This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Constant shut downs, Cannot use safe boot [Solved]

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My account cannot be accessed it now starts as a temp profile. Keep getting blue screens warning of file errors and the it runs diskcheck. But I cannot use Malwarebytes, it always locks up after 6 minutes 15 seconds and then I cannot use anything and am forced to do a manual shutdown. Cannot run safe boot, it will not complete the loading of the files. It stops here: WINDOWS: \WINDOWS\system32\drivers\CLASSPNP.SYS
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!

Can you please tell me if the information on your profile is correct that you have Windows 7 64 bit?
Let's see if we can get this to run:

Download Farbar Recovery Scan Tool and save it to a flash drive.

Plug the flashdrive into the infected PC.

Restart your computer and tap F8 to bring up the Advanced Menu, then click Repair your computer

Follow the prompt to enter keyboard input method, and then the prompt to enter a password. If the machine does not have a password, simply click Enter.

In the next menu, use the arrow keys on the keyboard to highlight Command Prompt and press Enter.
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst.exe and press Enter.
Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Place a check next to List Drivers MD5
  • Press Scan button.
    When finished, a log (FRST64.txt) will be created on the flash drive. Please copy and paste it to your reply.
Okay heres the log file. Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-12-2012 Ran by [removed] at 03-01-2013 17:47:18 Running from I:\ Windows 7 Home Premium (X64) OS Language: English(US) The current controlset is ControlSet002 ==================== Registry (Whitelisted) =================== HKLM\…\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10144288 2010-04-06] (Realtek Semiconductor) HKLM\…\Run: [PLD_FrameworkRun] c:\windows\system32\oem\_NowIntoDT.vbs [490 2009-10-11] () HKLM\…\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2327952 2010-07-21] (Microsoft Corporation) HKLM\…\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1289704 2012-09-12] (Microsoft Corporation) HKLM-x32\…\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-10-25] (Apple Inc.) HKU\Administrator.Family\…\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-06] (Google Inc.) HKU\Administrator.Family\…\Policies\system: [LogonHoursAction] 2 HKU\Administrator.Family\…\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\Ashanthe\…\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-06] (Google Inc.) HKU\Ashanthe\…\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe" [666384 2012-02-07] (SANDBOXIE L.T.D) HKU\Ashanthe\…\Policies\system: [LogonHoursAction] 2 HKU\Ashanthe\…\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\Betty\…\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-06] (Google Inc.) HKU\Betty\…\Policies\system: [LogonHoursAction] 2 HKU\Betty\…\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\Bryan\…\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-06] (Google Inc.) HKU\Bryan\…\Policies\system: [LogonHoursAction] 2 HKU\Bryan\…\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\Daniel\…\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-06] (Google Inc.) HKU\Daniel.Family\…\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-06] (Google Inc.) HKU\Daniel.Family\…\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [x] HKU\Daniel.Family\…\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4240760 2010-11-10] (Microsoft Corporation) HKU\Daniel.Family\…\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent [x] HKU\Daniel.Family\…\Policies\system: [LogonHoursAction] 2 HKU\Daniel.Family\…\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\Default\…\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [162336 2009-07-21] () HKU\Default User\…\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [162336 2009-07-21] () HKU\Gwen\…\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-06] (Google Inc.) HKU\Gwen\…\Policies\system: [LogonHoursAction] 2 HKU\Gwen\…\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\UpdatusUser\…\RunOnce: [ScrSav] C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe /default [162336 2009-07-21] () HKU\Zanthia\…\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-06] (Google Inc.) HKU\Zanthia\…\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4240760 2010-11-10] (Microsoft Corporation) HKU\Zanthia.Family\…\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2011-08-06] (Google Inc.) HKU\Zanthia.Family\…\Policies\system: [LogonHoursAction] 2 HKU\Zanthia.Family\…\Policies\system: [DontDisplayLogonHoursWarnings] 1 Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76 Startup: C:\Users\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia) Startup: C:\Users\Bryan\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> (No File) ==================== Services (Whitelisted) =================== 2 !SASCORE; "C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE" [140672 2012-10-06] (SUPERAntiSpyware.com) 2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [625184 2009-04-19] () 2 LMIGuardianSvc; "C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe" [375728 2012-10-19] (LogMeIn, Inc.) 4 LMIMaint; "C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe" [147888 2012-10-19] (LogMeIn, Inc.) 4 LogMeIn; "C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe" [407424 2012-08-24] (LogMeIn, Inc.) 2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [22072 2012-09-12] (Microsoft Corporation) 3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [368896 2012-09-12] (Microsoft Corporation) 2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [207904 2009-04-19] () 2 nvsvc; C:\Windows\SysWow64\nvvsvc.exe [0 2010-09-08] () 4 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75064 2010-05-23] () 4 PnkBstrB; C:\Windows\SysWow64\PnkBstrB.exe [219128 2010-07-31] () 2 SbieSvc; "C:\Program Files\Sandboxie\SbieSvc.exe" [97552 2012-02-07] (SANDBOXIE L.T.D) 2 Secunia PSI Agent; "C:\Program Files (x86)\Secunia\PSI\PSIA.exe" –start-service [994360 2011-10-13] (Secunia) 2 Secunia Update Agent; "C:\Program Files (x86)\Secunia\PSI\sua.exe" –start-service [399416 2011-10-13] (Secunia) ==================== Drivers (Whitelisted) ===================== 3 GEARAspiWDM; C:\Windows\SysWow64\Drivers\GEARAspiWDM.sys [15664 2012-06-07] (GEAR Software Inc.) 1 GIDv2; C:\Windows\System32\Drivers\GIDv2.sys [29288 2011-07-05] (StrikeForce Technologies, Inc.) 3 hitmanpro37; C:\Windows\System32\Drivers\hitmanpro37.sys [32152 2013-01-01] () 0 hotcore3; C:\Windows\System32\Drivers\hotcore3.sys [37456 2011-01-21] (Paragon Software Group) 2 LMIInfo; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [15928 2012-08-24] (LogMeIn, Inc.) 0 MpFilter; C:\Windows\System32\Drivers\MpFilter.sys [228768 2012-08-30] (Microsoft Corporation) 2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [128456 2012-08-30] (Microsoft Corporation) 3 NPF; C:\Windows\System32\Drivers\NPF.sys [40464 2007-11-06] (CACE Technologies) 0 pavboot; C:\Windows\System32\drivers\pavboot64.sys [33800 2009-06-30] (Panda Security, S.L.) 3 PCGenFam; C:\Windows\System32\Drivers\PCGenFam.sys [198088 2010-11-01] (Soluto LTD.) 3 pwdrvio; \??\C:\Windows\system32\pwdrvio.sys [19936 2011-05-06] () 3 pwdspio; \??\C:\Windows\system32\pwdspio.sys [13280 2011-05-06] () 3 SaiKF622; C:\Windows\System32\Drivers\SaiKF622.sys [140800 2009-06-02] (Saitek) 3 SaiMini; C:\Windows\System32\Drivers\SaiMini.sys [16000 2009-06-10] (Saitek) 3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [43264 2009-06-10] (Saitek) 1 SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) 1 SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) 3 SbieDrv; \??\C:\Program Files\Sandboxie\SbieDrv.sys [161432 2012-02-07] (SANDBOXIE L.T.D) 3 sscdserd; C:\Windows\System32\Drivers\sscdserd.sys [141384 2010-11-11] (MCCI Corporation) 1 UimBus; C:\Windows\System32\DRIVERS\uimx64.sys [53840 2011-01-21] (Windows ® 2000 DDK provider) 1 Uim_IM; C:\Windows\System32\Drivers\Uim_IMx64.sys [528464 2011-01-21] (Paragon) 3 usbbus; C:\Windows\System32\DRIVERS\lgx64bus.sys [17920 2008-11-11] (LG Electronics Inc.) 3 UsbDiag; C:\Windows\System32\DRIVERS\lgx64diag.sys [27136 2008-11-11] (LG Electronics Inc.) 3 USBModem; C:\Windows\System32\DRIVERS\lgx64modem.sys [33792 2008-11-11] (LG Electronics Inc.) 3 VaneFltr; C:\Windows\System32\drivers\Lachesis.sys [30336 2007-08-17] (Razer (Asia-Pacific) Pte Ltd) 3 ALSysIO; \??\C:\Users\Bryan\AppData\Local\Temp\ALSysIO64.sys [x] 3 catchme; \??\C:\ComboFix\catchme.sys [x] 3 easytether; C:\Windows\System32\DRIVERS\easytthr.sys [x] 0 hqmpym; [x] 4 LMIRfsClientNP; [x] 3 MEMSWEEP2; \??\C:\Windows\system32\7114.tmp [x] ==================== NetSvcs (Whitelisted) ==================== ==================== One Month Created Files and Folders ======== 2013-01-03 17:19 - 2013-01-03 17:19 - 00000000 ____D C:\FRST 2013-01-03 17:17 - 2013-01-03 17:17 - 01464235 ____A (Farbar) C:\Users\Bryan\Downloads\FRST64.exe 2013-01-02 23:07 - 2013-01-02 23:07 - 00000000 ____D C:\Users\All Users\BasicSeek 2013-01-02 23:07 - 2013-01-02 23:07 - 00000000 ____D C:\Program Files (x86)\BasicSeek 2013-01-02 21:55 - 2013-01-02 21:55 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Roaming\SUPERAntiSpyware.com 2013-01-02 14:58 - 2013-01-02 14:58 - 00002975 ____A C:\Users\Bryan\Desktop\HiJackThis.lnk 2013-01-02 13:28 - 2013-01-02 13:28 - 00000000 ____D C:\Program Files\WOT 2013-01-02 10:43 - 2013-01-02 10:43 - 05415956 ____A C:\Users\Bryan\Downloads\tweaking.com_windows_repair_aio_setup (1).exe 2013-01-02 10:42 - 2013-01-02 10:42 - 05415956 ____A C:\Users\Bryan\Downloads\tweaking.com_windows_repair_aio_setup.exe 2013-01-02 10:17 - 2013-01-02 10:17 - 00000000 ____D C:\Windows\System32\%LocalAppData% 2013-01-02 00:50 - 2013-01-02 00:50 - 00065736 ____A (Prevx) C:\Windows\System32\Drivers\pxrts.sys 2013-01-02 00:50 - 2013-01-02 00:50 - 00000000 ____D C:\Program Files\Prevx 2013-01-02 00:49 - 2013-01-02 14:24 - 00000000 ____D C:\Users\All Users\PrevxCSI 2013-01-01 18:10 - 2012-11-28 15:19 - 65087872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MRT.exe 2013-01-01 17:32 - 2013-01-01 17:32 - 00032152 ____A C:\Windows\System32\Drivers\hitmanpro37.sys 2013-01-01 17:30 - 2013-01-01 17:30 - 00000000 ____D C:\Users\Daniel.Family\Documents\4a games 2013-01-01 17:29 - 2013-01-01 17:29 - 00000000 ____D C:\Users\Daniel.Family\AppData\Local\{B1DD0CA5-E02F-444F-B0A5-D9F75FCC0CE5} 2013-01-01 17:19 - 2013-01-01 17:19 - 00000000 ____D C:\Users\Betty\AppData\Roaming\Malwarebytes 2013-01-01 17:05 - 2013-01-01 17:05 - 00208216 ____A (Kaspersky Lab, GERT) C:\Windows\System32\Drivers\34792715.sys 2013-01-01 17:04 - 2013-01-01 17:04 - 00000000 ____D C:\Users\Administrator.Family\AppData\Roaming\WinRAR 2013-01-01 17:01 - 2013-01-01 17:01 - 02195988 ____A C:\Users\Administrator.Family\Desktop\tdsskiller-2-8-14-0[1].zip 2013-01-01 17:01 - 2013-01-01 17:01 - 00000000 ____D C:\Users\Administrator.Family\Desktop\tdsskiller-2-8-14-0[1] 2013-01-01 16:59 - 2013-01-02 22:55 - 00000000 ____D C:\Users\Administrator.Family\AppData\Local\Conduit 2013-01-01 16:57 - 2013-01-01 16:57 - 00000000 ____D C:\Users\All Users\VisualBee 2013-01-01 16:56 - 2013-01-01 16:56 - 02195988 ____A C:\Users\Administrator.Family\Desktop\tdsskiller-2-8-14-0.zip 2013-01-01 16:49 - 2013-01-01 16:50 - 00000000 ____D C:\Users\Administrator.Family\AppData\Roaming\Google 2013-01-01 16:49 - 2013-01-01 16:49 - 00000000 ____D C:\Users\Administrator.Family\AppData\Roaming\Adobe 2013-01-01 16:49 - 2013-01-01 16:49 - 00000000 ____D C:\Users\Administrator.Family\AppData\Local\Google 2013-01-01 16:41 - 2013-01-01 16:41 - 00000000 ____D C:\Users\Administrator.Family\AppData\Roaming\SUPERAntiSpyware.com 2013-01-01 16:40 - 2013-01-01 16:40 - 00079176 ____A C:\Users\Administrator.Family\AppData\Local\GDIPFONTCACHEV1.DAT 2013-01-01 16:40 - 2013-01-01 16:40 - 00000632 _RASH C:\Users\Administrator.Family\ntuser.pol 2013-01-01 16:40 - 2013-01-01 16:40 - 00000020 __ASH C:\Users\Administrator.Family\ntuser.ini 2013-01-01 16:40 - 2013-01-01 16:40 - 00000000 ____D C:\users\Administrator.Family 2013-01-01 16:40 - 2012-11-19 00:04 - 00000000 ____D C:\Users\Administrator.Family\AppData\Roaming\Macromedia 2013-01-01 16:11 - 2013-01-01 16:11 - 00000000 __SHD C:\found.003 2013-01-01 15:25 - 2013-01-01 15:25 - 00000000 __SHD C:\found.002 2013-01-01 14:09 - 2013-01-01 14:09 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{0D15E399-8284-41A7-8304-CC9AAF180A83} 2013-01-01 13:48 - 2013-01-01 13:48 - 657833086 ____A C:\Windows\MEMORY.DMP 2013-01-01 13:48 - 2013-01-01 13:48 - 00291704 ____A C:\Windows\Minidump\010113-21184-01.dmp 2012-12-31 18:43 - 2012-12-31 18:43 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{6E89A9B8-1172-48C2-9F67-D725340AC89F} 2012-12-31 13:24 - 2012-12-31 13:24 - 00000000 __SHD C:\found.001 2012-12-30 09:07 - 2012-12-30 09:07 - 00000000 __SHD C:\found.000 2012-12-28 01:23 - 2012-12-28 01:23 - 06160306 ____A C:\Users\Bryan\Downloads\com.android.vending-3.10.10.apk 2012-12-27 17:24 - 2012-12-27 17:24 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{7A0A48BA-4014-4B44-9478-D77BEBDD1C0D} 2012-12-26 19:46 - 2012-12-26 19:46 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{1BBAC4FB-7992-4183-BDD0-1BE0573D692C} 2012-12-25 20:42 - 2012-12-25 20:42 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{2AF8418A-2691-4874-B3B1-16CB6EFF6ECA} 2012-12-25 08:59 - 2012-12-25 11:37 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Apple Computer 2012-12-25 08:59 - 2012-12-25 08:59 - 00000000 ____D C:\Users\Bryan\AppData\Local\Apple Computer 2012-12-25 08:58 - 2012-12-25 08:58 - 00001910 ____A C:\Users\Bryan\Desktop\CarbonPoker.lnk 2012-12-24 15:03 - 2009-06-30 10:37 - 00033800 ____A (Panda Security, S.L.) C:\Windows\System32\Drivers\pavboot64.sys 2012-12-24 15:02 - 2012-12-24 15:02 - 00000000 ____D C:\Windows\AxInstSV 2012-12-24 15:02 - 2012-12-24 15:02 - 00000000 ____D C:\Program Files (x86)\Panda Security 2012-12-24 13:25 - 2012-12-24 13:25 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{56D58E79-20E0-465E-8688-DE373C7DAF6D} 2012-12-23 23:11 - 2012-12-23 23:11 - 00334808 ____A C:\Users\Bryan\Downloads\417038_intl_x64_zip.exe 2012-12-22 17:26 - 2012-12-23 05:27 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{4363B4C1-9D35-4D06-975F-23249F497EE1} 2012-12-22 09:01 - 2012-12-16 09:11 - 00046080 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll 2012-12-22 09:01 - 2012-12-16 06:45 - 00367616 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll 2012-12-22 09:01 - 2012-12-16 06:13 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2012-12-22 09:01 - 2012-12-16 06:13 - 00034304 ____A (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2012-12-21 23:58 - 2012-12-21 23:58 - 00000281 ____A C:\Users\Bryan\Desktop\Proggrammer.url 2012-12-21 00:54 - 2012-12-21 00:54 - 00002591 ____A C:\Users\Bryan\Desktop\Radio Tuna.lnk 2012-12-21 00:53 - 2012-12-21 00:53 - 00002573 ____A C:\Users\Public\Desktop\Radio Tuna.lnk 2012-12-21 00:53 - 2012-12-21 00:53 - 00000000 ____D C:\Users\Bryan\AppData\Local\TunaMediaLtd 2012-12-21 00:53 - 2012-12-21 00:53 - 00000000 ____D C:\Program Files (x86)\TunaMediaLtd 2012-12-21 00:52 - 2012-12-21 00:52 - 00000000 ____D C:\Users\Bryan\AppData\Local\Downloaded Installations 2012-12-18 23:16 - 2012-12-18 23:16 - 04068352 ____A (http://yourfiledownloader.com) C:\Users\Bryan\Downloads\The_Walking_Dead_Comic_(1-93)_downloader_99132.exe 2012-12-15 11:52 - 2012-12-15 11:52 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{ED8A116C-86DF-4053-9D28-93F458FC209A} 2012-12-15 00:04 - 2012-12-15 00:04 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\SystemRequirementsLab 2012-12-14 23:25 - 2012-12-14 23:25 - 00000000 ____D C:\Users\Bryan\Documents\4A Games 2012-12-14 23:14 - 2012-12-14 23:14 - 00000000 ____D C:\Users\Bryan\AppData\Local\4A Games 2012-12-14 23:09 - 2012-12-14 23:10 - 00017513 ____A C:\Windows\DirectX.log 2012-12-14 09:41 - 2012-12-14 09:41 - 00000921 ____A C:\Users\Public\Desktop\Steam.lnk 2012-12-14 09:39 - 2012-12-04 09:16 - 00000000 ____D C:\Users\Bryan\Desktop\metro 2033 2012-12-13 12:55 - 2012-12-13 14:43 - 00000000 ____D C:\Users\Bryan\AppData\Local\DownTango 2012-12-13 12:55 - 2012-12-13 12:55 - 00000000 ____D C:\Program Files (x86)\Red Sky 2012-12-12 13:38 - 2012-12-13 13:38 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{A0DC0D10-3C88-4FDA-A996-CD84AF6B9659} 2012-12-12 01:52 - 2012-08-21 06:20 - 00046080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncobjapi.dll 2012-12-12 01:52 - 2012-08-21 05:49 - 00058368 ____A (Microsoft Corporation) C:\Windows\System32\ncobjapi.dll 2012-12-12 01:51 - 2012-08-21 06:59 - 00001536 ____A (Microsoft Corporation) C:\Windows\SysWOW64\winrsmgr.dll 2012-12-12 01:51 - 2012-08-21 06:56 - 00060416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WsmRes.dll 2012-12-12 01:51 - 2012-08-21 06:29 - 00009728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\winrssrv.dll 2012-12-12 01:51 - 2012-08-21 06:28 - 00010240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wsmplpxy.dll 2012-12-12 01:51 - 2012-08-21 06:20 - 00001536 ____A (Microsoft Corporation) C:\Windows\System32\winrsmgr.dll 2012-12-12 01:51 - 2012-08-21 06:19 - 00060416 ____A (Microsoft Corporation) C:\Windows\System32\WsmRes.dll 2012-12-12 01:51 - 2012-08-21 06:18 - 00089088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mi.dll 2012-12-12 01:51 - 2012-08-21 06:14 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wecapi.dll 2012-12-12 01:51 - 2012-08-21 06:08 - 00083456 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wevtfwd.dll 2012-12-12 01:51 - 2012-08-21 06:01 - 00012800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Register-CimProvider.exe 2012-12-12 01:51 - 2012-08-21 05:58 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\winrssrv.dll 2012-12-12 01:51 - 2012-08-21 05:57 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\wsmplpxy.dll 2012-12-12 01:51 - 2012-08-21 05:56 - 00078336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wecutil.exe 2012-12-12 01:51 - 2012-08-21 05:48 - 00106496 ____A (Microsoft Corporation) C:\Windows\System32\mi.dll 2012-12-12 01:51 - 2012-08-21 05:45 - 00083456 ____A (Microsoft Corporation) C:\Windows\System32\wecapi.dll 2012-12-12 01:51 - 2012-08-21 05:44 - 00059904 ____A (Microsoft Corporation) C:\Windows\SysWOW64\prvdmofcomp.dll 2012-12-12 01:51 - 2012-08-21 05:43 - 00154112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmitomi.dll 2012-12-12 01:51 - 2012-08-21 05:40 - 00108544 ____A (Microsoft Corporation) C:\Windows\System32\wevtfwd.dll 2012-12-12 01:51 - 2012-08-21 05:36 - 00124416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wmidcom.dll 2012-12-12 01:51 - 2012-08-21 05:34 - 00382464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wbemcomn2.dll 2012-12-12 01:51 - 2012-08-21 05:33 - 00172544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\miutils.dll 2012-12-12 01:51 - 2012-08-21 05:32 - 00021504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WsmAgent.dll 2012-12-12 01:51 - 2012-08-21 05:32 - 00013824 ____A (Microsoft Corporation) C:\Windows\System32\Register-CimProvider.exe 2012-12-12 01:51 - 2012-08-21 05:29 - 00192512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\framedynos.dll 2012-12-12 01:51 - 2012-08-21 05:28 - 00105472 ____A (Microsoft Corporation) C:\Windows\System32\wecutil.exe 2012-12-12 01:51 - 2012-08-21 05:27 - 00189952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\framedyn.dll 2012-12-12 01:51 - 2012-08-21 05:26 - 00216576 ____A (Microsoft Corporation) C:\Windows\System32\wecsvc.dll 2012-12-12 01:51 - 2012-08-21 05:17 - 00079360 ____A (Microsoft Corporation) C:\Windows\System32\prvdmofcomp.dll 2012-12-12 01:51 - 2012-08-21 05:16 - 00214528 ____A (Microsoft Corporation) C:\Windows\System32\wmitomi.dll 2012-12-12 01:51 - 2012-08-21 05:13 - 00020480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\winrshost.exe 2012-12-12 01:51 - 2012-08-21 05:09 - 00160768 ____A (Microsoft Corporation) C:\Windows\System32\wmidcom.dll 2012-12-12 01:51 - 2012-08-21 05:08 - 00494592 ____A (Microsoft Corporation) C:\Windows\System32\wbemcomn2.dll 2012-12-12 01:51 - 2012-08-21 05:07 - 00223232 ____A (Microsoft Corporation) C:\Windows\System32\miutils.dll 2012-12-12 01:51 - 2012-08-21 05:06 - 00026112 ____A (Microsoft Corporation) C:\Windows\System32\WsmAgent.dll 2012-12-12 01:51 - 2012-08-21 05:04 - 00039936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\winrs.exe 2012-12-12 01:51 - 2012-08-21 05:03 - 00247296 ____A (Microsoft Corporation) C:\Windows\System32\framedynos.dll 2012-12-12 01:51 - 2012-08-21 05:03 - 00035840 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wsmprovhost.exe 2012-12-12 01:51 - 2012-08-21 05:02 - 00242688 ____A (Microsoft Corporation) C:\Windows\System32\framedyn.dll 2012-12-12 01:51 - 2012-08-21 05:02 - 00227328 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll 2012-12-12 01:51 - 2012-08-21 05:02 - 00138752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll 2012-12-12 01:51 - 2012-08-21 05:02 - 00092160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\winrscmd.dll 2012-12-12 01:51 - 2012-08-21 04:56 - 00526848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WsmGCDeps.dll 2012-12-12 01:51 - 2012-08-21 04:52 - 02039296 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2012-12-12 01:51 - 2012-08-21 04:50 - 00036352 ____A (Microsoft Corporation) C:\Windows\SysWOW64\PSModuleDiscoveryProvider.dll 2012-12-12 01:51 - 2012-08-21 04:50 - 00030208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe 2012-12-12 01:51 - 2012-08-21 04:47 - 00023040 ____A (Microsoft Corporation) C:\Windows\System32\winrshost.exe 2012-12-12 01:51 - 2012-08-21 04:37 - 00046080 ____A (Microsoft Corporation) C:\Windows\System32\winrs.exe 2012-12-12 01:51 - 2012-08-21 04:36 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\wsmprovhost.exe 2012-12-12 01:51 - 2012-08-21 04:35 - 00157184 ____A (Microsoft Corporation) C:\Windows\System32\WsmAuto.dll 2012-12-12 01:51 - 2012-08-21 04:35 - 00106496 ____A (Microsoft Corporation) C:\Windows\System32\winrscmd.dll 2012-12-12 01:51 - 2012-08-21 04:34 - 00309248 ____A (Microsoft Corporation) C:\Windows\System32\WsmWmiPl.dll 2012-12-12 01:51 - 2012-08-21 04:30 - 00042496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\pwrshplugin.dll 2012-12-12 01:51 - 2012-08-21 04:26 - 00630784 ____A (Microsoft Corporation) C:\Windows\System32\WsmGCDeps.dll 2012-12-12 01:51 - 2012-08-21 04:24 - 02832384 ____A (Microsoft Corporation) C:\Windows\System32\WsmSvc.dll 2012-12-12 01:51 - 2012-08-21 04:22 - 00048128 ____A (Microsoft Corporation) C:\Windows\System32\PSModuleDiscoveryProvider.dll 2012-12-12 01:51 - 2012-08-21 04:22 - 00028672 ____A (Microsoft Corporation) C:\Windows\System32\WSManHTTPConfig.exe 2012-12-12 01:51 - 2012-08-21 04:04 - 00058368 ____A (Microsoft Corporation) C:\Windows\System32\pwrshplugin.dll 2012-12-12 01:51 - 2012-08-21 03:26 - 00056832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll 2012-12-12 01:51 - 2012-08-21 03:05 - 00066560 ____A (Microsoft Corporation) C:\Windows\System32\WSManMigrationPlugin.dll 2012-12-12 01:51 - 2012-07-23 10:17 - 00204105 ____A C:\Windows\System32\winrm.vbs 2012-12-12 01:51 - 2012-07-23 10:17 - 00004675 ____A C:\Windows\System32\wsmanconfig_schema.xml 2012-12-12 01:51 - 2012-07-23 10:17 - 00004148 ____A C:\Windows\System32\psmodulediscoveryprovider.mof 2012-12-12 01:51 - 2012-07-23 10:16 - 00204105 ____A C:\Windows\SysWOW64\winrm.vbs 2012-12-12 01:51 - 2012-07-23 10:16 - 00004675 ____A C:\Windows\SysWOW64\wsmanconfig_schema.xml 2012-12-12 01:45 - 2012-11-13 22:11 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-12-12 01:45 - 2012-11-13 22:04 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-12-12 01:45 - 2012-11-13 22:02 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-12-12 01:45 - 2012-11-13 22:02 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-12-12 01:45 - 2012-11-13 21:57 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-12-12 01:45 - 2012-11-13 21:55 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2012-12-12 01:45 - 2012-11-13 21:53 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-12-12 01:45 - 2012-11-13 21:52 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-12-12 01:45 - 2012-11-13 21:46 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-12-12 01:45 - 2012-11-13 17:58 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2012-12-12 01:45 - 2012-11-13 17:57 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2012-12-12 01:45 - 2012-11-13 17:55 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2012-12-12 01:45 - 2012-11-13 17:49 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2012-12-12 01:45 - 2012-11-13 17:48 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2012-12-12 01:45 - 2012-11-13 17:47 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2012-12-12 01:45 - 2012-11-13 17:45 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2012-12-12 01:45 - 2012-11-13 17:44 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2012-12-12 01:45 - 2012-11-13 17:41 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2012-12-12 01:44 - 2012-11-13 23:06 - 17811968 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-12-12 01:44 - 2012-11-13 22:32 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-12-12 01:44 - 2012-11-13 22:04 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-12-12 01:44 - 2012-11-13 21:59 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-12-12 01:44 - 2012-11-13 21:58 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-12-12 01:44 - 2012-11-13 21:57 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2012-12-12 01:44 - 2012-11-13 21:55 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-12-12 01:44 - 2012-11-13 18:48 - 12320256 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2012-12-12 01:44 - 2012-11-13 18:14 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2012-12-12 01:44 - 2012-11-13 18:09 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2012-12-12 01:44 - 2012-11-13 17:57 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2012-12-12 01:44 - 2012-11-13 17:51 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2012-12-12 01:44 - 2012-11-13 17:49 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2012-12-12 01:44 - 2012-11-13 17:46 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2012-12-12 01:41 - 2012-11-08 21:45 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\tzres.dll 2012-12-12 01:41 - 2012-11-08 20:42 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2012-12-12 01:40 - 2012-11-21 19:26 - 03149824 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-12-12 01:40 - 2012-10-04 09:46 - 00362496 ____A (Microsoft Corporation) C:\Windows\System32\wow64win.dll 2012-12-12 01:40 - 2012-10-04 09:46 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\wow64.dll 2012-12-12 01:40 - 2012-10-04 09:46 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\wow64cpu.dll 2012-12-12 01:40 - 2012-10-04 09:45 - 00215040 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll 2012-12-12 01:40 - 2012-10-04 09:43 - 00016384 ____A (Microsoft Corporation) C:\Windows\System32\ntvdm64.dll 2012-12-12 01:40 - 2012-10-04 09:41 - 01161216 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll 2012-12-12 01:40 - 2012-10-04 09:41 - 00424960 ____A (Microsoft Corporation) C:\Windows\System32\KernelBase.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00006144 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00005120 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00004608 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00004608 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00004096 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00004096 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00004096 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00004096 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003584 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003584 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003584 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003584 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003584 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003584 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003584 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003072 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003072 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003072 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003072 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003072 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003072 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003072 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003072 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003072 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003072 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003072 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003072 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 09:38 - 00003072 ____A (Microsoft Corporation) C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:47 - 01114112 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2012-12-12 01:40 - 2012-10-04 08:47 - 00274944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2012-12-12 01:40 - 2012-10-04 08:47 - 00005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00005120 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00004608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00004096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00004096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00004096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00004096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00004096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00003584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00003584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00003584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00003584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00003584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00003584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00003072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00003072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00003072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00003072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00003072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00003072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00003072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00003072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00003072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00003072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 08:40 - 00003072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 07:21 - 00338432 ____A (Microsoft Corporation) C:\Windows\System32\conhost.exe 2012-12-12 01:40 - 2012-10-04 06:46 - 00025600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2012-12-12 01:40 - 2012-10-04 06:46 - 00014336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2012-12-12 01:40 - 2012-10-04 06:46 - 00007680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2012-12-12 01:40 - 2012-10-04 06:46 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2012-12-12 01:40 - 2012-10-04 06:41 - 00006144 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 06:41 - 00004608 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 06:41 - 00003584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2012-12-12 01:40 - 2012-10-04 06:41 - 00003072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2012-12-12 01:38 - 2012-11-01 21:59 - 00478208 ____A (Microsoft Corporation) C:\Windows\System32\dpnet.dll 2012-12-12 01:38 - 2012-11-01 21:11 - 00376832 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dpnet.dll 2012-12-12 01:06 - 2012-12-12 01:06 - 00000077 ____A C:\prefs.js 2012-12-11 22:40 - 2012-12-11 22:40 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\LogMeIn 2012-12-11 22:40 - 2012-12-11 22:40 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{90D6F6D7-5592-408A-8BD2-874BB451A375} 2012-12-11 22:28 - 2012-12-11 22:28 - 00000000 ____D C:\Users\Betty\AppData\Local\LogMeIn 2012-12-11 22:02 - 2012-12-11 22:02 - 00000000 ____D C:\e 2012-12-11 21:58 - 2013-01-01 23:55 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\DefaultTab 2012-12-11 21:15 - 2012-12-11 21:15 - 00000127 ____A C:\Users\Bryan\wxDownloadFast.ini 2012-12-11 21:03 - 2012-12-11 21:03 - 00000104 ____A C:\Users\Bryan\Desktop\Control Panel - Shortcut.lnk 2012-12-11 14:54 - 2012-12-18 13:15 - 00000000 ____D C:\Users\All Users\LogMeIn 2012-12-11 14:54 - 2012-12-11 14:54 - 00001024 ____A C:\.rnd 2012-12-11 14:54 - 2012-12-11 14:54 - 00000000 ____D C:\Users\Bryan\AppData\Local\LogMeIn 2012-12-11 14:54 - 2012-12-11 14:54 - 00000000 ____D C:\Program Files (x86)\LogMeIn 2012-12-11 14:54 - 2012-10-19 18:11 - 00088008 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll 2012-12-11 14:54 - 2012-10-19 18:10 - 00083880 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIinit.dll 2012-12-11 14:54 - 2012-10-19 18:10 - 00035240 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIport.dll 2012-12-11 14:54 - 2012-08-24 14:41 - 00072216 ____A (LogMeIn, Inc.) C:\Windows\System32\Drivers\LMIRfsDriver.sys 2012-12-11 14:52 - 2012-12-11 14:52 - 00000000 ____D C:\Users\Bryan\AppData\Local\Deployment 2012-12-10 13:17 - 2012-12-13 14:22 - 263192576 ____A C:\Users\Bryan\Downloads\The.Walking.Dead.Comic.193.part1.rar 2012-12-10 13:14 - 2012-12-10 13:14 - 00000000 ____D C:\Users\Bryan\AppData\Local\PutLockerDownloader 2012-12-10 12:44 - 2012-12-10 12:44 - 11949279 ____A C:\Users\Bryan\Downloads\The_Walking_Dead__02.cbr 2012-12-10 12:40 - 2012-12-12 01:31 - 00000000 ____D C:\Users\Bryan\AppData\Local\SwvUpdater 2012-12-10 12:40 - 2012-12-10 12:40 - 00000000 ____D C:\Program Files (x86)\wxDownload Fast 2012-12-10 12:39 - 2013-01-03 17:36 - 00000406 ___AH C:\Windows\Tasks\OptimizerProUpdaterTask{8E001057-D4F6-4F11-911C-836301DC943B}.job 2012-12-10 12:39 - 2013-01-01 17:14 - 00000009 ____A C:\END 2012-12-10 12:39 - 2012-12-10 15:59 - 00000000 ____D C:\Users\Bryan\AppData\Local\Conduit 2012-12-10 12:39 - 2012-12-10 12:40 - 00000000 ____D C:\Users\All Users\Premium 2012-12-10 12:39 - 2012-12-10 12:39 - 00000000 ____D C:\Program Files (x86)\Conduit 2012-12-10 12:38 - 2012-12-10 12:40 - 00000000 ____D C:\Users\All Users\wxDownload 2012-12-10 12:38 - 2012-12-10 12:39 - 00000000 ____D C:\Program Files (x86)\WxDownload 2012-12-10 12:36 - 2012-12-12 01:06 - 00000000 ____D C:\Users\All Users\InstallMate 2012-12-08 00:22 - 2012-12-08 00:22 - 00000000 ____D C:\Program Files (x86)\Gophoto.it 2012-12-06 17:29 - 2012-12-07 06:23 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{DC4B3525-C8B8-462D-95FD-B770AA4356C7} 2012-12-04 01:28 - 2012-12-04 01:28 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{3F5B96F9-08B6-4D1C-BC53-A1276272854C} ==================== One Month Modified Files and Folders ======= 2013-01-03 17:40 - 2009-07-13 20:45 - 00009920 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-01-03 17:40 - 2009-07-13 20:45 - 00009920 ____A C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-01-03 17:40 - 2006-10-10 18:53 - 02030938 ____A C:\Windows\WindowsUpdate.log 2013-01-03 17:39 - 2010-05-03 02:28 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-01-03 17:36 - 2012-12-10 12:39 - 00000406 ___AH C:\Windows\Tasks\OptimizerProUpdaterTask{8E001057-D4F6-4F11-911C-836301DC943B}.job 2013-01-03 17:36 - 2012-10-29 14:55 - 00008242 ____A C:\Windows\setupact.log 2013-01-03 17:36 - 2010-05-03 02:28 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-01-03 17:36 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-01-03 17:36 - 2006-10-10 18:53 - 00000000 ____D C:\Users\All Users\NVIDIA 2013-01-03 17:19 - 2013-01-03 17:19 - 00000000 ____D C:\FRST 2013-01-03 17:17 - 2013-01-03 17:17 - 01464235 ____A (Farbar) C:\Users\Bryan\Downloads\FRST64.exe 2013-01-03 16:36 - 2009-07-13 21:13 - 00779306 ____A C:\Windows\System32\PerfStringBackup.INI 2013-01-03 16:32 - 2012-11-20 19:01 - 00000374 ____A C:\Windows\Tasks\WpsUpdateTask_Bryan.job 2013-01-03 16:29 - 2012-04-13 14:07 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-01-02 23:09 - 2012-11-01 06:59 - 00751974 ____A C:\Windows\PFRO.log 2013-01-02 23:07 - 2013-01-02 23:07 - 00000000 ____D C:\Users\All Users\BasicSeek 2013-01-02 23:07 - 2013-01-02 23:07 - 00000000 ____D C:\Program Files (x86)\BasicSeek 2013-01-02 23:04 - 2011-11-12 20:20 - 00000000 ____D C:\Program Files (x86)\MSN Games 2013-01-02 22:55 - 2013-01-01 16:59 - 00000000 ____D C:\Users\Administrator.Family\AppData\Local\Conduit 2013-01-02 22:54 - 2011-10-09 12:22 - 00000000 ____D C:\Program Files (x86)\Yahoo! 2013-01-02 22:53 - 2011-12-17 11:31 - 00000000 ____D C:\Program Files (x86)\Digiarty 2013-01-02 22:27 - 2010-07-14 18:09 - 00000000 ____D C:\Users\Bryan\AppData\Local\PokerStars.NET 2013-01-02 22:27 - 2010-05-02 23:00 - 00000000 ____D C:\Users\Bryan\AppData\Local\PokerStars 2013-01-02 21:55 - 2013-01-02 21:55 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Roaming\SUPERAntiSpyware.com 2013-01-02 14:58 - 2013-01-02 14:58 - 00002975 ____A C:\Users\Bryan\Desktop\HiJackThis.lnk 2013-01-02 14:24 - 2013-01-02 00:49 - 00000000 ____D C:\Users\All Users\PrevxCSI 2013-01-02 13:28 - 2013-01-02 13:28 - 00000000 ____D C:\Program Files\WOT 2013-01-02 13:28 - 2011-12-08 00:01 - 00000000 ____D C:\Program Files (x86)\WOT 2013-01-02 12:38 - 2010-05-01 21:58 - 00000000 ____D C:\Users\Bryan\AppData\Local\Google 2013-01-02 10:43 - 2013-01-02 10:43 - 05415956 ____A C:\Users\Bryan\Downloads\tweaking.com_windows_repair_aio_setup (1).exe 2013-01-02 10:43 - 2012-11-26 12:15 - 00002291 ____A C:\Users\Public\Desktop\Tweaking.com - Windows Repair (All in One).lnk 2013-01-02 10:42 - 2013-01-02 10:42 - 05415956 ____A C:\Users\Bryan\Downloads\tweaking.com_windows_repair_aio_setup.exe 2013-01-02 10:17 - 2013-01-02 10:17 - 00000000 ____D C:\Windows\System32\%LocalAppData% 2013-01-02 10:03 - 2010-05-20 21:38 - 00000000 ____D C:\Windows\ERDNT 2013-01-02 03:24 - 2011-02-10 02:24 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Roaming\WinRAR 2013-01-02 01:00 - 2010-05-01 21:36 - 00079176 ____A C:\Users\Bryan\AppData\Local\GDIPFONTCACHEV1.DAT 2013-01-02 00:50 - 2013-01-02 00:50 - 00065736 ____A (Prevx) C:\Windows\System32\Drivers\pxrts.sys 2013-01-02 00:50 - 2013-01-02 00:50 - 00000000 ____D C:\Program Files\Prevx 2013-01-02 00:49 - 2010-06-15 22:22 - 00000935 ____A C:\Windows\wininit.ini 2013-01-02 00:17 - 2010-05-02 11:55 - 00000000 ____D C:\users\Zanthia.Family 2013-01-02 00:06 - 2010-05-03 20:52 - 00000632 _RASH C:\Users\Zanthia.Family\ntuser.pol 2013-01-01 23:55 - 2012-12-11 21:58 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\DefaultTab 2013-01-01 23:26 - 2010-05-02 21:29 - 00000000 ____D C:\Users\Zanthia.Family\Tracing 2013-01-01 22:59 - 2012-02-08 03:10 - 00004264 ____A C:\Windows\Sandboxie.ini 2013-01-01 22:58 - 2010-11-16 11:48 - 00079176 ____A C:\Users\Betty\AppData\Local\GDIPFONTCACHEV1.DAT 2013-01-01 22:36 - 2010-05-02 11:59 - 00079176 ____A C:\Users\Zanthia.Family\AppData\Local\GDIPFONTCACHEV1.DAT 2013-01-01 22:34 - 2010-05-03 12:09 - 00000632 _RASH C:\Users\Bryan\ntuser.pol 2013-01-01 22:34 - 2010-05-01 21:34 - 00000000 ____D C:\users\Bryan 2013-01-01 22:33 - 2009-07-13 20:45 - 00334096 ____A C:\Windows\System32\FNTCACHE.DAT 2013-01-01 22:23 - 2012-11-26 12:16 - 00181064 ____A (Sysinternals) C:\Windows\PSEXESVC.EXE 2013-01-01 22:19 - 2011-01-02 21:40 - 00779306 ____A C:\Windows\SysWOW64\PerfStringBackup.INI 2013-01-01 17:43 - 2011-01-10 13:13 - 00000000 ____D C:\Windows\pss 2013-01-01 17:32 - 2013-01-01 17:32 - 00032152 ____A C:\Windows\System32\Drivers\hitmanpro37.sys 2013-01-01 17:30 - 2013-01-01 17:30 - 00000000 ____D C:\Users\Daniel.Family\Documents\4a games 2013-01-01 17:30 - 2010-12-01 11:45 - 00000000 ____D C:\Users\Daniel.Family\AppData\Local\Windows Live 2013-01-01 17:30 - 2010-05-05 01:18 - 00000000 ____D C:\Users\Daniel.Family\Tracing 2013-01-01 17:29 - 2013-01-01 17:29 - 00000000 ____D C:\Users\Daniel.Family\AppData\Local\{B1DD0CA5-E02F-444F-B0A5-D9F75FCC0CE5} 2013-01-01 17:29 - 2010-05-13 17:36 - 00079176 ____A C:\Users\Daniel.Family\AppData\Local\GDIPFONTCACHEV1.DAT 2013-01-01 17:19 - 2013-01-01 17:19 - 00000000 ____D C:\Users\Betty\AppData\Roaming\Malwarebytes 2013-01-01 17:14 - 2012-12-10 12:39 - 00000009 ____A C:\END 2013-01-01 17:05 - 2013-01-01 17:05 - 00208216 ____A (Kaspersky Lab, GERT) C:\Windows\System32\Drivers\34792715.sys 2013-01-01 17:04 - 2013-01-01 17:04 - 00000000 ____D C:\Users\Administrator.Family\AppData\Roaming\WinRAR 2013-01-01 17:01 - 2013-01-01 17:01 - 02195988 ____A C:\Users\Administrator.Family\Desktop\tdsskiller-2-8-14-0[1].zip 2013-01-01 17:01 - 2013-01-01 17:01 - 00000000 ____D C:\Users\Administrator.Family\Desktop\tdsskiller-2-8-14-0[1] 2013-01-01 16:57 - 2013-01-01 16:57 - 00000000 ____D C:\Users\All Users\VisualBee 2013-01-01 16:56 - 2013-01-01 16:56 - 02195988 ____A C:\Users\Administrator.Family\Desktop\tdsskiller-2-8-14-0.zip 2013-01-01 16:50 - 2013-01-01 16:49 - 00000000 ____D C:\Users\Administrator.Family\AppData\Roaming\Google 2013-01-01 16:49 - 2013-01-01 16:49 - 00000000 ____D C:\Users\Administrator.Family\AppData\Roaming\Adobe 2013-01-01 16:49 - 2013-01-01 16:49 - 00000000 ____D C:\Users\Administrator.Family\AppData\Local\Google 2013-01-01 16:41 - 2013-01-01 16:41 - 00000000 ____D C:\Users\Administrator.Family\AppData\Roaming\SUPERAntiSpyware.com 2013-01-01 16:40 - 2013-01-01 16:40 - 00079176 ____A C:\Users\Administrator.Family\AppData\Local\GDIPFONTCACHEV1.DAT 2013-01-01 16:40 - 2013-01-01 16:40 - 00000632 _RASH C:\Users\Administrator.Family\ntuser.pol 2013-01-01 16:40 - 2013-01-01 16:40 - 00000020 __ASH C:\Users\Administrator.Family\ntuser.ini 2013-01-01 16:40 - 2013-01-01 16:40 - 00000000 ____D C:\users\Administrator.Family 2013-01-01 16:11 - 2013-01-01 16:11 - 00000000 __SHD C:\found.003 2013-01-01 15:25 - 2013-01-01 15:25 - 00000000 __SHD C:\found.002 2013-01-01 14:09 - 2013-01-01 14:09 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{0D15E399-8284-41A7-8304-CC9AAF180A83} 2013-01-01 14:09 - 2010-10-24 14:00 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\Windows Live 2013-01-01 13:53 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration 2013-01-01 13:48 - 2013-01-01 13:48 - 657833086 ____A C:\Windows\MEMORY.DMP 2013-01-01 13:48 - 2013-01-01 13:48 - 00291704 ____A C:\Windows\Minidump\010113-21184-01.dmp 2013-01-01 13:48 - 2010-05-15 15:03 - 00000000 ____D C:\Windows\Minidump 2012-12-31 18:43 - 2012-12-31 18:43 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{6E89A9B8-1172-48C2-9F67-D725340AC89F} 2012-12-31 13:24 - 2012-12-31 13:24 - 00000000 __SHD C:\found.001 2012-12-31 13:02 - 2012-01-12 21:37 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Dropbox 2012-12-30 18:57 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF 2012-12-30 09:10 - 2010-05-06 09:22 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2012-12-30 09:07 - 2012-12-30 09:07 - 00000000 __SHD C:\found.000 2012-12-30 09:01 - 2012-09-19 07:27 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-12-28 01:23 - 2012-12-28 01:23 - 06160306 ____A C:\Users\Bryan\Downloads\com.android.vending-3.10.10.apk 2012-12-27 17:24 - 2012-12-27 17:24 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{7A0A48BA-4014-4B44-9478-D77BEBDD1C0D} 2012-12-26 19:46 - 2012-12-26 19:46 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{1BBAC4FB-7992-4183-BDD0-1BE0573D692C} 2012-12-26 15:58 - 2012-05-17 16:58 - 00004693 ____A C:\Users\Bryan\Downloads\809CB141_sp.rl0 2012-12-26 15:58 - 2012-05-16 01:36 - 00046080 ____A C:\Users\Bryan\Downloads\809CB141_sp.qcn 2012-12-25 20:42 - 2012-12-25 20:42 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{2AF8418A-2691-4874-B3B1-16CB6EFF6ECA} 2012-12-25 11:37 - 2012-12-25 08:59 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Apple Computer 2012-12-25 08:59 - 2012-12-25 08:59 - 00000000 ____D C:\Users\Bryan\AppData\Local\Apple Computer 2012-12-25 08:58 - 2012-12-25 08:58 - 00001910 ____A C:\Users\Bryan\Desktop\CarbonPoker.lnk 2012-12-24 15:02 - 2012-12-24 15:02 - 00000000 ____D C:\Windows\AxInstSV 2012-12-24 15:02 - 2012-12-24 15:02 - 00000000 ____D C:\Program Files (x86)\Panda Security 2012-12-24 13:25 - 2012-12-24 13:25 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{56D58E79-20E0-465E-8688-DE373C7DAF6D} 2012-12-23 23:11 - 2012-12-23 23:11 - 00334808 ____A C:\Users\Bryan\Downloads\417038_intl_x64_zip.exe 2012-12-23 23:08 - 2011-09-20 16:49 - 01699328 __ASH C:\Users\Bryan\Downloads\Thumbs.db 2012-12-23 22:59 - 2010-05-01 21:38 - 00000000 ____D C:\Users\Bryan\AppData\Local\VirtualStore 2012-12-23 05:27 - 2012-12-22 17:26 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{4363B4C1-9D35-4D06-975F-23249F497EE1} 2012-12-22 15:34 - 2010-05-04 13:31 - 00487048 ____A C:\Windows\System32\Drivers\etc\hosts_bak_44 2012-12-21 23:58 - 2012-12-21 23:58 - 00000281 ____A C:\Users\Bryan\Desktop\Proggrammer.url 2012-12-21 00:54 - 2012-12-21 00:54 - 00002591 ____A C:\Users\Bryan\Desktop\Radio Tuna.lnk 2012-12-21 00:53 - 2012-12-21 00:53 - 00002573 ____A C:\Users\Public\Desktop\Radio Tuna.lnk 2012-12-21 00:53 - 2012-12-21 00:53 - 00000000 ____D C:\Users\Bryan\AppData\Local\TunaMediaLtd 2012-12-21 00:53 - 2012-12-21 00:53 - 00000000 ____D C:\Program Files (x86)\TunaMediaLtd 2012-12-21 00:52 - 2012-12-21 00:52 - 00000000 ____D C:\Users\Bryan\AppData\Local\Downloaded Installations 2012-12-18 23:16 - 2012-12-18 23:16 - 04068352 ____A (http://yourfiledownloader.com) C:\Users\Bryan\Downloads\The_Walking_Dead_Comic_(1-93)_downloader_99132.exe 2012-12-18 13:15 - 2012-12-11 14:54 - 00000000 ____D C:\Users\All Users\LogMeIn 2012-12-18 13:14 - 2009-10-27 22:25 - 00000000 ____D C:\Users\All Users\Adobe 2012-12-16 09:11 - 2012-12-22 09:01 - 00046080 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll 2012-12-16 06:45 - 2012-12-22 09:01 - 00367616 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll 2012-12-16 06:13 - 2012-12-22 09:01 - 00295424 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2012-12-16 06:13 - 2012-12-22 09:01 - 00034304 ____A (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2012-12-15 11:52 - 2012-12-15 11:52 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{ED8A116C-86DF-4053-9D28-93F458FC209A} 2012-12-15 00:04 - 2012-12-15 00:04 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\SystemRequirementsLab 2012-12-15 00:04 - 2010-05-05 00:49 - 00000000 ____D C:\Program Files (x86)\SystemRequirementsLab 2012-12-14 23:25 - 2012-12-14 23:25 - 00000000 ____D C:\Users\Bryan\Documents\4A Games 2012-12-14 23:14 - 2012-12-14 23:14 - 00000000 ____D C:\Users\Bryan\AppData\Local\4A Games 2012-12-14 23:10 - 2012-12-14 23:09 - 00017513 ____A C:\Windows\DirectX.log 2012-12-14 16:49 - 2012-09-19 07:27 - 00024176 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2012-12-14 09:41 - 2012-12-14 09:41 - 00000921 ____A C:\Users\Public\Desktop\Steam.lnk 2012-12-13 15:30 - 2010-07-14 18:09 - 00000000 ____D C:\Program Files (x86)\PokerStars.NET 2012-12-13 14:43 - 2012-12-13 12:55 - 00000000 ____D C:\Users\Bryan\AppData\Local\DownTango 2012-12-13 14:22 - 2012-12-10 13:17 - 263192576 ____A C:\Users\Bryan\Downloads\The.Walking.Dead.Comic.193.part1.rar 2012-12-13 13:38 - 2012-12-12 13:38 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{A0DC0D10-3C88-4FDA-A996-CD84AF6B9659} 2012-12-13 12:55 - 2012-12-13 12:55 - 00000000 ____D C:\Program Files (x86)\Red Sky 2012-12-13 00:42 - 2012-01-31 14:47 - 00002378 ____A C:\Users\Public\Desktop\Google Chrome.lnk 2012-12-12 02:35 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache 2012-12-12 01:54 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2012-12-12 01:31 - 2012-12-10 12:40 - 00000000 ____D C:\Users\Bryan\AppData\Local\SwvUpdater 2012-12-12 01:29 - 2012-04-13 14:07 - 00697272 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2012-12-12 01:29 - 2011-11-07 09:34 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2012-12-12 01:06 - 2012-12-12 01:06 - 00000077 ____A C:\prefs.js 2012-12-12 01:06 - 2012-12-10 12:36 - 00000000 ____D C:\Users\All Users\InstallMate 2012-12-11 22:40 - 2012-12-11 22:40 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\LogMeIn 2012-12-11 22:40 - 2012-12-11 22:40 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{90D6F6D7-5592-408A-8BD2-874BB451A375} 2012-12-11 22:28 - 2012-12-11 22:28 - 00000000 ____D C:\Users\Betty\AppData\Local\LogMeIn 2012-12-11 22:02 - 2012-12-11 22:02 - 00000000 ____D C:\e 2012-12-11 21:15 - 2012-12-11 21:15 - 00000127 ____A C:\Users\Bryan\wxDownloadFast.ini 2012-12-11 21:03 - 2012-12-11 21:03 - 00000104 ____A C:\Users\Bryan\Desktop\Control Panel - Shortcut.lnk 2012-12-11 14:54 - 2012-12-11 14:54 - 00001024 ____A C:\.rnd 2012-12-11 14:54 - 2012-12-11 14:54 - 00000000 ____D C:\Users\Bryan\AppData\Local\LogMeIn 2012-12-11 14:54 - 2012-12-11 14:54 - 00000000 ____D C:\Program Files (x86)\LogMeIn 2012-12-11 14:52 - 2012-12-11 14:52 - 00000000 ____D C:\Users\Bryan\AppData\Local\Deployment 2012-12-11 14:52 - 2010-05-12 10:35 - 00000000 ____D C:\Users\Bryan\AppData\Local\Apps\2.0 2012-12-10 15:59 - 2012-12-10 12:39 - 00000000 ____D C:\Users\Bryan\AppData\Local\Conduit 2012-12-10 13:14 - 2012-12-10 13:14 - 00000000 ____D C:\Users\Bryan\AppData\Local\PutLockerDownloader 2012-12-10 12:46 - 2012-01-15 16:42 - 00000000 ____D C:\Program Files\WinRAR 2012-12-10 12:44 - 2012-12-10 12:44 - 11949279 ____A C:\Users\Bryan\Downloads\The_Walking_Dead__02.cbr 2012-12-10 12:40 - 2012-12-10 12:40 - 00000000 ____D C:\Program Files (x86)\wxDownload Fast 2012-12-10 12:40 - 2012-12-10 12:39 - 00000000 ____D C:\Users\All Users\Premium 2012-12-10 12:40 - 2012-12-10 12:38 - 00000000 ____D C:\Users\All Users\wxDownload 2012-12-10 12:39 - 2012-12-10 12:39 - 00000000 ____D C:\Program Files (x86)\Conduit 2012-12-10 12:39 - 2012-12-10 12:38 - 00000000 ____D C:\Program Files (x86)\WxDownload 2012-12-08 00:22 - 2012-12-08 00:22 - 00000000 ____D C:\Program Files (x86)\Gophoto.it 2012-12-07 06:23 - 2012-12-06 17:29 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{DC4B3525-C8B8-462D-95FD-B770AA4356C7} 2012-12-04 09:16 - 2012-12-14 09:39 - 00000000 ____D C:\Users\Bryan\Desktop\metro 2033 2012-12-04 01:28 - 2012-12-04 01:28 - 00000000 ____D C:\Users\Zanthia.Family\AppData\Local\{3F5B96F9-08B6-4D1C-BC53-A1276272854C} ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\…\.exe: exefile => OK HKLM\…\exefile\DefaultIcon: %1 => OK HKLM\…\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= ==================== Memory info =========================== Percentage of memory in use: 18% Total physical RAM: 3838.55 MB Available physical RAM: 3135.03 MB Total Pagefile: 3836.7 MB Available Pagefile: 3131.9 MB Total Virtual: 8192 MB Available Virtual: 8191.89 MB ==================== Partitions ============================= 1 Drive c: (Acer) (Fixed) (Total:684.87 GB) (Free:567.5 GB) NTFS 2 Drive e: (PQSERVICE) (Fixed) (Total:13.67 GB) (Free:3.98 GB) NTFS 6 Drive i: () (Removable) (Total:7.45 GB) (Free:7.4 GB) FAT32 7 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS 8 Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] Disk ### Status Size Free Dyn Gpt ——– ————- ——- ——- — — Disk 0 Online 698 GB 0 B Disk 1 No Media 0 B 0 B Disk 2 No Media 0 B 0 B Disk 3 Online 7633 MB 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Recovery 13 GB 1024 KB Partition 2 Primary 100 MB 13 GB Partition 3 Primary 684 GB 13 GB ================================================================================ == Disk: 0 Partition 1 Type : 27 Hidden: Yes Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 3 E PQSERVICE NTFS Partition 13 GB Healthy Hidden ========================================================= Disk: 0 Partition 2 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 1 Y SYSTEM RESE NTFS Partition 100 MB Healthy ========================================================= Disk: 0 Partition 3 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 C Acer NTFS Partition 684 GB Healthy ========================================================= Partitions of Disk 3: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 7633 MB 16 KB ================================================================================ == Disk: 3 Partition 1 Type : 0B Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 6 I FAT32 Removable 7633 MB Healthy ========================================================= Last Boot: 2010-08-29 17:25 ==================== End Of Log =============================
Thank you for the log. As you can see it is a bit lengthy and will take me a bit to look over, but it will give me a diagnostic look at the machine so we have a starting point :) I am at work but will attempt to get backt to you as quickly as I can today. If you can't post back during the day that is quite fine, but I will do my best to respond to you as soon as I can once you do.
I see that you have already installed the Windows Repair (All in One) Tool from Tweaking.com. Have you already run this tool?

I see that you also installed TDSSKiller. Did you run this and if so did you select skip or cure when you ran it?
There should be a report found in your root directory if you ran it, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt" which would be very helpful to me if you could post in your next reply.


Let's give something a try:
Restart your computer and tap F8 to bring up the Advanced Menu, then click Repair your computer

On this menu, this time I'd like you to select Startup Repair and follow the instructions on screen. You should not need to have a recovery disc for this.
Typically your machine can do this without having one. It may churn away for a little while and appear to be doing nothing. And indeed it may tell you it was either unable to find any errors or was unable to correct any that it found (which sometimes I've found to be true and sometimes they magically seem to be fixed anyway) but either way just reboot the machine into normal mode and let me know if there is any change.
I ran the repir tool from F8 but it didn't detect anything wrong, but a couple of days ago it did do some repair to the start menu when I was having trouble logging in. Tweaking .com shut itself down the first time I ran it a few days ago, but did complete running after that but also caused my account to be closed down every time I tried to log in. I ran a HJT scan it showed a problem with 010, 2 items. I did not try and correct anything with HJT but didn't save that log but I reran it today and both items under 010 are still there, I'll include that log also.

TDSKIller could not detect anything wrong in the scan and I'll show that also. I'll also include a scan from MalwareBytes from a full scan because the quick scan option would not complete after several attempts. I had to run some of these from my wifes account because I could no longer log into my own after running the Tweaking.com tool. After shutting things down for the night 2 days ago I was able to log in after cleaning the results from the Malwarebytes scan. Something is still wrong but I can at least log into my account agaIn. I also deleted all the crzy programs my wife downloads and the tool bars she always seems to accept being loaded. No matter how many times I ask her to ask me about downloading things she does it anyway because she likes to play the games offered and also checks on many of the hyped free stuff she sees. I installed Sandboxie on the system but it stopped starting from her account. Also I've had to restart MSE several ytimes because it keeps getting shut down by something. MSE and windows firewall are the only tools I currently use for protection.

I'll wait for you to complete cleaning things and then follow your advice concerning what security tools are best to use. Please keep in mind that I'm a disabled veteran living on $1038 a month so I cannot afford to buy the better antivirus and protection software out there. I use Gizmo's site for help in determining the best free tools to use for my system.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:55:30 AM, on 1/4/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
c:\Windows\System32\oem\SetEvent.exe
C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_5_502_135_ActiveX.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HiJackThis.exe
C:\Windows\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.privitize.com/?aff=7
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: DefaultTabBHO - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Bryan\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll (file missing)
O2 - BHO: wxDownload - {95B741CB-CF8A-6780-C5F6-FF7C39EA7BCE} - C:\ProgramData\wxDownload\50c64c701d1de.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll
O2 - BHO: WeCareReminder - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\ProgramData\WeCareReminder\IEHelperv2.5.0.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SimpleAdblock Class - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files (x86)\Common Files\Simple Adblock\SimpleAdblock.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://oas.support.microsoft.com/ActiveX/MSDcode.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - http://content.systemrequirementslab.com.s…ri_4.1.71.0.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files%20(x86)/Slingo%20Deluxe/Images/stg_drm.ocx
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://gamesville.worldwinner.com/games/v4…GamesLoader.cab
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} (TPIR Control) - http://www.worldwinner.com/games/v50/tpir/tpir.cab
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/…can8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - https://www.battlefieldheroes.com/static/up…er_4.0.53.0.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} (WorldWinner ActiveX Launcher Control) - http://www.worldwinner.com/games/launcher/….0/iewwload.cab
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {95A311CD-EC8E-452A-BCEC-B844EB616D03} (BejeweledTwist Control) - http://www.worldwinner.com/games/v51/bejew…eweledtwist.cab
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://www.worldwinner.com/games/v57/cubis/cubis.cab
O16 - DPF: {A021A215-6CDC-44B4-8C16-90491CED9605} (Clue Control) - http://www.worldwinner.com/games/v68/clue/clue.cab
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} (PCMaticVer Class) - http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
O16 - DPF: {BA35B9B8-DE9E-47C9-AFA7-3C77E3DDFD39} (Monopoly Control) - http://www.worldwinner.com/games/v46/monopoly/monopoly.cab
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} (Tilecity Control) - http://www.worldwinner.com/games/v42/tilecity/tilecity.cab
O16 - DPF: {C82BB209-F528-46F9-96D5-69DEF7260916} (MysteryPI Control) - http://www.worldwinner.com/games/v45/mysterypi/mysterypi.cab
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) - http://www.worldwinner.com/games/v43/paint/paint.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files%20(x86)/Slingo%20Deluxe/Images/armhelper.ocx
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} (SysInfo Class) - http://content.systemrequirementslab.com.s…yri_4.5.1.0.cab
O16 - DPF: {FC4CAF5F-91BD-4DD9-ADC1-F3C737E37BC4} (CPlayFirstSweetopiaControl Object) - http://zone.msn.com/bingame/swet/default/S…ia.1.0.0.46.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll
O20 - AppInit_DLLs: c:\PROGRA~2\WXDOWN~1\SPROTE~1.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Encrypting File System (EFS) (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\PSIA.exe
O23 - Service: Secunia Update Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\sua.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 13285 bytes

17:05:04.0007 1068 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
17:05:04.0600 1068 ============================================================
17:05:04.0600 1068 Current date / time: 2013/01/01 17:05:04.0600
17:05:04.0600 1068 SystemInfo:
17:05:04.0600 1068
17:05:04.0600 1068 OS Version: 6.1.7601 ServicePack: 1.0
17:05:04.0600 1068 Product type: Workstation
17:05:04.0600 1068 ComputerName: FAMILY
17:05:04.0600 1068 UserName: Administrator
17:05:04.0600 1068 Windows directory: C:\Windows
17:05:04.0600 1068 System windows directory: C:\Windows
17:05:04.0600 1068 Running under WOW64
17:05:04.0600 1068 Processor architecture: Intel x64
17:05:04.0600 1068 Number of processors: 2
17:05:04.0600 1068 Page size: 0x1000
17:05:04.0600 1068 Boot type: Normal boot
17:05:04.0600 1068 ============================================================
17:05:06.0363 1068 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
17:05:06.0378 1068 ============================================================
17:05:06.0378 1068 \Device\Harddisk0\DR0:
17:05:06.0378 1068 MBR partitions:
17:05:06.0378 1068 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1B58800, BlocksNum 0x32000
17:05:06.0378 1068 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1B8A800, BlocksNum 0x559BB6F0
17:05:06.0378 1068 ============================================================
17:05:06.0410 1068 C: <-> \Device\Harddisk0\DR0\Partition2
17:05:06.0410 1068 ============================================================
17:05:06.0410 1068 Initialize success
17:05:06.0410 1068 ============================================================
17:05:09.0686 2500 ============================================================
17:05:09.0686 2500 Scan started
17:05:09.0686 2500 Mode: Manual;
17:05:09.0686 2500 ============================================================
17:05:10.0559 2500 ================ Scan system memory ========================
17:05:10.0559 2500 System memory - ok
17:05:10.0559 2500 ================ Scan services =============================
17:05:10.0653 2500 [ 581D88B25C4D4121824FED2CA38E562F ] !SASCORE C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
17:05:10.0668 2500 !SASCORE - ok
17:05:10.0918 2500 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
17:05:10.0918 2500 1394ohci - ok
17:05:10.0980 2500 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
17:05:10.0980 2500 ACPI - ok
17:05:10.0996 2500 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
17:05:10.0996 2500 AcpiPmi - ok
17:05:11.0152 2500 [ 95CE557D16A75606CCC2D7F3B0B0BCCB ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
17:05:11.0152 2500 AdobeFlashPlayerUpdateSvc - ok
17:05:11.0183 2500 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
17:05:11.0183 2500 adp94xx - ok
17:05:11.0199 2500 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
17:05:11.0199 2500 adpahci - ok
17:05:11.0230 2500 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
17:05:11.0230 2500 adpu320 - ok
17:05:11.0277 2500 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
17:05:11.0277 2500 AeLookupSvc - ok
17:05:11.0324 2500 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
17:05:11.0339 2500 AFD - ok
17:05:11.0370 2500 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
17:05:11.0370 2500 agp440 - ok
17:05:11.0386 2500 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
17:05:11.0386 2500 ALG - ok
17:05:11.0417 2500 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
17:05:11.0417 2500 aliide - ok
17:05:11.0542 2500 ALSysIO - ok
17:05:11.0558 2500 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
17:05:11.0558 2500 amdide - ok
17:05:11.0573 2500 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
17:05:11.0573 2500 AmdK8 - ok
17:05:11.0589 2500 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
17:05:11.0604 2500 AmdPPM - ok
17:05:11.0636 2500 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
17:05:11.0636 2500 amdsata - ok
17:05:11.0651 2500 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
17:05:11.0651 2500 amdsbs - ok
17:05:11.0682 2500 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
17:05:11.0682 2500 amdxata - ok
17:05:11.0776 2500 [ 4DE0D5D747A73797C95A97DCCE5018B5 ] androidusb C:\Windows\system32\Drivers\ssadadb.sys
17:05:11.0776 2500 androidusb - ok
17:05:11.0792 2500 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
17:05:11.0792 2500 AppID - ok
17:05:11.0823 2500 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
17:05:11.0823 2500 AppIDSvc - ok
17:05:11.0854 2500 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
17:05:11.0854 2500 Appinfo - ok
17:05:11.0885 2500 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
17:05:11.0885 2500 arc - ok
17:05:11.0885 2500 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
17:05:11.0885 2500 arcsas - ok
17:05:12.0041 2500 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
17:05:12.0072 2500 aspnet_state - ok
17:05:12.0088 2500 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
17:05:12.0088 2500 AsyncMac - ok
17:05:12.0119 2500 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
17:05:12.0119 2500 atapi - ok
17:05:12.0182 2500 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
17:05:12.0182 2500 AudioEndpointBuilder - ok
17:05:12.0197 2500 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
17:05:12.0197 2500 AudioSrv - ok
17:05:12.0244 2500 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
17:05:12.0244 2500 AxInstSV - ok
17:05:12.0291 2500 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
17:05:12.0291 2500 b06bdrv - ok
17:05:12.0338 2500 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
17:05:12.0338 2500 b57nd60a - ok
17:05:12.0369 2500 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
17:05:12.0369 2500 BDESVC - ok
17:05:12.0384 2500 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
17:05:12.0384 2500 Beep - ok
17:05:12.0416 2500 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
17:05:12.0416 2500 BFE - ok
17:05:12.0478 2500 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
17:05:12.0478 2500 BITS - ok
17:05:12.0494 2500 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
17:05:12.0494 2500 blbdrive - ok
17:05:12.0618 2500 [ 5AB58C337AC65837FE404462AD6265AB ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe
17:05:12.0618 2500 Bonjour Service - ok
17:05:12.0665 2500 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
17:05:12.0665 2500 bowser - ok
17:05:12.0681 2500 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
17:05:12.0681 2500 BrFiltLo - ok
17:05:12.0696 2500 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
17:05:12.0696 2500 BrFiltUp - ok
17:05:12.0712 2500 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
17:05:12.0712 2500 BridgeMP - ok
17:05:12.0759 2500 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
17:05:12.0759 2500 Browser - ok
17:05:12.0790 2500 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
17:05:12.0790 2500 Brserid - ok
17:05:12.0806 2500 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
17:05:12.0806 2500 BrSerWdm - ok
17:05:12.0806 2500 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
17:05:12.0806 2500 BrUsbMdm - ok
17:05:12.0852 2500 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
17:05:12.0852 2500 BrUsbSer - ok
17:05:12.0868 2500 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
17:05:12.0868 2500 BTHMODEM - ok
17:05:12.0915 2500 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
17:05:12.0915 2500 bthserv - ok
17:05:12.0930 2500 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
17:05:12.0946 2500 cdfs - ok
17:05:13.0008 2500 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
17:05:13.0008 2500 cdrom - ok
17:05:13.0040 2500 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
17:05:13.0040 2500 CertPropSvc - ok
17:05:13.0055 2500 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
17:05:13.0071 2500 circlass - ok
17:05:13.0086 2500 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
17:05:13.0102 2500 CLFS - ok
17:05:13.0164 2500 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:05:13.0164 2500 clr_optimization_v2.0.50727_32 - ok
17:05:13.0211 2500 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
17:05:13.0211 2500 clr_optimization_v2.0.50727_64 - ok
17:05:13.0258 2500 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17:05:13.0336 2500 clr_optimization_v4.0.30319_32 - ok
17:05:13.0367 2500 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
17:05:13.0414 2500 clr_optimization_v4.0.30319_64 - ok
17:05:13.0461 2500 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
17:05:13.0461 2500 CmBatt - ok
17:05:13.0492 2500 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
17:05:13.0492 2500 cmdide - ok
17:05:13.0554 2500 [ AAFCB52FE0037207FB6FBEA070D25EFE ] CNG C:\Windows\system32\Drivers\cng.sys
17:05:13.0554 2500 CNG - ok
17:05:13.0586 2500 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
17:05:13.0586 2500 Compbatt - ok
17:05:13.0617 2500 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
17:05:13.0617 2500 CompositeBus - ok
17:05:13.0617 2500 COMSysApp - ok
17:05:13.0648 2500 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
17:05:13.0648 2500 crcdisk - ok
17:05:13.0695 2500 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
17:05:13.0695 2500 CryptSvc - ok
17:05:13.0742 2500 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
17:05:13.0742 2500 DcomLaunch - ok
17:05:13.0820 2500 [ 34AE0DFA3EE3B5B9975042D87332D0B7 ] DefaultTabUpdate C:\Users\Bryan\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe
17:05:13.0820 2500 DefaultTabUpdate - ok
17:05:13.0851 2500 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
17:05:13.0866 2500 defragsvc - ok
17:05:13.0929 2500 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
17:05:13.0929 2500 DfsC - ok
17:05:13.0976 2500 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
17:05:13.0976 2500 Dhcp - ok
17:05:13.0991 2500 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
17:05:13.0991 2500 discache - ok
17:05:14.0022 2500 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
17:05:14.0022 2500 Disk - ok
17:05:14.0069 2500 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
17:05:14.0069 2500 Dnscache - ok
17:05:14.0100 2500 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
17:05:14.0100 2500 dot3svc - ok
17:05:14.0116 2500 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
17:05:14.0116 2500 DPS - ok
17:05:14.0132 2500 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
17:05:14.0132 2500 drmkaud - ok
17:05:14.0194 2500 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
17:05:14.0194 2500 DXGKrnl - ok
17:05:14.0210 2500 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
17:05:14.0210 2500 EapHost - ok
17:05:14.0241 2500 easytether - ok
17:05:14.0303 2500 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
17:05:14.0366 2500 ebdrv - ok
17:05:14.0412 2500 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
17:05:14.0412 2500 EFS - ok
17:05:14.0475 2500 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
17:05:14.0475 2500 elxstor - ok
17:05:14.0584 2500 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
17:05:14.0584 2500 ErrDev - ok
17:05:14.0740 2500 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
17:05:14.0756 2500 EventSystem - ok
17:05:14.0771 2500 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
17:05:14.0771 2500 exfat - ok
17:05:14.0787 2500 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
17:05:14.0787 2500 fastfat - ok
17:05:14.0802 2500 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
17:05:14.0802 2500 fdc - ok
17:05:14.0818 2500 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
17:05:14.0834 2500 fdPHost - ok
17:05:14.0834 2500 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
17:05:14.0834 2500 FDResPub - ok
17:05:14.0849 2500 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
17:05:14.0849 2500 FileInfo - ok
17:05:14.0865 2500 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
17:05:14.0865 2500 Filetrace - ok
17:05:14.0865 2500 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
17:05:14.0880 2500 flpydisk - ok
17:05:14.0896 2500 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
17:05:14.0912 2500 FltMgr - ok
17:05:14.0958 2500 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
17:05:14.0990 2500 FontCache - ok
17:05:15.0068 2500 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
17:05:15.0068 2500 FontCache3.0.0.0 - ok
17:05:15.0239 2500 [ A9FF65EA14E4CABFCC1BB8ECE111A249 ] ForceWare Intelligent Application Manager (IAM) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
17:05:15.0239 2500 ForceWare Intelligent Application Manager (IAM) - ok
17:05:15.0286 2500 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
17:05:15.0286 2500 FsDepends - ok
17:05:15.0348 2500 [ 6C06701BF1DB05405804D7EB610991CE ] fssfltr C:\Windows\system32\DRIVERS\fssfltr.sys
17:05:15.0348 2500 fssfltr - ok
17:05:15.0458 2500 [ 4CE9DAC1518FF7E77BD213E6394B9D77 ] fsssvc C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
17:05:15.0473 2500 fsssvc - ok
17:05:15.0520 2500 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
17:05:15.0520 2500 Fs_Rec - ok
17:05:15.0551 2500 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
17:05:15.0551 2500 fvevol - ok
17:05:15.0582 2500 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
17:05:15.0582 2500 gagp30kx - ok
17:05:15.0660 2500 [ 67CF4C2E7477B9A01DF07E38AF293414 ] GameConsoleService C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe
17:05:15.0660 2500 GameConsoleService - ok
17:05:15.0676 2500 GEARAspiWDM - ok
17:05:15.0707 2500 [ 9BA22AEE7F531EF9CE085CC2E1112BC4 ] GIDv2 C:\Windows\system32\drivers\GIDv2.sys
17:05:15.0707 2500 GIDv2 - ok
17:05:15.0754 2500 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
17:05:15.0770 2500 gpsvc - ok
17:05:15.0832 2500 [ 816FD5A6F3C2F3D600900096632FC60E ] Greg_Service C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
17:05:15.0848 2500 Greg_Service - ok
17:05:15.0941 2500 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
17:05:15.0941 2500 gupdate - ok
17:05:15.0972 2500 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
17:05:15.0972 2500 gupdatem - ok
17:05:16.0019 2500 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
17:05:16.0019 2500 gusvc - ok
17:05:16.0050 2500 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
17:05:16.0050 2500 hcw85cir - ok
17:05:16.0097 2500 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
17:05:16.0097 2500 HdAudAddService - ok
17:05:16.0128 2500 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
17:05:16.0128 2500 HDAudBus - ok
17:05:16.0160 2500 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
17:05:16.0160 2500 HidBatt - ok
17:05:16.0175 2500 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
17:05:16.0175 2500 HidBth - ok
17:05:16.0175 2500 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
17:05:16.0175 2500 HidIr - ok
17:05:16.0222 2500 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
17:05:16.0222 2500 hidserv - ok
17:05:16.0238 2500 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
17:05:16.0238 2500 HidUsb - ok
17:05:16.0269 2500 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
17:05:16.0269 2500 hkmsvc - ok
17:05:16.0300 2500 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
17:05:16.0300 2500 HomeGroupListener - ok
17:05:16.0316 2500 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
17:05:16.0316 2500 HomeGroupProvider - ok
17:05:16.0362 2500 [ DDF58C2E16527073FEF370EDFE970745 ] hotcore3 C:\Windows\system32\DRIVERS\hotcore3.sys
17:05:16.0362 2500 hotcore3 - ok
17:05:16.0472 2500 [ FCB563B0A23643E5F80B6FF1E60F610F ] hpqcxs08 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll
17:05:16.0472 2500 hpqcxs08 - ok
17:05:16.0503 2500 [ 25E443E27165C652723A92D9BDFD4649 ] hpqddsvc C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll
17:05:16.0503 2500 hpqddsvc - ok
17:05:16.0550 2500 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
17:05:16.0550 2500 HpSAMD - ok
17:05:16.0581 2500 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
17:05:16.0596 2500 HTTP - ok
17:05:16.0628 2500 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
17:05:16.0628 2500 hwpolicy - ok
17:05:16.0674 2500 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
17:05:16.0674 2500 i8042prt - ok
17:05:16.0706 2500 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
17:05:16.0908 2500 iaStorV - ok
17:05:16.0986 2500 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
17:05:16.0986 2500 idsvc - ok
17:05:17.0033 2500 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
17:05:17.0033 2500 iirsp - ok
17:05:17.0080 2500 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
17:05:17.0096 2500 IKEEXT - ok
17:05:17.0174 2500 [ 0ADF714079AE174A39D69036143E4C50 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
17:05:17.0220 2500 IntcAzAudAddService - ok
17:05:17.0236 2500 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
17:05:17.0236 2500 intelide - ok
17:05:17.0267 2500 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
17:05:17.0267 2500 intelppm - ok
17:05:17.0298 2500 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
17:05:17.0298 2500 IPBusEnum - ok
17:05:17.0314 2500 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:05:17.0314 2500 IpFilterDriver - ok
17:05:17.0345 2500 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
17:05:17.0361 2500 iphlpsvc - ok
17:05:17.0376 2500 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
17:05:17.0376 2500 IPMIDRV - ok
17:05:17.0408 2500 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
17:05:17.0408 2500 IPNAT - ok
17:05:17.0423 2500 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
17:05:17.0423 2500 IRENUM - ok
17:05:17.0454 2500 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
17:05:17.0454 2500 isapnp - ok
17:05:17.0486 2500 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
17:05:17.0486 2500 iScsiPrt - ok
17:05:17.0501 2500 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
17:05:17.0501 2500 kbdclass - ok
17:05:17.0517 2500 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
17:05:17.0517 2500 kbdhid - ok
17:05:17.0532 2500 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
17:05:17.0532 2500 KeyIso - ok
17:05:17.0564 2500 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
17:05:17.0564 2500 KSecDD - ok
17:05:17.0610 2500 [ 7EFB9333E4ECCE6AE4AE9D777D9E553E ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
17:05:17.0610 2500 KSecPkg - ok
17:05:17.0610 2500 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
17:05:17.0610 2500 ksthunk - ok
17:05:17.0673 2500 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
17:05:17.0673 2500 KtmRm - ok
17:05:17.0720 2500 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
17:05:17.0735 2500 LanmanServer - ok
17:05:17.0766 2500 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
17:05:17.0766 2500 LanmanWorkstation - ok
17:05:17.0782 2500 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
17:05:17.0782 2500 lltdio - ok
17:05:17.0829 2500 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
17:05:17.0844 2500 lltdsvc - ok
17:05:17.0860 2500 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
17:05:17.0860 2500 lmhosts - ok
17:05:17.0922 2500 [ 7109163D8027076D2680CFC4E80E2A28 ] LMIGuardianSvc C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
17:05:17.0922 2500 LMIGuardianSvc - ok
17:05:17.0938 2500 [ 0317335B15FF3BDA8E10197E3434CFC0 ] LMIInfo C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys
17:05:17.0938 2500 LMIInfo - ok
17:05:17.0985 2500 [ 8054CE1FC8B417691960D00F931516A7 ] LMIMaint C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
17:05:17.0985 2500 LMIMaint - ok
17:05:18.0000 2500 [ 413ECDCFAD9A82804D3674C8D7EEC24E ] lmimirr C:\Windows\system32\DRIVERS\lmimirr.sys
17:05:18.0016 2500 lmimirr - ok
17:05:18.0016 2500 LMIRfsClientNP - ok
17:05:18.0047 2500 [ C57D3FAA50E6F395759FFB7C709BD944 ] LMIRfsDriver C:\Windows\system32\drivers\LMIRfsDriver.sys
17:05:18.0047 2500 LMIRfsDriver - ok
17:05:18.0094 2500 [ D3760BC17E1755091B7120CF32DBF56B ] LogMeIn C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
17:05:18.0094 2500 LogMeIn - ok
17:05:18.0125 2500 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
17:05:18.0125 2500 LSI_FC - ok
17:05:18.0156 2500 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
17:05:18.0156 2500 LSI_SAS - ok
17:05:18.0172 2500 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
17:05:18.0172 2500 LSI_SAS2 - ok
17:05:18.0188 2500 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
17:05:18.0188 2500 LSI_SCSI - ok
17:05:18.0250 2500 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
17:05:18.0250 2500 luafv - ok
17:05:18.0281 2500 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
17:05:18.0281 2500 megasas - ok
17:05:18.0312 2500 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
17:05:18.0312 2500 MegaSR - ok
17:05:18.0312 2500 MEMSWEEP2 - ok
17:05:18.0344 2500 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
17:05:18.0344 2500 MMCSS - ok
17:05:18.0359 2500 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
17:05:18.0359 2500 Modem - ok
17:05:18.0406 2500 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
17:05:18.0406 2500 monitor - ok
17:05:18.0453 2500 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\drivers\mouclass.sys
17:05:18.0453 2500 mouclass - ok
17:05:18.0484 2500 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
17:05:18.0484 2500 mouhid - ok
17:05:18.0515 2500 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
17:05:18.0515 2500 mountmgr - ok
17:05:18.0562 2500 [ 05BF204EC0E82CC4A054DB189C8A3D84 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
17:05:18.0578 2500 MpFilter - ok
17:05:18.0609 2500 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
17:05:18.0609 2500 mpio - ok
17:05:18.0624 2500 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
17:05:18.0624 2500 mpsdrv - ok
17:05:18.0687 2500 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
17:05:18.0687 2500 MpsSvc - ok
17:05:18.0749 2500 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
17:05:18.0749 2500 MRxDAV - ok
17:05:18.0780 2500 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
17:05:18.0780 2500 mrxsmb - ok
17:05:18.0827 2500 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:05:18.0827 2500 mrxsmb10 - ok
17:05:18.0843 2500 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:05:18.0843 2500 mrxsmb20 - ok
17:05:18.0874 2500 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
17:05:18.0874 2500 msahci - ok
17:05:18.0890 2500 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
17:05:18.0890 2500 msdsm - ok
17:05:18.0936 2500 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
17:05:18.0952 2500 MSDTC - ok
17:05:18.0983 2500 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
17:05:18.0983 2500 Msfs - ok
17:05:18.0999 2500 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
17:05:18.0999 2500 mshidkmdf - ok
17:05:19.0030 2500 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
17:05:19.0030 2500 msisadrv - ok
17:05:19.0077 2500 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
17:05:19.0077 2500 MSiSCSI - ok
17:05:19.0092 2500 msiserver - ok
17:05:19.0108 2500 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
17:05:19.0108 2500 MSKSSRV - ok
17:05:19.0170 2500 [ CC8E4F72F21340A4D3A3D4DB50313EF5 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe
17:05:19.0170 2500 MsMpSvc - ok
17:05:19.0186 2500 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
17:05:19.0186 2500 MSPCLOCK - ok
17:05:19.0202 2500 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
17:05:19.0202 2500 MSPQM - ok
17:05:19.0233 2500 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
17:05:19.0233 2500 MsRPC - ok
17:05:19.0248 2500 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
17:05:19.0248 2500 mssmbios - ok
17:05:19.0264 2500 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
17:05:19.0264 2500 MSTEE - ok
17:05:19.0280 2500 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
17:05:19.0280 2500 MTConfig - ok
17:05:19.0295 2500 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
17:05:19.0295 2500 Mup - ok
17:05:19.0342 2500 [ 6FFECC25B39DC7652A0CEC0ADA9DB589 ] mwlPSDFilter C:\Windows\system32\DRIVERS\mwlPSDFilter.sys
17:05:19.0342 2500 mwlPSDFilter - ok
17:05:19.0358 2500 [ 0BEFE32CA56D6EE89D58175725596A85 ] mwlPSDNServ C:\Windows\system32\DRIVERS\mwlPSDNServ.sys
17:05:19.0358 2500 mwlPSDNServ - ok
17:05:19.0373 2500 [ D43BC633B8660463E446E28E14A51262 ] mwlPSDVDisk C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys
17:05:19.0373 2500 mwlPSDVDisk - ok
17:05:19.0404 2500 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
17:05:19.0420 2500 napagent - ok
17:05:19.0451 2500 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
17:05:19.0451 2500 NativeWifiP - ok
17:05:19.0545 2500 [ 9D1CCE440552500DED3A62F9D779CDB4 ] NAUpdate C:\Program Files (x86)\Nero\Update\NASvc.exe
17:05:19.0545 2500 NAUpdate - ok
17:05:19.0576 2500 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
17:05:19.0592 2500 NDIS - ok
17:05:19.0623 2500 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
17:05:19.0623 2500 NdisCap - ok
17:05:19.0654 2500 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
17:05:19.0654 2500 NdisTapi - ok
17:05:19.0685 2500 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
17:05:19.0685 2500 Ndisuio - ok
17:05:19.0716 2500 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
17:05:19.0716 2500 NdisWan - ok
17:05:19.0748 2500 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
17:05:19.0748 2500 NDProxy - ok
17:05:19.0966 2500 [ 59267D2F0328599AA3B5408C2E06126F ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
17:05:19.0966 2500 Net Driver HPZ12 - ok
17:05:19.0982 2500 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
17:05:19.0982 2500 NetBIOS - ok
17:05:20.0028 2500 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
17:05:20.0028 2500 NetBT - ok
17:05:20.0044 2500 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
17:05:20.0044 2500 Netlogon - ok
17:05:20.0075 2500 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
17:05:20.0075 2500 Netman - ok
17:05:20.0138 2500 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:05:20.0184 2500 NetMsmqActivator - ok
17:05:20.0200 2500 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:05:20.0200 2500 NetPipeActivator - ok
17:05:20.0231 2500 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
17:05:20.0231 2500 netprofm - ok
17:05:20.0247 2500 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:05:20.0247 2500 NetTcpActivator - ok
17:05:20.0247 2500 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:05:20.0247 2500 NetTcpPortSharing - ok
17:05:20.0278 2500 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
17:05:20.0278 2500 nfrd960 - ok
17:05:20.0325 2500 [ 5FF89F20317309D28AC1EDEB0CD1BA72 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
17:05:20.0325 2500 NisDrv - ok
17:05:20.0356 2500 [ 79E80B10FE8F6662E0C9162A68C43444 ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe
17:05:20.0356 2500 NisSrv - ok
17:05:20.0387 2500 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
17:05:20.0387 2500 NlaSvc - ok
17:05:20.0418 2500 [ 3CEEE0BE85D24D911B9C02714817774C ] NPF C:\Windows\system32\drivers\npf.sys
17:05:20.0418 2500 NPF - ok
17:05:20.0465 2500 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
17:05:20.0465 2500 Npfs - ok
17:05:20.0496 2500 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
17:05:20.0496 2500 nsi - ok
17:05:20.0512 2500 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
17:05:20.0512 2500 nsiproxy - ok
17:05:20.0543 2500 [ C04F5DEF37E55F6A34428B050F44D3D6 ] nSvcIp C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
17:05:20.0543 2500 nSvcIp - ok
17:05:20.0606 2500 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
17:05:20.0621 2500 Ntfs - ok
17:05:20.0684 2500 [ BD691091AC7D9713D8F0B07C6B099E6C ] NTI IScheduleSvc C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
17:05:20.0684 2500 NTI IScheduleSvc - ok
17:05:20.0684 2500 [ 64DDD0DEE976302F4BD93E5EFCC2F013 ] NTIDrvr C:\Windows\system32\drivers\NTIDrvr.sys
17:05:20.0699 2500 NTIDrvr - ok
17:05:20.0699 2500 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
17:05:20.0699 2500 Null - ok
17:05:20.0730 2500 [ A85B4F2EF3A7304A5399EF0526423040 ] NVENETFD C:\Windows\system32\DRIVERS\nvm62x64.sys
17:05:20.0746 2500 NVENETFD - ok
17:05:20.0793 2500 [ 1F07B814C0BB5AABA703ABFF1F31F2E8 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys
17:05:20.0793 2500 NVHDA - ok
17:05:21.0011 2500 [ 5104BAC2DA2A5BDD86AC6B0708B00F06 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
17:05:21.0198 2500 nvlddmkm - ok
17:05:21.0261 2500 [ 0AD267A4674805B61A5D7B911D2A978A ] NVNET C:\Windows\system32\DRIVERS\nvmf6264.sys
17:05:21.0261 2500 NVNET - ok
17:05:21.0308 2500 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
17:05:21.0308 2500 nvraid - ok
17:05:21.0323 2500 [ E58D81FB8616D0CB55C1E36AA0B213C9 ] nvsmu C:\Windows\system32\DRIVERS\nvsmu.sys
17:05:21.0323 2500 nvsmu - ok
17:05:21.0354 2500 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
17:05:21.0354 2500 nvstor - ok
17:05:21.0401 2500 [ 1E45F96342429D63DC30E0D9117DA3D8 ] nvstor64 C:\Windows\system32\DRIVERS\nvstor64.sys
17:05:21.0401 2500 nvstor64 - ok
17:05:21.0448 2500 [ DDFAFCE89A5C93D04712B86F94E9FCBA ] nvsvc C:\Windows\system32\nvvsvc.exe
17:05:21.0464 2500 nvsvc - ok
17:05:21.0557 2500 [ 84E035225474E48CD3A6A3CE52332095 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
17:05:21.0588 2500 nvUpdatusService - ok
17:05:21.0620 2500 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
17:05:21.0620 2500 nv_agp - ok
17:05:21.0651 2500 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
17:05:21.0651 2500 ohci1394 - ok
17:05:21.0698 2500 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
17:05:21.0698 2500 p2pimsvc - ok
17:05:33.0195 2500 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
17:05:33.0195 2500 p2psvc - ok
17:05:38.0920 2500 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
17:05:38.0920 2500 Parport - ok
17:05:44.0614 2500 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
17:05:44.0614 2500 partmgr - ok
17:05:50.0308 2500 [ 8A0F8A9580D9F2FC512A35D5709088A9 ] pavboot C:\Windows\system32\drivers\pavboot64.sys
17:05:50.0308 2500 pavboot - ok
17:05:56.0033 2500 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
17:05:56.0033 2500 PcaSvc - ok
17:06:04.0613 2500 [ C10B593E2DEAA3B78A865DB539FDAE6C ] PCGenFam C:\Windows\system32\DRIVERS\PCGenFAM.sys
17:06:04.0613 2500 PCGenFam - ok
17:06:13.0006 2500 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
17:06:13.0006 2500 pci - ok
17:06:15.0908 2500 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
17:06:15.0908 2500 pciide - ok
17:06:24.0394 2500 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
17:06:24.0394 2500 pcmcia - ok
17:06:36.0125 2500 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
17:06:36.0125 2500 pcw - ok
17:06:50.0555 2500 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
17:06:50.0555 2500 PEAUTH - ok
17:07:05.0672 2500 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
17:07:05.0672 2500 PerfHost - ok
17:07:05.0812 2500 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
17:07:05.0843 2500 pla - ok
17:07:05.0890 2500 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
17:07:05.0890 2500 PlugPlay - ok
17:07:05.0952 2500 [ 5261A2FD55183AC6993145AB6662CDDF ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
17:07:05.0952 2500 Pml Driver HPZ12 - ok
17:07:05.0984 2500 [ A010F13D27C1033A8BE09D5FA9BF348B ] pneteth C:\Windows\system32\DRIVERS\pneteth.sys
17:07:05.0984 2500 pneteth - ok
17:07:06.0015 2500 PnkBstrA - ok
17:07:06.0030 2500 PnkBstrB - ok
17:07:06.0046 2500 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
17:07:06.0046 2500 PNRPAutoReg - ok
17:07:06.0093 2500 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
17:07:06.0093 2500 PNRPsvc - ok
17:07:06.0171 2500 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
17:07:06.0171 2500 PolicyAgent - ok
17:07:06.0218 2500 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
17:07:06.0218 2500 Power - ok
17:07:06.0249 2500 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
17:07:06.0249 2500 PptpMiniport - ok
17:07:06.0296 2500 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
17:07:06.0296 2500 Processor - ok
17:07:06.0327 2500 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
17:07:06.0342 2500 ProfSvc - ok
17:07:06.0358 2500 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
17:07:06.0358 2500 ProtectedStorage - ok
17:07:06.0405 2500 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
17:07:06.0405 2500 Psched - ok
17:07:06.0530 2500 [ FB46E9A827A8799EBD7BFA9128C91F37 ] PSI C:\Windows\system32\DRIVERS\psi_mf.sys
17:07:06.0530 2500 PSI - ok
17:07:06.0561 2500 [ DA3964D8FB8798DC741ABACA9ED1B99D ] pwdrvio C:\Windows\system32\pwdrvio.sys
17:07:06.0576 2500 pwdrvio - ok
17:07:06.0654 2500 [ A55ED5A63D0178A41EA05AC50A60F89A ] pwdspio C:\Windows\system32\pwdspio.sys
17:07:06.0654 2500 pwdspio - ok
17:07:06.0857 2500 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
17:07:06.0873 2500 ql2300 - ok
17:07:06.0920 2500 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
17:07:06.0920 2500 ql40xx - ok
17:07:06.0998 2500 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
17:07:07.0013 2500 QWAVE - ok
17:07:07.0013 2500 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
17:07:07.0013 2500 QWAVEdrv - ok
17:07:07.0044 2500 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
17:07:07.0060 2500 RasAcd - ok
17:07:07.0310 2500 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
17:07:07.0310 2500 RasAgileVpn - ok
17:07:07.0325 2500 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
17:07:07.0325 2500 RasAuto - ok
17:07:07.0388 2500 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
17:07:07.0388 2500 Rasl2tp - ok
17:07:07.0450 2500 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
17:07:07.0450 2500 RasMan - ok
17:07:07.0466 2500 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
17:07:07.0466 2500 RasPppoe - ok
17:07:07.0481 2500 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
17:07:07.0481 2500 RasSstp - ok
17:07:07.0528 2500 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
17:07:07.0528 2500 rdbss - ok
17:07:07.0544 2500 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
17:07:07.0544 2500 rdpbus - ok
17:07:07.0559 2500 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
17:07:07.0559 2500 RDPCDD - ok
17:07:07.0575 2500 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
17:07:07.0575 2500 RDPENCDD - ok
17:07:07.0590 2500 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
17:07:07.0590 2500 RDPREFMP - ok
17:07:07.0653 2500 [ 313F68E1A3E6345A4F47A36B07062F34 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
17:07:07.0653 2500 RdpVideoMiniport - ok
17:07:07.0684 2500 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
17:07:07.0684 2500 RDPWD - ok
17:07:07.0731 2500 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
17:07:07.0731 2500 rdyboost - ok
17:07:07.0762 2500 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
17:07:07.0762 2500 RemoteAccess - ok
17:07:07.0809 2500 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
17:07:07.0809 2500 RemoteRegistry - ok
17:07:07.0840 2500 [ 7B04C9843921AB1F695FB395422C5360 ] RimUsb C:\Windows\system32\Drivers\RimUsb_AMD64.sys
17:07:07.0840 2500 RimUsb - ok
17:07:07.0871 2500 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
17:07:07.0871 2500 RpcEptMapper - ok
17:07:07.0887 2500 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
17:07:07.0887 2500 RpcLocator - ok
17:07:07.0949 2500 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\System32\rpcss.dll
17:07:07.0949 2500 RpcSs - ok
17:07:07.0965 2500 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
17:07:07.0965 2500 rspndr - ok
17:07:08.0012 2500 [ 08D41F2633FC330749ABA842259483F8 ] SaiKF622 C:\Windows\system32\DRIVERS\SaiKF622.sys
17:07:08.0012 2500 SaiKF622 - ok
17:07:08.0043 2500 [ 296D0CC623EEB6D2B9800AD421F9116A ] SaiMini C:\Windows\system32\DRIVERS\SaiMini.sys
17:07:08.0043 2500 SaiMini - ok
17:07:08.0090 2500 [ 6A77D63B566DF14DA0E7DD0D2C594EF7 ] SaiNtBus C:\Windows\system32\drivers\SaiBus.sys
17:07:08.0090 2500 SaiNtBus - ok
17:07:08.0105 2500 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
17:07:08.0105 2500 SamSs - ok
17:07:08.0183 2500 [ 3289766038DB2CB14D07DC84392138D5 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
17:07:08.0183 2500 SASDIFSV - ok
17:07:08.0183 2500 [ 58A38E75F3316A83C23DF6173D41F2B5 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
17:07:08.0199 2500 SASKUTIL - ok
17:07:08.0261 2500 [ 554CB4C2E076CC0960D9E5590E4C7FA5 ] SbieDrv C:\Program Files\Sandboxie\SbieDrv.sys
17:07:08.0261 2500 SbieDrv - ok
17:07:08.0308 2500 [ 1BCC17921C3067CE5A6E480F3DAA6378 ] SbieSvc C:\Program Files\Sandboxie\SbieSvc.exe
17:07:08.0308 2500 SbieSvc - ok
17:07:08.0339 2500 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
17:07:08.0339 2500 sbp2port - ok
17:07:08.0386 2500 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
17:07:08.0386 2500 SCardSvr - ok
17:07:08.0417 2500 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
17:07:08.0417 2500 scfilter - ok
17:07:08.0464 2500 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
17:07:08.0480 2500 Schedule - ok
17:07:08.0526 2500 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
17:07:08.0526 2500 SCPolicySvc - ok
17:07:08.0558 2500 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
17:07:08.0558 2500 SDRSVC - ok
17:07:08.0589 2500 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
17:07:08.0589 2500 secdrv - ok
17:07:08.0620 2500 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
17:07:08.0620 2500 seclogon - ok
17:07:08.0698 2500 [ 5B66DB4877BBAC9F7493AA8D84421E49 ] Secunia PSI Agent C:\Program Files (x86)\Secunia\PSI\PSIA.exe
17:07:08.0714 2500 Secunia PSI Agent - ok
17:07:08.0948 2500 [ 0E88FDF474F2CDD370A4A6CE77D018F0 ] Secunia Update Agent C:\Program Files (x86)\Secunia\PSI\sua.exe
17:07:08.0963 2500 Secunia Update Agent - ok
17:07:08.0994 2500 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
17:07:08.0994 2500 SENS - ok
17:07:09.0026 2500 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
17:07:09.0026 2500 SensrSvc - ok
17:07:09.0041 2500 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
17:07:09.0041 2500 Serenum - ok
17:07:09.0057 2500 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
17:07:09.0057 2500 Serial - ok
17:07:09.0088 2500 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
17:07:09.0088 2500 sermouse - ok
17:07:09.0119 2500 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
17:07:09.0119 2500 SessionEnv - ok
17:07:09.0150 2500 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
17:07:09.0150 2500 sffdisk - ok
17:07:09.0150 2500 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
17:07:09.0166 2500 sffp_mmc - ok
17:07:09.0182 2500 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
17:07:09.0182 2500 sffp_sd - ok
17:07:09.0197 2500 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
17:07:09.0197 2500 sfloppy - ok
17:07:09.0244 2500 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
17:07:09.0244 2500 SharedAccess - ok
17:07:09.0291 2500 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:07:09.0306 2500 ShellHWDetection - ok
17:07:09.0306 2500 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
17:07:09.0306 2500 SiSRaid2 - ok
17:07:09.0322 2500 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
17:07:09.0322 2500 SiSRaid4 - ok
17:07:09.0369 2500 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
17:07:09.0369 2500 Smb - ok
17:07:09.0400 2500 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
17:07:09.0400 2500 SNMPTRAP - ok
17:07:09.0447 2500 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
17:07:09.0447 2500 spldr - ok
17:07:09.0509 2500 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
17:07:09.0509 2500 Spooler - ok
17:07:09.0603 2500 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
17:07:09.0650 2500 sppsvc - ok
17:07:09.0681 2500 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
17:07:09.0681 2500 sppuinotify - ok
17:07:09.0774 2500 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
17:07:09.0774 2500 srv - ok
17:07:09.0821 2500 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
17:07:09.0821 2500 srv2 - ok
17:07:09.0837 2500 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
17:07:09.0837 2500 srvnet - ok
17:07:09.0884 2500 [ 8F8324ED1DE63FFC7B1A02CD2D963C72 ] ssadbus C:\Windows\system32\DRIVERS\ssadbus.sys
17:07:09.0884 2500 ssadbus - ok
17:07:09.0915 2500 [ 58221EFCB74167B73667F0024C661CE0 ] ssadmdfl C:\Windows\system32\DRIVERS\ssadmdfl.sys
17:07:09.0915 2500 ssadmdfl - ok
17:07:09.0946 2500 [ 4DA7C71BFAC5AD71255B7E4CAB980163 ] ssadmdm C:\Windows\system32\DRIVERS\ssadmdm.sys
17:07:09.0946 2500 ssadmdm - ok
17:07:09.0977 2500 [ D33D1BD3EC0E766211A234F56A12726D ] ssadserd C:\Windows\system32\DRIVERS\ssadserd.sys
17:07:09.0977 2500 ssadserd - ok
17:07:10.0024 2500 [ ED161B91FDF7EAA39469D72D463D5F4E ] sscdbus C:\Windows\system32\DRIVERS\sscdbus.sys
17:07:10.0040 2500 sscdbus - ok
17:07:10.0086 2500 [ 4CB09E77593DBD8D7AF33B37375CA715 ] sscdmdfl C:\Windows\system32\DRIVERS\sscdmdfl.sys
17:07:10.0086 2500 sscdmdfl - ok
17:07:10.0133 2500 [ C7B4CF53497A6E5363F3439427663882 ] sscdmdm C:\Windows\system32\DRIVERS\sscdmdm.sys
17:07:10.0133 2500 sscdmdm - ok
17:07:10.0180 2500 [ 05FFA552F578E27AB2D41B6828DB477F ] sscdserd C:\Windows\system32\DRIVERS\sscdserd.sys
17:07:10.0180 2500 sscdserd - ok
17:07:10.0211 2500 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
17:07:10.0211 2500 SSDPSRV - ok
17:07:10.0242 2500 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
17:07:10.0242 2500 SstpSvc - ok
17:07:10.0289 2500 Steam Client Service - ok
17:07:10.0492 2500 [ F0359F7CE712D69ACEF0886BDB4792ED ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
17:07:10.0492 2500 Stereo Service - ok
17:07:10.0554 2500 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
17:07:10.0554 2500 stexstor - ok
17:07:10.0742 2500 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
17:07:10.0742 2500 stisvc - ok
17:07:10.0773 2500 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
17:07:10.0773 2500 swenum - ok
17:07:10.0835 2500 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
17:07:10.0835 2500 swprv - ok
17:07:10.0913 2500 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
17:07:10.0944 2500 SysMain - ok
17:07:10.0991 2500 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:07:10.0991 2500 TabletInputService - ok
17:07:11.0007 2500 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
17:07:11.0007 2500 TapiSrv - ok
17:07:11.0022 2500 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
17:07:11.0022 2500 TBS - ok
17:07:11.0100 2500 [ 37608401DFDB388CAF66917F6B2D6FB0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
17:07:11.0132 2500 Tcpip - ok
17:07:11.0178 2500 [ 37608401DFDB388CAF66917F6B2D6FB0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
17:07:11.0194 2500 TCPIP6 - ok
17:07:11.0225 2500 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
17:07:11.0225 2500 tcpipreg - ok
17:07:11.0256 2500 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
17:07:11.0272 2500 TDPIPE - ok
17:07:11.0303 2500 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
17:07:11.0303 2500 TDTCP - ok
17:07:11.0366 2500 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
17:07:11.0366 2500 tdx - ok
17:07:11.0412 2500 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
17:07:11.0412 2500 TermDD - ok
17:07:11.0459 2500 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
17:07:11.0459 2500 TermService - ok
17:07:11.0475 2500 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
17:07:11.0475 2500 Themes - ok
17:07:11.0537 2500 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
17:07:11.0537 2500 THREADORDER - ok
17:07:11.0553 2500 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
17:07:11.0553 2500 TrkWks - ok
17:07:11.0615 2500 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:07:11.0615 2500 TrustedInstaller - ok
17:07:11.0631 2500 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
17:07:11.0631 2500 tssecsrv - ok
17:07:11.0709 2500 [ 17C6B51CBCCDED95B3CC14E22791F85E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
17:07:11.0709 2500 TsUsbFlt - ok
17:07:11.0740 2500 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
17:07:11.0740 2500 tunnel - ok
17:07:11.0771 2500 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
17:07:11.0771 2500 uagp35 - ok
17:07:11.0787 2500 [ 2E22C1FD397A5A9FFEF55E9D1FC96C00 ] UBHelper C:\Windows\system32\drivers\UBHelper.sys
17:07:11.0787 2500 UBHelper - ok
17:07:11.0849 2500 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
17:07:11.0849 2500 udfs - ok
17:07:11.0880 2500 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
17:07:11.0880 2500 UI0Detect - ok
17:07:11.0896 2500 [ 49B13845F0DBE39B47FC91DC46B2170A ] UimBus C:\Windows\system32\DRIVERS\uimx64.sys
17:07:11.0896 2500 UimBus - ok
17:07:11.0927 2500 [ DD46BEC773C011EAA5E502C43A73A1CC ] Uim_IM C:\Windows\system32\Drivers\Uim_IMx64.sys
17:07:11.0943 2500 Uim_IM - ok
17:07:11.0974 2500 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
17:07:11.0974 2500 uliagpkx - ok
17:07:12.0005 2500 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys
17:07:12.0005 2500 umbus - ok
17:07:12.0021 2500 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
17:07:12.0021 2500 UmPass - ok
17:07:12.0083 2500 [ 70DDE3A86DBEB1D6C3C30AD687B1877A ] Updater Service C:\Program Files\Acer\Acer Updater\UpdaterService.exe
17:07:12.0083 2500 Updater Service - ok
17:07:12.0130 2500 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
17:07:12.0130 2500 upnphost - ok
17:07:12.0161 2500 [ 5FCC71487888589A9244AF54CFEFAB29 ] usbbus C:\Windows\system32\DRIVERS\lgx64bus.sys
17:07:12.0161 2500 usbbus - ok
17:07:12.0192 2500 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
17:07:12.0192 2500 usbccgp - ok
17:07:12.0224 2500 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
17:07:12.0224 2500 usbcir - ok
17:07:12.0270 2500 [ 3FB6E423F7567C92C32EA786F5FD0C69 ] UsbDiag C:\Windows\system32\DRIVERS\lgx64diag.sys
17:07:12.0270 2500 UsbDiag - ok
17:07:12.0286 2500 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
17:07:12.0286 2500 usbehci - ok
17:07:12.0317 2500 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
17:07:12.0317 2500 usbhub - ok
17:07:12.0348 2500 [ 78D551F5B93488B4666F5FC8DD4815F3 ] USBModem C:\Windows\system32\DRIVERS\lgx64modem.sys
17:07:12.0348 2500 USBModem - ok
17:07:12.0380 2500 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
17:07:12.0380 2500 usbohci - ok
17:07:12.0426 2500 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
17:07:12.0426 2500 usbprint - ok
17:07:12.0473 2500 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
17:07:12.0473 2500 usbscan - ok
17:07:12.0504 2500 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:07:12.0504 2500 USBSTOR - ok
17:07:12.0567 2500 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
17:07:12.0567 2500 usbuhci - ok
17:07:12.0614 2500 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
17:07:12.0614 2500 UxSms - ok
17:07:12.0801 2500 [ 81A9F455BF2C9180348949F7C8D93E66 ] VaneFltr C:\Windows\system32\drivers\Lachesis.sys
17:07:12.0801 2500 VaneFltr - ok
17:07:12.0816 2500 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
17:07:12.0816 2500 VaultSvc - ok
17:07:12.0848 2500 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
17:07:12.0848 2500 vdrvroot - ok
17:07:12.0879 2500 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
17:07:12.0879 2500 vds - ok
17:07:12.0941 2500 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
17:07:12.0941 2500 vga - ok
17:07:12.0957 2500 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
17:07:12.0957 2500 VgaSave - ok
17:07:13.0004 2500 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
17:07:13.0004 2500 vhdmp - ok
17:07:13.0035 2500 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
17:07:13.0035 2500 viaide - ok
17:07:13.0050 2500 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
17:07:13.0050 2500 volmgr - ok
17:07:13.0113 2500 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
17:07:13.0113 2500 volmgrx - ok
17:07:13.0128 2500 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
17:07:13.0128 2500 volsnap - ok
17:07:13.0160 2500 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
17:07:13.0160 2500 vsmraid - ok
17:07:13.0206 2500 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
17:07:13.0238 2500 VSS - ok
17:07:13.0253 2500 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
17:07:13.0269 2500 vwifibus - ok
17:07:13.0300 2500 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
17:07:13.0300 2500 W32Time - ok
17:07:13.0316 2500 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
17:07:13.0316 2500 WacomPen - ok
17:07:13.0347 2500 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
17:07:13.0347 2500 WANARP - ok
17:07:13.0347 2500 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
17:07:13.0347 2500 Wanarpv6 - ok
17:07:13.0409 2500 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
17:07:13.0425 2500 WatAdminSvc - ok
17:07:13.0487 2500 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
17:07:13.0503 2500 wbengine - ok
17:07:13.0534 2500 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
17:07:13.0534 2500 WbioSrvc - ok
17:07:13.0581 2500 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
17:07:13.0596 2500 wcncsvc - ok
17:07:13.0612 2500 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:07:13.0612 2500 WcsPlugInService - ok
17:07:13.0628 2500 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
17:07:13.0628 2500 Wd - ok
17:07:13.0674 2500 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
17:07:13.0674 2500 Wdf01000 - ok
17:07:13.0690 2500 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
17:07:13.0690 2500 WdiServiceHost - ok
17:07:13.0706 2500 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
17:07:13.0706 2500 WdiSystemHost - ok
17:07:13.0737 2500 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
17:07:13.0737 2500 WebClient - ok
17:07:13.0768 2500 [ D5BA7D43FA2EF656BF7E98A188391E40 ] Wecsvc C:\Windows\system32\wecsvc.dll
17:07:13.0768 2500 Wecsvc - ok
17:07:13.0784 2500 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
17:07:13.0784 2500 wercplsupport - ok
17:07:13.0799 2500 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
17:07:13.0799 2500 WerSvc - ok
17:07:13.0815 2500 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
17:07:13.0815 2500 WfpLwf - ok
17:07:13.0830 2500 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
17:07:13.0830 2500 WIMMount - ok
17:07:13.0862 2500 WinDefend - ok
17:07:13.0877 2500 WinHttpAutoProxySvc - ok
17:07:13.0955 2500 [ 136760C1E9697BAF4ECDEAE5590A0806 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
17:07:13.0955 2500 Winmgmt - ok
17:07:14.0080 2500 [ 3BB6B401A780BF434C8F58137DE10BF7 ] WinRM C:\Windows\system32\WsmSvc.dll
17:07:14.0127 2500 WinRM - ok
17:07:14.0158 2500 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
17:07:14.0158 2500 WinUsb - ok
17:07:14.0189 2500 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
17:07:14.0189 2500 Wlansvc - ok
17:07:14.0345 2500 [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
17:07:14.0376 2500 wlidsvc - ok
17:07:14.0408 2500 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
17:07:14.0408 2500 WmiAcpi - ok
17:07:14.0439 2500 [ 4DF841632B62A7CF19A79A05046A8AB1 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
17:07:14.0439 2500 wmiApSrv - ok
17:07:14.0454 2500 WMPNetworkSvc - ok
17:07:14.0486 2500 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
17:07:14.0501 2500 WPCSvc - ok
17:07:14.0517 2500 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
17:07:14.0532 2500 WPDBusEnum - ok
17:07:14.0579 2500 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
17:07:14.0579 2500 ws2ifsl - ok
17:07:14.0610 2500 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
17:07:14.0610 2500 wscsvc - ok
17:07:14.0626 2500 WSearch - ok
17:07:14.0844 2500 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
17:07:14.0938 2500 wuauserv - ok
17:07:15.0094 2500 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
17:07:15.0094 2500 WudfPf - ok
17:07:15.0141 2500 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
17:07:15.0156 2500 WUDFRd - ok
17:07:15.0203 2500 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
17:07:15.0203 2500 wudfsvc - ok
17:07:15.0234 2500 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
17:07:15.0234 2500 WwanSvc - ok
17:07:15.0281 2500 [ 2EE48CFCE7CA8E0DB4C44C7476C0943B ] xusb21 C:\Windows\system32\DRIVERS\xusb21.sys
17:07:15.0281 2500 xusb21 - ok
17:07:15.0406 2500 [ DD0042F0C3B606A6A8B92D49AFB18AD6 ] YahooAUService C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
17:07:15.0422 2500 YahooAUService - ok
17:07:15.0453 2500 ================ Scan global ===============================
17:07:15.0500 2500 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
17:07:15.0546 2500 [ 72CC564BBC70DE268784BCE91EB8A28F ] C:\Windows\system32\winsrv.dll
17:07:15.0562 2500 [ 72CC564BBC70DE268784BCE91EB8A28F ] C:\Windows\system32\winsrv.dll
17:07:15.0609 2500 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
17:07:15.0687 2500 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
17:07:15.0687 2500 [Global] - ok
17:07:15.0687 2500 ================ Scan MBR ==================================
17:07:15.0718 2500 [ 70E629B51C16B3C007730C6AE57144C9 ] \Device\Harddisk0\DR0
17:07:17.0933 2500 \Device\Harddisk0\DR0 - ok
17:07:17.0933 2500 ================ Scan VBR ==================================
17:07:17.0964 2500 [ 022497C1B7BCAD2D5CEEA13EDFA891A2 ] \Device\Harddisk0\DR0\Partition1
17:07:17.0964 2500 \Device\Harddisk0\DR0\Partition1 - ok
17:07:17.0996 2500 [ 6B5EE86C7E81C29076F016557E47BAF5 ] \Device\Harddisk0\DR0\Partition2
17:07:17.0996 2500 \Device\Harddisk0\DR0\Partition2 - ok
17:07:17.0996 2500 ============================================================
17:07:17.0996 2500 Scan finished
17:07:17.0996 2500 ============================================================
17:07:18.0011 4848 Detected object count: 0
17:07:18.0011 4848 Actual detected object count: 0
17:07:44.0344 1912 Deinitialize success
Also here is the log from Malwarebytes.

Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org

Database version: v2013.01.02.03

Windows 7 Service Pack 1 x64 NTFS (Safe Mode/Networking)
Internet Explorer 9.0.8112.16421
Zanthia :: FAMILY [administrator]

1/2/2013 1:08:40 AM
mbam-log-2013-01-02 (01-08-40).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 810621
Time elapsed: 1 hour(s), 37 minute(s), 45 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 65
HKCR\CLSID\{08fbcb5f-de4f-49e0-977e-e4269f4d7206} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{8b4c0e7e-23f4-419f-814e-957e905c31f3} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{0DB657AC-FA16-4F01-AADF-023D29F75D62} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.SettingsPlugin.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.SettingsPlugin (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08FBCB5F-DE4F-49E0-977E-E4269F4D7206} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GamingWonderlandbar Uninstall (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{44eaf1f4-7ff5-4b15-9bee-522532831236} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{6c71ddef-4c18-4fbc-aac2-d397ca175626} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{206F84B4-A5BC-448E-BB07-C091E2CA3F17} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{6fba26f4-e7c7-4db3-9276-a3312ccf07d0} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{2a5fb2eb-3559-4ad3-8d61-3cd3e8528fa6} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{2E252970-F6F6-46DA-B9A5-FEF849174D84} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{f4b1272e-0cb2-488c-9fa7-320e55fb8307} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.DynamicBarButton.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.DynamicBarButton (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{e71835ec-50b3-4409-a418-cca38afc49b1} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{1ba8c07d-d46c-444b-bf2c-577bd961d2e4} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{7975C249-952B-40B1-937F-F79986B47081} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.FeedManager.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.FeedManager (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{26A73C38-B71A-4D3A-80B7-E010420DA1E7} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.HTMLMenu.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.HTMLMenu (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{26A73C38-B71A-4D3A-80B7-E010420DA1E7} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{9634ef63-f560-4ece-b213-aee5667d7c3c} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{98840585-a9cf-477a-b7d4-81ce1fb1c2e4} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{B5923F3E-B4BC-4FB5-8318-9DFDF1BC7889} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{aa59b2d8-edd2-4730-8efb-c266e75e1168} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.MultipleButton.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.MultipleButton (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{1a30aa28-2fc6-4360-9e14-cfa627d51b6c} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{7494f5bf-10b7-4d2f-b90f-dfea50616a3e} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{5E394D6E-A48F-428C-9A87-DA32C2A57346} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.XMLSessionPlugin.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.XMLSessionPlugin (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1A30AA28-2FC6-4360-9E14-CFA627D51B6C} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{7bff5694-a950-4d01-a2fa-d5aea811d201} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{ac88eb5d-de86-4519-8b73-a4d677965b8c} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{66706B98-BBBD-4633-B2B4-1B8AD9EA8487} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.RadioSettings.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.RadioSettings (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{ed1ac743-8648-4e55-9104-a0c74baba152} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.ScriptButton.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.ScriptButton (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{0c7bac04-8f5d-4bbd-956a-34fafa547752} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{5e579db7-8e17-4137-b1e0-fd9dcb35f528} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{C2AA38BF-2179-45CB-9EF0-C9A555F4354F} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0C7BAC04-8F5D-4BBD-956A-34FAFA547752} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{ab5d199e-9659-47a2-930b-fc3b69061353} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{f4d7584b-6643-4bc7-8e24-17c3258dc5ef} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{5e302f1c-2e1f-4df7-bb17-687ccf9a8de2} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{0D49EF2C-6D09-4FE0-A26E-7301D89245C7} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.ThirdPartyInstaller.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.ThirdPartyInstaller (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F4D7584B-6643-4BC7-8E24-17C3258DC5EF} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{dd51557a-1bdc-473a-b9fd-b0d195155da8} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.UrlAlertButton.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.UrlAlertButton (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{99c8d756-4d22-4d0f-898a-34a232884ce1} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{970f08a0-2151-4f81-91d9-3c5e5c9a6861} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{1998CE9F-20C5-4EC7-80A8-0F6F8A2411E8} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.HTMLPanel.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.HTMLPanel (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{99C8D756-4D22-4D0F-898A-34A232884CE1} (PUP.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 33
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtauxstb.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtbar.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtbrmon.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtbrstub.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtdatact.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtdlghk.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtdyn.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtfeedmg.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gthighin.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gthkstub.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gthtmlmu.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gthttpct.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtidle.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtieovr.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtimpipe.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtmedint.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtmlbtn.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtmsg.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtPlugin.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtradio.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtregfft.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtreghk.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtregiet.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtscript.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtskin.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtskplay.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtSrcAs.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtSrchMn.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gttpinst.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtuabtn.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\NPgtStub.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\T8HTML.DLL (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\QPST\Scramp\Scramp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

(end)
My wifes account is not running very good either, do the fixes you require also help with other accounts?
I can understand your frustration with things getting installed on the machine without your knowledge. I can see you do your best to keep the machine clear, that is obvious from the security I can see and from the tools you have already run. Don't worry, we'll get you all sorted out on the various accounts (without any fuss at all) and I'll even help you get rid of some of the "junkware" that may have been installed along the way.

I cannot afford to buy the better antivirus and protection software out there. I use Gizmo's site for help in determining the best free tools to use for my system.

With only one exception on my own personal machines, I use ALL free security tools. I do not subscribe to the theory that paid is better. So we will be using free toos to clean your machine, and any recommendations for the future will be free tools. You don't need to worry about that at all :)

MSE and windows firewall are the only tools I currently use for protection

We'll work on the issues you've been having with them, but these are the antivirus (AV) and firewall I use. I know there has been alot of talk about MSE recently, but I still firmly believe it's one of best AV programs out there and I personally stand by it as a great option! I think in conjunction with regular scans from Malwarebytes you have a fine choice of security products on your machine.

It does appear that the full scan from Malwarebytes (MBAM) has removed quite a bit now that you've gotten it to run. It does run with Administrator privledges so it should have addressed all user accounts on your machine.

The O10 entries in your HijackThis log were fine they are from Windows Live and nothing to worry about. However, I can see some concerning items and while the tools we will run in a moment would likely take care of them, I'd like to go ahead with a quick fix in Hijack this anyway.

Run Hijack This
  • Right-click and choose Run as Administrator on the icon on your desktop to launch Hijack This
  • Click on the Scan button
  • When the scan has finished, please put a check in the box next to the following item:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.privitize.com/?aff=7
    O2 - BHO: wxDownload - {95B741CB-CF8A-6780-C5F6-FF7C39EA7BCE} - C:\ProgramData\wxDownload\50c64c701d1de.ocx
    O20 - AppInit_DLLs: c:\PROGRA~2\WXDOWN~1\SPROTE~1.DLL
  • Make sure all other windows, including your browser are closed, and then click on the Fix Checked button
If you are not prompted to do so, please reboot your computer after the fix has completed.




Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing anything, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

If you have a problem launching programs after running Combofix, please do not panic! Simply reboot the computer and all should be fine.
Hi, sorry I've been gone all day but heres the ComboFix log. I ran it this morning and the nhad to leave. When I got back I cannot log onto the internet with I.E. I had to use Chrome. When I first tried with I.E. I got a messege saying I'm about to view over a non secure connection, has this anything to do with not being able to log on with I.E.? I tried a restart and the same thing happened. Anyway heres the log from ComboFix. ComboFix 13-01-04.03 - Bryan 01/04/2013 10:59:53.11.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3839.2320 [GMT -8:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C} SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\BasicSeek c:\programdata\BasicSeek c:\programdata\BasicSeek\basicseek110.exe . . ((((((((((((((((((((((((( Files Created from 2012-12-04 to 2013-01-04 ))))))))))))))))))))))))))))))) . . 2013-01-04 07:32 . 2012-11-08 17:24 9125352 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FDF7B56D-4A36-474A-961D-693CC8662AB3}\mpengine.dll 2013-01-04 01:19 . 2013-01-04 01:19 ——– d—–w- C:\FRST 2013-01-03 18:16 . 2012-11-08 17:24 9125352 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-01-03 05:55 . 2013-01-03 05:55 ——– d—–w- c:\users\Zanthia.Family\AppData\Roaming\SUPERAntiSpyware.com 2013-01-02 22:58 . 2013-01-02 22:58 388096 —-a-r- c:\users\Bryan\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2013-01-02 21:28 . 2013-01-02 21:28 ——– d—–w- c:\program files\WOT 2013-01-02 18:17 . 2013-01-04 17:21 ——– d—–w- c:\windows\system32\%LocalAppData% 2013-01-02 08:50 . 2013-01-02 08:50 65736 —-a-w- c:\windows\system32\drivers\pxrts.sys 2013-01-02 08:50 . 2013-01-02 08:50 ——– d—–w- c:\program files\Prevx 2013-01-02 08:49 . 2013-01-02 22:24 ——– d—–w- c:\programdata\PrevxCSI 2013-01-02 06:33 . 2013-01-03 06:59 ——– d—–w- c:\windows\system32\catroot2 2013-01-02 01:32 . 2013-01-02 01:32 32152 —-a-w- c:\windows\system32\drivers\hitmanpro37.sys 2013-01-02 01:19 . 2013-01-02 01:19 ——– d—–w- c:\users\Betty\AppData\Roaming\Malwarebytes 2013-01-02 01:05 . 2013-01-02 01:05 208216 —-a-w- c:\windows\system32\drivers\34792715.sys 2013-01-02 00:57 . 2013-01-02 00:57 ——– d—–w- c:\programdata\VisualBee 2013-01-02 00:40 . 2013-01-02 00:40 ——– d—–w- c:\users\Administrator.Family 2013-01-02 00:11 . 2013-01-02 00:11 ——– d—–w- C:\found.003 2013-01-01 23:25 . 2013-01-01 23:25 ——– d—–w- C:\found.002 2013-01-01 21:58 . 2013-01-01 22:09 ——– d—–w- c:\users\TEMP 2012-12-31 21:24 . 2012-12-31 21:24 ——– d—–w- C:\found.001 2012-12-30 17:07 . 2012-12-30 17:07 ——– d—–w- C:\found.000 2012-12-30 17:01 . 2012-12-30 17:01 ——– d—–w- c:\users\Bryan\AppData\Local\Programs 2012-12-25 16:59 . 2012-12-25 19:37 ——– d—–w- c:\users\Bryan\AppData\Roaming\Apple Computer 2012-12-25 16:59 . 2012-12-25 16:59 ——– d—–w- c:\users\Bryan\AppData\Local\Apple Computer 2012-12-24 23:03 . 2009-06-30 18:37 33800 —-a-w- c:\windows\system32\drivers\pavboot64.sys 2012-12-24 23:02 . 2012-12-24 23:02 ——– d—–w- c:\program files (x86)\Panda Security 2012-12-24 23:02 . 2012-12-24 23:02 ——– d—–w- c:\windows\AxInstSV 2012-12-22 23:20 . 2012-12-22 23:20 ——– d—–w- c:\program files (x86)\Common Files\Simple Adblock 2012-12-22 17:01 . 2012-12-16 17:11 46080 —-a-w- c:\windows\system32\atmlib.dll 2012-12-22 17:01 . 2012-12-16 14:13 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-22 17:01 . 2012-12-16 14:45 367616 —-a-w- c:\windows\system32\atmfd.dll 2012-12-22 17:01 . 2012-12-16 14:13 295424 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-21 08:53 . 2012-12-21 08:53 ——– d—–w- c:\users\Bryan\AppData\Local\TunaMediaLtd 2012-12-21 08:53 . 2012-12-21 08:53 ——– d—–w- c:\program files (x86)\TunaMediaLtd 2012-12-21 08:52 . 2012-12-21 08:52 ——– d—–w- c:\users\Bryan\AppData\Local\Downloaded Installations 2012-12-15 08:04 . 2012-12-15 08:04 ——– d—–w- c:\users\Bryan\AppData\Roaming\SystemRequirementsLab 2012-12-15 07:14 . 2012-12-15 07:14 ——– d—–w- c:\users\Bryan\AppData\Local\4A Games 2012-12-13 20:55 . 2012-12-13 22:43 ——– d—–w- c:\users\Bryan\AppData\Local\DownTango 2012-12-13 20:55 . 2012-12-13 20:55 ——– d—–w- c:\program files (x86)\Red Sky 2012-12-12 09:54 . 2012-12-12 09:54 ——– d—–w- c:\windows\Migration 2012-12-12 09:52 . 2012-08-21 14:20 46080 —-a-w- c:\windows\SysWow64\ncobjapi.dll 2012-12-12 09:52 . 2012-08-21 13:49 58368 —-a-w- c:\windows\system32\ncobjapi.dll 2012-12-12 09:52 . 2012-08-21 13:12 74240 —-a-w- c:\windows\system32\wbem\NCProv.dll 2012-12-12 09:45 . 2012-11-14 05:52 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-12-12 09:44 . 2012-11-14 06:04 1392128 —-a-w- c:\windows\system32\wininet.dll 2012-12-12 09:41 . 2012-11-09 05:45 2048 —-a-w- c:\windows\system32\tzres.dll 2012-12-12 09:41 . 2012-11-09 04:42 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2012-12-12 09:38 . 2012-11-02 05:59 478208 —-a-w- c:\windows\system32\dpnet.dll 2012-12-12 09:38 . 2012-11-02 05:11 376832 —-a-w- c:\windows\SysWow64\dpnet.dll 2012-12-12 09:06 . 2012-12-12 09:06 77 —-a-w- C:\prefs.js 2012-12-12 06:40 . 2012-12-12 06:40 ——– d—–w- c:\users\Zanthia.Family\AppData\Local\LogMeIn 2012-12-12 06:28 . 2012-12-12 06:28 ——– d—–w- c:\users\Betty\AppData\Local\LogMeIn 2012-12-12 06:02 . 2012-12-12 06:02 ——– d—–w- C:\e 2012-12-12 05:58 . 2013-01-02 07:55 ——– d—–w- c:\users\Bryan\AppData\Roaming\DefaultTab 2012-12-11 22:54 . 2012-12-11 22:54 ——– d—–w- c:\users\Bryan\AppData\Local\LogMeIn 2012-12-11 22:54 . 2012-10-20 02:10 60328 —-a-w- c:\windows\system32\Spool\prtprocs\x64\LMIproc.dll 2012-12-11 22:54 . 2012-10-20 02:10 35240 —-a-w- c:\windows\system32\LMIport.dll 2012-12-11 22:54 . 2012-10-20 02:11 88008 —-a-w- c:\windows\system32\LMIRfsClientNP.dll 2012-12-11 22:54 . 2012-08-24 22:41 72216 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys 2012-12-11 22:54 . 2012-10-20 02:10 83880 —-a-w- c:\windows\system32\LMIinit.dll 2012-12-11 22:54 . 2012-12-18 21:15 ——– d—–w- c:\programdata\LogMeIn 2012-12-11 22:54 . 2012-12-11 22:54 ——– d—–w- c:\program files (x86)\LogMeIn 2012-12-11 22:52 . 2012-12-11 22:52 ——– d—–w- c:\users\Bryan\AppData\Local\Deployment 2012-12-10 21:14 . 2012-12-10 21:14 ——– d—–w- c:\users\Bryan\AppData\Local\PutLockerDownloader 2012-12-10 20:40 . 2012-12-10 20:40 ——– d—–w- c:\program files (x86)\wxDownload Fast 2012-12-10 20:40 . 2012-12-12 09:31 ——– d—–w- c:\users\Bryan\AppData\Local\SwvUpdater 2012-12-10 20:39 . 2012-12-10 20:39 ——– d—–w- c:\program files (x86)\Conduit 2012-12-10 20:39 . 2012-12-10 23:59 ——– d—–w- c:\users\Bryan\AppData\Local\Conduit 2012-12-10 20:39 . 2012-12-10 20:40 ——– d—–w- c:\programdata\Premium 2012-12-10 20:38 . 2012-12-10 20:39 ——– d—–w- c:\program files (x86)\WxDownload 2012-12-10 20:38 . 2013-01-04 18:45 ——– d—–w- c:\programdata\wxDownload 2012-12-10 20:36 . 2012-12-12 09:06 ——– d—–w- c:\programdata\InstallMate 2012-12-08 08:22 . 2012-12-08 08:22 ——– d—–w- c:\program files (x86)\Gophoto.it . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-01-02 06:23 . 2012-11-26 20:16 181064 —-a-w- c:\windows\PSEXESVC.EXE 2012-12-15 00:49 . 2012-09-19 15:27 24176 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-12-12 09:29 . 2012-04-13 22:07 697272 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-12-12 09:29 . 2011-11-07 17:34 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-11-28 23:58 . 2010-05-03 07:57 67413224 —-a-w- c:\windows\system32\MRT.exe 2012-11-28 20:58 . 2012-11-28 20:58 972264 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2D6959E6-5002-4EB6-9262-45F89279A03E}\gapaengine.dll 2012-11-26 22:43 . 2012-11-28 20:58 972192 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2012-11-08 17:24 . 2012-11-25 00:41 9125352 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F82B904F-663A-4D41-AFCA-F49ACDF967A6}\mpengine.dll 2012-10-30 23:51 . 2012-11-16 10:05 41224 —-a-w- c:\windows\avastSS.scr 2012-10-30 23:50 . 2012-11-16 10:05 227648 —-a-w- c:\windows\SysWow64\aswBoot.exe 2012-10-25 11:12 . 2012-10-25 11:12 94208 —-a-w- c:\windows\SysWow64\QuickTimeVR.qtx 2012-10-25 11:12 . 2012-10-25 11:12 69632 —-a-w- c:\windows\SysWow64\QuickTime.qts 2012-10-23 15:39 . 2012-10-23 15:40 108008 —-a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2012-10-23 15:39 . 2011-12-22 23:57 1034216 —-a-w- c:\windows\system32\npdeployJava1.dll 2012-10-23 15:39 . 2010-07-26 21:02 916456 —-a-w- c:\windows\system32\deployJava1.dll 2012-10-16 08:38 . 2012-11-27 19:27 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2012-10-16 08:38 . 2012-11-27 19:27 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2012-10-16 07:39 . 2012-11-27 19:27 561664 —-a-w- c:\windows\apppatch\AcLayers.dll 2012-10-09 18:17 . 2012-11-14 16:14 55296 —-a-w- c:\windows\system32\dhcpcsvc6.dll 2012-10-09 18:17 . 2012-11-14 16:14 226816 —-a-w- c:\windows\system32\dhcpcore6.dll 2012-10-09 17:40 . 2012-11-14 16:14 44032 —-a-w- c:\windows\SysWow64\dhcpcsvc6.dll 2012-10-09 17:40 . 2012-11-14 16:14 193536 —-a-w- c:\windows\SysWow64\dhcpcore6.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-06 39408] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2011-10-13 291896] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "EnableShellExecuteHooks"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "RequireSignedAppInit_DLLs"=0 (0x0) "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R0 hqmpym;hqmpym; [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 ALSysIO;ALSysIO;c:\users\Bryan\AppData\Local\Temp\ALSysIO64.sys [x] R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2011-05-13 36328] R3 easytether;easytether;c:\windows\system32\DRIVERS\easytthr.sys [x] R3 hitmanpro37;HitmanPro 3.7 Support Driver;c:\windows\system32\drivers\hitmanpro37.sys [2013-01-02 32152] R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\7114.tmp [x] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-08-31 128456] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-09-13 368896] R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 40464] R3 PCGenFam;PCGenFam;c:\windows\system32\DRIVERS\PCGenFAM.sys [2010-11-02 198088] R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2011-05-06 19936] R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2011-05-06 13280] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456] R3 SaiKF622;SaiKF622;c:\windows\system32\DRIVERS\SaiKF622.sys [2009-06-02 140800] R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672] R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872] R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640] R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856] R3 VaneFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2007-08-17 30336] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-03 1255736] S0 hotcore3;hc3ServiceName;c:\windows\system32\DRIVERS\hotcore3.sys [2011-01-21 37456] S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot64.sys [2009-06-30 33800] S1 GIDv2;GIDv2; [x] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 22576] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 20016] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60464] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-10-06 140672] S2 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496] S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-10-20 375728] S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2012-08-24 15928] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-08-12 62208] S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2011-10-14 994360] S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2011-10-14 399416] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824] S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160] S3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys [2011-11-25 15360] S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 17976] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{9191979D-821C-4EA8-B021-2DA1D859A7C5}-3Reg] 2011-07-05 17:26 435976 —-a-w- c:\program files (x86)\SFT\GuardedID\GIDI.exe . Contents of the 'Scheduled Tasks' folder . 2013-01-04 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 09:29] . 2013-01-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28] . 2013-01-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28] . 2013-01-04 c:\windows\Tasks\OptimizerProUpdaterTask{8E001057-D4F6-4F11-911C-836301DC943B}.job - c:\programdata\Premium\OptimizerPro\OptimizerPro.exe [2012-12-10 14:50] . 2013-01-04 c:\windows\Tasks\WpsUpdateTask_Bryan.job - c:\program files (x86)\Kingsoft\Kingsoft Office\office6\wpsupdate.exe [2012-09-17 16:00] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-07 10144288] "PLD_FrameworkRun"="c:\windows\system32\oem\_NowIntoDT.vbs" [2009-10-11 490] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-22 2327952] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-13 1289704] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://msn.com/ mLocal Page = c:\windows\SysWOW64\blank.htm mSearchAssistant = TCP: DhcpNameServer = 75.75.75.75 75.75.76.76 DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab FF - ProfilePath - . - - - - ORPHANS REMOVED - - - - . BHO-{7F6AFBF1-E065-4627-A2FD-810366367D01} - c:\users\Bryan\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll Toolbar-{a8a9d26a-734f-467a-8907-176f9c5bdf56} - (no file) ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file) ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file) ShellIconOverlayIdentifiers-{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} - (no file) AddRemove-DefaultTab - c:\users\Bryan\AppData\Roaming\DefaultTab\DefaultTab\uninstalldt.exe AddRemove-GamesBar - c:\program files (x86)\GamesBar\uninst.exe AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_heroes.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\MEMSWEEP2] "ImagePath"="\??\c:\windows\system32\7114.tmp" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*] "value"="?\03\04\16\176\1e?" . Completion time: 2013-01-04 11:11:23 ComboFix-quarantined-files.txt 2013-01-04 19:11 . Pre-Run: 607,213,539,328 bytes free Post-Run: 607,402,524,672 bytes free . - - End Of File - - 446D98BFBE3B46C89D8568CEA65AFEC5 When I try and open I.E. now it takes like 10 minutes to load, after it does load it takes forever to go to one of my favorites, basically rendering I.E. useless. How can I fix this?
The HijackThis fix I had you run removed the initial start page you had in Internet Explorer as Malwarebytes detectes that page as having malicious content.
I also had you remove two entries that were trojan downloaders. So in all liklihood, there are still some remnants we need to find that are causing IE to misbehave.
Let's have you go to Start > Control Panel > Internet Options > Connections > Click on the LAN Settings Button
Ensure that the checkbox for Automatically Detect Settings is Checked.
Thenk click OK, OK and close your Control Panel

Although I have one file I'd like to have you check online, I do have a fix I'd like you to run now that has to do with those files I already had you remove with HijackThis that I don't want to wait to remove.
Also, since your wife plays a lot of games, we are going to clear the Java Cache where infections are known to hide. You may want to let her know that some of her scores may disappear. Sorry, but it's better to be safe.

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

Folder::
c:\programdata\wxDownload
c:\program files (x86)\WxDownload

ClearJavaCache::


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe. ComboFix may request an update; please allow it.

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.




We need to get additional information about a file as it can be good or bad and we should confirm this one.

Please go to the following site:
http://www.virustotal.com/
Click on Choose File, and then upload the following file for analysis:

c:\programdata\Premium\OptimizerPro\OptimizerPro.exe

Then click Send File and allow the file to be scanned.

Please ensure the scan is complete and the results saved before submitting the next.
If a pop-up appears saying the file has been scanned already, please select the ReScan button.


Please copy and paste the links to each of the results here for me.


Here is a tool that will painless remove a large number of toolbars and potentially unwanted junkware that can get installed along with other programs. Please note your wife may not be happy after you run this but you will probably notice improvements.


[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.


Please let me know how the machine is runninge, especially Internet Explorer after all this.
I have fixed my problem with I.E. by stopping the add on from Adobe Shockwave player. It is disabled right now and as soon as it was I.E. started loading immediately. I know this is probably not a permenent solution because I'm sure I need the shockwave player for certain visual play.

The file c:\programdata\Premium\OptimizerPro\OptimizerPro.exe was no longer available to load on Virus Total. It must have been eliminated by one of the ComboFix or other scans because I can't find it even with the search tool. Other than that everything else ran fine and here are teh logs you need.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.3.8 (01.03.2013:2)
OS: Windows 7 Home Premium x64
Ran by [removed] on Sat 01/05/2013 at 9:50:21.46
Blog: http://thisisudax.blogspot.com
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] hkey_local_machine\software\conduit
Successfully deleted: [Registry Key] hkey_local_machine\software\default tab
Successfully deleted: [Registry Key] hkey_local_machine\software\freeze.com
Successfully deleted: [Registry Key] hkey_local_machine\software\iminent
Successfully deleted: [Registry Key] hkey_local_machine\software\sweetim
Successfully deleted: [Registry Key] hkey_local_machine\software\visualbee
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\conduit
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\iehelperv2.5.0.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\applications\ilividsetupv1.exe
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\iehelperv250.wecarereminder
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\iehelperv250.wecarereminder.1
Successfully deleted: [Registry Key] hkey_local_machine\software\wow6432node\microsoft\tracing\ilividsetupv1_rasapi32
Successfully deleted: [Registry Key] hkey_local_machine\software\wow6432node\microsoft\tracing\ilividsetupv1_rasmancs
Successfully deleted: [Registry Key] hkey_local_machine\software\wow6432node\sp global
Successfully deleted: [Registry Key] hkey_local_machine\software\wow6432node\sprotector
Successfully deleted: [Registry Key-Heur] HKEY_LOCAL_MACHINE\software\classes\Toolbar.CT3244149
Successfully deleted: [Registry Key-Heur] HKEY_LOCAL_MACHINE\software\classes\Toolbar.CT3268494
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{02478d38-c3f9-4efb-9b51-7695eca05670}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{3c471948-f874-49f5-b338-4f214a2ee0b1}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{7f6afbf1-e065-4627-a2fd-810366367d01}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{7f6afbf1-e065-4627-a2fd-810366367d01}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{d824f0de-3d60-4f57-9eb1-66033ecd8abb}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{d824f0de-3d60-4f57-9eb1-66033ecd8abb}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\installmate"
Successfully deleted: [Folder] "C:\ProgramData\premium"
Successfully deleted: [Folder] "C:\ProgramData\soluto"
Successfully deleted: [Folder] "C:\ProgramData\visualbee"
Successfully deleted: [Folder] "C:\Users\Bryan\appdata\local\conduit"
Successfully deleted: [Folder] "C:\Users\Bryan\appdata\local\swvupdater"
Successfully deleted: [Folder] "C:\Users\Bryan\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\Bryan\appdata\locallow\pricegong"
Successfully deleted: [Folder] "C:\Program Files (x86)\conduit"
Successfully deleted: [Folder] "C:\Program Files (x86)\gamingwonderland"



~~~ Chrome

Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\ippkomaaonokjnfjoikaemidanojkfmm



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 01/05/2013 at 9:56:40.85
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

ComboFix 13-01-05.01 - Bryan 01/05/2013 10:03:37.12.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3839.2397 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Bryan\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\WxDownload
c:\program files (x86)\WxDownload\sprotector.dll
c:\program files (x86)\WxDownload\uninstall.exe
c:\programdata\wxDownload
c:\programdata\wxDownload\50c64c701d216.html
c:\programdata\wxDownload\50c64c701d24f.js
c:\programdata\wxDownload\data\50c64c701d24f.js
c:\programdata\wxDownload\data\jsondb.js
c:\programdata\wxDownload\hpocchkfefabpamkoefnpoappdpdmman.crx
c:\programdata\wxDownload\settings.ini
c:\programdata\wxDownload\uninstall.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-12-05 to 2013-01-05 )))))))))))))))))))))))))))))))
.
.
2013-01-05 07:36 . 2012-11-08 17:24 9125352 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BAA689D2-EA2A-4B56-935D-0D85AE6F3C0D}\mpengine.dll
2013-01-05 07:22 . 2012-11-08 17:24 9125352 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-01-04 01:19 . 2013-01-04 01:19 ——– d—–w- C:\FRST
2013-01-03 05:55 . 2013-01-03 05:55 ——– d—–w- c:\users\Zanthia.Family\AppData\Roaming\SUPERAntiSpyware.com
2013-01-02 22:58 . 2013-01-02 22:58 388096 —-a-r- c:\users\Bryan\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-01-02 21:28 . 2013-01-02 21:28 ——– d—–w- c:\program files\WOT
2013-01-02 18:17 . 2013-01-04 17:21 ——– d—–w- c:\windows\system32\%LocalAppData%
2013-01-02 08:50 . 2013-01-02 08:50 65736 —-a-w- c:\windows\system32\drivers\pxrts.sys
2013-01-02 08:50 . 2013-01-02 08:50 ——– d—–w- c:\program files\Prevx
2013-01-02 08:49 . 2013-01-02 22:24 ——– d—–w- c:\programdata\PrevxCSI
2013-01-02 06:33 . 2013-01-03 06:59 ——– d—–w- c:\windows\system32\catroot2
2013-01-02 01:32 . 2013-01-02 01:32 32152 —-a-w- c:\windows\system32\drivers\hitmanpro37.sys
2013-01-02 01:19 . 2013-01-02 01:19 ——– d—–w- c:\users\Betty\AppData\Roaming\Malwarebytes
2013-01-02 01:05 . 2013-01-02 01:05 208216 —-a-w- c:\windows\system32\drivers\34792715.sys
2013-01-02 00:40 . 2013-01-02 00:40 ——– d—–w- c:\users\Administrator.Family
2013-01-02 00:11 . 2013-01-02 00:11 ——– d—–w- C:\found.003
2013-01-01 23:25 . 2013-01-01 23:25 ——– d—–w- C:\found.002
2013-01-01 21:58 . 2013-01-01 22:09 ——– d—–w- c:\users\TEMP
2012-12-31 21:24 . 2012-12-31 21:24 ——– d—–w- C:\found.001
2012-12-30 17:07 . 2012-12-30 17:07 ——– d—–w- C:\found.000
2012-12-30 17:01 . 2012-12-30 17:01 ——– d—–w- c:\users\Bryan\AppData\Local\Programs
2012-12-25 16:59 . 2012-12-25 19:37 ——– d—–w- c:\users\Bryan\AppData\Roaming\Apple Computer
2012-12-25 16:59 . 2012-12-25 16:59 ——– d—–w- c:\users\Bryan\AppData\Local\Apple Computer
2012-12-24 23:03 . 2009-06-30 18:37 33800 —-a-w- c:\windows\system32\drivers\pavboot64.sys
2012-12-24 23:02 . 2012-12-24 23:02 ——– d—–w- c:\program files (x86)\Panda Security
2012-12-24 23:02 . 2012-12-24 23:02 ——– d—–w- c:\windows\AxInstSV
2012-12-22 23:20 . 2012-12-22 23:20 ——– d—–w- c:\program files (x86)\Common Files\Simple Adblock
2012-12-22 17:01 . 2012-12-16 17:11 46080 —-a-w- c:\windows\system32\atmlib.dll
2012-12-22 17:01 . 2012-12-16 14:13 34304 —-a-w- c:\windows\SysWow64\atmlib.dll
2012-12-22 17:01 . 2012-12-16 14:45 367616 —-a-w- c:\windows\system32\atmfd.dll
2012-12-22 17:01 . 2012-12-16 14:13 295424 —-a-w- c:\windows\SysWow64\atmfd.dll
2012-12-21 08:53 . 2012-12-21 08:53 ——– d—–w- c:\users\Bryan\AppData\Local\TunaMediaLtd
2012-12-21 08:53 . 2012-12-21 08:53 ——– d—–w- c:\program files (x86)\TunaMediaLtd
2012-12-21 08:52 . 2012-12-21 08:52 ——– d—–w- c:\users\Bryan\AppData\Local\Downloaded Installations
2012-12-15 08:04 . 2012-12-15 08:04 ——– d—–w- c:\users\Bryan\AppData\Roaming\SystemRequirementsLab
2012-12-15 07:14 . 2012-12-15 07:14 ——– d—–w- c:\users\Bryan\AppData\Local\4A Games
2012-12-13 20:55 . 2012-12-13 22:43 ——– d—–w- c:\users\Bryan\AppData\Local\DownTango
2012-12-13 20:55 . 2012-12-13 20:55 ——– d—–w- c:\program files (x86)\Red Sky
2012-12-12 09:54 . 2012-12-12 09:54 ——– d—–w- c:\windows\Migration
2012-12-12 09:52 . 2012-08-21 14:20 46080 —-a-w- c:\windows\SysWow64\ncobjapi.dll
2012-12-12 09:52 . 2012-08-21 13:49 58368 —-a-w- c:\windows\system32\ncobjapi.dll
2012-12-12 09:52 . 2012-08-21 13:12 74240 —-a-w- c:\windows\system32\wbem\NCProv.dll
2012-12-12 09:45 . 2012-11-14 05:52 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-12-12 09:44 . 2012-11-14 06:04 1392128 —-a-w- c:\windows\system32\wininet.dll
2012-12-12 09:41 . 2012-11-09 05:45 2048 —-a-w- c:\windows\system32\tzres.dll
2012-12-12 09:41 . 2012-11-09 04:42 2048 —-a-w- c:\windows\SysWow64\tzres.dll
2012-12-12 09:38 . 2012-11-02 05:59 478208 —-a-w- c:\windows\system32\dpnet.dll
2012-12-12 09:38 . 2012-11-02 05:11 376832 —-a-w- c:\windows\SysWow64\dpnet.dll
2012-12-12 09:06 . 2012-12-12 09:06 77 —-a-w- C:\prefs.js
2012-12-12 06:40 . 2012-12-12 06:40 ——– d—–w- c:\users\Zanthia.Family\AppData\Local\LogMeIn
2012-12-12 06:28 . 2012-12-12 06:28 ——– d—–w- c:\users\Betty\AppData\Local\LogMeIn
2012-12-12 06:02 . 2012-12-12 06:02 ——– d—–w- C:\e
2012-12-12 05:58 . 2013-01-02 07:55 ——– d—–w- c:\users\Bryan\AppData\Roaming\DefaultTab
2012-12-11 22:54 . 2012-12-11 22:54 ——– d—–w- c:\users\Bryan\AppData\Local\LogMeIn
2012-12-11 22:54 . 2012-10-20 02:10 60328 —-a-w- c:\windows\system32\Spool\prtprocs\x64\LMIproc.dll
2012-12-11 22:54 . 2012-10-20 02:10 35240 —-a-w- c:\windows\system32\LMIport.dll
2012-12-11 22:54 . 2012-10-20 02:11 88008 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-12-11 22:54 . 2012-08-24 22:41 72216 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2012-12-11 22:54 . 2012-10-20 02:10 83880 —-a-w- c:\windows\system32\LMIinit.dll
2012-12-11 22:54 . 2012-12-18 21:15 ——– d—–w- c:\programdata\LogMeIn
2012-12-11 22:54 . 2012-12-11 22:54 ——– d—–w- c:\program files (x86)\LogMeIn
2012-12-11 22:52 . 2012-12-11 22:52 ——– d—–w- c:\users\Bryan\AppData\Local\Deployment
2012-12-10 21:14 . 2012-12-10 21:14 ——– d—–w- c:\users\Bryan\AppData\Local\PutLockerDownloader
2012-12-10 20:40 . 2012-12-10 20:40 ——– d—–w- c:\program files (x86)\wxDownload Fast
2012-12-08 08:22 . 2012-12-08 08:22 ——– d—–w- c:\program files (x86)\Gophoto.it
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-02 06:23 . 2012-11-26 20:16 181064 —-a-w- c:\windows\PSEXESVC.EXE
2012-12-15 00:49 . 2012-09-19 15:27 24176 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-12-12 09:29 . 2012-04-13 22:07 697272 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-12-12 09:29 . 2011-11-07 17:34 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-11-28 23:58 . 2010-05-03 07:57 67413224 —-a-w- c:\windows\system32\MRT.exe
2012-11-28 20:58 . 2012-11-28 20:58 972264 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2D6959E6-5002-4EB6-9262-45F89279A03E}\gapaengine.dll
2012-11-26 22:43 . 2012-11-28 20:58 972192 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2012-11-08 17:24 . 2012-11-25 00:41 9125352 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F82B904F-663A-4D41-AFCA-F49ACDF967A6}\mpengine.dll
2012-10-30 23:51 . 2012-11-16 10:05 41224 —-a-w- c:\windows\avastSS.scr
2012-10-30 23:50 . 2012-11-16 10:05 227648 —-a-w- c:\windows\SysWow64\aswBoot.exe
2012-10-25 11:12 . 2012-10-25 11:12 94208 —-a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2012-10-25 11:12 . 2012-10-25 11:12 69632 —-a-w- c:\windows\SysWow64\QuickTime.qts
2012-10-23 15:39 . 2012-10-23 15:40 108008 —-a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2012-10-23 15:39 . 2011-12-22 23:57 1034216 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-10-23 15:39 . 2010-07-26 21:02 916456 —-a-w- c:\windows\system32\deployJava1.dll
2012-10-16 08:38 . 2012-11-27 19:27 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38 . 2012-11-27 19:27 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39 . 2012-11-27 19:27 561664 —-a-w- c:\windows\apppatch\AcLayers.dll
2012-10-09 18:17 . 2012-11-14 16:14 55296 —-a-w- c:\windows\system32\dhcpcsvc6.dll
2012-10-09 18:17 . 2012-11-14 16:14 226816 —-a-w- c:\windows\system32\dhcpcore6.dll
2012-10-09 17:40 . 2012-11-14 16:14 44032 —-a-w- c:\windows\SysWow64\dhcpcsvc6.dll
2012-10-09 17:40 . 2012-11-14 16:14 193536 —-a-w- c:\windows\SysWow64\dhcpcore6.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-06 39408]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2011-10-13 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"RequireSignedAppInit_DLLs"=0 (0x0)
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R0 hqmpym;hqmpym; [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 ALSysIO;ALSysIO;c:\users\Bryan\AppData\Local\Temp\ALSysIO64.sys [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2011-05-13 36328]
R3 easytether;easytether;c:\windows\system32\DRIVERS\easytthr.sys [x]
R3 hitmanpro37;HitmanPro 3.7 Support Driver;c:\windows\system32\drivers\hitmanpro37.sys [2013-01-02 32152]
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\7114.tmp [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-08-31 128456]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-09-13 368896]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 40464]
R3 PCGenFam;PCGenFam;c:\windows\system32\DRIVERS\PCGenFAM.sys [2010-11-02 198088]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2011-05-06 19936]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2011-05-06 13280]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 SaiKF622;SaiKF622;c:\windows\system32\DRIVERS\SaiKF622.sys [2009-06-02 140800]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 VaneFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2007-08-17 30336]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-03 1255736]
S0 hotcore3;hc3ServiceName;c:\windows\system32\DRIVERS\hotcore3.sys [2011-01-21 37456]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot64.sys [2009-06-30 33800]
S1 GIDv2;GIDv2; [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 22576]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 20016]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60464]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-10-06 140672]
S2 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-10-20 375728]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2012-08-24 15928]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-08-12 62208]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2011-10-14 994360]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2011-10-14 399416]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
S3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys [2011-11-25 15360]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 17976]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{9191979D-821C-4EA8-B021-2DA1D859A7C5}-3Reg]
2011-07-05 17:26 435976 —-a-w- c:\program files (x86)\SFT\GuardedID\GIDI.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-01-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 09:29]
.
2013-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28]
.
2013-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28]
.
2013-01-05 c:\windows\Tasks\WpsUpdateTask_Bryan.job
- c:\program files (x86)\Kingsoft\Kingsoft Office\office6\wpsupdate.exe [2012-09-17 16:00]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-07 10144288]
"PLD_FrameworkRun"="c:\windows\system32\oem\_NowIntoDT.vbs" [2009-10-11 490]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-22 2327952]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-13 1289704]
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://msn.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearchAssistant =
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
FF - ProfilePath -
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{a8a9d26a-734f-467a-8907-176f9c5bdf56} - (no file)
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} - (no file)
AddRemove-DefaultTab - c:\users\Bryan\AppData\Roaming\DefaultTab\DefaultTab\uninstalldt.exe
AddRemove-GamesBar - c:\program files (x86)\GamesBar\uninst.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_heroes.exe
AddRemove-SP_0beb79c1 - c:\program files (x86)\WxDownload\uninstall.exe
AddRemove-{088DF54D-6FFC-8C91-02D5-A461DCC2E652} - c:\programdata\wxDownload\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\7114.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*]
"value"="?\03\04\16\176\1e?"
.
Completion time: 2013-01-05 10:15:35
ComboFix-quarantined-files.txt 2013-01-05 18:15
ComboFix2.txt 2013-01-04 19:11
.
Pre-Run: 607,632,191,488 bytes free
Post-Run: 608,152,727,552 bytes free
.
- - End Of File - - C29C07C597B49F8D630F7BBB30367307
Let me know what you need done. Thanks.
What version of Internet Explorer do you have? 8 or 9? I'm glad disabling Shockwave solved the issue but as you said, you'll want it again. If it were me, I'd remove Shockwave and reinstall it a fresh version and see if that helps. Something may just be corrupted.

I see you have Malwarebytes already on your machine. Please run it by right-clicking and choosing Run as Administrator on the icon on the desktop let's see if we can get it to run now.
  • Click on the tab labeled Update and then click on the button Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.


Go here to run an online scannner from ESET.
  • Note: For browsers other than Internet Explorer, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.

If it doesn't find anything there will be no log to post.


Overall how does the machine seem to be running now?
Malwarebytes found nothing. The ESET scan took along time but it did show 20 threats, I will include that scan log here. What should I do with those things detected, for now I'm not cleaning anything from the scan , let me know how and what you want done. C:\backup\sdcard\Verbous_GenoCYde.version.666.zip Android/Plankton.H trojan C:\backup\sdcard\back up\Removable Disk\Admiral-Beast-CWM.zip a variant of Android/Adware.Waps.D application C:\backup\sdcopy\back up\Removable Disk\Admiral-Beast-CWM.zip a variant of Android/Adware.Waps.D application C:\New folder (2)\Removable Disk\back up\Removable Disk\Admiral-Beast-CWM.zip a variant of Android/Adware.Waps.D application C:\Program Files (x86)\Trend Micro\HijackThis\backups\backup-20130104-104458-268.dll Win32/Adware.MultiPlug.E application C:\Qoobox\Quarantine\C\Program Files (x86)\WxDownload\sprotector.dll.vir a variant of Win32/SProtector.A application C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome\pptextlinks.jar Win32/Adware.Gamevance.Gen application C:\Users\Bryan\Desktop\sd card bu\appmonster2\backup\great.app.luck\rev\19.apk a variant of Android/Adware.AirPush.C application C:\Users\Bryan\Desktop\sd card bu\App_Manager\App_Backups\user_apps\great.app.luck.apk a variant of Android/Adware.AirPush.C application C:\Users\Bryan\Desktop\sd card bu\TitaniumBackup\great.app.luck-73d83b0622200494240f8460c0a9cfa7.apk.gz a variant of Android/Adware.AirPush.C application C:\Users\Bryan\Desktop\sd card bu\TitaniumBackup\mobi.mgeek.TunnyBrowser-b32e904a89df7510548bb253d28cbce0.apk.gz a variant of Android/Adware.Waps.D application C:\Users\Bryan\Documents\back up\Removable Disk\Admiral-Beast-CWM.zip a variant of Android/Adware.Waps.D application C:\Users\Bryan\Downloads\Admiral-Beast-CWM.zip a variant of Android/Adware.Waps.D application C:\Users\Bryan\Downloads\Avengers_Reborn_Verbous.zip a variant of Android/Adware.AirPush.C application C:\Users\Bryan\Downloads\Black_Ice.zip Android/HackTool.FaceNiff.A application C:\Users\Bryan\Downloads\Eternal_Ecstasy.zip multiple threats C:\Users\Bryan\Downloads\The_Walking_Dead_Comic_(1-93)_downloader_99132.exe a variant of Win32/YourFileDownloader.A application C:\Users\Bryan\Downloads\Titanium_Vip-A-Rom.zip Android/HackTool.FaceNiff.A application C:\Users\Bryan\Downloads\Verbous_GenoCYde.version.666.2.zip Android/HackTool.FaceNiff.A application C:\Users\Bryan\Downloads\Verbous_GenoCYde.version.666.zip Android/Plankton.H trojan
We'll take care of 19 of those with another script :) One of those was already quarantined in a Combofix file and will be taken care of when we clean up tools in just a bit.

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\backup\sdcard\Verbous_GenoCYde.version.666.zip
C:\backup\sdcard\back up\Removable Disk\Admiral-Beast-CWM.zip
C:\backup\sdcopy\back up\Removable Disk\Admiral-Beast-CWM.zip
C:\New folder (2)\Removable Disk\back up\Removable Disk\Admiral-Beast-CWM.zip
C:\Program Files (x86)\Trend Micro\HijackThis\backups\backup-20130104-104458-268.dll
C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome\pptextlinks.jar
C:\Users\Bryan\Desktop\sd card bu\appmonster2\backup\great.app.luck\rev\19.apk
C:\Users\Bryan\Desktop\sd card bu\App_Manager\App_Backups\user_apps\great.app.luck.apk
C:\Users\Bryan\Desktop\sd card bu\TitaniumBackup\great.app.luck-73d83b0622200494240f8460c0a9cfa7.apk.gz
C:\Users\Bryan\Desktop\sd card bu\TitaniumBackup\mobi.mgeek.TunnyBrowser-b32e904a89df7510548bb253d28cbce0.apk.gz
C:\Users\Bryan\Documents\back up\Removable Disk\Admiral-Beast-CWM.zip
C:\Users\Bryan\Downloads\Admiral-Beast-CWM.zip
C:\Users\Bryan\Downloads\Avengers_Reborn_Verbous.zip
C:\Users\Bryan\Downloads\Black_Ice.zip
C:\Users\Bryan\Downloads\Eternal_Ecstasy.zip
C:\Users\Bryan\Downloads\The_Walking_Dead_Comic_(1-93)_downloader_99132.exe
C:\Users\Bryan\Downloads\Titanium_Vip-A-Rom.zip
C:\Users\Bryan\Downloads\Verbous_GenoCYde.version.666.2.zip


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe. ComboFix may request an update; please allow it.

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.


How is the machine running, is everything doing ok at this point? Any problems on your account or your wife's? Any BSOD's? Shut downs? And most importantly is safe mode working again?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI