This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Problems starting windows

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Every time I start my pc this message appears: There is a problem starting C:\Users\AppData\Local\Temp\O__u_I_exe This message appears in a RunDLL window. Sometime Windows runs a diagnostic saying there is a problem with start up and it looks like it is running in safe mode, where the image is really crude. These things tend to make me think my computer is infected with some malware or virus. Any suggestions would be greatly appreciated.
Here is the scan I did using the OTL scan
OTL logfile created on: 9/15/2012 10:10:37 AM - Run 1
OTL by OldTimer - Version 3.2.61.4 Folder = C:\Users\Michael\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.71 Gb Available Physical Memory | 35.79% Memory free
3.98 Gb Paging File | 1.97 Gb Available in Paging File | 49.42% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.31 Gb Total Space | 308.07 Gb Free Space | 66.21% Space Free | Partition Type: NTFS
Drive I: | 74.31 Gb Total Space | 45.13 Gb Free Space | 60.73% Space Free | Partition Type: FAT32

Computer Name: MICHAEL-PC | User Name: Michael | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Michael\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Users\Michael\AppData\Local\Amazon\Cloud Drive\AmazonCloudDrive.exe ()
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE (Microsoft Corporation.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE (Microsoft Corporation.)
PRC - C:\Users\Michael\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Web Assistant\ExtensionUpdaterService.exe ()
PRC - C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Users\Michael\AppData\Local\Amazon\Cloud Drive\jre\bin\javaw.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Amazon\Amazon Unbox Video\ADVWindowsClientSystemTray.exe (Amazon.com)
PRC - C:\Program Files (x86)\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe (Amazon.com)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Kodak\MediaImpression\ArcMonitor.exe (ArcSoft, Inc.)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpy.exe ()
PRC - \\.\globalroot\systemroot\svchost.exe ()
PRC - \\.\globalroot\systemroot\svchost.exe ()
PRC - C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe ()
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files (x86)\CA\PPRT\bin\ITMRTSVC.exe (CA, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Users\Michael\AppData\Local\Amazon\Cloud Drive\AmazonCloudDrive.exe ()
MOD - C:\Users\Michael\AppData\Local\Temp\sqlite-3.7.2-sqlitejdbc.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Program Files (x86)\Yahoo!\Messenger\yui.dll ()
MOD - C:\Users\Michael\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpy.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (Web Assistant Updater) – C:\Program Files\Web Assistant\ExtensionUpdaterService.exe ()
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (lxda_device) – C:\Windows\SysNative\lxdacoms.exe ( )
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (McAfee SiteAdvisor Service) – c:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe (McAfee, Inc.)
SRV - (BBUpdate) – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (AntiVirService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirSchedulerService) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (ADVService) – C:\Program Files (x86)\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe (Amazon.com)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe (McAfee, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (AntiSpywareService) – C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe ()
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (ITMRTSVC) – C:\Program Files (x86)\CA\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
SRV - (lxda_device) – C:\Windows\SysWOW64\lxdacoms.exe ( )


========== Driver Services (SafeList) ==========

DRV:64bit: - (avipbb) – C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) – C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (avkmgr) – C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH)
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (kcusbser) – C:\Windows\SysNative\drivers\kcusbser.sys (Kyocera Corporation)
DRV:64bit: - (androidusb) – C:\Windows\SysNative\drivers\androidusb.sys (Kyocera Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE:64bit: - HKLM\..\SearchScopes\{CD1E221F-55E0-4505-A576-5BF15351149A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {86FDC6B9-BD92-43A3-831A-50AD37A4DC64}
IE - HKLM\..\SearchScopes\{86FDC6B9-BD92-43A3-831A-50AD37A4DC64}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2269050

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nmd.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredibar.com/mb139?a=6OyGk4b7id&i;=26
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2269050
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredibar.com/mb139/?searc…k4b7id&i;=26
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo.com/search?p={searchTe…&fr;=chr-rog
IE - HKCU\..\SearchScopes\{E94D42A1-3A0A-41C3-B2A5-1BD2EBF8B55E}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKCU\..\SearchScopes\{F095866D-3775-4B2E-BFB7-214051690903}: "URL" = http://search.yahoo.com/search?fr=mcafee&p;={SearchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========



FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_271.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX [2012/08/26 06:15:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/09/15 12:55:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox [2012/08/26 06:15:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/07 00:19:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/09/14 22:18:17 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/07 00:19:29 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/09/14 22:18:17 | 000,000,000 | —D | M]

[2011/02/12 18:30:57 | 000,000,000 | —D | M] (No name found) – C:\Users\Michael\AppData\Roaming\Mozilla\Extensions
[2012/08/01 06:57:45 | 000,000,000 | —D | M] (No name found) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\jgjzbyix.default\extensions
[2012/08/26 06:15:19 | 000,000,000 | —D | M] ("Free YouTube Download (Free Studio) Menu") – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\jgjzbyix.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012/08/26 06:15:18 | 000,000,000 | —D | M] (@@toolbarname@@) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\jgjzbyix.default\extensions\[removed]
[2012/09/13 20:13:06 | 000,000,000 | —D | M] (No name found) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions
[2012/08/26 06:15:19 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/08/26 06:15:19 | 000,000,000 | —D | M] (XFINITY Toolbar) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\{4b9bcce8-a70b-402a-a7e1-db96831ee26f}
[2012/08/26 06:15:20 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/08/26 06:15:20 | 000,000,000 | —D | M] (DVDVideoSoftTB Community Toolbar) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2012/08/26 06:15:20 | 000,000,000 | —D | M] ("Free YouTube Download (Free Studio) Menu") – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012/08/26 06:15:19 | 000,000,000 | —D | M] (Conduit Engine) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\[removed]
[2012/08/26 06:15:19 | 000,000,000 | —D | M] (Super Video Downloader) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\[removed]
[2012/08/26 06:15:19 | 000,000,000 | —D | M] ("Ask Toolbar") – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\[removed]
[1832/11/28 23:44:26 | 000,004,819 | —- | M] () (No name found) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\jgjzbyix.default\extensions\[removed]
[2012/08/20 22:39:52 | 000,243,317 | —- | M] () (No name found) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\[removed]
[2099/01/01 12:00:00 | 000,004,819 | —- | M] () (No name found) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\[removed]
[2012/09/12 15:24:26 | 000,621,521 | —- | M] () (No name found) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\[removed]
[2012/07/25 14:11:53 | 000,741,958 | —- | M] () (No name found) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/09/13 20:13:06 | 000,270,876 | —- | M] () (No name found) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2012/09/07 00:19:23 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/09/07 00:19:23 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA}
[2012/09/07 00:19:29 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/02/17 20:13:01 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012/08/29 00:16:43 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/08/29 00:16:43 | 000,002,253 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.60\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.60\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.60\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = I:\iTunes\iTunes Music\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: YouTube = C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Google Search = C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Web Assistant = C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.439_0\
CHR - Extension: SiteAdvisor = C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.50.146.1_0\
CHR - Extension: Gmail = C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\
CHR - Extension: Gmail = C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension64.dll ()
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O2 - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll ()
O2 - BHO: (XFINITY Toolbar) - {4b9bcce8-a70b-402a-a7e1-db96831ee26f} - C:\Program Files (x86)\xfin_portal\comcastdx.dll ()
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Updater For XFIN_PORTAL) - {bb46be07-13eb-4c49-b0f0-fc78b9ea4983} - C:\Program Files (x86)\xfin_portal\auxi\comcastAu.dll (Visicom Media)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (XFINITY Toolbar) - {4b9bcce8-a70b-402a-a7e1-db96831ee26f} - C:\Program Files (x86)\xfin_portal\comcastdx.dll ()
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [ArcSoft MediaImpression Monitor] C:\Program Files (x86)\Kodak\MediaImpression\ArcMonitor.exe (ArcSoft, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKCU..\Run: [Amazon Cloud Drive] C:\Users\Michael\AppData\Local\Amazon\Cloud Drive\AmazonCloudDrive.exe ()
O4 - HKCU..\Run: [Apple Computer] rundll32.exe ",CreateInstance File not found
O4 - HKCU..\Run: [ComcastAntispyClient] C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntispy.exe ()
O4 - HKCU..\Run: [Desktop Software] C:\Program Files (x86)\Common Files\SupportSoft\bin\bcont.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [Diagnostics] rundll32.exe "C:\Users\Michael\AppData\Local\Temp\",CreateInstance File not found
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Spotify] C:\Users\Michael\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\Michael\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
O4 - Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube Download - C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6B27F04F-8373-47B8-99A5-C007B39BFD32}: DhcpNameServer = 192.168.10.1
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{87e18cb4-814f-11e0-ac9c-4487fcdbb7d0}\Shell - "" = AutoRun
O33 - MountPoints2\{87e18cb4-814f-11e0-ac9c-4487fcdbb7d0}\Shell\AutoRun\command - "" = J:\MI.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.ac3filter - ac3filter64.acm ()
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.ac3filter - C:\Windows\SysWow64\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\Windows\SysWow64\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/09/14 22:15:54 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{D3B83377-1990-4731-8564-BB70D55CF501}
[2012/09/14 13:27:28 | 000,000,000 | —D | C] – C:\ProgramData\Sendori
[2012/09/14 13:27:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sendori
[2012/09/14 13:27:20 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Roaming\OpenCandy
[2012/09/14 08:49:55 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{A55A1049-5110-4413-9196-924C7B8F546A}
[2012/09/14 06:36:50 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{126CB019-75B4-431C-B1F9-2BC67436FBE5}
[2012/09/14 03:23:23 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{66A3CE22-8860-4A9E-92E6-D0BFE788906B}
[2012/09/13 08:08:18 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{37FB64AE-DC49-4BB5-A689-D264C6988593}
[2012/09/13 06:09:50 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{526F2048-0EA2-4B52-8DBD-4F84CA33D037}
[2012/09/13 04:18:30 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{048088E1-41B9-4A5D-9205-15BF87B774CB}
[2012/09/12 06:15:45 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{5B85A6B2-8B15-4125-BF9F-2D90C11A5333}
[2012/09/12 04:16:32 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{DAAB261B-EAB1-4E0D-8BD4-4772462FE414}
[2012/09/11 16:15:57 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{4AFB4EE1-F7CC-4F3F-9266-7C045C5C90F0}
[2012/09/09 12:44:26 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{D7F914F8-78F3-40DA-A535-D4971B464467}
[2012/09/07 00:19:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012/09/01 10:20:59 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{5E0607A6-87BB-4588-BBA8-87E718B7BE02}
[2012/08/30 14:10:14 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{AC4465CE-1426-4ACB-81FB-C94AC5ED4CEA}
[2012/08/29 13:23:31 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{B8F86225-89D8-401F-A1F8-387615E9D267}
[2012/08/28 11:04:42 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{2FB6718B-2C6D-472C-AF3A-9F6BA45898E2}
[2012/08/27 23:44:17 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\Adobe
[2012/08/27 06:25:28 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{3E75A750-7615-4BD4-AD5C-BBD17BB1141A}
[2012/08/26 03:21:49 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{1E4582EB-E3AB-4C46-A8AD-2BA75006C17E}
[2012/08/25 11:50:16 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{D7CCB081-D9DE-4088-97A9-DEDD7F75568A}
[2012/08/23 23:38:31 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{981DB989-DD5A-4956-BD00-01BED898E3A8}
[2012/08/23 19:14:37 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/08/23 19:03:11 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{F7A6283C-82CE-481C-A251-0AD24AF9D303}
[2012/08/22 12:02:15 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{D2C926F0-721E-47A7-AC12-F420C144DA51}
[2012/08/21 13:07:11 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{BB3E39F2-818A-4A05-872B-48BF007E3A14}
[2012/08/20 22:59:58 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{A4019318-FA38-4C2D-8DFD-AA3701FD8223}
[2012/08/20 10:59:22 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{D5283F8C-CFE8-4C2C-8DF9-67149639F353}
[2012/08/18 17:31:36 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{49321E89-5374-44B2-B2F6-C26771A5197A}
[2012/08/18 17:31:24 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{C128631C-E590-482C-B20E-0D203B0A1ED8}

========== Files - Modified Within 30 Days ==========

File not found – C:\Windows\SysNative\
[2012/09/15 10:10:34 | 000,727,334 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/09/15 10:10:34 | 000,624,614 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/09/15 10:10:34 | 000,106,732 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/09/15 10:07:06 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/15 10:03:59 | 000,000,129 | —- | M] () – C:\Windows\SysNative\MRT.INI
[2012/09/15 10:03:29 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/15 10:03:29 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/15 09:56:14 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/15 09:55:50 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/09/15 09:55:45 | 292,055,294 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/09/15 09:55:42 | 1602,985,984 | -HS- | M] () – C:\hiberfil.sys
[2012/09/14 03:00:37 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/13 20:17:04 | 000,054,459 | —- | M] () – C:\Users\Michael\Desktop\377302_10150911262267824_239339168_n.jpg
[2012/09/11 16:16:53 | 000,000,268 | —- | M] () – C:\Windows\Lexstat.ini
[2012/09/08 10:22:18 | 000,002,457 | —- | M] () – C:\Users\Michael\Desktop\Jesse resume.pdf
[2012/09/02 10:13:50 | 000,002,347 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/08/29 13:17:10 | 000,029,660 | —- | M] () – C:\Users\Michael\Desktop\belinda-en-el-amor-hay-que-perdonar.jpg
[2012/08/25 11:59:12 | 000,719,452 | —- | M] () – C:\Users\Michael\Desktop\desiderata-postcard-5.jpg
[2012/08/24 11:11:20 | 000,096,898 | —- | M] () – C:\Users\Michael\Desktop\christina aguilera i am stripped made by oly wood.jpeg

========== Files Created - No Company Name ==========

File not found – C:\Windows\SysNative\
[2012/09/13 20:16:54 | 000,054,459 | —- | C] () – C:\Users\Michael\Desktop\377302_10150911262267824_239339168_n.jpg
[2012/09/08 10:22:18 | 000,002,457 | —- | C] () – C:\Users\Michael\Desktop\Jesse resume.pdf
[2012/08/29 13:11:42 | 000,029,660 | —- | C] () – C:\Users\Michael\Desktop\belinda-en-el-amor-hay-que-perdonar.jpg
[2012/08/25 11:41:36 | 000,719,452 | —- | C] () – C:\Users\Michael\Desktop\desiderata-postcard-5.jpg
[2012/08/24 11:11:19 | 000,096,898 | —- | C] () – C:\Users\Michael\Desktop\christina aguilera i am stripped made by oly wood.jpeg
[2012/07/03 11:38:18 | 004,503,728 | —- | C] () – C:\ProgramData\l_u0_0.pad
[2012/05/15 11:07:35 | 002,011,303 | —- | C] () – C:\Users\Michael\Video05022012014850.3g2
[2012/01/11 14:49:10 | 000,002,048 | -HS- | C] () – C:\Windows\SysWOW64\config\systemprofile\AppData\Local\{b78eaa2b-9260-b0cd-dade-494fe06d1908}\@
[2012/01/11 14:49:10 | 000,002,048 | -HS- | C] () – C:\Windows\System32\config\systemprofile\AppData\Local\{b78eaa2b-9260-b0cd-dade-494fe06d1908}\@
[2012/01/11 14:49:10 | 000,002,048 | -HS- | C] () – C:\Windows\Installer\{b78eaa2b-9260-b0cd-dade-494fe06d1908}\@
[2012/01/11 14:49:10 | 000,002,048 | -HS- | C] () – C:\Users\Michael\AppData\Local\{b78eaa2b-9260-b0cd-dade-494fe06d1908}\@
[2012/01/01 05:34:41 | 000,000,000 | —- | C] () – C:\Users\Michael\AppData\Local\{4BDD0237-B635-4C96-A1F4-6FC5304ACEFD}
[2011/09/27 19:32:30 | 000,216,765 | —- | C] () – C:\Users\Michael\IMG_20110927_172630.jpg
[2011/04/11 16:59:54 | 000,005,120 | —- | C] () – C:\Users\Michael\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/17 21:20:25 | 000,743,538 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/02/13 20:35:45 | 000,000,268 | —- | C] () – C:\Windows\Lexstat.ini
[2011/02/13 20:34:59 | 001,224,704 | —- | C] ( ) – C:\Windows\SysWow64\lxdaserv.dll
[2011/02/13 20:34:59 | 000,991,232 | —- | C] ( ) – C:\Windows\SysWow64\lxdausb1.dll
[2011/02/13 20:34:59 | 000,696,320 | —- | C] ( ) – C:\Windows\SysWow64\lxdahbn3.dll
[2011/02/13 20:34:59 | 000,684,032 | —- | C] ( ) – C:\Windows\SysWow64\lxdacomc.dll
[2011/02/13 20:34:59 | 000,643,072 | —- | C] ( ) – C:\Windows\SysWow64\lxdapmui.dll
[2011/02/13 20:34:59 | 000,585,728 | —- | C] ( ) – C:\Windows\SysWow64\lxdalmpm.dll
[2011/02/13 20:34:59 | 000,537,520 | —- | C] ( ) – C:\Windows\SysWow64\lxdacoms.exe
[2011/02/13 20:34:59 | 000,421,888 | —- | C] ( ) – C:\Windows\SysWow64\lxdacomm.dll
[2011/02/13 20:34:59 | 000,413,696 | —- | C] () – C:\Windows\SysWow64\lxdautil.dll
[2011/02/13 20:34:59 | 000,413,696 | —- | C] ( ) – C:\Windows\SysWow64\lxdainpa.dll
[2011/02/13 20:34:59 | 000,397,312 | —- | C] ( ) – C:\Windows\SysWow64\lxdaiesc.dll
[2011/02/13 20:34:59 | 000,385,968 | —- | C] ( ) – C:\Windows\SysWow64\lxdaih.exe
[2011/02/13 20:34:59 | 000,381,872 | —- | C] ( ) – C:\Windows\SysWow64\lxdacfg.exe
[2011/02/13 20:34:59 | 000,274,432 | —- | C] () – C:\Windows\SysWow64\LXDAinst.dll
[2011/02/13 20:34:59 | 000,181,168 | —- | C] ( ) – C:\Windows\SysWow64\lxdappls.exe
[2011/02/13 20:34:59 | 000,163,840 | —- | C] ( ) – C:\Windows\SysWow64\lxdaprox.dll
[2011/02/13 20:34:59 | 000,094,208 | —- | C] ( ) – C:\Windows\SysWow64\lxdapplc.dll
[2009/07/31 00:42:53 | 000,002,746 | —- | C] () – C:\Users\Michael\.recently-used.xbel
[2009/07/07 00:16:40 | 000,000,042 | —- | C] () – C:\Users\Michael\default.pls

========== LOP Check ==========

[2011/02/19 02:49:48 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\Amazon
[2012/08/26 06:15:18 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\Audacity
[2011/11/12 20:21:02 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\com.amazon.music.uploader
[2012/09/15 09:57:28 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\Dropbox
[2012/09/14 13:28:03 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\DVDVideoSoft
[2012/04/21 12:27:45 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers
[2012/02/15 18:21:40 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\FutureDial
[2012/08/30 01:13:51 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\IrfanView
[2012/09/14 19:13:40 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\OpenCandy
[2012/06/28 08:24:46 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\SendSpace
[2012/09/11 16:12:59 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\SoftGrid Client
[2012/09/15 09:57:24 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\Spotify
[2011/02/17 21:21:20 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\TP
[2011/04/02 22:52:26 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\Windows Live Writer
[2012/09/15 06:52:03 | 000,032,572 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/13 21:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 15:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 01:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 20:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 00:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 00:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 00:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 01:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 01:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 00:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 08:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 01:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 00:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 20:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 01:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 01:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 01:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 21:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 21:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 21:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 21:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: IEXPLORE.EXE >
[2011/11/05 00:28:03 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=0377589BF14A6E5667B730D6D6DB59B4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16912_none_0fae4f323e42a646\iexplore.exe
[2012/02/28 00:42:27 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=09F6A10AB424E2DE445153065FA076BF – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16968_none_19d2eba472c68c00\iexplore.exe
[2012/06/27 02:05:59 | 000,696,408 | —- | M] (Microsoft Corporation) MD5=156169FAD6DEACEEF4BAFFEE8A662C4F – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17051_none_0f81e75a3e642ff5\iexplore.exe
[2012/04/20 00:08:37 | 000,672,856 | —- | M] (Microsoft Corporation) MD5=27019747D97AB5CEFB97677DBB5CF577 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17006_none_1a11a2ba7297e4ee\iexplore.exe
[2011/04/22 15:15:52 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=281C23EC5BCB1853A5D571F1A6E52FB1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20949_none_101e7c5957724e1d\iexplore.exe
[2009/07/13 20:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_19ba3f8a72d988f3\iexplore.exe
[2011/12/16 03:03:08 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=38668C6CADABC9487C683FADD3D165D0 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16930_none_19eb591872b56d75\iexplore.exe
[2011/08/19 23:35:15 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=41FE5E37EFE0B587A688BA0E4FA41288 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16869_none_19d3ea0872c5a830\iexplore.exe
[2011/11/05 00:34:31 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=441C397A9ECF07747920F7F5E40B419B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21085_none_0fef13a357968bc7\iexplore.exe
[2012/04/19 23:53:37 | 000,672,856 | —- | M] (Microsoft Corporation) MD5=4866404D6657D6E50619CCAF56B17D27 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21198_none_1a3bf0cd8bfcb2df\iexplore.exe
[2012/06/27 02:06:52 | 000,696,408 | —- | M] (Microsoft Corporation) MD5=5421E66F9F91F221B9B88AAE11B0CFE7 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21245_none_101a571f57761651\iexplore.exe
[2012/06/27 01:05:29 | 000,672,856 | —- | M] (Microsoft Corporation) MD5=555D62228092C7F87B9930F85F833297 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17051_none_19d691ac72c4f1f0\iexplore.exe
[2011/04/22 14:29:16 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=64EFAF916C4009F1B84153D0BB491FB0 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16800_none_1a0bc6f6729d1c7b\iexplore.exe
[2012/02/28 01:38:39 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=69073D126F71A4F0FFF1DEE5082A0052 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16968_none_0f7e41523e65ca05\iexplore.exe
[2011/06/21 01:14:22 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=6B2383EDA3956983E3219A62D8408DAB – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20992_none_0fe16ab757a12871\iexplore.exe
[2011/06/21 00:25:30 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6BB506124872ACDFAC5BD912CA1334CE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20992_none_1a3615098c01ea6c\iexplore.exe
[2010/12/18 01:17:48 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=700B40EA39DFB25517A81032F03D6D20 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16722_none_0fa37b7a3e4ac7e9\iexplore.exe
[2010/11/20 08:28:25 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Program Files\Internet Explorer\iexplore.exe
[2010/11/20 08:28:25 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2012/02/28 00:44:39 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=8AFD61FB2D96C8229B7D8604F62FA692 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21158_none_1a67307d8bdc431b\iexplore.exe
[2010/12/18 01:11:10 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=8C6C32E4AF8A3D7155656F5897C504E0 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20861_none_1000d84b5789be20\iexplore.exe
[2011/11/04 23:38:00 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=8ED7C19AEFA3673AADB0D6864B03FBCE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16912_none_1a02f98472a36841\iexplore.exe
[2010/12/18 00:32:25 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=9321CF0D023528C71E3645F8433C86C8 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20861_none_1a55829d8bea801b\iexplore.exe
[2012/06/27 01:11:42 | 000,672,832 | —- | M] (Microsoft Corporation) MD5=9B80D4B1CAD7C4160D9B2D65D468E336 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21245_none_1a6f01718bd6d84c\iexplore.exe
[2011/06/21 00:37:00 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=A3AB0A260049BE22AB52E302D9220A92 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16839_none_19f459cc72ad545d\iexplore.exe
[2011/12/16 03:45:57 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=A3F56CED7B94A30BE8954387F0E2B5D2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16930_none_0f96aec63e54ab7a\iexplore.exe
[2011/11/04 23:39:45 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=A8A14CD0CB499B80412F75D53996AE29 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21085_none_1a43bdf58bf74dc2\iexplore.exe
[2010/12/18 00:33:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AA08B68EF4E35EFA170CF85A44B23B70 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16722_none_19f825cc72ab89e4\iexplore.exe
[2011/02/24 00:45:11 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AB2BB40A5FE49AD236791AC22BD08869 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_1a9d66118bb386fd\iexplore.exe
[2011/08/20 00:46:07 | 000,696,576 | —- | M] (Microsoft Corporation) MD5=AC1CC7CD5CBE60EFF105BB3C0DC199C5 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16869_none_0f7f3fb63e64e635\iexplore.exe
[2011/06/21 01:21:24 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=B38DE184AC135A4B0AE7D286476FA33F – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16839_none_0f9faf7a3e4c9262\iexplore.exe
[2011/02/24 01:29:19 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=B4881B8F6EDB48CABD44BCC9FB5475C4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_1048bbbf5752c502\iexplore.exe
[2011/12/16 03:42:35 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=C152529FD67ABB61F0609EF5A299794C – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21108_none_104895c75752f56b\iexplore.exe
[2011/12/16 04:19:51 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=C53E41F92B19EC97D987F968403BEC49 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21108_none_1a9d40198bb3b766\iexplore.exe
[2010/11/20 07:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2010/11/20 07:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2011/02/24 00:32:52 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_19d0e74472c85f04\iexplore.exe
[2011/08/20 00:42:38 | 000,696,576 | —- | M] (Microsoft Corporation) MD5=C66C8BF791F9DB974022506265518EE0 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21033_none_102322ab576fcd64\iexplore.exe
[2011/04/22 15:16:25 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=D6F57A9ECB4606076FB9519D1698FCBA – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16800_none_0fb71ca43e3c5a80\iexplore.exe
[2012/04/20 01:26:39 | 000,696,408 | —- | M] (Microsoft Corporation) MD5=D889681C78E7BFE45587398AC42FC2D4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17006_none_0fbcf8683e3722f3\iexplore.exe
[2011/02/24 01:32:09 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=E1BBDE0F187194D4B08335234A4B9FC7 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_0f7c3cf23e679d09\iexplore.exe
[2012/02/28 01:56:21 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=EFCA1150F17BCE44357F03BB61A29966 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21158_none_1012862b577b8120\iexplore.exe
[2012/04/20 01:13:05 | 000,696,408 | —- | M] (Microsoft Corporation) MD5=F293ACB373FD8F090E08F183C06E07ED – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21198_none_0fe7467b579bf0e4\iexplore.exe
[2009/07/13 20:43:43 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe
[2011/04/22 14:11:29 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=F94877A94996B3C12BB31AD722840457 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20949_none_1a7326ab8bd31018\iexplore.exe
[2011/08/19 23:32:44 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=FA623BE79902A7B49FF4F21117B63C83 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21033_none_1a77ccfd8bd08f5f\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/07/13 21:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/07/13 21:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_09122aaf762607df\iexplore.exe.mui
[2009/07/13 21:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 21:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2009/07/13 21:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_1366d501aa86c9da\iexplore.exe.mui
[2009/07/13 21:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/10 16:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.CFG >
[2012/07/27 15:51:34 | 000,586,083 | —- | M] () MD5=6DE4EA437EC1FE6DB27CADB0A7EA8DC2 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.EXE >
[2012/08/13 22:59:18 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 21:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2009/07/13 21:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/13 21:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2009/07/13 21:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009/07/13 21:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 21:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2009/07/13 21:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 16:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 20:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 02:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 01:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 08:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/20 08:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
[2009/07/13 21:29:52 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_26ed83321dc778e1\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2009/07/13 21:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 21:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2012/09/15 09:55:42 | 1602,985,984 | -HS- | M] () – C:\hiberfil.sys
[2012/09/15 09:55:45 | 2137,317,376 | -HS- | M] () – C:\pagefile.sys
[2012/06/28 08:24:38 | 000,000,453 | —- | M] () – C:\user.js

< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/03/08 18:37:20 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >
[2012/01/24 22:38:47 | 000,000,000 | —D | M] – C:\Windows\system32\config\systemprofile\AppData\Local\IsolatedStorage\du1a5tvc.55h\rt53jevq.tzz\Url.udynpsygivp3gt3szhdxwfdfjmzqp5t0\Url.y115muuzdi3qxix11mkqpehmywhq4upe\Files\bak

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/06/25 21:37:41 | 000,000,177 | -HS- | M] () – C:\Users\Michael\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
[2011/02/12 19:23:55 | 000,000,221 | -HS- | M] () – C:\Users\Michael\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2009/06/26 17:05:19 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\Michael\Desktop\ATF-Cleaner.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
Here is the EXTRAS log from the same scan
OTL Extras logfile created on: 9/15/2012 10:10:37 AM - Run 1
OTL by OldTimer - Version 3.2.61.4 Folder = C:\Users\Michael\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.71 Gb Available Physical Memory | 35.79% Memory free
3.98 Gb Paging File | 1.97 Gb Available in Paging File | 49.42% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.31 Gb Total Space | 308.07 Gb Free Space | 66.21% Space Free | Partition Type: NTFS
Drive I: | 74.31 Gb Total Space | 45.13 Gb Free Space | 60.73% Space Free | Partition Type: FAT32

Computer Name: MICHAEL-PC | User Name: Michael | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Reg Error: Value error.] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
http [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{02A5BD31-16AC-45DF-BE9F-A3167BC4AFB2}" = Windows Live Family Safety
"{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{26A24AE4-039D-4CA4-87B4-2F86417005FF}" = Java™ 7 Update 5 (64-bit)
"{336D0C35-8A85-403a-B9D2-65C292C39087}_is1" = Web Assistant 2.0.0.439
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7203911B-70A5-4F68-A2FF-44BAFA5B3112}" = KYOCERA USB Modem M6000 Driver
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{B8AD779A-82DA-4365-A7D0-AD3DCFC55CFF}" = Apple Mobile Device Support
"{CF8FFD12-602B-422D-AF1D-511B411E7632}" = iTunes
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"HDMI" = Intel® Graphics Media Accelerator Driver
"Lexmark 640 Series" = Lexmark 640 Series
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0412CCFF-BFAC-83D8-44FB-3BE60F05FCF8}" = Amazon MP3 Uploader
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}" = Bing Bar
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{3035E526-C5C1-4194-AF49-FE5E2A749AAA}" = FutureDial Suite
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C8C16C8-C208-4B04-BF04-DD2AAEFD55FA}" = Amazon Cloud Drive
"{4EE36D59-254C-4302-A6D6-51FB3D886097}" = TouchCopy 09
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{54A4839E-87F8-4BD1-9682-A349E9943F0A}" = Amazon Unbox Video
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C975D391-7BF6-44A0-A4FF-EDF3CFD88F68}" = ArcSoft MediaImpression for Kodak
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CEF7211D-CE3A-44C4-B321-D84A2099AE94}" = Comcast Desktop Software (v1.2.0.9)
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}" = Microsoft Primary Interoperability Assemblies 2005
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{F05A5232-CE5E-4274-AB27-44EB8105898D}" = CA Pest Patrol Realtime Protection
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"AC3Filter_is1" = AC3Filter 1.63b
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.15
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.12 (Unicode)
"Avira AntiVir Desktop" = Avira Free Antivirus
"CameraUserGuide-PSSX230HSandPSSX220HS" = Canon PowerShot SX230 HS and PowerShot SX220 HS Camera User Guide
"CameraWindowDC8" = Canon Utilities CameraWindow DC 8
"CameraWindowLauncher" = Canon Utilities CameraWindow Launcher
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon MOV Decoder" = Canon MOV Decoder
"Canon MOV Encoder" = Canon MOV Encoder
"com.amazon.music.uploader" = Amazon MP3 Uploader
"DVDVideoSoftTB Toolbar" = DVDVideoSoftTB Toolbar
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4.8
"Free DVD Video Burner_is1" = Free DVD Video Burner version 3.1.5.423
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.11.20.423
"GOM Player" = GOM Player
"Google Chrome" = Google Chrome
"InstallShield_{54A4839E-87F8-4BD1-9682-A349E9943F0A}" = Amazon Unbox Video
"IrfanView" = IrfanView (remove only)
"LAME for Audacity_is1" = LAME v3.98.3 for Audacity
"MapUtility" = Canon Utilities Map Utility
"McAfee Security Scan" = McAfee Security Scan Plus
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"MovieUploaderForYouTube" = Canon Utilities Movie Uploader for YouTube
"Mozilla Firefox 15.0 (x86 en-US)" = Mozilla Firefox 15.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MPEG2 Codec(libmpeg2/mad)" = MPEG2 Codec(libmpeg2/mad)
"MyCamera" = Canon Utilities MyCamera
"MyCamera Download Plugin" = CANON iMAGE GATEWAY MyCamera Download Plugin
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"PhotoStitch" = Canon Utilities PhotoStitch
"Software Guide" = Canon DIGITAL CAMERA Solution Disk Software Guide
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VLC media player 2.0.3
"WavePad" = WavePad Sound Editor
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.00 beta 7 (32-bit)
"Wise Disk Cleaner_is1" = Wise Disk Cleaner 5.83
"Wise Registry Cleaner_is1" = Wise Registry Cleaner 5.9.4
"xfin_portal" = XFINITY Toolbar
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater
"Dropbox" = Dropbox
"f031ef6ac137efc5" = Dell Driver Download Manager
"Mozilla Firefox 15.0.1 (x86 en-US)" = Mozilla Firefox 15.0.1 (x86 en-US)
"Spotify" = Spotify

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 4/25/2012 11:13:10 PM | Computer Name = Michael-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 4/25/2012 11:13:10 PM | Computer Name = Michael-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 998

Error - 4/25/2012 11:13:10 PM | Computer Name = Michael-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 998

Error - 4/25/2012 11:13:11 PM | Computer Name = Michael-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 4/25/2012 11:13:11 PM | Computer Name = Michael-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2776

Error - 4/25/2012 11:13:11 PM | Computer Name = Michael-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2776

Error - 4/25/2012 11:13:12 PM | Computer Name = Michael-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 4/25/2012 11:13:12 PM | Computer Name = Michael-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3775

Error - 4/25/2012 11:13:12 PM | Computer Name = Michael-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3775

Error - 4/25/2012 11:13:13 PM | Computer Name = Michael-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

[ Media Center Events ]
Error - 8/16/2011 7:22:12 PM | Computer Name = Michael-PC | Source = MCUpdate | ID = 0
Description = 6:22:12 PM - Error connecting to the internet. 6:22:12 PM - Unable
to contact server..

Error - 8/16/2011 7:22:32 PM | Computer Name = Michael-PC | Source = MCUpdate | ID = 0
Description = 6:22:29 PM - Error connecting to the internet. 6:22:29 PM - Unable
to contact server..

Error - 1/25/2012 7:15:27 AM | Computer Name = Michael-PC | Source = MCUpdate | ID = 0
Description = 5:15:26 AM - Error connecting to the internet. 5:15:27 AM - Unable
to contact server..

Error - 1/25/2012 7:15:38 AM | Computer Name = Michael-PC | Source = MCUpdate | ID = 0
Description = 5:15:32 AM - Error connecting to the internet. 5:15:32 AM - Unable
to contact server..

Error - 1/25/2012 8:15:50 AM | Computer Name = Michael-PC | Source = MCUpdate | ID = 0
Description = 6:15:49 AM - Error connecting to the internet. 6:15:49 AM - Unable
to contact server..

Error - 1/25/2012 8:16:39 AM | Computer Name = Michael-PC | Source = MCUpdate | ID = 0
Description = 6:15:55 AM - Error connecting to the internet. 6:15:55 AM - Unable
to contact server..

Error - 1/25/2012 9:16:43 AM | Computer Name = Michael-PC | Source = MCUpdate | ID = 0
Description = 7:16:43 AM - Error connecting to the internet. 7:16:43 AM - Unable
to contact server..

Error - 1/25/2012 9:16:50 AM | Computer Name = Michael-PC | Source = MCUpdate | ID = 0
Description = 7:16:48 AM - Error connecting to the internet. 7:16:48 AM - Unable
to contact server..

Error - 1/25/2012 10:16:56 AM | Computer Name = Michael-PC | Source = MCUpdate | ID = 0
Description = 8:16:56 AM - Error connecting to the internet. 8:16:56 AM - Unable
to contact server..

Error - 1/25/2012 10:17:03 AM | Computer Name = Michael-PC | Source = MCUpdate | ID = 0
Description = 8:17:01 AM - Error connecting to the internet. 8:17:01 AM - Unable
to contact server..

[ System Events ]
Error - 9/15/2012 10:56:09 AM | Computer Name = Michael-PC | Source = Service Control Manager | ID = 7024
Description = The Avira Realtime Protection service terminated with service-specific
error %%306.

Error - 9/15/2012 10:56:11 AM | Computer Name = Michael-PC | Source = Service Control Manager | ID = 7003
Description = The IKE and AuthIP IPsec Keying Modules service depends the following
service: BFE. This service might not be installed.

Error - 9/15/2012 10:56:14 AM | Computer Name = Michael-PC | Source = Service Control Manager | ID = 7003
Description = The IPsec Policy Agent service depends the following service: BFE.
This service might not be installed.

Error - 9/15/2012 10:57:20 AM | Computer Name = Michael-PC | Source = Service Control Manager | ID = 7023
Description = The Function Discovery Resource Publication service terminated with
the following error: %%-2147024891

Error - 9/15/2012 10:57:20 AM | Computer Name = Michael-PC | Source = Service Control Manager | ID = 7001
Description = The HomeGroup Provider service depends on the Function Discovery Resource
Publication service which failed to start because of the following error: %%-2147024891

Error - 9/15/2012 11:08:30 AM | Computer Name = Michael-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk5\DR5.

Error - 9/15/2012 11:08:31 AM | Computer Name = Michael-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk5\DR5.

Error - 9/15/2012 11:08:31 AM | Computer Name = Michael-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk5\DR5.

Error - 9/15/2012 11:08:32 AM | Computer Name = Michael-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk5\DR5.

Error - 9/15/2012 11:08:32 AM | Computer Name = Michael-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk5\DR5.


< End of report >
Hello michael6606 and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.

I can see evidence of a serious infection that has password stealing capabilities.

If you use this machine for any kind of financial transactions please go to an uninfected computer and change all of your passwords as soon as you can.

It would also be very wise to backup all of your important data before we begin since this infection can be very difficult to clean, and we may have to resort to a reformat and reinstallation of the operating system if we are unable to clean the infected system.


Lets start with the following:


  • aswMBR


  • Download aswMBR.exe to your desktop.
  • Double click the aswMBR.exe to run it.
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the "Scan" button to start scan.

[external image: Posted Image]

  • On completion of the scan click save log, save it to your desktop and post in your next reply.

[external image: Posted Image]

Please post the aswMBR log in your next reply.
Here is the log from the avast scan aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-09-15 15:38:14 —————————– 15:38:14.175 OS Version: Windows x64 6.1.7601 Service Pack 1 15:38:14.175 Number of processors: 4 586 0x170A 15:38:14.176 ComputerName: MICHAEL-PC UserName: Michael 15:38:16.666 Initialize success 15:39:25.278 AVAST engine defs: 12091400 15:39:28.803 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 15:39:28.803 Disk 0 Vendor: SAMSUNG_HD503HI 1AJ10001 Size: 476940MB BusType: 3 15:39:28.819 Device \Driver\atapi -> MajorFunction fffffa8002e675e8 15:39:28.819 Disk 0 MBR read successfully 15:39:28.819 Disk 0 MBR scan 15:39:28.819 Disk 0 Windows 7 default MBR code 15:39:28.834 Disk 0 MBR hidden 15:39:28.850 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 456 MB offset 2048 15:39:28.866 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 476482 MB offset 935936 15:39:28.881 Disk 0 scanning C:\Windows\system32\drivers 15:39:40.020 Service scanning 15:40:04.418 Modules scanning 15:40:04.418 Disk 0 trace - called modules: 15:40:04.434 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa8002e675e8]<< 15:40:04.449 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80028d4060] 15:40:04.449 3 CLASSPNP.SYS[fffff8800186d43f] -> nt!IofCallDriver -> [0xfffffa8002284670] 15:40:04.449 5 ACPI.sys[fffff88000f4a7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0xfffffa80022a8060] 15:40:04.465 \Driver\atapi[0xfffffa8002816da0] -> IRP_MJ_CREATE -> 0xfffffa8002e675e8 15:40:04.933 AVAST engine scan C:\Windows 15:40:07.101 AVAST engine scan C:\Windows\system32 15:42:53.321 AVAST engine scan C:\Windows\system32\drivers 15:43:04.833 AVAST engine scan C:\Users\Michael 15:55:40.837 AVAST engine scan C:\ProgramData 15:57:19.920 Scan finished successfully 15:59:56.590 Disk 0 MBR has been saved successfully to "C:\Users\Michael\Downloads\MBR.dat" 15:59:56.596 The log file has been saved successfully to "C:\Users\Michael\Downloads\aswMBR.txt"
Hello michael6606

Thank you for the log.

The following tool may present you with the option to clean/cure what has been detected.

At this time please do not clean anything (I would like to review the log produced before deciding on the best course of action):


  • TDSS Killer


  • Please read carefully and follow these steps.
  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and Right click on TDSSKiller.exe and select "Run as Administrator" to run the application.
  • When the window opens, click on Change Parameters.
  • Under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”.
  • Click on OK and then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on SKIP.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

Please post the TDSSKiller log in your next reply.
Scan from the TDSSKiller: 18:29:59.0401 8300 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48 18:29:59.0794 8300 ============================================================ 18:29:59.0794 8300 Current date / time: 2012/09/15 18:29:59.0794 18:29:59.0794 8300 SystemInfo: 18:29:59.0794 8300 18:29:59.0794 8300 OS Version: 6.1.7601 ServicePack: 1.0 18:29:59.0794 8300 Product type: Workstation 18:29:59.0794 8300 ComputerName: MICHAEL-PC 18:29:59.0794 8300 UserName: Michael 18:29:59.0794 8300 Windows directory: C:\Windows 18:29:59.0794 8300 System windows directory: C:\Windows 18:29:59.0794 8300 Running under WOW64 18:29:59.0794 8300 Processor architecture: Intel x64 18:29:59.0794 8300 Number of processors: 4 18:29:59.0794 8300 Page size: 0x1000 18:29:59.0794 8300 Boot type: Normal boot 18:29:59.0794 8300 ============================================================ 18:30:01.0700 8300 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0x1BCE82, SectorsPerTrack: 0x8, TracksPerCylinder: 0x43, Type 'K0', Flags 0x00000040 18:30:01.0716 8300 ============================================================ 18:30:01.0716 8300 \Device\Harddisk0\DR0: 18:30:01.0716 8300 MBR partitions: 18:30:01.0716 8300 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xE4000 18:30:01.0716 8300 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xE4800, BlocksNum 0x3A2A1030 18:30:01.0716 8300 ============================================================ 18:30:01.0796 8300 C: <-> \Device\Harddisk0\DR0\Partition2 18:30:01.0796 8300 ============================================================ 18:30:01.0796 8300 Initialize success 18:30:01.0796 8300 ============================================================ 18:32:38.0293 6684 ============================================================ 18:32:38.0293 6684 Scan started 18:32:38.0293 6684 Mode: Manual; TDLFS; 18:32:38.0293 6684 ============================================================ 18:32:43.0901 6684 ================ Scan system memory ======================== 18:32:43.0901 6684 System memory - ok 18:32:43.0901 6684 ================ Scan services ============================= 18:32:47.0443 6684 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 18:32:47.0460 6684 1394ohci - ok 18:32:47.0688 6684 [ ADC420616C501B45D26C0FD3EF1E54E4 ] ACDaemon C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe 18:32:47.0690 6684 ACDaemon - ok 18:32:47.0738 6684 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 18:32:47.0742 6684 ACPI - ok 18:32:47.0796 6684 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 18:32:47.0797 6684 AcpiPmi - ok 18:32:47.0943 6684 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 18:32:47.0945 6684 AdobeARMservice - ok 18:32:48.0082 6684 [ A9D3B95E8466BD58EEB8A1154654E162 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 18:32:48.0102 6684 AdobeFlashPlayerUpdateSvc - ok 18:32:48.0155 6684 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 18:32:48.0161 6684 adp94xx - ok 18:32:48.0219 6684 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 18:32:48.0224 6684 adpahci - ok 18:32:48.0248 6684 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 18:32:48.0251 6684 adpu320 - ok 18:32:48.0385 6684 [ 96A0FF09E226B023DC6ACA253AACEE2E ] ADVService C:\Program Files (x86)\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe 18:32:48.0386 6684 ADVService - ok 18:32:48.0425 6684 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 18:32:48.0426 6684 AeLookupSvc - ok 18:32:48.0517 6684 [ 6CCD1135320109D6B219F1A6E04AD9F6 ] Afc C:\Windows\syswow64\drivers\Afc.sys 18:32:48.0519 6684 Afc - ok 18:32:48.0576 6684 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 18:32:48.0583 6684 AFD - ok 18:32:48.0657 6684 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 18:32:48.0658 6684 agp440 - ok 18:32:48.0675 6684 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 18:32:48.0677 6684 ALG - ok 18:32:48.0705 6684 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 18:32:48.0706 6684 aliide - ok 18:32:48.0729 6684 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 18:32:48.0731 6684 amdide - ok 18:32:48.0757 6684 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 18:32:48.0758 6684 AmdK8 - ok 18:32:48.0777 6684 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 18:32:48.0778 6684 AmdPPM - ok 18:32:48.0808 6684 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 18:32:48.0809 6684 amdsata - ok 18:32:48.0855 6684 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 18:32:48.0858 6684 amdsbs - ok 18:32:48.0873 6684 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 18:32:48.0875 6684 amdxata - ok 18:32:48.0940 6684 [ E25EBA0CB01A78487E7A825DA9F70641 ] androidusb C:\Windows\system32\Drivers\androidusb.sys 18:32:48.0950 6684 androidusb - ok 18:32:49.0046 6684 [ F9DAC844B1D370DA4C984D4C22F5E696 ] AntiSpywareService C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe 18:32:49.0054 6684 AntiSpywareService - ok 18:32:49.0155 6684 [ 0A1CC583E8147004E4AD4625D7FBF88C ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 18:32:49.0158 6684 AntiVirSchedulerService - ok 18:32:49.0213 6684 [ C9A36EF935ACED86AEDF93E97E606911 ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 18:32:49.0214 6684 AntiVirService - ok 18:32:49.0270 6684 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 18:32:49.0272 6684 AppID - ok 18:32:49.0291 6684 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 18:32:49.0293 6684 AppIDSvc - ok 18:32:49.0316 6684 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll 18:32:49.0318 6684 Appinfo - ok 18:32:49.0398 6684 [ 7EF47644B74EBE721CC32211D3C35E76 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 18:32:49.0400 6684 Apple Mobile Device - ok 18:32:49.0442 6684 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys 18:32:49.0443 6684 arc - ok 18:32:49.0483 6684 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 18:32:49.0485 6684 arcsas - ok 18:32:49.0516 6684 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 18:32:49.0518 6684 AsyncMac - ok 18:32:49.0561 6684 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 18:32:49.0562 6684 atapi - ok 18:32:49.0608 6684 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 18:32:49.0616 6684 AudioEndpointBuilder - ok 18:32:49.0631 6684 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 18:32:49.0636 6684 AudioSrv - ok 18:32:49.0682 6684 [ 26E38B5A58C6C55FAFBC563EEDDB0867 ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys 18:32:49.0684 6684 avgntflt - ok 18:32:49.0726 6684 [ 9D1F00BEFF84CBBF46D7F052BC7E0565 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys 18:32:49.0729 6684 avipbb - ok 18:32:49.0758 6684 [ 248DB59FC86DE44D2779F4C7FB1A567D ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys 18:32:49.0759 6684 avkmgr - ok 18:32:49.0803 6684 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 18:32:49.0805 6684 AxInstSV - ok 18:32:49.0853 6684 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys 18:32:49.0859 6684 b06bdrv - ok 18:32:49.0888 6684 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 18:32:49.0891 6684 b57nd60a - ok 18:32:50.0024 6684 [ F48FEB7DA35821DA15E0B006DCB9A169 ] BBSvc C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe 18:32:50.0027 6684 BBSvc - ok 18:32:50.0041 6684 [ 8E16F7A85441986FD2B9CE6C879524E4 ] BBUpdate C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe 18:32:50.0045 6684 BBUpdate - ok 18:32:50.0068 6684 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 18:32:50.0090 6684 BDESVC - ok 18:32:50.0119 6684 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 18:32:50.0120 6684 Beep - ok 18:32:50.0187 6684 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll 18:32:50.0206 6684 BITS - ok 18:32:50.0365 6684 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 18:32:50.0366 6684 blbdrive - ok 18:32:50.0469 6684 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 18:32:50.0476 6684 Bonjour Service - ok 18:32:50.0523 6684 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 18:32:50.0525 6684 bowser - ok 18:32:50.0576 6684 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 18:32:50.0577 6684 BrFiltLo - ok 18:32:50.0594 6684 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 18:32:50.0596 6684 BrFiltUp - ok 18:32:50.0650 6684 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 18:32:50.0652 6684 Browser - ok 18:32:50.0688 6684 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 18:32:50.0692 6684 Brserid - ok 18:32:50.0721 6684 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 18:32:50.0722 6684 BrSerWdm - ok 18:32:50.0747 6684 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 18:32:50.0749 6684 BrUsbMdm - ok 18:32:50.0764 6684 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 18:32:50.0765 6684 BrUsbSer - ok 18:32:50.0798 6684 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 18:32:50.0799 6684 BTHMODEM - ok 18:32:50.0861 6684 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 18:32:50.0863 6684 bthserv - ok 18:32:50.0890 6684 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 18:32:50.0892 6684 cdfs - ok 18:32:50.0949 6684 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\drivers\cdrom.sys 18:32:50.0951 6684 cdrom - ok 18:32:51.0002 6684 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 18:32:51.0004 6684 CertPropSvc - ok 18:32:51.0057 6684 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys 18:32:51.0058 6684 circlass - ok 18:32:51.0085 6684 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 18:32:51.0089 6684 CLFS - ok 18:32:51.0149 6684 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 18:32:51.0152 6684 clr_optimization_v2.0.50727_32 - ok 18:32:51.0200 6684 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 18:32:51.0203 6684 clr_optimization_v2.0.50727_64 - ok 18:32:51.0270 6684 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 18:32:51.0297 6684 clr_optimization_v4.0.30319_32 - ok 18:32:51.0353 6684 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 18:32:51.0357 6684 clr_optimization_v4.0.30319_64 - ok 18:32:51.0406 6684 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 18:32:51.0408 6684 CmBatt - ok 18:32:51.0437 6684 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 18:32:51.0438 6684 cmdide - ok 18:32:51.0490 6684 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 18:32:51.0497 6684 CNG - ok 18:32:51.0510 6684 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 18:32:51.0511 6684 Compbatt - ok 18:32:51.0560 6684 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 18:32:51.0572 6684 CompositeBus - ok 18:32:51.0585 6684 COMSysApp - ok 18:32:51.0616 6684 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 18:32:51.0617 6684 crcdisk - ok 18:32:51.0677 6684 [ 4F5414602E2544A4554D95517948B705 ] CryptSvc C:\Windows\system32\cryptsvc.dll 18:32:51.0679 6684 CryptSvc - ok 18:32:51.0785 6684 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE 18:32:51.0795 6684 cvhsvc - ok 18:32:51.0853 6684 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 18:32:51.0859 6684 DcomLaunch - ok 18:32:51.0904 6684 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 18:32:51.0909 6684 defragsvc - ok 18:32:51.0943 6684 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 18:32:51.0945 6684 DfsC - ok 18:32:52.0005 6684 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 18:32:52.0009 6684 Dhcp - ok 18:32:52.0042 6684 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 18:32:52.0043 6684 discache - ok 18:32:52.0080 6684 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys 18:32:52.0085 6684 Disk - ok 18:32:52.0132 6684 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 18:32:52.0134 6684 Dnscache - ok 18:32:52.0169 6684 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 18:32:52.0172 6684 dot3svc - ok 18:32:52.0224 6684 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 18:32:52.0226 6684 DPS - ok 18:32:52.0269 6684 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 18:32:52.0270 6684 drmkaud - ok 18:32:52.0322 6684 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 18:32:52.0334 6684 DXGKrnl - ok 18:32:52.0360 6684 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 18:32:52.0362 6684 EapHost - ok 18:32:52.0457 6684 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys 18:32:52.0507 6684 ebdrv - ok 18:32:52.0548 6684 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 18:32:52.0549 6684 EFS - ok 18:32:52.0609 6684 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 18:32:52.0617 6684 ehRecvr - ok 18:32:52.0653 6684 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 18:32:52.0656 6684 ehSched - ok 18:32:52.0694 6684 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 18:32:52.0700 6684 elxstor - ok 18:32:52.0746 6684 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 18:32:52.0747 6684 ErrDev - ok 18:32:52.0818 6684 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 18:32:52.0823 6684 EventSystem - ok 18:32:52.0854 6684 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 18:32:52.0857 6684 exfat - ok 18:32:52.0880 6684 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 18:32:52.0883 6684 fastfat - ok 18:32:52.0949 6684 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 18:32:52.0957 6684 Fax - ok 18:32:52.0977 6684 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys 18:32:52.0978 6684 fdc - ok 18:32:53.0031 6684 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 18:32:53.0032 6684 fdPHost - ok 18:32:53.0064 6684 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 18:32:53.0066 6684 FDResPub - ok 18:32:53.0101 6684 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 18:32:53.0102 6684 FileInfo - ok 18:32:53.0133 6684 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 18:32:53.0146 6684 Filetrace - ok 18:32:53.0177 6684 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 18:32:53.0178 6684 flpydisk - ok 18:32:53.0202 6684 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 18:32:53.0206 6684 FltMgr - ok 18:32:53.0264 6684 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll 18:32:53.0276 6684 FontCache - ok 18:32:53.0345 6684 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 18:32:53.0347 6684 FontCache3.0.0.0 - ok 18:32:53.0360 6684 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 18:32:53.0361 6684 FsDepends - ok 18:32:53.0407 6684 [ 07DA62C960DDCCC2D35836AEAB4FC578 ] fssfltr C:\Windows\system32\DRIVERS\fssfltr.sys 18:32:53.0409 6684 fssfltr - ok 18:32:53.0523 6684 [ 28DDEEEC44E988657B732CF404D504CB ] fsssvc C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe 18:32:53.0553 6684 fsssvc - ok 18:32:53.0580 6684 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 18:32:53.0581 6684 Fs_Rec - ok 18:32:53.0624 6684 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 18:32:53.0627 6684 fvevol - ok 18:32:53.0646 6684 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 18:32:53.0648 6684 gagp30kx - ok 18:32:53.0709 6684 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 18:32:53.0710 6684 GEARAspiWDM - ok 18:32:53.0756 6684 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 18:32:53.0765 6684 gpsvc - ok 18:32:53.0894 6684 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 18:32:53.0896 6684 gupdate - ok 18:32:53.0923 6684 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 18:32:53.0924 6684 gupdatem - ok 18:32:53.0939 6684 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 18:32:53.0940 6684 hcw85cir - ok 18:32:53.0998 6684 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 18:32:54.0003 6684 HdAudAddService - ok 18:32:54.0106 6684 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 18:32:54.0120 6684 HDAudBus - ok 18:32:54.0181 6684 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 18:32:54.0205 6684 HidBatt - ok 18:32:54.0260 6684 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 18:32:54.0281 6684 HidBth - ok 18:32:54.0289 6684 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 18:32:54.0299 6684 HidIr - ok 18:32:54.0390 6684 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll 18:32:54.0402 6684 hidserv - ok 18:32:54.0493 6684 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\drivers\hidusb.sys 18:32:54.0494 6684 HidUsb - ok 18:32:54.0533 6684 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 18:32:54.0535 6684 hkmsvc - ok 18:32:54.0573 6684 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 18:32:54.0576 6684 HomeGroupListener - ok 18:32:54.0626 6684 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 18:32:54.0629 6684 HomeGroupProvider - ok 18:32:54.0650 6684 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 18:32:54.0653 6684 HpSAMD - ok 18:32:54.0695 6684 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 18:32:54.0704 6684 HTTP - ok 18:32:54.0741 6684 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 18:32:54.0742 6684 hwpolicy - ok 18:32:54.0799 6684 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 18:32:54.0801 6684 i8042prt - ok 18:32:54.0857 6684 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 18:32:54.0863 6684 iaStorV - ok 18:32:54.0921 6684 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 18:32:54.0931 6684 idsvc - ok 18:32:55.0062 6684 [ 24CC43ECDEEFD4C19FBBEE4951B647F1 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys 18:32:55.0138 6684 igfx - ok 18:32:55.0162 6684 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 18:32:55.0163 6684 iirsp - ok 18:32:55.0226 6684 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 18:32:55.0235 6684 IKEEXT - ok 18:32:55.0308 6684 [ BC64B75E8E0A0B8982AB773483164E72 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys 18:32:55.0339 6684 IntcAzAudAddService - ok 18:32:55.0395 6684 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 18:32:55.0396 6684 intelide - ok 18:32:55.0522 6684 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 18:32:55.0581 6684 intelppm - ok 18:32:55.0662 6684 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 18:32:55.0665 6684 IPBusEnum - ok 18:32:55.0694 6684 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 18:32:55.0695 6684 IpFilterDriver - ok 18:32:55.0712 6684 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 18:32:55.0715 6684 IPMIDRV - ok 18:32:55.0780 6684 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 18:32:55.0815 6684 IPNAT - ok 18:32:56.0183 6684 [ 50D6CCC6FF5561F9F56946B3E6164FB8 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 18:32:56.0242 6684 iPod Service - ok 18:32:56.0296 6684 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 18:32:56.0297 6684 IRENUM - ok 18:32:56.0328 6684 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 18:32:56.0330 6684 isapnp - ok 18:32:56.0358 6684 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 18:32:56.0362 6684 iScsiPrt - ok 18:32:56.0440 6684 [ 54F694C6CD3A1149BA3A8BDACC83BADC ] ITMRTSVC C:\Program Files (x86)\CA\PPRT\bin\ITMRTSVC.exe 18:32:56.0444 6684 ITMRTSVC - ok 18:32:56.0480 6684 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys 18:32:56.0481 6684 kbdclass - ok 18:32:56.0522 6684 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys 18:32:56.0524 6684 kbdhid - ok 18:32:56.0598 6684 [ 326349D7DF3A7137AEA077CEB1EA8519 ] kcusbser C:\Windows\system32\DRIVERS\kcusbser.sys 18:32:56.0600 6684 kcusbser - ok 18:32:56.0622 6684 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 18:32:56.0623 6684 KeyIso - ok 18:32:56.0663 6684 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 18:32:56.0664 6684 KSecDD - ok 18:32:56.0699 6684 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 18:32:56.0701 6684 KSecPkg - ok 18:32:56.0727 6684 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 18:32:56.0743 6684 ksthunk - ok 18:32:56.0799 6684 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 18:32:56.0805 6684 KtmRm - ok 18:32:56.0839 6684 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll 18:32:56.0844 6684 LanmanServer - ok 18:32:56.0878 6684 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 18:32:56.0881 6684 LanmanWorkstation - ok 18:32:56.0936 6684 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 18:32:56.0937 6684 lltdio - ok 18:32:56.0962 6684 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 18:32:56.0967 6684 lltdsvc - ok 18:32:56.0981 6684 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 18:32:56.0982 6684 lmhosts - ok 18:32:57.0018 6684 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 18:32:57.0020 6684 LSI_FC - ok 18:32:57.0046 6684 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 18:32:57.0048 6684 LSI_SAS - ok 18:32:57.0069 6684 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 18:32:57.0071 6684 LSI_SAS2 - ok 18:32:57.0082 6684 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 18:32:57.0084 6684 LSI_SCSI - ok 18:32:57.0098 6684 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 18:32:57.0101 6684 luafv - ok 18:32:57.0146 6684 lxda_device - ok 18:32:57.0278 6684 [ B891E3920F24FF1A3BEAD6CD2B42ED99 ] McAfee SiteAdvisor Service c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe 18:32:57.0279 6684 McAfee SiteAdvisor Service - ok 18:32:57.0358 6684 [ 22A7776C5D8EB5930EDF9C8DD0884259 ] McComponentHostService C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe 18:32:57.0362 6684 McComponentHostService - ok 18:32:57.0396 6684 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 18:32:57.0398 6684 Mcx2Svc - ok 18:32:57.0426 6684 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 18:32:57.0428 6684 megasas - ok 18:32:57.0446 6684 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 18:32:57.0450 6684 MegaSR - ok 18:32:57.0502 6684 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 18:32:57.0503 6684 MMCSS - ok 18:32:57.0521 6684 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 18:32:57.0522 6684 Modem - ok 18:32:57.0564 6684 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 18:32:57.0565 6684 monitor - ok 18:32:57.0609 6684 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\drivers\mouclass.sys 18:32:57.0646 6684 mouclass - ok 18:32:57.0698 6684 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 18:32:57.0711 6684 mouhid - ok 18:32:57.0758 6684 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 18:32:57.0799 6684 mountmgr - ok 18:32:58.0028 6684 [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 18:32:58.0059 6684 MozillaMaintenance - ok 18:32:58.0106 6684 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 18:32:58.0122 6684 mpio - ok 18:32:58.0146 6684 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 18:32:58.0170 6684 mpsdrv - ok 18:32:58.0635 6684 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 18:32:58.0689 6684 MRxDAV - ok 18:32:58.0769 6684 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 18:32:58.0773 6684 mrxsmb - ok 18:32:58.0872 6684 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 18:32:58.0889 6684 mrxsmb10 - ok 18:32:58.0931 6684 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 18:32:58.0966 6684 mrxsmb20 - ok 18:32:58.0994 6684 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 18:32:58.0995 6684 msahci - ok 18:32:59.0061 6684 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 18:32:59.0064 6684 msdsm - ok 18:32:59.0132 6684 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 18:32:59.0143 6684 MSDTC - ok 18:32:59.0234 6684 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 18:32:59.0249 6684 Msfs - ok 18:32:59.0291 6684 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 18:32:59.0292 6684 mshidkmdf - ok 18:32:59.0344 6684 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 18:32:59.0352 6684 msisadrv - ok 18:32:59.0376 6684 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 18:32:59.0379 6684 MSiSCSI - ok 18:32:59.0384 6684 msiserver - ok 18:32:59.0418 6684 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 18:32:59.0419 6684 MSKSSRV - ok 18:32:59.0437 6684 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 18:32:59.0438 6684 MSPCLOCK - ok 18:32:59.0449 6684 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 18:32:59.0451 6684 MSPQM - ok 18:32:59.0499 6684 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 18:32:59.0504 6684 MsRPC - ok 18:32:59.0515 6684 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 18:32:59.0517 6684 mssmbios - ok 18:32:59.0524 6684 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 18:32:59.0526 6684 MSTEE - ok 18:32:59.0556 6684 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 18:32:59.0563 6684 MTConfig - ok 18:32:59.0590 6684 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 18:32:59.0591 6684 Mup - ok 18:32:59.0700 6684 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 18:32:59.0720 6684 napagent - ok 18:32:59.0787 6684 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 18:32:59.0792 6684 NativeWifiP - ok 18:32:59.0853 6684 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys 18:32:59.0880 6684 NDIS - ok 18:32:59.0911 6684 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 18:32:59.0923 6684 NdisCap - ok 18:32:59.0956 6684 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 18:32:59.0958 6684 NdisTapi - ok 18:33:00.0002 6684 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 18:33:00.0003 6684 Ndisuio - ok 18:33:00.0035 6684 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 18:33:00.0038 6684 NdisWan - ok 18:33:00.0066 6684 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 18:33:00.0069 6684 NDProxy - ok 18:33:00.0089 6684 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 18:33:00.0091 6684 NetBIOS - ok 18:33:00.0125 6684 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 18:33:00.0128 6684 NetBT - ok 18:33:00.0134 6684 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 18:33:00.0135 6684 Netlogon - ok 18:33:00.0184 6684 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 18:33:00.0191 6684 Netman - ok 18:33:00.0215 6684 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 18:33:00.0222 6684 netprofm - ok 18:33:00.0250 6684 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 18:33:00.0252 6684 NetTcpPortSharing - ok 18:33:00.0278 6684 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 18:33:00.0279 6684 nfrd960 - ok 18:33:00.0329 6684 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll 18:33:00.0333 6684 NlaSvc - ok 18:33:00.0364 6684 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 18:33:00.0366 6684 Npfs - ok 18:33:00.0405 6684 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 18:33:00.0407 6684 nsi - ok 18:33:00.0440 6684 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 18:33:00.0441 6684 nsiproxy - ok 18:33:00.0504 6684 [ A2F74975097F52A00745F9637451FDD8 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 18:33:00.0522 6684 Ntfs - ok 18:33:00.0544 6684 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 18:33:00.0545 6684 Null - ok 18:33:00.0607 6684 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 18:33:00.0609 6684 nvraid - ok 18:33:00.0622 6684 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 18:33:00.0625 6684 nvstor - ok 18:33:00.0683 6684 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 18:33:00.0711 6684 nv_agp - ok 18:33:00.0738 6684 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 18:33:00.0786 6684 ohci1394 - ok 18:33:00.0848 6684 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 18:33:00.0861 6684 ose - ok 18:33:00.0976 6684 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 18:33:01.0028 6684 osppsvc - ok 18:33:01.0058 6684 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 18:33:01.0062 6684 p2pimsvc - ok 18:33:01.0100 6684 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 18:33:01.0106 6684 p2psvc - ok 18:33:01.0155 6684 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys 18:33:01.0172 6684 Parport - ok 18:33:01.0208 6684 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 18:33:01.0209 6684 partmgr - ok 18:33:01.0223 6684 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 18:33:01.0226 6684 PcaSvc - ok 18:33:01.0266 6684 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 18:33:01.0269 6684 pci - ok 18:33:01.0282 6684 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 18:33:01.0283 6684 pciide - ok 18:33:01.0348 6684 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 18:33:01.0363 6684 pcmcia - ok 18:33:01.0460 6684 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 18:33:01.0481 6684 pcw - ok 18:33:01.0640 6684 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 18:33:01.0648 6684 PEAUTH - ok 18:33:01.0740 6684 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 18:33:01.0742 6684 PerfHost - ok 18:33:01.0815 6684 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 18:33:01.0831 6684 pla - ok 18:33:01.0891 6684 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 18:33:01.0897 6684 PlugPlay - ok 18:33:01.0912 6684 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 18:33:01.0915 6684 PNRPAutoReg - ok 18:33:01.0941 6684 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 18:33:01.0944 6684 PNRPsvc - ok 18:33:01.0988 6684 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 18:33:01.0994 6684 PolicyAgent - ok 18:33:02.0026 6684 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 18:33:02.0029 6684 Power - ok 18:33:02.0060 6684 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 18:33:02.0062 6684 PptpMiniport - ok 18:33:02.0086 6684 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys 18:33:02.0088 6684 Processor - ok 18:33:02.0135 6684 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 18:33:02.0139 6684 ProfSvc - ok 18:33:02.0175 6684 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 18:33:02.0176 6684 ProtectedStorage - ok 18:33:02.0240 6684 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 18:33:02.0242 6684 Psched - ok 18:33:02.0313 6684 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 18:33:02.0330 6684 ql2300 - ok 18:33:02.0352 6684 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 18:33:02.0354 6684 ql40xx - ok 18:33:02.0388 6684 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 18:33:02.0393 6684 QWAVE - ok 18:33:02.0414 6684 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 18:33:02.0415 6684 QWAVEdrv - ok 18:33:02.0431 6684 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 18:33:02.0453 6684 RasAcd - ok 18:33:02.0488 6684 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 18:33:02.0489 6684 RasAgileVpn - ok 18:33:02.0506 6684 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 18:33:02.0527 6684 RasAuto - ok 18:33:02.0559 6684 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 18:33:02.0561 6684 Rasl2tp - ok 18:33:02.0596 6684 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 18:33:02.0601 6684 RasMan - ok 18:33:02.0630 6684 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 18:33:02.0632 6684 RasPppoe - ok 18:33:02.0654 6684 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 18:33:02.0656 6684 RasSstp - ok 18:33:02.0713 6684 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 18:33:02.0717 6684 rdbss - ok 18:33:02.0749 6684 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 18:33:02.0751 6684 rdpbus - ok 18:33:02.0767 6684 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 18:33:02.0768 6684 RDPCDD - ok 18:33:02.0851 6684 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 18:33:02.0873 6684 RDPENCDD - ok 18:33:02.0907 6684 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 18:33:02.0908 6684 RDPREFMP - ok 18:33:02.0993 6684 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 18:33:02.0996 6684 RDPWD - ok 18:33:03.0052 6684 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 18:33:03.0055 6684 rdyboost - ok 18:33:03.0104 6684 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 18:33:03.0106 6684 RemoteAccess - ok 18:33:03.0132 6684 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 18:33:03.0135 6684 RemoteRegistry - ok 18:33:03.0146 6684 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 18:33:03.0168 6684 RpcEptMapper - ok 18:33:03.0194 6684 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 18:33:03.0196 6684 RpcLocator - ok 18:33:03.0257 6684 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll 18:33:03.0261 6684 RpcSs - ok 18:33:03.0279 6684 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 18:33:03.0281 6684 rspndr - ok 18:33:03.0332 6684 [ F65F171165FBB613F7AA3CC78E8CAB42 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys 18:33:03.0335 6684 RTL8167 - ok 18:33:03.0356 6684 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 18:33:03.0357 6684 SamSs - ok 18:33:03.0390 6684 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 18:33:03.0392 6684 sbp2port - ok 18:33:03.0412 6684 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 18:33:03.0416 6684 SCardSvr - ok 18:33:03.0455 6684 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 18:33:03.0456 6684 scfilter - ok 18:33:03.0506 6684 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 18:33:03.0521 6684 Schedule - ok 18:33:03.0555 6684 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 18:33:03.0556 6684 SCPolicySvc - ok 18:33:03.0599 6684 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 18:33:03.0602 6684 SDRSVC - ok 18:33:03.0644 6684 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 18:33:03.0645 6684 secdrv - ok 18:33:03.0672 6684 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 18:33:03.0674 6684 seclogon - ok 18:33:03.0703 6684 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll 18:33:03.0717 6684 SENS - ok 18:33:03.0782 6684 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 18:33:03.0790 6684 SensrSvc - ok 18:33:03.0844 6684 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 18:33:03.0868 6684 Serenum - ok 18:33:03.0909 6684 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys 18:33:03.0911 6684 Serial - ok 18:33:03.0949 6684 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 18:33:03.0950 6684 sermouse - ok 18:33:04.0016 6684 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 18:33:04.0033 6684 SessionEnv - ok 18:33:04.0071 6684 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 18:33:04.0084 6684 sffdisk - ok 18:33:04.0123 6684 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 18:33:04.0138 6684 sffp_mmc - ok 18:33:04.0158 6684 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 18:33:04.0159 6684 sffp_sd - ok 18:33:04.0172 6684 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 18:33:04.0173 6684 sfloppy - ok 18:33:04.0243 6684 [ C6CC9297BD53E5229653303E556AA539 ] Sftfs C:\Windows\system32\DRIVERS\Sftfslh.sys 18:33:04.0266 6684 Sftfs - ok 18:33:04.0343 6684 [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe 18:33:04.0349 6684 sftlist - ok 18:33:04.0364 6684 [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay C:\Windows\system32\DRIVERS\Sftplaylh.sys 18:33:04.0368 6684 Sftplay - ok 18:33:04.0386 6684 [ 617E29A0B0A2807466560D4C4E338D3E ] Sftredir C:\Windows\system32\DRIVERS\Sftredirlh.sys 18:33:04.0388 6684 Sftredir - ok 18:33:04.0405 6684 [ 8F571F016FA1976F445147E9E6C8AE9B ] Sftvol C:\Windows\system32\DRIVERS\Sftvollh.sys 18:33:04.0407 6684 Sftvol - ok 18:33:04.0426 6684 [ C3CDDD18F43D44AB713CF8C4916F7696 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe 18:33:04.0429 6684 sftvsa - ok 18:33:04.0476 6684 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 18:33:04.0482 6684 ShellHWDetection - ok 18:33:04.0506 6684 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 18:33:04.0508 6684 SiSRaid2 - ok 18:33:04.0529 6684 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 18:33:04.0531 6684 SiSRaid4 - ok 18:33:04.0580 6684 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 18:33:04.0581 6684 Smb - ok 18:33:04.0642 6684 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 18:33:04.0644 6684 SNMPTRAP - ok 18:33:04.0660 6684 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 18:33:04.0661 6684 spldr - ok 18:33:04.0752 6684 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 18:33:04.0760 6684 Spooler - ok 18:33:04.0847 6684 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 18:33:04.0886 6684 sppsvc - ok 18:33:04.0908 6684 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 18:33:04.0911 6684 sppuinotify - ok 18:33:04.0953 6684 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 18:33:04.0980 6684 srv - ok 18:33:05.0016 6684 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 18:33:05.0020 6684 srv2 - ok 18:33:05.0031 6684 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 18:33:05.0033 6684 srvnet - ok 18:33:05.0062 6684 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 18:33:05.0066 6684 SSDPSRV - ok 18:33:05.0089 6684 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 18:33:05.0092 6684 SstpSvc - ok 18:33:05.0114 6684 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 18:33:05.0116 6684 stexstor - ok 18:33:05.0168 6684 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 18:33:05.0175 6684 stisvc - ok 18:33:05.0209 6684 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys 18:33:05.0210 6684 swenum - ok 18:33:05.0250 6684 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 18:33:05.0257 6684 swprv - ok 18:33:05.0433 6684 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 18:33:05.0452 6684 SysMain - ok 18:33:05.0485 6684 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 18:33:05.0487 6684 TabletInputService - ok 18:33:05.0503 6684 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 18:33:05.0509 6684 TapiSrv - ok 18:33:05.0536 6684 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 18:33:05.0538 6684 TBS - ok 18:33:05.0600 6684 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] Tcpip C:\Windows\system32\drivers\tcpip.sys 18:33:05.0622 6684 Tcpip - ok 18:33:05.0662 6684 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 18:33:05.0674 6684 TCPIP6 - ok 18:33:05.0705 6684 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 18:33:05.0707 6684 tcpipreg - ok 18:33:05.0748 6684 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 18:33:05.0749 6684 TDPIPE - ok 18:33:05.0776 6684 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 18:33:05.0777 6684 TDTCP - ok 18:33:05.0822 6684 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 18:33:05.0840 6684 tdx - ok 18:33:05.0860 6684 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys 18:33:05.0861 6684 TermDD - ok 18:33:05.0912 6684 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 18:33:05.0920 6684 TermService - ok 18:33:05.0938 6684 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 18:33:05.0940 6684 Themes - ok 18:33:05.0958 6684 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 18:33:05.0959 6684 THREADORDER - ok 18:33:06.0002 6684 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 18:33:06.0005 6684 TrkWks - ok 18:33:06.0066 6684 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 18:33:06.0070 6684 TrustedInstaller - ok 18:33:06.0126 6684 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 18:33:06.0127 6684 tssecsrv - ok 18:33:06.0178 6684 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 18:33:06.0180 6684 TsUsbFlt - ok 18:33:06.0221 6684 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 18:33:06.0223 6684 tunnel - ok 18:33:06.0252 6684 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 18:33:06.0254 6684 uagp35 - ok 18:33:06.0324 6684 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 18:33:06.0329 6684 udfs - ok 18:33:06.0359 6684 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 18:33:06.0362 6684 UI0Detect - ok 18:33:06.0376 6684 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 18:33:06.0378 6684 uliagpkx - ok 18:33:06.0422 6684 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys 18:33:06.0424 6684 umbus - ok 18:33:06.0458 6684 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 18:33:06.0459 6684 UmPass - ok 18:33:06.0478 6684 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 18:33:06.0484 6684 upnphost - ok 18:33:06.0529 6684 [ FB251567F41BC61988B26731DEC19E4B ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys 18:33:06.0531 6684 USBAAPL64 - ok 18:33:06.0571 6684 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys 18:33:06.0573 6684 usbaudio - ok 18:33:06.0592 6684 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 18:33:06.0594 6684 usbccgp - ok 18:33:06.0626 6684 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 18:33:06.0628 6684 usbcir - ok 18:33:06.0642 6684 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 18:33:06.0643 6684 usbehci - ok 18:33:06.0662 6684 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 18:33:06.0667 6684 usbhub - ok 18:33:06.0686 6684 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys 18:33:06.0687 6684 usbohci - ok 18:33:06.0730 6684 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 18:33:06.0731 6684 usbprint - ok 18:33:06.0754 6684 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 18:33:06.0756 6684 USBSTOR - ok 18:33:06.0771 6684 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 18:33:06.0772 6684 usbuhci - ok 18:33:06.0797 6684 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 18:33:06.0799 6684 UxSms - ok 18:33:06.0811 6684 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 18:33:06.0812 6684 VaultSvc - ok 18:33:06.0835 6684 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 18:33:06.0836 6684 vdrvroot - ok 18:33:06.0879 6684 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 18:33:06.0886 6684 vds - ok 18:33:06.0921 6684 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 18:33:06.0922 6684 vga - ok 18:33:06.0935 6684 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 18:33:06.0937 6684 VgaSave - ok 18:33:06.0966 6684 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 18:33:06.0969 6684 vhdmp - ok 18:33:06.0990 6684 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 18:33:06.0992 6684 viaide - ok 18:33:07.0004 6684 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 18:33:07.0005 6684 volmgr - ok 18:33:07.0049 6684 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 18:33:07.0055 6684 volmgrx - ok 18:33:07.0079 6684 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 18:33:07.0082 6684 volsnap - ok 18:33:07.0112 6684 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 18:33:07.0115 6684 vsmraid - ok 18:33:07.0186 6684 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 18:33:07.0213 6684 VSS - ok 18:33:07.0236 6684 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys 18:33:07.0250 6684 vwifibus - ok 18:33:07.0308 6684 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 18:33:07.0323 6684 W32Time - ok 18:33:07.0370 6684 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 18:33:07.0386 6684 WacomPen - ok 18:33:07.0469 6684 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 18:33:07.0483 6684 WANARP - ok 18:33:07.0487 6684 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 18:33:07.0488 6684 Wanarpv6 - ok 18:33:07.0590 6684 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 18:33:07.0604 6684 WatAdminSvc - ok 18:33:07.0661 6684 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 18:33:07.0678 6684 wbengine - ok 18:33:07.0714 6684 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 18:33:07.0718 6684 WbioSrvc - ok 18:33:07.0754 6684 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 18:33:07.0759 6684 wcncsvc - ok 18:33:07.0772 6684 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 18:33:07.0774 6684 WcsPlugInService - ok 18:33:07.0797 6684 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys 18:33:07.0799 6684 Wd - ok 18:33:07.0825 6684 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 18:33:07.0834 6684 Wdf01000 - ok 18:33:07.0867 6684 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 18:33:07.0869 6684 WdiServiceHost - ok 18:33:07.0873 6684 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 18:33:07.0875 6684 WdiSystemHost - ok 18:33:07.0959 6684 [ EFB3074BDBABE0A137D89D8E58F02392 ] Web Assistant Updater C:\Program Files\Web Assistant\ExtensionUpdaterService.exe 18:33:07.0961 6684 Web Assistant Updater - ok 18:33:08.0001 6684 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 18:33:08.0005 6684 WebClient - ok 18:33:08.0028 6684 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 18:33:08.0032 6684 Wecsvc - ok 18:33:08.0043 6684 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 18:33:08.0046 6684 wercplsupport - ok 18:33:08.0083 6684 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 18:33:08.0086 6684 WerSvc - ok 18:33:08.0129 6684 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 18:33:08.0130 6684 WfpLwf - ok 18:33:08.0155 6684 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 18:33:08.0156 6684 WIMMount - ok 18:33:08.0163 6684 WinHttpAutoProxySvc - ok 18:33:08.0437 6684 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 18:33:08.0441 6684 Winmgmt - ok 18:33:08.0544 6684 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 18:33:08.0567 6684 WinRM - ok 18:33:08.0631 6684 [ FE88B288356E7B47B74B13372ADD906D ] winusb C:\Windows\system32\drivers\WinUSB.SYS 18:33:08.0632 6684 winusb - ok 18:33:08.0670 6684 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 18:33:08.0681 6684 Wlansvc - ok 18:33:08.0768 6684 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 18:33:08.0770 6684 wlcrasvc - ok 18:33:08.0867 6684 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 18:33:08.0892 6684 wlidsvc - ok 18:33:08.0925 6684 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 18:33:08.0926 6684 WmiAcpi - ok 18:33:08.0953 6684 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 18:33:08.0956 6684 wmiApSrv - ok 18:33:09.0004 6684 WMPNetworkSvc - ok 18:33:09.0022 6684 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 18:33:09.0024 6684 WPCSvc - ok 18:33:09.0059 6684 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 18:33:09.0062 6684 WPDBusEnum - ok 18:33:09.0091 6684 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 18:33:09.0092 6684 ws2ifsl - ok 18:33:09.0098 6684 WSearch - ok 18:33:09.0175 6684 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 18:33:09.0206 6684 wuauserv - ok 18:33:09.0231 6684 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 18:33:09.0250 6684 WudfPf - ok 18:33:09.0319 6684 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 18:33:09.0322 6684 WUDFRd - ok 18:33:09.0354 6684 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 18:33:09.0356 6684 wudfsvc - ok 18:33:09.0377 6684 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll 18:33:09.0382 6684 WwanSvc - ok 18:33:09.0599 6684 [ DD0042F0C3B606A6A8B92D49AFB18AD6 ] YahooAUService C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe 18:33:09.0614 6684 YahooAUService - ok 18:33:09.0644 6684 ================ Scan global =============================== 18:33:09.0708 6684 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 18:33:09.0774 6684 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll 18:33:09.0783 6684 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll 18:33:09.0817 6684 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 18:33:09.0861 6684 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 18:33:09.0865 6684 [Global] - ok 18:33:09.0866 6684 ================ Scan MBR ================================== 18:33:09.0870 6684 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 18:33:09.0871 6684 Suspicious mbr (Forged): \Device\Harddisk0\DR0 18:33:09.0921 6684 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected 18:33:09.0921 6684 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0) 18:33:09.0955 6684 \Device\Harddisk0\DR0 ( TDSS File System ) - warning 18:33:09.0956 6684 \Device\Harddisk0\DR0 - detected TDSS File System (1) 18:33:09.0956 6684 ================ Scan VBR ================================== 18:33:09.0960 6684 [ 7F4BAE3F82ABDA90104CA8F38942C5AB ] \Device\Harddisk0\DR0\Partition1 18:33:09.0962 6684 \Device\Harddisk0\DR0\Partition1 - ok 18:33:09.0991 6684 [ 59C8A64CF54C8950F50949910FFA4DDD ] \Device\Harddisk0\DR0\Partition2 18:33:09.0992 6684 \Device\Harddisk0\DR0\Partition2 - ok 18:33:09.0993 6684 ============================================================ 18:33:09.0993 6684 Scan finished 18:33:09.0993 6684 ============================================================ 18:33:10.0010 4268 Detected object count: 2 18:33:10.0010 4268 Actual detected object count: 2 18:47:01.0702 4268 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - skipped by user 18:47:01.0703 4268 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - User select action: Skip 18:47:01.0706 4268 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user 18:47:01.0706 4268 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
Hello michael6606

Thank you for the log.

Please re-run TDSSKiller as you did before and allow the detections to be cured.

Once you have done that, please run the following tool:

  • Combofix


  • Download ComboFix from one of the following locations:

    Link 1
    Link 2

  • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
  • Right click on ComboFix.exe and select "Run as Administrator" to run the program. Follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
  • Should there be issues with internet afterward:

    In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

    In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.

Please post the TDSSKiller log and the Combofix log in your next reply.
Here is my TDSSKiller log: 19:46:14.0193 11120 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48 19:46:14.0646 11120 ============================================================ 19:46:14.0646 11120 Current date / time: 2012/09/16 19:46:14.0646 19:46:14.0646 11120 SystemInfo: 19:46:14.0646 11120 19:46:14.0646 11120 OS Version: 6.1.7601 ServicePack: 1.0 19:46:14.0646 11120 Product type: Workstation 19:46:14.0647 11120 ComputerName: MICHAEL-PC 19:46:14.0647 11120 UserName: Michael 19:46:14.0647 11120 Windows directory: C:\Windows 19:46:14.0647 11120 System windows directory: C:\Windows 19:46:14.0647 11120 Running under WOW64 19:46:14.0647 11120 Processor architecture: Intel x64 19:46:14.0647 11120 Number of processors: 4 19:46:14.0647 11120 Page size: 0x1000 19:46:14.0647 11120 Boot type: Normal boot 19:46:14.0647 11120 ============================================================ 19:46:16.0484 11120 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0x1BCE82, SectorsPerTrack: 0x8, TracksPerCylinder: 0x43, Type 'K0', Flags 0x00000040 19:46:16.0510 11120 ============================================================ 19:46:16.0510 11120 \Device\Harddisk0\DR0: 19:46:16.0511 11120 MBR partitions: 19:46:16.0511 11120 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xE4000 19:46:16.0511 11120 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xE4800, BlocksNum 0x3A2A1030 19:46:16.0511 11120 ============================================================ 19:46:16.0582 11120 C: <-> \Device\Harddisk0\DR0\Partition2 19:46:16.0582 11120 ============================================================ 19:46:16.0582 11120 Initialize success 19:46:16.0582 11120 ============================================================ 19:46:27.0706 6532 ============================================================ 19:46:27.0706 6532 Scan started 19:46:27.0706 6532 Mode: Manual; 19:46:27.0706 6532 ============================================================ 19:46:30.0588 6532 ================ Scan system memory ======================== 19:46:30.0588 6532 System memory - ok 19:46:30.0589 6532 ================ Scan services ============================= 19:46:30.0723 6532 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 19:46:30.0733 6532 1394ohci - ok 19:46:30.0867 6532 [ ADC420616C501B45D26C0FD3EF1E54E4 ] ACDaemon C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe 19:46:30.0868 6532 ACDaemon - ok 19:46:30.0928 6532 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 19:46:30.0932 6532 ACPI - ok 19:46:30.0956 6532 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 19:46:30.0978 6532 AcpiPmi - ok 19:46:31.0089 6532 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 19:46:31.0090 6532 AdobeARMservice - ok 19:46:31.0205 6532 [ A9D3B95E8466BD58EEB8A1154654E162 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 19:46:31.0208 6532 AdobeFlashPlayerUpdateSvc - ok 19:46:31.0247 6532 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 19:46:31.0260 6532 adp94xx - ok 19:46:31.0299 6532 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 19:46:31.0329 6532 adpahci - ok 19:46:31.0360 6532 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 19:46:31.0367 6532 adpu320 - ok 19:46:31.0476 6532 [ 96A0FF09E226B023DC6ACA253AACEE2E ] ADVService C:\Program Files (x86)\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe 19:46:31.0476 6532 ADVService - ok 19:46:31.0504 6532 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 19:46:31.0505 6532 AeLookupSvc - ok 19:46:31.0577 6532 [ 6CCD1135320109D6B219F1A6E04AD9F6 ] Afc C:\Windows\syswow64\drivers\Afc.sys 19:46:31.0581 6532 Afc - ok 19:46:31.0642 6532 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 19:46:31.0647 6532 AFD - ok 19:46:31.0692 6532 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 19:46:31.0698 6532 agp440 - ok 19:46:31.0722 6532 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 19:46:31.0724 6532 ALG - ok 19:46:31.0746 6532 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 19:46:31.0750 6532 aliide - ok 19:46:31.0761 6532 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 19:46:31.0765 6532 amdide - ok 19:46:31.0793 6532 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 19:46:31.0800 6532 AmdK8 - ok 19:46:31.0824 6532 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 19:46:31.0831 6532 AmdPPM - ok 19:46:31.0859 6532 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 19:46:31.0885 6532 amdsata - ok 19:46:31.0916 6532 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 19:46:31.0924 6532 amdsbs - ok 19:46:31.0942 6532 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 19:46:31.0943 6532 amdxata - ok 19:46:31.0991 6532 [ E25EBA0CB01A78487E7A825DA9F70641 ] androidusb C:\Windows\system32\Drivers\androidusb.sys 19:46:31.0995 6532 androidusb - ok 19:46:32.0087 6532 [ F9DAC844B1D370DA4C984D4C22F5E696 ] AntiSpywareService C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe 19:46:32.0093 6532 AntiSpywareService - ok 19:46:32.0165 6532 [ 0A1CC583E8147004E4AD4625D7FBF88C ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 19:46:32.0166 6532 AntiVirSchedulerService - ok 19:46:32.0226 6532 [ C9A36EF935ACED86AEDF93E97E606911 ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 19:46:32.0227 6532 AntiVirService - ok 19:46:32.0282 6532 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 19:46:32.0287 6532 AppID - ok 19:46:32.0304 6532 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 19:46:32.0306 6532 AppIDSvc - ok 19:46:32.0349 6532 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll 19:46:32.0350 6532 Appinfo - ok 19:46:32.0455 6532 [ 7EF47644B74EBE721CC32211D3C35E76 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 19:46:32.0457 6532 Apple Mobile Device - ok 19:46:32.0491 6532 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys 19:46:32.0526 6532 arc - ok 19:46:32.0591 6532 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 19:46:32.0630 6532 arcsas - ok 19:46:32.0723 6532 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 19:46:32.0727 6532 AsyncMac - ok 19:46:32.0762 6532 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 19:46:32.0763 6532 atapi - ok 19:46:32.0798 6532 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 19:46:32.0807 6532 AudioEndpointBuilder - ok 19:46:32.0818 6532 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 19:46:32.0825 6532 AudioSrv - ok 19:46:32.0872 6532 [ 26E38B5A58C6C55FAFBC563EEDDB0867 ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys 19:46:32.0874 6532 avgntflt - ok 19:46:32.0905 6532 [ 9D1F00BEFF84CBBF46D7F052BC7E0565 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys 19:46:32.0914 6532 avipbb - ok 19:46:32.0934 6532 [ 248DB59FC86DE44D2779F4C7FB1A567D ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys 19:46:32.0941 6532 avkmgr - ok 19:46:33.0004 6532 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 19:46:33.0006 6532 AxInstSV - ok 19:46:33.0051 6532 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys 19:46:33.0063 6532 b06bdrv - ok 19:46:33.0098 6532 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 19:46:33.0127 6532 b57nd60a - ok 19:46:33.0236 6532 [ F48FEB7DA35821DA15E0B006DCB9A169 ] BBSvc C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe 19:46:33.0239 6532 BBSvc - ok 19:46:33.0275 6532 [ 8E16F7A85441986FD2B9CE6C879524E4 ] BBUpdate C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe 19:46:33.0277 6532 BBUpdate - ok 19:46:33.0301 6532 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 19:46:33.0304 6532 BDESVC - ok 19:46:33.0316 6532 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 19:46:33.0321 6532 Beep - ok 19:46:33.0367 6532 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll 19:46:33.0384 6532 BITS - ok 19:46:33.0416 6532 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 19:46:33.0422 6532 blbdrive - ok 19:46:33.0527 6532 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 19:46:33.0533 6532 Bonjour Service - ok 19:46:33.0580 6532 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 19:46:33.0582 6532 bowser - ok 19:46:33.0599 6532 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 19:46:33.0604 6532 BrFiltLo - ok 19:46:33.0630 6532 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 19:46:33.0633 6532 BrFiltUp - ok 19:46:33.0674 6532 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 19:46:33.0676 6532 Browser - ok 19:46:33.0699 6532 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 19:46:33.0711 6532 Brserid - ok 19:46:33.0734 6532 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 19:46:33.0739 6532 BrSerWdm - ok 19:46:33.0769 6532 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 19:46:33.0773 6532 BrUsbMdm - ok 19:46:33.0780 6532 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 19:46:33.0786 6532 BrUsbSer - ok 19:46:33.0812 6532 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 19:46:33.0818 6532 BTHMODEM - ok 19:46:33.0852 6532 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 19:46:33.0854 6532 bthserv - ok 19:46:33.0881 6532 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 19:46:33.0887 6532 cdfs - ok 19:46:33.0940 6532 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\drivers\cdrom.sys 19:46:33.0970 6532 cdrom - ok 19:46:34.0026 6532 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 19:46:34.0028 6532 CertPropSvc - ok 19:46:34.0063 6532 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys 19:46:34.0069 6532 circlass - ok 19:46:34.0098 6532 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 19:46:34.0103 6532 CLFS - ok 19:46:34.0162 6532 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 19:46:34.0186 6532 clr_optimization_v2.0.50727_32 - ok 19:46:34.0224 6532 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 19:46:34.0242 6532 clr_optimization_v2.0.50727_64 - ok 19:46:34.0317 6532 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 19:46:34.0320 6532 clr_optimization_v4.0.30319_32 - ok 19:46:34.0366 6532 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 19:46:34.0369 6532 clr_optimization_v4.0.30319_64 - ok 19:46:34.0405 6532 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 19:46:34.0409 6532 CmBatt - ok 19:46:34.0443 6532 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 19:46:34.0448 6532 cmdide - ok 19:46:34.0492 6532 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 19:46:34.0498 6532 CNG - ok 19:46:34.0525 6532 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 19:46:34.0531 6532 Compbatt - ok 19:46:34.0567 6532 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 19:46:34.0583 6532 CompositeBus - ok 19:46:34.0599 6532 COMSysApp - ok 19:46:34.0624 6532 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 19:46:34.0629 6532 crcdisk - ok 19:46:34.0668 6532 [ 4F5414602E2544A4554D95517948B705 ] CryptSvc C:\Windows\system32\cryptsvc.dll 19:46:34.0670 6532 CryptSvc - ok 19:46:34.0732 6532 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE 19:46:34.0740 6532 cvhsvc - ok 19:46:34.0788 6532 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 19:46:34.0795 6532 DcomLaunch - ok 19:46:34.0837 6532 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 19:46:34.0841 6532 defragsvc - ok 19:46:34.0890 6532 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 19:46:34.0892 6532 DfsC - ok 19:46:34.0919 6532 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 19:46:34.0923 6532 Dhcp - ok 19:46:34.0953 6532 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 19:46:34.0954 6532 discache - ok 19:46:34.0983 6532 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys 19:46:34.0984 6532 Disk - ok 19:46:35.0034 6532 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 19:46:35.0037 6532 Dnscache - ok 19:46:35.0071 6532 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 19:46:35.0075 6532 dot3svc - ok 19:46:35.0105 6532 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 19:46:35.0107 6532 DPS - ok 19:46:35.0136 6532 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 19:46:35.0139 6532 drmkaud - ok 19:46:35.0189 6532 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 19:46:35.0208 6532 DXGKrnl - ok 19:46:35.0230 6532 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 19:46:35.0232 6532 EapHost - ok 19:46:35.0300 6532 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys 19:46:35.0342 6532 ebdrv - ok 19:46:35.0384 6532 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 19:46:35.0386 6532 EFS - ok 19:46:35.0446 6532 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 19:46:35.0451 6532 ehRecvr - ok 19:46:35.0478 6532 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 19:46:35.0479 6532 ehSched - ok 19:46:35.0511 6532 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 19:46:35.0524 6532 elxstor - ok 19:46:35.0557 6532 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 19:46:35.0561 6532 ErrDev - ok 19:46:35.0589 6532 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 19:46:35.0594 6532 EventSystem - ok 19:46:35.0612 6532 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 19:46:35.0621 6532 exfat - ok 19:46:35.0634 6532 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 19:46:35.0640 6532 fastfat - ok 19:46:35.0697 6532 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 19:46:35.0712 6532 Fax - ok 19:46:35.0726 6532 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys 19:46:35.0731 6532 fdc - ok 19:46:35.0757 6532 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 19:46:35.0758 6532 fdPHost - ok 19:46:35.0768 6532 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 19:46:35.0771 6532 FDResPub - ok 19:46:35.0805 6532 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 19:46:35.0848 6532 FileInfo - ok 19:46:35.0870 6532 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 19:46:35.0924 6532 Filetrace - ok 19:46:36.0025 6532 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 19:46:36.0039 6532 flpydisk - ok 19:46:36.0061 6532 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 19:46:36.0066 6532 FltMgr - ok 19:46:36.0157 6532 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll 19:46:36.0170 6532 FontCache - ok 19:46:36.0225 6532 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 19:46:36.0261 6532 FontCache3.0.0.0 - ok 19:46:36.0281 6532 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 19:46:36.0286 6532 FsDepends - ok 19:46:36.0331 6532 [ 07DA62C960DDCCC2D35836AEAB4FC578 ] fssfltr C:\Windows\system32\DRIVERS\fssfltr.sys 19:46:36.0353 6532 fssfltr - ok 19:46:36.0461 6532 [ 28DDEEEC44E988657B732CF404D504CB ] fsssvc C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe 19:46:36.0477 6532 fsssvc - ok 19:46:36.0517 6532 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 19:46:36.0522 6532 Fs_Rec - ok 19:46:36.0571 6532 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 19:46:36.0573 6532 fvevol - ok 19:46:36.0596 6532 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 19:46:36.0602 6532 gagp30kx - ok 19:46:36.0657 6532 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 19:46:36.0662 6532 GEARAspiWDM - ok 19:46:36.0715 6532 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 19:46:36.0724 6532 gpsvc - ok 19:46:36.0829 6532 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 19:46:36.0859 6532 gupdate - ok 19:46:36.0899 6532 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 19:46:36.0901 6532 gupdatem - ok 19:46:36.0924 6532 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 19:46:36.0943 6532 hcw85cir - ok 19:46:37.0004 6532 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 19:46:37.0027 6532 HdAudAddService - ok 19:46:37.0063 6532 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 19:46:37.0070 6532 HDAudBus - ok 19:46:37.0103 6532 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 19:46:37.0107 6532 HidBatt - ok 19:46:37.0136 6532 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 19:46:37.0153 6532 HidBth - ok 19:46:37.0174 6532 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 19:46:37.0198 6532 HidIr - ok 19:46:37.0227 6532 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll 19:46:37.0228 6532 hidserv - ok 19:46:37.0241 6532 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\drivers\hidusb.sys 19:46:37.0246 6532 HidUsb - ok 19:46:37.0281 6532 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 19:46:37.0283 6532 hkmsvc - ok 19:46:37.0321 6532 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 19:46:37.0325 6532 HomeGroupListener - ok 19:46:37.0363 6532 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 19:46:37.0367 6532 HomeGroupProvider - ok 19:46:37.0385 6532 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 19:46:37.0393 6532 HpSAMD - ok 19:46:37.0446 6532 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 19:46:37.0454 6532 HTTP - ok 19:46:37.0474 6532 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 19:46:37.0475 6532 hwpolicy - ok 19:46:37.0503 6532 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 19:46:37.0511 6532 i8042prt - ok 19:46:37.0544 6532 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 19:46:37.0554 6532 iaStorV - ok 19:46:37.0601 6532 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 19:46:37.0693 6532 idsvc - ok 19:46:37.0824 6532 [ 24CC43ECDEEFD4C19FBBEE4951B647F1 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys 19:46:37.0892 6532 igfx - ok 19:46:37.0940 6532 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 19:46:37.0944 6532 iirsp - ok 19:46:38.0041 6532 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 19:46:38.0063 6532 IKEEXT - ok 19:46:38.0185 6532 [ BC64B75E8E0A0B8982AB773483164E72 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys 19:46:38.0218 6532 IntcAzAudAddService - ok 19:46:38.0264 6532 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 19:46:38.0266 6532 intelide - ok 19:46:38.0304 6532 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 19:46:38.0310 6532 intelppm - ok 19:46:38.0333 6532 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 19:46:38.0335 6532 IPBusEnum - ok 19:46:38.0374 6532 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 19:46:38.0381 6532 IpFilterDriver - ok 19:46:38.0399 6532 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 19:46:38.0407 6532 IPMIDRV - ok 19:46:38.0430 6532 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 19:46:38.0437 6532 IPNAT - ok 19:46:38.0522 6532 [ 50D6CCC6FF5561F9F56946B3E6164FB8 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 19:46:38.0533 6532 iPod Service - ok 19:46:38.0556 6532 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 19:46:38.0582 6532 IRENUM - ok 19:46:38.0609 6532 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 19:46:38.0614 6532 isapnp - ok 19:46:38.0637 6532 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 19:46:38.0649 6532 iScsiPrt - ok 19:46:38.0724 6532 [ 54F694C6CD3A1149BA3A8BDACC83BADC ] ITMRTSVC C:\Program Files (x86)\CA\PPRT\bin\ITMRTSVC.exe 19:46:38.0726 6532 ITMRTSVC - ok 19:46:38.0750 6532 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys 19:46:38.0757 6532 kbdclass - ok 19:46:38.0803 6532 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys 19:46:38.0820 6532 kbdhid - ok 19:46:38.0920 6532 [ 326349D7DF3A7137AEA077CEB1EA8519 ] kcusbser C:\Windows\system32\DRIVERS\kcusbser.sys 19:46:38.0949 6532 kcusbser - ok 19:46:38.0983 6532 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 19:46:38.0985 6532 KeyIso - ok 19:46:39.0034 6532 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 19:46:39.0036 6532 KSecDD - ok 19:46:39.0082 6532 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 19:46:39.0084 6532 KSecPkg - ok 19:46:39.0093 6532 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 19:46:39.0097 6532 ksthunk - ok 19:46:39.0138 6532 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 19:46:39.0152 6532 KtmRm - ok 19:46:39.0189 6532 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll 19:46:39.0194 6532 LanmanServer - ok 19:46:39.0228 6532 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 19:46:39.0231 6532 LanmanWorkstation - ok 19:46:39.0271 6532 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 19:46:39.0277 6532 lltdio - ok 19:46:39.0312 6532 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 19:46:39.0322 6532 lltdsvc - ok 19:46:39.0339 6532 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 19:46:39.0340 6532 lmhosts - ok 19:46:39.0369 6532 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 19:46:39.0376 6532 LSI_FC - ok 19:46:39.0407 6532 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 19:46:39.0427 6532 LSI_SAS - ok 19:46:39.0458 6532 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 19:46:39.0464 6532 LSI_SAS2 - ok 19:46:39.0490 6532 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 19:46:39.0497 6532 LSI_SCSI - ok 19:46:39.0536 6532 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 19:46:39.0538 6532 luafv - ok 19:46:39.0559 6532 lxda_device - ok 19:46:39.0682 6532 [ B891E3920F24FF1A3BEAD6CD2B42ED99 ] McAfee SiteAdvisor Service c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe 19:46:39.0684 6532 McAfee SiteAdvisor Service - ok 19:46:39.0763 6532 [ 22A7776C5D8EB5930EDF9C8DD0884259 ] McComponentHostService C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe 19:46:39.0767 6532 McComponentHostService - ok 19:46:39.0801 6532 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 19:46:39.0807 6532 Mcx2Svc - ok 19:46:39.0836 6532 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 19:46:39.0840 6532 megasas - ok 19:46:39.0853 6532 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 19:46:39.0861 6532 MegaSR - ok 19:46:39.0885 6532 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 19:46:39.0887 6532 MMCSS - ok 19:46:39.0893 6532 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 19:46:39.0897 6532 Modem - ok 19:46:39.0925 6532 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 19:46:39.0929 6532 monitor - ok 19:46:39.0950 6532 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\drivers\mouclass.sys 19:46:39.0957 6532 mouclass - ok 19:46:39.0983 6532 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 19:46:39.0987 6532 mouhid - ok 19:46:40.0020 6532 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 19:46:40.0021 6532 mountmgr - ok 19:46:40.0113 6532 [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 19:46:40.0115 6532 MozillaMaintenance - ok 19:46:40.0135 6532 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 19:46:40.0144 6532 mpio - ok 19:46:40.0160 6532 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 19:46:40.0167 6532 mpsdrv - ok 19:46:40.0201 6532 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 19:46:40.0209 6532 MRxDAV - ok 19:46:40.0247 6532 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 19:46:40.0249 6532 mrxsmb - ok 19:46:40.0295 6532 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 19:46:40.0298 6532 mrxsmb10 - ok 19:46:40.0309 6532 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 19:46:40.0312 6532 mrxsmb20 - ok 19:46:40.0322 6532 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 19:46:40.0327 6532 msahci - ok 19:46:40.0373 6532 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 19:46:40.0382 6532 msdsm - ok 19:46:40.0400 6532 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 19:46:40.0410 6532 MSDTC - ok 19:46:40.0435 6532 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 19:46:40.0437 6532 Msfs - ok 19:46:40.0454 6532 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 19:46:40.0457 6532 mshidkmdf - ok 19:46:40.0490 6532 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 19:46:40.0491 6532 msisadrv - ok 19:46:40.0522 6532 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 19:46:40.0530 6532 MSiSCSI - ok 19:46:40.0536 6532 msiserver - ok 19:46:40.0565 6532 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 19:46:40.0569 6532 MSKSSRV - ok 19:46:40.0576 6532 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 19:46:40.0579 6532 MSPCLOCK - ok 19:46:40.0586 6532 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 19:46:40.0590 6532 MSPQM - ok 19:46:40.0634 6532 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 19:46:40.0639 6532 MsRPC - ok 19:46:40.0651 6532 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 19:46:40.0677 6532 mssmbios - ok 19:46:40.0682 6532 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 19:46:40.0687 6532 MSTEE - ok 19:46:40.0719 6532 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 19:46:40.0723 6532 MTConfig - ok 19:46:40.0748 6532 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 19:46:40.0750 6532 Mup - ok 19:46:40.0794 6532 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 19:46:40.0801 6532 napagent - ok 19:46:40.0821 6532 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 19:46:40.0832 6532 NativeWifiP - ok 19:46:40.0889 6532 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys 19:46:40.0899 6532 NDIS - ok 19:46:40.0936 6532 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 19:46:40.0940 6532 NdisCap - ok 19:46:40.0963 6532 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 19:46:40.0968 6532 NdisTapi - ok 19:46:41.0009 6532 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 19:46:41.0026 6532 Ndisuio - ok 19:46:41.0217 6532 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 19:46:41.0280 6532 NdisWan - ok 19:46:41.0332 6532 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 19:46:41.0362 6532 NDProxy - ok 19:46:41.0379 6532 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 19:46:41.0381 6532 NetBIOS - ok 19:46:41.0400 6532 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 19:46:41.0402 6532 NetBT - ok 19:46:41.0408 6532 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 19:46:41.0410 6532 Netlogon - ok 19:46:41.0441 6532 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 19:46:41.0446 6532 Netman - ok 19:46:41.0462 6532 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 19:46:41.0469 6532 netprofm - ok 19:46:41.0496 6532 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 19:46:41.0522 6532 NetTcpPortSharing - ok 19:46:41.0544 6532 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 19:46:41.0550 6532 nfrd960 - ok 19:46:41.0597 6532 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll 19:46:41.0601 6532 NlaSvc - ok 19:46:41.0621 6532 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 19:46:41.0623 6532 Npfs - ok 19:46:41.0651 6532 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 19:46:41.0653 6532 nsi - ok 19:46:41.0658 6532 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 19:46:41.0659 6532 nsiproxy - ok 19:46:41.0718 6532 [ A2F74975097F52A00745F9637451FDD8 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 19:46:41.0735 6532 Ntfs - ok 19:46:41.0745 6532 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 19:46:41.0750 6532 Null - ok 19:46:41.0799 6532 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 19:46:41.0806 6532 nvraid - ok 19:46:41.0825 6532 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 19:46:41.0850 6532 nvstor - ok 19:46:41.0873 6532 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 19:46:41.0880 6532 nv_agp - ok 19:46:41.0895 6532 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 19:46:41.0903 6532 ohci1394 - ok 19:46:41.0962 6532 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 19:46:41.0986 6532 ose - ok 19:46:42.0136 6532 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 19:46:42.0206 6532 osppsvc - ok 19:46:42.0237 6532 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 19:46:42.0242 6532 p2pimsvc - ok 19:46:42.0257 6532 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 19:46:42.0264 6532 p2psvc - ok 19:46:42.0295 6532 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys 19:46:42.0301 6532 Parport - ok 19:46:42.0332 6532 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 19:46:42.0334 6532 partmgr - ok 19:46:42.0347 6532 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 19:46:42.0351 6532 PcaSvc - ok 19:46:42.0391 6532 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 19:46:42.0394 6532 pci - ok 19:46:42.0403 6532 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 19:46:42.0407 6532 pciide - ok 19:46:42.0440 6532 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 19:46:42.0450 6532 pcmcia - ok 19:46:42.0474 6532 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 19:46:42.0475 6532 pcw - ok 19:46:42.0504 6532 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 19:46:42.0522 6532 PEAUTH - ok 19:46:42.0578 6532 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 19:46:42.0579 6532 PerfHost - ok 19:46:42.0641 6532 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 19:46:42.0658 6532 pla - ok 19:46:42.0706 6532 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 19:46:42.0713 6532 PlugPlay - ok 19:46:42.0728 6532 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 19:46:42.0730 6532 PNRPAutoReg - ok 19:46:42.0745 6532 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 19:46:42.0748 6532 PNRPsvc - ok 19:46:42.0781 6532 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 19:46:42.0795 6532 PolicyAgent - ok 19:46:42.0819 6532 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 19:46:42.0822 6532 Power - ok 19:46:42.0845 6532 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 19:46:42.0853 6532 PptpMiniport - ok 19:46:42.0878 6532 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys 19:46:42.0884 6532 Processor - ok 19:46:42.0929 6532 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 19:46:42.0932 6532 ProfSvc - ok 19:46:42.0946 6532 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 19:46:42.0947 6532 ProtectedStorage - ok 19:46:42.0989 6532 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 19:46:42.0991 6532 Psched - ok 19:46:43.0042 6532 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 19:46:43.0066 6532 ql2300 - ok 19:46:43.0084 6532 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 19:46:43.0092 6532 ql40xx - ok 19:46:43.0126 6532 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 19:46:43.0130 6532 QWAVE - ok 19:46:43.0179 6532 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 19:46:43.0184 6532 QWAVEdrv - ok 19:46:43.0190 6532 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 19:46:43.0197 6532 RasAcd - ok 19:46:43.0241 6532 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 19:46:43.0246 6532 RasAgileVpn - ok 19:46:43.0266 6532 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 19:46:43.0268 6532 RasAuto - ok 19:46:43.0307 6532 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 19:46:43.0314 6532 Rasl2tp - ok 19:46:43.0345 6532 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 19:46:43.0350 6532 RasMan - ok 19:46:43.0376 6532 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 19:46:43.0414 6532 RasPppoe - ok 19:46:43.0433 6532 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 19:46:43.0439 6532 RasSstp - ok 19:46:43.0483 6532 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 19:46:43.0487 6532 rdbss - ok 19:46:43.0513 6532 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 19:46:43.0518 6532 rdpbus - ok 19:46:43.0533 6532 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 19:46:43.0534 6532 RDPCDD - ok 19:46:43.0559 6532 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 19:46:43.0560 6532 RDPENCDD - ok 19:46:43.0567 6532 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 19:46:43.0568 6532 RDPREFMP - ok 19:46:43.0613 6532 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 19:46:43.0620 6532 RDPWD - ok 19:46:43.0668 6532 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 19:46:43.0672 6532 rdyboost - ok 19:46:43.0699 6532 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 19:46:43.0701 6532 RemoteAccess - ok 19:46:43.0727 6532 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 19:46:43.0730 6532 RemoteRegistry - ok 19:46:43.0741 6532 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 19:46:43.0743 6532 RpcEptMapper - ok 19:46:43.0756 6532 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 19:46:43.0758 6532 RpcLocator - ok 19:46:43.0796 6532 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll 19:46:43.0801 6532 RpcSs - ok 19:46:43.0810 6532 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 19:46:43.0843 6532 rspndr - ok 19:46:43.0890 6532 [ F65F171165FBB613F7AA3CC78E8CAB42 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys 19:46:43.0897 6532 RTL8167 - ok 19:46:43.0918 6532 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 19:46:43.0920 6532 SamSs - ok 19:46:43.0971 6532 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 19:46:43.0978 6532 sbp2port - ok 19:46:44.0008 6532 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 19:46:44.0012 6532 SCardSvr - ok 19:46:44.0045 6532 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 19:46:44.0051 6532 scfilter - ok 19:46:44.0102 6532 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 19:46:44.0116 6532 Schedule - ok 19:46:44.0150 6532 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 19:46:44.0151 6532 SCPolicySvc - ok 19:46:44.0194 6532 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 19:46:44.0198 6532 SDRSVC - ok 19:46:44.0218 6532 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 19:46:44.0223 6532 secdrv - ok 19:46:44.0267 6532 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 19:46:44.0270 6532 seclogon - ok 19:46:44.0288 6532 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll 19:46:44.0291 6532 SENS - ok 19:46:44.0312 6532 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 19:46:44.0314 6532 SensrSvc - ok 19:46:44.0333 6532 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 19:46:44.0350 6532 Serenum - ok 19:46:44.0386 6532 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys 19:46:44.0392 6532 Serial - ok 19:46:44.0434 6532 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 19:46:44.0438 6532 sermouse - ok 19:46:44.0479 6532 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 19:46:44.0482 6532 SessionEnv - ok 19:46:44.0517 6532 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 19:46:44.0521 6532 sffdisk - ok 19:46:44.0534 6532 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 19:46:44.0539 6532 sffp_mmc - ok 19:46:44.0546 6532 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 19:46:44.0550 6532 sffp_sd - ok 19:46:44.0569 6532 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 19:46:44.0574 6532 sfloppy - ok 19:46:44.0615 6532 [ C6CC9297BD53E5229653303E556AA539 ] Sftfs C:\Windows\system32\DRIVERS\Sftfslh.sys 19:46:44.0631 6532 Sftfs - ok 19:46:44.0708 6532 [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe 19:46:44.0714 6532 sftlist - ok 19:46:44.0729 6532 [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay C:\Windows\system32\DRIVERS\Sftplaylh.sys 19:46:44.0738 6532 Sftplay - ok 19:46:44.0750 6532 [ 617E29A0B0A2807466560D4C4E338D3E ] Sftredir C:\Windows\system32\DRIVERS\Sftredirlh.sys 19:46:44.0751 6532 Sftredir - ok 19:46:44.0767 6532 [ 8F571F016FA1976F445147E9E6C8AE9B ] Sftvol C:\Windows\system32\DRIVERS\Sftvollh.sys 19:46:44.0772 6532 Sftvol - ok 19:46:44.0790 6532 [ C3CDDD18F43D44AB713CF8C4916F7696 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe 19:46:44.0792 6532 sftvsa - ok 19:46:44.0840 6532 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 19:46:44.0846 6532 ShellHWDetection - ok 19:46:44.0879 6532 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 19:46:44.0885 6532 SiSRaid2 - ok 19:46:44.0898 6532 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 19:46:44.0904 6532 SiSRaid4 - ok 19:46:44.0943 6532 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 19:46:44.0949 6532 Smb - ok 19:46:45.0006 6532 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 19:46:45.0008 6532 SNMPTRAP - ok 19:46:45.0046 6532 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 19:46:45.0047 6532 spldr - ok 19:46:45.0083 6532 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 19:46:45.0092 6532 Spooler - ok 19:46:45.0202 6532 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 19:46:45.0243 6532 sppsvc - ok 19:46:45.0261 6532 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 19:46:45.0277 6532 sppuinotify - ok 19:46:45.0317 6532 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 19:46:45.0323 6532 srv - ok 19:46:45.0346 6532 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 19:46:45.0352 6532 srv2 - ok 19:46:45.0372 6532 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 19:46:45.0375 6532 srvnet - ok 19:46:45.0403 6532 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 19:46:45.0407 6532 SSDPSRV - ok 19:46:45.0419 6532 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 19:46:45.0423 6532 SstpSvc - ok 19:46:45.0441 6532 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 19:46:45.0446 6532 stexstor - ok 19:46:45.0500 6532 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 19:46:45.0509 6532 stisvc - ok 19:46:45.0552 6532 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys 19:46:45.0556 6532 swenum - ok 19:46:45.0581 6532 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 19:46:45.0589 6532 swprv - ok 19:46:45.0654 6532 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 19:46:45.0675 6532 SysMain - ok 19:46:45.0705 6532 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 19:46:45.0708 6532 TabletInputService - ok 19:46:45.0723 6532 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 19:46:45.0729 6532 TapiSrv - ok 19:46:45.0756 6532 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 19:46:45.0758 6532 TBS - ok 19:46:45.0831 6532 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] Tcpip C:\Windows\system32\drivers\tcpip.sys 19:46:45.0854 6532 Tcpip - ok 19:46:45.0891 6532 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 19:46:45.0904 6532 TCPIP6 - ok 19:46:45.0949 6532 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 19:46:45.0954 6532 tcpipreg - ok 19:46:45.0979 6532 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 19:46:45.0993 6532 TDPIPE - ok 19:46:46.0018 6532 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 19:46:46.0022 6532 TDTCP - ok 19:46:46.0068 6532 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 19:46:46.0086 6532 tdx - ok 19:46:46.0122 6532 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys 19:46:46.0128 6532 TermDD - ok 19:46:46.0165 6532 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 19:46:46.0175 6532 TermService - ok 19:46:46.0191 6532 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 19:46:46.0194 6532 Themes - ok 19:46:46.0211 6532 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 19:46:46.0213 6532 THREADORDER - ok 19:46:46.0244 6532 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 19:46:46.0248 6532 TrkWks - ok 19:46:46.0319 6532 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 19:46:46.0320 6532 TrustedInstaller - ok 19:46:46.0379 6532 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 19:46:46.0403 6532 tssecsrv - ok 19:46:46.0453 6532 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 19:46:46.0460 6532 TsUsbFlt - ok 19:46:46.0512 6532 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 19:46:46.0521 6532 tunnel - ok 19:46:46.0550 6532 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 19:46:46.0556 6532 uagp35 - ok 19:46:46.0599 6532 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 19:46:46.0609 6532 udfs - ok 19:46:46.0634 6532 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 19:46:46.0638 6532 UI0Detect - ok 19:46:46.0651 6532 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 19:46:46.0657 6532 uliagpkx - ok 19:46:46.0731 6532 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys 19:46:46.0738 6532 umbus - ok 19:46:46.0767 6532 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 19:46:46.0770 6532 UmPass - ok 19:46:46.0787 6532 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 19:46:46.0793 6532 upnphost - ok 19:46:46.0860 6532 [ FB251567F41BC61988B26731DEC19E4B ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys 19:46:46.0865 6532 USBAAPL64 - ok 19:46:46.0934 6532 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys 19:46:46.0941 6532 usbaudio - ok 19:46:46.0958 6532 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 19:46:46.0983 6532 usbccgp - ok 19:46:47.0023 6532 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 19:46:47.0032 6532 usbcir - ok 19:46:47.0048 6532 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 19:46:47.0054 6532 usbehci - ok 19:46:47.0091 6532 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 19:46:47.0095 6532 usbhub - ok 19:46:47.0109 6532 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys 19:46:47.0114 6532 usbohci - ok 19:46:47.0151 6532 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 19:46:47.0156 6532 usbprint - ok 19:46:47.0173 6532 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 19:46:47.0180 6532 USBSTOR - ok 19:46:47.0196 6532 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 19:46:47.0197 6532 usbuhci - ok 19:46:47.0226 6532 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 19:46:47.0229 6532 UxSms - ok 19:46:47.0241 6532 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 19:46:47.0243 6532 VaultSvc - ok 19:46:47.0265 6532 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 19:46:47.0267 6532 vdrvroot - ok 19:46:47.0298 6532 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 19:46:47.0306 6532 vds - ok 19:46:47.0362 6532 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 19:46:47.0367 6532 vga - ok 19:46:47.0381 6532 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 19:46:47.0387 6532 VgaSave - ok 19:46:47.0407 6532 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 19:46:47.0417 6532 vhdmp - ok 19:46:47.0431 6532 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 19:46:47.0436 6532 viaide - ok 19:46:47.0456 6532 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 19:46:47.0458 6532 volmgr - ok 19:46:47.0501 6532 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 19:46:47.0506 6532 volmgrx - ok 19:46:47.0520 6532 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 19:46:47.0524 6532 volsnap - ok 19:46:47.0553 6532 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 19:46:47.0561 6532 vsmraid - ok 19:46:47.0627 6532 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 19:46:47.0647 6532 VSS - ok 19:46:47.0666 6532 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys 19:46:47.0671 6532 vwifibus - ok 19:46:47.0705 6532 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 19:46:47.0712 6532 W32Time - ok 19:46:47.0745 6532 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 19:46:47.0749 6532 WacomPen - ok 19:46:47.0772 6532 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 19:46:47.0778 6532 WANARP - ok 19:46:47.0784 6532 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 19:46:47.0786 6532 Wanarpv6 - ok 19:46:47.0887 6532 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 19:46:47.0923 6532 WatAdminSvc - ok 19:46:47.0981 6532 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 19:46:47.0999 6532 wbengine - ok 19:46:48.0022 6532 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 19:46:48.0027 6532 WbioSrvc - ok 19:46:48.0062 6532 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 19:46:48.0069 6532 wcncsvc - ok 19:46:48.0103 6532 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 19:46:48.0105 6532 WcsPlugInService - ok 19:46:48.0128 6532 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys 19:46:48.0153 6532 Wd - ok 19:46:48.0189 6532 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 19:46:48.0197 6532 Wdf01000 - ok 19:46:48.0208 6532 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 19:46:48.0211 6532 WdiServiceHost - ok 19:46:48.0217 6532 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 19:46:48.0219 6532 WdiSystemHost - ok 19:46:48.0289 6532 [ EFB3074BDBABE0A137D89D8E58F02392 ] Web Assistant Updater C:\Program Files\Web Assistant\ExtensionUpdaterService.exe 19:46:48.0291 6532 Web Assistant Updater - ok 19:46:48.0331 6532 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 19:46:48.0348 6532 WebClient - ok 19:46:48.0370 6532 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 19:46:48.0374 6532 Wecsvc - ok 19:46:48.0396 6532 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 19:46:48.0399 6532 wercplsupport - ok 19:46:48.0436 6532 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 19:46:48.0439 6532 WerSvc - ok 19:46:48.0462 6532 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 19:46:48.0466 6532 WfpLwf - ok 19:46:48.0485 6532 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 19:46:48.0490 6532 WIMMount - ok 19:46:48.0497 6532 WinHttpAutoProxySvc - ok 19:46:48.0580 6532 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 19:46:48.0584 6532 Winmgmt - ok 19:46:48.0643 6532 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 19:46:48.0667 6532 WinRM - ok 19:46:48.0740 6532 [ FE88B288356E7B47B74B13372ADD906D ] winusb C:\Windows\system32\drivers\WinUSB.SYS 19:46:48.0747 6532 winusb - ok 19:46:48.0812 6532 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 19:46:48.0824 6532 Wlansvc - ok 19:46:48.0933 6532 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 19:46:48.0960 6532 wlcrasvc - ok 19:46:49.0066 6532 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 19:46:49.0093 6532 wlidsvc - ok 19:46:49.0134 6532 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 19:46:49.0137 6532 WmiAcpi - ok 19:46:49.0173 6532 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 19:46:49.0176 6532 wmiApSrv - ok 19:46:49.0202 6532 WMPNetworkSvc - ok 19:46:49.0220 6532 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 19:46:49.0223 6532 WPCSvc - ok 19:46:49.0257 6532 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 19:46:49.0260 6532 WPDBusEnum - ok 19:46:49.0289 6532 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 19:46:49.0294 6532 ws2ifsl - ok 19:46:49.0299 6532 WSearch - ok 19:46:49.0408 6532 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 19:46:49.0438 6532 wuauserv - ok 19:46:49.0460 6532 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 19:46:49.0466 6532 WudfPf - ok 19:46:49.0505 6532 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 19:46:49.0513 6532 WUDFRd - ok 19:46:49.0574 6532 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 19:46:49.0577 6532 wudfsvc - ok 19:46:49.0597 6532 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll 19:46:49.0601 6532 WwanSvc - ok 19:46:49.0720 6532 [ DD0042F0C3B606A6A8B92D49AFB18AD6 ] YahooAUService C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe 19:46:49.0728 6532 YahooAUService - ok 19:46:49.0736 6532 ================ Scan global =============================== 19:46:49.0762 6532 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 19:46:49.0773 6532 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll 19:46:49.0783 6532 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll 19:46:49.0816 6532 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 19:46:49.0860 6532 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 19:46:49.0865 6532 [Global] - ok 19:46:49.0866 6532 ================ Scan MBR ================================== 19:46:49.0879 6532 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 19:46:49.0880 6532 Suspicious mbr (Forged): \Device\Harddisk0\DR0 19:46:49.0942 6532 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected 19:46:49.0942 6532 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0) 19:46:49.0943 6532 ================ Scan VBR ================================== 19:46:49.0946 6532 [ 7F4BAE3F82ABDA90104CA8F38942C5AB ] \Device\Harddisk0\DR0\Partition1 19:46:49.0947 6532 \Device\Harddisk0\DR0\Partition1 - ok 19:46:49.0957 6532 [ 59C8A64CF54C8950F50949910FFA4DDD ] \Device\Harddisk0\DR0\Partition2 19:46:49.0959 6532 \Device\Harddisk0\DR0\Partition2 - ok 19:46:49.0959 6532 ============================================================ 19:46:49.0959 6532 Scan finished 19:46:49.0959 6532 ============================================================ 19:46:49.0976 11004 Detected object count: 1 19:46:49.0976 11004 Actual detected object count: 1 19:47:12.0168 11004 \Device\Harddisk0\DR0\# - copied to quarantine 19:47:12.0170 11004 \Device\Harddisk0\DR0 - copied to quarantine 19:47:12.0190 11004 \Device\Harddisk0\DR0\TDLFS\cmd.dll - copied to quarantine 19:47:12.0191 11004 \Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine 19:47:12.0194 11004 \Device\Harddisk0\DR0\TDLFS\sub.dll - copied to quarantine 19:47:12.0197 11004 \Device\Harddisk0\DR0\TDLFS\subx.dll - copied to quarantine 19:47:12.0203 11004 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine 19:47:12.0207 11004 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine 19:47:12.0209 11004 \Device\Harddisk0\DR0\TDLFS\servers.dat - copied to quarantine 19:47:12.0211 11004 \Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine 19:47:12.0212 11004 \Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine 19:47:12.0215 11004 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine 19:47:12.0217 11004 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine 19:47:12.0219 11004 \Device\Harddisk0\DR0\TDLFS\s - copied to quarantine 19:47:12.0221 11004 \Device\Harddisk0\DR0\TDLFS\ldrm - copied to quarantine 19:47:12.0223 11004 \Device\Harddisk0\DR0\TDLFS\u - copied to quarantine 19:47:12.0229 11004 \Device\Harddisk0\DR0\TDLFS\ph.dll - copied to quarantine 19:47:12.0231 11004 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - will be cured on reboot 19:47:12.0232 11004 \Device\Harddisk0\DR0 - ok 19:47:12.0266 11004 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - User select action: Cure 19:47:29.0041 6436 Deinitialize success Here is the Combofix log: ComboFix 12-09-15.02 - Michael 09/16/2012 20:09:32.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2038.927 [GMT -5:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\Web Assistant\ExTEnsion32.dll c:\programdata\l_u0_0.pad c:\users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk c:\windows\svchost.exe . . ((((((((((((((((((((((((( Files Created from 2012-08-17 to 2012-09-17 ))))))))))))))))))))))))))))))) . . 2012-09-17 01:20 . 2012-09-17 01:20 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-09-17 00:47 . 2012-09-17 00:47 ——– d—–w- C:\TDSSKiller_Quarantine 2012-09-16 16:52 . 2012-09-16 16:52 ——– d—–w- c:\users\Michael\AppData\Local\Adobe 2012-09-15 15:04 . 2012-08-22 18:12 950128 —-a-w- c:\windows\system32\drivers\ndis.sys 2012-09-15 15:04 . 2012-07-04 20:26 41472 —-a-w- c:\windows\system32\drivers\RNDISMP.sys 2012-09-15 15:04 . 2012-08-02 17:58 574464 —-a-w- c:\windows\system32\d3d10level9.dll 2012-09-15 15:04 . 2012-08-02 16:57 490496 —-a-w- c:\windows\SysWow64\d3d10level9.dll 2012-09-15 15:04 . 2012-08-22 18:12 1913200 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-09-15 15:04 . 2012-08-22 18:12 376688 —-a-w- c:\windows\system32\drivers\netio.sys 2012-09-15 15:04 . 2012-08-22 18:12 288624 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-09-14 18:27 . 2012-09-15 00:13 ——– d—–w- c:\programdata\Sendori 2012-09-14 18:27 . 2012-09-15 00:13 ——– d—–w- c:\program files (x86)\Sendori 2012-09-14 18:27 . 2012-09-15 00:13 ——– d—–w- c:\users\Michael\AppData\Roaming\OpenCandy . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-09-15 15:00 . 2011-02-14 19:02 64462936 —-a-w- c:\windows\system32\MRT.exe 2012-08-31 11:32 . 2011-02-14 23:23 4278384 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2012-08-31 11:32 . 2011-02-13 14:25 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2012-08-14 21:07 . 2012-06-22 16:23 70344 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-14 21:07 . 2012-06-22 16:23 426184 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-08-14 03:59 . 2009-07-13 23:19 328704 —-a-w- c:\windows\system32\services.exe 2012-08-10 09:43 . 2012-08-10 09:43 69000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C27C4EF4-5C83-48A6-A6CC-E9604DBB2BA0}\offreg.dll 2012-08-01 21:53 . 2012-08-01 21:53 8281168 —-a-w- c:\programdata\Microsoft\BingBar\BBSvc\7.1.391.0oemBingBarSetup-Partner.EXE 2012-07-18 18:15 . 2012-08-14 21:07 3148800 —-a-w- c:\windows\system32\win32k.sys 2012-07-04 22:16 . 2012-08-14 21:07 73216 —-a-w- c:\windows\system32\netapi32.dll 2012-07-04 22:13 . 2012-08-14 21:07 59392 —-a-w- c:\windows\system32\browcli.dll 2012-07-04 22:13 . 2012-08-14 21:07 136704 —-a-w- c:\windows\system32\browser.dll 2012-07-04 21:14 . 2012-08-14 21:07 41984 —-a-w- c:\windows\SysWow64\browcli.dll 2012-06-29 10:04 . 2012-08-10 09:42 9133488 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C27C4EF4-5C83-48A6-A6CC-E9604DBB2BA0}\mpengine.dll 2012-06-27 07:06 . 2012-08-14 21:07 1188864 —-a-w- c:\windows\system32\wininet.dll 2012-06-27 07:06 . 2012-08-14 21:07 1494016 —-a-w- c:\windows\system32\urlmon.dll 2012-06-27 07:06 . 2012-08-14 21:07 134144 —-a-w- c:\windows\system32\url.dll 2012-06-27 07:03 . 2012-08-14 21:07 9059840 —-a-w- c:\windows\system32\mshtml.dll 2012-06-27 07:03 . 2012-08-14 21:07 97792 —-a-w- c:\windows\system32\mshtmled.dll 2012-06-27 07:03 . 2012-08-14 21:07 735744 —-a-w- c:\windows\system32\msfeeds.dll 2012-06-27 07:02 . 2012-08-14 21:07 64512 —-a-w- c:\windows\system32\jsproxy.dll 2012-06-27 07:02 . 2012-08-14 21:07 247808 —-a-w- c:\windows\system32\ieui.dll 2012-06-27 07:02 . 2012-08-14 21:07 2453504 —-a-w- c:\windows\system32\iertutil.dll 2012-06-27 07:02 . 2012-08-14 21:07 12297216 —-a-w- c:\windows\system32\ieframe.dll 2012-06-27 05:53 . 2012-08-14 21:07 981504 —-a-w- c:\windows\SysWow64\wininet.dll 2012-06-27 04:53 . 2012-08-14 21:07 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2012-06-27 04:10 . 2012-08-14 21:07 1638912 —-a-w- c:\windows\SysWow64\mshtml.tlb 2012-06-21 23:26 . 2012-06-21 23:26 955840 —-a-w- c:\windows\system32\npDeployJava1.dll 2012-06-21 23:26 . 2012-06-21 23:26 839096 —-a-w- c:\windows\system32\deployJava1.dll 2012-06-21 23:26 . 2012-06-21 23:26 268720 —-a-w- c:\windows\system32\javaws.exe 2012-06-21 23:26 . 2012-06-21 23:26 189360 —-a-w- c:\windows\system32\javaw.exe 2012-06-21 23:26 . 2012-06-21 23:26 188840 —-a-w- c:\windows\system32\java.exe 2012-06-21 22:19 . 2012-06-21 22:20 19736 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files (x86)\DVDVideoSoftTB\prxtbDVDV.dll" [2011-05-09 176936] "{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn3\yt.dll" [2012-06-11 1524056] . [HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}] . [HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}] [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1] [HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}] [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin] . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}] 2011-05-09 08:49 176936 —-a-w- c:\program files (x86)\DVDVideoSoftTB\prxtbDVDV.dll . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2012-04-09 22:43 1519272 —-a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2012-04-09 1519272] "{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files (x86)\DVDVideoSoftTB\prxtbDVDV.dll" [2011-05-09 176936] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 94208 —-a-w- c:\users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 94208 —-a-w- c:\users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 94208 —-a-w- c:\users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Desktop Software"="c:\program files (x86)\Common Files\SupportSoft\bin\bcont.exe" [2009-04-24 1025320] "ComcastAntispyClient"="c:\program files (x86)\comcasttb\ComcastSpywareScan\ComcastAntispy.exe" [2009-08-19 1589208] "Spotify"="c:\users\Michael\AppData\Roaming\Spotify\Spotify.exe" [2012-05-12 9478320] "Spotify Web Helper"="c:\users\Michael\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-05-12 932528] "Amazon Cloud Drive"="c:\users\Michael\AppData\Local\Amazon\Cloud Drive\AmazonCloudDrive.exe" [2012-08-13 874816] "Messenger (Yahoo!)"="c:\progra~2\Yahoo!\Messenger\YahooMessenger.exe" [2012-05-25 6595928] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424] "ArcSoft MediaImpression Monitor"="c:\program files (x86)\Kodak\MediaImpression\ArcMonitor.exe" [2010-12-15 80448] "ApnUpdater"="c:\program files (x86)\Ask.com\Updater\Updater.exe" [2012-04-09 1557160] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] . c:\users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-7-2 26868192] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Amazon Unbox.lnk - c:\program files (x86)\Amazon\Amazon Unbox Video\ADVWindowsClientSystemTray.exe [2011-11-23 97384] McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe [2011-6-17 272528] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux2"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-23 136176] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-14 250056] R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [2009-10-13 31744] R3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe [2012-06-11 240208] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-23 136176] R3 kcusbser;Kyocera USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\kcusbser.sys [2009-11-03 120832] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe [2011-06-17 237008] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-07 114144] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-02-13 1255736] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960] S2 AntiSpywareService;Comcast AntiSpyware;c:\program files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe [2009-06-17 616408] S2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe [2012-06-11 193616] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~2\mcafee\SITEAD~1\mcsacore.exe [2012-06-15 103472] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776] S2 Web Assistant Updater;Web Assistant Updater;c:\program files\Web Assistant\ExtensionUpdaterService.exe [2012-05-08 185856] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-07-30 236544] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-09-17 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-22 21:07] . 2012-09-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-23 19:26] . 2012-09-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-23 19:26] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}] 2012-05-08 20:13 201728 —-a-w- c:\program files\Web Assistant\Extension64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 97792 —-a-w- c:\users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 97792 —-a-w- c:\users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 97792 —-a-w- c:\users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 97792 —-a-w- c:\users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-20 7981088] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 165912] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 385560] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 363544] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://mystart.incredibar.com/mb139?a=6OyGk4b7id&i=26 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Free YouTube Download - c:\users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm IE: Free YouTube to MP3 Converter - c:\users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm Trusted Zone: internet Trusted Zone: mcafee.com TCP: DhcpNameServer = 192.168.10.1 FF - ProfilePath - c:\users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - about:home FF - prefs.js: keyword.URL - hxxp://mystart.incredibar.com/mb139/?loc=IB_DS&a=6OyGk4b7id&&i=26&search= FF - user.js: extensions.incredibar_i.newTab - false FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6OyGk4b7id&loc=IB_TB&i=26&search= FF - user.js: extensions.incredibar_i.id - 88e542270000000000004487fcdbb7d0 FF - user.js: extensions.incredibar_i.instlDay - 15519 FF - user.js: extensions.incredibar_i.vrsn - [removed] FF - user.js: extensions.incredibar_i.vrsni - [removed] FF - user.js: extensions.incredibar_i.vrsnTs - [removed]:24 FF - user.js: extensions.incredibar_i.prtnrId - Incredibar FF - user.js: extensions.incredibar_i.prdct - incredibar FF - user.js: extensions.incredibar_i.aflt - orgnl FF - user.js: extensions.incredibar_i.smplGrp - none FF - user.js: extensions.incredibar_i.tlbrId - base FF - user.js: extensions.incredibar_i.instlRef - FF - user.js: extensions.incredibar_i.dfltLng - FF - user.js: extensions.incredibar_i.excTlbr - false FF - user.js: extensions.incredibar_i.ms_url_id - FF - user.js: extensions.incredibar_i.upn2 - 6OyGk4b7id FF - user.js: extensions.incredibar_i.upn2n - 92261663447743341 FF - user.js: extensions.incredibar_i.productid - 26 FF - user.js: extensions.incredibar_i.installerproductid - 26 FF - user.js: extensions.incredibar_i.did - 10650 FF - user.js: extensions.incredibar_i.ppd - 34%5F6 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKCU-Run-Apple Computer - (no file) SafeBoot-73412918.sys Toolbar-Locked - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) WebBrowser-{872B5B88-9DB5-4310-BDD0-AC189557E5F5} - (no file) . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-3730337016-767289466-2862032461-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-3730337016-767289466-2862032461-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\CA\PPRT\bin\ITMRTSVC.exe c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe c:\program files (x86)\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe c:\windows\SysWOW64\rundll32.exe . ************************************************************************** . Completion time: 2012-09-16 20:28:21 - machine was rebooted ComboFix-quarantined-files.txt 2012-09-17 01:28 . Pre-Run: 331,523,440,640 bytes free Post-Run: 335,395,475,456 bytes free . - - End Of File - - A5055E66C4E95A753E527BB991A3FE20
Hello michael6606

Thank you for the logs.

We need to use Combofix again but this time we will be running it in a slightly different way:


  • Please work through the following steps


    • Hold down the Windows key (has the Windows symbol on it) and press the "R" key. A Run box will open. Type in Notepad and press Enter then click on "OK").
    • NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
    • Copy and Paste the text in the quotebox below into the open Notepad window:

      Driver::
      Web Assistant Updater

      File::
      c:\program files\Web Assistant\ExtensionUpdaterService.exe
      c:\program files\Web Assistant\Extension64.dll

      Folder::
      c:\program files\Web Assistant

      Registry::
      [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}]

      DDS::
      uStart Page = hxxp://mystart.incredibar.com/mb139?a=6OyGk4b7id&i=26
      Trusted Zone: internet
      Trusted Zone: mcafee.com

      Firefox::
      FF - ProfilePath - c:\users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\
      FF - prefs.js: keyword.URL - hxxp://mystart.incredibar.com/mb139/?loc=IB_DS&a=6OyGk4b7id&&i=26&search=
      FF - user.js: extensions.incredibar_i.newTab - false
      FF - user.js: extensions.incredibar_i.tlbrSrchUrl - hxxp://mystart.Incredibar.com/?a=6OyGk4b7id&loc=IB_TB&i=26&search=
      FF - user.js: extensions.incredibar_i.id - 88e542270000000000004487fcdbb7d0
      FF - user.js: extensions.incredibar_i.instlDay - 15519
      FF - user.js: extensions.incredibar_i.vrsn - [removed]
      FF - user.js: extensions.incredibar_i.vrsni - [removed]
      FF - user.js: extensions.incredibar_i.vrsnTs - [removed]:24
      FF - user.js: extensions.incredibar_i.prtnrId - Incredibar
      FF - user.js: extensions.incredibar_i.prdct - incredibar
      FF - user.js: extensions.incredibar_i.aflt - orgnl
      FF - user.js: extensions.incredibar_i.smplGrp - none
      FF - user.js: extensions.incredibar_i.tlbrId - base
      FF - user.js: extensions.incredibar_i.instlRef -
      FF - user.js: extensions.incredibar_i.dfltLng -
      FF - user.js: extensions.incredibar_i.excTlbr - false
      FF - user.js: extensions.incredibar_i.ms_url_id -
      FF - user.js: extensions.incredibar_i.upn2 - 6OyGk4b7id
      FF - user.js: extensions.incredibar_i.upn2n - 92261663447743341
      FF - user.js: extensions.incredibar_i.productid - 26
      FF - user.js: extensions.incredibar_i.installerproductid - 26
      FF - user.js: extensions.incredibar_i.did - 10650
      FF - user.js: extensions.incredibar_i.ppd - 34%5F6

      Reglock::
      [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
      [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]

    • Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
    • Close any open browsers.
    • Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Refering to the picture below, drag CFScript.txt into ComboFix.exe

      [external image: Posted Image]
    • When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
    • Once the log is produced, re-engage your resident anti virus.

  • Please perform the following scan:


    • Please download MalwareBytes AntiMalware by clicking here and save the file (called mbam-setup.exe) to your desktop.

    • Right click on the mbam-setup.exe icon and select "Run as Administrator" to install the program.
    • Follow the prompts during installation and have the Installation Wizzard create a desktop icon.
    • Once installed, double click on the MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform Quick Scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

    Please post the Combofix log and the MBAM in your next reply along with a new OTL scan log.
So when I ran ComboFix, the program froze on the screen that says ComboFix is preparing the Log Report. I waited about an hour and nothing happened. I left it running and went to bed. The next morning the screen was still there and still no Log Report. I rebooted the computer and ran MBAM and here is the log for that. Malwarebytes Anti-Malware (Trial) 1.65.0.1400 www.malwarebytes.org Database version: v2012.09.18.07 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Michael :: MICHAEL-PC [administrator] Protection: Enabled 9/18/2012 2:46:03 PM mbam-log-2012-09-18 (14-46-03).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 204086 Time elapsed: 4 minute(s), 4 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 C:\Users\Michael\Downloads\American Reunion Jason Biggs.mkv.exe (Affiliate.Downloader) -> Quarantined and deleted successfully. (end) Thanks.
Hello michael6606

Thank you for the MBAM log.

when I ran ComboFix, the program froze on the screen that says ComboFix is preparing the Log Report

Lets double check to see if a log was saved:

Please check your C:\ drive for the log. If present it will be called C:\ComboFix.txt

If the log has been saved please post it in your next reply. if not, please re-scan with OTL and post the new log for me to review.
I think this is the scan I ran last night. ComboFix 12-09-15.02 - Michael 09/17/2012 23:52:44.3.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2038.807 [GMT -5:00] Running from: C:\Users\[removed]\Downloads\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) —- Previous Run ——- c:\program files\Web Assistant\Extension64.dll c:\program files\Web Assistant\ExtensionUpdaterService.exe c:\program files\Web Assistant\Firefox\chrome.manifest c:\program files\Web Assistant\Firefox\chrome\content\libraries\DataExchangeScript.js c:\program files\Web Assistant\Firefox\chrome\content\main.js c:\program files\Web Assistant\Firefox\chrome\content\main.xul c:\program files\Web Assistant\Firefox\chrome\content\resources\localscript.js c:\program files\Web Assistant\Firefox\chrome\locale\en-US\overlay.dtd c:\program files\Web Assistant\Firefox\chrome\skin\overlay.css c:\program files\Web Assistant\Firefox\defaults\preferences\defaults.js c:\program files\Web Assistant\Firefox\install.rdf c:\program files\Web Assistant\InstallerHelper.dll c:\program files\Web Assistant\libraries\DataExchangeScript.js c:\program files\Web Assistant\resources\localscript.js c:\program files\Web Assistant\source.crx c:\program files\Web Assistant\unins000.dat c:\program files\Web Assistant\unins000.exe ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Service_Web Assistant Updater ((((((((((((((((((((((((( Files Created from 2012-08-18 to 2012-09-18 ))))))))))))))))))))))))))))))) 2012-09-18 04:59:52 . 2012-09-18 04:59:52 ——– d—–w- C:\Windows\system32\config\systemprofile\AppData\Local\temp 2012-09-18 04:59:52 . 2012-09-18 04:59:52 ——– d—–w- C:\Users\Default\AppData\Local\temp 2012-09-17 02:58:31 . 2012-09-17 02:58:31 ——– d—–w- C:\Users\Michael\AppData\Roaming\Avira 2012-09-17 02:52:54 . 2012-09-08 01:26:23 98848 —-a-w- C:\Windows\system32\drivers\avgntflt.sys 2012-09-17 02:52:54 . 2012-09-08 01:26:23 27760 —-a-w- C:\Windows\system32\drivers\avkmgr.sys 2012-09-17 02:52:54 . 2012-09-08 01:26:23 132832 —-a-w- C:\Windows\system32\drivers\avipbb.sys 2012-09-17 02:52:53 . 2012-09-17 02:52:53 ——– d—–w- C:\ProgramData\Avira 2012-09-17 02:52:53 . 2012-09-17 02:52:53 ——– d—–w- C:\Program Files (x86)\Avira 2012-09-17 00:47:11 . 2012-09-17 00:47:11 ——– d—–w- C:\TDSSKiller_Quarantine 2012-09-16 16:52:18 . 2012-09-16 16:52:18 ——– d—–w- C:\Users\Michael\AppData\Local\Adobe 2012-09-15 15:04:28 . 2012-08-22 18:12:40 950128 —-a-w- C:\Windows\system32\drivers\ndis.sys 2012-09-15 15:04:28 . 2012-07-04 20:26:03 41472 —-a-w- C:\Windows\system32\drivers\RNDISMP.sys 2012-09-15 15:04:24 . 2012-08-02 17:58:52 574464 —-a-w- C:\Windows\system32\d3d10level9.dll 2012-09-15 15:04:24 . 2012-08-02 16:57:20 490496 —-a-w- C:\Windows\SysWow64\d3d10level9.dll 2012-09-15 15:04:19 . 2012-08-22 18:12:50 1913200 —-a-w- C:\Windows\system32\drivers\tcpip.sys 2012-09-15 15:04:19 . 2012-08-22 18:12:40 376688 —-a-w- C:\Windows\system32\drivers\netio.sys 2012-09-15 15:04:19 . 2012-08-22 18:12:33 288624 —-a-w- C:\Windows\system32\drivers\FWPKCLNT.SYS 2012-09-14 18:27:28 . 2012-09-15 00:13:41 ——– d—–w- C:\ProgramData\Sendori 2012-09-14 18:27:26 . 2012-09-15 00:13:41 ——– d—–w- C:\Program Files (x86)\Sendori 2012-09-14 18:27:20 . 2012-09-15 00:13:40 ——– d—–w- C:\Users\Michael\AppData\Roaming\OpenCandy . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2012-09-15 15:00:23 . 2011-02-14 19:02:57 64462936 —-a-w- C:\Windows\system32\MRT.exe 2012-08-31 11:32:49 . 2011-02-14 23:23:28 4278384 —-a-w- C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2012-08-31 11:32:35 . 2011-02-13 14:25:32 42776 —-a-w- C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2012-08-14 21:07:34 . 2012-06-22 16:23:18 70344 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-14 21:07:34 . 2012-06-22 16:23:18 426184 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-08-14 03:59:18 . 2009-07-13 23:19:46 328704 —-a-w- C:\Windows\system32\services.exe 2012-08-10 09:43:15 . 2012-08-10 09:43:15 69000 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C27C4EF4-5C83-48A6-A6CC-E9604DBB2BA0}\offreg.dll 2012-08-01 21:53:55 . 2012-08-01 21:53:29 8281168 —-a-w- C:\ProgramData\Microsoft\BingBar\BBSvc\7.1.391.0oemBingBarSetup-Partner.EXE 2012-07-18 18:15:06 . 2012-08-14 21:07:25 3148800 —-a-w- C:\Windows\system32\win32k.sys 2012-07-04 22:16:43 . 2012-08-14 21:07:52 73216 —-a-w- C:\Windows\system32\netapi32.dll 2012-07-04 22:13:27 . 2012-08-14 21:07:52 59392 —-a-w- C:\Windows\system32\browcli.dll 2012-07-04 22:13:27 . 2012-08-14 21:07:52 136704 —-a-w- C:\Windows\system32\browser.dll 2012-07-04 21:14:34 . 2012-08-14 21:07:52 41984 —-a-w- C:\Windows\SysWow64\browcli.dll 2012-06-29 10:04:29 . 2012-08-10 09:42:23 9133488 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C27C4EF4-5C83-48A6-A6CC-E9604DBB2BA0}\mpengine.dll 2012-06-27 07:06:53 . 2012-08-14 21:07:37 1188864 —-a-w- C:\Windows\system32\wininet.dll 2012-06-27 07:06:36 . 2012-08-14 21:07:38 1494016 —-a-w- C:\Windows\system32\urlmon.dll 2012-06-27 07:06:35 . 2012-08-14 21:07:34 134144 —-a-w- C:\Windows\system32\url.dll 2012-06-27 07:03:32 . 2012-08-14 21:07:46 9059840 —-a-w- C:\Windows\system32\mshtml.dll 2012-06-27 07:03:32 . 2012-08-14 21:07:35 97792 —-a-w- C:\Windows\system32\mshtmled.dll 2012-06-27 07:03:29 . 2012-08-14 21:07:37 735744 —-a-w- C:\Windows\system32\msfeeds.dll 2012-06-27 07:02:52 . 2012-08-14 21:07:34 64512 —-a-w- C:\Windows\system32\jsproxy.dll 2012-06-27 07:02:41 . 2012-08-14 21:07:35 247808 —-a-w- C:\Windows\system32\ieui.dll 2012-06-27 07:02:41 . 2012-08-14 21:07:35 2453504 —-a-w- C:\Windows\system32\iertutil.dll 2012-06-27 07:02:40 . 2012-08-14 21:07:39 12297216 —-a-w- C:\Windows\system32\ieframe.dll 2012-06-27 05:53:07 . 2012-08-14 21:07:38 981504 —-a-w- C:\Windows\SysWow64\wininet.dll 2012-06-27 04:53:10 . 2012-08-14 21:07:34 1638912 —-a-w- C:\Windows\system32\mshtml.tlb 2012-06-27 04:10:55 . 2012-08-14 21:07:34 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2012-06-21 23:26:06 . 2012-06-21 23:26:33 955840 —-a-w- C:\Windows\system32\npDeployJava1.dll 2012-06-21 23:26:06 . 2012-06-21 23:26:33 839096 —-a-w- C:\Windows\system32\deployJava1.dll 2012-06-21 23:26:06 . 2012-06-21 23:26:33 268720 —-a-w- C:\Windows\system32\javaws.exe 2012-06-21 23:26:06 . 2012-06-21 23:26:16 189360 —-a-w- C:\Windows\system32\javaw.exe 2012-06-21 23:26:06 . 2012-06-21 23:26:16 188840 —-a-w- C:\Windows\system32\java.exe 2012-06-21 22:19:52 . 2012-06-21 22:20:01 19736 —-a-w- C:\ProgramData\Microsoft\IdentityCRL\production\ppcrlconfig600.dll ((((((((((((((((((((((((((((( SnapShot@2012-09-17_01.22.51 ))))))))))))))))))))))))))))))))))))))))) + 2012-09-18 05:00:20 . 2012-09-18 05:00:20 13342 C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat - 2012-09-17 01:21:18 . 2012-09-17 01:21:18 13342 C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat + 2010-07-22 16:52:10 . 2012-09-18 05:03:10 53150 C:\Windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-07-14 05:10:35 . 2012-09-18 05:03:10 33070 C:\Windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2011-02-12 22:11:22 . 2012-09-18 05:03:10 14266 C:\Windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3730337016-767289466-2862032461-1000_UserData.bin - 2011-02-12 23:01:53 . 2012-09-17 01:13:32 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-02-12 23:01:53 . 2012-09-18 04:05:23 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-02-12 23:01:53 . 2012-09-18 04:05:23 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2011-02-12 23:01:53 . 2012-09-17 01:13:32 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2012-09-17 01:22:07 . 2012-09-17 01:22:07 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-09-18 05:01:08 . 2012-09-18 05:01:08 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2012-09-18 05:01:08 . 2012-09-18 05:01:08 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2012-09-17 01:22:07 . 2012-09-17 01:22:07 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2012-08-23 23:59:54 . 2012-09-18 05:01:24 196608 C:\Windows\Temp\Cookies\index.dat - 2012-08-23 23:59:54 . 2012-09-17 01:22:26 196608 C:\Windows\Temp\Cookies\index.dat + 2011-03-10 03:05:15 . 2012-09-18 01:37:23 291570 C:\Windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_FastS4.bin - 2009-07-14 02:36:59 . 2012-09-17 00:57:14 624614 C:\Windows\system32\perfh009.dat + 2009-07-14 02:36:59 . 2012-09-17 04:45:13 624614 C:\Windows\system32\perfh009.dat + 2009-07-14 02:36:59 . 2012-09-17 04:45:13 106732 C:\Windows\system32\perfc009.dat - 2009-07-14 02:36:59 . 2012-09-17 00:57:14 106732 C:\Windows\system32\perfc009.dat - 2009-07-14 05:01:48 . 2012-09-17 01:21:12 229488 C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2009-07-14 05:01:48 . 2012-09-18 05:00:20 229488 C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2011-09-25 06:03:53 . 2012-09-17 01:48:05 458696 C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3730337016-767289466-2862032461-1000-12288.dat - 2012-08-23 23:59:52 . 2012-09-17 01:22:26 5259264 C:\Windows\Temp\Temporary Internet Files\Content.IE5\index.dat + 2012-08-23 23:59:52 . 2012-09-18 05:01:24 5259264 C:\Windows\Temp\Temporary Internet Files\Content.IE5\index.dat + 2012-08-23 23:59:54 . 2012-09-18 05:01:24 1392640 C:\Windows\Temp\History\History.IE5\index.dat - 2012-08-23 23:59:54 . 2012-09-17 01:22:26 1392640 C:\Windows\Temp\History\History.IE5\index.dat + 2011-04-03 04:30:16 . 2012-09-18 04:17:01 1514528 C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3730337016-767289466-2862032461-1000-8192.dat - 2011-04-03 04:30:16 . 2012-09-17 01:21:15 1514528 C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3730337016-767289466-2862032461-1000-8192.dat ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll" [2011-05-09 08:49:38 176936] "{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn3\yt.dll" [2012-06-11 19:08:00 1524056] [HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}] [HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}] [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1] [HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}] [HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin] [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}] 2011-05-09 08:49:38 176936 —-a-w- C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2012-04-09 22:43:36 1519272 —-a-w- C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll" [2012-04-09 22:43:36 1519272] "{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll" [2011-05-09 08:49:38 176936] [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] [HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}] [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19:10 94208 —-a-w- C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19:10 94208 —-a-w- C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19:10 94208 —-a-w- C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Desktop Software"="C:\Program Files (x86)\Common Files\SupportSoft\bin\bcont.exe" [2009-04-24 07:57:42 1025320] "ComcastAntispyClient"="C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntispy.exe" [2009-08-19 17:25:52 1589208] "Spotify"="C:\Users\Michael\AppData\Roaming\Spotify\Spotify.exe" [2012-05-12 16:20:36 9478320] "Spotify Web Helper"="C:\Users\Michael\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-05-12 16:20:36 932528] "Amazon Cloud Drive"="C:\Users\Michael\AppData\Local\Amazon\Cloud Drive\AmazonCloudDrive.exe" [2012-08-13 21:21:53 874816] "Messenger (Yahoo!)"="C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" [2012-05-25 09:25:02 6595928] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "ArcSoft Connection Service"="C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 00:17:52 207424] "ArcSoft MediaImpression Monitor"="C:\Program Files (x86)\Kodak\MediaImpression\ArcMonitor.exe" [2010-12-15 23:03:02 80448] "ApnUpdater"="C:\Program Files (x86)\Ask.com\Updater\Updater.exe" [2012-04-09 22:43:42 1557160] "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 02:28:32 59240] "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 20:02:04 254696] "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 10:09:24 421736] "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe" [2012-04-19 01:56:22 421888] "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 20:51:26 919008] "avgnt"="C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-09-08 01:26:13 348664] C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-7-2 26868192] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ Amazon Unbox.lnk - C:\Program Files (x86)\Amazon\Amazon Unbox Video\ADVWindowsClientSystemTray.exe [2011-11-23 97384] McAfee Security Scan Plus.lnk - C:\Program Files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe [2011-6-17 272528] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux2"=wdmaud.drv [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 20:27:14 138576] R2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-09-23 19:26:18 136176] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-14 21:07:35 250056] R3 androidusb;ADB Interface Driver;C:\Windows\system32\Drivers\androidusb.sys [2009-10-13 20:50:00 31744] R3 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe [2012-06-11 21:22:16 240208] R3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-09-23 19:26:18 136176] R3 kcusbser;Kyocera USB Device for Legacy Serial Communication;C:\Windows\system32\DRIVERS\kcusbser.sys [2009-11-03 21:53:00 120832] R3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe [2011-06-17 17:33:04 237008] R3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-07 05:19:29 114144] R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 03:34:24 4925184] R3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 11:07:05 59392] R3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys [2012-02-15 16:01:50 52736] R3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe [2011-02-13 20:09:05 1255736] R4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 00:10:10 57184] S1 avkmgr;avkmgr;C:\Windows\system32\DRIVERS\avkmgr.sys [2012-09-08 01:26:23 27760] S2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 20:51:26 63960] S2 AntiSpywareService;Comcast AntiSpyware;C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe [2009-06-17 17:49:44 616408] S2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2012-09-08 01:26:19 86224] S2 BBSvc;BingBar Service;C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe [2012-06-11 21:22:16 193616] S2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 20:22:40 822624] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [2012-06-15 17:26:32 103472] S2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 14:30:18 508776] S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-07-30 23:58:42 236544] S3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 14:30:10 764264] S3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 14:30:18 268648] S3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 14:30:18 25960] S3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 14:30:22 22376] S3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 14:30:22 219496] Contents of the 'Scheduled Tasks' folder 2012-09-18 C:\Windows\Tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-22 16:23:18 . 2012-08-14 21:07:35] 2012-09-18 C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-09-23 19:26:21 . 2011-09-23 19:26:18] 2012-09-18 C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-09-23 19:26:21 . 2011-09-23 19:26:18] ——— X64 Entries ———– [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19:10 97792 —-a-w- C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19:10 97792 —-a-w- C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19:10 97792 —-a-w- C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19:10 97792 —-a-w- C:\Users\Michael\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-20 23:23:26 7981088] "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2009-09-24 01:30:44 165912] "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2009-09-24 01:30:44 385560] "Persistence"="C:\Windows\system32\igfxpers.exe" [2009-09-24 01:30:44 363544]
Hello michael6606

I agree. That log is from a previous run, and is also incomplete.

Please re-scan the machine with OTL and post the new log created in your next reply.
Here is the latest OTL log. Thanks again for all you help.

OTL logfile created on: 9/19/2012 11:57:26 AM - Run 1
OTL by OldTimer - Version 3.2.64.0 Folder = C:\Users\Michael\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.99 Gb Total Physical Memory | 0.77 Gb Available Physical Memory | 38.93% Memory free
4.20 Gb Paging File | 1.57 Gb Available in Paging File | 37.48% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.31 Gb Total Space | 310.39 Gb Free Space | 66.70% Space Free | Partition Type: NTFS

Computer Name: MICHAEL-PC | User Name: Michael | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Michael\Downloads\OTL(1).exe (OldTimer Tools)
PRC - C:\Users\Michael\AppData\Local\Amazon\Cloud Drive\AmazonCloudDrive.exe ()
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Users\Michael\Desktop\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Users\Michael\Desktop\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Users\Michael\Desktop\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE (Microsoft Corporation.)
PRC - C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - C:\Users\Michael\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
PRC - C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Users\Michael\AppData\Local\Amazon\Cloud Drive\jre\bin\javaw.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Amazon\Amazon Unbox Video\ADVWindowsClientSystemTray.exe (Amazon.com)
PRC - C:\Program Files (x86)\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe (Amazon.com)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Kodak\MediaImpression\ArcMonitor.exe (ArcSoft, Inc.)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpy.exe ()
PRC - C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe ()
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files (x86)\CA\PPRT\bin\ITMRTSVC.exe (CA, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Users\Michael\AppData\Local\Temp\sqlite-3.7.2-sqlitejdbc.dll ()
MOD - C:\Users\Michael\AppData\Local\Amazon\Cloud Drive\AmazonCloudDrive.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Program Files (x86)\Yahoo!\Messenger\yui.dll ()
MOD - C:\Program Files (x86)\Yahoo!\Messenger\pcre.dll ()
MOD - C:\Users\Michael\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpy.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (lxda_device) – C:\Windows\SysNative\lxdacoms.exe ( )
SRV - (AntiVirSchedulerService) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (MBAMService) – C:\Users\Michael\Desktop\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Users\Michael\Desktop\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (McAfee SiteAdvisor Service) – c:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe (McAfee, Inc.)
SRV - (BBUpdate) – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (ADVService) – C:\Program Files (x86)\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe (Amazon.com)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe (McAfee, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (AntiSpywareService) – C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe ()
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (ITMRTSVC) – C:\Program Files (x86)\CA\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
SRV - (lxda_device) – C:\Windows\SysWOW64\lxdacoms.exe ( )


========== Driver Services (SafeList) ==========

DRV:64bit: - (avipbb) – C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH)
DRV:64bit: - (avgntflt) – C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:64bit: - (avkmgr) – C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (kcusbser) – C:\Windows\SysNative\drivers\kcusbser.sys (Kyocera Corporation)
DRV:64bit: - (androidusb) – C:\Windows\SysNative\drivers\androidusb.sys (Kyocera Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE:64bit: - HKLM\..\SearchScopes\{CD1E221F-55E0-4505-A576-5BF15351149A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {86FDC6B9-BD92-43A3-831A-50AD37A4DC64}
IE - HKLM\..\SearchScopes\{86FDC6B9-BD92-43A3-831A-50AD37A4DC64}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2269050

IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2269050
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredibar.com/mb139/?searc…k4b7id&i;=26
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo.com/search?p={searchTe…&fr;=chr-rog
IE - HKCU\..\SearchScopes\{E94D42A1-3A0A-41C3-B2A5-1BD2EBF8B55E}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKCU\..\SearchScopes\{F095866D-3775-4B2E-BFB7-214051690903}: "URL" = http://search.yahoo.com/search?fr=mcafee&p;={SearchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========



FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_271.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_35: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/09/15 20:42:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/07 00:19:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/09/18 15:06:20 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/07 00:19:29 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/09/18 15:06:20 | 000,000,000 | —D | M]

[2011/02/12 18:30:57 | 000,000,000 | —D | M] (No name found) – C:\Users\Michael\AppData\Roaming\Mozilla\Extensions
[2012/08/01 06:57:45 | 000,000,000 | —D | M] (No name found) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\jgjzbyix.default\extensions
[2012/08/26 06:15:19 | 000,000,000 | —D | M] ("Free YouTube Download (Free Studio) Menu") – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\jgjzbyix.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012/08/26 06:15:18 | 000,000,000 | —D | M] (@@toolbarname@@) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\jgjzbyix.default\extensions\[removed]
[2012/09/13 20:13:06 | 000,000,000 | —D | M] (No name found) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions
[2012/08/26 06:15:19 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/08/26 06:15:19 | 000,000,000 | —D | M] (XFINITY Toolbar) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\{4b9bcce8-a70b-402a-a7e1-db96831ee26f}
[2012/08/26 06:15:20 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/08/26 06:15:20 | 000,000,000 | —D | M] (DVDVideoSoftTB Community Toolbar) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2012/08/26 06:15:20 | 000,000,000 | —D | M] ("Free YouTube Download (Free Studio) Menu") – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012/08/26 06:15:19 | 000,000,000 | —D | M] (Conduit Engine) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\[removed]
[2012/08/26 06:15:19 | 000,000,000 | —D | M] (Super Video Downloader) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\[removed]
[2012/08/26 06:15:19 | 000,000,000 | —D | M] ("Ask Toolbar") – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\[removed]
[1832/11/28 23:44:26 | 000,004,819 | —- | M] () (No name found) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\jgjzbyix.default\extensions\[removed]
[2012/08/20 22:39:52 | 000,243,317 | —- | M] () (No name found) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\[removed]
[2099/01/01 12:00:00 | 000,004,819 | —- | M] () (No name found) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\[removed]
[2012/09/12 15:24:26 | 000,621,521 | —- | M] () (No name found) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\[removed]
[2012/07/25 14:11:53 | 000,741,958 | —- | M] () (No name found) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/09/13 20:13:06 | 000,270,876 | —- | M] () (No name found) – C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\kmlh6h5x.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2012/09/18 15:06:22 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/09/07 00:19:23 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0034-ABCDEFFEDCBA}
[2012/09/18 15:06:22 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012/09/07 00:19:29 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/08/29 00:16:43 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/08/29 00:16:43 | 000,002,253 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.60\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.60\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.60\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = I:\iTunes\iTunes Music\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: YouTube = C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Google Search = C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Web Assistant = C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.439_0\
CHR - Extension: SiteAdvisor = C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.50.146.1_0\
CHR - Extension: Gmail = C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\
CHR - Extension: Gmail = C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/09/17 23:31:51 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O2 - BHO: (XFINITY Toolbar) - {4b9bcce8-a70b-402a-a7e1-db96831ee26f} - C:\Program Files (x86)\xfin_portal\comcastdx.dll ()
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Updater For XFIN_PORTAL) - {bb46be07-13eb-4c49-b0f0-fc78b9ea4983} - C:\Program Files (x86)\xfin_portal\auxi\comcastAu.dll (Visicom Media)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (XFINITY Toolbar) - {4b9bcce8-a70b-402a-a7e1-db96831ee26f} - C:\Program Files (x86)\xfin_portal\comcastdx.dll ()
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (DVDVideoSoftTB Toolbar) - {872B5B88-9DB5-4310-BDD0-AC189557E5F5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [ArcSoft MediaImpression Monitor] C:\Program Files (x86)\Kodak\MediaImpression\ArcMonitor.exe (ArcSoft, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKCU..\Run: [Amazon Cloud Drive] C:\Users\Michael\AppData\Local\Amazon\Cloud Drive\AmazonCloudDrive.exe ()
O4 - HKCU..\Run: [ComcastAntispyClient] C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntispy.exe ()
O4 - HKCU..\Run: [Desktop Software] C:\Program Files (x86)\Common Files\SupportSoft\bin\bcont.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Spotify] C:\Users\Michael\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
O4 - HKCU..\Run: [Spotify Web Helper] C:\Users\Michael\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
O4 - Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Michael\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Free YouTube Download - C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube Download - C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_35)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/pub/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6B27F04F-8373-47B8-99A5-C007B39BFD32}: DhcpNameServer = 192.168.10.1
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/09/18 21:36:04 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\Adobe
[2012/09/18 15:06:20 | 000,477,168 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\npdeployJava1.dll
[2012/09/18 15:06:20 | 000,157,680 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2012/09/18 15:06:20 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2012/09/18 15:06:20 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2012/09/18 14:45:18 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Roaming\Malwarebytes
[2012/09/18 14:45:07 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/09/18 14:45:07 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/09/18 14:45:05 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/09/18 14:45:05 | 000,000,000 | —D | C] – C:\Users\Michael\Desktop\Malwarebytes' Anti-Malware
[2012/09/18 00:01:46 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2012/09/17 23:51:40 | 000,000,000 | —D | C] – C:\ComboFix
[2012/09/16 21:58:31 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Roaming\Avira
[2012/09/16 21:52:54 | 000,132,832 | —- | C] (Avira GmbH) – C:\Windows\SysNative\drivers\avipbb.sys
[2012/09/16 21:52:54 | 000,098,848 | —- | C] (Avira GmbH) – C:\Windows\SysNative\drivers\avgntflt.sys
[2012/09/16 21:52:54 | 000,027,760 | —- | C] (Avira GmbH) – C:\Windows\SysNative\drivers\avkmgr.sys
[2012/09/16 21:52:53 | 000,000,000 | —D | C] – C:\ProgramData\Avira
[2012/09/16 21:52:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\Avira
[2012/09/16 20:07:25 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/09/16 20:07:25 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/09/16 20:07:25 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/09/16 20:00:21 | 000,000,000 | —D | C] – C:\Qoobox
[2012/09/16 19:59:56 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/09/16 19:53:09 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{C70F5155-0966-44E8-970B-8AAF6513B10A}
[2012/09/16 19:47:11 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2012/09/15 17:48:28 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{BA845B2F-D277-4C12-B564-F1FFD27C6209}
[2012/09/15 10:40:54 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{8810A0E1-E8F8-4ECA-B32E-859A5270C209}
[2012/09/15 10:04:28 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\RNDISMP.sys
[2012/09/15 10:04:24 | 000,574,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2012/09/15 10:04:19 | 000,376,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\netio.sys
[2012/09/15 10:04:19 | 000,288,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2012/09/14 22:15:54 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{D3B83377-1990-4731-8564-BB70D55CF501}
[2012/09/14 13:27:28 | 000,000,000 | —D | C] – C:\ProgramData\Sendori
[2012/09/14 13:27:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sendori
[2012/09/14 13:27:20 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Roaming\OpenCandy
[2012/09/14 08:49:55 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{A55A1049-5110-4413-9196-924C7B8F546A}
[2012/09/14 06:36:50 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{126CB019-75B4-431C-B1F9-2BC67436FBE5}
[2012/09/14 03:23:23 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{66A3CE22-8860-4A9E-92E6-D0BFE788906B}
[2012/09/13 08:08:18 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{37FB64AE-DC49-4BB5-A689-D264C6988593}
[2012/09/13 06:09:50 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{526F2048-0EA2-4B52-8DBD-4F84CA33D037}
[2012/09/13 04:18:30 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{048088E1-41B9-4A5D-9205-15BF87B774CB}
[2012/09/12 06:15:45 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{5B85A6B2-8B15-4125-BF9F-2D90C11A5333}
[2012/09/12 04:16:32 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{DAAB261B-EAB1-4E0D-8BD4-4772462FE414}
[2012/09/11 16:15:57 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{4AFB4EE1-F7CC-4F3F-9266-7C045C5C90F0}
[2012/09/09 12:44:26 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{D7F914F8-78F3-40DA-A535-D4971B464467}
[2012/09/07 00:19:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012/09/01 10:20:59 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{5E0607A6-87BB-4588-BBA8-87E718B7BE02}
[2012/08/30 14:10:14 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{AC4465CE-1426-4ACB-81FB-C94AC5ED4CEA}
[2012/08/29 13:23:31 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{B8F86225-89D8-401F-A1F8-387615E9D267}
[2012/08/28 11:04:42 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{2FB6718B-2C6D-472C-AF3A-9F6BA45898E2}
[2012/08/27 06:25:28 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{3E75A750-7615-4BD4-AD5C-BBD17BB1141A}
[2012/08/26 03:21:49 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{1E4582EB-E3AB-4C46-A8AD-2BA75006C17E}
[2012/08/25 11:50:16 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{D7CCB081-D9DE-4088-97A9-DEDD7F75568A}
[2012/08/24 13:28:40 | 002,211,928 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Michael\Desktop\TDSSKiller.exe
[2012/08/23 23:38:31 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{981DB989-DD5A-4956-BD00-01BED898E3A8}
[2012/08/23 19:14:37 | 000,000,000 | —D | C] – C:\Config.Msi
[2012/08/23 19:03:11 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{F7A6283C-82CE-481C-A251-0AD24AF9D303}
[2012/08/22 12:02:15 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{D2C926F0-721E-47A7-AC12-F420C144DA51}
[2012/08/21 13:07:11 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{BB3E39F2-818A-4A05-872B-48BF007E3A14}
[2012/08/20 22:59:58 | 000,000,000 | —D | C] – C:\Users\Michael\AppData\Local\{A4019318-FA38-4C2D-8DFD-AA3701FD8223}

========== Files - Modified Within 30 Days ==========

File not found – C:\Windows\SysNative\
[2012/09/19 11:28:06 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/19 11:07:04 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/19 06:07:40 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/09/18 23:28:02 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/18 15:06:12 | 000,477,168 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\npdeployJava1.dll
[2012/09/18 15:06:12 | 000,473,072 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2012/09/18 15:06:12 | 000,157,680 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2012/09/18 15:06:12 | 000,149,488 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2012/09/18 15:06:12 | 000,149,488 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2012/09/18 15:02:09 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/18 15:02:09 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/18 14:53:54 | 000,065,536 | —- | M] () – C:\Windows\SysNative\Ikeext.etl
[2012/09/18 14:53:42 | 1602,985,984 | -HS- | M] () – C:\hiberfil.sys
[2012/09/18 14:45:08 | 000,000,803 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/17 23:31:51 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/09/16 23:45:13 | 000,727,334 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/09/16 23:45:13 | 000,624,614 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/09/16 23:45:13 | 000,106,732 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/09/16 21:53:08 | 000,002,073 | —- | M] () – C:\Users\Public\Desktop\Avira Control Center.lnk
[2012/09/16 19:59:31 | 000,001,489 | —- | M] () – C:\Users\Michael\Desktop\ComboFix.exe - Shortcut.lnk
[2012/09/16 19:59:20 | 000,000,286 | —- | M] () – C:\Windows\Lexstat.ini
[2012/09/15 18:28:49 | 002,211,928 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Michael\Desktop\TDSSKiller.exe
[2012/09/15 18:27:31 | 000,001,485 | —- | M] () – C:\Users\Michael\Desktop\tdsskiller.zip - Shortcut.lnk
[2012/09/15 17:44:01 | 301,082,878 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/09/15 10:03:59 | 000,000,129 | —- | M] () – C:\Windows\SysNative\MRT.INI
[2012/09/08 10:22:18 | 000,002,457 | —- | M] () – C:\Users\Michael\Desktop\Jesse resume.pdf
[2012/09/07 20:26:23 | 000,132,832 | —- | M] (Avira GmbH) – C:\Windows\SysNative\drivers\avipbb.sys
[2012/09/07 20:26:23 | 000,098,848 | —- | M] (Avira GmbH) – C:\Windows\SysNative\drivers\avgntflt.sys
[2012/09/07 20:26:23 | 000,027,760 | —- | M] (Avira GmbH) – C:\Windows\SysNative\drivers\avkmgr.sys
[2012/09/07 17:04:46 | 000,025,928 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/09/02 10:13:50 | 000,002,347 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/08/29 13:17:10 | 000,029,660 | —- | M] () – C:\Users\Michael\Desktop\belinda-en-el-amor-hay-que-perdonar.jpg
[2012/08/25 11:59:12 | 000,719,452 | —- | M] () – C:\Users\Michael\Desktop\desiderata-postcard-5.jpg
[2012/08/24 11:11:20 | 000,096,898 | —- | M] () – C:\Users\Michael\Desktop\christina aguilera i am stripped made by oly wood.jpeg
[2012/08/22 13:12:40 | 000,376,688 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\drivers\netio.sys
[2012/08/22 13:12:33 | 000,288,624 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\drivers\FWPKCLNT.SYS

========== Files Created - No Company Name ==========

File not found – C:\Windows\SysNative\
[2012/09/18 14:45:08 | 000,000,803 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/16 21:53:08 | 000,002,073 | —- | C] () – C:\Users\Public\Desktop\Avira Control Center.lnk
[2012/09/16 20:42:19 | 000,008,932 | -HS- | C] () – C:\Users\Michael\Documents\AlbumArt_{54975EE6-0656-4898-A0D1-98C7101AEDEA}_Large.jpg
[2012/09/16 20:41:56 | 000,009,522 | -HS- | C] () – C:\Users\Michael\Documents\AlbumArt_{25DAE98B-39C2-4308-9646-512FD8DCBCEA}_Large.jpg
[2012/09/16 20:07:25 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/09/16 20:07:25 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/09/16 20:07:25 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/09/16 20:07:25 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/09/16 20:07:25 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/09/16 19:45:20 | 000,001,489 | —- | C] () – C:\Users\Michael\Desktop\ComboFix.exe - Shortcut.lnk
[2012/09/15 18:26:39 | 000,001,485 | —- | C] () – C:\Users\Michael\Desktop\tdsskiller.zip - Shortcut.lnk
[2012/09/08 10:22:18 | 000,002,457 | —- | C] () – C:\Users\Michael\Desktop\Jesse resume.pdf
[2012/08/29 13:11:42 | 000,029,660 | —- | C] () – C:\Users\Michael\Desktop\belinda-en-el-amor-hay-que-perdonar.jpg
[2012/08/25 11:41:36 | 000,719,452 | —- | C] () – C:\Users\Michael\Desktop\desiderata-postcard-5.jpg
[2012/08/24 11:11:19 | 000,096,898 | —- | C] () – C:\Users\Michael\Desktop\christina aguilera i am stripped made by oly wood.jpeg
[2012/05/15 11:07:35 | 002,011,303 | —- | C] () – C:\Users\Michael\Video05022012014850.3g2
[2012/01/01 05:34:41 | 000,000,000 | —- | C] () – C:\Users\Michael\AppData\Local\{4BDD0237-B635-4C96-A1F4-6FC5304ACEFD}
[2011/09/27 19:32:30 | 000,216,765 | —- | C] () – C:\Users\Michael\IMG_20110927_172630.jpg
[2011/04/11 16:59:54 | 000,005,120 | —- | C] () – C:\Users\Michael\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/17 21:20:25 | 000,743,538 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/02/13 20:35:45 | 000,000,286 | —- | C] () – C:\Windows\Lexstat.ini
[2011/02/13 20:34:59 | 001,224,704 | —- | C] ( ) – C:\Windows\SysWow64\lxdaserv.dll
[2011/02/13 20:34:59 | 000,991,232 | —- | C] ( ) – C:\Windows\SysWow64\lxdausb1.dll
[2011/02/13 20:34:59 | 000,696,320 | —- | C] ( ) – C:\Windows\SysWow64\lxdahbn3.dll
[2011/02/13 20:34:59 | 000,684,032 | —- | C] ( ) – C:\Windows\SysWow64\lxdacomc.dll
[2011/02/13 20:34:59 | 000,643,072 | —- | C] ( ) – C:\Windows\SysWow64\lxdapmui.dll
[2011/02/13 20:34:59 | 000,585,728 | —- | C] ( ) – C:\Windows\SysWow64\lxdalmpm.dll
[2011/02/13 20:34:59 | 000,537,520 | —- | C] ( ) – C:\Windows\SysWow64\lxdacoms.exe
[2011/02/13 20:34:59 | 000,421,888 | —- | C] ( ) – C:\Windows\SysWow64\lxdacomm.dll
[2011/02/13 20:34:59 | 000,413,696 | —- | C] () – C:\Windows\SysWow64\lxdautil.dll
[2011/02/13 20:34:59 | 000,413,696 | —- | C] ( ) – C:\Windows\SysWow64\lxdainpa.dll
[2011/02/13 20:34:59 | 000,397,312 | —- | C] ( ) – C:\Windows\SysWow64\lxdaiesc.dll
[2011/02/13 20:34:59 | 000,385,968 | —- | C] ( ) – C:\Windows\SysWow64\lxdaih.exe
[2011/02/13 20:34:59 | 000,381,872 | —- | C] ( ) – C:\Windows\SysWow64\lxdacfg.exe
[2011/02/13 20:34:59 | 000,274,432 | —- | C] () – C:\Windows\SysWow64\LXDAinst.dll
[2011/02/13 20:34:59 | 000,181,168 | —- | C] ( ) – C:\Windows\SysWow64\lxdappls.exe
[2011/02/13 20:34:59 | 000,163,840 | —- | C] ( ) – C:\Windows\SysWow64\lxdaprox.dll
[2011/02/13 20:34:59 | 000,094,208 | —- | C] ( ) – C:\Windows\SysWow64\lxdapplc.dll
[2009/07/31 00:42:53 | 000,002,746 | —- | C] () – C:\Users\Michael\.recently-used.xbel
[2009/07/07 00:16:40 | 000,000,042 | —- | C] () – C:\Users\Michael\default.pls

========== ZeroAccess Check ==========

[2011/11/17 01:41:18 | 000,002,048 | -HS- | M] () – C:\Windows\Installer\{b78eaa2b-9260-b0cd-dade-494fe06d1908}\@
[2011/11/17 01:41:18 | 000,002,048 | -HS- | M] () – C:\Windows\SysWOW64\config\systemprofile\AppData\Local\{b78eaa2b-9260-b0cd-dade-494fe06d1908}\@
[2011/04/11 10:47:33 | 000,000,082 | —- | M] () – C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\system@yahoo[1].txt
[2009/07/13 23:55:00 | 000,000,227 | —- | M] () – C:\Windows\assembly\Desktop.ini
[2012/01/11 14:49:10 | 000,002,048 | -HS- | C] () – C:\Users\Michael\AppData\Local\{b78eaa2b-9260-b0cd-dade-494fe06d1908}\@

========== LOP Check ==========

[2011/02/19 02:49:48 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\Amazon
[2012/08/26 06:15:18 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\Audacity
[2011/11/12 20:21:02 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\com.amazon.music.uploader
[2012/09/18 14:55:07 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\Dropbox
[2012/09/14 13:28:03 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\DVDVideoSoft
[2012/04/21 12:27:45 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\DVDVideoSoftIEHelpers
[2012/02/15 18:21:40 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\FutureDial
[2012/08/30 01:13:51 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\IrfanView
[2012/09/14 19:13:40 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\OpenCandy
[2012/06/28 08:24:46 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\SendSpace
[2012/09/11 16:12:59 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\SoftGrid Client
[2012/09/18 14:55:21 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\Spotify
[2011/02/17 21:21:20 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\TP
[2011/04/02 22:52:26 | 000,000,000 | —D | M] – C:\Users\Michael\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI