This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Recurring rookit/trojan files [Solved]

63 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there,
I need some help removing malware. You guys have helped me in the past, and I'm very grateful.
I have rookit installer/trojan files that reappear after scan and removal by MalwareBytes. Symptoms are a progressively slowing cpu that ultimately blue screens.
Any help would be greatly appreciated.

I have OTL, HijackThis, and DDS logs but when I try to post them, cloudflare says the website is offline.

Here's what I have for Hijack:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:30:39 PM, on 3/29/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Users\mlawre\AppData\Roaming\Zeeqecoc\miytr.exe
C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Distillr\acrotray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Users\mlawre\AppData\Roaming\Zeeqecoc\miytr.exe
C:\Users\mlawre\AppData\Roaming\Zeeqecoc\miytr.exe
C:\Users\mlawre\AppData\Roaming\Zeeqecoc\miytr.exe
C:\Users\mlawre\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll
O2 - BHO: Javaβ„’ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Progra~2\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HPUsageTrackingLEDM] "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [StartNowToolbarHelper] "C:\Program Files (x86)\StartNow Toolbar\ToolbarHelper.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [27005020] C:\Users\mlawre\AppData\Roaming\Zeeqecoc\miytr.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: HP LaserJet Professional M1210 MFP Series Receive Fax Service (HPM1210RcvFaxSrvc) - HP - C:\Program Files\HP\HP LaserJet M1210 MFP Series\ReceiveFaxUtility.exe
O23 - Service: HP SI Service (HPSIService) - Unknown owner - C:\Windows\system32\HPSIsvc.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SpyHunter 4 Service - Enigma Software Group USA, LLC. - C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service for StartNow Toolbar - Unknown owner - C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 12506 bytes
Hi mlawre, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Did you try attaching the logs to your reply?
Hi mlaware,

Please read through the instructions to familarize youself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Link 1or Link 2 to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, before you save it to your desktop, rename Combofix to jgh.exe

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Right click on ComboFix.exe (jgh.exe in your case), click Run as Administrator & follow the prompts.
Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
4. If after running combofix you recieve an message "Illegal operation attempted on a registery key that has been marked for deletion" or similar reboot the computer.

Please post back with
  • combofix log
How is the computer?

Thanks
Hi oldman960, Thanks for your help! I ran the combofix. Then checked for the recurring rookit/trojan files with MalwareBytes, which showed only one infected file. I've attached the CF log. Thanks, Michael
Hi mlawre,

Then checked for the recurring rookit/trojan files with MalwareBytes, which showed only one infected file.

Please do not run any tools or remove items unless instructed. This will only make it more difficult.

Please post the MBAM log from the most recent run. You can find it by opening MBAM and clicking on the Logs tab.

You should be able to copy and paste the logs now, it's easier for me to read. If you can not copy and paste them attaching is fine.

It looks like you may still be infected.

Download the latest version of TDSSKiller from here and save it to your Desktop.



A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.

Please post back with
  • MBAM log
  • TDSSK
Ok oldman960, Sorry about the MBAM. It won't happen again. I was using to buy more time to read/download/run apps. The bluescreens occur within 1-2min after my desktop opens. The MBAM has been allowing me more time to run the download and run the programs. It seems like the longer I have the computer on after cleaning, the shorter I have before crashing. I solved this by using another computer for downloading to the network drive and then transferring. So I ran the tdsskiller (it bluescreened once during the run). After the second run, I was able to click on continue to 'cure'. Upon restarting there were a couple of odd file windows. One was asking to open an app and I cancelled. Another was something about C++?. Here are my logs: Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.03.30.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 mlawre :: MEDIA-PC [administrator] 3/30/2013 3:54:25 PM mbam-log-2013-03-30 (15-54-25).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 214081 Time elapsed: 2 minute(s), 11 second(s) Memory Processes Detected: 1 C:\Windows\svchost.exe (Trojan.Agent) -> 3724 -> Delete on reboot. Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 C:\Windows\svchost.exe (Trojan.Agent) -> Delete on reboot. (end) 18:30:04.0913 4020 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 18:30:05.0397 4020 ============================================================ 18:30:05.0397 4020 Current date / time: 2013/03/30 18:30:05.0397 18:30:05.0397 4020 SystemInfo: 18:30:05.0397 4020 18:30:05.0397 4020 OS Version: 6.1.7601 ServicePack: 1.0 18:30:05.0397 4020 Product type: Workstation 18:30:05.0397 4020 ComputerName: MEDIA-PC 18:30:05.0397 4020 UserName: mlawre 18:30:05.0397 4020 Windows directory: C:\Windows 18:30:05.0397 4020 System windows directory: C:\Windows 18:30:05.0397 4020 Running under WOW64 18:30:05.0397 4020 Processor architecture: Intel x64 18:30:05.0397 4020 Number of processors: 4 18:30:05.0397 4020 Page size: 0x1000 18:30:05.0397 4020 Boot type: Normal boot 18:30:05.0397 4020 ============================================================ 18:30:06.0364 4020 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xFC59, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040 18:30:06.0364 4020 ============================================================ 18:30:06.0364 4020 \Device\Harddisk0\DR0: 18:30:06.0364 4020 MBR partitions: 18:30:06.0364 4020 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 18:30:06.0364 4020 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x3A353000 18:30:06.0364 4020 ============================================================ 18:30:06.0380 4020 C: <-> \Device\Harddisk0\DR0\Partition2 18:30:06.0380 4020 ============================================================ 18:30:06.0380 4020 Initialize success 18:30:06.0380 4020 ============================================================ 18:30:13.0774 2292 ============================================================ 18:30:13.0774 2292 Scan started 18:30:13.0774 2292 Mode: Manual; SigCheck; TDLFS; 18:30:13.0774 2292 ============================================================ 18:30:14.0928 2292 ================ Scan system memory ======================== 18:30:14.0928 2292 System memory - ok 18:30:14.0928 2292 ================ Scan services ============================= 18:30:15.0038 2292 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 18:30:15.0100 2292 1394ohci - ok 18:30:15.0131 2292 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 18:30:15.0147 2292 ACPI - ok 18:30:15.0178 2292 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 18:30:15.0240 2292 AcpiPmi - ok 18:30:15.0287 2292 [ 8B46D5A1D3EF08232C04D0EAFB871FB2 ] Adobe LM Service C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe 18:30:15.0303 2292 Adobe LM Service ( UnsignedFile.Multi.Generic ) - warning 18:30:15.0303 2292 Adobe LM Service - detected UnsignedFile.Multi.Generic (1) 18:30:15.0396 2292 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 18:30:15.0412 2292 AdobeARMservice - ok 18:30:15.0490 2292 [ EA856F4A46320389D1899B2CAA7BF40F ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 18:30:15.0506 2292 AdobeFlashPlayerUpdateSvc - ok 18:30:15.0552 2292 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 18:30:15.0568 2292 adp94xx - ok 18:30:15.0584 2292 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 18:30:15.0599 2292 adpahci - ok 18:30:15.0615 2292 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 18:30:15.0630 2292 adpu320 - ok 18:30:15.0646 2292 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 18:30:15.0771 2292 AeLookupSvc - ok 18:30:15.0818 2292 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 18:30:15.0864 2292 AFD - ok 18:30:15.0896 2292 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 18:30:15.0911 2292 agp440 - ok 18:30:15.0911 2292 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 18:30:15.0974 2292 ALG - ok 18:30:15.0974 2292 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 18:30:15.0989 2292 aliide - ok 18:30:16.0020 2292 [ 54716D9BB43733578A5647E9B121141F ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe 18:30:16.0067 2292 AMD External Events Utility - ok 18:30:16.0083 2292 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 18:30:16.0098 2292 amdide - ok 18:30:16.0130 2292 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 18:30:16.0176 2292 AmdK8 - ok 18:30:16.0301 2292 [ 522A8BD1414CC7517FAEC907F138DB9C ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys 18:30:16.0488 2292 amdkmdag - ok 18:30:16.0520 2292 [ F712C26D40BF3CD2C020BB518E8150B1 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys 18:30:16.0551 2292 amdkmdap - ok 18:30:16.0566 2292 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 18:30:16.0598 2292 AmdPPM - ok 18:30:16.0613 2292 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 18:30:16.0629 2292 amdsata - ok 18:30:16.0644 2292 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 18:30:16.0660 2292 amdsbs - ok 18:30:16.0676 2292 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 18:30:16.0676 2292 amdxata - ok 18:30:16.0707 2292 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 18:30:16.0816 2292 AppID - ok 18:30:16.0847 2292 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 18:30:16.0894 2292 AppIDSvc - ok 18:30:16.0925 2292 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll 18:30:16.0956 2292 Appinfo - ok 18:30:17.0034 2292 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 18:30:17.0034 2292 Apple Mobile Device - ok 18:30:17.0066 2292 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys 18:30:17.0081 2292 arc - ok 18:30:17.0081 2292 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 18:30:17.0097 2292 arcsas - ok 18:30:17.0112 2292 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 18:30:17.0159 2292 AsyncMac - ok 18:30:17.0175 2292 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 18:30:17.0175 2292 atapi - ok 18:30:17.0222 2292 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 18:30:17.0284 2292 AudioEndpointBuilder - ok 18:30:17.0300 2292 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 18:30:17.0331 2292 AudioSrv - ok 18:30:17.0362 2292 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 18:30:17.0409 2292 AxInstSV - ok 18:30:17.0456 2292 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys 18:30:17.0502 2292 b06bdrv - ok 18:30:17.0534 2292 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 18:30:17.0565 2292 b57nd60a - ok 18:30:17.0596 2292 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 18:30:17.0627 2292 BDESVC - ok 18:30:17.0643 2292 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 18:30:17.0690 2292 Beep - ok 18:30:17.0752 2292 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll 18:30:17.0814 2292 BFE - ok 18:30:17.0861 2292 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll 18:30:17.0924 2292 BITS - ok 18:30:17.0939 2292 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 18:30:17.0970 2292 blbdrive - ok 18:30:18.0033 2292 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 18:30:18.0048 2292 Bonjour Service - ok 18:30:18.0080 2292 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 18:30:18.0111 2292 bowser - ok 18:30:18.0111 2292 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 18:30:18.0173 2292 BrFiltLo - ok 18:30:18.0173 2292 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 18:30:18.0189 2292 BrFiltUp - ok 18:30:18.0204 2292 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys 18:30:18.0236 2292 BridgeMP - ok 18:30:18.0267 2292 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 18:30:18.0282 2292 Browser - ok 18:30:18.0298 2292 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 18:30:18.0345 2292 Brserid - ok 18:30:18.0360 2292 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 18:30:18.0376 2292 BrSerWdm - ok 18:30:18.0392 2292 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 18:30:18.0407 2292 BrUsbMdm - ok 18:30:18.0407 2292 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 18:30:18.0423 2292 BrUsbSer - ok 18:30:18.0438 2292 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 18:30:18.0454 2292 BTHMODEM - ok 18:30:18.0485 2292 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 18:30:18.0532 2292 bthserv - ok 18:30:18.0563 2292 catchme - ok 18:30:18.0579 2292 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 18:30:18.0626 2292 cdfs - ok 18:30:18.0657 2292 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\drivers\cdrom.sys 18:30:18.0688 2292 cdrom - ok 18:30:18.0719 2292 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 18:30:18.0782 2292 CertPropSvc - ok 18:30:18.0828 2292 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys 18:30:18.0860 2292 circlass - ok 18:30:18.0875 2292 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 18:30:18.0891 2292 CLFS - ok 18:30:18.0938 2292 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 18:30:18.0938 2292 clr_optimization_v2.0.50727_32 - ok 18:30:18.0969 2292 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 18:30:18.0984 2292 clr_optimization_v2.0.50727_64 - ok 18:30:19.0047 2292 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 18:30:19.0094 2292 clr_optimization_v4.0.30319_32 - ok 18:30:19.0125 2292 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 18:30:19.0140 2292 clr_optimization_v4.0.30319_64 - ok 18:30:19.0156 2292 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 18:30:19.0172 2292 CmBatt - ok 18:30:19.0187 2292 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 18:30:19.0203 2292 cmdide - ok 18:30:19.0234 2292 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 18:30:19.0546 2292 CNG - ok 18:30:19.0577 2292 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 18:30:19.0577 2292 Compbatt - ok 18:30:19.0593 2292 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 18:30:19.0624 2292 CompositeBus - ok 18:30:19.0640 2292 COMSysApp - ok 18:30:19.0655 2292 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 18:30:19.0655 2292 crcdisk - ok 18:30:19.0686 2292 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll 18:30:19.0749 2292 CryptSvc - ok 18:30:19.0764 2292 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 18:30:19.0811 2292 DcomLaunch - ok 18:30:19.0858 2292 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 18:30:19.0889 2292 defragsvc - ok 18:30:19.0920 2292 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 18:30:19.0967 2292 DfsC - ok 18:30:19.0998 2292 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 18:30:20.0061 2292 Dhcp - ok 18:30:20.0061 2292 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 18:30:20.0108 2292 discache - ok 18:30:20.0139 2292 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys 18:30:20.0139 2292 Disk - ok 18:30:20.0170 2292 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 18:30:20.0217 2292 Dnscache - ok 18:30:20.0248 2292 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 18:30:20.0279 2292 dot3svc - ok 18:30:20.0310 2292 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 18:30:20.0342 2292 DPS - ok 18:30:20.0373 2292 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 18:30:20.0388 2292 drmkaud - ok 18:30:20.0435 2292 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 18:30:20.0451 2292 DXGKrnl - ok 18:30:20.0466 2292 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 18:30:20.0513 2292 EapHost - ok 18:30:20.0576 2292 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys 18:30:20.0654 2292 ebdrv - ok 18:30:20.0685 2292 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 18:30:20.0732 2292 EFS - ok 18:30:20.0794 2292 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 18:30:20.0825 2292 ehRecvr - ok 18:30:20.0856 2292 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 18:30:20.0872 2292 ehSched - ok 18:30:20.0903 2292 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 18:30:20.0919 2292 elxstor - ok 18:30:20.0950 2292 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 18:30:20.0966 2292 ErrDev - ok 18:30:20.0981 2292 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 18:30:21.0044 2292 EventSystem - ok 18:30:21.0075 2292 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 18:30:21.0122 2292 exfat - ok 18:30:21.0137 2292 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 18:30:21.0184 2292 fastfat - ok 18:30:21.0262 2292 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 18:30:21.0324 2292 Fax - ok 18:30:21.0324 2292 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys 18:30:21.0356 2292 fdc - ok 18:30:21.0371 2292 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 18:30:21.0402 2292 fdPHost - ok 18:30:21.0402 2292 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 18:30:21.0449 2292 FDResPub - ok 18:30:21.0449 2292 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 18:30:21.0480 2292 FileInfo - ok 18:30:21.0496 2292 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 18:30:21.0543 2292 Filetrace - ok 18:30:21.0543 2292 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 18:30:21.0558 2292 flpydisk - ok 18:30:21.0590 2292 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 18:30:21.0590 2292 FltMgr - ok 18:30:21.0636 2292 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll 18:30:21.0683 2292 FontCache - ok 18:30:21.0730 2292 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 18:30:21.0730 2292 FontCache3.0.0.0 - ok 18:30:21.0746 2292 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 18:30:21.0746 2292 FsDepends - ok 18:30:21.0777 2292 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 18:30:21.0777 2292 Fs_Rec - ok 18:30:21.0824 2292 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 18:30:21.0839 2292 fvevol - ok 18:30:21.0855 2292 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 18:30:21.0870 2292 gagp30kx - ok 18:30:21.0933 2292 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 18:30:21.0933 2292 GEARAspiWDM - ok 18:30:21.0964 2292 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 18:30:22.0026 2292 gpsvc - ok 18:30:22.0104 2292 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 18:30:22.0120 2292 gupdate - ok 18:30:22.0120 2292 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 18:30:22.0136 2292 gupdatem - ok 18:30:22.0182 2292 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe 18:30:22.0182 2292 gusvc - ok 18:30:22.0198 2292 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 18:30:22.0229 2292 hcw85cir - ok 18:30:22.0276 2292 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 18:30:22.0292 2292 HdAudAddService - ok 18:30:22.0323 2292 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 18:30:22.0338 2292 HDAudBus - ok 18:30:22.0370 2292 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 18:30:22.0385 2292 HidBatt - ok 18:30:22.0401 2292 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 18:30:22.0416 2292 HidBth - ok 18:30:22.0432 2292 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 18:30:22.0463 2292 HidIr - ok 18:30:22.0494 2292 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll 18:30:22.0526 2292 hidserv - ok 18:30:22.0572 2292 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 18:30:22.0588 2292 HidUsb - ok 18:30:22.0619 2292 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 18:30:22.0682 2292 hkmsvc - ok 18:30:22.0697 2292 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 18:30:22.0744 2292 HomeGroupListener - ok 18:30:22.0760 2292 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 18:30:22.0760 2292 HomeGroupProvider - ok 18:30:22.0838 2292 [ F90DD89E8A482AC976DD4E1029802E49 ] HP LaserJet Service C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe 18:30:22.0838 2292 HP LaserJet Service ( UnsignedFile.Multi.Generic ) - warning 18:30:22.0838 2292 HP LaserJet Service - detected UnsignedFile.Multi.Generic (1) 18:30:22.0884 2292 [ F8F686D62121549377D9E1CDF6BC3441 ] HPM1210RcvFaxSrvc C:\Program Files\HP\HP LaserJet M1210 MFP Series\ReceiveFaxUtility.exe 18:30:22.0916 2292 HPM1210RcvFaxSrvc - ok 18:30:22.0931 2292 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 18:30:22.0947 2292 HpSAMD - ok 18:30:22.0978 2292 [ 4E9CAE3200A46135DE01CE22BAF832BE ] HPSIService C:\Windows\system32\HPSIsvc.exe 18:30:22.0978 2292 HPSIService - ok 18:30:23.0025 2292 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 18:30:23.0056 2292 HTTP - ok 18:30:23.0072 2292 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 18:30:23.0087 2292 hwpolicy - ok 18:30:23.0118 2292 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 18:30:23.0118 2292 i8042prt - ok 18:30:23.0150 2292 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 18:30:23.0165 2292 iaStorV - ok 18:30:23.0196 2292 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 18:30:23.0228 2292 idsvc - ok 18:30:23.0243 2292 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 18:30:23.0259 2292 iirsp - ok 18:30:23.0290 2292 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 18:30:23.0337 2292 IKEEXT - ok 18:30:23.0337 2292 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 18:30:23.0352 2292 intelide - ok 18:30:23.0384 2292 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 18:30:23.0399 2292 intelppm - ok 18:30:23.0415 2292 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 18:30:23.0446 2292 IPBusEnum - ok 18:30:23.0477 2292 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 18:30:23.0508 2292 IpFilterDriver - ok 18:30:23.0555 2292 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 18:30:23.0602 2292 iphlpsvc - ok 18:30:23.0633 2292 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 18:30:23.0664 2292 IPMIDRV - ok 18:30:23.0680 2292 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 18:30:23.0711 2292 IPNAT - ok 18:30:23.0758 2292 [ B474C756C13960793C7583B766F904C4 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 18:30:23.0789 2292 iPod Service - ok 18:30:23.0805 2292 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 18:30:23.0820 2292 IRENUM - ok 18:30:23.0836 2292 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 18:30:23.0852 2292 isapnp - ok 18:30:23.0867 2292 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 18:30:23.0883 2292 iScsiPrt - ok 18:30:23.0898 2292 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 18:30:23.0914 2292 kbdclass - ok 18:30:23.0945 2292 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 18:30:23.0961 2292 kbdhid - ok 18:30:23.0976 2292 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 18:30:23.0992 2292 KeyIso - ok 18:30:24.0008 2292 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 18:30:24.0023 2292 KSecDD - ok 18:30:24.0054 2292 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 18:30:24.0070 2292 KSecPkg - ok 18:30:24.0070 2292 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 18:30:24.0117 2292 ksthunk - ok 18:30:24.0148 2292 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 18:30:24.0195 2292 KtmRm - ok 18:30:24.0226 2292 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll 18:30:24.0273 2292 LanmanServer - ok 18:30:24.0288 2292 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 18:30:24.0335 2292 LanmanWorkstation - ok 18:30:24.0351 2292 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 18:30:24.0398 2292 lltdio - ok 18:30:24.0429 2292 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 18:30:24.0460 2292 lltdsvc - ok 18:30:24.0476 2292 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 18:30:24.0507 2292 lmhosts - ok 18:30:24.0538 2292 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 18:30:24.0538 2292 LSI_FC - ok 18:30:24.0554 2292 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 18:30:24.0554 2292 LSI_SAS - ok 18:30:24.0569 2292 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 18:30:24.0585 2292 LSI_SAS2 - ok 18:30:24.0600 2292 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 18:30:24.0600 2292 LSI_SCSI - ok 18:30:24.0632 2292 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 18:30:24.0663 2292 luafv - ok 18:30:24.0725 2292 [ 92EB844D90615CB266F84C3202B8786E ] MBAMProtector C:\Windows\system32\drivers\mbam.sys 18:30:24.0725 2292 MBAMProtector - ok 18:30:24.0975 2292 [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe 18:30:24.0990 2292 MBAMScheduler - ok 18:30:25.0022 2292 [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe 18:30:25.0053 2292 MBAMService - ok 18:30:25.0084 2292 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 18:30:25.0100 2292 Mcx2Svc - ok 18:30:25.0100 2292 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 18:30:25.0115 2292 megasas - ok 18:30:25.0131 2292 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 18:30:25.0131 2292 MegaSR - ok 18:30:25.0193 2292 [ 123271BD5237AB991DC5C21FDF8835EB ] Microsoft Office Groove Audit Service C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe 18:30:25.0209 2292 Microsoft Office Groove Audit Service - ok 18:30:25.0224 2292 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 18:30:25.0256 2292 MMCSS - ok 18:30:25.0271 2292 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 18:30:25.0302 2292 Modem - ok 18:30:25.0334 2292 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 18:30:25.0349 2292 monitor - ok 18:30:25.0365 2292 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\drivers\mouclass.sys 18:30:25.0380 2292 mouclass - ok 18:30:25.0412 2292 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 18:30:25.0427 2292 mouhid - ok 18:30:25.0458 2292 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 18:30:25.0458 2292 mountmgr - ok 18:30:25.0505 2292 [ 8A7C8F4C713E70D73946833D76B77035 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 18:30:25.0521 2292 MozillaMaintenance - ok 18:30:25.0536 2292 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 18:30:25.0552 2292 mpio - ok 18:30:25.0552 2292 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 18:30:25.0583 2292 mpsdrv - ok 18:30:25.0646 2292 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll 18:30:25.0677 2292 MpsSvc - ok 18:30:25.0708 2292 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 18:30:25.0739 2292 MRxDAV - ok 18:30:25.0770 2292 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 18:30:25.0786 2292 mrxsmb - ok 18:30:25.0817 2292 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 18:30:25.0848 2292 mrxsmb10 - ok 18:30:25.0880 2292 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 18:30:25.0880 2292 mrxsmb20 - ok 18:30:25.0911 2292 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 18:30:25.0911 2292 msahci - ok 18:30:25.0926 2292 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 18:30:25.0926 2292 msdsm - ok 18:30:25.0942 2292 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 18:30:25.0973 2292 MSDTC - ok 18:30:26.0020 2292 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 18:30:26.0051 2292 Msfs - ok 18:30:26.0067 2292 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 18:30:26.0114 2292 mshidkmdf - ok 18:30:26.0285 2292 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 18:30:26.0285 2292 msisadrv - ok 18:30:26.0426 2292 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 18:30:26.0488 2292 MSiSCSI - ok 18:30:26.0488 2292 msiserver - ok 18:30:26.0566 2292 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 18:30:26.0613 2292 MSKSSRV - ok 18:30:26.0628 2292 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 18:30:26.0660 2292 MSPCLOCK - ok 18:30:26.0691 2292 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 18:30:26.0769 2292 MSPQM - ok 18:30:26.0862 2292 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 18:30:26.0894 2292 MsRPC - ok 18:30:26.0909 2292 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 18:30:26.0925 2292 mssmbios - ok 18:30:26.0956 2292 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 18:30:27.0034 2292 MSTEE - ok 18:30:27.0065 2292 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 18:30:27.0096 2292 MTConfig - ok 18:30:27.0143 2292 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 18:30:27.0159 2292 Mup - ok 18:30:27.0252 2292 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 18:30:27.0315 2292 napagent - ok 18:30:27.0393 2292 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 18:30:27.0440 2292 NativeWifiP - ok 18:30:27.0580 2292 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys 18:30:27.0611 2292 NDIS - ok 18:30:27.0674 2292 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 18:30:27.0736 2292 NdisCap - ok 18:30:27.0767 2292 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 18:30:27.0783 2292 NdisTapi - ok 18:30:27.0845 2292 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 18:30:27.0892 2292 Ndisuio - ok 18:30:27.0954 2292 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 18:30:28.0001 2292 NdisWan - ok 18:30:28.0032 2292 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 18:30:28.0079 2292 NDProxy - ok 18:30:28.0110 2292 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 18:30:28.0157 2292 NetBIOS - ok 18:30:28.0235 2292 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 18:30:28.0282 2292 NetBT - ok 18:30:28.0298 2292 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 18:30:28.0313 2292 Netlogon - ok 18:30:28.0407 2292 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 18:30:28.0469 2292 Netman - ok 18:30:28.0547 2292 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 18:30:28.0610 2292 netprofm - ok 18:30:28.0656 2292 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 18:30:28.0688 2292 NetTcpPortSharing - ok 18:30:28.0750 2292 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 18:30:28.0766 2292 nfrd960 - ok 18:30:28.0844 2292 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll 18:30:28.0875 2292 NlaSvc - ok 18:30:28.0890 2292 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 18:30:28.0922 2292 Npfs - ok 18:30:28.0953 2292 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 18:30:28.0984 2292 nsi - ok 18:30:29.0031 2292 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 18:30:29.0078 2292 nsiproxy - ok 18:30:29.0390 2292 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 18:30:29.0421 2292 Ntfs - ok 18:30:29.0452 2292 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 18:30:29.0514 2292 Null - ok 18:30:29.0561 2292 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 18:30:29.0608 2292 nvraid - ok 18:30:29.0655 2292 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 18:30:29.0670 2292 nvstor - ok 18:30:29.0717 2292 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 18:30:29.0733 2292 nv_agp - ok 18:30:29.0873 2292 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 18:30:29.0920 2292 odserv - ok 18:30:29.0951 2292 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 18:30:29.0982 2292 ohci1394 - ok 18:30:30.0045 2292 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 18:30:30.0076 2292 ose - ok 18:30:30.0185 2292 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 18:30:30.0232 2292 p2pimsvc - ok 18:30:30.0341 2292 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 18:30:30.0372 2292 p2psvc - ok 18:30:30.0450 2292 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys 18:30:30.0450 2292 Parport - ok 18:30:30.0513 2292 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 18:30:30.0528 2292 partmgr - ok 18:30:30.0591 2292 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 18:30:30.0638 2292 PcaSvc - ok 18:30:30.0684 2292 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 18:30:30.0700 2292 pci - ok 18:30:30.0731 2292 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 18:30:30.0747 2292 pciide - ok 18:30:30.0794 2292 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 18:30:30.0825 2292 pcmcia - ok 18:30:30.0856 2292 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 18:30:30.0856 2292 pcw - ok 18:30:30.0965 2292 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 18:30:31.0012 2292 PEAUTH - ok 18:30:31.0761 2292 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 18:30:31.0808 2292 PerfHost - ok 18:30:32.0073 2292 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 18:30:32.0135 2292 pla - ok 18:30:32.0244 2292 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 18:30:32.0307 2292 PlugPlay - ok 18:30:32.0354 2292 PnkBstrA - ok 18:30:32.0432 2292 PnkBstrB - ok 18:30:32.0463 2292 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 18:30:32.0478 2292 PNRPAutoReg - ok 18:30:32.0556 2292 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 18:30:32.0572 2292 PNRPsvc - ok 18:30:32.0666 2292 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 18:30:32.0728 2292 PolicyAgent - ok 18:30:32.0775 2292 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 18:30:32.0837 2292 Power - ok 18:30:32.0900 2292 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 18:30:32.0946 2292 PptpMiniport - ok 18:30:32.0993 2292 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys 18:30:33.0024 2292 Processor - ok 18:30:33.0056 2292 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 18:30:33.0118 2292 ProfSvc - ok 18:30:33.0134 2292 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 18:30:33.0149 2292 ProtectedStorage - ok 18:30:33.0227 2292 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 18:30:33.0290 2292 Psched - ok 18:30:33.0524 2292 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 18:30:33.0555 2292 ql2300 - ok 18:30:33.0570 2292 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 18:30:33.0586 2292 ql40xx - ok 18:30:33.0617 2292 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 18:30:33.0648 2292 QWAVE - ok 18:30:33.0664 2292 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 18:30:33.0695 2292 QWAVEdrv - ok 18:30:33.0711 2292 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 18:30:33.0758 2292 RasAcd - ok 18:30:33.0820 2292 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 18:30:33.0882 2292 RasAgileVpn - ok 18:30:33.0898 2292 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 18:30:33.0960 2292 RasAuto - ok 18:30:34.0038 2292 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 18:30:34.0085 2292 Rasl2tp - ok 18:30:34.0148 2292 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 18:30:34.0194 2292 RasMan - ok 18:30:34.0272 2292 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 18:30:34.0319 2292 RasPppoe - ok 18:30:34.0366 2292 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 18:30:34.0413 2292 RasSstp - ok 18:30:34.0475 2292 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 18:30:34.0522 2292 rdbss - ok 18:30:34.0538 2292 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 18:30:34.0569 2292 rdpbus - ok 18:30:34.0584 2292 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 18:30:34.0631 2292 RDPCDD - ok 18:30:34.0694 2292 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 18:30:34.0756 2292 RDPENCDD - ok 18:30:34.0772 2292 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 18:30:34.0803 2292 RDPREFMP - ok 18:30:34.0850 2292 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 18:30:34.0912 2292 RDPWD - ok 18:30:34.0974 2292 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 18:30:34.0990 2292 rdyboost - ok 18:30:35.0130 2292 [ A0FF419B61AE47E26ADF3BB15DB4F2FE ] RealNetworks Downloader Resolver Service C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe 18:30:35.0146 2292 RealNetworks Downloader Resolver Service - ok 18:30:35.0193 2292 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 18:30:35.0240 2292 RemoteAccess - ok 18:30:35.0302 2292 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 18:30:35.0364 2292 RemoteRegistry - ok 18:30:35.0520 2292 [ 06A49B7BDC36CFBF97DD90804F833369 ] RichVideo C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe 18:30:35.0552 2292 RichVideo - ok 18:30:35.0598 2292 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 18:30:35.0645 2292 RpcEptMapper - ok 18:30:35.0676 2292 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 18:30:35.0708 2292 RpcLocator - ok 18:30:35.0786 2292 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\System32\rpcss.dll 18:30:35.0817 2292 RpcSs - ok 18:30:35.0864 2292 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 18:30:35.0910 2292 rspndr - ok 18:30:35.0957 2292 [ BAEFEE35D27A5440D35092CE10267BEC ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys 18:30:35.0988 2292 RTL8167 - ok 18:30:35.0988 2292 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 18:30:36.0004 2292 SamSs - ok 18:30:36.0098 2292 SASDIFSV - ok 18:30:36.0113 2292 SASKUTIL - ok 18:30:36.0144 2292 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 18:30:36.0144 2292 sbp2port - ok 18:30:36.0176 2292 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 18:30:36.0207 2292 SCardSvr - ok 18:30:36.0254 2292 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 18:30:36.0285 2292 scfilter - ok 18:30:36.0347 2292 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 18:30:36.0394 2292 Schedule - ok 18:30:36.0425 2292 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 18:30:36.0441 2292 SCPolicySvc - ok 18:30:36.0472 2292 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 18:30:36.0503 2292 SDRSVC - ok 18:30:36.0534 2292 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 18:30:36.0581 2292 secdrv - ok 18:30:36.0612 2292 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 18:30:36.0659 2292 seclogon - ok 18:30:36.0675 2292 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll 18:30:36.0706 2292 SENS - ok 18:30:36.0722 2292 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 18:30:36.0753 2292 SensrSvc - ok 18:30:36.0768 2292 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 18:30:36.0784 2292 Serenum - ok 18:30:36.0800 2292 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys 18:30:36.0815 2292 Serial - ok 18:30:36.0831 2292 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 18:30:36.0846 2292 sermouse - ok 18:30:36.0878 2292 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 18:30:36.0909 2292 SessionEnv - ok 18:30:36.0940 2292 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 18:30:36.0971 2292 sffdisk - ok 18:30:36.0971 2292 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 18:30:37.0002 2292 sffp_mmc - ok 18:30:37.0002 2292 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 18:30:37.0018 2292 sffp_sd - ok 18:30:37.0034 2292 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 18:30:37.0049 2292 sfloppy - ok 18:30:37.0096 2292 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll 18:30:37.0127 2292 SharedAccess - ok 18:30:37.0158 2292 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 18:30:37.0190 2292 ShellHWDetection - ok 18:30:37.0205 2292 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 18:30:37.0221 2292 SiSRaid2 - ok 18:30:37.0221 2292 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 18:30:37.0236 2292 SiSRaid4 - ok 18:30:37.0252 2292 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 18:30:37.0283 2292 Smb - ok 18:30:37.0314 2292 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 18:30:37.0346 2292 SNMPTRAP - ok 18:30:37.0361 2292 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 18:30:37.0377 2292 spldr - ok 18:30:37.0408 2292 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 18:30:37.0424 2292 Spooler - ok 18:30:37.0486 2292 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 18:30:37.0595 2292 sppsvc - ok 18:30:37.0595 2292 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 18:30:37.0642 2292 sppuinotify - ok 18:30:37.0736 2292 [ 0D83AF0E8161ADC1ABC9C8EA73A95C27 ] SpyHunter 4 Service C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE 18:30:37.0767 2292 SpyHunter 4 Service - ok 18:30:37.0798 2292 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 18:30:37.0829 2292 srv - ok 18:30:37.0845 2292 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 18:30:37.0876 2292 srv2 - ok 18:30:37.0892 2292 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 18:30:37.0892 2292 srvnet - ok 18:30:37.0923 2292 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 18:30:37.0954 2292 SSDPSRV - ok 18:30:37.0970 2292 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 18:30:38.0001 2292 SstpSvc - ok 18:30:38.0016 2292 Steam Client Service - ok 18:30:38.0032 2292 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 18:30:38.0048 2292 stexstor - ok 18:30:38.0079 2292 [ DECACB6921DED1A38642642685D77DAC ] StillCam C:\Windows\system32\DRIVERS\serscan.sys 18:30:38.0094 2292 StillCam - ok 18:30:38.0126 2292 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 18:30:38.0172 2292 stisvc - ok 18:30:38.0204 2292 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys 18:30:38.0204 2292 swenum - ok 18:30:38.0219 2292 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 18:30:38.0266 2292 swprv - ok 18:30:38.0313 2292 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 18:30:38.0360 2292 SysMain - ok 18:30:38.0391 2292 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 18:30:38.0406 2292 TabletInputService - ok 18:30:38.0453 2292 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 18:30:38.0484 2292 TapiSrv - ok 18:30:38.0516 2292 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 18:30:38.0531 2292 TBS - ok 18:30:38.0672 2292 [ B62A953F2BF3922C8764A29C34A22899 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 18:30:38.0718 2292 Tcpip - ok 18:30:38.0734 2292 [ B62A953F2BF3922C8764A29C34A22899 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 18:30:38.0765 2292 TCPIP6 - ok 18:30:38.0796 2292 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 18:30:38.0828 2292 tcpipreg - ok 18:30:38.0843 2292 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 18:30:38.0859 2292 TDPIPE - ok 18:30:38.0890 2292 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 18:30:38.0890 2292 TDTCP - ok 18:30:38.0921 2292 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 18:30:38.0937 2292 tdx - ok 18:30:38.0968 2292 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys 18:30:38.0984 2292 TermDD - ok 18:30:39.0015 2292 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 18:30:39.0062 2292 TermService - ok 18:30:39.0062 2292 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 18:30:39.0093 2292 Themes - ok 18:30:39.0124 2292 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 18:30:39.0140 2292 THREADORDER - ok 18:30:39.0155 2292 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 18:30:39.0202 2292 TrkWks - ok 18:30:39.0249 2292 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 18:30:39.0280 2292 TrustedInstaller - ok 18:30:39.0311 2292 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 18:30:39.0358 2292 tssecsrv - ok 18:30:39.0405 2292 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 18:30:39.0420 2292 TsUsbFlt - ok 18:30:39.0452 2292 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 18:30:39.0498 2292 tunnel - ok 18:30:39.0514 2292 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 18:30:39.0530 2292 uagp35 - ok 18:30:39.0545 2292 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 18:30:39.0592 2292 udfs - ok 18:30:39.0608 2292 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 18:30:39.0623 2292 UI0Detect - ok 18:30:39.0639 2292 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 18:30:39.0654 2292 uliagpkx - ok 18:30:39.0686 2292 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 18:30:39.0701 2292 umbus - ok 18:30:39.0717 2292 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 18:30:39.0732 2292 UmPass - ok 18:30:39.0748 2292 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 18:30:39.0779 2292 upnphost - ok 18:30:39.0810 2292 [ 43228F8EDD1B0BCDD3145AD246E63D39 ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys 18:30:39.0842 2292 USBAAPL64 - ok 18:30:39.0873 2292 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys 18:30:39.0888 2292 usbaudio - ok 18:30:39.0920 2292 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 18:30:39.0951 2292 usbccgp - ok 18:30:39.0982 2292 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\DRIVERS\usbcir.sys 18:30:39.0998 2292 usbcir - ok 18:30:40.0013 2292 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 18:30:40.0029 2292 usbehci - ok 18:30:40.0060 2292 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 18:30:40.0091 2292 usbhub - ok 18:30:40.0154 2292 [ F9B3054339A71F16430F6585EBC8BE96 ] USBMULCD C:\Windows\system32\drivers\CM10664.sys 18:30:40.0216 2292 USBMULCD - ok 18:30:40.0232 2292 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys 18:30:40.0247 2292 usbohci - ok 18:30:40.0278 2292 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 18:30:40.0294 2292 usbprint - ok 18:30:40.0325 2292 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 18:30:40.0372 2292 USBSTOR - ok 18:30:40.0372 2292 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 18:30:40.0388 2292 usbuhci - ok 18:30:40.0403 2292 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 18:30:40.0450 2292 UxSms - ok 18:30:40.0466 2292 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 18:30:40.0466 2292 VaultSvc - ok 18:30:40.0497 2292 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 18:30:40.0512 2292 vdrvroot - ok 18:30:40.0544 2292 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 18:30:40.0590 2292 vds - ok 18:30:40.0590 2292 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 18:30:40.0606 2292 vga - ok 18:30:40.0637 2292 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 18:30:40.0668 2292 VgaSave - ok 18:30:40.0684 2292 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 18:30:40.0700 2292 vhdmp - ok 18:30:40.0715 2292 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 18:30:40.0731 2292 viaide - ok 18:30:40.0731 2292 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 18:30:40.0746 2292 volmgr - ok 18:30:40.0778 2292 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 18:30:40.0793 2292 volmgrx - ok 18:30:40.0793 2292 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 18:30:40.0809 2292 volsnap - ok 18:30:40.0840 2292 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 18:30:40.0840 2292 vsmraid - ok 18:30:40.0887 2292 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 18:30:40.0949 2292 VSS - ok 18:30:40.0965 2292 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys 18:30:40.0996 2292 vwifibus - ok 18:30:41.0027 2292 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 18:30:41.0074 2292 W32Time - ok 18:30:41.0090 2292 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 18:30:41.0105 2292 WacomPen - ok 18:30:41.0121 2292 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 18:30:41.0152 2292 WANARP - ok 18:30:41.0168 2292 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 18:30:41.0199 2292 Wanarpv6 - ok 18:30:41.0230 2292 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 18:30:41.0277 2292 WatAdminSvc - ok 18:30:41.0386 2292 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 18:30:41.0464 2292 wbengine - ok 18:30:41.0480 2292 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 18:30:41.0495 2292 WbioSrvc - ok 18:30:41.0511 2292 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 18:30:41.0542 2292 wcncsvc - ok 18:30:41.0542 2292 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 18:30:41.0573 2292 WcsPlugInService - ok 18:30:41.0573 2292 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys 18:30:41.0573 2292 Wd - ok 18:30:41.0604 2292 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 18:30:41.0636 2292 Wdf01000 - ok 18:30:41.0651 2292 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 18:30:41.0714 2292 WdiServiceHost - ok 18:30:41.0714 2292 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 18:30:41.0729 2292 WdiSystemHost - ok 18:30:41.0760 2292 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 18:30:41.0776 2292 WebClient - ok 18:30:41.0792 2292 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 18:30:41.0838 2292 Wecsvc - ok 18:30:41.0838 2292 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 18:30:41.0885 2292 wercplsupport - ok 18:30:41.0916 2292 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 18:30:41.0948 2292 WerSvc - ok 18:30:41.0963 2292 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 18:30:41.0994 2292 WfpLwf - ok 18:30:42.0010 2292 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 18:30:42.0010 2292 WIMMount - ok 18:30:42.0026 2292 WinDefend - ok 18:30:42.0026 2292 WinHttpAutoProxySvc - ok 18:30:42.0072 2292 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 18:30:42.0104 2292 Winmgmt - ok 18:30:42.0166 2292 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 18:30:42.0228 2292 WinRM - ok 18:30:42.0275 2292 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 18:30:42.0291 2292 WinUsb - ok 18:30:42.0338 2292 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 18:30:42.0384 2292 Wlansvc - ok 18:30:42.0416 2292 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 18:30:42.0431 2292 WmiAcpi - ok 18:30:42.0447 2292 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 18:30:42.0478 2292 wmiApSrv - ok 18:30:42.0494 2292 WMPNetworkSvc - ok 18:30:42.0509 2292 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 18:30:42.0525 2292 WPCSvc - ok 18:30:42.0556 2292 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 18:30:42.0556 2292 WPDBusEnum - ok 18:30:42.0587 2292 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 18:30:42.0603 2292 ws2ifsl - ok 18:30:42.0650 2292 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll 18:30:42.0665 2292 wscsvc - ok 18:30:42.0696 2292 [ 8D918B1DB190A4D9B1753A66FA8C96E8 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys 18:30:42.0712 2292 WSDPrintDevice - ok 18:30:42.0728 2292 WSearch - ok 18:30:42.0774 2292 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 18:30:42.0852 2292 wuauserv - ok 18:30:42.0884 2292 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 18:30:42.0915 2292 WudfPf - ok 18:30:42.0946 2292 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 18:30:42.0962 2292 WUDFRd - ok 18:30:43.0008 2292 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 18:30:43.0008 2292 wudfsvc - ok 18:30:43.0024 2292 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll 18:30:43.0055 2292 WwanSvc - ok 18:30:43.0071 2292 ================ Scan global =============================== 18:30:43.0086 2292 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 18:30:43.0118 2292 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll 18:30:43.0133 2292 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll 18:30:43.0149 2292 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 18:30:43.0180 2292 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 18:30:43.0180 2292 [Global] - ok 18:30:43.0180 2292 ================ Scan MBR ================================== 18:30:43.0180 2292 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 18:30:43.0180 2292 Suspicious mbr (Forged): \Device\Harddisk0\DR0 18:30:43.0227 2292 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected 18:30:43.0227 2292 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0) 18:30:43.0367 2292 \Device\Harddisk0\DR0 ( TDSS File System ) - warning 18:30:43.0367 2292 \Device\Harddisk0\DR0 - detected TDSS File System (1) 18:30:43.0383 2292 ================ Scan VBR ================================== 18:30:43.0383 2292 [ 826F8C5E7050F935A5087CA192EAFFE8 ] \Device\Harddisk0\DR0\Partition1 18:30:43.0383 2292 \Device\Harddisk0\DR0\Partition1 - ok 18:30:43.0383 2292 [ 5E38478C7B8095BABAFB421981242317 ] \Device\Harddisk0\DR0\Partition2 18:30:43.0398 2292 \Device\Harddisk0\DR0\Partition2 - ok 18:30:43.0398 2292 ============================================================ 18:30:43.0398 2292 Scan finished 18:30:43.0398 2292 ============================================================ 18:30:43.0398 3296 Detected object count: 4 18:30:43.0398 3296 Actual detected object count: 4 18:30:46.0191 3296 Adobe LM Service ( UnsignedFile.Multi.Generic ) - skipped by user 18:30:46.0191 3296 Adobe LM Service ( UnsignedFile.Multi.Generic ) - User select action: Skip 18:30:46.0191 3296 HP LaserJet Service ( UnsignedFile.Multi.Generic ) - skipped by user 18:30:46.0191 3296 HP LaserJet Service ( UnsignedFile.Multi.Generic ) - User select action: Skip 18:30:49.0170 3296 \Device\Harddisk0\DR0\# - copied to quarantine 18:30:49.0170 3296 \Device\Harddisk0\DR0 - copied to quarantine 18:30:49.0233 3296 \Device\Harddisk0\DR0\TDLFS\cmd.dll - copied to quarantine 18:30:49.0233 3296 \Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine 18:30:49.0248 3296 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine 18:30:49.0248 3296 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine 18:30:49.0248 3296 \Device\Harddisk0\DR0\TDLFS\servers.dat - copied to quarantine 18:30:49.0280 3296 \Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine 18:30:49.0280 3296 \Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine 18:30:49.0280 3296 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine 18:30:49.0280 3296 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine 18:30:49.0280 3296 \Device\Harddisk0\DR0\TDLFS\s - copied to quarantine 18:30:49.0280 3296 \Device\Harddisk0\DR0\TDLFS\ldrm - copied to quarantine 18:30:49.0311 3296 \Device\Harddisk0\DR0\TDLFS\u - copied to quarantine 18:30:49.0342 3296 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - will be cured on reboot 18:30:49.0358 3296 \Device\Harddisk0\DR0 - ok 18:30:49.0358 3296 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - User select action: Cure 18:30:49.0358 3296 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user 18:30:49.0358 3296 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip 18:30:54.0069 3488 Deinitialize success Thanks for your help!
Happy Easter Oldman960, The good news is that computer has not shutdown for 10+ minutes. I do notice it is slowing down/working harder. I did task manger to take a peek and see multiple entries of the same processes opend. CTF loader and couple of others? I just ran the CF. Here is my CF log: ComboFix 13-03-31.01 - mlawre 03/31/2013 8:52.4.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4094.2657 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\svchost.exe . . ((((((((((((((((((((((((( Files Created from 2013-02-28 to 2013-03-31 ))))))))))))))))))))))))))))))) . . 2013-03-31 13:57 . 2013-03-31 13:57 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-03-30 23:36 . 2013-03-15 06:28 9311288 β€”-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{081BBC2E-C179-4BE1-AFF7-FB2D04CBB98A}\mpengine.dll 2013-03-30 23:30 . 2013-03-30 23:30 ——– d—–w- C:\TDSSKiller_Quarantine 2013-03-30 17:05 . 2013-03-30 17:21 ——– d—–w- C:\jgh 2013-03-30 16:33 . 2013-03-30 16:33 ——– d—–w- c:\users\mlawre\AppData\Roaming\Vepuvuqe 2013-03-30 02:07 . 2013-03-30 02:07 ——– d—–w- c:\users\mlawre\AppData\Local\Macromedia 2013-03-29 02:59 . 2013-03-29 02:59 16486616 β€”-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2013-03-29 02:02 . 2013-03-29 02:02 ——– d—–w- c:\programdata\dbe 2013-03-29 02:00 . 2013-03-29 02:00 ——– d—–w- c:\windows\Sun 2013-03-28 05:41 . 2013-03-28 05:41 ——– d-sh–w- c:\windows\SysWow64\%APPDATA% 2013-03-28 05:17 . 2013-03-29 03:29 693976 β€”-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-03-26 02:32 . 2013-02-12 04:12 19968 β€”-a-w- c:\windows\system32\drivers\usb8023.sys 2013-03-24 04:57 . 2013-03-24 05:36 ——– d—–w- c:\users\mlawre\AppData\Local\SUPERAntiSpyware.com 2013-03-18 08:01 . 2013-03-18 08:01 ——– d—–w- c:\program files\Microsoft Silverlight 2013-03-18 08:01 . 2013-03-18 08:01 ——– d—–w- c:\program files (x86)\Microsoft Silverlight . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-03-31 02:21 . 2011-12-21 02:13 214520 β€”-a-w- c:\windows\SysWow64\PnkBstrB.exe 2013-03-31 02:21 . 2011-12-21 02:13 214520 β€”-a-w- c:\windows\SysWow64\PnkBstrB.xtr 2013-03-29 03:29 . 2011-08-18 05:57 73432 β€”-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-03-18 08:02 . 2011-11-06 21:16 72013344 β€”-a-w- c:\windows\system32\MRT.exe 2013-02-12 05:45 . 2013-03-18 05:03 135168 β€”-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-02-12 05:45 . 2013-03-18 05:03 308736 β€”-a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-02-12 05:45 . 2013-03-18 05:03 350208 β€”-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-02-12 05:45 . 2013-03-18 05:03 111104 β€”-a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-02-12 04:48 . 2013-03-18 05:03 474112 β€”-a-w- c:\windows\apppatch\AcSpecfc.dll 2013-02-12 04:48 . 2013-03-18 05:03 2176512 β€”-a-w- c:\windows\apppatch\AcGenral.dll 2013-01-17 06:28 . 2011-01-23 02:44 273840 β€”β€”w- c:\windows\system32\MpSigStub.exe 2013-01-13 21:17 . 2013-02-27 09:00 9728 β€”ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-01-13 21:17 . 2013-02-27 09:00 2560 β€”ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-01-13 21:16 . 2013-02-27 09:00 10752 β€”ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-01-13 21:12 . 2013-02-27 09:00 3584 β€”ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-01-13 21:11 . 2013-02-27 09:00 4096 β€”ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-01-13 21:11 . 2013-02-27 09:00 5632 β€”ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-01-13 21:11 . 2013-02-27 09:00 5632 β€”ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-01-13 21:11 . 2013-02-27 09:00 3072 β€”ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll 2013-01-13 21:11 . 2013-02-27 09:00 3072 β€”ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-01-13 20:35 . 2013-02-27 09:00 9728 β€”ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-01-13 20:35 . 2013-02-27 09:00 2560 β€”ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-01-13 20:35 . 2013-02-27 09:00 10752 β€”ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-01-13 20:32 . 2013-02-27 09:00 3584 β€”ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-01-13 20:31 . 2013-02-27 09:00 4096 β€”ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-01-13 20:31 . 2013-02-27 09:00 5632 β€”ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-01-13 20:31 . 2013-02-27 09:00 5632 β€”ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-01-13 20:31 . 2013-02-27 09:00 3072 β€”ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-01-13 20:31 . 2013-02-27 09:00 3072 β€”ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-01-13 20:31 . 2013-02-27 09:00 1247744 β€”-a-w- c:\windows\SysWow64\DWrite.dll 2013-01-13 20:22 . 2013-02-27 09:00 1988096 β€”-a-w- c:\windows\SysWow64\d3d10warp.dll 2013-01-13 20:20 . 2013-02-27 09:00 293376 β€”-a-w- c:\windows\SysWow64\dxgi.dll 2013-01-13 20:09 . 2013-02-27 09:00 249856 β€”-a-w- c:\windows\SysWow64\d3d10_1core.dll 2013-01-13 20:08 . 2013-02-27 09:00 220160 β€”-a-w- c:\windows\SysWow64\d3d10core.dll 2013-01-13 20:08 . 2013-02-27 09:00 1504768 β€”-a-w- c:\windows\SysWow64\d3d11.dll 2013-01-13 19:59 . 2013-02-27 09:00 1643520 β€”-a-w- c:\windows\system32\DWrite.dll 2013-01-13 19:58 . 2013-02-27 09:00 1175552 β€”-a-w- c:\windows\system32\FntCache.dll 2013-01-13 19:54 . 2013-02-27 09:00 604160 β€”-a-w- c:\windows\SysWow64\d3d10level9.dll 2013-01-13 19:53 . 2013-02-27 09:00 207872 β€”-a-w- c:\windows\SysWow64\WindowsCodecsExt.dll 2013-01-13 19:53 . 2013-02-27 09:00 187392 β€”-a-w- c:\windows\SysWow64\UIAnimation.dll 2013-01-13 19:51 . 2013-02-27 09:00 2565120 β€”-a-w- c:\windows\system32\d3d10warp.dll 2013-01-13 19:49 . 2013-02-27 09:00 363008 β€”-a-w- c:\windows\system32\dxgi.dll 2013-01-13 19:48 . 2013-02-27 09:00 161792 β€”-a-w- c:\windows\SysWow64\d3d10_1.dll 2013-01-13 19:46 . 2013-02-27 09:00 1080832 β€”-a-w- c:\windows\SysWow64\d3d10.dll 2013-01-13 19:43 . 2013-02-27 09:00 1230336 β€”-a-w- c:\windows\SysWow64\WindowsCodecs.dll 2013-01-13 19:38 . 2013-02-27 09:00 333312 β€”-a-w- c:\windows\system32\d3d10_1core.dll 2013-01-13 19:38 . 2013-02-27 09:00 1887232 β€”-a-w- c:\windows\system32\d3d11.dll 2013-01-13 19:38 . 2013-02-27 09:00 296960 β€”-a-w- c:\windows\system32\d3d10core.dll 2013-01-13 19:37 . 2013-02-27 09:00 3419136 β€”-a-w- c:\windows\SysWow64\d2d1.dll 2013-01-13 19:25 . 2013-02-27 09:00 245248 β€”-a-w- c:\windows\system32\WindowsCodecsExt.dll 2013-01-13 19:24 . 2013-02-27 09:00 648192 β€”-a-w- c:\windows\system32\d3d10level9.dll 2013-01-13 19:24 . 2013-02-27 09:00 221184 β€”-a-w- c:\windows\system32\UIAnimation.dll 2013-01-13 19:20 . 2013-02-27 09:00 194560 β€”-a-w- c:\windows\system32\d3d10_1.dll 2013-01-13 19:20 . 2013-02-27 09:00 1238528 β€”-a-w- c:\windows\system32\d3d10.dll 2013-01-13 19:15 . 2013-02-27 09:00 1424384 β€”-a-w- c:\windows\system32\WindowsCodecs.dll 2013-01-13 19:10 . 2013-02-27 09:00 3928064 β€”-a-w- c:\windows\system32\d2d1.dll 2013-01-13 19:02 . 2013-02-27 09:00 417792 β€”-a-w- c:\windows\SysWow64\WMPhoto.dll 2013-01-13 18:34 . 2013-02-27 09:00 364544 β€”-a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2013-01-13 18:32 . 2013-02-27 09:00 465920 β€”-a-w- c:\windows\system32\WMPhoto.dll 2013-01-13 18:09 . 2013-02-27 09:00 522752 β€”-a-w- c:\windows\system32\XpsGdiConverter.dll 2013-01-13 17:26 . 2013-02-27 09:00 1158144 β€”-a-w- c:\windows\SysWow64\XpsPrint.dll 2013-01-13 17:05 . 2013-02-27 09:00 1682432 β€”-a-w- c:\windows\system32\XpsPrint.dll 2013-01-05 05:53 . 2013-02-14 02:48 5553512 β€”-a-w- c:\windows\system32\ntoskrnl.exe 2013-01-05 05:00 . 2013-02-14 02:48 3967848 β€”-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-01-05 05:00 . 2013-02-14 02:48 3913064 β€”-a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-01-04 06:11 . 2013-02-27 09:00 2284544 β€”-a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2013-01-04 06:11 . 2013-02-27 09:00 2776576 β€”-a-w- c:\windows\system32\msmpeg2vdec.dll 2013-01-04 05:46 . 2013-02-14 02:48 215040 β€”-a-w- c:\windows\system32\winsrv.dll 2013-01-04 04:51 . 2013-02-14 02:48 5120 β€”-a-w- c:\windows\SysWow64\wow32.dll 2013-01-04 04:43 . 2013-02-14 02:48 44032 β€”-a-w- c:\windows\apppatch\acwow64.dll 2013-01-04 03:26 . 2013-02-14 02:48 3153408 β€”-a-w- c:\windows\system32\win32k.sys 2013-01-04 02:47 . 2013-02-14 02:48 25600 β€”-a-w- c:\windows\SysWow64\setup16.exe 2013-01-04 02:47 . 2013-02-14 02:48 7680 β€”-a-w- c:\windows\SysWow64\instnm.exe 2013-01-04 02:47 . 2013-02-14 02:48 2048 β€”-a-w- c:\windows\SysWow64\user.exe 2013-01-04 02:47 . 2013-02-14 02:48 14336 β€”-a-w- c:\windows\SysWow64\ntvdm64.dll 2013-01-03 06:00 . 2013-02-14 02:48 1913192 β€”-a-w- c:\windows\system32\drivers\tcpip.sys 2013-01-03 06:00 . 2013-02-14 02:48 288088 β€”-a-w- c:\windows\system32\drivers\FWPKCLNT.SYS . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\Steam.exe" [2013-03-26 1631144] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Acrobat Assistant 7.0"="c:\progra~2\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 483328] "HPUsageTrackingLEDM"="c:\program files (x86)\HP\HP UT LEDM\bin\hppusg.exe" [2009-10-15 30264] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-11-29 151952] "TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2012-12-30 295072] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [2011-3-19 25214] Adobe Gamma.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer] @="Service" . R1 SASDIFSV;SASDIFSV;c:\users\mlawre\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV64.SYS [x] R1 SASKUTIL;SASKUTIL;c:\users\mlawre\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL64.SYS [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-09-28 53760] R3 USBMULCD;USB Multi-Channel Audio Device Interface;c:\windows\system32\drivers\CM10664.sys [2009-09-30 1307648] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-01-24 1255736] R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-10-27 203776] S2 HP LaserJet Service;HP LaserJet Service;c:\program files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2009-10-15 136192] S2 HPM1210RcvFaxSrvc;HP LaserJet Professional M1210 MFP Series Receive Fax Service;c:\program files\HP\HP LaserJet M1210 MFP Series\ReceiveFaxUtility.exe [2010-05-11 362296] S2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe [2010-04-30 127800] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344] S2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2012-11-30 38608] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-03-18 04:49 1629648 β€”-a-w- c:\program files (x86)\Google\Chrome\Application\25.0.1364.172\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-03-31 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-28 01:46] . 2013-03-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21 00:56] . 2013-03-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21 00:56] . . β€”β€”β€” X64 Entries ———– . . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService FontCache . β€”β€”- Supplementary Scan β€”β€”- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Convert link target to Adobe PDF - c:\progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert to existing PDF - c:\progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 Trusted Zone: swmed.edu\mail TCP: DhcpNameServer = 192.168.1.254 FF - ProfilePath - c:\users\mlawre\AppData\Roaming\Mozilla\Firefox\Profiles\k29s6jq6.default\ . - - - - ORPHANS REMOVED - - - - . SafeBoot-75382453.sys AddRemove-RealPlayer 16.0 - c:\program files (x86)\real\realplayer\Update\r1puninst.exe . . . β€”β€”β€”β€”β€”β€”β€” LOCKED REGISTRY KEYS β€”β€”β€”β€”β€”β€”β€” . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-03-31 08:59:02 ComboFix-quarantined-files.txt 2013-03-31 13:59 ComboFix2.txt 2013-03-30 20:48 ComboFix3.txt 2013-03-30 17:21 . Pre-Run: 377,299,791,872 bytes free Post-Run: 377,649,000,448 bytes free . - - End Of File - - 65976136314F0DB976B4F1B2D8FEEA3B Thanks, Michael
Hi mlaware,

Reboot the the computer.

Next

Open OTL
  • check the box beside "scan all users"
  • Copy and paste the text in the code box into the window under Custom Scans/Fixes

    "c:\users\mlawre\AppData\Roaming\Vepuvuqe\*.*" /s
    /md5start
    svchost.exe
    services.exe
    /md5stop
  • Click the Quick Scan button.
Please post back with the OTL log.
Hi oldman960,
I rebooted and ran OTL.
Here is the log:
OTL logfile created on: 3/31/2013 4:52:10 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\mlawre\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.71 Gb Available Physical Memory | 67.79% Memory free
8.00 Gb Paging File | 6.57 Gb Available in Paging File | 82.14% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 351.75 Gb Free Space | 75.54% Space Free | Partition Type: NTFS

Computer Name: MEDIA-PC | User Name: mlawre | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Windows\SysWOW64\PnkBstrB.exe ()
PRC - C:\Users\mlawre\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Users\mlawre\AppData\Roaming\Vepuvuqe\manayc.exe (OperA software)
PRC - C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
PRC - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\acrobat_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Distillr\acrotray.exe (Adobe Systems Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files (x86)\Steam\SDL2.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\7366a39c36523a084bc11c230929ff92\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\7ff638de44686eab4afaa8b3c8a9cfca\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-51.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\HP\HP UT LEDM\bin\HPTools.dll ()
MOD - C:\Program Files (x86)\HP\HP UT LEDM\bin\HPToolkit.dll ()
MOD - C:\Program Files (x86)\HP\HP UT LEDM\bin\LEDMXMLObjects.dll ()
MOD - C:\Program Files (x86)\HP\HP UT LEDM\bin\DMBaseObjects.dll ()
MOD - C:\Program Files (x86)\HP\HP UT LEDM\bin\LEDMMapperObjects.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (SpyHunter 4 Service) – C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (HPM1210RcvFaxSrvc) – C:\Program Files\HP\HP LaserJet M1210 MFP Series\ReceiveFaxUtility.exe (HP)
SRV:64bit: - (HPSIService) – C:\Windows\SysNative\HPSIsvc.exe (HP)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (PnkBstrB) – C:\Windows\SysWOW64\PnkBstrB.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (HP LaserJet Service) – C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (USBMULCD) – C:\Windows\SysNative\drivers\CM10664.sys (C-Media Electronics Inc)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 2C 9B FF 4F B5 BA CB 01 [binary data]
IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\..\SearchScopes,DefaultScope = {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}
IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=i…8D-BB0278D58303
IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\..\SearchScopes\{9B97950D-482C-1D79-568F-FC7B9D40C785}: "URL" = http://www.bing.com/search?q={searchTerms}…eferrer:source}
IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2012/12/29 23:38:24 | 000,000,000 | β€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/07 22:20:09 | 000,000,000 | β€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/03/07 22:20:08 | 000,000,000 | β€”D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/07 22:20:09 | 000,000,000 | β€”D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/03/07 22:20:08 | 000,000,000 | β€”D | M]

[2011/10/26 21:35:25 | 000,000,000 | β€”D | M] (No name found) – C:\Users\mlawre\AppData\Roaming\Mozilla\Extensions
[2013/03/22 20:31:59 | 000,000,000 | β€”D | M] (No name found) – C:\Users\mlawre\AppData\Roaming\Mozilla\Firefox\Profiles\k29s6jq6.default\extensions
[2013/03/22 20:31:59 | 000,221,336 | β€”- | M] () (No name found) – C:\Users\mlawre\AppData\Roaming\Mozilla\Firefox\Profiles\k29s6jq6.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
[2013/03/07 22:20:07 | 000,000,000 | β€”D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/03/07 22:20:09 | 000,263,064 | β€”- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2009/10/07 20:33:08 | 001,645,320 | β€”- | M] (Microsoft Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\gdiplus.dll
[2012/12/29 23:38:09 | 000,124,056 | β€”- | M] (RealPlayer) – C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll
[2011/01/13 08:23:36 | 002,078,720 | β€”- | M] (Library Video Company) – C:\Program Files (x86)\mozilla firefox\plugins\npSAFARIMontagePlayer.dll
[2012/09/15 23:26:30 | 000,002,465 | β€”- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013/02/20 17:26:13 | 000,002,086 | β€”- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.152\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.152\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.152\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Javaβ„’ Platform SE 6 U27 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: RealPlayerβ„’ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprpplugin.dll
CHR - plugin: SAFARI Montage Player (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npSAFARIMontagePlayer.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworksβ„’ RealDownloader Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll
CHR - plugin: RealNetworksβ„’ RealDownloader HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
CHR - plugin: RealNetworksβ„’ RealDownloader PepperFlashVideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll
CHR - plugin: RealDownloader Plugin (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\mlawre\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\mlawre\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: RealDownloader = C:\Users\mlawre\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0\
CHR - Extension: Gmail = C:\Users\mlawre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2013/03/31 08:57:29 | 000,000,027 | β€”- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg64.dll (Google Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 7.0] C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [HPUsageTrackingLEDM] C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-1999296799-1591171409-122683792-1001..\Run: [838357232] C:\Users\mlawre\AppData\Roaming\Vepuvuqe\manayc.exe (OperA software)
O4 - HKU\S-1-5-21-1999296799-1591171409-122683792-1001..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to existing PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\..Trusted Domains: swmed.edu ([mail] https in Trusted sites)
O16:64bit: - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Reg Error: Key error.)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C833CAF0-286B-4913-80DC-06F4C9517C6A}: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/03/02 02:52:15 | 000,000,000 | β€”- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/03/31 16:49:48 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/03/31 08:59:04 | 000,000,000 | β€”D | C] – C:\Windows\temp
[2013/03/30 18:30:46 | 000,000,000 | β€”D | C] – C:\TDSSKiller_Quarantine
[2013/03/30 18:24:48 | 002,237,968 | β€”- | C] (Kaspersky Lab ZAO) – C:\Users\mlawre\Desktop\tdsskiller.exe
[2013/03/30 15:37:43 | 000,000,000 | β€”D | C] – C:\jgh3886j
[2013/03/30 12:05:32 | 000,000,000 | β€”D | C] – C:\jgh
[2013/03/30 11:56:05 | 000,518,144 | β€”- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/03/30 11:56:05 | 000,406,528 | β€”- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/03/30 11:56:05 | 000,060,416 | β€”- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/03/30 11:51:45 | 000,000,000 | β€”D | C] – C:\Qoobox
[2013/03/30 11:51:37 | 000,000,000 | β€”D | C] – C:\Windows\erdnt
[2013/03/30 11:36:49 | 005,045,456 | Rβ€” | C] (Swearware) – C:\Users\mlawre\Desktop\jgh.exe
[2013/03/30 11:34:28 | 005,045,447 | Rβ€” | C] (Swearware) – C:\Users\mlawre\Desktop\ComboFix.exe
[2013/03/30 11:33:29 | 000,000,000 | β€”D | C] – C:\Users\mlawre\AppData\Roaming\Vepuvuqe
[2013/03/29 21:07:58 | 000,000,000 | β€”D | C] – C:\Users\mlawre\AppData\Local\Macromedia
[2013/03/29 20:41:59 | 000,688,992 | Rβ€” | C] (Swearware) – C:\Users\mlawre\Desktop\dds.com
[2013/03/29 20:41:56 | 000,388,608 | β€”- | C] (Trend Micro Inc.) – C:\Users\mlawre\Desktop\HiJackThis.exe
[2013/03/29 20:41:52 | 000,602,112 | β€”- | C] (OldTimer Tools) – C:\Users\mlawre\Desktop\OTL.exe
[2013/03/28 21:02:39 | 000,000,000 | β€”D | C] – C:\ProgramData\dbe
[2013/03/28 21:00:35 | 000,000,000 | β€”D | C] – C:\Windows\Sun
[2013/03/28 00:41:41 | 000,000,000 | -HSD | C] – C:\Windows\SysWow64\%APPDATA%
[2013/03/24 22:41:02 | 001,606,848 | β€”- | C] (InstallX, LLC) – C:\Users\mlawre\Desktop\ezcalendar_d144272.exe
[2013/03/23 23:57:03 | 000,000,000 | β€”D | C] – C:\Users\mlawre\AppData\Local\SUPERAntiSpyware.com
[2013/03/18 03:01:58 | 000,000,000 | β€”D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/03/18 03:01:11 | 000,000,000 | β€”D | C] – C:\Program Files\Microsoft Silverlight
[2013/03/18 03:01:11 | 000,000,000 | β€”D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2013/03/07 22:20:07 | 000,000,000 | β€”D | C] – C:\Program Files (x86)\Mozilla Firefox
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/03/31 16:55:39 | 000,726,270 | β€”- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/03/31 16:55:39 | 000,624,162 | β€”- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/03/31 16:55:39 | 000,106,538 | β€”- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/03/31 16:49:55 | 000,000,894 | β€”- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/03/31 16:49:37 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/03/31 16:49:30 | 3220,037,632 | -HS- | M] () – C:\hiberfil.sys
[2013/03/31 09:38:01 | 000,000,898 | β€”- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/03/31 08:57:29 | 000,000,027 | β€”- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/03/31 08:57:00 | 000,000,830 | β€”- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/03/31 08:55:36 | 000,015,136 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/03/31 08:55:36 | 000,015,136 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/03/31 08:50:29 | 005,045,447 | Rβ€” | M] (Swearware) – C:\Users\mlawre\Desktop\ComboFix.exe
[2013/03/30 21:21:20 | 000,214,520 | β€”- | M] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2013/03/30 21:21:20 | 000,214,520 | β€”- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[2013/03/30 18:29:23 | 480,951,731 | β€”- | M] () – C:\Windows\MEMORY.DMP
[2013/03/30 18:24:57 | 002,237,968 | β€”- | M] (Kaspersky Lab ZAO) – C:\Users\mlawre\Desktop\tdsskiller.exe
[2013/03/30 11:51:30 | 005,045,456 | Rβ€” | M] (Swearware) – C:\Users\mlawre\Desktop\jgh.exe
[2013/03/29 20:11:53 | 000,388,608 | β€”- | M] (Trend Micro Inc.) – C:\Users\mlawre\Desktop\HiJackThis.exe
[2013/03/29 20:11:23 | 000,602,112 | β€”- | M] (OldTimer Tools) – C:\Users\mlawre\Desktop\OTL.exe
[2013/03/29 19:57:31 | 000,688,992 | Rβ€” | M] (Swearware) – C:\Users\mlawre\Desktop\dds.com
[2013/03/25 21:16:59 | 001,278,994 | β€”- | M] () – C:\Users\mlawre\Desktop\acspc-036845.pdf
[2013/03/24 22:41:09 | 001,606,848 | β€”- | M] (InstallX, LLC) – C:\Users\mlawre\Desktop\ezcalendar_d144272.exe
[2013/03/24 00:12:39 | 002,250,054 | β€”- | M] () – C:\ProgramData\1.bmp
[2013/03/24 00:12:27 | 000,350,795 | β€”- | M] () – C:\ProgramData\1.jpg
[2013/03/23 18:31:17 | 000,001,133 | β€”- | M] () – C:\Users\mlawre\Desktop\Continue Virtual Families Installation.lnk
[2013/03/23 18:31:14 | 001,220,752 | β€”- | M] () – C:\Users\mlawre\Desktop\Virtual_Families.exe
[2013/03/17 23:51:46 | 000,002,183 | β€”- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/03/11 00:21:12 | 001,997,167 | β€”- | M] () – C:\Users\mlawre\Desktop\Corbett[1].pdf
[2013/03/10 23:10:14 | 000,711,388 | β€”- | M] () – C:\Users\mlawre\Desktop\J_Immunol-2005-Mathews-1248-56[1].pdf
[2013/03/02 02:52:15 | 000,000,000 | β€”- | M] () – C:\autoexec.bat
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/03/30 11:56:05 | 000,256,000 | β€”- | C] () – C:\Windows\PEV.exe
[2013/03/30 11:56:05 | 000,208,896 | β€”- | C] () – C:\Windows\MBR.exe
[2013/03/30 11:56:05 | 000,098,816 | β€”- | C] () – C:\Windows\sed.exe
[2013/03/30 11:56:05 | 000,080,412 | β€”- | C] () – C:\Windows\grep.exe
[2013/03/30 11:56:05 | 000,068,096 | β€”- | C] () – C:\Windows\zip.exe
[2013/03/28 00:17:46 | 000,000,830 | β€”- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/03/25 21:16:58 | 001,278,994 | β€”- | C] () – C:\Users\mlawre\Desktop\acspc-036845.pdf
[2013/03/24 00:12:39 | 002,250,054 | β€”- | C] () – C:\ProgramData\1.bmp
[2013/03/24 00:12:25 | 000,350,795 | β€”- | C] () – C:\ProgramData\1.jpg
[2013/03/23 18:31:17 | 000,001,133 | β€”- | C] () – C:\Users\mlawre\Desktop\Continue Virtual Families Installation.lnk
[2013/03/23 18:31:02 | 001,220,752 | β€”- | C] () – C:\Users\mlawre\Desktop\Virtual_Families.exe
[2013/03/11 00:21:12 | 001,997,167 | β€”- | C] () – C:\Users\mlawre\Desktop\Corbett[1].pdf
[2013/03/10 23:10:14 | 000,711,388 | β€”- | C] () – C:\Users\mlawre\Desktop\J_Immunol-2005-Mathews-1248-56[1].pdf
[2013/03/02 02:52:15 | 000,000,000 | β€”- | C] () – C:\autoexec.bat
[2011/12/25 02:01:37 | 000,012,002 | -HS- | C] () – C:\Users\mlawre\AppData\Local\8451tl30e6p7e54f8xv0dl2461gmp300
[2011/12/25 02:01:37 | 000,012,002 | -HS- | C] () – C:\ProgramData\8451tl30e6p7e54f8xv0dl2461gmp300
[2011/12/20 21:13:36 | 000,214,520 | β€”- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2011/12/20 21:13:14 | 000,075,064 | β€”- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2011/10/16 16:44:45 | 000,000,293 | β€”- | C] () – C:\Windows\game.ini
[2011/08/21 15:47:12 | 000,001,688 | β€”- | C] () – C:\Users\mlawre\.powerschool_gradebook.properties
[2011/08/21 15:27:02 | 000,000,012 | β€”- | C] () – C:\Users\mlawre\.gradebook_userdict.tlx
[2011/03/27 16:23:54 | 000,010,752 | β€”- | C] () – C:\Users\mlawre\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2013/03/30 11:52:04 | 000,000,000 | β€”D | M] – C:\Windows\Installer\{d2758574-d05f-a7aa-fe5d-53f486ad1541}\L
[2013/03/30 11:52:04 | 000,000,000 | β€”D | M] – C:\Windows\Installer\{d2758574-d05f-a7aa-fe5d-53f486ad1541}\U
[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 00:43:10 | 014,172,672 | β€”- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 23:41:00 | 012,873,728 | β€”- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | β€”- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 07:19:02 | 000,606,208 | β€”- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | β€”- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/01/09 22:53:01 | 000,000,000 | β€”D | M] – C:\Users\mlawre\AppData\Roaming\EndNote
[2011/08/27 17:36:09 | 000,000,000 | β€”D | M] – C:\Users\mlawre\AppData\Roaming\Full
[2011/05/06 21:15:31 | 000,000,000 | β€”D | M] – C:\Users\mlawre\AppData\Roaming\GameRanger
[2012/01/17 00:32:24 | 000,000,000 | β€”D | M] – C:\Users\mlawre\AppData\Roaming\Might & Magic Heroes VI
[2011/08/27 17:14:03 | 000,000,000 | β€”D | M] – C:\Users\mlawre\AppData\Roaming\Sammsoft
[2012/04/01 17:27:14 | 000,000,000 | β€”D | M] – C:\Users\mlawre\AppData\Roaming\Tiny Rock
[2013/03/30 11:33:29 | 000,000,000 | β€”D | M] – C:\Users\mlawre\AppData\Roaming\Vepuvuqe
[2013/02/09 17:13:03 | 000,000,000 | β€”D | M] – C:\Users\mlawre\AppData\Roaming\Xirrus

========== Purity Check ==========



========== Custom Scans ==========

< "c:\users\mlawre\AppData\Roaming\Vepuvuqe\*.*" /s >
[2009/07/14 00:08:49 | 000,000,006 | -H– | C] () – C:\Windows\Tasks\SA.DAT
[2009/07/14 00:08:49 | 000,032,594 | β€”- | C] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2012/05/20 19:56:48 | 000,000,894 | β€”- | C] () – C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2012/05/20 19:56:48 | 000,000,898 | β€”- | C] () – C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2013/03/28 00:17:46 | 000,000,830 | β€”- | C] () – C:\Windows\Tasks\Adobe Flash Player Updater.job

< MD5 for: SERVICES.EXE >
[2009/07/13 20:39:37 | 000,328,704 | β€”- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\erdnt\cache64\services.exe
[2009/07/13 20:39:37 | 000,328,704 | β€”- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 20:39:37 | 000,328,704 | β€”- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2012/12/14 17:49:28 | 000,216,424 | β€”- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | β€”- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\erdnt\cache86\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | β€”- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | β€”- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | β€”- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\erdnt\cache64\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | β€”- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | β€”- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< End of report >

Thanks,
Michael
Hi mlaware,

Your system has been infected by one or more Rootkits/Backdoor Trojans.

This may allow hackers to remotely control your computer, steal critical system information and Download and Execute files

More information on Remote Access Trojans can be found here.

I strongly suggest you do the following immediately:
  • From a known clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer until it has been cleaned.



Rerun TDSSK and when presented with this line select delete.

18:30:49.0358 3296 \Device\Harddisk0\DR0 ( TDSS File System )


Next,

You have some old vulnerable java installed.

Click on the Start button > Control Panel

  • click on the Uninstall a program option under the Programs category.
Uninstall the following programs


Javaβ„’ 6 Update 26 (64-bit)
Javaβ„’ 6 Update 27


You can get the newest versions of Java from HERE.

Accept the licencing agreement amd scroll down to the bottom of the list. The files you want are jre-7u17-windows-i586.exe and jre-7u17-windows-x64.exe

Download them to your desktop. Right click and run as Adminstrator to install them. Decline any other install that may be offered.

Next

Right click on OTL.exe and chose Run as Administrator to run it
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
C:\Windows\Installer\{d2758574-d05f-a7aa-fe5d-53f486ad1541}\L
C:\Windows\Installer\{d2758574-d05f-a7aa-fe5d-53f486ad1541}\U
C:\Windows\Installer\{d2758574-d05f-a7aa-fe5d-53f486ad1541}

:Commands
[purity]
[emptytemp]
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the fix OTL log.

Next

Let's see if it damaged any services.

Please download Farbar Service Scanner and save it to your desktop.
  • Right click FSS.exe and click "Run as Administrator" to run it.
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.

Please post back with
  • OTL fix log
  • FSS log
Hi oldman960, Here are the logs for OTL and FSS: All processes killed ========== SERVICES/DRIVERS ========== ========== FILES ========== C:\Windows\Installer\{d2758574-d05f-a7aa-fe5d-53f486ad1541}\L folder moved successfully. C:\Windows\Installer\{d2758574-d05f-a7aa-fe5d-53f486ad1541}\U folder moved successfully. C:\Windows\Installer\{d2758574-d05f-a7aa-fe5d-53f486ad1541} folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: mlawre ->Temp folder emptied: 126177 bytes ->Temporary Internet Files folder emptied: 724099033 bytes ->Java cache emptied: 18661671 bytes ->FireFox cache emptied: 81045696 bytes ->Google Chrome cache emptied: 8086901 bytes ->Flash cache emptied: 9712 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 188145 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1686 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67563 bytes %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 666 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 794.00 mb Restore point Set: OTL Restore Point OTL by OldTimer - Version 3.2.69.0 log created on 03312013_183008 Files\Folders moved on Reboot… C:\Users\mlawre\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YRA5RUUT\ads[1].htm moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YN4JJXWM\ads[2].htm moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YN4JJXWM\zrt_lookup[1].html moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\62CEBZ6O\ads[3].htm moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\62CEBZ6O\iframe[1].html moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\62CEBZ6O\index[1].htm moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\62CEBZ6O\takeover[1].htm moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully. PendingFileRenameOperations files… Registry entries deleted on Reboot… Farbar Service Scanner Version: 03-03-2013 Ran by [removed] (administrator) on 31-03-2013 at 18:48:14 Running from "C:\Users\mlawre\Desktop" Windows 7 Home Premium Service Pack 1 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo IP is accessible. Yahoo.com is accessible. Other Services: ============== File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys => MD5 is legit C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit **** End of log **** Thanks, Michael
Hi mlawre,

Looks go so far. Any problems?

One more to check for stragglers.


As a Vista/Win7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
  • Do not use this instance of your browser for anything besides doing this scan
  • When the scan is complete and the results saved, close that instance of your browser
  • Open a new one the usual way and post the results in this topic.


*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.
Thanks oldman960, The ESET scan took a while. Here is the log: C:\Qoobox\Quarantine\C\ProgramData\Microsoft\Windows\DRM\A00C.tmp.vir Win64/Olmarik.AY trojan C:\Qoobox\Quarantine\C\ProgramData\Microsoft\Windows\DRM\A00D.tmp.vir Win64/Olmarik.AY trojan C:\Qoobox\Quarantine\C\Windows\Installer\{d2758574-d05f-a7aa-fe5d-53f486ad1541}\U\00000004.@.vir Win64/Conedex.C trojan C:\Qoobox\Quarantine\C\Windows\Installer\{d2758574-d05f-a7aa-fe5d-53f486ad1541}\U\80000000.@.vir Win64/Sirefef.AW trojan C:\Qoobox\Quarantine\C\Windows\Installer\{d2758574-d05f-a7aa-fe5d-53f486ad1541}\U\80000064.@.vir a variant of Win64/Sirefef.AN trojan C:\Qoobox\Quarantine\C\Windows\System32\services.exe.vir Win64/Patched.A.Gen trojan C:\TDSSKiller_Quarantine\30.03.2013_18.30.05\mbr0000\tdlfs0000\tsk0000.dta Win32/Olmarik.AYI trojan C:\TDSSKiller_Quarantine\30.03.2013_18.30.05\mbr0000\tdlfs0000\tsk0001.dta Win64/Olmarik.AM trojan C:\TDSSKiller_Quarantine\30.03.2013_18.30.05\mbr0000\tdlfs0000\tsk0002.dta a variant of Win32/Rootkit.Kryptik.TJ trojan C:\TDSSKiller_Quarantine\30.03.2013_18.30.05\mbr0000\tdlfs0000\tsk0003.dta Win64/Olmarik.AN trojan C:\TDSSKiller_Quarantine\30.03.2013_18.30.05\mbr0000\tdlfs0000\tsk0007.dta Win32/Olmarik.AFK trojan C:\TDSSKiller_Quarantine\30.03.2013_18.30.05\mbr0000\tdlfs0000\tsk0008.dta Win64/Olmarik.AK trojan C:\TDSSKiller_Quarantine\31.03.2013_18.03.17\tdlfs0000\tsk0000.dta Win32/Olmarik.AYI trojan C:\TDSSKiller_Quarantine\31.03.2013_18.03.17\tdlfs0000\tsk0001.dta Win64/Olmarik.AM trojan C:\TDSSKiller_Quarantine\31.03.2013_18.03.17\tdlfs0000\tsk0002.dta a variant of Win32/Rootkit.Kryptik.TJ trojan C:\TDSSKiller_Quarantine\31.03.2013_18.03.17\tdlfs0000\tsk0003.dta Win64/Olmarik.AN trojan C:\TDSSKiller_Quarantine\31.03.2013_18.03.17\tdlfs0000\tsk0007.dta Win32/Olmarik.AFK trojan C:\TDSSKiller_Quarantine\31.03.2013_18.03.17\tdlfs0000\tsk0008.dta Win64/Olmarik.AK trojan C:\Users\mlawre\Desktop\ezcalendar_d144272.exe probably a variant of Win32/InstallIQ application C:\Users\mlawre\Desktop\Virtual_Families.exe a variant of Win32/InstallCore.AZ application C:\Users\mlawre\Desktop\Studio\cnet2_3dmuse_Generator_setup_exe.exe a variant of Win32/InstallCore.D application C:\Users\mlawre\Desktop\Studio\cnet2_artoonix_1_11_full_setup_exe.exe a variant of Win32/InstallCore.D application C:\Users\mlawre\Desktop\Studio\cnet2_effectbox_zip.exe a variant of Win32/InstallCore.D application C:\Users\mlawre\Desktop\Studio\cnet2_FlipBoomClassic-win-trial_zip.exe a variant of Win32/InstallCore.D application C:\Users\mlawre\Desktop\Studio\cnet2_photoanim_install_v10_exe.exe a variant of Win32/InstallCore.D application C:\Users\mlawre\Desktop\Studio\cnet2_video-to-gif_exe.exe a variant of Win32/InstallCore.D application C:\Users\mlawre\Desktop\Studio\freefileviewer_2_1283.exe a variant of Win32/InstallIQ application C:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\60539d66-728eb768 multiple threats C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\60539d66-728eb768 multiple threats Operating memory a variant of Win32/Spy.Zbot.ABA trojan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI