This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser Redirect [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My problem seemed to start this morning I ran Malwarebytes Anti-Malware but as soon as it detected threats it locked up. So I then downloaded SuperAntiSpyware it detected the Happili trojan, Rogue.Agent/Gen-Null, and TrustyHound!rem. I removed those and restarted and that's when my real problems began. I still get a redirect when I search in IE or Firefox. It would direct to beesq.net but now it seems to go to random sites. I give up. None of the spyware/malware scanners I tried detected any other threats but obviously there is still a problem. Now my desktop even looks different. I don't seem to have the redirect problem in safe mode if that makes a difference. Hijackthis log listed below.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:48:45 PM, on 9/30/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Norton Security Suite\Engine\4.4.0.12\ccSvcHst.exe
C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
c:\Program Files (x86)\Cyberlink\Shared Files\brs.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_278_ActiveX.exe
C:\Program Files (x86)\Roxio\oem\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Krystal\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\4.4.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Security Suite\Engine\4.4.0.12\IPSBHO.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\4.4.0.12\coIEPlg.dll
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
O4 - HKCU\..\Run: [{359606B4-539E-4904-A6E9-682155F208BF}] rundll32.exe "C:\Users\Krystal\AppData\Local\{3DCB023F-4E21-42BE-82BE-DF5909610CC5}\{359606B4-539E-4904-A6E9-682155F208BF}\ptfebc.dll",iTunesHelperMainEntryPointW
O4 - HKCU\..\RunOnce: [adawarebp] reg.exe delete "HKCU\Software\AppDataLow\Software\adawarebp" /f
O4 - HKCU\..\RunOnce: [adawarebp_XP] reg.exe delete "HKCU\Software\adawarebp" /f
O4 - HKCU\..\RunOnce: [adawarebp_DATA_FOLDER] cmd.exe /c rmdir "C:\ProgramData\Ad-Aware Browsing Protection" /s /q
O4 - HKCU\..\RunOnce: [adawarebp_INSTALL_FOLDER] cmd.exe /c rmdir "C:\Users\Krystal\AppData\Local\adawarebp" /s /q
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3501816477-2625921513-584954640-1004\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-3501816477-2625921513-584954640-1004\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} (Scanner.SysScanner) - http://i.dell.com/images/global/js/scanner/SysProExe.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.6.0.cab
O16 - DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} (P3DActiveX Control) - http://panda-plugin.disney.go.com/plugin/w…/p3dactivex.cab
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} (DellSystemLite.Scanner) - http://support.dell.com/systemprofiler/DellSystemLite.CAB
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Product - 2011/03/16 09:25:24 (CLKMSVC10_9EC60124) - CyberLink - c:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe
O23 - Service: Intel® PROSet/Wireless WiMAX Red Bend Device Management Service (DMAgent) - Red Bend Ltd. - C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: Norton Security Suite (N360) - Symantec Corporation - C:\Program Files (x86)\Norton Security Suite\Engine\4.4.0.12\ccSvcHst.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: RoxMediaDB12OEM - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) - Sonic Solutions - C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Intel® Turbo Boost Technology Monitor 2.0 (TurboBoost) - Intel® Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Intel® PROSet/Wireless WiMAX Service (WiMAXAppSrv) - Intel® Corporation - C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 13149 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and attach its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

Please download TDSSKiller
  • Double click TDSSKiller.exe
  • When the window opens, click on Change Parameters
  • Under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”
  • click OK
  • Press Start Scan
  • Do Not Attempt To Fix Anything Now. We just need to look over the report and be sure we are removing the correct
    items.
  • Attach the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-
Thanks Jeff, My DDS, aswMBR, and TDSSKiller logs below: DDS Logs - DDS.txt followed by Attach.txt . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_26 Run by [removed] at 19:04:44 on 2012-10-01 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8152.6124 [GMT -5:00] . AV: Norton Security Suite *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton Security Suite *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Security Suite *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Intel\WiFi\bin\EvtEng.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Norton Security Suite\Engine\4.4.0.12\ccSvcHst.exe C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe C:\Windows\System32\rundll32.exe C:\Windows\SysWOW64\rundll32.exe C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\Norton Security Suite\Engine\4.4.0.12\ccSvcHst.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\DllHost.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe C:\Windows\servicing\TrustedInstaller.exe c:\Program Files (x86)\Cyberlink\Shared Files\brs.exe C:\Program Files (x86)\Roxio\oem\Roxio Burn\RoxioBurnLauncher.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_278_ActiveX.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uSearch Page = hxxp://www.google.com uStart Page = hxxp://www.yahoo.com/ uSearch Bar = hxxp://www.google.com uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com mWinlogon: Userinit=userinit.exe, BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Security Suite\Engine\4.4.0.12\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Security Suite\Engine\4.4.0.12\IPSBHO.DLL BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Security Suite\Engine\4.4.0.12\coIEPlg.dll TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File uRun: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe uRun: [{359606B4-539E-4904-A6E9-682155F208BF}] rundll32.exe "C:\Users\Krystal\AppData\Local\{3DCB023F-4E21-42BE-82BE-DF5909610CC5}\{359606B4-539E-4904-A6E9-682155F208BF}\ptfebc.dll",iTunesHelperMainEntryPointW mRun: [] mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" mRun: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} - hxxp://i.dell.com/images/global/js/scanner/SysProExe.cab DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.6.0.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} - hxxp://panda-plugin.disney.go.com/plugin/win32/p3dactivex.cab DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} - hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab TCP: DhcpNameServer = 192.168.1.1 75.75.75.75 75.75.76.76 TCP: Interfaces\{52734C9A-B7BD-4B2F-9C30-95BCAC99FADD} : DhcpNameServer = 192.168.1.1 75.75.75.75 75.75.76.76 TCP: Interfaces\{52734C9A-B7BD-4B2F-9C30-95BCAC99FADD}\84F6D656C696E6B6 : DhcpNameServer = [removed] [removed] TCP: Interfaces\{52734C9A-B7BD-4B2F-9C30-95BCAC99FADD}\C696E6B6379737 : DhcpNameServer = [removed] [removed] Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\4.4.0.12\coIEPlg.dll BHO-X64: Symantec NCO BHO - No File BHO-X64: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Security Suite\Engine\4.4.0.12\IPSBHO.DLL BHO-X64: Symantec Intrusion Prevention - No File BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\4.4.0.12\coIEPlg.dll TB-X64: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File mRun-x64: [(Default)] mRun-x64: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" mRun-x64: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Krystal\AppData\Roaming\Mozilla\Firefox\Profiles\xfy65lgs.default\ FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll . ============= SERVICES / DRIVERS =============== . R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys –> C:\Windows\system32\Drivers\PxHlpa64.sys [?] R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\system32\DRIVERS\stdcfltn.sys –> C:\Windows\system32\DRIVERS\stdcfltn.sys [?] R0 SymDS;Symantec Data Store;C:\Windows\system32\drivers\N360x64\0404000.00C\SYMDS64.SYS –> C:\Windows\system32\drivers\N360x64\0404000.00C\SYMDS64.SYS [?] R0 SymEFA;Symantec Extended File Attributes;C:\Windows\system32\drivers\N360x64\0404000.00C\SYMEFA64.SYS –> C:\Windows\system32\drivers\N360x64\0404000.00C\SYMEFA64.SYS [?] R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20120919.001\BHDrvx64.sys [2012-9-20 1385120] R1 ccHP;Symantec Hash Provider;C:\Windows\system32\drivers\N360x64\0404000.00C\ccHPx64.sys –> C:\Windows\system32\drivers\N360x64\0404000.00C\ccHPx64.sys [?] R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20120928.001\IDSviA64.sys [2012-9-28 513184] R1 SymIRON;Symantec Iron Driver;C:\Windows\system32\drivers\N360x64\0404000.00C\Ironx64.SYS –> C:\Windows\system32\drivers\N360x64\0404000.00C\Ironx64.SYS [?] R1 SYMTDIv;Symantec Vista Network Dispatch Driver;C:\Windows\system32\Drivers\N360x64\0404000.00C\SYMTDIV.SYS –> C:\Windows\system32\Drivers\N360x64\0404000.00C\SYMTDIV.SYS [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2011-4-24 98208] R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624] R2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [2010-11-7 499200] R2 N360;Norton Security Suite;C:\Program Files (x86)\Norton Security Suite\Engine\4.4.0.12\ccsvchst.exe [2011-11-1 126400] R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-3-4 2348352] R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776] R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2011-3-16 689472] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-2-9 382272] R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\system32\DRIVERS\TurboB.sys –> C:\Windows\system32\DRIVERS\TurboB.sys [?] R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-3-16 2656280] R2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [2010-11-7 869376] R3 Acceler;Accelerometer Service;C:\Windows\system32\DRIVERS\Accelern.sys –> C:\Windows\system32\DRIVERS\Accelern.sys [?] R3 bpenum;Intel® Centrino® WiMAX Enumerator;C:\Windows\system32\DRIVERS\bpenum.sys –> C:\Windows\system32\DRIVERS\bpenum.sys [?] R3 bpmp;Intel® Centrino® WiMAX 6050 Series;C:\Windows\system32\DRIVERS\bpmp.sys –> C:\Windows\system32\DRIVERS\bpmp.sys [?] R3 bpusb;Intel® Centrino® WiMAX 6050 Series Function Driver;C:\Windows\system32\Drivers\bpusb.sys –> C:\Windows\system32\Drivers\bpusb.sys [?] R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys –> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-9-30 138912] R3 MEIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys –> C:\Windows\system32\DRIVERS\HECIx64.sys [?] R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETwNs64.sys –> C:\Windows\system32\DRIVERS\NETwNs64.sys [?] R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys –> C:\Windows\system32\DRIVERS\nusb3hub.sys [?] R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys –> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys –> C:\Windows\system32\drivers\nvhda64v.sys [?] R3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;C:\Windows\system32\DRIVERS\nvstusb.sys –> C:\Windows\system32\DRIVERS\nvstusb.sys [?] R3 qicflt;upper Device Filter Driver;C:\Windows\system32\DRIVERS\qicflt.sys –> C:\Windows\system32\DRIVERS\qicflt.sys [?] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys –> C:\Windows\system32\DRIVERS\Sftfslh.sys [?] R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys –> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?] R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys –> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?] R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys –> C:\Windows\system32\DRIVERS\Sftvollh.sys [?] R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys –> C:\Windows\system32\DRIVERS\vwifimp.sys [?] S2 CLKMSVC10_9EC60124;CyberLink Product - 2011/03/16 09:25:24;C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-10-29 236016] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-9-4 219632] S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-4 114144] S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-12-17 340240] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-9-4 1116656] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys –> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?] S3 WSDPrintDevice;WSD Print Support via UMB;C:\Windows\system32\DRIVERS\WSDPrint.sys –> C:\Windows\system32\DRIVERS\WSDPrint.sys [?] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== Created Last 30 ================ . 2012-10-01 02:11:59 ——– d—–w- C:\Users\Krystal\AppData\Roaming\Anvisoft 2012-10-01 02:11:53 ——– d—–w- C:\ProgramData\Anvisoft 2012-10-01 02:11:52 ——– d—–w- C:\Program Files (x86)\Anvisoft 2012-10-01 02:02:36 ——– d—–w- C:\Users\Krystal\AppData\Roaming\LavasoftStatistics 2012-10-01 02:02:13 ——– d—–w- C:\ProgramData\blekko toolbars 2012-09-30 22:54:40 ——– d—–w- C:\Program Files (x86)\VS Revo Group 2012-09-30 22:33:09 ——– d—–w- C:\Program Files\Enigma Software Group 2012-09-30 22:32:23 ——– d—–w- C:\Windows\8C5C34C7BC6B48318B2C6535FE63E502.TMP 2012-09-30 22:32:23 ——– d—–w- C:\Program Files (x86)\Common Files\Wise Installation Wizard 2012-09-30 17:53:40 ——– d—–w- C:\Program Files (x86)\PC Tools 2012-09-30 17:51:19 251560 —-a-w- C:\Windows\System32\drivers\PCTSD64.sys 2012-09-30 17:51:19 ——– d—–w- C:\Program Files (x86)\Common Files\PC Tools 2012-09-30 17:50:35 ——– d—–w- C:\ProgramData\PC Tools 2012-09-30 17:50:32 ——– d—–w- C:\Users\Krystal\AppData\Roaming\TestApp 2012-09-30 17:49:21 ——– d—–w- C:\Program Files (x86)\Ad-Aware Antivirus 2012-09-30 17:48:43 ——– d—–w- C:\Program Files (x86)\adawaretb 2012-09-30 17:48:42 ——– d—–w- C:\Program Files (x86)\Toolbar Cleaner 2012-09-30 17:47:30 ——– d—–w- C:\Users\Krystal\AppData\Roaming\Ad-Aware Antivirus 2012-09-30 17:10:03 ——– d—–w- C:\ProgramData\Spybot - Search & Destroy 2012-09-30 17:10:03 ——– d—–w- C:\Program Files (x86)\Spybot - Search & Destroy 2012-09-26 01:45:43 245760 —-a-w- C:\Windows\System32\OxpsConverter.exe 2012-09-16 18:35:51 ——– d—–w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2012-09-16 18:35:51 ——– d—–w- C:\Program Files\iTunes 2012-09-16 18:35:51 ——– d—–w- C:\Program Files\iPod 2012-09-16 18:35:51 ——– d—–w- C:\Program Files (x86)\iTunes 2012-09-16 13:47:34 ——– d—–w- C:\Users\Krystal\AppData\Local\{1272B932-4220-4D49-A2D0-28CA212FF3A2} 2012-09-15 15:11:07 ——– d—–w- C:\Users\Krystal\AppData\Local\{332F0C9E-EE63-452A-94E3-58B28300D2FD} 2012-09-15 13:43:55 33240 —-a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys 2012-09-13 01:27:12 950128 —-a-w- C:\Windows\System32\drivers\ndis.sys 2012-09-13 01:27:12 41472 —-a-w- C:\Windows\System32\drivers\RNDISMP.sys 2012-09-13 01:27:07 574464 —-a-w- C:\Windows\System32\d3d10level9.dll 2012-09-13 01:27:07 490496 —-a-w- C:\Windows\SysWow64\d3d10level9.dll 2012-09-13 01:27:02 376688 —-a-w- C:\Windows\System32\drivers\netio.sys 2012-09-13 01:27:02 288624 —-a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS 2012-09-13 01:27:02 1913200 —-a-w- C:\Windows\System32\drivers\tcpip.sys . ==================== Find3M ==================== . 2012-09-28 03:00:18 696240 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-09-28 03:00:17 73136 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-08-24 18:05:06 1188864 —-a-w- C:\Windows\System32\wininet.dll 2012-08-24 16:57:48 981504 —-a-w- C:\Windows\SysWow64\wininet.dll 2012-08-24 15:59:30 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2012-08-24 15:20:39 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2012-08-21 18:01:20 125872 —-a-w- C:\Windows\System32\GEARAspi64.dll 2012-08-21 18:01:20 106928 —-a-w- C:\Windows\SysWow64\GEARAspi.dll 2012-07-18 18:15:06 3148800 —-a-w- C:\Windows\System32\win32k.sys 2012-07-09 18:42:56 4547984 —-a-w- C:\Windows\System32\usbaaplrc.dll 2012-07-09 18:42:54 52736 —-a-w- C:\Windows\System32\drivers\usbaapl64.sys 2012-07-04 22:13:27 59392 —-a-w- C:\Windows\System32\browcli.dll 2012-07-04 22:13:27 136704 —-a-w- C:\Windows\System32\browser.dll 2012-07-04 21:14:34 41984 —-a-w- C:\Windows\SysWow64\browcli.dll . ============= FINISH: 19:05:24.32 =============== DDS Attach.txt log . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 3/23/2011 9:05:37 PM System Uptime: 10/1/2012 6:53:04 PM (1 hours ago) . Motherboard: Dell Inc. | | 0C6YV7 Processor: Intel® Core™ i7-2720QM CPU @ 2.20GHz | CPU | 792/100mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 451 GiB total, 344.932 GiB free. D: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1} Description: SBRE Device ID: ROOT\LEGACY_SBRE\0000 Manufacturer: Name: SBRE PNP Device ID: ROOT\LEGACY_SBRE\0000 Service: SBRE . ==== System Restore Points =================== . RP143: 9/16/2012 1:30:41 PM - Removed iTunes RP144: 9/16/2012 1:35:31 PM - Installed iTunes RP145: 9/22/2012 7:41:17 AM - Windows Update RP146: 9/22/2012 2:19:45 PM - Norton Security Suite Registry RP147: 9/26/2012 3:00:22 AM - Windows Update RP148: 9/30/2012 5:32:30 PM - Installed SpyHunter RP149: 9/30/2012 5:56:17 PM - Revo Uninstaller's restore point - Snap.Do RP150: 9/30/2012 5:57:47 PM - Revo Uninstaller's restore point - Malwarebytes Anti-Malware version 1.65.0.1400 RP151: 9/30/2012 6:03:45 PM - Removed SpyHunter . ==== Installed Programs ====================== . AccelerometerP11 Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader 9.5.2 Adobe Shockwave Player 11.6 Advanced Audio FX Engine Apple Application Support Apple Software Update ArcSoft PhotoStudio 6 Canon IJ Network Tool Canon MOV Decoder Canon MP990 series User Registration CLEAR™ WiMAX Tutorial Consumer In-Home Service Agreement CyberLink PowerDVD 9.6 D3DX10 Dell DataSafe Local Backup Dell DataSafe Local Backup - Support Software Dell Driver Download Manager Dell Getting Started Guide Dell PhotoStage Dell Stage Dell VideoStage Dell Webcam Central DirectX 9 Runtime Disney Pirates of the Caribbean Online Disney Pirates of the Caribbean Online TEST ExamMatrix CPA Exam Review 2011 Infragisticsv62Install 2010 Intel® Management Engine Components Internet Explorer Java Auto Updater Java™ 6 Update 26 Junk Mail filter update Mesh Runtime Messenger Companion Microsoft Office 2010 Microsoft Office Click-to-Run 2010 Microsoft Office Starter 2010 - English Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Mozilla Firefox 15.0 (x86 en-US) Mozilla Firefox 15.0.1 (x86 en-US) Mozilla Maintenance Service MSVCRT MSVCRT_amd64 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Norton Security Suite NVIDIA 3D Vision Controller Driver NVIDIA PhysX NVIDIA Stereoscopic 3D Driver PhotoShowExpress QuickTime Realtek High Definition Audio Driver Renesas Electronics USB 3.0 Host Controller Driver Revo Uninstaller 1.94 Roxio Activation Module Roxio BackOnTrack Roxio Burn Roxio Creator Starter Roxio Express Labeler 3 Safari Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Extended (KB2487367) Security Update for Microsoft .NET Framework 4 Extended (KB2656351) Sonic CinePlayer Decoder Pack swMSM Tansee iPhone Transfer SMS [removed] TValue 5 Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft .NET Framework 4 Extended (KB2468871) Update for Microsoft .NET Framework 4 Extended (KB2533523) Update for Microsoft .NET Framework 4 Extended (KB2600217) Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Mail Windows Live Mesh Windows Live Mesh ActiveX Control for Remote Connections Windows Live Messenger Windows Live Messenger Companion Core Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources . ==== Event Viewer Messages From Past Week ======== . 9/30/2012 9:22:53 PM, Error: VDS Basic Provider [1] - Unexpected failure. Error code: D@01010004 9/30/2012 9:17:55 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 9/30/2012 9:02:28 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046} 9/30/2012 9:02:07 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 9/30/2012 8:43:35 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F} 9/30/2012 8:43:35 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF} 9/30/2012 8:36:56 PM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start. 9/30/2012 8:36:55 PM, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\IWMSSvc.dll Error Code: 21 9/30/2012 8:36:52 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 9/30/2012 8:36:52 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 9/30/2012 8:36:49 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 9/30/2012 8:36:43 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 9/30/2012 8:36:38 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: BHDrvx64 ccHP discache eeCtrl IDSVia64 PCTSD SASDIFSV SASKUTIL SBRE spldr SRTSP SRTSPX SymIRON SYMTDIv Wanarpv6 9/30/2012 8:36:36 PM, Error: Service Control Manager [7001] - The Client Virtualization Handler service depends on the Application Virtualization Client service which failed to start because of the following error: The dependency service or group failed to start. 9/30/2012 7:35:40 AM, Error: Server [2505] - The server could not bind to the transport \Device\NetBT_Tcpip_{52734C9A-B7BD-4B2F-9C30-95BCAC99FADD} because another computer on the network has the same name. The server could not start. 9/30/2012 6:34:59 PM, Error: PCTCore [280] - 9/30/2012 6:15:37 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error: An instance of the service is already running. 9/30/2012 6:14:52 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. 9/30/2012 6:14:52 PM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error %%-1073473535. 9/30/2012 3:31:18 PM, Error: Schannel [36888] - The following fatal alert was generated: 40. The internal error state is 107. 9/30/2012 3:31:18 PM, Error: Schannel [36874] - An SSL 3.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. 9/30/2012 1:09:24 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Intel® Management and Security Application User Notification Service service to connect. 9/30/2012 1:09:24 PM, Error: Service Control Manager [7000] - The Intel® Management and Security Application User Notification Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 10/1/2012 6:56:20 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: SBRE . ==== End Of File =========================== aswMBR.txt log aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-10-01 19:52:22 —————————– 19:52:22.340 OS Version: Windows x64 6.1.7601 Service Pack 1 19:52:22.340 Number of processors: 8 586 0x2A07 19:52:22.340 ComputerName: KRYSTAL-LAPTOP UserName: Krystal 19:52:24.228 Initialize success 19:52:32.133 AVAST engine defs: 12100101 19:52:36.972 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 19:52:36.972 Disk 0 Vendor: ST9500420AS D005SDM1 Size: 476940MB BusType: 11 19:52:37.035 Disk 0 MBR read successfully 19:52:37.035 Disk 0 MBR scan 19:52:37.050 Disk 0 Windows VISTA default MBR code 19:52:37.066 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 101 MB offset 63 19:52:37.081 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 208845 19:52:37.097 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 461837 MB offset 30928845 19:52:37.161 Disk 0 scanning C:\Windows\system32\drivers 19:53:02.780 Service scanning 19:53:29.852 Modules scanning 19:53:29.868 Disk 0 trace - called modules: 19:53:29.915 ntoskrnl.exe CLASSPNP.SYS disk.sys stdcfltn.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys 19:53:29.915 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007954790] 19:53:29.930 3 CLASSPNP.SYS[fffff8800195d43f] -> nt!IofCallDriver -> [0xfffffa80078578d0] 19:53:29.946 5 stdcfltn.sys[fffff880018a7c52] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80076e6060] 19:53:32.512 AVAST engine scan C:\Windows 19:53:38.195 AVAST engine scan C:\Windows\system32 19:59:24.742 AVAST engine scan C:\Windows\system32\drivers 19:59:48.037 AVAST engine scan C:\Users\Krystal 20:13:02.634 AVAST engine scan C:\ProgramData 20:27:12.780 File: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20120929.001\IDSviA64.sys **HIDDEN** 20:27:14.748 File: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20120929.001\IDSvix86.sys **HIDDEN** 20:27:16.074 File: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20120929.001\IDSxpx86.dll **HIDDEN** 20:27:16.933 File: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20120929.001\IDSXpx86.sys **HIDDEN** 20:27:18.196 File: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20120929.001\IPSFFPl.dll **HIDDEN** 20:27:19.917 File: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20120929.001\Scxpx86.dll **HIDDEN** 20:27:22.213 Scan finished successfully 20:27:35.134 Disk 0 MBR has been saved successfully to "C:\Users\Krystal\Desktop\MBR.dat" 20:27:35.134 The log file has been saved successfully to "C:\Users\Krystal\Desktop\aswMBR.txt" TDSSKiller.txt log 20:35:24.0824 3980 TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24 20:35:25.0276 3980 ============================================================ 20:35:25.0276 3980 Current date / time: 2012/10/01 20:35:25.0276 20:35:25.0276 3980 SystemInfo: 20:35:25.0276 3980 20:35:25.0276 3980 OS Version: 6.1.7601 ServicePack: 1.0 20:35:25.0276 3980 Product type: Workstation 20:35:25.0276 3980 ComputerName: KRYSTAL-LAPTOP 20:35:25.0276 3980 UserName: Krystal 20:35:25.0276 3980 Windows directory: C:\Windows 20:35:25.0276 3980 System windows directory: C:\Windows 20:35:25.0276 3980 Running under WOW64 20:35:25.0276 3980 Processor architecture: Intel x64 20:35:25.0276 3980 Number of processors: 8 20:35:25.0276 3980 Page size: 0x1000 20:35:25.0276 3980 Boot type: Normal boot 20:35:25.0276 3980 ============================================================ 20:35:26.0481 3980 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 20:35:26.0481 3980 ============================================================ 20:35:26.0481 3980 \Device\Harddisk0\DR0: 20:35:26.0481 3980 MBR partitions: 20:35:26.0481 3980 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32FCD, BlocksNum 0x1D4C000 20:35:26.0481 3980 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1D7EFCD, BlocksNum 0x38606863 20:35:26.0481 3980 ============================================================ 20:35:26.0512 3980 C: <-> \Device\Harddisk0\DR0\Partition2 20:35:26.0512 3980 ============================================================ 20:35:26.0512 3980 Initialize success 20:35:26.0512 3980 ============================================================ 20:35:32.0057 5132 ============================================================ 20:35:32.0057 5132 Scan started 20:35:32.0057 5132 Mode: Manual; 20:35:32.0057 5132 ============================================================ 20:35:33.0623 5132 ================ Scan system memory ======================== 20:35:33.0623 5132 System memory - ok 20:35:33.0638 5132 ================ Scan services ============================= 20:35:33.0794 5132 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 20:35:33.0810 5132 1394ohci - ok 20:35:33.0857 5132 [ E0065CBF1A25C015C218457D2CD522B9 ] Acceler C:\Windows\system32\DRIVERS\Accelern.sys 20:35:33.0872 5132 Acceler - ok 20:35:33.0966 5132 [ ADC420616C501B45D26C0FD3EF1E54E4 ] ACDaemon C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe 20:35:33.0966 5132 ACDaemon - ok 20:35:33.0997 5132 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 20:35:34.0013 5132 ACPI - ok 20:35:34.0028 5132 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 20:35:34.0044 5132 AcpiPmi - ok 20:35:34.0075 5132 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 20:35:34.0106 5132 adp94xx - ok 20:35:34.0122 5132 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 20:35:34.0153 5132 adpahci - ok 20:35:34.0169 5132 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 20:35:34.0184 5132 adpu320 - ok 20:35:34.0216 5132 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 20:35:34.0216 5132 AeLookupSvc - ok 20:35:34.0278 5132 [ D1E343BC00136CE03C4D403194D06A80 ] AERTFilters C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe 20:35:34.0278 5132 AERTFilters - ok 20:35:34.0340 5132 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 20:35:34.0356 5132 AFD - ok 20:35:34.0403 5132 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 20:35:34.0403 5132 agp440 - ok 20:35:34.0418 5132 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 20:35:34.0418 5132 ALG - ok 20:35:34.0450 5132 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 20:35:34.0465 5132 aliide - ok 20:35:34.0481 5132 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 20:35:34.0496 5132 amdide - ok 20:35:34.0528 5132 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 20:35:34.0528 5132 AmdK8 - ok 20:35:34.0543 5132 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 20:35:34.0559 5132 AmdPPM - ok 20:35:34.0590 5132 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 20:35:34.0590 5132 amdsata - ok 20:35:34.0621 5132 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 20:35:34.0621 5132 amdsbs - ok 20:35:34.0652 5132 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 20:35:34.0652 5132 amdxata - ok 20:35:34.0684 5132 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 20:35:34.0684 5132 AppID - ok 20:35:34.0699 5132 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 20:35:34.0699 5132 AppIDSvc - ok 20:35:34.0730 5132 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll 20:35:34.0730 5132 Appinfo - ok 20:35:34.0808 5132 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 20:35:34.0808 5132 Apple Mobile Device - ok 20:35:34.0824 5132 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys 20:35:34.0840 5132 arc - ok 20:35:34.0855 5132 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 20:35:34.0855 5132 arcsas - ok 20:35:34.0980 5132 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 20:35:34.0980 5132 aspnet_state - ok 20:35:35.0011 5132 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 20:35:35.0011 5132 AsyncMac - ok 20:35:35.0042 5132 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 20:35:35.0042 5132 atapi - ok 20:35:35.0105 5132 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 20:35:35.0136 5132 AudioEndpointBuilder - ok 20:35:35.0167 5132 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 20:35:35.0167 5132 AudioSrv - ok 20:35:35.0198 5132 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 20:35:35.0198 5132 AxInstSV - ok 20:35:35.0232 5132 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys 20:35:35.0263 5132 b06bdrv - ok 20:35:35.0294 5132 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 20:35:35.0310 5132 b57nd60a - ok 20:35:35.0341 5132 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 20:35:35.0356 5132 BDESVC - ok 20:35:35.0372 5132 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 20:35:35.0372 5132 Beep - ok 20:35:35.0434 5132 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll 20:35:35.0450 5132 BFE - ok 20:35:35.0653 5132 [ A45BE4E091636F6C86D6E4FC945D5A26 ] BHDrvx64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20120928.001\BHDrvx64.sys 20:35:35.0715 5132 BHDrvx64 - ok 20:35:35.0778 5132 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll 20:35:35.0809 5132 BITS - ok 20:35:35.0824 5132 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 20:35:35.0824 5132 blbdrive - ok 20:35:35.0902 5132 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 20:35:35.0918 5132 Bonjour Service - ok 20:35:35.0965 5132 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 20:35:35.0980 5132 bowser - ok 20:35:36.0012 5132 [ 597FFFAC47605337B1C719B4975238F0 ] bpenum C:\Windows\system32\DRIVERS\bpenum.sys 20:35:36.0012 5132 bpenum - ok 20:35:36.0043 5132 [ F66C6AD105EF5A899207F4907366E2E2 ] bpmp C:\Windows\system32\DRIVERS\bpmp.sys 20:35:36.0043 5132 bpmp - ok 20:35:36.0058 5132 [ AE6751F004DFEBE0A7548265CCF432CE ] bpusb C:\Windows\system32\Drivers\bpusb.sys 20:35:36.0058 5132 bpusb - ok 20:35:36.0090 5132 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 20:35:36.0090 5132 BrFiltLo - ok 20:35:36.0090 5132 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 20:35:36.0105 5132 BrFiltUp - ok 20:35:36.0136 5132 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 20:35:36.0152 5132 Browser - ok 20:35:36.0168 5132 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 20:35:36.0183 5132 Brserid - ok 20:35:36.0199 5132 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 20:35:36.0199 5132 BrSerWdm - ok 20:35:36.0214 5132 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 20:35:36.0214 5132 BrUsbMdm - ok 20:35:36.0230 5132 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 20:35:36.0230 5132 BrUsbSer - ok 20:35:36.0246 5132 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 20:35:36.0246 5132 BTHMODEM - ok 20:35:36.0292 5132 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 20:35:36.0292 5132 bthserv - ok 20:35:36.0386 5132 [ 37F1BAEC39B505B3B51893A35C8337EA ] ccHP C:\Windows\system32\drivers\N360x64\0404000.00C\ccHPx64.sys 20:35:36.0417 5132 ccHP - ok 20:35:36.0433 5132 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 20:35:36.0448 5132 cdfs - ok 20:35:36.0495 5132 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\drivers\cdrom.sys 20:35:36.0511 5132 cdrom - ok 20:35:36.0558 5132 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 20:35:36.0558 5132 CertPropSvc - ok 20:35:36.0573 5132 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys 20:35:36.0573 5132 circlass - ok 20:35:36.0604 5132 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 20:35:36.0636 5132 CLFS - ok 20:35:36.0698 5132 [ 730BF325E4CC1E3935B81943AC6DA216 ] CLKMSVC10_9EC60124 c:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe 20:35:36.0698 5132 CLKMSVC10_9EC60124 - ok 20:35:36.0745 5132 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 20:35:36.0760 5132 clr_optimization_v2.0.50727_32 - ok 20:35:36.0807 5132 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 20:35:36.0823 5132 clr_optimization_v2.0.50727_64 - ok 20:35:36.0885 5132 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 20:35:36.0885 5132 clr_optimization_v4.0.30319_32 - ok 20:35:36.0901 5132 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 20:35:36.0916 5132 clr_optimization_v4.0.30319_64 - ok 20:35:36.0932 5132 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 20:35:36.0932 5132 CmBatt - ok 20:35:36.0963 5132 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 20:35:36.0979 5132 cmdide - ok 20:35:37.0026 5132 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 20:35:37.0041 5132 CNG - ok 20:35:37.0088 5132 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 20:35:37.0088 5132 Compbatt - ok 20:35:37.0135 5132 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 20:35:37.0135 5132 CompositeBus - ok 20:35:37.0150 5132 COMSysApp - ok 20:35:37.0166 5132 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 20:35:37.0166 5132 crcdisk - ok 20:35:37.0228 5132 [ 4F5414602E2544A4554D95517948B705 ] CryptSvc C:\Windows\system32\cryptsvc.dll 20:35:37.0228 5132 CryptSvc - ok 20:35:37.0275 5132 [ FBE228ABEAB2BE13B9C3A3A112D4D8DC ] CtClsFlt C:\Windows\system32\DRIVERS\CtClsFlt.sys 20:35:37.0291 5132 CtClsFlt - ok 20:35:37.0400 5132 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE 20:35:37.0416 5132 cvhsvc - ok 20:35:37.0463 5132 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 20:35:37.0495 5132 DcomLaunch - ok 20:35:37.0510 5132 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 20:35:37.0526 5132 defragsvc - ok 20:35:37.0557 5132 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 20:35:37.0573 5132 DfsC - ok 20:35:37.0604 5132 dgderdrv - ok 20:35:37.0666 5132 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 20:35:37.0666 5132 Dhcp - ok 20:35:37.0697 5132 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 20:35:37.0697 5132 discache - ok 20:35:37.0729 5132 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys 20:35:37.0729 5132 Disk - ok 20:35:37.0791 5132 [ FD6780D8E79A4A0037DBCB339582F091 ] DMAgent C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe 20:35:37.0807 5132 DMAgent - ok 20:35:37.0838 5132 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 20:35:37.0853 5132 Dnscache - ok 20:35:37.0885 5132 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 20:35:37.0900 5132 dot3svc - ok 20:35:37.0931 5132 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 20:35:37.0947 5132 DPS - ok 20:35:37.0963 5132 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 20:35:37.0978 5132 drmkaud - ok 20:35:38.0025 5132 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 20:35:38.0072 5132 DXGKrnl - ok 20:35:38.0103 5132 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 20:35:38.0119 5132 EapHost - ok 20:35:38.0212 5132 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys 20:35:38.0306 5132 ebdrv - ok 20:35:38.0368 5132 [ 4353FF94D47A0A9D52B89ECCF0CDB013 ] eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys 20:35:38.0384 5132 eeCtrl - ok 20:35:38.0431 5132 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 20:35:38.0431 5132 EFS - ok 20:35:38.0493 5132 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 20:35:38.0509 5132 ehRecvr - ok 20:35:38.0540 5132 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 20:35:38.0555 5132 ehSched - ok 20:35:38.0571 5132 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 20:35:38.0602 5132 elxstor - ok 20:35:38.0696 5132 [ C5BCCB378D0A896304A3E71BE7215983 ] EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 20:35:38.0696 5132 EraserUtilRebootDrv - ok 20:35:38.0758 5132 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 20:35:38.0789 5132 ErrDev - ok 20:35:38.0883 5132 esgiguard - ok 20:35:38.0914 5132 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 20:35:38.0930 5132 EventSystem - ok 20:35:39.0039 5132 [ 8B6C9924B0D333DBF76086B8258A0891 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe 20:35:39.0055 5132 EvtEng - ok 20:35:39.0086 5132 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 20:35:39.0101 5132 exfat - ok 20:35:39.0117 5132 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 20:35:39.0133 5132 fastfat - ok 20:35:39.0195 5132 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 20:35:39.0226 5132 Fax - ok 20:35:39.0242 5132 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys 20:35:39.0242 5132 fdc - ok 20:35:39.0257 5132 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 20:35:39.0273 5132 fdPHost - ok 20:35:39.0273 5132 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 20:35:39.0273 5132 FDResPub - ok 20:35:39.0304 5132 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 20:35:39.0304 5132 FileInfo - ok 20:35:39.0320 5132 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 20:35:39.0320 5132 Filetrace - ok 20:35:39.0335 5132 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 20:35:39.0335 5132 flpydisk - ok 20:35:39.0351 5132 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 20:35:39.0367 5132 FltMgr - ok 20:35:39.0413 5132 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll 20:35:39.0445 5132 FontCache - ok 20:35:39.0491 5132 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 20:35:39.0507 5132 FontCache3.0.0.0 - ok 20:35:39.0523 5132 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 20:35:39.0523 5132 FsDepends - ok 20:35:39.0554 5132 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 20:35:39.0554 5132 Fs_Rec - ok 20:35:39.0585 5132 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 20:35:39.0601 5132 fvevol - ok 20:35:39.0635 5132 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 20:35:39.0635 5132 gagp30kx - ok 20:35:39.0682 5132 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 20:35:39.0697 5132 GEARAspiWDM - ok 20:35:39.0744 5132 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 20:35:39.0775 5132 gpsvc - ok 20:35:39.0791 5132 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 20:35:39.0806 5132 hcw85cir - ok 20:35:39.0853 5132 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 20:35:39.0884 5132 HdAudAddService - ok 20:35:39.0931 5132 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 20:35:39.0947 5132 HDAudBus - ok 20:35:39.0962 5132 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 20:35:39.0962 5132 HidBatt - ok 20:35:39.0978 5132 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 20:35:39.0978 5132 HidBth - ok 20:35:40.0009 5132 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 20:35:40.0009 5132 HidIr - ok 20:35:40.0040 5132 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll 20:35:40.0040 5132 hidserv - ok 20:35:40.0087 5132 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 20:35:40.0087 5132 HidUsb - ok 20:35:40.0134 5132 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 20:35:40.0134 5132 hkmsvc - ok 20:35:40.0181 5132 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 20:35:40.0181 5132 HomeGroupListener - ok 20:35:40.0212 5132 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 20:35:40.0228 5132 HomeGroupProvider - ok 20:35:40.0259 5132 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 20:35:40.0259 5132 HpSAMD - ok 20:35:40.0321 5132 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 20:35:40.0368 5132 HTTP - ok 20:35:40.0399 5132 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 20:35:40.0415 5132 hwpolicy - ok 20:35:40.0446 5132 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 20:35:40.0446 5132 i8042prt - ok 20:35:40.0477 5132 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 20:35:40.0508 5132 iaStorV - ok 20:35:40.0555 5132 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 20:35:40.0586 5132 idsvc - ok 20:35:40.0680 5132 [ A48928D4CCA6F8B731989DB08CF2C0AB ] IDSVia64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20120929.001\IDSvia64.sys 20:35:40.0696 5132 IDSVia64 - ok 20:35:40.0727 5132 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 20:35:40.0727 5132 iirsp - ok 20:35:40.0789 5132 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 20:35:40.0805 5132 IKEEXT - ok 20:35:40.0914 5132 [ 8FED6428FDE53D7F4C105095F22524BE ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys 20:35:40.0976 5132 IntcAzAudAddService - ok 20:35:40.0992 5132 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 20:35:40.0992 5132 intelide - ok 20:35:41.0008 5132 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 20:35:41.0008 5132 intelppm - ok 20:35:41.0039 5132 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 20:35:41.0054 5132 IPBusEnum - ok 20:35:41.0101 5132 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 20:35:41.0117 5132 IpFilterDriver - ok 20:35:41.0148 5132 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 20:35:41.0164 5132 iphlpsvc - ok 20:35:41.0195 5132 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 20:35:41.0210 5132 IPMIDRV - ok 20:35:41.0226 5132 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 20:35:41.0226 5132 IPNAT - ok 20:35:41.0382 5132 [ 6E50CFA46527B39015B750AAD161C5CC ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 20:35:41.0398 5132 iPod Service - ok 20:35:41.0413 5132 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 20:35:41.0429 5132 IRENUM - ok 20:35:41.0444 5132 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 20:35:41.0444 5132 isapnp - ok 20:35:41.0476 5132 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 20:35:41.0476 5132 iScsiPrt - ok 20:35:41.0507 5132 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys 20:35:41.0507 5132 kbdclass - ok 20:35:41.0538 5132 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys 20:35:41.0538 5132 kbdhid - ok 20:35:41.0554 5132 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 20:35:41.0569 5132 KeyIso - ok 20:35:41.0600 5132 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 20:35:41.0600 5132 KSecDD - ok 20:35:41.0647 5132 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 20:35:41.0647 5132 KSecPkg - ok 20:35:41.0678 5132 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 20:35:41.0694 5132 ksthunk - ok 20:35:41.0710 5132 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 20:35:41.0772 5132 KtmRm - ok 20:35:41.0819 5132 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll 20:35:41.0834 5132 LanmanServer - ok 20:35:41.0854 5132 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 20:35:41.0854 5132 LanmanWorkstation - ok 20:35:41.0901 5132 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 20:35:41.0901 5132 lltdio - ok 20:35:41.0932 5132 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 20:35:41.0948 5132 lltdsvc - ok 20:35:41.0963 5132 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 20:35:41.0979 5132 lmhosts - ok 20:35:42.0010 5132 [ 7F32D4C47A50E7223491E8FB9359907D ] LMS C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe 20:35:42.0010 5132 LMS - ok 20:35:42.0041 5132 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 20:35:42.0041 5132 LSI_FC - ok 20:35:42.0088 5132 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 20:35:42.0088 5132 LSI_SAS - ok 20:35:42.0104 5132 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 20:35:42.0104 5132 LSI_SAS2 - ok 20:35:42.0135 5132 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 20:35:42.0135 5132 LSI_SCSI - ok 20:35:42.0182 5132 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 20:35:42.0182 5132 luafv - ok 20:35:42.0228 5132 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 20:35:42.0260 5132 Mcx2Svc - ok 20:35:42.0275 5132 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 20:35:42.0275 5132 megasas - ok 20:35:42.0291 5132 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 20:35:42.0306 5132 MegaSR - ok 20:35:42.0322 5132 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys 20:35:42.0338 5132 MEIx64 - ok 20:35:42.0369 5132 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 20:35:42.0369 5132 MMCSS - ok 20:35:42.0384 5132 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 20:35:42.0384 5132 Modem - ok 20:35:42.0416 5132 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 20:35:42.0416 5132 monitor - ok 20:35:42.0478 5132 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 20:35:42.0478 5132 mouclass - ok 20:35:42.0509 5132 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 20:35:42.0525 5132 mouhid - ok 20:35:42.0556 5132 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 20:35:42.0572 5132 mountmgr - ok 20:35:42.0665 5132 [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 20:35:42.0681 5132 MozillaMaintenance - ok 20:35:42.0696 5132 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 20:35:42.0712 5132 mpio - ok 20:35:42.0728 5132 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 20:35:42.0728 5132 mpsdrv - ok 20:35:42.0790 5132 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll 20:35:42.0806 5132 MpsSvc - ok 20:35:42.0852 5132 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 20:35:42.0868 5132 MRxDAV - ok 20:35:42.0899 5132 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 20:35:42.0915 5132 mrxsmb - ok 20:35:42.0946 5132 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 20:35:42.0962 5132 mrxsmb10 - ok 20:35:42.0993 5132 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 20:35:42.0993 5132 mrxsmb20 - ok 20:35:43.0024 5132 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 20:35:43.0024 5132 msahci - ok 20:35:43.0055 5132 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 20:35:43.0071 5132 msdsm - ok 20:35:43.0086 5132 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 20:35:43.0102 5132 MSDTC - ok 20:35:43.0133 5132 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 20:35:43.0133 5132 Msfs - ok 20:35:43.0149 5132 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 20:35:43.0149 5132 mshidkmdf - ok 20:35:43.0180 5132 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 20:35:43.0180 5132 msisadrv - ok 20:35:43.0211 5132 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 20:35:43.0227 5132 MSiSCSI - ok 20:35:43.0227 5132 msiserver - ok 20:35:43.0258 5132 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 20:35:43.0258 5132 MSKSSRV - ok 20:35:43.0274 5132 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 20:35:43.0289 5132 MSPCLOCK - ok 20:35:43.0305 5132 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 20:35:43.0305 5132 MSPQM - ok 20:35:43.0336 5132 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 20:35:43.0352 5132 MsRPC - ok 20:35:43.0383 5132 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 20:35:43.0383 5132 mssmbios - ok 20:35:43.0398 5132 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 20:35:43.0414 5132 MSTEE - ok 20:35:43.0414 5132 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 20:35:43.0430 5132 MTConfig - ok 20:35:43.0430 5132 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 20:35:43.0445 5132 Mup - ok 20:35:43.0492 5132 [ 6ED8935257672F4CD04A88A0F3DE093D ] MyWiFiDHCPDNS C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe 20:35:43.0508 5132 MyWiFiDHCPDNS - ok 20:35:43.0570 5132 [ B4187346F54E362DAFFE647B25A58D50 ] N360 C:\Program Files (x86)\Norton Security Suite\Engine\4.4.0.12\ccSvcHst.exe 20:35:43.0570 5132 N360 - ok 20:35:43.0601 5132 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 20:35:43.0617 5132 napagent - ok 20:35:43.0648 5132 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 20:35:43.0664 5132 NativeWifiP - ok 20:35:43.0757 5132 [ C58D8A669D6551F616D90244BD2C2D4F ] NAVENG C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20121001.020\ENG64.SYS 20:35:43.0757 5132 NAVENG - ok 20:35:43.0835 5132 [ A3DBDB412ADFA5882DD6843B11FE0828 ] NAVEX15 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20121001.020\EX64.SYS 20:35:43.0913 5132 NAVEX15 - ok 20:35:44.0022 5132 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys 20:35:44.0058 5132 NDIS - ok 20:35:44.0073 5132 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 20:35:44.0089 5132 NdisCap - ok 20:35:44.0104 5132 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 20:35:44.0104 5132 NdisTapi - ok 20:35:44.0151 5132 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 20:35:44.0151 5132 Ndisuio - ok 20:35:44.0182 5132 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 20:35:44.0198 5132 NdisWan - ok 20:35:44.0245 5132 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 20:35:44.0245 5132 NDProxy - ok 20:35:44.0260 5132 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 20:35:44.0260 5132 NetBIOS - ok 20:35:44.0307 5132 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 20:35:44.0323 5132 NetBT - ok 20:35:44.0338 5132 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 20:35:44.0338 5132 Netlogon - ok 20:35:44.0370 5132 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 20:35:44.0385 5132 Netman - ok 20:35:44.0416 5132 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 20:35:44.0448 5132 NetMsmqActivator - ok 20:35:44.0463 5132 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 20:35:44.0463 5132 NetPipeActivator - ok 20:35:44.0494 5132 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 20:35:44.0510 5132 netprofm - ok 20:35:44.0526 5132 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 20:35:44.0526 5132 NetTcpActivator - ok 20:35:44.0526 5132 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 20:35:44.0541 5132 NetTcpPortSharing - ok 20:35:44.0713 5132 [ 5D262402B0634C998F8CBCEAD7DD8676 ] NETwNs64 C:\Windows\system32\DRIVERS\NETwNs64.sys 20:35:44.0853 5132 NETwNs64 - ok 20:35:44.0884 5132 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 20:35:44.0884 5132 nfrd960 - ok 20:35:44.0931 5132 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll 20:35:44.0947 5132 NlaSvc - ok 20:35:44.0962 5132 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 20:35:44.0962 5132 Npfs - ok 20:35:44.0978 5132 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 20:35:44.0978 5132 nsi - ok 20:35:44.0994 5132 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 20:35:44.0994 5132 nsiproxy - ok 20:35:45.0056 5132 [ A2F74975097F52A00745F9637451FDD8 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 20:35:45.0103 5132 Ntfs - ok 20:35:45.0118 5132 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 20:35:45.0118 5132 Null - ok 20:35:45.0150 5132 [ D584ABB6A308933A5F72B46C9E5A783F ] nusb3hub C:\Windows\system32\DRIVERS\nusb3hub.sys 20:35:45.0165 5132 nusb3hub - ok 20:35:45.0196 5132 [ 345B9C04E2036DA4346E3249A5BDFD06 ] nusb3xhc C:\Windows\system32\DRIVERS\nusb3xhc.sys 20:35:45.0212 5132 nusb3xhc - ok 20:35:45.0243 5132 [ 8D4AAC74B571FC356560E5B308955E93 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys 20:35:45.0274 5132 NVHDA - ok 20:35:45.0508 5132 [ 9C1996DD3C0469BC8933321F15709F5A ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 20:35:45.0742 5132 nvlddmkm - ok 20:35:45.0774 5132 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 20:35:45.0789 5132 nvraid - ok 20:35:45.0820 5132 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 20:35:45.0836 5132 nvstor - ok 20:35:45.0898 5132 [ 3A69345B9D32131745C4665A3AB4B889 ] NvStUSB C:\Windows\system32\DRIVERS\nvstusb.sys 20:35:45.0914 5132 NvStUSB - ok 20:35:45.0961 5132 [ 34E5498528BB3D5A951F889F8756AD26 ] NVSvc C:\Windows\system32\nvvsvc.exe 20:35:45.0976 5132 NVSvc - ok 20:35:46.0101 5132 [ CD0BFAA6872CFE38C908D313AE17C350 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 20:35:46.0164 5132 nvUpdatusService - ok 20:35:46.0195 5132 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 20:35:46.0195 5132 nv_agp - ok 20:35:46.0226 5132 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 20:35:46.0226 5132 ohci1394 - ok 20:35:46.0277 5132 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 20:35:46.0292 5132 ose - ok 20:35:46.0433 5132 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 20:35:46.0558 5132 osppsvc - ok 20:35:46.0589 5132 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 20:35:46.0589 5132 p2pimsvc - ok 20:35:46.0604 5132 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 20:35:46.0636 5132 p2psvc - ok 20:35:46.0651 5132 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys 20:35:46.0667 5132 Parport - ok 20:35:46.0698 5132 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 20:35:46.0714 5132 partmgr - ok 20:35:46.0729 5132 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 20:35:46.0745 5132 PcaSvc - ok 20:35:46.0760 5132 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 20:35:46.0760 5132 pci - ok 20:35:46.0807 5132 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 20:35:46.0807 5132 pciide - ok 20:35:46.0823 5132 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 20:35:46.0838 5132 pcmcia - ok 20:35:46.0854 5132 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 20:35:46.0854 5132 pcw - ok 20:35:46.0885 5132 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 20:35:46.0916 5132 PEAUTH - ok 20:35:47.0010 5132 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 20:35:47.0010 5132 PerfHost - ok 20:35:47.0088 5132 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 20:35:47.0135 5132 pla - ok 20:35:47.0166 5132 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 20:35:47.0182 5132 PlugPlay - ok 20:35:47.0197 5132 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 20:35:47.0197 5132 PNRPAutoReg - ok 20:35:47.0213 5132 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 20:35:47.0228 5132 PNRPsvc - ok 20:35:47.0244 5132 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 20:35:47.0260 5132 PolicyAgent - ok 20:35:47.0291 5132 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 20:35:47.0306 5132 Power - ok 20:35:47.0353 5132 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 20:35:47.0369 5132 PptpMiniport - ok 20:35:47.0384 5132 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys 20:35:47.0400 5132 Processor - ok 20:35:47.0431 5132 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 20:35:47.0447 5132 ProfSvc - ok 20:35:47.0462 5132 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 20:35:47.0462 5132 ProtectedStorage - ok 20:35:47.0494 5132 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 20:35:47.0494 5132 Psched - ok 20:35:47.0525 5132 [ 87B04878A6D59D6C79251DC960C674C1 ] PxHlpa64 C:\Windows\system32\Drivers\PxHlpa64.sys 20:35:47.0540 5132 PxHlpa64 - ok 20:35:47.0572 5132 [ 0928BD20273625622722FE1DE5BBDE57 ] qicflt C:\Windows\system32\DRIVERS\qicflt.sys 20:35:47.0572 5132 qicflt - ok 20:35:47.0650 5132 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 20:35:47.0728 5132 ql2300 - ok 20:35:47.0743 5132 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 20:35:47.0759 5132 ql40xx - ok 20:35:47.0790 5132 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 20:35:47.0806 5132 QWAVE - ok 20:35:47.0837 5132 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 20:35:47.0837 5132 QWAVEdrv - ok 20:35:47.0852 5132 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 20:35:47.0852 5132 RasAcd - ok 20:35:47.0884 5132 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 20:35:47.0884 5132 RasAgileVpn - ok 20:35:47.0915 5132 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 20:35:47.0915 5132 RasAuto - ok 20:35:47.0946 5132 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 20:35:47.0962 5132 Rasl2tp - ok 20:35:48.0008 5132 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 20:35:48.0024 5132 RasMan - ok 20:35:48.0040 5132 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 20:35:48.0055 5132 RasPppoe - ok 20:35:48.0071 5132 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 20:35:48.0086 5132 RasSstp - ok 20:35:48.0133 5132 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 20:35:48.0149 5132 rdbss - ok 20:35:48.0164 5132 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 20:35:48.0180 5132 rdpbus - ok 20:35:48.0196 5132 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 20:35:48.0196 5132 RDPCDD - ok 20:35:48.0227 5132 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 20:35:48.0227 5132 RDPENCDD - ok 20:35:48.0242 5132 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 20:35:48.0242 5132 RDPREFMP - ok 20:35:48.0274 5132 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 20:35:48.0274 5132 RDPWD - ok 20:35:48.0320 5132 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 20:35:48.0320 5132 rdyboost - ok 20:35:48.0383 5132 [ 189C5A8D2098E0AA14FD157A954B34FC ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe 20:35:48.0414 5132 RegSrvc - ok 20:35:48.0430 5132 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 20:35:48.0448 5132 RemoteAccess - ok 20:35:48.0466 5132 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 20:35:48.0481 5132 RemoteRegistry - ok 20:35:48.0575 5132 [ BDDC447AB46625A54619808575D5CB46 ] RoxMediaDB12OEM C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe 20:35:48.0606 5132 RoxMediaDB12OEM - ok 20:35:48.0637 5132 [ CE203243ADF512540249DF9C264F12DD ] RoxWatch12 C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe 20:35:48.0637 5132 RoxWatch12 - ok 20:35:48.0653 5132 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 20:35:48.0653 5132 RpcEptMapper - ok 20:35:48.0684 5132 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 20:35:48.0700 5132 RpcLocator - ok 20:35:48.0747 5132 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll 20:35:48.0762 5132 RpcSs - ok 20:35:48.0793 5132 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 20:35:48.0809 5132 rspndr - ok 20:35:48.0856 5132 [ EE082E06A82FF630351D1E0EBBD3D8D0 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys 20:35:48.0887 5132 RTL8167 - ok 20:35:48.0903 5132 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 20:35:48.0903 5132 SamSs - ok 20:35:48.0934 5132 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 20:35:48.0934 5132 sbp2port - ok 20:35:48.0949 5132 SBRE - ok 20:35:48.0965 5132 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 20:35:48.0981 5132 SCardSvr - ok 20:35:48.0996 5132 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 20:35:49.0012 5132 scfilter - ok 20:35:49.0074 5132 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 20:35:49.0121 5132 Schedule - ok 20:35:49.0152 5132 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 20:35:49.0152 5132 SCPolicySvc - ok 20:35:49.0183 5132 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 20:35:49.0215 5132 SDRSVC - ok 20:35:49.0246 5132 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 20:35:49.0246 5132 secdrv - ok 20:35:49.0277 5132 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 20:35:49.0277 5132 seclogon - ok 20:35:49.0308 5132 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll 20:35:49.0308 5132 SENS - ok 20:35:49.0339 5132 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 20:35:49.0339 5132 SensrSvc - ok 20:35:49.0355 5132 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 20:35:49.0355 5132 Serenum - ok 20:35:49.0386 5132 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys 20:35:49.0386 5132 Serial - ok 20:35:49.0433 5132 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 20:35:49.0449 5132 sermouse - ok 20:35:49.0480 5132 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 20:35:49.0495 5132 SessionEnv - ok 20:35:49.0511 5132 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 20:35:49.0511 5132 sffdisk - ok 20:35:49.0527 5132 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 20:35:49.0527 5132 sffp_mmc - ok 20:35:49.0542 5132 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 20:35:49.0542 5132 sffp_sd - ok 20:35:49.0558 5132 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 20:35:49.0573 5132 sfloppy - ok 20:35:49.0636 5132 [ C6CC9297BD53E5229653303E556AA539 ] Sftfs C:\Windows\system32\DRIVERS\Sftfslh.sys 20:35:49.0651 5132 Sftfs - ok 20:35:49.0714 5132 [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe 20:35:49.0729 5132 sftlist - ok 20:35:49.0761 5132 [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay C:\Windows\system32\DRIVERS\Sftplaylh.sys 20:35:49.0776 5132 Sftplay - ok 20:35:49.0792 5132 [ 617E29A0B0A2807466560D4C4E338D3E ] Sftredir C:\Windows\system32\DRIVERS\Sftredirlh.sys 20:35:49.0792 5132 Sftredir - ok 20:35:49.0854 5132 [ E1974A92AC0914A3859359A0A8C82C68 ] SftService C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE 20:35:49.0870 5132 SftService - ok 20:35:49.0885 5132 [ 8F571F016FA1976F445147E9E6C8AE9B ] Sftvol C:\Windows\system32\DRIVERS\Sftvollh.sys 20:35:49.0901 5132 Sftvol - ok 20:35:49.0932 5132 [ C3CDDD18F43D44AB713CF8C4916F7696 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe 20:35:49.0932 5132 sftvsa - ok 20:35:49.0979 5132 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll 20:35:50.0026 5132 SharedAccess - ok 20:35:50.0057 5132 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 20:35:50.0073 5132 ShellHWDetection - ok 20:35:50.0104 5132 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 20:35:50.0104 5132 SiSRaid2 - ok 20:35:50.0135 5132 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 20:35:50.0135 5132 SiSRaid4 - ok 20:35:50.0151 5132 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 20:35:50.0151 5132 Smb - ok 20:35:50.0182 5132 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 20:35:50.0197 5132 SNMPTRAP - ok 20:35:50.0213 5132 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 20:35:50.0213 5132 spldr - ok 20:35:50.0260 5132 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 20:35:50.0260 5132 Spooler - ok 20:35:50.0369 5132 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 20:35:50.0447 5132 sppsvc - ok 20:35:50.0463 5132 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 20:35:50.0463 5132 sppuinotify - ok 20:35:50.0556 5132 [ 96BABC4906ECDB1C69D1176F8647AD8E ] SRTSP C:\Windows\System32\Drivers\N360x64\0404000.00C\SRTSP64.SYS 20:35:50.0587 5132 SRTSP - ok 20:35:50.0619 5132 [ C7F491A290E0E4222F5CDCD50EEB8167 ] SRTSPX C:\Windows\system32\drivers\N360x64\0404000.00C\SRTSPX64.SYS 20:35:50.0619 5132 SRTSPX - ok 20:35:50.0666 5132 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 20:35:50.0698 5132 srv - ok 20:35:50.0729 5132 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 20:35:50.0729 5132 srv2 - ok 20:35:50.0744 5132 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 20:35:50.0760 5132 srvnet - ok 20:35:50.0776 5132 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 20:35:50.0791 5132 SSDPSRV - ok 20:35:50.0807 5132 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 20:35:50.0822 5132 SstpSvc - ok 20:35:50.0854 5132 [ 92E7F6666633D2DD91D527503DAA7BE0 ] stdcfltn C:\Windows\system32\DRIVERS\stdcfltn.sys 20:35:50.0854 5132 stdcfltn - ok 20:35:50.0932 5132 [ 8544A200C40447E465F06E58687428BB ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 20:35:50.0947 5132 Stereo Service - ok 20:35:50.0978 5132 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 20:35:50.0994 5132 stexstor - ok 20:35:51.0041 5132 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 20:35:51.0072 5132 stisvc - ok 20:35:51.0103 5132 [ 9E182DD94496550A22A392CC1A8E0F52 ] stllssvr C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe 20:35:51.0134 5132 stllssvr - ok 20:35:51.0166 5132 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys 20:35:51.0166 5132 swenum - ok 20:35:51.0197 5132 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 20:35:51.0197 5132 swprv - ok 20:35:51.0244 5132 [ 659B227A72B76115975A6A9491B2FE1F ] SymDS C:\Windows\system32\drivers\N360x64\0404000.00C\SYMDS64.SYS 20:35:51.0244 5132 SymDS - ok 20:35:51.0259 5132 [ 9F5783A4A03D0091CDBDAA858B566926 ] SymEFA C:\Windows\system32\drivers\N360x64\0404000.00C\SYMEFA64.SYS 20:35:51.0259 5132 SymEFA - ok 20:35:51.0275 5132 [ 3F9D5FE52585E2653E59FDBFDF09A94C ] SymEvent C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 20:35:51.0275 5132 SymEvent - ok 20:35:51.0290 5132 [ F57588546E738DB1583981D8F44E9BC2 ] SymIRON C:\Windows\system32\drivers\N360x64\0404000.00C\Ironx64.SYS 20:35:51.0306 5132 SymIRON - ok 20:35:51.0337 5132 [ 3ADFB72F0797AE3832509FE030755E21 ] SYMTDIv C:\Windows\System32\Drivers\N360x64\0404000.00C\SYMTDIV.SYS 20:35:51.0353 5132 SYMTDIv - ok 20:35:51.0400 5132 [ 5E3B232A614339399ACC71FA3AAAAA6B ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys 20:35:51.0462 5132 SynTP - ok 20:35:51.0524 5132 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 20:35:51.0587 5132 SysMain - ok 20:35:51.0602 5132 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 20:35:51.0618 5132 TabletInputService - ok 20:35:51.0649 5132 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 20:35:51.0680 5132 TapiSrv - ok 20:35:51.0712 5132 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 20:35:51.0727 5132 TBS - ok 20:35:51.0805 5132 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] Tcpip C:\Windows\system32\drivers\tcpip.sys 20:35:51.0868 5132 Tcpip - ok 20:35:51.0930 5132 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 20:35:51.0946 5132 TCPIP6 - ok 20:35:51.0977 5132 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 20:35:51.0977 5132 tcpipreg - ok 20:35:52.0008 5132 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 20:35:52.0008 5132 TDPIPE - ok 20:35:52.0039 5132 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 20:35:52.0070 5132 TDTCP - ok 20:35:52.0102 5132 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 20:35:52.0102 5132 tdx - ok 20:35:52.0148 5132 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys 20:35:52.0148 5132 TermDD - ok 20:35:52.0180 5132 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 20:35:52.0211 5132 TermService - ok 20:35:52.0226 5132 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 20:35:52.0226 5132 Themes - ok 20:35:52.0258 5132 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 20:35:52.0258 5132 THREADORDER - ok 20:35:52.0289 5132 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 20:35:52.0289 5132 TrkWks - ok 20:35:52.0336 5132 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 20:35:52.0351 5132 TrustedInstaller - ok 20:35:52.0382 5132 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 20:35:52.0398 5132 tssecsrv - ok 20:35:52.0429 5132 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 20:35:52.0445 5132 TsUsbFlt - ok 20:35:52.0492 5132 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 20:35:52.0492 5132 tunnel - ok 20:35:52.0538 5132 [ FD24F98D2898BE093FE926604BE7DB99 ] TurboB C:\Windows\system32\DRIVERS\TurboB.sys 20:35:52.0538 5132 TurboB - ok 20:35:52.0585 5132 [ 600B406A04D90F577FEA8A88D7379F08 ] TurboBoost C:\Program Files\Intel\TurboBoost\TurboBoost.exe 20:35:52.0648 5132 TurboBoost - ok 20:35:52.0679 5132 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 20:35:52.0679 5132 uagp35 - ok 20:35:52.0726 5132 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 20:35:52.0757 5132 udfs - ok 20:35:52.0788 5132 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 20:35:52.0804 5132 UI0Detect - ok 20:35:52.0835 5132 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 20:35:52.0835 5132 uliagpkx - ok 20:35:52.0872 5132 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 20:35:52.0888 5132 umbus - ok 20:35:52.0903 5132 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 20:35:52.0903 5132 UmPass - ok 20:35:53.0012 5132 [ 2C16648A12999AE69A9EBF41974B0BA2 ] UNS C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe 20:35:53.0090 5132 UNS - ok 20:35:53.0106 5132 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 20:35:53.0106 5132 upnphost - ok 20:35:53.0153 5132 [ AF1B9474D67897D0C2CFF58E0ACEACCC ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys 20:35:53.0153 5132 USBAAPL64 - ok 20:35:53.0153 5132 usbbus - ok 20:35:53.0200 5132 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 20:35:53.0215 5132 usbccgp - ok 20:35:53.0246 5132 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 20:35:53.0246 5132 usbcir - ok 20:35:53.0246 5132 UsbDiag - ok 20:35:53.0309 5132 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys 20:35:53.0309 5132 usbehci - ok 20:35:53.0356 5132 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 20:35:53.0371 5132 usbhub - ok 20:35:53.0387 5132 USBModem - ok 20:35:53.0418 5132 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys 20:35:53.0418 5132 usbohci - ok 20:35:53.0449 5132 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 20:35:53.0449 5132 usbprint - ok 20:35:53.0480 5132 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 20:35:53.0480 5132 USBSTOR - ok 20:35:53.0512 5132 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 20:35:53.0512 5132 usbuhci - ok 20:35:53.0543 5132 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys 20:35:53.0543 5132 usbvideo - ok 20:35:53.0574 5132 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 20:35:53.0574 5132 UxSms - ok 20:35:53.0590 5132 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 20:35:53.0605 5132 VaultSvc - ok 20:35:53.0621 5132 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 20:35:53.0652 5132 vdrvroot - ok 20:35:53.0699 5132 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 20:35:53.0714 5132 vds - ok 20:35:53.0730 5132 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 20:35:53.0746 5132 vga - ok 20:35:53.0761 5132 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 20:35:53.0761 5132 VgaSave - ok 20:35:53.0792 5132 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 20:35:53.0792 5132 vhdmp - ok 20:35:53.0808 5132 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 20:35:53.0808 5132 viaide - ok 20:35:53.0824 5132 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 20:35:53.0824 5132 volmgr - ok 20:35:53.0870 5132 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 20:35:53.0886 5132 volmgrx - ok 20:35:53.0902 5132 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 20:35:53.0917 5132 volsnap - ok 20:35:53.0948 5132 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 20:35:53.0948 5132 vsmraid - ok 20:35:54.0011 5132 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 20:35:54.0073 5132 VSS - ok 20:35:54.0089 5132 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 20:35:54.0089 5132 vwifibus - ok 20:35:54.0104 5132 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 20:35:54.0104 5132 vwififlt - ok 20:35:54.0136 5132 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys 20:35:54.0136 5132 vwifimp - ok 20:35:54.0182 5132 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 20:35:54.0198 5132 W32Time - ok 20:35:54.0214 5132 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 20:35:54.0214 5132 WacomPen - ok 20:35:54.0260 5132 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 20:35:54.0260 5132 WANARP - ok 20:35:54.0276 5132 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 20:35:54.0292 5132 Wanarpv6 - ok 20:35:54.0354 5132 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 20:35:54.0432 5132 WatAdminSvc - ok 20:35:54.0510 5132 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 20:35:54.0572 5132 wbengine - ok 20:35:54.0604 5132 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 20:35:54.0604 5132 WbioSrvc - ok 20:35:54.0650 5132 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 20:35:54.0666 5132 wcncsvc - ok 20:35:54.0682 5132 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 20:35:54.0697 5132 WcsPlugInService - ok 20:35:54.0713 5132 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys 20:35:54.0728 5132 Wd - ok 20:35:54.0744 5132 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 20:35:54.0791 5132 Wdf01000 - ok 20:35:54.0806 5132 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 20:35:54.0806 5132 WdiServiceHost - ok 20:35:54.0806 5132 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 20:35:54.0806 5132 WdiSystemHost - ok 20:35:54.0853 5132 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 20:35:54.0869 5132 WebClient - ok 20:35:54.0884 5132 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 20:35:54.0900 5132 Wecsvc - ok 20:35:54.0916 5132 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 20:35:54.0916 5132 wercplsupport - ok 20:35:54.0947 5132 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 20:35:54.0947 5132 WerSvc - ok 20:35:54.0978 5132 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 20:35:54.0978 5132 WfpLwf - ok 20:35:55.0040 5132 [ 49F06C7D5517DE53D848F38B9AE86A7C ] WiMAXAppSrv C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe 20:35:55.0059 5132 WiMAXAppSrv - ok 20:35:55.0107 5132 [ B14EF15BD757FA488F9C970EEE9C0D35 ] WimFltr C:\Windows\system32\DRIVERS\wimfltr.sys 20:35:55.0138 5132 WimFltr - ok 20:35:55.0169 5132 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 20:35:55.0169 5132 WIMMount - ok 20:35:55.0185 5132 WinDefend - ok 20:35:55.0185 5132 WinHttpAutoProxySvc - ok 20:35:55.0232 5132 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 20:35:55.0247 5132 Winmgmt - ok 20:35:55.0325 5132 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 20:35:55.0403 5132 WinRM - ok 20:35:55.0466 5132 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 20:35:55.0481 5132 WinUsb - ok 20:35:55.0528 5132 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 20:35:55.0559 5132 Wlansvc - ok 20:35:55.0590 5132 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 20:35:55.0606 5132 wlcrasvc - ok 20:35:55.0700 5132 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 20:35:55.0778 5132 wlidsvc - ok 20:35:55.0824 5132 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 20:35:55.0824 5132 WmiAcpi - ok 20:35:55.0856 5132 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 20:35:55.0871 5132 wmiApSrv - ok 20:35:55.0887 5132 WMPNetworkSvc - ok 20:35:55.0918 5132 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 20:35:55.0918 5132 WPCSvc - ok 20:35:55.0949 5132 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 20:35:55.0965 5132 WPDBusEnum - ok 20:35:55.0980 5132 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 20:35:55.0980 5132 ws2ifsl - ok 20:35:56.0012 5132 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll 20:35:56.0012 5132 wscsvc - ok 20:35:56.0043 5132 [ 8D918B1DB190A4D9B1753A66FA8C96E8 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys 20:35:56.0043 5132 WSDPrintDevice - ok 20:35:56.0058 5132 WSearch - ok 20:35:56.0168 5132 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 20:35:56.0246 5132 wuauserv - ok 20:35:56.0246 5132 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 20:35:56.0261 5132 WudfPf - ok 20:35:56.0308 5132 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 20:35:56.0324 5132 WUDFRd - ok 20:35:56.0355 5132 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 20:35:56.0355 5132 wudfsvc - ok 20:35:56.0386 5132 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll 20:35:56.0386 5132 WwanSvc - ok 20:35:56.0448 5132 ================ Scan global =============================== 20:35:56.0464 5132 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 20:35:56.0511 5132 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll 20:35:56.0526 5132 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll 20:35:56.0542 5132 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 20:35:56.0573 5132 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 20:35:56.0589 5132 [Global] - ok 20:35:56.0589 5132 ================ Scan MBR ================================== 20:35:56.0604 5132 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0 20:35:56.0948 5132 \Device\Harddisk0\DR0 - ok 20:35:56.0948 5132 ================ Scan VBR ================================== 20:35:56.0948 5132 [ 70DAAA6EEBFC8694A5EB9189555CF4FA ] \Device\Harddisk0\DR0\Partition1 20:35:56.0948 5132 \Device\Harddisk0\DR0\Partition1 - ok 20:35:56.0979 5132 [ 683C52AD82086AEDC39384B3D0160F54 ] \Device\Harddisk0\DR0\Partition2 20:35:56.0979 5132 \Device\Harddisk0\DR0\Partition2 - ok 20:35:56.0979 5132 ============================================================ 20:35:56.0979 5132 Scan finished 20:35:56.0979 5132 ============================================================ 20:35:56.0979 1612 Detected object count: 0 20:35:56.0979 1612 Actual detected object count: 0 20:36:10.0227 4852 ============================================================ 20:36:10.0227 4852 Scan started 20:36:10.0227 4852 Mode: Manual; TDLFS; 20:36:10.0227 4852 ============================================================ 20:36:10.0591 4852 ================ Scan system memory ======================== 20:36:10.0591 4852 System memory - ok 20:36:10.0591 4852 ================ Scan services ============================= 20:36:10.0731 4852 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 20:36:10.0731 4852 1394ohci - ok 20:36:10.0762 4852 [ E0065CBF1A25C015C218457D2CD522B9 ] Acceler C:\Windows\system32\DRIVERS\Accelern.sys 20:36:10.0762 4852 Acceler - ok 20:36:10.0840 4852 [ ADC420616C501B45D26C0FD3EF1E54E4 ] ACDaemon C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe 20:36:10.0840 4852 ACDaemon - ok 20:36:10.0856 4852 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 20:36:10.0871 4852 ACPI - ok 20:36:10.0887 4852 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 20:36:10.0887 4852 AcpiPmi - ok 20:36:10.0934 4852 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 20:36:10.0934 4852 adp94xx - ok 20:36:10.0965 4852 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 20:36:10.0965 4852 adpahci - ok 20:36:10.0981 4852 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 20:36:10.0981 4852 adpu320 - ok 20:36:10.0996 4852 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 20:36:11.0012 4852 AeLookupSvc - ok 20:36:11.0043 4852 [ D1E343BC00136CE03C4D403194D06A80 ] AERTFilters C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe 20:36:11.0059 4852 AERTFilters - ok 20:36:11.0105 4852 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 20:36:11.0105 4852 AFD - ok 20:36:11.0121 4852 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 20:36:11.0121 4852 agp440 - ok 20:36:11.0168 4852 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 20:36:11.0168 4852 ALG - ok 20:36:11.0183 4852 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 20:36:11.0183 4852 aliide - ok 20:36:11.0199 4852 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 20:36:11.0199 4852 amdide - ok 20:36:11.0215 4852 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 20:36:11.0215 4852 AmdK8 - ok 20:36:11.0230 4852 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 20:36:11.0246 4852 AmdPPM - ok 20:36:11.0261 4852 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 20:36:11.0261 4852 amdsata - ok 20:36:11.0293 4852 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 20:36:11.0293 4852 amdsbs - ok 20:36:11.0308 4852 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 20:36:11.0308 4852 amdxata - ok 20:36:11.0339 4852 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 20:36:11.0339 4852 AppID - ok 20:36:11.0355 4852 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 20:36:11.0355 4852 AppIDSvc - ok 20:36:11.0402 4852 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll 20:36:11.0402 4852 Appinfo - ok 20:36:11.0480 4852 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 20:36:11.0480 4852 Apple Mobile Device - ok 20:36:11.0495 4852 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys 20:36:11.0495 4852 arc - ok 20:36:11.0511 4852 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 20:36:11.0511 4852 arcsas - ok 20:36:11.0620 4852 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 20:36:11.0620 4852 aspnet_state - ok 20:36:11.0636 4852 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 20:36:11.0636 4852 AsyncMac - ok 20:36:11.0667 4852 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 20:36:11.0667 4852 atapi - ok 20:36:11.0714 4852 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 20:36:11.0729 4852 AudioEndpointBuilder - ok 20:36:11.0761 4852 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 20:36:11.0776 4852 AudioSrv - ok 20:36:11.0792 4852 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 20:36:11.0792 4852 AxInstSV - ok 20:36:11.0823 4852 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys 20:36:11.0823 4852 b06bdrv - ok 20:36:11.0854 4852 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 20:36:11.0854 4852 b57nd60a - ok 20:36:11.0885 4852 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 20:36:11.0885 4852 BDESVC - ok 20:36:11.0901 4852 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 20:36:11.0901 4852 Beep - ok 20:36:11.0948 4852 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll 20:36:11.0963 4852 BFE - ok 20:36:12.0119 4852 [ A45BE4E091636F6C86D6E4FC945D5A26 ] BHDrvx64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20120928.001\BHDrvx64.sys 20:36:12.0135 4852 BHDrvx64 - ok 20:36:12.0166 4852 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll 20:36:12.0182 4852 BITS - ok 20:36:12.0197 4852 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 20:36:12.0197 4852 blbdrive - ok 20:36:12.0244 4852 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 20:36:12.0260 4852 Bonjour Service - ok 20:36:12.0291 4852 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 20:36:12.0291 4852 bowser - ok 20:36:12.0307 4852 [ 597FFFAC47605337B1C719B4975238F0 ] bpenum C:\Windows\system32\DRIVERS\bpenum.sys 20:36:12.0322 4852 bpenum - ok 20:36:12.0338 4852 [ F66C6AD105EF5A899207F4907366E2E2 ] bpmp C:\Windows\system32\DRIVERS\bpmp.sys 20:36:12.0338 4852 bpmp - ok 20:36:12.0353 4852 [ AE6751F004DFEBE0A7548265CCF432CE ] bpusb C:\Windows\system32\Drivers\bpusb.sys 20:36:12.0353 4852 bpusb - ok 20:36:12.0369 4852 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 20:36:12.0369 4852 BrFiltLo - ok 20:36:12.0385 4852 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 20:36:12.0385 4852 BrFiltUp - ok 20:36:12.0416 4852 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 20:36:12.0431 4852 Browser - ok 20:36:12.0447 4852 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 20:36:12.0447 4852 Brserid - ok 20:36:12.0463 4852 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 20:36:12.0478 4852 BrSerWdm - ok 20:36:12.0494 4852 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 20:36:12.0494 4852 BrUsbMdm - ok 20:36:12.0494 4852 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 20:36:12.0494 4852 BrUsbSer - ok 20:36:12.0509 4852 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 20:36:12.0509 4852 BTHMODEM - ok 20:36:12.0541 4852 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 20:36:12.0541 4852 bthserv - ok 20:36:12.0619 4852 [ 37F1BAEC39B505B3B51893A35C8337EA ] ccHP C:\Windows\system32\drivers\N360x64\0404000.00C\ccHPx64.sys 20:36:12.0634 4852 ccHP - ok 20:36:12.0650 4852 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 20:36:12.0650 4852 cdfs - ok 20:36:12.0681 4852 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\drivers\cdrom.sys 20:36:12.0681 4852 cdrom - ok 20:36:12.0717 4852 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 20:36:12.0733 4852 CertPropSvc - ok 20:36:12.0748 4852 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys 20:36:12.0748 4852 circlass - ok 20:36:12.0764 4852 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 20:36:12.0780 4852 CLFS - ok 20:36:12.0842 4852 [ 730BF325E4CC1E3935B81943AC6DA216 ] CLKMSVC10_9EC60124 c:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe 20:36:12.0842 4852 CLKMSVC10_9EC60124 - ok 20:36:12.0889 4852 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 20:36:12.0889 4852 clr_optimization_v2.0.50727_32 - ok 20:36:12.0936 4852 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 20:36:12.0936 4852 clr_optimization_v2.0.50727_64 - ok 20:36:12.0982 4852 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 20:36:12.0998 4852 clr_optimization_v4.0.30319_32 - ok 20:36:13.0014 4852 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 20:36:13.0014 4852 clr_optimization_v4.0.30319_64 - ok 20:36:13.0029 4852 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 20:36:13.0029 4852 CmBatt - ok 20:36:13.0060 4852 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 20:36:13.0060 4852 cmdide - ok 20:36:13.0170 4852 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 20:36:13.0170 4852 CNG - ok 20:36:13.0201 4852 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 20:36:13.0201 4852 Compbatt - ok 20:36:13.0232 4852 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 20:36:13.0232 4852 CompositeBus - ok 20:36:13.0232 4852 COMSysApp - ok 20:36:13.0263 4852 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 20:36:13.0263 4852 crcdisk - ok 20:36:13.0294 4852 [ 4F5414602E2544A4554D95517948B705 ] CryptSvc C:\Windows\system32\cryptsvc.dll 20:36:13.0310 4852 CryptSvc - ok 20:36:13.0326 4852 [ FBE228ABEAB2BE13B9C3A3A112D4D8DC ] CtClsFlt C:\Windows\system32\DRIVERS\CtClsFlt.sys 20:36:13.0326 4852 CtClsFlt - ok 20:36:13.0419 4852 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE 20:36:13.0435 4852 cvhsvc - ok 20:36:13.0497 4852 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 20:36:13.0513 4852 DcomLaunch - ok 20:36:13.0544 4852 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 20:36:13.0560 4852 defragsvc - ok 20:36:13.0591 4852 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 20:36:13.0591 4852 DfsC - ok 20:36:13.0591 4852 dgderdrv - ok 20:36:13.0653 4852 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 20:36:13.0653 4852 Dhcp - ok 20:36:13.0684 4852 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 20:36:13.0684 4852 discache - ok 20:36:13.0700 4852 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys 20:36:13.0700 4852 Disk - ok 20:36:13.0747 4852 [ FD6780D8E79A4A0037DBCB339582F091 ] DMAgent C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe 20:36:13.0762 4852 DMAgent - ok 20:36:13.0809 4852 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 20:36:13.0809 4852 Dnscache - ok 20:36:13.0840 4852 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 20:36:13.0840 4852 dot3svc - ok 20:36:13.0872 4852 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 20:36:13.0887 4852 DPS - ok 20:36:13.0903 4852 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 20:36:13.0903 4852 drmkaud - ok 20:36:13.0950 4852 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 20:36:13.0965 4852 DXGKrnl - ok 20:36:13.0981 4852 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 20:36:13.0981 4852 EapHost - ok 20:36:14.0059 4852 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys 20:36:14.0074 4852 ebdrv - ok 20:36:14.0106 4852 [ 4353FF94D47A0A9D52B89ECCF0CDB013 ] eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys 20:36:14.0106 4852 eeCtrl - ok 20:36:14.0137 4852 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 20:36:14.0137 4852 EFS - ok 20:36:14.0199 4852 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 20:36:14.0199 4852 ehRecvr - ok 20:36:14.0230 4852 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 20:36:14.0230 4852 ehSched - ok 20:36:14.0246 4852 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 20:36:14.0262 4852 elxstor - ok 20:36:14.0293 4852 [ C5BCCB378D0A896304A3E71BE7215983 ] EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 20:36:14.0293 4852 EraserUtilRebootDrv - ok 20:36:14.0324 4852 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 20:36:14.0324 4852 ErrDev - ok 20:36:14.0355 4852 esgiguard - ok 20:36:14.0402 4852 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 20:36:14.0402 4852 EventSystem - ok 20:36:14.0496 4852 [ 8B6C9924B0D333DBF76086B8258A0891 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe 20:36:14.0511 4852 EvtEng - ok 20:36:14.0511 4852 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 20:36:14.0527 4852 exfat - ok 20:36:14.0527 4852 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 20:36:14.0527 4852 fastfat - ok 20:36:14.0574 4852 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 20:36:14.0589 4852 Fax - ok 20:36:14.0605 4852 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys 20:36:14.0605 4852 fdc - ok 20:36:14.0620 4852 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 20:36:14.0620 4852 fdPHost - ok 20:36:14.0636 4852 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 20:36:14.0636 4852 FDResPub - ok 20:36:14.0652 4852 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 20:36:14.0652 4852 FileInfo - ok 20:36:14.0667 4852 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 20:36:14.0667 4852 Filetrace - ok 20:36:14.0683 4852 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 20:36:14.0683 4852 flpydisk - ok 20:36:14.0714 4852 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 20:36:14.0730 4852 FltMgr - ok 20:36:14.0776 4852 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll 20:36:14.0792 4852 FontCache - ok 20:36:14.0839 4852 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 20:36:14.0854 4852 FontCache3.0.0.0 - ok 20:36:14.0870 4852 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 20:36:14.0870 4852 FsDepends - ok 20:36:14.0901 4852 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 20:36:14.0901 4852 Fs_Rec - ok 20:36:14.0933 4852 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 20:36:14.0949 4852 fvevol - ok 20:36:14.0965 4852 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 20:36:14.0965 4852 gagp30kx - ok 20:36:14.0996 4852 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 20:36:15.0011 4852 GEARAspiWDM - ok 20:36:15.0058 4852 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 20:36:15.0074 4852 gpsvc - ok 20:36:15.0089 4852 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 20:36:15.0089 4852 hcw85cir - ok 20:36:15.0121 4852 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 20:36:15.0136 4852 HdAudAddService - ok 20:36:15.0152 4852 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 20:36:15.0152 4852 HDAudBus - ok 20:36:15.0167 4852 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 20:36:15.0167 4852 HidBatt - ok 20:36:15.0183 4852 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 20:36:15.0183 4852 HidBth - ok 20:36:15.0199 4852 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 20:36:15.0199 4852 HidIr - ok 20:36:15.0214 4852 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll 20:36:15.0230 4852 hidserv - ok 20:36:15.0261 4852 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 20:36:15.0261 4852 HidUsb - ok 20:36:15.0292 4852 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 20:36:15.0308 4852 hkmsvc - ok 20:36:15.0339 4852 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 20:36:15.0339 4852 HomeGroupListener - ok 20:36:15.0386 4852 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 20:36:15.0386 4852 HomeGroupProvider - ok 20:36:15.0401 4852 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 20:36:15.0401 4852 HpSAMD - ok 20:36:15.0448 4852 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 20:36:15.0464 4852 HTTP - ok 20:36:15.0511 4852 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 20:36:15.0511 4852 hwpolicy - ok 20:36:15.0542 4852 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 20:36:15.0542 4852 i8042prt - ok 20:36:15.0573 4852 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 20:36:15.0573 4852 iaStorV - ok 20:36:15.0635 4852 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 20:36:15.0651 4852 idsvc - ok 20:36:15.0713 4852 [ A48928D4CCA6F8B731989DB08CF2C0AB ] IDSVia64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20120929.001\IDSvia64.sys 20:36:15.0729 4852 IDSVia64 - ok 20:36:15.0760 4852 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 20:36:15.0760 4852 iirsp - ok 20:36:15.0791 4852 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 20:36:15.0807 4852 IKEEXT - ok 20:36:15.0885 4852 [ 8FED6428FDE53D7F4C105095F22524BE ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys 20:36:15.0885 4852 IntcAzAudAddService - ok 20:36:15.0901 4852 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 20:36:15.0901 4852 intelide - ok 20:36:15.0901 4852 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 20:36:15.0901 4852 intelppm - ok 20:36:15.0916 4852 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 20:36:15.0916 4852 IPBusEnum - ok 20:36:15.0947 4852 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 20:36:15.0947 4852 IpFilterDriver - ok 20:36:15.0979 4852 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 20:36:15.0994 4852 iphlpsvc - ok 20:36:16.0025 4852 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 20:36:16.0025 4852 IPMIDRV - ok 20:36:16.0041 4852 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 20:36:16.0041 4852 IPNAT - ok 20:36:16.0103 4852 [ 6E50CFA46527B39015B750AAD161C5CC ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 20:36:16.0119 4852 iPod Service - ok 20:36:16.0135 4852 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 20:36:16.0135 4852 IRENUM - ok 20:36:16.0150 4852 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 20:36:16.0150 4852 isapnp - ok 20:36:16.0166 4852 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 20:36:16.0166 4852 iScsiPrt - ok 20:36:16.0181 4852 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys 20:36:16.0181 4852 kbdclass - ok 20:36:16.0197 4852 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys 20:36:16.0197 4852 kbdhid - ok 20:36:16.0213 4852 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 20:36:16.0213 4852 KeyIso - ok 20:36:16.0244 4852 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 20:36:16.0244 4852 KSecDD - ok 20:36:16.0275 4852 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 20:36:16.0291 4852 KSecPkg - ok 20:36:16.0306 4852 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 20:36:16.0306 4852 ksthunk - ok 20:36:16.0337 4852 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 20:36:16.0353 4852 KtmRm - ok 20:36:16.0384 4852 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll 20:36:16.0400 4852 LanmanServer - ok 20:36:16.0431 4852 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 20:36:16.0447 4852 LanmanWorkstation - ok 20:36:16.0447 4852 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 20:36:16.0462 4852 lltdio - ok 20:36:16.0493 4852 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 20:36:16.0493 4852 lltdsvc - ok 20:36:16.0509 4852 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 20:36:16.0509 4852 lmhosts - ok 20:36:16.0540 4852 [ 7F32D4C47A50E7223491E8FB9359907D ] LMS C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe 20:36:16.0540 4852 LMS - ok 20:36:16.0571 4852 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 20:36:16.0571 4852 LSI_FC - ok 20:36:16.0587 4852 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 20:36:16.0587 4852 LSI_SAS - ok 20:36:16.0618 4852 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 20:36:16.0618 4852 LSI_SAS2 - ok 20:36:16.0634 4852 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 20:36:16.0634 4852 LSI_SCSI - ok 20:36:16.0649 4852 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 20:36:16.0649 4852 luafv - ok 20:36:16.0696 4852 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 20:36:16.0696 4852 Mcx2Svc - ok 20:36:16.0712 4852 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 20:36:16.0712 4852 megasas - ok 20:36:16.0743 4852 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 20:36:16.0743 4852 MegaSR - ok 20:36:16.0774 4852 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys 20:36:16.0774 4852 MEIx64 - ok 20:36:16.0805 4852 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 20:36:16.0805 4852 MMCSS - ok 20:36:16.0821 4852 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 20:36:16.0821 4852 Modem - ok 20:36:16.0899 4852 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 20:36:16.0899 4852 monitor - ok 20:36:16.0946 4852 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 20:36:16.0946 4852 mouclass - ok 20:36:16.0961 4852 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 20:36:16.0961 4852 mouhid - ok 20:36:16.0993 4852 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 20:36:16.0993 4852 mountmgr - ok 20:36:17.0055 4852 [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 20:36:17.0055 4852 MozillaMaintenance - ok 20:36:17.0071 4852 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 20:36:17.0086 4852 mpio - ok 20:36:17.0107 4852 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 20:36:17.0107 4852 mpsdrv - ok 20:36:17.0170 4852 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll 20:36:17.0170 4852 MpsSvc - ok 20:36:17.0217 4852 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 20:36:17.0217 4852 MRxDAV - ok 20:36:17.0248 4852 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 20:36:17.0264 4852 mrxsmb - ok 20:36:17.0295 4852 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 20:36:17.0295 4852 mrxsmb10 - ok 20:36:17.0311 4852 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 20:36:17.0311 4852 mrxsmb20 - ok 20:36:17.0342 4852 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 20:36:17.0342 4852 msahci - ok 20:36:17.0357 4852 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 20:36:17.0373 4852 msdsm - ok 20:36:17.0389 4852 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 20:36:17.0389 4852 MSDTC - ok 20:36:17.0404 4852 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 20:36:17.0404 4852 Msfs - ok 20:36:17.0435 4852 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 20:36:17.0435 4852 mshidkmdf - ok 20:36:17.0451 4852 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 20:36:17.0451 4852 msisadrv - ok 20:36:17.0482 4852 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 20:36:17.0482 4852 MSiSCSI - ok 20:36:17.0482 4852 msiserver - ok 20:36:17.0498 4852 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 20:36:17.0498 4852 MSKSSRV - ok 20:36:17.0513 4852 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 20:36:17.0513 4852 MSPCLOCK - ok 20:36:17.0529 4852 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 20:36:17.0529 4852 MSPQM - ok 20:36:17.0576 4852 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 20:36:17.0576 4852 MsRPC - ok 20:36:17.0607 4852 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 20:36:17.0607 4852 mssmbios - ok 20:36:17.0623 4852 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 20:36:17.0623 4852 MSTEE - ok 20:36:17.0638 4852 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 20:36:17.0638 4852 MTConfig - ok 20:36:17.0654 4852 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 20:36:17.0654 4852 Mup - ok 20:36:17.0685 4852 [ 6ED8935257672F4CD04A88A0F3DE093D ] MyWiFiDHCPDNS C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe 20:36:17.0685 4852 MyWiFiDHCPDNS - ok 20:36:17.0763 4852 [ B4187346F54E362DAFFE647B25A58D50 ] N360 C:\Program Files (x86)\Norton Security Suite\Engine\4.4.0.12\ccSvcHst.exe 20:36:17.0763 4852 N360 - ok 20:36:17.0810 4852 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 20:36:17.0810 4852 napagent - ok 20:36:17.0841 4852 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 20:36:17.0841 4852 NativeWifiP - ok 20:36:17.0903 4852 [ C58D8A669D6551F616D90244BD2C2D4F ] NAVENG C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20121001.020\ENG64.SYS 20:36:17.0903 4852 NAVENG - ok 20:36:17.0966 4852 [ A3DBDB412ADFA5882DD6843B11FE0828 ] NAVEX15 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20121001.020\EX64.SYS 20:36:17.0966 4852 NAVEX15 - ok 20:36:18.0013 4852 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys 20:36:18.0013 4852 NDIS - ok 20:36:18.0028 4852 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 20:36:18.0028 4852 NdisCap - ok 20:36:18.0044 4852 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 20:36:18.0044 4852 NdisTapi - ok 20:36:18.0075 4852 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 20:36:18.0075 4852 Ndisuio - ok 20:36:18.0106 4852 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 20:36:18.0106 4852 NdisWan - ok 20:36:18.0153 4852 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 20:36:18.0153 4852 NDProxy - ok 20:36:18.0169 4852 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 20:36:18.0169 4852 NetBIOS - ok 20:36:18.0215 4852 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 20:36:18.0215 4852 NetBT - ok 20:36:18.0231 4852 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 20:36:18.0247 4852 Netlogon - ok 20:36:18.0278 4852 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 20:36:18.0278 4852 Netman - ok 20:36:18.0309 4852 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 20:36:18.0309 4852 NetMsmqActivator - ok 20:36:18.0325 4852 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 20:36:18.0325 4852 NetPipeActivator - ok 20:36:18.0356 4852 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 20:36:18.0371 4852 netprofm - ok 20:36:18.0387 4852 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 20:36:18.0387 4852 NetTcpActivator - ok 20:36:18.0387 4852 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 20:36:18.0387 4852 NetTcpPortSharing - ok 20:36:18.0543 4852 [ 5D262402B0634C998F8CBCEAD7DD8676 ] NETwNs64 C:\Windows\system32\DRIVERS\NETwNs64.sys 20:36:18.0574 4852 NETwNs64 - ok 20:36:18.0590 4852 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 20:36:18.0590 4852 nfrd960 - ok 20:36:18.0605 4852 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll 20:36:18.0605 4852 NlaSvc - ok 20:36:18.0605 4852 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 20:36:18.0605 4852 Npfs - ok 20:36:18.0621 4852 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 20:36:18.0621 4852 nsi - ok 20:36:18.0652 4852 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 20:36:18.0652 4852 nsiproxy - ok 20:36:18.0730 4852 [ A2F74975097F52A00745F9637451FDD8 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 20:36:18.0746 4852 Ntfs - ok 20:36:18.0761 4852 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 20:36:18.0761 4852 Null - ok 20:36:18.0777 4852 [ D584ABB6A308933A5F72B46C9E5A783F ] nusb3hub C:\Windows\system32\DRIVERS\nusb3hub.sys 20:36:18.0777 4852 nusb3hub - ok 20:36:18.0808 4852 [ 345B9C04E2036DA4346E3249A5BDFD06 ] nusb3xhc C:\Windows\system32\DRIVERS\nusb3xhc.sys 20:36:18.0808 4852 nusb3xhc - ok 20:36:18.0855 4852 [ 8D4AAC74B571FC356560E5B308955E93 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys 20:36:18.0855 4852 NVHDA - ok 20:36:19.0105 4852 [ 9C1996DD3C0469BC8933321F15709F5A ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 20:36:19.0167 4852 nvlddmkm - ok 20:36:19.0198 4852 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 20:36:19.0198 4852 nvraid - ok 20:36:19.0229 4852 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 20:36:19.0229 4852 nvstor - ok 20:36:19.0245 4852 [ 3A69345B9D32131745C4665A3AB4B889 ] NvStUSB C:\Windows\system32\DRIVERS\nvstusb.sys 20:36:19.0245 4852 NvStUSB - ok 20:36:19.0292 4852 [ 34E5498528BB3D5A951F889F8756AD26 ] NVSvc C:\Windows\system32\nvvsvc.exe 20:36:19.0317 4852 NVSvc - ok 20:36:19.0413 4852 [ CD0BFAA6872CFE38C908D313AE17C350 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 20:36:19.0429 4852 nvUpdatusService - ok 20:36:19.0460 4852 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 20:36:19.0460 4852 nv_agp - ok 20:36:19.0475 4852 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 20:36:19.0475 4852 ohci1394 - ok 20:36:19.0507 4852 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 20:36:19.0507 4852 ose - ok 20:36:19.0647 4852 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 20:36:19.0663 4852 osppsvc - ok 20:36:19.0694 4852 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 20:36:19.0694 4852 p2pimsvc - ok 20:36:19.0725 4852 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 20:36:19.0741 4852 p2psvc - ok 20:36:19.0756 4852 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys 20:36:19.0756 4852 Parport - ok 20:36:19.0803 4852 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 20:36:19.0803 4852 partmgr - ok 20:36:19.0819 4852 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 20:36:19.0819 4852 PcaSvc - ok 20:36:19.0834 4852 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 20:36:19.0850 4852 pci - ok 20:36:19.0881 4852 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 20:36:19.0881 4852 pciide - ok 20:36:19.0912 4852 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 20:36:19.0912 4852 pcmcia - ok 20:36:19.0928 4852 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 20:36:19.0928 4852 pcw - ok 20:36:19.0943 4852 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 20:36:19.0959 4852 PEAUTH - ok 20:36:20.0037 4852 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 20:36:20.0037 4852 PerfHost - ok 20:36:20.0099 4852 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 20:36:20.0115 4852 pla - ok 20:36:20.0131 4852 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 20:36:20.0146 4852 PlugPlay - ok 20:36:20.0162 4852 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 20:36:20.0162 4852 PNRPAutoReg - ok 20:36:20.0162 4852 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 20:36:20.0162 4852 PNRPsvc - ok 20:36:20.0177 4852 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 20:36:20.0193 4852 PolicyAgent - ok 20:36:20.0209 4852 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 20:36:20.0209 4852 Power - ok 20:36:20.0255 4852 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 20:36:20.0255 4852 PptpMiniport - ok 20:36:20.0271 4852 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys 20:36:20.0271 4852 Processor - ok 20:36:20.0302 4852 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 20:36:20.0318 4852 ProfSvc - ok 20:36:20.0333 4852 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 20:36:20.0333 4852 ProtectedStorage - ok 20:36:20.0365 4852 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 20:36:20.0365 4852 Psched - ok 20:36:20.0396 4852 [ 87B04878A6D59D6C79251DC960C674C1 ] PxHlpa64 C:\Windows\system32\Drivers\PxHlpa64.sys 20:36:20.0396 4852 PxHlpa64 - ok 20:36:20.0427 4852 [ 0928BD20273625622722FE1DE5BBDE57 ] qicflt C:\Windows\system32\DRIVERS\qicflt.sys 20:36:20.0427 4852 qicflt - ok 20:36:20.0489 4852 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 20:36:20.0489 4852 ql2300 - ok 20:36:20.0505 4852 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 20:36:20.0505 4852 ql40xx - ok 20:36:20.0552 4852 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 20:36:20.0552 4852 QWAVE - ok 20:36:20.0567 4852 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 20:36:20.0583 4852 QWAVEdrv - ok 20:36:20.0599 4852 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 20:36:20.0599 4852 RasAcd - ok 20:36:20.0614 4852 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 20:36:20.0614 4852 RasAgileVpn - ok 20:36:20.0645 4852 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 20:36:20.0645 4852 RasAuto - ok 20:36:20.0692 4852 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 20:36:20.0692 4852 Rasl2tp - ok 20:36:20.0739 4852 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 20:36:20.0739 4852 RasMan - ok 20:36:20.0755 4852 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 20:36:20.0770 4852 RasPppoe - ok 20:36:20.0786 4852 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 20:36:20.0786 4852 RasSstp - ok 20:36:20.0801 4852 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 20:36:20.0817 4852 rdbss - ok 20:36:20.0833 4852 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 20:36:20.0833 4852 rdpbus - ok 20:36:20.0848 4852 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 20:36:20.0848 4852 RDPCDD - ok 20:36:20.0864 4852 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 20:36:20.0879 4852 RDPENCDD - ok 20:36:20.0895 4852 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 20:36:20.0895 4852 RDPREFMP - ok 20:36:20.0926 4852 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 20:36:20.0926 4852 RDPWD - ok 20:36:20.0973 4852 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 20:36:20.0973 4852 rdyboost - ok 20:36:21.0035 4852 [ 189C5A8D2098E0AA14FD157A954B34FC ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe 20:36:21.0035 4852 RegSrvc - ok 20:36:21.0067 4852 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 20:36:21.0067 4852 RemoteAccess - ok 20:36:21.0098 4852 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 20:36:21.0113 4852 RemoteRegistry - ok 20:36:21.0191 4852 [ BDDC447AB46625A54619808575D5CB46 ] RoxMediaDB12OEM C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe 20:36:21.0223 4852 RoxMediaDB12OEM - ok 20:36:21.0254 4852 [ CE203243ADF512540249DF9C264F12DD ] RoxWatch12 C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe 20:36:21.0254 4852 RoxWatch12 - ok 20:36:21.0269 4852 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 20:36:21.0269 4852 RpcEptMapper - ok 20:36:21.0285 4852 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 20:36:21.0285 4852 RpcLocator - ok 20:36:21.0332 4852 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll 20:36:21.0347 4852 RpcSs - ok 20:36:21.0379 4852 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 20:36:21.0379 4852 rspndr - ok 20:36:21.0410 4852 [ EE082E06A82FF630351D1E0EBBD3D8D0 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys 20:36:21.0425 4852 RTL8167 - ok 20:36:21.0441 4852 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 20:36:21.0441 4852 SamSs - ok 20:36:21.0472 4852 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 20:36:21.0472 4852 sbp2port - ok 20:36:21.0472 4852 SBRE - ok 20:36:21.0503 4852 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 20:36:21.0519 4852 SCardSvr - ok 20:36:21.0551 4852 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 20:36:21.0551 4852 scfilter - ok 20:36:21.0582 4852 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 20:36:21.0614 4852 Schedule - ok 20:36:21.0645 4852 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 20:36:21.0645 4852 SCPolicySvc - ok 20:36:21.0692 4852 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 20:36:21.0692 4852 SDRSVC - ok 20:36:21.0707 4852 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 20:36:21.0707 4852 secdrv - ok 20:36:21.0738 4852 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 20:36:21.0738 4852 seclogon - ok 20:36:21.0770 4852 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll 20:36:21.0770 4852 SENS - ok 20:36:21.0785 4852 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 20:36:21.0785 4852 SensrSvc - ok 20:36:21.0801 4852 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 20:36:21.0801 4852 Serenum - ok 20:36:21.0816 4852 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys 20:36:21.0832 4852 Serial - ok 20:36:21.0863 4852 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 20:36:21.0863 4852 sermouse - ok 20:36:21.0910 4852 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 20:36:21.0910 4852 SessionEnv - ok 20:36:21.0910 4852 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 20:36:21.0910 4852 sffdisk - ok 20:36:21.0926 4852 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 20:36:21.0926 4852 sffp_mmc - ok 20:36:21.0957 4852 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 20:36:21.0957 4852 sffp_sd - ok 20:36:21.0972 4852 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 20:36:21.0972 4852 sfloppy - ok 20:36:22.0004 4852 [ C6CC9297BD53E5229653303E556AA539 ] Sftfs C:\Windows\system32\DRIVERS\Sftfslh.sys 20:36:22.0004 4852 Sftfs - ok 20:36:22.0066 4852 [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe 20:36:22.0066 4852 sftlist - ok 20:36:22.0128 4852 [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay C:\Windows\system32\DRIVERS\Sftplaylh.sys 20:36:22.0144 4852 Sftplay - ok 20:36:22.0144 4852 [ 617E29A0B0A2807466560D4C4E338D3E ] Sftredir C:\Windows\system32\DRIVERS\Sftredirlh.sys 20:36:22.0160 4852 Sftredir - ok 20:36:22.0238 4852 [ E1974A92AC0914A3859359A0A8C82C68 ] SftService C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE 20:36:22.0253 4852 SftService - ok 20:36:22.0253 4852 [ 8F571F016FA1976F445147E9E6C8AE9B ] Sftvol C:\Windows\system32\DRIVERS\Sftvollh.sys 20:36:22.0253 4852 Sftvol - ok 20:36:22.0269 4852 [ C3CDDD18F43D44AB713CF8C4916F7696 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe 20:36:22.0269 4852 sftvsa - ok 20:36:22.0300 4852 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll 20:36:22.0300 4852 SharedAccess - ok 20:36:22.0347 4852 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 20:36:22.0347 4852 ShellHWDetection - ok 20:36:22.0378 4852 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 20:36:22.0378 4852 SiSRaid2 - ok 20:36:22.0394 4852 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 20:36:22.0394 4852 SiSRaid4 - ok 20:36:22.0409 4852 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 20:36:22.0409 4852 Smb - ok 20:36:22.0425 4852 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 20:36:22.0425 4852 SNMPTRAP - ok 20:36:22.0440 4852 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 20:36:22.0440 4852 spldr - ok 20:36:22.0487 4852 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 20:36:22.0503 4852 Spooler - ok 20:36:22.0612 4852 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 20:36:22.0612 4852 sppsvc - ok 20:36:22.0643 4852 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 20:36:22.0643 4852 sppuinotify - ok 20:36:22.0721 4852 [ 96BABC4906ECDB1C69D1176F8647AD8E ] SRTSP C:\Windows\System32\Drivers\N360x64\0404000.00C\SRTSP64.SYS 20:36:22.0737 4852 SRTSP - ok 20:36:22.0752 4852 [ C7F491A290E0E4222F5CDCD50EEB8167 ] SRTSPX C:\Windows\system32\drivers\N360x64\0404000.00C\SRTSPX64.SYS 20:36:22.0752 4852 SRTSPX - ok 20:36:22.0784 4852 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 20:36:22.0784 4852 srv - ok 20:36:22.0799 4852 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 20:36:22.0815 4852 srv2 - ok 20:36:22.0830 4852 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 20:36:22.0830 4852 srvnet - ok 20:36:22.0846 4852 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 20:36:22.0846 4852 SSDPSRV - ok 20:36:22.0877 4852 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 20:36:22.0877 4852 SstpSvc - ok 20:36:22.0924 4852 [ 92E7F6666633D2DD91D527503DAA7BE0 ] stdcfltn C:\Windows\system32\DRIVERS\stdcfltn.sys 20:36:22.0924 4852 stdcfltn - ok 20:36:22.0955 4852 [ 8544A200C40447E465F06E58687428BB ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 20:36:22.0971 4852 Stereo Service - ok 20:36:23.0002 4852 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 20:36:23.0002 4852 stexstor - ok 20:36:23.0049 4852 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 20:36:23.0049 4852 stisvc - ok 20:36:23.0080 4852 [ 9E182DD94496550A22A392CC1A8E0F52 ] stllssvr C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe 20:36:23.0080 4852 stllssvr - ok 20:36:23.0127 4852 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys 20:36:23.0127 4852 swenum - ok 20:36:23.0158 4852 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 20:36:23.0174 4852 swprv - ok 20:36:23.0220 4852 [ 659B227A72B76115975A6A9491B2FE1F ] SymDS C:\Windows\system32\drivers\N360x64\0404000.00C\SYMDS64.SYS 20:36:23.0220 4852 SymDS - ok 20:36:23.0267 4852 [ 9F5783A4A03D0091CDBDAA858B566926 ] SymEFA C:\Windows\system32\drivers\N360x64\0404000.00C\SYMEFA64.SYS 20:36:23.0267 4852 SymEFA - ok 20:36:23.0283 4852 [ 3F9D5FE52585E2653E59FDBFDF09A94C ] SymEvent C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 20:36:23.0298 4852 SymEvent - ok 20:36:23.0314 4852 [ F57588546E738DB1583981D8F44E9BC2 ] SymIRON C:\Windows\system32\drivers\N360x64\0404000.00C\Ironx64.SYS 20:36:23.0314 4852 SymIRON - ok 20:36:23.0330 4852 [ 3ADFB72F0797AE3832509FE030755E21 ] SYMTDIv C:\Windows\System32\Drivers\N360x64\0404000.00C\SYMTDIV.SYS 20:36:23.0330 4852 SYMTDIv - ok 20:36:23.0392 4852 [ 5E3B232A614339399ACC71FA3AAAAA6B ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys 20:36:23.0408 4852 SynTP - ok 20:36:23.0486 4852 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 20:36:23.0517 4852 SysMain - ok 20:36:23.0548 4852 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 20:36:23.0548 4852 TabletInputService - ok 20:36:23.0564 4852 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 20:36:23.0579 4852 TapiSrv - ok 20:36:23.0595 4852 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 20:36:23.0595 4852 TBS - ok 20:36:23.0673 4852 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] Tcpip C:\Windows\system32\drivers\tcpip.sys 20:36:23.0688 4852 Tcpip - ok 20:36:23.0767 4852 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 20:36:23.0783 4852 TCPIP6 - ok 20:36:23.0814 4852 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 20:36:23.0814 4852 tcpipreg - ok 20:36:23.0845 4852 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 20:36:23.0845 4852 TDPIPE - ok 20:36:23.0892 4852 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 20:36:23.0892 4852 TDTCP - ok 20:36:23.0923 4852 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 20:36:23.0923 4852 tdx - ok 20:36:23.0955 4852 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys 20:36:23.0970 4852 TermDD - ok 20:36:24.0001 4852 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 20:36:24.0017 4852 TermService - ok 20:36:24.0033 4852 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 20:36:24.0048 4852 Themes - ok 20:36:24.0064 4852 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 20:36:24.0079 4852 THREADORDER - ok 20:36:24.0095 4852 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 20:36:24.0095 4852 TrkWks - ok 20:36:24.0142 4852 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 20:36:24.0142 4852 TrustedInstaller - ok 20:36:24.0189 4852 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 20:36:24.0189 4852 tssecsrv - ok 20:36:24.0204 4852 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 20:36:24.0204 4852 TsUsbFlt - ok 20:36:24.0235 4852 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 20:36:24.0251 4852 tunnel - ok 20:36:24.0267 4852 [ FD24F98D2898BE093FE926604BE7DB99 ] TurboB C:\Windows\system32\DRIVERS\TurboB.sys 20:36:24.0267 4852 TurboB - ok 20:36:24.0298 4852 [ 600B406A04D90F577FEA8A88D7379F08 ] TurboBoost C:\Program Files\Intel\TurboBoost\TurboBoost.exe 20:36:24.0298 4852 TurboBoost - ok 20:36:24.0313 4852 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 20:36:24.0329 4852 uagp35 - ok 20:36:24.0345 4852 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 20:36:24.0345 4852 udfs - ok 20:36:24.0376 4852 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 20:36:24.0376 4852 UI0Detect - ok 20:36:24.0391 4852 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 20:36:24.0391 4852 uliagpkx - ok 20:36:24.0423 4852 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 20:36:24.0423 4852 umbus - ok 20:36:24.0438 4852 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 20:36:24.0438 4852 UmPass - ok 20:36:24.0532 4852 [ 2C16648A12999AE69A9EBF41974B0BA2 ] UNS C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe 20:36:24.0532 4852 UNS - ok 20:36:24.0579 4852 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 20:36:24.0579 4852 upnphost - ok 20:36:24.0610 4852 [ AF1B9474D67897D0C2CFF58E0ACEACCC ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys 20:36:24.0610 4852 USBAAPL64 - ok 20:36:24.0625 4852 usbbus - ok 20:36:24.0672 4852 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 20:36:24.0672 4852 usbccgp - ok 20:36:24.0703 4852 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 20:36:24.0703 4852 usbcir - ok 20:36:24.0719 4852 UsbDiag - ok 20:36:24.0750 4852 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys 20:36:24.0750 4852 usbehci - ok 20:36:24.0781 4852 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 20:36:24.0797 4852 usbhub - ok 20:36:24.0797 4852 USBModem - ok 20:36:24.0844 4852 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys 20:36:24.0844 4852 usbohci - ok 20:36:24.0859 4852 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 20:36:24.0875 4852 usbprint - ok 20:36:24.0891 4852 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 20:36:24.0906 4852 USBSTOR - ok 20:36:24.0922 4852 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 20:36:24.0922 4852 usbuhci - ok 20:36:24.0937 4852 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys 20:36:24.0953 4852 usbvideo - ok 20:36:24.0969 4852 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 20:36:24.0969 4852 UxSms - ok 20:36:24.0984 4852 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 20:36:24.0984 4852 VaultSvc - ok 20:36:25.0000 4852 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 20:36:25.0000 4852 vdrvroot - ok 20:36:25.0047 4852 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 20:36:25.0047 4852 vds - ok 20:36:25.0062 4852 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 20:36:25.0062 4852 vga - ok 20:36:25.0078 4852 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 20:36:25.0078 4852 VgaSave - ok 20:36:25.0093 4852 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 20:36:25.0093 4852 vhdmp - ok 20:36:25.0109 4852 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 20:36:25.0125 4852 viaide - ok 20:36:25.0125 4852 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 20:36:25.0140 4852 volmgr - ok 20:36:25.0171 4852 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 20:36:25.0187 4852 volmgrx - ok 20:36:25.0203 4852 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 20:36:25.0203 4852 volsnap - ok 20:36:25.0218 4852 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 20:36:25.0218 4852 vsmraid - ok 20:36:25.0281 4852 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 20:36:25.0312 4852 VSS - ok 20:36:25.0312 4852 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 20:36:25.0312 4852 vwifibus - ok 20:36:25.0327 4852 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 20:36:25.0327 4852 vwififlt - ok 20:36:25.0343 4852 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys 20:36:25.0343 4852 vwifimp - ok 20:36:25.0390 4852 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 20:36:25.0405 4852 W32Time - ok 20:36:25.0421 4852 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 20:36:25.0421 4852 WacomPen - ok 20:36:25.0437 4852 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 20:36:25.0437 4852 WANARP - ok 20:36:25.0437 4852 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 20:36:25.0437 4852 Wanarpv6 - ok 20:36:25.0499 4852 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 20:36:25.0515 4852 WatAdminSvc - ok 20:36:25.0577 4852 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 20:36:25.0577 4852 wbengine - ok 20:36:25.0624 4852 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 20:36:25.0624 4852 WbioSrvc - ok 20:36:25.0655 4852 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 20:36:25.0671 4852 wcncsvc - ok 20:36:25.0686 4852 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 20:36:25.0686 4852 WcsPlugInService - ok 20:36:25.0717 4852 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys 20:36:25.0717 4852 Wd - ok 20:36:25.0749 4852 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 20:36:25.0749 4852 Wdf01000 - ok 20:36:25.0764 4852 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 20:36:25.0764 4852 WdiServiceHost - ok 20:36:25.0780 4852 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 20:36:25.0780 4852 WdiSystemHost - ok 20:36:25.0811 4852 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 20:36:25.0811 4852 WebClient - ok 20:36:25.0842 4852 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 20:36:25.0842 4852 Wecsvc - ok 20:36:25.0873 4852 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 20:36:25.0873 4852 wercplsupport - ok 20:36:25.0889 4852 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 20:36:25.0889 4852 WerSvc - ok 20:36:25.0905 4852 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 20:36:25.0905 4852 WfpLwf - ok 20:36:25.0970 4852 [ 49F06C7D5517DE53D848F38B9AE86A7C ] WiMAXAppSrv C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe 20:36:25.0970 4852 WiMAXAppSrv - ok 20:36:26.0017 4852 [ B14EF15BD757FA488F9C970EEE9C0D35 ] WimFltr C:\Windows\system32\DRIVERS\wimfltr.sys 20:36:26.0017 4852 WimFltr - ok 20:36:26.0048 4852 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 20:36:26.0048 4852 WIMMount - ok 20:36:26.0064 4852 WinDefend - ok 20:36:26.0079 4852 WinHttpAutoProxySvc - ok 20:36:26.0126 4852 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 20:36:26.0142 4852 Winmgmt - ok 20:36:26.0220 4852 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 20:36:26.0235 4852 WinRM - ok 20:36:26.0251 4852 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 20:36:26.0251 4852 WinUsb - ok 20:36:26.0282 4852 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 20:36:26.0282 4852 Wlansvc - ok 20:36:26.0313 4852 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 20:36:26.0313 4852 wlcrasvc - ok 20:36:26.0422 4852 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 20:36:26.0422 4852 wlidsvc - ok 20:36:26.0454 4852 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 20:36:26.0454 4852 WmiAcpi - ok 20:36:26.0469 4852 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 20:36:26.0469 4852 wmiApSrv - ok 20:36:26.0485 4852 WMPNetworkSvc - ok 20:36:26.0516 4852 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 20:36:26.0516 4852 WPCSvc - ok 20:36:26.0547 4852 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 20:36:26.0547 4852 WPDBusEnum - ok 20:36:26.0578 4852 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 20:36:26.0578 4852 ws2ifsl - ok 20:36:26.0610 4852 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll 20:36:26.0610 4852 wscsvc - ok 20:36:26.0625 4852 [ 8D918B1DB190A4D9B1753A66FA8C96E8 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys 20:36:26.0625 4852 WSDPrintDevice - ok 20:36:26.0625 4852 WSearch - ok 20:36:26.0719 4852 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 20:36:26.0719 4852 wuauserv - ok 20:36:26.0734 4852 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 20:36:26.0734 4852 WudfPf - ok 20:36:26.0766 4852 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 20:36:26.0766 4852 WUDFRd - ok 20:36:26.0781 4852 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 20:36:26.0781 4852 wudfsvc - ok 20:36:26.0812 4852 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll 20:36:26.0812 4852 WwanSvc - ok 20:36:26.0844 4852 ================ Scan global =============================== 20:36:26.0859 4852 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 20:36:26.0890 4852 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll 20:36:26.0922 4852 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll 20:36:26.0937 4852 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 20:36:26.0968 4852 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 20:36:26.0968 4852 [Global] - ok 20:36:26.0968 4852 ================ Scan MBR ================================== 20:36:26.0984 4852 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0 20:36:27.0436 4852 \Device\Harddisk0\DR0 - ok 20:36:27.0436 4852 ================ Scan VBR ================================== 20:36:27.0452 4852 [ 70DAAA6EEBFC8694A5EB9189555CF4FA ] \Device\Harddisk0\DR0\Partition1 20:36:27.0452 4852 \Device\Harddisk0\DR0\Partition1 - ok 20:36:27.0483 4852 [ 683C52AD82086AEDC39384B3D0160F54 ] \Device\Harddisk0\DR0\Partition2 20:36:27.0499 4852 \Device\Harddisk0\DR0\Partition2 - ok 20:36:27.0499 4852 ============================================================ 20:36:27.0499 4852 Scan finished 20:36:27.0499 4852 ============================================================ 20:36:27.0514 3572 Detected object count: 0 20:36:27.0514 3572 Actual detected object count: 0 20:36:52.0216 5744 Deinitialize success
Download Combofix from the link below, and save it to your desktop.
Link

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-
ComboFix.txt log ComboFix 12-09-30.03 - Krystal 10/01/2012 21:21:24.1.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8152.6543 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Norton Security Suite *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton Security Suite *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: Norton Security Suite *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\Roaming c:\users\Krystal\AppData\Local\{3DCB023F-4E21-42BE-82BE-DF5909610CC5}\{359606B4-539E-4904-A6E9-682155F208BF}\ptfebc.dll . . ((((((((((((((((((((((((( Files Created from 2012-09-02 to 2012-10-02 ))))))))))))))))))))))))))))))) . . 2012-10-02 02:27 . 2012-10-02 02:27 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2012-10-02 02:27 . 2012-10-02 02:27 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-10-01 02:11 . 2012-10-01 02:26 ——– d—–w- c:\users\Krystal\AppData\Roaming\Anvisoft 2012-10-01 02:11 . 2012-10-01 02:11 ——– d—–w- c:\programdata\Anvisoft 2012-10-01 02:11 . 2012-10-01 02:26 ——– d—–w- c:\program files (x86)\Anvisoft 2012-10-01 02:02 . 2012-10-01 02:02 ——– d—–w- c:\users\Krystal\AppData\Roaming\LavasoftStatistics 2012-10-01 02:02 . 2012-10-01 02:02 ——– d—–w- c:\programdata\blekko toolbars 2012-09-30 22:54 . 2012-09-30 22:54 ——– d—–w- c:\program files (x86)\VS Revo Group 2012-09-30 22:33 . 2012-09-30 22:33 ——– d—–w- c:\program files\Enigma Software Group 2012-09-30 22:32 . 2012-09-30 23:04 ——– d—–w- c:\windows\8C5C34C7BC6B48318B2C6535FE63E502.TMP 2012-09-30 22:32 . 2012-09-30 22:32 ——– d—–w- c:\program files (x86)\Common Files\Wise Installation Wizard 2012-09-30 17:53 . 2012-10-01 23:53 ——– d—–w- c:\program files (x86)\PC Tools 2012-09-30 17:51 . 2012-10-01 23:53 ——– d—–w- c:\program files (x86)\Common Files\PC Tools 2012-09-30 17:51 . 2012-06-22 20:35 251560 —-a-w- c:\windows\system32\drivers\PCTSD64.sys 2012-09-30 17:50 . 2012-10-01 02:28 ——– d—–w- c:\programdata\PC Tools 2012-09-30 17:50 . 2012-09-30 17:50 ——– d—–w- c:\users\Krystal\AppData\Roaming\TestApp 2012-09-30 17:49 . 2012-09-30 17:49 ——– d—–w- c:\programdata\Lavasoft 2012-09-30 17:49 . 2012-10-01 02:09 ——– d—–w- c:\program files (x86)\Ad-Aware Antivirus 2012-09-30 17:48 . 2012-09-30 17:48 ——– d—–w- c:\program files (x86)\adawaretb 2012-09-30 17:48 . 2012-09-30 17:48 ——– d—–w- c:\program files (x86)\Toolbar Cleaner 2012-09-30 17:47 . 2012-09-30 18:14 ——– d—–w- c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus 2012-09-30 17:10 . 2012-10-01 02:28 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2012-09-30 17:10 . 2012-10-01 02:28 ——– d—–w- c:\program files (x86)\Spybot - Search & Destroy 2012-09-26 01:45 . 2012-08-21 21:01 245760 —-a-w- c:\windows\system32\OxpsConverter.exe 2012-09-16 18:35 . 2012-09-16 18:36 ——– d—–w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2012-09-16 18:35 . 2012-09-16 18:36 ——– d—–w- c:\program files\iTunes 2012-09-16 18:35 . 2012-09-16 18:36 ——– d—–w- c:\program files (x86)\iTunes 2012-09-16 18:35 . 2012-09-16 18:35 ——– d—–w- c:\program files\iPod 2012-09-15 13:43 . 2012-08-21 18:01 33240 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-09-13 01:27 . 2012-08-22 18:12 950128 —-a-w- c:\windows\system32\drivers\ndis.sys 2012-09-13 01:27 . 2012-07-04 20:26 41472 —-a-w- c:\windows\system32\drivers\RNDISMP.sys 2012-09-13 01:27 . 2012-08-02 17:58 574464 —-a-w- c:\windows\system32\d3d10level9.dll 2012-09-13 01:27 . 2012-08-02 16:57 490496 —-a-w- c:\windows\SysWow64\d3d10level9.dll 2012-09-13 01:27 . 2012-08-22 18:12 1913200 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-09-13 01:27 . 2012-08-22 18:12 376688 —-a-w- c:\windows\system32\drivers\netio.sys 2012-09-13 01:27 . 2012-08-22 18:12 288624 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-09-28 03:00 . 2012-03-29 12:38 696240 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-09-28 03:00 . 2011-05-13 22:55 73136 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-09-13 08:00 . 2011-04-01 03:44 64462936 —-a-w- c:\windows\system32\MRT.exe 2012-08-21 18:01 . 2011-04-24 02:42 125872 —-a-w- c:\windows\system32\GEARAspi64.dll 2012-08-21 18:01 . 2011-04-24 02:42 106928 —-a-w- c:\windows\SysWow64\GEARAspi.dll 2012-07-18 18:15 . 2012-08-16 00:48 3148800 —-a-w- c:\windows\system32\win32k.sys 2012-07-09 18:42 . 2012-07-09 18:42 4547984 —-a-w- c:\windows\system32\usbaaplrc.dll 2012-07-09 18:42 . 2012-07-09 18:42 52736 —-a-w- c:\windows\system32\drivers\usbaapl64.sys 2012-07-04 22:16 . 2012-08-16 00:48 73216 —-a-w- c:\windows\system32\netapi32.dll 2012-07-04 22:13 . 2012-08-16 00:48 59392 —-a-w- c:\windows\system32\browcli.dll 2012-07-04 22:13 . 2012-08-16 00:48 136704 —-a-w- c:\windows\system32\browser.dll 2012-07-04 21:14 . 2012-08-16 00:48 41984 —-a-w- c:\windows\SysWow64\browcli.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ApplePhotoStreams"="c:\program files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2012-09-10 59280] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2011-09-16 115048] "ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-28 59280] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-11 919008] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-09-10 421776] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [x] R2 CLKMSVC10_9EC60124;CyberLink Product - 2011/03/16 09:25;c:\program files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-10-29 236016] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-09-04 219632] R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x] R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-13 114144] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-12-17 340240] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-09-04 1116656] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-03-27 1255736] R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856] S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [2010-08-20 21616] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\0404000.00C\SYMDS64.SYS [2009-10-15 433200] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\0404000.00C\SYMEFA64.SYS [2011-08-22 221304] S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20120928.001\BHDrvx64.sys [2012-08-31 1385120] S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360x64\0404000.00C\ccHPx64.sys [2011-08-04 593544] S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20120929.001\IDSvia64.sys [2012-09-06 513184] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\0404000.00C\Ironx64.SYS [2010-04-29 150064] S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\Drivers\N360x64\0404000.00C\SYMTDIV.SYS [2011-08-22 451704] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-17 98208] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624] S2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;c:\program files\Intel\WiMAX\Bin\DMAgent.exe [2010-11-07 499200] S2 N360;Norton Security Suite;c:\program files (x86)\Norton Security Suite\Engine\4.4.0.12\ccSvcHst.exe [2011-08-04 126400] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-10 2348352] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776] S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2010-08-20 689472] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-10 382272] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-11-29 16120] S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-12-20 2656280] S2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;c:\program files\Intel\WiMAX\Bin\AppSrv.exe [2010-11-07 869376] S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [2010-12-13 27760] S3 bpenum;Intel® Centrino® WiMAX Enumerator;c:\windows\system32\DRIVERS\bpenum.sys [2010-10-26 75264] S3 bpmp;Intel® Centrino® WiMAX 6050 Series;c:\windows\system32\DRIVERS\bpmp.sys [2010-10-26 173568] S3 bpusb;Intel® Centrino® WiMAX 6050 Series Function Driver;c:\windows\system32\Drivers\bpusb.sys [2010-10-26 81408] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2010-08-12 175168] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-08-09 138912] S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344] S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2010-12-22 8505856] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2011-09-13 95744] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2011-09-13 212992] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2012-01-17 188224] S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\DRIVERS\nvstusb.sys [2012-02-10 398144] S3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys [2010-07-13 29288] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] . . — Other Services/Drivers In Memory — . *Deregistered* - CLKMDRV10_9EC60124 . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-12-17 686704] "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-12-17 1933584] "IntelWirelessWiMAX"="c:\program files\Intel\WiMAX\Bin\WiMAXCU.exe" [2010-11-14 1605632] "IntelTBRunOnce"="wscript.exe" [2009-07-14 168960] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-02-18 6611048] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-01-18 2188904] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.yahoo.com/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com TCP: DhcpNameServer = 192.168.1.1 75.75.75.75 75.75.76.76 FF - ProfilePath - c:\users\Krystal\AppData\Roaming\Mozilla\Firefox\Profiles\xfy65lgs.default\ . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKCU-Run-{359606B4-539E-4904-A6E9-682155F208BF} - c:\users\Krystal\AppData\Local\{3DCB023F-4E21-42BE-82BE-DF5909610CC5}\{359606B4-539E-4904-A6E9-682155F208BF}\ptfebc.dll Wow6432Node-HKLM-Run- - (no file) Toolbar-Locked - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe AddRemove-ExamMatrix CPA Exam Review 2011 - c:\users\Krystal\ExamMatrix\ExamMatrix CPA Exam Review 2011\Uninstall ExamMatrix CPA Exam Review 2011 . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\N360] "ImagePath"="\"c:\program files (x86)\Norton Security Suite\Engine\4.4.0.12\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton Security Suite\Engine\4.4.0.12\diMaster.dll\" /prefetch:1" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-10-01 21:28:51 ComboFix-quarantined-files.txt 2012-10-02 02:28 . Pre-Run: 370,109,902,848 bytes free Post-Run: 369,888,280,576 bytes free . - - End Of File - - 47986B1303A55A852C86196C26EBEE2D
Yes, I uninstalled both. After trying one with no results I uninstalled and tried another. Didn't know if one would conflict with another so I uninstalled previous scanners before installing and trying new ones.
Hi,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the box below:


    ClearJavaCache::

    Folder::
    c:\users\Krystal\AppData\Roaming\Anvisoft
    c:\programdata\Anvisoft
    c:\program files (x86)\Anvisoft
    c:\programdata\blekko toolbars
    c:\program files (x86)\Ad-Aware Antivirus
    c:\program files (x86)\adawaretb
    c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus
    c:\programdata\Lavasoft
    c:\users\Krystal\AppData\Roaming\LavasoftStatistics

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Post the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

Please post the log made by ComboFix and let me know how your system is running. :)
So far so good. I've searched several different things and not one redirect. My ComboFix.txt log is below. Thank you so much for your help. ComboFix 12-10-02.02 - Krystal 10/02/2012 21:01:10.2.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8152.6292 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Krystal\Desktop\CFScript.txt AV: Norton Security Suite *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton Security Suite *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: Norton Security Suite *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Ad-Aware Antivirus c:\program files (x86)\Ad-Aware Antivirus\AdAwareSafeBrowsing.exe c:\program files (x86)\Ad-Aware Antivirus\Definitions\acertdefs0.std c:\program files (x86)\Ad-Aware Antivirus\Definitions\adsrules.dat c:\program files (x86)\Ad-Aware Antivirus\Definitions\AdviceTx.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\api0.std c:\program files (x86)\Ad-Aware Antivirus\Definitions\apincl.dat c:\program files (x86)\Ad-Aware Antivirus\Definitions\apprules.dat c:\program files (x86)\Ad-Aware Antivirus\Definitions\bhmem.vtd c:\program files (x86)\Ad-Aware Antivirus\Definitions\bhsl.vtd c:\program files (x86)\Ad-Aware Antivirus\Definitions\bmem.vtd c:\program files (x86)\Ad-Aware Antivirus\Definitions\CatDesc.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\CatID.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\cblk.vtd c:\program files (x86)\Ad-Aware Antivirus\Definitions\cmem.vtd c:\program files (x86)\Ad-Aware Antivirus\Definitions\cname.wtd c:\program files (x86)\Ad-Aware Antivirus\Definitions\comp0.std c:\program files (x86)\Ad-Aware Antivirus\Definitions\Cookies.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\CoreVer.txt c:\program files (x86)\Ad-Aware Antivirus\Definitions\ctid.vtd c:\program files (x86)\Ad-Aware Antivirus\Definitions\defs0.std c:\program files (x86)\Ad-Aware Antivirus\Definitions\DefVer.txt c:\program files (x86)\Ad-Aware Antivirus\Definitions\dnrl.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\EPSigs.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\FastSigs.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\FileDT.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\FolderDT.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\fsigs.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\hcol.wtd c:\program files (x86)\Ad-Aware Antivirus\Definitions\heur0.std c:\program files (x86)\Ad-Aware Antivirus\Definitions\HistoryCleaner.xml c:\program files (x86)\Ad-Aware Antivirus\Definitions\hstn.vtd c:\program files (x86)\Ad-Aware Antivirus\Definitions\idsrules.dat c:\program files (x86)\Ad-Aware Antivirus\Definitions\ih.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\IncompatiblePrograms.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\incompats.dat c:\program files (x86)\Ad-Aware Antivirus\Definitions\ip.vtd c:\program files (x86)\Ad-Aware Antivirus\Definitions\JSSigs.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\kbu.dat c:\program files (x86)\Ad-Aware Antivirus\Definitions\kbu.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\lgpl.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\lib7zip.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\libBase64.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\libCHM.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\libEmail.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\libMachoUniv.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\libMsCab.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\libMsi.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\libNSIS.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\libOleA.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\libRar.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\libRTF.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\libtd.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\libVvs.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\libZip.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\macroptn.std c:\program files (x86)\Ad-Aware Antivirus\Definitions\MFastSigs.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\mime0.std c:\program files (x86)\Ad-Aware Antivirus\Definitions\networkrules.dat c:\program files (x86)\Ad-Aware Antivirus\Definitions\pack0.std c:\program files (x86)\Ad-Aware Antivirus\Definitions\patchw32.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\qscnf.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\qscnr.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\RegDT.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\rem0.std c:\program files (x86)\Ad-Aware Antivirus\Definitions\remediation.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\RootCA.wtd c:\program files (x86)\Ad-Aware Antivirus\Definitions\RTmem.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\SBTS.dat c:\program files (x86)\Ad-Aware Antivirus\Definitions\script0.std c:\program files (x86)\Ad-Aware Antivirus\Definitions\sdll0.std c:\program files (x86)\Ad-Aware Antivirus\Definitions\sel.dat c:\program files (x86)\Ad-Aware Antivirus\Definitions\smim0.std c:\program files (x86)\Ad-Aware Antivirus\Definitions\ThreatCategoryGlossary.xml c:\program files (x86)\Ad-Aware Antivirus\Definitions\ThreatCategoryGlossary.xsd c:\program files (x86)\Ad-Aware Antivirus\Definitions\ThreatDT.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\ThreatID.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\TImem.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\unpck0.std c:\program files (x86)\Ad-Aware Antivirus\Definitions\updater.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\vcore.dll c:\program files (x86)\Ad-Aware Antivirus\Definitions\VVSSigs.vdx c:\program files (x86)\Ad-Aware Antivirus\Definitions\WebFilterExceptions.dat c:\program files (x86)\Ad-Aware Antivirus\Definitions\white.wtd c:\program files (x86)\Ad-Aware Antivirus\Definitions\white0.std c:\program files (x86)\Ad-Aware Antivirus\Definitions\whmem.wtd c:\program files (x86)\Ad-Aware Antivirus\Definitions\whsl.wtd c:\program files (x86)\Ad-Aware Antivirus\Definitions\wmem.wtd c:\program files (x86)\adawaretb c:\program files (x86)\adawaretb\ieUtils.exe c:\program files (x86)\Anvisoft c:\programdata\Anvisoft c:\programdata\Anvisoft\Anvi Smart Defender\config.xml c:\programdata\blekko toolbars c:\programdata\blekko toolbars\toolbar.txt c:\programdata\Lavasoft c:\programdata\Lavasoft\AntiMalware\APConfig.xml c:\programdata\Lavasoft\AntiMalware\context-menu-settings.xml c:\programdata\Lavasoft\AntiMalware\CountScans.XML c:\programdata\Lavasoft\AntiMalware\EmailAVConfig.xml c:\programdata\Lavasoft\AntiMalware\Events\EV2012093013055100.xml c:\programdata\Lavasoft\AntiMalware\Events\EV2012093013060601.xml c:\programdata\Lavasoft\AntiMalware\Events\EV2012093013061202.xml c:\programdata\Lavasoft\AntiMalware\Events\EV2012093013064903.xml c:\programdata\Lavasoft\AntiMalware\Events\EV2012093013073604.xml c:\programdata\Lavasoft\AntiMalware\Events\EV2012093013110505.xml c:\programdata\Lavasoft\AntiMalware\Events\EV2012093013145006.xml c:\programdata\Lavasoft\AntiMalware\Events\EV2012093013145207.xml c:\programdata\Lavasoft\AntiMalware\FirewallConfig.xml c:\programdata\Lavasoft\AntiMalware\HIPSConfig.xml c:\programdata\Lavasoft\AntiMalware\History\20120930125046.xml c:\programdata\Lavasoft\AntiMalware\History\20120930130734.xml c:\programdata\Lavasoft\AntiMalware\Logs\SBAMSvcLog.csv c:\programdata\Lavasoft\AntiMalware\Logs\SBAMThreatEngineLog.csv c:\programdata\Lavasoft\AntiMalware\RegistrationConfig.xml c:\programdata\Lavasoft\AntiMalware\ScanConfig.xml c:\programdata\Lavasoft\AntiMalware\SoftwareUpdateConfig.xml c:\programdata\Lavasoft\AntiMalware\ThreatDefinitionsConfig.xml c:\programdata\Lavasoft\AntiMalware\WebFilterConfig.xml c:\programdata\Lavasoft\AntiMalware\WSCConfig.xml c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus\application-settings.xml c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus\definitions-date.xml c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus\gaming-mode.xml c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus\id-watch-dog.xml c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus\language.xml c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus\Logs\20120930T174730.370624PID4136\GuiFramework.log c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus\Logs\20120930T180645.814659PID7008\AdAware.log c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus\Logs\20120930T180645.814659PID7008\GuiFramework.log c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus\Logs\20120930T180645.814659PID7008\Sunbelt.log c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus\Logs\20120930T181449.917348PID6528\AdAwareLauncher.log c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus\Logs\20121001T020142.722942PID2640\GlamorousInstaller.log c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus\Logs\20121001T020142.722942PID2640\GuiFramework.log c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus\Logs\20121001T020704.763284PID1840\GlamorousInstaller.log c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus\Logs\20121001T020704.763284PID1840\GuiFramework.log c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus\Logs\20121001T020857.502766PID2520\GlamorousInstaller.log c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus\Logs\20121001T020857.502766PID2520\GuiFramework.log c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus\protection-status.xml c:\users\Krystal\AppData\Roaming\Ad-Aware Antivirus\update-parameters.xml c:\users\Krystal\AppData\Roaming\Anvisoft c:\users\Krystal\AppData\Roaming\LavasoftStatistics c:\users\Krystal\AppData\Roaming\LavasoftStatistics\adaware.xml . . ((((((((((((((((((((((((( Files Created from 2012-09-03 to 2012-10-03 ))))))))))))))))))))))))))))))) . . 2012-10-03 02:33 . 2012-10-03 02:33 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2012-10-03 02:33 . 2012-10-03 02:33 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-09-30 22:54 . 2012-09-30 22:54 ——– d—–w- c:\program files (x86)\VS Revo Group 2012-09-30 22:33 . 2012-09-30 22:33 ——– d—–w- c:\program files\Enigma Software Group 2012-09-30 22:32 . 2012-09-30 23:04 ——– d—–w- c:\windows\8C5C34C7BC6B48318B2C6535FE63E502.TMP 2012-09-30 22:32 . 2012-09-30 22:32 ——– d—–w- c:\program files (x86)\Common Files\Wise Installation Wizard 2012-09-30 17:53 . 2012-10-01 23:53 ——– d—–w- c:\program files (x86)\PC Tools 2012-09-30 17:51 . 2012-10-01 23:53 ——– d—–w- c:\program files (x86)\Common Files\PC Tools 2012-09-30 17:51 . 2012-06-22 20:35 251560 —-a-w- c:\windows\system32\drivers\PCTSD64.sys 2012-09-30 17:50 . 2012-10-01 02:28 ——– d—–w- c:\programdata\PC Tools 2012-09-30 17:50 . 2012-09-30 17:50 ——– d—–w- c:\users\Krystal\AppData\Roaming\TestApp 2012-09-30 17:48 . 2012-09-30 17:48 ——– d—–w- c:\program files (x86)\Toolbar Cleaner 2012-09-30 17:10 . 2012-10-01 02:28 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2012-09-30 17:10 . 2012-10-01 02:28 ——– d—–w- c:\program files (x86)\Spybot - Search & Destroy 2012-09-26 01:45 . 2012-08-21 21:01 245760 —-a-w- c:\windows\system32\OxpsConverter.exe 2012-09-16 18:35 . 2012-09-16 18:36 ——– d—–w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2012-09-16 18:35 . 2012-09-16 18:36 ——– d—–w- c:\program files\iTunes 2012-09-16 18:35 . 2012-09-16 18:36 ——– d—–w- c:\program files (x86)\iTunes 2012-09-16 18:35 . 2012-09-16 18:35 ——– d—–w- c:\program files\iPod 2012-09-15 13:43 . 2012-08-21 18:01 33240 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-09-13 01:27 . 2012-08-22 18:12 950128 —-a-w- c:\windows\system32\drivers\ndis.sys 2012-09-13 01:27 . 2012-07-04 20:26 41472 —-a-w- c:\windows\system32\drivers\RNDISMP.sys 2012-09-13 01:27 . 2012-08-02 17:58 574464 —-a-w- c:\windows\system32\d3d10level9.dll 2012-09-13 01:27 . 2012-08-02 16:57 490496 —-a-w- c:\windows\SysWow64\d3d10level9.dll 2012-09-13 01:27 . 2012-08-22 18:12 1913200 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-09-13 01:27 . 2012-08-22 18:12 376688 —-a-w- c:\windows\system32\drivers\netio.sys 2012-09-13 01:27 . 2012-08-22 18:12 288624 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-09-28 03:00 . 2012-03-29 12:38 696240 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-09-28 03:00 . 2011-05-13 22:55 73136 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-09-13 08:00 . 2011-04-01 03:44 64462936 —-a-w- c:\windows\system32\MRT.exe 2012-08-21 18:01 . 2011-04-24 02:42 125872 —-a-w- c:\windows\system32\GEARAspi64.dll 2012-08-21 18:01 . 2011-04-24 02:42 106928 —-a-w- c:\windows\SysWow64\GEARAspi.dll 2012-07-18 18:15 . 2012-08-16 00:48 3148800 —-a-w- c:\windows\system32\win32k.sys 2012-07-09 18:42 . 2012-07-09 18:42 4547984 —-a-w- c:\windows\system32\usbaaplrc.dll 2012-07-09 18:42 . 2012-07-09 18:42 52736 —-a-w- c:\windows\system32\drivers\usbaapl64.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ApplePhotoStreams"="c:\program files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2012-09-10 59280] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2011-09-16 115048] "ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-28 59280] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-11 919008] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-09-10 421776] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [x] R2 CLKMSVC10_9EC60124;CyberLink Product - 2011/03/16 09:25;c:\program files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-10-29 236016] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-09-04 219632] R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x] R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-13 114144] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-12-17 340240] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-09-04 1116656] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-03-27 1255736] R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856] S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [2010-08-20 21616] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\0404000.00C\SYMDS64.SYS [2009-10-15 433200] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\0404000.00C\SYMEFA64.SYS [2011-08-22 221304] S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20120928.001\BHDrvx64.sys [2012-08-31 1385120] S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360x64\0404000.00C\ccHPx64.sys [2011-08-04 593544] S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20120929.001\IDSvia64.sys [2012-09-06 513184] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\0404000.00C\Ironx64.SYS [2010-04-29 150064] S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\Drivers\N360x64\0404000.00C\SYMTDIV.SYS [2011-08-22 451704] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-17 98208] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624] S2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;c:\program files\Intel\WiMAX\Bin\DMAgent.exe [2010-11-07 499200] S2 N360;Norton Security Suite;c:\program files (x86)\Norton Security Suite\Engine\4.4.0.12\ccSvcHst.exe [2011-08-04 126400] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-10 2348352] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776] S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2010-08-20 689472] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-10 382272] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-11-29 16120] S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-12-20 2656280] S2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;c:\program files\Intel\WiMAX\Bin\AppSrv.exe [2010-11-07 869376] S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [2010-12-13 27760] S3 bpenum;Intel® Centrino® WiMAX Enumerator;c:\windows\system32\DRIVERS\bpenum.sys [2010-10-26 75264] S3 bpmp;Intel® Centrino® WiMAX 6050 Series;c:\windows\system32\DRIVERS\bpmp.sys [2010-10-26 173568] S3 bpusb;Intel® Centrino® WiMAX 6050 Series Function Driver;c:\windows\system32\Drivers\bpusb.sys [2010-10-26 81408] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2010-08-12 175168] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-08-09 138912] S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344] S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2010-12-22 8505856] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2011-09-13 95744] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2011-09-13 212992] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2012-01-17 188224] S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\DRIVERS\nvstusb.sys [2012-02-10 398144] S3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys [2010-07-13 29288] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] . . — Other Services/Drivers In Memory — . *Deregistered* - CLKMDRV10_9EC60124 . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-12-17 686704] "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-12-17 1933584] "IntelWirelessWiMAX"="c:\program files\Intel\WiMAX\Bin\WiMAXCU.exe" [2010-11-14 1605632] "IntelTBRunOnce"="wscript.exe" [2009-07-14 168960] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-02-18 6611048] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-01-18 2188904] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.yahoo.com/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com TCP: DhcpNameServer = 192.168.1.1 75.75.75.75 75.75.76.76 FF - ProfilePath - c:\users\Krystal\AppData\Roaming\Mozilla\Firefox\Profiles\xfy65lgs.default\ . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKLM-Run- - (no file) AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\N360] "ImagePath"="\"c:\program files (x86)\Norton Security Suite\Engine\4.4.0.12\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton Security Suite\Engine\4.4.0.12\diMaster.dll\" /prefetch:1" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-10-02 21:35:13 ComboFix-quarantined-files.txt 2012-10-03 02:35 ComboFix2.txt 2012-10-02 02:28 . Pre-Run: 369,893,634,048 bytes free Post-Run: 371,520,380,928 bytes free . - - End Of File - - 2B588FE887F6430A0B1BFA4E2798C3A5
Hi,

Adobe Reader

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 9.5.2 first. Be sure to move any PDF documents to another folder first though.
———-

I see that your Java software is out of date. Please go to Start >> Control Panel >> Programs and Features >> uninstall all versions of Java.

Now download and install the newest version from here >> http://java.com/en/download/index.jsp
————-

Clear Java Cache

See this page for instructions on how to clear java's cache.

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.
———-

Please download Malwarebytes Anti-Malware to your desktop.

  • Right-click and Run as Administrator mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.


The log can also be found here:

Windows 2000 & Windows XP:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs

Windows Vista & Win7:
C:\Users\\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs
———-

ESET Online Scanner

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
———-
Seems to be doing much better. No more redirects and seems to be faster now. Thanks for all your help. I really do appreciate it. My logs are below. Malwarebytes log: Malwarebytes Anti-Malware 1.65.0.1400 www.malwarebytes.org Database version: v2012.10.03.11 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Krystal :: KRYSTAL-LAPTOP [administrator] 10/3/2012 7:59:44 PM mbam-log-2012-10-03 (19-59-44).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 226447 Time elapsed: 4 minute(s), 10 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ESET log: C:\Program Files (x86)\Dell DataSafe Local Backup\hstart.exe a variant of Win32/HiddenStart.A application C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe a variant of Win32/HiddenStart.A application C:\Qoobox\Quarantine\C\Users\Krystal\AppData\Local\{3DCB023F-4E21-42BE-82BE-DF5909610CC5}\{359606B4-539E-4904-A6E9-682155F208BF}\ptfebc.dll.vir Win32/Kryptik.AMNF trojan C:\Users\Krystal\AppData\Roaming\Mozilla\Firefox\Profiles\xfy65lgs.default\extensions\[removed] JS/Redirector.NCA trojan C:\Users\Krystal\Downloads\Adaware_Installer.exe Win32/OpenCandy application
Hi,

Great! Good to hear your system is doing better. :)

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the box below:


    ClearJavaCache::

    File::
    C:\Users\Krystal\AppData\Roaming\Mozilla\Firefox\Profiles\xfy65lgs.default\extensions\[removed]
    C:\Users\Krystal\Downloads\Adaware_Installer.exe

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Post the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Again thank you for your help. ComboFix.txt log ComboFix 12-10-04.02 - Krystal 10/04/2012 20:30:52.3.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8152.6193 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Krystal\Desktop\CFScript.txt AV: Norton Security Suite *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} FW: Norton Security Suite *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} SP: Norton Security Suite *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\users\Krystal\AppData\Roaming\Mozilla\Firefox\Profiles\xfy65lgs.default\extensions\[removed]" "c:\users\Krystal\Downloads\Adaware_Installer.exe" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Krystal\AppData\Roaming\Mozilla\Firefox\Profiles\xfy65lgs.default\extensions\[removed] c:\users\Krystal\Downloads\Adaware_Installer.exe . . ((((((((((((((((((((((((( Files Created from 2012-09-05 to 2012-10-05 ))))))))))))))))))))))))))))))) . . 2012-10-05 01:36 . 2012-10-05 01:36 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2012-10-05 01:36 . 2012-10-05 01:36 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-10-04 01:05 . 2012-10-04 01:05 ——– d—–w- c:\program files (x86)\ESET 2012-10-04 00:59 . 2012-10-04 00:59 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-10-04 00:59 . 2012-09-07 22:04 25928 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-10-04 00:55 . 2012-10-04 00:55 ——– d—–w- c:\program files (x86)\Common Files\Java 2012-10-04 00:54 . 2012-10-04 00:54 821736 —-a-w- c:\windows\SysWow64\npDeployJava1.dll 2012-10-04 00:54 . 2012-10-04 00:54 95208 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2012-10-04 00:50 . 2012-10-04 00:50 ——– d—–w- c:\program files (x86)\Foxit Software 2012-10-04 00:26 . 2012-10-04 00:27 ——– d—–w- c:\program files (x86)\Google 2012-09-30 22:54 . 2012-09-30 22:54 ——– d—–w- c:\program files (x86)\VS Revo Group 2012-09-30 22:33 . 2012-09-30 22:33 ——– d—–w- c:\program files\Enigma Software Group 2012-09-30 22:32 . 2012-09-30 23:04 ——– d—–w- c:\windows\8C5C34C7BC6B48318B2C6535FE63E502.TMP 2012-09-30 22:32 . 2012-09-30 22:32 ——– d—–w- c:\program files (x86)\Common Files\Wise Installation Wizard 2012-09-30 17:53 . 2012-10-01 23:53 ——– d—–w- c:\program files (x86)\PC Tools 2012-09-30 17:51 . 2012-10-01 23:53 ——– d—–w- c:\program files (x86)\Common Files\PC Tools 2012-09-30 17:51 . 2012-06-22 20:35 251560 —-a-w- c:\windows\system32\drivers\PCTSD64.sys 2012-09-30 17:50 . 2012-10-01 02:28 ——– d—–w- c:\programdata\PC Tools 2012-09-30 17:50 . 2012-09-30 17:50 ——– d—–w- c:\users\Krystal\AppData\Roaming\TestApp 2012-09-30 17:48 . 2012-09-30 17:48 ——– d—–w- c:\program files (x86)\Toolbar Cleaner 2012-09-30 17:10 . 2012-10-01 02:28 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2012-09-30 17:10 . 2012-10-01 02:28 ——– d—–w- c:\program files (x86)\Spybot - Search & Destroy 2012-09-26 01:45 . 2012-08-21 21:01 245760 —-a-w- c:\windows\system32\OxpsConverter.exe 2012-09-16 18:35 . 2012-09-16 18:36 ——– d—–w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2012-09-16 18:35 . 2012-09-16 18:36 ——– d—–w- c:\program files\iTunes 2012-09-16 18:35 . 2012-09-16 18:36 ——– d—–w- c:\program files (x86)\iTunes 2012-09-16 18:35 . 2012-09-16 18:35 ——– d—–w- c:\program files\iPod 2012-09-15 13:43 . 2012-08-21 18:01 33240 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-09-13 01:27 . 2012-08-22 18:12 950128 —-a-w- c:\windows\system32\drivers\ndis.sys 2012-09-13 01:27 . 2012-07-04 20:26 41472 —-a-w- c:\windows\system32\drivers\RNDISMP.sys 2012-09-13 01:27 . 2012-08-02 17:58 574464 —-a-w- c:\windows\system32\d3d10level9.dll 2012-09-13 01:27 . 2012-08-02 16:57 490496 —-a-w- c:\windows\SysWow64\d3d10level9.dll 2012-09-13 01:27 . 2012-08-22 18:12 1913200 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-09-13 01:27 . 2012-08-22 18:12 376688 —-a-w- c:\windows\system32\drivers\netio.sys 2012-09-13 01:27 . 2012-08-22 18:12 288624 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-09-28 03:00 . 2012-03-29 12:38 696240 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-09-28 03:00 . 2011-05-13 22:55 73136 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-09-13 08:00 . 2011-04-01 03:44 64462936 —-a-w- c:\windows\system32\MRT.exe 2012-08-21 18:01 . 2011-04-24 02:42 125872 —-a-w- c:\windows\system32\GEARAspi64.dll 2012-08-21 18:01 . 2011-04-24 02:42 106928 —-a-w- c:\windows\SysWow64\GEARAspi.dll 2012-07-18 18:15 . 2012-08-16 00:48 3148800 —-a-w- c:\windows\system32\win32k.sys 2012-07-09 18:42 . 2012-07-09 18:42 4547984 —-a-w- c:\windows\system32\usbaaplrc.dll 2012-07-09 18:42 . 2012-07-09 18:42 52736 —-a-w- c:\windows\system32\drivers\usbaapl64.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ApplePhotoStreams"="c:\program files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2012-09-10 59280] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2011-09-16 115048] "ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-28 59280] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-09-10 421776] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [x] R2 CLKMSVC10_9EC60124;CyberLink Product - 2011/03/16 09:25;c:\program files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-10-29 236016] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-04 116648] R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-09-04 219632] R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x] R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-04 116648] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-09-13 114144] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-12-17 340240] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-09-04 1116656] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 TurboBoost;Intel® Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-11-29 149504] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-03-27 1255736] R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856] S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys [2010-08-20 21616] S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\0404000.00C\SYMDS64.SYS [2009-10-15 433200] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\0404000.00C\SYMEFA64.SYS [2011-08-22 221304] S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20120928.001\BHDrvx64.sys [2012-08-31 1385120] S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360x64\0404000.00C\ccHPx64.sys [2011-08-04 593544] S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20121004.001\IDSvia64.sys [2012-09-06 513184] S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\0404000.00C\Ironx64.SYS [2010-04-29 150064] S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\Drivers\N360x64\0404000.00C\SYMTDIV.SYS [2011-08-22 451704] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-17 98208] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624] S2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;c:\program files\Intel\WiMAX\Bin\DMAgent.exe [2010-11-07 499200] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-07 399432] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-07 676936] S2 N360;Norton Security Suite;c:\program files (x86)\Norton Security Suite\Engine\4.4.0.12\ccSvcHst.exe [2011-08-04 126400] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-02-10 2348352] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776] S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2010-08-20 689472] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-02-10 382272] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-11-29 16120] S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-12-20 2656280] S2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;c:\program files\Intel\WiMAX\Bin\AppSrv.exe [2010-11-07 869376] S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [2010-12-13 27760] S3 bpenum;Intel® Centrino® WiMAX Enumerator;c:\windows\system32\DRIVERS\bpenum.sys [2010-10-26 75264] S3 bpmp;Intel® Centrino® WiMAX 6050 Series;c:\windows\system32\DRIVERS\bpmp.sys [2010-10-26 173568] S3 bpusb;Intel® Centrino® WiMAX 6050 Series Function Driver;c:\windows\system32\Drivers\bpusb.sys [2010-10-26 81408] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2010-08-12 175168] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-08-09 138912] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-07 25928] S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344] S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2010-12-22 8505856] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2011-09-13 95744] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2011-09-13 212992] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2012-01-17 188224] S3 NvStUSB;NVIDIA Stereoscopic 3D USB driver;c:\windows\system32\DRIVERS\nvstusb.sys [2012-02-10 398144] S3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys [2010-07-13 29288] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920] . . — Other Services/Drivers In Memory — . *NewlyCreated* - MBAMPROTECTOR *Deregistered* - CLKMDRV10_9EC60124 . Contents of the 'Scheduled Tasks' folder . 2012-10-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-04 00:26] . 2012-10-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-04 00:26] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-12-17 686704] "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-12-17 1933584] "IntelWirelessWiMAX"="c:\program files\Intel\WiMAX\Bin\WiMAXCU.exe" [2010-11-14 1605632] "IntelTBRunOnce"="wscript.exe" [2009-07-14 168960] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-02-18 6611048] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-01-18 2188904] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.yahoo.com/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com TCP: DhcpNameServer = 192.168.1.1 75.75.75.75 75.75.76.76 FF - ProfilePath - c:\users\Krystal\AppData\Roaming\Mozilla\Firefox\Profiles\xfy65lgs.default\ . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKLM-Run- - (no file) AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\N360] "ImagePath"="\"c:\program files (x86)\Norton Security Suite\Engine\4.4.0.12\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton Security Suite\Engine\4.4.0.12\diMaster.dll\" /prefetch:1" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_278_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_278_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_278.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-10-04 20:38:09 ComboFix-quarantined-files.txt 2012-10-05 01:38 ComboFix2.txt 2012-10-03 02:35 ComboFix3.txt 2012-10-02 02:28 . Pre-Run: 369,978,130,432 bytes free Post-Run: 369,675,382,784 bytes free . - - End Of File - - 235356F852CAE241D685F45C0069B700
Providing there are no other malware related problems…

IT APPEARS THAT YOUR LOGS ARE NOW CLEAN :D SO LETS DO A COUPLE OF THINGS TO WRAP THIS UP!! :D

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.
———-

The following will implement some cleanup procedures as well as reset System Restore points:

Press the Windows key + R and this will open the Run box. Copy/paste the following text into the Run box as shown and click OK.
Combofix /Uninstall
(Note: There is a space between the ..X and the /U that needs to be there.)

[external image: Posted Image]
———-

Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.
If you didn't already have it I would keep Malwarebytes AntiMalware though.


Here are some tips to reduce the potential for spyware infection in the future:

1. Internet Explorer. Even if you don't use it as your main browser it should be kept up-to-date because that is the browser Windows uses for updates.
Make your Internet Explorer more secure
- This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. FireFox. If you use Firefox, I recommend installing the following add-ons to help make your Firefox browser more secure:
NoScript
AdBlock Plus

3. Enable Protected Mode in Internet Explorer. This helps Windows Vista users stay more protected from attack by running Internet Explorer with restricted privileges as well as reducing the ability to write, alter or destroy data on your system or install malicious code. To make sure this is running follow these steps:
  • Open Internet Explorer
  • Click on Tools > Internet Options
  • Press Security tab
  • Select Internet zone then place check next to Enable Protected Mode if not already done
  • Do the same for Local Intranet, Trusted Sites and Restricted Sites and then press Apply
  • Restart Internet Explorer and in the bottom right corner of your screen you will see Protected Mode: On showing you it is enabled.
4. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

5. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. I would personally only recommend using one of the following two below:
Online Armor Free
Agnitum Outpost Firewall Free

6. Make sure you keep your Windows OS current. Windows XP users can visit Windows update regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

7. WOT (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

8.Finally, I strongly recommend that you read How to Prevent Malware found here and also PC Safety and Security - What Do I Need?.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI