Constant shut downs, Cannot use safe boot [Solved]
17 min read
My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
- Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
- Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
- Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
- Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
- Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
- Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
- Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
- Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!
Can you please tell me if the information on your profile is correct that you have Windows 7 64 bit?
Download Farbar Recovery Scan Tool and save it to a flash drive.
Plug the flashdrive into the infected PC.
Restart your computer and tap F8 to bring up the Advanced Menu, then click Repair your computer
Follow the prompt to enter keyboard input method, and then the prompt to enter a password. If the machine does not have a password, simply click Enter.
In the next menu, use the arrow keys on the keyboard to highlight Command Prompt and press Enter.
- In the command window type in notepad and press Enter.
- The notepad opens. Under File menu select Open.
- Select "Computer" and find your flash drive letter and close the notepad.
- In the command window type e:\frst.exe and press Enter.
- The tool will start to run.
- When the tool opens click Yes to disclaimer.
- Place a check next to List Drivers MD5
- Press Scan button.
When finished, a log (FRST64.txt) will be created on the flash drive. Please copy and paste it to your reply.
I see that you also installed TDSSKiller. Did you run this and if so did you select skip or cure when you ran it?
There should be a report found in your root directory if you ran it, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt" which would be very helpful to me if you could post in your next reply.
Let's give something a try:
Restart your computer and tap F8 to bring up the Advanced Menu, then click Repair your computer
On this menu, this time I'd like you to select Startup Repair and follow the instructions on screen. You should not need to have a recovery disc for this.
Typically your machine can do this without having one. It may churn away for a little while and appear to be doing nothing. And indeed it may tell you it was either unable to find any errors or was unable to correct any that it found (which sometimes I've found to be true and sometimes they magically seem to be fixed anyway) but either way just reboot the machine into normal mode and let me know if there is any change.
TDSKIller could not detect anything wrong in the scan and I'll show that also. I'll also include a scan from MalwareBytes from a full scan because the quick scan option would not complete after several attempts. I had to run some of these from my wifes account because I could no longer log into my own after running the Tweaking.com tool. After shutting things down for the night 2 days ago I was able to log in after cleaning the results from the Malwarebytes scan. Something is still wrong but I can at least log into my account agaIn. I also deleted all the crzy programs my wife downloads and the tool bars she always seems to accept being loaded. No matter how many times I ask her to ask me about downloading things she does it anyway because she likes to play the games offered and also checks on many of the hyped free stuff she sees. I installed Sandboxie on the system but it stopped starting from her account. Also I've had to restart MSE several ytimes because it keeps getting shut down by something. MSE and windows firewall are the only tools I currently use for protection.
I'll wait for you to complete cleaning things and then follow your advice concerning what security tools are best to use. Please keep in mind that I'm a disabled veteran living on $1038 a month so I cannot afford to buy the better antivirus and protection software out there. I use Gizmo's site for help in determining the best free tools to use for my system.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:55:30 AM, on 1/4/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
c:\Windows\System32\oem\SetEvent.exe
C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_5_502_135_ActiveX.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HiJackThis.exe
C:\Windows\SysWOW64\DllHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.privitize.com/?aff=7
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: DefaultTabBHO - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Bryan\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll (file missing)
O2 - BHO: wxDownload - {95B741CB-CF8A-6780-C5F6-FF7C39EA7BCE} - C:\ProgramData\wxDownload\50c64c701d1de.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll
O2 - BHO: WeCareReminder - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\ProgramData\WeCareReminder\IEHelperv2.5.0.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SimpleAdblock Class - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files (x86)\Common Files\Simple Adblock\SimpleAdblock.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://oas.support.microsoft.com/ActiveX/MSDcode.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - http://content.systemrequirementslab.com.s…ri_4.1.71.0.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files%20(x86)/Slingo%20Deluxe/Images/stg_drm.ocx
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://gamesville.worldwinner.com/games/v4…GamesLoader.cab
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} (TPIR Control) - http://www.worldwinner.com/games/v50/tpir/tpir.cab
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/…can8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - https://www.battlefieldheroes.com/static/up…er_4.0.53.0.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} (WorldWinner ActiveX Launcher Control) - http://www.worldwinner.com/games/launcher/….0/iewwload.cab
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {95A311CD-EC8E-452A-BCEC-B844EB616D03} (BejeweledTwist Control) - http://www.worldwinner.com/games/v51/bejew…eweledtwist.cab
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://www.worldwinner.com/games/v57/cubis/cubis.cab
O16 - DPF: {A021A215-6CDC-44B4-8C16-90491CED9605} (Clue Control) - http://www.worldwinner.com/games/v68/clue/clue.cab
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} (PCMaticVer Class) - http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
O16 - DPF: {BA35B9B8-DE9E-47C9-AFA7-3C77E3DDFD39} (Monopoly Control) - http://www.worldwinner.com/games/v46/monopoly/monopoly.cab
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} (Tilecity Control) - http://www.worldwinner.com/games/v42/tilecity/tilecity.cab
O16 - DPF: {C82BB209-F528-46F9-96D5-69DEF7260916} (MysteryPI Control) - http://www.worldwinner.com/games/v45/mysterypi/mysterypi.cab
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) - http://www.worldwinner.com/games/v43/paint/paint.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files%20(x86)/Slingo%20Deluxe/Images/armhelper.ocx
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} (SysInfo Class) - http://content.systemrequirementslab.com.s…yri_4.5.1.0.cab
O16 - DPF: {FC4CAF5F-91BD-4DD9-ADC1-F3C737E37BC4} (CPlayFirstSweetopiaControl Object) - http://zone.msn.com/bingame/swet/default/S…ia.1.0.0.46.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll
O20 - AppInit_DLLs: c:\PROGRA~2\WXDOWN~1\SPROTE~1.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Encrypting File System (EFS) (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\PSIA.exe
O23 - Service: Secunia Update Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\sua.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
–
End of file - 13285 bytes
17:05:04.0007 1068 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
17:05:04.0600 1068 ============================================================
17:05:04.0600 1068 Current date / time: 2013/01/01 17:05:04.0600
17:05:04.0600 1068 SystemInfo:
17:05:04.0600 1068
17:05:04.0600 1068 OS Version: 6.1.7601 ServicePack: 1.0
17:05:04.0600 1068 Product type: Workstation
17:05:04.0600 1068 ComputerName: FAMILY
17:05:04.0600 1068 UserName: Administrator
17:05:04.0600 1068 Windows directory: C:\Windows
17:05:04.0600 1068 System windows directory: C:\Windows
17:05:04.0600 1068 Running under WOW64
17:05:04.0600 1068 Processor architecture: Intel x64
17:05:04.0600 1068 Number of processors: 2
17:05:04.0600 1068 Page size: 0x1000
17:05:04.0600 1068 Boot type: Normal boot
17:05:04.0600 1068 ============================================================
17:05:06.0363 1068 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
17:05:06.0378 1068 ============================================================
17:05:06.0378 1068 \Device\Harddisk0\DR0:
17:05:06.0378 1068 MBR partitions:
17:05:06.0378 1068 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1B58800, BlocksNum 0x32000
17:05:06.0378 1068 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1B8A800, BlocksNum 0x559BB6F0
17:05:06.0378 1068 ============================================================
17:05:06.0410 1068 C: <-> \Device\Harddisk0\DR0\Partition2
17:05:06.0410 1068 ============================================================
17:05:06.0410 1068 Initialize success
17:05:06.0410 1068 ============================================================
17:05:09.0686 2500 ============================================================
17:05:09.0686 2500 Scan started
17:05:09.0686 2500 Mode: Manual;
17:05:09.0686 2500 ============================================================
17:05:10.0559 2500 ================ Scan system memory ========================
17:05:10.0559 2500 System memory - ok
17:05:10.0559 2500 ================ Scan services =============================
17:05:10.0653 2500 [ 581D88B25C4D4121824FED2CA38E562F ] !SASCORE C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
17:05:10.0668 2500 !SASCORE - ok
17:05:10.0918 2500 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
17:05:10.0918 2500 1394ohci - ok
17:05:10.0980 2500 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
17:05:10.0980 2500 ACPI - ok
17:05:10.0996 2500 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
17:05:10.0996 2500 AcpiPmi - ok
17:05:11.0152 2500 [ 95CE557D16A75606CCC2D7F3B0B0BCCB ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
17:05:11.0152 2500 AdobeFlashPlayerUpdateSvc - ok
17:05:11.0183 2500 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
17:05:11.0183 2500 adp94xx - ok
17:05:11.0199 2500 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
17:05:11.0199 2500 adpahci - ok
17:05:11.0230 2500 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
17:05:11.0230 2500 adpu320 - ok
17:05:11.0277 2500 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
17:05:11.0277 2500 AeLookupSvc - ok
17:05:11.0324 2500 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
17:05:11.0339 2500 AFD - ok
17:05:11.0370 2500 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
17:05:11.0370 2500 agp440 - ok
17:05:11.0386 2500 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
17:05:11.0386 2500 ALG - ok
17:05:11.0417 2500 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
17:05:11.0417 2500 aliide - ok
17:05:11.0542 2500 ALSysIO - ok
17:05:11.0558 2500 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
17:05:11.0558 2500 amdide - ok
17:05:11.0573 2500 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
17:05:11.0573 2500 AmdK8 - ok
17:05:11.0589 2500 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
17:05:11.0604 2500 AmdPPM - ok
17:05:11.0636 2500 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
17:05:11.0636 2500 amdsata - ok
17:05:11.0651 2500 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
17:05:11.0651 2500 amdsbs - ok
17:05:11.0682 2500 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
17:05:11.0682 2500 amdxata - ok
17:05:11.0776 2500 [ 4DE0D5D747A73797C95A97DCCE5018B5 ] androidusb C:\Windows\system32\Drivers\ssadadb.sys
17:05:11.0776 2500 androidusb - ok
17:05:11.0792 2500 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
17:05:11.0792 2500 AppID - ok
17:05:11.0823 2500 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
17:05:11.0823 2500 AppIDSvc - ok
17:05:11.0854 2500 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
17:05:11.0854 2500 Appinfo - ok
17:05:11.0885 2500 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
17:05:11.0885 2500 arc - ok
17:05:11.0885 2500 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
17:05:11.0885 2500 arcsas - ok
17:05:12.0041 2500 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
17:05:12.0072 2500 aspnet_state - ok
17:05:12.0088 2500 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
17:05:12.0088 2500 AsyncMac - ok
17:05:12.0119 2500 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
17:05:12.0119 2500 atapi - ok
17:05:12.0182 2500 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
17:05:12.0182 2500 AudioEndpointBuilder - ok
17:05:12.0197 2500 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
17:05:12.0197 2500 AudioSrv - ok
17:05:12.0244 2500 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
17:05:12.0244 2500 AxInstSV - ok
17:05:12.0291 2500 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
17:05:12.0291 2500 b06bdrv - ok
17:05:12.0338 2500 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
17:05:12.0338 2500 b57nd60a - ok
17:05:12.0369 2500 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
17:05:12.0369 2500 BDESVC - ok
17:05:12.0384 2500 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
17:05:12.0384 2500 Beep - ok
17:05:12.0416 2500 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
17:05:12.0416 2500 BFE - ok
17:05:12.0478 2500 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
17:05:12.0478 2500 BITS - ok
17:05:12.0494 2500 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
17:05:12.0494 2500 blbdrive - ok
17:05:12.0618 2500 [ 5AB58C337AC65837FE404462AD6265AB ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe
17:05:12.0618 2500 Bonjour Service - ok
17:05:12.0665 2500 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
17:05:12.0665 2500 bowser - ok
17:05:12.0681 2500 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
17:05:12.0681 2500 BrFiltLo - ok
17:05:12.0696 2500 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
17:05:12.0696 2500 BrFiltUp - ok
17:05:12.0712 2500 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
17:05:12.0712 2500 BridgeMP - ok
17:05:12.0759 2500 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
17:05:12.0759 2500 Browser - ok
17:05:12.0790 2500 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
17:05:12.0790 2500 Brserid - ok
17:05:12.0806 2500 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
17:05:12.0806 2500 BrSerWdm - ok
17:05:12.0806 2500 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
17:05:12.0806 2500 BrUsbMdm - ok
17:05:12.0852 2500 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
17:05:12.0852 2500 BrUsbSer - ok
17:05:12.0868 2500 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
17:05:12.0868 2500 BTHMODEM - ok
17:05:12.0915 2500 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
17:05:12.0915 2500 bthserv - ok
17:05:12.0930 2500 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
17:05:12.0946 2500 cdfs - ok
17:05:13.0008 2500 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
17:05:13.0008 2500 cdrom - ok
17:05:13.0040 2500 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
17:05:13.0040 2500 CertPropSvc - ok
17:05:13.0055 2500 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
17:05:13.0071 2500 circlass - ok
17:05:13.0086 2500 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
17:05:13.0102 2500 CLFS - ok
17:05:13.0164 2500 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:05:13.0164 2500 clr_optimization_v2.0.50727_32 - ok
17:05:13.0211 2500 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
17:05:13.0211 2500 clr_optimization_v2.0.50727_64 - ok
17:05:13.0258 2500 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17:05:13.0336 2500 clr_optimization_v4.0.30319_32 - ok
17:05:13.0367 2500 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
17:05:13.0414 2500 clr_optimization_v4.0.30319_64 - ok
17:05:13.0461 2500 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
17:05:13.0461 2500 CmBatt - ok
17:05:13.0492 2500 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
17:05:13.0492 2500 cmdide - ok
17:05:13.0554 2500 [ AAFCB52FE0037207FB6FBEA070D25EFE ] CNG C:\Windows\system32\Drivers\cng.sys
17:05:13.0554 2500 CNG - ok
17:05:13.0586 2500 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
17:05:13.0586 2500 Compbatt - ok
17:05:13.0617 2500 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
17:05:13.0617 2500 CompositeBus - ok
17:05:13.0617 2500 COMSysApp - ok
17:05:13.0648 2500 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
17:05:13.0648 2500 crcdisk - ok
17:05:13.0695 2500 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
17:05:13.0695 2500 CryptSvc - ok
17:05:13.0742 2500 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
17:05:13.0742 2500 DcomLaunch - ok
17:05:13.0820 2500 [ 34AE0DFA3EE3B5B9975042D87332D0B7 ] DefaultTabUpdate C:\Users\Bryan\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe
17:05:13.0820 2500 DefaultTabUpdate - ok
17:05:13.0851 2500 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
17:05:13.0866 2500 defragsvc - ok
17:05:13.0929 2500 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
17:05:13.0929 2500 DfsC - ok
17:05:13.0976 2500 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
17:05:13.0976 2500 Dhcp - ok
17:05:13.0991 2500 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
17:05:13.0991 2500 discache - ok
17:05:14.0022 2500 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
17:05:14.0022 2500 Disk - ok
17:05:14.0069 2500 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
17:05:14.0069 2500 Dnscache - ok
17:05:14.0100 2500 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
17:05:14.0100 2500 dot3svc - ok
17:05:14.0116 2500 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
17:05:14.0116 2500 DPS - ok
17:05:14.0132 2500 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
17:05:14.0132 2500 drmkaud - ok
17:05:14.0194 2500 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
17:05:14.0194 2500 DXGKrnl - ok
17:05:14.0210 2500 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
17:05:14.0210 2500 EapHost - ok
17:05:14.0241 2500 easytether - ok
17:05:14.0303 2500 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
17:05:14.0366 2500 ebdrv - ok
17:05:14.0412 2500 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
17:05:14.0412 2500 EFS - ok
17:05:14.0475 2500 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
17:05:14.0475 2500 elxstor - ok
17:05:14.0584 2500 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
17:05:14.0584 2500 ErrDev - ok
17:05:14.0740 2500 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
17:05:14.0756 2500 EventSystem - ok
17:05:14.0771 2500 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
17:05:14.0771 2500 exfat - ok
17:05:14.0787 2500 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
17:05:14.0787 2500 fastfat - ok
17:05:14.0802 2500 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
17:05:14.0802 2500 fdc - ok
17:05:14.0818 2500 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
17:05:14.0834 2500 fdPHost - ok
17:05:14.0834 2500 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
17:05:14.0834 2500 FDResPub - ok
17:05:14.0849 2500 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
17:05:14.0849 2500 FileInfo - ok
17:05:14.0865 2500 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
17:05:14.0865 2500 Filetrace - ok
17:05:14.0865 2500 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
17:05:14.0880 2500 flpydisk - ok
17:05:14.0896 2500 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
17:05:14.0912 2500 FltMgr - ok
17:05:14.0958 2500 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
17:05:14.0990 2500 FontCache - ok
17:05:15.0068 2500 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
17:05:15.0068 2500 FontCache3.0.0.0 - ok
17:05:15.0239 2500 [ A9FF65EA14E4CABFCC1BB8ECE111A249 ] ForceWare Intelligent Application Manager (IAM) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
17:05:15.0239 2500 ForceWare Intelligent Application Manager (IAM) - ok
17:05:15.0286 2500 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
17:05:15.0286 2500 FsDepends - ok
17:05:15.0348 2500 [ 6C06701BF1DB05405804D7EB610991CE ] fssfltr C:\Windows\system32\DRIVERS\fssfltr.sys
17:05:15.0348 2500 fssfltr - ok
17:05:15.0458 2500 [ 4CE9DAC1518FF7E77BD213E6394B9D77 ] fsssvc C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
17:05:15.0473 2500 fsssvc - ok
17:05:15.0520 2500 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
17:05:15.0520 2500 Fs_Rec - ok
17:05:15.0551 2500 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
17:05:15.0551 2500 fvevol - ok
17:05:15.0582 2500 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
17:05:15.0582 2500 gagp30kx - ok
17:05:15.0660 2500 [ 67CF4C2E7477B9A01DF07E38AF293414 ] GameConsoleService C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe
17:05:15.0660 2500 GameConsoleService - ok
17:05:15.0676 2500 GEARAspiWDM - ok
17:05:15.0707 2500 [ 9BA22AEE7F531EF9CE085CC2E1112BC4 ] GIDv2 C:\Windows\system32\drivers\GIDv2.sys
17:05:15.0707 2500 GIDv2 - ok
17:05:15.0754 2500 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
17:05:15.0770 2500 gpsvc - ok
17:05:15.0832 2500 [ 816FD5A6F3C2F3D600900096632FC60E ] Greg_Service C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
17:05:15.0848 2500 Greg_Service - ok
17:05:15.0941 2500 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
17:05:15.0941 2500 gupdate - ok
17:05:15.0972 2500 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
17:05:15.0972 2500 gupdatem - ok
17:05:16.0019 2500 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
17:05:16.0019 2500 gusvc - ok
17:05:16.0050 2500 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
17:05:16.0050 2500 hcw85cir - ok
17:05:16.0097 2500 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
17:05:16.0097 2500 HdAudAddService - ok
17:05:16.0128 2500 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
17:05:16.0128 2500 HDAudBus - ok
17:05:16.0160 2500 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
17:05:16.0160 2500 HidBatt - ok
17:05:16.0175 2500 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
17:05:16.0175 2500 HidBth - ok
17:05:16.0175 2500 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
17:05:16.0175 2500 HidIr - ok
17:05:16.0222 2500 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
17:05:16.0222 2500 hidserv - ok
17:05:16.0238 2500 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
17:05:16.0238 2500 HidUsb - ok
17:05:16.0269 2500 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
17:05:16.0269 2500 hkmsvc - ok
17:05:16.0300 2500 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
17:05:16.0300 2500 HomeGroupListener - ok
17:05:16.0316 2500 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
17:05:16.0316 2500 HomeGroupProvider - ok
17:05:16.0362 2500 [ DDF58C2E16527073FEF370EDFE970745 ] hotcore3 C:\Windows\system32\DRIVERS\hotcore3.sys
17:05:16.0362 2500 hotcore3 - ok
17:05:16.0472 2500 [ FCB563B0A23643E5F80B6FF1E60F610F ] hpqcxs08 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll
17:05:16.0472 2500 hpqcxs08 - ok
17:05:16.0503 2500 [ 25E443E27165C652723A92D9BDFD4649 ] hpqddsvc C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll
17:05:16.0503 2500 hpqddsvc - ok
17:05:16.0550 2500 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
17:05:16.0550 2500 HpSAMD - ok
17:05:16.0581 2500 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
17:05:16.0596 2500 HTTP - ok
17:05:16.0628 2500 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
17:05:16.0628 2500 hwpolicy - ok
17:05:16.0674 2500 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
17:05:16.0674 2500 i8042prt - ok
17:05:16.0706 2500 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
17:05:16.0908 2500 iaStorV - ok
17:05:16.0986 2500 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
17:05:16.0986 2500 idsvc - ok
17:05:17.0033 2500 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
17:05:17.0033 2500 iirsp - ok
17:05:17.0080 2500 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
17:05:17.0096 2500 IKEEXT - ok
17:05:17.0174 2500 [ 0ADF714079AE174A39D69036143E4C50 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
17:05:17.0220 2500 IntcAzAudAddService - ok
17:05:17.0236 2500 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
17:05:17.0236 2500 intelide - ok
17:05:17.0267 2500 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
17:05:17.0267 2500 intelppm - ok
17:05:17.0298 2500 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
17:05:17.0298 2500 IPBusEnum - ok
17:05:17.0314 2500 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:05:17.0314 2500 IpFilterDriver - ok
17:05:17.0345 2500 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
17:05:17.0361 2500 iphlpsvc - ok
17:05:17.0376 2500 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
17:05:17.0376 2500 IPMIDRV - ok
17:05:17.0408 2500 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
17:05:17.0408 2500 IPNAT - ok
17:05:17.0423 2500 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
17:05:17.0423 2500 IRENUM - ok
17:05:17.0454 2500 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
17:05:17.0454 2500 isapnp - ok
17:05:17.0486 2500 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
17:05:17.0486 2500 iScsiPrt - ok
17:05:17.0501 2500 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
17:05:17.0501 2500 kbdclass - ok
17:05:17.0517 2500 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
17:05:17.0517 2500 kbdhid - ok
17:05:17.0532 2500 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
17:05:17.0532 2500 KeyIso - ok
17:05:17.0564 2500 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
17:05:17.0564 2500 KSecDD - ok
17:05:17.0610 2500 [ 7EFB9333E4ECCE6AE4AE9D777D9E553E ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
17:05:17.0610 2500 KSecPkg - ok
17:05:17.0610 2500 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
17:05:17.0610 2500 ksthunk - ok
17:05:17.0673 2500 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
17:05:17.0673 2500 KtmRm - ok
17:05:17.0720 2500 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
17:05:17.0735 2500 LanmanServer - ok
17:05:17.0766 2500 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
17:05:17.0766 2500 LanmanWorkstation - ok
17:05:17.0782 2500 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
17:05:17.0782 2500 lltdio - ok
17:05:17.0829 2500 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
17:05:17.0844 2500 lltdsvc - ok
17:05:17.0860 2500 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
17:05:17.0860 2500 lmhosts - ok
17:05:17.0922 2500 [ 7109163D8027076D2680CFC4E80E2A28 ] LMIGuardianSvc C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
17:05:17.0922 2500 LMIGuardianSvc - ok
17:05:17.0938 2500 [ 0317335B15FF3BDA8E10197E3434CFC0 ] LMIInfo C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys
17:05:17.0938 2500 LMIInfo - ok
17:05:17.0985 2500 [ 8054CE1FC8B417691960D00F931516A7 ] LMIMaint C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
17:05:17.0985 2500 LMIMaint - ok
17:05:18.0000 2500 [ 413ECDCFAD9A82804D3674C8D7EEC24E ] lmimirr C:\Windows\system32\DRIVERS\lmimirr.sys
17:05:18.0016 2500 lmimirr - ok
17:05:18.0016 2500 LMIRfsClientNP - ok
17:05:18.0047 2500 [ C57D3FAA50E6F395759FFB7C709BD944 ] LMIRfsDriver C:\Windows\system32\drivers\LMIRfsDriver.sys
17:05:18.0047 2500 LMIRfsDriver - ok
17:05:18.0094 2500 [ D3760BC17E1755091B7120CF32DBF56B ] LogMeIn C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
17:05:18.0094 2500 LogMeIn - ok
17:05:18.0125 2500 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
17:05:18.0125 2500 LSI_FC - ok
17:05:18.0156 2500 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
17:05:18.0156 2500 LSI_SAS - ok
17:05:18.0172 2500 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
17:05:18.0172 2500 LSI_SAS2 - ok
17:05:18.0188 2500 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
17:05:18.0188 2500 LSI_SCSI - ok
17:05:18.0250 2500 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
17:05:18.0250 2500 luafv - ok
17:05:18.0281 2500 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
17:05:18.0281 2500 megasas - ok
17:05:18.0312 2500 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
17:05:18.0312 2500 MegaSR - ok
17:05:18.0312 2500 MEMSWEEP2 - ok
17:05:18.0344 2500 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
17:05:18.0344 2500 MMCSS - ok
17:05:18.0359 2500 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
17:05:18.0359 2500 Modem - ok
17:05:18.0406 2500 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
17:05:18.0406 2500 monitor - ok
17:05:18.0453 2500 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\drivers\mouclass.sys
17:05:18.0453 2500 mouclass - ok
17:05:18.0484 2500 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
17:05:18.0484 2500 mouhid - ok
17:05:18.0515 2500 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
17:05:18.0515 2500 mountmgr - ok
17:05:18.0562 2500 [ 05BF204EC0E82CC4A054DB189C8A3D84 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
17:05:18.0578 2500 MpFilter - ok
17:05:18.0609 2500 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
17:05:18.0609 2500 mpio - ok
17:05:18.0624 2500 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
17:05:18.0624 2500 mpsdrv - ok
17:05:18.0687 2500 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
17:05:18.0687 2500 MpsSvc - ok
17:05:18.0749 2500 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
17:05:18.0749 2500 MRxDAV - ok
17:05:18.0780 2500 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
17:05:18.0780 2500 mrxsmb - ok
17:05:18.0827 2500 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:05:18.0827 2500 mrxsmb10 - ok
17:05:18.0843 2500 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:05:18.0843 2500 mrxsmb20 - ok
17:05:18.0874 2500 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
17:05:18.0874 2500 msahci - ok
17:05:18.0890 2500 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
17:05:18.0890 2500 msdsm - ok
17:05:18.0936 2500 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
17:05:18.0952 2500 MSDTC - ok
17:05:18.0983 2500 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
17:05:18.0983 2500 Msfs - ok
17:05:18.0999 2500 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
17:05:18.0999 2500 mshidkmdf - ok
17:05:19.0030 2500 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
17:05:19.0030 2500 msisadrv - ok
17:05:19.0077 2500 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
17:05:19.0077 2500 MSiSCSI - ok
17:05:19.0092 2500 msiserver - ok
17:05:19.0108 2500 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
17:05:19.0108 2500 MSKSSRV - ok
17:05:19.0170 2500 [ CC8E4F72F21340A4D3A3D4DB50313EF5 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe
17:05:19.0170 2500 MsMpSvc - ok
17:05:19.0186 2500 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
17:05:19.0186 2500 MSPCLOCK - ok
17:05:19.0202 2500 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
17:05:19.0202 2500 MSPQM - ok
17:05:19.0233 2500 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
17:05:19.0233 2500 MsRPC - ok
17:05:19.0248 2500 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
17:05:19.0248 2500 mssmbios - ok
17:05:19.0264 2500 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
17:05:19.0264 2500 MSTEE - ok
17:05:19.0280 2500 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
17:05:19.0280 2500 MTConfig - ok
17:05:19.0295 2500 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
17:05:19.0295 2500 Mup - ok
17:05:19.0342 2500 [ 6FFECC25B39DC7652A0CEC0ADA9DB589 ] mwlPSDFilter C:\Windows\system32\DRIVERS\mwlPSDFilter.sys
17:05:19.0342 2500 mwlPSDFilter - ok
17:05:19.0358 2500 [ 0BEFE32CA56D6EE89D58175725596A85 ] mwlPSDNServ C:\Windows\system32\DRIVERS\mwlPSDNServ.sys
17:05:19.0358 2500 mwlPSDNServ - ok
17:05:19.0373 2500 [ D43BC633B8660463E446E28E14A51262 ] mwlPSDVDisk C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys
17:05:19.0373 2500 mwlPSDVDisk - ok
17:05:19.0404 2500 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
17:05:19.0420 2500 napagent - ok
17:05:19.0451 2500 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
17:05:19.0451 2500 NativeWifiP - ok
17:05:19.0545 2500 [ 9D1CCE440552500DED3A62F9D779CDB4 ] NAUpdate C:\Program Files (x86)\Nero\Update\NASvc.exe
17:05:19.0545 2500 NAUpdate - ok
17:05:19.0576 2500 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
17:05:19.0592 2500 NDIS - ok
17:05:19.0623 2500 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
17:05:19.0623 2500 NdisCap - ok
17:05:19.0654 2500 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
17:05:19.0654 2500 NdisTapi - ok
17:05:19.0685 2500 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
17:05:19.0685 2500 Ndisuio - ok
17:05:19.0716 2500 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
17:05:19.0716 2500 NdisWan - ok
17:05:19.0748 2500 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
17:05:19.0748 2500 NDProxy - ok
17:05:19.0966 2500 [ 59267D2F0328599AA3B5408C2E06126F ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
17:05:19.0966 2500 Net Driver HPZ12 - ok
17:05:19.0982 2500 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
17:05:19.0982 2500 NetBIOS - ok
17:05:20.0028 2500 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
17:05:20.0028 2500 NetBT - ok
17:05:20.0044 2500 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
17:05:20.0044 2500 Netlogon - ok
17:05:20.0075 2500 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
17:05:20.0075 2500 Netman - ok
17:05:20.0138 2500 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:05:20.0184 2500 NetMsmqActivator - ok
17:05:20.0200 2500 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:05:20.0200 2500 NetPipeActivator - ok
17:05:20.0231 2500 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
17:05:20.0231 2500 netprofm - ok
17:05:20.0247 2500 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:05:20.0247 2500 NetTcpActivator - ok
17:05:20.0247 2500 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:05:20.0247 2500 NetTcpPortSharing - ok
17:05:20.0278 2500 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
17:05:20.0278 2500 nfrd960 - ok
17:05:20.0325 2500 [ 5FF89F20317309D28AC1EDEB0CD1BA72 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
17:05:20.0325 2500 NisDrv - ok
17:05:20.0356 2500 [ 79E80B10FE8F6662E0C9162A68C43444 ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe
17:05:20.0356 2500 NisSrv - ok
17:05:20.0387 2500 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
17:05:20.0387 2500 NlaSvc - ok
17:05:20.0418 2500 [ 3CEEE0BE85D24D911B9C02714817774C ] NPF C:\Windows\system32\drivers\npf.sys
17:05:20.0418 2500 NPF - ok
17:05:20.0465 2500 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
17:05:20.0465 2500 Npfs - ok
17:05:20.0496 2500 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
17:05:20.0496 2500 nsi - ok
17:05:20.0512 2500 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
17:05:20.0512 2500 nsiproxy - ok
17:05:20.0543 2500 [ C04F5DEF37E55F6A34428B050F44D3D6 ] nSvcIp C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
17:05:20.0543 2500 nSvcIp - ok
17:05:20.0606 2500 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
17:05:20.0621 2500 Ntfs - ok
17:05:20.0684 2500 [ BD691091AC7D9713D8F0B07C6B099E6C ] NTI IScheduleSvc C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
17:05:20.0684 2500 NTI IScheduleSvc - ok
17:05:20.0684 2500 [ 64DDD0DEE976302F4BD93E5EFCC2F013 ] NTIDrvr C:\Windows\system32\drivers\NTIDrvr.sys
17:05:20.0699 2500 NTIDrvr - ok
17:05:20.0699 2500 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
17:05:20.0699 2500 Null - ok
17:05:20.0730 2500 [ A85B4F2EF3A7304A5399EF0526423040 ] NVENETFD C:\Windows\system32\DRIVERS\nvm62x64.sys
17:05:20.0746 2500 NVENETFD - ok
17:05:20.0793 2500 [ 1F07B814C0BB5AABA703ABFF1F31F2E8 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys
17:05:20.0793 2500 NVHDA - ok
17:05:21.0011 2500 [ 5104BAC2DA2A5BDD86AC6B0708B00F06 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
17:05:21.0198 2500 nvlddmkm - ok
17:05:21.0261 2500 [ 0AD267A4674805B61A5D7B911D2A978A ] NVNET C:\Windows\system32\DRIVERS\nvmf6264.sys
17:05:21.0261 2500 NVNET - ok
17:05:21.0308 2500 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
17:05:21.0308 2500 nvraid - ok
17:05:21.0323 2500 [ E58D81FB8616D0CB55C1E36AA0B213C9 ] nvsmu C:\Windows\system32\DRIVERS\nvsmu.sys
17:05:21.0323 2500 nvsmu - ok
17:05:21.0354 2500 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
17:05:21.0354 2500 nvstor - ok
17:05:21.0401 2500 [ 1E45F96342429D63DC30E0D9117DA3D8 ] nvstor64 C:\Windows\system32\DRIVERS\nvstor64.sys
17:05:21.0401 2500 nvstor64 - ok
17:05:21.0448 2500 [ DDFAFCE89A5C93D04712B86F94E9FCBA ] nvsvc C:\Windows\system32\nvvsvc.exe
17:05:21.0464 2500 nvsvc - ok
17:05:21.0557 2500 [ 84E035225474E48CD3A6A3CE52332095 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
17:05:21.0588 2500 nvUpdatusService - ok
17:05:21.0620 2500 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
17:05:21.0620 2500 nv_agp - ok
17:05:21.0651 2500 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
17:05:21.0651 2500 ohci1394 - ok
17:05:21.0698 2500 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
17:05:21.0698 2500 p2pimsvc - ok
17:05:33.0195 2500 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
17:05:33.0195 2500 p2psvc - ok
17:05:38.0920 2500 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
17:05:38.0920 2500 Parport - ok
17:05:44.0614 2500 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
17:05:44.0614 2500 partmgr - ok
17:05:50.0308 2500 [ 8A0F8A9580D9F2FC512A35D5709088A9 ] pavboot C:\Windows\system32\drivers\pavboot64.sys
17:05:50.0308 2500 pavboot - ok
17:05:56.0033 2500 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
17:05:56.0033 2500 PcaSvc - ok
17:06:04.0613 2500 [ C10B593E2DEAA3B78A865DB539FDAE6C ] PCGenFam C:\Windows\system32\DRIVERS\PCGenFAM.sys
17:06:04.0613 2500 PCGenFam - ok
17:06:13.0006 2500 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
17:06:13.0006 2500 pci - ok
17:06:15.0908 2500 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
17:06:15.0908 2500 pciide - ok
17:06:24.0394 2500 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
17:06:24.0394 2500 pcmcia - ok
17:06:36.0125 2500 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
17:06:36.0125 2500 pcw - ok
17:06:50.0555 2500 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
17:06:50.0555 2500 PEAUTH - ok
17:07:05.0672 2500 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
17:07:05.0672 2500 PerfHost - ok
17:07:05.0812 2500 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
17:07:05.0843 2500 pla - ok
17:07:05.0890 2500 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
17:07:05.0890 2500 PlugPlay - ok
17:07:05.0952 2500 [ 5261A2FD55183AC6993145AB6662CDDF ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
17:07:05.0952 2500 Pml Driver HPZ12 - ok
17:07:05.0984 2500 [ A010F13D27C1033A8BE09D5FA9BF348B ] pneteth C:\Windows\system32\DRIVERS\pneteth.sys
17:07:05.0984 2500 pneteth - ok
17:07:06.0015 2500 PnkBstrA - ok
17:07:06.0030 2500 PnkBstrB - ok
17:07:06.0046 2500 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
17:07:06.0046 2500 PNRPAutoReg - ok
17:07:06.0093 2500 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
17:07:06.0093 2500 PNRPsvc - ok
17:07:06.0171 2500 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
17:07:06.0171 2500 PolicyAgent - ok
17:07:06.0218 2500 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
17:07:06.0218 2500 Power - ok
17:07:06.0249 2500 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
17:07:06.0249 2500 PptpMiniport - ok
17:07:06.0296 2500 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
17:07:06.0296 2500 Processor - ok
17:07:06.0327 2500 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
17:07:06.0342 2500 ProfSvc - ok
17:07:06.0358 2500 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
17:07:06.0358 2500 ProtectedStorage - ok
17:07:06.0405 2500 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
17:07:06.0405 2500 Psched - ok
17:07:06.0530 2500 [ FB46E9A827A8799EBD7BFA9128C91F37 ] PSI C:\Windows\system32\DRIVERS\psi_mf.sys
17:07:06.0530 2500 PSI - ok
17:07:06.0561 2500 [ DA3964D8FB8798DC741ABACA9ED1B99D ] pwdrvio C:\Windows\system32\pwdrvio.sys
17:07:06.0576 2500 pwdrvio - ok
17:07:06.0654 2500 [ A55ED5A63D0178A41EA05AC50A60F89A ] pwdspio C:\Windows\system32\pwdspio.sys
17:07:06.0654 2500 pwdspio - ok
17:07:06.0857 2500 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
17:07:06.0873 2500 ql2300 - ok
17:07:06.0920 2500 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
17:07:06.0920 2500 ql40xx - ok
17:07:06.0998 2500 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
17:07:07.0013 2500 QWAVE - ok
17:07:07.0013 2500 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
17:07:07.0013 2500 QWAVEdrv - ok
17:07:07.0044 2500 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
17:07:07.0060 2500 RasAcd - ok
17:07:07.0310 2500 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
17:07:07.0310 2500 RasAgileVpn - ok
17:07:07.0325 2500 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
17:07:07.0325 2500 RasAuto - ok
17:07:07.0388 2500 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
17:07:07.0388 2500 Rasl2tp - ok
17:07:07.0450 2500 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
17:07:07.0450 2500 RasMan - ok
17:07:07.0466 2500 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
17:07:07.0466 2500 RasPppoe - ok
17:07:07.0481 2500 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
17:07:07.0481 2500 RasSstp - ok
17:07:07.0528 2500 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
17:07:07.0528 2500 rdbss - ok
17:07:07.0544 2500 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
17:07:07.0544 2500 rdpbus - ok
17:07:07.0559 2500 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
17:07:07.0559 2500 RDPCDD - ok
17:07:07.0575 2500 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
17:07:07.0575 2500 RDPENCDD - ok
17:07:07.0590 2500 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
17:07:07.0590 2500 RDPREFMP - ok
17:07:07.0653 2500 [ 313F68E1A3E6345A4F47A36B07062F34 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
17:07:07.0653 2500 RdpVideoMiniport - ok
17:07:07.0684 2500 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
17:07:07.0684 2500 RDPWD - ok
17:07:07.0731 2500 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
17:07:07.0731 2500 rdyboost - ok
17:07:07.0762 2500 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
17:07:07.0762 2500 RemoteAccess - ok
17:07:07.0809 2500 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
17:07:07.0809 2500 RemoteRegistry - ok
17:07:07.0840 2500 [ 7B04C9843921AB1F695FB395422C5360 ] RimUsb C:\Windows\system32\Drivers\RimUsb_AMD64.sys
17:07:07.0840 2500 RimUsb - ok
17:07:07.0871 2500 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
17:07:07.0871 2500 RpcEptMapper - ok
17:07:07.0887 2500 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
17:07:07.0887 2500 RpcLocator - ok
17:07:07.0949 2500 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\System32\rpcss.dll
17:07:07.0949 2500 RpcSs - ok
17:07:07.0965 2500 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
17:07:07.0965 2500 rspndr - ok
17:07:08.0012 2500 [ 08D41F2633FC330749ABA842259483F8 ] SaiKF622 C:\Windows\system32\DRIVERS\SaiKF622.sys
17:07:08.0012 2500 SaiKF622 - ok
17:07:08.0043 2500 [ 296D0CC623EEB6D2B9800AD421F9116A ] SaiMini C:\Windows\system32\DRIVERS\SaiMini.sys
17:07:08.0043 2500 SaiMini - ok
17:07:08.0090 2500 [ 6A77D63B566DF14DA0E7DD0D2C594EF7 ] SaiNtBus C:\Windows\system32\drivers\SaiBus.sys
17:07:08.0090 2500 SaiNtBus - ok
17:07:08.0105 2500 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
17:07:08.0105 2500 SamSs - ok
17:07:08.0183 2500 [ 3289766038DB2CB14D07DC84392138D5 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
17:07:08.0183 2500 SASDIFSV - ok
17:07:08.0183 2500 [ 58A38E75F3316A83C23DF6173D41F2B5 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
17:07:08.0199 2500 SASKUTIL - ok
17:07:08.0261 2500 [ 554CB4C2E076CC0960D9E5590E4C7FA5 ] SbieDrv C:\Program Files\Sandboxie\SbieDrv.sys
17:07:08.0261 2500 SbieDrv - ok
17:07:08.0308 2500 [ 1BCC17921C3067CE5A6E480F3DAA6378 ] SbieSvc C:\Program Files\Sandboxie\SbieSvc.exe
17:07:08.0308 2500 SbieSvc - ok
17:07:08.0339 2500 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
17:07:08.0339 2500 sbp2port - ok
17:07:08.0386 2500 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
17:07:08.0386 2500 SCardSvr - ok
17:07:08.0417 2500 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
17:07:08.0417 2500 scfilter - ok
17:07:08.0464 2500 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
17:07:08.0480 2500 Schedule - ok
17:07:08.0526 2500 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
17:07:08.0526 2500 SCPolicySvc - ok
17:07:08.0558 2500 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
17:07:08.0558 2500 SDRSVC - ok
17:07:08.0589 2500 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
17:07:08.0589 2500 secdrv - ok
17:07:08.0620 2500 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
17:07:08.0620 2500 seclogon - ok
17:07:08.0698 2500 [ 5B66DB4877BBAC9F7493AA8D84421E49 ] Secunia PSI Agent C:\Program Files (x86)\Secunia\PSI\PSIA.exe
17:07:08.0714 2500 Secunia PSI Agent - ok
17:07:08.0948 2500 [ 0E88FDF474F2CDD370A4A6CE77D018F0 ] Secunia Update Agent C:\Program Files (x86)\Secunia\PSI\sua.exe
17:07:08.0963 2500 Secunia Update Agent - ok
17:07:08.0994 2500 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
17:07:08.0994 2500 SENS - ok
17:07:09.0026 2500 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
17:07:09.0026 2500 SensrSvc - ok
17:07:09.0041 2500 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
17:07:09.0041 2500 Serenum - ok
17:07:09.0057 2500 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
17:07:09.0057 2500 Serial - ok
17:07:09.0088 2500 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
17:07:09.0088 2500 sermouse - ok
17:07:09.0119 2500 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
17:07:09.0119 2500 SessionEnv - ok
17:07:09.0150 2500 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
17:07:09.0150 2500 sffdisk - ok
17:07:09.0150 2500 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
17:07:09.0166 2500 sffp_mmc - ok
17:07:09.0182 2500 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
17:07:09.0182 2500 sffp_sd - ok
17:07:09.0197 2500 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
17:07:09.0197 2500 sfloppy - ok
17:07:09.0244 2500 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
17:07:09.0244 2500 SharedAccess - ok
17:07:09.0291 2500 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:07:09.0306 2500 ShellHWDetection - ok
17:07:09.0306 2500 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
17:07:09.0306 2500 SiSRaid2 - ok
17:07:09.0322 2500 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
17:07:09.0322 2500 SiSRaid4 - ok
17:07:09.0369 2500 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
17:07:09.0369 2500 Smb - ok
17:07:09.0400 2500 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
17:07:09.0400 2500 SNMPTRAP - ok
17:07:09.0447 2500 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
17:07:09.0447 2500 spldr - ok
17:07:09.0509 2500 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
17:07:09.0509 2500 Spooler - ok
17:07:09.0603 2500 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
17:07:09.0650 2500 sppsvc - ok
17:07:09.0681 2500 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
17:07:09.0681 2500 sppuinotify - ok
17:07:09.0774 2500 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
17:07:09.0774 2500 srv - ok
17:07:09.0821 2500 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
17:07:09.0821 2500 srv2 - ok
17:07:09.0837 2500 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
17:07:09.0837 2500 srvnet - ok
17:07:09.0884 2500 [ 8F8324ED1DE63FFC7B1A02CD2D963C72 ] ssadbus C:\Windows\system32\DRIVERS\ssadbus.sys
17:07:09.0884 2500 ssadbus - ok
17:07:09.0915 2500 [ 58221EFCB74167B73667F0024C661CE0 ] ssadmdfl C:\Windows\system32\DRIVERS\ssadmdfl.sys
17:07:09.0915 2500 ssadmdfl - ok
17:07:09.0946 2500 [ 4DA7C71BFAC5AD71255B7E4CAB980163 ] ssadmdm C:\Windows\system32\DRIVERS\ssadmdm.sys
17:07:09.0946 2500 ssadmdm - ok
17:07:09.0977 2500 [ D33D1BD3EC0E766211A234F56A12726D ] ssadserd C:\Windows\system32\DRIVERS\ssadserd.sys
17:07:09.0977 2500 ssadserd - ok
17:07:10.0024 2500 [ ED161B91FDF7EAA39469D72D463D5F4E ] sscdbus C:\Windows\system32\DRIVERS\sscdbus.sys
17:07:10.0040 2500 sscdbus - ok
17:07:10.0086 2500 [ 4CB09E77593DBD8D7AF33B37375CA715 ] sscdmdfl C:\Windows\system32\DRIVERS\sscdmdfl.sys
17:07:10.0086 2500 sscdmdfl - ok
17:07:10.0133 2500 [ C7B4CF53497A6E5363F3439427663882 ] sscdmdm C:\Windows\system32\DRIVERS\sscdmdm.sys
17:07:10.0133 2500 sscdmdm - ok
17:07:10.0180 2500 [ 05FFA552F578E27AB2D41B6828DB477F ] sscdserd C:\Windows\system32\DRIVERS\sscdserd.sys
17:07:10.0180 2500 sscdserd - ok
17:07:10.0211 2500 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
17:07:10.0211 2500 SSDPSRV - ok
17:07:10.0242 2500 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
17:07:10.0242 2500 SstpSvc - ok
17:07:10.0289 2500 Steam Client Service - ok
17:07:10.0492 2500 [ F0359F7CE712D69ACEF0886BDB4792ED ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
17:07:10.0492 2500 Stereo Service - ok
17:07:10.0554 2500 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
17:07:10.0554 2500 stexstor - ok
17:07:10.0742 2500 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
17:07:10.0742 2500 stisvc - ok
17:07:10.0773 2500 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
17:07:10.0773 2500 swenum - ok
17:07:10.0835 2500 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
17:07:10.0835 2500 swprv - ok
17:07:10.0913 2500 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
17:07:10.0944 2500 SysMain - ok
17:07:10.0991 2500 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:07:10.0991 2500 TabletInputService - ok
17:07:11.0007 2500 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
17:07:11.0007 2500 TapiSrv - ok
17:07:11.0022 2500 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
17:07:11.0022 2500 TBS - ok
17:07:11.0100 2500 [ 37608401DFDB388CAF66917F6B2D6FB0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
17:07:11.0132 2500 Tcpip - ok
17:07:11.0178 2500 [ 37608401DFDB388CAF66917F6B2D6FB0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
17:07:11.0194 2500 TCPIP6 - ok
17:07:11.0225 2500 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
17:07:11.0225 2500 tcpipreg - ok
17:07:11.0256 2500 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
17:07:11.0272 2500 TDPIPE - ok
17:07:11.0303 2500 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
17:07:11.0303 2500 TDTCP - ok
17:07:11.0366 2500 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
17:07:11.0366 2500 tdx - ok
17:07:11.0412 2500 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
17:07:11.0412 2500 TermDD - ok
17:07:11.0459 2500 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
17:07:11.0459 2500 TermService - ok
17:07:11.0475 2500 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
17:07:11.0475 2500 Themes - ok
17:07:11.0537 2500 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
17:07:11.0537 2500 THREADORDER - ok
17:07:11.0553 2500 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
17:07:11.0553 2500 TrkWks - ok
17:07:11.0615 2500 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:07:11.0615 2500 TrustedInstaller - ok
17:07:11.0631 2500 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
17:07:11.0631 2500 tssecsrv - ok
17:07:11.0709 2500 [ 17C6B51CBCCDED95B3CC14E22791F85E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
17:07:11.0709 2500 TsUsbFlt - ok
17:07:11.0740 2500 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
17:07:11.0740 2500 tunnel - ok
17:07:11.0771 2500 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
17:07:11.0771 2500 uagp35 - ok
17:07:11.0787 2500 [ 2E22C1FD397A5A9FFEF55E9D1FC96C00 ] UBHelper C:\Windows\system32\drivers\UBHelper.sys
17:07:11.0787 2500 UBHelper - ok
17:07:11.0849 2500 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
17:07:11.0849 2500 udfs - ok
17:07:11.0880 2500 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
17:07:11.0880 2500 UI0Detect - ok
17:07:11.0896 2500 [ 49B13845F0DBE39B47FC91DC46B2170A ] UimBus C:\Windows\system32\DRIVERS\uimx64.sys
17:07:11.0896 2500 UimBus - ok
17:07:11.0927 2500 [ DD46BEC773C011EAA5E502C43A73A1CC ] Uim_IM C:\Windows\system32\Drivers\Uim_IMx64.sys
17:07:11.0943 2500 Uim_IM - ok
17:07:11.0974 2500 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
17:07:11.0974 2500 uliagpkx - ok
17:07:12.0005 2500 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys
17:07:12.0005 2500 umbus - ok
17:07:12.0021 2500 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
17:07:12.0021 2500 UmPass - ok
17:07:12.0083 2500 [ 70DDE3A86DBEB1D6C3C30AD687B1877A ] Updater Service C:\Program Files\Acer\Acer Updater\UpdaterService.exe
17:07:12.0083 2500 Updater Service - ok
17:07:12.0130 2500 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
17:07:12.0130 2500 upnphost - ok
17:07:12.0161 2500 [ 5FCC71487888589A9244AF54CFEFAB29 ] usbbus C:\Windows\system32\DRIVERS\lgx64bus.sys
17:07:12.0161 2500 usbbus - ok
17:07:12.0192 2500 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
17:07:12.0192 2500 usbccgp - ok
17:07:12.0224 2500 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
17:07:12.0224 2500 usbcir - ok
17:07:12.0270 2500 [ 3FB6E423F7567C92C32EA786F5FD0C69 ] UsbDiag C:\Windows\system32\DRIVERS\lgx64diag.sys
17:07:12.0270 2500 UsbDiag - ok
17:07:12.0286 2500 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
17:07:12.0286 2500 usbehci - ok
17:07:12.0317 2500 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
17:07:12.0317 2500 usbhub - ok
17:07:12.0348 2500 [ 78D551F5B93488B4666F5FC8DD4815F3 ] USBModem C:\Windows\system32\DRIVERS\lgx64modem.sys
17:07:12.0348 2500 USBModem - ok
17:07:12.0380 2500 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
17:07:12.0380 2500 usbohci - ok
17:07:12.0426 2500 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
17:07:12.0426 2500 usbprint - ok
17:07:12.0473 2500 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
17:07:12.0473 2500 usbscan - ok
17:07:12.0504 2500 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:07:12.0504 2500 USBSTOR - ok
17:07:12.0567 2500 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
17:07:12.0567 2500 usbuhci - ok
17:07:12.0614 2500 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
17:07:12.0614 2500 UxSms - ok
17:07:12.0801 2500 [ 81A9F455BF2C9180348949F7C8D93E66 ] VaneFltr C:\Windows\system32\drivers\Lachesis.sys
17:07:12.0801 2500 VaneFltr - ok
17:07:12.0816 2500 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
17:07:12.0816 2500 VaultSvc - ok
17:07:12.0848 2500 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
17:07:12.0848 2500 vdrvroot - ok
17:07:12.0879 2500 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
17:07:12.0879 2500 vds - ok
17:07:12.0941 2500 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
17:07:12.0941 2500 vga - ok
17:07:12.0957 2500 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
17:07:12.0957 2500 VgaSave - ok
17:07:13.0004 2500 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
17:07:13.0004 2500 vhdmp - ok
17:07:13.0035 2500 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
17:07:13.0035 2500 viaide - ok
17:07:13.0050 2500 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
17:07:13.0050 2500 volmgr - ok
17:07:13.0113 2500 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
17:07:13.0113 2500 volmgrx - ok
17:07:13.0128 2500 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
17:07:13.0128 2500 volsnap - ok
17:07:13.0160 2500 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
17:07:13.0160 2500 vsmraid - ok
17:07:13.0206 2500 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
17:07:13.0238 2500 VSS - ok
17:07:13.0253 2500 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
17:07:13.0269 2500 vwifibus - ok
17:07:13.0300 2500 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
17:07:13.0300 2500 W32Time - ok
17:07:13.0316 2500 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
17:07:13.0316 2500 WacomPen - ok
17:07:13.0347 2500 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
17:07:13.0347 2500 WANARP - ok
17:07:13.0347 2500 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
17:07:13.0347 2500 Wanarpv6 - ok
17:07:13.0409 2500 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
17:07:13.0425 2500 WatAdminSvc - ok
17:07:13.0487 2500 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
17:07:13.0503 2500 wbengine - ok
17:07:13.0534 2500 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
17:07:13.0534 2500 WbioSrvc - ok
17:07:13.0581 2500 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
17:07:13.0596 2500 wcncsvc - ok
17:07:13.0612 2500 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:07:13.0612 2500 WcsPlugInService - ok
17:07:13.0628 2500 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
17:07:13.0628 2500 Wd - ok
17:07:13.0674 2500 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
17:07:13.0674 2500 Wdf01000 - ok
17:07:13.0690 2500 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
17:07:13.0690 2500 WdiServiceHost - ok
17:07:13.0706 2500 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
17:07:13.0706 2500 WdiSystemHost - ok
17:07:13.0737 2500 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
17:07:13.0737 2500 WebClient - ok
17:07:13.0768 2500 [ D5BA7D43FA2EF656BF7E98A188391E40 ] Wecsvc C:\Windows\system32\wecsvc.dll
17:07:13.0768 2500 Wecsvc - ok
17:07:13.0784 2500 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
17:07:13.0784 2500 wercplsupport - ok
17:07:13.0799 2500 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
17:07:13.0799 2500 WerSvc - ok
17:07:13.0815 2500 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
17:07:13.0815 2500 WfpLwf - ok
17:07:13.0830 2500 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
17:07:13.0830 2500 WIMMount - ok
17:07:13.0862 2500 WinDefend - ok
17:07:13.0877 2500 WinHttpAutoProxySvc - ok
17:07:13.0955 2500 [ 136760C1E9697BAF4ECDEAE5590A0806 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
17:07:13.0955 2500 Winmgmt - ok
17:07:14.0080 2500 [ 3BB6B401A780BF434C8F58137DE10BF7 ] WinRM C:\Windows\system32\WsmSvc.dll
17:07:14.0127 2500 WinRM - ok
17:07:14.0158 2500 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
17:07:14.0158 2500 WinUsb - ok
17:07:14.0189 2500 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
17:07:14.0189 2500 Wlansvc - ok
17:07:14.0345 2500 [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
17:07:14.0376 2500 wlidsvc - ok
17:07:14.0408 2500 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
17:07:14.0408 2500 WmiAcpi - ok
17:07:14.0439 2500 [ 4DF841632B62A7CF19A79A05046A8AB1 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
17:07:14.0439 2500 wmiApSrv - ok
17:07:14.0454 2500 WMPNetworkSvc - ok
17:07:14.0486 2500 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
17:07:14.0501 2500 WPCSvc - ok
17:07:14.0517 2500 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
17:07:14.0532 2500 WPDBusEnum - ok
17:07:14.0579 2500 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
17:07:14.0579 2500 ws2ifsl - ok
17:07:14.0610 2500 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
17:07:14.0610 2500 wscsvc - ok
17:07:14.0626 2500 WSearch - ok
17:07:14.0844 2500 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
17:07:14.0938 2500 wuauserv - ok
17:07:15.0094 2500 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
17:07:15.0094 2500 WudfPf - ok
17:07:15.0141 2500 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
17:07:15.0156 2500 WUDFRd - ok
17:07:15.0203 2500 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
17:07:15.0203 2500 wudfsvc - ok
17:07:15.0234 2500 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
17:07:15.0234 2500 WwanSvc - ok
17:07:15.0281 2500 [ 2EE48CFCE7CA8E0DB4C44C7476C0943B ] xusb21 C:\Windows\system32\DRIVERS\xusb21.sys
17:07:15.0281 2500 xusb21 - ok
17:07:15.0406 2500 [ DD0042F0C3B606A6A8B92D49AFB18AD6 ] YahooAUService C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
17:07:15.0422 2500 YahooAUService - ok
17:07:15.0453 2500 ================ Scan global ===============================
17:07:15.0500 2500 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
17:07:15.0546 2500 [ 72CC564BBC70DE268784BCE91EB8A28F ] C:\Windows\system32\winsrv.dll
17:07:15.0562 2500 [ 72CC564BBC70DE268784BCE91EB8A28F ] C:\Windows\system32\winsrv.dll
17:07:15.0609 2500 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
17:07:15.0687 2500 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
17:07:15.0687 2500 [Global] - ok
17:07:15.0687 2500 ================ Scan MBR ==================================
17:07:15.0718 2500 [ 70E629B51C16B3C007730C6AE57144C9 ] \Device\Harddisk0\DR0
17:07:17.0933 2500 \Device\Harddisk0\DR0 - ok
17:07:17.0933 2500 ================ Scan VBR ==================================
17:07:17.0964 2500 [ 022497C1B7BCAD2D5CEEA13EDFA891A2 ] \Device\Harddisk0\DR0\Partition1
17:07:17.0964 2500 \Device\Harddisk0\DR0\Partition1 - ok
17:07:17.0996 2500 [ 6B5EE86C7E81C29076F016557E47BAF5 ] \Device\Harddisk0\DR0\Partition2
17:07:17.0996 2500 \Device\Harddisk0\DR0\Partition2 - ok
17:07:17.0996 2500 ============================================================
17:07:17.0996 2500 Scan finished
17:07:17.0996 2500 ============================================================
17:07:18.0011 4848 Detected object count: 0
17:07:18.0011 4848 Actual detected object count: 0
17:07:44.0344 1912 Deinitialize success
Also here is the log from Malwarebytes.
Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org
Database version: v2013.01.02.03
Windows 7 Service Pack 1 x64 NTFS (Safe Mode/Networking)
Internet Explorer 9.0.8112.16421
Zanthia :: FAMILY [administrator]
1/2/2013 1:08:40 AM
mbam-log-2013-01-02 (01-08-40).txt
Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 810621
Time elapsed: 1 hour(s), 37 minute(s), 45 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 65
HKCR\CLSID\{08fbcb5f-de4f-49e0-977e-e4269f4d7206} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{8b4c0e7e-23f4-419f-814e-957e905c31f3} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{0DB657AC-FA16-4F01-AADF-023D29F75D62} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.SettingsPlugin.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.SettingsPlugin (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08FBCB5F-DE4F-49E0-977E-E4269F4D7206} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GamingWonderlandbar Uninstall (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{44eaf1f4-7ff5-4b15-9bee-522532831236} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{6c71ddef-4c18-4fbc-aac2-d397ca175626} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{206F84B4-A5BC-448E-BB07-C091E2CA3F17} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{6fba26f4-e7c7-4db3-9276-a3312ccf07d0} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{2a5fb2eb-3559-4ad3-8d61-3cd3e8528fa6} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{2E252970-F6F6-46DA-B9A5-FEF849174D84} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{f4b1272e-0cb2-488c-9fa7-320e55fb8307} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.DynamicBarButton.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.DynamicBarButton (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{e71835ec-50b3-4409-a418-cca38afc49b1} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{1ba8c07d-d46c-444b-bf2c-577bd961d2e4} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{7975C249-952B-40B1-937F-F79986B47081} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.FeedManager.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.FeedManager (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{26A73C38-B71A-4D3A-80B7-E010420DA1E7} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.HTMLMenu.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.HTMLMenu (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{26A73C38-B71A-4D3A-80B7-E010420DA1E7} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{9634ef63-f560-4ece-b213-aee5667d7c3c} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{98840585-a9cf-477a-b7d4-81ce1fb1c2e4} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{B5923F3E-B4BC-4FB5-8318-9DFDF1BC7889} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{aa59b2d8-edd2-4730-8efb-c266e75e1168} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.MultipleButton.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.MultipleButton (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{1a30aa28-2fc6-4360-9e14-cfa627d51b6c} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{7494f5bf-10b7-4d2f-b90f-dfea50616a3e} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{5E394D6E-A48F-428C-9A87-DA32C2A57346} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.XMLSessionPlugin.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.XMLSessionPlugin (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1A30AA28-2FC6-4360-9E14-CFA627D51B6C} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{7bff5694-a950-4d01-a2fa-d5aea811d201} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{ac88eb5d-de86-4519-8b73-a4d677965b8c} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{66706B98-BBBD-4633-B2B4-1B8AD9EA8487} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.RadioSettings.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.RadioSettings (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{ed1ac743-8648-4e55-9104-a0c74baba152} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.ScriptButton.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.ScriptButton (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{0c7bac04-8f5d-4bbd-956a-34fafa547752} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{5e579db7-8e17-4137-b1e0-fd9dcb35f528} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{C2AA38BF-2179-45CB-9EF0-C9A555F4354F} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0C7BAC04-8F5D-4BBD-956A-34FAFA547752} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{ab5d199e-9659-47a2-930b-fc3b69061353} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{f4d7584b-6643-4bc7-8e24-17c3258dc5ef} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{5e302f1c-2e1f-4df7-bb17-687ccf9a8de2} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{0D49EF2C-6D09-4FE0-A26E-7301D89245C7} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.ThirdPartyInstaller.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.ThirdPartyInstaller (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F4D7584B-6643-4BC7-8E24-17C3258DC5EF} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{dd51557a-1bdc-473a-b9fd-b0d195155da8} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.UrlAlertButton.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.UrlAlertButton (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\CLSID\{99c8d756-4d22-4d0f-898a-34a232884ce1} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\TypeLib\{970f08a0-2151-4f81-91d9-3c5e5c9a6861} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\Interface\{1998CE9F-20C5-4EC7-80A8-0F6F8A2411E8} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.HTMLPanel.1 (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKCR\GamingWonderland.HTMLPanel (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{99C8D756-4D22-4D0F-898A-34A232884CE1} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 33
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtauxstb.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtbar.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtbrmon.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtbrstub.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtdatact.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtdlghk.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtdyn.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtfeedmg.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gthighin.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gthkstub.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gthtmlmu.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gthttpct.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtidle.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtieovr.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtimpipe.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtmedint.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtmlbtn.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtmsg.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtPlugin.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtradio.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtregfft.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtreghk.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtregiet.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtscript.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtskin.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtskplay.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtSrcAs.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtSrchMn.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gttpinst.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\gtuabtn.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\NPgtStub.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\GamingWonderland\bar\2.bin\T8HTML.DLL (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files (x86)\QPST\Scramp\Scramp.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
(end)
My wifes account is not running very good either, do the fixes you require also help with other accounts?
With only one exception on my own personal machines, I use ALL free security tools. I do not subscribe to the theory that paid is better. So we will be using free toos to clean your machine, and any recommendations for the future will be free tools. You don't need to worry about that at allI cannot afford to buy the better antivirus and protection software out there. I use Gizmo's site for help in determining the best free tools to use for my system.
We'll work on the issues you've been having with them, but these are the antivirus (AV) and firewall I use. I know there has been alot of talk about MSE recently, but I still firmly believe it's one of best AV programs out there and I personally stand by it as a great option! I think in conjunction with regular scans from Malwarebytes you have a fine choice of security products on your machine.MSE and windows firewall are the only tools I currently use for protection
It does appear that the full scan from Malwarebytes (MBAM) has removed quite a bit now that you've gotten it to run. It does run with Administrator privledges so it should have addressed all user accounts on your machine.
The O10 entries in your HijackThis log were fine they are from Windows Live and nothing to worry about. However, I can see some concerning items and while the tools we will run in a moment would likely take care of them, I'd like to go ahead with a quick fix in Hijack this anyway.
Run Hijack This
- Right-click and choose Run as Administrator on the icon on your desktop to launch Hijack This
- Click on the Scan button
- When the scan has finished, please put a check in the box next to the following item:
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.privitize.com/?aff=7
O2 - BHO: wxDownload - {95B741CB-CF8A-6780-C5F6-FF7C39EA7BCE} - C:\ProgramData\wxDownload\50c64c701d1de.ocx
O20 - AppInit_DLLs: c:\PROGRA~2\WXDOWN~1\SPROTE~1.DLL
- Make sure all other windows, including your browser are closed, and then click on the Fix Checked button
Download and Install Combofix
Download ComboFix from one of the following locations:
Link 1
Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
- Double click on ComboFix.exe & follow the prompts.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing anything, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
If you have a problem launching programs after running Combofix, please do not panic! Simply reboot the computer and all should be fine.
I also had you remove two entries that were trojan downloaders. So in all liklihood, there are still some remnants we need to find that are causing IE to misbehave.
Let's have you go to Start > Control Panel > Internet Options > Connections > Click on the LAN Settings Button
Ensure that the checkbox for Automatically Detect Settings is Checked.
Thenk click OK, OK and close your Control Panel
Although I have one file I'd like to have you check online, I do have a fix I'd like you to run now that has to do with those files I already had you remove with HijackThis that I don't want to wait to remove.
Also, since your wife plays a lot of games, we are going to clear the Java Cache where infections are known to hide. You may want to let her know that some of her scores may disappear. Sorry, but it's better to be safe.
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quotebox below into it:
Folder::
c:\programdata\wxDownload
c:\program files (x86)\WxDownload
ClearJavaCache::
Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe
[external image: Posted Image]
Refering to the picture above, drag CFScript into ComboFix.exe. ComboFix may request an update; please allow it.
When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
We need to get additional information about a file as it can be good or bad and we should confirm this one.
Please go to the following site:
http://www.virustotal.com/
Click on Choose File, and then upload the following file for analysis:
c:\programdata\Premium\OptimizerPro\OptimizerPro.exe
Then click Send File and allow the file to be scanned.
Please ensure the scan is complete and the results saved before submitting the next.
If a pop-up appears saying the file has been scanned already, please select the ReScan button.
Please copy and paste the links to each of the results here for me.
Here is a tool that will painless remove a large number of toolbars and potentially unwanted junkware that can get installed along with other programs. Please note your wife may not be happy after you run this but you will probably notice improvements.
[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
- Shut down your protection software now to avoid potential conflicts.
- Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
- The tool will open and start scanning your system.
- Please be patient as this can take a while to complete depending on your system's specifications.
- On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
- Post the contents of JRT.txt into your next message.
Please let me know how the machine is runninge, especially Internet Explorer after all this.
The file c:\programdata\Premium\OptimizerPro\OptimizerPro.exe was no longer available to load on Virus Total. It must have been eliminated by one of the ComboFix or other scans because I can't find it even with the search tool. Other than that everything else ran fine and here are teh logs you need.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.3.8 (01.03.2013:2)
OS: Windows 7 Home Premium x64
Ran by [removed] on Sat 01/05/2013 at 9:50:21.46
Blog: http://thisisudax.blogspot.com
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] hkey_local_machine\software\conduit
Successfully deleted: [Registry Key] hkey_local_machine\software\default tab
Successfully deleted: [Registry Key] hkey_local_machine\software\freeze.com
Successfully deleted: [Registry Key] hkey_local_machine\software\iminent
Successfully deleted: [Registry Key] hkey_local_machine\software\sweetim
Successfully deleted: [Registry Key] hkey_local_machine\software\visualbee
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\conduit
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\iehelperv2.5.0.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\applications\ilividsetupv1.exe
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\iehelperv250.wecarereminder
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\iehelperv250.wecarereminder.1
Successfully deleted: [Registry Key] hkey_local_machine\software\wow6432node\microsoft\tracing\ilividsetupv1_rasapi32
Successfully deleted: [Registry Key] hkey_local_machine\software\wow6432node\microsoft\tracing\ilividsetupv1_rasmancs
Successfully deleted: [Registry Key] hkey_local_machine\software\wow6432node\sp global
Successfully deleted: [Registry Key] hkey_local_machine\software\wow6432node\sprotector
Successfully deleted: [Registry Key-Heur] HKEY_LOCAL_MACHINE\software\classes\Toolbar.CT3244149
Successfully deleted: [Registry Key-Heur] HKEY_LOCAL_MACHINE\software\classes\Toolbar.CT3268494
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{02478d38-c3f9-4efb-9b51-7695eca05670}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{3c471948-f874-49f5-b338-4f214a2ee0b1}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{7f6afbf1-e065-4627-a2fd-810366367d01}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{7f6afbf1-e065-4627-a2fd-810366367d01}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{d824f0de-3d60-4f57-9eb1-66033ecd8abb}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{d824f0de-3d60-4f57-9eb1-66033ecd8abb}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\installmate"
Successfully deleted: [Folder] "C:\ProgramData\premium"
Successfully deleted: [Folder] "C:\ProgramData\soluto"
Successfully deleted: [Folder] "C:\ProgramData\visualbee"
Successfully deleted: [Folder] "C:\Users\Bryan\appdata\local\conduit"
Successfully deleted: [Folder] "C:\Users\Bryan\appdata\local\swvupdater"
Successfully deleted: [Folder] "C:\Users\Bryan\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\Bryan\appdata\locallow\pricegong"
Successfully deleted: [Folder] "C:\Program Files (x86)\conduit"
Successfully deleted: [Folder] "C:\Program Files (x86)\gamingwonderland"
~~~ Chrome
Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\ippkomaaonokjnfjoikaemidanojkfmm
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 01/05/2013 at 9:56:40.85
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
ComboFix 13-01-05.01 - Bryan 01/05/2013 10:03:37.12.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3839.2397 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Bryan\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\WxDownload
c:\program files (x86)\WxDownload\sprotector.dll
c:\program files (x86)\WxDownload\uninstall.exe
c:\programdata\wxDownload
c:\programdata\wxDownload\50c64c701d216.html
c:\programdata\wxDownload\50c64c701d24f.js
c:\programdata\wxDownload\data\50c64c701d24f.js
c:\programdata\wxDownload\data\jsondb.js
c:\programdata\wxDownload\hpocchkfefabpamkoefnpoappdpdmman.crx
c:\programdata\wxDownload\settings.ini
c:\programdata\wxDownload\uninstall.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-12-05 to 2013-01-05 )))))))))))))))))))))))))))))))
.
.
2013-01-05 07:36 . 2012-11-08 17:24 9125352 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BAA689D2-EA2A-4B56-935D-0D85AE6F3C0D}\mpengine.dll
2013-01-05 07:22 . 2012-11-08 17:24 9125352 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-01-04 01:19 . 2013-01-04 01:19 ——– d—–w- C:\FRST
2013-01-03 05:55 . 2013-01-03 05:55 ——– d—–w- c:\users\Zanthia.Family\AppData\Roaming\SUPERAntiSpyware.com
2013-01-02 22:58 . 2013-01-02 22:58 388096 —-a-r- c:\users\Bryan\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2013-01-02 21:28 . 2013-01-02 21:28 ——– d—–w- c:\program files\WOT
2013-01-02 18:17 . 2013-01-04 17:21 ——– d—–w- c:\windows\system32\%LocalAppData%
2013-01-02 08:50 . 2013-01-02 08:50 65736 —-a-w- c:\windows\system32\drivers\pxrts.sys
2013-01-02 08:50 . 2013-01-02 08:50 ——– d—–w- c:\program files\Prevx
2013-01-02 08:49 . 2013-01-02 22:24 ——– d—–w- c:\programdata\PrevxCSI
2013-01-02 06:33 . 2013-01-03 06:59 ——– d—–w- c:\windows\system32\catroot2
2013-01-02 01:32 . 2013-01-02 01:32 32152 —-a-w- c:\windows\system32\drivers\hitmanpro37.sys
2013-01-02 01:19 . 2013-01-02 01:19 ——– d—–w- c:\users\Betty\AppData\Roaming\Malwarebytes
2013-01-02 01:05 . 2013-01-02 01:05 208216 —-a-w- c:\windows\system32\drivers\34792715.sys
2013-01-02 00:40 . 2013-01-02 00:40 ——– d—–w- c:\users\Administrator.Family
2013-01-02 00:11 . 2013-01-02 00:11 ——– d—–w- C:\found.003
2013-01-01 23:25 . 2013-01-01 23:25 ——– d—–w- C:\found.002
2013-01-01 21:58 . 2013-01-01 22:09 ——– d—–w- c:\users\TEMP
2012-12-31 21:24 . 2012-12-31 21:24 ——– d—–w- C:\found.001
2012-12-30 17:07 . 2012-12-30 17:07 ——– d—–w- C:\found.000
2012-12-30 17:01 . 2012-12-30 17:01 ——– d—–w- c:\users\Bryan\AppData\Local\Programs
2012-12-25 16:59 . 2012-12-25 19:37 ——– d—–w- c:\users\Bryan\AppData\Roaming\Apple Computer
2012-12-25 16:59 . 2012-12-25 16:59 ——– d—–w- c:\users\Bryan\AppData\Local\Apple Computer
2012-12-24 23:03 . 2009-06-30 18:37 33800 —-a-w- c:\windows\system32\drivers\pavboot64.sys
2012-12-24 23:02 . 2012-12-24 23:02 ——– d—–w- c:\program files (x86)\Panda Security
2012-12-24 23:02 . 2012-12-24 23:02 ——– d—–w- c:\windows\AxInstSV
2012-12-22 23:20 . 2012-12-22 23:20 ——– d—–w- c:\program files (x86)\Common Files\Simple Adblock
2012-12-22 17:01 . 2012-12-16 17:11 46080 —-a-w- c:\windows\system32\atmlib.dll
2012-12-22 17:01 . 2012-12-16 14:13 34304 —-a-w- c:\windows\SysWow64\atmlib.dll
2012-12-22 17:01 . 2012-12-16 14:45 367616 —-a-w- c:\windows\system32\atmfd.dll
2012-12-22 17:01 . 2012-12-16 14:13 295424 —-a-w- c:\windows\SysWow64\atmfd.dll
2012-12-21 08:53 . 2012-12-21 08:53 ——– d—–w- c:\users\Bryan\AppData\Local\TunaMediaLtd
2012-12-21 08:53 . 2012-12-21 08:53 ——– d—–w- c:\program files (x86)\TunaMediaLtd
2012-12-21 08:52 . 2012-12-21 08:52 ——– d—–w- c:\users\Bryan\AppData\Local\Downloaded Installations
2012-12-15 08:04 . 2012-12-15 08:04 ——– d—–w- c:\users\Bryan\AppData\Roaming\SystemRequirementsLab
2012-12-15 07:14 . 2012-12-15 07:14 ——– d—–w- c:\users\Bryan\AppData\Local\4A Games
2012-12-13 20:55 . 2012-12-13 22:43 ——– d—–w- c:\users\Bryan\AppData\Local\DownTango
2012-12-13 20:55 . 2012-12-13 20:55 ——– d—–w- c:\program files (x86)\Red Sky
2012-12-12 09:54 . 2012-12-12 09:54 ——– d—–w- c:\windows\Migration
2012-12-12 09:52 . 2012-08-21 14:20 46080 —-a-w- c:\windows\SysWow64\ncobjapi.dll
2012-12-12 09:52 . 2012-08-21 13:49 58368 —-a-w- c:\windows\system32\ncobjapi.dll
2012-12-12 09:52 . 2012-08-21 13:12 74240 —-a-w- c:\windows\system32\wbem\NCProv.dll
2012-12-12 09:45 . 2012-11-14 05:52 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-12-12 09:44 . 2012-11-14 06:04 1392128 —-a-w- c:\windows\system32\wininet.dll
2012-12-12 09:41 . 2012-11-09 05:45 2048 —-a-w- c:\windows\system32\tzres.dll
2012-12-12 09:41 . 2012-11-09 04:42 2048 —-a-w- c:\windows\SysWow64\tzres.dll
2012-12-12 09:38 . 2012-11-02 05:59 478208 —-a-w- c:\windows\system32\dpnet.dll
2012-12-12 09:38 . 2012-11-02 05:11 376832 —-a-w- c:\windows\SysWow64\dpnet.dll
2012-12-12 09:06 . 2012-12-12 09:06 77 —-a-w- C:\prefs.js
2012-12-12 06:40 . 2012-12-12 06:40 ——– d—–w- c:\users\Zanthia.Family\AppData\Local\LogMeIn
2012-12-12 06:28 . 2012-12-12 06:28 ——– d—–w- c:\users\Betty\AppData\Local\LogMeIn
2012-12-12 06:02 . 2012-12-12 06:02 ——– d—–w- C:\e
2012-12-12 05:58 . 2013-01-02 07:55 ——– d—–w- c:\users\Bryan\AppData\Roaming\DefaultTab
2012-12-11 22:54 . 2012-12-11 22:54 ——– d—–w- c:\users\Bryan\AppData\Local\LogMeIn
2012-12-11 22:54 . 2012-10-20 02:10 60328 —-a-w- c:\windows\system32\Spool\prtprocs\x64\LMIproc.dll
2012-12-11 22:54 . 2012-10-20 02:10 35240 —-a-w- c:\windows\system32\LMIport.dll
2012-12-11 22:54 . 2012-10-20 02:11 88008 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-12-11 22:54 . 2012-08-24 22:41 72216 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2012-12-11 22:54 . 2012-10-20 02:10 83880 —-a-w- c:\windows\system32\LMIinit.dll
2012-12-11 22:54 . 2012-12-18 21:15 ——– d—–w- c:\programdata\LogMeIn
2012-12-11 22:54 . 2012-12-11 22:54 ——– d—–w- c:\program files (x86)\LogMeIn
2012-12-11 22:52 . 2012-12-11 22:52 ——– d—–w- c:\users\Bryan\AppData\Local\Deployment
2012-12-10 21:14 . 2012-12-10 21:14 ——– d—–w- c:\users\Bryan\AppData\Local\PutLockerDownloader
2012-12-10 20:40 . 2012-12-10 20:40 ——– d—–w- c:\program files (x86)\wxDownload Fast
2012-12-08 08:22 . 2012-12-08 08:22 ——– d—–w- c:\program files (x86)\Gophoto.it
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-02 06:23 . 2012-11-26 20:16 181064 —-a-w- c:\windows\PSEXESVC.EXE
2012-12-15 00:49 . 2012-09-19 15:27 24176 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-12-12 09:29 . 2012-04-13 22:07 697272 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-12-12 09:29 . 2011-11-07 17:34 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-11-28 23:58 . 2010-05-03 07:57 67413224 —-a-w- c:\windows\system32\MRT.exe
2012-11-28 20:58 . 2012-11-28 20:58 972264 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2D6959E6-5002-4EB6-9262-45F89279A03E}\gapaengine.dll
2012-11-26 22:43 . 2012-11-28 20:58 972192 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2012-11-08 17:24 . 2012-11-25 00:41 9125352 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F82B904F-663A-4D41-AFCA-F49ACDF967A6}\mpengine.dll
2012-10-30 23:51 . 2012-11-16 10:05 41224 —-a-w- c:\windows\avastSS.scr
2012-10-30 23:50 . 2012-11-16 10:05 227648 —-a-w- c:\windows\SysWow64\aswBoot.exe
2012-10-25 11:12 . 2012-10-25 11:12 94208 —-a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2012-10-25 11:12 . 2012-10-25 11:12 69632 —-a-w- c:\windows\SysWow64\QuickTime.qts
2012-10-23 15:39 . 2012-10-23 15:40 108008 —-a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2012-10-23 15:39 . 2011-12-22 23:57 1034216 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-10-23 15:39 . 2010-07-26 21:02 916456 —-a-w- c:\windows\system32\deployJava1.dll
2012-10-16 08:38 . 2012-11-27 19:27 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38 . 2012-11-27 19:27 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39 . 2012-11-27 19:27 561664 —-a-w- c:\windows\apppatch\AcLayers.dll
2012-10-09 18:17 . 2012-11-14 16:14 55296 —-a-w- c:\windows\system32\dhcpcsvc6.dll
2012-10-09 18:17 . 2012-11-14 16:14 226816 —-a-w- c:\windows\system32\dhcpcore6.dll
2012-10-09 17:40 . 2012-11-14 16:14 44032 —-a-w- c:\windows\SysWow64\dhcpcsvc6.dll
2012-10-09 17:40 . 2012-11-14 16:14 193536 —-a-w- c:\windows\SysWow64\dhcpcore6.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-06 39408]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2011-10-13 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"RequireSignedAppInit_DLLs"=0 (0x0)
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R0 hqmpym;hqmpym; [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 ALSysIO;ALSysIO;c:\users\Bryan\AppData\Local\Temp\ALSysIO64.sys [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2011-05-13 36328]
R3 easytether;easytether;c:\windows\system32\DRIVERS\easytthr.sys [x]
R3 hitmanpro37;HitmanPro 3.7 Support Driver;c:\windows\system32\drivers\hitmanpro37.sys [2013-01-02 32152]
R3 MEMSWEEP2;MEMSWEEP2;c:\windows\system32\7114.tmp [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-08-31 128456]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-09-13 368896]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 40464]
R3 PCGenFam;PCGenFam;c:\windows\system32\DRIVERS\PCGenFAM.sys [2010-11-02 198088]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2011-05-06 19936]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2011-05-06 13280]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 SaiKF622;SaiKF622;c:\windows\system32\DRIVERS\SaiKF622.sys [2009-06-02 140800]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 VaneFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2007-08-17 30336]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-03 1255736]
S0 hotcore3;hc3ServiceName;c:\windows\system32\DRIVERS\hotcore3.sys [2011-01-21 37456]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot64.sys [2009-06-30 33800]
S1 GIDv2;GIDv2; [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 22576]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 20016]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60464]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-10-06 140672]
S2 Greg_Service;GRegService;c:\program files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-10-20 375728]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2012-08-24 15928]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-08-12 62208]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2011-10-14 994360]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2011-10-14 399416]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-10-02 382824]
S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
S3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys [2011-11-25 15360]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 17976]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{9191979D-821C-4EA8-B021-2DA1D859A7C5}-3Reg]
2011-07-05 17:26 435976 —-a-w- c:\program files (x86)\SFT\GuardedID\GIDI.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-01-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 09:29]
.
2013-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28]
.
2013-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-05-03 10:28]
.
2013-01-05 c:\windows\Tasks\WpsUpdateTask_Bryan.job
- c:\program files (x86)\Kingsoft\Kingsoft Office\office6\wpsupdate.exe [2012-09-17 16:00]
.
.
——— X64 Entries ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-07 10144288]
"PLD_FrameworkRun"="c:\windows\system32\oem\_NowIntoDT.vbs" [2009-10-11 490]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-22 2327952]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-13 1289704]
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://msn.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearchAssistant =
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
FF - ProfilePath -
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{a8a9d26a-734f-467a-8907-176f9c5bdf56} - (no file)
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} - (no file)
AddRemove-DefaultTab - c:\users\Bryan\AppData\Roaming\DefaultTab\DefaultTab\uninstalldt.exe
AddRemove-GamesBar - c:\program files (x86)\GamesBar\uninst.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_heroes.exe
AddRemove-SP_0beb79c1 - c:\program files (x86)\WxDownload\uninstall.exe
AddRemove-{088DF54D-6FFC-8C91-02D5-A461DCC2E652} - c:\programdata\wxDownload\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\7114.tmp"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,60,b7,6e,ff,df,50,47,be,ce,3c,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*]
"value"="?\03\04\16\176\1e?"
.
Completion time: 2013-01-05 10:15:35
ComboFix-quarantined-files.txt 2013-01-05 18:15
ComboFix2.txt 2013-01-04 19:11
.
Pre-Run: 607,632,191,488 bytes free
Post-Run: 608,152,727,552 bytes free
.
- - End Of File - - C29C07C597B49F8D630F7BBB30367307
Let me know what you need done. Thanks.
I see you have Malwarebytes already on your machine. Please run it by right-clicking and choosing Run as Administrator on the icon on the desktop let's see if we can get it to run now.
- Click on the tab labeled Update and then click on the button Check for updates.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select Perform quick scan, then click Scan.
[external image: Posted Image] - When the scan is complete, click OK, then Show Results to view the results.
- Be sure that everything is checked, and click Remove Selected .
- When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
- Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.
Go here to run an online scannner from ESET.
- Note: For browsers other than Internet Explorer, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
- Turn off the real time scanner of any existing antivirus program while performing the online scan
- Tick the box next to YES, I accept the Terms of Use.
- Click Start
- When asked, allow the activex control to install
- Click Start
- Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
- Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
- Click Scan
- Wait for the scan to finish
- Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
- Copy and paste that log as a reply to this topic and also let me know how things are now.
If it doesn't find anything there will be no log to post.
Overall how does the machine seem to be running now?
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quotebox below into it:
File::
C:\backup\sdcard\Verbous_GenoCYde.version.666.zip
C:\backup\sdcard\back up\Removable Disk\Admiral-Beast-CWM.zip
C:\backup\sdcopy\back up\Removable Disk\Admiral-Beast-CWM.zip
C:\New folder (2)\Removable Disk\back up\Removable Disk\Admiral-Beast-CWM.zip
C:\Program Files (x86)\Trend Micro\HijackThis\backups\backup-20130104-104458-268.dll
C:\Users\Bryan\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]\chrome\pptextlinks.jar
C:\Users\Bryan\Desktop\sd card bu\appmonster2\backup\great.app.luck\rev\19.apk
C:\Users\Bryan\Desktop\sd card bu\App_Manager\App_Backups\user_apps\great.app.luck.apk
C:\Users\Bryan\Desktop\sd card bu\TitaniumBackup\great.app.luck-73d83b0622200494240f8460c0a9cfa7.apk.gz
C:\Users\Bryan\Desktop\sd card bu\TitaniumBackup\mobi.mgeek.TunnyBrowser-b32e904a89df7510548bb253d28cbce0.apk.gz
C:\Users\Bryan\Documents\back up\Removable Disk\Admiral-Beast-CWM.zip
C:\Users\Bryan\Downloads\Admiral-Beast-CWM.zip
C:\Users\Bryan\Downloads\Avengers_Reborn_Verbous.zip
C:\Users\Bryan\Downloads\Black_Ice.zip
C:\Users\Bryan\Downloads\Eternal_Ecstasy.zip
C:\Users\Bryan\Downloads\The_Walking_Dead_Comic_(1-93)_downloader_99132.exe
C:\Users\Bryan\Downloads\Titanium_Vip-A-Rom.zip
C:\Users\Bryan\Downloads\Verbous_GenoCYde.version.666.2.zip
Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe
[external image: Posted Image]
Refering to the picture above, drag CFScript into ComboFix.exe. ComboFix may request an update; please allow it.
When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
How is the machine running, is everything doing ok at this point? Any problems on your account or your wife's? Any BSOD's? Shut downs? And most importantly is safe mode working again?
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI