This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Noisy computer/infected?

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is generally running fine, except at random times it seems to just run, and it sounds like it does when it is working overtime. It happens overnight when not in use and during the day when in use. I have run a Norton 360 scan this morning, and it only found a cookie. Yet, the computer has been running since at least 4 this morning when I got up. It quiets down when you turn it off, and stays quiet for a while when rebooted. The only time I know it will definitely do this is when I go to Drudge Report. This makes me suspicious it is not a hardware problem, but something malicious. Although I will be quick to add, that it does happen even if I don't go to that site on occasion. If it is a hardware issue, I apologize. I just want to make sure there isn't something malicious that is going on in the background that is causing this. . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 7:31:35.19 on Fri 01/11/2013 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.1237 [GMT -6:00] . AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\rundll32.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\LSI SoftModem\agrsmsvc.exe C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe C:\Program Files\Norton 360\Engine\20.2.0.19\ccSvcHst.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files\Norton 360\Engine\20.2.0.19\ccSvcHst.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\wpcumi.exe C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\ehome\ehmsas.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\DllHost.exe C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\notepad.exe C:\Windows\system32\vssvc.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\system32\notepad.exe C:\Windows\system32\wscript.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\jtmeserole\Downloads\dds.scr . ============== Pseudo HJT Report =============== . uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2801948 uURLSearchHooks: NCH EN Toolbar: {37483b40-c254-4a72-bda4-22ee90182c1e} - c:\program files\nch_en\prxtbNCH_.dll uURLSearchHooks: H - No File mURLSearchHooks: NCH EN Toolbar: {37483b40-c254-4a72-bda4-22ee90182c1e} - c:\program files\nch_en\prxtbNCH_.dll BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: NCH EN Toolbar: {37483b40-c254-4a72-bda4-22ee90182c1e} - c:\program files\nch_en\prxtbNCH_.dll BHO: Norton Identity Protection: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\20.2.0.19\coIEPlg.dll BHO: Norton Vulnerability Protection: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\20.2.0.19\ips\IPSBHO.DLL BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\mi1933~1\office14\URLREDIR.DLL BHO: Norton Family BHO: {b8e07826-0971-4f16-b133-047b88034e89} - c:\program files\norton family\engine\2.6.0.43\coIEPlg.dll BHO: Free Download Manager: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: NCH EN Toolbar: {37483b40-c254-4a72-bda4-22ee90182c1e} - c:\program files\nch_en\prxtbNCH_.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\20.2.0.19\coIEPlg.dll EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe mRun: [Windstream Service Agent.exe] "c:\program files\windstream\service agent\Windstream Service Agent.exe" /AUTORUN mRun: [DiagnosticTools.exe] "c:\program files\windstream\diagnostic tools\DiagnosticTools.exe" /AUTORUN mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\mi1933~1\office14\ONBttnIE.dll/105 IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll LSP: c:\windows\system32\wpclsp.dll Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\24.0.1312.52\installer\setup.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome . ================= FIREFOX =================== . FF - ProfilePath - c:\users\jtmese~1\appdata\roaming\mozilla\firefox\profiles\tkucy2ap.default\ FF - prefs.js: browser.search.defaulturl - Bing FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.ldsscripturemastery.net/en/ FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bf3b5f3b9-99d4-4d13-9c1c-397b9c9ecfab%7D&mid=a0c880af8f7247d0bea3d16f5eae26b7-4b869c74173af2f9aa392fa149498c5861dbbba5&ds=ft011&v=11.1.0.7&lang=en&pr=sa&d=2012-06-18%2017%3A44%3A13&sap=ku&q= FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\progra~1\mi1933~1\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\mi1933~1\office14\NPSPWRAP.DLL FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll FF - plugin: c:\program files\musicnotes\npmusicn.dll FF - plugin: c:\program files\musicnotes\NPSibelius.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\program files\windstream\service agent\nprpspa.dll FF - plugin: c:\users\jtmeserole\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\users\jtmeserole\appdata\roaming\mozilla\firefox\profiles\tkucy2ap.default\extensions\{000f1ea4-5e08-4564-a29b-29076f63a37a}\plugins\npsoe.dll FF - plugin: c:\users\jtmeserole\appdata\roaming\mozilla\firefox\profiles\tkucy2ap.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_265.dll . —- FIREFOX POLICIES —- FF - user.js: extentions.y2layers.installId - 1132a82e-f3dd-43a0-b9bf-af81c9d2c769 . ============= SERVICES / DRIVERS =============== . R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\1402000.013\symds.sys [2012-11-22 368288] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\1402000.013\symefa.sys [2012-11-22 927904] R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_20.1.1.2\definitions\bashdefs\20130107.001\BHDrvx86.sys [2013-1-8 995488] R1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\n360\1402000.013\ccsetx86.sys [2012-11-22 134304] R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\rsdrv.sys [2011-9-7 22312] R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_20.1.1.2\definitions\ipsdefs\20130111.001\IDSvix86.sys [2013-1-10 386720] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\1402000.013\ironx86.sys [2012-11-22 175264] R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\1402000.013\symtdiv.sys [2012-11-22 350368] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] R2 HsdService;HsdService;c:\program files\windstream\diagnostic tools\HsdService.exe [2012-1-17 1393976] R2 N360;Norton 360;c:\program files\norton 360\engine\20.2.0.19\ccsvchst.exe [2012-11-22 143928] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-11-24 106656] R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfslh.sys [2011-10-1 579944] R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplaylh.sys [2011-10-1 194408] R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvollh.sys [2011-10-1 19304] R3 sftvsa;Application Virtualization Service Agent;c:\program files\microsoft application virtualization client\sftvsa.exe [2011-10-1 219496] S1 ccSet_NSM;Norton Family Settings Manager;c:\windows\system32\drivers\nsm\0206000.02b\ccSetx86.sys [2012-11-11 134304] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 cvhsvc;Client Virtualization Handler;c:\program files\common files\microsoft shared\virtualization handler\CVHSVC.EXE [2012-1-4 822624] S2 NSM;Norton Family;c:\program files\norton family\engine\2.6.0.43\ccSvcHst.exe [2012-11-11 143928] S2 PCCUJobMgr;Common Client Job Manager Service;c:\program files\norton pc checkup\engine\2.0.12.27\ccSvcHst.exe [2011-9-30 126392] S2 sftlist;Application Virtualization Client;"c:\program files\microsoft application virtualization client\sftlist.exe" –> c:\program files\microsoft application virtualization client\sftlist.exe [?] S3 dsiarhwprog;dsiarhwprog;c:\windows\system32\drivers\dsiarhwprog.sys [2011-8-14 29184] S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2011-1-26 39272] S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352] S3 MHIKEY10;MHIKEY10;c:\windows\system32\drivers\MHIKEY10.sys [2008-5-27 50560] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-5-6 115168] S3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirlh.sys [2011-10-1 21864] S3 SYMRDR_{78CA3BF0-9C3B-40e1-B46D-38C877EF059A};Symantec Redirector - Norton Family;c:\windows\system32\drivers\nsm\0206000.02b\symrdr.sys [2012-11-11 202144] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S4 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-10 136176] S4 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-2-10 136176] S4 Norton PC Checkup Application Launcher;Norton PC Checkup Application Launcher;c:\program files\norton pc checkup 3.0\SymcPCCULaunchSvc.exe [2012-9-22 132056] S4 ServicepointService;ServicepointService;c:\program files\windstream\service agent\ServicepointService.exe [2012-1-17 10315064] S4 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944] S4 UMVPFSrv;UMVPFSrv;c:\program files\common files\logishrd\lvmvfm\UMVPFSrv.exe [2011-8-19 450848] . =============== Created Last 30 ================ . 2013-01-11 04:01:33 710504 —-a-w- c:\windows\isRS-000.tmp 2013-01-10 23:07:23 ——– d—–w- c:\users\jtmese~1\appdata\local\{1F54E683-0E8B-44BA-AA3E-CFB4069A77E9} 2013-01-09 17:56:10 2048000 —-a-w- c:\windows\system32\win32k.sys 2013-01-09 17:55:40 204288 —-a-w- c:\windows\system32\ncrypt.dll 2013-01-09 17:55:39 1400832 —-a-w- c:\windows\system32\msxml6.dll 2013-01-05 05:16:10 ——– d—–w- c:\users\jtmese~1\appdata\local\{F1267C69-57B7-4979-BB6B-3EC38190399E} 2012-12-22 13:39:13 34304 —-a-w- c:\windows\system32\atmlib.dll 2012-12-22 13:39:13 293376 —-a-w- c:\windows\system32\atmfd.dll 2012-12-14 13:15:53 9728 —-a-w- c:\windows\system32\Wdfres.dll 2012-12-14 13:15:50 73216 —-a-w- c:\windows\system32\WUDFSvc.dll 2012-12-14 13:15:50 66560 —-a-w- c:\windows\system32\drivers\WUDFPf.sys 2012-12-14 13:15:50 172032 —-a-w- c:\windows\system32\WUDFPlatform.dll 2012-12-14 13:15:50 16896 —-a-w- c:\windows\system32\winusb.dll 2012-12-14 13:15:50 155136 —-a-w- c:\windows\system32\drivers\WUDFRd.sys 2012-12-14 13:15:49 613888 —-a-w- c:\windows\system32\WUDFx.dll 2012-12-14 13:15:49 526952 —-a-w- c:\windows\system32\drivers\Wdf01000.sys 2012-12-14 13:15:49 47720 —-a-w- c:\windows\system32\drivers\WdfLdr.sys 2012-12-14 13:15:49 38912 —-a-w- c:\windows\system32\WUDFCoinstaller.dll 2012-12-14 13:15:49 196608 —-a-w- c:\windows\system32\WUDFHost.exe 2012-12-13 12:46:29 376320 —-a-w- c:\windows\system32\dpnet.dll 2012-12-13 12:46:29 23040 —-a-w- c:\windows\system32\dpnsvr.exe 2012-12-13 12:46:27 224640 —-a-w- c:\windows\system32\drivers\volsnap.sys 2012-12-13 12:46:24 2048 —-a-w- c:\windows\system32\tzres.dll . ==================== Find3M ==================== . 2012-11-14 02:09:22 1800704 —-a-w- c:\windows\system32\jscript9.dll 2012-11-14 01:58:15 1427968 —-a-w- c:\windows\system32\inetcpl.cpl 2012-11-14 01:57:37 1129472 —-a-w- c:\windows\system32\wininet.dll 2012-11-14 01:49:25 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2012-11-14 01:48:27 420864 —-a-w- c:\windows\system32\vbscript.dll 2012-11-14 01:44:42 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-03-26 15:22:17 35113704 —-a-w- c:\program files\common files\directx_9c_redist.exe . ============= FINISH: 7:31:54.62 ===============
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!


I need to get another diagnostic scan before we can continue so I make sure I know we are not dealing with any rootkits.

Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.


I can also see you have a few potentially unwanted items on your machine. They are not necessarily considered malware but they can track your browsing history, serve up ads you don't want, and may install items without your consent. I'd suggest you run this tool to remove those items before we continue so they can be removed from the equation.

[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
Here you go!




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.4.2 (01.08.2013:1)
OS: Windows Vista ™ Home Premium x86
Ran by [removed] on Mon 01/14/2013 at 13:09:14.58
Blog: http://thisisudax.blogspot.com
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully deleted: [Registry Value] hkey_current_user\software\microsoft\internet explorer\toolbar\webbrowser\\{37483b40-c254-4a72-bda4-22ee90182c1e}
Successfully deleted: [Registry Value] hkey_current_user\software\microsoft\internet explorer\urlsearchhooks\\{37483b40-c254-4a72-bda4-22ee90182c1e}
Successfully deleted: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\toolbar\\{37483b40-c254-4a72-bda4-22ee90182c1e}
Successfully deleted: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\urlsearchhooks\\{37483b40-c254-4a72-bda4-22ee90182c1e}
Successfully deleted: [Registry Value] hkey_current_user\software\microsoft\internet explorer\urlsearchhooks\\{d3d233d5-9f6d-436c-b6c7-e63f77503b30}
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-3496540520-3972749145-994392144-1000\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-3496540520-3972749145-994392144-1000\software\microsoft\internet explorer\searchscopes\\DefaultScope



~~~ Registry Keys

Successfully deleted: [Registry Key] hkey_current_user\software\conduit
Successfully deleted: [Registry Key] hkey_local_machine\software\conduit
Successfully deleted: [Registry Key] hkey_current_user\software\ilivid
Successfully deleted: [Registry Key] hkey_current_user\software\installedbrowserextensions
Successfully deleted: [Registry Key] hkey_current_user\software\softonic
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\conduit
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\conduitsearchscopes
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\crossrider
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\i want this
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\pricegong
Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\searchqutoolbar
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\discoveryhelper.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\escort.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\gifanimator.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\imtrprogress.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\imweb.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\nctaudiocdgrabber2.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\wmhelper.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\yontooieclient.dll
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\conduit.engine
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\discoveryhelper.imesh6discovery
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\discoveryhelper.imesh6discovery.1
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\imweb.imwebcontrol
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\prod.cap
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\yontooieclient.api
Successfully deleted: [Registry Key] hkey_local_machine\software\classes\yontooieclient.api.1
Successfully deleted: [Registry Key-Heur] HKEY_LOCAL_MACHINE\software\classes\Toolbar.CT2117678
Successfully deleted: [Registry Key-Heur] HKEY_LOCAL_MACHINE\software\classes\Toolbar.CT2801948
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{2eecd738-5844-4a99-b4b6-146bf802613b}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{37483b40-c254-4a72-bda4-22ee90182c1e}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{37483b40-c254-4a72-bda4-22ee90182c1e}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{3c471948-f874-49f5-b338-4f214a2ee0b1}
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{5aa2ba46-9913-4dc7-9620-69ab0fa17ae7}
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{95b7759c-8c7f-4bf1-b163-73684a933233}
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{9bb47c17-9c68-4bb3-b188-dd9af0fd2406}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{9bb47c17-9c68-4bb3-b188-dd9af0fd2406}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{c04b7d22-5aec-4561-8f49-27f6269208f6}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{cc59e0f9-7e43-44fa-9faa-8377850bf205}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{cc59e0f9-7e43-44fa-9faa-8377850bf205}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{e46c8196-b634-44a1-af6e-957c64278ab1}
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{afbcb7e0-f91a-4951-9f31-58fee57a25c4}



~~~ Files

Successfully deleted: [File] "C:\Program Files\mozilla firefox\plugins\npcouponprinter.dll"
Successfully deleted: [File] "C:\Program Files\mozilla firefox\plugins\npmozcouponprinter.dll"
Successfully deleted: [File] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ebay.lnk"
Successfully deleted: [File] "C:\Windows\couponprinter.ocx"



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\Users\jtmeserole\AppData\Roaming\pccustubinstaller"
Successfully deleted: [Folder] "C:\Users\jtmeserole\appdata\local\conduit"
Successfully deleted: [Folder] "C:\Users\jtmeserole\appdata\local\ilivid player"
Successfully deleted: [Folder] "C:\Users\jtmeserole\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\jtmeserole\appdata\locallow\nch_en"
Successfully deleted: [Folder] "C:\Users\jtmeserole\appdata\locallow\searchquband"
Successfully deleted: [Folder] "C:\Program Files\conduit"
Successfully deleted: [Folder] "C:\Program Files\coupons"
Successfully deleted: [Folder] "C:\Program Files\ilivid"
Successfully deleted: [Folder] "C:\Program Files\imesh applications"
Successfully deleted: [Folder] "C:\Program Files\nch_en"
Successfully deleted: [Folder] "C:\Program Files\yontoo layers runtime"
Successfully deleted: [Folder] "C:\Users\jtmeserole\appdata\locallow\asktoolbar"



~~~ FireFox

Successfully deleted: [File] "C:\Program Files\Mozilla Firefox\searchplugins\bing.xml.old"
Successfully deleted: [File] C:\Users\jtmeserole\AppData\Roaming\mozilla\firefox\profiles\tkucy2ap.default\user.js
Successfully deleted: [File] "C:\Users\jtmeserole\AppData\Roaming\mozilla\firefox\profiles\tkucy2ap.default\extensions\[removed]"
Successfully deleted: [File] C:\Users\jtmeserole\AppData\Roaming\mozilla\firefox\profiles\tkucy2ap.default\searchplugins\askcom.xml
Successfully deleted: [File] C:\Users\jtmeserole\AppData\Roaming\mozilla\firefox\profiles\tkucy2ap.default\searchplugins\bing-zugo.xml
Successfully deleted: [Folder] C:\Users\jtmeserole\AppData\Roaming\mozilla\firefox\profiles\tkucy2ap.default\searchqutoolbar
Successfully deleted the following from C:\Users\jtmeserole\AppData\Roaming\mozilla\firefox\profiles\tkucy2ap.default\prefs.js

user_pref("browser.search.defaultengine", "Ask.com");
user_pref("browser.search.order.1", "Ask.com");
user_pref("extensions.BabylonToolbar.aflt", "babclient");
user_pref("extensions.BabylonToolbar.bbDpng", 2);
user_pref("extensions.BabylonToolbar.firstRun", false);
user_pref("extensions.BabylonToolbar.id", "00eb19d50000000000000026184acf44");
user_pref("extensions.BabylonToolbar.instlDay", "15188");
user_pref("extensions.BabylonToolbar.instlRef", "std");
user_pref("extensions.BabylonToolbar.lastDP", 2);
user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.4.31.623:22:46");
user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
user_pref("extensions.BabylonToolbar.smplGrp", "none");
user_pref("extensions.BabylonToolbar.srchPrvdr", "");
user_pref("extensions.BabylonToolbar.tlbrId", "base");
user_pref("extensions.BabylonToolbar.vrsn", "[removed]");
user_pref("extensions.BabylonToolbar.vrsnTs", "1.4.31.623:22:46");
user_pref("extensions.crossrider.bic", "1346ca576420d59de23a21a18060c203");
user_pref("extensions.crossriderapp498.498.InstallationThankYouPage", true);
user_pref("extensions.crossriderapp498.498.InstallationTime", 1324672592);
user_pref("extensions.crossriderapp498.498.InstallationUserSettings.searchUserConifrma
tion", false);
user_pref("extensions.crossriderapp498.498.InstallationUserSettings.setHomepage", false);
user_pref("extensions.crossriderapp498.498.InstallationUserSettings.setNewTab", false);
user_pref("extensions.crossriderapp498.498.InstallationUserSettings.setSearch", false);
user_pref("extensions.crossriderapp498.498.active", true);
user_pref("extensions.crossriderapp498.498.addressbar", "");
user_pref("extensions.crossriderapp498.498.affid", "0");
user_pref("extensions.crossriderapp498.498.backgroundjs", "\n/********************************************************************************
****\n This is your background c
user_pref("extensions.crossriderapp498.498.backgroundver", 4);
user_pref("extensions.crossriderapp498.498.certdomaininstaller", "");
user_pref("extensions.crossriderapp498.498.changeprevious", false);
user_pref("extensions.crossriderapp498.498.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT-0600 (Central Standard Time)");
user_pref("extensions.crossriderapp498.498.cookie.InstallationTime.value", "1324672592");
user_pref("extensions.crossriderapp498.498.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 GMT-0600 (Central Standard Time)");
user_pref("extensions.crossriderapp498.498.cookie.InstallerParams.value", "%7B%22sub_id%22%3A%22default%22%2C%22source_id%22%3A%224cross5a93dbRW1AR24CA07DE%22%2C%22uzid%22%3A%
user_pref("extensions.crossriderapp498.498.cookie._GPL_geo.expiration", "Fri Dec 30 2011 14:38:47 GMT-0600 (Central Standard Time)");
user_pref("extensions.crossriderapp498.498.cookie._GPL_geo.value", "%7B%22geoplugin_city%22%3A%22Washington%22%2C%22geoplugin_region%22%3A%22IA%22%2C%22geoplugin_areaCode%22%3
user_pref("extensions.crossriderapp498.498.cookie._GPL_hotfix20111102645.expiration", "Fri Feb 01 2030 00:00:00 GMT-0600 (Central Standard Time)");
user_pref("extensions.crossriderapp498.498.cookie._GPL_hotfix20111102645.value", "%221%22");
user_pref("extensions.crossriderapp498.498.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT-0600 (Central Standard Time)");
user_pref("extensions.crossriderapp498.498.cookie._GPL_parent_zoneid.value", "%2210621%22");
user_pref("extensions.crossriderapp498.498.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:00 GMT-0600 (Central Standard Time)");
user_pref("extensions.crossriderapp498.498.cookie._GPL_zoneid.value", "%2214374%22");
user_pref("extensions.crossriderapp498.498.description", "RewardsArcade is a platform that allows users to play amazing games against their friends on Facebook and other socia
user_pref("extensions.crossriderapp498.498.domain", "www.rewardsarcade.com");
user_pref("extensions.crossriderapp498.498.emailsig", "");
user_pref("extensions.crossriderapp498.498.enablesearch", false);
user_pref("extensions.crossriderapp498.498.exposesites", "");
user_pref("extensions.crossriderapp498.498.fbremoteurl", "");
user_pref("extensions.crossriderapp498.498.group", 0);
user_pref("extensions.crossriderapp498.498.homepage", "");
user_pref("extensions.crossriderapp498.498.iframe", false);
user_pref("extensions.crossriderapp498.498.js", "\n\nvar _GPL_PID = 18;\n\n(function($) { \n\n $.geoplugin = function(options) {\n var baseCurrency = \"USD\";\n var a
user_pref("extensions.crossriderapp498.498.manifesturl", "");
user_pref("extensions.crossriderapp498.498.name", "RewardsArcade");
user_pref("extensions.crossriderapp498.498.newtab", "");
user_pref("extensions.crossriderapp498.498.opensearch", "");
user_pref("extensions.crossriderapp498.498.premium", true);
user_pref("extensions.crossriderapp498.498.publisher", "215 Apps");
user_pref("extensions.crossriderapp498.498.searchstatus", 0);
user_pref("extensions.crossriderapp498.498.setnewtab", false);
user_pref("extensions.crossriderapp498.498.settingsurl", "");
user_pref("extensions.crossriderapp498.498.thankyou", "http://www.rewardsarcade.com/r.php?app_id=498");
user_pref("extensions.crossriderapp498.498.updateinterval", 360);
user_pref("extensions.crossriderapp498.498.ver", 61);
user_pref("extensions.crossriderapp498.apps", "498");
user_pref("extensions.crossriderapp498.bic", "1346ca576420d59de23a21a18060c203");
user_pref("extensions.crossriderapp498.cid", 498);
user_pref("extensions.crossriderapp498.firstrun", false);
user_pref("extensions.crossriderapp498.hadappinstalled", true);
user_pref("extensions.crossriderapp498.installationdate", 1324672710);
user_pref("extensions.crossriderapp498.jsver", 3);
user_pref("extensions.crossriderapp498.lastcheck", 22079775);
user_pref("extensions.crossriderapp498.lastcheckitem", 22079775);
user_pref("extensions.crossriderapp498.misc.lastBgWorkerTimer", "1324786602089");
user_pref("extensions.crossriderapp498.misc.lastDomWorkerTimer", "1324786602088");
user_pref("extentions.y2layers.installId", "1132a82e-f3dd-43a0-b9bf-af81c9d2c769");
user_pref("keyword.URL", "http://isearch.avg.com/search?cid=%7Bf3b5f3b9-99d4-4d13-9c1c-397b9c9ecfab%7D&mid=a0c880af8f7247d0bea3d16f5eae26b7-4b869c74173af2f9aa392fa149498c5861d
Emptied folder: C:\Users\jtmeserole\AppData\Roaming\mozilla\firefox\profiles\tkucy2ap.default\minidumps [229 files]



~~~ Chrome

Dumping contents of C:\Users\jtmeserole\appdata\local\Google\Chrome\User Data\Default\Default
C:\Users\jtmeserole\appdata\local\Google\Chrome\User Data\Default\Default\ejoljoceolecigjbiccmpddfgnikamjh
C:\Users\jtmeserole\appdata\local\Google\Chrome\User Data\Default\Default\ejoljoceolecigjbiccmpddfgnikamjh\manifest.json

Successfully deleted: [Folder] C:\Users\jtmeserole\appdata\local\Google\Chrome\User Data\Default\Default [Default Extension 1.0]
Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\dhkplhfnhceodhffomolpfigojocbpcb
Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\niapdbllcanepiiimjjndipklodoedlc



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 01/14/2013 at 13:13:04.61
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~









13:01:19.0648 5376 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
13:01:21.0395 5376 ============================================================
13:01:21.0395 5376 Current date / time: 2013/01/14 13:01:21.0395
13:01:21.0395 5376 SystemInfo:
13:01:21.0395 5376
13:01:21.0395 5376 OS Version: 6.0.6002 ServicePack: 2.0
13:01:21.0395 5376 Product type: Workstation
13:01:21.0395 5376 ComputerName: JTMESEROLE-PC
13:01:21.0395 5376 UserName: jtmeserole
13:01:21.0395 5376 Windows directory: C:\Windows
13:01:21.0395 5376 System windows directory: C:\Windows
13:01:21.0395 5376 Processor architecture: Intel x86
13:01:21.0395 5376 Number of processors: 2
13:01:21.0395 5376 Page size: 0x1000
13:01:21.0395 5376 Boot type: Normal boot
13:01:21.0395 5376 ============================================================
13:01:21.0816 5376 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
13:01:21.0816 5376 ============================================================
13:01:21.0816 5376 \Device\Harddisk0\DR0:
13:01:21.0816 5376 MBR partitions:
13:01:21.0816 5376 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x23D9C201
13:01:21.0816 5376 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x23D9C240, BlocksNum 0x1691481
13:01:21.0816 5376 ============================================================
13:01:21.0832 5376 C: <-> \Device\Harddisk0\DR0\Partition1
13:01:21.0879 5376 D: <-> \Device\Harddisk0\DR0\Partition2
13:01:21.0879 5376 ============================================================
13:01:21.0879 5376 Initialize success
13:01:21.0879 5376 ============================================================
13:01:31.0644 4900 ============================================================
13:01:31.0644 4900 Scan started
13:01:31.0644 4900 Mode: Manual;
13:01:31.0644 4900 ============================================================
13:01:31.0925 4900 ================ Scan system memory ========================
13:01:31.0925 4900 System memory - ok
13:01:31.0925 4900 ================ Scan services =============================
13:01:32.0097 4900 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
13:01:32.0112 4900 ACPI - ok
13:01:32.0175 4900 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
13:01:32.0175 4900 adp94xx - ok
13:01:32.0206 4900 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
13:01:32.0206 4900 adpahci - ok
13:01:32.0221 4900 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
13:01:32.0221 4900 adpu160m - ok
13:01:32.0237 4900 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
13:01:32.0253 4900 adpu320 - ok
13:01:32.0299 4900 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
13:01:32.0299 4900 AeLookupSvc - ok
13:01:32.0362 4900 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
13:01:32.0362 4900 AFD - ok
13:01:32.0471 4900 [ 48091A2374A69F473273C44951195452 ] AgereModemAudio C:\Program Files\LSI SoftModem\agrsmsvc.exe
13:01:32.0471 4900 AgereModemAudio - ok
13:01:32.0549 4900 [ C6FA08A8CCA9001F3197525B07331715 ] AgereSoftModem C:\Windows\system32\DRIVERS\AGRSM.sys
13:01:32.0565 4900 AgereSoftModem - ok
13:01:32.0627 4900 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
13:01:32.0627 4900 agp440 - ok
13:01:32.0643 4900 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
13:01:32.0643 4900 aic78xx - ok
13:01:32.0658 4900 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
13:01:32.0658 4900 ALG - ok
13:01:32.0674 4900 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
13:01:32.0674 4900 aliide - ok
13:01:32.0689 4900 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
13:01:32.0689 4900 amdagp - ok
13:01:32.0705 4900 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
13:01:32.0705 4900 amdide - ok
13:01:32.0721 4900 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
13:01:32.0721 4900 AmdK7 - ok
13:01:32.0721 4900 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
13:01:32.0721 4900 AmdK8 - ok
13:01:32.0783 4900 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
13:01:32.0783 4900 Appinfo - ok
13:01:32.0908 4900 [ 3DEBBECF665DCDDE3A95D9B902010817 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
13:01:32.0908 4900 Apple Mobile Device - ok
13:01:32.0970 4900 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
13:01:32.0970 4900 arc - ok
13:01:33.0017 4900 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
13:01:33.0033 4900 arcsas - ok
13:01:33.0079 4900 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
13:01:33.0079 4900 AsyncMac - ok
13:01:33.0126 4900 [ 2D9C903DC76A66813D350A562DE40ED9 ] atapi C:\Windows\system32\drivers\atapi.sys
13:01:33.0126 4900 atapi - ok
13:01:33.0204 4900 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
13:01:33.0204 4900 AudioEndpointBuilder - ok
13:01:33.0220 4900 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
13:01:33.0220 4900 Audiosrv - ok
13:01:33.0235 4900 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
13:01:33.0235 4900 Beep - ok
13:01:33.0313 4900 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
13:01:33.0313 4900 BFE - ok
13:01:33.0516 4900 [ 9DFFCB249663AA3C2ECB67202280054E ] BHDrvx86 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\BASHDefs\20130107.001\BHDrvx86.sys
13:01:33.0547 4900 BHDrvx86 - ok
13:01:33.0625 4900 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\system32\qmgr.dll
13:01:33.0625 4900 BITS - ok
13:01:33.0657 4900 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
13:01:33.0657 4900 blbdrive - ok
13:01:33.0735 4900 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
13:01:33.0750 4900 Bonjour Service - ok
13:01:33.0781 4900 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
13:01:33.0781 4900 bowser - ok
13:01:33.0828 4900 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
13:01:33.0828 4900 BrFiltLo - ok
13:01:33.0844 4900 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
13:01:33.0844 4900 BrFiltUp - ok
13:01:33.0859 4900 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
13:01:33.0859 4900 Browser - ok
13:01:33.0906 4900 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
13:01:33.0906 4900 Brserid - ok
13:01:33.0922 4900 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
13:01:33.0922 4900 BrSerWdm - ok
13:01:33.0937 4900 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
13:01:33.0937 4900 BrUsbMdm - ok
13:01:33.0953 4900 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
13:01:33.0953 4900 BrUsbSer - ok
13:01:34.0000 4900 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
13:01:34.0000 4900 BTHMODEM - ok
13:01:34.0109 4900 [ 1277AD8F053CC60C17CAFAB411F3CF40 ] ccSet_N360 C:\Windows\system32\drivers\N360\1402000.013\ccSetx86.sys
13:01:34.0109 4900 ccSet_N360 - ok
13:01:34.0234 4900 [ 41CD31307E054F878EA3FD7F7D2C2922 ] ccSet_NSM C:\Windows\system32\drivers\NSM\0206000.02B\ccSetx86.sys
13:01:34.0234 4900 ccSet_NSM - ok
13:01:34.0296 4900 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
13:01:34.0296 4900 cdfs - ok
13:01:34.0374 4900 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
13:01:34.0374 4900 cdrom - ok
13:01:34.0421 4900 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
13:01:34.0421 4900 CertPropSvc - ok
13:01:34.0452 4900 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\DRIVERS\circlass.sys
13:01:34.0452 4900 circlass - ok
13:01:34.0468 4900 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
13:01:34.0468 4900 CLFS - ok
13:01:34.0515 4900 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:01:34.0515 4900 clr_optimization_v2.0.50727_32 - ok
13:01:34.0593 4900 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:01:34.0608 4900 clr_optimization_v4.0.30319_32 - ok
13:01:34.0624 4900 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
13:01:34.0624 4900 cmdide - ok
13:01:34.0624 4900 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\drivers\compbatt.sys
13:01:34.0624 4900 Compbatt - ok
13:01:34.0639 4900 COMSysApp - ok
13:01:34.0655 4900 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
13:01:34.0655 4900 crcdisk - ok
13:01:34.0671 4900 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
13:01:34.0671 4900 Crusoe - ok
13:01:34.0733 4900 [ F1E8C34892336D33EDDCDFE44E474F64 ] CryptSvc C:\Windows\system32\cryptsvc.dll
13:01:34.0733 4900 CryptSvc - ok
13:01:34.0842 4900 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
13:01:34.0858 4900 cvhsvc - ok
13:01:34.0967 4900 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
13:01:34.0983 4900 DcomLaunch - ok
13:01:35.0029 4900 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
13:01:35.0029 4900 DfsC - ok
13:01:35.0139 4900 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
13:01:35.0185 4900 DFSR - ok
13:01:35.0263 4900 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
13:01:35.0263 4900 Dhcp - ok
13:01:35.0295 4900 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
13:01:35.0295 4900 disk - ok
13:01:35.0341 4900 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
13:01:35.0341 4900 Dnscache - ok
13:01:35.0373 4900 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
13:01:35.0373 4900 dot3svc - ok
13:01:35.0435 4900 [ 4F59C172C094E1A1D46463A8DC061CBD ] Dot4 C:\Windows\system32\DRIVERS\Dot4.sys
13:01:35.0435 4900 Dot4 - ok
13:01:35.0451 4900 [ 80BF3BA09F6F2523C8F6B7CC6DBF7BD5 ] Dot4Print C:\Windows\system32\DRIVERS\Dot4Prt.sys
13:01:35.0451 4900 Dot4Print - ok
13:01:35.0451 4900 [ C55004CA6B419B6695970DFE849B122F ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys
13:01:35.0451 4900 dot4usb - ok
13:01:35.0513 4900 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
13:01:35.0513 4900 DPS - ok
13:01:35.0575 4900 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
13:01:35.0575 4900 drmkaud - ok
13:01:35.0622 4900 [ F35B5D0CC142B87E687FC504BAA69D82 ] dsiarhwprog C:\Windows\system32\Drivers\dsiarhwprog.sys
13:01:35.0622 4900 dsiarhwprog - ok
13:01:35.0653 4900 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
13:01:35.0685 4900 DXGKrnl - ok
13:01:35.0700 4900 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
13:01:35.0700 4900 E1G60 - ok
13:01:35.0763 4900 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
13:01:35.0763 4900 EapHost - ok
13:01:35.0825 4900 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
13:01:35.0825 4900 Ecache - ok
13:01:35.0887 4900 [ 85B8B4032A895A746D46A288A9B30DED ] eeCtrl C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
13:01:35.0903 4900 eeCtrl - ok
13:01:35.0934 4900 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
13:01:35.0934 4900 ehRecvr - ok
13:01:35.0950 4900 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
13:01:35.0950 4900 ehSched - ok
13:01:35.0950 4900 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
13:01:35.0965 4900 ehstart - ok
13:01:36.0012 4900 [ B8EAC99B14772BDC36CA963AED109FA2 ] ElRawDisk C:\Windows\system32\drivers\rsdrv.sys
13:01:36.0012 4900 ElRawDisk - ok
13:01:36.0059 4900 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
13:01:36.0075 4900 elxstor - ok
13:01:36.0121 4900 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
13:01:36.0121 4900 EMDMgmt - ok
13:01:36.0137 4900 EraserUtilDrvI10 - ok
13:01:36.0215 4900 [ B5A8A04A6E5B4E86B95B1553AA918F5F ] EraserUtilRebootDrv C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
13:01:36.0215 4900 EraserUtilRebootDrv - ok
13:01:36.0277 4900 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
13:01:36.0277 4900 ErrDev - ok
13:01:36.0371 4900 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
13:01:36.0371 4900 EventSystem - ok
13:01:36.0433 4900 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
13:01:36.0449 4900 exfat - ok
13:01:36.0480 4900 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
13:01:36.0480 4900 fastfat - ok
13:01:36.0543 4900 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
13:01:36.0558 4900 fdc - ok
13:01:36.0574 4900 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
13:01:36.0574 4900 fdPHost - ok
13:01:36.0589 4900 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
13:01:36.0589 4900 FDResPub - ok
13:01:36.0605 4900 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
13:01:36.0605 4900 FileInfo - ok
13:01:36.0621 4900 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
13:01:36.0621 4900 Filetrace - ok
13:01:36.0621 4900 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
13:01:36.0621 4900 flpydisk - ok
13:01:36.0652 4900 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
13:01:36.0667 4900 FltMgr - ok
13:01:36.0761 4900 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll
13:01:36.0777 4900 FontCache - ok
13:01:36.0839 4900 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
13:01:36.0839 4900 FontCache3.0.0.0 - ok
13:01:36.0901 4900 [ D909075FA72C090F27AA926C32CB4612 ] fssfltr C:\Windows\system32\DRIVERS\fssfltr.sys
13:01:36.0901 4900 fssfltr - ok
13:01:37.0026 4900 [ 4CE9DAC1518FF7E77BD213E6394B9D77 ] fsssvc C:\Program Files\Windows Live\Family Safety\fsssvc.exe
13:01:37.0042 4900 fsssvc - ok
13:01:37.0089 4900 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
13:01:37.0089 4900 Fs_Rec - ok
13:01:37.0120 4900 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
13:01:37.0120 4900 gagp30kx - ok
13:01:37.0151 4900 [ 551D463E4CCEB5240234DA6718C93A44 ] GameConsoleService C:\Program Files\HP Games\HP Game Console\GameConsoleService.exe
13:01:37.0167 4900 GameConsoleService - ok
13:01:37.0213 4900 [ 5AE3A887ECE5BBB72CFAB273C2FD1CFA ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
13:01:37.0213 4900 GEARAspiWDM - ok
13:01:37.0245 4900 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
13:01:37.0260 4900 gpsvc - ok
13:01:37.0338 4900 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
13:01:37.0338 4900 gupdate - ok
13:01:37.0354 4900 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
13:01:37.0354 4900 gupdatem - ok
13:01:37.0416 4900 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
13:01:37.0432 4900 HDAudBus - ok
13:01:37.0494 4900 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
13:01:37.0494 4900 HidBth - ok
13:01:37.0510 4900 [ D8DF3722D5E961BAA1292AA2F12827E2 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
13:01:37.0510 4900 HidIr - ok
13:01:37.0525 4900 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\System32\hidserv.dll
13:01:37.0541 4900 hidserv - ok
13:01:37.0557 4900 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
13:01:37.0557 4900 HidUsb - ok
13:01:37.0588 4900 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
13:01:37.0588 4900 hkmsvc - ok
13:01:37.0666 4900 [ AA9EF0B395097F24D289F64445B2FD2E ] HP Health Check Service c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
13:01:37.0666 4900 HP Health Check Service - ok
13:01:37.0666 4900 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
13:01:37.0666 4900 HpCISSs - ok
13:01:37.0791 4900 [ 0A3C6AA4A9FC38C20BA4EAC2C3351C05 ] hpqcxs08 C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
13:01:37.0791 4900 hpqcxs08 - ok
13:01:37.0822 4900 [ F3F72A2A86C22610BCA5439FA789DD52 ] hpqddsvc C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
13:01:37.0822 4900 hpqddsvc - ok
13:01:37.0978 4900 [ E82871D75565219A7E28C6B14572EF63 ] HsdService C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe
13:01:38.0009 4900 HsdService - ok
13:01:38.0056 4900 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys
13:01:38.0071 4900 HTTP - ok
13:01:38.0134 4900 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
13:01:38.0134 4900 i2omp - ok
13:01:38.0196 4900 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
13:01:38.0196 4900 i8042prt - ok
13:01:38.0212 4900 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
13:01:38.0212 4900 iaStorV - ok
13:01:38.0259 4900 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
13:01:38.0274 4900 idsvc - ok
13:01:38.0415 4900 [ 404FB2AAF532BC7BBACC8880BE401C74 ] IDSVix86 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\IPSDefs\20130113.001\IDSvix86.sys
13:01:38.0415 4900 IDSVix86 - ok
13:01:38.0446 4900 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
13:01:38.0446 4900 iirsp - ok
13:01:38.0493 4900 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
13:01:38.0493 4900 IKEEXT - ok
13:01:38.0602 4900 [ 84ED2154239F9D013BBD3220755ADA8B ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
13:01:38.0680 4900 IntcAzAudAddService - ok
13:01:38.0727 4900 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
13:01:38.0727 4900 intelide - ok
13:01:38.0742 4900 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
13:01:38.0742 4900 intelppm - ok
13:01:38.0773 4900 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
13:01:38.0773 4900 IPBusEnum - ok
13:01:38.0789 4900 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:01:38.0789 4900 IpFilterDriver - ok
13:01:38.0820 4900 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
13:01:38.0820 4900 iphlpsvc - ok
13:01:38.0820 4900 IpInIp - ok
13:01:38.0883 4900 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
13:01:38.0883 4900 IPMIDRV - ok
13:01:38.0898 4900 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
13:01:38.0898 4900 IPNAT - ok
13:01:38.0976 4900 [ 178FE38B7740F598391EB2F51AE4CCAC ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
13:01:38.0992 4900 iPod Service - ok
13:01:39.0039 4900 [ E50A95179211B12946F7E035D60AF560 ] irda C:\Windows\system32\DRIVERS\irda.sys
13:01:39.0054 4900 irda - ok
13:01:39.0070 4900 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
13:01:39.0070 4900 IRENUM - ok
13:01:39.0085 4900 [ CBB0D940221A281BCFEAEA695BD1CDA5 ] Irmon C:\Windows\System32\irmon.dll
13:01:39.0085 4900 Irmon - ok
13:01:39.0101 4900 [ 5896B5FF6332AB2BE1582523E9656A67 ] irsir C:\Windows\system32\DRIVERS\irsir.sys
13:01:39.0117 4900 irsir - ok
13:01:39.0117 4900 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
13:01:39.0117 4900 isapnp - ok
13:01:39.0179 4900 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
13:01:39.0179 4900 iScsiPrt - ok
13:01:39.0195 4900 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
13:01:39.0210 4900 iteatapi - ok
13:01:39.0210 4900 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
13:01:39.0210 4900 iteraid - ok
13:01:39.0226 4900 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
13:01:39.0226 4900 kbdclass - ok
13:01:39.0257 4900 [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
13:01:39.0257 4900 kbdhid - ok
13:01:39.0288 4900 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
13:01:39.0288 4900 KeyIso - ok
13:01:39.0335 4900 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
13:01:39.0335 4900 KSecDD - ok
13:01:39.0397 4900 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
13:01:39.0397 4900 KtmRm - ok
13:01:39.0429 4900 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\System32\srvsvc.dll
13:01:39.0429 4900 LanmanServer - ok
13:01:39.0460 4900 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:01:39.0460 4900 LanmanWorkstation - ok
13:01:39.0507 4900 [ DFEFF67508D3A9AEB1A85D7B0F513B24 ] LightScribeService c:\Program Files\Common Files\LightScribe\LSSrvc.exe
13:01:39.0507 4900 LightScribeService - ok
13:01:39.0522 4900 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
13:01:39.0538 4900 lltdio - ok
13:01:39.0553 4900 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
13:01:39.0553 4900 lltdsvc - ok
13:01:39.0569 4900 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
13:01:39.0569 4900 lmhosts - ok
13:01:39.0569 4900 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
13:01:39.0585 4900 LSI_FC - ok
13:01:39.0585 4900 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
13:01:39.0585 4900 LSI_SAS - ok
13:01:39.0600 4900 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
13:01:39.0600 4900 LSI_SCSI - ok
13:01:39.0616 4900 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
13:01:39.0616 4900 luafv - ok
13:01:39.0678 4900 [ 7521C0C58EE91BE90B6CC33E792D10C7 ] LVRS C:\Windows\system32\DRIVERS\lvrs.sys
13:01:39.0694 4900 LVRS - ok
13:01:39.0803 4900 [ 37E57C48AF530DF01CDD4E8A2AD77B51 ] LVUVC C:\Windows\system32\DRIVERS\lvuvc.sys
13:01:39.0881 4900 LVUVC - ok
13:01:39.0943 4900 [ E6CB119EF2E148EAA1A247343550756E ] McciCMService C:\Program Files\Common Files\Motive\McciCMService.exe
13:01:39.0943 4900 McciCMService - ok
13:01:39.0975 4900 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
13:01:39.0975 4900 Mcx2Svc - ok
13:01:40.0037 4900 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
13:01:40.0037 4900 megasas - ok
13:01:40.0053 4900 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
13:01:40.0068 4900 MegaSR - ok
13:01:40.0115 4900 [ 3412A454FDF9F68341AB80F3EE79EDAB ] MHIKEY10 C:\Windows\system32\Drivers\MHIKEY10.sys
13:01:40.0115 4900 MHIKEY10 - ok
13:01:40.0131 4900 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
13:01:40.0131 4900 MMCSS - ok
13:01:40.0146 4900 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
13:01:40.0146 4900 Modem - ok
13:01:40.0193 4900 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
13:01:40.0193 4900 monitor - ok
13:01:40.0209 4900 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
13:01:40.0224 4900 mouclass - ok
13:01:40.0240 4900 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
13:01:40.0240 4900 mouhid - ok
13:01:40.0240 4900 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
13:01:40.0240 4900 MountMgr - ok
13:01:40.0318 4900 [ 730A519505621DF46BCBF9CDAC9FB6AD ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
13:01:40.0318 4900 MozillaMaintenance - ok
13:01:40.0365 4900 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
13:01:40.0365 4900 mpio - ok
13:01:40.0380 4900 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
13:01:40.0380 4900 mpsdrv - ok
13:01:40.0411 4900 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
13:01:40.0427 4900 MpsSvc - ok
13:01:40.0489 4900 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
13:01:40.0489 4900 Mraid35x - ok
13:01:40.0521 4900 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
13:01:40.0521 4900 MRxDAV - ok
13:01:40.0536 4900 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
13:01:40.0536 4900 mrxsmb - ok
13:01:40.0567 4900 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:01:40.0567 4900 mrxsmb10 - ok
13:01:40.0583 4900 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:01:40.0583 4900 mrxsmb20 - ok
13:01:40.0599 4900 [ 28023E86F17001F7CD9B15A5BC9AE07D ] msahci C:\Windows\system32\drivers\msahci.sys
13:01:40.0599 4900 msahci - ok
13:01:40.0614 4900 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
13:01:40.0614 4900 msdsm - ok
13:01:40.0630 4900 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
13:01:40.0630 4900 MSDTC - ok
13:01:40.0645 4900 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
13:01:40.0645 4900 Msfs - ok
13:01:40.0645 4900 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
13:01:40.0645 4900 msisadrv - ok
13:01:40.0692 4900 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
13:01:40.0708 4900 MSiSCSI - ok
13:01:40.0708 4900 msiserver - ok
13:01:40.0755 4900 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
13:01:40.0755 4900 MSKSSRV - ok
13:01:40.0770 4900 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
13:01:40.0770 4900 MSPCLOCK - ok
13:01:40.0770 4900 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
13:01:40.0770 4900 MSPQM - ok
13:01:40.0801 4900 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
13:01:40.0817 4900 MsRPC - ok
13:01:40.0817 4900 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
13:01:40.0817 4900 mssmbios - ok
13:01:40.0833 4900 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
13:01:40.0833 4900 MSTEE - ok
13:01:40.0864 4900 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
13:01:40.0864 4900 Mup - ok
13:01:41.0098 4900 [ 4A9258B9597A31DB68EC9740F3A8A70B ] N360 C:\Program Files\Norton 360\Engine\20.2.0.19\ccSvcHst.exe
13:01:41.0098 4900 N360 - ok
13:01:41.0129 4900 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
13:01:41.0145 4900 napagent - ok
13:01:41.0207 4900 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
13:01:41.0207 4900 NativeWifiP - ok
13:01:41.0316 4900 [ 8E4C77AD9BB279900C00F870CC0C674B ] NAVENG C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\VirusDefs\20130114.004\NAVENG.SYS
13:01:41.0316 4900 NAVENG - ok
13:01:41.0379 4900 [ 826F699B69E88A3920C70F344DD42D88 ] NAVEX15 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\VirusDefs\20130114.004\NAVEX15.SYS
13:01:41.0410 4900 NAVEX15 - ok
13:01:41.0488 4900 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
13:01:41.0503 4900 NDIS - ok
13:01:41.0550 4900 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
13:01:41.0550 4900 NdisTapi - ok
13:01:41.0566 4900 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
13:01:41.0581 4900 Ndisuio - ok
13:01:41.0628 4900 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
13:01:41.0628 4900 NdisWan - ok
13:01:41.0644 4900 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
13:01:41.0644 4900 NDProxy - ok
13:01:41.0675 4900 [ 510C138564486FF926A3F773205C63D1 ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
13:01:41.0675 4900 Net Driver HPZ12 - ok
13:01:41.0691 4900 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
13:01:41.0691 4900 NetBIOS - ok
13:01:41.0722 4900 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
13:01:41.0722 4900 netbt - ok
13:01:41.0722 4900 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe
13:01:41.0737 4900 Netlogon - ok
13:01:41.0769 4900 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
13:01:41.0769 4900 Netman - ok
13:01:41.0831 4900 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
13:01:41.0831 4900 netprofm - ok
13:01:41.0878 4900 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
13:01:41.0893 4900 NetTcpPortSharing - ok
13:01:41.0909 4900 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
13:01:41.0909 4900 nfrd960 - ok
13:01:41.0909 4900 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
13:01:41.0925 4900 NlaSvc - ok
13:01:41.0940 4900 Norton PC Checkup Application Launcher - ok
13:01:42.0003 4900 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
13:01:42.0018 4900 Npfs - ok
13:01:42.0018 4900 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
13:01:42.0018 4900 nsi - ok
13:01:42.0034 4900 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
13:01:42.0034 4900 nsiproxy - ok
13:01:42.0205 4900 [ 8D11DA92F83D8C8281689739BEF05FD5 ] NSM C:\Program Files\Norton Family\Engine\2.6.0.43\ccSvcHst.exe
13:01:42.0221 4900 NSM - ok
13:01:42.0299 4900 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
13:01:42.0330 4900 Ntfs - ok
13:01:42.0408 4900 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
13:01:42.0439 4900 ntrigdigi - ok
13:01:42.0486 4900 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
13:01:42.0486 4900 Null - ok
13:01:42.0595 4900 [ D958A2B5F6AD5C3B8CCDC4D7DA62466C ] NVENETFD C:\Windows\system32\DRIVERS\nvmfdx32.sys
13:01:42.0611 4900 NVENETFD - ok
13:01:43.0266 4900 [ 09F5E33F91E186037262355B0BA72913 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
13:01:43.0391 4900 nvlddmkm - ok
13:01:43.0422 4900 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
13:01:43.0438 4900 nvraid - ok
13:01:43.0469 4900 [ 5DD1242CABC1EF8DCE4438D72D72A436 ] nvrd32 C:\Windows\system32\drivers\nvrd32.sys
13:01:43.0469 4900 nvrd32 - ok
13:01:43.0500 4900 [ 62754E376185EACBB73D06FEA0FFC54A ] nvsmu C:\Windows\system32\drivers\nvsmu.sys
13:01:43.0500 4900 nvsmu - ok
13:01:43.0500 4900 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
13:01:43.0500 4900 nvstor - ok
13:01:43.0531 4900 [ BB4DD678706510D9249EED1DA0219900 ] nvstor32 C:\Windows\system32\drivers\nvstor32.sys
13:01:43.0531 4900 nvstor32 - ok
13:01:43.0594 4900 [ F531F9B76E3E2595049F145160D280DE ] nvsvc C:\Windows\system32\nvvsvc.exe
13:01:43.0609 4900 nvsvc - ok
13:01:43.0609 4900 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
13:01:43.0609 4900 nv_agp - ok
13:01:43.0625 4900 NwlnkFlt - ok
13:01:43.0625 4900 NwlnkFwd - ok
13:01:43.0672 4900 [ BE32DA025A0BE1878F0EE8D6D9386CD5 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
13:01:43.0672 4900 ohci1394 - ok
13:01:43.0703 4900 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:01:43.0703 4900 ose - ok
13:01:43.0859 4900 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
13:01:43.0921 4900 osppsvc - ok
13:01:43.0968 4900 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
13:01:43.0968 4900 p2pimsvc - ok
13:01:43.0984 4900 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
13:01:43.0999 4900 p2psvc - ok
13:01:44.0015 4900 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
13:01:44.0015 4900 Parport - ok
13:01:44.0031 4900 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
13:01:44.0031 4900 partmgr - ok
13:01:44.0046 4900 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
13:01:44.0046 4900 Parvdm - ok
13:01:44.0062 4900 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
13:01:44.0062 4900 PcaSvc - ok
13:01:44.0155 4900 [ 2F86BE1818C2D7AC90478E3323EE7FCB ] PCCUJobMgr C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
13:01:44.0171 4900 PCCUJobMgr - ok
13:01:44.0202 4900 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
13:01:44.0202 4900 pci - ok
13:01:44.0218 4900 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys
13:01:44.0218 4900 pciide - ok
13:01:44.0233 4900 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
13:01:44.0233 4900 pcmcia - ok
13:01:44.0265 4900 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
13:01:44.0280 4900 PEAUTH - ok
13:01:44.0358 4900 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
13:01:44.0374 4900 pla - ok
13:01:44.0499 4900 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
13:01:44.0499 4900 PlugPlay - ok
13:01:44.0530 4900 [ 37E5E8FFBAD35605DAEEC3224EA0E465 ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
13:01:44.0545 4900 Pml Driver HPZ12 - ok
13:01:44.0561 4900 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
13:01:44.0561 4900 PNRPAutoReg - ok
13:01:44.0670 4900 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
13:01:44.0686 4900 PNRPsvc - ok
13:01:44.0717 4900 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
13:01:44.0717 4900 PolicyAgent - ok
13:01:44.0733 4900 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
13:01:44.0748 4900 PptpMiniport - ok
13:01:44.0748 4900 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\DRIVERS\processr.sys
13:01:44.0748 4900 Processor - ok
13:01:44.0779 4900 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
13:01:44.0779 4900 ProfSvc - ok
13:01:44.0795 4900 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
13:01:44.0795 4900 ProtectedStorage - ok
13:01:44.0826 4900 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
13:01:44.0826 4900 PSched - ok
13:01:44.0889 4900 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
13:01:44.0904 4900 ql2300 - ok
13:01:44.0920 4900 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
13:01:44.0920 4900 ql40xx - ok
13:01:44.0951 4900 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
13:01:44.0951 4900 QWAVE - ok
13:01:44.0967 4900 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
13:01:44.0967 4900 QWAVEdrv - ok
13:01:44.0967 4900 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
13:01:44.0967 4900 RasAcd - ok
13:01:44.0982 4900 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
13:01:44.0998 4900 RasAuto - ok
13:01:45.0013 4900 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
13:01:45.0013 4900 Rasl2tp - ok
13:01:45.0045 4900 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
13:01:45.0045 4900 RasMan - ok
13:01:45.0060 4900 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
13:01:45.0060 4900 RasPppoe - ok
13:01:45.0091 4900 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
13:01:45.0091 4900 RasSstp - ok
13:01:45.0123 4900 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
13:01:45.0123 4900 rdbss - ok
13:01:45.0138 4900 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
13:01:45.0154 4900 RDPCDD - ok
13:01:45.0169 4900 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
13:01:45.0169 4900 rdpdr - ok
13:01:45.0169 4900 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
13:01:45.0185 4900 RDPENCDD - ok
13:01:45.0216 4900 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
13:01:45.0232 4900 RDPWD - ok
13:01:45.0247 4900 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
13:01:45.0263 4900 RemoteAccess - ok
13:01:45.0279 4900 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
13:01:45.0279 4900 RemoteRegistry - ok
13:01:45.0310 4900 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
13:01:45.0310 4900 RpcLocator - ok
13:01:45.0372 4900 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\System32\rpcss.dll
13:01:45.0388 4900 RpcSs - ok
13:01:45.0435 4900 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
13:01:45.0435 4900 rspndr - ok
13:01:45.0450 4900 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe
13:01:45.0450 4900 SamSs - ok
13:01:45.0513 4900 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
13:01:45.0513 4900 sbp2port - ok
13:01:45.0544 4900 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
13:01:45.0559 4900 SCardSvr - ok
13:01:45.0622 4900 [ BB68443901FF680C799E8F4A464ECE39 ] SCDEmu C:\Windows\system32\drivers\SCDEmu.sys
13:01:45.0622 4900 SCDEmu - ok
13:01:45.0653 4900 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll
13:01:45.0669 4900 Schedule - ok
13:01:45.0715 4900 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
13:01:45.0715 4900 SCPolicySvc - ok
13:01:45.0731 4900 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
13:01:45.0731 4900 SDRSVC - ok
13:01:45.0747 4900 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
13:01:45.0747 4900 secdrv - ok
13:01:45.0762 4900 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
13:01:45.0762 4900 seclogon - ok
13:01:45.0778 4900 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\system32\sens.dll
13:01:45.0778 4900 SENS - ok
13:01:45.0793 4900 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys
13:01:45.0793 4900 Serenum - ok
13:01:45.0809 4900 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
13:01:45.0809 4900 Serial - ok
13:01:45.0825 4900 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
13:01:45.0825 4900 sermouse - ok
13:01:46.0074 4900 [ 9910F4097EECBF561B257D614ADEF09A ] ServicepointService C:\Program Files\Windstream\Service Agent\ServicepointService.exe
13:01:46.0215 4900 ServicepointService - ok
13:01:46.0246 4900 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
13:01:46.0246 4900 SessionEnv - ok
13:01:46.0246 4900 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
13:01:46.0261 4900 sffdisk - ok
13:01:46.0261 4900 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
13:01:46.0261 4900 sffp_mmc - ok
13:01:46.0277 4900 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
13:01:46.0277 4900 sffp_sd - ok
13:01:46.0293 4900 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
13:01:46.0293 4900 sfloppy - ok
13:01:46.0324 4900 [ D9B734638DD8DBA9D59AAD3189CD0FAD ] Sftfs C:\Windows\system32\DRIVERS\Sftfslh.sys
13:01:46.0355 4900 Sftfs - ok
13:01:46.0371 4900 sftlist - ok
13:01:46.0402 4900 [ 2F61BD46C0BFF4EB36E1E359CA17BFC5 ] Sftplay C:\Windows\system32\DRIVERS\Sftplaylh.sys
13:01:46.0402 4900 Sftplay - ok
13:01:46.0417 4900 [ 518BAC0179F94304F422696B47C0EC12 ] Sftredir C:\Windows\system32\DRIVERS\Sftredirlh.sys
13:01:46.0417 4900 Sftredir - ok
13:01:46.0433 4900 [ 747325236D88B3F05FFD27FF9EC711C5 ] Sftvol C:\Windows\system32\DRIVERS\Sftvollh.sys
13:01:46.0433 4900 Sftvol - ok
13:01:46.0464 4900 [ A5812F0281CA5081BF696626F9BF324D ] sftvsa C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
13:01:46.0464 4900 sftvsa - ok
13:01:46.0542 4900 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
13:01:46.0542 4900 SharedAccess - ok
13:01:46.0573 4900 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:01:46.0573 4900 ShellHWDetection - ok
13:01:46.0605 4900 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
13:01:46.0605 4900 sisagp - ok
13:01:46.0620 4900 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
13:01:46.0620 4900 SiSRaid2 - ok
13:01:46.0620 4900 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
13:01:46.0636 4900 SiSRaid4 - ok
13:01:46.0714 4900 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
13:01:46.0714 4900 SkypeUpdate - ok
13:01:46.0823 4900 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
13:01:46.0870 4900 slsvc - ok
13:01:46.0932 4900 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
13:01:46.0932 4900 SLUINotify - ok
13:01:46.0963 4900 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
13:01:46.0963 4900 Smb - ok
13:01:46.0995 4900 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
13:01:46.0995 4900 SNMPTRAP - ok
13:01:47.0026 4900 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
13:01:47.0026 4900 spldr - ok
13:01:47.0041 4900 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe
13:01:47.0057 4900 Spooler - ok
13:01:47.0151 4900 [ 26C1B59C80FEF94B025DF5C3C1B791A7 ] SRTSP C:\Windows\System32\Drivers\N360\1402000.013\SRTSP.SYS
13:01:47.0166 4900 SRTSP - ok
13:01:47.0197 4900 [ 21AC3AE81E8263061624C4ED3B11509A ] SRTSPX C:\Windows\system32\drivers\N360\1402000.013\SRTSPX.SYS
13:01:47.0197 4900 SRTSPX - ok
13:01:47.0229 4900 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys
13:01:47.0244 4900 srv - ok
13:01:47.0275 4900 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
13:01:47.0275 4900 srv2 - ok
13:01:47.0307 4900 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
13:01:47.0307 4900 srvnet - ok
13:01:47.0369 4900 [ D5DFFEAA1E15D4EFFABB9D9A3068AC5B ] sscdbus C:\Windows\system32\DRIVERS\sscdbus.sys
13:01:47.0369 4900 sscdbus - ok
13:01:47.0400 4900 [ 8A1BE0C347814F482F493AEA619D57F6 ] sscdmdfl C:\Windows\system32\DRIVERS\sscdmdfl.sys
13:01:47.0400 4900 sscdmdfl - ok
13:01:47.0431 4900 [ 5AB0B1987F682A59B15B78F84C6AD7D0 ] sscdmdm C:\Windows\system32\DRIVERS\sscdmdm.sys
13:01:47.0431 4900 sscdmdm - ok
13:01:47.0447 4900 [ 751E66EB32EFA80633B80F5D7FF0A1D8 ] sscdserd C:\Windows\system32\DRIVERS\sscdserd.sys
13:01:47.0463 4900 sscdserd - ok
13:01:47.0478 4900 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
13:01:47.0478 4900 SSDPSRV - ok
13:01:47.0556 4900 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
13:01:47.0556 4900 SstpSvc - ok
13:01:47.0619 4900 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
13:01:47.0634 4900 stisvc - ok
13:01:47.0697 4900 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
13:01:47.0697 4900 swenum - ok
13:01:47.0728 4900 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
13:01:47.0728 4900 swprv - ok
13:01:47.0743 4900 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
13:01:47.0743 4900 Symc8xx - ok
13:01:47.0775 4900 [ FB69A67FEEE3026C7F99774A1C405326 ] SymDS C:\Windows\system32\drivers\N360\1402000.013\SYMDS.SYS
13:01:47.0775 4900 SymDS - ok
13:01:47.0806 4900 [ 28C5FAFA7FD1C522B8DCD59694D39412 ] SymEFA C:\Windows\system32\drivers\N360\1402000.013\SYMEFA.SYS
13:01:47.0837 4900 SymEFA - ok
13:01:47.0884 4900 [ C940F10C31E2C60CC967FFD6A370720C ] SymEvent C:\Windows\system32\Drivers\SYMEVENT.SYS
13:01:47.0884 4900 SymEvent - ok
13:01:47.0915 4900 [ 8C9B9036E301A9965CF15BEC91C58A12 ] SymIRON C:\Windows\system32\drivers\N360\1402000.013\Ironx86.SYS
13:01:47.0915 4900 SymIRON - ok
13:01:48.0009 4900 [ BB77096DC7F6E408D44C0BC6D2641850 ] SYMRDR_{78CA3BF0-9C3B-40e1-B46D-38C877EF059A} C:\Windows\system32\drivers\NSM\0206000.02B\SymRdr.SYS
13:01:48.0024 4900 SYMRDR_{78CA3BF0-9C3B-40e1-B46D-38C877EF059A} - ok
13:01:48.0040 4900 [ 93DE018EC6FBAA9A58FF9F2EB9198092 ] SYMTDIv C:\Windows\System32\Drivers\N360\1402000.013\SYMTDIV.SYS
13:01:48.0040 4900 SYMTDIv - ok
13:01:48.0071 4900 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
13:01:48.0071 4900 Sym_hi - ok
13:01:48.0087 4900 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
13:01:48.0087 4900 Sym_u3 - ok
13:01:48.0118 4900 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
13:01:48.0133 4900 SysMain - ok
13:01:48.0149 4900 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
13:01:48.0149 4900 TabletInputService - ok
13:01:48.0180 4900 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
13:01:48.0180 4900 TapiSrv - ok
13:01:48.0196 4900 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
13:01:48.0196 4900 TBS - ok
13:01:48.0243 4900 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
13:01:48.0274 4900 Tcpip - ok
13:01:48.0305 4900 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
13:01:48.0321 4900 Tcpip6 - ok
13:01:48.0352 4900 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
13:01:48.0352 4900 tcpipreg - ok
13:01:48.0383 4900 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
13:01:48.0383 4900 TDPIPE - ok
13:01:48.0399 4900 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
13:01:48.0399 4900 TDTCP - ok
13:01:48.0430 4900 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
13:01:48.0445 4900 tdx - ok
13:01:48.0477 4900 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
13:01:48.0477 4900 TermDD - ok
13:01:48.0570 4900 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
13:01:48.0586 4900 TermService - ok
13:01:48.0601 4900 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll
13:01:48.0601 4900 Themes - ok
13:01:48.0617 4900 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
13:01:48.0617 4900 THREADORDER - ok
13:01:48.0633 4900 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
13:01:48.0633 4900 TrkWks - ok
13:01:48.0695 4900 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
13:01:48.0695 4900 TrustedInstaller - ok
13:01:48.0726 4900 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
13:01:48.0726 4900 tssecsrv - ok
13:01:48.0742 4900 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
13:01:48.0742 4900 tunmp - ok
13:01:48.0757 4900 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
13:01:48.0757 4900 tunnel - ok
13:01:48.0773 4900 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
13:01:48.0773 4900 uagp35 - ok
13:01:48.0804 4900 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
13:01:48.0804 4900 udfs - ok
13:01:48.0835 4900 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
13:01:48.0835 4900 UI0Detect - ok
13:01:48.0851 4900 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
13:01:48.0851 4900 uliagpkx - ok
13:01:48.0867 4900 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
13:01:48.0867 4900 uliahci - ok
13:01:48.0882 4900 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
13:01:48.0882 4900 UlSata - ok
13:01:48.0898 4900 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
13:01:48.0898 4900 ulsata2 - ok
13:01:48.0913 4900 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
13:01:48.0913 4900 umbus - ok
13:01:49.0069 4900 [ 927754ABF077AEB5504BE4E0F2C60C1B ] UMVPFSrv C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
13:01:49.0069 4900 UMVPFSrv - ok
13:01:49.0085 4900 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
13:01:49.0085 4900 upnphost - ok
13:01:49.0116 4900 [ 83CAFCB53201BBAC04D822F32438E244 ] USBAAPL C:\Windows\system32\Drivers\usbaapl.sys
13:01:49.0116 4900 USBAAPL - ok
13:01:49.0147 4900 [ 32DB9517628FF0D070682AAB61E688F0 ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
13:01:49.0147 4900 usbaudio - ok
13:01:49.0163 4900 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
13:01:49.0163 4900 usbccgp - ok
13:01:49.0210 4900 [ 32C068EAF37C92D7194EEE1FAA1E7853 ] USBCCID C:\Windows\system32\DRIVERS\usbccid.sys
13:01:49.0210 4900 USBCCID - ok
13:01:49.0225 4900 [ 47B9770EA21436DE4AD5AEA7926E0900 ] usbcir C:\Windows\system32\DRIVERS\usbcir.sys
13:01:49.0225 4900 usbcir - ok
13:01:49.0272 4900 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
13:01:49.0272 4900 usbehci - ok
13:01:49.0288 4900 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
13:01:49.0303 4900 usbhub - ok
13:01:49.0303 4900 [ CE697FEE0D479290D89BEC80DFE793B7 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
13:01:49.0303 4900 usbohci - ok
13:01:49.0319 4900 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
13:01:49.0319 4900 usbprint - ok
13:01:49.0381 4900 [ A508C9BD8724980512136B039BBA65E9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
13:01:49.0381 4900 usbscan - ok
13:01:49.0413 4900 [ D575246188F63DE0ACCF6EAC5FB59E6A ] usbser C:\Windows\system32\DRIVERS\usbser.sys
13:01:49.0413 4900 usbser - ok
13:01:49.0428 4900 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:01:49.0428 4900 USBSTOR - ok
13:01:49.0444 4900 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
13:01:49.0444 4900 usbuhci - ok
13:01:49.0459 4900 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
13:01:49.0459 4900 usbvideo - ok
13:01:49.0491 4900 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
13:01:49.0491 4900 UxSms - ok
13:01:49.0569 4900 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
13:01:49.0584 4900 vds - ok
13:01:49.0631 4900 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
13:01:49.0631 4900 vga - ok
13:01:49.0647 4900 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
13:01:49.0647 4900 VgaSave - ok
13:01:49.0662 4900 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
13:01:49.0662 4900 viaagp - ok
13:01:49.0662 4900 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
13:01:49.0678 4900 ViaC7 - ok
13:01:49.0678 4900 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
13:01:49.0678 4900 viaide - ok
13:01:49.0709 4900 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
13:01:49.0709 4900 volmgr - ok
13:01:49.0725 4900 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
13:01:49.0740 4900 volmgrx - ok
13:01:49.0771 4900 [ 786DB5771F05EF300390399F626BF30A ] volsnap C:\Windows\system32\drivers\volsnap.sys
13:01:49.0771 4900 volsnap - ok
13:01:49.0787 4900 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
13:01:49.0787 4900 vsmraid - ok
13:01:49.0834 4900 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
13:01:49.0849 4900 VSS - ok
13:01:49.0881 4900 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
13:01:49.0881 4900 W32Time - ok
13:01:49.0896 4900 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
13:01:49.0896 4900 WacomPen - ok
13:01:49.0912 4900 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
13:01:49.0912 4900 Wanarp - ok
13:01:49.0912 4900 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
13:01:49.0912 4900 Wanarpv6 - ok
13:01:49.0927 4900 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
13:01:49.0927 4900 wcncsvc - ok
13:01:49.0959 4900 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
13:01:49.0959 4900 WcsPlugInService - ok
13:01:49.0974 4900 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
13:01:49.0974 4900 Wd - ok
13:01:50.0005 4900 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
13:01:50.0021 4900 Wdf01000 - ok
13:01:50.0037 4900 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
13:01:50.0037 4900 WdiServiceHost - ok
13:01:50.0037 4900 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
13:01:50.0037 4900 WdiSystemHost - ok
13:01:50.0068 4900 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
13:01:50.0068 4900 WebClient - ok
13:01:50.0099 4900 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
13:01:50.0115 4900 Wecsvc - ok
13:01:50.0115 4900 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
13:01:50.0115 4900 wercplsupport - ok
13:01:50.0146 4900 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
13:01:50.0146 4900 WerSvc - ok
13:01:50.0193 4900 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
13:01:50.0193 4900 WinDefend - ok
13:01:50.0208 4900 WinHttpAutoProxySvc - ok
13:01:50.0255 4900 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
13:01:50.0255 4900 Winmgmt - ok
13:01:50.0302 4900 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
13:01:50.0333 4900 WinRM - ok
13:01:50.0380 4900 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll
13:01:50.0395 4900 Wlansvc - ok
13:01:50.0458 4900 [ 0A70F4022EC2E14C159EFC4F69AA2477 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
13:01:50.0505 4900 wlidsvc - ok
13:01:50.0536 4900 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
13:01:50.0551 4900 WmiAcpi - ok
13:01:50.0629 4900 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
13:01:50.0629 4900 wmiApSrv - ok
13:01:50.0676 4900 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
13:01:50.0676 4900 WMPNetworkSvc - ok
13:01:50.0707 4900 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll
13:01:50.0707 4900 WPCSvc - ok
13:01:50.0739 4900 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
13:01:50.0739 4900 WPDBusEnum - ok
13:01:50.0801 4900 [ DE9D36F91A4DF3D911626643DEBF11EA ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
13:01:50.0801 4900 WpdUsb - ok
13:01:50.0879 4900 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
13:01:50.0895 4900 WPFFontCache_v0400 - ok
13:01:50.0910 4900 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
13:01:50.0910 4900 ws2ifsl - ok
13:01:50.0941 4900 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\system32\wscsvc.dll
13:01:50.0957 4900 wscsvc - ok
13:01:50.0957 4900 WSearch - ok
13:01:51.0051 4900 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
13:01:51.0082 4900 wuauserv - ok
13:01:51.0113 4900 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
13:01:51.0129 4900 WudfPf - ok
13:01:51.0191 4900 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
13:01:51.0191 4900 WUDFRd - ok
13:01:51.0222 4900 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
13:01:51.0238 4900 wudfsvc - ok
13:01:51.0238 4900 ================ Scan global ===============================
13:01:51.0269 4900 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
13:01:51.0316 4900 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
13:01:51.0331 4900 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
13:01:51.0363 4900 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
13:01:51.0363 4900 [Global] - ok
13:01:51.0363 4900 ================ Scan MBR ==================================
13:01:51.0394 4900 [ 81CD5EC01DB0CE57EDD853F82462EF27 ] \Device\Harddisk0\DR0
13:01:51.0799 4900 \Device\Harddisk0\DR0 - ok
13:01:51.0799 4900 ================ Scan VBR ==================================
13:01:51.0815 4900 [ CEF15918BE2688DEFAA35F41055B3604 ] \Device\Harddisk0\DR0\Partition1
13:01:51.0815 4900 \Device\Harddisk0\DR0\Partition1 - ok
13:01:51.0815 4900 [ 0B0DA37ADE752F88D2202D35A96D330D ] \Device\Harddisk0\DR0\Partition2
13:01:51.0831 4900 \Device\Harddisk0\DR0\Partition2 - ok
13:01:51.0831 4900 ============================================================
13:01:51.0831 4900 Scan finished
13:01:51.0831 4900 ============================================================
13:01:51.0846 2696 Detected object count: 0
13:01:51.0846 2696 Actual detected object count: 0
13:02:27.0227 5168 ============================================================
13:02:27.0227 5168 Scan started
13:02:27.0227 5168 Mode: Manual;
13:02:27.0227 5168 ============================================================
13:02:27.0586 5168 ================ Scan system memory ========================
13:02:27.0586 5168 System memory - ok
13:02:27.0586 5168 ================ Scan services =============================
13:02:28.0163 5168 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
13:02:28.0163 5168 ACPI - ok
13:02:28.0210 5168 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
13:02:28.0225 5168 adp94xx - ok
13:02:28.0225 5168 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
13:02:28.0225 5168 adpahci - ok
13:02:28.0288 5168 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
13:02:28.0288 5168 adpu160m - ok
13:02:28.0366 5168 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
13:02:28.0366 5168 adpu320 - ok
13:02:28.0475 5168 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
13:02:28.0475 5168 AeLookupSvc - ok
13:02:28.0631 5168 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
13:02:28.0631 5168 AFD - ok
13:02:28.0834 5168 [ 48091A2374A69F473273C44951195452 ] AgereModemAudio C:\Program Files\LSI SoftModem\agrsmsvc.exe
13:02:28.0834 5168 AgereModemAudio - ok
13:02:28.0959 5168 [ C6FA08A8CCA9001F3197525B07331715 ] AgereSoftModem C:\Windows\system32\DRIVERS\AGRSM.sys
13:02:28.0959 5168 AgereSoftModem - ok
13:02:28.0990 5168 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
13:02:28.0990 5168 agp440 - ok
13:02:29.0037 5168 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
13:02:29.0037 5168 aic78xx - ok
13:02:29.0068 5168 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
13:02:29.0068 5168 ALG - ok
13:02:29.0099 5168 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
13:02:29.0099 5168 aliide - ok
13:02:29.0115 5168 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
13:02:29.0115 5168 amdagp - ok
13:02:29.0115 5168 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
13:02:29.0115 5168 amdide - ok
13:02:29.0130 5168 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
13:02:29.0130 5168 AmdK7 - ok
13:02:29.0146 5168 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
13:02:29.0146 5168 AmdK8 - ok
13:02:29.0161 5168 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
13:02:29.0161 5168 Appinfo - ok
13:02:29.0255 5168 [ 3DEBBECF665DCDDE3A95D9B902010817 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
13:02:29.0255 5168 Apple Mobile Device - ok
13:02:29.0271 5168 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
13:02:29.0271 5168 arc - ok
13:02:29.0286 5168 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
13:02:29.0286 5168 arcsas - ok
13:02:29.0302 5168 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
13:02:29.0302 5168 AsyncMac - ok
13:02:29.0349 5168 [ 2D9C903DC76A66813D350A562DE40ED9 ] atapi C:\Windows\system32\drivers\atapi.sys
13:02:29.0349 5168 atapi - ok
13:02:29.0411 5168 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
13:02:29.0411 5168 AudioEndpointBuilder - ok
13:02:29.0427 5168 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
13:02:29.0427 5168 Audiosrv - ok
13:02:29.0458 5168 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
13:02:29.0458 5168 Beep - ok
13:02:29.0583 5168 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
13:02:29.0583 5168 BFE - ok
13:02:30.0129 5168 [ 9DFFCB249663AA3C2ECB67202280054E ] BHDrvx86 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\BASHDefs\20130107.001\BHDrvx86.sys
13:02:30.0144 5168 BHDrvx86 - ok
13:02:30.0191 5168 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\system32\qmgr.dll
13:02:30.0207 5168 BITS - ok
13:02:30.0222 5168 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
13:02:30.0222 5168 blbdrive - ok
13:02:30.0316 5168 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
13:02:30.0316 5168 Bonjour Service - ok
13:02:30.0378 5168 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
13:02:30.0378 5168 bowser - ok
13:02:30.0456 5168 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
13:02:30.0456 5168 BrFiltLo - ok
13:02:30.0503 5168 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
13:02:30.0503 5168 BrFiltUp - ok
13:02:30.0581 5168 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
13:02:30.0581 5168 Browser - ok
13:02:30.0628 5168 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
13:02:30.0628 5168 Brserid - ok
13:02:30.0675 5168 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
13:02:30.0675 5168 BrSerWdm - ok
13:02:30.0721 5168 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
13:02:30.0721 5168 BrUsbMdm - ok
13:02:30.0768 5168 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
13:02:30.0768 5168 BrUsbSer - ok
13:02:30.0799 5168 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
13:02:30.0799 5168 BTHMODEM - ok
13:02:30.0971 5168 [ 1277AD8F053CC60C17CAFAB411F3CF40 ] ccSet_N360 C:\Windows\system32\drivers\N360\1402000.013\ccSetx86.sys
13:02:30.0971 5168 ccSet_N360 - ok
13:02:31.0065 5168 [ 41CD31307E054F878EA3FD7F7D2C2922 ] ccSet_NSM C:\Windows\system32\drivers\NSM\0206000.02B\ccSetx86.sys
13:02:31.0065 5168 ccSet_NSM - ok
13:02:31.0096 5168 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
13:02:31.0096 5168 cdfs - ok
13:02:31.0127 5168 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
13:02:31.0127 5168 cdrom - ok
13:02:31.0189 5168 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
13:02:31.0189 5168 CertPropSvc - ok
13:02:31.0221 5168 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\DRIVERS\circlass.sys
13:02:31.0221 5168 circlass - ok
13:02:31.0252 5168 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
13:02:31.0252 5168 CLFS - ok
13:02:31.0486 5168 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:02:31.0486 5168 clr_optimization_v2.0.50727_32 - ok
13:02:31.0735 5168 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:02:31.0735 5168 clr_optimization_v4.0.30319_32 - ok
13:02:31.0845 5168 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
13:02:31.0845 5168 cmdide - ok
13:02:31.0907 5168 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\drivers\compbatt.sys
13:02:31.0907 5168 Compbatt - ok
13:02:31.0907 5168 COMSysApp - ok
13:02:31.0954 5168 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
13:02:31.0954 5168 crcdisk - ok
13:02:32.0001 5168 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
13:02:32.0001 5168 Crusoe - ok
13:02:32.0110 5168 [ F1E8C34892336D33EDDCDFE44E474F64 ] CryptSvc C:\Windows\system32\cryptsvc.dll
13:02:32.0110 5168 CryptSvc - ok
13:02:32.0235 5168 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
13:02:32.0250 5168 cvhsvc - ok
13:02:32.0281 5168 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
13:02:32.0281 5168 DcomLaunch - ok
13:02:32.0359 5168 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
13:02:32.0359 5168 DfsC - ok
13:02:32.0765 5168 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
13:02:32.0781 5168 DFSR - ok
13:02:32.0874 5168 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
13:02:32.0874 5168 Dhcp - ok
13:02:32.0968 5168 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
13:02:32.0968 5168 disk - ok
13:02:33.0061 5168 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
13:02:33.0061 5168 Dnscache - ok
13:02:33.0139 5168 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
13:02:33.0139 5168 dot3svc - ok
13:02:33.0186 5168 [ 4F59C172C094E1A1D46463A8DC061CBD ] Dot4 C:\Windows\system32\DRIVERS\Dot4.sys
13:02:33.0186 5168 Dot4 - ok
13:02:33.0217 5168 [ 80BF3BA09F6F2523C8F6B7CC6DBF7BD5 ] Dot4Print C:\Windows\system32\DRIVERS\Dot4Prt.sys
13:02:33.0217 5168 Dot4Print - ok
13:02:33.0264 5168 [ C55004CA6B419B6695970DFE849B122F ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys
13:02:33.0264 5168 dot4usb - ok
13:02:33.0280 5168 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
13:02:33.0295 5168 DPS - ok
13:02:33.0342 5168 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
13:02:33.0342 5168 drmkaud - ok
13:02:33.0420 5168 [ F35B5D0CC142B87E687FC504BAA69D82 ] dsiarhwprog C:\Windows\system32\Drivers\dsiarhwprog.sys
13:02:33.0420 5168 dsiarhwprog - ok
13:02:33.0623 5168 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
13:02:33.0623 5168 DXGKrnl - ok
13:02:33.0654 5168 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
13:02:33.0654 5168 E1G60 - ok
13:02:33.0670 5168 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
13:02:33.0670 5168 EapHost - ok
13:02:33.0763 5168 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
13:02:33.0763 5168 Ecache - ok
13:02:33.0904 5168 [ 85B8B4032A895A746D46A288A9B30DED ] eeCtrl C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
13:02:33.0904 5168 eeCtrl - ok
13:02:34.0138 5168 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
13:02:34.0138 5168 ehRecvr - ok
13:02:34.0153 5168 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
13:02:34.0153 5168 ehSched - ok
13:02:34.0169 5168 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
13:02:34.0169 5168 ehstart - ok
13:02:34.0309 5168 [ B8EAC99B14772BDC36CA963AED109FA2 ] ElRawDisk C:\Windows\system32\drivers\rsdrv.sys
13:02:34.0309 5168 ElRawDisk - ok
13:02:34.0325 5168 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
13:02:34.0325 5168 elxstor - ok
13:02:34.0419 5168 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
13:02:34.0434 5168 EMDMgmt - ok
13:02:34.0434 5168 EraserUtilDrvI10 - ok
13:02:34.0465 5168 [ B5A8A04A6E5B4E86B95B1553AA918F5F ] EraserUtilRebootDrv C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
13:02:34.0465 5168 EraserUtilRebootDrv - ok
13:02:34.0481 5168 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
13:02:34.0481 5168 ErrDev - ok
13:02:34.0575 5168 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
13:02:34.0575 5168 EventSystem - ok
13:02:34.0606 5168 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
13:02:34.0606 5168 exfat - ok
13:02:34.0684 5168 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
13:02:34.0684 5168 fastfat - ok
13:02:34.0746 5168 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
13:02:34.0746 5168 fdc - ok
13:02:34.0840 5168 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
13:02:34.0840 5168 fdPHost - ok
13:02:34.0871 5168 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
13:02:34.0871 5168 FDResPub - ok
13:02:34.0887 5168 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
13:02:34.0887 5168 FileInfo - ok
13:02:34.0996 5168 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
13:02:34.0996 5168 Filetrace - ok
13:02:35.0027 5168 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
13:02:35.0027 5168 flpydisk - ok
13:02:35.0121 5168 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
13:02:35.0121 5168 FltMgr - ok
13:02:35.0183 5168 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll
13:02:35.0199 5168 FontCache - ok
13:02:35.0245 5168 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
13:02:35.0245 5168 FontCache3.0.0.0 - ok
13:02:35.0261 5168 [ D909075FA72C090F27AA926C32CB4612 ] fssfltr C:\Windows\system32\DRIVERS\fssfltr.sys
13:02:35.0261 5168 fssfltr - ok
13:02:35.0464 5168 [ 4CE9DAC1518FF7E77BD213E6394B9D77 ] fsssvc C:\Program Files\Windows Live\Family Safety\fsssvc.exe
13:02:35.0479 5168 fsssvc - ok
13:02:35.0511 5168 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
13:02:35.0511 5168 Fs_Rec - ok
13:02:35.0542 5168 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
13:02:35.0542 5168 gagp30kx - ok
13:02:35.0620 5168 [ 551D463E4CCEB5240234DA6718C93A44 ] GameConsoleService C:\Program Files\HP Games\HP Game Console\GameConsoleService.exe
13:02:35.0620 5168 GameConsoleService - ok
13:02:35.0635 5168 [ 5AE3A887ECE5BBB72CFAB273C2FD1CFA ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
13:02:35.0635 5168 GEARAspiWDM - ok
13:02:35.0713 5168 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
13:02:35.0713 5168 gpsvc - ok
13:02:35.0916 5168 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
13:02:35.0916 5168 gupdate - ok
13:02:35.0932 5168 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
13:02:35.0932 5168 gupdatem - ok
13:02:35.0979 5168 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
13:02:35.0994 5168 HDAudBus - ok
13:02:36.0010 5168 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
13:02:36.0010 5168 HidBth - ok
13:02:36.0025 5168 [ D8DF3722D5E961BAA1292AA2F12827E2 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
13:02:36.0025 5168 HidIr - ok
13:02:36.0057 5168 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\System32\hidserv.dll
13:02:36.0057 5168 hidserv - ok
13:02:36.0088 5168 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
13:02:36.0088 5168 HidUsb - ok
13:02:36.0135 5168 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
13:02:36.0135 5168 hkmsvc - ok
13:02:36.0181 5168 [ AA9EF0B395097F24D289F64445B2FD2E ] HP Health Check Service c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
13:02:36.0181 5168 HP Health Check Service - ok
13:02:36.0197 5168 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
13:02:36.0197 5168 HpCISSs - ok
13:02:36.0306 5168 [ 0A3C6AA4A9FC38C20BA4EAC2C3351C05 ] hpqcxs08 C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
13:02:36.0306 5168 hpqcxs08 - ok
13:02:36.0337 5168 [ F3F72A2A86C22610BCA5439FA789DD52 ] hpqddsvc C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
13:02:36.0337 5168 hpqddsvc - ok
13:02:36.0462 5168 [ E82871D75565219A7E28C6B14572EF63 ] HsdService C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe
13:02:36.0462 5168 HsdService - ok
13:02:36.0525 5168 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys
13:02:36.0540 5168 HTTP - ok
13:02:36.0571 5168 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
13:02:36.0571 5168 i2omp - ok
13:02:36.0603 5168 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
13:02:36.0603 5168 i8042prt - ok
13:02:36.0649 5168 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
13:02:36.0649 5168 iaStorV - ok
13:02:37.0211 5168 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
13:02:37.0211 5168 idsvc - ok
13:02:37.0320 5168 [ 404FB2AAF532BC7BBACC8880BE401C74 ] IDSVix86 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\IPSDefs\20130113.001\IDSvix86.sys
13:02:37.0320 5168 IDSVix86 - ok
13:02:37.0383 5168 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
13:02:37.0383 5168 iirsp - ok
13:02:37.0757 5168 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
13:02:37.0757 5168 IKEEXT - ok
13:02:38.0615 5168 [ 84ED2154239F9D013BBD3220755ADA8B ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
13:02:38.0631 5168 IntcAzAudAddService - ok
13:02:38.0662 5168 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
13:02:38.0662 5168 intelide - ok
13:02:38.0771 5168 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
13:02:38.0771 5168 intelppm - ok
13:02:38.0943 5168 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
13:02:38.0943 5168 IPBusEnum - ok
13:02:39.0021 5168 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:02:39.0021 5168 IpFilterDriver - ok
13:02:39.0145 5168 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
13:02:39.0145 5168 iphlpsvc - ok
13:02:39.0145 5168 IpInIp - ok
13:02:39.0223 5168 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
13:02:39.0223 5168 IPMIDRV - ok
13:02:39.0255 5168 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
13:02:39.0255 5168 IPNAT - ok
13:02:39.0348 5168 [ 178FE38B7740F598391EB2F51AE4CCAC ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
13:02:39.0364 5168 iPod Service - ok
13:02:39.0379 5168 [ E50A95179211B12946F7E035D60AF560 ] irda C:\Windows\system32\DRIVERS\irda.sys
13:02:39.0395 5168 irda - ok
13:02:39.0395 5168 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
13:02:39.0411 5168 IRENUM - ok
13:02:39.0426 5168 [ CBB0D940221A281BCFEAEA695BD1CDA5 ] Irmon C:\Windows\System32\irmon.dll
13:02:39.0426 5168 Irmon - ok
13:02:39.0457 5168 [ 5896B5FF6332AB2BE1582523E9656A67 ] irsir C:\Windows\system32\DRIVERS\irsir.sys
13:02:39.0457 5168 irsir - ok
13:02:39.0473 5168 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
13:02:39.0473 5168 isapnp - ok
13:02:39.0504 5168 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
13:02:39.0504 5168 iScsiPrt - ok
13:02:39.0535 5168 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
13:02:39.0535 5168 iteatapi - ok
13:02:39.0582 5168 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
13:02:39.0582 5168 iteraid - ok
13:02:39.0598 5168 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
13:02:39.0598 5168 kbdclass - ok
13:02:39.0645 5168 [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
13:02:39.0645 5168 kbdhid - ok
13:02:39.0691 5168 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
13:02:39.0691 5168 KeyIso - ok
13:02:39.0832 5168 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
13:02:39.0847 5168 KSecDD - ok
13:02:39.0894 5168 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
13:02:39.0894 5168 KtmRm - ok
13:02:39.0941 5168 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\System32\srvsvc.dll
13:02:39.0941 5168 LanmanServer - ok
13:02:40.0019 5168 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:02:40.0019 5168 LanmanWorkstation - ok
13:02:40.0081 5168 [ DFEFF67508D3A9AEB1A85D7B0F513B24 ] LightScribeService c:\Program Files\Common Files\LightScribe\LSSrvc.exe
13:02:40.0081 5168 LightScribeService - ok
13:02:40.0159 5168 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
13:02:40.0159 5168 lltdio - ok
13:02:40.0191 5168 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
13:02:40.0191 5168 lltdsvc - ok
13:02:40.0206 5168 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
13:02:40.0206 5168 lmhosts - ok
13:02:40.0237 5168 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
13:02:40.0237 5168 LSI_FC - ok
13:02:40.0253 5168 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
13:02:40.0269 5168 LSI_SAS - ok
13:02:40.0315 5168 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
13:02:40.0315 5168 LSI_SCSI - ok
13:02:40.0331 5168 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
13:02:40.0331 5168 luafv - ok
13:02:40.0362 5168 [ 7521C0C58EE91BE90B6CC33E792D10C7 ] LVRS C:\Windows\system32\DRIVERS\lvrs.sys
13:02:40.0362 5168 LVRS - ok
13:02:40.0955 5168 [ 37E57C48AF530DF01CDD4E8A2AD77B51 ] LVUVC C:\Windows\system32\DRIVERS\lvuvc.sys
13:02:40.0971 5168 LVUVC - ok
13:02:41.0142 5168 [ E6CB119EF2E148EAA1A247343550756E ] McciCMService C:\Program Files\Common Files\Motive\McciCMService.exe
13:02:41.0142 5168 McciCMService - ok
13:02:41.0173 5168 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
13:02:41.0173 5168 Mcx2Svc - ok
13:02:41.0220 5168 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
13:02:41.0220 5168 megasas - ok
13:02:41.0376 5168 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
13:02:41.0376 5168 MegaSR - ok
13:02:41.0407 5168 [ 3412A454FDF9F68341AB80F3EE79EDAB ] MHIKEY10 C:\Windows\system32\Drivers\MHIKEY10.sys
13:02:41.0407 5168 MHIKEY10 - ok
13:02:41.0454 5168 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
13:02:41.0454 5168 MMCSS - ok
13:02:41.0485 5168 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
13:02:41.0485 5168 Modem - ok
13:02:41.0532 5168 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
13:02:41.0532 5168 monitor - ok
13:02:41.0579 5168 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
13:02:41.0579 5168 mouclass - ok
13:02:41.0595 5168 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
13:02:41.0595 5168 mouhid - ok
13:02:41.0626 5168 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
13:02:41.0626 5168 MountMgr - ok
13:02:41.0751 5168 [ 730A519505621DF46BCBF9CDAC9FB6AD ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
13:02:41.0751 5168 MozillaMaintenance - ok
13:02:41.0782 5168 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
13:02:41.0782 5168 mpio - ok
13:02:41.0797 5168 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
13:02:41.0797 5168 mpsdrv - ok
13:02:41.0922 5168 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
13:02:41.0922 5168 MpsSvc - ok
13:02:41.0938 5168 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
13:02:41.0953 5168 Mraid35x - ok
13:02:41.0985 5168 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
13:02:41.0985 5168 MRxDAV - ok
13:02:42.0016 5168 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
13:02:42.0016 5168 mrxsmb - ok
13:02:42.0063 5168 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:02:42.0063 5168 mrxsmb10 - ok
13:02:42.0078 5168 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:02:42.0078 5168 mrxsmb20 - ok
13:02:42.0125 5168 [ 28023E86F17001F7CD9B15A5BC9AE07D ] msahci C:\Windows\system32\drivers\msahci.sys
13:02:42.0125 5168 msahci - ok
13:02:42.0141 5168 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
13:02:42.0141 5168 msdsm - ok
13:02:42.0172 5168 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
13:02:42.0172 5168 MSDTC - ok
13:02:42.0203 5168 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
13:02:42.0203 5168 Msfs - ok
13:02:42.0219 5168 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
13:02:42.0219 5168 msisadrv - ok
13:02:42.0265 5168 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
13:02:42.0265 5168 MSiSCSI - ok
13:02:42.0281 5168 msiserver - ok
13:02:42.0312 5168 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
13:02:42.0312 5168 MSKSSRV - ok
13:02:42.0328 5168 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
13:02:42.0328 5168 MSPCLOCK - ok
13:02:42.0359 5168 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
13:02:42.0359 5168 MSPQM - ok
13:02:42.0375 5168 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
13:02:42.0375 5168 MsRPC - ok
13:02:42.0390 5168 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
13:02:42.0390 5168 mssmbios - ok
13:02:42.0406 5168 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
13:02:42.0406 5168 MSTEE - ok
13:02:42.0421 5168 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
13:02:42.0421 5168 Mup - ok
13:02:42.0609 5168 [ 4A9258B9597A31DB68EC9740F3A8A70B ] N360 C:\Program Files\Norton 360\Engine\20.2.0.19\ccSvcHst.exe
13:02:42.0609 5168 N360 - ok
13:02:42.0702 5168 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
13:02:42.0702 5168 napagent - ok
13:02:42.0733 5168 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
13:02:42.0733 5168 NativeWifiP - ok
13:02:42.0874 5168 [ 8E4C77AD9BB279900C00F870CC0C674B ] NAVENG C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\VirusDefs\20130114.004\NAVENG.SYS
13:02:42.0874 5168 NAVENG - ok
13:02:43.0295 5168 [ 826F699B69E88A3920C70F344DD42D88 ] NAVEX15 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\VirusDefs\20130114.004\NAVEX15.SYS
13:02:43.0311 5168 NAVEX15 - ok
13:02:43.0373 5168 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
13:02:43.0389 5168 NDIS - ok
13:02:43.0404 5168 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
13:02:43.0404 5168 NdisTapi - ok
13:02:43.0420 5168 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
13:02:43.0420 5168 Ndisuio - ok
13:02:43.0435 5168 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
13:02:43.0451 5168 NdisWan - ok
13:02:43.0451 5168 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
13:02:43.0451 5168 NDProxy - ok
13:02:43.0498 5168 [ 510C138564486FF926A3F773205C63D1 ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
13:02:43.0498 5168 Net Driver HPZ12 - ok
13:02:43.0529 5168 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
13:02:43.0529 5168 NetBIOS - ok
13:02:43.0607 5168 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
13:02:43.0607 5168 netbt - ok
13:02:43.0623 5168 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe
13:02:43.0623 5168 Netlogon - ok
13:02:43.0685 5168 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
13:02:43.0685 5168 Netman - ok
13:02:43.0732 5168 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
13:02:43.0732 5168 netprofm - ok
13:02:43.0763 5168 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
13:02:43.0763 5168 NetTcpPortSharing - ok
13:02:43.0825 5168 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
13:02:43.0825 5168 nfrd960 - ok
13:02:43.0872 5168 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
13:02:43.0872 5168 NlaSvc - ok
13:02:43.0981 5168 Norton PC Checkup Application Launcher - ok
13:02:44.0028 5168 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
13:02:44.0028 5168 Npfs - ok
13:02:44.0075 5168 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
13:02:44.0075 5168 nsi - ok
13:02:44.0091 5168 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
13:02:44.0091 5168 nsiproxy - ok
13:02:44.0262 5168 [ 8D11DA92F83D8C8281689739BEF05FD5 ] NSM C:\Program Files\Norton Family\Engine\2.6.0.43\ccSvcHst.exe
13:02:44.0278 5168 NSM - ok
13:02:44.0325 5168 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
13:02:44.0325 5168 Ntfs - ok
13:02:44.0418 5168 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
13:02:44.0418 5168 ntrigdigi - ok
13:02:44.0434 5168 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
13:02:44.0434 5168 Null - ok
13:02:44.0465 5168 [ D958A2B5F6AD5C3B8CCDC4D7DA62466C ] NVENETFD C:\Windows\system32\DRIVERS\nvmfdx32.sys
13:02:44.0481 5168 NVENETFD - ok
13:02:45.0292 5168 [ 09F5E33F91E186037262355B0BA72913 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
13:02:45.0323 5168 nvlddmkm - ok
13:02:45.0385 5168 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
13:02:45.0385 5168 nvraid - ok
13:02:45.0401 5168 [ 5DD1242CABC1EF8DCE4438D72D72A436 ] nvrd32 C:\Windows\system32\drivers\nvrd32.sys
13:02:45.0401 5168 nvrd32 - ok
13:02:45.0432 5168 [ 62754E376185EACBB73D06FEA0FFC54A ] nvsmu C:\Windows\system32\drivers\nvsmu.sys
13:02:45.0432 5168 nvsmu - ok
13:02:45.0448 5168 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
13:02:45.0448 5168 nvstor - ok
13:02:45.0479 5168 [ BB4DD678706510D9249EED1DA0219900 ] nvstor32 C:\Windows\system32\drivers\nvstor32.sys
13:02:45.0479 5168 nvstor32 - ok
13:02:45.0541 5168 [ F531F9B76E3E2595049F145160D280DE ] nvsvc C:\Windows\system32\nvvsvc.exe
13:02:45.0541 5168 nvsvc - ok
13:02:45.0573 5168 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
13:02:45.0573 5168 nv_agp - ok
13:02:45.0573 5168 NwlnkFlt - ok
13:02:45.0588 5168 NwlnkFwd - ok
13:02:45.0604 5168 [ BE32DA025A0BE1878F0EE8D6D9386CD5 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
13:02:45.0604 5168 ohci1394 - ok
13:02:45.0666 5168 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:02:45.0666 5168 ose - ok
13:02:46.0150 5168 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
13:02:46.0181 5168 osppsvc - ok
13:02:46.0259 5168 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
13:02:46.0259 5168 p2pimsvc - ok
13:02:46.0306 5168 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
13:02:46.0321 5168 p2psvc - ok
13:02:46.0353 5168 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
13:02:46.0353 5168 Parport - ok
13:02:46.0384 5168 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
13:02:46.0384 5168 partmgr - ok
13:02:46.0431 5168 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
13:02:46.0431 5168 Parvdm - ok
13:02:46.0446 5168 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
13:02:46.0446 5168 PcaSvc - ok
13:02:46.0571 5168 [ 2F86BE1818C2D7AC90478E3323EE7FCB ] PCCUJobMgr C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe
13:02:46.0571 5168 PCCUJobMgr - ok
13:02:46.0633 5168 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
13:02:46.0633 5168 pci - ok
13:02:46.0680 5168 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys
13:02:46.0680 5168 pciide - ok
13:02:46.0743 5168 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
13:02:46.0743 5168 pcmcia - ok
13:02:46.0930 5168 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
13:02:46.0930 5168 PEAUTH - ok
13:02:47.0257 5168 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
13:02:47.0273 5168 pla - ok
13:02:47.0304 5168 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
13:02:47.0304 5168 PlugPlay - ok
13:02:47.0320 5168 [ 37E5E8FFBAD35605DAEEC3224EA0E465 ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
13:02:47.0335 5168 Pml Driver HPZ12 - ok
13:02:47.0351 5168 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
13:02:47.0351 5168 PNRPAutoReg - ok
13:02:47.0429 5168 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
13:02:47.0429 5168 PNRPsvc - ok
13:02:47.0523 5168 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
13:02:47.0538 5168 PolicyAgent - ok
13:02:47.0585 5168 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
13:02:47.0585 5168 PptpMiniport - ok
13:02:47.0632 5168 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\DRIVERS\processr.sys
13:02:47.0632 5168 Processor - ok
13:02:47.0679 5168 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
13:02:47.0679 5168 ProfSvc - ok
13:02:47.0710 5168 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
13:02:47.0710 5168 ProtectedStorage - ok
13:02:47.0741 5168 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
13:02:47.0741 5168 PSched - ok
13:02:47.0959 5168 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
13:02:47.0959 5168 ql2300 - ok
13:02:47.0975 5168 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
13:02:47.0975 5168 ql40xx - ok
13:02:48.0069 5168 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
13:02:48.0069 5168 QWAVE - ok
13:02:48.0084 5168 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
13:02:48.0084 5168 QWAVEdrv - ok
13:02:48.0131 5168 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
13:02:48.0131 5168 RasAcd - ok
13:02:48.0162 5168 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
13:02:48.0162 5168 RasAuto - ok
13:02:48.0193 5168 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
13:02:48.0193 5168 Rasl2tp - ok
13:02:48.0271 5168 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
13:02:48.0271 5168 RasMan - ok
13:02:48.0303 5168 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
13:02:48.0303 5168 RasPppoe - ok
13:02:48.0334 5168 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
13:02:48.0334 5168 RasSstp - ok
13:02:48.0365 5168 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
13:02:48.0365 5168 rdbss - ok
13:02:48.0396 5168 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
13:02:48.0396 5168 RDPCDD - ok
13:02:48.0443 5168 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
13:02:48.0459 5168 rdpdr - ok
13:02:48.0459 5168 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
13:02:48.0459 5168 RDPENCDD - ok
13:02:48.0568 5168 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
13:02:48.0568 5168 RDPWD - ok
13:02:48.0599 5168 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
13:02:48.0599 5168 RemoteAccess - ok
13:02:48.0630 5168 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
13:02:48.0630 5168 RemoteRegistry - ok
13:02:48.0661 5168 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
13:02:48.0677 5168 RpcLocator - ok
13:02:48.0802 5168 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\System32\rpcss.dll
13:02:48.0817 5168 RpcSs - ok
13:02:48.0849 5168 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
13:02:48.0849 5168 rspndr - ok
13:02:48.0864 5168 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe
13:02:48.0864 5168 SamSs - ok
13:02:48.0895 5168 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
13:02:48.0895 5168 sbp2port - ok
13:02:48.0927 5168 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
13:02:48.0927 5168 SCardSvr - ok
13:02:48.0958 5168 [ BB68443901FF680C799E8F4A464ECE39 ] SCDEmu C:\Windows\system32\drivers\SCDEmu.sys
13:02:48.0958 5168 SCDEmu - ok
13:02:49.0051 5168 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll
13:02:49.0067 5168 Schedule - ok
13:02:49.0083 5168 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
13:02:49.0083 5168 SCPolicySvc - ok
13:02:49.0129 5168 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
13:02:49.0129 5168 SDRSVC - ok
13:02:49.0161 5168 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
13:02:49.0161 5168 secdrv - ok
13:02:49.0192 5168 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
13:02:49.0192 5168 seclogon - ok
13:02:49.0207 5168 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\system32\sens.dll
13:02:49.0207 5168 SENS - ok
13:02:49.0239 5168 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys
13:02:49.0239 5168 Serenum - ok
13:02:49.0270 5168 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
13:02:49.0270 5168 Serial - ok
13:02:49.0285 5168 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
13:02:49.0285 5168 sermouse - ok
13:02:50.0502 5168 [ 9910F4097EECBF561B257D614ADEF09A ] ServicepointService C:\Program Files\Windstream\Service Agent\ServicepointService.exe
13:02:50.0565 5168 ServicepointService - ok
13:02:50.0596 5168 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
13:02:50.0596 5168 SessionEnv - ok
13:02:50.0611 5168 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
13:02:50.0627 5168 sffdisk - ok
13:02:50.0674 5168 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
13:02:50.0674 5168 sffp_mmc - ok
13:02:50.0736 5168 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
13:02:50.0736 5168 sffp_sd - ok
13:02:50.0752 5168 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
13:02:50.0752 5168 sfloppy - ok
13:02:50.0814 5168 [ D9B734638DD8DBA9D59AAD3189CD0FAD ] Sftfs C:\Windows\system32\DRIVERS\Sftfslh.sys
13:02:50.0814 5168 Sftfs - ok
13:02:50.0861 5168 sftlist - ok
13:02:50.0892 5168 [ 2F61BD46C0BFF4EB36E1E359CA17BFC5 ] Sftplay C:\Windows\system32\DRIVERS\Sftplaylh.sys
13:02:50.0892 5168 Sftplay - ok
13:02:50.0908 5168 [ 518BAC0179F94304F422696B47C0EC12 ] Sftredir C:\Windows\system32\DRIVERS\Sftredirlh.sys
13:02:50.0908 5168 Sftredir - ok
13:02:50.0970 5168 [ 747325236D88B3F05FFD27FF9EC711C5 ] Sftvol C:\Windows\system32\DRIVERS\Sftvollh.sys
13:02:50.0970 5168 Sftvol - ok
13:02:51.0017 5168 [ A5812F0281CA5081BF696626F9BF324D ] sftvsa C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
13:02:51.0017 5168 sftvsa - ok
13:02:51.0048 5168 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
13:02:51.0064 5168 SharedAccess - ok
13:02:51.0189 5168 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:02:51.0189 5168 ShellHWDetection - ok
13:02:51.0282 5168 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
13:02:51.0282 5168 sisagp - ok
13:02:51.0329 5168 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
13:02:51.0329 5168 SiSRaid2 - ok
13:02:51.0360 5168 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
13:02:51.0360 5168 SiSRaid4 - ok
13:02:51.0391 5168 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
13:02:51.0391 5168 SkypeUpdate - ok
13:02:51.0469 5168 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
13:02:51.0501 5168 slsvc - ok
13:02:51.0532 5168 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
13:02:51.0532 5168 SLUINotify - ok
13:02:51.0563 5168 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
13:02:51.0563 5168 Smb - ok
13:02:51.0594 5168 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
13:02:51.0594 5168 SNMPTRAP - ok
13:02:51.0610 5168 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
13:02:51.0610 5168 spldr - ok
13:02:51.0641 5168 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe
13:02:51.0641 5168 Spooler - ok
13:02:51.0703 5168 [ 26C1B59C80FEF94B025DF5C3C1B791A7 ] SRTSP C:\Windows\System32\Drivers\N360\1402000.013\SRTSP.SYS
13:02:51.0703 5168 SRTSP - ok
13:02:51.0735 5168 [ 21AC3AE81E8263061624C4ED3B11509A ] SRTSPX C:\Windows\system32\drivers\N360\1402000.013\SRTSPX.SYS
13:02:51.0735 5168 SRTSPX - ok
13:02:51.0766 5168 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys
13:02:51.0766 5168 srv - ok
13:02:51.0797 5168 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
13:02:51.0797 5168 srv2 - ok
13:02:51.0828 5168 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
13:02:51.0828 5168 srvnet - ok
13:02:51.0859 5168 [ D5DFFEAA1E15D4EFFABB9D9A3068AC5B ] sscdbus C:\Windows\system32\DRIVERS\sscdbus.sys
13:02:51.0859 5168 sscdbus - ok
13:02:51.0891 5168 [ 8A1BE0C347814F482F493AEA619D57F6 ] sscdmdfl C:\Windows\system32\DRIVERS\sscdmdfl.sys
13:02:51.0891 5168 sscdmdfl - ok
13:02:51.0922 5168 [ 5AB0B1987F682A59B15B78F84C6AD7D0 ] sscdmdm C:\Windows\system32\DRIVERS\sscdmdm.sys
13:02:51.0922 5168 sscdmdm - ok
13:02:51.0937 5168 [ 751E66EB32EFA80633B80F5D7FF0A1D8 ] sscdserd C:\Windows\system32\DRIVERS\sscdserd.sys
13:02:51.0953 5168 sscdserd - ok
13:02:51.0969 5168 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
13:02:51.0969 5168 SSDPSRV - ok
13:02:51.0984 5168 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
13:02:51.0984 5168 SstpSvc - ok
13:02:52.0015 5168 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
13:02:52.0015 5168 stisvc - ok
13:02:52.0047 5168 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
13:02:52.0047 5168 swenum - ok
13:02:52.0078 5168 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
13:02:52.0093 5168 swprv - ok
13:02:52.0093 5168 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
13:02:52.0093 5168 Symc8xx - ok
13:02:52.0140 5168 [ FB69A67FEEE3026C7F99774A1C405326 ] SymDS C:\Windows\system32\drivers\N360\1402000.013\SYMDS.SYS
13:02:52.0140 5168 SymDS - ok
13:02:52.0171 5168 [ 28C5FAFA7FD1C522B8DCD59694D39412 ] SymEFA C:\Windows\system32\drivers\N360\1402000.013\SYMEFA.SYS
13:02:52.0171 5168 SymEFA - ok
13:02:52.0203 5168 [ C940F10C31E2C60CC967FFD6A370720C ] SymEvent C:\Windows\system32\Drivers\SYMEVENT.SYS
13:02:52.0203 5168 SymEvent - ok
13:02:52.0249 5168 [ 8C9B9036E301A9965CF15BEC91C58A12 ] SymIRON C:\Windows\system32\drivers\N360\1402000.013\Ironx86.SYS
13:02:52.0249 5168 SymIRON - ok
13:02:52.0327 5168 [ BB77096DC7F6E408D44C0BC6D2641850 ] SYMRDR_{78CA3BF0-9C3B-40e1-B46D-38C877EF059A} C:\Windows\system32\drivers\NSM\0206000.02B\SymRdr.SYS
13:02:52.0327 5168 SYMRDR_{78CA3BF0-9C3B-40e1-B46D-38C877EF059A} - ok
13:02:52.0343 5168 [ 93DE018EC6FBAA9A58FF9F2EB9198092 ] SYMTDIv C:\Windows\System32\Drivers\N360\1402000.013\SYMTDIV.SYS
13:02:52.0343 5168 SYMTDIv - ok
13:02:52.0374 5168 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
13:02:52.0374 5168 Sym_hi - ok
13:02:52.0405 5168 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
13:02:52.0405 5168 Sym_u3 - ok
13:02:52.0437 5168 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
13:02:52.0437 5168 SysMain - ok
13:02:52.0452 5168 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
13:02:52.0468 5168 TabletInputService - ok
13:02:52.0499 5168 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
13:02:52.0499 5168 TapiSrv - ok
13:02:52.0515 5168 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
13:02:52.0515 5168 TBS - ok
13:02:52.0561 5168 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
13:02:52.0561 5168 Tcpip - ok
13:02:52.0593 5168 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
13:02:52.0608 5168 Tcpip6 - ok
13:02:52.0624 5168 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
13:02:52.0624 5168 tcpipreg - ok
13:02:52.0655 5168 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
13:02:52.0655 5168 TDPIPE - ok
13:02:52.0655 5168 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
13:02:52.0655 5168 TDTCP - ok
13:02:52.0686 5168 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
13:02:52.0686 5168 tdx - ok
13:02:52.0717 5168 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
13:02:52.0717 5168 TermDD - ok
13:02:52.0749 5168 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
13:02:52.0749 5168 TermService - ok
13:02:52.0764 5168 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll
13:02:52.0764 5168 Themes - ok
13:02:52.0780 5168 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
13:02:52.0780 5168 THREADORDER - ok
13:02:52.0795 5168 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
13:02:52.0811 5168 TrkWks - ok
13:02:52.0858 5168 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
13:02:52.0858 5168 TrustedInstaller - ok
13:02:52.0873 5168 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
13:02:52.0873 5168 tssecsrv - ok
13:02:52.0889 5168 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
13:02:52.0889 5168 tunmp - ok
13:02:52.0905 5168 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
13:02:52.0905 5168 tunnel - ok
13:02:52.0920 5168 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
13:02:52.0920 5168 uagp35 - ok
13:02:52.0983 5168 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
13:02:52.0983 5168 udfs - ok
13:02:52.0998 5168 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
13:02:53.0014 5168 UI0Detect - ok
13:02:53.0029 5168 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
13:02:53.0029 5168 uliagpkx - ok
13:02:53.0045 5168 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
13:02:53.0045 5168 uliahci - ok
13:02:53.0061 5168 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
13:02:53.0061 5168 UlSata - ok
13:02:53.0076 5168 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
13:02:53.0076 5168 ulsata2 - ok
13:02:53.0092 5168 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
13:02:53.0092 5168 umbus - ok
13:02:53.0139 5168 [ 927754ABF077AEB5504BE4E0F2C60C1B ] UMVPFSrv C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
13:02:53.0154 5168 UMVPFSrv - ok
13:02:53.0170 5168 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
13:02:53.0170 5168 upnphost - ok
13:02:53.0201 5168 [ 83CAFCB53201BBAC04D822F32438E244 ] USBAAPL C:\Windows\system32\Drivers\usbaapl.sys
13:02:53.0201 5168 USBAAPL - ok
13:02:53.0232 5168 [ 32DB9517628FF0D070682AAB61E688F0 ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
13:02:53.0232 5168 usbaudio - ok
13:02:53.0248 5168 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
13:02:53.0248 5168 usbccgp - ok
13:02:53.0263 5168 [ 32C068EAF37C92D7194EEE1FAA1E7853 ] USBCCID C:\Windows\system32\DRIVERS\usbccid.sys
13:02:53.0263 5168 USBCCID - ok
13:02:53.0279 5168 [ 47B9770EA21436DE4AD5AEA7926E0900 ] usbcir C:\Windows\system32\DRIVERS\usbcir.sys
13:02:53.0279 5168 usbcir - ok
13:02:53.0295 5168 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
13:02:53.0295 5168 usbehci - ok
13:02:53.0310 5168 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
13:02:53.0310 5168 usbhub - ok
13:02:53.0326 5168 [ CE697FEE0D479290D89BEC80DFE793B7 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
13:02:53.0326 5168 usbohci - ok
13:02:53.0341 5168 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
13:02:53.0341 5168 usbprint - ok
13:02:53.0357 5168 [ A508C9BD8724980512136B039BBA65E9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
13:02:53.0357 5168 usbscan - ok
13:02:53.0373 5168 [ D575246188F63DE0ACCF6EAC5FB59E6A ] usbser C:\Windows\system32\DRIVERS\usbser.sys
13:02:53.0388 5168 usbser - ok
13:02:53.0404 5168 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:02:53.0404 5168 USBSTOR - ok
13:02:53.0419 5168 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
13:02:53.0419 5168 usbuhci - ok
13:02:53.0435 5168 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
13:02:53.0435 5168 usbvideo - ok
13:02:53.0466 5168 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
13:02:53.0466 5168 UxSms - ok
13:02:53.0529 5168 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
13:02:53.0529 5168 vds - ok
13:02:53.0544 5168 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
13:02:53.0544 5168 vga - ok
13:02:53.0560 5168 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
13:02:53.0560 5168 VgaSave - ok
13:02:53.0560 5168 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
13:02:53.0560 5168 viaagp - ok
13:02:53.0591 5168 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
13:02:53.0591 5168 ViaC7 - ok
13:02:53.0591 5168 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
13:02:53.0591 5168 viaide - ok
13:02:53.0638 5168 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
13:02:53.0638 5168 volmgr - ok
13:02:53.0669 5168 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
13:02:53.0669 5168 volmgrx - ok
13:02:53.0700 5168 [ 786DB5771F05EF300390399F626BF30A ] volsnap C:\Windows\system32\drivers\volsnap.sys
13:02:53.0700 5168 volsnap - ok
13:02:53.0716 5168 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
13:02:53.0716 5168 vsmraid - ok
13:02:53.0763 5168 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
13:02:53.0778 5168 VSS - ok
13:02:53.0825 5168 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
13:02:53.0825 5168 W32Time - ok
13:02:53.0841 5168 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
13:02:53.0841 5168 WacomPen - ok
13:02:53.0856 5168 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
13:02:53.0856 5168 Wanarp - ok
13:02:53.0856 5168 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
13:02:53.0856 5168 Wanarpv6 - ok
13:02:53.0872 5168 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
13:02:53.0887 5168 wcncsvc - ok
13:02:53.0903 5168 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
13:02:53.0903 5168 WcsPlugInService - ok
13:02:53.0919 5168 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
13:02:53.0919 5168 Wd - ok
13:02:53.0950 5168 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
13:02:53.0950 5168 Wdf01000 - ok
13:02:53.0965 5168 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
13:02:53.0965 5168 WdiServiceHost - ok
13:02:53.0981 5168 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
13:02:53.0981 5168 WdiSystemHost - ok
13:02:54.0012 5168 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
13:02:54.0012 5168 WebClient - ok
13:02:54.0043 5168 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
13:02:54.0043 5168 Wecsvc - ok
13:02:54.0059 5168 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
13:02:54.0059 5168 wercplsupport - ok
13:02:54.0090 5168 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
13:02:54.0090 5168 WerSvc - ok
13:02:54.0246 5168 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
13:02:54.0246 5168 WinDefend - ok
13:02:54.0262 5168 WinHttpAutoProxySvc - ok
13:02:54.0418 5168 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
13:02:54.0418 5168 Winmgmt - ok
13:02:54.0465 5168 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
13:02:54.0480 5168 WinRM - ok
13:02:54.0527 5168 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll
13:02:54.0527 5168 Wlansvc - ok
13:02:54.0839 5168 [ 0A70F4022EC2E14C159EFC4F69AA2477 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
13:02:54.0839 5168 wlidsvc - ok
13:02:54.0870 5168 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
13:02:54.0886 5168 WmiAcpi - ok
13:02:54.0964 5168 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
13:02:54.0964 5168 wmiApSrv - ok
13:02:55.0213 5168 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
13:02:55.0213 5168 WMPNetworkSvc - ok
13:02:55.0245 5168 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll
13:02:55.0245 5168 WPCSvc - ok
13:02:55.0291 5168 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
13:02:55.0291 5168 WPDBusEnum - ok
13:02:55.0323 5168 [ DE9D36F91A4DF3D911626643DEBF11EA ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
13:02:55.0323 5168 WpdUsb - ok
13:02:55.0479 5168 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
13:02:55.0479 5168 WPFFontCache_v0400 - ok
13:02:55.0541 5168 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
13:02:55.0541 5168 ws2ifsl - ok
13:02:55.0572 5168 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\system32\wscsvc.dll
13:02:55.0572 5168 wscsvc - ok
13:02:55.0572 5168 WSearch - ok
13:02:56.0149 5168 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
13:02:56.0165 5168 wuauserv - ok
13:02:56.0196 5168 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
13:02:56.0196 5168 WudfPf - ok
13:02:56.0243 5168 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
13:02:56.0243 5168 WUDFRd - ok
13:02:56.0337 5168 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
13:02:56.0337 5168 wudfsvc - ok
13:02:56.0337 5168 ================ Scan global ===============================
13:02:56.0415 5168 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
13:02:56.0477 5168 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
13:02:56.0539 5168 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
13:02:56.0586 5168 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
13:02:56.0586 5168 [Global] - ok
13:02:56.0586 5168 ================ Scan MBR ==================================
13:02:56.0602 5168 [ 81CD5EC01DB0CE57EDD853F82462EF27 ] \Device\Harddisk0\DR0
13:02:57.0709 5168 \Device\Harddisk0\DR0 - ok
13:02:57.0709 5168 ================ Scan VBR ==================================
13:02:57.0725 5168 [ CEF15918BE2688DEFAA35F41055B3604 ] \Device\Harddisk0\DR0\Partition1
13:02:57.0756 5168 \Device\Harddisk0\DR0\Partition1 - ok
13:02:57.0787 5168 [ 0B0DA37ADE752F88D2202D35A96D330D ] \Device\Harddisk0\DR0\Partition2
13:02:57.0803 5168 \Device\Harddisk0\DR0\Partition2 - ok
13:02:57.0803 5168 ============================================================
13:02:57.0803 5168 Scan finished
13:02:57.0803 5168 ============================================================
13:02:57.0819 4420 Detected object count: 0
13:02:57.0819 4420 Actual detected object count: 0
Well, it looks like we got rid of quite a few potentially unwanted items from your browsers. That should definitely help browser performance.

I'm not seeing anything alarming in your logs, but there are no tools that look in all places, so let's run a couple of tools that will look a little deeper and check in some other locations to see if there is anything else found.


Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

If Malwarebytes finds anything and you remove it, you may find improvement in your symptoms. If so - please let me know.



This next tool we will just be scanning. If we find anything with this, we'll bring out a more powerful tool to deal with what we find.


This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.


Go here to run an online scannner from ESET.
  • Note: For browsers other than Internet Explorer, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.

If it doesn't find anything there will be no log to post.
Eset results: C:\Users\jtmeserole\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\47e0b923-12eb0db9 a variant of Java/Exploit.CVE-2012-1723.AP trojan C:\Users\jtmeserole\Downloads\SavevidSetupV2.exe Win32/Toolbar.SearchSuite application F:\MEESHAMESERO-PC\Backup Set 2010-12-21 183027\Backup Files 2010-12-21 183027\Backup files 18.zip multiple threats Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.01.14.10 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 jtmeserole :: JTMESEROLE-PC [administrator] 1/16/2013 8:48:53 PM mbam-log-2013-01-16 (20-48-53).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 322809 Time elapsed: 6 minute(s), 1 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
My computer started freezing and firefox kept closing because of an error, so I ran mbam again and this is the new report: Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.01.14.10 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 jtmeserole :: JTMESEROLE-PC [administrator] 1/17/2013 2:14:08 PM mbam-log-2013-01-17 (14-14-08).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 322413 Time elapsed: 10 minute(s), 16 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 C:\Users\jtmeserole\AppData\Local\temp\0.3828760873717153 (Trojan.Happili) -> Quarantined and deleted successfully. (end)
Well, since you did have a trojan today, I'd like to go ahead and run a scan with a tool that will look deeper and remove any further threats found. It's more of a "big gun" tool.

After running it initially, we'll be able to use it to script out anything that ESET found that it might not automatically remove as well. You also have an old version of Java on the machine. I'd like to get that updated too since it is extremely vulnerable at this point and those vulnerabilities are being highly exploited right now, but I want to go ahead and run this tool before we do.


Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing anything, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

If you have a problem launching programs after running Combofix, please do not panic! Simply reboot the computer and all should be fine.


Even though we may not be done cleaning just yet, after you've successfully run Combofix, I'd like you to go ahead and update your Java so you can be better protected from the current exploits going on.


Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 7 and Save it to your Desktop.
  • Scroll down to where it says Java SE 7u11
  • Click the Download button under JRE to the right.
  • Read the License Agreement then select Accept License Agreement
  • Click on the link to download Windows x86 Offline and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-7u11-windows-i586.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are three options in the window to clear the cache - Leave these two Checked
    Trace and Log Files
    Cached Applications and Applets
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.
Here is the combofix log. I followed your instructions and updated java as well.


ComboFix 13-01-17.03 - jtmeserole 01/17/2013 20:59:09.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.1861 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\jtmeserole\AppData\Local\Google\Facebook\qayfxxzd.dll
c:\users\jtmeserole\AppData\Roaming\.#
.
.
((((((((((((((((((((((((( Files Created from 2012-12-18 to 2013-01-18 )))))))))))))))))))))))))))))))
.
.
2013-01-18 03:07 . 2013-01-18 03:08 ——– d—–w- c:\users\jtmeserole\AppData\Local\temp
2013-01-18 03:07 . 2013-01-18 03:07 ——– d—–w- c:\users\What\AppData\Local\temp
2013-01-18 03:07 . 2013-01-18 03:07 ——– d—–w- c:\users\school acct\AppData\Local\temp
2013-01-18 03:07 . 2013-01-18 03:07 ——– d—–w- c:\users\safe kids\AppData\Local\temp
2013-01-18 03:07 . 2013-01-18 03:07 ——– d—–w- c:\users\s\AppData\Local\temp
2013-01-18 03:07 . 2013-01-18 03:07 ——– d—–w- c:\users\Nice\AppData\Local\temp
2013-01-18 03:07 . 2013-01-18 03:07 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-01-14 21:43 . 2013-01-14 21:43 ——– d—–w- c:\users\jtmeserole\AppData\Roaming\Playrix Entertainment
2013-01-14 21:41 . 2013-01-14 21:41 ——– d—–w- c:\program files\Coupons
2013-01-14 19:09 . 2013-01-14 19:09 ——– d—–w- c:\windows\ERUNT
2013-01-14 19:06 . 2013-01-14 19:06 ——– d—–w- C:\JRT
2013-01-14 03:20 . 2013-01-14 03:21 ——– d—–w- c:\program files\Royal Envoy 2
2013-01-14 03:16 . 2013-01-14 03:17 ——– d—–w- c:\users\jtmeserole\AppData\Roaming\Realore_Whiterra Roads Of Rome 3
2013-01-14 03:14 . 2013-01-14 03:14 ——– d—–w- c:\program files\Roads of Rome III
2013-01-14 03:14 . 2013-01-14 03:14 ——– d—–w- c:\users\jtmeserole\AppData\Roaming\Meridian93
2013-01-14 03:11 . 2013-01-14 03:12 ——– d—–w- c:\program files\Magic Farm 2 - Fairy Lands
2013-01-09 17:56 . 2012-11-23 01:35 2048000 —-a-w- c:\windows\system32\win32k.sys
2013-01-09 17:55 . 2012-11-20 04:22 204288 —-a-w- c:\windows\system32\ncrypt.dll
2013-01-09 17:55 . 2012-11-02 10:19 1400832 —-a-w- c:\windows\system32\msxml6.dll
2012-12-22 13:39 . 2012-12-16 13:12 34304 —-a-w- c:\windows\system32\atmlib.dll
2012-12-22 13:39 . 2012-12-16 10:50 293376 —-a-w- c:\windows\system32\atmfd.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-14 22:49 . 2010-11-26 20:52 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-11-22 19:03 . 2010-09-22 16:15 142496 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2012-11-14 02:09 . 2012-12-14 13:19 1800704 —-a-w- c:\windows\system32\jscript9.dll
2012-11-14 01:58 . 2012-12-14 13:19 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2012-11-14 01:57 . 2012-12-14 13:19 1129472 —-a-w- c:\windows\system32\wininet.dll
2012-11-14 01:49 . 2012-12-14 13:19 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2012-11-14 01:48 . 2012-12-14 13:19 420864 —-a-w- c:\windows\system32\vbscript.dll
2012-11-14 01:44 . 2012-12-14 13:19 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-11-13 01:29 . 2012-12-13 12:46 2048 —-a-w- c:\windows\system32\tzres.dll
2012-11-02 10:18 . 2012-12-13 12:46 376320 —-a-w- c:\windows\system32\dpnet.dll
2012-11-02 08:26 . 2012-12-13 12:46 23040 —-a-w- c:\windows\system32\dpnsvr.exe
2012-03-26 15:22 . 2012-03-26 15:22 35113704 —-a-w- c:\program files\Common Files\directx_9c_redist.exe
2010-03-31 16:09 . 2013-01-11 13:52 10437264 —-a-w- c:\program files\mozilla firefox\plugins\PDFNetC.dll
2010-04-08 18:36 . 2013-01-11 13:52 107760 —-a-w- c:\program files\mozilla firefox\plugins\ScorchPDFWrapper.dll
2013-01-11 13:52 . 2013-01-11 13:52 262704 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-08 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-08 92704]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"Windstream Service Agent.exe"="c:\program files\Windstream\Service Agent\Windstream Service Agent.exe" [2011-10-14 10204472]
"DiagnosticTools.exe"="c:\program files\Windstream\Diagnostic Tools\DiagnosticTools.exe" [2011-04-25 2037048]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HsdService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\prwntdrv]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ServicepointService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-12-03 07:35 946352 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-07-31 11:20 38872 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2008-12-04 15:14 75016 —-a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2008-12-08 22:34 54576 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPADVISOR]
2009-04-04 00:25 1644088 —-a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
2008-11-20 17:47 62768 —-a-w- c:\program files\Hewlett-Packard\HP Odometer\hpsysdrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2012-12-14 22:49 824232 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut]
2008-12-04 05:15 218408 —-a-w- c:\program files\Cyberlink\LabelPrint\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GoShortCut]
2008-12-04 05:15 218408 —-a-w- c:\program files\Cyberlink\Power2Go\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePDIRShortCut]
2008-12-04 05:15 218408 —-a-w- c:\program files\Cyberlink\PowerDirector\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePSTShortCut]
2009-02-02 21:05 210216 —-a-w- c:\program files\Cyberlink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-01-11 09:07 1606760 —-a-w- c:\program files\Google\Chrome\Application\24.0.1312.52\Installer\setup.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-01-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-11 01:23]
.
2013-01-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-11 01:23]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MI1933~1\Office14\ONBttnIE.dll/105
LSP: c:\windows\system32\wpclsp.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.254.254
FF - ProfilePath - c:\users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\
FF - prefs.js: browser.search.defaulturl - Bing
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.ldsscripturemastery.net/en/
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2049-12-31 15:00; {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}; c:\users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi
FF - ExtSQL: !HIDDEN! 2010-09-23 05:02; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - ExtSQL: !HIDDEN! 2011-03-28 10:30; [removed]; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Facebook - c:\users\jtmeserole\AppData\Local\Google\Facebook\qayfxxzd.dll
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-NCH_EN Toolbar - c:\program files\NCH_EN\uninstall.exe
AddRemove-Norton PC Checkup_is1 - c:\programdata\Norton\PC Checkup\unins000.exe
AddRemove-NortonPCCheckup - c:\program files\NortonInstaller\{170fa89a-6886-4c9e-b17b-12bccdd80788}\NortonPCCheckup\LicenseType\2.0.12.27\InstStub.exe
AddRemove-NSM - c:\program files\NortonInstaller\{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}\NSM\LicenseType\2.6.0.43\InstStub.exe
AddRemove-RadialpointServicepointDashboardExtensions_is1 - c:\users\JTMESE~1\AppData\Local\Temp\is-JDI7E.tmp\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-01-17 21:08
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\20.2.0.19\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\20.2.0.19\diMaster.dll\" /prefetch:1"
–
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NSM]
"ImagePath"="\"c:\program files\Norton Family\Engine\2.6.0.43\ccSvcHst.exe\" /s \"NSM\" /m \"c:\program files\Norton Family\Engine\2.6.0.43\diMaster.dll\" /prefetch:1"
–
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCCUJobMgr]
"ImagePath"="\"c:\program files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files\Norton PC Checkup\Engine\2.0.12.27\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2013-01-17 21:10:17
ComboFix-quarantined-files.txt 2013-01-18 03:10
.
Pre-Run: 153,224,445,952 bytes free
Post-Run: 152,395,538,432 bytes free
.
- - End Of File - - 4B95975A1F96C26A63DC2AFCCE2BBC11
1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Users\jtmeserole\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\47e0b923-12eb0db9
C:\Users\jtmeserole\Downloads\SavevidSetupV2.exe
F:\MEESHAMESERO-PC\Backup Set 2010-12-21 183027\Backup Files 2010-12-21 183027\Backup files 18.zip

ClearJavaCache::


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe. ComboFix may request an update; please allow it.

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.


Please be sure to reboot the computer, and then let me know how things are running in your next reply.
The computer is still running constantly. It isn't as loud, though.





ComboFix 13-01-17.04 - jtmeserole 01/18/2013 21:08:55.5.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.1819 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\jtmeserole\Desktop\CFScript.txt
AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\jtmeserole\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35\47e0b923-12eb0db9"
"c:\users\jtmeserole\Downloads\SavevidSetupV2.exe"
"f:\meeshamesero-pc\Backup Set 2010-12-21 183027\Backup Files 2010-12-21 183027\Backup files 18.zip"
.
.
((((((((((((((((((((((((( Files Created from 2012-12-19 to 2013-01-19 )))))))))))))))))))))))))))))))
.
.
2013-01-19 03:17 . 2013-01-19 03:18 ——– d—–w- c:\users\jtmeserole\AppData\Local\temp
2013-01-19 03:17 . 2013-01-19 03:17 ——– d—–w- c:\users\What\AppData\Local\temp
2013-01-19 03:17 . 2013-01-19 03:17 ——– d—–w- c:\users\school acct\AppData\Local\temp
2013-01-19 03:17 . 2013-01-19 03:17 ——– d—–w- c:\users\safe kids\AppData\Local\temp
2013-01-19 03:17 . 2013-01-19 03:17 ——– d—–w- c:\users\s\AppData\Local\temp
2013-01-19 03:17 . 2013-01-19 03:17 ——– d—–w- c:\users\Public\AppData\Local\temp
2013-01-19 03:17 . 2013-01-19 03:17 ——– d—–w- c:\users\Nice\AppData\Local\temp
2013-01-19 03:17 . 2013-01-19 03:17 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-01-18 03:28 . 2013-01-18 03:28 ——– d—–w- c:\program files\Common Files\Java
2013-01-18 03:28 . 2013-01-18 03:27 859552 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-01-18 03:27 . 2013-01-18 03:27 94112 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-01-14 21:43 . 2013-01-14 21:43 ——– d—–w- c:\users\jtmeserole\AppData\Roaming\Playrix Entertainment
2013-01-14 21:41 . 2013-01-14 21:41 ——– d—–w- c:\program files\Coupons
2013-01-14 19:09 . 2013-01-14 19:09 ——– d—–w- c:\windows\ERUNT
2013-01-14 19:06 . 2013-01-14 19:06 ——– d—–w- C:\JRT
2013-01-14 03:20 . 2013-01-14 03:21 ——– d—–w- c:\program files\Royal Envoy 2
2013-01-14 03:16 . 2013-01-14 03:17 ——– d—–w- c:\users\jtmeserole\AppData\Roaming\Realore_Whiterra Roads Of Rome 3
2013-01-14 03:14 . 2013-01-14 03:14 ——– d—–w- c:\program files\Roads of Rome III
2013-01-14 03:14 . 2013-01-14 03:14 ——– d—–w- c:\users\jtmeserole\AppData\Roaming\Meridian93
2013-01-14 03:11 . 2013-01-14 03:12 ——– d—–w- c:\program files\Magic Farm 2 - Fairy Lands
2013-01-09 17:56 . 2012-11-23 01:35 2048000 —-a-w- c:\windows\system32\win32k.sys
2013-01-09 17:55 . 2012-11-20 04:22 204288 —-a-w- c:\windows\system32\ncrypt.dll
2013-01-09 17:55 . 2012-11-02 10:19 1400832 —-a-w- c:\windows\system32\msxml6.dll
2012-12-22 13:39 . 2012-12-16 13:12 34304 —-a-w- c:\windows\system32\atmlib.dll
2012-12-22 13:39 . 2012-12-16 10:50 293376 —-a-w- c:\windows\system32\atmfd.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-18 03:27 . 2010-09-20 21:21 780192 —-a-w- c:\windows\system32\deployJava1.dll
2012-12-14 22:49 . 2010-11-26 20:52 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-11-22 19:03 . 2010-09-22 16:15 142496 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2012-11-14 02:09 . 2012-12-14 13:19 1800704 —-a-w- c:\windows\system32\jscript9.dll
2012-11-14 01:58 . 2012-12-14 13:19 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2012-11-14 01:57 . 2012-12-14 13:19 1129472 —-a-w- c:\windows\system32\wininet.dll
2012-11-14 01:49 . 2012-12-14 13:19 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2012-11-14 01:48 . 2012-12-14 13:19 420864 —-a-w- c:\windows\system32\vbscript.dll
2012-11-14 01:44 . 2012-12-14 13:19 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-11-13 01:29 . 2012-12-13 12:46 2048 —-a-w- c:\windows\system32\tzres.dll
2012-11-02 10:18 . 2012-12-13 12:46 376320 —-a-w- c:\windows\system32\dpnet.dll
2012-11-02 08:26 . 2012-12-13 12:46 23040 —-a-w- c:\windows\system32\dpnsvr.exe
2012-03-26 15:22 . 2012-03-26 15:22 35113704 —-a-w- c:\program files\Common Files\directx_9c_redist.exe
2010-03-31 16:09 . 2013-01-11 13:52 10437264 —-a-w- c:\program files\mozilla firefox\plugins\PDFNetC.dll
2010-04-08 18:36 . 2013-01-11 13:52 107760 —-a-w- c:\program files\mozilla firefox\plugins\ScorchPDFWrapper.dll
2013-01-11 13:52 . 2013-01-11 13:52 262704 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-08 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-08 92704]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"Windstream Service Agent.exe"="c:\program files\Windstream\Service Agent\Windstream Service Agent.exe" [2011-10-14 10204472]
"DiagnosticTools.exe"="c:\program files\Windstream\Diagnostic Tools\DiagnosticTools.exe" [2011-04-25 2037048]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HsdService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\prwntdrv]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ServicepointService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-12-03 07:35 946352 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-07-31 11:20 38872 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2008-12-04 15:14 75016 —-a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2008-12-08 22:34 54576 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPADVISOR]
2009-04-04 00:25 1644088 —-a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
2008-11-20 17:47 62768 —-a-w- c:\program files\Hewlett-Packard\HP Odometer\hpsysdrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2012-12-14 22:49 824232 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut]
2008-12-04 05:15 218408 —-a-w- c:\program files\Cyberlink\LabelPrint\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GoShortCut]
2008-12-04 05:15 218408 —-a-w- c:\program files\Cyberlink\Power2Go\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePDIRShortCut]
2008-12-04 05:15 218408 —-a-w- c:\program files\Cyberlink\PowerDirector\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePSTShortCut]
2009-02-02 21:05 210216 —-a-w- c:\program files\Cyberlink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-01-11 09:07 1606760 —-a-w- c:\program files\Google\Chrome\Application\24.0.1312.52\Installer\setup.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-11 01:23]
.
2013-01-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-11 01:23]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MI1933~1\Office14\ONBttnIE.dll/105
LSP: c:\windows\system32\wpclsp.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.254.254
FF - ProfilePath - c:\users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\
FF - prefs.js: browser.search.defaulturl - Bing
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.ldsscripturemastery.net/en/
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2049-12-31 15:00; {ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}; c:\users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi
FF - ExtSQL: !HIDDEN! 2010-09-23 05:02; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - ExtSQL: !HIDDEN! 2011-03-28 10:30; [removed]; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-01-18 21:18
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\20.2.0.19\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\20.2.0.19\diMaster.dll\" /prefetch:1"
–
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NSM]
"ImagePath"="\"c:\program files\Norton Family\Engine\2.6.0.43\ccSvcHst.exe\" /s \"NSM\" /m \"c:\program files\Norton Family\Engine\2.6.0.43\diMaster.dll\" /prefetch:1"
–
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCCUJobMgr]
"ImagePath"="\"c:\program files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files\Norton PC Checkup\Engine\2.0.12.27\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2013-01-18 21:19:46
ComboFix-quarantined-files.txt 2013-01-19 03:19
ComboFix2.txt 2013-01-18 03:10
.
Pre-Run: 152,868,118,528 bytes free
Post-Run: 152,832,249,856 bytes free
.
- - End Of File - - 6C9D2387FAA8DA3E39D89B795EDBD96C
When you first ran the DDS log there should have been an attach.txt file that showed up on your desktop. Can you please copy and past the contents of that initial file here please? Also, can you tell me if you are using a router?
Rather than run DDS again, let's do another scan. It's an opportunity to look a little deeper on the machine in some other places. This will show me what the other log would have plus more so it's another double check.

OTL Custom Scan

  • Download OTL to your desktop.
  • Right-click and choose Run as Administrator on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    consrv.dll
    services.*
    /md5stop
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.


Since your router is a modem/router combination I'm a little hesitate to give you the standard instructions for just resetting a router. Did your ISP provide you with instructions on how to reset it? If not, I'll go ahead and give you the generic router instructions below but if you have ones for your particular modem/router I would strongly suggest you follow them, or let me know the brand and model and I can try to find them for you.



I would like to have you reset your router. Most routers have a reset pin hole on the back.

1. With the unit on, place an straightend paperclip into the hole on the back on the unit labeled Reset.
2. Hold the paperclip/reset down for 10 seconds and then release it.
3. The unit will reboot on its own.
4. As soon as the lights stop blinking, the unit is ready.
5. You may need to reinstall the router to regain your internet access.

Note: If you changed your password, it will be gone so refer to your user's guide for your router.

If you have not already done so after doing this, please go into your router's settings and change the default password to a stronger one.
OTL Extras logfile created on: 1/24/2013 8:14:56 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\jtmeserole\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 1.84 Gb Available Physical Memory | 63.95% Memory free
5.96 Gb Paging File | 5.03 Gb Available in Paging File | 84.44% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 286.80 Gb Total Space | 141.77 Gb Free Space | 49.43% Space Free | Partition Type: NTFS
Drive D: | 11.28 Gb Total Space | 1.59 Gb Free Space | 14.08% Space Free | Partition Type: NTFS
Drive F: | 298.02 Gb Total Space | 121.47 Gb Free Space | 40.76% Space Free | Partition Type: FAT32

Computer Name: JTMESEROLE-PC | User Name: jtmeserole | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\WINWORD.EXE" /n /dde
https [open] – Reg Error: Value error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UpdatesDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{B233142D-9D39-4251-B949-268C9BF4E98D}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{D735A0B5-E349-4096-A8C2-A6086B2D2663}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0A01AB01-E568-4347-8D24-30AFAA09BBDC}" = protocol=6 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe |
"{30D5582A-806C-4576-86C0-BA4710D34EFD}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpzwiz01.exe |
"{33CE8D40-970C-4AD3-B3D0-A90C8AE9EC2C}" = protocol=6 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe |
"{33EFE1F2-7E0C-4F58-937B-F4B260615682}" = protocol=6 | dir=in | app=c:\program files\windstream\service agent\servicepointservice.exe |
"{39BE8C4D-2FE0-4A83-95A1-0FD5FC782C41}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgplgtupl.exe |
"{3AE88328-BEFA-4BF9-A61F-61F29CDB807A}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe |
"{461DAA71-6FB3-4A50-98DA-DCC443A6CA20}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqtra08.exe |
"{4698EACC-1810-4C66-9880-AC452F943984}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |
"{47C4D73B-5ADF-44D4-949C-F790C0CF06C6}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe |
"{4A964099-63FE-4787-A1E3-F6F8E451D265}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpofxs08.exe |
"{5392C678-ED81-4679-AFA4-75457A234DE6}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe |
"{539D015A-DEDC-4664-A2F0-1BE83F282F1C}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{55504218-2DFE-4126-A81A-BC529FB31BAE}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5FEB64E7-3583-49CA-A28F-32627241784F}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpoews01.exe |
"{63090AE1-3CDF-42AF-A07D-F9332787B7D4}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6D08AE45-DFC7-4085-BBAD-B0FA2A5971DC}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqfxt08.exe |
"{75657E49-C1E5-4F45-9334-F81C9A464301}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{8581BA4A-4A37-4893-9A59-E1DF7B81EC43}" = protocol=17 | dir=in | app=c:\program files\windstream\service agent\servicepointservice.exe |
"{8E39346B-9997-49AB-8BCE-7F5916E6BFAA}" = protocol=17 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe |
"{8EFF84B3-0333-4FB4-B208-178D32185F3C}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe |
"{93AC7A78-60DF-4B94-B000-61AB858BDE91}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{AC229239-AE20-4721-8B13-14AC4270EAE6}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{AD9DC147-3A31-4DBF-90D0-F87DC7D883D0}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B2E3A4A6-8891-417B-9BA6-B5FC7D8274D4}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpfccopy.exe |
"{B39F120E-0363-483E-97BC-80F042173A41}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpofxm08.exe |
"{B4018310-E726-4697-9B45-0F70B5F91F30}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{B401841D-C59E-4B99-93D0-D19867A1F7AF}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposfx08.exe |
"{CDC43877-897C-4B60-BD5D-806B2AC173BB}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{D7D99986-DCBE-4050-B65D-3F8887A59E30}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |
"{DB9276BA-290F-4D25-BDF5-F44194173CA1}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe |
"{DD2AF25C-2DF7-4ED7-B93D-B633D6B21EFD}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{E0E504B5-D609-41AC-9483-96E78CA819E4}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{E2141DD9-9E71-498A-8AD6-B39459BD4AFE}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{E9F63A19-C9BA-4318-AF5B-DADF2BB59860}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{EDDED172-A45C-411B-8A0E-520E3FC901A3}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{F1126A22-4750-4BC7-8819-E404F379B55D}" = protocol=17 | dir=in | app=c:\program files\imesh applications\imesh\imesh.exe |
"{FBA1CD45-86BB-4DF8-A222-95B6DEFB393A}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0136E4E1-28E6-45CF-BB34-AD9179AE3584}_is1" = Resonance Demo version 1.0
"{0295F89F-F698-4101-9A7D-49F407EC2D82}" = HP Active Support Library
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{0F956834-2785-4E63-A2AB-C1CB6359191B}" = MyLearnExpress
"{10ABE49D-343A-463E-9753-C4C5A05ECEF9}" = Sibelius Scorch (Firefox, Opera, Netscape only)
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1CC069FA-1A86-402E-9787-3F04E652C67A}" = HP Support Information
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83217011FF}" = Java 7 Update 11
"{27D29B49-8F31-485B-83DC-7236BB70EBC3}" = MyLearnExpress
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{328687A2-2504-49FA-AE3E-08B0DEDB51EC}" = MSRedist
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EB6F78A-66E3-434f-BD0E-76C7D078DB5E}" = 4500G510af_Software_Min
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{47F36D92-E58E-456D-B73C-3382737E4C42}" = HP Update
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{662140BE-138C-4DC1-B4CD-B62C6C855A25}" = Pirate101
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}" = Power Tab Editor 1.7
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73A43E42-3658-4DD9-8551-FACDA3632538}" = HP Advisor
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{779DECD7-E072-4B56-9B6B-BEB5973EEEB5}" = MobileMe Control Panel
"{784BEA84-FA66-4B19-BB80-7B545F248AC6}" = HP Total Care Setup
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7AAA27E4-CDB3-49C0-AA2D-41827C001BA3}" = Microsoft Small Basic v1.0
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7F10292C-A190-4176-A665-A1ED3478DF86}" = LightScribe System Software
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B9F50F9-BA6F-47c5-990B-76A74A1C68B0}" = 4500G510af
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FB495A1-4A3F-4C1D-BD27-3F3AB2E66763}" = iMesh
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{92A51949-EE4C-466D-AAF0-99E74A49A63F}" = DocMgr
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CC89170-000B-457D-91F1-53691F85B223}" = Python 2.6.1
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{9EE969A0-46EE-441C-9DE1-CAE97F015CAB}" = Discover Babylon
"{A0640EC2-B97E-4FC1-AD14-227C9E386BB4}" = HP Recovery Manager RSS
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{A9E27FF5-6294-46A8-B8FD-77B1DECA3021}" = Wizard101
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.2
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B7DBF6E8-0D17-4BE4-853B-ACD6EFBD4A1F}" = iTunes
"{B84739A3-F943-47E4-95D8-96381EF5AC48}" = HP Customer Experience Enhancements
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{B94F6A6A-56CB-465E-885E-CB099331E456}" = Convergys Health Checker
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{BEE9B594-5D0E-4EB5-BDBE-BA9E7C020083}" = Food Storage Planner 5.0
"{C175D5B0-ED04-42C9-B23F-D8BD406173E7}" = 4500_G510af_Help
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{C98517B6-DCE9-49B7-B19E-E384178D3986}" = HP Officejet 4500 G510a-f
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2AF3E5D-9697-485C-A5AC-E2B9468C446A}" = Safari
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Alphabet Express" = Alphabet Express
"Audacity_is1" = Audacity 2.0
"BFG-1 Penguin 100 Cases" = 1 Penguin 100 Cases
"BFG-Avenue Flo - Special Delivery" = Avenue Flo: Special Delivery
"BFG-Be a King - Golden Empire" = Be a King: Golden Empire
"BFG-Be a King 3 - Golden Empire Survey" = Be a King 3: Golden Empire Survey
"BFG-Burger Bustle - Ellie's Organics" = Burger Bustle: Ellie's Organics
"BFG-Burger Island" = Burger Island
"BFG-Burger Island 2 - The Missing Ingredients" = Burger Island 2: The Missing Ingredients
"BFG-Bus Driver" = Bus Driver
"BFGC" = Big Fish Games: Game Manager
"BFG-Chessmaster Challenge" = Chessmaster Challenge
"BFG-Chocolatier" = Chocolatier
"BFG-Chocolatier - Decadence by Design" = Chocolatier: Decadence by Design
"BFG-Chocolatier 2 - Secret Ingredients" = Chocolatier 2: Secret Ingredients
"BFG-Cooking Dash 3 - Thrills and Spills" = Cooking Dash 3: Thrills and Spills
"BFG-DinerTown - Detective Agency" = DinerTown: Detective Agency
"BFG-DinerTown Tycoon" = DinerTown Tycoon
"BFG-Farm Frenzy - Ancient Rome" = Farm Frenzy: Ancient Rome
"BFG-Farm Frenzy - Gone Fishing" = Farm Frenzy: Gone Fishing
"BFG-Farm Mania - Hot Vacation" = Farm Mania: Hot Vacation
"BFG-Farmers Market" = Farmers Market
"BFG-Flux Family Secrets - The Ripple Effect" = Flux Family Secrets: The Ripple Effect
"BFG-Garage Inc" = Garage Inc.
"BFG-Garden Dash" = Garden Dash
"BFG-Gold Miner Vegas" = Gold Miner Vegas
"BFG-Hotel Dash 2 - Lost Luxuries" = Hotel Dash 2: Lost Luxuries
"BFG-Magic Farm 2 - Fairy Lands" = Magic Farm 2: Fairy Lands
"BFG-Monument Builders - Statue of Liberty" = Monument Builders: Statue of Liberty
"BFG-My Kingdom for the Princess" = My Kingdom for the Princess
"BFG-New Yankee in King Arthur's Court" = New Yankee in King Arthur's Court
"BFG-Parking Dash" = Parking Dash
"BFG-Plantasia" = Plantasia
"BFG-Ranch Rush 2 - Sara's Island Experiment" = Ranch Rush 2 - Sara's Island Experiment
"BFG-Roads of Rome II" = Roads of Rome II
"BFG-Roads of Rome III" = Roads of Rome III
"BFG-Royal Envoy" = Royal Envoy
"BFG-Royal Envoy 2" = Royal Envoy 2
"BFG-Supercow" = Supercow
"BFG-Supermarket Mania 2" = Supermarket Mania ® 2
"BFG-The Great Chocolate Chase" = The Great Chocolate Chase
"BFG-The Palace Builder" = The Palace Builder
"BFG-The Promised Land" = The Promised Land
"BFG-Turbo Fiesta" = Turbo Fiesta
"BFG-Turbo Pizza" = Turbo Pizza
"BFG-Turbo Subs" = Turbo Subs
"BFG-Wandering Willows" = Wandering Willows
"BFG-War Chess" = War Chess
"BFG-Wedding Dash 4-Ever" = Wedding Dash 4-Ever
"BFG-Ye Olde Sandwich Shoppe" = Ye Olde Sandwich Shoppe
"BFG-Youda Sushi Chef" = Youda Sushi Chef
"BFG-Zuma Deluxe" = Zuma Deluxe
"Celestia_is1" = Celestia 1.6.1
"Coupon Printer for Windows5.0.0.2" = Coupon Printer for Windows
"Crescendo" = Crescendo Music Notation Editor
"Debut" = Debut Video Capture Software
"Disney Pirates of the Caribbean Online" = Disney Pirates of the Caribbean Online
"DownVision_is1" = DownVision
"Doxillion" = Doxillion Document Converter
"EarTest for Windows ver. 1.12_is1" = EarTest for Windows ver. 1.12
"ESET Online Scanner" = ESET Online Scanner v3
"EuroTalk Talk Now Plus!" = EuroTalk Talk Now Plus!
"ExpressBurn" = Express Burn Disc Burning Software
"Food Storage Planner" = Food Storage Planner
"Forte Standard" = Forte Standard 2.0
"Free Download Manager_is1" = Free Download Manager 3.8
"Google Chrome" = Google Chrome
"HP Document Manager" = HP Document Manager 2.0
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Print Projects" = HP Print Projects 1.0
"HP Smart Web Printing" = HP Smart Web Printing 4.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"iMesh" = iMesh
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"JumpStart Advanced Kindergarten" = JumpStart Advanced Kindergarten
"Kidzui" = Kidzui
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 18.0.1 (x86 en-US)" = Mozilla Firefox 18.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSNINST" = MSN
"MuseScore" = MuseScore 0.9.6.3 MuseScore score typesetter
"Musicnotes Combined Installer_is1" = Musicnotes Software Suite 1.5.3
"N360" = Norton 360
"NVIDIA Drivers" = NVIDIA Drivers
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"Photo Pos Pro" = Photo Pos Pro
"PowerISO" = PowerISO
"Prism" = Prism Video File Converter
"pywin32-py2.6" = Python 2.6 pywin32-212
"RadialpointClientGateway_is1" = Windstream Service Agent 4.1.15
"RadialpointHomeSecurityDashboard_is1" = Windstream Diagnostic Tools 3.0.21
"RadialpointSecurityAdvisorService_is1" = Radialpoint Security Advisor 2.5.15
"Shop for HP Supplies" = Shop for HP Supplies
"Stellarium_is1" = Stellarium 0.11.2
"transformer_ie" = Widevine Media Transformer Plugin 5.0.0
"TuxMath" = Tux of Math Command (remove only)
"TwelveKeys" = TwelveKeys Music Transcription Software
"VideoPad" = VideoPad Video Editor
"VLC media player" = VLC media player 0.9.9
"WavePad" = WavePad Sound Editor
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite" = Windows Live Essentials
"Wondershare iPod Video Transfer_is1" = Wondershare iPod Video Transfer(Build 3.0.17)
"YTdetect" = Yahoo! Detect

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Kitten Catastrophy" = Kitten Catastrophy
"SOE-Clone Wars" = Clone Wars
"SOE-Free Realms" = Free Realms
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 1/22/2013 11:50:41 AM | Computer Name = jtmeserole-PC | Source = Application Hang | ID = 1002
Description = The program TuxMath.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 1124 Start Time: 01cdf8b82b55085c Termination Time: 5

Error - 1/22/2013 4:58:12 PM | Computer Name = jtmeserole-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 18.0.1.4764 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: bd0 Start Time: 01cdf8a47e5f64ac Termination Time: 99

Error - 1/22/2013 9:15:24 PM | Computer Name = jtmeserole-PC | Source = WinMgmt | ID = 10
Description =

Error - 1/22/2013 11:09:39 PM | Computer Name = jtmeserole-PC | Source = SignInAssistant | ID = 0
Description =

Error - 1/23/2013 9:05:29 AM | Computer Name = jtmeserole-PC | Source = WinMgmt | ID = 10
Description =

Error - 1/23/2013 11:37:51 AM | Computer Name = jtmeserole-PC | Source = Application Error | ID = 1000
Description = Faulting application plugin-container.exe, version 18.0.1.4764, time
stamp 0x50f70549, faulting module ntdll.dll, version 6.0.6002.18541, time stamp
0x4ec3e3d5, exception code 0xc0000374, fault offset 0x000b06b7, process id 0x5dc,
application start time 0x01cdf97f9a05c5b2.

Error - 1/23/2013 10:51:10 PM | Computer Name = jtmeserole-PC | Source = WinMgmt | ID = 10
Description =

Error - 1/23/2013 11:40:06 PM | Computer Name = jtmeserole-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 18.0.1.4764 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 96c Start Time: 01cdf9e374121164 Termination Time: 6

Error - 1/23/2013 11:54:56 PM | Computer Name = jtmeserole-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 18.0.1.4764 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 1630 Start Time: 01cdf9e481bbb2c4 Termination Time: 182

Error - 1/24/2013 9:32:15 AM | Computer Name = jtmeserole-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 1/23/2013 10:51:10 PM | Computer Name = jtmeserole-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 1/23/2013 10:51:10 PM | Computer Name = jtmeserole-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 1/23/2013 10:52:56 PM | Computer Name = jtmeserole-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 1/23/2013 11:24:45 PM | Computer Name = jtmeserole-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.254.3 for the Network Card with network
address 0026184ACF44 has been denied by the DHCP server 192.168.254.254 (The DHCP
Server sent a DHCPNACK message).

Error - 1/24/2013 9:32:16 AM | Computer Name = jtmeserole-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 1/24/2013 9:32:16 AM | Computer Name = jtmeserole-PC | Source = Service Control Manager | ID = 7024
Description =

Error - 1/24/2013 9:32:16 AM | Computer Name = jtmeserole-PC | Source = Service Control Manager | ID = 7024
Description =

Error - 1/24/2013 9:32:16 AM | Computer Name = jtmeserole-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 1/24/2013 9:32:16 AM | Computer Name = jtmeserole-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 1/24/2013 9:32:16 AM | Computer Name = jtmeserole-PC | Source = Service Control Manager | ID = 7026
Description =


< End of report >


OTL logfile created on: 1/24/2013 8:14:56 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\jtmeserole\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 1.84 Gb Available Physical Memory | 63.95% Memory free
5.96 Gb Paging File | 5.03 Gb Available in Paging File | 84.44% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 286.80 Gb Total Space | 141.77 Gb Free Space | 49.43% Space Free | Partition Type: NTFS
Drive D: | 11.28 Gb Total Space | 1.59 Gb Free Space | 14.08% Space Free | Partition Type: NTFS
Drive F: | 298.02 Gb Total Space | 121.47 Gb Free Space | 40.76% Space Free | Partition Type: FAT32

Computer Name: JTMESEROLE-PC | User Name: jtmeserole | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\jtmeserole\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton 360\Engine\20.2.1.22\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe (Windstream)
PRC - C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe (Windstream)
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wpcumi.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Norton 360\Engine\20.2.1.22\wincfi39.dll ()


========== Services (SafeList) ==========

SRV - (sftlist) – C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (N360) – C:\Program Files\Norton 360\Engine\20.2.1.22\ccSvcHst.exe (Symantec Corporation)
SRV - (NSM) – C:\Program Files\Norton Family\Engine\2.6.0.43\ccSvcHst.exe (Symantec Corporation)
SRV - (Norton PC Checkup Application Launcher) – C:\Program Files\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe (Symantec Corporation)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (ServicepointService) – C:\Program Files\Windstream\Service Agent\ServicepointService.exe (Radialpoint SafeCare Inc.)
SRV - (sftvsa) – C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (UMVPFSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (PCCUJobMgr) – C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe (Symantec Corporation)
SRV - (HsdService) – C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe (Windstream)
SRV - (GameConsoleService) – C:\Program Files\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (EraserUtilDrvI10) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI10.sys File not found
DRV - (catchme) – C:\Users\JTMESE~1\AppData\Local\Temp\catchme.sys File not found
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\VirusDefs\20130123.023\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\VirusDefs\20130123.023\NAVENG.SYS (Symantec Corporation)
DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\BASHDefs\20130116.013\BHDrvx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\IPSDefs\20130123.001\IDSvix86.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\N360\1402010.016\srtsp.sys (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\System32\drivers\N360\1402010.016\symefa.sys (Symantec Corporation)
DRV - (SymDS) – C:\Windows\System32\drivers\N360\1402010.016\symds.sys (Symantec Corporation)
DRV - (SYMTDIv) – C:\Windows\System32\drivers\N360\1402010.016\symtdiv.sys (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\System32\drivers\N360\1402010.016\ironx86.sys (Symantec Corporation)
DRV - (ccSet_N360) – C:\Windows\System32\drivers\N360\1402010.016\ccsetx86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (ccSet_NSM) – C:\Windows\System32\drivers\NSM\0206000.02B\ccSetx86.sys (Symantec Corporation)
DRV - (SYMRDR_{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}) – C:\Windows\System32\drivers\NSM\0206000.02B\symrdr.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\N360\1402010.016\srtspx.sys (Symantec Corporation)
DRV - (SCDEmu) – C:\Windows\System32\drivers\scdemu.sys (Power Software Ltd)
DRV - (Sftvol) – C:\Windows\System32\drivers\Sftvollh.sys (Microsoft Corporation)
DRV - (Sftredir) – C:\Windows\System32\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV - (Sftplay) – C:\Windows\System32\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV - (Sftfs) – C:\Windows\System32\drivers\Sftfslh.sys (Microsoft Corporation)
DRV - (LVUVC) – C:\Windows\System32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\Windows\System32\drivers\lvrs.sys (Logitech Inc.)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corporation)
DRV - (USBCCID) – C:\Windows\System32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (ElRawDisk) – C:\Windows\System32\drivers\rsdrv.sys (EldoS Corporation)
DRV - (nvrd32) – C:\Windows\System32\drivers\nvrd32.sys (NVIDIA Corporation)
DRV - (nvstor32) – C:\Windows\System32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (MHIKEY10) – C:\Windows\System32\drivers\MHIKEY10.sys (Generic USB smartcard reader)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (irsir) – C:\Windows\System32\drivers\irsir.sys (Microsoft Corporation)
DRV - (dsiarhwprog) – C:\Windows\System32\drivers\dsiarhwprog.sys (Thesycon GmbH, Germany)
DRV - (sscdserd) – C:\Windows\System32\drivers\sscdserd.sys (MCCI)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKLM\..\SearchScopes\{7EC2F961-F9C4-4F23-8885-C882FF51F8B2}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HPDTDF
IE - HKLM\..\SearchScopes\{8A96AF9E-4074-43b7-BEA3-87217BDA7405}: "URL" = http://www.searchqu.com/web?src=ieb&sy;…q={searchTerms}
IE - HKLM\..\SearchScopes\{EB475035-0EBF-456D-88E2-19D936F8977D}: "URL" = http://www.ask.com/web?q={searchTerms}&l;=dis&o;=uscqd

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 98 7D 03 02 CE 6E E2 4D 9F 26 81 EE 65 AF 76 3D [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {C4E9144D-8269-4F50-B1BE-371B8170CF5A}
IE - HKCU\..\SearchScopes\{7EC2F961-F9C4-4F23-8885-C882FF51F8B2}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{87F4AA8D-49A2-40F5-A3C0-5178A5EB883A}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2801948
IE - HKCU\..\SearchScopes\{8A96AF9E-4074-43b7-BEA3-87217BDA7405}: "URL" = http://www.searchqu.com/web?src=ieb&sy;…q={searchTerms}
IE - HKCU\..\SearchScopes\{9B97950D-482C-1D79-568F-FC7B9D40C785}: "URL" = http://www.bing.com/search?q={searchTerms}…eferrer:source}
IE - HKCU\..\SearchScopes\{C4E9144D-8269-4F50-B1BE-371B8170CF5A}: "URL" = http://www.google.com/search?q={searchTerms}
IE - HKCU\..\SearchScopes\{EB0EBC8D-EEA7-40EF-A953-3FF678C87F77}: "URL" = http://websearch.ask.com/redirect?client=i…E08CD3777D&
IE - HKCU\..\SearchScopes\{EB475035-0EBF-456D-88E2-19D936F8977D}: "URL" = http://www.ask.com/web?q={searchTerms}&l;=dis&o;=uscqd
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.defaultthis.engineName: "www.google.com"
FF - prefs.js..browser.search.defaulturl: "Bing"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.ldsscripturemastery.net/en/"
FF - prefs.js..extensions.enabledAddons: %7Be001c731-5e37-4538-a5cb-8168736a2360%7D:0.9.9.119
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:5.0.1
FF - prefs.js..extensions.enabledItems: [removed]:2.3
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: [removed]:1.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {000F1EA4-5E08-4564-A29B-29076F63A37A}:[removed]
FF - prefs.js..extensions.enabledItems: {6D5C8FC4-DE46-41bf-9092-93F0F78E9115}:2.1.0.51
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.11.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MI1933~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MI1933~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Musicnotes.com/Musicnotes Viewer,version=1.18.9: C:\Program Files\Musicnotes\npmusicn.dll (Musicnotes, Inc.)
FF - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files\Windstream\Service Agent\nprpspa.dll (Windstream)
FF - HKLM\Software\MozillaPlugins\@Sibelius.com/Scorch Plugin,version=6.2.0.88: C:\Program Files\Musicnotes\npsibelius.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll ()
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\jtmeserole\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6D5C8FC4-DE46-41bf-9092-93F0F78E9115}: C:\ProgramData\Norton\{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}\NSM_2.6.0.43\coFFFw\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/03/28 09:30:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\IPSFFPlgn\ [2012/11/22 13:04:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\coFFPlgn\ [2013/01/24 07:31:37 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/01/18 21:36:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/01/18 21:36:52 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/03/28 09:30:49 | 000,000,000 | —D | M]

[2011/11/09 10:14:59 | 000,000,000 | —D | M] (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Extensions
[2013/01/17 13:39:49 | 000,000,000 | —D | M] (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions
[2012/09/11 12:55:36 | 000,000,000 | —D | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
[2010/09/27 20:35:19 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/06/27 14:16:06 | 000,000,000 | —D | M] (Bitdefender QuickScan) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2012/05/18 17:51:09 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2010/09/20 14:59:14 | 000,000,000 | —D | M] (KidZui) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2012/04/23 17:38:59 | 000,234,665 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2011/08/23 21:57:12 | 000,074,961 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2008/01/20 20:23:50 | 000,004,815 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2011/07/19 19:56:57 | 000,310,942 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2012/12/17 11:34:28 | 000,222,578 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.xpi
[2012/03/30 09:31:17 | 000,685,019 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi
[2011/05/03 10:52:57 | 000,002,469 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\safesearch.xml
[2013/01/18 21:36:51 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/01/18 21:36:55 | 000,262,552 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/08/14 09:09:55 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol400.dll
[2012/10/19 17:18:49 | 000,248,192 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2012/10/19 17:18:57 | 000,248,192 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2010/03/31 10:09:22 | 010,437,264 | —- | M] (PDFTron Systems Inc.) – C:\Program Files\mozilla firefox\plugins\PDFNetC.dll
[2010/04/08 12:36:02 | 000,107,760 | —- | M] () – C:\Program Files\mozilla firefox\plugins\ScorchPDFWrapper.dll
[2012/06/18 16:44:09 | 000,003,749 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/08/29 16:21:22 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/19 17:32:47 | 000,002,058 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://isearch.avg.com/?cid={9BC737C8-EB9C…mp;d=2012-06-18 17:44:13&v;=11.1.0.7&sap;=hp
CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url = http://isearch.avg.com/search?cid={9BC737C…mp;d=2012-06-18 17:44:13&v;=11.1.0.7&sap;=dsp&q;={searchTerms}
CHR - default_search_provider: suggest_url = http://clients5.google.com/complete/search…outputEncoding}
CHR - homepage: http://isearch.avg.com/?cid={9BC737C8-EB9C…mp;d=2012-06-18 17:44:13&v;=11.1.0.7&sap;=hp
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Client Gateway 4.1.15 (Enabled) = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmmhpfbhngkongobaoibpmnijjokabmj\1.0_0\nprpspa.dll
CHR - plugin: Norton Confidential (Enabled) = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbkkogpfmmfmppkbopdikooeibnjhfpi\2.3.0.19_0\npcoplgn.dll
CHR - plugin: Norton Confidential (Enabled) = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.3.7_0\npcoplgn.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: ScorchPlugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPSibelius.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MI1933~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MI1933~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Musicnotes (Enabled) = C:\Program Files\Musicnotes\npmusicn.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\jtmeserole\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: SOE Web Installer (Enabled) = C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - Extension: Missing e = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcjbagclppcgdbpobcpoojdjdmcjhpid\2.14.3_0\
CHR - Extension: YouTube = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\
CHR - Extension: Google Search = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\
CHR - Extension: The Great Grass Sea Theme = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpghdlkjginnphhfpdccobkbncldkgmc\1.0_0\
CHR - Extension: Radialpoint SPD Extension = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmmhpfbhngkongobaoibpmnijjokabmj\1.0_0\
CHR - Extension: Norton Identity Protection = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.2.0.18_0\
CHR - Extension: Gmail = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2013/01/17 21:07:58 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\20.2.1.22\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\20.2.1.22\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Norton Family BHO) - {B8E07826-0971-4f16-B133-047B88034E89} - C:\Program Files\Norton Family\Engine\2.6.0.43\coIEPlg.dll File not found
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\20.2.1.22\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [DiagnosticTools.exe] C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe (Windstream)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [Windstream Service Agent.exe] C:\Program Files\Windstream\Service Agent\Windstream Service Agent.exe (Windstream)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (BitDefender QuickScan Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/…can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DC2E7865-5ADB-466A-9527-0EFA9B7FF184}: DhcpNameServer = 192.168.254.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\jtmeserole\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\jtmeserole\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2008/06/27 10:31:18 | 000,000,000 | —D | M] - F:\autorun – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/01/22 21:22:25 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\jtmeserole\Desktop\OTL.exe
[2013/01/18 21:36:51 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/01/18 21:19:48 | 000,000,000 | —D | C] – C:\Windows\temp
[2013/01/18 21:19:48 | 000,000,000 | —D | C] – C:\Users\jtmeserole\AppData\Local\temp
[2013/01/18 21:19:16 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/01/17 21:28:38 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2013/01/17 21:28:03 | 000,859,552 | —- | C] (Oracle Corporation) – C:\Windows\System32\npDeployJava1.dll
[2013/01/17 21:28:03 | 000,261,024 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2013/01/17 21:27:35 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2013/01/17 21:27:35 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\System32\java.exe
[2013/01/17 21:27:35 | 000,094,112 | —- | C] (Oracle Corporation) – C:\Windows\System32\WindowsAccessBridge.dll
[2013/01/17 21:14:27 | 031,473,568 | —- | C] (Oracle Corporation) – C:\Users\jtmeserole\Desktop\jre-7u11-windows-i586.exe
[2013/01/17 20:54:27 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/01/17 20:54:27 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/01/17 20:54:27 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/01/17 20:51:59 | 000,000,000 | —D | C] – C:\Qoobox
[2013/01/17 20:44:56 | 005,023,971 | R— | C] (Swearware) – C:\Users\jtmeserole\Desktop\ComboFix.exe
[2013/01/14 15:43:26 | 000,000,000 | —D | C] – C:\Users\jtmeserole\AppData\Roaming\Playrix Entertainment
[2013/01/14 15:41:18 | 000,000,000 | —D | C] – C:\Program Files\Coupons
[2013/01/14 13:09:12 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/01/14 13:06:46 | 000,000,000 | —D | C] – C:\JRT
[2013/01/13 21:20:53 | 000,000,000 | —D | C] – C:\Users\jtmeserole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Royal Envoy 2
[2013/01/13 21:20:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Royal Envoy 2
[2013/01/13 21:20:53 | 000,000,000 | —D | C] – C:\Program Files\Royal Envoy 2
[2013/01/13 21:16:25 | 000,000,000 | —D | C] – C:\Users\jtmeserole\AppData\Roaming\Realore_Whiterra Roads Of Rome 3
[2013/01/13 21:14:50 | 000,000,000 | —D | C] – C:\Users\jtmeserole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roads of Rome III
[2013/01/13 21:14:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roads of Rome III
[2013/01/13 21:14:50 | 000,000,000 | —D | C] – C:\Program Files\Roads of Rome III
[2013/01/13 21:14:05 | 000,000,000 | —D | C] – C:\Users\jtmeserole\AppData\Roaming\Meridian93
[2013/01/13 21:11:40 | 000,000,000 | —D | C] – C:\Users\jtmeserole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Magic Farm 2 - Fairy Lands
[2013/01/13 21:11:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic Farm 2 - Fairy Lands
[2013/01/13 21:11:40 | 000,000,000 | —D | C] – C:\Program Files\Magic Farm 2 - Fairy Lands
[2013/01/10 17:07:23 | 000,000,000 | —D | C] – C:\Users\jtmeserole\AppData\Local\{1F54E683-0E8B-44BA-AA3E-CFB4069A77E9}
[2013/01/09 11:56:10 | 002,048,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/01/09 11:55:40 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncrypt.dll
[2013/01/04 23:16:10 | 000,000,000 | —D | C] – C:\Users\jtmeserole\AppData\Local\{F1267C69-57B7-4979-BB6B-3EC38190399E}
[2012/03/26 09:22:17 | 035,113,704 | —- | C] (Microsoft Corporation) – C:\Program Files\Common Files\directx_9c_redist.exe
[1 C:\Users\jtmeserole\Desktop\*.tmp files -> C:\Users\jtmeserole\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/01/24 08:06:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/24 08:06:00 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/24 07:31:19 | 000,065,536 | —- | M] () – C:\Windows\System32\Ikeext.etl
[2013/01/24 07:31:13 | 000,003,616 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/24 07:31:13 | 000,003,616 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/24 07:31:03 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/01/23 15:43:01 | 000,001,356 | —- | M] () – C:\Users\jtmeserole\AppData\Local\d3d9caps.dat
[2013/01/23 07:43:40 | 000,029,410 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\wklnhst.dat
[2013/01/23 07:04:36 | 002,293,642 | —- | M] () – C:\Windows\System32\drivers\N360\1402010.016\Cat.DB
[2013/01/23 07:03:33 | 000,014,818 | —- | M] () – C:\Windows\System32\drivers\N360\1402010.016\VT20130115.021
[2013/01/22 21:22:25 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\jtmeserole\Desktop\OTL.exe
[2013/01/22 09:26:06 | 000,697,864 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/01/22 09:26:06 | 000,074,248 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/01/21 10:46:39 | 000,023,604 | —- | M] () – C:\Users\jtmeserole\Desktop\550428_4074845441773_1178477638_n.jpg
[2013/01/18 21:00:07 | 005,023,971 | R— | M] (Swearware) – C:\Users\jtmeserole\Desktop\ComboFix.exe
[2013/01/17 21:27:25 | 000,094,112 | —- | M] (Oracle Corporation) – C:\Windows\System32\WindowsAccessBridge.dll
[2013/01/17 21:27:23 | 000,261,024 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2013/01/17 21:27:23 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2013/01/17 21:27:23 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\System32\java.exe
[2013/01/17 21:27:22 | 000,859,552 | —- | M] (Oracle Corporation) – C:\Windows\System32\npDeployJava1.dll
[2013/01/17 21:27:22 | 000,780,192 | —- | M] (Oracle Corporation) – C:\Windows\System32\deployJava1.dll
[2013/01/17 21:15:00 | 031,473,568 | —- | M] (Oracle Corporation) – C:\Users\jtmeserole\Desktop\jre-7u11-windows-i586.exe
[2013/01/17 21:07:58 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2013/01/17 20:46:50 | 000,000,836 | —- | M] () – C:\Users\jtmeserole\Desktop\ComboFix - Shortcut.lnk
[2013/01/17 13:43:12 | 499,626,117 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/01/16 11:30:27 | 000,604,946 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/01/16 11:30:27 | 000,104,388 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/01/14 13:06:02 | 000,000,805 | —- | M] () – C:\Users\jtmeserole\Desktop\JRT - Shortcut.lnk
[2013/01/14 13:00:32 | 002,213,976 | —- | M] (Kaspersky Lab ZAO) – C:\Users\jtmeserole\Desktop\TDSSKiller.exe
[2013/01/13 21:21:29 | 000,001,741 | —- | M] () – C:\Users\Public\Desktop\Play Royal Envoy 2.lnk
[2013/01/13 21:21:29 | 000,001,192 | —- | M] () – C:\Users\Public\Desktop\More Great Games.lnk
[2013/01/13 21:14:53 | 000,001,775 | —- | M] () – C:\Users\Public\Desktop\Play Roads of Rome III.lnk
[2013/01/13 21:12:00 | 000,001,856 | —- | M] () – C:\Users\Public\Desktop\Play Magic Farm 2 - Fairy Lands.lnk
[2013/01/11 12:35:55 | 000,002,001 | —- | M] () – C:\Users\jtmeserole\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/01/11 12:35:55 | 000,001,977 | —- | M] () – C:\Users\jtmeserole\Desktop\Google Chrome.lnk
[2013/01/10 22:01:33 | 000,000,912 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/10 08:10:04 | 000,381,240 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/01/10 01:46:06 | 000,000,172 | —- | M] () – C:\Windows\System32\drivers\N360\1402010.016\isolate.ini
[2013/01/09 23:11:28 | 000,006,714 | —- | M] () – C:\Users\jtmeserole\Documents\BYE!.jpg
[2013/01/09 22:30:32 | 000,005,935 | —- | M] () – C:\Users\jtmeserole\Documents\instructor oswald.jpg
[2013/01/09 22:23:58 | 000,007,332 | —- | M] () – C:\Users\jtmeserole\Documents\gunpowder.jpg
[2013/01/04 23:22:17 | 000,296,989 | —- | M] () – C:\Users\jtmeserole\Documents\Musicclass.xps
[2012/12/30 00:27:45 | 000,016,384 | —- | M] () – C:\Users\jtmeserole\Documents\trish 2012 tips.xlr
[1 C:\Users\jtmeserole\Desktop\*.tmp files -> C:\Users\jtmeserole\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/01/21 10:46:39 | 000,023,604 | —- | C] () – C:\Users\jtmeserole\Desktop\550428_4074845441773_1178477638_n.jpg
[2013/01/17 20:54:27 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/01/17 20:54:27 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/01/17 20:54:27 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/01/17 20:54:27 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/01/17 20:54:27 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/01/17 20:46:50 | 000,000,836 | —- | C] () – C:\Users\jtmeserole\Desktop\ComboFix - Shortcut.lnk
[2013/01/17 13:43:12 | 499,626,117 | —- | C] () – C:\Windows\MEMORY.DMP
[2013/01/14 13:06:02 | 000,000,805 | —- | C] () – C:\Users\jtmeserole\Desktop\JRT - Shortcut.lnk
[2013/01/13 21:21:29 | 000,001,741 | —- | C] () – C:\Users\Public\Desktop\Play Royal Envoy 2.lnk
[2013/01/13 21:21:29 | 000,001,192 | —- | C] () – C:\Users\Public\Desktop\More Great Games.lnk
[2013/01/13 21:14:53 | 000,001,775 | —- | C] () – C:\Users\Public\Desktop\Play Roads of Rome III.lnk
[2013/01/13 21:12:00 | 000,001,856 | —- | C] () – C:\Users\Public\Desktop\Play Magic Farm 2 - Fairy Lands.lnk
[2013/01/09 23:11:28 | 000,006,714 | —- | C] () – C:\Users\jtmeserole\Documents\BYE!.jpg
[2013/01/09 22:30:32 | 000,005,935 | —- | C] () – C:\Users\jtmeserole\Documents\instructor oswald.jpg
[2013/01/09 22:23:57 | 000,007,332 | —- | C] () – C:\Users\jtmeserole\Documents\gunpowder.jpg
[2013/01/04 23:22:15 | 000,296,989 | —- | C] () – C:\Users\jtmeserole\Documents\Musicclass.xps
[2012/12/30 00:27:45 | 000,016,384 | —- | C] () – C:\Users\jtmeserole\Documents\trish 2012 tips.xlr
[2012/12/29 14:48:23 | 000,035,328 | —- | C] () – C:\Users\jtmeserole\Desktop\01074461.XLT
[2012/12/29 14:48:10 | 000,035,328 | —- | C] () – C:\Users\jtmeserole\01074461.XLT
[2012/09/04 19:29:20 | 000,019,456 | —- | C] () – C:\Users\jtmeserole\01026644.xlt
[2012/08/28 07:43:51 | 000,003,632 | —- | C] () – C:\Users\jtmeserole\profiles.xml
[2012/02/29 09:51:38 | 000,000,022 | —- | C] () – C:\Windows\WinInit.Ini
[2012/02/29 09:51:28 | 000,168,207 | —- | C] () – C:\Windows\System32\Unstall.exe
[2012/01/25 13:38:22 | 000,000,043 | —- | C] () – C:\Users\jtmeserole\Food Storage Planner-Path
[2011/08/20 15:04:22 | 000,150,004 | —- | C] () – C:\Windows\System32\mlfcache.dat
[2011/08/19 03:26:20 | 010,898,456 | —- | C] () – C:\Windows\System32\LogiDPP.dll
[2011/08/19 03:26:20 | 000,336,408 | —- | C] () – C:\Windows\System32\DevManagerCore.dll
[2011/08/19 03:26:20 | 000,104,472 | —- | C] () – C:\Windows\System32\LogiDPPApp.exe
[2011/08/17 17:30:51 | 000,000,115 | —- | C] () – C:\Users\jtmeserole\webct_upload_applet.properties
[2011/08/12 12:20:14 | 000,015,896 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2011/07/26 00:48:54 | 000,028,418 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2011/05/15 18:27:51 | 000,000,092 | -HS- | C] () – C:\Windows\WSYS049.SYS
[2011/05/15 18:26:24 | 000,199,297 | —- | C] () – C:\Windows\Photo Pos Pro Uninstaller.exe
[2011/03/28 09:52:04 | 000,171,321 | —- | C] () – C:\Windows\hpwins27.dat.temp
[2011/03/28 09:52:04 | 000,000,385 | —- | C] () – C:\Windows\hpwmdl27.dat.temp
[2011/03/28 09:20:22 | 000,170,596 | —- | C] () – C:\Windows\hpwins27.dat
[2011/02/12 21:26:46 | 000,000,048 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/10/14 09:35:04 | 000,000,632 | RHS- | C] () – C:\Users\jtmeserole\ntuser.pol
[2010/09/25 18:46:40 | 000,057,344 | —- | C] () – C:\Users\jtmeserole\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/22 22:41:23 | 000,029,410 | —- | C] () – C:\Users\jtmeserole\AppData\Roaming\wklnhst.dat
[2010/09/20 12:18:13 | 000,001,356 | —- | C] () – C:\Users\jtmeserole\AppData\Local\d3d9caps.dat

========== ZeroAccess Check ==========

[2006/11/02 06:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 11:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 00:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 00:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/10/08 18:13:19 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\.minecraft
[2011/09/23 10:48:03 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\.t4k_common
[2011/03/02 19:50:37 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\2monkeys
[2012/09/01 18:32:54 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Anuman
[2012/09/22 20:08:08 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Audacity
[2012/08/08 08:16:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Boolat Games
[2011/09/29 15:30:47 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Catalina Marketing Corp
[2011/05/30 16:30:34 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Chessmaster Challenge
[2012/08/13 20:26:06 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\EuroTalk
[2011/04/10 13:35:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Farm Mania 2.1
[2012/11/22 13:30:03 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Free Download Manager
[2011/01/24 20:48:39 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\freshgames
[2011/09/07 17:15:19 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Guitar Pro 6
[2011/10/17 21:06:00 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\KidZui
[2011/12/11 16:31:28 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Leadertech
[2011/03/03 12:06:46 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Mean Hamster
[2013/01/13 21:14:05 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Meridian93
[2011/03/01 10:52:31 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\MSNInstaller
[2010/10/15 16:58:10 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\MusE
[2010/11/05 17:54:16 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\MusicNet
[2011/02/12 11:24:20 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\NCH Swift Sound
[2010/12/15 13:38:17 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Oberon Games
[2012/08/18 07:56:49 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Peace Craft
[2012/05/03 19:05:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\PlayFirst
[2013/01/14 15:43:26 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Playrix Entertainment
[2013/01/08 17:18:12 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\QuickScan
[2012/11/21 13:53:54 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Radialpoint
[2012/10/06 17:04:46 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\redsn0w
[2012/08/22 19:19:52 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Sandlot Games
[2012/02/27 15:38:58 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\School Zone Preferences
[2010/10/19 10:23:24 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Skunk Studios
[2012/02/28 10:30:52 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\SoftGrid Client
[2012/03/26 08:53:35 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Stellarium
[2012/08/22 19:06:25 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\SulusGames
[2012/03/08 12:16:04 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Super-Cow
[2011/01/25 20:26:00 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Supermarket Mania 2
[2010/09/22 22:41:24 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Template
[2011/09/30 17:21:20 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Tific
[2012/03/01 17:12:26 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\TP
[2012/10/01 12:19:09 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\tuxmath
[2010/09/27 14:17:15 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Unity
[2010/10/18 06:10:46 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\WildTangent
[2012/01/17 20:37:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Windstream
[2010/10/15 19:20:28 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\YoudaGames

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2006/09/18 15:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 00:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2009/05/18 14:28:11 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2013/01/18 21:19:46 | 000,013,578 | —- | M] () – C:\ComboFix.txt
[2006/09/18 15:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2011/09/07 11:57:44 | 000,000,000 | —- | M] () – C:\FileRecovery.log
[2012/02/28 12:03:39 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/02/28 12:03:39 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2013/01/24 07:30:39 | 3399,237,632 | -HS- | M] () – C:\pagefile.sys
[2012/09/04 06:55:42 | 000,000,414 | —- | M] () – C:\TDSSKiller.2.5.15.0_04.09.2012_07.55.37_log.txt
[2012/09/11 14:51:23 | 000,000,414 | —- | M] () – C:\TDSSKiller.2.5.15.0_11.09.2012_15.51.20_log.txt
[2013/01/14 13:06:33 | 000,259,570 | —- | M] () – C:\TDSSKiller.2.8.15.0_14.01.2013_13.01.19_log.txt
[2012/09/04 06:57:29 | 000,132,120 | —- | M] () – C:\TDSSKiller.2.8.8.0_04.09.2012_07.56.29_log.txt
[2012/09/11 14:53:29 | 000,132,458 | —- | M] () – C:\TDSSKiller.2.8.8.0_11.09.2012_15.52.06_log.txt
[2009/05/18 14:31:49 | 000,000,349 | —- | M] () – C:\updatedatfix.log
[2008/08/26 06:37:52 | 000,000,458 | —- | M] () – C:\Windows Sidebar

< %systemroot%\Fonts\*.com >
[2006/11/02 06:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 06:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 06:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/12/21 11:24:56 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 15:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/04/20 11:23:48 | 000,315,904 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpfpp70w.dll
[2008/01/20 20:23:14 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 06:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 01:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 20:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 21:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 21:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 21:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/10/28 18:13:39 | 000,000,351 | -HS- | M] () – C:\Users\jtmeserole\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/08/17 19:23:28 | 001,404,720 | —- | M] (Kaspersky Lab ZAO) – C:\Users\jtmeserole\Desktop\12345.com.exe
[2011/08/20 14:55:47 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\jtmeserole\Desktop\ATF_Cleaner.exe
[2013/01/18 21:00:07 | 005,023,971 | R— | M] (Swearware) – C:\Users\jtmeserole\Desktop\ComboFix.exe
[2013/01/17 21:15:00 | 031,473,568 | —- | M] (Oracle Corporation) – C:\Users\jtmeserole\Desktop\jre-7u11-windows-i586.exe
[2012/11/22 13:01:44 | 154,740,304 | —- | M] (Symantec Corporation) – C:\Users\jtmeserole\Desktop\N360-ESD-20-1-1-2-EN.exe
[2012/11/22 12:09:15 | 000,866,592 | —- | M] () – C:\Users\jtmeserole\Desktop\Norton_Removal_Tool.exe
[2013/01/22 21:22:25 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\jtmeserole\Desktop\OTL.exe
[2013/01/14 13:00:32 | 002,213,976 | —- | M] (Kaspersky Lab ZAO) – C:\Users\jtmeserole\Desktop\TDSSKiller.exe
[1 C:\Users\jtmeserole\Desktop\*.tmp files -> C:\Users\jtmeserole\Desktop\*.tmp -> ]

< %PROGRAMFILES%\Common Files\*.* >
[2012/03/26 09:22:17 | 035,113,704 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\directx_9c_redist.exe

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EXE >
[1995/04/25 01:00:00 | 000,969,792 | —- | M] () MD5=182749693EF4B3BE232EAC23BC68A448 – C:\HISTORY\EXPLORER.EXE
[2009/05/18 14:45:17 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2009/05/18 14:45:16 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2009/05/18 14:45:16 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/11 00:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\ERDNT\cache\explorer.exe
[2009/04/11 00:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/11 00:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2009/05/18 14:45:16 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/20 20:24:24 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: EXPLORER.EXE.3164.DMP >
[2013/01/17 20:48:36 | 003,469,158 | —- | M] () MD5=922F306FBA3C8D838F683FB1C74F171C – C:\Users\jtmeserole\AppData\Local\CrashDumps\explorer.exe.3164.dmp

< MD5 for: EXPLORER.EXE.MUI >
[2006/11/02 06:41:18 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\en-US\explorer.exe.mui
[2006/11/02 06:41:18 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_03bbc52176b6ba20\explorer.exe.mui

< MD5 for: EXPLORER.EXE-7A3328DA.PF >
[2013/01/22 09:11:27 | 000,342,752 | —- | M] () MD5=031CFD4A13BE11DFC8079D4560578A9D – C:\Windows\Prefetch\EXPLORER.EXE-7A3328DA.pf

< MD5 for: EXPLORER.HLP >
[1995/04/25 01:00:00 | 000,571,344 | —- | M] () MD5=78B5A9803EBA4EA7CE1CCEEE76F5543E – C:\HISTORY\EXPLORER.HLP

< MD5 for: EXPLORER.INI >
[2012/03/09 11:21:51 | 000,000,467 | —- | M] () MD5=05C10B448D97CCD55D08AD8583583DEA – C:\HISTORY\EXPLORER.INI

< MD5 for: IEXPLORE.BAT >
[2013/01/04 14:58:30 | 000,031,067 | —- | M] () MD5=709A62B22C7BA09D875F765341E0FFFC – C:\JRT\iexplore.bat

< MD5 for: IEXPLORE.EXE >
[2012/05/17 17:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16446_none_5898f8e3ebb5c47b\iexplore.exe
[2011/07/23 05:02:27 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=04D1DC458C723B291179F8449ACC281D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19120_none_12355fcb2fdc2111\iexplore.exe
[2009/05/18 14:30:20 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=07ED775D6DB4BFA96D7CFB09EB228418 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16681_none_2d26424d1d17e8b7\iexplore.exe
[2009/05/18 14:49:59 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=0844F5B9CB3BB85A917D347EF1565B6C – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16809_none_2d84c7c91ccfce35\iexplore.exe
[2012/11/13 20:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Program Files\Internet Explorer\iexplore.exe
[2012/11/13 20:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\ERDNT\cache\iexplore.exe
[2012/11/13 20:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16457_none_588f2941ebbcf9c3\iexplore.exe
[2011/09/30 17:49:11 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=0E1695AD4C30E72D68170F01B4818A80 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23250_none_129e8cd2491214ae\iexplore.exe
[2009/05/18 14:35:44 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=157F8DE991396C536820D7FA5C8DCF7D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16711_none_2d71f3a71cdf2247\iexplore.exe
[2009/05/18 14:29:17 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=182CAF7403705ACCB51211A761080B8F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20777_none_2dc0b0c03628049a\iexplore.exe
[2009/05/18 14:40:03 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=19403B64906C9EAC627E3C10847B0FDA – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16757_none_2d4cb5b31cfa2a15\iexplore.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2012/08/24 01:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16450_none_5888273bebc34862\iexplore.exe
[2012/05/17 16:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20551_none_5912c45104e00183\iexplore.exe
[2012/10/08 02:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16455_none_588d28adebbec715\iexplore.exe
[2011/11/03 01:33:09 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=2A268DF89913A0E927091077878EDB3E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23266_none_1299bea24914c8a9\iexplore.exe
[2009/04/11 00:27:44 | 000,636,080 | —- | M] (Microsoft Corporation) MD5=2C5168C856455CC43C4B4E1CC1920001 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_314d791517204c15\iexplore.exe
[2012/06/02 03:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16447_none_5899f92debb4ddd2\iexplore.exe
[2010/09/08 00:26:34 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=4A719476A6393B1DCACFEB4F3AC6599C – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23067_none_129abb204913e7b2\iexplore.exe
[2009/05/18 14:43:57 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=4CBA2F58668F2D5F3259CBE73E227F25 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20937_none_2debf43c36078f24\iexplore.exe
[2011/07/23 05:42:34 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=4D08A4234D645EFCB30605CC0BFA87F4 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23216_none_12cfce3e48ec3cf4\iexplore.exe
[2009/05/18 14:35:44 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=4DBD95312B1C96C5285D38F1D748CD4D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20868_none_2dcc82dc361eff27\iexplore.exe
[2011/12/15 01:36:29 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=54EF418BD99720658CCE24210799BD1A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23286_none_12841eca4925008b\iexplore.exe
[2010/11/02 00:03:13 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=5AB037B17F8A87D052F5A88E0D29A3C8 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18999_none_11f2d8e9300c984e\iexplore.exe
[2008/01/20 20:23:50 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=5B92133D3E7FB2644677686305E29E81 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_2f62000919fe80c9\iexplore.exe
[2012/08/24 01:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20557_none_5918c60d04da998d\iexplore.exe
[2009/05/18 14:40:03 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=6655B851D9EEF7C83395EE52D551B448 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20927_none_2df6c42835ff7333\iexplore.exe
[2010/06/26 00:06:48 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7420BE0E7D3D1320054F7ACA0594953D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18943_none_1222e6c92fe9748f\iexplore.exe
[2010/12/18 01:19:44 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7852371DA9EFBC17B645558E23780EAC – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23111_none_12cacae648f0c11a\iexplore.exe
[2011/09/30 17:07:49 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=7ACBBC85FCE4989B533220FC3B291633 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19154_none_1218f12f2ff0da40\iexplore.exe
[2011/05/28 01:09:20 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7EE10C5413AD7ED1AF9E8FAE1B58FC3E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23181_none_127f1b72492984b1\iexplore.exe
[2010/06/28 10:33:13 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=867D06F3C473F65921F5EDF35866FF14 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22720_none_2fd60860332c475f\iexplore.exe
[2012/02/20 03:02:12 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16421_none_58a99749ebaa0de6\iexplore.exe
[2010/11/02 01:13:47 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=92A17B0A89D14815AACC62CD190B6CE3 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23091_none_127449a04931a37b\iexplore.exe
[2012/06/28 19:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16448_none_589af977ebb3f729\iexplore.exe
[2009/05/18 14:29:17 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=9437CA21CD48C9B6BFD6F5AC0143D251 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16643_none_2d5382911cf5aba1\iexplore.exe
[2011/02/22 01:18:28 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=9CE5543464432CA73134F170FA2BF823 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23143_none_12ac5bb64907479b\iexplore.exe
[2009/05/18 14:30:20 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=9F1427F203CA078005C9943800929640 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20823_none_2df2c11a360310b0\iexplore.exe
[2011/12/15 00:22:33 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=AB18B8902C06954F8DFBAC5C6DC7E1E8 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19190_none_11e9b0573014e4a8\iexplore.exe
[2009/03/08 15:09:24 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18702_none_124d22632fc9f126\iexplore.exe
[2010/06/28 10:19:40 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6D7D54B736056991109F169737592C7 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18498_none_2f08baa51a403b96\iexplore.exe
[2010/12/18 00:28:35 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=B988D7F127B94BD5BF8356FE81B985C4 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19019_none_1249306b2fcbec08\iexplore.exe
[2012/06/02 02:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20553_none_5914c4e504de3431\iexplore.exe
[2011/02/22 00:21:12 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=C1D36A2CBE0CEC4DF593DB1288CF586E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19048_none_1227c05d2fe52684\iexplore.exe
[2011/11/03 00:23:19 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=CCDB0B2D1F2E016966B1DB1097E24842 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19170_none_11ff502f3004acc6\iexplore.exe
[2012/10/08 02:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20562_none_5908f4af04e736cb\iexplore.exe
[2010/09/08 00:02:42 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=D5A730DFDEAE005373E62BC2A866E3BB – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18975_none_120477992ffffb10\iexplore.exe
[2009/05/18 14:43:57 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=D762642A109433EEDCD332B0A9511137 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16764_none_2d3ee4e91d04fa01\iexplore.exe
[2012/06/28 17:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20554_none_5915c52f04dd4d88\iexplore.exe
[2011/05/28 00:09:21 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=ED65737D70FDEAC29F738E77D2496EE5 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19088_none_11fc80ad30059648\iexplore.exe
[2010/06/26 00:52:42 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=F05B3A2C6CB319DD1377AD566CF5ECE5 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23040_none_12a958f24909fe6f\iexplore.exe
[2009/05/18 14:49:59 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=F0B1CA517977BA2FF6DA33F1B966C488 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20996_none_2daa146a36391d73\iexplore.exe
[2012/11/13 20:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20565_none_590bf58d04e482d0\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2006/11/02 06:41:15 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_3b55b11a57da5590\iexplore.exe.mui
[2012/02/20 03:02:13 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012/02/20 03:02:13 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.1.8112.16421_en-us_52562cc123574ecd\iexplore.exe.mui
[2009/03/08 15:27:11 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_8.0.6001.18702_en-us_207795706a90d6c1\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-1B894AFB.PF >
[2013/01/22 21:10:49 | 000,246,656 | —- | M] () MD5=CB51AB05277850AB46A4DC26F2EBE548 – C:\Windows\Prefetch\IEXPLORE.EXE-1B894AFB.pf

< MD5 for: SERVICES >
[2006/09/18 15:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows\System32\drivers\etc\services
[2006/09/18 15:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6000.16386_none_024e4071fa6fea95\services

< MD5 for: SERVICES.DAT >
[2013/01/02 22:13:04 | 000,001,473 | —- | M] () MD5=108383F37C9E5A81588433B23995EBD8 – C:\JRT\services.dat

< MD5 for: SERVICES.EXE >
[2008/01/20 20:24:48 | 000,279,040 | —- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2009/04/11 00:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\ERDNT\cache\services.exe
[2009/04/11 00:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\System32\services.exe
[2009/04/11 00:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2006/11/02 06:40:53 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows\System32\en-US\services.exe.mui
[2006/11/02 06:40:53 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.0.6000.16386_en-us_67c6851b290a1ced\services.exe.mui

< MD5 for: SERVICES.LNK >
[2008/01/20 20:42:58 | 000,001,688 | —- | M] () MD5=C50AE46E57C3F3FB61A3B3A1E5D9C412 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2008/01/20 20:42:58 | 000,001,688 | —- | M] () MD5=C50AE46E57C3F3FB61A3B3A1E5D9C412 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2006/09/18 15:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2006/09/18 15:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.mof
[2006/09/18 15:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.mof

< MD5 for: SERVICES.MSC >
[2006/11/02 06:41:29 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2006/09/18 15:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2006/11/02 06:41:29 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.0.6000.16386_en-us_a2085506ff73b6e0\services.msc
[2006/09/18 15:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6001.18000_none_cf63e2a445bae4e3\services.msc

< MD5 for: WINLOGON.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/04/11 00:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\ERDNT\cache\winlogon.exe
[2009/04/11 00:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/11 00:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 20:24:49 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2008/01/20 20:25:40 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\System32\en-US\winlogon.exe.mui
[2008/01/20 20:25:40 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_en-us_caf8918b0416723a\winlogon.exe.mui
[2006/11/02 06:40:50 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=A1D2856F3EC3C86EBBF1442B0245A8B3 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_en-us_c8c1cf8f072b6166\winlogon.exe.mui

< MD5 for: WINLOGON.EXE-8163EECC.PF >
[2013/01/22 16:26:35 | 000,034,524 | —- | M] () MD5=8F15401978FD9FAAFBAC43E39F862285 – C:\Windows\Prefetch\WINLOGON.EXE-8163EECC.pf

< MD5 for: WINLOGON.MOF >
[2006/09/18 15:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\System32\wbem\winlogon.mof
[2006/09/18 15:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.0.6000.16386_none_7e0207d478fccc94\winlogon.mof

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-01-10 13:54:41

========== Alternate Data Streams ==========

@Alternate Data Stream - 231 bytes -> C:\ProgramData\Temp:4B244549
@Alternate Data Stream - 228 bytes -> C:\ProgramData\Temp:E5F8E280
@Alternate Data Stream - 223 bytes -> C:\ProgramData\Temp:162E02F7
@Alternate Data Stream - 221 bytes -> C:\ProgramData\Temp:ED9B661E
@Alternate Data Stream - 214 bytes -> C:\ProgramData\Temp:966CEAE7
@Alternate Data Stream - 213 bytes -> C:\ProgramData\Temp:517B507A
@Alternate Data Stream - 208 bytes -> C:\ProgramData\Temp:FEEEFFAD
@Alternate Data Stream - 206 bytes -> C:\ProgramData\Temp:1663E41B
@Alternate Data Stream - 195 bytes -> C:\ProgramData\Temp:A1D3FEF0
@Alternate Data Stream - 158 bytes -> C:\ProgramData\Temp:6B708944
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:FD786DCA
@Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:F98E6C67
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:A6B07419
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:A69FAA24
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:A2B3764A
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:00811B66
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:D2397415
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:9CF728A6
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:A8606E6E
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:C9BC8592
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:A9ABA3FF
@Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:A00BCDEF
@Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp:CE6885F1
@Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:18897B1D

< End of report >
I'm still seeing a lot of the items that Junkware Tool Remover should have taken care of so let's run that again. Please right-click and delete it if it's still on your desktop and let's download a fresh copy as it's updated often.


[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

Please reboot your computer after running this tool.


Then, I'd like you to do the following:


Please open your Chrome Browser and in the upper right hand corner you'll see the little icon that looks like a menu or several little stacked lines.
Click on it to open the menu and then choose Settings
At the bottom of the screen you will see where you can click on "Show Advanced Settings"
In the section for Privacy, you will see a button to click called Content Settings, please click on that
Scroll down to Plug-Ins and click on Disable Individual Plug-Ins
You want to locate the Plug-in called Remoting Viewer (or internal-remoting-viewer) and Disable and if you have the option remove it
Then go ahead and close Chrome.



Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal.

Double click ComboFix.exe to run it. It will prompt you that an update is available - please allow it to update.

Follow all prompts. Post the C:\ComboFix.txt when it has completed.

Follow the same directions for Combofix as before, don't do anything while it is running and post the resulting log. After it's done, please reboot the machine and give things a try and let me know how things are running.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI