This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Appears to Boot Normaly But Nothing Works [Solved]

31 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi oldman960,

I really appreciate all your help. I followed your instructions and dragged and dropped the script file onto combo fix (jgh.exe). I got an error message that the combo fix was out of date and when I clicked on the error message the combo fix (jgh.exe) icon disappeared from the desktop. I then went to a working computer, re-downloaded combo fix, renamed it jgh.exe and saved it to a flash drive. I brought it over to the sick computer running in safe mode without networking and moved the file to the desktop. I then dragged and dropped the script file onto the renamed combo fix and it started up without a hitch. During the scan it gave a warning that a rootkit was discovered (no mention of ZeroAccess). Combo fix then rebooted and I directed it into safemode where the scan continued and completed. The log file is attached to this post below.

I rebooted in normal mode and things are still not good. The first reboot took forever and seemed to wait a long time for something to load. I was, however, able to double-click on internet explorer and get a connection. The browser then became non-responsive and I had to hold the power button to get the computer to shut down. The second time I rebooted the boot was much faster but nothing seemed to work. None of the programs I double-clicked would open.

___________________________________

ComboFix 13-03-27.01 - Administrator 03/28/2013 14:03:07.4.2 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.3068 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\jgh.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
.
FILE ::
"c:\documents and settings\All Users\Application Data\6o4v7yr6ikfw18072u"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\$NtUninstallKB32607$\3870726633
.
.
————— FCopy —————
.
c:\windows\ServicePackFiles\i386\intelppm.sys –> c:\windows\system32\drivers\intelppm.sys
.
((((((((((((((((((((((((( Files Created from 2013-02-28 to 2013-03-28 )))))))))))))))))))))))))))))))
.
.
2013-03-28 18:03 . 2008-04-13 18:31 36352 —-a-w- c:\windows\system32\drivers\intelppm.sys
2013-03-27 20:02 . 2013-03-27 20:02 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2013-03-27 20:00 . 2013-03-27 20:00 ——– d—–w- c:\program files\Mozilla Maintenance Service
2013-03-18 16:37 . 2013-03-18 18:09 ——– d—–w- C:\jgh
2013-03-14 14:50 . 2013-03-14 14:50 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\BVRP Software
2013-03-13 20:26 . 2013-03-13 20:26 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2013-03-13 20:12 . 2013-03-13 20:12 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-27 15:17 . 2012-06-01 11:51 691568 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-27 15:17 . 2012-02-13 15:40 71024 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-19 19:15 . 2012-04-10 17:30 60920 —-a-w- c:\windows\system32\drivers\cfwids.sys
2013-02-19 19:12 . 2012-04-10 17:20 172416 —-a-w- c:\windows\system32\mfevtps.exe
2013-02-19 19:11 . 2012-04-10 17:30 91640 —-a-w- c:\windows\system32\drivers\mfetdi2k.sys
2013-02-19 19:11 . 2012-04-10 17:30 10088 —-a-w- c:\windows\system32\drivers\mfeclnk.sys
2013-02-19 19:10 . 2012-04-10 17:30 92632 —-a-w- c:\windows\system32\drivers\mferkdet.sys
2013-02-19 19:09 . 2011-10-15 16:16 565888 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2013-02-19 19:09 . 2012-12-17 15:09 84904 —-a-w- c:\windows\system32\drivers\mfendisk.sys
2013-02-19 19:09 . 2012-04-10 17:30 363080 —-a-w- c:\windows\system32\drivers\mfefirek.sys
2013-02-19 19:08 . 2012-04-10 17:30 65928 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2013-02-19 19:08 . 2012-04-10 17:30 235264 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2013-02-19 19:07 . 2011-10-15 16:16 133416 —-a-w- c:\windows\system32\drivers\mfeapfk.sys
2013-03-07 14:31 . 2013-03-27 20:00 263064 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-01-05 98304]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2007-10-30 77824]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-10-10 185784]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-10-11 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-10-11 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2009-02-10 745472]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-10-30 77824]
"Memeo Instant Backup"="c:\program files\Memeo\AutoBackup\MemeoLauncher2.exe" [2010-12-11 136416]
"Seagate Dashboard"="c:\program files\Seagate\Seagate Dashboard\MemeoLauncher.exe" [2011-11-03 73728]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-04 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2013-01-14 1278064]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-1-20 724992]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToMyPC]
2011-11-13 12:53 15216 —-a-w- c:\program files\Citrix\GoToMyPC\G2WinLogon.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Seagate\\Seagate Dashboard\\HipServAgent\\HipServAgent.exe"=
.
R0 xmasbus;xmasbus;c:\windows\SYSTEM32\DRIVERS\xmasbus.sys [2/4/2005 2:11 PM 140800]
R0 xmasscsi;xmasscsi;c:\windows\SYSTEM32\DRIVERS\xmasscsi.sys [2/4/2005 2:11 PM 5504]
S1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\SYSTEM32\DRIVERS\mfetdi2k.sys [4/10/2012 1:30 PM 91640]
S2 LxrSII1d;Secure II Driver;c:\windows\SYSTEM32\DRIVERS\LxrSII1d.sys [5/13/2008 2:31 PM 72672]
S2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [4/10/2012 1:30 PM 167784]
S2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\Memeo\AutoBackup\MemeoBackgroundService.exe [12/10/2010 9:49 PM 25824]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\Mcafee\SystemCore\mfefire.exe [4/10/2012 1:31 PM 169320]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\SYSTEM32\mfevtps.exe [4/10/2012 1:20 PM 172416]
S2 RapidPortM1;RapidPortM1;c:\windows\SYSTEM32\DRIVERS\CAPM1LP.SYS [2/23/2005 7:04 PM 22912]
S2 SeagateDashboardService;Seagate Dashboard Service;c:\program files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [11/3/2011 2:10 PM 8704]
S3 cfwids;McAfee Inc. cfwids;c:\windows\SYSTEM32\DRIVERS\cfwids.sys [4/10/2012 1:30 PM 60920]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.318\McCHSvc.exe [2/5/2013 11:48 AM 235216]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\SYSTEM32\DRIVERS\mfefirek.sys [4/10/2012 1:30 PM 363080]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [12/17/2012 11:09 AM 84904]
S3 mfendiskmp;mfendiskmp;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [12/17/2012 11:09 AM 84904]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\SYSTEM32\DRIVERS\mferkdet.sys [4/10/2012 1:30 PM 92632]
.
Contents of the 'Scheduled Tasks' folder
.
2013-03-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-01 15:17]
.
2013-03-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-22 20:34]
.
2005-01-07 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\OOBEBALN.EXE [2004-08-04 00:12]
.
2013-03-19 c:\windows\Tasks\User_Feed_Synchronization-{9F65D221-A6DA-4935-A0FB-B46D030E6DFB}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.dell4me.com/myway
mStart Page = hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzutDtDtCtAtBtDyBtB0DtCtDyEzz0AtA0AtN0D0Tzu0CtByDzztN1L2Xzut
BtFtCtFtCtFtAtCtB&cr=1554250186
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
DPF: {A762E064-A885-40E4-AC10-671BB62DC2B2} - hxxp://www.eomniform.com/OF5/nsplugins/OFMailX.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ytskgyqs.default\
FF - ExtSQL: 2013-03-19 16:53; {D19CA586-DD6C-4a0a-96F8-14644F340D60}; c:\program files\Common Files\McAfee\SystemCore
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-03-28 14:19
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD800JD-75JNA0 rev.05.01C05 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
.
device: opened successfully
user: MBR read successfully
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8A8E02E2
user & kernel MBR OK
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-4073680847-1405297832-2471763517-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b2,6c,21,3f,31,7e,5e,41,a3,f2,b3,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b2,6c,21,3f,31,7e,5e,41,a3,f2,b3,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_171_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="4FDA30922D1D3A4A1A518A89786166259F7EDB5C427B6808351193CC975D2AF0366B0F1D0D2
9192344801B1DA40F8878C6AF3B417DB9EAC349444851CFCDD2C520FADA1F447948AE66148D529013
6FAD41FB00C56744F61778843EEBB9CBE595E3A5E2CF484EA8ED9D5A9C1B05ACF5CE1083F2333F7C8
7B3CA5D6961A87C1C5C2B89678E23ABCC46D823758EE164ADC908E54DF9DA09C8B29762B11806445F
7876CB1C5A70DAFB82DBC2FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BE
CC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E667C038D530D6EB3452A6A0AC4980AC
7933BA7FD869164D679495747435A8FAC96341B3DE98263F27383A1B78105C0A222DC2209BCEE5FCA
1B5F1912D37D708A550DD8E2F2D5E33805417129D6F9D6DDC5C788D9F09E36E97BCC0958BD1B4AAE9
090018327694D560A956A9839D36F5A005FAE07D91E80208B41FBE6C83E01A0F499528FA5547C6822
752F4157BA34C1065B38514688D8A98CAA471C58F33735ED1803CB46EA90DF7BB59A850AF96019EBE
FD89D756A040433356B4207E3738766494751C2AA491235D2D1F4722F285965527A14F63A1BDD524B
1B516982ACA4B4A9B1982B35121BC8384D5A10251AF92F37222965D4783F057A6435970FEF3A24DD1
0ECC7C036DCFAB886F183D7EBB04E79607DA58FBF38B8C19522FD65DE1193F68E275B6390C3DD5573
1F98B7B463104C0F062A9DB57EF066079EDE29EA21BF1044988DC2E76B6878286A8E57CD2B01C8D9F
02EAB857B98A4AF50271D02CEB3E3F93A7A94C89C54991FA9B08E947F18B11FCA5FA18855DE394A6E
CA038D5247EA53D089D34074727FC415B7460EEB3AED2914D7B33531FE1F411C253C95D2D15B86173
FBB61468B2B4AF08EFAF760B67CC0E0BD2789A985713DAAA3130624562EC42464E5E3A2DFE97C0D20
3DCF0609B6E4407AA0A94B71A0AD1E1254B697FCFACC37260E5676F267E9082FAA155F1359BAA7D72
3BE1BE046B64385E2C59C349546FFCC1BC6DD8C3B363F0EAE87ECEA229DDBBDB1705C3753A2891CF9
901CB3D34F000C785006A79721E0CA453295D53E49B25DB5AE530D06ED2E7318E1026A0921BA70918
3AF7EBEEC8D744B67955BD8B47332EF7CFC07B7542C5FDB99A376A27E135E201972943CE1468A41AF
3445DD167EECF13F108E12C75CBF3FC983416A0DD00757D7B792C2CD06969BA050A2D5DA679838860
6CF1EA112F97EF6828231D4D6E2405AA38D61574987589F9DB31CAD4044F6291279DF5DB37AEDAC7F
016B50FFE183BCC89798A994872AA84426D27E457FCE46146DB8B4241C5BFDB44F57029C3BB7D72E6
CA037D5F4EF53D9A6BF6EB4D1B8390AAA7DA54BBAACD2FA54E4B44DF415B0B9888E982573A789C153
A312657FBE8400B0009C5ACF16DAA"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(276)
c:\windows\system32\WININET.dll
c:\program files\Citrix\GoToMyPC\G2WinLogon.dll
.
- - - - - - - > 'lsass.exe'(336)
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(1280)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
Completion time: 2013-03-28 14:24:39
ComboFix-quarantined-files.txt 2013-03-28 18:24
ComboFix2.txt 2013-03-18 18:09
ComboFix3.txt 2010-04-18 15:10
.
Pre-Run: 39,582,068,736 bytes free
Post-Run: 39,613,493,248 bytes free
.
- - End Of File - - 34AB941C2B70A47C19DC5418A05A9377
Hi EricDSr,

Download and transfer this tool to the sick computer" desktop.


Download the latest version of TDSSKiller from here and save it to your Desktop.



A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.
Hi oldman960, TDSSKiller ran without a problem. Found over 20 threats only one of which was labled serious and had "cure" as an option. Thanks again. _________________________________ 12:31:03.0156 1336 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 12:31:03.0203 1336 ============================================================ 12:31:03.0203 1336 Current date / time: 2013/03/29 12:31:03.0203 12:31:03.0203 1336 SystemInfo: 12:31:03.0203 1336 12:31:03.0203 1336 OS Version: 5.1.2600 ServicePack: 3.0 12:31:03.0203 1336 Product type: Workstation 12:31:03.0203 1336 ComputerName: IRWINA 12:31:03.0203 1336 UserName: Administrator 12:31:03.0203 1336 Windows directory: C:\WINDOWS 12:31:03.0203 1336 System windows directory: C:\WINDOWS 12:31:03.0203 1336 Processor architecture: Intel x86 12:31:03.0203 1336 Number of processors: 2 12:31:03.0203 1336 Page size: 0x1000 12:31:03.0203 1336 Boot type: Safe boot 12:31:03.0203 1336 ============================================================ 12:31:06.0843 1336 Drive \Device\Harddisk0\DR0 - Size: 0x12A05F2000 (74.51 Gb), SectorSize: 0x200, Cylinders: 0x25FE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 12:31:06.0843 1336 Drive \Device\Harddisk1\DR4 - Size: 0x3BF80000 (0.94 Gb), SectorSize: 0x200, Cylinders: 0x7A, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 12:31:06.0843 1336 ============================================================ 12:31:06.0843 1336 \Device\Harddisk0\DR0: 12:31:06.0843 1336 MBR partitions: 12:31:06.0843 1336 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1F608, BlocksNum 0x8ECA268 12:31:06.0843 1336 \Device\Harddisk1\DR4: 12:31:06.0843 1336 MBR partitions: 12:31:06.0843 1336 \Device\Harddisk1\DR4\Partition1: MBR, Type 0x4, StartLBA 0x20, BlocksNum 0x1DFBE0 12:31:06.0843 1336 ============================================================ 12:31:06.0921 1336 C: <-> \Device\Harddisk0\DR0\Partition1 12:31:06.0937 1336 ============================================================ 12:31:06.0937 1336 Initialize success 12:31:06.0937 1336 ============================================================ 12:33:10.0437 1740 ============================================================ 12:33:10.0437 1740 Scan started 12:33:10.0437 1740 Mode: Manual; SigCheck; TDLFS; 12:33:10.0437 1740 ============================================================ 12:33:12.0046 1740 ================ Scan system memory ======================== 12:33:12.0046 1740 System memory - ok 12:33:12.0046 1740 ================ Scan services ============================= 12:33:12.0484 1740 Abiosdsk - ok 12:33:12.0546 1740 [ 6ABB91494FE6C59089B9336452AB2EA3 ] abp480n5 C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 12:33:18.0906 1740 abp480n5 - ok 12:33:19.0031 1740 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 12:33:19.0328 1740 ACPI - ok 12:33:19.0390 1740 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 12:33:19.0671 1740 ACPIEC - ok 12:33:19.0859 1740 [ 9942DC4CC265CDA00486504444EF521D ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe 12:33:19.0968 1740 AdobeFlashPlayerUpdateSvc - ok 12:33:20.0031 1740 [ 9A11864873DA202C996558B2106B0BBC ] adpu160m C:\WINDOWS\system32\DRIVERS\adpu160m.sys 12:33:20.0265 1740 adpu160m - ok 12:33:20.0328 1740 [ 11C04B17ED2ABBB4833694BCD644AC90 ] aeaudio C:\WINDOWS\system32\drivers\aeaudio.sys 12:33:20.0390 1740 aeaudio - ok 12:33:20.0468 1740 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 12:33:20.0765 1740 aec - ok 12:33:20.0875 1740 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys 12:33:21.0031 1740 AFD - ok 12:33:21.0093 1740 [ 08FD04AA961BDC77FB983F328334E3D7 ] agp440 C:\WINDOWS\system32\DRIVERS\agp440.sys 12:33:21.0296 1740 agp440 - ok 12:33:21.0328 1740 [ 03A7E0922ACFE1B07D5DB2EEB0773063 ] agpCPQ C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 12:33:21.0546 1740 agpCPQ - ok 12:33:21.0687 1740 [ C23EA9B5F46C7F7910DB3EAB648FF013 ] Aha154x C:\WINDOWS\system32\DRIVERS\aha154x.sys 12:33:21.0796 1740 Aha154x - ok 12:33:21.0828 1740 [ 19DD0FB48B0C18892F70E2E7D61A1529 ] aic78u2 C:\WINDOWS\system32\DRIVERS\aic78u2.sys 12:33:22.0046 1740 aic78u2 - ok 12:33:22.0078 1740 [ B7FE594A7468AA0132DEB03FB8E34326 ] aic78xx C:\WINDOWS\system32\DRIVERS\aic78xx.sys 12:33:22.0281 1740 aic78xx - ok 12:33:22.0328 1740 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll 12:33:22.0546 1740 Alerter - ok 12:33:22.0687 1740 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe 12:33:22.0812 1740 ALG - ok 12:33:22.0828 1740 [ 1140AB9938809700B46BB88E46D72A96 ] AliIde C:\WINDOWS\system32\DRIVERS\aliide.sys 12:33:23.0031 1740 AliIde - ok 12:33:23.0078 1740 [ CB08AED0DE2DD889A8A820CD8082D83C ] alim1541 C:\WINDOWS\system32\DRIVERS\alim1541.sys 12:33:23.0296 1740 alim1541 - ok 12:33:23.0312 1740 [ 95B4FB835E28AA1336CEEB07FD5B9398 ] amdagp C:\WINDOWS\system32\DRIVERS\amdagp.sys 12:33:23.0546 1740 amdagp - ok 12:33:23.0671 1740 [ 79F5ADD8D24BD6893F2903A3E2F3FAD6 ] amsint C:\WINDOWS\system32\DRIVERS\amsint.sys 12:33:23.0765 1740 amsint - ok 12:33:23.0859 1740 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 12:33:24.0031 1740 AppMgmt - ok 12:33:24.0062 1740 [ 62D318E9A0C8FC9B780008E724283707 ] asc C:\WINDOWS\system32\DRIVERS\asc.sys 12:33:24.0265 1740 asc - ok 12:33:24.0281 1740 [ 69EB0CC7714B32896CCBFD5EDCBEA447 ] asc3350p C:\WINDOWS\system32\DRIVERS\asc3350p.sys 12:33:24.0375 1740 asc3350p - ok 12:33:24.0406 1740 [ 5D8DE112AA0254B907861E9E9C31D597 ] asc3550 C:\WINDOWS\system32\DRIVERS\asc3550.sys 12:33:24.0687 1740 asc3550 - ok 12:33:24.0890 1740 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 12:33:24.0953 1740 aspnet_state - ok 12:33:24.0984 1740 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 12:33:25.0171 1740 AsyncMac - ok 12:33:25.0234 1740 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 12:33:25.0421 1740 atapi - ok 12:33:25.0437 1740 Atdisk - ok 12:33:25.0781 1740 [ 4DEAA162480367B232F3EE3A6D34084B ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe 12:33:26.0062 1740 Ati HotKey Poller - ok 12:33:26.0375 1740 [ F0D0B0CDEC0BE32D775F404CAC2604BF ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 12:33:26.0921 1740 ati2mtag - ok 12:33:26.0968 1740 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 12:33:27.0171 1740 Atmarpc - ok 12:33:27.0218 1740 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 12:33:27.0421 1740 AudioSrv - ok 12:33:27.0468 1740 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 12:33:27.0750 1740 audstub - ok 12:33:27.0843 1740 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 12:33:28.0031 1740 Beep - ok 12:33:28.0250 1740 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll 12:33:28.0921 1740 BITS - ok 12:33:28.0984 1740 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll 12:33:29.0109 1740 Browser - ok 12:33:29.0125 1740 bvrp_pci - ok 12:33:29.0281 1740 catchme - ok 12:33:29.0328 1740 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 12:33:29.0515 1740 cbidf - ok 12:33:29.0546 1740 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 12:33:29.0734 1740 cbidf2k - ok 12:33:29.0765 1740 [ F3EC03299634490E97BBCE94CD2954C7 ] cd20xrnt C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 12:33:29.0875 1740 cd20xrnt - ok 12:33:29.0937 1740 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 12:33:30.0125 1740 Cdaudio - ok 12:33:30.0171 1740 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 12:33:30.0390 1740 Cdfs - ok 12:33:30.0453 1740 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 12:33:30.0718 1740 Cdrom - ok 12:33:30.0812 1740 [ 25C323075C5EA4A2555E35355A01F793 ] cfwids C:\WINDOWS\system32\drivers\cfwids.sys 12:33:30.0890 1740 cfwids - ok 12:33:30.0906 1740 Changer - ok 12:33:30.0984 1740 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe 12:33:31.0203 1740 CiSvc - ok 12:33:31.0250 1740 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 12:33:31.0468 1740 ClipSrv - ok 12:33:31.0531 1740 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 12:33:31.0593 1740 clr_optimization_v2.0.50727_32 - ok 12:33:31.0609 1740 [ E5DCB56C533014ECBC556A8357C929D5 ] CmdIde C:\WINDOWS\system32\DRIVERS\cmdide.sys 12:33:31.0812 1740 CmdIde - ok 12:33:31.0828 1740 COMSysApp - ok 12:33:31.0890 1740 [ 3EE529119EED34CD212A215E8C40D4B6 ] Cpqarray C:\WINDOWS\system32\DRIVERS\cpqarray.sys 12:33:32.0078 1740 Cpqarray - ok 12:33:32.0140 1740 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 12:33:32.0359 1740 CryptSvc - ok 12:33:32.0437 1740 [ E550E7418984B65A78299D248F0A7F36 ] dac2w2k C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 12:33:32.0687 1740 dac2w2k - ok 12:33:32.0734 1740 [ 683789CAA3864EB46125AE86FF677D34 ] dac960nt C:\WINDOWS\system32\DRIVERS\dac960nt.sys 12:33:32.0921 1740 dac960nt - ok 12:33:33.0078 1740 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 12:33:33.0359 1740 DcomLaunch - ok 12:33:33.0453 1740 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 12:33:33.0671 1740 Dhcp - ok 12:33:33.0734 1740 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 12:33:33.0937 1740 Disk - ok 12:33:33.0953 1740 dmadmin - ok 12:33:34.0265 1740 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 12:33:34.0875 1740 dmboot - ok 12:33:34.0937 1740 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys 12:33:35.0187 1740 dmio - ok 12:33:35.0234 1740 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 12:33:35.0437 1740 dmload - ok 12:33:35.0500 1740 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll 12:33:35.0687 1740 dmserver - ok 12:33:35.0734 1740 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 12:33:36.0000 1740 DMusic - ok 12:33:36.0078 1740 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 12:33:36.0250 1740 Dnscache - ok 12:33:36.0328 1740 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 12:33:36.0562 1740 Dot3svc - ok 12:33:36.0593 1740 [ 40F3B93B4E5B0126F2F5C0A7A5E22660 ] dpti2o C:\WINDOWS\system32\DRIVERS\dpti2o.sys 12:33:36.0796 1740 dpti2o - ok 12:33:36.0843 1740 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 12:33:37.0031 1740 drmkaud - ok 12:33:37.0093 1740 [ B15F9E526BA511A48B1B1B8537815740 ] drvmcdb C:\WINDOWS\system32\drivers\drvmcdb.sys 12:33:37.0140 1740 drvmcdb ( UnsignedFile.Multi.Generic ) - warning 12:33:37.0140 1740 drvmcdb - detected UnsignedFile.Multi.Generic (1) 12:33:37.0187 1740 [ FA4670CAE95AE2BB857C68E535661145 ] drvnddm C:\WINDOWS\system32\drivers\drvnddm.sys 12:33:37.0218 1740 drvnddm ( UnsignedFile.Multi.Generic ) - warning 12:33:37.0218 1740 drvnddm - detected UnsignedFile.Multi.Generic (1) 12:33:37.0375 1740 [ FE80901578E7E3DA70299A5AEB2B7FBD ] DSBrokerService C:\Program Files\DellSupport\brkrsvc.exe 12:33:37.0437 1740 DSBrokerService - ok 12:33:37.0531 1740 [ 413F2D5F9D802688242C23B38F767ECB ] DSproct C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys 12:33:37.0546 1740 DSproct ( UnsignedFile.Multi.Generic ) - warning 12:33:37.0546 1740 DSproct - detected UnsignedFile.Multi.Generic (1) 12:33:37.0593 1740 [ DFEABB7CFFFADEA4A912AB95BDC3177A ] dsunidrv C:\WINDOWS\system32\DRIVERS\dsunidrv.sys 12:33:37.0671 1740 dsunidrv - ok 12:33:37.0750 1740 [ 7D91DC6342248369F94D6EBA0CF42E99 ] E100B C:\WINDOWS\system32\DRIVERS\e100b325.sys 12:33:37.0875 1740 E100B - ok 12:33:37.0921 1740 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll 12:33:38.0125 1740 EapHost - ok 12:33:38.0187 1740 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll 12:33:38.0390 1740 ERSvc - ok 12:33:38.0468 1740 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe 12:33:38.0515 1740 Eventlog - ok 12:33:38.0656 1740 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll 12:33:38.0828 1740 EventSystem - ok 12:33:38.0906 1740 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 12:33:39.0140 1740 Fastfat - ok 12:33:39.0218 1740 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 12:33:39.0375 1740 FastUserSwitchingCompatibility - ok 12:33:39.0531 1740 [ E97D6A8684466DF94FF3BC24FB787A07 ] Fax C:\WINDOWS\system32\fxssvc.exe 12:33:39.0812 1740 Fax - ok 12:33:39.0875 1740 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys 12:33:40.0062 1740 Fdc - ok 12:33:40.0125 1740 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 12:33:40.0328 1740 Fips - ok 12:33:40.0375 1740 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys 12:33:40.0578 1740 Flpydisk - ok 12:33:40.0656 1740 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys 12:33:40.0921 1740 FltMgr - ok 12:33:41.0046 1740 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 12:33:41.0078 1740 FontCache3.0.0.0 - ok 12:33:41.0125 1740 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 12:33:41.0328 1740 Fs_Rec - ok 12:33:41.0406 1740 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 12:33:41.0625 1740 Ftdisk - ok 12:33:42.0046 1740 [ 0B53F4306E17025E7685D18C3A77127E ] GoToMyPC C:\Program Files\Citrix\GoToMyPC\g2svc.exe 12:33:42.0593 1740 GoToMyPC - ok 12:33:42.0656 1740 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 12:33:42.0875 1740 Gpc - ok 12:33:43.0031 1740 [ CC839E8D766CC31A7710C9F38CF3E375 ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 12:33:43.0140 1740 gusvc - ok 12:33:43.0250 1740 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 12:33:43.0453 1740 helpsvc - ok 12:33:43.0468 1740 HidServ - ok 12:33:43.0531 1740 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 12:33:43.0750 1740 hkmsvc - ok 12:33:43.0796 1740 [ B028377DEA0546A5FCFBA928A8AEFAE0 ] hpn C:\WINDOWS\system32\DRIVERS\hpn.sys 12:33:43.0984 1740 hpn - ok 12:33:44.0093 1740 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 12:33:44.0234 1740 HTTP - ok 12:33:44.0281 1740 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 12:33:44.0484 1740 HTTPFilter - ok 12:33:44.0515 1740 [ 9368670BD426EBEA5E8B18A62416EC28 ] i2omgmt C:\WINDOWS\system32\drivers\i2omgmt.sys 12:33:44.0703 1740 i2omgmt - ok 12:33:44.0734 1740 [ F10863BF1CCC290BABD1A09188AE49E0 ] i2omp C:\WINDOWS\system32\DRIVERS\i2omp.sys 12:33:44.0968 1740 i2omp - ok 12:33:45.0000 1740 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 12:33:45.0234 1740 i8042prt - ok 12:33:45.0609 1740 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 12:33:46.0171 1740 idsvc - ok 12:33:46.0250 1740 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 12:33:46.0453 1740 Imapi - ok 12:33:46.0531 1740 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe 12:33:46.0796 1740 ImapiService - ok 12:33:46.0828 1740 [ 4A40E045FAEE58631FD8D91AFC620719 ] ini910u C:\WINDOWS\system32\DRIVERS\ini910u.sys 12:33:47.0046 1740 ini910u - ok 12:33:47.0515 1740 [ 7509C548400F4C9E0211E3F6E66ABBE6 ] IntelC51 C:\WINDOWS\system32\DRIVERS\IntelC51.sys 12:33:48.0281 1740 IntelC51 - ok 12:33:48.0531 1740 [ 9584FFDD41D37F2C239681D0DAC2513E ] IntelC52 C:\WINDOWS\system32\DRIVERS\IntelC52.sys 12:33:48.0921 1740 IntelC52 - ok 12:33:48.0984 1740 [ CF0B937710CEC6EF39416EDECD803CBB ] IntelC53 C:\WINDOWS\system32\DRIVERS\IntelC53.sys 12:33:49.0031 1740 IntelC53 - ok 12:33:49.0062 1740 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys 12:33:49.0250 1740 IntelIde - ok 12:33:49.0312 1740 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 12:33:49.0500 1740 intelppm - ok 12:33:49.0562 1740 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys 12:33:49.0765 1740 Ip6Fw - ok 12:33:49.0828 1740 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 12:33:50.0015 1740 IpFilterDriver - ok 12:33:50.0046 1740 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 12:33:50.0250 1740 IpInIp - ok 12:33:50.0328 1740 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 12:33:50.0562 1740 IpNat - ok 12:33:50.0625 1740 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 12:33:50.0843 1740 IPSec - ok 12:33:50.0875 1740 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 12:33:51.0015 1740 IRENUM - ok 12:33:51.0093 1740 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 12:33:51.0281 1740 isapnp - ok 12:33:51.0468 1740 [ 0A5709543986843D37A92290B7838340 ] JavaQuickStarterService C:\Program Files\Java\jre6\bin\jqs.exe 12:33:51.0578 1740 JavaQuickStarterService - ok 12:33:51.0625 1740 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 12:33:51.0843 1740 Kbdclass - ok 12:33:51.0921 1740 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 12:33:52.0171 1740 kmixer - ok 12:33:52.0234 1740 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 12:33:52.0421 1740 KSecDD - ok 12:33:52.0531 1740 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll 12:33:52.0640 1740 lanmanserver - ok 12:33:52.0750 1740 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 12:33:52.0875 1740 lanmanworkstation - ok 12:33:52.0890 1740 lbrtfdc - ok 12:33:53.0000 1740 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 12:33:53.0187 1740 LmHosts - ok 12:33:53.0265 1740 [ 7C12F93C005021861A36C11DF951891A ] LxrSII1d C:\WINDOWS\system32\Drivers\LxrSII1d.sys 12:33:53.0296 1740 LxrSII1d ( UnsignedFile.Multi.Generic ) - warning 12:33:53.0296 1740 LxrSII1d - detected UnsignedFile.Multi.Generic (1) 12:33:53.0312 1740 LxrSII1s - ok 12:33:53.0531 1740 [ DDCC236009C707761D60E5C76D639176 ] McComponentHostService C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe 12:33:53.0656 1740 McComponentHostService - ok 12:33:53.0859 1740 [ ECAB006AC6136F1307E140B633CDB8C2 ] mcmscsvc C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe 12:33:53.0937 1740 mcmscsvc - ok 12:33:54.0000 1740 [ ECAB006AC6136F1307E140B633CDB8C2 ] McNaiAnn C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe 12:33:54.0031 1740 McNaiAnn - ok 12:33:54.0093 1740 [ ECAB006AC6136F1307E140B633CDB8C2 ] McNASvc C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe 12:33:54.0125 1740 McNASvc - ok 12:33:54.0296 1740 [ C7DA06C9A9AEEFBE37AAC281EA6385D5 ] McODS C:\Program Files\McAfee\VirusScan\mcods.exe 12:33:54.0390 1740 McODS - ok 12:33:54.0468 1740 [ ECAB006AC6136F1307E140B633CDB8C2 ] McProxy C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe 12:33:54.0484 1740 McProxy - ok 12:33:54.0625 1740 [ 6FE0532CB16300C09D098F808EAAEE9D ] McShield C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe 12:33:54.0750 1740 McShield - ok 12:33:54.0921 1740 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 12:33:55.0062 1740 MDM - ok 12:33:55.0125 1740 [ 0377F70E41FEFA850B96A8FB157C5681 ] MemeoBackgroundService C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe 12:33:55.0156 1740 MemeoBackgroundService - ok 12:33:55.0203 1740 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll 12:33:55.0421 1740 Messenger - ok 12:33:55.0531 1740 [ 6708AD7D9ABDD6FDE1EB9B54FFE426B0 ] mfeapfk C:\WINDOWS\system32\drivers\mfeapfk.sys 12:33:55.0593 1740 mfeapfk - ok 12:33:55.0718 1740 [ 375DE90B68533D9D0D7766D4CCB4CA32 ] mfeavfk C:\WINDOWS\system32\drivers\mfeavfk.sys 12:33:55.0828 1740 mfeavfk - ok 12:33:55.0906 1740 [ 5ED806D4DF27AC11236BD9AD2CC10B7E ] mfebopk C:\WINDOWS\system32\drivers\mfebopk.sys 12:33:55.0953 1740 mfebopk - ok 12:33:56.0031 1740 [ 1A427BB508ACBEE09A88F08D1CA38E2F ] mfefire C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe 12:33:56.0109 1740 mfefire - ok 12:33:56.0265 1740 [ 16BF9475BFCFAA420A8CB29E40284457 ] mfefirek C:\WINDOWS\system32\drivers\mfefirek.sys 12:33:56.0484 1740 mfefirek - ok 12:33:56.0734 1740 [ 875452ECDF4AEBE12B8C2EFD8599A36F ] mfehidk C:\WINDOWS\system32\drivers\mfehidk.sys 12:33:57.0046 1740 mfehidk - ok 12:33:57.0109 1740 [ 3004E3FE086E76D7D6DFB9A851ED6F10 ] mfendisk C:\WINDOWS\system32\DRIVERS\mfendisk.sys 12:33:57.0171 1740 mfendisk - ok 12:33:57.0203 1740 [ 3004E3FE086E76D7D6DFB9A851ED6F10 ] mfendiskmp C:\WINDOWS\system32\DRIVERS\mfendisk.sys 12:33:57.0234 1740 mfendiskmp - ok 12:33:57.0312 1740 [ D669ACBE7672819109706C3CFF6BD1DB ] mferkdet C:\WINDOWS\system32\drivers\mferkdet.sys 12:33:57.0375 1740 mferkdet - ok 12:33:57.0437 1740 [ 1328C929A2F801BB93DBDFCDC25E0E7A ] mfetdi2k C:\WINDOWS\system32\drivers\mfetdi2k.sys 12:33:57.0500 1740 mfetdi2k - ok 12:33:57.0593 1740 [ D66A1A16166897A5F7D04961F582F03B ] mfevtp C:\WINDOWS\system32\mfevtps.exe 12:33:57.0687 1740 mfevtp - ok 12:33:57.0750 1740 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 12:33:57.0953 1740 mnmdd - ok 12:33:58.0015 1740 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 12:33:58.0218 1740 mnmsrvc - ok 12:33:58.0281 1740 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 12:33:58.0484 1740 Modem - ok 12:33:58.0515 1740 [ 1992E0D143B09653AB0F9C5E04B0FD65 ] MODEMCSA C:\WINDOWS\system32\drivers\MODEMCSA.sys 12:33:58.0703 1740 MODEMCSA - ok 12:33:58.0734 1740 [ 59B8B11FF70728EEC60E72131C58B716 ] mohfilt C:\WINDOWS\system32\DRIVERS\mohfilt.sys 12:33:58.0781 1740 mohfilt - ok 12:33:58.0828 1740 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 12:33:59.0015 1740 Mouclass - ok 12:33:59.0062 1740 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 12:33:59.0265 1740 MountMgr - ok 12:33:59.0359 1740 [ 8A7C8F4C713E70D73946833D76B77035 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 12:33:59.0437 1740 MozillaMaintenance - ok 12:33:59.0453 1740 [ 3F4BB95E5A44F3BE34824E8E7CAF0737 ] mraid35x C:\WINDOWS\system32\DRIVERS\mraid35x.sys 12:33:59.0656 1740 mraid35x - ok 12:33:59.0734 1740 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 12:33:59.0984 1740 MRxDAV - ok 12:34:00.0187 1740 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 12:34:00.0484 1740 MRxSmb - ok 12:34:00.0546 1740 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe 12:34:00.0734 1740 MSDTC - ok 12:34:00.0781 1740 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 12:34:01.0000 1740 Msfs - ok 12:34:01.0015 1740 MSIServer - ok 12:34:01.0078 1740 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 12:34:01.0265 1740 MSKSSRV - ok 12:34:01.0281 1740 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 12:34:01.0484 1740 MSPCLOCK - ok 12:34:01.0515 1740 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 12:34:01.0687 1740 MSPQM - ok 12:34:01.0734 1740 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 12:34:01.0906 1740 mssmbios - ok 12:34:01.0968 1740 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 12:34:02.0078 1740 Mup - ok 12:34:02.0203 1740 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll 12:34:02.0484 1740 napagent - ok 12:34:02.0578 1740 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 12:34:02.0828 1740 NDIS - ok 12:34:02.0875 1740 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12:34:02.0968 1740 NdisTapi - ok 12:34:03.0015 1740 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 12:34:03.0203 1740 Ndisuio - ok 12:34:03.0265 1740 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 12:34:03.0468 1740 NdisWan - ok 12:34:03.0531 1740 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 12:34:03.0640 1740 NDProxy - ok 12:34:03.0671 1740 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 12:34:03.0890 1740 NetBIOS - ok 12:34:03.0984 1740 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 12:34:04.0203 1740 NetBT - ok 12:34:04.0296 1740 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe 12:34:04.0515 1740 NetDDE - ok 12:34:04.0562 1740 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 12:34:04.0765 1740 NetDDEdsdm - ok 12:34:04.0812 1740 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe 12:34:05.0000 1740 Netlogon - ok 12:34:05.0109 1740 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll 12:34:05.0343 1740 Netman - ok 12:34:05.0484 1740 [ 02D0798F376FCBD0210EDA58476D0B1B ] NetSvc C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe 12:34:05.0546 1740 NetSvc ( UnsignedFile.Multi.Generic ) - warning 12:34:05.0546 1740 NetSvc - detected UnsignedFile.Multi.Generic (1) 12:34:05.0671 1740 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 12:34:05.0765 1740 NetTcpPortSharing - ok 12:34:05.0875 1740 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll 12:34:06.0015 1740 Nla - ok 12:34:06.0078 1740 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 12:34:06.0265 1740 Npfs - ok 12:34:06.0484 1740 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 12:34:06.0953 1740 Ntfs - ok 12:34:06.0984 1740 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 12:34:07.0156 1740 NtLmSsp - ok 12:34:07.0328 1740 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 12:34:07.0781 1740 NtmsSvc - ok 12:34:07.0812 1740 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 12:34:07.0984 1740 Null - ok 12:34:08.0609 1740 [ 2B298519EDBFCF451D43E0F1E8F1006D ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 12:34:09.0906 1740 nv - ok 12:34:09.0984 1740 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 12:34:10.0187 1740 NwlnkFlt - ok 12:34:10.0234 1740 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 12:34:10.0421 1740 NwlnkFwd - ok 12:34:10.0593 1740 [ 2DDCC672E3A9F615CACE2AB6B9601056 ] O&O Defrag C:\WINDOWS\system32\oodag.exe 12:34:10.0796 1740 O&O Defrag ( UnsignedFile.Multi.Generic ) - warning 12:34:10.0796 1740 O&O Defrag - detected UnsignedFile.Multi.Generic (1) 12:34:10.0843 1740 [ 53D5F1278D9EDB21689BBBCECC09108D ] omci C:\WINDOWS\system32\DRIVERS\omci.sys 12:34:10.0859 1740 omci ( UnsignedFile.Multi.Generic ) - warning 12:34:10.0859 1740 omci - detected UnsignedFile.Multi.Generic (1) 12:34:10.0953 1740 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 12:34:11.0015 1740 ose - ok 12:34:11.0109 1740 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys 12:34:11.0343 1740 Parport - ok 12:34:11.0375 1740 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 12:34:11.0593 1740 PartMgr - ok 12:34:11.0640 1740 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 12:34:11.0875 1740 ParVdm - ok 12:34:11.0937 1740 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 12:34:12.0218 1740 PCI - ok 12:34:12.0234 1740 PCIDump - ok 12:34:12.0281 1740 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 12:34:12.0546 1740 PCIIde - ok 12:34:12.0640 1740 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys 12:34:13.0000 1740 Pcmcia - ok 12:34:13.0015 1740 PDCOMP - ok 12:34:13.0046 1740 PDFRAME - ok 12:34:13.0062 1740 PDRELI - ok 12:34:13.0093 1740 PDRFRAME - ok 12:34:13.0125 1740 [ 6C14B9C19BA84F73D3A86DBA11133101 ] perc2 C:\WINDOWS\system32\DRIVERS\perc2.sys 12:34:13.0359 1740 perc2 - ok 12:34:13.0406 1740 [ F50F7C27F131AFE7BEBA13E14A3B9416 ] perc2hib C:\WINDOWS\system32\DRIVERS\perc2hib.sys 12:34:13.0656 1740 perc2hib - ok 12:34:13.0875 1740 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe 12:34:13.0906 1740 PlugPlay - ok 12:34:13.0968 1740 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 12:34:14.0156 1740 PolicyAgent - ok 12:34:14.0203 1740 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 12:34:14.0406 1740 PptpMiniport - ok 12:34:14.0421 1740 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 12:34:14.0593 1740 ProtectedStorage - ok 12:34:14.0640 1740 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 12:34:14.0921 1740 PSched - ok 12:34:14.0984 1740 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 12:34:15.0171 1740 Ptilink - ok 12:34:15.0234 1740 [ DB3B30C3A4CDCF07E164C14584D9D0F2 ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys 12:34:15.0296 1740 PxHelp20 ( UnsignedFile.Multi.Generic ) - warning 12:34:15.0296 1740 PxHelp20 - detected UnsignedFile.Multi.Generic (1) 12:34:15.0343 1740 [ 0A63FB54039EB5662433CABA3B26DBA7 ] ql1080 C:\WINDOWS\system32\DRIVERS\ql1080.sys 12:34:15.0546 1740 ql1080 - ok 12:34:15.0593 1740 [ 6503449E1D43A0FF0201AD5CB1B8C706 ] Ql10wnt C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 12:34:15.0796 1740 Ql10wnt - ok 12:34:15.0843 1740 [ 156ED0EF20C15114CA097A34A30D8A01 ] ql12160 C:\WINDOWS\system32\DRIVERS\ql12160.sys 12:34:16.0031 1740 ql12160 - ok 12:34:16.0062 1740 [ 70F016BEBDE6D29E864C1230A07CC5E6 ] ql1240 C:\WINDOWS\system32\DRIVERS\ql1240.sys 12:34:16.0265 1740 ql1240 - ok 12:34:16.0296 1740 [ 907F0AEEA6BC451011611E732BD31FCF ] ql1280 C:\WINDOWS\system32\DRIVERS\ql1280.sys 12:34:16.0515 1740 ql1280 - ok 12:34:16.0578 1740 [ 7F599E8BCC5EBC78FA711E9E55EEA40C ] RapidPortM1 C:\WINDOWS\system32\Drivers\CAPM1LP.SYS 12:34:16.0656 1740 RapidPortM1 - ok 12:34:16.0703 1740 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 12:34:16.0906 1740 RasAcd - ok 12:34:16.0984 1740 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll 12:34:17.0187 1740 RasAuto - ok 12:34:17.0234 1740 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 12:34:17.0453 1740 Rasl2tp - ok 12:34:17.0546 1740 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll 12:34:17.0812 1740 RasMan - ok 12:34:17.0843 1740 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 12:34:18.0031 1740 RasPppoe - ok 12:34:18.0046 1740 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 12:34:18.0234 1740 Raspti - ok 12:34:18.0328 1740 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 12:34:18.0546 1740 Rdbss - ok 12:34:18.0578 1740 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 12:34:18.0750 1740 RDPCDD - ok 12:34:18.0859 1740 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys 12:34:19.0093 1740 rdpdr - ok 12:34:19.0187 1740 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 12:34:19.0296 1740 RDPWD - ok 12:34:19.0453 1740 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 12:34:19.0828 1740 RDSessMgr - ok 12:34:19.0921 1740 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 12:34:20.0156 1740 redbook - ok 12:34:20.0234 1740 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 12:34:20.0453 1740 RemoteAccess - ok 12:34:20.0515 1740 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 12:34:20.0750 1740 RemoteRegistry - ok 12:34:20.0812 1740 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe 12:34:21.0015 1740 RpcLocator - ok 12:34:21.0203 1740 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll 12:34:21.0312 1740 RpcSs - ok 12:34:21.0406 1740 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe 12:34:21.0625 1740 RSVP - ok 12:34:21.0640 1740 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe 12:34:21.0859 1740 SamSs - ok 12:34:21.0937 1740 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 12:34:22.0140 1740 SCardSvr - ok 12:34:22.0250 1740 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll 12:34:22.0500 1740 Schedule - ok 12:34:22.0609 1740 [ A1A26E8EC51E199D873D85F3E2B6FC65 ] SeagateDashboardService C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe 12:34:22.0625 1740 SeagateDashboardService ( UnsignedFile.Multi.Generic ) - warning 12:34:22.0625 1740 SeagateDashboardService - detected UnsignedFile.Multi.Generic (1) 12:34:22.0687 1740 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 12:34:22.0796 1740 Secdrv - ok 12:34:22.0843 1740 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll 12:34:23.0078 1740 seclogon - ok 12:34:23.0140 1740 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll 12:34:23.0359 1740 SENS - ok 12:34:23.0406 1740 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 12:34:23.0625 1740 serenum - ok 12:34:23.0703 1740 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys 12:34:23.0921 1740 Serial - ok 12:34:24.0015 1740 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 12:34:24.0265 1740 Sfloppy - ok 12:34:24.0453 1740 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 12:34:24.0890 1740 SharedAccess - ok 12:34:24.0968 1740 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 12:34:25.0000 1740 ShellHWDetection - ok 12:34:25.0015 1740 Simbad - ok 12:34:25.0078 1740 [ 6B33D0EBD30DB32E27D1D78FE946A754 ] sisagp C:\WINDOWS\system32\DRIVERS\sisagp.sys 12:34:25.0281 1740 sisagp - ok 12:34:25.0546 1740 [ 4AA922332433CDEB8B82C072C212E32E ] smwdm C:\WINDOWS\system32\drivers\smwdm.sys 12:34:25.0921 1740 smwdm - ok 12:34:25.0953 1740 [ 83C0F71F86D3BDAF915685F3D568B20E ] Sparrow C:\WINDOWS\system32\DRIVERS\sparrow.sys 12:34:26.0078 1740 Sparrow - ok 12:34:26.0140 1740 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 12:34:26.0312 1740 splitter - ok 12:34:26.0359 1740 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe 12:34:26.0437 1740 Spooler - ok 12:34:26.0468 1740 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 12:34:26.0609 1740 sr - ok 12:34:26.0703 1740 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll 12:34:26.0859 1740 srservice - ok 12:34:27.0000 1740 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 12:34:27.0296 1740 Srv - ok 12:34:27.0359 1740 [ D7968049BE0ADBB6A57CEE3960320911 ] sscdbhk5 C:\WINDOWS\system32\drivers\sscdbhk5.sys 12:34:27.0359 1740 sscdbhk5 ( UnsignedFile.Multi.Generic ) - warning 12:34:27.0359 1740 sscdbhk5 - detected UnsignedFile.Multi.Generic (1) 12:34:27.0421 1740 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 12:34:27.0562 1740 SSDPSRV - ok 12:34:27.0578 1740 [ C3FFD65ABFB6441E7606CF74F1155273 ] ssrtln C:\WINDOWS\system32\drivers\ssrtln.sys 12:34:27.0609 1740 ssrtln ( UnsignedFile.Multi.Generic ) - warning 12:34:27.0609 1740 ssrtln - detected UnsignedFile.Multi.Generic (1) 12:34:27.0671 1740 [ A9573045BAA16EAB9B1085205B82F1ED ] StillCam C:\WINDOWS\system32\DRIVERS\serscan.sys 12:34:27.0890 1740 StillCam - ok 12:34:28.0046 1740 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll 12:34:28.0468 1740 stisvc - ok 12:34:28.0515 1740 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 12:34:28.0703 1740 swenum - ok 12:34:28.0781 1740 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 12:34:28.0984 1740 swmidi - ok 12:34:29.0000 1740 SwPrv - ok 12:34:29.0046 1740 [ 1FF3217614018630D0A6758630FC698C ] symc810 C:\WINDOWS\system32\DRIVERS\symc810.sys 12:34:29.0218 1740 symc810 - ok 12:34:29.0265 1740 [ 070E001D95CF725186EF8B20335F933C ] symc8xx C:\WINDOWS\system32\DRIVERS\symc8xx.sys 12:34:29.0468 1740 symc8xx - ok 12:34:29.0484 1740 [ 80AC1C4ABBE2DF3B738BF15517A51F2C ] sym_hi C:\WINDOWS\system32\DRIVERS\sym_hi.sys 12:34:29.0687 1740 sym_hi - ok 12:34:29.0703 1740 [ BF4FAB949A382A8E105F46EBB4937058 ] sym_u3 C:\WINDOWS\system32\DRIVERS\sym_u3.sys 12:34:29.0890 1740 sym_u3 - ok 12:34:29.0968 1740 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 12:34:30.0171 1740 sysaudio - ok 12:34:30.0234 1740 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 12:34:30.0453 1740 SysmonLog - ok 12:34:30.0562 1740 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 12:34:30.0828 1740 TapiSrv - ok 12:34:31.0000 1740 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 12:34:31.0281 1740 Tcpip - ok 12:34:31.0343 1740 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 12:34:31.0531 1740 TDPIPE - ok 12:34:31.0578 1740 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 12:34:31.0765 1740 TDTCP - ok 12:34:31.0843 1740 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 12:34:32.0031 1740 TermDD - ok 12:34:32.0171 1740 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll 12:34:32.0453 1740 TermService - ok 12:34:32.0531 1740 [ 1D265CD2FB1673A0873BF8CEC19DDC7F ] tfsnboio C:\WINDOWS\system32\dla\tfsnboio.sys 12:34:32.0562 1740 tfsnboio ( UnsignedFile.Multi.Generic ) - warning 12:34:32.0562 1740 tfsnboio - detected UnsignedFile.Multi.Generic (1) 12:34:32.0609 1740 [ 62E4901295E0467CAC78E5B4B131AE5C ] tfsncofs C:\WINDOWS\system32\dla\tfsncofs.sys 12:34:32.0625 1740 tfsncofs ( UnsignedFile.Multi.Generic ) - warning 12:34:32.0625 1740 tfsncofs - detected UnsignedFile.Multi.Generic (1) 12:34:32.0656 1740 [ A2F380F9252AB3464C859ADF91EEAD9C ] tfsndrct C:\WINDOWS\system32\dla\tfsndrct.sys 12:34:32.0671 1740 tfsndrct ( UnsignedFile.Multi.Generic ) - warning 12:34:32.0671 1740 tfsndrct - detected UnsignedFile.Multi.Generic (1) 12:34:32.0703 1740 [ EEE79BBEFE9C6A2A3CE6C8753CFEA950 ] tfsndres C:\WINDOWS\system32\dla\tfsndres.sys 12:34:32.0718 1740 tfsndres ( UnsignedFile.Multi.Generic ) - warning 12:34:32.0718 1740 tfsndres - detected UnsignedFile.Multi.Generic (1) 12:34:32.0765 1740 [ 9D644EB11FEC9487450C4CFCD63A5DF4 ] tfsnifs C:\WINDOWS\system32\dla\tfsnifs.sys 12:34:32.0796 1740 tfsnifs ( UnsignedFile.Multi.Generic ) - warning 12:34:32.0796 1740 tfsnifs - detected UnsignedFile.Multi.Generic (1) 12:34:32.0828 1740 [ E656AF05C67EDB7C0E9230A5DF71ED1B ] tfsnopio C:\WINDOWS\system32\dla\tfsnopio.sys 12:34:32.0843 1740 tfsnopio ( UnsignedFile.Multi.Generic ) - warning 12:34:32.0843 1740 tfsnopio - detected UnsignedFile.Multi.Generic (1) 12:34:32.0875 1740 [ 64FCCB9CCE703CA507DFFC3CEBF6B2CB ] tfsnpool C:\WINDOWS\system32\dla\tfsnpool.sys 12:34:32.0890 1740 tfsnpool ( UnsignedFile.Multi.Generic ) - warning 12:34:32.0890 1740 tfsnpool - detected UnsignedFile.Multi.Generic (1) 12:34:32.0937 1740 [ 48BC9D8AB4E4B9BFF70FB18E55CEC3D6 ] tfsnudf C:\WINDOWS\system32\dla\tfsnudf.sys 12:34:32.0984 1740 tfsnudf ( UnsignedFile.Multi.Generic ) - warning 12:34:32.0984 1740 tfsnudf - detected UnsignedFile.Multi.Generic (1) 12:34:33.0031 1740 [ 79F60822224256B49BFC855DA8D651D5 ] tfsnudfa C:\WINDOWS\system32\dla\tfsnudfa.sys 12:34:33.0078 1740 tfsnudfa ( UnsignedFile.Multi.Generic ) - warning 12:34:33.0078 1740 tfsnudfa - detected UnsignedFile.Multi.Generic (1) 12:34:33.0140 1740 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll 12:34:33.0156 1740 Themes - ok 12:34:33.0234 1740 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe 12:34:33.0390 1740 TlntSvr - ok 12:34:33.0421 1740 [ F2790F6AF01321B172AA62F8E1E187D9 ] TosIde C:\WINDOWS\system32\DRIVERS\toside.sys 12:34:33.0609 1740 TosIde - ok 12:34:33.0671 1740 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll 12:34:33.0890 1740 TrkWks - ok 12:34:33.0968 1740 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 12:34:34.0171 1740 Udfs - ok 12:34:34.0250 1740 [ 1B698A51CD528D8DA4FFAED66DFC51B9 ] ultra C:\WINDOWS\system32\DRIVERS\ultra.sys 12:34:34.0375 1740 ultra - ok 12:34:34.0421 1740 [ AB0A7CA90D9E3D6A193905DC1715DED0 ] UMWdf C:\WINDOWS\system32\wdfmgr.exe 12:34:34.0531 1740 UMWdf - ok 12:34:34.0703 1740 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 12:34:35.0078 1740 Update - ok 12:34:35.0187 1740 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll 12:34:35.0375 1740 upnphost - ok 12:34:35.0406 1740 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe 12:34:35.0609 1740 UPS - ok 12:34:35.0656 1740 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 12:34:35.0859 1740 usbehci - ok 12:34:35.0937 1740 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 12:34:36.0140 1740 usbhub - ok 12:34:36.0203 1740 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 12:34:36.0468 1740 USBSTOR - ok 12:34:36.0531 1740 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 12:34:36.0750 1740 usbuhci - ok 12:34:36.0781 1740 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 12:34:36.0984 1740 VgaSave - ok 12:34:37.0046 1740 [ 754292CE5848B3738281B4F3607EAEF4 ] viaagp C:\WINDOWS\system32\DRIVERS\viaagp.sys 12:34:37.0250 1740 viaagp - ok 12:34:37.0296 1740 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys 12:34:37.0484 1740 ViaIde - ok 12:34:37.0546 1740 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 12:34:37.0750 1740 VolSnap - ok 12:34:37.0890 1740 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe 12:34:38.0078 1740 VSS - ok 12:34:38.0171 1740 [ 54AF4B1D5459500EF0937F6D33B1914F ] w32time C:\WINDOWS\system32\w32time.dll 12:34:38.0421 1740 w32time - ok 12:34:38.0500 1740 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 12:34:38.0687 1740 Wanarp - ok 12:34:38.0703 1740 wanatw - ok 12:34:38.0734 1740 WDICA - ok 12:34:38.0828 1740 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 12:34:39.0031 1740 wdmaud - ok 12:34:39.0093 1740 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll 12:34:39.0312 1740 WebClient - ok 12:34:39.0484 1740 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 12:34:39.0687 1740 winmgmt - ok 12:34:39.0796 1740 [ 140EF97B64F560FD78643CAE2CDAD838 ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll 12:34:39.0875 1740 WmdmPmSN - ok 12:34:40.0093 1740 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll 12:34:40.0468 1740 Wmi - ok 12:34:40.0546 1740 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 12:34:40.0765 1740 WmiApSrv - ok 12:34:40.0796 1740 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys 12:34:40.0984 1740 WS2IFSL - ok 12:34:41.0046 1740 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll 12:34:41.0328 1740 wscsvc - ok 12:34:41.0375 1740 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll 12:34:41.0562 1740 wuauserv - ok 12:34:41.0765 1740 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 12:34:42.0171 1740 WZCSVC - ok 12:34:42.0296 1740 [ DDD8286B88FE764AD2A8BD171E7B569A ] xmasbus C:\WINDOWS\system32\DRIVERS\xmasbus.sys 12:34:42.0343 1740 xmasbus ( UnsignedFile.Multi.Generic ) - warning 12:34:42.0343 1740 xmasbus - detected UnsignedFile.Multi.Generic (1) 12:34:42.0375 1740 [ 2222677F06FB7FBE44B04316437585D2 ] xmasscsi C:\WINDOWS\system32\Drivers\xmasscsi.sys 12:34:42.0390 1740 xmasscsi ( UnsignedFile.Multi.Generic ) - warning 12:34:42.0390 1740 xmasscsi - detected UnsignedFile.Multi.Generic (1) 12:34:42.0468 1740 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 12:34:42.0687 1740 xmlprov - ok 12:34:42.0703 1740 ================ Scan global =============================== 12:34:42.0781 1740 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll 12:34:42.0906 1740 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll 12:34:43.0109 1740 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll 12:34:43.0156 1740 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe 12:34:43.0156 1740 [Global] - ok 12:34:43.0156 1740 ================ Scan MBR ================================== 12:34:43.0187 1740 [ B16A2359F4962B0C622D81A1C1F4B703 ] \Device\Harddisk0\DR0 12:34:43.0187 1740 Suspicious mbr (Forged): \Device\Harddisk0\DR0 12:34:43.0218 1740 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected 12:34:43.0218 1740 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0) 12:34:43.0296 1740 \Device\Harddisk0\DR0 ( TDSS File System ) - warning 12:34:43.0296 1740 \Device\Harddisk0\DR0 - detected TDSS File System (1) 12:34:43.0296 1740 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR4 12:34:43.0421 1740 \Device\Harddisk1\DR4 - ok 12:34:43.0421 1740 ================ Scan VBR ================================== 12:34:43.0453 1740 [ F91B2ABF342CCA128AD36D2858A29125 ] \Device\Harddisk0\DR0\Partition1 12:34:43.0453 1740 \Device\Harddisk0\DR0\Partition1 - ok 12:34:43.0468 1740 [ F04B61A23EE30C35E406F694D410833D ] \Device\Harddisk1\DR4\Partition1 12:34:43.0468 1740 \Device\Harddisk1\DR4\Partition1 - ok 12:34:43.0484 1740 ============================================================ 12:34:43.0484 1740 Scan finished 12:34:43.0484 1740 ============================================================ 12:34:43.0625 1732 Detected object count: 24 12:34:43.0625 1732 Actual detected object count: 24 12:43:12.0937 1732 drvmcdb ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:12.0937 1732 drvmcdb ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:12.0953 1732 drvnddm ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:12.0953 1732 drvnddm ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:12.0968 1732 DSproct ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:12.0968 1732 DSproct ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:12.0968 1732 LxrSII1d ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:12.0968 1732 LxrSII1d ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:12.0984 1732 NetSvc ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:12.0984 1732 NetSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:13.0000 1732 O&O Defrag ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:13.0000 1732 O&O Defrag ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:13.0015 1732 omci ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:13.0015 1732 omci ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:13.0015 1732 PxHelp20 ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:13.0015 1732 PxHelp20 ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:13.0031 1732 SeagateDashboardService ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:13.0031 1732 SeagateDashboardService ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:13.0046 1732 sscdbhk5 ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:13.0046 1732 sscdbhk5 ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:13.0046 1732 ssrtln ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:13.0046 1732 ssrtln ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:13.0062 1732 tfsnboio ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:13.0062 1732 tfsnboio ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:13.0078 1732 tfsncofs ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:13.0078 1732 tfsncofs ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:13.0078 1732 tfsndrct ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:13.0078 1732 tfsndrct ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:13.0093 1732 tfsndres ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:13.0093 1732 tfsndres ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:13.0109 1732 tfsnifs ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:13.0109 1732 tfsnifs ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:13.0109 1732 tfsnopio ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:13.0109 1732 tfsnopio ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:13.0125 1732 tfsnpool ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:13.0125 1732 tfsnpool ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:13.0140 1732 tfsnudf ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:13.0140 1732 tfsnudf ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:13.0156 1732 tfsnudfa ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:13.0156 1732 tfsnudfa ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:13.0156 1732 xmasbus ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:13.0156 1732 xmasbus ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:13.0171 1732 xmasscsi ( UnsignedFile.Multi.Generic ) - skipped by user 12:43:13.0171 1732 xmasscsi ( UnsignedFile.Multi.Generic ) - User select action: Skip 12:43:14.0265 1732 \Device\Harddisk0\DR0\# - copied to quarantine 12:43:14.0265 1732 \Device\Harddisk0\DR0 - copied to quarantine 12:43:14.0343 1732 \Device\Harddisk0\DR0\TDLFS\ldrm - copied to quarantine 12:43:14.0359 1732 \Device\Harddisk0\DR0\TDLFS\cmd.dll - copied to quarantine 12:43:14.0375 1732 \Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine 12:43:14.0390 1732 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine 12:43:14.0406 1732 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine 12:43:14.0437 1732 \Device\Harddisk0\DR0\TDLFS\servers.dat - copied to quarantine 12:43:14.0437 1732 \Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine 12:43:14.0453 1732 \Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine 12:43:14.0453 1732 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine 12:43:14.0453 1732 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine 12:43:14.0453 1732 \Device\Harddisk0\DR0\TDLFS\s - copied to quarantine 12:43:14.0484 1732 \Device\Harddisk0\DR0\TDLFS\u - copied to quarantine 12:43:14.0484 1732 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - will be cured on reboot 12:43:14.0484 1732 \Device\Harddisk0\DR0 - ok 12:43:14.0484 1732 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - User select action: Cure 12:43:14.0484 1732 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user 12:43:14.0500 1732 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip 12:44:06.0234 1328 Deinitialize success
Hi oldman960, I did the last scan in safe mode but rebooted to normal and so far the computer is much better. I can open programs now and the computer is currently downloading automatic updates to windows, java etc which it hasn't been able to do for a while.
Hi EricDSr,

Your system has been infected by one or more Rootkits/Backdoor Trojans.

This may allow hackers to remotely control your computer, steal critical system information and Download and Execute files

More information on Remote Access Trojans can be found here.

I strongly suggest you do the following immediately:
  • From a known clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer until it has been cleaned.

Let the updates finish then continue with cleaning.

Rerun TDSSK and when presented with this line select delete.

12:43:14.0484 1732 \Device\Harddisk0\DR0 ( TDSS File System )


Next, please delete the copy of combofix (jgh.exe) you have and download a new copy from HERE . You shouldn't need to rename it this time.

Disable your security programs before running combofix.

Please post back with
  • TDSSK log
  • combofix log
How is the computer?

Thanks
Hi oldman960,

The computer seems pretty good

When the computer finished updating windows I rebooted into normal mode to finish the installation and McCaffe notices poped up four times indicating that a trojan had been found and removed.

TDSSKIller run as instructed with no problems.

I then got a windows error notice for McHlp32.exe indicating that a certain referenced memory could not be found or read. I clicked on "OK" to continue.

I the downloaded and ran ComboFix after disabling antivirus.

ZeroAccess was again found and required a reboot after which the scan continued.

Thanks.

Logs follow:
______________________________________________

14:17:20.0046 0140 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
14:17:21.0453 0140 ============================================================
14:17:21.0453 0140 Current date / time: 2013/03/29 14:17:21.0453
14:17:21.0453 0140 SystemInfo:
14:17:21.0453 0140
14:17:21.0453 0140 OS Version: 5.1.2600 ServicePack: 3.0
14:17:21.0453 0140 Product type: Workstation
14:17:21.0453 0140 ComputerName: IRWINA
14:17:21.0453 0140 UserName: Amy
14:17:21.0453 0140 Windows directory: C:\WINDOWS
14:17:21.0453 0140 System windows directory: C:\WINDOWS
14:17:21.0453 0140 Processor architecture: Intel x86
14:17:21.0453 0140 Number of processors: 2
14:17:21.0453 0140 Page size: 0x1000
14:17:21.0453 0140 Boot type: Normal boot
14:17:21.0453 0140 ============================================================
14:17:31.0390 0140 Drive \Device\Harddisk0\DR0 - Size: 0x12A05F2000 (74.51 Gb), SectorSize: 0x200, Cylinders: 0x25FE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
14:17:31.0500 0140 ============================================================
14:17:31.0500 0140 \Device\Harddisk0\DR0:
14:17:31.0734 0140 MBR partitions:
14:17:31.0734 0140 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1F608, BlocksNum 0x8ECA268
14:17:31.0734 0140 ============================================================
14:17:31.0828 0140 C: <-> \Device\Harddisk0\DR0\Partition1
14:17:31.0875 0140 ============================================================
14:17:31.0875 0140 Initialize success
14:17:31.0875 0140 ============================================================
14:21:27.0968 2604 ============================================================
14:21:27.0968 2604 Scan started
14:21:27.0968 2604 Mode: Manual; SigCheck; TDLFS;
14:21:27.0968 2604 ============================================================
14:21:28.0406 2604 ================ Scan system memory ========================
14:21:28.0406 2604 System memory - ok
14:21:28.0406 2604 ================ Scan services =============================
14:21:28.0593 2604 Abiosdsk - ok
14:21:28.0640 2604 [ 6ABB91494FE6C59089B9336452AB2EA3 ] abp480n5 C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
14:21:28.0906 2604 abp480n5 - ok
14:21:28.0953 2604 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
14:21:29.0093 2604 ACPI - ok
14:21:29.0156 2604 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
14:21:29.0296 2604 ACPIEC - ok
14:21:29.0390 2604 [ EA856F4A46320389D1899B2CAA7BF40F ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
14:21:29.0421 2604 AdobeFlashPlayerUpdateSvc - ok
14:21:29.0468 2604 [ 9A11864873DA202C996558B2106B0BBC ] adpu160m C:\WINDOWS\system32\DRIVERS\adpu160m.sys
14:21:29.0625 2604 adpu160m - ok
14:21:29.0656 2604 [ 11C04B17ED2ABBB4833694BCD644AC90 ] aeaudio C:\WINDOWS\system32\drivers\aeaudio.sys
14:21:29.0734 2604 aeaudio - ok
14:21:29.0765 2604 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
14:21:29.0906 2604 aec - ok
14:21:29.0953 2604 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
14:21:30.0000 2604 AFD - ok
14:21:30.0015 2604 [ 08FD04AA961BDC77FB983F328334E3D7 ] agp440 C:\WINDOWS\system32\DRIVERS\agp440.sys
14:21:30.0171 2604 agp440 - ok
14:21:30.0187 2604 [ 03A7E0922ACFE1B07D5DB2EEB0773063 ] agpCPQ C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
14:21:30.0359 2604 agpCPQ - ok
14:21:30.0375 2604 [ C23EA9B5F46C7F7910DB3EAB648FF013 ] Aha154x C:\WINDOWS\system32\DRIVERS\aha154x.sys
14:21:30.0500 2604 Aha154x - ok
14:21:30.0515 2604 [ 19DD0FB48B0C18892F70E2E7D61A1529 ] aic78u2 C:\WINDOWS\system32\DRIVERS\aic78u2.sys
14:21:30.0734 2604 aic78u2 - ok
14:21:30.0750 2604 [ B7FE594A7468AA0132DEB03FB8E34326 ] aic78xx C:\WINDOWS\system32\DRIVERS\aic78xx.sys
14:21:30.0968 2604 aic78xx - ok
14:21:31.0015 2604 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
14:21:31.0250 2604 Alerter - ok
14:21:31.0265 2604 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe
14:21:31.0390 2604 ALG - ok
14:21:31.0406 2604 [ 1140AB9938809700B46BB88E46D72A96 ] AliIde C:\WINDOWS\system32\DRIVERS\aliide.sys
14:21:31.0609 2604 AliIde - ok
14:21:31.0640 2604 [ CB08AED0DE2DD889A8A820CD8082D83C ] alim1541 C:\WINDOWS\system32\DRIVERS\alim1541.sys
14:21:31.0875 2604 alim1541 - ok
14:21:31.0875 2604 [ 95B4FB835E28AA1336CEEB07FD5B9398 ] amdagp C:\WINDOWS\system32\DRIVERS\amdagp.sys
14:21:32.0140 2604 amdagp - ok
14:21:32.0140 2604 [ 79F5ADD8D24BD6893F2903A3E2F3FAD6 ] amsint C:\WINDOWS\system32\DRIVERS\amsint.sys
14:21:32.0265 2604 amsint - ok
14:21:32.0328 2604 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
14:21:32.0437 2604 AppMgmt - ok
14:21:32.0468 2604 [ 62D318E9A0C8FC9B780008E724283707 ] asc C:\WINDOWS\system32\DRIVERS\asc.sys
14:21:32.0640 2604 asc - ok
14:21:32.0656 2604 [ 69EB0CC7714B32896CCBFD5EDCBEA447 ] asc3350p C:\WINDOWS\system32\DRIVERS\asc3350p.sys
14:21:32.0750 2604 asc3350p - ok
14:21:32.0765 2604 [ 5D8DE112AA0254B907861E9E9C31D597 ] asc3550 C:\WINDOWS\system32\DRIVERS\asc3550.sys
14:21:32.0906 2604 asc3550 - ok
14:21:33.0125 2604 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
14:21:33.0156 2604 aspnet_state - ok
14:21:33.0187 2604 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
14:21:33.0359 2604 AsyncMac - ok
14:21:33.0406 2604 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
14:21:33.0562 2604 atapi - ok
14:21:33.0562 2604 Atdisk - ok
14:21:33.0718 2604 [ 4DEAA162480367B232F3EE3A6D34084B ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe
14:21:33.0781 2604 Ati HotKey Poller - ok
14:21:34.0000 2604 [ F0D0B0CDEC0BE32D775F404CAC2604BF ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
14:21:34.0093 2604 ati2mtag - ok
14:21:34.0109 2604 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
14:21:34.0281 2604 Atmarpc - ok
14:21:34.0312 2604 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
14:21:34.0546 2604 AudioSrv - ok
14:21:34.0578 2604 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
14:21:34.0828 2604 audstub - ok
14:21:34.0890 2604 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
14:21:35.0140 2604 Beep - ok
14:21:35.0187 2604 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll
14:21:35.0421 2604 BITS - ok
14:21:35.0453 2604 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll
14:21:35.0531 2604 Browser - ok
14:21:35.0546 2604 bvrp_pci - ok
14:21:35.0640 2604 catchme - ok
14:21:35.0656 2604 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
14:21:35.0812 2604 cbidf - ok
14:21:35.0828 2604 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
14:21:35.0968 2604 cbidf2k - ok
14:21:35.0984 2604 [ F3EC03299634490E97BBCE94CD2954C7 ] cd20xrnt C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
14:21:36.0078 2604 cd20xrnt - ok
14:21:36.0125 2604 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
14:21:36.0312 2604 Cdaudio - ok
14:21:36.0343 2604 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
14:21:36.0593 2604 Cdfs - ok
14:21:36.0625 2604 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
14:21:36.0843 2604 Cdrom - ok
14:21:36.0875 2604 [ 25C323075C5EA4A2555E35355A01F793 ] cfwids C:\WINDOWS\system32\drivers\cfwids.sys
14:21:36.0968 2604 cfwids - ok
14:21:36.0984 2604 Changer - ok
14:21:37.0015 2604 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe
14:21:37.0265 2604 CiSvc - ok
14:21:37.0312 2604 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
14:21:37.0546 2604 ClipSrv - ok
14:21:37.0625 2604 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
14:21:37.0656 2604 clr_optimization_v2.0.50727_32 - ok
14:21:37.0671 2604 [ E5DCB56C533014ECBC556A8357C929D5 ] CmdIde C:\WINDOWS\system32\DRIVERS\cmdide.sys
14:21:37.0906 2604 CmdIde - ok
14:21:37.0921 2604 COMSysApp - ok
14:21:37.0937 2604 [ 3EE529119EED34CD212A215E8C40D4B6 ] Cpqarray C:\WINDOWS\system32\DRIVERS\cpqarray.sys
14:21:38.0125 2604 Cpqarray - ok
14:21:38.0156 2604 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
14:21:38.0343 2604 CryptSvc - ok
14:21:38.0390 2604 [ E550E7418984B65A78299D248F0A7F36 ] dac2w2k C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
14:21:38.0640 2604 dac2w2k - ok
14:21:38.0656 2604 [ 683789CAA3864EB46125AE86FF677D34 ] dac960nt C:\WINDOWS\system32\DRIVERS\dac960nt.sys
14:21:38.0890 2604 dac960nt - ok
14:21:38.0937 2604 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
14:21:39.0031 2604 DcomLaunch - ok
14:21:39.0078 2604 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
14:21:39.0296 2604 Dhcp - ok
14:21:39.0312 2604 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
14:21:39.0562 2604 Disk - ok
14:21:39.0578 2604 dmadmin - ok
14:21:39.0640 2604 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
14:21:39.0953 2604 dmboot - ok
14:21:39.0953 2604 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys
14:21:40.0218 2604 dmio - ok
14:21:40.0250 2604 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
14:21:40.0500 2604 dmload - ok
14:21:40.0531 2604 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll
14:21:40.0750 2604 dmserver - ok
14:21:40.0796 2604 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
14:21:41.0015 2604 DMusic - ok
14:21:41.0078 2604 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
14:21:41.0250 2604 Dnscache - ok
14:21:41.0296 2604 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
14:21:41.0531 2604 Dot3svc - ok
14:21:41.0562 2604 [ 40F3B93B4E5B0126F2F5C0A7A5E22660 ] dpti2o C:\WINDOWS\system32\DRIVERS\dpti2o.sys
14:21:41.0796 2604 dpti2o - ok
14:21:41.0828 2604 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
14:21:42.0062 2604 drmkaud - ok
14:21:42.0093 2604 [ B15F9E526BA511A48B1B1B8537815740 ] drvmcdb C:\WINDOWS\system32\drivers\drvmcdb.sys
14:21:42.0125 2604 drvmcdb ( UnsignedFile.Multi.Generic ) - warning
14:21:42.0125 2604 drvmcdb - detected UnsignedFile.Multi.Generic (1)
14:21:42.0140 2604 [ FA4670CAE95AE2BB857C68E535661145 ] drvnddm C:\WINDOWS\system32\drivers\drvnddm.sys
14:21:42.0156 2604 drvnddm ( UnsignedFile.Multi.Generic ) - warning
14:21:42.0156 2604 drvnddm - detected UnsignedFile.Multi.Generic (1)
14:21:42.0281 2604 [ FE80901578E7E3DA70299A5AEB2B7FBD ] DSBrokerService C:\Program Files\DellSupport\brkrsvc.exe
14:21:42.0312 2604 DSBrokerService - ok
14:21:42.0406 2604 [ 413F2D5F9D802688242C23B38F767ECB ] DSproct C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
14:21:42.0421 2604 DSproct ( UnsignedFile.Multi.Generic ) - warning
14:21:42.0421 2604 DSproct - detected UnsignedFile.Multi.Generic (1)
14:21:42.0468 2604 [ DFEABB7CFFFADEA4A912AB95BDC3177A ] dsunidrv C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
14:21:42.0546 2604 dsunidrv - ok
14:21:42.0609 2604 [ 7D91DC6342248369F94D6EBA0CF42E99 ] E100B C:\WINDOWS\system32\DRIVERS\e100b325.sys
14:21:42.0671 2604 E100B - ok
14:21:42.0718 2604 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll
14:21:42.0984 2604 EapHost - ok
14:21:43.0015 2604 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll
14:21:43.0265 2604 ERSvc - ok
14:21:43.0312 2604 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe
14:21:43.0359 2604 Eventlog - ok
14:21:43.0421 2604 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll
14:21:43.0531 2604 EventSystem - ok
14:21:43.0562 2604 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
14:21:43.0828 2604 Fastfat - ok
14:21:43.0859 2604 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
14:21:44.0000 2604 FastUserSwitchingCompatibility - ok
14:21:44.0062 2604 [ E97D6A8684466DF94FF3BC24FB787A07 ] Fax C:\WINDOWS\system32\fxssvc.exe
14:21:44.0328 2604 Fax - ok
14:21:44.0359 2604 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
14:21:44.0609 2604 Fdc - ok
14:21:44.0640 2604 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
14:21:44.0890 2604 Fips - ok
14:21:44.0906 2604 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
14:21:45.0171 2604 Flpydisk - ok
14:21:45.0203 2604 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
14:21:45.0468 2604 FltMgr - ok
14:21:45.0562 2604 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
14:21:45.0609 2604 FontCache3.0.0.0 - ok
14:21:45.0640 2604 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
14:21:45.0875 2604 Fs_Rec - ok
14:21:45.0906 2604 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
14:21:46.0156 2604 Ftdisk - ok
14:21:46.0281 2604 [ 0B53F4306E17025E7685D18C3A77127E ] GoToMyPC C:\Program Files\Citrix\GoToMyPC\g2svc.exe
14:21:46.0390 2604 GoToMyPC - ok
14:21:46.0421 2604 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
14:21:46.0687 2604 Gpc - ok
14:21:46.0796 2604 [ CC839E8D766CC31A7710C9F38CF3E375 ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
14:21:46.0843 2604 gusvc - ok
14:21:46.0921 2604 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
14:21:47.0171 2604 helpsvc - ok
14:21:47.0171 2604 HidServ - ok
14:21:47.0218 2604 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
14:21:47.0500 2604 hkmsvc - ok
14:21:47.0531 2604 [ B028377DEA0546A5FCFBA928A8AEFAE0 ] hpn C:\WINDOWS\system32\DRIVERS\hpn.sys
14:21:47.0765 2604 hpn - ok
14:21:47.0796 2604 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
14:21:47.0875 2604 HTTP - ok
14:21:47.0921 2604 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
14:21:48.0156 2604 HTTPFilter - ok
14:21:48.0187 2604 [ 9368670BD426EBEA5E8B18A62416EC28 ] i2omgmt C:\WINDOWS\system32\drivers\i2omgmt.sys
14:21:48.0421 2604 i2omgmt - ok
14:21:48.0453 2604 [ F10863BF1CCC290BABD1A09188AE49E0 ] i2omp C:\WINDOWS\system32\DRIVERS\i2omp.sys
14:21:48.0718 2604 i2omp - ok
14:21:48.0734 2604 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
14:21:48.0968 2604 i8042prt - ok
14:21:49.0062 2604 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
14:21:49.0171 2604 idsvc - ok
14:21:49.0203 2604 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
14:21:49.0468 2604 Imapi - ok
14:21:49.0500 2604 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe
14:21:49.0765 2604 ImapiService - ok
14:21:49.0781 2604 [ 4A40E045FAEE58631FD8D91AFC620719 ] ini910u C:\WINDOWS\system32\DRIVERS\ini910u.sys
14:21:50.0015 2604 ini910u - ok
14:21:50.0109 2604 [ 7509C548400F4C9E0211E3F6E66ABBE6 ] IntelC51 C:\WINDOWS\system32\DRIVERS\IntelC51.sys
14:21:50.0218 2604 IntelC51 - ok
14:21:50.0250 2604 [ 9584FFDD41D37F2C239681D0DAC2513E ] IntelC52 C:\WINDOWS\system32\DRIVERS\IntelC52.sys
14:21:50.0343 2604 IntelC52 - ok
14:21:50.0359 2604 [ CF0B937710CEC6EF39416EDECD803CBB ] IntelC53 C:\WINDOWS\system32\DRIVERS\IntelC53.sys
14:21:50.0406 2604 IntelC53 - ok
14:21:50.0453 2604 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys
14:21:50.0765 2604 IntelIde - ok
14:21:50.0812 2604 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
14:21:51.0031 2604 intelppm - ok
14:21:51.0078 2604 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys
14:21:51.0296 2604 Ip6Fw - ok
14:21:51.0359 2604 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
14:21:51.0593 2604 IpFilterDriver - ok
14:21:51.0625 2604 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
14:21:51.0859 2604 IpInIp - ok
14:21:51.0906 2604 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
14:21:52.0140 2604 IpNat - ok
14:21:52.0171 2604 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
14:21:52.0421 2604 IPSec - ok
14:21:52.0437 2604 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
14:21:52.0578 2604 IRENUM - ok
14:21:52.0625 2604 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
14:21:52.0859 2604 isapnp - ok
14:21:53.0000 2604 [ 999DB5F88C8E145CCA9D471E33227143 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
14:21:53.0046 2604 JavaQuickStarterService - ok
14:21:53.0078 2604 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
14:21:53.0296 2604 Kbdclass - ok
14:21:53.0328 2604 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
14:21:53.0578 2604 kmixer - ok
14:21:53.0609 2604 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
14:21:53.0703 2604 KSecDD - ok
14:21:53.0750 2604 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
14:21:53.0843 2604 lanmanserver - ok
14:21:53.0890 2604 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
14:21:53.0984 2604 lanmanworkstation - ok
14:21:54.0000 2604 lbrtfdc - ok
14:21:54.0046 2604 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
14:21:54.0296 2604 LmHosts - ok
14:21:54.0343 2604 [ 7C12F93C005021861A36C11DF951891A ] LxrSII1d C:\WINDOWS\system32\Drivers\LxrSII1d.sys
14:21:54.0359 2604 LxrSII1d ( UnsignedFile.Multi.Generic ) - warning
14:21:54.0359 2604 LxrSII1d - detected UnsignedFile.Multi.Generic (1)
14:21:54.0359 2604 LxrSII1s - ok
14:21:54.0484 2604 [ DDCC236009C707761D60E5C76D639176 ] McComponentHostService C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe
14:21:54.0531 2604 McComponentHostService - ok
14:21:54.0687 2604 [ ECAB006AC6136F1307E140B633CDB8C2 ] mcmscsvc C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
14:21:54.0734 2604 mcmscsvc - ok
14:21:54.0765 2604 [ ECAB006AC6136F1307E140B633CDB8C2 ] McNaiAnn C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
14:21:54.0812 2604 McNaiAnn - ok
14:21:54.0828 2604 [ ECAB006AC6136F1307E140B633CDB8C2 ] McNASvc C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
14:21:54.0875 2604 McNASvc - ok
14:21:54.0937 2604 [ C7DA06C9A9AEEFBE37AAC281EA6385D5 ] McODS C:\Program Files\McAfee\VirusScan\mcods.exe
14:21:54.0984 2604 McODS - ok
14:21:55.0000 2604 [ ECAB006AC6136F1307E140B633CDB8C2 ] McProxy C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
14:21:55.0046 2604 McProxy - ok
14:21:55.0140 2604 [ 6FE0532CB16300C09D098F808EAAEE9D ] McShield C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
14:21:55.0187 2604 McShield - ok
14:21:55.0265 2604 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
14:21:55.0328 2604 MDM - ok
14:21:55.0421 2604 [ 0377F70E41FEFA850B96A8FB157C5681 ] MemeoBackgroundService C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe
14:21:55.0453 2604 MemeoBackgroundService - ok
14:21:55.0484 2604 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll
14:21:55.0734 2604 Messenger - ok
14:21:55.0781 2604 [ 6708AD7D9ABDD6FDE1EB9B54FFE426B0 ] mfeapfk C:\WINDOWS\system32\drivers\mfeapfk.sys
14:21:55.0828 2604 mfeapfk - ok
14:21:55.0875 2604 [ 375DE90B68533D9D0D7766D4CCB4CA32 ] mfeavfk C:\WINDOWS\system32\drivers\mfeavfk.sys
14:21:55.0921 2604 mfeavfk - ok
14:21:55.0937 2604 mfeavfk01 - ok
14:21:55.0953 2604 [ 5ED806D4DF27AC11236BD9AD2CC10B7E ] mfebopk C:\WINDOWS\system32\drivers\mfebopk.sys
14:21:56.0000 2604 mfebopk - ok
14:21:56.0031 2604 [ 1A427BB508ACBEE09A88F08D1CA38E2F ] mfefire C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
14:21:56.0078 2604 mfefire - ok
14:21:56.0109 2604 [ 16BF9475BFCFAA420A8CB29E40284457 ] mfefirek C:\WINDOWS\system32\drivers\mfefirek.sys
14:21:56.0156 2604 mfefirek - ok
14:21:56.0203 2604 [ 875452ECDF4AEBE12B8C2EFD8599A36F ] mfehidk C:\WINDOWS\system32\drivers\mfehidk.sys
14:21:56.0281 2604 mfehidk - ok
14:21:56.0328 2604 [ 3004E3FE086E76D7D6DFB9A851ED6F10 ] mfendisk C:\WINDOWS\system32\DRIVERS\mfendisk.sys
14:21:56.0375 2604 mfendisk - ok
14:21:56.0390 2604 [ 3004E3FE086E76D7D6DFB9A851ED6F10 ] mfendiskmp C:\WINDOWS\system32\DRIVERS\mfendisk.sys
14:21:56.0421 2604 mfendiskmp - ok
14:21:56.0468 2604 [ D669ACBE7672819109706C3CFF6BD1DB ] mferkdet C:\WINDOWS\system32\drivers\mferkdet.sys
14:21:56.0500 2604 mferkdet - ok
14:21:56.0546 2604 [ 1328C929A2F801BB93DBDFCDC25E0E7A ] mfetdi2k C:\WINDOWS\system32\drivers\mfetdi2k.sys
14:21:56.0593 2604 mfetdi2k - ok
14:21:56.0625 2604 [ D66A1A16166897A5F7D04961F582F03B ] mfevtp C:\WINDOWS\system32\mfevtps.exe
14:21:56.0671 2604 mfevtp - ok
14:21:56.0734 2604 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
14:21:57.0000 2604 mnmdd - ok
14:21:57.0046 2604 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
14:21:57.0296 2604 mnmsrvc - ok
14:21:57.0328 2604 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
14:21:57.0562 2604 Modem - ok
14:21:57.0593 2604 [ 1992E0D143B09653AB0F9C5E04B0FD65 ] MODEMCSA C:\WINDOWS\system32\drivers\MODEMCSA.sys
14:21:57.0843 2604 MODEMCSA - ok
14:21:57.0843 2604 [ 59B8B11FF70728EEC60E72131C58B716 ] mohfilt C:\WINDOWS\system32\DRIVERS\mohfilt.sys
14:21:57.0906 2604 mohfilt - ok
14:21:57.0937 2604 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
14:21:58.0171 2604 Mouclass - ok
14:21:58.0203 2604 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
14:21:58.0468 2604 MountMgr - ok
14:21:58.0515 2604 [ 8A7C8F4C713E70D73946833D76B77035 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
14:21:58.0578 2604 MozillaMaintenance - ok
14:21:58.0578 2604 [ 3F4BB95E5A44F3BE34824E8E7CAF0737 ] mraid35x C:\WINDOWS\system32\DRIVERS\mraid35x.sys
14:21:58.0843 2604 mraid35x - ok
14:21:58.0890 2604 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
14:21:59.0140 2604 MRxDAV - ok
14:21:59.0187 2604 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
14:21:59.0296 2604 MRxSmb - ok
14:21:59.0328 2604 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe
14:21:59.0562 2604 MSDTC - ok
14:21:59.0578 2604 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
14:21:59.0843 2604 Msfs - ok
14:21:59.0859 2604 MSIServer - ok
14:21:59.0906 2604 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
14:22:00.0125 2604 MSKSSRV - ok
14:22:00.0140 2604 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
14:22:00.0375 2604 MSPCLOCK - ok
14:22:00.0406 2604 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
14:22:00.0640 2604 MSPQM - ok
14:22:00.0687 2604 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
14:22:00.0921 2604 mssmbios - ok
14:22:00.0953 2604 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
14:22:01.0062 2604 Mup - ok
14:22:01.0109 2604 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll
14:22:01.0359 2604 napagent - ok
14:22:01.0390 2604 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
14:22:01.0625 2604 NDIS - ok
14:22:01.0671 2604 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
14:22:01.0718 2604 NdisTapi - ok
14:22:01.0734 2604 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
14:22:01.0875 2604 Ndisuio - ok
14:22:01.0921 2604 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
14:22:02.0062 2604 NdisWan - ok
14:22:02.0109 2604 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
14:22:02.0187 2604 NDProxy - ok
14:22:02.0203 2604 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
14:22:02.0359 2604 NetBIOS - ok
14:22:02.0375 2604 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
14:22:02.0515 2604 NetBT - ok
14:22:02.0546 2604 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
14:22:02.0765 2604 NetDDE - ok
14:22:02.0781 2604 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
14:22:03.0000 2604 NetDDEdsdm - ok
14:22:03.0031 2604 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
14:22:03.0281 2604 Netlogon - ok
14:22:03.0312 2604 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
14:22:03.0484 2604 Netman - ok
14:22:03.0687 2604 [ 02D0798F376FCBD0210EDA58476D0B1B ] NetSvc C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
14:22:03.0750 2604 NetSvc ( UnsignedFile.Multi.Generic ) - warning
14:22:03.0750 2604 NetSvc - detected UnsignedFile.Multi.Generic (1)
14:22:03.0937 2604 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
14:22:03.0984 2604 NetTcpPortSharing - ok
14:22:04.0015 2604 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
14:22:04.0078 2604 Nla - ok
14:22:04.0125 2604 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
14:22:04.0312 2604 Npfs - ok
14:22:04.0406 2604 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
14:22:04.0593 2604 Ntfs - ok
14:22:04.0609 2604 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
14:22:04.0781 2604 NtLmSsp - ok
14:22:04.0812 2604 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
14:22:05.0156 2604 NtmsSvc - ok
14:22:05.0171 2604 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
14:22:05.0359 2604 Null - ok
14:22:05.0640 2604 [ 2B298519EDBFCF451D43E0F1E8F1006D ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
14:22:06.0000 2604 nv - ok
14:22:06.0046 2604 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
14:22:06.0281 2604 NwlnkFlt - ok
14:22:06.0312 2604 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
14:22:06.0500 2604 NwlnkFwd - ok
14:22:06.0578 2604 [ 2DDCC672E3A9F615CACE2AB6B9601056 ] O&O Defrag C:\WINDOWS\system32\oodag.exe
14:22:06.0609 2604 O&O Defrag ( UnsignedFile.Multi.Generic ) - warning
14:22:06.0609 2604 O&O Defrag - detected UnsignedFile.Multi.Generic (1)
14:22:06.0671 2604 [ 53D5F1278D9EDB21689BBBCECC09108D ] omci C:\WINDOWS\system32\DRIVERS\omci.sys
14:22:06.0687 2604 omci ( UnsignedFile.Multi.Generic ) - warning
14:22:06.0687 2604 omci - detected UnsignedFile.Multi.Generic (1)
14:22:06.0734 2604 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
14:22:06.0765 2604 ose - ok
14:22:06.0859 2604 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
14:22:07.0078 2604 Parport - ok
14:22:07.0109 2604 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
14:22:07.0328 2604 PartMgr - ok
14:22:07.0375 2604 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
14:22:07.0625 2604 ParVdm - ok
14:22:07.0640 2604 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
14:22:07.0875 2604 PCI - ok
14:22:07.0890 2604 PCIDump - ok
14:22:07.0906 2604 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
14:22:08.0156 2604 PCIIde - ok
14:22:08.0203 2604 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
14:22:08.0421 2604 Pcmcia - ok
14:22:08.0421 2604 PDCOMP - ok
14:22:08.0437 2604 PDFRAME - ok
14:22:08.0453 2604 PDRELI - ok
14:22:08.0453 2604 PDRFRAME - ok
14:22:08.0468 2604 [ 6C14B9C19BA84F73D3A86DBA11133101 ] perc2 C:\WINDOWS\system32\DRIVERS\perc2.sys
14:22:08.0703 2604 perc2 - ok
14:22:08.0734 2604 [ F50F7C27F131AFE7BEBA13E14A3B9416 ] perc2hib C:\WINDOWS\system32\DRIVERS\perc2hib.sys
14:22:08.0953 2604 perc2hib - ok
14:22:09.0000 2604 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
14:22:09.0046 2604 PlugPlay - ok
14:22:09.0062 2604 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
14:22:09.0312 2604 PolicyAgent - ok
14:22:09.0343 2604 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
14:22:09.0562 2604 PptpMiniport - ok
14:22:09.0578 2604 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
14:22:09.0781 2604 ProtectedStorage - ok
14:22:09.0796 2604 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
14:22:10.0000 2604 PSched - ok
14:22:10.0031 2604 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
14:22:10.0265 2604 Ptilink - ok
14:22:10.0296 2604 [ DB3B30C3A4CDCF07E164C14584D9D0F2 ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys
14:22:10.0312 2604 PxHelp20 ( UnsignedFile.Multi.Generic ) - warning
14:22:10.0312 2604 PxHelp20 - detected UnsignedFile.Multi.Generic (1)
14:22:10.0359 2604 [ 0A63FB54039EB5662433CABA3B26DBA7 ] ql1080 C:\WINDOWS\system32\DRIVERS\ql1080.sys
14:22:10.0609 2604 ql1080 - ok
14:22:10.0640 2604 [ 6503449E1D43A0FF0201AD5CB1B8C706 ] Ql10wnt C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
14:22:10.0890 2604 Ql10wnt - ok
14:22:10.0906 2604 [ 156ED0EF20C15114CA097A34A30D8A01 ] ql12160 C:\WINDOWS\system32\DRIVERS\ql12160.sys
14:22:11.0125 2604 ql12160 - ok
14:22:11.0140 2604 [ 70F016BEBDE6D29E864C1230A07CC5E6 ] ql1240 C:\WINDOWS\system32\DRIVERS\ql1240.sys
14:22:11.0421 2604 ql1240 - ok
14:22:11.0437 2604 [ 907F0AEEA6BC451011611E732BD31FCF ] ql1280 C:\WINDOWS\system32\DRIVERS\ql1280.sys
14:22:11.0671 2604 ql1280 - ok
14:22:11.0703 2604 [ 7F599E8BCC5EBC78FA711E9E55EEA40C ] RapidPortM1 C:\WINDOWS\system32\Drivers\CAPM1LP.SYS
14:22:11.0812 2604 RapidPortM1 - ok
14:22:11.0843 2604 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
14:22:12.0062 2604 RasAcd - ok
14:22:12.0109 2604 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
14:22:12.0359 2604 RasAuto - ok
14:22:12.0390 2604 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
14:22:12.0625 2604 Rasl2tp - ok
14:22:12.0671 2604 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
14:22:12.0921 2604 RasMan - ok
14:22:12.0937 2604 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
14:22:13.0171 2604 RasPppoe - ok
14:22:13.0187 2604 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
14:22:13.0437 2604 Raspti - ok
14:22:13.0468 2604 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
14:22:13.0687 2604 Rdbss - ok
14:22:13.0718 2604 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
14:22:13.0937 2604 RDPCDD - ok
14:22:13.0968 2604 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
14:22:14.0203 2604 rdpdr - ok
14:22:14.0250 2604 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
14:22:14.0343 2604 RDPWD - ok
14:22:14.0390 2604 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
14:22:14.0625 2604 RDSessMgr - ok
14:22:14.0640 2604 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
14:22:14.0906 2604 redbook - ok
14:22:14.0968 2604 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
14:22:15.0218 2604 RemoteAccess - ok
14:22:15.0265 2604 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
14:22:15.0531 2604 RemoteRegistry - ok
14:22:15.0562 2604 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe
14:22:15.0812 2604 RpcLocator - ok
14:22:15.0859 2604 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll
14:22:15.0921 2604 RpcSs - ok
14:22:15.0968 2604 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe
14:22:16.0203 2604 RSVP - ok
14:22:16.0218 2604 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
14:22:16.0453 2604 SamSs - ok
14:22:16.0484 2604 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
14:22:16.0718 2604 SCardSvr - ok
14:22:16.0765 2604 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
14:22:17.0015 2604 Schedule - ok
14:22:17.0109 2604 [ A1A26E8EC51E199D873D85F3E2B6FC65 ] SeagateDashboardService C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
14:22:17.0125 2604 SeagateDashboardService ( UnsignedFile.Multi.Generic ) - warning
14:22:17.0125 2604 SeagateDashboardService - detected UnsignedFile.Multi.Generic (1)
14:22:17.0171 2604 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
14:22:17.0296 2604 Secdrv - ok
14:22:17.0328 2604 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
14:22:17.0578 2604 seclogon - ok
14:22:17.0609 2604 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll
14:22:17.0890 2604 SENS - ok
14:22:17.0921 2604 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
14:22:18.0156 2604 serenum - ok
14:22:18.0203 2604 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
14:22:18.0437 2604 Serial - ok
14:22:18.0500 2604 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
14:22:18.0734 2604 Sfloppy - ok
14:22:18.0796 2604 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
14:22:19.0031 2604 SharedAccess - ok
14:22:19.0062 2604 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
14:22:19.0109 2604 ShellHWDetection - ok
14:22:19.0125 2604 Simbad - ok
14:22:19.0171 2604 [ 6B33D0EBD30DB32E27D1D78FE946A754 ] sisagp C:\WINDOWS\system32\DRIVERS\sisagp.sys
14:22:19.0406 2604 sisagp - ok
14:22:19.0484 2604 [ 4AA922332433CDEB8B82C072C212E32E ] smwdm C:\WINDOWS\system32\drivers\smwdm.sys
14:22:19.0578 2604 smwdm - ok
14:22:19.0609 2604 [ 83C0F71F86D3BDAF915685F3D568B20E ] Sparrow C:\WINDOWS\system32\DRIVERS\sparrow.sys
14:22:19.0765 2604 Sparrow - ok
14:22:19.0812 2604 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
14:22:20.0031 2604 splitter - ok
14:22:20.0062 2604 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
14:22:20.0140 2604 Spooler - ok
14:22:20.0156 2604 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
14:22:20.0296 2604 sr - ok
14:22:20.0343 2604 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
14:22:20.0484 2604 srservice - ok
14:22:20.0531 2604 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
14:22:20.0687 2604 Srv - ok
14:22:20.0734 2604 [ D7968049BE0ADBB6A57CEE3960320911 ] sscdbhk5 C:\WINDOWS\system32\drivers\sscdbhk5.sys
14:22:20.0734 2604 sscdbhk5 ( UnsignedFile.Multi.Generic ) - warning
14:22:20.0734 2604 sscdbhk5 - detected UnsignedFile.Multi.Generic (1)
14:22:20.0781 2604 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
14:22:20.0890 2604 SSDPSRV - ok
14:22:20.0906 2604 [ C3FFD65ABFB6441E7606CF74F1155273 ] ssrtln C:\WINDOWS\system32\drivers\ssrtln.sys
14:22:20.0921 2604 ssrtln ( UnsignedFile.Multi.Generic ) - warning
14:22:20.0921 2604 ssrtln - detected UnsignedFile.Multi.Generic (1)
14:22:20.0968 2604 [ A9573045BAA16EAB9B1085205B82F1ED ] StillCam C:\WINDOWS\system32\DRIVERS\serscan.sys
14:22:21.0171 2604 StillCam - ok
14:22:21.0234 2604 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
14:22:21.0484 2604 stisvc - ok
14:22:21.0515 2604 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
14:22:21.0796 2604 swenum - ok
14:22:21.0843 2604 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
14:22:22.0078 2604 swmidi - ok
14:22:22.0093 2604 SwPrv - ok
14:22:22.0125 2604 [ 1FF3217614018630D0A6758630FC698C ] symc810 C:\WINDOWS\system32\DRIVERS\symc810.sys
14:22:22.0359 2604 symc810 - ok
14:22:22.0390 2604 [ 070E001D95CF725186EF8B20335F933C ] symc8xx C:\WINDOWS\system32\DRIVERS\symc8xx.sys
14:22:22.0625 2604 symc8xx - ok
14:22:22.0640 2604 [ 80AC1C4ABBE2DF3B738BF15517A51F2C ] sym_hi C:\WINDOWS\system32\DRIVERS\sym_hi.sys
14:22:22.0875 2604 sym_hi - ok
14:22:22.0890 2604 [ BF4FAB949A382A8E105F46EBB4937058 ] sym_u3 C:\WINDOWS\system32\DRIVERS\sym_u3.sys
14:22:23.0125 2604 sym_u3 - ok
14:22:23.0171 2604 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
14:22:23.0390 2604 sysaudio - ok
14:22:23.0421 2604 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
14:22:23.0656 2604 SysmonLog - ok
14:22:23.0703 2604 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
14:22:23.0968 2604 TapiSrv - ok
14:22:24.0046 2604 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
14:22:24.0093 2604 Tcpip - ok
14:22:24.0125 2604 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
14:22:24.0375 2604 TDPIPE - ok
14:22:24.0421 2604 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
14:22:24.0671 2604 TDTCP - ok
14:22:24.0734 2604 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
14:22:24.0984 2604 TermDD - ok
14:22:25.0046 2604 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
14:22:25.0296 2604 TermService - ok
14:22:25.0343 2604 [ 1D265CD2FB1673A0873BF8CEC19DDC7F ] tfsnboio C:\WINDOWS\system32\dla\tfsnboio.sys
14:22:25.0359 2604 tfsnboio ( UnsignedFile.Multi.Generic ) - warning
14:22:25.0359 2604 tfsnboio - detected UnsignedFile.Multi.Generic (1)
14:22:25.0390 2604 [ 62E4901295E0467CAC78E5B4B131AE5C ] tfsncofs C:\WINDOWS\system32\dla\tfsncofs.sys
14:22:25.0406 2604 tfsncofs ( UnsignedFile.Multi.Generic ) - warning
14:22:25.0406 2604 tfsncofs - detected UnsignedFile.Multi.Generic (1)
14:22:25.0421 2604 [ A2F380F9252AB3464C859ADF91EEAD9C ] tfsndrct C:\WINDOWS\system32\dla\tfsndrct.sys
14:22:25.0437 2604 tfsndrct ( UnsignedFile.Multi.Generic ) - warning
14:22:25.0437 2604 tfsndrct - detected UnsignedFile.Multi.Generic (1)
14:22:25.0453 2604 [ EEE79BBEFE9C6A2A3CE6C8753CFEA950 ] tfsndres C:\WINDOWS\system32\dla\tfsndres.sys
14:22:25.0484 2604 tfsndres ( UnsignedFile.Multi.Generic ) - warning
14:22:25.0484 2604 tfsndres - detected UnsignedFile.Multi.Generic (1)
14:22:25.0500 2604 [ 9D644EB11FEC9487450C4CFCD63A5DF4 ] tfsnifs C:\WINDOWS\system32\dla\tfsnifs.sys
14:22:25.0515 2604 tfsnifs ( UnsignedFile.Multi.Generic ) - warning
14:22:25.0515 2604 tfsnifs - detected UnsignedFile.Multi.Generic (1)
14:22:25.0531 2604 [ E656AF05C67EDB7C0E9230A5DF71ED1B ] tfsnopio C:\WINDOWS\system32\dla\tfsnopio.sys
14:22:25.0546 2604 tfsnopio ( UnsignedFile.Multi.Generic ) - warning
14:22:25.0546 2604 tfsnopio - detected UnsignedFile.Multi.Generic (1)
14:22:25.0562 2604 [ 64FCCB9CCE703CA507DFFC3CEBF6B2CB ] tfsnpool C:\WINDOWS\system32\dla\tfsnpool.sys
14:22:25.0609 2604 tfsnpool ( UnsignedFile.Multi.Generic ) - warning
14:22:25.0609 2604 tfsnpool - detected UnsignedFile.Multi.Generic (1)
14:22:25.0640 2604 [ 48BC9D8AB4E4B9BFF70FB18E55CEC3D6 ] tfsnudf C:\WINDOWS\system32\dla\tfsnudf.sys
14:22:25.0640 2604 tfsnudf ( UnsignedFile.Multi.Generic ) - warning
14:22:25.0640 2604 tfsnudf - detected UnsignedFile.Multi.Generic (1)
14:22:25.0671 2604 [ 79F60822224256B49BFC855DA8D651D5 ] tfsnudfa C:\WINDOWS\system32\dla\tfsnudfa.sys
14:22:25.0671 2604 tfsnudfa ( UnsignedFile.Multi.Generic ) - warning
14:22:25.0671 2604 tfsnudfa - detected UnsignedFile.Multi.Generic (1)
14:22:25.0718 2604 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
14:22:25.0765 2604 Themes - ok
14:22:25.0812 2604 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
14:22:25.0953 2604 TlntSvr - ok
14:22:25.0984 2604 [ F2790F6AF01321B172AA62F8E1E187D9 ] TosIde C:\WINDOWS\system32\DRIVERS\toside.sys
14:22:26.0218 2604 TosIde - ok
14:22:26.0265 2604 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
14:22:26.0515 2604 TrkWks - ok
14:22:26.0562 2604 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
14:22:26.0828 2604 Udfs - ok
14:22:26.0859 2604 [ 1B698A51CD528D8DA4FFAED66DFC51B9 ] ultra C:\WINDOWS\system32\DRIVERS\ultra.sys
14:22:26.0984 2604 ultra - ok
14:22:27.0031 2604 [ AB0A7CA90D9E3D6A193905DC1715DED0 ] UMWdf C:\WINDOWS\system32\wdfmgr.exe
14:22:27.0125 2604 UMWdf - ok
14:22:27.0171 2604 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
14:22:27.0437 2604 Update - ok
14:22:27.0484 2604 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
14:22:27.0625 2604 upnphost - ok
14:22:27.0656 2604 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
14:22:27.0906 2604 UPS - ok
14:22:27.0953 2604 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
14:22:28.0187 2604 usbehci - ok
14:22:28.0250 2604 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
14:22:28.0484 2604 usbhub - ok
14:22:28.0531 2604 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:22:28.0781 2604 USBSTOR - ok
14:22:28.0828 2604 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
14:22:29.0062 2604 usbuhci - ok
14:22:29.0125 2604 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
14:22:29.0375 2604 VgaSave - ok
14:22:29.0390 2604 [ 754292CE5848B3738281B4F3607EAEF4 ] viaagp C:\WINDOWS\system32\DRIVERS\viaagp.sys
14:22:29.0656 2604 viaagp - ok
14:22:29.0703 2604 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys
14:22:29.0937 2604 ViaIde - ok
14:22:29.0984 2604 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
14:22:30.0218 2604 VolSnap - ok
14:22:30.0250 2604 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
14:22:30.0375 2604 VSS - ok
14:22:30.0421 2604 [ 54AF4B1D5459500EF0937F6D33B1914F ] w32time C:\WINDOWS\system32\w32time.dll
14:22:30.0671 2604 w32time - ok
14:22:30.0734 2604 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
14:22:30.0968 2604 Wanarp - ok
14:22:30.0984 2604 wanatw - ok
14:22:30.0984 2604 WDICA - ok
14:22:31.0031 2604 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
14:22:31.0265 2604 wdmaud - ok
14:22:31.0312 2604 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
14:22:31.0531 2604 WebClient - ok
14:22:31.0625 2604 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
14:22:31.0828 2604 winmgmt - ok
14:22:31.0906 2604 [ 140EF97B64F560FD78643CAE2CDAD838 ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
14:22:31.0984 2604 WmdmPmSN - ok
14:22:32.0015 2604 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll
14:22:32.0125 2604 Wmi - ok
14:22:32.0156 2604 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
14:22:32.0390 2604 WmiApSrv - ok
14:22:32.0421 2604 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
14:22:32.0640 2604 WS2IFSL - ok
14:22:32.0687 2604 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
14:22:32.0953 2604 wscsvc - ok
14:22:33.0000 2604 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll
14:22:33.0234 2604 wuauserv - ok
14:22:33.0312 2604 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
14:22:33.0625 2604 WZCSVC - ok
14:22:33.0671 2604 [ DDD8286B88FE764AD2A8BD171E7B569A ] xmasbus C:\WINDOWS\system32\DRIVERS\xmasbus.sys
14:22:33.0687 2604 xmasbus ( UnsignedFile.Multi.Generic ) - warning
14:22:33.0687 2604 xmasbus - detected UnsignedFile.Multi.Generic (1)
14:22:33.0734 2604 [ 2222677F06FB7FBE44B04316437585D2 ] xmasscsi C:\WINDOWS\system32\Drivers\xmasscsi.sys
14:22:33.0734 2604 xmasscsi ( UnsignedFile.Multi.Generic ) - warning
14:22:33.0734 2604 xmasscsi - detected UnsignedFile.Multi.Generic (1)
14:22:33.0781 2604 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
14:22:34.0015 2604 xmlprov - ok
14:22:34.0031 2604 ================ Scan global ===============================
14:22:34.0078 2604 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
14:22:34.0125 2604 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
14:22:34.0156 2604 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
14:22:34.0171 2604 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
14:22:34.0187 2604 [Global] - ok
14:22:34.0187 2604 ================ Scan MBR ==================================
14:22:34.0218 2604 [ B16A2359F4962B0C622D81A1C1F4B703 ] \Device\Harddisk0\DR0
14:22:34.0453 2604 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
14:22:34.0453 2604 \Device\Harddisk0\DR0 - detected TDSS File System (1)
14:22:34.0453 2604 ================ Scan VBR ==================================
14:22:34.0453 2604 [ F91B2ABF342CCA128AD36D2858A29125 ] \Device\Harddisk0\DR0\Partition1
14:22:34.0468 2604 \Device\Harddisk0\DR0\Partition1 - ok
14:22:34.0468 2604 ============================================================
14:22:34.0468 2604 Scan finished
14:22:34.0468 2604 ============================================================
14:22:34.0593 3452 Detected object count: 23
14:22:34.0593 3452 Actual detected object count: 23
14:23:40.0359 3452 drvmcdb ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0359 3452 drvmcdb ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0359 3452 drvnddm ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0359 3452 drvnddm ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0359 3452 DSproct ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0359 3452 DSproct ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0359 3452 LxrSII1d ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0359 3452 LxrSII1d ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0375 3452 NetSvc ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0375 3452 NetSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0375 3452 O&O Defrag ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0375 3452 O&O Defrag ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0375 3452 omci ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0375 3452 omci ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0375 3452 PxHelp20 ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0375 3452 PxHelp20 ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0375 3452 SeagateDashboardService ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0375 3452 SeagateDashboardService ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0375 3452 sscdbhk5 ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0375 3452 sscdbhk5 ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0375 3452 ssrtln ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0375 3452 ssrtln ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0375 3452 tfsnboio ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0375 3452 tfsnboio ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0390 3452 tfsncofs ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0390 3452 tfsncofs ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0390 3452 tfsndrct ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0390 3452 tfsndrct ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0390 3452 tfsndres ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0390 3452 tfsndres ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0390 3452 tfsnifs ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0390 3452 tfsnifs ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0390 3452 tfsnopio ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0390 3452 tfsnopio ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0406 3452 tfsnpool ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0406 3452 tfsnpool ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0406 3452 tfsnudf ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0406 3452 tfsnudf ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0406 3452 tfsnudfa ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0406 3452 tfsnudfa ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0406 3452 xmasbus ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0406 3452 xmasbus ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0406 3452 xmasscsi ( UnsignedFile.Multi.Generic ) - skipped by user
14:23:40.0406 3452 xmasscsi ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:23:40.0468 3452 \Device\Harddisk0\DR0\TDLFS\ldrm - copied to quarantine
14:23:40.0484 3452 \Device\Harddisk0\DR0\TDLFS\cmd.dll - copied to quarantine
14:23:40.0484 3452 \Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine
14:23:40.0500 3452 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine
14:23:40.0500 3452 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine
14:23:40.0500 3452 \Device\Harddisk0\DR0\TDLFS\servers.dat - copied to quarantine
14:23:40.0515 3452 \Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine
14:23:40.0609 3452 \Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine
14:23:40.0609 3452 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine
14:23:40.0625 3452 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine
14:23:40.0625 3452 \Device\Harddisk0\DR0\TDLFS\s - copied to quarantine
14:23:40.0625 3452 \Device\Harddisk0\DR0\TDLFS\u - copied to quarantine
14:23:40.0625 3452 \Device\Harddisk0\DR0\TDLFS - deleted
14:23:40.0625 3452 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Delete
14:24:08.0406 3184 ============================================================
14:24:08.0406 3184 Scan started
14:24:08.0406 3184 Mode: Manual; SigCheck; TDLFS;
14:24:08.0406 3184 ============================================================
14:24:09.0328 3184 ================ Scan system memory ========================
14:24:09.0328 3184 System memory - ok
14:24:09.0328 3184 ================ Scan services =============================
14:24:09.0578 3184 Abiosdsk - ok
14:24:09.0625 3184 [ 6ABB91494FE6C59089B9336452AB2EA3 ] abp480n5 C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
14:24:09.0968 3184 abp480n5 - ok
14:24:10.0015 3184 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
14:24:10.0250 3184 ACPI - ok
14:24:10.0296 3184 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
14:24:10.0609 3184 ACPIEC - ok
14:24:10.0687 3184 [ EA856F4A46320389D1899B2CAA7BF40F ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
14:24:10.0937 3184 AdobeFlashPlayerUpdateSvc - ok
14:24:10.0953 3184 [ 9A11864873DA202C996558B2106B0BBC ] adpu160m C:\WINDOWS\system32\DRIVERS\adpu160m.sys
14:24:11.0531 3184 adpu160m - ok
14:24:11.0562 3184 [ 11C04B17ED2ABBB4833694BCD644AC90 ] aeaudio C:\WINDOWS\system32\drivers\aeaudio.sys
14:24:11.0812 3184 aeaudio - ok
14:24:11.0843 3184 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
14:24:12.0031 3184 aec - ok
14:24:12.0078 3184 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
14:24:12.0265 3184 AFD - ok
14:24:12.0296 3184 [ 08FD04AA961BDC77FB983F328334E3D7 ] agp440 C:\WINDOWS\system32\DRIVERS\agp440.sys
14:24:12.0562 3184 agp440 - ok
14:24:12.0578 3184 [ 03A7E0922ACFE1B07D5DB2EEB0773063 ] agpCPQ C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
14:24:12.0781 3184 agpCPQ - ok
14:24:12.0796 3184 [ C23EA9B5F46C7F7910DB3EAB648FF013 ] Aha154x C:\WINDOWS\system32\DRIVERS\aha154x.sys
14:24:13.0046 3184 Aha154x - ok
14:24:13.0093 3184 [ 19DD0FB48B0C18892F70E2E7D61A1529 ] aic78u2 C:\WINDOWS\system32\DRIVERS\aic78u2.sys
14:24:13.0359 3184 aic78u2 - ok
14:24:13.0359 3184 [ B7FE594A7468AA0132DEB03FB8E34326 ] aic78xx C:\WINDOWS\system32\DRIVERS\aic78xx.sys
14:24:13.0765 3184 aic78xx - ok
14:24:13.0812 3184 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
14:24:14.0015 3184 Alerter - ok
14:24:14.0031 3184 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe
14:24:14.0125 3184 ALG - ok
14:24:14.0140 3184 [ 1140AB9938809700B46BB88E46D72A96 ] AliIde C:\WINDOWS\system32\DRIVERS\aliide.sys
14:24:14.0390 3184 AliIde - ok
14:24:14.0406 3184 [ CB08AED0DE2DD889A8A820CD8082D83C ] alim1541 C:\WINDOWS\system32\DRIVERS\alim1541.sys
14:24:14.0578 3184 alim1541 - ok
14:24:14.0593 3184 [ 95B4FB835E28AA1336CEEB07FD5B9398 ] amdagp C:\WINDOWS\system32\DRIVERS\amdagp.sys
14:24:14.0765 3184 amdagp - ok
14:24:14.0781 3184 [ 79F5ADD8D24BD6893F2903A3E2F3FAD6 ] amsint C:\WINDOWS\system32\DRIVERS\amsint.sys
14:24:15.0015 3184 amsint - ok
14:24:15.0062 3184 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
14:24:15.0234 3184 AppMgmt - ok
14:24:15.0250 3184 [ 62D318E9A0C8FC9B780008E724283707 ] asc C:\WINDOWS\system32\DRIVERS\asc.sys
14:24:15.0687 3184 asc - ok
14:24:15.0703 3184 [ 69EB0CC7714B32896CCBFD5EDCBEA447 ] asc3350p C:\WINDOWS\system32\DRIVERS\asc3350p.sys
14:24:15.0921 3184 asc3350p - ok
14:24:15.0937 3184 [ 5D8DE112AA0254B907861E9E9C31D597 ] asc3550 C:\WINDOWS\system32\DRIVERS\asc3550.sys
14:24:16.0187 3184 asc3550 - ok
14:24:16.0296 3184 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
14:24:16.0437 3184 aspnet_state - ok
14:24:16.0484 3184 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
14:24:16.0734 3184 AsyncMac - ok
14:24:16.0781 3184 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
14:24:17.0000 3184 atapi - ok
14:24:17.0000 3184 Atdisk - ok
14:24:17.0078 3184 [ 4DEAA162480367B232F3EE3A6D34084B ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe
14:24:17.0343 3184 Ati HotKey Poller - ok
14:24:17.0421 3184 [ F0D0B0CDEC0BE32D775F404CAC2604BF ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
14:24:17.0718 3184 ati2mtag - ok
14:24:17.0781 3184 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
14:24:17.0968 3184 Atmarpc - ok
14:24:18.0015 3184 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
14:24:18.0218 3184 AudioSrv - ok
14:24:18.0250 3184 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
14:24:18.0500 3184 audstub - ok
14:24:18.0546 3184 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
14:24:18.0781 3184 Beep - ok
14:24:18.0843 3184 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll
14:24:19.0093 3184 BITS - ok
14:24:19.0187 3184 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll
14:24:19.0375 3184 Browser - ok
14:24:19.0375 3184 bvrp_pci - ok
14:24:19.0484 3184 catchme - ok
14:24:19.0515 3184 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
14:24:19.0765 3184 cbidf - ok
14:24:19.0781 3184 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
14:24:19.0984 3184 cbidf2k - ok
14:24:20.0000 3184 [ F3EC03299634490E97BBCE94CD2954C7 ] cd20xrnt C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
14:24:20.0265 3184 cd20xrnt - ok
14:24:20.0296 3184 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
14:24:20.0515 3184 Cdaudio - ok
14:24:20.0625 3184 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
14:24:20.0875 3184 Cdfs - ok
14:24:20.0937 3184 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
14:24:21.0156 3184 Cdrom - ok
14:24:21.0218 3184 [ 25C323075C5EA4A2555E35355A01F793 ] cfwids C:\WINDOWS\system32\drivers\cfwids.sys
14:24:21.0375 3184 cfwids - ok
14:24:21.0390 3184 Changer - ok
14:24:21.0421 3184 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe
14:24:21.0640 3184 CiSvc - ok
14:24:21.0671 3184 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
14:24:21.0906 3184 ClipSrv - ok
14:24:21.0953 3184 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
14:24:22.0171 3184 clr_optimization_v2.0.50727_32 - ok
14:24:22.0203 3184 [ E5DCB56C533014ECBC556A8357C929D5 ] CmdIde C:\WINDOWS\system32\DRIVERS\cmdide.sys
14:24:22.0515 3184 CmdIde - ok
14:24:22.0515 3184 COMSysApp - ok
14:24:22.0609 3184 [ 3EE529119EED34CD212A215E8C40D4B6 ] Cpqarray C:\WINDOWS\system32\DRIVERS\cpqarray.sys
14:24:22.0828 3184 Cpqarray - ok
14:24:22.0921 3184 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
14:24:23.0109 3184 CryptSvc - ok
14:24:23.0125 3184 [ E550E7418984B65A78299D248F0A7F36 ] dac2w2k C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
14:24:23.0343 3184 dac2w2k - ok
14:24:23.0359 3184 [ 683789CAA3864EB46125AE86FF677D34 ] dac960nt C:\WINDOWS\system32\DRIVERS\dac960nt.sys
14:24:23.0718 3184 dac960nt - ok
14:24:23.0796 3184 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
14:24:23.0953 3184 DcomLaunch - ok
14:24:23.0984 3184 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
14:24:24.0187 3184 Dhcp - ok
14:24:24.0203 3184 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
14:24:24.0406 3184 Disk - ok
14:24:24.0406 3184 dmadmin - ok
14:24:24.0468 3184 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
14:24:24.0703 3184 dmboot - ok
14:24:24.0718 3184 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys
14:24:24.0968 3184 dmio - ok
14:24:24.0984 3184 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
14:24:25.0140 3184 dmload - ok
14:24:25.0187 3184 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll
14:24:25.0406 3184 dmserver - ok
14:24:25.0437 3184 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
14:24:25.0687 3184 DMusic - ok
14:24:25.0734 3184 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
14:24:25.0968 3184 Dnscache - ok
14:24:26.0000 3184 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
14:24:26.0281 3184 Dot3svc - ok
14:24:26.0281 3184 [ 40F3B93B4E5B0126F2F5C0A7A5E22660 ] dpti2o C:\WINDOWS\system32\DRIVERS\dpti2o.sys
14:24:26.0531 3184 dpti2o - ok
14:24:26.0562 3184 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
14:24:26.0843 3184 drmkaud - ok
14:24:26.0890 3184 [ B15F9E526BA511A48B1B1B8537815740 ] drvmcdb C:\WINDOWS\system32\drivers\drvmcdb.sys
14:24:27.0140 3184 drvmcdb ( UnsignedFile.Multi.Generic ) - warning
14:24:27.0140 3184 drvmcdb - detected UnsignedFile.Multi.Generic (1)
14:24:27.0171 3184 [ FA4670CAE95AE2BB857C68E535661145 ] drvnddm C:\WINDOWS\system32\drivers\drvnddm.sys
14:24:27.0312 3184 drvnddm ( UnsignedFile.Multi.Generic ) - warning
14:24:27.0312 3184 drvnddm - detected UnsignedFile.Multi.Generic (1)
14:24:27.0421 3184 [ FE80901578E7E3DA70299A5AEB2B7FBD ] DSBrokerService C:\Program Files\DellSupport\brkrsvc.exe
14:24:27.0578 3184 DSBrokerService - ok
14:24:27.0718 3184 [ 413F2D5F9D802688242C23B38F767ECB ] DSproct C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
14:24:27.0859 3184 DSproct ( UnsignedFile.Multi.Generic ) - warning
14:24:27.0859 3184 DSproct - detected UnsignedFile.Multi.Generic (1)
14:24:27.0906 3184 [ DFEABB7CFFFADEA4A912AB95BDC3177A ] dsunidrv C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
14:24:27.0984 3184 dsunidrv - ok
14:24:28.0000 3184 [ 7D91DC6342248369F94D6EBA0CF42E99 ] E100B C:\WINDOWS\system32\DRIVERS\e100b325.sys
14:24:28.0250 3184 E100B - ok
14:24:28.0312 3184 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll
14:24:28.0593 3184 EapHost - ok
14:24:28.0703 3184 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll
14:24:28.0984 3184 ERSvc - ok
14:24:29.0031 3184 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe
14:24:29.0125 3184 Eventlog - ok
14:24:29.0171 3184 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll
14:24:29.0375 3184 EventSystem - ok
14:24:29.0406 3184 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
14:24:29.0703 3184 Fastfat - ok
14:24:29.0750 3184 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
14:24:29.0937 3184 FastUserSwitchingCompatibility - ok
14:24:30.0015 3184 [ E97D6A8684466DF94FF3BC24FB787A07 ] Fax C:\WINDOWS\system32\fxssvc.exe
14:24:30.0328 3184 Fax - ok
14:24:30.0375 3184 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
14:24:30.0656 3184 Fdc - ok
14:24:30.0703 3184 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
14:24:30.0937 3184 Fips - ok
14:24:31.0000 3184 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
14:24:31.0218 3184 Flpydisk - ok
14:24:31.0250 3184 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
14:24:31.0468 3184 FltMgr - ok
14:24:31.0593 3184 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
14:24:31.0640 3184 FontCache3.0.0.0 - ok
14:24:31.0656 3184 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
14:24:31.0843 3184 Fs_Rec - ok
14:24:31.0875 3184 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
14:24:32.0078 3184 Ftdisk - ok
14:24:32.0171 3184 [ 0B53F4306E17025E7685D18C3A77127E ] GoToMyPC C:\Program Files\Citrix\GoToMyPC\g2svc.exe
14:24:32.0359 3184 GoToMyPC - ok
14:24:32.0390 3184 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
14:24:32.0750 3184 Gpc - ok
14:24:32.0828 3184 [ CC839E8D766CC31A7710C9F38CF3E375 ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
14:24:32.0968 3184 gusvc - ok
14:24:33.0062 3184 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
14:24:33.0218 3184 helpsvc - ok
14:24:33.0234 3184 HidServ - ok
14:24:33.0281 3184 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
14:24:33.0500 3184 hkmsvc - ok
14:24:33.0531 3184 [ B028377DEA0546A5FCFBA928A8AEFAE0 ] hpn C:\WINDOWS\system32\DRIVERS\hpn.sys
14:24:33.0781 3184 hpn - ok
14:24:33.0812 3184 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
14:24:33.0875 3184 HTTP - ok
14:24:33.0921 3184 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
14:24:34.0156 3184 HTTPFilter - ok
14:24:34.0296 3184 [ 9368670BD426EBEA5E8B18A62416EC28 ] i2omgmt C:\WINDOWS\system32\drivers\i2omgmt.sys
14:24:34.0468 3184 i2omgmt - ok
14:24:34.0484 3184 [ F10863BF1CCC290BABD1A09188AE49E0 ] i2omp C:\WINDOWS\system32\DRIVERS\i2omp.sys
14:24:34.0671 3184 i2omp - ok
14:24:34.0687 3184 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
14:24:34.0906 3184 i8042prt - ok
14:24:35.0015 3184 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
14:24:35.0328 3184 idsvc - ok
14:24:35.0375 3184 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
14:24:35.0718 3184 Imapi - ok
14:24:35.0750 3184 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe
14:24:36.0031 3184 ImapiService - ok
14:24:36.0062 3184 [ 4A40E045FAEE58631FD8D91AFC620719 ] ini910u C:\WINDOWS\system32\DRIVERS\ini910u.sys
14:24:36.0406 3184 ini910u - ok
14:24:36.0484 3184 [ 7509C548400F4C9E0211E3F6E66ABBE6 ] IntelC51 C:\WINDOWS\system32\DRIVERS\IntelC51.sys
14:24:36.0687 3184 IntelC51 - ok
14:24:36.0718 3184 [ 9584FFDD41D37F2C239681D0DAC2513E ] IntelC52 C:\WINDOWS\system32\DRIVERS\IntelC52.sys
14:24:36.0953 3184 IntelC52 - ok
14:24:36.0984 3184 [ CF0B937710CEC6EF39416EDECD803CBB ] IntelC53 C:\WINDOWS\system32\DRIVERS\IntelC53.sys
14:24:37.0125 3184 IntelC53 - ok
14:24:37.0140 3184 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys
14:24:37.0375 3184 IntelIde - ok
14:24:37.0406 3184 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
14:24:37.0593 3184 intelppm - ok
14:24:37.0640 3184 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys
14:24:37.0859 3184 Ip6Fw - ok
14:24:37.0890 3184 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
14:24:38.0031 3184 IpFilterDriver - ok
14:24:38.0062 3184 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
14:24:38.0359 3184 IpInIp - ok
14:24:38.0421 3184 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
14:24:38.0625 3184 IpNat - ok
14:24:38.0656 3184 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
14:24:38.0875 3184 IPSec - ok
14:24:38.0890 3184 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
14:24:39.0015 3184 IRENUM - ok
14:24:39.0046 3184 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
14:24:39.0281 3184 isapnp - ok
14:24:39.0421 3184 [ 999DB5F88C8E145CCA9D471E33227143 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
14:24:39.0562 3184 JavaQuickStarterService - ok
14:24:39.0609 3184 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
14:24:39.0890 3184 Kbdclass - ok
14:24:39.0937 3184 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
14:24:40.0109 3184 kmixer - ok
14:24:40.0156 3184 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
14:24:40.0218 3184 KSecDD - ok
14:24:40.0265 3184 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
14:24:40.0406 3184 lanmanserver - ok
14:24:40.0453 3184 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
14:24:40.0531 3184 lanmanworkstation - ok
14:24:40.0546 3184 lbrtfdc - ok
14:24:40.0609 3184 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
14:24:40.0796 3184 LmHosts - ok
14:24:40.0828 3184 [ 7C12F93C005021861A36C11DF951891A ] LxrSII1d C:\WINDOWS\system32\Drivers\LxrSII1d.sys
14:24:41.0156 3184 LxrSII1d ( UnsignedFile.Multi.Generic ) - warning
14:24:41.0156 3184 LxrSII1d - detected UnsignedFile.Multi.Generic (1)
14:24:41.0156 3184 LxrSII1s - ok
14:24:41.0265 3184 [ DDCC236009C707761D60E5C76D639176 ] McComponentHostService C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe
14:24:41.0406 3184 McComponentHostService - ok
14:24:41.0531 3184 [ ECAB006AC6136F1307E140B633CDB8C2 ] mcmscsvc C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
14:24:41.0671 3184 mcmscsvc - ok
14:24:41.0703 3184 [ ECAB006AC6136F1307E140B633CDB8C2 ] McNaiAnn C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
14:24:41.0718 3184 McNaiAnn - ok
14:24:41.0734 3184 [ ECAB006AC6136F1307E140B633CDB8C2 ] McNASvc C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
14:24:41.0750 3184 McNASvc - ok
14:24:41.0828 3184 [ C7DA06C9A9AEEFBE37AAC281EA6385D5 ] McODS C:\Program Files\McAfee\VirusScan\mcods.exe
14:24:41.0968 3184 McODS - ok
14:24:41.0968 3184 [ ECAB006AC6136F1307E140B633CDB8C2 ] McProxy C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
14:24:42.0000 3184 McProxy - ok
14:24:42.0078 3184 [ 6FE0532CB16300C09D098F808EAAEE9D ] McShield C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
14:24:42.0218 3184 McShield - ok
14:24:42.0281 3184 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
14:24:42.0343 3184 MDM - ok
14:24:42.0390 3184 [ 0377F70E41FEFA850B96A8FB157C5681 ] MemeoBackgroundService C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe
14:24:42.0515 3184 MemeoBackgroundService - ok
14:24:42.0546 3184 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll
14:24:42.0765 3184 Messenger - ok
14:24:42.0812 3184 [ 6708AD7D9ABDD6FDE1EB9B54FFE426B0 ] mfeapfk C:\WINDOWS\system32\drivers\mfeapfk.sys
14:24:42.0984 3184 mfeapfk - ok
14:24:43.0031 3184 [ 375DE90B68533D9D0D7766D4CCB4CA32 ] mfeavfk C:\WINDOWS\system32\drivers\mfeavfk.sys
14:24:43.0265 3184 mfeavfk - ok
14:24:43.0281 3184 mfeavfk01 - ok
14:24:43.0312 3184 [ 5ED806D4DF27AC11236BD9AD2CC10B7E ] mfebopk C:\WINDOWS\system32\drivers\mfebopk.sys
14:24:43.0468 3184 mfebopk - ok
14:24:43.0515 3184 [ 1A427BB508ACBEE09A88F08D1CA38E2F ] mfefire C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
14:24:43.0656 3184 mfefire - ok
14:24:43.0687 3184 [ 16BF9475BFCFAA420A8CB29E40284457 ] mfefirek C:\WINDOWS\system32\drivers\mfefirek.sys
14:24:43.0890 3184 mfefirek - ok
14:24:43.0953 3184 [ 875452ECDF4AEBE12B8C2EFD8599A36F ] mfehidk C:\WINDOWS\system32\drivers\mfehidk.sys
14:24:44.0390 3184 mfehidk - ok
14:24:44.0421 3184 [ 3004E3FE086E76D7D6DFB9A851ED6F10 ] mfendisk C:\WINDOWS\system32\DRIVERS\mfendisk.sys
14:24:44.0625 3184 mfendisk - ok
14:24:44.0671 3184 [ 3004E3FE086E76D7D6DFB9A851ED6F10 ] mfendiskmp C:\WINDOWS\system32\DRIVERS\mfendisk.sys
14:24:44.0718 3184 mfendiskmp - ok
14:24:44.0765 3184 [ D669ACBE7672819109706C3CFF6BD1DB ] mferkdet C:\WINDOWS\system32\drivers\mferkdet.sys
14:24:45.0156 3184 mferkdet - ok
14:24:45.0203 3184 [ 1328C929A2F801BB93DBDFCDC25E0E7A ] mfetdi2k C:\WINDOWS\system32\drivers\mfetdi2k.sys
14:24:45.0406 3184 mfetdi2k - ok
14:24:45.0500 3184 [ D66A1A16166897A5F7D04961F582F03B ] mfevtp C:\WINDOWS\system32\mfevtps.exe
14:24:45.0687 3184 mfevtp - ok
14:24:45.0750 3184 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
14:24:46.0125 3184 mnmdd - ok
14:24:46.0296 3184 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
14:24:46.0578 3184 mnmsrvc - ok
14:24:46.0609 3184 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
14:24:46.0828 3184 Modem - ok
14:24:46.0859 3184 [ 1992E0D143B09653AB0F9C5E04B0FD65 ] MODEMCSA C:\WINDOWS\system32\drivers\MODEMCSA.sys
14:24:47.0234 3184 MODEMCSA - ok
14:24:47.0234 3184 [ 59B8B11FF70728EEC60E72131C58B716 ] mohfilt C:\WINDOWS\system32\DRIVERS\mohfilt.sys
14:24:47.0375 3184 mohfilt - ok
14:24:47.0406 3184 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
14:24:47.0546 3184 Mouclass - ok
14:24:47.0562 3184 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
14:24:47.0781 3184 MountMgr - ok
14:24:47.0843 3184 [ 8A7C8F4C713E70D73946833D76B77035 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
14:24:47.0984 3184 MozillaMaintenance - ok
14:24:47.0984 3184 [ 3F4BB95E5A44F3BE34824E8E7CAF0737 ] mraid35x C:\WINDOWS\system32\DRIVERS\mraid35x.sys
14:24:48.0234 3184 mraid35x - ok
14:24:48.0265 3184 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
14:24:48.0484 3184 MRxDAV - ok
14:24:48.0546 3184 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
14:24:48.0812 3184 MRxSmb - ok
14:24:48.0843 3184 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe
14:24:49.0000 3184 MSDTC - ok
14:24:49.0015 3184 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
14:24:49.0156 3184 Msfs - ok
14:24:49.0156 3184 MSIServer - ok
14:24:49.0203 3184 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
14:24:49.0359 3184 MSKSSRV - ok
14:24:49.0390 3184 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
14:24:49.0546 3184 MSPCLOCK - ok
14:24:49.0578 3184 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
14:24:49.0718 3184 MSPQM - ok
14:24:49.0750 3184 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
14:24:49.0890 3184 mssmbios - ok
14:24:49.0906 3184 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
14:24:50.0031 3184 Mup - ok
14:24:50.0062 3184 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll
14:24:50.0203 3184 napagent - ok
14:24:50.0234 3184 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
14:24:50.0546 3184 NDIS - ok
14:24:50.0578 3184 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
14:24:50.0718 3184 NdisTapi - ok
14:24:50.0734 3184 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
14:24:50.0890 3184 Ndisuio - ok
14:24:50.0937 3184 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
14:24:51.0156 3184 NdisWan - ok
14:24:51.0187 3184 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
14:24:51.0390 3184 NDProxy - ok
14:24:51.0421 3184 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
14:24:51.0640 3184 NetBIOS - ok
14:24:51.0687 3184 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
14:24:51.0906 3184 NetBT - ok
14:24:51.0953 3184 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
14:24:52.0078 3184 NetDDE - ok
14:24:52.0093 3184 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
14:24:52.0218 3184 NetDDEdsdm - ok
14:24:52.0265 3184 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
14:24:52.0484 3184 Netlogon - ok
14:24:52.0531 3184 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
14:24:52.0875 3184 Netman - ok
14:24:53.0015 3184 [ 02D0798F376FCBD0210EDA58476D0B1B ] NetSvc C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
14:24:53.0187 3184 NetSvc ( UnsignedFile.Multi.Generic ) - warning
14:24:53.0187 3184 NetSvc - detected UnsignedFile.Multi.Generic (1)
14:24:53.0296 3184 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
14:24:53.0359 3184 NetTcpPortSharing - ok
14:24:53.0390 3184 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
14:24:53.0562 3184 Nla - ok
14:24:53.0593 3184 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
14:24:53.0812 3184 Npfs - ok
14:24:53.0875 3184 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
14:24:54.0093 3184 Ntfs - ok
14:24:54.0109 3184 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
14:24:54.0312 3184 NtLmSsp - ok
14:24:54.0359 3184 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
14:24:54.0640 3184 NtmsSvc - ok
14:24:54.0687 3184 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
14:24:54.0953 3184 Null - ok
14:24:55.0218 3184 [ 2B298519EDBFCF451D43E0F1E8F1006D ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
14:24:55.0593 3184 nv - ok
14:24:55.0625 3184 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
14:24:55.0828 3184 NwlnkFlt - ok
14:24:55.0875 3184 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
14:24:56.0078 3184 NwlnkFwd - ok
14:24:56.0171 3184 [ 2DDCC672E3A9F615CACE2AB6B9601056 ] O&O Defrag C:\WINDOWS\system32\oodag.exe
14:24:58.0187 3184 O&O Defrag ( UnsignedFile.Multi.Generic ) - warning
14:24:58.0187 3184 O&O Defrag - detected UnsignedFile.Multi.Generic (1)
14:24:58.0281 3184 [ 53D5F1278D9EDB21689BBBCECC09108D ] omci C:\WINDOWS\system32\DRIVERS\omci.sys
14:24:58.0406 3184 omci ( UnsignedFile.Multi.Generic ) - warning
14:24:58.0406 3184 omci - detected UnsignedFile.Multi.Generic (1)
14:24:58.0515 3184 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
14:24:58.0562 3184 ose - ok
14:24:58.0609 3184 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
14:24:58.0843 3184 Parport - ok
14:24:58.0859 3184 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
14:24:59.0359 3184 PartMgr - ok
14:24:59.0406 3184 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
14:24:59.0796 3184 ParVdm - ok
14:24:59.0843 3184 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
14:25:00.0171 3184 PCI - ok
14:25:00.0171 3184 PCIDump - ok
14:25:00.0218 3184 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
14:25:00.0406 3184 PCIIde - ok
14:25:00.0453 3184 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
14:25:00.0734 3184 Pcmcia - ok
14:25:00.0750 3184 PDCOMP - ok
14:25:00.0765 3184 PDFRAME - ok
14:25:00.0781 3184 PDRELI - ok
14:25:00.0812 3184 PDRFRAME - ok
14:25:00.0890 3184 [ 6C14B9C19BA84F73D3A86DBA11133101 ] perc2 C:\WINDOWS\system32\DRIVERS\perc2.sys
14:25:01.0312 3184 perc2 - ok
14:25:01.0343 3184 [ F50F7C27F131AFE7BEBA13E14A3B9416 ] perc2hib C:\WINDOWS\system32\DRIVERS\perc2hib.sys
14:25:01.0640 3184 perc2hib - ok
14:25:01.0671 3184 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
14:25:01.0718 3184 PlugPlay - ok
14:25:01.0734 3184 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
14:25:01.0953 3184 PolicyAgent - ok
14:25:02.0000 3184 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
14:25:02.0234 3184 PptpMiniport - ok
14:25:02.0234 3184 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
14:25:02.0375 3184 ProtectedStorage - ok
14:25:02.0390 3184 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
14:25:02.0515 3184 PSched - ok
14:25:02.0562 3184 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
14:25:02.0703 3184 Ptilink - ok
14:25:02.0734 3184 [ DB3B30C3A4CDCF07E164C14584D9D0F2 ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys
14:25:02.0859 3184 PxHelp20 ( UnsignedFile.Multi.Generic ) - warning
14:25:02.0859 3184 PxHelp20 - detected UnsignedFile.Multi.Generic (1)
14:25:02.0875 3184 [ 0A63FB54039EB5662433CABA3B26DBA7 ] ql1080 C:\WINDOWS\system32\DRIVERS\ql1080.sys
14:25:03.0031 3184 ql1080 - ok
14:25:03.0078 3184 [ 6503449E1D43A0FF0201AD5CB1B8C706 ] Ql10wnt C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
14:25:03.0250 3184 Ql10wnt - ok
14:25:03.0281 3184 [ 156ED0EF20C15114CA097A34A30D8A01 ] ql12160 C:\WINDOWS\system32\DRIVERS\ql12160.sys
14:25:03.0421 3184 ql12160 - ok
14:25:03.0421 3184 [ 70F016BEBDE6D29E864C1230A07CC5E6 ] ql1240 C:\WINDOWS\system32\DRIVERS\ql1240.sys
14:25:03.0578 3184 ql1240 - ok
14:25:03.0578 3184 [ 907F0AEEA6BC451011611E732BD31FCF ] ql1280 C:\WINDOWS\system32\DRIVERS\ql1280.sys
14:25:03.0718 3184 ql1280 - ok
14:25:03.0765 3184 [ 7F599E8BCC5EBC78FA711E9E55EEA40C ] RapidPortM1 C:\WINDOWS\system32\Drivers\CAPM1LP.SYS
14:25:03.0890 3184 RapidPortM1 - ok
14:25:03.0906 3184 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
14:25:04.0140 3184 RasAcd - ok
14:25:04.0187 3184 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
14:25:04.0437 3184 RasAuto - ok
14:25:04.0453 3184 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
14:25:04.0703 3184 Rasl2tp - ok
14:25:04.0734 3184 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
14:25:04.0906 3184 RasMan - ok
14:25:04.0937 3184 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
14:25:05.0218 3184 RasPppoe - ok
14:25:05.0234 3184 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
14:25:05.0578 3184 Raspti - ok
14:25:05.0609 3184 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
14:25:05.0781 3184 Rdbss - ok
14:25:05.0812 3184 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
14:25:05.0953 3184 RDPCDD - ok
14:25:05.0968 3184 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
14:25:06.0109 3184 rdpdr - ok
14:25:06.0296 3184 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
14:25:06.0609 3184 RDPWD - ok
14:25:06.0640 3184 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
14:25:06.0875 3184 RDSessMgr - ok
14:25:06.0953 3184 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
14:25:07.0468 3184 redbook - ok
14:25:07.0546 3184 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
14:25:07.0843 3184 RemoteAccess - ok
14:25:07.0906 3184 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
14:25:08.0234 3184 RemoteRegistry - ok
14:25:08.0281 3184 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe
14:25:08.0546 3184 RpcLocator - ok
14:25:08.0593 3184 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll
14:25:08.0750 3184 RpcSs - ok
14:25:08.0812 3184 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe
14:25:09.0062 3184 RSVP - ok
14:25:09.0109 3184 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
14:25:09.0343 3184 SamSs - ok
14:25:09.0359 3184 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
14:25:09.0734 3184 SCardSvr - ok
14:25:09.0781 3184 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
14:25:10.0015 3184 Schedule - ok
14:25:10.0312 3184 [ A1A26E8EC51E199D873D85F3E2B6FC65 ] SeagateDashboardService C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
14:25:10.0468 3184 SeagateDashboardService ( UnsignedFile.Multi.Generic ) - warning
14:25:10.0468 3184 SeagateDashboardService - detected UnsignedFile.Multi.Generic (1)
14:25:10.0515 3184 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
14:25:10.0656 3184 Secdrv - ok
14:25:10.0687 3184 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
14:25:10.0906 3184 seclogon - ok
14:25:10.0937 3184 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll
14:25:11.0109 3184 SENS - ok
14:25:11.0187 3184 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
14:25:11.0390 3184 serenum - ok
14:25:11.0421 3184 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
14:25:11.0562 3184 Serial - ok
14:25:11.0609 3184 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
14:25:11.0843 3184 Sfloppy - ok
14:25:11.0890 3184 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
14:25:12.0125 3184 SharedAccess - ok
14:25:12.0156 3184 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
14:25:12.0187 3184 ShellHWDetection - ok
14:25:12.0203 3184 Simbad - ok
14:25:12.0250 3184 [ 6B33D0EBD30DB32E27D1D78FE946A754 ] sisagp C:\WINDOWS\system32\DRIVERS\sisagp.sys
14:25:12.0484 3184 sisagp - ok
14:25:12.0546 3184 [ 4AA922332433CDEB8B82C072C212E32E ] smwdm C:\WINDOWS\system32\drivers\smwdm.sys
14:25:12.0781 3184 smwdm - ok
14:25:12.0796 3184 [ 83C0F71F86D3BDAF915685F3D568B20E ] Sparrow C:\WINDOWS\system32\DRIVERS\sparrow.sys
14:25:13.0093 3184 Sparrow - ok
14:25:13.0203 3184 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
14:25:13.0406 3184 splitter - ok
14:25:13.0437 3184 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
14:25:13.0687 3184 Spooler - ok
14:25:13.0703 3184 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
14:25:13.0781 3184 sr - ok
14:25:13.0812 3184 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
14:25:14.0000 3184 srservice - ok
14:25:14.0218 3184 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
14:25:14.0406 3184 Srv - ok
14:25:14.0453 3184 [ D7968049BE0ADBB6A57CEE3960320911 ] sscdbhk5 C:\WINDOWS\system32\drivers\sscdbhk5.sys
14:25:14.0578 3184 sscdbhk5 ( UnsignedFile.Multi.Generic ) - warning
14:25:14.0578 3184 sscdbhk5 - detected UnsignedFile.Multi.Generic (1)
14:25:14.0625 3184 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
14:25:14.0812 3184 SSDPSRV - ok
14:25:14.0843 3184 [ C3FFD65ABFB6441E7606CF74F1155273 ] ssrtln C:\WINDOWS\system32\drivers\ssrtln.sys
14:25:15.0078 3184 ssrtln ( UnsignedFile.Multi.Generic ) - warning
14:25:15.0078 3184 ssrtln - detected UnsignedFile.Multi.Generic (1)
14:25:15.0265 3184 [ A9573045BAA16EAB9B1085205B82F1ED ] StillCam C:\WINDOWS\system32\DRIVERS\serscan.sys
14:25:15.0515 3184 StillCam - ok
14:25:15.0640 3184 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
14:25:15.0828 3184 stisvc - ok
14:25:15.0859 3184 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
14:25:16.0078 3184 swenum - ok
14:25:16.0140 3184 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
14:25:16.0328 3184 swmidi - ok
14:25:16.0343 3184 SwPrv - ok
14:25:16.0390 3184 [ 1FF3217614018630D0A6758630FC698C ] symc810 C:\WINDOWS\system32\DRIVERS\symc810.sys
14:25:16.0687 3184 symc810 - ok
14:25:16.0734 3184 [ 070E001D95CF725186EF8B20335F933C ] symc8xx C:\WINDOWS\system32\DRIVERS\symc8xx.sys
14:25:17.0000 3184 symc8xx - ok
14:25:17.0015 3184 [ 80AC1C4ABBE2DF3B738BF15517A51F2C ] sym_hi C:\WINDOWS\system32\DRIVERS\sym_hi.sys
14:25:17.0250 3184 sym_hi - ok
14:25:17.0265 3184 [ BF4FAB949A382A8E105F46EBB4937058 ] sym_u3 C:\WINDOWS\system32\DRIVERS\sym_u3.sys
14:25:17.0578 3184 sym_u3 - ok
14:25:17.0625 3184 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
14:25:17.0765 3184 sysaudio - ok
14:25:17.0796 3184 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
14:25:18.0000 3184 SysmonLog - ok
14:25:18.0046 3184 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
14:25:18.0218 3184 TapiSrv - ok
14:25:18.0281 3184 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
14:25:18.0343 3184 Tcpip - ok
14:25:18.0375 3184 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
14:25:18.0562 3184 TDPIPE - ok
14:25:18.0625 3184 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
14:25:18.0765 3184 TDTCP - ok
14:25:18.0812 3184 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
14:25:19.0015 3184 TermDD - ok
14:25:19.0062 3184 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
14:25:19.0296 3184 TermService - ok
14:25:19.0359 3184 [ 1D265CD2FB1673A0873BF8CEC19DDC7F ] tfsnboio C:\WINDOWS\system32\dla\tfsnboio.sys
14:25:19.0562 3184 tfsnboio ( UnsignedFile.Multi.Generic ) - warning
14:25:19.0562 3184 tfsnboio - detected UnsignedFile.Multi.Generic (1)
14:25:19.0593 3184 [ 62E4901295E0467CAC78E5B4B131AE5C ] tfsncofs C:\WINDOWS\system32\dla\tfsncofs.sys
14:25:19.0750 3184 tfsncofs ( UnsignedFile.Multi.Generic ) - warning
14:25:19.0750 3184 tfsncofs - detected UnsignedFile.Multi.Generic (1)
14:25:19.0828 3184 [ A2F380F9252AB3464C859ADF91EEAD9C ] tfsndrct C:\WINDOWS\system32\dla\tfsndrct.sys
14:25:20.0062 3184 tfsndrct ( UnsignedFile.Multi.Generic ) - warning
14:25:20.0109 3184 tfsndrct - detected UnsignedFile.Multi.Generic (1)
14:25:20.0171 3184 [ EEE79BBEFE9C6A2A3CE6C8753CFEA950 ] tfsndres C:\WINDOWS\system32\dla\tfsndres.sys
14:25:20.0296 3184 tfsndres ( UnsignedFile.Multi.Generic ) - warning
14:25:20.0296 3184 tfsndres - detected UnsignedFile.Multi.Generic (1)
14:25:20.0328 3184 [ 9D644EB11FEC9487450C4CFCD63A5DF4 ] tfsnifs C:\WINDOWS\system32\dla\tfsnifs.sys
14:25:20.0531 3184 tfsnifs ( UnsignedFile.Multi.Generic ) - warning
14:25:20.0531 3184 tfsnifs - detected UnsignedFile.Multi.Generic (1)
14:25:20.0562 3184 [ E656AF05C67EDB7C0E9230A5DF71ED1B ] tfsnopio C:\WINDOWS\system32\dla\tfsnopio.sys
14:25:20.0718 3184 tfsnopio ( UnsignedFile.Multi.Generic ) - warning
14:25:20.0718 3184 tfsnopio - detected UnsignedFile.Multi.Generic (1)
14:25:20.0734 3184 [ 64FCCB9CCE703CA507DFFC3CEBF6B2CB ] tfsnpool C:\WINDOWS\system32\dla\tfsnpool.sys
14:25:20.0921 3184 tfsnpool ( UnsignedFile.Multi.Generic ) - warning
14:25:20.0921 3184 tfsnpool - detected UnsignedFile.Multi.Generic (1)
14:25:20.0937 3184 [ 48BC9D8AB4E4B9BFF70FB18E55CEC3D6 ] tfsnudf C:\WINDOWS\system32\dla\tfsnudf.sys
14:25:21.0156 3184 tfsnudf ( UnsignedFile.Multi.Generic ) - warning
14:25:21.0156 3184 tfsnudf - detected UnsignedFile.Multi.Generic (1)
14:25:21.0187 3184 [ 79F60822224256B49BFC855DA8D651D5 ] tfsnudfa C:\WINDOWS\system32\dla\tfsnudfa.sys
14:25:21.0343 3184 tfsnudfa ( UnsignedFile.Multi.Generic ) - warning
14:25:21.0343 3184 tfsnudfa - detected UnsignedFile.Multi.Generic (1)
14:25:21.0375 3184 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
14:25:21.0406 3184 Themes - ok
14:25:21.0437 3184 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
14:25:21.0703 3184 TlntSvr - ok
14:25:21.0734 3184 [ F2790F6AF01321B172AA62F8E1E187D9 ] TosIde C:\WINDOWS\system32\DRIVERS\toside.sys
14:25:21.0937 3184 TosIde - ok
14:25:21.0984 3184 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
14:25:22.0203 3184 TrkWks - ok
14:25:22.0250 3184 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
14:25:22.0453 3184 Udfs - ok
14:25:22.0484 3184 [ 1B698A51CD528D8DA4FFAED66DFC51B9 ] ultra C:\WINDOWS\system32\DRIVERS\ultra.sys
14:25:22.0781 3184 ultra - ok
14:25:22.0812 3184 [ AB0A7CA90D9E3D6A193905DC1715DED0 ] UMWdf C:\WINDOWS\system32\wdfmgr.exe
14:25:23.0062 3184 UMWdf - ok
14:25:23.0140 3184 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
14:25:23.0312 3184 Update - ok
14:25:23.0406 3184 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
14:25:23.0515 3184 upnphost - ok
14:25:23.0609 3184 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
14:25:23.0843 3184 UPS - ok
14:25:23.0875 3184 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
14:25:24.0078 3184 usbehci - ok
14:25:24.0218 3184 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
14:25:24.0421 3184 usbhub - ok
14:25:24.0484 3184 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:25:24.0625 3184 USBSTOR - ok
14:25:24.0671 3184 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
14:25:24.0812 3184 usbuhci - ok
14:25:24.0859 3184 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
14:25:25.0000 3184 VgaSave - ok
14:25:25.0046 3184 [ 754292CE5848B3738281B4F3607EAEF4 ] viaagp C:\WINDOWS\system32\DRIVERS\viaagp.sys
14:25:25.0187 3184 viaagp - ok
14:25:25.0203 3184 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys
14:25:25.0343 3184 ViaIde - ok
14:25:25.0375 3184 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
14:25:25.0531 3184 VolSnap - ok
14:25:25.0562 3184 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
14:25:25.0656 3184 VSS - ok
14:25:25.0687 3184 [ 54AF4B1D5459500EF0937F6D33B1914F ] w32time C:\WINDOWS\system32\w32time.dll
14:25:25.0843 3184 w32time - ok
14:25:25.0875 3184 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
14:25:26.0031 3184 Wanarp - ok
14:25:26.0031 3184 wanatw - ok
14:25:26.0046 3184 WDICA - ok
14:25:26.0093 3184 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
14:25:26.0218 3184 wdmaud - ok
14:25:26.0265 3184 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
14:25:26.0421 3184 WebClient - ok
14:25:26.0500 3184 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
14:25:26.0734 3184 winmgmt - ok
14:25:26.0781 3184 [ 140EF97B64F560FD78643CAE2CDAD838 ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
14:25:26.0906 3184 WmdmPmSN - ok
14:25:26.0953 3184 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll
14:25:27.0187 3184 Wmi - ok
14:25:27.0234 3184 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
14:25:27.0421 3184 WmiApSrv - ok
14:25:27.0453 3184 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
14:25:27.0671 3184 WS2IFSL - ok
14:25:27.0703 3184 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
14:25:27.0921 3184 wscsvc - ok
14:25:27.0953 3184 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll
14:25:28.0234 3184 wuauserv - ok
14:25:28.0296 3184 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
14:25:28.0515 3184 WZCSVC - ok
14:25:28.0578 3184 [ DDD8286B88FE764AD2A8BD171E7B569A ] xmasbus C:\WINDOWS\system32\DRIVERS\xmasbus.sys
14:25:28.0703 3184 xmasbus ( UnsignedFile.Multi.Generic ) - warning
14:25:28.0703 3184 xmasbus - detected UnsignedFile.Multi.Generic (1)
14:25:28.0750 3184 [ 2222677F06FB7FBE44B04316437585D2 ] xmasscsi C:\WINDOWS\system32\Drivers\xmasscsi.sys
14:25:28.0890 3184 xmasscsi ( UnsignedFile.Multi.Generic ) - warning
14:25:28.0890 3184 xmasscsi - detected UnsignedFile.Multi.Generic (1)
14:25:28.0921 3184 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
14:25:29.0156 3184 xmlprov - ok
14:25:29.0171 3184 ================ Scan global ===============================
14:25:29.0203 3184 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
14:25:29.0343 3184 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
14:25:29.0453 3184 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
14:25:29.0484 3184 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
14:25:29.0484 3184 [Global] - ok
14:25:29.0484 3184 ================ Scan MBR ==================================
14:25:29.0500 3184 [ B16A2359F4962B0C622D81A1C1F4B703 ] \Device\Harddisk0\DR0
14:25:29.0765 3184 \Device\Harddisk0\DR0 - ok
14:25:29.0765 3184 ================ Scan VBR ==================================
14:25:29.0765 3184 [ F91B2ABF342CCA128AD36D2858A29125 ] \Device\Harddisk0\DR0\Partition1
14:25:29.0765 3184 \Device\Harddisk0\DR0\Partition1 - ok
14:25:29.0765 3184 ============================================================
14:25:29.0765 3184 Scan finished
14:25:29.0765 3184 ============================================================
14:25:29.0781 0620 Detected object count: 22
14:25:29.0781 0620 Actual detected object count: 22
14:25:50.0687 0620 drvmcdb ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0687 0620 drvmcdb ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0687 0620 drvnddm ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0687 0620 drvnddm ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0687 0620 DSproct ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0687 0620 DSproct ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0687 0620 LxrSII1d ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0687 0620 LxrSII1d ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0687 0620 NetSvc ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0687 0620 NetSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0687 0620 O&O Defrag ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0687 0620 O&O Defrag ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0687 0620 omci ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0687 0620 omci ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0687 0620 PxHelp20 ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0687 0620 PxHelp20 ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0687 0620 SeagateDashboardService ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0687 0620 SeagateDashboardService ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0687 0620 sscdbhk5 ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0687 0620 sscdbhk5 ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0687 0620 ssrtln ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0687 0620 ssrtln ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0687 0620 tfsnboio ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0687 0620 tfsnboio ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0687 0620 tfsncofs ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0687 0620 tfsncofs ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0687 0620 tfsndrct ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0687 0620 tfsndrct ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0687 0620 tfsndres ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0687 0620 tfsndres ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0703 0620 tfsnifs ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0703 0620 tfsnifs ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0703 0620 tfsnopio ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0703 0620 tfsnopio ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0703 0620 tfsnpool ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0703 0620 tfsnpool ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0703 0620 tfsnudf ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0703 0620 tfsnudf ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0703 0620 tfsnudfa ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0703 0620 tfsnudfa ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0703 0620 xmasbus ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0703 0620 xmasbus ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:25:50.0703 0620 xmasscsi ( UnsignedFile.Multi.Generic ) - skipped by user
14:25:50.0703 0620 xmasscsi ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:26:01.0687 2100 Deinitialize success


_________________________________


ComboFix 13-03-28.01 - Amy 03/29/2013 14:42:00.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2928 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
* Resident AV is active
.
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Amy\Local Settings\Application Data\{0C619940-D883-4492-9EC5-EAFB3EBF9421}
c:\documents and settings\Amy\Local Settings\Application Data\{0C619940-D883-4492-9EC5-EAFB3EBF9421}\chrome.manifest
c:\documents and settings\Amy\Local Settings\Application Data\{0C619940-D883-4492-9EC5-EAFB3EBF9421}\chrome\content\overlay.xul
c:\documents and settings\Amy\Local Settings\Application Data\{0C619940-D883-4492-9EC5-EAFB3EBF9421}\install.rdf
c:\documents and settings\Amy\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
.
.
((((((((((((((((((((((((( Files Created from 2013-02-28 to 2013-03-29 )))))))))))))))))))))))))))))))
.
.
2013-03-29 18:18 . 2013-03-29 18:18 ——– d—–w- c:\documents and settings\Amy\Local Settings\Application Data\Sun
2013-03-29 18:15 . 2013-03-29 18:15 ——– d—–w- c:\documents and settings\Amy\Local Settings\Application Data\PCHealth
2013-03-29 17:29 . 2013-03-29 17:28 143872 —-a-w- c:\windows\system32\javacpl.cpl
2013-03-29 17:29 . 2013-03-29 17:28 861088 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-03-29 17:29 . 2013-03-29 17:28 94112 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-03-29 17:28 . 2013-03-29 17:28 ——– d—–w- c:\program files\Java
2013-03-29 16:43 . 2013-03-29 18:23 ——– d—–w- C:\TDSSKiller_Quarantine
2013-03-28 18:03 . 2008-04-13 18:31 36352 —-a-w- c:\windows\system32\drivers\intelppm.sys
2013-03-28 18:03 . 2008-04-13 18:31 36352 —-a-w- c:\windows\system32\dllcache\intelppm.sys
2013-03-27 20:02 . 2013-03-27 20:02 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2013-03-27 20:00 . 2013-03-27 20:00 ——– d—–w- c:\program files\Mozilla Maintenance Service
2013-03-18 16:37 . 2013-03-18 18:09 ——– d—–w- C:\jgh
2013-03-14 14:50 . 2013-03-14 14:50 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\BVRP Software
2013-03-13 20:26 . 2013-03-13 20:26 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2013-03-13 20:12 . 2013-03-13 20:12 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-29 17:28 . 2010-09-22 13:36 782240 —-a-w- c:\windows\system32\deployJava1.dll
2013-03-29 17:18 . 2012-06-01 11:51 693976 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-29 17:18 . 2012-02-13 15:40 73432 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-19 19:15 . 2012-04-10 17:30 60920 —-a-w- c:\windows\system32\drivers\cfwids.sys
2013-02-19 19:12 . 2012-04-10 17:20 172416 —-a-w- c:\windows\system32\mfevtps.exe
2013-02-19 19:11 . 2012-04-10 17:30 91640 —-a-w- c:\windows\system32\drivers\mfetdi2k.sys
2013-02-19 19:11 . 2012-04-10 17:30 10088 —-a-w- c:\windows\system32\drivers\mfeclnk.sys
2013-02-19 19:10 . 2012-04-10 17:30 92632 —-a-w- c:\windows\system32\drivers\mferkdet.sys
2013-02-19 19:09 . 2011-10-15 16:16 565888 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2013-02-19 19:09 . 2012-12-17 15:09 84904 —-a-w- c:\windows\system32\drivers\mfendisk.sys
2013-02-19 19:09 . 2012-04-10 17:30 363080 —-a-w- c:\windows\system32\drivers\mfefirek.sys
2013-02-19 19:08 . 2012-04-10 17:30 65928 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2013-02-19 19:08 . 2012-04-10 17:30 235264 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2013-02-19 19:07 . 2011-10-15 16:16 133416 —-a-w- c:\windows\system32\drivers\mfeapfk.sys
2013-02-12 00:32 . 2008-09-03 23:47 12928 ——w- c:\windows\system32\drivers\usb8023x.sys
2013-02-12 00:32 . 2004-08-04 11:00 12928 —-a-w- c:\windows\system32\drivers\usb8023.sys
2013-02-05 20:05 . 2004-08-04 11:00 916480 —-a-w- c:\windows\system32\wininet.dll
2013-02-05 20:05 . 2004-08-04 11:00 43520 ——w- c:\windows\system32\licmgr10.dll
2013-02-05 20:05 . 2004-08-04 11:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2013-02-05 05:53 . 2004-08-04 11:00 385024 ——w- c:\windows\system32\html.iec
2013-01-26 03:55 . 2004-08-04 11:00 552448 —-a-w- c:\windows\system32\oleaut32.dll
2013-01-07 01:19 . 1980-01-01 06:00 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-01-07 00:37 . 1980-01-01 06:00 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-04 01:20 . 2004-08-04 11:00 1867264 —-a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49 . 2004-08-04 11:00 148992 —-a-w- c:\windows\system32\mpg2splt.ax
2013-01-02 06:49 . 2004-08-04 11:00 1292288 —-a-w- c:\windows\system32\quartz.dll
2013-03-07 14:31 . 2013-03-27 20:00 263064 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-04-21 39408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-01-05 98304]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2007-10-30 77824]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-10-10 185784]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-10-11 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-10-11 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2009-02-10 745472]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-10-30 77824]
"Memeo Instant Backup"="c:\program files\Memeo\AutoBackup\MemeoLauncher2.exe" [2010-12-11 136416]
"Seagate Dashboard"="c:\program files\Seagate\Seagate Dashboard\MemeoLauncher.exe" [2011-11-03 73728]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-04 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2013-01-14 1278064]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\documents and settings\Amy\Start Menu\Programs\Startup\
TrayDay.lnk - c:\program files\TrayDay\TrayDay.exe [2005-1-28 204800]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2011-4-8 542264]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-1-20 724992]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToMyPC]
2011-11-13 12:53 15216 —-a-w- c:\program files\Citrix\GoToMyPC\G2WinLogon.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Seagate\\Seagate Dashboard\\HipServAgent\\HipServAgent.exe"=
.
R0 xmasbus;xmasbus;c:\windows\SYSTEM32\DRIVERS\xmasbus.sys [2/4/2005 2:11 PM 140800]
R0 xmasscsi;xmasscsi;c:\windows\SYSTEM32\DRIVERS\xmasscsi.sys [2/4/2005 2:11 PM 5504]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\SYSTEM32\DRIVERS\mfetdi2k.sys [4/10/2012 1:30 PM 91640]
R2 LxrSII1d;Secure II Driver;c:\windows\SYSTEM32\DRIVERS\LxrSII1d.sys [5/13/2008 2:31 PM 72672]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [4/10/2012 1:30 PM 167784]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\Memeo\AutoBackup\MemeoBackgroundService.exe [12/10/2010 9:49 PM 25824]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\Mcafee\SystemCore\mfefire.exe [4/10/2012 1:31 PM 169320]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\SYSTEM32\mfevtps.exe [4/10/2012 1:20 PM 172416]
R2 RapidPortM1;RapidPortM1;c:\windows\SYSTEM32\DRIVERS\CAPM1LP.SYS [2/23/2005 7:04 PM 22912]
R2 SeagateDashboardService;Seagate Dashboard Service;c:\program files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [11/3/2011 2:10 PM 8704]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\SYSTEM32\DRIVERS\mfefirek.sys [4/10/2012 1:30 PM 363080]
R3 mfendiskmp;mfendiskmp;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [12/17/2012 11:09 AM 84904]
S3 cfwids;McAfee Inc. cfwids;c:\windows\SYSTEM32\DRIVERS\cfwids.sys [4/10/2012 1:30 PM 60920]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.318\McCHSvc.exe [2/5/2013 11:48 AM 235216]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [12/17/2012 11:09 AM 84904]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\SYSTEM32\DRIVERS\mferkdet.sys [4/10/2012 1:30 PM 92632]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2013-03-29 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-01 17:18]
.
2013-03-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-22 20:34]
.
2005-01-07 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\OOBEBALN.EXE [2004-08-04 00:12]
.
2013-03-29 c:\windows\Tasks\ReclaimerUpdateFiles_Amy.job
- c:\documents and settings\Amy\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.40\agent\rnupgagent.exe [2013-03-29 17:08]
.
2013-03-29 c:\windows\Tasks\ReclaimerUpdateXML_Amy.job
- c:\documents and settings\Amy\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.40\agent\rnupgagent.exe [2013-03-29 17:08]
.
2013-03-29 c:\windows\Tasks\RNUpgradeHelperLogonPrompt_Amy.job
- c:\documents and settings\Amy\Application Data\Real\Update\UpgradeHelper\RealPlayer\10.40\agent\rnupgagent.exe [2013-03-29 17:08]
.
2013-03-28 c:\windows\Tasks\User_Feed_Synchronization-{9F65D221-A6DA-4935-A0FB-B46D030E6DFB}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzuyEtN2Y1L1QzutDtDtCtAtBtDyBtB0DtCtDyEzz0AtA0AtN0D0Tzu0CtByDzztN1L2Xzut
BtFtCtFtCtFtAtCtB&cr=1554250186
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
TCP: DhcpNameServer = [removed] [removed]
DPF: {A762E064-A885-40E4-AC10-671BB62DC2B2} - hxxp://www.eomniform.com/OF5/nsplugins/OFMailX.cab
FF - ProfilePath -
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKCU-Run-LxrAutorun - c:\documents and settings\Amy\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
SafeBoot-43974309.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-03-29 15:01
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="4FDA30922D1D3A4A1A518A89786166259F7EDB5C427B6808351193CC975D2AF0366B0F1D0D2
9192344801B1DA40F8878C6AF3B417DB9EAC349444851CFCDD2C520FADA1F447948AE66148D529013
6FAD41FB00C56744F61778843EEBB9CBE595E3A5E2CF484EA8ED9D5A9C1B05ACF5CE1083F2333F7C8
7B3CA5D6961A87C1C5C2B89678E23ABCC46D823758EE164ADC908E54DF9DA09C8B29762B11806445F
7876CB1C5A70DAFB82DBC2FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BE
CC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E667C038D530D6EB3452A6A0AC4980AC
7933BA7FD869164D679495747435A8FAC96341B3DE98263F27383A1B78105C0A222DC2209BCEE5FCA
1B5F1912D37D708A550DD8E2F2D5E33805417129D6F9D6DDC5C788D9F09E36E97BCC0958BD1B4AAE9
090018327694D560A956A9839D36F5A005FAE07D91E80208B41FBE6C83E01A0F499528FA5547C6822
752F4157BA34C1065B38514688D8A98CAA471C58F33735ED1803CB46EA90DF7BB59A850AF96019EBE
FD89D756A040433356B4207E3738766494751C2AA491235D2D1F4722F285965527A14F63A1BDD524B
1B516982ACA4B4A9B1982B35121BC8384D5A10251AF92F37222965D4783F057A6435970FEF3A24DD1
0ECC7C036DCFAB886F183D7EBB04E79607DA58FBF38B8C19522FD65DE1193F68E275B6390C3DD5573
1F98B7B463104C0F062A9DB57EF066079EDE29EA21BF1044988DC2E76B6878286A8E57CD2B01C8D9F
02EAB857B98A4AF50271D02CEB3E3F93A7A94C89C54991FA9B08E947F18B11FCA5FA18855DE394A6E
CA038D5247EA53D089D34074727FC415B7460EEB3AED2914D7B33531FE1F411C253C95D2D15B86173
FBB61468B2B4AF08EFAF760B67CC0E0BD2789A985713DAAA3130624562EC42464E5E3A2DFE97C0D20
3DCF0609B6E4407AA0A94B71A0AD1E1254B697FCFACC37260E5676F267E9082FAA155F1359BAA7D72
3BE1BE046B64385E2C59C349546FFCC1BC6DD8C3B363F0EAE87ECEA229DDBBDB1705C3753A2891CF9
901CB3D34F000C785006A79721E0CA453295D53E49B25DB5AE530D06ED2E7318E1026A0921BA70918
3AF7EBEEC8D744B67955BD8B47332EF7CFC07B7542C5FDB99A376A27E135E201972943CE1468A41AF
3445DD167EECF13F108E12C75CBF3FC983416A0DD00757D7B792C2CD06969BA050A2D5DA679838860
6CF1EA112F97EF6828231D4D6E2405AA38D61574987589F9DB31CAD4044F6291279DF5DB37AEDAC7F
016B50FFE183BCC89798A994872AA84426D27E457FCE46146DB8B4241C5BFDB44F57029C3BB7D72E6
CA037D5F4EF53D9A6BF6EB4D1B8390AAA7DA54BBAACD2FA54E4B44DF415B0B9888E982573A789C153
A312657FBE8400B0009C5ACF16DAA"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1108)
c:\program files\Citrix\GoToMyPC\G2WinLogon.dll
.
- - - - - - - > 'explorer.exe'(344)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\windows\system32\LxrSII1s.exe
c:\windows\system32\CAPM1RSK.EXE
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\spool\drivers\w32x86\3\CAPM1SWK.EXE
c:\windows\system32\oodag.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\program files\Memeo\AutoBackup\InstantBackup.exe
c:\program files\Seagate\Seagate Dashboard\MemeoDashboard.exe
c:\program files\Memeo\AutoBackup\MemeoUpdater.exe
c:\program files\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe
.
**************************************************************************
.
Completion time: 2013-03-29 15:11:25 - machine was rebooted
ComboFix-quarantined-files.txt 2013-03-29 19:11
ComboFix2.txt 2013-03-28 18:24
ComboFix3.txt 2013-03-18 18:09
ComboFix4.txt 2010-04-18 15:10
.
Pre-Run: 36,384,280,576 bytes free
Post-Run: 37,991,374,848 bytes free
.
- - End Of File - - 3DFAA343CE6596A2A665CA4F81E5DCE5
PS: I also got a windows popup somewhere in the process that my virtual memory was too low and that windows was increasin the size of some page file. Thanks again
Hi EricDSr,

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


NextOpen OTL
  • check the box beside "scan all users"
  • In the Extra Registry section check All
  • Click the Quick Scan button.
2 logs will be produced, OTL.txt and Extra.txt. Please pst them in your next reply.

Please post back with
  • MBAM log
  • both OTL logs

Thanks
Hi oldman960,

The only problem I had running the scans was that OTL would not run a scan with the extra registry checked. Once the scan begins the check mark reverts to "none." Also only one log was generated. No extra.txt.

The computer is behaving well.

Thanks

________________________________

Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org

Database version: v2013.03.30.05

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Amy :: IRWINA [administrator]

3/30/2013 1:22:52 PM
mbam-log-2013-03-30 (13-22-52).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 223508
Time elapsed: 5 minute(s), 10 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 20
HKCR\CLSID\{75A4D144-506D-4BE5-81DB-EC7DA1E7F840} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\TypeLib\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\esrv.funmoodsESrvc.1 (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\esrv.funmoodsESrvc (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\CLSID\{965B9DBE-B104-44AC-950A-8A5F97AFF439} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\escort.escortIEPane.1 (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\escort.escortIEPane (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\CLSID\{A9DB719C-7156-415E-B49D-BAD039DE4F13} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\funmoodsApp.appCore.1 (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\funmoodsApp.appCore (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\CLSID\{F03FD9D0-4F2B-497C-8A71-DD41D70B07D9} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\f (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\Typelib\{1D085C0A-E4F4-4F66-BDBF-4BE51015BFC3} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\Interface\{0D80F1C5-D17B-4177-AC68-955F3EF9F191} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Funmoods (PUP.FunMoods) -> Quarantined and deleted successfully.
HKCU\Software\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCU\Software\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj (PUP.FunMoods) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh (PUP.Funmoods) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj (PUP.FunMoods) -> Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 3
C:\Documents and Settings\Amy\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bbjciahceamgodcoidkjpchnokgfpphh_0.localstorage (PUP.Funmoods) -> Quarantined and deleted successfully.
C:\Documents and Settings\Amy\Local Settings\Application Data\funmoods.crx (PUP.Funmoods) -> Quarantined and deleted successfully.
C:\Documents and Settings\Amy\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cjpglkicenollcignonpgiafdgfeehoj_0.localstorage (PUP.FunMoods) -> Quarantined and deleted successfully.

(end)

_____________________________

OTL logfile created on: 3/30/2013 1:43:27 PM - Run 6
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Amy\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.25 Gb Total Physical Memory | 2.70 Gb Available Physical Memory | 83.04% Memory free
3.51 Gb Paging File | 2.73 Gb Available in Paging File | 77.69% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 71.39 Gb Total Space | 35.22 Gb Free Space | 49.34% Space Free | Partition Type: NTFS
Drive X: | 931.51 Gb Total Space | 886.29 Gb Free Space | 95.15% Space Free | Partition Type: NTFS
Drive Y: | 931.51 Gb Total Space | 886.29 Gb Free Space | 95.15% Space Free | Partition Type: NTFS
Drive Z: | 931.51 Gb Total Space | 886.29 Gb Free Space | 95.15% Space Free | Partition Type: NTFS

Computer Name: IRWINA | User Name: Amy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Documents and Settings\Amy\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\SYSTEM32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Documents and Settings\All Users\Application Data\WeCareReminder\ReminderHelper.exe (We-Care.com)
PRC - C:\Program Files\Seagate\Seagate Dashboard\MemeoDashboard.exe (Memeo)
PRC - C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe (Memeo)
PRC - C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe (Google)
PRC - C:\Program Files\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe (Axentra Corporation)
PRC - C:\Program Files\Memeo\AutoBackup\MemeoUpdater.exe (Memeo Inc.)
PRC - C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe (Memeo)
PRC - C:\Program Files\Memeo\AutoBackup\InstantBackup.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit, Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\SYSTEM32\oodag.exe (O&O Software GmbH)
PRC - C:\WINDOWS\SYSTEM32\LxrSII1s.exe ()
PRC - C:\Program Files\TrayDay\TrayDay.exe (MJMSoft Design Limited)
PRC - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAPM1SWK.EXE (CANON INC.)
PRC - C:\WINDOWS\SYSTEM32\CAPM1RSK.EXE (CANON INC.)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\e143370f0583abe015d8e3d2d536185e\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\d7ee03714420b252415b952d40ef59e4\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\1a6f9e23985e3159e6dd9827fd81c2fd\System.Management.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\024c898ad1ccfde466d033c0a08d0564\Microsoft.VisualBasic.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\96b7a0136e9e72e8f4eb0230c20766d2\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\cbee94ec6a0fe649e3b4643cea6e1259\Accessibility.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\fe025743210c22bea2f009e1612c38bf\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ba12e418b906593b7c9c18f971f36bf9\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\7782f356a838c403b4a8e9c80df5a577\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\8462c03b4f10c4624feb95790d6d1e30\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\aeac298c43c77d8860db8e7634d9f2eb\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\eab2340ead8e1a84bdf1a87868659979\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll ()
MOD - C:\Program Files\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.VideoTutorialsPlugin.dll ()
MOD - C:\Program Files\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.TroubleshootingPlugin.dll ()
MOD - C:\Program Files\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SeagateSharePlusPlugin.dll ()
MOD - C:\Program Files\Seagate\Seagate Dashboard\Memeo.Progress.dll ()
MOD - C:\Program Files\Memeo\AutoBackup\Memeo.Client.UI.dll ()
MOD - C:\Program Files\Memeo\AutoBackup\Memeo.Client.DriveDetection.dll ()
MOD - C:\Program Files\Memeo\AutoBackup\InstantBackup.exe ()
MOD - C:\Program Files\Seagate\Seagate Dashboard\HipServAgent\libxml2.dll ()
MOD - C:\Program Files\Seagate\Seagate Dashboard\HipServAgent\libupnp.dll ()
MOD - C:\Program Files\Memeo\AutoBackup\sqlite3.dll ()
MOD - C:\Program Files\Common Files\Memeo\ProfMan.dll ()
MOD - C:\WINDOWS\SYSTEM32\LxrSII1s.exe ()
MOD - C:\WINDOWS\SYSTEM32\BrMuSNMP.dll ()


========== Services (SafeList) ==========

SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (mfevtp) – C:\WINDOWS\SYSTEM32\mfevtps.exe (McAfee, Inc.)
SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe (McAfee, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (GoToMyPC) – C:\Program Files\Citrix\GoToMyPC\g2svc.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (SeagateDashboardService) – C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe (Memeo)
SRV - (MemeoBackgroundService) – C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe (Memeo)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (O&O Defrag) – C:\WINDOWS\SYSTEM32\oodag.exe (O&O Software GmbH)
SRV - (LxrSII1s) – C:\WINDOWS\System32\LxrSII1s.exe ()


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (wanatw) – system32\DRIVERS\wanatw4.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (mfeavfk01) – File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – C:\ComboFix\catchme.sys File not found
DRV - (bvrp_pci) – File not found
DRV - (cfwids) – C:\WINDOWS\SYSTEM32\DRIVERS\cfwids.sys (McAfee, Inc.)
DRV - (mfetdi2k) – C:\WINDOWS\SYSTEM32\DRIVERS\mfetdi2k.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\WINDOWS\SYSTEM32\DRIVERS\mferkdet.sys (McAfee, Inc.)
DRV - (mfehidk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfehidk.sys (McAfee, Inc.)
DRV - (mfendiskmp) – C:\WINDOWS\SYSTEM32\DRIVERS\mfendisk.sys (McAfee, Inc.)
DRV - (mfendisk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfendisk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\WINDOWS\SYSTEM32\DRIVERS\mfefirek.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\SYSTEM32\DRIVERS\mfeapfk.sys (McAfee, Inc.)
DRV - (dsunidrv) – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys (Gteko Ltd.)
DRV - (LxrSII1d) – C:\WINDOWS\SYSTEM32\DRIVERS\LxrSII1d.sys ()
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (IntelC53) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys (Intel Corporation)
DRV - (IntelC52) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys (Intel Corporation)
DRV - (xmasbus) – C:\WINDOWS\SYSTEM32\DRIVERS\xmasbus.sys ( )
DRV - (xmasscsi) – C:\WINDOWS\SYSTEM32\DRIVERS\xmasscsi.sys ( )
DRV - (omci) – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (RapidPortM1) – C:\WINDOWS\SYSTEM32\DRIVERS\CAPM1LP.SYS (CANON INC.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=axl&a…p;cr=1554250186
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{3280D243-2E15-DC28-DBC6-2289DB19CCEC}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=1554250186


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell4me.com/myway
IE - HKU\.DEFAULT\..\URLSearchHook: {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - No CLSID value found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell4me.com/myway
IE - HKU\S-1-5-18\..\URLSearchHook: {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - No CLSID value found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-4073680847-1405297832-2471763517-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://q103albany.com/listen-live/
IE - HKU\S-1-5-21-4073680847-1405297832-2471763517-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-4073680847-1405297832-2471763517-1006\..\SearchScopes,Backup.Old.DefaultScope = {DAC606D8-D01B-4D7C-9545-09DAFF870ED9}
IE - HKU\S-1-5-21-4073680847-1405297832-2471763517-1006\..\SearchScopes,DefaultScope = {DAC606D8-D01B-4D7C-9545-09DAFF870ED9}
IE - HKU\S-1-5-21-4073680847-1405297832-2471763517-1006\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-4073680847-1405297832-2471763517-1006\..\SearchScopes\{3280D243-2E15-DC28-DBC6-2289DB19CCEC}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7ADFA_en
IE - HKU\S-1-5-21-4073680847-1405297832-2471763517-1006\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKU\S-1-5-21-4073680847-1405297832-2471763517-1006\..\SearchScopes\{DAC606D8-D01B-4D7C-9545-09DAFF870ED9}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7ADFA_en
IE - HKU\S-1-5-21-4073680847-1405297832-2471763517-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@ei.DotSpot_2k.com/Plugin: C:\Program Files\DotSpot_2kEI\Installr\1.bin\NP2kEISB.dll (DotSpot)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2536: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2594: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1698: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{71EA6046-8286-4ADC-BF58-501E76626E60}: C:\Documents and Settings\Amy\Local Settings\Application Data\{71EA6046-8286-4ADC-BF58-501E76626E60}
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2013/03/30 13:11:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/03/27 16:00:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2013/03/27 16:00:34 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/03/07 10:31:00 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/03/07 10:30:20 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/03/07 10:30:20 | 000,002,086 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2013/03/29 15:00:43 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20120628081231.dll (McAfee, Inc.)
O2 - BHO: (WeCareReminder Class) - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEHelperv2.5.0.dll (We-Care.com)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O3 - HKU\S-1-5-21-4073680847-1405297832-2471763517-1006\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-4073680847-1405297832-2471763517-1006\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Memeo Instant Backup] C:\Program Files\Memeo\AutoBackup\MemeoLauncher2.exe (Memeo Inc.)
O4 - HKLM..\Run: [Seagate Dashboard] C:\Program Files\Seagate\Seagate Dashboard\MemeoLauncher.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Calendar Sync.lnk = C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe (Google)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit, Inc.)
O4 - Startup: C:\Documents and Settings\Amy\Start Menu\Programs\Startup\TrayDay.lnk = C:\Program Files\TrayDay\TrayDay.exe (MJMSoft Design Limited)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4073680847-1405297832-2471763517-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4073680847-1405297832-2471763517-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-4073680847-1405297832-2471763517-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-4073680847-1405297832-2471763517-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab (SupportSoft SmartIssue)
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab (SupportSoft Script Runner Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1136553665781 (MUWebControl Class)
O16 - DPF: {A762E064-A885-40E4-AC10-671BB62DC2B2} http://www.eomniform.com/OF5/nsplugins/OFMailX.cab (OFMailHTMLCtl Class)
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab (ActiveDataInfo Class)
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} http://download.microsoft.com/download/7/E…04/clearadj.cab (CTAdjust Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3907E8B6-1C61-484E-8A99-8A099D358E38}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToMyPC: DllName - (C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll) - C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Amy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Amy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 19:15:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (OODBS)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/03/30 13:21:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/03/30 13:21:03 | 000,021,104 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2013/03/30 13:17:39 | 010,156,344 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Amy\Desktop\mbam-setup-1.70.0.1100.exe
[2013/03/30 13:10:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
[2013/03/29 14:32:04 | 005,044,813 | R— | C] (Swearware) – C:\Documents and Settings\Amy\Desktop\ComboFix.exe
[2013/03/29 14:18:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Amy\Local Settings\Application Data\Sun
[2013/03/29 14:15:23 | 002,237,968 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Amy\Desktop\tdsskiller.exe
[2013/03/29 14:15:23 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Amy\Desktop\OTL.exe
[2013/03/29 14:15:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Amy\Local Settings\Application Data\PCHealth
[2013/03/29 14:14:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Amy\Desktop\Virus March 2013
[2013/03/29 13:28:48 | 000,000,000 | —D | C] – C:\Program Files\Java
[2013/03/29 12:43:13 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2013/03/28 14:24:47 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2013/03/28 13:48:55 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2013/03/28 13:48:55 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2013/03/28 13:48:55 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2013/03/27 16:00:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Mozilla
[2013/03/27 16:00:35 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2013/03/27 16:00:31 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/03/18 12:37:50 | 000,000,000 | —D | C] – C:\jgh
[2013/03/14 11:12:38 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2013/03/14 11:11:53 | 000,000,000 | —D | C] – C:\Qoobox
[2005/02/04 13:54:26 | 000,089,680 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Amy\MSSSerif120.fon

========== Files - Modified Within 30 Days ==========

[2013/03/30 13:21:05 | 000,000,818 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/03/30 13:17:39 | 010,156,344 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Amy\Desktop\mbam-setup-1.70.0.1100.exe
[2013/03/30 13:17:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/03/30 13:10:58 | 000,001,629 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee AntiVirus Plus.lnk
[2013/03/30 13:06:48 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2013/03/30 13:06:14 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/03/30 13:06:14 | 000,000,404 | —- | M] () – C:\WINDOWS\tasks\RNUpgradeHelperLogonPrompt_Amy.job
[2013/03/30 13:06:10 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2013/03/30 13:06:09 | 3487,715,328 | -HS- | M] () – C:\hiberfil.sys
[2013/03/30 13:06:07 | 000,476,658 | —- | M] () – C:\WINDOWS\System32\OODBS.lor
[2013/03/29 15:17:46 | 000,000,418 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{9F65D221-A6DA-4935-A0FB-B46D030E6DFB}.job
[2013/03/29 15:00:43 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\hosts
[2013/03/29 14:32:15 | 005,044,813 | R— | M] (Swearware) – C:\Documents and Settings\Amy\Desktop\ComboFix.exe
[2013/03/29 14:11:00 | 000,000,398 | —- | M] () – C:\WINDOWS\tasks\ReclaimerUpdateFiles_Amy.job
[2013/03/29 14:11:00 | 000,000,394 | —- | M] () – C:\WINDOWS\tasks\ReclaimerUpdateXML_Amy.job
[2013/03/29 14:10:48 | 000,146,808 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/03/29 14:05:43 | 000,445,836 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2013/03/29 14:05:43 | 000,073,042 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2013/03/29 13:56:07 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2013/03/29 13:19:15 | 000,001,590 | —- | M] () – C:\WINDOWS\TIMESLIP.INI
[2013/03/29 11:40:10 | 002,237,968 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Amy\Desktop\tdsskiller.exe
[2013/03/27 16:01:58 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2013/03/18 15:25:00 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2013/03/18 14:51:56 | 000,002,521 | —- | M] () – C:\Documents and Settings\Amy\Desktop\Microsoft Office Outlook 2003.lnk
[2013/03/13 16:36:37 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Amy\Desktop\OTL.exe
[2013/03/11 16:16:11 | 000,000,060 | -H– | M] () – C:\WINDOWS\popcreg.dat
[2013/03/11 16:16:11 | 000,000,042 | —- | M] () – C:\WINDOWS\popcinfot.dat
[2013/03/04 11:23:30 | 000,002,495 | —- | M] () – C:\Documents and Settings\Amy\Desktop\Microsoft Office Excel 2003.lnk

========== Files Created - No Company Name ==========

[2013/03/30 13:21:05 | 000,000,818 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/03/29 14:11:52 | 000,000,404 | —- | C] () – C:\WINDOWS\tasks\RNUpgradeHelperLogonPrompt_Amy.job
[2013/03/29 14:10:59 | 000,000,398 | —- | C] () – C:\WINDOWS\tasks\ReclaimerUpdateFiles_Amy.job
[2013/03/29 14:10:58 | 000,000,394 | —- | C] () – C:\WINDOWS\tasks\ReclaimerUpdateXML_Amy.job
[2013/03/29 12:57:02 | 3487,715,328 | -HS- | C] () – C:\hiberfil.sys
[2013/03/28 13:48:56 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2013/03/28 13:48:55 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2013/03/28 13:48:55 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2013/03/28 13:48:55 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2013/03/28 13:48:55 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2013/03/27 16:01:58 | 000,000,724 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2013/03/27 16:01:18 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2012/10/31 10:36:58 | 000,003,208 | -HS- | C] () – C:\Documents and Settings\Amy\Local Settings\Application Data\6o4v7yr6ikfw18072u
[2012/10/31 10:36:58 | 000,003,208 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\6o4v7yr6ikfw18072u
[2012/09/14 14:19:43 | 000,384,844 | —- | C] () – C:\Documents and Settings\Amy\Local Settings\Application Data\funmoods-speeddial.crx
[2012/08/07 14:49:20 | 004,608,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ReadOnlyInstaller.msi
[2012/02/15 09:03:55 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2005/01/28 15:27:49 | 000,010,240 | —- | C] () – C:\Documents and Settings\Amy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/01/21 12:36:19 | 000,000,816 | —- | C] () – C:\Documents and Settings\Amy\Eudora.lnk
[2005/01/07 18:12:08 | 000,000,126 | —- | C] () – C:\Documents and Settings\Amy\Local Settings\Application Data\fusioncache.dat

========== ZeroAccess Check ==========

[2004/08/11 19:21:56 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2008/04/13 20:12:05 | 001,499,136 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/02/09 08:10:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/04/13 20:12:08 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/04/10 13:06:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2012/01/12 10:38:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CitrixLogs
[2010/10/05 14:06:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MemeoCommon
[2010/07/20 14:10:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2010/09/17 12:13:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2012/09/14 14:19:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2008/11/03 10:13:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2012/09/14 14:20:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WeCareReminder
[2008/05/13 14:28:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\Ceedo
[2011/03/25 10:06:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\F8825A71ED75651A8D57DC362A93BB58
[2012/09/14 14:21:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\Funmoods
[2005/02/04 13:54:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\Leadertech
[2010/10/05 14:05:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\Memeo
[2011/09/27 11:23:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\PC-FAX TX
[2005/01/21 12:36:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\Qualcomm
[2006/02/13 13:23:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\ScanSoft
[2010/10/05 13:54:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\Seagate
[2009/05/20 15:44:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\The Labyrinth Plus! Edition
[2006/10/24 11:03:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\UVU
[2007/06/11 14:25:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\Viewpoint
[2010/10/05 13:54:43 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Seagate

========== Purity Check ==========



< End of report >
Hi EricDSr,

That's ok. Please post the contents of this file it will show us wwhat we need to see.

C:\Qoobox\Add-Remove Programs.txt
Hi oldman960, I have to leave town for a few days and am away from the computer in question. If you can stick with me I'll be able to continue on Wednesday. Thanks for all your help.
Hi oldman960, Thanks for sticking with this. The computer seems good. Here is the contents of the requested file. ______________________________________________ Ad-Aware SE Personal Adobe AIR Adobe Flash Player 11 ActiveX Adobe Reader 9.5.0 Alcohol 120% ASPCA Reminder by We-Care.com v4.1.18.1 ATI Control Panel ATI Display Driver Bejeweled 2 Deluxe Brother MFL-Pro Suite Canon PC1200/iC D600/iR1200G ClearType Tuning Control Panel Applet Compatibility Pack for the 2007 Office system Dell Driver Reset Tool DellSupport EFS version 4.0 Eudora Google Calendar Sync Google Toolbar for Internet Explorer GoToMyPC Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB2633952) Hotfix for Windows XP (KB2756822) Hotfix for Windows XP (KB2779562) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) Intel® 537EP V9x DF PCI Modem Intel® PRO Network Adapters and Drivers Intel® PROSet for Wired Connections Internet Explorer Default Page Jasc Paint Shop Photo Album Jasc Paint Shop Pro 8 Dell Edition Java 7 Update 17 Java Auto Updater McAfee AntiVirus Plus McAfee Security Scan Plus Memeo Instant Backup Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2656353) Microsoft .NET Framework 1.1 Security Update (KB2656370) Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Basic Edition 2003 Microsoft Office File Validation Add-In Microsoft Plus! Digital Media Edition Installer Microsoft Plus! for Windows XP Microsoft Plus! Photo Story 2 LE Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Modem Event Monitor Modem Helper Modem On Hold Mozilla Firefox 19.0.2 (x86 en-US) Mozilla Maintenance Service MSN MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) My Way Search Assistant O&O Defrag Professional Edition OGA Notifier 2.0.0048.0 PaperPort Image Printer Photo Click PowerDVD 5.3 Qualxserve Service Agreement QuickBooks Basic Edition 2004 QuickTime RealPlayer Rhapsody Player Engine ScanSoft PaperPort 11 Seagate Dashboard Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416) Security Update for Microsoft Windows (KB2564958) Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB2183461) Security Update for Windows Internet Explorer 7 (KB2360131) Security Update for Windows Internet Explorer 7 (KB2416400) Security Update for Windows Internet Explorer 7 (KB2482017) Security Update for Windows Internet Explorer 7 (KB2497640) Security Update for Windows Internet Explorer 7 (KB2530548) Security Update for Windows Internet Explorer 7 (KB2544521) Security Update for Windows Internet Explorer 7 (KB2559049) Security Update for Windows Internet Explorer 7 (KB2586448) Security Update for Windows Internet Explorer 7 (KB2618444) Security Update for Windows Internet Explorer 7 (KB2647516) Security Update for Windows Internet Explorer 7 (KB2675157) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB978207) Security Update for Windows Internet Explorer 7 (KB982381) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2618444) Security Update for Windows Internet Explorer 8 (KB2647516) Security Update for Windows Internet Explorer 8 (KB2675157) Security Update for Windows Internet Explorer 8 (KB2699988) Security Update for Windows Internet Explorer 8 (KB2722913) Security Update for Windows Internet Explorer 8 (KB2744842) Security Update for Windows Internet Explorer 8 (KB2797052) Security Update for Windows Internet Explorer 8 (KB2809289) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2491683) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2510581) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567053) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2585542) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2621440) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2633171) Security Update for Windows XP (KB2639417) Security Update for Windows XP (KB2641653) Security Update for Windows XP (KB2646524) Security Update for Windows XP (KB2647518) Security Update for Windows XP (KB2653956) Security Update for Windows XP (KB2655992) Security Update for Windows XP (KB2659262) Security Update for Windows XP (KB2660465) Security Update for Windows XP (KB2661637) Security Update for Windows XP (KB2676562) Security Update for Windows XP (KB2685939) Security Update for Windows XP (KB2686509) Security Update for Windows XP (KB2691442) Security Update for Windows XP (KB2695962) Security Update for Windows XP (KB2698365) Security Update for Windows XP (KB2705219) Security Update for Windows XP (KB2707511) Security Update for Windows XP (KB2709162) Security Update for Windows XP (KB2712808) Security Update for Windows XP (KB2718523) Security Update for Windows XP (KB2719985) Security Update for Windows XP (KB2723135) Security Update for Windows XP (KB2724197) Security Update for Windows XP (KB2727528) Security Update for Windows XP (KB2731847) Security Update for Windows XP (KB2753842-v2) Security Update for Windows XP (KB2757638) Security Update for Windows XP (KB2758857) Security Update for Windows XP (KB2770660) Security Update for Windows XP (KB2778344) Security Update for Windows XP (KB2780091) Security Update for Windows XP (KB2799494) Security Update for Windows XP (KB2802968) Security Update for Windows XP (KB2807986) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981349) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) Shared C Run-time for x86 Sonic DLA Sonic RecordNow! Sonic Update Manager Spybot - Search & Destroy 1.3 Timeslips v11 TrayDay Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 7 (KB976749) Update for Windows Internet Explorer 7 (KB980182) Update for Windows Internet Explorer 8 (KB2598845) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB2541763) Update for Windows XP (KB2607712) Update for Windows XP (KB2616676) Update for Windows XP (KB2641690) Update for Windows XP (KB2661254-v2) Update for Windows XP (KB2718704) Update for Windows XP (KB2736233) Update for Windows XP (KB2749655) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VLC media player 2.0.0 WebFldrs XP Winamp (remove only) Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage v1.3.0254.0 Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Media Format Runtime Windows Media Player 10 Windows XP Service Pack 3 Yontoo 1.10.02 Zuma's Revenge!
Hi EricDSr,

Let's see how we are doing.

Next, openOTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=axl&a…p;cr=1554250186
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=1554250186
IE - HKU\.DEFAULT\..\URLSearchHook: {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - No CLSID value found
IE - HKU\S-1-5-18\..\URLSearchHook: {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - No CLSID value found
O3 - HKU\S-1-5-21-4073680847-1405297832-2471763517-1006\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
2012/09/14 14:21:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Amy\Application Data\Funmoods

:Files
dir C:\Documents and Settings\Amy\Local Settings\Application Data\{71EA6046-8286-4ADC-BF58-501E76626E60}\*.* /s /c

:Commands
[emptytemp]
[createrestorepoint]

Next

Let's see if combofix is still detecting Zero Access.

Please delete the copy of combofix you have and download a new one from HERE

Disable your security programs before running combofix.

Please post back with
  • OTL fix log
  • combofix log
Did combofix detect Zero Access this time?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI