This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google redirect virus [Closed]

57 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello mikej62,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice, this will be a team effort. This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Important Note for Vista and Windows 7 users:

These tools MUST be run from the executable.(.exe) every time you run them with Admin Rights (Right click, choose "Run as Administrator")

Please stay with this topic until I let you know that your system appears to be "All Clear"
Hi mikej62,

Please copy & paste all requested logs directly into your reply, do not attach them unless specifically asked to do so.

= = = = = = = = = = = = = = = = = = = =

I noticed that you don't appear to have an Antivirus program installed on your system. Limit your internet activity to downloading the tools requested during the cleaning process, and responding to this thread. We will address the lack of an Anti-Virus program after we remove the malware.

= = = = = = = = = = = = = = = = = = = =

Please download TDSSKiller.zip
  • Extract it to your desktop
  • TDSSKiller.exe - Right click and select "Run as Administrator".
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
In your next post please provide the following:
  • TDSSKiller log
19:42:25.0690 7304 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 19:42:25.0939 7304 ============================================================ 19:42:25.0939 7304 Current date / time: 2013/03/21 19:42:25.0939 19:42:25.0939 7304 SystemInfo: 19:42:25.0939 7304 19:42:25.0939 7304 OS Version: 6.1.7601 ServicePack: 1.0 19:42:25.0939 7304 Product type: Workstation 19:42:25.0939 7304 ComputerName: NMOHAMED-PC 19:42:25.0939 7304 UserName: NMohamed 19:42:25.0939 7304 Windows directory: C:\windows 19:42:25.0939 7304 System windows directory: C:\windows 19:42:25.0939 7304 Running under WOW64 19:42:25.0939 7304 Processor architecture: Intel x64 19:42:25.0939 7304 Number of processors: 4 19:42:25.0939 7304 Page size: 0x1000 19:42:25.0939 7304 Boot type: Normal boot 19:42:25.0939 7304 ============================================================ 19:42:26.0580 7304 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 19:42:26.0580 7304 ============================================================ 19:42:26.0580 7304 \Device\Harddisk0\DR0: 19:42:26.0580 7304 MBR partitions: 19:42:26.0580 7304 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x2308C000 19:42:26.0580 7304 ============================================================ 19:42:26.0595 7304 C: <-> \Device\Harddisk0\DR0\Partition1 19:42:26.0611 7304 ============================================================ 19:42:26.0611 7304 Initialize success 19:42:26.0611 7304 ============================================================ 19:42:30.0192 6560 ============================================================ 19:42:30.0192 6560 Scan started 19:42:30.0192 6560 Mode: Manual; 19:42:30.0192 6560 ============================================================ 19:42:30.0442 6560 ================ Scan system memory ======================== 19:42:30.0442 6560 System memory - ok 19:42:30.0442 6560 ================ Scan services ============================= 19:42:30.0645 6560 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\windows\system32\drivers\1394ohci.sys 19:42:30.0645 6560 1394ohci - ok 19:42:30.0692 6560 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\windows\system32\drivers\ACPI.sys 19:42:30.0692 6560 ACPI - ok 19:42:30.0738 6560 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\windows\system32\drivers\acpipmi.sys 19:42:30.0738 6560 AcpiPmi - ok 19:42:30.0879 6560 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 19:42:30.0879 6560 AdobeARMservice - ok 19:42:31.0050 6560 [ EA856F4A46320389D1899B2CAA7BF40F ] AdobeFlashPlayerUpdateSvc C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 19:42:31.0050 6560 AdobeFlashPlayerUpdateSvc - ok 19:42:31.0113 6560 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\windows\system32\DRIVERS\adp94xx.sys 19:42:31.0113 6560 adp94xx - ok 19:42:31.0144 6560 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\windows\system32\DRIVERS\adpahci.sys 19:42:31.0160 6560 adpahci - ok 19:42:31.0160 6560 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\windows\system32\DRIVERS\adpu320.sys 19:42:31.0160 6560 adpu320 - ok 19:42:31.0206 6560 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\windows\System32\aelupsvc.dll 19:42:31.0206 6560 AeLookupSvc - ok 19:42:31.0269 6560 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\windows\system32\drivers\afd.sys 19:42:31.0269 6560 AFD - ok 19:42:31.0300 6560 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\windows\system32\drivers\agp440.sys 19:42:31.0300 6560 agp440 - ok 19:42:31.0347 6560 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\windows\System32\alg.exe 19:42:31.0347 6560 ALG - ok 19:42:31.0394 6560 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\windows\system32\drivers\aliide.sys 19:42:31.0394 6560 aliide - ok 19:42:31.0409 6560 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\windows\system32\drivers\amdide.sys 19:42:31.0409 6560 amdide - ok 19:42:31.0456 6560 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\windows\system32\DRIVERS\amdk8.sys 19:42:31.0456 6560 AmdK8 - ok 19:42:31.0472 6560 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\windows\system32\DRIVERS\amdppm.sys 19:42:31.0472 6560 AmdPPM - ok 19:42:31.0518 6560 [ 6EC6D772EAE38DC17C14AED9B178D24B ] amdsata C:\windows\system32\drivers\amdsata.sys 19:42:31.0518 6560 amdsata - ok 19:42:31.0534 6560 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\windows\system32\DRIVERS\amdsbs.sys 19:42:31.0534 6560 amdsbs - ok 19:42:31.0550 6560 [ 1142A21DB581A84EA5597B03A26EBAA0 ] amdxata C:\windows\system32\drivers\amdxata.sys 19:42:31.0550 6560 amdxata - ok 19:42:31.0596 6560 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\windows\system32\drivers\appid.sys 19:42:31.0596 6560 AppID - ok 19:42:31.0643 6560 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\windows\System32\appidsvc.dll 19:42:31.0643 6560 AppIDSvc - ok 19:42:31.0690 6560 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\windows\System32\appinfo.dll 19:42:31.0690 6560 Appinfo - ok 19:42:31.0784 6560 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 19:42:31.0784 6560 Apple Mobile Device - ok 19:42:31.0830 6560 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\windows\system32\DRIVERS\arc.sys 19:42:31.0846 6560 arc - ok 19:42:31.0846 6560 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\windows\system32\DRIVERS\arcsas.sys 19:42:31.0846 6560 arcsas - ok 19:42:31.0877 6560 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys 19:42:31.0877 6560 AsyncMac - ok 19:42:31.0924 6560 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\windows\system32\drivers\atapi.sys 19:42:31.0940 6560 atapi - ok 19:42:32.0033 6560 [ D6CAD7E5B05055BB8226BDCB1644DA27 ] athr C:\windows\system32\DRIVERS\athrx.sys 19:42:32.0049 6560 athr - ok 19:42:32.0127 6560 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll 19:42:32.0127 6560 AudioEndpointBuilder - ok 19:42:32.0142 6560 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\windows\System32\Audiosrv.dll 19:42:32.0158 6560 AudioSrv - ok 19:42:32.0205 6560 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\windows\System32\AxInstSV.dll 19:42:32.0205 6560 AxInstSV - ok 19:42:32.0236 6560 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\windows\system32\DRIVERS\bxvbda.sys 19:42:32.0236 6560 b06bdrv - ok 19:42:32.0252 6560 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\windows\system32\DRIVERS\b57nd60a.sys 19:42:32.0252 6560 b57nd60a - ok 19:42:32.0298 6560 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\windows\System32\bdesvc.dll 19:42:32.0298 6560 BDESVC - ok 19:42:32.0314 6560 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\windows\system32\drivers\Beep.sys 19:42:32.0314 6560 Beep - ok 19:42:32.0361 6560 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\windows\System32\bfe.dll 19:42:32.0376 6560 BFE - ok 19:42:32.0408 6560 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\windows\System32\qmgr.dll 19:42:32.0408 6560 BITS - ok 19:42:32.0454 6560 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\windows\system32\DRIVERS\blbdrive.sys 19:42:32.0454 6560 blbdrive - ok 19:42:32.0564 6560 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 19:42:32.0564 6560 Bonjour Service - ok 19:42:32.0610 6560 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\windows\system32\DRIVERS\bowser.sys 19:42:32.0610 6560 bowser - ok 19:42:32.0657 6560 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\windows\system32\DRIVERS\BrFiltLo.sys 19:42:32.0657 6560 BrFiltLo - ok 19:42:32.0657 6560 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\windows\system32\DRIVERS\BrFiltUp.sys 19:42:32.0657 6560 BrFiltUp - ok 19:42:32.0688 6560 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\windows\System32\browser.dll 19:42:32.0704 6560 Browser - ok 19:42:32.0735 6560 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\windows\System32\Drivers\Brserid.sys 19:42:32.0735 6560 Brserid - ok 19:42:32.0751 6560 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\windows\System32\Drivers\BrSerWdm.sys 19:42:32.0751 6560 BrSerWdm - ok 19:42:32.0751 6560 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\windows\System32\Drivers\BrUsbMdm.sys 19:42:32.0751 6560 BrUsbMdm - ok 19:42:32.0751 6560 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\windows\System32\Drivers\BrUsbSer.sys 19:42:32.0766 6560 BrUsbSer - ok 19:42:32.0766 6560 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\windows\system32\DRIVERS\bthmodem.sys 19:42:32.0766 6560 BTHMODEM - ok 19:42:32.0813 6560 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\windows\system32\bthserv.dll 19:42:32.0829 6560 bthserv - ok 19:42:32.0844 6560 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\windows\system32\DRIVERS\cdfs.sys 19:42:32.0860 6560 cdfs - ok 19:42:32.0907 6560 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\windows\system32\drivers\cdrom.sys 19:42:32.0907 6560 cdrom - ok 19:42:32.0954 6560 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\windows\System32\certprop.dll 19:42:32.0954 6560 CertPropSvc - ok 19:42:32.0985 6560 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\windows\system32\DRIVERS\circlass.sys 19:42:32.0985 6560 circlass - ok 19:42:33.0032 6560 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\windows\system32\CLFS.sys 19:42:33.0032 6560 CLFS - ok 19:42:33.0094 6560 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 19:42:33.0110 6560 clr_optimization_v2.0.50727_32 - ok 19:42:33.0125 6560 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 19:42:33.0125 6560 clr_optimization_v2.0.50727_64 - ok 19:42:33.0188 6560 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\windows\system32\DRIVERS\CmBatt.sys 19:42:33.0188 6560 CmBatt - ok 19:42:33.0203 6560 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\windows\system32\drivers\cmdide.sys 19:42:33.0203 6560 cmdide - ok 19:42:33.0250 6560 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\windows\system32\Drivers\cng.sys 19:42:33.0266 6560 CNG - ok 19:42:33.0312 6560 [ 25C58EE97BE0416A373E3E4F855206B5 ] CnxtHdAudService C:\windows\system32\drivers\CHDRT64.sys 19:42:33.0328 6560 CnxtHdAudService - ok 19:42:33.0359 6560 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\windows\system32\DRIVERS\compbatt.sys 19:42:33.0359 6560 Compbatt - ok 19:42:33.0422 6560 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\windows\system32\drivers\CompositeBus.sys 19:42:33.0422 6560 CompositeBus - ok 19:42:33.0437 6560 COMSysApp - ok 19:42:33.0453 6560 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\windows\system32\DRIVERS\crcdisk.sys 19:42:33.0453 6560 crcdisk - ok 19:42:33.0500 6560 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\windows\system32\cryptsvc.dll 19:42:33.0500 6560 CryptSvc - ok 19:42:33.0546 6560 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\windows\system32\rpcss.dll 19:42:33.0562 6560 DcomLaunch - ok 19:42:33.0593 6560 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\windows\System32\defragsvc.dll 19:42:33.0609 6560 defragsvc - ok 19:42:33.0656 6560 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\windows\system32\Drivers\dfsc.sys 19:42:33.0656 6560 DfsC - ok 19:42:33.0702 6560 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\windows\system32\dhcpcore.dll 19:42:33.0702 6560 Dhcp - ok 19:42:33.0734 6560 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\windows\system32\drivers\discache.sys 19:42:33.0734 6560 discache - ok 19:42:33.0780 6560 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\windows\system32\DRIVERS\disk.sys 19:42:33.0780 6560 Disk - ok 19:42:33.0812 6560 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\windows\System32\dnsrslvr.dll 19:42:33.0812 6560 Dnscache - ok 19:42:33.0858 6560 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\windows\System32\dot3svc.dll 19:42:33.0874 6560 dot3svc - ok 19:42:33.0905 6560 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\windows\system32\dps.dll 19:42:33.0905 6560 DPS - ok 19:42:33.0952 6560 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\windows\system32\drivers\drmkaud.sys 19:42:33.0952 6560 drmkaud - ok 19:42:34.0014 6560 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys 19:42:34.0014 6560 DXGKrnl - ok 19:42:34.0046 6560 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\windows\System32\eapsvc.dll 19:42:34.0046 6560 EapHost - ok 19:42:34.0155 6560 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\windows\system32\DRIVERS\evbda.sys 19:42:34.0202 6560 ebdrv - ok 19:42:34.0217 6560 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\windows\System32\lsass.exe 19:42:34.0217 6560 EFS - ok 19:42:34.0295 6560 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\windows\ehome\ehRecvr.exe 19:42:34.0295 6560 ehRecvr - ok 19:42:34.0326 6560 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\windows\ehome\ehsched.exe 19:42:34.0326 6560 ehSched - ok 19:42:34.0389 6560 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\windows\system32\DRIVERS\elxstor.sys 19:42:34.0389 6560 elxstor - ok 19:42:34.0404 6560 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\windows\system32\drivers\errdev.sys 19:42:34.0404 6560 ErrDev - ok 19:42:34.0436 6560 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\windows\system32\es.dll 19:42:34.0451 6560 EventSystem - ok 19:42:34.0482 6560 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\windows\system32\drivers\exfat.sys 19:42:34.0482 6560 exfat - ok 19:42:34.0498 6560 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\windows\system32\drivers\fastfat.sys 19:42:34.0498 6560 fastfat - ok 19:42:34.0560 6560 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\windows\system32\fxssvc.exe 19:42:34.0560 6560 Fax - ok 19:42:34.0576 6560 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\windows\system32\DRIVERS\fdc.sys 19:42:34.0576 6560 fdc - ok 19:42:34.0607 6560 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\windows\system32\fdPHost.dll 19:42:34.0607 6560 fdPHost - ok 19:42:34.0623 6560 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\windows\system32\fdrespub.dll 19:42:34.0623 6560 FDResPub - ok 19:42:34.0638 6560 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\windows\system32\drivers\fileinfo.sys 19:42:34.0638 6560 FileInfo - ok 19:42:34.0654 6560 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\windows\system32\drivers\filetrace.sys 19:42:34.0654 6560 Filetrace - ok 19:42:34.0670 6560 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\windows\system32\DRIVERS\flpydisk.sys 19:42:34.0670 6560 flpydisk - ok 19:42:34.0685 6560 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\windows\system32\drivers\fltmgr.sys 19:42:34.0701 6560 FltMgr - ok 19:42:34.0748 6560 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\windows\system32\FntCache.dll 19:42:34.0763 6560 FontCache - ok 19:42:34.0826 6560 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 19:42:34.0826 6560 FontCache3.0.0.0 - ok 19:42:34.0857 6560 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\windows\system32\drivers\FsDepends.sys 19:42:34.0857 6560 FsDepends - ok 19:42:34.0888 6560 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys 19:42:34.0888 6560 Fs_Rec - ok 19:42:34.0935 6560 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\windows\system32\DRIVERS\fvevol.sys 19:42:34.0935 6560 fvevol - ok 19:42:34.0966 6560 [ 60ACB128E64C35C2B4E4AAB1B0A5C293 ] FwLnk C:\windows\system32\DRIVERS\FwLnk.sys 19:42:34.0966 6560 FwLnk - ok 19:42:34.0982 6560 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\windows\system32\DRIVERS\gagp30kx.sys 19:42:34.0997 6560 gagp30kx - ok 19:42:35.0060 6560 [ 1FDA0DF739234C4023851A282DD28704 ] GameConsoleService C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe 19:42:35.0075 6560 GameConsoleService - ok 19:42:35.0122 6560 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\windows\system32\DRIVERS\GEARAspiWDM.sys 19:42:35.0122 6560 GEARAspiWDM - ok 19:42:35.0169 6560 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\windows\System32\gpsvc.dll 19:42:35.0184 6560 gpsvc - ok 19:42:35.0216 6560 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 19:42:35.0216 6560 gupdate - ok 19:42:35.0247 6560 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 19:42:35.0247 6560 gupdatem - ok 19:42:35.0294 6560 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe 19:42:35.0294 6560 gusvc - ok 19:42:35.0325 6560 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\windows\system32\drivers\hcw85cir.sys 19:42:35.0325 6560 hcw85cir - ok 19:42:35.0372 6560 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys 19:42:35.0387 6560 HdAudAddService - ok 19:42:35.0434 6560 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\windows\system32\drivers\HDAudBus.sys 19:42:35.0434 6560 HDAudBus - ok 19:42:35.0481 6560 [ B6AC71AAA2B10848F57FC49D55A651AF ] HECIx64 C:\windows\system32\DRIVERS\HECIx64.sys 19:42:35.0481 6560 HECIx64 - ok 19:42:35.0496 6560 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\windows\system32\DRIVERS\HidBatt.sys 19:42:35.0496 6560 HidBatt - ok 19:42:35.0512 6560 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\windows\system32\DRIVERS\hidbth.sys 19:42:35.0512 6560 HidBth - ok 19:42:35.0512 6560 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\windows\system32\DRIVERS\hidir.sys 19:42:35.0512 6560 HidIr - ok 19:42:35.0543 6560 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\windows\system32\hidserv.dll 19:42:35.0543 6560 hidserv - ok 19:42:35.0590 6560 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\windows\system32\drivers\hidusb.sys 19:42:35.0590 6560 HidUsb - ok 19:42:35.0621 6560 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\windows\system32\kmsvc.dll 19:42:35.0621 6560 hkmsvc - ok 19:42:35.0652 6560 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\windows\system32\ListSvc.dll 19:42:35.0668 6560 HomeGroupListener - ok 19:42:35.0699 6560 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\windows\system32\provsvc.dll 19:42:35.0715 6560 HomeGroupProvider - ok 19:42:35.0746 6560 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\windows\system32\drivers\HpSAMD.sys 19:42:35.0746 6560 HpSAMD - ok 19:42:35.0777 6560 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\windows\system32\drivers\HTTP.sys 19:42:35.0793 6560 HTTP - ok 19:42:35.0808 6560 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\windows\system32\drivers\hwpolicy.sys 19:42:35.0808 6560 hwpolicy - ok 19:42:35.0855 6560 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\windows\system32\drivers\i8042prt.sys 19:42:35.0871 6560 i8042prt - ok 19:42:35.0933 6560 [ 85977CD13FC16069CE0AF7943A811775 ] iaStor C:\windows\system32\DRIVERS\iaStor.sys 19:42:35.0933 6560 iaStor - ok 19:42:35.0964 6560 [ 3DF4395A7CF8B7A72A5F4606366B8C2D ] iaStorV C:\windows\system32\drivers\iaStorV.sys 19:42:35.0980 6560 iaStorV - ok 19:42:36.0027 6560 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 19:42:36.0042 6560 idsvc - ok 19:42:36.0276 6560 [ 898AB5BFED7040D7AB07AF01885EB944 ] igfx C:\windows\system32\DRIVERS\igdkmd64.sys 19:42:36.0479 6560 igfx - ok 19:42:36.0510 6560 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\windows\system32\DRIVERS\iirsp.sys 19:42:36.0510 6560 iirsp - ok 19:42:36.0542 6560 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\windows\System32\ikeext.dll 19:42:36.0542 6560 IKEEXT - ok 19:42:36.0604 6560 [ 4B6363CD4610BB848531BB260B15DFCC ] Impcd C:\windows\system32\DRIVERS\Impcd.sys 19:42:36.0604 6560 Impcd - ok 19:42:36.0635 6560 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\windows\system32\drivers\intelide.sys 19:42:36.0635 6560 intelide - ok 19:42:36.0666 6560 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\windows\system32\DRIVERS\intelppm.sys 19:42:36.0666 6560 intelppm - ok 19:42:36.0698 6560 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\windows\system32\ipbusenum.dll 19:42:36.0713 6560 IPBusEnum - ok 19:42:36.0729 6560 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys 19:42:36.0729 6560 IpFilterDriver - ok 19:42:36.0776 6560 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\windows\System32\iphlpsvc.dll 19:42:36.0791 6560 iphlpsvc - ok 19:42:36.0822 6560 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\windows\system32\drivers\IPMIDrv.sys 19:42:36.0822 6560 IPMIDRV - ok 19:42:36.0854 6560 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\windows\system32\drivers\ipnat.sys 19:42:36.0854 6560 IPNAT - ok 19:42:36.0947 6560 [ 0F261EC4F514926177C70C1832374231 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 19:42:36.0963 6560 iPod Service - ok 19:42:37.0010 6560 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\windows\system32\drivers\irenum.sys 19:42:37.0010 6560 IRENUM - ok 19:42:37.0025 6560 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\windows\system32\drivers\isapnp.sys 19:42:37.0041 6560 isapnp - ok 19:42:37.0072 6560 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\windows\system32\drivers\msiscsi.sys 19:42:37.0072 6560 iScsiPrt - ok 19:42:37.0103 6560 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\windows\system32\drivers\kbdclass.sys 19:42:37.0103 6560 kbdclass - ok 19:42:37.0150 6560 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\windows\system32\drivers\kbdhid.sys 19:42:37.0150 6560 kbdhid - ok 19:42:37.0181 6560 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\windows\system32\lsass.exe 19:42:37.0181 6560 KeyIso - ok 19:42:37.0212 6560 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\windows\system32\Drivers\ksecdd.sys 19:42:37.0228 6560 KSecDD - ok 19:42:37.0244 6560 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\windows\system32\Drivers\ksecpkg.sys 19:42:37.0259 6560 KSecPkg - ok 19:42:37.0275 6560 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\windows\system32\drivers\ksthunk.sys 19:42:37.0275 6560 ksthunk - ok 19:42:37.0322 6560 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\windows\system32\msdtckrm.dll 19:42:37.0322 6560 KtmRm - ok 19:42:37.0353 6560 [ 48686C29856F46443952A831424F8D6F ] L1C C:\windows\system32\DRIVERS\L1C62x64.sys 19:42:37.0368 6560 L1C - ok 19:42:37.0384 6560 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\windows\system32\srvsvc.dll 19:42:37.0400 6560 LanmanServer - ok 19:42:37.0431 6560 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\windows\System32\wkssvc.dll 19:42:37.0431 6560 LanmanWorkstation - ok 19:42:37.0478 6560 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\windows\system32\DRIVERS\lltdio.sys 19:42:37.0478 6560 lltdio - ok 19:42:37.0509 6560 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\windows\System32\lltdsvc.dll 19:42:37.0524 6560 lltdsvc - ok 19:42:37.0524 6560 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\windows\System32\lmhsvc.dll 19:42:37.0540 6560 lmhosts - ok 19:42:37.0618 6560 [ 259E9D38F7CABB068530101F87B6C202 ] LMS C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe 19:42:37.0634 6560 LMS - ok 19:42:37.0665 6560 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\windows\system32\DRIVERS\lsi_fc.sys 19:42:37.0665 6560 LSI_FC - ok 19:42:37.0696 6560 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\windows\system32\DRIVERS\lsi_sas.sys 19:42:37.0696 6560 LSI_SAS - ok 19:42:37.0696 6560 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\windows\system32\DRIVERS\lsi_sas2.sys 19:42:37.0696 6560 LSI_SAS2 - ok 19:42:37.0712 6560 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\windows\system32\DRIVERS\lsi_scsi.sys 19:42:37.0712 6560 LSI_SCSI - ok 19:42:37.0743 6560 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\windows\system32\drivers\luafv.sys 19:42:37.0743 6560 luafv - ok 19:42:37.0774 6560 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\windows\system32\Mcx2Svc.dll 19:42:37.0774 6560 Mcx2Svc - ok 19:42:37.0790 6560 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\windows\system32\DRIVERS\megasas.sys 19:42:37.0790 6560 megasas - ok 19:42:37.0821 6560 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\windows\system32\DRIVERS\MegaSR.sys 19:42:37.0821 6560 MegaSR - ok 19:42:37.0836 6560 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\windows\system32\mmcss.dll 19:42:37.0852 6560 MMCSS - ok 19:42:37.0852 6560 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\windows\system32\drivers\modem.sys 19:42:37.0852 6560 Modem - ok 19:42:37.0883 6560 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\windows\system32\DRIVERS\monitor.sys 19:42:37.0883 6560 monitor - ok 19:42:37.0914 6560 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\windows\system32\drivers\mouclass.sys 19:42:37.0914 6560 mouclass - ok 19:42:37.0930 6560 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\windows\system32\DRIVERS\mouhid.sys 19:42:37.0930 6560 mouhid - ok 19:42:37.0977 6560 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\windows\system32\drivers\mountmgr.sys 19:42:37.0977 6560 mountmgr - ok 19:42:38.0055 6560 [ 8A7C8F4C713E70D73946833D76B77035 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 19:42:38.0055 6560 MozillaMaintenance - ok 19:42:38.0086 6560 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\windows\system32\drivers\mpio.sys 19:42:38.0086 6560 mpio - ok 19:42:38.0133 6560 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys 19:42:38.0133 6560 mpsdrv - ok 19:42:38.0164 6560 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\windows\system32\mpssvc.dll 19:42:38.0180 6560 MpsSvc - ok 19:42:38.0211 6560 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\windows\system32\drivers\mrxdav.sys 19:42:38.0211 6560 MRxDAV - ok 19:42:38.0242 6560 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys 19:42:38.0242 6560 mrxsmb - ok 19:42:38.0258 6560 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys 19:42:38.0258 6560 mrxsmb10 - ok 19:42:38.0289 6560 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys 19:42:38.0289 6560 mrxsmb20 - ok 19:42:38.0320 6560 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\windows\system32\drivers\msahci.sys 19:42:38.0320 6560 msahci - ok 19:42:38.0351 6560 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\windows\system32\drivers\msdsm.sys 19:42:38.0351 6560 msdsm - ok 19:42:38.0367 6560 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\windows\System32\msdtc.exe 19:42:38.0367 6560 MSDTC - ok 19:42:38.0398 6560 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\windows\system32\drivers\Msfs.sys 19:42:38.0414 6560 Msfs - ok 19:42:38.0445 6560 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\windows\System32\drivers\mshidkmdf.sys 19:42:38.0445 6560 mshidkmdf - ok 19:42:38.0476 6560 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\windows\system32\drivers\msisadrv.sys 19:42:38.0476 6560 msisadrv - ok 19:42:38.0492 6560 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\windows\system32\iscsiexe.dll 19:42:38.0492 6560 MSiSCSI - ok 19:42:38.0507 6560 msiserver - ok 19:42:38.0523 6560 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys 19:42:38.0523 6560 MSKSSRV - ok 19:42:38.0538 6560 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys 19:42:38.0538 6560 MSPCLOCK - ok 19:42:38.0538 6560 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\windows\system32\drivers\MSPQM.sys 19:42:38.0538 6560 MSPQM - ok 19:42:39.0006 6560 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\windows\system32\drivers\MsRPC.sys 19:42:39.0038 6560 MsRPC - ok 19:42:39.0100 6560 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\windows\system32\drivers\mssmbios.sys 19:42:39.0100 6560 mssmbios - ok 19:42:39.0131 6560 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\windows\system32\drivers\MSTEE.sys 19:42:39.0131 6560 MSTEE - ok 19:42:39.0147 6560 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\windows\system32\DRIVERS\MTConfig.sys 19:42:39.0147 6560 MTConfig - ok 19:42:39.0162 6560 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\windows\system32\Drivers\mup.sys 19:42:39.0162 6560 Mup - ok 19:42:39.0194 6560 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\windows\system32\qagentRT.dll 19:42:39.0209 6560 napagent - ok 19:42:39.0287 6560 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys 19:42:39.0287 6560 NativeWifiP - ok 19:42:39.0396 6560 [ 934BB0D23A25C8C136570800A5A149B6 ] NAUpdate C:\Program Files (x86)\Nero\Update\NASvc.exe 19:42:39.0396 6560 NAUpdate - ok 19:42:39.0474 6560 [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS C:\windows\system32\drivers\ndis.sys 19:42:39.0490 6560 NDIS - ok 19:42:39.0521 6560 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\windows\system32\DRIVERS\ndiscap.sys 19:42:39.0521 6560 NdisCap - ok 19:42:39.0568 6560 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys 19:42:39.0568 6560 NdisTapi - ok 19:42:39.0615 6560 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys 19:42:39.0615 6560 Ndisuio - ok 19:42:39.0646 6560 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys 19:42:39.0646 6560 NdisWan - ok 19:42:39.0662 6560 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\windows\system32\drivers\NDProxy.sys 19:42:39.0662 6560 NDProxy - ok 19:42:39.0708 6560 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys 19:42:39.0708 6560 NetBIOS - ok 19:42:39.0740 6560 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\windows\system32\DRIVERS\netbt.sys 19:42:39.0755 6560 NetBT - ok 19:42:39.0771 6560 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\windows\system32\lsass.exe 19:42:39.0786 6560 Netlogon - ok 19:42:39.0833 6560 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\windows\System32\netman.dll 19:42:39.0833 6560 Netman - ok 19:42:39.0849 6560 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\windows\System32\netprofm.dll 19:42:39.0849 6560 netprofm - ok 19:42:39.0880 6560 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 19:42:39.0880 6560 NetTcpPortSharing - ok 19:42:39.0911 6560 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\windows\system32\DRIVERS\nfrd960.sys 19:42:39.0911 6560 nfrd960 - ok 19:42:39.0958 6560 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\windows\System32\nlasvc.dll 19:42:39.0974 6560 NlaSvc - ok 19:42:39.0989 6560 Norton PC Checkup Application Launcher - ok 19:42:40.0005 6560 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\windows\system32\drivers\Npfs.sys 19:42:40.0005 6560 Npfs - ok 19:42:40.0036 6560 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\windows\system32\nsisvc.dll 19:42:40.0036 6560 nsi - ok 19:42:40.0052 6560 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\windows\system32\drivers\nsiproxy.sys 19:42:40.0052 6560 nsiproxy - ok 19:42:40.0098 6560 [ 05D78AA5CB5F3F5C31160BDB955D0B7C ] Ntfs C:\windows\system32\drivers\Ntfs.sys 19:42:40.0130 6560 Ntfs - ok 19:42:40.0145 6560 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\windows\system32\drivers\Null.sys 19:42:40.0145 6560 Null - ok 19:42:40.0176 6560 [ 5D9FD91F3D38DC9DA01E3CB5FA89CD48 ] nvraid C:\windows\system32\drivers\nvraid.sys 19:42:40.0176 6560 nvraid - ok 19:42:40.0192 6560 [ F7CD50FE7139F07E77DA8AC8033D1832 ] nvstor C:\windows\system32\drivers\nvstor.sys 19:42:40.0208 6560 nvstor - ok 19:42:40.0239 6560 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\windows\system32\drivers\nv_agp.sys 19:42:40.0239 6560 nv_agp - ok 19:42:40.0348 6560 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 19:42:40.0348 6560 odserv - ok 19:42:40.0379 6560 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\windows\system32\drivers\ohci1394.sys 19:42:40.0379 6560 ohci1394 - ok 19:42:40.0410 6560 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 19:42:40.0410 6560 ose - ok 19:42:40.0442 6560 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\windows\system32\pnrpsvc.dll 19:42:40.0457 6560 p2pimsvc - ok 19:42:40.0488 6560 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\windows\system32\p2psvc.dll 19:42:40.0488 6560 p2psvc - ok 19:42:40.0535 6560 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\windows\system32\DRIVERS\parport.sys 19:42:40.0535 6560 Parport - ok 19:42:40.0566 6560 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\windows\system32\drivers\partmgr.sys 19:42:40.0566 6560 partmgr - ok 19:42:40.0566 6560 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\windows\System32\pcasvc.dll 19:42:40.0582 6560 PcaSvc - ok 19:42:40.0613 6560 [ 2F86BE1818C2D7AC90478E3323EE7FCB ] PCCUJobMgr C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.6.22\ccSvcHst.exe 19:42:40.0613 6560 PCCUJobMgr - ok 19:42:40.0644 6560 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\windows\system32\drivers\pci.sys 19:42:40.0644 6560 pci - ok 19:42:40.0660 6560 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\windows\system32\drivers\pciide.sys 19:42:40.0660 6560 pciide - ok 19:42:40.0707 6560 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\windows\system32\DRIVERS\pcmcia.sys 19:42:40.0707 6560 pcmcia - ok 19:42:40.0707 6560 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\windows\system32\drivers\pcw.sys 19:42:40.0722 6560 pcw - ok 19:42:40.0738 6560 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\windows\system32\drivers\peauth.sys 19:42:40.0738 6560 PEAUTH - ok 19:42:40.0816 6560 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\windows\SysWow64\perfhost.exe 19:42:40.0816 6560 PerfHost - ok 19:42:40.0878 6560 [ 663962900E7FEA522126BA287715BB4A ] PGEffect C:\windows\system32\DRIVERS\pgeffect.sys 19:42:40.0878 6560 PGEffect - ok 19:42:40.0925 6560 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\windows\system32\pla.dll 19:42:40.0956 6560 pla - ok 19:42:41.0003 6560 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\windows\system32\umpnpmgr.dll 19:42:41.0003 6560 PlugPlay - ok 19:42:41.0034 6560 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\windows\system32\pnrpauto.dll 19:42:41.0034 6560 PNRPAutoReg - ok 19:42:41.0050 6560 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\windows\system32\pnrpsvc.dll 19:42:41.0066 6560 PNRPsvc - ok 19:42:41.0097 6560 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\windows\System32\ipsecsvc.dll 19:42:41.0097 6560 PolicyAgent - ok 19:42:41.0144 6560 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\windows\system32\umpo.dll 19:42:41.0144 6560 Power - ok 19:42:41.0159 6560 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\windows\system32\DRIVERS\raspptp.sys 19:42:41.0159 6560 PptpMiniport - ok 19:42:41.0190 6560 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\windows\system32\DRIVERS\processr.sys 19:42:41.0190 6560 Processor - ok 19:42:41.0222 6560 [ 5C78838B4D166D1A27DB3A8A820C799A ] ProfSvc C:\windows\system32\profsvc.dll 19:42:41.0237 6560 ProfSvc - ok 19:42:41.0253 6560 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\windows\system32\lsass.exe 19:42:41.0253 6560 ProtectedStorage - ok 19:42:41.0284 6560 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\windows\system32\DRIVERS\pacer.sys 19:42:41.0284 6560 Psched - ok 19:42:41.0346 6560 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\windows\system32\DRIVERS\ql2300.sys 19:42:41.0362 6560 ql2300 - ok 19:42:41.0393 6560 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\windows\system32\DRIVERS\ql40xx.sys 19:42:41.0393 6560 ql40xx - ok 19:42:41.0424 6560 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\windows\system32\qwave.dll 19:42:41.0424 6560 QWAVE - ok 19:42:41.0424 6560 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\windows\system32\drivers\qwavedrv.sys 19:42:41.0440 6560 QWAVEdrv - ok 19:42:41.0440 6560 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\windows\system32\DRIVERS\rasacd.sys 19:42:41.0440 6560 RasAcd - ok 19:42:41.0487 6560 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\windows\system32\DRIVERS\AgileVpn.sys 19:42:41.0487 6560 RasAgileVpn - ok 19:42:41.0502 6560 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\windows\System32\rasauto.dll 19:42:41.0502 6560 RasAuto - ok 19:42:41.0518 6560 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\windows\system32\DRIVERS\rasl2tp.sys 19:42:41.0534 6560 Rasl2tp - ok 19:42:41.0580 6560 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\windows\System32\rasmans.dll 19:42:41.0580 6560 RasMan - ok 19:42:41.0612 6560 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\windows\system32\DRIVERS\raspppoe.sys 19:42:41.0612 6560 RasPppoe - ok 19:42:41.0627 6560 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\windows\system32\DRIVERS\rassstp.sys 19:42:41.0627 6560 RasSstp - ok 19:42:41.0674 6560 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\windows\system32\DRIVERS\rdbss.sys 19:42:41.0674 6560 rdbss - ok 19:42:41.0690 6560 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\windows\system32\DRIVERS\rdpbus.sys 19:42:41.0690 6560 rdpbus - ok 19:42:41.0721 6560 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\windows\system32\DRIVERS\RDPCDD.sys 19:42:41.0721 6560 RDPCDD - ok 19:42:41.0752 6560 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\windows\system32\drivers\rdpencdd.sys 19:42:41.0752 6560 RDPENCDD - ok 19:42:41.0752 6560 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\windows\system32\drivers\rdprefmp.sys 19:42:41.0752 6560 RDPREFMP - ok 19:42:41.0783 6560 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\windows\system32\drivers\RDPWD.sys 19:42:41.0799 6560 RDPWD - ok 19:42:41.0830 6560 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\windows\system32\drivers\rdyboost.sys 19:42:41.0830 6560 rdyboost - ok 19:42:41.0861 6560 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\windows\System32\mprdim.dll 19:42:41.0861 6560 RemoteAccess - ok 19:42:41.0892 6560 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\windows\system32\regsvc.dll 19:42:41.0892 6560 RemoteRegistry - ok 19:42:41.0908 6560 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\windows\System32\RpcEpMap.dll 19:42:41.0924 6560 RpcEptMapper - ok 19:42:41.0939 6560 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\windows\system32\locator.exe 19:42:41.0939 6560 RpcLocator - ok 19:42:41.0986 6560 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\windows\system32\rpcss.dll 19:42:41.0986 6560 RpcSs - ok 19:42:42.0017 6560 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\windows\system32\DRIVERS\rspndr.sys 19:42:42.0017 6560 rspndr - ok 19:42:42.0080 6560 [ 907C4464381B5EBDFDC60F6C7D0DEDFC ] RSUSBSTOR C:\windows\system32\Drivers\RtsUStor.sys 19:42:42.0080 6560 RSUSBSTOR - ok 19:42:42.0095 6560 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\windows\system32\lsass.exe 19:42:42.0095 6560 SamSs - ok 19:42:42.0111 6560 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\windows\system32\drivers\sbp2port.sys 19:42:42.0126 6560 sbp2port - ok 19:42:42.0142 6560 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\windows\System32\SCardSvr.dll 19:42:42.0158 6560 SCardSvr - ok 19:42:42.0173 6560 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\windows\system32\DRIVERS\scfilter.sys 19:42:42.0173 6560 scfilter - ok 19:42:42.0220 6560 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\windows\system32\schedsvc.dll 19:42:42.0236 6560 Schedule - ok 19:42:42.0251 6560 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\windows\System32\certprop.dll 19:42:42.0251 6560 SCPolicySvc - ok 19:42:42.0282 6560 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\windows\System32\SDRSVC.dll 19:42:42.0298 6560 SDRSVC - ok 19:42:42.0329 6560 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\windows\system32\drivers\secdrv.sys 19:42:42.0329 6560 secdrv - ok 19:42:42.0376 6560 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\windows\system32\seclogon.dll 19:42:42.0376 6560 seclogon - ok 19:42:42.0423 6560 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\windows\System32\sens.dll 19:42:42.0423 6560 SENS - ok 19:42:42.0438 6560 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\windows\system32\sensrsvc.dll 19:42:42.0438 6560 SensrSvc - ok 19:42:42.0470 6560 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\windows\system32\DRIVERS\serenum.sys 19:42:42.0470 6560 Serenum - ok 19:42:42.0501 6560 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\windows\system32\DRIVERS\serial.sys 19:42:42.0501 6560 Serial - ok 19:42:42.0516 6560 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\windows\system32\DRIVERS\sermouse.sys 19:42:42.0516 6560 sermouse - ok 19:42:42.0548 6560 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\windows\system32\sessenv.dll 19:42:42.0563 6560 SessionEnv - ok 19:42:42.0594 6560 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\windows\system32\drivers\sffdisk.sys 19:42:42.0594 6560 sffdisk - ok 19:42:42.0610 6560 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\windows\system32\drivers\sffp_mmc.sys 19:42:42.0610 6560 sffp_mmc - ok 19:42:42.0626 6560 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\windows\system32\drivers\sffp_sd.sys 19:42:42.0626 6560 sffp_sd - ok 19:42:42.0657 6560 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\windows\system32\DRIVERS\sfloppy.sys 19:42:42.0657 6560 sfloppy - ok 19:42:42.0688 6560 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\windows\System32\ipnathlp.dll 19:42:42.0704 6560 SharedAccess - ok 19:42:42.0735 6560 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\windows\System32\shsvcs.dll 19:42:42.0735 6560 ShellHWDetection - ok 19:42:42.0750 6560 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\windows\system32\DRIVERS\SiSRaid2.sys 19:42:42.0750 6560 SiSRaid2 - ok 19:42:42.0750 6560 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\windows\system32\DRIVERS\sisraid4.sys 19:42:42.0750 6560 SiSRaid4 - ok 19:42:42.0969 6560 [ 23E3C83DFF7B09A97B01A85ED8A44478 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe 19:42:43.0000 6560 Skype C2C Service - ok 19:42:43.0062 6560 [ 8C4F0DCC6A5100D48F9B2F950CDD220F ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 19:42:43.0062 6560 SkypeUpdate - ok 19:42:43.0109 6560 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\windows\system32\DRIVERS\smb.sys 19:42:43.0109 6560 Smb - ok 19:42:43.0156 6560 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\windows\System32\snmptrap.exe 19:42:43.0172 6560 SNMPTRAP - ok 19:42:43.0172 6560 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\windows\system32\drivers\spldr.sys 19:42:43.0187 6560 spldr - ok 19:42:43.0218 6560 [ B96C17B5DC1424D56EEA3A99E97428CD ] Spooler C:\windows\System32\spoolsv.exe 19:42:43.0234 6560 Spooler - ok 19:42:43.0343 6560 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\windows\system32\sppsvc.exe 19:42:43.0374 6560 sppsvc - ok 19:42:43.0390 6560 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\windows\system32\sppuinotify.dll 19:42:43.0406 6560 sppuinotify - ok 19:42:43.0421 6560 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\windows\system32\DRIVERS\srv.sys 19:42:43.0421 6560 srv - ok 19:42:43.0452 6560 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\windows\system32\DRIVERS\srv2.sys 19:42:43.0452 6560 srv2 - ok 19:42:43.0484 6560 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\windows\system32\DRIVERS\srvnet.sys 19:42:43.0484 6560 srvnet - ok 19:42:43.0530 6560 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\windows\System32\ssdpsrv.dll 19:42:43.0546 6560 SSDPSRV - ok 19:42:43.0562 6560 [ AD47A64046DDBC23A54D7C5CBC22DB94 ] ssfs0bbc C:\windows\system32\DRIVERS\ssfs0bbc.sys 19:42:43.0562 6560 ssfs0bbc - ok 19:42:43.0577 6560 [ 4F5F30EED40CF4B4BD22F07902133ED7 ] ssidrv C:\windows\system32\DRIVERS\ssidrv.sys 19:42:43.0577 6560 ssidrv - ok 19:42:43.0593 6560 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\windows\system32\sstpsvc.dll 19:42:43.0593 6560 SstpSvc - ok 19:42:43.0624 6560 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\windows\system32\DRIVERS\stexstor.sys 19:42:43.0640 6560 stexstor - ok 19:42:43.0702 6560 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\windows\System32\wiaservc.dll 19:42:43.0718 6560 stisvc - ok 19:42:43.0749 6560 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\windows\system32\drivers\swenum.sys 19:42:43.0749 6560 swenum - ok 19:42:43.0796 6560 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\windows\System32\swprv.dll 19:42:43.0796 6560 swprv - ok 19:42:43.0858 6560 [ 470C47DABA9CA3966F0AB3F835D7D135 ] SynTP C:\windows\system32\DRIVERS\SynTP.sys 19:42:43.0858 6560 SynTP - ok 19:42:43.0920 6560 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\windows\system32\sysmain.dll 19:42:43.0952 6560 SysMain - ok 19:42:43.0983 6560 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\windows\System32\TabSvc.dll 19:42:43.0983 6560 TabletInputService - ok 19:42:44.0014 6560 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\windows\System32\tapisrv.dll 19:42:44.0014 6560 TapiSrv - ok 19:42:44.0045 6560 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\windows\System32\tbssvc.dll 19:42:44.0061 6560 TBS - ok 19:42:44.0170 6560 [ B62A953F2BF3922C8764A29C34A22899 ] Tcpip C:\windows\system32\drivers\tcpip.sys 19:42:44.0201 6560 Tcpip - ok 19:42:44.0248 6560 [ B62A953F2BF3922C8764A29C34A22899 ] TCPIP6 C:\windows\system32\DRIVERS\tcpip.sys 19:42:44.0264 6560 TCPIP6 - ok 19:42:44.0310 6560 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\windows\system32\drivers\tcpipreg.sys 19:42:44.0310 6560 tcpipreg - ok 19:42:44.0357 6560 [ FD542B661BD22FA69CA789AD0AC58C29 ] tdcmdpst C:\windows\system32\DRIVERS\tdcmdpst.sys 19:42:44.0373 6560 tdcmdpst - ok 19:42:44.0404 6560 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\windows\system32\drivers\tdpipe.sys 19:42:44.0404 6560 TDPIPE - ok 19:42:44.0435 6560 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\windows\system32\drivers\tdtcp.sys 19:42:44.0435 6560 TDTCP - ok 19:42:44.0466 6560 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\windows\system32\DRIVERS\tdx.sys 19:42:44.0466 6560 tdx - ok 19:42:44.0498 6560 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\windows\system32\drivers\termdd.sys 19:42:44.0498 6560 TermDD - ok 19:42:44.0544 6560 [ 2E648163254233755035B46DD7B89123 ] TermService C:\windows\System32\termsrv.dll 19:42:44.0544 6560 TermService - ok 19:42:44.0591 6560 [ F0344071948D1A1FA732231785A0664C ] Themes C:\windows\system32\themeservice.dll 19:42:44.0591 6560 Themes - ok 19:42:44.0591 6560 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\windows\system32\mmcss.dll 19:42:44.0607 6560 THREADORDER - ok 19:42:44.0669 6560 [ 28644B0523D64EFF2FC7312A2EE74B0A ] TMachInfo C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe 19:42:44.0669 6560 TMachInfo - ok 19:42:44.0700 6560 [ ED32035BDFECED1AD66D459FD9CC1140 ] TODDSrv C:\windows\system32\TODDSrv.exe 19:42:44.0716 6560 TODDSrv - ok 19:42:44.0794 6560 [ DB9719688C08F42705FEB3F6A0C98B91 ] TosCoSrv C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe 19:42:44.0810 6560 TosCoSrv - ok 19:42:44.0856 6560 [ 74C2FA8C3765EE71A9C22182EC108457 ] TOSHIBA HDD SSD Alert Service C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe 19:42:44.0872 6560 TOSHIBA HDD SSD Alert Service - ok 19:42:44.0903 6560 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\windows\System32\trkwks.dll 19:42:44.0903 6560 TrkWks - ok 19:42:44.0950 6560 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe 19:42:44.0950 6560 TrustedInstaller - ok 19:42:44.0981 6560 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\windows\system32\DRIVERS\tssecsrv.sys 19:42:44.0981 6560 tssecsrv - ok 19:42:45.0059 6560 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\windows\system32\drivers\tsusbflt.sys 19:42:45.0059 6560 TsUsbFlt - ok 19:42:45.0106 6560 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\windows\system32\DRIVERS\tunnel.sys 19:42:45.0106 6560 tunnel - ok 19:42:45.0153 6560 [ 550B567F9364D8F7684C3FB3EA665A72 ] TVALZ C:\windows\system32\DRIVERS\TVALZ_O.SYS 19:42:45.0153 6560 TVALZ - ok 19:42:45.0184 6560 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\windows\system32\DRIVERS\uagp35.sys 19:42:45.0200 6560 uagp35 - ok 19:42:45.0231 6560 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\windows\system32\DRIVERS\udfs.sys 19:42:45.0231 6560 udfs - ok 19:42:45.0262 6560 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\windows\system32\UI0Detect.exe 19:42:45.0262 6560 UI0Detect - ok 19:42:45.0309 6560 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\windows\system32\drivers\uliagpkx.sys 19:42:45.0309 6560 uliagpkx - ok 19:42:45.0324 6560 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\windows\system32\DRIVERS\umbus.sys 19:42:45.0324 6560 umbus - ok 19:42:45.0371 6560 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\windows\system32\DRIVERS\umpass.sys 19:42:45.0371 6560 UmPass - ok 19:42:45.0513 6560 [ 48E114762941941D5821EAAE29D75E9E ] UNS C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe 19:42:45.0544 6560 UNS - ok 19:42:45.0575 6560 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\windows\System32\upnphost.dll 19:42:45.0575 6560 upnphost - ok 19:42:45.0637 6560 [ 43228F8EDD1B0BCDD3145AD246E63D39 ] USBAAPL64 C:\windows\system32\Drivers\usbaapl64.sys 19:42:45.0637 6560 USBAAPL64 - ok 19:42:45.0669 6560 [ 481DFF26B4DCA8F4CBAC1F7DCE1D6829 ] usbccgp C:\windows\system32\DRIVERS\usbccgp.sys 19:42:45.0669 6560 usbccgp - ok 19:42:45.0700 6560 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\windows\system32\drivers\usbcir.sys 19:42:45.0700 6560 usbcir - ok 19:42:45.0731 6560 [ 74EE782B1D9C241EFE425565854C661C ] usbehci C:\windows\system32\drivers\usbehci.sys 19:42:45.0731 6560 usbehci - ok 19:42:45.0747 6560 [ DC96BD9CCB8403251BCF25047573558E ] usbhub C:\windows\system32\DRIVERS\usbhub.sys 19:42:45.0747 6560 usbhub - ok 19:42:45.0778 6560 [ 58E546BBAF87664FC57E0F6081E4F609 ] usbohci C:\windows\system32\drivers\usbohci.sys 19:42:45.0778 6560 usbohci - ok 19:42:45.0809 6560 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\windows\system32\DRIVERS\usbprint.sys 19:42:45.0809 6560 usbprint - ok 19:42:45.0871 6560 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\windows\system32\DRIVERS\usbscan.sys 19:42:45.0871 6560 usbscan - ok 19:42:45.0903 6560 [ D76510CFA0FC09023077F22C2F979D86 ] USBSTOR C:\windows\system32\DRIVERS\USBSTOR.SYS 19:42:45.0903 6560 USBSTOR - ok 19:42:45.0918 6560 [ 81FB2216D3A60D1284455D511797DB3D ] usbuhci C:\windows\system32\drivers\usbuhci.sys 19:42:45.0934 6560 usbuhci - ok 19:42:45.0981 6560 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\windows\System32\Drivers\usbvideo.sys 19:42:45.0981 6560 usbvideo - ok 19:42:46.0012 6560 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\windows\System32\uxsms.dll 19:42:46.0012 6560 UxSms - ok 19:42:46.0027 6560 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\windows\system32\lsass.exe 19:42:46.0043 6560 VaultSvc - ok 19:42:46.0059 6560 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\windows\system32\drivers\vdrvroot.sys 19:42:46.0059 6560 vdrvroot - ok 19:42:46.0105 6560 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\windows\System32\vds.exe 19:42:46.0121 6560 vds - ok 19:42:46.0152 6560 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\windows\system32\DRIVERS\vgapnp.sys 19:42:46.0152 6560 vga - ok 19:42:46.0168 6560 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\windows\System32\drivers\vga.sys 19:42:46.0168 6560 VgaSave - ok 19:42:46.0199 6560 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\windows\system32\drivers\vhdmp.sys 19:42:46.0199 6560 vhdmp - ok 19:42:46.0215 6560 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\windows\system32\drivers\viaide.sys 19:42:46.0215 6560 viaide - ok 19:42:46.0261 6560 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\windows\system32\drivers\volmgr.sys 19:42:46.0261 6560 volmgr - ok 19:42:46.0293 6560 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\windows\system32\drivers\volmgrx.sys 19:42:46.0293 6560 volmgrx - ok 19:42:46.0324 6560 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\windows\system32\drivers\volsnap.sys 19:42:46.0324 6560 volsnap - ok 19:42:46.0355 6560 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\windows\system32\DRIVERS\vsmraid.sys 19:42:46.0355 6560 vsmraid - ok 19:42:46.0417 6560 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\windows\system32\vssvc.exe 19:42:46.0433 6560 VSS - ok 19:42:46.0449 6560 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\windows\system32\DRIVERS\vwifibus.sys 19:42:46.0449 6560 vwifibus - ok 19:42:46.0464 6560 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\windows\system32\DRIVERS\vwififlt.sys 19:42:46.0464 6560 vwififlt - ok 19:42:46.0511 6560 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\windows\system32\w32time.dll 19:42:46.0511 6560 W32Time - ok 19:42:46.0542 6560 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\windows\system32\DRIVERS\wacompen.sys 19:42:46.0542 6560 WacomPen - ok 19:42:46.0589 6560 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\windows\system32\DRIVERS\wanarp.sys 19:42:46.0589 6560 WANARP - ok 19:42:46.0589 6560 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\windows\system32\DRIVERS\wanarp.sys 19:42:46.0589 6560 Wanarpv6 - ok 19:42:46.0667 6560 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\windows\system32\Wat\WatAdminSvc.exe 19:42:46.0683 6560 WatAdminSvc - ok 19:42:46.0745 6560 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\windows\system32\wbengine.exe 19:42:46.0761 6560 wbengine - ok 19:42:46.0792 6560 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\windows\System32\wbiosrvc.dll 19:42:46.0792 6560 WbioSrvc - ok 19:42:46.0823 6560 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\windows\System32\wcncsvc.dll 19:42:46.0839 6560 wcncsvc - ok 19:42:46.0854 6560 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll 19:42:46.0854 6560 WcsPlugInService - ok 19:42:46.0870 6560 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\windows\system32\DRIVERS\wd.sys 19:42:46.0885 6560 Wd - ok 19:42:46.0901 6560 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\windows\system32\drivers\Wdf01000.sys 19:42:46.0917 6560 Wdf01000 - ok 19:42:46.0948 6560 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\windows\system32\wdi.dll 19:42:46.0948 6560 WdiServiceHost - ok 19:42:46.0948 6560 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\windows\system32\wdi.dll 19:42:46.0948 6560 WdiSystemHost - ok 19:42:46.0979 6560 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\windows\System32\webclnt.dll 19:42:46.0995 6560 WebClient - ok 19:42:47.0135 6560 [ 51B4F00A7685F0FE5ECE6B113926E323 ] WebrootSpySweeperService C:\Program Files (x86)\Webroot\WebrootSecurity\SpySweeper.exe 19:42:47.0229 6560 WebrootSpySweeperService - ok 19:42:47.0260 6560 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\windows\system32\wecsvc.dll 19:42:47.0260 6560 Wecsvc - ok 19:42:47.0291 6560 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\windows\System32\wercplsupport.dll 19:42:47.0291 6560 wercplsupport - ok 19:42:47.0322 6560 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\windows\System32\WerSvc.dll 19:42:47.0322 6560 WerSvc - ok 19:42:47.0353 6560 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\windows\system32\DRIVERS\wfplwf.sys 19:42:47.0353 6560 WfpLwf - ok 19:42:47.0369 6560 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\windows\system32\drivers\wimmount.sys 19:42:47.0385 6560 WIMMount - ok 19:42:47.0400 6560 WinDefend - ok 19:42:47.0416 6560 WinHttpAutoProxySvc - ok 19:42:47.0478 6560 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\windows\system32\wbem\WMIsvc.dll 19:42:47.0478 6560 Winmgmt - ok 19:42:47.0556 6560 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\windows\system32\WsmSvc.dll 19:42:47.0587 6560 WinRM - ok 19:42:47.0650 6560 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\windows\system32\DRIVERS\WinUsb.sys 19:42:47.0665 6560 WinUsb - ok 19:42:47.0697 6560 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\windows\System32\wlansvc.dll 19:42:47.0712 6560 Wlansvc - ok 19:42:47.0759 6560 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 19:42:47.0775 6560 wlcrasvc - ok 19:42:47.0868 6560 [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 19:42:47.0915 6560 wlidsvc - ok 19:42:47.0946 6560 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\windows\system32\drivers\wmiacpi.sys 19:42:47.0946 6560 WmiAcpi - ok 19:42:47.0977 6560 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\windows\system32\wbem\WmiApSrv.exe 19:42:47.0977 6560 wmiApSrv - ok 19:42:48.0009 6560 WMPNetworkSvc - ok 19:42:48.0040 6560 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\windows\System32\wpcsvc.dll 19:42:48.0040 6560 WPCSvc - ok 19:42:48.0087 6560 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\windows\system32\wpdbusenum.dll 19:42:48.0087 6560 WPDBusEnum - ok 19:42:48.0133 6560 [ 7B24D0143B4A68433A578E49D1A13EDC ] WRConsumerService C:\Program Files (x86)\Webroot\WebrootSecurity\WRConsumerService.exe 19:42:48.0149 6560 WRConsumerService - ok 19:42:48.0180 6560 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\windows\system32\drivers\ws2ifsl.sys 19:42:48.0180 6560 ws2ifsl - ok 19:42:48.0196 6560 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\windows\System32\wscsvc.dll 19:42:48.0211 6560 wscsvc - ok 19:42:48.0211 6560 WSearch - ok 19:42:48.0305 6560 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\windows\system32\wuaueng.dll 19:42:48.0352 6560 wuauserv - ok 19:42:48.0367 6560 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\windows\system32\drivers\WudfPf.sys 19:42:48.0367 6560 WudfPf - ok 19:42:48.0399 6560 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\windows\system32\DRIVERS\WUDFRd.sys 19:42:48.0399 6560 WUDFRd - ok 19:42:48.0414 6560 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\windows\System32\WUDFSvc.dll 19:42:48.0414 6560 wudfsvc - ok 19:42:48.0445 6560 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\windows\System32\wwansvc.dll 19:42:48.0461 6560 WwanSvc - ok 19:42:48.0477 6560 ================ Scan global =============================== 19:42:48.0492 6560 [ BA0CD8C393E8C9F83354106093832C7B ] C:\windows\system32\basesrv.dll 19:42:48.0523 6560 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\windows\system32\winsrv.dll 19:42:48.0539 6560 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\windows\system32\winsrv.dll 19:42:48.0570 6560 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\windows\system32\sxssrv.dll 19:42:48.0601 6560 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\windows\system32\services.exe 19:42:48.0601 6560 [Global] - ok 19:42:48.0601 6560 ================ Scan MBR ================================== 19:42:48.0617 6560 [ 5B5E648D12FCADC244C1EC30318E1EB9 ] \Device\Harddisk0\DR0 19:42:48.0633 6560 Suspicious mbr (Forged): \Device\Harddisk0\DR0 19:42:48.0679 6560 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected 19:42:48.0679 6560 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0) 19:42:48.0679 6560 ================ Scan VBR ================================== 19:42:48.0695 6560 [ FD50DC78FC4127D5734A385A5E645B42 ] \Device\Harddisk0\DR0\Partition1 19:42:48.0695 6560 \Device\Harddisk0\DR0\Partition1 - ok 19:42:48.0695 6560 ============================================================ 19:42:48.0695 6560 Scan finished 19:42:48.0695 6560 ============================================================ 19:42:48.0726 4872 Detected object count: 1 19:42:48.0726 4872 Actual detected object count: 1 19:42:54.0344 4872 \Device\Harddisk0\DR0\# - copied to quarantine 19:42:54.0360 4872 \Device\Harddisk0\DR0 - copied to quarantine 19:42:54.0422 4872 \Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine 19:42:54.0485 4872 \Device\Harddisk0\DR0\TDLFS\sub.dll - copied to quarantine 19:42:54.0500 4872 \Device\Harddisk0\DR0\TDLFS\subx.dll - copied to quarantine 19:42:54.0609 4872 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine 19:42:54.0625 4872 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine 19:42:54.0641 4872 \Device\Harddisk0\DR0\TDLFS\servers.dat - copied to quarantine 19:42:54.0641 4872 \Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine 19:42:54.0641 4872 \Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine 19:42:54.0641 4872 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine 19:42:54.0656 4872 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine 19:42:54.0656 4872 \Device\Harddisk0\DR0\TDLFS\s - copied to quarantine 19:42:54.0672 4872 \Device\Harddisk0\DR0\TDLFS\ldrm - copied to quarantine 19:42:54.0672 4872 \Device\Harddisk0\DR0\TDLFS\u - copied to quarantine 19:42:54.0734 4872 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - will be cured on reboot 19:42:54.0734 4872 \Device\Harddisk0\DR0 - ok 19:42:54.0984 4872 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - User select action: Cure 19:45:04.0933 4832 Deinitialize success
Hi mikej62,

Refer to the ComboFix User's Guide

  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

In your next post please provide the following:
  • ComboFix.txt
  • How is the computer running, any remaining issues?
Hi mikej62,

Please try and remember to copy and paste your logs into the thread. Attaching them makes it a bit more time consuming because I must download the file before I can view it. :thumbup:

= = = = = = = = = = = = = = = = = = = =

Locate the Java Control Panel
  • Click on the Start button and then click on the Control Panel option.
  • In the Control Panel Search enter "Java Control Panel".
  • Click on the Java icon [external image: Posted Image] to open the Java Control Panel.
Delete Temporary Files through the Java Control Panel
[external image: Posted Image]
  • In the Java Control Panel, under the General tab, click Settings under the Temporary Internet Files section.
    The Temporary Files Settings dialog box appears.
[external image: Posted Image]
  • Click Delete Files on the Temporary Files Settings dialog.
    The Delete Temporary Files dialog box appears.
[external image: Posted Image]
  • Click OK on the Delete Temporary Files dialog.
    Note: This deletes all the Downloaded Applications and Applets from the cache.
  • Click OK on the Temporary Files Settings dialog.
    Note: If you want to delete a specific application and applet from the cache, click on View Application and View Applet options respectively.

- - - - - Next - - - - -

Launch the Command Prompt as an Administrator.
  • Click on the Start menu, then selecting All Programs, and then Accessories.
  • You will now see a shortcut labeled Command Prompt.
  • Right-click on it and select Run as administrator as shown below.

[external image: Posted Image]


When you select Run as administrator a User Account Control prompt will appear asking if you would like to allow the Command Prompt to be able to make changes on your computer.


[external image: Posted Image]


Click on the Yes button and you will now be at the Elevated Command Prompt as shown below.


[external image: Posted Image]

  • Type "ipconfig /flushdns" (without the " marks and be sure to place a space between ipconfig /), hit Enter
  • Close the Command Prompt
Reboot

In your next post please provide the following:
  • Any change with Google redirection issue?
Hi mikej62,
  • Which browsers are you using?
  • Which browsers are experiencing the redirecting?
- - - - - Next - - - - -

Re-run RogueKiller

Right click and select "Run as Administrator"
  • Quit all programs
  • Wait until Prescan has finished …
  • Click on Scan, Do Not Fix Anything at this point.
  • Click the Report button, save the report to your desktop
In your next post please provide the following:
  • Answer to the browser redirection question
  • RogueKiller log
I'm using Firefox. I still get the google redirect on Firefox, but there is no redirect on Chrome right now and it doesn't crash anymore either. Here is the RK log.

ogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : NMohamed [Admin rights]
Mode : Scan – Date : 03/25/2013 14:17:08
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 4 ¤¤¤
[HJPOL] HKLM\[…]\System : DisableRegistryTools (0) -> FOUND
[HJPOL] HKLM\[…]\Wow6432Node\System : DisableRegistryTools (0) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> C:\windows\system32\drivers\etc\hosts



¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: TOSHIBA MK3276GSX +++++
— User —
[MBR] 4a4b60e8fefe6e7f39ed700ce3dcb96c
[BSP] d01a24c4416a6794a0694d1b2f52da28 : Windows Vista MBR Code
Partition table:
0 - [ACTIVE] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 1500 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 3074048 | Size: 287000 Mo
2 - [XXXXXX] NTFS (0x17) [HIDDEN!] Offset (sectors): 590850048 | Size: 16743 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[2]_S_03252013_02d1417.txt >>
RKreport[1]_S_03202013_02d1215.txt ; RKreport[2]_S_03252013_02d1417.txt
Hi mikej62,

Flush the FireFox Cache
  • In Firefox, click Tools
  • select Options
  • select Privacy
  • in the section labeled Private Data click Clear Now
In your next post please provide the following:
  • Any change in the redirections while using FireFox?
I don't see anywhere where it says private data. When I click tools, options, privacy, I don't see anywhere that mentions private data. Just a section for tracking, remember history, and location bar
Hi mikej62,

Try these directions, see if they are better suited to the version of Firefox you might be running.

Flush the FireFox Cache
(these directions are specific to Firefox 19, if you have a different version the exact steps might be slightly different)
  • In Firefox, Options
  • Select Options
  • Select Privacy tab
  • Find the section that reads: You might want to clear your recent history or remove individual cookies
  • Select clear your recent history
  • Click the Details drop-down arrow
  • Make sure a check mark is placed in the following boxes:
    • Cookies
    • Cache
  • Next select the Time Range to Clear drop-down menu
  • Select Everything (this will only delete all the cookies and cache, and will save the other items not selected)
  • Click Clear Now
In your next post please provide the following:
  • Any change in the redirections while using Firefox?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI