This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Recurring rookit/trojan files [Solved]

63 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi mlaware,

Sorry I meant to ask for the TDSSK log from the last run also. Please include it in your next reply.

Half the detections are files we have quarantined and the other half is just a warning of the cnet downloader.

We'll clear up a couple of them now, thew quarantined items will be removed when we remove the tools.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
C:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\60539d66-728eb768 
C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\60539d66-728eb768
C:\Users\mlawre\AppData\Local\8451tl30e6p7e54f8xv0dl2461gmp300
C:\ProgramData\8451tl30e6p7e54f8xv0dl2461gmp300

:Commands
[purity]
[emptytemp]
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log .

Next

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with
  • TDSK log
  • OTL log
  • MBAM log
Everything ok?
Hey Oldman960, I'm still here. Thanks for your reply. Symptoms of my computer are progressively slowing cpu until overheat crash. I learned that if I close spontaneous activity of multiple *32 processes that use of memory I can prolong computer use. The name comes in random name/letters and the description is the same as the file name. For example, last time it was "tapliofhea.exe" described as tapliofhea. There were up to 8 instances at once some taking up to 600K. I ran OTL and MBAM. Here are my logs: 18:22:26.0960 6944 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 18:22:27.0500 6944 ============================================================ 18:22:27.0500 6944 Current date / time: 2013/03/31 18:22:27.0500 18:22:27.0500 6944 SystemInfo: 18:22:27.0500 6944 18:22:27.0500 6944 OS Version: 6.1.7601 ServicePack: 1.0 18:22:27.0500 6944 Product type: Workstation 18:22:27.0500 6944 ComputerName: MEDIA-PC 18:22:27.0500 6944 UserName: mlawre 18:22:27.0500 6944 Windows directory: C:\Windows 18:22:27.0500 6944 System windows directory: C:\Windows 18:22:27.0500 6944 Running under WOW64 18:22:27.0500 6944 Processor architecture: Intel x64 18:22:27.0500 6944 Number of processors: 4 18:22:27.0500 6944 Page size: 0x1000 18:22:27.0500 6944 Boot type: Normal boot 18:22:27.0500 6944 ============================================================ 18:22:29.0560 6944 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xFC59, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040 18:22:29.0560 6944 ============================================================ 18:22:29.0560 6944 \Device\Harddisk0\DR0: 18:22:29.0560 6944 MBR partitions: 18:22:29.0560 6944 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 18:22:29.0560 6944 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x3A353000 18:22:29.0560 6944 ============================================================ 18:22:29.0650 6944 C: <-> \Device\Harddisk0\DR0\Partition2 18:22:29.0650 6944 ============================================================ 18:22:29.0650 6944 Initialize success 18:22:29.0650 6944 ============================================================ 18:22:39.0417 6408 ============================================================ 18:22:39.0417 6408 Scan started 18:22:39.0417 6408 Mode: Manual; SigCheck; TDLFS; 18:22:39.0417 6408 ============================================================ 18:22:43.0087 6408 ================ Scan system memory ======================== 18:22:43.0087 6408 System memory - ok 18:22:43.0087 6408 ================ Scan services ============================= 18:22:43.0687 6408 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 18:22:43.0777 6408 1394ohci - ok 18:22:43.0817 6408 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 18:22:43.0827 6408 ACPI - ok 18:22:43.0867 6408 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 18:22:43.0927 6408 AcpiPmi - ok 18:22:43.0987 6408 [ 8B46D5A1D3EF08232C04D0EAFB871FB2 ] Adobe LM Service C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe 18:22:43.0997 6408 Adobe LM Service ( UnsignedFile.Multi.Generic ) - warning 18:22:43.0997 6408 Adobe LM Service - detected UnsignedFile.Multi.Generic (1) 18:22:44.0087 6408 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 18:22:44.0097 6408 AdobeARMservice - ok 18:22:44.0417 6408 [ EA856F4A46320389D1899B2CAA7BF40F ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 18:22:44.0437 6408 AdobeFlashPlayerUpdateSvc - ok 18:22:44.0517 6408 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 18:22:44.0537 6408 adp94xx - ok 18:22:44.0567 6408 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 18:22:44.0577 6408 adpahci - ok 18:22:44.0597 6408 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 18:22:44.0607 6408 adpu320 - ok 18:22:44.0627 6408 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 18:22:44.0747 6408 AeLookupSvc - ok 18:22:44.0797 6408 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 18:22:44.0837 6408 AFD - ok 18:22:44.0877 6408 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 18:22:44.0887 6408 agp440 - ok 18:22:44.0917 6408 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 18:22:44.0977 6408 ALG - ok 18:22:44.0987 6408 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 18:22:44.0997 6408 aliide - ok 18:22:45.0037 6408 [ 54716D9BB43733578A5647E9B121141F ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe 18:22:45.0097 6408 AMD External Events Utility - ok 18:22:45.0107 6408 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 18:22:45.0107 6408 amdide - ok 18:22:45.0137 6408 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 18:22:45.0187 6408 AmdK8 - ok 18:22:45.0397 6408 [ 522A8BD1414CC7517FAEC907F138DB9C ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys 18:22:45.0597 6408 amdkmdag - ok 18:22:45.0627 6408 [ F712C26D40BF3CD2C020BB518E8150B1 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys 18:22:45.0667 6408 amdkmdap - ok 18:22:45.0697 6408 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 18:22:45.0727 6408 AmdPPM - ok 18:22:45.0767 6408 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 18:22:45.0777 6408 amdsata - ok 18:22:45.0817 6408 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 18:22:45.0837 6408 amdsbs - ok 18:22:45.0847 6408 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 18:22:45.0857 6408 amdxata - ok 18:22:45.0887 6408 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 18:22:46.0017 6408 AppID - ok 18:22:46.0037 6408 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 18:22:46.0087 6408 AppIDSvc - ok 18:22:46.0127 6408 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll 18:22:46.0167 6408 Appinfo - ok 18:22:46.0247 6408 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 18:22:46.0267 6408 Apple Mobile Device - ok 18:22:46.0317 6408 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys 18:22:46.0327 6408 arc - ok 18:22:46.0357 6408 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 18:22:46.0387 6408 arcsas - ok 18:22:46.0437 6408 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 18:22:46.0467 6408 AsyncMac - ok 18:22:46.0497 6408 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 18:22:46.0507 6408 atapi - ok 18:22:46.0547 6408 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 18:22:46.0617 6408 AudioEndpointBuilder - ok 18:22:46.0627 6408 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 18:22:46.0667 6408 AudioSrv - ok 18:22:46.0717 6408 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 18:22:46.0767 6408 AxInstSV - ok 18:22:46.0797 6408 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys 18:22:46.0837 6408 b06bdrv - ok 18:22:46.0867 6408 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 18:22:46.0907 6408 b57nd60a - ok 18:22:46.0937 6408 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 18:22:46.0977 6408 BDESVC - ok 18:22:47.0007 6408 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 18:22:47.0067 6408 Beep - ok 18:22:47.0117 6408 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll 18:22:47.0187 6408 BFE - ok 18:22:47.0317 6408 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll 18:22:47.0377 6408 BITS - ok 18:22:47.0407 6408 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 18:22:47.0437 6408 blbdrive - ok 18:22:47.0537 6408 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 18:22:47.0577 6408 Bonjour Service - ok 18:22:47.0627 6408 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 18:22:47.0647 6408 bowser - ok 18:22:47.0677 6408 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 18:22:47.0737 6408 BrFiltLo - ok 18:22:47.0767 6408 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 18:22:47.0777 6408 BrFiltUp - ok 18:22:47.0807 6408 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys 18:22:47.0867 6408 BridgeMP - ok 18:22:47.0937 6408 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 18:22:47.0987 6408 Browser - ok 18:22:48.0007 6408 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 18:22:48.0048 6408 Brserid - ok 18:22:48.0058 6408 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 18:22:48.0088 6408 BrSerWdm - ok 18:22:48.0128 6408 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 18:22:48.0148 6408 BrUsbMdm - ok 18:22:48.0188 6408 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 18:22:48.0208 6408 BrUsbSer - ok 18:22:48.0228 6408 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 18:22:48.0258 6408 BTHMODEM - ok 18:22:48.0298 6408 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 18:22:48.0368 6408 bthserv - ok 18:22:48.0408 6408 catchme - ok 18:22:48.0418 6408 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 18:22:48.0468 6408 cdfs - ok 18:22:48.0538 6408 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\drivers\cdrom.sys 18:22:48.0598 6408 cdrom - ok 18:22:48.0668 6408 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 18:22:48.0778 6408 CertPropSvc - ok 18:22:48.0828 6408 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys 18:22:48.0848 6408 circlass - ok 18:22:48.0878 6408 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 18:22:48.0898 6408 CLFS - ok 18:22:48.0938 6408 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 18:22:48.0948 6408 clr_optimization_v2.0.50727_32 - ok 18:22:49.0008 6408 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 18:22:49.0028 6408 clr_optimization_v2.0.50727_64 - ok 18:22:49.0088 6408 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 18:22:49.0108 6408 clr_optimization_v4.0.30319_32 - ok 18:22:49.0148 6408 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 18:22:49.0158 6408 clr_optimization_v4.0.30319_64 - ok 18:22:49.0188 6408 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 18:22:49.0208 6408 CmBatt - ok 18:22:49.0218 6408 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 18:22:49.0228 6408 cmdide - ok 18:22:49.0338 6408 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 18:22:49.0378 6408 CNG - ok 18:22:49.0398 6408 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 18:22:49.0408 6408 Compbatt - ok 18:22:49.0458 6408 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 18:22:49.0488 6408 CompositeBus - ok 18:22:49.0508 6408 COMSysApp - ok 18:22:49.0518 6408 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 18:22:49.0528 6408 crcdisk - ok 18:22:49.0568 6408 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll 18:22:49.0618 6408 CryptSvc - ok 18:22:49.0678 6408 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 18:22:49.0748 6408 DcomLaunch - ok 18:22:49.0808 6408 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 18:22:49.0858 6408 defragsvc - ok 18:22:49.0898 6408 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 18:22:49.0948 6408 DfsC - ok 18:22:49.0978 6408 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 18:22:50.0028 6408 Dhcp - ok 18:22:50.0038 6408 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 18:22:50.0088 6408 discache - ok 18:22:50.0118 6408 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys 18:22:50.0128 6408 Disk - ok 18:22:50.0158 6408 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 18:22:50.0208 6408 Dnscache - ok 18:22:50.0238 6408 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 18:22:50.0278 6408 dot3svc - ok 18:22:50.0308 6408 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 18:22:50.0348 6408 DPS - ok 18:22:50.0378 6408 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 18:22:50.0408 6408 drmkaud - ok 18:22:50.0548 6408 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 18:22:50.0568 6408 DXGKrnl - ok 18:22:50.0598 6408 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 18:22:50.0648 6408 EapHost - ok 18:22:51.0338 6408 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys 18:22:51.0418 6408 ebdrv - ok 18:22:51.0458 6408 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 18:22:51.0498 6408 EFS - ok 18:22:51.0668 6408 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 18:22:51.0738 6408 ehRecvr - ok 18:22:51.0768 6408 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 18:22:51.0808 6408 ehSched - ok 18:22:51.0878 6408 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 18:22:51.0898 6408 elxstor - ok 18:22:51.0928 6408 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 18:22:51.0958 6408 ErrDev - ok 18:22:51.0998 6408 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 18:22:52.0038 6408 EventSystem - ok 18:22:52.0058 6408 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 18:22:52.0098 6408 exfat - ok 18:22:52.0108 6408 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 18:22:52.0158 6408 fastfat - ok 18:22:52.0198 6408 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 18:22:52.0248 6408 Fax - ok 18:22:52.0258 6408 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys 18:22:52.0288 6408 fdc - ok 18:22:52.0318 6408 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 18:22:52.0348 6408 fdPHost - ok 18:22:52.0358 6408 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 18:22:52.0398 6408 FDResPub - ok 18:22:52.0408 6408 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 18:22:52.0418 6408 FileInfo - ok 18:22:52.0428 6408 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 18:22:52.0478 6408 Filetrace - ok 18:22:52.0498 6408 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 18:22:52.0508 6408 flpydisk - ok 18:22:52.0558 6408 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 18:22:52.0568 6408 FltMgr - ok 18:22:52.0628 6408 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll 18:22:52.0708 6408 FontCache - ok 18:22:52.0738 6408 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 18:22:52.0758 6408 FontCache3.0.0.0 - ok 18:22:52.0758 6408 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 18:22:52.0768 6408 FsDepends - ok 18:22:52.0788 6408 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 18:22:52.0798 6408 Fs_Rec - ok 18:22:52.0838 6408 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 18:22:52.0858 6408 fvevol - ok 18:22:52.0898 6408 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 18:22:52.0908 6408 gagp30kx - ok 18:22:52.0958 6408 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 18:22:52.0968 6408 GEARAspiWDM - ok 18:22:53.0049 6408 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 18:22:53.0119 6408 gpsvc - ok 18:22:53.0249 6408 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 18:22:53.0389 6408 gupdate - ok 18:22:53.0399 6408 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 18:22:53.0399 6408 gupdatem - ok 18:22:53.0459 6408 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe 18:22:53.0459 6408 gusvc - ok 18:22:53.0489 6408 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 18:22:53.0539 6408 hcw85cir - ok 18:22:53.0569 6408 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 18:22:53.0589 6408 HdAudAddService - ok 18:22:53.0639 6408 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 18:22:53.0679 6408 HDAudBus - ok 18:22:53.0699 6408 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 18:22:53.0729 6408 HidBatt - ok 18:22:53.0749 6408 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 18:22:53.0769 6408 HidBth - ok 18:22:53.0949 6408 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 18:22:54.0009 6408 HidIr - ok 18:22:54.0029 6408 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll 18:22:54.0079 6408 hidserv - ok 18:22:54.0099 6408 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 18:22:54.0119 6408 HidUsb - ok 18:22:54.0139 6408 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 18:22:54.0199 6408 hkmsvc - ok 18:22:54.0249 6408 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 18:22:54.0329 6408 HomeGroupListener - ok 18:22:54.0389 6408 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 18:22:54.0409 6408 HomeGroupProvider - ok 18:22:54.0479 6408 [ F90DD89E8A482AC976DD4E1029802E49 ] HP LaserJet Service C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe 18:22:54.0499 6408 HP LaserJet Service ( UnsignedFile.Multi.Generic ) - warning 18:22:54.0499 6408 HP LaserJet Service - detected UnsignedFile.Multi.Generic (1) 18:22:54.0539 6408 [ F8F686D62121549377D9E1CDF6BC3441 ] HPM1210RcvFaxSrvc C:\Program Files\HP\HP LaserJet M1210 MFP Series\ReceiveFaxUtility.exe 18:22:54.0559 6408 HPM1210RcvFaxSrvc - ok 18:22:54.0589 6408 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 18:22:54.0599 6408 HpSAMD - ok 18:22:54.0639 6408 [ 4E9CAE3200A46135DE01CE22BAF832BE ] HPSIService C:\Windows\system32\HPSIsvc.exe 18:22:54.0659 6408 HPSIService - ok 18:22:54.0729 6408 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 18:22:54.0819 6408 HTTP - ok 18:22:54.0859 6408 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 18:22:54.0869 6408 hwpolicy - ok 18:22:54.0909 6408 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 18:22:54.0929 6408 i8042prt - ok 18:22:54.0959 6408 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 18:22:54.0979 6408 iaStorV - ok 18:22:55.0059 6408 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 18:22:55.0089 6408 idsvc - ok 18:22:55.0119 6408 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 18:22:55.0129 6408 iirsp - ok 18:22:55.0169 6408 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 18:22:55.0219 6408 IKEEXT - ok 18:22:55.0239 6408 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 18:22:55.0239 6408 intelide - ok 18:22:55.0289 6408 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 18:22:55.0309 6408 intelppm - ok 18:22:55.0349 6408 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 18:22:55.0389 6408 IPBusEnum - ok 18:22:55.0439 6408 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 18:22:55.0479 6408 IpFilterDriver - ok 18:22:55.0529 6408 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 18:22:55.0599 6408 iphlpsvc - ok 18:22:55.0659 6408 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 18:22:55.0719 6408 IPMIDRV - ok 18:22:55.0739 6408 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 18:22:55.0779 6408 IPNAT - ok 18:22:55.0839 6408 [ B474C756C13960793C7583B766F904C4 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 18:22:55.0859 6408 iPod Service - ok 18:22:55.0889 6408 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 18:22:55.0899 6408 IRENUM - ok 18:22:55.0909 6408 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 18:22:55.0919 6408 isapnp - ok 18:22:55.0949 6408 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 18:22:55.0959 6408 iScsiPrt - ok 18:22:55.0979 6408 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 18:22:55.0989 6408 kbdclass - ok 18:22:56.0019 6408 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 18:22:56.0049 6408 kbdhid - ok 18:22:56.0069 6408 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 18:22:56.0079 6408 KeyIso - ok 18:22:56.0129 6408 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 18:22:56.0149 6408 KSecDD - ok 18:22:56.0199 6408 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 18:22:56.0229 6408 KSecPkg - ok 18:22:56.0259 6408 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 18:22:56.0299 6408 ksthunk - ok 18:22:56.0339 6408 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 18:22:56.0399 6408 KtmRm - ok 18:22:56.0429 6408 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll 18:22:56.0479 6408 LanmanServer - ok 18:22:56.0509 6408 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 18:22:56.0549 6408 LanmanWorkstation - ok 18:22:56.0579 6408 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 18:22:56.0619 6408 lltdio - ok 18:22:56.0652 6408 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 18:22:56.0681 6408 lltdsvc - ok 18:22:56.0691 6408 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 18:22:56.0731 6408 lmhosts - ok 18:22:56.0761 6408 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 18:22:56.0771 6408 LSI_FC - ok 18:22:56.0781 6408 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 18:22:56.0791 6408 LSI_SAS - ok 18:22:56.0801 6408 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 18:22:56.0811 6408 LSI_SAS2 - ok 18:22:56.0831 6408 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 18:22:56.0841 6408 LSI_SCSI - ok 18:22:56.0881 6408 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 18:22:56.0921 6408 luafv - ok 18:22:56.0981 6408 [ 92EB844D90615CB266F84C3202B8786E ] MBAMProtector C:\Windows\system32\drivers\mbam.sys 18:22:56.0991 6408 MBAMProtector - ok 18:22:57.0051 6408 [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe 18:22:57.0071 6408 MBAMScheduler - ok 18:22:57.0081 6408 [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe 18:22:57.0111 6408 MBAMService - ok 18:22:57.0151 6408 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 18:22:57.0171 6408 Mcx2Svc - ok 18:22:57.0191 6408 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 18:22:57.0201 6408 megasas - ok 18:22:57.0211 6408 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 18:22:57.0231 6408 MegaSR - ok 18:22:57.0301 6408 [ 123271BD5237AB991DC5C21FDF8835EB ] Microsoft Office Groove Audit Service C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe 18:22:57.0311 6408 Microsoft Office Groove Audit Service - ok 18:22:57.0331 6408 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 18:22:57.0371 6408 MMCSS - ok 18:22:57.0401 6408 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 18:22:57.0431 6408 Modem - ok 18:22:57.0471 6408 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 18:22:57.0491 6408 monitor - ok 18:22:57.0521 6408 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\drivers\mouclass.sys 18:22:57.0531 6408 mouclass - ok 18:22:57.0551 6408 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 18:22:57.0581 6408 mouhid - ok 18:22:57.0621 6408 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 18:22:57.0641 6408 mountmgr - ok 18:22:57.0681 6408 [ 8A7C8F4C713E70D73946833D76B77035 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 18:22:57.0691 6408 MozillaMaintenance - ok 18:22:57.0751 6408 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 18:22:57.0761 6408 mpio - ok 18:22:57.0791 6408 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 18:22:57.0821 6408 mpsdrv - ok 18:22:57.0861 6408 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll 18:22:57.0911 6408 MpsSvc - ok 18:22:57.0931 6408 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 18:22:57.0991 6408 MRxDAV - ok 18:22:58.0021 6408 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 18:22:58.0051 6408 mrxsmb - ok 18:22:58.0091 6408 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 18:22:58.0151 6408 mrxsmb10 - ok 18:22:58.0171 6408 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 18:22:58.0181 6408 mrxsmb20 - ok 18:22:58.0221 6408 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 18:22:58.0231 6408 msahci - ok 18:22:58.0261 6408 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 18:22:58.0271 6408 msdsm - ok 18:22:58.0291 6408 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 18:22:58.0331 6408 MSDTC - ok 18:22:58.0361 6408 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 18:22:58.0391 6408 Msfs - ok 18:22:58.0401 6408 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 18:22:58.0441 6408 mshidkmdf - ok 18:22:58.0461 6408 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 18:22:58.0471 6408 msisadrv - ok 18:22:58.0511 6408 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 18:22:58.0541 6408 MSiSCSI - ok 18:22:58.0541 6408 msiserver - ok 18:22:58.0571 6408 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 18:22:58.0611 6408 MSKSSRV - ok 18:22:58.0621 6408 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 18:22:58.0651 6408 MSPCLOCK - ok 18:22:58.0691 6408 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 18:22:58.0721 6408 MSPQM - ok 18:22:58.0781 6408 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 18:22:58.0841 6408 MsRPC - ok 18:22:58.0871 6408 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 18:22:58.0881 6408 mssmbios - ok 18:22:58.0901 6408 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 18:22:58.0931 6408 MSTEE - ok 18:22:58.0951 6408 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 18:22:58.0971 6408 MTConfig - ok 18:22:59.0001 6408 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 18:22:59.0011 6408 Mup - ok 18:22:59.0091 6408 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 18:22:59.0161 6408 napagent - ok 18:22:59.0191 6408 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 18:22:59.0221 6408 NativeWifiP - ok 18:22:59.0341 6408 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys 18:22:59.0381 6408 NDIS - ok 18:22:59.0411 6408 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 18:22:59.0441 6408 NdisCap - ok 18:22:59.0481 6408 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 18:22:59.0501 6408 NdisTapi - ok 18:22:59.0583 6408 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 18:22:59.0623 6408 Ndisuio - ok 18:22:59.0663 6408 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 18:22:59.0753 6408 NdisWan - ok 18:22:59.0803 6408 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 18:22:59.0873 6408 NDProxy - ok 18:22:59.0913 6408 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 18:22:59.0953 6408 NetBIOS - ok 18:23:00.0023 6408 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 18:23:00.0093 6408 NetBT - ok 18:23:00.0133 6408 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 18:23:00.0143 6408 Netlogon - ok 18:23:00.0223 6408 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 18:23:00.0263 6408 Netman - ok 18:23:00.0313 6408 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 18:23:00.0373 6408 netprofm - ok 18:23:00.0413 6408 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 18:23:00.0433 6408 NetTcpPortSharing - ok 18:23:00.0473 6408 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 18:23:00.0483 6408 nfrd960 - ok 18:23:00.0513 6408 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll 18:23:00.0533 6408 NlaSvc - ok 18:23:00.0553 6408 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 18:23:00.0573 6408 Npfs - ok 18:23:00.0583 6408 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 18:23:00.0613 6408 nsi - ok 18:23:00.0623 6408 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 18:23:00.0663 6408 nsiproxy - ok 18:23:00.0883 6408 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 18:23:00.0933 6408 Ntfs - ok 18:23:00.0983 6408 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 18:23:01.0023 6408 Null - ok 18:23:01.0063 6408 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 18:23:01.0083 6408 nvraid - ok 18:23:01.0093 6408 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 18:23:01.0103 6408 nvstor - ok 18:23:01.0113 6408 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 18:23:01.0133 6408 nv_agp - ok 18:23:01.0223 6408 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 18:23:01.0353 6408 odserv - ok 18:23:01.0383 6408 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 18:23:01.0403 6408 ohci1394 - ok 18:23:01.0453 6408 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 18:23:01.0473 6408 ose - ok 18:23:01.0533 6408 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 18:23:01.0563 6408 p2pimsvc - ok 18:23:01.0603 6408 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 18:23:01.0613 6408 p2psvc - ok 18:23:01.0653 6408 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys 18:23:01.0663 6408 Parport - ok 18:23:01.0703 6408 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 18:23:01.0713 6408 partmgr - ok 18:23:01.0763 6408 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 18:23:01.0793 6408 PcaSvc - ok 18:23:01.0833 6408 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 18:23:01.0843 6408 pci - ok 18:23:01.0893 6408 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 18:23:01.0903 6408 pciide - ok 18:23:01.0913 6408 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 18:23:01.0933 6408 pcmcia - ok 18:23:01.0943 6408 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 18:23:01.0953 6408 pcw - ok 18:23:01.0983 6408 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 18:23:02.0043 6408 PEAUTH - ok 18:23:02.0563 6408 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 18:23:02.0583 6408 PerfHost - ok 18:23:02.0733 6408 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 18:23:02.0833 6408 pla - ok 18:23:02.0883 6408 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 18:23:02.0923 6408 PlugPlay - ok 18:23:02.0953 6408 PnkBstrA - ok 18:23:02.0973 6408 PnkBstrB - ok 18:23:02.0993 6408 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 18:23:03.0003 6408 PNRPAutoReg - ok 18:23:03.0013 6408 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 18:23:03.0033 6408 PNRPsvc - ok 18:23:03.0093 6408 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 18:23:03.0183 6408 PolicyAgent - ok 18:23:03.0213 6408 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 18:23:03.0263 6408 Power - ok 18:23:03.0373 6408 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 18:23:03.0453 6408 PptpMiniport - ok 18:23:03.0483 6408 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys 18:23:03.0513 6408 Processor - ok 18:23:03.0533 6408 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 18:23:03.0563 6408 ProfSvc - ok 18:23:03.0583 6408 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 18:23:03.0593 6408 ProtectedStorage - ok 18:23:03.0643 6408 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 18:23:03.0693 6408 Psched - ok 18:23:03.0923 6408 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 18:23:03.0963 6408 ql2300 - ok 18:23:03.0983 6408 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 18:23:04.0003 6408 ql40xx - ok 18:23:04.0083 6408 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 18:23:04.0103 6408 QWAVE - ok 18:23:04.0123 6408 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 18:23:04.0153 6408 QWAVEdrv - ok 18:23:04.0433 6408 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 18:23:04.0493 6408 RasAcd - ok 18:23:04.0523 6408 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 18:23:04.0553 6408 RasAgileVpn - ok 18:23:04.0583 6408 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 18:23:04.0623 6408 RasAuto - ok 18:23:04.0653 6408 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 18:23:04.0693 6408 Rasl2tp - ok 18:23:04.0723 6408 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 18:23:04.0783 6408 RasMan - ok 18:23:04.0793 6408 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 18:23:04.0833 6408 RasPppoe - ok 18:23:04.0863 6408 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 18:23:04.0903 6408 RasSstp - ok 18:23:04.0913 6408 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 18:23:04.0943 6408 rdbss - ok 18:23:04.0963 6408 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 18:23:04.0973 6408 rdpbus - ok 18:23:05.0003 6408 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 18:23:05.0043 6408 RDPCDD - ok 18:23:05.0063 6408 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 18:23:05.0093 6408 RDPENCDD - ok 18:23:05.0103 6408 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 18:23:05.0133 6408 RDPREFMP - ok 18:23:05.0153 6408 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 18:23:05.0203 6408 RDPWD - ok 18:23:05.0283 6408 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 18:23:05.0303 6408 rdyboost - ok 18:23:05.0443 6408 [ A0FF419B61AE47E26ADF3BB15DB4F2FE ] RealNetworks Downloader Resolver Service C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe 18:23:05.0453 6408 RealNetworks Downloader Resolver Service - ok 18:23:05.0513 6408 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 18:23:05.0553 6408 RemoteAccess - ok 18:23:05.0583 6408 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 18:23:05.0633 6408 RemoteRegistry - ok 18:23:05.0733 6408 [ 06A49B7BDC36CFBF97DD90804F833369 ] RichVideo C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe 18:23:05.0763 6408 RichVideo - ok 18:23:05.0793 6408 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 18:23:05.0853 6408 RpcEptMapper - ok 18:23:05.0873 6408 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 18:23:05.0893 6408 RpcLocator - ok 18:23:05.0943 6408 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\System32\rpcss.dll 18:23:05.0983 6408 RpcSs - ok 18:23:06.0033 6408 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 18:23:06.0083 6408 rspndr - ok 18:23:06.0123 6408 [ BAEFEE35D27A5440D35092CE10267BEC ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys 18:23:06.0153 6408 RTL8167 - ok 18:23:06.0173 6408 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 18:23:06.0193 6408 SamSs - ok 18:23:06.0713 6408 SASDIFSV - ok 18:23:06.0733 6408 SASKUTIL - ok 18:23:06.0763 6408 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 18:23:06.0773 6408 sbp2port - ok 18:23:06.0803 6408 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 18:23:06.0863 6408 SCardSvr - ok 18:23:06.0913 6408 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 18:23:06.0963 6408 scfilter - ok 18:23:07.0143 6408 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 18:23:07.0233 6408 Schedule - ok 18:23:07.0273 6408 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 18:23:07.0313 6408 SCPolicySvc - ok 18:23:07.0373 6408 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 18:23:07.0403 6408 SDRSVC - ok 18:23:07.0433 6408 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 18:23:07.0483 6408 secdrv - ok 18:23:07.0523 6408 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 18:23:07.0583 6408 seclogon - ok 18:23:07.0623 6408 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll 18:23:07.0693 6408 SENS - ok 18:23:07.0743 6408 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 18:23:07.0803 6408 SensrSvc - ok 18:23:07.0833 6408 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 18:23:07.0853 6408 Serenum - ok 18:23:07.0913 6408 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys 18:23:07.0923 6408 Serial - ok 18:23:07.0973 6408 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 18:23:07.0993 6408 sermouse - ok 18:23:08.0033 6408 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 18:23:08.0084 6408 SessionEnv - ok 18:23:08.0124 6408 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 18:23:08.0154 6408 sffdisk - ok 18:23:08.0154 6408 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 18:23:08.0184 6408 sffp_mmc - ok 18:23:08.0194 6408 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 18:23:08.0214 6408 sffp_sd - ok 18:23:08.0224 6408 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 18:23:08.0234 6408 sfloppy - ok 18:23:08.0284 6408 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll 18:23:08.0334 6408 SharedAccess - ok 18:23:08.0404 6408 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 18:23:08.0464 6408 ShellHWDetection - ok 18:23:08.0502 6408 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 18:23:08.0516 6408 SiSRaid2 - ok 18:23:08.0536 6408 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 18:23:08.0556 6408 SiSRaid4 - ok 18:23:08.0586 6408 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 18:23:08.0650 6408 Smb - ok 18:23:08.0698 6408 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 18:23:08.0728 6408 SNMPTRAP - ok 18:23:08.0748 6408 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 18:23:08.0768 6408 spldr - ok 18:23:08.0858 6408 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 18:23:08.0928 6408 Spooler - ok 18:23:09.0308 6408 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 18:23:09.0428 6408 sppsvc - ok 18:23:09.0458 6408 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 18:23:09.0548 6408 sppuinotify - ok 18:23:10.0088 6408 [ 0D83AF0E8161ADC1ABC9C8EA73A95C27 ] SpyHunter 4 Service C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE 18:23:10.0108 6408 SpyHunter 4 Service - ok 18:23:10.0198 6408 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 18:23:10.0248 6408 srv - ok 18:23:10.0258 6408 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 18:23:10.0298 6408 srv2 - ok 18:23:10.0318 6408 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 18:23:10.0328 6408 srvnet - ok 18:23:10.0358 6408 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 18:23:10.0388 6408 SSDPSRV - ok 18:23:10.0398 6408 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 18:23:10.0438 6408 SstpSvc - ok 18:23:10.0468 6408 Steam Client Service - ok 18:23:10.0488 6408 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 18:23:10.0508 6408 stexstor - ok 18:23:10.0548 6408 [ DECACB6921DED1A38642642685D77DAC ] StillCam C:\Windows\system32\DRIVERS\serscan.sys 18:23:10.0568 6408 StillCam - ok 18:23:10.0618 6408 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 18:23:10.0658 6408 stisvc - ok 18:23:10.0718 6408 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys 18:23:10.0728 6408 swenum - ok 18:23:10.0778 6408 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 18:23:10.0848 6408 swprv - ok 18:23:11.0109 6408 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 18:23:11.0169 6408 SysMain - ok 18:23:11.0199 6408 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 18:23:11.0229 6408 TabletInputService - ok 18:23:11.0299 6408 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 18:23:11.0359 6408 TapiSrv - ok 18:23:11.0389 6408 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 18:23:11.0429 6408 TBS - ok 18:23:11.0569 6408 [ B62A953F2BF3922C8764A29C34A22899 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 18:23:11.0629 6408 Tcpip - ok 18:23:11.0679 6408 [ B62A953F2BF3922C8764A29C34A22899 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 18:23:11.0709 6408 TCPIP6 - ok 18:23:11.0739 6408 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 18:23:11.0769 6408 tcpipreg - ok 18:23:11.0809 6408 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 18:23:11.0829 6408 TDPIPE - ok 18:23:11.0859 6408 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 18:23:11.0879 6408 TDTCP - ok 18:23:11.0909 6408 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 18:23:11.0939 6408 tdx - ok 18:23:11.0979 6408 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys 18:23:11.0989 6408 TermDD - ok 18:23:12.0119 6408 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 18:23:12.0179 6408 TermService - ok 18:23:12.0219 6408 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 18:23:12.0269 6408 Themes - ok 18:23:12.0329 6408 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 18:23:12.0349 6408 THREADORDER - ok 18:23:12.0409 6408 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 18:23:12.0459 6408 TrkWks - ok 18:23:12.0549 6408 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 18:23:12.0599 6408 TrustedInstaller - ok 18:23:12.0669 6408 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 18:23:12.0699 6408 tssecsrv - ok 18:23:12.0759 6408 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 18:23:12.0789 6408 TsUsbFlt - ok 18:23:12.0829 6408 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 18:23:12.0869 6408 tunnel - ok 18:23:12.0929 6408 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 18:23:12.0939 6408 uagp35 - ok 18:23:12.0959 6408 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 18:23:13.0009 6408 udfs - ok 18:23:13.0029 6408 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 18:23:13.0049 6408 UI0Detect - ok 18:23:13.0079 6408 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 18:23:13.0089 6408 uliagpkx - ok 18:23:13.0119 6408 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 18:23:13.0149 6408 umbus - ok 18:23:13.0169 6408 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 18:23:13.0189 6408 UmPass - ok 18:23:13.0209 6408 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 18:23:13.0249 6408 upnphost - ok 18:23:13.0379 6408 [ 43228F8EDD1B0BCDD3145AD246E63D39 ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys 18:23:13.0419 6408 USBAAPL64 - ok 18:23:13.0459 6408 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys 18:23:13.0489 6408 usbaudio - ok 18:23:13.0519 6408 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 18:23:13.0539 6408 usbccgp - ok 18:23:13.0579 6408 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\DRIVERS\usbcir.sys 18:23:13.0589 6408 usbcir - ok 18:23:13.0619 6408 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 18:23:13.0659 6408 usbehci - ok 18:23:13.0699 6408 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 18:23:13.0729 6408 usbhub - ok 18:23:13.0789 6408 [ F9B3054339A71F16430F6585EBC8BE96 ] USBMULCD C:\Windows\system32\drivers\CM10664.sys 18:23:13.0849 6408 USBMULCD - ok 18:23:13.0859 6408 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys 18:23:13.0879 6408 usbohci - ok 18:23:13.0899 6408 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 18:23:13.0919 6408 usbprint - ok 18:23:13.0929 6408 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 18:23:13.0969 6408 USBSTOR - ok 18:23:13.0979 6408 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 18:23:13.0999 6408 usbuhci - ok 18:23:14.0029 6408 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 18:23:14.0079 6408 UxSms - ok 18:23:14.0099 6408 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 18:23:14.0109 6408 VaultSvc - ok 18:23:14.0149 6408 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 18:23:14.0159 6408 vdrvroot - ok 18:23:14.0289 6408 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 18:23:14.0359 6408 vds - ok 18:23:14.0369 6408 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 18:23:14.0379 6408 vga - ok 18:23:14.0399 6408 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 18:23:14.0449 6408 VgaSave - ok 18:23:14.0479 6408 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 18:23:14.0499 6408 vhdmp - ok 18:23:14.0519 6408 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 18:23:14.0529 6408 viaide - ok 18:23:14.0559 6408 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 18:23:14.0569 6408 volmgr - ok 18:23:14.0599 6408 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 18:23:14.0619 6408 volmgrx - ok 18:23:14.0669 6408 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 18:23:14.0679 6408 volsnap - ok 18:23:14.0719 6408 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 18:23:14.0729 6408 vsmraid - ok 18:23:14.0839 6408 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 18:23:14.0949 6408 VSS - ok 18:23:14.0979 6408 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys 18:23:15.0029 6408 vwifibus - ok 18:23:15.0069 6408 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 18:23:15.0120 6408 W32Time - ok 18:23:15.0170 6408 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 18:23:15.0180 6408 WacomPen - ok 18:23:15.0230 6408 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 18:23:15.0290 6408 WANARP - ok 18:23:15.0310 6408 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 18:23:15.0340 6408 Wanarpv6 - ok 18:23:15.0560 6408 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 18:23:15.0600 6408 WatAdminSvc - ok 18:23:15.0690 6408 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 18:23:15.0770 6408 wbengine - ok 18:23:15.0810 6408 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 18:23:15.0830 6408 WbioSrvc - ok 18:23:15.0890 6408 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 18:23:15.0950 6408 wcncsvc - ok 18:23:15.0960 6408 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 18:23:15.0990 6408 WcsPlugInService - ok 18:23:16.0040 6408 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys 18:23:16.0050 6408 Wd - ok 18:23:16.0181 6408 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 18:23:16.0241 6408 Wdf01000 - ok 18:23:16.0291 6408 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 18:23:16.0371 6408 WdiServiceHost - ok 18:23:16.0371 6408 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 18:23:16.0391 6408 WdiSystemHost - ok 18:23:16.0451 6408 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 18:23:16.0481 6408 WebClient - ok 18:23:16.0521 6408 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 18:23:16.0581 6408 Wecsvc - ok 18:23:16.0611 6408 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 18:23:16.0681 6408 wercplsupport - ok 18:23:16.0721 6408 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 18:23:16.0751 6408 WerSvc - ok 18:23:16.0781 6408 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 18:23:16.0821 6408 WfpLwf - ok 18:23:16.0841 6408 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 18:23:16.0861 6408 WIMMount - ok 18:23:16.0871 6408 WinDefend - ok 18:23:16.0881 6408 WinHttpAutoProxySvc - ok 18:23:16.0941 6408 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 18:23:16.0991 6408 Winmgmt - ok 18:23:17.0311 6408 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 18:23:17.0451 6408 WinRM - ok 18:23:17.0551 6408 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 18:23:17.0571 6408 WinUsb - ok 18:23:17.0661 6408 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 18:23:17.0711 6408 Wlansvc - ok 18:23:17.0751 6408 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 18:23:17.0781 6408 WmiAcpi - ok 18:23:17.0851 6408 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 18:23:17.0901 6408 wmiApSrv - ok 18:23:17.0941 6408 WMPNetworkSvc - ok 18:23:17.0951 6408 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 18:23:17.0971 6408 WPCSvc - ok 18:23:18.0021 6408 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 18:23:18.0041 6408 WPDBusEnum - ok 18:23:18.0081 6408 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 18:23:18.0134 6408 ws2ifsl - ok 18:23:18.0163 6408 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll 18:23:18.0183 6408 wscsvc - ok 18:23:18.0233 6408 [ 8D918B1DB190A4D9B1753A66FA8C96E8 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys 18:23:18.0253 6408 WSDPrintDevice - ok 18:23:18.0253 6408 WSearch - ok 18:23:18.0503 6408 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 18:23:18.0573 6408 wuauserv - ok 18:23:18.0633 6408 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 18:23:18.0703 6408 WudfPf - ok 18:23:18.0743 6408 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 18:23:18.0763 6408 WUDFRd - ok 18:23:18.0833 6408 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 18:23:18.0873 6408 wudfsvc - ok 18:23:18.0923 6408 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll 18:23:18.0953 6408 WwanSvc - ok 18:23:18.0993 6408 ================ Scan global =============================== 18:23:19.0013 6408 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 18:23:19.0043 6408 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll 18:23:19.0053 6408 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll 18:23:19.0063 6408 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 18:23:19.0135 6408 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 18:23:19.0145 6408 [Global] - ok 18:23:19.0145 6408 ================ Scan MBR ================================== 18:23:19.0155 6408 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 18:23:21.0495 6408 \Device\Harddisk0\DR0 - ok 18:23:21.0495 6408 ================ Scan VBR ================================== 18:23:21.0535 6408 [ 826F8C5E7050F935A5087CA192EAFFE8 ] \Device\Harddisk0\DR0\Partition1 18:23:21.0585 6408 \Device\Harddisk0\DR0\Partition1 - ok 18:23:21.0615 6408 [ 5E38478C7B8095BABAFB421981242317 ] \Device\Harddisk0\DR0\Partition2 18:23:21.0665 6408 \Device\Harddisk0\DR0\Partition2 - ok 18:23:21.0665 6408 ============================================================ 18:23:21.0665 6408 Scan finished 18:23:21.0665 6408 ============================================================ 18:23:21.0675 3700 Detected object count: 2 18:23:21.0675 3700 Actual detected object count: 2 18:23:39.0268 3700 Adobe LM Service ( UnsignedFile.Multi.Generic ) - skipped by user 18:23:39.0268 3700 Adobe LM Service ( UnsignedFile.Multi.Generic ) - User select action: Skip 18:23:39.0268 3700 HP LaserJet Service ( UnsignedFile.Multi.Generic ) - skipped by user 18:23:39.0268 3700 HP LaserJet Service ( UnsignedFile.Multi.Generic ) - User select action: Skip 18:23:41.0428 1192 Deinitialize success All processes killed ========== SERVICES/DRIVERS ========== ========== FILES ========== C:\Windows\System32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\60539d66-728eb768 moved successfully. File\Folder C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\60539d66-728eb768 not found. C:\Users\mlawre\AppData\Local\8451tl30e6p7e54f8xv0dl2461gmp300 moved successfully. C:\ProgramData\8451tl30e6p7e54f8xv0dl2461gmp300 moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: mlawre ->Temp folder emptied: 12116617 bytes ->Temporary Internet Files folder emptied: 96117110 bytes ->Java cache emptied: 10946 bytes ->FireFox cache emptied: 3259438 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 6982 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 551894 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes RecycleBin emptied: 410022 bytes Total Files Cleaned = 107.00 mb Restore point Set: OTL Restore Point OTL by OldTimer - Version 3.2.69.0 log created on 04132013_184728 Files\Folders moved on Reboot… C:\Users\mlawre\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\WECF430I\iframe[1].html moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\QT5F8BAL\ads[2].htm moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\QT5F8BAL\index[1].htm moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HW11X6H1\ads[6].htm moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HW11X6H1\search[1].htm moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\31L5544Q\takeover[1].htm moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\31L5544Q\zrt_lookup[1].html moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully. C:\Users\mlawre\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XSCL0NUQ\c50873715e7787df38c48c87[1].txt moved successfully. PendingFileRenameOperations files… Registry entries deleted on Reboot… Malwarebytes Anti-Malware (PRO) 1.75.0.1300 www.malwarebytes.org Database version: v2013.04.13.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 mlawre :: MEDIA-PC [administrator] Protection: Disabled 4/13/2013 7:00:49 PM mbam-log-2013-04-13 (19-00-49).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 218933 Time elapsed: 3 minute(s), 1 second(s) Memory Processes Detected: 3 C:\Users\mlawre\AppData\Roaming\Pimeymef\ofhea.exe (Trojan.Agent.ED) -> 3432 -> Delete on reboot. C:\Users\mlawre\AppData\Roaming\Pimeymef\ofhea.exe (Trojan.Agent.ED) -> 3804 -> Delete on reboot. C:\Users\mlawre\AppData\Roaming\Pimeymef\ofhea.exe (Trojan.Agent.ED) -> 4732 -> Delete on reboot. Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Irecaximteukgei (Trojan.Agent.ED) -> Data: C:\Users\mlawre\AppData\Roaming\Pimeymef\ofhea.exe -> Quarantined and deleted successfully. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 3 C:\Users\mlawre\AppData\Roaming\Pimeymef\ofhea.exe (Trojan.Agent.ED) -> Delete on reboot. C:\Users\mlawre\AppData\Roaming\Woasdyki\ahrueke.exe (Trojan.Agent.CS) -> Quarantined and deleted successfully. C:\Windows\Tasks\Security Center Update - 2127541107.job (Trojan.Agent.RvGen) -> Quarantined and deleted successfully. (end) Many thanks! Michael
Hi mlware,

Looks like you may have picked up something new.

Please delete the copy of combofix that you have.

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Right click on ComboFix.exe, click Run as Administrator & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. If after running combofix you recieve an message "Illegal operation attempted on a registery key that has been marked for deletion" or similar reboot the computer.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log.

Thanks
Hi Oldman960, So I was about to tell you that since your last fix + MBAM run, the computer has been running alot more smoothly. Here is my combofix log in case something still remains: ComboFix 13-04-15.01 - mlawre 04/16/2013 19:54:07.5.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4094.2825 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((( Files Created from 2013-03-17 to 2013-04-17 ))))))))))))))))))))))))))))))) . . 2013-04-17 00:58 . 2013-04-17 00:58 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-04-16 02:27 . 2013-04-16 02:27 76232 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C45D6806-C876-44CC-961A-EC85FB46F514}\offreg.dll 2013-04-14 22:26 . 2013-03-15 06:28 9311288 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C45D6806-C876-44CC-961A-EC85FB46F514}\mpengine.dll 2013-04-13 23:47 . 2013-02-15 06:08 44032 —-a-w- c:\windows\system32\tsgqec.dll 2013-04-13 23:47 . 2013-02-15 06:06 3717632 —-a-w- c:\windows\system32\mstscax.dll 2013-04-13 23:47 . 2013-02-15 06:02 158720 —-a-w- c:\windows\system32\aaclient.dll 2013-04-13 23:47 . 2013-02-15 04:37 3217408 —-a-w- c:\windows\SysWow64\mstscax.dll 2013-04-13 23:47 . 2013-02-15 04:34 131584 —-a-w- c:\windows\SysWow64\aaclient.dll 2013-04-13 23:47 . 2013-02-15 03:25 36864 —-a-w- c:\windows\SysWow64\tsgqec.dll 2013-04-13 23:47 . 2013-03-01 03:36 3153408 —-a-w- c:\windows\system32\win32k.sys 2013-04-13 23:47 . 2013-03-02 05:50 9059328 —-a-w- c:\windows\system32\mshtml.dll 2013-04-13 23:47 . 2013-03-02 05:49 12294656 —-a-w- c:\windows\system32\ieframe.dll 2013-04-13 23:38 . 2013-04-14 00:06 ——– d—–w- c:\users\mlawre\AppData\Roaming\Pimeymef 2013-04-08 01:49 . 2013-04-10 01:47 ——– d—–w- c:\users\mlawre\AppData\Roaming\Ycgemya 2013-04-06 13:46 . 2013-04-08 01:49 ——– d—–w- c:\users\mlawre\AppData\Roaming\Ekaxfuu 2013-04-06 02:44 . 2013-04-06 13:46 ——– d—–w- c:\users\mlawre\AppData\Roaming\Likyyn 2013-04-03 01:09 . 2013-04-14 00:04 ——– d—–w- c:\users\mlawre\AppData\Roaming\Woasdyki 2013-04-02 03:12 . 2013-04-02 03:12 ——– d—–w- c:\users\mlawre\AppData\Local\ElevatedDiagnostics 2013-04-01 01:05 . 2013-04-01 01:05 ——– d—–w- c:\program files (x86)\ESET 2013-03-31 23:30 . 2013-03-31 23:30 ——– d—–w- C:\_OTL 2013-03-31 23:28 . 2013-03-31 23:28 310688 —-a-w- c:\windows\system32\javaws.exe 2013-03-31 23:28 . 2013-03-31 23:28 188832 —-a-w- c:\windows\system32\javaw.exe 2013-03-31 23:28 . 2013-03-31 23:28 188320 —-a-w- c:\windows\system32\java.exe 2013-03-31 23:28 . 2013-03-31 23:28 108448 —-a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2013-03-31 23:27 . 2013-03-31 23:28 1085344 —-a-w- c:\windows\system32\npDeployJava1.dll 2013-03-31 23:27 . 2013-03-31 23:27 ——– d—–w- c:\program files (x86)\Common Files\Java 2013-03-31 23:26 . 2013-03-31 23:26 861088 —-a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-03-31 23:26 . 2013-03-31 23:26 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-03-30 23:30 . 2013-03-31 23:05 ——– d—–w- C:\TDSSKiller_Quarantine 2013-03-30 17:05 . 2013-03-30 17:21 ——– d—–w- C:\jgh 2013-03-30 02:07 . 2013-03-30 02:07 ——– d—–w- c:\users\mlawre\AppData\Local\Macromedia 2013-03-29 02:59 . 2013-03-29 02:59 16486616 —-a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe 2013-03-29 02:02 . 2013-03-29 02:02 ——– d—–w- c:\programdata\dbe 2013-03-29 02:00 . 2013-03-29 02:00 ——– d—–w- c:\windows\Sun 2013-03-28 05:41 . 2013-03-28 05:41 ——– d-sh–w- c:\windows\SysWow64\%APPDATA% 2013-03-28 05:17 . 2013-03-29 03:29 693976 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-03-26 02:32 . 2013-02-12 04:12 19968 —-a-w- c:\windows\system32\drivers\usb8023.sys 2013-03-24 04:57 . 2013-03-24 05:36 ——– d—–w- c:\users\mlawre\AppData\Local\SUPERAntiSpyware.com 2013-03-18 08:01 . 2013-03-18 08:01 ——– d—–w- c:\program files\Microsoft Silverlight 2013-03-18 08:01 . 2013-03-18 08:01 ——– d—–w- c:\program files (x86)\Microsoft Silverlight . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-04-14 00:39 . 2011-11-06 21:16 72702784 —-a-w- c:\windows\system32\MRT.exe 2013-04-04 19:50 . 2011-12-25 18:13 25928 —-a-w- c:\windows\system32\drivers\mbam.sys 2013-03-31 23:28 . 2011-08-21 20:26 963488 —-a-w- c:\windows\system32\deployJava1.dll 2013-03-31 23:26 . 2011-08-27 21:27 782240 —-a-w- c:\windows\SysWow64\deployJava1.dll 2013-03-31 02:21 . 2011-12-21 02:13 214520 —-a-w- c:\windows\SysWow64\PnkBstrB.exe 2013-03-31 02:21 . 2011-12-21 02:13 214520 —-a-w- c:\windows\SysWow64\PnkBstrB.xtr 2013-03-29 03:29 . 2011-08-18 05:57 73432 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-03-12 06:10 . 2011-01-23 02:44 282744 ——w- c:\windows\system32\MpSigStub.exe 2013-02-12 05:45 . 2013-03-18 05:03 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-02-12 05:45 . 2013-03-18 05:03 308736 —-a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-02-12 05:45 . 2013-03-18 05:03 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-02-12 05:45 . 2013-03-18 05:03 111104 —-a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-02-12 04:48 . 2013-03-18 05:03 474112 —-a-w- c:\windows\apppatch\AcSpecfc.dll 2013-02-12 04:48 . 2013-03-18 05:03 2176512 —-a-w- c:\windows\apppatch\AcGenral.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="c:\program files (x86)\Steam\Steam.exe" [2013-03-26 1631144] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Acrobat Assistant 7.0"="c:\progra~2\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 483328] "HPUsageTrackingLEDM"="c:\program files (x86)\HP\HP UT LEDM\bin\hppusg.exe" [2009-10-15 30264] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-11-29 151952] "TkBellExe"="c:\program files (x86)\real\realplayer\Update\realsched.exe" [2012-12-30 295072] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [2011-3-19 25214] Adobe Gamma.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer] @="Service" . R1 SASDIFSV;SASDIFSV;c:\users\mlawre\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV64.SYS [x] R1 SASKUTIL;SASKUTIL;c:\users\mlawre\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL64.SYS [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512] R3 cpuz134;cpuz134;c:\users\mlawre\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-09-28 53760] R3 USBMULCD;USB Multi-Channel Audio Device Interface;c:\windows\system32\drivers\CM10664.sys [2009-09-30 1307648] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-01-24 1255736] R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-10-27 203776] S2 HP LaserJet Service;HP LaserJet Service;c:\program files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2009-10-15 136192] S2 HPM1210RcvFaxSrvc;HP LaserJet Professional M1210 MFP Series Receive Fax Service;c:\program files\HP\HP LaserJet M1210 MFP Series\ReceiveFaxUtility.exe [2010-05-11 362296] S2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe [2010-04-30 127800] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376] S2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [2012-11-30 38608] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 25928] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-04-13 23:38 1642448 —-a-w- c:\program files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-04-17 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-28 01:46] . 2013-04-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21 00:56] . 2013-04-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-21 00:56] . . ——— X64 Entries ———– . . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService FontCache . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Convert link target to Adobe PDF - c:\progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert to existing PDF - c:\progra~2\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 Trusted Zone: swmed.edu\mail TCP: DhcpNameServer = 192.168.1.254 FF - ProfilePath - c:\users\mlawre\AppData\Roaming\Mozilla\Firefox\Profiles\k29s6jq6.default\ . - - - - ORPHANS REMOVED - - - - . AddRemove-RealPlayer 16.0 - c:\program files (x86)\real\realplayer\Update\r1puninst.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-04-16 20:00:19 ComboFix-quarantined-files.txt 2013-04-17 01:00 ComboFix2.txt 2013-03-31 13:59 ComboFix3.txt 2013-03-30 20:48 ComboFix4.txt 2013-03-30 17:21 . Pre-Run: 380,275,851,264 bytes free Post-Run: 379,847,475,200 bytes free . - - End Of File - - 7C6EF6AF526B453F0DF3224B280129EF Thanks! Michael
Hi mlware,

That looks ok. Let's get a new OTL log. Open OTL
  • check the box beside"scan all users"
  • check the boxes beside Lop check and Purity check
  • click the quick scan button
Please post the log.
Thanks Oldman960! All seems to be running ok. There is one thing that might not be related, but I can't activate my MBAM monitoring without some extreme lag. I can use it to scan just fine, but if I enable protection, the mouse pointer is almost unresponsive. Other than that the computer seems to be normal now!

Here is my OTL log:
OTL logfile created on: 4/21/2013 11:12:07 PM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\mlawre\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.80 Gb Available Physical Memory | 69.98% Memory free
8.00 Gb Paging File | 6.30 Gb Available in Paging File | 78.84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 353.41 Gb Free Space | 75.89% Space Free | Partition Type: NTFS

Computer Name: MEDIA-PC | User Name: mlawre | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrB.exe ()
PRC - C:\Users\mlawre\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
PRC - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Distillr\acrotray.exe (Adobe Systems Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (SpyHunter 4 Service) – C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe (Enigma Software Group USA, LLC.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (HPM1210RcvFaxSrvc) – C:\Program Files\HP\HP LaserJet M1210 MFP Series\ReceiveFaxUtility.exe (HP)
SRV:64bit: - (HPSIService) – C:\Windows\SysNative\HPSIsvc.exe (HP)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (PnkBstrB) – C:\Windows\SysWOW64\PnkBstrB.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (HP LaserJet Service) – C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (USBMULCD) – C:\Windows\SysNative\drivers\CM10664.sys (C-Media Electronics Inc)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 2C 9B FF 4F B5 BA CB 01 [binary data]
IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\..\SearchScopes,DefaultScope = {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}
IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=i…8D-BB0278D58303
IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\..\SearchScopes\{9B97950D-482C-1D79-568F-FC7B9D40C785}: "URL" = http://www.bing.com/search?q={searchTerms}…eferrer:source}
IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2012/12/29 23:38:24 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/04/17 21:33:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/04/17 21:33:44 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/04/17 21:33:46 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/04/17 21:33:44 | 000,000,000 | —D | M]

[2011/10/26 21:35:25 | 000,000,000 | —D | M] (No name found) – C:\Users\mlawre\AppData\Roaming\Mozilla\Extensions
[2013/03/22 20:31:59 | 000,000,000 | —D | M] (No name found) – C:\Users\mlawre\AppData\Roaming\Mozilla\Firefox\Profiles\k29s6jq6.default\extensions
[2013/03/22 20:31:59 | 000,221,336 | —- | M] () (No name found) – C:\Users\mlawre\AppData\Roaming\Mozilla\Firefox\Profiles\k29s6jq6.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
[2013/04/17 21:33:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/04/17 21:33:46 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2009/10/07 20:33:08 | 001,645,320 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\mozilla firefox\plugins\gdiplus.dll
[2012/12/29 23:38:09 | 000,124,056 | —- | M] (RealPlayer) – C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll
[2011/01/13 08:23:36 | 002,078,720 | —- | M] (Library Video Company) – C:\Program Files (x86)\mozilla firefox\plugins\npSAFARIMontagePlayer.dll
[2012/09/15 23:26:30 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013/02/20 17:26:13 | 000,002,086 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.152\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.152\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.152\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U27 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprpplugin.dll
CHR - plugin: SAFARI Montage Player (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npSAFARIMontagePlayer.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworks™ RealDownloader Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll
CHR - plugin: RealNetworks™ RealDownloader HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
CHR - plugin: RealNetworks™ RealDownloader PepperFlashVideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll
CHR - plugin: RealDownloader Plugin (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\mlawre\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\mlawre\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: RealDownloader = C:\Users\mlawre\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0\
CHR - Extension: Gmail = C:\Users\mlawre\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2013/03/31 08:57:29 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg64.dll (Google Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 7.0] C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [HPUsageTrackingLEDM] C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-1999296799-1591171409-122683792-1001..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - HKU\S-1-5-21-1999296799-1591171409-122683792-1001..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil64_11_6_602_180_ActiveX.exe -update activex File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to existing PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files (x86)\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-1999296799-1591171409-122683792-1001\..Trusted Domains: swmed.edu ([mail] https in Trusted sites)
O16:64bit: - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C833CAF0-286B-4913-80DC-06F4C9517C6A}: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/03/02 02:52:15 | 000,000,000 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/04/17 21:33:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/04/16 20:45:17 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/04/16 20:00:20 | 000,000,000 | —D | C] – C:\Windows\temp
[2013/04/16 19:51:15 | 005,054,270 | R— | C] (Swearware) – C:\Users\mlawre\Desktop\ComboFix.exe
[2013/04/13 18:38:04 | 000,000,000 | —D | C] – C:\Users\mlawre\AppData\Roaming\Pimeymef
[2013/04/07 20:49:45 | 000,000,000 | —D | C] – C:\Users\mlawre\AppData\Roaming\Ycgemya
[2013/04/06 08:46:48 | 000,000,000 | —D | C] – C:\Users\mlawre\AppData\Roaming\Ekaxfuu
[2013/04/05 21:44:54 | 000,000,000 | —D | C] – C:\Users\mlawre\AppData\Roaming\Likyyn
[2013/04/02 20:09:11 | 000,000,000 | —D | C] – C:\Users\mlawre\AppData\Roaming\Woasdyki
[2013/04/01 22:12:07 | 000,000,000 | —D | C] – C:\Users\mlawre\AppData\Local\ElevatedDiagnostics
[2013/03/31 20:05:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2013/03/31 18:30:08 | 000,000,000 | —D | C] – C:\_OTL
[2013/03/31 18:27:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2013/03/30 18:30:46 | 000,000,000 | —D | C] – C:\TDSSKiller_Quarantine
[2013/03/30 18:24:48 | 002,237,968 | —- | C] (Kaspersky Lab ZAO) – C:\Users\mlawre\Desktop\tdsskiller.exe
[2013/03/30 15:37:43 | 000,000,000 | —D | C] – C:\jgh3886j
[2013/03/30 12:05:32 | 000,000,000 | —D | C] – C:\jgh
[2013/03/30 11:56:05 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/03/30 11:56:05 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/03/30 11:56:05 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/03/30 11:51:45 | 000,000,000 | —D | C] – C:\Qoobox
[2013/03/30 11:51:37 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/03/29 21:07:58 | 000,000,000 | —D | C] – C:\Users\mlawre\AppData\Local\Macromedia
[2013/03/29 20:41:59 | 000,688,992 | R— | C] (Swearware) – C:\Users\mlawre\Desktop\dds.com
[2013/03/29 20:41:56 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\mlawre\Desktop\HiJackThis.exe
[2013/03/29 20:41:52 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\mlawre\Desktop\OTL.exe
[2013/03/28 21:02:39 | 000,000,000 | —D | C] – C:\ProgramData\dbe
[2013/03/28 21:00:35 | 000,000,000 | —D | C] – C:\Windows\Sun
[2013/03/28 00:41:41 | 000,000,000 | -HSD | C] – C:\Windows\SysWow64\%APPDATA%
[2013/03/24 22:41:02 | 001,606,848 | —- | C] (InstallX, LLC) – C:\Users\mlawre\Desktop\ezcalendar_d144272.exe
[2013/03/23 23:57:03 | 000,000,000 | —D | C] – C:\Users\mlawre\AppData\Local\SUPERAntiSpyware.com

========== Files - Modified Within 30 Days ==========

[2013/04/21 22:57:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/04/21 22:38:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/04/21 20:58:23 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/04/21 20:48:59 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/04/16 21:30:22 | 000,015,136 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/04/16 21:30:22 | 000,015,136 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/04/16 19:51:22 | 005,054,270 | R— | M] (Swearware) – C:\Users\mlawre\Desktop\ComboFix.exe
[2013/04/14 22:47:02 | 3220,037,632 | -HS- | M] () – C:\hiberfil.sys
[2013/04/13 19:44:25 | 000,421,840 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/04/13 19:00:17 | 000,001,109 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/04/13 18:39:02 | 000,002,183 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/04/08 01:06:06 | 000,726,270 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/04/08 01:06:06 | 000,624,162 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/04/08 01:06:06 | 000,106,538 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/04/06 23:00:37 | 000,053,126 | —- | M] () – C:\Users\mlawre\Desktop\360_homonids_0324.jpg
[2013/04/04 14:50:32 | 000,025,928 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/03/31 18:36:56 | 000,000,162 | —- | M] () – C:\Windows\Reimage.ini
[2013/03/31 08:57:29 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/03/30 21:21:20 | 000,214,520 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2013/03/30 21:21:20 | 000,214,520 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[2013/03/30 18:29:23 | 480,951,731 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/03/30 18:24:57 | 002,237,968 | —- | M] (Kaspersky Lab ZAO) – C:\Users\mlawre\Desktop\tdsskiller.exe
[2013/03/29 20:11:53 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\mlawre\Desktop\HiJackThis.exe
[2013/03/29 20:11:23 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\mlawre\Desktop\OTL.exe
[2013/03/29 19:57:31 | 000,688,992 | R— | M] (Swearware) – C:\Users\mlawre\Desktop\dds.com
[2013/03/25 21:16:59 | 001,278,994 | —- | M] () – C:\Users\mlawre\Desktop\acspc-036845.pdf
[2013/03/24 22:41:09 | 001,606,848 | —- | M] (InstallX, LLC) – C:\Users\mlawre\Desktop\ezcalendar_d144272.exe
[2013/03/24 00:12:39 | 002,250,054 | —- | M] () – C:\ProgramData\1.bmp
[2013/03/24 00:12:27 | 000,350,795 | —- | M] () – C:\ProgramData\1.jpg

========== Files Created - No Company Name ==========

[2013/04/06 23:00:52 | 000,053,126 | —- | C] () – C:\Users\mlawre\Desktop\360_homonids_0324.jpg
[2013/03/31 18:35:38 | 000,000,162 | —- | C] () – C:\Windows\Reimage.ini
[2013/03/30 11:56:05 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/03/30 11:56:05 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/03/30 11:56:05 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/03/30 11:56:05 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/03/30 11:56:05 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/03/28 00:17:46 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/03/25 21:16:58 | 001,278,994 | —- | C] () – C:\Users\mlawre\Desktop\acspc-036845.pdf
[2013/03/24 00:12:39 | 002,250,054 | —- | C] () – C:\ProgramData\1.bmp
[2013/03/24 00:12:25 | 000,350,795 | —- | C] () – C:\ProgramData\1.jpg
[2011/12/20 21:13:36 | 000,214,520 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2011/12/20 21:13:14 | 000,075,064 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2011/10/16 16:44:45 | 000,000,293 | —- | C] () – C:\Windows\game.ini
[2011/03/27 16:23:54 | 000,010,752 | —- | C] () – C:\Users\mlawre\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 00:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 23:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 07:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/04/07 20:49:48 | 000,000,000 | —D | M] – C:\Users\mlawre\AppData\Roaming\Ekaxfuu
[2013/01/09 22:53:01 | 000,000,000 | —D | M] – C:\Users\mlawre\AppData\Roaming\EndNote
[2011/08/27 17:36:09 | 000,000,000 | —D | M] – C:\Users\mlawre\AppData\Roaming\Full
[2011/05/06 21:15:31 | 000,000,000 | —D | M] – C:\Users\mlawre\AppData\Roaming\GameRanger
[2013/04/06 08:46:52 | 000,000,000 | —D | M] – C:\Users\mlawre\AppData\Roaming\Likyyn
[2012/01/17 00:32:24 | 000,000,000 | —D | M] – C:\Users\mlawre\AppData\Roaming\Might & Magic Heroes VI
[2013/04/13 19:06:55 | 000,000,000 | —D | M] – C:\Users\mlawre\AppData\Roaming\Pimeymef
[2011/08/27 17:14:03 | 000,000,000 | —D | M] – C:\Users\mlawre\AppData\Roaming\Sammsoft
[2012/04/01 17:27:14 | 000,000,000 | —D | M] – C:\Users\mlawre\AppData\Roaming\Tiny Rock
[2013/04/13 19:04:41 | 000,000,000 | —D | M] – C:\Users\mlawre\AppData\Roaming\Woasdyki
[2013/02/09 17:13:03 | 000,000,000 | —D | M] – C:\Users\mlawre\AppData\Roaming\Xirrus
[2013/04/09 20:47:11 | 000,000,000 | —D | M] – C:\Users\mlawre\AppData\Roaming\Ycgemya

========== Purity Check ==========



< End of report >
Hi mlware,,

You don't have an antivirus program installed. MBAM is not an antivirus. We can take care of that shortly.

You may be seeing a conflic between MBAM and SpyHunter and Windows Defender. I suggest you uninstall SpyHunter and disable Windows Defender.

Next, openOTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
C:\Users\mlawre\AppData\Roaming\Ekaxfuu
C:\Users\mlawre\AppData\Roaming\Likyyn
C:\Users\mlawre\AppData\Roaming\Pimeymef
C:\Users\mlawre\AppData\Roaming\Woasdyki
C:\Users\mlawre\AppData\Roaming\Xirrus
C:\Users\mlawre\AppData\Roaming\Ycgemya

:Commands
[emptytemp[
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.

Please post back with
  • OTL fix log
Thanks Oldman960! I ran OTL with your code. Here is the log: ========== SERVICES/DRIVERS ========== ========== FILES ========== C:\Users\mlawre\AppData\Roaming\Ekaxfuu folder moved successfully. C:\Users\mlawre\AppData\Roaming\Likyyn folder moved successfully. C:\Users\mlawre\AppData\Roaming\Pimeymef folder moved successfully. C:\Users\mlawre\AppData\Roaming\Woasdyki folder moved successfully. C:\Users\mlawre\AppData\Roaming\Xirrus\Xirrus Wi-Fi Inspector-1.2.1.4\install folder moved successfully. C:\Users\mlawre\AppData\Roaming\Xirrus\Xirrus Wi-Fi Inspector-1.2.1.4 folder moved successfully. C:\Users\mlawre\AppData\Roaming\Xirrus folder moved successfully. C:\Users\mlawre\AppData\Roaming\Ycgemya folder moved successfully. ========== COMMANDS ========== Error: Unable to interpret <[emptytemp[> in the current context! Restore point Set: OTL Restore Point OTL by OldTimer - Version 3.2.69.0 log created on 04232013_223514
Hi Oldman960, Computer is running much better. Thanks so much! I don't use the Xirrus Wi-Fi Inspector. I downloaded it a few months back for some separate issue. Thanks again for all your help! Michael
Hi mlware,

Ok, no point in restoring the Xirrus Wi-Fi Inspector folders if you don't need it. You can always download it again.

Any problems? If not we will clean up the tools.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • DDS.scr
  • Attach.txt
  • TDSSKiller
You can also delete from the C:\ drive the file called TDSSKiller_* (* denotes version & date) and C:\TDSSKiller_Quarantine

Next

Click the Start button, in the search box type Run. At the top click run

Copy and paste the following line into the run box and click OK

Combofix /uninstall



Next

Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM. Keep it updated and use it regularly.



Next, download and install one of these free antivirus programs.

Avast
Help and support can be found here Avast Forum
Antivir PersonalEditionClassic
Help and support can be found here Avira Personal Support Forum
Microsoft Security Essentials
Support


Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. Those you have now provided once you install an antiviurs program and use a firewall.

Windows 7 has a built in firewall which is pretty good when set up. You can find some very good information HERE .


You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.



-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Make sure you have reset Windows Updates to your chosen option. Click your start button > Control Panel > System > Windows updates (lower left) > change settings


- Keep your antivirus program updated, as well as any other security programs you have.

-More tips and programs can be found HERE

Please post back if you have any problems.

Take care :adios:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI