This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Registry problems? [Solved]

37 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi WTT,

My Trend Micro software is blocking the same (3) web pages every minute (30 seconds when computer is on for a while). I couldn't figure out how to attach a screen grab of the Trend Micro dialog box so I attached it below, if it's of any interest to you.

And I cannot get to google.com. Computer seems to be a bit slower but no other 'major' issues. I ran OTL….logs below. Thanks for looking!


OTL logfile created on: 8/17/2012 16:53:17 - Run 1
OTL by OldTimer - Version 3.2.57.0 Folder = C:\Users\Nikki\Downloads
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.41 Mb Total Physical Memory | 464.34 Mb Available Physical Memory | 45.77% Memory free
2.05 Gb Paging File | 0.75 Gb Available in Paging File | 36.58% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74.43 Gb Total Space | 42.79 Gb Free Space | 57.50% Space Free | Partition Type: NTFS

Computer Name: HANNAH | User Name: Nikki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Nikki\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Office\Office14\WINWORD.EXE (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\TmListen.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\NTRtScan.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe (Trend Micro Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (tmlisten) – C:\Program Files\Trend Micro\OfficeScan Client\TmListen.exe (Trend Micro Inc.)
SRV - (ntrtscan) – C:\Program Files\Trend Micro\OfficeScan Client\NTRtScan.exe (Trend Micro Inc.)
SRV - (TmProxy) – C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe (Trend Micro Inc.)
SRV - (TMBMServer) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (TmFilter) – C:\Program Files\Trend Micro\OfficeScan Client\TmXPFlt.sys (Trend Micro Inc.)
DRV - (TmPreFilter) – C:\Program Files\Trend Micro\OfficeScan Client\tmpreflt.sys (Trend Micro Inc.)
DRV - (VSApiNt) – C:\Program Files\Trend Micro\OfficeScan Client\vsapiNT.sys (Trend Micro Inc.)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (dmvsc) – C:\Windows\System32\drivers\dmvsc.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbGD) – C:\Windows\System32\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (tmactmon) – C:\Windows\System32\drivers\tmactmon.sys (Trend Micro Inc.)
DRV - (tmevtmgr) – C:\Windows\System32\drivers\tmevtmgr.sys (Trend Micro Inc.)
DRV - (tmcomm) – C:\Windows\System32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (tmtdi) – C:\Windows\System32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (TPM) – C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (netw5v32) – C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (e1express) – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.jsonline.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 02 18 E6 8B 90 C6 CC 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…1I7GGHP_enUS464
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)



O1 HOSTS File: ([2009/06/10 16:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [OfficeScanNT Monitor] C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe (Trend Micro Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Nikki\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{784526E1-2CAB-4226-A604-BAE8146403EA}: DhcpNameServer = 10.130.10.43 10.130.10.45 10.130.10.44 10.135.10.43 10.5.10.43
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F3FDBC7D-2202-4E15-81D9-36B7C6B69698}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{aa5c31ca-4227-11e1-8b40-00197de9d644}\Shell - "" = AutoRun
O33 - MountPoints2\{aa5c31ca-4227-11e1-8b40-00197de9d644}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/08/17 15:33:57 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{4C2B0B7C-8775-4254-A7B1-917A18AFEB96}
[2012/08/17 15:33:41 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{65F6150E-A337-46AD-B926-DC0C4FBB4EE6}
[2012/08/16 20:48:31 | 000,400,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srcore.dll
[2012/08/16 20:43:30 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/08/16 20:43:29 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/08/16 20:43:29 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2012/08/16 20:43:28 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/08/16 20:43:28 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/08/16 20:43:27 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/08/16 20:43:26 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/08/16 20:22:25 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2012/08/16 18:00:01 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Roaming\Systweak
[2012/08/16 17:59:58 | 000,017,320 | —- | C] (Systweak Inc., (www.systweak.com)) – C:\Windows\System32\roboot.exe
[2012/08/16 17:26:51 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{D68FEF37-AB3E-4419-8A0D-61AF5665C4FA}
[2012/08/16 17:26:28 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{ABE48FA9-C17C-448F-8C11-DF4BFCCB84DF}
[2012/08/16 17:04:27 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Roaming\SpeedyPC Software
[2012/08/16 17:04:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SpeedyPC Software
[2012/08/16 17:04:04 | 000,000,000 | —D | C] – C:\ProgramData\SpeedyPC Software
[2012/08/16 17:04:04 | 000,000,000 | —D | C] – C:\Program Files\SpeedyPC Software
[2012/08/16 16:52:59 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Roaming\DriverCure
[2012/08/16 16:52:58 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Roaming\SpeedMaxPc
[2012/08/16 16:52:33 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SpeedMaxPc
[2012/08/16 16:52:28 | 000,000,000 | —D | C] – C:\ProgramData\SpeedMaxPc
[2012/08/16 16:52:28 | 000,000,000 | —D | C] – C:\Program Files\SpeedMaxPc
[2012/08/16 15:29:02 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/08/16 15:19:57 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{E4870D0A-2E8D-41A6-92E8-7D46A49B3F8C}
[2012/08/15 19:02:36 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{E44BC0DF-7BDD-4F89-957C-D9EB9AD21473}
[2012/08/15 19:02:21 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{87BD7986-F224-4A88-8498-0FE17F69C168}
[2012/08/13 06:11:03 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{202F5A57-6558-428C-A4EA-F44176A7AE93}
[2012/08/13 06:10:48 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{332B9CDD-A6FA-4F73-8D7F-97431357DC36}
[2012/08/12 08:45:47 | 000,000,000 | —D | C] – C:\Program Files\Synaptics
[2012/08/12 08:41:33 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\ElevatedDiagnostics
[2012/08/12 06:38:21 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{DAB854D8-9B5C-4460-A682-F92DEAB064D9}
[2012/08/12 06:38:09 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{16B45AFC-2410-417A-A0B8-CE9C15432E0E}
[2012/08/06 14:15:48 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{A14601A2-2482-470C-973C-245F8F3B18CB}
[2012/08/05 20:26:49 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{1B966F84-C8EC-426D-A300-FFC0C8390DF6}
[2012/08/05 05:41:50 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{EB29C971-7B9A-4622-9DB9-773BFB56FE3D}
[2012/08/04 16:37:31 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{EA1A9549-E44C-4F9D-9EC0-1D9E42815577}
[2012/08/04 16:37:14 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{786BF141-399E-4253-B204-5619C92356AA}
[2012/07/28 05:38:01 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{607BC6D5-F828-4C84-9081-E5DF56338598}
[2012/07/27 15:32:13 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{273E2D39-C65D-4E59-BD06-8489BD623601}
[2012/07/27 15:31:57 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{4C8B99C7-7740-40AA-BA01-BB9931578960}
[2012/07/26 15:37:27 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{20716A81-1353-4C2E-B81B-2AD8F5ED95AF}
[2012/07/26 15:37:12 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{BF51473E-8190-4B33-AA11-E36D5B0012A6}
[2012/07/25 21:16:07 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{68BDA168-F1E0-4654-8073-E86026AF03C6}
[2012/07/25 21:15:53 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{5657AF53-17C3-47D3-8CE8-3A408ED4FCF3}
[2012/07/24 15:09:18 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{971F8D96-3DDB-4A39-B5C1-A3C4802E9187}
[2012/07/24 15:09:05 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{BE8060AC-3EE6-4CB1-88D2-4FA754090BAB}
[2012/07/23 15:59:24 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{ADBCE486-B8BB-498B-8CA6-E03636217F01}
[2012/07/23 15:59:13 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{B1ED65E1-BD82-4914-BD48-92E178D5D4ED}
[2012/07/22 06:13:20 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{9028F9F6-FCCC-4FBF-8031-7D4AD8505587}
[2012/07/22 06:12:54 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{B398B234-389E-4F87-A646-0C9BB002B8AA}

========== Files - Modified Within 30 Days ==========

[2012/08/17 16:22:04 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/17 16:07:05 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/08/17 15:51:29 | 000,032,224 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/17 15:51:29 | 000,032,224 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/17 15:33:10 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/17 15:32:32 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/08/17 15:32:22 | 797,765,632 | -HS- | M] () – C:\hiberfil.sys
[2012/08/16 20:22:18 | 271,368,644 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/08/16 18:07:21 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/08/16 18:07:21 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/08/16 17:49:19 | 000,026,883 | —- | M] () – C:\Users\Nikki\Desktop\Trend Capture.PNG
[2012/08/16 16:52:40 | 000,000,376 | —- | M] () – C:\Windows\tasks\SpeedMaxPc.job

========== Files Created - No Company Name ==========

[2012/08/16 20:22:18 | 271,368,644 | —- | C] () – C:\Windows\MEMORY.DMP
[2012/08/16 17:49:19 | 000,026,883 | —- | C] () – C:\Users\Nikki\Desktop\Trend Capture.PNG
[2012/08/16 16:52:35 | 000,000,376 | —- | C] () – C:\Windows\tasks\SpeedMaxPc.job
[2011/12/22 20:01:12 | 000,033,134 | —- | C] () – C:\Users\Nikki\AppData\Roaming\UserTile.png
[2011/12/16 10:03:41 | 000,021,432 | —- | C] () – C:\Windows\cfgall.ini
[2010/11/20 16:29:26 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe

========== LOP Check ==========

[2012/08/16 16:52:59 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\DriverCure
[2012/03/17 17:47:21 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\DVDVideoSoft
[2012/03/17 17:46:55 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\DVDVideoSoftIEHelpers
[2012/01/19 18:48:11 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\f-secure
[2012/08/16 16:52:58 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\SpeedMaxPc
[2012/08/16 17:04:27 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\SpeedyPC Software
[2012/08/16 18:07:34 | 000,000,000 | —D | M] – C:\Users\Nikki\AppData\Roaming\Systweak
[2009/07/13 23:53:46 | 000,026,116 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2012/08/16 16:52:40 | 000,000,376 | —- | M] () – C:\Windows\Tasks\SpeedMaxPc.job

========== Purity Check ==========



========== Custom Scans ==========

< >

< >

< %SYSTEMDRIVE%\*.* >
[2009/06/10 16:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/10 16:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2012/08/17 15:32:22 | 797,765,632 | -HS- | M] () – C:\hiberfil.sys
[2012/03/17 17:42:59 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/03/17 17:42:59 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/08/17 16:48:16 | 1140,850,688 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/13 23:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 23:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 23:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 23:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 20:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2010/11/20 16:29:21 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 23:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/01/16 18:37:08 | 000,000,221 | -HS- | M] () – C:\Users\Nikki\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-08-17 20:48:02

< >

< >

< >

< >

< End of report >

OTL Extras logfile created on: 8/17/2012 16:53:17 - Run 1
OTL by OldTimer - Version 3.2.57.0 Folder = C:\Users\Nikki\Downloads
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.41 Mb Total Physical Memory | 464.34 Mb Available Physical Memory | 45.77% Memory free
2.05 Gb Paging File | 0.75 Gb Available in Paging File | 36.58% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74.43 Gb Total Space | 42.79 Gb Free Space | 57.50% Space Free | Partition Type: NTFS

Computer Name: HANNAH | User Name: Nikki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{5F8A2DD1-8CF2-4894-A91A-FE4EF9736C7A}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{A1053530-61DF-46FD-AC95-C7BD4D03024A}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
"{B6BCE1C5-AFF5-4D02-B6E2-DB958325B178}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{DB3A7FE4-FF53-4E46-9573-3077559F41C1}" = lport=12345 | protocol=6 | dir=in | name=trend micro officescan listener |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04495A4F-273B-4121-AC90-4BCC6C452A25}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{04B0AFD4-E300-438B-8137-335D966742C7}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{6D6A2C01-B272-4EEE-9210-D39552AEC861}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{7905D1EA-3087-4B02-8F34-EC8CEA8C3CFB}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{87C7D44F-2ED3-40D9-8DBE-9E0FB8616368}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{F6DBE07C-0DD1-4DF0-9CD8-3A324BA7843D}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUS_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUS_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUS_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUS_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUS_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.1
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.10.17.221
"HDMI" = Intel® Graphics Media Accelerator Driver
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"OfficeScanNT" = Trend Micro OfficeScan Client
"Power Management Driver" = ThinkPad Power Management Driver
"WinLiveSuite" = Windows Live Essentials

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 8/12/2012 11:16:28 | Computer Name = Hannah | Source = WinMgmt | ID = 10
Description =

Error - 8/12/2012 15:05:15 | Computer Name = Hannah | Source = WinMgmt | ID = 10
Description =

Error - 8/12/2012 16:13:25 | Computer Name = Hannah | Source = WinMgmt | ID = 10
Description =

Error - 8/13/2012 7:11:43 | Computer Name = Hannah | Source = WinMgmt | ID = 10
Description =

Error - 8/15/2012 20:03:17 | Computer Name = Hannah | Source = WinMgmt | ID = 10
Description =

Error - 8/16/2012 17:23:30 | Computer Name = Hannah | Source = WinMgmt | ID = 10
Description =

Error - 8/16/2012 18:26:06 | Computer Name = Hannah | Source = WinMgmt | ID = 10
Description =

Error - 8/16/2012 19:06:05 | Computer Name = Hannah | Source = Application Hang | ID = 1002
Description = The program PCHealthBoost.exe version 1.0.0.0 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 604 Start
Time: 01cd7c02087a1f3a Termination Time: 47 Application Path: C:\Program Files\PC
HealthBoost\PCHealthBoost.exe Report Id:

Error - 8/16/2012 21:24:05 | Computer Name = Hannah | Source = WinMgmt | ID = 10
Description =

Error - 8/17/2012 16:34:19 | Computer Name = Hannah | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 8/12/2012 9:45:16 | Computer Name = Hannah | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x8007001f: Intel Corporation - Display - Mobile Intel® 945 Express
Chipset Family.

Error - 8/16/2012 16:18:38 | Computer Name = Hannah | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Google
Update Service (gupdate) service to connect.

Error - 8/16/2012 16:18:38 | Computer Name = Hannah | Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate) service failed to start due to
the following error: %%1053

Error - 8/16/2012 16:18:40 | Computer Name = Hannah | Source = DCOM | ID = 10005
Description =

Error - 8/16/2012 17:19:46 | Computer Name = Hannah | Source = EventLog | ID = 6008
Description = The previous system shutdown at 4:18:24 PM on ?8/?16/?2012 was unexpected.

Error - 8/16/2012 18:35:00 | Computer Name = Hannah | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Definition Update for Windows Defender - KB915597 (Definition
1.131.2019.0).

Error - 8/16/2012 21:22:30 | Computer Name = Hannah | Source = EventLog | ID = 6008
Description = The previous system shutdown at 8:21:25 PM on ?8/?16/?2012 was unexpected.

Error - 8/16/2012 21:22:33 | Computer Name = Hannah | Source = BugCheck | ID = 1001
Description =

Error - 8/17/2012 16:38:20 | Computer Name = Hannah | Source = Service Control Manager | ID = 7022
Description = The Windows Defender service hung on starting.

Error - 8/17/2012 16:48:13 | Computer Name = Hannah | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Definition Update for Windows Defender - KB915597 (Definition
1.131.2244.0).


< End of report >
Hi Paul Ryan 12,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

As we work through your logs. Please remember to run any tools by Right-clicking on the icon and selecting Run As Administrator….

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes

:OTL
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Value error. File not found
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - Reg Error: Value error. File not found
O33 - MountPoints2\{aa5c31ca-4227-11e1-8b40-00197de9d644}\Shell - "" = AutoRun
O33 - MountPoints2\{aa5c31ca-4227-11e1-8b40-00197de9d644}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
[2012/08/17 15:33:57 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{4C2B0B7C-8775-4254-A7B1-917A18AFEB96}
[2012/08/16 17:26:51 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{D68FEF37-AB3E-4419-8A0D-61AF5665C4FA}
[2012/08/16 17:26:28 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{ABE48FA9-C17C-448F-8C11-DF4BFCCB84DF}
[2012/08/16 15:19:57 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{E4870D0A-2E8D-41A6-92E8-7D46A49B3F8C}
[2012/08/15 19:02:36 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{E44BC0DF-7BDD-4F89-957C-D9EB9AD21473}
[2012/08/15 19:02:21 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{87BD7986-F224-4A88-8498-0FE17F69C168}
[2012/08/13 06:11:03 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{202F5A57-6558-428C-A4EA-F44176A7AE93}
[2012/08/13 06:10:48 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{332B9CDD-A6FA-4F73-8D7F-97431357DC36}
[2012/08/12 06:38:21 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{DAB854D8-9B5C-4460-A682-F92DEAB064D9}
[2012/08/12 06:38:09 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{16B45AFC-2410-417A-A0B8-CE9C15432E0E}
[2012/08/06 14:15:48 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{A14601A2-2482-470C-973C-245F8F3B18CB}
[2012/08/05 20:26:49 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{1B966F84-C8EC-426D-A300-FFC0C8390DF6}
[2012/08/05 05:41:50 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{EB29C971-7B9A-4622-9DB9-773BFB56FE3D}
[2012/08/04 16:37:31 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{EA1A9549-E44C-4F9D-9EC0-1D9E42815577}
[2012/08/04 16:37:14 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{786BF141-399E-4253-B204-5619C92356AA}
[2012/07/28 05:38:01 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{607BC6D5-F828-4C84-9081-E5DF56338598}
[2012/07/27 15:32:13 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{273E2D39-C65D-4E59-BD06-8489BD623601}
[2012/07/27 15:31:57 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{4C8B99C7-7740-40AA-BA01-BB9931578960}
[2012/07/26 15:37:27 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{20716A81-1353-4C2E-B81B-2AD8F5ED95AF}
[2012/07/26 15:37:12 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{BF51473E-8190-4B33-AA11-E36D5B0012A6}
[2012/07/25 21:16:07 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{68BDA168-F1E0-4654-8073-E86026AF03C6}
[2012/07/25 21:15:53 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{5657AF53-17C3-47D3-8CE8-3A408ED4FCF3}
[2012/07/24 15:09:18 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{971F8D96-3DDB-4A39-B5C1-A3C4802E9187}
[2012/07/24 15:09:05 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{BE8060AC-3EE6-4CB1-88D2-4FA754090BAB}
[2012/07/23 15:59:24 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{ADBCE486-B8BB-498B-8CA6-E03636217F01}
[2012/07/23 15:59:13 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{B1ED65E1-BD82-4914-BD48-92E178D5D4ED}
[2012/07/22 06:13:20 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{9028F9F6-FCCC-4FBF-8031-7D4AD8505587}
[2012/07/22 06:12:54 | 000,000,000 | —D | C] – C:\Users\Nikki\AppData\Local\{B398B234-389E-4F87-A646-0C9BB002B8AA}
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log.
Thank you, Tomk! Everything ran well. The resulting log is below. It, to me, looks incomplete. But what do I know. Also, Trend Micro still blocking same url(s). All processes killed ========== PROCESSES ========== ========== OTL ========== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2670000A-7350-4f3c-8081-5663EE0C6C49}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2670000A-7350-4f3c-8081-5663EE0C6C49}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2670000A-7350-4f3c-8081-5663EE0C6C49}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2670000A-7350-4f3c-8081-5663EE0C6C49}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aa5c31ca-4227-11e1-8b40-00197de9d644}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa5c31ca-4227-11e1-8b40-00197de9d644}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{aa5c31ca-4227-11e1-8b40-00197de9d644}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{aa5c31ca-4227-11e1-8b40-00197de9d644}\ not found. File E:\LaunchU3.exe -a not found. C:\Users\Nikki\AppData\Local\{4C2B0B7C-8775-4254-A7B1-917A18AFEB96} folder moved successfully. C:\Users\Nikki\AppData\Local\{D68FEF37-AB3E-4419-8A0D-61AF5665C4FA} folder moved successfully. C:\Users\Nikki\AppData\Local\{ABE48FA9-C17C-448F-8C11-DF4BFCCB84DF} folder moved successfully. C:\Users\Nikki\AppData\Local\{E4870D0A-2E8D-41A6-92E8-7D46A49B3F8C} folder moved successfully. C:\Users\Nikki\AppData\Local\{E44BC0DF-7BDD-4F89-957C-D9EB9AD21473} folder moved successfully. C:\Users\Nikki\AppData\Local\{87BD7986-F224-4A88-8498-0FE17F69C168} folder moved successfully. C:\Users\Nikki\AppData\Local\{202F5A57-6558-428C-A4EA-F44176A7AE93} folder moved successfully. C:\Users\Nikki\AppData\Local\{332B9CDD-A6FA-4F73-8D7F-97431357DC36} folder moved successfully. C:\Users\Nikki\AppData\Local\{DAB854D8-9B5C-4460-A682-F92DEAB064D9} folder moved successfully. C:\Users\Nikki\AppData\Local\{16B45AFC-2410-417A-A0B8-CE9C15432E0E} folder moved successfully. C:\Users\Nikki\AppData\Local\{A14601A2-2482-470C-973C-245F8F3B18CB} folder moved successfully. C:\Users\Nikki\AppData\Local\{1B966F84-C8EC-426D-A300-FFC0C8390DF6} folder moved successfully. C:\Users\Nikki\AppData\Local\{EB29C971-7B9A-4622-9DB9-773BFB56FE3D} folder moved successfully. C:\Users\Nikki\AppData\Local\{EA1A9549-E44C-4F9D-9EC0-1D9E42815577} folder moved successfully. C:\Users\Nikki\AppData\Local\{786BF141-399E-4253-B204-5619C92356AA} folder moved successfully. C:\Users\Nikki\AppData\Local\{607BC6D5-F828-4C84-9081-E5DF56338598} folder moved successfully. C:\Users\Nikki\AppData\Local\{273E2D39-C65D-4E59-BD06-8489BD623601} folder moved successfully. C:\Users\Nikki\AppData\Local\{4C8B99C7-7740-40AA-BA01-BB9931578960} folder moved successfully. C:\Users\Nikki\AppData\Local\{20716A81-1353-4C2E-B81B-2AD8F5ED95AF} folder moved successfully. C:\Users\Nikki\AppData\Local\{BF51473E-8190-4B33-AA11-E36D5B0012A6} folder moved successfully. C:\Users\Nikki\AppData\Local\{68BDA168-F1E0-4654-8073-E86026AF03C6} folder moved successfully. C:\Users\Nikki\AppData\Local\{5657AF53-17C3-47D3-8CE8-3A408ED4FCF3} folder moved successfully. C:\Users\Nikki\AppData\Local\{971F8D96-3DDB-4A39-B5C1-A3C4802E9187} folder moved successfully. C:\Users\Nikki\AppData\Local\{BE8060AC-3EE6-4CB1-88D2-4FA754090BAB} folder moved successfully. C:\Users\Nikki\AppData\Local\{ADBCE486-B8BB-498B-8CA6-E03636217F01} folder moved successfully. C:\Users\Nikki\AppData\Local\{B1ED65E1-BD82-4914-BD48-92E178D5D4ED} folder moved successfully. C:\Users\Nikki\AppData\Local\{9028F9F6-FCCC-4FBF-8031-7D4AD8505587} folder moved successfully. C:\Users\Nikki\AppData\Local\{B398B234-389E-4F87-A646-0C9BB002B8AA} folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56475 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Nikki ->Temp folder emptied: 246295437 bytes ->Temporary Internet Files folder emptied: 625244964 bytes ->Java cache emptied: 29633 bytes ->Flash cache emptied: 1329 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 204626096 bytes RecycleBin emptied: 348817343 bytes Total Files Cleaned = 1,359.00 mb OTL by OldTimer - Version 3.2.57.0 log created on 08202012_160113 Files\Folders moved on Reboot… File\Folder C:\Users\Nikki\AppData\Local\Temp\OICE_B251A937-B842-4BAB-ABA6-2542B4E58E88.0\B8D73898. not found! File move failed. C:\Windows\temp\tm_icrcL_A606D985_38CA_41ab_BCD9_60F771CF800D scheduled to be moved on reboot. PendingFileRenameOperations files… File C:\Users\Nikki\AppData\Local\Temp\OICE_B251A937-B842-4BAB-ABA6-2542B4E58E88.0\B8D73898. not found! [2012/08/20 16:06:07 | 000,000,000 | —- | M] () C:\Windows\temp\tm_icrcL_A606D985_38CA_41ab_BCD9_60F771CF800D : Unable to obtain MD5 Registry entries deleted on Reboot…
We've only just begun to fight! :lol:

Download ComboFix:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Tomk, I cannot get the Trend Micro disabled. I bought the machine used from work and Trend was on it…..it appears that I may need a password to get this disabled. I will have to check at work tomorrow and then try. I am considering just removing the program altogether.
ok, Tomk….I think I've got it. Combo log below. ComboFix 12-08-20.02 - Nikki 08/21/2012 8:32.1.2 - x86 Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.1014.345 [GMT -5:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: Trend Micro OfficeScan Antivirus *Disabled/Updated* {48929DFC-7A52-A34F-8351-C4DBEDBD9C50} SP: Trend Micro OfficeScan Anti-spyware *Disabled/Updated* {F3F37C18-5C68-ACC1-B9E1-FFA9963AD6ED} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\system32\roboot.exe . . ((((((((((((((((((((((((( Files Created from 2012-07-21 to 2012-08-21 ))))))))))))))))))))))))))))))) . . 2012-08-21 13:39 . 2012-08-21 13:39 ——– d—–w- c:\users\Nikki\AppData\Local\temp 2012-08-21 13:39 . 2012-08-21 13:39 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-08-20 21:01 . 2012-08-20 21:01 ——– d—–w- C:\_OTL 2012-08-17 20:47 . 2012-06-29 08:44 6891424 ——w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{59F5A475-29A8-4283-9E26-336E7272C861}\mpengine.dll 2012-08-17 01:48 . 2012-05-05 07:46 400896 —-a-w- c:\windows\system32\srcore.dll 2012-08-17 01:47 . 2012-02-11 05:40 769024 —-a-w- c:\windows\system32\localspl.dll 2012-08-17 01:47 . 2012-02-11 05:43 492032 —-a-w- c:\windows\system32\win32spl.dll 2012-08-17 01:47 . 2012-02-11 05:37 317440 —-a-w- c:\windows\system32\spoolsv.exe 2012-08-17 01:44 . 2012-07-06 19:23 393728 —-a-w- c:\windows\system32\drivers\bthport.sys 2012-08-16 23:00 . 2012-08-16 23:07 ——– d—–w- c:\users\Nikki\AppData\Roaming\Systweak 2012-08-16 22:04 . 2012-08-16 22:04 ——– d—–w- c:\users\Nikki\AppData\Roaming\SpeedyPC Software 2012-08-16 22:04 . 2012-08-16 22:04 ——– d—–w- c:\program files\Common Files\SpeedyPC Software 2012-08-16 22:04 . 2012-08-16 22:04 ——– d—–w- c:\programdata\SpeedyPC Software 2012-08-16 22:04 . 2012-08-16 22:04 ——– d—–w- c:\program files\SpeedyPC Software 2012-08-16 21:52 . 2012-08-16 21:52 ——– d—–w- c:\users\Nikki\AppData\Roaming\DriverCure 2012-08-16 21:52 . 2012-08-16 21:52 ——– d—–w- c:\users\Nikki\AppData\Roaming\SpeedMaxPc 2012-08-16 21:52 . 2012-08-16 21:52 ——– d—–w- c:\program files\Common Files\SpeedMaxPc 2012-08-16 21:52 . 2012-08-16 21:52 ——– d—–w- c:\programdata\SpeedMaxPc 2012-08-16 21:52 . 2012-08-16 21:52 ——– d—–w- c:\program files\SpeedMaxPc 2012-08-12 13:45 . 2012-08-12 13:45 ——– d—–w- c:\program files\Synaptics 2012-08-12 13:41 . 2012-08-12 13:41 ——– d—–w- c:\users\Nikki\AppData\Local\ElevatedDiagnostics 2012-08-11 19:31 . 2012-08-11 19:31 122368 —-a-w- c:\programdata\Microsoft\Windows\DRM\557A.tmp . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-08-16 23:07 . 2012-04-04 19:56 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-08-16 23:07 . 2011-12-23 01:33 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-06-12 02:40 . 2012-07-11 20:00 2345984 —-a-w- c:\windows\system32\win32k.sys 2012-06-06 13:49 . 2012-06-06 13:49 1070152 —-a-w- c:\windows\system32\MSCOMCTL.OCX 2012-06-06 05:05 . 2012-07-10 21:40 1390080 —-a-w- c:\windows\system32\msxml6.dll 2012-06-06 05:05 . 2012-07-10 21:40 1236992 —-a-w- c:\windows\system32\msxml3.dll 2012-06-06 05:03 . 2012-07-10 21:41 805376 —-a-w- c:\windows\system32\cdosys.dll 2012-06-02 22:19 . 2012-06-23 15:18 53784 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2012-06-23 15:18 45080 —-a-w- c:\windows\system32\wups2.dll 2012-06-02 22:19 . 2012-06-23 15:18 35864 —-a-w- c:\windows\system32\wups.dll 2012-06-02 22:19 . 2012-06-23 15:18 577048 —-a-w- c:\windows\system32\wuapi.dll 2012-06-02 22:19 . 2012-06-23 15:18 1933848 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-02 22:12 . 2012-06-23 15:18 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-06-02 22:12 . 2012-06-23 15:18 88576 —-a-w- c:\windows\system32\wudriver.dll 2012-06-02 20:19 . 2012-06-23 15:17 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-02 20:12 . 2012-06-23 15:17 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-06-02 04:45 . 2012-07-10 21:41 67440 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2012-06-02 04:45 . 2012-07-10 21:41 134000 —-a-w- c:\windows\system32\drivers\ksecpkg.sys 2012-06-02 04:40 . 2012-07-10 21:41 369336 —-a-w- c:\windows\system32\drivers\cng.sys 2012-06-02 04:40 . 2012-07-10 21:41 225280 —-a-w- c:\windows\system32\schannel.dll 2012-06-02 04:39 . 2012-07-10 21:41 219136 —-a-w- c:\windows\system32\ncrypt.dll 2012-05-31 17:25 . 2011-12-16 13:24 237072 ——w- c:\windows\system32\MpSigStub.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-12-29 39408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 150552] "OfficeScanNT Monitor"="c:\program files\Trend Micro\OfficeScan Client\pccntmon.exe" [2010-02-05 849192] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-11 919008] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x] R2 TmFilter;Trend Micro Filter;c:\program files\Trend Micro\OfficeScan Client\TmXPFlt.sys [x] R2 TmPreFilter;Trend Micro PreFilter;c:\program files\Trend Micro\OfficeScan Client\TmPreFlt.sys [x] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x] R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [x] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [x] R3 tmevtmgr;tmevtmgr;c:\windows\system32\DRIVERS\tmevtmgr.sys [x] R3 TmProxy;OfficeScan NT Proxy Service;c:\program files\Trend Micro\OfficeScan Client\TmProxy.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [x] S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [x] S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [x] S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [x] . . Contents of the 'Scheduled Tasks' folder . 2012-08-21 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 23:07] . 2012-08-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-12-29 23:12] . 2012-08-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-12-29 23:12] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.jsonline.com/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000 IE: Free YouTube to MP3 Converter - c:\users\Nikki\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Se&nd to OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = [removed] [removed] . - - - - ORPHANS REMOVED - - - - . AddRemove-Advanced System Protector_is1 - c:\program files\Advanced System Protector\unins000.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-08-21 08:42:19 ComboFix-quarantined-files.txt 2012-08-21 13:42 . Pre-Run: 47,282,036,736 bytes free Post-Run: 46,701,817,856 bytes free . - - End Of File - - DFDC44825BEF6C851A409264608CC3D7
Download aswMBR.exe to your desktop.

Double click the aswMBR.exe to run it. If asked to download Avast's database please do so.

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-08-21 10:33:30 —————————– 10:33:30.046 OS Version: Windows 6.1.7601 Service Pack 1 10:33:30.046 Number of processors: 2 586 0xF06 10:33:30.046 ComputerName: HANNAH UserName: Nikki 10:33:31.044 Initialize success 10:33:38.284 AVAST engine download error: 0 10:33:42.590 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-2 10:33:42.590 Disk 0 Vendor: TOSHIBA_MK8034GSX AH301E Size: 76319MB BusType: 11 10:33:42.590 Disk 0 MBR read successfully 10:33:42.590 Disk 0 MBR scan 10:33:42.605 Disk 0 Windows 7 default MBR code 10:33:42.605 Disk 0 MBR hidden 10:33:42.621 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 10:33:42.621 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 76217 MB offset 206848 10:33:42.636 Disk 0 scanning sectors +156299264 10:33:42.699 Disk 0 scanning C:\Windows\system32\drivers 10:33:49.017 Service scanning 10:34:12.464 Modules scanning 10:34:21.387 Disk 0 trace - called modules: 10:34:21.387 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x855a64b1]<< 10:34:21.402 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85351530] 10:34:21.402 3 CLASSPNP.SYS[871d559e] -> nt!IofCallDriver -> [0x855f8780] 10:34:21.402 \Driver\atapi[0x854e6d38] -> IRP_MJ_CREATE -> 0x855a64b1 10:34:21.418 Scan finished successfully 10:35:52.195 Disk 0 MBR has been saved successfully to "C:\Users\Nikki\Desktop\MBR.dat" 10:35:52.210 The log file has been saved successfully to "C:\Users\Nikki\Desktop\aswMBR.txt"

Attachments:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Hi Tomk, After the scan did it's thing I clicked OK in the dialog box and there was no place to click 'Show Results' anywhere. But there was a log open in notepad. The results are below. Malwarebytes Anti-Malware (Trial) 1.62.0.1300 www.malwarebytes.org Database version: v2012.08.21.12 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 9.0.8112.16421 Nikki :: HANNAH [administrator] Protection: Enabled 8/21/2012 15:33:59 mbam-log-2012-08-21 (15-33-59).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 183425 Time elapsed: 16 minute(s), 7 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Paul Ryan 12, I'm sorry but I'm just not finding any malware. Give me some time and I'll have some colleagues look things over and see if they can see what I'm missing.
Let's try another tool.

Download the latest version of TDSSKiller from here and save it to your Desktop.



A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.
ok, Tomk…….I am going to try to explain this as best I can. I ran the tool (TDSSKiller) and the blue screen of death interrupted it while in progress. So I tried to run it again but this time with a real sense of urgency to play 'beat the clock' against the blue screen and 2 threats were found. One of the threats had 'Cure' next to it and the other said 'Skip' so I hit the Continue button. It then told me that a reboot was necessary, I hit the button to reboot. When the computer came back on I was at the black screen and it was asking if I wanted to boot in safe mode, or safe mode with networking etc…..I told it to start normally. This made me think that the tool did not get a chance to complete it's work. When the computer came back on I raced the clock again to get the TDSSKiller to run and this time it found 3 threats. One of which had 'Cure', so I once again hit continue and it asked for a reboot, which I did. This time the reboot seemed to work fine and the machine rebooted as normal. Here's the deal….I now have 5 TDSSKiller logs in my root. The earliest time stamped log is quite lengthly, and when I look at it appears as though it is not complete. It just drops off at the end as though it was still working. The same can be said for the next 2 time stamped logs. Time stamp number 4 is also lengthly but appears to have a conclusion. And time stamp log number 5 is quite brief. I will post time stamp log number 4 first….followed by number 5. I hope I have made SOME sense with this post. Also, the blue screens seem to have ceased. 05:59:34.0706 1760 TDSS rootkit removing tool [removed] Aug 20 2012 17:30:03 05:59:35.0267 1760 ============================================================ 05:59:35.0267 1760 Current date / time: 2012/08/22 05:59:35.0267 05:59:35.0267 1760 SystemInfo: 05:59:35.0267 1760 05:59:35.0267 1760 OS Version: 6.1.7601 ServicePack: 1.0 05:59:35.0267 1760 Product type: Workstation 05:59:35.0267 1760 ComputerName: HANNAH 05:59:35.0267 1760 UserName: Nikki 05:59:35.0267 1760 Windows directory: C:\Windows 05:59:35.0267 1760 System windows directory: C:\Windows 05:59:35.0267 1760 Processor architecture: Intel x86 05:59:35.0267 1760 Number of processors: 2 05:59:35.0267 1760 Page size: 0x1000 05:59:35.0267 1760 Boot type: Normal boot 05:59:35.0267 1760 ============================================================ 05:59:36.0796 1760 BG loaded 05:59:37.0483 1760 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2861, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000050 05:59:37.0483 1760 Drive \Device\Harddisk1\DR1 - Size: 0x1DDD00000 (7.47 Gb), SectorSize: 0x200, Cylinders: 0x3CE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 05:59:37.0498 1760 ============================================================ 05:59:37.0498 1760 \Device\Harddisk0\DR0: 05:59:37.0498 1760 MBR partitions: 05:59:37.0498 1760 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 05:59:37.0498 1760 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x94DC800 05:59:37.0498 1760 \Device\Harddisk1\DR1: 05:59:37.0498 1760 MBR partitions: 05:59:37.0498 1760 ============================================================ 05:59:37.0639 1760 C: <-> \Device\Harddisk0\DR0\Partition2 05:59:37.0639 1760 ============================================================ 05:59:37.0639 1760 Initialize success 05:59:37.0639 1760 ============================================================ 05:59:43.0255 2740 ============================================================ 05:59:43.0255 2740 Scan started 05:59:43.0255 2740 Mode: Manual; SigCheck; TDLFS; 05:59:43.0255 2740 ============================================================ 05:59:47.0404 2740 ================ Scan system memory ======================== 05:59:47.0404 2740 System memory - ok 05:59:47.0404 2740 ================ Scan services ============================= 05:59:47.0810 2740 08450247 - ok 05:59:47.0872 2740 [ 2A8681AEA24003040CA7D677BE9F1702 ] 10638432 C:\Windows\system32\drivers\57212150.sys 05:59:47.0888 2740 Suspicious file (Forged): C:\Windows\system32\drivers\57212150.sys. Real md5: 2A8681AEA24003040CA7D677BE9F1702, Fake md5: DB4A6AE4B7CF4073D2BFD49DDC62B622 05:59:47.0888 2740 10638432 ( ForgedFile.Multi.Generic ) - warning 05:59:47.0888 2740 10638432 - detected ForgedFile.Multi.Generic (1) 05:59:47.0997 2740 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 05:59:48.0434 2740 1394ohci - ok 05:59:48.0465 2740 81976548 - ok 05:59:48.0496 2740 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys 05:59:48.0527 2740 ACPI - ok 05:59:48.0621 2740 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 05:59:48.0917 2740 AcpiPmi - ok 05:59:49.0089 2740 [ A9D3B95E8466BD58EEB8A1154654E162 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 05:59:49.0385 2740 AdobeFlashPlayerUpdateSvc - ok 05:59:49.0448 2740 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 05:59:49.0479 2740 adp94xx - ok 05:59:49.0853 2740 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\drivers\adpahci.sys 05:59:50.0009 2740 adpahci - ok 05:59:50.0337 2740 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 05:59:50.0368 2740 adpu320 - ok 05:59:50.0462 2740 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 05:59:52.0895 2740 AeLookupSvc - ok 05:59:52.0973 2740 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys 05:59:53.0114 2740 AFD - ok 05:59:53.0207 2740 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys 05:59:53.0223 2740 agp440 - ok 05:59:53.0270 2740 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\drivers\djsvs.sys 05:59:53.0301 2740 aic78xx - ok 05:59:53.0379 2740 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe 05:59:53.0473 2740 ALG - ok 05:59:53.0504 2740 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys 05:59:53.0551 2740 aliide - ok 05:59:53.0566 2740 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys 05:59:53.0597 2740 amdagp - ok 05:59:53.0644 2740 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys 05:59:53.0675 2740 amdide - ok 05:59:53.0738 2740 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 05:59:53.0769 2740 AmdK8 - ok 05:59:53.0800 2740 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys 05:59:53.0831 2740 AmdPPM - ok 05:59:53.0909 2740 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys 05:59:53.0925 2740 amdsata - ok 05:59:53.0972 2740 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\drivers\amdsbs.sys 05:59:54.0003 2740 amdsbs - ok 05:59:54.0050 2740 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys 05:59:54.0065 2740 amdxata - ok 05:59:54.0128 2740 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys 05:59:54.0190 2740 AppID - ok 05:59:54.0253 2740 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll 05:59:54.0346 2740 AppIDSvc - ok 05:59:54.0393 2740 [ FB1959012294D6AD43E5304DF65E3C26 ] Appinfo C:\Windows\System32\appinfo.dll 05:59:54.0471 2740 Appinfo - ok 05:59:54.0533 2740 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll 05:59:54.0643 2740 AppMgmt - ok 05:59:54.0705 2740 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\drivers\arc.sys 05:59:54.0736 2740 arc - ok 05:59:54.0767 2740 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\drivers\arcsas.sys 05:59:54.0799 2740 arcsas - ok 05:59:54.0814 2740 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 05:59:55.0079 2740 AsyncMac - ok 05:59:55.0126 2740 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys 05:59:55.0157 2740 atapi - ok 05:59:55.0235 2740 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 05:59:55.0360 2740 AudioEndpointBuilder - ok 05:59:55.0391 2740 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll 05:59:55.0438 2740 Audiosrv - ok 05:59:55.0501 2740 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll 05:59:55.0735 2740 AxInstSV - ok 05:59:55.0828 2740 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\drivers\bxvbdx.sys 05:59:55.0922 2740 b06bdrv - ok 05:59:55.0969 2740 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys 05:59:56.0015 2740 b57nd60x - ok 05:59:56.0062 2740 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll 05:59:56.0156 2740 BDESVC - ok 05:59:56.0218 2740 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys 05:59:56.0296 2740 Beep - ok 05:59:56.0359 2740 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll 05:59:56.0437 2740 BFE - ok 05:59:56.0561 2740 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\system32\qmgr.dll 05:59:56.0671 2740 BITS - ok 05:59:56.0686 2740 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 05:59:56.0733 2740 blbdrive - ok 05:59:56.0795 2740 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 05:59:56.0842 2740 bowser - ok 05:59:56.0905 2740 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys 05:59:56.0936 2740 BrFiltLo - ok 05:59:56.0967 2740 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys 05:59:57.0061 2740 BrFiltUp - ok 05:59:57.0185 2740 [ 77361D72A04F18809D0EFB6CCEB74D4B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys 05:59:57.0263 2740 BridgeMP - ok 05:59:57.0326 2740 [ 6E11F33D14D020F58D5E02E4D67DFA19 ] Browser C:\Windows\System32\browser.dll 05:59:57.0466 2740 Browser - ok 05:59:57.0544 2740 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys 05:59:57.0669 2740 Brserid - ok 05:59:57.0716 2740 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 05:59:57.0763 2740 BrSerWdm - ok 05:59:57.0778 2740 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 05:59:57.0825 2740 BrUsbMdm - ok 05:59:57.0841 2740 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 05:59:57.0903 2740 BrUsbSer - ok 05:59:57.0966 2740 [ 2865A5C8E98C70C605F417908CEBB3A4 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys 05:59:58.0059 2740 BthEnum - ok 05:59:58.0090 2740 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys 05:59:58.0137 2740 BTHMODEM - ok 05:59:58.0200 2740 [ AD1872E5829E8A2C3B5B4B641C3EAB0E ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys 05:59:58.0231 2740 BthPan - ok 05:59:58.0371 2740 [ 1153DE2E4F5941E10C399CB5592F78A1 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys 05:59:58.0402 2740 BTHPORT - ok 05:59:58.0465 2740 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll 05:59:58.0574 2740 bthserv - ok 05:59:58.0590 2740 [ C81E9413A25A439F436B1D4B6A0CF9E9 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys 05:59:58.0636 2740 BTHUSB - ok 05:59:58.0902 2740 catchme - ok 05:59:58.0964 2740 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 05:59:59.0042 2740 cdfs - ok 05:59:59.0104 2740 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 05:59:59.0136 2740 cdrom - ok 05:59:59.0198 2740 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll 05:59:59.0323 2740 CertPropSvc - ok 05:59:59.0338 2740 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\drivers\circlass.sys 05:59:59.0385 2740 circlass - ok 05:59:59.0432 2740 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys 05:59:59.0448 2740 CLFS - ok 05:59:59.0635 2740 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 05:59:59.0744 2740 clr_optimization_v2.0.50727_32 - ok 05:59:59.0838 2740 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 06:00:00.0009 2740 clr_optimization_v4.0.30319_32 - ok 06:00:00.0040 2740 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 06:00:00.0103 2740 CmBatt - ok 06:00:00.0134 2740 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys 06:00:00.0181 2740 cmdide - ok 06:00:00.0399 2740 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys 06:00:00.0477 2740 CNG - ok 06:00:00.0524 2740 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 06:00:00.0555 2740 Compbatt - ok 06:00:00.0618 2740 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys 06:00:00.0664 2740 CompositeBus - ok 06:00:00.0711 2740 COMSysApp - ok 06:00:00.0727 2740 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 06:00:00.0758 2740 crcdisk - ok 06:00:00.0820 2740 [ 06E771AA596B8761107AB57E99F128D7 ] CryptSvc C:\Windows\system32\cryptsvc.dll 06:00:00.0961 2740 CryptSvc - ok 06:00:00.0992 2740 [ 3C2177A897B4CA2788C6FB0C3FD81D4B ] CSC C:\Windows\system32\drivers\csc.sys 06:00:01.0101 2740 CSC - ok 06:00:01.0242 2740 [ 15F93B37F6801943360D9EB42485D5D3 ] CscService C:\Windows\System32\cscsvc.dll 06:00:01.0351 2740 CscService - ok 06:00:01.0491 2740 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll 06:00:01.0616 2740 DcomLaunch - ok 06:00:01.0694 2740 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll 06:00:01.0834 2740 defragsvc - ok 06:00:01.0912 2740 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 06:00:01.0990 2740 DfsC - ok 06:00:02.0068 2740 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll 06:00:02.0209 2740 Dhcp - ok 06:00:02.0224 2740 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys 06:00:02.0271 2740 discache - ok 06:00:02.0365 2740 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\drivers\disk.sys 06:00:02.0396 2740 Disk - ok 06:00:02.0427 2740 [ 2A958EF85DB1B61FFCA65044FA4BCE9E ] dmvsc C:\Windows\system32\drivers\dmvsc.sys 06:00:02.0521 2740 dmvsc - ok 06:00:02.0614 2740 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll 06:00:02.0724 2740 Dnscache - ok 06:00:02.0770 2740 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll 06:00:02.0880 2740 dot3svc - ok 06:00:02.0926 2740 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll 06:00:03.0036 2740 DPS - ok 06:00:03.0098 2740 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 06:00:03.0160 2740 drmkaud - ok 06:00:03.0270 2740 [ 23F5D28378A160352BA8F817BD8C71CB ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 06:00:03.0379 2740 DXGKrnl - ok 06:00:03.0488 2740 [ CF0A6015F437161698C5B2A0A12CF052 ] e1express C:\Windows\system32\DRIVERS\e1e6032.sys 06:00:03.0550 2740 e1express - ok 06:00:03.0613 2740 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll 06:00:03.0722 2740 EapHost - ok 06:00:04.0018 2740 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\drivers\evbdx.sys 06:00:04.0128 2740 ebdrv - ok 06:00:04.0174 2740 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe 06:00:04.0299 2740 EFS - ok 06:00:04.0424 2740 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 06:00:04.0627 2740 ehRecvr - ok 06:00:04.0658 2740 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe 06:00:04.0736 2740 ehSched - ok 06:00:04.0845 2740 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\drivers\elxstor.sys 06:00:04.0892 2740 elxstor - ok 06:00:04.0923 2740 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys 06:00:04.0954 2740 ErrDev - ok 06:00:05.0048 2740 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll 06:00:05.0110 2740 EventSystem - ok 06:00:05.0220 2740 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys 06:00:05.0298 2740 exfat - ok 06:00:05.0313 2740 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys 06:00:05.0376 2740 fastfat - ok 06:00:05.0516 2740 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe 06:00:05.0734 2740 Fax - ok 06:00:05.0781 2740 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\drivers\fdc.sys 06:00:05.0844 2740 fdc - ok 06:00:05.0875 2740 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll 06:00:05.0984 2740 fdPHost - ok 06:00:06.0000 2740 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll 06:00:06.0093 2740 FDResPub - ok 06:00:06.0109 2740 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 06:00:06.0124 2740 FileInfo - ok 06:00:06.0140 2740 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 06:00:06.0218 2740 Filetrace - ok 06:00:06.0249 2740 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\drivers\flpydisk.sys 06:00:06.0296 2740 flpydisk - ok 06:00:06.0358 2740 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 06:00:06.0390 2740 FltMgr - ok 06:00:06.0499 2740 [ B3A5EC6B6B6673DB7E87C2BCDBDDC074 ] FontCache C:\Windows\system32\FntCache.dll 06:00:06.0686 2740 FontCache - ok 06:00:06.0780 2740 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 06:00:06.0889 2740 FontCache3.0.0.0 - ok 06:00:06.0936 2740 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 06:00:06.0982 2740 FsDepends - ok 06:00:07.0029 2740 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 06:00:07.0076 2740 Fs_Rec - ok 06:00:07.0107 2740 [ 8A73E79089B282100B9393B644CB853B ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 06:00:07.0170 2740 fvevol - ok 06:00:07.0201 2740 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 06:00:07.0216 2740 gagp30kx - ok 06:00:07.0404 2740 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll 06:00:07.0591 2740 gpsvc - ok 06:00:07.0809 2740 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe 06:00:07.0918 2740 gupdate - ok 06:00:07.0934 2740 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe 06:00:07.0965 2740 gupdatem - ok 06:00:08.0028 2740 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 06:00:08.0121 2740 gusvc - ok 06:00:08.0152 2740 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 06:00:08.0230 2740 hcw85cir - ok 06:00:08.0277 2740 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 06:00:08.0371 2740 HdAudAddService - ok 06:00:08.0402 2740 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 06:00:08.0464 2740 HDAudBus - ok 06:00:08.0496 2740 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\drivers\HidBatt.sys 06:00:08.0558 2740 HidBatt - ok 06:00:08.0589 2740 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\drivers\hidbth.sys 06:00:08.0652 2740 HidBth - ok 06:00:08.0698 2740 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\drivers\hidir.sys 06:00:08.0761 2740 HidIr - ok 06:00:08.0792 2740 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\System32\hidserv.dll 06:00:08.0870 2740 hidserv - ok 06:00:08.0917 2740 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 06:00:08.0995 2740 HidUsb - ok 06:00:09.0026 2740 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll 06:00:09.0135 2740 hkmsvc - ok 06:00:09.0182 2740 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll 06:00:09.0369 2740 HomeGroupListener - ok 06:00:09.0400 2740 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 06:00:09.0494 2740 HomeGroupProvider - ok 06:00:09.0541 2740 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 06:00:09.0572 2740 HpSAMD - ok 06:00:09.0619 2740 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys 06:00:09.0712 2740 HTTP - ok 06:00:09.0728 2740 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 06:00:09.0759 2740 hwpolicy - ok 06:00:09.0837 2740 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys 06:00:09.0900 2740 i8042prt - ok 06:00:09.0993 2740 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 06:00:10.0024 2740 iaStorV - ok 06:00:10.0087 2740 [ BF648877413F6160E480814A24942B65 ] IBMPMDRV C:\Windows\system32\DRIVERS\ibmpmdrv.sys 06:00:10.0149 2740 IBMPMDRV - ok 06:00:10.0180 2740 [ A75CE11915E4ECC5E1597D6E0F7BB2DB ] IBMPMSVC C:\Windows\system32\ibmpmsvc.exe 06:00:10.0212 2740 IBMPMSVC - ok 06:00:10.0461 2740 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 06:00:10.0617 2740 idsvc - ok 06:00:11.0226 2740 [ 9467514EA189475A6E7FDC5D7BDE9D3F ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys 06:00:11.0600 2740 igfx - ok 06:00:11.0678 2740 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\drivers\iirsp.sys 06:00:11.0694 2740 iirsp - ok 06:00:11.0881 2740 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll 06:00:12.0115 2740 IKEEXT - ok 06:00:12.0146 2740 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys 06:00:12.0162 2740 intelide - ok 06:00:12.0224 2740 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 06:00:12.0271 2740 intelppm - ok 06:00:12.0302 2740 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll 06:00:12.0364 2740 IPBusEnum - ok 06:00:12.0396 2740 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 06:00:12.0458 2740 IpFilterDriver - ok 06:00:12.0598 2740 [ 4D65A07B795D6674312F879D09AA7663 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 06:00:12.0676 2740 iphlpsvc - ok 06:00:12.0708 2740 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 06:00:12.0723 2740 IPMIDRV - ok 06:00:12.0754 2740 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys 06:00:12.0817 2740 IPNAT - ok 06:00:12.0848 2740 [ 9F7E491FB0BA0F9E370163834FC1FE31 ] irda C:\Windows\system32\DRIVERS\irda.sys 06:00:12.0910 2740 irda - ok 06:00:12.0957 2740 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys 06:00:13.0020 2740 IRENUM - ok 06:00:13.0176 2740 [ 4220D2F03D5C4226D0A1AA4B84025E45 ] Irmon C:\Windows\System32\irmon.dll 06:00:13.0269 2740 Irmon - ok 06:00:13.0347 2740 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys 06:00:13.0378 2740 isapnp - ok 06:00:13.0503 2740 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 06:00:13.0550 2740 iScsiPrt - ok 06:00:13.0675 2740 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 06:00:13.0706 2740 kbdclass - ok 06:00:13.0768 2740 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys 06:00:13.0831 2740 kbdhid - ok 06:00:13.0862 2740 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe 06:00:13.0909 2740 KeyIso - ok 06:00:13.0956 2740 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 06:00:13.0987 2740 KSecDD - ok 06:00:14.0018 2740 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 06:00:14.0034 2740 KSecPkg - ok 06:00:14.0143 2740 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll 06:00:14.0283 2740 KtmRm - ok 06:00:14.0377 2740 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\System32\srvsvc.dll 06:00:14.0470 2740 LanmanServer - ok 06:00:14.0517 2740 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 06:00:14.0611 2740 LanmanWorkstation - ok 06:00:14.0689 2740 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 06:00:14.0751 2740 lltdio - ok 06:00:14.0814 2740 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll 06:00:14.0892 2740 lltdsvc - ok 06:00:14.0923 2740 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll 06:00:14.0985 2740 lmhosts - ok 06:00:15.0032 2740 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 06:00:15.0048 2740 LSI_FC - ok 06:00:15.0094 2740 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 06:00:15.0110 2740 LSI_SAS - ok 06:00:15.0157 2740 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys 06:00:15.0172 2740 LSI_SAS2 - ok 06:00:15.0204 2740 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 06:00:15.0219 2740 LSI_SCSI - ok 06:00:15.0250 2740 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys 06:00:15.0344 2740 luafv - ok 06:00:15.0438 2740 [ 6DFE7F2E8E8A337263AA5C92A215F161 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys 06:00:15.0469 2740 MBAMProtector - ok 06:00:15.0531 2740 [ 43683E970F008C93C9429EF428147A54 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 06:00:15.0703 2740 MBAMService - ok 06:00:15.0765 2740 MBAMSwissArmy - ok 06:00:15.0812 2740 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 06:00:15.0874 2740 Mcx2Svc - ok 06:00:15.0921 2740 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\drivers\megasas.sys 06:00:15.0952 2740 megasas - ok 06:00:15.0999 2740 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys 06:00:16.0077 2740 MegaSR - ok 06:00:16.0218 2740 Microsoft SharePoint Workspace Audit Service - ok 06:00:16.0249 2740 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll 06:00:16.0342 2740 MMCSS - ok 06:00:16.0374 2740 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys 06:00:16.0467 2740 Modem - ok 06:00:16.0530 2740 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 06:00:16.0576 2740 monitor - ok 06:00:16.0639 2740 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 06:00:16.0701 2740 mouclass - ok 06:00:16.0764 2740 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 06:00:16.0795 2740 mouhid - ok 06:00:16.0826 2740 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 06:00:16.0857 2740 mountmgr - ok 06:00:16.0888 2740 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys 06:00:16.0920 2740 mpio - ok 06:00:16.0935 2740 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 06:00:17.0013 2740 mpsdrv - ok 06:00:17.0091 2740 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll 06:00:17.0200 2740 MpsSvc - ok 06:00:17.0216 2740 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 06:00:17.0263 2740 MRxDAV - ok 06:00:17.0294 2740 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 06:00:17.0341 2740 mrxsmb - ok 06:00:17.0388 2740 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 06:00:17.0434 2740 mrxsmb10 - ok 06:00:17.0481 2740 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 06:00:17.0497 2740 mrxsmb20 - ok 06:00:17.0528 2740 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys 06:00:17.0544 2740 msahci - ok 06:00:17.0590 2740 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys 06:00:17.0622 2740 msdsm - ok 06:00:17.0668 2740 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe 06:00:17.0746 2740 MSDTC - ok 06:00:17.0762 2740 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys 06:00:17.0809 2740 Msfs - ok 06:00:17.0824 2740 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 06:00:17.0856 2740 mshidkmdf - ok 06:00:17.0887 2740 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 06:00:17.0902 2740 msisadrv - ok 06:00:17.0965 2740 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 06:00:18.0214 2740 MSiSCSI - ok 06:00:18.0214 2740 msiserver - ok 06:00:18.0261 2740 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 06:00:18.0339 2740 MSKSSRV - ok 06:00:18.0355 2740 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 06:00:18.0433 2740 MSPCLOCK - ok 06:00:18.0480 2740 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 06:00:18.0526 2740 MSPQM - ok 06:00:18.0558 2740 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 06:00:18.0589 2740 MsRPC - ok 06:00:18.0620 2740 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys 06:00:18.0651 2740 mssmbios - ok 06:00:18.0698 2740 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 06:00:18.0745 2740 MSTEE - ok 06:00:18.0776 2740 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\drivers\MTConfig.sys 06:00:18.0807 2740 MTConfig - ok 06:00:18.0838 2740 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys 06:00:18.0854 2740 Mup - ok 06:00:18.0932 2740 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll 06:00:19.0010 2740 napagent - ok 06:00:19.0057 2740 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 06:00:19.0119 2740 NativeWifiP - ok 06:00:19.0182 2740 [ E7C54812A2AAF43316EB6930C1FFA108 ] NDIS C:\Windows\system32\drivers\ndis.sys 06:00:19.0228 2740 NDIS - ok 06:00:19.0275 2740 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 06:00:19.0353 2740 NdisCap - ok 06:00:19.0384 2740 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 06:00:19.0447 2740 NdisTapi - ok 06:00:19.0494 2740 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 06:00:19.0603 2740 Ndisuio - ok 06:00:19.0618 2740 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 06:00:19.0712 2740 NdisWan - ok 06:00:19.0743 2740 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 06:00:19.0806 2740 NDProxy - ok 06:00:19.0837 2740 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 06:00:19.0915 2740 NetBIOS - ok 06:00:19.0946 2740 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 06:00:20.0008 2740 NetBT - ok 06:00:20.0040 2740 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe 06:00:20.0086 2740 Netlogon - ok 06:00:20.0180 2740 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll 06:00:20.0258 2740 Netman - ok 06:00:20.0430 2740 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll 06:00:20.0508 2740 netprofm - ok 06:00:20.0554 2740 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 06:00:20.0664 2740 NetTcpPortSharing - ok 06:00:21.0600 2740 [ 58218EC6B61B1169CF54AAB0D00F5FE2 ] netw5v32 C:\Windows\system32\DRIVERS\netw5v32.sys 06:00:21.0787 2740 netw5v32 - ok 06:00:21.0849 2740 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 06:00:21.0880 2740 nfrd960 - ok 06:00:22.0036 2740 [ 912084381D30D8B89EC4E293053F4710 ] NlaSvc C:\Windows\System32\nlasvc.dll 06:00:22.0114 2740 NlaSvc - ok 06:00:22.0161 2740 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys 06:00:22.0286 2740 Npfs - ok 06:00:22.0333 2740 [ 6D8D2E5652FC2442C810C5D8BE784148 ] NSCIRDA C:\Windows\system32\DRIVERS\nscirda.sys 06:00:22.0411 2740 NSCIRDA - ok 06:00:22.0458 2740 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll 06:00:22.0567 2740 nsi - ok 06:00:22.0598 2740 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 06:00:22.0723 2740 nsiproxy - ok 06:00:23.0269 2740 [ 81189C3D7763838E55C397759D49007A ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 06:00:23.0331 2740 Ntfs - ok 06:00:23.0893 2740 [ 7EC20D4E92CA8F63C924918AFBA82EC2 ] ntrtscan C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe 06:00:24.0064 2740 ntrtscan - ok 06:00:24.0127 2740 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys 06:00:24.0189 2740 Null - ok 06:00:24.0220 2740 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys 06:00:24.0267 2740 nvraid - ok 06:00:24.0330 2740 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys 06:00:24.0361 2740 nvstor - ok 06:00:24.0408 2740 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 06:00:24.0439 2740 nv_agp - ok 06:00:24.0470 2740 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 06:00:24.0532 2740 ohci1394 - ok 06:00:24.0626 2740 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 06:00:24.0688 2740 ose - ok 06:00:25.0484 2740 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 06:00:25.0936 2740 osppsvc - ok 06:00:25.0999 2740 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 06:00:26.0155 2740 p2pimsvc - ok 06:00:26.0248 2740 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll 06:00:26.0389 2740 p2psvc - ok 06:00:26.0420 2740 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\drivers\parport.sys 06:00:26.0467 2740 Parport - ok 06:00:26.0498 2740 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys 06:00:26.0514 2740 partmgr - ok 06:00:26.0545 2740 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\drivers\parvdm.sys 06:00:26.0670 2740 Parvdm - ok 06:00:26.0794 2740 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll 06:00:26.0841 2740 PcaSvc - ok 06:00:26.0950 2740 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys 06:00:26.0966 2740 pci - ok 06:00:26.0997 2740 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys 06:00:27.0028 2740 pciide - ok 06:00:27.0122 2740 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 06:00:27.0153 2740 pcmcia - ok 06:00:27.0200 2740 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys 06:00:27.0231 2740 pcw - ok 06:00:27.0403 2740 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys 06:00:27.0512 2740 PEAUTH - ok 06:00:27.0715 2740 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll 06:00:27.0871 2740 PeerDistSvc - ok 06:00:28.0136 2740 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll 06:00:28.0339 2740 pla - ok 06:00:28.0401 2740 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll 06:00:28.0526 2740 PlugPlay - ok 06:00:28.0557 2740 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 06:00:28.0635 2740 PNRPAutoReg - ok 06:00:28.0682 2740 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 06:00:28.0713 2740 PNRPsvc - ok 06:00:28.0776 2740 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 06:00:28.0885 2740 PolicyAgent - ok 06:00:28.0932 2740 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll 06:00:28.0994 2740 Power - ok 06:00:29.0056 2740 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 06:00:29.0166 2740 PptpMiniport - ok 06:00:29.0197 2740 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\drivers\processr.sys 06:00:29.0244 2740 Processor - ok 06:00:29.0275 2740 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll 06:00:29.0415 2740 ProfSvc - ok 06:00:29.0446 2740 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe 06:00:29.0478 2740 ProtectedStorage - ok 06:00:29.0540 2740 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys 06:00:29.0602 2740 Psched - ok 06:00:29.0852 2740 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\drivers\ql2300.sys 06:00:29.0930 2740 ql2300 - ok 06:00:29.0977 2740 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 06:00:30.0008 2740 ql40xx - ok 06:00:30.0102 2740 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll 06:00:30.0242 2740 QWAVE - ok 06:00:30.0289 2740 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 06:00:30.0320 2740 QWAVEdrv - ok 06:00:30.0351 2740 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 06:00:30.0429 2740 RasAcd - ok 06:00:30.0492 2740 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 06:00:30.0554 2740 RasAgileVpn - ok 06:00:30.0601 2740 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll 06:00:30.0710 2740 RasAuto - ok 06:00:30.0741 2740 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 06:00:30.0788 2740 Rasl2tp - ok 06:00:30.0835 2740 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll 06:00:30.0913 2740 RasMan - ok 06:00:30.0944 2740 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 06:00:30.0975 2740 RasPppoe - ok 06:00:31.0022 2740 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 06:00:31.0116 2740 RasSstp - ok 06:00:31.0162 2740 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 06:00:31.0209 2740 rdbss - ok 06:00:31.0240 2740 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 06:00:31.0256 2740 rdpbus - ok 06:00:31.0287 2740 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 06:00:31.0365 2740 RDPCDD - ok 06:00:31.0396 2740 [ B973FCFC50DC1434E1970A146F7E3885 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys 06:00:31.0443 2740 RDPDR - ok 06:00:31.0490 2740 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 06:00:31.0552 2740 RDPENCDD - ok 06:00:31.0568 2740 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 06:00:31.0630 2740 RDPREFMP - ok 06:00:31.0677 2740 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 06:00:31.0755 2740 RDPWD - ok 06:00:31.0786 2740 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 06:00:31.0818 2740 rdyboost - ok 06:00:31.0880 2740 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll 06:00:31.0958 2740 RemoteAccess - ok 06:00:32.0020 2740 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll 06:00:32.0114 2740 RemoteRegistry - ok 06:00:32.0145 2740 [ CB928D9E6DAF51879DD6BA8D02F01321 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys 06:00:32.0176 2740 RFCOMM - ok 06:00:32.0208 2740 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 06:00:32.0301 2740 RpcEptMapper - ok 06:00:32.0364 2740 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe 06:00:32.0442 2740 RpcLocator - ok 06:00:32.0504 2740 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\System32\rpcss.dll 06:00:32.0582 2740 RpcSs - ok 06:00:32.0660 2740 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 06:00:32.0754 2740 rspndr - ok 06:00:32.0800 2740 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys 06:00:32.0894 2740 s3cap - ok 06:00:32.0941 2740 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe 06:00:32.0972 2740 SamSs - ok 06:00:33.0019 2740 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 06:00:33.0081 2740 sbp2port - ok 06:00:33.0144 2740 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll 06:00:33.0268 2740 SCardSvr - ok 06:00:33.0300 2740 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 06:00:33.0378 2740 scfilter - ok 06:00:33.0502 2740 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll 06:00:33.0658 2740 Schedule - ok 06:00:33.0690 2740 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll 06:00:33.0752 2740 SCPolicySvc - ok 06:00:33.0814 2740 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll 06:00:33.0924 2740 SDRSVC - ok 06:00:33.0955 2740 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys 06:00:34.0048 2740 secdrv - ok 06:00:34.0080 2740 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll 06:00:34.0220 2740 seclogon - ok 06:00:34.0236 2740 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\system32\sens.dll 06:00:34.0298 2740 SENS - ok 06:00:34.0314 2740 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll 06:00:34.0407 2740 SensrSvc - ok 06:00:34.0438 2740 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\drivers\serenum.sys 06:00:34.0470 2740 Serenum - ok 06:00:34.0501 2740 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\drivers\serial.sys 06:00:34.0579 2740 Serial - ok 06:00:34.0579 2740 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\drivers\sermouse.sys 06:00:34.0626 2740 sermouse - ok 06:00:34.0672 2740 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll 06:00:34.0782 2740 SessionEnv - ok 06:00:34.0828 2740 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 06:00:34.0891 2740 sffdisk - ok 06:00:34.0922 2740 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 06:00:34.0969 2740 sffp_mmc - ok 06:00:35.0016 2740 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 06:00:35.0078 2740 sffp_sd - ok 06:00:35.0094 2740 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 06:00:35.0156 2740 sfloppy - ok 06:00:35.0218 2740 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll 06:00:35.0312 2740 SharedAccess - ok 06:00:35.0406 2740 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 06:00:35.0499 2740 ShellHWDetection - ok 06:00:35.0546 2740 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys 06:00:35.0562 2740 sisagp - ok 06:00:35.0593 2740 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys 06:00:35.0624 2740 SiSRaid2 - ok 06:00:35.0640 2740 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 06:00:35.0655 2740 SiSRaid4 - ok 06:00:35.0702 2740 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys 06:00:35.0749 2740 Smb - ok 06:00:35.0796 2740 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 06:00:35.0842 2740 SNMPTRAP - ok 06:00:35.0858 2740 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys 06:00:35.0889 2740 spldr - ok 06:00:35.0967 2740 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe 06:00:36.0076 2740 Spooler - ok 06:00:36.0576 2740 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe 06:00:36.0856 2740 sppsvc - ok 06:00:36.0888 2740 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll 06:00:36.0966 2740 sppuinotify - ok 06:00:37.0059 2740 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys 06:00:37.0122 2740 srv - ok 06:00:37.0215 2740 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 06:00:37.0293 2740 srv2 - ok 06:00:37.0340 2740 [ E00FDFAFF025E94F9821153750C35A6D ] SrvHsfHDA C:\Windows\system32\DRIVERS\VSTAZL3.SYS 06:00:37.0418 2740 SrvHsfHDA - ok 06:00:37.0574 2740 [ CEB4E3B6890E1E42DCA6694D9E59E1A0 ] SrvHsfV92 C:\Windows\system32\DRIVERS\VSTDPV3.SYS 06:00:37.0652 2740 SrvHsfV92 - ok 06:00:37.0792 2740 [ BC0C7EA89194C299F051C24119000E17 ] SrvHsfWinac C:\Windows\system32\DRIVERS\VSTCNXT3.SYS 06:00:37.0855 2740 SrvHsfWinac - ok 06:00:37.0886 2740 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 06:00:37.0948 2740 srvnet - ok 06:00:38.0011 2740 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 06:00:38.0151 2740 SSDPSRV - ok 06:00:38.0167 2740 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll 06:00:38.0307 2740 SstpSvc - ok 06:00:38.0338 2740 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\drivers\stexstor.sys 06:00:38.0370 2740 stexstor - ok 06:00:38.0432 2740 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll 06:00:38.0557 2740 StiSvc - ok 06:00:38.0588 2740 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys 06:00:38.0604 2740 storflt - ok 06:00:38.0650 2740 [ 0BF669F0A910BEDA4A32258D363AF2A5 ] StorSvc C:\Windows\system32\storsvc.dll 06:00:38.0760 2740 StorSvc - ok 06:00:38.0806 2740 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys 06:00:38.0838 2740 storvsc - ok 06:00:38.0853 2740 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\DRIVERS\swenum.sys 06:00:38.0884 2740 swenum - ok 06:00:39.0025 2740 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll 06:00:39.0134 2740 swprv - ok 06:00:39.0368 2740 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll 06:00:39.0493 2740 SysMain - ok 06:00:39.0540 2740 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll 06:00:39.0618 2740 TabletInputService - ok 06:00:39.0649 2740 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll 06:00:39.0727 2740 TapiSrv - ok 06:00:39.0742 2740 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll 06:00:39.0820 2740 TBS - ok 06:00:40.0008 2740 [ 7FA2E0F8B072BD04B77B421480B6CC22 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 06:00:40.0054 2740 Tcpip - ok 06:00:40.0101 2740 [ 7FA2E0F8B072BD04B77B421480B6CC22 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 06:00:40.0148 2740 TCPIP6 - ok 06:00:40.0179 2740 [ CCA24162E055C3714CE5A88B100C64ED ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 06:00:40.0257 2740 tcpipreg - ok 06:00:40.0304 2740 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 06:00:40.0413 2740 TDPIPE - ok 06:00:40.0460 2740 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 06:00:40.0476 2740 TDTCP - ok 06:00:40.0507 2740 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 06:00:40.0616 2740 tdx - ok 06:00:40.0678 2740 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys 06:00:40.0710 2740 TermDD - ok 06:00:40.0944 2740 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll 06:00:41.0053 2740 TermService - ok 06:00:41.0100 2740 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll 06:00:41.0162 2740 Themes - ok 06:00:41.0193 2740 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll 06:00:41.0240 2740 THREADORDER - ok 06:00:41.0302 2740 [ CA9E9C2C04A198ED345C1752222A5F3E ] tmactmon C:\Windows\system32\DRIVERS\tmactmon.sys 06:00:41.0334 2740 tmactmon - ok 06:00:41.0412 2740 [ 4D69206E3A3E665221FDD7E397106405 ] TMBMServer C:\Program Files\Trend Micro\BM\TMBMSRV.exe 06:00:41.0505 2740 TMBMServer - ok 06:00:41.0552 2740 [ A3D20789B3FF0576A29462BEF25BCFCC ] tmcomm C:\Windows\system32\DRIVERS\tmcomm.sys 06:00:41.0583 2740 tmcomm - ok 06:00:41.0646 2740 [ 21F215E54770C4BF93EFAF63F58FE57E ] tmevtmgr C:\Windows\system32\DRIVERS\tmevtmgr.sys 06:00:41.0677 2740 tmevtmgr - ok 06:00:41.0739 2740 [ 717E406972BBC07F8FB2A989416CAB73 ] TmFilter C:\Program Files\Trend Micro\OfficeScan Client\TmXPFlt.sys 06:00:41.0755 2740 TmFilter - ok 06:00:42.0036 2740 [ A4F769194F2497C20E27F7504F1FDF10 ] tmlisten C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe 06:00:42.0129 2740 tmlisten - ok 06:00:42.0192 2740 [ 379C4F99994A56B66E11D1E32BB22A1C ] TmPreFilter C:\Program Files\Trend Micro\OfficeScan Client\TmPreFlt.sys 06:00:42.0207 2740 TmPreFilter - ok 06:00:42.0472 2740 [ 7E3601439FF68B4F64AB3342DFBA7FE7 ] TmProxy C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe 06:00:42.0566 2740 TmProxy - ok 06:00:42.0613 2740 [ 50453BC5BA46C6AE2F85FA124A59DA2E ] tmtdi C:\Windows\system32\DRIVERS\tmtdi.sys 06:00:42.0644 2740 tmtdi - ok 06:00:42.0675 2740 [ 5AD05191DC8B444A7BA4D79B76C42A30 ] TPM C:\Windows\system32\drivers\tpm.sys 06:00:42.0722 2740 TPM - ok 06:00:42.0784 2740 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll 06:00:42.0878 2740 TrkWks - ok 06:00:42.0972 2740 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 06:00:43.0096 2740 TrustedInstaller - ok 06:00:43.0128 2740 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 06:00:43.0190 2740 tssecsrv - ok 06:00:43.0221 2740 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 06:00:43.0299 2740 TsUsbFlt - ok 06:00:43.0330 2740 [ 01246F0BAAD7B68EC0F472AA41E33282 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys 06:00:43.0393 2740 TsUsbGD - ok 06:00:43.0471 2740 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 06:00:43.0518 2740 tunnel - ok 06:00:43.0549 2740 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\drivers\uagp35.sys 06:00:43.0580 2740 uagp35 - ok 06:00:43.0642 2740 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys 06:00:43.0752 2740 udfs - ok 06:00:43.0814 2740 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe 06:00:43.0908 2740 UI0Detect - ok 06:00:43.0939 2740 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 06:00:43.0954 2740 uliagpkx - ok 06:00:43.0986 2740 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\DRIVERS\umbus.sys 06:00:44.0032 2740 umbus - ok 06:00:44.0048 2740 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\drivers\umpass.sys 06:00:44.0126 2740 UmPass - ok 06:00:44.0173 2740 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll 06:00:44.0266 2740 UmRdpService - ok 06:00:44.0360 2740 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll 06:00:44.0469 2740 upnphost - ok 06:00:44.0532 2740 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 06:00:44.0594 2740 usbccgp - ok 06:00:44.0656 2740 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys 06:00:44.0703 2740 usbcir - ok 06:00:44.0734 2740 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 06:00:44.0766 2740 usbehci - ok 06:00:44.0812 2740 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 06:00:44.0875 2740 usbhub - ok 06:00:44.0937 2740 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\drivers\usbohci.sys 06:00:45.0000 2740 usbohci - ok 06:00:45.0031 2740 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\drivers\usbprint.sys 06:00:45.0046 2740 usbprint - ok 06:00:45.0093 2740 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 06:00:45.0187 2740 USBSTOR - ok 06:00:45.0202 2740 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 06:00:45.0249 2740 usbuhci - ok 06:00:45.0280 2740 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll 06:00:45.0421 2740 UxSms - ok 06:00:45.0452 2740 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe 06:00:45.0499 2740 VaultSvc - ok 06:00:45.0561 2740 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 06:00:45.0592 2740 vdrvroot - ok 06:00:45.0686 2740 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe 06:00:45.0795 2740 vds - ok 06:00:45.0826 2740 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 06:00:45.0873 2740 vga - ok 06:00:45.0904 2740 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys 06:00:45.0951 2740 VgaSave - ok 06:00:45.0967 2740 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 06:00:46.0029 2740 vhdmp - ok 06:00:46.0107 2740 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys 06:00:46.0138 2740 viaagp - ok 06:00:46.0170 2740 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\drivers\viac7.sys 06:00:46.0232 2740 ViaC7 - ok 06:00:46.0263 2740 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys 06:00:46.0294 2740 viaide - ok 06:00:46.0326 2740 [ C2F2911156FDC7817C52829C86DA494E ] vmbus C:\Windows\system32\drivers\vmbus.sys 06:00:46.0357 2740 vmbus - ok 06:00:46.0404 2740 [ D4D77455211E204F370D08F4963063CE ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys 06:00:46.0497 2740 VMBusHID - ok 06:00:46.0560 2740 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys 06:00:46.0622 2740 volmgr - ok 06:00:46.0716 2740 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 06:00:46.0747 2740 volmgrx - ok 06:00:46.0840 2740 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys 06:00:46.0887 2740 volsnap - ok 06:00:47.0433 2740 [ 642EB152CB980AD9181B2161066BE629 ] VSApiNt C:\Program Files\Trend Micro\OfficeScan Client\VSApiNt.sys 06:00:47.0496 2740 VSApiNt - ok 06:00:47.0620 2740 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 06:00:47.0667 2740 vsmraid - ok 06:00:48.0010 2740 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe 06:00:48.0198 2740 VSS - ok 06:00:48.0229 2740 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys 06:00:48.0291 2740 vwifibus - ok 06:00:48.0338 2740 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll 06:00:48.0432 2740 W32Time - ok 06:00:48.0478 2740 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\drivers\wacompen.sys 06:00:48.0525 2740 WacomPen - ok 06:00:48.0556 2740 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 06:00:48.0634 2740 WANARP - ok 06:00:48.0634 2740 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 06:00:48.0681 2740 Wanarpv6 - ok 06:00:48.0790 2740 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 06:00:48.0884 2740 WatAdminSvc - ok 06:00:49.0024 2740 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe 06:00:49.0165 2740 wbengine - ok 06:00:49.0196 2740 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 06:00:49.0305 2740 WbioSrvc - ok 06:00:49.0352 2740 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll 06:00:49.0446 2740 wcncsvc - ok 06:00:49.0477 2740 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 06:00:49.0602 2740 WcsPlugInService - ok 06:00:49.0648 2740 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\drivers\wd.sys 06:00:49.0695 2740 Wd - ok 06:00:49.0773 2740 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 06:00:49.0820 2740 Wdf01000 - ok 06:00:49.0851 2740 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll 06:00:49.0976 2740 WdiServiceHost - ok 06:00:49.0976 2740 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll 06:00:50.0038 2740 WdiSystemHost - ok 06:00:50.0101 2740 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll 06:00:50.0179 2740 WebClient - ok 06:00:50.0226 2740 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll 06:00:50.0304 2740 Wecsvc - ok 06:00:50.0319 2740 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll 06:00:50.0366 2740 wercplsupport - ok 06:00:50.0397 2740 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll 06:00:50.0506 2740 WerSvc - ok 06:00:50.0553 2740 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 06:00:50.0600 2740 WfpLwf - ok 06:00:50.0631 2740 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys 06:00:50.0647 2740 WIMMount - ok 06:00:50.0834 2740 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll 06:00:50.0912 2740 WinDefend - ok 06:00:50.0928 2740 WinHttpAutoProxySvc - ok 06:00:50.0990 2740 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 06:00:51.0037 2740 Winmgmt - ok 06:00:51.0115 2740 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll 06:00:51.0380 2740 WinRM - ok 06:00:51.0442 2740 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 06:00:51.0458 2740 WinUsb - ok 06:00:51.0520 2740 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll 06:00:51.0598 2740 Wlansvc - ok 06:00:51.0817 2740 [ FB01D4AE207B9EFDBABFC55DC95C7E31 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 06:00:51.0895 2740 wlidsvc - ok 06:00:51.0926 2740 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 06:00:51.0942 2740 WmiAcpi - ok 06:00:51.0988 2740 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 06:00:52.0129 2740 wmiApSrv - ok 06:00:52.0285 2740 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe 06:00:52.0378 2740 WMPNetworkSvc - ok 06:00:52.0425 2740 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll 06:00:52.0503 2740 WPCSvc - ok 06:00:52.0519 2740 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 06:00:52.0706 2740 WPDBusEnum - ok 06:00:52.0753 2740 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 06:00:52.0815 2740 ws2ifsl - ok 06:00:52.0878 2740 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\system32\wscsvc.dll 06:00:53.0018 2740 wscsvc - ok 06:00:53.0018 2740 WSearch - ok 06:00:53.0190 2740 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll 06:00:53.0580 2740 wuauserv - ok 06:00:53.0626 2740 [ E714A1C0354636837E20CCBF00888EE7 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 06:00:53.0720 2740 WudfPf - ok 06:00:53.0814 2740 [ 1023EE888C9B47178C5293ED5336AB69 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 06:00:53.0892 2740 WUDFRd - ok 06:00:53.0923 2740 [ 8D1E1E529A2C9E9B6A85B55A345F7629 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 06:00:53.0985 2740 wudfsvc - ok 06:00:54.0032 2740 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll 06:00:54.0126 2740 WwanSvc - ok 06:00:54.0157 2740 ================ Scan global =============================== 06:00:54.0188 2740 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll 06:00:54.0250 2740 [ 183B4188D5D91B271613EC3EFD1B3CEF ] C:\Windows\system32\winsrv.dll 06:00:54.0297 2740 [ 183B4188D5D91B271613EC3EFD1B3CEF ] C:\Windows\system32\winsrv.dll 06:00:54.0360 2740 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll 06:00:54.0438 2740 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe 06:00:54.0531 2740 [Global] - ok 06:00:54.0531 2740 ================ Scan MBR ================================== 06:00:54.0547 2740 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 06:00:54.0547 2740 Suspicious mbr (Forged): \Device\Harddisk0\DR0 06:00:54.0672 2740 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected 06:00:54.0672 2740 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0) 06:00:55.0171 2740 \Device\Harddisk0\DR0 ( TDSS File System ) - warning 06:00:55.0171 2740 \Device\Harddisk0\DR0 - detected TDSS File System (1) 06:00:55.0171 2740 [ D60C3F43B7154600E165B5AD24389474 ] \Device\Harddisk1\DR1 06:00:57.0214 2740 \Device\Harddisk1\DR1 - ok 06:00:57.0214 2740 ================ Scan VBR ================================== 06:00:57.0230 2740 [ 83C0771810F854807E66D8F82B0ED0AD ] \Device\Harddisk0\DR0\Partition1 06:00:57.0230 2740 \Device\Harddisk0\DR0\Partition1 - ok 06:00:57.0246 2740 [ 308AD796C2AE3617A478980267035EA1 ] \Device\Harddisk0\DR0\Partition2 06:00:57.0246 2740 \Device\Harddisk0\DR0\Partition2 - ok 06:00:57.0261 2740 ============================================================ 06:00:57.0261 2740 Scan finished 06:00:57.0261 2740 ============================================================ 06:00:57.0261 2700 Detected object count: 3 06:00:57.0261 2700 Actual detected object count: 3 06:01:01.0239 2700 10638432 ( ForgedFile.Multi.Generic ) - skipped by user 06:01:01.0239 2700 10638432 ( ForgedFile.Multi.Generic ) - User select action: Skip 06:01:02.0160 2700 \Device\Harddisk0\DR0\# - copied to quarantine 06:01:02.0175 2700 \Device\Harddisk0\DR0 - copied to quarantine 06:01:02.0238 2700 \Device\Harddisk0\DR0\TDLFS\ldrm - copied to quarantine 06:01:02.0253 2700 \Device\Harddisk0\DR0\TDLFS\cmd.dll - copied to quarantine 06:01:02.0316 2700 \Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine 06:01:02.0347 2700 \Device\Harddisk0\DR0\TDLFS\sub.dll - copied to quarantine 06:01:02.0409 2700 \Device\Harddisk0\DR0\TDLFS\subx.dll - copied to quarantine 06:01:02.0472 2700 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine 06:01:02.0550 2700 \Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine 06:01:02.0628 2700 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine 06:01:02.0706 2700 \Device\Harddisk0\DR0\TDLFS\servers.dat - copied to quarantine 06:01:02.0784 2700 \Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine 06:01:02.0846 2700 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine 06:01:02.0955 2700 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine 06:01:03.0033 2700 \Device\Harddisk0\DR0\TDLFS\s - copied to quarantine 06:01:03.0111 2700 \Device\Harddisk0\DR0\TDLFS\u - copied to quarantine 06:01:03.0127 2700 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - will be cured on reboot 06:01:03.0127 2700 \Device\Harddisk0\DR0 - ok 06:01:03.0142 2700 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - User select action: Cure 06:01:03.0142 2700 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user 06:01:03.0142 2700 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip 06:01:06.0964 2252 Deinitialize success And now for time stamped log number 5….. 06:02:27.0946 2704 TDSS rootkit removing tool [removed] Aug 20 2012 17:30:03 06:02:28.0008 2704 ============================================================ 06:02:28.0008 2704 Current date / time: 2012/08/22 06:02:28.0008 06:02:28.0008 2704 SystemInfo: 06:02:28.0008 2704 06:02:28.0008 2704 OS Version: 6.1.7601 ServicePack: 1.0 06:02:28.0008 2704 Product type: Workstation 06:02:28.0008 2704 ComputerName: HANNAH 06:02:28.0008 2704 UserName: Nikki 06:02:28.0008 2704 Windows directory: C:\Windows 06:02:28.0008 2704 System windows directory: C:\Windows 06:02:28.0008 2704 Processor architecture: Intel x86 06:02:28.0008 2704 Number of processors: 2 06:02:28.0008 2704 Page size: 0x1000 06:02:28.0008 2704 Boot type: Normal boot 06:02:28.0008 2704 ============================================================ 06:02:31.0315 2704 BG loaded 06:02:31.0934 2704 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2861, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000050 06:02:31.0964 2704 Drive \Device\Harddisk1\DR1 - Size: 0x1DDD00000 (7.47 Gb), SectorSize: 0x200, Cylinders: 0x3CE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 06:02:31.0964 2704 ============================================================ 06:02:31.0964 2704 \Device\Harddisk0\DR0: 06:02:31.0984 2704 MBR partitions: 06:02:31.0984 2704 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 06:02:31.0984 2704 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x94DC800 06:02:31.0984 2704 \Device\Harddisk1\DR1: 06:02:31.0984 2704 MBR partitions: 06:02:31.0984 2704 ============================================================ 06:02:32.0024 2704 C: <-> \Device\Harddisk0\DR0\Partition2 06:02:32.0024 2704 ============================================================ 06:02:32.0024 2704 Initialize success 06:02:32.0024 2704 ============================================================

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI