This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

IE & FireFox - Cannot Connect [Closed]

63 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

"IE Cannot display the webpage" & "Server Not Found" - reopening from "Closed" - apologies, never saw the reply

Most websites I try to enter I receive the two errors above (IE & FireFox)…but a small percentage of sites work without any problem at all (i.e. google, forums.whattheteck, etc). A few others kind of work…they will display plain text, but no graphics. This problem started last week and magically the next day my computer was running without issue, except for a few instances where graphics would not display correctly on the internet.

For no reason I can think of, this morning the major problem came back I described above.

I ran Malmarebytes and Security Essentials earlier today and they picked up a few Trojan & Backdoor viruses. After removing these viruses, I'm still having the same problem.

OTL Output

OTL logfile created on: 10/22/2012 4:40:57 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\PC\Documents
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 1.57 Gb Available Physical Memory | 54.65% Memory free
5.73 Gb Paging File | 4.33 Gb Available in Paging File | 75.45% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 222.43 Gb Total Space | 5.81 Gb Free Space | 2.61% Space Free | Partition Type: NTFS
Drive D: | 244.60 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: PC-PC | User Name: PC | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found – C:\Users\PC\My Documents\OTL.exe
PRC - [2012/10/19 16:27:36 | 000,917,984 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012/10/05 10:10:10 | 001,174,824 | —- | M] (Starfield Technologies) – C:\Program Files (x86)\Workspace\offSyncService.exe
PRC - [2012/09/29 19:54:26 | 000,766,536 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/09/29 19:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/09/29 19:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/21 09:43:24 | 001,559,832 | —- | M] (Starfield Technologies, LLC) – C:\Users\PC\AppData\Local\Workspace\wben.exe
PRC - [2012/09/18 21:34:49 | 000,034,496 | —- | M] () – C:\Users\PC\AppData\Local\Workspace\workspaceupdate.exe
PRC - [2012/07/27 16:51:38 | 000,823,224 | —- | M] (Adobe Systems Inc.) – C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
PRC - [2012/07/27 13:51:28 | 000,063,960 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/07/26 19:23:20 | 000,397,992 | —- | M] (Ask) – C:\Program Files (x86)\Ask.com\Updater\Updater.exe
PRC - [2011/06/17 13:33:04 | 000,272,528 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe
PRC - [2011/03/09 11:41:08 | 001,066,896 | —- | M] () – C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe
PRC - [2009/07/28 23:26:42 | 000,062,848 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files (x86)\Toshiba\ConfigFree\CFSwMgr.exe
PRC - [2009/07/14 22:10:30 | 000,042,368 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files (x86)\Toshiba\ConfigFree\CFProcSRVC.exe
PRC - [2009/07/13 18:24:00 | 000,304,496 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files (x86)\Toshiba\ConfigFree\NDSTray.exe
PRC - [2009/07/13 01:36:04 | 001,141,232 | —- | M] () – C:\Program Files (x86)\Roxio\Roxio Burn\Roxio Burn.exe
PRC - [2009/07/13 01:35:58 | 000,498,160 | —- | M] () – C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
PRC - [2009/03/10 21:51:20 | 000,046,448 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files (x86)\Toshiba\ConfigFree\CFSvcs.exe
PRC - [2009/01/14 00:33:40 | 000,034,088 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files (x86)\Toshiba\Utilities\KeNotify.exe


========== Modules (No Company Name) ==========

MOD - [2012/10/19 16:26:51 | 002,294,240 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012/09/18 21:34:49 | 000,034,496 | —- | M] () – C:\Users\PC\AppData\Local\Workspace\workspaceupdate.exe
MOD - [2010/11/17 17:16:56 | 000,067,872 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2009/07/13 01:36:04 | 001,141,232 | —- | M] () – C:\Program Files (x86)\Roxio\Roxio Burn\Roxio Burn.exe
MOD - [2009/07/13 01:35:58 | 000,498,160 | —- | M] () – C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
MOD - [2009/07/13 01:35:54 | 000,588,272 | —- | M] () – C:\Program Files (x86)\Roxio\Roxio Burn\BBEngineAS.dll
MOD - [2009/04/25 12:03:56 | 000,375,280 | —- | M] () – c:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\SQLite352.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/09/12 21:21:48 | 000,368,896 | —- | M] (Microsoft Corporation) [On_Demand | Running] – c:\Program Files\Microsoft Security Client\NisSrv.exe – (NisSrv)
SRV:64bit: - [2012/09/12 21:21:48 | 000,022,072 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\MsMpEng.exe – (MsMpSvc)
SRV:64bit: - [2011/03/09 11:10:40 | 000,288,768 | —- | M] (WDC) [Auto | Running] – C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe – (WDDMService)
SRV:64bit: - [2009/08/21 12:31:06 | 000,488,800 | —- | M] (TOSHIBA Corporation) [Auto | Running] – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe – (TosCoSrv)
SRV:64bit: - [2009/08/03 22:17:56 | 000,137,560 | —- | M] (TOSHIBA Corporation) [On_Demand | Running] – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe – (TOSHIBA HDD SSD Alert Service)
SRV:64bit: - [2009/07/28 19:48:06 | 000,140,632 | —- | M] (TOSHIBA Corporation) [Auto | Running] – C:\Windows\SysNative\TODDSrv.exe – (TODDSrv)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2012/10/19 16:27:34 | 000,115,168 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/10/09 07:39:24 | 000,250,808 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/10/05 10:10:10 | 001,174,824 | —- | M] (Starfield Technologies) [Auto | Running] – C:\Program Files (x86)\Workspace\offSyncService.exe – (File Backup)
SRV - [2012/09/29 19:54:26 | 000,676,936 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/09/29 19:54:26 | 000,399,432 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012/07/27 13:51:28 | 000,063,960 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/07/13 13:28:36 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2011/06/17 13:33:04 | 000,237,008 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe – (McComponentHostService)
SRV - [2011/03/09 11:41:10 | 000,491,920 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe – (WDSC)
SRV - [2011/03/09 11:41:08 | 001,066,896 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe – (WDFME)
SRV - [2011/02/11 13:45:52 | 000,054,136 | —- | M] (TOSHIBA Corporation) [On_Demand | Running] – C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe – (TMachInfo)
SRV - [2010/03/18 16:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/08/10 22:55:58 | 000,248,688 | —- | M] (TOSHIBA CORPORATION) [Auto | Running] – C:\Program Files (x86)\Toshiba\ConfigFree\CFIWmxSvcs64.exe – (cfWiMAXService)
SRV - [2009/07/14 22:10:30 | 000,042,368 | —- | M] (TOSHIBA CORPORATION) [Auto | Running] – C:\Program Files (x86)\Toshiba\ConfigFree\CFProcSRVC.exe – (ConfigFree Gadget Service)
SRV - [2009/06/10 17:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/03/10 21:51:20 | 000,046,448 | —- | M] (TOSHIBA CORPORATION) [Auto | Running] – C:\Program Files (x86)\Toshiba\ConfigFree\CFSvcs.exe – (ConfigFree Service)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/09/29 19:54:26 | 000,025,928 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2012/08/30 22:03:48 | 000,128,456 | —- | M] (Microsoft Corporation) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\NisDrvWFP.sys – (NisDrv)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/02/16 16:53:00 | 000,014,464 | —- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\wdcsam64.sys – (WDC_SAM)
DRV:64bit: - [2010/12/14 22:51:20 | 000,051,712 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/03/31 06:10:18 | 000,450,048 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\RTL8187B.sys – (RTL8187B)
DRV:64bit: - [2009/10/27 03:29:46 | 000,173,456 | —- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\PTUMWVsp.sys – (PTUMWVsp)
DRV:64bit: - [2009/10/27 03:29:40 | 000,173,456 | —- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\PTUMWNSP.sys – (PTUMWNSP)
DRV:64bit: - [2009/10/27 03:29:34 | 000,144,912 | —- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\PTUMWNET.sys – (PTUMWNET)
DRV:64bit: - [2009/10/27 03:29:26 | 000,173,456 | —- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\PTUMWMdm.sys – (PTUMWMdm)
DRV:64bit: - [2009/10/27 03:29:20 | 000,012,688 | —- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\PTUMWFLT.sys – (PTUMWFLT)
DRV:64bit: - [2009/10/27 03:29:14 | 000,173,456 | —- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\PTUMWCSP.sys – (PTUMWCSP)
DRV:64bit: - [2009/10/27 03:29:08 | 000,024,976 | —- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\PTUMWCDF.sys – (PTUMWCDF)
DRV:64bit: - [2009/10/27 03:29:00 | 000,071,056 | —- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\PTUMWBus.sys – (PTUMWBus)
DRV:64bit: - [2009/08/27 11:07:06 | 007,369,600 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2009/07/31 00:22:04 | 000,027,784 | —- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\tdcmdpst.sys – (tdcmdpst)
DRV:64bit: - [2009/07/31 00:02:36 | 000,044,912 | —- | M] (COMPAL ELECTRONIC INC.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\LPCFilter.sys – (LPCFilter)
DRV:64bit: - [2009/07/30 20:46:22 | 000,222,208 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV:64bit: - [2009/07/24 18:57:08 | 000,482,384 | —- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\tos_sps64.sys – (tos_sps64)
DRV:64bit: - [2009/07/20 20:48:32 | 000,274,480 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2009/07/14 18:31:18 | 000,026,840 | —- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\TVALZ_O.SYS – (TVALZ)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/09 06:00:00 | 000,055,280 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2009/06/10 17:01:06 | 001,146,880 | —- | M] (LSI Corp) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\agrsm64.sys – (AgereSoftModem)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/06/04 21:54:36 | 000,408,600 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/05/23 01:52:30 | 000,215,040 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2009/05/18 17:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV - [2009/07/13 21:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
DRV - [2009/05/25 15:43:58 | 000,043,032 | —- | M] (Smith Micro Inc.) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Verizon Wireless\VZAccess Manager\SMSIVZAM5X64.sys – (SMSIVZAM5X64)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {5FE48A63-03BD-4821-892B-64C593622D14}
IE:64bit: - HKLM\..\SearchScopes\{5FE48A63-03BD-4821-892B-64C593622D14}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSNA
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…A&bmod;=TSNA
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…A&bmod;=TSNA
IE - HKLM\..\SearchScopes,DefaultScope = {669AB064-BCAA-4A58-8D84-1C2B0F78786E}
IE - HKLM\..\SearchScopes\{669AB064-BCAA-4A58-8D84-1C2B0F78786E}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSNA

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…A&bmod;=TSNA
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/?pc=AVBR
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…A&bmod;=TSNA
IE - HKCU\..\SearchScopes,DefaultScope = {078E9A4A-EB4A-48EA-BA79-0232D8D7817C}
IE - HKCU\..\SearchScopes\{078E9A4A-EB4A-48EA-BA79-0232D8D7817C}: "URL" = http://www.google.com/search?sourceid=ie7&…1I7TSNA_enUS389
IE - HKCU\..\SearchScopes\{288575EA-507B-42CB-97BE-ACED08F1998A}: "URL" = http://www.bing.com/search?q={searchTerms}…3DF&pc;=AVBR
IE - HKCU\..\SearchScopes\{669AB064-BCAA-4A58-8D84-1C2B0F78786E}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSNA
IE - HKCU\..\SearchScopes\{B7B664DF-3AF9-4C8E-8148-F42BB7831D27}: "URL" = http://www.ask.com/web?o=15710&l;=dis&q;={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://search.yahoo.com/search?fr=mcafee&p;="
FF - prefs.js..extensions.enabledAddons: zoomext@starfield:1.4
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=mcafee&p;="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_4_402_287.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll (Best Buy)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll (Best Buy)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@starfield.com/off: C:\Users\PC\AppData\Roaming\Mozilla\Plugins\npoff.dll ( Starfield Technologies, LLC.)
FF - HKCU\Software\MozillaPlugins\@starfield.com/off64: C:\Users\PC\AppData\Roaming\Mozilla\Plugins\npoff64.dll ( Starfield Technologies, LLC.)
FF - HKCU\Software\MozillaPlugins\@starfield.com/wbe: C:\Users\PC\AppData\Roaming\Mozilla\Plugins\npwbe.dll (Starfield Technology, LLC)
FF - HKCU\Software\MozillaPlugins\@starfield.com/wbe64: C:\Users\PC\AppData\Roaming\Mozilla\Plugins\npwbe64.dll (Starfield Technology, LLC)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\PC\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\PC\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\PC\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\PC\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/09/11 11:35:07 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/09/17 13:11:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/10/19 16:27:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/09/11 11:35:07 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/10/19 16:27:37 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 16.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2012/09/18 21:35:11 | 000,000,000 | —D | M] (No name found) – C:\Users\PC\AppData\Roaming\Mozilla\Extensions
[2012/05/07 20:58:15 | 000,000,000 | —D | M] (No name found) – C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\pvf6o9mn.default\extensions
[2012/05/02 22:40:29 | 000,000,000 | —D | M] (Ask Toolbar) – C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\pvf6o9mn.default\extensions\[removed]
[2012/10/19 16:26:37 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/10/19 16:26:37 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/09/18 21:35:12 | 000,000,000 | —D | M] (Workspace Email Zoom) – C:\USERS\PC\APPDATA\ROAMING\MOZILLA\EXTENSIONS\{EC8030F7-C20A-464F-9B0E-13A3A9E97384}\ZOOMEXT@STARFIELD
[2012/10/19 16:27:36 | 000,261,600 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/09/12 09:00:40 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/09/19 10:19:03 | 000,002,024 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2012/10/19 16:26:47 | 000,002,058 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\18.0.1025.162\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.140.8 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java™ Platform SE 6 U14 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\18.0.1025.162\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Best Buy pc app Detector (Enabled) = C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Skype Click to Call = C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosNC] C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [KeNotify] C:\Program Files (x86)\Toshiba\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKCU..\Run: [Akamai NetSession Interface] "C:\Users\PC\AppData\Local\Akamai\netsession_win.exe" File not found
O4 - HKCU..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background File not found
O4 - HKCU..\Run: [Starfield Updater] C:\Users\PC\AppData\Local\Workspace\workspaceupdate.exe ()
O4 - HKCU..\Run: [wben] C:\Users\PC\AppData\Local\Workspace\wben.exe (Starfield Technologies, LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} http://cdn.scan.onecare.live.com/resource/…S/wlscctrl2.cab (Windows Live OneCare safety scanner control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4AAC1865-70C9-4D56-A74C-C1609AA0102E}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BAEBB794-CF1F-4234-BA12-AE94D8CEDC47}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/05/25 13:02:25 | 000,011,136 | R— | M] (ARRL - The national association for Amateur Radio) - D:\autorun.exe – [ CDFS ]
O32 - AutoRun File - [2011/05/25 13:02:25 | 000,000,166 | R— | M] () - D:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{0adb063e-f9bf-11df-8903-705ab6be5318}\Shell - "" = AutoRun
O33 - MountPoints2\{0adb063e-f9bf-11df-8903-705ab6be5318}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O33 - MountPoints2\{9c1c68b5-4bdc-11df-8e99-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{9c1c68b5-4bdc-11df-8e99-806e6f6e6963}\Shell\AutoRun\command - "" = D:\autorun.exe [open][1] "ARRL Setup.exe"
O33 - MountPoints2\{cdad683e-eb9d-11e1-a8be-b482fe6de9a9}\Shell - "" = AutoRun
O33 - MountPoints2\{cdad683e-eb9d-11e1-a8be-b482fe6de9a9}\Shell\AutoRun\command - "" = E:\VZAccess_Manager.exe /z detect
O33 - MountPoints2\{cdad684a-eb9d-11e1-a8be-b482fe6de9a9}\Shell - "" = AutoRun
O33 - MountPoints2\{cdad684a-eb9d-11e1-a8be-b482fe6de9a9}\Shell\AutoRun\command - "" = E:\VZAccess_Manager.exe /z detect
O33 - MountPoints2\{cdad6878-eb9d-11e1-a8be-7a8020000200}\Shell - "" = AutoRun
O33 - MountPoints2\{cdad6878-eb9d-11e1-a8be-7a8020000200}\Shell\AutoRun\command - "" = E:\VZAccess_Manager.exe /z detect
O33 - MountPoints2\{d8a0c3c1-eadd-11e1-8d22-705ab6be5318}\Shell - "" = AutoRun
O33 - MountPoints2\{d8a0c3c1-eadd-11e1-8d22-705ab6be5318}\Shell\AutoRun\command - "" = E:\unlock.exe autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/10/22 09:36:12 | 000,000,000 | —D | C] – C:\Users\PC\AppData\Local\Western_Digital
[2012/10/22 09:34:20 | 000,000,000 | —D | C] – C:\ProgramData\Western Digital
[2012/10/22 09:32:21 | 000,000,000 | —D | C] – C:\Program Files\Western Digital
[2012/10/22 09:32:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Western Digital
[2012/10/22 09:32:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WD SmartWare
[2012/10/19 16:26:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012/10/19 11:33:49 | 000,000,000 | —D | C] – C:\Users\PC\Documents\Sun Knowledge
[2012/10/11 16:46:06 | 000,000,000 | —D | C] – C:\Users\PC\AppData\Roaming\NCH Software
[2012/10/11 16:45:58 | 000,000,000 | —D | C] – C:\ProgramData\NCH Software
[2012/10/11 16:45:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\NCH Software
[2012/10/11 15:06:58 | 000,000,000 | —D | C] – C:\ProgramData\AVS4YOU
[2012/10/11 15:06:57 | 000,000,000 | —D | C] – C:\Users\PC\AppData\Roaming\AVS4YOU
[2012/10/11 15:06:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVSMedia
[2012/10/11 15:05:32 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\msxml3a.dll
[2012/10/11 15:05:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVS4YOU
[2012/10/11 07:24:17 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\kernel32.dll
[2012/10/11 07:24:17 | 000,424,448 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\KernelBase.dll
[2012/10/11 07:24:17 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\conhost.exe
[2012/10/11 07:24:17 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\winsrv.dll
[2012/10/11 07:24:15 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wow64.dll
[2012/10/11 07:24:15 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\setup16.exe
[2012/10/11 07:24:14 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wow64win.dll
[2012/10/11 07:24:14 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ntvdm64.dll
[2012/10/11 07:24:14 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntvdm64.dll
[2012/10/11 07:24:14 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wow64cpu.dll
[2012/10/11 07:24:14 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\wow32.dll
[2012/10/11 07:24:13 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\instnm.exe
[2012/10/11 07:24:13 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012/10/11 07:24:13 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012/10/11 07:24:13 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012/10/11 07:24:13 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/10/11 07:24:13 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/10/11 07:24:13 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012/10/11 07:24:13 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012/10/11 07:24:13 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012/10/11 07:24:13 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012/10/11 07:24:13 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012/10/11 07:24:13 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/10/11 07:24:13 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/10/11 07:24:13 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/10/11 07:24:13 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/10/11 07:24:13 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/10/11 07:24:13 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012/10/11 07:24:13 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012/10/11 07:24:13 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012/10/11 07:24:13 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012/10/11 07:24:13 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012/10/11 07:24:13 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012/10/11 07:24:13 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012/10/11 07:24:13 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/10/11 07:24:13 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012/10/11 07:24:13 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012/10/11 07:24:12 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012/10/11 07:24:12 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012/10/11 07:24:12 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012/10/11 07:24:11 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012/10/11 07:24:11 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012/10/11 07:24:09 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012/10/11 07:24:09 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012/10/11 07:24:09 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012/10/11 07:24:09 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012/10/11 07:24:09 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012/10/11 07:24:09 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012/10/11 07:24:09 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012/10/11 07:24:09 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012/10/11 07:24:06 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\user.exe
[2012/10/11 07:23:55 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wintrust.dll
[2012/10/11 07:23:19 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\crypt32.dll
[2012/10/11 07:23:16 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\cryptnet.dll
[2012/10/11 07:21:59 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ntoskrnl.exe
[2012/10/11 07:21:58 | 003,914,096 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntoskrnl.exe
[2012/10/11 07:21:57 | 003,968,880 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntkrnlpa.exe
[2012/10/10 14:46:56 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\PC\Documents\OTL.exe
[2012/10/10 14:07:01 | 000,000,000 | —D | C] – C:\Users\PC\AppData\Roaming\LavasoftStatistics
[2012/10/10 14:04:26 | 000,000,000 | —D | C] – C:\Users\PC\AppData\Roaming\Ad-Aware Antivirus
[2012/10/10 13:54:05 | 000,000,000 | —D | C] – C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012/10/10 13:54:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2012/10/10 11:42:04 | 000,000,000 | —D | C] – C:\Users\PC\AppData\Roaming\Malwarebytes
[2012/10/10 11:41:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/10/10 11:41:43 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/10/10 11:41:41 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\windows\SysNative\drivers\mbam.sys
[2012/10/10 11:41:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/10/10 07:55:35 | 000,000,000 | —D | C] – C:\Users\PC\Documents\My Received Files
[2012/10/09 11:28:32 | 000,000,000 | —D | C] – C:\Users\PC\Documents\Fragments
[2012/10/02 12:50:38 | 000,000,000 | —D | C] – C:\Users\PC\Documents\GMC4x4
[2012/10/01 21:42:19 | 000,000,000 | —D | C] – C:\perflogs
[2012/09/28 11:35:30 | 000,000,000 | —D | C] – C:\windows\rescache
[2012/09/26 07:25:22 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\OxpsConverter.exe
[2012/09/24 08:50:20 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\mshtmled.dll
[2012/09/24 08:50:20 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\mshtmled.dll
[2012/09/24 08:50:18 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieui.dll
[2012/09/24 08:50:17 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieui.dll
[2012/09/24 08:50:17 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieUnatt.exe
[2012/09/24 08:50:16 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieUnatt.exe
[2012/09/24 08:50:15 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\url.dll
[2012/09/24 08:50:15 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\url.dll
[2012/09/24 08:50:14 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\inetcpl.cpl
[2012/09/24 08:50:14 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\inetcpl.cpl
[2012/09/24 08:50:13 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\jscript9.dll
[2012/09/24 08:50:13 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\msfeeds.dll
[2012/09/24 08:50:09 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\jscript.dll
[2012/09/24 08:50:09 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\vbscript.dll
[2012/09/24 08:50:08 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\jscript.dll
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/10/22 16:43:25 | 000,016,304 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/22 16:43:25 | 000,016,304 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/22 16:39:00 | 000,000,830 | —- | M] () – C:\windows\tasks\Adobe Flash Player Updater.job
[2012/10/22 16:35:18 | 000,000,894 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/22 16:35:01 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2012/10/22 16:34:53 | 2309,660,672 | -HS- | M] () – C:\hiberfil.sys
[2012/10/22 16:22:00 | 000,000,896 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3206294807-2866115109-661179758-1000UA.job
[2012/10/22 15:55:00 | 000,000,898 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/22 12:22:05 | 000,000,844 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3206294807-2866115109-661179758-1000Core.job
[2012/10/22 09:32:53 | 000,001,329 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WDDMStatus.lnk
[2012/10/22 09:29:10 | 000,726,316 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2012/10/22 09:29:10 | 000,624,256 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2012/10/22 09:29:10 | 000,106,600 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2012/10/19 11:29:08 | 000,001,120 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/16 12:02:14 | 000,056,280 | —- | M] () – C:\Users\PC\Desktop\default_emoticons.zip
[2012/10/10 16:57:29 | 002,435,220 | —- | M] () – C:\Users\PC\Desktop\AvatarPicture.jpg
[2012/10/10 14:47:06 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\PC\Documents\OTL.exe
[2012/10/10 13:54:05 | 000,002,961 | —- | M] () – C:\Users\PC\Desktop\HiJackThis.lnk
[2012/10/10 13:26:37 | 000,002,385 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/10/09 07:39:23 | 000,696,760 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerApp.exe
[2012/10/09 07:39:23 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/10/02 23:29:38 | 000,001,945 | —- | M] () – C:\windows\epplauncher.mif
[2012/10/01 21:45:26 | 000,007,600 | —- | M] () – C:\Users\PC\AppData\Local\Resmon.ResmonCfg
[2012/09/29 19:54:26 | 000,025,928 | —- | M] (Malwarebytes Corporation) – C:\windows\SysNative\drivers\mbam.sys
[2012/09/26 17:55:10 | 010,706,596 | —- | M] () – C:\Users\PC\Desktop\IMG_5959.JPG
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/22 09:32:53 | 000,001,329 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WDDMStatus.lnk
[2012/10/16 12:02:14 | 000,056,280 | —- | C] () – C:\Users\PC\Desktop\default_emoticons.zip
[2012/10/10 13:54:05 | 000,002,961 | —- | C] () – C:\Users\PC\Desktop\HiJackThis.lnk
[2012/10/10 11:41:48 | 000,001,120 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/01 21:45:26 | 000,007,600 | —- | C] () – C:\Users\PC\AppData\Local\Resmon.ResmonCfg
[2012/09/26 17:55:08 | 010,706,596 | —- | C] () – C:\Users\PC\Desktop\IMG_5959.JPG
[2012/04/10 12:32:17 | 000,743,534 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2011/12/20 19:26:50 | 000,011,176 | -HS- | C] () – C:\Users\PC\AppData\Local\54i2l106d3cmf1p72m5rm
[2011/12/20 19:26:50 | 000,011,176 | -HS- | C] () – C:\ProgramData\54i2l106d3cmf1p72m5rm
[2011/01/07 11:59:42 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/07/24 16:43:27 | 000,000,114 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 01:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 00:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/10/10 14:05:45 | 000,000,000 | —D | M] – C:\Users\PC\AppData\Roaming\Ad-Aware Antivirus
[2011/03/16 15:58:32 | 000,000,000 | —D | M] – C:\Users\PC\AppData\Roaming\Amazon
[2012/10/19 11:14:49 | 000,000,000 | —D | M] – C:\Users\PC\AppData\Roaming\FileZilla
[2012/08/21 10:47:11 | 000,000,000 | —D | M] – C:\Users\PC\AppData\Roaming\Smith Micro
[2012/04/11 09:04:47 | 000,000,000 | —D | M] – C:\Users\PC\AppData\Roaming\Toshiba
[2010/07/24 09:04:22 | 000,000,000 | —D | M] – C:\Users\PC\AppData\Roaming\WinBatch

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/13 22:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 16:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 02:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 01:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 01:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 02:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 02:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 02:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 09:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 02:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 21:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 02:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 02:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2012/10/22 09:21:44 | 000,031,440 | —- | M] () MD5=79E745DCA445159C55B6E414E6061E78 – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf

< MD5 for: IEXPLORE.EXE >
[2011/11/05 01:28:03 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=0377589BF14A6E5667B730D6D6DB59B4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16912_none_0fae4f323e42a646\iexplore.exe
[2012/06/29 01:02:52 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2010/09/08 00:36:39 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=14803EA3E5DD7CB37CB446C74CFDA38F – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_1a39121b8bff3c23\iexplore.exe
[2012/08/24 03:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2012/08/24 03:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2011/04/22 16:15:52 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=281C23EC5BCB1853A5D571F1A6E52FB1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20949_none_101e7c5957724e1d\iexplore.exe
[2009/07/13 21:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_19ba3f8a72d988f3\iexplore.exe
[2012/08/24 07:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Program Files\Internet Explorer\iexplore.exe
[2012/08/24 07:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2011/08/20 00:35:15 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=41FE5E37EFE0B587A688BA0E4FA41288 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16869_none_19d3ea0872c5a830\iexplore.exe
[2011/11/05 01:34:31 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=441C397A9ECF07747920F7F5E40B419B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21085_none_0fef13a357968bc7\iexplore.exe
[2010/09/08 01:37:57 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=4879CB864E290BED38C5BDB641144B1B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_0fe467c9579e7a28\iexplore.exe
[2010/09/08 01:49:01 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=498035ABCCF1ED47AE6791D239187587 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_0f6c69ae3e743d20\iexplore.exe
[2010/11/04 01:54:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=58CF468D3FF4CF830339FE5E45356355 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16700_none_1a0bc510729d1f54\iexplore.exe
[2012/08/24 06:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012/06/28 22:45:31 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=5D03518409F37D1483C98869D86E23FF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2010/09/08 00:31:24 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=61EDBCE47ADF3E52AB0B9F49EE4AEBB8 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_19c1140072d4ff1b\iexplore.exe
[2012/08/24 03:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2011/04/22 15:29:16 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=64EFAF916C4009F1B84153D0BB491FB0 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16800_none_1a0bc6f6729d1c7b\iexplore.exe
[2010/11/04 01:54:59 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6B2258FF6D2332073FE9E90122FA4168 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20831_none_1a75f2618bd22c48\iexplore.exe
[2011/06/21 02:14:22 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=6B2383EDA3956983E3219A62D8408DAB – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20992_none_0fe16ab757a12871\iexplore.exe
[2011/06/21 01:25:30 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6BB506124872ACDFAC5BD912CA1334CE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20992_none_1a3615098c01ea6c\iexplore.exe
[2010/12/18 02:17:48 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=700B40EA39DFB25517A81032F03D6D20 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16722_none_0fa37b7a3e4ac7e9\iexplore.exe
[2010/11/20 09:28:25 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2010/12/18 02:11:10 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=8C6C32E4AF8A3D7155656F5897C504E0 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20861_none_1000d84b5789be20\iexplore.exe
[2011/11/05 00:38:00 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=8ED7C19AEFA3673AADB0D6864B03FBCE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16912_none_1a02f98472a36841\iexplore.exe
[2011/12/19 10:23:30 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2010/12/18 01:32:25 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=9321CF0D023528C71E3645F8433C86C8 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20861_none_1a55829d8bea801b\iexplore.exe
[2012/06/28 21:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2011/06/21 01:37:00 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=A3AB0A260049BE22AB52E302D9220A92 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16839_none_19f459cc72ad545d\iexplore.exe
[2011/11/05 00:39:45 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=A8A14CD0CB499B80412F75D53996AE29 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21085_none_1a43bdf58bf74dc2\iexplore.exe
[2010/12/18 01:33:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AA08B68EF4E35EFA170CF85A44B23B70 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16722_none_19f825cc72ab89e4\iexplore.exe
[2011/02/24 01:45:11 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AB2BB40A5FE49AD236791AC22BD08869 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_1a9d66118bb386fd\iexplore.exe
[2011/08/20 01:46:07 | 000,696,576 | —- | M] (Microsoft Corporation) MD5=AC1CC7CD5CBE60EFF105BB3C0DC199C5 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16869_none_0f7f3fb63e64e635\iexplore.exe
[2011/06/21 02:21:24 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=B38DE184AC135A4B0AE7D286476FA33F – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16839_none_0f9faf7a3e4c9262\iexplore.exe
[2011/02/24 02:29:19 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=B4881B8F6EDB48CABD44BCC9FB5475C4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_1048bbbf5752c502\iexplore.exe
[2010/11/20 08:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2011/02/24 01:32:52 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_19d0e74472c85f04\iexplore.exe
[2011/08/20 01:42:38 | 000,696,576 | —- | M] (Microsoft Corporation) MD5=C66C8BF791F9DB974022506265518EE0 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21033_none_102322ab576fcd64\iexplore.exe
[2011/04/22 16:16:25 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=D6F57A9ECB4606076FB9519D1698FCBA – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16800_none_0fb71ca43e3c5a80\iexplore.exe
[2010/11/04 02:37:41 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=D8E00EA671A1EFE95C69C7566C505AD4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16700_none_0fb71abe3e3c5d59\iexplore.exe
[2011/02/24 02:32:09 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=E1BBDE0F187194D4B08335234A4B9FC7 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_0f7c3cf23e679d09\iexplore.exe
[2010/11/04 02:42:22 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=E220FB009F54AAF649C6A278A5156764 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20831_none_1021480f57716a4d\iexplore.exe
[2012/06/28 19:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2011/12/19 10:23:24 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2009/07/13 21:43:43 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe
[2011/04/22 15:11:29 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=F94877A94996B3C12BB31AD722840457 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20949_none_1a7326ab8bd31018\iexplore.exe
[2011/08/20 00:32:44 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=FA623BE79902A7B49FF4F21117B63C83 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21033_none_1a77ccfd8bd08f5f\iexplore.exe

< MD5 for: IEXPLORE.EXE.2080.DMP >
[2012/09/19 22:23:10 | 006,756,969 | —- | M] () MD5=409992DB8E7992C14C2F73D93D6F072A – C:\Users\PC\AppData\Local\CrashDumps\iexplore.exe.2080.dmp

< MD5 for: IEXPLORE.EXE.2644.DMP >
[2012/09/19 22:22:44 | 006,786,853 | —- | M] () MD5=590F82A145717AAA9E7CDC8E8844D385 – C:\Users\PC\AppData\Local\CrashDumps\iexplore.exe.2644.dmp

< MD5 for: IEXPLORE.EXE.2952.DMP >
[2012/09/19 23:35:09 | 007,637,906 | —- | M] () MD5=9971015D4DCCF42FF36437387F2672E3 – C:\Users\PC\AppData\Local\CrashDumps\iexplore.exe.2952.dmp

< MD5 for: IEXPLORE.EXE.3196.DMP >
[2012/09/23 19:58:53 | 008,502,510 | —- | M] () MD5=9EFFEFEF5B1ACB655B94BAD2D3C06F25 – C:\Users\PC\AppData\Local\CrashDumps\iexplore.exe.3196.dmp

< MD5 for: IEXPLORE.EXE.3284.DMP >
[2012/09/24 16:14:01 | 006,898,513 | —- | M] () MD5=B4D135A143F73399B811EFC0090EC79C – C:\Users\PC\AppData\Local\CrashDumps\iexplore.exe.3284.dmp

< MD5 for: IEXPLORE.EXE.4876.DMP >
[2012/10/08 12:13:36 | 015,175,553 | —- | M] () MD5=FD078C73B8529CE319017A183F332E1E – C:\Users\PC\AppData\Local\CrashDumps\iexplore.exe.4876.dmp

< MD5 for: IEXPLORE.EXE.5040.DMP >
[2012/09/19 22:22:11 | 007,620,424 | —- | M] () MD5=2903BDFE82949078E9C4546BE4A4D940 – C:\Users\PC\AppData\Local\CrashDumps\iexplore.exe.5040.dmp

< MD5 for: IEXPLORE.EXE.5608.DMP >
[2012/09/28 11:41:55 | 007,985,830 | —- | M] () MD5=5CAFEE393DE8C34F0918215EFD1E555D – C:\Users\PC\AppData\Local\CrashDumps\iexplore.exe.5608.dmp

< MD5 for: IEXPLORE.EXE.MUI >
[2011/12/19 10:23:24 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2011/12/19 10:23:24 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011/12/19 10:23:30 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2011/12/19 10:23:30 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_09122aaf762607df\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_1366d501aa86c9da\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-4B6C9213.PF >
[2012/10/24 09:05:22 | 000,243,720 | —- | M] () MD5=80DDEAD00688D50AE5AF70E39C08D420 – C:\Windows\Prefetch\IEXPLORE.EXE-4B6C9213.pf

< MD5 for: SERVICES >
[2009/06/10 17:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.ASFX >
[2012/07/27 16:51:52 | 000,002,626 | —- | M] () MD5=8073B18DC740B965256CE0957E363AC5 – C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\fr_FR\Services\Services.asfx
[2012/07/27 16:51:54 | 000,002,655 | —- | M] () MD5=ABFBB9D0398492D849690C344C1316BB – C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Locale\de_DE\Services\Services.asfx

< MD5 for: SERVICES.CFG >
[2012/07/27 16:51:52 | 000,586,083 | —- | M] () MD5=6DE4EA437EC1FE6DB27CADB0A7EA8DC2 – C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Services\Services.cfg

< MD5 for: SERVICES.EXE >
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\windows\SysNative\en-US\services.exe.mui
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\windows\SysNative\wbem\services.mof
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\windows\SysNative\en-US\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\windows\SysNative\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2009/07/13 22:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\windows\SysNative\winlogon.exe
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 21:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/09/29 19:54:26 | 000,218,184 | —- | M] () MD5=8846E87210AD131CF71E3E2E49F647B0 – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/28 03:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 02:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 09:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\windows\SysNative\en-US\winlogon.exe.mui
[2010/11/20 09:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
[2009/07/13 22:29:52 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_26ed83321dc778e1\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\windows\SysNative\wbem\winlogon.mof
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2009/07/13 21:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2009/12/01 00:07:20 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2012/10/22 16:34:53 | 2309,660,672 | -HS- | M] () – C:\hiberfil.sys
[2012/10/22 16:35:01 | 3079,548,928 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/07/10 16:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\windows\WLXPGSS.SCR
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/12/19 10:29:43 | 000,000,221 | -HS- | M] () – C:\Users\PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >
I've run the OTL scan twice and the Extras file will not appear upon completion of the scan. I then moved to HiJackThis application to see if I would have better success and it will not write the log file. Any recommendations?
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and attach its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

Please download TDSSKiller
  • Double click TDSSKiller.exe
  • When the window opens, click on Change Parameters
  • Under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”
  • click OK
  • Press Start Scan
  • Do Not Attempt To Fix Anything Now. We just need to look over the report and be sure we are removing the correct
    items.
  • Attach the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-
Still here :) ASW output 08:37:19.0631 5060 TDSS rootkit removing tool [removed] Oct 12 2012 17:26:47 08:37:19.0926 5060 ============================================================ 08:37:19.0926 5060 Current date / time: 2012/10/25 08:37:19.0926 08:37:19.0926 5060 SystemInfo: 08:37:19.0926 5060 08:37:19.0926 5060 OS Version: 6.1.7601 ServicePack: 1.0 08:37:19.0926 5060 Product type: Workstation 08:37:19.0926 5060 ComputerName: PC-PC 08:37:19.0926 5060 UserName: PC 08:37:19.0926 5060 Windows directory: C:\windows 08:37:19.0926 5060 System windows directory: C:\windows 08:37:19.0926 5060 Running under WOW64 08:37:19.0926 5060 Processor architecture: Intel x64 08:37:19.0926 5060 Number of processors: 1 08:37:19.0926 5060 Page size: 0x1000 08:37:19.0926 5060 Boot type: Normal boot 08:37:19.0926 5060 ============================================================ 08:37:21.0861 5060 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 08:37:21.0911 5060 ============================================================ 08:37:21.0911 5060 \Device\Harddisk0\DR0: 08:37:21.0911 5060 MBR partitions: 08:37:21.0911 5060 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x1BCDE800 08:37:21.0911 5060 ============================================================ 08:37:21.0956 5060 C: <-> \Device\Harddisk0\DR0\Partition1 08:37:21.0956 5060 ============================================================ 08:37:21.0956 5060 Initialize success 08:37:21.0956 5060 ============================================================ 08:37:49.0836 5208 ============================================================ 08:37:49.0836 5208 Scan started 08:37:49.0836 5208 Mode: Manual; TDLFS; 08:37:49.0836 5208 ============================================================ 08:37:53.0171 5208 ================ Scan system memory ======================== 08:37:53.0171 5208 System memory - ok 08:37:53.0176 5208 ================ Scan services ============================= 08:37:53.0956 5208 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\windows\system32\drivers\1394ohci.sys 08:37:53.0961 5208 1394ohci - ok 08:37:54.0041 5208 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\windows\system32\drivers\ACPI.sys 08:37:54.0046 5208 ACPI - ok 08:37:54.0156 5208 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\windows\system32\drivers\acpipmi.sys 08:37:54.0156 5208 AcpiPmi - ok 08:37:54.0521 5208 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 08:37:54.0521 5208 AdobeARMservice - ok 08:37:55.0016 5208 [ 44C00A385CA9DBC1D5CF3781F8C26AEA ] AdobeFlashPlayerUpdateSvc C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 08:37:55.0021 5208 AdobeFlashPlayerUpdateSvc - ok 08:37:55.0156 5208 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\windows\system32\DRIVERS\adp94xx.sys 08:37:55.0161 5208 adp94xx - ok 08:37:55.0276 5208 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\windows\system32\DRIVERS\adpahci.sys 08:37:55.0281 5208 adpahci - ok 08:37:55.0321 5208 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\windows\system32\DRIVERS\adpu320.sys 08:37:55.0321 5208 adpu320 - ok 08:37:55.0396 5208 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\windows\System32\aelupsvc.dll 08:37:55.0396 5208 AeLookupSvc - ok 08:37:55.0526 5208 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\windows\system32\drivers\afd.sys 08:37:55.0531 5208 AFD - ok 08:37:55.0736 5208 [ 98022774D9930ECBB292E70DB7601DF6 ] AgereSoftModem C:\windows\system32\DRIVERS\agrsm64.sys 08:37:55.0751 5208 AgereSoftModem - ok 08:37:55.0896 5208 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\windows\system32\drivers\agp440.sys 08:37:55.0901 5208 agp440 - ok 08:37:56.0036 5208 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\windows\System32\alg.exe 08:37:56.0036 5208 ALG - ok 08:37:56.0141 5208 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\windows\system32\drivers\aliide.sys 08:37:56.0141 5208 aliide - ok 08:37:56.0206 5208 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\windows\system32\drivers\amdide.sys 08:37:56.0206 5208 amdide - ok 08:37:56.0286 5208 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\windows\system32\DRIVERS\amdk8.sys 08:37:56.0286 5208 AmdK8 - ok 08:37:56.0326 5208 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\windows\system32\DRIVERS\amdppm.sys 08:37:56.0326 5208 AmdPPM - ok 08:37:56.0451 5208 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\windows\system32\drivers\amdsata.sys 08:37:56.0451 5208 amdsata - ok 08:37:56.0501 5208 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\windows\system32\DRIVERS\amdsbs.sys 08:37:56.0501 5208 amdsbs - ok 08:37:56.0626 5208 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\windows\system32\drivers\amdxata.sys 08:37:56.0631 5208 amdxata - ok 08:37:56.0731 5208 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\windows\system32\drivers\appid.sys 08:37:56.0731 5208 AppID - ok 08:37:56.0766 5208 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\windows\System32\appidsvc.dll 08:37:56.0771 5208 AppIDSvc - ok 08:37:56.0876 5208 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\windows\System32\appinfo.dll 08:37:56.0876 5208 Appinfo - ok 08:37:57.0016 5208 [ 5AA788D5A2C6737BB9C45933985BC1B8 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 08:37:57.0016 5208 Apple Mobile Device - ok 08:37:57.0101 5208 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\windows\system32\DRIVERS\arc.sys 08:37:57.0101 5208 arc - ok 08:37:57.0161 5208 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\windows\system32\DRIVERS\arcsas.sys 08:37:57.0161 5208 arcsas - ok 08:37:57.0261 5208 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys 08:37:57.0261 5208 AsyncMac - ok 08:37:57.0461 5208 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\windows\system32\drivers\atapi.sys 08:37:57.0461 5208 atapi - ok 08:37:57.0586 5208 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll 08:37:57.0591 5208 AudioEndpointBuilder - ok 08:37:57.0611 5208 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\windows\System32\Audiosrv.dll 08:37:57.0616 5208 AudioSrv - ok 08:37:57.0731 5208 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\windows\System32\AxInstSV.dll 08:37:57.0731 5208 AxInstSV - ok 08:37:57.0881 5208 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\windows\system32\DRIVERS\bxvbda.sys 08:37:57.0891 5208 b06bdrv - ok 08:37:57.0986 5208 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\windows\system32\DRIVERS\b57nd60a.sys 08:37:57.0991 5208 b57nd60a - ok 08:37:58.0071 5208 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\windows\System32\bdesvc.dll 08:37:58.0071 5208 BDESVC - ok 08:37:58.0146 5208 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\windows\system32\drivers\Beep.sys 08:37:58.0146 5208 Beep - ok 08:37:58.0371 5208 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\windows\System32\bfe.dll 08:37:58.0381 5208 BFE - ok 08:37:58.0541 5208 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\windows\System32\qmgr.dll 08:37:58.0551 5208 BITS - ok 08:37:58.0621 5208 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\windows\system32\DRIVERS\blbdrive.sys 08:37:58.0621 5208 blbdrive - ok 08:37:58.0761 5208 [ F832F1505AD8B83474BD9A5B1B985E01 ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe 08:37:58.0766 5208 Bonjour Service - ok 08:37:58.0836 5208 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\windows\system32\DRIVERS\bowser.sys 08:37:58.0841 5208 bowser - ok 08:37:58.0876 5208 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\windows\system32\DRIVERS\BrFiltLo.sys 08:37:58.0876 5208 BrFiltLo - ok 08:37:58.0941 5208 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\windows\system32\DRIVERS\BrFiltUp.sys 08:37:58.0941 5208 BrFiltUp - ok 08:37:59.0006 5208 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\windows\System32\browser.dll 08:37:59.0011 5208 Browser - ok 08:37:59.0111 5208 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\windows\System32\Drivers\Brserid.sys 08:37:59.0116 5208 Brserid - ok 08:37:59.0131 5208 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\windows\System32\Drivers\BrSerWdm.sys 08:37:59.0131 5208 BrSerWdm - ok 08:37:59.0161 5208 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\windows\System32\Drivers\BrUsbMdm.sys 08:37:59.0161 5208 BrUsbMdm - ok 08:37:59.0196 5208 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\windows\System32\Drivers\BrUsbSer.sys 08:37:59.0196 5208 BrUsbSer - ok 08:37:59.0226 5208 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\windows\system32\DRIVERS\bthmodem.sys 08:37:59.0226 5208 BTHMODEM - ok 08:37:59.0311 5208 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\windows\system32\bthserv.dll 08:37:59.0316 5208 bthserv - ok 08:37:59.0401 5208 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\windows\system32\DRIVERS\cdfs.sys 08:37:59.0401 5208 cdfs - ok 08:37:59.0541 5208 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\windows\system32\DRIVERS\cdrom.sys 08:37:59.0541 5208 cdrom - ok 08:37:59.0656 5208 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\windows\System32\certprop.dll 08:37:59.0661 5208 CertPropSvc - ok 08:37:59.0786 5208 [ 837FF2D497880198C918E6954DBD170C ] cfWiMAXService C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe 08:37:59.0791 5208 cfWiMAXService - ok 08:37:59.0926 5208 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\windows\system32\DRIVERS\circlass.sys 08:37:59.0926 5208 circlass - ok 08:37:59.0981 5208 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\windows\system32\CLFS.sys 08:37:59.0986 5208 CLFS - ok 08:38:00.0076 5208 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 08:38:00.0081 5208 clr_optimization_v2.0.50727_32 - ok 08:38:00.0191 5208 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 08:38:00.0196 5208 clr_optimization_v2.0.50727_64 - ok 08:38:00.0346 5208 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 08:38:00.0351 5208 clr_optimization_v4.0.30319_32 - ok 08:38:00.0461 5208 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 08:38:00.0461 5208 clr_optimization_v4.0.30319_64 - ok 08:38:00.0536 5208 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\windows\system32\DRIVERS\CmBatt.sys 08:38:00.0536 5208 CmBatt - ok 08:38:00.0611 5208 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\windows\system32\drivers\cmdide.sys 08:38:00.0616 5208 cmdide - ok 08:38:00.0706 5208 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\windows\system32\Drivers\cng.sys 08:38:00.0711 5208 CNG - ok 08:38:00.0831 5208 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\windows\system32\DRIVERS\compbatt.sys 08:38:00.0831 5208 Compbatt - ok 08:38:00.0946 5208 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\windows\system32\drivers\CompositeBus.sys 08:38:00.0946 5208 CompositeBus - ok 08:38:00.0991 5208 COMSysApp - ok 08:38:01.0036 5208 [ D252C53BCDFC199BBA55EEB10CDB266E ] ConfigFree Gadget Service C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe 08:38:01.0036 5208 ConfigFree Gadget Service - ok 08:38:01.0096 5208 [ CAB0EEAF5295FC96DDD3E19DCE27E131 ] ConfigFree Service C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe 08:38:01.0096 5208 ConfigFree Service - ok 08:38:01.0176 5208 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\windows\system32\DRIVERS\crcdisk.sys 08:38:01.0176 5208 crcdisk - ok 08:38:01.0316 5208 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\windows\system32\cryptsvc.dll 08:38:01.0316 5208 CryptSvc - ok 08:38:01.0436 5208 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\windows\system32\rpcss.dll 08:38:01.0441 5208 DcomLaunch - ok 08:38:01.0556 5208 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\windows\System32\defragsvc.dll 08:38:01.0556 5208 defragsvc - ok 08:38:01.0636 5208 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\windows\system32\Drivers\dfsc.sys 08:38:01.0636 5208 DfsC - ok 08:38:01.0736 5208 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\windows\system32\dhcpcore.dll 08:38:01.0741 5208 Dhcp - ok 08:38:01.0781 5208 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\windows\system32\drivers\discache.sys 08:38:01.0786 5208 discache - ok 08:38:01.0831 5208 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\windows\system32\DRIVERS\disk.sys 08:38:01.0831 5208 Disk - ok 08:38:01.0921 5208 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\windows\System32\dnsrslvr.dll 08:38:01.0921 5208 Dnscache - ok 08:38:02.0001 5208 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\windows\System32\dot3svc.dll 08:38:02.0006 5208 dot3svc - ok 08:38:02.0131 5208 [ B42ED0320C6E41102FDE0005154849BB ] Dot4 C:\windows\system32\DRIVERS\Dot4.sys 08:38:02.0136 5208 Dot4 - ok 08:38:02.0221 5208 [ E9F5969233C5D89F3C35E3A66A52A361 ] Dot4Print C:\windows\system32\drivers\Dot4Prt.sys 08:38:02.0221 5208 Dot4Print - ok 08:38:02.0366 5208 [ FD05A02B0370BC3000F402E543CA5814 ] dot4usb C:\windows\system32\DRIVERS\dot4usb.sys 08:38:02.0366 5208 dot4usb - ok 08:38:02.0421 5208 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\windows\system32\dps.dll 08:38:02.0426 5208 DPS - ok 08:38:02.0531 5208 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\windows\system32\drivers\drmkaud.sys 08:38:02.0531 5208 drmkaud - ok 08:38:02.0661 5208 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys 08:38:02.0671 5208 DXGKrnl - ok 08:38:02.0741 5208 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\windows\System32\eapsvc.dll 08:38:02.0746 5208 EapHost - ok 08:38:02.0901 5208 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\windows\system32\DRIVERS\evbda.sys 08:38:02.0976 5208 ebdrv - ok 08:38:03.0031 5208 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\windows\System32\lsass.exe 08:38:03.0036 5208 EFS - ok 08:38:03.0271 5208 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\windows\ehome\ehRecvr.exe 08:38:03.0301 5208 ehRecvr - ok 08:38:03.0381 5208 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\windows\ehome\ehsched.exe 08:38:03.0381 5208 ehSched - ok 08:38:03.0626 5208 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\windows\system32\DRIVERS\elxstor.sys 08:38:03.0656 5208 elxstor - ok 08:38:03.0716 5208 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\windows\system32\drivers\errdev.sys 08:38:03.0716 5208 ErrDev - ok 08:38:03.0936 5208 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\windows\system32\es.dll 08:38:03.0946 5208 EventSystem - ok 08:38:03.0991 5208 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\windows\system32\drivers\exfat.sys 08:38:03.0996 5208 exfat - ok 08:38:04.0091 5208 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\windows\system32\drivers\fastfat.sys 08:38:04.0091 5208 fastfat - ok 08:38:04.0206 5208 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\windows\system32\fxssvc.exe 08:38:04.0221 5208 Fax - ok 08:38:04.0261 5208 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\windows\system32\DRIVERS\fdc.sys 08:38:04.0261 5208 fdc - ok 08:38:04.0316 5208 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\windows\system32\fdPHost.dll 08:38:04.0316 5208 fdPHost - ok 08:38:04.0341 5208 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\windows\system32\fdrespub.dll 08:38:04.0346 5208 FDResPub - ok 08:38:04.0631 5208 [ D3B8DDF0731ADB88B1336231DADB8DD9 ] File Backup C:\Program Files (x86)\Workspace\offSyncService.exe 08:38:04.0646 5208 File Backup - ok 08:38:04.0721 5208 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\windows\system32\drivers\fileinfo.sys 08:38:04.0721 5208 FileInfo - ok 08:38:04.0751 5208 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\windows\system32\drivers\filetrace.sys 08:38:04.0751 5208 Filetrace - ok 08:38:04.0776 5208 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\windows\system32\DRIVERS\flpydisk.sys 08:38:04.0781 5208 flpydisk - ok 08:38:04.0891 5208 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\windows\system32\drivers\fltmgr.sys 08:38:04.0896 5208 FltMgr - ok 08:38:05.0061 5208 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\windows\system32\FntCache.dll 08:38:05.0076 5208 FontCache - ok 08:38:05.0211 5208 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 08:38:05.0211 5208 FontCache3.0.0.0 - ok 08:38:05.0291 5208 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\windows\system32\drivers\FsDepends.sys 08:38:05.0296 5208 FsDepends - ok 08:38:05.0376 5208 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys 08:38:05.0381 5208 Fs_Rec - ok 08:38:05.0506 5208 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\windows\system32\DRIVERS\fvevol.sys 08:38:05.0506 5208 fvevol - ok 08:38:05.0631 5208 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\windows\system32\DRIVERS\gagp30kx.sys 08:38:05.0631 5208 gagp30kx - ok 08:38:05.0821 5208 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\windows\system32\DRIVERS\GEARAspiWDM.sys 08:38:05.0821 5208 GEARAspiWDM - ok 08:38:05.0996 5208 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\windows\System32\gpsvc.dll 08:38:06.0006 5208 gpsvc - ok 08:38:06.0241 5208 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 08:38:06.0241 5208 gupdate - ok 08:38:06.0451 5208 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 08:38:06.0456 5208 gupdatem - ok 08:38:06.0566 5208 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\windows\system32\drivers\hcw85cir.sys 08:38:06.0566 5208 hcw85cir - ok 08:38:06.0871 5208 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys 08:38:06.0941 5208 HdAudAddService - ok 08:38:07.0191 5208 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\windows\system32\drivers\HDAudBus.sys 08:38:07.0211 5208 HDAudBus - ok 08:38:07.0271 5208 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\windows\system32\DRIVERS\HidBatt.sys 08:38:07.0271 5208 HidBatt - ok 08:38:07.0296 5208 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\windows\system32\DRIVERS\hidbth.sys 08:38:07.0296 5208 HidBth - ok 08:38:07.0326 5208 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\windows\system32\DRIVERS\hidir.sys 08:38:07.0331 5208 HidIr - ok 08:38:07.0411 5208 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\windows\system32\hidserv.dll 08:38:07.0416 5208 hidserv - ok 08:38:07.0606 5208 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\windows\system32\DRIVERS\hidusb.sys 08:38:07.0611 5208 HidUsb - ok 08:38:07.0736 5208 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\windows\system32\kmsvc.dll 08:38:07.0741 5208 hkmsvc - ok 08:38:07.0811 5208 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\windows\system32\ListSvc.dll 08:38:07.0816 5208 HomeGroupListener - ok 08:38:07.0901 5208 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\windows\system32\provsvc.dll 08:38:07.0906 5208 HomeGroupProvider - ok 08:38:08.0371 5208 [ 0A3C6AA4A9FC38C20BA4EAC2C3351C05 ] hpqcxs08 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll 08:38:08.0371 5208 hpqcxs08 - ok 08:38:08.0446 5208 [ F3F72A2A86C22610BCA5439FA789DD52 ] hpqddsvc C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll 08:38:08.0451 5208 hpqddsvc - ok 08:38:08.0646 5208 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\windows\system32\drivers\HpSAMD.sys 08:38:08.0646 5208 HpSAMD - ok 08:38:08.0751 5208 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\windows\system32\drivers\HTTP.sys 08:38:08.0761 5208 HTTP - ok 08:38:08.0826 5208 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\windows\system32\drivers\hwpolicy.sys 08:38:08.0826 5208 hwpolicy - ok 08:38:08.0931 5208 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\windows\system32\drivers\i8042prt.sys 08:38:08.0936 5208 i8042prt - ok 08:38:09.0006 5208 [ 1D004CB1DA6323B1F55CAEF7F94B61D9 ] iaStor C:\windows\system32\DRIVERS\iaStor.sys 08:38:09.0021 5208 iaStor - ok 08:38:09.0186 5208 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\windows\system32\drivers\iaStorV.sys 08:38:09.0191 5208 iaStorV - ok 08:38:09.0431 5208 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 08:38:09.0541 5208 idsvc - ok 08:38:10.0161 5208 [ 3C3F27002ABC69C5AFE29CBE6CF7ADDF ] igfx C:\windows\system32\DRIVERS\igdkmd64.sys 08:38:10.0326 5208 igfx - ok 08:38:10.0371 5208 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\windows\system32\DRIVERS\iirsp.sys 08:38:10.0376 5208 iirsp - ok 08:38:10.0461 5208 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\windows\System32\ikeext.dll 08:38:10.0476 5208 IKEEXT - ok 08:38:10.0721 5208 [ 0C3CF4B3BAE28E121A1689E3538F8712 ] IntcAzAudAddService C:\windows\system32\drivers\RTKVHD64.sys 08:38:10.0776 5208 IntcAzAudAddService - ok 08:38:10.0811 5208 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\windows\system32\drivers\intelide.sys 08:38:10.0811 5208 intelide - ok 08:38:10.0861 5208 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\windows\system32\DRIVERS\intelppm.sys 08:38:10.0861 5208 intelppm - ok 08:38:10.0946 5208 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\windows\system32\ipbusenum.dll 08:38:10.0951 5208 IPBusEnum - ok 08:38:11.0001 5208 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys 08:38:11.0001 5208 IpFilterDriver - ok 08:38:11.0101 5208 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\windows\System32\iphlpsvc.dll 08:38:11.0106 5208 iphlpsvc - ok 08:38:11.0156 5208 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\windows\system32\drivers\IPMIDrv.sys 08:38:11.0156 5208 IPMIDRV - ok 08:38:11.0191 5208 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\windows\system32\drivers\ipnat.sys 08:38:11.0191 5208 IPNAT - ok 08:38:11.0416 5208 [ 3D62FE4FEFE9C67DAFEC52B534DFA1FB ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 08:38:11.0431 5208 iPod Service - ok 08:38:11.0496 5208 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\windows\system32\drivers\irenum.sys 08:38:11.0496 5208 IRENUM - ok 08:38:11.0541 5208 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\windows\system32\drivers\isapnp.sys 08:38:11.0546 5208 isapnp - ok 08:38:11.0661 5208 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\windows\system32\drivers\msiscsi.sys 08:38:11.0666 5208 iScsiPrt - ok 08:38:11.0771 5208 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\windows\system32\drivers\kbdclass.sys 08:38:11.0776 5208 kbdclass - ok 08:38:11.0911 5208 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\windows\system32\drivers\kbdhid.sys 08:38:11.0911 5208 kbdhid - ok 08:38:11.0976 5208 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\windows\system32\lsass.exe 08:38:12.0091 5208 KeyIso - ok 08:38:12.0186 5208 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\windows\system32\Drivers\ksecdd.sys 08:38:12.0186 5208 KSecDD - ok 08:38:12.0246 5208 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\windows\system32\Drivers\ksecpkg.sys 08:38:12.0251 5208 KSecPkg - ok 08:38:12.0306 5208 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\windows\system32\drivers\ksthunk.sys 08:38:12.0306 5208 ksthunk - ok 08:38:12.0356 5208 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\windows\system32\msdtckrm.dll 08:38:12.0361 5208 KtmRm - ok 08:38:12.0446 5208 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\windows\system32\srvsvc.dll 08:38:12.0446 5208 LanmanServer - ok 08:38:12.0546 5208 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\windows\System32\wkssvc.dll 08:38:12.0551 5208 LanmanWorkstation - ok 08:38:12.0606 5208 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\windows\system32\DRIVERS\lltdio.sys 08:38:12.0606 5208 lltdio - ok 08:38:12.0696 5208 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\windows\System32\lltdsvc.dll 08:38:12.0706 5208 lltdsvc - ok 08:38:12.0741 5208 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\windows\System32\lmhsvc.dll 08:38:12.0746 5208 lmhosts - ok 08:38:12.0856 5208 [ 41E122F6D1448C94CC05196BC41D6BFB ] LPCFilter C:\windows\system32\DRIVERS\LPCFilter.sys 08:38:12.0856 5208 LPCFilter - ok 08:38:12.0971 5208 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\windows\system32\DRIVERS\lsi_fc.sys 08:38:12.0976 5208 LSI_FC - ok 08:38:13.0001 5208 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\windows\system32\DRIVERS\lsi_sas.sys 08:38:13.0001 5208 LSI_SAS - ok 08:38:13.0066 5208 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\windows\system32\DRIVERS\lsi_sas2.sys 08:38:13.0071 5208 LSI_SAS2 - ok 08:38:13.0096 5208 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\windows\system32\DRIVERS\lsi_scsi.sys 08:38:13.0096 5208 LSI_SCSI - ok 08:38:13.0136 5208 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\windows\system32\drivers\luafv.sys 08:38:13.0141 5208 luafv - ok 08:38:13.0316 5208 [ A8FE8F2783B2929B56F5370A89356CE9 ] MBAMProtector C:\windows\system32\drivers\mbam.sys 08:38:13.0316 5208 MBAMProtector - ok 08:38:13.0576 5208 [ 85B16A92B117A5A800032ECD904B86DB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe 08:38:13.0576 5208 MBAMScheduler - ok 08:38:13.0831 5208 [ 20E2469DB709FC675E655CEAA11BE312 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe 08:38:13.0841 5208 MBAMService - ok 08:38:14.0166 5208 [ 22A7776C5D8EB5930EDF9C8DD0884259 ] McComponentHostService C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe 08:38:14.0171 5208 McComponentHostService - ok 08:38:14.0221 5208 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\windows\system32\Mcx2Svc.dll 08:38:14.0221 5208 Mcx2Svc - ok 08:38:14.0336 5208 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\windows\system32\DRIVERS\megasas.sys 08:38:14.0336 5208 megasas - ok 08:38:14.0386 5208 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\windows\system32\DRIVERS\MegaSR.sys 08:38:14.0391 5208 MegaSR - ok 08:38:14.0481 5208 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\windows\system32\mmcss.dll 08:38:14.0481 5208 MMCSS - ok 08:38:14.0526 5208 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\windows\system32\drivers\modem.sys 08:38:14.0526 5208 Modem - ok 08:38:14.0656 5208 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\windows\system32\DRIVERS\monitor.sys 08:38:14.0656 5208 monitor - ok 08:38:14.0736 5208 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\windows\system32\DRIVERS\mouclass.sys 08:38:14.0741 5208 mouclass - ok 08:38:14.0816 5208 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\windows\system32\DRIVERS\mouhid.sys 08:38:14.0816 5208 mouhid - ok 08:38:14.0891 5208 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\windows\system32\drivers\mountmgr.sys 08:38:14.0891 5208 mountmgr - ok 08:38:15.0081 5208 [ 4D7F2682D29B92A6251B17957AA0B985 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 08:38:15.0081 5208 MozillaMaintenance - ok 08:38:15.0351 5208 [ 05BF204EC0E82CC4A054DB189C8A3D84 ] MpFilter C:\windows\system32\DRIVERS\MpFilter.sys 08:38:15.0356 5208 MpFilter - ok 08:38:15.0451 5208 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\windows\system32\drivers\mpio.sys 08:38:15.0456 5208 mpio - ok 08:38:15.0526 5208 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys 08:38:15.0526 5208 mpsdrv - ok 08:38:15.0691 5208 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\windows\system32\mpssvc.dll 08:38:15.0706 5208 MpsSvc - ok 08:38:15.0751 5208 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\windows\system32\drivers\mrxdav.sys 08:38:15.0756 5208 MRxDAV - ok 08:38:15.0866 5208 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys 08:38:15.0866 5208 mrxsmb - ok 08:38:15.0966 5208 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys 08:38:15.0966 5208 mrxsmb10 - ok 08:38:16.0046 5208 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys 08:38:16.0046 5208 mrxsmb20 - ok 08:38:16.0131 5208 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\windows\system32\drivers\msahci.sys 08:38:16.0131 5208 msahci - ok 08:38:16.0221 5208 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\windows\system32\drivers\msdsm.sys 08:38:16.0226 5208 msdsm - ok 08:38:16.0271 5208 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\windows\System32\msdtc.exe 08:38:16.0286 5208 MSDTC - ok 08:38:16.0416 5208 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\windows\system32\drivers\Msfs.sys 08:38:16.0416 5208 Msfs - ok 08:38:16.0506 5208 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\windows\System32\drivers\mshidkmdf.sys 08:38:16.0511 5208 mshidkmdf - ok 08:38:16.0536 5208 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\windows\system32\drivers\msisadrv.sys 08:38:16.0536 5208 msisadrv - ok 08:38:16.0606 5208 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\windows\system32\iscsiexe.dll 08:38:16.0611 5208 MSiSCSI - ok 08:38:16.0631 5208 msiserver - ok 08:38:16.0676 5208 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys 08:38:16.0676 5208 MSKSSRV - ok 08:38:16.0786 5208 [ CC8E4F72F21340A4D3A3D4DB50313EF5 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe 08:38:16.0786 5208 MsMpSvc - ok 08:38:16.0846 5208 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys 08:38:16.0846 5208 MSPCLOCK - ok 08:38:16.0856 5208 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\windows\system32\drivers\MSPQM.sys 08:38:16.0856 5208 MSPQM - ok 08:38:16.0931 5208 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\windows\system32\drivers\MsRPC.sys 08:38:16.0936 5208 MsRPC - ok 08:38:17.0026 5208 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\windows\system32\drivers\mssmbios.sys 08:38:17.0051 5208 mssmbios - ok 08:38:17.0106 5208 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\windows\system32\drivers\MSTEE.sys 08:38:17.0106 5208 MSTEE - ok 08:38:17.0136 5208 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\windows\system32\DRIVERS\MTConfig.sys 08:38:17.0136 5208 MTConfig - ok 08:38:17.0171 5208 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\windows\system32\Drivers\mup.sys 08:38:17.0171 5208 Mup - ok 08:38:17.0281 5208 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\windows\system32\qagentRT.dll 08:38:17.0286 5208 napagent - ok 08:38:17.0546 5208 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys 08:38:17.0551 5208 NativeWifiP - ok 08:38:17.0761 5208 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\windows\system32\drivers\ndis.sys 08:38:17.0771 5208 NDIS - ok 08:38:17.0851 5208 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\windows\system32\DRIVERS\ndiscap.sys 08:38:17.0851 5208 NdisCap - ok 08:38:17.0896 5208 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys 08:38:17.0901 5208 NdisTapi - ok 08:38:17.0966 5208 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys 08:38:17.0971 5208 Ndisuio - ok 08:38:18.0041 5208 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys 08:38:18.0046 5208 NdisWan - ok 08:38:18.0126 5208 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\windows\system32\drivers\NDProxy.sys 08:38:18.0126 5208 NDProxy - ok 08:38:18.0311 5208 [ 2334DC48997BA203B794DF3EE70521DB ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll 08:38:18.0311 5208 Net Driver HPZ12 - ok 08:38:18.0371 5208 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys 08:38:18.0371 5208 NetBIOS - ok 08:38:18.0451 5208 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\windows\system32\DRIVERS\netbt.sys 08:38:18.0461 5208 NetBT - ok 08:38:18.0491 5208 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\windows\system32\lsass.exe 08:38:18.0491 5208 Netlogon - ok 08:38:18.0616 5208 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\windows\System32\netman.dll 08:38:18.0621 5208 Netman - ok 08:38:18.0656 5208 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\windows\System32\netprofm.dll 08:38:18.0661 5208 netprofm - ok 08:38:18.0701 5208 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 08:38:18.0726 5208 NetTcpPortSharing - ok 08:38:18.0801 5208 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\windows\system32\DRIVERS\nfrd960.sys 08:38:18.0806 5208 nfrd960 - ok 08:38:18.0946 5208 [ 5FF89F20317309D28AC1EDEB0CD1BA72 ] NisDrv C:\windows\system32\DRIVERS\NisDrvWFP.sys 08:38:18.0946 5208 NisDrv - ok 08:38:19.0106 5208 [ 79E80B10FE8F6662E0C9162A68C43444 ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe 08:38:19.0111 5208 NisSrv - ok 08:38:19.0381 5208 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\windows\System32\nlasvc.dll 08:38:19.0391 5208 NlaSvc - ok 08:38:19.0451 5208 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\windows\system32\drivers\Npfs.sys 08:38:19.0451 5208 Npfs - ok 08:38:19.0506 5208 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\windows\system32\nsisvc.dll 08:38:19.0506 5208 nsi - ok 08:38:19.0546 5208 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\windows\system32\drivers\nsiproxy.sys 08:38:19.0551 5208 nsiproxy - ok 08:38:19.0971 5208 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\windows\system32\drivers\Ntfs.sys 08:38:20.0026 5208 Ntfs - ok 08:38:20.0186 5208 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\windows\system32\drivers\Null.sys 08:38:20.0186 5208 Null - ok 08:38:20.0276 5208 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\windows\system32\drivers\nvraid.sys 08:38:20.0276 5208 nvraid - ok 08:38:20.0321 5208 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\windows\system32\drivers\nvstor.sys 08:38:20.0326 5208 nvstor - ok 08:38:20.0451 5208 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\windows\system32\drivers\nv_agp.sys 08:38:20.0456 5208 nv_agp - ok 08:38:20.0586 5208 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\windows\system32\drivers\ohci1394.sys 08:38:20.0591 5208 ohci1394 - ok 08:38:20.0701 5208 [ 4965B005492CBA7719E82B71E3245495 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 08:38:20.0706 5208 ose64 - ok 08:38:21.0726 5208 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 08:38:21.0836 5208 osppsvc - ok 08:38:21.0916 5208 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\windows\system32\pnrpsvc.dll 08:38:21.0921 5208 p2pimsvc - ok 08:38:21.0971 5208 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\windows\system32\p2psvc.dll 08:38:21.0981 5208 p2psvc - ok 08:38:22.0056 5208 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\windows\system32\DRIVERS\parport.sys 08:38:22.0061 5208 Parport - ok 08:38:22.0136 5208 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\windows\system32\drivers\partmgr.sys 08:38:22.0146 5208 partmgr - ok 08:38:22.0186 5208 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\windows\System32\pcasvc.dll 08:38:22.0196 5208 PcaSvc - ok 08:38:22.0256 5208 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\windows\system32\drivers\pci.sys 08:38:22.0256 5208 pci - ok 08:38:22.0331 5208 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\windows\system32\drivers\pciide.sys 08:38:22.0331 5208 pciide - ok 08:38:22.0381 5208 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\windows\system32\DRIVERS\pcmcia.sys 08:38:22.0381 5208 pcmcia - ok 08:38:22.0541 5208 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\windows\system32\drivers\pcw.sys 08:38:22.0541 5208 pcw - ok 08:38:22.0586 5208 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\windows\system32\drivers\peauth.sys 08:38:22.0596 5208 PEAUTH - ok 08:38:22.0676 5208 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\windows\SysWow64\perfhost.exe 08:38:22.0791 5208 PerfHost - ok 08:38:23.0001 5208 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\windows\system32\pla.dll 08:38:23.0051 5208 pla - ok 08:38:23.0136 5208 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\windows\system32\umpnpmgr.dll 08:38:23.0146 5208 PlugPlay - ok 08:38:23.0281 5208 [ AC78DF349F0E4CFB8B667C0CFFF83CCE ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll 08:38:23.0286 5208 Pml Driver HPZ12 - ok 08:38:23.0351 5208 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\windows\system32\pnrpauto.dll 08:38:23.0351 5208 PNRPAutoReg - ok 08:38:23.0486 5208 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\windows\system32\pnrpsvc.dll 08:38:23.0491 5208 PNRPsvc - ok 08:38:23.0586 5208 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\windows\System32\ipsecsvc.dll 08:38:23.0591 5208 PolicyAgent - ok 08:38:23.0661 5208 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\windows\system32\umpo.dll 08:38:23.0661 5208 Power - ok 08:38:23.0776 5208 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\windows\system32\DRIVERS\raspptp.sys 08:38:23.0776 5208 PptpMiniport - ok 08:38:23.0846 5208 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\windows\system32\DRIVERS\processr.sys 08:38:23.0846 5208 Processor - ok 08:38:23.0936 5208 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\windows\system32\profsvc.dll 08:38:23.0941 5208 ProfSvc - ok 08:38:23.0981 5208 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\windows\system32\lsass.exe 08:38:23.0981 5208 ProtectedStorage - ok 08:38:24.0061 5208 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\windows\system32\DRIVERS\pacer.sys 08:38:24.0066 5208 Psched - ok 08:38:24.0156 5208 [ 452C20382DF763F966C12DC48259F34E ] PTUMWBus C:\windows\system32\DRIVERS\PTUMWBus.sys 08:38:24.0156 5208 PTUMWBus - ok 08:38:24.0276 5208 [ 3754C646BBDAEDAFC09F793C6B38E877 ] PTUMWCDF C:\windows\system32\DRIVERS\PTUMWCDF.sys 08:38:24.0276 5208 PTUMWCDF - ok 08:38:24.0346 5208 [ 46823290BF74DFFEBB4E30F9D1E6A46E ] PTUMWCSP C:\windows\system32\DRIVERS\PTUMWCSP.sys 08:38:24.0351 5208 PTUMWCSP - ok 08:38:24.0441 5208 [ AC86BB916FBEA16B0005EFC3BA3ADB58 ] PTUMWFLT C:\windows\system32\DRIVERS\PTUMWFLT.sys 08:38:24.0441 5208 PTUMWFLT - ok 08:38:24.0541 5208 [ CB146794BC3B96661A32CBD68673B479 ] PTUMWMdm C:\windows\system32\DRIVERS\PTUMWMdm.sys 08:38:24.0546 5208 PTUMWMdm - ok 08:38:24.0636 5208 [ 329E77868A92BB6F97C119050D97E9EC ] PTUMWNET C:\windows\system32\DRIVERS\PTUMWNET.sys 08:38:24.0636 5208 PTUMWNET - ok 08:38:24.0721 5208 [ 258AAD147F0B5B7EC45C71D9369145AC ] PTUMWNSP C:\windows\system32\DRIVERS\PTUMWNSP.sys 08:38:24.0726 5208 PTUMWNSP - ok 08:38:24.0956 5208 [ 4FFD7E6D2CB293849C1181D08717EA09 ] PTUMWVsp C:\windows\system32\DRIVERS\PTUMWVsp.sys 08:38:24.0956 5208 PTUMWVsp - ok 08:38:25.0026 5208 [ 4712CC14E720ECCCC0AA16949D18AAF1 ] PxHlpa64 C:\windows\system32\Drivers\PxHlpa64.sys 08:38:25.0026 5208 PxHlpa64 - ok 08:38:25.0216 5208 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\windows\system32\DRIVERS\ql2300.sys 08:38:25.0251 5208 ql2300 - ok 08:38:25.0311 5208 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\windows\system32\DRIVERS\ql40xx.sys 08:38:25.0311 5208 ql40xx - ok 08:38:25.0396 5208 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\windows\system32\qwave.dll 08:38:25.0401 5208 QWAVE - ok 08:38:25.0446 5208 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\windows\system32\drivers\qwavedrv.sys 08:38:25.0451 5208 QWAVEdrv - ok 08:38:25.0531 5208 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\windows\system32\DRIVERS\rasacd.sys 08:38:25.0536 5208 RasAcd - ok 08:38:25.0766 5208 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\windows\system32\DRIVERS\AgileVpn.sys 08:38:25.0776 5208 RasAgileVpn - ok 08:38:25.0826 5208 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\windows\System32\rasauto.dll 08:38:25.0826 5208 RasAuto - ok 08:38:25.0981 5208 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\windows\system32\DRIVERS\rasl2tp.sys 08:38:25.0996 5208 Rasl2tp - ok 08:38:26.0111 5208 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\windows\System32\rasmans.dll 08:38:26.0116 5208 RasMan - ok 08:38:26.0221 5208 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\windows\system32\DRIVERS\raspppoe.sys 08:38:26.0221 5208 RasPppoe - ok 08:38:26.0251 5208 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\windows\system32\DRIVERS\rassstp.sys 08:38:26.0256 5208 RasSstp - ok 08:38:26.0411 5208 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\windows\system32\DRIVERS\rdbss.sys 08:38:26.0421 5208 rdbss - ok 08:38:26.0536 5208 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\windows\system32\DRIVERS\rdpbus.sys 08:38:26.0536 5208 rdpbus - ok 08:38:26.0561 5208 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\windows\system32\DRIVERS\RDPCDD.sys 08:38:26.0561 5208 RDPCDD - ok 08:38:26.0581 5208 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\windows\system32\drivers\rdpencdd.sys 08:38:26.0586 5208 RDPENCDD - ok 08:38:26.0606 5208 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\windows\system32\drivers\rdprefmp.sys 08:38:26.0606 5208 RDPREFMP - ok 08:38:26.0731 5208 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\windows\system32\drivers\RDPWD.sys 08:38:26.0731 5208 RDPWD - ok 08:38:26.0811 5208 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\windows\system32\drivers\rdyboost.sys 08:38:26.0811 5208 rdyboost - ok 08:38:26.0876 5208 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\windows\System32\mprdim.dll 08:38:26.0881 5208 RemoteAccess - ok 08:38:26.0986 5208 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\windows\system32\regsvc.dll 08:38:26.0991 5208 RemoteRegistry - ok 08:38:27.0016 5208 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\windows\System32\RpcEpMap.dll 08:38:27.0021 5208 RpcEptMapper - ok 08:38:27.0061 5208 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\windows\system32\locator.exe 08:38:27.0061 5208 RpcLocator - ok 08:38:27.0146 5208 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\windows\system32\rpcss.dll 08:38:27.0151 5208 RpcSs - ok 08:38:27.0206 5208 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\windows\system32\DRIVERS\rspndr.sys 08:38:27.0211 5208 rspndr - ok 08:38:27.0306 5208 [ 8C22F21C924413D4E109995F748E18BB ] RSUSBSTOR C:\windows\system32\Drivers\RtsUStor.sys 08:38:27.0316 5208 RSUSBSTOR - ok 08:38:27.0391 5208 [ B49DC435AE3695BAC5623DD94B05732D ] RTL8167 C:\windows\system32\DRIVERS\Rt64win7.sys 08:38:27.0391 5208 RTL8167 - ok 08:38:27.0471 5208 [ 945AB249D12CBE044782430C6013AA1A ] RTL8187B C:\windows\system32\DRIVERS\RTL8187B.sys 08:38:27.0476 5208 RTL8187B - ok 08:38:27.0521 5208 RtsUIR - ok 08:38:27.0546 5208 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\windows\system32\lsass.exe 08:38:27.0546 5208 SamSs - ok 08:38:27.0621 5208 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\windows\system32\drivers\sbp2port.sys 08:38:27.0626 5208 sbp2port - ok 08:38:27.0681 5208 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\windows\System32\SCardSvr.dll 08:38:27.0686 5208 SCardSvr - ok 08:38:27.0741 5208 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\windows\system32\DRIVERS\scfilter.sys 08:38:27.0746 5208 scfilter - ok 08:38:27.0921 5208 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\windows\system32\schedsvc.dll 08:38:27.0941 5208 Schedule - ok 08:38:28.0021 5208 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\windows\System32\certprop.dll 08:38:28.0026 5208 SCPolicySvc - ok 08:38:28.0091 5208 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\windows\System32\SDRSVC.dll 08:38:28.0091 5208 SDRSVC - ok 08:38:28.0151 5208 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\windows\system32\drivers\secdrv.sys 08:38:28.0151 5208 secdrv - ok 08:38:28.0236 5208 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\windows\system32\seclogon.dll 08:38:28.0241 5208 seclogon - ok 08:38:28.0296 5208 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\windows\System32\sens.dll 08:38:28.0301 5208 SENS - ok 08:38:28.0316 5208 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\windows\system32\sensrsvc.dll 08:38:28.0321 5208 SensrSvc - ok 08:38:28.0351 5208 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\windows\system32\DRIVERS\serenum.sys 08:38:28.0356 5208 Serenum - ok 08:38:28.0426 5208 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\windows\system32\DRIVERS\serial.sys 08:38:28.0426 5208 Serial - ok 08:38:28.0486 5208 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\windows\system32\DRIVERS\sermouse.sys 08:38:28.0486 5208 sermouse - ok 08:38:28.0561 5208 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\windows\system32\sessenv.dll 08:38:28.0561 5208 SessionEnv - ok 08:38:28.0641 5208 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\windows\system32\drivers\sffdisk.sys 08:38:28.0646 5208 sffdisk - ok 08:38:28.0686 5208 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\windows\system32\drivers\sffp_mmc.sys 08:38:28.0691 5208 sffp_mmc - ok 08:38:28.0711 5208 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\windows\system32\drivers\sffp_sd.sys 08:38:28.0711 5208 sffp_sd - ok 08:38:28.0781 5208 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\windows\system32\DRIVERS\sfloppy.sys 08:38:28.0781 5208 sfloppy - ok 08:38:28.0851 5208 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\windows\System32\ipnathlp.dll 08:38:28.0856 5208 SharedAccess - ok 08:38:28.0916 5208 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\windows\System32\shsvcs.dll 08:38:28.0921 5208 ShellHWDetection - ok 08:38:29.0011 5208 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\windows\system32\DRIVERS\SiSRaid2.sys 08:38:29.0011 5208 SiSRaid2 - ok 08:38:29.0041 5208 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\windows\system32\DRIVERS\sisraid4.sys 08:38:29.0041 5208 SiSRaid4 - ok 08:38:29.0126 5208 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 08:38:29.0131 5208 SkypeUpdate - ok 08:38:29.0176 5208 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\windows\system32\DRIVERS\smb.sys 08:38:29.0176 5208 Smb - ok 08:38:29.0366 5208 [ B5D3C24E4EA8E6D4850E83DAD8C510D4 ] SMSIVZAM5X64 C:\PROGRA~2\VERIZO~1\VZACCE~1\SMSIVZAM5X64.SYS 08:38:29.0366 5208 SMSIVZAM5X64 - ok 08:38:29.0416 5208 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\windows\System32\snmptrap.exe 08:38:29.0426 5208 SNMPTRAP - ok 08:38:29.0456 5208 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\windows\system32\drivers\spldr.sys 08:38:29.0461 5208 spldr - ok 08:38:29.0551 5208 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\windows\System32\spoolsv.exe 08:38:29.0561 5208 Spooler - ok 08:38:30.0236 5208 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\windows\system32\sppsvc.exe 08:38:30.0356 5208 sppsvc - ok 08:38:30.0446 5208 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\windows\system32\sppuinotify.dll 08:38:30.0451 5208 sppuinotify - ok 08:38:30.0771 5208 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\windows\system32\DRIVERS\srv.sys 08:38:30.0826 5208 srv - ok 08:38:30.0906 5208 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\windows\system32\DRIVERS\srv2.sys 08:38:30.0911 5208 srv2 - ok 08:38:30.0966 5208 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\windows\system32\DRIVERS\srvnet.sys 08:38:30.0966 5208 srvnet - ok 08:38:31.0086 5208 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\windows\System32\ssdpsrv.dll 08:38:31.0091 5208 SSDPSRV - ok 08:38:31.0131 5208 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\windows\system32\sstpsvc.dll 08:38:31.0141 5208 SstpSvc - ok 08:38:31.0191 5208 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\windows\system32\DRIVERS\stexstor.sys 08:38:31.0191 5208 stexstor - ok 08:38:31.0336 5208 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\windows\System32\wiaservc.dll 08:38:31.0346 5208 stisvc - ok 08:38:31.0486 5208 [ FF5EB78AF7DFB68C2FB363537AAF753E ] stllssvr C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe 08:38:31.0571 5208 stllssvr - ok 08:38:31.0626 5208 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\windows\system32\drivers\swenum.sys 08:38:31.0626 5208 swenum - ok 08:38:31.0691 5208 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\windows\System32\swprv.dll 08:38:31.0706 5208 swprv - ok 08:38:31.0816 5208 [ BE7311DA9D6833FA69ED04B744A1C8F8 ] SynTP C:\windows\system32\DRIVERS\SynTP.sys 08:38:31.0826 5208 SynTP - ok 08:38:31.0991 5208 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\windows\system32\sysmain.dll 08:38:32.0066 5208 SysMain - ok 08:38:32.0146 5208 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\windows\System32\TabSvc.dll 08:38:32.0151 5208 TabletInputService - ok 08:38:32.0211 5208 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\windows\System32\tapisrv.dll 08:38:32.0216 5208 TapiSrv - ok 08:38:32.0256 5208 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\windows\System32\tbssvc.dll 08:38:32.0261 5208 TBS - ok 08:38:32.0426 5208 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] Tcpip C:\windows\system32\drivers\tcpip.sys 08:38:32.0471 5208 Tcpip - ok 08:38:32.0656 5208 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] TCPIP6 C:\windows\system32\DRIVERS\tcpip.sys 08:38:32.0671 5208 TCPIP6 - ok 08:38:32.0761 5208 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\windows\system32\drivers\tcpipreg.sys 08:38:32.0761 5208 tcpipreg - ok 08:38:32.0861 5208 [ FD542B661BD22FA69CA789AD0AC58C29 ] tdcmdpst C:\windows\system32\DRIVERS\tdcmdpst.sys 08:38:32.0861 5208 tdcmdpst - ok 08:38:32.0926 5208 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\windows\system32\drivers\tdpipe.sys 08:38:32.0926 5208 TDPIPE - ok 08:38:33.0026 5208 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\windows\system32\drivers\tdtcp.sys 08:38:33.0026 5208 TDTCP - ok 08:38:33.0096 5208 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\windows\system32\DRIVERS\tdx.sys 08:38:33.0101 5208 tdx - ok 08:38:33.0126 5208 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\windows\system32\drivers\termdd.sys 08:38:33.0131 5208 TermDD - ok 08:38:33.0191 5208 [ 2E648163254233755035B46DD7B89123 ] TermService C:\windows\System32\termsrv.dll 08:38:33.0196 5208 TermService - ok 08:38:33.0281 5208 [ F0344071948D1A1FA732231785A0664C ] Themes C:\windows\system32\themeservice.dll 08:38:33.0286 5208 Themes - ok 08:38:33.0331 5208 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\windows\system32\mmcss.dll 08:38:33.0351 5208 THREADORDER - ok 08:38:33.0591 5208 [ F120967184A27E927052E8DDBB727851 ] TMachInfo C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe 08:38:33.0591 5208 TMachInfo - ok 08:38:33.0656 5208 [ ED32035BDFECED1AD66D459FD9CC1140 ] TODDSrv C:\Windows\system32\TODDSrv.exe 08:38:33.0656 5208 TODDSrv - ok 08:38:33.0831 5208 [ 06C61275ADC64F1E36240A2287998A5E ] TosCoSrv C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe 08:38:33.0836 5208 TosCoSrv - ok 08:38:33.0991 5208 [ DD58E1250F604CBBADDA04575E5E2376 ] TOSHIBA HDD SSD Alert Service C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe 08:38:33.0991 5208 TOSHIBA HDD SSD Alert Service - ok 08:38:34.0131 5208 [ 09FF7B0B1B5C3D225495CB6F5A9B39F8 ] tos_sps64 C:\windows\system32\DRIVERS\tos_sps64.sys 08:38:34.0141 5208 tos_sps64 - ok 08:38:34.0246 5208 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\windows\System32\trkwks.dll 08:38:34.0251 5208 TrkWks - ok 08:38:34.0396 5208 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe 08:38:34.0401 5208 TrustedInstaller - ok 08:38:34.0496 5208 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\windows\system32\DRIVERS\tssecsrv.sys 08:38:34.0496 5208 tssecsrv - ok 08:38:34.0631 5208 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\windows\system32\drivers\tsusbflt.sys 08:38:34.0631 5208 TsUsbFlt - ok 08:38:34.0756 5208 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\windows\system32\DRIVERS\tunnel.sys 08:38:34.0761 5208 tunnel - ok 08:38:34.0831 5208 [ 550B567F9364D8F7684C3FB3EA665A72 ] TVALZ C:\windows\system32\DRIVERS\TVALZ_O.SYS 08:38:34.0831 5208 TVALZ - ok 08:38:34.0871 5208 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\windows\system32\DRIVERS\uagp35.sys 08:38:34.0871 5208 uagp35 - ok 08:38:35.0001 5208 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\windows\system32\DRIVERS\udfs.sys 08:38:35.0006 5208 udfs - ok 08:38:35.0081 5208 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\windows\system32\UI0Detect.exe 08:38:35.0091 5208 UI0Detect - ok 08:38:35.0126 5208 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\windows\system32\drivers\uliagpkx.sys 08:38:35.0131 5208 uliagpkx - ok 08:38:35.0211 5208 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\windows\system32\drivers\umbus.sys 08:38:35.0211 5208 umbus - ok 08:38:35.0286 5208 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\windows\system32\DRIVERS\umpass.sys 08:38:35.0286 5208 UmPass - ok 08:38:35.0381 5208 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\windows\System32\upnphost.dll 08:38:35.0386 5208 upnphost - ok 08:38:35.0506 5208 [ F724B03C3DFAACF08D17D38BF3333583 ] USBAAPL64 C:\windows\system32\Drivers\usbaapl64.sys 08:38:35.0506 5208 USBAAPL64 - ok 08:38:35.0601 5208 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\windows\system32\drivers\usbaudio.sys 08:38:35.0601 5208 usbaudio - ok 08:38:35.0671 5208 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\windows\system32\DRIVERS\usbccgp.sys 08:38:35.0671 5208 usbccgp - ok 08:38:35.0681 5208 USBCCID - ok 08:38:35.0791 5208 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\windows\system32\drivers\usbcir.sys 08:38:35.0796 5208 usbcir - ok 08:38:35.0861 5208 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\windows\system32\DRIVERS\usbehci.sys 08:38:35.0861 5208 usbehci - ok 08:38:35.0966 5208 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\windows\system32\DRIVERS\usbhub.sys 08:38:35.0971 5208 usbhub - ok 08:38:36.0036 5208 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\windows\system32\drivers\usbohci.sys 08:38:36.0036 5208 usbohci - ok 08:38:36.0086 5208 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\windows\system32\DRIVERS\usbprint.sys 08:38:36.0086 5208 usbprint - ok 08:38:36.0161 5208 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\windows\system32\DRIVERS\usbscan.sys 08:38:36.0161 5208 usbscan - ok 08:38:36.0271 5208 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\windows\system32\DRIVERS\USBSTOR.SYS 08:38:36.0271 5208 USBSTOR - ok 08:38:36.0326 5208 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\windows\system32\DRIVERS\usbuhci.sys 08:38:36.0326 5208 usbuhci - ok 08:38:36.0451 5208 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\windows\system32\Drivers\usbvideo.sys 08:38:36.0451 5208 usbvideo - ok 08:38:36.0486 5208 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\windows\System32\uxsms.dll 08:38:36.0491 5208 UxSms - ok 08:38:36.0516 5208 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\windows\system32\lsass.exe 08:38:36.0516 5208 VaultSvc - ok 08:38:36.0591 5208 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\windows\system32\drivers\vdrvroot.sys 08:38:36.0591 5208 vdrvroot - ok 08:38:36.0736 5208 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\windows\System32\vds.exe 08:38:36.0746 5208 vds - ok 08:38:36.0871 5208 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\windows\system32\DRIVERS\vgapnp.sys 08:38:36.0871 5208 vga - ok 08:38:36.0921 5208 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\windows\System32\drivers\vga.sys 08:38:36.0921 5208 VgaSave - ok 08:38:37.0101 5208 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\windows\system32\drivers\vhdmp.sys 08:38:37.0101 5208 vhdmp - ok 08:38:37.0146 5208 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\windows\system32\drivers\viaide.sys 08:38:37.0146 5208 viaide - ok 08:38:37.0176 5208 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\windows\system32\drivers\volmgr.sys 08:38:37.0176 5208 volmgr - ok 08:38:37.0261 5208 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\windows\system32\drivers\volmgrx.sys 08:38:37.0266 5208 volmgrx - ok 08:38:37.0366 5208 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\windows\system32\drivers\volsnap.sys 08:38:37.0371 5208 volsnap - ok 08:38:37.0451 5208 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\windows\system32\DRIVERS\vsmraid.sys 08:38:37.0456 5208 vsmraid - ok 08:38:37.0626 5208 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\windows\system32\vssvc.exe 08:38:37.0646 5208 VSS - ok 08:38:37.0686 5208 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\windows\System32\drivers\vwifibus.sys 08:38:37.0686 5208 vwifibus - ok 08:38:37.0751 5208 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\windows\system32\DRIVERS\vwififlt.sys 08:38:37.0751 5208 vwififlt - ok 08:38:37.0861 5208 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\windows\system32\w32time.dll 08:38:37.0871 5208 W32Time - ok 08:38:37.0936 5208 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\windows\system32\DRIVERS\wacompen.sys 08:38:37.0936 5208 WacomPen - ok 08:38:38.0061 5208 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\windows\system32\DRIVERS\wanarp.sys 08:38:38.0071 5208 WANARP - ok 08:38:38.0096 5208 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\windows\system32\DRIVERS\wanarp.sys 08:38:38.0096 5208 Wanarpv6 - ok 08:38:38.0361 5208 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\windows\system32\Wat\WatAdminSvc.exe 08:38:38.0396 5208 WatAdminSvc - ok 08:38:38.0631 5208 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\windows\system32\wbengine.exe 08:38:38.0651 5208 wbengine - ok 08:38:38.0686 5208 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\windows\System32\wbiosrvc.dll 08:38:38.0691 5208 WbioSrvc - ok 08:38:38.0891 5208 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\windows\System32\wcncsvc.dll 08:38:38.0896 5208 wcncsvc - ok 08:38:38.0931 5208 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll 08:38:38.0936 5208 WcsPlugInService - ok 08:38:39.0016 5208 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\windows\system32\DRIVERS\wd.sys 08:38:39.0016 5208 Wd - ok 08:38:39.0126 5208 [ A3D04EBF5227886029B4532F20D026F7 ] WDC_SAM C:\windows\system32\DRIVERS\wdcsam64.sys 08:38:39.0126 5208 WDC_SAM - ok 08:38:39.0286 5208 [ E6050FE6B60FA91188B8ABDB5B1E339F ] WDDMService C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe 08:38:39.0291 5208 WDDMService - ok 08:38:39.0336 5208 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\windows\system32\drivers\Wdf01000.sys 08:38:39.0341 5208 Wdf01000 - ok 08:38:39.0546 5208 [ B83D5071B32A70BEBDB3330BFA7ACB80 ] WDFME C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe 08:38:39.0596 5208 WDFME - ok 08:38:39.0626 5208 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\windows\system32\wdi.dll 08:38:39.0631 5208 WdiServiceHost - ok 08:38:39.0641 5208 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\windows\system32\wdi.dll 08:38:39.0646 5208 WdiSystemHost - ok 08:38:39.0786 5208 [ 517DE2C5568CBA6B2A24A557AC60C30B ] WDSC C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe 08:38:39.0831 5208 WDSC - ok 08:38:39.0886 5208 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\windows\System32\webclnt.dll 08:38:39.0896 5208 WebClient - ok 08:38:39.0971 5208 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\windows\system32\wecsvc.dll 08:38:39.0976 5208 Wecsvc - ok 08:38:40.0016 5208 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\windows\System32\wercplsupport.dll 08:38:40.0016 5208 wercplsupport - ok 08:38:40.0046 5208 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\windows\System32\WerSvc.dll 08:38:40.0051 5208 WerSvc - ok 08:38:40.0116 5208 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\windows\system32\DRIVERS\wfplwf.sys 08:38:40.0116 5208 WfpLwf - ok 08:38:40.0176 5208 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\windows\system32\drivers\wimmount.sys 08:38:40.0176 5208 WIMMount - ok 08:38:40.0201 5208 WinDefend - ok 08:38:40.0221 5208 WinHttpAutoProxySvc - ok 08:38:40.0346 5208 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\windows\system32\wbem\WMIsvc.dll 08:38:40.0351 5208 Winmgmt - ok 08:38:40.0491 5208 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\windows\system32\WsmSvc.dll 08:38:40.0551 5208 WinRM - ok 08:38:40.0736 5208 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\windows\system32\DRIVERS\WinUsb.sys 08:38:40.0766 5208 WinUsb - ok 08:38:40.0871 5208 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\windows\System32\wlansvc.dll 08:38:40.0881 5208 Wlansvc - ok 08:38:40.0991 5208 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\windows\system32\drivers\wmiacpi.sys 08:38:40.0991 5208 WmiAcpi - ok 08:38:41.0041 5208 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\windows\system32\wbem\WmiApSrv.exe 08:38:41.0046 5208 wmiApSrv - ok 08:38:41.0146 5208 WMPNetworkSvc - ok 08:38:41.0216 5208 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\windows\System32\wpcsvc.dll 08:38:41.0221 5208 WPCSvc - ok 08:38:41.0296 5208 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\windows\system32\wpdbusenum.dll 08:38:41.0301 5208 WPDBusEnum - ok 08:38:41.0371 5208 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\windows\system32\drivers\ws2ifsl.sys 08:38:41.0371 5208 ws2ifsl - ok 08:38:41.0441 5208 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\windows\System32\wscsvc.dll 08:38:41.0446 5208 wscsvc - ok 08:38:41.0456 5208 WSearch - ok 08:38:41.0681 5208 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\windows\system32\wuaueng.dll 08:38:41.0731 5208 wuauserv - ok 08:38:41.0806 5208 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\windows\system32\drivers\WudfPf.sys 08:38:41.0811 5208 WudfPf - ok 08:38:41.0936 5208 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\windows\system32\DRIVERS\WUDFRd.sys 08:38:41.0941 5208 WUDFRd - ok 08:38:42.0011 5208 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\windows\System32\WUDFSvc.dll 08:38:42.0011 5208 wudfsvc - ok 08:38:42.0066 5208 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\windows\System32\wwansvc.dll 08:38:42.0076 5208 WwanSvc - ok 08:38:42.0141 5208 ================ Scan global =============================== 08:38:42.0221 5208 [ BA0CD8C393E8C9F83354106093832C7B ] C:\windows\system32\basesrv.dll 08:38:42.0306 5208 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\windows\system32\winsrv.dll 08:38:42.0326 5208 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\windows\system32\winsrv.dll 08:38:42.0396 5208 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\windows\system32\sxssrv.dll 08:38:42.0511 5208 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\windows\system32\services.exe 08:38:42.0516 5208 [Global] - ok 08:38:42.0521 5208 ================ Scan MBR ================================== 08:38:42.0591 5208 [ 5B5E648D12FCADC244C1EC30318E1EB9 ] \Device\Harddisk0\DR0 08:38:43.0241 5208 \Device\Harddisk0\DR0 - ok 08:38:43.0241 5208 ================ Scan VBR ================================== 08:38:43.0291 5208 [ D081F37BD3D62809C092D0AEA6AD5670 ] \Device\Harddisk0\DR0\Partition1 08:38:43.0291 5208 \Device\Harddisk0\DR0\Partition1 - ok 08:38:43.0301 5208 ============================================================ 08:38:43.0301 5208 Scan finished 08:38:43.0301 5208 ============================================================ 08:38:43.0321 4300 Detected object count: 0 08:38:43.0321 4300 Actual detected object count: 0
08:37:19.0631 5060 TDSS rootkit removing tool [removed] Oct 12 2012 17:26:47 08:37:19.0926 5060 ============================================================ 08:37:19.0926 5060 Current date / time: 2012/10/25 08:37:19.0926 08:37:19.0926 5060 SystemInfo: 08:37:19.0926 5060 08:37:19.0926 5060 OS Version: 6.1.7601 ServicePack: 1.0 08:37:19.0926 5060 Product type: Workstation 08:37:19.0926 5060 ComputerName: PC-PC 08:37:19.0926 5060 UserName: PC 08:37:19.0926 5060 Windows directory: C:\windows 08:37:19.0926 5060 System windows directory: C:\windows 08:37:19.0926 5060 Running under WOW64 08:37:19.0926 5060 Processor architecture: Intel x64 08:37:19.0926 5060 Number of processors: 1 08:37:19.0926 5060 Page size: 0x1000 08:37:19.0926 5060 Boot type: Normal boot 08:37:19.0926 5060 ============================================================ 08:37:21.0861 5060 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 08:37:21.0911 5060 ============================================================ 08:37:21.0911 5060 \Device\Harddisk0\DR0: 08:37:21.0911 5060 MBR partitions: 08:37:21.0911 5060 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x1BCDE800 08:37:21.0911 5060 ============================================================ 08:37:21.0956 5060 C: <-> \Device\Harddisk0\DR0\Partition1 08:37:21.0956 5060 ============================================================ 08:37:21.0956 5060 Initialize success 08:37:21.0956 5060 ============================================================ 08:37:49.0836 5208 ============================================================ 08:37:49.0836 5208 Scan started 08:37:49.0836 5208 Mode: Manual; TDLFS; 08:37:49.0836 5208 ============================================================ 08:37:53.0171 5208 ================ Scan system memory ======================== 08:37:53.0171 5208 System memory - ok 08:37:53.0176 5208 ================ Scan services ============================= 08:37:53.0956 5208 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\windows\system32\drivers\1394ohci.sys 08:37:53.0961 5208 1394ohci - ok 08:37:54.0041 5208 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\windows\system32\drivers\ACPI.sys 08:37:54.0046 5208 ACPI - ok 08:37:54.0156 5208 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\windows\system32\drivers\acpipmi.sys 08:37:54.0156 5208 AcpiPmi - ok 08:37:54.0521 5208 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 08:37:54.0521 5208 AdobeARMservice - ok 08:37:55.0016 5208 [ 44C00A385CA9DBC1D5CF3781F8C26AEA ] AdobeFlashPlayerUpdateSvc C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 08:37:55.0021 5208 AdobeFlashPlayerUpdateSvc - ok 08:37:55.0156 5208 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\windows\system32\DRIVERS\adp94xx.sys 08:37:55.0161 5208 adp94xx - ok 08:37:55.0276 5208 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\windows\system32\DRIVERS\adpahci.sys 08:37:55.0281 5208 adpahci - ok 08:37:55.0321 5208 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\windows\system32\DRIVERS\adpu320.sys 08:37:55.0321 5208 adpu320 - ok 08:37:55.0396 5208 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\windows\System32\aelupsvc.dll 08:37:55.0396 5208 AeLookupSvc - ok 08:37:55.0526 5208 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\windows\system32\drivers\afd.sys 08:37:55.0531 5208 AFD - ok 08:37:55.0736 5208 [ 98022774D9930ECBB292E70DB7601DF6 ] AgereSoftModem C:\windows\system32\DRIVERS\agrsm64.sys 08:37:55.0751 5208 AgereSoftModem - ok 08:37:55.0896 5208 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\windows\system32\drivers\agp440.sys 08:37:55.0901 5208 agp440 - ok 08:37:56.0036 5208 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\windows\System32\alg.exe 08:37:56.0036 5208 ALG - ok 08:37:56.0141 5208 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\windows\system32\drivers\aliide.sys 08:37:56.0141 5208 aliide - ok 08:37:56.0206 5208 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\windows\system32\drivers\amdide.sys 08:37:56.0206 5208 amdide - ok 08:37:56.0286 5208 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\windows\system32\DRIVERS\amdk8.sys 08:37:56.0286 5208 AmdK8 - ok 08:37:56.0326 5208 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\windows\system32\DRIVERS\amdppm.sys 08:37:56.0326 5208 AmdPPM - ok 08:37:56.0451 5208 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\windows\system32\drivers\amdsata.sys 08:37:56.0451 5208 amdsata - ok 08:37:56.0501 5208 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\windows\system32\DRIVERS\amdsbs.sys 08:37:56.0501 5208 amdsbs - ok 08:37:56.0626 5208 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\windows\system32\drivers\amdxata.sys 08:37:56.0631 5208 amdxata - ok 08:37:56.0731 5208 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\windows\system32\drivers\appid.sys 08:37:56.0731 5208 AppID - ok 08:37:56.0766 5208 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\windows\System32\appidsvc.dll 08:37:56.0771 5208 AppIDSvc - ok 08:37:56.0876 5208 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\windows\System32\appinfo.dll 08:37:56.0876 5208 Appinfo - ok 08:37:57.0016 5208 [ 5AA788D5A2C6737BB9C45933985BC1B8 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 08:37:57.0016 5208 Apple Mobile Device - ok 08:37:57.0101 5208 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\windows\system32\DRIVERS\arc.sys 08:37:57.0101 5208 arc - ok 08:37:57.0161 5208 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\windows\system32\DRIVERS\arcsas.sys 08:37:57.0161 5208 arcsas - ok 08:37:57.0261 5208 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys 08:37:57.0261 5208 AsyncMac - ok 08:37:57.0461 5208 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\windows\system32\drivers\atapi.sys 08:37:57.0461 5208 atapi - ok 08:37:57.0586 5208 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll 08:37:57.0591 5208 AudioEndpointBuilder - ok 08:37:57.0611 5208 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\windows\System32\Audiosrv.dll 08:37:57.0616 5208 AudioSrv - ok 08:37:57.0731 5208 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\windows\System32\AxInstSV.dll 08:37:57.0731 5208 AxInstSV - ok 08:37:57.0881 5208 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\windows\system32\DRIVERS\bxvbda.sys 08:37:57.0891 5208 b06bdrv - ok 08:37:57.0986 5208 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\windows\system32\DRIVERS\b57nd60a.sys 08:37:57.0991 5208 b57nd60a - ok 08:37:58.0071 5208 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\windows\System32\bdesvc.dll 08:37:58.0071 5208 BDESVC - ok 08:37:58.0146 5208 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\windows\system32\drivers\Beep.sys 08:37:58.0146 5208 Beep - ok 08:37:58.0371 5208 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\windows\System32\bfe.dll 08:37:58.0381 5208 BFE - ok 08:37:58.0541 5208 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\windows\System32\qmgr.dll 08:37:58.0551 5208 BITS - ok 08:37:58.0621 5208 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\windows\system32\DRIVERS\blbdrive.sys 08:37:58.0621 5208 blbdrive - ok 08:37:58.0761 5208 [ F832F1505AD8B83474BD9A5B1B985E01 ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe 08:37:58.0766 5208 Bonjour Service - ok 08:37:58.0836 5208 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\windows\system32\DRIVERS\bowser.sys 08:37:58.0841 5208 bowser - ok 08:37:58.0876 5208 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\windows\system32\DRIVERS\BrFiltLo.sys 08:37:58.0876 5208 BrFiltLo - ok 08:37:58.0941 5208 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\windows\system32\DRIVERS\BrFiltUp.sys 08:37:58.0941 5208 BrFiltUp - ok 08:37:59.0006 5208 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\windows\System32\browser.dll 08:37:59.0011 5208 Browser - ok 08:37:59.0111 5208 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\windows\System32\Drivers\Brserid.sys 08:37:59.0116 5208 Brserid - ok 08:37:59.0131 5208 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\windows\System32\Drivers\BrSerWdm.sys 08:37:59.0131 5208 BrSerWdm - ok 08:37:59.0161 5208 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\windows\System32\Drivers\BrUsbMdm.sys 08:37:59.0161 5208 BrUsbMdm - ok 08:37:59.0196 5208 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\windows\System32\Drivers\BrUsbSer.sys 08:37:59.0196 5208 BrUsbSer - ok 08:37:59.0226 5208 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\windows\system32\DRIVERS\bthmodem.sys 08:37:59.0226 5208 BTHMODEM - ok 08:37:59.0311 5208 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\windows\system32\bthserv.dll 08:37:59.0316 5208 bthserv - ok 08:37:59.0401 5208 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\windows\system32\DRIVERS\cdfs.sys 08:37:59.0401 5208 cdfs - ok 08:37:59.0541 5208 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\windows\system32\DRIVERS\cdrom.sys 08:37:59.0541 5208 cdrom - ok 08:37:59.0656 5208 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\windows\System32\certprop.dll 08:37:59.0661 5208 CertPropSvc - ok 08:37:59.0786 5208 [ 837FF2D497880198C918E6954DBD170C ] cfWiMAXService C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe 08:37:59.0791 5208 cfWiMAXService - ok 08:37:59.0926 5208 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\windows\system32\DRIVERS\circlass.sys 08:37:59.0926 5208 circlass - ok 08:37:59.0981 5208 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\windows\system32\CLFS.sys 08:37:59.0986 5208 CLFS - ok 08:38:00.0076 5208 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 08:38:00.0081 5208 clr_optimization_v2.0.50727_32 - ok 08:38:00.0191 5208 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 08:38:00.0196 5208 clr_optimization_v2.0.50727_64 - ok 08:38:00.0346 5208 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 08:38:00.0351 5208 clr_optimization_v4.0.30319_32 - ok 08:38:00.0461 5208 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 08:38:00.0461 5208 clr_optimization_v4.0.30319_64 - ok 08:38:00.0536 5208 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\windows\system32\DRIVERS\CmBatt.sys 08:38:00.0536 5208 CmBatt - ok 08:38:00.0611 5208 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\windows\system32\drivers\cmdide.sys 08:38:00.0616 5208 cmdide - ok 08:38:00.0706 5208 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\windows\system32\Drivers\cng.sys 08:38:00.0711 5208 CNG - ok 08:38:00.0831 5208 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\windows\system32\DRIVERS\compbatt.sys 08:38:00.0831 5208 Compbatt - ok 08:38:00.0946 5208 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\windows\system32\drivers\CompositeBus.sys 08:38:00.0946 5208 CompositeBus - ok 08:38:00.0991 5208 COMSysApp - ok 08:38:01.0036 5208 [ D252C53BCDFC199BBA55EEB10CDB266E ] ConfigFree Gadget Service C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe 08:38:01.0036 5208 ConfigFree Gadget Service - ok 08:38:01.0096 5208 [ CAB0EEAF5295FC96DDD3E19DCE27E131 ] ConfigFree Service C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe 08:38:01.0096 5208 ConfigFree Service - ok 08:38:01.0176 5208 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\windows\system32\DRIVERS\crcdisk.sys 08:38:01.0176 5208 crcdisk - ok 08:38:01.0316 5208 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\windows\system32\cryptsvc.dll 08:38:01.0316 5208 CryptSvc - ok 08:38:01.0436 5208 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\windows\system32\rpcss.dll 08:38:01.0441 5208 DcomLaunch - ok 08:38:01.0556 5208 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\windows\System32\defragsvc.dll 08:38:01.0556 5208 defragsvc - ok 08:38:01.0636 5208 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\windows\system32\Drivers\dfsc.sys 08:38:01.0636 5208 DfsC - ok 08:38:01.0736 5208 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\windows\system32\dhcpcore.dll 08:38:01.0741 5208 Dhcp - ok 08:38:01.0781 5208 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\windows\system32\drivers\discache.sys 08:38:01.0786 5208 discache - ok 08:38:01.0831 5208 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\windows\system32\DRIVERS\disk.sys 08:38:01.0831 5208 Disk - ok 08:38:01.0921 5208 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\windows\System32\dnsrslvr.dll 08:38:01.0921 5208 Dnscache - ok 08:38:02.0001 5208 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\windows\System32\dot3svc.dll 08:38:02.0006 5208 dot3svc - ok 08:38:02.0131 5208 [ B42ED0320C6E41102FDE0005154849BB ] Dot4 C:\windows\system32\DRIVERS\Dot4.sys 08:38:02.0136 5208 Dot4 - ok 08:38:02.0221 5208 [ E9F5969233C5D89F3C35E3A66A52A361 ] Dot4Print C:\windows\system32\drivers\Dot4Prt.sys 08:38:02.0221 5208 Dot4Print - ok 08:38:02.0366 5208 [ FD05A02B0370BC3000F402E543CA5814 ] dot4usb C:\windows\system32\DRIVERS\dot4usb.sys 08:38:02.0366 5208 dot4usb - ok 08:38:02.0421 5208 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\windows\system32\dps.dll 08:38:02.0426 5208 DPS - ok 08:38:02.0531 5208 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\windows\system32\drivers\drmkaud.sys 08:38:02.0531 5208 drmkaud - ok 08:38:02.0661 5208 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys 08:38:02.0671 5208 DXGKrnl - ok 08:38:02.0741 5208 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\windows\System32\eapsvc.dll 08:38:02.0746 5208 EapHost - ok 08:38:02.0901 5208 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\windows\system32\DRIVERS\evbda.sys 08:38:02.0976 5208 ebdrv - ok 08:38:03.0031 5208 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\windows\System32\lsass.exe 08:38:03.0036 5208 EFS - ok 08:38:03.0271 5208 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\windows\ehome\ehRecvr.exe 08:38:03.0301 5208 ehRecvr - ok 08:38:03.0381 5208 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\windows\ehome\ehsched.exe 08:38:03.0381 5208 ehSched - ok 08:38:03.0626 5208 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\windows\system32\DRIVERS\elxstor.sys 08:38:03.0656 5208 elxstor - ok 08:38:03.0716 5208 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\windows\system32\drivers\errdev.sys 08:38:03.0716 5208 ErrDev - ok 08:38:03.0936 5208 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\windows\system32\es.dll 08:38:03.0946 5208 EventSystem - ok 08:38:03.0991 5208 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\windows\system32\drivers\exfat.sys 08:38:03.0996 5208 exfat - ok 08:38:04.0091 5208 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\windows\system32\drivers\fastfat.sys 08:38:04.0091 5208 fastfat - ok 08:38:04.0206 5208 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\windows\system32\fxssvc.exe 08:38:04.0221 5208 Fax - ok 08:38:04.0261 5208 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\windows\system32\DRIVERS\fdc.sys 08:38:04.0261 5208 fdc - ok 08:38:04.0316 5208 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\windows\system32\fdPHost.dll 08:38:04.0316 5208 fdPHost - ok 08:38:04.0341 5208 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\windows\system32\fdrespub.dll 08:38:04.0346 5208 FDResPub - ok 08:38:04.0631 5208 [ D3B8DDF0731ADB88B1336231DADB8DD9 ] File Backup C:\Program Files (x86)\Workspace\offSyncService.exe 08:38:04.0646 5208 File Backup - ok 08:38:04.0721 5208 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\windows\system32\drivers\fileinfo.sys 08:38:04.0721 5208 FileInfo - ok 08:38:04.0751 5208 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\windows\system32\drivers\filetrace.sys 08:38:04.0751 5208 Filetrace - ok 08:38:04.0776 5208 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\windows\system32\DRIVERS\flpydisk.sys 08:38:04.0781 5208 flpydisk - ok 08:38:04.0891 5208 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\windows\system32\drivers\fltmgr.sys 08:38:04.0896 5208 FltMgr - ok 08:38:05.0061 5208 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\windows\system32\FntCache.dll 08:38:05.0076 5208 FontCache - ok 08:38:05.0211 5208 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 08:38:05.0211 5208 FontCache3.0.0.0 - ok 08:38:05.0291 5208 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\windows\system32\drivers\FsDepends.sys 08:38:05.0296 5208 FsDepends - ok 08:38:05.0376 5208 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys 08:38:05.0381 5208 Fs_Rec - ok 08:38:05.0506 5208 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\windows\system32\DRIVERS\fvevol.sys 08:38:05.0506 5208 fvevol - ok 08:38:05.0631 5208 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\windows\system32\DRIVERS\gagp30kx.sys 08:38:05.0631 5208 gagp30kx - ok 08:38:05.0821 5208 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\windows\system32\DRIVERS\GEARAspiWDM.sys 08:38:05.0821 5208 GEARAspiWDM - ok 08:38:05.0996 5208 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\windows\System32\gpsvc.dll 08:38:06.0006 5208 gpsvc - ok 08:38:06.0241 5208 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 08:38:06.0241 5208 gupdate - ok 08:38:06.0451 5208 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 08:38:06.0456 5208 gupdatem - ok 08:38:06.0566 5208 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\windows\system32\drivers\hcw85cir.sys 08:38:06.0566 5208 hcw85cir - ok 08:38:06.0871 5208 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys 08:38:06.0941 5208 HdAudAddService - ok 08:38:07.0191 5208 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\windows\system32\drivers\HDAudBus.sys 08:38:07.0211 5208 HDAudBus - ok 08:38:07.0271 5208 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\windows\system32\DRIVERS\HidBatt.sys 08:38:07.0271 5208 HidBatt - ok 08:38:07.0296 5208 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\windows\system32\DRIVERS\hidbth.sys 08:38:07.0296 5208 HidBth - ok 08:38:07.0326 5208 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\windows\system32\DRIVERS\hidir.sys 08:38:07.0331 5208 HidIr - ok 08:38:07.0411 5208 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\windows\system32\hidserv.dll 08:38:07.0416 5208 hidserv - ok 08:38:07.0606 5208 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\windows\system32\DRIVERS\hidusb.sys 08:38:07.0611 5208 HidUsb - ok 08:38:07.0736 5208 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\windows\system32\kmsvc.dll 08:38:07.0741 5208 hkmsvc - ok 08:38:07.0811 5208 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\windows\system32\ListSvc.dll 08:38:07.0816 5208 HomeGroupListener - ok 08:38:07.0901 5208 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\windows\system32\provsvc.dll 08:38:07.0906 5208 HomeGroupProvider - ok 08:38:08.0371 5208 [ 0A3C6AA4A9FC38C20BA4EAC2C3351C05 ] hpqcxs08 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll 08:38:08.0371 5208 hpqcxs08 - ok 08:38:08.0446 5208 [ F3F72A2A86C22610BCA5439FA789DD52 ] hpqddsvc C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll 08:38:08.0451 5208 hpqddsvc - ok 08:38:08.0646 5208 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\windows\system32\drivers\HpSAMD.sys 08:38:08.0646 5208 HpSAMD - ok 08:38:08.0751 5208 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\windows\system32\drivers\HTTP.sys 08:38:08.0761 5208 HTTP - ok 08:38:08.0826 5208 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\windows\system32\drivers\hwpolicy.sys 08:38:08.0826 5208 hwpolicy - ok 08:38:08.0931 5208 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\windows\system32\drivers\i8042prt.sys 08:38:08.0936 5208 i8042prt - ok 08:38:09.0006 5208 [ 1D004CB1DA6323B1F55CAEF7F94B61D9 ] iaStor C:\windows\system32\DRIVERS\iaStor.sys 08:38:09.0021 5208 iaStor - ok 08:38:09.0186 5208 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\windows\system32\drivers\iaStorV.sys 08:38:09.0191 5208 iaStorV - ok 08:38:09.0431 5208 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 08:38:09.0541 5208 idsvc - ok 08:38:10.0161 5208 [ 3C3F27002ABC69C5AFE29CBE6CF7ADDF ] igfx C:\windows\system32\DRIVERS\igdkmd64.sys 08:38:10.0326 5208 igfx - ok 08:38:10.0371 5208 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\windows\system32\DRIVERS\iirsp.sys 08:38:10.0376 5208 iirsp - ok 08:38:10.0461 5208 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\windows\System32\ikeext.dll 08:38:10.0476 5208 IKEEXT - ok 08:38:10.0721 5208 [ 0C3CF4B3BAE28E121A1689E3538F8712 ] IntcAzAudAddService C:\windows\system32\drivers\RTKVHD64.sys 08:38:10.0776 5208 IntcAzAudAddService - ok 08:38:10.0811 5208 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\windows\system32\drivers\intelide.sys 08:38:10.0811 5208 intelide - ok 08:38:10.0861 5208 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\windows\system32\DRIVERS\intelppm.sys 08:38:10.0861 5208 intelppm - ok 08:38:10.0946 5208 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\windows\system32\ipbusenum.dll 08:38:10.0951 5208 IPBusEnum - ok 08:38:11.0001 5208 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys 08:38:11.0001 5208 IpFilterDriver - ok 08:38:11.0101 5208 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\windows\System32\iphlpsvc.dll 08:38:11.0106 5208 iphlpsvc - ok 08:38:11.0156 5208 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\windows\system32\drivers\IPMIDrv.sys 08:38:11.0156 5208 IPMIDRV - ok 08:38:11.0191 5208 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\windows\system32\drivers\ipnat.sys 08:38:11.0191 5208 IPNAT - ok 08:38:11.0416 5208 [ 3D62FE4FEFE9C67DAFEC52B534DFA1FB ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 08:38:11.0431 5208 iPod Service - ok 08:38:11.0496 5208 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\windows\system32\drivers\irenum.sys 08:38:11.0496 5208 IRENUM - ok 08:38:11.0541 5208 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\windows\system32\drivers\isapnp.sys 08:38:11.0546 5208 isapnp - ok 08:38:11.0661 5208 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\windows\system32\drivers\msiscsi.sys 08:38:11.0666 5208 iScsiPrt - ok 08:38:11.0771 5208 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\windows\system32\drivers\kbdclass.sys 08:38:11.0776 5208 kbdclass - ok 08:38:11.0911 5208 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\windows\system32\drivers\kbdhid.sys 08:38:11.0911 5208 kbdhid - ok 08:38:11.0976 5208 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\windows\system32\lsass.exe 08:38:12.0091 5208 KeyIso - ok 08:38:12.0186 5208 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\windows\system32\Drivers\ksecdd.sys 08:38:12.0186 5208 KSecDD - ok 08:38:12.0246 5208 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\windows\system32\Drivers\ksecpkg.sys 08:38:12.0251 5208 KSecPkg - ok 08:38:12.0306 5208 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\windows\system32\drivers\ksthunk.sys 08:38:12.0306 5208 ksthunk - ok 08:38:12.0356 5208 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\windows\system32\msdtckrm.dll 08:38:12.0361 5208 KtmRm - ok 08:38:12.0446 5208 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\windows\system32\srvsvc.dll 08:38:12.0446 5208 LanmanServer - ok 08:38:12.0546 5208 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\windows\System32\wkssvc.dll 08:38:12.0551 5208 LanmanWorkstation - ok 08:38:12.0606 5208 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\windows\system32\DRIVERS\lltdio.sys 08:38:12.0606 5208 lltdio - ok 08:38:12.0696 5208 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\windows\System32\lltdsvc.dll 08:38:12.0706 5208 lltdsvc - ok 08:38:12.0741 5208 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\windows\System32\lmhsvc.dll 08:38:12.0746 5208 lmhosts - ok 08:38:12.0856 5208 [ 41E122F6D1448C94CC05196BC41D6BFB ] LPCFilter C:\windows\system32\DRIVERS\LPCFilter.sys 08:38:12.0856 5208 LPCFilter - ok 08:38:12.0971 5208 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\windows\system32\DRIVERS\lsi_fc.sys 08:38:12.0976 5208 LSI_FC - ok 08:38:13.0001 5208 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\windows\system32\DRIVERS\lsi_sas.sys 08:38:13.0001 5208 LSI_SAS - ok 08:38:13.0066 5208 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\windows\system32\DRIVERS\lsi_sas2.sys 08:38:13.0071 5208 LSI_SAS2 - ok 08:38:13.0096 5208 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\windows\system32\DRIVERS\lsi_scsi.sys 08:38:13.0096 5208 LSI_SCSI - ok 08:38:13.0136 5208 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\windows\system32\drivers\luafv.sys 08:38:13.0141 5208 luafv - ok 08:38:13.0316 5208 [ A8FE8F2783B2929B56F5370A89356CE9 ] MBAMProtector C:\windows\system32\drivers\mbam.sys 08:38:13.0316 5208 MBAMProtector - ok 08:38:13.0576 5208 [ 85B16A92B117A5A800032ECD904B86DB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe 08:38:13.0576 5208 MBAMScheduler - ok 08:38:13.0831 5208 [ 20E2469DB709FC675E655CEAA11BE312 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe 08:38:13.0841 5208 MBAMService - ok 08:38:14.0166 5208 [ 22A7776C5D8EB5930EDF9C8DD0884259 ] McComponentHostService C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe 08:38:14.0171 5208 McComponentHostService - ok 08:38:14.0221 5208 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\windows\system32\Mcx2Svc.dll 08:38:14.0221 5208 Mcx2Svc - ok 08:38:14.0336 5208 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\windows\system32\DRIVERS\megasas.sys 08:38:14.0336 5208 megasas - ok 08:38:14.0386 5208 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\windows\system32\DRIVERS\MegaSR.sys 08:38:14.0391 5208 MegaSR - ok 08:38:14.0481 5208 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\windows\system32\mmcss.dll 08:38:14.0481 5208 MMCSS - ok 08:38:14.0526 5208 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\windows\system32\drivers\modem.sys 08:38:14.0526 5208 Modem - ok 08:38:14.0656 5208 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\windows\system32\DRIVERS\monitor.sys 08:38:14.0656 5208 monitor - ok 08:38:14.0736 5208 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\windows\system32\DRIVERS\mouclass.sys 08:38:14.0741 5208 mouclass - ok 08:38:14.0816 5208 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\windows\system32\DRIVERS\mouhid.sys 08:38:14.0816 5208 mouhid - ok 08:38:14.0891 5208 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\windows\system32\drivers\mountmgr.sys 08:38:14.0891 5208 mountmgr - ok 08:38:15.0081 5208 [ 4D7F2682D29B92A6251B17957AA0B985 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 08:38:15.0081 5208 MozillaMaintenance - ok 08:38:15.0351 5208 [ 05BF204EC0E82CC4A054DB189C8A3D84 ] MpFilter C:\windows\system32\DRIVERS\MpFilter.sys 08:38:15.0356 5208 MpFilter - ok 08:38:15.0451 5208 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\windows\system32\drivers\mpio.sys 08:38:15.0456 5208 mpio - ok 08:38:15.0526 5208 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys 08:38:15.0526 5208 mpsdrv - ok 08:38:15.0691 5208 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\windows\system32\mpssvc.dll 08:38:15.0706 5208 MpsSvc - ok 08:38:15.0751 5208 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\windows\system32\drivers\mrxdav.sys 08:38:15.0756 5208 MRxDAV - ok 08:38:15.0866 5208 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys 08:38:15.0866 5208 mrxsmb - ok 08:38:15.0966 5208 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys 08:38:15.0966 5208 mrxsmb10 - ok 08:38:16.0046 5208 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys 08:38:16.0046 5208 mrxsmb20 - ok 08:38:16.0131 5208 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\windows\system32\drivers\msahci.sys 08:38:16.0131 5208 msahci - ok 08:38:16.0221 5208 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\windows\system32\drivers\msdsm.sys 08:38:16.0226 5208 msdsm - ok 08:38:16.0271 5208 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\windows\System32\msdtc.exe 08:38:16.0286 5208 MSDTC - ok 08:38:16.0416 5208 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\windows\system32\drivers\Msfs.sys 08:38:16.0416 5208 Msfs - ok 08:38:16.0506 5208 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\windows\System32\drivers\mshidkmdf.sys 08:38:16.0511 5208 mshidkmdf - ok 08:38:16.0536 5208 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\windows\system32\drivers\msisadrv.sys 08:38:16.0536 5208 msisadrv - ok 08:38:16.0606 5208 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\windows\system32\iscsiexe.dll 08:38:16.0611 5208 MSiSCSI - ok 08:38:16.0631 5208 msiserver - ok 08:38:16.0676 5208 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys 08:38:16.0676 5208 MSKSSRV - ok 08:38:16.0786 5208 [ CC8E4F72F21340A4D3A3D4DB50313EF5 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe 08:38:16.0786 5208 MsMpSvc - ok 08:38:16.0846 5208 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys 08:38:16.0846 5208 MSPCLOCK - ok 08:38:16.0856 5208 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\windows\system32\drivers\MSPQM.sys 08:38:16.0856 5208 MSPQM - ok 08:38:16.0931 5208 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\windows\system32\drivers\MsRPC.sys 08:38:16.0936 5208 MsRPC - ok 08:38:17.0026 5208 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\windows\system32\drivers\mssmbios.sys 08:38:17.0051 5208 mssmbios - ok 08:38:17.0106 5208 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\windows\system32\drivers\MSTEE.sys 08:38:17.0106 5208 MSTEE - ok 08:38:17.0136 5208 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\windows\system32\DRIVERS\MTConfig.sys 08:38:17.0136 5208 MTConfig - ok 08:38:17.0171 5208 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\windows\system32\Drivers\mup.sys 08:38:17.0171 5208 Mup - ok 08:38:17.0281 5208 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\windows\system32\qagentRT.dll 08:38:17.0286 5208 napagent - ok 08:38:17.0546 5208 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys 08:38:17.0551 5208 NativeWifiP - ok 08:38:17.0761 5208 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\windows\system32\drivers\ndis.sys 08:38:17.0771 5208 NDIS - ok 08:38:17.0851 5208 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\windows\system32\DRIVERS\ndiscap.sys 08:38:17.0851 5208 NdisCap - ok 08:38:17.0896 5208 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys 08:38:17.0901 5208 NdisTapi - ok 08:38:17.0966 5208 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys 08:38:17.0971 5208 Ndisuio - ok 08:38:18.0041 5208 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys 08:38:18.0046 5208 NdisWan - ok 08:38:18.0126 5208 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\windows\system32\drivers\NDProxy.sys 08:38:18.0126 5208 NDProxy - ok 08:38:18.0311 5208 [ 2334DC48997BA203B794DF3EE70521DB ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll 08:38:18.0311 5208 Net Driver HPZ12 - ok 08:38:18.0371 5208 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys 08:38:18.0371 5208 NetBIOS - ok 08:38:18.0451 5208 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\windows\system32\DRIVERS\netbt.sys 08:38:18.0461 5208 NetBT - ok 08:38:18.0491 5208 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\windows\system32\lsass.exe 08:38:18.0491 5208 Netlogon - ok 08:38:18.0616 5208 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\windows\System32\netman.dll 08:38:18.0621 5208 Netman - ok 08:38:18.0656 5208 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\windows\System32\netprofm.dll 08:38:18.0661 5208 netprofm - ok 08:38:18.0701 5208 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 08:38:18.0726 5208 NetTcpPortSharing - ok 08:38:18.0801 5208 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\windows\system32\DRIVERS\nfrd960.sys 08:38:18.0806 5208 nfrd960 - ok 08:38:18.0946 5208 [ 5FF89F20317309D28AC1EDEB0CD1BA72 ] NisDrv C:\windows\system32\DRIVERS\NisDrvWFP.sys 08:38:18.0946 5208 NisDrv - ok 08:38:19.0106 5208 [ 79E80B10FE8F6662E0C9162A68C43444 ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe 08:38:19.0111 5208 NisSrv - ok 08:38:19.0381 5208 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\windows\System32\nlasvc.dll 08:38:19.0391 5208 NlaSvc - ok 08:38:19.0451 5208 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\windows\system32\drivers\Npfs.sys 08:38:19.0451 5208 Npfs - ok 08:38:19.0506 5208 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\windows\system32\nsisvc.dll 08:38:19.0506 5208 nsi - ok 08:38:19.0546 5208 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\windows\system32\drivers\nsiproxy.sys 08:38:19.0551 5208 nsiproxy - ok 08:38:19.0971 5208 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\windows\system32\drivers\Ntfs.sys 08:38:20.0026 5208 Ntfs - ok 08:38:20.0186 5208 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\windows\system32\drivers\Null.sys 08:38:20.0186 5208 Null - ok 08:38:20.0276 5208 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\windows\system32\drivers\nvraid.sys 08:38:20.0276 5208 nvraid - ok 08:38:20.0321 5208 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\windows\system32\drivers\nvstor.sys 08:38:20.0326 5208 nvstor - ok 08:38:20.0451 5208 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\windows\system32\drivers\nv_agp.sys 08:38:20.0456 5208 nv_agp - ok 08:38:20.0586 5208 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\windows\system32\drivers\ohci1394.sys 08:38:20.0591 5208 ohci1394 - ok 08:38:20.0701 5208 [ 4965B005492CBA7719E82B71E3245495 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 08:38:20.0706 5208 ose64 - ok 08:38:21.0726 5208 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 08:38:21.0836 5208 osppsvc - ok 08:38:21.0916 5208 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\windows\system32\pnrpsvc.dll 08:38:21.0921 5208 p2pimsvc - ok 08:38:21.0971 5208 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\windows\system32\p2psvc.dll 08:38:21.0981 5208 p2psvc - ok 08:38:22.0056 5208 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\windows\system32\DRIVERS\parport.sys 08:38:22.0061 5208 Parport - ok 08:38:22.0136 5208 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\windows\system32\drivers\partmgr.sys 08:38:22.0146 5208 partmgr - ok 08:38:22.0186 5208 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\windows\System32\pcasvc.dll 08:38:22.0196 5208 PcaSvc - ok 08:38:22.0256 5208 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\windows\system32\drivers\pci.sys 08:38:22.0256 5208 pci - ok 08:38:22.0331 5208 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\windows\system32\drivers\pciide.sys 08:38:22.0331 5208 pciide - ok 08:38:22.0381 5208 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\windows\system32\DRIVERS\pcmcia.sys 08:38:22.0381 5208 pcmcia - ok 08:38:22.0541 5208 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\windows\system32\drivers\pcw.sys 08:38:22.0541 5208 pcw - ok 08:38:22.0586 5208 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\windows\system32\drivers\peauth.sys 08:38:22.0596 5208 PEAUTH - ok 08:38:22.0676 5208 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\windows\SysWow64\perfhost.exe 08:38:22.0791 5208 PerfHost - ok 08:38:23.0001 5208 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\windows\system32\pla.dll 08:38:23.0051 5208 pla - ok 08:38:23.0136 5208 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\windows\system32\umpnpmgr.dll 08:38:23.0146 5208 PlugPlay - ok 08:38:23.0281 5208 [ AC78DF349F0E4CFB8B667C0CFFF83CCE ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll 08:38:23.0286 5208 Pml Driver HPZ12 - ok 08:38:23.0351 5208 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\windows\system32\pnrpauto.dll 08:38:23.0351 5208 PNRPAutoReg - ok 08:38:23.0486 5208 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\windows\system32\pnrpsvc.dll 08:38:23.0491 5208 PNRPsvc - ok 08:38:23.0586 5208 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\windows\System32\ipsecsvc.dll 08:38:23.0591 5208 PolicyAgent - ok 08:38:23.0661 5208 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\windows\system32\umpo.dll 08:38:23.0661 5208 Power - ok 08:38:23.0776 5208 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\windows\system32\DRIVERS\raspptp.sys 08:38:23.0776 5208 PptpMiniport - ok 08:38:23.0846 5208 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\windows\system32\DRIVERS\processr.sys 08:38:23.0846 5208 Processor - ok 08:38:23.0936 5208 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\windows\system32\profsvc.dll 08:38:23.0941 5208 ProfSvc - ok 08:38:23.0981 5208 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\windows\system32\lsass.exe 08:38:23.0981 5208 ProtectedStorage - ok 08:38:24.0061 5208 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\windows\system32\DRIVERS\pacer.sys 08:38:24.0066 5208 Psched - ok 08:38:24.0156 5208 [ 452C20382DF763F966C12DC48259F34E ] PTUMWBus C:\windows\system32\DRIVERS\PTUMWBus.sys 08:38:24.0156 5208 PTUMWBus - ok 08:38:24.0276 5208 [ 3754C646BBDAEDAFC09F793C6B38E877 ] PTUMWCDF C:\windows\system32\DRIVERS\PTUMWCDF.sys 08:38:24.0276 5208 PTUMWCDF - ok 08:38:24.0346 5208 [ 46823290BF74DFFEBB4E30F9D1E6A46E ] PTUMWCSP C:\windows\system32\DRIVERS\PTUMWCSP.sys 08:38:24.0351 5208 PTUMWCSP - ok 08:38:24.0441 5208 [ AC86BB916FBEA16B0005EFC3BA3ADB58 ] PTUMWFLT C:\windows\system32\DRIVERS\PTUMWFLT.sys 08:38:24.0441 5208 PTUMWFLT - ok 08:38:24.0541 5208 [ CB146794BC3B96661A32CBD68673B479 ] PTUMWMdm C:\windows\system32\DRIVERS\PTUMWMdm.sys 08:38:24.0546 5208 PTUMWMdm - ok 08:38:24.0636 5208 [ 329E77868A92BB6F97C119050D97E9EC ] PTUMWNET C:\windows\system32\DRIVERS\PTUMWNET.sys 08:38:24.0636 5208 PTUMWNET - ok 08:38:24.0721 5208 [ 258AAD147F0B5B7EC45C71D9369145AC ] PTUMWNSP C:\windows\system32\DRIVERS\PTUMWNSP.sys 08:38:24.0726 5208 PTUMWNSP - ok 08:38:24.0956 5208 [ 4FFD7E6D2CB293849C1181D08717EA09 ] PTUMWVsp C:\windows\system32\DRIVERS\PTUMWVsp.sys 08:38:24.0956 5208 PTUMWVsp - ok 08:38:25.0026 5208 [ 4712CC14E720ECCCC0AA16949D18AAF1 ] PxHlpa64 C:\windows\system32\Drivers\PxHlpa64.sys 08:38:25.0026 5208 PxHlpa64 - ok 08:38:25.0216 5208 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\windows\system32\DRIVERS\ql2300.sys 08:38:25.0251 5208 ql2300 - ok 08:38:25.0311 5208 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\windows\system32\DRIVERS\ql40xx.sys 08:38:25.0311 5208 ql40xx - ok 08:38:25.0396 5208 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\windows\system32\qwave.dll 08:38:25.0401 5208 QWAVE - ok 08:38:25.0446 5208 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\windows\system32\drivers\qwavedrv.sys 08:38:25.0451 5208 QWAVEdrv - ok 08:38:25.0531 5208 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\windows\system32\DRIVERS\rasacd.sys 08:38:25.0536 5208 RasAcd - ok 08:38:25.0766 5208 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\windows\system32\DRIVERS\AgileVpn.sys 08:38:25.0776 5208 RasAgileVpn - ok 08:38:25.0826 5208 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\windows\System32\rasauto.dll 08:38:25.0826 5208 RasAuto - ok 08:38:25.0981 5208 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\windows\system32\DRIVERS\rasl2tp.sys 08:38:25.0996 5208 Rasl2tp - ok 08:38:26.0111 5208 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\windows\System32\rasmans.dll 08:38:26.0116 5208 RasMan - ok 08:38:26.0221 5208 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\windows\system32\DRIVERS\raspppoe.sys 08:38:26.0221 5208 RasPppoe - ok 08:38:26.0251 5208 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\windows\system32\DRIVERS\rassstp.sys 08:38:26.0256 5208 RasSstp - ok 08:38:26.0411 5208 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\windows\system32\DRIVERS\rdbss.sys 08:38:26.0421 5208 rdbss - ok 08:38:26.0536 5208 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\windows\system32\DRIVERS\rdpbus.sys 08:38:26.0536 5208 rdpbus - ok 08:38:26.0561 5208 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\windows\system32\DRIVERS\RDPCDD.sys 08:38:26.0561 5208 RDPCDD - ok 08:38:26.0581 5208 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\windows\system32\drivers\rdpencdd.sys 08:38:26.0586 5208 RDPENCDD - ok 08:38:26.0606 5208 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\windows\system32\drivers\rdprefmp.sys 08:38:26.0606 5208 RDPREFMP - ok 08:38:26.0731 5208 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\windows\system32\drivers\RDPWD.sys 08:38:26.0731 5208 RDPWD - ok 08:38:26.0811 5208 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\windows\system32\drivers\rdyboost.sys 08:38:26.0811 5208 rdyboost - ok 08:38:26.0876 5208 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\windows\System32\mprdim.dll 08:38:26.0881 5208 RemoteAccess - ok 08:38:26.0986 5208 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\windows\system32\regsvc.dll 08:38:26.0991 5208 RemoteRegistry - ok 08:38:27.0016 5208 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\windows\System32\RpcEpMap.dll 08:38:27.0021 5208 RpcEptMapper - ok 08:38:27.0061 5208 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\windows\system32\locator.exe 08:38:27.0061 5208 RpcLocator - ok 08:38:27.0146 5208 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\windows\system32\rpcss.dll 08:38:27.0151 5208 RpcSs - ok 08:38:27.0206 5208 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\windows\system32\DRIVERS\rspndr.sys 08:38:27.0211 5208 rspndr - ok 08:38:27.0306 5208 [ 8C22F21C924413D4E109995F748E18BB ] RSUSBSTOR C:\windows\system32\Drivers\RtsUStor.sys 08:38:27.0316 5208 RSUSBSTOR - ok 08:38:27.0391 5208 [ B49DC435AE3695BAC5623DD94B05732D ] RTL8167 C:\windows\system32\DRIVERS\Rt64win7.sys 08:38:27.0391 5208 RTL8167 - ok 08:38:27.0471 5208 [ 945AB249D12CBE044782430C6013AA1A ] RTL8187B C:\windows\system32\DRIVERS\RTL8187B.sys 08:38:27.0476 5208 RTL8187B - ok 08:38:27.0521 5208 RtsUIR - ok 08:38:27.0546 5208 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\windows\system32\lsass.exe 08:38:27.0546 5208 SamSs - ok 08:38:27.0621 5208 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\windows\system32\drivers\sbp2port.sys 08:38:27.0626 5208 sbp2port - ok 08:38:27.0681 5208 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\windows\System32\SCardSvr.dll 08:38:27.0686 5208 SCardSvr - ok 08:38:27.0741 5208 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\windows\system32\DRIVERS\scfilter.sys 08:38:27.0746 5208 scfilter - ok 08:38:27.0921 5208 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\windows\system32\schedsvc.dll 08:38:27.0941 5208 Schedule - ok 08:38:28.0021 5208 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\windows\System32\certprop.dll 08:38:28.0026 5208 SCPolicySvc - ok 08:38:28.0091 5208 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\windows\System32\SDRSVC.dll 08:38:28.0091 5208 SDRSVC - ok 08:38:28.0151 5208 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\windows\system32\drivers\secdrv.sys 08:38:28.0151 5208 secdrv - ok 08:38:28.0236 5208 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\windows\system32\seclogon.dll 08:38:28.0241 5208 seclogon - ok 08:38:28.0296 5208 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\windows\System32\sens.dll 08:38:28.0301 5208 SENS - ok 08:38:28.0316 5208 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\windows\system32\sensrsvc.dll 08:38:28.0321 5208 SensrSvc - ok 08:38:28.0351 5208 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\windows\system32\DRIVERS\serenum.sys 08:38:28.0356 5208 Serenum - ok 08:38:28.0426 5208 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\windows\system32\DRIVERS\serial.sys 08:38:28.0426 5208 Serial - ok 08:38:28.0486 5208 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\windows\system32\DRIVERS\sermouse.sys 08:38:28.0486 5208 sermouse - ok 08:38:28.0561 5208 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\windows\system32\sessenv.dll 08:38:28.0561 5208 SessionEnv - ok 08:38:28.0641 5208 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\windows\system32\drivers\sffdisk.sys 08:38:28.0646 5208 sffdisk - ok 08:38:28.0686 5208 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\windows\system32\drivers\sffp_mmc.sys 08:38:28.0691 5208 sffp_mmc - ok 08:38:28.0711 5208 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\windows\system32\drivers\sffp_sd.sys 08:38:28.0711 5208 sffp_sd - ok 08:38:28.0781 5208 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\windows\system32\DRIVERS\sfloppy.sys 08:38:28.0781 5208 sfloppy - ok 08:38:28.0851 5208 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\windows\System32\ipnathlp.dll 08:38:28.0856 5208 SharedAccess - ok 08:38:28.0916 5208 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\windows\System32\shsvcs.dll 08:38:28.0921 5208 ShellHWDetection - ok 08:38:29.0011 5208 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\windows\system32\DRIVERS\SiSRaid2.sys 08:38:29.0011 5208 SiSRaid2 - ok 08:38:29.0041 5208 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\windows\system32\DRIVERS\sisraid4.sys 08:38:29.0041 5208 SiSRaid4 - ok 08:38:29.0126 5208 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 08:38:29.0131 5208 SkypeUpdate - ok 08:38:29.0176 5208 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\windows\system32\DRIVERS\smb.sys 08:38:29.0176 5208 Smb - ok 08:38:29.0366 5208 [ B5D3C24E4EA8E6D4850E83DAD8C510D4 ] SMSIVZAM5X64 C:\PROGRA~2\VERIZO~1\VZACCE~1\SMSIVZAM5X64.SYS 08:38:29.0366 5208 SMSIVZAM5X64 - ok 08:38:29.0416 5208 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\windows\System32\snmptrap.exe 08:38:29.0426 5208 SNMPTRAP - ok 08:38:29.0456 5208 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\windows\system32\drivers\spldr.sys 08:38:29.0461 5208 spldr - ok 08:38:29.0551 5208 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\windows\System32\spoolsv.exe 08:38:29.0561 5208 Spooler - ok 08:38:30.0236 5208 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\windows\system32\sppsvc.exe 08:38:30.0356 5208 sppsvc - ok 08:38:30.0446 5208 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\windows\system32\sppuinotify.dll 08:38:30.0451 5208 sppuinotify - ok 08:38:30.0771 5208 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\windows\system32\DRIVERS\srv.sys 08:38:30.0826 5208 srv - ok 08:38:30.0906 5208 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\windows\system32\DRIVERS\srv2.sys 08:38:30.0911 5208 srv2 - ok 08:38:30.0966 5208 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\windows\system32\DRIVERS\srvnet.sys 08:38:30.0966 5208 srvnet - ok 08:38:31.0086 5208 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\windows\System32\ssdpsrv.dll 08:38:31.0091 5208 SSDPSRV - ok 08:38:31.0131 5208 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\windows\system32\sstpsvc.dll 08:38:31.0141 5208 SstpSvc - ok 08:38:31.0191 5208 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\windows\system32\DRIVERS\stexstor.sys 08:38:31.0191 5208 stexstor - ok 08:38:31.0336 5208 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\windows\System32\wiaservc.dll 08:38:31.0346 5208 stisvc - ok 08:38:31.0486 5208 [ FF5EB78AF7DFB68C2FB363537AAF753E ] stllssvr C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe 08:38:31.0571 5208 stllssvr - ok 08:38:31.0626 5208 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\windows\system32\drivers\swenum.sys 08:38:31.0626 5208 swenum - ok 08:38:31.0691 5208 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\windows\System32\swprv.dll 08:38:31.0706 5208 swprv - ok 08:38:31.0816 5208 [ BE7311DA9D6833FA69ED04B744A1C8F8 ] SynTP C:\windows\system32\DRIVERS\SynTP.sys 08:38:31.0826 5208 SynTP - ok 08:38:31.0991 5208 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\windows\system32\sysmain.dll 08:38:32.0066 5208 SysMain - ok 08:38:32.0146 5208 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\windows\System32\TabSvc.dll 08:38:32.0151 5208 TabletInputService - ok 08:38:32.0211 5208 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\windows\System32\tapisrv.dll 08:38:32.0216 5208 TapiSrv - ok 08:38:32.0256 5208 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\windows\System32\tbssvc.dll 08:38:32.0261 5208 TBS - ok 08:38:32.0426 5208 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] Tcpip C:\windows\system32\drivers\tcpip.sys 08:38:32.0471 5208 Tcpip - ok 08:38:32.0656 5208 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] TCPIP6 C:\windows\system32\DRIVERS\tcpip.sys 08:38:32.0671 5208 TCPIP6 - ok 08:38:32.0761 5208 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\windows\system32\drivers\tcpipreg.sys 08:38:32.0761 5208 tcpipreg - ok 08:38:32.0861 5208 [ FD542B661BD22FA69CA789AD0AC58C29 ] tdcmdpst C:\windows\system32\DRIVERS\tdcmdpst.sys 08:38:32.0861 5208 tdcmdpst - ok 08:38:32.0926 5208 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\windows\system32\drivers\tdpipe.sys 08:38:32.0926 5208 TDPIPE - ok 08:38:33.0026 5208 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\windows\system32\drivers\tdtcp.sys 08:38:33.0026 5208 TDTCP - ok 08:38:33.0096 5208 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\windows\system32\DRIVERS\tdx.sys 08:38:33.0101 5208 tdx - ok 08:38:33.0126 5208 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\windows\system32\drivers\termdd.sys 08:38:33.0131 5208 TermDD - ok 08:38:33.0191 5208 [ 2E648163254233755035B46DD7B89123 ] TermService C:\windows\System32\termsrv.dll 08:38:33.0196 5208 TermService - ok 08:38:33.0281 5208 [ F0344071948D1A1FA732231785A0664C ] Themes C:\windows\system32\themeservice.dll 08:38:33.0286 5208 Themes - ok 08:38:33.0331 5208 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\windows\system32\mmcss.dll 08:38:33.0351 5208 THREADORDER - ok 08:38:33.0591 5208 [ F120967184A27E927052E8DDBB727851 ] TMachInfo C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe 08:38:33.0591 5208 TMachInfo - ok 08:38:33.0656 5208 [ ED32035BDFECED1AD66D459FD9CC1140 ] TODDSrv C:\Windows\system32\TODDSrv.exe 08:38:33.0656 5208 TODDSrv - ok 08:38:33.0831 5208 [ 06C61275ADC64F1E36240A2287998A5E ] TosCoSrv C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe 08:38:33.0836 5208 TosCoSrv - ok 08:38:33.0991 5208 [ DD58E1250F604CBBADDA04575E5E2376 ] TOSHIBA HDD SSD Alert Service C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe 08:38:33.0991 5208 TOSHIBA HDD SSD Alert Service - ok 08:38:34.0131 5208 [ 09FF7B0B1B5C3D225495CB6F5A9B39F8 ] tos_sps64 C:\windows\system32\DRIVERS\tos_sps64.sys 08:38:34.0141 5208 tos_sps64 - ok 08:38:34.0246 5208 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\windows\System32\trkwks.dll 08:38:34.0251 5208 TrkWks - ok 08:38:34.0396 5208 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe 08:38:34.0401 5208 TrustedInstaller - ok 08:38:34.0496 5208 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\windows\system32\DRIVERS\tssecsrv.sys 08:38:34.0496 5208 tssecsrv - ok 08:38:34.0631 5208 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\windows\system32\drivers\tsusbflt.sys 08:38:34.0631 5208 TsUsbFlt - ok 08:38:34.0756 5208 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\windows\system32\DRIVERS\tunnel.sys 08:38:34.0761 5208 tunnel - ok 08:38:34.0831 5208 [ 550B567F9364D8F7684C3FB3EA665A72 ] TVALZ C:\windows\system32\DRIVERS\TVALZ_O.SYS 08:38:34.0831 5208 TVALZ - ok 08:38:34.0871 5208 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\windows\system32\DRIVERS\uagp35.sys 08:38:34.0871 5208 uagp35 - ok 08:38:35.0001 5208 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\windows\system32\DRIVERS\udfs.sys 08:38:35.0006 5208 udfs - ok 08:38:35.0081 5208 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\windows\system32\UI0Detect.exe 08:38:35.0091 5208 UI0Detect - ok 08:38:35.0126 5208 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\windows\system32\drivers\uliagpkx.sys 08:38:35.0131 5208 uliagpkx - ok 08:38:35.0211 5208 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\windows\system32\drivers\umbus.sys 08:38:35.0211 5208 umbus - ok 08:38:35.0286 5208 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\windows\system32\DRIVERS\umpass.sys 08:38:35.0286 5208 UmPass - ok 08:38:35.0381 5208 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\windows\System32\upnphost.dll 08:38:35.0386 5208 upnphost - ok 08:38:35.0506 5208 [ F724B03C3DFAACF08D17D38BF3333583 ] USBAAPL64 C:\windows\system32\Drivers\usbaapl64.sys 08:38:35.0506 5208 USBAAPL64 - ok 08:38:35.0601 5208 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\windows\system32\drivers\usbaudio.sys 08:38:35.0601 5208 usbaudio - ok 08:38:35.0671 5208 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\windows\system32\DRIVERS\usbccgp.sys 08:38:35.0671 5208 usbccgp - ok 08:38:35.0681 5208 USBCCID - ok 08:38:35.0791 5208 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\windows\system32\drivers\usbcir.sys 08:38:35.0796 5208 usbcir - ok 08:38:35.0861 5208 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\windows\system32\DRIVERS\usbehci.sys 08:38:35.0861 5208 usbehci - ok 08:38:35.0966 5208 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\windows\system32\DRIVERS\usbhub.sys 08:38:35.0971 5208 usbhub - ok 08:38:36.0036 5208 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\windows\system32\drivers\usbohci.sys 08:38:36.0036 5208 usbohci - ok 08:38:36.0086 5208 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\windows\system32\DRIVERS\usbprint.sys 08:38:36.0086 5208 usbprint - ok 08:38:36.0161 5208 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\windows\system32\DRIVERS\usbscan.sys 08:38:36.0161 5208 usbscan - ok 08:38:36.0271 5208 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\windows\system32\DRIVERS\USBSTOR.SYS 08:38:36.0271 5208 USBSTOR - ok 08:38:36.0326 5208 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\windows\system32\DRIVERS\usbuhci.sys 08:38:36.0326 5208 usbuhci - ok 08:38:36.0451 5208 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\windows\system32\Drivers\usbvideo.sys 08:38:36.0451 5208 usbvideo - ok 08:38:36.0486 5208 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\windows\System32\uxsms.dll 08:38:36.0491 5208 UxSms - ok 08:38:36.0516 5208 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\windows\system32\lsass.exe 08:38:36.0516 5208 VaultSvc - ok 08:38:36.0591 5208 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\windows\system32\drivers\vdrvroot.sys 08:38:36.0591 5208 vdrvroot - ok 08:38:36.0736 5208 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\windows\System32\vds.exe 08:38:36.0746 5208 vds - ok 08:38:36.0871 5208 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\windows\system32\DRIVERS\vgapnp.sys 08:38:36.0871 5208 vga - ok 08:38:36.0921 5208 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\windows\System32\drivers\vga.sys 08:38:36.0921 5208 VgaSave - ok 08:38:37.0101 5208 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\windows\system32\drivers\vhdmp.sys 08:38:37.0101 5208 vhdmp - ok 08:38:37.0146 5208 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\windows\system32\drivers\viaide.sys 08:38:37.0146 5208 viaide - ok 08:38:37.0176 5208 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\windows\system32\drivers\volmgr.sys 08:38:37.0176 5208 volmgr - ok 08:38:37.0261 5208 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\windows\system32\drivers\volmgrx.sys 08:38:37.0266 5208 volmgrx - ok 08:38:37.0366 5208 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\windows\system32\drivers\volsnap.sys 08:38:37.0371 5208 volsnap - ok 08:38:37.0451 5208 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\windows\system32\DRIVERS\vsmraid.sys 08:38:37.0456 5208 vsmraid - ok 08:38:37.0626 5208 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\windows\system32\vssvc.exe 08:38:37.0646 5208 VSS - ok 08:38:37.0686 5208 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\windows\System32\drivers\vwifibus.sys 08:38:37.0686 5208 vwifibus - ok 08:38:37.0751 5208 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\windows\system32\DRIVERS\vwififlt.sys 08:38:37.0751 5208 vwififlt - ok 08:38:37.0861 5208 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\windows\system32\w32time.dll 08:38:37.0871 5208 W32Time - ok 08:38:37.0936 5208 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\windows\system32\DRIVERS\wacompen.sys 08:38:37.0936 5208 WacomPen - ok 08:38:38.0061 5208 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\windows\system32\DRIVERS\wanarp.sys 08:38:38.0071 5208 WANARP - ok 08:38:38.0096 5208 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\windows\system32\DRIVERS\wanarp.sys 08:38:38.0096 5208 Wanarpv6 - ok 08:38:38.0361 5208 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\windows\system32\Wat\WatAdminSvc.exe 08:38:38.0396 5208 WatAdminSvc - ok 08:38:38.0631 5208 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\windows\system32\wbengine.exe 08:38:38.0651 5208 wbengine - ok 08:38:38.0686 5208 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\windows\System32\wbiosrvc.dll 08:38:38.0691 5208 WbioSrvc - ok 08:38:38.0891 5208 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\windows\System32\wcncsvc.dll 08:38:38.0896 5208 wcncsvc - ok 08:38:38.0931 5208 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll 08:38:38.0936 5208 WcsPlugInService - ok 08:38:39.0016 5208 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\windows\system32\DRIVERS\wd.sys 08:38:39.0016 5208 Wd - ok 08:38:39.0126 5208 [ A3D04EBF5227886029B4532F20D026F7 ] WDC_SAM C:\windows\system32\DRIVERS\wdcsam64.sys 08:38:39.0126 5208 WDC_SAM - ok 08:38:39.0286 5208 [ E6050FE6B60FA91188B8ABDB5B1E339F ] WDDMService C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe 08:38:39.0291 5208 WDDMService - ok 08:38:39.0336 5208 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\windows\system32\drivers\Wdf01000.sys 08:38:39.0341 5208 Wdf01000 - ok 08:38:39.0546 5208 [ B83D5071B32A70BEBDB3330BFA7ACB80 ] WDFME C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe 08:38:39.0596 5208 WDFME - ok 08:38:39.0626 5208 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\windows\system32\wdi.dll 08:38:39.0631 5208 WdiServiceHost - ok 08:38:39.0641 5208 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\windows\system32\wdi.dll 08:38:39.0646 5208 WdiSystemHost - ok 08:38:39.0786 5208 [ 517DE2C5568CBA6B2A24A557AC60C30B ] WDSC C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe 08:38:39.0831 5208 WDSC - ok 08:38:39.0886 5208 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\windows\System32\webclnt.dll 08:38:39.0896 5208 WebClient - ok 08:38:39.0971 5208 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\windows\system32\wecsvc.dll 08:38:39.0976 5208 Wecsvc - ok 08:38:40.0016 5208 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\windows\System32\wercplsupport.dll 08:38:40.0016 5208 wercplsupport - ok 08:38:40.0046 5208 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\windows\System32\WerSvc.dll 08:38:40.0051 5208 WerSvc - ok 08:38:40.0116 5208 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\windows\system32\DRIVERS\wfplwf.sys 08:38:40.0116 5208 WfpLwf - ok 08:38:40.0176 5208 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\windows\system32\drivers\wimmount.sys 08:38:40.0176 5208 WIMMount - ok 08:38:40.0201 5208 WinDefend - ok 08:38:40.0221 5208 WinHttpAutoProxySvc - ok 08:38:40.0346 5208 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\windows\system32\wbem\WMIsvc.dll 08:38:40.0351 5208 Winmgmt - ok 08:38:40.0491 5208 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\windows\system32\WsmSvc.dll 08:38:40.0551 5208 WinRM - ok 08:38:40.0736 5208 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\windows\system32\DRIVERS\WinUsb.sys 08:38:40.0766 5208 WinUsb - ok 08:38:40.0871 5208 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\windows\System32\wlansvc.dll 08:38:40.0881 5208 Wlansvc - ok 08:38:40.0991 5208 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\windows\system32\drivers\wmiacpi.sys 08:38:40.0991 5208 WmiAcpi - ok 08:38:41.0041 5208 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\windows\system32\wbem\WmiApSrv.exe 08:38:41.0046 5208 wmiApSrv - ok 08:38:41.0146 5208 WMPNetworkSvc - ok 08:38:41.0216 5208 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\windows\System32\wpcsvc.dll 08:38:41.0221 5208 WPCSvc - ok 08:38:41.0296 5208 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\windows\system32\wpdbusenum.dll 08:38:41.0301 5208 WPDBusEnum - ok 08:38:41.0371 5208 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\windows\system32\drivers\ws2ifsl.sys 08:38:41.0371 5208 ws2ifsl - ok 08:38:41.0441 5208 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\windows\System32\wscsvc.dll 08:38:41.0446 5208 wscsvc - ok 08:38:41.0456 5208 WSearch - ok 08:38:41.0681 5208 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\windows\system32\wuaueng.dll 08:38:41.0731 5208 wuauserv - ok 08:38:41.0806 5208 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\windows\system32\drivers\WudfPf.sys 08:38:41.0811 5208 WudfPf - ok 08:38:41.0936 5208 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\windows\system32\DRIVERS\WUDFRd.sys 08:38:41.0941 5208 WUDFRd - ok 08:38:42.0011 5208 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\windows\System32\WUDFSvc.dll 08:38:42.0011 5208 wudfsvc - ok 08:38:42.0066 5208 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\windows\System32\wwansvc.dll 08:38:42.0076 5208 WwanSvc - ok 08:38:42.0141 5208 ================ Scan global =============================== 08:38:42.0221 5208 [ BA0CD8C393E8C9F83354106093832C7B ] C:\windows\system32\basesrv.dll 08:38:42.0306 5208 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\windows\system32\winsrv.dll 08:38:42.0326 5208 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\windows\system32\winsrv.dll 08:38:42.0396 5208 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\windows\system32\sxssrv.dll 08:38:42.0511 5208 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\windows\system32\services.exe 08:38:42.0516 5208 [Global] - ok 08:38:42.0521 5208 ================ Scan MBR ================================== 08:38:42.0591 5208 [ 5B5E648D12FCADC244C1EC30318E1EB9 ] \Device\Harddisk0\DR0 08:38:43.0241 5208 \Device\Harddisk0\DR0 - ok 08:38:43.0241 5208 ================ Scan VBR ================================== 08:38:43.0291 5208 [ D081F37BD3D62809C092D0AEA6AD5670 ] \Device\Harddisk0\DR0\Partition1 08:38:43.0291 5208 \Device\Harddisk0\DR0\Partition1 - ok 08:38:43.0301 5208 ============================================================ 08:38:43.0301 5208 Scan finished 08:38:43.0301 5208 ============================================================ 08:38:43.0321 4300 Detected object count: 0 08:38:43.0321 4300 Actual detected object count: 0
Hi,

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
ComboFix 12-10-25.01 - PC 10/25/2012 9:41.1.1 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2937.1016 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C} SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\{43FD076E-7C17-4EE1-B382-6906FBE50DBB}.xps c:\windows\security\Database\tmp.edb . . ((((((((((((((((((((((((( Files Created from 2012-09-25 to 2012-10-25 ))))))))))))))))))))))))))))))) . . 2012-10-25 13:56 . 2012-10-25 13:56 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-10-25 12:57 . 2012-10-25 12:57 69000 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{12C84F1A-6E66-4502-ADC4-3D8E74300435}\offreg.dll 2012-10-24 22:32 . 2012-10-12 07:19 9291768 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{12C84F1A-6E66-4502-ADC4-3D8E74300435}\mpengine.dll 2012-10-24 13:44 . 2012-10-12 07:19 9291768 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-10-22 15:26 . 2012-10-22 15:26 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll 2012-10-22 15:25 . 2012-10-22 15:25 2876528 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2012-10-22 15:24 . 2012-10-22 15:25 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2012-10-22 13:36 . 2012-10-22 13:36 ——– d—–w- c:\users\PC\AppData\Local\Western_Digital 2012-10-22 13:34 . 2012-10-22 13:35 ——– d—–w- c:\programdata\Western Digital 2012-10-22 13:32 . 2012-10-22 13:32 ——– d—–w- c:\program files\Western Digital 2012-10-22 13:32 . 2012-10-22 13:32 ——– d—–w- c:\program files (x86)\Western Digital 2012-10-20 10:56 . 2012-10-03 11:42 972192 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{68F8A5EA-7F03-4FD4-AE8C-D384694F2CDE}\gapaengine.dll 2012-10-11 20:46 . 2012-10-11 20:46 ——– d—–w- c:\users\PC\AppData\Roaming\NCH Software 2012-10-11 20:45 . 2012-10-11 20:45 ——– d—–w- c:\programdata\NCH Software 2012-10-11 20:45 . 2012-10-11 21:41 ——– d—–w- c:\program files (x86)\NCH Software 2012-10-11 19:06 . 2012-10-11 19:06 ——– d—–w- c:\programdata\AVS4YOU 2012-10-11 19:06 . 2012-10-11 19:06 ——– d—–w- c:\users\PC\AppData\Roaming\AVS4YOU 2012-10-11 19:06 . 2012-10-11 20:45 ——– d—–w- c:\program files (x86)\Common Files\AVSMedia 2012-10-11 19:05 . 2012-04-20 16:08 24576 —-a-w- c:\windows\SysWow64\msxml3a.dll 2012-10-11 19:05 . 2012-10-11 20:45 ——– d—–w- c:\program files (x86)\AVS4YOU 2012-10-11 11:23 . 2012-08-24 18:05 220160 —-a-w- c:\windows\system32\wintrust.dll 2012-10-11 11:23 . 2012-08-24 16:57 172544 —-a-w- c:\windows\SysWow64\wintrust.dll 2012-10-11 11:23 . 2012-09-14 19:19 2048 —-a-w- c:\windows\system32\tzres.dll 2012-10-11 11:23 . 2012-09-14 18:28 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2012-10-11 11:23 . 2012-08-11 00:56 715776 —-a-w- c:\windows\system32\kerberos.dll 2012-10-11 11:23 . 2012-08-10 23:56 542208 —-a-w- c:\windows\SysWow64\kerberos.dll 2012-10-11 11:23 . 2012-06-02 05:41 1464320 —-a-w- c:\windows\system32\crypt32.dll 2012-10-11 11:23 . 2012-06-02 04:36 1159680 —-a-w- c:\windows\SysWow64\crypt32.dll 2012-10-11 11:23 . 2012-06-02 05:41 184320 —-a-w- c:\windows\system32\cryptsvc.dll 2012-10-11 11:23 . 2012-06-02 05:41 140288 —-a-w- c:\windows\system32\cryptnet.dll 2012-10-11 11:23 . 2012-06-02 04:36 140288 —-a-w- c:\windows\SysWow64\cryptsvc.dll 2012-10-11 11:23 . 2012-06-02 04:36 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll 2012-10-11 11:21 . 2012-08-30 18:03 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-10-11 11:21 . 2012-08-30 17:12 3914096 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-10-11 11:21 . 2012-08-30 17:12 3968880 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-10-11 11:06 . 2012-10-11 11:06 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll 2012-10-11 11:06 . 2012-10-11 11:06 2876528 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2012-10-11 11:06 . 2012-10-11 11:06 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2012-10-11 11:06 . 2012-10-11 11:06 539984 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2012-10-10 18:07 . 2012-10-10 18:07 ——– d—–w- c:\users\PC\AppData\Roaming\LavasoftStatistics 2012-10-10 18:04 . 2012-10-10 18:05 ——– d—–w- c:\users\PC\AppData\Roaming\Ad-Aware Antivirus 2012-10-10 17:54 . 2012-10-10 17:54 388096 —-a-r- c:\users\PC\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2012-10-10 17:54 . 2012-10-10 17:54 ——– d—–w- c:\program files (x86)\Trend Micro 2012-10-10 15:42 . 2012-10-10 15:42 ——– d—–w- c:\users\PC\AppData\Roaming\Malwarebytes 2012-10-10 15:41 . 2012-10-10 15:41 ——– d—–w- c:\programdata\Malwarebytes 2012-10-10 15:41 . 2012-10-19 15:29 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-10-10 15:41 . 2012-09-29 23:54 25928 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-10-02 01:42 . 2012-10-02 01:42 ——– d—–w- C:\perflogs 2012-09-28 15:35 . 2012-10-11 23:42 ——– d—–w- c:\windows\rescache 2012-09-26 11:25 . 2012-08-21 21:01 245760 —-a-w- c:\windows\system32\OxpsConverter.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-10-11 12:35 . 2010-09-15 10:57 65309168 —-a-w- c:\windows\system32\MRT.exe 2012-10-09 11:39 . 2012-04-30 01:12 696760 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-10-09 11:39 . 2011-05-20 01:19 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-10-03 11:42 . 2012-08-17 04:20 972192 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2012-08-31 02:03 . 2012-08-31 02:03 228768 —-a-w- c:\windows\system32\drivers\MpFilter.sys 2012-08-31 02:03 . 2011-04-27 19:25 128456 —-a-w- c:\windows\system32\drivers\NisDrvWFP.sys 2012-08-24 11:15 . 2012-09-24 12:50 17810944 —-a-w- c:\windows\system32\mshtml.dll 2012-08-24 10:39 . 2012-09-24 12:49 10925568 —-a-w- c:\windows\system32\ieframe.dll 2012-08-24 10:31 . 2012-09-24 12:50 2312704 —-a-w- c:\windows\system32\jscript9.dll 2012-08-24 10:22 . 2012-09-24 12:50 1346048 —-a-w- c:\windows\system32\urlmon.dll 2012-08-24 10:21 . 2012-09-24 12:50 1392128 —-a-w- c:\windows\system32\wininet.dll 2012-08-24 10:20 . 2012-09-24 12:50 1494528 —-a-w- c:\windows\system32\inetcpl.cpl 2012-08-24 10:18 . 2012-09-24 12:50 237056 —-a-w- c:\windows\system32\url.dll 2012-08-24 10:17 . 2012-09-24 12:50 85504 —-a-w- c:\windows\system32\jsproxy.dll 2012-08-24 10:14 . 2012-09-24 12:50 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2012-08-24 10:14 . 2012-09-24 12:50 816640 —-a-w- c:\windows\system32\jscript.dll 2012-08-24 10:13 . 2012-09-24 12:50 599040 —-a-w- c:\windows\system32\vbscript.dll 2012-08-24 10:12 . 2012-09-24 12:50 2144768 —-a-w- c:\windows\system32\iertutil.dll 2012-08-24 10:11 . 2012-09-24 12:50 729088 —-a-w- c:\windows\system32\msfeeds.dll 2012-08-24 10:10 . 2012-09-24 12:50 96768 —-a-w- c:\windows\system32\mshtmled.dll 2012-08-24 10:09 . 2012-09-24 12:50 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-08-24 10:04 . 2012-09-24 12:50 248320 —-a-w- c:\windows\system32\ieui.dll 2012-08-24 06:59 . 2012-09-24 12:50 1800704 —-a-w- c:\windows\SysWow64\jscript9.dll 2012-08-24 06:51 . 2012-09-24 12:50 1129472 —-a-w- c:\windows\SysWow64\wininet.dll 2012-08-24 06:51 . 2012-09-24 12:50 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2012-08-24 06:47 . 2012-09-24 12:50 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2012-08-24 06:47 . 2012-09-24 12:50 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2012-08-24 06:43 . 2012-09-24 12:50 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2012-08-22 18:12 . 2012-09-12 13:13 1913200 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-08-22 18:12 . 2012-09-12 13:13 950128 —-a-w- c:\windows\system32\drivers\ndis.sys 2012-08-22 18:12 . 2012-09-12 13:13 376688 —-a-w- c:\windows\system32\drivers\netio.sys 2012-08-22 18:12 . 2012-09-12 13:13 288624 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-08-20 17:38 . 2012-10-11 11:24 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-08-02 17:58 . 2012-09-12 13:13 574464 —-a-w- c:\windows\system32\d3d10level9.dll 2012-08-02 16:57 . 2012-09-12 13:13 490496 —-a-w- c:\windows\SysWow64\d3d10level9.dll 2012-07-27 20:51 . 2012-07-27 20:51 24984 —-a-w- c:\windows\system32\AdobePDFUI.dll 2012-07-27 20:51 . 2012-07-27 20:51 53656 —-a-w- c:\windows\system32\AdobePDF.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2011-07-26 23:23 1493160 —-a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2011-07-26 1493160] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Starfield Updater"="c:\users\PC\AppData\Local\Workspace\WorkspaceUpdate.exe" [2012-09-19 34496] "wben"="c:\users\PC\AppData\Local\Workspace\wben.exe" [2012-09-21 1559832] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2009-08-12 352256] "HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2009-06-02 423936] "KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2009-01-14 34088] "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2011-02-11 1295736] "Desktop Disc Tool"="c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2009-07-13 498160] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-30 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-01-25 421160] "ApnUpdater"="c:\program files (x86)\Ask.com\Updater\Updater.exe" [2011-07-26 397992] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208] "Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2012-07-27 36800] "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2012-07-27 823224] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-22 275768] McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe [2011-6-17 272528] WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2011-3-9 4236288] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2011-2-25 15776] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-24 135664] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-09 250808] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-24 135664] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe [2011-06-17 237008] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-19 115168] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-08-31 128456] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-09-13 368896] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-10 174440] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 PTUMWBus;PANTECH USB Modem V2 Composite Device Driver;c:\windows\system32\DRIVERS\PTUMWBus.sys [2009-10-27 71056] R3 PTUMWCDF;PANTECH USB Modem V2 Installation CD;c:\windows\system32\DRIVERS\PTUMWCDF.sys [2009-10-27 24976] R3 PTUMWCSP;PANTECH USB Modem V2 Connection Port;c:\windows\system32\DRIVERS\PTUMWCSP.sys [2009-10-27 173456] R3 PTUMWFLT;PTUMWNET Filter Driver;c:\windows\system32\DRIVERS\PTUMWFLT.sys [2009-10-27 12688] R3 PTUMWMdm;PANTECH USB Modem V2 Modem Driver;c:\windows\system32\DRIVERS\PTUMWMdm.sys [2009-10-27 173456] R3 PTUMWNET;PANTECH USB Modem V2 WWAN Driver;c:\windows\system32\DRIVERS\PTUMWNET.sys [2009-10-27 144912] R3 PTUMWNSP;PANTECH USB Modem V2 NMEA Port;c:\windows\system32\DRIVERS\PTUMWNSP.sys [2009-10-27 173456] R3 PTUMWVsp;PANTECH USB Modem V2 Diagnostic Port;c:\windows\system32\DRIVERS\PTUMWVsp.sys [2009-10-27 173456] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-07-31 222208] R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x] R3 SMSIVZAM5X64;SMSIVZAM5X64 NDIS Protocol Driver;c:\progra~2\VERIZO~1\VZACCE~1\SMSIVZAM5X64.SYS [2009-05-25 43032] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2010-12-15 51712] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-27 1255736] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2011-02-16 14464] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280] S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [2009-07-24 482384] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960] S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2009-08-11 248688] S2 ConfigFree Gadget Service;ConfigFree Gadget Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe [2009-07-15 42368] S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448] S2 File Backup;File Backup Service;c:\program files (x86)\Workspace\offSyncService.exe [2012-10-05 1174824] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-29 399432] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-29 676936] S2 WDDMService;WDDMService;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2011-03-09 288768] S2 WDFME;WD File Management Engine;c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe [2011-03-09 1066896] S2 WDSC;WD File Management Shadow Engine;c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe [2011-03-09 491920] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-29 25928] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-05-23 215040] S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys [2010-03-31 450048] S3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2011-02-11 54136] S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-04 137560] . . — Other Services/Drivers In Memory — . *NewlyCreated* - 29339609 *NewlyCreated* - ASWMBR *Deregistered* - 29339609 *Deregistered* - aswMBR . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2012-10-25 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-30 11:39] . 2012-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-24 13:54] . 2012-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-24 13:54] . 2012-10-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3206294807-2866115109-661179758-1000Core.job - c:\users\PC\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-15 13:41] . 2012-10-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3206294807-2866115109-661179758-1000UA.job - c:\users\PC\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-15 13:41] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\off0] @="{8E33AEC3-C5F2-43C4-B048-9E3EB19B1DD5}" [HKEY_CLASSES_ROOT\CLSID\{8E33AEC3-C5F2-43C4-B048-9E3EB19B1DD5}] 2012-09-19 01:36 1308432 —-a-w- c:\program files (x86)\Workspace\offsyncext64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\off1] @="{8E33AEC4-C5F2-43C4-B048-9E3EB19B1DD5}" [HKEY_CLASSES_ROOT\CLSID\{8E33AEC4-C5F2-43C4-B048-9E3EB19B1DD5}] 2012-09-19 01:36 1308432 —-a-w- c:\program files (x86)\Workspace\offsyncext64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-02 165912] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-02 387608] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-02 365592] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-29 7982112] "TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-04 709976] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-13 1289704] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local; IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 Trusted Zone: intuit.com\ttlc TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\pvf6o9mn.default\ FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: browser.startup.homepage - hxxp://search.yahoo.com/search?fr=mcafee&p= FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p= FF - prefs.js: network.proxy.type - 0 FF - ExtSQL: 2012-09-11 08:21; [removed]; c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF - ExtSQL: 2012-09-18 21:35; wbepaste@starfield; c:\users\PC\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\wbepaste@starfield FF - ExtSQL: 2012-09-18 21:35; zoomext@starfield; c:\users\PC\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\zoomext@starfield FF - ExtSQL: !HIDDEN! 2010-09-11 11:35; [removed]; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKCU-Run-Akamai NetSession Interface - c:\users\PC\AppData\Local\Akamai\netsession_win.exe Wow6432Node-HKLM-Run- - (no file) Toolbar-Locked - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE HKLM-Run-SmoothView - c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe HKLM-Run-00TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe AddRemove-EASEUS Data Recovery Wizard Free Edition 5.5.1_is1 - f:\easeus data recovery wizard free edition 5.5.1\unins000.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-3206294807-2866115109-661179758-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4A8B08D1-4DC1-AA7C-79A7-7FB04A8811B4}*] "jaojlabpjlbihdhpnebn"=hex:6f,61,6c,6b,6a,65,67,68,6f,6a,68,6d,6b,69,69,6d,64, 65,62,64,61,65,63,6c,70,70,69,6a,6c,6b,00,00 "hapjkafebjpjlbdn"=hex:61,62,6f,69,66,6b,6b,6c,63,69,6d,69,67,62,66,64,70,6a, 62,63,6e,70,6a,6a,6d,6f,62,6a,6d,69,64,67,68,6f,00,00 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-10-25 10:23:34 ComboFix-quarantined-files.txt 2012-10-25 14:23 . Pre-Run: 6,695,264,256 bytes free Post-Run: 7,256,338,432 bytes free . - - End Of File - - DEEDDB2A1B42061BB5766AF3E1AD54F0
Hi,
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:


    ClearJavaCache::

    File::
    c:\program files (x86)\Ask.com\GenericAskToolbar.dll

    Registry::
    [-HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "ApnUpdater"=-

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

Post the new ComboFix log and let me know how your system is running now before we move on. :)
The computer is running great today….it has been working fine for the last two days. The problem I have with IE & FF is really strange, one day it barely works and I can only access a few sites, then the next it works fine. It literally happens one day a week (totally random day), each week for the last three to four weeks. Here is the log: ComboFix 12-10-25.01 - PC 10/25/2012 11:22:18.2.1 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2937.1430 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\PC\Desktop\CFScript.txt AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C} SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Ask.com\GenericAskToolbar.dll . . ((((((((((((((((((((((((( Files Created from 2012-09-25 to 2012-10-25 ))))))))))))))))))))))))))))))) . . 2012-10-25 15:34 . 2012-10-25 15:34 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-10-25 14:30 . 2012-10-25 14:30 69000 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1031A524-A142-4827-B743-2CB86EC3437A}\offreg.dll 2012-10-25 14:28 . 2012-10-12 07:19 9291768 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1031A524-A142-4827-B743-2CB86EC3437A}\mpengine.dll 2012-10-25 14:27 . 2012-10-12 07:19 9291768 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-10-22 15:26 . 2012-10-22 15:26 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll 2012-10-22 15:25 . 2012-10-22 15:25 2876528 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2012-10-22 15:24 . 2012-10-22 15:25 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2012-10-22 13:36 . 2012-10-22 13:36 ——– d—–w- c:\users\PC\AppData\Local\Western_Digital 2012-10-22 13:34 . 2012-10-22 13:35 ——– d—–w- c:\programdata\Western Digital 2012-10-22 13:32 . 2012-10-22 13:32 ——– d—–w- c:\program files\Western Digital 2012-10-22 13:32 . 2012-10-22 13:32 ——– d—–w- c:\program files (x86)\Western Digital 2012-10-20 10:56 . 2012-10-03 11:42 972192 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{68F8A5EA-7F03-4FD4-AE8C-D384694F2CDE}\gapaengine.dll 2012-10-11 20:46 . 2012-10-11 20:46 ——– d—–w- c:\users\PC\AppData\Roaming\NCH Software 2012-10-11 20:45 . 2012-10-11 20:45 ——– d—–w- c:\programdata\NCH Software 2012-10-11 20:45 . 2012-10-11 21:41 ——– d—–w- c:\program files (x86)\NCH Software 2012-10-11 19:06 . 2012-10-11 19:06 ——– d—–w- c:\programdata\AVS4YOU 2012-10-11 19:06 . 2012-10-11 19:06 ——– d—–w- c:\users\PC\AppData\Roaming\AVS4YOU 2012-10-11 19:06 . 2012-10-11 20:45 ——– d—–w- c:\program files (x86)\Common Files\AVSMedia 2012-10-11 19:05 . 2012-04-20 16:08 24576 —-a-w- c:\windows\SysWow64\msxml3a.dll 2012-10-11 19:05 . 2012-10-11 20:45 ——– d—–w- c:\program files (x86)\AVS4YOU 2012-10-11 11:23 . 2012-08-24 18:05 220160 —-a-w- c:\windows\system32\wintrust.dll 2012-10-11 11:23 . 2012-08-24 16:57 172544 —-a-w- c:\windows\SysWow64\wintrust.dll 2012-10-11 11:23 . 2012-09-14 19:19 2048 —-a-w- c:\windows\system32\tzres.dll 2012-10-11 11:23 . 2012-09-14 18:28 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2012-10-11 11:23 . 2012-08-11 00:56 715776 —-a-w- c:\windows\system32\kerberos.dll 2012-10-11 11:23 . 2012-08-10 23:56 542208 —-a-w- c:\windows\SysWow64\kerberos.dll 2012-10-11 11:23 . 2012-06-02 05:41 1464320 —-a-w- c:\windows\system32\crypt32.dll 2012-10-11 11:23 . 2012-06-02 04:36 1159680 —-a-w- c:\windows\SysWow64\crypt32.dll 2012-10-11 11:23 . 2012-06-02 05:41 184320 —-a-w- c:\windows\system32\cryptsvc.dll 2012-10-11 11:23 . 2012-06-02 05:41 140288 —-a-w- c:\windows\system32\cryptnet.dll 2012-10-11 11:23 . 2012-06-02 04:36 140288 —-a-w- c:\windows\SysWow64\cryptsvc.dll 2012-10-11 11:23 . 2012-06-02 04:36 103936 —-a-w- c:\windows\SysWow64\cryptnet.dll 2012-10-11 11:21 . 2012-08-30 18:03 5559664 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-10-11 11:21 . 2012-08-30 17:12 3914096 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2012-10-11 11:21 . 2012-08-30 17:12 3968880 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2012-10-11 11:06 . 2012-10-11 11:06 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll 2012-10-11 11:06 . 2012-10-11 11:06 2876528 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2012-10-11 11:06 . 2012-10-11 11:06 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2012-10-11 11:06 . 2012-10-11 11:06 539984 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2012-10-10 18:07 . 2012-10-10 18:07 ——– d—–w- c:\users\PC\AppData\Roaming\LavasoftStatistics 2012-10-10 18:04 . 2012-10-10 18:05 ——– d—–w- c:\users\PC\AppData\Roaming\Ad-Aware Antivirus 2012-10-10 17:54 . 2012-10-10 17:54 388096 —-a-r- c:\users\PC\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2012-10-10 17:54 . 2012-10-10 17:54 ——– d—–w- c:\program files (x86)\Trend Micro 2012-10-10 15:42 . 2012-10-10 15:42 ——– d—–w- c:\users\PC\AppData\Roaming\Malwarebytes 2012-10-10 15:41 . 2012-10-10 15:41 ——– d—–w- c:\programdata\Malwarebytes 2012-10-10 15:41 . 2012-10-19 15:29 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-10-10 15:41 . 2012-09-29 23:54 25928 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-10-02 01:42 . 2012-10-02 01:42 ——– d—–w- C:\perflogs 2012-09-28 15:35 . 2012-10-11 23:42 ——– d—–w- c:\windows\rescache 2012-09-26 11:25 . 2012-08-21 21:01 245760 —-a-w- c:\windows\system32\OxpsConverter.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-10-11 12:35 . 2010-09-15 10:57 65309168 —-a-w- c:\windows\system32\MRT.exe 2012-10-09 11:39 . 2012-04-30 01:12 696760 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-10-09 11:39 . 2011-05-20 01:19 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-10-03 11:42 . 2012-08-17 04:20 972192 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2012-08-31 02:03 . 2012-08-31 02:03 228768 —-a-w- c:\windows\system32\drivers\MpFilter.sys 2012-08-31 02:03 . 2011-04-27 19:25 128456 —-a-w- c:\windows\system32\drivers\NisDrvWFP.sys 2012-08-24 11:15 . 2012-09-24 12:50 17810944 —-a-w- c:\windows\system32\mshtml.dll 2012-08-24 10:39 . 2012-09-24 12:49 10925568 —-a-w- c:\windows\system32\ieframe.dll 2012-08-24 10:31 . 2012-09-24 12:50 2312704 —-a-w- c:\windows\system32\jscript9.dll 2012-08-24 10:22 . 2012-09-24 12:50 1346048 —-a-w- c:\windows\system32\urlmon.dll 2012-08-24 10:21 . 2012-09-24 12:50 1392128 —-a-w- c:\windows\system32\wininet.dll 2012-08-24 10:20 . 2012-09-24 12:50 1494528 —-a-w- c:\windows\system32\inetcpl.cpl 2012-08-24 10:18 . 2012-09-24 12:50 237056 —-a-w- c:\windows\system32\url.dll 2012-08-24 10:17 . 2012-09-24 12:50 85504 —-a-w- c:\windows\system32\jsproxy.dll 2012-08-24 10:14 . 2012-09-24 12:50 173056 —-a-w- c:\windows\system32\ieUnatt.exe 2012-08-24 10:14 . 2012-09-24 12:50 816640 —-a-w- c:\windows\system32\jscript.dll 2012-08-24 10:13 . 2012-09-24 12:50 599040 —-a-w- c:\windows\system32\vbscript.dll 2012-08-24 10:12 . 2012-09-24 12:50 2144768 —-a-w- c:\windows\system32\iertutil.dll 2012-08-24 10:11 . 2012-09-24 12:50 729088 —-a-w- c:\windows\system32\msfeeds.dll 2012-08-24 10:10 . 2012-09-24 12:50 96768 —-a-w- c:\windows\system32\mshtmled.dll 2012-08-24 10:09 . 2012-09-24 12:50 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-08-24 10:04 . 2012-09-24 12:50 248320 —-a-w- c:\windows\system32\ieui.dll 2012-08-24 06:59 . 2012-09-24 12:50 1800704 —-a-w- c:\windows\SysWow64\jscript9.dll 2012-08-24 06:51 . 2012-09-24 12:50 1129472 —-a-w- c:\windows\SysWow64\wininet.dll 2012-08-24 06:51 . 2012-09-24 12:50 1427968 —-a-w- c:\windows\SysWow64\inetcpl.cpl 2012-08-24 06:47 . 2012-09-24 12:50 142848 —-a-w- c:\windows\SysWow64\ieUnatt.exe 2012-08-24 06:47 . 2012-09-24 12:50 420864 —-a-w- c:\windows\SysWow64\vbscript.dll 2012-08-24 06:43 . 2012-09-24 12:50 2382848 —-a-w- c:\windows\SysWow64\mshtml.tlb 2012-08-22 18:12 . 2012-09-12 13:13 1913200 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-08-22 18:12 . 2012-09-12 13:13 950128 —-a-w- c:\windows\system32\drivers\ndis.sys 2012-08-22 18:12 . 2012-09-12 13:13 376688 —-a-w- c:\windows\system32\drivers\netio.sys 2012-08-22 18:12 . 2012-09-12 13:13 288624 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2012-08-20 17:38 . 2012-10-11 11:24 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-08-02 17:58 . 2012-09-12 13:13 574464 —-a-w- c:\windows\system32\d3d10level9.dll 2012-08-02 16:57 . 2012-09-12 13:13 490496 —-a-w- c:\windows\SysWow64\d3d10level9.dll 2012-07-27 20:51 . 2012-07-27 20:51 24984 —-a-w- c:\windows\system32\AdobePDFUI.dll 2012-07-27 20:51 . 2012-07-27 20:51 53656 —-a-w- c:\windows\system32\AdobePDF.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Starfield Updater"="c:\users\PC\AppData\Local\Workspace\WorkspaceUpdate.exe" [2012-09-19 34496] "wben"="c:\users\PC\AppData\Local\Workspace\wben.exe" [2012-09-21 1559832] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2009-08-12 352256] "HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2009-06-02 423936] "KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2009-01-14 34088] "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2011-02-11 1295736] "Desktop Disc Tool"="c:\program files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2009-07-13 498160] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-30 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-01-25 421160] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208] "Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2012-07-27 36800] "Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2012-07-27 823224] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-22 275768] McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\3.0.207\SSScheduler.exe [2011-6-17 272528] WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2011-3-9 4236288] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2011-2-25 15776] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-24 135664] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-09 250808] R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-24 135664] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe [2011-06-17 237008] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-19 115168] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-08-31 128456] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-09-13 368896] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-10 174440] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 PTUMWBus;PANTECH USB Modem V2 Composite Device Driver;c:\windows\system32\DRIVERS\PTUMWBus.sys [2009-10-27 71056] R3 PTUMWCDF;PANTECH USB Modem V2 Installation CD;c:\windows\system32\DRIVERS\PTUMWCDF.sys [2009-10-27 24976] R3 PTUMWCSP;PANTECH USB Modem V2 Connection Port;c:\windows\system32\DRIVERS\PTUMWCSP.sys [2009-10-27 173456] R3 PTUMWFLT;PTUMWNET Filter Driver;c:\windows\system32\DRIVERS\PTUMWFLT.sys [2009-10-27 12688] R3 PTUMWMdm;PANTECH USB Modem V2 Modem Driver;c:\windows\system32\DRIVERS\PTUMWMdm.sys [2009-10-27 173456] R3 PTUMWNET;PANTECH USB Modem V2 WWAN Driver;c:\windows\system32\DRIVERS\PTUMWNET.sys [2009-10-27 144912] R3 PTUMWNSP;PANTECH USB Modem V2 NMEA Port;c:\windows\system32\DRIVERS\PTUMWNSP.sys [2009-10-27 173456] R3 PTUMWVsp;PANTECH USB Modem V2 Diagnostic Port;c:\windows\system32\DRIVERS\PTUMWVsp.sys [2009-10-27 173456] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-07-31 222208] R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x] R3 SMSIVZAM5X64;SMSIVZAM5X64 NDIS Protocol Driver;c:\progra~2\VERIZO~1\VZACCE~1\SMSIVZAM5X64.SYS [2009-05-25 43032] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2010-12-15 51712] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-27 1255736] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2011-02-16 14464] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280] S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [2009-07-24 482384] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960] S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2009-08-11 248688] S2 ConfigFree Gadget Service;ConfigFree Gadget Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe [2009-07-15 42368] S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-11 46448] S2 File Backup;File Backup Service;c:\program files (x86)\Workspace\offSyncService.exe [2012-10-05 1174824] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-29 399432] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-29 676936] S2 WDDMService;WDDMService;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2011-03-09 288768] S2 WDFME;WD File Management Engine;c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe [2011-03-09 1066896] S2 WDSC;WD File Management Shadow Engine;c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe [2011-03-09 491920] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-29 25928] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-05-23 215040] S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys [2010-03-31 450048] S3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2011-02-11 54136] S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-04 137560] . . — Other Services/Drivers In Memory — . *NewlyCreated* - 29339609 *NewlyCreated* - ASWMBR *Deregistered* - 29339609 *Deregistered* - aswMBR . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2012-10-25 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-30 11:39] . 2012-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-24 13:54] . 2012-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-24 13:54] . 2012-10-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3206294807-2866115109-661179758-1000Core.job - c:\users\PC\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-15 13:41] . 2012-10-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3206294807-2866115109-661179758-1000UA.job - c:\users\PC\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-15 13:41] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\off0] @="{8E33AEC3-C5F2-43C4-B048-9E3EB19B1DD5}" [HKEY_CLASSES_ROOT\CLSID\{8E33AEC3-C5F2-43C4-B048-9E3EB19B1DD5}] 2012-09-19 01:36 1308432 —-a-w- c:\program files (x86)\Workspace\offsyncext64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\off1] @="{8E33AEC4-C5F2-43C4-B048-9E3EB19B1DD5}" [HKEY_CLASSES_ROOT\CLSID\{8E33AEC4-C5F2-43C4-B048-9E3EB19B1DD5}] 2012-09-19 01:36 1308432 —-a-w- c:\program files (x86)\Workspace\offsyncext64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-02 165912] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-02 387608] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-02 365592] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-29 7982112] "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU] "TPwrMain"="c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE" [BU] "SmoothView"="c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe" [BU] "00TCrdMain"="c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe" [BU] "TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-04 709976] "TosNC"="c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe" [BU] "TosReelTimeMonitor"="c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe" [BU] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-13 1289704] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local; IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 Trusted Zone: intuit.com\ttlc TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\pvf6o9mn.default\ FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: browser.startup.homepage - hxxp://search.yahoo.com/search?fr=mcafee&p= FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p= FF - prefs.js: network.proxy.type - 0 FF - ExtSQL: 2012-09-11 08:21; [removed]; c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF - ExtSQL: 2012-09-18 21:35; wbepaste@starfield; c:\users\PC\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\wbepaste@starfield FF - ExtSQL: 2012-09-18 21:35; zoomext@starfield; c:\users\PC\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\zoomext@starfield FF - ExtSQL: !HIDDEN! 2010-09-11 11:35; [removed]; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 . - - - - ORPHANS REMOVED - - - - . BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files (x86)\Ask.com\GenericAskToolbar.dll Toolbar-Locked - (no file) Wow6432Node-HKLM-Run- - (no file) AddRemove-EASEUS Data Recovery Wizard Free Edition 5.5.1_is1 - f:\easeus data recovery wizard free edition 5.5.1\unins000.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-3206294807-2866115109-661179758-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4A8B08D1-4DC1-AA7C-79A7-7FB04A8811B4}*] "jaojlabpjlbihdhpnebn"=hex:6f,61,6c,6b,6a,65,67,68,6f,6a,68,6d,6b,69,69,6d,64, 65,62,64,61,65,63,6c,70,70,69,6a,6c,6b,00,00 "hapjkafebjpjlbdn"=hex:61,62,6f,69,66,6b,6b,6c,63,69,6d,69,67,62,66,64,70,6a, 62,63,6e,70,6a,6a,6d,6f,62,6a,6d,69,64,67,68,6f,00,00 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-10-25 11:59:18 ComboFix-quarantined-files.txt 2012-10-25 15:59 ComboFix2.txt 2012-10-25 14:23 . Pre-Run: 7,519,649,792 bytes free Post-Run: 7,467,016,192 bytes free . - - End Of File - - BBC24DDC495938C68C87A8DDA0272990
Good to hear your system is running better. :)

AdwCleaner

Please download AdwCleaner by Xplode onto your desktop.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Search.
  • A logfile will automatically open after the scan has finished.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[R1].txt as well.
———-

Please open OTL.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the Extra Registry section change it to All
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open 2 notepad windows, OTL.Txt and Extra.txt. Please post the Extra.txt.
———-
Adw output # AdwCleaner v2.005 - Logfile created 10/25/2012 at 16:47:10 # Updated 14/10/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : PC - PC-PC # Boot Mode : Normal # Running from : C:\Users\PC\Downloads\AdwCleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Program Files (x86)\Ask.com Folder Found : C:\ProgramData\Partner Folder Found : C:\Users\PC\AppData\LocalLow\AskToolbar Folder Found : C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\pvf6o9mn.default\extensions\[removed] Folder Found : C:\windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} ***** [Registry] ***** Key Found : HKCU\Software\APN Key Found : HKCU\Software\AppDataLow\Software\AskToolbar Key Found : HKCU\Software\Ask.com Key Found : HKCU\Software\Conduit Key Found : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Found : HKLM\Software\APN Key Found : HKLM\Software\AskToolbar Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\Software\Conduit Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Software ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v15.0.1 (en-US) Profile name : default File : C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\pvf6o9mn.default\prefs.js Found : user_pref("extensions.asktb.InstallDir", "C:\\Program Files (x86)\\Ask.com\\"); Found : user_pref("extensions.asktb.abar-war-timeout", "4000"); Found : user_pref("extensions.asktb.cbid", "SV"); Found : user_pref("extensions.asktb.config-updated", true); Found : user_pref("extensions.asktb.crumb", "2011.12.20+15.44.49-toolbar008iad-US-Qm9zdG9uLE1BLFVuaXRlZCBTdG[…] Found : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://www.ask.com/web?q={query}&o={o}&l={l}[…] Found : user_pref("extensions.asktb.dtid", "YYYYYYYYUS"); Found : user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", false); Found : user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "USMA0046"); Found : user_pref("extensions.asktb.dyn-weather-tempunit-weatherWidget", "F"); Found : user_pref("extensions.asktb.first-launch-url", "hxxp://go.sammsoft.com/?linkid=100646"); Found : user_pref("extensions.asktb.first-restart-after-config-update", true); Found : user_pref("extensions.asktb.guid", "342BA21D-C045-4B51-A727-CB5558EEDB80"); Found : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com[…] Found : user_pref("extensions.asktb.if", "first"); Found : user_pref("extensions.asktb.l", "dis"); Found : user_pref("extensions.asktb.last-config-req", "1334493808220"); Found : user_pref("extensions.asktb.last-v", "3.12.5.17640"); Found : user_pref("extensions.asktb.locale", "en_US"); Found : user_pref("extensions.asktb.location", "Boston,MA,United States"); Found : user_pref("extensions.asktb.new-tab-enabled", true); Found : user_pref("extensions.asktb.o", "13959"); Found : user_pref("extensions.asktb.qsrc", "2871"); Found : user_pref("extensions.asktb.sa", "NO"); Found : user_pref("extensions.asktb.search-suggestions-enabled", true); Found : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false); Found : user_pref("extensions.asktb.socialmini-first", true); Found : user_pref("extensions.asktb.socialmini-interval", "1200000"); Found : user_pref("extensions.asktb.socialmini-max-char-ticker", "33"); Found : user_pref("extensions.asktb.socialmini-max-items", "30"); Found : user_pref("extensions.asktb.socialmini-native-on", true); Found : user_pref("extensions.asktb.socialmini-speed", "5000"); Found : user_pref("extensions.asktb.socialmini-transition-first-open", false); Found : user_pref("extensions.asktb.themeid", ""); Found : user_pref("extensions.asktb.to", ""); -\\ Google Chrome v [Unable to get version] File : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[R1].txt - [5883 octets] - [25/10/2012 16:47:10] ########## EOF - C:\AdwCleaner[R1].txt - [5943 octets] ##########
Extras Txt

OTL Extras logfile created on: 10/25/2012 4:51:05 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\PC\Documents
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 1.29 Gb Available Physical Memory | 45.06% Memory free
5.73 Gb Paging File | 3.92 Gb Available in Paging File | 68.41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 222.43 Gb Total Space | 6.74 Gb Free Space | 3.03% Space Free | Partition Type: NTFS
Drive D: | 244.60 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: PC-PC | User Name: PC | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm[@ = chm.file] – C:\windows\hh.exe (Microsoft Corporation)
.cpl[@ = cplfile] – C:\windows\SysNative\control.exe (Microsoft Corporation)
.hlp[@ = hlpfile] – C:\windows\winhlp32.exe (Microsoft Corporation)
.hta[@ = htafile] – C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html[@ = htmlfile] – C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf[@ = inffile] – C:\windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.ini[@ = inifile] – C:\windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\windows\SysNative\rundll32.exe (Microsoft Corporation)
.js[@ = JSFile] – C:\windows\SysNative\WScript.exe (Microsoft Corporation)
.jse[@ = JSEFile] – C:\windows\SysNative\WScript.exe (Microsoft Corporation)
.reg[@ = regfile] – C:\windows\regedit.exe (Microsoft Corporation)
.txt[@ = txtfile] – C:\windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.vbe[@ = VBEFile] – C:\windows\SysNative\WScript.exe (Microsoft Corporation)
.vbs[@ = VBSFile] – C:\windows\SysNative\WScript.exe (Microsoft Corporation)
.wsf[@ = WSFFile] – C:\windows\SysNative\WScript.exe (Microsoft Corporation)
.wsh[@ = WSHFile] – C:\windows\SysNative\WScript.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.bat [@ = batfile] – "%1" %*
.chm [@ = chm.file] – C:\windows\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] – "%1" %*
.com [@ = ComFile] – "%1" %*
.cpl [@ = cplfile] – C:\windows\SysWow64\control.exe (Microsoft Corporation)
.exe [@ = exefile] – "%1" %*
.hlp [@ = hlpfile] – C:\windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] – C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf [@ = inffile] – C:\windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] – C:\windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] – C:\windows\SysWow64\rundll32.exe (Microsoft Corporation)
.js [@ = JSFile] – C:\windows\SysWow64\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] – C:\windows\SysWow64\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] – "%1" %*
.reg [@ = regfile] – C:\windows\SysWow64\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] – "%1" /S
.txt [@ = txtfile] – C:\windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] – C:\windows\SysWow64\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] – C:\windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] – C:\windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] – C:\windows\SysWow64\WScript.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] – "%1" %*
batfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] – "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] – "%1" %*
cmdfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] – C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile – C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] – C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile – C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] – C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] – C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile – %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] – regedit.exe "%1" (Microsoft Corporation)
regfile [merge] – Reg Error: Key error.
regfile [print] – %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
txtfile [open] – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] – %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile – "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] – "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile – "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] – "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile – "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] – "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] – "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] – "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] – "%1" %*
batfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] – "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] – "%1" %*
cmdfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] – C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile – C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] – C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile – C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] – C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] – C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile – %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] – regedit.exe "%1" (Microsoft Corporation)
regfile [merge] – Reg Error: Key error.
regfile [print] – %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
txtfile [open] – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] – %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile – "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] – "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile – "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] – "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile – "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] – "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] – "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] – "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{08E7EBC1-5DE0-4903-987D-ED8CA8EEDD30}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{10E7D911-B4DB-4C20-A1B5-60D3DC1C5468}" = lport=139 | protocol=6 | dir=in | app=system |
"{23994CE6-F32B-4501-A88E-37D054015A92}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{25100A3D-733B-4ABF-AD3E-90145190A005}" = rport=138 | protocol=17 | dir=out | app=system |
"{35BC5E0A-CEFE-4C1F-A479-9DCEAEECB7B7}" = lport=138 | protocol=17 | dir=in | app=system |
"{529AEC24-8C7B-4328-BD1B-C49ED708989A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{5FAD280D-A11E-4EA7-815C-95D47843E410}" = lport=10243 | protocol=6 | dir=in | app=system |
"{6054BD7F-A0FC-4FB5-BC6B-40C88DBBD930}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{62B7D793-B460-4D11-84F6-83BAC7B2785A}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
"{70565CE5-655A-41A5-8E97-B491BCA4D56A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{74B81CF4-4645-4998-B34C-947D8DE011B0}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{77BF4A72-0267-4917-9211-B158329D59E4}" = lport=445 | protocol=6 | dir=in | app=system |
"{9C85A8F8-4BC6-40BB-9390-C10CFCC1B15B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A1FEF736-D013-4E8A-B79D-C3E134DEE6CB}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{AA194F3A-F5C4-4073-AD9F-6BA03B1AD418}" = rport=139 | protocol=6 | dir=out | app=system |
"{B1FDFAD4-04A2-4636-B462-ED20B4AC6187}" = rport=137 | protocol=17 | dir=out | app=system |
"{B3E30C0F-D61E-449F-A42D-57837A0AEDF8}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B7702AF2-D524-4DD8-8328-5F1C88161293}" = rport=10243 | protocol=6 | dir=out | app=system |
"{E1B1D6F6-600A-44C9-A5C8-509C86456C85}" = lport=137 | protocol=17 | dir=in | app=system |
"{E79649B6-7AC2-42C9-BD9B-35613D2154A3}" = rport=445 | protocol=6 | dir=out | app=system |
"{EB4BE5A5-1594-4596-AFA0-D9C67323F1FE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FFB327CA-4DEF-4FC5-AE09-16E58C6AAF1C}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0B49DBFF-1F62-4339-84F6-DB2C35879F57}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{1CA355FD-12EF-4AFC-8192-564E736D9F13}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{2077D146-83C9-47C6-AC50-5E4F027191A0}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe |
"{255FD79E-8A4E-4CED-BBD5-F6624E9F752E}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe |
"{27A5CC07-D0C8-4DC2-8DB7-6024B070CB4C}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{2E5C7C3B-FCA8-45A4-A009-FCB2697B2E79}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqcopy2.exe |
"{2F78CFC9-FEAD-434F-AB16-B2DB4F72D64E}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe |
"{36717913-C597-4CC9-929F-B942730F1509}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3BF103B7-ADD3-4141-8EBD-B6EAF7994B03}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{49278F9B-60FE-4F27-A605-899C6E7CCB93}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{4BCAC104-61E7-4EDC-BB94-DCEEB0747A8D}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{4C9A76F2-2F07-4A14-A852-25144770DE0E}" = protocol=6 | dir=in | app=c:\program files (x86)\dragon age 2\bin_ship\dragonage2.exe |
"{567AEF1B-2668-4DD5-9D77-2610278B5F32}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{5D5EB3D0-F285-4261-B5AA-8C52B3C5D959}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5F12FA79-8F95-4698-821C-D9E53D285C05}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe |
"{5FDDEB52-2500-4F3E-A982-3F7887CC14E9}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{686F289D-53A1-4AFC-9246-3ED683004AFB}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |
"{68BF9258-8875-4005-9343-4222321AB00A}" = protocol=6 | dir=in | app=c:\users\pc\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{6C91E3CD-4835-437A-99CA-40F901BEACA6}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{707C1260-50BB-45C0-958A-CF320D80AB8C}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe |
"{77E25A39-AB37-4750-AAAF-AB8FC7CA08F8}" = protocol=6 | dir=out | app=system |
"{7981776C-CA7B-4EF8-9AA6-E065980B18A7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{79C03456-69E3-432F-ACE4-69BF9E764FFF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{816CA50E-E8D5-478B-A5C1-5E237B9F418E}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{831B64D3-F574-41BB-86B0-92B6893100AD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{850E941C-08DC-40D9-904D-8C77ABEC8819}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{884EE87A-5D74-4C4D-9B62-457AA03774D6}" = protocol=17 | dir=in | app=c:\users\pc\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{88901670-3E17-44CF-8C8B-9157CCD0490A}" = protocol=6 | dir=in | app=c:\program files (x86)\dragon age 2\dragonage2launcher.exe |
"{90199E2A-8C5F-429C-83CB-8911B98B9DFE}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{954B8F10-C21E-4AB0-9388-A43B40D0DC0F}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{A6F68965-7CBF-4984-B589-6B94383866EF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{ADD385DB-5492-42E3-9099-BC773E9A0F2B}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{AEA575AD-FA67-4B3C-BC46-798828BE5B73}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B0A11F0A-24A6-43FC-AF73-B44B3ED30D56}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe |
"{B22980D0-D870-4E14-9385-F8EFF292B10B}" = protocol=17 | dir=in | app=c:\program files (x86)\dragon age 2\dragonage2launcher.exe |
"{BC6FBFFB-A4E9-418E-8B7C-FB25A5291BC0}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BDF629EC-84D6-463D-9E68-F1124EACBF96}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe |
"{C8343CCC-FFD2-462F-B877-A714919C0802}" = protocol=17 | dir=in | app=c:\program files (x86)\dragon age 2\bin_ship\dragonage2.exe |
"{CB8771FF-B3DD-418C-9842-A29A84C52AE4}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe |
"{CBD57668-70F1-449C-B0BA-EB5F062DB361}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe |
"{D46FB61C-9C6B-4E41-8DDF-BEC6AB02E447}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{DCBF897D-DA65-4540-A151-B4B397F78FF8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E049DB77-00BE-455E-9CEB-0DA802C7D9F3}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe |
"{E27C87FD-50DC-4325-ABEC-3F925C92F0A1}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe |
"{E2976B3B-62F1-4036-82EC-755975768BF2}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{E7C39957-AD53-4D03-B37D-3741AE2DCCF6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{EA6F272C-C9ED-491B-9413-2C63900FF46B}" = dir=in | app=c:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{F9A35C93-B937-4C11-BEE9-441DD05E0EE7}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{FACBD019-BA04-4DF3-8F06-31E3514D29B0}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"TCP Query User{88360820-8152-4A40-A00A-D25BD7F3FBB7}C:\users\pc\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\pc\appdata\local\akamai\netsession_win.exe |
"UDP Query User{127B67AC-68B0-4C2C-AC3D-7317FF95A51D}C:\users\pc\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\pc\appdata\local\akamai\netsession_win.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{07179D37-D5FE-4373-90D9-A25B992EFB3E}" = WD SmartWare
"{1C336D20-A089-4818-9C56-96AD81BF5A11}" = PANTECH USB Modem V2
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5BCC94A1-DEF1-4AB4-8046-BC13048E929A}" = TOSHIBA ReelTime
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{77B8B4A5-EE79-4907-A318-2DA86325B8D7}" = iTunes
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}_Office14.SingleImage_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-1000-0000000FF1CE}_Office14.SingleImage_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.SingleImage_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-1000-0000000FF1CE}_Office14.SingleImage_{270CA0B9-9881-44DB-BC3B-37C7E66A044A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-1000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-1000-0000000FF1CE}_Office14.SingleImage_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0000-1000-0000000FF1CE}_Office14.SingleImage_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0043-0409-1000-0000000FF1CE}_Office14.SingleImage_{FCD1C311-8B02-4DBD-BA46-1079C629577E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}_Office14.SingleImage_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}_Office14.SingleImage_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}_Office14.SingleImage_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{C78D3032-9DFD-41D0-9DE9-58EAE750CBA4}" = Microsoft Security Client
"{CDBF8C2D-04B0-4F9B-9AE1-7422F7F0EC94}" = HP Deskjet F2400 All-In-One Driver Software 13.0 Rel .6
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{E4F5E48E-7155-4CF9-88CD-7F377EC9AC54}" = Bonjour
"{E5C95CA5-4565-4B9D-97ED-05088D775614}" = Apple Mobile Device Support
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F64684A0-754B-4637-B7F9-6E8DAA8CD5CD}" = TOSHIBA Bulletin Board
"{FBBC4667-2521-4E78-B1BD-8706F774549B}" = Best Buy pc app
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Print Projects" = HP Print Projects 1.0
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Office14.SingleImage" = Microsoft Office Home and Business 2010
"Shop for HP Supplies" = Shop for HP Supplies
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{0FB630AB-7BD8-40AE-B223-60397D57C3C9}" = Realtek WLAN Driver
"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1B87C40B-A60B-4EF3-9A68-706CF4B69978}" = TOSHIBA Assist
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 14
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{42E2EEB2-D48E-4A47-B181-32ECA031D93B}" = DJ_AIO_06_F2400_SW_Min
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5AF550B4-BB67-4E7E-82F1-2C4300279050}" = ToshibaRegistration
"{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BAA71B6-8F43-4C72-931A-3354ABB0258A}" = F2400
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}" = TOSHIBA Application Installer
"{983CD6FE-8320-4B80-A8F6-0D0366E0AA22}" = TOSHIBA Media Controller
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D76F31F-AEF9-4AE7-8F9C-CE676A4A529A}" = ARRL Exam Review - Technician
"{A33E7B0C-B99C-4EC9-B702-8A328B161AF9}" = Roxio Roxio Burn
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.2
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}" = Roxio Burn
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{DFD30824-6BD0-34E1-ABE8-308AD3CBB9A0}" = Google Talk Plugin
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E69992ED-A7F6-406C-9280-1C156417BC49}" = TOSHIBA Quality Application
"{EBC8295F-BFB4-4DFB-9248-9A8804C1DC48}" = VZAccess Manager
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2E23139-3404-4E3C-9855-7724415D62A5}" = Dragon Age II
"{F3529665-D75E-4D6D-98F0-745C78C68E9B}" = TOSHIBA ConfigFree
"{FAF26102-09D7-4C58-AB01-0D59A2E517CA}" = Copy
"{FBBC4667-2521-4E78-B1BD-8706F774549B}" = Best Buy pc app
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.10
"EASEUS Data Recovery Wizard Free Edition 5.5.1_is1" = EASEUS Data Recovery Wizard Free Edition 5.5.1
"FileZilla Client" = FileZilla Client 3.5.3
"Google Chrome" = Google Chrome
"InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"InstallShield_{5BCC94A1-DEF1-4AB4-8046-BC13048E929A}" = TOSHIBA ReelTime
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"InstallShield_{F64684A0-754B-4637-B7F9-6E8DAA8CD5CD}" = TOSHIBA Bulletin Board
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.1.1000
"McAfee Security Scan" = McAfee Security Scan Plus
"Mozilla Firefox 15.0.1 (x86 en-US)" = Mozilla Firefox 15.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"WinLiveSuite_Wave3" = Windows Live Essentials

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Mozilla Firefox 16.0.1 (x86 en-US)" = Mozilla Firefox 16.0.1 (x86 en-US)
"workspacedesktop" = Workspace Desktop

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 5/2/2012 10:40:32 PM | Computer Name = PC-PC | Source = MsiInstaller | ID = 10005
Description =

Error - 5/3/2012 12:14:19 AM | Computer Name = PC-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 5/3/2012 12:14:19 AM | Computer Name = PC-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1264

Error - 5/3/2012 12:14:19 AM | Computer Name = PC-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1264

Error - 5/3/2012 12:14:20 AM | Computer Name = PC-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 5/3/2012 12:14:20 AM | Computer Name = PC-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 2387

Error - 5/3/2012 12:14:20 AM | Computer Name = PC-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 2387

Error - 5/3/2012 12:14:21 AM | Computer Name = PC-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 5/3/2012 12:14:21 AM | Computer Name = PC-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3526

Error - 5/3/2012 12:14:21 AM | Computer Name = PC-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3526

[ Media Center Events ]
Error - 10/22/2012 8:19:13 AM | Computer Name = PC-PC | Source = MCUpdate | ID = 0
Description = 8:19:13 AM - Error connecting to the internet. 8:19:13 AM - Unable
to contact server..

Error - 10/22/2012 8:19:49 AM | Computer Name = PC-PC | Source = MCUpdate | ID = 0
Description = 8:19:43 AM - Error connecting to the internet. 8:19:43 AM - Unable
to contact server..

Error - 10/22/2012 9:20:32 AM | Computer Name = PC-PC | Source = MCUpdate | ID = 0
Description = 9:20:32 AM - Error connecting to the internet. 9:20:32 AM - Unable
to contact server..

Error - 10/22/2012 9:21:11 AM | Computer Name = PC-PC | Source = MCUpdate | ID = 0
Description = 9:21:06 AM - Error connecting to the internet. 9:21:06 AM - Unable
to contact server..

Error - 10/22/2012 10:22:34 AM | Computer Name = PC-PC | Source = MCUpdate | ID = 0
Description = 10:22:33 AM - Error connecting to the internet. 10:22:34 AM - Unable
to contact server..

Error - 10/22/2012 10:23:23 AM | Computer Name = PC-PC | Source = MCUpdate | ID = 0
Description = 10:23:03 AM - Error connecting to the internet. 10:23:03 AM - Unable
to contact server..

Error - 10/22/2012 5:00:10 PM | Computer Name = PC-PC | Source = MCUpdate | ID = 0
Description = 4:54:31 PM - Error connecting to the internet. 4:54:39 PM - Unable
to contact server..

Error - 10/22/2012 6:01:03 PM | Computer Name = PC-PC | Source = MCUpdate | ID = 0
Description = 6:00:56 PM - Error connecting to the internet. 6:00:56 PM - Unable
to contact server..

Error - 10/22/2012 7:01:43 PM | Computer Name = PC-PC | Source = MCUpdate | ID = 0
Description = 7:01:39 PM - Error connecting to the internet. 7:01:39 PM - Unable
to contact server..

Error - 10/22/2012 8:02:34 PM | Computer Name = PC-PC | Source = MCUpdate | ID = 0
Description = 8:02:27 PM - Error connecting to the internet. 8:02:27 PM - Unable
to contact server..

[ System Events ]
Error - 9/24/2012 11:46:31 AM | Computer Name = PC-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 40. The internal error state
is 107.

Error - 9/24/2012 11:46:31 AM | Computer Name = PC-PC | Source = Schannel | ID = 36874
Description = An SSL 3.0 connection request was received from a remote client application,
but none of the cipher suites supported by the client application are supported
by the server. The SSL connection request has failed.

Error - 9/24/2012 11:46:31 AM | Computer Name = PC-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 40. The internal error state
is 107.

Error - 9/24/2012 11:46:32 AM | Computer Name = PC-PC | Source = Schannel | ID = 36874
Description = An SSL 3.0 connection request was received from a remote client application,
but none of the cipher suites supported by the client application are supported
by the server. The SSL connection request has failed.

Error - 9/24/2012 11:46:32 AM | Computer Name = PC-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 40. The internal error state
is 107.

Error - 9/24/2012 11:46:32 AM | Computer Name = PC-PC | Source = Schannel | ID = 36874
Description = An SSL 3.0 connection request was received from a remote client application,
but none of the cipher suites supported by the client application are supported
by the server. The SSL connection request has failed.

Error - 9/24/2012 11:46:32 AM | Computer Name = PC-PC | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 40. The internal error state
is 107.

Error - 9/25/2012 7:19:20 AM | Computer Name = PC-PC | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 9/25/2012 7:19:41 AM | Computer Name = PC-PC | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 9/25/2012 8:19:13 AM | Computer Name = PC-PC | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.


< End of report >
Hi,

Good job!!
————

AdwCleaner

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • You will be prompted to restart your computer. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
———-

I see that your Java software is out of date. Please go to Start >> Control Panel >> Programs and Features >> uninstall all versions of Java.

Now download and install the newest version from here >> http://java.com/en/download/index.jsp
————-

Clear Java Cache

See this page for instructions on how to clear java's cache.

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.
———-

Malwarebytes

I see that you have Malwarebytes already on your computer. Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

ESET Online Scanner

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
———-

Please post the logs made by AdwCleaner, Malwarebytes and ESET. :)
# AdwCleaner v2.005 - Logfile created 10/25/2012 at 17:16:47
# Updated 14/10/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : PC - PC-PC
# Boot Mode : Normal
# Running from : C:\Users\PC\Downloads\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Program Files (x86)\Ask.com
Folder Deleted : C:\ProgramData\Partner
Folder Deleted : C:\Users\PC\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\pvf6o9mn.default\extensions\[removed]
Folder Deleted : C:\windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

***** [Registry] *****

Key Deleted : HKCU\Software\APN
Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
Key Deleted : HKCU\Software\Ask.com
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\Software\APN
Key Deleted : HKLM\Software\AskToolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Key Deleted : HKLM\SOFTWARE\Software

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v15.0.1 (en-US)

Profile name : default
File : C:\Users\PC\AppData\Roaming\Mozilla\Firefox\Profiles\pvf6o9mn.default\prefs.js

Deleted : user_pref("extensions.asktb.InstallDir", "C:\\Program Files (x86)\\Ask.com\\");
Deleted : user_pref("extensions.asktb.abar-war-timeout", "4000");
Deleted : user_pref("extensions.asktb.cbid", "SV");
Deleted : user_pref("extensions.asktb.config-updated", true);
Deleted : user_pref("extensions.asktb.crumb", "2011.12.20+15.44.49-toolbar008iad-US-Qm9zdG9uLE1BLFVuaXRlZCBTdG[…]
Deleted : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://www.ask.com/web?q={query}&o={o}&l={l}[…]
Deleted : user_pref("extensions.asktb.dtid", "YYYYYYYYUS");
Deleted : user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", false);
Deleted : user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "USMA0046");
Deleted : user_pref("extensions.asktb.dyn-weather-tempunit-weatherWidget", "F");
Deleted : user_pref("extensions.asktb.first-launch-url", "hxxp://go.sammsoft.com/?linkid=100646");
Deleted : user_pref("extensions.asktb.first-restart-after-config-update", true);
Deleted : user_pref("extensions.asktb.guid", "342BA21D-C045-4B51-A727-CB5558EEDB80");
Deleted : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com[…]
Deleted : user_pref("extensions.asktb.if", "first");
Deleted : user_pref("extensions.asktb.l", "dis");
Deleted : user_pref("extensions.asktb.last-config-req", "1334493808220");
Deleted : user_pref("extensions.asktb.last-v", "3.12.5.17640");
Deleted : user_pref("extensions.asktb.locale", "en_US");
Deleted : user_pref("extensions.asktb.location", "Boston,MA,United States");
Deleted : user_pref("extensions.asktb.new-tab-enabled", true);
Deleted : user_pref("extensions.asktb.o", "13959");
Deleted : user_pref("extensions.asktb.qsrc", "2871");
Deleted : user_pref("extensions.asktb.sa", "NO");
Deleted : user_pref("extensions.asktb.search-suggestions-enabled", true);
Deleted : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false);
Deleted : user_pref("extensions.asktb.socialmini-first", true);
Deleted : user_pref("extensions.asktb.socialmini-interval", "1200000");
Deleted : user_pref("extensions.asktb.socialmini-max-char-ticker", "33");
Deleted : user_pref("extensions.asktb.socialmini-max-items", "30");
Deleted : user_pref("extensions.asktb.socialmini-native-on", true);
Deleted : user_pref("extensions.asktb.socialmini-speed", "5000");
Deleted : user_pref("extensions.asktb.socialmini-transition-first-open", false);
Deleted : user_pref("extensions.asktb.themeid", "");
Deleted : user_pref("extensions.asktb.to", "");

-\\ Google Chrome v [Unable to get version]

File : C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [6000 octets] - [25/10/2012 16:47:10]
AdwCleaner[S1].txt - [6302 octets] - [25/10/2012 17:16:47]

########## EOF - C:\AdwCleaner[S1].txt - [6362 octets] ##########


When I went to clear the Temporary Internet Files from Java, the three options I received were
-Trace and Log Files
-Cached Applications and Applets
-Installed Applications and Applets

Should I check those three and then delete?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI