This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My first BSOD... Windows 7 trying to fix myself [Solved]

74 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Bad news Jeff. The computer does not like what you instructed me to do. I followed the procedures you outlined… created a text file called CFScript.txt with the text you specified pasted and saved….. dragged it onto combofix and it launches.. It reaches stage 4 or stage 3 and it goes into BSOD… Everytime. I tried it about five times and it was obvious it wasn't going to do it. :pullhair: What do you suggest I do? Any more tools in your bag? Thanks again.. Anxiously expecting what your next plan of attaack is going to be. One bright note… the computer stays on without crashing. I left it on all day today and it went into energy save mode. I push the power button and it is right there waiting to hit the user button. It just doesn't like what you are doing to it. :unsure:
Bad news Jeff. The computer does not like what you instructed me to do. I followed the procedures you outlined… created a text file called CFScript.txt with the text you specified pasted nd saved….. dragged it onto combofix and it launches.. It reaches stage 4 or stage 3 and it goes into BSOD… Everytime. I tried it about five times and it was obvious it waasn't going to do it. :pullhair: What do you suggest I do? Any more tools in your bag? Thanks again.. Anxiously expecting what your next plan of attaack is going to be. On a good note… The computer stays runnung without crashing now. I left it on all day and no problem yet. It just doesn't like what we are doing to it. :huh:
Oops sorry didn't realize you sent a new post. I'll try to do it in safe mode tomorrow. Got to work tomorrow so sleep time. Thanks again
Ok. Machine is still running. No BSOD since I was trying to run the ComboFix Script file. Ran the Script in Safe Mode. Here is the log from that run: ComboFix 12-08-20.02 - Manuel 08/21/2012 12:27:51.6.2 - x64 NETWORK Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4056.3322 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Manuel\Desktop\CFScript.txt AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . FILE :: "c:\program files (x86)\RegCure\RegCure.exe" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\RegCure\RegCure.exe c:\users\Manuel\AppData\Roaming\inst.exe c:\users\Manuel\AppData\Roaming\vso_ts_preview.xml c:\windows\svchost.exe c:\windows\SysWow64\aplib.dll . . ((((((((((((((((((((((((( Files Created from 2012-07-21 to 2012-08-21 ))))))))))))))))))))))))))))))) . . 2012-08-21 17:41 . 2012-08-21 17:41 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-08-19 14:53 . 2012-07-03 18:46 24904 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-08-19 03:21 . 2012-08-19 03:21 31080 —-a-w- c:\windows\system32\drivers\avgtpx64.sys 2012-08-19 03:21 . 2012-08-19 03:21 ——– d—–w- c:\program files (x86)\AVG Secure Search 2012-08-19 03:19 . 2012-08-21 13:27 ——– d—–w- c:\windows\system32\drivers\AVG 2012-08-19 03:13 . 2012-07-16 07:40 9133488 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8B620935-52B6-4707-9D20-A83CDCE0E351}\mpengine.dll 2012-08-19 03:00 . 2012-08-19 14:53 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-08-19 02:58 . 2012-08-19 04:23 ——– d—–w- C:\AntiVirus 2012-08-19 00:22 . 2012-08-19 00:22 ——– d—–w- c:\users\Manuel\AppData\Roaming\AVG2012 2012-08-19 00:20 . 2012-08-19 00:20 ——– d—–w- c:\users\Manuel\AppData\Local\AVG Secure Search 2012-08-19 00:20 . 2012-08-19 00:20 ——– d—–w- c:\programdata\AVG Secure Search 2012-08-19 00:20 . 2012-08-19 03:21 ——– d—–w- c:\program files (x86)\Common Files\AVG Secure Search 2012-08-19 00:17 . 2012-08-19 18:06 ——– d—–w- c:\programdata\AVG2012 2012-08-19 00:17 . 2012-08-19 00:17 ——– d—–w- C:\$AVG 2012-08-19 00:02 . 2012-08-21 13:27 ——– d—–w- c:\programdata\MFAData 2012-08-19 00:02 . 2012-08-19 00:02 ——– d–h–w- c:\programdata\Common Files 2012-08-18 23:53 . 2012-08-19 05:55 ——– d—–w- c:\program files (x86)\Common Files\Java 2012-08-18 23:53 . 2012-08-18 23:53 477168 —-a-w- c:\windows\SysWow64\npdeployJava1.dll 2012-08-18 04:19 . 2012-08-18 04:19 ——– d—–w- c:\windows\Sun 2012-08-12 14:45 . 2012-08-18 04:42 ——– d—–w- c:\program files (x86)\SopCast 2012-07-23 01:46 . 2012-08-19 05:55 ——– d—–w- c:\program files (x86)\Common Files\ParetoLogic 2012-07-23 01:46 . 2012-07-23 01:46 ——– d—–w- c:\programdata\ParetoLogic . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-08-19 08:02 . 2009-10-25 03:20 62134624 —-a-w- c:\windows\system32\MRT.exe 2012-08-19 03:08 . 2012-06-22 04:50 426184 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-08-19 03:08 . 2011-06-08 02:09 70344 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-18 23:53 . 2011-03-27 02:01 473072 —-a-w- c:\windows\SysWow64\deployJava1.dll 2012-06-28 16:07 . 2009-07-14 02:36 175616 —-a-w- c:\windows\system32\msclmd.dll 2012-06-28 16:07 . 2009-07-14 02:36 152576 —-a-w- c:\windows\SysWow64\msclmd.dll 2012-06-21 23:51 . 2012-06-21 23:51 499712 —-a-w- c:\windows\SysWow64\msvcp71.dll 2012-06-21 23:51 . 2012-06-21 23:51 348160 —-a-w- c:\windows\SysWow64\msvcr71.dll 2012-06-09 05:43 . 2012-07-11 20:42 14172672 —-a-w- c:\windows\system32\shell32.dll 2012-06-06 06:06 . 2012-07-11 20:42 2004480 —-a-w- c:\windows\system32\msxml6.dll 2012-06-06 06:06 . 2012-07-11 20:42 1881600 —-a-w- c:\windows\system32\msxml3.dll 2012-06-06 06:02 . 2012-07-11 20:39 1133568 —-a-w- c:\windows\system32\cdosys.dll 2012-06-06 05:05 . 2012-07-11 20:42 1390080 —-a-w- c:\windows\SysWow64\msxml6.dll 2012-06-06 05:05 . 2012-07-11 20:42 1236992 —-a-w- c:\windows\SysWow64\msxml3.dll 2012-06-06 05:03 . 2012-07-11 20:39 805376 —-a-w- c:\windows\SysWow64\cdosys.dll 2012-06-02 22:19 . 2012-06-22 04:46 38424 —-a-w- c:\windows\system32\wups.dll 2012-06-02 22:19 . 2012-06-22 04:46 2428952 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-02 22:19 . 2012-06-22 04:46 57880 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2012-06-22 04:46 44056 —-a-w- c:\windows\system32\wups2.dll 2012-06-02 22:19 . 2012-06-22 04:46 701976 —-a-w- c:\windows\system32\wuapi.dll 2012-06-02 22:15 . 2012-06-22 04:46 2622464 —-a-w- c:\windows\system32\wucltux.dll 2012-06-02 22:15 . 2012-06-22 04:46 99840 —-a-w- c:\windows\system32\wudriver.dll 2012-06-02 20:19 . 2012-06-22 04:45 186752 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-02 20:15 . 2012-06-22 04:45 36864 —-a-w- c:\windows\system32\wuapp.exe 2012-06-02 05:50 . 2012-07-11 20:42 458704 —-a-w- c:\windows\system32\drivers\cng.sys 2012-06-02 05:48 . 2012-07-11 20:42 95600 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2012-06-02 05:48 . 2012-07-11 20:42 151920 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2012-06-02 05:45 . 2012-07-11 20:42 340992 —-a-w- c:\windows\system32\schannel.dll 2012-06-02 05:44 . 2012-07-11 20:42 307200 —-a-w- c:\windows\system32\ncrypt.dll 2012-06-02 04:40 . 2012-07-11 20:42 22016 —-a-w- c:\windows\SysWow64\secur32.dll 2012-06-02 04:40 . 2012-07-11 20:42 225280 —-a-w- c:\windows\SysWow64\schannel.dll 2012-06-02 04:39 . 2012-07-11 20:42 219136 —-a-w- c:\windows\SysWow64\ncrypt.dll 2012-06-02 04:34 . 2012-07-11 20:42 96768 —-a-w- c:\windows\SysWow64\sspicli.dll 2012-05-31 17:25 . 2009-10-27 01:23 279656 ——w- c:\windows\system32\MpSigStub.exe . . ((((((((((((((((((((((((((((( SnapShot@2012-08-19_23.36.05 ))))))))))))))))))))))))))))))))))))))))) . + 2012-08-19 00:06 . 2012-08-21 12:31 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData\index.dat - 2012-08-19 00:06 . 2012-08-19 21:36 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData\index.dat + 2012-08-20 08:04 . 2012-08-20 07:50 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012012082020120821\index.dat + 2012-08-20 08:04 . 2012-08-20 07:50 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012012081320120820\index.dat + 2012-08-20 12:42 . 2012-08-21 00:51 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{7477D84E-EAC4-11E1-9D59-00256461FE7E}.dat + 2012-08-20 11:29 . 2012-08-21 00:51 25088 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{4CBB2A93-EABA-11E1-9D59-00256461FE7E}.dat - 2012-08-18 23:42 . 2012-08-19 21:36 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat + 2012-08-18 23:42 . 2012-08-21 17:43 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat + 2009-09-27 11:55 . 2012-08-21 17:44 55922 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10 . 2012-08-21 17:44 43070 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2009-10-25 03:17 . 2012-08-21 17:44 16592 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-619968354-1771590295-360577582-1001_UserData.bin + 2009-07-14 04:46 . 2012-08-21 01:09 94000 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat + 2012-08-20 11:29 . 2012-08-20 12:42 5632 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{4CBB2A92-EABA-11E1-9D59-00256461FE7E}.dat - 2012-08-19 23:33 . 2012-08-19 23:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-08-21 17:42 . 2012-08-21 17:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-08-21 17:42 . 2012-08-21 17:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2012-08-19 23:33 . 2012-08-19 23:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2010-01-22 09:17 . 2012-08-19 23:37 262144 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat + 2010-01-22 09:17 . 2012-08-21 17:45 262144 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat + 2009-07-14 04:54 . 2012-08-21 17:45 163840 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2012-08-19 23:37 163840 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-10-25 00:13 . 2012-08-21 17:10 341320 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin - 2009-07-14 02:36 . 2012-08-19 08:03 633180 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2012-08-20 02:51 633180 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2012-08-20 02:51 110782 c:\windows\system32\perfc009.dat - 2009-07-14 02:36 . 2012-08-19 08:03 110782 c:\windows\system32\perfc009.dat - 2009-07-14 05:01 . 2012-08-19 23:32 324324 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 05:01 . 2012-08-21 17:14 324324 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 04:54 . 2012-08-21 17:43 7094272 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2012-03-15 08:20 . 2012-08-19 23:32 1566920 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-619968354-1771590295-360577582-1001-8192.dat + 2012-03-15 08:20 . 2012-08-21 17:14 1566920 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-619968354-1771590295-360577582-1001-8192.dat - 2012-03-15 08:20 . 2012-08-19 23:32 8776748 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-619968354-1771590295-360577582-1001-4096.dat + 2012-03-15 08:20 . 2012-08-21 17:14 8776748 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-619968354-1771590295-360577582-1001-4096.dat + 2012-08-18 04:49 . 2012-08-21 17:14 2902224 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-18-16384.dat + 2009-07-14 04:54 . 2012-08-21 17:43 16187392 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] 2012-08-19 03:21 2045024 —-a-w- c:\program files (x86)\AVG Secure Search\12.2.0.5\AVG Secure Search_toolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG Secure Search\12.2.0.5\AVG Secure Search_toolbar.dll" [2012-08-19 2045024] . [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="c:\program files (x86)\Yahoo!\Messenger\YahooMessenger.exe" [2010-04-29 5248312] "avichannel"="c:\program files (x86)\Evaer\videochannel.exe" [2011-07-29 1689088] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "PDVDDXSrv"="c:\program files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520] "Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-06-24 409744] "Desktop Disc Tool"="c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2009-06-19 494064] "DellSupportCenter"="c:\program files (x86)\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064] "Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232] "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-12 640376] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-03-18 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-03-26 142120] "CloneCDTray"="c:\program files (x86)\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 57344] "QuickFinder Scheduler"="c:\program files (x86)\Corel\WordPerfect Office X5\Programs\QFSCHD150.EXE" [2010-03-12 136600] "TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2012-06-21 296056] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "AVG_TRAY"="c:\program files (x86)\AVG\AVG2012\avgtray.exe" [2012-04-05 2587008] "vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2012-08-19 1162848] "ROC_roc_ssl_v12"="c:\program files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" [2012-08-19 1020512] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] "c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"="c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [2011-10-09 559616] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-6-30 1316192] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2012\avgrsa.exe /sync /restart . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-21 136176] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-08 160944] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-19 250056] R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys [2010-07-01 51600] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-21 136176] R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2010-07-21 45456] R3 SUSTUCAM;Susteen USB Cable Modem Driver;c:\windows\system32\DRIVERS\sustucam.sys [2009-11-25 56832] R3 SUSTUCAP;Susteen USB Cable Port Driver;c:\windows\system32\DRIVERS\sustucap.sys [2009-11-25 56832] R3 SUSTUCAU;Susteen USB Cable USB Driver;c:\windows\system32\DRIVERS\sustucau.sys [2009-11-25 33792] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2009-10-16 50176] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-13 1255736] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2008-05-06 14464] S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [2012-04-19 28480] S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2012-01-31 36944] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280] S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2012-02-22 289872] S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2011-12-23 47696] S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2012-03-19 383808] S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys [2012-08-19 31080] S1 sbtis;sbtis;c:\windows\system32\drivers\sbtis.sys [2008-10-09 82480] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2012\avgidsagent.exe [2012-07-04 5160568] S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-02-14 193288] S2 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-10-21 196176] S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-10-13 249648] S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-12-18 155648] S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.exe [2011-08-18 1692480] S2 vToolbarUpdater12.2.0;vToolbarUpdater12.2.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.0\ToolbarUpdater.exe [2012-08-19 927840] S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [2011-12-23 124496] S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\avgidsfiltera.sys [2011-12-23 29776] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2009-06-15 172704] S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2009-12-25 82816] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-05-08 215552] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-09-28 395264] . . Contents of the 'Scheduled Tasks' folder . 2012-08-21 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-22 03:08] . 2012-08-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-21 23:55] . 2012-08-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-21 23:55] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-01-23 305664] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-06-29 444416] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-06-30 165912] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-06-30 385560] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-06-30 365080] "Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4968960] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-21 2327952] "MRT"="c:\windows\system32\MRT.exe" [2012-08-19 62134624] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.yahoo.com/ mStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm IE: Copy to &Lightning Note - c:\program files (x86)\Corel\WordPerfect Lightning\Programs\WPLightningCopyToNote.hta IE: Open with WordPerfect - c:\program files (x86)\Corel\WordPerfect Office X5\Programs\WPLauncher.hta Trusted Zone: intuit.com\ttlc TCP: DhcpNameServer = 192.168.254.254 Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.0\ViProtocol.dll FF - ProfilePath - c:\users\Manuel\AppData\Roaming\Mozilla\Firefox\Profiles\kp6s54a2.default\ FF - prefs.js: network.proxy.type - 0 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Toolbar-{aac55042-b985-4a23-a4c9-3ba84830ef84} - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions] @Denied: (2) (LocalSystem) "{259F616C-A300-44F5-B04A-ED001A26C85C}"=hex:51,66,7a,6c,4c,1d,38,12,02,62,8c, 21,32,ed,9b,01,cf,5c,ae,40,1f,78,8c,48 "{47833539-D0C5-4125-9FA8-0819E2EAAC93}"=hex:51,66,7a,6c,4c,1d,38,12,57,36,90, 43,f7,9e,4b,04,e0,be,4b,59,e7,b4,e8,87 "{8DCB7100-DF86-4384-8842-8FA844297B3F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,72,d8, 89,b4,91,ea,06,f7,54,cc,e8,41,77,3f,2b "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b, 27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b "{95B7759C-8C7F-4BF1-B163-73684A933233}"=hex:51,66,7a,6c,4c,1d,38,12,f2,76,a4, 91,4d,c2,9f,0e,ce,75,30,28,4f,cd,76,27 "{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc, 1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7 "{3049C3E9-B461-4BC5-8870-4C09146192CA}"=hex:51,66,7a,6c,4c,1d,38,12,87,c0,5a, 34,53,fa,ab,0e,f7,66,0f,49,11,3f,d6,de "{31332EEF-CB9F-458F-AFEB-D30E9A66B6BA}"=hex:51,66,7a,6c,4c,1d,38,12,81,2d,20, 35,ad,85,e1,00,d0,fd,90,4e,9f,38,f2,ae "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07, 72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57 "{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b, ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3 "{AE7CD045-E861-484F-8273-0445EE161910}"=hex:51,66,7a,6c,4c,1d,38,12,2b,d3,6f, aa,53,a6,21,0d,fd,65,47,05,eb,48,5d,04 "{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93, aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83 "{D2CE3E00-F94A-4740-988E-03DC2F38C34F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,3d,dd, d6,78,b7,2e,02,e7,98,40,9c,2a,66,87,5b "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db, df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd "{F4971EE7-DAA0-4053-9964-665D8EE6A077}"=hex:51,66,7a,6c,4c,1d,38,12,89,1d,84, f0,92,94,3d,05,e6,72,25,1d,8b,b8,e4,63 "{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16, fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17 "{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9, b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] @Denied: (2) (LocalSystem) "Timestamp"=hex:c3,05,fc,ad,dd,7d,cd,01 . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.032" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.abr" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.ani" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.apd\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.apd" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.arw" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.bay" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.bmp" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.bw" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bwf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.bwf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.cr2" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.crw" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.cs1" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.cur" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.dcr" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.dcx" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.dib" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.djv" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.djvu" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.dng" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.emf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.eps" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.erf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.fff" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flc\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.flc" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fli\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.fli" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.fpx" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.gif" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.hdr" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.icl" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.icn" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.iff" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ilbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.ilbm" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.int\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.int" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inta\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.inta" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.iw4" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.j2c" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.j2k" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jbr" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jfif" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jif" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jp2" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jpc" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jpe" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jpeg" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jpg" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jpk" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.jpx" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kar\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.kar" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.kdc" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.lbm" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m15\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.m15" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1a\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.m1a" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2a\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.m2a" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m75\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.m75" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.mef" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.mos" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.mpv" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.mrw" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.nef" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nrw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.nrw" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.orf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pbm" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pbr" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pcd" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pct" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pcx" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pef" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pgm" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pic" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pics\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pics" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pict" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pix\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pix" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.png" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.ppm" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.psd" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.psp" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pspbrush" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.pspimage" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qtpf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.qtpf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.raf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.ras" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.raw" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgb\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.rgb" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgba\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.rgba" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.rle" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsb\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.rsb" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rw2\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.rw2" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rwl\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.rwl" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sdv\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.sdv" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sfil\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.sfil" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.sgi" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.smf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.sml" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.sr2" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.srf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.swa\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.swa" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.tga" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.thm" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.tif" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.tiff" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.ttc" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.ttf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ulw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.ulw" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30po\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.v30po" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30pp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.v30pp" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v30ppf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.v30ppf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vfw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.vfw" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.wbm" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.wbmp" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.wmf" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.xbm" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.xif" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.xmp" . [HKEY_USERS\S-1-5-21-619968354-1771590295-360577582-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee Pro 3.xpm" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe c:\program files (x86)\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe c:\program files (x86)\Dell DataSafe Local Backup\TOASTER.EXE c:\program files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe c:\program files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe c:\\.\globalroot\systemroot\svchost.exe c:\program files (x86)\Dell Support Center\bin\sprtsvc.exe . ************************************************************************** . Completion time: 2012-08-21 12:57:13 - machine was rebooted ComboFix-quarantined-files.txt 2012-08-21 17:57 ComboFix2.txt 2012-08-19 23:49 . Pre-Run: 35,019,821,056 bytes free Post-Run: 34,895,773,696 bytes free . - - End Of File - - 654BB43FEE364CD66E3056ADC9E8A307 Let me know what you think. Thanks
Jeff, I am now getting the following message: Do you want the following program to make changes to the computer? Program Name: Microsoft Windows Malicious Software removal tool Verified Publisher: Microsoft Windows Program Location: C:\windows\System32\MRT.exe"/R/RE Is this legitimate? I keep answereing no. What do you suggest about this?
It is legit but don't allow it right now.
–

Malwarebytes

I see that you have Malwarebytes already on your computer. Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

Go here to run an online scannner from ESET.
Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
———-
Here they are Jeff. Fist Malwarebyte log: Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.08.21.13 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Manuel :: MANUEL-PC [administrator] 8/21/2012 9:34:33 PM mbam-log-2012-08-22 (00-19-32).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 212087 Time elapsed: 5 minute(s), 3 second(s) Memory Processes Detected: 1 C:\Windows\svchost.exe (Trojan.Agent) -> 7876 -> No action taken. Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 C:\Windows\svchost.exe (Trojan.Agent) -> No action taken. (end) Next the Eset Log: C:\Downloads\ud_hjsplit_24.exe a variant of Win32/SoftonicDownloader.A application C:\Program Files (x86)\Dell DataSafe Local Backup\hstart.exe a variant of Win32/HiddenStart.A application C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe a variant of Win32/HiddenStart.A application C:\Program Files (x86)\PDF Password Remover v3.1\winDecrypt.exe probably a variant of Win32/PSWTool.PdfCracker.A application C:\Users\Manuel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\QuickStores.lnk Win32/Adware.ADON application C:\Users\Manuel\AppData\Roaming\Microsoft\Windows\Start Menu\QuickStores.lnk Win32/Adware.ADON application C:\Users\Manuel\Desktop\QuickStores.lnk Win32/Adware.ADON application C:\Users\Manuel\Downloads\Unlocker1.9.1.exe a variant of Win32/Toolbar.Babylon application Well, seems that the system is not doing the BSOD on me as before. I'll keep malware bytes open and waiting to delete the svchost. Let me know what the next thing is to do. Thanks
FRST

For 32 bit systems, download Farbar Recovery Scan Tool and save it to a flash drive.
For 64 bit systems, download Farbar Recovery Scan Tool64 and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

OK Jeff got that done. Here is the Farbar scan log. Thanks again. Good instructions. Scan result of Farbar Recovery Scan Tool Version: 22-08-2012 Ran by [removed] at 22-08-2012 16:06:14 Running from G:\ Windows 7 Home Premium (X64) OS Language: English(US) The current controlset is ControlSet001 ========================== Registry (Whitelisted) ============= HKLM\…\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe [305664 2009-01-22] (Alps Electric Co., Ltd.) HKLM\…\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe [444416 2009-06-28] (IDT, Inc.) HKLM\…\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [165912 2009-06-30] (Intel Corporation) HKLM\…\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [385560 2009-06-30] (Intel Corporation) HKLM\…\Run: [Persistence] C:\Windows\system32\igfxpers.exe [365080 2009-06-30] (Intel Corporation) HKLM\…\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [4968960 2009-07-16] (Dell Inc.) HKLM\…\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation) HKLM\…\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2327952 2010-07-21] (Microsoft Corporation) HKLM\…\Run: [MRT] "C:\Windows\system32\MRT.exe" /R [62134624 2012-08-19] (Microsoft Corporation) HKLM-x32\…\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35696 2009-02-27] (Adobe Systems Incorporated) HKLM-x32\…\Run: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [140520 2009-06-24] (CyberLink Corp.) HKLM-x32\…\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2 [409744 2009-06-24] (Creative Technology Ltd) HKLM-x32\…\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [494064 2009-06-18] () HKLM-x32\…\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter [206064 2009-05-21] (SupportSoft, Inc.) HKLM-x32\…\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [37232 2008-06-12] (Adobe Systems Incorporated) HKLM-x32\…\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [640376 2008-06-11] (Adobe Systems Inc.) HKLM-x32\…\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2010-03-17] (Apple Inc.) HKLM-x32\…\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [142120 2010-03-26] (Apple Inc.) HKLM-x32\…\Run: [CloneCDTray] "C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s [57344 2006-09-28] (SlySoft, Inc.) HKLM-x32\…\Run: [QuickFinder Scheduler] "c:\Program Files (x86)\Corel\WordPerfect Office X5\Programs\QFSCHD150.EXE" [136600 2010-03-11] (Corel Corporation) HKLM-x32\…\Run: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot [296056 2012-06-21] (RealNetworks, Inc.) HKLM-x32\…\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2012-01-18] (Sun Microsystems, Inc.) HKLM-x32\…\Run: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" [2587008 2012-04-05] (AVG Technologies CZ, s.r.o.) HKLM-x32\…\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" [1162848 2012-08-18] () HKLM-x32\…\Run: [ROC_roc_ssl_v12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 [1020512 2012-08-18] () HKU\Default\…\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe [1475584 2010-11-20] (Microsoft Corporation) HKU\Default User\…\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe [1475584 2010-11-20] (Microsoft Corporation) HKU\Manuel\…\Run: [Messenger (Yahoo!)] "C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe" -quiet [5248312 2010-04-29] (Yahoo! Inc.) HKU\Manuel\…\Run: [avichannel] "C:\Program Files (x86)\Evaer\videochannel.exe" [1689088 2011-07-28] (Evaer) HKLM-x32\…\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe" [559616 2011-10-09] (Dell) Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll [X] Tcpip\Parameters: [DhcpNameServer] 192.168.254.254 Startup: C:\Users\Default\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Default User\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) ==================== Services (Whitelisted) ====== 2 AVGIDSAgent; "C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe" [5160568 2012-07-04] (AVG Technologies CZ, s.r.o.) 2 avgwd; "C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe" [193288 2012-02-14] (AVG Technologies CZ, s.r.o.) 2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) 2 ScReadSpool; C:\Program Files (x86)\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe [69632 2006-02-10] (VoyagerSoft, LLC) 2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe [240128 2009-06-28] (IDT, Inc.) 2 vToolbarUpdater12.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.0\ToolbarUpdater.exe [927840 2012-08-18] () 3 aspnet_state; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [x] ========================== Drivers (Whitelisted) ============= 3 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [124496 2011-12-23] (AVG Technologies CZ, s.r.o. ) 3 AVGIDSFilter; C:\Windows\System32\DRIVERS\avgidsfiltera.sys [29776 2011-12-23] (AVG Technologies CZ, s.r.o. ) 0 AVGIDSHA; C:\Windows\System32\Drivers\AVGIDSHA.sys [28480 2012-04-19] (AVG Technologies CZ, s.r.o. ) 1 Avgldx64; C:\Windows\System32\Drivers\Avgldx64.sys [289872 2012-02-22] (AVG Technologies CZ, s.r.o.) 1 Avgmfx64; C:\Windows\System32\Drivers\Avgmfx64.sys [47696 2011-12-23] (AVG Technologies CZ, s.r.o.) 0 Avgrkx64; C:\Windows\System32\Drivers\Avgrkx64.sys [36944 2012-01-31] (AVG Technologies CZ, s.r.o.) 1 Avgtdia; C:\Windows\System32\Drivers\Avgtdia.sys [383808 2012-03-19] (AVG Technologies CZ, s.r.o.) 1 avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [31080 2012-08-18] (AVG Technologies) 3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2006-12-26] (SlySoft, Inc.) 3 ElbyCDFL; C:\Windows\SysWow64\Drivers\ElbyCDFL.sys [40648 2006-12-26] (SlySoft, Inc.) 1 sbtis; C:\Windows\System32\Drivers\sbtis.sys [82480 2008-10-09] (Sunbelt Software) 3 SUSTUCAM; C:\Windows\System32\Drivers\SUSTUCAM.sys [56832 2009-11-25] (Susteen, Inc.) 3 SUSTUCAP; C:\Windows\System32\Drivers\SUSTUCAP.sys [56832 2009-11-25] (Susteen, Inc.) 3 SUSTUCAU; C:\Windows\System32\Drivers\SUSTUCAU.sys [33792 2009-11-25] (Susteen, Inc.) 3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] () 3 catchme; \??\C:\ComboFix\catchme.sys [x] 3 hwdatacard; C:\Windows\System32\DRIVERS\ewusbmdm.sys [x] ========================== NetSvcs (Whitelisted) =========== ============ One Month Created Files and Folders ============== 2012-08-21 21:54 - 2012-08-21 21:54 - 00000000 ____D C:\Program Files (x86)\ESET 2012-08-21 17:22 - 2009-07-13 20:14 - 00020480 ____A (Microsoft Corporation) C:\Windows\svchost.exe 2012-08-21 12:57 - 2012-08-21 12:57 - 00051698 ____A C:\ComboFix.txt 2012-08-20 21:02 - 2012-08-20 21:02 - 00277088 ____A C:\Windows\Minidump\082012-31122-01.dmp 2012-08-20 20:45 - 2012-08-20 20:45 - 00277088 ____A C:\Windows\Minidump\082012-32900-01.dmp 2012-08-20 20:29 - 2012-08-20 20:29 - 00277088 ____A C:\Windows\Minidump\082012-40716-01.dmp 2012-08-20 20:20 - 2012-08-20 20:21 - 00277200 ____A C:\Windows\Minidump\082012-37206-01.dmp 2012-08-20 19:57 - 2012-08-20 19:58 - 00277144 ____A C:\Windows\Minidump\082012-37923-01.dmp 2012-08-19 18:04 - 2011-06-26 01:45 - 00256000 ____A C:\Windows\PEV.exe 2012-08-19 18:04 - 2010-11-07 12:20 - 00208896 ____A C:\Windows\MBR.exe 2012-08-19 18:04 - 2009-04-19 23:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2012-08-19 18:04 - 2000-08-30 19:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2012-08-19 18:04 - 2000-08-30 19:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2012-08-19 18:04 - 2000-08-30 19:00 - 00098816 ____A C:\Windows\sed.exe 2012-08-19 18:04 - 2000-08-30 19:00 - 00080412 ____A C:\Windows\grep.exe 2012-08-19 18:04 - 2000-08-30 19:00 - 00068096 ____A C:\Windows\zip.exe 2012-08-19 18:01 - 2012-08-21 12:57 - 00000000 ____D C:\Qoobox 2012-08-19 18:00 - 2012-08-19 18:44 - 00000000 ____D C:\Windows\erdnt 2012-08-19 17:58 - 2012-08-20 19:50 - 04734695 ____R (Swearware) C:\Users\Manuel\Desktop\ComboFix.exe 2012-08-19 13:42 - 2012-08-19 13:42 - 00002382 ____A C:\Users\Manuel\Desktop\aswMBR.txt 2012-08-19 13:06 - 2012-08-19 13:06 - 00277256 ____A C:\Windows\Minidump\081912-42167-01.dmp 2012-08-19 12:21 - 2012-08-19 12:21 - 00026993 ____A C:\Users\Manuel\Desktop\DDS.txt 2012-08-19 12:20 - 2012-08-19 12:20 - 00018312 ____A C:\Users\Manuel\Desktop\Attach.txt 2012-08-19 10:06 - 2012-08-19 10:08 - 04731392 ____A (AVAST Software) C:\Users\Manuel\Desktop\aswMBR.exe 2012-08-19 10:06 - 2012-08-19 10:06 - 00607260 ____R (Swearware) C:\Users\Manuel\Desktop\dds.scr 2012-08-19 10:06 - 2012-08-19 10:06 - 00607260 ____R (Swearware) C:\Users\Manuel\Desktop\dds.com 2012-08-19 09:53 - 2012-08-19 09:53 - 00001071 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-08-19 09:53 - 2012-08-19 09:53 - 00001071 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk 2012-08-19 09:53 - 2012-07-03 13:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2012-08-19 09:50 - 2012-08-19 09:50 - 00006646 ____A C:\Users\Manuel\Desktop\AVG Scan 19 Aug 2012 0940hrs.csv 2012-08-19 03:09 - 2012-06-28 23:55 - 17809920 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-08-19 03:09 - 2012-06-28 23:09 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-08-19 03:09 - 2012-06-28 22:56 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-08-19 03:09 - 2012-06-28 22:49 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-08-19 03:09 - 2012-06-28 22:49 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-08-19 03:09 - 2012-06-28 22:48 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-08-19 03:09 - 2012-06-28 22:47 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-08-19 03:09 - 2012-06-28 22:45 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-08-19 03:09 - 2012-06-28 22:44 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-08-19 03:09 - 2012-06-28 22:43 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-08-19 03:09 - 2012-06-28 22:42 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-08-19 03:09 - 2012-06-28 22:40 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-08-19 03:09 - 2012-06-28 22:39 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-08-19 03:09 - 2012-06-28 22:35 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-08-19 03:09 - 2012-06-28 19:52 - 12317184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-08-19 03:09 - 2012-06-28 19:27 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-08-19 03:09 - 2012-06-28 19:16 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-08-19 03:09 - 2012-06-28 19:09 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-08-19 03:09 - 2012-06-28 19:09 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-08-19 03:09 - 2012-06-28 19:08 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-08-19 03:09 - 2012-06-28 19:07 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-08-19 03:09 - 2012-06-28 19:06 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-08-19 03:09 - 2012-06-28 19:04 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-08-19 03:09 - 2012-06-28 19:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-08-19 03:09 - 2012-06-28 19:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-08-19 03:09 - 2012-06-28 19:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-08-19 03:09 - 2012-06-28 19:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-08-19 03:09 - 2012-06-28 18:57 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-08-19 03:06 - 2012-08-19 03:06 - 00000129 ____A C:\Windows\System32\MRT.INI 2012-08-18 22:21 - 2012-08-18 22:21 - 00031080 ____A (AVG Technologies) C:\Windows\System32\Drivers\avgtpx64.sys 2012-08-18 22:21 - 2012-08-18 22:21 - 00000000 ____D C:\Program Files (x86)\AVG Secure Search 2012-08-18 22:19 - 2012-08-22 08:44 - 00000000 ____D C:\Windows\System32\Drivers\AVG 2012-08-18 22:00 - 2012-08-19 09:53 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2012-08-18 21:58 - 2012-08-18 23:23 - 00000000 ____D C:\AntiVirus 2012-08-18 19:22 - 2012-08-18 19:22 - 00000000 ____D C:\Users\Manuel\Application Data\AVG2012 2012-08-18 19:22 - 2012-08-18 19:22 - 00000000 ____D C:\Users\Manuel\AppData\Roaming\AVG2012 2012-08-18 19:20 - 2012-08-18 22:21 - 00000927 ____A C:\Users\Public\Desktop\AVG 2012.lnk 2012-08-18 19:20 - 2012-08-18 22:21 - 00000927 ____A C:\Users\All Users\Desktop\AVG 2012.lnk 2012-08-18 19:20 - 2012-08-18 19:20 - 00000000 ____D C:\Users\Manuel\Local Settings\AVG Secure Search 2012-08-18 19:20 - 2012-08-18 19:20 - 00000000 ____D C:\Users\Manuel\Local Settings\Application Data\AVG Secure Search 2012-08-18 19:20 - 2012-08-18 19:20 - 00000000 ____D C:\Users\Manuel\AppData\Local\AVG Secure Search 2012-08-18 19:20 - 2012-08-18 19:20 - 00000000 ____D C:\Users\All Users\AVG Secure Search 2012-08-18 19:20 - 2012-08-18 19:20 - 00000000 ____D C:\Users\All Users\Application Data\AVG Secure Search 2012-08-18 19:17 - 2012-08-19 13:06 - 00000000 ____D C:\Users\All Users\AVG2012 2012-08-18 19:17 - 2012-08-19 13:06 - 00000000 ____D C:\Users\All Users\Application Data\AVG2012 2012-08-18 19:17 - 2012-08-18 19:17 - 00000000 ____D C:\$AVG 2012-08-18 19:02 - 2012-08-22 08:44 - 00000000 ____D C:\Users\All Users\MFAData 2012-08-18 19:02 - 2012-08-22 08:44 - 00000000 ____D C:\Users\All Users\Application Data\MFAData 2012-08-18 18:53 - 2012-08-18 18:53 - 00477168 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll 2012-08-18 18:53 - 2012-08-18 18:53 - 00157680 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe 2012-08-18 18:53 - 2012-08-18 18:53 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe 2012-08-18 18:53 - 2012-08-18 18:53 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe 2012-08-18 18:42 - 2012-07-18 13:15 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-08-18 18:42 - 2012-07-04 17:16 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll 2012-08-18 18:42 - 2012-07-04 17:13 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll 2012-08-18 18:42 - 2012-07-04 17:13 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll 2012-08-18 18:42 - 2012-07-04 16:16 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll 2012-08-18 18:42 - 2012-07-04 16:14 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll 2012-08-18 18:42 - 2012-05-14 00:26 - 00956928 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll 2012-08-18 18:42 - 2012-05-05 03:36 - 00503808 ____A (Microsoft Corporation) C:\Windows\System32\srcore.dll 2012-08-18 18:42 - 2012-05-05 02:46 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2012-08-18 18:42 - 2012-02-11 01:43 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll 2012-08-18 18:42 - 2012-02-11 01:36 - 00559104 ____A (Microsoft Corporation) C:\Windows\System32\spoolsv.exe 2012-08-18 18:42 - 2012-02-11 01:36 - 00067072 ____A (Microsoft Corporation) C:\Windows\splwow64.exe 2012-08-18 18:42 - 2012-02-11 00:43 - 00492032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll 2012-08-18 18:32 - 2012-08-18 18:32 - 00365248 ____A C:\Windows\Minidump\081812-31777-01.dmp 2012-08-17 23:19 - 2012-08-17 23:19 - 00000000 ____D C:\Windows\Sun 2012-08-15 20:56 - 2012-08-17 23:41 - 00000000 ___RD C:\Users\Manuel\Desktop\DESKTOP shortcuts 2012-08-12 09:45 - 2012-08-17 23:42 - 00000000 ____D C:\Program Files (x86)\SopCast ============ 3 Months Modified Files ======================== 2012-08-22 15:00 - 2012-06-21 18:55 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2012-08-22 15:00 - 2009-07-14 00:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2012-08-22 15:00 - 2009-07-13 23:51 - 00089061 ____A C:\Windows\setupact.log 2012-08-22 14:58 - 2009-07-14 00:10 - 01992530 ____A C:\Windows\WindowsUpdate.log 2012-08-22 14:56 - 2012-06-21 23:50 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2012-08-22 14:56 - 2012-06-21 18:55 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2012-08-22 07:12 - 2009-07-13 23:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2012-08-22 07:12 - 2009-07-13 23:45 - 00014240 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2012-08-21 17:26 - 2009-07-14 00:13 - 00739918 ____A C:\Windows\System32\PerfStringBackup.INI 2012-08-21 12:57 - 2012-08-21 12:57 - 00051698 ____A C:\ComboFix.txt 2012-08-21 12:44 - 2009-07-13 21:34 - 00000215 ____A C:\Windows\system.ini 2012-08-21 12:42 - 2009-09-27 08:24 - 02839824 ____A C:\Windows\PFRO.log 2012-08-20 21:02 - 2012-08-20 21:02 - 00277088 ____A C:\Windows\Minidump\082012-31122-01.dmp 2012-08-20 21:02 - 2010-01-13 00:13 - 539827083 ____A C:\Windows\MEMORY.DMP 2012-08-20 20:45 - 2012-08-20 20:45 - 00277088 ____A C:\Windows\Minidump\082012-32900-01.dmp 2012-08-20 20:29 - 2012-08-20 20:29 - 00277088 ____A C:\Windows\Minidump\082012-40716-01.dmp 2012-08-20 20:21 - 2012-08-20 20:20 - 00277200 ____A C:\Windows\Minidump\082012-37206-01.dmp 2012-08-20 19:58 - 2012-08-20 19:57 - 00277144 ____A C:\Windows\Minidump\082012-37923-01.dmp 2012-08-20 19:50 - 2012-08-19 17:58 - 04734695 ____R (Swearware) C:\Users\Manuel\Desktop\ComboFix.exe 2012-08-19 13:42 - 2012-08-19 13:42 - 00002382 ____A C:\Users\Manuel\Desktop\aswMBR.txt 2012-08-19 13:06 - 2012-08-19 13:06 - 00277256 ____A C:\Windows\Minidump\081912-42167-01.dmp 2012-08-19 12:21 - 2012-08-19 12:21 - 00026993 ____A C:\Users\Manuel\Desktop\DDS.txt 2012-08-19 12:20 - 2012-08-19 12:20 - 00018312 ____A C:\Users\Manuel\Desktop\Attach.txt 2012-08-19 10:08 - 2012-08-19 10:06 - 04731392 ____A (AVAST Software) C:\Users\Manuel\Desktop\aswMBR.exe 2012-08-19 10:06 - 2012-08-19 10:06 - 00607260 ____R (Swearware) C:\Users\Manuel\Desktop\dds.scr 2012-08-19 10:06 - 2012-08-19 10:06 - 00607260 ____R (Swearware) C:\Users\Manuel\Desktop\dds.com 2012-08-19 09:53 - 2012-08-19 09:53 - 00001071 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-08-19 09:53 - 2012-08-19 09:53 - 00001071 ____A C:\Users\All Users\Desktop\Malwarebytes Anti-Malware.lnk 2012-08-19 09:50 - 2012-08-19 09:50 - 00006646 ____A C:\Users\Manuel\Desktop\AVG Scan 19 Aug 2012 0940hrs.csv 2012-08-19 03:32 - 2009-07-13 23:45 - 00359848 ____A C:\Windows\System32\FNTCACHE.DAT 2012-08-19 03:13 - 2009-07-13 21:34 - 00000499 ____A C:\Windows\win.ini 2012-08-19 03:06 - 2012-08-19 03:06 - 00000129 ____A C:\Windows\System32\MRT.INI 2012-08-19 03:02 - 2009-10-24 22:20 - 62134624 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2012-08-18 22:21 - 2012-08-18 22:21 - 00031080 ____A (AVG Technologies) C:\Windows\System32\Drivers\avgtpx64.sys 2012-08-18 22:21 - 2012-08-18 19:20 - 00000927 ____A C:\Users\Public\Desktop\AVG 2012.lnk 2012-08-18 22:21 - 2012-08-18 19:20 - 00000927 ____A C:\Users\All Users\Desktop\AVG 2012.lnk 2012-08-18 22:08 - 2012-06-21 23:50 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2012-08-18 22:08 - 2011-06-07 21:09 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2012-08-18 18:56 - 2010-02-25 04:16 - 00000052 ____A C:\Windows\System32\ashttpstats.csv 2012-08-18 18:53 - 2012-08-18 18:53 - 00477168 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\npdeployJava1.dll 2012-08-18 18:53 - 2012-08-18 18:53 - 00157680 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaws.exe 2012-08-18 18:53 - 2012-08-18 18:53 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\javaw.exe 2012-08-18 18:53 - 2012-08-18 18:53 - 00149488 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\java.exe 2012-08-18 18:53 - 2011-03-26 21:01 - 00473072 ____A (Sun Microsystems, Inc.) C:\Windows\SysWOW64\deployJava1.dll 2012-08-18 18:32 - 2012-08-18 18:32 - 00365248 ____A C:\Windows\Minidump\081812-31777-01.dmp 2012-08-14 18:11 - 2010-02-23 22:43 - 00000376 ____A C:\Users\Manuel\AppData\Roamingprivacy.xml 2012-07-18 13:15 - 2012-08-18 18:42 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-07-04 17:16 - 2012-08-18 18:42 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll 2012-07-04 17:13 - 2012-08-18 18:42 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll 2012-07-04 17:13 - 2012-08-18 18:42 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll 2012-07-04 16:16 - 2012-08-18 18:42 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll 2012-07-04 16:14 - 2012-08-18 18:42 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll 2012-07-03 13:46 - 2012-08-19 09:53 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2012-06-28 23:55 - 2012-08-19 03:09 - 17809920 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-06-28 23:09 - 2012-08-19 03:09 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-06-28 22:56 - 2012-08-19 03:09 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-06-28 22:49 - 2012-08-19 03:09 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-06-28 22:49 - 2012-08-19 03:09 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-06-28 22:48 - 2012-08-19 03:09 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-06-28 22:47 - 2012-08-19 03:09 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-06-28 22:45 - 2012-08-19 03:09 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-06-28 22:44 - 2012-08-19 03:09 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-06-28 22:43 - 2012-08-19 03:09 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-06-28 22:42 - 2012-08-19 03:09 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-06-28 22:40 - 2012-08-19 03:09 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-06-28 22:39 - 2012-08-19 03:09 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-06-28 22:35 - 2012-08-19 03:09 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-06-28 19:52 - 2012-08-19 03:09 - 12317184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-06-28 19:27 - 2012-08-19 03:09 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-06-28 19:16 - 2012-08-19 03:09 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-06-28 19:09 - 2012-08-19 03:09 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-06-28 19:09 - 2012-08-19 03:09 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-06-28 19:08 - 2012-08-19 03:09 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-06-28 19:07 - 2012-08-19 03:09 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-06-28 19:06 - 2012-08-19 03:09 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-06-28 19:04 - 2012-08-19 03:09 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-06-28 19:04 - 2012-08-19 03:09 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-06-28 19:01 - 2012-08-19 03:09 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-06-28 19:01 - 2012-08-19 03:09 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-06-28 19:00 - 2012-08-19 03:09 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-06-28 18:57 - 2012-08-19 03:09 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-06-28 15:03 - 2011-10-30 17:51 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk 2012-06-28 15:03 - 2011-10-30 17:51 - 00002515 ____A C:\Users\All Users\Desktop\Skype.lnk 2012-06-28 13:25 - 2009-07-14 00:08 - 00032536 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2012-06-28 11:07 - 2009-07-13 21:36 - 00175616 ____A (Microsoft Corporation) C:\Windows\System32\msclmd.dll 2012-06-28 11:07 - 2009-07-13 21:36 - 00152576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msclmd.dll 2012-06-27 19:09 - 2012-06-27 19:09 - 00001220 ____A C:\Users\Manuel\Desktop\Spybot - Search & Destroy.lnk 2012-06-21 18:53 - 2012-06-21 18:53 - 00001042 ____A C:\Users\Public\Desktop\RealPlayer.lnk 2012-06-21 18:53 - 2012-06-21 18:53 - 00001042 ____A C:\Users\All Users\Desktop\RealPlayer.lnk 2012-06-21 18:52 - 2012-06-21 18:52 - 00198832 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\rmoc3260.dll 2012-06-21 18:51 - 2012-06-21 18:51 - 00499712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll 2012-06-21 18:51 - 2012-06-21 18:51 - 00348160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll 2012-06-21 18:51 - 2012-06-21 18:51 - 00272896 ____A (Progressive Networks) C:\Windows\SysWOW64\pncrt.dll 2012-06-21 18:51 - 2012-06-21 18:51 - 00006656 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5016.dll 2012-06-21 18:51 - 2012-06-21 18:51 - 00005632 ____A (RealNetworks, Inc.) C:\Windows\SysWOW64\pndx5032.dll 2012-06-09 00:43 - 2012-07-11 15:42 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2012-06-08 23:41 - 2012-07-11 15:42 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2012-06-06 01:06 - 2012-07-11 15:42 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll 2012-06-06 01:06 - 2012-07-11 15:42 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll 2012-06-06 01:02 - 2012-07-11 15:39 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll 2012-06-06 00:05 - 2012-07-11 15:42 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2012-06-06 00:05 - 2012-07-11 15:42 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2012-06-06 00:03 - 2012-07-11 15:39 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll 2012-06-02 17:19 - 2012-06-21 23:46 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2012-06-02 17:19 - 2012-06-21 23:46 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2012-06-02 17:19 - 2012-06-21 23:46 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2012-06-02 17:19 - 2012-06-21 23:46 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll 2012-06-02 17:19 - 2012-06-21 23:46 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll 2012-06-02 17:15 - 2012-06-21 23:46 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2012-06-02 17:15 - 2012-06-21 23:46 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2012-06-02 15:19 - 2012-06-21 23:45 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2012-06-02 15:15 - 2012-06-21 23:45 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2012-06-02 00:50 - 2012-07-11 15:42 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys 2012-06-02 00:48 - 2012-07-11 15:42 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys 2012-06-02 00:48 - 2012-07-11 15:42 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys 2012-06-02 00:45 - 2012-07-11 15:42 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll 2012-06-02 00:44 - 2012-07-11 15:42 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2012-06-01 23:40 - 2012-07-11 15:42 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2012-06-01 23:40 - 2012-07-11 15:42 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2012-06-01 23:39 - 2012-07-11 15:42 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2012-06-01 23:34 - 2012-07-11 15:42 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2012-05-31 12:25 - 2009-10-26 20:23 - 00279656 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe Type 00 partition infection: C:\Windows\svchost.exe ========================= Known DLLs (Whitelisted) ============ ========================= Bamital & volsnap Check ============ C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit TDL4: custom:26000022 <===== ATTENTION! ==================== EXE ASSOCIATION ===================== HKLM\…\.exe: exefile => OK HKLM\…\exefile\DefaultIcon: %1 => OK HKLM\…\exefile\open\command: "%1" %* => OK ========================= Memory info ====================== Percentage of memory in use: 15% Total physical RAM: 4056.36 MB Available physical RAM: 3441.22 MB Total Pagefile: 4054.51 MB Available Pagefile: 3439.74 MB Total Virtual: 8192 MB Available Virtual: 8191.9 MB ======================= Partitions ========================= 1 Drive c: (OS) (Fixed) (Total:213.72 GB) (Free:36.67 GB) NTFS 2 Drive d: (RECOVERY) (Fixed) (Total:18.87 GB) (Free:14.27 GB) NTFS ==>[System with boot components (obtained from reading drive)] 5 Drive g: (BlackArmor Drive) (Fixed) (Total:465.76 GB) (Free:261.51 GB) NTFS 6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Disk ### Status Size Free Dyn Gpt ——– ————- ——- ——- — — Disk 0 Online 232 GB 0 B Disk 1 No Media 0 B 0 B Disk 2 Online 465 GB 1024 KB Partitions of Disk 0: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 OEM 298 MB 31 KB Partition 2 Primary 18 GB 299 MB Partition 3 Primary 213 GB 19 GB ================================================================================ == Disk: 0 Partition 1 Type : DE Hidden: Yes Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 5 FAT Partition 298 MB Healthy Hidden ================================================================================ == Disk: 0 Partition 2 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 1 D RECOVERY NTFS Partition 18 GB Healthy ================================================================================ == Disk: 0 Partition 3 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 C OS NTFS Partition 213 GB Healthy ================================================================================ == Partitions of Disk 2: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 465 GB 31 KB ================================================================================ == Disk: 2 Partition 1 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 4 G BlackArmor NTFS Partition 465 GB Healthy ================================================================================ == Last Boot: 2012-08-18 21:48 ======================= End Of Log ==========================
Hi,

Good job getting that ran.

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan but do nothing else as we are just looking for what is there.
  • If Malicious objects are found, select Skip by changing the Cure dropdown in the upper right.
  • Attach the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-
OK Jeff ran TDSSkiller… no problems so far…. here is the log file. Thanks for the quick response. 22:31:04.0753 4036 TDSS rootkit removing tool [removed] Aug 20 2012 17:30:03 22:31:06.0298 4036 ============================================================ 22:31:06.0298 4036 Current date / time: 2012/08/22 22:31:06.0298 22:31:06.0298 4036 SystemInfo: 22:31:06.0298 4036 22:31:06.0298 4036 OS Version: 6.1.7601 ServicePack: 1.0 22:31:06.0298 4036 Product type: Workstation 22:31:06.0298 4036 ComputerName: MANUEL-PC 22:31:06.0298 4036 UserName: Manuel 22:31:06.0298 4036 Windows directory: C:\Windows 22:31:06.0298 4036 System windows directory: C:\Windows 22:31:06.0298 4036 Running under WOW64 22:31:06.0298 4036 Processor architecture: Intel x64 22:31:06.0298 4036 Number of processors: 2 22:31:06.0298 4036 Page size: 0x1000 22:31:06.0298 4036 Boot type: Normal boot 22:31:06.0298 4036 ============================================================ 22:31:07.0015 4036 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 22:31:07.0031 4036 ============================================================ 22:31:07.0031 4036 \Device\Harddisk0\DR0: 22:31:07.0031 4036 MBR partitions: 22:31:07.0031 4036 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x95800, BlocksNum 0x25C0000 22:31:07.0031 4036 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x2655800, BlocksNum 0x1AB6F970 22:31:07.0031 4036 ============================================================ 22:31:07.0062 4036 C: <-> \Device\Harddisk0\DR0\Partition2 22:31:07.0062 4036 ============================================================ 22:31:07.0062 4036 Initialize success 22:31:07.0062 4036 ============================================================ 22:31:18.0793 6044 ============================================================ 22:31:18.0793 6044 Scan started 22:31:18.0793 6044 Mode: Manual; 22:31:18.0793 6044 ============================================================ 22:31:20.0930 6044 ================ Scan system memory ======================== 22:31:20.0930 6044 System memory - ok 22:31:20.0930 6044 ================ Scan services ============================= 22:31:21.0320 6044 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 22:31:21.0320 6044 1394ohci - ok 22:31:21.0352 6044 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 22:31:21.0367 6044 ACPI - ok 22:31:21.0430 6044 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 22:31:21.0430 6044 AcpiPmi - ok 22:31:21.0617 6044 [ A9D3B95E8466BD58EEB8A1154654E162 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 22:31:21.0617 6044 AdobeFlashPlayerUpdateSvc - ok 22:31:21.0679 6044 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 22:31:21.0695 6044 adp94xx - ok 22:31:21.0742 6044 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 22:31:21.0742 6044 adpahci - ok 22:31:21.0773 6044 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 22:31:21.0773 6044 adpu320 - ok 22:31:21.0804 6044 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 22:31:21.0804 6044 AeLookupSvc - ok 22:31:21.0866 6044 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 22:31:21.0882 6044 AFD - ok 22:31:21.0929 6044 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 22:31:21.0929 6044 agp440 - ok 22:31:21.0976 6044 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 22:31:21.0976 6044 ALG - ok 22:31:22.0022 6044 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 22:31:22.0022 6044 aliide - ok 22:31:22.0054 6044 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 22:31:22.0054 6044 amdide - ok 22:31:22.0100 6044 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 22:31:22.0100 6044 AmdK8 - ok 22:31:22.0116 6044 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 22:31:22.0116 6044 AmdPPM - ok 22:31:22.0178 6044 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 22:31:22.0178 6044 amdsata - ok 22:31:22.0210 6044 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 22:31:22.0225 6044 amdsbs - ok 22:31:22.0256 6044 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 22:31:22.0256 6044 amdxata - ok 22:31:22.0319 6044 [ 1412E9A88FE1F7E35CE6058A2EF03664 ] ApfiltrService C:\Windows\system32\DRIVERS\Apfiltr.sys 22:31:22.0334 6044 ApfiltrService - ok 22:31:22.0397 6044 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 22:31:22.0397 6044 AppID - ok 22:31:22.0428 6044 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 22:31:22.0444 6044 AppIDSvc - ok 22:31:22.0475 6044 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll 22:31:22.0475 6044 Appinfo - ok 22:31:22.0662 6044 [ ACB095E7E1663F1B83A41C22C5D75F90 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 22:31:22.0662 6044 Apple Mobile Device - ok 22:31:22.0756 6044 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys 22:31:22.0756 6044 arc - ok 22:31:22.0818 6044 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 22:31:22.0818 6044 arcsas - ok 22:31:22.0880 6044 aspnet_state - ok 22:31:22.0958 6044 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 22:31:22.0958 6044 AsyncMac - ok 22:31:23.0021 6044 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 22:31:23.0021 6044 atapi - ok 22:31:23.0099 6044 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 22:31:23.0099 6044 AudioEndpointBuilder - ok 22:31:23.0114 6044 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 22:31:23.0130 6044 AudioSrv - ok 22:31:23.0380 6044 [ D67719BCFDE5798F5C30D14EFED3BCAF ] AVGIDSAgent C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe 22:31:23.0536 6044 AVGIDSAgent - ok 22:31:23.0598 6044 [ 1B2E9FCDC26DC7C81D4131430E2DC936 ] AVGIDSDriver C:\Windows\system32\DRIVERS\avgidsdrivera.sys 22:31:23.0598 6044 AVGIDSDriver - ok 22:31:23.0645 6044 [ 0F293406F64B48D5D2F0D3A1117F3A83 ] AVGIDSFilter C:\Windows\system32\DRIVERS\avgidsfiltera.sys 22:31:23.0645 6044 AVGIDSFilter - ok 22:31:23.0676 6044 [ CFFC3A4A638F462E0561CB368B9A7A3A ] AVGIDSHA C:\Windows\system32\DRIVERS\avgidsha.sys 22:31:23.0676 6044 AVGIDSHA - ok 22:31:23.0754 6044 [ 59955B4C288DD2A8B9FD2CD5158355C5 ] Avgldx64 C:\Windows\system32\DRIVERS\avgldx64.sys 22:31:23.0754 6044 Avgldx64 - ok 22:31:23.0832 6044 [ A6AEC362AAE5E2DDA7445E7690CB0F33 ] Avgmfx64 C:\Windows\system32\DRIVERS\avgmfx64.sys 22:31:23.0832 6044 Avgmfx64 - ok 22:31:23.0910 6044 [ 645C7F0A0E39758A0024A9B1748273C0 ] Avgrkx64 C:\Windows\system32\DRIVERS\avgrkx64.sys 22:31:23.0910 6044 Avgrkx64 - ok 22:31:23.0957 6044 [ 1BEE674AD792B1C63BB0DAC5FA724B23 ] Avgtdia C:\Windows\system32\DRIVERS\avgtdia.sys 22:31:23.0957 6044 Avgtdia - ok 22:31:24.0019 6044 [ E964EA70249DDE1343C8F694B52575EE ] avgtp C:\Windows\system32\drivers\avgtpx64.sys 22:31:24.0019 6044 avgtp - ok 22:31:24.0082 6044 [ EA1145DEBCD508FD25BD1E95C4346929 ] avgwd C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe 22:31:24.0082 6044 avgwd - ok 22:31:24.0144 6044 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 22:31:24.0144 6044 AxInstSV - ok 22:31:24.0222 6044 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys 22:31:24.0238 6044 b06bdrv - ok 22:31:24.0269 6044 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 22:31:24.0269 6044 b57nd60a - ok 22:31:24.0394 6044 [ 01A24B415926BB5F772DBE12459D97DE ] BBSvc C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE 22:31:24.0394 6044 BBSvc - ok 22:31:24.0472 6044 [ 785DE7ABDA13309D6065305542829E76 ] BBUpdate C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE 22:31:24.0472 6044 BBUpdate - ok 22:31:24.0518 6044 [ E001DD475A7C27EBE5A0DB45C11BAD71 ] BCM42RLY C:\Windows\system32\drivers\BCM42RLY.sys 22:31:24.0518 6044 BCM42RLY - ok 22:31:24.0659 6044 [ 37394D3553E220FB732C21E217E1BD8B ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl664.sys 22:31:24.0674 6044 BCM43XX - ok 22:31:24.0737 6044 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 22:31:24.0737 6044 BDESVC - ok 22:31:24.0768 6044 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 22:31:24.0768 6044 Beep - ok 22:31:24.0846 6044 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll 22:31:24.0862 6044 BFE - ok 22:31:24.0924 6044 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll 22:31:24.0940 6044 BITS - ok 22:31:24.0986 6044 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 22:31:24.0986 6044 blbdrive - ok 22:31:25.0111 6044 [ A065F048E9E23E6C026A7BB548D126A7 ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe 22:31:25.0111 6044 Bonjour Service - ok 22:31:25.0158 6044 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 22:31:25.0174 6044 bowser - ok 22:31:25.0205 6044 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 22:31:25.0205 6044 BrFiltLo - ok 22:31:25.0220 6044 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 22:31:25.0220 6044 BrFiltUp - ok 22:31:25.0267 6044 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys 22:31:25.0267 6044 BridgeMP - ok 22:31:25.0314 6044 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 22:31:25.0314 6044 Browser - ok 22:31:25.0345 6044 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 22:31:25.0345 6044 Brserid - ok 22:31:25.0376 6044 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 22:31:25.0376 6044 BrSerWdm - ok 22:31:25.0408 6044 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 22:31:25.0423 6044 BrUsbMdm - ok 22:31:25.0423 6044 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 22:31:25.0423 6044 BrUsbSer - ok 22:31:25.0454 6044 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 22:31:25.0454 6044 BTHMODEM - ok 22:31:25.0517 6044 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 22:31:25.0517 6044 bthserv - ok 22:31:25.0548 6044 catchme - ok 22:31:25.0595 6044 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 22:31:25.0595 6044 cdfs - ok 22:31:25.0657 6044 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\drivers\cdrom.sys 22:31:25.0673 6044 cdrom - ok 22:31:25.0751 6044 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 22:31:25.0751 6044 CertPropSvc - ok 22:31:25.0798 6044 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys 22:31:25.0798 6044 circlass - ok 22:31:25.0844 6044 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 22:31:25.0844 6044 CLFS - ok 22:31:25.0876 6044 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 22:31:25.0876 6044 clr_optimization_v2.0.50727_32 - ok 22:31:25.0922 6044 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 22:31:25.0938 6044 clr_optimization_v2.0.50727_64 - ok 22:31:26.0094 6044 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 22:31:26.0110 6044 clr_optimization_v4.0.30319_32 - ok 22:31:26.0266 6044 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 22:31:26.0266 6044 clr_optimization_v4.0.30319_64 - ok 22:31:26.0312 6044 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 22:31:26.0312 6044 CmBatt - ok 22:31:26.0390 6044 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 22:31:26.0406 6044 cmdide - ok 22:31:26.0921 6044 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 22:31:26.0921 6044 CNG - ok 22:31:26.0983 6044 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 22:31:26.0983 6044 Compbatt - ok 22:31:27.0030 6044 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 22:31:27.0046 6044 CompositeBus - ok 22:31:27.0061 6044 COMSysApp - ok 22:31:27.0124 6044 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 22:31:27.0124 6044 crcdisk - ok 22:31:27.0186 6044 [ 4F5414602E2544A4554D95517948B705 ] CryptSvc C:\Windows\system32\cryptsvc.dll 22:31:27.0186 6044 CryptSvc - ok 22:31:27.0264 6044 [ ED5CF92396A62F4C15110DCDB5E854D9 ] CtClsFlt C:\Windows\system32\DRIVERS\CtClsFlt.sys 22:31:27.0280 6044 CtClsFlt - ok 22:31:27.0342 6044 [ 76E02DB615A03801D698199A2BC4A06A ] dc3d C:\Windows\system32\DRIVERS\dc3d.sys 22:31:27.0342 6044 dc3d - ok 22:31:27.0436 6044 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 22:31:27.0436 6044 DcomLaunch - ok 22:31:27.0498 6044 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 22:31:27.0498 6044 defragsvc - ok 22:31:27.0576 6044 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 22:31:27.0576 6044 DfsC - ok 22:31:27.0623 6044 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 22:31:27.0623 6044 Dhcp - ok 22:31:27.0654 6044 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 22:31:27.0654 6044 discache - ok 22:31:27.0685 6044 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys 22:31:27.0685 6044 Disk - ok 22:31:27.0748 6044 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 22:31:27.0748 6044 Dnscache - ok 22:31:27.0888 6044 [ 0840ABBBDF438691EE65A20040635CBE ] DockLoginService C:\Program Files\Dell\DellDock\DockLogin.exe 22:31:27.0888 6044 DockLoginService - ok 22:31:27.0966 6044 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 22:31:27.0966 6044 dot3svc - ok 22:31:28.0028 6044 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 22:31:28.0028 6044 DPS - ok 22:31:28.0075 6044 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 22:31:28.0075 6044 drmkaud - ok 22:31:28.0169 6044 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 22:31:28.0184 6044 DXGKrnl - ok 22:31:28.0231 6044 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 22:31:28.0231 6044 EapHost - ok 22:31:28.0372 6044 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys 22:31:28.0418 6044 ebdrv - ok 22:31:28.0496 6044 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 22:31:28.0496 6044 EFS - ok 22:31:28.0621 6044 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 22:31:28.0637 6044 ehRecvr - ok 22:31:28.0652 6044 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 22:31:28.0668 6044 ehSched - ok 22:31:28.0730 6044 [ 8D18A680BDAB2ACA00506FE6F8AEF81A ] ElbyCDFL C:\Windows\system32\Drivers\ElbyCDFL.sys 22:31:28.0730 6044 ElbyCDFL - ok 22:31:28.0762 6044 [ EA2FF60FCCE3B9FFE0BD77658B88512D ] ElbyCDIO C:\Windows\system32\Drivers\ElbyCDIO.sys 22:31:28.0762 6044 ElbyCDIO - ok 22:31:28.0808 6044 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 22:31:28.0824 6044 elxstor - ok 22:31:28.0902 6044 [ 1E345F2A2D95DA3190596E691CDE9342 ] EPSON_PM_RPCV4_01 C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE 22:31:28.0902 6044 EPSON_PM_RPCV4_01 - ok 22:31:28.0949 6044 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 22:31:28.0949 6044 ErrDev - ok 22:31:29.0042 6044 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 22:31:29.0058 6044 EventSystem - ok 22:31:29.0074 6044 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 22:31:29.0074 6044 exfat - ok 22:31:29.0120 6044 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 22:31:29.0120 6044 fastfat - ok 22:31:29.0183 6044 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 22:31:29.0183 6044 Fax - ok 22:31:29.0214 6044 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys 22:31:29.0214 6044 fdc - ok 22:31:29.0230 6044 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 22:31:29.0230 6044 fdPHost - ok 22:31:29.0276 6044 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 22:31:29.0276 6044 FDResPub - ok 22:31:29.0339 6044 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 22:31:29.0339 6044 FileInfo - ok 22:31:29.0354 6044 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 22:31:29.0354 6044 Filetrace - ok 22:31:29.0448 6044 [ F76D04F7413B07DAA029F6520B64B4E8 ] FLEXnet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 22:31:29.0464 6044 FLEXnet Licensing Service - ok 22:31:29.0495 6044 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 22:31:29.0495 6044 flpydisk - ok 22:31:29.0557 6044 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 22:31:29.0557 6044 FltMgr - ok 22:31:29.0635 6044 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll 22:31:29.0651 6044 FontCache - ok 22:31:29.0729 6044 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 22:31:29.0729 6044 FontCache3.0.0.0 - ok 22:31:29.0760 6044 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 22:31:29.0760 6044 FsDepends - ok 22:31:29.0822 6044 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 22:31:29.0822 6044 Fs_Rec - ok 22:31:29.0885 6044 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 22:31:29.0885 6044 fvevol - ok 22:31:29.0932 6044 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 22:31:29.0932 6044 gagp30kx - ok 22:31:29.0978 6044 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 22:31:29.0978 6044 GEARAspiWDM - ok 22:31:30.0025 6044 [ D3316F6E3C011435F36E3D6E49B3196C ] GoToAssist C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe 22:31:30.0025 6044 GoToAssist - ok 22:31:30.0103 6044 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 22:31:30.0103 6044 gpsvc - ok 22:31:30.0197 6044 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 22:31:30.0197 6044 gupdate - ok 22:31:30.0228 6044 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 22:31:30.0228 6044 gupdatem - ok 22:31:30.0290 6044 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe 22:31:30.0290 6044 gusvc - ok 22:31:30.0337 6044 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 22:31:30.0337 6044 hcw85cir - ok 22:31:30.0415 6044 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 22:31:30.0415 6044 HDAudBus - ok 22:31:30.0431 6044 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 22:31:30.0431 6044 HidBatt - ok 22:31:30.0478 6044 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 22:31:30.0478 6044 HidBth - ok 22:31:30.0524 6044 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 22:31:30.0524 6044 HidIr - ok 22:31:30.0571 6044 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll 22:31:30.0571 6044 hidserv - ok 22:31:30.0634 6044 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 22:31:30.0634 6044 HidUsb - ok 22:31:30.0680 6044 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 22:31:30.0680 6044 hkmsvc - ok 22:31:30.0743 6044 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 22:31:30.0743 6044 HomeGroupListener - ok 22:31:30.0805 6044 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 22:31:30.0805 6044 HomeGroupProvider - ok 22:31:30.0852 6044 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 22:31:30.0852 6044 HpSAMD - ok 22:31:30.0946 6044 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 22:31:30.0946 6044 HTTP - ok 22:31:30.0992 6044 hwdatacard - ok 22:31:31.0039 6044 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 22:31:31.0039 6044 hwpolicy - ok 22:31:31.0133 6044 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 22:31:31.0133 6044 i8042prt - ok 22:31:31.0242 6044 [ 7548066DF68A8A1A56B043359F915F37 ] IAANTMON C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe 22:31:31.0242 6044 IAANTMON - ok 22:31:31.0320 6044 [ 4F6FB2CDBDEEFC47E7D2066E78254580 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys 22:31:31.0336 6044 iaStor - ok 22:31:31.0429 6044 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 22:31:31.0429 6044 iaStorV - ok 22:31:31.0538 6044 [ DAF66902F08796F9C694901660E5A64A ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe 22:31:31.0538 6044 IDriverT - ok 22:31:31.0663 6044 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 22:31:31.0663 6044 idsvc - ok 22:31:32.0038 6044 [ BABD5F9B2BCC82CE556A0BAF1AE208A7 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys 22:31:32.0225 6044 igfx - ok 22:31:32.0272 6044 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 22:31:32.0272 6044 iirsp - ok 22:31:32.0381 6044 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 22:31:32.0396 6044 IKEEXT - ok 22:31:32.0459 6044 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 22:31:32.0459 6044 intelide - ok 22:31:32.0506 6044 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 22:31:32.0506 6044 intelppm - ok 22:31:32.0552 6044 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 22:31:32.0552 6044 IPBusEnum - ok 22:31:32.0599 6044 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 22:31:32.0615 6044 IpFilterDriver - ok 22:31:32.0677 6044 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 22:31:32.0677 6044 iphlpsvc - ok 22:31:32.0740 6044 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 22:31:32.0740 6044 IPMIDRV - ok 22:31:32.0786 6044 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 22:31:32.0786 6044 IPNAT - ok 22:31:32.0833 6044 [ DC115BD67A913F71A77C7C72C1E64C0A ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 22:31:32.0833 6044 iPod Service - ok 22:31:32.0880 6044 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 22:31:32.0880 6044 IRENUM - ok 22:31:32.0958 6044 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 22:31:32.0958 6044 isapnp - ok 22:31:32.0974 6044 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 22:31:32.0989 6044 iScsiPrt - ok 22:31:33.0067 6044 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 22:31:33.0067 6044 kbdclass - ok 22:31:33.0098 6044 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 22:31:33.0114 6044 kbdhid - ok 22:31:33.0145 6044 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 22:31:33.0145 6044 KeyIso - ok 22:31:33.0176 6044 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 22:31:33.0176 6044 KSecDD - ok 22:31:33.0208 6044 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 22:31:33.0208 6044 KSecPkg - ok 22:31:33.0520 6044 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 22:31:33.0520 6044 ksthunk - ok 22:31:33.0582 6044 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 22:31:33.0598 6044 KtmRm - ok 22:31:33.0644 6044 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll 22:31:33.0644 6044 LanmanServer - ok 22:31:33.0722 6044 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 22:31:33.0722 6044 LanmanWorkstation - ok 22:31:33.0769 6044 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 22:31:33.0769 6044 lltdio - ok 22:31:33.0816 6044 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 22:31:33.0832 6044 lltdsvc - ok 22:31:33.0863 6044 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 22:31:33.0863 6044 lmhosts - ok 22:31:33.0910 6044 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 22:31:34.0050 6044 LSI_FC - ok 22:31:34.0081 6044 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 22:31:34.0081 6044 LSI_SAS - ok 22:31:34.0128 6044 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 22:31:34.0144 6044 LSI_SAS2 - ok 22:31:34.0159 6044 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 22:31:34.0159 6044 LSI_SCSI - ok 22:31:34.0175 6044 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 22:31:34.0175 6044 luafv - ok 22:31:34.0222 6044 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 22:31:34.0222 6044 Mcx2Svc - ok 22:31:34.0284 6044 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 22:31:34.0284 6044 MDM - ok 22:31:34.0315 6044 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 22:31:34.0315 6044 megasas - ok 22:31:34.0346 6044 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 22:31:34.0346 6044 MegaSR - ok 22:31:34.0393 6044 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 22:31:34.0393 6044 MMCSS - ok 22:31:34.0424 6044 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 22:31:34.0424 6044 Modem - ok 22:31:34.0456 6044 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 22:31:34.0456 6044 monitor - ok 22:31:34.0487 6044 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 22:31:34.0487 6044 mouclass - ok 22:31:34.0518 6044 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 22:31:34.0518 6044 mouhid - ok 22:31:34.0565 6044 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 22:31:34.0565 6044 mountmgr - ok 22:31:34.0612 6044 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 22:31:34.0612 6044 mpio - ok 22:31:34.0627 6044 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 22:31:34.0627 6044 mpsdrv - ok 22:31:34.0690 6044 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll 22:31:34.0690 6044 MpsSvc - ok 22:31:34.0736 6044 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 22:31:34.0736 6044 MRxDAV - ok 22:31:34.0783 6044 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 22:31:34.0799 6044 mrxsmb - ok 22:31:34.0830 6044 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 22:31:34.0846 6044 mrxsmb10 - ok 22:31:34.0908 6044 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 22:31:34.0908 6044 mrxsmb20 - ok 22:31:34.0924 6044 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 22:31:34.0924 6044 msahci - ok 22:31:34.0955 6044 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 22:31:34.0955 6044 msdsm - ok 22:31:34.0970 6044 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 22:31:34.0970 6044 MSDTC - ok 22:31:35.0017 6044 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 22:31:35.0017 6044 Msfs - ok 22:31:35.0033 6044 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 22:31:35.0048 6044 mshidkmdf - ok 22:31:35.0080 6044 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 22:31:35.0080 6044 msisadrv - ok 22:31:35.0126 6044 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 22:31:35.0126 6044 MSiSCSI - ok 22:31:35.0126 6044 msiserver - ok 22:31:35.0189 6044 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 22:31:35.0189 6044 MSKSSRV - ok 22:31:35.0204 6044 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 22:31:35.0204 6044 MSPCLOCK - ok 22:31:35.0204 6044 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 22:31:35.0204 6044 MSPQM - ok 22:31:35.0251 6044 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 22:31:35.0251 6044 MsRPC - ok 22:31:35.0298 6044 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 22:31:35.0298 6044 mssmbios - ok 22:31:35.0345 6044 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 22:31:35.0345 6044 MSTEE - ok 22:31:35.0345 6044 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 22:31:35.0345 6044 MTConfig - ok 22:31:35.0423 6044 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 22:31:35.0423 6044 Mup - ok 22:31:35.0470 6044 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 22:31:35.0485 6044 napagent - ok 22:31:35.0532 6044 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 22:31:35.0532 6044 NativeWifiP - ok 22:31:35.0626 6044 [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS C:\Windows\system32\drivers\ndis.sys 22:31:35.0641 6044 NDIS - ok 22:31:35.0672 6044 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 22:31:35.0672 6044 NdisCap - ok 22:31:35.0704 6044 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 22:31:35.0704 6044 NdisTapi - ok 22:31:35.0750 6044 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 22:31:35.0750 6044 Ndisuio - ok 22:31:35.0797 6044 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 22:31:35.0797 6044 NdisWan - ok 22:31:35.0844 6044 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 22:31:35.0844 6044 NDProxy - ok 22:31:35.0875 6044 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 22:31:35.0875 6044 NetBIOS - ok 22:31:35.0922 6044 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 22:31:35.0938 6044 NetBT - ok 22:31:35.0953 6044 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 22:31:35.0953 6044 Netlogon - ok 22:31:35.0984 6044 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 22:31:35.0984 6044 Netman - ok 22:31:36.0016 6044 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 22:31:36.0016 6044 netprofm - ok 22:31:36.0047 6044 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 22:31:36.0047 6044 NetTcpPortSharing - ok 22:31:36.0078 6044 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 22:31:36.0078 6044 nfrd960 - ok 22:31:36.0140 6044 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll 22:31:36.0156 6044 NlaSvc - ok 22:31:36.0156 6044 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 22:31:36.0172 6044 Npfs - ok 22:31:36.0203 6044 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 22:31:36.0203 6044 nsi - ok 22:31:36.0218 6044 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 22:31:36.0218 6044 nsiproxy - ok 22:31:36.0312 6044 [ A2F74975097F52A00745F9637451FDD8 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 22:31:36.0328 6044 Ntfs - ok 22:31:36.0390 6044 [ 4C08A14D04E62963E96E0BB57BBC953B ] NuidFltr C:\Windows\system32\DRIVERS\NuidFltr.sys 22:31:36.0390 6044 NuidFltr - ok 22:31:36.0421 6044 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 22:31:36.0421 6044 Null - ok 22:31:36.0452 6044 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 22:31:36.0452 6044 nvraid - ok 22:31:36.0499 6044 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 22:31:36.0499 6044 nvstor - ok 22:31:36.0530 6044 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 22:31:36.0530 6044 nv_agp - ok 22:31:36.0546 6044 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 22:31:36.0546 6044 ohci1394 - ok 22:31:36.0593 6044 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 22:31:36.0593 6044 ose - ok 22:31:36.0655 6044 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 22:31:36.0655 6044 p2pimsvc - ok 22:31:36.0686 6044 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 22:31:36.0702 6044 p2psvc - ok 22:31:36.0733 6044 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys 22:31:36.0733 6044 Parport - ok 22:31:36.0780 6044 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 22:31:36.0780 6044 partmgr - ok 22:31:36.0811 6044 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 22:31:36.0811 6044 PcaSvc - ok 22:31:36.0874 6044 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 22:31:36.0874 6044 pci - ok 22:31:36.0889 6044 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 22:31:36.0889 6044 pciide - ok 22:31:36.0920 6044 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 22:31:36.0936 6044 pcmcia - ok 22:31:36.0983 6044 [ AF7CE12C4F3DC8CB2B07685C916BBCFE ] pcouffin C:\Windows\system32\Drivers\pcouffin.sys 22:31:36.0983 6044 pcouffin - ok 22:31:37.0014 6044 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 22:31:37.0014 6044 pcw - ok 22:31:37.0045 6044 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 22:31:37.0045 6044 PEAUTH - ok 22:31:37.0123 6044 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 22:31:37.0123 6044 PerfHost - ok 22:31:37.0217 6044 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 22:31:37.0248 6044 pla - ok 22:31:37.0388 6044 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 22:31:37.0388 6044 PlugPlay - ok 22:31:37.0420 6044 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 22:31:37.0420 6044 PNRPAutoReg - ok 22:31:37.0435 6044 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 22:31:37.0435 6044 PNRPsvc - ok 22:31:37.0498 6044 [ B8D8EC78B0F9ED8E220506181274F3D3 ] Point64 C:\Windows\system32\DRIVERS\point64.sys 22:31:37.0498 6044 Point64 - ok 22:31:37.0544 6044 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 22:31:37.0560 6044 PolicyAgent - ok 22:31:37.0591 6044 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 22:31:37.0591 6044 Power - ok 22:31:37.0622 6044 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 22:31:37.0622 6044 PptpMiniport - ok 22:31:37.0654 6044 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys 22:31:37.0654 6044 Processor - ok 22:31:37.0700 6044 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 22:31:37.0716 6044 ProfSvc - ok 22:31:37.0732 6044 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 22:31:37.0732 6044 ProtectedStorage - ok 22:31:37.0778 6044 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 22:31:37.0794 6044 Psched - ok 22:31:37.0856 6044 [ A6A7AD767BF5141665F5C675F671B3E1 ] PSI_SVC_2 c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe 22:31:37.0856 6044 PSI_SVC_2 - ok 22:31:37.0888 6044 [ 4712CC14E720ECCCC0AA16949D18AAF1 ] PxHlpa64 C:\Windows\system32\Drivers\PxHlpa64.sys 22:31:37.0888 6044 PxHlpa64 - ok 22:31:37.0950 6044 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 22:31:37.0981 6044 ql2300 - ok 22:31:37.0997 6044 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 22:31:37.0997 6044 ql40xx - ok 22:31:38.0044 6044 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 22:31:38.0044 6044 QWAVE - ok 22:31:38.0075 6044 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 22:31:38.0075 6044 QWAVEdrv - ok 22:31:38.0106 6044 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 22:31:38.0106 6044 RasAcd - ok 22:31:38.0137 6044 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 22:31:38.0137 6044 RasAgileVpn - ok 22:31:38.0168 6044 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 22:31:38.0168 6044 RasAuto - ok 22:31:38.0231 6044 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 22:31:38.0231 6044 Rasl2tp - ok 22:31:38.0293 6044 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 22:31:38.0293 6044 RasMan - ok 22:31:38.0340 6044 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 22:31:38.0340 6044 RasPppoe - ok 22:31:38.0356 6044 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 22:31:38.0371 6044 RasSstp - ok 22:31:38.0418 6044 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 22:31:38.0418 6044 rdbss - ok 22:31:38.0449 6044 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 22:31:38.0449 6044 rdpbus - ok 22:31:38.0480 6044 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 22:31:38.0480 6044 RDPCDD - ok 22:31:38.0496 6044 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 22:31:38.0496 6044 RDPENCDD - ok 22:31:38.0512 6044 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 22:31:38.0512 6044 RDPREFMP - ok 22:31:38.0558 6044 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 22:31:38.0558 6044 RDPWD - ok 22:31:38.0605 6044 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 22:31:38.0605 6044 rdyboost - ok 22:31:38.0636 6044 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 22:31:38.0636 6044 RemoteAccess - ok 22:31:38.0668 6044 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 22:31:38.0668 6044 RemoteRegistry - ok 22:31:38.0714 6044 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 22:31:38.0730 6044 RpcEptMapper - ok 22:31:38.0761 6044 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 22:31:38.0761 6044 RpcLocator - ok 22:31:38.0808 6044 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll 22:31:38.0808 6044 RpcSs - ok 22:31:38.0886 6044 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 22:31:38.0886 6044 rspndr - ok 22:31:38.0933 6044 [ 4A25DC970C58104602ED274DACAFD784 ] RSUSBSTOR C:\Windows\system32\Drivers\RtsUStor.sys 22:31:38.0933 6044 RSUSBSTOR - ok 22:31:38.0948 6044 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 22:31:38.0948 6044 SamSs - ok 22:31:38.0995 6044 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 22:31:38.0995 6044 sbp2port - ok 22:31:39.0104 6044 [ 794D4B48DFB6E999537C7C3947863463 ] SBSDWSCService C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe 22:31:39.0104 6044 SBSDWSCService - ok 22:31:39.0167 6044 [ F9C85B83954B976702AA8E61B77D9C68 ] sbtis C:\Windows\system32\drivers\sbtis.sys 22:31:39.0167 6044 sbtis - ok 22:31:39.0198 6044 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 22:31:39.0214 6044 SCardSvr - ok 22:31:39.0245 6044 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 22:31:39.0245 6044 scfilter - ok 22:31:39.0323 6044 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 22:31:39.0338 6044 Schedule - ok 22:31:39.0385 6044 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 22:31:39.0385 6044 SCPolicySvc - ok 22:31:39.0432 6044 [ 003EE6F643B8336837150B4E28D2531B ] ScReadSpool C:\Program Files (x86)\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe 22:31:39.0432 6044 ScReadSpool - ok 22:31:39.0479 6044 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 22:31:39.0479 6044 SDRSVC - ok 22:31:39.0510 6044 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 22:31:39.0510 6044 secdrv - ok 22:31:39.0557 6044 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 22:31:39.0557 6044 seclogon - ok 22:31:39.0588 6044 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll 22:31:39.0588 6044 SENS - ok 22:31:39.0635 6044 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 22:31:39.0635 6044 SensrSvc - ok 22:31:39.0650 6044 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 22:31:39.0666 6044 Serenum - ok 22:31:39.0697 6044 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys 22:31:39.0713 6044 Serial - ok 22:31:39.0760 6044 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 22:31:39.0760 6044 sermouse - ok 22:31:39.0822 6044 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 22:31:39.0822 6044 SessionEnv - ok 22:31:39.0869 6044 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 22:31:39.0869 6044 sffdisk - ok 22:31:39.0869 6044 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 22:31:39.0884 6044 sffp_mmc - ok 22:31:39.0884 6044 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 22:31:39.0884 6044 sffp_sd - ok 22:31:39.0916 6044 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 22:31:39.0916 6044 sfloppy - ok 22:31:40.0025 6044 [ 74EC60E20516AAA573BE74F31175270F ] SftService C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.exe 22:31:40.0040 6044 SftService - ok 22:31:40.0087 6044 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll 22:31:40.0087 6044 SharedAccess - ok 22:31:40.0134 6044 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 22:31:40.0134 6044 ShellHWDetection - ok 22:31:40.0165 6044 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 22:31:40.0165 6044 SiSRaid2 - ok 22:31:40.0181 6044 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 22:31:40.0181 6044 SiSRaid4 - ok 22:31:40.0274 6044 [ DDAA5F4A6B958FC313EBD02DD925752F ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 22:31:40.0274 6044 SkypeUpdate - ok 22:31:40.0321 6044 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 22:31:40.0321 6044 Smb - ok 22:31:40.0352 6044 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 22:31:40.0352 6044 SNMPTRAP - ok 22:31:40.0384 6044 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 22:31:40.0384 6044 spldr - ok 22:31:40.0430 6044 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 22:31:40.0446 6044 Spooler - ok 22:31:40.0571 6044 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 22:31:40.0633 6044 sppsvc - ok 22:31:40.0664 6044 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 22:31:40.0664 6044 sppuinotify - ok 22:31:40.0742 6044 [ D630B6F2E8379B6F10DC16E82A426552 ] sprtsvc_DellSupportCenter C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe 22:31:40.0742 6044 sprtsvc_DellSupportCenter - ok 22:31:40.0805 6044 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 22:31:40.0805 6044 srv - ok 22:31:40.0836 6044 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 22:31:40.0836 6044 srv2 - ok 22:31:40.0898 6044 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 22:31:40.0898 6044 srvnet - ok 22:31:40.0945 6044 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 22:31:40.0961 6044 SSDPSRV - ok 22:31:40.0961 6044 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 22:31:40.0976 6044 SstpSvc - ok 22:31:41.0070 6044 [ 444109453A2B87E6C16BCDA5953E81A9 ] STacSV C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe 22:31:41.0070 6044 STacSV - ok 22:31:41.0117 6044 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 22:31:41.0117 6044 stexstor - ok 22:31:41.0148 6044 [ 02E784FA49032F84964DB90A3ED81890 ] STHDA C:\Windows\system32\DRIVERS\stwrt64.sys 22:31:41.0164 6044 STHDA - ok 22:31:41.0210 6044 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 22:31:41.0226 6044 stisvc - ok 22:31:41.0273 6044 [ 745E8BDD1AD92BCE97DBCF1BA60D4045 ] SUSTUCAM C:\Windows\system32\DRIVERS\sustucam.sys 22:31:41.0273 6044 SUSTUCAM - ok 22:31:41.0304 6044 [ C7C1C5CA51447B273A6C8BC972397BA5 ] SUSTUCAP C:\Windows\system32\DRIVERS\sustucap.sys 22:31:41.0304 6044 SUSTUCAP - ok 22:31:41.0320 6044 [ A69A9A9FE119907E85BB30CDFBFB2A38 ] SUSTUCAU C:\Windows\system32\DRIVERS\sustucau.sys 22:31:41.0320 6044 SUSTUCAU - ok 22:31:41.0366 6044 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys 22:31:41.0366 6044 swenum - ok 22:31:41.0413 6044 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 22:31:41.0429 6044 swprv - ok 22:31:41.0522 6044 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 22:31:41.0538 6044 SysMain - ok 22:31:41.0585 6044 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 22:31:41.0585 6044 TabletInputService - ok 22:31:41.0632 6044 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 22:31:41.0632 6044 TapiSrv - ok 22:31:41.0678 6044 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 22:31:41.0678 6044 TBS - ok 22:31:41.0756 6044 [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 22:31:41.0788 6044 Tcpip - ok 22:31:41.0866 6044 [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 22:31:41.0881 6044 TCPIP6 - ok 22:31:41.0912 6044 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 22:31:41.0912 6044 tcpipreg - ok 22:31:41.0959 6044 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 22:31:41.0959 6044 TDPIPE - ok 22:31:42.0006 6044 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 22:31:42.0006 6044 TDTCP - ok 22:31:42.0068 6044 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 22:31:42.0068 6044 tdx - ok 22:31:42.0115 6044 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys 22:31:42.0115 6044 TermDD - ok 22:31:42.0162 6044 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 22:31:42.0178 6044 TermService - ok 22:31:42.0209 6044 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 22:31:42.0209 6044 Themes - ok 22:31:42.0224 6044 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 22:31:42.0240 6044 THREADORDER - ok 22:31:42.0271 6044 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 22:31:42.0271 6044 TrkWks - ok 22:31:42.0334 6044 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 22:31:42.0334 6044 TrustedInstaller - ok 22:31:42.0380 6044 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 22:31:42.0380 6044 tssecsrv - ok 22:31:42.0443 6044 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 22:31:42.0443 6044 TsUsbFlt - ok 22:31:42.0505 6044 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 22:31:42.0505 6044 tunnel - ok 22:31:42.0552 6044 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 22:31:42.0552 6044 uagp35 - ok 22:31:42.0599 6044 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 22:31:42.0614 6044 udfs - ok 22:31:42.0646 6044 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 22:31:42.0646 6044 UI0Detect - ok 22:31:42.0677 6044 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 22:31:42.0677 6044 uliagpkx - ok 22:31:42.0739 6044 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys 22:31:42.0739 6044 umbus - ok 22:31:42.0770 6044 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 22:31:42.0770 6044 UmPass - ok 22:31:42.0802 6044 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 22:31:42.0817 6044 upnphost - ok 22:31:42.0864 6044 [ 5CF1EAD086176DD3348E920A40BED03D ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys 22:31:42.0864 6044 USBAAPL64 - ok 22:31:42.0911 6044 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 22:31:42.0911 6044 usbccgp - ok 22:31:42.0973 6044 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 22:31:42.0973 6044 usbcir - ok 22:31:42.0989 6044 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 22:31:42.0989 6044 usbehci - ok 22:31:43.0051 6044 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 22:31:43.0067 6044 usbhub - ok 22:31:43.0082 6044 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys 22:31:43.0082 6044 usbohci - ok 22:31:43.0114 6044 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 22:31:43.0114 6044 usbprint - ok 22:31:43.0160 6044 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys 22:31:43.0160 6044 usbscan - ok 22:31:43.0223 6044 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\drivers\USBSTOR.SYS 22:31:43.0223 6044 USBSTOR - ok 22:31:43.0238 6044 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 22:31:43.0238 6044 usbuhci - ok 22:31:43.0332 6044 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys 22:31:43.0332 6044 usbvideo - ok 22:31:43.0363 6044 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 22:31:43.0363 6044 UxSms - ok 22:31:43.0379 6044 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 22:31:43.0379 6044 VaultSvc - ok 22:31:43.0441 6044 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 22:31:43.0441 6044 vdrvroot - ok 22:31:43.0519 6044 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 22:31:43.0519 6044 vds - ok 22:31:43.0566 6044 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 22:31:43.0566 6044 vga - ok 22:31:43.0597 6044 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 22:31:43.0597 6044 VgaSave - ok 22:31:43.0660 6044 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 22:31:43.0675 6044 vhdmp - ok 22:31:43.0706 6044 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 22:31:43.0722 6044 viaide - ok 22:31:43.0753 6044 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 22:31:43.0753 6044 volmgr - ok 22:31:43.0800 6044 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 22:31:43.0800 6044 volmgrx - ok 22:31:43.0831 6044 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 22:31:43.0831 6044 volsnap - ok 22:31:43.0909 6044 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 22:31:43.0909 6044 vsmraid - ok 22:31:44.0003 6044 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 22:31:44.0018 6044 VSS - ok 22:31:44.0128 6044 [ EF51747440486C23BD466311048BD924 ] vToolbarUpdater12.2.0 C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.0\ToolbarUpdater.exe 22:31:44.0143 6044 vToolbarUpdater12.2.0 - ok 22:31:44.0174 6044 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 22:31:44.0174 6044 vwifibus - ok 22:31:44.0190 6044 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 22:31:44.0190 6044 vwififlt - ok 22:31:44.0252 6044 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys 22:31:44.0252 6044 vwifimp - ok 22:31:44.0284 6044 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 22:31:44.0299 6044 W32Time - ok 22:31:44.0330 6044 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 22:31:44.0346 6044 WacomPen - ok 22:31:44.0408 6044 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 22:31:44.0408 6044 WANARP - ok 22:31:44.0424 6044 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 22:31:44.0424 6044 Wanarpv6 - ok 22:31:44.0486 6044 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 22:31:44.0502 6044 WatAdminSvc - ok 22:31:44.0580 6044 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 22:31:44.0596 6044 wbengine - ok 22:31:44.0627 6044 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 22:31:44.0627 6044 WbioSrvc - ok 22:31:44.0689 6044 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 22:31:44.0689 6044 wcncsvc - ok 22:31:44.0705 6044 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 22:31:44.0705 6044 WcsPlugInService - ok 22:31:44.0736 6044 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys 22:31:44.0736 6044 Wd - ok 22:31:44.0814 6044 [ A3D04EBF5227886029B4532F20D026F7 ] WDC_SAM C:\Windows\system32\DRIVERS\wdcsam64.sys 22:31:44.0814 6044 WDC_SAM - ok 22:31:44.0845 6044 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 22:31:44.0845 6044 Wdf01000 - ok 22:31:44.0892 6044 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 22:31:44.0892 6044 WdiServiceHost - ok 22:31:44.0892 6044 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 22:31:44.0908 6044 WdiSystemHost - ok 22:31:44.0954 6044 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 22:31:44.0970 6044 WebClient - ok 22:31:44.0986 6044 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 22:31:45.0001 6044 Wecsvc - ok 22:31:45.0032 6044 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 22:31:45.0032 6044 wercplsupport - ok 22:31:45.0064 6044 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 22:31:45.0064 6044 WerSvc - ok 22:31:45.0095 6044 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 22:31:45.0095 6044 WfpLwf - ok 22:31:45.0142 6044 [ B14EF15BD757FA488F9C970EEE9C0D35 ] WimFltr C:\Windows\system32\DRIVERS\wimfltr.sys 22:31:45.0142 6044 WimFltr - ok 22:31:45.0157 6044 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 22:31:45.0157 6044 WIMMount - ok 22:31:45.0204 6044 WinDefend - ok 22:31:45.0220 6044 WinHttpAutoProxySvc - ok 22:31:45.0282 6044 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 22:31:45.0282 6044 Winmgmt - ok 22:31:45.0391 6044 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 22:31:45.0407 6044 WinRM - ok 22:31:45.0500 6044 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 22:31:45.0500 6044 WinUsb - ok 22:31:45.0563 6044 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 22:31:45.0563 6044 Wlansvc - ok 22:31:45.0610 6044 [ 13B0A570E1AE451C92DA550085D72CF3 ] wltrysvc C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE 22:31:45.0610 6044 wltrysvc - ok 22:31:45.0703 6044 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 22:31:45.0703 6044 WmiAcpi - ok 22:31:45.0750 6044 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 22:31:45.0750 6044 wmiApSrv - ok 22:31:45.0797 6044 WMPNetworkSvc - ok 22:31:45.0812 6044 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 22:31:45.0812 6044 WPCSvc - ok 22:31:45.0890 6044 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 22:31:45.0890 6044 WPDBusEnum - ok 22:31:45.0922 6044 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 22:31:45.0922 6044 ws2ifsl - ok 22:31:45.0968 6044 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll 22:31:45.0968 6044 wscsvc - ok 22:31:45.0984 6044 WSearch - ok 22:31:46.0093 6044 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 22:31:46.0124 6044 wuauserv - ok 22:31:46.0171 6044 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 22:31:46.0171 6044 WudfPf - ok 22:31:46.0202 6044 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 22:31:46.0218 6044 WUDFRd - ok 22:31:46.0265 6044 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 22:31:46.0265 6044 wudfsvc - ok 22:31:46.0296 6044 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll 22:31:46.0296 6044 WwanSvc - ok 22:31:46.0343 6044 [ 64F88AF327AA74E03658AE32B48CCB8B ] yukonw7 C:\Windows\system32\DRIVERS\yk62x64.sys 22:31:46.0358 6044 yukonw7 - ok 22:31:46.0374 6044 ================ Scan global =============================== 22:31:46.0405 6044 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 22:31:46.0452 6044 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll 22:31:46.0468 6044 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll 22:31:46.0499 6044 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 22:31:46.0530 6044 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 22:31:46.0530 6044 [Global] - ok 22:31:46.0530 6044 ================ Scan MBR ================================== 22:31:46.0546 6044 [ CDB4DE4BBD714F152979DA2DCBEF57EB ] \Device\Harddisk0\DR0 22:31:46.0546 6044 Suspicious mbr (Forged): \Device\Harddisk0\DR0 22:31:46.0592 6044 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected 22:31:46.0592 6044 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0) 22:31:46.0592 6044 ================ Scan VBR ================================== 22:31:46.0608 6044 [ 9025F5F50A56850B1F101CD31FC80309 ] \Device\Harddisk0\DR0\Partition1 22:31:46.0608 6044 \Device\Harddisk0\DR0\Partition1 - ok 22:31:46.0624 6044 [ B8423112AD17DD9169A457BB0123942B ] \Device\Harddisk0\DR0\Partition2 22:31:46.0624 6044 \Device\Harddisk0\DR0\Partition2 - ok 22:31:46.0624 6044 ============================================================ 22:31:46.0624 6044 Scan finished 22:31:46.0624 6044 ============================================================ 22:31:46.0639 5552 Detected object count: 1 22:31:46.0639 5552 Actual detected object count: 1 22:32:34.0867 5552 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - skipped by user 22:32:34.0867 5552 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - User select action: Skip 22:33:01.0038 6132 Deinitialize success
OK got it done. This log is smaller. Does that mean TDSSkiller removed those rootkits? Recall when we started all this AVG had found 28 of them? Did TDSSkiller get them all? Anyway here is the TDSSkiller log after I selected cure and thanks for hanging in there with me: 11:17:18.0050 2204 TDSS rootkit removing tool [removed] Aug 20 2012 17:30:03 11:17:18.0846 2204 ============================================================ 11:17:18.0846 2204 Current date / time: 2012/08/23 11:17:18.0846 11:17:18.0846 2204 SystemInfo: 11:17:18.0846 2204 11:17:18.0846 2204 OS Version: 6.1.7601 ServicePack: 1.0 11:17:18.0846 2204 Product type: Workstation 11:17:18.0846 2204 ComputerName: MANUEL-PC 11:17:18.0846 2204 UserName: Manuel 11:17:18.0846 2204 Windows directory: C:\Windows 11:17:18.0846 2204 System windows directory: C:\Windows 11:17:18.0846 2204 Running under WOW64 11:17:18.0846 2204 Processor architecture: Intel x64 11:17:18.0846 2204 Number of processors: 2 11:17:18.0846 2204 Page size: 0x1000 11:17:18.0846 2204 Boot type: Normal boot 11:17:18.0846 2204 ============================================================ 11:17:19.0033 2204 BG loaded 11:17:19.0782 2204 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 11:17:19.0782 2204 ============================================================ 11:17:19.0782 2204 \Device\Harddisk0\DR0: 11:17:19.0782 2204 MBR partitions: 11:17:19.0782 2204 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x95800, BlocksNum 0x25C0000 11:17:19.0782 2204 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x2655800, BlocksNum 0x1AB6F970 11:17:19.0782 2204 ============================================================ 11:17:19.0922 2204 C: <-> \Device\Harddisk0\DR0\Partition2 11:17:19.0922 2204 ============================================================ 11:17:19.0922 2204 Initialize success 11:17:19.0922 2204 ============================================================
That is looking better. :thumbup: Please run a new scan with FRST and post that new log. ——— Run new scans with Malwarebytes and ESET and post those logs as well. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI