This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Win32/small.CA - Troj/Exps-Cl - W32/Autorun-ALP [Solved]

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey What the Tech

Earlier today i had a warning from Windows telling me that Win32/small.CA had caused my computer to not function properly. Trying the Windows solution of using their definitions gave no result in removing the virus.

Quick view on the internet indicates that you guys are the once who can actually help me.

After discovering the virus I also ran my antivirus(sophos), which yielded two other warnings, the Troj and W32, stated in the topic title. I asked the program to clean these up, but i not sure that its done correctly. And nothing indicates that the Win32/small has actually been removed. (Seems the W32/Autorun was on my external hdd that was connected at that point)

While trying to clean up my computer, i also deleted and updated Adobe and Java.

I then ran the HijackThis program, which yielded the following log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:49:40, on 31-01-2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Program Files (x86)\BOINC\boincmgr.exe
C:\Program Files (x86)\BOINC\boinctray.exe
C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
C:\Program Files (x86)\Creative\USB Sound Blaster HD\Volume Panel\VolPanlu.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\BOINC\boinc.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Users\dtb05\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\dtb05\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\dtb05\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\dtb05\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\dtb05\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\dtb05\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\dtb05\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\dtb05\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\dtb05\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nfit.au.dk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [AutoProfileRepair] "C:\Program Files (x86)\Oracle\Outlook Connector\profilerepair.exe" -msi
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [boincmgr] "C:\Program Files (x86)\BOINC\boincmgr.exe" /a /s
O4 - HKLM\..\Run: [boinctray] "C:\Program Files (x86)\BOINC\boinctray.exe"
O4 - HKLM\..\Run: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files (x86)\Creative\USB Sound Blaster HD\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Users\dtb05\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-2231803270-93480321-3026884197-1066\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background (User 'Dines')
O4 - HKUS\S-1-5-21-2231803270-93480321-3026884197-1066\..\Run: [Google Update] "C:\Users\Dines\AppData\Local\Google\Update\GoogleUpdate.exe" /c (User 'Dines')
O4 - HKUS\S-1-5-21-2231803270-93480321-3026884197-1066\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload (User 'Dines')
O4 - HKUS\S-1-5-21-2231803270-93480321-3026884197-1066\..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (User 'Dines')
O4 - HKUS\S-1-5-21-2231803270-93480321-3026884197-500\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background (User 'Administrator')
O4 - HKUS\S-1-5-21-2231803270-93480321-3026884197-500\..\RunOnce: [InetReg] "C:\Program Files (x86)\Creative\Product Registration\English\InetReg.exe" /PreProcess=RegFlash.exe /Delay=6 (User 'Administrator')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_e085d3cd5b474ba6\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Credential Vault Host Control Service - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
O23 - Service: Credential Vault Host Storage - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - Unknown owner - c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FF Install Filter Service (InstallFilterService) - Unknown owner - C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\InstallFilterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Oracle Connector Automatic Updates Service (ocautoupds) - Oracle Corporation - C:\Program Files (x86)\Oracle\Outlook Connector\ocautoupds.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Limited - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Limited - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Sophos AutoUpdate Service - Sophos Limited - C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Web Control Service - Sophos Limited - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_e085d3cd5b474ba6\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Sophos Web Intelligence Service (swi_service) - Sophos Limited - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
O23 - Service: Sophos Web Intelligence Update (swi_update_64) - Sophos Limited - C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 15739 bytes


Many thanks in advance.
Hi and Welcome!! My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Having said that….Let's get going!!
———-
Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any antivirus programs during the scan (If you have difficulty properly disabling your protective programs, refer to this link here )
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

[external image: Posted Image] Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

[external image: Posted Image] AdwCleaner
  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • You will be prompted to restart your computer. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
———-
Ok, ran all the programs as administrator. When running the awsMBR I was prompted with a message telling me the program had stopped working and that it would be shutdown(Ran it three times - all as administrator). All programs and windows were shutdown, when running it the 3. time. It was allowed to update. Also, Sophos was turned off for all the scans. The other logs are: DDS: DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 10.11.2 Run by [removed] at 16:29:29 on 2013-01-31 Microsoft Windows 7 Enterprise 6.1.7601.1.1252.45.1033.18.4022.1322 [GMT 1:00] . AV: Sophos Anti-Virus *Disabled/Updated* {65FBD860-96D8-75EF-C7ED-7BE27E6C498A} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Sophos Anti-Virus *Disabled/Updated* {DE9A3984-B0E2-7A61-FD5D-409005EB0337} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_e085d3cd5b474ba6\STacSV64.exe C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\System32\WUDFHost.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskhost.exe C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_e085d3cd5b474ba6\AESTSr64.exe C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\InstallFilterService.exe C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Program Files (x86)\Oracle\Outlook Connector\ocautoupds.exe C:\Program Files\DellTPad\Apoint.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Windows\System32\rundll32.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files (x86)\BOINC\boincmgr.exe C:\Program Files (x86)\BOINC\boinctray.exe C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe C:\Program Files (x86)\Creative\USB Sound Blaster HD\Volume Panel\VolPanlu.exe C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe C:\Program Files (x86)\BOINC\boinc.exe C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\svchost.exe -k bthsvcs C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\DellTPad\Apntex.exe C:\Windows\System32\WUDFHost.exe C:\Windows\SysWOW64\RunDll32.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\system32\svchost.exe -k SDRSVC C:\Program Files (x86)\Internet Explorer\IELowutil.exe C:\Windows\system32\UI0Detect.exe C:\Users\dtb05\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\dtb05\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\dtb05\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\dtb05\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\dtb05\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\dtb05\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\dtb05\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\dtb05\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\explorer.exe C:\Users\dtb05\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavMain.exe C:\Users\dtb05\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uDefault_Page_URL = hxxp://nfit.au.dk mWinlogon: Userinit = userinit.exe BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background uRun: [Google Update] "C:\Users\dtb05\AppData\Local\Google\Update\GoogleUpdate.exe" /c mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin mRun: [AutoProfileRepair] "C:\Program Files (x86)\Oracle\Outlook Connector\profilerepair.exe" -msi mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe" mRun: [boincmgr] "C:\Program Files (x86)\BOINC\boincmgr.exe" /a /s mRun: [boinctray] "C:\Program Files (x86)\BOINC\boinctray.exe" mRun: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe mRun: [VolPanel] "C:\Program Files (x86)\Creative\USB Sound Blaster HD\Volume Panel\VolPanlu.exe" /r mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices mRun: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-Explorer: NoActiveDesktopChanges = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 IE: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm LSP: C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: NameServer = 10.19.28.77 10.19.28.78 TCP: Interfaces\{3FC5559F-922B-4327-A74F-A2089D5D4650} : DHCPNameServer = 10.0.0.1 [removed] [removed] TCP: Interfaces\{3FC5559F-922B-4327-A74F-A2089D5D4650}\1407162747D214277616 : DHCPNameServer = 172.30.3.254 TCP: Interfaces\{3FC5559F-922B-4327-A74F-A2089D5D4650}\1455D2741646765647 : DHCPNameServer = [removed] TCP: Interfaces\{3FC5559F-922B-4327-A74F-A2089D5D4650}\34F6C6C696E6370284F64756C602D49616D696 : DHCPNameServer = [removed] [removed] TCP: Interfaces\{3FC5559F-922B-4327-A74F-A2089D5D4650}\47F677E65686F64756C633 : DHCPNameServer = 192.168.1.1 TCP: Interfaces\{3FC5559F-922B-4327-A74F-A2089D5D4650}\64C6F627964616973702255637F6274702F427C616E646F60275966496 : DHCPNameServer = 10.128.128.128 TCP: Interfaces\{3FC5559F-922B-4327-A74F-A2089D5D4650}\8416C6560214C656762756D27657563747 : DHCPNameServer = [removed] [removed] [removed] TCP: Interfaces\{3FC5559F-922B-4327-A74F-A2089D5D4650}\8496C6F6022416970284F6374756C6 : DHCPNameServer = 192.168.0.1 TCP: Interfaces\{BFABC185-30F5-46D5-8E7C-E0FB825039FC} : DHCPNameServer = 10.19.28.77 10.19.28.78 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll AppInit_DLLs= C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL SSODL: WebCheck - SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL x64-Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" x64-Run: [Creative SB Monitoring Utility] RunDll32 sbavmon.dll,SBAVMonitor x64-Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" x64-Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe /installquiet x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - x64-SSODL: WebCheck - x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\dtb05\AppData\Roaming\Mozilla\Firefox\Profiles\yes0y26u.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: network.proxy.type - 0 FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL FF - plugin: C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll FF - plugin: C:\Program Files (x86)\Veetle\Player\npvlc.dll FF - plugin: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll FF - plugin: C:\Users\dtb05\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: C:\Users\dtb05\AppData\Roaming\TorrentStream\player\npts.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll . ============= SERVICES / DRIVERS =============== . R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-9-2 55856] R0 stdflt;Disk Filter Driver for Accelerometer;C:\Windows\System32\drivers\stdfltn.sys [2010-9-2 21040] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2012-3-16 283200] R1 SAVOnAccess;SAVOnAccess;C:\Windows\System32\drivers\savonaccess.sys [2012-11-29 154952] R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_e085d3cd5b474ba6\AESTSr64.exe [2010-9-2 89600] R2 Credential Vault Host Control Service;Credential Vault Host Control Service;C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [2009-12-17 1039776] R2 Credential Vault Host Storage;Credential Vault Host Storage;C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [2009-12-17 31136] R2 InstallFilterService;FF Install Filter Service;C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\InstallFilterService.exe [2010-9-2 60928] R2 ocautoupds;Oracle Connector Automatic Updates Service;C:\Program Files (x86)\Oracle\Outlook Connector\ocautoupds.exe [2009-1-30 69632] R2 risdpcie;risdpcie;C:\Windows\System32\drivers\risdpe64.sys [2010-9-2 81920] R2 SAVAdminService;Sophos Anti-Virus status reporter;C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [2012-12-6 216640] R2 SAVService;Sophos Anti-Virus;C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [2012-11-29 159296] R2 Sophos AutoUpdate Service;Sophos AutoUpdate Service;C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [2012-12-6 236608] R2 Sophos Web Control Service;Sophos Web Control Service;C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [2012-11-15 357400] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-4-27 382272] R2 swi_service;Sophos Web Intelligence Service;C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2012-12-6 2878016] R3 Acceler;Accelerometer Service;C:\Windows\System32\drivers\Accelern.sys [2010-9-2 26160] R3 btwampfl;Bluetooth AMP USB Filter;C:\Windows\System32\drivers\btwampfl.sys [2010-5-31 321576] R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2010-9-2 39464] R3 cvusbdrv;Dell ControlVault;C:\Windows\System32\drivers\cvusbdrv.sys [2009-11-3 38440] R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;C:\Windows\System32\drivers\e1k62x64.sys [2010-9-2 294064] R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2010-9-2 158976] R3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETw5s64.sys [2010-9-2 6952960] R3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-9 160944] S2 swi_update_64;Sophos Web Intelligence Update;C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2012-6-16 2010688] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-1-14 79360] S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe –> c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [?] S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);C:\Windows\System32\drivers\ssudbus.sys [2012-10-26 102368] S3 ksaud;Creative USB Audio Driver;C:\Windows\System32\drivers\ksaud.sys [2011-1-14 1557248] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2011-5-3 20992] S3 sdcfilter;sdcfilter;C:\Windows\System32\drivers\sdcfilter.sys [2012-11-15 36640] S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);C:\Windows\System32\drivers\ssudmdm.sys [2012-10-26 203104] S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 27136] S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-5-3 59392] S3 vmxnet3ndis6;vmxnet3 NDIS 6 Ethernet Adapter Driver;C:\Windows\System32\drivers\vmxnet3n61x64.sys [2010-8-16 70192] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-8-16 1255736] S4 SophosBootDriver;SophosBootDriver;C:\Windows\System32\drivers\SophosBootDriver.sys [2012-11-15 25608] . =============== Created Last 30 ================ . 2013-01-31 14:20:27 95648 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll 2013-01-31 12:58:44 76232 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9773D15E-53BC-4A29-A943-C28A33EEBF22}\offreg.dll 2013-01-31 08:08:45 ——– d—–w- C:\Users\dtb05\AppData\Local\{4192E28F-68EA-4195-A74A-FCF389D8B77A} 2013-01-30 09:29:02 ——– d—–w- C:\Users\dtb05\AppData\Local\{FC44F79A-77B6-4EC5-8EC0-FDD74A60E4E5} 2013-01-29 08:15:16 9161176 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9773D15E-53BC-4A29-A943-C28A33EEBF22}\mpengine.dll 2013-01-29 08:10:09 ——– d—–w- C:\Users\dtb05\AppData\Local\{D7C3B48F-CB51-4905-882A-F7889FB0F075} 2013-01-28 08:57:01 ——– d—–w- C:\Users\dtb05\AppData\Local\{2F5BBB96-1B9C-4313-8E47-0DFEE8A0EA8E} 2013-01-27 09:51:19 ——– d—–w- C:\Users\dtb05\AppData\Local\{B9A78A08-5F47-4F60-BC5A-0ADC41595198} 2013-01-25 09:50:53 ——– d—–w- C:\Users\dtb05\AppData\Local\{4E4EA229-30E5-4775-8073-95EEE4C91D89} 2013-01-24 09:24:13 ——– d—–w- C:\Users\dtb05\AppData\Local\{590C3EDC-DC00-4A61-AD90-DEB81E004638} 2013-01-21 09:00:06 ——– d—–w- C:\Users\dtb05\AppData\Local\{83F474DE-FC9C-4D48-B220-2231A2794F95} 2013-01-19 11:07:55 ——– d—–w- C:\Users\dtb05\AppData\Local\{A49CD6F7-50DB-442F-9609-DB69BDD00F8E} 2013-01-18 08:42:31 ——– d—–w- C:\Users\dtb05\AppData\Local\{C00C6794-6374-4807-BCCF-0B4CC7DFAE1A} 2013-01-17 09:41:07 ——– d—–w- C:\Users\dtb05\AppData\Local\{A269BA34-13D6-4D8F-AEB6-B6EF34F3B615} 2013-01-16 15:42:29 ——– d—–w- C:\Users\dtb05\AppData\Local\{E1B1E60F-7D9B-4123-B286-F180744370D0} 2013-01-15 09:04:34 ——– d—–w- C:\Users\dtb05\AppData\Local\{D7E2AC0F-16DF-4AFD-954D-6009E99AF56D} 2013-01-14 10:13:20 ——– d—–w- C:\Users\dtb05\AppData\Local\{25D38CAB-A8DC-41C7-8B0A-E4FE6D5D690F} 2013-01-11 09:04:59 ——– d—–w- C:\Users\dtb05\AppData\Local\{B979F291-E314-4917-A2EC-0BCF14D98E11} 2013-01-10 08:01:42 ——– d—–w- C:\Users\dtb05\AppData\Local\{9834E6E8-7521-460A-A25E-723DA1F66346} 2013-01-09 18:02:21 424448 —-a-w- C:\Windows\System32\KernelBase.dll 2013-01-09 18:01:55 68608 —-a-w- C:\Windows\System32\taskhost.exe 2013-01-09 18:01:55 3149824 —-a-w- C:\Windows\System32\win32k.sys 2013-01-09 09:57:29 ——– d—–w- C:\Users\dtb05\AppData\Local\{FB5CA33E-A8A9-4A18-8100-955ECA874602} 2013-01-08 09:03:37 ——– d—–w- C:\Users\dtb05\AppData\Local\{E8092831-8709-4EBE-A66F-0CEED8F41E5B} 2013-01-07 09:08:04 ——– d—–w- C:\Users\dtb05\AppData\Local\{AEF64BC5-C359-48C1-A2A3-70E9C781D551} 2013-01-04 09:53:51 ——– d—–w- C:\Users\dtb05\AppData\Local\{D206B44E-5A5C-490E-BD6B-A630FFCE1969} 2013-01-03 10:00:35 ——– d—–w- C:\Users\dtb05\AppData\Local\{2AFA514A-936E-46A1-A126-B02D91663155} 2013-01-02 12:12:40 ——– d—–w- C:\Users\dtb05\AppData\Local\{953E24A5-5C64-41C4-AE65-8F4990167CE5} . ==================== Find3M ==================== . 2013-01-31 14:20:20 859552 —-a-w- C:\Windows\SysWow64\npDeployJava1.dll 2013-01-31 14:20:20 780192 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2013-01-09 11:41:09 74248 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-01-09 11:41:09 697864 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-12-16 17:11:22 46080 —-a-w- C:\Windows\System32\atmlib.dll 2012-12-16 14:45:03 367616 —-a-w- C:\Windows\System32\atmfd.dll 2012-12-16 14:13:28 295424 —-a-w- C:\Windows\SysWow64\atmfd.dll 2012-12-16 14:13:20 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2012-12-07 13:20:16 441856 —-a-w- C:\Windows\System32\Wpc.dll 2012-12-07 13:15:31 2746368 —-a-w- C:\Windows\System32\gameux.dll 2012-12-07 12:26:17 308736 —-a-w- C:\Windows\SysWow64\Wpc.dll 2012-12-07 12:20:43 2576384 —-a-w- C:\Windows\SysWow64\gameux.dll 2012-12-07 11:20:04 30720 —-a-w- C:\Windows\System32\usk.rs 2012-12-07 11:20:03 43520 —-a-w- C:\Windows\System32\csrr.rs 2012-12-07 11:20:03 23552 —-a-w- C:\Windows\System32\oflc.rs 2012-12-07 11:20:01 45568 —-a-w- C:\Windows\System32\oflc-nz.rs 2012-12-07 11:20:01 44544 —-a-w- C:\Windows\System32\pegibbfc.rs 2012-12-07 11:20:01 20480 —-a-w- C:\Windows\System32\pegi-fi.rs 2012-12-07 11:20:00 20480 —-a-w- C:\Windows\System32\pegi-pt.rs 2012-12-07 11:19:59 20480 —-a-w- C:\Windows\System32\pegi.rs 2012-12-07 11:19:58 46592 —-a-w- C:\Windows\System32\fpb.rs 2012-12-07 11:19:57 40960 —-a-w- C:\Windows\System32\cob-au.rs 2012-12-07 11:19:57 21504 —-a-w- C:\Windows\System32\grb.rs 2012-12-07 11:19:57 15360 —-a-w- C:\Windows\System32\djctq.rs 2012-12-07 11:19:56 55296 —-a-w- C:\Windows\System32\cero.rs 2012-12-07 11:19:55 51712 —-a-w- C:\Windows\System32\esrb.rs 2012-11-30 05:45:35 362496 —-a-w- C:\Windows\System32\wow64win.dll 2012-11-30 05:45:35 243200 —-a-w- C:\Windows\System32\wow64.dll 2012-11-30 05:45:35 13312 —-a-w- C:\Windows\System32\wow64cpu.dll 2012-11-30 05:45:14 215040 —-a-w- C:\Windows\System32\winsrv.dll 2012-11-30 05:43:12 16384 —-a-w- C:\Windows\System32\ntvdm64.dll 2012-11-30 04:54:00 5120 —-a-w- C:\Windows\SysWow64\wow32.dll 2012-11-30 04:53:59 274944 —-a-w- C:\Windows\SysWow64\KernelBase.dll 2012-11-30 03:23:48 338432 —-a-w- C:\Windows\System32\conhost.exe 2012-11-30 02:44:06 25600 —-a-w- C:\Windows\SysWow64\setup16.exe 2012-11-30 02:44:04 7680 —-a-w- C:\Windows\SysWow64\instnm.exe 2012-11-30 02:44:04 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll 2012-11-30 02:44:03 2048 —-a-w- C:\Windows\SysWow64\user.exe 2012-11-30 02:38:59 6144 —ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll 2012-11-30 02:38:59 4608 —ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll 2012-11-30 02:38:59 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll 2012-11-30 02:38:59 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll 2012-11-29 13:36:41 154952 —-a-w- C:\Windows\System32\drivers\savonaccess.sys 2012-11-29 13:36:36 37440 —-a-w- C:\Windows\System32\SophosBootTasks.exe 2012-11-22 05:44:23 800768 —-a-w- C:\Windows\System32\usp10.dll 2012-11-22 04:45:03 626688 —-a-w- C:\Windows\SysWow64\usp10.dll 2012-11-20 05:48:49 307200 —-a-w- C:\Windows\System32\ncrypt.dll 2012-11-20 04:51:09 220160 —-a-w- C:\Windows\SysWow64\ncrypt.dll 2012-11-15 01:00:19 36640 —-a-w- C:\Windows\System32\drivers\sdcfilter.sys 2012-11-15 00:44:47 183024 —-a-w- C:\Windows\System32\sdccoinstaller.dll 2012-11-15 00:36:07 25608 —-a-w- C:\Windows\System32\drivers\SophosBootDriver.sys 2012-11-12 12:28:37 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2012-11-12 11:52:18 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2012-11-09 05:45:32 750592 —-a-w- C:\Windows\System32\win32spl.dll 2012-11-09 05:45:09 2048 —-a-w- C:\Windows\System32\tzres.dll 2012-11-09 04:43:04 492032 —-a-w- C:\Windows\SysWow64\win32spl.dll 2012-11-09 04:42:49 2048 —-a-w- C:\Windows\SysWow64\tzres.dll . ============= FINISH: 16:30:03.99 =============== Attach: . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows 7 Enterprise Boot Device: \Device\HarddiskVolume2 Install Date: 02-09-2010 07:35:41 System Uptime: 31-01-2013 09:06:46 (7 hours ago) . Motherboard: Dell Inc. | | 0K42JR Processor: Intel® Core™ i5 CPU M 520 @ 2.40GHz | CPU 1 | 2400/533mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 233 GiB total, 27.951 GiB free. D: is CDROM () E: is Removable F: is CDROM () H: is FIXED (NTFS) - 931 GiB total, 642.779 GiB free. . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP303: 29-01-2013 09:13:36 - Windows Update RP304: 31-01-2013 14:40:30 - Removed Adobe Acrobat 9 Pro - English, Français, Deutsch. RP305: 31-01-2013 15:12:15 - Removed Java 7 Update 11 RP306: 31-01-2013 15:14:24 - Removed JavaFX 2.1.1 RP307: 31-01-2013 15:15:56 - Removed Java™ SE Development Kit 6 Update 21 RP308: 31-01-2013 15:20:08 - Installed Java 7 Update 11 . ==== Installed Programs ====================== . 64 Bit HP BiDi Channel Components Installer 7-Zip 4.65 (x64 edition) AccelerometerP11 Acrobat.com Adobe AIR Adobe Community Help Adobe Creative Suite 5 Design Standard Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader XI - Dansk AdobeCS5_Std µTorrent BioAPI Framework Blobby Volley 2 Version 1.0RC1 BOINC Brain Workshop 4.8.1 CCleaner Counter-Strike Creative Software AutoUpdate Creative System Information D3DX10 DAEMON Tools Pro Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition Dell ControlVault Host Components Installer 64Bit Dell Security Device Driver Pack Dell Touchpad Diablo III Dota 2 Dropbox EndNote X4 EVEREST Home Edition v2.20 FileZilla Client 3.3.4 FreeMind Garmin Communicator Plugin Garmin Communicator Plugin x64 Garmin USB Drivers Garmin WebUpdater Google Chrome Gwyddion HFSExplorer 0.21 Hotfix for Microsoft .NET Framework 4 Client Profile (KB2461678) ImageJ 1.43u Java 7 Update 11 Java Auto Updater JDownloader 0.9 JPK Data Processing Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft IntelliPoint 8.2 Microsoft Motocross Madness 2 Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office 2010 Language Pack Service Pack 1 (SP1) Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (Danish) 2007 Microsoft Office Access MUI (Danish) 2010 Microsoft Office Access MUI (English) 2010 Microsoft Office Access Setup Metadata MUI (English) 2010 Microsoft Office Excel MUI (Danish) 2007 Microsoft Office Excel MUI (Danish) 2010 Microsoft Office Excel MUI (English) 2010 Microsoft Office Groove MUI (Danish) 2007 Microsoft Office Groove MUI (Danish) 2010 Microsoft Office Groove MUI (English) 2010 Microsoft Office IME (Chinese (Simplified)) 2007 Microsoft Office IME (Chinese (Traditional)) 2007 Microsoft Office IME (Japanese) 2007 Microsoft Office IME (Korean) 2007 Microsoft Office InfoPath MUI (Danish) 2007 Microsoft Office InfoPath MUI (Danish) 2010 Microsoft Office InfoPath MUI (English) 2010 Microsoft Office Language Pack 2007 - Danish/dansk Microsoft Office Language Pack 2010 - Danish/dansk Microsoft Office O MUI (Danish) 2007 Microsoft Office O MUI (Danish) 2010 Microsoft Office Office 64-bit Components 2010 Microsoft Office OneNote MUI (Danish) 2007 Microsoft Office OneNote MUI (Danish) 2010 Microsoft Office OneNote MUI (English) 2010 Microsoft Office Outlook MUI (Danish) 2007 Microsoft Office Outlook MUI (Danish) 2010 Microsoft Office Outlook MUI (English) 2010 Microsoft Office PowerPoint MUI (Danish) 2007 Microsoft Office PowerPoint MUI (Danish) 2010 Microsoft Office PowerPoint MUI (English) 2010 Microsoft Office Professional Plus 2010 Microsoft Office Proof (Arabic) 2007 Microsoft Office Proof (Basque) 2007 Microsoft Office Proof (Bulgarian) 2007 Microsoft Office Proof (Catalan) 2007 Microsoft Office Proof (Chinese (Simplified)) 2007 Microsoft Office Proof (Chinese (Traditional)) 2007 Microsoft Office Proof (Croatian) 2007 Microsoft Office Proof (Czech) 2007 Microsoft Office Proof (Danish) 2007 Microsoft Office Proof (Danish) 2010 Microsoft Office Proof (Dutch) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (English) 2010 Microsoft Office Proof (Estonian) 2007 Microsoft Office Proof (Finnish) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (French) 2010 Microsoft Office Proof (Galician) 2007 Microsoft Office Proof (German) 2007 Microsoft Office Proof (German) 2010 Microsoft Office Proof (Greek) 2007 Microsoft Office Proof (Gujarati) 2007 Microsoft Office Proof (Hebrew) 2007 Microsoft Office Proof (Hindi) 2007 Microsoft Office Proof (Hungarian) 2007 Microsoft Office Proof (Italian) 2007 Microsoft Office Proof (Japanese) 2007 Microsoft Office Proof (Kannada) 2007 Microsoft Office Proof (Korean) 2007 Microsoft Office Proof (Latvian) 2007 Microsoft Office Proof (Lithuanian) 2007 Microsoft Office Proof (Marathi) 2007 Microsoft Office Proof (Norwegian (Bokmål)) 2007 Microsoft Office Proof (Norwegian (Nynorsk)) 2007 Microsoft Office Proof (Polish) 2007 Microsoft Office Proof (Portuguese (Brazil)) 2007 Microsoft Office Proof (Portuguese (Portugal)) 2007 Microsoft Office Proof (Punjabi) 2007 Microsoft Office Proof (Romanian) 2007 Microsoft Office Proof (Russian) 2007 Microsoft Office Proof (Serbian (Latin)) 2007 Microsoft Office Proof (Slovak) 2007 Microsoft Office Proof (Slovenian) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proof (Spanish) 2010 Microsoft Office Proof (Swedish) 2007 Microsoft Office Proof (Swedish) 2010 Microsoft Office Proof (Tamil) 2007 Microsoft Office Proof (Telugu) 2007 Microsoft Office Proof (Thai) 2007 Microsoft Office Proof (Turkish) 2007 Microsoft Office Proof (Ukrainian) 2007 Microsoft Office Proof (Urdu) 2007 Microsoft Office Proofing (Danish) 2007 Microsoft Office Proofing (Danish) 2010 Microsoft Office Proofing (English) 2010 Microsoft Office Proofing Kit 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Proofing Tools Kit 2007 Microsoft Office ProofMUI (English) 2007 Microsoft Office Publisher MUI (Danish) 2007 Microsoft Office Publisher MUI (Danish) 2010 Microsoft Office Publisher MUI (English) 2010 Microsoft Office Shared 64-bit MUI (Danish) 2007 Microsoft Office Shared 64-bit MUI (Danish) 2010 Microsoft Office Shared 64-bit MUI (English) 2010 Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 Microsoft Office Shared MUI (Danish) 2007 Microsoft Office Shared MUI (Danish) 2010 Microsoft Office Shared MUI (English) 2010 Microsoft Office Shared Setup Metadata MUI (English) 2010 Microsoft Office SharePoint Designer 2007 Service Pack 3 (SP3) Microsoft Office SharePoint Designer MUI (Danish) 2007 Microsoft Office SharePoint Designer MUI (Danish) 2010 Microsoft Office Word MUI (Danish) 2007 Microsoft Office Word MUI (Danish) 2010 Microsoft Office Word MUI (English) 2010 Microsoft Office X MUI (Danish) 2007 Microsoft Office X MUI (Danish) 2010 Microsoft SharePoint Designer 2010 Service Pack 1 (SP1) Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 mIRC Mozilla Firefox 14.0.1 (x86 en-US) Mozilla Maintenance Service Mozilla Thunderbird (3.1.2) MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Nexus Mod Manager NVIDIA 3D Vision Driver 296.70 NVIDIA Control Panel 296.70 NVIDIA Graphics Driver 296.70 NVIDIA HD Audio Driver [removed] NVIDIA Install Application NVIDIA nView 136.27 NVIDIA nView Desktop Manager NVIDIA PhysX NVIDIA PhysX System Software 9.10.0514 NVIDIA Stereoscopic 3D Driver Opdatering til Microsoft Office Excel 2007 Help (KB963678) Opdatering til Microsoft Office Powerpoint 2007 Help (KB963669) Opdatering til Microsoft Office Word 2007 Help (KB963665) Oracle Calendar Oracle Connector for Outlook Origin8 OriginPro 8 Pack 500 track PDF Settings CS5 PuTTY version 0.60 PVSonyDll ResearchSoft Direct Export Helper RICOH Media Driver ver.2.11.01.02 Samsung Kies SAMSUNG USB Driver for Mobile Phones Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition Security Update for Microsoft InfoPath 2010 (KB2687436) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553091) Security Update for Microsoft Office 2010 (KB2553096) Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition Security Update for Microsoft Visio 2010 (KB2687508) 32-Bit Edition Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition Skype Click to Call Skype™ 6.0 SopCast 3.5.0 Sophos Anti-Virus Sophos AutoUpdate Steam System Requirements Lab Team Fortress 2 The Elder Scrolls V: Skyrim Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Office 2007 suites (KB2597120) 32-Bit Edition Update for Microsoft Office 2010 (KB2494150) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553092) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2687277) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition UPEK TouchChip Fingerprint Reader USB Sound Blaster HD Veetle TV 0.9.18 VLC media player 2.0.2 WIDCOMM Bluetooth Software Winamp Winamp Detector Plug-in Windows Driver Package - Dell Inc. PBADRV System (09/11/2009 1.0.1.6) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) Windows Live Communications Platform Windows Live Essentials Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Language Selector Windows Live Messenger Windows Live Photo Common Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Media Player Firefox Plugin . ==== Event Viewer Messages From Past Week ======== . 28-01-2013 21:01:26, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Sophos AutoUpdate Service service to connect. 28-01-2013 21:01:26, Error: Service Control Manager [7000] - The Sophos AutoUpdate Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 26-01-2013 11:26:18, Error: Service Control Manager [7022] - The Windows Update service hung on starting. . ==== End Of File =========================== AdwCleaner: # AdwCleaner v2.109 - Logfile created 01/31/2013 at 16:53:19 # Updated 26/01/2013 by Xplode # Operating system : Windows 7 Enterprise Service Pack 1 (64 bits) # User : dtb05 - NF-A00030 # Boot Mode : Normal # Running from : C:\Users\dtb05\Desktop\AdwCleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Users\Dines\AppData\Local\Temp\AskSearch ***** [Registry] ***** Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCU\Software\Softonic Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.7601.17514 [OK] Registry is clean. -\\ Mozilla Firefox v14.0.1 (en-US) File : C:\Users\dtb05\AppData\Roaming\Mozilla\Firefox\Profiles\yes0y26u.default\prefs.js [OK] File is clean. File : C:\Users\Dines\AppData\Roaming\Mozilla\Firefox\Profiles\ysse7yzc.default\prefs.js [OK] File is clean. -\\ Google Chrome v24.0.1312.56 File : C:\Users\dtb05\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. File : C:\Users\Dines\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [2030 octets] - [31/01/2013 16:53:19] ########## EOF - C:\AdwCleaner[S1].txt - [2090 octets] ##########
Try and run aswMBR in Safe Mode….if that does not work, do the following:

[external image: Posted Image] Please download TDSSKiller
  • Double click TDSSKiller.exe
  • Press Start Scan but do nothing else as we are just looking for what is there.
  • If Malicious objects are found, select Skip by changing the Cure dropdown in the upper right.
  • Attach the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-
Ran it in SafeMode, the same result and it seems its when it scans the same file, something with "microsoft visual".. Here is the log from TDSS: 17:51:17.0374 0472 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35 17:51:17.0527 0472 ============================================================ 17:51:17.0527 0472 Current date / time: 2013/01/31 17:51:17.0527 17:51:17.0528 0472 SystemInfo: 17:51:17.0528 0472 17:51:17.0528 0472 OS Version: 6.1.7601 ServicePack: 1.0 17:51:17.0528 0472 Product type: Workstation 17:51:17.0528 0472 ComputerName: NF-A00030 17:51:17.0528 0472 UserName: dtb05 17:51:17.0528 0472 Windows directory: C:\Windows 17:51:17.0528 0472 System windows directory: C:\Windows 17:51:17.0528 0472 Running under WOW64 17:51:17.0528 0472 Processor architecture: Intel x64 17:51:17.0528 0472 Number of processors: 4 17:51:17.0528 0472 Page size: 0x1000 17:51:17.0528 0472 Boot type: Normal boot 17:51:17.0528 0472 ============================================================ 17:51:20.0090 0472 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 17:51:20.0096 0472 Drive \Device\Harddisk1\DR1 - Size: 0x78EB00000 (30.23 Gb), SectorSize: 0x200, Cylinders: 0xF6A, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 17:51:20.0098 0472 ============================================================ 17:51:20.0098 0472 \Device\Harddisk0\DR0: 17:51:20.0098 0472 MBR partitions: 17:51:20.0098 0472 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x1D129000 17:51:20.0098 0472 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1D129800, BlocksNum 0x96000 17:51:20.0098 0472 \Device\Harddisk1\DR1: 17:51:20.0099 0472 MBR partitions: 17:51:20.0099 0472 \Device\Harddisk1\DR1\Partition1: MBR, Type 0xC, StartLBA 0x2000, BlocksNum 0x3C75800 17:51:20.0099 0472 ============================================================ 17:51:20.0123 0472 C: <-> \Device\Harddisk0\DR0\Partition1 17:51:20.0123 0472 ============================================================ 17:51:20.0123 0472 Initialize success 17:51:20.0123 0472 ============================================================ 17:51:23.0391 5500 ============================================================ 17:51:23.0391 5500 Scan started 17:51:23.0391 5500 Mode: Manual; 17:51:23.0391 5500 ============================================================ 17:51:25.0188 5500 ================ Scan system memory ======================== 17:51:25.0188 5500 System memory - ok 17:51:25.0188 5500 ================ Scan services ============================= 17:51:25.0483 5500 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 17:51:25.0487 5500 1394ohci - ok 17:51:25.0523 5500 [ 627371B2D48F64CECC4D019114FB140D ] Acceler C:\Windows\system32\DRIVERS\Accelern.sys 17:51:25.0523 5500 Acceler - ok 17:51:25.0609 5500 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 17:51:25.0613 5500 ACPI - ok 17:51:25.0687 5500 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 17:51:25.0690 5500 AcpiPmi - ok 17:51:25.0892 5500 [ 424877CB9D5517F980FF7BACA2EB379D ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 17:51:25.0897 5500 AdobeFlashPlayerUpdateSvc - ok 17:51:25.0957 5500 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 17:51:25.0982 5500 adp94xx - ok 17:51:26.0061 5500 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 17:51:26.0092 5500 adpahci - ok 17:51:26.0107 5500 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 17:51:26.0111 5500 adpu320 - ok 17:51:26.0137 5500 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 17:51:26.0139 5500 AeLookupSvc - ok 17:51:26.0227 5500 [ A6FB9DB8F1A86861D955FD6975977AE0 ] AESTFilters C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_e085d3cd5b474ba6\AESTSr64.exe 17:51:26.0228 5500 AESTFilters - ok 17:51:26.0422 5500 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 17:51:26.0438 5500 AFD - ok 17:51:26.0495 5500 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 17:51:26.0500 5500 agp440 - ok 17:51:26.0515 5500 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 17:51:26.0517 5500 ALG - ok 17:51:26.0550 5500 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 17:51:26.0552 5500 aliide - ok 17:51:26.0568 5500 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 17:51:26.0570 5500 amdide - ok 17:51:26.0604 5500 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 17:51:26.0606 5500 AmdK8 - ok 17:51:26.0616 5500 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 17:51:26.0619 5500 AmdPPM - ok 17:51:26.0638 5500 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 17:51:26.0641 5500 amdsata - ok 17:51:26.0657 5500 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 17:51:26.0662 5500 amdsbs - ok 17:51:26.0675 5500 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 17:51:26.0675 5500 amdxata - ok 17:51:26.0716 5500 [ 4B92F0063C633BD4FDBD7D76977F65B3 ] ApfiltrService C:\Windows\system32\DRIVERS\Apfiltr.sys 17:51:26.0718 5500 ApfiltrService - ok 17:51:26.0779 5500 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 17:51:26.0782 5500 AppID - ok 17:51:26.0796 5500 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 17:51:26.0798 5500 AppIDSvc - ok 17:51:26.0856 5500 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll 17:51:26.0858 5500 Appinfo - ok 17:51:26.0895 5500 [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt C:\Windows\System32\appmgmts.dll 17:51:26.0899 5500 AppMgmt - ok 17:51:26.0916 5500 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys 17:51:26.0919 5500 arc - ok 17:51:26.0939 5500 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 17:51:26.0941 5500 arcsas - ok 17:51:26.0967 5500 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 17:51:26.0970 5500 AsyncMac - ok 17:51:26.0992 5500 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 17:51:26.0994 5500 atapi - ok 17:51:27.0104 5500 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 17:51:27.0126 5500 AudioEndpointBuilder - ok 17:51:27.0148 5500 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 17:51:27.0152 5500 AudioSrv - ok 17:51:27.0205 5500 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 17:51:27.0208 5500 AxInstSV - ok 17:51:27.0238 5500 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys 17:51:27.0246 5500 b06bdrv - ok 17:51:27.0277 5500 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 17:51:27.0284 5500 b57nd60a - ok 17:51:27.0324 5500 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 17:51:27.0326 5500 BDESVC - ok 17:51:27.0341 5500 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 17:51:27.0342 5500 Beep - ok 17:51:27.0418 5500 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll 17:51:27.0438 5500 BFE - ok 17:51:27.0520 5500 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll 17:51:27.0544 5500 BITS - ok 17:51:27.0573 5500 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 17:51:27.0575 5500 blbdrive - ok 17:51:27.0624 5500 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 17:51:27.0627 5500 bowser - ok 17:51:27.0651 5500 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 17:51:27.0652 5500 BrFiltLo - ok 17:51:27.0668 5500 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 17:51:27.0670 5500 BrFiltUp - ok 17:51:27.0725 5500 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 17:51:27.0730 5500 Browser - ok 17:51:27.0750 5500 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 17:51:27.0755 5500 Brserid - ok 17:51:27.0769 5500 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 17:51:27.0771 5500 BrSerWdm - ok 17:51:27.0785 5500 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 17:51:27.0788 5500 BrUsbMdm - ok 17:51:27.0797 5500 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 17:51:27.0799 5500 BrUsbSer - ok 17:51:27.0862 5500 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys 17:51:27.0871 5500 BthEnum - ok 17:51:27.0898 5500 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 17:51:27.0900 5500 BTHMODEM - ok 17:51:27.0926 5500 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys 17:51:27.0928 5500 BthPan - ok 17:51:27.0985 5500 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys 17:51:27.0993 5500 BTHPORT - ok 17:51:28.0040 5500 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 17:51:28.0043 5500 bthserv - ok 17:51:28.0096 5500 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys 17:51:28.0101 5500 BTHUSB - ok 17:51:28.0139 5500 [ 2D19C44A9D0E175BC93D23C562A0AA01 ] btwampfl C:\Windows\system32\drivers\btwampfl.sys 17:51:28.0141 5500 btwampfl - ok 17:51:28.0170 5500 [ AD4B38BF35896778236B40CF453F58AA ] btwaudio C:\Windows\system32\drivers\btwaudio.sys 17:51:28.0171 5500 btwaudio - ok 17:51:28.0192 5500 [ C2A11549E72841EF9FC5AF14C7F29233 ] btwavdt C:\Windows\system32\DRIVERS\btwavdt.sys 17:51:28.0193 5500 btwavdt - ok 17:51:28.0268 5500 [ 3D13849A1F9E7C61096294B955EFCDF2 ] btwdins C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe 17:51:28.0285 5500 btwdins - ok 17:51:28.0298 5500 [ 06E96CF5C046F7CAB4AA131DF6E2B9BC ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys 17:51:28.0299 5500 btwl2cap - ok 17:51:28.0324 5500 [ D8270F1D59DD10743C8E62D806AF85E2 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys 17:51:28.0325 5500 btwrchid - ok 17:51:28.0361 5500 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 17:51:28.0368 5500 cdfs - ok 17:51:28.0446 5500 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 17:51:28.0449 5500 cdrom - ok 17:51:28.0516 5500 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 17:51:28.0522 5500 CertPropSvc - ok 17:51:28.0548 5500 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys 17:51:28.0551 5500 circlass - ok 17:51:28.0579 5500 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 17:51:28.0585 5500 CLFS - ok 17:51:28.0662 5500 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 17:51:28.0670 5500 clr_optimization_v2.0.50727_32 - ok 17:51:28.0705 5500 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 17:51:28.0713 5500 clr_optimization_v2.0.50727_64 - ok 17:51:28.0772 5500 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 17:51:28.0837 5500 clr_optimization_v4.0.30319_32 - ok 17:51:28.0877 5500 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 17:51:28.0880 5500 clr_optimization_v4.0.30319_64 - ok 17:51:28.0917 5500 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 17:51:28.0919 5500 CmBatt - ok 17:51:28.0938 5500 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 17:51:28.0940 5500 cmdide - ok 17:51:28.0998 5500 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 17:51:29.0003 5500 CNG - ok 17:51:29.0028 5500 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 17:51:29.0028 5500 Compbatt - ok 17:51:29.0085 5500 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 17:51:29.0091 5500 CompositeBus - ok 17:51:29.0107 5500 COMSysApp - ok 17:51:29.0121 5500 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 17:51:29.0123 5500 crcdisk - ok 17:51:29.0255 5500 [ C0EAD9F8AB83D41FF07303C75589C2B8 ] Creative Audio Engine Licensing Service C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe 17:51:29.0258 5500 Creative Audio Engine Licensing Service - ok 17:51:29.0367 5500 [ 55A9081A7A6D0977A0B470AC88F37E6F ] Credential Vault Host Control Service C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe 17:51:29.0387 5500 Credential Vault Host Control Service - ok 17:51:29.0401 5500 [ 53371039D4027E1BB4DDCC83007D3A04 ] Credential Vault Host Storage C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe 17:51:29.0402 5500 Credential Vault Host Storage - ok 17:51:29.0470 5500 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll 17:51:29.0474 5500 CryptSvc - ok 17:51:29.0526 5500 [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC C:\Windows\system32\drivers\csc.sys 17:51:29.0534 5500 CSC - ok 17:51:29.0554 5500 [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService C:\Windows\System32\cscsvc.dll 17:51:29.0572 5500 CscService - ok 17:51:29.0712 5500 [ 07BA6D17E66879018B30B6C3F976EBED ] CTAudSvcService C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe 17:51:29.0740 5500 CTAudSvcService - ok 17:51:29.0815 5500 [ A84CAAE89B487931200B969D94018AFA ] cvusbdrv C:\Windows\system32\Drivers\cvusbdrv.sys 17:51:29.0815 5500 cvusbdrv - ok 17:51:30.0098 5500 DAUpdaterSvc - ok 17:51:30.0192 5500 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 17:51:30.0268 5500 DcomLaunch - ok 17:51:30.0297 5500 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 17:51:30.0303 5500 defragsvc - ok 17:51:30.0351 5500 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 17:51:30.0353 5500 DfsC - ok 17:51:30.0414 5500 [ B9430166FEB246F6070A62B3554932C9 ] dg_ssudbus C:\Windows\system32\DRIVERS\ssudbus.sys 17:51:30.0438 5500 dg_ssudbus - ok 17:51:30.0533 5500 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 17:51:30.0549 5500 Dhcp - ok 17:51:30.0574 5500 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 17:51:30.0580 5500 discache - ok 17:51:30.0623 5500 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys 17:51:30.0628 5500 Disk - ok 17:51:30.0688 5500 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 17:51:30.0712 5500 Dnscache - ok 17:51:30.0765 5500 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 17:51:30.0769 5500 dot3svc - ok 17:51:30.0817 5500 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 17:51:30.0821 5500 DPS - ok 17:51:30.0843 5500 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 17:51:30.0845 5500 drmkaud - ok 17:51:30.0945 5500 [ 46571ED73AE84469DCA53081D33CF3C8 ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys 17:51:30.0947 5500 dtsoftbus01 - ok 17:51:31.0029 5500 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 17:51:31.0034 5500 DXGKrnl - ok 17:51:31.0105 5500 [ F369E83F6CDAB987CA2DD764278659A6 ] e1kexpress C:\Windows\system32\DRIVERS\e1k62x64.sys 17:51:31.0107 5500 e1kexpress - ok 17:51:31.0147 5500 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 17:51:31.0149 5500 EapHost - ok 17:51:31.0454 5500 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys 17:51:31.0522 5500 ebdrv - ok 17:51:31.0612 5500 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 17:51:31.0613 5500 EFS - ok 17:51:31.0846 5500 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 17:51:31.0862 5500 ehRecvr - ok 17:51:31.0904 5500 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 17:51:31.0906 5500 ehSched - ok 17:51:31.0955 5500 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 17:51:31.0963 5500 elxstor - ok 17:51:32.0005 5500 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 17:51:32.0007 5500 ErrDev - ok 17:51:32.0051 5500 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 17:51:32.0057 5500 EventSystem - ok 17:51:32.0075 5500 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 17:51:32.0079 5500 exfat - ok 17:51:32.0100 5500 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 17:51:32.0104 5500 fastfat - ok 17:51:32.0231 5500 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 17:51:32.0297 5500 Fax - ok 17:51:32.0319 5500 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys 17:51:32.0323 5500 fdc - ok 17:51:32.0336 5500 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 17:51:32.0344 5500 fdPHost - ok 17:51:32.0354 5500 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 17:51:32.0361 5500 FDResPub - ok 17:51:32.0375 5500 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 17:51:32.0377 5500 FileInfo - ok 17:51:32.0394 5500 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 17:51:32.0396 5500 Filetrace - ok 17:51:32.0412 5500 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 17:51:32.0414 5500 flpydisk - ok 17:51:32.0515 5500 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 17:51:32.0556 5500 FltMgr - ok 17:51:32.0694 5500 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll 17:51:32.0719 5500 FontCache - ok 17:51:32.0810 5500 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 17:51:32.0815 5500 FontCache3.0.0.0 - ok 17:51:32.0864 5500 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 17:51:32.0867 5500 FsDepends - ok 17:51:32.0937 5500 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 17:51:32.0938 5500 Fs_Rec - ok 17:51:33.0008 5500 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 17:51:33.0012 5500 fvevol - ok 17:51:33.0042 5500 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 17:51:33.0046 5500 gagp30kx - ok 17:51:33.0081 5500 GGSAFERDriver - ok 17:51:33.0182 5500 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 17:51:33.0230 5500 gpsvc - ok 17:51:33.0244 5500 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 17:51:33.0246 5500 hcw85cir - ok 17:51:33.0302 5500 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 17:51:33.0305 5500 HDAudBus - ok 17:51:33.0321 5500 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 17:51:33.0323 5500 HidBatt - ok 17:51:33.0338 5500 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 17:51:33.0341 5500 HidBth - ok 17:51:33.0370 5500 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 17:51:33.0373 5500 HidIr - ok 17:51:33.0394 5500 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll 17:51:33.0396 5500 hidserv - ok 17:51:33.0468 5500 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 17:51:33.0469 5500 HidUsb - ok 17:51:33.0523 5500 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 17:51:33.0530 5500 hkmsvc - ok 17:51:33.0580 5500 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 17:51:33.0584 5500 HomeGroupListener - ok 17:51:33.0632 5500 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 17:51:33.0636 5500 HomeGroupProvider - ok 17:51:33.0688 5500 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 17:51:33.0691 5500 HpSAMD - ok 17:51:33.0815 5500 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 17:51:33.0840 5500 HTTP - ok 17:51:34.0045 5500 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 17:51:34.0046 5500 hwpolicy - ok 17:51:34.0109 5500 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 17:51:34.0111 5500 i8042prt - ok 17:51:34.0134 5500 [ ABBF174CB394F5C437410A788B7E404A ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys 17:51:34.0137 5500 iaStor - ok 17:51:34.0206 5500 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 17:51:34.0212 5500 iaStorV - ok 17:51:34.0305 5500 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 17:51:34.0350 5500 idsvc - ok 17:51:34.0377 5500 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 17:51:34.0379 5500 iirsp - ok 17:51:34.0496 5500 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 17:51:34.0520 5500 IKEEXT - ok 17:51:34.0551 5500 [ DD587A55390ED2295BCE6D36AD567DA9 ] Impcd C:\Windows\system32\DRIVERS\Impcd.sys 17:51:34.0555 5500 Impcd - ok 17:51:34.0601 5500 [ A4A87C2F228DD2AC93DAE94E103792D3 ] InstallFilterService C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\InstallFilterService.exe 17:51:34.0602 5500 InstallFilterService - ok 17:51:34.0656 5500 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 17:51:34.0658 5500 intelide - ok 17:51:34.0686 5500 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 17:51:34.0686 5500 intelppm - ok 17:51:34.0717 5500 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 17:51:34.0720 5500 IPBusEnum - ok 17:51:34.0768 5500 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 17:51:34.0772 5500 IpFilterDriver - ok 17:51:34.0828 5500 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 17:51:34.0860 5500 iphlpsvc - ok 17:51:34.0904 5500 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 17:51:34.0908 5500 IPMIDRV - ok 17:51:34.0939 5500 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 17:51:34.0942 5500 IPNAT - ok 17:51:34.0970 5500 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 17:51:34.0971 5500 IRENUM - ok 17:51:34.0986 5500 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 17:51:34.0988 5500 isapnp - ok 17:51:35.0097 5500 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 17:51:35.0102 5500 iScsiPrt - ok 17:51:35.0141 5500 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 17:51:35.0142 5500 kbdclass - ok 17:51:35.0153 5500 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 17:51:35.0156 5500 kbdhid - ok 17:51:35.0168 5500 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 17:51:35.0169 5500 KeyIso - ok 17:51:35.0295 5500 [ 51F6FBE49CD2E8CB5EA96034134D8EDE ] ksaud C:\Windows\system32\drivers\ksaud.sys 17:51:35.0326 5500 ksaud - ok 17:51:35.0386 5500 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 17:51:35.0389 5500 KSecDD - ok 17:51:35.0457 5500 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 17:51:35.0460 5500 KSecPkg - ok 17:51:35.0505 5500 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 17:51:35.0508 5500 ksthunk - ok 17:51:35.0550 5500 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 17:51:35.0598 5500 KtmRm - ok 17:51:35.0740 5500 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll 17:51:35.0744 5500 LanmanServer - ok 17:51:35.0823 5500 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 17:51:35.0828 5500 LanmanWorkstation - ok 17:51:35.0934 5500 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 17:51:35.0939 5500 lltdio - ok 17:51:36.0018 5500 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 17:51:36.0023 5500 lltdsvc - ok 17:51:36.0034 5500 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 17:51:36.0041 5500 lmhosts - ok 17:51:36.0070 5500 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 17:51:36.0073 5500 LSI_FC - ok 17:51:36.0129 5500 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 17:51:36.0133 5500 LSI_SAS - ok 17:51:36.0160 5500 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 17:51:36.0164 5500 LSI_SAS2 - ok 17:51:36.0201 5500 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 17:51:36.0209 5500 LSI_SCSI - ok 17:51:36.0245 5500 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 17:51:36.0249 5500 luafv - ok 17:51:36.0312 5500 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 17:51:36.0316 5500 Mcx2Svc - ok 17:51:36.0441 5500 [ 7CF1B716372B89568AE4C0FE769F5869 ] MDM C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe 17:51:36.0443 5500 MDM - ok 17:51:36.0468 5500 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 17:51:36.0474 5500 megasas - ok 17:51:36.0512 5500 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 17:51:36.0516 5500 MegaSR - ok 17:51:36.0757 5500 Microsoft SharePoint Workspace Audit Service - ok 17:51:36.0826 5500 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 17:51:36.0828 5500 MMCSS - ok 17:51:36.0850 5500 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 17:51:36.0852 5500 Modem - ok 17:51:36.0906 5500 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 17:51:36.0907 5500 monitor - ok 17:51:36.0967 5500 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 17:51:36.0968 5500 mouclass - ok 17:51:36.0984 5500 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 17:51:36.0984 5500 mouhid - ok 17:51:37.0056 5500 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 17:51:37.0062 5500 mountmgr - ok 17:51:37.0304 5500 [ 46297FA8E30A6007F14118FC2B942FBC ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 17:51:37.0319 5500 MozillaMaintenance - ok 17:51:37.0377 5500 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 17:51:37.0382 5500 mpio - ok 17:51:37.0454 5500 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 17:51:37.0457 5500 mpsdrv - ok 17:51:37.0526 5500 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll 17:51:37.0546 5500 MpsSvc - ok 17:51:37.0597 5500 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 17:51:37.0600 5500 MRxDAV - ok 17:51:37.0664 5500 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 17:51:37.0667 5500 mrxsmb - ok 17:51:37.0745 5500 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 17:51:37.0754 5500 mrxsmb10 - ok 17:51:37.0775 5500 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 17:51:37.0778 5500 mrxsmb20 - ok 17:51:37.0823 5500 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 17:51:37.0826 5500 msahci - ok 17:51:37.0844 5500 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 17:51:37.0848 5500 msdsm - ok 17:51:37.0860 5500 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 17:51:37.0864 5500 MSDTC - ok 17:51:37.0889 5500 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 17:51:37.0892 5500 Msfs - ok 17:51:37.0910 5500 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 17:51:37.0912 5500 mshidkmdf - ok 17:51:37.0922 5500 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 17:51:37.0923 5500 msisadrv - ok 17:51:37.0952 5500 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 17:51:37.0957 5500 MSiSCSI - ok 17:51:37.0960 5500 msiserver - ok 17:51:37.0994 5500 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 17:51:37.0996 5500 MSKSSRV - ok 17:51:38.0003 5500 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 17:51:38.0005 5500 MSPCLOCK - ok 17:51:38.0018 5500 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 17:51:38.0020 5500 MSPQM - ok 17:51:38.0104 5500 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 17:51:38.0119 5500 MsRPC - ok 17:51:38.0163 5500 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 17:51:38.0164 5500 mssmbios - ok 17:51:38.0195 5500 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 17:51:38.0196 5500 MSTEE - ok 17:51:38.0209 5500 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 17:51:38.0210 5500 MTConfig - ok 17:51:38.0225 5500 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 17:51:38.0226 5500 Mup - ok 17:51:38.0344 5500 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 17:51:38.0360 5500 napagent - ok 17:51:38.0416 5500 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 17:51:38.0421 5500 NativeWifiP - ok 17:51:38.0484 5500 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys 17:51:38.0507 5500 NDIS - ok 17:51:38.0524 5500 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 17:51:38.0526 5500 NdisCap - ok 17:51:38.0549 5500 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 17:51:38.0551 5500 NdisTapi - ok 17:51:38.0603 5500 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 17:51:38.0604 5500 Ndisuio - ok 17:51:38.0669 5500 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 17:51:38.0681 5500 NdisWan - ok 17:51:38.0729 5500 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 17:51:38.0731 5500 NDProxy - ok 17:51:38.0804 5500 [ 59267D2F0328599AA3B5408C2E06126F ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll 17:51:38.0818 5500 Net Driver HPZ12 - ok 17:51:38.0832 5500 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 17:51:38.0834 5500 NetBIOS - ok 17:51:38.0881 5500 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 17:51:38.0885 5500 NetBT - ok 17:51:38.0897 5500 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 17:51:38.0898 5500 Netlogon - ok 17:51:38.0938 5500 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 17:51:38.0944 5500 Netman - ok 17:51:38.0964 5500 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 17:51:38.0971 5500 netprofm - ok 17:51:38.0986 5500 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 17:51:38.0989 5500 NetTcpPortSharing - ok 17:51:39.0143 5500 [ 4D85A450EDEF10C38882182753A49AAE ] NETw5s64 C:\Windows\system32\DRIVERS\NETw5s64.sys 17:51:39.0254 5500 NETw5s64 - ok 17:51:39.0284 5500 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 17:51:39.0286 5500 nfrd960 - ok 17:51:39.0318 5500 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll 17:51:39.0323 5500 NlaSvc - ok 17:51:39.0341 5500 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 17:51:39.0343 5500 Npfs - ok 17:51:39.0366 5500 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 17:51:39.0368 5500 nsi - ok 17:51:39.0382 5500 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 17:51:39.0384 5500 nsiproxy - ok 17:51:39.0461 5500 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 17:51:39.0489 5500 Ntfs - ok 17:51:39.0504 5500 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 17:51:39.0506 5500 Null - ok 17:51:39.0565 5500 [ 8D4AAC74B571FC356560E5B308955E93 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys 17:51:39.0566 5500 NVHDA - ok 17:51:40.0163 5500 [ 0DEC98637ED9CE8FA02E45AB7D813826 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 17:51:40.0229 5500 nvlddmkm - ok 17:51:40.0282 5500 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 17:51:40.0286 5500 nvraid - ok 17:51:40.0341 5500 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 17:51:40.0345 5500 nvstor - ok 17:51:40.0527 5500 [ 299D89CDC66C7B294F2E756673138C8E ] nvsvc C:\Windows\system32\nvvsvc.exe 17:51:40.0531 5500 nvsvc - ok 17:51:40.0564 5500 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 17:51:40.0570 5500 nv_agp - ok 17:51:40.0671 5500 [ 3E7E38A442A48438290D533CEC719982 ] ocautoupds C:\Program Files (x86)\Oracle\Outlook Connector\ocautoupds.exe 17:51:40.0672 5500 ocautoupds - ok 17:51:40.0726 5500 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 17:51:40.0729 5500 ohci1394 - ok 17:51:40.0764 5500 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 17:51:40.0769 5500 ose - ok 17:51:41.0282 5500 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 17:51:41.0385 5500 osppsvc - ok 17:51:41.0509 5500 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 17:51:41.0550 5500 p2pimsvc - ok 17:51:41.0583 5500 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 17:51:41.0588 5500 p2psvc - ok 17:51:41.0631 5500 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys 17:51:41.0634 5500 Parport - ok 17:51:41.0686 5500 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 17:51:41.0688 5500 partmgr - ok 17:51:41.0724 5500 [ 363B3F857ABEE85767E01E3044C539CD ] PBADRV C:\Windows\system32\DRIVERS\PBADRV.sys 17:51:41.0724 5500 PBADRV - ok 17:51:41.0739 5500 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 17:51:41.0743 5500 PcaSvc - ok 17:51:41.0789 5500 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 17:51:41.0792 5500 pci - ok 17:51:41.0809 5500 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 17:51:41.0812 5500 pciide - ok 17:51:41.0834 5500 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 17:51:41.0839 5500 pcmcia - ok 17:51:41.0854 5500 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 17:51:41.0855 5500 pcw - ok 17:51:41.0878 5500 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 17:51:41.0887 5500 PEAUTH - ok 17:51:41.0926 5500 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll 17:51:42.0008 5500 PeerDistSvc - ok 17:51:42.0102 5500 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 17:51:42.0105 5500 PerfHost - ok 17:51:42.0173 5500 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 17:51:42.0200 5500 pla - ok 17:51:42.0252 5500 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 17:51:42.0259 5500 PlugPlay - ok 17:51:42.0283 5500 [ 5261A2FD55183AC6993145AB6662CDDF ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll 17:51:42.0286 5500 Pml Driver HPZ12 - ok 17:51:42.0296 5500 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 17:51:42.0299 5500 PNRPAutoReg - ok 17:51:42.0318 5500 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 17:51:42.0320 5500 PNRPsvc - ok 17:51:42.0389 5500 [ 4F0878FD62D5F7444C5F1C4C66D9D293 ] Point64 C:\Windows\system32\DRIVERS\point64.sys 17:51:42.0390 5500 Point64 - ok 17:51:42.0410 5500 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 17:51:42.0417 5500 PolicyAgent - ok 17:51:42.0437 5500 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 17:51:42.0442 5500 Power - ok 17:51:42.0501 5500 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 17:51:42.0503 5500 PptpMiniport - ok 17:51:42.0529 5500 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys 17:51:42.0531 5500 Processor - ok 17:51:42.0600 5500 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 17:51:42.0605 5500 ProfSvc - ok 17:51:42.0620 5500 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 17:51:42.0620 5500 ProtectedStorage - ok 17:51:42.0679 5500 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 17:51:42.0683 5500 Psched - ok 17:51:42.0702 5500 [ 87B04878A6D59D6C79251DC960C674C1 ] PxHlpa64 C:\Windows\system32\Drivers\PxHlpa64.sys 17:51:42.0703 5500 PxHlpa64 - ok 17:51:42.0760 5500 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 17:51:42.0788 5500 ql2300 - ok 17:51:42.0818 5500 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 17:51:42.0821 5500 ql40xx - ok 17:51:42.0859 5500 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 17:51:42.0864 5500 QWAVE - ok 17:51:42.0882 5500 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 17:51:42.0884 5500 QWAVEdrv - ok 17:51:42.0900 5500 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 17:51:42.0903 5500 RasAcd - ok 17:51:42.0941 5500 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 17:51:42.0943 5500 RasAgileVpn - ok 17:51:42.0956 5500 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 17:51:42.0959 5500 RasAuto - ok 17:51:43.0004 5500 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 17:51:43.0006 5500 Rasl2tp - ok 17:51:43.0055 5500 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 17:51:43.0060 5500 RasMan - ok 17:51:43.0109 5500 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 17:51:43.0112 5500 RasPppoe - ok 17:51:43.0142 5500 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 17:51:43.0144 5500 RasSstp - ok 17:51:43.0190 5500 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 17:51:43.0195 5500 rdbss - ok 17:51:43.0205 5500 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 17:51:43.0207 5500 rdpbus - ok 17:51:43.0235 5500 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 17:51:43.0237 5500 RDPCDD - ok 17:51:43.0300 5500 [ 1B6163C503398B23FF8B939C67747683 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys 17:51:43.0305 5500 RDPDR - ok 17:51:43.0319 5500 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 17:51:43.0321 5500 RDPENCDD - ok 17:51:43.0349 5500 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 17:51:43.0352 5500 RDPREFMP - ok 17:51:43.0425 5500 [ 70CBA1A0C98600A2AA1863479B35CB90 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys 17:51:43.0428 5500 RdpVideoMiniport - ok 17:51:43.0472 5500 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 17:51:43.0477 5500 RDPWD - ok 17:51:43.0497 5500 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 17:51:43.0502 5500 rdyboost - ok 17:51:43.0529 5500 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 17:51:43.0532 5500 RemoteAccess - ok 17:51:43.0561 5500 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 17:51:43.0566 5500 RemoteRegistry - ok 17:51:43.0605 5500 [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys 17:51:43.0609 5500 RFCOMM - ok 17:51:43.0658 5500 [ 91C2AE052652E7ABD88155F11D667ED2 ] risdpcie C:\Windows\system32\DRIVERS\risdpe64.sys 17:51:43.0660 5500 risdpcie - ok 17:51:43.0676 5500 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 17:51:43.0679 5500 RpcEptMapper - ok 17:51:43.0693 5500 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 17:51:43.0695 5500 RpcLocator - ok 17:51:43.0786 5500 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll 17:51:43.0789 5500 RpcSs - ok 17:51:43.0834 5500 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 17:51:43.0836 5500 rspndr - ok 17:51:43.0878 5500 [ E60C0A09F997826C7627B244195AB581 ] s3cap C:\Windows\system32\drivers\vms3cap.sys 17:51:43.0880 5500 s3cap - ok 17:51:43.0898 5500 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 17:51:43.0899 5500 SamSs - ok 17:51:43.0993 5500 [ 4DCFF3FC0FB89384D22AE35144B44D8A ] SAVAdminService C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe 17:51:43.0994 5500 SAVAdminService - ok 17:51:44.0041 5500 [ C3999EF390EB460A636E9FFBA040BF8A ] SAVOnAccess C:\Windows\system32\DRIVERS\savonaccess.sys 17:51:44.0042 5500 SAVOnAccess - ok 17:51:44.0074 5500 [ D31E18B53B0E52C234568BB61EEC7940 ] SAVService C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe 17:51:44.0078 5500 SAVService - ok 17:51:44.0093 5500 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 17:51:44.0096 5500 sbp2port - ok 17:51:44.0117 5500 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 17:51:44.0121 5500 SCardSvr - ok 17:51:44.0169 5500 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 17:51:44.0171 5500 scfilter - ok 17:51:44.0236 5500 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 17:51:44.0262 5500 Schedule - ok 17:51:44.0309 5500 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 17:51:44.0310 5500 SCPolicySvc - ok 17:51:44.0333 5500 [ 111E0EBC0AD79CB0FA014B907B231CF0 ] sdbus C:\Windows\system32\drivers\sdbus.sys 17:51:44.0337 5500 sdbus - ok 17:51:44.0402 5500 [ 7D67AEABEB597C602EDB5B3AE316E96A ] sdcfilter C:\Windows\system32\DRIVERS\sdcfilter.sys 17:51:44.0415 5500 sdcfilter - ok 17:51:44.0432 5500 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 17:51:44.0436 5500 SDRSVC - ok 17:51:44.0462 5500 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 17:51:44.0464 5500 secdrv - ok 17:51:44.0511 5500 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 17:51:44.0514 5500 seclogon - ok 17:51:44.0532 5500 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll 17:51:44.0535 5500 SENS - ok 17:51:44.0545 5500 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 17:51:44.0549 5500 SensrSvc - ok 17:51:44.0564 5500 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 17:51:44.0566 5500 Serenum - ok 17:51:44.0578 5500 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys 17:51:44.0580 5500 Serial - ok 17:51:44.0651 5500 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 17:51:44.0654 5500 sermouse - ok 17:51:44.0737 5500 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 17:51:44.0740 5500 SessionEnv - ok 17:51:44.0785 5500 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 17:51:44.0788 5500 sffdisk - ok 17:51:44.0801 5500 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 17:51:44.0803 5500 sffp_mmc - ok 17:51:44.0814 5500 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 17:51:44.0816 5500 sffp_sd - ok 17:51:44.0824 5500 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 17:51:44.0826 5500 sfloppy - ok 17:51:44.0859 5500 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll 17:51:44.0865 5500 SharedAccess - ok 17:51:44.0916 5500 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 17:51:44.0923 5500 ShellHWDetection - ok 17:51:44.0952 5500 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 17:51:44.0954 5500 SiSRaid2 - ok 17:51:44.0975 5500 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 17:51:44.0978 5500 SiSRaid4 - ok 17:51:45.0070 5500 [ A4FAB5F7818A69DA6E740943CB8F7CA9 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 17:51:45.0073 5500 SkypeUpdate - ok 17:51:45.0084 5500 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 17:51:45.0086 5500 Smb - ok 17:51:45.0115 5500 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 17:51:45.0117 5500 SNMPTRAP - ok 17:51:45.0199 5500 [ 3F04E2F60FEAAF96D144C9462575FD24 ] Sophos AutoUpdate Service C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe 17:51:45.0202 5500 Sophos AutoUpdate Service - ok 17:51:45.0351 5500 [ BD03374253F79CE7A716A870DC85BD84 ] Sophos Web Control Service C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe 17:51:45.0356 5500 Sophos Web Control Service - ok 17:51:45.0400 5500 [ 69FBE35A8165ADBC313AA7F64B868CA1 ] SophosBootDriver C:\Windows\system32\DRIVERS\SophosBootDriver.sys 17:51:45.0402 5500 SophosBootDriver - ok 17:51:45.0418 5500 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 17:51:45.0419 5500 spldr - ok 17:51:45.0478 5500 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 17:51:45.0486 5500 Spooler - ok 17:51:45.0592 5500 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 17:51:45.0659 5500 sppsvc - ok 17:51:45.0686 5500 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 17:51:45.0689 5500 sppuinotify - ok 17:51:45.0743 5500 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 17:51:45.0750 5500 srv - ok 17:51:45.0771 5500 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 17:51:45.0777 5500 srv2 - ok 17:51:45.0792 5500 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 17:51:45.0796 5500 srvnet - ok 17:51:45.0822 5500 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 17:51:45.0827 5500 SSDPSRV - ok 17:51:45.0837 5500 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 17:51:45.0841 5500 SstpSvc - ok 17:51:45.0899 5500 [ C692C94FE55CAD0633440236022C27B3 ] ssudmdm C:\Windows\system32\DRIVERS\ssudmdm.sys 17:51:45.0903 5500 ssudmdm - ok 17:51:46.0046 5500 [ 64F41D5A4CDCF83D36BC16E52FE1EA92 ] STacSV C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_e085d3cd5b474ba6\STacSV64.exe 17:51:46.0050 5500 STacSV - ok 17:51:46.0092 5500 [ C568FDB21CE77A44FD166F28F104AC46 ] stdflt C:\Windows\system32\DRIVERS\stdfltn.sys 17:51:46.0092 5500 stdflt - ok 17:51:46.0161 5500 Steam Client Service - ok 17:51:46.0249 5500 [ AE937A7138EB60AA8D8C7ED305AD28B9 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 17:51:46.0255 5500 Stereo Service - ok 17:51:46.0282 5500 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 17:51:46.0284 5500 stexstor - ok 17:51:46.0327 5500 [ 7A0CEC55645E0817F70FB8708D93E669 ] STHDA C:\Windows\system32\DRIVERS\stwrt64.sys 17:51:46.0334 5500 STHDA - ok 17:51:46.0393 5500 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 17:51:46.0413 5500 stisvc - ok 17:51:46.0473 5500 [ 7785DC213270D2FC066538DAF94087E7 ] storflt C:\Windows\system32\drivers\vmstorfl.sys 17:51:46.0474 5500 storflt - ok 17:51:46.0493 5500 [ C40841817EF57D491F22EB103DA587CC ] StorSvc C:\Windows\system32\storsvc.dll 17:51:46.0497 5500 StorSvc - ok 17:51:46.0512 5500 [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc C:\Windows\system32\drivers\storvsc.sys 17:51:46.0515 5500 storvsc - ok 17:51:46.0532 5500 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys 17:51:46.0532 5500 swenum - ok 17:51:46.0706 5500 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe 17:51:46.0722 5500 SwitchBoard - ok 17:51:47.0041 5500 [ 4402D541DA0413CB128D0455E9753B60 ] swi_service C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe 17:51:47.0091 5500 swi_service - ok 17:51:47.0237 5500 [ 79FF2406BB7EB7DACB12EE3DBF8F91AE ] swi_update_64 C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe 17:51:47.0276 5500 swi_update_64 - ok 17:51:47.0340 5500 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 17:51:47.0356 5500 swprv - ok 17:51:47.0382 5500 Synth3dVsc - ok 17:51:47.0462 5500 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 17:51:47.0495 5500 SysMain - ok 17:51:47.0834 5500 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 17:51:47.0838 5500 TabletInputService - ok 17:51:47.0931 5500 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 17:51:47.0952 5500 TapiSrv - ok 17:51:48.0003 5500 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 17:51:48.0007 5500 TBS - ok 17:51:48.0084 5500 [ 37608401DFDB388CAF66917F6B2D6FB0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 17:51:48.0129 5500 Tcpip - ok 17:51:48.0166 5500 [ 37608401DFDB388CAF66917F6B2D6FB0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 17:51:48.0176 5500 TCPIP6 - ok 17:51:48.0198 5500 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 17:51:48.0201 5500 tcpipreg - ok 17:51:48.0228 5500 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 17:51:48.0231 5500 TDPIPE - ok 17:51:48.0278 5500 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 17:51:48.0281 5500 TDTCP - ok 17:51:48.0346 5500 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 17:51:48.0349 5500 tdx - ok 17:51:48.0433 5500 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys 17:51:48.0434 5500 TermDD - ok 17:51:48.0479 5500 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 17:51:48.0495 5500 TermService - ok 17:51:48.0522 5500 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 17:51:48.0525 5500 Themes - ok 17:51:48.0551 5500 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 17:51:48.0552 5500 THREADORDER - ok 17:51:48.0562 5500 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 17:51:48.0565 5500 TrkWks - ok 17:51:48.0632 5500 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 17:51:48.0636 5500 TrustedInstaller - ok 17:51:48.0688 5500 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 17:51:48.0690 5500 tssecsrv - ok 17:51:48.0752 5500 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 17:51:48.0754 5500 TsUsbFlt - ok 17:51:48.0776 5500 tsusbhub - ok 17:51:48.0840 5500 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 17:51:48.0843 5500 tunnel - ok 17:51:48.0871 5500 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 17:51:48.0873 5500 uagp35 - ok 17:51:48.0925 5500 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 17:51:48.0931 5500 udfs - ok 17:51:48.0953 5500 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 17:51:48.0956 5500 UI0Detect - ok 17:51:48.0999 5500 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 17:51:49.0001 5500 uliagpkx - ok 17:51:49.0054 5500 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys 17:51:49.0056 5500 umbus - ok 17:51:49.0077 5500 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 17:51:49.0079 5500 UmPass - ok 17:51:49.0133 5500 [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService C:\Windows\System32\umrdp.dll 17:51:49.0138 5500 UmRdpService - ok 17:51:49.0164 5500 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 17:51:49.0171 5500 upnphost - ok 17:51:49.0196 5500 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys 17:51:49.0200 5500 usbaudio - ok 17:51:49.0247 5500 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 17:51:49.0249 5500 usbccgp - ok 17:51:49.0291 5500 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 17:51:49.0295 5500 usbcir - ok 17:51:49.0343 5500 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys 17:51:49.0347 5500 usbehci - ok 17:51:49.0399 5500 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 17:51:49.0405 5500 usbhub - ok 17:51:49.0452 5500 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys 17:51:49.0455 5500 usbohci - ok 17:51:49.0499 5500 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 17:51:49.0501 5500 usbprint - ok 17:51:49.0595 5500 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys 17:51:49.0778 5500 usbscan - ok 17:51:49.0804 5500 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 17:51:49.0807 5500 USBSTOR - ok 17:51:49.0849 5500 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys 17:51:49.0851 5500 usbuhci - ok 17:51:49.0874 5500 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 17:51:49.0877 5500 UxSms - ok 17:51:49.0888 5500 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 17:51:49.0889 5500 VaultSvc - ok 17:51:49.0912 5500 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 17:51:49.0912 5500 vdrvroot - ok 17:51:49.0968 5500 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 17:51:49.0977 5500 vds - ok 17:51:50.0005 5500 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 17:51:50.0007 5500 vga - ok 17:51:50.0022 5500 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 17:51:50.0023 5500 VgaSave - ok 17:51:50.0033 5500 VGPU - ok 17:51:50.0053 5500 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 17:51:50.0057 5500 vhdmp - ok 17:51:50.0101 5500 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 17:51:50.0103 5500 viaide - ok 17:51:50.0122 5500 [ 86EA3E79AE350FEA5331A1303054005F ] vmbus C:\Windows\system32\drivers\vmbus.sys 17:51:50.0125 5500 vmbus - ok 17:51:50.0142 5500 [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys 17:51:50.0144 5500 VMBusHID - ok 17:51:50.0168 5500 [ E8BE6CBE640F1CFB26F5A2A6DB24BE7D ] vmxnet3ndis6 C:\Windows\system32\DRIVERS\vmxnet3n61x64.sys 17:51:50.0171 5500 vmxnet3ndis6 - ok 17:51:50.0181 5500 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 17:51:50.0183 5500 volmgr - ok 17:51:50.0239 5500 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 17:51:50.0244 5500 volmgrx - ok 17:51:50.0255 5500 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 17:51:50.0259 5500 volsnap - ok 17:51:50.0276 5500 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 17:51:50.0280 5500 vsmraid - ok 17:51:50.0350 5500 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 17:51:50.0384 5500 VSS - ok 17:51:50.0400 5500 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 17:51:50.0402 5500 vwifibus - ok 17:51:50.0412 5500 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 17:51:50.0415 5500 vwififlt - ok 17:51:50.0435 5500 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys 17:51:50.0437 5500 vwifimp - ok 17:51:50.0459 5500 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 17:51:50.0466 5500 W32Time - ok 17:51:50.0480 5500 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 17:51:50.0483 5500 WacomPen - ok 17:51:50.0514 5500 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 17:51:50.0516 5500 WANARP - ok 17:51:50.0532 5500 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 17:51:50.0533 5500 Wanarpv6 - ok 17:51:50.0585 5500 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 17:51:50.0611 5500 WatAdminSvc - ok 17:51:50.0681 5500 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 17:51:50.0708 5500 wbengine - ok 17:51:50.0730 5500 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 17:51:50.0735 5500 WbioSrvc - ok 17:51:50.0793 5500 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 17:51:50.0799 5500 wcncsvc - ok 17:51:50.0817 5500 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 17:51:50.0820 5500 WcsPlugInService - ok 17:51:50.0841 5500 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys 17:51:50.0843 5500 Wd - ok 17:51:50.0905 5500 [ A3D04EBF5227886029B4532F20D026F7 ] WDC_SAM C:\Windows\system32\DRIVERS\wdcsam64.sys 17:51:50.0907 5500 WDC_SAM - ok 17:51:50.0968 5500 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 17:51:50.0984 5500 Wdf01000 - ok 17:51:50.0998 5500 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 17:51:51.0001 5500 WdiServiceHost - ok 17:51:51.0005 5500 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 17:51:51.0007 5500 WdiSystemHost - ok 17:51:51.0059 5500 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 17:51:51.0065 5500 WebClient - ok 17:51:51.0081 5500 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 17:51:51.0087 5500 Wecsvc - ok 17:51:51.0103 5500 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 17:51:51.0106 5500 wercplsupport - ok 17:51:51.0130 5500 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 17:51:51.0133 5500 WerSvc - ok 17:51:51.0162 5500 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 17:51:51.0164 5500 WfpLwf - ok 17:51:51.0180 5500 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 17:51:51.0183 5500 WIMMount - ok 17:51:51.0194 5500 WinDefend - ok 17:51:51.0199 5500 WinHttpAutoProxySvc - ok 17:51:51.0240 5500 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 17:51:51.0244 5500 Winmgmt - ok 17:51:51.0318 5500 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 17:51:51.0369 5500 WinRM - ok 17:51:51.0438 5500 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 17:51:51.0440 5500 WinUsb - ok 17:51:51.0468 5500 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 17:51:51.0488 5500 Wlansvc - ok 17:51:51.0670 5500 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 17:51:51.0728 5500 wlidsvc - ok 17:51:51.0746 5500 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 17:51:51.0747 5500 WmiAcpi - ok 17:51:51.0833 5500 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 17:51:51.0837 5500 wmiApSrv - ok 17:51:51.0871 5500 WMPNetworkSvc - ok 17:51:51.0898 5500 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 17:51:51.0901 5500 WPCSvc - ok 17:51:51.0951 5500 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 17:51:51.0955 5500 WPDBusEnum - ok 17:51:51.0982 5500 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 17:51:51.0984 5500 ws2ifsl - ok 17:51:51.0999 5500 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll 17:51:52.0003 5500 wscsvc - ok 17:51:52.0006 5500 WSearch - ok 17:51:52.0089 5500 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 17:51:52.0140 5500 wuauserv - ok 17:51:52.0191 5500 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 17:51:52.0193 5500 WudfPf - ok 17:51:52.0211 5500 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 17:51:52.0214 5500 WUDFRd - ok 17:51:52.0230 5500 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 17:51:52.0233 5500 wudfsvc - ok 17:51:52.0255 5500 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll 17:51:52.0260 5500 WwanSvc - ok 17:51:52.0335 5500 [ 38F55D07B1D3391065C40EC065F984E2 ] xusb21 C:\Windows\system32\DRIVERS\xusb21.sys 17:51:52.0337 5500 xusb21 - ok 17:51:52.0357 5500 ================ Scan global =============================== 17:51:52.0387 5500 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 17:51:52.0441 5500 [ 9E479C2B605C25DA4971ABA36250FAEF ] C:\Windows\system32\winsrv.dll 17:51:52.0449 5500 [ 9E479C2B605C25DA4971ABA36250FAEF ] C:\Windows\system32\winsrv.dll 17:51:52.0481 5500 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 17:51:52.0505 5500 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 17:51:52.0507 5500 [Global] - ok 17:51:52.0508 5500 ================ Scan MBR ================================== 17:51:52.0519 5500 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 17:51:52.0854 5500 \Device\Harddisk0\DR0 - ok 17:51:52.0858 5500 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk1\DR1 17:51:52.0864 5500 \Device\Harddisk1\DR1 - ok 17:51:52.0865 5500 ================ Scan VBR ================================== 17:51:52.0916 5500 [ 6557A8F171F5C51B744149F379629E48 ] \Device\Harddisk0\DR0\Partition1 17:51:52.0918 5500 \Device\Harddisk0\DR0\Partition1 - ok 17:51:52.0954 5500 [ C500478C197CD839BFE78546098EA75C ] \Device\Harddisk0\DR0\Partition2 17:51:52.0961 5500 \Device\Harddisk0\DR0\Partition2 - ok 17:51:52.0964 5500 [ E4CFE00A20E465BFF5D4B5C6728F17D8 ] \Device\Harddisk1\DR1\Partition1 17:51:52.0965 5500 \Device\Harddisk1\DR1\Partition1 - ok 17:51:52.0966 5500 ============================================================ 17:51:52.0966 5500 Scan finished 17:51:52.0966 5500 ============================================================ 17:51:52.0975 5544 Detected object count: 0 17:51:52.0975 5544 Actual detected object count: 0
ComboFix

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
For some reason I can no longer disable my Antivirus. The antivirus was preinstalled by my university and it seems I no longer have the rights to tinker with it. Should i run the ComboFix anyway?
Here we go, ComboFix-log: ComboFix 13-01-31.03 - dtb05 31-01-2013 20:41:37.1.4 - x64 MINIMAL Microsoft Windows 7 Enterprise 6.1.7601.1.1252.45.1033.18.4022.2395 [GMT 1:00] Kører fra: c:\users\dtb05\Desktop\ComboFix.exe AV: Sophos Anti-Virus *Disabled/Updated* {65FBD860-96D8-75EF-C7ED-7BE27E6C498A} SP: Sophos Anti-Virus *Disabled/Updated* {DE9A3984-B0E2-7A61-FD5D-409005EB0337} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Dannede nyt systemgendannelsespunkt . . ((((((((((((((((((((((((((((((((((((((( Andet, der er slettet ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\dtb05\AppData\Local\{B5971518-FF9D-4B54-97A6-BE84E584A348} c:\windows\SysWow64\muzapp.exe c:\windows\SysWow64\tmpACD2.tmp c:\windows\SysWow64\tmpACD3.tmp . . ((((((((((((((((((((((((((((( Filer skabt fra 2012-12-28 til 2013-01-31 ))))))))))))))))))))))))))))))))))) . . 2013-01-31 14:21 . 2013-01-31 14:21 ——– d—–w- c:\program files (x86)\Common Files\Java 2013-01-31 14:20 . 2013-01-31 14:20 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-01-29 08:15 . 2013-01-08 05:32 9161176 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9773D15E-53BC-4A29-A943-C28A33EEBF22}\mpengine.dll 2013-01-15 08:27 . 2013-01-04 15:53 9060864 —-a-w- c:\windows\system32\mshtml.dll 2013-01-09 18:02 . 2012-11-30 05:41 424448 —-a-w- c:\windows\system32\KernelBase.dll 2013-01-09 18:01 . 2012-11-23 03:26 3149824 —-a-w- c:\windows\system32\win32k.sys 2013-01-09 18:01 . 2012-11-23 03:13 68608 —-a-w- c:\windows\system32\taskhost.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-01-31 14:20 . 2012-07-01 16:38 859552 —-a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-01-31 14:20 . 2010-09-02 13:23 780192 —-a-w- c:\windows\SysWow64\deployJava1.dll 2013-01-09 22:16 . 2010-08-16 07:09 67599240 —-a-w- c:\windows\system32\MRT.exe 2013-01-09 11:41 . 2012-04-03 08:45 697864 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-01-09 11:41 . 2011-05-18 08:42 74248 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-12-16 17:11 . 2012-12-21 09:24 46080 —-a-w- c:\windows\system32\atmlib.dll 2012-12-16 14:45 . 2012-12-21 09:24 367616 —-a-w- c:\windows\system32\atmfd.dll 2012-12-16 14:13 . 2012-12-21 09:24 295424 —-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-16 14:13 . 2012-12-21 09:24 34304 —-a-w- c:\windows\SysWow64\atmlib.dll 2012-11-30 04:45 . 2013-01-09 18:02 44032 —-a-w- c:\windows\apppatch\acwow64.dll 2012-11-29 13:36 . 2012-11-29 13:36 154952 —-a-w- c:\windows\system32\drivers\savonaccess.sys 2012-11-29 13:36 . 2012-11-15 01:52 37440 —-a-w- c:\windows\system32\SophosBootTasks.exe 2012-11-15 01:00 . 2012-11-15 01:00 36640 —-a-w- c:\windows\system32\drivers\sdcfilter.sys 2012-11-15 00:44 . 2012-11-15 00:44 183024 —-a-w- c:\windows\system32\sdccoinstaller.dll 2012-11-15 00:36 . 2012-11-15 00:36 25608 —-a-w- c:\windows\system32\drivers\SophosBootDriver.sys 2012-11-12 12:28 . 2012-12-12 09:02 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2012-11-12 11:52 . 2012-12-12 09:02 1638912 —-a-w- c:\windows\SysWow64\mshtml.tlb 2012-11-09 05:45 . 2012-12-12 09:03 2048 —-a-w- c:\windows\system32\tzres.dll 2012-11-09 04:42 . 2012-12-12 09:03 2048 —-a-w- c:\windows\SysWow64\tzres.dll . . ((((((((((((((((((((((((((((((((((( Start steder i reg.basen )))))))))))))))))))))))))))))))))))))))))))))))) . . *Bemærk* tomme linier & lovlige standard linier vises ikke REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 94208 —-a-w- c:\users\dtb05\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 94208 —-a-w- c:\users\dtb05\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 94208 —-a-w- c:\users\dtb05\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-22 402432] "AutoProfileRepair"="c:\program files (x86)\Oracle\Outlook Connector\profilerepair.exe" [2009-01-30 73728] "WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2012-06-28 74752] "boincmgr"="c:\program files (x86)\BOINC\boincmgr.exe" [2010-07-01 4862720] "boinctray"="c:\program files (x86)\BOINC\boinctray.exe" [2010-07-01 58112] "Sophos AutoUpdate Monitor"="c:\program files (x86)\Sophos\AutoUpdate\almon.exe" [2012-12-06 928832] "VolPanel"="c:\program files (x86)\Creative\USB Sound Blaster HD\Volume Panel\VolPanlu.exe" [2009-07-07 241789] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-11-12 309688] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-1-8 1121568] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~1\sophos_detoured.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService] @="service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus] "DisableMonitoring"=dword:00000001 . R1 SAVOnAccess;SAVOnAccess;c:\windows\system32\DRIVERS\savonaccess.sys [2012-11-29 154952] R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_e085d3cd5b474ba6\AESTSr64.exe [2009-03-03 89600] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [2009-12-17 1039776] R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [2009-12-17 31136] R2 InstallFilterService;FF Install Filter Service;c:\program files (x86)\STMicroelectronics\AccelerometerP11\InstallFilterService.exe [2010-01-10 60928] R2 ocautoupds;Oracle Connector Automatic Updates Service;c:\program files (x86)\Oracle\Outlook Connector\ocautoupds.exe [2009-01-30 69632] R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [2012-12-06 216640] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944] R2 Sophos Web Control Service;Sophos Web Control Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [2012-11-15 357400] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-04-27 382272] R2 swi_service;Sophos Web Intelligence Service;c:\program files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2012-12-06 2878016] R2 swi_update_64;Sophos Web Intelligence Update;c:\programdata\Sophos\Web Intelligence\swi_update_64.exe [2012-12-06 2010688] R3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2010-01-11 321576] R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-01-11 39464] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-01-14 79360] R3 cvusbdrv;Dell ControlVault;c:\windows\system32\Drivers\cvusbdrv.sys [2009-11-03 38440] R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2012-09-20 102368] R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\DRIVERS\e1k62x64.sys [2009-12-10 294064] R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena\safedrv.sys [x] R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2010-02-26 158976] R3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys [2010-04-09 1557248] R3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [2009-09-15 6952960] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 20992] R3 sdcfilter;sdcfilter;c:\windows\system32\DRIVERS\sdcfilter.sys [2012-11-15 36640] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2012-09-20 203104] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 vmxnet3ndis6;vmxnet3 NDIS 6 Ethernet Adapter Driver;c:\windows\system32\DRIVERS\vmxnet3n61x64.sys [2009-04-30 70192] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-16 1255736] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2008-05-06 14464] R4 SophosBootDriver;SophosBootDriver;c:\windows\system32\DRIVERS\SophosBootDriver.sys [2012-11-15 25608] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2011-03-04 55856] S0 stdflt;Disk Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdfltn.sys [2010-01-18 21040] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-03-16 283200] S2 risdpcie;risdpcie;c:\windows\system32\DRIVERS\risdpe64.sys [2010-03-19 81920] S2 SAVService;Sophos Anti-Virus;c:\program files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [2012-11-29 159296] S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys [2010-01-18 26160] S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2011-08-01 45416] . . Indhold af mappen 'Planlagte Opgaver' . 2013-01-31 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 11:41] . 2013-01-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2231803270-93480321-3026884197-1008Core.job - c:\users\dtb05\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-19 13:54] . 2013-01-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2231803270-93480321-3026884197-1008UA.job - c:\users\dtb05\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-19 13:54] . 2013-01-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2231803270-93480321-3026884197-1066Core.job - c:\users\Dines\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-01 18:02] . 2013-01-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2231803270-93480321-3026884197-1066UA.job - c:\users\Dines\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-01 18:02] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 97792 —-a-w- c:\users\dtb05\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 97792 —-a-w- c:\users\dtb05\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 97792 —-a-w- c:\users\dtb05\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2012-06-30 04:19 97792 —-a-w- c:\users\dtb05\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-05-12 391024] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-03-09 487424] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208] "Creative SB Monitoring Utility"="sbavmon.dll" [2010-01-12 109056] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032] "nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2012-04-27 1694016] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\progra~2\Sophos\SOPHOS~1\sophos_detoured_x64.dll . ——- Yderligere scanning ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mLocal Page = c:\windows\SysWOW64\blank.htm IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105 IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm TCP: DhcpNameServer = [removed] [removed] [removed] FF - ProfilePath - c:\users\dtb05\AppData\Roaming\Mozilla\Firefox\Profiles\yes0y26u.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: network.proxy.type - 0 . - - - - TOMME GENVEJE FJERNET - - - - . Toolbar-Locked - (no file) Toolbar-Locked - (no file) . . . ——————— LÅSTE REGISTRERINGS NØGLER ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" "Key"="ActionsPane3" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Gennemført tid: 2013-01-31 20:51:24 ComboFix-quarantined-files.txt 2013-01-31 19:51 . Pre-Kørsel: 29.513.748.480 bytes free Post-Kørsel: 31.579.185.152 bytes free . - - End Of File - - BE56AA82903D12742004726BA31685F3
The system is running fine. Had to get the IT-guys to reinstall the sophos antivirus, since it wouldnt let me activate it again. Sophos then found a PUA or something, which I asked it to delete. I am currently running a full scan with sophos. Also ran a scan using Spybot search and destroy. It did not come up with anything.. Just not sure I can shake the paranoia from not actually seeing anything deleting the Win32/small.CA.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI