This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

"Remove the Win32/Small.CA virus" [Solved]

39 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Full context: This may or may not be related: I was cheerily browsing the internet using Google Chrome when suddenly every page I visited gave me an 'Aw, snap', including the homepage that shows your most visited sites. I read up on it in a different browser and found this could be down to my anti-virus. I use the free version of avast! so I opened it up and it wanted to update so I let it do that and then restarted my computer to let the update take effect. Sure enough, chrome is fine again. A little later on in the same day, chrome (the only thing I had open at the time) becomes unresponsive and crashes and I can't relaunch it or anything else. Then a message pops up telling me to save my work because windows has encountered a critical error and will restart in 1 minute. No work to save, so I let it restart. When it starts up again it goes through checking what I can only guess are some basic, important files and it apparently found no problems before going on to the desktop as normal. I'm thinking at this point that this is odd, as this has never happened before, but everything's working fine and nothing else weird is happening. Then after 15 or 20 minutes, up comes the message from Windows action centre asking me to "Remove the Win32/Small.CA virus". So this immediately has me worried and I use the scanning program windows recommended (I can't remember what ti was called, Windows Safety Scanner or something like that). I also look up other peoples' experiences with this virus and find similar situations to mine - they have no idea where it could have come from (I had only been on trustworthy sites that day and hadn't opened any attachments, etc). A lot of people recommended Malwarebytes in these cases so I decided to give that a go, too and ran that after the safety scanner scan found nothing. Malwarebytes also found nothing and it was nearly time for bed, so I decided to run an avast! full system scan as well and, again, nothing. Then I go to bed (with nothing odd happening at all since windows alerted me to this virus), intending to start this topic the next day. So now I'm here, but when I started up my PC again today, it got past the windows 'Welcome' screen that I get before getting to the desktop but then it just gave me a black screen, but with a moveable cursor on it. Again, this is not something that I remember happening before. This didn't problem go away in the few minutes I waited so I hit the restart button and everything was fine the second time round. Also, when I opened up chrome to get here, I noticed my cursor got stuck for a split-second (i.e. I moved the mouse but the cursor didn't) at one point. I've noticed this does sometimes happen in chrome from time to time so that may be unrelated. I've never had to deal with anything like this before and am generally quite paranoid about computer-related stuff, so if any procedures you recommend will involve things like momentary black screens or the PC restarting itself or any other temporary side-effects, it would be great to know beforehand :P Anyway, here's the DDS.txt: . DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 16:55:34.08 on 18/12/2012 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.7.2 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.8144.5824 [GMT 0:00] . SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\Windows\system32\atieclxx.exe C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe C:\Program Files (x86)\Bluetooth Suite\adminservice.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe C:\Windows\system32\taskhost.exe C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt C:\Program Files\Intel\iCLS Client\HeciServer.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Windows\SysWOW64\PnkBstrA.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe C:\Windows\system32\svchost.exe -k HPService C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files\Microsoft Device Center\itype.exe C:\Program Files\Microsoft Device Center\ipoint.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe C:\Program Files\AVAST Software\Avast\AvastUI.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe C:\Users\Danny\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Danny\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Danny\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Danny\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Danny\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Danny\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Danny\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Danny\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Danny\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Danny\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Danny\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Danny\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Danny\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Danny\Desktop\dds.scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll mWinlogon: Userinit=userinit.exe BHO: &Yahoo;! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: CIESpeechBHO Class: {8d10f6c4-0e01-4bd4-8601-11ac1fdf8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll uRun: [Google Update] "C:\Users\Danny\AppData\Local\Google\Update\GoogleUpdate.exe" /c uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun uRun: [F.lux] "C:\Users\Danny\Local Settings\Apps\F.lux\flux.exe" /noshow mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe mRun: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun: [] mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" –auto-start StartupFolder: C:\Users\Danny\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: E&xport; to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 IE: Se&nd; to OneNote - C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL BHO-X64: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll BHO-X64: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll BHO-X64: SkypeIEPluginBHO - No File BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL BHO-X64: URLRedirectionBHO - No File BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll TB-X64: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File mRun-x64: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" mRun-x64: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s mRun-x64: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" mRun-x64: [IntelliType Pro] "c:\Program Files\Microsoft Device Center\itype.exe" mRun-x64: [IntelliPoint] "c:\Program Files\Microsoft Device Center\ipoint.exe" IE-X64: {7815BE26-237D-41A8-A98F-F7BD75F71086} . ============= SERVICES / DRIVERS =============== . R0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2012-5-2 19224] R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2012-5-4 984144] R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2012-5-4 370288] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-7-27 63960] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-9-28 239616] R2 asComSvc;ASUS Com Service;C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe [2012-2-1 922240] R2 asHmComSvc;ASUS HM Com Service;C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2012-2-1 915584] R2 AsSysCtrlService;ASUS System Control Service;C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2012-2-1 586880] R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2012-5-4 25232] R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2012-5-4 71600] R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2011-3-13 74912] R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-12-17 44808] R2 cpuz135;cpuz135;C:\Windows\System32\drivers\cpuz135_x64.sys [2012-2-1 21992] R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-10 2465712] R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2012-5-5 8704] R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-2-1 13592] R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-2-2 628448] R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe [2012-5-2 163608] R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-5-11 375728] R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2012-4-2 15928] R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\System32\drivers\LMIRfsDriver.sys [2012-6-26 72216] R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-17 399432] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-17 676936] R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2012-2-1 2214504] R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-12-13 3290896] R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-5-2 363800] R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2012-9-28 10697216] R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2012-9-28 460288] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2012-5-14 96896] R3 BTATH_BUS;Atheros Bluetooth Bus;C:\Windows\System32\drivers\btath_bus.sys [2011-3-13 28832] R3 iusb3hub;Intel® USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2012-5-2 356632] R3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2012-5-2 789272] R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-12-17 25928] R3 MEIx64;Intel® Management Engine Interface ;C:\Windows\System32\drivers\HECIx64.sys [2012-5-2 60184] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-1-18 565352] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-5-4 250808] S3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\System32\drivers\asmthub3.sys [2012-1-18 126952] S3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\System32\drivers\asmtxhci.sys [2012-2-2 369640] S3 ASUSstpt;ASUS USB 3.0 Boost Storage Driver (Storage Driver);C:\Windows\System32\drivers\ASUSstpt.sys [2012-2-1 24648] S3 ASUSumsc;ASUS USB 3.0 Boost Storage Driver (WDM);C:\Windows\System32\drivers\ASUSumsc.sys [2012-2-1 141896] S3 ASUSxpsp;ASUS USB 3.0 Boost Storage Driver (Storage Driver);C:\Windows\System32\drivers\ASUSxpsp.sys [2012-2-1 25160] S3 AthBTPort;Atheros Virtual Bluetooth Class;C:\Windows\System32\drivers\btath_flt.sys [2011-3-13 36000] S3 ATHDFU;Atheros Valkyrie USB BootROM;C:\Windows\System32\drivers\AthDfu.sys [2011-3-13 51872] S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\System32\drivers\btath_a2dp.sys [2011-3-13 298656] S3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\System32\drivers\btath_hcrp.sys [2011-3-13 201376] S3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\System32\drivers\btath_lwflt.sys [2011-3-13 55456] S3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\System32\drivers\btath_rcp.sys [2011-3-13 154272] S3 BtFilter;BtFilter;C:\Windows\System32\drivers\btfilter.sys [2011-3-13 280224] S3 e1cexpress;Intel® PRO/1000 PCI Express Network Connection Driver C;C:\Windows\System32\drivers\e1c62x64.sys [2012-1-18 342704] S3 IAMTVE;Driver for Intel® Active Management Technology - KCS;C:\Windows\System32\drivers\IAMTVE.sys [2012-2-2 43416] S3 IAMTXPE;Driver for Intel® Active Management Technology - KCS;C:\Windows\System32\drivers\IAMTXPE.sys [2012-2-2 51096] S3 ioatdma1;ioatdma1;C:\Windows\System32\drivers\qd162x64.sys [2012-1-18 40144] S3 ioatdma2;Intel® QuickData Technology device ver.2;C:\Windows\System32\drivers\qd262x64.sys [2012-2-2 42192] S3 mv91xx;mv91xx;C:\Windows\System32\drivers\mv91xx.sys [2010-9-17 297000] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2012-1-18 80384] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2012-1-18 181248] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 PciIsaSerial;PCI-ISA Communication Port;C:\Windows\System32\drivers\PciIsaSerial.sys [2012-1-18 72192] S3 PciPPorts;PCI ECP Parallel Port;C:\Windows\System32\drivers\PciPPorts.sys [2012-1-18 95744] S3 PciSPorts;High-Speed PCI Serial Port;C:\Windows\System32\drivers\PciSPorts.sys [2012-1-18 126464] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-2-1 1255736] . =============== Created Last 30 ================ . 2012-12-18 16:44:58 76232 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{E46C8BF8-6F11-4183-AA7A-66F2A65E737E}\offreg.dll 2012-12-18 16:36:55 9125352 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{E46C8BF8-6F11-4183-AA7A-66F2A65E737E}\mpengine.dll 2012-12-17 19:11:32 ——– d—–w- C:\Users\Danny\AppData\Roaming\Malwarebytes 2012-12-17 19:11:20 ——– d—–w- C:\PROGRA~3\Malwarebytes 2012-12-17 19:11:19 25928 —-a-w- C:\Windows\System32\drivers\mbam.sys 2012-12-17 19:11:19 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware 2012-12-12 14:48:03 2048 —-a-w- C:\Windows\SysWow64\tzres.dll 2012-12-12 14:48:03 2048 —-a-w- C:\Windows\System32\tzres.dll 2012-12-11 16:41:58 ——– d—–w- C:\Program Files (x86)\LogMeIn Hamachi 2012-11-28 21:24:52 2560 —-a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui 2012-11-28 21:24:51 9728 —-a-w- C:\Windows\System32\Wdfres.dll 2012-11-28 21:24:51 785512 —-a-w- C:\Windows\System32\drivers\Wdf01000.sys 2012-11-28 21:24:51 54376 —-a-w- C:\Windows\System32\drivers\WdfLdr.sys 2012-11-28 21:20:21 87040 —-a-w- C:\Windows\System32\drivers\WUDFPf.sys 2012-11-28 21:20:21 84992 —-a-w- C:\Windows\System32\WUDFSvc.dll 2012-11-28 21:20:21 198656 —-a-w- C:\Windows\System32\drivers\WUDFRd.sys 2012-11-28 21:20:21 194048 —-a-w- C:\Windows\System32\WUDFPlatform.dll 2012-11-28 21:20:20 744448 —-a-w- C:\Windows\System32\WUDFx.dll 2012-11-28 21:20:20 45056 —-a-w- C:\Windows\System32\WUDFCoinstaller.dll 2012-11-28 21:20:20 229888 —-a-w- C:\Windows\System32\WUDFHost.exe 2012-11-26 14:39:53 95744 —-a-w- C:\Windows\System32\synceng.dll . ==================== Find3M ==================== . 2012-12-12 19:45:08 73656 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-12-12 19:45:08 697272 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-11-22 03:26:40 3149824 —-a-w- C:\Windows\System32\win32k.sys 2012-11-14 06:11:44 2312704 —-a-w- C:\Windows\System32\jscript9.dll 2012-11-14 06:04:11 1392128 —-a-w- C:\Windows\System32\wininet.dll 2012-11-14 06:02:49 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl 2012-11-14 05:57:46 599040 —-a-w- C:\Windows\System32\vbscript.dll 2012-11-14 05:57:35 173056 —-a-w- C:\Windows\System32\ieUnatt.exe 2012-11-14 05:52:40 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2012-11-14 02:09:22 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll 2012-11-14 01:58:15 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2012-11-14 01:57:37 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll 2012-11-14 01:49:25 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe 2012-11-14 01:48:27 420864 —-a-w- C:\Windows\SysWow64\vbscript.dll 2012-11-14 01:44:42 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2012-11-06 22:01:35 88008 —-a-w- C:\Windows\System32\LMIRfsClientNP.dll 2012-11-06 22:01:34 83880 —-a-w- C:\Windows\System32\LMIinit.dll 2012-11-06 22:01:34 35240 —-a-w- C:\Windows\System32\LMIport.dll 2012-11-05 21:35:16 46080 —-a-w- C:\Windows\System32\atmlib.dll 2012-11-05 20:41:32 367616 —-a-w- C:\Windows\System32\atmfd.dll 2012-11-05 20:32:16 295424 —-a-w- C:\Windows\SysWow64\atmfd.dll 2012-11-05 20:32:09 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2012-11-02 05:59:11 478208 —-a-w- C:\Windows\System32\dpnet.dll 2012-11-02 05:11:31 376832 —-a-w- C:\Windows\SysWow64\dpnet.dll 2012-10-30 22:51:55 984144 —-a-w- C:\Windows\System32\drivers\aswSnx.sys 2012-10-30 22:51:55 71600 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys 2012-10-30 22:51:07 41224 —-a-w- C:\Windows\avastSS.scr 2012-10-16 08:38:37 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll 2012-10-16 08:38:34 350208 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll 2012-10-16 07:39:52 561664 —-a-w- C:\Windows\apppatch\AcLayers.dll 2012-10-15 16:59:28 54072 —-a-w- C:\Windows\System32\drivers\aswRdr2.sys 2012-10-10 14:50:36 0 —-a-w- C:\STFB9A3.tmp 2012-10-09 18:17:13 55296 —-a-w- C:\Windows\System32\dhcpcsvc6.dll 2012-10-09 18:17:13 226816 —-a-w- C:\Windows\System32\dhcpcore6.dll 2012-10-09 17:40:31 44032 —-a-w- C:\Windows\SysWow64\dhcpcsvc6.dll 2012-10-09 17:40:31 193536 —-a-w- C:\Windows\SysWow64\dhcpcore6.dll 2012-10-04 17:46:16 362496 —-a-w- C:\Windows\System32\wow64win.dll 2012-10-04 17:46:15 243200 —-a-w- C:\Windows\System32\wow64.dll 2012-10-04 17:46:15 13312 —-a-w- C:\Windows\System32\wow64cpu.dll 2012-10-04 17:45:55 215040 —-a-w- C:\Windows\System32\winsrv.dll 2012-10-04 17:43:28 16384 —-a-w- C:\Windows\System32\ntvdm64.dll 2012-10-04 17:41:16 424960 —-a-w- C:\Windows\System32\KernelBase.dll 2012-10-04 16:47:41 5120 —-a-w- C:\Windows\SysWow64\wow32.dll 2012-10-04 16:47:41 274944 —-a-w- C:\Windows\SysWow64\KernelBase.dll 2012-10-04 15:21:55 338432 —-a-w- C:\Windows\System32\conhost.exe 2012-10-04 14:46:46 7680 —-a-w- C:\Windows\SysWow64\instnm.exe 2012-10-04 14:46:46 25600 —-a-w- C:\Windows\SysWow64\setup16.exe 2012-10-04 14:46:44 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll 2012-10-04 14:46:43 2048 —-a-w- C:\Windows\SysWow64\user.exe 2012-10-04 14:41:50 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll 2012-10-04 14:41:50 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll 2012-10-04 14:41:50 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll 2012-10-04 14:41:50 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll 2012-10-03 17:56:54 1914248 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2012-10-03 17:44:21 70656 —-a-w- C:\Windows\System32\nlaapi.dll 2012-10-03 17:44:21 303104 —-a-w- C:\Windows\System32\nlasvc.dll 2012-10-03 17:44:17 246272 —-a-w- C:\Windows\System32\netcorehc.dll 2012-10-03 17:44:17 18944 —-a-w- C:\Windows\System32\netevent.dll 2012-10-03 17:44:16 216576 —-a-w- C:\Windows\System32\ncsi.dll 2012-10-03 17:42:16 569344 —-a-w- C:\Windows\System32\iphlpsvc.dll 2012-10-03 16:42:24 18944 —-a-w- C:\Windows\SysWow64\netevent.dll 2012-10-03 16:42:24 175104 —-a-w- C:\Windows\SysWow64\netcorehc.dll 2012-10-03 16:42:23 156672 —-a-w- C:\Windows\SysWow64\ncsi.dll 2012-10-03 16:07:26 45568 —-a-w- C:\Windows\System32\drivers\tcpipreg.sys 2012-09-28 14:37:02 221696 —-a-w- C:\Windows\System32\clinfo.exe 2012-09-28 14:36:44 75776 —-a-w- C:\Windows\System32\OpenVideo64.dll 2012-09-28 14:36:40 65536 —-a-w- C:\Windows\SysWow64\OpenVideo.dll 2012-09-28 14:36:36 63488 —-a-w- C:\Windows\System32\OVDecode64.dll 2012-09-28 14:36:34 56320 —-a-w- C:\Windows\SysWow64\OVDecode.dll 2012-09-28 14:36:24 32635904 —-a-w- C:\Windows\System32\amdocl64.dll 2012-09-28 14:32:16 27341824 —-a-w- C:\Windows\SysWow64\amdocl.dll 2012-09-28 02:23:00 5557928 —-a-w- C:\Windows\SysWow64\atiumdag.dll 2012-09-28 02:21:20 10697216 —-a-w- C:\Windows\System32\drivers\atikmdag.sys 2012-09-28 02:05:38 70144 —-a-w- C:\Windows\System32\coinst_9.002.dll 2012-09-28 02:03:52 163840 —-a-w- C:\Windows\System32\atiapfxx.exe 2012-09-28 02:02:30 51200 —-a-w- C:\Windows\System32\aticalrt64.dll 2012-09-28 02:02:28 46080 —-a-w- C:\Windows\SysWow64\aticalrt.dll 2012-09-28 02:02:22 44544 —-a-w- C:\Windows\System32\aticalcl64.dll 2012-09-28 02:02:20 44032 —-a-w- C:\Windows\SysWow64\aticalcl.dll 2012-09-28 02:02:08 16082432 —-a-w- C:\Windows\System32\aticaldd64.dll 2012-09-28 01:59:56 23825920 —-a-w- C:\Windows\System32\atio6axx.dll 2012-09-28 01:57:20 13703168 —-a-w- C:\Windows\SysWow64\aticaldd.dll 2012-09-28 01:43:28 935424 —-a-w- C:\Windows\SysWow64\aticfx32.dll 2012-09-28 01:41:40 1120768 —-a-w- C:\Windows\System32\aticfx64.dll 2012-09-28 01:41:14 19624960 —-a-w- C:\Windows\SysWow64\atioglxx.dll 2012-09-28 01:39:36 6536192 —-a-w- C:\Windows\SysWow64\atidxx32.dll 2012-09-28 01:39:14 442368 —-a-w- C:\Windows\System32\atidemgy.dll 2012-09-28 01:39:08 538112 —-a-w- C:\Windows\System32\atieclxx.exe 2012-09-28 01:38:16 239616 —-a-w- C:\Windows\System32\atiesrxx.exe 2012-09-28 01:36:50 120320 —-a-w- C:\Windows\System32\atitmm64.dll 2012-09-28 01:36:36 21504 —-a-w- C:\Windows\System32\atimuixx.dll 2012-09-28 01:36:30 59392 —-a-w- C:\Windows\System32\atiedu64.dll 2012-09-28 01:36:26 43520 —-a-w- C:\Windows\SysWow64\ati2edxx.dll 2012-09-28 01:31:26 3127296 —-a-w- C:\Windows\System32\atiumd6a.dll 2012-09-28 01:25:24 6704640 —-a-w- C:\Windows\System32\atiumd64.dll 2012-09-28 01:22:42 7167488 —-a-w- C:\Windows\System32\atidxx64.dll 2012-09-28 01:22:30 2691584 —-a-w- C:\Windows\SysWow64\atiumdva.dll 2012-09-28 01:13:40 595456 —-a-w- C:\Windows\System32\atiadlxx.dll 2012-09-28 01:13:30 405504 —-a-w- C:\Windows\SysWow64\atiadlxy.dll 2012-09-28 01:13:16 17920 —-a-w- C:\Windows\System32\atig6pxx.dll . ============= FINISH: 16:55:51.43 =============== Quick side-question: Do you think it's safe for me to transfer files to my USB memory stick without transmitting anything unwanted over? Again, this is all new to me :P Thanks in advance!

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, Danny94

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.

—————————————————————————————————

Sorry for the late response. Do you still need help with this?

—————————————————————————————————
Hello there :) No problem about the delay, I expected to wait a few days so this is perfectly timed as far as I'm concerned :) Anyway, yes, I could still do with some advice on this. I've basically abandoned the machine for the time being and am using this laptop instead. I know there's probably no real need for that, but I guess I just prefer using a machine that can't be doing goodness knows what should I need to, say, log in to something. The computer in question therefore hasn't been used since I started this topic. I guess I should note one other symptom I noticed after I'd done that. I used Chrome again for starting up this topic and when I was done and I closed chrome, it claimed it had crashed and asked if I'd like to relaunch. It was clear it hadn't crashed, but I relaunched anyway and closed it again immediately to see if the same thing would happen and it didn't. I can't say I remember this happening very much before, if at all. It seems, then, that a lot of the oddities are happening to chrome, although they all seem minor. Admittedly, I haven't really used much else other than Internet Explorer, just to see how it behaved and that acted normally, as have other things I tend to have going in the background like steam and skype. So yes, the situation hasn't really advanced since I started this topic because I decided to wait and see what this awesome service recommended, and now you've come to my rescue :D Thanks for offering your help, I really appreciate it :)
Hello,

You're welcome :)

Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Allow it to update where necessary
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
===================================================

Download TDSSKiller.exe and save it to your desktop

Execute TDSSKiller.exe by doubleclicking on it.
Press Start Scan
If Malicious objects are found, do NOT select Cure. Change the action to Skip, and save the log.
Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.log.txt

===================================================

On your next reply please post :
aswMBR log
MBR.dat (attachment)
TDSS Killer log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Cool, that all went as smoothly as I could have ever hoped, and thanks for the swift reply :D Here's the log from aswMBR: aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2012-12-21 14:49:31 —————————– 14:49:31.528 OS Version: Windows x64 6.1.7601 Service Pack 1 14:49:31.528 Number of processors: 4 586 0x2A07 14:49:31.528 ComputerName: GILES UserName: Danny 14:49:33.718 Initialize success 14:49:33.778 AVAST engine defs: 12122100 14:49:49.282 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 14:49:49.285 Disk 0 Vendor: ST1000DM003-9YN162 CC4D Size: 953869MB BusType: 11 14:49:49.300 Disk 0 MBR read successfully 14:49:49.302 Disk 0 MBR scan 14:49:49.304 Disk 0 Windows 7 default MBR code 14:49:49.312 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 14:49:49.318 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848 14:49:49.331 Disk 0 scanning C:\Windows\system32\drivers 14:49:53.138 Service scanning 14:50:25.256 Modules scanning 14:50:25.264 Disk 0 trace - called modules: 14:50:25.295 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys 14:50:25.300 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80077b0060] 14:50:25.306 3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80074ed0c0] 14:50:27.091 AVAST engine scan C:\Windows 14:50:29.191 AVAST engine scan C:\Windows\system32 14:52:42.410 AVAST engine scan C:\Windows\system32\drivers 14:53:13.693 AVAST engine scan C:\Users\Danny 14:59:19.790 AVAST engine scan C:\ProgramData 15:00:06.216 Scan finished successfully 15:00:55.974 Disk 0 MBR has been saved successfully to "C:\Users\Danny\Desktop\MBR.dat" 15:00:55.976 The log file has been saved successfully to "C:\Users\Danny\Desktop\aswMBRscan.txt" And here's the log from TDSS Killer: 15:02:39.0421 2456 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35 15:02:39.0579 2456 ============================================================ 15:02:39.0579 2456 Current date / time: 2012/12/21 15:02:39.0579 15:02:39.0579 2456 SystemInfo: 15:02:39.0579 2456 15:02:39.0579 2456 OS Version: 6.1.7601 ServicePack: 1.0 15:02:39.0579 2456 Product type: Workstation 15:02:39.0579 2456 ComputerName: GILES 15:02:39.0579 2456 UserName: Danny 15:02:39.0579 2456 Windows directory: C:\Windows 15:02:39.0579 2456 System windows directory: C:\Windows 15:02:39.0579 2456 Running under WOW64 15:02:39.0579 2456 Processor architecture: Intel x64 15:02:39.0579 2456 Number of processors: 4 15:02:39.0579 2456 Page size: 0x1000 15:02:39.0579 2456 Boot type: Normal boot 15:02:39.0579 2456 ============================================================ 15:02:40.0282 2456 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 15:02:40.0295 2456 ============================================================ 15:02:40.0295 2456 \Device\Harddisk0\DR0: 15:02:40.0295 2456 MBR partitions: 15:02:40.0295 2456 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 15:02:40.0295 2456 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800 15:02:40.0295 2456 ============================================================ 15:02:40.0337 2456 C: <-> \Device\Harddisk0\DR0\Partition2 15:02:40.0337 2456 ============================================================ 15:02:40.0337 2456 Initialize success 15:02:40.0337 2456 ============================================================ 15:02:48.0338 5252 ============================================================ 15:02:48.0338 5252 Scan started 15:02:48.0338 5252 Mode: Manual; 15:02:48.0338 5252 ============================================================ 15:02:48.0676 5252 ================ Scan system memory ======================== 15:02:48.0676 5252 System memory - ok 15:02:48.0677 5252 ================ Scan services ============================= 15:02:48.0951 5252 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 15:02:48.0953 5252 1394ohci - ok 15:02:48.0961 5252 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 15:02:48.0964 5252 ACPI - ok 15:02:48.0965 5252 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 15:02:48.0966 5252 AcpiPmi - ok 15:02:49.0058 5252 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 15:02:49.0059 5252 AdobeARMservice - ok 15:02:49.0228 5252 [ 95CE557D16A75606CCC2D7F3B0B0BCCB ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 15:02:49.0229 5252 AdobeFlashPlayerUpdateSvc - ok 15:02:49.0260 5252 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 15:02:49.0263 5252 adp94xx - ok 15:02:49.0266 5252 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys 15:02:49.0268 5252 adpahci - ok 15:02:49.0278 5252 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 15:02:49.0280 5252 adpu320 - ok 15:02:49.0289 5252 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 15:02:49.0290 5252 AeLookupSvc - ok 15:02:49.0309 5252 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 15:02:49.0312 5252 AFD - ok 15:02:49.0328 5252 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 15:02:49.0330 5252 agp440 - ok 15:02:49.0337 5252 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 15:02:49.0338 5252 ALG - ok 15:02:49.0369 5252 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 15:02:49.0370 5252 aliide - ok 15:02:49.0486 5252 ALSysIO - ok 15:02:49.0558 5252 [ 4C1E3649C89C7D542CD18ECC5210099D ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe 15:02:49.0560 5252 AMD External Events Utility - ok 15:02:49.0562 5252 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 15:02:49.0562 5252 amdide - ok 15:02:49.0588 5252 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 15:02:49.0589 5252 AmdK8 - ok 15:02:49.0687 5252 [ A3C0A15B39F979E8F3EABA901D72ECD7 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys 15:02:49.0773 5252 amdkmdag - ok 15:02:49.0793 5252 [ 20F3CD38B107C1BD747C0EA37D450165 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys 15:02:49.0795 5252 amdkmdap - ok 15:02:49.0797 5252 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys 15:02:49.0797 5252 AmdPPM - ok 15:02:49.0821 5252 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 15:02:49.0823 5252 amdsata - ok 15:02:49.0841 5252 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys 15:02:49.0842 5252 amdsbs - ok 15:02:49.0844 5252 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 15:02:49.0844 5252 amdxata - ok 15:02:49.0852 5252 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 15:02:49.0853 5252 AppID - ok 15:02:49.0864 5252 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 15:02:49.0865 5252 AppIDSvc - ok 15:02:49.0867 5252 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll 15:02:49.0868 5252 Appinfo - ok 15:02:49.0870 5252 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys 15:02:49.0870 5252 arc - ok 15:02:49.0878 5252 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys 15:02:49.0878 5252 arcsas - ok 15:02:49.0932 5252 [ 6E3F4538B33BC19259E99BE1826286A3 ] asComSvc C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe 15:02:49.0935 5252 asComSvc - ok 15:02:49.0987 5252 [ A63173897EA1A73A75D0E65036DE5B15 ] asHmComSvc C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe 15:02:49.0990 5252 asHmComSvc - ok 15:02:50.0029 5252 [ FEF9DD9EA587F8886ADE43C1BEFBDAFE ] AsIO C:\Windows\syswow64\drivers\AsIO.sys 15:02:50.0029 5252 AsIO - ok 15:02:50.0064 5252 [ 954950D11ADA98AC1B7EE3C770E4622C ] asmthub3 C:\Windows\system32\drivers\asmthub3.sys 15:02:50.0065 5252 asmthub3 - ok 15:02:50.0074 5252 [ B0CF9AB16006B61634D4F955345CA5D2 ] asmtxhci C:\Windows\system32\drivers\asmtxhci.sys 15:02:50.0076 5252 asmtxhci - ok 15:02:50.0270 5252 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 15:02:50.0271 5252 aspnet_state - ok 15:02:50.0286 5252 [ 5C31DFB196CB3A488A041881634D86D2 ] AsSysCtrlService C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe 15:02:50.0288 5252 AsSysCtrlService - ok 15:02:50.0300 5252 [ A5E4CDB420540095D1293C874B5F89AA ] ASUSFILTER C:\Windows\syswow64\drivers\ASUSFILTER.sys 15:02:50.0301 5252 ASUSFILTER - ok 15:02:50.0309 5252 [ 7882BB401553008C3D17251D98474412 ] ASUSstpt C:\Windows\system32\drivers\ASUSstpt.sys 15:02:50.0309 5252 ASUSstpt - ok 15:02:50.0312 5252 [ 23041D6FADF1287457E12CDBE2466554 ] ASUSumsc C:\Windows\system32\drivers\ASUSumsc.sys 15:02:50.0313 5252 ASUSumsc - ok 15:02:50.0315 5252 [ 6A3FD248900D5FB97065ACC3E33FED02 ] ASUSxpsp C:\Windows\system32\drivers\ASUSxpsp.sys 15:02:50.0315 5252 ASUSxpsp - ok 15:02:50.0343 5252 [ 4FCAEF0C5BE7629AEB878998E0FE959B ] aswFsBlk C:\Windows\system32\drivers\aswFsBlk.sys 15:02:50.0343 5252 aswFsBlk - ok 15:02:50.0353 5252 [ B50CDD87772D6A11CB90924AAD399DF8 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys 15:02:50.0353 5252 aswMonFlt - ok 15:02:50.0382 5252 [ 57768C7DB4681F2510F247F82EF31D4F ] aswRdr C:\Windows\System32\Drivers\aswrdr2.sys 15:02:50.0383 5252 aswRdr - ok 15:02:50.0435 5252 [ E71D826A1F3CE9C9DE3E77F2D02AFFBF ] aswSnx C:\Windows\system32\drivers\aswSnx.sys 15:02:50.0438 5252 aswSnx - ok 15:02:50.0460 5252 [ 538A32E2C99BF073D4CA76C30BEDAA60 ] aswSP C:\Windows\system32\drivers\aswSP.sys 15:02:50.0461 5252 aswSP - ok 15:02:50.0469 5252 [ 6EDC79D73745FD44C41B55B2D13D0B70 ] aswTdi C:\Windows\system32\drivers\aswTdi.sys 15:02:50.0470 5252 aswTdi - ok 15:02:50.0485 5252 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 15:02:50.0485 5252 AsyncMac - ok 15:02:50.0494 5252 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 15:02:50.0494 5252 atapi - ok 15:02:50.0501 5252 [ CBE61B4494165F458BD87E37181EE934 ] AthBTPort C:\Windows\system32\DRIVERS\btath_flt.sys 15:02:50.0501 5252 AthBTPort - ok 15:02:50.0508 5252 [ 4119870B90E1B5E7797D6433D21F9216 ] ATHDFU C:\Windows\System32\Drivers\AthDfu.sys 15:02:50.0509 5252 ATHDFU - ok 15:02:50.0550 5252 [ 21753130331188C4B474E1D3B396E629 ] AtherosSvc C:\Program Files (x86)\Bluetooth Suite\adminservice.exe 15:02:50.0551 5252 AtherosSvc - ok 15:02:50.0607 5252 [ B0790FF0E25B7A2674296052F2162C1A ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys 15:02:50.0607 5252 AtiHDAudioService - ok 15:02:50.0645 5252 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 15:02:50.0648 5252 AudioEndpointBuilder - ok 15:02:50.0653 5252 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 15:02:50.0655 5252 AudioSrv - ok 15:02:50.0742 5252 [ 8FA553E9AE69808D99C164733A0F9590 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe 15:02:50.0742 5252 avast! Antivirus - ok 15:02:50.0754 5252 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 15:02:50.0755 5252 AxInstSV - ok 15:02:50.0815 5252 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys 15:02:50.0823 5252 b06bdrv - ok 15:02:50.0832 5252 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 15:02:50.0834 5252 b57nd60a - ok 15:02:50.0843 5252 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 15:02:50.0843 5252 BDESVC - ok 15:02:50.0845 5252 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 15:02:50.0846 5252 Beep - ok 15:02:50.0877 5252 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll 15:02:50.0880 5252 BFE - ok 15:02:50.0907 5252 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll 15:02:50.0913 5252 BITS - ok 15:02:50.0915 5252 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 15:02:50.0915 5252 blbdrive - ok 15:02:50.0917 5252 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 15:02:50.0918 5252 bowser - ok 15:02:50.0920 5252 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys 15:02:50.0920 5252 BrFiltLo - ok 15:02:50.0922 5252 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys 15:02:50.0922 5252 BrFiltUp - ok 15:02:50.0948 5252 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 15:02:50.0949 5252 Browser - ok 15:02:50.0971 5252 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 15:02:50.0973 5252 Brserid - ok 15:02:50.0975 5252 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 15:02:50.0975 5252 BrSerWdm - ok 15:02:50.0977 5252 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 15:02:50.0977 5252 BrUsbMdm - ok 15:02:50.0979 5252 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 15:02:50.0979 5252 BrUsbSer - ok 15:02:50.0990 5252 [ FE70889A85C57A9268101B2DB0474509 ] BTATH_A2DP C:\Windows\system32\drivers\btath_a2dp.sys 15:02:50.0991 5252 BTATH_A2DP - ok 15:02:51.0022 5252 [ A83A91D07D1FE6BBE7A9DB46CA00434B ] BTATH_BUS C:\Windows\system32\DRIVERS\btath_bus.sys 15:02:51.0023 5252 BTATH_BUS - ok 15:02:51.0029 5252 [ C864FF85EE16D61C2BDD5EF76824625F ] BTATH_HCRP C:\Windows\system32\drivers\btath_hcrp.sys 15:02:51.0030 5252 BTATH_HCRP - ok 15:02:51.0033 5252 [ 0DEA505EFB5D771826D177EF8B8A208F ] BTATH_LWFLT C:\Windows\system32\DRIVERS\btath_lwflt.sys 15:02:51.0033 5252 BTATH_LWFLT - ok 15:02:51.0036 5252 [ 724C8088C96EFE7A3E63FEC21D4681C0 ] BTATH_RCP C:\Windows\system32\drivers\btath_rcp.sys 15:02:51.0037 5252 BTATH_RCP - ok 15:02:51.0041 5252 [ AA0F5AFCF077C5246589B32ECEEAE566 ] BtFilter C:\Windows\system32\DRIVERS\btfilter.sys 15:02:51.0043 5252 BtFilter - ok 15:02:51.0057 5252 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys 15:02:51.0058 5252 BthEnum - ok 15:02:51.0061 5252 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys 15:02:51.0061 5252 BTHMODEM - ok 15:02:51.0063 5252 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys 15:02:51.0064 5252 BthPan - ok 15:02:51.0092 5252 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys 15:02:51.0095 5252 BTHPORT - ok 15:02:51.0111 5252 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 15:02:51.0113 5252 bthserv - ok 15:02:51.0132 5252 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys 15:02:51.0133 5252 BTHUSB - ok 15:02:51.0145 5252 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 15:02:51.0146 5252 cdfs - ok 15:02:51.0149 5252 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 15:02:51.0150 5252 cdrom - ok 15:02:51.0160 5252 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 15:02:51.0161 5252 CertPropSvc - ok 15:02:51.0169 5252 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys 15:02:51.0170 5252 circlass - ok 15:02:51.0183 5252 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 15:02:51.0186 5252 CLFS - ok 15:02:51.0252 5252 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 15:02:51.0254 5252 clr_optimization_v2.0.50727_32 - ok 15:02:51.0321 5252 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 15:02:51.0323 5252 clr_optimization_v2.0.50727_64 - ok 15:02:51.0431 5252 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 15:02:51.0439 5252 clr_optimization_v4.0.30319_32 - ok 15:02:51.0464 5252 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 15:02:51.0466 5252 clr_optimization_v4.0.30319_64 - ok 15:02:51.0478 5252 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\drivers\CmBatt.sys 15:02:51.0478 5252 CmBatt - ok 15:02:51.0480 5252 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 15:02:51.0480 5252 cmdide - ok 15:02:51.0499 5252 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 15:02:51.0502 5252 CNG - ok 15:02:51.0520 5252 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\drivers\compbatt.sys 15:02:51.0522 5252 Compbatt - ok 15:02:51.0524 5252 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys 15:02:51.0524 5252 CompositeBus - ok 15:02:51.0526 5252 COMSysApp - ok 15:02:51.0543 5252 cpuz130 - ok 15:02:51.0569 5252 [ CCB09EB78E047C931708149992C2E435 ] cpuz135 C:\Windows\system32\drivers\cpuz135_x64.sys 15:02:51.0570 5252 cpuz135 - ok 15:02:51.0579 5252 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 15:02:51.0581 5252 crcdisk - ok 15:02:51.0613 5252 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll 15:02:51.0616 5252 CryptSvc - ok 15:02:51.0650 5252 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 15:02:51.0658 5252 DcomLaunch - ok 15:02:51.0676 5252 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 15:02:51.0679 5252 defragsvc - ok 15:02:51.0686 5252 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 15:02:51.0687 5252 DfsC - ok 15:02:51.0716 5252 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 15:02:51.0720 5252 Dhcp - ok 15:02:51.0739 5252 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 15:02:51.0740 5252 discache - ok 15:02:51.0754 5252 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys 15:02:51.0756 5252 Disk - ok 15:02:51.0786 5252 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 15:02:51.0789 5252 Dnscache - ok 15:02:51.0800 5252 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 15:02:51.0804 5252 dot3svc - ok 15:02:51.0815 5252 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 15:02:51.0818 5252 DPS - ok 15:02:51.0844 5252 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 15:02:51.0845 5252 drmkaud - ok 15:02:51.0874 5252 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 15:02:51.0881 5252 DXGKrnl - ok 15:02:51.0921 5252 [ EAFCB4551836FF44EE775CEDDFA7A77E ] e1cexpress C:\Windows\system32\DRIVERS\e1c62x64.sys 15:02:51.0925 5252 e1cexpress - ok 15:02:51.0933 5252 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 15:02:51.0935 5252 EapHost - ok 15:02:51.0994 5252 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys 15:02:52.0037 5252 ebdrv - ok 15:02:52.0069 5252 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 15:02:52.0070 5252 EFS - ok 15:02:52.0124 5252 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 15:02:52.0131 5252 ehRecvr - ok 15:02:52.0141 5252 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 15:02:52.0143 5252 ehSched - ok 15:02:52.0180 5252 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys 15:02:52.0186 5252 elxstor - ok 15:02:52.0189 5252 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 15:02:52.0190 5252 ErrDev - ok 15:02:52.0206 5252 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 15:02:52.0211 5252 EventSystem - ok 15:02:52.0216 5252 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 15:02:52.0219 5252 exfat - ok 15:02:52.0229 5252 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 15:02:52.0230 5252 fastfat - ok 15:02:52.0241 5252 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 15:02:52.0245 5252 Fax - ok 15:02:52.0247 5252 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys 15:02:52.0248 5252 fdc - ok 15:02:52.0270 5252 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 15:02:52.0271 5252 fdPHost - ok 15:02:52.0273 5252 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 15:02:52.0274 5252 FDResPub - ok 15:02:52.0287 5252 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 15:02:52.0287 5252 FileInfo - ok 15:02:52.0289 5252 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 15:02:52.0289 5252 Filetrace - ok 15:02:52.0294 5252 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys 15:02:52.0295 5252 flpydisk - ok 15:02:52.0306 5252 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 15:02:52.0308 5252 FltMgr - ok 15:02:52.0334 5252 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll 15:02:52.0340 5252 FontCache - ok 15:02:52.0364 5252 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 15:02:52.0365 5252 FontCache3.0.0.0 - ok 15:02:52.0370 5252 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 15:02:52.0370 5252 FsDepends - ok 15:02:52.0382 5252 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 15:02:52.0382 5252 Fs_Rec - ok 15:02:52.0385 5252 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 15:02:52.0387 5252 fvevol - ok 15:02:52.0403 5252 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 15:02:52.0416 5252 gagp30kx - ok 15:02:52.0434 5252 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 15:02:52.0438 5252 gpsvc - ok 15:02:52.0460 5252 [ 1E6438D4EA6E1174A3B3B1EDC4DE660B ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys 15:02:52.0461 5252 hamachi - ok 15:02:52.0536 5252 [ 785FD63B74B30986A9F2C7D965CA509F ] Hamachi2Svc C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe 15:02:52.0543 5252 Hamachi2Svc - ok 15:02:52.0577 5252 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 15:02:52.0577 5252 hcw85cir - ok 15:02:52.0588 5252 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 15:02:52.0591 5252 HdAudAddService - ok 15:02:52.0593 5252 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 15:02:52.0594 5252 HDAudBus - ok 15:02:52.0607 5252 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys 15:02:52.0609 5252 HidBatt - ok 15:02:52.0625 5252 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys 15:02:52.0626 5252 HidBth - ok 15:02:52.0643 5252 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys 15:02:52.0644 5252 HidIr - ok 15:02:52.0652 5252 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll 15:02:52.0653 5252 hidserv - ok 15:02:52.0685 5252 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 15:02:52.0685 5252 HidUsb - ok 15:02:52.0745 5252 [ 82B2A78BCA8CA0B63BF09005783C6548 ] HiPatchService C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe 15:02:52.0746 5252 HiPatchService - ok 15:02:52.0764 5252 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 15:02:52.0765 5252 hkmsvc - ok 15:02:52.0778 5252 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 15:02:52.0780 5252 HomeGroupListener - ok 15:02:52.0794 5252 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 15:02:52.0797 5252 HomeGroupProvider - ok 15:02:53.0033 5252 [ 1DAE5C46D42B02A6D5862E1482EFB390 ] hpqcxs08 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll 15:02:53.0034 5252 hpqcxs08 - ok 15:02:53.0043 5252 [ 99E8EEF42FE2F4AF29B08C3355DD7685 ] hpqddsvc C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll 15:02:53.0044 5252 hpqddsvc - ok 15:02:53.0046 5252 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 15:02:53.0046 5252 HpSAMD - ok 15:02:53.0082 5252 [ F37882F128EFACEFE353E0BAE2766909 ] HPSLPSVC C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL 15:02:53.0085 5252 HPSLPSVC - ok 15:02:53.0099 5252 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 15:02:53.0108 5252 HTTP - ok 15:02:53.0120 5252 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 15:02:53.0120 5252 hwpolicy - ok 15:02:53.0139 5252 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 15:02:53.0140 5252 i8042prt - ok 15:02:53.0153 5252 [ 87A72502C8AC5E89B5A46FF6E874F5C5 ] IAMTVE C:\Windows\system32\drivers\IAMTVE.sys 15:02:53.0154 5252 IAMTVE - ok 15:02:53.0156 5252 [ 5516F8E518A2F6A8755498F3E73957CF ] IAMTXPE C:\Windows\system32\drivers\IAMTXPE.sys 15:02:53.0156 5252 IAMTXPE - ok 15:02:53.0231 5252 [ 2FDAEC4B02729C48C0FD1B0B4695995B ] iaStor C:\Windows\system32\drivers\iaStor.sys 15:02:53.0240 5252 iaStor - ok 15:02:53.0319 5252 [ D41861E56E7552C13674D7F147A02464 ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe 15:02:53.0320 5252 IAStorDataMgrSvc - ok 15:02:53.0340 5252 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 15:02:53.0343 5252 iaStorV - ok 15:02:53.0388 5252 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 15:02:53.0394 5252 idsvc - ok 15:02:53.0403 5252 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys 15:02:53.0404 5252 iirsp - ok 15:02:53.0426 5252 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 15:02:53.0431 5252 IKEEXT - ok 15:02:53.0492 5252 [ 589B94A9B73A0E819FF873743A480834 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys 15:02:53.0499 5252 IntcAzAudAddService - ok 15:02:53.0558 5252 [ 832CE330DD987227B7DEA8C03F22AEFA ] Intel® Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe 15:02:53.0560 5252 Intel® Capability Licensing Service Interface - ok 15:02:53.0562 5252 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 15:02:53.0563 5252 intelide - ok 15:02:53.0600 5252 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 15:02:53.0600 5252 intelppm - ok 15:02:53.0608 5252 [ E45575812630B049CE0F679D87561A4D ] ioatdma1 C:\Windows\System32\Drivers\qd162x64.sys 15:02:53.0608 5252 ioatdma1 - ok 15:02:53.0610 5252 [ 2C23820DD9E81199E60F553EB50BC449 ] ioatdma2 C:\Windows\System32\Drivers\qd262x64.sys 15:02:53.0611 5252 ioatdma2 - ok 15:02:53.0622 5252 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 15:02:53.0623 5252 IPBusEnum - ok 15:02:53.0625 5252 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 15:02:53.0626 5252 IpFilterDriver - ok 15:02:53.0658 5252 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 15:02:53.0662 5252 iphlpsvc - ok 15:02:53.0664 5252 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 15:02:53.0665 5252 IPMIDRV - ok 15:02:53.0687 5252 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 15:02:53.0688 5252 IPNAT - ok 15:02:53.0703 5252 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 15:02:53.0703 5252 IRENUM - ok 15:02:53.0720 5252 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 15:02:53.0720 5252 isapnp - ok 15:02:53.0730 5252 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 15:02:53.0732 5252 iScsiPrt - ok 15:02:53.0766 5252 [ B2381712638B0B714D0EEAB9A1F7C640 ] iusb3hcs C:\Windows\system32\DRIVERS\iusb3hcs.sys 15:02:53.0766 5252 iusb3hcs - ok 15:02:53.0778 5252 [ FD2C6457232E95C014DAD21DEBC64867 ] iusb3hub C:\Windows\system32\DRIVERS\iusb3hub.sys 15:02:53.0779 5252 iusb3hub - ok 15:02:53.0793 5252 [ F6A2B5D030BE7EDF8ADC12C9A40825A8 ] iusb3xhc C:\Windows\system32\DRIVERS\iusb3xhc.sys 15:02:53.0796 5252 iusb3xhc - ok 15:02:53.0837 5252 [ B443D3D1B6F21C2B424E49491B65C488 ] jhi_service C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe 15:02:53.0838 5252 jhi_service - ok 15:02:53.0854 5252 [ A577F5DB30F70ECA9708C07C2EACBD9D ] JRAID C:\Windows\system32\drivers\jraid.sys 15:02:53.0855 5252 JRAID - ok 15:02:53.0870 5252 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 15:02:53.0870 5252 kbdclass - ok 15:02:53.0879 5252 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 15:02:53.0880 5252 kbdhid - ok 15:02:53.0910 5252 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 15:02:53.0911 5252 KeyIso - ok 15:02:53.0947 5252 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 15:02:53.0948 5252 KSecDD - ok 15:02:53.0954 5252 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 15:02:53.0955 5252 KSecPkg - ok 15:02:53.0970 5252 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 15:02:53.0971 5252 ksthunk - ok 15:02:53.0986 5252 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 15:02:53.0989 5252 KtmRm - ok 15:02:54.0004 5252 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll 15:02:54.0007 5252 LanmanServer - ok 15:02:54.0012 5252 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 15:02:54.0014 5252 LanmanWorkstation - ok 15:02:54.0016 5252 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 15:02:54.0017 5252 lltdio - ok 15:02:54.0030 5252 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 15:02:54.0032 5252 lltdsvc - ok 15:02:54.0043 5252 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 15:02:54.0044 5252 lmhosts - ok 15:02:54.0123 5252 [ 7109163D8027076D2680CFC4E80E2A28 ] LMIGuardianSvc C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe 15:02:54.0124 5252 LMIGuardianSvc - ok 15:02:54.0133 5252 [ 0317335B15FF3BDA8E10197E3434CFC0 ] LMIInfo C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys 15:02:54.0134 5252 LMIInfo - ok 15:02:54.0147 5252 [ 8054CE1FC8B417691960D00F931516A7 ] LMIMaint C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe 15:02:54.0148 5252 LMIMaint - ok 15:02:54.0174 5252 [ 413ECDCFAD9A82804D3674C8D7EEC24E ] lmimirr C:\Windows\system32\DRIVERS\lmimirr.sys 15:02:54.0175 5252 lmimirr - ok 15:02:54.0177 5252 LMIRfsClientNP - ok 15:02:54.0192 5252 [ C57D3FAA50E6F395759FFB7C709BD944 ] LMIRfsDriver C:\Windows\system32\drivers\LMIRfsDriver.sys 15:02:54.0193 5252 LMIRfsDriver - ok 15:02:54.0202 5252 [ 9BE23DF9B1FC56F58DD0F28CC187E713 ] LMS C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe 15:02:54.0203 5252 LMS - ok 15:02:54.0213 5252 [ D3760BC17E1755091B7120CF32DBF56B ] LogMeIn C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe 15:02:54.0214 5252 LogMeIn - ok 15:02:54.0226 5252 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 15:02:54.0228 5252 LSI_FC - ok 15:02:54.0244 5252 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 15:02:54.0245 5252 LSI_SAS - ok 15:02:54.0247 5252 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys 15:02:54.0248 5252 LSI_SAS2 - ok 15:02:54.0262 5252 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 15:02:54.0264 5252 LSI_SCSI - ok 15:02:54.0271 5252 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 15:02:54.0278 5252 luafv - ok 15:02:54.0309 5252 [ A8FE8F2783B2929B56F5370A89356CE9 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys 15:02:54.0310 5252 MBAMProtector - ok 15:02:54.0353 5252 [ 85B16A92B117A5A800032ECD904B86DB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe 15:02:54.0354 5252 MBAMScheduler - ok 15:02:54.0372 5252 [ 20E2469DB709FC675E655CEAA11BE312 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe 15:02:54.0374 5252 MBAMService - ok 15:02:54.0385 5252 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 15:02:54.0386 5252 Mcx2Svc - ok 15:02:54.0420 5252 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys 15:02:54.0421 5252 megasas - ok 15:02:54.0430 5252 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys 15:02:54.0432 5252 MegaSR - ok 15:02:54.0465 5252 [ 6B01B7414A105B9E51652089A03027CF ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys 15:02:54.0466 5252 MEIx64 - ok 15:02:54.0476 5252 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 15:02:54.0478 5252 MMCSS - ok 15:02:54.0480 5252 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 15:02:54.0481 5252 Modem - ok 15:02:54.0497 5252 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 15:02:54.0497 5252 monitor - ok 15:02:54.0503 5252 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 15:02:54.0504 5252 mouclass - ok 15:02:54.0512 5252 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 15:02:54.0512 5252 mouhid - ok 15:02:54.0519 5252 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 15:02:54.0525 5252 mountmgr - ok 15:02:54.0561 5252 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 15:02:54.0562 5252 mpio - ok 15:02:54.0566 5252 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 15:02:54.0567 5252 mpsdrv - ok 15:02:54.0584 5252 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll 15:02:54.0589 5252 MpsSvc - ok 15:02:54.0591 5252 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 15:02:54.0592 5252 MRxDAV - ok 15:02:54.0604 5252 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 15:02:54.0606 5252 mrxsmb - ok 15:02:54.0617 5252 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 15:02:54.0619 5252 mrxsmb10 - ok 15:02:54.0621 5252 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 15:02:54.0621 5252 mrxsmb20 - ok 15:02:54.0629 5252 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 15:02:54.0629 5252 msahci - ok 15:02:54.0631 5252 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 15:02:54.0632 5252 msdsm - ok 15:02:54.0635 5252 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 15:02:54.0636 5252 MSDTC - ok 15:02:54.0645 5252 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 15:02:54.0646 5252 Msfs - ok 15:02:54.0647 5252 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 15:02:54.0648 5252 mshidkmdf - ok 15:02:54.0649 5252 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 15:02:54.0650 5252 msisadrv - ok 15:02:54.0658 5252 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 15:02:54.0659 5252 MSiSCSI - ok 15:02:54.0661 5252 msiserver - ok 15:02:54.0670 5252 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 15:02:54.0671 5252 MSKSSRV - ok 15:02:54.0680 5252 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 15:02:54.0680 5252 MSPCLOCK - ok 15:02:54.0687 5252 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 15:02:54.0688 5252 MSPQM - ok 15:02:54.0701 5252 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 15:02:54.0704 5252 MsRPC - ok 15:02:54.0712 5252 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys 15:02:54.0712 5252 mssmbios - ok 15:02:54.0714 5252 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 15:02:54.0714 5252 MSTEE - ok 15:02:54.0720 5252 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys 15:02:54.0721 5252 MTConfig - ok 15:02:54.0733 5252 [ 19B006B181E3875FD254F7B67ACF1E7C ] MTsensor C:\Windows\system32\drivers\ASACPI.sys 15:02:54.0733 5252 MTsensor - ok 15:02:54.0735 5252 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 15:02:54.0736 5252 Mup - ok 15:02:54.0776 5252 [ 34D08C9C64F657D194961E96C47E9C69 ] mv91xx C:\Windows\system32\drivers\mv91xx.sys 15:02:54.0778 5252 mv91xx - ok 15:02:54.0789 5252 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 15:02:54.0793 5252 napagent - ok 15:02:54.0827 5252 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 15:02:54.0829 5252 NativeWifiP - ok 15:02:54.0868 5252 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys 15:02:54.0872 5252 NDIS - ok 15:02:54.0885 5252 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 15:02:54.0887 5252 NdisCap - ok 15:02:54.0905 5252 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 15:02:54.0905 5252 NdisTapi - ok 15:02:54.0908 5252 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 15:02:54.0909 5252 Ndisuio - ok 15:02:54.0921 5252 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 15:02:54.0922 5252 NdisWan - ok 15:02:54.0925 5252 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 15:02:54.0926 5252 NDProxy - ok 15:02:54.0948 5252 [ 2334DC48997BA203B794DF3EE70521DB ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll 15:02:54.0949 5252 Net Driver HPZ12 - ok 15:02:54.0951 5252 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 15:02:54.0952 5252 NetBIOS - ok 15:02:54.0955 5252 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 15:02:54.0957 5252 NetBT - ok 15:02:54.0969 5252 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 15:02:54.0970 5252 Netlogon - ok 15:02:55.0000 5252 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 15:02:55.0003 5252 Netman - ok 15:02:55.0021 5252 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 15:02:55.0023 5252 NetMsmqActivator - ok 15:02:55.0040 5252 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 15:02:55.0041 5252 NetPipeActivator - ok 15:02:55.0056 5252 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 15:02:55.0059 5252 netprofm - ok 15:02:55.0064 5252 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 15:02:55.0065 5252 NetTcpActivator - ok 15:02:55.0068 5252 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 15:02:55.0069 5252 NetTcpPortSharing - ok 15:02:55.0078 5252 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 15:02:55.0080 5252 nfrd960 - ok 15:02:55.0092 5252 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll 15:02:55.0095 5252 NlaSvc - ok 15:02:55.0097 5252 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 15:02:55.0097 5252 Npfs - ok 15:02:55.0110 5252 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 15:02:55.0112 5252 nsi - ok 15:02:55.0120 5252 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 15:02:55.0121 5252 nsiproxy - ok 15:02:55.0167 5252 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 15:02:55.0184 5252 Ntfs - ok 15:02:55.0203 5252 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 15:02:55.0205 5252 Null - ok 15:02:55.0212 5252 [ 158AD24745BD85BA9BE3C51C38F48C32 ] nusb3hub C:\Windows\system32\drivers\nusb3hub.sys 15:02:55.0214 5252 nusb3hub - ok 15:02:55.0223 5252 [ D40A13B2C0891E218F9523B376955DB6 ] nusb3xhc C:\Windows\system32\drivers\nusb3xhc.sys 15:02:55.0224 5252 nusb3xhc - ok 15:02:55.0365 5252 [ B34E9BFBD9C61048EF6281C3E7EC210A ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 15:02:55.0476 5252 nvlddmkm - ok 15:02:55.0506 5252 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 15:02:55.0507 5252 nvraid - ok 15:02:55.0510 5252 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 15:02:55.0511 5252 nvstor - ok 15:02:55.0534 5252 [ DFDA089BB2CD0FF7E789E2EF6BA1E4BA ] nvsvc C:\Windows\system32\nvvsvc.exe 15:02:55.0540 5252 nvsvc - ok 15:02:55.0590 5252 [ E7818CD4FB51284C948D68A7A85A69B8 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe 15:02:55.0597 5252 nvUpdatusService - ok 15:02:55.0609 5252 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 15:02:55.0610 5252 nv_agp - ok 15:02:55.0612 5252 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 15:02:55.0612 5252 ohci1394 - ok 15:02:55.0655 5252 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 15:02:55.0656 5252 ose - ok 15:02:55.0749 5252 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 15:02:55.0800 5252 osppsvc - ok 15:02:55.0825 5252 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 15:02:55.0828 5252 p2pimsvc - ok 15:02:55.0842 5252 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 15:02:55.0846 5252 p2psvc - ok 15:02:55.0855 5252 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys 15:02:55.0855 5252 Parport - ok 15:02:55.0868 5252 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 15:02:55.0869 5252 partmgr - ok 15:02:55.0872 5252 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 15:02:55.0874 5252 PcaSvc - ok 15:02:55.0888 5252 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 15:02:55.0890 5252 pci - ok 15:02:55.0896 5252 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 15:02:55.0896 5252 pciide - ok 15:02:55.0915 5252 [ D7C203015E2C2A2EAC8DACEF156D8DC3 ] PciIsaSerial C:\Windows\system32\drivers\PciIsaSerial.sys 15:02:55.0916 5252 PciIsaSerial - ok 15:02:55.0918 5252 [ 088B509B2F35A3CEE00AC0E0BC4C5BED ] PciPPorts C:\Windows\system32\drivers\PciPPorts.sys 15:02:55.0918 5252 PciPPorts - ok 15:02:55.0921 5252 [ 7F97CDD5E91FC73DA2B01344957AA058 ] PciSPorts C:\Windows\system32\drivers\PciSPorts.sys 15:02:55.0922 5252 PciSPorts - ok 15:02:55.0935 5252 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 15:02:55.0937 5252 pcmcia - ok 15:02:55.0938 5252 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 15:02:55.0939 5252 pcw - ok 15:02:55.0949 5252 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 15:02:55.0953 5252 PEAUTH - ok 15:02:56.0080 5252 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 15:02:56.0082 5252 PerfHost - ok 15:02:56.0104 5252 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 15:02:56.0121 5252 pla - ok 15:02:56.0160 5252 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 15:02:56.0163 5252 PlugPlay - ok 15:02:56.0181 5252 [ AC78DF349F0E4CFB8B667C0CFFF83CCE ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll 15:02:56.0182 5252 Pml Driver HPZ12 - ok 15:02:56.0184 5252 PnkBstrA - ok 15:02:56.0186 5252 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 15:02:56.0188 5252 PNRPAutoReg - ok 15:02:56.0191 5252 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 15:02:56.0193 5252 PNRPsvc - ok 15:02:56.0238 5252 [ 32D374C60778253B81FA76C2FE19E155 ] Point64 C:\Windows\system32\DRIVERS\point64.sys 15:02:56.0238 5252 Point64 - ok 15:02:56.0270 5252 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 15:02:56.0273 5252 PolicyAgent - ok 15:02:56.0277 5252 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 15:02:56.0279 5252 Power - ok 15:02:56.0319 5252 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 15:02:56.0320 5252 PptpMiniport - ok 15:02:56.0341 5252 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys 15:02:56.0343 5252 Processor - ok 15:02:56.0358 5252 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 15:02:56.0360 5252 ProfSvc - ok 15:02:56.0368 5252 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 15:02:56.0370 5252 ProtectedStorage - ok 15:02:56.0373 5252 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 15:02:56.0374 5252 Psched - ok 15:02:56.0393 5252 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys 15:02:56.0410 5252 ql2300 - ok 15:02:56.0413 5252 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 15:02:56.0414 5252 ql40xx - ok 15:02:56.0428 5252 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 15:02:56.0431 5252 QWAVE - ok 15:02:56.0433 5252 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 15:02:56.0434 5252 QWAVEdrv - ok 15:02:56.0436 5252 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 15:02:56.0436 5252 RasAcd - ok 15:02:56.0452 5252 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 15:02:56.0453 5252 RasAgileVpn - ok 15:02:56.0461 5252 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 15:02:56.0464 5252 RasAuto - ok 15:02:56.0466 5252 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 15:02:56.0467 5252 Rasl2tp - ok 15:02:56.0476 5252 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 15:02:56.0479 5252 RasMan - ok 15:02:56.0481 5252 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 15:02:56.0482 5252 RasPppoe - ok 15:02:56.0484 5252 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 15:02:56.0485 5252 RasSstp - ok 15:02:56.0497 5252 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 15:02:56.0499 5252 rdbss - ok 15:02:56.0501 5252 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\drivers\rdpbus.sys 15:02:56.0501 5252 rdpbus - ok 15:02:56.0518 5252 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 15:02:56.0519 5252 RDPCDD - ok 15:02:56.0537 5252 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 15:02:56.0538 5252 RDPENCDD - ok 15:02:56.0540 5252 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 15:02:56.0541 5252 RDPREFMP - ok 15:02:56.0555 5252 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 15:02:56.0556 5252 RDPWD - ok 15:02:56.0567 5252 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 15:02:56.0568 5252 rdyboost - ok 15:02:56.0580 5252 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 15:02:56.0583 5252 RemoteAccess - ok 15:02:56.0594 5252 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 15:02:56.0596 5252 RemoteRegistry - ok 15:02:56.0622 5252 [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys 15:02:56.0623 5252 RFCOMM - ok 15:02:56.0629 5252 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 15:02:56.0630 5252 RpcEptMapper - ok 15:02:56.0638 5252 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 15:02:56.0639 5252 RpcLocator - ok 15:02:56.0648 5252 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll 15:02:56.0651 5252 RpcSs - ok 15:02:56.0663 5252 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 15:02:56.0663 5252 rspndr - ok 15:02:56.0707 5252 [ 9140DB0911DE035FED0A9A77A2D156EA ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys 15:02:56.0709 5252 RTL8167 - ok 15:02:56.0711 5252 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 15:02:56.0712 5252 SamSs - ok 15:02:56.0720 5252 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 15:02:56.0721 5252 sbp2port - ok 15:02:56.0734 5252 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 15:02:56.0736 5252 SCardSvr - ok 15:02:56.0746 5252 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 15:02:56.0747 5252 scfilter - ok 15:02:56.0759 5252 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 15:02:56.0765 5252 Schedule - ok 15:02:56.0784 5252 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 15:02:56.0785 5252 SCPolicySvc - ok 15:02:56.0791 5252 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 15:02:56.0793 5252 SDRSVC - ok 15:02:56.0814 5252 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 15:02:56.0815 5252 secdrv - ok 15:02:56.0826 5252 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 15:02:56.0828 5252 seclogon - ok 15:02:56.0834 5252 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll 15:02:56.0836 5252 SENS - ok 15:02:56.0846 5252 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 15:02:56.0848 5252 SensrSvc - ok 15:02:56.0850 5252 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 15:02:56.0850 5252 Serenum - ok 15:02:56.0873 5252 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys 15:02:56.0874 5252 Serial - ok 15:02:56.0876 5252 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys 15:02:56.0876 5252 sermouse - ok 15:02:56.0885 5252 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 15:02:56.0887 5252 SessionEnv - ok 15:02:56.0896 5252 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 15:02:56.0896 5252 sffdisk - ok 15:02:56.0898 5252 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 15:02:56.0899 5252 sffp_mmc - ok 15:02:56.0904 5252 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 15:02:56.0905 5252 sffp_sd - ok 15:02:56.0906 5252 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 15:02:56.0907 5252 sfloppy - ok 15:02:56.0915 5252 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll 15:02:56.0918 5252 SharedAccess - ok 15:02:56.0931 5252 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 15:02:56.0934 5252 ShellHWDetection - ok 15:02:56.0946 5252 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys 15:02:56.0947 5252 SiSRaid2 - ok 15:02:56.0949 5252 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 15:02:56.0949 5252 SiSRaid4 - ok 15:02:57.0074 5252 [ 183F04C6742902F33039913A96F5B574 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe 15:02:57.0084 5252 Skype C2C Service - ok 15:02:57.0130 5252 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 15:02:57.0130 5252 SkypeUpdate - ok 15:02:57.0146 5252 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 15:02:57.0147 5252 Smb - ok 15:02:57.0160 5252 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 15:02:57.0162 5252 SNMPTRAP - ok 15:02:57.0171 5252 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 15:02:57.0172 5252 spldr - ok 15:02:57.0188 5252 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 15:02:57.0191 5252 Spooler - ok 15:02:57.0225 5252 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 15:02:57.0259 5252 sppsvc - ok 15:02:57.0262 5252 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 15:02:57.0264 5252 sppuinotify - ok 15:02:57.0275 5252 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 15:02:57.0278 5252 srv - ok 15:02:57.0290 5252 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 15:02:57.0293 5252 srv2 - ok 15:02:57.0295 5252 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 15:02:57.0297 5252 srvnet - ok 15:02:57.0314 5252 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 15:02:57.0316 5252 SSDPSRV - ok 15:02:57.0319 5252 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 15:02:57.0321 5252 SstpSvc - ok 15:02:57.0328 5252 Steam Client Service - ok 15:02:57.0330 5252 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys 15:02:57.0331 5252 stexstor - ok 15:02:57.0353 5252 [ DECACB6921DED1A38642642685D77DAC ] StillCam C:\Windows\system32\DRIVERS\serscan.sys 15:02:57.0354 5252 StillCam - ok 15:02:57.0372 5252 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 15:02:57.0377 5252 stisvc - ok 15:02:57.0388 5252 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys 15:02:57.0388 5252 swenum - ok 15:02:57.0402 5252 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 15:02:57.0406 5252 swprv - ok 15:02:57.0422 5252 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 15:02:57.0439 5252 SysMain - ok 15:02:57.0451 5252 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 15:02:57.0454 5252 TabletInputService - ok 15:02:57.0460 5252 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 15:02:57.0463 5252 TapiSrv - ok 15:02:57.0468 5252 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 15:02:57.0470 5252 TBS - ok 15:02:57.0515 5252 [ 37608401DFDB388CAF66917F6B2D6FB0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 15:02:57.0540 5252 Tcpip - ok 15:02:57.0565 5252 [ 37608401DFDB388CAF66917F6B2D6FB0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 15:02:57.0570 5252 TCPIP6 - ok 15:02:57.0606 5252 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 15:02:57.0607 5252 tcpipreg - ok 15:02:57.0646 5252 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 15:02:57.0646 5252 TDPIPE - ok 15:02:57.0668 5252 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 15:02:57.0669 5252 TDTCP - ok 15:02:57.0671 5252 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 15:02:57.0672 5252 tdx - ok 15:02:57.0674 5252 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys 15:02:57.0674 5252 TermDD - ok 15:02:57.0684 5252 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 15:02:57.0689 5252 TermService - ok 15:02:57.0695 5252 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 15:02:57.0696 5252 Themes - ok 15:02:57.0701 5252 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 15:02:57.0702 5252 THREADORDER - ok 15:02:57.0713 5252 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 15:02:57.0715 5252 TrkWks - ok 15:02:57.0741 5252 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 15:02:57.0742 5252 TrustedInstaller - ok 15:02:57.0744 5252 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 15:02:57.0745 5252 tssecsrv - ok 15:02:57.0747 5252 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 15:02:57.0748 5252 TsUsbFlt - ok 15:02:57.0750 5252 [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys 15:02:57.0750 5252 TsUsbGD - ok 15:02:57.0764 5252 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 15:02:57.0764 5252 tunnel - ok 15:02:57.0766 5252 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys 15:02:57.0767 5252 uagp35 - ok 15:02:57.0791 5252 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 15:02:57.0793 5252 udfs - ok 15:02:57.0802 5252 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 15:02:57.0804 5252 UI0Detect - ok 15:02:57.0806 5252 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 15:02:57.0807 5252 uliagpkx - ok 15:02:57.0809 5252 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 15:02:57.0810 5252 umbus - ok 15:02:57.0812 5252 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys 15:02:57.0813 5252 UmPass - ok 15:02:57.0877 5252 [ 30FF46EABCA1BB18E4F357492A8F7FC9 ] UNS C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe 15:02:57.0879 5252 UNS - ok 15:02:57.0888 5252 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 15:02:57.0891 5252 upnphost - ok 15:02:57.0901 5252 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 15:02:57.0903 5252 usbccgp - ok 15:02:57.0915 5252 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 15:02:57.0917 5252 usbcir - ok 15:02:57.0927 5252 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 15:02:57.0928 5252 usbehci - ok 15:02:57.0940 5252 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 15:02:57.0942 5252 usbhub - ok 15:02:57.0944 5252 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys 15:02:57.0945 5252 usbohci - ok 15:02:57.0953 5252 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\drivers\usbprint.sys 15:02:57.0955 5252 usbprint - ok 15:02:57.0957 5252 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 15:02:57.0958 5252 USBSTOR - ok 15:02:57.0960 5252 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 15:02:57.0961 5252 usbuhci - ok 15:02:57.0970 5252 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 15:02:57.0971 5252 UxSms - ok 15:02:57.0977 5252 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 15:02:57.0978 5252 VaultSvc - ok 15:02:57.0988 5252 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 15:02:57.0988 5252 vdrvroot - ok 15:02:58.0002 5252 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 15:02:58.0006 5252 vds - ok 15:02:58.0009 5252 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 15:02:58.0009 5252 vga - ok 15:02:58.0011 5252 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 15:02:58.0012 5252 VgaSave - ok 15:02:58.0014 5252 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 15:02:58.0015 5252 vhdmp - ok 15:02:58.0017 5252 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 15:02:58.0018 5252 viaide - ok 15:02:58.0020 5252 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 15:02:58.0020 5252 volmgr - ok 15:02:58.0030 5252 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 15:02:58.0032 5252 volmgrx - ok 15:02:58.0036 5252 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 15:02:58.0038 5252 volsnap - ok 15:02:58.0041 5252 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 15:02:58.0042 5252 vsmraid - ok 15:02:58.0062 5252 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 15:02:58.0079 5252 VSS - ok 15:02:58.0081 5252 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys 15:02:58.0082 5252 vwifibus - ok 15:02:58.0086 5252 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 15:02:58.0089 5252 W32Time - ok 15:02:58.0092 5252 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys 15:02:58.0092 5252 WacomPen - ok 15:02:58.0095 5252 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 15:02:58.0096 5252 WANARP - ok 15:02:58.0098 5252 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 15:02:58.0099 5252 Wanarpv6 - ok 15:02:58.0125 5252 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 15:02:58.0142 5252 WatAdminSvc - ok 15:02:58.0158 5252 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 15:02:58.0175 5252 wbengine - ok 15:02:58.0178 5252 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 15:02:58.0181 5252 WbioSrvc - ok 15:02:58.0184 5252 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 15:02:58.0187 5252 wcncsvc - ok 15:02:58.0198 5252 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 15:02:58.0200 5252 WcsPlugInService - ok 15:02:58.0211 5252 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys 15:02:58.0212 5252 Wd - ok 15:02:58.0243 5252 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 15:02:58.0247 5252 Wdf01000 - ok 15:02:58.0263 5252 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 15:02:58.0265 5252 WdiServiceHost - ok 15:02:58.0268 5252 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 15:02:58.0270 5252 WdiSystemHost - ok 15:02:58.0279 5252 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 15:02:58.0282 5252 WebClient - ok 15:02:58.0293 5252 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 15:02:58.0296 5252 Wecsvc - ok 15:02:58.0304 5252 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 15:02:58.0306 5252 wercplsupport - ok 15:02:58.0309 5252 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 15:02:58.0312 5252 WerSvc - ok 15:02:58.0322 5252 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 15:02:58.0323 5252 WfpLwf - ok 15:02:58.0325 5252 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 15:02:58.0326 5252 WIMMount - ok 15:02:58.0327 5252 WinDefend - ok 15:02:58.0330 5252 WinHttpAutoProxySvc - ok 15:02:58.0392 5252 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 15:02:58.0394 5252 Winmgmt - ok 15:02:58.0420 5252 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 15:02:58.0446 5252 WinRM - ok 15:02:58.0459 5252 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 15:02:58.0465 5252 Wlansvc - ok 15:02:58.0468 5252 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys 15:02:58.0468 5252 WmiAcpi - ok 15:02:58.0474 5252 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 15:02:58.0476 5252 wmiApSrv - ok 15:02:58.0483 5252 WMPNetworkSvc - ok 15:02:58.0487 5252 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 15:02:58.0490 5252 WPCSvc - ok 15:02:58.0492 5252 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 15:02:58.0494 5252 WPDBusEnum - ok 15:02:58.0496 5252 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 15:02:58.0497 5252 ws2ifsl - ok 15:02:58.0507 5252 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll 15:02:58.0509 5252 wscsvc - ok 15:02:58.0511 5252 WSearch - ok 15:02:58.0567 5252 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 15:02:58.0593 5252 wuauserv - ok 15:02:58.0604 5252 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 15:02:58.0605 5252 WudfPf - ok 15:02:58.0631 5252 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 15:02:58.0632 5252 WUDFRd - ok 15:02:58.0644 5252 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 15:02:58.0646 5252 wudfsvc - ok 15:02:58.0660 5252 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll 15:02:58.0663 5252 WwanSvc - ok 15:02:58.0677 5252 ================ Scan global =============================== 15:02:58.0704 5252 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 15:02:58.0734 5252 [ 72CC564BBC70DE268784BCE91EB8A28F ] C:\Windows\system32\winsrv.dll 15:02:58.0739 5252 [ 72CC564BBC70DE268784BCE91EB8A28F ] C:\Windows\system32\winsrv.dll 15:02:58.0771 5252 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 15:02:58.0791 5252 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 15:02:58.0794 5252 [Global] - ok 15:02:58.0794 5252 ================ Scan MBR ================================== 15:02:58.0806 5252 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 15:02:58.0909 5252 \Device\Harddisk0\DR0 - ok 15:02:58.0910 5252 ================ Scan VBR ================================== 15:02:58.0913 5252 [ 59262318E84A9E2E3A8CAE201064DEA8 ] \Device\Harddisk0\DR0\Partition1 15:02:58.0913 5252 \Device\Harddisk0\DR0\Partition1 - ok 15:02:58.0919 5252 [ 07F825E65D7D83483399F162D406F093 ] \Device\Harddisk0\DR0\Partition2 15:02:58.0920 5252 \Device\Harddisk0\DR0\Partition2 - ok 15:02:58.0920 5252 ============================================================ 15:02:58.0920 5252 Scan finished 15:02:58.0920 5252 ============================================================ 15:02:58.0924 6768 Detected object count: 0 15:02:58.0924 6768 Actual detected object count: 0 15:04:34.0259 1940 Deinitialize success Last of all, a compressed version of MBR.dat should be attached. Thanks again!

Attachments:

Please read through these instructions to familiarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide


Download ComboFix from one of these locations:

Link 1
Link 2



* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


====================================================


Double click on combofix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
Thanks for providing all those useful links - they made disabling all the stuff I needed to disable much easier :) Here's the log: ComboFix 12-12-20.02 - Danny 21/12/2012 17:19:42.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.8144.6141 [GMT 0:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\STFB9A3.tmp c:\users\Danny\Documents\~WRL0003.tmp c:\users\Danny\Documents\~WRL0004.tmp . . ((((((((((((((((((((((((( Files Created from 2012-11-21 to 2012-12-21 ))))))))))))))))))))))))))))))) . . 2012-12-21 17:24 . 2012-12-21 17:24 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2012-12-21 17:24 . 2012-12-21 17:24 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-12-21 14:50 . 2012-11-19 01:01 9125352 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7B5CF02A-0940-4E94-B80B-C632ECBD4BFD}\mpengine.dll 2012-12-17 19:11 . 2012-12-17 19:11 ——– d—–w- c:\users\Danny\AppData\Roaming\Malwarebytes 2012-12-17 19:11 . 2012-12-17 19:11 ——– d—–w- c:\programdata\Malwarebytes 2012-12-17 19:11 . 2012-12-17 19:11 ——– d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2012-12-17 19:11 . 2012-09-29 19:54 25928 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-12-12 14:48 . 2012-11-09 05:45 2048 —-a-w- c:\windows\system32\tzres.dll 2012-12-12 14:48 . 2012-11-09 04:42 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2012-12-11 16:41 . 2012-12-11 16:41 ——– d—–w- c:\program files (x86)\LogMeIn Hamachi 2012-12-10 00:09 . 2012-12-10 00:09 ——– d—–w- c:\users\UpdatusUser\AppData\Local\CrashDumps 2012-11-28 21:24 . 2012-07-26 04:47 2560 —-a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui 2012-11-28 21:24 . 2012-07-26 04:55 785512 —-a-w- c:\windows\system32\drivers\Wdf01000.sys 2012-11-28 21:24 . 2012-07-26 04:55 54376 —-a-w- c:\windows\system32\drivers\WdfLdr.sys 2012-11-28 21:24 . 2012-07-26 02:36 9728 —-a-w- c:\windows\system32\Wdfres.dll 2012-11-28 21:20 . 2012-07-26 03:08 84992 —-a-w- c:\windows\system32\WUDFSvc.dll 2012-11-28 21:20 . 2012-07-26 03:08 194048 —-a-w- c:\windows\system32\WUDFPlatform.dll 2012-11-28 21:20 . 2012-07-26 02:26 87040 —-a-w- c:\windows\system32\drivers\WUDFPf.sys 2012-11-28 21:20 . 2012-07-26 02:26 198656 —-a-w- c:\windows\system32\drivers\WUDFRd.sys 2012-11-28 21:20 . 2012-07-26 03:08 229888 —-a-w- c:\windows\system32\WUDFHost.exe 2012-11-28 21:20 . 2012-07-26 03:08 744448 —-a-w- c:\windows\system32\WUDFx.dll 2012-11-28 21:20 . 2012-07-26 03:08 45056 —-a-w- c:\windows\system32\WUDFCoinstaller.dll 2012-11-26 14:39 . 2012-09-25 22:46 95744 —-a-w- c:\windows\system32\synceng.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-12-12 19:45 . 2012-05-04 21:45 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-12-12 19:45 . 2012-05-04 21:45 697272 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-12-12 16:09 . 2012-02-01 16:07 67413224 —-a-w- c:\windows\system32\MRT.exe 2012-11-06 22:01 . 2012-06-26 21:58 88008 —-a-w- c:\windows\system32\LMIRfsClientNP.dll 2012-11-06 22:01 . 2012-06-26 21:58 35240 —-a-w- c:\windows\system32\LMIport.dll 2012-11-06 22:01 . 2012-06-26 21:58 83880 —-a-w- c:\windows\system32\LMIinit.dll 2012-10-30 22:51 . 2012-05-04 17:07 59728 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2012-10-30 22:51 . 2012-05-04 17:07 370288 —-a-w- c:\windows\system32\drivers\aswSP.sys 2012-10-30 22:51 . 2012-05-04 17:07 984144 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2012-10-30 22:51 . 2012-05-04 17:07 71600 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-10-30 22:51 . 2012-05-04 17:07 25232 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-10-30 22:51 . 2012-05-04 17:06 41224 —-a-w- c:\windows\avastSS.scr 2012-10-30 22:50 . 2012-05-04 17:06 227648 —-a-w- c:\windows\SysWow64\aswBoot.exe 2012-10-30 22:50 . 2012-05-04 17:07 285328 —-a-w- c:\windows\system32\aswBoot.exe 2012-10-16 08:38 . 2012-11-28 12:50 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2012-10-16 08:38 . 2012-11-28 12:50 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2012-10-16 07:39 . 2012-11-28 12:50 561664 —-a-w- c:\windows\apppatch\AcLayers.dll 2012-10-15 16:59 . 2012-05-04 17:07 54072 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2012-10-04 16:40 . 2012-12-12 14:47 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-09-28 14:37 . 2012-09-28 14:37 221696 —-a-w- c:\windows\system32\clinfo.exe 2012-09-28 14:36 . 2012-09-28 14:36 75776 —-a-w- c:\windows\system32\OpenVideo64.dll 2012-09-28 14:36 . 2012-09-28 14:36 65536 —-a-w- c:\windows\SysWow64\OpenVideo.dll 2012-09-28 14:36 . 2012-09-28 14:36 63488 —-a-w- c:\windows\system32\OVDecode64.dll 2012-09-28 14:36 . 2012-09-28 14:36 56320 —-a-w- c:\windows\SysWow64\OVDecode.dll 2012-09-28 14:36 . 2012-09-28 14:36 32635904 —-a-w- c:\windows\system32\amdocl64.dll 2012-09-28 14:32 . 2012-09-28 14:32 27341824 —-a-w- c:\windows\SysWow64\amdocl.dll 2012-09-28 02:23 . 2012-05-02 23:59 5557928 —-a-w- c:\windows\SysWow64\atiumdag.dll 2012-09-28 02:21 . 2012-09-28 02:21 10697216 —-a-w- c:\windows\system32\drivers\atikmdag.sys 2012-09-28 02:05 . 2012-09-28 02:05 70144 —-a-w- c:\windows\system32\coinst_9.002.dll 2012-09-28 02:03 . 2012-09-28 02:03 163840 —-a-w- c:\windows\system32\atiapfxx.exe 2012-09-28 02:02 . 2012-09-28 02:02 51200 —-a-w- c:\windows\system32\aticalrt64.dll 2012-09-28 02:02 . 2012-09-28 02:02 46080 —-a-w- c:\windows\SysWow64\aticalrt.dll 2012-09-28 02:02 . 2012-09-28 02:02 44544 —-a-w- c:\windows\system32\aticalcl64.dll 2012-09-28 02:02 . 2012-09-28 02:02 44032 —-a-w- c:\windows\SysWow64\aticalcl.dll 2012-09-28 02:02 . 2012-09-28 02:02 16082432 —-a-w- c:\windows\system32\aticaldd64.dll 2012-09-28 01:59 . 2012-09-28 01:59 23825920 —-a-w- c:\windows\system32\atio6axx.dll 2012-09-28 01:57 . 2012-09-28 01:57 13703168 —-a-w- c:\windows\SysWow64\aticaldd.dll 2012-09-28 01:43 . 2012-05-02 23:59 935424 —-a-w- c:\windows\SysWow64\aticfx32.dll 2012-09-28 01:41 . 2012-09-28 01:41 1120768 —-a-w- c:\windows\system32\aticfx64.dll 2012-09-28 01:41 . 2012-09-28 01:41 19624960 —-a-w- c:\windows\SysWow64\atioglxx.dll 2012-09-28 01:39 . 2012-09-28 01:39 6536192 —-a-w- c:\windows\SysWow64\atidxx32.dll 2012-09-28 01:39 . 2012-09-28 01:39 442368 —-a-w- c:\windows\system32\atidemgy.dll 2012-09-28 01:39 . 2012-09-28 01:39 538112 —-a-w- c:\windows\system32\atieclxx.exe 2012-09-28 01:38 . 2012-09-28 01:38 239616 —-a-w- c:\windows\system32\atiesrxx.exe 2012-09-28 01:36 . 2012-09-28 01:36 120320 —-a-w- c:\windows\system32\atitmm64.dll 2012-09-28 01:36 . 2012-09-28 01:36 21504 —-a-w- c:\windows\system32\atimuixx.dll 2012-09-28 01:36 . 2012-09-28 01:36 59392 —-a-w- c:\windows\system32\atiedu64.dll 2012-09-28 01:36 . 2012-09-28 01:36 43520 —-a-w- c:\windows\SysWow64\ati2edxx.dll 2012-09-28 01:31 . 2012-09-28 01:31 3127296 —-a-w- c:\windows\system32\atiumd6a.dll 2012-09-28 01:25 . 2012-09-28 01:25 6704640 —-a-w- c:\windows\system32\atiumd64.dll 2012-09-28 01:22 . 2012-09-28 01:22 7167488 —-a-w- c:\windows\system32\atidxx64.dll 2012-09-28 01:22 . 2012-05-02 23:59 2691584 —-a-w- c:\windows\SysWow64\atiumdva.dll 2012-09-28 01:13 . 2012-09-28 01:13 595456 —-a-w- c:\windows\system32\atiadlxx.dll 2012-09-28 01:13 . 2012-09-28 01:13 405504 —-a-w- c:\windows\SysWow64\atiadlxy.dll 2012-09-28 01:13 . 2012-09-28 01:13 17920 —-a-w- c:\windows\system32\atig6pxx.dll 2012-09-28 01:13 . 2012-09-28 01:13 14848 —-a-w- c:\windows\SysWow64\atiglpxx.dll 2012-09-28 01:13 . 2012-09-28 01:13 14848 —-a-w- c:\windows\system32\atiglpxx.dll 2012-09-28 01:13 . 2012-09-28 01:13 41984 —-a-w- c:\windows\system32\atig6txx.dll 2012-09-28 01:13 . 2012-09-28 01:13 33280 —-a-w- c:\windows\SysWow64\atigktxx.dll 2012-09-28 01:12 . 2012-09-28 01:12 56320 —-a-w- c:\windows\system32\atimpc64.dll 2012-09-28 01:12 . 2012-09-28 01:12 56320 —-a-w- c:\windows\system32\amdpcom64.dll 2012-09-28 01:12 . 2012-09-28 01:12 460288 —-a-w- c:\windows\system32\drivers\atikmpag.sys 2012-09-28 01:12 . 2012-09-28 01:12 56832 —-a-w- c:\windows\SysWow64\atimpc32.dll 2012-09-28 01:12 . 2012-09-28 01:12 56832 —-a-w- c:\windows\SysWow64\amdpcom32.dll 2012-09-28 01:11 . 2012-05-02 23:59 129536 —-a-w- c:\windows\system32\atiuxp64.dll 2012-09-28 01:11 . 2012-09-28 01:11 109568 —-a-w- c:\windows\SysWow64\atiuxpag.dll 2012-09-28 01:11 . 2012-09-28 01:11 103424 —-a-w- c:\windows\system32\atiu9p64.dll 2012-09-28 01:10 . 2012-05-02 23:59 82944 —-a-w- c:\windows\SysWow64\atiu9pag.dll 2012-09-28 01:09 . 2012-09-28 01:09 53248 —-a-w- c:\windows\system32\drivers\ati2erec.dll 2012-09-26 15:30 . 2012-09-26 13:53 283032 —-a-w- c:\windows\SysWow64\PnkBstrB.xtr 2012-09-26 15:30 . 2012-09-26 13:41 283032 —-a-w- c:\windows\SysWow64\PnkBstrB.exe 2012-09-26 14:35 . 2012-09-26 13:41 298016 —-a-w- c:\windows\SysWow64\PnkBstrB.ex0 2012-09-26 13:54 . 2012-09-26 13:41 76888 —-a-w- c:\windows\SysWow64\PnkBstrA.exe 2012-09-25 20:57 . 2012-09-26 13:41 3130440 —-a-w- c:\windows\SysWow64\pbsvc_blr.exe 2012-06-26 22:05 . 2012-06-26 22:05 3858432 —-a-w- c:\program files\Hamachi.msi 2012-06-26 21:58 . 2012-06-26 21:57 16151040 —-a-w- c:\program files\LogMeIn.msi . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\steam.exe" [2012-12-03 1354736] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-07-13 17418928] "F.lux"="c:\users\Danny\Local Settings\Apps\F.lux\flux.exe" [2009-08-29 966656] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2011-05-20 284440] "JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2012-02-01 43632] "USB3MON"="c:\program files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-03-27 291608] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-09-28 642728] "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-12-10 2254768] . c:\users\Danny\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2011-9-2 227712] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-12-10 2465712] R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [2012-10-09 8704] R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-12-13 3290896] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944] R3 ALSysIO;ALSysIO;c:\users\ADMINI~1\AppData\Local\Temp\ALSysIO64.sys [x] R3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\drivers\asmthub3.sys [2011-02-24 126952] R3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\drivers\asmtxhci.sys [2010-12-08 369640] R3 ASUSFILTER;ASUSFILTER;SysWow64\drivers\ASUSFILTER.sys [x] R3 ASUSstpt;ASUS USB 3.0 Boost Storage Driver (Storage Driver);c:\windows\system32\drivers\ASUSstpt.sys [2011-10-07 24648] R3 ASUSumsc;ASUS USB 3.0 Boost Storage Driver (WDM);c:\windows\system32\drivers\ASUSumsc.sys [2011-10-07 141896] R3 ASUSxpsp;ASUS USB 3.0 Boost Storage Driver (Storage Driver);c:\windows\system32\drivers\ASUSxpsp.sys [2011-10-07 25160] R3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [2011-03-13 36000] R3 ATHDFU;Atheros Valkyrie USB BootROM;c:\windows\System32\Drivers\AthDfu.sys [2011-03-13 51872] R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [2011-03-13 298656] R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\drivers\btath_hcrp.sys [2011-03-13 201376] R3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [2011-03-13 55456] R3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\drivers\btath_rcp.sys [2011-03-13 154272] R3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [2011-03-13 280224] R3 cpuz130;cpuz130;c:\users\ADMINI~1\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x] R3 IAMTVE;Driver for Intel® Active Management Technology - KCS;c:\windows\system32\drivers\IAMTVE.sys [2007-04-11 43416] R3 IAMTXPE;Driver for Intel® Active Management Technology - KCS;c:\windows\system32\drivers\IAMTXPE.sys [2007-04-11 51096] R3 ioatdma1;ioatdma1;c:\windows\System32\Drivers\qd162x64.sys [2009-11-15 40144] R3 ioatdma2;Intel® QuickData Technology device ver.2;c:\windows\System32\Drivers\qd262x64.sys [2009-11-15 42192] R3 mv91xx;mv91xx;c:\windows\system32\drivers\mv91xx.sys [2010-09-17 297000] R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys [2011-11-04 80384] R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys [2011-11-04 181248] R3 PciIsaSerial;PCI-ISA Communication Port;c:\windows\system32\drivers\PciIsaSerial.sys [2008-05-22 72192] R3 PciPPorts;PCI ECP Parallel Port;c:\windows\system32\drivers\PciPPorts.sys [2008-05-22 95744] R3 PciSPorts;High-Speed PCI Serial Port;c:\windows\system32\drivers\PciSPorts.sys [2008-05-22 126464] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-02-01 1255736] S0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys [2012-03-27 19224] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-09-28 239616] S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe [2011-10-07 922240] S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2011-10-07 915584] S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2011-10-07 586880] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600] S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe [2011-03-13 74912] S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys [2011-01-19 21992] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-05-20 13592] S2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2012-02-02 628448] S2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [2012-03-06 163608] S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-11-06 375728] S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2012-04-02 15928] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-29 399432] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-29 676936] S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-03-06 363800] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-05-14 96896] S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [2011-03-13 28832] S3 iusb3hub;Intel® USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys [2012-03-27 356632] S3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys [2012-03-27 789272] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-29 25928] S3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2012-06-26 46176] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-08-23 565352] . . — Other Services/Drivers In Memory — . *NewlyCreated* - 06966001 *NewlyCreated* - ASWMBR *Deregistered* - 06966001 *Deregistered* - aswMBR . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2012-12-21 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-04 19:45] . 2012-12-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2753751658-3377567136-329492228-1002Core.job - c:\users\Danny\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-04 16:56] . 2012-12-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2753751658-3377567136-329492228-1002UA.job - c:\users\Danny\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-04 16:56] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-10-30 22:50 133400 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2011-03-13 617120] "AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2011-03-13 379552] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-02-01 11613288] "LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2012-04-02 57928] "IntelliType Pro"="c:\program files\Microsoft Device Center\itype.exe" [2012-06-26 1464928] "IntelliPoint"="c:\program files\Microsoft Device Center\ipoint.exe" [2012-06-26 2004584] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport; to Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000 IE: Se&nd; to OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105 Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Wow6432Node-HKLM-Run- - (no file) SafeBoot-BsScanner Toolbar-Locked - (no file) AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_blr.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-12-21 17:25:50 ComboFix-quarantined-files.txt 2012-12-21 17:25 . Pre-Run: 740,587,024,384 bytes free Post-Run: 741,225,512,960 bytes free . - - End Of File - - C233C844DC3A7FEAD88DC97D62159CFE
I must admit, I didn't notice any oddities yesterday aside from another crash that was somewhat similar to the one I got on day 1, however I was never given a 1-minute warning about a restart so I restarted it myself and everything was fine thereafter. I went over to the Windows Action Centre afterwards and it did not attribute this crash to the presence of any virus. I should note this happened in the evening, many hours after I used ComboFix. Nothing strange has happened to Chrome, apart from Adobe… Shockwave Player, I think it's called, breaking once while I was on youtube (again, this was long after ComboFix had been used). This has happened numerous times before so this is probably unrelated. Other than that, all has appeared to be normal.
Great. I wish to clarify one thing before we move further. Did you set these as trusted sites yourself? Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com
Honestly, I can't remember. If any anti-virus message popped up saying 'This site is potentially malicious, do you trust it?', then I can say with good confidence that I will have said yes for soe and sony. soe is behind a massively multiplayer free to play game I got into a little while ago, and soe stands for Sony Online Entertainment, so, obviously, Sony is related to that. As for the other two, clonewarsadventures doesn't really ring any bells, but it sounds like the sort of place I could have visited before. I've heard of freerealms before, but again I can't distinctly remember visiting it. Seeing as none of those four sound completely random and unrelated to my interests, and that I'm familiar with soe which is very closely related to sony, I could easily believe that I did indeed set all those as trusted sites myself.
There are times where AV will give out false warnings, so it is up to us to decide to trust them or not. We do know that Sony site is legit so we will have to give it a pass this time round.

Please run this tool. Don't worry, it's not related to the question I was asking just now.

-AdwCleaner-

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
Here's the log (Yes, I named my computer Giles :thumbup: ): # AdwCleaner v2.101 - Logfile created 12/22/2012 at 15:18:00 # Updated 16/12/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Danny - GILES # Boot Mode : Normal # Running from : C:\Users\Danny\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\ProgramData\boost_interprocess ***** [Registry] ***** ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16457 [OK] Registry is clean. -\\ Google Chrome v23.0.1271.97 File : C:\Users\Danny\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [705 octets] - [22/12/2012 15:18:00] ########## EOF - C:\AdwCleaner[S1].txt - [764 octets] ##########
Very good. :)

Once we're done with the follow-up, given that all is clean, you will be good to go.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
===================================================

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
===================================================

Malwarebytes' Anti-Malware
Download Malwarebytes' Anti-Malware here and save to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program. (Note to Vista users, please right-click and select Run as Administrator.)
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

On your next reply please post :
ESET log
MBAM log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
I ran ESET, and it detected no threats, so no text file for that.

I downloaded MBAM a few days ago when the problem first arose, so I used that installation (whose database updated earlier today). It also found nothing malicious, and I'm guessing that it's as a result of that that I found myself unable to complete these steps:

When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.




Here's the log from MBAM:



Malwarebytes Anti-Malware (Trial) 1.65.1.1000
www.malwarebytes.org

Database version: v2012.12.22.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Danny :: GILES [administrator]

Protection: Enabled

22/12/2012 18:24:25
mbam-log-2012-12-22 (18-24-25).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 230046
Time elapsed: 1 minute(s), 33 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI