 2012-04-05.xlsm 2012-06-01 04:22 - 2012-06-01 04:22 - 00025934 ____A C:\Users\localuser\Downloads\Provision 2012-04-05.xlsm 2012-06-01 04:21 - 2012-06-01 04:21 - 00054206 ____A C:\Users\localuser\Desktop\Snurran_2012-05-24 - Gdocs.xlsm 2012-06-01 03:18 - 2012-06-01 03:18 - 00054010 ____A C:\Users\localuser\Downloads\Snurran_2012-05-24 - Gdocs.xlsm 2012-05-25 08:15 - 2012-05-24 04:23 - 00079121 ____A C:\Users\localuser\Desktop\previous_partners_without_running_deals.xlsx 2012-05-25 08:15 - 2012-05-24 03:58 - 06575626 ____A C:\Users\localuser\Desktop\Copy of Giltiga deals.xlsx 2012-05-24 22:35 - 2012-05-08 01:03 - 00001042 ____A C:\Users\localuser\Desktop\Dropbox.lnk 2012-05-22 09:32 - 2012-05-22 06:38 - 00717307 ____A C:\Users\localuser\Desktop\Rollout_mall - Copy.pptx 2012-05-22 00:55 - 2012-05-22 00:55 - 39483256 ____A (Apple Inc.) C:\Users\localuser\Downloads\QuickTimeInstaller.exe 2012-05-21 03:08 - 2012-05-21 03:09 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2012-05-21 03:08 - 2012-05-21 03:09 - 00174024 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2012-05-21 03:08 - 2012-05-21 03:08 - 00892360 ____A (Oracle Corporation) C:\Users\localuser\Downloads\jxpiinstall.exe 2012-05-15 21:55 - 2012-05-08 08:13 - 00633326 ____A C:\Users\localuser\Desktop\Rollout_mall.pptx 2012-05-15 00:29 - 2012-05-15 00:29 - 00012934 ____A C:\Users\localuser\Downloads\report1337070563082.xls 2012-05-08 22:00 - 2012-05-08 21:59 - 16697344 ____A C:\Users\localuser\Downloads\atmcns.msi 2012-05-08 06:01 - 2012-05-08 06:01 - 00012749 ____N C:\Users\localuser\Desktop\Copy of TOP 50 local categories Sweden.xlsx 2012-05-08 04:16 - 2012-05-08 04:16 - 08045936 ____A C:\Users\localuser\Downloads\jing_setup(1).exe 2012-05-08 04:08 - 2012-05-08 04:08 - 08045936 ____A C:\Users\localuser\Downloads\jing_setup.exe 2012-05-08 01:00 - 2012-05-08 01:00 - 18154528 ____A (Dropbox, Inc.) C:\Users\localuser\Downloads\Dropbox 1.4.0.exe 2012-05-07 23:35 - 2012-05-07 23:35 - 00001145 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk 2012-05-07 23:26 - 2012-05-07 23:26 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk 2012-05-04 03:06 - 2012-06-13 22:15 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2012-05-04 02:03 - 2012-06-13 22:15 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2012-05-04 02:03 - 2012-06-13 22:15 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe ZeroAccess: C:\Windows\Installer\{d8014164-3546-6ede-ae8d-4a8662a67314} C:\Windows\Installer\{d8014164-3546-6ede-ae8d-4a8662a67314}\U ZeroAccess: C:\Users\localuser\AppData\Local\{d8014164-3546-6ede-ae8d-4a8662a67314} C:\Users\localuser\AppData\Local\{d8014164-3546-6ede-ae8d-4a8662a67314}\@ C:\Users\localuser\AppData\Local\{d8014164-3546-6ede-ae8d-4a8662a67314}\L C:\Users\localuser\AppData\Local\{d8014164-3546-6ede-ae8d-4a8662a67314}\U ========================= Known DLLs (Whitelisted) ============ ========================= Bamital & volsnap Check ============ C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!. C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\…\.exe: exefile => OK HKLM\…\exefile\DefaultIcon: %1 => OK HKLM\…\exefile\open\command: "%1" %* => OK ========================= Memory info ====================== Percentage of memory in use: 21% Total physical RAM: 4009.98 MB Available physical RAM: 3165.34 MB Total Pagefile: 4008.18 MB Available Pagefile: 3163.39 MB Total Virtual: 8192 MB Available Virtual: 8191.9 MB ======================= Partitions ========================= 1 Drive c: (Windows7_OS) (Fixed) (Total:281 GB) (Free:232.43 GB) NTFS ==>[System with boot components (obtained from reading drive)] 2 Drive e: (Lenovo_Recovery) (Fixed) (Total:15.62 GB) (Free:2.3 GB) NTFS 3 Drive f: () (Removable) (Total:30.44 GB) (Free:30.44 GB) FAT32 4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS 5 Drive y: (SYSTEM_DRV) (Fixed) (Total:1.46 GB) (Free:1.11 GB) NTFS ==>[System with boot components (obtained from reading drive)] Disk ### Status Size Free Dyn Gpt ——– ————- ——- ——- — — Disk 0 Online 298 GB 0 B Disk 1 Online 30 GB 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 1500 MB 1024 KB Partition 2 Primary 280 GB 1501 MB Partition 3 Primary 15 GB 282 GB ================================================================================ == Disk: 0 Partition 1 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 0 Y SYSTEM_DRV NTFS Partition 1500 MB Healthy ================================================================================ == Disk: 0 Partition 2 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 1 C Windows7_OS NTFS Partition 280 GB Healthy ================================================================================ == Disk: 0 Partition 3 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 E Lenovo_Reco NTFS Partition 15 GB Healthy ================================================================================ == Partitions of Disk 1: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 30 GB 18 MB ================================================================================ == Disk: 1 Partition 1 Type : 0C Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 3 F FAT32 Removable 30 GB Healthy ================================================================================ == ========================================================== Last Boot: 2012-07-30 02:16 ======================= End Of Log ==========================
Hi,

In Vista or Windows 7: Boot to System Recovery Options and run FRST.
Type the following in the edit box after "Search:"

services.exe


It should look like:

Search: services.exe

Click Search button and post the log (Search.txt) it makes to your reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI