This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Avira Antivir crashes or hangs when scanning

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello:
I would appreciate if someone could take a look at my HJT log and tell me if there is a virus on my machine. I have tried to run Avira Antivir and it started scanning then stalled at 18% for the rest of the day. I experienced a similar thing with another computer in the past, and it turned out to be a virus. I don't want the same thing to happen with this computer.

Thanks for any help:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:35:02 PM, on 03/11/2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16455)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe
C:\Windows\vsnp2uvc.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_6_602_171.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_6_602_171.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Owner\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [Linksys Wireless Manager] "C:\Program Files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe" /cm /min /lcid 1033
O4 - HKLM\..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote Table Of Contents.onetoc2
O4 - Global Startup: HP Connections.lnk = C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxdiCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdiserv.exe
O23 - Service: lxdi_device - - C:\Windows\system32\lxdicoms.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 9783 bytes
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)












  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Thank you for your help, here are the logs you requested:

TDSSKiller

22:30:21.0327 4780 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
22:30:21.0855 4780 ============================================================
22:30:21.0855 4780 Current date / time: 2013/03/12 22:30:21.0855
22:30:21.0855 4780 SystemInfo:
22:30:21.0855 4780
22:30:21.0855 4780 OS Version: 6.0.6002 ServicePack: 2.0
22:30:21.0855 4780 Product type: Workstation
22:30:21.0855 4780 ComputerName: OWNER-PC
22:30:21.0855 4780 UserName: Owner
22:30:21.0855 4780 Windows directory: C:\Windows
22:30:21.0855 4780 System windows directory: C:\Windows
22:30:21.0855 4780 Processor architecture: Intel x86
22:30:21.0855 4780 Number of processors: 2
22:30:21.0856 4780 Page size: 0x1000
22:30:21.0856 4780 Boot type: Normal boot
22:30:21.0856 4780 ============================================================
22:30:22.0865 4780 Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
22:30:22.0867 4780 ============================================================
22:30:22.0867 4780 \Device\Harddisk0\DR0:
22:30:22.0867 4780 MBR partitions:
22:30:22.0867 4780 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xD25AAE3
22:30:22.0867 4780 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xD25AB22, BlocksNum 0xD38C9F
22:30:22.0867 4780 ============================================================
22:30:22.0880 4780 C: <-> \Device\Harddisk0\DR0\Partition1
22:30:22.0957 4780 D: <-> \Device\Harddisk0\DR0\Partition2
22:30:22.0957 4780 ============================================================
22:30:22.0957 4780 Initialize success
22:30:22.0957 4780 ============================================================
22:30:49.0765 3568 ============================================================
22:30:49.0765 3568 Scan started
22:30:49.0765 3568 Mode: Manual;
22:30:49.0765 3568 ============================================================
22:30:50.0125 3568 ================ Scan system memory ========================
22:30:50.0125 3568 System memory - ok
22:30:50.0125 3568 ================ Scan services =============================
22:30:50.0735 3568 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
22:30:50.0735 3568 ACPI - ok
22:30:50.0825 3568 [ E6D2486EC85A36B8336ED456D0317D96 ] AddFiltr C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
22:30:50.0855 3568 AddFiltr - ok
22:30:50.0945 3568 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
22:30:50.0995 3568 AdobeARMservice - ok
22:30:51.0144 3568 [ EA856F4A46320389D1899B2CAA7BF40F ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
22:30:51.0147 3568 AdobeFlashPlayerUpdateSvc - ok
22:30:51.0209 3568 [ 2EDC5BBAC6C651ECE337BDE8ED97C9FB ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
22:30:51.0232 3568 adp94xx - ok
22:30:51.0261 3568 [ B84088CA3CDCA97DA44A984C6CE1CCAD ] adpahci C:\Windows\system32\drivers\adpahci.sys
22:30:51.0267 3568 adpahci - ok
22:30:51.0299 3568 [ 7880C67BCCC27C86FD05AA2AFB5EA469 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
22:30:51.0300 3568 adpu160m - ok
22:30:51.0333 3568 [ 9AE713F8E30EFC2ABCCD84904333DF4D ] adpu320 C:\Windows\system32\drivers\adpu320.sys
22:30:51.0337 3568 adpu320 - ok
22:30:51.0411 3568 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
22:30:51.0413 3568 AeLookupSvc - ok
22:30:51.0481 3568 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
22:30:51.0537 3568 AFD - ok
22:30:51.0646 3568 [ EF23439CDD587F64C2C1B8825CEAD7D8 ] agp440 C:\Windows\system32\drivers\agp440.sys
22:30:51.0696 3568 agp440 - ok
22:30:51.0751 3568 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
22:30:51.0792 3568 aic78xx - ok
22:30:51.0852 3568 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
22:30:51.0853 3568 ALG - ok
22:30:51.0875 3568 [ 90395B64600EBB4552E26E178C94B2E4 ] aliide C:\Windows\system32\drivers\aliide.sys
22:30:51.0899 3568 aliide - ok
22:30:51.0929 3568 [ 2B13E304C9DFDFA5EB582F6A149FA2C7 ] amdagp C:\Windows\system32\drivers\amdagp.sys
22:30:51.0947 3568 amdagp - ok
22:30:51.0969 3568 [ 0577DF1D323FE75A739C787893D300EA ] amdide C:\Windows\system32\drivers\amdide.sys
22:30:51.0995 3568 amdide - ok
22:30:52.0035 3568 [ DC487885BCEF9F28EECE6FAC0E5DDFC5 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
22:30:52.0043 3568 AmdK7 - ok
22:30:52.0092 3568 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
22:30:52.0101 3568 AmdK8 - ok
22:30:52.0160 3568 [ 0A1CC583E8147004E4AD4625D7FBF88C ] AntiVirSchedulerService C:\Program Files\Avira\AntiVir Desktop\sched.exe
22:30:52.0161 3568 AntiVirSchedulerService - ok
22:30:52.0235 3568 [ C9A36EF935ACED86AEDF93E97E606911 ] AntiVirService C:\Program Files\Avira\AntiVir Desktop\avguard.exe
22:30:52.0238 3568 AntiVirService - ok
22:30:52.0291 3568 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
22:30:52.0292 3568 Appinfo - ok
22:30:52.0353 3568 [ 5F673180268BB1FDB69C99B6619FE379 ] arc C:\Windows\system32\drivers\arc.sys
22:30:52.0388 3568 arc - ok
22:30:52.0447 3568 [ 957F7540B5E7F602E44648C7DE5A1C05 ] arcsas C:\Windows\system32\drivers\arcsas.sys
22:30:52.0449 3568 arcsas - ok
22:30:52.0503 3568 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
22:30:52.0509 3568 AsyncMac - ok
22:30:52.0554 3568 [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi C:\Windows\system32\drivers\atapi.sys
22:30:52.0556 3568 atapi - ok
22:30:52.0604 3568 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
22:30:52.0611 3568 AudioEndpointBuilder - ok
22:30:52.0621 3568 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
22:30:52.0624 3568 Audiosrv - ok
22:30:52.0699 3568 [ D5541F0AFB767E85FC412FC609D96A74 ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys
22:30:52.0702 3568 avgntflt - ok
22:30:52.0746 3568 [ 7D967A682D4694DF7FA57D63A2DB01FE ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys
22:30:52.0750 3568 avipbb - ok
22:30:52.0804 3568 [ 53E56450DA16A1A7F0D002F511113F67 ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys
22:30:52.0838 3568 avkmgr - ok
22:30:52.0954 3568 [ 34A0A6386256080F52C74076C6157026 ] BCM43XV C:\Windows\system32\DRIVERS\bcmwl6.sys
22:30:53.0019 3568 BCM43XV - ok
22:30:53.0188 3568 [ 34A0A6386256080F52C74076C6157026 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl6.sys
22:30:53.0198 3568 BCM43XX - ok
22:30:53.0228 3568 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
22:30:53.0258 3568 Beep - ok
22:30:53.0318 3568 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
22:30:53.0318 3568 BFE - ok
22:30:53.0398 3568 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\System32\qmgr.dll
22:30:53.0438 3568 BITS - ok
22:30:53.0448 3568 blbdrive - ok
22:30:53.0488 3568 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
22:30:53.0508 3568 bowser - ok
22:30:53.0558 3568 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
22:30:53.0588 3568 BrFiltLo - ok
22:30:53.0618 3568 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
22:30:53.0648 3568 BrFiltUp - ok
22:30:53.0708 3568 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
22:30:53.0708 3568 Browser - ok
22:30:53.0748 3568 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
22:30:53.0748 3568 Brserid - ok
22:30:53.0818 3568 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
22:30:53.0858 3568 BrSerWdm - ok
22:30:53.0888 3568 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
22:30:53.0918 3568 BrUsbMdm - ok
22:30:53.0948 3568 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
22:30:53.0968 3568 BrUsbSer - ok
22:30:54.0018 3568 [ A820438255F37AB8BAA2BD59753A8D81 ] BthEnum C:\Windows\system32\DRIVERS\BthEnum.sys
22:30:54.0018 3568 BthEnum - ok
22:30:54.0058 3568 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
22:30:54.0068 3568 BTHMODEM - ok
22:30:54.0098 3568 [ B8C3D9DDF85FD197C3E5F849FEF71144 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
22:30:54.0118 3568 BthPan - ok
22:30:54.0148 3568 [ 4A74BBB2B6761789F42A6613479BDB1D ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys
22:30:54.0158 3568 BTHPORT - ok
22:30:54.0218 3568 [ A4C8377FA4A994E07075107DBE2E3DCE ] BthServ C:\Windows\System32\bthserv.dll
22:30:54.0218 3568 BthServ - ok
22:30:54.0238 3568 [ 1A407F9B707A06F55AA150F9AA072B09 ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys
22:30:54.0238 3568 BTHUSB - ok
22:30:54.0308 3568 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
22:30:54.0308 3568 cdfs - ok
22:30:54.0388 3568 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
22:30:54.0428 3568 cdrom - ok
22:30:54.0488 3568 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
22:30:54.0498 3568 CertPropSvc - ok
22:30:54.0548 3568 [ DA8E0AFC7BAA226C538EF53AC2F90897 ] circlass C:\Windows\system32\drivers\circlass.sys
22:30:54.0598 3568 circlass - ok
22:30:54.0928 3568 [ BD632712D67A30EDC7317682FE186CB0 ] CLCapSvc C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
22:30:54.0958 3568 CLCapSvc - ok
22:30:55.0028 3568 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
22:30:55.0038 3568 CLFS - ok
22:30:55.0088 3568 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:30:55.0108 3568 clr_optimization_v2.0.50727_32 - ok
22:30:55.0238 3568 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
22:30:55.0268 3568 clr_optimization_v4.0.30319_32 - ok
22:30:55.0318 3568 [ D008E122A28954ACFD10515E6A672CA7 ] CLSched C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
22:30:55.0368 3568 CLSched - ok
22:30:55.0408 3568 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
22:30:55.0438 3568 CmBatt - ok
22:30:55.0488 3568 [ 45201046C776FFDAF3FC8A0029C581C8 ] cmdide C:\Windows\system32\drivers\cmdide.sys
22:30:55.0518 3568 cmdide - ok
22:30:55.0598 3568 [ A4D44AB8423791DB757B38150EC599A4 ] CnxtHdAudService C:\Windows\system32\drivers\CHDRT32.sys
22:30:55.0628 3568 CnxtHdAudService - ok
22:30:55.0668 3568 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
22:30:55.0668 3568 Compbatt - ok
22:30:55.0668 3568 COMSysApp - ok
22:30:55.0678 3568 [ 2A213AE086BBEC5E937553C7D9A2B22C ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
22:30:55.0688 3568 crcdisk - ok
22:30:55.0718 3568 [ 22A7F883508176489F559EE745B5BF5D ] Crusoe C:\Windows\system32\drivers\crusoe.sys
22:30:55.0728 3568 Crusoe - ok
22:30:55.0768 3568 [ F1E8C34892336D33EDDCDFE44E474F64 ] CryptSvc C:\Windows\system32\cryptsvc.dll
22:30:55.0768 3568 CryptSvc - ok
22:30:55.0838 3568 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
22:30:55.0858 3568 DcomLaunch - ok
22:30:55.0888 3568 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
22:30:55.0898 3568 DfsC - ok
22:30:56.0008 3568 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
22:30:56.0078 3568 DFSR - ok
22:30:56.0129 3568 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
22:30:56.0129 3568 Dhcp - ok
22:30:56.0179 3568 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
22:30:56.0197 3568 disk - ok
22:30:56.0246 3568 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
22:30:56.0249 3568 Dnscache - ok
22:30:56.0293 3568 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
22:30:56.0296 3568 dot3svc - ok
22:30:56.0376 3568 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
22:30:56.0387 3568 DPS - ok
22:30:56.0419 3568 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
22:30:56.0443 3568 drmkaud - ok
22:30:56.0504 3568 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
22:30:56.0548 3568 DXGKrnl - ok
22:30:56.0605 3568 [ C0B00E55CF82D122D25983C7A6A53DEA ] E100B C:\Windows\system32\DRIVERS\e100b325.sys
22:30:56.0628 3568 E100B - ok
22:30:56.0674 3568 [ F88FB26547FD2CE6D0A5AF2985892C48 ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
22:30:56.0696 3568 E1G60 - ok
22:30:56.0754 3568 [ A6476585B4FEFEE46A9F42E4D2BFDFA4 ] eabfiltr C:\Windows\system32\DRIVERS\eabfiltr.sys
22:30:56.0782 3568 eabfiltr - ok
22:30:56.0827 3568 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
22:30:56.0841 3568 EapHost - ok
22:30:56.0885 3568 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
22:30:56.0887 3568 Ecache - ok
22:30:56.0958 3568 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
22:30:56.0963 3568 ehRecvr - ok
22:30:56.0990 3568 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
22:30:56.0994 3568 ehSched - ok
22:30:57.0007 3568 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
22:30:57.0009 3568 ehstart - ok
22:30:57.0067 3568 [ E8F3F21A71720C84BCF423B80028359F ] elxstor C:\Windows\system32\drivers\elxstor.sys
22:30:57.0073 3568 elxstor - ok
22:30:57.0157 3568 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
22:30:57.0169 3568 EMDMgmt - ok
22:30:57.0326 3568 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
22:30:57.0338 3568 EventSystem - ok
22:30:57.0387 3568 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
22:30:57.0415 3568 exfat - ok
22:30:57.0515 3568 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
22:30:57.0570 3568 fastfat - ok
22:30:57.0610 3568 [ 63BDADA84951B9C03E641800E176898A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
22:30:57.0637 3568 fdc - ok
22:30:57.0678 3568 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
22:30:57.0696 3568 fdPHost - ok
22:30:57.0732 3568 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
22:30:57.0763 3568 FDResPub - ok
22:30:57.0802 3568 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
22:30:57.0826 3568 FileInfo - ok
22:30:57.0866 3568 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
22:30:57.0868 3568 Filetrace - ok
22:30:57.0887 3568 [ 6603957EFF5EC62D25075EA8AC27DE68 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
22:30:57.0894 3568 flpydisk - ok
22:30:57.0951 3568 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
22:30:57.0955 3568 FltMgr - ok
22:30:58.0095 3568 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll
22:30:58.0129 3568 FontCache - ok
22:30:58.0202 3568 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
22:30:58.0252 3568 FontCache3.0.0.0 - ok
22:30:58.0291 3568 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
22:30:58.0323 3568 Fs_Rec - ok
22:30:58.0366 3568 [ 4E1CD0A45C50A8882616CAE5BF82F3C5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
22:30:58.0394 3568 gagp30kx - ok
22:30:58.0484 3568 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
22:30:58.0506 3568 gpsvc - ok
22:30:58.0548 3568 [ DE15777902A5D9121857D155873A1D1B ] HBtnKey C:\Windows\system32\DRIVERS\cpqbttn.sys
22:30:58.0582 3568 HBtnKey - ok
22:30:58.0642 3568 [ DE4020F928A2F8A6327F5687F36D361B ] HdAudAddService C:\Windows\system32\drivers\CHDART.sys
22:30:58.0645 3568 HdAudAddService - ok
22:30:58.0702 3568 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
22:30:58.0725 3568 HDAudBus - ok
22:30:58.0755 3568 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
22:30:58.0787 3568 HidBth - ok
22:30:58.0806 3568 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
22:30:58.0831 3568 HidIr - ok
22:30:58.0868 3568 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\system32\hidserv.dll
22:30:58.0870 3568 hidserv - ok
22:30:58.0897 3568 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
22:30:58.0920 3568 HidUsb - ok
22:30:58.0960 3568 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
22:30:58.0964 3568 hkmsvc - ok
22:30:59.0023 3568 [ 0D26C438E2938A3E6BDD91173BC96FF0 ] HP Health Check Service c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
22:30:59.0025 3568 HP Health Check Service - ok
22:30:59.0066 3568 [ DF353B401001246853763C4B7AAA6F50 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
22:30:59.0075 3568 HpCISSs - ok
22:30:59.0109 3568 [ 04C1DCBB226C6AE647B794833CE3CEB6 ] hpqwmiex C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
22:30:59.0112 3568 hpqwmiex - ok
22:30:59.0169 3568 [ 46D67209550973257601A533E2AC5785 ] HSFHWAZL C:\Windows\system32\DRIVERS\VSTAZL3.SYS
22:30:59.0182 3568 HSFHWAZL - ok
22:30:59.0265 3568 [ 53229DCF431D76434816CD29251168A0 ] HSF_DPV C:\Windows\system32\DRIVERS\HSX_DPV.sys
22:30:59.0371 3568 HSF_DPV - ok
22:30:59.0407 3568 [ 31F949D452201F2F0AF0C88D7DB512CD ] HSXHWAZL C:\Windows\system32\DRIVERS\HSXHWAZL.sys
22:30:59.0471 3568 HSXHWAZL - ok
22:30:59.0519 3568 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys
22:30:59.0528 3568 HTTP - ok
22:30:59.0564 3568 [ 324C2152FF2C61ABAE92D09F3CCA4D63 ] i2omp C:\Windows\system32\drivers\i2omp.sys
22:30:59.0596 3568 i2omp - ok
22:30:59.0657 3568 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
22:30:59.0702 3568 i8042prt - ok
22:30:59.0792 3568 [ 496DB78E6A0C4C44023D9A92B4A7AC31 ] ialm C:\Windows\system32\DRIVERS\igdkmd32.sys
22:30:59.0913 3568 ialm - ok
22:30:59.0943 3568 [ C957BF4B5D80B46C5017BF0101E6C906 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
22:30:59.0949 3568 iaStorV - ok
22:31:00.0021 3568 [ 6F95324909B502E2651442C1548AB12F ] IDriverT C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe
22:31:00.0054 3568 IDriverT - ok
22:31:00.0135 3568 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
22:31:00.0190 3568 idsvc - ok
22:31:00.0233 3568 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
22:31:00.0294 3568 iirsp - ok
22:31:00.0412 3568 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
22:31:00.0442 3568 IKEEXT - ok
22:31:00.0492 3568 [ 97469037714070E45194ED318D636401 ] intelide C:\Windows\system32\drivers\intelide.sys
22:31:00.0492 3568 intelide - ok
22:31:00.0522 3568 [ CE44CC04262F28216DD4341E9E36A16F ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
22:31:00.0522 3568 intelppm - ok
22:31:00.0592 3568 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
22:31:00.0632 3568 IPBusEnum - ok
22:31:00.0682 3568 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:31:00.0712 3568 IpFilterDriver - ok
22:31:00.0762 3568 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
22:31:00.0782 3568 iphlpsvc - ok
22:31:00.0782 3568 IpInIp - ok
22:31:00.0812 3568 [ 40F34F8ABA2A015D780E4B09138B6C17 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
22:31:00.0812 3568 IPMIDRV - ok
22:31:00.0892 3568 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
22:31:00.0932 3568 IPNAT - ok
22:31:00.0992 3568 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
22:31:01.0042 3568 IRENUM - ok
22:31:01.0082 3568 [ 350FCA7E73CF65BCEF43FAE1E4E91293 ] isapnp C:\Windows\system32\drivers\isapnp.sys
22:31:01.0102 3568 isapnp - ok
22:31:01.0162 3568 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
22:31:01.0163 3568 iScsiPrt - ok
22:31:01.0191 3568 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
22:31:01.0200 3568 iteatapi - ok
22:31:01.0228 3568 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
22:31:01.0237 3568 iteraid - ok
22:31:01.0269 3568 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
22:31:01.0312 3568 kbdclass - ok
22:31:01.0350 3568 [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
22:31:01.0390 3568 kbdhid - ok
22:31:01.0434 3568 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
22:31:01.0461 3568 KeyIso - ok
22:31:01.0507 3568 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
22:31:01.0521 3568 KSecDD - ok
22:31:01.0597 3568 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
22:31:01.0619 3568 KtmRm - ok
22:31:01.0679 3568 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\system32\srvsvc.dll
22:31:01.0690 3568 LanmanServer - ok
22:31:01.0733 3568 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
22:31:01.0739 3568 LanmanWorkstation - ok
22:31:01.0803 3568 [ 6E5DAC168D1FF9843E84A59D51D31107 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
22:31:01.0805 3568 LightScribeService - ok
22:31:01.0834 3568 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
22:31:01.0836 3568 lltdio - ok
22:31:01.0875 3568 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
22:31:01.0924 3568 lltdsvc - ok
22:31:01.0952 3568 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
22:31:01.0957 3568 lmhosts - ok
22:31:02.0002 3568 [ A2262FB9F28935E862B4DB46438C80D2 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
22:31:02.0005 3568 LSI_FC - ok
22:31:02.0027 3568 [ 30D73327D390F72A62F32C103DAF1D6D ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
22:31:02.0037 3568 LSI_SAS - ok
22:31:02.0082 3568 [ E1E36FEFD45849A95F1AB81DE0159FE3 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
22:31:02.0105 3568 LSI_SCSI - ok
22:31:02.0156 3568 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
22:31:02.0167 3568 luafv - ok
22:31:02.0259 3568 [ DA4F31909E1FD4AB342813867B801582 ] lxdiCATSCustConnectService C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdiserv.exe
22:31:02.0282 3568 lxdiCATSCustConnectService - ok
22:31:02.0288 3568 lxdi_device - ok
22:31:02.0353 3568 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
22:31:02.0411 3568 Mcx2Svc - ok
22:31:02.0442 3568 [ 0CEA2D0D3FA284B85ED5B68365114F76 ] mdmxsdk C:\Windows\system32\DRIVERS\mdmxsdk.sys
22:31:02.0478 3568 mdmxsdk - ok
22:31:02.0539 3568 [ D153B14FC6598EAE8422A2037553ADCE ] megasas C:\Windows\system32\drivers\megasas.sys
22:31:02.0573 3568 megasas - ok
22:31:02.0599 3568 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
22:31:02.0609 3568 MMCSS - ok
22:31:02.0633 3568 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
22:31:02.0662 3568 Modem - ok
22:31:02.0709 3568 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
22:31:02.0711 3568 monitor - ok
22:31:02.0747 3568 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
22:31:02.0778 3568 mouclass - ok
22:31:02.0804 3568 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
22:31:02.0853 3568 mouhid - ok
22:31:02.0903 3568 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
22:31:02.0904 3568 MountMgr - ok
22:31:02.0965 3568 [ 8A7C8F4C713E70D73946833D76B77035 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
22:31:02.0995 3568 MozillaMaintenance - ok
22:31:03.0035 3568 [ 583A41F26278D9E0EA548163D6139397 ] mpio C:\Windows\system32\drivers\mpio.sys
22:31:03.0073 3568 mpio - ok
22:31:03.0132 3568 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
22:31:03.0138 3568 mpsdrv - ok
22:31:03.0189 3568 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
22:31:03.0225 3568 MpsSvc - ok
22:31:03.0272 3568 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
22:31:03.0272 3568 Mraid35x - ok
22:31:03.0302 3568 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
22:31:03.0302 3568 MRxDAV - ok
22:31:03.0342 3568 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
22:31:03.0342 3568 mrxsmb - ok
22:31:03.0362 3568 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:31:03.0372 3568 mrxsmb10 - ok
22:31:03.0382 3568 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:31:03.0392 3568 mrxsmb20 - ok
22:31:03.0422 3568 [ 742AED7939E734C36B7E8D6228CE26B7 ] msahci C:\Windows\system32\drivers\msahci.sys
22:31:03.0432 3568 msahci - ok
22:31:03.0452 3568 [ 3FC82A2AE4CC149165A94699183D3028 ] msdsm C:\Windows\system32\drivers\msdsm.sys
22:31:03.0492 3568 msdsm - ok
22:31:03.0532 3568 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
22:31:03.0532 3568 MSDTC - ok
22:31:03.0582 3568 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
22:31:03.0592 3568 Msfs - ok
22:31:03.0622 3568 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
22:31:03.0622 3568 msisadrv - ok
22:31:03.0652 3568 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
22:31:03.0682 3568 MSiSCSI - ok
22:31:03.0692 3568 msiserver - ok
22:31:03.0722 3568 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
22:31:03.0722 3568 MSKSSRV - ok
22:31:03.0752 3568 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
22:31:03.0772 3568 MSPCLOCK - ok
22:31:03.0802 3568 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
22:31:03.0832 3568 MSPQM - ok
22:31:03.0872 3568 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
22:31:03.0882 3568 MsRPC - ok
22:31:03.0922 3568 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
22:31:03.0922 3568 mssmbios - ok
22:31:03.0952 3568 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
22:31:03.0992 3568 MSTEE - ok
22:31:04.0032 3568 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
22:31:04.0032 3568 Mup - ok
22:31:04.0122 3568 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
22:31:04.0132 3568 napagent - ok
22:31:04.0182 3568 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
22:31:04.0182 3568 NativeWifiP - ok
22:31:04.0242 3568 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
22:31:04.0252 3568 NDIS - ok
22:31:04.0292 3568 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
22:31:04.0322 3568 NdisTapi - ok
22:31:04.0362 3568 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
22:31:04.0392 3568 Ndisuio - ok
22:31:04.0472 3568 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
22:31:04.0472 3568 NdisWan - ok
22:31:04.0532 3568 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
22:31:04.0582 3568 NDProxy - ok
22:31:04.0612 3568 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
22:31:04.0612 3568 NetBIOS - ok
22:31:04.0652 3568 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
22:31:04.0692 3568 netbt - ok
22:31:04.0712 3568 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe
22:31:04.0712 3568 Netlogon - ok
22:31:04.0772 3568 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
22:31:04.0772 3568 Netman - ok
22:31:04.0902 3568 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
22:31:04.0922 3568 netprofm - ok
22:31:04.0962 3568 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:31:04.0982 3568 NetTcpPortSharing - ok
22:31:05.0032 3568 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
22:31:05.0052 3568 nfrd960 - ok
22:31:05.0142 3568 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
22:31:05.0152 3568 NlaSvc - ok
22:31:05.0462 3568 [ 0F078C31E9123DF22A49C54B26CE556A ] nmservice C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
22:31:05.0472 3568 nmservice - ok
22:31:05.0532 3568 [ C5F0202A00227AECB69E722C52385FFC ] NPF C:\Windows\system32\drivers\npf.sys
22:31:05.0562 3568 NPF - ok
22:31:05.0592 3568 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
22:31:05.0602 3568 Npfs - ok
22:31:05.0632 3568 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
22:31:05.0632 3568 nsi - ok
22:31:05.0652 3568 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
22:31:05.0652 3568 nsiproxy - ok
22:31:05.0832 3568 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
22:31:05.0882 3568 Ntfs - ok
22:31:05.0912 3568 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
22:31:05.0932 3568 ntrigdigi - ok
22:31:05.0972 3568 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
22:31:06.0002 3568 Null - ok
22:31:06.0072 3568 [ D958A2B5F6AD5C3B8CCDC4D7DA62466C ] NVENETFD C:\Windows\system32\DRIVERS\nvmfdx32.sys
22:31:06.0192 3568 NVENETFD - ok
22:31:07.0239 3568 [ B36C3B866B0D47E2E2856EC8FD746E39 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
22:31:07.0478 3568 nvlddmkm - ok
22:31:07.0510 3568 [ E69E946F80C1C31C53003BFBF50CBB7C ] nvraid C:\Windows\system32\drivers\nvraid.sys
22:31:07.0540 3568 nvraid - ok
22:31:07.0579 3568 [ ADFDD343B1D3A9E061F17C730F1E83DC ] nvsmu C:\Windows\system32\DRIVERS\nvsmu.sys
22:31:07.0581 3568 nvsmu - ok
22:31:07.0618 3568 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
22:31:07.0619 3568 nvstor - ok
22:31:07.0654 3568 [ CF672C71844A3B407EB86042829BCE09 ] nvsvc C:\Windows\system32\nvvsvc.exe
22:31:07.0658 3568 nvsvc - ok
22:31:07.0688 3568 [ 07C186427EB8FCC3D8D7927187F260F7 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
22:31:07.0691 3568 nv_agp - ok
22:31:07.0700 3568 NwlnkFlt - ok
22:31:07.0707 3568 NwlnkFwd - ok
22:31:08.0003 3568 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
22:31:08.0037 3568 odserv - ok
22:31:08.0075 3568 [ 6F310E890D46E246E0E261A63D9B36B4 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
22:31:08.0078 3568 ohci1394 - ok
22:31:08.0115 3568 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:31:08.0145 3568 ose - ok
22:31:08.0242 3568 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
22:31:08.0299 3568 p2pimsvc - ok
22:31:08.0329 3568 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
22:31:08.0339 3568 p2psvc - ok
22:31:08.0409 3568 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
22:31:08.0439 3568 Parport - ok
22:31:08.0469 3568 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
22:31:08.0469 3568 partmgr - ok
22:31:08.0479 3568 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
22:31:08.0509 3568 Parvdm - ok
22:31:08.0549 3568 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
22:31:08.0559 3568 PcaSvc - ok
22:31:08.0589 3568 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
22:31:08.0609 3568 pci - ok
22:31:08.0639 3568 [ 1636D43F10416AEB483BC6001097B26C ] pciide C:\Windows\system32\drivers\pciide.sys
22:31:08.0639 3568 pciide - ok
22:31:08.0679 3568 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
22:31:08.0709 3568 pcmcia - ok
22:31:08.0769 3568 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
22:31:08.0879 3568 PEAUTH - ok
22:31:09.0089 3568 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
22:31:09.0149 3568 pla - ok
22:31:09.0199 3568 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
22:31:09.0209 3568 PlugPlay - ok
22:31:09.0249 3568 [ B63A3AE87ED0AC525B3AA88B39608BFC ] pnarp C:\Windows\system32\DRIVERS\pnarp.sys
22:31:09.0269 3568 pnarp - ok
22:31:09.0309 3568 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
22:31:09.0319 3568 PNRPAutoReg - ok
22:31:09.0389 3568 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
22:31:09.0389 3568 PNRPsvc - ok
22:31:09.0539 3568 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
22:31:09.0569 3568 PolicyAgent - ok
22:31:09.0609 3568 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
22:31:09.0629 3568 PptpMiniport - ok
22:31:09.0659 3568 [ 0E3CEF5D28B40CF273281D620C50700A ] Processor C:\Windows\system32\drivers\processr.sys
22:31:09.0689 3568 Processor - ok
22:31:09.0729 3568 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
22:31:09.0729 3568 ProfSvc - ok
22:31:09.0739 3568 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
22:31:09.0749 3568 ProtectedStorage - ok
22:31:09.0769 3568 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
22:31:09.0769 3568 PSched - ok
22:31:09.0809 3568 [ 633CC728D6493C4263368A86928B0BFD ] purendis C:\Windows\system32\DRIVERS\purendis.sys
22:31:09.0809 3568 purendis - ok
22:31:09.0869 3568 [ FEFFCFDC528764A04C8ED63D5FA6E711 ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
22:31:09.0879 3568 PxHelp20 - ok
22:31:09.0939 3568 [ CCDAC889326317792480C0A67156A1EC ] ql2300 C:\Windows\system32\drivers\ql2300.sys
22:31:09.0999 3568 ql2300 - ok
22:31:10.0039 3568 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
22:31:10.0069 3568 ql40xx - ok
22:31:10.0169 3568 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
22:31:10.0179 3568 QWAVE - ok
22:31:10.0229 3568 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
22:31:10.0239 3568 QWAVEdrv - ok
22:31:10.0349 3568 [ 70DBDAB246C18B78E2200D6401D038BE ] RapiMgr C:\Windows\WindowsMobile\rapimgr.dll
22:31:10.0379 3568 RapiMgr - ok
22:31:10.0409 3568 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
22:31:10.0439 3568 RasAcd - ok
22:31:10.0469 3568 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
22:31:10.0479 3568 RasAuto - ok
22:31:10.0509 3568 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
22:31:10.0539 3568 Rasl2tp - ok
22:31:10.0669 3568 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
22:31:10.0699 3568 RasMan - ok
22:31:10.0739 3568 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
22:31:10.0739 3568 RasPppoe - ok
22:31:10.0789 3568 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
22:31:10.0789 3568 RasSstp - ok
22:31:10.0839 3568 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
22:31:10.0839 3568 rdbss - ok
22:31:10.0879 3568 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
22:31:10.0909 3568 RDPCDD - ok
22:31:10.0949 3568 [ E8BD98D46F2ED77132BA927FCCB47D8B ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
22:31:10.0999 3568 rdpdr - ok
22:31:11.0009 3568 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
22:31:11.0019 3568 RDPENCDD - ok
22:31:11.0069 3568 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
22:31:11.0109 3568 RDPWD - ok
22:31:11.0159 3568 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
22:31:11.0169 3568 RemoteAccess - ok
22:31:11.0189 3568 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
22:31:11.0199 3568 RemoteRegistry - ok
22:31:11.0219 3568 [ 7EC90C316177BA3F1BCE92005264B447 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
22:31:11.0219 3568 RFCOMM - ok
22:31:11.0263 3568 [ D85E3FA9F5B1F29BB4ED185C450D1470 ] rimmptsk C:\Windows\system32\DRIVERS\rimmptsk.sys
22:31:11.0289 3568 rimmptsk - ok
22:31:11.0324 3568 [ DB8EB01C58C9FADA00C70B1775278AE0 ] rimsptsk C:\Windows\system32\DRIVERS\rimsptsk.sys
22:31:11.0325 3568 rimsptsk - ok
22:31:11.0348 3568 [ 6C1F93C0760C9F79A1869D07233DF39D ] rismxdp C:\Windows\system32\DRIVERS\rixdptsk.sys
22:31:11.0379 3568 rismxdp - ok
22:31:11.0488 3568 [ AD1411A7EA50F2F97A73A3F51153066E ] RoxMediaDB9 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
22:31:11.0605 3568 RoxMediaDB9 - ok
22:31:11.0665 3568 [ 5380F54FAA2D980C9C9A65E87A3CD7F1 ] rpcapd C:\Program Files\WinPcap\rpcapd.exe
22:31:11.0694 3568 rpcapd - ok
22:31:11.0723 3568 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
22:31:11.0725 3568 RpcLocator - ok
22:31:11.0755 3568 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll
22:31:11.0762 3568 RpcSs - ok
22:31:11.0806 3568 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
22:31:11.0808 3568 rspndr - ok
22:31:11.0817 3568 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe
22:31:11.0819 3568 SamSs - ok
22:31:11.0847 3568 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
22:31:11.0850 3568 sbp2port - ok
22:31:11.0897 3568 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
22:31:11.0900 3568 SCardSvr - ok
22:31:11.0961 3568 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll
22:31:11.0983 3568 Schedule - ok
22:31:12.0013 3568 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
22:31:12.0015 3568 SCPolicySvc - ok
22:31:12.0049 3568 [ 8F36B54688C31EED4580129040C6A3D3 ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys
22:31:12.0077 3568 sdbus - ok
22:31:12.0124 3568 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
22:31:12.0127 3568 SDRSVC - ok
22:31:12.0163 3568 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
22:31:12.0190 3568 secdrv - ok
22:31:12.0231 3568 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
22:31:12.0235 3568 seclogon - ok
22:31:12.0288 3568 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll
22:31:12.0292 3568 SENS - ok
22:31:12.0317 3568 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys
22:31:12.0349 3568 Serenum - ok
22:31:12.0374 3568 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
22:31:12.0377 3568 Serial - ok
22:31:12.0397 3568 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
22:31:12.0427 3568 sermouse - ok
22:31:12.0482 3568 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
22:31:12.0487 3568 SessionEnv - ok
22:31:12.0521 3568 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\DRIVERS\sffdisk.sys
22:31:12.0526 3568 sffdisk - ok
22:31:12.0543 3568 [ 8FD08A310645FE872EEEC6E08C6BF3EE ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
22:31:12.0573 3568 sffp_mmc - ok
22:31:12.0608 3568 [ 9F66A46C55D6F1CCABC79BB7AFCCC545 ] sffp_sd C:\Windows\system32\DRIVERS\sffp_sd.sys
22:31:12.0636 3568 sffp_sd - ok
22:31:12.0658 3568 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
22:31:12.0664 3568 sfloppy - ok
22:31:12.0699 3568 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
22:31:12.0704 3568 SharedAccess - ok
22:31:12.0735 3568 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
22:31:12.0743 3568 ShellHWDetection - ok
22:31:12.0774 3568 [ D2A595D6EEBEEAF4334F8E50EFBC9931 ] sisagp C:\Windows\system32\drivers\sisagp.sys
22:31:12.0797 3568 sisagp - ok
22:31:12.0824 3568 [ CEDD6F4E7D84E9F98B34B3FE988373AA ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
22:31:12.0825 3568 SiSRaid2 - ok
22:31:12.0865 3568 [ DF843C528C4F69D12CE41CE462E973A7 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
22:31:12.0887 3568 SiSRaid4 - ok
22:31:12.0950 3568 [ 8C4F0DCC6A5100D48F9B2F950CDD220F ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
22:31:12.0953 3568 SkypeUpdate - ok
22:31:13.0206 3568 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
22:31:13.0359 3568 slsvc - ok
22:31:13.0414 3568 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
22:31:13.0417 3568 SLUINotify - ok
22:31:13.0485 3568 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
22:31:13.0513 3568 Smb - ok
22:31:13.0559 3568 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
22:31:13.0562 3568 SNMPTRAP - ok
22:31:13.0987 3568 [ 5140166BBCAFE1393D4669353A1F8C0A ] SNP2UVC C:\Windows\system32\DRIVERS\snp2uvc.sys
22:31:14.0186 3568 SNP2UVC - ok
22:31:14.0234 3568 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
22:31:14.0272 3568 spldr - ok
22:31:14.0307 3568 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe
22:31:14.0311 3568 Spooler - ok
22:31:14.0467 3568 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys
22:31:14.0478 3568 srv - ok
22:31:14.0521 3568 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
22:31:14.0524 3568 srv2 - ok
22:31:14.0546 3568 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
22:31:14.0550 3568 srvnet - ok
22:31:14.0606 3568 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
22:31:14.0611 3568 SSDPSRV - ok
22:31:14.0635 3568 [ A36EE93698802CD899F98BFD553D8185 ] ssmdrv C:\Windows\system32\DRIVERS\ssmdrv.sys
22:31:14.0637 3568 ssmdrv - ok
22:31:14.0682 3568 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
22:31:14.0687 3568 SstpSvc - ok
22:31:14.0734 3568 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
22:31:14.0745 3568 stisvc - ok
22:31:14.0855 3568 [ B254B1434208F280EDF3785613DCC41B ] stllssvr C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
22:31:14.0855 3568 stllssvr - ok
22:31:14.0895 3568 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
22:31:14.0915 3568 swenum - ok
22:31:15.0065 3568 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
22:31:15.0075 3568 swprv - ok
22:31:15.0105 3568 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
22:31:15.0165 3568 Symc8xx - ok
22:31:15.0185 3568 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
22:31:15.0205 3568 Sym_hi - ok
22:31:15.0235 3568 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
22:31:15.0275 3568 Sym_u3 - ok
22:31:15.0325 3568 [ F5D926807BD9BC0AF68F9376144DE425 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
22:31:15.0335 3568 SynTP - ok
22:31:15.0465 3568 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
22:31:15.0515 3568 SysMain - ok
22:31:15.0565 3568 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
22:31:15.0575 3568 TabletInputService - ok
22:31:15.0615 3568 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
22:31:15.0645 3568 TapiSrv - ok
22:31:15.0685 3568 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
22:31:15.0685 3568 TBS - ok
22:31:15.0755 3568 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
22:31:15.0795 3568 Tcpip - ok
22:31:15.0835 3568 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
22:31:15.0845 3568 Tcpip6 - ok
22:31:15.0885 3568 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
22:31:15.0885 3568 tcpipreg - ok
22:31:15.0915 3568 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
22:31:15.0955 3568 TDPIPE - ok
22:31:15.0995 3568 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
22:31:16.0005 3568 TDTCP - ok
22:31:16.0055 3568 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
22:31:16.0105 3568 tdx - ok
22:31:16.0125 3568 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
22:31:16.0155 3568 TermDD - ok
22:31:16.0205 3568 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
22:31:16.0235 3568 TermService - ok
22:31:16.0265 3568 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll
22:31:16.0275 3568 Themes - ok
22:31:16.0295 3568 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
22:31:16.0295 3568 THREADORDER - ok
22:31:16.0326 3568 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
22:31:16.0326 3568 TrkWks - ok
22:31:16.0376 3568 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
22:31:16.0377 3568 TrustedInstaller - ok
22:31:16.0422 3568 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
22:31:16.0423 3568 tssecsrv - ok
22:31:16.0470 3568 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
22:31:16.0503 3568 tunmp - ok
22:31:16.0536 3568 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
22:31:16.0538 3568 tunnel - ok
22:31:16.0566 3568 [ C3ADE15414120033A36C0F293D4A4121 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
22:31:16.0568 3568 uagp35 - ok
22:31:16.0603 3568 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
22:31:16.0636 3568 udfs - ok
22:31:16.0678 3568 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
22:31:16.0682 3568 UI0Detect - ok
22:31:16.0700 3568 [ 75E6890EBFCE0841D3291B02E7A8BDB0 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
22:31:16.0732 3568 uliagpkx - ok
22:31:16.0757 3568 [ 3CD4EA35A6221B85DCC25DAA46313F8D ] uliahci C:\Windows\system32\drivers\uliahci.sys
22:31:16.0792 3568 uliahci - ok
22:31:16.0844 3568 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
22:31:16.0875 3568 UlSata - ok
22:31:16.0893 3568 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
22:31:16.0925 3568 ulsata2 - ok
22:31:16.0974 3568 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
22:31:16.0997 3568 umbus - ok
22:31:17.0048 3568 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
22:31:17.0056 3568 upnphost - ok
22:31:17.0080 3568 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
22:31:17.0105 3568 usbccgp - ok
22:31:17.0142 3568 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
22:31:17.0145 3568 usbcir - ok
22:31:17.0195 3568 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
22:31:17.0197 3568 usbehci - ok
22:31:17.0240 3568 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
22:31:17.0245 3568 usbhub - ok
22:31:17.0283 3568 [ CE697FEE0D479290D89BEC80DFE793B7 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
22:31:17.0323 3568 usbohci - ok
22:31:17.0352 3568 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
22:31:17.0377 3568 usbprint - ok
22:31:17.0427 3568 [ B1F95285C08DDFE00C0B955462637EC7 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
22:31:17.0487 3568 usbscan - ok
22:31:17.0510 3568 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:31:17.0536 3568 USBSTOR - ok
22:31:17.0582 3568 [ 325DBBACB8A36AF9988CCF40EAC228CC ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
22:31:17.0632 3568 usbuhci - ok
22:31:17.0685 3568 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
22:31:17.0688 3568 usbvideo - ok
22:31:17.0734 3568 [ 35C9095FA7076466AFBFC5B9EC4B779E ] usb_rndisx C:\Windows\system32\DRIVERS\usb8023x.sys
22:31:17.0755 3568 usb_rndisx - ok
22:31:17.0803 3568 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
22:31:17.0824 3568 UxSms - ok
22:31:17.0872 3568 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
22:31:17.0906 3568 vds - ok
22:31:17.0951 3568 [ 7D92BE0028ECDEDEC74617009084B5EF ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
22:31:17.0973 3568 vga - ok
22:31:18.0005 3568 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
22:31:18.0034 3568 VgaSave - ok
22:31:18.0073 3568 [ 045D9961E591CF0674A920B6BA3BA5CB ] viaagp C:\Windows\system32\drivers\viaagp.sys
22:31:18.0097 3568 viaagp - ok
22:31:18.0136 3568 [ 56A4DE5F02F2E88182B0981119B4DD98 ] ViaC7 C:\Windows\system32\drivers\viac7.sys
22:31:18.0166 3568 ViaC7 - ok
22:31:18.0192 3568 [ FD2E3175FCADA350C7AB4521DCA187EC ] viaide C:\Windows\system32\drivers\viaide.sys
22:31:18.0216 3568 viaide - ok
22:31:18.0264 3568 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
22:31:18.0266 3568 volmgr - ok
22:31:18.0326 3568 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
22:31:18.0332 3568 volmgrx - ok
22:31:18.0422 3568 [ 147281C01FCB1DF9252DE2A10D5E7093 ] volsnap C:\Windows\system32\drivers\volsnap.sys
22:31:18.0442 3568 volsnap - ok
22:31:18.0502 3568 [ D984439746D42B30FC65A4C3546C6829 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
22:31:18.0532 3568 vsmraid - ok
22:31:18.0592 3568 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
22:31:18.0622 3568 VSS - ok
22:31:18.0672 3568 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
22:31:18.0672 3568 W32Time - ok
22:31:18.0702 3568 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
22:31:18.0712 3568 WacomPen - ok
22:31:18.0752 3568 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
22:31:18.0782 3568 Wanarp - ok
22:31:18.0782 3568 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
22:31:18.0782 3568 Wanarpv6 - ok
22:31:18.0832 3568 [ 779F9C90D3FE9C70B6FFD8EF035F3E83 ] WcesComm C:\Windows\WindowsMobile\wcescomm.dll
22:31:18.0842 3568 WcesComm - ok
22:31:18.0892 3568 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
22:31:18.0892 3568 wcncsvc - ok
22:31:18.0922 3568 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
22:31:18.0932 3568 WcsPlugInService - ok
22:31:18.0962 3568 [ AFC5AD65B991C1E205CF25CFDBF7A6F4 ] Wd C:\Windows\system32\drivers\wd.sys
22:31:18.0992 3568 Wd - ok
22:31:19.0042 3568 [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
22:31:19.0052 3568 Wdf01000 - ok
22:31:19.0092 3568 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
22:31:19.0102 3568 WdiServiceHost - ok
22:31:19.0102 3568 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
22:31:19.0112 3568 WdiSystemHost - ok
22:31:19.0152 3568 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
22:31:19.0152 3568 WebClient - ok
22:31:19.0202 3568 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
22:31:19.0202 3568 Wecsvc - ok
22:31:19.0262 3568 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
22:31:19.0262 3568 wercplsupport - ok
22:31:19.0292 3568 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
22:31:19.0302 3568 WerSvc - ok
22:31:19.0352 3568 [ 6D2350BB6E77E800FC4BE4E5B7A2E89A ] winachsf C:\Windows\system32\DRIVERS\HSX_CNXT.sys
22:31:19.0362 3568 winachsf - ok
22:31:19.0422 3568 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
22:31:19.0422 3568 WinDefend - ok
22:31:19.0432 3568 WinHttpAutoProxySvc - ok
22:31:19.0482 3568 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
22:31:19.0492 3568 Winmgmt - ok
22:31:19.0562 3568 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
22:31:19.0602 3568 WinRM - ok
22:31:19.0662 3568 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll
22:31:19.0672 3568 Wlansvc - ok
22:31:19.0702 3568 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
22:31:19.0702 3568 WmiAcpi - ok
22:31:19.0742 3568 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
22:31:19.0752 3568 wmiApSrv - ok
22:31:19.0832 3568 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
22:31:19.0862 3568 WMPNetworkSvc - ok
22:31:19.0892 3568 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll
22:31:19.0902 3568 WPCSvc - ok
22:31:19.0932 3568 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
22:31:19.0942 3568 WPDBusEnum - ok
22:31:19.0972 3568 [ DE9D36F91A4DF3D911626643DEBF11EA ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
22:31:20.0002 3568 WpdUsb - ok
22:31:20.0112 3568 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
22:31:20.0122 3568 WPFFontCache_v0400 - ok
22:31:20.0162 3568 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
22:31:20.0192 3568 ws2ifsl - ok
22:31:20.0242 3568 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\System32\wscsvc.dll
22:31:20.0242 3568 wscsvc - ok
22:31:20.0252 3568 WSearch - ok
22:31:20.0342 3568 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
22:31:20.0412 3568 wuauserv - ok
22:31:20.0452 3568 [ AC13CB789D93412106B0FB6C7EB2BCB6 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
22:31:20.0452 3568 WUDFRd - ok
22:31:20.0492 3568 [ 575A4190D989F64732119E4114045A4F ] wudfsvc C:\Windows\System32\WUDFSvc.dll
22:31:20.0502 3568 wudfsvc - ok
22:31:20.0582 3568 [ 2E812881EC96E80EAE304877ED90206B ] WUSB54GCv3 C:\Windows\system32\DRIVERS\WUSB54GCv3.sys
22:31:20.0682 3568 WUSB54GCv3 - ok
22:31:20.0712 3568 [ 5A7FF9A18FF6D7E0527FE3ABF9204EF8 ] XAudio C:\Windows\system32\DRIVERS\xaudio.sys
22:31:20.0732 3568 XAudio - ok
22:31:20.0802 3568 [ 28DC5D626E036A75A572556F0A6EB1F6 ] XAudioService C:\Windows\system32\DRIVERS\xaudio.exe
22:31:20.0822 3568 XAudioService - ok
22:31:20.0862 3568 ================ Scan global ===============================
22:31:20.0892 3568 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
22:31:20.0922 3568 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
22:31:20.0952 3568 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll
22:31:21.0062 3568 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
22:31:21.0082 3568 [Global] - ok
22:31:21.0082 3568 ================ Scan MBR ==================================
22:31:21.0092 3568 [ 1A1A06F62E891045814007163C1C76C3 ] \Device\Harddisk0\DR0
22:31:21.0433 3568 \Device\Harddisk0\DR0 - ok
22:31:21.0435 3568 ================ Scan VBR ==================================
22:31:21.0453 3568 [ 4D454D0297B98FD2F7C71FC9477EAB87 ] \Device\Harddisk0\DR0\Partition1
22:31:21.0470 3568 \Device\Harddisk0\DR0\Partition1 - ok
22:31:21.0504 3568 [ 9CA86763B1B1ED54A8B7CA248AB8F976 ] \Device\Harddisk0\DR0\Partition2
22:31:21.0536 3568 \Device\Harddisk0\DR0\Partition2 - ok
22:31:21.0536 3568 ============================================================
22:31:21.0536 3568 Scan finished
22:31:21.0536 3568 ============================================================
22:31:21.0555 5184 Detected object count: 0
22:31:21.0556 5184 Actual detected object count: 0
22:32:04.0909 1776 Deinitialize success

OTL.txt

OTL logfile created on: 03/12/2013 10:36:33 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Owner\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00002409 | Country: Caribbean | Language: ENB | Date Format: MM/dd/yyyy

2.50 Gb Total Physical Memory | 1.35 Gb Available Physical Memory | 53.93% Memory free
5.22 Gb Paging File | 3.75 Gb Available in Paging File | 71.90% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 105.18 Gb Total Space | 57.76 Gb Free Space | 54.92% Space Free | Partition Type: NTFS
Drive D: | 6.61 Gb Total Space | 0.65 Gb Free Space | 9.78% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_6_602_180.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_6_602_171.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe (Linksys, LLC)
PRC - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
PRC - C:\Windows\vsnp2uvc.exe (Sonix)
PRC - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe ()
PRC - C:\Windows\System32\lxdicoms.exe ( )
PRC - C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
PRC - C:\Program Files\HP Connections\6811507\Program\HP Connections.exe (Hewlett Packard)


========== Modules (No Company Name) ==========

MOD - C:\Windows\System32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files\Common Files\Pure Networks Shared\Platform\CAntiVirusCOM.dll ()
MOD - C:\Program Files\Common Files\Pure Networks Shared\Platform\CFirewallCOM.dll ()
MOD - C:\Program Files\HP\QuickPlay\Kernel\TV\CLTinyDB.dll ()
MOD - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapEngine.dll ()
MOD - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSchMgr.dll ()
MOD - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvcps.dll ()
MOD - C:\Program Files\HP\QuickPlay\Kernel\common\MCEMediaStatus.dll ()
MOD - C:\Program Files\HP Connections\6811507\6.3.2.139-6811507\Program\FrExt.dll ()
MOD - C:\Program Files\HP Connections\6811507\6.3.2.139-6811507\Program\bwfiles.dll ()
MOD - C:\Program Files\HP Connections\6811507\6.3.2.139-6811507\Program\clntutil.dll ()
MOD - C:\Program Files\HP Connections\6811507\Program\HPClientExt.dll ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (rpcapd) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (nmservice) – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (CLSched) – C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe ()
SRV - (CLCapSvc) – C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe ()
SRV - (lxdi_device) – C:\Windows\System32\lxdicoms.exe ( )
SRV - (lxdiCATSCustConnectService) – C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe ()
SRV - (AddFiltr) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IDriverT) – C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (avkmgr) – C:\Windows\System32\drivers\avkmgr.sys (Avira GmbH)
DRV - (ssmdrv) – C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) – C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (SNP2UVC) – C:\Windows\System32\drivers\snp2uvc.sys ()
DRV - (NPF) – C:\Windows\System32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (WUSB54GCv3) – C:\Windows\System32\drivers\WUSB54GCv3.sys (Ralink Technology Corp.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (pnarp) – C:\Windows\System32\drivers\pnarp.sys (Pure Networks, Inc.)
DRV - (purendis) – C:\Windows\System32\drivers\purendis.sys (Pure Networks, Inc.)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (HdAudAddService) – C:\Windows\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (eabfiltr) – C:\Windows\System32\drivers\eabfiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HBtnKey) – C:\Windows\System32\drivers\CPQBttn.sys (Hewlett-Packard Development Company, L.P.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {9E2A3FCB-2AB6-46E3-83E8-600016F1C5FB}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{9E2A3FCB-2AB6-46E3-83E8-600016F1C5FB}: "URL" = http://www.google.com/search?q={searchTerm…age={startPage}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 127.0.0.1:8080

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "DuckDuckGo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://duckduckgo.com/about"
FF - prefs.js..extensions.enabledAddons: john%40velvetcache.org:1.3.7
FF - prefs.js..extensions.enabledAddons: %7B8b86149f-01fb-4842-9dd8-4d7eb02fd055%7D:0.25.1
FF - prefs.js..extensions.enabledAddons: donottrackplus%40abine.com:[removed]
FF - prefs.js..extensions.enabledAddons: %7B23fcfd51-4958-4f00-80a3-ae97e717ed8b%7D:[removed]
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..keyword.URL: "https://duckduckgo.com/?q="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.3088: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.3146: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.11.3006: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013/02/25 19:31:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/03/08 19:39:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/03/08 19:39:05 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/03/08 19:39:11 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/03/08 19:39:05 | 000,000,000 | —D | M]

[2009/07/12 09:50:01 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2013/03/09 21:14:24 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\2m9hs0hd.default\extensions
[2013/02/08 20:31:40 | 000,000,000 | —D | M] (All-in-One Gestures) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\2m9hs0hd.default\extensions\{8b86149f-01fb-4842-9dd8-4d7eb02fd055}
[2013/02/13 23:12:57 | 000,000,000 | —D | M] (DoNotTrackMe) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\2m9hs0hd.default\extensions\[removed]
[2013/03/09 21:14:24 | 000,302,153 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\2m9hs0hd.default\extensions\[removed]
[2012/07/27 14:41:40 | 000,017,677 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\2m9hs0hd.default\extensions\[removed]
[2013/02/07 18:16:47 | 000,004,412 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\2m9hs0hd.default\extensions\[removed]
[2012/09/08 10:50:32 | 000,020,591 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\2m9hs0hd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
[2013/02/14 20:37:47 | 000,817,280 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\2m9hs0hd.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/02/12 00:55:59 | 000,007,919 | —- | M] () (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\2m9hs0hd.default\extensions\[removed]\chrome\content\ff\view_expiry.js
[2013/02/27 17:37:39 | 000,010,339 | —- | M] () – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\2m9hs0hd.default\searchplugins\duckduckgo-1.xml
[2013/02/27 17:37:18 | 000,010,339 | —- | M] () – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\2m9hs0hd.default\searchplugins\duckduckgo.xml
[2009/07/28 11:30:20 | 000,004,153 | —- | M] () – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\2m9hs0hd.default\searchplugins\youtube.xml
[2013/03/08 19:39:04 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/02/25 19:31:11 | 000,000,000 | —D | M] (No name found) – C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
[2013/03/08 19:39:10 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/09/05 20:26:22 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/02/26 18:19:13 | 000,002,086 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Linksys Wireless Manager] C:\Program Files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe (Linksys, LLC)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe (Sonix)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote Table Of Contents.onetoc2 ()
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 File not found
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.17.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{428B593C-4B18-48AD-B167-45913FC331DB}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5244B39B-3C34-4F34-A39D-9DB422EF5043}: DhcpNameServer = 8.8.8.8 8.8.4.4 208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{90B417F8-A0C1-4A5C-B6FF-A35FD7E1A224}: DhcpNameServer = 172.16.0.3 4.2.2.1 4.2.2.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{93FDB787-C68C-410F-97BF-E781DAF87EBC}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9C7C7D79-1137-419A-B13C-8C04B9344104}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img36.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img36.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/12/18 14:58:05 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005/09/11 09:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O33 - MountPoints2\{58b524c3-3e9a-11df-b425-001b243508d3}\Shell - "" = AutoRun
O33 - MountPoints2\{58b524c3-3e9a-11df-b425-001b243508d3}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/03/12 22:34:00 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2013/03/11 17:33:56 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Owner\Desktop\HiJackThis.exe
[2013/03/08 19:39:04 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/03/07 18:22:02 | 000,000,000 | —D | C] – C:\Program Files\Putty
[2013/03/07 18:21:39 | 000,262,560 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2013/03/07 18:21:04 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2013/03/07 18:21:04 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\System32\java.exe
[2013/03/07 18:21:04 | 000,094,112 | —- | C] (Oracle Corporation) – C:\Windows\System32\WindowsAccessBridge.dll
[2013/02/25 19:45:20 | 000,000,000 | —D | C] – C:\Users\Owner\.vnc
[2013/02/15 21:36:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2013/02/15 21:36:55 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2013/02/12 19:39:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IrfanView
[2013/02/11 18:51:50 | 002,237,968 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Owner\Desktop\TDSSKiller.exe

========== Files - Modified Within 30 Days ==========

[2013/03/12 22:36:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/03/12 22:34:19 | 000,207,308 | —- | M] () – C:\ProgramData\nvModes.001
[2013/03/12 22:34:01 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2013/03/12 22:29:46 | 002,237,968 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Owner\Desktop\TDSSKiller.exe
[2013/03/12 21:22:14 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/03/12 21:22:14 | 000,003,168 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/03/12 17:36:26 | 000,693,976 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/03/12 17:36:26 | 000,073,432 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/03/12 17:24:07 | 000,000,161 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2013/03/12 17:22:48 | 000,207,308 | —- | M] () – C:\ProgramData\nvModes.dat
[2013/03/12 17:21:52 | 000,351,864 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/03/12 17:21:51 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/03/12 06:02:35 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2013/03/11 17:34:00 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Owner\Desktop\HiJackThis.exe
[2013/03/11 06:03:15 | 000,008,296 | —- | M] () – C:\Users\Owner\AppData\Local\d3d9caps.dat
[2013/03/07 21:14:15 | 000,000,600 | —- | M] () – C:\Users\Owner\AppData\Local\PUTTY.RND
[2013/03/07 18:20:43 | 000,094,112 | —- | M] (Oracle Corporation) – C:\Windows\System32\WindowsAccessBridge.dll
[2013/03/07 18:20:41 | 000,861,088 | —- | M] (Oracle Corporation) – C:\Windows\System32\npDeployJava1.dll
[2013/03/07 18:20:41 | 000,782,240 | —- | M] (Oracle Corporation) – C:\Windows\System32\deployJava1.dll
[2013/03/07 18:20:41 | 000,262,560 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2013/03/07 18:20:41 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2013/03/07 18:20:41 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\System32\java.exe
[2013/02/15 21:36:55 | 000,001,878 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2013/02/12 19:39:21 | 000,000,807 | —- | M] () – C:\Users\Public\Desktop\IrfanView.lnk

========== Files Created - No Company Name ==========

[2013/03/12 17:21:44 | 000,351,864 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2013/02/15 21:36:55 | 000,001,878 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2009/03/15 22:32:41 | 000,207,308 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/03/15 22:32:41 | 000,207,308 | —- | C] () – C:\ProgramData\nvModes.001
[2009/03/09 20:39:25 | 000,000,600 | —- | C] () – C:\Users\Owner\AppData\Local\PUTTY.RND
[2008/10/08 20:44:08 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2008/01/09 21:47:45 | 000,000,032 | —- | C] () – C:\ProgramData\ezsid.dat
[2007/11/08 00:21:38 | 000,008,296 | —- | C] () – C:\Users\Owner\AppData\Local\d3d9caps.dat
[2007/07/25 19:26:19 | 000,022,528 | —- | C] () – C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/07/12 22:43:02 | 000,070,339 | —- | C] () – C:\Users\Owner\AppData\Roaming\nvModes.001
[2007/07/12 22:40:37 | 000,070,339 | —- | C] () – C:\Users\Owner\AppData\Roaming\nvModes.dat

========== ZeroAccess Check ==========

[2006/11/02 07:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 12:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 01:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 01:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2009/08/06 23:05:30 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\.purple
[2007/12/29 11:08:41 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\eMule
[2007/07/20 22:42:50 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Grisoft
[2009/08/01 11:07:35 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\gtk-2.0
[2009/07/27 14:45:48 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\IrfanView
[2008/03/23 19:22:14 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Lexmark Productivity Studio
[2011/04/03 22:03:12 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Lite
[2009/06/03 16:46:54 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Notepad++
[2009/07/12 11:18:35 | 000,000,000 | —D | M] – C:\Users\Owner\AppData\Roaming\Wireshark

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2008/10/29 01:20:29 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 01:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/29 22:59:17 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2007/11/15 18:22:51 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2007/11/15 18:22:51 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/27 21:15:02 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006/11/02 04:45:07 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008/01/19 02:33:10 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: SVCHOST.EXE >
[2006/11/02 04:45:47 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe
[2008/01/19 02:33:32 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\System32\svchost.exe
[2008/01/19 02:33:32 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/01/19 02:33:33 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\System32\userinit.exe
[2008/01/19 02:33:33 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006/11/02 04:45:50 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006/11/02 04:45:57 | 000,308,224 | —- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008/01/19 02:33:37 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< C:\Windows\assembly\tmp\U\*.* /s >
[2006/11/02 08:01:49 | 000,000,006 | -H– | C] () – C:\Windows\Tasks\SA.DAT
[2006/11/02 08:01:49 | 000,032,562 | —- | C] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2013/02/08 20:29:40 | 000,000,830 | —- | C] () – C:\Windows\Tasks\Adobe Flash Player Updater.job

< End of report >

Extras.txt

OTL Extras logfile created on: 03/12/2013 10:36:33 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Owner\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00002409 | Country: Caribbean | Language: ENB | Date Format: MM/dd/yyyy

2.50 Gb Total Physical Memory | 1.35 Gb Available Physical Memory | 53.93% Memory free
5.22 Gb Paging File | 3.75 Gb Available in Paging File | 71.90% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 105.18 Gb Total Space | 57.76 Gb Free Space | 54.92% Space Free | Partition Type: NTFS
Drive D: | 6.61 Gb Total Space | 0.65 Gb Free Space | 9.78% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-4209408274-2400752346-149060358-1000]
"EnableNotifications" = 0
"EnableNotificationsRef" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02AC249C-946C-48D5-85AE-78E6C69B5873}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{06C77936-7770-4ECC-B5CA-D9A694096956}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{0B158402-9583-4B17-A38F-7CBB94C46ADB}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{279DBC50-DB11-4A09-B35E-41799C2DE098}" = lport=4001 | protocol=17 | dir=in | name=emule_udp |
"{2C4F30C3-294C-485F-A23B-47F20ECCC482}" = lport=12476 | protocol=17 | dir=in | name=bitcomet 12476 udp |
"{30F5D058-303F-48B8-BEBA-ED410BB1B07B}" = lport=4000 | protocol=6 | dir=in | name=emule_tcp |
"{3433EAC9-6177-433F-92DA-E7B85AE6FA3C}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{5C554092-8E66-415B-A0E5-0E59EAB26B21}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{5D9AFC5E-31AF-4E5B-B14B-25011AEAE971}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{652BDCAD-A3C5-41F0-B2DF-8EA78F7B3B0E}" = lport=45570 | protocol=17 | dir=in | name=bitcomet_listen |
"{6D22850C-7F43-411F-BBE2-4D69A9FF24DD}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{7CBAAB4F-59D5-4FA0-8004-35959EC3D833}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{863E27E6-ED1E-4E22-ABFE-491CB13D9039}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{924659C5-F579-48D4-8132-297BFB5B8418}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{9F7A0E5D-81C3-4872-AE32-DD9AA8D2DFF7}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{B32FC1DD-431A-4CDA-81B5-B0CBB83F2A1E}" = lport=12476 | protocol=6 | dir=in | name=bitcomet 12476 tcp |
"{B7545361-9B9B-4EAD-9D06-57999F355610}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{D3A3714F-E286-4AD3-884A-2F4E5971209D}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{E1A4BAEE-9206-4D54-8A10-F00E254C9FB0}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{EF585BDB-BF30-48DF-B685-67AF6BB9D74C}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{F29C3704-C9C8-483A-825E-6EA1E016F494}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00A54F6D-FB15-41D2-BAC5-1D814581E298}" = protocol=6 | dir=in | app=c:\program files\lexmark 3500-4500 series\lxdimon.exe |
"{090CF6CF-EE2B-41E5-8C78-4E27BDD9A0C7}" = protocol=6 | dir=in | app=c:\program files\hp connections\6811507\program\hp connections.exe |
"{0CA0798A-3E2C-4FD7-BEAB-7513E7519FE5}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{106A939A-C6D8-400D-8E30-EBF37146E63E}" = protocol=6 | dir=in | app=c:\windows\system32\lxdicoms.exe |
"{197C84F5-A319-4C96-A784-1B2B49AE0C13}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{1EFD6655-F2DD-49EE-9E5E-7153771B5D1A}" = protocol=17 | dir=in | app=c:\program files\lexmark 3500-4500 series\lxdimon.exe |
"{23BB653A-C93E-46ED-89E3-25ED02AE2CAF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{362AAD09-0B86-4A1E-9B73-DA8ABAD7358E}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{50D8617A-F29C-41C3-A334-8FA62CE48AAF}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{5A8F5909-A086-4C36-B6FD-AA2858898BAC}" = protocol=17 | dir=in | app=c:\windows\system32\lxdicoms.exe |
"{5B517202-C517-4798-BE04-3B0D254B56BD}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{60DEC888-F219-4253-B879-9DCB9F49D1E6}" = protocol=17 | dir=in | app=c:\program files\hp connections\6811507\program\hp connections.exe |
"{61CC6B45-F4AE-4554-87CC-B030B001C452}" = protocol=6 | dir=in | app=c:\windows\system32\lxdicfg.exe |
"{69766FF7-C030-44B6-941A-342BD87A0965}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{6B57F522-FAAD-41A8-B1C1-953062BF9446}" = dir=in | app=c:\program files\hp connections\6811507\program\hp connections |
"{6B858232-CDA8-4787-BC69-95686C88817A}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{6C11370A-A0E5-4A5E-AB48-7372F8B06AE0}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxditime.exe |
"{7C557805-3804-49B2-8285-F2601BD66E9B}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdipswx.exe |
"{81A65DC1-77E6-4167-8E14-4B7FCA87FA72}" = protocol=17 | dir=in | app=c:\program files\hp connections\6811507\program\hp connections.exe |
"{847B4D9A-56A3-49A5-9521-2D7585715908}" = protocol=6 | dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{95ECDD01-AB84-4195-A36C-29147C571235}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{964A17A2-B864-49C4-AE05-C970AF48F245}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{983291AD-11C8-4B5B-B374-B9279CB4C5A2}" = protocol=17 | dir=in | app=c:\windows\system32\lxdicfg.exe |
"{9D406FA2-D569-4B05-AF04-B5EF70ABB61D}" = protocol=6 | dir=in | app=c:\program files\lexmark 3500-4500 series\app4r.exe |
"{9E02C4F2-DF48-4ADA-B6DF-757714F01315}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{A34FF9F8-2CF9-4E94-AC08-245826E3B077}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxditime.exe |
"{A95992EC-4DEE-4470-AC4B-2890DC7E49A2}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{AB06BDE8-59B8-48EC-BE3A-F47C57907ABE}" = protocol=6 | dir=in | app=c:\program files\hp connections\6811507\program\hp connections.exe |
"{AC329DFE-9885-4654-B95B-F7DD2939CF01}" = protocol=17 | dir=in | app=c:\program files\lexmark 3500-4500 series\wireless\lxdiwpss.exe |
"{B5CA92E7-6DDE-47CB-A8A8-D1BD76B38552}" = protocol=17 | dir=in | app=c:\program files\lexmark 3500-4500 series\lxdiamon.exe |
"{D0E33B3D-1A5D-4264-A998-9D761F9F2B0E}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{D3C42945-3116-4475-8D5D-1142DB34472B}" = protocol=6 | dir=in | app=c:\program files\lexmark 3500-4500 series\wireless\lxdiwpss.exe |
"{E24E9DEE-818A-495F-A2F9-37C1AB2449F9}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxdipswx.exe |
"{E41058C6-7D05-484F-A228-0EEB30B548C1}" = protocol=17 | dir=in | app=c:\program files\lexmark 3500-4500 series\app4r.exe |
"{E4F8C58C-172C-4E9F-87BD-9C7CCBAA8251}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{EA9FBFDD-B1E8-421A-8B23-40ED40432329}" = protocol=6 | dir=in | app=c:\program files\lexmark 3500-4500 series\lxdiamon.exe |
"{EC58DC15-F7C5-434D-85D3-CDAD99FD9AC4}" = protocol=6 | dir=in | app=c:\program files\hp connections\6811507\program\hp connections.exe |
"{F510D6BD-800C-4A2B-A813-0643366B29DC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FB635DC9-2310-43AB-8258-2FC7970730FC}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"TCP Query User{079CFC6C-53BC-47E9-9F88-A6F1B28CA9DF}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{49506812-1C9D-4532-9B3A-A1938433481E}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{56D58C72-9F9E-407D-9B6F-4A59D7FB3715}C:\program files\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files\skype\phone\skype.exe |
"TCP Query User{581C3B05-A806-47E1-89AF-23AE5D3A758F}C:\program files\lexmark 3500-4500 series\lxdimon.exe" = protocol=6 | dir=in | app=c:\program files\lexmark 3500-4500 series\lxdimon.exe |
"TCP Query User{795557DE-B1F5-4031-A6D5-A47E606DC3F3}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{91DA76BF-AE81-4F8A-B5C1-526A7538C028}C:\program files\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files\skype\phone\skype.exe |
"TCP Query User{B8562F76-F6A4-4DEA-9483-14F56D8F2E67}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{CBDD2C74-1926-4E53-883D-2B1E4A061F8B}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"TCP Query User{F94457F1-2053-4347-BEC1-D5D09200409B}C:\program files\quicktime\quicktimeplayer.exe" = protocol=6 | dir=in | app=c:\program files\quicktime\quicktimeplayer.exe |
"UDP Query User{061EEE29-0260-4435-9667-031586967802}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{1A6D0E9B-E95D-42EF-B0F6-08629085CA33}C:\program files\lexmark 3500-4500 series\lxdimon.exe" = protocol=17 | dir=in | app=c:\program files\lexmark 3500-4500 series\lxdimon.exe |
"UDP Query User{40CA1F43-FC16-4FC8-A7EF-61BA0EE14EC6}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{6248F043-F201-4AB4-AEFA-E392298FDA03}C:\program files\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files\skype\phone\skype.exe |
"UDP Query User{88F44D68-E3E2-4DC7-BD83-059BD87334EE}C:\program files\quicktime\quicktimeplayer.exe" = protocol=17 | dir=in | app=c:\program files\quicktime\quicktimeplayer.exe |
"UDP Query User{E7E6DE32-E6BD-4DEF-9BE4-5AF01F603A47}C:\program files\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files\skype\phone\skype.exe |
"UDP Query User{EC00734C-AAEE-4F9D-9D00-B368BB8D45EA}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"UDP Query User{F7FB4459-D72B-4789-9D8E-2EB24AA94837}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{F9FA9492-1148-4849-8569-633EAB1396F5}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{02F33FB0-F7D5-4C0A-B4AD-8CE5CE230BBE}" = HP Wireless Assistant
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{11BB336F-0E58-4977-B866-F24FA334616B}" = HP Active Support Library
"{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}" = Roxio Creator EasyArchive
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 17
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{33C65B6A-5D73-4E3E-A1F9-127C27BD3F72}" = Roxio MyDVD Basic v9
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.10 B9
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{40F7AED3-0C7D-4582-99F6-484A515C73F2}" = HP Easy Setup - Frontend
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.3
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.1
"{5198360C-D0E0-4EE2-B4E3-8BA83C8D4053}" = Pure Networks Platform
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{5CA81D12-9EC2-4082-972B-43ECA63F41F2}" = HP Pavilion Webcam Driver for Vista v061.001.00005
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}" = QuickTime
"{99C5770C-1C90-42E7-9B74-D47CFAF14621}" = muvee autoProducer 5.0
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A12A3DED-CCDA-4F29-A1BA-00F0C6521CD5}" = HP Total Care Advisor
"{AB5E289E-76BF-4251-9F3F-9B763F681AE0}" = HP Customer Experience Enhancements
"{ABFBC596-7EB3-4E4D-A1A3-D2B6806EF1FE}" = HP User Guide 0041
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.6)
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E1180142-3B31-4DCC-9D27-7AC2D37662BF}" = LightScribe 1.4.124.1
"{E4DDBA93-769B-49D8-BA33-8814E45ED0C1}" = HP Help and Support
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F94234DB-FD06-42C3-B88D-6FC4DC9F988C}" = HP Easy Setup - Core
"{FAB0C302-CB18-4A7A-BA03-C3DC23101A68}" = ASL_HS_Installer32
"AC3Filter" = AC3Filter (remove only)
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Avira AntiVir Desktop" = Avira Free Antivirus
"CCleaner" = CCleaner
"CNXT_HDAUDIO" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_5045&SUBSYS_103C30B7" = Soft Data Fax Modem with SmartCP
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup" = DivX Setup
"GTK 2.0" = GTK+ Runtime 2.14.7 rev a (remove only)
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HPOOVClient-6811507 Uninstaller" = HP Connections (remove only)
"IrfanView" = IrfanView (remove only)
"Lexmark 3500-4500 Series" = Lexmark 3500-4500 Series
"Linksys Wireless Manager" = Linksys Wireless Manager
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 19.0.2 (x86 en-US)" = Mozilla Firefox 19.0.2 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIA Drivers" = NVIDIA Drivers
"Pidgin" = Pidgin
"RealPlayer 6.0" = RealPlayer
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.3.2
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VobSub" = VobSub v2.23 (Remove Only)
"WildTangent hplaptop Master Uninstall" = My HP Games
"WinPcapInst" = WinPcap 4.1 beta5
"Wireshark" = Wireshark 1.2.0
"YTdetect" = Yahoo! Detect

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 02/21/2013 7:58:26 PM | Computer Name = Owner-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 02/21/2013 7:58:26 PM | Computer Name = Owner-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 02/21/2013 7:58:26 PM | Computer Name = Owner-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 02/21/2013 7:58:26 PM | Computer Name = Owner-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 02/21/2013 7:58:26 PM | Computer Name = Owner-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 02/21/2013 7:58:26 PM | Computer Name = Owner-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 02/27/2013 6:46:30 AM | Computer Name = Owner-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 03/02/2013 12:55:02 AM | Computer Name = Owner-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 03/02/2013 12:55:02 AM | Computer Name = Owner-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 03/06/2013 2:56:44 AM | Computer Name = Owner-PC | Source = Windows Search Service | ID = 3013
Description =

[ System Events ]
Error - 03/10/2013 7:03:54 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 03/10/2013 7:03:55 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 03/12/2013 6:32:24 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 03/12/2013 6:32:24 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 03/12/2013 6:33:49 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 03/12/2013 6:33:49 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 03/12/2013 6:22:41 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 03/12/2013 6:22:41 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 03/12/2013 6:24:06 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 03/12/2013 6:24:06 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7001
Description =


< End of report >
Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error
ComboFix.txt ComboFix 13-03-13.02 - Owner 03/13/2013 17:32:42.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2558.1199 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . Infected copy of c:\windows\system32\Services.exe was found and disinfected Restored copy from - c:\windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe . . ((((((((((((((((((((((((( Files Created from 2013-02-13 to 2013-03-13 ))))))))))))))))))))))))))))))) . . 2013-03-13 22:41 . 2013-03-13 22:41 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-03-07 23:22 . 2013-03-07 23:22 ——– d—–w- c:\program files\Putty 2013-03-07 23:21 . 2013-03-07 23:20 94112 —-a-w- c:\windows\system32\WindowsAccessBridge.dll 2013-02-26 00:45 . 2013-02-26 00:45 ——– d—–w- c:\users\Owner\.vnc 2013-02-16 02:36 . 2013-02-16 02:36 ——– d—–w- c:\program files\Common Files\Skype 2013-02-15 22:31 . 2013-02-15 22:31 186432 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-03-12 22:36 . 2012-09-07 22:46 693976 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2013-03-12 22:36 . 2011-08-10 11:31 73432 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-03-07 23:20 . 2012-09-08 02:09 861088 —-a-w- c:\windows\system32\npDeployJava1.dll 2013-03-07 23:20 . 2011-08-11 00:28 782240 —-a-w- c:\windows\system32\deployJava1.dll 2013-03-09 00:39 . 2013-03-09 00:39 263064 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-01-08 18705664] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800] "QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-11-06 159744] "WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2006-10-18 317152] "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2006-10-18 472800] "Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552] "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-06-23 181480] "nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-09-14 648488] "Linksys Wireless Manager"="c:\program files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe" [2008-12-05 1350192] "snp2uvc"="c:\windows\vsnp2uvc.exe" [2008-08-02 675840] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-09-08 348664] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-04 13556256] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-04 92704] "DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2013-01-30 450560] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2013-02-13 1263952] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] . c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote Table Of Contents.onetoc2 [2011-8-23 3656] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Connections.lnk - c:\program files\HP Connections\6811507\Program\HP Connections.exe [2006-12-18 34520] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKLM\~\startupfolder\C:^Users^Owner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk] path=c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate] 2013-02-13 02:37 1263952 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-4209408274-2400752346-149060358-1000] "EnableNotificationsRef"=dword:00000001 . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ WindowsMobile REG_MULTI_SZ wcescomm rapimgr LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Contents of the 'Scheduled Tasks' folder . 2013-03-13 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-07 22:36] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ mStart Page = hxxp://www.yahoo.com uInternet Settings,ProxyServer = 127.0.0.1:8080 uInternet Settings,ProxyOverride = local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\2m9hs0hd.default\ FF - prefs.js: browser.search.selectedEngine - DuckDuckGo FF - prefs.js: browser.startup.homepage - hxxps://duckduckgo.com/about FF - prefs.js: keyword.URL - hxxps://duckduckgo.com/?q= FF - ExtSQL: 2013-02-27 17:37; jid1-ZAdIEUB7XOzOJw@jetpack; c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\2m9hs0hd.default\extensions\[removed] FF - ExtSQL: !HIDDEN! 2009-08-05 23:09; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension . - - - - ORPHANS REMOVED - - - - . MSConfigStartUp-Malwarebytes' Anti-Malware - c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe . . . ************************************************************************** scanning hidden processes … . scanning hidden autostart entries … . scanning hidden files … . scan completed successfully hidden files: . ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ———————— Other Running Processes ———————— . c:\program files\Avira\AntiVir Desktop\avguard.exe c:\program files\Avira\AntiVir Desktop\avshadow.exe c:\windows\system32\nvvsvc.exe c:\windows\system32\rundll32.exe c:\windows\system32\WLANExt.exe c:\program files\Avira\AntiVir Desktop\sched.exe c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\windows\system32\lxdicoms.exe c:\windows\system32\DRIVERS\xaudio.exe c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe c:\program files\HP\QuickPlay\Kernel\TV\CLSched.exe c:\windows\System32\rundll32.exe c:\progra~1\HEWLET~1\Shared\HPQTOA~1.EXE c:\windows\ehome\ehmsas.exe c:\windows\system32\wbem\unsecapp.exe c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe c:\windows\servicing\TrustedInstaller.exe . ************************************************************************** . Completion time: 2013-03-13 17:51:13 - machine was rebooted ComboFix-quarantined-files.txt 2013-03-13 22:49 . Pre-Run: 62,325,706,752 bytes free Post-Run: 62,163,271,680 bytes free . - - End Of File - - C5D9862AB2F350961BDCEBCD3268BE77
Please download Malwarebytes Free from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please










Next

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is not checked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/





Also tell me how the computer is running now.
Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.03.14.10 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Owner :: OWNER-PC [administrator] 03/14/2013 5:37:47 PM mbam-log-2013-03-14 (17-37-47).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 203581 Time elapsed: 6 minute(s), 6 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ESET Online Scanner —————————— C:\Program Files\Avira\AntiVir Desktop\apnic.dll a variant of Win32/Bundled.Toolbar.Ask application cleaned by deleting (after the next restart) - quarantined C:\Program Files\Avira\AntiVir Desktop\apntoolbarinstaller.exe a variant of Win32/Bundled.Toolbar.Ask application cleaned by deleting (after the next restart) - quarantined C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YVJTQYLR\ApnIC[1].0 a variant of Win32/Bundled.Toolbar.Ask application cleaned by deleting - quarantined The laptop is running faster now. Also, Avira scans appear to be working now. Can you say what the nature of the infection was? Would I be able to follow the same instructions if I notice the symptoms again? Thanks again for your patience and your help with this. Regards, elmkd

Can you say what the nature of the infection was? Would I be able to follow the same instructions if I notice the symptoms again?

Combofix removed a rootkit, it is not advisable to run Combofix on your own.

You appear clean of infections,please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.










Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing
Thank you once again. Would you please recommend a suitable firewall. If there are any good free ones I would appreciate any recommendation that you could make. Regards, elmkd

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI