This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow Internet [Solved]

69 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

1. I have a slow internet and my connection drops a lot. My ISP suggested that I might have a virus. I have 3 computers to check.

Computer #1 is my most important computer as I work from home and need it for that. I will start with it.

OTL logfile created on: 03/01/2013 3:28:49 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Karri\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

7.93 Gb Total Physical Memory | 2.99 Gb Available Physical Memory | 37.72% Memory free
16.07 Gb Paging File | 8.76 Gb Available in Paging File | 54.51% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.59 Gb Total Space | 70.86 Gb Free Space | 30.47% Space Free | Partition Type: NTFS
Drive D: | 348.93 Gb Total Space | 92.10 Gb Free Space | 26.40% Space Free | Partition Type: NTFS
Drive J: | 295.02 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive N: | 3.79 Gb Total Space | 3.79 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive O: | 930.95 Gb Total Space | 813.57 Gb Free Space | 87.39% Space Free | Partition Type: FAT32

Computer Name: KARRI-PC | User Name: Karri | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/01/03 15:28:41 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Karri\Desktop\OTL.exe
PRC - [2012/12/20 13:13:01 | 000,541,760 | —- | M] (Valve Corporation) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe
PRC - [2012/12/14 04:17:04 | 003,467,768 | —- | M] (TeamViewer GmbH) – C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
PRC - [2012/12/14 04:17:03 | 009,876,472 | —- | M] (TeamViewer GmbH) – C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
PRC - [2012/12/14 04:08:24 | 000,190,968 | —- | M] (TeamViewer GmbH) – C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
PRC - [2012/12/04 07:57:14 | 001,354,736 | —- | M] (Valve Corporation) – C:\Program Files (x86)\Steam\Steam.exe
PRC - [2012/11/28 15:17:53 | 000,040,376 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Program Files (x86)\Citrix\GoToMeeting\1060\g2mstart.exe
PRC - [2012/11/28 15:17:53 | 000,040,376 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Program Files (x86)\Citrix\GoToMeeting\1060\g2mlauncher.exe
PRC - [2012/11/28 15:17:53 | 000,040,376 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Program Files (x86)\Citrix\GoToMeeting\1060\g2mcomm.exe
PRC - [2012/11/14 13:45:40 | 001,831,936 | —- | M] (Livedrive Internet Ltd) – C:\Program Files (x86)\Livedrive\Livedrive.exe
PRC - [2012/10/26 12:17:52 | 000,079,384 | —- | M] (Google) – C:\Users\Karri\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
PRC - [2012/10/10 21:23:42 | 001,258,856 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012/10/04 12:47:20 | 027,112,568 | —- | M] (ooVoo LLC) – C:\Program Files (x86)\ooVoo\ooVoo.exe
PRC - [2012/10/02 13:15:38 | 000,382,824 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012/09/28 20:44:54 | 012,105,344 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Lync\communicator.exe
PRC - [2012/08/30 15:16:16 | 000,310,920 | —- | M] (Pelmorex Media Inc.) – C:\Users\Karri\AppData\Local\The Weather Network\weathereye.exe
PRC - [2012/08/08 14:18:52 | 000,348,664 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012/07/27 15:51:28 | 001,498,552 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
PRC - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/17 17:45:12 | 000,079,872 | —- | M] (SanDisk Corporation) – C:\Users\Karri\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
PRC - [2012/05/02 00:42:31 | 000,086,224 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012/05/01 23:34:37 | 000,110,032 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/08/19 04:26:50 | 000,450,848 | —- | M] (Logitech Inc.) – C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe
PRC - [2011/08/12 12:18:42 | 000,205,336 | —- | M] (Logitech Inc.) – C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
PRC - [2011/02/09 14:00:00 | 000,610,120 | R— | M] (WinZip Computing, S.L.) – C:\Program Files (x86)\WinZip\WZQKPICK.EXE
PRC - [2010/10/29 15:06:08 | 005,915,480 | —- | M] (Logitech Inc.) – C:\Program Files (x86)\Logitech\Vid HD\Vid.exe
PRC - [2009/05/15 06:35:52 | 000,935,208 | —- | M] (Nero AG) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2009/04/23 08:51:38 | 000,691,656 | —- | M] (DT Soft Ltd) – C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe
PRC - [2008/09/11 15:19:28 | 000,105,504 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdateService.exe
PRC - [2008/09/11 15:19:26 | 000,068,640 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdate.exe
PRC - [2008/09/11 15:19:14 | 000,179,232 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaMonitorService.exe
PRC - [2008/09/11 15:19:12 | 000,322,592 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaService.exe
PRC - [2008/08/01 14:30:28 | 000,501,760 | —- | M] () – C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe
PRC - [2008/07/29 16:53:00 | 000,500,784 | —- | M] (Egis Incorporated) – C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
PRC - [2008/07/29 16:52:56 | 000,454,704 | —- | M] (Egis inc.) – C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe
PRC - [2008/07/20 16:45:06 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/07/20 16:45:06 | 000,182,808 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/06/23 12:12:52 | 000,174,616 | —- | M] (Intel Corporation) – C:\Program Files\Intel\AMT\LMS.exe
PRC - [2008/05/20 16:50:50 | 000,269,448 | —- | M] (CyberLink) – C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe


========== Modules (No Company Name) ==========

MOD - [2012/12/20 13:13:10 | 000,647,168 | —- | M] () – C:\Program Files (x86)\Steam\sdl.dll
MOD - [2012/12/20 13:13:00 | 020,320,240 | —- | M] () – C:\Program Files (x86)\Steam\bin\libcef.dll
MOD - [2012/12/20 13:12:58 | 000,969,280 | —- | M] () – C:\Program Files (x86)\Steam\bin\chromehtml.dll
MOD - [2012/12/20 13:12:56 | 000,124,416 | —- | M] () – C:\Program Files (x86)\Steam\bin\avutil-51.dll
MOD - [2012/12/20 13:12:54 | 000,192,000 | —- | M] () – C:\Program Files (x86)\Steam\bin\avformat-53.dll
MOD - [2012/12/20 13:12:52 | 001,100,800 | —- | M] () – C:\Program Files (x86)\Steam\bin\avcodec-53.dll
MOD - [2012/12/04 20:15:15 | 012,456,040 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll
MOD - [2012/12/04 20:15:15 | 000,460,904 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppgooglenaclpluginchrome.dll
MOD - [2012/12/04 20:15:14 | 004,008,040 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
MOD - [2012/12/04 20:14:29 | 000,587,880 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\libglesv2.dll
MOD - [2012/12/04 20:14:28 | 000,124,520 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\libegl.dll
MOD - [2012/12/04 20:14:21 | 000,157,304 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\avutil-51.dll
MOD - [2012/12/04 20:14:20 | 000,275,576 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\avformat-54.dll
MOD - [2012/12/04 20:14:19 | 002,168,952 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\avcodec-54.dll
MOD - [2012/11/21 11:19:12 | 000,059,392 | —- | M] () – C:\Users\Karri\AppData\Local\Temp\{1d478740-1c26-43ed-9b9e-2f8938b03192}\Livedrive.Native.dll
MOD - [2012/11/18 09:00:54 | 000,998,400 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\d08cb6b1c4052e6f5a4e2452870d67d7\System.Management.ni.dll
MOD - [2012/11/18 09:00:04 | 001,840,640 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\7844c1ae91c8f584025756ad72e65176\System.Web.Services.ni.dll
MOD - [2012/11/18 08:59:55 | 001,116,672 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\6082261ca7c89e5c073a073fdd851572\System.DirectoryServices.ni.dll
MOD - [2012/11/18 08:59:55 | 000,627,200 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\850a371af19c00078a8cfbee763fb449\System.Transactions.ni.dll
MOD - [2012/11/18 08:59:54 | 000,627,712 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\1f0ff07c7fa3ef235a9e2b3b6a49db04\System.EnterpriseServices.ni.dll
MOD - [2012/11/18 08:59:50 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\7f15d0cb7e4f87f86e425d5ffe7e8280\System.Configuration.ni.dll
MOD - [2012/11/18 08:46:58 | 005,450,752 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\741164a3e36f879b9f9e3ff176465127\System.Xml.ni.dll
MOD - [2012/11/18 08:46:46 | 012,433,920 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\22e554f2c4da53c07e4815a24e2d50e2\System.Windows.Forms.ni.dll
MOD - [2012/11/18 08:46:38 | 001,592,320 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\2c6cd37f29fc76d6c2ed6bbed202d82c\System.Drawing.ni.dll
MOD - [2012/11/18 08:46:26 | 006,621,696 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\ee724aeea5f1b9d8a01fa6047fd2ef99\System.Data.ni.dll
MOD - [2012/11/18 08:45:49 | 007,976,960 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\b2052acbbbba4f98585196872195e009\System.ni.dll
MOD - [2012/11/18 08:45:43 | 011,492,352 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7ad9c44df3b85848590e63f13fc59804\mscorlib.ni.dll
MOD - [2012/11/14 13:43:48 | 000,781,312 | —- | M] () – C:\Program Files (x86)\Livedrive\Livedrive.Localisation.dll
MOD - [2012/07/27 15:51:28 | 000,249,272 | —- | M] () – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\sqlite.dll
MOD - [2011/09/27 06:23:00 | 000,087,912 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 06:22:40 | 001,242,472 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/08/19 04:26:16 | 000,183,320 | —- | M] () – C:\Program Files (x86)\Common Files\LogiShrd\SharedBin\LvApi11.dll
MOD - [2011/08/12 12:18:56 | 000,342,552 | —- | M] () – C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTXml4.dll
MOD - [2011/08/12 12:18:56 | 000,128,536 | —- | M] () – C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll
MOD - [2011/08/12 12:18:56 | 000,029,208 | —- | M] () – C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll
MOD - [2011/08/12 12:18:54 | 007,956,504 | —- | M] () – C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTGui4.dll
MOD - [2011/08/12 12:18:54 | 002,145,304 | —- | M] () – C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTCore4.dll
MOD - [2011/07/28 15:20:34 | 000,270,336 | —- | M] () – C:\Program Files (x86)\Livedrive\AlphaFS.dll
MOD - [2011/03/17 00:11:16 | 004,297,568 | —- | M] () – C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/29 15:02:38 | 000,751,616 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\vpxmd.dll
MOD - [2010/10/29 15:01:30 | 000,027,472 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\SDL.dll
MOD - [2010/10/20 15:45:26 | 008,801,120 | —- | M] () – C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2009/04/22 16:53:56 | 000,969,040 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtNetwork4.dll
MOD - [2009/04/09 18:04:56 | 002,141,008 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtCore4.dll
MOD - [2009/03/29 23:42:19 | 000,261,632 | —- | M] () – C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2009/03/29 23:42:17 | 002,933,760 | —- | M] () – C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2009/03/03 17:18:08 | 000,138,064 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qjpeg4.dll
MOD - [2009/03/03 17:18:06 | 000,035,152 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qico4.dll
MOD - [2009/03/03 17:18:06 | 000,029,008 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qgif4.dll
MOD - [2009/03/03 17:17:46 | 011,311,952 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtWebKit4.dll
MOD - [2009/03/03 17:17:46 | 000,363,856 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtXml4.dll
MOD - [2009/03/03 17:17:44 | 000,200,016 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtSql4.dll
MOD - [2009/03/03 17:17:40 | 000,475,472 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtOpenGL4.dll
MOD - [2009/03/03 17:17:38 | 007,704,400 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtGui4.dll
MOD - [2009/03/03 17:17:32 | 000,291,664 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\phonon4.dll
MOD - [2008/08/01 14:30:28 | 000,501,760 | —- | M] () – C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe
MOD - [2008/04/28 08:49:18 | 000,002,560 | —- | M] () – C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTrayLOC.dll
MOD - [2007/07/11 12:27:24 | 000,400,896 | —- | M] () – C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQDEVCL.dll
MOD - [2007/06/24 15:14:52 | 000,029,696 | —- | M] () – C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMDLL.DLL


========== Services (SafeList) ==========

SRV:64bit: - [2012/10/14 23:20:08 | 000,026,760 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Dynamics CRM\Client\bin\CrmSqlStartupSvc.exe – (CrmSqlStartupSvc)
SRV:64bit: - [2010/02/02 18:03:04 | 000,015,768 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe – (c2wts)
SRV:64bit: - [2008/07/16 12:50:24 | 002,476,432 | —- | M] (Intel® Corporation) [Auto | Running] – C:\Program Files\Intel\inteldh\msm\MSM.exe – (ME Services Manager)
SRV:64bit: - [2008/07/16 12:44:02 | 000,068,496 | —- | M] (Intel® Corporation) [Auto | Running] – C:\Program Files\Intel\inteldh\common\IntelDHSvcMgr.exe – (Software Services Manager)
SRV:64bit: - [2008/06/23 12:12:52 | 000,174,616 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\AMT\LMS.exe – (LMS)
SRV:64bit: - [2008/06/02 08:25:40 | 000,024,576 | —- | M] () [Auto | Running] – C:\Program Files\Acer\Empowering Technology\Service\ETService.exe – (ETService)
SRV:64bit: - [2008/01/20 21:47:32 | 000,383,544 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2012/12/20 13:13:01 | 000,541,760 | —- | M] (Valve Corporation) [On_Demand | Running] – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2012/12/19 08:28:50 | 000,250,808 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/12/14 04:17:04 | 003,467,768 | —- | M] (TeamViewer GmbH) [Auto | Running] – C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe – (TeamViewer8)
SRV - [2012/12/05 16:29:30 | 000,115,168 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/11/14 13:48:28 | 000,210,144 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Livedrive\VSSService.exe – (LivedriveVSSService)
SRV - [2012/10/10 21:23:42 | 001,258,856 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe – (nvUpdatusService)
SRV - [2012/10/02 13:15:38 | 000,382,824 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe – (Stereo Service)
SRV - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/05/02 00:42:31 | 000,086,224 | —- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe – (AntiVirSchedulerService)
SRV - [2012/05/01 23:34:37 | 000,110,032 | —- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe – (AntiVirService)
SRV - [2011/08/19 04:26:50 | 000,450,848 | —- | M] (Logitech Inc.) [Auto | Running] – C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe – (UMVPFSrv)
SRV - [2010/03/18 12:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/05/15 06:35:52 | 000,935,208 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe – (Nero BackItUp Scheduler 4.0)
SRV - [2009/03/29 23:42:14 | 000,066,368 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2008/09/11 15:19:28 | 000,105,504 | —- | M] (CyberLink) [Auto | Running] – C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdateService.exe – (CyberLink Live Push Update Service)
SRV - [2008/09/11 15:19:14 | 000,179,232 | —- | M] (CyberLink) [Auto | Running] – C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaMonitorService.exe – (CyberLink Live Monitor Service)
SRV - [2008/09/11 15:19:12 | 000,322,592 | —- | M] (CyberLink Corp.) [Auto | Running] – C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaService.exe – (CyberLink Live Service)
SRV - [2008/07/29 16:53:00 | 000,500,784 | —- | M] (Egis Incorporated) [Auto | Running] – C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe – (eDataSecurity Service)
SRV - [2008/07/20 16:45:06 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON)
SRV - [2008/05/20 16:50:50 | 000,269,448 | —- | M] (CyberLink) [Auto | Running] – C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe – (Acer HomeMedia Connect Service)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/11/10 10:50:36 | 000,352,008 | —- | M] (EldoS Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\cbfs3.sys – (cbfs3)
DRV:64bit: - [2012/08/21 12:01:20 | 000,033,240 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2012/07/09 12:42:54 | 000,052,736 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2012/05/02 14:24:12 | 000,027,760 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\Windows\SysNative\DRIVERS\avkmgr.sys – (avkmgr)
DRV:64bit: - [2012/04/27 09:20:04 | 000,132,832 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\Windows\SysNative\DRIVERS\avipbb.sys – (avipbb)
DRV:64bit: - [2012/04/24 23:32:27 | 000,098,848 | —- | M] (Avira GmbH) [File_System | Auto | Running] – C:\Windows\SysNative\DRIVERS\avgntflt.sys – (avgntflt)
DRV:64bit: - [2012/02/29 08:52:46 | 000,016,384 | —- | M] (Microsoft Corporation) [Recognizer | System | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/08/19 04:27:30 | 004,869,024 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\lvuvc64.sys – (LVUVC64)
DRV:64bit: - [2011/08/19 04:27:30 | 000,351,136 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\lvrs64.sys – (LVRS64)
DRV:64bit: - [2009/11/20 14:26:50 | 000,031,232 | —- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\tap0901.sys – (tap0901)
DRV:64bit: - [2009/09/30 19:51:42 | 000,046,592 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\wpdusb.sys – (WpdUsb)
DRV:64bit: - [2009/08/06 11:52:34 | 000,871,408 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\sptd.sys – (sptd)
DRV:64bit: - [2009/05/09 00:14:20 | 000,015,752 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\NuidFltr.sys – (NuidFltr)
DRV:64bit: - [2008/08/13 21:18:54 | 008,029,792 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\igdkmd64.sys – (igfx)
DRV:64bit: - [2008/07/29 16:53:50 | 000,060,976 | —- | M] (Egis Incorporated) [Kernel | Auto | Running] – C:\Windows\SysNative\DRIVERS\PSDVdisk.sys – (psdvdisk)
DRV:64bit: - [2008/07/29 16:53:50 | 000,021,040 | —- | M] (Egis Incorporated) [Kernel | Auto | Running] – C:\Windows\SysNative\DRIVERS\PSDNServ.sys – (PSDNServ)
DRV:64bit: - [2008/07/29 16:53:48 | 000,022,064 | —- | M] (Egis Incorporated) [File_System | Boot | Running] – C:\Windows\SysNative\DRIVERS\psdfilter.sys – (PSDFilter)
DRV:64bit: - [2008/07/25 04:26:20 | 000,315,008 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\e1y60x64.sys – (e1yexpress)
DRV:64bit: - [2008/07/20 04:44:54 | 000,402,456 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\DRIVERS\iaStor.sys – (iaStor)
DRV:64bit: - [2008/07/14 19:20:42 | 000,126,464 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\IntcHdmi.sys – (IntcHdmiAddService)
DRV:64bit: - [2008/03/28 11:42:58 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\HECIx64.sys – (HECIx64)
DRV:64bit: - [2008/01/30 19:48:32 | 000,016,384 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\NTIDrvr.sys – (NTIDrvr)
DRV:64bit: - [2008/01/30 19:48:16 | 000,016,384 | —- | M] (NewTech Infosystems Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\UBHelper.sys – (UBHelper)
DRV - [2008/06/02 08:20:12 | 000,017,952 | —- | M] (Acer, Inc.) [Kernel | Auto | Running] – C:\Windows\SysWOW64\drivers\int15_64.sys – (int15)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE - HKLM\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyn0.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACAW
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://global.acer.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyn0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: CFBFAE00-17A6-11D0-99CB-00C04FD64497} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACAW
IE - HKCU\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms}
IE - HKCU\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.theweathernetwork.com/weather/caon0532"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}:6.0.30
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_38: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Users\Karri\AppData\Local\Citrix\Plugins\79\npappdetector.dll (Citrix Online)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Karri\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Karri\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Karri\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Karri\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/12/05 16:29:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/12/05 16:29:26 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/12/05 16:29:30 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/12/05 16:29:26 | 000,000,000 | —D | M]

[2009/10/29 12:03:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Karri\AppData\Roaming\Mozilla\Extensions
[2009/10/29 12:03:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Karri\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/10/26 01:50:20 | 000,000,000 | —D | M] (No name found) – C:\Users\Karri\AppData\Roaming\Mozilla\Firefox\Profiles\3rkyge3u.default\extensions
[2011/10/15 13:35:37 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Karri\AppData\Roaming\Mozilla\Firefox\Profiles\3rkyge3u.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/08/06 11:56:41 | 000,002,399 | —- | M] () – C:\Users\Karri\AppData\Roaming\Mozilla\Firefox\Profiles\3rkyge3u.default\searchplugins\daemon-search.xml
[2012/12/28 23:43:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/12/05 16:29:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/12/05 16:29:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012/12/05 16:29:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2012/12/28 23:43:40 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA}
[2012/12/05 16:29:30 | 000,262,112 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/09/28 20:39:06 | 000,031,872 | —- | M] () – C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll
[2012/09/24 16:21:50 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/12/05 16:29:29 | 000,002,058 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.theweathernetwork.com/weather/caon0532
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter}
CHR - homepage: http://www.theweathernetwork.com/weather/caon0532
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Karri\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Karri\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Oberon com adapter (Enabled) = C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Java™ Platform SE 6 U32 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.320.5 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Karri\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Entanglement = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.9_0\
CHR - Extension: AT_JamesWhite = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkeidgmehkdjmpjodpjkepolokanalkm\3\
CHR - Extension: AdBlock = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.54_0\
CHR - Extension: Poppit = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\

O1 HOSTS File: ([2013/01/03 08:12:30 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\ActiveToolBand.dll (Egis)
O2:64bit: - BHO: (BrowserHelper Class) - {EDF48A39-1442-463F-9F4E-F376A78D034A} - C:\Program Files (x86)\Livedrive\LivedriveExplorerExtensions.dll (Livedrive Internet Ltd)
O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyn0.dll (Conduit Ltd.)
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll File not found
O3:64bit: - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll (Egis Incorporated.)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKLM\..\Toolbar: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyn0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll (Egis Incorporated.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Zynga Toolbar) - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - C:\Program Files (x86)\Zynga\tbZyn0.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [Acer Empowering Technology Monitor] C:\Program Files\Acer\Empowering Technology\SysMonitor.exe ()
O4:64bit: - HKLM..\Run: [eDataSecurity Loader] C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe (Egis Incorporated)
O4:64bit: - HKLM..\Run: [EmpoweringTechnology] C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe boot File not found
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelSWUpdateClient] C:\Program Files\Intel\inteldh\common\SWUpdateClient.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Acer Assist Launcher] C:\Program Files (x86)\Acer\Acer Assist\launcher.exe ()
O4 - HKLM..\Run: [Acer Product Registration] C:\Program Files (x86)\Acer\Acer Registration\ACE1.exe (Leader Technologies)
O4 - HKLM..\Run: [ACQTMOUSE] C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [CLPushUpdate] C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdate.exe (CyberLink)
O4 - HKLM..\Run: [Communicator] C:\Program Files (x86)\Microsoft Lync\communicator.exe (Microsoft Corporation)
O4 - HKLM..\Run: [DivXMediaServer] "C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe" File not found
O4 - HKLM..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [PCMMediaSharing] C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe ()
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent File not found
O4 - HKCU..\Run: [EADM] C:\Program Files (x86)\Origin\Origin.exe (Electronic Arts)
O4 - HKCU..\Run: [GoToMeeting] C:\Program Files (x86)\Citrix\GoToMeeting\1060\g2mstart.exe (Citrix Online, a division of Citrix Systems, Inc.)
O4 - HKCU..\Run: [Livedrive] C:\Program Files (x86)\Livedrive\Livedrive.exe (Livedrive Internet Ltd)
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files (x86)\Logitech\Vid HD\Vid.exe (Logitech Inc.)
O4 - HKCU..\Run: [ooVoo.exe] C:\Program Files (x86)\ooVoo\oovoo.exe (ooVoo LLC)
O4 - HKCU..\Run: [SansaDispatch] C:\Users\Karri\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [WeatherEye] C:\Users\Karri\AppData\Local\The Weather Network\weathereye.exe (Pelmorex Media Inc.)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O9 - Extra Button: Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aboriginallink.ca ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: aboriginallink.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: dynamics.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: live.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoftonline.com ([portal] https in Trusted sites)
O15 - HKCU\..Trusted Domains: outlook.com ([]http in Trusted sites)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} http://www.shockwave.com/content/trijinx/s…nx.1.0.0.86.cab (CPlayFirstTriJinxControl Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_38)
O16 - DPF: {CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_38)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_38)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3DF7249C-DC40-4434-8123-8375B94A51F0}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\intu-qt2008 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-qt2009 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-tt2010 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-tt2011 - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\intu-qt2008 {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - C:\Program Files (x86)\QuickTax 2008\ic2008pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files (x86)\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-tt2010 {97A0575E-2309-4e75-8509-B1F9390C4DE7} - C:\Program Files (x86)\TurboTax 2010\ic2010pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-tt2011 {B3B5DAD9-E96D-45b4-B636-B6CF2F773DE1} - C:\Program Files (x86)\TurboTax 2011\ic2011pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysNative\CbFsMntNtf3.dll (EldoS Corporation)
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
O22:64bit: - SharedTaskScheduler: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - Virtual Storage Mount Notification - C:\Windows\SysNative\CbFsMntNtf3.dll (EldoS Corporation)
O22 - SharedTaskScheduler: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - Virtual Storage Mount Notification - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img16.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img16.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/24 10:26:00 | 000,000,740 | R— | M] () - J:\autorun.inf – [ UDF ]
O32 - Unable to obtain root file information for disk N:\
O32 - Unable to obtain root file information for disk O:\
O33 - MountPoints2\{a4b61a9e-df1e-11e1-aff1-00219761ce94}\Shell\AutoRun\command - "" = J:\fscommand\LS_Start_Launch.exe – [2010/05/10 13:00:11 | 000,151,040 | R— | M] ()
O33 - MountPoints2\{a4b61a9e-df1e-11e1-aff1-00219761ce94}\Shell\Launcher\command - "" = J:\Get_Started_with_LifeStudio.exe – [2010/05/10 13:00:13 | 003,478,888 | R— | M] (Adobe Systems, Inc.)
O33 - MountPoints2\{a4b61b3b-df1e-11e1-aff1-00219761ce94}\Shell\AutoRun\command - "" = N:\fscommand\LS_Start_Launch.exe
O33 - MountPoints2\{a4b61b3b-df1e-11e1-aff1-00219761ce94}\Shell\Launcher\command - "" = N:\Get_Started_with_LifeStudio.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/01/03 15:28:39 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Karri\Desktop\OTL.exe
[2013/01/03 08:16:20 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{3858D4CE-7BC8-4FE8-9F1E-F3F94A633EFD}
[2013/01/02 15:49:38 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\ooVoo Details
[2013/01/02 15:49:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ooVoo
[2013/01/02 15:49:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\ooVoo
[2013/01/02 15:39:54 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2013/01/02 15:39:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2013/01/02 15:25:53 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\Yahoo!
[2013/01/02 15:17:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Yahoo!
[2013/01/02 15:16:04 | 000,439,704 | —- | C] (Yahoo! Inc.) – C:\Users\Karri\Desktop\msgr11us.exe
[2013/01/02 09:23:29 | 015,271,824 | —- | C] (Google Inc.) – C:\Users\Karri\Desktop\picasa39-setup.exe
[2013/01/02 08:12:35 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{10BF1A49-4693-4220-A360-114CA5DDC371}
[2013/01/01 10:41:28 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{86E62FE5-66DA-4681-AE2C-76E89E9BC9DD}
[2012/12/31 07:33:55 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{87035D76-36ED-4720-BF9B-830C39E20E79}
[2012/12/30 11:42:34 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{91A02224-9FFD-4884-8A5A-7F1D116DD04D}
[2012/12/28 23:43:35 | 000,157,680 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2012/12/28 23:43:35 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2012/12/28 23:43:35 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2012/12/28 18:58:45 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{184713FA-E986-4774-94A8-A2A93B6AD872}
[2012/12/23 09:17:29 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{0CB37340-0337-46FF-802E-71CB478313AD}
[2012/12/21 23:44:49 | 000,368,128 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2012/12/21 23:44:49 | 000,293,376 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2012/12/21 23:44:49 | 000,048,128 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2012/12/21 23:44:49 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2012/12/21 08:52:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/12/21 07:38:56 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{3FBDA6A9-2EFD-4BDB-A67E-2F015241502F}
[2012/12/20 08:04:19 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{A92265B7-2452-434A-9E9C-3A6977E6589B}
[2012/12/19 15:46:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/12/19 15:46:26 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/12/19 15:46:24 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/12/19 15:46:24 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2012/12/19 07:57:25 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{7AF64024-6B51-43B7-B313-07638ED02640}
[2012/12/14 13:18:51 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Regina Qu'Appelle Health Region
[2012/12/14 12:52:10 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Porcupine Health Unit
[2012/12/14 12:45:41 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Ontario Hospital Association
[2012/12/14 08:42:45 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Weather Network
[2012/12/14 08:42:41 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\The Weather Network
[2012/12/14 08:40:20 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{7069D2AB-F115-4928-B074-71ACB02FC834}
[2012/12/14 08:17:15 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\NVIDIA
[2012/12/13 15:04:37 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Timmins and District Hospital
[2012/12/13 14:59:30 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\North Bay Regional Health Centre
[2012/12/13 08:15:05 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{AF641A64-E0DF-4E17-92D3-BF9AC3E13389}
[2012/12/12 21:10:05 | 000,054,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdfLdr.sys
[2012/12/12 21:10:05 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Wdfres.dll
[2012/12/12 21:10:03 | 000,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFPlatform.dll
[2012/12/12 21:10:03 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winusb.dll
[2012/12/12 21:10:02 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFx.dll
[2012/12/12 21:10:02 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFHost.exe
[2012/12/12 21:10:02 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFCoinstaller.dll
[2012/12/12 21:09:16 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/12/12 21:09:16 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/12/12 21:09:16 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/12/12 21:09:15 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/12/12 21:09:15 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/12/12 21:09:15 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/12/12 21:09:15 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/12/12 21:09:15 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/12/12 21:09:15 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/12/12 21:09:14 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/12/12 21:09:14 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/12/12 21:09:14 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/12/12 21:09:13 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/12/12 21:09:13 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/12/12 21:09:13 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/12/12 16:03:15 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Atlantic Aboriginal health Research Program
[2012/12/12 14:18:55 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Health Sciences North - Sudbury
[2012/12/12 14:16:52 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Patient Voices Network
[2012/12/12 04:19:36 | 001,210,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2012/12/12 04:19:29 | 000,477,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnet.dll
[2012/12/12 04:19:29 | 000,376,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnet.dll
[2012/12/12 04:19:29 | 000,068,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnathlp.dll
[2012/12/12 04:19:29 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnsvr.exe
[2012/12/12 04:19:29 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnsvr.exe
[2012/12/11 21:17:55 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{A122EF8E-C279-47A0-BF6B-64C219125E8A}
[2012/12/11 13:56:12 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Citrix
[2012/12/11 13:31:44 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Dilico
[2012/12/11 13:26:33 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\St. Joseph's Care Group
[2012/12/11 13:23:55 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Thunder Bay Community Economic Development Commission
[2012/12/11 13:14:39 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Confederation College
[2012/12/11 08:03:42 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{0CD10092-4D8A-4B3A-8161-1F0997E76605}
[2012/12/10 16:13:05 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Victoria General Hospital
[2012/12/10 15:54:56 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Concordia Hospital
[2012/12/10 15:28:35 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Seven Oaks General Hospital
[2012/12/10 15:15:41 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Norwest Community Health Centres
[2012/12/10 14:38:54 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\LogMeIn Rescue Applet
[2012/12/10 13:20:27 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Sault Area Hospital
[2012/12/10 13:10:20 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Thunder Bay Regional Health Sciences Centre
[2012/12/10 12:56:56 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Health Sciences Centre Winnipeg
[2012/12/10 07:55:58 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{A4C7EEF5-843F-4720-BD17-CDD942FA9120}
[2012/12/09 13:18:37 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{57AECE94-BF36-4E90-B2D7-1A5F166C5616}
[2012/12/07 09:58:45 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Northern Ontario School of Medicine (NOSM)
[2012/12/07 09:40:22 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Couchiching Family Health Team
[2012/12/07 08:10:59 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{1B7C379E-2F27-4C8B-9C7D-26384FDECA9E}
[2012/12/06 07:31:52 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{B4D454D9-8266-474A-B661-688CEE1665A5}
[2012/12/05 16:29:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012/12/05 11:00:52 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Northern Health
[2012/12/05 11:00:35 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Opening Scripts
[2012/12/05 07:36:50 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{2C228139-8687-43F2-9088-E478BB61A606}

========== Files - Modified Within 30 Days ==========

[2013/01/03 15:29:11 | 000,025,854 | —- | M] () – C:\Users\Karri\Desktop\R110829104.20130102.pdf
[2013/01/03 15:28:41 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Karri\Desktop\OTL.exe
[2013/01/03 15:27:59 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/01/03 15:20:22 | 000,002,559 | —- | M] () – C:\Users\Karri\Desktop\HiJackThis.lnk
[2013/01/03 14:39:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3989614313-289073978-4266361891-1000UA.job
[2013/01/03 14:15:29 | 000,201,281 | —- | M] () – C:\Users\Karri\Desktop\27292_10151363206356049_672386584_n.jpg
[2013/01/03 14:12:21 | 000,003,344 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/03 14:12:21 | 000,003,344 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/03 08:12:30 | 000,000,761 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/01/03 08:12:20 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/01/02 15:49:32 | 000,001,772 | —- | M] () – C:\Users\Public\Desktop\ooVoo.lnk
[2013/01/02 15:24:12 | 001,402,880 | —- | M] () – C:\Users\Karri\Desktop\HiJackThis.msi
[2013/01/02 15:23:40 | 000,004,824 | —- | M] () – C:\Windows\wininit.ini
[2013/01/02 15:16:34 | 000,439,704 | —- | M] (Yahoo! Inc.) – C:\Users\Karri\Desktop\msgr11us.exe
[2013/01/02 11:24:00 | 000,132,078 | —- | M] () – C:\Users\Karri\Desktop\Scandinavian.jpg
[2013/01/02 11:19:14 | 000,432,213 | —- | M] () – C:\Users\Karri\Desktop\Video call snapshot 48.png
[2013/01/02 09:25:01 | 000,000,969 | —- | M] () – C:\Users\Karri\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2013/01/02 09:25:01 | 000,000,945 | —- | M] () – C:\Users\Public\Desktop\Picasa 3.lnk
[2013/01/02 09:24:05 | 015,271,824 | —- | M] (Google Inc.) – C:\Users\Karri\Desktop\picasa39-setup.exe
[2012/12/31 21:39:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3989614313-289073978-4266361891-1000Core.job
[2012/12/22 13:58:20 | 000,092,623 | —- | M] () – C:\Users\Karri\Desktop\16800_10151343017346049_1636654817_n.jpg
[2012/12/22 08:29:40 | 000,393,856 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/12/21 14:36:44 | 000,051,335 | —- | M] () – C:\Users\Karri\Desktop\224562_10150266265914978_307550646_n.jpg
[2012/12/21 14:34:55 | 000,027,506 | —- | M] () – C:\Users\Karri\Desktop\17082_548427821850478_1374715143_n.jpg
[2012/12/21 08:52:23 | 000,000,905 | —- | M] () – C:\Users\Public\Desktop\VLC media player.lnk
[2012/12/19 15:46:48 | 000,001,698 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/12/19 11:15:11 | 000,001,001 | —- | M] () – C:\Users\Public\Desktop\TeamViewer 8.lnk
[2012/12/19 08:28:50 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/12/19 08:28:50 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/12/18 07:31:32 | 000,652,288 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/12/18 07:31:31 | 000,766,246 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/12/18 07:31:31 | 000,125,686 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/12/16 08:31:20 | 000,048,128 | —- | M] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2012/12/16 08:12:54 | 000,034,304 | —- | M] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2012/12/16 06:08:21 | 000,368,128 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2012/12/16 05:50:29 | 000,293,376 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2012/12/14 16:25:20 | 000,077,393 | —- | M] () – C:\Users\Karri\Desktop\oj-murders-tape-photographs__oPt.jpg
[2012/12/14 08:42:48 | 000,000,952 | —- | M] () – C:\Users\Karri\Desktop\The Weather Network.lnk
[2012/12/13 13:44:08 | 000,002,046 | —- | M] () – C:\Users\Karri\Desktop\Google Chrome.lnk
[2012/12/13 13:44:08 | 000,002,008 | —- | M] () – C:\Users\Karri\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/12/11 13:56:12 | 000,001,207 | —- | M] () – C:\Users\Karri\Desktop\GoToMeeting.lnk
[2012/12/07 16:06:43 | 000,000,466 | —- | M] () – C:\Users\Karri\Documents\ChatLog New Meeting 2012_12_07 16_06.rtf
[2012/12/07 15:08:36 | 005,406,957 | —- | M] () – C:\Users\Karri\Desktop\DSC01531.JPG
[2012/12/07 15:00:54 | 005,391,002 | —- | M] () – C:\Users\Karri\Desktop\DSC01505.JPG
[2012/12/07 15:00:30 | 005,038,827 | —- | M] () – C:\Users\Karri\Desktop\DSC01476.JPG
[2012/12/07 15:00:24 | 005,120,304 | —- | M] () – C:\Users\Karri\Desktop\DSC01475.JPG
[2012/12/07 14:59:34 | 005,157,162 | —- | M] () – C:\Users\Karri\Desktop\DSC01466.JPG
[2012/12/07 14:58:38 | 004,863,461 | —- | M] () – C:\Users\Karri\Desktop\DSC01464.JPG
[2012/12/07 11:21:09 | 708,422,035 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/12/07 09:15:02 | 005,410,422 | —- | M] () – C:\Users\Karri\Desktop\DSC01436.JPG

========== Files Created - No Company Name ==========

[2013/01/03 15:29:10 | 000,025,854 | —- | C] () – C:\Users\Karri\Desktop\R110829104.20130102.pdf
[2013/01/03 14:15:28 | 000,201,281 | —- | C] () – C:\Users\Karri\Desktop\27292_10151363206356049_672386584_n.jpg
[2013/01/02 15:49:32 | 000,001,772 | —- | C] () – C:\Users\Public\Desktop\ooVoo.lnk
[2013/01/02 15:39:54 | 000,002,559 | —- | C] () – C:\Users\Karri\Desktop\HiJackThis.lnk
[2013/01/02 15:24:05 | 001,402,880 | —- | C] () – C:\Users\Karri\Desktop\HiJackThis.msi
[2013/01/02 11:24:00 | 000,132,078 | —- | C] () – C:\Users\Karri\Desktop\Scandinavian.jpg
[2013/01/02 11:19:05 | 000,432,213 | —- | C] () – C:\Users\Karri\Desktop\Video call snapshot 48.png
[2012/12/22 13:58:20 | 000,092,623 | —- | C] () – C:\Users\Karri\Desktop\16800_10151343017346049_1636654817_n.jpg
[2012/12/21 14:36:43 | 000,051,335 | —- | C] () – C:\Users\Karri\Desktop\224562_10150266265914978_307550646_n.jpg
[2012/12/21 14:34:55 | 000,027,506 | —- | C] () – C:\Users\Karri\Desktop\17082_548427821850478_1374715143_n.jpg
[2012/12/21 08:52:23 | 000,000,905 | —- | C] () – C:\Users\Public\Desktop\VLC media player.lnk
[2012/12/19 07:59:00 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/12/14 16:25:20 | 000,077,393 | —- | C] () – C:\Users\Karri\Desktop\oj-murders-tape-photographs__oPt.jpg
[2012/12/14 08:42:48 | 000,000,952 | —- | C] () – C:\Users\Karri\Desktop\The Weather Network.lnk
[2012/12/12 21:10:08 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012/12/12 21:10:08 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012/12/11 13:56:12 | 000,001,207 | —- | C] () – C:\Users\Karri\Desktop\GoToMeeting.lnk
[2012/12/07 16:06:43 | 000,000,466 | —- | C] () – C:\Users\Karri\Documents\ChatLog New Meeting 2012_12_07 16_06.rtf
[2012/12/07 15:20:27 | 005,406,957 | —- | C] () – C:\Users\Karri\Desktop\DSC01531.JPG
[2012/12/07 15:19:09 | 005,391,002 | —- | C] () – C:\Users\Karri\Desktop\DSC01505.JPG
[2012/12/07 15:02:00 | 005,120,304 | —- | C] () – C:\Users\Karri\Desktop\DSC01475.JPG
[2012/12/07 15:01:37 | 005,038,827 | —- | C] () – C:\Users\Karri\Desktop\DSC01476.JPG
[2012/12/07 14:59:50 | 005,157,162 | —- | C] () – C:\Users\Karri\Desktop\DSC01466.JPG
[2012/12/07 14:59:11 | 004,863,461 | —- | C] () – C:\Users\Karri\Desktop\DSC01464.JPG
[2012/12/07 14:57:04 | 005,410,422 | —- | C] () – C:\Users\Karri\Desktop\DSC01436.JPG
[2012/12/06 10:57:24 | 000,001,013 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk
[2012/12/06 10:57:24 | 000,001,001 | —- | C] () – C:\Users\Public\Desktop\TeamViewer 8.lnk
[2012/07/22 17:32:00 | 000,004,096 | —- | C] () – C:\Windows\d3dx.dat
[2012/02/01 17:18:15 | 000,000,552 | —- | C] () – C:\Users\Karri\AppData\Local\d3d8caps.dat
[2011/12/30 21:49:42 | 000,000,680 | —- | C] () – C:\Users\Karri\AppData\Local\d3d9caps.dat
[2011/10/10 17:52:43 | 000,742,262 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/09/02 13:28:57 | 000,031,232 | —- | C] () – C:\Users\Karri\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/19 04:26:20 | 010,898,456 | —- | C] () – C:\Windows\SysWow64\LogiDPP.dll
[2011/08/19 04:26:20 | 000,336,408 | —- | C] () – C:\Windows\SysWow64\DevManagerCore.dll
[2011/08/19 04:26:20 | 000,104,472 | —- | C] () – C:\Windows\SysWow64\LogiDPPApp.exe
[2011/04/01 09:07:49 | 000,060,864 | —- | C] () – C:\Users\Karri\g2mdlhlpx.exe
[2011/03/19 12:17:47 | 000,004,824 | —- | C] () – C:\Windows\wininit.ini
[2010/03/12 21:00:58 | 000,000,760 | —- | C] () – C:\Users\Karri\AppData\Roaming\setup_ldm.iss
[2009/09/21 11:30:38 | 000,000,029 | —- | C] () – C:\Users\Karri\AppData\Roaming\default.rss
[2009/09/15 11:40:54 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/06/28 10:50:52 | 000,048,127 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/06/28 10:50:52 | 000,048,127 | —- | C] () – C:\ProgramData\nvModes.001
[2008/10/28 07:57:39 | 000,000,052 | —- | C] () – C:\ProgramData\CLSDefine.ini

========== ZeroAccess Check ==========

[2006/11/02 10:30:40 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 12:59:03 | 012,899,840 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 12:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/04/11 02:11:14 | 000,891,392 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 01:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2008/01/20 21:50:58 | 000,513,024 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Alternate Data Streams ==========

@Alternate Data Stream - 94 bytes -> C:\ProgramData\Temp:D5AA39DD
@Alternate Data Stream - 257 bytes -> C:\ProgramData\Temp:36608448
@Alternate Data Stream - 252 bytes -> C:\ProgramData\Temp:1E288DA3
@Alternate Data Stream - 251 bytes -> C:\ProgramData\Temp:AE289451
@Alternate Data Stream - 247 bytes -> C:\ProgramData\Temp:7D288858
@Alternate Data Stream - 247 bytes -> C:\ProgramData\Temp:0E61938B
@Alternate Data Stream - 242 bytes -> C:\ProgramData\Temp:FEE00EB9
@Alternate Data Stream - 237 bytes -> C:\ProgramData\Temp:2EB79F01
@Alternate Data Stream - 236 bytes -> C:\ProgramData\Temp:F2327E82
@Alternate Data Stream - 236 bytes -> C:\ProgramData\Temp:DE6EED8B
@Alternate Data Stream - 235 bytes -> C:\ProgramData\Temp:35629AE6
@Alternate Data Stream - 233 bytes -> C:\ProgramData\Temp:CEE4A457
@Alternate Data Stream - 230 bytes -> C:\ProgramData\Temp:08DB8D99
@Alternate Data Stream - 229 bytes -> C:\ProgramData\Temp:3B07E6F4
@Alternate Data Stream - 229 bytes -> C:\ProgramData\Temp:349E5B74
@Alternate Data Stream - 225 bytes -> C:\ProgramData\Temp:10D45FC3
@Alternate Data Stream - 224 bytes -> C:\ProgramData\Temp:4B244549
@Alternate Data Stream - 222 bytes -> C:\ProgramData\Temp:5AE33054
@Alternate Data Stream - 222 bytes -> C:\ProgramData\Temp:014BC3B4
@Alternate Data Stream - 221 bytes -> C:\ProgramData\Temp:3C0887BF
@Alternate Data Stream - 218 bytes -> C:\ProgramData\Temp:41884BBE
@Alternate Data Stream - 216 bytes -> C:\ProgramData\Temp:CB0FEE2B
@Alternate Data Stream - 216 bytes -> C:\ProgramData\Temp:38D2EA83
@Alternate Data Stream - 216 bytes -> C:\ProgramData\Temp:169E7AC5
@Alternate Data Stream - 214 bytes -> C:\ProgramData\Temp:A9ABA3FF
@Alternate Data Stream - 210 bytes -> C:\ProgramData\Temp:ED9B661E
@Alternate Data Stream - 196 bytes -> C:\ProgramData\Temp:3D36932D
@Alternate Data Stream - 152 bytes -> C:\ProgramData\Temp:6301CE40
@Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:2A8A3140
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:E9900C74
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:4B70A9FA
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:908A1B53
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:6E11933F
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:1B3549F2
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:7BB584AA
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:274516E7
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:131C0EE9
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:3AC0ED43
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:C9BC8592
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:793F316E
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:92DB4653
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:8AB6C1D7
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:CFF6B3FF
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:490BCC52
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:DCA79AB3
@Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:2CED8825
@Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp:FC60E0F8
@Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp:861A898F
@Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:580E04D8
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:4F636E25

< End of report >

OTL Extras logfile created on: 03/01/2013 3:28:49 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Karri\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

7.93 Gb Total Physical Memory | 2.99 Gb Available Physical Memory | 37.72% Memory free
16.07 Gb Paging File | 8.76 Gb Available in Paging File | 54.51% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.59 Gb Total Space | 70.86 Gb Free Space | 30.47% Space Free | Partition Type: NTFS
Drive D: | 348.93 Gb Total Space | 92.10 Gb Free Space | 26.40% Space Free | Partition Type: NTFS
Drive J: | 295.02 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive N: | 3.79 Gb Total Space | 3.79 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive O: | 930.95 Gb Total Space | 813.57 Gb Free Space | 87.39% Space Free | Partition Type: FAT32

Computer Name: KARRI-PC | User Name: Karri | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = C9 C1 E4 2F 8B 3A CA 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0485F8E3-1A09-4024-BA7E-F98A6E3B67FB}" = rport=138 | protocol=17 | dir=out | app=system |
"{26EACD8C-7194-4F96-81ED-2154D5E90590}" = lport=2869 | protocol=6 | dir=in | app=system |
"{42D82151-1A35-4B9D-A760-559221DBBA4F}" = rport=137 | protocol=17 | dir=out | app=system |
"{438F3FCE-8893-48B9-A035-40554350B370}" = lport=139 | protocol=6 | dir=in | app=system |
"{50115D97-DB49-44CD-84E2-4DA4E2F2EEF9}" = lport=137 | protocol=17 | dir=in | app=system |
"{5AA76EEF-6B8E-438A-B21C-10FE61C8273E}" = rport=445 | protocol=6 | dir=out | app=system |
"{72723F71-5C72-4E2F-A8BB-1B2FACDB0B03}" = lport=138 | protocol=17 | dir=in | app=system |
"{7368AFD0-6C88-4905-BAB2-CC2F4BB6602B}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
"{8A9ABA56-F005-42CB-835A-680487CE04E1}" = lport=445 | protocol=6 | dir=in | app=system |
"{B1E53891-F0B7-4D8F-87CF-92D87825598A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{B8806828-0C3B-4515-8175-852416FE4373}" = rport=139 | protocol=6 | dir=out | app=system |
"{BCE834EC-BBCE-41BD-8EAE-8AD289A873AF}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{C73FCED9-8013-44F9-9592-8A54D7382EFF}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{D8416C81-AE7C-4BDA-9F38-50CB9711BFF2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{EA7FAF37-873E-474D-ACA0-61CFD228318E}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{026A20FC-E75E-4AE5-A84F-3FB1E5C8E8FD}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{0D80A6FE-DF65-421F-9336-1A166CC05632}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\droplitz\cascade.exe |
"{143090E1-9C5F-41B5-9B2E-C1D71C44FB47}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hotel dash\hoteldash.exe |
"{15586373-00E5-411F-BFF2-941CC4C64474}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\eufloria\eufloria.exe |
"{1A6A2C55-F5C3-49DA-95B9-70BBA78D5589}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe |
"{1CB745C2-A73C-42B2-ACA3-A3F7F2C3C15B}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia connect\kernel\dms\clmsserver.exe |
"{1D84E0DD-067E-4B7D-88CB-A6E2F48DD0A5}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{211AD758-F2EB-4C6B-867E-9E1B7A5A0437}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hotel dash\hoteldash.exe |
"{25757D9E-3675-4F14-A555-A49B3425CE2B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\custom.exe |
"{28280830-880C-44CF-8B73-76D37540F99B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzle chronicles\puzzlechronicles.exe |
"{2F4D3580-9E97-40D0-993E-04DADC4CE426}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{31084447-3FDA-4BC2-B9ED-916FEF2295CF}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{31DB2597-38D6-4A4E-AA8B-EF6C74DEF37B}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia connect\acer homemedia connect.exe |
"{33B49371-D92B-40D5-867C-05009872AB14}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{36BE2B08-E41C-430A-8CE3-BA072FB7BB18}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\zuma's revenge\zumasrevenge.exe |
"{3EA1A45A-B3BE-4B86-83A9-882D7631EB07}" = dir=in | app=c:\program files\microsoft lync\ucmapi64.exe |
"{41EB73A3-0B7B-4FE3-89F3-ABF7F7551415}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\luxor 5th passage\luxor - 5th passage.exe |
"{42D7C32D-AFB0-4E17-805C-D17ACCBF9B1F}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{437A62E9-5F86-447B-BC81-C06350379349}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{45E1E295-7947-4BC0-A7D5-1341E4C006DF}" = dir=in | app=c:\program files (x86)\acer arcade live\acer arcade live main page\acer arcade live.exe |
"{46319C9A-D991-4DF5-AAB0-75693DD14404}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{482E5199-DCBB-40E3-A1DB-BC2D27399AB0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{49DF5E5B-FAC5-4C46-A567-8DEC235647EC}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe |
"{4CD3CDE7-136E-4D80-8E17-BCA58F2A9160}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{4DE71902-F71D-485C-BFA2-FCFFC948878D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{50BCD8A0-DE73-4E01-8E42-A26440FEA07D}" = dir=in | app=c:\program files (x86)\cyberlink\cyberlink live\clsomamonitorservice.exe |
"{5128F576-1743-46EE-BD62-15FD815E5D6F}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{53F1AE12-C085-4AF4-A1A3-3E0493DDE57C}" = dir=in | app=c:\program files (x86)\cyberlink\cyberlink live\clsomaservice.exe |
"{59F76541-B1FB-4C81-A98D-9DFB3F36A7A7}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia trial creator\acer homemedia trial creator.exe |
"{5A4CD912-D98B-4752-8758-9CBEFF37B38C}" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"{5A846A34-4E3D-4397-B499-EA651EAC799A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{5B53DBD0-CF30-4E48-A60A-B8F14A7338AB}" = dir=in | app=c:\program files (x86)\acer arcade live\acer slideshow dvd\acer slideshow dvd.exe |
"{5BFCE5AC-A1CF-4E02-945E-082F476C53AB}" = protocol=17 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"{60908FE1-AD5A-44DE-973F-D1B56E4C95C4}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{63529CEB-A982-4D8F-B3D4-38798D235B97}" = dir=in | app=c:\program files (x86)\acer arcade live\acer dv magician\acer dv magician.exe |
"{6B53143B-FAF1-4826-A5C4-2D0D25E3B6B1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\eufloria\eufloria.exe |
"{6BF7994F-F161-4D37-BA52-9F2B7903F92D}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{6EF76C59-39D2-4E16-A3D9-FD112F09E4D5}" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"{70DDDEC1-424F-4FB0-90AB-DC467AF2DE73}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{722B5250-5770-4A57-AA8A-77F2F3935D0C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\luxor 5th passage\luxor - 5th passage.exe |
"{7992BD87-E39E-4DF3-AE41-7CC61872FA91}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzlequest2\puzzlequest2.exe |
"{8B57FA11-FAAA-45D7-9CD0-779B67A0691F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\zuma's revenge\zumasrevenge.exe |
"{8F30AF37-993B-4183-9481-23345349D2E4}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{9AE2D478-D3BA-40C2-ADE9-3C8EBE115FAF}" = dir=in | app=c:\program files (x86)\acer arcade live\acer videomagician\acer videomagician.exe |
"{9EBA2EBE-1437-41D5-B5DD-D10C4459955A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\recettear.exe |
"{A755F2BB-5391-4EC8-8CC9-2A6E28230F0D}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A792D402-18C2-4584-9985-67947D43CBB4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\torchlight2.exe |
"{AB95C5A1-1EE1-4623-B8B8-AC3AD4717B59}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{AF57DC65-FE10-4F0E-87EB-850082FEC2A5}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{B4B4EF0A-F441-4C4E-9B49-E8DF65F3DC53}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{B7035FE8-3D41-48BC-83DB-3069996FDF15}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{BA977534-1A57-46A1-9D5C-E8CAF28DA686}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzle chronicles\puzzlechronicles.exe |
"{BAE33E54-2BEA-4488-AE6A-9184671ACDB0}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{BCB23F56-6620-45C9-97B1-743DA0A787D2}" = dir=in | app=c:\program files (x86)\cyberlink\cyberlink live\clpushupdateservice.exe |
"{BDEE44E1-CC0F-418D-BDE1-F2A29A22B66A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{BE958C74-7849-4FC8-955D-53C4840F85DE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzlequest2\puzzlequest2.exe |
"{C0BCE171-BA08-4A8A-9468-CECD02E07F30}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\torchlight2.exe |
"{C30E81C8-6756-4A8E-A10A-75D500F199C8}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{C39E0424-540B-45DB-9A3E-A8D23D3A7630}" = dir=in | app=c:\program files (x86)\microsoft lync\communicator.exe |
"{C6E9C062-FDE1-4E8F-B5E9-E60EDAB60356}" = dir=in | app=c:\program files (x86)\acer arcade live\acer dvdivine\acer dvdivine.exe |
"{C77AB154-B16F-4739-AB97-294A1E700D8E}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{CE2A96E7-0A4E-4840-987F-8AE7692D4E66}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\custom.exe |
"{CF6AFB91-9BB1-40CD-951F-7334F89F92D9}" = protocol=6 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"{D2B0635A-BF7B-4CCD-9FF4-33A786BF9772}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{D7929809-9DB7-4971-BE00-795D130BB3DA}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{DBBFBF7F-6998-4EE7-8B1C-5D4F1298ED14}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia\acer homemedia.exe |
"{E21B7CAE-632B-4891-B03B-7FEC13816437}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{E38229C0-4738-44C9-BC16-E3B2760638D3}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{E890FBFF-A9A1-41D1-B7F6-DF8CD784C568}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{F3315C0F-CCAA-4FE6-B1C1-D1FC8116906E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fitness dash\fitnessdash.exe |
"{F44E840B-CA0A-494D-974E-F88DC2AE18E8}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{F4E391D2-9AD6-4A86-B632-A7B3D4DB1868}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{F5431383-35A1-4C6F-BC45-4A7AEF330988}" = dir=in | app=c:\program files (x86)\microsoft lync\ucmapi.exe |
"{F736369E-A09E-4770-82FA-EE01A02543D4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\droplitz\cascade.exe |
"{FB3D19E9-958E-43D1-9E96-A676CE39491A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fitness dash\fitnessdash.exe |
"{FD2FA6DC-FA5E-4EC9-8311-481D5157822B}" = dir=in | app=c:\program files (x86)\cyberlink\cyberlink live\clhomemediaserver.exe |
"{FE228B95-329B-46E8-950B-70EE4F5B549E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\recettear.exe |
"TCP Query User{1FD7F4E9-C63D-4CFD-89DE-0279CE61ACBA}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"TCP Query User{236DB553-2209-4978-BD98-DDA820C234FE}C:\program files (x86)\oovoo\oovoo.exe" = protocol=6 | dir=in | app=c:\program files (x86)\oovoo\oovoo.exe |
"TCP Query User{385704E7-8985-4F92-8901-C6FE813E201A}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{B504721D-C368-4CB9-90EB-852F3C2212B7}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"TCP Query User{CE3E5FCD-7C89-492C-9C89-CCA6312E7DED}C:\program files (x86)\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"TCP Query User{E6899A08-551C-4CBB-8A09-8514A08C1D03}C:\program files (x86)\logitech\vid hd\vid.exe" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"UDP Query User{534508C2-EC9A-4B83-BE0C-780DD08D8D53}C:\program files (x86)\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"UDP Query User{5B1C0B5B-B3D2-46B4-9AAF-F334DD805AAF}C:\program files (x86)\logitech\vid hd\vid.exe" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"UDP Query User{9A50E594-A30A-4554-9667-ADB34FA275F8}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"UDP Query User{BF90CEB4-CD3C-49C5-8BDE-10B1040E2383}C:\program files (x86)\oovoo\oovoo.exe" = protocol=17 | dir=in | app=c:\program files (x86)\oovoo\oovoo.exe |
"UDP Query User{CCA1448D-D510-44CC-953D-484C5605B7F5}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"UDP Query User{E121835F-7ABC-45F8-84AE-DAC397530DEB}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{0370E621-61D1-4199-82AF-8F21851FD194}" = i_instrumentation [removed]
"{072F206C-2F30-48C9-8ED0-3CDF4F612CB1}" = ME_Kit_Files_x64
"{0C524D20-1409-0050-8A9E-0C4C490E4E54}" = Microsoft Dynamics CRM 2011 for Microsoft Office Outlook
"{0C524DC1-1409-0050-8121-88490F4D5549}" = Microsoft Dynamics CRM 2011 English (United States) Language Pack
"{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D666E21-2924-4B94-9A33-D6136761ACAB}" = Intel® Remote Wake Technology 1.0.296.0
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86416014FF}" = Java™ 6 Update 14 (64-bit)
"{273799F6-BC76-46F1-95E1-EF05322C3A5F}" = i_msm 1.0.312.0
"{2BE51F94-8ED9-4B31-898C-01BFA71CC1DC}" = i_swupdate [removed]
"{4975D666-729A-46A5-8C80-1F022AD43543}" = Livedrive
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{52A7026F-476C-4E3B-A4C7-8FF7DAD65FEB}" = i_redistributables 1.0.45
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{70E8EBD5-78C9-4258-B20A-5098CCA000F0}" = Dolby Control Center
"{81BE0B17-563B-45D4-B198-5721E6C665CD}" = Microsoft Lync 2010
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{868EA922-5675-4E91-BDA6-BBD0F923C5EF}" = HP Officejet Pro All-In-One Series
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUSR_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.PROPLUSR_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{270CA0B9-9881-44DB-BC3B-37C7E66A044A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0043-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{FCD1C311-8B02-4DBD-BA46-1079C629577E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-1000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 306.97
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support
"{E20B2752-0909-4B28-B8A9-A9BE519CA1A1}" = Microsoft Online Services Sign-in Assistant
"{F39076D7-7168-44CD-A2C6-EBC1CDA7DC1C}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft CRM Client" = Microsoft Dynamics CRM 2011 for Microsoft Office Outlook
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"WinRAR archiver" = WinRAR 4.01 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{021C4C4F-C93C-4425-BFFD-C2D16776BFAE}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{0A55CDBB-0566-4AA2-A15B-24C7F27C6FF4}" = BPD_Scan
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D2F6F25-394B-4ACA-BC9C-1394E963C620}" = Intel® Remote Wake Technology [removed]
"{12CAA28E-56CA-4C3D-B3F2-7311540DD410}" = TurboTax 2011
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{131B84C2-5435-4993-9888-6C62D9AC755E}" = CyberLink Live
"{132888AE-EF67-41C5-BCA2-7D5D2488AB63}" = Acer HomeMedia Connect
"{13D85C14-2B85-419F-AC41-C7F21E68B25D}" = Acer eSettings Management
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{24AE6B5B-3D5A-488C-9224-1BEE11F75DD9}" = TurboTax 2010
"{26A24AE4-039D-4CA4-87B4-2F83216032FF}" = Java™ 6 Update 38
"{28DA3304-9EC2-4097-BC64-B59A1958841F}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
"{359cfc0a-beb1-440d-95ba-cf63a86da34f}" = Nero Recode
"{368ba326-73ad-4351-84ed-3c0a7a52cc53}" = Nero Rescue Agent
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{41581EF5-45A7-11DA-9D78-000129760D75}" = Acer SlideShow DVD
"{43D16DA8-BF42-3C62-89D3-3AD47829DC2E}" = Google Talk Plugin
"{43e39830-1826-415d-8bae-86845787b54b}" = Nero Vision
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4FB600F5-C478-4DF7-A2BC-57D3807BAC91}" = BPDSoftware_Ini
"{5104B07C-6A3D-4E7E-8BBB-960B52554BDD}" = BPD_HPSU
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{5AE12194-3EAA-40DF-B2BF-FE1D6B78BBF4}" = Nero Vision
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner
"{63e01893-1aef-40c9-b436-5817c1394f52}" = Nero 9 Trial
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6ad7d061-da98-4a17-8960-1ba830ff4861}" = Nero 9
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71828142-5A24-4BD0-97E7-976DA08CE6CF}" = The Sims™ 3 High-End Loft Stuff
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110111700}" = Zuma Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110113233}" = Bookworm Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11029123}" = Bricks of Egypt
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110322783}" = Big Kahuna Reef
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110411970}" = Chuzzle
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111252743}" = Mahjong Escape Ancient China
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111324990}" = Kick N Rush
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111543617}" = Backspin Billiards
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111692950}" = Mahjongg Artifacts
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111771833}" = Jewel Quest Solitaire
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111796363}" = Mystery Solitaire - Secret Island
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111872660}" = Diner Dash Flo on the Go
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112310577}" = Flip Words 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112531267}" = Chicken Invaders 3
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113009953}" = Turbo Pizza
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113080210}" = Azada
"{83BEEFB4-8C28-4F4F-8A9D-E0D1ADCE335B}" = The Sims Medieval
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8868D822-2CBA-46B2-A286-B400B6185769}" = 7500_7600_7700_Help
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F1B6239-FEA0-450A-A950-B05276CE177C}" = Acer Empowering Technology
"{8F968232-15C6-4872-84C2-9FCDAA1AEAB6}" = MPM
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = The Sims™ 3 Ambitions
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A875B56-A35C-46BA-A3AA-DF8D03EE9F2F}" = Nero ControlCenter
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{9e82b934-9a25-445b-b8df-8012808074ac}" = Nero PhotoSnap
"{9e9fdde6-2c26-492a-85a0-05646b3f2795}" = NeroLiveGadget
"{a209525b-3377-43f4-b886-32f6b6e7356f}" = Nero WaveEditor
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A495D4DC-4036-4914-9CB2-0FCF6A3166EF}" = L7500
"{A5633652-3795-4829-BB0B-644F0279E279}" = Acer eDataSecurity Management
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA0D2D5F-612B-45D3-8759-DA87206E5CC9}" = QuickTax 2008
"{AA4BF92B-2AAF-11DA-9D78-000129760D75}" = Acer HomeMedia
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B145EC69-66F5-11D8-9D75-000129760D75}" = Acer DVDivine
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{b1adf008-e898-4fe2-8a1f-690d9a06acaf}" = DolbyFiles
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{B580C409-E16F-44FF-904D-3AE94E113BE0}" = Acer HomeMedia Trial Creator
"{b78120a0-cf84-4366-a393-4d0a59bc546c}" = Menu Templates - Starter Kit
"{B83FC356-B7C0-441F-8A4D-D71E088E7974}" = NVIDIA PhysX
"{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}" = The Sims™ 3 World Adventures
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C19B3EB6-B54C-3204-A4DF-88432E0C79F7}" = Microsoft ReportViewer 2010 Redistributable
"{c5a7cb6c-e76d-408f-ba0e-85605420fe9d}" = SoundTrax
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C1}" = WinZip 15.0
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{d025a639-b9c9-417d-8531-208859000af8}" = NeroBurningROM
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}" = Nero ShowTime
"{DEB9AEF7-3ADA-40a9-9C98-546D54FE9CBD}" = ProductContext
"{df6a95f5-adc1-406a-bdc6-2aa7cc0182aa}" = Nero Live
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{e498385e-1c51-459a-b45f-1721e37aa1a0}" = Movie Templates - Starter Kit
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{ECAD4F6A-0BF3-4028-9C81-E5D9F9606CBA}" = BPDSoftware
"{ECB9C58E-C565-4683-9599-B72290BD3B25}" = QuickTax 2009
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{EEEB604C-C1A7-4f8c-B03F-56F9C1C9C45F}" = Fax
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}" = Acer Arcade Live Main Page
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f1861f30-3419-44db-b2a1-c274825698b3}" = Nero Disc Copy Gadget
"{F6EFFB76-4A07-11DA-9D78-000129760D75}" = Acer DV Magician
"{F79A208D-D929-11D9-9D77-000129760D75}" = Acer VideoMagician
"{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}" = ooVoo
"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Acer Assist" = Acer Assist
"Acer GameZone Console_is1" = Acer GameZone Console DTV 2.0.1.1
"Acer Registration" = Acer Registration
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Avira AntiVir Desktop" = Avira Free Antivirus
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"BFG-Be a King - Golden Empire" = Be a King: Golden Empire
"BFG-Be Richest!" = Be Richest!
"BFG-Bistro Boulevard" = Bistro Boulevard
"BFG-Boutique Boulevard" = Boutique Boulevard
"BFG-Build-a-lot - Fairy Tales" = Build-a-lot: Fairy Tales
"BFG-Build-a-lot - On Vacation" = Build-a-lot: On Vacation
"BFG-Build-a-Lot 4 - Power Source" = Build-a-Lot 4: Power Source
"BFGC" = Big Fish Games: Game Manager
"BFG-Campgrounds" = Campgrounds
"BFG-Casino Chaos" = Casino Chaos
"BFG-Chloe's Dream Resort" = Chloe's Dream Resort
"BFG-Club Paradise" = Club Paradise
"BFG-Cooking Dash 3 - Thrills and Spills" = Cooking Dash 3: Thrills and Spills
"BFG-Dancing Craze" = Dancing Craze
"BFG-DinerTown - Detective Agency" = DinerTown: Detective Agency
"BFG-Dress Up Rush" = Dress Up Rush
"BFG-Farm Frenzy 3" = Farm Frenzy 3
"BFG-Fiona Finch and the Finest Flowers" = Fiona Finch and the Finest Flowers
"BFG-First Class Flurry" = First Class Flurry
"BFG-Grave Mania - Undead Fever" = Grave Mania: Undead Fever
"BFG-Hotel Dash 2 - Lost Luxuries" = Hotel Dash 2: Lost Luxuries
"BFG-Island Tribe 2" = Island Tribe 2
"BFG-Jet Set Go" = Jet Set Go
"BFG-Jo's Dream - Organic Coffee" = Jo's Dream: Organic Coffee
"BFG-Juliette's Fashion Empire" = Juliette's Fashion Empire
"BFG-Katy and Bob - Way Back Home" = Katy and Bob: Way Back Home
"BFG-My Farm Life" = My Farm Life
"BFG-Northern Tale" = Northern Tale
"BFG-Pet Rush - Arround the World" = Pet Rush: Arround the World
"BFG-Princess Isabella - A Witch's Curse" = Princess Isabella: A Witch's Curse
"BFG-Rescue Frenzy" = Rescue Frenzy
"BFG-Roads of Rome III" = Roads of Rome III
"BFG-Royal Envoy 2 Collector's Edition" = Royal Envoy 2 Collector's Edition
"BFG-Sally's Studio Collector's Edition" = Sally's Studio Collector's Edition
"BFG-Shop-n-Spree - Shopping Paradise" = Shop-n-Spree: Shopping Paradise
"BFG-Soap Opera Dash" = Soap Opera Dash
"BFG-Spa Mania 2" = Spa Mania 2
"BFG-The Timebuilders - Pyramid Rising" = The Timebuilders: Pyramid Rising
"BFG-Virtual City 2 - Paradise Resort" = Virtual City 2: Paradise Resort
"BFG-Wedding Dash 2 - Rings Around the World" = Wedding Dash 2: Rings Around the World
"BFG-Wedding Dash 4-Ever" = Wedding Dash 4-Ever
"BFG-Wedding Salon" = Wedding Salon
"BFG-Youda Jewel Shop" = Youda Jewel Shop
"Comical_is1" = Comical 0.8
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{131B84C2-5435-4993-9888-6C62D9AC755E}" = CyberLink Live
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"Kobo" = Kobo
"Logitech Vid" = Logitech Vid HD
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mouse Setting Software_is1" = Mouse Setting Software 4.0
"Mozilla Firefox 15.0 (x86 en-US)" = Mozilla Firefox 15.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"Origin" = Origin
"Picasa 3" = Picasa 3
"Royal Envoy Collector's Edition" = Royal Envoy Collector's Edition
"Runic Games Torchlight" = Torchlight
"Steam App 19020" = Puzzle Chronicles
"Steam App 200710" = Torchlight II
"Steam App 23120" = Droplitz
"Steam App 3620" = Zuma's Revenge
"Steam App 37340" = Fitness Dash
"Steam App 41210" = Eufloria
"Steam App 47540" = Puzzle Quest 2
"Steam App 49000" = Hotel Dash
"Steam App 60340" = LUXOR: 5th Passage
"Steam App 70400" = Recettear: An Item Shop's Tale
"Strat-O-Matic CD-ROM Ver16.00H" = Strat-O-Matic CD-ROM Ver16.00H
"TeamViewer 8" = TeamViewer 8
"VLC media player" = VLC media player 2.0.5
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"YTdetect" = Yahoo! Detect
"Zynga Toolbar" = Zynga Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"GoToMeeting" = GoToMeeting 5.4.0.1060
"Mozilla Firefox 17.0.1 (x86 en-US)" = Mozilla Firefox 17.0.1 (x86 en-US)
"Oracle Live Help On Demand - Agent Console - NNA CLPOC ORILLIA Karri Tougas (105652707)" = Oracle Live Help On Demand - Agent Console - NNA CLPOC ORILLIA Karri Tougas (105652707)
"Sansa Updater" = Sansa Updater
"The Weather Network" = The Weather Network
"uTorrent" = µTorrent

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 03/01/2013 1:20:57 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.

Error - 03/01/2013 1:30:59 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.

Error - 03/01/2013 1:35:59 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.

Error - 03/01/2013 1:46:01 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.

Error - 03/01/2013 1:51:01 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.

Error - 03/01/2013 2:01:02 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.

Error - 03/01/2013 2:16:06 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.

Error - 03/01/2013 2:21:06 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.

Error - 03/01/2013 2:36:09 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.

Error - 03/01/2013 2:42:14 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5981
Description = An error occurred retrieving data from the Microsoft CRM server for
processing pending Microsoft CRM e-mail messages. Verify that the current user
has appropriate permissions and server connectivity and try the action again. HR=0x80131501.
Context=. Function=CEmailBackgroundSend::Run. Line=332.

[ System Events ]
Error - 30/12/2012 12:41:35 PM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 30/12/2012 12:41:35 PM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 31/12/2012 8:34:34 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 31/12/2012 8:34:34 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 01/01/2013 11:40:16 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 01/01/2013 11:40:16 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 02/01/2013 9:12:52 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 02/01/2013 9:12:53 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 03/01/2013 9:14:00 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 03/01/2013 9:14:00 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =


< End of report >
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!

I will be happy to take a look at your logs and help you out. We will work on one computer at a time as it is too confusing to try and deal with more than one machine at a time. I'll be back with you shortly after I review your OTl log.

In the mean time, can you please also run the following diagnostic scan for me?




Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
Thanks in advance for your help! 19:55:51.0885 5272 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35 19:55:52.0587 5272 ============================================================ 19:55:52.0587 5272 Current date / time: 2013/01/03 19:55:52.0587 19:55:52.0587 5272 SystemInfo: 19:55:52.0587 5272 19:55:52.0587 5272 OS Version: 6.0.6002 ServicePack: 2.0 19:55:52.0587 5272 Product type: Workstation 19:55:52.0587 5272 ComputerName: KARRI-PC 19:55:52.0588 5272 UserName: Karri 19:55:52.0588 5272 Windows directory: C:\Windows 19:55:52.0588 5272 System windows directory: C:\Windows 19:55:52.0588 5272 Running under WOW64 19:55:52.0588 5272 Processor architecture: Intel x64 19:55:52.0588 5272 Number of processors: 4 19:55:52.0588 5272 Page size: 0x1000 19:55:52.0588 5272 Boot type: Normal boot 19:55:52.0588 5272 ============================================================ 19:55:52.0930 5272 Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 19:55:52.0951 5272 Drive \Device\Harddisk6\DR6 - Size: 0xE8C4BA0000 (931.07 Gb), SectorSize: 0x200, Cylinders: 0x1DAC7, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 19:55:52.0953 5272 Drive \Device\Harddisk7\DR7 - Size: 0xF2C00000 (3.79 Gb), SectorSize: 0x200, Cylinders: 0x1EF, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 19:55:52.0955 5272 ============================================================ 19:55:52.0955 5272 \Device\Harddisk0\DR0: 19:55:52.0955 5272 MBR partitions: 19:55:52.0955 5272 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1D4F800, BlocksNum 0x1D12D000 19:55:52.0955 5272 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1EE7C800, BlocksNum 0x2B9DB000 19:55:52.0955 5272 \Device\Harddisk6\DR6: 19:55:52.0955 5272 MBR partitions: 19:55:52.0955 5272 \Device\Harddisk6\DR6\Partition1: MBR, Type 0xC, StartLBA 0x3F, BlocksNum 0x746221C8 19:55:52.0955 5272 \Device\Harddisk7\DR7: 19:55:52.0956 5272 MBR partitions: 19:55:52.0956 5272 \Device\Harddisk7\DR7\Partition1: MBR, Type 0xB, StartLBA 0x2000, BlocksNum 0x794000 19:55:52.0956 5272 ============================================================ 19:55:52.0987 5272 C: <-> \Device\Harddisk0\DR0\Partition1 19:55:53.0024 5272 D: <-> \Device\Harddisk0\DR0\Partition2 19:55:53.0025 5272 O: <-> \Device\Harddisk6\DR6\Partition1 19:55:53.0025 5272 ============================================================ 19:55:53.0025 5272 Initialize success 19:55:53.0025 5272 ============================================================ 19:55:56.0082 1384 ============================================================ 19:55:56.0082 1384 Scan started 19:55:56.0082 1384 Mode: Manual; 19:55:56.0082 1384 ============================================================ 19:55:56.0484 1384 ================ Scan system memory ======================== 19:55:56.0484 1384 System memory - ok 19:55:56.0485 1384 ================ Scan services ============================= 19:55:56.0573 1384 [ 517D30057C726C797764BFD70A55D82A ] Acer HomeMedia Connect Service C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe 19:55:56.0578 1384 Acer HomeMedia Connect Service - ok 19:55:56.0696 1384 [ 1965AAFFAB07E3FB03C77F81BEBA3547 ] ACPI C:\Windows\system32\drivers\acpi.sys 19:55:56.0700 1384 ACPI - ok 19:55:56.0766 1384 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 19:55:56.0767 1384 AdobeARMservice - ok 19:55:56.0860 1384 [ 95CE557D16A75606CCC2D7F3B0B0BCCB ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 19:55:56.0862 1384 AdobeFlashPlayerUpdateSvc - ok 19:55:56.0893 1384 [ F14215E37CF124104575073F782111D2 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 19:55:56.0910 1384 adp94xx - ok 19:55:56.0949 1384 [ 7D05A75E3066861A6610F7EE04FF085C ] adpahci C:\Windows\system32\drivers\adpahci.sys 19:55:56.0953 1384 adpahci - ok 19:55:56.0965 1384 [ 820A201FE08A0C345B3BEDBC30E1A77C ] adpu160m C:\Windows\system32\drivers\adpu160m.sys 19:55:56.0967 1384 adpu160m - ok 19:55:56.0981 1384 [ 9B4AB6854559DC168FBB4C24FC52E794 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 19:55:56.0983 1384 adpu320 - ok 19:55:57.0015 1384 [ 0F421175574BFE0BF2F4D8E910A253BB ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 19:55:57.0016 1384 AeLookupSvc - ok 19:55:57.0058 1384 [ C4F6CE6087760AD70960C9EB130E7943 ] AFD C:\Windows\system32\drivers\afd.sys 19:55:57.0063 1384 AFD - ok 19:55:57.0081 1384 [ F6F6793B7F17B550ECFDBD3B229173F7 ] agp440 C:\Windows\system32\drivers\agp440.sys 19:55:57.0082 1384 agp440 - ok 19:55:57.0105 1384 [ 222CB641B4B8A1D1126F8033F9FD6A00 ] aic78xx C:\Windows\system32\drivers\djsvs.sys 19:55:57.0107 1384 aic78xx - ok 19:55:57.0123 1384 [ 5922F4F59B7868F3D74BBBBEB7B825A3 ] ALG C:\Windows\System32\alg.exe 19:55:57.0124 1384 ALG - ok 19:55:57.0147 1384 [ 157D0898D4B73F075CE9FA26B482DF98 ] aliide C:\Windows\system32\drivers\aliide.sys 19:55:57.0148 1384 aliide - ok 19:55:57.0159 1384 [ 970FA5059E61E30D25307B99903E991E ] amdide C:\Windows\system32\drivers\amdide.sys 19:55:57.0159 1384 amdide - ok 19:55:57.0174 1384 [ CDC3632A3A5EA4DBB83E46076A3165A1 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 19:55:57.0175 1384 AmdK8 - ok 19:55:57.0224 1384 [ 0A1CC583E8147004E4AD4625D7FBF88C ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 19:55:57.0225 1384 AntiVirSchedulerService - ok 19:55:57.0233 1384 [ C9A36EF935ACED86AEDF93E97E606911 ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 19:55:57.0234 1384 AntiVirService - ok 19:55:57.0261 1384 [ 9C37B3FD5615477CB9A0CD116CF43F5C ] Appinfo C:\Windows\System32\appinfo.dll 19:55:57.0262 1384 Appinfo - ok 19:55:57.0339 1384 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 19:55:57.0340 1384 Apple Mobile Device - ok 19:55:57.0362 1384 [ BA8417D4765F3988FF921F30F630E303 ] arc C:\Windows\system32\drivers\arc.sys 19:55:57.0363 1384 arc - ok 19:55:57.0397 1384 [ 9D41C435619733B34CC16A511E644B11 ] arcsas C:\Windows\system32\drivers\arcsas.sys 19:55:57.0399 1384 arcsas - ok 19:55:57.0493 1384 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 19:55:57.0494 1384 aspnet_state - ok 19:55:57.0517 1384 [ 22D13FF3DAFEC2A80634752B1EAA2DE6 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 19:55:57.0518 1384 AsyncMac - ok 19:55:57.0531 1384 [ 1898FAE8E07D97F2F6C2D5326C633FAC ] atapi C:\Windows\system32\drivers\atapi.sys 19:55:57.0532 1384 atapi - ok 19:55:57.0570 1384 [ 79318C744693EC983D20E9337A2F8196 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 19:55:57.0574 1384 AudioEndpointBuilder - ok 19:55:57.0587 1384 [ 79318C744693EC983D20E9337A2F8196 ] AudioSrv C:\Windows\System32\Audiosrv.dll 19:55:57.0590 1384 AudioSrv - ok 19:55:57.0615 1384 [ 26E38B5A58C6C55FAFBC563EEDDB0867 ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys 19:55:57.0617 1384 avgntflt - ok 19:55:57.0643 1384 [ 9D1F00BEFF84CBBF46D7F052BC7E0565 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys 19:55:57.0644 1384 avipbb - ok 19:55:57.0655 1384 [ 248DB59FC86DE44D2779F4C7FB1A567D ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys 19:55:57.0656 1384 avkmgr - ok 19:55:57.0700 1384 [ FFB96C2589FFA60473EAD78B39FBDE29 ] BFE C:\Windows\System32\bfe.dll 19:55:57.0705 1384 BFE - ok 19:55:57.0766 1384 [ 6D316F4859634071CC25C4FD4589AD2C ] BITS C:\Windows\System32\qmgr.dll 19:55:57.0792 1384 BITS - ok 19:55:57.0817 1384 [ 79FEEB40056683F8F61398D81DDA65D2 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys 19:55:57.0818 1384 blbdrive - ok 19:55:57.0900 1384 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 19:55:57.0908 1384 Bonjour Service - ok 19:55:57.0937 1384 [ 2348447A80920B2493A9B582A23E81E1 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 19:55:57.0938 1384 bowser - ok 19:55:57.0958 1384 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys 19:55:57.0959 1384 BrFiltLo - ok 19:55:57.0974 1384 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys 19:55:57.0975 1384 BrFiltUp - ok 19:55:58.0004 1384 [ A1B39DE453433B115B4EA69EE0343816 ] Browser C:\Windows\System32\browser.dll 19:55:58.0005 1384 Browser - ok 19:55:58.0021 1384 [ F0F0BA4D815BE446AA6A4583CA3BCA9B ] Brserid C:\Windows\system32\drivers\brserid.sys 19:55:58.0022 1384 Brserid - ok 19:55:58.0042 1384 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys 19:55:58.0043 1384 BrSerWdm - ok 19:55:58.0054 1384 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys 19:55:58.0054 1384 BrUsbMdm - ok 19:55:58.0062 1384 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys 19:55:58.0062 1384 BrUsbSer - ok 19:55:58.0078 1384 [ E0777B34E05F8A82A21856EFC900C29F ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys 19:55:58.0079 1384 BTHMODEM - ok 19:55:58.0122 1384 [ 09E6AFFAE6C0E9158BF05C7D08D0107A ] BUNAgentSvc C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe 19:55:58.0123 1384 BUNAgentSvc - ok 19:55:58.0159 1384 c2wts - ok 19:55:58.0209 1384 [ 3D50891CAA71E3479A8A10F25CA9207F ] cbfs3 C:\Windows\system32\drivers\cbfs3.sys 19:55:58.0214 1384 cbfs3 - ok 19:55:58.0236 1384 [ B4D787DB8D30793A4D4DF9FEED18F136 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 19:55:58.0238 1384 cdfs - ok 19:55:58.0273 1384 [ C025AA69BE3D0D25C7A2E746EF6F94FC ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 19:55:58.0274 1384 cdrom - ok 19:55:58.0304 1384 [ 5A268127633C7EE2A7FB87F39D748D56 ] CertPropSvc C:\Windows\System32\certprop.dll 19:55:58.0306 1384 CertPropSvc - ok 19:55:58.0321 1384 [ 02EA568D498BBDD4BA55BF3FCE34D456 ] circlass C:\Windows\system32\drivers\circlass.sys 19:55:58.0322 1384 circlass - ok 19:55:58.0355 1384 [ 3DCA9A18B204939CFB24BEA53E31EB48 ] CLFS C:\Windows\system32\CLFS.sys 19:55:58.0360 1384 CLFS - ok 19:55:58.0406 1384 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 19:55:58.0407 1384 clr_optimization_v2.0.50727_32 - ok 19:55:58.0445 1384 [ CE07A466201096F021CD09D631B21540 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 19:55:58.0446 1384 clr_optimization_v2.0.50727_64 - ok 19:55:58.0516 1384 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 19:55:58.0519 1384 clr_optimization_v4.0.30319_32 - ok 19:55:58.0530 1384 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 19:55:58.0533 1384 clr_optimization_v4.0.30319_64 - ok 19:55:58.0551 1384 [ E5D5499A1C50A54B5161296B6AFE6192 ] cmdide C:\Windows\system32\drivers\cmdide.sys 19:55:58.0552 1384 cmdide - ok 19:55:58.0567 1384 [ 7FB8AD01DB0EABE60C8A861531A8F431 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 19:55:58.0568 1384 Compbatt - ok 19:55:58.0573 1384 COMSysApp - ok 19:55:58.0579 1384 [ A8585B6412253803CE8EFCBD6D6DC15C ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 19:55:58.0580 1384 crcdisk - ok 19:55:58.0645 1384 [ 0CB856463577085CF64ACA536BA1E881 ] CrmSqlStartupSvc C:\Program Files\Microsoft Dynamics CRM\Client\bin\CrmSqlStartupSvc.exe 19:55:58.0645 1384 CrmSqlStartupSvc - ok 19:55:58.0678 1384 [ CA78B312C44E4D52E842C2C8BD48E452 ] CryptSvc C:\Windows\system32\cryptsvc.dll 19:55:58.0680 1384 CryptSvc - ok 19:55:58.0724 1384 [ 6CB6E82300947870A873A7288B96E9BF ] CyberLink Live Monitor Service C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaMonitorService.exe 19:55:58.0727 1384 CyberLink Live Monitor Service - ok 19:55:58.0740 1384 [ 0FDAAE1EA129D0F3948564F96C010BA3 ] CyberLink Live Push Update Service C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdateService.exe 19:55:58.0742 1384 CyberLink Live Push Update Service - ok 19:55:58.0760 1384 [ 24F71344D945C85B15C0717196238BD2 ] CyberLink Live Service C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaService.exe 19:55:58.0764 1384 CyberLink Live Service - ok 19:55:58.0812 1384 [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] DcomLaunch C:\Windows\system32\rpcss.dll 19:55:58.0828 1384 DcomLaunch - ok 19:55:58.0858 1384 [ 8B722BA35205C71E7951CDC4CDBADE19 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 19:55:58.0859 1384 DfsC - ok 19:55:58.0942 1384 [ C647F468F7DE343DF8C143655C5557D4 ] DFSR C:\Windows\system32\DFSR.exe 19:55:58.0991 1384 DFSR - ok 19:55:59.0039 1384 [ 3ED0321127CE70ACDAABBF77E157C2A7 ] Dhcp C:\Windows\System32\dhcpcsvc.dll 19:55:59.0041 1384 Dhcp - ok 19:55:59.0071 1384 [ B0107E40ECDB5FA692EBF832F295D905 ] disk C:\Windows\system32\drivers\disk.sys 19:55:59.0073 1384 disk - ok 19:55:59.0106 1384 [ 06230F1B721494A6DF8D47FD395BB1B0 ] Dnscache C:\Windows\System32\dnsrslvr.dll 19:55:59.0108 1384 Dnscache - ok 19:55:59.0122 1384 [ 1A7156DD1E850E9914E5E991E3225B94 ] dot3svc C:\Windows\System32\dot3svc.dll 19:55:59.0126 1384 dot3svc - ok 19:55:59.0160 1384 [ 74C02B1717740C3B8039539E23E4B53F ] Dot4 C:\Windows\system32\DRIVERS\Dot4.sys 19:55:59.0162 1384 Dot4 - ok 19:55:59.0177 1384 [ 08321D1860235BF42CF2854234337AEA ] Dot4Print C:\Windows\system32\DRIVERS\Dot4Prt.sys 19:55:59.0177 1384 Dot4Print - ok 19:55:59.0190 1384 [ 4ADCCF0124F2B6911D3786A5D0E779E5 ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys 19:55:59.0191 1384 dot4usb - ok 19:55:59.0216 1384 [ 1583B39790DB3EAEC7EDB0CB0140C708 ] DPS C:\Windows\system32\dps.dll 19:55:59.0219 1384 DPS - ok 19:55:59.0240 1384 [ F1A78A98CFC2EE02144C6BEC945447E6 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 19:55:59.0240 1384 drmkaud - ok 19:55:59.0278 1384 [ B8E554E502D5123BC111F99D6A2181B4 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 19:55:59.0295 1384 DXGKrnl - ok 19:55:59.0317 1384 [ 264CEE7B031A9D6C827F3D0CB031F2FE ] E1G60 C:\Windows\system32\DRIVERS\E1G6032E.sys 19:55:59.0319 1384 E1G60 - ok 19:55:59.0343 1384 [ B64CFEB83AB75AA74D0E193C423A991D ] e1yexpress C:\Windows\system32\DRIVERS\e1y60x64.sys 19:55:59.0347 1384 e1yexpress - ok 19:55:59.0372 1384 [ C2303883FD9BE49DC36A6400643002EA ] EapHost C:\Windows\System32\eapsvc.dll 19:55:59.0373 1384 EapHost - ok 19:55:59.0404 1384 [ 5F94962BE5A62DB6E447FF6470C4F48A ] Ecache C:\Windows\system32\drivers\ecache.sys 19:55:59.0405 1384 Ecache - ok 19:55:59.0469 1384 [ B1F2503E23425B386DF0F3413B2596F3 ] eDataSecurity Service C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe 19:55:59.0478 1384 eDataSecurity Service - ok 19:55:59.0509 1384 [ 14CE384D2E27B64C256BDA4DC39C312D ] ehRecvr C:\Windows\ehome\ehRecvr.exe 19:55:59.0514 1384 ehRecvr - ok 19:55:59.0523 1384 [ B93159C1313D66FDFBBE876F5189CD52 ] ehSched C:\Windows\ehome\ehsched.exe 19:55:59.0525 1384 ehSched - ok 19:55:59.0540 1384 [ F5EE2527D74449868E3C3227A59BCD28 ] ehstart C:\Windows\ehome\ehstart.dll 19:55:59.0541 1384 ehstart - ok 19:55:59.0565 1384 [ C4636D6E10469404AB5308D9FD45ED07 ] elxstor C:\Windows\system32\drivers\elxstor.sys 19:55:59.0571 1384 elxstor - ok 19:55:59.0615 1384 [ A9B18B63A4FD6BAAB83326706D857FAB ] EMDMgmt C:\Windows\system32\emdmgmt.dll 19:55:59.0618 1384 EMDMgmt - ok 19:55:59.0631 1384 [ BC3A58E938BB277E46BF4B3003B01ABD ] ErrDev C:\Windows\system32\drivers\errdev.sys 19:55:59.0632 1384 ErrDev - ok 19:55:59.0668 1384 [ 27D2754314D12EB27D81D462FD0D86C0 ] ETService C:\Program Files\Acer\Empowering Technology\Service\ETService.exe 19:55:59.0669 1384 ETService - ok 19:55:59.0710 1384 [ E12F22B73F153DECE721CD45EC05B4AF ] EventSystem C:\Windows\system32\es.dll 19:55:59.0715 1384 EventSystem - ok 19:55:59.0746 1384 [ 486844F47B6636044A42454614ED4523 ] exfat C:\Windows\system32\drivers\exfat.sys 19:55:59.0749 1384 exfat - ok 19:55:59.0786 1384 [ 1A4BEE34277784619DDAF0422C0C6E23 ] fastfat C:\Windows\system32\drivers\fastfat.sys 19:55:59.0788 1384 fastfat - ok 19:55:59.0813 1384 [ 81B79B6DF71FA1D2C6D688D830616E39 ] fdc C:\Windows\system32\DRIVERS\fdc.sys 19:55:59.0814 1384 fdc - ok 19:55:59.0841 1384 [ BB9267ACACD8B7533DD936C34A0CBA5E ] fdPHost C:\Windows\system32\fdPHost.dll 19:55:59.0842 1384 fdPHost - ok 19:55:59.0850 1384 [ 300C80931EABBE1DB7591C516EFE8D0F ] FDResPub C:\Windows\system32\fdrespub.dll 19:55:59.0852 1384 FDResPub - ok 19:55:59.0859 1384 [ 457B7D1D533E4BD62A99AED9C7BB4C59 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 19:55:59.0861 1384 FileInfo - ok 19:55:59.0878 1384 [ D421327FD6EFCCAF884A54C58E1B0D7F ] Filetrace C:\Windows\system32\drivers\filetrace.sys 19:55:59.0878 1384 Filetrace - ok 19:55:59.0897 1384 [ 230923EA2B80F79B0F88D90F87B87EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 19:55:59.0898 1384 flpydisk - ok 19:55:59.0931 1384 [ E3041BC26D6930D61F42AEDB79C91720 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 19:55:59.0935 1384 FltMgr - ok 19:55:59.0996 1384 [ BE1C5BD1CA7ED015BC6FA1AE67E592C8 ] FontCache C:\Windows\system32\FntCache.dll 19:56:00.0023 1384 FontCache - ok 19:56:00.0059 1384 [ BC5B0BE5AF3510B0FD8C140EE42C6D3E ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 19:56:00.0059 1384 FontCache3.0.0.0 - ok 19:56:00.0088 1384 [ 5779B86CD8B32519FBECB136394D946A ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 19:56:00.0089 1384 Fs_Rec - ok 19:56:00.0111 1384 [ C8E416668D3DC2BE3D4FE4C79224997F ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 19:56:00.0112 1384 gagp30kx - ok 19:56:00.0141 1384 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 19:56:00.0142 1384 GEARAspiWDM - ok 19:56:00.0180 1384 [ A0E1B575BA8F504968CD40C0FAEB2384 ] gpsvc C:\Windows\System32\gpsvc.dll 19:56:00.0197 1384 gpsvc - ok 19:56:00.0250 1384 [ C1B577B2169900F4CF7190C39F085794 ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe 19:56:00.0251 1384 gusvc - ok 19:56:00.0269 1384 [ DF45F8142DC6DF9D18C39B3EFFBD0409 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 19:56:00.0274 1384 HdAudAddService - ok 19:56:00.0330 1384 [ F942C5820205F2FB453243EDFEC82A3D ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 19:56:00.0348 1384 HDAudBus - ok 19:56:00.0366 1384 [ 72D70BCF68C092978BFCD32F88BD6454 ] HECIx64 C:\Windows\system32\DRIVERS\HECIx64.sys 19:56:00.0367 1384 HECIx64 - ok 19:56:00.0390 1384 [ 68214C82FA6222591873677A72DF2A66 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 19:56:00.0391 1384 HidBatt - ok 19:56:00.0405 1384 [ B4881C84A180E75B8C25DC1D726C375F ] HidBth C:\Windows\system32\drivers\hidbth.sys 19:56:00.0406 1384 HidBth - ok 19:56:00.0415 1384 [ 4E77A77E2C986E8F88F996BB3E1AD829 ] HidIr C:\Windows\system32\drivers\hidir.sys 19:56:00.0416 1384 HidIr - ok 19:56:00.0449 1384 [ 59361D38A297755D46A540E450202B2A ] hidserv C:\Windows\system32\hidserv.dll 19:56:00.0450 1384 hidserv - ok 19:56:00.0481 1384 [ 443BDD2D30BB4F00795C797E2CF99EDF ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 19:56:00.0481 1384 HidUsb - ok 19:56:00.0503 1384 [ B12F367EA39C0795FD57E31242CE1A5A ] hkmsvc C:\Windows\system32\kmsvc.dll 19:56:00.0506 1384 hkmsvc - ok 19:56:00.0527 1384 [ D7109A1E6BD2DFDBCBA72A6BC626A13B ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys 19:56:00.0528 1384 HpCISSs - ok 19:56:00.0594 1384 [ CE0FCEC4D4D860F36D972759B11EAF0F ] hpqcxs08 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll 19:56:00.0597 1384 hpqcxs08 - ok 19:56:00.0620 1384 [ EE4C7A4CF2316701FFDE90F404520265 ] hpqddsvc C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll 19:56:00.0622 1384 hpqddsvc - ok 19:56:00.0652 1384 [ 098F1E4E5C9CB5B0063A959063631610 ] HTTP C:\Windows\system32\drivers\HTTP.sys 19:56:00.0668 1384 HTTP - ok 19:56:00.0695 1384 [ DA94C854CEA5FAC549D4E1F6E88349E8 ] i2omp C:\Windows\system32\drivers\i2omp.sys 19:56:00.0696 1384 i2omp - ok 19:56:00.0712 1384 [ CBB597659A2713CE0C9CC20C88C7591F ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys 19:56:00.0713 1384 i8042prt - ok 19:56:00.0743 1384 [ 3E42C4691AAD4B1E8D0466F9CBF05CBE ] IAANTMON C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe 19:56:00.0748 1384 IAANTMON - ok 19:56:00.0776 1384 [ FC28E90F2204D8FD147FA9BFA8A51C01 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys 19:56:00.0779 1384 iaStor - ok 19:56:00.0794 1384 [ 3E3BF3627D886736D0B4E90054F929F6 ] iaStorV C:\Windows\system32\drivers\iastorv.sys 19:56:00.0798 1384 iaStorV - ok 19:56:00.0851 1384 [ 749F5F8CEDCA70F2A512945325FC489D ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 19:56:00.0868 1384 idsvc - ok 19:56:01.0019 1384 [ CF00559906E45ECC6F035913880BE2FC ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys 19:56:01.0143 1384 igfx - ok 19:56:01.0247 1384 [ 8C3951AD2FE886EF76C7B5027C3125D3 ] iirsp C:\Windows\system32\drivers\iirsp.sys 19:56:01.0248 1384 iirsp - ok 19:56:01.0299 1384 [ 0C9EA6E654E7B0471741E343A6C671AF ] IKEEXT C:\Windows\System32\ikeext.dll 19:56:01.0316 1384 IKEEXT - ok 19:56:01.0391 1384 [ 8C7FA71CB1EBCD3EDE8958D27B1BF0B4 ] int15 C:\Windows\SysWOW64\drivers\int15_64.sys 19:56:01.0391 1384 int15 - ok 19:56:01.0450 1384 [ AECDAA95B5BBFAC856C4A22D06D3D76A ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys 19:56:01.0501 1384 IntcAzAudAddService - ok 19:56:01.0523 1384 [ DEA2AB452B4FA773187369C4B6517320 ] IntcHdmiAddService C:\Windows\system32\drivers\IntcHdmi.sys 19:56:01.0524 1384 IntcHdmiAddService - ok 19:56:01.0547 1384 [ DF797A12176F11B2D301C5B234BB200E ] intelide C:\Windows\system32\drivers\intelide.sys 19:56:01.0547 1384 intelide - ok 19:56:01.0560 1384 [ BFD84AF32FA1BAD6231C4585CB469630 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 19:56:01.0561 1384 intelppm - ok 19:56:01.0585 1384 [ 5624BC1BC5EEB49C0AB76A8114F05EA3 ] IPBusEnum C:\Windows\system32\ipbusenum.dll 19:56:01.0588 1384 IPBusEnum - ok 19:56:01.0620 1384 [ D8AABC341311E4780D6FCE8C73C0AD81 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 19:56:01.0622 1384 IpFilterDriver - ok 19:56:01.0645 1384 [ BF0DBFA9792C5C14FA00F61C75116C1B ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 19:56:01.0647 1384 iphlpsvc - ok 19:56:01.0651 1384 IpInIp - ok 19:56:01.0675 1384 [ 9C2EE2E6E5A7203BFAE15C299475EC67 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys 19:56:01.0677 1384 IPMIDRV - ok 19:56:01.0707 1384 [ B7E6212F581EA5F6AB0C3A6CEEEB89BE ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys 19:56:01.0709 1384 IPNAT - ok 19:56:01.0764 1384 [ 0F261EC4F514926177C70C1832374231 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 19:56:01.0781 1384 iPod Service - ok 19:56:01.0797 1384 [ 8C42CA155343A2F11D29FECA67FAA88D ] IRENUM C:\Windows\system32\drivers\irenum.sys 19:56:01.0797 1384 IRENUM - ok 19:56:01.0819 1384 [ 0672BFCEDC6FC468A2B0500D81437F4F ] isapnp C:\Windows\system32\drivers\isapnp.sys 19:56:01.0820 1384 isapnp - ok 19:56:01.0853 1384 [ E4FDF99599F27EC25D2CF6D754243520 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys 19:56:01.0856 1384 iScsiPrt - ok 19:56:01.0872 1384 [ 63C766CDC609FF8206CB447A65ABBA4A ] iteatapi C:\Windows\system32\drivers\iteatapi.sys 19:56:01.0873 1384 iteatapi - ok 19:56:01.0896 1384 [ 1281FE73B17664631D12F643CBEA3F59 ] iteraid C:\Windows\system32\drivers\iteraid.sys 19:56:01.0897 1384 iteraid - ok 19:56:01.0911 1384 [ 423696F3BA6472DD17699209B933BC26 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 19:56:01.0912 1384 kbdclass - ok 19:56:01.0938 1384 [ DBDF75D51464FBC47D0104EC3D572C05 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 19:56:01.0939 1384 kbdhid - ok 19:56:01.0966 1384 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] KeyIso C:\Windows\system32\lsass.exe 19:56:01.0969 1384 KeyIso - ok 19:56:02.0006 1384 [ 88956AD9FA510848AD176777A6C6C1F5 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 19:56:02.0014 1384 KSecDD - ok 19:56:02.0027 1384 [ 1D419CF43DB29396ECD7113D129D94EB ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 19:56:02.0028 1384 ksthunk - ok 19:56:02.0060 1384 [ 1FAF6926F3416D3DA05C5B265491BDAE ] KtmRm C:\Windows\system32\msdtckrm.dll 19:56:02.0065 1384 KtmRm - ok 19:56:02.0099 1384 [ 50C7A3CB427E9BB5ED0708A669956AB5 ] LanmanServer C:\Windows\system32\srvsvc.dll 19:56:02.0103 1384 LanmanServer - ok 19:56:02.0126 1384 [ CAF86FC1388BE1E470F1A7B43E348ADB ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 19:56:02.0130 1384 LanmanWorkstation - ok 19:56:02.0166 1384 [ 793FF718477345CD5D232C50BED1E452 ] LightScribeService C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe 19:56:02.0167 1384 LightScribeService - ok 19:56:02.0205 1384 [ 8049859F85CB18083AD26063BDF1766B ] LivedriveVSSService C:\Program Files (x86)\Livedrive\VSSService.exe 19:56:02.0208 1384 LivedriveVSSService - ok 19:56:02.0243 1384 [ 96ECE2659B6654C10A0C310AE3A6D02C ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 19:56:02.0244 1384 lltdio - ok 19:56:02.0265 1384 [ 961CCBD0B1CCB5675D64976FAE37D092 ] lltdsvc C:\Windows\System32\lltdsvc.dll 19:56:02.0270 1384 lltdsvc - ok 19:56:02.0283 1384 [ A47F8080CACC23C91FE823AD19AA5612 ] lmhosts C:\Windows\System32\lmhsvc.dll 19:56:02.0285 1384 lmhosts - ok 19:56:02.0314 1384 [ 650B3BE84ECA8BE345F9C423EF02605D ] LMS C:\Program Files\Intel\AMT\LMS.exe 19:56:02.0317 1384 LMS - ok 19:56:02.0333 1384 [ ACBE1AF32D3123E330A07BFBC5EC4A9B ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 19:56:02.0335 1384 LSI_FC - ok 19:56:02.0362 1384 [ 799FFB2FC4729FA46D2157C0065B3525 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 19:56:02.0364 1384 LSI_SAS - ok 19:56:02.0389 1384 [ F445FF1DAAD8A226366BFAF42551226B ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 19:56:02.0391 1384 LSI_SCSI - ok 19:56:02.0429 1384 [ 52F87B9CC8932C2A7375C3B2A9BE5E3E ] luafv C:\Windows\system32\drivers\luafv.sys 19:56:02.0671 1384 luafv - ok 19:56:02.0685 1384 lvpepf64 - ok 19:56:02.0690 1384 LVPr2M64 - ok 19:56:02.0731 1384 [ EF2BE2F45D4F06410A3BD2A3467325B0 ] LVRS64 C:\Windows\system32\DRIVERS\lvrs64.sys 19:56:02.0736 1384 LVRS64 - ok 19:56:02.0741 1384 LVUSBS64 - ok 19:56:02.0872 1384 [ AC22F92C6078640FE8A70D662A2F3AD5 ] LVUVC64 C:\Windows\system32\DRIVERS\lvuvc64.sys 19:56:02.0963 1384 LVUVC64 - ok 19:56:02.0992 1384 [ 76A58DF02BD4EA29F189B82D0BEF17F8 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 19:56:02.0995 1384 Mcx2Svc - ok 19:56:03.0056 1384 [ 7C08B11778AE7FF97E4601D6111F104A ] ME Services Manager C:\Program Files\intel\inteldh\msm\MSM.exe 19:56:03.0114 1384 ME Services Manager - ok 19:56:03.0143 1384 [ 5C5CD6AACED32FB26C3FB34B3DCF972F ] megasas C:\Windows\system32\drivers\megasas.sys 19:56:03.0144 1384 megasas - ok 19:56:03.0172 1384 [ 859BC2436B076C77C159ED694ACFE8F8 ] MegaSR C:\Windows\system32\drivers\megasr.sys 19:56:03.0178 1384 MegaSR - ok 19:56:03.0220 1384 Microsoft SharePoint Workspace Audit Service - ok 19:56:03.0239 1384 [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] MMCSS C:\Windows\system32\mmcss.dll 19:56:03.0241 1384 MMCSS - ok 19:56:03.0273 1384 [ 59848D5CC74606F0EE7557983BB73C2E ] Modem C:\Windows\system32\drivers\modem.sys 19:56:03.0274 1384 Modem - ok 19:56:03.0322 1384 [ C247CC2A57E0A0C8C6DCCF7807B3E9E5 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 19:56:03.0323 1384 monitor - ok 19:56:03.0330 1384 [ 9367304E5E412B120CF5F4EA14E4E4F1 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 19:56:03.0331 1384 mouclass - ok 19:56:03.0345 1384 [ C2C2BD5C5CE5AAF786DDD74B75D2AC69 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 19:56:03.0346 1384 mouhid - ok 19:56:03.0355 1384 [ 11BC9B1E8801B01F7F6ADB9EAD30019B ] MountMgr C:\Windows\system32\drivers\mountmgr.sys 19:56:03.0356 1384 MountMgr - ok 19:56:03.0393 1384 [ 8C7336950F1E69CDFD811CBBD9CF00A2 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 19:56:03.0394 1384 MozillaMaintenance - ok 19:56:03.0416 1384 [ F8276EB8698142884498A528DFEA8478 ] mpio C:\Windows\system32\drivers\mpio.sys 19:56:03.0418 1384 mpio - ok 19:56:03.0437 1384 [ C92B9ABDB65A5991E00C28F13491DBA2 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 19:56:03.0438 1384 mpsdrv - ok 19:56:03.0478 1384 [ 897E3BAF68BA406A61682AE39C83900C ] MpsSvc C:\Windows\system32\mpssvc.dll 19:56:03.0495 1384 MpsSvc - ok 19:56:03.0518 1384 [ 3C200630A89EF2C0864D515B7A75802E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys 19:56:03.0519 1384 Mraid35x - ok 19:56:03.0546 1384 [ 7C1DE4AA96DC0C071611F9E7DE02A68D ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 19:56:03.0548 1384 MRxDAV - ok 19:56:03.0577 1384 [ 1485811B320FF8C7EDAD1CAEBB1C6C2B ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 19:56:03.0579 1384 mrxsmb - ok 19:56:03.0601 1384 [ 3B929A60C833FC615FD97FBA82BC7632 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 19:56:03.0605 1384 mrxsmb10 - ok 19:56:03.0610 1384 [ C64AB3E1F53B4F5B5BB6D796B2D7BEC3 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 19:56:03.0612 1384 mrxsmb20 - ok 19:56:03.0639 1384 [ 1AC860612B85D8E85EE257D372E39F4D ] msahci C:\Windows\system32\drivers\msahci.sys 19:56:03.0640 1384 msahci - ok 19:56:03.0656 1384 [ 264BBB4AAF312A485F0E44B65A6B7202 ] msdsm C:\Windows\system32\drivers\msdsm.sys 19:56:03.0658 1384 msdsm - ok 19:56:03.0689 1384 [ 7EC02CE772F068ED0BEAFA3DA341A9BC ] MSDTC C:\Windows\System32\msdtc.exe 19:56:03.0692 1384 MSDTC - ok 19:56:03.0724 1384 [ 704F59BFC4512D2BB0146AEC31B10A7C ] Msfs C:\Windows\system32\drivers\Msfs.sys 19:56:03.0725 1384 Msfs - ok 19:56:03.0747 1384 [ 00EBC952961664780D43DCA157E79B27 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 19:56:03.0748 1384 msisadrv - ok 19:56:03.0766 1384 [ 366B0C1F4478B519C181E37D43DCDA32 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 19:56:03.0770 1384 MSiSCSI - ok 19:56:03.0774 1384 msiserver - ok 19:56:03.0796 1384 [ 0EA73E498F53B96D83DBFCA074AD4CF8 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 19:56:03.0797 1384 MSKSSRV - ok 19:56:03.0887 1384 [ 3D9DF5C79ABE835E58DF426B14600A33 ] msoidsvc C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE 19:56:03.0928 1384 msoidsvc - ok 19:56:03.0956 1384 [ 52E59B7E992A58E740AA63F57EDBAE8B ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 19:56:03.0957 1384 MSPCLOCK - ok 19:56:03.0963 1384 [ 49084A75BAE043AE02D5B44D02991BB2 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 19:56:03.0964 1384 MSPQM - ok 19:56:04.0000 1384 [ DC6CCF440CDEDE4293DB41C37A5060A5 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 19:56:04.0004 1384 MsRPC - ok 19:56:04.0032 1384 [ 855796E59DF77EA93AF46F20155BF55B ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys 19:56:04.0033 1384 mssmbios - ok 19:56:04.0050 1384 [ 86D632D75D05D5B7C7C043FA3564AE86 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 19:56:04.0051 1384 MSTEE - ok 19:56:04.0068 1384 [ 0CC49F78D8ACA0877D885F149084E543 ] Mup C:\Windows\system32\Drivers\mup.sys 19:56:04.0069 1384 Mup - ok 19:56:04.0111 1384 [ A5B10C845E7538C60C0F5D87A57CB3F5 ] napagent C:\Windows\system32\qagentRT.dll 19:56:04.0126 1384 napagent - ok 19:56:04.0155 1384 [ 2007B826C4ACD94AE32232B41F0842B9 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 19:56:04.0158 1384 NativeWifiP - ok 19:56:04.0191 1384 [ 65950E07329FCEE8E6516B17C8D0ABB6 ] NDIS C:\Windows\system32\drivers\ndis.sys 19:56:04.0223 1384 NDIS - ok 19:56:04.0241 1384 [ 64DF698A425478E321981431AC171334 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 19:56:04.0242 1384 NdisTapi - ok 19:56:04.0259 1384 [ 8BAA43196D7B5BB972C9A6B2BBF61A19 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 19:56:04.0260 1384 Ndisuio - ok 19:56:04.0288 1384 [ F8158771905260982CE724076419EF19 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 19:56:04.0291 1384 NdisWan - ok 19:56:04.0305 1384 [ 9CB77ED7CB72850253E973A2D6AFDF49 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 19:56:04.0306 1384 NDProxy - ok 19:56:04.0370 1384 [ B90E093E7A7250906F1054418B5339C0 ] Nero BackItUp Scheduler 4.0 C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe 19:56:04.0381 1384 Nero BackItUp Scheduler 4.0 - ok 19:56:04.0434 1384 [ 2334DC48997BA203B794DF3EE70521DB ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll 19:56:04.0436 1384 Net Driver HPZ12 - ok 19:56:04.0447 1384 [ A499294F5029A7862ADC115BDA7371CE ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 19:56:04.0448 1384 NetBIOS - ok 19:56:04.0477 1384 [ FC2C792EBDDC8E28DF939D6A92C83D61 ] netbt C:\Windows\system32\DRIVERS\netbt.sys 19:56:04.0481 1384 netbt - ok 19:56:04.0491 1384 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] Netlogon C:\Windows\system32\lsass.exe 19:56:04.0493 1384 Netlogon - ok 19:56:04.0509 1384 [ 9B63B29DEFC0F3115A559D2597BF5D75 ] Netman C:\Windows\System32\netman.dll 19:56:04.0516 1384 Netman - ok 19:56:04.0577 1384 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 19:56:04.0579 1384 NetMsmqActivator - ok 19:56:04.0583 1384 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 19:56:04.0584 1384 NetPipeActivator - ok 19:56:04.0608 1384 [ 7846D0136CC2B264926A73047BA7688A ] netprofm C:\Windows\System32\netprofm.dll 19:56:04.0613 1384 netprofm - ok 19:56:04.0625 1384 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 19:56:04.0627 1384 NetTcpActivator - ok 19:56:04.0632 1384 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 19:56:04.0633 1384 NetTcpPortSharing - ok 19:56:04.0664 1384 [ 4AC08BD6AF2DF42E0C3196D826C8AEA7 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 19:56:04.0665 1384 nfrd960 - ok 19:56:04.0692 1384 [ F145BF4C4668E7E312069F81EF847CFC ] NlaSvc C:\Windows\System32\nlasvc.dll 19:56:04.0697 1384 NlaSvc - ok 19:56:04.0723 1384 [ B298874F8E0EA93F06EC40AA8D146478 ] Npfs C:\Windows\system32\drivers\Npfs.sys 19:56:04.0724 1384 Npfs - ok 19:56:04.0734 1384 [ ACB62BAA1C319B17752553DF3026EEEB ] nsi C:\Windows\system32\nsisvc.dll 19:56:04.0736 1384 nsi - ok 19:56:04.0746 1384 [ 1523AF19EE8B030BA682F7A53537EAEB ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 19:56:04.0747 1384 nsiproxy - ok 19:56:04.0799 1384 [ BAC869DFB98E499BA4D9BB1FB43270E1 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 19:56:04.0824 1384 Ntfs - ok 19:56:04.0862 1384 [ A2B6583A5652A385DFF5E4F49AD48761 ] NTIBackupSvc C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe 19:56:04.0863 1384 NTIBackupSvc - ok 19:56:04.0873 1384 [ 7D397449AAF52B0E7C79B64F6AD4473E ] NTIDrvr C:\Windows\system32\Drivers\NTIDrvr.sys 19:56:04.0874 1384 NTIDrvr - ok 19:56:04.0883 1384 [ 40B87FE8A1A9A5AC9E5A91D96F212BCD ] NTISchedulerSvc C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe 19:56:04.0885 1384 NTISchedulerSvc - ok 19:56:04.0915 1384 [ D4012918D3A3847B44B888D56BC095D6 ] NuidFltr C:\Windows\system32\DRIVERS\NuidFltr.sys 19:56:04.0916 1384 NuidFltr - ok 19:56:04.0924 1384 [ DD5D684975352B85B52E3FD5347C20CB ] Null C:\Windows\system32\drivers\Null.sys 19:56:04.0925 1384 Null - ok 19:56:05.0171 1384 [ 5104BAC2DA2A5BDD86AC6B0708B00F06 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 19:56:05.0371 1384 nvlddmkm - ok 19:56:05.0407 1384 [ 2C040B7ADA5B06F6FACADAC8514AA034 ] nvraid C:\Windows\system32\drivers\nvraid.sys 19:56:05.0409 1384 nvraid - ok 19:56:05.0422 1384 [ F7EA0FE82842D05EDA3EFDD376DBFDBA ] nvstor C:\Windows\system32\drivers\nvstor.sys 19:56:05.0423 1384 nvstor - ok 19:56:05.0456 1384 [ DDFAFCE89A5C93D04712B86F94E9FCBA ] nvsvc C:\Windows\system32\nvvsvc.exe 19:56:05.0473 1384 nvsvc - ok 19:56:05.0558 1384 [ 84E035225474E48CD3A6A3CE52332095 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 19:56:05.0586 1384 nvUpdatusService - ok 19:56:05.0610 1384 [ 19067CA93075EF4823E3938A686F532F ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 19:56:05.0612 1384 nv_agp - ok 19:56:05.0618 1384 NwlnkFlt - ok 19:56:05.0623 1384 NwlnkFwd - ok 19:56:05.0672 1384 [ B5B1CE65AC15BBD11C0619E3EF7CFC28 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys 19:56:05.0673 1384 ohci1394 - ok 19:56:05.0696 1384 [ 4965B005492CBA7719E82B71E3245495 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 19:56:05.0698 1384 ose64 - ok 19:56:05.0832 1384 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 19:56:05.0914 1384 osppsvc - ok 19:56:05.0963 1384 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2pimsvc C:\Windows\system32\p2psvc.dll 19:56:05.0979 1384 p2pimsvc - ok 19:56:06.0018 1384 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2psvc C:\Windows\system32\p2psvc.dll 19:56:06.0024 1384 p2psvc - ok 19:56:06.0057 1384 [ AECD57F94C887F58919F307C35498EA0 ] Parport C:\Windows\system32\drivers\parport.sys 19:56:06.0059 1384 Parport - ok 19:56:06.0095 1384 [ B43751085E2ABE389DA466BC62A4B987 ] partmgr C:\Windows\system32\drivers\partmgr.sys 19:56:06.0097 1384 partmgr - ok 19:56:06.0111 1384 [ 9AB157B374192FF276C1628FBDBA2B0E ] PcaSvc C:\Windows\System32\pcasvc.dll 19:56:06.0113 1384 PcaSvc - ok 19:56:06.0123 1384 [ 47AB1E0FC9D0E12BB53BA246E3A0906D ] pci C:\Windows\system32\drivers\pci.sys 19:56:06.0126 1384 pci - ok 19:56:06.0143 1384 [ 8D618C829034479985A9ED56106CC732 ] pciide C:\Windows\system32\drivers\pciide.sys 19:56:06.0143 1384 pciide - ok 19:56:06.0161 1384 [ 037661F3D7C507C9993B7010CEEE6288 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 19:56:06.0164 1384 pcmcia - ok 19:56:06.0186 1384 [ 58865916F53592A61549B04941BFD80D ] PEAUTH C:\Windows\system32\drivers\peauth.sys 19:56:06.0203 1384 PEAUTH - ok 19:56:06.0270 1384 [ 0ED8727EA0172860F47258456C06CAEA ] PerfHost C:\Windows\SysWow64\perfhost.exe 19:56:06.0272 1384 PerfHost - ok 19:56:06.0302 1384 PID_PEPI - ok 19:56:06.0332 1384 [ E9E68C1A0F25CF4A7AC966EEA74EE89E ] pla C:\Windows\system32\pla.dll 19:56:06.0357 1384 pla - ok 19:56:06.0396 1384 [ FE6B0F59215C9FD9F9D26539C58C8B82 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 19:56:06.0401 1384 PlugPlay - ok 19:56:06.0439 1384 [ AC78DF349F0E4CFB8B667C0CFFF83CCE ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll 19:56:06.0441 1384 Pml Driver HPZ12 - ok 19:56:06.0488 1384 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPAutoReg C:\Windows\system32\p2psvc.dll 19:56:06.0494 1384 PNRPAutoReg - ok 19:56:06.0538 1384 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPsvc C:\Windows\system32\p2psvc.dll 19:56:06.0544 1384 PNRPsvc - ok 19:56:06.0590 1384 [ 89A5560671C2D8B4A4B51F3E1AA069D8 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 19:56:06.0607 1384 PolicyAgent - ok 19:56:06.0649 1384 [ 23386E9952025F5F21C368971E2E7301 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 19:56:06.0650 1384 PptpMiniport - ok 19:56:06.0669 1384 [ 5080E59ECEE0BC923F14018803AA7A01 ] Processor C:\Windows\system32\drivers\processr.sys 19:56:06.0670 1384 Processor - ok 19:56:06.0697 1384 [ E058CE4FC2449D8BFA14739C83B7FF2A ] ProfSvc C:\Windows\system32\profsvc.dll 19:56:06.0701 1384 ProfSvc - ok 19:56:06.0708 1384 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] ProtectedStorage C:\Windows\system32\lsass.exe 19:56:06.0709 1384 ProtectedStorage - ok 19:56:06.0737 1384 [ C5AB7F0809392D0DA027F4A2A81BFA31 ] PSched C:\Windows\system32\DRIVERS\pacer.sys 19:56:06.0738 1384 PSched - ok 19:56:06.0757 1384 [ 2CFD31D41CDE75328ACAEEE2D4F4B836 ] PSDFilter C:\Windows\system32\DRIVERS\psdfilter.sys 19:56:06.0758 1384 PSDFilter - ok 19:56:06.0777 1384 [ 51A585F999672D8BB07F22AE12B40846 ] PSDNServ C:\Windows\system32\DRIVERS\PSDNServ.sys 19:56:06.0778 1384 PSDNServ - ok 19:56:06.0793 1384 [ DB50D3F5C31B1A848B04F7F2A6FF2709 ] psdvdisk C:\Windows\system32\DRIVERS\PSDVdisk.sys 19:56:06.0794 1384 psdvdisk - ok 19:56:06.0822 1384 [ 0B83F4E681062F3839BE2EC1D98FD94A ] ql2300 C:\Windows\system32\drivers\ql2300.sys 19:56:06.0847 1384 ql2300 - ok 19:56:06.0862 1384 [ E1C80F8D4D1E39EF9595809C1369BF2A ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 19:56:06.0865 1384 ql40xx - ok 19:56:06.0889 1384 [ 90574842C3DA781E279061A3EFF91F07 ] QWAVE C:\Windows\system32\qwave.dll 19:56:06.0895 1384 QWAVE - ok 19:56:06.0902 1384 [ E8D76EDAB77EC9C634C27B8EAC33ADC5 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 19:56:06.0903 1384 QWAVEdrv - ok 19:56:06.0913 1384 [ 1013B3B663A56D3DDD784F581C1BD005 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 19:56:06.0914 1384 RasAcd - ok 19:56:06.0932 1384 [ B2AE18F847D07F0044404DDF7CB04497 ] RasAuto C:\Windows\System32\rasauto.dll 19:56:06.0936 1384 RasAuto - ok 19:56:06.0941 1384 [ AC7BC4D42A7E558718DFDEC599BBFC2C ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 19:56:06.0944 1384 Rasl2tp - ok 19:56:06.0977 1384 [ 3AD83E4046C43BE510DE681588ACB8AF ] RasMan C:\Windows\System32\rasmans.dll 19:56:06.0983 1384 RasMan - ok 19:56:07.0018 1384 [ 4517FBF8B42524AFE4EDE1DE102AAE3E ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 19:56:07.0019 1384 RasPppoe - ok 19:56:07.0050 1384 [ C6A593B51F34C33E5474539544072527 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 19:56:07.0051 1384 RasSstp - ok 19:56:07.0077 1384 [ 322DB5C6B55E8D8EE8D6F358B2AAABB1 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 19:56:07.0081 1384 rdbss - ok 19:56:07.0091 1384 [ 603900CC05F6BE65CCBF373800AF3716 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 19:56:07.0092 1384 RDPCDD - ok 19:56:07.0115 1384 [ C045D1FB111C28DF0D1BE8D4BDA22C06 ] rdpdr C:\Windows\system32\drivers\rdpdr.sys 19:56:07.0119 1384 rdpdr - ok 19:56:07.0138 1384 [ CAB9421DAF3D97B33D0D055858E2C3AB ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 19:56:07.0139 1384 RDPENCDD - ok 19:56:07.0167 1384 [ AE4BD9E1C33D351D8E607FC81F15160C ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 19:56:07.0170 1384 RDPWD - ok 19:56:07.0188 1384 [ C612B9557DA73F70D41F8A6FBC8E5344 ] RemoteAccess C:\Windows\System32\mprdim.dll 19:56:07.0190 1384 RemoteAccess - ok 19:56:07.0221 1384 [ 44B9D8EC2F3EF3A0EFB00857AF70D861 ] RemoteRegistry C:\Windows\system32\regsvc.dll 19:56:07.0226 1384 RemoteRegistry - ok 19:56:07.0267 1384 [ A035A7BF5132682F53F1E7B955690CE7 ] RichVideo C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe 19:56:07.0270 1384 RichVideo - ok 19:56:07.0280 1384 [ F46C457840D4B7A4DAAFEE739CE04102 ] RpcLocator C:\Windows\system32\locator.exe 19:56:07.0282 1384 RpcLocator - ok 19:56:07.0319 1384 [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] RpcSs C:\Windows\system32\rpcss.dll 19:56:07.0326 1384 RpcSs - ok 19:56:07.0348 1384 [ 22A9CB08B1A6707C1550C6BF099AAE73 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 19:56:07.0350 1384 rspndr - ok 19:56:07.0383 1384 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] SamSs C:\Windows\system32\lsass.exe 19:56:07.0384 1384 SamSs - ok 19:56:07.0403 1384 [ CD9C693589C60AD59BBBCFB0E524E01B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 19:56:07.0404 1384 sbp2port - ok 19:56:07.0425 1384 [ FD1CDCF108D5EF3366F00D18B70FB89B ] SCardSvr C:\Windows\System32\SCardSvr.dll 19:56:07.0430 1384 SCardSvr - ok 19:56:07.0463 1384 [ 0F838C811AD295D2A4489B9993096C63 ] Schedule C:\Windows\system32\schedsvc.dll 19:56:07.0478 1384 Schedule - ok 19:56:07.0520 1384 [ 5A268127633C7EE2A7FB87F39D748D56 ] SCPolicySvc C:\Windows\System32\certprop.dll 19:56:07.0521 1384 SCPolicySvc - ok 19:56:07.0542 1384 [ 4FF71B076A7760FE75EA5AE2D0EE0018 ] SDRSVC C:\Windows\System32\SDRSVC.dll 19:56:07.0545 1384 SDRSVC - ok 19:56:07.0575 1384 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 19:56:07.0576 1384 secdrv - ok 19:56:07.0589 1384 [ 5ACDCBC67FCF894A1815B9F96D704490 ] seclogon C:\Windows\system32\seclogon.dll 19:56:07.0591 1384 seclogon - ok 19:56:07.0602 1384 [ 90973A64B96CD647FF81C79443618EED ] SENS C:\Windows\System32\sens.dll 19:56:07.0605 1384 SENS - ok 19:56:07.0616 1384 [ 2449316316411D65BD2C761A6FFB2CE2 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 19:56:07.0616 1384 Serenum - ok 19:56:07.0629 1384 [ 4B438170BE2FC8E0BD35EE87A960F84F ] Serial C:\Windows\system32\DRIVERS\serial.sys 19:56:07.0631 1384 Serial - ok 19:56:07.0646 1384 [ A842F04833684BCEEA7336211BE478DF ] sermouse C:\Windows\system32\drivers\sermouse.sys 19:56:07.0647 1384 sermouse - ok 19:56:07.0691 1384 [ A8E4A4407A09F35DCCC3771AF590B0C4 ] SessionEnv C:\Windows\system32\sessenv.dll 19:56:07.0694 1384 SessionEnv - ok 19:56:07.0727 1384 [ 14D4B4465193A87C127933978E8C4106 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 19:56:07.0728 1384 sffdisk - ok 19:56:07.0762 1384 [ 7073AEE3F82F3D598E3825962AA98AB2 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 19:56:07.0763 1384 sffp_mmc - ok 19:56:07.0773 1384 [ 35E59EBE4A01A0532ED67975161C7B82 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 19:56:07.0774 1384 sffp_sd - ok 19:56:07.0785 1384 [ 6B7838C94135768BD455CBDC23E39E5F ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 19:56:07.0786 1384 sfloppy - ok 19:56:07.0813 1384 [ 4C5AEE179DA7E1EE9A9CCB9DA289AF34 ] SharedAccess C:\Windows\System32\ipnathlp.dll 19:56:07.0818 1384 SharedAccess - ok 19:56:07.0847 1384 [ 56793271ECDEDD350C5ADD305603E963 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 19:56:07.0853 1384 ShellHWDetection - ok 19:56:07.0866 1384 [ 7A5DE502AEB719D4594C6471060A78B3 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys 19:56:07.0867 1384 SiSRaid2 - ok 19:56:07.0877 1384 [ 3A2F769FAB9582BC720E11EA1DFB184D ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 19:56:07.0879 1384 SiSRaid4 - ok 19:56:07.0903 1384 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 19:56:07.0905 1384 SkypeUpdate - ok 19:56:07.0978 1384 [ A9A27A8E257B45A604FDAD4F26FE7241 ] slsvc C:\Windows\system32\SLsvc.exe 19:56:08.0045 1384 slsvc - ok 19:56:08.0084 1384 [ FD74B4B7C2088E390A30C85A896FC3AF ] SLUINotify C:\Windows\system32\SLUINotify.dll 19:56:08.0087 1384 SLUINotify - ok 19:56:08.0130 1384 [ 290B6F6A0EC4FCDFC90F5CB6D7020473 ] Smb C:\Windows\system32\DRIVERS\smb.sys 19:56:08.0131 1384 Smb - ok 19:56:08.0178 1384 [ F8F47F38909823B1AF28D60B96340CFF ] SNMPTRAP C:\Windows\System32\snmptrap.exe 19:56:08.0181 1384 SNMPTRAP - ok 19:56:08.0211 1384 [ BDCE0DE74BC57ABD1EF2CE6AEAC37876 ] Software Services Manager C:\Program Files\intel\inteldh\common\IntelDHSvcMgr.exe 19:56:08.0212 1384 Software Services Manager - ok 19:56:08.0250 1384 [ 386C3C63F00A7040C7EC5E384217E89D ] spldr C:\Windows\system32\drivers\spldr.sys 19:56:08.0251 1384 spldr - ok 19:56:08.0288 1384 [ F66FF751E7EFC816D266977939EF5DC3 ] Spooler C:\Windows\System32\spoolsv.exe 19:56:08.0293 1384 Spooler - ok 19:56:08.0345 1384 [ 88E5162E58C8919CC873F5D8946197CF ] sptd C:\Windows\system32\Drivers\sptd.sys 19:56:08.0346 1384 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 88E5162E58C8919CC873F5D8946197CF 19:56:08.0348 1384 sptd ( LockedFile.Multi.Generic ) - warning 19:56:08.0348 1384 sptd - detected LockedFile.Multi.Generic (1) 19:56:08.0384 1384 [ 880A57FCCB571EBD063D4DD50E93E46D ] srv C:\Windows\system32\DRIVERS\srv.sys 19:56:08.0390 1384 srv - ok 19:56:08.0421 1384 [ A1AD14A6D7A37891FFFECA35EBBB0730 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 19:56:08.0423 1384 srv2 - ok 19:56:08.0439 1384 [ 4BED62F4FA4D8300973F1151F4C4D8A7 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 19:56:08.0442 1384 srvnet - ok 19:56:08.0469 1384 [ 192C74646EC5725AEF3F80D19FF75F6A ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 19:56:08.0473 1384 SSDPSRV - ok 19:56:08.0482 1384 [ 2EE3FA0308E6185BA64A9A7F2E74332B ] SstpSvc C:\Windows\system32\sstpsvc.dll 19:56:08.0485 1384 SstpSvc - ok 19:56:08.0526 1384 Steam Client Service - ok 19:56:08.0584 1384 [ F0359F7CE712D69ACEF0886BDB4792ED ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 19:56:08.0589 1384 Stereo Service - ok 19:56:08.0639 1384 [ 15825C1FBFB8779992CB65087F316AF5 ] stisvc C:\Windows\System32\wiaservc.dll 19:56:08.0655 1384 stisvc - ok 19:56:08.0692 1384 [ 8A851CA908B8B974F89C50D2E18D4F0C ] swenum C:\Windows\system32\DRIVERS\swenum.sys 19:56:08.0693 1384 swenum - ok 19:56:08.0721 1384 [ 6DE37F4DE19D4EFD9C48C43ADDBC949A ] swprv C:\Windows\System32\swprv.dll 19:56:08.0729 1384 swprv - ok 19:56:08.0751 1384 [ 2F26A2C6FC96B29BEFF5D8ED74E6625B ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys 19:56:08.0752 1384 Symc8xx - ok 19:56:08.0764 1384 [ A909667976D3BCCD1DF813FED517D837 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys 19:56:08.0765 1384 Sym_hi - ok 19:56:08.0779 1384 [ 36887B56EC2D98B9C362F6AE4DE5B7B0 ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys 19:56:08.0780 1384 Sym_u3 - ok 19:56:08.0814 1384 [ 92D7A8B0F87B036F17D25885937897A6 ] SysMain C:\Windows\system32\sysmain.dll 19:56:08.0828 1384 SysMain - ok 19:56:08.0867 1384 [ 005CE42567F9113A3BCCB3B20073B029 ] TabletInputService C:\Windows\System32\TabSvc.dll 19:56:08.0871 1384 TabletInputService - ok 19:56:08.0902 1384 [ 595CB8DA5B522AD8CC28193DC21FD496 ] tap0901 C:\Windows\system32\DRIVERS\tap0901.sys 19:56:08.0903 1384 tap0901 - ok 19:56:08.0925 1384 [ CC2562B4D55E0B6A4758C65407F63B79 ] TapiSrv C:\Windows\System32\tapisrv.dll 19:56:08.0931 1384 TapiSrv - ok 19:56:08.0953 1384 [ CDBE8D7C1E201B911CDC346D06617FB5 ] TBS C:\Windows\System32\tbssvc.dll 19:56:08.0957 1384 TBS - ok 19:56:08.0999 1384 [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip C:\Windows\system32\drivers\tcpip.sys 19:56:09.0025 1384 Tcpip - ok 19:56:09.0088 1384 [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys 19:56:09.0097 1384 Tcpip6 - ok 19:56:09.0132 1384 [ C7E72A4071EE0200E3C075DACFB2B334 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 19:56:09.0133 1384 tcpipreg - ok 19:56:09.0144 1384 [ 1D8BF4AAA5FB7A2761475781DC1195BC ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 19:56:09.0145 1384 TDPIPE - ok 19:56:09.0156 1384 [ 7F7E00CDF609DF657F4CDA02DD1C9BB1 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 19:56:09.0157 1384 TDTCP - ok 19:56:09.0179 1384 [ 458919C8C42E398DC4802178D5FFEE27 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 19:56:09.0180 1384 tdx - ok 19:56:09.0292 1384 [ 9F3E7CABE86BBDECA009DE291DB6D9E2 ] TeamViewer8 C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe 19:56:09.0367 1384 TeamViewer8 - ok 19:56:09.0401 1384 [ 8C19678D22649EC002EF2282EAE92F98 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys 19:56:09.0402 1384 TermDD - ok 19:56:09.0435 1384 [ 5CDD30BC217082DAC71A9878D9BFD566 ] TermService C:\Windows\System32\termsrv.dll 19:56:09.0452 1384 TermService - ok 19:56:09.0480 1384 [ 56793271ECDEDD350C5ADD305603E963 ] Themes C:\Windows\system32\shsvcs.dll 19:56:09.0484 1384 Themes - ok 19:56:09.0522 1384 [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] THREADORDER C:\Windows\system32\mmcss.dll 19:56:09.0524 1384 THREADORDER - ok 19:56:09.0539 1384 [ F4689F05AF472A651A7B1B7B02D200E7 ] TrkWks C:\Windows\System32\trkwks.dll 19:56:09.0543 1384 TrkWks - ok 19:56:09.0590 1384 [ 66328B08EF5A9305D8EDE36B93930369 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 19:56:09.0590 1384 TrustedInstaller - ok 19:56:09.0609 1384 [ 9E5409CD17C8BEF193AAD498F3BC2CB8 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 19:56:09.0610 1384 tssecsrv - ok 19:56:09.0631 1384 [ 89EC74A9E602D16A75A4170511029B3C ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys 19:56:09.0632 1384 tunmp - ok 19:56:09.0651 1384 [ 30A9B3F45AD081BFFC3BCAA9C812B609 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 19:56:09.0653 1384 tunnel - ok 19:56:09.0670 1384 [ FEC266EF401966311744BD0F359F7F56 ] uagp35 C:\Windows\system32\drivers\uagp35.sys 19:56:09.0671 1384 uagp35 - ok 19:56:09.0698 1384 [ 00C8CE31657624A125FDB90EFD554371 ] UBHelper C:\Windows\system32\drivers\UBHelper.sys 19:56:09.0699 1384 UBHelper - ok 19:56:09.0734 1384 [ FAF2640A2A76ED03D449E443194C4C34 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 19:56:09.0738 1384 udfs - ok 19:56:09.0758 1384 [ 060507C4113391394478F6953A79EEDC ] UI0Detect C:\Windows\system32\UI0Detect.exe 19:56:09.0760 1384 UI0Detect - ok 19:56:09.0778 1384 [ 4EC9447AC3AB462647F60E547208CA00 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 19:56:09.0780 1384 uliagpkx - ok 19:56:09.0793 1384 [ 697F0446134CDC8F99E69306184FBBB4 ] uliahci C:\Windows\system32\drivers\uliahci.sys 19:56:09.0795 1384 uliahci - ok 19:56:09.0809 1384 [ 31707F09846056651EA2C37858F5DDB0 ] UlSata C:\Windows\system32\drivers\ulsata.sys 19:56:09.0812 1384 UlSata - ok 19:56:09.0827 1384 [ 85E5E43ED5B48C8376281BAB519271B7 ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys 19:56:09.0830 1384 ulsata2 - ok 19:56:09.0844 1384 [ 46E9A994C4FED537DD951F60B86AD3F4 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 19:56:09.0845 1384 umbus - ok 19:56:09.0907 1384 [ 927754ABF077AEB5504BE4E0F2C60C1B ] UMVPFSrv C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe 19:56:09.0910 1384 UMVPFSrv - ok 19:56:09.0927 1384 [ 7093799FF80E9DECA0680D2E3535BE60 ] upnphost C:\Windows\System32\upnphost.dll 19:56:09.0934 1384 upnphost - ok 19:56:09.0968 1384 [ AF1B9474D67897D0C2CFF58E0ACEACCC ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys 19:56:09.0970 1384 USBAAPL64 - ok 19:56:09.0995 1384 [ C6BA890DE6E41857FBE84175519CAE7D ] usbaudio C:\Windows\system32\drivers\usbaudio.sys 19:56:09.0996 1384 usbaudio - ok 19:56:10.0018 1384 [ 07E3498FC60834219D2356293DA0FECC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 19:56:10.0020 1384 usbccgp - ok 19:56:10.0036 1384 [ 9247F7E0B65852C1F6631480984D6ED2 ] usbcir C:\Windows\system32\drivers\usbcir.sys 19:56:10.0038 1384 usbcir - ok 19:56:10.0056 1384 [ 827E44DE934A736EA31E91D353EB126F ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 19:56:10.0057 1384 usbehci - ok 19:56:10.0090 1384 [ BB35CD80A2ECECFADC73569B3D70C7D1 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 19:56:10.0094 1384 usbhub - ok 19:56:10.0105 1384 [ EBA14EF0C07CEC233F1529C698D0D154 ] usbohci C:\Windows\system32\drivers\usbohci.sys 19:56:10.0106 1384 usbohci - ok 19:56:10.0122 1384 [ 28B693B6D31E7B9332C1BDCEFEF228C1 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 19:56:10.0123 1384 usbprint - ok 19:56:10.0150 1384 [ EA0BF666868964FBE8CB10E50C97B9F1 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys 19:56:10.0151 1384 usbscan - ok 19:56:10.0161 1384 [ B854C1558FCA0C269A38663E8B59B581 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 19:56:10.0163 1384 USBSTOR - ok 19:56:10.0168 1384 [ B2872CBF9F47316ABD0E0C74A1ABA507 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 19:56:10.0169 1384 usbuhci - ok 19:56:10.0193 1384 [ FC33099877790D51B0927B7039059855 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys 19:56:10.0195 1384 usbvideo - ok 19:56:10.0229 1384 [ D76E231E4850BB3F88A3D9A78DF191E3 ] UxSms C:\Windows\System32\uxsms.dll 19:56:10.0232 1384 UxSms - ok 19:56:10.0265 1384 [ 294945381DFA7CE58CECF0A9896AF327 ] vds C:\Windows\System32\vds.exe 19:56:10.0282 1384 vds - ok 19:56:10.0297 1384 [ 916B94BCF1E09873FFF2D5FB11767BBC ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 19:56:10.0298 1384 vga - ok 19:56:10.0302 1384 [ B83AB16B51FEDA65DD81B8C59D114D63 ] VgaSave C:\Windows\System32\drivers\vga.sys 19:56:10.0303 1384 VgaSave - ok 19:56:10.0314 1384 [ 8294B6C3FDB6C33F24E150DE647ECDAA ] viaide C:\Windows\system32\drivers\viaide.sys 19:56:10.0315 1384 viaide - ok 19:56:10.0326 1384 [ 2B7E885ED951519A12C450D24535DFCA ] volmgr C:\Windows\system32\drivers\volmgr.sys 19:56:10.0328 1384 volmgr - ok 19:56:10.0362 1384 [ CEC5AC15277D75D9E5DEC2E1C6EAF877 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 19:56:10.0367 1384 volmgrx - ok 19:56:10.0395 1384 [ 582F710097B46140F5A89A19A6573D4B ] volsnap C:\Windows\system32\drivers\volsnap.sys 19:56:10.0399 1384 volsnap - ok 19:56:10.0416 1384 [ A68F455ED2673835209318DD61BFBB0E ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 19:56:10.0419 1384 vsmraid - ok 19:56:10.0468 1384 [ B75232DAD33BFD95BF6F0A3E6BFF51E1 ] VSS C:\Windows\system32\vssvc.exe 19:56:10.0492 1384 VSS - ok 19:56:10.0543 1384 [ F14A7DE2EA41883E250892E1E5230A9A ] W32Time C:\Windows\system32\w32time.dll 19:56:10.0560 1384 W32Time - ok 19:56:10.0596 1384 [ FEF8FE5923FEAD2CEE4DFABFCE3393A7 ] WacomPen C:\Windows\system32\drivers\wacompen.sys 19:56:10.0598 1384 WacomPen - ok 19:56:10.0620 1384 [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys 19:56:10.0622 1384 Wanarp - ok 19:56:10.0626 1384 [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 19:56:10.0628 1384 Wanarpv6 - ok 19:56:10.0644 1384 [ B4E4C37D0AA6100090A53213EE2BF1C1 ] wcncsvc C:\Windows\System32\wcncsvc.dll 19:56:10.0661 1384 wcncsvc - ok 19:56:10.0677 1384 [ EA4B369560E986F19D93F45A881484AC ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 19:56:10.0680 1384 WcsPlugInService - ok 19:56:10.0688 1384 [ 0C17A0816F65B89E362E682AD5E7266E ] Wd C:\Windows\system32\drivers\wd.sys 19:56:10.0689 1384 Wd - ok 19:56:10.0724 1384 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 19:56:10.0741 1384 Wdf01000 - ok 19:56:10.0753 1384 [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiServiceHost C:\Windows\system32\wdi.dll 19:56:10.0757 1384 WdiServiceHost - ok 19:56:10.0761 1384 [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiSystemHost C:\Windows\system32\wdi.dll 19:56:10.0764 1384 WdiSystemHost - ok 19:56:10.0776 1384 [ 3E6D05381CF35F75EBB055544A8ED9AC ] WebClient C:\Windows\System32\webclnt.dll 19:56:10.0781 1384 WebClient - ok 19:56:10.0813 1384 [ 8D40BC587993F876658BF9FB0F7D3462 ] Wecsvc C:\Windows\system32\wecsvc.dll 19:56:10.0817 1384 Wecsvc - ok 19:56:10.0828 1384 [ 9C980351D7E96288EA0C23AE232BD065 ] wercplsupport C:\Windows\System32\wercplsupport.dll 19:56:10.0832 1384 wercplsupport - ok 19:56:10.0840 1384 [ 66B9ECEBC46683F47EDC06333C075FEF ] WerSvc C:\Windows\System32\WerSvc.dll 19:56:10.0844 1384 WerSvc - ok 19:56:10.0863 1384 WinDefend - ok 19:56:10.0872 1384 WinHttpAutoProxySvc - ok 19:56:10.0935 1384 [ D2E7296ED1BD26D8DB2799770C077A02 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 19:56:10.0948 1384 Winmgmt - ok 19:56:11.0004 1384 [ 6CBB0C68F13B9C2EC1B16F5FA5E7C869 ] WinRM C:\Windows\system32\WsmSvc.dll 19:56:11.0038 1384 WinRM - ok 19:56:11.0092 1384 [ EC339C8115E91BAED835957E9A677F16 ] Wlansvc C:\Windows\System32\wlansvc.dll 19:56:11.0109 1384 Wlansvc - ok 19:56:11.0186 1384 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 19:56:11.0219 1384 wlidsvc - ok 19:56:11.0241 1384 [ E18AEBAAA5A773FE11AA2C70F65320F5 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys 19:56:11.0242 1384 WmiAcpi - ok 19:56:11.0272 1384 [ 21FA389E65A852698B6A1341F36EE02D ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 19:56:11.0275 1384 wmiApSrv - ok 19:56:11.0278 1384 WMPNetworkSvc - ok 19:56:11.0302 1384 [ CBC156C913F099E6680D1DF9307DB7A8 ] WPCSvc C:\Windows\System32\wpcsvc.dll 19:56:11.0306 1384 WPCSvc - ok 19:56:11.0336 1384 [ 490A18B4E4D53DC10879DEAA8E8B70D9 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 19:56:11.0339 1384 WPDBusEnum - ok 19:56:11.0372 1384 [ 5E2401B3FC1089C90E081291357371A9 ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys 19:56:11.0374 1384 WpdUsb - ok 19:56:11.0490 1384 [ 991E2C2CF3BC204C2BB2EE1476149E4E ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe 19:56:11.0504 1384 WPFFontCache_v0400 - ok 19:56:11.0528 1384 [ 8A900348370E359B6BFF6A550E4649E1 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 19:56:11.0529 1384 ws2ifsl - ok 19:56:11.0561 1384 [ 9EA3E6D0EF7A5C2B9181961052A4B01A ] wscsvc C:\Windows\System32\wscsvc.dll 19:56:11.0564 1384 wscsvc - ok 19:56:11.0568 1384 WSearch - ok 19:56:11.0647 1384 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 19:56:11.0696 1384 wuauserv - ok 19:56:11.0737 1384 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 19:56:11.0738 1384 WudfPf - ok 19:56:11.0759 1384 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 19:56:11.0762 1384 WUDFRd - ok 19:56:11.0780 1384 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 19:56:11.0783 1384 wudfsvc - ok 19:56:11.0788 1384 ================ Scan global =============================== 19:56:11.0824 1384 [ 060DC3A7A9A2626031EB23D90151428D ] C:\Windows\system32\basesrv.dll 19:56:11.0847 1384 [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll 19:56:11.0905 1384 [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll 19:56:11.0943 1384 [ 934E0B7D77FF78C18D9F8891221B6DE3 ] C:\Windows\system32\services.exe 19:56:11.0959 1384 [Global] - ok 19:56:11.0960 1384 ================ Scan MBR ================================== 19:56:11.0970 1384 [ EF9CDC51B437D322D54016B68F003416 ] \Device\Harddisk0\DR0 19:56:14.0294 1384 \Device\Harddisk0\DR0 - ok 19:56:14.0298 1384 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk6\DR6 19:56:14.0302 1384 \Device\Harddisk6\DR6 - ok 19:56:14.0308 1384 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk7\DR7 19:56:14.0314 1384 \Device\Harddisk7\DR7 - ok 19:56:14.0314 1384 ================ Scan VBR ================================== 19:56:14.0317 1384 [ F37317A04E269FC7D3212197B7B9F501 ] \Device\Harddisk0\DR0\Partition1 19:56:14.0319 1384 \Device\Harddisk0\DR0\Partition1 - ok 19:56:14.0334 1384 [ F9408424C850BD05070FD9BC762A4383 ] \Device\Harddisk0\DR0\Partition2 19:56:14.0335 1384 \Device\Harddisk0\DR0\Partition2 - ok 19:56:14.0339 1384 [ 56F460BB9DBFEA0C8D6B73C4A9C406AE ] \Device\Harddisk6\DR6\Partition1 19:56:14.0340 1384 \Device\Harddisk6\DR6\Partition1 - ok 19:56:14.0345 1384 [ C1B8EEB1DD2BD4F572BD55F2202480C5 ] \Device\Harddisk7\DR7\Partition1 19:56:14.0346 1384 \Device\Harddisk7\DR7\Partition1 - ok 19:56:14.0346 1384 ============================================================ 19:56:14.0346 1384 Scan finished 19:56:14.0346 1384 ============================================================ 19:56:14.0357 7264 Detected object count: 1 19:56:14.0357 7264 Actual detected object count: 1 19:56:28.0473 7264 sptd ( LockedFile.Multi.Generic ) - skipped by user 19:56:28.0474 7264 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
P2P - I see you have P2P software ( µTorrent ) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Programs and Features.

If you choose to leave them on the machine, please refrain from using them while we are cleaning the machine to prevent further infection.



We may have several steps to get you running at the best possible speed for your internet. In your next reply can you also tell me which of the browsers you prefer to use as your default? Internet Explorer, Firefox or Chrome? I see that you have them all on your machine, and depending on which you use the most may affect which one we focus on doing the most to "improve" some of your browser speed in cleaning up some of the potential items that, while not necessarily malware, can slow down your internet.




Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing anything, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

If you have a problem launching programs after running Combofix, please do not panic! Simply reboot the computer and all should be fine.
Hello again! With regard to my browers, I use Chrome for personal use and IE for business use. I am not a fan of IE but my company uses Microsoft products so it is a requirement. Please let me know if you need anything else. ComboFix 13-01-03.05 - Karri 03/01/2013 20:22:52.1.4 - x64 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.8125.4986 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Karri\AppData\Local\Temp\{1d478740-1c26-43ed-9b9e-2f8938b03192}\Livedrive.Native.dll c:\users\Karri\AppData\Local\The Weather Network\WeatherEye.exe c:\users\Karri\AppData\Roaming\.# c:\users\Karri\AppData\Roaming\.#\MBX@1D9C@222990.### c:\users\Karri\AppData\Roaming\.#\MBX@1D9C@2229C0.### c:\users\Karri\AppData\Roaming\.#\MBX@1D9C@2229F0.### c:\users\Karri\g2mdlhlpx.exe O:\autorun.inf . . ((((((((((((((((((((((((( Files Created from 2012-12-04 to 2013-01-04 ))))))))))))))))))))))))))))))) . . 2013-01-04 01:32 . 2013-01-04 01:32 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2013-01-04 01:32 . 2013-01-04 01:32 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-01-02 20:49 . 2013-01-02 20:50 ——– d—–w- c:\users\Karri\AppData\Roaming\ooVoo Details 2013-01-02 20:49 . 2013-01-02 20:49 ——– d—–w- c:\program files (x86)\ooVoo 2013-01-02 20:39 . 2013-01-02 20:39 388096 —-a-r- c:\users\Karri\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2013-01-02 20:39 . 2013-01-02 20:39 ——– d—–w- c:\program files (x86)\Trend Micro 2013-01-02 20:25 . 2013-01-02 20:25 ——– d—–w- c:\users\Karri\AppData\Roaming\Yahoo! 2013-01-02 20:17 . 2013-01-02 21:00 ——– d—–w- c:\program files (x86)\Yahoo! 2012-12-22 04:44 . 2012-12-16 13:31 48128 —-a-w- c:\windows\system32\atmlib.dll 2012-12-22 04:44 . 2012-12-16 13:12 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-22 04:44 . 2012-12-16 11:08 368128 —-a-w- c:\windows\system32\atmfd.dll 2012-12-22 04:44 . 2012-12-16 10:50 293376 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-19 20:46 . 2012-12-19 20:46 ——– d—–w- c:\program files\iPod 2012-12-19 20:46 . 2012-12-19 20:46 ——– d—–w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2012-12-19 20:46 . 2012-12-19 20:46 ——– d—–w- c:\program files\iTunes 2012-12-14 13:42 . 2013-01-04 01:31 ——– d—–w- c:\users\Karri\AppData\Local\The Weather Network 2012-12-14 13:17 . 2012-12-14 13:17 ——– d—–w- c:\users\Karri\AppData\Roaming\NVIDIA 2012-12-13 02:09 . 2012-11-14 05:52 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-12-12 09:19 . 2012-09-28 16:34 1210368 —-a-w- c:\windows\system32\kernel32.dll 2012-12-12 09:19 . 2012-11-13 01:55 2770432 —-a-w- c:\windows\system32\win32k.sys 2012-12-12 09:19 . 2012-08-21 11:50 267648 —-a-w- c:\windows\system32\drivers\volsnap.sys 2012-12-12 09:19 . 2012-11-13 01:45 2048 —-a-w- c:\windows\system32\tzres.dll 2012-12-12 09:19 . 2012-11-13 01:29 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2012-12-12 09:19 . 2012-11-02 10:45 477696 —-a-w- c:\windows\system32\dpnet.dll 2012-12-12 09:19 . 2012-11-02 10:45 68096 —-a-w- c:\windows\system32\dpnathlp.dll 2012-12-12 09:19 . 2012-11-02 10:18 376320 —-a-w- c:\windows\SysWow64\dpnet.dll 2012-12-12 09:19 . 2012-11-02 08:59 26112 —-a-w- c:\windows\system32\dpnsvr.exe 2012-12-12 09:19 . 2012-11-02 08:26 23040 —-a-w- c:\windows\SysWow64\dpnsvr.exe 2012-12-10 19:38 . 2012-12-11 13:02 ——– d—–w- c:\users\Karri\AppData\Local\LogMeIn Rescue Applet . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-12-19 13:28 . 2012-09-29 19:56 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-12-19 13:28 . 2012-09-29 19:56 697272 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-12-13 02:11 . 2006-11-02 12:35 67413224 —-a-w- c:\windows\system32\mrt.exe 2012-11-25 15:29 . 2010-11-30 11:28 18160 —-a-w- c:\programdata\Microsoft\MSOIdentityCRL\production\msoidconfig.dll 2012-11-14 09:52 . 2012-04-28 23:22 477168 —-a-w- c:\windows\SysWow64\npdeployJava1.dll 2012-11-14 09:52 . 2010-06-02 14:27 473072 —-a-w- c:\windows\SysWow64\deployJava1.dll 2012-11-10 15:56 . 2012-11-21 16:18 141672 —-a-w- c:\windows\system32\CbFsNetRdr3.dll 2012-11-10 15:56 . 2012-11-21 16:18 223592 —-a-w- c:\windows\SysWow64\CbFsNetRdr3.dll 2012-11-10 15:55 . 2012-11-21 16:18 190312 —-a-w- c:\windows\system32\CbFsMntNtf3.dll 2012-11-10 15:55 . 2012-11-21 16:18 158056 —-a-w- c:\windows\SysWow64\CbFsMntNtf3.dll 2012-11-10 15:50 . 2012-11-21 16:18 352008 —-a-w- c:\windows\system32\drivers\cbfs3.sys 2012-10-25 08:12 . 2012-10-25 08:12 94208 —-a-w- c:\windows\SysWow64\QuickTimeVR.qtx 2012-10-25 08:12 . 2012-10-25 08:12 69632 —-a-w- c:\windows\SysWow64\QuickTime.qts 2012-10-15 04:20 . 2012-10-15 04:20 83080 —-a-w- c:\windows\system32\CRMMS32.dll 2012-10-11 02:23 . 2012-10-11 02:23 1867112 —-a-w- c:\windows\SysWow64\nvcuvenc.dll 2012-10-11 02:23 . 2012-10-11 02:23 18252136 —-a-w- c:\windows\system32\nvd3dumx.dll 2012-10-11 02:23 . 2012-10-11 02:23 1482600 —-a-w- c:\windows\system32\nvdispgenco64.dll 2012-10-11 02:23 . 2012-10-11 02:23 6127464 —-a-w- c:\windows\SysWow64\nvopencl.dll 2012-10-11 02:23 . 2012-10-11 02:23 2574696 —-a-w- c:\windows\SysWow64\nvcuvid.dll 2012-10-11 02:23 . 2012-10-11 02:23 25256296 —-a-w- c:\windows\system32\nvcompiler.dll 2012-10-11 02:23 . 2012-10-11 02:23 7414632 —-a-w- c:\windows\system32\nvopencl.dll 2012-10-11 02:23 . 2012-10-11 02:23 2731880 —-a-w- c:\windows\system32\nvapi64.dll 2012-10-11 02:23 . 2012-10-11 02:23 14922600 —-a-w- c:\windows\system32\nvwgf2umx.dll 2012-10-11 02:23 . 2012-10-11 02:23 9146728 —-a-w- c:\windows\system32\nvcuda.dll 2012-10-11 02:23 . 2012-10-11 02:23 7697768 —-a-w- c:\windows\SysWow64\nvcuda.dll 2012-10-11 02:23 . 2012-10-11 02:23 2218344 —-a-w- c:\windows\system32\nvcuvenc.dll 2012-10-11 02:23 . 2012-10-11 02:23 12501352 —-a-w- c:\windows\SysWow64\nvwgf2um.dll 2012-10-11 02:22 . 2012-10-11 02:22 2428776 —-a-w- c:\windows\SysWow64\nvapi.dll 2012-10-11 02:22 . 2012-10-11 02:22 26331496 —-a-w- c:\windows\system32\nvoglv64.dll 2012-10-11 02:22 . 2012-10-11 02:22 1760104 —-a-w- c:\windows\system32\nvdispco64.dll 2012-10-11 02:22 . 2012-10-11 02:22 15309160 —-a-w- c:\windows\SysWow64\nvd3dum.dll 2012-10-11 02:22 . 2012-10-11 02:22 2747240 —-a-w- c:\windows\system32\nvcuvid.dll 2012-10-11 02:22 . 2012-10-11 02:22 19906920 —-a-w- c:\windows\SysWow64\nvoglv32.dll 2012-10-11 02:22 . 2012-10-11 02:22 13443944 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys 2012-10-11 02:22 . 2012-10-11 02:22 17559912 —-a-w- c:\windows\SysWow64\nvcompiler.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{7b13ec3e-999a-4b70-b9cb-2617b8323822}"= "c:\program files (x86)\Zynga\tbZyn0.dll" [2010-02-22 2353176] . [HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}] . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{7b13ec3e-999a-4b70-b9cb-2617b8323822}] 2010-02-22 16:05 2353176 —-a-w- c:\program files (x86)\Zynga\tbZyn0.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{7b13ec3e-999a-4b70-b9cb-2617b8323822}"= "c:\program files (x86)\Zynga\tbZyn0.dll" [2010-02-22 2353176] . [HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-07-29 21:52 121392 —-a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EldosIconOverlay] @="{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}" [HKEY_CLASSES_ROOT\CLSID\{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}] 2012-11-10 15:55 158056 —-a-w- c:\windows\SysWOW64\CbFsMntNtf3.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656] "Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-12-04 1354736] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2012-07-13 17418928] "EADM"="c:\program files (x86)\Origin\Origin.exe" [2011-09-29 27763848] "Logitech Vid"="c:\program files (x86)\Logitech\Vid HD\Vid.exe" [2010-10-29 5915480] "SansaDispatch"="c:\users\Karri\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe" [2012-07-17 79872] "Livedrive"="c:\program files (x86)\Livedrive\Livedrive.exe" [2012-11-14 1831936] "GoToMeeting"="c:\program files (x86)\Citrix\GoToMeeting\1060\g2mstart.exe" [2012-11-28 40376] "ooVoo.exe"="c:\program files (x86)\ooVoo\oovoo.exe" [2012-10-04 27112568] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "CLPushUpdate"="c:\program files (x86)\CyberLink\CyberLink Live\CLPushUpdate.exe" [2008-09-11 68640] "PCMMediaSharing"="c:\program files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2008-05-20 204908] "BkupTray"="c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-26 28672] "Acer Product Registration"="c:\program files (x86)\Acer\Acer Registration\ACE1.exe" [2007-11-26 3387392] "Acer Assist Launcher"="c:\program files (x86)\Acer\Acer Assist\launcher.exe" [2007-11-19 1261568] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152] "ACQTMOUSE"="c:\program files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe" [2008-08-01 501760] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "LWS"="c:\program files (x86)\Logitech\LWS\Webcam Software\LWS.exe" [2011-08-12 205336] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2012-08-08 348664] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "Communicator"="c:\program files (x86)\Microsoft Lync\communicator.exe" [2012-09-29 12105344] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-12-12 152544] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360] WinZip Quick Pick.lnk - c:\program files (x86)\WinZip\WZQKPICK.EXE [2011-2-9 610120] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-05-20 269448] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs Themes . Contents of the 'Scheduled Tasks' folder . 2013-01-04 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-29 13:28] . 2013-01-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3989614313-289073978-4266361891-1000Core.job - c:\users\Karri\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-14 19:00] . 2013-01-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3989614313-289073978-4266361891-1000UA.job - c:\users\Karri\AppData\Local\Google\Update\GoogleUpdate.exe [2010-02-14 19:00] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupOverlay] @="{B44A5D93-1351-41A1-BD91-5E92435D8ECD}" [HKEY_CLASSES_ROOT\CLSID\{B44A5D93-1351-41A1-BD91-5E92435D8ECD}] 2012-11-14 18:48 1245920 —-a-w- c:\program files (x86)\Livedrive\LivedriveExtensions.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-07-29 21:53 50736 —-a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\PSDProtect.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EldosIconOverlay] @="{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}" [HKEY_CLASSES_ROOT\CLSID\{5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC}] 2012-11-10 15:55 190312 —-a-w- c:\windows\System32\CbFsMntNtf3.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\LivedriveDownloadOverlay] @="{CBCDB610-6B68-4EE9-B7A2-1282FD0C9292}" [HKEY_CLASSES_ROOT\CLSID\{CBCDB610-6B68-4EE9-B7A2-1282FD0C9292}] 2012-11-14 18:48 1245920 —-a-w- c:\program files (x86)\Livedrive\LivedriveExtensions.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\LivedriveSharedOverlay] @="{84CEF1E4-1356-4063-845F-05047F4DD52C}" [HKEY_CLASSES_ROOT\CLSID\{84CEF1E4-1356-4063-845F-05047F4DD52C}] 2012-11-14 18:48 1245920 —-a-w- c:\program files (x86)\Livedrive\LivedriveExtensions.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\LivedriveSyncedOverlay] @="{42058329-2FBF-4B33-8E52-3BE5754DE0C1}" [HKEY_CLASSES_ROOT\CLSID\{42058329-2FBF-4B33-8E52-3BE5754DE0C1}] 2012-11-14 18:48 1245920 —-a-w- c:\program files (x86)\Livedrive\LivedriveExtensions.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\LivedriveUploadOverlay] @="{39A1715A-E4CD-4F1E-B5C4-36B5DB80124E}" [HKEY_CLASSES_ROOT\CLSID\{39A1715A-E4CD-4F1E-B5C4-36B5DB80124E}] 2012-11-14 18:48 1245920 —-a-w- c:\program files (x86)\Livedrive\LivedriveExtensions.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IntelSWUpdateClient"="c:\program files\intel\inteldh\common\SWUpdateClient.exe" [2008-07-16 179600] "RtHDVCpl"="RAVCpl64.exe" [2008-08-04 6455840] "Skytel"="Skytel.exe" [2008-08-04 1833504] "Acer Empowering Technology Monitor"="c:\program files\Acer\Empowering Technology\SysMonitor.exe" [2008-06-02 319488] "EmpoweringTechnology"="c:\program files\Acer\Empowering Technology\Framework.Launcher.exe" [2008-06-02 319488] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808] "eDataSecurity Loader"="c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe" [2008-07-29 561200] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-08-25 153624] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-08-25 225816] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-08-25 199704] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-11 171520] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512] . ——- Supplementary Scan ——- . uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=1009&s=1&o=vp64&d=0309&m=aspire_m5700 uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=1009&s=1&o=vp64&d=0309&m=aspire_m5700 mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=1009&s=1&o=vp64&d=0309&m=aspire_m5700 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 Trusted Zone: aboriginallink.ca Trusted Zone: aboriginallink.com Trusted Zone: dynamics.com Trusted Zone: live.com Trusted Zone: microsoftonline.com\portal Trusted Zone: outlook.com TCP: DhcpNameServer = 192.168.0.1 Handler: intu-tt2011 - {B3B5DAD9-E96D-45b4-B636-B6CF2F773DE1} - c:\program files (x86)\TurboTax 2011\ic2011pp.dll DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} - hxxp://www.shockwave.com/content/trijinx/sis/TriJinx.1.0.0.86.cab FF - ProfilePath - c:\users\Karri\AppData\Roaming\Mozilla\Firefox\Profiles\3rkyge3u.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.theweathernetwork.com/weather/caon0532 FF - ExtSQL: 2012-12-28 23:43; {CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA}; c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA} FF - ExtSQL: !HIDDEN! 2009-07-11 00:01; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) Wow6432Node-HKCU-Run-EA Core - c:\program files (x86)\Electronic Arts\EADM\Core.exe Wow6432Node-HKCU-Run-WMPNSCFG - c:\program files (x86)\Windows Media Player\WMPNSCFG.exe Wow6432Node-HKCU-Run-WeatherEye - c:\users\Karri\AppData\Local\The Weather Network\WeatherEye.exe Wow6432Node-HKLM-Run-DivXMediaServer - c:\program files (x86)\DivX\DivX Media Server\DivXMediaServer.exe SafeBoot-WudfPf SafeBoot-WudfRd WebBrowser-{7B13EC3E-999A-4B70-B9CB-2617B8323822} - (no file) AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files (x86)\DivX\DivXCodecUninstall.exe AddRemove-The Weather Network - c:\users\Karri\AppData\Local\The Weather Network\WeatherEye.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.032" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.abr" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.ani" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.apd\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.apd" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.arw" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.bay" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice] @Denied: (2) (S-1-5-21-3989614313-289073978-4266361891-1000) @Denied: (2) (LocalSystem) "Progid"="PhotoViewer.FileAssoc.Bitmap" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.bw" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bwf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.bwf" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.caf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.caf" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cdda\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.cdda" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cel\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.cel" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.cr2" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.crw" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.cs1" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.cur" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.dcr" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.dcx" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.dib" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.djv" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.djvu" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.dng" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.emf" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.eps" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.erf" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.fff" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flc\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.flc" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fli\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.fli" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.fpx" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice] @Denied: (2) (S-1-5-21-3989614313-289073978-4266361891-1000) @Denied: (2) (LocalSystem) "Progid"="PhotoViewer.FileAssoc.Gif" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gsm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.gsm" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.hdr" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.icl" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.icn" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.iff" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ilbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.ilbm" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.int\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.int" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inta\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.inta" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.iw4" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.j2c" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.j2k" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.jbr" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.jfif" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.jif" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.jp2" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.jpc" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice] @Denied: (2) (S-1-5-21-3989614313-289073978-4266361891-1000) @Denied: (2) (LocalSystem) "Progid"="PhotoViewer.FileAssoc.Jpeg" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice] @Denied: (2) (S-1-5-21-3989614313-289073978-4266361891-1000) @Denied: (2) (LocalSystem) "Progid"="PhotoViewer.FileAssoc.Jpeg" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice] @Denied: (2) (S-1-5-21-3989614313-289073978-4266361891-1000) @Denied: (2) (LocalSystem) "Progid"="PhotoViewer.FileAssoc.Jpeg" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.jpk" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.jpx" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kar\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.kar" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.kdc" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.lbm" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m15\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.m15" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1a\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.m1a" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2a\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.m2a" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4b\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.m4b" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m75\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.m75" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.mef" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.mos" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.mpv" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.mrw" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.nef" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nrw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.nrw" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.orf" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pbm" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pbr" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pcd" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pct" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pcx" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pef" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pgm" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pic" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pics\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pics" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pict" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pix\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pix" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice] @Denied: (2) (S-1-5-21-3989614313-289073978-4266361891-1000) @Denied: (2) (LocalSystem) "Progid"="PhotoViewer.FileAssoc.Png" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.ppm" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.psd" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.psp" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pspbrush" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.pspimage" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qcp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.qcp" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qtpf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.qtpf" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.raf" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.ras" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.raw" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgb\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.rgb" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgba\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.rgba" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.rle" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsb\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.rsb" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rw2\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.rw2" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rwl\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.rwl" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sdv\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.sdv" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sfil\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.sfil" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.sgi" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.smf" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smi\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.smi" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smil\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.smil" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.sml" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.sr2" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.srf" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.srw" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.swa\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.swa" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.tga" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.thm" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice] @Denied: (2) (S-1-5-21-3989614313-289073978-4266361891-1000) @Denied: (2) (LocalSystem) "Progid"="PhotoViewer.FileAssoc.Tiff" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice] @Denied: (2) (S-1-5-21-3989614313-289073978-4266361891-1000) @Denied: (2) (LocalSystem) "Progid"="PhotoViewer.FileAssoc.Tiff" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.ttc" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.ttf" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ulw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.ulw" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v14o\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.v14o" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v14p\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.v14p" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v14pf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.v14pf" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vfw\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.vfw" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.wbm" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.wbmp" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.wmf" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.xbm" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.xif" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.xmp" . [HKEY_USERS\S-1-5-21-3989614313-289073978-4266361891-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice] @Denied: (2) (LocalSystem) "Progid"="ACDSee 14.xpm" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] @Denied: (A 2) (Everyone) . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] @="Shockwave Flash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] @Denied: (A 2) (Everyone) @="" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] @="FlashBroker" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes] "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . ———————— Other Running Processes ———————— . c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe c:\program files (x86)\Avira\AntiVir Desktop\sched.exe c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe c:\program files (x86)\CyberLink\CyberLink Live\CLSomaMonitorService.exe c:\program files (x86)\CyberLink\CyberLink Live\CLPushUpdateService.exe c:\program files (x86)\CyberLink\CyberLink Live\CLSomaService.exe c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe c:\program files\Intel\AMT\LMS.exe c:\program files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe c:\program files (x86)\CyberLink\Shared Files\RichVideo.exe c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe c:\program files (x86)\TeamViewer\Version8\TeamViewer.exe c:\program files (x86)\TeamViewer\Version8\tv_w32.exe c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe c:\program files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe c:\program files (x86)\Citrix\GoToMeeting\1060\g2mcomm.exe c:\program files (x86)\HP\Digital Imaging\bin\hpqbam08.exe c:\program files (x86)\Citrix\GoToMeeting\1060\g2mlauncher.exe c:\program files (x86)\Internet Explorer\IELowutil.exe c:\program files (x86)\Common Files\Steam\SteamService.exe c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe . ************************************************************************** . Completion time: 2013-01-03 20:43:21 - machine was rebooted ComboFix-quarantined-files.txt 2013-01-04 01:43 . Pre-Run: 88,649,867,264 bytes free Post-Run: 94,726,258,688 bytes free . - - End Of File - - 22CEB16C18E801E95AEA242BBF03218C
You had a rootkit on this machine that has modified some of your system files. In order to assure that it has been fully removed, we may need to run the same tool a number of separate times after running other tools, so your patience will be required :)

I am at work right now, so my responses may be a little slower, but I will attempt to continue to work with you throughout the day so we can keep moving if you are able to do so. If you are not able to do so, that is quite fine, you can simply post back when you are able and I will respond as quickly as I can.

Let's run TDSSKiller w/skip again to see how things stand now:




Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.


Also,
I see you have Malwarebytes already on your machine. Please run it by right-clicking and choosing Run as Administrator on the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Please be sure to give me an update on how the machine is running in your next reply as well.
Hi, Don't worry! I have a lot of patience. :D My computer seems to be running fine, although this is not the one that I have the most trouble with but it is the most important one as I work from home and use this computer. 11:28:46.0790 10812 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35 11:28:48.0405 10812 ============================================================ 11:28:48.0405 10812 Current date / time: 2013/01/04 11:28:48.0405 11:28:48.0405 10812 SystemInfo: 11:28:48.0405 10812 11:28:48.0405 10812 OS Version: 6.0.6002 ServicePack: 2.0 11:28:48.0405 10812 Product type: Workstation 11:28:48.0406 10812 ComputerName: KARRI-PC 11:28:48.0406 10812 UserName: Karri 11:28:48.0406 10812 Windows directory: C:\Windows 11:28:48.0406 10812 System windows directory: C:\Windows 11:28:48.0406 10812 Running under WOW64 11:28:48.0406 10812 Processor architecture: Intel x64 11:28:48.0406 10812 Number of processors: 4 11:28:48.0406 10812 Page size: 0x1000 11:28:48.0406 10812 Boot type: Normal boot 11:28:48.0406 10812 ============================================================ 11:28:48.0979 10812 Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 11:28:49.0008 10812 Drive \Device\Harddisk6\DR6 - Size: 0xE8C4BA0000 (931.07 Gb), SectorSize: 0x200, Cylinders: 0x1DAC7, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 11:28:49.0011 10812 Drive \Device\Harddisk7\DR7 - Size: 0xF2C00000 (3.79 Gb), SectorSize: 0x200, Cylinders: 0x1EF, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 11:28:49.0016 10812 ============================================================ 11:28:49.0016 10812 \Device\Harddisk0\DR0: 11:28:49.0016 10812 MBR partitions: 11:28:49.0016 10812 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1D4F800, BlocksNum 0x1D12D000 11:28:49.0016 10812 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1EE7C800, BlocksNum 0x2B9DB000 11:28:49.0016 10812 \Device\Harddisk6\DR6: 11:28:49.0018 10812 MBR partitions: 11:28:49.0018 10812 \Device\Harddisk6\DR6\Partition1: MBR, Type 0xC, StartLBA 0x3F, BlocksNum 0x746221C8 11:28:49.0018 10812 \Device\Harddisk7\DR7: 11:28:49.0020 10812 MBR partitions: 11:28:49.0020 10812 \Device\Harddisk7\DR7\Partition1: MBR, Type 0xB, StartLBA 0x2000, BlocksNum 0x794000 11:28:49.0020 10812 ============================================================ 11:28:49.0062 10812 C: <-> \Device\Harddisk0\DR0\Partition1 11:28:49.0182 10812 D: <-> \Device\Harddisk0\DR0\Partition2 11:28:49.0185 10812 O: <-> \Device\Harddisk6\DR6\Partition1 11:28:49.0185 10812 ============================================================ 11:28:49.0185 10812 Initialize success 11:28:49.0185 10812 ============================================================ 11:28:50.0264 11060 ============================================================ 11:28:50.0265 11060 Scan started 11:28:50.0265 11060 Mode: Manual; 11:28:50.0265 11060 ============================================================ 11:28:56.0984 11060 ================ Scan system memory ======================== 11:28:56.0984 11060 System memory - ok 11:28:56.0984 11060 ================ Scan services ============================= 11:28:57.0115 11060 [ 517D30057C726C797764BFD70A55D82A ] Acer HomeMedia Connect Service C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe 11:28:57.0126 11060 Acer HomeMedia Connect Service - ok 11:28:57.0254 11060 [ 1965AAFFAB07E3FB03C77F81BEBA3547 ] ACPI C:\Windows\system32\drivers\acpi.sys 11:28:57.0256 11060 ACPI - ok 11:28:57.0324 11060 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 11:28:57.0331 11060 AdobeARMservice - ok 11:28:57.0484 11060 [ 95CE557D16A75606CCC2D7F3B0B0BCCB ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 11:28:57.0510 11060 AdobeFlashPlayerUpdateSvc - ok 11:28:57.0651 11060 [ F14215E37CF124104575073F782111D2 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 11:28:57.0695 11060 adp94xx - ok 11:28:57.0740 11060 [ 7D05A75E3066861A6610F7EE04FF085C ] adpahci C:\Windows\system32\drivers\adpahci.sys 11:28:57.0766 11060 adpahci - ok 11:28:57.0798 11060 [ 820A201FE08A0C345B3BEDBC30E1A77C ] adpu160m C:\Windows\system32\drivers\adpu160m.sys 11:28:57.0807 11060 adpu160m - ok 11:28:57.0847 11060 [ 9B4AB6854559DC168FBB4C24FC52E794 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 11:28:57.0855 11060 adpu320 - ok 11:28:57.0914 11060 [ 0F421175574BFE0BF2F4D8E910A253BB ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 11:28:57.0920 11060 AeLookupSvc - ok 11:28:58.0033 11060 [ C4F6CE6087760AD70960C9EB130E7943 ] AFD C:\Windows\system32\drivers\afd.sys 11:28:58.0079 11060 AFD - ok 11:28:58.0113 11060 [ F6F6793B7F17B550ECFDBD3B229173F7 ] agp440 C:\Windows\system32\drivers\agp440.sys 11:28:58.0120 11060 agp440 - ok 11:28:58.0238 11060 [ 222CB641B4B8A1D1126F8033F9FD6A00 ] aic78xx C:\Windows\system32\drivers\djsvs.sys 11:28:58.0275 11060 aic78xx - ok 11:28:58.0297 11060 [ 5922F4F59B7868F3D74BBBBEB7B825A3 ] ALG C:\Windows\System32\alg.exe 11:28:58.0324 11060 ALG - ok 11:28:58.0363 11060 [ 157D0898D4B73F075CE9FA26B482DF98 ] aliide C:\Windows\system32\drivers\aliide.sys 11:28:58.0369 11060 aliide - ok 11:28:58.0391 11060 [ 970FA5059E61E30D25307B99903E991E ] amdide C:\Windows\system32\drivers\amdide.sys 11:28:58.0433 11060 amdide - ok 11:28:58.0457 11060 [ CDC3632A3A5EA4DBB83E46076A3165A1 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 11:28:58.0506 11060 AmdK8 - ok 11:28:58.0590 11060 [ 0A1CC583E8147004E4AD4625D7FBF88C ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 11:28:58.0599 11060 AntiVirSchedulerService - ok 11:28:58.0657 11060 [ C9A36EF935ACED86AEDF93E97E606911 ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 11:28:58.0682 11060 AntiVirService - ok 11:28:58.0727 11060 [ 9C37B3FD5615477CB9A0CD116CF43F5C ] Appinfo C:\Windows\System32\appinfo.dll 11:28:58.0727 11060 Appinfo - ok 11:28:58.0821 11060 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 11:28:58.0868 11060 Apple Mobile Device - ok 11:28:58.0894 11060 [ BA8417D4765F3988FF921F30F630E303 ] arc C:\Windows\system32\drivers\arc.sys 11:28:58.0917 11060 arc - ok 11:28:58.0955 11060 [ 9D41C435619733B34CC16A511E644B11 ] arcsas C:\Windows\system32\drivers\arcsas.sys 11:28:58.0963 11060 arcsas - ok 11:28:59.0067 11060 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 11:28:59.0159 11060 aspnet_state - ok 11:28:59.0191 11060 [ 22D13FF3DAFEC2A80634752B1EAA2DE6 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 11:28:59.0225 11060 AsyncMac - ok 11:28:59.0247 11060 [ 1898FAE8E07D97F2F6C2D5326C633FAC ] atapi C:\Windows\system32\drivers\atapi.sys 11:28:59.0253 11060 atapi - ok 11:28:59.0303 11060 [ 79318C744693EC983D20E9337A2F8196 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 11:28:59.0343 11060 AudioEndpointBuilder - ok 11:28:59.0360 11060 [ 79318C744693EC983D20E9337A2F8196 ] AudioSrv C:\Windows\System32\Audiosrv.dll 11:28:59.0363 11060 AudioSrv - ok 11:28:59.0406 11060 [ 26E38B5A58C6C55FAFBC563EEDDB0867 ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys 11:28:59.0413 11060 avgntflt - ok 11:28:59.0475 11060 [ 9D1F00BEFF84CBBF46D7F052BC7E0565 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys 11:28:59.0483 11060 avipbb - ok 11:28:59.0538 11060 [ 248DB59FC86DE44D2779F4C7FB1A567D ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys 11:28:59.0543 11060 avkmgr - ok 11:28:59.0623 11060 Beep - ok 11:28:59.0683 11060 [ FFB96C2589FFA60473EAD78B39FBDE29 ] BFE C:\Windows\System32\bfe.dll 11:28:59.0699 11060 BFE - ok 11:28:59.0741 11060 [ 6D316F4859634071CC25C4FD4589AD2C ] BITS C:\Windows\system32\qmgr.dll 11:28:59.0767 11060 BITS - ok 11:28:59.0791 11060 [ 79FEEB40056683F8F61398D81DDA65D2 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys 11:28:59.0800 11060 blbdrive - ok 11:28:59.0883 11060 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 11:28:59.0894 11060 Bonjour Service - ok 11:28:59.0944 11060 [ 2348447A80920B2493A9B582A23E81E1 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 11:28:59.0951 11060 bowser - ok 11:28:59.0974 11060 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys 11:28:59.0978 11060 BrFiltLo - ok 11:29:00.0007 11060 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys 11:29:00.0011 11060 BrFiltUp - ok 11:29:00.0045 11060 [ A1B39DE453433B115B4EA69EE0343816 ] Browser C:\Windows\System32\browser.dll 11:29:00.0053 11060 Browser - ok 11:29:00.0078 11060 [ F0F0BA4D815BE446AA6A4583CA3BCA9B ] Brserid C:\Windows\system32\drivers\brserid.sys 11:29:00.0085 11060 Brserid - ok 11:29:00.0116 11060 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys 11:29:00.0123 11060 BrSerWdm - ok 11:29:00.0145 11060 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys 11:29:00.0148 11060 BrUsbMdm - ok 11:29:00.0177 11060 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys 11:29:00.0181 11060 BrUsbSer - ok 11:29:00.0193 11060 [ E0777B34E05F8A82A21856EFC900C29F ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys 11:29:00.0199 11060 BTHMODEM - ok 11:29:00.0228 11060 [ 09E6AFFAE6C0E9158BF05C7D08D0107A ] BUNAgentSvc C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe 11:29:00.0233 11060 BUNAgentSvc - ok 11:29:00.0266 11060 c2wts - ok 11:29:00.0270 11060 catchme - ok 11:29:00.0325 11060 [ 3D50891CAA71E3479A8A10F25CA9207F ] cbfs3 C:\Windows\system32\drivers\cbfs3.sys 11:29:00.0327 11060 cbfs3 - ok 11:29:00.0334 11060 [ B4D787DB8D30793A4D4DF9FEED18F136 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 11:29:00.0339 11060 cdfs - ok 11:29:00.0364 11060 [ C025AA69BE3D0D25C7A2E746EF6F94FC ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 11:29:00.0370 11060 cdrom - ok 11:29:00.0445 11060 [ 5A268127633C7EE2A7FB87F39D748D56 ] CertPropSvc C:\Windows\System32\certprop.dll 11:29:00.0450 11060 CertPropSvc - ok 11:29:00.0487 11060 [ 02EA568D498BBDD4BA55BF3FCE34D456 ] circlass C:\Windows\system32\drivers\circlass.sys 11:29:00.0493 11060 circlass - ok 11:29:00.0529 11060 [ 3DCA9A18B204939CFB24BEA53E31EB48 ] CLFS C:\Windows\system32\CLFS.sys 11:29:00.0542 11060 CLFS - ok 11:29:00.0588 11060 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 11:29:00.0596 11060 clr_optimization_v2.0.50727_32 - ok 11:29:00.0661 11060 [ CE07A466201096F021CD09D631B21540 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 11:29:00.0696 11060 clr_optimization_v2.0.50727_64 - ok 11:29:00.0774 11060 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 11:29:00.0867 11060 clr_optimization_v4.0.30319_32 - ok 11:29:00.0887 11060 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 11:29:00.0916 11060 clr_optimization_v4.0.30319_64 - ok 11:29:00.0951 11060 [ E5D5499A1C50A54B5161296B6AFE6192 ] cmdide C:\Windows\system32\drivers\cmdide.sys 11:29:00.0957 11060 cmdide - ok 11:29:00.0991 11060 [ 7FB8AD01DB0EABE60C8A861531A8F431 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 11:29:00.0996 11060 Compbatt - ok 11:29:01.0001 11060 COMSysApp - ok 11:29:01.0010 11060 [ A8585B6412253803CE8EFCBD6D6DC15C ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 11:29:01.0016 11060 crcdisk - ok 11:29:01.0152 11060 [ 0CB856463577085CF64ACA536BA1E881 ] CrmSqlStartupSvc C:\Program Files\Microsoft Dynamics CRM\Client\bin\CrmSqlStartupSvc.exe 11:29:01.0157 11060 CrmSqlStartupSvc - ok 11:29:01.0227 11060 [ CA78B312C44E4D52E842C2C8BD48E452 ] CryptSvc C:\Windows\system32\cryptsvc.dll 11:29:01.0228 11060 CryptSvc - ok 11:29:01.0265 11060 [ 6CB6E82300947870A873A7288B96E9BF ] CyberLink Live Monitor Service C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaMonitorService.exe 11:29:01.0275 11060 CyberLink Live Monitor Service - ok 11:29:01.0356 11060 [ 0FDAAE1EA129D0F3948564F96C010BA3 ] CyberLink Live Push Update Service C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdateService.exe 11:29:01.0363 11060 CyberLink Live Push Update Service - ok 11:29:01.0401 11060 [ 24F71344D945C85B15C0717196238BD2 ] CyberLink Live Service C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaService.exe 11:29:01.0413 11060 CyberLink Live Service - ok 11:29:01.0460 11060 [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] DcomLaunch C:\Windows\system32\rpcss.dll 11:29:01.0477 11060 DcomLaunch - ok 11:29:01.0507 11060 [ 8B722BA35205C71E7951CDC4CDBADE19 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 11:29:01.0514 11060 DfsC - ok 11:29:01.0633 11060 [ C647F468F7DE343DF8C143655C5557D4 ] DFSR C:\Windows\system32\DFSR.exe 11:29:01.0698 11060 DFSR - ok 11:29:01.0747 11060 [ 3ED0321127CE70ACDAABBF77E157C2A7 ] Dhcp C:\Windows\System32\dhcpcsvc.dll 11:29:01.0812 11060 Dhcp - ok 11:29:01.0870 11060 [ B0107E40ECDB5FA692EBF832F295D905 ] disk C:\Windows\system32\drivers\disk.sys 11:29:01.0878 11060 disk - ok 11:29:01.0922 11060 [ 06230F1B721494A6DF8D47FD395BB1B0 ] Dnscache C:\Windows\System32\dnsrslvr.dll 11:29:01.0923 11060 Dnscache - ok 11:29:01.0955 11060 [ 1A7156DD1E850E9914E5E991E3225B94 ] dot3svc C:\Windows\System32\dot3svc.dll 11:29:01.0964 11060 dot3svc - ok 11:29:02.0009 11060 [ 74C02B1717740C3B8039539E23E4B53F ] Dot4 C:\Windows\system32\DRIVERS\Dot4.sys 11:29:02.0018 11060 Dot4 - ok 11:29:02.0051 11060 [ 08321D1860235BF42CF2854234337AEA ] Dot4Print C:\Windows\system32\DRIVERS\Dot4Prt.sys 11:29:02.0054 11060 Dot4Print - ok 11:29:02.0072 11060 [ 4ADCCF0124F2B6911D3786A5D0E779E5 ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys 11:29:02.0078 11060 dot4usb - ok 11:29:02.0107 11060 [ 1583B39790DB3EAEC7EDB0CB0140C708 ] DPS C:\Windows\system32\dps.dll 11:29:02.0109 11060 DPS - ok 11:29:02.0156 11060 [ F1A78A98CFC2EE02144C6BEC945447E6 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 11:29:02.0161 11060 drmkaud - ok 11:29:02.0219 11060 [ B8E554E502D5123BC111F99D6A2181B4 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 11:29:02.0225 11060 DXGKrnl - ok 11:29:02.0249 11060 [ 264CEE7B031A9D6C827F3D0CB031F2FE ] E1G60 C:\Windows\system32\DRIVERS\E1G6032E.sys 11:29:02.0257 11060 E1G60 - ok 11:29:02.0293 11060 [ B64CFEB83AB75AA74D0E193C423A991D ] e1yexpress C:\Windows\system32\DRIVERS\e1y60x64.sys 11:29:02.0302 11060 e1yexpress - ok 11:29:02.0346 11060 [ C2303883FD9BE49DC36A6400643002EA ] EapHost C:\Windows\System32\eapsvc.dll 11:29:02.0351 11060 EapHost - ok 11:29:02.0370 11060 [ 5F94962BE5A62DB6E447FF6470C4F48A ] Ecache C:\Windows\system32\drivers\ecache.sys 11:29:02.0381 11060 Ecache - ok 11:29:02.0477 11060 [ B1F2503E23425B386DF0F3413B2596F3 ] eDataSecurity Service C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe 11:29:02.0488 11060 eDataSecurity Service - ok 11:29:02.0583 11060 [ 14CE384D2E27B64C256BDA4DC39C312D ] ehRecvr C:\Windows\ehome\ehRecvr.exe 11:29:02.0607 11060 ehRecvr - ok 11:29:02.0622 11060 [ B93159C1313D66FDFBBE876F5189CD52 ] ehSched C:\Windows\ehome\ehsched.exe 11:29:02.0631 11060 ehSched - ok 11:29:02.0648 11060 [ F5EE2527D74449868E3C3227A59BCD28 ] ehstart C:\Windows\ehome\ehstart.dll 11:29:02.0648 11060 ehstart - ok 11:29:02.0672 11060 [ C4636D6E10469404AB5308D9FD45ED07 ] elxstor C:\Windows\system32\drivers\elxstor.sys 11:29:02.0689 11060 elxstor - ok 11:29:02.0750 11060 [ A9B18B63A4FD6BAAB83326706D857FAB ] EMDMgmt C:\Windows\system32\emdmgmt.dll 11:29:02.0763 11060 EMDMgmt - ok 11:29:02.0805 11060 [ BC3A58E938BB277E46BF4B3003B01ABD ] ErrDev C:\Windows\system32\drivers\errdev.sys 11:29:02.0809 11060 ErrDev - ok 11:29:02.0850 11060 [ 27D2754314D12EB27D81D462FD0D86C0 ] ETService C:\Program Files\Acer\Empowering Technology\Service\ETService.exe 11:29:02.0855 11060 ETService - ok 11:29:02.0893 11060 [ E12F22B73F153DECE721CD45EC05B4AF ] EventSystem C:\Windows\system32\es.dll 11:29:02.0896 11060 EventSystem - ok 11:29:02.0928 11060 [ 486844F47B6636044A42454614ED4523 ] exfat C:\Windows\system32\drivers\exfat.sys 11:29:02.0936 11060 exfat - ok 11:29:02.0976 11060 [ 1A4BEE34277784619DDAF0422C0C6E23 ] fastfat C:\Windows\system32\drivers\fastfat.sys 11:29:03.0001 11060 fastfat - ok 11:29:03.0037 11060 [ 81B79B6DF71FA1D2C6D688D830616E39 ] fdc C:\Windows\system32\DRIVERS\fdc.sys 11:29:03.0041 11060 fdc - ok 11:29:03.0056 11060 [ BB9267ACACD8B7533DD936C34A0CBA5E ] fdPHost C:\Windows\system32\fdPHost.dll 11:29:03.0056 11060 fdPHost - ok 11:29:03.0074 11060 [ 300C80931EABBE1DB7591C516EFE8D0F ] FDResPub C:\Windows\system32\fdrespub.dll 11:29:03.0080 11060 FDResPub - ok 11:29:03.0092 11060 [ 457B7D1D533E4BD62A99AED9C7BB4C59 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 11:29:03.0099 11060 FileInfo - ok 11:29:03.0118 11060 [ D421327FD6EFCCAF884A54C58E1B0D7F ] Filetrace C:\Windows\system32\drivers\filetrace.sys 11:29:03.0123 11060 Filetrace - ok 11:29:03.0138 11060 [ 230923EA2B80F79B0F88D90F87B87EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 11:29:03.0142 11060 flpydisk - ok 11:29:03.0172 11060 [ E3041BC26D6930D61F42AEDB79C91720 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 11:29:03.0202 11060 FltMgr - ok 11:29:03.0262 11060 [ BE1C5BD1CA7ED015BC6FA1AE67E592C8 ] FontCache C:\Windows\system32\FntCache.dll 11:29:03.0285 11060 FontCache - ok 11:29:03.0324 11060 [ BC5B0BE5AF3510B0FD8C140EE42C6D3E ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 11:29:03.0331 11060 FontCache3.0.0.0 - ok 11:29:03.0379 11060 [ 5779B86CD8B32519FBECB136394D946A ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 11:29:03.0382 11060 Fs_Rec - ok 11:29:03.0401 11060 [ C8E416668D3DC2BE3D4FE4C79224997F ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 11:29:03.0409 11060 gagp30kx - ok 11:29:03.0457 11060 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 11:29:03.0460 11060 GEARAspiWDM - ok 11:29:03.0496 11060 [ A0E1B575BA8F504968CD40C0FAEB2384 ] gpsvc C:\Windows\System32\gpsvc.dll 11:29:03.0529 11060 gpsvc - ok 11:29:03.0582 11060 [ C1B577B2169900F4CF7190C39F085794 ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe 11:29:03.0596 11060 gusvc - ok 11:29:03.0627 11060 [ DF45F8142DC6DF9D18C39B3EFFBD0409 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 11:29:03.0676 11060 HdAudAddService - ok 11:29:03.0746 11060 [ F942C5820205F2FB453243EDFEC82A3D ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 11:29:03.0760 11060 HDAudBus - ok 11:29:03.0774 11060 [ 72D70BCF68C092978BFCD32F88BD6454 ] HECIx64 C:\Windows\system32\DRIVERS\HECIx64.sys 11:29:03.0779 11060 HECIx64 - ok 11:29:03.0798 11060 [ 68214C82FA6222591873677A72DF2A66 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 11:29:03.0803 11060 HidBatt - ok 11:29:03.0821 11060 [ B4881C84A180E75B8C25DC1D726C375F ] HidBth C:\Windows\system32\drivers\hidbth.sys 11:29:03.0826 11060 HidBth - ok 11:29:03.0881 11060 [ 4E77A77E2C986E8F88F996BB3E1AD829 ] HidIr C:\Windows\system32\drivers\hidir.sys 11:29:03.0885 11060 HidIr - ok 11:29:03.0914 11060 [ 59361D38A297755D46A540E450202B2A ] hidserv C:\Windows\System32\hidserv.dll 11:29:03.0920 11060 hidserv - ok 11:29:03.0963 11060 [ 443BDD2D30BB4F00795C797E2CF99EDF ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 11:29:03.0967 11060 HidUsb - ok 11:29:03.0985 11060 [ B12F367EA39C0795FD57E31242CE1A5A ] hkmsvc C:\Windows\system32\kmsvc.dll 11:29:03.0991 11060 hkmsvc - ok 11:29:04.0010 11060 [ D7109A1E6BD2DFDBCBA72A6BC626A13B ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys 11:29:04.0017 11060 HpCISSs - ok 11:29:04.0085 11060 [ CE0FCEC4D4D860F36D972759B11EAF0F ] hpqcxs08 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll 11:29:04.0086 11060 hpqcxs08 - ok 11:29:04.0119 11060 [ EE4C7A4CF2316701FFDE90F404520265 ] hpqddsvc C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll 11:29:04.0120 11060 hpqddsvc - ok 11:29:04.0151 11060 [ 098F1E4E5C9CB5B0063A959063631610 ] HTTP C:\Windows\system32\drivers\HTTP.sys 11:29:04.0180 11060 HTTP - ok 11:29:04.0202 11060 [ DA94C854CEA5FAC549D4E1F6E88349E8 ] i2omp C:\Windows\system32\drivers\i2omp.sys 11:29:04.0208 11060 i2omp - ok 11:29:04.0269 11060 [ CBB597659A2713CE0C9CC20C88C7591F ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys 11:29:04.0276 11060 i8042prt - ok 11:29:04.0301 11060 [ 3E42C4691AAD4B1E8D0466F9CBF05CBE ] IAANTMON C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe 11:29:04.0316 11060 IAANTMON - ok 11:29:04.0350 11060 [ FC28E90F2204D8FD147FA9BFA8A51C01 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys 11:29:04.0353 11060 iaStor - ok 11:29:04.0368 11060 [ 3E3BF3627D886736D0B4E90054F929F6 ] iaStorV C:\Windows\system32\drivers\iastorv.sys 11:29:04.0401 11060 iaStorV - ok 11:29:04.0442 11060 [ 749F5F8CEDCA70F2A512945325FC489D ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 11:29:04.0509 11060 idsvc - ok 11:29:04.0657 11060 [ CF00559906E45ECC6F035913880BE2FC ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys 11:29:04.0882 11060 igfx - ok 11:29:04.0954 11060 [ 8C3951AD2FE886EF76C7B5027C3125D3 ] iirsp C:\Windows\system32\drivers\iirsp.sys 11:29:04.0959 11060 iirsp - ok 11:29:05.0006 11060 [ 0C9EA6E654E7B0471741E343A6C671AF ] IKEEXT C:\Windows\System32\ikeext.dll 11:29:05.0024 11060 IKEEXT - ok 11:29:05.0123 11060 [ 8C7FA71CB1EBCD3EDE8958D27B1BF0B4 ] int15 C:\Windows\SysWOW64\drivers\int15_64.sys 11:29:05.0127 11060 int15 - ok 11:29:05.0182 11060 [ AECDAA95B5BBFAC856C4A22D06D3D76A ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys 11:29:05.0199 11060 IntcAzAudAddService - ok 11:29:05.0230 11060 [ DEA2AB452B4FA773187369C4B6517320 ] IntcHdmiAddService C:\Windows\system32\drivers\IntcHdmi.sys 11:29:05.0236 11060 IntcHdmiAddService - ok 11:29:05.0262 11060 [ DF797A12176F11B2D301C5B234BB200E ] intelide C:\Windows\system32\drivers\intelide.sys 11:29:05.0267 11060 intelide - ok 11:29:05.0318 11060 [ BFD84AF32FA1BAD6231C4585CB469630 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 11:29:05.0318 11060 intelppm - ok 11:29:05.0351 11060 [ 5624BC1BC5EEB49C0AB76A8114F05EA3 ] IPBusEnum C:\Windows\system32\ipbusenum.dll 11:29:05.0359 11060 IPBusEnum - ok 11:29:05.0411 11060 [ D8AABC341311E4780D6FCE8C73C0AD81 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 11:29:05.0418 11060 IpFilterDriver - ok 11:29:05.0544 11060 [ BF0DBFA9792C5C14FA00F61C75116C1B ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 11:29:05.0553 11060 iphlpsvc - ok 11:29:05.0559 11060 IpInIp - ok 11:29:05.0583 11060 [ 9C2EE2E6E5A7203BFAE15C299475EC67 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys 11:29:05.0590 11060 IPMIDRV - ok 11:29:05.0639 11060 [ B7E6212F581EA5F6AB0C3A6CEEEB89BE ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys 11:29:05.0647 11060 IPNAT - ok 11:29:05.0980 11060 [ 0F261EC4F514926177C70C1832374231 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 11:29:05.0984 11060 iPod Service - ok 11:29:06.0079 11060 [ 8C42CA155343A2F11D29FECA67FAA88D ] IRENUM C:\Windows\system32\drivers\irenum.sys 11:29:06.0083 11060 IRENUM - ok 11:29:06.0102 11060 [ 0672BFCEDC6FC468A2B0500D81437F4F ] isapnp C:\Windows\system32\drivers\isapnp.sys 11:29:06.0108 11060 isapnp - ok 11:29:06.0294 11060 [ E4FDF99599F27EC25D2CF6D754243520 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys 11:29:06.0295 11060 iScsiPrt - ok 11:29:06.0320 11060 [ 63C766CDC609FF8206CB447A65ABBA4A ] iteatapi C:\Windows\system32\drivers\iteatapi.sys 11:29:06.0326 11060 iteatapi - ok 11:29:06.0470 11060 [ 1281FE73B17664631D12F643CBEA3F59 ] iteraid C:\Windows\system32\drivers\iteraid.sys 11:29:06.0477 11060 iteraid - ok 11:29:06.0535 11060 [ 423696F3BA6472DD17699209B933BC26 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 11:29:06.0541 11060 kbdclass - ok 11:29:06.0720 11060 [ DBDF75D51464FBC47D0104EC3D572C05 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 11:29:06.0724 11060 kbdhid - ok 11:29:06.0765 11060 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] KeyIso C:\Windows\system32\lsass.exe 11:29:06.0769 11060 KeyIso - ok 11:29:06.0913 11060 [ 88956AD9FA510848AD176777A6C6C1F5 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 11:29:06.0941 11060 KSecDD - ok 11:29:07.0009 11060 [ 1D419CF43DB29396ECD7113D129D94EB ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 11:29:07.0013 11060 ksthunk - ok 11:29:07.0179 11060 [ 1FAF6926F3416D3DA05C5B265491BDAE ] KtmRm C:\Windows\system32\msdtckrm.dll 11:29:07.0211 11060 KtmRm - ok 11:29:07.0289 11060 [ 50C7A3CB427E9BB5ED0708A669956AB5 ] LanmanServer C:\Windows\System32\srvsvc.dll 11:29:07.0298 11060 LanmanServer - ok 11:29:07.0334 11060 [ CAF86FC1388BE1E470F1A7B43E348ADB ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 11:29:07.0367 11060 LanmanWorkstation - ok 11:29:07.0465 11060 [ 793FF718477345CD5D232C50BED1E452 ] LightScribeService C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe 11:29:07.0472 11060 LightScribeService - ok 11:29:07.0521 11060 [ 8049859F85CB18083AD26063BDF1766B ] LivedriveVSSService C:\Program Files (x86)\Livedrive\VSSService.exe 11:29:07.0531 11060 LivedriveVSSService - ok 11:29:07.0575 11060 [ 96ECE2659B6654C10A0C310AE3A6D02C ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 11:29:07.0583 11060 lltdio - ok 11:29:07.0614 11060 [ 961CCBD0B1CCB5675D64976FAE37D092 ] lltdsvc C:\Windows\System32\lltdsvc.dll 11:29:07.0665 11060 lltdsvc - ok 11:29:07.0699 11060 [ A47F8080CACC23C91FE823AD19AA5612 ] lmhosts C:\Windows\System32\lmhsvc.dll 11:29:07.0704 11060 lmhosts - ok 11:29:07.0747 11060 [ 650B3BE84ECA8BE345F9C423EF02605D ] LMS C:\Program Files\Intel\AMT\LMS.exe 11:29:07.0756 11060 LMS - ok 11:29:07.0774 11060 [ ACBE1AF32D3123E330A07BFBC5EC4A9B ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 11:29:07.0781 11060 LSI_FC - ok 11:29:07.0920 11060 [ 799FFB2FC4729FA46D2157C0065B3525 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 11:29:07.0931 11060 LSI_SAS - ok 11:29:07.0963 11060 [ F445FF1DAAD8A226366BFAF42551226B ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 11:29:07.0972 11060 LSI_SCSI - ok 11:29:08.0003 11060 [ 52F87B9CC8932C2A7375C3B2A9BE5E3E ] luafv C:\Windows\system32\drivers\luafv.sys 11:29:08.0012 11060 luafv - ok 11:29:08.0027 11060 lvpepf64 - ok 11:29:08.0032 11060 LVPr2M64 - ok 11:29:08.0213 11060 [ EF2BE2F45D4F06410A3BD2A3467325B0 ] LVRS64 C:\Windows\system32\DRIVERS\lvrs64.sys 11:29:08.0223 11060 LVRS64 - ok 11:29:08.0228 11060 LVUSBS64 - ok 11:29:08.0399 11060 [ AC22F92C6078640FE8A70D662A2F3AD5 ] LVUVC64 C:\Windows\system32\DRIVERS\lvuvc64.sys 11:29:08.0437 11060 LVUVC64 - ok 11:29:08.0483 11060 [ 76A58DF02BD4EA29F189B82D0BEF17F8 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 11:29:08.0491 11060 Mcx2Svc - ok 11:29:08.0630 11060 [ 7C08B11778AE7FF97E4601D6111F104A ] ME Services Manager C:\Program Files\intel\inteldh\msm\MSM.exe 11:29:08.0666 11060 ME Services Manager - ok 11:29:08.0709 11060 [ 5C5CD6AACED32FB26C3FB34B3DCF972F ] megasas C:\Windows\system32\drivers\megasas.sys 11:29:08.0714 11060 megasas - ok 11:29:08.0838 11060 [ 859BC2436B076C77C159ED694ACFE8F8 ] MegaSR C:\Windows\system32\drivers\megasr.sys 11:29:08.0871 11060 MegaSR - ok 11:29:08.0977 11060 Microsoft SharePoint Workspace Audit Service - ok 11:29:09.0046 11060 [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] MMCSS C:\Windows\system32\mmcss.dll 11:29:09.0051 11060 MMCSS - ok 11:29:09.0114 11060 [ 59848D5CC74606F0EE7557983BB73C2E ] Modem C:\Windows\system32\drivers\modem.sys 11:29:09.0143 11060 Modem - ok 11:29:09.0237 11060 [ C247CC2A57E0A0C8C6DCCF7807B3E9E5 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 11:29:09.0238 11060 monitor - ok 11:29:09.0271 11060 [ 9367304E5E412B120CF5F4EA14E4E4F1 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 11:29:09.0277 11060 mouclass - ok 11:29:09.0361 11060 [ C2C2BD5C5CE5AAF786DDD74B75D2AC69 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 11:29:09.0364 11060 mouhid - ok 11:29:09.0420 11060 [ 11BC9B1E8801B01F7F6ADB9EAD30019B ] MountMgr C:\Windows\system32\drivers\mountmgr.sys 11:29:09.0428 11060 MountMgr - ok 11:29:09.0517 11060 [ 8C7336950F1E69CDFD811CBBD9CF00A2 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 11:29:09.0528 11060 MozillaMaintenance - ok 11:29:09.0715 11060 [ F8276EB8698142884498A528DFEA8478 ] mpio C:\Windows\system32\drivers\mpio.sys 11:29:09.0724 11060 mpio - ok 11:29:09.0785 11060 [ C92B9ABDB65A5991E00C28F13491DBA2 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 11:29:09.0793 11060 mpsdrv - ok 11:29:09.0885 11060 [ 897E3BAF68BA406A61682AE39C83900C ] MpsSvc C:\Windows\system32\mpssvc.dll 11:29:09.0934 11060 MpsSvc - ok 11:29:09.0950 11060 [ 3C200630A89EF2C0864D515B7A75802E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys 11:29:09.0955 11060 Mraid35x - ok 11:29:10.0094 11060 [ 7C1DE4AA96DC0C071611F9E7DE02A68D ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 11:29:10.0101 11060 MRxDAV - ok 11:29:10.0167 11060 [ 1485811B320FF8C7EDAD1CAEBB1C6C2B ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 11:29:10.0176 11060 mrxsmb - ok 11:29:10.0483 11060 [ 3B929A60C833FC615FD97FBA82BC7632 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 11:29:10.0498 11060 mrxsmb10 - ok 11:29:10.0693 11060 [ C64AB3E1F53B4F5B5BB6D796B2D7BEC3 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 11:29:10.0701 11060 mrxsmb20 - ok 11:29:10.0763 11060 [ 1AC860612B85D8E85EE257D372E39F4D ] msahci C:\Windows\system32\drivers\msahci.sys 11:29:10.0768 11060 msahci - ok 11:29:10.0788 11060 [ 264BBB4AAF312A485F0E44B65A6B7202 ] msdsm C:\Windows\system32\drivers\msdsm.sys 11:29:10.0796 11060 msdsm - ok 11:29:10.0929 11060 [ 7EC02CE772F068ED0BEAFA3DA341A9BC ] MSDTC C:\Windows\System32\msdtc.exe 11:29:10.0937 11060 MSDTC - ok 11:29:11.0006 11060 [ 704F59BFC4512D2BB0146AEC31B10A7C ] Msfs C:\Windows\system32\drivers\Msfs.sys 11:29:11.0010 11060 Msfs - ok 11:29:11.0046 11060 [ 00EBC952961664780D43DCA157E79B27 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 11:29:11.0051 11060 msisadrv - ok 11:29:11.0082 11060 [ 366B0C1F4478B519C181E37D43DCDA32 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 11:29:11.0090 11060 MSiSCSI - ok 11:29:11.0106 11060 msiserver - ok 11:29:11.0186 11060 [ 0EA73E498F53B96D83DBFCA074AD4CF8 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 11:29:11.0189 11060 MSKSSRV - ok 11:29:11.0361 11060 [ 3D9DF5C79ABE835E58DF426B14600A33 ] msoidsvc C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE 11:29:11.0447 11060 msoidsvc - ok 11:29:11.0488 11060 [ 52E59B7E992A58E740AA63F57EDBAE8B ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 11:29:11.0491 11060 MSPCLOCK - ok 11:29:11.0520 11060 [ 49084A75BAE043AE02D5B44D02991BB2 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 11:29:11.0523 11060 MSPQM - ok 11:29:11.0568 11060 [ DC6CCF440CDEDE4293DB41C37A5060A5 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 11:29:11.0587 11060 MsRPC - ok 11:29:11.0639 11060 [ 855796E59DF77EA93AF46F20155BF55B ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys 11:29:11.0640 11060 mssmbios - ok 11:29:11.0665 11060 [ 86D632D75D05D5B7C7C043FA3564AE86 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 11:29:11.0669 11060 MSTEE - ok 11:29:11.0700 11060 [ 0CC49F78D8ACA0877D885F149084E543 ] Mup C:\Windows\system32\Drivers\mup.sys 11:29:11.0708 11060 Mup - ok 11:29:11.0852 11060 [ A5B10C845E7538C60C0F5D87A57CB3F5 ] napagent C:\Windows\system32\qagentRT.dll 11:29:11.0885 11060 napagent - ok 11:29:12.0129 11060 [ 2007B826C4ACD94AE32232B41F0842B9 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 11:29:12.0146 11060 NativeWifiP - ok 11:29:12.0206 11060 [ 65950E07329FCEE8E6516B17C8D0ABB6 ] NDIS C:\Windows\system32\drivers\ndis.sys 11:29:12.0222 11060 NDIS - ok 11:29:12.0240 11060 [ 64DF698A425478E321981431AC171334 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 11:29:12.0244 11060 NdisTapi - ok 11:29:12.0308 11060 [ 8BAA43196D7B5BB972C9A6B2BBF61A19 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 11:29:12.0312 11060 Ndisuio - ok 11:29:12.0437 11060 [ F8158771905260982CE724076419EF19 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 11:29:12.0444 11060 NdisWan - ok 11:29:12.0470 11060 [ 9CB77ED7CB72850253E973A2D6AFDF49 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 11:29:12.0477 11060 NDProxy - ok 11:29:12.0685 11060 [ B90E093E7A7250906F1054418B5339C0 ] Nero BackItUp Scheduler 4.0 C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe 11:29:12.0765 11060 Nero BackItUp Scheduler 4.0 - ok 11:29:12.0858 11060 [ 2334DC48997BA203B794DF3EE70521DB ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll 11:29:12.0865 11060 Net Driver HPZ12 - ok 11:29:12.0896 11060 [ A499294F5029A7862ADC115BDA7371CE ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 11:29:12.0900 11060 NetBIOS - ok 11:29:12.0968 11060 [ FC2C792EBDDC8E28DF939D6A92C83D61 ] netbt C:\Windows\system32\DRIVERS\netbt.sys 11:29:12.0992 11060 netbt - ok 11:29:13.0023 11060 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] Netlogon C:\Windows\system32\lsass.exe 11:29:13.0024 11060 Netlogon - ok 11:29:13.0140 11060 [ 9B63B29DEFC0F3115A559D2597BF5D75 ] Netman C:\Windows\System32\netman.dll 11:29:13.0155 11060 Netman - ok 11:29:13.0576 11060 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 11:29:13.0645 11060 NetMsmqActivator - ok 11:29:13.0650 11060 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 11:29:13.0651 11060 NetPipeActivator - ok 11:29:13.0674 11060 [ 7846D0136CC2B264926A73047BA7688A ] netprofm C:\Windows\System32\netprofm.dll 11:29:13.0678 11060 netprofm - ok 11:29:13.0716 11060 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 11:29:13.0717 11060 NetTcpActivator - ok 11:29:13.0723 11060 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 11:29:13.0725 11060 NetTcpPortSharing - ok 11:29:13.0780 11060 [ 4AC08BD6AF2DF42E0C3196D826C8AEA7 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 11:29:13.0789 11060 nfrd960 - ok 11:29:13.0883 11060 [ F145BF4C4668E7E312069F81EF847CFC ] NlaSvc C:\Windows\System32\nlasvc.dll 11:29:13.0886 11060 NlaSvc - ok 11:29:14.0005 11060 [ B298874F8E0EA93F06EC40AA8D146478 ] Npfs C:\Windows\system32\drivers\Npfs.sys 11:29:14.0010 11060 Npfs - ok 11:29:14.0066 11060 [ ACB62BAA1C319B17752553DF3026EEEB ] nsi C:\Windows\system32\nsisvc.dll 11:29:14.0071 11060 nsi - ok 11:29:14.0103 11060 [ 1523AF19EE8B030BA682F7A53537EAEB ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 11:29:14.0108 11060 nsiproxy - ok 11:29:14.0214 11060 [ BAC869DFB98E499BA4D9BB1FB43270E1 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 11:29:14.0296 11060 Ntfs - ok 11:29:14.0344 11060 [ A2B6583A5652A385DFF5E4F49AD48761 ] NTIBackupSvc C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe 11:29:14.0350 11060 NTIBackupSvc - ok 11:29:14.0388 11060 [ 7D397449AAF52B0E7C79B64F6AD4473E ] NTIDrvr C:\Windows\system32\Drivers\NTIDrvr.sys 11:29:14.0392 11060 NTIDrvr - ok 11:29:14.0507 11060 [ 40B87FE8A1A9A5AC9E5A91D96F212BCD ] NTISchedulerSvc C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe 11:29:14.0518 11060 NTISchedulerSvc - ok 11:29:14.0622 11060 [ D4012918D3A3847B44B888D56BC095D6 ] NuidFltr C:\Windows\system32\DRIVERS\NuidFltr.sys 11:29:14.0627 11060 NuidFltr - ok 11:29:14.0648 11060 [ DD5D684975352B85B52E3FD5347C20CB ] Null C:\Windows\system32\drivers\Null.sys 11:29:14.0651 11060 Null - ok 11:29:14.0978 11060 [ 5104BAC2DA2A5BDD86AC6B0708B00F06 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 11:29:15.0080 11060 nvlddmkm - ok 11:29:15.0147 11060 [ 2C040B7ADA5B06F6FACADAC8514AA034 ] nvraid C:\Windows\system32\drivers\nvraid.sys 11:29:15.0156 11060 nvraid - ok 11:29:15.0204 11060 [ F7EA0FE82842D05EDA3EFDD376DBFDBA ] nvstor C:\Windows\system32\drivers\nvstor.sys 11:29:15.0211 11060 nvstor - ok 11:29:15.0363 11060 [ DDFAFCE89A5C93D04712B86F94E9FCBA ] nvsvc C:\Windows\system32\nvvsvc.exe 11:29:15.0376 11060 nvsvc - ok 11:29:15.0556 11060 [ 84E035225474E48CD3A6A3CE52332095 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 11:29:15.0643 11060 nvUpdatusService - ok 11:29:15.0700 11060 [ 19067CA93075EF4823E3938A686F532F ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 11:29:15.0709 11060 nv_agp - ok 11:29:15.0714 11060 NwlnkFlt - ok 11:29:15.0721 11060 NwlnkFwd - ok 11:29:15.0812 11060 [ B5B1CE65AC15BBD11C0619E3EF7CFC28 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys 11:29:15.0814 11060 ohci1394 - ok 11:29:15.0837 11060 [ 4965B005492CBA7719E82B71E3245495 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 11:29:15.0846 11060 ose64 - ok 11:29:16.0122 11060 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 11:29:16.0573 11060 osppsvc - ok 11:29:16.0753 11060 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2pimsvc C:\Windows\system32\p2psvc.dll 11:29:16.0831 11060 p2pimsvc - ok 11:29:16.0860 11060 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2psvc C:\Windows\system32\p2psvc.dll 11:29:16.0866 11060 p2psvc - ok 11:29:16.0931 11060 [ AECD57F94C887F58919F307C35498EA0 ] Parport C:\Windows\system32\drivers\parport.sys 11:29:16.0938 11060 Parport - ok 11:29:17.0077 11060 [ B43751085E2ABE389DA466BC62A4B987 ] partmgr C:\Windows\system32\drivers\partmgr.sys 11:29:17.0086 11060 partmgr - ok 11:29:17.0135 11060 [ 9AB157B374192FF276C1628FBDBA2B0E ] PcaSvc C:\Windows\System32\pcasvc.dll 11:29:17.0144 11060 PcaSvc - ok 11:29:17.0206 11060 [ 47AB1E0FC9D0E12BB53BA246E3A0906D ] pci C:\Windows\system32\drivers\pci.sys 11:29:17.0217 11060 pci - ok 11:29:17.0241 11060 [ 8D618C829034479985A9ED56106CC732 ] pciide C:\Windows\system32\drivers\pciide.sys 11:29:17.0246 11060 pciide - ok 11:29:17.0284 11060 [ 037661F3D7C507C9993B7010CEEE6288 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 11:29:17.0296 11060 pcmcia - ok 11:29:17.0409 11060 [ 58865916F53592A61549B04941BFD80D ] PEAUTH C:\Windows\system32\drivers\peauth.sys 11:29:17.0446 11060 PEAUTH - ok 11:29:17.0663 11060 [ 0ED8727EA0172860F47258456C06CAEA ] PerfHost C:\Windows\SysWow64\perfhost.exe 11:29:17.0669 11060 PerfHost - ok 11:29:17.0876 11060 PID_PEPI - ok 11:29:17.0939 11060 [ E9E68C1A0F25CF4A7AC966EEA74EE89E ] pla C:\Windows\system32\pla.dll 11:29:18.0180 11060 pla - ok 11:29:18.0319 11060 [ FE6B0F59215C9FD9F9D26539C58C8B82 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 11:29:18.0368 11060 PlugPlay - ok 11:29:18.0546 11060 [ AC78DF349F0E4CFB8B667C0CFFF83CCE ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll 11:29:18.0553 11060 Pml Driver HPZ12 - ok 11:29:18.0736 11060 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPAutoReg C:\Windows\system32\p2psvc.dll 11:29:18.0743 11060 PNRPAutoReg - ok 11:29:18.0779 11060 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPsvc C:\Windows\system32\p2psvc.dll 11:29:18.0786 11060 PNRPsvc - ok 11:29:18.0923 11060 [ 89A5560671C2D8B4A4B51F3E1AA069D8 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 11:29:18.0949 11060 PolicyAgent - ok 11:29:19.0097 11060 [ 23386E9952025F5F21C368971E2E7301 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 11:29:19.0122 11060 PptpMiniport - ok 11:29:19.0150 11060 [ 5080E59ECEE0BC923F14018803AA7A01 ] Processor C:\Windows\system32\drivers\processr.sys 11:29:19.0189 11060 Processor - ok 11:29:19.0278 11060 [ E058CE4FC2449D8BFA14739C83B7FF2A ] ProfSvc C:\Windows\system32\profsvc.dll 11:29:19.0289 11060 ProfSvc - ok 11:29:19.0306 11060 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] ProtectedStorage C:\Windows\system32\lsass.exe 11:29:19.0307 11060 ProtectedStorage - ok 11:29:19.0477 11060 [ C5AB7F0809392D0DA027F4A2A81BFA31 ] PSched C:\Windows\system32\DRIVERS\pacer.sys 11:29:19.0485 11060 PSched - ok 11:29:19.0639 11060 [ 2CFD31D41CDE75328ACAEEE2D4F4B836 ] PSDFilter C:\Windows\system32\DRIVERS\psdfilter.sys 11:29:19.0643 11060 PSDFilter - ok 11:29:19.0859 11060 [ 51A585F999672D8BB07F22AE12B40846 ] PSDNServ C:\Windows\system32\DRIVERS\PSDNServ.sys 11:29:19.0863 11060 PSDNServ - ok 11:29:19.0883 11060 [ DB50D3F5C31B1A848B04F7F2A6FF2709 ] psdvdisk C:\Windows\system32\DRIVERS\PSDVdisk.sys 11:29:19.0889 11060 psdvdisk - ok 11:29:20.0096 11060 [ 0B83F4E681062F3839BE2EC1D98FD94A ] ql2300 C:\Windows\system32\drivers\ql2300.sys 11:29:20.0454 11060 ql2300 - ok 11:29:20.0536 11060 [ E1C80F8D4D1E39EF9595809C1369BF2A ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 11:29:20.0545 11060 ql40xx - ok 11:29:20.0646 11060 [ 90574842C3DA781E279061A3EFF91F07 ] QWAVE C:\Windows\system32\qwave.dll 11:29:20.0731 11060 QWAVE - ok 11:29:20.0750 11060 [ E8D76EDAB77EC9C634C27B8EAC33ADC5 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 11:29:20.0755 11060 QWAVEdrv - ok 11:29:20.0778 11060 [ 1013B3B663A56D3DDD784F581C1BD005 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 11:29:20.0782 11060 RasAcd - ok 11:29:20.0956 11060 [ B2AE18F847D07F0044404DDF7CB04497 ] RasAuto C:\Windows\System32\rasauto.dll 11:29:20.0964 11060 RasAuto - ok 11:29:21.0196 11060 [ AC7BC4D42A7E558718DFDEC599BBFC2C ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 11:29:21.0202 11060 Rasl2tp - ok 11:29:21.0676 11060 [ 3AD83E4046C43BE510DE681588ACB8AF ] RasMan C:\Windows\System32\rasmans.dll 11:29:21.0742 11060 RasMan - ok 11:29:21.0824 11060 [ 4517FBF8B42524AFE4EDE1DE102AAE3E ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 11:29:21.0830 11060 RasPppoe - ok 11:29:21.0890 11060 [ C6A593B51F34C33E5474539544072527 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 11:29:21.0895 11060 RasSstp - ok 11:29:21.0984 11060 [ 322DB5C6B55E8D8EE8D6F358B2AAABB1 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 11:29:22.0026 11060 rdbss - ok 11:29:22.0056 11060 [ 603900CC05F6BE65CCBF373800AF3716 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 11:29:22.0060 11060 RDPCDD - ok 11:29:22.0088 11060 [ C045D1FB111C28DF0D1BE8D4BDA22C06 ] rdpdr C:\Windows\system32\drivers\rdpdr.sys 11:29:22.0099 11060 rdpdr - ok 11:29:22.0111 11060 [ CAB9421DAF3D97B33D0D055858E2C3AB ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 11:29:22.0115 11060 RDPENCDD - ok 11:29:22.0148 11060 [ AE4BD9E1C33D351D8E607FC81F15160C ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 11:29:22.0189 11060 RDPWD - ok 11:29:22.0219 11060 [ C612B9557DA73F70D41F8A6FBC8E5344 ] RemoteAccess C:\Windows\System32\mprdim.dll 11:29:22.0227 11060 RemoteAccess - ok 11:29:22.0295 11060 [ 44B9D8EC2F3EF3A0EFB00857AF70D861 ] RemoteRegistry C:\Windows\system32\regsvc.dll 11:29:22.0305 11060 RemoteRegistry - ok 11:29:22.0399 11060 [ A035A7BF5132682F53F1E7B955690CE7 ] RichVideo C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe 11:29:22.0407 11060 RichVideo - ok 11:29:22.0437 11060 [ F46C457840D4B7A4DAAFEE739CE04102 ] RpcLocator C:\Windows\system32\locator.exe 11:29:22.0441 11060 RpcLocator - ok 11:29:22.0526 11060 [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] RpcSs C:\Windows\System32\rpcss.dll 11:29:22.0532 11060 RpcSs - ok 11:29:22.0563 11060 [ 22A9CB08B1A6707C1550C6BF099AAE73 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 11:29:22.0592 11060 rspndr - ok 11:29:22.0631 11060 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] SamSs C:\Windows\system32\lsass.exe 11:29:22.0633 11060 SamSs - ok 11:29:22.0676 11060 [ CD9C693589C60AD59BBBCFB0E524E01B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 11:29:22.0684 11060 sbp2port - ok 11:29:22.0832 11060 [ FD1CDCF108D5EF3366F00D18B70FB89B ] SCardSvr C:\Windows\System32\SCardSvr.dll 11:29:22.0842 11060 SCardSvr - ok 11:29:23.0011 11060 [ 0F838C811AD295D2A4489B9993096C63 ] Schedule C:\Windows\system32\schedsvc.dll 11:29:23.0069 11060 Schedule - ok 11:29:23.0177 11060 [ 5A268127633C7EE2A7FB87F39D748D56 ] SCPolicySvc C:\Windows\System32\certprop.dll 11:29:23.0178 11060 SCPolicySvc - ok 11:29:23.0240 11060 [ 4FF71B076A7760FE75EA5AE2D0EE0018 ] SDRSVC C:\Windows\System32\SDRSVC.dll 11:29:23.0248 11060 SDRSVC - ok 11:29:23.0299 11060 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 11:29:23.0303 11060 secdrv - ok 11:29:23.0345 11060 [ 5ACDCBC67FCF894A1815B9F96D704490 ] seclogon C:\Windows\system32\seclogon.dll 11:29:23.0351 11060 seclogon - ok 11:29:23.0442 11060 [ 90973A64B96CD647FF81C79443618EED ] SENS C:\Windows\system32\sens.dll 11:29:23.0452 11060 SENS - ok 11:29:23.0514 11060 [ 2449316316411D65BD2C761A6FFB2CE2 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 11:29:23.0519 11060 Serenum - ok 11:29:23.0694 11060 [ 4B438170BE2FC8E0BD35EE87A960F84F ] Serial C:\Windows\system32\DRIVERS\serial.sys 11:29:23.0701 11060 Serial - ok 11:29:23.0719 11060 [ A842F04833684BCEEA7336211BE478DF ] sermouse C:\Windows\system32\drivers\sermouse.sys 11:29:23.0723 11060 sermouse - ok 11:29:23.0798 11060 [ A8E4A4407A09F35DCCC3771AF590B0C4 ] SessionEnv C:\Windows\system32\sessenv.dll 11:29:23.0807 11060 SessionEnv - ok 11:29:23.0834 11060 [ 14D4B4465193A87C127933978E8C4106 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 11:29:23.0838 11060 sffdisk - ok 11:29:23.0852 11060 [ 7073AEE3F82F3D598E3825962AA98AB2 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 11:29:23.0856 11060 sffp_mmc - ok 11:29:23.0897 11060 [ 35E59EBE4A01A0532ED67975161C7B82 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 11:29:23.0900 11060 sffp_sd - ok 11:29:23.0917 11060 [ 6B7838C94135768BD455CBDC23E39E5F ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 11:29:23.0920 11060 sfloppy - ok 11:29:24.0061 11060 [ 4C5AEE179DA7E1EE9A9CCB9DA289AF34 ] SharedAccess C:\Windows\System32\ipnathlp.dll 11:29:24.0094 11060 SharedAccess - ok 11:29:24.0162 11060 [ 56793271ECDEDD350C5ADD305603E963 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 11:29:24.0211 11060 ShellHWDetection - ok 11:29:24.0231 11060 [ 7A5DE502AEB719D4594C6471060A78B3 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys 11:29:24.0239 11060 SiSRaid2 - ok 11:29:24.0275 11060 [ 3A2F769FAB9582BC720E11EA1DFB184D ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 11:29:24.0282 11060 SiSRaid4 - ok 11:29:24.0334 11060 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 11:29:24.0335 11060 SkypeUpdate - ok 11:29:24.0428 11060 [ A9A27A8E257B45A604FDAD4F26FE7241 ] slsvc C:\Windows\system32\SLsvc.exe 11:29:24.0980 11060 slsvc - ok 11:29:25.0016 11060 [ FD74B4B7C2088E390A30C85A896FC3AF ] SLUINotify C:\Windows\system32\SLUINotify.dll 11:29:25.0024 11060 SLUINotify - ok 11:29:25.0153 11060 [ 290B6F6A0EC4FCDFC90F5CB6D7020473 ] Smb C:\Windows\system32\DRIVERS\smb.sys 11:29:25.0159 11060 Smb - ok 11:29:25.0277 11060 [ F8F47F38909823B1AF28D60B96340CFF ] SNMPTRAP C:\Windows\System32\snmptrap.exe 11:29:25.0282 11060 SNMPTRAP - ok 11:29:25.0343 11060 [ BDCE0DE74BC57ABD1EF2CE6AEAC37876 ] Software Services Manager C:\Program Files\intel\inteldh\common\IntelDHSvcMgr.exe 11:29:25.0349 11060 Software Services Manager - ok 11:29:25.0523 11060 [ 386C3C63F00A7040C7EC5E384217E89D ] spldr C:\Windows\system32\drivers\spldr.sys 11:29:25.0528 11060 spldr - ok 11:29:25.0636 11060 [ F66FF751E7EFC816D266977939EF5DC3 ] Spooler C:\Windows\System32\spoolsv.exe 11:29:25.0648 11060 Spooler - ok 11:29:25.0769 11060 [ 88E5162E58C8919CC873F5D8946197CF ] sptd C:\Windows\system32\Drivers\sptd.sys 11:29:25.0769 11060 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 88E5162E58C8919CC873F5D8946197CF 11:29:25.0777 11060 sptd ( LockedFile.Multi.Generic ) - warning 11:29:25.0777 11060 sptd - detected LockedFile.Multi.Generic (1) 11:29:25.0866 11060 [ 880A57FCCB571EBD063D4DD50E93E46D ] srv C:\Windows\system32\DRIVERS\srv.sys 11:29:25.0981 11060 srv - ok 11:29:26.0102 11060 [ A1AD14A6D7A37891FFFECA35EBBB0730 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 11:29:26.0117 11060 srv2 - ok 11:29:26.0168 11060 [ 4BED62F4FA4D8300973F1151F4C4D8A7 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 11:29:26.0187 11060 srvnet - ok 11:29:26.0292 11060 [ 192C74646EC5725AEF3F80D19FF75F6A ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 11:29:26.0304 11060 SSDPSRV - ok 11:29:26.0878 11060 [ 2EE3FA0308E6185BA64A9A7F2E74332B ] SstpSvc C:\Windows\system32\sstpsvc.dll 11:29:26.0886 11060 SstpSvc - ok 11:29:27.0499 11060 Steam Client Service - ok 11:29:27.0762 11060 [ F0359F7CE712D69ACEF0886BDB4792ED ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 11:29:27.0778 11060 Stereo Service - ok 11:29:27.0862 11060 [ 15825C1FBFB8779992CB65087F316AF5 ] stisvc C:\Windows\System32\wiaservc.dll 11:29:27.0899 11060 stisvc - ok 11:29:27.0932 11060 [ 8A851CA908B8B974F89C50D2E18D4F0C ] swenum C:\Windows\system32\DRIVERS\swenum.sys 11:29:27.0936 11060 swenum - ok 11:29:28.0094 11060 [ 6DE37F4DE19D4EFD9C48C43ADDBC949A ] swprv C:\Windows\System32\swprv.dll 11:29:28.0145 11060 swprv - ok 11:29:28.0191 11060 [ 2F26A2C6FC96B29BEFF5D8ED74E6625B ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys 11:29:28.0197 11060 Symc8xx - ok 11:29:28.0212 11060 [ A909667976D3BCCD1DF813FED517D837 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys 11:29:28.0218 11060 Sym_hi - ok 11:29:28.0352 11060 [ 36887B56EC2D98B9C362F6AE4DE5B7B0 ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys 11:29:28.0372 11060 Sym_u3 - ok 11:29:28.0462 11060 [ 92D7A8B0F87B036F17D25885937897A6 ] SysMain C:\Windows\system32\sysmain.dll 11:29:28.0851 11060 SysMain - ok 11:29:29.0390 11060 [ 005CE42567F9113A3BCCB3B20073B029 ] TabletInputService C:\Windows\System32\TabSvc.dll 11:29:29.0398 11060 TabletInputService - ok 11:29:29.0492 11060 [ 595CB8DA5B522AD8CC28193DC21FD496 ] tap0901 C:\Windows\system32\DRIVERS\tap0901.sys 11:29:29.0497 11060 tap0901 - ok 11:29:29.0548 11060 [ CC2562B4D55E0B6A4758C65407F63B79 ] TapiSrv C:\Windows\System32\tapisrv.dll 11:29:29.0664 11060 TapiSrv - ok 11:29:29.0693 11060 [ CDBE8D7C1E201B911CDC346D06617FB5 ] TBS C:\Windows\System32\tbssvc.dll 11:29:29.0695 11060 TBS - ok 11:29:29.0831 11060 [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip C:\Windows\system32\drivers\tcpip.sys 11:29:29.0978 11060 Tcpip - ok 11:29:30.0272 11060 [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys 11:29:30.0280 11060 Tcpip6 - ok 11:29:30.0371 11060 [ C7E72A4071EE0200E3C075DACFB2B334 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 11:29:30.0376 11060 tcpipreg - ok 11:29:30.0425 11060 [ 1D8BF4AAA5FB7A2761475781DC1195BC ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 11:29:30.0430 11060 TDPIPE - ok 11:29:30.0462 11060 [ 7F7E00CDF609DF657F4CDA02DD1C9BB1 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 11:29:30.0467 11060 TDTCP - ok 11:29:30.0553 11060 [ 458919C8C42E398DC4802178D5FFEE27 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 11:29:30.0554 11060 tdx - ok 11:29:30.0897 11060 [ 9F3E7CABE86BBDECA009DE291DB6D9E2 ] TeamViewer8 C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe 11:29:30.0928 11060 TeamViewer8 - ok 11:29:30.0974 11060 [ 8C19678D22649EC002EF2282EAE92F98 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys 11:29:30.0980 11060 TermDD - ok 11:29:31.0116 11060 [ 5CDD30BC217082DAC71A9878D9BFD566 ] TermService C:\Windows\System32\termsrv.dll 11:29:31.0150 11060 TermService - ok 11:29:31.0203 11060 [ 56793271ECDEDD350C5ADD305603E963 ] Themes C:\Windows\system32\shsvcs.dll 11:29:31.0206 11060 Themes - ok 11:29:31.0237 11060 [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] THREADORDER C:\Windows\system32\mmcss.dll 11:29:31.0238 11060 THREADORDER - ok 11:29:31.0279 11060 [ F4689F05AF472A651A7B1B7B02D200E7 ] TrkWks C:\Windows\System32\trkwks.dll 11:29:31.0286 11060 TrkWks - ok 11:29:31.0396 11060 [ 66328B08EF5A9305D8EDE36B93930369 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 11:29:31.0397 11060 TrustedInstaller - ok 11:29:31.0440 11060 [ 9E5409CD17C8BEF193AAD498F3BC2CB8 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 11:29:31.0444 11060 tssecsrv - ok 11:29:31.0471 11060 [ 89EC74A9E602D16A75A4170511029B3C ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys 11:29:31.0475 11060 tunmp - ok 11:29:31.0616 11060 [ 30A9B3F45AD081BFFC3BCAA9C812B609 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 11:29:31.0620 11060 tunnel - ok 11:29:31.0685 11060 [ FEC266EF401966311744BD0F359F7F56 ] uagp35 C:\Windows\system32\drivers\uagp35.sys 11:29:31.0692 11060 uagp35 - ok 11:29:31.0821 11060 [ 00C8CE31657624A125FDB90EFD554371 ] UBHelper C:\Windows\system32\drivers\UBHelper.sys 11:29:31.0825 11060 UBHelper - ok 11:29:31.0940 11060 [ FAF2640A2A76ED03D449E443194C4C34 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 11:29:31.0951 11060 udfs - ok 11:29:31.0981 11060 [ 060507C4113391394478F6953A79EEDC ] UI0Detect C:\Windows\system32\UI0Detect.exe 11:29:31.0988 11060 UI0Detect - ok 11:29:32.0051 11060 [ 4EC9447AC3AB462647F60E547208CA00 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 11:29:32.0058 11060 uliagpkx - ok 11:29:32.0107 11060 [ 697F0446134CDC8F99E69306184FBBB4 ] uliahci C:\Windows\system32\drivers\uliahci.sys 11:29:32.0149 11060 uliahci - ok 11:29:32.0166 11060 [ 31707F09846056651EA2C37858F5DDB0 ] UlSata C:\Windows\system32\drivers\ulsata.sys 11:29:32.0174 11060 UlSata - ok 11:29:32.0192 11060 [ 85E5E43ED5B48C8376281BAB519271B7 ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys 11:29:32.0200 11060 ulsata2 - ok 11:29:32.0292 11060 [ 46E9A994C4FED537DD951F60B86AD3F4 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 11:29:32.0299 11060 umbus - ok 11:29:32.0713 11060 [ 927754ABF077AEB5504BE4E0F2C60C1B ] UMVPFSrv C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe 11:29:32.0725 11060 UMVPFSrv - ok 11:29:32.0783 11060 [ 7093799FF80E9DECA0680D2E3535BE60 ] upnphost C:\Windows\System32\upnphost.dll 11:29:32.0824 11060 upnphost - ok 11:29:32.0883 11060 [ AF1B9474D67897D0C2CFF58E0ACEACCC ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys 11:29:32.0926 11060 USBAAPL64 - ok 11:29:32.0976 11060 [ C6BA890DE6E41857FBE84175519CAE7D ] usbaudio C:\Windows\system32\drivers\usbaudio.sys 11:29:32.0982 11060 usbaudio - ok 11:29:33.0116 11060 [ 07E3498FC60834219D2356293DA0FECC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 11:29:33.0121 11060 usbccgp - ok 11:29:33.0400 11060 [ 9247F7E0B65852C1F6631480984D6ED2 ] usbcir C:\Windows\system32\drivers\usbcir.sys 11:29:33.0439 11060 usbcir - ok 11:29:33.0621 11060 [ 827E44DE934A736EA31E91D353EB126F ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 11:29:33.0709 11060 usbehci - ok 11:29:33.0821 11060 [ BB35CD80A2ECECFADC73569B3D70C7D1 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 11:29:33.0930 11060 usbhub - ok 11:29:33.0978 11060 [ EBA14EF0C07CEC233F1529C698D0D154 ] usbohci C:\Windows\system32\drivers\usbohci.sys 11:29:33.0982 11060 usbohci - ok 11:29:34.0020 11060 [ 28B693B6D31E7B9332C1BDCEFEF228C1 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 11:29:34.0025 11060 usbprint - ok 11:29:34.0131 11060 [ EA0BF666868964FBE8CB10E50C97B9F1 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys 11:29:34.0136 11060 usbscan - ok 11:29:34.0251 11060 [ B854C1558FCA0C269A38663E8B59B581 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 11:29:34.0257 11060 USBSTOR - ok 11:29:34.0271 11060 [ B2872CBF9F47316ABD0E0C74A1ABA507 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 11:29:34.0276 11060 usbuhci - ok 11:29:34.0391 11060 [ FC33099877790D51B0927B7039059855 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys 11:29:34.0399 11060 usbvideo - ok 11:29:34.0527 11060 [ D76E231E4850BB3F88A3D9A78DF191E3 ] UxSms C:\Windows\System32\uxsms.dll 11:29:34.0532 11060 UxSms - ok 11:29:34.0747 11060 [ 294945381DFA7CE58CECF0A9896AF327 ] vds C:\Windows\System32\vds.exe 11:29:34.0773 11060 vds - ok 11:29:34.0820 11060 [ 916B94BCF1E09873FFF2D5FB11767BBC ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 11:29:34.0823 11060 vga - ok 11:29:34.0862 11060 [ B83AB16B51FEDA65DD81B8C59D114D63 ] VgaSave C:\Windows\System32\drivers\vga.sys 11:29:34.0866 11060 VgaSave - ok 11:29:35.0003 11060 [ 8294B6C3FDB6C33F24E150DE647ECDAA ] viaide C:\Windows\system32\drivers\viaide.sys 11:29:35.0008 11060 viaide - ok 11:29:35.0066 11060 [ 2B7E885ED951519A12C450D24535DFCA ] volmgr C:\Windows\system32\drivers\volmgr.sys 11:29:35.0073 11060 volmgr - ok 11:29:35.0210 11060 [ CEC5AC15277D75D9E5DEC2E1C6EAF877 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 11:29:35.0234 11060 volmgrx - ok 11:29:35.0293 11060 [ 582F710097B46140F5A89A19A6573D4B ] volsnap C:\Windows\system32\drivers\volsnap.sys 11:29:35.0334 11060 volsnap - ok 11:29:35.0414 11060 [ A68F455ED2673835209318DD61BFBB0E ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 11:29:35.0424 11060 vsmraid - ok 11:29:35.0490 11060 [ B75232DAD33BFD95BF6F0A3E6BFF51E1 ] VSS C:\Windows\system32\vssvc.exe 11:29:35.0732 11060 VSS - ok 11:29:35.0817 11060 [ F14A7DE2EA41883E250892E1E5230A9A ] W32Time C:\Windows\system32\w32time.dll 11:29:35.0840 11060 W32Time - ok 11:29:35.0861 11060 [ FEF8FE5923FEAD2CEE4DFABFCE3393A7 ] WacomPen C:\Windows\system32\drivers\wacompen.sys 11:29:35.0867 11060 WacomPen - ok 11:29:36.0085 11060 [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys 11:29:36.0091 11060 Wanarp - ok 11:29:36.0105 11060 [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 11:29:36.0106 11060 Wanarpv6 - ok 11:29:36.0308 11060 [ B4E4C37D0AA6100090A53213EE2BF1C1 ] wcncsvc C:\Windows\System32\wcncsvc.dll 11:29:36.0336 11060 wcncsvc - ok 11:29:36.0350 11060 [ EA4B369560E986F19D93F45A881484AC ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 11:29:36.0358 11060 WcsPlugInService - ok 11:29:36.0395 11060 [ 0C17A0816F65B89E362E682AD5E7266E ] Wd C:\Windows\system32\drivers\wd.sys 11:29:36.0400 11060 Wd - ok 11:29:36.0538 11060 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 11:29:36.0638 11060 Wdf01000 - ok 11:29:36.0709 11060 [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiServiceHost C:\Windows\system32\wdi.dll 11:29:36.0712 11060 WdiServiceHost - ok 11:29:36.0717 11060 [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiSystemHost C:\Windows\system32\wdi.dll 11:29:36.0720 11060 WdiSystemHost - ok 11:29:36.0782 11060 [ 3E6D05381CF35F75EBB055544A8ED9AC ] WebClient C:\Windows\System32\webclnt.dll 11:29:36.0789 11060 WebClient - ok 11:29:37.0228 11060 [ 8D40BC587993F876658BF9FB0F7D3462 ] Wecsvc C:\Windows\system32\wecsvc.dll 11:29:37.0251 11060 Wecsvc - ok 11:29:37.0276 11060 [ 9C980351D7E96288EA0C23AE232BD065 ] wercplsupport C:\Windows\System32\wercplsupport.dll 11:29:37.0284 11060 wercplsupport - ok 11:29:37.0321 11060 [ 66B9ECEBC46683F47EDC06333C075FEF ] WerSvc C:\Windows\System32\WerSvc.dll 11:29:37.0329 11060 WerSvc - ok 11:29:37.0361 11060 WinDefend - ok 11:29:37.0370 11060 WinHttpAutoProxySvc - ok 11:29:37.0700 11060 [ D2E7296ED1BD26D8DB2799770C077A02 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 11:29:38.0024 11060 Winmgmt - ok 11:29:38.0145 11060 [ 6CBB0C68F13B9C2EC1B16F5FA5E7C869 ] WinRM C:\Windows\system32\WsmSvc.dll 11:29:38.0268 11060 WinRM - ok 11:29:38.0356 11060 [ EC339C8115E91BAED835957E9A677F16 ] Wlansvc C:\Windows\System32\wlansvc.dll 11:29:38.0378 11060 Wlansvc - ok 11:29:38.0499 11060 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 11:29:38.0663 11060 wlidsvc - ok 11:29:38.0722 11060 [ E18AEBAAA5A773FE11AA2C70F65320F5 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys 11:29:38.0723 11060 WmiAcpi - ok 11:29:38.0769 11060 [ 21FA389E65A852698B6A1341F36EE02D ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 11:29:38.0771 11060 wmiApSrv - ok 11:29:38.0813 11060 WMPNetworkSvc - ok 11:29:38.0849 11060 [ CBC156C913F099E6680D1DF9307DB7A8 ] WPCSvc C:\Windows\System32\wpcsvc.dll 11:29:38.0860 11060 WPCSvc - ok 11:29:38.0892 11060 [ 490A18B4E4D53DC10879DEAA8E8B70D9 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 11:29:38.0901 11060 WPDBusEnum - ok 11:29:39.0003 11060 [ 5E2401B3FC1089C90E081291357371A9 ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys 11:29:39.0009 11060 WpdUsb - ok 11:29:39.0304 11060 [ 991E2C2CF3BC204C2BB2EE1476149E4E ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe 11:29:39.0343 11060 WPFFontCache_v0400 - ok 11:29:39.0368 11060 [ 8A900348370E359B6BFF6A550E4649E1 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 11:29:39.0372 11060 ws2ifsl - ok 11:29:39.0425 11060 [ 9EA3E6D0EF7A5C2B9181961052A4B01A ] wscsvc C:\Windows\system32\wscsvc.dll 11:29:39.0427 11060 wscsvc - ok 11:29:39.0432 11060 WSearch - ok 11:29:39.0527 11060 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 11:29:39.0761 11060 wuauserv - ok 11:29:39.0793 11060 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 11:29:39.0799 11060 WudfPf - ok 11:29:39.0866 11060 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 11:29:39.0906 11060 WUDFRd - ok 11:29:39.0944 11060 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 11:29:39.0952 11060 wudfsvc - ok 11:29:39.0959 11060 ================ Scan global =============================== 11:29:39.0988 11060 [ 060DC3A7A9A2626031EB23D90151428D ] C:\Windows\system32\basesrv.dll 11:29:40.0037 11060 [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll 11:29:40.0145 11060 [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll 11:29:40.0240 11060 [ 934E0B7D77FF78C18D9F8891221B6DE3 ] C:\Windows\system32\services.exe 11:29:40.0244 11060 [Global] - ok 11:29:40.0244 11060 ================ Scan MBR ================================== 11:29:40.0310 11060 [ EF9CDC51B437D322D54016B68F003416 ] \Device\Harddisk0\DR0 11:29:43.0225 11060 \Device\Harddisk0\DR0 - ok 11:29:43.0232 11060 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk6\DR6 11:29:43.0242 11060 \Device\Harddisk6\DR6 - ok 11:29:43.0250 11060 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk7\DR7 11:29:43.0260 11060 \Device\Harddisk7\DR7 - ok 11:29:43.0260 11060 ================ Scan VBR ================================== 11:29:43.0280 11060 [ F37317A04E269FC7D3212197B7B9F501 ] \Device\Harddisk0\DR0\Partition1 11:29:43.0282 11060 \Device\Harddisk0\DR0\Partition1 - ok 11:29:43.0298 11060 [ F9408424C850BD05070FD9BC762A4383 ] \Device\Harddisk0\DR0\Partition2 11:29:43.0300 11060 \Device\Harddisk0\DR0\Partition2 - ok 11:29:43.0307 11060 [ 8CEF4638949DF1999DDF5C51523BD629 ] \Device\Harddisk6\DR6\Partition1 11:29:43.0309 11060 \Device\Harddisk6\DR6\Partition1 - ok 11:29:43.0315 11060 [ C1B8EEB1DD2BD4F572BD55F2202480C5 ] \Device\Harddisk7\DR7\Partition1 11:29:43.0317 11060 \Device\Harddisk7\DR7\Partition1 - ok 11:29:43.0317 11060 ============================================================ 11:29:43.0317 11060 Scan finished 11:29:43.0318 11060 ============================================================ 11:29:43.0330 11052 Detected object count: 1 11:29:43.0330 11052 Actual detected object count: 1 11:29:58.0860 11052 sptd ( LockedFile.Multi.Generic ) - skipped by user 11:29:58.0860 11052 sptd ( LockedFile.Multi.Generic ) - User select action: Skip Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.01.04.05 Windows Vista Service Pack 2 x64 NTFS Internet Explorer 9.0.8112.16421 Karri :: KARRI-PC [administrator] 04/01/2013 8:47:18 AM mbam-log-2013-01-04 (08-47-18).txt Scan type: Full scan (C:\|D:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 658830 Time elapsed: 2 hour(s), 32 minute(s), 29 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 D:\Karri2\Program Files\Games\Vanilla and Chocolate FINAL\Vanilla&Chocolate.exe (Trojan.Agent) -> Quarantined and deleted successfully. (end)
This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.


Go here to run an online scannner from ESET.
  • Note: For browsers other than Internet Explorer, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.

If it doesn't find anything there will be no log to post.
Hi Doris, The ESET scanner will not work on my machine. It gets hung up at 158 files scanned and then locks up my entire machine. It won't even let me get to the Task Manager. Sorry. :(
Let's try a different scanner, because no one tool looks everywhere, I like to get an online scan as a confirmation that we haven't missed anything. If this doesn't work we'll move on to tool cleanup, but I would feel just a wee bit better if we could get one more scan. It's not absolutely critical though, I've had a few other logs lately where ESET has been misbehaving..


Perform an online scan with Internet Explorer with Panda ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open…click the Check Now button
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, it should start to scan automatically
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to your desktop.
  • Post the report in your next reply.

Note: Turn off the real time scanner of any existing antivirus program while performing the online scan
Hi Doris, I got this error: Oh! It seems that your version of Internet Explorer is 64-bit. Unfortunately, ActiveScan 2.0 does not run correctly with this browser. Perhaps this is the problem with the ESET scanner? Thanks,
ESET is designed to work with 64-bit systems. Has everything seemed to be running ok on this machine at this point? Are you having any further difficulties with machine #1?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI