This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer locks up after boot

42 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, My computer is running Windows 7 home edition. Every time I boot in normal mode, the computer locks up shortly after boot up. The mouse becomes non responsive, no lights flick on the computer hard drive and cntl-alt-del is not recognized. However when I boot in safe mode with networking, the computer appears to run well. I am posting this from safe mode right now on the troubled computer. I did not run the requested programs for the first post because I am unsure if they should be run in safe more. Please advise for my first step. Thank you for your help!
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!

It's fine to use many of our tools in Safe Mode. I'd like you to run the following 2 diagnostic scans for me please. They will not be fixing anything, but will help give me an idea of what is going on with the machine so we can determine how to move forward.


Download and Run DDS by sUBs

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
    • DDS.com
    • DDS.pif
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE



Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

Here is the dds,txt file and I have attached the attach.txt. I will work on the tdsskiller part next =================================== DDS (Ver_2012-11-20.01) - NTFS_AMD64 NETWORK Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.5.1 Run by [removed] at 20:47:56 on 2013-01-04 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2815.2242 [GMT -5:00] . AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\Explorer.EXE C:\Windows\system32\ctfmon.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://blekkosearch.mystart.com/blekko_soc/?source=f06b8e24&toolbarid=blekkotb_sa5&u=655192AEBE11C8F198023550AA48AA1E&tbp=homepage&v=1_2 uSearch Bar = hxxp://feed.snap.do/?publisher=Download&dpid=Download&co=US&userid=3ffa63ea-48db-44aa-85fe-7dd4558237a5&searchtype=ds&q={searchTerms} uSearch Page = hxxp://feed.snap.do/?publisher=Download&dpid=Download&co=US&userid=3ffa63ea-48db-44aa-85fe-7dd4558237a5&searchtype=ds&q={searchTerms} uSearchAssistant = hxxp://feed.snap.do/?publisher=Download&dpid=Download&co=US&userid=3ffa63ea-48db-44aa-85fe-7dd4558237a5&searchtype=ds&q={searchTerms} mURLSearchHooks: FreeOnlineRadioPlayerRecorder Toolbar: {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files (x86)\FreeOnlineRadioPlayerRecorder\prxtbFree.dll mURLSearchHooks: WinZipBar Toolbar: {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - C:\Program Files (x86)\WinZipBar\prxtbWinZ.dll mURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll BHO: WinZipBar Toolbar: {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - C:\Program Files (x86)\WinZipBar\prxtbWinZ.dll BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL BHO: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll BHO: FreeOnlineRadioPlayerRecorder Toolbar: {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files (x86)\FreeOnlineRadioPlayerRecorder\prxtbFree.dll BHO: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll TB: FreeOnlineRadioPlayerRecorder Toolbar: {F999A48B-1950-4D81-9971-79018F807B4B} - C:\Program Files (x86)\FreeOnlineRadioPlayerRecorder\prxtbFree.dll TB: FreeOnlineRadioPlayerRecorder Toolbar: {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files (x86)\FreeOnlineRadioPlayerRecorder\prxtbFree.dll TB: Conduit Engine: {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll TB: WinZipBar Toolbar: {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - C:\Program Files (x86)\WinZipBar\prxtbWinZ.dll TB: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuze.dll TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll TB: : {ae07101b-46d4-4a98-af68-0333ea26e113} - LocalServer32 - mRun: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [HF_G_Jul] "C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe" /DoAction mRun: [ROC_ROC_JULY_P1] "C:\Program Files (x86)\AVG Secure Search\ROC_ROC_JULY_P1.exe" / /PROMPT /CMPID=ROC_JULY_P1 mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\EVENTR~1.LNK - C:\Program Files (x86)\Broderbund\PrintMaster\PMremind.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MICROS~1.LNK - C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SNAPFI~1.LNK - C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll . INFO: HKCU has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . TCP: NameServer = 192.168.1.1 TCP: Interfaces\{4033BB00-608A-4B9D-A26D-220D60739AC0} : DHCPNameServer = 192.168.1.1 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\13.2.0\ViProtocol.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll SSODL: WebCheck - x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll x64-TB: : {ae07101b-46d4-4a98-af68-0333ea26e113} - LocalServer32 - x64-Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe x64-Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background x64-DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL x64-Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - x64-SSODL: WebCheck - . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Busa Family\AppData\Roaming\Mozilla\Firefox\Profiles\ejb5sw10.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3106777&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - www.google.com FF - prefs.js: keyword.URL - hxxp://www.google.com/search?btnI=I%27m+Feeling+Lucky&ie=UTF-8&oe=UTF-8&q= FF - component: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn\components\coFFPlgn.dll FF - component: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\components\IPSFFPl.dll FF - component: C:\Users\Busa Family\AppData\Roaming\Mozilla\Firefox\Profiles\ejb5sw10.default\extensions\{f999a48b-1950-4d81-9971-79018f807b4b}\components\FFExternalAlert.dll FF - component: C:\Users\Busa Family\AppData\Roaming\Mozilla\Firefox\Profiles\ejb5sw10.default\extensions\{f999a48b-1950-4d81-9971-79018f807b4b}\components\RadioWMPCore.dll FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\13.2.0\npsitesafety.dll FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\NPCIG.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll FF - plugin: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll FF - plugin: C:\Program Files (x86)\Sony\Media Go\npmediago.dll FF - plugin: C:\Program Files (x86)\Unity\WebPlayer\loader\npUnity3D32.dll FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\Busa Family\AppData\Local\HuluDesktop\instances\0.9.14.1\nphdplg.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll FF - plugin: C:\Windows\SysWOW64\npmproxy.dll . —- FIREFOX POLICIES —- FF - user.js: general.useragent.extra.brc - FF - user.js: yahoo.homepage.dontask - true);user_pref(extentions.y2layers.installId, 59a73efd-c240-4fe5-8de2-f8483412f875 FF - user.js: extentions.y2layers.defaultEnableAppsList - Buzzdock,Buzzdock, FF - user.js: extensions.autoDisableScopes - 14 FF - user.js: security.csp.enable - false . ============= SERVICES / DRIVERS =============== . R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2012-9-3 30568] R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\drivers\netr28x.sys [2011-2-1 1002848] S1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2011-6-2 984144] S1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2011-2-10 370288] S2 AirPrint;AirPrint;C:\Program Files (x86)\AirPrint\airprint.exe -s –> C:\Program Files (x86)\AirPrint\airprint.exe -s [?] S2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2011-2-10 25232] S2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2011-2-10 71600] S2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2012-11-8 44808] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624] S2 HP Support Assistant Service;HP Support Assistant Service;"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe" –> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [?] S2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-8-5 291896] S2 IntuitUpdateServiceV4;Intuit Update Service v4;C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [2011-8-25 13672] S2 pdfcDispatcher;PDF Document Manager;C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2011-2-1 1121304] S2 RoxioNow Service;RoxioNow Service;C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [2010-9-11 399344] S2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776] S2 vToolbarUpdater13.2.0;vToolbarUpdater13.2.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe [2012-11-8 711112] S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] S3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2011-10-1 764264] S3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2011-10-1 268648] S3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2011-10-1 25960] S3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2011-10-1 22376] S3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-2-23 59392] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-9-28 53760] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-2-13 1255736] . =============== Created Last 30 ================ . 2013-01-02 09:07:27 76232 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{516AA629-39E0-43FA-B4B1-C320C1C87164}\offreg.dll 2013-01-01 15:24:12 9125352 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{516AA629-39E0-43FA-B4B1-C320C1C87164}\mpengine.dll 2012-12-21 08:01:11 46080 —-a-w- C:\Windows\System32\atmlib.dll 2012-12-21 08:01:11 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2012-12-21 08:01:06 367616 —-a-w- C:\Windows\System32\atmfd.dll 2012-12-21 08:01:03 295424 —-a-w- C:\Windows\SysWow64\atmfd.dll 2012-12-12 10:33:15 2048 —-a-w- C:\Windows\SysWow64\tzres.dll 2012-12-12 10:33:15 2048 —-a-w- C:\Windows\System32\tzres.dll 2012-12-12 10:33:11 3149824 —-a-w- C:\Windows\System32\win32k.sys 2012-12-12 10:33:01 424960 —-a-w- C:\Windows\System32\KernelBase.dll 2012-12-12 10:33:00 338432 —-a-w- C:\Windows\System32\conhost.exe 2012-12-12 10:33:00 215040 —-a-w- C:\Windows\System32\winsrv.dll 2012-12-10 17:07:45 ——– d—–w- C:\Program Files\iPod 2012-12-10 17:07:44 ——– d—–w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2012-12-10 17:07:44 ——– d—–w- C:\Program Files\iTunes 2012-12-10 17:07:44 ——– d—–w- C:\Program Files (x86)\iTunes . ==================== Find3M ==================== . 2012-12-12 02:11:51 73656 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-12-12 02:11:51 697272 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-11-14 06:11:44 2312704 —-a-w- C:\Windows\System32\jscript9.dll 2012-11-14 06:04:11 1392128 —-a-w- C:\Windows\System32\wininet.dll 2012-11-14 06:02:49 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl 2012-11-14 05:57:46 599040 —-a-w- C:\Windows\System32\vbscript.dll 2012-11-14 05:57:35 173056 —-a-w- C:\Windows\System32\ieUnatt.exe 2012-11-14 05:52:40 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2012-11-14 02:09:22 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll 2012-11-14 01:58:15 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2012-11-14 01:57:37 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll 2012-11-14 01:49:25 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe 2012-11-14 01:48:27 420864 —-a-w- C:\Windows\SysWow64\vbscript.dll 2012-11-14 01:44:42 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2012-11-08 13:28:02 30568 —-a-w- C:\Windows\System32\drivers\avgtpx64.sys 2012-11-02 05:59:11 478208 —-a-w- C:\Windows\System32\dpnet.dll 2012-11-02 05:11:31 376832 —-a-w- C:\Windows\SysWow64\dpnet.dll 2012-10-30 23:51:55 984144 —-a-w- C:\Windows\System32\drivers\aswSnx.sys 2012-10-30 23:51:55 71600 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys 2012-10-30 23:51:07 41224 —-a-w- C:\Windows\avastSS.scr 2012-10-16 08:38:37 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll 2012-10-16 08:38:34 350208 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll 2012-10-16 07:39:52 561664 —-a-w- C:\Windows\apppatch\AcLayers.dll 2012-10-15 16:59:28 54072 —-a-w- C:\Windows\System32\drivers\aswRdr2.sys 2012-10-09 18:17:13 55296 —-a-w- C:\Windows\System32\dhcpcsvc6.dll 2012-10-09 18:17:13 226816 —-a-w- C:\Windows\System32\dhcpcore6.dll 2012-10-09 17:40:31 44032 —-a-w- C:\Windows\SysWow64\dhcpcsvc6.dll 2012-10-09 17:40:31 193536 —-a-w- C:\Windows\SysWow64\dhcpcore6.dll . ============= FINISH: 20:49:03.58 ===============
I ran tdsskiller. No issues were found and no reboot was required. Here is the log file ===================== 20:54:09.0942 1804 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35 20:54:10.0286 1804 ============================================================ 20:54:10.0286 1804 Current date / time: 2013/01/04 20:54:10.0286 20:54:10.0286 1804 SystemInfo: 20:54:10.0286 1804 20:54:10.0286 1804 OS Version: 6.1.7601 ServicePack: 1.0 20:54:10.0286 1804 Product type: Workstation 20:54:10.0286 1804 ComputerName: BUSAFAMILY-HP 20:54:10.0286 1804 UserName: Busa Family 20:54:10.0286 1804 Windows directory: C:\Windows 20:54:10.0286 1804 System windows directory: C:\Windows 20:54:10.0286 1804 Running under WOW64 20:54:10.0286 1804 Processor architecture: Intel x64 20:54:10.0286 1804 Number of processors: 2 20:54:10.0286 1804 Page size: 0x1000 20:54:10.0286 1804 Boot type: Safe boot with network 20:54:10.0286 1804 ============================================================ 20:54:11.0300 1804 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 20:54:11.0300 1804 Drive \Device\Harddisk1\DR1 - Size: 0x15D50D00000 (1397.26 Gb), SectorSize: 0x200, Cylinders: 0x2C881, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 20:54:18.0507 1804 ============================================================ 20:54:18.0507 1804 \Device\Harddisk0\DR0: 20:54:18.0507 1804 MBR partitions: 20:54:18.0507 1804 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 20:54:18.0507 1804 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x38946800 20:54:18.0507 1804 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x38979000, BlocksNum 0x1A0C800 20:54:18.0507 1804 \Device\Harddisk1\DR1: 20:54:18.0507 1804 MBR partitions: 20:54:18.0507 1804 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xAEA86000 20:54:18.0507 1804 ============================================================ 20:54:18.0538 1804 C: <-> \Device\Harddisk0\DR0\Partition2 20:54:18.0585 1804 D: <-> \Device\Harddisk0\DR0\Partition3 20:54:18.0616 1804 F: <-> \Device\Harddisk1\DR1\Partition1 20:54:18.0616 1804 ============================================================ 20:54:18.0616 1804 Initialize success 20:54:18.0616 1804 ============================================================ 20:54:20.0098 1872 ============================================================ 20:54:20.0098 1872 Scan started 20:54:20.0098 1872 Mode: Manual; 20:54:20.0098 1872 ============================================================ 20:54:20.0426 1872 ================ Scan system memory ======================== 20:54:20.0426 1872 System memory - ok 20:54:20.0441 1872 ================ Scan services ============================= 20:54:20.0566 1872 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 20:54:20.0566 1872 1394ohci - ok 20:54:20.0597 1872 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 20:54:20.0597 1872 ACPI - ok 20:54:20.0613 1872 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 20:54:20.0613 1872 AcpiPmi - ok 20:54:20.0722 1872 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 20:54:20.0722 1872 AdobeARMservice - ok 20:54:20.0816 1872 [ 95CE557D16A75606CCC2D7F3B0B0BCCB ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 20:54:20.0816 1872 AdobeFlashPlayerUpdateSvc - ok 20:54:20.0847 1872 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 20:54:20.0847 1872 adp94xx - ok 20:54:20.0878 1872 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 20:54:20.0894 1872 adpahci - ok 20:54:20.0894 1872 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 20:54:20.0894 1872 adpu320 - ok 20:54:20.0925 1872 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 20:54:20.0925 1872 AeLookupSvc - ok 20:54:20.0972 1872 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 20:54:20.0972 1872 AFD - ok 20:54:21.0003 1872 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 20:54:21.0018 1872 agp440 - ok 20:54:21.0050 1872 AirPrint - ok 20:54:21.0081 1872 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 20:54:21.0081 1872 ALG - ok 20:54:21.0096 1872 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 20:54:21.0096 1872 aliide - ok 20:54:21.0112 1872 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 20:54:21.0112 1872 amdide - ok 20:54:21.0143 1872 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 20:54:21.0143 1872 AmdK8 - ok 20:54:21.0159 1872 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 20:54:21.0159 1872 AmdPPM - ok 20:54:21.0190 1872 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 20:54:21.0190 1872 amdsata - ok 20:54:21.0206 1872 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 20:54:21.0206 1872 amdsbs - ok 20:54:21.0206 1872 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 20:54:21.0206 1872 amdxata - ok 20:54:21.0252 1872 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 20:54:21.0252 1872 AppID - ok 20:54:21.0284 1872 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 20:54:21.0284 1872 AppIDSvc - ok 20:54:21.0315 1872 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll 20:54:21.0315 1872 Appinfo - ok 20:54:21.0362 1872 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 20:54:21.0362 1872 Apple Mobile Device - ok 20:54:21.0393 1872 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys 20:54:21.0393 1872 arc - ok 20:54:21.0393 1872 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 20:54:21.0393 1872 arcsas - ok 20:54:21.0502 1872 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 20:54:21.0502 1872 aspnet_state - ok 20:54:21.0518 1872 [ 4FCAEF0C5BE7629AEB878998E0FE959B ] aswFsBlk C:\Windows\system32\drivers\aswFsBlk.sys 20:54:21.0518 1872 aswFsBlk - ok 20:54:21.0533 1872 [ B50CDD87772D6A11CB90924AAD399DF8 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys 20:54:21.0533 1872 aswMonFlt - ok 20:54:21.0564 1872 [ 57768C7DB4681F2510F247F82EF31D4F ] aswRdr C:\Windows\System32\Drivers\aswrdr2.sys 20:54:21.0564 1872 aswRdr - ok 20:54:21.0596 1872 [ E71D826A1F3CE9C9DE3E77F2D02AFFBF ] aswSnx C:\Windows\system32\drivers\aswSnx.sys 20:54:21.0611 1872 aswSnx - ok 20:54:21.0627 1872 [ 538A32E2C99BF073D4CA76C30BEDAA60 ] aswSP C:\Windows\system32\drivers\aswSP.sys 20:54:21.0627 1872 aswSP - ok 20:54:21.0642 1872 [ 6EDC79D73745FD44C41B55B2D13D0B70 ] aswTdi C:\Windows\system32\drivers\aswTdi.sys 20:54:21.0642 1872 aswTdi - ok 20:54:21.0658 1872 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 20:54:21.0658 1872 AsyncMac - ok 20:54:21.0720 1872 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 20:54:21.0720 1872 atapi - ok 20:54:21.0767 1872 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 20:54:21.0767 1872 AudioEndpointBuilder - ok 20:54:21.0783 1872 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 20:54:21.0783 1872 AudioSrv - ok 20:54:21.0830 1872 [ 8FA553E9AE69808D99C164733A0F9590 ] avast! Antivirus C:\Program Files\Alwil Software\Avast5\AvastSvc.exe 20:54:21.0830 1872 avast! Antivirus - ok 20:54:21.0876 1872 [ 371428CF0F71934CB0F2344823ADFA32 ] avgtp C:\Windows\system32\drivers\avgtpx64.sys 20:54:21.0876 1872 avgtp - ok 20:54:21.0923 1872 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 20:54:21.0923 1872 AxInstSV - ok 20:54:21.0954 1872 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys 20:54:21.0954 1872 b06bdrv - ok 20:54:21.0986 1872 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 20:54:21.0986 1872 b57nd60a - ok 20:54:22.0032 1872 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 20:54:22.0032 1872 BDESVC - ok 20:54:22.0048 1872 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 20:54:22.0048 1872 Beep - ok 20:54:22.0095 1872 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll 20:54:22.0095 1872 BFE - ok 20:54:22.0142 1872 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll 20:54:22.0142 1872 BITS - ok 20:54:22.0173 1872 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 20:54:22.0173 1872 blbdrive - ok 20:54:22.0220 1872 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 20:54:22.0235 1872 Bonjour Service - ok 20:54:22.0266 1872 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 20:54:22.0266 1872 bowser - ok 20:54:22.0298 1872 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 20:54:22.0298 1872 BrFiltLo - ok 20:54:22.0298 1872 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 20:54:22.0298 1872 BrFiltUp - ok 20:54:22.0344 1872 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 20:54:22.0344 1872 Browser - ok 20:54:22.0360 1872 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 20:54:22.0360 1872 Brserid - ok 20:54:22.0376 1872 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 20:54:22.0376 1872 BrSerWdm - ok 20:54:22.0391 1872 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 20:54:22.0391 1872 BrUsbMdm - ok 20:54:22.0407 1872 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 20:54:22.0422 1872 BrUsbSer - ok 20:54:22.0422 1872 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 20:54:22.0422 1872 BTHMODEM - ok 20:54:22.0454 1872 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 20:54:22.0454 1872 bthserv - ok 20:54:22.0469 1872 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 20:54:22.0469 1872 cdfs - ok 20:54:22.0516 1872 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\drivers\cdrom.sys 20:54:22.0532 1872 cdrom - ok 20:54:22.0563 1872 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 20:54:22.0563 1872 CertPropSvc - ok 20:54:22.0594 1872 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys 20:54:22.0594 1872 circlass - ok 20:54:22.0625 1872 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 20:54:22.0625 1872 CLFS - ok 20:54:22.0672 1872 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 20:54:22.0672 1872 clr_optimization_v2.0.50727_32 - ok 20:54:22.0719 1872 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 20:54:22.0719 1872 clr_optimization_v2.0.50727_64 - ok 20:54:22.0797 1872 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 20:54:22.0797 1872 clr_optimization_v4.0.30319_32 - ok 20:54:22.0812 1872 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 20:54:22.0812 1872 clr_optimization_v4.0.30319_64 - ok 20:54:22.0844 1872 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 20:54:22.0844 1872 CmBatt - ok 20:54:22.0859 1872 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 20:54:22.0859 1872 cmdide - ok 20:54:22.0906 1872 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 20:54:22.0906 1872 CNG - ok 20:54:22.0922 1872 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 20:54:22.0922 1872 Compbatt - ok 20:54:22.0953 1872 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 20:54:22.0953 1872 CompositeBus - ok 20:54:22.0953 1872 COMSysApp - ok 20:54:22.0984 1872 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 20:54:22.0984 1872 crcdisk - ok 20:54:23.0015 1872 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll 20:54:23.0015 1872 CryptSvc - ok 20:54:23.0093 1872 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE 20:54:23.0093 1872 cvhsvc - ok 20:54:23.0140 1872 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 20:54:23.0156 1872 DcomLaunch - ok 20:54:23.0171 1872 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 20:54:23.0171 1872 defragsvc - ok 20:54:23.0218 1872 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 20:54:23.0218 1872 DfsC - ok 20:54:23.0265 1872 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 20:54:23.0265 1872 Dhcp - ok 20:54:23.0296 1872 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 20:54:23.0296 1872 discache - ok 20:54:23.0312 1872 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys 20:54:23.0312 1872 Disk - ok 20:54:23.0343 1872 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 20:54:23.0343 1872 Dnscache - ok 20:54:23.0374 1872 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 20:54:23.0374 1872 dot3svc - ok 20:54:23.0421 1872 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 20:54:23.0421 1872 DPS - ok 20:54:23.0452 1872 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 20:54:23.0452 1872 drmkaud - ok 20:54:23.0514 1872 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 20:54:23.0514 1872 DXGKrnl - ok 20:54:23.0530 1872 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 20:54:23.0546 1872 EapHost - ok 20:54:23.0592 1872 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys 20:54:23.0624 1872 ebdrv - ok 20:54:23.0655 1872 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 20:54:23.0655 1872 EFS - ok 20:54:23.0702 1872 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 20:54:23.0702 1872 ehRecvr - ok 20:54:23.0733 1872 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 20:54:23.0733 1872 ehSched - ok 20:54:23.0764 1872 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 20:54:23.0764 1872 elxstor - ok 20:54:23.0795 1872 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 20:54:23.0795 1872 ErrDev - ok 20:54:23.0842 1872 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 20:54:23.0842 1872 EventSystem - ok 20:54:23.0858 1872 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 20:54:23.0858 1872 exfat - ok 20:54:23.0873 1872 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 20:54:23.0889 1872 fastfat - ok 20:54:23.0920 1872 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 20:54:23.0936 1872 Fax - ok 20:54:23.0951 1872 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys 20:54:23.0951 1872 fdc - ok 20:54:23.0982 1872 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 20:54:23.0982 1872 fdPHost - ok 20:54:23.0998 1872 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 20:54:24.0014 1872 FDResPub - ok 20:54:24.0029 1872 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 20:54:24.0029 1872 FileInfo - ok 20:54:24.0029 1872 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 20:54:24.0029 1872 Filetrace - ok 20:54:24.0045 1872 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 20:54:24.0045 1872 flpydisk - ok 20:54:24.0092 1872 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 20:54:24.0107 1872 FltMgr - ok 20:54:24.0123 1872 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll 20:54:24.0138 1872 FontCache - ok 20:54:24.0185 1872 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 20:54:24.0185 1872 FontCache3.0.0.0 - ok 20:54:24.0263 1872 [ B60DF5324D7EA0C8017F4C5331962D59 ] ForceWare Intelligent Application Manager (IAM) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe 20:54:24.0263 1872 ForceWare Intelligent Application Manager (IAM) - ok 20:54:24.0279 1872 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 20:54:24.0279 1872 FsDepends - ok 20:54:24.0310 1872 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 20:54:24.0310 1872 Fs_Rec - ok 20:54:24.0357 1872 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 20:54:24.0372 1872 fvevol - ok 20:54:24.0372 1872 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 20:54:24.0372 1872 gagp30kx - ok 20:54:24.0435 1872 [ C403C5DB49A0F9AAF4F2128EDC0106D8 ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe 20:54:24.0435 1872 GamesAppService - ok 20:54:24.0482 1872 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 20:54:24.0482 1872 GEARAspiWDM - ok 20:54:24.0528 1872 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 20:54:24.0528 1872 gpsvc - ok 20:54:24.0638 1872 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 20:54:24.0638 1872 gupdate - ok 20:54:24.0653 1872 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 20:54:24.0669 1872 gupdatem - ok 20:54:24.0684 1872 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 20:54:24.0684 1872 hcw85cir - ok 20:54:24.0731 1872 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 20:54:24.0747 1872 HdAudAddService - ok 20:54:24.0762 1872 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 20:54:24.0762 1872 HDAudBus - ok 20:54:24.0778 1872 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 20:54:24.0778 1872 HidBatt - ok 20:54:24.0794 1872 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 20:54:24.0794 1872 HidBth - ok 20:54:24.0809 1872 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 20:54:24.0809 1872 HidIr - ok 20:54:24.0840 1872 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll 20:54:24.0840 1872 hidserv - ok 20:54:24.0887 1872 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\drivers\hidusb.sys 20:54:24.0887 1872 HidUsb - ok 20:54:24.0918 1872 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 20:54:24.0918 1872 hkmsvc - ok 20:54:24.0950 1872 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 20:54:24.0965 1872 HomeGroupListener - ok 20:54:24.0996 1872 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 20:54:24.0996 1872 HomeGroupProvider - ok 20:54:25.0028 1872 HP Support Assistant Service - ok 20:54:25.0074 1872 [ 3DC11A802353401332D49C3CBFBBE5FC ] HPClientSvc C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe 20:54:25.0090 1872 HPClientSvc - ok 20:54:25.0106 1872 hpqwmiex - ok 20:54:25.0137 1872 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 20:54:25.0137 1872 HpSAMD - ok 20:54:25.0184 1872 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 20:54:25.0199 1872 HTTP - ok 20:54:25.0230 1872 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 20:54:25.0230 1872 hwpolicy - ok 20:54:25.0277 1872 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 20:54:25.0277 1872 i8042prt - ok 20:54:25.0308 1872 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 20:54:25.0324 1872 iaStorV - ok 20:54:25.0371 1872 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 20:54:25.0371 1872 idsvc - ok 20:54:25.0402 1872 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 20:54:25.0402 1872 iirsp - ok 20:54:25.0449 1872 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 20:54:25.0449 1872 IKEEXT - ok 20:54:25.0511 1872 [ 3C4B4EE54FEBB09F7E9F58776DE96DCA ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys 20:54:25.0527 1872 IntcAzAudAddService - ok 20:54:25.0558 1872 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 20:54:25.0558 1872 intelide - ok 20:54:25.0589 1872 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 20:54:25.0605 1872 intelppm - ok 20:54:25.0683 1872 [ 3DC635B66DD7412E1C9C3A77B8D78F25 ] IntuitUpdateService C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe 20:54:25.0683 1872 IntuitUpdateService - ok 20:54:25.0761 1872 [ 1663A135865F0BA6E853353E98E67F2A ] IntuitUpdateServiceV4 C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe 20:54:25.0776 1872 IntuitUpdateServiceV4 - ok 20:54:25.0792 1872 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 20:54:25.0792 1872 IPBusEnum - ok 20:54:25.0823 1872 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 20:54:25.0823 1872 IpFilterDriver - ok 20:54:25.0870 1872 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 20:54:25.0870 1872 iphlpsvc - ok 20:54:25.0901 1872 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 20:54:25.0917 1872 IPMIDRV - ok 20:54:25.0932 1872 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 20:54:25.0932 1872 IPNAT - ok 20:54:26.0010 1872 [ B474C756C13960793C7583B766F904C4 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 20:54:26.0010 1872 iPod Service - ok 20:54:26.0026 1872 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 20:54:26.0026 1872 IRENUM - ok 20:54:26.0042 1872 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 20:54:26.0042 1872 isapnp - ok 20:54:26.0073 1872 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 20:54:26.0073 1872 iScsiPrt - ok 20:54:26.0088 1872 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys 20:54:26.0088 1872 kbdclass - ok 20:54:26.0104 1872 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys 20:54:26.0104 1872 kbdhid - ok 20:54:26.0120 1872 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 20:54:26.0120 1872 KeyIso - ok 20:54:26.0151 1872 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 20:54:26.0151 1872 KSecDD - ok 20:54:26.0182 1872 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 20:54:26.0198 1872 KSecPkg - ok 20:54:26.0213 1872 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 20:54:26.0213 1872 ksthunk - ok 20:54:26.0244 1872 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 20:54:26.0244 1872 KtmRm - ok 20:54:26.0307 1872 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll 20:54:26.0307 1872 LanmanServer - ok 20:54:26.0338 1872 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 20:54:26.0338 1872 LanmanWorkstation - ok 20:54:26.0369 1872 [ FA4A45C179AB0E0F1A31B9751D4B18D7 ] LightScribeService c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe 20:54:26.0369 1872 LightScribeService - ok 20:54:26.0400 1872 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 20:54:26.0400 1872 lltdio - ok 20:54:26.0416 1872 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 20:54:26.0432 1872 lltdsvc - ok 20:54:26.0432 1872 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 20:54:26.0447 1872 lmhosts - ok 20:54:26.0463 1872 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 20:54:26.0463 1872 LSI_FC - ok 20:54:26.0494 1872 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 20:54:26.0494 1872 LSI_SAS - ok 20:54:26.0510 1872 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 20:54:26.0510 1872 LSI_SAS2 - ok 20:54:26.0525 1872 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 20:54:26.0525 1872 LSI_SCSI - ok 20:54:26.0541 1872 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 20:54:26.0541 1872 luafv - ok 20:54:26.0572 1872 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 20:54:26.0572 1872 Mcx2Svc - ok 20:54:26.0588 1872 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 20:54:26.0588 1872 megasas - ok 20:54:26.0603 1872 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 20:54:26.0603 1872 MegaSR - ok 20:54:26.0634 1872 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 20:54:26.0634 1872 MMCSS - ok 20:54:26.0650 1872 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 20:54:26.0650 1872 Modem - ok 20:54:26.0666 1872 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 20:54:26.0666 1872 monitor - ok 20:54:26.0697 1872 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\drivers\mouclass.sys 20:54:26.0697 1872 mouclass - ok 20:54:26.0728 1872 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 20:54:26.0728 1872 mouhid - ok 20:54:26.0759 1872 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 20:54:26.0759 1872 mountmgr - ok 20:54:26.0837 1872 [ 8C7336950F1E69CDFD811CBBD9CF00A2 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 20:54:26.0837 1872 MozillaMaintenance - ok 20:54:26.0868 1872 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 20:54:26.0868 1872 mpio - ok 20:54:26.0900 1872 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 20:54:26.0900 1872 mpsdrv - ok 20:54:26.0946 1872 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll 20:54:26.0946 1872 MpsSvc - ok 20:54:26.0993 1872 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 20:54:26.0993 1872 MRxDAV - ok 20:54:27.0024 1872 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 20:54:27.0024 1872 mrxsmb - ok 20:54:27.0056 1872 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 20:54:27.0056 1872 mrxsmb10 - ok 20:54:27.0071 1872 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 20:54:27.0071 1872 mrxsmb20 - ok 20:54:27.0118 1872 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 20:54:27.0118 1872 msahci - ok 20:54:27.0134 1872 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 20:54:27.0134 1872 msdsm - ok 20:54:27.0149 1872 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 20:54:27.0149 1872 MSDTC - ok 20:54:27.0165 1872 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 20:54:27.0165 1872 Msfs - ok 20:54:27.0196 1872 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 20:54:27.0196 1872 mshidkmdf - ok 20:54:27.0227 1872 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 20:54:27.0227 1872 msisadrv - ok 20:54:27.0243 1872 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 20:54:27.0243 1872 MSiSCSI - ok 20:54:27.0243 1872 msiserver - ok 20:54:27.0274 1872 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 20:54:27.0274 1872 MSKSSRV - ok 20:54:27.0290 1872 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 20:54:27.0290 1872 MSPCLOCK - ok 20:54:27.0305 1872 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 20:54:27.0305 1872 MSPQM - ok 20:54:27.0336 1872 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 20:54:27.0336 1872 MsRPC - ok 20:54:27.0368 1872 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 20:54:27.0368 1872 mssmbios - ok 20:54:27.0399 1872 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 20:54:27.0399 1872 MSTEE - ok 20:54:27.0399 1872 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 20:54:27.0414 1872 MTConfig - ok 20:54:27.0430 1872 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 20:54:27.0430 1872 Mup - ok 20:54:27.0477 1872 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 20:54:27.0477 1872 napagent - ok 20:54:27.0524 1872 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 20:54:27.0524 1872 NativeWifiP - ok 20:54:27.0586 1872 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys 20:54:27.0586 1872 NDIS - ok 20:54:27.0617 1872 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 20:54:27.0617 1872 NdisCap - ok 20:54:27.0633 1872 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 20:54:27.0633 1872 NdisTapi - ok 20:54:27.0664 1872 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 20:54:27.0664 1872 Ndisuio - ok 20:54:27.0695 1872 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 20:54:27.0695 1872 NdisWan - ok 20:54:27.0726 1872 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 20:54:27.0726 1872 NDProxy - ok 20:54:27.0742 1872 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 20:54:27.0742 1872 NetBIOS - ok 20:54:27.0789 1872 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 20:54:27.0789 1872 NetBT - ok 20:54:27.0789 1872 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 20:54:27.0789 1872 Netlogon - ok 20:54:27.0820 1872 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 20:54:27.0836 1872 Netman - ok 20:54:27.0882 1872 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 20:54:27.0882 1872 NetMsmqActivator - ok 20:54:27.0898 1872 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 20:54:27.0898 1872 NetPipeActivator - ok 20:54:27.0914 1872 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 20:54:27.0914 1872 netprofm - ok 20:54:27.0960 1872 [ 1982B291DF9833FB3ADC397EBD310A18 ] netr28x C:\Windows\system32\DRIVERS\netr28x.sys 20:54:27.0960 1872 netr28x - ok 20:54:27.0976 1872 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 20:54:27.0976 1872 NetTcpActivator - ok 20:54:27.0976 1872 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 20:54:27.0976 1872 NetTcpPortSharing - ok 20:54:28.0007 1872 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 20:54:28.0007 1872 nfrd960 - ok 20:54:28.0038 1872 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll 20:54:28.0038 1872 NlaSvc - ok 20:54:28.0054 1872 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 20:54:28.0054 1872 Npfs - ok 20:54:28.0085 1872 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 20:54:28.0085 1872 nsi - ok 20:54:28.0085 1872 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 20:54:28.0085 1872 nsiproxy - ok 20:54:28.0101 1872 [ 6324EEF641C2B6D1B7EC423850B10F82 ] nSvcIp C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe 20:54:28.0101 1872 nSvcIp - ok 20:54:28.0163 1872 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 20:54:28.0179 1872 Ntfs - ok 20:54:28.0194 1872 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 20:54:28.0194 1872 Null - ok 20:54:28.0382 1872 [ C967514483FA30A0A352E70BB6414D1D ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 20:54:28.0553 1872 nvlddmkm - ok 20:54:28.0584 1872 [ BD25E03EAD63AC3365F25175B4DBD56A ] NVNET C:\Windows\system32\DRIVERS\nvmf6264.sys 20:54:28.0584 1872 NVNET - ok 20:54:28.0616 1872 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 20:54:28.0616 1872 nvraid - ok 20:54:28.0662 1872 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 20:54:28.0662 1872 nvstor - ok 20:54:28.0678 1872 [ 1E45F96342429D63DC30E0D9117DA3D8 ] nvstor64 C:\Windows\system32\DRIVERS\nvstor64.sys 20:54:28.0678 1872 nvstor64 - ok 20:54:28.0709 1872 [ E26706A65D97EF9188B1D7BFA23C96C2 ] nvsvc C:\Windows\system32\nvvsvc.exe 20:54:28.0709 1872 nvsvc - ok 20:54:28.0756 1872 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 20:54:28.0756 1872 nv_agp - ok 20:54:28.0772 1872 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 20:54:28.0772 1872 ohci1394 - ok 20:54:28.0803 1872 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 20:54:28.0803 1872 ose - ok 20:54:28.0912 1872 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 20:54:28.0959 1872 osppsvc - ok 20:54:28.0974 1872 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 20:54:28.0974 1872 p2pimsvc - ok 20:54:29.0006 1872 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 20:54:29.0006 1872 p2psvc - ok 20:54:29.0037 1872 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys 20:54:29.0037 1872 Parport - ok 20:54:29.0068 1872 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 20:54:29.0068 1872 partmgr - ok 20:54:29.0084 1872 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 20:54:29.0084 1872 PcaSvc - ok 20:54:29.0115 1872 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 20:54:29.0115 1872 pci - ok 20:54:29.0146 1872 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 20:54:29.0146 1872 pciide - ok 20:54:29.0162 1872 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 20:54:29.0162 1872 pcmcia - ok 20:54:29.0177 1872 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 20:54:29.0177 1872 pcw - ok 20:54:29.0208 1872 pdfcDispatcher - ok 20:54:29.0224 1872 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 20:54:29.0224 1872 PEAUTH - ok 20:54:29.0286 1872 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 20:54:29.0286 1872 PerfHost - ok 20:54:29.0349 1872 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 20:54:29.0364 1872 pla - ok 20:54:29.0396 1872 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 20:54:29.0411 1872 PlugPlay - ok 20:54:29.0427 1872 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 20:54:29.0427 1872 PNRPAutoReg - ok 20:54:29.0442 1872 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 20:54:29.0442 1872 PNRPsvc - ok 20:54:29.0489 1872 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 20:54:29.0489 1872 PolicyAgent - ok 20:54:29.0520 1872 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 20:54:29.0520 1872 Power - ok 20:54:29.0552 1872 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 20:54:29.0567 1872 PptpMiniport - ok 20:54:29.0583 1872 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys 20:54:29.0583 1872 Processor - ok 20:54:29.0630 1872 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 20:54:29.0630 1872 ProfSvc - ok 20:54:29.0645 1872 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 20:54:29.0645 1872 ProtectedStorage - ok 20:54:29.0676 1872 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 20:54:29.0676 1872 Psched - ok 20:54:29.0708 1872 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 20:54:29.0723 1872 ql2300 - ok 20:54:29.0739 1872 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 20:54:29.0739 1872 ql40xx - ok 20:54:29.0770 1872 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 20:54:29.0770 1872 QWAVE - ok 20:54:29.0786 1872 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 20:54:29.0786 1872 QWAVEdrv - ok 20:54:29.0801 1872 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 20:54:29.0801 1872 RasAcd - ok 20:54:29.0817 1872 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 20:54:29.0817 1872 RasAgileVpn - ok 20:54:29.0832 1872 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 20:54:29.0832 1872 RasAuto - ok 20:54:29.0864 1872 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 20:54:29.0864 1872 Rasl2tp - ok 20:54:29.0895 1872 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 20:54:29.0910 1872 RasMan - ok 20:54:29.0926 1872 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 20:54:29.0926 1872 RasPppoe - ok 20:54:29.0942 1872 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 20:54:29.0942 1872 RasSstp - ok 20:54:29.0957 1872 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 20:54:29.0973 1872 rdbss - ok 20:54:29.0973 1872 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 20:54:29.0973 1872 rdpbus - ok 20:54:29.0988 1872 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 20:54:29.0988 1872 RDPCDD - ok 20:54:30.0020 1872 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 20:54:30.0020 1872 RDPENCDD - ok 20:54:30.0035 1872 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 20:54:30.0035 1872 RDPREFMP - ok 20:54:30.0082 1872 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 20:54:30.0082 1872 RDPWD - ok 20:54:30.0113 1872 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 20:54:30.0113 1872 rdyboost - ok 20:54:30.0144 1872 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 20:54:30.0144 1872 RemoteAccess - ok 20:54:30.0160 1872 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 20:54:30.0160 1872 RemoteRegistry - ok 20:54:30.0191 1872 [ C1568E17039B2EC2B73A4F880DDD51E5 ] RoxioNow Service C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe 20:54:30.0207 1872 RoxioNow Service - ok 20:54:30.0222 1872 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 20:54:30.0222 1872 RpcEptMapper - ok 20:54:30.0238 1872 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 20:54:30.0238 1872 RpcLocator - ok 20:54:30.0285 1872 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll 20:54:30.0285 1872 RpcSs - ok 20:54:30.0316 1872 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 20:54:30.0316 1872 rspndr - ok 20:54:30.0332 1872 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 20:54:30.0332 1872 SamSs - ok 20:54:30.0363 1872 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 20:54:30.0363 1872 sbp2port - ok 20:54:30.0378 1872 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 20:54:30.0378 1872 SCardSvr - ok 20:54:30.0410 1872 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 20:54:30.0410 1872 scfilter - ok 20:54:30.0472 1872 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 20:54:30.0472 1872 Schedule - ok 20:54:30.0503 1872 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 20:54:30.0503 1872 SCPolicySvc - ok 20:54:30.0534 1872 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 20:54:30.0534 1872 SDRSVC - ok 20:54:30.0566 1872 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 20:54:30.0566 1872 secdrv - ok 20:54:30.0566 1872 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 20:54:30.0566 1872 seclogon - ok 20:54:30.0581 1872 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll 20:54:30.0581 1872 SENS - ok 20:54:30.0597 1872 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 20:54:30.0597 1872 SensrSvc - ok 20:54:30.0628 1872 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 20:54:30.0628 1872 Serenum - ok 20:54:30.0644 1872 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys 20:54:30.0644 1872 Serial - ok 20:54:30.0659 1872 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 20:54:30.0659 1872 sermouse - ok 20:54:30.0690 1872 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 20:54:30.0690 1872 SessionEnv - ok 20:54:30.0722 1872 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 20:54:30.0722 1872 sffdisk - ok 20:54:30.0737 1872 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 20:54:30.0737 1872 sffp_mmc - ok 20:54:30.0753 1872 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 20:54:30.0753 1872 sffp_sd - ok 20:54:30.0768 1872 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 20:54:30.0768 1872 sfloppy - ok 20:54:30.0831 1872 [ C6CC9297BD53E5229653303E556AA539 ] Sftfs C:\Windows\system32\DRIVERS\Sftfslh.sys 20:54:30.0831 1872 Sftfs - ok 20:54:30.0862 1872 [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe 20:54:30.0878 1872 sftlist - ok 20:54:30.0878 1872 [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay C:\Windows\system32\DRIVERS\Sftplaylh.sys 20:54:30.0893 1872 Sftplay - ok 20:54:30.0893 1872 [ 617E29A0B0A2807466560D4C4E338D3E ] Sftredir C:\Windows\system32\DRIVERS\Sftredirlh.sys 20:54:30.0893 1872 Sftredir - ok 20:54:30.0924 1872 [ 8F571F016FA1976F445147E9E6C8AE9B ] Sftvol C:\Windows\system32\DRIVERS\Sftvollh.sys 20:54:30.0924 1872 Sftvol - ok 20:54:30.0940 1872 [ C3CDDD18F43D44AB713CF8C4916F7696 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe 20:54:30.0940 1872 sftvsa - ok 20:54:30.0971 1872 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll 20:54:30.0987 1872 SharedAccess - ok 20:54:31.0034 1872 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 20:54:31.0034 1872 ShellHWDetection - ok 20:54:31.0049 1872 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 20:54:31.0049 1872 SiSRaid2 - ok 20:54:31.0065 1872 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 20:54:31.0065 1872 SiSRaid4 - ok 20:54:31.0080 1872 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 20:54:31.0080 1872 Smb - ok 20:54:31.0112 1872 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 20:54:31.0112 1872 SNMPTRAP - ok 20:54:31.0127 1872 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 20:54:31.0127 1872 spldr - ok 20:54:31.0174 1872 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 20:54:31.0174 1872 Spooler - ok 20:54:31.0252 1872 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 20:54:31.0283 1872 sppsvc - ok 20:54:31.0299 1872 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 20:54:31.0299 1872 sppuinotify - ok 20:54:31.0330 1872 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 20:54:31.0346 1872 srv - ok 20:54:31.0361 1872 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 20:54:31.0361 1872 srv2 - ok 20:54:31.0377 1872 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 20:54:31.0377 1872 srvnet - ok 20:54:31.0424 1872 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 20:54:31.0424 1872 SSDPSRV - ok 20:54:31.0439 1872 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 20:54:31.0439 1872 SstpSvc - ok 20:54:31.0455 1872 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 20:54:31.0455 1872 stexstor - ok 20:54:31.0502 1872 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 20:54:31.0517 1872 stisvc - ok 20:54:31.0548 1872 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys 20:54:31.0548 1872 swenum - ok 20:54:31.0580 1872 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 20:54:31.0580 1872 swprv - ok 20:54:31.0626 1872 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 20:54:31.0642 1872 SysMain - ok 20:54:31.0673 1872 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 20:54:31.0689 1872 TabletInputService - ok 20:54:31.0720 1872 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 20:54:31.0720 1872 TapiSrv - ok 20:54:31.0736 1872 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 20:54:31.0736 1872 TBS - ok 20:54:31.0798 1872 [ 37608401DFDB388CAF66917F6B2D6FB0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 20:54:31.0814 1872 Tcpip - ok 20:54:31.0845 1872 [ 37608401DFDB388CAF66917F6B2D6FB0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 20:54:31.0845 1872 TCPIP6 - ok 20:54:31.0876 1872 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 20:54:31.0876 1872 tcpipreg - ok 20:54:31.0892 1872 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 20:54:31.0892 1872 TDPIPE - ok 20:54:31.0923 1872 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 20:54:31.0923 1872 TDTCP - ok 20:54:31.0970 1872 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 20:54:31.0970 1872 tdx - ok 20:54:32.0001 1872 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys 20:54:32.0001 1872 TermDD - ok 20:54:32.0016 1872 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 20:54:32.0016 1872 TermService - ok 20:54:32.0048 1872 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 20:54:32.0048 1872 Themes - ok 20:54:32.0063 1872 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 20:54:32.0063 1872 THREADORDER - ok 20:54:32.0079 1872 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 20:54:32.0079 1872 TrkWks - ok 20:54:32.0126 1872 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 20:54:32.0126 1872 TrustedInstaller - ok 20:54:32.0157 1872 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 20:54:32.0172 1872 tssecsrv - ok 20:54:32.0204 1872 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 20:54:32.0204 1872 TsUsbFlt - ok 20:54:32.0266 1872 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 20:54:32.0266 1872 tunnel - ok 20:54:32.0282 1872 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 20:54:32.0297 1872 uagp35 - ok 20:54:32.0328 1872 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 20:54:32.0328 1872 udfs - ok 20:54:32.0344 1872 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 20:54:32.0344 1872 UI0Detect - ok 20:54:32.0375 1872 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 20:54:32.0375 1872 uliagpkx - ok 20:54:32.0422 1872 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys 20:54:32.0422 1872 umbus - ok 20:54:32.0438 1872 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 20:54:32.0438 1872 UmPass - ok 20:54:32.0453 1872 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 20:54:32.0453 1872 upnphost - ok 20:54:32.0500 1872 [ 43228F8EDD1B0BCDD3145AD246E63D39 ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys 20:54:32.0500 1872 USBAAPL64 - ok 20:54:32.0516 1872 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 20:54:32.0516 1872 usbccgp - ok 20:54:32.0562 1872 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 20:54:32.0562 1872 usbcir - ok 20:54:32.0578 1872 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 20:54:32.0578 1872 usbehci - ok 20:54:32.0594 1872 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 20:54:32.0609 1872 usbhub - ok 20:54:32.0609 1872 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys 20:54:32.0609 1872 usbohci - ok 20:54:32.0640 1872 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 20:54:32.0640 1872 usbprint - ok 20:54:32.0656 1872 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 20:54:32.0656 1872 USBSTOR - ok 20:54:32.0672 1872 [ 81FB2216D3A60D1284455D511797DB3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 20:54:32.0672 1872 usbuhci - ok 20:54:32.0687 1872 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 20:54:32.0687 1872 UxSms - ok 20:54:32.0703 1872 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 20:54:32.0703 1872 VaultSvc - ok 20:54:32.0750 1872 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 20:54:32.0750 1872 vdrvroot - ok 20:54:32.0781 1872 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 20:54:32.0781 1872 vds - ok 20:54:32.0812 1872 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 20:54:32.0812 1872 vga - ok 20:54:32.0828 1872 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 20:54:32.0828 1872 VgaSave - ok 20:54:32.0843 1872 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 20:54:32.0843 1872 vhdmp - ok 20:54:32.0890 1872 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 20:54:32.0890 1872 viaide - ok 20:54:32.0906 1872 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 20:54:32.0906 1872 volmgr - ok 20:54:32.0937 1872 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 20:54:32.0952 1872 volmgrx - ok 20:54:32.0952 1872 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 20:54:32.0952 1872 volsnap - ok 20:54:32.0984 1872 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 20:54:32.0984 1872 vsmraid - ok 20:54:33.0030 1872 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 20:54:33.0046 1872 VSS - ok 20:54:33.0140 1872 [ 7D110D645030C05A06C3CD08D1E47D0A ] vToolbarUpdater13.2.0 C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe 20:54:33.0155 1872 vToolbarUpdater13.2.0 - ok 20:54:33.0171 1872 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 20:54:33.0171 1872 vwifibus - ok 20:54:33.0171 1872 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 20:54:33.0171 1872 vwififlt - ok 20:54:33.0202 1872 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys 20:54:33.0202 1872 vwifimp - ok 20:54:33.0218 1872 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 20:54:33.0218 1872 W32Time - ok 20:54:33.0249 1872 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 20:54:33.0249 1872 WacomPen - ok 20:54:33.0296 1872 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 20:54:33.0296 1872 WANARP - ok 20:54:33.0296 1872 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 20:54:33.0296 1872 Wanarpv6 - ok 20:54:33.0358 1872 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 20:54:33.0374 1872 WatAdminSvc - ok 20:54:33.0420 1872 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 20:54:33.0436 1872 wbengine - ok 20:54:33.0452 1872 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 20:54:33.0467 1872 WbioSrvc - ok 20:54:33.0498 1872 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 20:54:33.0498 1872 wcncsvc - ok 20:54:33.0514 1872 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 20:54:33.0514 1872 WcsPlugInService - ok 20:54:33.0530 1872 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys 20:54:33.0530 1872 Wd - ok 20:54:33.0576 1872 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 20:54:33.0576 1872 Wdf01000 - ok 20:54:33.0608 1872 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 20:54:33.0608 1872 WdiServiceHost - ok 20:54:33.0608 1872 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 20:54:33.0608 1872 WdiSystemHost - ok 20:54:33.0639 1872 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 20:54:33.0654 1872 WebClient - ok 20:54:33.0670 1872 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 20:54:33.0670 1872 Wecsvc - ok 20:54:33.0686 1872 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 20:54:33.0686 1872 wercplsupport - ok 20:54:33.0701 1872 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 20:54:33.0701 1872 WerSvc - ok 20:54:33.0732 1872 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 20:54:33.0732 1872 WfpLwf - ok 20:54:33.0748 1872 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 20:54:33.0748 1872 WIMMount - ok 20:54:33.0764 1872 WinDefend - ok 20:54:33.0764 1872 WinHttpAutoProxySvc - ok 20:54:33.0810 1872 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 20:54:33.0826 1872 Winmgmt - ok 20:54:33.0873 1872 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 20:54:33.0888 1872 WinRM - ok 20:54:33.0935 1872 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 20:54:33.0935 1872 WinUsb - ok 20:54:33.0966 1872 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 20:54:33.0982 1872 Wlansvc - ok 20:54:34.0044 1872 [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 20:54:34.0076 1872 wlidsvc - ok 20:54:34.0107 1872 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 20:54:34.0107 1872 WmiAcpi - ok 20:54:34.0122 1872 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 20:54:34.0122 1872 wmiApSrv - ok 20:54:34.0154 1872 WMPNetworkSvc - ok 20:54:34.0185 1872 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 20:54:34.0185 1872 WPCSvc - ok 20:54:34.0216 1872 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 20:54:34.0232 1872 WPDBusEnum - ok 20:54:34.0247 1872 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 20:54:34.0247 1872 ws2ifsl - ok 20:54:34.0263 1872 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll 20:54:34.0263 1872 wscsvc - ok 20:54:34.0263 1872 WSearch - ok 20:54:34.0325 1872 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 20:54:34.0341 1872 wuauserv - ok 20:54:34.0372 1872 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 20:54:34.0372 1872 WudfPf - ok 20:54:34.0419 1872 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 20:54:34.0419 1872 WUDFRd - ok 20:54:34.0434 1872 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 20:54:34.0434 1872 wudfsvc - ok 20:54:34.0450 1872 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll 20:54:34.0450 1872 WwanSvc - ok 20:54:34.0466 1872 ================ Scan global =============================== 20:54:34.0481 1872 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 20:54:34.0512 1872 [ 72CC564BBC70DE268784BCE91EB8A28F ] C:\Windows\system32\winsrv.dll 20:54:34.0528 1872 [ 72CC564BBC70DE268784BCE91EB8A28F ] C:\Windows\system32\winsrv.dll 20:54:34.0559 1872 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 20:54:34.0575 1872 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 20:54:34.0575 1872 [Global] - ok 20:54:34.0575 1872 ================ Scan MBR ================================== 20:54:34.0590 1872 [ 3BBE1D1AAA03783C009C815739064B34 ] \Device\Harddisk0\DR0 20:54:34.0809 1872 \Device\Harddisk0\DR0 - ok 20:54:34.0824 1872 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1 20:54:34.0824 1872 \Device\Harddisk1\DR1 - ok 20:54:34.0824 1872 ================ Scan VBR ================================== 20:54:34.0824 1872 [ A8E7A9B8997CCDC5BB03FEDC9C44474C ] \Device\Harddisk0\DR0\Partition1 20:54:34.0824 1872 \Device\Harddisk0\DR0\Partition1 - ok 20:54:34.0840 1872 [ 8EB97A4201E3042E68902ACB061A7422 ] \Device\Harddisk0\DR0\Partition2 20:54:34.0840 1872 \Device\Harddisk0\DR0\Partition2 - ok 20:54:34.0871 1872 [ 55555E00B612E7E9496E73A6044997BD ] \Device\Harddisk0\DR0\Partition3 20:54:34.0871 1872 \Device\Harddisk0\DR0\Partition3 - ok 20:54:34.0871 1872 [ 4E98B8268ECD120B872C0D04178DF844 ] \Device\Harddisk1\DR1\Partition1 20:54:34.0887 1872 \Device\Harddisk1\DR1\Partition1 - ok 20:54:34.0887 1872 ============================================================ 20:54:34.0887 1872 Scan finished 20:54:34.0887 1872 ============================================================ 20:54:34.0887 1240 Detected object count: 0 20:54:34.0887 1240 Actual detected object count: 0
You do have a couple of suspicious entries in your log so let's go ahead and run a tool to do a little deeper looking and removal of any items found. I can also see some remnants of what looks like AVG on your system, even though that is not your current antivirus. Those could be causing some conflicts in normal mode on the machine. This tool should remove those "orphaned" files. If not, we can manually remove them after this scan. Please be sure to tell me how the machine is running after this tool has run.

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing anything, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

If you have a problem launching programs after running Combofix, please do not panic! Simply reboot the computer and all should be fine.
Here is the combo fix log. I will reboot now and see if there are any changes in the computer symptoms ComboFix 13-01-04.03 - Busa Family 01/04/2013 21:17:31.1.2 - x64 NETWORK Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2815.2154 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\Mozilla Firefox\searchplugins\search.xml C:\Thumbs.db c:\users\Busa Family\AppData\Roaming\inst.exe c:\users\Busa Family\Documents\ShopToWin c:\windows\security\Database\tmp.edb F:\Autorun.inf . . ((((((((((((((((((((((((( Files Created from 2012-12-05 to 2013-01-05 ))))))))))))))))))))))))))))))) . . 2013-01-05 02:23 . 2013-01-05 02:23 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-01-02 09:07 . 2013-01-02 09:07 76232 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{516AA629-39E0-43FA-B4B1-C320C1C87164}\offreg.dll 2013-01-01 15:24 . 2012-11-08 17:24 9125352 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{516AA629-39E0-43FA-B4B1-C320C1C87164}\mpengine.dll 2012-12-21 08:01 . 2012-12-16 17:11 46080 —-a-w- c:\windows\system32\atmlib.dll 2012-12-21 08:01 . 2012-12-16 14:13 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-21 08:01 . 2012-12-16 14:45 367616 —-a-w- c:\windows\system32\atmfd.dll 2012-12-21 08:01 . 2012-12-16 14:13 295424 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-12 10:33 . 2012-11-09 05:45 2048 —-a-w- c:\windows\system32\tzres.dll 2012-12-12 10:33 . 2012-11-09 04:42 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2012-12-12 10:33 . 2012-11-22 03:26 3149824 —-a-w- c:\windows\system32\win32k.sys 2012-12-12 10:33 . 2012-10-04 17:41 424960 —-a-w- c:\windows\system32\KernelBase.dll 2012-12-12 10:33 . 2012-10-04 17:41 1161216 —-a-w- c:\windows\system32\kernel32.dll 2012-12-12 10:33 . 2012-10-04 17:45 215040 —-a-w- c:\windows\system32\winsrv.dll 2012-12-12 10:33 . 2012-10-04 15:21 338432 —-a-w- c:\windows\system32\conhost.exe 2012-12-10 17:07 . 2012-12-10 17:07 ——– d—–w- c:\program files\iPod 2012-12-10 17:07 . 2012-12-10 17:08 ——– d—–w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 2012-12-10 17:07 . 2012-12-10 17:08 ——– d—–w- c:\program files\iTunes 2012-12-10 17:07 . 2012-12-10 17:08 ——– d—–w- c:\program files (x86)\iTunes . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-12-12 15:36 . 2011-02-23 12:57 67413224 —-a-w- c:\windows\system32\MRT.exe 2012-12-12 02:11 . 2012-04-12 01:10 697272 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-12-12 02:11 . 2011-05-23 13:42 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-11-08 13:28 . 2012-09-04 04:04 30568 —-a-w- c:\windows\system32\drivers\avgtpx64.sys 2012-10-30 23:51 . 2011-02-10 18:24 59728 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2012-10-30 23:51 . 2011-06-02 19:43 984144 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2012-10-30 23:51 . 2011-02-10 18:24 370288 —-a-w- c:\windows\system32\drivers\aswSP.sys 2012-10-30 23:51 . 2011-02-10 18:24 71600 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2012-10-30 23:51 . 2011-02-10 18:24 25232 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-10-30 23:51 . 2011-02-10 18:24 41224 —-a-w- c:\windows\avastSS.scr 2012-10-30 23:50 . 2011-02-10 18:24 227648 —-a-w- c:\windows\SysWow64\aswBoot.exe 2012-10-30 23:50 . 2011-02-10 18:24 285328 —-a-w- c:\windows\system32\aswBoot.exe 2012-10-16 08:38 . 2012-11-28 10:51 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2012-10-16 08:38 . 2012-11-28 10:51 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2012-10-16 07:39 . 2012-11-28 10:52 561664 —-a-w- c:\windows\apppatch\AcLayers.dll 2012-10-15 16:59 . 2012-02-24 16:55 54072 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2012-10-09 18:17 . 2012-11-14 06:20 55296 —-a-w- c:\windows\system32\dhcpcsvc6.dll 2012-10-09 18:17 . 2012-11-14 06:20 226816 —-a-w- c:\windows\system32\dhcpcore6.dll 2012-10-09 17:40 . 2012-11-14 06:20 44032 —-a-w- c:\windows\SysWow64\dhcpcsvc6.dll 2012-10-09 17:40 . 2012-11-14 06:20 193536 —-a-w- c:\windows\SysWow64\dhcpcore6.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}] 2011-01-17 20:54 175912 —-a-w- c:\program files (x86)\ConduitEngine\prxConduitEngine.dll . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}] 2011-05-09 08:49 176936 —-a-w- c:\program files (x86)\WinZipBar\prxtbWinZ.dll . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] 2012-11-08 13:28 1796552 —-a-w- c:\program files (x86)\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}] 2011-05-09 08:49 176936 —-a-w- c:\program files (x86)\Vuze_Remote\prxtbVuze.dll . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{f999a48b-1950-4d81-9971-79018f807b4b}] 2011-01-17 20:54 175912 —-a-w- c:\program files (x86)\FreeOnlineRadioPlayerRecorder\prxtbFree.dll . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}] 2011-12-09 01:11 194848 —-a-w- c:\program files (x86)\Yontoo\YontooIEClient.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{f999a48b-1950-4d81-9971-79018f807b4b}"= "c:\program files (x86)\FreeOnlineRadioPlayerRecorder\prxtbFree.dll" [2011-01-17 175912] "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912] "{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}"= "c:\program files (x86)\WinZipBar\prxtbWinZ.dll" [2011-05-09 176936] "{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files (x86)\Vuze_Remote\prxtbVuze.dll" [2011-05-09 176936] "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG Secure Search\13.2.0.5\AVG Secure Search_toolbar.dll" [2012-11-08 1796552] . [HKEY_CLASSES_ROOT\clsid\{f999a48b-1950-4d81-9971-79018f807b4b}] . [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}] . [HKEY_CLASSES_ROOT\clsid\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}] . [HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}] . [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "PDF Complete"="c:\program files (x86)\PDF Complete\pdfsty.exe" [2010-10-22 895512] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] "avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2012-10-30 4297136] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208] "vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2012-11-08 997320] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296] "HF_G_Jul"="c:\program files (x86)\AVG Secure Search\HF_G_Jul.exe" [2012-07-19 36960] "ROC_ROC_JULY_P1"="c:\program files (x86)\AVG Secure Search\ROC_ROC_JULY_P1.exe" [2012-09-04 1022048] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-11-29 151952] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Event Reminder.lnk - c:\program files (x86)\Broderbund\PrintMaster\PMremind.exe [2011-2-13 331776] Microsoft Office.lnk - c:\program files (x86)\Microsoft Office\Office\OSA9.EXE [2000-1-20 65588] Snapfish PictureMover.lnk - c:\program files (x86)\PictureMover\Bin\PictureMover.exe [2010-9-28 1040952] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R1 aswSnx;aswSnx; [x] R1 aswSP;aswSP; [x] R2 AirPrint;AirPrint;c:\program files (x86)\AirPrint\airprint.exe [2011-11-03 234784] R2 aswFsBlk;aswFsBlk; [x] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624] R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x] R2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-08-06 291896] R2 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [2011-08-25 13672] R2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe [2010-10-22 1121304] R2 RoxioNow Service;RoxioNow Service;c:\program files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [2010-09-11 399344] R2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776] R2 vToolbarUpdater13.2.0;vToolbarUpdater13.2.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe [2012-11-08 711112] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] R3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264] R3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648] R3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960] R3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376] R3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-09-28 53760] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-02-13 1255736] S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys [2012-11-08 30568] S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [2010-07-22 1002848] . . — Other Services/Drivers In Memory — . *NewlyCreated* - 61861007 *Deregistered* - 61861007 . Contents of the 'Scheduled Tasks' folder . 2013-01-04 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-12 02:11] . 2013-01-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-29 19:15] . 2013-01-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-29 19:15] . 2013-01-02 c:\windows\Tasks\HPCeeScheduleForBUSAFAMILY-HP$.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-10-30 23:50 133400 —-a-w- c:\program files\Alwil Software\Avast5\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768] "SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2010-09-15 611896] . ——- Supplementary Scan ——- . uStart Page = hxxp://blekkosearch.mystart.com/blekko_soc/?source=f06b8e24&toolbarid=blekkotb_sa5&u=655192AEBE11C8F198023550AA48AA1E&tbp=homepage&v=1_2 uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://feed.snap.do/?publisher=Download&dpid=Download&co=US&userid=3ffa63ea-48db-44aa-85fe-7dd4558237a5&searchtype=ds&q={searchTerms} Trusted Zone: intuit.com\ttlc TCP: DhcpNameServer = 192.168.1.1 Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\13.2.0\ViProtocol.dll FF - ProfilePath - c:\users\Busa Family\AppData\Roaming\Mozilla\Firefox\Profiles\ejb5sw10.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3106777&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - www.google.com FF - prefs.js: keyword.URL - hxxp://www.google.com/search?btnI=I%27m+Feeling+Lucky&ie=UTF-8&oe=UTF-8&q= FF - user.js: general.useragent.extra.brc - FF - user.js: yahoo.homepage.dontask - true);user_pref(extentions.y2layers.installId, 59a73efd-c240-4fe5-8de2-f8483412f875 FF - user.js: extentions.y2layers.defaultEnableAppsList - Buzzdock,Buzzdock, FF - user.js: extensions.autoDisableScopes - 14 FF - user.js: security.csp.enable - false . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKLM-Run- - (no file) WebBrowser-{F999A48B-1950-4D81-9971-79018F807B4B} - (no file) AddRemove-Shockwave - c:\windows\System32\Macromed\SHOCKW~1\UNWISE.EXE . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pdfcDispatcher] "ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*] "value"="?\03\00\0b\053#?" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-01-04 21:25:19 ComboFix-quarantined-files.txt 2013-01-05 02:25 . Pre-Run: 395,791,929,344 bytes free Post-Run: 398,525,640,704 bytes free . - - End Of File - - 686FAA510C2F97775573F2B02B2E40FB
ok I rebooted into normal and for a time things appeared to be ok. Then I had my wife start to use it and as soon as she opened up her hotmail account, she got the blue screen of death which she said she saw once this morning just before the mouse stop responding. Here is some information on the failure that just occurred a couple of minutes ago. I also have the dmp file associated with this blue screen crash but I was not allowed to attach it to this post. This is starting to smell a bit like a memory problem but I am unsure why running in Safe mode does not produce any errors. Problem signature: Problem Event Name: BlueScreen OS Version: 6.1.7601.2.1.0.768.3 Locale ID: 1033 Additional information about the problem: BCCode: fc BCP1: FFFFF88002842D38 BCP2: 800000002ADCA963 BCP3: FFFFF88002842AF0 BCP4: 0000000000000002 OS Version: 6_1_7601 Service Pack: 1_0 Product: 768_1
I found a program to help me read the dump files from the blue screen of deaths. Here is some info from the Blue Screen of Death from just a few minutes ago 010413-34117-01.dmp 1/4/2013 9:39:20 PM ATTEMPTED_EXECUTE_OF_NOEXECUTE_MEMORY 0x000000fc fffff880`02842d38 80000000`2adca963 fffff880`02842af0 00000000`00000002 Ntfs.sys Ntfs.sys+f87e x64 ntoskrnl.exe+7efc0 C:\Windows\Minidump\010413-34117-01.dmp 2 15 7601 301,394 ================= And here is some info from the Blue Screen of Death from this morning when the problem was first encountered 010413-48063-01.dmp 1/4/2013 6:36:55 AM KMODE_EXCEPTION_NOT_HANDLED 0x0000001e 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 nwifi.sys nwifi.sys+1107518 x64 ntoskrnl.exe+7ef90 C:\Windows\Minidump\010413-48063-01.dmp 2 15 7601 305,762
Please go to Start > Control Panel > Programs and Features and uninstall the following:
AVG Security Toolbar (I have seen this cause problems in browsers)
Yontoo 1.10.02 (This is what we call a potentially unwanted program and can make modifications to website pages that are not obvious and is installed without user consent I would suggest uninstalling it)

Please reboot the computer after doing so.


Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal.
In your last run it did not appear your antivirus was disabled and this may have impacted a proper run of the tool. Please run Combofix again with your antivirus disabled..

Double click ComboFix.exe to run it. It will prompt you that an update is available - please allow it to update.

Follow all prompts. Post the C:\ComboFix.txt when it has completed.


Can you please tell me what browser (Internet Explorer or Firefox) you were using when you got the BSOD and what version of Internet Explorer 8 or 9 installed? (When in Internet Explorer please click on Help > About Internet Explorer from the file menu or on the little Gear Icon and choose About Internet Explorer and it will show you which you have.)
I uninstalled the two programs requested and rebooted into normal mode. I disabled avast, updated combo fix and ran it but got the blue screen of death before it finished. No browser was open during this time period. I tried again in normal mode with Avast diabled "permenantly" from the task bar but ComboFix still thinks it is running. Eventually I got the blue screen again before I could debug more why ComboFix felt Avast was still running. I rebooted into safe mode I am having problems disabling the avast control in safe mode. The program does not appear in the task bar and I am unsure how to disable it. I don't think it is running in safe mode. Looking at the task manager shows that Avast is not running as a program or a process and that its service is stopped but ComboFix still believes it is running. We use Firefox as our normal browser. The IE version installed is 9.0.8112.16421
Please see previous post if you have not read that first ================================================= I went on to the Avast forums and mentioned my issue with ComboFix in safe mode. They stated that the avast shields are not running in Safe mode and that the ComboFix warnings can be ignored. This would result in pretty much the situation I ran ComboFix in last time in safe mode but I can run it again if you request. I also read that I disabled Avast correctly in normal mode, but that ComboFix can sometimes kick the warning if the drivers are loaded even if it is disabled. However, I can't stay alive long enough in normal mode to let ComboFix finish running. As a side note, I have noticed that the BC error code is different every time I crash with the Blue Screen issue. The computer was up for over 8 hours straight in safe mode but won't stay alive for more than a couple of minutes in normal mode.
You should be able to do run this in safe mode with no issue. Please remove any threats it finds:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.



I'm not sure if you can run this in safe mode but give it a try, please follow the instructions for using Firefox (I've had a some logs lately where ESET has been acting a little odd in IE so your preferred browser would actually be our preferred choice here.)

This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.


Go here to run an online scannner from ESET.
  • Note: For browsers other than Internet Explorer, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.

If it doesn't find anything there will be no log to post.
MalwareBytes did not find any issues. Eset found 3 issues. Both log files are below. ==================================== Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.01.05.07 Windows 7 Service Pack 1 x64 NTFS (Safe Mode/Networking) Internet Explorer 9.0.8112.16421 Busa Family :: BUSAFAMILY-HP [administrator] 1/5/2013 2:05:00 PM mbam-log-2013-01-05 (14-05-00).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 212417 Time elapsed: 2 minute(s), 24 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ======================== ESETSmartInstaller@High as CAB hook log: OnlineScanner64.ocx - registred OK OnlineScanner.ocx - registred OK # version=8 # iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330) # OnlineScanner.ocx=1.0.0.6844 # api_version=3.0.2 # EOSSerial= # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2013-01-05 10:12:04 # local_time=2013-01-05 05:12:04 (-0500, Eastern Standard Time) # country="United States" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 0 108967374 0 0 # scanned=222436 # found=3 # cleaned=0 # scan_time=10558 C:\ProgramData\Tarma Installer\{C049526F-B3EB-4151-9B11-B11F00F53A96}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application (unable to clean) 48EF8B4E06E0F1D3C06C4D6E1EA2B6CE48AA5231 I C:\Users\All Users\Tarma Installer\{C049526F-B3EB-4151-9B11-B11F00F53A96}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application (unable to clean) 48EF8B4E06E0F1D3C06C4D6E1EA2B6CE48AA5231 I F:\Books\Poker\Various\Poker Pro 2006\PokerPro2006v4167_Crack.exe a variant of Win32/HackTool.Patcher.X application (unable to clean) A716428F74D8733F26B1215015AC49A5950CB185 I
oh shoot! I apologize. I read your instructions backwards. I thought I was suppose to run eset in IE. I am going to rerun it now for Firefox. You can read the above log that was run in IE in case it was of any interest since it did find some issues

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI