This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PC running slow and some wierd ads [Solved]

90 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, My PC has been running very slow lately and I get these goofy ads when I mouse over highlighted text on webpages that pops up these unwanted ads. I'm assuming that I must be infected with some malware or something. Can you help me, please? I got a response earlier but was out of town and couldn't respond. So, I'd really appreciate any help. Thank you!
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!


Download and Run DDS by sUBs

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
    • DDS.com
    • DDS.pif
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE





Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
THank you very much. Here is the DDS log: DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.7.2 Run by [removed] at 16:58:05 on 2013-02-06 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3062.939 [GMT -8:00] . AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C} SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes ================ . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe c:\Program Files\Microsoft Security Client\MsMpEng.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\Windows\System32\spoolsv.exe C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\CSR\Vista Profile Pack\BthFilterHelper.exe C:\Program Files\Cobian Backup 10\cbVSCService.exe C:\Program Files\Cobian Backup 10\cbService.exe C:\Users\Dave\AppData\Local\CrossLoop\CrossLoopService.exe C:\Program Files\Common Files\Nuance\dgnsvc.exe C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe c:\Program Files\Microsoft Security Client\NisSrv.exe C:\Windows\System32\WUDFHost.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\microsoft office\Office14\WINWORD.EXE C:\Program Files\microsoft office\Office14\OUTLOOK.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe C:\Program Files\Microsoft Office\Office14\WINWORD.EXE C:\Windows\System32\WUDFHost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Microsoft Office\Office14\WINWORD.EXE C:\Program Files\Microsoft Office\Office14\WINWORD.EXE C:\Users\Dave\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Dave\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Dave\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Dave\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Dave\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files\Microsoft Office\Office14\EXCEL.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k bthsvcs C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k HPService C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k WindowsMobile C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation . ============== Pseudo HJT Report =============== . uStart Page = hxxps://www.google.com/ uDefault_Search_URL = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s uURLSearchHooks: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: &Yahoo;! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll BHO: SaveAs Class: {F9E78825-7C02-AA49-74D9-0D62DA67A447} - c:\programdata\saveas\50d3fda10f9b7.ocx BHO: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll uRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup uRun: [OfficeSyncProcess] "c:\program files\microsoft office\office14\MSOSYNC.EXE" uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler uRun: [cdloader] "c:\users\dave\appdata\roaming\mjusbsp\cdloader2.exe" MAGICJACK uRun: [googletalk] c:\users\dave\appdata\roaming\google\google talk\googletalk.exe /autostart uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [Spotify Web Helper] "c:\users\dave\appdata\roaming\spotify\data\SpotifyWebHelper.exe" uRun: [MobileDocuments] c:\program files\common files\apple\internet services\ubd.exe uRun: [GoogleDriveSync] "c:\program files\google\drive\googledrivesync.exe" /autostart mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume mRun: [HP LaserJet M1522 MFP Series Fax] c:\program files\hp\hp laserjet m1522\hppfaxprintersrv.exe "HP LaserJet M1522 MFP Series Fax" mRun: [HPUsageTracking] "c:\program files\hp\hp ut\bin\hppusg.exe" "c:\program files\hp\hp ut\" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [LockStatusTray] c:\windows\LockStatusTray.exe mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE mRun: [Windows Mobile-based device management] c:\windows\windowsmobile\wmdcBase.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [OEM13Mon.exe] c:\windows\OEM13Mon.exe mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [DNS7reminder] "c:\program files\nuance\naturallyspeaking11\ereg\ereg.exe" -r "c:\programdata\nuance\naturallyspeaking11\Ereg.ini mRun: [Cobian Backup 10 Interface] "c:\program files\cobian backup 10\cbInterface.exe" -service mRun: [Intuit SyncManager] c:\program files\common files\intuit\sync\IntuitSyncManager.exe startup mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [ToolboxFX] "c:\program files\hp\toolboxfx\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe" mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe" mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\google~1.lnk - c:\program files\google\google calendar sync\GoogleCalendarSync.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe uPolicies-Explorer: NoDrives = dword:0 mPolicies-Explorer: NoDrives = dword:0 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 mPolicies-System: PromptOnSecureDesktop = dword:0 IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200 IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000 IE: Se&nd; to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll Trusted Zone: //about.htm/ Trusted Zone: //Exclude.htm/ Trusted Zone: //FWEvent.htm/ Trusted Zone: //LanguageSelection.htm/ Trusted Zone: //Message.htm/ Trusted Zone: //MyAgttryCmd.htm/ Trusted Zone: //MyAgttryNag.htm/ Trusted Zone: //MyNotification.htm/ Trusted Zone: //NOCLessUpdate.htm/ Trusted Zone: //quarantine.htm/ Trusted Zone: //ScanNow.htm/ Trusted Zone: //strings.vbs/ Trusted Zone: //Template.htm/ Trusted Zone: //Update.htm/ Trusted Zone: //VirFound.htm/ DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: NameServer = 192.168.1.1 TCP: Interfaces\{6FD2D014-3DEE-49C5-BAC4-5EFC7C823EDC} : DHCPNameServer = [removed] [removed] TCP: Interfaces\{79EE02E4-39BE-4C39-881D-F5B949F8BF5E} : DHCPNameServer = 192.168.1.1 TCP: Interfaces\{79EE02E4-39BE-4C39-881D-F5B949F8BF5E}\44146554D27457563747 : DHCPNameServer = 192.168.1.1 TCP: Interfaces\{79EE02E4-39BE-4C39-881D-F5B949F8BF5E}\44146554D28444 : DHCPNameServer = 192.168.1.1 TCP: Interfaces\{79EE02E4-39BE-4C39-881D-F5B949F8BF5E}\6596379647F627 : DHCPNameServer = [removed] Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Handler: intu-help-qb3 - {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - c:\program files\intuit\quickbooks 2010\HelpAsyncPluggableProtocol.dll Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll Notify: igfxcui - igfxdev.dll Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\users\dave\appdata\roaming\mozilla\firefox\profiles\qln39cgr.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT3220468&SearchSource;=13 FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3220468&SearchSource;=2&q;= FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\program files\logitech\harmony remote driver\NprtHarmonyPlugin.dll FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll FF - plugin: c:\users\dave\appdata\local\google\update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: c:\users\dave\appdata\roaming\facebook\npfbplugin_1_0_3.dll FF - plugin: c:\users\dave\appdata\roaming\mozilla\plugins\npgoogletalk.dll FF - plugin: c:\users\dave\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_5_502_146.dll FF - plugin: c:\windows\system32\npDeployJava1.dll FF - plugin: c:\windows\system32\npmproxy.dll FF - ExtSQL: 2012-12-20 22:11; [removed]; c:\users\dave\appdata\roaming\mozilla\firefox\profiles\qln39cgr.default\extensions\[removed] FF - ExtSQL: !HIDDEN! 2010-08-15 23:37; [removed]; c:\program files\hp\digital imaging\smart web printing\MozillaAddOn3 . ============= SERVICES / DRIVERS =============== . R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-8-30 193552] R0 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2005-11-14 34176] R2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2012-3-20 99272] R3 OEM13Vfx;Creative Camera OEM013 Video VFX Driver;c:\windows\system32\drivers\OEM13Vfx.sys [2007-3-5 7424] R3 OEM13Vid;Creative Camera OEM013 Driver;c:\windows\system32\drivers\OEM13Vid.sys [2008-5-28 235840] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-9-22 36640] S3 HPFXBULKLEDM;HPFXBULKLEDM;c:\windows\system32\drivers\hppcbulkio.sys [2010-10-3 20504] S3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hpfxfax.sys [2010-1-26 20504] S3 libusb0;Jawbone LibUsb-Win32 - Kernel Driver 09/22/2011,1.2.5.0;c:\windows\system32\drivers\libusb0.sys [2012-3-13 42592] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-7-7 15872] S3 SIUSBXP;SIUSBXP;c:\windows\system32\drivers\SiUSBXp.sys [2012-9-14 14592] S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2011-2-12 96488] S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2011-2-12 12776] S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2011-2-12 121576] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-7-7 52224] . =============== File Associations =============== . FileExt: .chm: chm.file="c:\windows\hh.exe" %1 [UserChoice] . =============== Created Last 30 ================ . 2013-02-06 17:54:57 6991832 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{3cb77cf7-542b-4af1-9d5c-b90c4f449c44}\mpengine.dll 2013-02-05 06:30:55 6991832 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2013-01-09 10:54:33 626688 —-a-w- c:\windows\system32\usp10.dll 2013-01-09 10:54:31 2345984 —-a-w- c:\windows\system32\win32k.sys 2013-01-09 10:54:29 492032 —-a-w- c:\windows\system32\win32spl.dll 2013-01-09 10:54:09 1389568 —-a-w- c:\windows\system32\msxml6.dll 2013-01-09 10:54:00 293376 —-a-w- c:\windows\system32\KernelBase.dll 2013-01-09 10:52:40 220160 —-a-w- c:\windows\system32\ncrypt.dll 2013-01-09 10:52:38 49152 —-a-w- c:\windows\system32\taskhost.exe . ==================== Find3M ==================== . 2013-01-30 10:53:21 232336 ——w- c:\windows\system32\MpSigStub.exe 2013-01-09 20:25:19 74248 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-01-09 20:25:19 697864 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-12-16 14:13:28 295424 —-a-w- c:\windows\system32\atmfd.dll 2012-12-16 14:13:20 34304 —-a-w- c:\windows\system32\atmlib.dll 2012-12-07 12:26:17 308736 —-a-w- c:\windows\system32\Wpc.dll 2012-12-07 12:20:43 2576384 —-a-w- c:\windows\system32\gameux.dll 2012-11-30 04:53:34 169984 —-a-w- c:\windows\system32\winsrv.dll 2012-11-30 02:55:25 271360 —-a-w- c:\windows\system32\conhost.exe 2012-11-30 02:38:59 6144 —ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2012-11-30 02:38:59 4608 —ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2012-11-30 02:38:59 3584 —ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2012-11-30 02:38:59 3072 —ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2012-11-20 23:50:29 60304 —-a-w- c:\users\dave\g2mdlhlpx.exe 2012-11-14 02:09:22 1800704 —-a-w- c:\windows\system32\jscript9.dll 2012-11-14 01:58:15 1427968 —-a-w- c:\windows\system32\inetcpl.cpl 2012-11-14 01:57:37 1129472 —-a-w- c:\windows\system32\wininet.dll 2012-11-14 01:49:25 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2012-11-14 01:48:27 420864 —-a-w- c:\windows\system32\vbscript.dll 2012-11-14 01:44:42 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-11-09 04:42:49 2048 —-a-w- c:\windows\system32\tzres.dll . ============= FINISH: 17:09:58.32 =============== Here's the second file (I'm not sure if I was supposed to copy and paste or attach… . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows 7 Ultimate Boot Device: \Device\HarddiskVolume2 Install Date: 1/24/2010 3:34:30 PM System Uptime: 2/3/2013 1:19:13 PM (76 hours ago) . Motherboard: Dell Inc. | | GEA31U Processor: Intel® Core™2 Duo CPU T8100 @ 2.10GHz | U2E1 | 2094/800mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 288 GiB total, 93.211 GiB free. D: is CDROM () E: is Removable . ==== Disabled Device Manager Items ============= . Class GUID: Description: Officejet Pro 8500 A909g Device ID: ROOT\MULTIFUNCTION\0000 Manufacturer: Name: Officejet Pro 8500 A909g PNP Device ID: ROOT\MULTIFUNCTION\0000 Service: . Class GUID: Description: Officejet Pro 8500 A909g Device ID: ROOT\MULTIFUNCTION\0001 Manufacturer: Name: Officejet Pro 8500 A909g PNP Device ID: ROOT\MULTIFUNCTION\0001 Service: . Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318} Description: HP LaserJet CP1525nw Device ID: ROOT\MULTIFUNCTION\0002 Manufacturer: Hewlett-Packard Name: HP LaserJet CP1525nw PNP Device ID: ROOT\MULTIFUNCTION\0002 Service: . Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318} Description: Officejet Pro 8500 A909g Device ID: ROOT\MULTIFUNCTION\0003 Manufacturer: HP Name: Officejet Pro 8500 A909g PNP Device ID: ROOT\MULTIFUNCTION\0003 Service: . ==== System Restore Points =================== . RP895: 1/17/2013 3:17:26 AM - Windows Update RP896: 1/22/2013 6:30:12 AM - Windows Update RP897: 1/25/2013 11:48:36 AM - Windows Update RP898: 1/31/2013 12:01:54 AM - Windows Update RP899: 2/3/2013 12:15:57 AM - Windows Update RP900: 2/6/2013 9:53:30 AM - Windows Update . ==== Installed Programs ====================== . µTorrent 32 Bit HP CIO Components Installer 7-Zip 4.65 8500A909_eDocs 8500A909_Help 8500A909g Acrobat.com Ad-Aware Adobe AIR Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader X (10.1.5) AnswerWorks 5.0 English Runtime Apple Application Support Apple Mobile Device Support Apple Software Update AudibleManager Bing Maps 3D Blues Chapter 16 - Full Version Blues Chapter 17 - Full Version Bonjour BPD_DSWizards bpd_scan BPDSoftware BPDSoftware_Ini BufferChm Canon Camera WIA Driver Canon EOS Kiss REBEL 300D WIA Driver Canon MOV Decoder Canon MOV Encoder Canon MovieEdit Task for ZoomBrowser EX Canon PhotoRecord Canon RAW Codec Canon RAW Image Task for ZoomBrowser EX Canon RemoteCapture Task for ZoomBrowser EX Canon Utilities CameraWindow Canon Utilities CameraWindow DC 8 Canon Utilities Digital Photo Professional 3.8 Canon Utilities File Viewer Utility 1.3 Canon Utilities MyCamera Canon Utilities PhotoStitch 3.1 Canon Utilities RemoteCapture 2.7 Canon Utilities ZoomBrowser EX Canon ZoomBrowser EX Memory Card Utility CATS Microsoft Outlook Plug-in v1.95 CATS Microsoft Word Plug-in v1.35 CDDRV_Installer Chap 1 - How to Match Chords up with any Melody Chap 1 - How to play fantastic solos on the keyboard Chap 2 - How to Match Chords up with any Melody Chap 3 - How to Match Chords up with any Melody Chord Voicings Vault Click to Call with Skype Cobian Backup 10 Combined Community Codec Pack 2011-07-30 CrossLoop 2.72 Dassault Systemes Software Prerequisites x86 Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition Dell Driver Download Manager Destinations DeviceDiscovery Digsby Diminished 7th Chords - Chapter 1 DocMgr DocProc Dragon NaturallySpeaking 11 Dropbox Duplicate File Finder Ear Training 101 V4 Full Version erLT Facebook Plug-In Fax ffdshow [rev 2527] [2008-12-19] File Viewer Utility 1.3.2 GOM Player Google Apps Sync™ for Microsoft Outlook® 3.2.353.947 Google Calendar Sync Google Chrome Google Cloud Connect for Microsoft Office Google Drive Google Earth Plug-in Google Talk (remove only) Google Talk Plugin Google Toolbar for Internet Explorer Google Update Helper GoToMeeting 5.1.0.880 GPBaseService2 gwabbit Hewlett-Packard ACLM.NET v1.1.0.0 HP Customer Participation Program 13.0 HP Document Manager 2.0 HP FWUpdateEDO3 HP Imaging Device Functions 13.0 HP LaserJet M1522 MFP Series 4.2 HP LaserJet Professional CP1520 Series HP Photosmart Essential 3.5 HP Product Detection HP Smart Web Printing 4.60 HP Solution Center 13.0 HP Update HPDiagnosticAlert HPLaserJetHelp_LearnCenter HPLJUT hppCP1520LaserJetService hppFaxDrvM1522 hppFaxUtility hppFonts HPPhotoSmartDiscLabelContent1 HPPhotosmartEssential hppLaserJetService hppLJM1522 hppManualsM1522 HPProductAssistant hppScanTo hppSendFaxM1522 hppTLBXFXCP1520 hppTLBXFXM1522 hppusgM1522 hpzTLBXFX InstaCodecs Intel® Graphics Media Accelerator Driver Intel® TV Wizard IrfanView (remove only) iTunes Java 7 Update 7 Java Auto Updater Java™ 6 Update 26 JavaFX 2.1.0 Jawbone Updater Keyboard Lock Status KhalInstallWrapper Laptop Integrated Webcam Driver (1.01.01.0529) Logitech Harmony Remote Software Logitech Harmony Remote Software 7 Logitech SetPoint Macromedia Dreamweaver 8 Macromedia Extension Manager magicJack magicJack Outlook Add-In 1.0.3.521 Malwarebytes' Anti-Malware MarketResearch MediaMonkey 3.2 Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) Microsoft Default Manager Microsoft IntelliPoint 8.2 Microsoft IntelliType Pro 8.2 Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (English) 2010 Microsoft Office Access Setup Metadata MUI (English) 2010 Microsoft Office Excel MUI (English) 2010 Microsoft Office Groove MUI (English) 2010 Microsoft Office InfoPath MUI (English) 2010 Microsoft Office OneNote MUI (English) 2010 Microsoft Office Outlook MUI (English) 2010 Microsoft Office PowerPoint MUI (English) 2010 Microsoft Office Professional Plus 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (Spanish) 2010 Microsoft Office Proofing (English) 2010 Microsoft Office Publisher MUI (English) 2010 Microsoft Office Shared MUI (English) 2010 Microsoft Office Shared Setup Metadata MUI (English) 2010 Microsoft Office Word MUI (English) 2010 Microsoft Security Client Microsoft Security Essentials Microsoft Silverlight Microsoft SQL Server 2005 Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) Microsoft SQL Server 2005 Tools Express Edition Microsoft SQL Server Native Client Microsoft SQL Server Setup Support Files (English) Microsoft SQL Server VSS Writer Microsoft UI Engine Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft WSE 3.0 Runtime MobileMe Control Panel Mozilla Firefox 18.0.1 (x86 en-US) MPEG2 Codec(libmpeg2/mad) MPM MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP2 Parser and SDK Network OCR Software by I.R.I.S. 13.0 Officejet Pro 8500 A909 Series OGA Notifier 2.0.0048.0 PhotoStitch Picasa 3 Product_Min_QFolder ProductContext QuickBooks QuickBooks Pro 2010 Quicken 2009 QuickTime RAW Image Task Remote Control USB Driver RemoteCapture 2.7.5 RemoteCapture Task SAMSUNG USB Driver for Mobile Phones SaveAs Scan Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition Security Update for Microsoft InfoPath 2010 (KB2687436) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553091) Security Update for Microsoft Office 2010 (KB2553096) Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition Security Update for Microsoft Visio 2010 (KB2687508) 32-Bit Edition Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition Shared Add-in Extensibility Update for Microsoft .NET Framework 2.0 (KB908002) Shared Add-in Support Update for Microsoft .NET Framework 2.0 (KB908002) Skype™ 6.0 SmartWebPrinting SolutionCenter Songwriting, Chapter 1 Spotify Status Telephone Plug-in Toolbox TrayApp Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Office 2010 (KB2494150) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553092) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2687277) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition Vista Profile Pack Visual C++ 8.0 ATL (x86) WinSXS MSM Visual C++ 8.0 CRT (x86) WinSXS MSM Visual C++ 9.0 Runtime for Dragon NaturallySpeaking Visual C++ Runtime for Dragon NaturallySpeaking Visual Studio Tools for the Office system 3.0 Runtime Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) VLC media player 1.1.7 WebEx WebReg WinDirStat 1.1.2 Windows Migration Assistant WinRAR archiver Yahoo! Toolbar Zoho CRM Plug-in for Microsoft Outlook . ==== Event Viewer Messages From Past Week ======== . 2/6/2013 9:41:26 AM, Error: Server [2505] - The server could not bind to the transport \Device\NetBT_Tcpip_{79EE02E4-39BE-4C39-881D-F5B949F8BF5E} because another computer on the network has the same name. The server could not start. 2/6/2013 9:41:12 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service. 2/2/2013 12:37:10 AM, Error: bowser [8003] - The master browser has received a server announcement from the computer GABE-LAPTOP that believes that it is the master browser for the domain on transport NetBT_Tcpip_{6FD2D014-3DEE-49C5-BAC4-5EFC7C. The master browser is stopping or an election is being forced. . ==== End Of File =========================== TDSS Killer Report: 17:20:20.0963 5724 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35 17:20:21.0496 5724 ============================================================ 17:20:21.0496 5724 Current date / time: 2013/02/06 17:20:21.0496 17:20:21.0496 5724 SystemInfo: 17:20:21.0496 5724 17:20:21.0497 5724 OS Version: 6.1.7601 ServicePack: 1.0 17:20:21.0497 5724 Product type: Workstation 17:20:21.0497 5724 ComputerName: DAVE-PC 17:20:21.0497 5724 UserName: Dave 17:20:21.0497 5724 Windows directory: C:\Windows 17:20:21.0497 5724 System windows directory: C:\Windows 17:20:21.0497 5724 Processor architecture: Intel x86 17:20:21.0497 5724 Number of processors: 2 17:20:21.0497 5724 Page size: 0x1000 17:20:21.0497 5724 Boot type: Normal boot 17:20:21.0497 5724 ============================================================ 17:20:26.0430 5724 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 17:20:26.0631 5724 Drive \Device\Harddisk1\DR1 - Size: 0x3BA300000 (14.91 Gb), SectorSize: 0x200, Cylinders: 0x79A, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 17:20:26.0633 5724 ============================================================ 17:20:26.0633 5724 \Device\Harddisk0\DR0: 17:20:26.0633 5724 MBR partitions: 17:20:26.0633 5724 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x240922A8 17:20:26.0633 5724 \Device\Harddisk1\DR1: 17:20:26.0634 5724 MBR partitions: 17:20:26.0634 5724 \Device\Harddisk1\DR1\Partition1: MBR, Type 0xC, StartLBA 0x20, BlocksNum 0x1DD17E0 17:20:26.0634 5724 ============================================================ 17:20:26.0669 5724 C: <-> \Device\Harddisk0\DR0\Partition1 17:20:26.0670 5724 ============================================================ 17:20:26.0670 5724 Initialize success 17:20:26.0670 5724 ============================================================ 17:20:33.0256 1088 ============================================================ 17:20:33.0256 1088 Scan started 17:20:33.0256 1088 Mode: Manual; 17:20:33.0256 1088 ============================================================ 17:20:34.0364 1088 ================ Scan system memory ======================== 17:20:34.0364 1088 System memory - ok 17:20:34.0365 1088 ================ Scan services ============================= 17:20:34.0627 1088 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 17:20:34.0631 1088 1394ohci - ok 17:20:34.0679 1088 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys 17:20:34.0684 1088 ACPI - ok 17:20:34.0747 1088 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 17:20:34.0749 1088 AcpiPmi - ok 17:20:34.0960 1088 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe 17:20:34.0969 1088 AdobeARMservice - ok 17:20:35.0063 1088 [ 424877CB9D5517F980FF7BACA2EB379D ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 17:20:35.0068 1088 AdobeFlashPlayerUpdateSvc - ok 17:20:35.0127 1088 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 17:20:35.0135 1088 adp94xx - ok 17:20:35.0203 1088 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 17:20:35.0211 1088 adpahci - ok 17:20:35.0241 1088 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 17:20:35.0245 1088 adpu320 - ok 17:20:35.0279 1088 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 17:20:35.0281 1088 AeLookupSvc - ok 17:20:35.0390 1088 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys 17:20:35.0397 1088 AFD - ok 17:20:35.0466 1088 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys 17:20:35.0468 1088 agp440 - ok 17:20:35.0519 1088 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys 17:20:35.0522 1088 aic78xx - ok 17:20:35.0569 1088 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe 17:20:35.0571 1088 ALG - ok 17:20:35.0600 1088 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys 17:20:35.0602 1088 aliide - ok 17:20:35.0634 1088 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys 17:20:35.0637 1088 amdagp - ok 17:20:35.0656 1088 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys 17:20:35.0657 1088 amdide - ok 17:20:35.0689 1088 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 17:20:35.0691 1088 AmdK8 - ok 17:20:35.0703 1088 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 17:20:35.0705 1088 AmdPPM - ok 17:20:35.0768 1088 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys 17:20:35.0771 1088 amdsata - ok 17:20:35.0820 1088 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 17:20:35.0824 1088 amdsbs - ok 17:20:35.0853 1088 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys 17:20:35.0855 1088 amdxata - ok 17:20:35.0902 1088 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys 17:20:35.0904 1088 AppID - ok 17:20:35.0958 1088 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll 17:20:35.0960 1088 AppIDSvc - ok 17:20:36.0005 1088 [ FB1959012294D6AD43E5304DF65E3C26 ] Appinfo C:\Windows\System32\appinfo.dll 17:20:36.0037 1088 Appinfo - ok 17:20:36.0229 1088 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 17:20:36.0238 1088 Apple Mobile Device - ok 17:20:36.0341 1088 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll 17:20:36.0345 1088 AppMgmt - ok 17:20:36.0582 1088 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys 17:20:36.0585 1088 arc - ok 17:20:36.0619 1088 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 17:20:36.0622 1088 arcsas - ok 17:20:36.0644 1088 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 17:20:36.0646 1088 AsyncMac - ok 17:20:36.0738 1088 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys 17:20:36.0738 1088 atapi - ok 17:20:36.0863 1088 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 17:20:36.0873 1088 AudioEndpointBuilder - ok 17:20:36.0895 1088 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll 17:20:36.0899 1088 Audiosrv - ok 17:20:36.0982 1088 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll 17:20:36.0984 1088 AxInstSV - ok 17:20:37.0062 1088 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys 17:20:37.0071 1088 b06bdrv - ok 17:20:37.0144 1088 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys 17:20:37.0149 1088 b57nd60x - ok 17:20:37.0223 1088 [ EB7C2DADF52F50F69F198C14C3556DC1 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl6.sys 17:20:37.0299 1088 BCM43XX - ok 17:20:37.0333 1088 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll 17:20:37.0336 1088 BDESVC - ok 17:20:37.0352 1088 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys 17:20:37.0354 1088 Beep - ok 17:20:37.0434 1088 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll 17:20:37.0452 1088 BFE - ok 17:20:37.0515 1088 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\System32\qmgr.dll 17:20:37.0595 1088 BITS - ok 17:20:37.0606 1088 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 17:20:37.0608 1088 blbdrive - ok 17:20:37.0702 1088 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 17:20:37.0710 1088 Bonjour Service - ok 17:20:37.0793 1088 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 17:20:37.0795 1088 bowser - ok 17:20:37.0830 1088 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 17:20:37.0832 1088 BrFiltLo - ok 17:20:37.0844 1088 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 17:20:37.0845 1088 BrFiltUp - ok 17:20:37.0893 1088 [ 77361D72A04F18809D0EFB6CCEB74D4B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys 17:20:37.0896 1088 BridgeMP - ok 17:20:37.0949 1088 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll 17:20:37.0952 1088 Browser - ok 17:20:38.0009 1088 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys 17:20:38.0014 1088 Brserid - ok 17:20:38.0030 1088 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 17:20:38.0033 1088 BrSerWdm - ok 17:20:38.0051 1088 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 17:20:38.0052 1088 BrUsbMdm - ok 17:20:38.0065 1088 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 17:20:38.0067 1088 BrUsbSer - ok 17:20:38.0122 1088 [ 2865A5C8E98C70C605F417908CEBB3A4 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys 17:20:38.0125 1088 BthEnum - ok 17:20:38.0254 1088 [ D8ABBCB42C550FD3A29DEC6DAABD0A87 ] BthFilterHelper C:\Program Files\CSR\Vista Profile Pack\BthFilterHelper.exe 17:20:38.0390 1088 BthFilterHelper - ok 17:20:38.0442 1088 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 17:20:38.0444 1088 BTHMODEM - ok 17:20:38.0482 1088 [ AD1872E5829E8A2C3B5B4B641C3EAB0E ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys 17:20:38.0485 1088 BthPan - ok 17:20:38.0536 1088 [ 1153DE2E4F5941E10C399CB5592F78A1 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys 17:20:38.0543 1088 BTHPORT - ok 17:20:38.0580 1088 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll 17:20:38.0583 1088 bthserv - ok 17:20:38.0613 1088 [ C81E9413A25A439F436B1D4B6A0CF9E9 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys 17:20:38.0615 1088 BTHUSB - ok 17:20:38.0794 1088 catchme - ok 17:20:38.0923 1088 [ ED5411A69C5BAC78D245C893AF64352A ] cbVSCService C:\Program Files\Cobian Backup 10\cbVSCService.exe 17:20:38.0996 1088 cbVSCService - ok 17:20:39.0041 1088 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 17:20:39.0043 1088 cdfs - ok 17:20:39.0120 1088 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 17:20:39.0123 1088 cdrom - ok 17:20:39.0177 1088 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll 17:20:39.0179 1088 CertPropSvc - ok 17:20:39.0213 1088 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys 17:20:39.0215 1088 circlass - ok 17:20:39.0305 1088 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys 17:20:39.0310 1088 CLFS - ok 17:20:39.0374 1088 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 17:20:39.0377 1088 clr_optimization_v2.0.50727_32 - ok 17:20:39.0532 1088 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 17:20:39.0536 1088 clr_optimization_v4.0.30319_32 - ok 17:20:39.0574 1088 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 17:20:39.0575 1088 CmBatt - ok 17:20:39.0598 1088 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys 17:20:39.0600 1088 cmdide - ok 17:20:39.0642 1088 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys 17:20:39.0649 1088 CNG - ok 17:20:39.0754 1088 [ 06302EA7EDA9DCDD7F82CEC2A03D2015 ] CobianBackup10 C:\Program Files\Cobian Backup 10\cbService.exe 17:20:40.0669 1088 CobianBackup10 - ok 17:20:40.0716 1088 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 17:20:40.0717 1088 Compbatt - ok 17:20:40.0798 1088 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 17:20:40.0800 1088 CompositeBus - ok 17:20:40.0815 1088 COMSysApp - ok 17:20:40.0879 1088 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 17:20:40.0880 1088 crcdisk - ok 17:20:41.0002 1088 [ E811AA921C33005B310826B8562161AC ] CrossLoopService C:\Users\Dave\AppData\Local\CrossLoop\CrossLoopService.exe 17:20:41.0387 1088 CrossLoopService - ok 17:20:41.0458 1088 [ 96C0E38905CFD788313BE8E11DAE3F2F ] CryptSvc C:\Windows\system32\cryptsvc.dll 17:20:41.0462 1088 CryptSvc - ok 17:20:41.0537 1088 [ 3C2177A897B4CA2788C6FB0C3FD81D4B ] CSC C:\Windows\system32\drivers\csc.sys 17:20:41.0544 1088 CSC - ok 17:20:41.0625 1088 [ 15F93B37F6801943360D9EB42485D5D3 ] CscService C:\Windows\System32\cscsvc.dll 17:20:41.0643 1088 CscService - ok 17:20:41.0708 1088 [ 8E1945984E147562F9F08E1D344A69CC ] CSRBC C:\Windows\system32\Drivers\csrbcxp.sys 17:20:41.0709 1088 CSRBC - ok 17:20:41.0759 1088 [ 7CAAF4AF453EF3582FEF65DD72CAA0AA ] dc3d C:\Windows\system32\DRIVERS\dc3d.sys 17:20:41.0761 1088 dc3d - ok 17:20:41.0807 1088 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll 17:20:41.0827 1088 DcomLaunch - ok 17:20:41.0865 1088 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll 17:20:41.0871 1088 defragsvc - ok 17:20:41.0927 1088 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 17:20:41.0930 1088 DfsC - ok 17:20:41.0957 1088 dgderdrv - ok 17:20:42.0096 1088 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll 17:20:42.0155 1088 Dhcp - ok 17:20:42.0201 1088 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys 17:20:42.0202 1088 discache - ok 17:20:42.0237 1088 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys 17:20:42.0239 1088 Disk - ok 17:20:42.0291 1088 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll 17:20:42.0295 1088 Dnscache - ok 17:20:42.0339 1088 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll 17:20:42.0344 1088 dot3svc - ok 17:20:42.0398 1088 [ B5E479EB83707DD698F66953E922042C ] dot4 C:\Windows\system32\DRIVERS\Dot4.sys 17:20:42.0402 1088 dot4 - ok 17:20:42.0486 1088 [ CAEFD09B6A6249C53A67D55A9A9FCABF ] Dot4Print C:\Windows\system32\DRIVERS\Dot4Prt.sys 17:20:42.0488 1088 Dot4Print - ok 17:20:42.0525 1088 [ 9F7DE667C505CE6500BECDD8E11644D7 ] Dot4Scan C:\Windows\system32\DRIVERS\Dot4Scan.sys 17:20:42.0526 1088 Dot4Scan - ok 17:20:42.0553 1088 [ CF491FF38D62143203C065260567E2F7 ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys 17:20:42.0555 1088 dot4usb - ok 17:20:42.0614 1088 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll 17:20:42.0618 1088 DPS - ok 17:20:42.0691 1088 [ F7BDA38AFBDA04F0A89DEBA767EEDA79 ] DragonSvc C:\Program Files\Common Files\Nuance\dgnsvc.exe 17:20:42.0697 1088 DragonSvc - ok 17:20:42.0727 1088 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 17:20:42.0729 1088 drmkaud - ok 17:20:42.0788 1088 [ 23F5D28378A160352BA8F817BD8C71CB ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 17:20:42.0809 1088 DXGKrnl - ok 17:20:42.0852 1088 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll 17:20:42.0856 1088 EapHost - ok 17:20:42.0984 1088 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys 17:20:43.0086 1088 ebdrv - ok 17:20:43.0138 1088 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe 17:20:43.0141 1088 EFS - ok 17:20:43.0543 1088 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 17:20:43.0560 1088 ehRecvr - ok 17:20:43.0628 1088 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe 17:20:43.0631 1088 ehSched - ok 17:20:43.0680 1088 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 17:20:43.0698 1088 elxstor - ok 17:20:43.0764 1088 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys 17:20:43.0766 1088 ErrDev - ok 17:20:43.0926 1088 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll 17:20:43.0938 1088 EventSystem - ok 17:20:43.0980 1088 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys 17:20:43.0984 1088 exfat - ok 17:20:44.0003 1088 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys 17:20:44.0007 1088 fastfat - ok 17:20:44.0170 1088 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe 17:20:44.0190 1088 Fax - ok 17:20:44.0228 1088 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys 17:20:44.0229 1088 fdc - ok 17:20:44.0310 1088 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll 17:20:44.0312 1088 fdPHost - ok 17:20:44.0349 1088 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll 17:20:44.0351 1088 FDResPub - ok 17:20:44.0450 1088 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 17:20:44.0452 1088 FileInfo - ok 17:20:44.0518 1088 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 17:20:44.0520 1088 Filetrace - ok 17:20:44.0628 1088 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 17:20:44.0630 1088 flpydisk - ok 17:20:44.0679 1088 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 17:20:44.0684 1088 FltMgr - ok 17:20:44.0790 1088 [ B3A5EC6B6B6673DB7E87C2BCDBDDC074 ] FontCache C:\Windows\system32\FntCache.dll 17:20:44.0824 1088 FontCache - ok 17:20:44.0971 1088 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 17:20:44.0973 1088 FontCache3.0.0.0 - ok 17:20:45.0049 1088 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 17:20:45.0051 1088 FsDepends - ok 17:20:45.0189 1088 [ B07663A810E861EEBFD0EAC7E82CA62D ] FsUsbExDisk C:\Windows\system32\FsUsbExDisk.SYS 17:20:45.0192 1088 FsUsbExDisk - ok 17:20:45.0343 1088 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 17:20:45.0344 1088 Fs_Rec - ok 17:20:45.0583 1088 [ 8A73E79089B282100B9393B644CB853B ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 17:20:45.0586 1088 fvevol - ok 17:20:45.0633 1088 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 17:20:45.0635 1088 gagp30kx - ok 17:20:45.0744 1088 [ 185ADA973B5020655CEE342059A86CBB ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 17:20:45.0746 1088 GEARAspiWDM - ok 17:20:45.0997 1088 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll 17:20:46.0016 1088 gpsvc - ok 17:20:46.0216 1088 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe 17:20:46.0219 1088 gupdate - ok 17:20:46.0272 1088 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe 17:20:46.0273 1088 gupdatem - ok 17:20:46.0342 1088 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 17:20:46.0347 1088 gusvc - ok 17:20:46.0390 1088 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 17:20:46.0392 1088 hcw85cir - ok 17:20:46.0451 1088 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 17:20:46.0457 1088 HdAudAddService - ok 17:20:46.0492 1088 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 17:20:46.0494 1088 HDAudBus - ok 17:20:46.0519 1088 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 17:20:46.0521 1088 HidBatt - ok 17:20:46.0542 1088 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 17:20:46.0545 1088 HidBth - ok 17:20:46.0583 1088 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 17:20:46.0585 1088 HidIr - ok 17:20:46.0621 1088 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\System32\hidserv.dll 17:20:46.0624 1088 hidserv - ok 17:20:46.0663 1088 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 17:20:46.0664 1088 HidUsb - ok 17:20:46.0723 1088 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll 17:20:46.0727 1088 hkmsvc - ok 17:20:46.0778 1088 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll 17:20:46.0784 1088 HomeGroupListener - ok 17:20:46.0835 1088 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 17:20:46.0841 1088 HomeGroupProvider - ok 17:20:46.0935 1088 [ D1E9CB573A9EDF7BE12E9C57F32E97F7 ] HP LaserJet Service C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe 17:20:46.0988 1088 HP LaserJet Service - ok 17:20:47.0045 1088 [ 299683D4C8AAA3F6F5D5D226A1782A6E ] HPFXBULK C:\Windows\system32\drivers\hpfxbulk.sys 17:20:47.0047 1088 HPFXBULK - ok 17:20:47.0116 1088 [ 6F98A555ACF3C1B68FCC1F50E0FD2091 ] HPFXBULKLEDM C:\Windows\system32\drivers\hppcbulkio.sys 17:20:47.0117 1088 HPFXBULKLEDM - ok 17:20:47.0158 1088 [ F728DB73A87231E27B6BA34D71CE2EDB ] HPFXFAX C:\Windows\system32\drivers\hpfxfax.sys 17:20:47.0160 1088 HPFXFAX - ok 17:20:47.0279 1088 [ 08457D8F8149757C70CEA59C71EC5D27 ] hpqcxs08 C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll 17:20:47.0323 1088 hpqcxs08 - ok 17:20:47.0361 1088 [ 75CC8C5146A3FB76221A7606628778D5 ] hpqddsvc C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll 17:20:47.0723 1088 hpqddsvc - ok 17:20:47.0800 1088 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 17:20:47.0802 1088 HpSAMD - ok 17:20:47.0899 1088 [ 83DB5DD8BE71CBA5447FBD7A48FDBEDA ] HPSLPSVC C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL 17:20:47.0948 1088 HPSLPSVC - ok 17:20:48.0018 1088 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys 17:20:48.0027 1088 HTTP - ok 17:20:48.0072 1088 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 17:20:48.0072 1088 hwpolicy - ok 17:20:48.0149 1088 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 17:20:48.0151 1088 i8042prt - ok 17:20:48.0212 1088 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 17:20:48.0220 1088 iaStorV - ok 17:20:48.0283 1088 [ 6F95324909B502E2651442C1548AB12F ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe 17:20:48.0286 1088 IDriverT - ok 17:20:48.0368 1088 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 17:20:48.0403 1088 idsvc - ok 17:20:48.0579 1088 [ 9467514EA189475A6E7FDC5D7BDE9D3F ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys 17:20:48.0705 1088 igfx - ok 17:20:48.0756 1088 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 17:20:48.0758 1088 iirsp - ok 17:20:48.0824 1088 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll 17:20:48.0847 1088 IKEEXT - ok 17:20:48.0891 1088 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys 17:20:48.0893 1088 intelide - ok 17:20:48.0912 1088 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 17:20:48.0914 1088 intelppm - ok 17:20:48.0945 1088 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll 17:20:48.0949 1088 IPBusEnum - ok 17:20:48.0967 1088 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 17:20:48.0969 1088 IpFilterDriver - ok 17:20:49.0023 1088 [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 17:20:49.0042 1088 iphlpsvc - ok 17:20:49.0095 1088 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 17:20:49.0098 1088 IPMIDRV - ok 17:20:49.0118 1088 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys 17:20:49.0121 1088 IPNAT - ok 17:20:49.0216 1088 [ E8A39D41474BE42FD8830CED32932D6C ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 17:20:49.0234 1088 iPod Service - ok 17:20:49.0270 1088 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys 17:20:49.0272 1088 IRENUM - ok 17:20:49.0313 1088 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys 17:20:49.0315 1088 isapnp - ok 17:20:49.0376 1088 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 17:20:49.0382 1088 iScsiPrt - ok 17:20:49.0414 1088 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 17:20:49.0416 1088 kbdclass - ok 17:20:49.0474 1088 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 17:20:49.0476 1088 kbdhid - ok 17:20:49.0486 1088 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe 17:20:49.0489 1088 KeyIso - ok 17:20:49.0541 1088 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 17:20:49.0544 1088 KSecDD - ok 17:20:49.0588 1088 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 17:20:49.0592 1088 KSecPkg - ok 17:20:49.0631 1088 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll 17:20:49.0639 1088 KtmRm - ok 17:20:49.0696 1088 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\System32\srvsvc.dll 17:20:49.0704 1088 LanmanServer - ok 17:20:49.0746 1088 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 17:20:49.0753 1088 LanmanWorkstation - ok 17:20:49.0869 1088 [ CC7D978C4F56FB434E841D35788A7F3C ] Lavasoft Ad-Aware Service C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe 17:20:49.0904 1088 Lavasoft Ad-Aware Service - ok 17:20:50.0042 1088 [ 3AF6B73A3AD1FC37C5933441F66CEB91 ] LBTServ C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe 17:20:50.0047 1088 LBTServ - ok 17:20:50.0105 1088 [ 7F9C7B28CF1C859E1C42619EEA946DC8 ] LHidFilt C:\Windows\system32\DRIVERS\LHidFilt.Sys 17:20:50.0107 1088 LHidFilt - ok 17:20:50.0183 1088 [ B716D4D759663BC4174FD0A379DA8E50 ] libusb0 C:\Windows\system32\DRIVERS\libusb0.sys 17:20:50.0185 1088 libusb0 - ok 17:20:50.0243 1088 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 17:20:50.0245 1088 lltdio - ok 17:20:50.0288 1088 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll 17:20:50.0295 1088 lltdsvc - ok 17:20:50.0310 1088 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll 17:20:50.0314 1088 lmhosts - ok 17:20:50.0340 1088 [ AB33792A87285344F43B5CE23421BAB0 ] LMouFilt C:\Windows\system32\DRIVERS\LMouFilt.Sys 17:20:50.0342 1088 LMouFilt - ok 17:20:50.0379 1088 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 17:20:50.0382 1088 LSI_FC - ok 17:20:50.0397 1088 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 17:20:50.0400 1088 LSI_SAS - ok 17:20:50.0419 1088 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 17:20:50.0421 1088 LSI_SAS2 - ok 17:20:50.0440 1088 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 17:20:50.0444 1088 LSI_SCSI - ok 17:20:50.0483 1088 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys 17:20:50.0485 1088 luafv - ok 17:20:50.0525 1088 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 17:20:50.0529 1088 Mcx2Svc - ok 17:20:50.0546 1088 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 17:20:50.0548 1088 megasas - ok 17:20:50.0579 1088 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 17:20:50.0584 1088 MegaSR - ok 17:20:50.0695 1088 Microsoft SharePoint Workspace Audit Service - ok 17:20:50.0730 1088 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll 17:20:50.0734 1088 MMCSS - ok 17:20:50.0752 1088 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys 17:20:50.0754 1088 Modem - ok 17:20:50.0786 1088 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 17:20:50.0814 1088 monitor - ok 17:20:50.0873 1088 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 17:20:50.0875 1088 mouclass - ok 17:20:50.0896 1088 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 17:20:50.0897 1088 mouhid - ok 17:20:50.0940 1088 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 17:20:50.0942 1088 mountmgr - ok 17:20:51.0012 1088 [ EE728AF83850DDAD9A3FCAC0AAB3AD97 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys 17:20:51.0017 1088 MpFilter - ok 17:20:51.0044 1088 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys 17:20:51.0047 1088 mpio - ok 17:20:51.0190 1088 [ A69630D039C38018689190234F866D77 ] MpKsl4d755c6d c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{3CB77CF7-542B-4AF1-9D5C-B90C4F449C44}\MpKsl4d755c6d.sys 17:20:51.0191 1088 MpKsl4d755c6d - ok 17:20:51.0221 1088 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 17:20:51.0223 1088 mpsdrv - ok 17:20:51.0360 1088 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll 17:20:51.0372 1088 MpsSvc - ok 17:20:51.0422 1088 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 17:20:51.0438 1088 MRxDAV - ok 17:20:51.0731 1088 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 17:20:51.0734 1088 mrxsmb - ok 17:20:51.0868 1088 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 17:20:51.0872 1088 mrxsmb10 - ok 17:20:51.0891 1088 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 17:20:51.0893 1088 mrxsmb20 - ok 17:20:51.0945 1088 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys 17:20:51.0947 1088 msahci - ok 17:20:51.0989 1088 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys 17:20:51.0992 1088 msdsm - ok 17:20:52.0013 1088 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe 17:20:52.0019 1088 MSDTC - ok 17:20:52.0074 1088 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys 17:20:52.0075 1088 Msfs - ok 17:20:52.0084 1088 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 17:20:52.0086 1088 mshidkmdf - ok 17:20:52.0132 1088 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 17:20:52.0134 1088 msisadrv - ok 17:20:52.0179 1088 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 17:20:52.0184 1088 MSiSCSI - ok 17:20:52.0191 1088 msiserver - ok 17:20:52.0207 1088 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 17:20:52.0209 1088 MSKSSRV - ok 17:20:52.0315 1088 [ E077FCA2A7E79FB9BF67D3E30B5CE593 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe 17:20:52.0316 1088 MsMpSvc - ok 17:20:52.0342 1088 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 17:20:52.0344 1088 MSPCLOCK - ok 17:20:52.0363 1088 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 17:20:52.0365 1088 MSPQM - ok 17:20:52.0387 1088 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 17:20:52.0391 1088 MsRPC - ok 17:20:52.0435 1088 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 17:20:52.0436 1088 mssmbios - ok 17:20:52.0548 1088 MSSQL$MSSMLBIZ - ok 17:20:52.0633 1088 [ 1D89EB4E2A99CABD4E81225F4F4C4B25 ] MSSQLServerADHelper c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe 17:20:52.0636 1088 MSSQLServerADHelper - ok 17:20:52.0650 1088 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 17:20:52.0652 1088 MSTEE - ok 17:20:52.0675 1088 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 17:20:52.0677 1088 MTConfig - ok 17:20:52.0693 1088 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys 17:20:52.0695 1088 Mup - ok 17:20:52.0747 1088 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll 17:20:52.0767 1088 napagent - ok 17:20:52.0808 1088 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 17:20:52.0813 1088 NativeWifiP - ok 17:20:52.0887 1088 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys 17:20:52.0910 1088 NDIS - ok 17:20:52.0932 1088 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 17:20:52.0934 1088 NdisCap - ok 17:20:52.0964 1088 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 17:20:52.0966 1088 NdisTapi - ok 17:20:53.0021 1088 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 17:20:53.0023 1088 Ndisuio - ok 17:20:53.0059 1088 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 17:20:53.0062 1088 NdisWan - ok 17:20:53.0116 1088 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 17:20:53.0118 1088 NDProxy - ok 17:20:53.0156 1088 [ A081CB6FB9A12668F233EB5414BE3A0E ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll 17:20:53.0160 1088 Net Driver HPZ12 - ok 17:20:53.0186 1088 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 17:20:53.0187 1088 NetBIOS - ok 17:20:53.0238 1088 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 17:20:53.0241 1088 NetBT - ok 17:20:53.0255 1088 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe 17:20:53.0258 1088 Netlogon - ok 17:20:53.0297 1088 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll 17:20:53.0305 1088 Netman - ok 17:20:53.0324 1088 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll 17:20:53.0343 1088 netprofm - ok 17:20:53.0386 1088 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 17:20:53.0391 1088 NetTcpPortSharing - ok 17:20:53.0424 1088 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 17:20:53.0426 1088 nfrd960 - ok 17:20:53.0517 1088 [ 2CD24A6AF497D0E9B9BF3DA924ED05E6 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys 17:20:53.0519 1088 NisDrv - ok 17:20:53.0573 1088 [ 3B846434055F80D9E89D0742F3ADAD34 ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe 17:20:53.0579 1088 NisSrv - ok 17:20:53.0637 1088 [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc C:\Windows\System32\nlasvc.dll 17:20:53.0644 1088 NlaSvc - ok 17:20:53.0676 1088 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys 17:20:53.0678 1088 Npfs - ok 17:20:53.0709 1088 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll 17:20:53.0713 1088 nsi - ok 17:20:53.0727 1088 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 17:20:53.0729 1088 nsiproxy - ok 17:20:53.0817 1088 [ 0D87503986BB3DFED58E343FE39DDE13 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 17:20:53.0852 1088 Ntfs - ok 17:20:54.0211 1088 [ CF7E041663119E09D2E118521ADA9300 ] NuidFltr C:\Windows\system32\DRIVERS\NuidFltr.sys 17:20:54.0213 1088 NuidFltr - ok 17:20:54.0235 1088 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys 17:20:54.0237 1088 Null - ok 17:20:54.0275 1088 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys 17:20:54.0278 1088 nvraid - ok 17:20:54.0337 1088 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys 17:20:54.0341 1088 nvstor - ok 17:20:54.0401 1088 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 17:20:54.0404 1088 nv_agp - ok 17:20:54.0444 1088 [ 634FF60F418792906887B3D6CEECB431 ] O2MDRDR C:\Windows\system32\DRIVERS\o2media.sys 17:20:54.0445 1088 O2MDRDR - ok 17:20:54.0471 1088 [ 86326062A90494BDD79CE383511D7D69 ] OEM13Vfx C:\Windows\system32\DRIVERS\OEM13Vfx.sys 17:20:54.0472 1088 OEM13Vfx - ok 17:20:54.0512 1088 [ 12539B57ED05DE7552403A12B3E0161C ] OEM13Vid C:\Windows\system32\DRIVERS\OEM13Vid.sys 17:20:54.0517 1088 OEM13Vid - ok 17:20:54.0564 1088 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 17:20:54.0567 1088 ohci1394 - ok 17:20:54.0610 1088 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 17:20:54.0617 1088 ose - ok 17:20:54.0786 1088 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 17:20:54.0910 1088 osppsvc - ok 17:20:54.0959 1088 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 17:20:54.0967 1088 p2pimsvc - ok 17:20:54.0983 1088 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll 17:20:54.0993 1088 p2psvc - ok 17:20:55.0026 1088 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys 17:20:55.0029 1088 Parport - ok 17:20:55.0080 1088 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys 17:20:55.0083 1088 partmgr - ok 17:20:55.0104 1088 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys 17:20:55.0106 1088 Parvdm - ok 17:20:55.0128 1088 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll 17:20:55.0134 1088 PcaSvc - ok 17:20:55.0155 1088 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys 17:20:55.0159 1088 pci - ok 17:20:55.0180 1088 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys 17:20:55.0182 1088 pciide - ok 17:20:55.0209 1088 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 17:20:55.0214 1088 pcmcia - ok 17:20:55.0237 1088 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys 17:20:55.0239 1088 pcw - ok 17:20:55.0305 1088 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys 17:20:55.0322 1088 PEAUTH - ok 17:20:55.0382 1088 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll 17:20:55.0418 1088 PeerDistSvc - ok 17:20:55.0518 1088 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll 17:20:55.0586 1088 pla - ok 17:20:55.0667 1088 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll 17:20:55.0686 1088 PlugPlay - ok 17:20:55.0735 1088 [ 65BC271F337637731D3C71455AE1F476 ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll 17:20:55.0739 1088 Pml Driver HPZ12 - ok 17:20:55.0772 1088 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 17:20:55.0776 1088 PNRPAutoReg - ok 17:20:55.0793 1088 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 17:20:55.0799 1088 PNRPsvc - ok 17:20:55.0858 1088 [ 896D916DE06F5502D301E8C4DC442AE8 ] Point32 C:\Windows\system32\DRIVERS\point32.sys 17:20:55.0860 1088 Point32 - ok 17:20:55.0912 1088 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 17:20:55.0920 1088 PolicyAgent - ok 17:20:55.0974 1088 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll 17:20:55.0980 1088 Power - ok 17:20:56.0021 1088 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 17:20:56.0024 1088 PptpMiniport - ok 17:20:56.0040 1088 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys 17:20:56.0043 1088 Processor - ok 17:20:56.0104 1088 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll 17:20:56.0111 1088 ProfSvc - ok 17:20:56.0124 1088 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe 17:20:56.0127 1088 ProtectedStorage - ok 17:20:56.0155 1088 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys 17:20:56.0157 1088 Psched - ok 17:20:56.0284 1088 [ 35DD92AF8B4EC79162A6A013884797AF ] QBCFMonitorService C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe 17:20:56.0296 1088 QBCFMonitorService - ok 17:20:56.0417 1088 [ 6BEE1814470DC12FA20C53DFC3C97EBB ] QBFCService C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe 17:20:56.0420 1088 QBFCService - ok 17:20:56.0481 1088 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 17:20:56.0527 1088 ql2300 - ok 17:20:56.0577 1088 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 17:20:56.0580 1088 ql40xx - ok 17:20:56.0627 1088 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll 17:20:56.0635 1088 QWAVE - ok 17:20:56.0647 1088 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 17:20:56.0649 1088 QWAVEdrv - ok 17:20:56.0724 1088 [ 8F97D374AD1857E1EED85A79F29A1D3D ] RapiMgr C:\Windows\WindowsMobile\rapimgr.dll 17:20:56.0728 1088 RapiMgr - ok 17:20:56.0744 1088 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 17:20:56.0746 1088 RasAcd - ok 17:20:56.0788 1088 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 17:20:56.0789 1088 RasAgileVpn - ok 17:20:56.0802 1088 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll 17:20:56.0808 1088 RasAuto - ok 17:20:56.0820 1088 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 17:20:56.0823 1088 Rasl2tp - ok 17:20:56.0873 1088 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll 17:20:56.0882 1088 RasMan - ok 17:20:56.0899 1088 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 17:20:56.0902 1088 RasPppoe - ok 17:20:56.0920 1088 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 17:20:56.0922 1088 RasSstp - ok 17:20:56.0980 1088 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 17:20:56.0985 1088 rdbss - ok 17:20:56.0997 1088 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 17:20:56.0999 1088 rdpbus - ok 17:20:57.0044 1088 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 17:20:57.0046 1088 RDPCDD - ok 17:20:57.0097 1088 [ B973FCFC50DC1434E1970A146F7E3885 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys 17:20:57.0101 1088 RDPDR - ok 17:20:57.0125 1088 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 17:20:57.0127 1088 RDPENCDD - ok 17:20:57.0150 1088 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 17:20:57.0151 1088 RDPREFMP - ok 17:20:57.0423 1088 [ 68A0387F58E226DEEE23D9715955572A ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys 17:20:57.0425 1088 RdpVideoMiniport - ok 17:20:57.0477 1088 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 17:20:57.0482 1088 RDPWD - ok 17:20:57.0555 1088 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 17:20:57.0559 1088 rdyboost - ok 17:20:57.0584 1088 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll 17:20:57.0589 1088 RemoteAccess - ok 17:20:57.0619 1088 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll 17:20:57.0625 1088 RemoteRegistry - ok 17:20:57.0649 1088 [ CB928D9E6DAF51879DD6BA8D02F01321 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys 17:20:57.0652 1088 RFCOMM - ok 17:20:57.0708 1088 [ F17713D108ACA124A139FDE877EEF68A ] RimUsb C:\Windows\system32\Drivers\RimUsb.sys 17:20:57.0710 1088 RimUsb - ok 17:20:57.0728 1088 [ 2C4FB2E9F039287767C384E46EE91030 ] RimVSerPort C:\Windows\system32\DRIVERS\RimSerial.sys 17:20:57.0730 1088 RimVSerPort - ok 17:20:57.0757 1088 [ 564297827D213F52C7A3A2FF749568CA ] ROOTMODEM C:\Windows\system32\Drivers\RootMdm.sys 17:20:57.0759 1088 ROOTMODEM - ok 17:20:57.0789 1088 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 17:20:57.0794 1088 RpcEptMapper - ok 17:20:57.0825 1088 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe 17:20:57.0828 1088 RpcLocator - ok 17:20:57.0874 1088 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll 17:20:57.0882 1088 RpcSs - ok 17:20:57.0909 1088 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 17:20:57.0911 1088 rspndr - ok 17:20:57.0959 1088 [ 7DFD48E24479B68B258D8770121155A0 ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys 17:20:57.0963 1088 RTL8167 - ok 17:20:58.0003 1088 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys 17:20:58.0005 1088 s3cap - ok 17:20:58.0015 1088 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe 17:20:58.0018 1088 SamSs - ok 17:20:58.0080 1088 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 17:20:58.0083 1088 sbp2port - ok 17:20:58.0136 1088 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll 17:20:58.0143 1088 SCardSvr - ok 17:20:58.0161 1088 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 17:20:58.0163 1088 scfilter - ok 17:20:58.0228 1088 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll 17:20:58.0262 1088 Schedule - ok 17:20:58.0303 1088 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll 17:20:58.0304 1088 SCPolicySvc - ok 17:20:58.0372 1088 [ 0328BE1C7F1CBA23848179F8762E391C ] sdbus C:\Windows\system32\drivers\sdbus.sys 17:20:58.0375 1088 sdbus - ok 17:20:58.0421 1088 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll 17:20:58.0428 1088 SDRSVC - ok 17:20:58.0467 1088 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys 17:20:58.0469 1088 secdrv - ok 17:20:58.0502 1088 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll 17:20:58.0507 1088 seclogon - ok 17:20:58.0542 1088 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\system32\sens.dll 17:20:58.0547 1088 SENS - ok 17:20:58.0582 1088 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll 17:20:58.0587 1088 SensrSvc - ok 17:20:58.0604 1088 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 17:20:58.0606 1088 Serenum - ok 17:20:58.0626 1088 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys 17:20:58.0629 1088 Serial - ok 17:20:58.0686 1088 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 17:20:58.0688 1088 sermouse - ok 17:20:58.0747 1088 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll 17:20:58.0754 1088 SessionEnv - ok 17:20:58.0790 1088 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 17:20:58.0792 1088 sffdisk - ok 17:20:58.0811 1088 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 17:20:58.0813 1088 sffp_mmc - ok 17:20:58.0828 1088 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 17:20:58.0830 1088 sffp_sd - ok 17:20:58.0847 1088 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 17:20:58.0849 1088 sfloppy - ok 17:20:58.0924 1088 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll 17:20:58.0931 1088 SharedAccess - ok 17:20:58.0954 1088 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 17:20:58.0964 1088 ShellHWDetection - ok 17:20:59.0019 1088 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys 17:20:59.0021 1088 sisagp - ok 17:20:59.0048 1088 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 17:20:59.0050 1088 SiSRaid2 - ok 17:20:59.0065 1088 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 17:20:59.0068 1088 SiSRaid4 - ok 17:20:59.0140 1088 [ 599F3715602F4CB09AD0FDC606E3B9D9 ] SIUSBXP C:\Windows\system32\drivers\SiUSBXp.sys 17:20:59.0142 1088 SIUSBXP - ok 17:20:59.0218 1088 [ A4FAB5F7818A69DA6E740943CB8F7CA9 ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe 17:20:59.0222 1088 SkypeUpdate - ok 17:20:59.0246 1088 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys 17:20:59.0249 1088 Smb - ok 17:20:59.0297 1088 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 17:20:59.0302 1088 SNMPTRAP - ok 17:20:59.0334 1088 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys 17:20:59.0336 1088 spldr - ok 17:20:59.0385 1088 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe 17:20:59.0404 1088 Spooler - ok 17:20:59.0497 1088 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe 17:20:59.0599 1088 sppsvc - ok 17:20:59.0637 1088 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll 17:20:59.0642 1088 sppuinotify - ok 17:20:59.0703 1088 [ 86EBD8B1F23E743AAD21F4D5B4D40985 ] SQLBrowser c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe 17:20:59.0710 1088 SQLBrowser - ok 17:20:59.0756 1088 [ D89083C4EB02DACA8F944B0E05E57F9D ] SQLWriter c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe 17:20:59.0758 1088 SQLWriter - ok 17:20:59.0823 1088 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys 17:20:59.0829 1088 srv - ok 17:20:59.0854 1088 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 17:20:59.0860 1088 srv2 - ok 17:20:59.0881 1088 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 17:20:59.0885 1088 srvnet - ok 17:20:59.0945 1088 [ 6D83FF6722BAF7E82A4521DBEC363E5A ] ssadbus C:\Windows\system32\DRIVERS\ssadbus.sys 17:20:59.0948 1088 ssadbus - ok 17:20:59.0991 1088 [ 5AE42E90F99749E0E35B9989A2D0275C ] ssadmdfl C:\Windows\system32\DRIVERS\ssadmdfl.sys 17:20:59.0993 1088 ssadmdfl - ok 17:21:00.0028 1088 [ 9285D8ABA50A4D6482B1574448F9EB76 ] ssadmdm C:\Windows\system32\DRIVERS\ssadmdm.sys 17:21:00.0031 1088 ssadmdm - ok 17:21:00.0096 1088 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 17:21:00.0104 1088 SSDPSRV - ok 17:21:00.0123 1088 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll 17:21:00.0134 1088 SstpSvc - ok 17:21:00.0167 1088 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 17:21:00.0169 1088 stexstor - ok 17:21:00.0217 1088 [ EDB05BD63148796F23EA78506404A538 ] StillCam C:\Windows\system32\DRIVERS\serscan.sys 17:21:00.0218 1088 StillCam - ok 17:21:00.0344 1088 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll 17:21:00.0366 1088 StiSvc - ok 17:21:00.0406 1088 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys 17:21:00.0408 1088 storflt - ok 17:21:00.0485 1088 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys 17:21:00.0487 1088 storvsc - ok 17:21:00.0531 1088 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys 17:21:00.0532 1088 swenum - ok 17:21:00.0578 1088 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll 17:21:00.0597 1088 swprv - ok 17:21:00.0604 1088 Synth3dVsc - ok 17:21:00.0675 1088 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll 17:21:00.0754 1088 SysMain - ok 17:21:00.0814 1088 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll 17:21:00.0820 1088 TabletInputService - ok 17:21:00.0858 1088 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll 17:21:00.0866 1088 TapiSrv - ok 17:21:00.0883 1088 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll 17:21:00.0888 1088 TBS - ok 17:21:00.0963 1088 [ E23A56F843E2AEBBB209D0ACCA73C640 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 17:21:01.0009 1088 Tcpip - ok 17:21:01.0056 1088 [ E23A56F843E2AEBBB209D0ACCA73C640 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 17:21:01.0069 1088 TCPIP6 - ok 17:21:01.0123 1088 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 17:21:01.0125 1088 tcpipreg - ok 17:21:01.0188 1088 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 17:21:01.0190 1088 TDPIPE - ok 17:21:01.0237 1088 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 17:21:01.0240 1088 TDTCP - ok 17:21:01.0285 1088 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 17:21:01.0288 1088 tdx - ok 17:21:01.0300 1088 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys 17:21:01.0302 1088 TermDD - ok 17:21:01.0355 1088 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll 17:21:01.0377 1088 TermService - ok 17:21:01.0410 1088 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll 17:21:01.0416 1088 Themes - ok 17:21:01.0427 1088 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll 17:21:01.0431 1088 THREADORDER - ok 17:21:01.0464 1088 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll 17:21:01.0470 1088 TrkWks - ok 17:21:01.0557 1088 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 17:21:01.0562 1088 TrustedInstaller - ok 17:21:01.0617 1088 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 17:21:01.0619 1088 tssecsrv - ok 17:21:01.0664 1088 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 17:21:01.0667 1088 TsUsbFlt - ok 17:21:01.0673 1088 tsusbhub - ok 17:21:01.0764 1088 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 17:21:01.0767 1088 tunnel - ok 17:21:01.0804 1088 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 17:21:01.0807 1088 uagp35 - ok 17:21:01.0856 1088 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys 17:21:01.0861 1088 udfs - ok 17:21:01.0900 1088 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe 17:21:01.0906 1088 UI0Detect - ok 17:21:01.0966 1088 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 17:21:01.0968 1088 uliagpkx - ok 17:21:02.0019 1088 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\drivers\umbus.sys 17:21:02.0021 1088 umbus - ok 17:21:02.0038 1088 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 17:21:02.0040 1088 UmPass - ok 17:21:02.0085 1088 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll 17:21:02.0093 1088 UmRdpService - ok 17:21:02.0118 1088 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll 17:21:02.0127 1088 upnphost - ok 17:21:02.0163 1088 [ 73B41F4EAD65F355962168D766AF0F2E ] USBAAPL C:\Windows\system32\Drivers\usbaapl.sys 17:21:02.0165 1088 USBAAPL - ok 17:21:02.0234 1088 [ 1D9F2BD026E8E2D45033A4DF3F16B78C ] usbaudio C:\Windows\system32\drivers\usbaudio.sys 17:21:02.0237 1088 usbaudio - ok 17:21:02.0278 1088 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 17:21:02.0280 1088 usbccgp - ok 17:21:02.0341 1088 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys 17:21:02.0344 1088 usbcir - ok 17:21:02.0385 1088 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 17:21:02.0387 1088 usbehci - ok 17:21:02.0413 1088 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 17:21:02.0418 1088 usbhub - ok 17:21:02.0438 1088 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\drivers\usbohci.sys 17:21:02.0440 1088 usbohci - ok 17:21:02.0485 1088 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 17:21:02.0488 1088 usbprint - ok 17:21:02.0514 1088 [ 576096CCBC07E7C4EA4F5E6686D6888F ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys 17:21:02.0516 1088 usbscan - ok 17:21:02.0541 1088 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 17:21:02.0542 1088 USBSTOR - ok 17:21:02.0559 1088 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 17:21:02.0560 1088 usbuhci - ok 17:21:02.0627 1088 [ 45F4E7BF43DB40A6C6B4D92C76CBC3F2 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys 17:21:02.0631 1088 usbvideo - ok 17:21:02.0666 1088 [ D82F43D15FDAA666856C0190CB73E7C9 ] usb_rndisx C:\Windows\system32\DRIVERS\usb8023x.sys 17:21:02.0668 1088 usb_rndisx - ok 17:21:02.0702 1088 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll 17:21:02.0708 1088 UxSms - ok 17:21:02.0718 1088 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe 17:21:02.0721 1088 VaultSvc - ok 17:21:02.0755 1088 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 17:21:02.0757 1088 vdrvroot - ok 17:21:02.0810 1088 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe 17:21:02.0830 1088 vds - ok 17:21:02.0866 1088 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 17:21:02.0868 1088 vga - ok 17:21:02.0876 1088 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys 17:21:02.0878 1088 VgaSave - ok 17:21:02.0900 1088 VGPU - ok 17:21:02.0955 1088 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 17:21:02.0960 1088 vhdmp - ok 17:21:03.0001 1088 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys 17:21:03.0003 1088 viaagp - ok 17:21:03.0028 1088 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys 17:21:03.0031 1088 ViaC7 - ok 17:21:03.0081 1088 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys 17:21:03.0083 1088 viaide - ok 17:21:03.0136 1088 [ C2F2911156FDC7817C52829C86DA494E ] vmbus C:\Windows\system32\drivers\vmbus.sys 17:21:03.0141 1088 vmbus - ok 17:21:03.0162 1088 [ D4D77455211E204F370D08F4963063CE ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys 17:21:03.0164 1088 VMBusHID - ok 17:21:03.0180 1088 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys 17:21:03.0182 1088 volmgr - ok 17:21:03.0205 1088 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 17:21:03.0211 1088 volmgrx - ok 17:21:03.0304 1088 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys 17:21:03.0309 1088 volsnap - ok 17:21:03.0344 1088 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 17:21:03.0349 1088 vsmraid - ok 17:21:03.0418 1088 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe 17:21:03.0453 1088 VSS - ok 17:21:03.0491 1088 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 17:21:03.0493 1088 vwifibus - ok 17:21:03.0509 1088 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 17:21:03.0512 1088 vwififlt - ok 17:21:03.0543 1088 [ A3F04CBEA6C2A10E6CB01F8B47611882 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys 17:21:03.0545 1088 vwifimp - ok 17:21:03.0581 1088 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll 17:21:03.0602 1088 W32Time - ok 17:21:03.0643 1088 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 17:21:03.0646 1088 WacomPen - ok 17:21:03.0699 1088 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 17:21:03.0702 1088 WANARP - ok 17:21:03.0709 1088 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 17:21:03.0711 1088 Wanarpv6 - ok 17:21:03.0821 1088 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 17:21:03.0868 1088 WatAdminSvc - ok 17:21:03.0942 1088 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe 17:21:03.0989 1088 wbengine - ok 17:21:04.0020 1088 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 17:21:04.0028 1088 WbioSrvc - ok 17:21:04.0074 1088 [ 59E19BD13C3BDB857646B9E436BA27F7 ] WcesComm C:\Windows\WindowsMobile\wcescomm.dll 17:21:04.0081 1088 WcesComm - ok 17:21:04.0132 1088 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll 17:21:04.0141 1088 wcncsvc - ok 17:21:04.0153 1088 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 17:21:04.0159 1088 WcsPlugInService - ok 17:21:04.0184 1088 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys 17:21:04.0186 1088 Wd - ok 17:21:04.0243 1088 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 17:21:04.0262 1088 Wdf01000 - ok 17:21:04.0282 1088 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll 17:21:04.0289 1088 WdiServiceHost - ok 17:21:04.0295 1088 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll 17:21:04.0301 1088 WdiSystemHost - ok 17:21:04.0344 1088 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll 17:21:04.0352 1088 WebClient - ok 17:21:04.0366 1088 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll 17:21:04.0374 1088 Wecsvc - ok 17:21:04.0397 1088 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll 17:21:04.0403 1088 wercplsupport - ok 17:21:04.0426 1088 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll 17:21:04.0433 1088 WerSvc - ok 17:21:04.0467 1088 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 17:21:04.0469 1088 WfpLwf - ok 17:21:04.0490 1088 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys 17:21:04.0492 1088 WIMMount - ok 17:21:04.0567 1088 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll 17:21:04.0591 1088 WinDefend - ok 17:21:04.0611 1088 WinHttpAutoProxySvc - ok 17:21:04.0695 1088 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 17:21:04.0699 1088 Winmgmt - ok 17:21:04.0776 1088 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll 17:21:04.0834 1088 WinRM - ok 17:21:04.0920 1088 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\Windows\system32\DRIVERS\WinUSB.sys 17:21:04.0922 1088 WinUsb - ok 17:21:04.0970 1088 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll 17:21:05.0004 1088 Wlansvc - ok 17:21:05.0097 1088 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 17:21:05.0119 1088 WmiAcpi - ok 17:21:05.0234 1088 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 17:21:05.0238 1088 wmiApSrv - ok 17:21:05.0331 1088 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe 17:21:05.0366 1088 WMPNetworkSvc - ok 17:21:05.0411 1088 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll 17:21:05.0416 1088 WPCSvc - ok 17:21:05.0458 1088 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 17:21:05.0465 1088 WPDBusEnum - ok 17:21:05.0493 1088 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 17:21:05.0494 1088 ws2ifsl - ok 17:21:05.0512 1088 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\system32\wscsvc.dll 17:21:05.0518 1088 wscsvc - ok 17:21:05.0525 1088 WSearch - ok 17:21:05.0653 1088 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll 17:21:05.0711 1088 wuauserv - ok 17:21:05.0752 1088 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 17:21:05.0755 1088 WudfPf - ok 17:21:05.0791 1088 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 17:21:05.0797 1088 WUDFRd - ok 17:21:05.0909 1088 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 17:21:05.0915 1088 wudfsvc - ok 17:21:05.0979 1088 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll 17:21:05.0988 1088 WwanSvc - ok 17:21:06.0116 1088 [ A5B3BC640C593C455A8E1E7636071F9D ] Zoho Assist C:\Users\Dave\Documents\ZohoMeeting\ZohoMeeting.exe 17:21:06.0643 1088 Zoho Assist - ok 17:21:06.0754 1088 ================ Scan global =============================== 17:21:06.0800 1088 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll 17:21:06.0849 1088 [ D70FE45855CAD4C0C6B1C1426ABDEBA9 ] C:\Windows\system32\winsrv.dll 17:21:06.0872 1088 [ D70FE45855CAD4C0C6B1C1426ABDEBA9 ] C:\Windows\system32\winsrv.dll 17:21:06.0915 1088 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll 17:21:06.0952 1088 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe 17:21:06.0964 1088 [Global] - ok 17:21:06.0966 1088 ================ Scan MBR ================================== 17:21:06.0982 1088 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 17:21:07.0262 1088 \Device\Harddisk0\DR0 - ok 17:21:07.0269 1088 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk1\DR1 17:21:07.0277 1088 \Device\Harddisk1\DR1 - ok 17:21:07.0278 1088 ================ Scan VBR ================================== 17:21:07.0282 1088 [ 95D292FE809D133CFD28501D835D77DF ] \Device\Harddisk0\DR0\Partition1 17:21:07.0284 1088 \Device\Harddisk0\DR0\Partition1 - ok 17:21:07.0292 1088 [ 6EA0EF5035FF2673E7F404A60EF1DC35 ] \Device\Harddisk1\DR1\Partition1 17:21:07.0294 1088 \Device\Harddisk1\DR1\Partition1 - ok 17:21:07.0295 1088 ============================================================ 17:21:07.0295 1088 Scan finished 17:21:07.0295 1088 ============================================================ 17:21:07.0315 7860 Detected object count: 0 17:21:07.0316 7860 Actual detected object count: 0
[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.



I see you have Malwarebytes already on your machine. Please run it by right-clicking and choosing Run as Administrator on the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.



This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.


Go here to run an online scannner from ESET.
  • Note: For browsers other than Internet Explorer, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.

If it doesn't find anything there will be no log to post.
Hi, I have to send this a bit early as I'm leaving out of town for a week and not bringing my computer. I will finish up your tasks when I return. Thank you very much! Dave ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.6.2 (02.02.2013:2) OS: Windows 7 Ultimate x86 Ran by [removed] on Mon 02/11/2013 at 21:51:15.81 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully deleted: [Registry Value] hkey_current_user\software\microsoft\internet explorer\urlsearchhooks\\{ef99bd32-c1fb-11d2-892f-0090271d4f88} Successfully deleted: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\toolbar\\{ef99bd32-c1fb-11d2-892f-0090271d4f88} Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{0633ee93-d776-472f-a0ff-e1416b8b2e3a}\\DisplayName Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{0633ee93-d776-472f-a0ff-e1416b8b2e3a}\\URL ~~~ Registry Keys Successfully deleted: [Registry Key] hkey_current_user\software\1clickdownload Successfully deleted: [Registry Key] hkey_local_machine\software\babylon Successfully deleted: [Registry Key] hkey_current_user\software\conduit Successfully deleted: [Registry Key] hkey_local_machine\software\conduit Successfully deleted: [Registry Key] hkey_local_machine\software\freeze.com Successfully deleted: [Registry Key] hkey_local_machine\software\iminent Successfully deleted: [Registry Key] hkey_current_user\software\softonic Successfully deleted: [Registry Key] hkey_current_user\software\sweetim Successfully deleted: [Registry Key] hkey_local_machine\software\sweetim Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\conduit Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\conduitsearchscopes Successfully deleted: [Registry Key] hkey_current_user\software\appdatalow\software\smartbar Successfully deleted: [Registry Key] hkey_local_machine\software\classes\appid\escort.dll Successfully deleted: [Registry Key] hkey_local_machine\software\classes\prod.cap Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\mybabylontb_rasapi32 Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\tracing\mybabylontb_rasmancs Successfully deleted: [Registry Key-Heur] HKEY_LOCAL_MACHINE\software\classes\Toolbar.CT3220468 Successfully deleted: [Registry Key] hkey_classes_root\clsid\{02478d38-c3f9-4efb-9b51-7695eca05670} Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{02478d38-c3f9-4efb-9b51-7695eca05670} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{2eecd738-5844-4a99-b4b6-146bf802613b} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{3c471948-f874-49f5-b338-4f214a2ee0b1} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{e46c8196-b634-44a1-af6e-957c64278ab1} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{ef99bd32-c1fb-11d2-892f-0090271d4f88} Successfully deleted: [Registry Key] hkey_classes_root\clsid\{F9E78825-7C02-AA49-74D9-0D62DA67A447} Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{F9E78825-7C02-AA49-74D9-0D62DA67A447} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\babylon" Successfully deleted: [Folder] "C:\ProgramData\installmate" Successfully deleted: [Folder] "C:\ProgramData\saveas" Successfully deleted: [Folder] "C:\ProgramData\tarma installer" Successfully deleted: [Folder] "C:\Users\Dave\AppData\Roaming\babylon" Successfully deleted: [Folder] "C:\Users\Dave\AppData\Roaming\opencandy" Successfully deleted: [Folder] "C:\Users\Dave\appdata\local\babylon" Successfully deleted: [Folder] "C:\Users\Dave\appdata\local\blekkotb" Successfully deleted: [Folder] "C:\Users\Dave\appdata\local\conduit" Successfully deleted: [Folder] "C:\Users\Dave\appdata\local\opencandy" Successfully deleted: [Folder] "C:\Users\Dave\appdata\locallow\conduit" Successfully deleted: [Folder] "C:\Program Files\conduit" Successfully deleted: [Folder] "C:\Program Files\fbphotozoom" Successfully deleted: [Folder] "C:\Program Files\free offers from freeze.com" Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\saveas" Successfully deleted: [Folder] "C:\Program Files\ask.com" ~~~ FireFox Successfully deleted: [File] C:\user.js Successfully deleted: [File] "C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml" Successfully deleted: [File] "C:\Program Files\Mozilla Firefox\searchplugins\blekkotb.xml" Successfully deleted: [File] C:\Users\Dave\AppData\Roaming\mozilla\firefox\profiles\qln39cgr.default\user.js Successfully deleted: [File] C:\Users\Dave\AppData\Roaming\mozilla\firefox\profiles\qln39cgr.default\searchplugins\askcom.xml Successfully deleted: [File] C:\Users\Dave\AppData\Roaming\mozilla\firefox\profiles\qln39cgr.default\searchplugins\conduit.xml Successfully deleted: [Folder] C:\Users\Dave\AppData\Roaming\mozilla\firefox\profiles\qln39cgr.default\extensions\[removed] Successfully deleted the following from C:\Users\Dave\AppData\Roaming\mozilla\firefox\profiles\qln39cgr.default\prefs.js user_pref("Smartbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3220468&SearchSource=13"); user_pref("Smartbar.ConduitSearchEngineList", "uTorrentControl_v2 Customized Web Search"); user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3220468&SearchSource=2&q="); user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://search.babylon.com/?AF=109221&babsrc=adbartrp&mntrId=c885e5da000000000000002186cb341c&q="); user_pref("Smartbar.keywordURLSelectedCTID", "CT3220468"); user_pref("browser.babylon.HPOnNewTab", "search.babylon.com"); user_pref("browser.search.defaultengine", "Ask.com"); user_pref("browser.search.defaultenginename", "Search the web (Babylon)"); user_pref("browser.search.order.1", "Search the web (Babylon)"); user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?ctid=CT3220468&SearchSource=13"); user_pref("de.soerenrinne.googlebuttons.userlist", "Mail,Mail - Gmail this,Maps,Reader,Scholar,Wave,Web Search,YouTube,Google Shortcuts Settings,Android Market Developer Conso user_pref("extensions.50d3fda10f8d3.scode", "(function(){try{if('aol.com,mail.google.com,premiumreports.info,search.babylon.com,search.gboxap p.com'.indexOf(window.self.locatio user_pref("extensions.BabylonToolbar_i.aflt", "babsst"); user_pref("extensions.BabylonToolbar_i.babExt", ""); user_pref("extensions.BabylonToolbar_i.babTrack", "affID=109221"); user_pref("extensions.BabylonToolbar_i.hardId", "c885e5da000000000000002186cb341c"); user_pref("extensions.BabylonToolbar_i.id", "c885e5da000000000000002186cb341c"); user_pref("extensions.BabylonToolbar_i.instlDay", "15405"); user_pref("extensions.BabylonToolbar_i.instlRef", "sst"); user_pref("extensions.BabylonToolbar_i.newTab", true); user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://search.babylon.com/?AF=109221&babsrc=NT_ss&mntrId=c885e5da000000000000002186cb341c"); user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar"); user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon"); user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); user_pref("extensions.BabylonToolbar_i.tlbrId", "base"); user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17"); user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1717:20:10"); user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17"); user_pref("extensions.enabledItems", "{5C46D283-ABDE-4dce-B83C-08881401921C}:2.1.5,[removed]:0.9.8.0,{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20,{CAFEEFAC-00 user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3220468&SearchSource=2&q="); Emptied folder: C:\Users\Dave\AppData\Roaming\mozilla\firefox\profiles\qln39cgr.default\minidumps [34 files] ~~~ Chrome Successfully deleted: [Registry Key] hkey_current_user\software\google\chrome\extensions\ejpbbhjlbipncjklfjjaedaieimbmdda Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\ejpbbhjlbipncjklfjjaedaieimbmdda Successfully deleted: [Registry Key] hkey_local_machine\software\google\chrome\extensions\pmlghpafmmnmmkjdhacccolfgnkiboco ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Mon 02/11/2013 at 21:56:10.93 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.02.12.02 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 9.0.8112.16421 Dave :: DAVE-PC [administrator] 2/11/2013 10:03:58 PM mbam-log-2013-02-11 (22-03-58).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 261317 Time elapsed: 19 minute(s), 35 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 3 C:\Users\Dave\Documents\Downloads\dp_genius.exe (PUP.Adware.Agent) -> Quarantined and deleted successfully. C:\Users\Dave\Downloads\SaveAs.exe (PUP.Offerware) -> Quarantined and deleted successfully. C:\Users\Dave\Downloads\The_Who_-_Discography_(Mp3@320Kbps).exe (PUP.Adware.Agent) -> Quarantined and deleted successfully. (end)
Hi, I'm back in town. I guess the ESET scanner didn't find anything. Here is the log: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK The PC is still running slow. I wonder what the issue is. Your help is greatly appreciated!! Dave
Given that our tools aren't seeing the malware, I suspect we have a zero access infection, which may be a bit more complicated to clear up, but let's give Combofix a try and just see if we get any relief from the ads and the slowness. It's possible it's just something hiding in a place we haven't looked yet. If it does happen to be one of the more stubborn zero access variants, then it can be difficult to "see" with tools, and we may have to attack it a bit differently, but that just takes a bit of patience is all :)


Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing anything, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

If you have a problem launching programs after running Combofix, please do not panic! Simply reboot the computer and all should be fine.

Please be sure to tell me if you are still getting the ads and having the slowness after running this tool, so I can best determine how to proceed.
Hi, here is the Combofix data. And the computer is still showing these wierd ads; when you look at a webpage certain words are highlighted and you click on them and it takes you to some cheesy ad. And in LinkedIn, there is a panel on the side with some R rated ads that I know LinkedIn doesn't put up there. Pretty weird!

ComboFix 13-02-26.01 - Dave 02/26/2013 11:37:06.4.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3062.1404 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Dave\AppData\Local\assembly\tmp
c:\users\Dave\AppData\Local\Temp\_MEI51282\_ctypes.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\_elementtree.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\_hashlib.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\_socket.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\_ssl.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\pyexpat.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\pysqlite2._sqlite.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\python26.dll
c:\users\Dave\AppData\Local\Temp\_MEI51282\pythoncom26.dll
c:\users\Dave\AppData\Local\Temp\_MEI51282\PyWinTypes26.dll
c:\users\Dave\AppData\Local\Temp\_MEI51282\select.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\unicodedata.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32api.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32com.shell.shell.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32crypt.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32event.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32file.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32inet.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32pdh.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32process.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32profile.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32security.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\win32ts.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\windows._cacheinvalidation.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\wx._controls_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\wx._core_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\wx._gdi_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\wx._html2.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\wx._misc_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\wx._windows_.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\wx._wizard.pyd
c:\users\Dave\AppData\Local\Temp\_MEI51282\wxbase293u_net_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51282\wxbase293u_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51282\wxmsw293u_adv_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51282\wxmsw293u_core_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51282\wxmsw293u_html_vc.dll
c:\users\Dave\AppData\Local\Temp\_MEI51282\wxmsw293u_webview_vc.dll
c:\users\Dave\g2mdlhlpx.exe
.
.
((((((((((((((((((((((((( Files Created from 2013-01-26 to 2013-02-26 )))))))))))))))))))))))))))))))
.
.
2013-02-26 19:52 . 2013-02-26 19:52 ——– d—–w- c:\users\Public\AppData\Local\temp
2013-02-26 19:52 . 2013-02-26 19:52 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-02-26 19:52 . 2013-02-26 19:52 ——– d—–w- c:\users\Administrator\AppData\Local\temp
2013-02-26 19:29 . 2013-02-26 19:29 29904 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3A5AEA98-B0EF-4EBC-AC93-68EC78833FFA}\MpKsl35130a3e.sys
2013-02-25 18:41 . 2013-02-25 18:41 60872 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3A5AEA98-B0EF-4EBC-AC93-68EC78833FFA}\offreg.dll
2013-02-25 18:41 . 2013-02-25 18:41 29904 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3A5AEA98-B0EF-4EBC-AC93-68EC78833FFA}\MpKsl7fc33600.sys
2013-02-25 18:11 . 2013-02-08 00:45 6954968 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3A5AEA98-B0EF-4EBC-AC93-68EC78833FFA}\mpengine.dll
2013-02-23 20:36 . 2013-02-08 00:45 6954968 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-02-19 11:07 . 2013-01-08 22:01 768000 —-a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-19 04:22 . 2013-01-04 03:00 2347008 —-a-w- c:\windows\system32\win32k.sys
2013-02-19 04:22 . 2013-01-05 05:00 3967848 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-02-19 04:22 . 2013-01-05 05:00 3913064 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-02-19 04:22 . 2013-01-03 05:05 1293672 —-a-w- c:\windows\system32\drivers\tcpip.sys
2013-02-19 04:22 . 2013-01-03 05:04 187752 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2013-02-19 04:22 . 2013-01-04 04:50 169984 —-a-w- c:\windows\system32\winsrv.dll
2013-02-15 22:31 . 2013-02-15 22:31 186432 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2013-02-15 22:31 . 2013-02-15 22:31 186432 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
2013-02-12 06:49 . 2013-02-12 06:49 ——– d—–w- c:\program files\ESET
2013-02-12 05:50 . 2013-02-12 05:50 ——– d—–w- c:\windows\ERUNT
2013-02-12 05:50 . 2013-02-12 05:52 ——– d—–w- C:\JRT
2013-02-08 07:51 . 2013-02-08 07:51 ——– d—–w- c:\users\Dave\AppData\Local\LogMeIn
2013-02-08 07:51 . 2013-01-26 00:37 53096 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2013-02-08 07:51 . 2013-01-26 00:37 31592 —-a-w- c:\windows\system32\LMIport.dll
2013-02-08 07:51 . 2013-01-26 00:37 84352 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2013-02-08 07:51 . 2012-11-29 19:56 47640 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2013-02-08 07:51 . 2013-01-26 00:37 92520 —-a-w- c:\windows\system32\LMIinit.dll
2013-02-08 07:51 . 2013-02-26 12:58 ——– d—–w- c:\programdata\LogMeIn
2013-02-08 07:50 . 2013-02-08 07:55 ——– d—–w- c:\program files\LogMeIn
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-07 22:25 . 2012-03-31 19:00 697712 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-07 22:25 . 2011-06-23 17:40 74096 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-30 10:53 . 2010-01-25 02:56 232336 ——w- c:\windows\system32\MpSigStub.exe
2012-12-16 14:13 . 2012-12-24 06:08 295424 —-a-w- c:\windows\system32\atmfd.dll
2012-12-16 14:13 . 2012-12-24 06:08 34304 —-a-w- c:\windows\system32\atmlib.dll
2012-12-15 00:49 . 2010-02-08 18:25 21104 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-12-07 12:26 . 2013-01-09 10:53 308736 —-a-w- c:\windows\system32\Wpc.dll
2012-12-07 12:20 . 2013-01-09 10:53 2576384 —-a-w- c:\windows\system32\gameux.dll
2012-12-07 10:46 . 2013-01-09 10:53 43520 —-a-w- c:\windows\system32\csrr.rs
2012-12-07 10:46 . 2013-01-09 10:53 30720 —-a-w- c:\windows\system32\usk.rs
2012-12-07 10:46 . 2013-01-09 10:53 45568 —-a-w- c:\windows\system32\oflc-nz.rs
2012-12-07 10:46 . 2013-01-09 10:53 44544 —-a-w- c:\windows\system32\pegibbfc.rs
2012-12-07 10:46 . 2013-01-09 10:53 20480 —-a-w- c:\windows\system32\pegi-pt.rs
2012-12-07 10:46 . 2013-01-09 10:53 23552 —-a-w- c:\windows\system32\oflc.rs
2012-12-07 10:46 . 2013-01-09 10:53 20480 —-a-w- c:\windows\system32\pegi-fi.rs
2012-12-07 10:46 . 2013-01-09 10:53 46592 —-a-w- c:\windows\system32\fpb.rs
2012-12-07 10:46 . 2013-01-09 10:53 20480 —-a-w- c:\windows\system32\pegi.rs
2012-12-07 10:46 . 2013-01-09 10:53 21504 —-a-w- c:\windows\system32\grb.rs
2012-12-07 10:46 . 2013-01-09 10:53 40960 —-a-w- c:\windows\system32\cob-au.rs
2012-12-07 10:46 . 2013-01-09 10:53 15360 —-a-w- c:\windows\system32\djctq.rs
2012-12-07 10:46 . 2013-01-09 10:53 51712 —-a-w- c:\windows\system32\esrb.rs
2012-12-07 10:46 . 2013-01-09 10:53 55296 —-a-w- c:\windows\system32\cero.rs
2012-11-30 04:47 . 2013-01-09 10:54 293376 —-a-w- c:\windows\system32\KernelBase.dll
2012-11-30 04:45 . 2013-01-09 10:53 4096 —ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 4608 —ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 4096 —ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 4096 —ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 4096 —ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3584 —ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3584 —ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3584 —ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3584 —ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3584 —ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3584 —ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 4096 —ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 5120 —ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2012-11-30 04:45 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2012-11-30 02:55 . 2013-01-09 10:53 271360 —-a-w- c:\windows\system32\conhost.exe
2012-11-30 02:38 . 2013-01-09 10:53 6144 —ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-11-30 02:38 . 2013-01-09 10:53 4608 —ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-30 02:38 . 2013-01-09 10:53 3584 —ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-11-30 02:38 . 2013-01-09 10:53 3072 —ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-11-29 19:56 . 2012-11-29 19:56 25248 —-a-w- c:\windows\system32\lmimirr.dll
2012-11-29 19:56 . 2012-11-29 19:56 11552 —-a-w- c:\windows\system32\lmimirr2.dll
2012-11-29 19:56 . 2012-11-29 19:56 10144 —-a-w- c:\windows\system32\drivers\lmimirr.sys
2012-11-29 02:34 . 2012-11-29 02:35 740840 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{976634D8-D591-4345-A817-7182E360E333}\gapaengine.dll
2013-02-25 20:22 . 2013-01-10 19:10 263064 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2012-12-18 03:50 556648 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2008-10-24 206112]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2012-01-21 719672]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 206112]
"cdloader"="c:\users\Dave\AppData\Roaming\mjusbsp\cdloader2.exe" [2010-12-03 50592]
"googletalk"="c:\users\Dave\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-01-25 39408]
"Spotify Web Helper"="c:\users\Dave\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-11-15 1199576]
"GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2012-12-18 16328976]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2008-10-24 79136]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"HP LaserJet M1522 MFP Series Fax"="c:\program files\HP\hp LaserJet M1522\hppfaxprintersrv.exe" [2009-09-23 2453504]
"HPUsageTracking"="c:\program files\HP\HP UT\bin\hppusg.exe" [2007-08-31 36864]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2012-12-15 824232]
"LockStatusTray"="c:\windows\LockStatusTray.exe" [2008-02-19 192512]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 648072]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-23 150528]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 150552]
"OEM13Mon.exe"="c:\windows\OEM13Mon.exe" [2008-01-08 36864]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-10-06 59240]
"DNS7reminder"="c:\program files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" [2007-04-16 259624]
"Cobian Backup 10 Interface"="c:\program files\Cobian Backup 10\cbInterface.exe" [2010-09-24 3154432]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2009-08-31 996616]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"ToolboxFX"="c:\program files\HP\ToolboxFX\bin\HPTLBXFX.exe" [2010-10-25 58936]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-08-10 1313640]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 1821576]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-13 947176]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-12-12 152544]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2012-11-29 63048]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-23 270336]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-4-20 813584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 19:28 72208 —-a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux5"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 CrossLoopService;CrossLoop Service;c:\users\Dave\AppData\Local\CrossLoop\CrossLoopService.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [x]
R3 HPFXBULKLEDM;HPFXBULKLEDM;c:\windows\system32\drivers\hppcbulkio.sys [x]
R3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hpfxfax.sys [x]
R3 libusb0;Jawbone LibUsb-Win32 - Kernel Driver 09/22/2011,1.2.5.0;c:\windows\system32\DRIVERS\libusb0.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
R3 SIUSBXP;SIUSBXP;c:\windows\system32\drivers\SiUSBXp.sys [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 Zoho Assist;Zoho Assist;c:\users\Dave\Documents\ZohoMeeting\ZohoMeeting.exe [x]
S0 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2media.sys [x]
S1 MpKsl35130a3e;MpKsl35130a3e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3A5AEA98-B0EF-4EBC-AC93-68EC78833FFA}\MpKsl35130a3e.sys [x]
S1 MpKsl7fc33600;MpKsl7fc33600;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3A5AEA98-B0EF-4EBC-AC93-68EC78833FFA}\MpKsl7fc33600.sys [x]
S2 BthFilterHelper;Bluetooth Feature Support;c:\program files\CSR\Vista Profile Pack\BthFilterHelper.exe [x]
S2 cbVSCService;Cobian Backup 10 Volume Shadow Copy service;c:\program files\Cobian Backup 10\cbVSCService.exe [x]
S2 CobianBackup10;Cobian Backup 10;c:\program files\Cobian Backup 10\cbService.exe [x]
S2 DragonSvc;Dragon Service;c:\program files\Common Files\Nuance\dgnsvc.exe [x]
S2 HP LaserJet Service;HP LaserJet Service;c:\program files\HP\HPLaserJetService\HPLaserJetService.exe [x]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [x]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [x]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [x]
S3 OEM13Vfx;Creative Camera OEM013 Video VFX Driver;c:\windows\system32\DRIVERS\OEM13Vfx.sys [x]
S3 OEM13Vid;Creative Camera OEM013 Driver;c:\windows\system32\DRIVERS\OEM13Vid.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL35130A3E
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
HPService REG_MULTI_SZ HPSLPSVC
.
Contents of the 'Scheduled Tasks' folder
.
2013-02-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]
.
2013-02-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 22:25]
.
2013-02-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 05:19]
.
2013-02-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 05:19]
.
2013-02-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2557060353-3338967487-1032703843-1000Core.job
- c:\users\Dave\AppData\Local\Google\Update\GoogleUpdate.exe [2010-01-25 06:29]
.
2013-02-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2557060353-3338967487-1032703843-1000UA.job
- c:\users\Dave\AppData\Local\Google\Update\GoogleUpdate.exe [2010-01-25 06:29]
.
.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://www.google.com/ie
uStart Page = https://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //FWEvent.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\qln39cgr.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - ExtSQL: !HIDDEN! 2010-08-15 23:37; [removed]; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-MobileDocuments - c:\program files\Common Files\Apple\Internet Services\ubd.exe
AddRemove-{16726771-C380-4280-BAF9-1223B3838786} - c:\programdata\SaveAs\uninstall.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.download\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariDownload"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.safariextz\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariExtension"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webarchive\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_USERS\S-1-5-21-2557060353-3338967487-1032703843-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-2557060353-3338967487-1032703843-1000)
"Progid"="SafariHTML"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-02-26 11:57:11
ComboFix-quarantined-files.txt 2013-02-26 19:57
ComboFix2.txt 2012-10-26 04:12
.
Pre-Run: 97,461,280,768 bytes free
Post-Run: 97,831,178,240 bytes free
.
- - End Of File - - EE994F9D5BCD4F7363189AB776C954FF
Well, Combofix did remove a bunch of unwanted files, but obviously it didn't get to the root of the problem. As I suspected, we'll need to keep delving a bit further. The next tool will let us look a bit deeper. If it's what I suspect, tools don't show the actual infected files, but they can show symptoms of the infection in the logs and that's what I'm hoping we'll see in this next log. I know this is frustrating so please be patient. We'll get to the bottom of this.

Can you also tell me in your next reply which browser you use, and if you have had the same symptoms in multiple browsers? For instance, if Chrome is your favorite browser, have you also tried Internet Explorer and you have the same trouble there? Or do you mainly use only one browser so you've only seen the problem in one browser?


Download Farbar Recovery Scan Tool and save it to a flash drive.

Plug the flashdrive into the infected PC.

Restart your computer and tap F8 to bring up the Advanced Menu, then click Repair your computer

Follow the prompt to enter keyboard input method, and then the prompt to enter a password. If the machine does not have a password, simply click Enter.

In the next menu, use the arrow keys on the keyboard to highlight Command Prompt and press Enter.
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst.exe and press Enter.
Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Place a check next to List Drivers MD5
  • Press Scan button.
    When finished, a log (FRST.txt) will be created on the flash drive. Please copy and paste it to your reply.


Please note: This is another diagnostic tool. This isn't a fix to remove anything. This is just going to give me a lot more information so I can see if I can spot the signs of the infection I'm looking for.
Hi PatnDoris, thank you very much for all of your assistance. I use Firefox, Chrome and IE for browsers. It looks like it's Firefox that has the ads issue. Typically on a Linkedin profile there will be highlighted words and if you click them it opens up a cheesy ad. And on the right side of the page it also inserts an R rated ad. Here it the log: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-02-2013 01 Ran by [removed] at 27-02-2013 14:34:37 Running from E:\ Windows 7 Ultimate (X86) OS Language: English(US) The current controlset is ControlSet001 ==================== Registry (Whitelisted) =================== HKLM\…\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot [210472 2006-10-25] (Nuance Communications, Inc.) HKLM\…\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start [79136 2008-10-24] (Macrovision Corporation) HKLM\…\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume [288080 2009-07-17] (Microsoft Corporation) HKLM\…\Run: [HP LaserJet M1522 MFP Series Fax] C:\Program Files\HP\hp LaserJet M1522\hppfaxprintersrv.exe "HP LaserJet M1522 MFP Series Fax" [2453504 2009-09-22] (Hewlett-Packard Company) HKLM\…\Run: [HPUsageTracking] "C:\Program Files\HP\HP UT\bin\hppusg.exe" "C:\Program Files\HP\HP UT\" [36864 2007-08-31] () HKLM\…\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript [824232 2012-12-14] (Malwarebytes Corporation) HKLM\…\Run: [LockStatusTray] C:\Windows\LockStatusTray.exe [192512 2008-02-19] (Logitech, Inc.) HKLM\…\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE [x] HKLM\…\Run: [Windows Mobile-based device management] %WINDIR%\WindowsMobile\wmdcBase.exe [648072 2007-05-31] (Microsoft Corporation) HKLM\…\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard) HKLM\…\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM\…\Run: [OEM13Mon.exe] C:\Windows\OEM13Mon.exe [36864 2008-01-07] (Creative Technology Ltd.) HKLM\…\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation) HKLM\…\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-10-06] (Apple Inc.) HKLM\…\Run: [DNS7reminder] "C:\Program Files\Nuance\NaturallySpeaking11\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\NaturallySpeaking11\Ereg.ini [344 2013-02-25] () HKLM\…\Run: [Cobian Backup 10 Interface] "C:\Program Files\Cobian Backup 10\cbInterface.exe" -service [3154432 2010-09-23] (Luis Cobian, CobianSoft) HKLM\…\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup [996616 2009-08-30] (Intuit Inc. All rights reserved.) HKLM\…\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-02] (Adobe Systems Incorporated) HKLM\…\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-11-28] (Apple Inc.) HKLM\…\Run: [ToolboxFX] "C:\Program Files\HP\ToolboxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on [58936 2010-10-25] (Hewlett-Packard Company) HKLM\…\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe" [1313640 2011-08-10] (Microsoft Corporation) HKLM\…\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [1821576 2011-08-01] (Microsoft Corporation) HKLM\…\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [947152 2013-01-27] (Microsoft Corporation) HKLM\…\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.) HKLM\…\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [421888 2012-10-25] (Apple Inc.) HKLM\…\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [152544 2012-12-12] (Apple Inc.) HKLM\…\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [63048 2012-11-29] (LogMeIn, Inc.) HKU\Dave\…\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup [206112 2008-10-24] (Macrovision Corporation) HKU\Dave\…\Run: [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE" [719672 2012-01-20] (Microsoft Corporation) HKU\Dave\…\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler [206112 2008-10-24] (Macrovision Corporation) HKU\Dave\…\Run: [cdloader] "C:\Users\Dave\AppData\Roaming\mjusbsp\cdloader2.exe" MAGICJACK [50592 2010-12-03] (magicJack L.P.) HKU\Dave\…\Run: [googletalk] C:\Users\Dave\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart [3739648 2007-01-01] (Google) HKU\Dave\…\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-01-24] (Google Inc.) HKU\Dave\…\Run: [Spotify Web Helper] "C:\Users\Dave\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1199576 2012-11-14] (Spotify Ltd) HKU\Dave\…\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart [16328976 2012-12-17] (Google) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [X] Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Startup: C:\ProgramData\Start Menu\Programs\Startup\Google Calendar Sync.lnk ShortcutTarget: Google Calendar Sync.lnk -> C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe (Google) Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\ProgramData\Start Menu\Programs\Startup\Logitech SetPoint.lnk ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.) Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files\microsoft office\Office14\ONENOTEM.EXE (Microsoft Corporation) ==================== Services (Whitelisted) =================== 2 BthFilterHelper; "C:\Program Files\CSR\Vista Profile Pack\BthFilterHelper.exe" [127488 2006-11-07] (CSR, plc) 2 cbVSCService; C:\Program Files\Cobian Backup 10\cbVSCService.exe [67584 2010-09-23] (CobianSoft, Luis Cobian) 2 CobianBackup10; C:\Program Files\Cobian Backup 10\cbService.exe [1125376 2010-09-23] (Luis Cobian, CobianSoft) 2 CrossLoopService; "C:\Users\Dave\AppData\Local\CrossLoop\CrossLoopService.exe" –service [560792 2010-03-15] (CrossLoop Inc) 2 DragonSvc; C:\Program Files\Common Files\Nuance\dgnsvc.exe [296808 2010-07-23] (Nuance Communications, Inc.) 2 Lavasoft Ad-Aware Service; "C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe" [1029456 2009-07-03] (Lavasoft) 3 Zoho Assist; "C:\Users\Dave\Documents\ZohoMeeting\ZohoMeeting.exe" run -dir "C:\Users\Dave\Documents\ZohoMeeting" [289928 2012-08-17] () 2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [x] 2 MSSQL$MSSMLBIZ; "c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ [x] 4 MSSQLServerADHelper; "c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe" [x] 3 NisSrv; "c:\Program Files\Microsoft Security Client\NisSrv.exe" [x] 2 SQLBrowser; "c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe" [x] 2 SQLWriter; "c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [x] ==================== Drivers (Whitelisted) ==================== 3 CSRBC; C:\Windows\System32\Drivers\csrbcxp.sys [31744 2007-01-16] (CSR, plc) 3 Dot4Scan; C:\Windows\System32\DRIVERS\Dot4Scan.sys [10752 2009-07-13] (Microsoft Corporation) 3 FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [36640 2010-08-23] () 3 HPFXBULK; C:\Windows\System32\drivers\hpfxbulk.sys [17432 2007-07-16] (Hewlett Packard) 3 HPFXBULKLEDM; C:\Windows\System32\drivers\hppcbulkio.sys [20504 2010-10-03] (Hewlett Packard) 3 HPFXFAX; C:\Windows\System32\drivers\hpfxfax.sys [20504 2007-07-16] (Hewlett Packard) 3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [42592 2012-03-13] (http://libusb-win32.sourceforge.net) 3 LMouFilt; C:\Windows\System32\DRIVERS\LMouFilt.Sys [37392 2009-06-17] (Logitech, Inc.) 0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [195296 2013-01-20] (Microsoft Corporation) 3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [14736 2009-06-01] (Microsoft Corporation) 3 OEM13Vfx; C:\Windows\System32\DRIVERS\OEM13Vfx.sys [7424 2007-03-05] (EyePower Games Pte. Ltd.) 3 OEM13Vid; C:\Windows\System32\DRIVERS\OEM13Vid.sys [235840 2008-05-28] (Creative Technology Ltd.) 3 SIUSBXP; C:\Windows\System32\drivers\SiUSBXp.sys [14592 2012-09-14] (Silicon Laboratories) 3 catchme; \??\C:\Users\Dave\AppData\Local\Temp\catchme.sys [x] 3 dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [x] 4 LMIRfsClientNP; [x] 3 Synth3dVsc; C:\Windows\System32\drivers\synth3dvsc.sys [x] 3 tsusbhub; C:\Windows\System32\drivers\tsusbhub.sys [x] 3 VGPU; C:\Windows\System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-02-27 14:34 - 2013-02-27 14:34 - 00000000 ____D C:\FRST 2013-02-27 13:48 - 2013-02-27 13:48 - 00000000 ____D C:\Users\Dave\AppData\Local\Proxure 2013-02-27 13:46 - 2013-02-27 13:46 - 00000000 ____D C:\ProgramData\ClubSanDisk 2013-02-27 12:24 - 2013-02-27 12:26 - 00000000 ____D C:\6374b811a3da28081de47899 2013-02-26 11:57 - 2013-02-26 11:57 - 00027999 ____A C:\ComboFix.txt 2013-02-26 11:33 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe 2013-02-26 11:33 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe 2013-02-26 11:33 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2013-02-26 11:33 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2013-02-26 11:33 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2013-02-26 11:33 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe 2013-02-26 11:33 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe 2013-02-26 11:33 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe 2013-02-26 11:29 - 2013-02-26 11:57 - 00000000 ____D C:\Qoobox 2013-02-26 11:25 - 2013-02-26 11:26 - 05036023 ____R (Swearware) C:\Users\Dave\Desktop\ComboFix.exe 2013-02-19 03:08 - 2013-01-08 14:23 - 12321280 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-02-19 03:08 - 2013-01-08 14:11 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-02-19 03:08 - 2013-01-08 14:09 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-02-19 03:08 - 2013-01-08 14:03 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-02-19 03:08 - 2013-01-08 14:03 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-02-19 03:08 - 2013-01-08 14:03 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-02-19 03:08 - 2013-01-08 14:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-02-19 03:08 - 2013-01-08 14:00 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-02-19 03:08 - 2013-01-08 13:59 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-02-19 03:08 - 2013-01-08 13:58 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-02-19 03:08 - 2013-01-08 13:58 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-02-19 03:08 - 2013-01-08 13:57 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-02-19 03:08 - 2013-01-08 13:56 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-02-19 03:08 - 2013-01-08 13:56 - 01796096 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-02-19 03:08 - 2013-01-08 13:56 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-02-19 03:08 - 2013-01-08 13:53 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-02-18 20:22 - 2013-01-04 21:00 - 03967848 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe 2013-02-18 20:22 - 2013-01-04 21:00 - 03913064 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2013-02-18 20:22 - 2013-01-03 20:50 - 00169984 ____A (Microsoft Corporation) C:\Windows\System32\winsrv.dll 2013-02-18 20:22 - 2013-01-03 19:00 - 02347008 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-02-18 20:22 - 2013-01-02 21:05 - 01293672 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys 2013-02-18 20:22 - 2013-01-02 21:04 - 00187752 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\FWPKCLNT.SYS 2013-02-11 22:49 - 2013-02-11 22:49 - 00000000 ____D C:\Program Files\ESET 2013-02-11 22:03 - 2013-02-11 22:03 - 00001073 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2013-02-11 22:02 - 2013-02-11 22:02 - 10156424 ____A (Malwarebytes Corporation ) C:\Users\Dave\Desktop\mbam-setup.exe 2013-02-11 21:56 - 2013-02-11 21:56 - 00008810 ____A C:\Users\Dave\Desktop\JRT.txt 2013-02-11 21:50 - 2013-02-11 21:52 - 00000000 ____D C:\JRT 2013-02-11 21:50 - 2013-02-11 21:50 - 00000000 ____D C:\Windows\ERUNT 2013-02-11 21:49 - 2013-02-11 21:50 - 00547275 ____A (Oleg N. Scherbakov) C:\Users\Dave\Desktop\JRT.exe 2013-02-11 21:48 - 2013-02-11 21:48 - 00547275 ____A (Oleg N. Scherbakov) C:\Users\Dave\Downloads\JRT.exe 2013-02-08 02:21 - 2013-02-08 02:21 - 00151984 ____A C:\Windows\Minidump\020813-19390-01.dmp 2013-02-08 00:31 - 2013-02-08 00:31 - 00151992 ____A C:\Windows\Minidump\020813-68468-01.dmp 2013-02-08 00:30 - 2013-02-08 02:21 - 351098775 ____A C:\Windows\MEMORY.DMP 2013-02-07 23:51 - 2013-02-27 12:20 - 00000000 ____D C:\ProgramData\LogMeIn 2013-02-07 23:51 - 2013-02-07 23:51 - 00001024 ____A C:\.rnd 2013-02-07 23:51 - 2013-02-07 23:51 - 00000000 ____D C:\Users\Dave\AppData\Local\LogMeIn 2013-02-07 23:51 - 2013-01-25 16:37 - 00092520 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIinit.dll 2013-02-07 23:51 - 2013-01-25 16:37 - 00084352 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIRfsClientNP.dll 2013-02-07 23:51 - 2013-01-25 16:37 - 00031592 ____A (LogMeIn, Inc.) C:\Windows\System32\LMIport.dll 2013-02-07 23:51 - 2012-11-29 11:56 - 00047640 ____A (LogMeIn, Inc.) C:\Windows\System32\Drivers\LMIRfsDriver.sys 2013-02-07 23:50 - 2013-02-07 23:55 - 00000000 ____D C:\Program Files\LogMeIn 2013-02-06 16:56 - 2013-02-06 16:57 - 00688992 ____R (Swearware) C:\Users\Dave\Downloads\dds.com ==================== One Month Modified Files and Folders ======== 2013-02-27 14:27 - 2010-01-24 15:18 - 01505941 ____A C:\Windows\WindowsUpdate.log 2013-02-27 14:26 - 2010-01-24 22:29 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2557060353-3338967487-1032703843-1000UA.job 2013-02-27 14:25 - 2012-03-31 11:00 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-02-27 14:25 - 2010-11-03 21:12 - 00000194 ____A C:\Users\Dave\AppData\Local\CATSWord.ini 2013-02-27 14:15 - 2010-01-30 21:19 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-02-27 14:03 - 2011-01-06 08:02 - 00000000 ____D C:\Users\Dave\Documents\Outlook Files 2013-02-27 14:03 - 2009-04-14 13:42 - 00000000 ____D C:\Users\Dave\Documents\PST Files 2013-02-27 13:48 - 2013-02-27 13:48 - 00000000 ____D C:\Users\Dave\AppData\Local\Proxure 2013-02-27 13:48 - 2010-01-24 15:35 - 00796132 ____A C:\Windows\System32\PerfStringBackup.INI 2013-02-27 13:46 - 2013-02-27 13:46 - 00000000 ____D C:\ProgramData\ClubSanDisk 2013-02-27 12:31 - 2009-10-27 21:15 - 00000000 ____D C:\Users\Dave\Documents\LCG Candidates 2013-02-27 12:26 - 2013-02-27 12:24 - 00000000 ____D C:\6374b811a3da28081de47899 2013-02-27 12:26 - 2011-02-02 13:35 - 00001945 ____A C:\Windows\epplauncher.mif 2013-02-27 12:26 - 2011-02-02 13:33 - 00000000 ____D C:\Program Files\Microsoft Security Client 2013-02-27 12:25 - 2012-03-31 11:00 - 00691568 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe 2013-02-27 12:25 - 2011-06-23 09:40 - 00071024 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl 2013-02-27 12:23 - 2010-01-24 21:30 - 00000000 ____D C:\Users\Dave\AppData\Roaming\Mozilla 2013-02-27 12:20 - 2013-02-07 23:51 - 00000000 ____D C:\ProgramData\LogMeIn 2013-02-26 20:15 - 2010-01-30 21:19 - 00000882 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-02-26 16:26 - 2010-01-24 22:29 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2557060353-3338967487-1032703843-1000Core.job 2013-02-26 11:57 - 2013-02-26 11:57 - 00027999 ____A C:\ComboFix.txt 2013-02-26 11:57 - 2013-02-26 11:29 - 00000000 ____D C:\Qoobox 2013-02-26 11:53 - 2009-07-13 18:04 - 00000215 ____A C:\Windows\system.ini 2013-02-26 11:51 - 2010-01-24 15:34 - 00000000 ____D C:\users\Dave 2013-02-26 11:28 - 2010-02-08 11:18 - 00000000 ____D C:\Windows\ERDNT 2013-02-26 11:26 - 2013-02-26 11:25 - 05036023 ____R (Swearware) C:\Users\Dave\Desktop\ComboFix.exe 2013-02-25 22:34 - 2009-07-13 20:34 - 00013760 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-02-25 22:34 - 2009-07-13 20:34 - 00013760 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-02-25 22:28 - 2012-08-30 14:19 - 00000000 ___SD C:\Users\Dave\Google Drive 2013-02-25 22:26 - 2013-01-18 11:43 - 00001980 ____A C:\Windows\setupact.log 2013-02-25 22:26 - 2012-04-21 18:33 - 00016572 ____A C:\aaw7boot.log 2013-02-25 22:26 - 2009-07-13 20:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-02-25 20:00 - 2010-07-05 08:58 - 00000000 ____D C:\Users\Dave\AppData\Roaming\HpUpdate 2013-02-25 12:22 - 2013-01-10 11:10 - 00000000 ____D C:\Program Files\Mozilla Firefox 2013-02-23 10:46 - 2009-04-14 13:43 - 00000000 ____D C:\Users\Dave\Documents\Personal stuff 2013-02-23 10:41 - 2012-12-07 23:43 - 00001294 ____A C:\Users\Dave\Desktop\Party invitees 12-2012 Cleaned up.csv 2013-02-22 12:46 - 2010-03-19 20:27 - 00000000 ____D C:\Users\Dave\Documents\LCG Consultants 2013-02-22 12:45 - 2010-05-18 13:28 - 00298496 ____A C:\Users\Dave\Desktop\Candidate Rate Ranges.xls 2013-02-22 00:15 - 2012-04-19 23:15 - 00000472 ____A C:\Windows\Tasks\Ad-Aware Update (Weekly).job 2013-02-19 03:48 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-02-19 03:37 - 2009-07-13 20:33 - 00497088 ____A C:\Windows\System32\FNTCACHE.DAT 2013-02-19 03:12 - 2010-01-25 14:48 - 67823584 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-02-19 03:12 - 2010-01-24 22:46 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-02-18 20:12 - 2010-01-24 22:51 - 00000000 ____D C:\Windows\PCHEALTH 2013-02-18 20:12 - 2010-01-24 18:38 - 00092754 ____A C:\Windows\PFRO.log 2013-02-11 22:49 - 2013-02-11 22:49 - 00000000 ____D C:\Program Files\ESET 2013-02-11 22:03 - 2013-02-11 22:03 - 00001073 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2013-02-11 22:03 - 2010-02-08 10:25 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2013-02-11 22:02 - 2013-02-11 22:02 - 10156424 ____A (Malwarebytes Corporation ) C:\Users\Dave\Desktop\mbam-setup.exe 2013-02-11 21:56 - 2013-02-11 21:56 - 00008810 ____A C:\Users\Dave\Desktop\JRT.txt 2013-02-11 21:52 - 2013-02-11 21:50 - 00000000 ____D C:\JRT 2013-02-11 21:50 - 2013-02-11 21:50 - 00000000 ____D C:\Windows\ERUNT 2013-02-11 21:50 - 2013-02-11 21:49 - 00547275 ____A (Oleg N. Scherbakov) C:\Users\Dave\Desktop\JRT.exe 2013-02-11 21:48 - 2013-02-11 21:48 - 00547275 ____A (Oleg N. Scherbakov) C:\Users\Dave\Downloads\JRT.exe 2013-02-08 02:21 - 2013-02-08 02:21 - 00151984 ____A C:\Windows\Minidump\020813-19390-01.dmp 2013-02-08 02:21 - 2013-02-08 00:30 - 351098775 ____A C:\Windows\MEMORY.DMP 2013-02-08 02:21 - 2010-02-08 18:07 - 00000000 ____D C:\Windows\Minidump 2013-02-08 00:31 - 2013-02-08 00:31 - 00151992 ____A C:\Windows\Minidump\020813-68468-01.dmp 2013-02-07 23:55 - 2013-02-07 23:50 - 00000000 ____D C:\Program Files\LogMeIn 2013-02-07 23:51 - 2013-02-07 23:51 - 00001024 ____A C:\.rnd 2013-02-07 23:51 - 2013-02-07 23:51 - 00000000 ____D C:\Users\Dave\AppData\Local\LogMeIn 2013-02-07 23:49 - 2010-03-13 20:37 - 00000000 ____D C:\Users\Dave\AppData\Local\Deployment 2013-02-07 23:48 - 2009-04-20 13:44 - 00000000 ____D C:\Users\Dave\AppData\Local\Apps\2.0 2013-02-07 21:29 - 2010-02-13 07:32 - 00000000 ____D C:\Users\Dave\AppData\Roaming\Skype 2013-02-07 10:56 - 2009-04-14 13:33 - 00000000 ____D C:\Users\Dave\Documents\Accounts 2013-02-06 16:57 - 2013-02-06 16:56 - 00688992 ____R (Swearware) C:\Users\Dave\Downloads\dds.com 2013-01-30 13:57 - 2010-02-17 08:37 - 00000000 ____D C:\Users\Dave\Documents\LCG Contracts 2013-01-30 13:04 - 2010-10-25 11:12 - 00000000 ____D C:\Users\Dave\Documents\LCG Marketing 2013-01-30 02:53 - 2010-01-24 18:56 - 00232336 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\…\.exe: exefile => OK HKLM\…\exefile\DefaultIcon: %1 => OK HKLM\…\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2013-02-08 02:58:35 Restore point made on: 2013-02-08 23:30:18 Restore point made on: 2013-02-09 11:35:24 Restore point made on: 2013-02-09 23:30:29 Restore point made on: 2013-02-11 23:30:50 Restore point made on: 2013-02-18 20:17:20 Restore point made on: 2013-02-18 23:30:19 Restore point made on: 2013-02-19 03:01:16 Restore point made on: 2013-02-20 23:30:57 Restore point made on: 2013-02-23 10:43:58 Restore point made on: 2013-02-26 23:30:17 Restore point made on: 2013-02-27 12:24:08 ==================== Memory info =========================== Percentage of memory in use: 15% Total physical RAM: 3062.43 MB Available physical RAM: 2598.95 MB Total Pagefile: 3060.71 MB Available Pagefile: 2604.06 MB Total Virtual: 2047.88 MB Available Virtual: 1960.7 MB ==================== Partitions ============================= 1 Drive c: (OS) (Fixed) (Total:288.29 GB) (Free:90.14 GB) NTFS ==>[Drive with boot components (obtained from BCD)] 3 Drive e: () (Removable) (Total:14.9 GB) (Free:14.55 GB) FAT32 4 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Disk ### Status Size Free Dyn Gpt ——– ————- ——- ——- — — Disk 0 Online 298 GB 5120 KB Disk 1 Online 14 GB 0 B Partitions of Disk 0: =============== Disk ID: A42D04A3 Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 OEM 39 MB 31 KB Partition 2 Primary 288 GB 40 MB Partition 3 Primary 9 GB 288 GB ========================================================= Disk: 0 Partition 1 Type : DE Hidden: Yes Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 3 FAT Partition 39 MB Healthy Hidden ========================================================= Disk: 0 Partition 2 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 1 C OS NTFS Partition 288 GB Healthy ========================================================= Disk: 0 Partition 3 Type : DB Hidden: Yes Active: No There is no volume associated with this partition. ========================================================= Partitions of Disk 1: =============== Disk ID: 00000000 Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 14 GB 16 KB ========================================================= Disk: 1 Partition 1 Type : 0C Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 E FAT32 Removable 14 GB Healthy ========================================================= Last Boot: 2013-02-23 15:16 ==================== End Of Log ============================
Well, the good news is that I don't see any symptoms of what I was expecting. That is very good. And the fact you are mostly experiencing the problem in Firefox does narrow things down a bit.

Can you please run a fresh DDS log for me so I can take a look at what's remaining in the Firefox entries since you've run the Junkware remover? There were some entries originally that might have caused the ads, but they *should* have been removed. If not, we can manually removed them with Combofix. I'd just like to confirm if they are still there or not.


Run DDS by sUBs
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE
Hi, here is the text: DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 9.0.8112.16464 BrowserJavaVersion: 10.7.2 Run by [removed] at 16:27:10 on 2013-02-27 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.3062.1061 [GMT -8:00] . AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508} . ============== Running Processes ================ . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe c:\Program Files\Microsoft Security Client\MsMpEng.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\Windows\System32\spoolsv.exe C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\CSR\Vista Profile Pack\BthFilterHelper.exe C:\Program Files\Cobian Backup 10\cbVSCService.exe C:\Program Files\Cobian Backup 10\cbService.exe C:\Users\Dave\AppData\Local\CrossLoop\CrossLoopService.exe C:\Program Files\Common Files\Nuance\dgnsvc.exe C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe C:\Program Files\LogMeIn\x86\RaMaint.exe C:\Program Files\LogMeIn\x86\LogMeIn.exe c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe c:\Program Files\Microsoft Security Client\NisSrv.exe C:\Windows\System32\WUDFHost.exe C:\Windows\System32\WUDFHost.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\HP\HP UT\bin\hppusg.exe C:\Windows\LockStatusTray.exe C:\Windows\WindowsMobile\wmdcBase.exe C:\Program Files\HP\HP Software Update\hpwuschd2.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\OEM13Mon.exe C:\Program Files\Cobian Backup 10\cbInterface.exe C:\Program Files\HP\ToolboxFX\bin\HPTLBXFX.exe C:\Program Files\Microsoft IntelliType Pro\itype.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe C:\Program Files\itunes\iTunesHelper.exe C:\Program Files\LogMeIn\x86\LogMeInSystray.exe C:\Program Files\microsoft office\Office14\MSOSYNC.EXE C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\Windows\system32\SearchIndexer.exe C:\Users\Dave\AppData\Roaming\Google\Google Talk\googletalk.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\iPod\bin\iPodService.exe C:\Users\Dave\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe C:\Program Files\Google\Drive\googledrivesync.exe C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\microsoft office\Office14\ONENOTEM.EXE C:\Windows\system32\wuauclt.exe C:\Program Files\Google\Drive\googledrivesync.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\Program Files\microsoft office\Office14\OUTLOOK.EXE C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Microsoft Office\Office14\WINWORD.EXE C:\Users\Dave\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Dave\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Dave\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Dave\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Dave\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Dave\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Dave\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k bthsvcs C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k HPService C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k WindowsMobile C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation . ============== Pseudo HJT Report =============== . uStart Page = hxxps://www.google.com/ uDefault_Search_URL = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll BHO: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll uRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup uRun: [OfficeSyncProcess] "c:\program files\microsoft office\office14\MSOSYNC.EXE" uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler uRun: [cdloader] "c:\users\dave\appdata\roaming\mjusbsp\cdloader2.exe" MAGICJACK uRun: [googletalk] c:\users\dave\appdata\roaming\google\google talk\googletalk.exe /autostart uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [Spotify Web Helper] "c:\users\dave\appdata\roaming\spotify\data\SpotifyWebHelper.exe" uRun: [GoogleDriveSync] "c:\program files\google\drive\googledrivesync.exe" /autostart mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume mRun: [HP LaserJet M1522 MFP Series Fax] c:\program files\hp\hp laserjet m1522\hppfaxprintersrv.exe "HP LaserJet M1522 MFP Series Fax" mRun: [HPUsageTracking] "c:\program files\hp\hp ut\bin\hppusg.exe" "c:\program files\hp\hp ut\" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [LockStatusTray] c:\windows\LockStatusTray.exe mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE mRun: [Windows Mobile-based device management] c:\windows\windowsmobile\wmdcBase.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [OEM13Mon.exe] c:\windows\OEM13Mon.exe mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [DNS7reminder] "c:\program files\nuance\naturallyspeaking11\ereg\ereg.exe" -r "c:\programdata\nuance\naturallyspeaking11\Ereg.ini mRun: [Cobian Backup 10 Interface] "c:\program files\cobian backup 10\cbInterface.exe" -service mRun: [Intuit SyncManager] c:\program files\common files\intuit\sync\IntuitSyncManager.exe startup mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [ToolboxFX] "c:\program files\hp\toolboxfx\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe" mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe" mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe" StartupFolder: c:\users\dave\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office14\ONENOTEM.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\google~1.lnk - c:\program files\google\google calendar sync\GoogleCalendarSync.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe uPolicies-Explorer: NoDrives = dword:0 mPolicies-Explorer: NoDrives = dword:0 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 mPolicies-System: PromptOnSecureDesktop = dword:0 IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200 IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000 IE: Se&nd; to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll Trusted Zone: //about.htm/ Trusted Zone: //Exclude.htm/ Trusted Zone: //FWEvent.htm/ Trusted Zone: //LanguageSelection.htm/ Trusted Zone: //Message.htm/ Trusted Zone: //MyAgttryCmd.htm/ Trusted Zone: //MyAgttryNag.htm/ Trusted Zone: //MyNotification.htm/ Trusted Zone: //NOCLessUpdate.htm/ Trusted Zone: //quarantine.htm/ Trusted Zone: //ScanNow.htm/ Trusted Zone: //strings.vbs/ Trusted Zone: //Template.htm/ Trusted Zone: //Update.htm/ Trusted Zone: //VirFound.htm/ DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: NameServer = 192.168.1.1 TCP: Interfaces\{6FD2D014-3DEE-49C5-BAC4-5EFC7C823EDC} : DHCPNameServer = 192.168.1.1 TCP: Interfaces\{79EE02E4-39BE-4C39-881D-F5B949F8BF5E} : DHCPNameServer = 192.168.1.1 TCP: Interfaces\{79EE02E4-39BE-4C39-881D-F5B949F8BF5E}\44146554D27457563747 : DHCPNameServer = 192.168.1.1 TCP: Interfaces\{79EE02E4-39BE-4C39-881D-F5B949F8BF5E}\44146554D28444 : DHCPNameServer = 192.168.1.1 TCP: Interfaces\{79EE02E4-39BE-4C39-881D-F5B949F8BF5E}\6596379647F627 : DHCPNameServer = [removed] Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Handler: intu-help-qb3 - {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - c:\program files\intuit\quickbooks 2010\HelpAsyncPluggableProtocol.dll Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll Notify: igfxcui - igfxdev.dll Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\users\dave\appdata\roaming\mozilla\firefox\profiles\qln39cgr.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\google\update\1.3.21.135\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\program files\logitech\harmony remote driver\NprtHarmonyPlugin.dll FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll FF - plugin: c:\users\dave\appdata\local\google\update\1.3.21.135\npGoogleUpdate3.dll FF - plugin: c:\users\dave\appdata\roaming\facebook\npfbplugin_1_0_3.dll FF - plugin: c:\users\dave\appdata\roaming\mozilla\plugins\npgoogletalk.dll FF - plugin: c:\users\dave\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll FF - plugin: c:\users\dave\appdata\roaming\mozilla\plugins\npo1d.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_6_602_171.dll FF - plugin: c:\windows\system32\npDeployJava1.dll FF - plugin: c:\windows\system32\npmproxy.dll FF - ExtSQL: !HIDDEN! 2010-08-15 23:37; [removed]; c:\program files\hp\digital imaging\smart web printing\MozillaAddOn3 . ============= SERVICES / DRIVERS =============== . R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2013-1-20 195296] R0 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2005-11-14 34176] R2 BthFilterHelper;Bluetooth Feature Support;c:\program files\csr\vista profile pack\BthFilterHelper.exe [2006-11-7 127488] R2 cbVSCService;Cobian Backup 10 Volume Shadow Copy service;c:\program files\cobian backup 10\cbVSCService.exe [2011-2-9 67584] R2 CobianBackup10;Cobian Backup 10;c:\program files\cobian backup 10\cbService.exe [2011-2-9 1125376] R2 CrossLoopService;CrossLoop Service;c:\users\dave\appdata\local\crossloop\CrossLoopService.exe [2010-1-26 560792] R2 DragonSvc;Dragon Service;c:\program files\common files\nuance\dgnsvc.exe [2010-7-23 296808] R2 HP LaserJet Service;HP LaserJet Service;c:\program files\hp\hplaserjetservice\HPLaserJetService.exe [2010-10-25 145920] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456] R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2013-1-25 375144] R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2012-11-29 12856] R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2013-2-7 47640] R2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2012-3-20 100328] R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2013-1-27 295232] R3 OEM13Vfx;Creative Camera OEM013 Video VFX Driver;c:\windows\system32\drivers\OEM13Vfx.sys [2007-3-5 7424] R3 OEM13Vid;Creative Camera OEM013 Driver;c:\windows\system32\drivers\OEM13Vid.sys [2008-5-28 235840] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-11-9 160944] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-9-22 36640] S3 HPFXBULKLEDM;HPFXBULKLEDM;c:\windows\system32\drivers\hppcbulkio.sys [2010-10-3 20504] S3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hpfxfax.sys [2010-1-26 20504] S3 libusb0;Jawbone LibUsb-Win32 - Kernel Driver 09/22/2011,1.2.5.0;c:\windows\system32\drivers\libusb0.sys [2012-3-13 42592] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-7-7 15872] S3 SIUSBXP;SIUSBXP;c:\windows\system32\drivers\SiUSBXp.sys [2012-9-14 14592] S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2011-2-12 96488] S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2011-2-12 12776] S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2011-2-12 121576] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-7-7 52224] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-3-1 1343400] S3 Zoho Assist;Zoho Assist;c:\users\dave\documents\zohomeeting\ZohoMeeting.exe [2012-8-17 289928] . =============== File Associations =============== . FileExt: .chm: chm.file="c:\windows\hh.exe" %1 [UserChoice] . =============== Created Last 30 ================ . 2013-02-27 22:34:02 ——– d—–w- C:\FRST 2013-02-27 21:48:39 ——– d—–w- c:\users\dave\appdata\local\Proxure 2013-02-27 21:46:21 ——– d—–w- c:\programdata\ClubSanDisk 2013-02-27 20:42:12 6954968 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{34d6af83-fc4d-4c65-a98c-504fae342b88}\mpengine.dll 2013-02-27 02:03:04 6954968 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2013-02-26 19:57:20 ——– d-sh–w- C:\$RECYCLE.BIN 2013-02-26 19:33:06 98816 —-a-w- c:\windows\sed.exe 2013-02-26 19:33:06 256000 —-a-w- c:\windows\PEV.exe 2013-02-26 19:33:06 208896 —-a-w- c:\windows\MBR.exe 2013-02-19 11:07:58 768000 —-a-w- c:\program files\common files\microsoft shared\vgx\VGX.dll 2013-02-19 04:22:50 2347008 —-a-w- c:\windows\system32\win32k.sys 2013-02-19 04:22:27 3967848 —-a-w- c:\windows\system32\ntkrnlpa.exe 2013-02-19 04:22:26 3913064 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-02-19 04:22:24 1293672 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-02-19 04:22:22 187752 —-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS 2013-02-19 04:22:18 169984 —-a-w- c:\windows\system32\winsrv.dll 2013-02-15 22:31:23 186432 —-a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll 2013-02-15 22:31:23 186432 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll 2013-02-12 06:49:49 ——– d—–w- c:\program files\ESET 2013-02-12 05:50:57 ——– d—–w- c:\windows\ERUNT 2013-02-12 05:50:27 ——– d—–w- C:\JRT 2013-02-08 07:51:32 ——– d—–w- c:\users\dave\appdata\local\LogMeIn 2013-02-08 07:51:25 53096 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll 2013-02-08 07:51:25 31592 —-a-w- c:\windows\system32\LMIport.dll 2013-02-08 07:51:23 84352 —-a-w- c:\windows\system32\LMIRfsClientNP.dll 2013-02-08 07:51:23 47640 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys 2013-02-08 07:51:14 92520 —-a-w- c:\windows\system32\LMIinit.dll 2013-02-08 07:51:07 ——– d—–w- c:\programdata\LogMeIn 2013-02-08 07:50:22 ——– d—–w- c:\program files\LogMeIn . ==================== Find3M ==================== . 2013-02-27 20:25:30 71024 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-02-27 20:25:30 691568 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2013-01-30 10:53:21 232336 ——w- c:\windows\system32\MpSigStub.exe 2013-01-20 23:59:04 195296 —-a-w- c:\windows\system32\drivers\MpFilter.sys 2013-01-20 23:59:04 100328 —-a-w- c:\windows\system32\drivers\NisDrvWFP.sys 2013-01-08 22:11:21 1800704 —-a-w- c:\windows\system32\jscript9.dll 2013-01-08 22:03:20 1129472 —-a-w- c:\windows\system32\wininet.dll 2013-01-08 22:03:12 1427968 —-a-w- c:\windows\system32\inetcpl.cpl 2013-01-08 21:59:02 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2013-01-08 21:58:29 420864 —-a-w- c:\windows\system32\vbscript.dll 2013-01-08 21:56:23 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-12-16 14:13:28 295424 —-a-w- c:\windows\system32\atmfd.dll 2012-12-16 14:13:20 34304 —-a-w- c:\windows\system32\atmlib.dll 2012-12-15 00:49:28 21104 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-12-07 12:26:17 308736 —-a-w- c:\windows\system32\Wpc.dll 2012-12-07 12:20:43 2576384 —-a-w- c:\windows\system32\gameux.dll 2012-11-30 04:47:45 293376 —-a-w- c:\windows\system32\KernelBase.dll 2012-11-30 02:55:25 271360 —-a-w- c:\windows\system32\conhost.exe 2012-11-30 02:38:59 6144 —ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2012-11-30 02:38:59 4608 —ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2012-11-30 02:38:59 3584 —ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2012-11-30 02:38:59 3072 —ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll . ============= FINISH: 16:39:15.35 ===============

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI